[TUT/Guide] Removing Malware/Computer Optimization

karthik potluri

New Member
INTRODUCTION






What you need to know in regards to removing malware is that there is no sure-fire way to remove all malware. You need to alternate depending on the type of malware. For example, if it’s Windows 7 Antivirus pro 2011 or something of that nature, odds are it is bundled with process killers that will block tools such as Malwarebytes, super anti spyware, and completely deny access to Spybot’s download servers. It most likely will completely block access to the task manager as well, making killing the process quite difficult. Access to command prompt also will more than likely be blocked.



In situations like this, you may be asking, “What do I do if I cannot run any anti-malware tools?” well, it cannot possibly block 100% of anti-malware tools. Regardless of that fact, there are other actions you can take to effectively stop the malware from running.



After the virus is removed, you shouldn’t stop there. You may want to take measures to further secure your computer, for example updating antivirus/anti malware programs, cleaning out your temp folder, etc.



In this thread I will attempt to teach how to remove most types of malware, or at the very least stop it from running. I will also tell you how to successfully optimize your computer.




In the following posts, DO NOT run more than 1 scan at a time. Furthermore, DO NOT run any alternative programs while scanning. The reason for this is that you will double your scan time. Furthermore, you also run the possibility of missing certain malware. Another possibility [FAR more likely] is that you will fail to remove it. Take it from me, do not run any applications while the scan is running.





ATF-CLEANER



The first program I will be talking about is ATFCleaner. Before removing ANY sort of malware, you MUST empty your temp folder. This is where the virus entered your computer [more than likely] and this is where it executed from. This is the original location of the virus. FUD or not, cleaning your temp folder will permanently delete the program from your temp files. There are many tools to do this, however I find the best one is ATFCleaner. It can be downloaded at the place I was previously employed at:



http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemi d=25



Once downloaded, select everything, for each browser it supports, and remove everything. Another program that does the same thing is CCleaner or TFC Screenshot of program:



screenshot2011071623243.png






MALWAREBYTES' ANTI-MALWARE



The second program I will be talking about is Malwarebytes Anti-Malware. This program is a great tool for any situation. You can download it at http://www.malwarebytes.org.



screenshot2011071618173.jpg




Once downloaded, install the program. When you install Malwarebytes, make sure you update the program. Scanning your computer with an anti-malware program with an out of date database just wastes your time. You can do this by:



screenshot2011071618194.png




Let it update, more than likely it’ll try to install a new version, let it. When it is done re-installing [if needed] attempt to re-update the program. Malwarebytes’ has a weird updating system where it updates like 5 times an hour as oppose to in the morning, and at night like most anti viruses. When it is fully updated, you will get a box like this:



screenshot2011071618221.png




Once that is done, I HIGHLY recommend cracking your program so that you have the pro version. Some keys are:



Id: 7CH74

Code: MUBR-AYRN-FC2J-8PVL



Id: 3AM52

Code: CU3D-7WWE-D1BA-1QJB



Id: 2UH36

Code: GXVK-TG5F-AMPD-8GP7



Once you choose one of the keys from above, you can now use the “flash scan.” The flash scan is a great utility as it scans run time processes and flash memory. It also takes LESS THAN 2 MINUTES 99% of the time. Choose this as the FIRST scan:




screenshot2011071618262.png




After you run this scan, remove what it finds, then restart your computer [if required to.]



Once you run the flash scan, you can now proceed to running a quick scan. You may ask, “Isn’t a full scan better than a quick scan?” The answer to that is no. A quick scan takes around 10-20 minutes to run, while a full time scan I have seen run on some computers for over 4 hours. If you do this with every program, you will be running anti-malware scans for days. With the amount of redundancy you do, a full scan is RARELY ever needed.



Once you are done running a quick scan, remove what it finds [if anything], restart regardless of if it asks you to or not. This is to ensure a smooth removal of everything it finds, without issue. If it finds nothing:




screenshot2011071618330.png




Move on to the next program.





