Best Virus Removal Tools: Cleaning a deeply infected system

Поделиться
HTML-код
  • Опубликовано: 27 дек 2024

Комментарии • 927

  • @pcsecuritychannel
    @pcsecuritychannel  2 года назад +446

    When I say I tried pretty much every tool, I mean it. For everyone curious about how some other tool would perform, I tried:
    ESET Online Scanner, F Secure, Comodo Cleaning Essentials, Emsisoft Emergency Kit, Bitdefender, Tron script etc and in the end even Protegent 😅 before coming up with this list. I went through all of these in a 1 hr stream on Discord but didn’t include here cause that would make for a boring video.

    • @novaUT
      @novaUT 2 года назад +23

      Tron isnt really good at all in my opinion it causes more harm then good

    • @tubehenry
      @tubehenry 2 года назад +5

      @@novaUT
      He mentioned that.

    • @RodneyGearheart
      @RodneyGearheart 2 года назад +8

      Hey Leo. Did you happen to try renaming the tools to see if that would allow them to run? I've had luck doing that before.

    • @wannabedal-adx458
      @wannabedal-adx458 2 года назад +6

      As long as when the Tron script is running it is playing the soundtrack from BOTH movies, I'm ok with it!! 😁😎

    • @Wall9K
      @Wall9K 2 года назад +33

      But can any of them remove McAfee?

  • @youreinthematrix
    @youreinthematrix 9 месяцев назад +77

    5:10 Steps to clean a deeply infected system:
    1. Norton Power Eraser (repair certain system files and functions)
    2. Kaspersky (advanced disinfection recommended)
    3. Hitman Pro (only quarantine and delete)
    4. Malwarebytes

  • @joez.2794
    @joez.2794 2 года назад +551

    If your system is "deeply infected" the most effective tool BY FAR is your existing backups because you need to reload/reimage/reinstall. AND, when you tally up all the hours you'll spend tracing down remnants or just worrying - it's often faster to boot. Sometimes a LOT faster!

    • @david09baz
      @david09baz 2 года назад +90

      The malware might infect your backups which results in them not working.

    • @a.x.w
      @a.x.w 2 года назад +131

      @@david09baz backups should be encrypted and your system shouldn't have write access to existing backups

    • @joez.2794
      @joez.2794 2 года назад +39

      @@a.x.w Exactly - "air gapped" (as much as I dislike that term). At work people sometimes rib me for still using tape, but it's cheap, fast, and I can look at all those cartridges on the shelf and say to myself "encrypt that" during any potential ransomware attack.

    • @hugbearsx4
      @hugbearsx4 2 года назад +28

      True. But how do you know you haven't backed up an already infected system?

    • @axeivy
      @axeivy 2 года назад +14

      I would say yes, but also no. All in all, it still depends on the status quo. If the most recent clean backup was a day ago before the infection, by all means recovering from a backup (should) be fine. But if the most recent clean backup was 6 days ago (weekly backups), or 29 days ago (monthly backups), we're talking days and weeks of potential data / progress being wiped out completely. Of course this is briefly speaking and it obviously gets more intricate, but this video is nice for techs like us to keep up with their tool-belt and be prepared / made aware of more options to consider if such an incident were to occur.

  • @zebawsh4357
    @zebawsh4357 Год назад +32

    Thank you so much, My pc got infected with a pretty deep virus that dug it's way into windows registry folders and I was searching on how to fix it because the virus was not letting me on any antivirus websites and I followed your instructions on this video and I finally recovered my 5 years of research I almost lost, so thank you I really appreciate it.

    • @edwardmacnab354
      @edwardmacnab354 2 месяца назад +1

      dude , keep a copy of all your data off line . That is the first rule of fight club lol . I never keep anything ON my computer except things like Gimp and OBS , but I can just reinstall those after a clean install of my OS .

  • @EastCoastScott
    @EastCoastScott 2 года назад +93

    Leo, I was just doing a survey for a well known AV site and your channel name came up. They wanted to know if I’d like to see you or your channel (whatever they meant) in their published reports. I said HELL YES!! You’ve come a long way over the years, you have a bright future ahead.

  • @Frank-Thoresen
    @Frank-Thoresen 2 года назад +82

    Thank you for going through with all the testing and present the findings with us

  • @rb2287
    @rb2287 Год назад +203

    The biggest problem with malware and virus removal is that no single tool finds everything. So, your approach of utilizing MULTIPLE or SEVERAL tools is strongly recommended. I use the following approach; Whenever possible, use an off-line tool to scan the system such as one which runs from a USB. Better yet, if you have a second computer, pull the infected drive and scan it with the second (uninflected) computer using multiple tools. This ensures that NO suspect processes could possibly have been running. place the computer into “Safe Mode” which only allows the Windows system files necessary to run. THEN, perform your cleanup. Unless you know EXACTLY when your system was compromised, you have to consider that system restore points are also worthless. I’ve seen this time and time again. If you restore to a certain point, you wind up re-infecting your system all over again. Only after doing THIS level of cleanup will you be better assured that the cleanup is complete.

    • @shaggydawg5419
      @shaggydawg5419 Год назад +16

      You're correct but I don't do cleanups. Nuke and rebuild is my solution

    • @rb2287
      @rb2287 Год назад +7

      @@shaggydawg5419 Yes, there’s always the “Nuclear Option.” As simple as this option actually is, I’ve learned that most people simply won’t go down this road. I would say that the nuclear option is the #1 approach to virus & malware removal. That’s why I primarily use Linux as my operating system.

