Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Malware Cleaning tricks

Posted on November 6, 2009May 17, 2011 By Michael Kavka No Comments on Malware Cleaning tricks

So, its been one of those weeks for me. I have had 3 machines so far infected with various malware. I would love to find some of these people who get of on writing malware and just stick a nuclear warhead in their pants and detonate it, but that isn’t happening. So being the IT person I am, I run into the infamous clean or rebuild scenario.

Of course rebuilding the machine is the best answer overall, mostly because you know that you have a clean machine when you are done. The problem is that a good portion of the time your clients have too much on the machine, software they no longer have the install media for, and of course have nothing backed up.

So we, as IT people, let out a big sigh and try to see what we can do. We get out our tool kit which in my case includes:

SuperAntiSpyware

Malwarebytes

Combofix

The problem is that all of a sudden you can’t seem to get the last little bits and pieces out of the system. There a files that just won’t delete and registry entries that just keep coming back. Of course this is by the malware’s design as it loads the one or two files up upon startup, even in safe mode, and that one file becomes locked by the system. That same file keeps putting the registry entries back in. So what is a poor technician to do?

Well, if you are lucky enough to have a copy of ERD 2003 or something similar, there is hope. ERD (which I have had for years) doesn’t load any of the windows files, nor the registry. Plus it has a registry editor in it. Now deleting the malicious files is as simple as knowing where they are hiding. Removing the registry entries is pretty easy also.

Yet there is one last trick. See while we all know about HKLMSoftwareMicrosoftWindowsCurrent VersionRun and cleaning that, make sure you do two more things. One is use the find feature to search for the filenames of the malware listed in the run key. Also go to HKLMSoftwareMicrosoftWindows NTCurrent VersionWindows and see if there is an appinit key with values in it. If there is, open the key and remove anything in it. It should be blank. This one little spot is where it loads the crap into the Windows/explorer shell.

Now boot back into Windows and re-run the programs listed above. Odds are that you will get rid of just about any and all infections this way. Also you can do the ERD trick first, especially if you can’t seem to run any Anti-malware software on the machine. It works wonders.

Computers, General, Security

Post navigation

Previous Post: Shecky Tweets for 2009-11-05
Next Post: Shecky Tweets for 2009-11-06

Related Posts

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • Defender, KQL and Lockbit Microsoft
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
New Year, New Post, from the start General
Defender, KQL and Lockbit Microsoft
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware September 15, 2026
  • Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems September 12, 2026 djohnson
  • Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal September 11, 2026 Tim Starks
  • Hackers abused Claude to extract secrets from 1.8M Android apps September 11, 2026 Bill Toulas
  • Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device September 11, 2026
  • CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration September 11, 2026 aws@amazon.com
  • Florida confirms DMV database breached via stolen police account September 11, 2026 Lawrence Abrams
  • GitLab’s critical flaw is already drawing internet-wide probes September 11, 2026 Greg Otto
  • Microsoft sees some new wrinkles in invoice-scam emails September 11, 2026
  • More JFrog Artifactory bugs under attack, and all 3 have patches September 11, 2026
  • Passkey-themed phishing attacks lead to Microsoft 365 data theft September 11, 2026 Lawrence Abrams
  • CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2 September 11, 2026 aws@amazon.com

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware September 15, 2026
  • Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems September 12, 2026 djohnson
  • Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal September 11, 2026 Tim Starks
  • Hackers abused Claude to extract secrets from 1.8M Android apps September 11, 2026 Bill Toulas
  • Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device September 11, 2026
  • CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration September 11, 2026 aws@amazon.com
  • Florida confirms DMV database breached via stolen police account September 11, 2026 Lawrence Abrams
  • GitLab’s critical flaw is already drawing internet-wide probes September 11, 2026 Greg Otto
  • Microsoft sees some new wrinkles in invoice-scam emails September 11, 2026
  • More JFrog Artifactory bugs under attack, and all 3 have patches September 11, 2026
  • Passkey-themed phishing attacks lead to Microsoft 365 data theft September 11, 2026 Lawrence Abrams
  • CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2 September 11, 2026 aws@amazon.com
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.