Timmy's Tips
My name is "Timmy the Tech". I'm here to throw you guys and gals a bone or two .
Ask for me personally the next time you're at our Midtown location.
Timmy's Tips
 

Here's What I've Dug Up Lately:

How to remove Trojans, Viruses, Worms, and other Malware

How do these infections start?

Just like any program, in order for the program to work, it must be started. Malware programs are no different in this respect and must be started in some fashion in order to do what they were designed to do. For the most part these infections run by creating a configuration entry in the Windows Registry in order to make these programs start when your computer starts.

Unfortunately, though, in the Windows operating system there are many different ways to make a program start which can make it difficult for the average computer user to find manually. Luckily for us, though, there are programs that allow us to cut through this confusion and see the various programs that are automatically starting when windows boots. The program we recommend for this, because it's free and detailed, is Autoruns from Sysinternals.

When you run this program it will list all the various programs that start when your computer is booted into Windows. For the most part, the majority of these programs are safe and should be left alone unless you know what you are doing or know you do not need them to run at startup.

At this point, you should download Autoruns and try it out. Just run the Autoruns.exe and look at all the programs that start automatically. Don't uncheck or delete anything at this point. Just examine the information to see an overview of the amount of programs that are starting automatically. When you feel comfortable with what you are seeing, move on to the next section.

How can you remove these infections?

We have finally arrived at the section you came here for. You are most likely reading this tutorial because you are infected with some sort of Malware and want to remove it. With this knowledge that you are infected, it is also assumed that you examined the programs running on your computer and found one that does not look right.

If you have identified the particular program that is part of the Malware, and you want to remove it, please follow these steps.

Download and extract the Autoruns program by Sysinternals to C:\Autoruns

Reboot into Safe Mode so that the Malware is not started when you are doing these steps. Many Malware monitor the keys that allow them to start and if they notice they have been removed, will automatically replace that startup key. For this reason booting into safe mode allows us to get past that defense in most cases.

Navigate to the C:\Autoruns folder you created in Step 1 and double-click on autoruns.exe.

When the program starts, click on the Options menu and enable the following options by clicking on them. This will place a checkmark next to each of these options.

Include empty locations

Verify Code Signatures

Hide Signed Microsoft Entries

Then press the F5 key on your keyboard to refresh the startups list using these new settings.

The program shows information about your startup entries in 8 different tabs. For the most part, the filename you are looking for will be found under the Logon or the Services tabs, but you should check all the other tabs to make sure they are not loading elsewhere as well. Click on each tab and look through the list for the filename that you want to remove. The filename will be found under the Image Path column. There may be more than one entry associated with the same file as it is common for Malware to create multiple startup entries. It is important to note that many Malware programs disguise themselves by using the same filenames as valid Microsoft files. It is therefore important to know exactly which file, and the folder they are in, that you want to remove.

Once you find the entry that is associated with the Malware, you want to delete that entry so it will not start again on the next reboot. To do that right click on the entry and select delete. This startup entry will now be removed from the Registry.

Now that we made it so it will not start on boot up, you should delete the file using My Computer or Windows Explorer. If you can not see the file, it may be hidden. To allow you to see hidden files you can follow the steps for your operating system found in this tutorial:

How to see hidden files in Windows

When you are finished removing the Malware entries from the Registry and deleting the files, reboot into normal mode as you will now be clean from the infection.

I want to help you take a bite out of these evil rascals!

Click here for a Dog's Philosophy
On Life !