Cleaning an Infected Computer
1. Some ways a computer gets infected
- Responding to a phishing email
- Failing to keep your anti-virus and spyware definitions current
- Clicking on a seemingly innocuous web site for a free widget while a malicious script runs in the background
- Using an anonymous thumb drive you found in the airport and installing its keylogger software
- Opening an attachment from a long lost uncle you didn't know you had (and actually don't)
- Not disabling your web browser's function to automatically run scripts (check its security configuration and set to "high")
2. Signs a computer is infected
It begins to run slowly- Task manager indicates 100% utilization
- Firewall is asking permission to allow unknown programs access to the Internet
- There are unknown processes and programs at start up
- Policy changes were made without your knowledge
- There are visible configuration changes
- Some programs no longer work
- You begin to get pop-ups
3. Tools for your toolbox
CW Shredder (Trend Micro)- Ad-Aware (Lavasoft - for personal home use only)
- Spybot Search & Destroy
- SpyWare Blaster
- HijackThis
- Rootkit Buster
- RUBotted (automated scanning)
- Belarc Advisor
- Microsoft Baseline Analyzer
- Malwarebytes (Help Desk recommendation)
- MacScan (spyware removal tool for Macs)
- Flash or CD-run antivirus tool
4.
Steps to disinfect
- Remove the machine from the network
- If using XP, turn off the system restore
- Clean out the temporary files using Disk Clean-up
- Run the following apps: CW Shredder, Ad-Aware, Spybot S&D, SpyWare Blaster and HijackThis
- Run your system's antivirus tool plus a non-resident antivirus tool
- Reconnect to the network
- Run Belarc Advisor and then Run MS-Baseline Analyzer
- Take actions as needed, including turn on system restore
- Afterwards, change all passwords and monitor online banking, credit cards, etc.
5. Summary
The best defense is sometimes your best offense as well:
- If you use a firewall, keep it on
- Keep all your system tools up-to-date
- Consider using automatic updates
- Read everything that comes from ISG
- Use common sense!
Related Resources
PowerPoint Slides | Audio and Slides (Captivate) | Checklist version

