Automated virus / spyware removal script: June 2010 (BROKEN)

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Thanks for the testing.

t the Microsoft scanner never showed a log or progress bar or anything to see what it was doing.
It was not supposed to, the only I way that I could make it unattended was to fully purge any progress bar.


Looks like you had several false positives... may have to turn down Sophos' heuristics or just remove it completely.

the entire test ran about almost 9hours and again i stopped early. the test had no interruptions for the most part damn thats long time haha.
Yeh, this thing is mainly for starting on a room of like 50 PCs and letting them run overnight. I am getting the same feedback from the people that are field testing about scan time. I may create a "light edition" with only a2, Trend, and Mcafee or something similar. It is already easy to remove certain scanners yourself (just remove the entries in the .cmd file within scanners).

I really think that the aVast (note the one used in the script is NOT the full version) and the Microsoft Malicious Software Removal tools are useless in this, as the other programs should catch their limited library of malware.

I just wish that I could get the antivir command line version working, but I think that it is a 16-bit application.
 

NYCSTE2003

Member
Oct 27, 2003
168
0
0
antivir command line working would be killer for sure. what about an avg version not sure if they make it but it would be free
what about macafee avert stinger program http://www.majorgeeks.com/download4063.html
and Kaspersky Free Cleaner http://www.majorgeeks.com/Kasp...ree_Cleaner_d4515.html
and F-Secure F-Bot cleaner tool http://www.f-secure.com/download-purchase/tools.shtml
and AVIRA Removal Tool for Windows http://www.avira.com/en/suppor..._tool_for_windows.html
just sharing some programs ive used in past no idea how good or bad or outdated they are.

second. i noticed for some reason my game that i normally play wouldnt work. im not blaming this program but its possible something was deleted or removed that made my games not work. i went to uninstall the game cuz im gonnna reformat anyway soon but then i saw the repair feature so i loaded up the disc and repaired. the game worked after that not sure what was messed up or missing. wanted to share.

on a side note i did test 1-2 other programs last night that clean stuff so perhaps it was those programs and i dont mean to blame your program setup at all just sharing what i found.

ps. my rig is 3gb ram duocore e6300. so by all means not slow and it took 9hours+ lewl. scared to see howlong p3 or slower p4s and amds would do
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Some of those scanners are redundant (IE the mcafee used in the current script should catch the ones in Stinger). Same reason that I am thinking of removing the aVast and the Microsoft Malicious Software Removal Tool (the others should pick up what either can detect), since both of those applications have a limited scope... the others are much broader.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
More positive results from the field, coworker of my father used it on two of his PCs that he built for his kids. Safely removed the infections, only complaint seems to be the scan time. Which should improve slightly if I take out the aVast lite scanner and the MS MSRT (since the other scanners should catch the narrow spectrum that they look for). I may have to remove ClamWin as well (or at least not let it scan within archives, it seems to take the longest and for some reason it thinks the JDK is a malware).

Currently, I am looking into using Sophos' antirootkit command line utility in the next release of the script.
 

NYCSTE2003

Member
Oct 27, 2003
168
0
0
sounds good bro. yea 9hours on a fast rig time is crazy.... cant imagine on an old system esp one thats really messed up

fyi my issue still remains nothing seems to be able to fix it or find what the problem is. the picture explains exactly whats wrong but no one seems to recognize it yet
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Script updated, removed clamwin (very slow scan time), AVast worm scanner and the MS Malicious Software Removal Tool was removed as well (due to redundancy).

I also created a separate script (that is included) which only scans / reports (at least it should just do that).

I submitted a report to avira, but I am not including the Panda command line scanner at this time due to a false positive (antivir thinks that a file in it is malware).

Anyone know if Sophos' command line scanner searches for rootkits as well? (IE has the functionality of Sophos' AntiRootkit tool)?

Let me know if you guys have any trouble on your test machines with the new script, I know it has three fewer scanners, but it will be much faster now and I am gambling that the other scanners will catch anything that ClamWin might have picked up (ClamWin's detection rate was never that great).
 

NYCSTE2003

Member
Oct 27, 2003
168
0
0
hey have any files updated since i last tested?? im too lazy to check and im falling asleep.

new package is about 20mb smaller to a size of 85.8mb uncompressed.

and using 7z best compression it is ... waiting haha... 61.3. not to shabby.


just sharing the direct links. plz delete if this is not smart to do.

SCHADENFROH'S MALWARE REMOVAL SCRIPT (September 15, 2007)

I have been working on creating a script that will automatically remove malware by using several antimalware application's command line versions.
This was created to help speed up the removal process when I am asked to clean a system for a friend or family member.

