Viruses/Spyware/Malware Removal Guide


Recommended Posts

Viruses/Spyware/Malware Removal Guide

Note:

  • This Guide is intended for members who wish to clean their computers of Viruses/Spyware/Malware infections
  • This Guide is designed as a first steps in cleaning your computer, and should not be used as a one stop fix all
  • Users doing online banking, or who have sensitive data on their systems, may prefer to backup/reinstall clean

Many known Viruses; Spywares and Malware issues, may have a removal tool already available on the Net
If you are are aware of the specific infection(s) name, please search Google for the removal tool (if exists)
To install and run all the free tools below, your User Account should have Administrator privileges
To confirm if you are an Administrator privileged account holder, click on Start > Run > control nusrmgr.cpl
Note: Vista and Windows 7 come with "User Account Control" (UAC) You can read more about this HERE
Final Note: Before running the free updated program scans listed below, please disconnect from your Network/Internet
This will reduce the possibility of any further Malwares from being installed on your computer (during the scan process)

> Antivirus:
Your present single installed Antivirus software program, must be fully updated online (if possible)
Complete a full scan with your (fully updated) Antivirus software, and remove all found Viruses
If you are not using any Antivirus software you should download/install/update one immediately
Here are two recommended free Antivirus programs, to choose from:

If you cannot download or update your Antivirus, you can also do an online scan with Kaspersky scan HERE

> Temp Files:

Generally if a computer is infected, so are the many temp files located in many areas on your system

Removing these temp files is best done through one of the many cleaners on the Net, I recommend:

  • icon48.gifCCleaner. Direct link here >>
http://www.ccleaner....loadbinportable

> AntiMalware:

Whilst many Antivirus programs also include AntiMalware removal, it is still strongly advised to scan with a specialized removal tool

  • malwarebytesgc8.pngMalwarebytes. Direct link here >>
http://www.malwareby.../mbam-setup.exe

Once Downloaded and Installed, make sure to fully update Malwarebytes, or run the Manual Update file

Complete a QUICK scan, Once the scan is completed, remove all found malwares at the end of the scan

> AntiSpyware:

As above, it is still strongly advised to scan with a specialized AntiSpyware removal tool

  • SASLogo48x48.gifSUPERAntiSpyware. Direct link here >>
http://downloads.sup...AntiSpyware.exe

Once Downloaded and Installed, make sure to fully update SUPERAntiSpyware, or run the Manual Update file

Complete a full scan, Once the scan is completed, you may need to restart your computer to finalize the removal

> Further Specialized Malware Removal Tools:

16lxye9.jpg

Combofix

      • You are advised to read the Combofix Instructions
HERE before using this specialized program
Your Antivirus software must be disabled before running a scan. Combofix download link HERE
After downloading and starting Combofix you will be given warnings and accepting to continue questions
Your Desktop may temporarily disappear during the scan (this is normal) Your clock settings may change as well
Allow Combofix to run a scan (usually lasting approximately 10mins) Your system may also restart once finished
Combofix will automatically save the log file to C:\combofix.txt, which may need to be attached to a new topic

IE_icon_internetexplorer.png

RIES
(
R
eset
I
nternet
E
xplorer
S
ettings)

Even if you use another browser, RIES can
still
help.

This is because Internet Explorer is part of Windows itself.

RIES will
reset
all Internet Explorer's settings, and:
  • All Internet temp files are removed

    All extensions are disabled (Toolbars, Browser Extensions, and Browser Helper Objects)

    All ActiveX controls are restored

IE8 Users can run the MS Fixit tool:
w8kzfo.jpg

IE7 users can view the Video on how to Reset IE

29gd0dx.jpg

Startup Control Panel

This program is useful in removing known Windows startup
shortcuts
(not the program itself)

This program is preferred over Windows MSconfig (a diagnostic utility
only
)

