Spyware/Adware/Virus/Trojan/Rootkit/Keylogger Removal Guide

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
<div align="center"><!--sizeo:5--><span style="font-size:18pt;line-height:100%"><!--/sizeo--><u>Spyware/Adware/Virus/Trojan/Rootkit/Keylogger Removal Guide</u><!--sizec--></span><!--/sizec-->

So, you're obviously here because your computer has some sort of problem.
We're gonna fix you up, and, with a little effort, prevent problems from occurring in the future.</div>

<div align="center"><!--sizeo:3--><span style="font-size:12pt;line-height:100%"><!--/sizeo--><b><!--coloro:#990000--><span style="color:#990000"><!--/coloro-->FORMATTING IS A LAST RESORT ONLY!<!--colorc--></span><!--/colorc--></b><!--sizec--></span><!--/sizec--></div><!--sizeo:1--><span style="font-size:8pt;line-height:100%"><!--/sizeo-->Please note that a (re)format (when you wipe the computer and reinstall windows) is rarely needed to get rid of a computer infection. A worst case scenario is that an infection infects and changes critical system files, but those can be replaced with clean copies off any install CD with a simple command. Some people may have 50 gigabytes of personal files on their computer, and some people have their computers set up a very specific way that would take hours or days to restore to working order after a format. Just because formatting is <i>your</i> choice does not mean it should be the first suggestion to <i>somebody else</i>.<!--sizec--></span><!--/sizec-->



<!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo--><div align="center">Basic, Advanced, or Super removal?</div><!--sizec--></span><!--/sizec-->
<ol type='1'><li>If your only problem is internet popups (even when no internet windows are open) or viruses infecting your files, and you still have control over your computer, then after "Setup", follow the "Basic Removal" post.
--------------------------------------------------------
</li><li>If you are infected by a program that's only pretending to be a virus/spyware remover, and you know it's fake...
If you are getting fake virus warnings from your own computer, not on internet pages...
If your wallpaper has changed to a fake warning...
If you are for some reason unable to fully control your own computer, like settings are locked...
If the basic removal failed...

I suggest you use the "Advanced Removal" post after "setup".
--------------------------------------------------------
</li><li>If you have little to no control over your computer...
If something closes/kills any scanner you run...
If you can't get into safe mode because of a Blue Screen error...
If you cannot run the Task Manager...
If your account(s) are no longer Administrator...
If the advanced removal failed...

You should go to the "Super Removal" post.</li></ol>



<!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo--><div align="center">Setup</div><!--sizec--></span><!--/sizec-->
Before you start removing infections, there's a few precautions you should take.
These steps will help cripple most infections, making them easier to remove.<ol type='1'><li><u>Disable IE Addons</u>

Open Internet Explorer, and press the ALT key on your keyboard once. At the top, go to the "Tools" menu, and choose "Internet Options". In the new window, on the Advanced tab you will find many options. Uncheck the option "Enable third party browser extensions", and press OK. Close Internet Explorer.


</li><li><u>Disable System Restore</u>

<b>If you're on XP...</b>
In your start menu, go to the control panel, and there should be a bunch of icons, one of them being "system". If not, click "switch to classic view" on the left. Open "system", and click the "system restore" tab at the top. In that section, click the checkbox to "turn off system restore on all drives", if it not already checked. Save the settings. That will delete any older system restore points, which could easily contain viruses, to prevent them from coming back in the future if you use a restore point.

<b>If you're on Vista...</b>
Open the start menu, right-click "Computer", and click "properties". In the new window, go near the top-left and click "System protection". In a new window, you'll see a list of your drives. Uncheck them. Tell windows that you want to turn system restore off by clicking the button when it asks you.

<b>If you're on Windows 7...</b>
Open the start menu, right-click "Computer", and click "properties". In the new window, go near the top-left and click "System protection". In a new window, you'll see a list of your drives. Below that, click the "configure" button. In the next new window, choose "Turn off system protection", then click the "OK" button.


</li><li><u>Remove Redirects</u><ul><li>Part A

<b>If you're on XP...</b>
Open the start menu and click "run". In the white box, type "regedit.exe" (without the quotes) and press enter.

<b>If you're on Vista or Windows 7...</b>
Open the start menu and click in the white box at the bottom. Type "regedit.exe" (without the quotes) and press enter.


That will start the registry editor, which we will use to find where the <i>current</i> HOSTS file is.
On the left, double-click "<!--coloro:#000099--><span style="color:#000099"><!--/coloro-->HKEY_LOCAL_MACHINE<!--colorc--></span><!--/colorc-->".
After that, double-click "<!--coloro:#000099--><span style="color:#000099"><!--/coloro-->System<!--colorc--></span><!--/colorc-->".
Then, double-click "<!--coloro:#000099--><span style="color:#000099"><!--/coloro-->CurrentControlSet<!--colorc--></span><!--/colorc-->".
After that, you want to open "<!--coloro:#000099--><span style="color:#000099"><!--/coloro-->Services<!--colorc--></span><!--/colorc-->".
Almost done now, open "<!--coloro:#000099--><span style="color:#000099"><!--/coloro-->Tcpip<!--colorc--></span><!--/colorc-->".
Finally, you want to open "<!--coloro:#000099--><span style="color:#000099"><!--/coloro-->Parameters<!--colorc--></span><!--/colorc-->".

On the right side of the you will see three columns. "Name", "Type", and "Data".
In the "Name" column, find "DataBasePath" and double-click it. Copy the "Value Data".

Remember how you ran "regedit.exe" before? This time, instead of running regedit, you should paste that "Value Data" line in the "run" box (or the bottom of the start menu in Vista/7), and press enter. This will open the folder that has the HOSTS file!

It will just be called "hosts" and won't have any special icon. Delete it.</li><li>Part B

There's a possibility that your computer has been set to use a different DNS server, instead of the clean one run by your internet company. These other DNS servers are usually bad, directing you to fake sites instead of real ones (like telling you that Jack's house is in the middle of a highway, instead of giving you the real address).

To get around that, <a href="https://store.opendns.com/setup/computer/" target="_blank">here's instructions on using a clean DNS server</a> (with pictures!).
If you don't want to use OpenDNS, you can follow those instructions and put in google's DNS servers. 8.8.8.8 and 8.8.4.4 are the IPs for them.</li></ul></li></ol>



<!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo--><div align="center">Programs List</div><!--sizec--></span><!--/sizec-->
<u>Anti-virus</u>
<b>Free</b>
Avast! - <a href="http://www.avast.com/eng/download-avast-home.html" target="_blank">www.avast.com</a>
Microsoft Security essentials - <a href="http://www.microsoft.com/Security_essentials/" target="_blank">www.microsoft.com/Security_essentials</a>
Avira (Shows an ad) - From <a href="http://download.cnet.com/Avira-AntiVir-Personal-Free-Antivirus/3000-2239_4-10322935.html?part=dl-10322935&subj=dl&tag=button&cdlPid=11012914" target="_blank">download.cnet.com</a>.
AVG - From <a href="http://download.cnet.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10320142.html?part=dl-10044820&subj=dl&tag=button&cdlPid=11014801" target="_blank">download.cnet.com</a>.
ClamWin - <a href="http://www.clamwin.com/" target="_blank">www.clamwin.com</a>
Comodo - <a href="http://antivirus.comodo.com/" target="_blank">antivirus.comodo.com</a>

<b>Paid</b>
Kaspersky - <a href="http://usa.kaspersky.com/products_services/anti-virus.php" target="_blank">www.kaspersky.com</a>
NOD32 - <a href="http://www.eset.com/purchase/" target="_blank">www.eset.com</a>
Bitdefender - <a href="http://www.bitdefender.com/" target="_blank">www.bitdefender.com</a>
F-Secure - <a href="http://www.f-secure.com/en_US/products/home-office/antivirus/index.html" target="_blank">www.f-secure.com</a>
Trend Micro - <a href="http://us.trendmicro.com/us/products/personal/antivirus-plus-anti-spyware/index.html" target="_blank">www.trendmicro.com</a>


