We have been down for nearly a week as a result of a DDoS. We needed to switch providers. We apologize for any inconvenience this may have caused.

There may be some bugs which occur as a result of the move. Please let us know if you find any.

Thank you --Robin 21:14, 15 July 2008 (UTC)

Malware Removal and Prevention: Overview

From CastleCopsWiki

Jump to: navigation, search

With the basic understanding of why you have decided to undertake this procedure (as explained in the Introduction), we have designed the following Malware Removal and Prevention procedure. This procedure consists of several malware steps that should be performed in sequence, followed by instructions how to post a HJT log should it be required. It concludes with prevention measures you can implement to properly maintain a secure system.

Please follow the instructions listed below. If you find you are still experiencing computer problems after these steps are completed, you may then post a HJT log and receive expert assistance in cleaning any infections which remain.

Image:PR-ICON.png Please print out a copy of this overview and use it to check off each step as it is completed.

Save this 'checklist' of removal programs you have run, because we will be asking you to provide us with that information when it comes time to post a HijackThis log. Good Luck!

  1. Image:Hijackthis.gif Perform a reference (preliminary) HijackThis scan

  2. Winfixer / WinAntiSpyware / WinAntiVirus Popups / Virtumundo victims only (Unsure? - then proceed to Step 4):
    Please follow the Virtumundo Removal Instructions for all versions of Windows including Vista.

  3. Windows 2K/XP/Vista - Intrusive and fake "antispyware" programs such as Privacy Protector / AntiVirGear / SpyLocked / VirusBurst(er(s)) / SpyFalcon / SpyAxe victims only (Unsure? - then proceed to Step 4):
    Please follow the Smitfraud Removal Instructions instead of steps 4-8 below.

  4. Next stop - Image:Mini-ARP-icon.png The Control Panel - Add/Remove Programs

  5. Image:Mini-no-sign-red.gifTemporarily Disable Real Time Monitoring Programs


    Now please complete the following automatic malware detection and removal steps

    After you have installed the scanning programs listed below, please be sure to update them. A security program is only effective if it updated with the latest definitions. Updating will help provide protection against the most recently introduced security threats.



  6. Clean the Clutter:
  7. Antispyware Scanners - Run at least one, preferably two - if your system is functioning well enough:
  8. Image:mini-AV.gif Antiviral Scans - Run at least one

  9. AntiTrojan Scans - Run one:

    You will have completed the automated malware removal process once you have followed the above steps. We sincerely hope that your computer problems have been resolved to your satisfaction once you've reached this point. Even if you think your computer is now 'clean', some additional steps are advisable to further ensure the security of your computer.

    Please consult: Image:rxprevent.png How to Prevent Reinfection for further details.



  10. Only if your computer problems persist, Image:HijackThislogo.gifConsider Getting Expert Help With Your HijackThis Log - How to submit a post to HijackThis Forum for review by the CastleCops HJT staff.

This article is part of the Malware Removal and Prevention series
The series was developed as the key deliverable of the
Cleaning Malware Project.
Malware Removal and Prevention Overview
Malware Prevention
edit this template
Personal tools