What to do after dissinfection?

papajo_r

New Member
Thread author
Jun 9, 2015
2
Ok maybe this is a stupid question but I lost my confidence so I ask you guyz...

well my computer had some adware maybe some spyware as well (it wasnt broke or anything but surely it should have some silent background stuff, since the cpu was used more than it should and had some laggy response once in a while ) so I installed Bidefender total security 2015 I updated it and nothing (i think it would like 2-3 "viruses" of which 2 were like 2 crack.exes that i am sure they are safe) so i installed it on an already infected system as you can tell by now.

But things have gotten worse after a few months of the said installation (and I tuned BD to aggressive in any given setting and had autopilot off to check every notification etc yet i didnt had anything... ) it gotten to a point were some strange stuff has happened to BD itself (like asking my for password 2 times on a single setting change were it should only ask me once not start up with windows at random days and needing me to manually start it and for some days failing to update for quite a few times) then also firefox began to be even more slopier in the point of freezing and freezing windows

like for the first minutes (or forever if i didnt try to open anything new) already opened tasks working just fine like word or vlc for example but anything else like explorer.exe itself shutting down not even ctrl+shift+esc or ctr+alt+delete working though as i said alt+tab and already opened apps worked fine just couldt open new ones.. and then after that everything freezing and me needing hard shutdown(clicking on the power button) to close and start again the pc.

Then i decided to do some tunning I used repair software from tweaking.com downloaded malwarebytes anti-malware, malwarebytes anti-exploit, spybot search and destroy,adw cleaner. and did scans etc on safe mode (I have windows 8.1 btw) allong with some rootkit scanners and other stuff and those scans yielded a few potential viruses and malware/spyware (also when spybod worked all the sudden bitdefender woke up from it sleep and started spoting threats on its own.. like all the previous time it assured me that my pc was clean and it needed spybot to search files in order to for it-BD- to make it self usefull again)

and things just seemed to go fine except one thing... when the computer is idle for no reason windows diskcleaner pops up... but if i try to push a button from my keyboard or to hover my mouse it dissapears...

Couldnt find a way to stop it so i supposed its a adware/malware of some sort (my pc works fine now its speedy as if it was on a clean install and just has this issue) anyway I decided to run the eset online scanner and as of now it found 20 threats! (while all the other software didnt find anything as a threat)

from all the above I suspect that all the previous programs didnt work or didnt work at full extend because they got installed while the pc was already infected.

so my question is this :(yea i know too much details but i think you should be aware of them in order to answer my question :) )

suppose that eset did the trick and removes the final remaining viruses/malware on my pc and its 100% clean now

should I remove all the above software (Bidefender total security 2015, malwarebytes anti-malware, malwarebytes anti-exploit, spybot search and destroy,adw cleaner.) and reinstall it now that my computer is clean?

I mean since -if my assumption is correct- they couldnt find all the threats because malware that was already isntalled somehow hinder their scannign abilities (like by altering registry or whatever) now if all that said malware is removed would the programs work find as if in a clean installation detecting everything as they should without problems? or will they keep be problematic and thus need reinstalling?
 
D

Deleted member 178

if you don't have lot of work files on your system , reformat and reinstall ; then you will be sure that everything is clean. then install right away a security soft. Sybot is useless, you don't need it.

my advice is surely hash but , a reinstall takes you 1hour max , finding & cleaning an hypothetic malware may takes days.
 

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
What I do after disinfection:

Clean all Temps
Flush all System Restore Points and create a new registry backup.
Ask customer for payment
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
A such protocol where even there's a leftovers then a manual deleting those junk files is required however that depends on severity of infection, tools may not guaranteed a successful operation therefore a clean install should be proper enforce.

Some viruses/malware are nasty where replicates itself to detect all over again by scanners.
 

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
A such protocol where even there's a leftovers then a manual deleting those junk files is required however that depends on severity of infection, tools may not guaranteed a successful operation therefore a clean install should be proper enforce.

Some viruses/malware are nasty where replicates itself to detect all over again by scanners.

There are more than one way to skin a cat

  • Cleaning all temps, either manual (better option if you know where to look) or automatic. If you can get rid of Gigs of temps, scanning time would be drastically reduced.
  • Offline registry editing to disable startup entries of hard to remove nasty malwares
  • A boot scan (Avast!) can be performed to get rid of other leftover files
  • or booting from a Live CD/DVD or USB drive and doing a scan with an updated AV (Portable Avira)
  • using MBAM for malware removal after an AV scan
  • For patching malwares (e.g. virut, sality) SFC can be used to replace damaged Windows files
  • Other applications can be reinstalled
I do malware removal in Normal mode but you too can do it in Safe Mode with Networking (Try MBAM Chameleon)

I'm don't rely too much with online scanners because most PCs I repair don't have net.
For not so severe infection, it's faster to disinfect compared to a reinstall (based on my experience)
 
Last edited:

papajo_r

New Member
Thread author
Jun 9, 2015
2
Thank you guys for your responses, but that was not my question

In my question we suppose that the sytem now after my procedures is totally dissinfected (and we dont care about the possibility this being untrue)

I am asking about the protecting software such as bitdefender.

