sMobile ? "width=device-width,initial-scale=1.0,minimum-scale=1.0,maximum-scale=1.0" : "width=1100"' name='viewport'/> android xda: Security
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, 2 June 2016

LG security error fix f160

First download Firmware related to your model HERE
Download KDZ and Drivers HERE
open kdz select downloaded firmware click normal flash
Put phone in download mode by pressing vol up home and power key
or turn off phone press vol up and vol down and plug cable

Now press START and RUN
Select Country and Language / Optional Clear Registry
Hit OK and just wait* (*don't close the program)
Phone will restart in Firmware Update and flash itself
best of luck no data lose just update firmware file which are broken during root or etc...

Wednesday, 20 August 2014

Pebble SmartWatch DoSed through message bomb method, does a factory reset and loses all user data

If you have read this article you may be knowing about Pebble SmartWatch.  Pebble smartwatch has been developed by Pebble Technology Corporation and was released in September, 2013. Pebble smartwatch which ran on Android operating system was a instant success and PTC has sold over 1 million units of all versions of Pebble smartwatch as of July this year.  However Pebble is vulnerable to a DoS (Denial of Service) attack through message bombing.  The Proof of Concept for this DoSing was published Hemanth Joseph of White Hat Pages today.

Pebble SmartWatch DoSed through message bomb method, does a factory reset and loses all user data


As per Hemanth, he tested the Pebble smartwatch with firmware version 2.4.1 aboard it.  As published on his blog he,

1.    Connected  Pebble smartwatch to Sony Z2 smart phone
2.    Tested notification.
3.    Did a message bombing to through his own WhatsApp Account        through 1500 messages in 5 secs.

What he got was a garbled screen and a automatic factory reset. The auto reset caused him to lose all his data on the smart watch. Carrying the PoC a bit further, he message bombed it with 300 WhatsApp Messages in 5 secs and as expected the result was same. After testing various times he found out that during some of testing though the screen got garbled, the Pebble smartwatch didnt go for a auto factory reset.  He has noted that, to bring the bricked Pebble back to normal working, he had to reset it thereby losing all the saved data.  This is what his Pebble smartwatch looked like after the DoS testing.
Pebble SmartWatch DoSed through message bomb method, does a factory reset and loses all user data

As per the PoC given by him, any attacker who wished to DoS any Pebble smartwatch has to just get the potential victims Mobile number or Facebook id.  Once the attacker gets any of these, he can message bomb your Pebble smartwatch to death (reset). The smartwatch it seems is unable to handle large amounts of message transfers in limited time and has a auto reset mechanism which PTC should look into. 

Friday, 1 August 2014

Hackers can control your smart phones with tools already built in according to wired.com

In this day and age of surveillance everywhere from your traffic signal to your lobby and now thanks to NSA's snooping on your personal communications with your near and dear ones, a article in Wired has made matters worse.  Wired article says that the built in tools or embedded software as its technically called,  in the smart phone offer unrestricted access to the the carrier, and of course a potential hacker. A study by Mathew Solnik and Marc Blanchou, two research consultants with Accuvant Labs took just a few months to discover the vulnerabilities and exploit them. It goes on to say that almost all smart phone that the researchers examined would allows a potential hacker to change all its cellular network functionality and in many cases, they could also control firmware updates.

Hackers can control your smart phones with tools already built in according to wired.com
HTC One M7 one of the easiest phone to compromise

All this was discovered by two researchers who have uncovered such built-in vulnerabilities in a large number of smartphones that would allow government spies and sophisticated hackers to install malicious code and take control of the device.  As per the article the  attacks would require proximity to the phones, using a rogue base station or femtocell and a high level of skill to pull off.  A Femtocell is a low power cellular base station usually set up by service providers for small offices/businesses or to pitch in if there is a network black out. 

The two researches say that the vulnerabilities lie within a device management tool carriers and manufacturers embed in handsets and tablets to remotely configure them. Though some design their own tool, most use a tool developed by a specific third-party vendor—which the researchers will not identify until they present their findings next week at the Black Hat security conference in Las Vegas.  The tool is used in some form in more than 2 billion phones worldwide. The vulnerabilities, they say, were found so far in Android and BlackBerry devices and a small number of Apple iPhones used by Sprint customers. 