    • @shaggydawg5419
      @shaggydawg5419 Год назад +7

      @@rb2287 People don't want to lose documents and/or start over from scratch. I'd rather lose a little bit of data (that hasn't been backed up yet) than risk an unstable system with a potential of reinfection or hidden malware. There's no way I'm going to use an infected system even after it's been cleaned and multiple malware products find nothing in it.

    • @taxcollector8858
      @taxcollector8858 Год назад

      ​@shaggydawg5419 how do you "nuke" your computer? I got a maleware and I got a ransom message. I'm planning on nuking but idk how

    • @shaggydawg5419
      @shaggydawg5419 Год назад +5

      @@taxcollector8858 I was referring to reinstalling the operating systems. Use other computer to download and create a Windows setup media on a USB flash. Turn off the infected PC and turn it back on. Boot off the USB device with Windows setup and delete the entire partitions on the infected hard disk. Start with a fresh Windows 10 or 11 installation.

  • @surfingsub5854
    @surfingsub5854 2 года назад +20

    The question that comes to mind is the system infection was obviously downloading it's own tools and not what you thought perhaps due to HOSTS file, or had a Image File Execution Options Injection settings for all of these tools. Then when you used a couple of them that were probably missing from the list they were able to run. Without having the exact infection it's difficult to say for sure which method was used, but bottom line is probably ALL of the tools or Most of the tools would have worked had IEFO or similar method of running its own tools been dealt with. It was NOT due to the tool not being able to deal with it. It was the method used to try and run it.

  • @stephenarkless9444
    @stephenarkless9444 2 года назад +685

    I don’t believe it!?!? Norton is useful for something???

    • @oskkim2163
      @oskkim2163 2 года назад +356

      Yes bro, Norton will remove your malware and install his own

    • @chirukun
      @chirukun 2 года назад +91

      @@oskkim2163 common Norton W

    • @intertop10
      @intertop10 2 года назад +9

      @@oskkim2163 😂😂😂😁

    • @intertop10
      @intertop10 2 года назад +18

      @@oskkim2163 Norton is Notorious 😁

    • @autisticsongs9657
      @autisticsongs9657 2 года назад +57

      bruh literally. you can use it to remove your malware while it probably mines for crypto in the background

  • @Netsuko
    @Netsuko 2 года назад +27

    You are the hero we need. EVERYONE needs to see your videos. Seriously.

  • @TheRossMadness
    @TheRossMadness 2 года назад +150

    Honestly, when I saw the malware take over the AV downloads, my first instinct was to not do the malware removal in Windows at all. Kaspersky Rescue Disk is a Linux boot disk that lets you run KAV on an offline system. I would be curious to see how it fares in this scenario. I've used it and Bitdefender Rescue CD (RIP) in the past with some good success.

    • @pcsecuritychannel
      @pcsecuritychannel  2 года назад +43

      Yes but this was much quicker.

    • @philpeko1796
      @philpeko1796 2 года назад +46

      @@pcsecuritychannel May be Quicker, but useless. @TheRossMadness is right, trying to clean a corrupted system from this live system is absolutely unreliable. The only way to do it right is using an external system. Otherwise, you can never be sure to have really cleaned up the system. It is a basic concept in IT security.

    • @Dyanosis
      @Dyanosis Год назад +5

      In my experience, for Windows anyway, doing things from safe mode is also a half-way decent option and normally solves most problems. Though it doesn't help against rootkits or bios attacks, but at least it'd help with things that want to be running on top of everything else (and most need internet to run, which safe mode doesn't allow).

    • @philpeko1796
      @philpeko1796 Год назад +8

      @@Dyanosis 1) In my line of work, that is Computer Security, there are no half-measures : You cannot be mildly confident that you have solved the issue.
      My customers want to be sure the problem is gone, not half-sure, with a half-baked solution, and what you recommend does not do the job.
      2) Thank you for proving my point, you said it yourself : Your solution does not help against rootkits/trojans. And I want to be sure to deal with them.
      3) You don't know well windows : You can run safe mode WITH Network enabled, it is an option. Enjoy, and Peace !

    • @williamking9707
      @williamking9707 Год назад +13

      @@philpeko1796 While you may be correct, there's no need to be aggressive about it. He does have 'something' of a point after all- in all honesty windows safe mode, while NOT a panacea by any means, is a useful but often-overlooked tool these days.
      And while security is always something to be done in absolutes, the way things are done at home is often different from the business world- at home there's no concern for liability or partnerships or tax breaks or write-offs etc etc, which can dictate decisions that in other cases wouldn't happen. For example MWB is the name in the game for AVs, but when the business pays for norton, that's what you're stuck with.
      There's also the simple matter that a full reinstall... Honestly isn't that bad these days. Personal treasures like photos and writing aside, I could probably do a full, fresh reinstall and re-setup of my home pc in under an hour. That was NOT the case when I had dial-up. And if a system is infected to THAT degree a full reinstall might not be that bad of an option. Not always an option, obviously, but it's something more worth considering than it perhaps once was.

  • @markganus1085
    @markganus1085 Год назад +2

    this is my new favourite channel. i can barely wait to get home from work and from class and try it out

  • @CoolJosh3k
    @CoolJosh3k 2 года назад +38

    I feel like the idea here is to clean up the system enough that what might remain of the user’s valued data can be offloaded to a backup, then the OS completely reinstalled.

    • @hatsandboots
      @hatsandboots 2 года назад +4

      Bingo! Now this idea I like.

