Solved

Recommended sequence of antivirus programs for really pernicious malware

Posted on 2014-01-13
7
626 Views
Last Modified: 2014-02-03
I'm just wrapping up with an older XP laptop what was badly infected with malware. Here's what I used:

VIPRE - Our native antivirus
SuperAntiSypware
MalwareBytes
Kasperky's TDSSKiller

I have ComboFix in my arsenal of antivirus apps, but I don't use it unless I have to since it will occasionally break a legitimate app.

As anyone published a recommended sequence of antivirus apps when running multiple antivirus apps is necessary?
0
Comment
Question by:jdana
7 Comments
 
LVL 90

Assisted Solution

by:John Hurst
John Hurst earned 47 total points
ID: 39777645
For really bad cases, reinstalling Windows is the only practical long term solution.

For lesser cases, I find scanning with the regular AV (provided it is good), followed by Malwarebytes to be generally effective.

... Thinkpads_User
0
 
LVL 47

Assisted Solution

by:dbrunton
dbrunton earned 93 total points
ID: 39777683
Probably best is to scan from another OS rather than the native OS.  By this I mean you could slave the hard disk to another computer and use that system's anti-virus or scan the concerned computer from a boot CD eg Kapersky http://support.kaspersky.com/4131 (others do exist).

If you can't do this and you've got an infection that the standard anti virus being used isn't stopping then I'd recommend starting with MalwareBytes.
0
 
LVL 22

Accepted Solution

by:
Nick Rhode earned 47 total points
ID: 39777837
I put up an article to help guide with removing viruses/malware.

Here: http://www.experts-exchange.com/Security/Vulnerabilities/A_12285-Virus-Removal-Methods.html

If you use combofix I would run it after the sequence
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 
LVL 24

Assisted Solution

by:aadih
aadih earned 47 total points
ID: 39777916
(1) Malwarebytes Antimalware.

(2) TDSSKiller.

(3) SuperAntispyware.

suffice, usually.
0
 
LVL 47

Assisted Solution

by:dbrunton
dbrunton earned 93 total points
ID: 39777967
0
 
LVL 23

Assisted Solution

by:Mohammed Hamada
Mohammed Hamada earned 46 total points
ID: 39779147
I agree with dbrunton on the bootable antivirus system! It's your best bit if there's away to disinfect the infected files.

It helped me so much once on Windows 2003 server that was about to die. I used Kaspersky bootable disk and found away to fully updated using offline update definition file which later on cleaned the OS.
0
 

Author Closing Comment

by:jdana
ID: 39831162
Thanks for all the input!
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

Suggested Solutions

Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
This story has been written with permission from the scammed victim, a valued client of mine – identity protected by request.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now