Because I think that (if most of is not a hoax and programs like bitdefender total security 2015 actually are worth having installed in your pc) their efficiency may have been compromised due to being installed in an already hostile enviroment (with viruses/malware already being active on the computer)

So my question is that after 100% dissinfecting the computer will those programs work as they should and be 100% efficient (for example in any online review i see that BD gets the 1st place with the most detections etc) or will they keep malfunctioning and thus I have to uninstall and reinstall them ?

more short version of the question: while system was infected antimalware/antivirus software detected almost nothing and their protection was limited after dissinfecting the stystem will the antivirus/antimalware software perform normally and starting to detect future threats (which previously didnt due to the hostile enviroment it had when it was installed) ?
 

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
Because I think that (if most of is not a hoax and programs like bitdefender total security 2015 actually are worth having installed in your pc) their efficiency may have been compromised due to being installed in an already hostile enviroment (with viruses/malware already being active on the computer)

First, as much as possible, I don't install an AV on an infected system. I disable the malware first so I can install my AV of choice and do a scan without resistance. It's like using FRST (or something similar) to analyze what's in the system first before doing the disinfection. You may start with installing BD and doing the scan but for clarification, I do a different thing like killing the malware first running in memory or disabling it from starting up with Windows then doing the scan when all is clean.


So my question is that after 100% dissinfecting the computer will those programs work as they should and be 100% efficient (for example in any online review i see that BD gets the 1st place with the most detections etc) or will they keep malfunctioning and thus I have to uninstall and reinstall them ?

If PC is clean and all infected files are deleted or replaced (either via SFC or re-installation of the infected app, AV included) and the registry had been repaired, i.e. the effect/damage done by the malware had been reversed, then Windows should work fine.


more short version of the question: while system was infected antimalware/antivirus software detected almost nothing and their protection was limited after dissinfecting the stystem will the antivirus/antimalware software perform normally and starting to detect future threats (which previously didnt due to the hostile enviroment it had when it was installed) ?

Of course, sometimes, it's hard for an antivirus or antimalware to detect active malwares (infections) that's why there are other approaches of dis-infections like

  • Doing a Boot Scan
  • Using a Boot CD/DVD/USB to perform the scan
  • Scanning in Safe Mode
But the best way is using the path of less resistance. Kill the malware first, scan later.
 

tonibalas

Level 40
Verified
Honorary Member
Top Poster
Well-known
Sep 26, 2014
2,973
I am not an expert but from what i have learned here i can tell you a few things.
If system is infected try installing malware scanners like Malwarebytes AntiMalware, HitmanPro, Zemana Anti-Malware, Norton Power Eraser.
This scanners can do a better and more a deep scan than the AV's and so they can find more malware on your system.
The other thing i want to suggest is to install a back up software like Aomei or Macrium Reflect as my friend @frogboy is suggesting always
to avoid doing a format.
I hope i have helped;)
 
  • Like
Reactions: frogboy and JM Safe

Cch123

Level 7
Verified
May 6, 2014
335
What were you infected by? If its a threat that isn't known to attack AV and is not a file infector, there should be no problems for your AV. However, I think the best and safest option for you now is to completely uninstall bitdefender and reinstall again.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
As much as possible if Bitdefender fail to protect the system from heavy infections then start all over again (when cleaning process is totally done) and choose another AV alternatives or a maintainance security tool like Voodoshield + Anti-Executable for whitelisting/blacklisting which needs a training eye to analyze.
 
  • Like
Reactions: JM Safe
D

Deleted member 178

why bothering adding a AV on hostile system...

first, infected may still be crippled already even if they are cleaned. nothing can verify all the sub-system files.
second, how can you trust an infected even cleaned OS (as if your girlfriend cheated you and you say "ok now that she made excuses, no problem , nothing happened...).

i am always a big supporter of the full reformat and reinstall. the only case , i didnt reformat is that the owner has no Windows license (bought or OEM) or has some program/files/datas they can't afford to loose .
 
  • Like
Reactions: tonibalas

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
i am always a big supporter of the full reformat and reinstall. the only case , i didnt reformat is that the owner has no Windows license (bought or OEM) or has some program/files/datas they can't afford to loose .

Yes and that's why the first step for all users to know which is, conduct a snapshot from a software like Rollback RX from the beginning then keep it to restore any problems. ;)
 
  • Like
Reactions: frogboy and JM Safe

Atlas147

Level 30
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 28, 2014
1,990
A friend of mine is having the same issues, she has malware on her system and I can't seem to get rid of it. She's probably gonna reformat her system to clear it
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
hey James , how RX performs now, before it screwed my system.

Since I'm using it before on VM so I cannot tell exactly what behavior performs in real system. For only testing purpose on malware analysis.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top