- Malwarebytes
- ESET Free web
- eset website
- Microsoft Security Essentials
- TDS Killer
- TDS Killer from Kaspersky site
- FreeFixer
- AdwCleaner
- JRT – removal tool
Detection programs
- Process Explorer
- Monitor all network connections from infected machine
- Handle Sysinternals
- System Explorer- download SystemExplorerSetup_700
Links
- http://malwaretips.com/blogs/adware-win32-gamevance-virus/
- http://www.bleepingcomputer.com/virus-removal/
Registry fixes after virus removed
Process to remove virus
-
create a backup image of boot drive using Image for windows
-
do not plug computer into main network. plug into dmz
-
clean all temp files from the system %userprofile%\temp
-
download and run TFC from oldtimer TFC
-
-
if possible look are number or running processes, note any that are using a constant % of the cpu
-
document the number of processes running
-
-
check scheduled tasks, sometimes they are started from here
-
run autoruns.exe and look at all the start programs, download
-
see this under spyware removal processes
-
boot into safemode with networking
-
download and run tddskiller http://support.kaspersky.com/downloads/utils/tdsskiller.exe
-
run and see if it finds virus and cure
-
-
install malwarebytes and update and complete a full scan
-
save log file to memory stick in directory for customer
-
-
download and install Microsoft Security Essentials
-
run scan of system
-
goto nod32 and run online scan off system
-
reboot and run malwarebytes again
-
Optional sophos
-
using memory stick run the following program from sophos
-
SAV32CLI -REMOVE -P=C:\LOGFILE.TXT
-
boot into standard mode
-
update installed antivirus and run a complete scan of the system.
-
checklist after clean
-
the following must be completed to make sure system is clean
-
go to several websites, leave running for about 1/2 hour check for unwanted popups
-
run windowsupdate if it gives you a dns error
-
check dns stack using lspfix download lspfix
-
-
run gmer, it must be clean download gmer
-
run mbr in dos from gmer this checks master boot record sometimes the bugs hide here
-
last thing to try if you still can not clean it
-
run combofix download combofix
-