|
To scan a file with a
bunch of different scanners and get a single report from all of them, use this
site:
And if you want to see
what a malicious file does, use this site:
And the best way to get
rid of a file like that is probably to boot in Safe Mode, then edit all the
usual registry places to get rid of the malware, and delete each instance of the
file. Also check that the hosts. file has no bogus entries. If you
can't delete a file because it's running, rename the file on the
drive. If you want to terminate a process that Task Manager won't let you
terminate, use pskill.exe from http://www.sysinternals.com/ as an
Administrator-equivalent userid.
It won't hurt to also, as
the user, install http://www.javacoolsoftware.com/
which will tighten up their Internet Explorer settings, and turn on the "kill
bit" for many CLASSIDs of known malware. If you don't mind fetching
updates interactively, Spyware Blaster is free for personal use.
For a general perusal and
interactive utility to see what applications are set to start from where, check
out HijackThis from http://www.spywareinfo.com/~merijn/downloads.html
And for the next week, I
think the best interactive tool to ferret out start all the startup applications
and places is still Microsoft Antispyware. They've taken a hit recently
because although they continue to find several Adware vendors' software, they
now suggest an action of "Ignore" instead of "Remove". http://www.microsoft.com/athome/security/spyware/software/default.mspx
Andrew 8)
p.s.
You might guess that I've had to remove, oh, just one or two bits of
malware from users' workstations...
|
- [Declude.Virus] OT: Online file check? William Stillwell
- RE: [Declude.Virus] OT: Online file check? John Tolmachoff \(Lists\)
- Re: [Declude.Virus] OT: Online file che... Greg Little
- Re: [Declude.Virus] OT: Online file... William Stillwell
- Re: [Declude.Virus] OT: Online ... Greg Little
- Re: [Declude.Virus] OT: Online file che... William Stillwell
- RE: [Declude.Virus] OT: Online file check? Colbeck, Andrew
- RE: [Declude.Virus] OT: Online file check? Colbeck, Andrew
- RE: [Declude.Virus] OT: Online file check? Colbeck, Andrew
- RE: [Declude.Virus] OT: Online file check? Colbeck, Andrew
- RE: [Declude.Virus] OT: Online file che... Marc Catuogno
