Spyware/Adware/Virus/Trojan/Rootkit/Keylogger Removal Guide

Trulen

Well-Known Member
Member
Joined
Jun 27, 2007
Messages
447
Trophies
0
XP
315
Country
United States
Great stuff! Thanks. Will come in great handiness when I fix up folk's computers that Microsoft Security Essentials can't handle.
 

ComplicatioN

Broken Barriers
Member
Joined
Aug 23, 2008
Messages
844
Trophies
0
Age
38
Location
Thousand Sunny
Website
Visit site
XP
304
Country
Alright thanks, managed to revive my screwed up comp thanks to this guide
tongue.gif

Thumbs Up
 

Minox

Thanks for the fish
Former Staff
Joined
Aug 27, 2007
Messages
6,995
Trophies
2
XP
6,156
Country
Japan
Skyline969 said:
Ah, my faith in Malwarebytes' Anti-Malware has been strengthened even more. My friend had a horrible virus on her computer, where she couldn't access any websites at all. It disguised itself as "Vista Antispyware 2010" or some bullshit, which to her (since she's a total retard on the computer) looked legit. I knew it was a virus right away, because she said it appeared out of thin air, and said she didn't install it. I had to send her MBAM through MSN, and one 3-hour scan later her computer was completely repaired. MBAM 23439408789239, virus 0.
tongue.gif
I got a similar infection myself through a java exploit. It wasn't Vista Antispyware 2010, but it was something along those lines. However scanning my hard drives for this infection took far too long and didn't yield much of a result so I ended up having to remove it manually. Luckily I had shut down my computer instantly when I noticed that fraud anti-spyware/virus application and rebooted into safe mode so it didn't have much time to mess around with things. Another good thing was that the infection was rather stupidly made and only one instance of it existed. Once I had removed that and a couple of registry changes it had made I was pretty much done. Although I still ran another scan to make sure of it being removed properly.

So what did I learn from all this? Well first of all I learnt that I should have noscript running all the time to avoid nasty java/flash exploits. I also learnt that once you know what you're dealing with it's sometimes much easier to just remove it manually. That is unless the infection does major changes to your computer.
 

MaK11-12

Well-Known Member
Member
Joined
Jul 26, 2009
Messages
241
Trophies
0
Location
Namek
Website
www.deltabeard.com
XP
434
Country
OR you could just use UBCD which has loads of Computer repair stuff.
Great guide though. BUT i haven't got an anti-virus, and still no virus in sight. You have to be smart when browsing the net otherwise there isn't any need for anti-virus.
OR you could just use linux ((K)ubuntu/Puppy/Slitax/Slax/ect)
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
MaK11-12 said:
Great guide though. BUT i haven't got an anti-virus, and still no virus in sight.A - I've never been to the doctor! I don't need to, no doctor has ever told me I'm sick!
B - I never bothered getting checked for STDs, because I'm sure I don't have any!
C - Well I don't see anybody wearing a black suit and shades, so there's no FBI agents here!

MaK11-12 said:
You have to be smart when browsing the net otherwise there isn't any need for anti-virus.CNET: Malware delivered by Yahoo, Fox, Google ads
QUOTE said:
Viruses and other malware were found to be lurking in ads last year on high-profile sites like The New York Times and conservative news aggregator Drudge Report.com, and this year on Drudge, TechCrunch and WhitePages.com. The practice has been dubbed "malvertising."
QUOTE(MaK11-12 @ Jul 18 2010, 11:09 AM)
OR you could just use linux ((K)ubuntu/Puppy/Slitax/Slax/ect)
Unless they need to use some windows-only programs as a requirement of their work/school.


If this guide was not needed it would not exist and would not be stickied.
 

Ace

GBATemp's Patrick Bateman
Member
Joined
Apr 8, 2009
Messages
1,034
Trophies
0
Age
29
Location
Manhattan
Website
goo.gl
XP
538
Country
I'm trying to follow this guide for my cousin with the Super Removal. She's only here for visit and doesn't have her Vista recovery discs, so I'd be delighted to know what to do if Super Removal method fails? I'm well-oriented with these methods already, I just need to know what comes if Super Removal will not have an effect.
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
Make a new user account and run rkill, then disable the proxy in the windows control panel and change your DNS settings to auomatic. Install an antispyware program fresh and scan with it, then run hijackthis and let hijackthis.de analyze your log, pick out whatever in there it marks as bad and anything else you find suspicious (like shit with a random name running from application data or a temp directory, keep a specific eye out for those) and fix it, then do a full antivirus scan.

If critical windows files have become infected you're kinda' fucked (and when this is fixed you need to turn UAC on and leave it on), you'll need to borrow somebody else's disc (with vista the version doesn't matter as long as it's the right bit-depth) and do an in-place "upgrade" (which is like XP's repair install), which will reinstall windows overtop of itself, leaving all your personal files, but some/all programs need to be reinstalled and windows update needs to be run again.
 

Ace

GBATemp's Patrick Bateman
Member
Joined
Apr 8, 2009
Messages
1,034
Trophies
0
Age
29
Location
Manhattan
Website
goo.gl
XP
538
Country
Rydian said:
*How I should fix the system*

Thank you. I somewhat foresaw I'd need a Vista CD. I have one available from my mother's company (old Company-versions of Windows, most likely with VLK keys... Distribute or not?
evil.gif
), so I won't need to change my Windows Activation key, right?

I should mention that the virus she has (most likely Vundo, although it also gives thousands of error messages of a fake svchost process called "svchosty.exe") has crippled her system to a BSOD the instant Windows has finished booting, and Safe Mode is compromised as well. This is why I am now attempting the Super Removal. Upon questioning her on details (She isn't good with anti-virus programs), she came to the conclusion that the system has had the virus for a few weeks, to a few months. This was alerting, of course. I don't think I've heard of anyone using a crippled system for THAT long.
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
The discs that tend to come with computers are usually modified copies and don't have any of the extra options (such as upgrading or even the recovery console sometimes) and are just made to image the drive, so be careful.

If it's been there for ages then the livecd should be able to remove it.
 

Ace

GBATemp's Patrick Bateman
Member
Joined
Apr 8, 2009
Messages
1,034
Trophies
0
Age
29
Location
Manhattan
Website
goo.gl
XP
538
Country
I really must thank you for this guide! It helped my cousin remove her Vundo + about 30 other viruses from her computer. For me, I just got another one of those "Fake AntiSpyware Crapware Beta 2.33.1235 2011 Christmas Rudolph's Limited Special Edition" from an XSS'd website. NOD32 and Malwarebytes' Anti-Malware got them away in a few hours
wink.gif
 
Joined
Apr 12, 2009
Messages
379
Trophies
1
Age
28
XP
540
Country
United States
Dude, you are a genius. I had to reset my computer at least 4 times since I had no way on how to remove a virus(w/o installing programs to slow my computer down)
 
Joined
Apr 12, 2009
Messages
379
Trophies
1
Age
28
XP
540
Country
United States
Hey, I click the link for super removal and it pops up with unable to go to the site. so i found another site with a bunch of Antivirus Live cd downloads
smile.gif

Antivirus Live CD

Rydian, add this in your Super Removal links
smile.gif
 

aimansss95

Well-Known Member
Member
Joined
Dec 22, 2008
Messages
271
Trophies
0
Age
34
Location
malaysia
XP
101
Country
United States
Help!!
I can't open those four flavors thing cause this 'security tool' doesn't allow me to
HELP PLS
frown.gif


EDIT = And any of the programs that is said that can delete this virus
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: @NinStar, why you hurting your sisters