Things you need to do when your pc is infected

Capt.Jack Sparrow

Crash Dump Analyst
Guru
Local time
5:04 PM
Messages
4,772
THINGS YOU NEED TO DO WHEN YOUR PC IS INFECTED




For those who are facing the challenge of malware removal, here's a basic guide on what to do when the system is infected.
But I strongly recommend posting a question for there are times when ComboFix and MalwareBytes are unable to remove the infection. For malware that patched system files we need to determine which file is patched and replace it before we can continue the cleanup process and run diagnostic tools.



" ISOLATE THE INFECTED SYSTEM:

The very first thing you should do is to isolate the infected system from the network to stop the spread of infection.
Turn off the internet connection except while you're downloading the tools to use which shouldn't take long. Or you can use another pc with internet access to download the files into a USB. Unplug the network cable, turn off wireless connections of the infected system. Do not share removable media device.



" LEAVE SYSTEM RESTORE TURNED ON:

DO NOT disable System Restore, you need to keep those restore points intact in case you need it later, you can disable it afterwards when the PC is clean and stable.
Any viruses in the System Restore (if there are any) are harmless so they pose no threat while in that folder.
For further information about viruses in System Restore check out below link --> Viruses in the System Volume Information (System Restore).



" BACKUP YOUR DATA:

As a precaution, you need to back up your important files now while you still can just in case something goes wrong during the cleanup and you have no choice but to reformat. Bear in mind that you MUST scan the backup before you start using them.



" ERUNT (Emergency Recovery Utility NT):

Some malware will turn off System Restore and other windows features to lessen the PC's functionality. If you noticed that the System Restore had already been turned off or tabs are grayed, use ERUNT to do a complete backup of the registry. Registry export is not good enough. Removing nasties requires making registry changes and if the registry is corrupted it can prevent the pc from booting. The ERUNT backup can then be restored later if needed.

Complete ERUNT tutorial:
t-online.de

If the virus has already disabled SR and you don't have ERUNT backup then the next thing you should do is run ComboFix before you run any other tools so you have a registry backup. Post a question and we'll guide you with its usage.



" DOWNLOAD THE TOOLS AND START THE CLEANUP:

Download the programs needed for the cleanup. There are many free tools out there but these ones below are among the most commonly used, they work well and they are FREE.
Usually MBAM or ComboFix alone will remove most infections but it's good to also clean temp folders.

a). ATF Cleaner or TFC
b). MalwareBytes
c). SUPERAntispyware
d). Combofix(with a Helper's guidance). Post a question if using ComboFix and attach the log file for us to analyse.



" SCAN FOR ROOTKITS:

If the problem is not resolved after scanning with reliable scanners, then scan for rootkits, I prefer using Gmer and RootRepeal. Even if the issue no longer exist it's always a good idea to scan with these tools for the reassurance that nothing is hiding.



" DISABLE SYSTEM RESTORE:

Once the problem is resolved and the system is clean, you can then disable System Restore to purge all those restore points, then turn it back On and immediately create a new and clean restore point.

How to turn Off/On System Restore:
How to turn off and turn on System Restore in Windows XP



" PREVENTION:

Prevention is better than cure so make sure that you have the 3 basic security real-time protections in-place, without doubling each one.

1. Antivirus
2. Firewall
3. Anti-malware

Make sure all your installed programs have regular updates and windows have all the critical security patches. Tighten security features in your browsers, if using Firefox use the 'no-script' add-on.
Install the latest version of java to minimize the risk of vundo threats as lower versions are very vulnerable to vundo exploits.
Use a customized Hosts file to block unwanted nasties. Browse the internet using a limited user account, even though this (LUA) is 'not useful' against the rogue family of antivirus it is still better than browsing online with an Admin account.

NOTE: the best protection is User Education.

For more in-depth info on prevention please read below links:

TonyKlein's article "So how did I get infected in the first place?
miekiemoes' "How to prevent Malware"
Simple and easy ways to keep your computer safe and secure on the Internet:

Source: THINGS YOU NEED TO DO WHEN YOUR PC IS INFECTED

Hope this helps,
Captain
 

My Computer My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)
I hope they sticky this.

Also you should have mentioned Imaging your system while its virus and problem free.

Many(myself included) keep current images of our systems incase of attack, infection or general windows blunders.

It is the fastest way to get back on your feet.
 

