Thema geschlossen
Zeige Ergebnis 1 bis 3 von 3

Thema: Viruses - First Self-Help Guide

  1. #1
    Supermod a.D. Benutzerbild von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.175

    Viruses - First Self-Help Guide

    Hello Guest - welcome to HijackThis.de Support Board

    Do you need some help and no helper is online?
    You don't know what to do with this viruses on your computer and there is no one you can ask?


    Well, just for you I have written this First-Help-Tutorial. Reading this, you will learn how to help yourself. We will come back soon and see that you already have done your best.

    First of all, you should visit this page: English-Help. Have you already been here? Ok. So you know more about Hijack This. But you don't know anything about how to get rid of your problem, right? Well, you can read this: Security Tips. Are you afraid that your problem is so great that you will have to format your system? On this Board we try to do our best that no one must format a system. Sometimes it's not possible to avoid formatting. But in the most cases we succeed in giving help.

    So let's find out, what we can do for you, dear Guest.

    Please visit Know how - HijackThis to learn more about our Board, our Team and about the way we want you to post your logfiles.

    Please post your HijackThis-Logfile to your own new thread on the English-Board. Now, come here and browse your HijackThis Logfile from your computer into the window of the Analysis. Well, now you will see some different symbols:

    - - -

    If you have red and yellow symbols in your HijackThis Logfile, you may already begin with the first steps, until someone of us comes back to help you.

    STEP 1
    Make sure you set windows to see the hidden files and folders.

    Note: Using Windows XP or ME:
    Having cleaned up your system you must do this: turn off System Restore. Right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. Reboot. Turn System Restore Back On. Right-click My Computer. Click Properties. Click the System Restore tab. UN-Check *Turn off System Restore*. Click Apply, and then click OK.

    The first thing you can do, as you have got some malware on your system, is: turn your system back to an earlier System Restore Point. It can help you to get rid off all the malware without doing anything else.

    STEP 2
    Please let us begin to clean up your system.
    Create some new directories (folders) - Windows Tutorial)

    C:\download
    C:\bases
    C:\badthings

    STEP 3
    Load down this security software for free to C:\download:

    zipgenius (if you have no zip-tool)
    Disk Cleaner
    eScan
    Spybot Search and Destroy (install and update it)
    Ad-Aware SE and the Add-ons (VX2 Cleaner) (install and update it)
    SpywareBlaster to protect your Browsers (install and update it)
    Autostart Viewer
    Winpooch
    CWShredder (install and update it)
    DElLATER.ZIP install it to your desktop!

    STEP 4
    Run now first the DElLATER.exe on your system.
    Don't wonder. Nothing happens. You must only click "ok". That's all. That's ok.
    DelLater is the ideal program to use when you can't delete a file, no matter how hard you try.

    STEP 5
    Close down all programs, all windows including the Internet Explorer.
    Run CWShredder Put a Checkmark to Move CWS Files found .. ->Fix!

    STEP 6
    Run the Disk Cleaner
    Have a look to the screenshot. Set a checkmark to every item you want to clean:
    Temporary Internet Files and Temporary System Files, Cache, History and Prefetch (WindowsXP) must be cleaned up.
    Clean up as much folders as you can clean.

    Note: Every time you have finished your work on the Internet, please clean up your system with one of the Cleaning-Tools you can find here: Free Helper Tools

    Don't shut your system down without having cleaned up the traces of the Internet. This will help you to avoid problems.

    STEP 7
    (MUST!)Turn to safe mode

    STEP 8
    a) Run Ad-Aware SE - Tutorial
    All red Items must be green ones. Please use the VX2 Cleaner.
    Take a Full System Scan. Let the program delete everything it finds.
    It's finished? Well, then......

    b) Run Spybot Search and Destroy
    Put a checkmark into all boxes.
    Let the program delete everything it finds. Get the immunication for your system.

    Turn your system back to Normal Mode.

    STEP 9
    (Either STEP 9 or STEP 10 -> you don't need to do both STEPs, because the eScan works with the same signatures as KAV does)

    Run the eScan. Don't buy the program, we only need to see the results.

    STEP 10
    (Either STEP 10 or STEP 9 -> you don't need to do both STEPs, because the eScan works with the same signatures as KAV does)

    As you have got some worms and trojans on your system, you may want to load down a free Trial version of www.kaspersky.com (KAV). Update the program online.

    NOTE: you may not run two AV-Programs with On-Access-Scanners at the same time. Please disable your own AV-Program using KAV. Otherwise your system could crash.

    Now turn off your computer and remove the network cable/phone line from your machine. Reboot your computer into Safe Mode Scan your system with Kaspersky in Safe Mode. Let the program delete everything it finds. Save the logfile or copy all information about everything what has been deleted by KAV and paste it to you thread.

    STEP 11
    Having done all of this, you have done a lot. And now you have lost a lot of your problems, don't you? Please don't leave us. Scan your system online for free: Free Online-Scans

    You will find Online-Scans for all kinds of malware. Please use minimally three different Online Scans, because they all work with different signatures. May be one Online Scan finds something else than the other one. That's normal, that's ok. Take FullSystemScans and allow the Online-Scans to delete all malware they find. Save the logfiles.

    May I give you the advice to scan your system at first with:

    * http://housecall.trendmicro.com or housecall.trendmicro for NOT-IE
    * Panda ActiveScan
    * http://bitdefender.com/scan/licence.php

    As you want to know which threats are still left on your system, please control it with the
    Kaspersky Online Scanner

    Please reboot your system everytime when one scan is finished. You will have to allow ActiveX and set your IE settings to Standard for scanning online. The Panda Scan needs about 2 hours to do his work. Post all the results to your thread. You may want to take the "edit" or "ändern" Button to edit your postings.

    Don't forget to configure the IE with these Settings when the Online Scans are finished.

    Do you want to scan only one file for free?

    o virusscan.jotti.dhs.org
    o Virustotal
    o www.kaspersky.com
    o www.virus112.nu
    o IKARUS Free Online-Scanner
    o Dr.Web® anti-virus-scan
    o clamav online specimen scanner

    Report all the results into your thread on Board.

    Also if you belong to those ones who have got problems whith Pop-Ups and Promotion what means that you have some kinds of malware on your system, mostly ad- or spyware, you may want to have a look to this Thread because you will find there many different programs helping you to get rid off many Pests:

    - Free Ad- and Spyware Protection Tools

    Don't forget the Online-Scans against Ad- and Spyware:

    - Free Online-Scans for Ad- and Spyware

    Are you looking for a Remover for some kind of a very dangerous malware? You will find a list of different Removers here:

    - Malware Removal-Tools.

    Please click onto the links to get more information.

    Can't you find these strange programs and processes of your system anywhere? Only if you are not able to find back these files anywhere else, because it is really new malware, please use:

    UploadMalware.com or www.thespykiller.co.uk

    Ask us, we will help you to get your unknown files uploaded.
    .

    Do you need a Scout on our Board? Find it here:

    - Remover, AV, Ad-/Spyware.

    STEP 12
    Please visit Microsoft's windowsupdate site to load down the newest version of the service pack (Windows XP SP2): www.windowsupdate.com-SP2, please run the intern firewall of SP2. You can also visitwww.windowsupdate.com. Note: it's very important that Windows and the Internet Explorer are updated with all patches and with all Updates. Take once more a look here:Security Tips. Did you know that there are programs to make the Internet Explorer more safe? Did you know about alternative Browsers which avoid all these troubles you have? Please have a look to the Free Helper Tools where you can find alternative Browsers, secure Messenger Programs and even a secure MP3 Player. You can already begin to load down all these things which you must have to surf safely on the WorldWideWeb.

    Do you want to know more about these strange files on your system? You can find some information here:

    - ProcessLibrary
    - I am not a geek
    - Processes in Windows NT/2000/XP
    - Google

    Did you found out that you need an AntiVirus but you have no one? There are AntiVirus Programs for free, with On-Access-Scanners. You need one of these programs running in the background as you are working online. They can protect your work. But you need to configure these programs. Take the settings to delete malware. Don't forget to clean up the content of the Quarantine-Folders as Malware has been removed into these folders. Find all information about AntiVirus Programs, Freeware and Trial Versions here:

    - Anti-Malware (free)

    Do you know that you need a well configured Firewall running on your system?
    You can get all information about Firewalls here:

    - Firewalls & Information.

    Please don't forget: You are the one who must protect his system. Programs can help you. But as you don't know anything about the risks on the Internet, your programs are not able to protect you. Please read:


    Well, by the moment I'm not able to do more for you.

