I am fighting with a friend from work’s personal computer and have removed many virus/malware/etc off of it so far. Something is still a little fucked with it, but I made some good progress. I’ve learned of a few handy little freeware programs in the process and I thought I’d share.
First off is Advanced Process Manipulation, a lightweight program that acts as a more advanced version of task manager. You can see all the running processes and also what DLLs they are using (and therefore protecting). You can end the whole process or just unload certain DLLs on each process. Pretty handy for finding what files a process is tying up.
Next we have the Locked Files Wizard, which is another small program that is incredibly handy. It allows you to pick protected Windows files and rename, delete, move, and replace them. The only really handy (and best way not to fuck up your copy of windows) use for this is to replace corrupt/infected system files with a copy of good files off another computer. I thought she had some infected system files, namely comctl32.dll, so I replaced the file with this program.
I discovered a couple free anti virus programs that made AVG look like crap (admittedly not difficult). Avira seems to have positive reviews, so I tried that out and it was not bad. ClamWin Portable was also quite handy. It can be installed and updated to a single folder and is easily copied to a flash drive and can be ran from there on another computer. Of course, Spybot is always a great help too.
There is a nice little guide here that gives methods for removing protected files, and links to many more utilities like above. So, if what I’ve listed above doesn’t work for you check it out.
If you have any more suggestions for nice freeware utilities/software, or helpful suggestions for when “just rebuild it” isn’t the best option, feel free to comment and add your thoughts.