Poll: How do YOU remove malware?

What is your technique for removing malware on either your own or others PC?

  • I just format and reinstall

    Votes: 44 21.8%
  • I run various anti-virus/malware products and if they fail to remove it I end up reinstalling

    Votes: 88 43.6%
  • I try to find and use a specific removal utility designed for the exact type of malware

    Votes: 29 14.4%
  • I use tools like HijackThis/Sysinternals but not always successfully and I end up formatting

    Votes: 10 5.0%
  • I use tools (as above) and have ways of preventing the malware from "coming back"

    Votes: 31 15.3%

  • Total voters
    202
I've googled and googled but I've never seen my technique talked about or documented anywhere. Quite strange really considering it is such a simple and easy to use technique.

I believe the only malware/rootkit that at least partially prevents this technique is Conficker. But only because it sets the NTFS Security of its hidden rootkit files to deny the "Users" group all access to its files. But the "SYSTEM" account would still have access so it would just be a case of executing a script under that account to modify the NTFS Security. It would be much more involved but still possible.
What does it feel like being a trailblazer? :)
 
I don't have any problems on my own system, not for a very long time anyway.

On other peoples systems I have used Adaware and Spybot.

I once used a program called Regrun, this removed some things that the above missed but its pretty dangerous as its easy to cause more problems with it as it complains at so many normal things you have installed.
 
I don't really have any malware issues but if there's any problems I reboot in safe mode and run all my updated anti-spyware and anti-virus. If you know what the virus is then the specific tools usually get the job done and if you think your AV is compromised (root kit etc) you can use an online checker.

Prevention is the best method though.
 
Depending on the severity of the infection depends on what i do.

Normally use HJT and Spybot plus trend online virus scan.

If all else fails then i format.
 
Depends what it is. If it's a fairly minor piece of adware then I'll just run Malwarebytes, etc. and root through the registry myself for signs of it. If it's a more invasive trojan then the easiest and safest way to get rid of it is to reinstall. Admittedly reinstalling is easier on my own system with the OS on a separate partition than it would be on someone else's.
 
5.

to stop things coming back..

get them to buy nod32, install spyware blaster & spybot, and use the immunize features.


install Firefox, with adblock plus and maybe Noscript.

tell them never to use IE again
 
I don't get malware :p

If anything goes even slightly wrong with my install, I'll just reinstall. Only takes 15 minutes, much quicker than scanning/fixing and whatnot :)
 
Back
Top Bottom