My process for removing infections

Countryside

New Member
Messages
11
This is under the presumption that the PC can boot into Windows...or at least into safe mode.

I have a USB drive and I download the install files of the following onto it from a clean PC:
rkill
TDSSKiller
SuperAntiSpyware (free)
Malwarebytes (free)
Combofix
Either IObit Uninstaller or REVOuninstaller
AVAST (free)
Windows Repair (All in One)

The majority of these can be found for download on CNET or Bleepingcomputer.
The Windows Repair Tool is at tweaking.com.

If I can make it into Windows on the infected PC, I insert the USB drive. I then drag and drop the programs from the USB drive onto the desktop.
First I run rkill.
Rkill runs a scan and tries to stop (not remove) any malicious processes it may find.
Then I update and run TDSSKiller.
After it gets through, I install and run SuperAntiSpyware and Malwarebytes...full scans.
If there is any anti-virus program, I stop any active protection in order to run Combofix.
After Combofix, I install and run an uninstaller (IOBit, etc) program to find and completely remove junk and unwanted programs.
After this, I install and update AVAST free, and then I run a PRE-BOOT scan.
The final step I normally use is running the Windows All in One Repair Tool. It takes you step by step through a process (including check disk and system file check) and a final process that corrects and restores Windows settings.
Depending on the existing anti-virus on the machine, I may or may not uninstall AVAST.
 
Last edited:

My Computer

System One

  • OS
    Win 8.1
    Computer type
    Laptop
Format C:\ works every time in my experience, needless to say that a good back up strategy is also a must!
 
Last edited:

My Computer

System One

  • OS
    Windows 8 Pro With Media Centre

My Computer

System One

  • OS
    Windows 10 Pro Prieview x64
    Computer type
    Laptop
    System Manufacturer/Model
    MacBook Pro Core2Duo
    CPU
    T7600
    Memory
    3
    Graphics Card(s)
    ATI Radeon X1600
    Monitor(s) Displays
    Internal
    Screen Resolution
    1440 x 800
    Hard Drives
    40GB
    Keyboard
    Apple
    Mouse
    Apple
    Internet Speed
    Varies
    Browser
    Various
    Antivirus
    Defender
Format C:\ works every time in my experience, needless a good back up strategy is also a must!

I'm right there with ya :thumbsup:

99.5% after cleaning an infection depending on what it is, the OS is just never the same again, best just to reformat / reinstall.
 

My Computer

System One

  • OS
    Windows 7 Home Premium x64 / Windows 8.1 Pro x64 Dual Boot
    Computer type
    PC/Desktop
    System Manufacturer/Model
    HP
    Memory
    8 gigs
    Graphics Card(s)
    Nvidia GE Force 5200
    Monitor(s) Displays
    HP 2009M x's 2
    Screen Resolution
    1600 x 900 x's 2
    Hard Drives
    One internal Western Digital HD 650 GB
    Three external Western Digital HD's - 1 TB each
Format C:\ works every time in my experience, needless a good back up strategy is also a must!

I'm right there with ya :thumbsup:

99.5% after cleaning an infection depending on what it is, the OS is just never the same again, best just to reformat / reinstall.
Unless the infection isn't on your disk of course.
 

My Computer

System One

  • OS
    Windows 10 Pro Prieview x64
    Computer type
    Laptop
    System Manufacturer/Model
    MacBook Pro Core2Duo
    CPU
    T7600
    Memory
    3
    Graphics Card(s)
    ATI Radeon X1600
    Monitor(s) Displays
    Internal
    Screen Resolution
    1440 x 800
    Hard Drives
    40GB
    Keyboard
    Apple
    Mouse
    Apple
    Internet Speed
    Varies
    Browser
    Various
    Antivirus
    Defender
The suggestions are fine if it is your own computer and if you have a restore partition and/or restore media and all your important files have been backed up.
I was mainly talking about how I do PCs that others bring me. The majority of them will not have backup, may not have a restore partition, and very few have restore media. Gotta work with what ya got.
 

