Tuesday, August 16, 2005

WinPFind – Search the malware by their pattern!

Sometimes, it becomes very difficult to remove some spyware infection. This is because, even after virus/spyware scans, these spywares will re-spawn. In these cases, we have to manually search the "bad" files and delete them! This is simply not feasible, because of the large number of files present in a system.

But, there is a tool called WinPFind, to help us in this situation! Most of the spyware/virus files follow a "pattern". A pattern may be in the form of "packing" (file type compression) like UPX or file location (most of these files are located Windows, System32 or System folders) etc or possible Registry locations.

WinPFind searches for the above mentioned and some more patterns and gives a list of files and Registry entries satisfying these patterns. From this list, we can identify "bad" files and Registry entries and remove them for good. It is to be noted that WinPFind searches for files with specific patterns and not the "bad" file itself. Hence, the result of WinPFind scan will also contain legitimate files too. So, be careful while analyzing the log of WinPFind!

Get it here.

4 Comments:

Anonymous Anonymous said...

Love your site - explanations in real English, not tekspeak!
I'm bookmarking it : )

12:56 AM  
Blogger swatkat said...

Thank you :)

1:29 AM  
Anonymous Anonymous said...

The information is simple.
And simple is what I need.
A nicely written simple explanation from which I can delve deeper.
Well done

5:10 PM  
Anonymous Free Antivirus Download said...

malware are destruct every thing in our system. free antivirus download

3:07 PM  

Post a Comment

<< Home