Malware Removal Guide

Viruses, Spyware, Hackers, Phishes, Key Loggers,  Browser Hijacks,Trojan Horses, Sluggish Computers, Worms, Adware, Zombied Computers, Pop-ups, Spam, Spoofed Email Addresses, Identity Theft, Advanced Fee Fraud, Lottery Scams, Phony Auctions, Dialers, Computer Crashes, Root Kits, Nigerian 419s .... The list of threats and annoyances never seems to stop.

If you are here because you are faced with one or more of these problems, you have found your way to a solution. One that will rid your computer of malware and have it more stable, running faster and much more secure from these types of threats.

Here's a guide that I've put together from my years of experience in cleaning up malware infested computers. What the computer is actually infected with will determine what steps, if any, need to be taken after these to completely rid your system of malware.

Just because no symptoms appear after running the scans does NOT mean your system is fully clean. Please don't stop here. A lot of malware is designed to be invisible to the user so that your computer can be used by criminals for a variety of illegal activities such as sending spam, DDoS attacks, identity theft, etc.

Start by updating your anti-virus software. If you don't have one that you are able to update, download, install and update AVG. This is the free version. You can read about it at Grisoft.com. Do not scan yet. It also may be a good idea to install AVG anyway, as some AVs are often compromised. It is not a good idea to have two AV resident shields operating at the same time, so turn one off.

Download Mike Lin's Startup utility. Unzip and run. Use this utility to disable programs from loading at startup. Uncheck those that are unnecessary and especially those that are malware. Google the filename if you don't know what it is.

Download and unzip IttyBitty Process Manager to your desktop or a convenient folder. Run and kill any processes that you can determine are malware. Write them down so you will know what they are once you go into safe mode.

Download and install CCleaner. Do not run yet.

Download CWShredder. Do not scan yet.

Download, install and update Ad-Aware. Do not scan yet.

Download, install and update Spybot Search & Destroy. Do not scan yet.

Create a folder on your desktop or in a convenient location and download HiJackThis to that folder. Do not scan yet.

Create a folder on your desktop or in a convenient location, download and unzip LSPFix. This is a precaution. Some malware messes up Winsock settings and you could lose your Internet connection when it's uninstalled. LSPFix will repair it.

Turn off System Restore. System Restore creates backups that allow you to return to an earlier time, but it also backs up malware. Remember to turn it back on once your computer is clean again.

REBOOT (Restart) in SAFE MODE

Open CCleaner. The default is to remove all cookies and history as well as other things, so make sure you look through the list of things that CCleaner will remove before you actually run the cleaner. There are two tabs of items, so look at both of them. Run CCleaner to clean up unneeded files from your hard drive(s).

Run CWShredder and choose Fix.

Scan with AVG or your anti-virus software. If it needs to restart to delete some files, let it restart normally.

Continue in Safe Mode.

Launch Ad-Aware. Click on the Gear at the top of the start screen and click the "Scanning" button. Under Drives, Folders and Files, place a check mark next to "Scan within Archives". Click "Proceed." Click "Start" and, in the "Select a scan mode:" section, choose "Perform a full system scan." Click "Next" to begin the scan. When the scan is finished, click "Next." Select any critical objects it finds. You can ignore the MRUs if you want. Click "Next"

Let it restart normally if it asks so it can delete any stubborn files.

Continue in Safe Mode.

Run Spybot Search & Destroy. Click the "Check for Problems" button. When it is finished scanning, click "Fix Selected Problems" and allow Spybot to fix the RED entries. Allow it to rescan at restart if it needs to.

Restart in Normal Mode.

Close all windows if any are open. Run HijackThis and save the log. Have someone knowledgeable in HijackThis help you analyze the log. They should be able to tell you if there are any additional tools needed to finish the cleanup.

One option is to post to one of the various forums that have trained responders that can help you. Read the FAQs before you post. Most of these forums are overwhelmed with people posting logs, so be patient.

One other option is to use HijackThis Log Analyzer to do it yourself.

You will need to keep running HijackThis until your log is clean. Often malware will come right back until you complete eradicate it. So continue looking for a solution until it's clean.

  

[Malware Removal Guide] [Secure Your Computer]

For inquires or, to report dead links, etc. mail
webmaster <at> malwareremovalguide <dot> com