My Computer

System One

  • OS
    Win 8.1
    Computer type
    Laptop
Personally I never had an infection(half luck/half good security practice, safe surfing) but one should also look in firewall after to see if any ports are left open from sloppy uninstalled programs and any changes due to an infection. Go to Windows Firewall and click Restore Defaults:
View attachment 56930
 

My Computer

System One

  • OS
    Windows 8.1 Update Pro in Hyper-V/Windows 10 Pro 64 bit
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Cliff's Black & Blue Wonder
    CPU
    Intel Core i9-9900K
    Motherboard
    ASUS ROG Maximus X Hero
    Memory
    32 GB Quad Kit, G.Skill Trident Z RGB Series schwarz, DDR4-3866, 18-19-19-39-2T
    Graphics Card(s)
    ASUS GeForce RTX 3090 ROG Strix O24G, 24576 MB GDDR6X
    Sound Card
    (1) HD Webcam C270 (2) NVIDIA High Definition Audio (3) Realtek High Definition Audio
    Monitor(s) Displays
    BenQ BL2711U(4K) and a hp 27vx(1080p)
    Screen Resolution
    1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
    Hard Drives
    C: Samsung 960 EVO NVMe M.2 SSD
    E: & O: Libraries & OneDrive-> Samsung 850 EVO 1TB
    D: Hyper-V VM's -> Samsung PM951 Client M.2 512Gb SSD
    G: System Images -> HDD Seagate Barracuda 2TB
    PSU
    Corsair HX1000i High Performance ATX Power Supply 80+ Platinum
    Case
    hanteks Enthoo Pro TG
    Cooling
    Thermaltake Floe Riing RGB TT Premium-Edition 360mm and 3 Corsair blue LED fans
    Keyboard
    Trust GTX THURA
    Mouse
    Trust GTX 148
    Internet Speed
    25+/5+ (+usually faster)
    Browser
    Edge; Chrome; IE11
    Antivirus
    Windows Defender of course & Malwarebytes Anti-Exploit as a
    Other Info
    Router: FRITZ!Box 7590 AX V2
    Sound system: SHARP HT-SBW460 Dolby Atmos Soundbar
    Webcam: Logitech BRIO ULTRA HD PRO WEBCAM 4K webcam with HDR

My Computer

System One

  • OS
    Windows 8 Pro With Media Centre
The suggestions are fine if it is your own computer and if you have a restore partition and/or restore media and all your important files have been backed up.
I was mainly talking about how I do PCs that others bring me. The majority of them will not have backup, may not have a restore partition, and very few have restore media. Gotta work with what ya got.

I usually save photo's emails, documents etc to another drive and after checking them restore to the formatted drive, again potentially not a 100% cure but has always worked for me, you have to know the likely places where infections will be lurking.
 

My Computer

System One

  • OS
    Windows 8 Pro With Media Centre
Format C:\ works every time in my experience, needless a good back up strategy is also a must!

I'm right there with ya :thumbsup:

99.5% after cleaning an infection depending on what it is, the OS is just never the same again, best just to reformat / reinstall.
Unless the infection isn't on your disk of course.

We get the point. there is also something that delivers malware over an air gap called BadBIOS. When we worry to much about such things we might as well put our PCs away and just use paper and pencils again(oh and an abacus too)
 

My Computer

System One

  • OS
    Windows 8.1 Update Pro in Hyper-V/Windows 10 Pro 64 bit
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Cliff's Black & Blue Wonder
    CPU
    Intel Core i9-9900K
    Motherboard
    ASUS ROG Maximus X Hero
    Memory
    32 GB Quad Kit, G.Skill Trident Z RGB Series schwarz, DDR4-3866, 18-19-19-39-2T
    Graphics Card(s)
    ASUS GeForce RTX 3090 ROG Strix O24G, 24576 MB GDDR6X
    Sound Card
    (1) HD Webcam C270 (2) NVIDIA High Definition Audio (3) Realtek High Definition Audio
    Monitor(s) Displays
    BenQ BL2711U(4K) and a hp 27vx(1080p)
    Screen Resolution
    1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
    Hard Drives
    C: Samsung 960 EVO NVMe M.2 SSD
    E: & O: Libraries & OneDrive-> Samsung 850 EVO 1TB
    D: Hyper-V VM's -> Samsung PM951 Client M.2 512Gb SSD
    G: System Images -> HDD Seagate Barracuda 2TB
    PSU
    Corsair HX1000i High Performance ATX Power Supply 80+ Platinum
    Case
    hanteks Enthoo Pro TG
    Cooling
    Thermaltake Floe Riing RGB TT Premium-Edition 360mm and 3 Corsair blue LED fans
    Keyboard
    Trust GTX THURA
    Mouse
    Trust GTX 148
    Internet Speed
    25+/5+ (+usually faster)
    Browser
    Edge; Chrome; IE11
    Antivirus
    Windows Defender of course & Malwarebytes Anti-Exploit as a
    Other Info
    Router: FRITZ!Box 7590 AX V2
    Sound system: SHARP HT-SBW460 Dolby Atmos Soundbar
    Webcam: Logitech BRIO ULTRA HD PRO WEBCAM 4K webcam with HDR
After it gets through, I install and run SuperAntiSpyware and Malwarebytes...full scans.
That is the problem, if there is a tough malware, you will not be able to install or start it.
I prefer portable versions like Emsisoft Emergency Kit, Dr.Web CureIt! or Hitman Pro.

REVOuninstaller Free does not support 64-bit, try Wise Uninstaller.
 

My Computer

System One

  • OS
    Win 8.1.1 Pro x64
    Computer type
    Laptop
    System Manufacturer/Model
    Lenovo E525
    CPU
    AMD A4-3300M @ 2,0GHz
    Memory
    6GB DDR3 1333MHz
    Graphics Card(s)
    AMD Radeon HD 6480G 512MB shared
    Sound Card
    Creative Sound Blaster X-Fi Surround 5.1
    Screen Resolution
    1366x768
    Hard Drives
    WD 465GB
    Cooling
    Fusion Tweaker
    Keyboard
    Logitech K360
    Mouse
    Logitech M705
    Internet Speed
    50/50 MBps
    Browser
    Yandex
    Antivirus
    No AV & No Firewall
    Other Info
    Headphones: Sennheiser RS170
Always worked for me and computers I've sorted for friends or family.
I'm not saying it doesn't often work. So far defender plus malwarebytes and adwcleaner have worked for me. Only consider that you can't assume it if keys are stored elsewhere and even replacing your disk will not work.
 

My Computer

System One

  • OS
    Windows 10 Pro Prieview x64
    Computer type
    Laptop
    System Manufacturer/Model
    MacBook Pro Core2Duo
    CPU
    T7600
    Memory
    3
    Graphics Card(s)
    ATI Radeon X1600
    Monitor(s) Displays
    Internal
    Screen Resolution
    1440 x 800
    Hard Drives
    40GB
    Keyboard
    Apple
    Mouse
    Apple
    Internet Speed
    Varies
    Browser
    Various
    Antivirus
    Defender
Always worked for me and computers I've sorted for friends or family.
I'm not saying it doesn't often work. So far defender plus malwarebytes and adwcleaner have worked for me. Only consider that you can't assume it if keys are stored elsewhere and even replacing your disk will not work.

I have to agree... what if you have an ssd and the controller gets infected? I suspect what your trying to say (correct me if I'm wrong) is there is malware out there that can attack ANY electronic part of the computer today?
 

My Computer

System One

  • OS
    Windows 8.1 Update Pro in Hyper-V/Windows 10 Pro 64 bit
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Cliff's Black & Blue Wonder
    CPU
    Intel Core i9-9900K
    Motherboard
    ASUS ROG Maximus X Hero
    Memory
    32 GB Quad Kit, G.Skill Trident Z RGB Series schwarz, DDR4-3866, 18-19-19-39-2T
    Graphics Card(s)
    ASUS GeForce RTX 3090 ROG Strix O24G, 24576 MB GDDR6X
    Sound Card
    (1) HD Webcam C270 (2) NVIDIA High Definition Audio (3) Realtek High Definition Audio
    Monitor(s) Displays
    BenQ BL2711U(4K) and a hp 27vx(1080p)
    Screen Resolution
    1920 x 1080 x 32 bits (4294967296 colors) @ 60 Hz
    Hard Drives
    C: Samsung 960 EVO NVMe M.2 SSD
    E: & O: Libraries & OneDrive-> Samsung 850 EVO 1TB
    D: Hyper-V VM's -> Samsung PM951 Client M.2 512Gb SSD
    G: System Images -> HDD Seagate Barracuda 2TB
    PSU
    Corsair HX1000i High Performance ATX Power Supply 80+ Platinum
    Case
    hanteks Enthoo Pro TG
    Cooling
    Thermaltake Floe Riing RGB TT Premium-Edition 360mm and 3 Corsair blue LED fans
    Keyboard
    Trust GTX THURA
    Mouse
    Trust GTX 148
    Internet Speed
    25+/5+ (+usually faster)
    Browser
    Edge; Chrome; IE11
    Antivirus
    Windows Defender of course & Malwarebytes Anti-Exploit as a
    Other Info
    Router: FRITZ!Box 7590 AX V2
    Sound system: SHARP HT-SBW460 Dolby Atmos Soundbar
    Webcam: Logitech BRIO ULTRA HD PRO WEBCAM 4K webcam with HDR
I suspect what your trying to say (correct me if I'm wrong) is there is malware out there that can attack ANY electronic part of the computer today?
No. I gave 2 specific links to where an EFI EPROM can theoretically be infected. The point being even if you remove your drive and put in a new one your problem still exists. I've no idea if power supplies, screens or keyboards have firmware that can be updated with similar malicious intent... Probably not if you want to be realistic but I've never researched it.
 

My Computer

System One

  • OS
    Windows 10 Pro Prieview x64
    Computer type
    Laptop
    System Manufacturer/Model
    MacBook Pro Core2Duo
    CPU
    T7600
    Memory
    3
    Graphics Card(s)
    ATI Radeon X1600
    Monitor(s) Displays
    Internal
    Screen Resolution
    1440 x 800
    Hard Drives
    40GB
    Keyboard
    Apple
    Mouse
    Apple
    Internet Speed
    Varies
    Browser
    Various
    Antivirus
    Defender

My Computer

System One

  • OS
    Win 7 32, Win 7 64 Pro, Win 8.1 Pro
    Computer type
    PC/Desktop
    System Manufacturer/Model
    It's a Dell, Dude.
    CPU
    Intel Caffinated Core Duo
    Motherboard
    Father is bored too.
    Memory
    4 GB
    Graphics Card(s)
    NVidia something-or-another
    Monitor(s) Displays
    24" HD TV/Monitor/Alternative Dimensional Viewing Portal
    Screen Resolution
    Fuzzy after a couple drinks
    Hard Drives
    2 or 3, depending on if it's a night they're arguing about having a "split personality crisis" because I partitioned the drive.
    Case
    Don't get on my case....man
    Cooling
    Scotch on the rocks on the weekends..
    Keyboard
    Mad Catz Cyborg V7. Or maybe Cyborg Catz Are Mad At V7's??? I know it lights up...far out.
    Mouse
    currently being stalked by the cat...
    Internet Speed
    Never fast enough...
    Browser
    Defeated by Mario...wait...OH...BRowser...
    Antivirus
    Various
Back
Top