Blitz it and start again.
Quickest and simplest solution for all usually :-)
Blitz it and start again.
Quickest and simplest solution for all usually :-)
Simple answer - no, there's no easy by the numbers way to 100% remove all infections from a badly infected PC, and the situation is only getting worse.
Accept defeat now and look to other solutions to help you do your job more efficiently...
The first time you do a format/reinstall, set up each PC so that user data is on a separate partition and image the drive with something like Norton Ghost when the install is complete. Then, if/when you see that machine again down the line it's a 15 minute job to restore from image and if user data is on a separate partition you won't even need to worry about lots of user data to backup and restore. It's a lot more efficient than attempting to clean a badly infected PC or reinstalling from scratch.
To stand a fighting chance of cleaning a badly infected PC you'll need detailed knowledge of each individual infection and manual procedures for removing it. Mounting the infected HD in a clean system is almost a must to bypass a lot of the protections (rootkits, ADS streams, illegal filenames etc) that many modern malware use. Then there are certain polymorphic infections such as Sality/Virut etc that append their code into all running processes making it almost impossible to clean - it's going to take a very determined person to rebuild that system without reformatting.
Last edited by Phil_P; 09-09-2007 at 06:18 PM.
In my experience, I will only ever bother trying to use an antivirus program to disinfect a PC and maybe ad aware aswell. If those cant remove it, its format time. You can spend hours cleaning the system and 2 weeks later its just as bad as it was before.
Mind you, I have setup WDS at work so a reformat/reinstall is actually a 5 minute job for me (and appx 1 hour wait for the user)
"In a perfect world... spammers would get caught, go to jail, and share a cell with many men who have enlarged their penises, taken Viagra and are looking for a new relationship."
Glad that everyone's pretty much agreed with me. What do these places that do "PC Health Checks" actually do? I can't see somewhere like PC World spending hours and hours trying to remove all different kinds of malware with the chance it's going to happen again sometime soon.
"Reality is what it is, not what you want it to be." Frank Zappa. ----------- "The invisible and the non-existent look very much alike." Huang Po.----------- "A drowsy line of wasted time bathes my open mind", - Ride.
I usually reach for the DBAN.
Failing that, it's the usual time-consuming process of going through Spybot, Ad-aware, Avira Antivir, with Sysinternal's Process Explorer and Autoruns.
Latest addition to the toolkit is Xblock's Xclean Micro utility. Small, quick and free. Google for it.
There are currently 1 users browsing this thread. (0 members and 1 guests)