Sinisterly
So you think you might be infected - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Computers (https://sinister.ly/Forum-Computers)
+--- Forum: Antivirus & Protection (https://sinister.ly/Forum-Antivirus-Protection)
+--- Thread: So you think you might be infected (/Thread-So-you-think-you-might-be-infected)



So you think you might be infected - TesterOfTest - 07-12-2013

Well here we go. New user here, so lets see how this goes.
In this thread I will be telling you a few way to try and determine if you might be infected. I would like to say, this in no way should substitute a virus scanner, and some could cause a little damage, so just read everything first then do it, while reading it!

Start-Up

This is my first step, because I like to know what I have starting up with my computer, and this step can sometimes speed up you computer.
Many I have seen complain they think they have a virus because their computer starts up slow. Well here, we are going to look for what is starting with your computer. There are a few ways to do it, and I am going to tell you a few.

MSConfig
Well this program comes with Windows, in i believe all versions. This program shows a lot of details related to the computers start up. There are a few spots in this program that can cause some damage, so be careful!!
What we are going to do is look at the Startup Tab. In this tab you will be able to see many of the programs that start up with the computer, along with the file location, and the location of how it starts. Now you can go through this, and look. If you see anything that looks suspicious then take not of it.

Things to look for:
  • Programs you do not remember installing
  • Program name is just random letters or numbers
So now you can disable them here, You should do that, just to see if that fixed the problem, but then you get this Selective Start-Up thing, which I hate. So if you want you can do that. Otherwise, take not of the last column which is how the program start up. There are 3 common types. Registry, Startup, and Common Startup.

The startup folder is simply that, a folder that is in the start menu folder of the user. To access this, go to my computer. Then navigate to "Documents And Settings" or "Users" The start up can be in either just your account of the All Users Account. So check both! Go to the user Account then go to this location "\Start Menu\Programs\Startup" you are now in the startup folder for the user. You can delete these shortcuts if you think they are suspicious.

Registry
The other way is through Registry. This is another area where it can get dangerous. These are the programs that have HKLM (Local Machine) or HKCU (Current User) in the last column. Take note of that. You will need it to know which place to go! To access the Registry, you need to have admin control, so just note that! You are going to type "regedit" in the same run box as you opened up before this. This will open a program with 2 windows in it. On the left it displays the treeview of the registry (That is what I like to call it). Now remember that location I said to remember, that is where we have to go. Usually it is in "Software\Microsoft\Windows\CurrentVersion\Run" in either HKLM (Runs when anyone logs on), or HKCU (Runs only when you log in). After you get there, direct your attention to the view on the right! Somewhere in there should be that value you saw in MSconfig. You are going to click it, then delete it! This will stop the program from running on start up.

*THAT IS WHERE SOME DAMAGE COULD OCCUR*

Some programs might need those programs to run correctly. IF you delete anything in this program that is required by another program (Or Windows) it can cause more damage, some might not be recoverable as easy. Before deleting anything in here, it would be in your best interest to ask me if it is ok! Some might look like a virus when it is a legitimate program!

Steps Overview
  1. Open the Run Menu (Windows Key & R or through the start menu)
  2. Type in "msconfig" and hit run
  3. Click on Start-Up Tab
  4. Disable programs that look suspicious
  5. Reboot to see if it fixes your problem
  6. If it does, then go to the location, delete the startup, or delete the file
  7. There you go, it should now not start up with the computer

After successfully stopping it from running on start-up, see if it made a difference! If it did, it might have been a virus, but it also might be a program that is normal, but just hogs the computers power.

Take Note
* Folders sometimes will show up as PROGRA~1 This is ok. In Windows, when using some command prompts you only use the first 6 letters, and the ~1 at the end to say there is more to that folder.
* Look for program names or values that have random letters and/or Numbers. This is one technique Hackers use to make AV's not detect the virus!
* Some viruses have the ability to replace Registry values if you delete them! These are a little harder to stop. I will add another section later on on how to try to fight these!

