![]() |
|
If your pc is showing signs of malware (programs won't run, popups saying you have hundreds of viruses or Trojans, use the information here to remove it. I’m
going to show you how anyone can clean their computer and keep it free of these annoying fakes that try to hold your computer hostage until you pay a ransom
to get their anti virus. This is their trick, the program that’s calling itself an anti virus is in fact the virus. I had to clean a very extreme version of it a while ago. It
wiped out the start program shortcuts, could not use run to start anything and using explorer to start programs required the run as administrator option.
What to do
Check your internet connection through the control panel internet options icon
select connections tab then lan settings and view proxy settings if use a proxy server is checked then
uncheck it.
If you still have internet ability then follow these instructions,
if not then try to get access to another computer that does and make sure
you have a flash drive
(usb thumbnail drive) available and get started downloading these applications
Avg Free
http://free.avg.com/us-en/free-downloads
select “get free protection”
Spybot
http://www.safer-networking.org/en/download/
its about halfway down the page Spybot – Search & Destroy 1.6.2
Malware bytes Anti Malware
http://download.cnet.com/malware
bytes antimalware
Tdsskiller from Kaspersky
http://support.kaspersky.com/tdsskiller
copy the installation programs to your flash drive and then rename them, keeping the extensions intact. This will confuse the fake antivirus if its set to prevent their
installation. Take to infected computer and copy files to desktop and install from there using explorer and the run as command using the administrator
credentials. If administrator is not active on your computer make sure you are connected to a modem, router, switch or hub and follow these steps.For win7 and
vista hit start and click the run option and in the box type in "cmd" without quotes, and instead of hitting the enter key, use Ctrl+Shift + Enter. You will be prompted with the User
Account Control dialog but it will then open up a command prompt in
Administrator mode.Copy and paste “net user administrator /active:yes”
do not include the quotes.
Change the password for administrator by pasting “net user administrator
123456” again without the quotes.
now your administrator account is active with a password of 123456.
Use this when you install the apps you have placed on your desktop. you can run
explorer by right clicking the start button and selecting explorer. Navaigate to
your desktop and install avg first.
Once your copy of avg is installed click start and navigate to the avg start folder
and to avg user interface and right click this item and run as administrator. At the
top select tools and then advanced settings then expand scans, select scan
whole computer and ensure the automatically heal option is checked.
Select resident shield and insure that the auto heal option here is
checked also.
Close the interface and install malware bytes. Update during installation. Then
Choose spybot and update this during the install. spybot and malware bytes do
not need any adjustments after installation, then install tdsskiller. Now your ready to
send that virus to the garbage heap. Run tdsskiller first, this will locate any
rootkits on your computer. A root kit controls everything you see on your
computer, so if it's infected and it has a root kit installed you may not be seeing
everything you should as it controls what you see and what the anti virus tools
you just installed can see. This is where stealth programs are hidden. you can't
see them because the virus is in control of what task manager and explorer shows
you. At the end of tddsskillers’s scan it will tell you if there is an infection and give
you a choice to remove it or quarantine it. I prefer to quarantine it in case it turns
out to be a false positive. you will probably be required to reboot and once your
system is back up you need to start malware bytes, scan in regular mode as its
Creators claim it works better than when run in safe mode. At the end you will have
the option to fix any problems found. Run spybot and avg. when done, reboot
and check if programs are accessible again. Leave system for awhile to see if the
virus rerturns. When all is fine remove administrator access by clicking start
and run cmd in administrator mode and then pasting this command
“net user administrator /active:no” without the quotes.
hope this helps. will show you a trick to use with restore points next
time.