My Computer My Computer

Computer Manufacturer/Model Number
I trust nobody!
OS
Windows 7 Ultimate x64/x86 Windows 7 Pro x64/x86 Windows 7 Home Premium x64/x86
CPU
Intel C2Q 9650
Motherboard
Intel
Memory
8GB DDR2800 Corsair
Graphics Card(s)
NVIDIA 260 GTX
Sound Card
Onboard
Monitor(s) Displays
Dell 2409w
Screen Resolution
1920x1080
Hard Drives
10 of em!
PSU
600 Watt FSP Group
Case
Antec
Cooling
Fresh Air
Keyboard
Microsoft
Mouse
Razer
Internet Speed
Fast enough
Very useful information, thanks.
 

My Computer My Computer

Computer Manufacturer/Model Number
self built
OS
Windows 7 Professional 64-bit
CPU
Intel E8400 3GHz
Motherboard
Intel DX48BT2
Memory
Kingston PC3-10700H 4Gb
Graphics Card(s)
XFX Radeon HD 5850 BlackEd.
Sound Card
Asus Xonar DG
Monitor(s) Displays
2x Samsung SM-T220HD 22"
Screen Resolution
1680x1050 on two monitors
Hard Drives
OCZ Vertex 2 120gb 3.5" (OS)
Seagate Momentus XT 500gb
Samsung F3 1Tb (games)
2x Samsung F1 1Tb
PSU
Thermaltake ToughPower 850w
Case
Thermaltake Armor
Cooling
Scythe Mugen II
Keyboard
Microsoft Comfort Curve USB
Mouse
Razer Diamondback 3G
Internet Speed
8128/443
Very nice Bhai. :D
 

My Computer My Computer

Computer Manufacturer/Model Number
Samsung NP530U4B-S02IN
OS
Windows® 8 Pro (64-bit)
CPU
Intel® Core™ i5 Processor 2467M (1.60GHz, 3MB L3 Cache)
Motherboard
Samsung Electronics
Memory
6GB DDR3 System Memory at 1,333MHz (on BD 4GB + 2GB x 1)
Graphics Card(s)
AMD Radeon™ HD7550M 1GB DDR3 (Ext. Graphic)
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
35.56cm (14.0) SuperBright 300nit HD LED Display
Screen Resolution
1366x768
Hard Drives
1TB S-ATA II Hard Drive (5400RPM) with ExpressCache 16GB SSD
Internet Speed
sucks
Antivirus
Microsoft Security Essentials
Browser
Google Chrome (Sync enabled)
Thanks !! Glad that you find it helpful !!
 

My Computer My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)
Notes:

ERUNT compatibility: Registry Backup and Restore for Windows NT/2000/2003/XP. For Windows Vista, it is necessary to turn off System Restore.

ComboFix: Strong advisory to not use unless requested by a trained member of the security community.

Tony Klein's article, "So how did I get infected in the first place?": Coincidentally, I a lot of time yesterday updating the sites where I "maintain" that article. Updated version: "So how did I get infected in the first place?" © Tony Klein.
 

My Computer My Computer

OS
Windows 7 & Windows Vista Ultimate
Captain, this should be a tutorial. Very good job.
 

My Computer My Computer

Computer Manufacturer/Model Number
Home built
OS
Windows 7 Ultimate 32 bit
CPU
Intel(R) Pentium(R) 4 CPU 3.00GHz
Motherboard
ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5
Memory
2.50 GB RAM
Graphics Card(s)
NVIDIA GeForce 7600 GS
Sound Card
SoundMax Integrated Digital Audio (Chip)
Monitor(s) Displays
ViewSonic VX 1962 wm
Screen Resolution
1680 X 1050
Hard Drives
Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB
Cooling
Fan based
Keyboard
Microsoft Comfort Curve Keyboard 2000 v10 USB
Mouse
Logitec optic USB
Internet Speed
3.01 Mb/s download 0.64 Mb/s upload
Notes:

ERUNT compatibility: Registry Backup and Restore for Windows NT/2000/2003/XP. For Windows Vista, it is necessary to turn off System Restore.

ComboFix: Strong advisory to not use unless requested by a trained member of the security community.

Tony Klein's article, "So how did I get infected in the first place?": Coincidentally, I a lot of time yesterday updating the sites where I "maintain" that article. Updated version: "So how did I get infected in the first place?" © Tony Klein.

Thanks for the additional Tips Corrine !!
 

My Computer My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)

My Computer My Computer

Computer Manufacturer/Model Number
Samsung NP550P5C-S02IN
OS
Windows 7 Ultimate - 64-bit | Windows 8 Pro - 64-bit
CPU
Intel® Core™ i7 Processor 3,610QM (2.30Hz, 6MB L3 Cach
Memory
8 GB
Graphics Card(s)
NVIDIA® GeForce® GT 650M 2GB Graphics, Optimus™ techno
Sound Card
SoundAlive™ JBL 3 Speakers (With sub-Woofer)
Monitor(s) Displays
39.62cm (15.6) SuperBright 300nit HD+ LED Display
Screen Resolution
1,600 x 900, Anti-Reflective
Hard Drives
1TB S-ATA II Hard Drive (5,400RPM)
You should add to run those programs in safe mode too. That way the malicious program won't run.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Pro 64bit build 7601 SP1
CPU
Intel Core I5 3570K 3.4Ghz w/ Zalman CNPS9900NT RT
Motherboard
MSI Z77A-G45 Gaming
Memory
G.Skill F3-12800CL9D-8GbXL ; 4Gx2
Graphics Card(s)
EVGA Geforce GTX 770 Superclocked
Sound Card
Creative Sound Blaster Z
Monitor(s) Displays
Dual ViewSonic VX2770Smh-LED Black 27"IPS-Panel
Screen Resolution
1920x1080
Hard Drives
Kingston Hyper X 240GB SSD Win8 Pro 64bit 6GB/s Sata III
Intel 335 Series SSD 240GB Win8 Storage 6GB/s Sata III
Intel 320 Series SSD 600GB Storage 3GB/s Sata II
Western Digital Scorpio Black 1TB - Docked via Esata
PSU
Coolermaster GX 750W
Case
Corsair Vengence C70
Cooling
Coolermaster 120mm and Enermax 140mm
Keyboard
Corsair Vengence K70
Mouse
Logitech G500
Internet Speed
22mbps+
Browser
Firefox, Chrome, IE
Other Info
Swan M50W 2.1 speakers
APC UPS
Thermaltake BlacX HDD Dock
Samsung BD Optical Drive
Netgear WNDR4500
Hi, metalmania31.

If at all possible, it is best to run anti-malware programs in normal mode. Malwarebytes' Anti-Malware, is intended to run in normal mode rather than safe mode as it gives it a chance to catch malware while it is active.
 

My Computer My Computer

OS
Windows 7 & Windows Vista Ultimate
Hi, metalmania31.

If at all possible, it is best to run anti-malware programs in normal mode. Malwarebytes' Anti-Malware, is intended to run in normal mode rather than safe mode as it gives it a chance to catch malware while it is active.

Wouldn't it depend on the circumstance, because sometimes viruses will block anti-malware programs from running at all. I had this happen on my parents computer when it was infected with one of those fake anti virus programs.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Pro 64bit build 7601 SP1
CPU
Intel Core I5 3570K 3.4Ghz w/ Zalman CNPS9900NT RT
Motherboard
MSI Z77A-G45 Gaming
Memory
G.Skill F3-12800CL9D-8GbXL ; 4Gx2
Graphics Card(s)
EVGA Geforce GTX 770 Superclocked
Sound Card
Creative Sound Blaster Z
Monitor(s) Displays
Dual ViewSonic VX2770Smh-LED Black 27"IPS-Panel
Screen Resolution
1920x1080
Hard Drives
Kingston Hyper X 240GB SSD Win8 Pro 64bit 6GB/s Sata III
Intel 335 Series SSD 240GB Win8 Storage 6GB/s Sata III
Intel 320 Series SSD 600GB Storage 3GB/s Sata II
Western Digital Scorpio Black 1TB - Docked via Esata
PSU
Coolermaster GX 750W
Case
Corsair Vengence C70
Cooling
Coolermaster 120mm and Enermax 140mm
Keyboard
Corsair Vengence K70
Mouse
Logitech G500
Internet Speed
22mbps+
Browser
Firefox, Chrome, IE
Other Info
Swan M50W 2.1 speakers
APC UPS
Thermaltake BlacX HDD Dock
Samsung BD Optical Drive
Netgear WNDR4500
Back
Top