Remember, you MUST register to post on the Fiesta Fan forums. It's completely free to join. Just click HERE to become a member for free!


REGISTER NOW TO REMOVE ALL ADS ON THIS FORUM!

Reply
 
Thread Tools Search this Thread Display Modes
Old 12-16-2008, 03:07 PM   #1
lamchopz
Goblin Swordman
 

In-Game Name: yummy
Current Level: skewl
Posts: 463
lamchopz has disabled reputation
Malware removal guide

Malware (malicious software) includes virus, Trojan, worm, spyware, adware, rootkit, etc. Click here if you're interested in reading more about the definitions of spyware by the Antispyware Coalition.

Your computer may be infected if you see:
  • persistent popups that flood your screen
  • your wallpaper has been mysteriously changed to something weird
  • browser homepage is changed to something else and can't be reset
  • programs nagging you to buy full version because they find lots of "risks" on your machine. You installed these from some sites or popups that jumped out of nowhere.
  • computer is really really sluggish and you're sure that you have followed these steps to speed up your PC.

Now, follow these steps if you're sure your system is infected:

First thing you do is update your existing antivirus/antispyware programs and scan your computer with them.

The two free applications that are now recommended by PCPitstop security forum are Malwarebytes' Antimalware and SUPERAntispyware.

Download Malwarebytes' Antimalware. Then:
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Download and install SUPERAntispyware. Then:
  • Launch SUPERAntiSpyware
  • Click Check for Updates and update to the latest definitions.
  • Click Scan your Computer.
  • Check all boxes in the Scan Location box.
  • Check the Complete Scan radio button.
  • Click Close.
  • Click Next.
  • SUPERAntiSpyware will now scan your computer, please be patient.
  • When finished it will present you with a summary of its findings.
  • Click OK.
  • The Removal Screen will open.
  • Check the items in the list to mark them for Quarantine.
  • Click Next and SAS will Quarantine them.

Ideally, you should disconnect your Internet while the scans are being performed (i.e. after the updates have finished). Some crafty malware can contact their servers and receive instructions to change themselves, making it harder for them to be detected.

Once that is done, download HijackThis. Then:
  • Save HJTInstall.exe to your desktop.
  • Double-click on HJTInstall.exe to run the program.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis.
  • Accept the license agreement by clicking the "I Accept" button.
  • Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
  • Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
  • Click "Save log" to save the log file and then the log will open in Notepad.
  • Click on Edit>Select All, then click on "Edit>Copy" to copy the entire contents of the log.
  • Go to this forum and start a new thread. Registration is free.
  • Make sure you explain the problem as well as mentioning that you have tried the two programs above. If you know the name of the malware that is causing the problem, please mention it in the thread title.

The most common mistake is that the user is satisfied when the antispyware/antivirus appear to have remove the culprits. To make sure that the malware has been removed completely, you need to folllow the last step: use HijackThis, then wait for further instructions from the forum helper to verify that you're totally malware-free.
__________________
-------------------------------------------------
Primum non nocere

-------------------------------------------------
lamchopz is offline   Reply With Quote
Old 12-16-2008, 04:54 PM   #2
Belaslav
Yank me.


 
Belaslav's Avatar
 

In-Game Name: -quit-
Current Level: -quit-
Server: Teva
Posts: 1,502
Belaslav has much to be proud ofBelaslav has much to be proud ofBelaslav has much to be proud ofBelaslav has much to be proud ofBelaslav has much to be proud ofBelaslav has much to be proud ofBelaslav has much to be proud ofBelaslav has much to be proud ofBelaslav has much to be proud ofBelaslav has much to be proud of
Send a message via MSN to Belaslav
Is there a guide on how to read HijackThis logs yourself to see if you are infected or not?
__________________


Free software for Virus, Malware, Adware and Spyware protection: Avast and Malwarebytes' Anti-Malware.

Those of you using Firefox I recommend NoScript and AdBlock Plus addons.
Belaslav is offline   Reply With Quote
Old 12-17-2008, 05:08 AM   #3
lamchopz
Goblin Swordman
 

In-Game Name: yummy
Current Level: skewl
Posts: 463
lamchopz has disabled reputation
Here's the guide for pro-active HJT analysis.

Keep in mind, though, that HJT is not the ultimate antimalware tool. In many cases, you will need to employ other specialised applications to get the job done.

In that case, and if you're interested, sign up for a HJT Traineeship at any one of the following forums (there are more but these are the ones I have visited and know that they're great):

After the training, please stay as one of their HJT Advisors and help other unfortunate users. You don't need to stay on the compy 24/7 to help. Just do as much as you can. =]
__________________
-------------------------------------------------
Primum non nocere

-------------------------------------------------
lamchopz is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 11:20 AM.
Design by Vjacheslav Trushkin, color scheme by ColorizeIt!.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.