Malware Removal StepsBelow are steps to begin the malware removal process. The steps will produce three logs which are requested to be added in your post.
* Important: Work the steps in order.* If you don't understand a step
stop and ask!* Keep all questions/replies in the same thread.
* Continue to respond until given the all clear.
* Be patient: Malware removal can be just as time consuming and stressful for us as it is for you.
* Remember: Just because the symptoms may be gone does not promise that all of the malware is. It is strongly suggested to continue in posting all requested logs until given the all clear. You will then receive final cleanup steps specific to your PC, links to programs and advice to help you prevent infections in the future.
If for some reason you cannot perform one of the steps, move on to the next step and make note of what happened when posting your logs.
Spybot TeaTimer Users Only
While TeaTimer is an excellent tool for the prevention of spyware, it can also interfere with HijackThis and other tools we use to remove malware.
Please disable TeaTimer now and leave it OFF until we are done cleaning the computer.
1. Right click Spybot in the System Tray (looks like a calendar with a padlock symbol). Choose
Exit Spybot S&D Resident2. Run
Spybot S&D 3. Go to the
Mode menu, and make sure
Advanced Mode is selected.
4. On the left hand side, choose
Tools >
Resident uncheck
Resident TeaTimer and
OK any prompt and
Restart your computer.
Note: If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.
With both TeaTimer and Spybot closed download
ResetTeaTimer.zip to the Desktop.
Unzip the file to the Desktop.
Double click
ResetTeaTimer.bat to remove all entries set by Spybot's TeaTimer.
Please don't forget this step to disable TeaTimer.
Delete ResetTeaTimer.zip when complete.
If TeaTimer will not turn off go to Start > Control Panel > Add or Remove Programs and uninstall Spybot - Search & DestroyIt can be re-installed when we are done cleaning the computer.
Step A: AntivirusStep A is for people who say yes to either of the following:
1) You do not have an antivirus installed.
2) You have an antivirus program or Security Suite that is expired.
If the answer to either of the above is yes:Download one of the free antivirus programs listed below.
Important: Uninstall any old/outdated antivirus program(s), including Security Suites before upgrading or replacing with a new one.
Install the new antivirus and make sure it is updated.
Do a
full system scan and remove or quarantine everything found.
Continue on to Step One.
You should only have one antivirus and one firewall installed at any time. If you have two of either installed then uninstall one now before continuing.Step 1: Add or Remove Programs1. Click on the Windows
Start button and click on the
Control Panel2. In the
Control Panel window, double-click
Add or Remove Programs icon.
3. When the
Add or Remove Programs window has fully populated, check for any unknown or suspicious looking programs.
4. Do not uninstall anything you may be unsure of.
5. Post the details of unknown or suspicious programs when creating a thread and we will advise on which to uninstall.
For a list of Malware applications that can be found in Add or Remove Programs follow this link.
Uninstall Malware via Add or Remove ProgramsPrograms to look for are adware/spyware Toolbars (not Google, AOL, MSN or Yahoo) or security programs you did not install.
Step 2: House CleaningDownload, install and run
CCleaner Slim -
Alternate download link - Double click on the ccsetup.exe file to start the installation of the program.
- Select your language and click OK, then Next.
- Read the license agreement and click I Agree.
- Click Next to use the default install location.
- Under Install Options, choose all the default settings
- Click Install then finish to complete installation.
- Double click the CCleaner shortcut on the desktop to start the program.
- On the Windows tab, under Internet Explorer, uncheck Cookies if you do not want them deleted. (If deleted, you will likely need to re-enter your passwords at all sites where a cookie is used to recognize you when you visit).
- If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
- Click on the Options icon at the left side of the window, then click on Advanced.
uncheck Only delete files in Windows Temp folders older than 48 hours.
- Click on the Cleaner icon on the left side of the window, then click Run Cleaner to run the program.
- Caution: Only use the Registry feature if you are very familiar with the registry.
- Always back up your registry before making any changes.
- Exit CCleaner after it has completed it's process.
.Step 3: SUPERAntiSpywareDownload
SUPERAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to
Update the program definitions, click
Yes* If you encounter any problems while downloading the updates, manually download and unzip them from here* Next click the
Preferences button.
- Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the
Scanning Control tab.
* Under
Scanner Options make sure only the following are checked:
- Close browsers before scanning
- Scan for tracking cookies
- Terminate memory threats before quarantining
- Please leave the others unchecked
- Click the Close button to leave the control center screen.
* On the main screen click
Scan your computer* On the left check the box for the drive you are scanning.
* On the right choose
Perform Complete Scan* Click
Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click
OK* Make sure everything in the white box has a check next to it, then click
Next* It will quarantine what it found and if it asks if you want to reboot, click
Yes- To retrieve the removal information please do the following:
- After reboot, double-click the SUPERAntiSpyware icon on your desktop.
- Click Preferences. Click the Statistics/Logs tab.
- Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
- It will open in your default text editor (preferably Notepad).
- Save the notepad file to your desktop by clicking (in notepad) File > Save As...
* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*
Copy and Paste the log in your post
Step 4: Malwarebytes' Anti-Malware (MBAM)Download
Malwarebytes Anti-Malware and save it to your desktop.
Alternate download link (.exe)- Double-click mbam-setup.exe and follow the prompts to install the program.
- Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform Quick Scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When completed, a log will open in Notepad. Save it to a convenient location like the Desktop.
- The log is also automatically saved and can be viewed later by clicking the Logs tab in MBAM.
- Copy and Paste the contents of the report in your reply.
- Exit MBAM.
.Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.Step 5: Update Your Java (JRE) Old versions of Java have vulnerabilities that malware can use to infect your system.First
Verify your Java VersionIf there are any other version(s) installed then update now.
Get the new version (if needed)If your version is out of date install the newest version of the
Sun Java Runtime EnvironmentBe sure to close ALL open web browsers before starting the installation.Remove any old version1. Go to
Start >
Control Panel >
Add or Remove programs and uninstall all older versions of Java.
2. Remove any item with Java Runtime Environment
(JRE or J2SE) in the name.
* Do not remove the new version just installed.3. Download JavaRa and unzip the file to your Desktop.
4. Open JavaRA.exe and choose
Remove Older Versions5. Once complete exit JavaRA and delete the program.
6. Run CCleaner.
Step 6: HijackThisPlease run HijackThis only after the above steps have been completed
Download and rename
HijackThis.exe (HJT)
* Double-click on HJTInstall.
* Click on the
Install button.
* It will automatically place HJT in
C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
* Upon install, HijackThis should open for you.
- Close HijackThis and rename it.
- Go to C:\Program Files\Trend Micro\HijackThis.exe
- Right click on HijackThis.exe and select Rename.
- Type in sniper.exe and press Enter.
- Right-click on sniper.exe and select Send To > Desktop (create shortcut)
.* From the desktop open HijackThis.
*
If using Windows Vista,
Right-click and Run As Administrator.
* Click on the
Do a system scan and save a log file button
* HijackThis will scan and then a log will open in notepad.
- Copy and Paste the entire contents of the log in your post.
.
Do not have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
.Although we have renamed HijackThis to sniper, we will still refer to it as HijackThis or HJT.
Posting The LogsPlease give details. Just posting the logs in many instances is not enough information for us.Post the logs in the
Computer Viruses and Spyware forum.
Logs needed:SuperAntispyware
Malwarebytes' Anti-Malware
HijackThis