I have a friend that has a computer that has Malware and want to help. Her computer doesn't have Internet Access and I'm trying to give her instruction on how to upload HJT and post a log to What the Tech forumz. From their She can receive instruction from someone better qualified in Malware removal. But I dont know how to go about it. I'm pretty sure she can download to some memory stick, I believe the size of HJT micro trend v. 2.0.2 is 793.3K and then upload it to the computer, booted up in safe mode right? Well like I said I only have an Idea of how to do it but would really like some expert advice.
Yes thats just what you do, download it on a clean system, then transfer it over, run it, then save\transfer the report back for uploading for the pro's to help with in the appropriate section.
The first thing we need to do though is make sure the clean system remains clean, I suggest getting Flash Disinfector, have them plug the thumb drive into the clean system and run this file, it will help stop that from getting infected from the other system when you transfer the report back to it.
I also suggest ensuring they have ALL the latest updates, security patches etc available, and then check what protection they have, make sure it's good enough to protect them, and that they are all fully updated BEFORE plugging the thumb drive back into it from the infected system.
Another level of caution is to open the My Computer on the clean system with the thumb drive plugged in, then right click on it and select scan via….. whatever protection comes up via right click, and have them do this BEFORE going into the drive, it minimises the risk of getting the clean system infected, maybe the pro's have a few more words of wisdom for you, but thats pretty much the only way you have of doing this without net access on the infected system, hope this helps.
Thank you. Is it possible to get the computer infected by just uploading the HJT log from the other PC that is infected?
Download HJT to a memory stick
Upload it to the PC that is infected
Run a scan, save the log to the memory stick
Upload the log to the PC with internet access
Post it on What the Tech
Can you tell me where along these lines is the PC going to get infected, and how to prevent that?
It's just the way I see it I'm only uploading the HJT log not the files or programs. I dont really know
how that works. But can you explain it to a novice such as myself.
Your assistance is very much appreciated
Thank you
The HJT log you upload will actually be a .txt file. It is unlikely that you transfer an infection with a text file. However, if you do not run Flash Disenfector (as already suggested) first, it is likely that autorun.inf will "run" the flash drive as soon as you plug it in. Unbeknownst to you, the flash drive could be harboring an infection in addition to the .txt file you are transferring. If so, you will transfer the infection.
Run Flash Disenfector on the memory stick from the "non-infected" machine
Yes it is highly possible to infect a clean system this way, and the nastier the infection the more probable this becomes, you have to remember the 1st job of an infection is to shut down protection and infect anything else it can, BUT, that said I regularly connect heavily infected drives on my system to sort them out, but I have an idea what to watch out for, and what to do, and more importantly NOT to do, yes I can get caught out, I'm only human, but at the end of the day it's nothing a reinstall can't sort out, and often when a system is that badly infected it is the way I go, because even when it's cleaned up theres no knowing how much corruption was caused, when I get a case like that I simply recover any files they need then low level format the drive.
Now given that system has no net access, all we can do (other than straight format etc) is to take as many precautions as we can to protect the clean system, hence the above, installing that file to the thumb drive BEFORE touching the infected system will help protect it, a lot, TBH ALL thumb drives should have it installed when being used between numerous systems where you have no control over whats gone on prior, it makes it harder for it to get infected.
Stick on top of that the rest of the above, the more the better IMHO, they will be as safe as is possible to be, but warning them about warning signs such as unknown files asking for access etc and not touching them, theres not much more you can do, but they must be really strict when connecting the thumb drive, because the must NOT access it until AFTER scanning it, they must also update the protection BEFORE connecting the drive as well, but I can tell you the following protection has scan via right click ability:-
a-squared Free
Malwarebytes' Anti-Malware
SUPERAntiSpyware
Avast
Spybot-S&D
I suggest they remove all files from the thumb drive so it's blank, worst case they wont lose anything on it, install the file above, then add Hijack to it and transfer it to the infected system, run it etc, for which you will probably need to access it via the My Computer - Thumb Drive Name, cut and paste the Hijack file into it's own folder on the desktop, then run it as one would to create a report to get the help from the pro's.
I say cut and paste because I don't want a .exe file transferring back to the clean system, and given the report is a notepad file it's ability to transfer an infection via it is not as likely as a .exe file is, then updating definition files before plugging the report back into the clean system, and scanning via right click with ALL the protection they can BEFORE accessing the drive is about as safe as you can get IMHO, the pro's may well have different opinions\suggestions, but this is what I do with infected drives connected to my system, and to date I have yet to be infected doing this.
I don't suggest this is a dead cert safe practise, if an infection is nasty enough who knows what it can do, there is always a "risk" connecting to an infected system, and it should not be done lightly, but when there are no other options, the method I suggest here is as safe as you can get, at least in my experience, the pro's may well know more than I on this, but the danger point is when you connect back to the clean system after being connected to an infected system, more so when bringing files back to the clean system, hence scanning via right click BEFORE accessing the drive, if all reports come back clean then theres nothing more you can do.
But remember, some infections can be that new that even the protection makers don't know about it yet, and as such they wont be able to detect it, but fortunately thats quite rare, they are usually very quick out with protection against new threats, so there is always a risk, but it's also why I said about updating definitions BEFORE connecting the drive, some of those I listed above update several times a day at times, so new definitions can be added at any time, so don't think because it updated 1 hour ago that it automatically has the latest definitions still, it's quite possible another update could have been released, so always check for maximum safety, hope this helps.
*edit
Dam my slow typing lol, my method may be belt and braces, but it's served me well over the years, but at least you have a pro confirming (pretty much) what I have said, albeit in simpler terms lol, it's hard to tell someone to do a risky procedure without briefing them fully to make them as safe as possible first, and that makes replies look scary at times, but if you follow my suggestion it's as safe as you can get when doing this that I am aware of anyway.
You don't upload Flash Disinfector to the thumb drive, you download it to the desktop on the clean system, insert the thumb drive then you run it, this then places what it needs onto the thumb drive, it is a hidden file so you wont see anything when it's done, you will simply get a message saying it's done, after which put HJT onto it and move to the other system etc..
Everything else you've said is pretty much right. just remember Malwarebytes (and any other protection used) is to be installed on the clean system to protect that system when putting the drive back into it from the infected system so the thumb drive can be scanned before going into it.
So in simple terms it's like this:-
Download the required files to the clean system.
Run\Install (and update) required files on the clean system.
Upload HJT to the thumb drive.
Move HJT to infected system and run it etc.
Save the log to the thumb drive.
Scan thumb drive (update definitions 1st) on clean system BEFORE entering it.
If all is well then post the log and let the pro's work they're magic.
Should they require further files\scans then repeat this with those and job done
Hope that tells you what you need.