Posted: 11/27/2011 4:58:40 PM EDT
|
Hi everyone,
I would like to share my malware removal guide with all of you. It contains step by step instructions on how to remove malware from a computer. It's still a work in progress. I would appreciate any feedback. This guide will help you clean your computer of malware. If you think your computer is infected with a virus or some other malicious software, you may want to use this guide. It contains instructions that, if done correctly and in order, will remove most malware infections on a Windows operating system. It highlights the tools and resources that are necessary to clean your system. Malware is a general term for any malicious software, including viruses, trojans, rootkits, spyware and adware.
Guide: http://www.selectrealsecurity.com/malware-removal-guide |
|
add 'delete internet explorer's temp files cache.' wit the delete temp folder. I've also seen things hide in the temp folder of the pseudo users 'Local system' and 'Network Services'. also should have section to reset winsock to fix browser hijack type things.. for XP anyway http://support.microsoft.com/kb/299357 |
|
Looks good. I've had great luck with Kaspersky Rescue Disc installed to a USB drive. Boot from that and let it run a scan, then reboot and let Malwarebytes do its thing. |
|
I can save you a lot of work; Install Linux Just kidding. Great job on the writeup. Most of the programs I've used at one time or another, but there were a few on your list that I wasn't aware of. Looks like I have some more documentation and programs to put into my bag of tricks. Thanks! |
|
Update:
- Added RogueKiller (Additional Detection/Removal Tools) - Added Windows Defender Offline (formerly Standalone System Sweeper) - Added Ultra Virus Killer (Additional Detection/Removal Tools) - Added file sizes (Additional Detection/Removal Tools) - Removed unnecessary links |
|
Good list. When I first started in IT years ago I wish I would've run into a list like this.
I spent many a weeks trying to find the ideal virus removal program. Like you and many others, mbam has become my favorite. However, I have run into many severe rootkits recently that TDSS and MBAM haven't been able to tackle, and combofix has been the only solution. I'd suggest adding it to your list. Bravo
|
|
Not a bad document, but your "Note 1" is really the only thing necessary.
I *HATE HATE HATE HATE* seeing people say, "Oh, I ran malwarebytes and now my computer is clean!" It's not. You just don't know what malware you're running now, and your computer is probably part of a bot farm. Anyway, that's the advice I give everyone who comes in here with "I got a virus, what do I do". Wipe and reload, it's the only way to be sure. Or switch to Unix, preferably packaged with a Mac. |
|
Update:
- Added instructions on how to fix the Registry (Preparation for Removal) - Changed Malwarebytes download link - Added note about manually updating Malwarebytes (Step 2) - Updated HitmanPro (3.6) - Removed F-Secure Online Scanner - Added Bitdefender Bootkit Removal Tool (Additional Detection/Removal Tools) |
|
Quoted: Quoted: I don't have "Merge" as an option. I'm running MS XP Home Edition 2002 SP3.Hi txgp17, Right-click the FixNCR.reg file and click Merge. ![]() By default Windows should know what to do with a .reg file, but you can do it manually. Go to Start -> Run and type "regedit" and hit <Enter>. Go to the File menu, select Import, and then locate and double click the .reg file. |
|
Quoted: That didn't seem to change anything, it still asks which program I want to use to open the file.
Quoted:
Quoted:
I don't have "Merge" as an option. I'm running MS XP Home Edition 2002 SP3.Hi txgp17, Right-click the FixNCR.reg file and click Merge.
By default Windows should know what to do with a .reg file, but you can do it manually. Go to Start -> Run and type "regedit" and hit <Enter>. Go to the File menu, select Import, and then locate and double click the .reg file. |
|
Quoted:
Posted: 12/5/2011 12:25:41 PM EST - Trojan / browser hijack problem, unable to remove, please help
Next time please open your own thread |
|
Update:
- Changed the link to backup instructions - Added Windows Repair by Tweaking.com (Fix Post-Disinfection Problems) - Removed TaskManager.xls - Added Process Hacker (Additional Detection/Removal Tools) - Removed unnecessary links http://www.selectrealsecurity.com/malware-removal-guide |
|
to import a .reg file when .exe are hijacked, broken and explorer is wonky.
start task manager (ctrl+shift+esc) and pray IT is not broken also.
file->new change selection box to all files (*.*) find the .reg file you want to merge, right click on it and you can select merge from the popup menu. |
|
Quoted:
Update: - Changed the link to backup instructions - Added Windows Repair by Tweaking.com (Fix Post-Disinfection Problems) - Removed TaskManager.xls - Added Process Hacker (Additional Detection/Removal Tools) - Removed unnecessary links http://www.selectrealsecurity.com/malware-removal-guide are you going to repond to my IM? |
|
Update:
- Removed unnecessary notes (Step 2) - Revised instructions for running SuperAntiSpyware (Step 2) - Removed tutorial links (Step 2) - Changed the order of steps in After the Removal Process - Added instructions on how to Repair Windows Update and Firewall (Fix Post-Disinfection Problems) |
|
Update:
- Added a Comments and Reviews page (under the title) - Created a PDF version of the guide (under the title) - Added a link about disconnecting your Internet connection (Step 2) - Added a link to Malwarebytes randomly named installer (Step 2) - Combined steps: Get Expert Analysis and Further Help I also created a Google+ page. https://plus.google.com/106459453799715716104/posts Please follow me. |
|
Brian,
You are awesome!!!!! I have been living with web browser redirects for months. Been cutting and pasteing in order to use the net for so long that I forgot what regular hyperlinks on Google were like. Your simple instructions helped me to clean up the computer, Super anti spyware cleared off a trojan, and I was able to use the program to reset the hosts file. The laptop works great now. Thank you so much. The assholes who write the damn viruses and mal ware never know who they are hurting. Im telling you that you just really helped me. |
|
Hi JeepinSoldier,
I'm glad that my guide helped you! Update: - Added a new image (Introduction) - Added a new page: Fix Internet Connection after Malware Removal (Removal Process) - Added an important note - RKill (Step 2) - Removed Malwarebytes offline database installer (isn't updated often) - Removed SuperAntiSpyware (Step 2) - Changed a few links - Updated the PDF version |
|
Hi everyone,
Recently, I've been getting questions about my recent update (particularly the part about removing SuperAntiSpyware). I would like share the reasons why I removed SAS. I removed SuperAntiSpyware for the following main reasons: 1. SuperAntiSpyware has the lowest malware detection rates compared to Malwarebytes and HitmanPro. 2. The fact that HitmanPro uses 4 antivirus engines to detect malware. 3. Malwarebytes and HitmanPro provide adequate malware removal when used together. SuperAntiSpyware is still an excellent product, and I will definitely keep an eye on it. Brian |
|
Update (1.1):
- Added a version number - Added an important note about the time (Introduction) - Revised the Fix Executable Files section (Preparation for Removal) - Added an important note about broken Internet connection (Removal Process) - Revised the Repair Windows Update and Firewall section (URLs) - Updated file sizes (AV Rescue CDs) - Added a few new links |
|
Update:
- Added a last updated date - Revised the introduction - Created a new page: http://www.selectrealsecurity.com/stop-malicious-processes - Replaced FixNCR.reg with RKill - Moved Safe Mode to the Preparation section - Removed aswMBR - Updated the PDF version |
|
Update:
- Revised the introduction - Added an important note about the USB autorun file (Preparation for Removal) - The guide is now officially copyrighted (added copyright notice). - Changed the subheadings - Revised page: Stop Malicious Processes and Fix EXE Files - Revised Step 3 - Changed a few links - Updated the PDF version |


