Download Sites: filehippo.com, threatfire.com
Software Descriptions:
Malwarebytes Antimalware (mbam) = On-Demand Scan Anti-Malware.
SuperAntiSpyware (sas) = On-Demand Scan Anti-Malware
Avira AntiVir = Realtime Antimalware
Threatfire = Real-time Behavioral Analysis
The steps below will remove almost any piece of malware. Notice that I say almost. If you’re infected with a rootkit you may need to use a bootable anti-malware disc.
- Double Click the MalwareBytes Installer (mbam-setup) and install with default options.
- Malwarebytes will check for the latest updates. If Malwarebytes fails to load (closes automatically when you open it) rename C:Program FilesMalwarebytes’ Anti-Malwarembam.exe to mb.exe.
- Try to update Mbam. If mbam fails to update then delete your hosts file in c:windowssystem32driversetc. If the mbam still fails to update move on to the next step.
- Run a full scan with Mbam.
- Once the scan completes click show results and remove anything checked.
- Reboot.
- Install SuperAntiSpyware (sas) with default options.
- Update SAS. If you can’t update SAS procede to the next step.
- Run a full scan.
- When the scan completes make sure all items are checked and click NEXT to begin the quarantine and removal process.
- Reboot.
- Once your computer is fully booted install AntiVir. Choose to do a custom install. Set heuristics on high. Let Antivir perform an update.
- Scan your entire C drive by right clicking on the drive and choosing to “Scan selected files with AntiVir”. If Antivir detects any malware choose to quarantine it.
- Reboot after the scan completes.
This concludes the malware removal section in this guide. Next, we’ll remove any software restrictions placed on our computer from the malware.
Restriction Removal Tips:
Now it’s time to cleanup security restrictions placed on our computer from the malware that was loaded. Malware will place security restrictions on your pc to make removal all that more difficult. I use a couple of free utilities and commands to accomplish this.
Commands
(For XP Pro) Click Start – Run – paste the command in below:
secedit /configure /cfg %windir%repairsecsetup.inf /db secsetup.sdb /verbose
(For Vista) Click Globe – paste in the command below where it says “start search”:
secedit /configure /cfg %windir%infdefltbase.inf /db defltbase.sdb /verbose
Microsoft also has a small program that will reset your security policy back to defaults. You can download it here:
http://support.microsoft.com/kb/313222
Misc Commands that may help:
Can’t launch regedit? Issue this command (click-start-run-paste in the command below):
REG add HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem /v DisableRegistryTools /t REG_DWORD /d 0 /f
Can’t load the task manager? Issue this command (click-start-run-paste in the command below):
REG add HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem /v DisableTaskMgr /t REG_DWORD /d 0 /f
Can’t load a command prompt? Issue this command (click-start-run-paste in the command below):
REG add HKCUSoftwarePoliciesMicrosoftWindowsSystem /v DisableCMD /t REG_DWORD /d 0 /f
Programs To Run (For XP Only)
XP_SecurityConsole will often resolve security restrictions just by opening it (make sure you click the apply key before closing).
http://www.dougknox.com/xp/utils/xp_securityconsole.htm





Pingback: HELP! Im going off my head, my computer has been hijacked. ? - Q&A WIKI