Malware Removal StepsBelow are steps to begin the malware removal process. The steps will produce three logs which are requested to be added in your post.
* Important: Work the steps in order.* If you don't understand a step
stop and ask!* Keep all questions/replies in the same thread.
* Continue to respond until given the all clear.
* Be patient: Malware removal can be just as time consuming and stressful for us as it is for you.
* Remember: Just because the symptoms may be gone does not promise that all of the malware is. It is strongly suggested to continue in posting all requested logs until given the all clear. You will then receive final cleanup steps specific to your PC, links to programs and advice to help you prevent infections in the future.
If for some reason you cannot perform one of the steps, move on to the next step and make note of what happened when posting your logs.
Spybot TeaTimer Users Only
While TeaTimer is an excellent tool for the prevention of spyware, it can also interfere with HijackThis and other tools we use to remove malware.
Please disable TeaTimer now and leave it OFF until we are done cleaning the computer.
1. Right click Spybot in the System Tray (looks like a calendar with a padlock symbol) then choose Exit Spybot S&D Resident
2. Run Spybot S&D
3. Go to the Mode menu, and make sure Advanced Mode is selected.
4. On the left hand side, choose Tools > Resident uncheck Resident TeaTimer and OK any prompt and Restart your computer.
Note: If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.
If TeaTimer will not turn off go to Start > Control Panel > Add or Remove Programs and uninstall Spybot - Search & Destroy
Spybot can be re-installed once we are done cleaning the computer.
Step A: AntivirusStep A is for people who say yes to either of the following:
1) You do not have an antivirus installed.
2) You have an antivirus program or Security Suite that is expired.
If the answer to either of the above is yes:Download one of the free antivirus programs listed below.
.Important: Uninstall any old/outdated antivirus program(s), including Security Suites before upgrading or replacing with a new one.
Install the new antivirus and make sure it is updated.
Do a
full system scan and remove or quarantine everything found.
Continue on to Step One.
Step B: FirewallIt is critical that XP users use third party firewall software to protect your computer and your personal information from hackers. Microsoft even acknowledges that the built in XP firewall is insufficient in this article.
Why would I consider a third party firewall?Step B is for people who say yes to any of the following:
1) You have Windows XP (any version) and only use the built in Windows firewall.
2) You have a firewall that you don't like or is expired (no longer updates).
3) You use Windows XP (any version) and don't know what a firewall is.
If the answer to any of the above is yes, download and install one of the free firewalls listed below.
Only install one firewall at a time or you can damage your computer.
.You should only have one antivirus and one firewall active at any time. If you have two of either installed then only ONE should be running. Either uninstall one now before continuing or adjust the settings to where the real-time protection is not running. Having two running at the same time will just cause problems.Step 1: Add or Remove Programs1. Click on the Windows
Start button and click on the
Control Panel2. In the
Control Panel window, double-click
Add or Remove Programs icon.
3. When the
Add or Remove Programs window has fully populated, check for any unknown or suspicious looking programs.
4. Do not uninstall anything you may be unsure of.
5. Post the details of unknown or suspicious programs when creating a thread and we will advise on which to uninstall.
For a list of Malware applications that can be found in Add or Remove Programs follow this link.
Uninstall Malware via Add or Remove ProgramsPrograms to look for are adware/spyware toolbars (not Google, AOL, MSN or Yahoo) or security programs you did not install.
Step 2: House CleaningDownload
CCleaner Slim and save it to your Desktop -
Alternate download linkWhen the file has been saved, go to your Desktop and double-click on
ccsetupxxx_slim.exeFollow the prompts to install the program.
* Double-click the
CCleaner shortcut on the desktop to start the program.
* Click on the
Options block on the left, then choose
Cookies.
* Under
Cookies to Delete, highlight any cookies you would like to retain permanently
* Click the right arrow
> to move them to the
Cookies to Keep window.
* Go into Options > Advanced uncheck Only delete files in Windows Temp folders older than 48 hours* Click
Cleaner on the left then
Run Cleaner on the right to run the program.
*
Important: Make sure that
ALL browser windows are closed before selecting
Run Cleaner
Caution: Only use the
Registry feature if you are very familiar with the registry.
Always back up your registry before making any changes.
Exit CCleaner after it has completed it's process.
.Step 3: SUPERAntiSpywareIf you already have SUPERAntiSpyware be sure to check for updates before scanning!Download
SUPERAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to
Update the program definitions, click
Yes* If you encounter any problems while downloading the updates, manually download and unzip them from here* Next click the
Preferences button.
- Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the
Scanning Control tab.
* Under
Scanner Options make sure only the following are checked:
- Close browsers before scanning
- Scan for tracking cookies
- Terminate memory threats before quarantining
- Please leave the others unchecked
- Click the Close button to leave the control center screen.
* On the main screen click
Scan your computer* On the left check the box for the drive you are scanning.
* On the right choose
Perform Complete Scan* Click
Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click
OK* Make sure everything in the white box has a check next to it, then click
Next* It will quarantine what it found and if it asks if you want to reboot, click
Yes- To retrieve the removal information please do the following:
- After reboot, double-click the SUPERAntiSpyware icon on your desktop.
- Click Preferences. Click the Statistics/Logs tab.
- Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
- It will open in your default text editor (preferably Notepad).
- Save the notepad file to your desktop by clicking (in notepad) File > Save As...
* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*
Copy and Paste the log in your post
Step 4: Malwarebytes' Anti-Malware (MBAM)If you already have Malwarebytes be sure to check for updates before scanning!Download
Malwarebytes Anti-Malware and save it to your desktop.
Alternate download link (.exe)- Double-click mbam-setup.exe and follow the prompts to install the program.
- Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform Quick Scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When completed, a log will open in Notepad. Save it to a convenient location like the Desktop.
- The log is also automatically saved and can be viewed later by clicking the Logs tab in MBAM.
- Copy and Paste the contents of the report in your reply.
- Exit MBAM.
.Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.Step 5: Update Your Java (JRE) Old versions of Java have vulnerabilities that malware can use to infect your system.First
Verify your Java VersionIf there are any other version(s) installed then update now.
Get the new version (if needed)If your version is out of date install the newest version of the
Sun Java Runtime EnvironmentNote: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
Be sure to close ALL open web browsers before starting the installation.Remove any old version1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose
Remove Older Versions3. Once complete exit JavaRA.
4. Run CCleaner.
Additional Note: The
Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to
Start > Control Panel > Java > Advanced > Miscellaneous and
uncheck the box for
Java Quick Starter. Click OK and reboot your computer.
Step 6: DDSDownload
DDS from
HERE or
HERE and save it to your desktop.
Vista and Windows 7 users right click on
dds and select
Run as administrator (you will receive a UAC prompt, please allow it)
*
XP users Double click on dds to run it.
* If your antivirus or firewall try to block
DDS then please allow it to run.
* When finished
DDS will open two (2) logs.
* Save both reports to your desktop.
* The instructions here ask you to attach the Attach.txt.

1)
DDS.txt2)
Attach.txtInstead of attaching, please copy/past both logs into your ThreadNote: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copying and pasting it into the reply.
* Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control
HERE .Then post your DDS logs. (
DDS.txt and
Attach.txt )
Posting The LogsPlease give details. Just posting the logs in many instances is not enough information for us.Post the logs in the
Virus and spyware removal forum.
Logs needed:- SuperAntispyware
- Malwarebytes' Anti-Malware
- DDS logs (DDS.txt & Attach.txt)Please copy and paste the logs directly into the reply unless specifically requested by your helperIllegal softwareComputer Hope does not support illegal activity. We do not support the use of any pirated or otherwise illegal software including Windows itself. If you install the cracked software, you are running executable files from unknown sources. You are in effect giving unknown sources access to information on your hard disk and potentially giving complete control over the operation of your computer.
* We will
NOT help anyone pirate anything or help to make the system work with pirated software. But if you mess up your computer in the process, we will help you fix it.
* Uninstall any cracked applications before posting for help.
* You may be asked to uninstall any P2P or File Sharing programs during the removal process if they are believed to be the source of the problem.
* We will discontinue help if you refuse to remove any cracked (illegal) program.