We've seen ones infecting important system files in such way that when tried to cure the files they got deleted by the antivirus software. As a result the whole system failed to boot and we had to reinstall the Windows from the ground up.
The new variants were able to penetrate even through Safe mode - they loaded themselves as system drivers thus being unstoppable by the usual antivirus program shields.
And let's not forget the upgraded self modifying code: we've got a case of 1 virus detected by the AV software pretending to be of at least 100 other virus variants by constantly modifying its code.
Also lots of viruses were tracking their own files/memory loaded processes and when modified/deleted by the antivirus application, the whole system got restarted.
More and more spyware didn't touched the HOSTS file in order to redirect you to their own web pages, or slow your surfing, but directly modified the Windows core libraries(DLL-s) and Internet Transfer Protocols this way successfully blocking the antivirus update process, as well as the access the latter respectful websites.
In case that you might be infected but still unwilling to install Linux here are some practical advices that you can follow in order to remove the newest virus variants from your computer:
1. Safe mode booting is essential. Few antispyware products could successfully clean up infected process or file in normal mode. The ones that are free and worth mentioning are SpywareTerminator and Microsoft Security Essentials. In case of a stubborn one you might load up Live CD and then run your antivirus software.
2. If the virus is preventing you from updating your antivirus application, then just use a proxy server or find a mirror offering the latest program's definitions.
3. Perform scan using various applications: here is a list of the really good and free ones: DrWeb Cureit, a-squared free, malwarebytes anti malware, superantispyware. They have different scanning times as well as virus databases, but are proven effective in case of a strongly infected computer. And if you wish to have protection from a non-free software I would suggest you the fast one from DrWeb or Kaspersky Antivirus(if your machine is a fast one).
4. Exchange Avast, Norton, NOD32 and so on with AVG, Avira Antiviral Toolkit Pro or Spyware Terminator. The previous excellent Spybot Search and Destroy and AdAware are now useless when faced with the new trojan variants.
5. Ensure that you've got constantly running access shield and be careful what you're allowing to run - here I could again recommend Spyware Terminator. by Nevyan Neykov


Post a Comment