How to get rid of malware<p class=MsoNormal style="margin:0cm 0cm 0pt"><span>You may experience any one or more of the following symptoms: <br/>- When you start your computer, or when your computer has been idle for many minutes, your - Internet browser opens to display Web site advertisements.<br/>- When you use your browser to view Web sites, other instances of your browser open to display Web site advertisements.<br/>- Your Web browser's home page unexpectedly changes.<br/>- Web pages are unexpectedly added to your Favorites folder.<br/>- New toolbars are unexpectedly added to your Web browser.<br/>- You cannot start a program.<br/>- When you click a link in a program, the link does not work.<br/>- Your Web browser suddenly closes or stops responding.<br/>- It takes a much longer time to start or to resume your computer.<br/>- Components of Windows or other programs no longer work.</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span>See: <br/><a href="http://support.microsoft.com/kb/827315/en-us">http://support.microsoft.com/kb/827315/en-us</a><br/>&quot;Unexplained computer behavior may be caused by deceptive software&quot;.<br/><br/><strong>1. </strong></span><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>Run the</span><strong><span style="font-weight:normal;font-size:8pt;color:black;font-family:Verdana" lang=EN-GB> </span></strong><span class=MsoHyperlink><strong><span style="font-size:8pt;font-family:Verdana" lang=EN-GB><a href="http://www.microsoft.com/security/malwareremove/default.mspx">Microsoft Windows Malicious Software Removal Tool</a></span></strong></span><span lang=EN-GB><span style="font-size:small"><span style="font-family:Times New Roman"> </span></span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:#cc0000;font-family:Verdana" lang=EN-GB>2</span></strong><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>. Download <strong>ATF Cleaner</strong> by Microsoft MVP <strong>Atribune</strong> from </span><span class=MsoHyperlink><span style="font-size:8pt;font-family:Verdana"><a href="http://www.atribune.org/index.php?option=com_content&amp;task=view&amp;id=25&amp;Itemid=25"><span lang=EN-GB>http://www.atribune.org/</span></a></span></span><span style="font-size:8pt;font-family:Verdana" lang=EN-GB><span>  </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Double-click ATF-Cleaner.exe to run the program. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Click Select All found at the bottom of the list. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Click the Empty Selected button. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Click Exit on the Main menu to close the program. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Shutdown/restart the computer.</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:#cc0000;font-family:Verdana" lang=EN-GB>3</span></strong><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>. Next, download </span><span class=MsoHyperlink><strong><span style="font-size:8pt;font-family:Verdana"><a href="http://www.besttechie.net/tools/mbam-setup.exe"><span lang=EN-GB>Malwarebytes' Anti-Malware</span></a></span></strong></span><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> to your desktop. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>[<strong>Malwarebytes' Anti-Malware</strong> was created by a Microsoft MVP and is free for personal use].</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Double-click mbam-setup.exe and follow the prompts to install the program. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- If an update is found, it will download and install the latest version. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Once the program has loaded, select Perform full scan, then click Scan. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- When the scan is complete, click OK, then Show Results to view the results. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Be sure that everything is checked, and click Remove Selected.</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:#cc0000;font-family:Verdana" lang=EN-GB>4</span></strong><strong><span style="font-weight:normal;font-size:8pt;color:black;font-family:Verdana" lang=EN-GB>. </span></strong><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>Download, install, update and run: </span><span class=MsoHyperlink><strong><span style="font-size:8pt;font-family:Verdana"><a title="http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE" href="http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE"><span lang=EN-GB>SUPERAntispyware</span></a></span></strong></span><span class=MsoHyperlink><strong><span style="font-size:8pt;font-family:Verdana"><span style="text-decoration:underline"><span style="color:#0000ff"> </span></span></span></strong></span><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>(<em><span style="color:black">freeware</span></em>)<span style="color:#666666"> </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- <a href="http://www.superantispyware.com/supportfaqdisplay.html?faq=1"><span style="font-size:8.5pt;color:windowtext;text-decoration:none;text-underline:none" lang=IT><span><span style="text-decoration:underline"><span style="color:blue" lang=EN-GB>How do I download and install SUPERAntiSpyware?</span></span></span></span></a></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- <a href="http://www.superantispyware.com/support.html"><span style="color:#800080">Customer Service and Product Support</span></a> (FAQs)</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:#cc0000;font-family:Verdana" lang=EN-GB>5</span></strong><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>. If still no joy see and follow <strong>carefully</strong>: <br/><span class=MsoHyperlink><a title="http://blogs.dotnethell.it/vincent/Post_4820.aspx" href="http://blogs.dotnethell.it/vincent/Post_4820.aspx">&quot;Checking for/Help with Spyware, Malware and Hijackware&quot;</a></span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:black;font-family:Verdana" lang=EN-GB> </span></strong></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:black;font-family:Verdana" lang=EN-GB> </span></strong></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>In the event you need further assistance with malware removal, I suggest you follow the instructions at one of the </span><span class=MsoHyperlink><span style="font-size:8pt;font-family:Verdana"><a href="http://asap.maddoktor2.com/"><span lang=EN-GB>ASAP Member</span></a></span></span><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> sites that provides malware removal assistance. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>Part of this Guided Help courtesy of my colleague <strong>MVP Consumer Security</strong> <a href="http://securitygarden.blogspot.com/"><strong>Corrine</strong></a></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>Hope this helps,</span></p> <hr class=sig> Vincenzo Di Russo - Microsoft MVP Windows Internet Explorer, Windows Desktop Experience &amp; Security - Since 2003. <br/>~ My Blog: <a href="http://blogs.dotnethell.it/vincent/">http://blogs.dotnethell.it/vincent/</a>© 2009 Microsoft Corporation. All rights reserved.Sat, 14 Nov 2009 22:28:37 Zba80504b-61f1-4d71-960f-b561798b7b42http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#ba80504b-61f1-4d71-960f-b561798b7b42http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#ba80504b-61f1-4d71-960f-b561798b7b42Vincenzo Di Russohttp://social.answers.microsoft.com/Profile/en-US/?user=Vincenzo%20Di%20RussoHow to get rid of malware<p class=MsoNormal style="margin:0cm 0cm 0pt"><span>You may experience any one or more of the following symptoms: <br/>- When you start your computer, or when your computer has been idle for many minutes, your - Internet browser opens to display Web site advertisements.<br/>- When you use your browser to view Web sites, other instances of your browser open to display Web site advertisements.<br/>- Your Web browser's home page unexpectedly changes.<br/>- Web pages are unexpectedly added to your Favorites folder.<br/>- New toolbars are unexpectedly added to your Web browser.<br/>- You cannot start a program.<br/>- When you click a link in a program, the link does not work.<br/>- Your Web browser suddenly closes or stops responding.<br/>- It takes a much longer time to start or to resume your computer.<br/>- Components of Windows or other programs no longer work.</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span>See: <br/><a href="http://support.microsoft.com/kb/827315/en-us">http://support.microsoft.com/kb/827315/en-us</a><br/>&quot;Unexplained computer behavior may be caused by deceptive software&quot;.<br/><br/><strong>1. </strong></span><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>Run the</span><strong><span style="font-weight:normal;font-size:8pt;color:black;font-family:Verdana" lang=EN-GB> </span></strong><span class=MsoHyperlink><strong><span style="font-size:8pt;font-family:Verdana" lang=EN-GB><a href="http://www.microsoft.com/security/malwareremove/default.mspx">Microsoft Windows Malicious Software Removal Tool</a></span></strong></span><span lang=EN-GB><span style="font-size:small"><span style="font-family:Times New Roman"> </span></span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:#cc0000;font-family:Verdana" lang=EN-GB>2</span></strong><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>. Download <strong>ATF Cleaner</strong> by Microsoft MVP <strong>Atribune</strong> from </span><span class=MsoHyperlink><span style="font-size:8pt;font-family:Verdana"><a href="http://www.atribune.org/index.php?option=com_content&amp;task=view&amp;id=25&amp;Itemid=25"><span lang=EN-GB>http://www.atribune.org/</span></a></span></span><span style="font-size:8pt;font-family:Verdana" lang=EN-GB><span>  </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Double-click ATF-Cleaner.exe to run the program. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Click Select All found at the bottom of the list. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Click the Empty Selected button. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Click Exit on the Main menu to close the program. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Shutdown/restart the computer.</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:#cc0000;font-family:Verdana" lang=EN-GB>3</span></strong><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>. Next, download </span><span class=MsoHyperlink><strong><span style="font-size:8pt;font-family:Verdana"><a href="http://www.besttechie.net/tools/mbam-setup.exe"><span lang=EN-GB>Malwarebytes' Anti-Malware</span></a></span></strong></span><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> to your desktop. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>[<strong>Malwarebytes' Anti-Malware</strong> was created by a Microsoft MVP and is free for personal use].</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Double-click mbam-setup.exe and follow the prompts to install the program. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- If an update is found, it will download and install the latest version. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Once the program has loaded, select Perform full scan, then click Scan. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- When the scan is complete, click OK, then Show Results to view the results. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- Be sure that everything is checked, and click Remove Selected.</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:#cc0000;font-family:Verdana" lang=EN-GB>4</span></strong><strong><span style="font-weight:normal;font-size:8pt;color:black;font-family:Verdana" lang=EN-GB>. </span></strong><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>Download, install, update and run: </span><span class=MsoHyperlink><strong><span style="font-size:8pt;font-family:Verdana"><a title="http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE" href="http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE"><span lang=EN-GB>SUPERAntispyware</span></a></span></strong></span><span class=MsoHyperlink><strong><span style="font-size:8pt;font-family:Verdana"><span style="text-decoration:underline"><span style="color:#0000ff"> </span></span></span></strong></span><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>(<em><span style="color:black">freeware</span></em>)<span style="color:#666666"> </span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- <a href="http://www.superantispyware.com/supportfaqdisplay.html?faq=1"><span style="font-size:8.5pt;color:windowtext;text-decoration:none;text-underline:none" lang=IT><span><span style="text-decoration:underline"><span style="color:blue" lang=EN-GB>How do I download and install SUPERAntiSpyware?</span></span></span></span></a></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>- <a href="http://www.superantispyware.com/support.html"><span style="color:#800080">Customer Service and Product Support</span></a> (FAQs)</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:#cc0000;font-family:Verdana" lang=EN-GB>5</span></strong><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>. If still no joy see and follow <strong>carefully</strong>: <br/><span class=MsoHyperlink><a title="http://blogs.dotnethell.it/vincent/Post_4820.aspx" href="http://blogs.dotnethell.it/vincent/Post_4820.aspx">&quot;Checking for/Help with Spyware, Malware and Hijackware&quot;</a></span></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:black;font-family:Verdana" lang=EN-GB> </span></strong></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><strong><span style="font-size:8pt;color:black;font-family:Verdana" lang=EN-GB> </span></strong></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>In the event you need further assistance with malware removal, I suggest you follow the instructions at one of the </span><span class=MsoHyperlink><span style="font-size:8pt;font-family:Verdana"><a href="http://asap.maddoktor2.com/"><span lang=EN-GB>ASAP Member</span></a></span></span><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> sites that provides malware removal assistance. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>Part of this Guided Help courtesy of my colleague <strong>MVP Consumer Security</strong> <a href="http://securitygarden.blogspot.com/"><strong>Corrine</strong></a></span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:8pt;font-family:Verdana" lang=EN-GB>Hope this helps,</span></p> <hr class=sig> Vincenzo Di Russo - Microsoft MVP Windows Internet Explorer, Windows Desktop Experience &amp; Security - Since 2003. <br/>~ My Blog: <a href="http://blogs.dotnethell.it/vincent/">http://blogs.dotnethell.it/vincent/</a>Sat, 09 May 2009 08:18:01 Z2009-11-18T21:21:08Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#2c9b3ebe-e529-4729-a0f0-425b1d16feaehttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#2c9b3ebe-e529-4729-a0f0-425b1d16feaeVincenzo Di Russohttp://social.answers.microsoft.com/Profile/en-US/?user=Vincenzo%20Di%20RussoHow to get rid of malware<p><strong>Guided Help Part Two</strong></p> <p>When all else fails, <strong>HijackThis v2.0.2</strong> (<a href="http://aumha.org/downloads/hijackthis.exe">http://aumha.org/downloads/hijackthis.exe</a>) is the preferred tool to use (in conjunction with some other utilities). <br/>HijackThis will NOT fix anything on its own, but it will help you to both identify and remove any hijackware / spyware with assistance from an expert.<br/>Download: <a href="http://aumha.org/downloads/hijackthis.exe">http://aumha.org/downloads/hijackthis.exe</a></p> <p>Post your log to: <br/><a href="http://spywarehammer.com/simplemachinesforum/index.php?board=10.0">http://spywarehammer.com/simplemachinesforum/index.php?board=10.0</a>,<br/><a href="http://forums.spybot.info/forumdisplay.php?f=22">http://forums.spybot.info/forumdisplay.php?f=22</a>,<br/><a href="http://aumha.net/viewforum.php?f=30">http://aumha.net/viewforum.php?f=30</a>, <br/>or another appropriate forum for review by an expert in such matters<br/><br/>If the procedures look too complex - and there is no shame in admitting this isn't your cup of tea - take the machine to a local, reputable and independent (i.e., not BigBoxStoreUSA or Geek Squad) computer repair shop.<br/>Or you might consider deleting the User Profile altogether (although I wouldn't and trust the security of all other Profiles).<br/><br/>Courtesy of my colleague <strong>Robear Dyer</strong> (PA Bear) <strong>MS MVP</strong>-IE, Mail, Security, Windows Desktop Experience - since 2002<br/><br/>Hope this helps, <hr class=sig> Vincenzo Di Russo - Microsoft MVP Windows Internet Explorer, Windows Desktop Experience &amp; Security - Since 2003. <br/>~ My Blog: <a href="http://blogs.dotnethell.it/vincent/">http://blogs.dotnethell.it/vincent/</a></p>Sat, 09 May 2009 09:02:49 Z2009-05-09T09:06:53Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#a56a85d6-f677-4ff8-87bf-882eeb5e1dfdhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#a56a85d6-f677-4ff8-87bf-882eeb5e1dfdCorrine -http://social.answers.microsoft.com/Profile/en-US/?user=Corrine%20-How to get rid of malware<strong>Update:  Guided Help Part Two </strong> <blockquote>When all else fails, <strong>HijackThis v2.0.2</strong> (<a href="http://aumha.org/downloads/hijackthis.exe">http://aumha.org/downloads/hijackthis.exe</a> ) is the preferred tool to use (in conjunction with some other utilities). <br/></blockquote> Recently, many of the security help forums have begun moving away from HijackThis (HJT) as an initial tool, finding it useful only for a general idea of possible issues.  Malware today is often not visible in a HJT log.  In addition, preliminary cleaning often results in the issue not being visible in a HJT log.  <br/> <br/> As a result, it is suggested that anyone seeking additional assistance pay particular attention to the preliminary requirements of the site where they are obtaining help.  It is particularly useful to the analyst if a clear and concise explanation of the nature of the problem is provided along with all requested logs.  <br/> <br/> The help sites are very busy.  As a result, it may be a few days before a response is received.  It is advisable that you track your topic so you will know when an analyst has replied.  Because many of the sites track new help requests by zero (0) responses, it is not recommended that you &quot;bump&quot; your post.  Most sites have a place to post if you think your problem has been overlooked.  <br/> <br/> It is important to note that many of the tools used at the security help forums are extremely powerful.  If used incorrectly can turn your expensive computer into a large paperweight. For that reason, it is advisable that you seek help at an established, recognized site with trained analysts and not attempt to use specialized tools or fixes without proper guidance.  You can find Microsoft MVPs and other trained analysts at the following help sites:<br/> <br/> <br/> <a class=postlink href="http://asap.maddoktor2.com/" class=postlink><span style="text-decoration:underline"><span style="font-size:150%;line-height:normal"><span style="color:red">ASAP Member Forums Providing Log Analysis</span> </span> </span> </a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Dansk - Danish</span> </span> </span> <br/> <a class=postlink href="http://spywarefri.dk/" class=postlink>Spywarefri</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Deutsch - German</span> </span> </span> Spezifisch deutschsprachige Computerhilfe-Foren (german-language sites to get help from):<br/> <a class=postlink href="http://forum.emsisoft.com/Default.aspx?g=forum&amp;c=2" class=postlink>a-squared Anti-Malware</a> Sie haben Probleme mit a-squared Anti-Malware? Fragen Sie hier unsere Experten! <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">English</span> </span> </span> <br/> <a class=postlink href="http://www.247fixes.com/" class=postlink>247Fixes</a> <br/> <a class=postlink href="http://www.5starsupport.com/ipboard/" class=postlink>5 Star Support</a> <br/> <a class=postlink href="http://forum.emsisoft.com/Default.aspx?g=forum&amp;c=1" class=postlink>a-squared Anti-Malware</a> If you have problems with a-squared Anti-Malware? <br/> <a class=postlink href="http://amazingtechs.com/index.php?act=idx" class=postlink>Amazingtechs</a> <br/> <a class=postlink href="http://www.atribune.org/forums/" class=postlink>Atribune.org</a> <br/> <a class=postlink href="http://www.besttechie.net/forums/" class=postlink>BestTechie</a> <br/> <a class=postlink href="http://www.bluetack.co.uk/" class=postlink>Bluetack Internet Security Solutions</a> <br/> <a class=postlink href="http://www.cyberanswers.org/" class=postlink>CyberAnswers.org</a> <br/> <a class=postlink href="http://www.d-a-l.com/" class=postlink>D-A-L Computer Help</a> <br/> <a class=postlink href="http://www.freedomlist.com/forum/" class=postlink>Freedomlist</a> <br/> <a