Donate To The Empire:
I previously wrote a guide for End Users that gave a relatively simple and straight forward way to clean their PCs. This is a guide for professionals who have more experience and can delve into some of the more intricate details of their client systems.
Most people have their personal favorite Anti-Virus and Anti-Spyware tools, but by now you all know that I recommend AVG-Antivirus and SuperAntiSpyware, I also recommend AVG-Antirootkit. These tools are relatively simple to use and the only tip I’ll offer to other pros is to make sure you run AVG-Antirootkit before either of the other two.
The tools I’m going to talk about in this article are HiJackThis 2.0, Process Explorer, Killbox, and CCleaner. We’re also going to examine a few tools for specific malware removal like FixVundo and ComboFix.
I’ve developed a procedure that generally takes two hours on a given machine. At my rates that usually costs my client $160 which is about $90 less than most of the places in my area that offer this service. I have a machine specifically dedicated to System Cleaning that has all of the tools I use installed on it already. I have a USB thumb drive that has HiJackThis, ProcessExplorer and KillBox on it. My procedure is as follows:
You may have to get creative with steps 15-17 in the way that you suspend and kill processes in order to get KillBox to delete them. You may also have to use the DeleteOnReboot option on some of the files. I’ve had rogue DLLs attach themselves to the Lsass.exe process, when you kill that process you have 60 seconds to do whatever you can do before the system automatically shuts down. When you have to get killbox to delete 8-10 files in that 60 second window or they all regenerate after the reboot it starts to feel like defusing a bomb.
When you are using HiJackThis you do have to be very cautious. It takes some experience to interpret the log file it generates, but after a while of using Hijackthis.de to analyze the files for you you will start to recognize bad entries on your own.
Combofix is the same way and I don’t currently know of an automatic analyzer for it, but there is a great guide for it over here. I recommend posting the ComboFix logs at ComputerHope for analysis until you start to get a feel for the log entries.
With this procedure you should be able to streamline your spyware removal process, undercut your competitors (And your local Best Buy) and make more of your clients happier faster. So how about using some of those increased profits to
.[...] Read the rest of this great post here [...]