The Naked Scientists
  • Login
  • Register
  • Podcasts
      • The Naked Scientists
      • eLife
      • Naked Genetics
      • Naked Astronomy
      • In short
      • Naked Neuroscience
      • Ask! The Naked Scientists
      • Question of the Week
      • Archive
      • Video
      • SUBSCRIBE to our Podcasts
  • Articles
      • Science News
      • Features
      • Interviews
      • Answers to Science Questions
  • Get Naked
      • Donate
      • Do an Experiment
      • Science Forum
      • Ask a Question
  • About
      • Meet the team
      • Our Sponsors
      • Site Map
      • Contact us

User menu

  • Login
  • Register
  • Home
  • Help
  • Search
  • Tags
  • Member Map
  • Recent Topics
  • Login
  • Register
  1. Naked Science Forum
  2. Non Life Sciences
  3. Geek Speak
  4. How do you remove malware that commercial antivirus won't find?
« previous next »
  • Print
Pages: [1]   Go Down

How do you remove malware that commercial antivirus won't find?

  • 5 Replies
  • 809 Views
  • 2 Tags

0 Members and 1 Guest are viewing this topic.

Offline vhfpmr (OP)

  • Sr. Member
  • ****
  • 494
  • Activity:
    7%
  • Thanked: 41 times
    • View Profile
How do you remove malware that commercial antivirus won't find?
« on: 07/10/2022 16:43:18 »
As per the title, if antivirus like Norton, McAfee, & Malwarebytes won't find the malware, how do you go about removing it?
Logged
 



Online evan_au

  • Global Moderator
  • Naked Science Forum GOD!
  • ********
  • 10748
  • Activity:
    20%
  • Thanked: 1383 times
    • View Profile
Re: How do you remove malware that commercial antivirus won't find?
« Reply #1 on: 07/10/2022 22:38:28 »
How do you know that you have malware?
- How do you distinguish that from a software bug, or a corrupted hard disk?

A "well-designed" and well-entrenched malware might detect your attempt to install antivirus software and block it
- So you have to wrest control from the malware
- When my old Windows computer was attacked by ransomware, I created a LINUX boot disk on read-only media.
- I rebooted the computer under LINUX (not giving the malware a familiar environment to run in), and had a look around the disk
- I recovered what was still readable (not much - all images had been encrypted)
- I started again with a new computer, moving in the files I wanted from a backup disk.

So the best way to recover from malware is:
- Keep your operating system up-to-date
- With up-to-date virus scanning software
- Take regular offline backups of everything that is important to you
- ie the best time to recover from malware is before you get infected... (not much comfort for you, I'm afraid!)
Logged
 
The following users thanked this post: vhfpmr, Zer0

Offline vhfpmr (OP)

  • Sr. Member
  • ****
  • 494
  • Activity:
    7%
  • Thanked: 41 times
    • View Profile
Re: How do you remove malware that commercial antivirus won't find?
« Reply #2 on: 08/10/2022 00:33:50 »
Quote from: evan_au on 07/10/2022 22:38:28
How do you know that you have malware?
- How do you distinguish that from a software bug, or a corrupted hard disk?

Because a tiny handful of very specific files containing legal evidence, including all the backups, have been deleted by a powerful organisation with an interest in them going missing. I think it must have arrived in a Word file attached to an email, then gone from the computer to all my storage media, then from that media to a new computer.

McAfee insist it's not possible to write malware that can evade their antivirus, and when I referred them to Stuxnet that the US government managed to spread around the world undetected, they said "Stux what? Never heard of it".

I've found a company that specialises in forensic data recovery, but the organisation hacking me is one of their best clients.
Logged
 

Online evan_au

  • Global Moderator
  • Naked Science Forum GOD!
  • ********
  • 10748
  • Activity:
    20%
  • Thanked: 1383 times
    • View Profile
Re: How do you remove malware that commercial antivirus won't find?
« Reply #3 on: 08/10/2022 01:22:02 »
Quote
very specific files containing legal evidence, including all the backups, have been deleted
It sounds more like a hacker, interested in these specific files.
- Antivirus software won't find them or stop them, because they are a user (pretending to be you), not a virus.

Your backups should not be attached to your computer, except while actually doing the backing-up. That will stop remote hackers.
- Presumably, cloud backups can be accessed at any time
- An in-person hacker will find all your non-connected backups, and delete files from them too - but this is a much more risky operation
- If you have important files, storing them offline and offsite is a good idea
Logged
 

Offline vhfpmr (OP)

  • Sr. Member
  • ****
  • 494
  • Activity:
    7%
  • Thanked: 41 times
    • View Profile
Re: How do you remove malware that commercial antivirus won't find?
« Reply #4 on: 08/10/2022 15:29:31 »
Quote from: evan_au on 08/10/2022 01:22:02
Your backups should not be attached to your computer, except while actually doing the backing-up.
Backups that are never connected to the computer are of no use.
Quote
That will stop remote hackers.
If the hacker places malware on the computer that's been primed to look for a specific file and delete it when ever external media are connected, then backups are useless. Whenever I connect media with sensitive files, the fan on the computer runs continuously all day long. It rarely runs at other times, and then only briefly.
Quote
- An in-person hacker
If there's one of those, someone's breaking into the house.
Quote
- If you have important files, storing them offline and offsite is a good idea
I have no clean equipment to make clean copies with/from. (I also have no other site than the house.) I've considered buying a new computer, but it seems to me it's useless if I have no way of transferring (even non-sensitive) files from the old one, and can't connect it to the infected media with the relevant data on.

The idea that I could search one backup to check whether anything's missing before connecting another would be a non-starter, there are hundreds of files, and it's not necessarily apparent which ones will become important until months/years later. I'm trying to piece togther what has happened to me, and it's often not apparent that something is significant until I stumble across a snippet of information much later.
Logged
 



Offline nicephotog

  • Sr. Member
  • ****
  • 457
  • Activity:
    0%
  • Thanked: 11 times
  • [ censored ]
    • View Profile
Re: How do you remove malware that commercial antivirus won't find?
« Reply #5 on: 04/11/2022 10:43:58 »
In ms windows you press cntrl+alt+del keys together , then choose the "task manager" (of the most recent , Linux Slackware 15 has a "task manager" gui prog) and look for names that indicate the name of the program, either a .exe or .dll , also open "services" and look for names that indicate the program if you have some idea from an icon or company name it placed  in the taskbar or desktop. Terminate the process and watch for a minute to see if the process switches on again and if it does then look for another, there can be up to three or four other programs of it of similar or unsimilar name supporting as watch to see they are not switched off.
If that occurs , you need to use the OS rescue / boot from disc disc and use the command line to go into the directories and remove all the .dll and .exe that support it.
« Last Edit: 04/11/2022 10:46:00 by nicephotog »
Logged
How To Tutorial (all Java servers) HttpOutPutTools (port to .jar Hell Pig Entelodont) 2nd November 2022
https://drive.google.com/file/d/1gjHmdC-BW0Q2vXiQYmp1rzPU497sybNy/view?usp=share_link
 



  • Print
Pages: [1]   Go Up
« previous next »
Tags: malware  / antivirus 
 

Similar topics (5)

Find x-intercept and y-intercept for the function: f(x)=9x^2+12x+4.

Started by malyloBoard General Science

Replies: 1
Views: 11161
Last post 10/11/2011 04:31:16
by CliffordK
Why do we find things "cute"?

Started by mike2niner4Board Plant Sciences, Zoology & Evolution

Replies: 10
Views: 17530
Last post 12/07/2009 06:51:15
by Karen W.
How do you use decay constant formula to find decay in excel?

Started by dgt20Board Physics, Astronomy & Cosmology

Replies: 13
Views: 10565
Last post 05/03/2018 15:59:26
by chris
Where can I find the definition of "label claim viscosity"

Started by ratwingBoard General Science

Replies: 1
Views: 5922
Last post 06/09/2011 13:42:37
by damocles
How to find amount of mass knowing the mass transfer coefficient?

Started by scientizschtBoard Physics, Astronomy & Cosmology

Replies: 1
Views: 1843
Last post 28/11/2019 14:53:44
by Bored chemist
There was an error while thanking
Thanking...
  • SMF 2.0.15 | SMF © 2017, Simple Machines
    Privacy Policy
    SMFAds for Free Forums
  • Naked Science Forum ©

Page created in 0.081 seconds with 43 queries.

  • Podcasts
  • Articles
  • Get Naked
  • About
  • Contact us
  • Advertise
  • Privacy Policy
  • Subscribe to newsletter
  • We love feedback

Follow us

cambridge_logo_footer.png

©The Naked Scientists® 2000–2017 | The Naked Scientists® and Naked Science® are registered trademarks created by Dr Chris Smith. Information presented on this website is the opinion of the individual contributors and does not reflect the general views of the administrators, editors, moderators, sponsors, Cambridge University or the public at large.