class=postlink href="http://forum.gladiator-antivirus.com/" class=postlink>Gladiator Security</a> <br/> <a class=postlink href="http://www.landzdown.com/" class=postlink>LandzDown</a> <br/> <a class=postlink href="http://help.lockergnome.com/" class=postlink>Lockergnome</a> <br/> <a class=postlink href="http://www.lognrock.com/forum/index.php?act=idx" class=postlink>Log'N'Rock</a> <br/> <a class=postlink href="http://www.malwarebytes.org/forums/index.php?act=idx" class=postlink>MalwareBytes</a> <br/> <a class=postlink href="http://www.malwareremoval.com/" class=postlink>MalWare Removal</a> <br/> <a href="http://www.nutnworks.com/forums/">NutnWorks</a> <br/> <a class=postlink href="http://forum.securitycadets.com/" class=postlink>Security Cadets</a> <br/> <a class=postlink href="http://www.forums.security-central.us/" class=postlink>Security Central</a> <br/> <a class=postlink href="http://www.smokey-services.eu/forum/" class=postlink>Smokey's Security Forums</a> <br/> <a class=postlink href="http://forums.maddoktor2.com/" class=postlink>SpyWare BeWare!</a> <br/> <a class=postlink href="http://www.spywareinfoforum.com/" class=postlink>SpywareInfoForum</a> <br/> <a class=postlink href="http://www.subratam.org/" class=postlink>Subratam.org</a> <br/> <a class=postlink href="http://www.techmonkeys.co.uk/" class=postlink>Techmonkeys</a> <br/> <a class=postlink href="http://www.techsupportforum.com/" class=postlink>Tech Support Forum</a> <br/> <a class=postlink href="http://forums.techguy.org/" class=postlink>Tech Support Guy</a> <br/> <a class=postlink href="http://temerc.com/" class=postlink>TeMerc Internet Countermeasures</a> <br/> <a class=postlink href="http://forums.thatcomputerguy.us/" class=postlink></a> <a class=postlink href="http://www.thespykiller.co.uk/" class=postlink>The Spykiller</a> <br/> <a class=postlink href="http://www.whatthetech.com/" class=postlink>WhatTheTech</a> <br/> <a class=postlink href="http://forums.windowsforum.org/" class=postlink>Windows Forum</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Español - Spanish</span> </span> </span> Sitios de ayuda contra el spyware en idioma español<br/> <a class=postlink href="http://forum.emsisoft.com/Default.aspx?g=forum&amp;c=4" class=postlink>a-squared Anti-Malware</a> Tiene problemas con a-squared, con la página de inicio de a-squared o con algún Malware en especial? Siéntase libre de pedir ayuda. <br/> <a class=postlink href="http://www.infospyware.com/" class=postlink>InfoSpyware</a> <br/> <a class=postlink href="http://www.forospyware.com/" class=postlink>ForoSpyware</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Finnish</span> </span> </span> Suomalaisia sivuja mistä saada malwaren poisto-apua (Finnish sites to get help from):<br/> <a class=postlink href="http://www.virustorjunta.net/" class=postlink>Virustorjunta</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Français - French</span> </span> </span> Voici des <span style="font-weight:bold">forums français</span> sur lesquels vous trouverez une aide rapide et efficace :<br/> <a class=postlink href="http://forum.emsisoft.com/Default.aspx?g=forum&amp;c=3" class=postlink>a-squared Anti-Malware</a> Vous avez des problèmes avec a-squared Anti-Malware ou avec certain Malware? Demandez ici à nos experts! <br/> <a class=postlink href="http://assiste.com/" class=postlink>Assiste.com</a> <br/> <a class=postlink href="http://forum.zebulon.fr/index.php?showforum=40" class=postlink>Zebulon</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Italiano - Italian</span> </span> </span> <br/> <a class=postlink href="http://forum.emsisoft.com/Default.aspx?g=forum&amp;c=5" class=postlink>a-squared Anti-Malware</a> Hai problemi con a-squared Anti-Malware o con malware speciale? Chiedi pure aiuto. <br/> <a class=postlink href="http://www.alground.com/forum/" class=postlink>Alground Research Center</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Nederlandstalig - Dutch</span> </span> </span> Op deze <span style="font-weight:bold">Nederlandstalige forums</span> wordt U snel en efficiënt geholpen :<br/> <a class=postlink href="http://www.hijackthis.nl/forum/" class=postlink>Hijackthis.nl</a> <br/> <a class=postlink href="http://www.antispywareoffensief.nl/" class=postlink>Nucia / Anti Spyware Offensief</a> <br/> <a class=postlink href="http://www.pchelper.nl/" class=postlink>PCHelper</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Portuguese</span> </span> </span> <br/> <a class=postlink href="http://linhadefensiva.uol.com.br/forum/" class=postlink>Linha Defensiva</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Serbian/Croatian</span> </span> </span> <br/> <a class=postlink href="http://www.mycity.co.yu/Ambulanta/" class=postlink>MyCity</a> <br/> <br/> <br/> <span style="text-decoration:underline"><span style="font-size:150%;line-height:normal"><span style="color:red">non-ASAP Forum Providing Log Analisis</span> </span> </span> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Deutsch - German</span> </span> </span> Spezifisch deutschsprachige Computerhilfe-Foren (German-language sites to get help from):<br/> <a class=postlink href="http://www.hijackthis-forum.de/index.php" class=postlink>HijackThis.de Support Board</a> <br/> <a class=postlink href="http://board.protecus.de/" class=postlink>Protecus</a> <br/> <a class=postlink href="http://rokop-security.de/index.php?act=idx" class=postlink>Rokop Security</a> <br/> <a class=postlink href="http://www.trojaner-board.de/" class=postlink>TrojanBoard</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">English</span> </span> </span> <br/> <a class=postlink href="http://www.asksomeone.net/forums/index.php?showforum=20" class=postlink>Asksomeone.net</a> <br/> <a class=postlink href="http://aumha.net/viewforum.php?f=30" class=postlink>Aumha.org</a> <br/> <a class=postlink href="http://www.bleepingcomputer.com/" class=postlink>BleepingComputer</a> <br/> <a class=postlink href="http://forums.us.dell.com/supportforums/board?board.id=si_hijack" class=postlink>Dell Community Forum - HJT room</a> <br/> <a class=postlink href="http://www.geekstogo.com/" class=postlink>Geeks to Go</a> <br/> <a class=postlink href="http://forums.spybot.info/forumdisplay.php?f=22" class=postlink>Safer-Networking</a> <br/> <a href="http://spywarehammer.com/simplemachinesforum/index.php">SpywareHammer</a> <br/> <a class=postlink href="http://spywarewarrior.com/" class=postlink>Spyware Warrior</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Français - French</span> </span> </span> <br/> <a class=postlink href="http://www.infos-du-net.com/forum/forum-11.html" class=postlink>IDN - Infos-Du-Net</a> <br/> <a class=postlink href="http://www.vista-xp.fr/forum/" class=postlink>Vista-XP.fr</a> <br/> <a class=postlink href="http://forums.futura-sciences.com/forum36.html" class=postlink>FS - Futura-Sciences</a> <br/> <a class=postlink href="http://forum.pcastuces.com/forum.asp?FORUM_ID=25" class=postlink>PCA - PC-Astuces</a> <br/> <a