Viruses,
Spyware, Hackers, Phishes, Key Loggers, Browser Hijacks,Trojan
Horses, Sluggish Computers, Worms, Adware, Zombied Computers, Pop-ups,
Spam, Spoofed Email Addresses, Identity Theft, Advanced Fee Fraud,
Lottery Scams, Phony Auctions, Dialers, Computer Crashes, Root Kits,
Nigerian 419s .... The list of threats and annoyances never seems to
stop.
If
you are here because you are faced with one or more of these problems,
you have found your way to a solution. One that will rid your computer
of malware and have it more stable, running faster and much more secure
from these types of threats.
Here's
a guide that I've put together from my years of experience in cleaning
up malware infested computers. What the computer is actually infected
with will determine what steps, if any, need to be taken after these to
completely rid your system of malware.
Just
because no symptoms appear after running the scans does NOT mean your
system is fully clean. Please don't stop here. A lot of malware is
designed to be invisible to the user so that your computer can be used
by criminals for a variety of illegal activities such as sending spam,
DDoS attacks, identity theft, etc.
Start by updating your anti-virus software. If you don't have one that you are able to update, download, install and update AVG. This is the free version. You can read about it at Grisoft.com.
Do not scan yet. It also may be a good idea to install AVG anyway, as
some AVs are often compromised. It is not a good idea to have two AV
resident shields operating at the same time, so turn one off.
Download Mike Lin's Startup
utility. Unzip and run. Use this utility to disable programs from
loading at startup. Uncheck those that are unnecessary and especially
those that are malware. Google the filename if you don't know what it
is.
Download and unzip IttyBitty Process Manager
to your desktop or a convenient folder. Run and kill any processes that
you can determine are malware. Write them down so you will know what
they are once you go into safe mode.
Download and install CCleaner. Do not run yet.
Download CWShredder. Do not scan yet.
Download, install and update Ad-Aware. Do not scan yet.
Download, install and update Spybot Search & Destroy. Do not scan yet.
Create a folder on your desktop or in a convenient location and download HiJackThis to that folder. Do not scan yet.
Create a folder on your desktop or in a convenient location, download and unzip LSPFix.
This is a precaution. Some malware messes up Winsock settings and you
could lose your Internet connection when it's uninstalled. LSPFix will
repair it.
Turn off System Restore.
System Restore creates backups that allow you to return to an earlier
time, but it also backs up malware. Remember to turn it back on once
your computer is clean again.
REBOOT (Restart) in SAFE MODE
Open
CCleaner. The default is to remove all cookies and history as well as
other things, so make sure you look through the list of things that
CCleaner will remove before you actually run the cleaner. There are two
tabs of items, so look at both of them. Run CCleaner to clean up
unneeded files from your hard drive(s).
Run CWShredder and choose Fix.
Scan with AVG or your anti-virus software. If it needs to restart to delete some files, let it restart normally.
Continue in Safe Mode.
Launch
Ad-Aware. Click on the Gear at the top of the start screen and click
the "Scanning" button. Under Drives, Folders and Files, place a check
mark next to "Scan within Archives". Click "Proceed." Click "Start"
and, in the "Select a scan mode:" section, choose "Perform a full
system scan." Click "Next" to begin the scan. When the scan is
finished, click "Next." Select any critical objects it finds. You can
ignore the MRUs if you want. Click "Next"
Let it restart normally if it asks so it can delete any stubborn files.
Continue in Safe Mode.
Run
Spybot Search & Destroy. Click the "Check for Problems" button.
When it is finished scanning, click "Fix Selected Problems" and allow
Spybot to fix the RED entries. Allow it to rescan at restart if it
needs to.
Restart in Normal Mode.
Close
all windows if any are open. Run HijackThis and save the log. Have
someone knowledgeable in HijackThis help you analyze the log. They
should be able to tell you if there are any additional tools needed to
finish the cleanup.
One
option is to post to one of the various forums that have trained
responders that can help you. Read the FAQs before you post. Most of
these forums are overwhelmed with people posting logs, so be patient.
One other option is to use HijackThis Log Analyzer to do it yourself.
You will need to keep running HijackThis until your log is clean. Often malware will come right back until you complete eradicate it. So continue looking for a solution until it's clean.
|