Welcome! Register for a free account (or login) > How does it work?
|
|
![]() ![]() |
Feb 7 2006, 06:24 PM
Post
#1
|
|
![]() Forum God Group: Root Admin Posts: 48,261 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
![]() WARNING this is ONLY a STARTING point and in most cases WILL NOT totally remove the infection. Use at your own risk: WhatTheTech forum's, does not take responsibility for any outcome of following these directions. Every computer is different, so we cannot guarantee the outcome. Please Register first. New here? Want to learn more about how free, community based tech support works? Click here. Please Do NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision. Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data. If you would like to know who is helping you here at WhatTheTech Forums please read The Different Groups Here At WhattheTech. We suggest you print out these instructions Vista and Windows 7 users: 1. These tools MUST be run from the executable. (.exe) every time you run them 2. With Admin Rights (Right click, choose "Run as Administrator") Preparation: Please download ATF Cleaner by Atribune.
Under Main choose: Select All Click the Empty Selected button.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. Why? This ensures there's a valid system restore point, in case it's needed. We use a simple program called SysRestorePoint that automates the steps of creating a restore point.
Why? This ensures we have a valid registry backup. ERUNT (Emergency Recovery Utility NT) allows you to store a complete backup of your registry and restore if needed. Removing modern malware infections often requires making changes to the registry, and a corrupt registry can prevent a system from booting. Compatible with Windows NT, 2000, 2003, XP, Vista, 32 & 64-bit versions.
Important Disable any script blocking protection (How to Disable your Security Programs) Step One: Scan for Spyware/Adware Why? Malwarebytes' Anti-Malware is very good at removing the zlob trojan, virtumonde, and most other current infections. This single tool has replaced multiple tools that have been required in the past.
Note: Some infections will prevent MBAM from running. If MBAM won't run, try renaming the file mbam-setup.exe to a random name, and then try again. Extra Note: Do not run a full scan with MBAM. It is not required or needed, and in fact makes our job tougher. Step Two: Rootkit Detection Please download GMER from one of the following locations and save it to your desktop:
Note: If GMER doesn't start, Please download DeFogger to your desktop. Double click DeFogger to run the tool.
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop. Do not re-enable these drivers until otherwise instructed. You must remember to re-enable your Emulation drivers once we are finished, double click DeFogger to run the tool.
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop. Your Emulation drivers are now re-enabled. Step Three: Download DDS and save it to your desktop from Here here or here.
Malware and Spyware Removal Forum Rules:
NOTE: Start your topic in Infections Removal Note: Don't forget to post your MBAM and GMER log, in addition to the DDS log. Please DO NOT bump your log. We look for logs with 0 replies first. If you are being helped and you haven't replied within 3 days your topic will be closed as inactive. If that is the case, please start a new topic when you have the time needed to finish all the instructions. |
|
|
|
Feb 14 2006, 11:55 PM
Post
#2
|
|
![]() Retired ClassroomTeacher ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 1,280 Joined: 7-August 04 Member No.: 12,002 Operating System: Windows XP-Pro, etc. etc. |
bump
|
|
|
|
May 17 2008, 08:51 AM
Post
#3
|
|
![]() Forum God Group: Root Admin Posts: 48,261 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated May 2008
|
|
|
|
Dec 6 2008, 07:54 AM
Post
#4
|
|
![]() Forum God Group: Root Admin Posts: 48,261 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated Dec.08
|
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
5 | ArtemusGordon | 117 | Yesterday, 08:14 PM Last post by: LDTate |
|||
![]() |
7 | stech | 178 | 11th March 2010 - 02:47 AM Last post by: Conspire |
|||
![]() |
1 | harliequin | 52 | 10th March 2010 - 11:27 PM Last post by: oldman960 |
|||
![]() |
30 | tvhevh | 446 | 8th March 2010 - 10:16 PM Last post by: CatByte |
|||
|
Time is now: 13th March 2010 - 08:21 AM |