Re: removing infected files

From: Bob_Whaley (Bob_Whaley_at_discussions.microsoft.com)
Date: 01/25/05


Date: Tue, 25 Jan 2005 08:33:08 -0800

Thanks for a very disciplined and useful answer, Malke. It is a good example
of how to help others.

"Malke" wrote:

> tungstentoaster wrote:
>
> > I would suggest deleting them in the MS-DOS environment booting your
> > computer on an MS-DOS boot disk and using "del C:\undo\<name of
> > infected file>.ini" for each.
>
> This will not be useful for the OP unless he has a) his XP installation
> on a FAT32 partition; b) or is using a specialized DOS boot disk that
> can read NTFS.
>
> To the OP: Make sure your NAV has the most current virus definitions and
> scan with it in Safe Mode. To get to Safe Mode, repeatedly tap the F8
> key as the computer is starting. This will get you to the proper menu.
> Do a thorough scan.
>
> If you are having difficulty seeing files/folders, make sure you have
> the Folder Options>View choices set to show all files and extensions.
> After you are completely sure your computer is clean, make a new System
> Restore point and delete all but that System Restore point from the
> More Options section of Disk Cleanup (Run>cleanmgr).
>
> Here are general malware removal steps. Do everything with updated tools
> in Safe Mode:
>
> 1) Scan in Safe Mode with current version (not earlier than 2003)
> antivirus using updated definitions.
>
> Before you remove malware, get LSPFix (or WinSockFix for XP which you
> can get from MajorGeeks) - see links below.
>
> 2) Remove spyware with Spybot Search & Destroy and Ad-aware. These
> programs are free, so use them both since they complement each other.
> There is a new version of CWShredder from Intermute. I would not
> install the other Intermute programs, however. Alternately, there are
> CoolWebSearch malware removal steps at SilentRunners.
>
> Be sure to update these programs before running, and it is a good idea
> to do virus/spyware scans in Safe Mode. Make sure you are able to see
> all hidden files and extensions (View tab in Folder Options).
>
> If the malware remains even after you used Ad-aware and Spybot, you can
> scan with HijackThis. HijackThis is an excellent tool to discover and
> disable hijackers, but it requires expert skill. See below for
> HijackThis links, including sites where you can post your HJT logs. A
> combination of HijackThis and About:Buster works well in removing the
> About:Blank homepage hijacker. Again, this is an expert tool and
> novices should get help with it.
>
> 3) If you are running Windows ME or XP, you should disable/enable System
> Restore because malware will be in the Restore Points. With ME, you
> must disable System Restore completely. With XP, you can delete all but
> the most recent (presumably clean) System Restore point from the More
> Options section of Disk Cleanup (Run>cleanmgr).
>
> 4) Make sure you've visited Windows Update and applied all security
> patches. Do not install driver updates from Windows Update.
>
> 5) Run a firewall.
>
> Links to help with malware:
>
> Software/Methods:
> http://www.safer-networking.org - Spybot Search & Destroy
> http://www.lavasoftusa.com - Ad-aware
> http://www.majorgeeks.com - good download site
> http://www.intermute.com/spysubtract/cwshredder_download.html
> http://www.silentrunners.org/sr_cwsremoval.html. - SilentRunners
> http://www.cexx.org/lspfix.htm - Repair Winsock 2 settings after
> removing spyware
>
> HijackThis:
> http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
> Eshelman
> http://forum.aumha.org/
> http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
> forum
> http://www.wilderssecurity.com/
> http://forums.tomcoyote.org/
>
> General:
> http://forum.aumha.org/ - look under "Security" for various forums
> http://rgharper.mvps.org/cleanit.htm
> http://mvps.org/winhelp2002/unwanted.htm
> http://www.aumha.org/a/parasite.htm - The Parasite Fight
> http://www.spywarewarrior.com/rogue_anti-spyware.htm
>
> Malke
> --
> MS MVP - Windows Shell/User
> Elephant Boy Computers
> www.elephantboycomputers.com
> "Don't Panic!"
>



Relevant Pages

  • Re: blue screens and avg
    ... Thanks ever so much Malke for your VERY comprehensive advice! ... > Certainly you can clean up your computer before doing a System Restore ... > and if you suspect that malware is the issue, ... > scan with HijackThis. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Dialer.WSV
    ... "Malke" wrote: ... > Before you remove malware, get LSPFix or WinSockFix for XP - see links ... > scan with HijackThis. ... you must disable System Restore completely. ...
    (microsoft.public.security)
  • Re: Nasty Virus need Help Badly!
    ... Thanx Malke I will take you up on your advice! ... >> System Restore its almos the same kinda thing, ... Please do not post HijackThis ... Following the malware removal steps I will give ...
    (microsoft.public.security)
  • Re: Malware
    ... > You are correct - you do have malware on your computer. ... To get to Safe Mode, repeatedly tap the F8 key as the ... See below for HijackThis links. ... > the most recent System Restore point from the More ...
    (microsoft.public.windowsxp.network_web)
  • Re: Copy Paste Function
    ... I deleted my system restore points so I think ... > It sounds like you have malware on your computer. ... See below for HijackThis links. ... > 3) If you are running Windows ME or XP, ...
    (microsoft.public.windowsxp.general)

Loading