In the ongoing war against malware threats, you need tools that will baseline your system, detect vulnerabilities, and remove existing malware.
Cybercriminals are putting forth every effort to make malware difficult to detect. Successfully, I might add. Ever optimistic, I thought I would have a go at providing information on how to make their job a little tougher.
Baselining is an important reference
Knowing exactly what is running on a computer is paramount to learning what shouldn’t be. Creating a reference baseline is the best way I’ve found to accomplish this. Let’s look at three applications that do just that.
1: Microsoft Process Explorer (formerly Sysinternals)
Process Explorer provides an excellent way to determine what processes are running on a computer. It also describes the function of each process.
More important, you can use Process Explorer to create a baseline of the running processes used by the computer when it’s operating correctly. If for some reason the computer starts behaving poorly, run Process Explorer again and compare the scans. Any differences will be good places to start looking for malware.
2: Trend Micro’s HiJackThis
HiJackThis is Process Explorer on steroids, making the application somewhat daunting to those of us not completely familiar with operating systems. Still, running HiJackThis before having malware problems creates a great reference baseline, making it easy to spot changes.
If it’s too late to run a baseline scan, do not fear. Several Web sites offer online applications that will automatically analyze the log file from HiJackThis, pointing out possible conflicts. Two that I use are HiJackThis.de Security and NetworkTechs.com. If you would rather have trained experts help, I would recommend WindowSecurity.com’s HiJackThis forum.
3: Kaspersky’s GetSystemInfo
Kaspersky has an application similar to HiJackThis called GetSystemInfo. I like the fact that Kaspersky has an online parser. Just upload the log file and the parser will point out any disparities.
GetSystemInfo, like the other scanners, is a good way to keep track of what’s on the computer, and if need be, it can help find any malware that happens to sneak in.
Be careful: As I alluded to earlier, removing processes suggested by the scanners is not for the faint of heart. It requires in-depth knowledge of operating systems or being able to compare before and after scans.
Next, I’d like to discuss two vulnerability scanners.
It’s simple: No vulnerabilities, no malware
Anti-malware includes any program that combats malware, whether it’s real-time protection or detection and removal of existing malware. Vulnerability scanners proactively detect vulnerabilities so that malware can’t gain a foothold. I’d rather update applications than chase malware any day.
4: Microsoft Baseline Security Analyzer
Microsoft Baseline Security Analyzer (MBSA) is a vulnerability scanner that detects insecure configuration settings and checks all installed Microsoft products for missing security updates. I recommend using MBSA when upper management needs convincing. Making a case for needing a vulnerability scanner is sometimes easier if the product is from the OEM.
5: Secunia inspection scanners
Secunia’s scanners are similar to MBSA when it comes to Microsoft products. But unlike MBSA, Secunia products also scan hundreds of third-party applications, which gives Secunia a distinct advantage.
All the Secunia scanners, online and client-side, have an intuitive way of determining what is wrong and how to rectify it. They usually offer a link to the application’s Web page, where the update can be downloaded.
Not always simple
Remember when I said, “It’s simple: No vulnerabilities, no malware”? Well, it’s not exactly that easy. It would be, except for those nasty things called zero-day exploits and zero-day viruses. That’s where antivirus applications come into play, especially if they use heuristics.
6: Antivirus programs
Lately, antivirus software is getting little respect. Like everyone, I get frustrated when my antivirus program misses malcode that other scanners mange to find. Still, I would not run a computer without antivirus. It’s too risky. I subscribe to the layered approach when it comes to security.
Choosing the correct antivirus application is personal. Comments come fast and furious when someone asks TechRepublic members which one is the best. A majority feel that any of the free versions are fine for nonbusiness use. I use Avast or Comodo on Windows machines.
Anti-malware enforcers
The next class of anti-malware is capable of both detecting and removing malware. I’m sure you are wondering why not just use these from the start. I wish it was that simple.
Scanners use signature files and heuristics to detect malware. Malware developers know all about each and can morph their code, which then nullifies signature files and confuses heuristics. That’s why malware scanners aren’t the cure-all answer. Maybe someday.
More caution: I want to emphasize that you need to be careful when picking malware scanners. The bad guys like to disguise malware (antivirus 2009) as a malware scanner, claiming it will solve all your problems. All four of the scanners I have chosen are recommended by experts.
