CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Strategies: Malware Removal and Prevention Procedure image
CastleCops
We would like to introduce visitors to an exciting and valuable new resource available at CastleCops called the Malware Removal and Prevention procedure. This procedure is designed to enable users to either partially, or fully clean their systems without the direct aid of an expert. It provides instructions on how to perform a series of antispyware, antivirus and antitrojan scans, as well as, run a system cleaning utility. The generalized scanners we recommend are intended to address a broad spectrum of malware including adware, spyware, trojans, viruses, and browser hijackers. Soon it will become standard practice for all HijackThis (HJT) posters to perform malware removal before posting a HJT log. The ideas and suggestions of numerous staff members have contributed to the development of the final product. We even took a staff poll to decide on a name but such catchy monikers such as "Purging the Parasites" and "Zapping the Crap' were rejected in favor of the humdrum but more descript Malware Removal and Prevention (MRP).

Preliminary testing of MRP has been very promising and feedback has been positive. We have just concluded a six week trial in which the procedure was offered to posters awaiting HJT log assistance. Many of these "waiting posters" cleaned their systems to their satisfaction and elected not to stick around for HJT help. The procedure has also benefited the HJT staff, in that they are presented with cleaner logs and need only assist in eliminating the more tenacious, resistant infections .

Although, preliminary scanning before posting a HJT log is a requirement at several security forums, our procedure is unique in the following way. We ask posters to perform an HJT scan (dubbed the reference log) prior to running any of the automatic detection and removal programs, and once again, after Malware Removal is completed. This enables the HJT staff to see the infected log entries which were initially present but may no longer be visible in the post-scan HJT log. In certain cases, additional removal measures may be indicated to eliminate components known to be associated with entries apparent only in the reference log.

In an effort to accomodate users with varying levels of expertise we have provided help features to augment our basic directions. The instructions for each program included in Malware Removal include both a link to an online tutorial and a link to the corresponding CastleCops support forum. For example, following the Ad-Aware instructions, there is a link to The Ad-Aware FAQ. In the unlikely event that this does not adequately answer a user's query, we also provide a link to the Castle Cops Lavasoft Ad-Aware online support forum. Thus, the user has a variety of self-help options at their disposal to overcome any difficulties they may encounter.

As the name suggests, prevention is also a key focus of MRP. We provide recommendations for users to keep their systems secure in our Malware Prevention section. These include installing a blocking host file, setting secure browser settings, and installing protective programs such as SpywareBaster and IESpyads. We also provide safe surfing tips. The Prevention section will be updated as new solutions and new malware evolve. Future additions may include a topic on advanced tools used to address specific infections or types of infections. Although, we already stress the importance of obtaining Windows Updates in a timely manner, an expansion is planned to include advice on Windows Update troubleshooting. Other additions may include an entry on security tools which support Vista. Any members with expertise in such areas are welcome to contribute.

Our ultimate goal is to educate users to protect their systems and take responsibilitity for their own security. We do not want to offer a quick fix and then see the same user back again with a whole new collection of malware the following week. We want to offer a long term solution so users are armed with the knowledge and tools to effectively protect themselves.
Posted on Saturday, 12 November 2005 @ 04:46:45 UTC by Paul (3915 reads)
[ Trackback ]
image

"Strategies: Malware Removal and Prevention Procedure" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· HotScripts
· W3 Consortium
· CastleCops
· More about CastleCops
· News by Paul


Most read story about CastleCops:
Acceptable Use Policy

block bottom
Article Rating
spacer
Average Score: 4.87
Votes: 8


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer