Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

Shecky Tweets for 2009-11-06

November 6, 2009 By Michael Kavka Leave a Comment

  • Critical Windows Security Bulletins on Tap for Patch Tuesday – http://shar.es/aATvM #
  • Gumblar malware's home domain is active again – http://shar.es/aATAT #
  • RT@threatpost: Critical Flaw in BlackBerry Desktop Manager Software | #
  • Does free antivirus offer a false feeling of security? http://blogs.zdnet.com/security/?p=3733 #

Powered by Twitter Tools

Filed Under: General Tagged With: General Thoughts, Tweets

Malware Cleaning tricks

November 6, 2009 By Michael Kavka Leave a Comment

So, its been one of those weeks for me. I have had 3 machines so far infected with various malware. I would love to find some of these people who get of on writing malware and just stick a nuclear warhead in their pants and detonate it, but that isn’t happening. So being the IT person I am, I run into the infamous clean or rebuild scenario.

Of course rebuilding the machine is the best answer overall, mostly because you know that you have a clean machine when you are done. The problem is that a good portion of the time your clients have too much on the machine, software they no longer have the install media for, and of course have nothing backed up.

So we, as IT people, let out a big sigh and try to see what we can do. We get out our tool kit which in my case includes:

SuperAntiSpyware

Malwarebytes

Combofix

The problem is that all of a sudden you can’t seem to get the last little bits and pieces out of the system. There a files that just won’t delete and registry entries that just keep coming back. Of course this is by the malware’s design as it loads the one or two files up upon startup, even in safe mode, and that one file becomes locked by the system. That same file keeps putting the registry entries back in. So what is a poor technician to do?

Well, if you are lucky enough to have a copy of ERD 2003 or something similar, there is hope. ERD (which I have had for years) doesn’t load any of the windows files, nor the registry. Plus it has a registry editor in it. Now deleting the malicious files is as simple as knowing where they are hiding. Removing the registry entries is pretty easy also.

Yet there is one last trick. See while we all know about HKLMSoftwareMicrosoftWindowsCurrent VersionRun and cleaning that, make sure you do two more things. One is use the find feature to search for the filenames of the malware listed in the run key. Also go to HKLMSoftwareMicrosoftWindows NTCurrent VersionWindows and see if there is an appinit key with values in it. If there is, open the key and remove anything in it. It should be blank. This one little spot is where it loads the crap into the Windows/explorer shell.

Now boot back into Windows and re-run the programs listed above. Odds are that you will get rid of just about any and all infections this way. Also you can do the ERD trick first, especially if you can’t seem to run any Anti-malware software on the machine. It works wonders.

Filed Under: Computers, General, Security

Shecky Tweets for 2009-11-05

November 5, 2009 By Michael Kavka Leave a Comment

  • Windows 7 UAC Is Ineffective Security Solution for Malware, Sophos Says – http://shar.es/aAyjC #
  • RT@threatpost: SSL Flaw Has Researchers Hustling to Fix | #
  • House Panel Approves Cybersecurity Awareness Act – http://shar.es/aAIF8 #

Powered by Twitter Tools

Filed Under: General Tagged With: General Thoughts, Tweets

  • « Previous Page
  • 1
  • …
  • 190
  • 191
  • 192
  • 193
  • 194
  • …
  • 248
  • Next Page »

RSS Taggart Institute Intel Feed

  • Shaq's new ride gets jaq'ed in haq attaq October 26, 2025 Brandon Vigliarolo
  • The Kavanaugh stop, 50 days later October 26, 2025 Chris Geidner
  • Kaitai Struct WebIDE, (Sun, Oct 26th) October 26, 2025
  • [REVIVE-SA-2025-002] Revive Adserver Vulnerability October 26, 2025
  • [REVIVE-SA-2025-001] Revive Adserver Vulnerability October 26, 2025
  • New CoPhish attack steals OAuth tokens via Copilot Studio agents October 25, 2025 Bill Toulas
  • What Really Doomed Napoleon’s Army? Scientists Find New Clues in DNA October 25, 2025 Becky Ferreira
  • MPs urge government to stop Britain's phone theft wave through tech October 25, 2025 Lindsay Clark
  • Beyond good ol’ Run key, Part 153 October 25, 2025 adam
  • Cloud Discovery With AzureHound October 24, 2025 Margaret Kelley

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP