This is what I feel about the infections (viruses) today and the process I follow to remove the infections.
The infections are more of adware type promoting useless products and of course other types as well.
Common reasons for Viruses (and sub Genres) today are USB, Internet Explorer and Instant messaging applications.
USB is a major culprit behind any infection today . I suggest not to double-click external drives from the explorer since most of the drives have a autorun.inf file at the root directory of the drive. It has an entry to execute an application which is most likely to infect the machine.
Some symptoms of infections:
- Registry/Task Manager/Folder options/control panel do not open. (You might get “Disabled by Administrator” error)
- Cannot unhide files in spite of allowing to “show hidden files/protected files”
- Applications not opening
- “Open With” when you double-click drives (mostly with external drives)
- Frequent error messages and system slowness
I use some free tools like Malwarebytes, Process Explorer etc. to get rid of the infections.
Process I follow to remove the bad guys.
- Clean junk like IE cache and Temp files. I prefer to use CCleaner since it not only cleans the regular places where unwanted info is left over but also it supports other applications like Browsers, Office, Adobe, Zip tools etc.
- Disable the unwanted or suspicious IE add-ons (Optional).
- Disable System Restore (Optional)
- Do a quick scan instead of a full scan using Malwarbytes. Quick scan removes infections most of the time. Spybot is a good tool but it takes quite a lot of time to scan.
- Some viruses detect anti-virus/anti malware products and can disable or even stop the installation.
- You can use the built-in Msconfig to disable start-up items.
- Autoruns by Sysinternals is a mother of Msconfig gives you a very detailed information of auto-starting locations, what programs are configured to run during system boot up or login etc .
- Process explorer by Sysinternals can give a detailed information of the processes running and much more which can help you troubleshoot a bit more. The below link is a webcast which talks about advanced malware cleaning (its old but still helpful)
http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=359
- Honestly I have never seen or removed Rootkits but there some applications which might help to remove them eg RootkitRevealer by Sysinternals
- Windows updates
Sysinternals Suite has some pretty good tools to nail down infections.
There are many Pre-installation Environment (PE) products which help you boot from a CD/USB etc which can be used to integrate millions of free and paid products into them (Including CCleaner, Malwarebytes etc). You can download prebuilt products or even build it yourself using Bart-PE and other PE tools
These are some ways which “might” help you to get rid of the infections but of course there would be situations where you just have to reimage the machine.
Some free tools which might be helpful
Optimization and Cleaning
Malware, Adware & others
Preinstallation environment (PE) tools:
Search files:
Other tools: