Removing Critical Viruses and Spyware

Overview

Note: the following tips apply to Windows only. Mac users generally do not have these types of "hijacking" problems.

Unfortunately most people who use the Internet even a little bit know what spyware and viruses are. Those are programs that perform operations for another party, such as tracking one's Internet surfing habits. It's quite possible for a Windows XP® systems to become so overloaded with trojan software that the computer seems unusable.

Fortunately there is a "secret handshake" to start Windows XP in a mode that doesn't load spyware and several free programs that can get rid of the Internet's nastiest problems. This tip offers step-by-step instructions for exorcising an infected XP system.

General Steps

To remove critical viruses and spyware from an XP computer, we go through the following general steps:

Each of these general steps has several specific steps, which we discuss in the following paragraphs.

Step By Step Procedure

The following steps are the absolute minimum necessary to disinfect a Windows XP system. If the computer still runs extremely slow after performing this procedure, perhaps there is a hardware fault. Consult with us for further details should this be the case.

Boot in Safe Mode

Step 1: Start XP in Safe Mode: Turn the computer on and start pressing the F8 key once a second. Eventually a text menu with various XP run modes appears. Select Safe Mode and press Enter twice to confirm the selection. Grant permission to run in safe mode after logging in. Note: safe mode runs with reduced colors and resolution, so the screen will look different then normal.

Step 2: Remove Peer to Peer Networking: With networking off, P2P networking software won't be able to set up server processes connecting to the Internet. Run Add/Remove Software under Control Panel, look for these programs (names sorted alphabetically), and click the Remove button to uninstall them:

Boot in Safe Mode With Networking

Step 3: Restart XP in Safe Mode With Networking: With P2P networking gone, the computer will be more responsive when connected to the Internet. Restart the computer and again press the F8 key once a second. This time select Safe Mode with Networking from the text menu and press Enter twice. Again, grant permission to run in safe mode after logging in.

Download Appropriate Utilities

Warning: Some so-called ad or spy removal programs are in fact ads themselves. We have tested the following utilities and they do not introduce more problems into a system.

Step 4: Download Freeware: Download the latest version of Stinger, Ad-Aware, and Spybot Search and Destroy.

Visit http://vil.nai.com/vil/stinger to obtain McAfee's Stinger program.

Visit http://www.tucows.com/preview/236049.html to download Lavasoft's Ad-Aware Special Edition.

Finally visit http://www.tucows.com/preview/310138.html for Safer Networking's Spybot - Search and Destroy.

Store all three files either on the desktop or a folder for later use.

Run the Appropriate Utilities

Step 5: Run Stinger: Stinger does not need to be installed: simply double click on stinger.exe and click the Scan Now button. No other steps are necessary, unless the computer has more then one hard disk. In this case, click Browse to add other drives to the scan list. Note Stinger takes about twenty minutes to run on a Ghz speed system.

Step 6: Install and Run Ad-Aware: Double click on aawsepersonal.exe and follow the prompts to install Ad-Aware. The last screen will automatically select options to perform a web update and a full system scan. Keep those selections and Ad-Aware will run after one clicks Finish.

When Ad-Aware's system scan is complete, which also takes about twenty minutes on a fast system, right click on the first found critical object and choose Select all objects from the resulting menu. Then click the Next button to quarantine and delete those objects.

Step 7: Install and Run Spybot: Double click on spybotsd13.exe and follow the prompts to install Spybot. The installer also will run the program after installation by default. Spybot has a help assistant which pops up: it's OK to click the suggested buttons and then click Next using this assistant. When prompted, run the tutorial. Again, if Spybot wants to delete some spyware after restart, grant permission and restart again in safe mode.

Restart and Rerun in Normal Mode

Step 8: One More Time: This sounds crazy, but we need to restart the computer in normal mode and rerun Spybot again FOR EACH LOGON NAME! Unfortunately some malicious software does not install at the system level, but at the user level. So one logon could have an infection that the others do not share. Go ahead and rerun this program in all accounts.

Patch to Prevent Future Attacks

Step 9: Run Windows Update: It now should be OK to begin using Internet Explorer. But before checking email or visiting more web sites, choose Windows Update under IE's Tools menu to apply the latest security patches. Restart the system and visit Windows Update again until there are no critical or security updates left.

Questions?

Feel free to call (number below) or send us email if you have questions about this tip.

Left Brained Geeks +1 214 234 9283