Two phones that provided the highest level of exploitation were the HTC One M7 and the Blackberry Z10. Among iOS devices, they found that only iPhones offered by Sprint and running an operating system prior to version 7.0.4 were vulnerable. The 7.0.4 version of the software, which Apple released in November, partially solved the issue.

You can read the full story here

Thursday, 31 July 2014

BitTorrent introduces new 'Bleep' decentralized online Instant Messenger for secure peer to peer communication

BitTorrent the most popular torrent client and the company that develops the  peer-to-peer protocol and two popular clients that use it, has announced the release of Bleep, an online communication (voice and text) application that lets users "make a direct, decentralized connection to someone they trust." 

BitTorrent introduces new 'Bleep' decentralized online Instant Messenger for secure peer to peer communication


Announcing the release of Bleep, Jaehee Lee, a senior product manager at BitTorrent, says that Bleep can freely be used by journalists that want to keep their sources anonymous, diplomats looking to keep their reports private, and businesses that need to keep their communications safe from industrial spies.

What makes Bleep different is that unlike traditional messaging services, where a chat app establishes a Session Initiation Protocol (SIP) connection with a central server app, Bleep does the same with a distributed server app.

This means that there is no central central repository of metadata (storage of your conversations) as the decentralization disables any storing.   This also means that whatever you chat is just read and go. Another plus point for Bleep is that the person who wants to talk with someone must go search for them through nodes and this search is also not tracked from the server side.

"All links are encrypted .We are using secure encryption protocols such as curve25519, ed25519, salsa20, poly1305, and others. Links between nodes are encrypted. All communication is end to end encrypted," Fadaie says.

Bleep got its name from the fact that the company does not see the metadata or the contents of the exchanged messages. "As far as we’re concerned, anything you say is 'bleep' to us," noted Lee.

Bleep has been released in pre-alpha and is currently available only for Windows 7 and 8. Those who wish to test the app can sign-up here, but should be aware that there are surely glitches and bugs that have to be ironed out, or maybe you could be a bug tester yourself.

Tuesday, 15 April 2014

How to Manually Remove a Virus

computer viruses.virus, computer, security, How to Manually Remove a Virus
Our computers have a threat from different types of computer viruses. In this write-up, we will know how to make our computers free of viruses.
Computers have become an integral part of our life. Along with computers, Internet has also become an indispensable part. However, there is a negative side to the Internet technology, which is the rampant spread of computer viruses. Therefore, computer security becomes a matter of major concern for every one. Although it is recommended that we should have an antivirus software installed on our machines, there are times that we may not have it installed and that is exactly when the computer may be infested by a software. This brings up the question, what are the steps to manually remove a virus so that the machine is not infested with the threatening virus.

Steps to Remove a Virus

You will need some computer programming skills to get rid of the computer virus. You will just need the knowledge of basic syntax. The first step you should take before you start with the computer viruses removal process is to take system back up. It is essential so that in case you delete a wrong file in the process, you will not lose important data. In some cases, the file may be necessary to run the computer system. The data should ideally be backed up in an external device. Once the data has been backed up, you can format the system to get rid of the virus totally. However, it is not recommended that you use the system restore option to get rid of the virus, as this often leads to virus multiplication as opposed to removal.

The other process is a lengthy one which will need technical expertise. In this process, the first step is to identify the virus as there are many different types of computer viruses. To identify the virus you can seek help from various antivirus websites. From these websites you will be able to see the way the particular virus makes files. Now you will have to look for the behavioral pattern of the virus. Once that has been identified, the next step is to go to task manager. From the task manager stop the virus processes so that there is no chance that the virus replicates itself. The next step is to go to the file registry and delete the virus files, taking help from the information you have found from the different websites pertaining to the virus.