SUPERANTISPYWARE



The next program I would like to talk about is a program called Superantispyware [SASW]. SASW can be downloaded here:



screenshot2011071620570fz.jpg




Once downloaded, install it. It MAY ask you to automatically update and send a usage report, I personally keep my programs up to date, so I uncheck automatically update, and I really do not want them seeing any information on my computer at all, so I uncheck those. Once that is done, you will be at a window like this:



screenshot2011071620595.png




With SASW, there are extremely specific options for optimal scanning results. Click “Preferences” Uncheck both the first and the third check, as programs running on start-up greatly decrease start-up time, and the splash menu causes SASW to load extremely slowly:



screenshot2011071621022.png




Click “Scanning Control” and have ONLY THE FOLLOWING checked:



screenshot2011071621035.png




Then click “Scan Your Computer...” You will come to a window like this:



screenshot2011071621065.png




Check the disks you wish to scan [recommend everything if you are unsure] and select Quick scan. You can do a full scan if you want, but if you have two 500GB drives like I do, you won’t want to scan EVERY SINGLE FILE on your entire computer. You will literally be there 4 hours or more.



screenshot2011071622103.png




When the scan is done, if it finds something like the above, CHECK FIRST to see if it is a program you recognize [DO NOT be fooled by programs named svchost.exe or explorer.exe or support.exe, etc] SASW Will NEVER remove a program like that and if it finds something by that name, you are safe to remove it. If you are in doubt, send me a PM with a screenshot and I will be more than happy to help. However, if it finds something you are familiar with AND TRUST FULLY [oreans32 for example is a graphics driver previously detected] then feel free to leave it on your computer. ONCE AGAIN, feel free to pm me with ANY QUESTIONS AT ALL, I will be more than happy to answer them. With this program, whether it asks you to restart or not, if you remove something, restart. Let’s move on to the next program
<
.




 
Werbung:

karthik potluri

New Member
Spybot Search & Destroy
The next program I will be describing is Spybot Search & Destroy. I am fully aware that spybot S&D has 2.0 beta 1 released, however we will be talking about the stable release. Spybot search & destroy used to be one of the greatest programs out there. While it is still quite good, it is nowhere near what it used to be. Its detection rate is not that great, however its removal is unmatched. You can be assured that if it finds anything, it WILL be removed. To download Spybot S&D, visit the website http://www.safer-networking.org:​
screenshot2011071622214.png
Once there, choose your country. Then on the next screen, hit download in the top right corner. Download from any mirror you choose. Upon downloading, install it however way you see fit. TeaTimer isn’t really needed and is a real time scanner. I personally do not use it. Once downloaded and installed, run the program. Update the program [updates once every Wednesday]:
screenshot2011071622371.png
Choose the closest mirror to you, and then download everything. It will then re-start the program. Once the program has fully restarted, you can now check for malware. Occasionally you will get something like this:
screenshot2011071622494.png
I recommend clicking yes, however if you followed the steps earlier in this guide, you shouldn’t have to. Let the scan run, after the scan finishes, remove everything it finds then restart your computer.
HOSTS FILE
The last thing I would like to talk to you about is a program I modified myself. It is a program that inserts my host file onto your computer. Some viruses edit your Hosts file causing you to be unable to visit anti-virus sites like http://www.avast.com for example. This is 100% clean and the hosts file can be edited by anyone by simply opening it with notepad. The batch file was programmed by myself. The hosts file was NOT 100% created by me, however I have added my own personal touches to it. BE ADVISED, THIS BLOCKS MOST ADS, IF YOU WISH TO SUPPORT THE SITES YOU VISIT, DO NOT RUN THIS!
Virus Scan: Here

CONCLUSION
This concludes the malware removal portion of this guide. Obviously there are many more things you can do, but due to the vast majority, if I go over every single topic, I will literally have pages and pages of information.
 
Werbung:
Top