class=postlink href="http://forum.generation-nt.com/" class=postlink>Génération Nouvelles Technologies</a> <br/> <a class=postlink href="http://forum.telecharger.01net.com/telecharger/securite_virus_et_assimiles/sujets-1.html" class=postlink>Telecharger.Com/01net</a> <br/> <br/> <span style="font-weight:bold"><span style="color:red"><span style="text-decoration:underline">Nederlandstalig - Dutch</span> </span> </span> <br/> <a class=postlink href="http://support.bluemedicine.be/mybb/index.php" class=postlink>BlueMedicine</a> <br/> <a class=postlink href="http://www.minatica.be/forum.php" class=postlink>Minatica.be</a> <br/> <hr class=sig> Corrine, Microsoft MVP This posting is provided &quot;AS IS&quot; without warranty, and confers no rights.Sat, 09 May 2009 15:40:17 Z2009-05-09T16:04:25Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#03046670-221e-4f04-b734-84fac1e16458http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#03046670-221e-4f04-b734-84fac1e16458Vincenzo Di Russohttp://social.answers.microsoft.com/Profile/en-US/?user=Vincenzo%20Di%20RussoHow to get rid of malwareHi Corrine,<br/><br/>thank you very much for your update!<hr class="sig">Vincenzo Di Russo - Microsoft MVP Windows Internet Explorer, Windows Desktop Experience &amp; Security - Since 2003. ~ My Blog: http://blogs.dotnethell.it/vincent/Sat, 09 May 2009 15:55:48 Z2009-05-09T15:55:48Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#7002a20c-103d-4a13-a31b-7104b133a3b8http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#7002a20c-103d-4a13-a31b-7104b133a3b8Corrine -http://social.answers.microsoft.com/Profile/en-US/?user=Corrine%20-How to get rid of malwareYou're welcome.  I thought providing a list of some of the known international help sites would aid people needing further assistance.  The trick is to remember to keep the list updated.   :) <br/><hr class="sig">Corrine, Microsoft MVP This posting is provided &quot;AS IS&quot; without warranty, and confers no rights.Sat, 09 May 2009 16:07:29 Z2009-05-09T16:07:29Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#cd36c9e9-9dfc-4b9e-a643-26e7e34714f1http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#cd36c9e9-9dfc-4b9e-a643-26e7e34714f1Vincenzo Di Russohttp://social.answers.microsoft.com/Profile/en-US/?user=Vincenzo%20Di%20RussoHow to get rid of malwareHi again Corrine,<br/><br/>I agree with you ;-)<br/><br/>Now I hope that one <strong>MSFT - Moderator</strong> makes this thread &quot;<strong>Sticky</strong>&quot;, thanks!<hr class="sig">Vincenzo Di Russo - Microsoft MVP Windows Internet Explorer, Windows Desktop Experience &amp; Security - Since 2003. ~ My Blog: http://blogs.dotnethell.it/vincent/Sat, 09 May 2009 16:34:15 Z2009-05-09T16:34:15Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#08a8e38d-5e54-4505-922d-b3a6ebc62fdchttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#08a8e38d-5e54-4505-922d-b3a6ebc62fdcKaren0451http://social.answers.microsoft.com/Profile/en-US/?user=Karen0451How to get rid of malwareI'm sorry but should have said that I'm using my laptop to post this message and be on the net, the problem is with my <br/>Dell desktop (Vista)....<br/>KarenSun, 10 May 2009 16:05:13 Z2009-05-10T16:05:13Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#3f917c0a-6481-4251-b1bc-ce6e4429a854http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#3f917c0a-6481-4251-b1bc-ce6e4429a854Ken - Former Support Engineerhttp://social.answers.microsoft.com/Profile/en-US/?user=Ken%20-%20Former%20Support%20EngineerHow to get rid of malwareHi Karen0451<br/><br/>Please go to your original Post<br/><a href="http://social.answers.microsoft.com/Forums/en-US/InternetExplorer/thread/e4b33e63-d298-4ca7-ab66-56fba9c56117">http://social.answers.microsoft.com/Forums/en-US/InternetExplorer/thread/e4b33e63-d298-4ca7-ab66-56fba9c56117</a><br/><br/>If you need to download/reinstall Internet Explorer, you can do it on your laptop, burn it to a CD then re-install it on the Desktop.<br/><br/><a href="http://www.microsoft.com/windows/internet-explorer/?ocid=ie8_s_d69beac7-83c7-4a58-a655-68831a2e474a">http://www.microsoft.com/windows/internet-explorer/?ocid=ie8_s_d69beac7-83c7-4a58-a655-68831a2e474a</a><br/><br/>Were you successfull in removing the Virus/Malware?<br/><hr class="sig">Ken <br/> Microsoft Answers Support Engineer <br/> Visit our <a href="http://social.answers.microsoft.com/Forums/en-US/answersfeedback/threads/">Microsoft Answers Feedback Forum</a> and let us know what you think. Sun, 10 May 2009 17:07:08 Z2009-05-10T17:07:08Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#1c36830c-e054-4f3d-97fc-57403b6e2dfchttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#1c36830c-e054-4f3d-97fc-57403b6e2dfcVincenzo Di Russohttp://social.answers.microsoft.com/Profile/en-US/?user=Vincenzo%20Di%20RussoHow to get rid of malware<strong>Thank you MSFTs and Moderators for making this thread sticky!<br/></strong><br/>Cheers,<hr class="sig">Vincenzo Di Russo - Microsoft MVP Windows Internet Explorer, Windows Desktop Experience &amp; Security - Since 2003. ~ My Blog: http://blogs.dotnethell.it/vincent/Mon, 18 May 2009 09:25:08 Z2009-05-18T09:25:08Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#9dd7b5a4-f187-4f67-b19b-3f6edefa9fdchttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#9dd7b5a4-f187-4f67-b19b-3f6edefa9fdcAvatarrrrhttp://social.answers.microsoft.com/Profile/en-US/?user=AvatarrrrHow to get rid of malwareAn Excellent post Mr. Di Russo ^5<br/><br/>Typically, I run the MRT tool (Microsoft Windows Malicious Software Removal Tool, or, mrt.exe, for those that do not know) from an elevated (Administrator) command prompt.<br/><br/>During the monthly patching cycle, the mrt is updated in the system32 directory as I'm sure you know.  This file is larger than the one offered by Microsoft on the page you listed.  I realize that Microsoft recommends using the method you have described but, I feel the version in the system32 directory has more definitions and I am not aware that it is &quot;targeted&quot; by malware authors.  Please correct me if I am wrong.<br/><br/>I'll quote a part from:<br/><a href="http://support.microsoft.com/?kbid=890830#Faq">http://support.microsoft.com/?kbid=890830#Faq</a><br/><br/>The easiest way to download and run the tool is to turn on Automatic Updates. Turning on Automatic Updates guarantees that you receive the tool automatically every month. If you have Automatic Updates turned on, you have already been receiving new versions of this tool monthly. The tool runs in quiet mode unless it finds an infection. If you have not been notified of an infection, no malicious software has been found that needs your attention. <br/><br/>I did Google to see if this the mrt is targeted and came up empty, pretty much.  I have also not seen any blogs from cnet, zdnet or slashdot about this.  It also happens, sometimes, that a user is blocked from the Internet by malware and cannot get updates to any malware removal program.<br/><br/>I highly believe in the mrt so I am going to suggest the following for running the mrt locally:<br/>Open an Administrator command prompt:  Pres the Orb or start key, Or, use the Windows key and type:<br/>cmd<br/>Press all these keys together: CTRL+SHIFT+ENTER and deal with UAC as required.<br/>type, in the command box that opens:<br/>mrt and press enter.<br/>In the windows that opens, click next then, choose the radio button for Full scan and click next.<br/><br/>Allow the tool to complete.  This may take quite a while, depending.<br/>If an infection is found, follow the on screen instructions.<br/>If an infection is not found, press Finish.<br/><br/>I would also like to add Windows Defender to your list. It is continually being improved.  It has also been given a thumbs up by one malware author:<br/><a href="http://blogs.zdnet.com/security/?p=2385">http://blogs.zdnet.com/security/?p=2385</a><br/>and<br/><a href="http://blogs.technet.com/mmpc/archive/2008/10/10/malware-writer-wants-an-eye-to-eye-with-us.aspx">http://blogs.technet.com/mmpc/archive/2008/10/10/malware-writer-wants-an-eye-to-eye-with-us.aspx</a><br/><br/>I am open to a dialogue about this posting.  I will follow all advice given about this post and, if so requested, delete it.<br/><br/>Kind Regards,<br/>Avatar<br/><br/>edit:  I forgot to mention this can be done from the Recovery Enviroment.Mon, 18 May 2009 15:26:20 Z2009-05-18T15:29:00Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#f53c341c-a8dc-4e69-b874-034767e4c6bahttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#f53c341c-a8dc-4e69-b874-034767e4c6baoroukahttp://social.answers.microsoft.com/Profile/en-US/?user=oroukaHow to get rid of malware<p>I've just posted my own question about adserv cookies but your posting may be able to help me.  Will the steps you suggest remove adserv cookies and block them in future?</p>Wed, 17 Jun 2009 16:17:33 Z2009-06-17T16:17:33Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#eb85b0dc-98b1-4ec5-8bf2-8cc20cfb99b0http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#eb85b0dc-98b1-4ec5-8bf2-8cc20cfb99b0Vincenzo Di Russohttp://social.answers.microsoft.com/Profile/en-US/?user=Vincenzo%20Di%20RussoHow to get rid of malwareHi orouka,<br/><br/>I see your post: <a href="http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/1eb8043b-1bb9-4210-815b-5806dbffdc38"><span style="color:#0033cc">Windows defender not detecting or blocking Adserve cookies</span></a><br/><br/>See if this thread helps:<br/><a href="http://www.lavasoftsupport.com/index.php?showtopic=23414">http://www.lavasoftsupport.com/index.php?showtopic=23414</a> <hr class=sig> Vincenzo Di Russo - Microsoft MVP Windows Internet Explorer, Windows Desktop Experience &amp; Security - Since 2003. ~~~ My MVP Profile: <a href="https://mvp.support.microsoft.com/profile/Vincenzo">https://mvp.support.microsoft.com/profile/Vincenzo</a>Wed, 17 Jun 2009 16:48:15 Z2009-06-17T16:48:27Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#39972d47-5c56-4d3a-8650-c69077e59243http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#39972d47-5c56-4d3a-8650-c69077e59243Capt Garyhttp://social.answers.microsoft.com/Profile/en-US/?user=Capt%20GaryHow to get rid of malwareVincenzo, thanks for your help. It worked!<br/>I'm very new at this stuff and you really helped.<br/>GaryWed, 01 Jul 2009 02:22:31 Z2009-07-01T02:22:31Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#b9639910-387d-41a4-923f-ea6f04c37b2ahttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#b9639910-387d-41a4-923f-ea6f04c37b2aVincenzo Di Russohttp://social.answers.microsoft.com/Profile/en-US/?user=Vincenzo%20Di%20RussoHow to get rid of malwareHi Gary,<br/><br/>You're welcome. Glad to help and thank you very much for your feedback.<br/><br/>Cheers, <hr class=sig> Vincenzo Di Russo - Microsoft MVP Windows Internet Explorer, Windows Desktop Experience &amp; Security - Since 2003. ~~~ My MVP Profile: <a href="https://mvp.support.microsoft.com/profile/Vincenzo">https://mvp.support.microsoft.com/profile/Vincenzo</a>Wed, 01 Jul 2009 04:17:40 Z2009-07-01T04:17:49Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#5c4518e0-6c6c-4c00-8e88-7f0c9b6ef67bhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#5c4518e0-6c6c-4c00-8e88-7f0c9b6ef67bDal Thttp://social.answers.microsoft.com/Profile/en-US/?user=Dal%20THow to get rid of malwareI have tried this but it it detected nothing. Tried to download malwarebytes but my anti-virus bloked it, i am using Kaspersky. Does Kaspersky offer a feature to solve these advert pop-up problems? I'm new to all this so any help is much appreciated.<br/>Tue, 11 Aug 2009 13:37:06 Z2009-08-11T13:37:06Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#9392d835-9269-4e9e-8a7a-efe8f5c58996http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#9392d835-9269-4e9e-8a7a-efe8f5c58996Corrine -http://social.answers.microsoft.com/Profile/en-US/?user=Corrine%20-How to get rid of malwareHi, Dal T<br/> <br/> Kaspersky is not likely to block MalwareBytes Anti-Malware.  I suggest that you try a couple on-line scans.  Follow the instructions provided at the links below.<br/> <br/> <a href="http://onecare.live.com/site/en-US/default.htm">http://onecare.live.com/site/en-US/default.htm</a> <br/> <a href="http://www.eset.com/onlinescan/">http://www.eset.com/onlinescan/</a> <br/><hr class="sig">Corrine, Microsoft MVP This posting is provided &quot;AS IS&quot; without warranty, and confers no rights.Tue, 11 Aug 2009 13:59:32 Z2009-08-11T13:59:32Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#2bc728c6-410f-410f-95dc-34c63ef448adhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#2bc728c6-410f-410f-95dc-34c63ef448adbizmd4uhttp://social.answers.microsoft.com/Profile/en-US/?user=bizmd4uHow to get rid of malwaregrazie mille, Vincenzo!<br/><br/>I worked feverishly today to try to remove &quot;Personal Antivirus&quot; from a system for a customer--one that would be a problem to backup/reformat/reload. Your posting worked great! In particular the Malwarebytes software solved the problem. It worked even with the system logged in and running. I had first removed the HDD and scanned with ESET NOD32 to remove viruses and it did find over 100 infections, but was unsuccessful at removing &quot;Personal Antivirus&quot; once I reinstalled it to the original computer.<br/><br/>--BizMDThu, 20 Aug 2009 22:52:44 Z2009-08-20T22:52:44Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#ec3204ae-dc60-4a14-a716-7fcefa024d31http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#ec3204ae-dc60-4a14-a716-7fcefa024d31Vincenzo Di Russohttp://social.answers.microsoft.com/Profile/en-US/?user=Vincenzo%20Di%20RussoHow to get rid of malwareHi BizMD,<br/><br/>You're welcome. Glad to help and thank you very much for your feedback. <hr class=sig> Vincenzo Di Russo - Microsoft MVP Windows Internet Explorer, Windows Desktop Experience &amp; Security - Since 2003. ~~~ My MVP Profile: <a href="https://mvp.support.microsoft.com/profile/Vincenzo">https://mvp.support.microsoft.com/profile/Vincenzo</a>Fri, 21 Aug 2009 04:43:35 Z2009-08-21T04:43:48Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#f79e301a-13ba-42d7-94ad-f4f41e550c60http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#f79e301a-13ba-42d7-94ad-f4f41e550c60LeucadiaGhttp://social.answers.microsoft.com/Profile/en-US/?user=LeucadiaGHow to get rid of malwareHi Vincenzo,<br/><br/>I noticed that these instructions are on the Vista thread.  What should I do with a computer (Dell laptop Inspiron 8600) with Win XP?<br/><br/>Thank you,<br/>JGFri, 11 Sep 2009 10:57:03 Z2009-09-11T10:57:03Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#8d8556fb-f3e8-47ae-bb29-dc3f698e049chttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#8d8556fb-f3e8-47ae-bb29-dc3f698e049cVincenzo Di Russohttp://social.answers.microsoft.com/Profile/en-US/?user=Vincenzo%20Di%20RussoHow to get rid of malwareJG,<br/><br/>You can follow these directions also for Windows XP.<br/><br/><em>Hope this helps,</em><br/> <hr class=sig> Vincenzo Di Russo - Microsoft MVP Windows Internet Explorer, Windows Desktop Experience &amp; Security - Since 2003. ~~~ My MVP Profile: <a href="https://mvp.support.microsoft.com/profile/Vincenzo">https://mvp.support.microsoft.com/profile/Vincenzo</a>Fri, 11 Sep 2009 11:23:40 Z2009-09-11T11:23:54Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#872e15b1-2ffa-4c41-a117-1d91e5623c1ahttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#872e15b1-2ffa-4c41-a117-1d91e5623c1atotally pissedhttp://social.answers.microsoft.com/Profile/en-US/?user=totally%20pissedHow to get rid of malware<span style="font-family:verdana">sir i tried hijackThis ..it shows &quot;C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE&quot; is &quot;NASTY&quot;</span> <div><span style="">now what to do? i was thinking to delete this folder but couldn't find this file in C:\Program Files....</span></div> <div><span style="">plz help</span></div>Thu, 17 Sep 2009 11:48:29 Z2009-09-17T11:48:29Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#1f45b8e1-6ec8-4717-8cd5-9ea7f40ed1e9http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#1f45b8e1-6ec8-4717-8cd5-9ea7f40ed1e9Corrine -http://social.answers.microsoft.com/Profile/en-US/?user=Corrine%20-How to get rid of malware<blockquote><span style="font-family:verdana">sir i tried hijackThis ..it shows &quot;C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE&quot; is &quot;NASTY&quot;</span> <div><span>now what to do? i was thinking to delete this folder but couldn't find this file in C:\Program Files....</span></div> <div><span>plz help</span></div> </blockquote> <br/> <br/> HijackThis is an analysis tool and does not diagnose programs on the computer.  That said, MyWebSearch has been classified as malware, spyware, spyware, adware, or other potentially unwanted software.  I suggest that you start with Add/Remove Programs for an uninstall option.  If there is no uninstall option, you can use WinPatrol to remove the browser hijack.  <a href="http://www.winpatrol.com/bho.html">http://www.winpatrol.com/bho.html</a> .  WinPatrol is free for personal use.  There is also a one-time license purchase option for WinPatrol PLUS.  See <a href="http://www.winpatrol.com/">http://www.winpatrol.com/</a> .<strong>  </strong><hr class="sig">Corrine, Microsoft MVP (Consumer Security). This posting is provided &quot;AS IS&quot; without warranty, and confers no rights.Thu, 17 Sep 2009 14:16:10 Z2009-09-17T14:16:10Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#911b94e9-4cf0-487a-8fdc-15984c08824dhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#911b94e9-4cf0-487a-8fdc-15984c08824dStclewishttp://social.answers.microsoft.com/Profile/en-US/?user=StclewisHow to get rid of malwareHi there.  I received the Antivirus Pro 2010 virus on my computer this weekend.  Unfortunately, it has taken control of my computer.  I had read that I could delete the actually application by deleting it from my harddrive (manually since I could not get into Explorer-internet).  I found and deleted it but my computer still is having issues.  It now will load up and then after 5 minutes it does a restart.  Also, I can not get into other applications.  It seems to be a memory issue when looking at the error quickly.<br/>What can I do to get rid of the remaining virus if I can't get into applications and the internet?<br/><br/>Thank you<br/><br/>TerriMon, 21 Sep 2009 13:31:23 Z2009-09-21T13:31:23Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#8de5c405-910a-426d-8270-91a4a81bf11bhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#8de5c405-910a-426d-8270-91a4a81bf11bSpiritXhttp://social.answers.microsoft.com/Profile/en-US/?user=SpiritXHow to get rid of malwareHi,<br/><br/>You can follow the instructions here. And you can download programs on another computer<br/>and transfer them to your machine via removable media.<br/><br/>Remove Antivirus Pro 2010 (Uninstall Guide)<br/><a href="http://www.bleepingcomputer.com/virus-removal/remove-antivirus-pro-2010">http://www.bleepingcomputer.com/virus-removal/remove-antivirus-pro-2010</a><br/><br/>Download malwarebytes and scan with it, run MRT, and add Prevx to be sure it is gone. (If Rootkits run UnHackMe)<br/><br/>Download - SAVE - go to where you out it - Right Click on it - RUN AS ADMIN<br/><br/>Malwarebytes - free<br/><a href="http://www.malwarebytes.org/"><span style="color:#0033cc">http://www.malwarebytes.org/</span></a><br/><br/><br/>Run the Microsoft Malicious Removal Tool <br/><br/>Start - type in Search box -&gt; MRT  find at top of list - Right Click on it - RUN AS ADMIN.<br/><br/>You should be getting this tool and its updates via Windows Updates - if needed you can download it here.<br/><br/>Download - SAVE - go to where you out it - Right Click on it - RUN AS ADMIN<br/>(Then run MRT as above.)<br/><br/>Microsoft Malicious Removal Tool <br/><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=AD724AE0-E72D-4F54-9AB3-75B8EB148356&amp;displaylang=en"><span style="color:#0033cc">http://www.microsoft.com/downloads/details.aspx?FamilyID=AD724AE0-E72D-4F54-9AB3-75B8EB148356&amp;displaylang=en</span></a><br/><br/>-----------------------------<br/><br/>also install Prevx to be sure it is all gone. <p>Prevx - Home - Free - small, fast, exceptional CLOUD protection, works with other security programs. This is <br/>a scanner only, VERY EFFECTIVE, if it finds something come back here or use Google to see how to remove. <br/><a href="http://www.prevx.com/"><span style="color:#0033cc">http://www.prevx.com/</span></a></p> <p>PCmag - Prevx - Editor's Choice<br/><a href="http://www.pcmag.com/article2/0,2817,2346862,00.asp"><span style="color:#0033cc">http://www.pcmag.com/article2/0,2817,2346862,00.asp<br/></span></a><br/>--------------------------------------------<br/>Here are some online free scanners to help if needed :<br/><br/><a href="http://www.eset.com/onlinescan/"><span style="color:#0033cc">http://www.eset.com/onlinescan/</span></a><br/><br/><br/><a href="http://www.kaspersky.com/virusscanner"><span style="color:#0033cc">http://www.kaspersky.com/virusscanner</span></a><br/><br/>Other Free online scans<br/><a href="http://www.google.com/search?hl=en&amp;source=hp&amp;q=antivirus+free+online+scan&amp;aq=f&amp;oq=&amp;aqi=g1"><span style="color:#0033cc">http://www.google.com/search?hl=en&amp;source=hp&amp;q=antivirus+free+online+scan&amp;aq=f&amp;oq=&amp;aqi=g1</span></a><br/><br/>--------------------------------------------<br/><br/>Also do these to cleanup general corruption.