View Single Post
  #1 (permalink)  
Old 01-26-2009, 03:20 AM
Blind Dragon's Avatar
Blind Dragon Blind Dragon is offline
Site Admin

 
Join Date: Dec 2008
Location: Florida
Posts: 1,310
Send a message via MSN to Blind Dragon Send a message via Yahoo to Blind Dragon Send a message via Skype™ to Blind Dragon
Default Virus/Malware Preliminary Removal Instructions

Very Important: Malware infections can possibly lead to identity theft, stolen bank funds, misuse of credit card information etc.

After completing these steps your symptoms may disappear, you still need to post your logs so that we can check them. We also need to secure your system from future attacks


================================================== =======

Step 1

Temporarily Disable Real Time Monitoring Programs

This is because some real time protection programs can interfere with any fixes we are trying to run.

See How to disable real time monitoring... for some of the most commonly used programs.

Once your system is clean, you are advised to turn the protection back on.

If you need specific instructions on your product, or if you have other protection that may need disabled feel free to ask in your thread in the security section.

================================================== =======

Step 2

If you`re NOT running any antivirus or firewall software, you should install some ASAP

If you already have an Anti-virus program - please be sure to check for updates and run a full scan of your system - Please note anything that it finds in your thread.

Recommended Free Anti Virus:


Recommended Free Firewall:
================================================== =====

Step 3

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

================================================== =====

Step 4

Malwarebytes' Anti-Malware
  • Please download Malwarebytes' Anti-Malware from from Here or Here
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
  • Update Malwarebytes' Anti-Malware
  • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please attach this log with your reply
  • If you accidently close it, the log file is saved here and will be named like this:
  • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

================================================== ====

Step 5

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.


  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.

================================================== =====

Step 6

Update your Java Runtime Environment

Many types of malware like to exploit out of date Java versions!
  • First Verify that your version is up to date by clicking HERE
    If you need to update your version:
  • That link button will change to one that allows you to update directly by clicking on it, in which case please do so.
  • When it finds the newer version - Follow the on screen instructions (uncheck the yahoo toolbar option)
  • After it installs the newest version Go back to Start -> Control Panel -> Add/remove programs (programs and features in vista)
  • Uninstall any older versions of Java except the most current update that you just installed

You can manually install the most recent version of Java through this link -> Java Runtime Environment Make sure to scroll down to Java Runtime Environment

================================================== =====

Step 7


Please download DDS by sUBs from HERE or HERE and save it to your Desktop.

Vista users. Right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

  • Double click on dds to run it.
  • When done, DDS.txt will open.
  • You will receive another prompt after a while. Click Yes at the prompt. It will take another few minutes to scan.
  • When done, Attach.txt will open.
  • Please copy and paste the contents of DDS.txt and attach the Attach.txt in your next reply.


================================================== ========

Step 8

If you do not already have a thread, please start a new thread in our Virus and Malware Removal Forum

Copy and paste the following logs PLEASE DO NOT ATTACH LOGS UNLESS WE SPECIFICALLY ASK FOR THEM!,

1) DDS log and attach the Attach.txt
2) Malwarebytes Anti Malware log
3) GMER log


!!!Also remember to tell us any symptoms that you may be having !!!