You can read more on why not to use MSconfig to disable Windows startups

Read more about Startup Control Panel
. Direct download

There is also another (much better, but extremely critical in use) program

You are advised to only use Startup Control Panel though

pn4_p_java.gifJavaRa

JavaRa removes old and redundant versions of the Java Runtime Environment (JRE)

It can also check for newest Java Runtime Environment (JRE) updates, and remove autostart update and icon entry

Read more about JavaRa
. Direct download

hjtsy1.jpg

HijackThis

HijackThis on its own cannot remove Malware. It is designed to show support users certain settings in your computer

You are advised to read the warnings and excellent tutorial
. HijackThis direct download link

Support members may ask for a HJT "logfile", which can be provided by clicking on:
Do a system scan and save a logfile

> Restart

One more point of interest is Windows Updates. Once your system is clean, I highly recommend doing all MS Updates

This will help keep your Windows usage more secure online, and will likely keep you updated with Windows improvements

Hopefully, your system will be fully cleaned of any Viruses / Spywares / Malware from performing all of the above

Note that you can also perform most scans in Windows Safe Mode (accessed by pressing F8 key at system startup)

If you still require help in removing bugs, please create a new topic in the Software Discussion & Assistance forum

Also include what the fault is, and what steps you have already taken to resolve it. Good luck. and surf safe :)

This topic to be used as an initial removal guide only, it may not resolve all Virus/Malware infections on your system

Link to comment
https://www.neowin.net/forum/topic/795114-virusesspywaremalware-removal-guide/
Share on other sites

  • 2 weeks later...

Great guide! May I recommend adding Spybot-S&D? It's a great anti-spyware tool that works well with removing and preventing spyware infections. Best of all, it's 100% free and updated quite frequently.

Avira and Avast? :laugh: I suggest fixing that because it ruins a (IMO) great guide.

I'd love to know why it "ruins" the guide. And don't mention any anti-virus software that isn't free because that's the point here.

Hm I wasn't assigned to my own guide!

Anyway, to answer the above

Spybots is not good

Avira is the best, and its what I use (I put Avast for an alternative free Antivirus ;))

The PE bootCD will not repair Registry (malware) entries

And I still have Edit rights on the Guide, but find it presently perfect :) But I'm open for friendly debate

RIES (Reset Internet Explorer Settings

Startup Control Panel

SUPERAntiSpyware can do both of those, and reset MANY more settings back to default. all you have to do is go to the "tools" tab. it's why i think it's the #1 malware cleaner over MBAM

super antispyware and malwarebytes together are very good but spybot does not have the edge it used to have.i do not recommend it these days but super antispyware and malwarebytes i do.

super antispyware and malwarebytes together are very good but spybot does not have the edge it used to have.i do not recommend it these days but super antispyware and malwarebytes i do.

Should they be used together, or can I get by by picking one? If you had to choose, which would you? Thanks.

Should they be used together, or can I get by by picking one? If you had to choose, which would you? Thanks.

you could get by with just one of them, but you are of course better off if you use both of them. if you only wanna use one i would pick malwarebytes myself as i find it just a tad bit better than super antispyware.

Should they be used together, or can I get by by picking one? If you had to choose, which would you? Thanks.

i would choose malwarebytes if i had to choose between them. but it would be better to use them together.

Isnt it a bit risky to use two antispyware programs? Unless they are not both running real time that is... i am not sure as i dont use any on my machine (and never been infected either).

I know running two antivirus software is not recommended, so im guessing using two antispyware programs is not a good idea either.

That's ironic, I have never thought of that.

Certainly you can only have 1 Antivirus installed (with live protect) at any one time

This is because if a Virus is found one Antivirus will try to move it to the quarantine folder. Just at the same time, the other Antivirus will see a Virus being moved to some strange folder and then try to move it to its quarantine folder. Basically an endless loop.

But with Antispyware most tech boards recommend running minimum 2 AntiSpyware/Malware programs (by the way, I run none as well, but I do start them up and scan (updated) every now and then)

I think this "2" Antispywar/malware programs comes from having 2 different scanners, ie where one scans for Spyware (specifically speaking) and one scans for say Trojans (only) Mind you, both being Malware.

