Malware Removal Guide For 2009 Q1

by malwarekilla on January 31, 2009

Step-By-Step Malware Removal Guide for First Quarter of 2009 (free software edition) 

Required Software:  Malwarebytes Antimalware (free), SuperAntiSpyware (free), Avira AntiVir (free), Threatfire (free), Sandboxie (free)

Download Sites:  filehippo.comthreatfire.com

Software Descriptions:

Malwarebytes Antimalware (mbam) = On-Demand Scan Anti-Malware.
SuperAntiSpyware (sas) = On-Demand Scan Anti-Malware
Avira AntiVir = Realtime Antimalware
Threatfire = Real-time Behavioral Analysis

The steps below will remove almost any piece of malware.  Notice that I say almost.  If you’re infected with a rootkit you may need to use a bootable anti-malware disc.

  1. Double Click the MalwareBytes Installer (mbam-setup) and install with default options.
  2. Malwarebytes will check for the latest updates.  If Malwarebytes fails to load (closes automatically when you open it) rename C:\Program Files\Malwarebytes’ Anti-Malware\mbam.exe to mb.exe.
  3. Try to update Mbam.  If mbam fails to update then delete your hosts file in c:\windows\system32\drivers\etc.  If the mbam still fails to update move on to the next step.
  4. Run a full scan with Mbam.
  5. Once the scan completes click show results and remove anything checked.
  6. Reboot.
  7. Install SuperAntiSpyware (sas) with default options.
  8. Update SAS.  If you can’t update SAS procede to the next step.
  9. Run a full scan.
  10. When the scan completes make sure all items are checked and click NEXT to begin the quarantine and removal process.
  11. Reboot.
  12. Once your computer is fully booted install AntiVir.  Choose to do a custom install.  Set heuristics on high.  Let Antivir perform an update.
  13. Scan your entire C drive by right clicking on the drive and choosing to “Scan selected files with AntiVir”.  If Antivir detects any malware choose to quarantine it.
  14. Reboot after the scan completes.

This concludes the malware removal section in this guide.  Next, we’ll remove any software restrictions placed on our computer from the malware.

Restriction Removal Tips:

Now it’s time to cleanup security restrictions placed on our computer from the malware that was loaded.  Malware will place security restrictions on your pc to make removal all that more difficult.  I use a couple of free utilities and commands to accomplish this.

Commands

(For XP Pro) Click Start – Run – paste the command in below:
secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose

(For Vista) Click Globe – paste in the command below where it says “start search”:
secedit /configure /cfg %windir%\inf\defltbase.inf /db defltbase.sdb /verbose

Microsoft also has a small program that will reset your security policy back to defaults.  You can download it here:

http://support.microsoft.com/kb/313222

Misc Commands that may help:

Can’t launch regedit?  Issue this command (click-start-run-paste in the command below):
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0 /f

Can’t load the task manager?  Issue this command (click-start-run-paste in the command below):
REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f

Can’t load a command prompt?  Issue this command (click-start-run-paste in the command below):
REG add HKCU\Software\Policies\Microsoft\Windows\System /v DisableCMD /t REG_DWORD /d 0 /f

Programs To Run (For XP Only)

XP_SecurityConsole will often resolve security restrictions just by opening it (make sure you click the apply key before closing).
http://www.dougknox.com/xp/utils/xp_securityconsole.htm

This concludes for the malware removal guide for now.

{ 1 trackback }

HELP! Im going off my head, my computer has been hijacked. ? - Q&A WIKI
February 4, 2009 at 12:56 am

{ 11 comments… read them below or add one }

R------$---- January 31, 2009 at 11:20 am

Hi, malwarekilla. Which security program is best to detect and remove keyloggers?

ComputerHelpGuy1 January 31, 2009 at 11:31 am

Cool! Will you be doing videos on this?

JJ January 31, 2009 at 11:25 pm

Matt,

I hear you use Defense wall on your home PCs.

What do you run with Defense wall? Can I run NIS 2009 or NIS 2009 with it? How about Avira Antivir?

JJ January 31, 2009 at 11:28 pm

I meant to ask do you run PC tools spyware doctor with AI, Commodo or NIS 2009 with Defense wall?

AZLAN210396 February 1, 2009 at 4:52 am

I thought MBAM will remove the restriction thingy??

Jimmy James February 1, 2009 at 8:11 am

@ JJ

You can run any antivirus/antimalware software with Defensewall and have no conflicts. I run it with ESET Smart Security and everything runs great

malwarekilla February 1, 2009 at 6:23 pm

@Azlan – I think it removes a few, but not all…that’s for sure.

malwarekilla February 1, 2009 at 6:24 pm

@ComputerHelpGuy1 – Yep, it’ll be up in about 2 hours.

Herb March 12, 2009 at 4:29 pm

under your section:

Misc Commands that may help:

do you have a fix for if “you cant do a start/run” ?

Thanks

Herb March 12, 2009 at 4:36 pm

On your page:

Malware Prevention Software
http://remove-malware.com/prevention/

you list several SW packages.
I see your comment you’ve tested them.

Do you run all of them all at the same time? If so, do they “play nice” together?

Thanks

kas November 22, 2009 at 11:12 pm

malware bytes keep being rejected upon installing, and error message come at the end saying exe file missing

Leave a Comment

Previous post:

Next post: