eg \ HOME PAGE OF WA2NTK and W2NTK
>

MALWARE  WHAT  IT  IS  AND  HOW  TO  CLEAN  IT   FROM  YOUR  MACHINE


MALWARE, The joining of the words, Malicious and Software

Along with viruses, one of the biggest and fastest growing threats to computer users on the Internet today is malware. It can hijack your browser, redirect your search attempts, serve up nasty pop-up ads, track what web sites you visit, and generally screw things up with out you downloading anything. Malware programs are usually programs that can cause your computer to become unbearably slow and unstable over a period of time. Many of them will continue to reinstall themselves every time your re-boot your computer even after you think you have removed them. They will hide in a variety of places, in the system restore file or in the operating system itself or they "hide" themselves in the registery, RAM or hardware drivers or a Dll file waiting for you to access that area of your computer at which time the "loader" will go and get the "payload" using your internet connection and you have just been infected by some malware. Easy to get they can however be very difficult to clean. By the way the "loader" is usually a somewhat crude program between 200 and 300 bytes in size. By itself it can't do much damage but is designed to download the "payload" which can be a very sophisticated and troublesome software package.

Malware is getting more sophisticated every day and you can get infected in several ways. Malware often comes bundled with other programs and comes along with the seemingly trouble free download. In some cases they can be acquired by just logging on to an infected site. Many of them come with annoying pop up ads trying to sell you software to rid the infected computer of the infection.

This document will guide you through the steps to rid your machine of any malware or virus plus any Trojans or Worms your computer may be infected with. The following approach is non-destructive and has been used many times with excellent results. However even with the success this procedure has enjoyed I do not accept any responsibility for the outcome of its undertaking.

YOU ARE DOING THIS AT YOUR OWN RISK!!

BEFORE YOU GO ANY FURTHER:.     Back up ALL of your essential data. I know that it can be a difficult and time consuming task but it will be well worth it if something should go wrong during the procedure. By the way!!, did I mention you should backup all of you essential data.

So lets get started. You will need to acquire the following software. All of it is freeware. OK, You will need the following software:

PLEASE NOTE: There is other software programs that might do a better job of cleaning up your machine but the following are the best of the available freeware.

Mcafee Avert Stinger.   Eliminates Trojans and worms. Use the link to download the stinger and read the instructions

The following software should all be up-dated prior to use.

Ad-Aware by Lavasoft. Eliminates key trackers, popups and other tracking software. Download, install then update the detection files

Spy-Bot Search and Destroy.  Eliminates, bots and malware. Download, install and update the detection files.

AVG 8 Anti virus software.  Eliminates virus software. Download, install and update the detection files.

CCleaner  is a cleaner that cleans a host of software applications including the registery. This is a good software package and will do the job at hand.

READY SET GO... If your computer is not already running boot it up. Go to Start - Control Panel - System - System Restore- turn off system restore and click on apply. When asked if you want to turn off system restore answer "Yes" and click on "OK". the reason for this is two fold. First, some malware resides in the system restore file. Second when you shut down the computer Windows™ will "flush" the system restore file and any malware along with it.

Turn off the computer and disconnect it from the internet or network. This is a precaution in case the problem was not in the system reatore and will prevent the "loader" from loading the "payload" on the reboot.

Reboot the computer, during the boot press and hold the F8 key. You want to re-boot the computer into the safe mode without networking. You want the safe mode so the computer is operating on a minimum set of drivers. Once again this is to prevent a dirver which may be infected with the "loader" from loading the "payload".

Once the machine reboots in the safe mode run the software inthe following order:

1- Macfee Avert Stinger
2- Spy- Bot Search and destroy
3- Ad-Aware
4- AVG8
5- CCleaner

Do not re-attach the computer to the internet or network at this time. Reboot the computer into the normal mode. If Spy-Bot automatically requests to run again during or just after the boot process let it do so. After the process is complete shut it down and once again and connect it to the internet or network. Reboot and launch your registery cleaner followed by your internet browser If all seems well and there are no apparent problems turn system restore back on and set a restore point. That's it. Seems complicated but it's not.

Congradulations... You now should have a virus and malware free computer. Your computer should now be squeeky clean.
The above process performs several functions, finding and elimating any virus software, bots, trojans and worms plus locating and removing any malware. If you think that the only problem may be malware and is not a virus you can skip all of the software with the exception of Spy-Bot Search and Destroy. Happy and once again hopefully speedy computing. Ralph

Return to the Home Page           ARRL logoARRL logo Email Ralph or Kristi at wa2ntk "at" wa2ntk "dot" com

URL http://www.wa2ntk.com/main.htm

last update12/12.08