Disclaimer: This script has the potential to damage your windows install. Use it and the programs linked below at your own risk.
I highly suggest that you only try it in a virtual machine or a test machine for now. I have only tested it in a Windows 2000
Virtual Machine that was uninfected. It should work "in theory," so proceed at your own risk, I take no responsibility for
anything that is the result of you using this. Also note that it may remove some legit applications in that the antimalware applications have false positives.
Some scanners may purge your existing stored emails if malware is detected in one (applies to only certain email clients).
It is possible that some of these programs require that you own the base product and/or cannot be used in a non home environment.
Do not use those if that is the case and remove them from the .cmd (read the license)


Instructions are in the readme file, but here is what you should do:

1. Download and extract the a-squared command line scanner (@ http://www.emsisoft.com/en/software/download/) into the
"a2cmd" folder within the scanners folderin the package you downloaded. (a2cmd.exe should be in the a2cmd folder, not a subfolder of a2cmd)

http://download1.emsisoft.com/a2cmd.zip

2. Download Mcafee's latest beta (with command line scanner) called win_betaengdat.zip ( @ http://vil.nai.com/vil/virus-4d.aspx) into
the "Mcafee" folder within the "Scanners" folder. (scan.exe should be in the Mcafee folder)

http://download.nai.com/produc...ges/win_betaengdat.zip

3. Download Sophos (@ http://www.sophos.com/support/...se/article/13251.html), extract it into the Sophos folder
(note that SAV32CLI.EXE should be in the "Sophos" folder) Also, be sure you update the virus definitions (@ http://www.sophos.com/downloads/ide/)
by downloading the update files (latest IDE for web & CD) and overwriting the existing definitions (if any) in the sophos folder.

http://www.sophos.com/tools/sav32sfx.exe

4. Download Trend Micro's command line scanner (Sysclean Package @ http://www.trendmicro.com/download/dcs.asp) and the latest
definitions ( @ http://www.trendmicro.com/download/pattern.asp),Create a folder for the .com file and then double click on it
in windows explorer. After that, it should pop up trend micro, now without closing the application copy and paste all of the
files that it unpacked into the "TrendMicro" folder within the "Scanners" folder. Note if you run either program, the associated files
will be deleted, so copy it into the folder while you leave it running.
(note that vscantm.bin, sysclean.exe, lpt$vpn, vscantm.bin and their associated files should be in the "TrendMicro" folder)

http://www.trendmicro.com/ftp/products/tsc/sysclean.com
http://www.trendmicro.com/ftp/...cts/pattern/lpt721.zip

5. Burn the readme, the .bat file and the scanners folder to a cd (or removal storage medium)
6. Bring the cd (or removal storage medium like a USB flash drive) to the infected computer (or your virtual machine to test with) and boot the PC
into "Safe Mode Command Prompt" by hitting F8 before the windows logo appears
7. Move to your CD (or removal storage medium) drive once the command prompt comes up (usually D:\)
8. Type "clean" without the quotes and it will automatically copy over the files to the PC, scan, and remove any malware found without user intervention.
If you type "ScanOnly" without the quotes instead of "clean" the script will only scan for malware, it will not remove it.
"clean" = scan, remove, and report; "ScanOnly" = scan and report only.
9. Once the first scanner window pops up (after the files have copied over to the hard drive), it is safe to remove the cd or
flash drive and begin treating another PC in a similar fashion.
10. Logs of the various scanners will pop up at the completion of the script with details on what was scanned, found, and/or deleted.

Report bugs, suggestions, comments, etc. in the thread about this on the Anandtech forums:
http://forums.anandtech.com/me...=2084960&enterthread=y
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
hey have any files updated since i last tested??
No, I just removed calls for some utilities from the script and added a script that only scans (IE you are fine) and updated the readme accordingly. The programs themselves usually get definition updates a few times a day.
just sharing the direct links.
I did not include them in the readme because the developers usually prefer that the user visit their website and not just download the file. They probably do not care on a web forum, since it is free advertisement for them.
 

NYCSTE2003

Member
Oct 27, 2003
168
0
0
wow so last night at some point all shiiiznits broke loose and i had multiple things trying to access the internet i was like oo no. i was fine for a while then bam blewup. so i ran all my normal programs and then i ran this.

CHECKOUT THE SOPHOS file. it removed like all my files haha. and whatever hit me disabled my AV and lots of other things. and sophos removed or deleted a lot i should say.

ok just realized i have no idea how to upload a txt file here. sooo who wants to see it. let me know if i can email someone or AIm it over or something.

chcekout my thread here. its scary.

http://forums.anandtech.com/me...id=2093349&STARTPAGE=1
 

NYCSTE2003

Member
Oct 27, 2003
168
0
0
also wanted to share my thoughts on scanning order.

sophos seems best scan. finds the most. run it before perhaps last scan?

mcafee seemed to be the totally fastest scanner. perhaps run first just to get it done and find anything it might find fast

asquared took a while, trend micro was faster i think.

just some notes.


also sophos remove dlike half my system haha. hopefully everything actually removed was infected and not some sophos messup.

my system is now really messed haha
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
hopefully everything actually removed was infected and not some sophos messup
That is what I am worried about.... false positives with Sophos.


btw, I hear that the new version of CrapCleaner has CLI abilities. If so, that will save on scan time (just blowing away temp / internet files).
 

NYCSTE2003

Member
Oct 27, 2003
168
0
0
false positives would stink

but as im sitting here. comodo firewall keeps poopping up questions about allowing stuff and that files have changed. man i got hit with something really annoying and the funny thing is. i clean peoples computers normally for fun. but i cant come close to fixing mine haha.

i thought im using latest version of CC. i never understood why it doesnt remove temp folders to begin with
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Updated the script pack.

New Features / changes
  • "qclean" and "qscanonly" have been added. They work the same way as their non "q" counterparts, save they do not run the time consuming ClamWin and Sophos scans
  • Added clamwin back to the scanning options that do not begin with "q"
  • CCleaner used in "qclean" and "clean" now, it will purge the files that are removed with the default settings of CrapCleaner. It should save time in that the scanners will not have to scan the temporary files (of that user at least)
 

NYCSTE2003

Member
Oct 27, 2003
168
0
0
alright i fullly updated to your new version havent tested it yet. might not do so either hehe but curious to say the least. ive cleaned my entire computer there are no traces of anything left lost about 5gb or more of data and a reformat.
 

usernamemax20charact

Platinum Member
Dec 23, 2003
2,863
0
0
Thanks Schadenfroh. Awesome work.

I ran the version prior to your 9-24 update.

From what I remember, it took about 4-5 hours to scan a person's computer. Didn't get to finish the Sophos scan. It started but didn't seem to be doing anything so I just exited the scan and called it a night.

A-squared picked off a few items.... about 5 or 6. Not a long scan, but also not a fast scan. About average.

McAfee was pretty quick though.

Can't remember if it was the McAfee or Trend scan, but one of them couldn't read quite a few files saying something to the effect of "error, can't open."

Trend also picked up Spybot search and destroy as possible spyware (false positive?) but couldn't read/open certain files either to scan them. But that's probably because Spybot had been uninstalled prior to the scans. *shrugs*

Anyways, I'm sure that person's PC was totally screwed up..... had all sorts of trojans, keyloggers, dialers, spyware, adware, etc. I mean, what didn't it have?

I'll have to try out the updated version with CCleaner.

Thanks again.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Thanks for trying on your test machines, guys.

From what I remember, it took about 4-5 hours to scan a person's computer.
The "qscanonly" and "qclean" methods should be FAR faster (Sophos and ClamWin are excluded from those two, which the detection rates of Sophos and ClamWin are not that great)

Running CrapCleaner right off the bat helps as well, since it purges temporary files and such (so they do not have to be scanned).

Anyone know how to keep ClamWin from removing zip files that are "oversized" without disabling archival scans?

 

Mayfriday0529

Diamond Member
Sep 15, 2003
7,187
0
71
With Trend Micro, which definitions to i download. the page for defitions has virus, spyware and all kind of files? Thats the only part that i'm stuck at.
 

Mayfriday0529

Diamond Member
Sep 15, 2003
7,187
0
71
I tried it out today. It worked pretty good in my opinion. i tried it on a Virtual Windows XP Pro using VMware Desktop. Its a clean install so it didn't find anything. Know any bad websites to get my virtual machine infected with a virus? would that affect my host system?
I did see lots of messages about cannot open this file, mostly like system32 files and user.dat files. I'm guessing thats normal.

 

Mayfriday0529

Diamond Member
Sep 15, 2003
7,187
0
71
Originally posted by: Jnetty99
I tried it out today. It worked pretty good in my opinion. i tried it on a Virtual Windows XP Pro using VMware Desktop. Its a clean install so it didn't find anything. Know any bad websites to get my virtual machine infected with a virus? would that affect my host system?
I did see lots of messages about cannot open this file, mostly like system32 files and user.dat files. I'm guessing thats normal.

wow this thing is great. I went to a few bad websites, downloaded some fake spyware programs and got a couple of trojan virures.

rebooted the machine, rain just qclean and bam they are gone. system rebooted and no bad programs installed and no pop ups.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
I contacted Panda regarding their command line scanner (it is being detected as a false positive by several other antivirus products) and they said that they have fixed the issue internally and it will no longer occur once they release the new version of it. It should be a worthy addition to the script.

The freeware version of the AntiVir command line scanner only scans one directory (no sub directories).

SuperAntiSpyware has stated that a command line version of 4.0 will be available in the future.

The next major update will likely use a vb script (or maybe an open source c++ program) rather than a .bat / .cmd to drive it, so it can have expanded functionality. Let me know your thoughts on this.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |