{"id":439,"date":"2010-01-03T20:58:41","date_gmt":"2010-01-04T01:58:41","guid":{"rendered":"http:\/\/www.jasemccarty.com\/blog\/?p=439"},"modified":"2010-01-03T20:58:41","modified_gmt":"2010-01-04T01:58:41","slug":"spywarevirus-remove-technique","status":"publish","type":"post","link":"https:\/\/www.jasemccarty.com\/blog\/spywarevirus-remove-technique\/","title":{"rendered":"Spyware\/Virus Removal Technique"},"content":{"rendered":"<p>I normally blog about virtualization topics, but I saw a tweet from a guy I follow, and noticed that he spent some money getting his PC cleaned by the Geek Squad.<\/p>\n<p>Well, I was shown a method that has worked pretty well for me, and I figured I would share it.<\/p>\n<p>The primary component necessary, is <strong><a title=\"Process Explorer\" href=\"http:\/\/technet.microsoft.com\/en-us\/sysinternals\/bb896653.aspx\" target=\"_blank\">Process Explorer<\/a><\/strong> from Microsoft (formerly a Sysinternals tool).  This tool looks similar to the native Windows Task Manager, but is much more powerful.  The reason why it is an important component, is because it can suspend Explorer.exe and Winlogon.  These two processes are core pieces to the Windows operating system.  Viruses and Spyware often times hook into these, and as long as they are still running, <span style=\"color: #ff0000;\"><strong>can not be cleaned<\/strong><\/span>.<\/p>\n<table border=\"0\">\n<tbody>\n<tr>\n<td>To start, download Process Explorer.<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_download.png\"><img loading=\"lazy\" decoding=\"async\" title=\"PE_download\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_download-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td>Right click on the ProcessExplorer.zip file, and choose extract.<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_extract.png\"><img loading=\"lazy\" decoding=\"async\" title=\"PE_extract\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_extract-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td>When the extraction is complete, choose <strong>Show extracted files<\/strong>, and click <strong>Finish<\/strong>.<\/p>\n<p>Double click on <strong>procexp.exe<\/strong> to launch Process Explorer.<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_run.png\"><img loading=\"lazy\" decoding=\"async\" title=\"PE_run\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_run-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td>When presented with the license agreement, select <strong>Agree<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_agree.png\"><img loading=\"lazy\" decoding=\"async\" title=\"PE_agree\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_agree-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td>An application that looks like Task Manger will now be running.<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_running.png\"><img loading=\"lazy\" decoding=\"async\" title=\"PE_running\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_running-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td>Minimize Process Explorer.<\/p>\n<p>The second component, can be the antivirus or antispyware software package of your choice.  I often choose <strong><a title=\"http:\/\/www.malwarebytes.org\/\" href=\"http:\/\/www.malwarebytes.org\/\" target=\"_blank\">Malwarebytes<\/a><\/strong>, because I&#8217;ve seen quite a bit of success with it.  To get Malwarebytes, go to their web site: <strong><a title=\"http:\/\/www.malwarebytes.org\/\" href=\"http:\/\/www.malwarebytes.org\/\" target=\"_blank\">http:\/\/www.malwarebytes.org\/<\/a><\/strong> and click Download Free Version.  Once it is downloaded, double click on <strong>mbam-setup.exe<\/strong> to install it.  Choose all of the defaults.<\/p>\n<p>When the Malwarebytes installer is complete, make sure to Update Malwarebytes.<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/MB_update.png\"><img loading=\"lazy\" decoding=\"async\" title=\"MB_update\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/MB_update-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td>Once Malwarebytes is at the main application screen, choose <strong>Perform Full Scan<\/strong>, <em>but don&#8217;t click Scan yet<\/em>!<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/MB_scan.png\"><img loading=\"lazy\" decoding=\"async\" title=\"MB_scan\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/MB_scan-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td>Now restore Process Explorer, and make sure that both Process Explorer and Malwarebytes can be seen (clicked on) on the screen. This is because we won&#8217;t be able to use our Taskbar, ALT+TAB, or any other Explorer features shortly.<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE-MB-running.png\"><img loading=\"lazy\" decoding=\"async\" title=\"PE-MB-running\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE-MB-running-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td>Now right click on <strong>winlogon.exe<\/strong> and select <strong>Suspend<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_suspend_winlogon.png\"><img loading=\"lazy\" decoding=\"async\" title=\"PE_suspend_winlogon\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_suspend_winlogon-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td>Do the same to Explorer.exe, by right clicking <strong>Explorer.exe<\/strong> and selecting <strong>Suspend<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_suspend_explorer.png\"><img loading=\"lazy\" decoding=\"async\" title=\"PE_suspend_explorer\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/PE_suspend_explorer-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<tr>\n<td>Now click on the still visible <strong>Malwarebytes<\/strong> application, and choose <strong>Scan<\/strong>.  Choose any drives you wish to scan, and continue.<\/td>\n<\/tr>\n<tr>\n<td><a href=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/MB_scanning.png\"><img loading=\"lazy\" decoding=\"async\" title=\"MB_scanning\" src=\"http:\/\/www.jasemccarty.com\/blog\/wp-content\/uploads\/2010\/01\/MB_scanning-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>When the scanning is done, delete any spyware found, or any viruses.  Malwarebytes will tell you that Windows needs to be restarted to complete the process (most likely).  Answer Ok, but do not resume <strong>winlogon.exe<\/strong> or <strong>explorer.exe<\/strong>.  <span style=\"color: #ff0000;\"><strong>They could still be infected<\/strong><\/span>.<\/p>\n<p>Now power off the system.  Don&#8217;t reboot.  Don&#8217;t shutdown.  POWER OFF the system with the power switch.  I know, a No-No in the old days, but Windows XP and above do fine with this crash method.<\/p>\n<p>When the system boots back up, Malwarebytes may perform some additional actions, or it may not, it depends on what you were infected with.<\/p>\n<p>The important thing to remember, is suspending winlogon.exe and explorer.exe are crucial while scanning and cleanup. As mentioned before, often times, spyware and viruses will hook themselves into these processes.<\/p>\n<p>This method has worked for me with about a 95% success rate, with some nasty viruses\/spyware needing a little more effort.  The vast majority of junk out there should be cleaned with this method.<\/p>\n<p>I hope this helps anyone looking to get rid of unwanted junk.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I normally blog about virtualization topics, but I saw a tweet from a guy I follow, and noticed that he spent some money getting his &hellip; <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"class_list":["post-439","post","type-post","status-publish","format-standard","hentry","category-windows"],"_links":{"self":[{"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/posts\/439","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/comments?post=439"}],"version-history":[{"count":0,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/posts\/439\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/media?parent=439"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/categories?post=439"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jasemccarty.com\/blog\/wp-json\/wp\/v2\/tags?post=439"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}