Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
coinstarpatrick
May 21, 2007

by T. Finn
Nthing superantispyware.
It seems to be a few days in front of Malwarebytes now consistently, but MWBAM is still a vital tool. Between those two you can pretty much get anything.

A few posts up where it was suggested to run a livecd... is there a way to run SuperAS or MWB off a livecd? That would be unbelievable.

Adbot
ADBOT LOVES YOU

coinstarpatrick
May 21, 2007

by T. Finn
Edit:It sounds stupid to me, but is it possible using wine or something?

(clicked quote instead of edit like an idiot)

coinstarpatrick
May 21, 2007

by T. Finn
I don't know if this has been mentioned in this thread..but just in case.

In WinXP combofix was the poo poo, it would basically always run, malware generally didn't stop it. Run combofix, then run malwarebytes.

In the win7 world where we are left without combofix my only savior has been Kaspersky Rescue Disk. They release it free and it is a linux boot disk with networking (updates itself). I've actually been using it for everything to save myself time, it doesn't catch everything but it has always cleaned up enough that I can run MWB.

coinstarpatrick
May 21, 2007

by T. Finn
In all my reading in this thread I've never seen anyone mention Rkill (I thought it was pretty well known?). This is a life saver when you are dealing with tricky malware. It kills malware processes instantly.

http://www.bleepingcomputer.com/forums/topic308364.html

Basically run it before you run MWB and SAS to insure they will run without issue, I've had great success with it.

coinstarpatrick
May 21, 2007

by T. Finn

RichieWolk posted:

I keep a folder on my desktop with all my programs for my USB drive in it, and whenever I go out to work, I just wipe a stick and copy the contents over. I'll probably start using that ketarin program to keep the big ones updated.

My USB drive contains:

-generic hex editor
-Norton Removal Tool
-port scanner (superscan, because it's familiar to me)
-Malwarebyte's Anti-Malware installer
-Spybot Search&Destroy installer and includes
-Spywareblaster installer
-Combofix
-.NET Version detector
-GMER
-HijackThis
-Hitman Pro
-LSPfix.exe from cexx.org
-process explorer
-rkill
-Scanner
-TDSSKiller
-Rootkit unhooker
-various fixes for vundo, virut, smitfraud, etc.
-other random tweaks, like registry settings to restore .exe function, or stuff like that

So far it's caught almost everything I've come across.

Add the portable version of Superantispyware. It comes in handy and is kept up to date. The scan is a lot quicker than a MWB scan, MWB can be extremely slow if you are on site (especially on a highly infected sloth box).

coinstarpatrick
May 21, 2007

by T. Finn

bbcisdabomb posted:

You're saying Malwarebytes is slow and recomending Superantispyware :stare:

SAS is the second loving slowest AV I've used behind ClamAV. I use SAS because it gets drat near everything, but I use Malwarebytes when I'm with customers because it's so much faster.

Maybe the install version runs faster, but god drat does the portable version drag.

Funny, I just ran a quick scan of both.. SAS: 16:29 MWB: 1:32 (perfect conditions on a fast machine). I've definitely been in situations were MWB's really drags though. Another consideration: AFAIK SAS is designed to be run in safe mode and Malwarebytes isn't.

VVV Not sure but I think that's from the developers. VVV

-Some MWB staff member "This goes into areas where I cant say much without giving away the internal workings but MBAM is stronger from regular mode . This is by design as the majority of new malware runs from safemode so you gain nothing anyway . There are also multiple infections that as part of their first step blow away the entire safeboot keyset so we do not rely on it being there . "

coinstarpatrick fucked around with this message at 04:15 on May 17, 2011

coinstarpatrick
May 21, 2007

by T. Finn

Pope Guilty posted:

Well, other than being able to run MBAM at all since most competent malware authors refuse to let you run programs other than the malware in regular mode.

If you run Rkill first you will almost always be able to run MBAM right then and there from regular mode.

Adbot
ADBOT LOVES YOU

coinstarpatrick
May 21, 2007

by T. Finn

Crossbar posted:

Microsoft has a bootable malware remover now. Anyone checked it out?

http://connect.microsoft.com/systemsweeper

I'm running it on a client's (seemingly) rootkitted Vista machine now, I'll update the post with the results. The installation was great, it formats and installs on a flashdrive automatically with the latest definitions. However it seems that to keep an updated stick with this software you would have to let it reformat and reinstall on the drive (maybe the final version will have a better option).

Edit: Scan took about 1:30, despite selecting a partition upon boot it scans all the partitions and drives by default. It found a java exploit that MBAM and SAS didn't find so I am optimistic about this program.

coinstarpatrick fucked around with this message at 20:08 on Jun 1, 2011

  • Locked thread