  • @onlyVetements
    @onlyVetements 2 года назад +31

    the best way to deep clean an infected pc is to wipe the drive and start fresh, and not install some sketchy software again. keep your stuff backed up, and stay safe and comfy!

  • @wannabedal-adx458
    @wannabedal-adx458 2 года назад +15

    Leo, if you have to ask if we want to see a demo on something you mentioned in a video. The likely answer is YES!!! 😎 This is awesome info you put out for the novice to amateur computer user. Thanks for this video!

  • @7onysWorld
    @7onysWorld 2 года назад +9

    A customized Tron script video will be amazing to watch. I'm looking forward for that one.

  • @Evile_7780
    @Evile_7780 Год назад +4

    Thank you so much for this video, I searched for deep cleaning virus tools and your video was probably the savior of my steam account. In my stupidity I downloaded a sketchy piece of software that ended up stealing my account information and sold all my in-game items :( fortunately, I recovered my account just in time, i'm stealing a bit paranoid if some piece of malware is running deep inside my system but from what I can tell, my computer is cleaned.
    Thank you so much for making this video, you save my PC

  • @martinsalmeida321
    @martinsalmeida321 2 года назад +6

    Norton Power Eraser due to the very small installer size, seems to be an online installer, which in case of an infected computer where the internet connection may not work, it will not execute as the computer cannot access the cloud to get the latest and complete virus signatures. In this situation it will be better to use another Norton tool - Norton Bootable Recovery Tool. On the other hand, it is always advised to try to clean a computer via a bootable tool and do not execute the cleaning software with the infected operating system active and running.

  • @mikecrabtree8200
    @mikecrabtree8200 2 года назад +9

    A shop that I used when I used widows, never cleaned a system with widows loaded.
    They used a program called BartPE.
    They loaded the most current AV updates, burned a live disc, doing that on a separate PC. Turned the infected device off and then live booted the disc.
    The purpose to this is that some viruses use known inadequacies and flat out gross Vulnerabilities in the windows OS to hide themselves from AV software. Booting outside of the OS allows BPE to scan the full drive. Including areas that have been marked by windows as bad sectors for viruses.
    Windows marks sections of the formatted drive as bad if it finds issues. Windows will ignore these areas, but the virus can find them and use still good space in them.
    I personally stopped using windows decades ago because it was so riddled with vulnerabilities.
    No OS is fool proof, but windows is all but impossible to keep clean because of how haphazardly Microsoft writes it.
    The one thing it does well is keep a army of people employed trying to keep the OS running.

    • @billx4266
      @billx4266 2 года назад

      Thats not possible anymore since secure boot uefi

  • @MuhammadAhmad-dt4cq
    @MuhammadAhmad-dt4cq 8 месяцев назад +2

    Just by using the Norton power eraser my issue was fixed. Thanks bud.

  • @tubehenry
    @tubehenry 2 года назад +4

    I would certainly appreciate a video on Tron. Thanks for this one, by the way.

  • @delcogoblin
    @delcogoblin Год назад +13

    Thanks for the help, man. I'm starting a small PC repair business and I was looking for some good tools to clear infected computers. I'm more of a hardware repair guy but I want to open the business to anyone in need of assistance.

  • @cepay2015
    @cepay2015 2 года назад +15

    I love this kind of testing AV's and AV's tools videos!

  • @caseyriley1014
    @caseyriley1014 Год назад +2

    Please do make a video on tronscript I would love to see it!
    It's always fun to see how things stack up against some virus or another. Plus, hearing what you have to say about of the different steps and processes tron does would be interesting.
    Then if on top of that, you even mentioned changes or upgrades?! Yeah, that sounds like a great video!!

  • @CrypticKD
    @CrypticKD Год назад +3

    The Norton Power Eraser solved my issue.. THANK YOU!!

  • @ray070784
    @ray070784 2 года назад +4

    so let me get this clear, the best virus removal tools, Norton Power Eraser and Hitman Pro is the only two that still can be installed into our PC even AFTER we have deeply infected? or is Norton Power Eraser and Hitman Pro has been installed BEFORE it gets infected? but what if we've already installed the AV before get infected? like Kaspersky, Malwarebytes, etc, could we still can get auto infected?

  • @xKold
    @xKold 2 года назад +6

    Have you tried RKill for disabling malware before running any of the other av one-time scanners? Curious on your opinion of it.

  • @helifynoe9930
    @helifynoe9930 2 года назад +2

    My computer runs with the OS/programs/files each stored on one NVMe SSD. But the computer also has a HDD. So I cloned the contents of the NVMe SDD onto the HDD. I then disconnected the HDD from power and SATA connection to protect it from malware. So if I run into problems, be that malware or updates causing problems etc., I just reconnect the HDD and boot up from there. This takes less than 5 minutes, and so I then can proceed to do things such as pay bills and so forth, without there being any inhibitors or any other problems at hand. Thanks to this method, I am up and running bug free in mere minutes, rather than having to cross my fingers and reload or perform other recovery methods. Once I have some free time, I then just clone the contents of the HDD on over to the NVMe SSD, and once again have a bug free system. Thus with this technique, I in no way have to accept a corrupted computer to be able to somewhat repair itself via the help of another software app.

  • @slamscaper128
    @slamscaper128 Год назад +8

    I would love to see a more detailed video on fileless malware. I had a seriously compromised network back in 2018 and every system on my network (including my smartphone) was completely infected. In Windows I noticed the malware was highly cloaked and used a ton of strange Powershell scripts to gather data and deploy whatever was needed. I had a hell of time with it and had to replace my router and remove all IoT devices, thoroughly clean my system and reinstall Windows, and flash the stock FW to my phone using Odin. Simply reinstalling Windows always led to a reinfected system, which was crazy to me.

    • @Dead_Weight21
      @Dead_Weight21 Год назад +2

      That sounds scary

    • @slamscaper128
      @slamscaper128 Год назад +7

      @@Dead_Weight21 It really was. I also found all sorts of strange files inside my Google Drive, like a few Linux distros and such. I of course never put them in there.
      When I was trying to clean the system, I found a folder inside the Windows directory with around 100 .ps1 files (Powershell scripts) and I copied them over to a removable drive for later analysis. Sadly, they were gone when I went to find them again. Not sure if my AV killed them silently or if the threat actor deleted them. I really wish I would have kept more of what I found because the malware was amazingly robust.

    • @ManAdam712
      @ManAdam712 Год назад +2

      This happened to me in 2021. My S8 picked it up immediately after Samsung stopped updates w/o notice. - To make a very long story short, I ditched Samsung & I use quite a bit of google/chromium stuff now and EVERYTHING is either still infected, (or re-infected). Your post is the closest description to what I've been struggling to with.
      I could go on forever - I would love for an expert to analyze it all. It's really quite crazy how these system apps or APKs manipulate my network and devices, then hide & respawn like weeds.

    • @riperroxd7664
      @riperroxd7664 Год назад

      ​@@slamscaper128what the actual hell? How can reinstalling windows can end up reinfecting your system? That's terrific

    • @slamscaper128
      @slamscaper128 Год назад +2

      @@riperroxd7664 The malware was very advanced and has multiple ways of remaining persistent after a reinstallation of Windows.

  • @rafaelsuarez7415
    @rafaelsuarez7415 2 года назад +6

    Karspersky used to have a bootable cd you could download free . Boot from it , it would update itself and then scan your hdds .
    Was great.
    Isn it available any more ?

    • @carlospulido6224
      @carlospulido6224 2 года назад +3

      Yes it is available for free. Its called Kaspersky Rescue Kit.

    • @Wahinies
      @Wahinies 2 года назад +1

      Offline scanners seem to be far less effective these days and the update servers take longer than the scans.

  • @Swordshreader
    @Swordshreader Месяц назад +2

    Since the U.S. banned "Kaspersky" what do you recommend instead?

  • @dannylaw7367
    @dannylaw7367 2 года назад +6

    Great job and pretty clear communication also.

  • @leandsonpinheiro
    @leandsonpinheiro 2 года назад +3

    Yes, a video about Tron Script would be awesome

  • @evaldas249
    @evaldas249 Год назад +6

    I am aware this is a channel regarding PCs but a video like this for Android would be greatly appreciated as well.
    Helpful video, by the way!

  • @jonathanalvarez1162
    @jonathanalvarez1162 2 года назад +2

    Thank you so much for this I'm about to try this. I have a really infected system most my registry has been changed and permissions have been taken over. I thought about the tron script but I don't know anything about code or coding so I am very thankful your video popped up. Subscribed !

    • @sceneflexin8701
      @sceneflexin8701 Год назад

      Hey I have this current problem dude, THE EXACT ONE., which service helped you bro? And was your malware capturing your screen like mine is ? It’s scary stuff I need help

  • @SriHarshaChilakapati
    @SriHarshaChilakapati 2 года назад +14

    Just a curious scenario. What if instead of downloading the .exe directly, you right click on the link, select save as and enter a different name without an extension? If CMD opens up, you can then issue `%1 filename` to execute it as an executable. Is that too somehow blocked?

    • @Belisiario
      @Belisiario 2 года назад +5

      Want to know if that works too

  • @kens-jr2vv
    @kens-jr2vv 2 года назад +2

    Just wondering if scanning in safe mode would be a viable option?

  • @Aryan0207
    @Aryan0207 2 года назад +8

    I have a suggestion. Why not test the security of minor browsers. Like Vivaldi, Brave and Opera?

    • @NoneRain_
      @NoneRain_ 2 года назад +1

      Cuz most people don't use em.

  • @AmazingPhilippines1
    @AmazingPhilippines1 Год назад +1

    Many thanks for your computer security discussions!

  • @bobbinatorrah67
    @bobbinatorrah67 2 года назад +5

    Norton be allowed by the malware because the malware was like “eh, what’s he gonna do?”
    JK. Good video!

  • @kamranrasheed4180
    @kamranrasheed4180 2 года назад +1

    Hey when will you test any antivirus? Waiting for Kaspersky vs Bitdefender

  • @andrewr7820
    @andrewr7820 Год назад +4

    An easy mistake that people can make is to have the drive containing the backups be Read/Write for Windows. The backups will be encrypted right along with everything else.
    When backing up a system, I use the Clonezilla live CD (linux-based) with an external USB drive. In order to protect the external drive from infection, do the following: a) shutdown/power-off Windows, b) Insert bootable Clonezilla media DVD/USB, c) power-on machine and run BIOS Setup to change the boot order (assuming no F-key for a boot menu), boot the Clonezilla media, and ONLY THEN plug in the external drive. Finally run Clonezilla to make your backup. I also format the external drive using a Linux-native filesystem like EXT2/3/4, XFS, etc., since Windows still arrogantly ignores any partition types except their own.

  • @deuss001
    @deuss001 Год назад +1

    Would you recommend having them on a bootable usb to completely remove everything, some infected the bios?

  • @Alex_Martz
    @Alex_Martz 2 года назад +4

    What about offline cleaning?, running an antivirus from a bootable USB has always worked great

    • @hugbearsx4
      @hugbearsx4 2 года назад +1

      This is the only way to attempt a serious disinfecton.

    • @7DeadlyJinxs
      @7DeadlyJinxs 2 года назад +1

      @@hugbearsx4 Can't you download the setup files of what you need in another computer and then place those files in an offline portable storage? Being disconnected from the internet from an infected computer should be a given.

    • @hugbearsx4
      @hugbearsx4 2 года назад +1

      @@7DeadlyJinxs If the system is up, then the virus is ACTIVE and the chances of it trying to hide/morph/attack your antivirus are very high. That's why you should shut the system down and boot from a known-to-be-clean antivirus tool, that won't load any of the infected files to be executed - therefore denying the virus the chance to act.

    • @7DeadlyJinxs
      @7DeadlyJinxs 2 года назад +1

      @@hugbearsx4 What?

  • @JayEhEy
    @JayEhEy 7 месяцев назад

    What do you do in instance that, yes fake VR tools download, but it also keeps doing fake reformats? Yes - I have been 5 actual places, two I hired to clean out the system, both have failed.

  • @yallinmuller7137
    @yallinmuller7137 Год назад +3

    Hey someone here who hasn't the least idea about any off this stuff.
    Your video where helpful and i feel at least a bit safer using my laptop. Thanks for your free help.
    Ps: im thinking its time to learn about that stuff since my dad used to fix my shit when my pc was slower than city traffic during rush hour.

  • @athanasiossoulakakis7893
    @athanasiossoulakakis7893 2 года назад +1

    I tried the Norton power eraser but it stuck at 1% and then my PC stopped responding.

    • @goodjohnjr
      @goodjohnjr 2 года назад

      Sometimes it can take a long time, give it some time.

  • @kc9sep
    @kc9sep 2 года назад +4

    Interesting but do note that Norton Power Eraser is very aggressive at times classifying foxit editor and openboard as medium category malware.

    • @HCIbn
      @HCIbn Год назад

      don't use it yes or no?

  • @atulbesra822
    @atulbesra822 Месяц назад

    If a system is deeply infected then trying to clean it when the system is running is futile because the malware has taken control and would not allow any malware removal tool to function. The effective way, in my opinion is to shut down the computer, remove the hard disk, make it into an external USB disk by fitting it into a hard disk enclosure. Then scan it with a good malware removal tool on another computer. With this hard disk in inactive condition, malware removal tool will have realistic chances of identifying and removing the malware.
    Once malware is thus removed, fit the hard disk back into the computer.

  • @Imkadir
    @Imkadir 2 года назад +3

    I got virus on my bios whenever I reinstall new windows I still have it on my pc 😢 welp.

    • @AidenPro-mo2hf
      @AidenPro-mo2hf Месяц назад

      Very unlikely to be on your bios but if it is try Re-Flashing Your BIOS

    • @AidenPro-mo2hf
      @AidenPro-mo2hf Месяц назад

      Why do you think is in your bios

  • @fritsvanzanten3573
    @fritsvanzanten3573 3 месяца назад

    I see NPE detects threads installed on two disinct data, one of them october 13, which was a Thursday, but might have been already Friday in some time zones. In cases like this I go check what I downloaded, visited or installed at that day and time to maybe find when and how I was running the risk.

  • @dantecruzz
    @dantecruzz 2 года назад +5

    Well I'm not an expert in this but i once had a system which was infected by a ransomware, and kept on crashing everytime I wanted to use another anti virus and surprisingly "Hitman Pro" removed the virus (completely) the system was alright and I did a system reset and it was all good

  • @reghardmostert8425
    @reghardmostert8425 9 месяцев назад

    would you recommend to do a clean every month or year? Also in that order which you showed in video every time??

  • @TheCocoaDaddy
    @TheCocoaDaddy 2 года назад +7

    Great video! Question: given the scenario of having an *already* deeply infected system, how did/would you get Norton Power Eraser on the system such that it would able to run correctly? I presume the malware that "tainted" the downloads you demonstrated would also "taint" Norton Power Eraser, if attempted to be downloaded the same way you downloaded the other tools. Thanks for posting!!!!

    • @kruemelfelix
      @kruemelfelix 2 года назад +6

      You could also always use a bootable USB recovery stick from a well known AV brand. This allows to start the AV without Windows booting up in the first place and will work nearly every time.

    • @TheCocoaDaddy
      @TheCocoaDaddy 2 года назад +1

      @@kruemelfelix Do you know of any that include Norton Power Eraser?

    • @itsmebeyonder
      @itsmebeyonder Год назад +1

      @@TheCocoaDaddy
      Perhaps download it to usb drive from other pc?

    • @Lant1s
      @Lant1s Год назад

      @@kruemelfelix​​⁠I have a question for you dont read it if u dont want to. do I have a virus (trojan) if I downloaded something but didn’t open it I just put it to virustotal and deleted it like 1minute after or less after downloading and I didnt have an antivirus (malwarebytes which is the one that detected the virus) then but I downloaded it straight after and scanned it found no threats. but I got really anxious and tried to do a custom scan it scanned for 3h I noticed that system and windows update service would use more cpu if combined up to 16% when I didn’t press anything for a few minutes I googled it and it said I may have malware. Then at around 3hour mark I started playing games (leauge of legends) 1st game was all good didn’t lagg a single time (i was almost always at stable 240fps) but the 2nd I got 2 huge lagspikes 1st lasted 6seconds after i spammed my keyboard it opened the desktop for some reason wallpaper engine turned off and on then i got back into the game the fps was still fine but the 2nd time i lagged for 12secs or so and it didnt end so i turned off the powersupply and the extension cord didnt touch it since. please help me what do I do?

    • @SciK.
      @SciK. Год назад

      Some trojans use an injection method where once you download it, it executes by itself. Although you didnt run it, it still might have injected itself into your pc which in your case would be the windows update service file. If i was you i would reinstall windows and wipe all of your harddrives as well as backing up your data. Better the be safe than sorry. And for your information, the windows update service should really only be using 0-2 percent of your cpu, even if there is an update available. @@Lant1sAlso, are you sure that its a virus? Where did you download this file from?

  • @ricksteven7027
    @ricksteven7027 Год назад

    Thanks!

  • @jaken0
    @jaken0 2 года назад +3

    Hi Leo, I enjoy your videos! Can you maybe consider creating video about Bitdefender's tool used to cleanup the pc from malware. They have something similar to KVRT form Kaspersky. I am thinking to switch from Kaspersky to Bitdefender so I would love to see more comparisions against those products in the future.

    • @brunokoeke8843
      @brunokoeke8843 2 года назад +1

      Hey how's it going ? I'm a bitdefender user and I like it a lot, I'm a bit of a layman in this subject but when I used both, I didn't see much difference between the two, one thing I noticed was that the bitdefender panel has more settings than kaspersky.

  • @techyDotCom
    @techyDotCom 2 года назад

    Can you plz help me ?
    I've in problem with my w11 desktop for unwanted exe hidden running apps. On Pc Manager it's detected as WDCloud.exe which runs hidden chrome windows I can just feel it. but can't remove this. Every time it opens automatic even I uninstall chrome.
    Plz Plz

  • @thefadebeta580
    @thefadebeta580 Год назад +3

    To bad ComboFix is no longer supported that was a great tool!

  • @deusvlad2.083
    @deusvlad2.083 Год назад +1

    A little off topic but For old harddrives does anyone know what program would win between Perfectdisk, Piriform defraggler, My defrag, O&O defrag, Auslogics, Smart Defrag, Wise care 365, windows 7 built in defrag, and any other popular brands? and why is it the best?
    Priority-
    1: Boost harddrive performance.
    2: Extend the lifespan of the harddrive.

  • @oliveiracfabricio
    @oliveiracfabricio 2 года назад +2

    Is it possible for you to do some of those tests on mobile apps? I always follow your suggestions for PC, but on mobile im know nothing. Hhaha Thank you!

  • @HypzEU
    @HypzEU 2 года назад +1

    Kaspersky is the way to go, its to one and only Antivirus I use and I had never any problems so far.

    • @y0._.
      @y0._. 5 месяцев назад

      And prices are a bit unfair for kaspersky hahah it is so cheap

  • @zer00rdie
    @zer00rdie 2 года назад +8

    Having a lifetime license of Malware bytes, I don't think I'll ever swap it out.

    • @SayAhh
      @SayAhh 2 года назад +4

      I actually remember when I saw it but I passed. Later when I wanted one it was no longer available.

  • @peterhansen5804
    @peterhansen5804 Год назад +2

    I have cleaned machines like this many times before, and I prefer to use Process Explorer - the scanning of the running programs/processes can be done via the built-in VirusTotal check. And then it is mostly just a question of "Kill process", then "delete file".

  • @GooogleGoglee
    @GooogleGoglee 2 года назад +7

    Yes please I would like to see a Tron script video! thank you!

  • @krssfloyen_
    @krssfloyen_ Год назад +1

    Guys so my phone has beeen infected by a malware and ads keeps popping on my phone as well as certain files are downloading on my phone. Can someone help me to remove all this? The safe mode option sadly won't show when I press my power button😢 I've also downloaded anti viruses apps but it says they don't detect anything but last time i checked there's still malware on my phone. I'll really appreciate any help. Thank you.

    • @Schubert93
      @Schubert93 Год назад +2

      Delete your whole system, or better to say make a factory reset

    • @krssfloyen_
      @krssfloyen_ Год назад

      i already did that but there's still virus on my phone after. when I left my phone for example to sleep some malicious files are downloading. @@Schubert93

  • @___..Blade..___
    @___..Blade..___ 4 месяца назад +18

    Biggest malware is windows updater

  • @TheKillerman3333
    @TheKillerman3333 Год назад +1

    is the kaspersky free antivirus good?
    like better then the baked in security software for windows 11?

  • @Tomb_Raider123
    @Tomb_Raider123 2 года назад +3

    Hey Leo I hope that you could do a malware test of Trend Micro maximum security. Its been years since this product has been tested by TPSC.

  • @menguardingtheirownwallets6791
    @menguardingtheirownwallets6791 2 года назад +1

    When my Win-7 computer gets a nasty virus, I just reload a system image that I created a few months earlier, at a time where the computer was known to be clean. That's why I keep all of my data and portable browsers on an external hard drive, not on the computer's hard drive itself. After reloading the system image I then use virus removal tools on the external hard drives to clean them up.

  • @rationalbushcraft
    @rationalbushcraft 2 года назад +4

    I would wonder about how command line tools like roguekillercmd and malwarebytes workbench would do. I know malwarebytes workbench is only available to resellers but I find it superior to any other product. I have never had anything block it and it has a ton of other useful tools and scripts. But roguekillercmd has been pretty useful too. Only it is very slow. Clone everything with clonezilla to a network NAS we have then scan.

  • @corumuk67
    @corumuk67 2 года назад +1

    How effective are system restore points or an in place upgrade in cleaning a system? These are my fall back options now that Macrium Reflect free edition is scheduled for end of life.

    • @pcsecuritychannel
      @pcsecuritychannel  2 года назад +1

      Not at all for the most part. System Restore may work if you are lucky, but it often creates other problems.

    • @corumuk67
      @corumuk67 2 года назад +1

      @@pcsecuritychannel OK, well thanks for the links in this vid. Have added NPE and the Kaspersky Tool to my existing portable apps (CCE, EEK, ADWCL Sys Internals etc) so should have sufficient tools. Skipped Hitman Pro though as it's not really free, just a trial.
      Had a pretty nasty infection a couple weeks back from a 'verified' torrent, first in ages (years probably). Windows Defender detected ok but couldn't seem to fix it. Every time it was blocked it was constantly trying to create and run instances of svchost.exe in a temp folder. None of my portable tools seemed to fix it. Ended up running System File Checker, which worked but messed up windows explorer (option for tabs disappeared), so ran an 'In Place Upgrade' and that reset everything back to working condition.

    • @Tabaspu
      @Tabaspu 2 года назад +1

      not sure if this is relevant but comodo time machine saved me from long.official site dont support it now but available in file hosting's,

    • @corumuk67
      @corumuk67 2 года назад +1

      @@Tabaspu Thanks for the suggestion. Looks like a good solution and its also free. The benefit over windows restore seems to be that it can also restore user files and documents, which could be very useful. Not sure if it would work with windows 11 though. I currently use an ancient but pretty good free software called 'create synchronicity' for weekly backups of documents and data, in addition to relying on system restore for rescuing the OS.

  • @HomerChiotakos
    @HomerChiotakos Год назад +4

    One interesting manual technique that worked for me was to change the security properties of some executables that I knew were infected such that the user SYSTEM was denied all privileges on the file and then restart. The error messages were pretty fun.

    • @greyveteran7007
      @greyveteran7007 Год назад +5

      Cut all the Infected files you can identify to your desktop and restart. then you can delete them. or if you can change the file extensions to .old

    • @Saitou2004
      @Saitou2004 Год назад

      Explain this please

  • @lilman2295
    @lilman2295 2 года назад +1

    is it possible that viruses/malware can also cause your computer to be slower then it actually was when you got it?

  • @mr.awesomesauce8412
    @mr.awesomesauce8412 Год назад +3

    Norton Power Eraser being good at removing the malware files is very surprising to me because Norton Antivirus is notorious for being unable to remove malware and asking you to remove it yourself.

    • @TomokoAbe_
      @TomokoAbe_ Год назад

      I never use Norton Antivirus because it does not remove malware by itself. In fact my computer got infected and I had to wipe out the hard drive while I WAS using Norton Antivirus (registered version). It is overrated garbage!

  • @cosmicdebris2223
    @cosmicdebris2223 5 месяцев назад +2

    kaspersky... Russian? errr dunno... naa, can't risk that.

    • @coolnesschannels
      @coolnesschannels 5 месяцев назад +2

      Kaspersky is good, they exposed an exploit utilized by the NSA. By the way, they're banned, so you won't be able to download it

    • @saikyue4462
      @saikyue4462 4 месяца назад

      servers are in switzerland

    • @cosmicdebris2223
      @cosmicdebris2223 4 месяца назад

      @@saikyue4462 how about the programmers? Who are they and perhaps they are located "at home" (not in CH). With datacomms the location of the servers is irrelevant, surely?

    • @saikyue4462
      @saikyue4462 4 месяца назад

      @@cosmicdebris2223 possible

  • @ziadkhalaf198
    @ziadkhalaf198 Год назад +1

    great video, but I wonder what is the best security package that you recommend to prevent malware from entering the computer in first place? I am running Bitdefender firewall/AV for several years now and wondering if you think I should stay with this software or try something better?

    • @da3sii
      @da3sii Год назад +1

      kaspersky is always better

    • @cengizcoskun-fb7md
      @cengizcoskun-fb7md Месяц назад

      @@da3siiçoook uzun yıllar kaspersky kullandım ancak şu aralar bitdefender çok daha iyi. Ben ise comodo firewall kullanıyorum.

  • @coldpizza2453
    @coldpizza2453 2 года назад +3

    👍👍👍

  • @ChrisM541
    @ChrisM541 7 месяцев назад

    Question: why is the '.exe / Return key vector' NOT being intercepted by one/more of these infections? Remember, a 'fully' infected system can very easily patch into any process that happens from the point immediately after pressing the Return key, or, left mouse key double click, or similar. Etc ??? ;)
    If you are able to execute any removal infection program then, quite simply, that means the infection is...inadequate, or, not fully exploiting its 'potential'.
    The best answer to any infection is to re-image with a (hopefully) clean historical file. Clearly, attention will need to be paid to any attached storage, direct or networked.

  • @Derpingtonshere
    @Derpingtonshere Год назад

    Norton labeled things as medium threat that shouldn't be labeled. It labeled programs I made myself as medium threats. Both of these were made via AHK. One hides icons when double clicking on desktop and one turns up or down volume via scroll wheel when hovering over anywhere in the taskbar area. SO, imho norton kinda missed the mark here for security.

  • @xXAkitokunXx
    @xXAkitokunXx 4 месяца назад

    would rKill be a good way to stop these virus or background programs from working then use Tron to clean out your system?