I think this is the reason why users need to scan with one at a time. Antivirus first (that may contain some Antimalware scanning too. Then scan with another program, such as Malwarebytes, and therefore if Malwarebytes finds an infection, at least the Antivirus program won't jump in (ie its already done its full scanning)

But, (your question) What if there are 2 running together? (at the same time) As requested by most Virus/Malware removal forums.

There is some relief though. A full manual scan of any live protecting AntiMalware program will in actual fact repair/remove infections at the end of the scan, therefore passing by any other live protecting scanner already, that also may have removed the infection already, therefore no concern either way (and it follows the above guide ;) )

But (again) 2 live Antimalware programs running together (not under manual scan) That hypothetically find the same infection, and then both try to remove the infection (at the same time) can be a concern :/ Similar to AntiVirus programs (if two were incorrectly installed together)

You know, I've never had that issue. I suspect that one of them would win the battle (but they may not)

I might be missing something, but this does sound like a concern (even though we talk about installing different detection scanners) ?

At least the guide works ;)

Edit:

I think I worked it out

When 1 Antimalware finds a detection it will ask you first what to do.

Therefore allowing you to decide on allowing only 1 Antimalware detection to be moved (usually renamed) into its quarantine folder

By the pausing and asking by both Antimalware programs, both (hypothetically) at the same time. Will allow 1 option only by user input

That will work, therefore having 2 Antimalware programs installed at the same time, is still ok :)

Thank goodness for that !

Edited by kimsland

The reason you cant have 2 antivirus programs with realtime protection is because when one scans an active file, the other will scan it because the other one has activated the file, this doubling on the CPU and HDD time and even possibly RAM.

I believe this would be the same for realtime protection on antispyware...

I prefer the guide found here: http://wiki.lunarsoft.net/wiki/PC_Cleanup

The Anti-Malware Toolkit goes along with it really well.

There are no download links for any of the tools (except online Antivirus scan) !

Therefore that guide is not good. Unless you want users to go searching or something?

Please note there are many guides on the web, I have tried to simplify and give the best possible free tools above

Meh

Comodo should be up there to be honest. The way you can block processes, stop things escalating with Defense+ makes it perfect for cleaning up! The detection rate isn't brilliant but I use Malwarebytes to sweep up!

Plus it's free.

Comodo is a firewall, it also has a seperate free Antivirus (they basically wanted to get into this market about 6 months ago)

Unless you are talking about the paid version: Internet Security?

I only quote free tools (including the download links) as above

Note: No one needs to pay for anything to go through this guide

Thanks for the input though, but both of above are not required

Comodo is a firewall, it also has a seperate free Antivirus (they basically wanted to get into this market about 6 months ago)

Unless you are talking about the paid version: Internet Security?

No, your confused. Comodo Internet Security is 100% free. Their is not Comodo Firewall or Comodo Anti Virus. Just Comodo Internet Security with the option to install either component.

http://www.comodointernetsecurity.com/

  • 3 weeks later...
There are no download links for any of the tools (except online Antivirus scan) !

Therefore that guide is not good. Unless you want users to go searching or something?

Please note there are many guides on the web, I have tried to simplify and give the best possible free tools above

You must not have read the guide. They say to use the Anti-Malware Toolkit to get those apps.

So you can reread and try them:

Anti-Malware Toolkit

PC Cleanup

Anti-Malware Toolkit on the wiki.

I had a better look, and even downloaded the program and apps and updates

I updated Malwarebytes (from Anti-Malware Toolkit "Download" folder created on my Desktop)

Then started Malwarebytes, and did a manual update and I got another 2.4 meg download (and higher revision defs)

Even so.. Yes the program looks good at downloading these programs and updates to one central location

Also it seems I was not subscribed to this Neowin thread again (luckily I was just checking it)

I read somewhere that you automatically unsubscribe after a month (I believe) Which I'm not all that happy with

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Universal USB Installer 2.0.3.7 by Razvan Serea The Universal USB Installer (UUI) is a powerful bootable USB software tool for creating USB boot drives from ISO files, perfect for installing Linux or Windows, running live systems, or building diagnostic toolkits. This versatile ISO-to-USB software makes it easy to boot from USB and create Live USBs for Linux distributions, Windows setup installers, antivirus tools, and system diagnostic utilities. Whether you need a multisystem Windows Media Creation Tool, a Live USB Linux installer, or an all-in-one PC diagnostic toolkit, UUI offers a reliable and flexible Linux and Windows bootable USB creator. Effortlessly carry your favorite portable operating systems and essential troubleshooting and diagnostic tools on a single flash drive or USB boot stick. Take your preferred Live Linux distributions, Windows installers, recovery software, backup utilities, and diagnostic tools with you, all bootable from a single USB drive. No more juggling multiple USB sticks or complicated bootloaders, UUI consolidates everything into one flexible, multiboot solution. Using this open source USB boot maker software is easy as 123. To create a Linux or Windows bootable USB drive, you simply select your target flash drive, choose your distribution from the list, browse to the ISO file (or choose to download the ISO), and then click Create. Once finished, you should have a ready to run Live USB containing the Live operating system, Windows installation media, or system diagnostics utility, or advanced system cleaner tool you previously selected. Universal USB Installer 2.0.3.7 changelog: Expanded the distro and tool catalog with additional popular Linux ISO entries. Updated: several distro homepage and download links, including Ubuntu Unity, Garuda Linux, Arch Linux, Fedora, Manjaro, and SystemRescue. Fixed: ISOs added via drag and drop (or manually copied to the drive) are now listed in the removal dropdown alongside normally installed distros. Download: Universal USB Installer 2.0.3.7 | 19.4 MB (Open Source) Link: Universal USB Installer Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • You are clueless. The updates are done in the background so the next time you open Edge the updates are applied automatically. There is no need to close all your tabs. Just keep browsing like you normally do. Clearly you don't use Edge and are just one of those haters that complain for the sake of complaining.
    • I don't get this David. Can you explain it please.  
    • Microsoft is busy. Lots of changes to be released imminently for Windows server or soon. Also, lots happening for next version as well. Third party virus scanning software is being moved out of Kernel mode to avoid repeat of Crowdstrike incident. Windows Protected Mode and Windows Ready Print no longer require third party print drivers to be installed. New storage stack being developed. New NVME drivers now available for Windows Server 2025 to improve local NVME drive performance by 60+ percent. NVME-Of of fabric being worked on for next release to improve network access to NVME drives. ReFs (next file system) now has ability to boot and will become default file system in next release of Windows Server. ReFs improves on NTFS in several areas including resiliency and reliability and scalability. New update stack is being worked on to unify Windows updates, and updates for drivers and first party/3rd party application software. A stricter and more robust third-party driver certification program (ODI) is being worked on to improve performance, thermals, battery life, and reliability on modern Windows hardware by tightening how OEMs and IHVs (Intel, AMD, Qualcomm, NVIDIA, etc.) build and ship drivers. There is a tone more but too numerous to mention.
    • Now disable that stupid OneDrive backup request when Windows starts please. So unbelievably frustrating to only have “remind me later” instead of “no and never ask me again”
  • Recent Achievements

    • One Month Later
      Markus94287 earned a badge
      One Month Later
    • Week One Done
      Markus94287 earned a badge
      Week One Done
    • One Year In
      Markus94287 earned a badge
      One Year In
    • Dedicated
      truespursfan earned a badge
      Dedicated
    • Rookie
      restore went up a rank
      Rookie
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      168
    3. 3
      PsYcHoKiLLa
      154
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      79
  • Tell a friend

    Love Neowin? Tell a friend!