<u>Spyware scanner</u>
<b>Free</b>
Spybot S&D - <a href="http://www.safer-networking.org/en/spybotsd/index.html" target="_blank">www.safer-networking.org</a>
AdAware - <a href="http://www.lavasoft.com/products/ad_aware_free.php" target="_blank">www.lavasoft.com</a>
SUPERAntiSpyware - <a href="http://www.superantispyware.com/superantispywarefreevspro.html" target="_blank">www.superantispyware.com</a>
MalwareBytes - <a href="http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button" target="_blank">www.malwarebytes.org</a>



<div align="center"><!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo-->Basic Removal<!--sizec--></span><!--/sizec--></div>
<ol type='1'><li>If you don't have some, pick out one Antivirus program and one Antispyware program from the "Programs" post. Please make sure you have at least one from both of the categories (antivirus and spyware scanner).
<b>Do not buy one online right now, because somebody could use the infection to steal your financial information!</b>
</li><li>Install the programs, run them and they might ask you to update the definitions. If so, let them.
</li><li>Then, go into Safe Mode, but read the rest of this post before you do that.

This site has instructions on getting into safe mode.
<a href="http://www.computerhope.com/issues/chsafe.htm" target="_blank">http://www.computerhope.com/issues/chsafe.htm</a>
Safe mode will not have internet (possibly no sound, either), and things may look weird.
Don't panic, it's only temporary. When you restart things will be back to normal.
</li><li>In safe mode, run the scanners, and heal/remove anything they find.
</li><li>Restart (which will get you out of safe mode) and things should be fixed!</li></ol>If so, go on down to the "After Scanning" post.
If not, go to the "Advanced Removal" post.



<!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo--><div align="center">Advanced Removal</div><!--sizec--></span><!--/sizec-->
<ol type='1'><li><a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en" target="_blank">Microsoft Windows Malicious Software Removal Tool</a>
This is the first program that you should download and run. It's a tool that checks your computer for infection by specific viruses known to affect windows, it is not a replacement for a normal anti-virus, but it is useful in removing something that has already infected you.

</li><li>If your issue is a fake antivirus program, it should have a fake name it's trying to use to sound legitimate.
If your virus scanner is picking up an infection but can't remove it, it should also present you with some sort of name.

Go to a search site (such as google, bing, yahoo, ask) and try to find instructions on removing the specific name of the infection. Type in something like <i>"NAME removal"</i>. The first few results should have specific instructions (or sometimes even a free program) specifically made to remove that type of infection. It's best to follow those instructions first, since they can remove specific parts of an infection that generic guides miss.

</li><li>After following those instructions (or if you couldn't find any), download and run this tool.
It comes in four "flavors", if one doesn't work try the others.
<a href="http://download.bleepingcomputer.com/grinler/rkill.exe" target="_blank">http://download.bleepingcomputer.com/grinler/rkill.exe</a>
<a href="http://download.bleepingcomputer.com/grinler/rkill.com" target="_blank">http://download.bleepingcomputer.com/grinler/rkill.com</a>
<a href="http://download.bleepingcomputer.com/grinler/rkill.scr" target="_blank">http://download.bleepingcomputer.com/grinler/rkill.scr</a>
<a href="http://download.bleepingcomputer.com/grinler/rkill.pif" target="_blank">http://download.bleepingcomputer.com/grinler/rkill.pif</a>
This will attempt to kill any active infections that would stop you from running removal tools.
<b>Any time you restart, run one of these again.</b>
</li><li>Then, run this tool.
<a href="http://www.internetinspiration.co.uk/roguefix.htm" target="_blank">http://www.internetinspiration.co.uk/roguefix.htm</a>

That is an updated tool that will attempt to remove all known deep infections.
Follow all the instructions exactly (remember safe mode when it says to!) and give it time to do it's job.

After downloading it, open a folder, any folder. Go to "Tools" at the top menu, and click "Folder options". When a new window comes up, go to the the "view" section. Find and <!--coloro:#990000--><span style="color:#990000"><!--/coloro-->UNcheck<!--colorc--></span><!--/colorc--> "hide file extensions for known types", save the changes. Then rename the text file you got from "roguefix.txt" to "roguefix.bat", that way you can run it. Feel free to recheck the box afterwards, it's only needed to be off so that you can run roguefix.

If you cannot run that tool for some reason, use one of these.
<a href="http://www.bleepingcomputer.com/combofix/how-to-use-combofix" target="_blank">http://www.bleepingcomputer.com/combofix/how-to-use-combofix</a>
<a href="http://siri.geekstogo.com/SmitfraudFix.php" target="_blank">http://siri.geekstogo.com/SmitfraudFix.php</a>

</li><li>When that program finishes, go back into normal mode and follow the "Basic Removal" instructions.
If that fixes your problem, skip on down to the "After Scanning" section.</li></ol><i>If that still does not remove your infection</i>, you may have a "Rootkit", which hides files from windows itself.

Download and run this rootkit detector. Do not just "run" it, but actually save it somewhere you can find it, and then run it.
If you don't know how to do this, post and ask us (be sure to tell us what browser program you view web pages with!)
<a href="ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe" target="_blank">ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe</a>

Run that, and it will scan for things that are hidden to windows and normal programs. When it's done, it'll have a list of results. Look at a result, and look for it with a search engine like google or yahoo (search for the file/folder name along with the word "rootkit" ), and if the results involve a type of infection (spyware, adware, rogue software, malware, virus, trojan), you should see a removal guide.

Not everything it finds is bad! Some are involved with programs you know are safe (like firefox) or part of windows itself. When it's done, you'll find a log file where you saved the program. It will be named something like "fsbl-20090124034050.log". If some things were found, open it (right-click it, choose "open with", and choose Notepad or some other text editor) and show us what it says.



<!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo--><div align="center">Super Removal</div><!--sizec--></span><!--/sizec-->
A Live CD is a disc that runs it's own Operating System. What a Live CD allows you to do is do things on your computer even if something in windows is really messed up.. This also means than any infection will not be active, so the Live CD is free to scan and remove viruses without interference. The down side is it requires you to burn a CD (you will probably need to burn it from another computer), and the scan can take a while.<ol type='1'><li><a href="http://www.free-av.com/en/tools/12/avira_antivir_rescue_system.html" target="_blank">Download it here.</a> (It's free.)
Run that when you have a blank CD in your computer and it will start creating the disc.

</li><li>When it's done, take the disc out and label it if you want, then put it back in and restart your computer. You'll need to tell your computer to boot the CD, there's multiple ways it can be done. Once it's started, go to step 3.

A - Your computer may start the CD on it's own.

B - When it's first starting up you should see something like "press (something) to boot from CD", or may just say "Boot from CD" If so, press that key (or enter) to start the CD.

C - If that doesn't appear, you may see something like "F10 (or some other key) - Boot Menu". If so, press that key, and then choose the CD drive from the list.

D - If you're not given any of those options, there should be a "Press (some key) to enter setup" notice. Press that key to access your motherboard's settings. You navigate around with the arrow keys, tab, enter, and escape. Somewhere in there should be an option for changing the "Boot order". Choose that, and change it so that the CD drive is above the harddrive in the list. Press whatever key it is to save changes and exit, and the computer should now be able to boot off the CD.

</li><li>When the CD first starts, you'll see a screen like this. You should press the "1" key on your keyboard.
<a href="http://img264.imageshack.us/img264/6329/31710781.gif" target="_blank"><img src="http://img81.imageshack.us/img81/8527/rescuecd369scr01.th.jpg" border="0" class="linked-image" /></a>
(Click for full version)

</li><li>When the Live CD is fully started up, you'll see two flags in the bottom-left.
The right-one (British flag) changes the language to english, click it.
<img src="http://img137.imageshack.us/img137/6757/flags.gif" border="0" class="linked-image" />

</li><li>In the left-hand menu, click "Configuration".
Select "Scan all files" and "Try to repair infected files".
<a href="http://img81.imageshack.us/img81/3107/configg.gif" target="_blank"><img src="http://img81.imageshack.us/img81/3107/configg.th.gif" border="0" class="linked-image" /></a>
(Click for full version)

</li><li>In the left-hand menu, choose "Virus scanner", then click "Start scan" near the bottom.
The scanning process may take a long time, this is normal.
<a href="http://img217.imageshack.us/img217/7999/start.gif" target="_blank"><img src="http://img217.imageshack.us/img217/7999/start.th.gif" border="0" class="linked-image" /></a>
(Click for full version)

</li><li>When the scanning is finished, go to the left and find "Miscellaneous" and click it, then click "Shutdown".
The system shout shut down and eject the CD (or tell you to eject it) and then restart normally.

<img src="http://img230.imageshack.us/img230/2014/shutdown.gif" border="0" class="linked-image" /></li></ol>If that fixed the issue, go on down to the "After Scanning" post!


If this does nothing to fix the issue, then it's possible that some critical windows system files are infected to the point that they cannot be healed. This will require removing the files (running the scan again with the "remove infected files" option selected), and replacing them with clean versions off a windows CD. How you would do this greatly depends on your situation, so ask us about doing a "repair install" and we will help you personally.



<!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo--><div align="center">After Scanning</div><!--sizec--></span><!--/sizec-->
After your infection seems to be gone, it's best to do a few things just to be sure! When you're going to show us a log, it's best to put it on another site and give us a link. This saves space in a thread, and also prevents the forum system from removing anything it thinks may be harmful (such as malicious javascript) or a smiley.

This is a site you can use.
<a href="http://dpaste.com/" target="_blank">http://dpaste.com/</a>
Visit that page, paste whatever you want to show us in the "Code" box, then click the "Paste it" button.
You will see a new page with the coding, just give us a link to the page and we can see it.<ol type='1'><li>If whatever programs you scanned with offers you a log, show it to us.

</li><li>Download and run the executable version of Hijack This!
<a href="http://free.antivirus.com/hijackthis/" target="_blank">http://free.antivirus.com/hijackthis/</a>

Choose "Do a system scan and save a log file". It will open the log file when it's done scanning. Please show us the log first, then continue these instructions.

Go to www.hijackthis.de and paste your log into the white box. Tell it to analyze your log, and it will scan it, and then give you the results after a small bit. The results will be a long list, but the only things you need to worry about are the symbols on each item in the list. Ones with a red X are bad, and you should go into hijackthis, and put a check next to every bad item. Then, after marking all the bad ones in hijackthis, tell it to delete the entries, which will fix the issues.

Run hijackthis again, so it makes another log, and show us the second log.</li></ol>



<!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo--><div align="center">Cleanup</div><!--sizec--></span><!--/sizec-->
So you're done removing the infection, but there's a few things to change back.<ol type='1'><li>Go to the "Setup" post, and follow the instructions on disabling Internet Explorer browser extensions, but this time turn them back on.

</li><li>Turn System Restore back on.

</li><li>Change your DNS settings back to "automatic".
<a href="https://store.opendns.com/setup/computer/" target="_blank">Here's the page about it.</a>

</li><li>If you find trying to run some programs gives you a message asking you what to open it with, then download <a href="http://www.dougknox.com/xp/fileassoc/xp_exe_fix.zip" target="_blank">this file</a>, open it, and choose to run the file inside it. When it asks you if you want to merge/add the info to the registry, choose yes. After that, restart and you should be able to run programs properly again.

</li><li>And finally, this page covers the rest.
<a href="http://www.internetinspiration.co.uk/pc_clean_up.htm" target="_blank">http://www.internetinspiration.co.uk/pc_clean_up.htm</a></li></ol>



<!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo--><div align="center">Future Prevention</div><!--sizec--></span><!--/sizec-->
<div align="center"><b>How did I get that infection in the first place?
What can I do to prevent it?
Where do infections come from?
How can I spot bad programs?</b>

An ounce of prevention is worth a pound of cure.
Taking 30 seconds of your life every so often to keep your protection up to date can save you hours of fixing issues later.</div><ul><li><b>Q - How do I avoid getting viruses and spyware and all that other bad stuff?</b>
A - Here's a list of preventative measures you can take.<ol type='1'><li>Turn windows update on and leave it on! It's very important that your version of windows is kept up to date!</li><li>If you are in windows Vista/7, <a href="http://windows.microsoft.com/en-US/windows-vista/Turn-User-Account-Control-on-or-off" target="_blank">make sure UAC is on</a>.</li><li>Make sure to allow your antivirus to update automatically.</li><li>Scan with your antispyware at least once a week, updating it with the update option in the program before you scan.</li><li>Any good antivirus software (like the ones listed in this guide) will have what's known as an "active guard" or "resident shield". What that does is scan every file before it enters your computer, like a robot security guard at the door of a nightclub. If it detects an infection, it can stop it from doing anything, and alert you. Leave this option on.</li><li>Spybot also has a neat tool, the "immunizer". What this does it make it so that your computer cannot normally connect to any site that's known to be a fake, or one that attempts to install infections.</li><li>Using OpenDNS (http://opendns.org/) can help prevent infections from getting to your computer in the first place as well.</li></ul></li><li><b>Q - Why did my current program not protect me?</b>
Here's some possible reasons.<ol type='1'><li>It was not fully updated.</li><li>It was a pay program, and you stopped paying for it, so it stopped protecting you.</li><li>It was a scanner for a different type of infection then you got. Virus scanners usually will not scan for spyware/adware, and the same goes the other way way around.</li><li>The virus managed to break your protection program.</li><li>It could have been a rogue program that actually doesn't protect you, see below for a bit of details.</li></ol></li></ol><ul><u>Here's a list of common places/ways people get infected.</u>
</li><li><b>Advertisements</b>
This is one of the biggest. Yes, random advertisements on websites. Websites get paid by advertising companies to let the ad companies stick random ads in the website when it's viewed. The ad companies get paid by people that want to advertise. The people that want to advertise pay the ad company, and give the ad company the code/image/file for the ad, which is then randomly given out to any sites that display it. Normally that works fine, but if some low-life uses a trick or three to stick an infection in an ad, it can show up in multiple sites for hours before it's caught and removed. <i>So almost any site that displays advertisements could possibly give an infection.</i> The chances are slim, but it's possible, even more on sites that deal in shady things, like ROMs or Warez or porn. This is partially why it's so important to keep some protection that's always on.
</li><li><b>Rogue Software</b>
Sometimes you might see a random popup or a page claiming it's scanning your computer, and showing you hundreds of problems it's finding that claims it can fix. THESE ARE FALSE. It is not scanning your computer, it is not detecting issues, all it's trying to do is scare you into buying it. You can usually tell by opening "My Computer" or "Computer" from the start menu and looking at your list of drives and comparing it to the fake screenshot the program is showing you.
</li><li><b>Crack/Serial/Warez Sites</b>
These are absolutely packed with infections and should be avoided.
</li><li><b>P2P/Filesharing Programs (such as Limewire)</b>
When you use these programs, <i>you are downloading files from other people's computers, and other people are downloading files from your computer</i>. That's why it's called "file sharing". If anybody has an infection on their computer, you can catch it since your computer connects to theirs in order to get the file. Every single one of these programs has a very high risk of infection, you should try to avoid these.

Why not try these websites where you can listen to free legal music instead!
<a href="http://www.last.fm/" target="_blank">http://www.last.fm/</a>
<a href="http://www.mp3.com/free-music/free-mp3s" target="_blank">http://www.mp3.com/free-music/free-mp3s</a>
<a href="http://www.jamendo.com/" target="_blank">http://www.jamendo.com/</a>
<a href="http://www.garageband.com/" target="_blank">http://www.garageband.com/</a>
<a href="http://www.unsignedbandweb.com/" target="_blank">http://www.unsignedbandweb.com/</a>
</li><li><b>Links In Instant Messengers</b>
If you suddenly get a message over MSN/AIM/Live/Yahoo saying "hey, look at this cool thing", or "are these pictures of you?", or "hey look at these naked pictures of me!", along with a link, you should ask the person if they sent it to you or not before you click on it. It could be a special type of worm, there are ones that will continue to spread because they send that message to everyone on the infected person's buddy list. Same sort of thing as viruses in e-mails, it appears to be from somebody you know, but could easily be an infection.</li></ul>Most importantly, if you are going to install a program, simply look it up. Go to a search website, and type in the name of the program. If the first few results are saying "It's bad, here's how you remove it!", you should avoid it!



<!--sizeo:4--><span style="font-size:14pt;line-height:100%"><!--/sizeo--><div align="center">F.A.Q.</div><!--sizec--></span><!--/sizec-->
<b>Q - A lot of this seems useless.</b>
A - DO IT ANYWAY. Far too often people will skip steps, only to find they are still infected. Every step has a purpose. Follow them all.


<b>Q - Why doesn't your sticky specifically list (name of infection here)?</b>
A - There's thousands and thousands of computer infections, just like there's thousands and thousands of viral infections your IRL body can get, but there's not thousands and thousands of cold medications, are there? There's tons of breeds of dogs, but they're all still dogs. You don't buy dog food specifically for your dog's breed+gender+age+color+attitude, do you? Most infections have core things in common with each other, so a few tools and instructions can remove 99% of computer infections people get. Furthermore the same infection can often call itself multiple names in order to try to disguise itself. This is most often true of infections that pretend to be virus scanners and try to scare you into "buying" them.


<b>Q - A scanner is telling me that something I know is clean (for example, a game like maple story) is an infection, why?</b>
A - Either it really DOES have an infection (<i>viruses infect other programs in order to reproduce</i>!), or the scanner you're using is doing "heuristics" scanning. That's where it takes the program, and basically puts it in a virtual environment and tests how it reacts to certain actions, and if it does anything the scanner finds suspicious (that the scanner thinks it has no right doing, like a fast food employee carrying a gun), the scanner will mark it with a generic alert based on what type of infection the scanner thinks it is.

<a href="http://www.virustotal.com/" target="_blank">http://www.virustotal.com/</a> - Go there, upload the file it says is infected, and it will scan it with many virus scanners. There you can see what the results are. If only a small percentage of the scanners mark it as bad, and they use generic terms, like just "spyware" or "trojan" or "keylogger", then you can assume that the file is really clean. Real viruses are given codenames, like "Fojack" or "Hidrag.a".


<b>Q - What is all this stuff about DNS and HOSTS?</b>
A - DNS means "Domain Name Server". A DNS server keeps information which web address relates to which IP address on the internet (like how google.com is 74.125.45.100). It's sort of like how "Jack's house" means "123 Oak Tree Lane" in the real world. Unfortunately, sometimes an infection will misdirect your computer, sending it to the wrong websites. We can do a few things to stop that.

The HOSTS file is a file on windows that holds information about DNS entries on your own computer, it's usually used to bypass a normal DNS server for whatever reason. Unfortunately infections will add entries that make real sites redirect to fake sites... so we will delete the HOSTS file so that it cannot be used for evil. Your computer can work without it, and if it's needed it will be recreated later, but for now it can be considered dangerous.


<b>Q - What's a tracking cookie?</b>
A tracking cookie is not a virus, it will not hurt your computer. They are used by ads on websites for marking purposes. They record what "genre" of sites you generally visit (such as anime sites, military sites, car sites) so that the advertisements on a site know which types of ads to show you. <i>They do not record any personal information about you, they do not know who you are.</i>

A cookie is a text file created by a website on your computer to store information about what you've done there. A text file is several kilobytes, which is one thousandth of a megabyte, which in turn, is one thousandth of a gigabyte. It would take millions of cookies to amount to anything that might slow down your computer.
 

Law

rip ninjacat that zarcon made me
Member
Joined
Aug 14, 2007
Messages
4,128
Trophies
0
Age
32
Location
‭jerkland
Website
www.twitch.tv
XP
334
Country
Thoob said:
Rydian said:
This saves space in a thread, and also prevents gaia's forum system from removing anything it thinks may be harmful to gaia (such as malicious javascript).

Dude... You copied this thread from Gaia?!

This + multiple mentions of internet explorer = useless thread

thanks for playing, though.


Oh not to mention the formatting is terrible and the thread is a giant pain to read.
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
Law said:
Thoob said:
Rydian said:
This saves space in a thread, and also prevents gaia's forum system from removing anything it thinks may be harmful to gaia (such as malicious javascript).

Dude... You copied this thread from Gaia?!


This + multiple mentions of internet explorer = useless thread

thanks for playing, though.
Well isn't that close-minded of you?
If you're doubting the guide's accuracy, feel free to point out a statement or some such that you think is false, and I'll gladly go pull up some research to back it up. Also, if you read the mentions of IE, it's mainly making sure that if part of an infection has modified IE (such as a malicious BHO) it's disabled to prevent it from attempting to hamper recovery.

QUOTE(Law @ Feb 14 2010, 03:45 PM)
Oh not to mention the formatting is terrible and the thread is a giant pain to read.
If you have suggestions on the proper way to format this thread, please post them, as I have had a bit of an issue getting all this information readable, the spoiler tags help with that but I think the guide itself may need some color-coding or something...

But if you're just here to troll, I will go get a moderator to stop it.
I was told by wildwon that if I had a guide, I could just post it right in this section.
 

Law

rip ninjacat that zarcon made me
Member
Joined
Aug 14, 2007
Messages
4,128
Trophies
0
Age
32
Location
‭jerkland
Website
www.twitch.tv
XP
334
Country
Rydian said:
If you have suggestions on the proper way to format this thread, please post them, as I have had a bit of an issue getting all this information readable, the spoiler tags help with that but I think the guide itself may need some color-coding or something...

Get rid of the spoiler tags, they're part of the problem

make a proper Index/Contents with something to ctrl+f to or use the anchor point bbtag

Stop centering shit
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
Law said:
Get rid of the spoiler tags, they're part of the problemWouldn't that make the page far too long?

Law said:
make a proper Index/Contents with something to ctrl+f to or use the anchor point bbtagOoh, that's useful, thank you!

QUOTE(Law @ Feb 14 2010, 04:01 PM)
Stop centering shit
Yeah, it's harder to read on a wider forum, thanks.
 

Hakoda

Well-Known Member
Member
Joined
Feb 2, 2008
Messages
2,133
Trophies
0
Age
29
Location
San Jose, CA
Website
Visit site
XP
343
Country
United States
Thank you, this was very much needed. Mods sticky this, its instruction & format is worthy of stickiness.
bow.gif


I liked the three levels of removal as well as easy to understand setup for noobies. The best part was prolly the spoilers, imagine all that without spoilers. Holy crap. That and the word "Norton" was not found on this thread at all. Very well done Rydian

For anyone using this guide in the future, FOLLOW IT TO THE VERY END. Just because the infection is gone does not mean your system is stable. The "After Scanning", "Cleanup", & "Future Prevention" steps are CRITICAL.
 

steve-p

Well-Known Member
Member
Joined
Apr 13, 2009
Messages
503
Trophies
0
XP
143
Country
this whole thread makes me glad i dont use windoze anymore,

and it's a joke that if you go to any torernt index site the top searches other than media are damned security apps.
ph34r.gif
ph34r.gif
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
steve-p said:
this whole thread makes me glad i dont use windoze anymore,Linux or OSX?

steve-p said:
and it's a joke that if you go to any torernt index site the top searches other than media are damned security apps.
ph34r.gif
ph34r.gif
Yeah, people just don't understand things. D:


QUOTE(.Radiant @ Feb 14 2010, 09:16 PM)
srsly. safe mode, a program like malware bytes and an online scanner will solve most of your problems.
And that's what the basic instructions are, however there's infections that will modify all sorts of things in order to prevent that. Some will remove or modify files causing a STOP error when you try to go into safe mode, some will hook into windows in order to kill any process it recognizes as capable of removing it (originally they went by just filename, but not anymore), some will entry fake DNS entries in the hosts file to block known malware removal sites or redirect to fake sites, others will set up a proxy so they can update the blocks and redirects from their end, or just set your connection up to use a fake DNS server itself...

There's plenty modern infections (especially those fake virus removers) can do to prevent you from just running a scanner, that's why this guide is as long as it is.
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
Sephi said:
combofix always saves the day.And it scares people when they watch you run it! =D

Sephi said:
also, you wouldn't happen this guy would you http://www.gaiaonline.com/p/9462127Fo'rizzle.

QUOTE(Sephi @ Feb 14 2010, 09:31 PM)
I am the caffeinated one that quit the forums after a day
Don't remember you. D:
 

antwill

Better Than You
Member
Joined
Dec 24, 2006
Messages
1,023
Trophies
0
Age
34
Location
Australia
Website
Visit site
XP
166
Country
Why not mention 'common sense' in the prevention section as well? It's not that hard to avoid all of these problems with a bit of common sense after all.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    slaphappygamer @ slaphappygamer: I havent played my xbox360 is a couple of years. My switch got much use the last few days. Tears...