Saturday, May 1, 2010

Security Tools Virus and Similar Virus..

This is good information that has helped me on a few systems. I found this surfing the web and wanted to pass it on.

Some of my People have encountered this particular piece of spy ware more than once now, I have found the best way around it. Since I have a number of clients I was able to install Mal ware Mal bytes on my computers before they become infected. Obviously most people don't have it before they get infected. So I list the following steps to help without Malware. I realize that the steps below may look overwhelming, but it takes less time if not the same time to have to reformat your computer. and since I don't have the time to format over 10 computer a week, just removing the virus, and not have to back up all kinds of files, and put them all back on, its a better option for me to go the harder route. Please be advised that this has worked for me multiple times, and I wouldn't suggest someone that barley knows how to turn on a computer not to try the steps below, as it could possibly end in disaster. If you have no clue what below is explaining, then take it to a professional.

(Windows XP only)

1.) start up your computer.
2.) once you are in your computer, click the start button, and choose log off. Make sure you click the log off button, not the switch user button.
3.) Once you are logged off, you will then click your name to log back in. IMPORTANT: The second you click your name to log in, Begin pushing these 3 buttons all at the same time: CTRL+ALT+DEL. You can stop once your task manager comes up.
NOTE: If you are able to start your task manager before the spy ware starts, it cannot stop it once it has started.
4.) once you have your task manager open, you will open the processes tab. Once you have chosen that, you will need to click inside the box where it says "User Name". This will organize everything in your task manager. Please note that anything marked with "LOCAL SERVICES, NETWORK SERVICES, AND SYSTEM" DO NOT END THESE PROCESS. (Please end explorer.exe as soon as possible) Anything under "user" or Your name, or Administrator, you will need to end these process. ALL OF THEM. This should disable the virus so that you can open programs. Now you will not be able to use the standard point and click interface, so we will have to run programs using commands.
5.) once you have all your process ended that need to be ended, you will need to click on the applications tab. If you look in the lower right hand corner, you will see where it says new task. You will need to click that button. It will bring up a "Create New Task button". You will need to type "iexplore.exe". That will open an Internet explorer. Please note that this may reactivate the spy ware. You will need to watch the process tab and end any process under your name, Administrator or User except iexplore.exe. Once you have an Internet explorer window open, you will need to put this link in the address bar: http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe. hit enter. This should automatically bring up a download link. Just click run. Then follow the prompts to install. It may prompt you to restart your computer, if necessary, then do so. Then refer back to step 1 - 4. Then skip to step 6. ( if it tells you that Internet explorer cannot open page, or there is not connection, please refer to step 7, then come back to this step once you have Internet connectivity)
6.) Once you have your task manager back up, and unnecessary process ended. You will need to go to the Applications tab, and click New task. Withing that box, you will need to type "mbam.exe". This will open Malware Malbytes. You will need to update it. Click on the update tab, and click the update button. IF IT DOES NOT UPDATE Due to "no Internet connection" then follow the steps in step 7. If it updates, go to step 8.
7.) You will need to open an Internet explorer window. (go to new task under the applications tab, and type in "iexplore.exe" Once you have it open, you will need to go to Tools, Internet Options, Connections, and click the Lan Settings button. Once you have that window open, the only box that should be checked should be "automatically detect settings". More than likely, use proxy connection is checked, as the spy ware has made it harder for you to connect to the Internet to get a spy ware removal tool.
8.) Once it updates, you will need to choose "perform full scan" and let it scan your PC. During the time it is scanning your PC, you will need to go to the applications tab of your task manager, and click New Task. You will then type msconfig in the new task window, and hit enter. This will bring up your system configuration utility. Once it has loaded, you will need to go to the startup tab, and you will need to look through that list, and make sure anything that says like "super anti spy ware" or Antivirus "anything", you uncheck them. Once you do that, you will need to click Apply. then click OK. This will result in another window that says "system configuration". you must restart your computer for some of the changes made by system configuration utility to take effect, you will choose the Exit without restart button as you do not want to restart your computer while malware is scanning your computer for spy ware. You will need to wait for malware to finish. Once it has finished, follow the prompts, and it will ask you if you would like to restart your computer. Choose yes.
9.) Once the computer restarts, the spy ware should not show up, but this doesn't mean its gone. You will need to choose "do not show me this again" on the system config utility as you disable the spy ware through your system config utility. You will need to start up malware again, and run it one more time, it shouldn't matter whether you choose quick scan, or full scan, but it should get whatever is left by the spy ware. If you need to restart then restart.
10.) before opening any other Internet explorer pages, you will need to go to Start, Control panel or Settings, Control panel. Then you will need to choose Internet Options. Once you get Internet options open, you will need to click on the Advanced tab (all the way to the right) and you will look at the bottom, and click the "reset" button. This will set your Internet explorer back to normal and erase any trace of the spy ware off your Internet explorer. Once this is done, you should be fully back to normal.

No comments:

Post a Comment