    Geändert von Ruby (03.03.2007 um 23:39 Uhr) Grund: Update

  2. #2
    Supermod a.D. Benutzerbild von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.175

    AW: Viruses - First Help - Tutorial

    How to clean out Temporary Files and Folders

    1) What do I have to do before....
    Please print out this instructions or safe it as a textfile (*.txt)
    since we will ask you to work offline in safe mode.


    Follow the numbers.

    1
    Make sure you set windows to see the hidden files and folders.

    2
    Remember that Hijackthis must be run in an own folder.
    C:\Program Files\HJT of C:\HJT
    Only if Hijackthis runs in an own folder it will create backups!


    --> NOT OK: C:\Documents and Settings\any name\Documenti\hijackthis_199\HijackThi s.exe

    3
    Look at
    IE Settings

    4
    Download for free: clearprog
    (other free Cleaning Tools)

    5
    Disconnect to the Internet.

    6
    Turn to safe mode.


    2) Delete the content of the temporary folders:

    1-1
    Go to START > run and type: cleanmgr and click ok.
    Let it scan your system for files to remove.
    Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked. Press OK to remove them.

    1-2
    Go to START> run> type %temp% and press [enter]. Do this for every account.

    1-3
    Go to START>Control Panel>Internet Options>tab programs> and click restore websettings.

    1-4
    1) Open Control Panel
    2) Click on Internet Options
    3) On the General Tab, in the middle of the screen, click on Delete Files
    4) You may also want to check the box "Delete all offline content"
    5) Click on OK and wait for the hourglass icon to stop after it deletes the temporary internet files
    6) You can now click on Delete Cookies and click OK to delete cookies that websites have placed on your hard drive

    1-5
    Delete the whole content of C:\Documents and Settings\Your Name\Local Settings\Temp <== this folder.

    1-6
    Delete the content of the Quarantine/Infected folders of AntiVirusPrograms.

    2
    (WindowsXP and ME)
    Turn System Restore Back On.
    Right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK

    2-1
    (WindowsXP and ME)
    Reboot.

    2-2
    (WindowsXP and ME)
    Turn off System Restore.
    Right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    3
    Reboot your system into normal mode.

    4
    Connect to the Internet

    5
    Run ClearProg
    "Clear all" and "Clear" must be checkmarked.
    Delete the content of your temporary folders and files.

    6
    (WindowsXP and ME: Turn on System Restore.)
    (WindowsXP) Create a new System Restore Point.
    Geändert von Ruby (20.08.2007 um 15:21 Uhr) Grund: Update

  3. #3
    Einsteiger Benutzerbild von mrrockford
    Registriert seit
    03.03.2007
    Beiträge
    7

    Viruses - First Help - Guide

    Howdy,

    A self-help procedure developed by CastleCops® Staff to assist folks who are having problems dealing with malware and/or who want to prevent (re)occurence of malware issues.

    Malware Removal and Prevention

    Step 10 in this procedure is specific to CastleCops. You can post at any help Board you want but please ask for help at only one Board as you will tie up resources if you post on multiple Boards! Also make sure you follow the specific guidelines for posting logs at the Board you use.
    Administrator CastleCops Deutsch
    Forum and News Admin CastleCops

Thema geschlossen

Aktive Benutzer

Aktive Benutzer

Aktive Benutzer in diesem Thema: 1 (Registrierte Benutzer: 0, Gäste: 1)

     

Ähnliche Themen

  1. Know how - HijackThis (de)
    Von Ruby im Forum Tipps & Tricks
    Antworten: 1
    Letzter Beitrag: 04.05.2010, 17:40
  2. Malware Guide
    Von Ruby im Forum Tipps & Tricks
    Antworten: 6
    Letzter Beitrag: 09.01.2008, 02:02
  3. Firewall Guide
    Von Ruby im Forum Tipps & Tricks
    Antworten: 0
    Letzter Beitrag: 07.11.2005, 01:54
  4. se.dll Removal Guide in Deutsch ;)
    Von Marc im Forum Archiv
    Antworten: 0
    Letzter Beitrag: 06.03.2005, 19:26

Forumregeln

  • Es ist Ihnen nicht erlaubt, neue Themen zu verfassen.
  • Es ist Ihnen nicht erlaubt, auf Beiträge zu antworten.
  • Es ist Ihnen nicht erlaubt, Anhänge hochzuladen.
  • Es ist Ihnen nicht erlaubt, Ihre Beiträge zu bearbeiten.