Steps to Manually Remove a Trojan Virus

If you do not want to use the options available online for the removal of the Trojan, you will have to undertake the process of removing the virus manually. To remove Trojan virus, you will have to first identify the system files which are infected by the virus. The next step is to erase the files so that normal functioning of the system is possible. You can seek help from online forums or antivirus software websites.

I would recommend that although there are steps one can take to remove the virus manually, it is best to invest in a reputed antivirus to avoid attacks to your system where your data is at risk.

Monday, 14 April 2014

Types of Computer Security Threats



With the wide scale use of internet, there are different types of computer threats, that the computer networks are susceptible to. Each of these threats can cause potential damage and cause a lot of harm, if the data is lost. It is important to know the different types of threats, so that the data can be safeguarded.
Computer network as well as stand alone systems are susceptible to a number of computer threats. The damage caused by the threats can cause very high loss to the company. The danger increases, when the computer network is connected to the internet. Although there are different types of threats to computer systems, they have a common bond. They are designed to trick the user and gain access to the network or the stand alone systems or destroy the data. Some of the threats are known to replicate itself, while others destroy the files on the system or some infect the files itself.

Types of Computer Security Threats

The classification of the types of information security threats is made on the way the information in the system is compromised upon. There are the passive threats and the active threats. The passive threats are very difficult to detect and equally difficult to prevent as well. Then there are the active threats. Since these threats continue to make changes to the system, they are easy to find out and fix as well.

Virus: The most common of the types of cyber threats are the viruses. They infect different files on the computer network or on the stand alone systems. Most people fall prey to the viruses, as they trick the person into taking some action, like clicking on a malicious link, downloading a malicious file, etc. It is from these links and files, that the virus is transmitted to the computer. There are also cases of the viruses been a part of an email attachment, which may be downloaded from the internet. In some cases, the viruses can also spread through infected portable data storage as well. Hence, it is important to have an antivirus on the system, which can not only detect the virus, but be able to get rid of them as well.

Worms: The other common types of internet security threats are the worms. They are actually malicious programs, which take advantage of the weaknesses in the operating system. Like the worms in real life crawl to move from one place to another, similarly the worms in the cyber world also spread from one computer to another and from one network to another. The most prominent feature of the worms is that they are able to spread at very high rates, which can lead the system being at risk of crashing. There is a type of worm, called net worm. These worms replicates itself by sending complete and independent copes of itself over a network, thereby infecting almost all the systems on the said network.

Trojan: This is a different type of computer virus, which is disguised under the garbs of a friend. The Trojans derive their name from the legend. They make their way into the software, which may not be noticed. It is often seen, that the Trojans are a part of the different attachments in emails or download links. In some cases making a visit to certain web pages also puts the computer system at risk.

Spyware: Spyware as the name suggests spy on the network and the computer system. They may be downloaded unintentionally from different websites, email messages or instant messages. In some cases, they may also make their way through different direct file sharing connection. In some cases, clicking on 'Accept User License Agreement', can also put the computer at risk.

Rootkits: The job of the rootkits is to give cover to the hackers. The best or the worst part about rootkits is that they are able to hide themselves from the antivirus software as well, due to which the user is not aware that a rootkit is present on the system. This helps the hacker and he is able to spread malware on the system. Therefore, it is important that one opts for antivirus, which also has a rootkit scanner, which will be able to detect the invasion.

Riskware: They are dangerous applications, who often become a part of software applications. They are often seen as a part of development environment for malicious programs and spread to the software applications. In some cases, these applications can also be used by hackers as additional components to gain access in the network.

Adware: The recent addition to the list of computer threats are the adware. They are actually advertising supported software. It is not uncommon to see different advertisements or pop ups coming up on the computer, when certain applications are being used. They may not pose a lot of threat, but often lower the speed of the computers. There are chances that the computer system may become unstable because of these adware.

Cookies: When we visit a website, there are files due to which the website is able to remember the details of the computer. They are more of a threat to confidentiality as opposed to the data on the computer. In most cases, cookies may be stored on the computer without the consent of the user and data may be stored on them, which is passed back to the website server the next time, one visits the website. The data gathered may be sold to third parties and depending on the interests, which may lead to different advertisements flashing on the screen.

Phishing: Often people appear to get emails from trustworthy organizations, like banks. In some cases, the emails may come from bogus sites, which may resemble the original site or it may superimposes a bogus pop up, due to which confidential data is gathered. They are often a part of different scamming activities and often poses to the financial threats.

These were the main types of computer threats. It is important to be on the look always to ensure that the network and/or standalone systems are protected from the threats. As soon as any of the threats are detected, measures will have to be taken to get rid of them at the earliest, so that the data is protected.

Sunday, 16 March 2014

Bluetooth Security

These days, all communication technology faces the issue of privacy and identity theft, with Bluetooth
being no exception.  Almost everyone knows that email services and networks require security.  What users of Bluetooth need to realize is that Bluetooth also requires security measures as well.

Bluetooth Security

The good news for Bluetooth users is that the security scares, like most scares, are normally over
dramatized and blown entirely out of proportion.  The truth being told, these issues are easy to manage, with various measures already in place to provide security for Bluetooth technology.

It's true that there has been some Bluetooth phones that have been hacked into.  Most devices that are
hacked into are normally those that don't have any type of security at all.

According to Bluetooth specialists, in order to hack into a Bluetooth device, the hacker must:

    1.  Force two paired devices to break their connection.
    2.  Steal the packets that are used to resend the pin.
    3.  Decode the pin.

Of course, the hacker must also be within range of the device, and using very expensive developer type equipment.  Most specialists recommend that you  have a longer pin, with 8 digits being recommended.

Fundamentals of security The "pairing process" is one of the most basic levels of security for Bluetooth devices.  Pairing, is two or more Bluetooth devices that recognize each other by the profiles they share - in most cases they both must enter the same pin.

The core specifications for Bluetooth use an  encryption algorithm, which is completely and entirely
secure.  Once the devices pair with each other, they too become entirely secure.

Until they have successfully paired, the Bluetooth devices won't communicate with each other.  Due to
this pairing process and the fact that it is short range - Bluetooth technology is considered to be
secure.

As the news has indicated, experienced hackers have developed ways to get around this level of
basic security.  There are ways to get around this threat, as you can install software to prevent
hackers from getting in.

With Bluetooth becoming more and more popular, it's really no wonder that security is always in
question.  As Bluetooth gets bigger and better, security will always be something that no one
really takes lightly.

If you've been concerned about Bluetooth security in the past, rest assured that newer devices will
offer bigger and better security.  Preventing  hackers from getting in is something every owner is concerned about - and the manufacturer's are very aware.


Friday, 21 February 2014

How to Clean An Infected Computer


How to Clean An Infected Computer
The truth is that it's a lot easier to keep a computer malware free than it is to clean one that is already infected. However, with the advice given in this article you should be able to remove any type of malware from your computer and get it back to working order. The main problem with most malware removal guides is that you have no way of knowing if all of the infections were removed. However, with my approach you can easily tell if even just running a single scanner was able to entirely clean the infection. Thus, this can save you the hassle of having to run many different scanners and the uncertainty of whether your computer is really malware free.

Make sure you follow this article in order so as to clean the infections with as little work as possible. The idea is that most people won't have to go any further than the first approach in order to clean their computers of active malware. Thus, effectively this article is actually much shorter than it appears to be.

However, before attempting to remove any infected files you should first back up all important files. These may include documents, pictures, videos, etc... This way if anything goes wrong with the cleaning process, which is a very real possibility, your important documents will still be intact. However, do not include any program files as it is possible that these may be infected. Please note that if your computer cannot boot you should follow the advice on this page in order to back up all important files. Also, while cleaning the computer it's important to remember that all scanners can sometimes be guilty of false positive detections. Therefore, before removing any files which you believe could possibly be safe, you should check them using the methods I discuss in How to Tell if a File is Malicious.

Index

1. Make Sure Computer Is Actually Infected
2. How To Clean Your Computer And Make Sure It's Actually Clean
    ​A) Clean Computer With CCE and TDSSKiller
    BIf Still Not Clean Then Scan With HitmanPro, Malwarebytes, And Emsisoft Anti-Malware
    C) If Needed Try These More Time Consuming Methods
    D) If Necessary Make A Bootable Disk
3. What To Do If The Above Methods Are Unable To Clean Your Computer
4. What To Do After All Malware Is Confirmed To Be Removed

1. Make Sure Computer Is Actually Infected


Before attempting to clean any infections from your computer it's important to make sure that the computer is actually infected. To do this please follow the advice I give in How to Know If Your Computer Is Infected. If the results of this do in fact show that your computer is infected then continue to follow the steps in the next section. Make sure that you follow them in order.

2. How To Clean Your Computer And Make Sure It's Actually Clean


Please note that advanced users may just want to skip to the last part about how to Make A Bootable Disk and clean the computer that way. This approach is the one which is most powerful, but it is also one of the more time consuming approaches. That said, if you wish you can jump directly to that section and then come back to the beginning again if the infection is not entirely removed.

A) Clean Computer With CCE and TDSSKiller
Download Comodo Cleaning Essentials (CCE). Make sure to select the correct version for your operating system. If you're not sure if your computer is running a 32 or 64 bit operating system then please see this FAQ. Also, download Kaspersky TDSSKiller . Note that if neither will not download correctly, or your internet connection is not working, you should download them on another computer and transfer them to the infected one via a flash drive. Make sure there were no other files on the flash drive. Be careful with the flash drive as the malware may actually infect it when you plug it into the computer. Thus, don't plug it into any other computers after transferring these programs. Also, I would like to point out that both programs are portable. This means that once you're done using them no uninstall is required. Just delete their folders and they will be gone.

After downloading CCE unzip the file, open the folder for CCE, and double click on the file called CCE. This will open the main program for Comodo Cleaning Essentials. If it refuses to open then hold down the shift key and, while still holding it down, double click on the file called CCE. After CCE has successfully opened you can let go of the shift key. However, do not let go of it until the program has fully loaded. If you let go of it even during the UAC popup it may not be able to forcefully open correctly. Holding down shift should allow it to open, even on heavily infected computers. It does this by killing most of the unnecessary processes that could be interfering with its launch. If it still will not launch then download and run a program called RKill. This program will terminate known malicious processes. Thus, after running it CCE should be able to open fine.


Once it's opened perform a "Smart Scan" with CCE and quarantine anything it finds. This program also scans for system changes which may have been caused by malware. These will be shown with the results. I would advise letting it fix these as well. Restart your computer when prompted. After the computer restarts run Kaspersky TDSSKiller, perform a "Smart Scan", and quarantine anything it finds. If anything was quarantined restart your computer once more.

Also, if your internet connection was previously not working please check again to see if it is now working. If not then you should go to this section of my guide about How to Fix a Malware Infected Computer and follow the advice given to fix your internet connection. A working internet connection is required for the remaining steps of this section.

Once you have verified that your internet connection is working, again open CCE. Hopefully it will open up normally this time, but if not then open it while holding down shift. Then open up KillSwitch from the tools menu in CCE. In KillSwitch, select the option to "Hide Safe Processes" from the "View" menu. Then right click on all processes which are flagged as suspicious or dangerous and select the option to delete them. You should also right click on any unknown processes that remain and select the option to "Kill Process". Do not delete processes flagged as FLS.Unknown. Next, open up Comodo Autoruns from the tools menu in CCE, and select the option to "Hide Safe Entries" from the "View" menu. Then disable any entries belonging to files which are flagged as suspicious or dangerous. You can do this by making sure the check box next to the entries is unchecked. You should also disable any entries flagged as FLS.Unknown, but which you believe likely belong to malware. Do not delete any entries. 

Now restart your computer. After it reboots, again check your computer using the advice I give in How to Know If Your Computer Is Infected. If all is well then you can skip to the section about What To Do After All Malware Is Confirmed To Be Removed. Remember that a disabled registry entry is not a risk. Also, note that even if your computer is found to be clean of active infections there could still be pieces of malware on your computer. These are not dangerous, but don't be surprised if running another scanning program still detects malware on your computer. These are the inactive remnants of what you have just removed. If you are not comfortable having these remnants on your computer then you can remove the vast majority of them by scanning with the programs in the next section.

