STEP 1: Remove Malware
- Run rkill.exe – this will kill several known Spyware processes
- Malwarebytes Anti-Malware
- Kaspersky
- Spy Sweeper
- Adaware
- SpyBod Search & Destroy
- CWShredder
- McAfee Avert Stinger
Specific Malware removal:
STEP 2: Applications Tune-Up
- Uninstall unused applications
- Run HijackThis and parse it at http://www.hijackthis.de
- Run Auto-Runs to identify applications that do not need to be ran during start up
- Check any unknown applications with the following sites for additional information:
- www.File.net
- www.ProcessLibrary.com
- (Reference: Unnecessary Start up Applications)
STEP 3: HDD Tune-Up
- Run CCleaner to remove any unnecessary temporary files and registry entries
- Run Defraggler to defrag hard drive
- Run SpinRite v6 at Level 4 for hardware maintenance
STEP 4: Physical Cleaning
- Dust out inside of case (if working on machine locally)
- Wipe down screen and tower
STEP: Data Backup for OS Reinstall
- Review each installed application with the customer
- Backup any serial numbers, product codes or activation codes necessary to reinstall the software
- Windows Product code
- Microsoft Office Product codes
- Other Microsoft Product codes
- Documents and Settings
- C:\Documents and Settings\USERNAME\Application Data
- C:\Documents and Settings\USERNAME\Desktop
- C:\Documents and Settings\USERNAME\Favorites
- C:\Documents and Settings\USERNAME\Local Settings
- C:\Documents and Settings\USERNAME\My Documents
- Intuit Quick books default data folder
- C:\Documents and Settings\All Users\Documents\Intuit\QuickBooks\Company Files\
- Microsoft Outlook
- Outlook Settings:
C:\Documents and Settings\USERNAME\Application Data\Microsoft\Outlook - Outlook PST:
C:\Documents and Settings\USERNAME\Local Settings\Application Data\Microsoft\Outlook
- Outlook Settings:
- Firefox Bookmarks and Add-ons
- Deauthorize iTuenes account if possible
- Drivers if already on C:, this can save alot of time finding and downloading drivers
- Anti-Virus\Anti-Spyware product codes in the event that the software is still active
http://www.bleepingcomputer.com/virus-removal/
0 Responses
Stay in touch with the conversation, subscribe to the RSS feed for comments on this post.
You must be logged in to post a comment.