Well, I hope this is good for now. Spent an hour typing it. I am going to cut this off for now, but I will add more to this thread tomorrow when I can think!! I think this is a good enough post to make on the topic. I am trying to break it up so it is easier to read because I am sure I would use to many pictures to explain each step I make!
Let me know what you think!


RE: So you think you might be infected - TesterOfTest - 07-12-2013

Scans

This is usually the second thing I do. Anything that has a scanner, I use! This includes programs like antiviruses to scans for cookies to delete. There are many different AV's out there, so picking the ones right for you is really up to you, but I use the following:
  • Avast (Proactive)
  • MalwareBytes (Proactive)
  • SpyBot Search and Destroy
  • Microsoft Security Essentials
  • And I highly recomend Comodo Firewall (Not exactly an AV but great program)
Now, I labeled the ones I use the proactive with. The reason I did was because running to many AV's at one time will slow the computer down to the point of no use because each of them will want to scan the file, and if you have 4 programs all trying to scan 1 file at the same time, it will slow you down.

First Step:
First thing I do, is go to My Computer Properties and turn off System Restore. Why do this? Well there are a few viruses that can manage to get into it, and if you ever try to restore it might pop back up, and also there is one virus that can restore itself from there! By turning it off, all restore points should be removed.
  1. Right click My Computer
  2. Properties
  3. System Restore
  4. Turn off System Restore
And remember that you need to turn it back on at some point!!

Second step:
Start scanning. I like to start with the scans that I know take the shortest time. This just might speed it up. Start your scan and after it is finished, remove/quarantine everything that pops up (Unless it is system files! Viruses like Win32.Sality will inject the virus into every EXE file causing the AV to delete it! There are others like this!) If it ask you to reboot, DO IT RIGHT THEN AND THERE! This is because you do not want to give the virus a chance to reinfect!

Once rebooted I start scanning with my other scanners. Rebooting if it ask me to.

Third Step:
Here is my favorite, Manual searching! This one is a little advance, and if done wrong, you can lose some files or possibly damage your PC! AV's are not 100% safe! Everything you do to keep the computer clean of viruses are just deterrents, to slow the hackers down, but they still can get a virus on it that NO AV can detect. These viruses are known to hackers as FUD (Fully UnDetected), or UD (UnDetected) if only a few AV's detect the virus.
Because the virus might be FUD, I like to do some manual searching. If the virus is a good one, finding it manual will not work, but for viruses done by new hackers, this works well.

Here is what to do first:
  1. Open Windows Explorer (My Computer)
  2. Go to Tools > File Options > Click the "View" Tab
  3. Make sure the following are set the way I say:
    • Show hidden Files and Folders - Checked
    • Hide Extentions of Known File Types - Unchecked
    • Hide Protected Operating System Files - Unchecked
  4. Look in the common areas for viruses (Listed below!)

These are a few areas I find that most viruses use to store the virus. There are more, but these seem the most common. Look for program files that have random names. Some might be normal, if you want me to check them, let me know! Random Character program names are one technique used to hide from antiviruses! If you find one you want to remove, delete it. If it blocks you, it might be because it is running, you will need to stop it from Task Manager.
Common Areas to check:
  • AppData folder - In Run menu type "%APPDATA%"
  • My Documents, My Pictures, My Music
  • Temp folder - In Run type "%TEMP%"


Take Note:
* One tip on this that can speed up this step drastically, is using a program to delete the cookies, and temp files! I currently use CleanUp! because it lets you know how much was removed, and you can change what it deletes.By deleting these files you remove hundreds of files that now the AV does not need to check! Speeding up scan time!
* Some viruses have the ability to not be killed so easily by the past 2 methods. These viruses have some type of persistence setting so that the virus will keep reinstalling if it is uninstalled. If this happens, look for the post with the title "Programs"!
* Some viruses also have the ability to block AV's from running, being installed, or having the site visited. If this is happening, you might need to look at the section "Safe Mode" to try to get an Antivirus to run.

Well, I think I covered everything for this section. I might have left out a part or two, but I do not want to put in to much in one post!