Malware Cleaning Guide - MalwareTeks Wiki

Malware Cleaning Guide


From MalwareTeks Wiki

Jump to: navigation, search
These instructions are for Windows 2000/XP/2003/Vista


Often problems are solved just by running Preliminary Scans.


Important Notice:

No system that has been infected can be trusted ever again. The only way to ensure that your system is safe again, is to do a 'Clean Install' of the Operating System. If your system has a 'RootKit' installed, there is a good chance your system is completely subverted by the RootKit; and is not to be trusted ever again. Malware comes in many forms; Spyware, Adware, Viruses, Trojans, Worms, Keyloggers, Remote Administration Tools and RootKits; ranging in difficultly to remove. Some can simply be removed by uninstalling the Malware via Add or Remove Programs in the Control Panel; others can be extremely difficult to remove. However the only way to truly be sure that the Malware is completely gone is to completely remove the partitions, format the drive, and do a 'Clean Install' of the Operating System.

If you don't take this advice and decide to do a manual clean instead of a reinstall of your system don't blame us if any sensitive data is stolen from you. The only reply you will ever get from us will be: "YOU WERE WARNED!"


Make sure you know how to do the following:

Do NOT disable System Restore yet! An infected restore point is better than no restore point at all.


In order for the volunteers, who offer a their free time and expertise, to assist you in a timely manner, complete the following steps before posting a request for help:


Download and install the following tools. Make sure to get ALL updates.


This will self extract to C:\Program Files\Trend Micro\HijackThis.


If you already have HijackThis and it's not in this location. Uninstall HijackThis and reinstall HijackThis from the above link

Many people are under the very mistaken impression that HijackThis (HJT) is a Malware removal tool. It is not. HJT is simply a tool that is used to identify browser hijackers and in some cases will show entries for 'some' Malware that is, for instance, running at startup, but HJT will by no means show everything. Those who have infected computers and are relying on HJT without the benefit of running additional scans such as the ones in this guide, listed below, are more than likely still infected. In most cases, where there is one Virus/Trojan there are more.


IMPORTANT: Rename hijackthis.exe to analyse.exe. There is a variant of Virtumonde (Vundo), aka WinFixer, that keys on the name HijackThis. If you do not rename HijackThis we will not see the infection in the initial HJT log.

You will need to create a new shortcut to HijackThis or fix the path in the existing shortcut.


Update to the latest definitions and Enable its "Immunize" feature and Do NOT use TeaTimer!


Put this on your Desktop for easier access.


Double-click mbam-setup.exe and follow the prompts to install the program. Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. If an update is found, it will download and install the latest version. Close Malwarebytes' Anti-Malware




Cleaning Process


1 - Look in Add/Remove Programs and uninstall any Applications that you deem suspicious.


For a list of Malware applications that can be uninstalled via Add or Remove Programs see: Uninstall Malware via Add/Remove Programs


2 - Enable the viewing of hidden files and folders. Also uncheck Hide Protected Operating System Files


Close ALL Browsers and physically unplug your Internet Cable


3 - Now reboot to Safe Mode and continue -->

  • Run ATF Cleaner 3 by Atribune
-- Click on ATF-Cleaner.exe to run it

-- Where it says Select Files To Delete, Check the Select All Option
-- Click Empty Selected > OK > EXIT
-- If you use Firefox browser

  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click No at the prompt.
-- If you use Opera browser

  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.

NOTE: If you would like to keep your saved passwords, please click No at the prompt.

-- Click Exit on the Main menu to close the program.

NOTE: This will remove all files from the items that are checked so if you have some cookies you'd like to save. please move them to a different directory first.


Notes for Windows Vista users:

On Windows Vista "Windows Temp" is disabled, to empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator". Prefetch has been disabled on Windows Vista.


  • Run Spybot Search and Destroy and allow it to "fix" anything it finds.
-- Unblock Ignored Products - Choose Mode > Advanced Mode > Yes > Settings > Ignore Products > All Products tab. Right click and choose Deselect All


  • Run Malwarebytes' Anti-Malware
-- Once the program has loaded, select Perform quick scan, then click Scan.

-- When the scan is complete, click OK, then Show Results to view the results.
-- Be sure that everything is checked, and click Remove Selected.

-- When completed, a log will open in Notepad. Save the log to a convenient location, you will be posting the log later.


  • Open and run Microsoft Malicious Software Removal Tool and fix what it finds.


Reconnect your Internet Cable


4 - Now reboot to Safe Mode with Networking and continue -->


(Use of Internet Explorer is required for this step)


Choose 2 of the following Online scans and run them:


Be sure to save the logs.


If after doing the above steps you are still having problems, continue with the below:


Post Cleaning Process


5 - Reboot back into Normal Mode


  • Run ISeeYouXP


NOTE: For Win9x and WinMe users! ISeeYouXP does not support Win9x and WinMe.


Double-click ISeeYouXP.exe, ISeeYouXp will be extracted to C:\ISeeYouXP; and a shortcut to ISeeYouXP.bat will be placed on the Desktop.


Double-click the ISeeYouXP shortcut to run ISeeYouXP.


IMPORTANT NOTE: Vista Users

UAC must be turned off to run this script.

Turning Off/On UAC in Vista
1. Open the Control Panel.
2. Under User Account and Family settings click on the "Add or remove user account".
3. Click on your user account.
4. Under the user account click on the "Go to the main User Account page" link.
5. Under "Make changes to your user account" click on the "Change security settings" link.
6. In the "Turn on User Account Control (UAC) to make your computer more secure" click to unselect the "Use User Account Control (UAC) to help protect your computer". Click on the "OK" button.
7. You will be prompted to reboot your computer. Do so.

In order to re-enable UAC just select the above checkbox and reboot.


Vista Users: To Run ISeeYouXP right-click on ISeeYouXP.bat and select "Run as Administrator"


Possible Error Messages

-- If your ISeeYouXP.txt log appear to be empty or semi-empty or if you get an error message similar to the below
when running ISeeYouXP.bat and you are running Windows XP or Windows 2000, follow the steps further down that relate
to your OS
C:\WINDOWS\SYSTEM32\AUTOEXEC.NT.
The system file is not suitable for running MS-DOS and Microsoft Window applications.


To fix the above error message, choose the download below which is appropriate for your system

  • For Windows XP Pro: download and run: XPproFix
  • For Windows XP Home: download and run: XPHomeFix
  • For Windows 2000: download and run: W2KFix Then run ISeeYouXP.bat again and attach the log.

-- A possible second type of error message may occur as shown below! If you get either of these two messages, perform the Resolution steps given in this: Virtual Device Driver Error Message in 16-Bit MS-DOS Subsystem
16 bit MS-DOS Subsystem
drive:\program path
XXXX. An installable Virtual Device Driver failed DLL initialization. Choose 'Close' to terminate the application.

-or-
16 bit MS-DOS Subsystem
drive:\program path
SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers. VDD. Virtual Device Driver format in the registry is invalid. Choose 'Close' to terminate the application.

After attempting to fix the above errors, run ISeeYouXP.bat again and attach the log.


  • Run HijackThis
-- Right-click the Start Button at the bottom-left corner of the screen. Click "Explore" to open Windows Explorer.

-- Navigate to C:\Program Files\Trend Micro\HijackThis and double-click analyse.exe.
Note: On XP, an Open File security window may pop up, click Run.

-- Click the Do System Scan and Save Logfile button.
-- Hijackthis will scan your system, it may take a little while.
-- When it has finished a notepad will automatically pop up.
Note: Do NOT attempt to fix anything yourself as a lot of what HijackThis lists is useful and even essential to the running of your PC.

-- Close the notepad file and exit Hijackthis.

Note: The HijackThis log file is already saved in the HijackThis installation folder (C:\Program Files\HJT\hijackthis.log).


Start a thread in our Malware Removal Forum where one of our approved volunteers will be happy to assist you.


You must be a registered member of our site; in order to post in the Forums.


If you are not registered you may do so now, by Clicking Here!


Attach the following logs:

  • ISeeYouXP
  • HijackThis
  • Malwarebytes' Anti-Malware
  • Both Logs from the Online Anti-Virus scanners (You chose to run)


To attach your logs, do the following:

  • Save your files as a .txt file somewhere such as your desktop where they will be easy to locate.
  • Under Add an Attachment you will see a Filename box
  • Click Browse to the right of the Filename box and browse to where you saved your text file
  • Highlight your file and choose Open
  • Now choose Add Attachment


Please note that responses to threads requesting help may be limited as this is a community forum dependent on the free time and good will of volunteers. Also, please be aware that not all of the advice given in an open forum is accurate. Do not be afraid to question any advice you believe to be suspect!


Copyright MalwareTeks 2006-2008

MalwareTeks retains the Copyright to this article.

You may not reproduce this article in whole or part without the expression permission of the author.


Updated: 14 June, 1008

Views
Personal tools
Ads