Antimalware for the Bench

article #162, updated 1489 days ago

The first try as of this writing, whenever possible, is RogueKiller:

http://tigzy.geekstogo.com/roguekiller.php

RogueKiller has done amazing things.

Second is often MalwareBytes, or a LiveCD.

Recently I had to try a number of LiveCDs on two different PCs, and they all failed, either failed to boot or froze or whatever. As a consequence, things have changed, and I’m listing the Avira AntiVir Rescue System as first LiveCD:

http://www.avira.com/en/download/product/avira-antivir-rescue-system

and second, the venerable Trinity Rescue Kit:

http://trinityhome.org/Home/index.php?content=TRINITY_RESCUE_KIT_DOWNLOAD&front_id=12&lang=en&locale=en

TRK has five different scanners set up, two of which (F-PROT and Clam) are currently working very well. BitDefender’s (automatic) download site was timing out today, and although Avast is there, it needs a license.

There are also some very special non-liveCD tools for bench work, from bleepingcomputer.com quite a large community devoted to helping handle malware situations. Bearing strongly in mind, that they recommend against using these unless their people are directly involved…

…here is ComboFix.

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

ComboFix removes a large proportion of malware, but even if it cannot remove everything, it is good to use it (if possible) before anything else, because it fixes damage done by malware, which other tools generally do not.

And also from the BC folks, we have UnHide:

http://download.bleepingcomputer.com/grinler/unhide.exe

UnHide is very useful for certain attacks, including “Vista Recovery Malware”, in which most or all relevant files are turned to ‘hidden’. UnHide reverses this, and properly.

And a good emergency tool, also from BleepingComputer, we have RKill:

http://www.bleepingcomputer.com/download/anti-virus/rkill

RKill is especially neat, it will kill ‘rogue antivirus products’ and similar nasties, so that you can rip them out before they start up again! And if you can’t run a .EXE, rename it to .SCR, it will probably run just as well, as if it were a screen saver :-) Many different filenames are available at the above link, just in case.

Categories:   Antivirus/Antimalware Tools and Issues   Cleanup