eg \ HOME PAGE OF WA2NTK and W2NTK
>

MALWARE  WHAT  IT  IS  AND  HOW  TO  CLEAN  IT   FROM  YOUR  MACHINE


MALWARE, The joining of the words, Malicious and Software

Along with viruses, one of the biggest and fastest growing threats to computer users on the Internet today is malware. It can hijack your browser, redirect your search attempts, serve up nasty pop-up ads, track what web sites you visit, and generally screw things up with out you downloading anything. Malware programs are usually programs that can cause your computer to become unbearably slow and unstable over a period of time. Many of them will continue to reinstall themselves every time your re-boot your computer even after you think you have removed them. They will hide in a variety of places, in the system restore file or in the operating system itself or they "hide" themselves in the registery, RAM or hardware drivers or a Dll file waiting for you to access that area of your computer at which time the "loader" will go and get the "payload" using your internet connection and you have just been infected by some malware. Easy to get they can however be very difficult to clean. By the way the "loader" is usually a somewhat crude program between 200 and 300 bytes in size. By itself it can't do much damage but is designed to download the "payload" which can be a very sophisticated and troublesome software package.

Malware is getting more sophisticated every day and you can get infected in several ways. Malware often comes bundled with other programs and comes along with the seemingly trouble free download. In some cases they can be acquired by just logging on to an infected site. Many of them come with annoying pop up ads warning you of numerious infections.Thier goal is to sell you their anti virus and removal software to "clean" the infected computer. Be advised that most if not all of these compinies are off shore and should you pay them and there is no solution to the infections your credit card company will not be able to recover your money. (this is happenning at an alarming rate)

Hopefully this document will guide you through the steps to rid your machine of any malware or virus plus any Trojans or Worms your computer m ay be infected with. The following approach is non-destructive (ie. no data loss) and is used daily in our store with excellent results. However even with the success this procedure has enjoyed I do not accept any responsibility for your particular outcome. Please note that this is a time consuming procedure. Some of the scans can take a considerable length of time depending on the quantity of files that are stored on your computer.It cannot be done in segments so plan to be able to have the computer down for the better part of the day.

YOU ARE DOING THIS AT YOUR OWN RISK!!

BEFORE YOU GO ANY FURTHER:.     Back up ALL of your essential data. I know that it can be a difficult and time consuming task but it will be well worth it if something should go wrong during the procedure. By the way!!, did I mention you should BACK UP ALL OF YOUR ESSENTIAL DATA !! didn't I?

So lets get started. After several months and over one hundred virus infected computers to clean here are my suggestios. Virus's are getting vicious. Any where from simple re-directs such as the Olmarik virus (difficulf if not impossibe to remove while the HHD is in the host computer), to virus's that hide all of your data.This is where all file atributes are changed to hidden, read only or system files and all directories will appear empty.

PLEASE NOTE: Again based on my expierence, download Malware Bytes (trial version) and ESET-NOD32 30 day free trial version. Whithout execption I have solved better than 99 percent of all problems with these two applications. Virusu's will hide ANYWHERE and REPLACATE themselves several times each time you boot up your computer. They can and will hide in any folder, in particular the Windows folder and any sub folder in that directory. They will change the name of system files, reside in memory and in the system restore directory. Another recent hiding place we have seen is in the Re-cycle bin.

READY SET GO... If your computer is not already running boot it up. Go to Start - Control Panel - System - System Restore- turn off system restore and click on apply. When asked if you want to turn off system restore answer "Yes" and click on "OK". the reason for this is two fold. First, some malware resides in the system restore file. Second when you shut down the computer Windows will "flush" the system restore file and any malware along with it. Then navigate to the recycle bin and empty it. At this time download Malware Bytes and ESET NOD-32. Install both applications and up-date them but do not run them at this time. Shutdown the machine.

Reboot into the safe mode (F8 key) during boot.Select safe mode without networking.This is a precaution in case the problem is the virus is using a "loader" to pull in the "payload" from the internet on a reboot. Once in the safe mode run Malware Bytes until it no longer finds any infected objects. and then run it once again. Reboot into the normal mode and run Malware Bytes again and again until it no longer finds any infected objects. Then run NOD-32 and be sure to scan your memory and ALL drives in the computer. Again as we did with Malware bytes scan until all infected objects are found and then scan once again. If you have a single drive computer my suggestion is to take out the drive, place it in another computer as a slave and do your scanning there. In many cases when a file is in use Windows "locks the file" and it cannot be cleaned, deleted or quarantined. Moving the HHD to another machine works around this problem. I/we have been very successful in getting rid of the Olmarik virus using this technique.

If your machine boots but most software will not run and most if not all of your data is apperas to be gone, don't panic. If you have the ability to boot the machine in DOS using a disk such as Hiren's boot disk or the "Ultimate Boot Disk" do so. If not go to Windows Start and in the run dialog box type in "CMD" without the quotes. In some versions of windows you will have to do this as the system administrator. Type the following on the command line... type
attrib /?.    This is the help directory for using the attrib command.If you have a problem here just refer to it.
Next type type    attrib -r -a -h -s /d /s *.*
This should reset all of your file attributes back where they should be and your computer should run normally once again. Once the machine is running normally you can go in and turn system restore back on and set a restore point in case you need it in the future. Another tip. If you are a single user or if security within your house hold members is not an issue, turning off UAC, User Account Control will eliminate those pesky annoying dialog boxes that pop up requesting you to approve the request you just entered into the computer.

Congradulations... You now should have a virus and malware free computer. Happy and once again hopefully speedy computing. Ralph

Return to the Home Page           ARRL logoARRL logo Email Ralph or Kristi at wa2ntk "at" wa2ntk "dot" com

URL http://www.wa2ntk.com/main.htm

last update05/29/11