2011/10/12

E-Virus (Part III): I have a PC infected! Now as I clean it?

After confirming the presence of one or more e-virus on your PC,



... you should read up as much as possible (with Internet) what are the characteristics of those virus that are present (mode of distribution, payload, removal instructions). Knowing the enemy is easier to defeat him! 


In fact, knowing the name of the virus and how it is dangerous it is possible that a specific removal tool is freely available from software company like: Symantec, Kaspersky, McAfee, TrendMicro, etc.. 
For example, there are removal tools for specific viruses as the most common: Melissa , Bagle , MyDoom, Sasser , Conficker , etc.. 

Or you can use tools to remove general (broad spectrum) as:
Obviously you can increase the benefits of these products by performing sequentially scanning of the PC with different instruments. 

Sometimes however, you must do multiple scans with different products but you can not install too many anti-virus simultaneously on the same PC for speed and compatibility issues. Besides installing and removing sequentially the various antivirus becomes costly and long, so you can avoid using the services of free online tools for virus scanning and removing offered by some software house (the only constraint is given by having to scan through internet connection always active).
For example we can mention:
All these operations are of course possible only when the virus has not completely compromise access to the PC.

If you can not start the operating system then you can use antivirus software from a CD or bootable USB key (Rescue CD). These systems are typically available as .ISO images and you must create CD / DVD or install it on bootable USB sticks, so you can operate independently of the operating system installed on the infected PC (Windows / Linux). The only care is to be placed in verify that the BIOS is selected  to the CD or USB external drive as first boot device.
Some examples:
9) COMODO Rescue Disk CD
Once you start the CD you can scan the hard drive and require the deletion / correction of infected files.

PERSONAL EXPERIENCE:
I have often used some of these tools along with excellent results. In particular ComboFix was decisive with the virus most "resistant". 
Regarding the now infamous "worm" Conficker - Downadup, I can indicate the presence of specific free removal tool from almost all manufacturers of antivirus. Bitdefender, however, provides also a free removal tool that works on ALL the LAN and not only on the individual PC ( Network Downadup Removal Tool ). 
In some situations even after you delete virus, the operating system is "unstable" because it partly damaged by the virus itself. A viable technique in these cases, apart from the total reinstallation of the operating system, is to make the System Restore going back a few days compared to infection of the virus (feature available on versions of Windows from XP forward).