  • @5vonz
    @5vonz 6 месяцев назад

    The frustrating thing about the virus I have right now is that my browser crashes whenever I try to download an antivirus program. Additionally, when I try to open the antivirus file directly, it crashes as well.

  • @IanB1015
    @IanB1015 11 месяцев назад

    Do you have a video showing how to create a flash drive with these scanners on it? Or is it better to download them locally and then delete when done?

  • @thepathnotfound
    @thepathnotfound Год назад

    Why brother? We kept emergency backup images for the ship floor computers etc at a smelter I worked at, that and regular data backups.

  • @TomokoAbe_
    @TomokoAbe_ Год назад

    I had no problems with Avast, but Malwarebytes detected malware which Avast ignored. I used Norton Power Eraser, but one of my very common utilities (photocopier) was detected as malware, which it is not. Wow. I'm thinking of getting the yearly subscription of Malwarebytes. I really like it!

    • @Lant1s
      @Lant1s Год назад

      well if you want to save some money u can create new accounts for malwarebytes and get 14days premium each time

  • @marks5777
    @marks5777 2 года назад +2

    Interesting! Question…. Considering how closely Kaspersky and Bitdefender are in many of your tests, I am wondering how Bitdefender fared where it was substituted for Kaspersky in that sequence?

    • @SacreDro
      @SacreDro Год назад +2

      Bitdefender is on top.

  • @orick92
    @orick92 Год назад +1

    Hi, Thank you for a video! I have question regarding my issue. When I run antivirus for a full scan, windows pops-up and asks for password. Because it password protected by creator and skips scanning on particular folder or app. How can I scan it and make sure I don't have viruses on that password protected files?

  • @gleex8906
    @gleex8906 Год назад

    ily man you so chill and helpful like i would honestly really want to get to know someone like you in my life

  • @carlallison9530
    @carlallison9530 Год назад +1

    you could not download anti virus tools than how could you download norton eraser tool? The norton recovery iso is not bootable with rufus.

  • @shivamkrishn
    @shivamkrishn 2 года назад +2

    Sir I just purchased regular basic Kaspersky Antivirus for a good Xmas deal but now I found it does not have a built in FIREWALL and Kaspersky did not mention this on their product page. Feeling cheated lol.

    • @LakadMatatag2702
      @LakadMatatag2702 2 года назад +2

      Kaspersky real time protection and its ability to remove existing malware/virus is the cream of the cream. You are safe in their hand. I don't know what type of feature you want but no virus/ malware can bypass Kaspersky

    • @shivamkrishn
      @shivamkrishn 2 года назад

      @@LakadMatatag2702 yes I know Kaspersky is the best when it comes to detection and real time protection.
      My suite just doesn't have a firewall, so I'm using built in firewall of windows 11

    • @goodjohnjr
      @goodjohnjr 2 года назад

      @@shivamkrishn That is good enough for most people.

  • @slipk0rvayne17
    @slipk0rvayne17 2 года назад +1

    great video.. but can you run all of these in "Safe mode"? my experience in safe mode with networking has helped

  • @jamzey7568
    @jamzey7568 Год назад

    Thx a lot for your videos, btw wanted to clarify for what do we need malwarebytes? Cause u haven't opened it in video.

  • @kkx8268
    @kkx8268 2 года назад +1

    Is it possible for you to test cortex xdr from palo alto? It should be worth a test because rumors say its better then Kaspersky

  • @rogerturner1881
    @rogerturner1881 Год назад

    I have a OBJ/A virus and i've tried Defender etc but nothing can you recommend something...the only thing that i can do is save my files to another disk and then reinsert to a clean windows 10 pro from the disk.From Greece

  • @RodneyGearheart
    @RodneyGearheart 2 года назад +1

    Can you try running KVRT by renaming the executable to something else to see if you can get it to run that way?

  • @Web3Prep
    @Web3Prep Год назад

    I just realized I’ve been using a fake apple App Store and iCloud for four months. Been working with apple ever since. It’s bad. In my network. It led me here. I used Norton but the bug was so deeply imbedded it would shut it off thereby not giving coverage. Still can’t seem to get rid of it. My network has it too. I’m thinking it’s based on a very big and expensive tv. Won’t let me factory reset either any ideas? Lg 65”.

  • @fritsvanzanten3573
    @fritsvanzanten3573 3 месяца назад

    Funny thing. Had Norton for some years, since I bought this PC. Since Norton's core business seems to be attention seeking, spamming and distraction in general I switched to another AV. Now I tried this NPE you showed and guess what? It finds several threads installed during the period I used Norton. Granted, not serious, I won't remove them.

  • @jalilakl7216
    @jalilakl7216 11 месяцев назад

    what about a slightly infected system? i use Bitdefender, when i do a scan using it it shows nothing but when i scan using Loaris trojan remover it shows some medium threats, one of 'em is a trojan downloader... please what do u recommend me to do?

  • @blo0dwitch
    @blo0dwitch Год назад

    my laptop has some kind of music running in the background and i have nothing opened so i think its an ad of some sort. Ive tried restarting my device and leaving it sit for a while shutdown but those didn’t work so i’m gonna see if this works

  • @Romavodila
    @Romavodila Год назад

    5:12, Just a reminder for me, what programms I should use after downloading premiere pro speech to text 2024 from 1337x

  • @DG-sy3rv
    @DG-sy3rv 2 года назад

    My PC was knocked down by an internet attack two years ago while I was using Kaspersky.