By using Apprenticeforums services you agree to our Cookies Use and Data Transfer outside the EU.
We and our partners operate globally and use cookies, including for analytics, personalisation, ads and Newsletters.

  • Join our UK Small business Forum

    Helping business owners with every day advice, tips and discussions with likeminded business owners. Become apart of a community surrounded by level headed business folk from around the UK


    Join us!

Virus / Malware Removal Guide

  • Thread starter Lanarkshire IT Services
  • Start date
L

Lanarkshire IT Services

New Member
A Guide To Help Remove Viruses / Malware / Spyware

Using this guide will help remove most common infections from your system

Step 1

Get rid of any temp files from your system by using a temp file cleaner such as:

* TFC
* Temp File Cleaner
* ATF CLeaner
* Cleanup


These tools will make the steps of virus / malware scanning quicker but please make sure you know how to use them.

Please be aware that if you use autocomplete in Internet Explorer etc to store usernames or passwords for websites then you should NOT empty your temporary internet files or cookies or use TFC instead.



Step 2

Create a system restore point. Should anything go wrong with the cleaning process then you always have a safe point to return to. There is a freeware tool that makes this task simple. Get SysRestorePoint here.



Step 3

Backup your registry with ERUNT. As removing viruses / malware etc requires changes to the Windows Registry then it is very advised to back this BEFORE any changes are made. Then, like the system restore method above, should anything go wrong you can always revert back to a working copy of the registry. Failure to do this could leave your system unbootable / usable. Download and install ERUNT accepting all the defaults.

* Download ERUNT
* Double click erunt_setup.exe and select Run
* Choose English as the language
* At the ERUNT setup wizard click Next, install in C:\Program Files\ERUNT (the default),click Next and Next and Next again then Install
* Choose NO to create an ERUNT entry in the Startup Folder
* Untick Show Documentation and leave Launch ERUNT checked
* ERUNT will launch with the following screen:
erunt%20settings.jpg


ERUNT settings

* Choose the same settings as shown above
* ERUNT will prompt you to create the folder if it doesn't exist (mostly likely won't)
* ERUNT will start backing up the registry to the desired location as shown:

erunt2.jpg


ERUNT backing up registry

* Once this has been done you should get the following output:

erunt3.jpg


ERUNT backup registry complete

* This output screen tells you that the registry backup was successful and how / where to restore it in future.


Step 4

Spyware / malware removal

Download and install Malware Bytes Anti Malware (MBAM).

Update MBAM and do a FULL scan until nothing is found as shown below. You might have to reboot and rescan to achieve this.

MBAM Clean Log:

malware%20bytes%20clean%20log.jpg




Step 5

Scan for viruses with a decent free anti-virus program such as:

* Avast Free Edition - FREE FOR HOME / PERSONAL USE
* Avira Free Edition - FREE FOR HOME / PERSONAL USE
* Scan suspicious / unknown files with VirusTotal
* Use an online anti-virus scanner such as: TrendMicro HouseCall or Kapersky

Download, install, update and scan until nothing is found.

Step 6

Restart your system and see how the performance is doing.

If you are still experiencing problems then see our slow computer fix tutorial then our HiJackThis tutorial

If your system is now OK then please carry out the following to ensure protection in future:

System Restore

* Create a new system restore point by Get SysRestorePoint here.
* Get rid of all old, possibly infected system restore points. XP guide here. Vista guide here.

Virus / Spyware / Malware / Trojan Protection

* Clean your temp files regularly using TFC
* Update and scan with both your anti-virus and anti-malware software atleast once a week.
* Install SpywareBlaster - Many known malicious programs are ActiveX programs that integrate into Internet Explorer. If you use Internet Explorer, then we recommend that you download and install SpywareBlaster. This program will load a huge list of known malicious programs into your computer's configuration and make it so that you can not run these programs on your computer and therefore become infected.
* Install SpywareGuard -This will give you realtime protection against spyware etc.
* Make sure that the anti-virus / spyware / malware program you installed IS NOT listed here.

