Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

To: unixfox
It's part of my job to outsmart malware that our clients get in to. It is getting trickier and tricker.

Step 1 (this freaks many people out.....) Disable System Restore. If you clean a virus without taking this step, often times it comes right back. I have yet to have to reinstall an OS due to malware, but if that were the next step, System Restore won't) do you any good anyway.

2) Disable any running antivirus program.

3) Hit Start. In the "start search" line (vista, right?) paste the following: (excluding the "'s)

"iexplore.exe http://download.bleepingcomputer.com/sUBs/ComboFix.exe"

This takes you directly to the combofix executable. Save it to your desktop and run it. Answer Yes to the "combofix is not affiliated...." statement, NO to the Recovery console, and let it do its thing.....should progress through over 50 stages and then produce a text file. I typically download and run Superantispyware free or malwarebytes after combofix, but combofix will at least get you functional.

If your malware infection stops the combofix download, it will need the work of a professional to remove the infection. There's more that can be done, but it's too complicated to describe here.

Good Luck

33 posted on 03/09/2010 5:09:36 PM PST by Mygirlsmom (Episode 2010: A NEW HOPE)
[ Post Reply | Private Reply | To 6 | View Replies ]


To: Mygirlsmom
Also good to remember to close any popup, especially the scareware "your system is infected" ones.....

Use ALT + F4 to close. Not the X, not right click. Even if it closes out something you're working on, it's better to do that than to enable spyware. I have seen that move prevent the spyware from executing in some cases.

34 posted on 03/09/2010 5:13:13 PM PST by Mygirlsmom (Episode 2010: A NEW HOPE)
[ Post Reply | Private Reply | To 33 | View Replies ]

To: Mygirlsmom

If they cannot get to the windows app in any mode, how can they run those steps?


35 posted on 03/10/2010 1:38:34 PM PST by joedel
[ Post Reply | Private Reply | To 33 | View Replies ]

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson