Anti-malware software - what does it really do?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JJR87, Mar 7, 2011.

  1. JJR87

    JJR87 Private E-2

    Hello,

    Does anyone know exactly how an anti-malware program removes trojans and viruses?

    I was having a problem with the Google Redirect trojan and researched how to get rid of it including renaming MalwareBytes .exe file, going into Safemode, as well as searching in the Non plug-n-play directory of devmgmt.msc (Device Manager) but couldn't find threats or the device entry "TDSSserv.sys" or any of its aliases e.g. seneka, etc.

    After running through these methods several time to no avail, I opened up the registry editor and ran a search for "tdss" and found within a file named url3 a binary string that included "t.d.s.s" and deleted it.
    Seemed to work fine after that but I can't be sure if it's completely gone.

    Can anyone knowledgeable explain/describe to me what the anti-malware software actually does?

    Thanks!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    AV and AS software looks for the following based upon definitions built into the programs. Which is why you need to keep them updated:

    If you think you still are having malware issues, please do the following:

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. JJR87

    JJR87 Private E-2

    Thanks Tim. Looks like a good read.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In addition to the R&R instructions, since you said you found a TDSS type of infection, you can run this:

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  5. JJR87

    JJR87 Private E-2

    TDSS killer log file attached. No infection was found, but I still seem to be having the redirection issue. Please advise! Thanks.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the rest of the requested logs from doing the Read and Run First instructions:
    SAS
    MBAM
    RootRepeal -- If it runs.
    ComboFix
    C:\MGLogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds