Penewab2007:Are you using a security app or a manual? One thing I could get better at, is manual hunt and deletes, but that is time consuming.
Both. The only really killers out there are Root Kits. I've read about some that will flash the BIOS and render the PC un cleanable even if formatted.....but I've never actually encountered one of these. I use the gmer root-kit detector. Once ID'd it can be tracked-down and removed with the Live CD. RAIDs are a problem though. don't have a raid driver on a live cd yet.
I use a live CD to take a quick peek a the registry remotely [there are about 5 places you can quickly peek-at and dis-able nastys,] so that when I boot into "safe mode with networking" I don't need to worry about fighting for control of the system, just load the scan tools and drive-on.
Tallon41
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
ensure AppInit_DLLs is blank....google anything found here, though I've yet to find a legitimate entry.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
check the path to c:\windows\system32\userinit.exe (and that there are no ADDITIONAL listed exe files.)
check that UIHost is logonui.exe
check that System key is blank, google anything found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\notify
look for any key listed not found in google, (or ID'd in google as Malware.)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run
export the key, then google everything and delete as needed.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run
same as above
Then inspect
c:\
c:\windows
c:\windows\system32
c:\windows\system32\drivers [I usually just check here, run CCleaner and let the cleaning tools find the rest ]
reverse date sort by "date created" must add that column first. see what c**p floats to the top. the drivers folder is where most rootkits like to put files.
run CCleaner on all the temp files from a portable drive on . Files deleted in the live CD do not go to the recycle bin.
like anything else you get to know what SHOULD be there and what should not, so it does not take much time for me to do this.
What weight does your Spirit have to be in order to be considered "heavy" ?
----------------------Me