However, if your computer is not yet clean of active infections, but at least one of the programs was able to run, then go through the steps outlined in this section once more and see if that is able to remove the infections. However, if neither program was able to run please continue to the next section. In addition, if even following the advice in this section a second time is not enough to clean your computer you should continue to the next section.

B) If Still Not Clean Then Scan With HitmanPro, Malwarebytes, And Emsisoft Anti-Malware
If the above steps failed to fully remove the infections then you should download HitmanPro  Install the program and run a "Default Scan". Note that if it will not install please continue to the next paragraph and install Malwarebytes. During the installation of HitmanPro, when asked I would recommend you choose the option to only perform a one-time check of the computer. This should be suitable for most users. Also, if malware prevents it from loading correctly then open the program while holding down the CTRL key until the program is loaded. Quarantine any infections it finds. Please note that this program will only be able to remove infections for 30 days after it is installed. During removal you will be asked to activate the trial license.

Once all detected infections are removed by HitmanPro, or if Hitman Pro refused to install, you should download the free version of Malwarebytes  Note that it has chameleon technology which should allow it to even install on computers which are heavily infected. During installation I would advise that you uncheck the box to "Enable free trial of Malwarebytes Anti-malware Pro". Make sure that it is fully updated and then run a quick scan. Quarantine any infections that it finds. If asked by either program to restart your computer, make sure that you restart it.


Next download Emsisoft Emergency Kit . Once it's finished downloading, extract the contents from the zip file. Then double click on the file called "start" and open the "Emergency Kit Scanner". When prompted allow it to update the database. Once it's updated select the option to go "Back To Security Status". Then go to "Scan now" and select the option to perform a "Smart Scan". Once the scan is complete quarantine all detected items. Restart whenever required.

After scanning your computer with these programs you should restart your computer. Then once again check your computer using the advice I give in How to Know If Your Computer Is Infected. If all is well then you can skip to the section about What To Do After All Malware Is Confirmed To Be Removed. Remember that a disabled registry entry is not a risk. However, if your computer is not yet clean then go through the steps outlined in this section once more and see if that is able to remove the infections. If the programs in part A of this section were previously not able to run correctly you should go back and try and run them again. If none of the above programs were able to run correctly please boot into Safe Mode with Networking and try scanning from there. However, if they were able to run correctly, and threats still remain even after following the advice in this section a second time, then you should continue to the next section.

C) If Needed Try These More Time Consuming Methods
If the above steps were not able to completely remove the infection then you likely have some very inhospitable malware inhabiting your machine. Thus the methods discussed in this section are much more powerful, but will take much longer to complete. The first thing I would advise doing is to scan your computer with another anti-rootkit scanner called GMER. It can be downloaded from Remove anything shaded in red. Make sure you do click on the Scan button once the program has finished its quick analysis of the system. Also, if you're running a 32 bit operating system you should download a program to scan for and remove the ZeroAccess rootkit. Information about this rootkit, and a link to a program to remove it from 32 bit systems. The AntiZeroAccess tool can be downloaded from the link in the second paragraph.

After scanning with the above programs you should next open CCE, go to the options, and select the option to "Scan for suspicious MBR modification". Then select OK. Now perform a full scan with CCE. Restart where requested and quarantine anything it finds. Note that this option can be relatively dangerous as it could possibly identify problems where there are none. Use it carefully and make sure everything important is already backed up. Note that in rare cases scanning with these options may render your system unbootable. This rarely happens, but even if it does it should be fixable. If running this scan renders your computer unbootable please see this section of an article I wrote about How to Fix a Malware Infected Computer. It should be able to help make your computer bootable again.

Once CCE has completely finished, again open up CCE while holding down the SHIFT key. This will kill most unnecessary processes which may be interfering with your scans. Then open KillSwitch, go to "Tools", and choose the option to "Hide Safe Processes". Now, once again delete all dangerous processes. Then, you should also right click on any unknown processes that remain and select the option to "Kill Process". Do not delete them. You should follow the advice in this paragraph each time you restart your computer in order to make sure that the following scans are as effective as possible.


After killing all processes not verified to be safe you should open HitmanPro while holding down the CTRL key. Then perform a "Default Scan" and quarantine anything it finds. Then perform full scans with Malwarebytes and Emsisoft Emergency Kit. Quarantine anything they find. Then download the free version of SUPERAntiSpyware from this page. During installation be very careful as other programs come bundled with the installer. On the first page make sure to uncheck both options about adding Google Chrome. Then click on the option for "Custom Install". During the custom install you will once again have to uncheck two boxes about adding Google Chrome.

Other than that the program will install fine. When asked I would recommend that you decline the option to start a free trial. Once the program is fully loaded select the option to do a Complete Scan and click on the button to "Scan your Computer...". Then click on the button to "Start Complete Scan>". Remove all detected files and restart wherever required.

After following these steps you should restart your computer. Then once again check your computer using the advice I give in How to Know If Your Computer Is Infected. If all is well then you can skip to the section about What To Do After All Malware Is Confirmed To Be Removed. Remember that a disabled registry entry is not a risk. However, if your computer is still not clean then go through the steps outlined in this section once more and see if that is able to remove the infections. If it is not then you should continue to the next section.

D) If Necessary Make A Bootable Disk
If the above methods were not able to completely remove the infection, or you cannot even boot your computer, then you may need to use a bootable CD/Flash-Drive, also called a bootable disk, to clean your computer. I know this may sound complicated, but it's really not that bad. Just remember to create this disk on a computer that is not infected. Otherwise the files may be corrupted or even possibly infected.

Because this is a bootable disk no malware can hide from it, disable it, or interfere with it in any way. Thus scanning in this way, with multiple programs, should allow you to clean almost any machine, no matter how infected it may be. One exception to this is if the system files on the machine have themselves been infected. If this is the case then removing the infection may cripple the machine. It's largely for that reason that you backed up all important documents before starting the cleaning process. That said, sometimes it's possible to get around that by following the advice I give below.


To do this you should download the Shardana Antivirus Rescue Disk Utility (SARDU). This is an excellent program which will allow you to create a single rescue disk with multiple antivirus programs on it. It also has many other useful functions, which I will not be discussing in this article. A few very useful tutorials for SARDU can be found on this page. Be very careful about the added offers now included with the installer. Sadly, this program now tries to trick people into installing extra programs, which are largely unnecessary.

After downloading it extract the contents and open the SARDU folder. Then open the correct executable for your operating system, either sardu or sardu_x64. Under the Antivirus tab click on whichever antivirus applications you would like to add to your disk. You can add as many or as few as you wish. I would recommend that you scan your computer with at least Dr. Web, Avira AntiVir Rescue System, and Kaspersky Rescue System. One of the nice things about Dr. Web is that it sometimes has the option to replace an infected file with a clean version of it instead of just deleting it. This may allow you to clean some infected systems without crippling the computer. Thus I'd strongly recommend including Dr. Web in your bootable disk.

Clicking on the names of the various antivirus applications will often direct you to a page where you can download the ISO for that particular antivirus. Sometimes it will instead give you the option to download it directly through SARDU, which can be found under the Downloader tab. If given the choice always select the option to download the ISO. Also, after downloading the ISO you may need to move it to the ISO folder inside the main SARDU folder. Once you have moved all of the ISO's, for the antivirus products you would like to include, to the ISO folder, you are ready to create the rescue disk. To do this go to the Antivirus tab and make sure that all desired antiviruses have a check next to them. Then either click the button to make a USB or make an ISO. Either will work fine. It just depends on whether you want to run this off of a USB drive or a disk.

After creating your rescue disk you will likely need to change the bootup sequence in your BIOS settings to ensure that when you insert the bootable CD, or flash-drive, the computer will boot from it instead of from the normal operating system. Here is a useful article on How To Change the Boot Order in BIOS. For our purposes you should change the order so that the "CD/DVD Rom drive" is first if you want to boot from a CD or DVD, or that "Removable Devices" is first if you want to boot from a flash-drive. Once that's done just follow the advice given in this other article about How To Boot From a CD, DVD, or BD Disc in order to boot from the rescue disk.