7: Microsoft’s Malicious Software Removal Tool
Malicious Software Removal Tool (MSRT) is a good general malware removal tool, simply because Microsoft should know whether the scanned code is theirs or not. Three things I like about MSRT are:
- The scan and removal process is automated.
- Windows Update keeps the signature file database current automatically.
- It has the advantage of being an OEM product, thus it’s less intrusive and more likely to be accepted by management.
8: SUPERAntiSpyware
SUPERAntiSpyware is another general purpose scanner that does a good job of detecting and removing most malware. I have used it on several occasions and found it to be more than adequate.
A number of TechRepublic members have mentioned to me that SUPERAntiSpyware was the only scanner they found capable of completely removing antivirus 2009 (malware).
9: Malwarebyte’s Anti-Malware
Malwarebytes Anti-Malware (MBAM) malware scanner was the most successful of the four I tested. I was first introduced to it by world-renowned malware expert Dr. Jose Nazario of Arbor Networks. For a detailed explanation of how MBAM works, refer to my post Malware scanners: MBAM is best of breed.
Still, MBAM does not catch everything. As I pointed out in the MBAM article, it misses some of the more sophisticated malware, especially rootkits. When that happens, I turn to the next malware scanner.
10: GMER
In Rootkits: Is removing them even possible?, I explained why it’s hard to find rootkit malware. Fortunately, GMER is one of the best when it comes to detecting and removing rootkits — enough so that it’s recommended by Dr. Nazario.
Source: http://blogs.techrepublic.com


Nice dispatch and this enter helped me alot in my college assignement. Say thank you you on your information.
Nice dispatch and this mail helped me alot in my college assignement. Say thank you you as your information.
I think that that was really interesting. Good post!
Great article. There’s a lot of good info here, though I did want to let you know something – I am running Mac OS X with the latest beta of Firefox, and the layout of your blog is kind of quirky for me. I can understand the articles, but the navigation doesn’t function so well.
This is a root blog and I like reading it every morning lead one’s thanks you
in every nook sharing it!
Opulently I assent to but I dream the brief should secure more info then it has.
I truly believe that we have reached the point where technology has become one with our lives, and I am 99% certain that we have passed the point of no return in our relationship with technology.
I don’t mean this in a bad way, of course! Societal concerns aside… I just hope that as technology further develops, the possibility of uploading our brains onto a digital medium becomes a true reality. It’s one of the things I really wish I could see in my lifetime.
(Posted on Nintendo DS running [url=http://kwstar88.insanejournal.com/397.html]R4i Card[/url] DS SKu2)
Well I agree but I contemplate the brief should prepare more info then it has.
Blog looks great! Always looking for motivating blogs to keep mine going!
wow this is an excellent post, defo bookmarking and visiting this site again.
Nice fill someone in on and this mail helped me alot in my college assignement. Thank you seeking your information.
very useful read. I would love to follow you on twitter.
blog.warezone.com; You saved my day again.
Hey I just received a alert from my antivirus when I opened your page do you know how come this occured? Could it possibly from your ads or something? Thanks, really odd i hope it was harmless?
I like your articles on your website, but it looks as though your RSS feed is getting a 404 error? Maybe it has something to do with your host. I just thought from webmaster to webmaster I would warn you of this problem so you don’t miss out on potential subscribers! If it still works for you have a friend try it, could be blocking external connections.
Excellent Web site! I was wondering if I could quote a portion of your site and use a few things for a term paper. Please email me whether its ok or not. Thanks
Coffee Maker…
[...]Listed below are links from authority web sites that have been utilized as a source to this post [...]…
Great article. There’s a lot of good info here, though I did want to let you know something – I am running Ubuntu with the latest beta of Firefox, and the look and feel of your blog is kind of bizarre for me. I can understand the articles, but the navigation doesn’t work so well.
Wonderful Website! I wanted to ask if I could quote a portion of your web page and use a few items for a term paper. Please email me whether its ok or not. Thanks
Good dispatch and this post helped me alot in my college assignement. Gratefulness you for your information.
i definitely love all your writing kind, very useful.
don’t give up as well as keep creating due to the fact it simply just nicely to follow it.
excited to view much more of your current articles, good bye
Good info. Tweeted about it. I’ll bookmark this post too later.
Intriguing, how do I apply this?