MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal > Malware Removal FAQ
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal FAQ testing


Closed Thread
 
Thread Tools Rate Thread Display Modes
  #1  
Old 09-29-07, 23:58
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,320
Thanks: 61
Thanked 7,640 Times in 4,113 Posts
Default Windows XP Malware Removal/Cleaning Procedure

Windows XP Malware Removal/Cleaning Procedure

Notes:
  • Some programs (like MGtools mentioned later and maybe other tools too) may not run on restricted user accounts so you may need to temporarily change the user account to an admin type account and then complete the scans.
  • If you are a Spybot Search and Destroy user, make sure that you do not have Teatimer enabled. If you already have Teatimer enabled, see this to disable it: How to disable Spybot's TeaTimer
Step 1: Downloading Tools

In this section we are going to download tools we will use. We will install and configure the programs and then run scans at a later point so please only download right now.

Make sure you download the tools to the exact locations specified below in the procedures to avoid problems later. It is not a good idea to download them to any folder within C:\Documents and Settings.) It is also a bad idea to download and save anything you need into any kind of Temp folder. Malware hides in Temp folders and standard cleaning practices will delete everything from Temp folders.

If you have difficulty knowing how to download and save files to locations on your PC, check out the below Video Tutorial by TimW



Now download the below tools ( PLEASE only download at this point ) If your protection software blocks downloading because it calls these malware then shutdown your protection software because it is mistaken and is just getting in the way.
  • RogueKiller - Save to your Desktop. See the download links under this icon
  • Malwarebytes Anti-Malware - See the download links under this icon
    • Important: Rename the downloaded mbam-setup.exe file to mb.exe to help work around certain malware that will block it from being run.
  • TDSSKiller - Save to your desktop. See the download links under this icon
  • HitmanPro - Save to your desktop. See the download links under this icon
  • MGtools - Recent bugs in many antivirus programs are detecting this as malware. Disable your AV while you download and run MGtools if you have this problem. Rest assured that it is clean. Your AV is incorrect. We prefer that you download this file to the root folder of the drive where you have installed Windows (Typically this would be C:\ and thus you would have a C:\MGtools.exe file after downloading). If you use FireFox and still have it set to defaults, it will not let you choose where to download files to. To change FireFox, run FireFox and Click Tools, Options, and on the Main tab select Always ask me where to save files. If for some reason you still have a problem trying to save MGtools.exe properly which can happen with Vista and Win7, you can download and run it from your Desktop as long as your Desktop folder is located on the same drive that you boot Windows from.
Step 2: Installing Tools and Running Scans - please only run one scan at a time and only run each scan one time. Also try to complete all scans before attaching any logs!
  • RogueKiller Instructions
    • Double click RogueKiller.exe to run (Note: If running Vista or Win 7 use right-click and select Run as Administrator)
    • When it opens, press the Scan button. . Only run a scan! Do not fix anything at this time
    • When it is finished, there will be a log on your desktop called RKreport[1].txt
    • Attach RKreport[1].txt to your next message ( after you complete all scans or get as far as you can go). (See: HOW TO: Attach Items To Your Post )
  • Malwarebytes Anti-Malware Instructions
  • TDSSKiller Instructions
  • HitmanPro Instructions
  • MGtools Instructions
    • Now follow the directions in the below link for running MGtools. It also explains possible reasons for not being able to run MGtools
Step 3: Do You Still Have Problems
  • Yes, I’m still having problems
    • DO NOT run the READ ME again!!!! And DO NOT move on to Step 4 below!!! Please just attach your logs as given below and tell us what problems you are still having.
    • PLEASE ATTACH ALL REQUESTED LOGS whether the find anything or not!!!!! We must check that proper updated versions were run.
    • If you do not already have a thread started, start a new thread otherwise post the following in your original thread. Clearly describe in detail the problems you are having and how long ago they started. Think about what you were doing at the time.
    • Now you need to attach (See: HOW TO: Attach Items To Your Post ) ( Or View: How to Attach Items to Your Posts) the below logs created while running the above scans
      • RKreport[1].txt log from RogueKiller.
      • Malwarebytes Anti-Malware log
      • TDSSKiller log
      • HitmanPro log
      • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
    • You should attach all of your logs after you have completed all scans.
    • Be patient after posting your logs and wait for one of the helpers to get to you. It can take a while to read thru all of the logs and to create individual fixes for you.
    • Also DO NOT BUMP your thread to try and get a faster answer. This will actually significantly delay getting an answer. See this: Don't Bump! It Only Hurts You!!!
  • No, I’m not having any problems
    • If you are sure everything is okay ( give it a couple days to be sure ) and that you do not need to request any help, then jump to the next step below.
Step 4: Toggle System Restore
  • Before you toggle System Restore, make sure that you are no longer having any malware or other problems as specified above in step 3. If necessary, run your PC for a few days to make sure that everything is working well.
  • You only need to Toggle System Restore if malware had been found during the cleaning procedures. If no malware was found, there are no infected restore points to worry about, thus you can skip to the next step.
  • Once you are sure all malware problems have been removed follow the below steps:
Why we toggle System Restore!
If you have been infected with any trojans, spyware, etc, they could have been saved in System Restore and are waiting to re-infect you. Since System Restore is a protected directory, your tools can not access it to delete files that may contain viruses. Even though your tools may say they are deleting them, they are not! The reason for doing this after your system has been completely cleaned of problems, is so we can remove possible infected restore points. When you disable system restore, it removes restore points!
We only toggle System Restore after you are clean because keeping even infected restore points around while we are fixing things may prove useful if something goes wrong during the process. An infected restore point could be better than none at all!
Step 5: Keeping your computer safe and secure Step 6: Alternative Scans - If still having problems, see: Alternative Scans

Now surf safely!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter

Last edited by chaslang; 07-31-13 at 17:27.. Reason: Attach logs even if nothing found
The Following 411 Users Say Thank You to chaslang For This Useful Post:
1100011CS (12-14-08), 2ndmillion (11-29-08), 68gman (11-24-10), abc3b (01-14-10), abern01 (04-05-10), abwpotf (11-07-08), achkar (04-19-10), AddyDog (04-24-09), adrianrn (07-28-12), aka laptop (12-18-08), alan monro (04-10-11), Alaskero (12-09-08), Allis_Chalmers (01-11-09), Alstrone (02-27-09), Amjad (03-19-09), anarkomoppe (09-05-09), Ancsi0909 (10-12-08), Androl (02-02-09), animal7296 (09-06-08), ANT1964 (11-22-08), Aphelion5 (10-02-09), aranacaa (09-15-08), arborethic (04-25-11), Arconos (05-06-09), ark203 (12-17-08), ash5353 (11-27-08), avee (10-10-11), Bad Panda (10-03-08), ballth5 (09-08-08), bb3nn3tt (11-29-08), bbrose10 (02-23-09), bbu (04-15-09), bcarlsson (12-09-08), BCPInc (07-15-10), beaniecaper (01-08-12), beastly115 (12-17-08), BeInAZ (12-15-08), Bettsy (07-23-08), bettyagnes (08-23-08), bibek mazumdar (07-21-08), biffabacon (03-16-09), biggadawg (04-04-09), Bill13118 (03-06-09), Bioware (12-17-08), birddogblue@hotmail.com (12-16-08), Blacksmith (03-12-10), Blinx (01-08-10), Bluepickle (10-11-08), bobotron (01-16-09), boogieman (12-26-09), BoredOutOfMyMind (06-24-11), Boundaryman (01-22-13), Bri (12-29-08), briskyman (01-03-09), btel (02-25-10), bugsy1275 (07-27-12), butterfly090965 (03-04-09), Calpurnio (07-11-10), campbratcher (07-20-08), Capt Bob (09-27-08), cassidycaid (02-27-09), cchrisgates (10-15-08), CDF69 (05-14-09), Chairman Wood (02-22-10), chasemonster (04-02-11), Chazmataz (12-03-08), chemathtry (11-16-08), Chicagoshirl (07-08-10), chris1315 (08-12-08), cindyw9 (09-28-11), clarencereed (12-22-08), clash city rocker (08-21-11), clayidus (11-19-08), Clockwork Avatar (02-05-10), cnx_michael (11-15-08), ComputerHelp1 (04-01-10), computermanbrown (01-19-09), concre+e (01-02-09), coopvet2000 (04-26-11), Copy1 (05-19-10), cshbonawitz (01-31-09), cuchulain64 (08-26-08), CyberTiger (07-13-10), d4m14n (07-14-10), DADDIOFLOYD (09-05-14), damfadd11 (11-07-08), DanaRKelley (12-02-08), danielbu (01-19-09), dant17 (03-15-09), Darkoshacy (07-02-09), dawnmorning (10-20-08), dbaggers (10-16-08), DeeEmmTee (05-01-10), dementievafan (09-09-09), DGenerationX (12-12-12), dhdan13 (11-09-08), dirtyred (10-07-09), dittosaur (02-19-09), diver79 (10-22-08), djames216 (11-29-10), djoni1980 (09-04-09), DLyons4287 (08-13-10), docpaulo (10-31-08), donald.hsdnb (09-20-10), Dracandros (02-07-09), dueyit (03-13-09), d_spice (07-17-08), eaulegere (01-15-10), Ebmocwen (05-06-09), eddieeffg (09-07-09), edgolfer7 (09-07-08), edwata (09-29-11), Eezak (11-20-09), Eilenach (05-14-12), Eire32 (08-27-08), Electroenzo (06-17-11), electronic whiz (11-22-09), ElleSchneiderHof (10-28-08), Ermonis (01-31-11), erratic (07-29-08), EsjayUK (08-27-10), Excob (10-01-09), fbcsteve (08-17-08), Fervent (07-25-09), Fierc3 (11-12-08), fireblitz95 (09-20-09), Fish Bonz (05-06-09), fishiam (01-01-09), fixmyPC (06-20-10), Flashorn (08-24-08), flyinghooves (03-29-10), ForYouToEnvy (10-17-08), fred2525 (09-14-08), freelancegeek (09-27-09), frustratedPCowner (12-08-08), Futrell (02-01-09), g6qwerty (12-21-08), galacey (07-06-12), gasman87 (03-10-10), gatorrich (06-07-10), Gawayne (08-04-10), GCWesq (02-14-09), geek342 (08-25-10), GeekBen (09-29-09), geex_newbie (01-11-09), ggggranville (11-07-08), Gilmore (06-28-12), glider_mak (10-11-08), gordie (02-21-10), Grotbag08 (10-15-08), gvfbgvfb (03-15-09), HardCorps (12-14-09), harveee (07-22-08), HiJack (07-04-09), Himo (10-29-08), hitekrednek (02-01-09), huntilla (08-14-11), iagojames (05-23-11), iamadam (12-28-08), ifallapart (12-26-08), iminsarasota (02-26-09), infected2k (06-29-12), infectshun (09-20-08), infernalinferno (07-27-08), jaber (12-23-09), jakec9 (03-08-09), jaspie (08-06-08), JaymzLinus (10-03-08), jbkiddtx (10-10-10), jdr109 (10-22-11), Jeff Snyder (11-22-08), JeremiahKD (03-21-09), Jetro (09-02-11), Jhealynyad (11-01-08), Jilogethan (11-21-08), JimLL (04-04-11), jimmys (11-15-11), Joebakb (09-23-10), joeboff (03-14-09), johnboy777 (05-16-10), Jones.Neil (07-10-12), Josr (01-02-09), JP75 (01-03-09), jshr (07-30-10), jsthib (07-22-08), jtmacomb (02-02-09), JustinHoMi (04-30-09), ka tee (05-26-11), Karkas (05-29-09), KayleeLee (08-16-08), kbrettm1977 (03-11-09), KCEngineer (01-19-09), keeferj2 (01-10-09), kfitzharr (08-23-08), kingk75 (12-30-08), klohana (08-12-09), kmac_24 (05-22-11), KrypticMind (04-17-10), kskovach (08-19-08), ktluu78 (09-04-08), KVT (09-03-10), L33t_SSF_Killa (09-19-11), Laamalia (07-28-12), Laitnesse (04-13-09), Lanceosh (01-25-11), lane99 (10-07-08), Laney2001 (08-18-09), lauriepost (07-10-08), Lead (08-18-09), leonie8427 (12-28-08), LesterB (06-19-11), LGM08 (08-24-08), ljouwert (09-08-08), lmaliski (11-16-08), LordAtari (12-11-08), Love goddess (10-05-08), lpontius1 (12-01-08), lucid25 (08-29-08), lyckos (12-09-09), Mad-Friend (08-16-10), Madam (12-21-10), MadDogg80 (01-02-10), magna (05-15-12), majec (12-26-09), Majsea (09-07-08), mancow2000 (06-14-10), manilka835 (11-25-12), markozimek (11-13-10), mathiasofthed (02-01-10), mattag08 (01-05-09), maty (04-04-09), mbfranchi (03-05-12), mch (01-06-09), MediGeek (08-05-13), Medscimez (09-27-08), mhl (12-18-10), MightyBeaker (07-16-08), mikwya (04-27-11), mindless (08-17-08), mistergofio (05-23-09), MisuzuKamio (12-01-08), mneenee (03-23-11), mntngirl (10-24-10), mojo-domo (03-09-10), monkeydo (02-10-09), monkiemonk (07-24-08), mpetro1 (09-11-13), mrayfield (12-01-08), mrt1918 (03-26-09), mummaonthaedge (08-17-10), mummygeek (10-12-08), munkeyboi (08-18-08), murderhigh187 (12-06-08), murphatoid (02-20-09), MutD (04-05-09), mysticzero (01-04-09), nadsab (03-29-09), nanabell1225 (09-23-09), napalm1984 (02-06-09), newmy51 (03-30-10), Norutaj (11-10-10), notmentalyet (09-15-09), noussah (10-15-08), nrbuss (12-24-09), Octavius (08-14-08), octron2008 (07-19-12), OkieMomma (11-17-08), ol_leprechaun (11-16-08), Op7ima (02-19-09), OriginalEggman (04-01-10), otaehoon (06-27-09), otarpilot (12-28-08), p1lgrim_grs (08-10-08), p45cal (01-18-11), padrig_jh (04-09-10), parkie70 (06-04-12), PCBeatMe (06-20-09), Pedross (09-29-10), petie42pu (08-03-08), phxguy81 (03-22-10), psychoticbarber (12-16-08), RadicalPatriot (12-19-08), radiorep (08-13-09), radu5er (11-01-08), ragexzero (12-05-08), rahuld (09-22-08), Ramachandrea (04-17-11), Raphee (01-25-10), ravenous1 (12-12-08), Rayster (09-01-09), rchandra (12-08-08), Recycle Bin (10-30-08), RedPaul (10-28-08), red_headphones (04-11-09), reshav (05-03-11), Rickie123 (09-28-11), robc1776 (07-05-09), ron91265 (08-30-08), roncrier (08-09-08), rpole (08-28-09), runningcart (07-01-10), rwallsten (03-29-10), SafariHat (11-13-08), SalemDesign (10-02-09), samm20065 (12-29-09), sandb (08-06-09), Sean Et Cetera (04-14-09), seaside (08-18-08), sec.attorney (02-25-09), SEGA (10-18-11), semiartificial (01-11-10), shagschain (10-30-09), shagz7 (10-31-08), shelbot (04-13-14), silvergunsuperman (05-21-13), skanuga (09-09-08), skaps6969 (12-13-10), skeezix (04-08-09), skoka (05-30-09), Slide (08-14-09), slip809 (08-25-08), smileycrossbones (04-24-13), sms1226 (03-14-09), snapper23 (Today), SnowCat MacDobhran (11-01-09), snurbnacnud (07-20-09), soem (01-31-10), SopeV1.0 (01-08-09), sotiris (04-25-10), spaceywolfe (01-07-09), sparkle7778 (11-01-08), spensaur (08-31-09), spidermanusa (01-02-09), SponginaTOR (02-04-09), spoonlamp (01-10-09), Srf (05-17-09), star33gazer (01-16-09), stevejouanny (11-28-08), steve_wilson (02-05-09), str8g8 (03-10-09), StreetSpirit (09-19-10), sunpalm (08-27-08), Superlost6 (05-15-12), swamprat1 (02-17-09), synth3tk (02-06-09), tamale (02-28-09), tatsall (08-09-08), Texan2000 (09-28-09), The Old Wolf (01-01-10), TheBakers (11-29-08), thedon01 (10-27-11), thefly (06-24-09), them (01-18-09), themcmillens (07-14-08), thepeanut (04-10-09), thesmokingun (03-06-10), ThomasK (08-19-08), thorir (06-18-09), tibi (12-01-11), timoth22 (07-18-09), tlink211 (02-01-09), tojono (12-31-10), tonycas (07-09-08), tonyhale (11-06-12), ToyotaMafia (03-17-09), tremblant (10-27-08), Trntstr4 (12-18-08), trubacca (10-22-08), Tubbs (09-12-08), Turok (05-27-10), ugunit89 (12-22-08), Uli (10-06-09), Unbelievable (01-04-09), unjdm (05-16-11), urbanphoenix (09-03-09), ureritemate (10-25-08), Uriah (08-22-08), vale (06-01-09), vanheijzen (01-01-10), varie (12-30-08), vass (10-29-09), VaultBoy (11-11-08), vcurtis (07-24-08), VeryBerry (01-22-11), Virtumondehatesme (07-23-08), vlashka (12-19-08), vparunak (08-18-08), vxrandall (10-23-10), Waelfwulf (01-24-10), WaightZer (06-26-09), wendy m (06-17-09), wflei (12-12-08), whiteoaks47 (08-24-09), Why Not (02-19-09), Wicked_Man_I_Am (07-11-08), Wild (05-31-09), WonderWeasel82 (04-19-12), wonkydonkey (03-09-09), Wrenchman (01-19-09), Wuf4Wds (03-16-10), Xitherius (09-22-08), xlivegamingx (11-14-09), xtrovrt (03-24-10), Yakodi (04-12-10), yli9yli9 (01-26-09), yolkboy (02-19-10), zDeadly (04-15-09), zela (12-16-09), zippyf23 (08-24-08), zugzug (02-16-10), zulfirsadat (03-02-10)
Sponsored links
Closed Thread

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
i have run these Windows XP Cleaning Procedure but ms vaughn stump Malware Removal 1 02-18-10 14:22
Followed Windows XP Cleaning Procedure wado66 Malware Removal 1 04-19-09 00:14
Malware cleaning procedure attempted, still have problems Aidara Malware Removal 3 03-21-09 23:52
Some sort of Malware. Not solved by cleaning procedure JLong2004 Malware Removal 7 01-17-08 09:25


All times are GMT -5. The time now is 18:46.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger