Tuesday, July 14, 2009

How to properly remove malware?

my laptop has a lot of malware in it all in the program files (c:\program files\) xml, xmod, xsofware, zsearch, data 19, e2g a whole bunch of stuff. i know i could put in the OS disc (XP home) and repair windows. would i still be able to type in program files in the repair windows screen and delete these malware files or should i rename them. If you could please give me help that would be great. DETAILED ANSWERS PLEASE! if it helps i used malware immunizer 1.5 a free malware sweeper.

How to properly remove malware?
Get adaware free and spybot. Run them, between the two they should clean up 99% of your problems.





www.lavasoft.com





www.safer-networking.org
Reply:Well if you don't want to reformat %26amp; rebuild your hard drive and are willing to spend some time doing it manually, give this procedure a shot. I haven't had it fail yet.





All you need for info is the name of the "malware" you're trying to get rid of. You'll need to do this procedure for each piece of malware you are infected with. Give it a shot.





DELETING PROBLEM FILES - SOFTWARE -MALWARE FROM YOUR PC





Let’s assume the problem File/Software/Virus, etc. is named “W32spybot” and you want to remove it from your PC.





Where ever you see the name “W32spybot” below, you will need to insert the actual name of the file/software/virus, etc. that you are trying to remove.





Click on Start %26gt; Settings %26gt; Control Panel %26gt; Add/Remove Programs and remove any “W32SPYBOT” programs residing there.





Now click on Start %26gt; Search %26gt; For Files or Folders %26gt; All Files and Folders


type in “W32SPYBOT” in the top box and let the computer do a complete search of your hard drive.


When it is done, click on Edit at the top of the window and click on Select All


Then click on File and click on Delete. It will ask you if you want to remove them. Click on Yes.





If you want to REALLY finish the job:





NOTE: DON'T DO ANYTHING ELSE IN THE REGISTRY OTHER THAN WHAT I MENTION HERE.


If you are not familiar with editing the registry and you do other things you may give yourself some big headaches.





Click on Start %26gt; Run %26gt;





type in regedit





Click once on the very top directory in the left hand pane to hilite it.





Hold down Ctrl + F; this will open a search window





Type in “W32SPYBOT” and then click on Find Next





When it finds a “W32SPYBOT” entry, right click on it and select Delete and YES. (Do this whether it is a folder in the left hand pane or if it is an entry in the right hand pane)





Hold down Ctrl + F again and repeat the process until you have cleaned your registry of all “W32SPYBOT” items.





This is a bit of a tedious process so hang in there.





When you think you have it all out. Go back up to the top directory in the left pane, hilite it, and search for “W32SPYBOT” once again just to make sure you didn't miss any instances of it.





Once you have completely removed all instances of W32spybot from the Registry, reboot your PC. This will reset the registry without all the “W32SPYBOT” entries and you should be rid of your problem.
Reply:You unfortunately can't remove malware by just deleting files that look suspicious or by renaming them.





Speaking from personal experience, I had both my home computers attacked by all kinds of malware, spyware, and trojan programs - even though I had Norton installed on one computer, and McAfee on the other.





I did find a program called Spyware Doctor that was able to remove MalwareAlarm and all the other infections, and I took screenshots along the way in hopes of helping other people get their systems back to normal as well (link below).
Reply:I've not heard of Malware Immunizer, and I must say I'm a little suspicious of programs I don't know about. Here's some steps you might find useful.


1. download ad-aware (http://www.lavasoftusa.com/products/ad_a...


2. download spybot search and destroy (http://www.safer-networking.org/en/downl...


3. download ccleaner (http://filehippo.com/download_ccleaner/)


4. clear your temp files using ccleaner.


5. run spybot and ad-aware until they don't show any new detections. This may require rebooting several times.





This is a quick-and-dirty method, and may not completely remove what you've got.





When you're clean, make sure you're not using programs that contain spyware (Kazaa/limewire are a couple).





Run Windows Updates! Make sure you have all security updates marked on their site - especially ones listed as crititcal.





Get a good antivirus/antispyware solution... I know a lot of people think AVG is great, but honestly, it's really prone to false positives, so you might want to try something else.


No comments:

Post a Comment