# IT GUYs: Method of virus removal

**URL:** https://forums.speedlife.net/t/it-guys-method-of-virus-removal/250186
**Category:** Shift518 Off Topic
**Created:** [February 7, 2010, 8:06am UTC](https://forums.speedlife.net/t/it-guys-method-of-virus-removal/250186 "2010-02-07T08:06:06Z")
**Posts on this page:** 1
**Showing post:** 12

<div class="post-metadata">

### Author: ![Shady](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@Shady](https://forums.speedlife.net/u/Shady)
#### Post date: [February 8, 2010, 8:19am UTC](https://forums.speedlife.net/t/it-guys-method-of-virus-removal/250186/12 "2010-02-08T08:19:11Z")

</div>

> [@Homosexual Undertones - NYSPEED Edition](https://forums.speedlife.net/t/homosexual-undertones-nyspeed-edition/15447/222):
>
> First, it depends on the the type and severity of the virus. If it is something simple, I manually uninstall it. If it is complex but not going to destroy the system, I will back up the data and run ComboFix. ComboFix is perfectly safe if you know what you are doing.  
> If the system is gone beyond saving, (attached to system files that will be destroyed upon removal) I will salvage the users files, format, and reinstall the OS/Files.

I’ve found combofix misses a lot of shit, but as far as “system being beyond saving” even if they are attatched to system files, its easy enough to replace them, depending on what the file is. But yes there are times where you just need to backup and start fresh.

> [@noobie.....](https://forums.speedlife.net/t/noobie/29146/2):
>
> Any tips on spotting a virus by file name?

As ILYA said, some are a bunch of random number likes 1234454.exe , some are just odd looking names like wasd23.exe/.dll/.sys etc…

Basicly if you know around the time the machine was infected you can sort by date modified as krazykid said, look at the publisher as for the most part 90% of legit files will have the publisher name attatched. If you arte ever unsure just google it, or rename it to .old … restart the system and see if anythings broken

> [@Taffys Meet anyone???](https://forums.speedlife.net/t/taffys-meet-anyone/29147/2):
>
> +1 I dick with an infected machine for 40 minutes… after that I quite, backup and reinstall.
> 
> All depends on the situation with me, if I can have the customers machine here in the shop for awhile, if they dont mind leaving it a bit longer I am one of those people that much rather figure out the quickest way to get rid of it so that if I come accross it I know exactly what to do.
> 
> I keep a notebook of all the crazy shit I come accross and what I did to fix it.
> 
> If the shit just started or you know when it first began running like crap or started having issues, I put the view on DETAILS and filter by date modified, anything that sticks out or looks out of place is prolly the virus.

This, but if your unsure just alway rename to .old and if it breaks the system or a program just go back and fix it.

> [@Just Got A Bike ... And I Already Need Your Help!](https://forums.speedlife.net/t/just-got-a-bike-and-i-already-need-your-help/29082/13):
>
> I run a security suite prior to Virus removal call IO Bit Security. Installs very fast and deep scans your system. It will tell you the names and how many variations of the virus are on your system. Whether its a hijacker, vundo, etc.

By the time youve installed that and ran a full scan, i bet you could have had the virus almost completely gone and the machine uninfected in a 1/4 of the time. The only thing you really tend to miss is a few registry keys, but for the most part as long as you deleted any files their trying to call to it wont matter, just run a scan using something small and fast to find them… I’ve found that CCLeaner will acctualy kill registry keys left by viruses

Im not saying I dont agree with you, but why run the scan prior and have it take more time as its finding things rather than just delete everything you can find and run a scan that will presumably be much faster

Unless you need log files in which case I guess thats a different story

---

_[View the full topic](https://forums.speedlife.net/t/it-guys-method-of-virus-removal/250186)._
