Reply to Message

Re: How successful is this method...
Well, I agree a reformat and reinstall is the best (and surest) remediation, but sometimes it's just not possible!
What if the owner or end-user doesn't have the installation media?

In any case, once I've cleaned the hard drive with a Rescue CD, I:
1) verify the PC is disconnected to the Internet
2) Verify the PC boots without error (missing system files, etc)
3) Uninstall the existing antivirus/antispyware product(s)
4) Reinstall antivirus/antispyware product(s)
5) Reconnect to the Internet and update all definitions
6) Reboot in Safe Mode and scan all connected hard drives.

I make sure to do steps 3 through 5 because the existing product(s) were most likely comprised by the malware infection.

Not as comforting as a reformat and reinstall, but sometimes it's the next best thing.

My $.02.
Posted by Altiris_Grunt
9th Jun 2010