<br/><br/>Run DiskCleanup - Start - All Programs - Accessories - System Tools - Disk Cleanup<br/><br/>Start - type this in Search Box -&gt;  COMMAND   find at top and RIGHT CLICK  -  RUN AS ADMIN<br/><br/>Enter this at the prompt - sfc /scannow<br/><br/><span lang=EN>How to analyze the log file entries that the Microsoft Windows Resource Checker (SFC.exe) program <br/>generates in Windows Vista cbs.log<br/><a href="http://support.microsoft.com/kb/928228"><span style="color:#0033cc">http://support.microsoft.com/kb/928228</span></a></span><br/><br/>Run checkdisk - schedule it to run at next start and then Apply OK your way out then restart.<br/><br/>How to Run Check Disk at Startup in Vista<br/><a href="http://www.vistax64.com/tutorials/67612-check-disk-chkdsk.html"><span style="color:#0033cc">http://www.vistax64.com/tutorials/67612-check-disk-chkdsk.html</span></a><br/><br/>-----------------------------------------------------------------------<br/><br/>If any Rootkits are found use this thread and other suggestions. (Run UnHackMe)<br/><br/><a href="http://social.answers.microsoft.com/Forums/en-US/InternetExplorer/thread/a8f665f0-c793-441a-a5b9-54b7e1e7a5a4/"><span style="color:#0033cc">http://social.answers.microsoft.com/Forums/en-US/InternetExplorer/thread/a8f665f0-c793-441a-a5b9-54b7e1e7a5a4/</span></a><br/><br/>Hope this helps.<br/> <hr class=sig> Rob - Bicycle - Mark Twain said it right.</p>Mon, 21 Sep 2009 13:38:19 Z2009-10-24T18:07:59Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#d53726e6-5a62-473a-aa66-a6e7318a8eb6http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#d53726e6-5a62-473a-aa66-a6e7318a8eb6Stclewishttp://social.answers.microsoft.com/Profile/en-US/?user=StclewisHow to get rid of malwareRob,<br/><br/>Thank you for the information.  I believe you are stating that I will need to use removable media in order to download the application from my laptop to my desktop.  What would be the best to purchase since I do not have this currently?  And where should I purchase this?<br/><br/>Thank you again!!Mon, 21 Sep 2009 13:51:15 Z2009-09-21T13:51:15Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#a1bb65c0-4f9c-4234-98e6-77b849d360efhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#a1bb65c0-4f9c-4234-98e6-77b849d360efSpiritXhttp://social.answers.microsoft.com/Profile/en-US/?user=SpiritXHow to get rid of malwareHi,<br/><br/>You can do some of that without extra programs. Run MRT and checkout the guide.<br/><br/>CD - DVD - USBThumb Drives - USB external drives.... whatever is best solution for your systems.<br/><br/>Good Luck<hr class="sig">Rob - Bicycle - Mark Twain said it right.Mon, 21 Sep 2009 14:04:41 Z2009-09-21T14:04:41Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#e6e54dc0-e664-4e16-935b-3673a628fbc0http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#e6e54dc0-e664-4e16-935b-3673a628fbc0Mattcb09http://social.answers.microsoft.com/Profile/en-US/?user=Mattcb09How to get rid of malware<span style="font-size:x-small">&quot;Download <strong>ATF Cleaner</strong> by Microsoft MVP <strong>Atribune</strong> from </span><span class=MsoHyperlink><span style="font-size:8pt;font-family:Verdana"><a href="http://www.atribune.org/index.php?option=com_content&amp;task=view&amp;id=25&amp;Itemid=25"><span lang=EN-GB>http://www.atribune.org/</span></a>&quot; <br/><br/>when i open this hyperlink there is a warning &quot;Please download <a rel=nofollow href="http://www.atribune.org/ccount/click.php?id=1"><strong><span style="color:red"><span style="font-size:x-small">ATF Cleaner</span></span></strong></a> by Atribune.<br/><strong>This program is for XP and Windows 2000 only&quot;<br/><br/> Is there a way to do this for vista?</strong></span></span>Sun, 25 Oct 2009 09:02:51 Z2009-10-25T09:02:51Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#d11f2b23-5388-4ef3-a2e3-abfbf35a9633http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#d11f2b23-5388-4ef3-a2e3-abfbf35a9633Ed T ATC 81http://social.answers.microsoft.com/Profile/en-US/?user=Ed%20T%20ATC%2081How to get rid of malwareThank you very much!Sun, 25 Oct 2009 16:59:08 Z2009-10-25T16:59:08Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#2477e6b5-fcdc-4ac3-afc7-5e7d6810898dhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#2477e6b5-fcdc-4ac3-afc7-5e7d6810898dCorrine -http://social.answers.microsoft.com/Profile/en-US/?user=Corrine%20-How to get rid of malwareHi, Mattcb09.<br/> <br/> Yes, you need to right-click the .exe file and select &quot;Run as Administrator&quot;, allowing the UAC elevation prompt.  As Atri indicated <a href="http://www.atribune.org/index.php?option=com_content&amp;task=view&amp;id=25&amp;Itemid=25">here</a> :<br/> <br/> <blockquote>Notes for Windows Vista users: <p>On Windows Vista that &quot;Windows Temp&quot; is disabled, to empty &quot;Windows Temp&quot; ATF-Cleaner must be &quot;Run as an Administrator&quot;</p> Prefetch has been disabled on Windows Vista. As I'm not sure the effects that emptying prefetch on Windows Vista  will have for the time being it I won't enable that function.</blockquote><hr class="sig">Corrine, Microsoft MVP (Consumer Security). This posting is provided &quot;AS IS&quot; without warranty, and confers no rights.Sun, 25 Oct 2009 22:13:38 Z2009-10-25T22:13:38Zhttp://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#7290837d-2548-4ea3-908b-72892ad4f874http://social.answers.microsoft.com/Forums/en-US/vistasecurity/thread/ba80504b-61f1-4d71-960f-b561798b7b42#7290837d-2548-4ea3-908b-72892ad4f874bintang11http://social.answers.microsoft.com/Profile/en-US/?user=bintang11How to get rid of malwareI've had the same problem as many others have listed... ie8 and unwanted websites opening themselves. The most common one I get is<br/> http://dati.pzzz.org:8081/lt/1plus1.html?pid=15&amp;mid=21904&amp;channel=23&amp;extra=-1&amp;pt=df&amp;clientid=1256628524<br/> This is a new laptop and I've only installed Windows and updated to ie8 so it's not a problem with anything I've loaded, and I haven't visited any other sites than those I used to with my old laptop running ie7.<br/> <br/> Rather than mess around downloading this, opening that, checking with this, cross referencing with that... I've got a better idea.<br/> I'm just going to stop using ie and switch to Google Chrome or Mozilla Firefox instead!<br/> <br/> I hate ie 8 and will not use it again... I've never had a problem like this with either of the other two browsers I've named!Tue, 27 Oct 2009 07:57:12 Z2009-10-27T07:57:12Z