Peer to Peer Programs

* DO NOT install or use peer to peer (p2p) downloading applications such as Limewire, blubster, Kazaa, uTorrent etc

Windows Updates

* Keep up to date with Windows Update by turning ON automatic updates. XP Guide here. Vista Guide here.

Limited Users

* Create limited user accounts (ideal for kids, limited users, public users etc) with Windows Steady State

Web Filtering

* Use a web / content filtering program such as OpenDNS or K9.

Backup

* Once all this has been done then create a system backup - preferably a system image. FREE solutions are Drive Image XML , DiscWizard (FREE for Maxtor / Seagate drives)

Any questions / comments / suggestions welcome.
 
G

Gouldie0

New Member
Thanks guys, i shall look into this further. Although i'm sure that my computer is ok, i'd like to make sure as i do hold client details etc.

Cheers

Neil
 
L

Lanarkshire IT Services

New Member
Hi All

Due to the ever changing nature of malware / viruses etc the above guide is updated constantly.

Please visit the most recent malware removal guide on my site for the latest fixes etc.

Regards
 
L

Lanarkshire IT Services

New Member
Hi All

My FREE Virus / Malware Removal Guide updated to include:

Kaspersky AVP Tool - Ideal if you can only get into Safe Mode.

And the removal of the following fake security products:

# Antivirus Vista 2010
# Vista Antispyware 2010
# Vista Guardian
# Vista Antivirus Pro
# Vista Internet Security
# Vista Internet Security 2010
# XP Guardian
# XP Antivirus Pro
# XP AntiSpyware 2010
# XP Internet Security
# XP Internet Security 2010
# Antivirus XP 2010
# Antivirus Win 7 2010
# Win7 Guardian
# Win 7 Antivirus Pro
# Win 7 Antispyware 2010
# Win 7 Internet Security
# Win 7 Internet Security 2010
# Actns/Swif.T trojan
# Spyware Protect 2009
# Anti Virus 2008

The guide is also slimmed down a bit for more easier understanding

Any questions etc then just ask!

Regards
 
Jason

Jason

New Member
Hello

Like many other people I have found there is often a software solution for removing virus/malware.

However more and more I am coming across situations where no software applications is able to either detect or remove the offending code.

In many cases I have had to manually track and remove viruses.

If your in this situation, please do not hesitate to get in touch.

Good hunting!

Jason
Popcorn Solutions » IT support for home and business users in Edinburgh
'Get the Popcorn in!'
 
L

Lanarkshire IT Services

New Member
Hello

Like many other people I have found there is often a software solution for removing virus/malware.

However more and more I am coming across situations where no software applications is able to either detect or remove the offending code.

In many cases I have had to manually track and remove viruses.

If your in this situation, please do not hesitate to get in touch.

Good hunting!

Jason
Popcorn Solutions » IT support for home and business users in Edinburgh
'Get the Popcorn in!'

Hi Mate

I think it is totally impossible to detect / remove viruses / malware etc without some form of software.

Even if you are using Regedit or Autoruns or some sort of process viewer etc to manually detect / remove then you are still using software.

Infact most successful / advanced removal techiques require detailed knowledge of the registry and regedit or something similar.

I'd be interested to find out how you can view malicious code WITHOUT some form of application even if it is Notepad.

Regards
 
Jason

Jason

New Member
Hi

Many viruses/spyware use standard locations for install and standard methods of startup.
If you have a good understanding of the registry and also Internet Explorer add-ons you usually have a good chance of detecting and eliminating a virus and spyware.

On many occassions I have tried several sofware applications to detect a virus which I know is resident on the target PC, but all have failed.

This is a common approach when you know what you are doing.
 
L

Lanarkshire IT Services

New Member
Hi Mate

Getting a bit of a debate here but nevermind.

Yes many viruses / malware use standard loading points but that is OLD news now and many now attach / disguise themselves to legimate files / drivers / services etc.

In these cases you can use a decent system lister program with a 3M / 6M facility which lists anything added or altered etc in the last 3 or 6 months with very detailed accuracy.

As I said earlier, some form of software is still required.

Regards
 
Top