After booting from the disk you can select whichever antivirus you want to first scan your computer with. As I previously mentioned, I would recommend starting with Dr. Web. Once it's finished, and you have repaired or deleted everything it finds, you should shut down the computer. Then make sure to again boot from the disk and then scan with another antivirus. Continue this process until you have scanned your computer with all of the antivirus programs you have put on the rescue disk.

After cleaning your computer with whichever programs you've put on the disk you should now try booting your system into Windows again. If it is able to boot into Windows then check your computer using the advice I give in How to Know If Your Computer Is Infected. If all is well then you can skip to the section about What To Do After All Malware Is Confirmed To Be Removed. Remember that a disabled registry entry is not a risk.

If your computer is not yet clean, but you are able to boot into Windows, then I would recommend trying to clean your computer from inside windows, starting from this section of this article and following the suggested methods. However, if your computer is still not able to boot into Windows then again try fixing it by following the advice in this section of an article I wrote about How to Fix a Malware Infected Computer. It should be able to help make your computer bootable again. If even that can't make your computer bootable then try adding even more antiviruses to the boot disk and then rescanning your computer. If doing that still does not work then please read the next section.

3. What To Do If The Above Methods Are Unable To Clean Your Computer


If you followed all of the above advice and were still not able to clean your computer, but you're convinced that the problems are due to malware, then there's not much more I can do to help. I'm actually hoping that nobody ever reaches this section. This article is meant to allow you to completely clean an infected computer. Thus I'd really appreciate it if you could leave a comment below that explains what you tried to do in order to clean the computer, and what symptoms remain that make you think that your computer is not yet clean. This is very important in order for me to improve the article.


You can also seek advice from a specialized malware removal forum. A forum which I have found to be very helpful is MalwareTips. However, if even after seeking help on a malware removal forum your computer is still not free of malware, it may be necessary to format your computer and start over. This means that you will lose anything on the computer which you did not back up. Make sure that if you do this you do a complete format of your computer before reinstalling Windows. This will be able to destroy almost any type of malware. Once Windows is freshly installed please follow the steps in the next section.

4. What To Do After All Malware Is Confirmed To Be Removed


After confirming that your computer is now clean you can now try to repair any damage that may have been caused. For this I have written an article about How to Fix a Malware Infected Computer. Please follow the advice in this article in order to fix any damage that was caused by the infection. If after doing this your computer is running fine, then you can also open Comodo Autoruns and select the option to delete those registry items you had previously only disabled. This way they will no longer be on your computer at all.


Once you have successfully cleaned all infections from your computer, and repaired any leftover damage, you should take steps to ensure that it does not happen again. For this reason I have written a guide about How to Stay Safe While Online. Please read through it and implement whichever methods you feel best fit your needs.

After securing your computer you can now restore any of the previously backed up files that were lost during the cleanup process. Hopefully this step is also not necessary. Also, before restoring them make sure that your computer is very well protected. If you don't lock the computer down strongly enough then you may inadvertently infect it and again have to clean the infections from the computer. In addition, if you used a USB drive to transfer any files to the infected computer you can now plug that back into the computer and make sure there is no malware on it. I would recommend doing this by deleting all files left on it.



 

If you have any problems, or are confused by my directions, please leave a comment below and I will try to help you. Trust me, if you are having a problem then so are many others. I need to know this so that I can improve the advice in this article. Also, I do realize that there are a plethora of programs that can be used to clean an infected computer. I have selected these particular programs, and arranged them in such a way as to emphasize their positive qualities while at the same time compensating for their weaknesses, in an attempt to simplify the malware removal process. Please let me know if you see any problems with the approach I have outlined.
In addition, please help by rating this article. If you believe this article deserves anything less than 5 stars, please leave a comment below explaining how you think it can be improved or where you find fault. This article is written by me but fueled by the community. Thus your opinions and advice are not only much appreciated, but actually necessary in order for this article to grow and improve.