STEP 1
Uninstall Malware from Windows Add/Remove Program Tab
Go to Start > Control Panel > Add / Remove Programs and uninstall any of the following malware/spyware/adware programs if you find them listed.
180 Search Assistant
180Solutions
Active alert
Ad Service
AdTools
AdTools Service
Alexa toolbar
BargainBuddy
Bullseye Networks
CashBack
cosmi
DH
EasySearchBar
Elite Sidebar
Elite Toolbar
Freeze Clip Art
GAIN
Gator
Hotbar Outlook Tools
Hotbar Web Tools
HuntBar
ISTbar
ISTSvc
Media Access
Media Gateway
MySearch
MyWay Search Bar
MyWebSearch
NavExcel Search Toolbar
NavHelper
ncase
Oemji Toolbar
Open Site
Preview AdService
Search Toolbar (HuntBar/WinTools)
ShopperReports by Hotbar
Sidefind
SideSearch
Slotchbar
Software Update Manager
SurfAccuracy
Upspiral Toolbar
TurboDownload
VBouncer
Viewpoint
Viewpoint Manager
Viewpoint Media Player
WareOut
WeatherBug
Web Rebates
Web Search Toolbar (WinTools)
Webhancer
WhenU (any entry)
WeirdOnTheWeb
Windows AdService
Windows ServeAd
WinTools
WinTools Easy Installer
WSEM Update
These are Optional removals but we recommend you remove them as well.
Download Accelerator Plus
Kazaa
Kontiki
Messenger Plus
NetPumper
NewDotNet
P2P Networking
StarWare
WildTangent
*Note* If you're unsure about ANY entry then leave it alone and the Analyst will advise you in the fix later.
Search for Rogue and Suspect Programs
Please visit the following site and REMOVE/UNINSTALL any program you have that is listed on this site.
Spyware Warrior: Rogue/Suspect Anti-Spyware Products & Web Sites (
http://www.spywarewarrior.com/rogue_anti-spyware.htm )
This site is updated and maintained with a list of known "Rogue" and "Suspect" programs. These programs cannot be trusted as they either don't do what they say, are poorly designed, or take advantage of the user in an effort to get YOU to spend money on buying their products. Several of these programs actually install "Spyware/Adware" on your system!
Step 2:
Run an Online scan
Perform an online scan with Internet Explorer with Panda ActiveScan (
http://www.pandasoftware.com/products/activescan.htm)
1. Click on "scan pc" located at the bottom of the page.
2. A "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
3. Enter your e-mail address, country, and state & click "Free Online Scan" *The download of the 8 MB Panda's ActiveX control will take place*
Begin the scan by selecting "My Computer"
* If it finds any malware, it will offer you a report.
* Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
* Click on See Report then click Save report
* You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
* Turn off the real time scanner of any existing antivirus program while performing the online scan
Save the log
STEP 3
Installing Immediate Protection
Please download and install the following programmes Ã?Æ?Ã?â??Ã?â??Ã?¢Ã?Æ?Ã?¢Ã?¢ââ??¬Ã?¡Ã?â??Ã?¬Ã?Æ?Ã?¢Ã?¢ââ?¬Å¡Ã?¬Ã?â?¦Ã¢â?¬Å? they will provide some protection against further malware attacks and will continue to protect your system after you have been cleansed.
Spyware Blaster [
http://www.javacoolsoftware.com/downloads.html] to help prevent spyware from installing in the first place. A tutorial on installing this product can be found here.
IE-Spyad[
http://www.spywarewarrior.com/uiuc/resource.htm] places more than 4000 dubious websites and domains in the IE Restricted list. This severely impairs attempts to infect your system. A tutorial on installing this product can be found here.
*Note* After installing IE-SPYAD, a HijackThis scan will take a bit longer to run. This is normal Ã?Æ?Ã?â??Ã?â??Ã?¢Ã?Æ?Ã?¢Ã?¢ââ??¬Ã?¡Ã?â??Ã?¬Ã?Æ?Ã?¢Ã?¢ââ?¬Å¡Ã?¬Ã?â?¦Ã¢â?¬Å? please be patient.
Step 4.
Download
http://www.download.com/HijackThis/3000-8022_4-10379544.html (hijackthis), and run it, then save the log!
Step 5.
Go to techsupportforum.com and register there, then post you're hijackthis log in the "
HijackThis Log Help " center.
s:TSF
Hope this learns you to scan every file before you open it.