Search This Blog

Showing posts with label Malwares. Show all posts
Showing posts with label Malwares. Show all posts

Friday, December 2, 2011

Remove Hard-to-Kill Malware

Are you sure the problem is malware? People often jump to that conclusion when there's something wrong with their PC, and in my experience that conclusion is more often wrong than right. There's a lot of malicious code in this world, but there's even more code that's merely incompetent. There's also a fair amount of worn-out hardware.
On the other hand, if you're experiencing any of the following symptoms, you quite likely have malware:
  • Your security software doesn't work properly, or refuses to update.
  • Common programs for configuring and repairing Windows, such as MSCONFIG and System Restore, don't work.
  • Messages from a program you never installed pop up and tell you that your computer is infected, your hard drive is dying, or you have some other serious problem. (See Watch Out for Rogues for more on this issue.)
  • Your browser's home page keeps changing to something you don't want, and/or your search results aren't what they should be.
  • Your computer slows down sometimes for no apparent reason. (This may not be malware. See Very Slow PC for more on this.)
But what if you've got one or more of these symptoms, yet nothing in your battery of malware-fighting programs finds something evil?
The solution is to use a Linux-based malware-fighting program that boots off a flash drive or CD-ROM. By working outside of Windows, and outside the hard drive's boot sector, these programs can better get around the malware's defenses.
I'm going to recommend two of them, both of which can boot off flash drives or CDs. They're AVG Rescue CD and Dr.Web LiveCD or LiveUSB. If one doesn't do the trick, try the other.

Tuesday, November 22, 2011

How to Remove Malware From Your Windows PC

Has a malware infection taken your PC hostage? Here's how to clean it out and restore your PC to a pristine state.

Is your computer running slower than usual? Are you getting lots of pop-ups? Have you seen other weird problems crop up? If so, your PC might be infected with a virus, spyware, or other malware--even if you have an antivirus program installed on it. Though other problems, such as hardware issues, can produce similar symptoms, it's best to check for malware if you aren't sure. But you don't necessarily need to call tech support or the geek across the street to scan for malware--I'll show you how to do it yourself.

Step 1: Enter Safe Mode

Keep your PC disconnected from the Internet, and don't use it until you're ready to clean your PC. This can help prevent the malware from spreading and/or leaking your private data.
If you think your PC may have a malware infection, boot your PC into Microsoft's Safe Mode. In this mode, only the minimum required programs and services are loaded. If any malware is set to load automatically when Windows starts, entering in this mode may prevent it from doing so.
To boot into Windows Safe Mode, first shut down your PC. Locate the F8 key on your PC's keyboard; turn the PC on; and as soon as you see anything on the screen, press the F8 key repeatedly. This should bring up the Advanced Boot Options menu; there, select Safe Mode with Networking and press Enter.
You may find that your PC runs noticeably faster in Safe Mode. This could be a sign that your system has a malware infection, or it could mean that you have a lot of legitimate programs that normally start up alongside Windows.

Step 2: Delete Temporary Files

Now that you're in Safe Mode, you'll want to run a virus scan. But before you do that, delete your temporary files. Doing this may speed up the virus scanning, free up disk space, and even get rid of some malware. To use the Disk Cleanup utility included with Windows, select Start, All Programs(or just Programs), Accessories, System Tools, Disk Cleanup.

Step 3: Download Malware Scanners

Now you're ready to have a malware scanner do it's work--and fortunately, running a scanner is enough to remove most infections. If you already had an antivirus program active on your computer, you should use a different scanner for this malware check, since your current antivirus software may have not detected the malware. Remember, no antivirus program can detect 100 percent of the millions of malware types and variants.
There are two types of antivirus programs. You're probably more familiar with real-time antivirus programs, which constantly watch for malware. Another option is on-demand scanners, which search for malware infections when you open the program manually and run a scan. You should have only one real-time antivirus program installed at a time, but you can keep a few on-demand scanners handy to run scans with multiple programs, thereby ensuring that you're covered.
If you think your PC is infected, I recommend using an on-demand scanner first and then following up with a full scan by your real-time antivirus program. Among the free (and high-quality) on-demand scanners available are BitDefender Free Edition, Kaspersky Virus Removal Tool, Malwarebytes,Norman Malware Cleaner, and SuperAntiSpyware.

Step 4: Run a Scan With Malwarebytes

For illustrative purposes, I'll describe how to use the Malwarebytes on-demand scanner. To get started, download it. If you disconnected from the Internet for safety reasons when you first suspected that you might be infected, reconnect to it so you can download, install, and update Malwarebytes; then disconnect from the Internet again before you start the actual scanning. If you can't access the Internet or you can't download Malwarebytes on the infected computer, download it on another computer, save it to a USB flash drive, and take the flash drive to the infected computer.
After downloading Malwarebytes, run the setup file and follow the wizard to install the program. Once installed, Malwarebytes will check for updates and launch the app itself. If you get a message about the database being outdated, select Yes to download the updates and then click OK when prompted that they have been successfully installed.
Once the program opens, keep the default scan option ('Perform quick scan') selected and click theScan button.
Starting the scan in Malwarebytes; click for full-size image.Starting the scan in Malwarebytes.
Though it offers a full-scan option, Malwarebytes recommends that you perform the quick scan first, as that scan usually finds all of the infections anyway. Depending on your computer, the quick scan can take anywhere from 5 to 20 minutes, whereas the full scan might take 30 to 60 minutes or more. While Malwarebytes is scanning, you can see how many files or objects the software has already scanned, and how many of those files it has identified either as being malware or as being infected by malware.
If Malwarebytes automatically disappears after it begins scanning and won't reopen, you probably have a rootkit or other deep infection that automatically kills scanners to prevent them from removing it. Though you can try some tricks to get around this malicious technique, you might be better offreinstalling Windows after backing up your files (as discussed later), in view of the time and effort you may have to expend to beat the malware.
If Malwarebytes' quick scan doesn't find any infections, it will show you a text file containing the scan results. If you still think that your system may have acquired some malware, consider running a full scan with Malwarebytes and trying the other scanners mentioned earlier. If Malwarebytes does find infections, it'll bring up a dialog box warning you of the discovery. To see what suspect files the scanner detected, click the Scan Results button in the lower right. It automatically selects to remove the ones that are known to be dangerous. If you want to remove other detected items, select them as well. Then click the Remove Selected button in the lower left to get rid of the specified infections.
Removing infections in Malwarebytes; click for full-size image.Removing infections in Malwarebytes.
After removing the infections, Malwarebytes will open a text file listing the scan and removal results; skim through these results to confirm that the antivirus program successfully removed each item. Malwarebytes may also prompt you to restart your PC in order to complete the removal process, which you should do.
If your problems persist after you've run the quick scan and it has found and removed unwanted files, consider running a full scan with Malwarebytes and the other scanners mentioned earlier. If the malware appears to be gone, run a full scan with your real-time antivirus program to confirm that result.

Friday, October 28, 2011

What Is the Security Intelligence Report?


With a collection of data from Internet services and over 600 million computers worldwide, the Security Intelligence Report (SIR) exposes the threat landscape of exploits, vulnerabilities, and malware. Awareness of threats is a preventive step to help you protect your organization, software, and people.
Worldwide Threat Assessment is an analysis of the global impact while Regional Threat
Assessment
 provides detailed telemetry by location. Protection methods appear in Managing Risk. SIR volume 11 provides data from January to June 2011 and features the ZeroDay article.

Link: 
http://www.microsoft.com/security/sir/default.aspx