Subscribe:

Labels

Wednesday, June 11, 2014

What to do if you get a virus or malware via a pop up message

There have been many posts on TechGeekandMore concerning viruses, spyware, malware, and scareware.  If you wonder why, its because as a tech, the number one question and the number one support call that I will take involves pc’s that have already been infected (because the user didn’t know any better) and what to do to clean up the pc.

     Sometimes the infection isn’t really bad and a simple scan and delete will clean things up, other times, its a matter of recover/save what you can from the pc and format/reinstall everything (and yes that could mean saying goodbye to important documents or a long downtime). On top of everything else keep in mind that hiring someone like me to clean up your pc could cost $100 / HR or more, and in some cases it may be more cost effective to buy a new pc.
     So where do we start, we start at a couple of common things that are DO’s and DONT
1) If your on any website and see a messages like the following
AV system pro spyware 1    Personal AV fake install message
DO NOT CLICK ON YES OR OK, it is a trick used by the writer of the virus or malware (known as social engineering) to get you to install the malware or virus.  Since the message will probably pop up as part of the page your on, you may just think that its a natural part of Windows and agree to it, at least that’s what the bad guy hopes you will believe.
Additionally, when online, DO READ WHAT THE POP MESSAGES SAY AND DONT JUST CLICK ON THEM TO GET THEM OUT OF YOUR WAY. ADDITIONALLY DONT BELIEVE EVERYTHING THAT POPS UP (I know this is a hard concept for most). The following are just some of the MILLIONS of possible messages that you could see
ConfickerFakeAVpop up message virus
Virus popup2 Virus popup1virus2windows-security-center-popup   
     Now lets talk about how these happen, they can happen because the website your visiting has been infected by a virus.  These days its not just pc’s that get infected it can also be websites both minor and major (Scareware Pop-Ups Target Google, New York Times), so DONT think that because the only sites you visit are major sites (Google, NY Times, Twitter, Facebook, etc) that your entirely safe.  You MUST always stay alert.
What if you machine is under attack from a Virus or Malware
     Take immediate action as soon as the message or popup comes up. The majority of viruses and malware is written in such a way that not only will your machine get infected, but the infection will go out to the internet (completely automatically) and download additional files and infections to reinforce itself. So the longer you take to address the issue the harder (and probably more expensive) it will be to clean your machine.  Image your self getting the flu, you take care of yourself and in a few days your body recovers and everything is normal again. However, if you get the flu and ignore it and just let it continue without doing anything about it, you could get sick enough to end up in a hospital or even dead. (Sorry to make it so over dramatic, but really that’s what it boils down to).
     As soon as you receive a one of these type of scareware/malware/virus pop up windows, you need to use the task manager to close whatever program your using to get to the internet (You should NEVER try and close the program with the ok or cancel button on the program as all the buttons no matter what they say will download unwanted files on to your pc). You can access the task manager 1 of 2 ways
Task Manager via Ctrl Alt Del key

ctrl_alt_del Hold down ctrl, alt, and delete at the same time.
XP ctrl alt del If your on WindowsXP you will see this box. Just select task manager. Ctrl alt del windows 7 If your on Windows Vista or 7, then you will see this window. Select Start Task Manager from here.
 Task Manager via Right Click
TaskManager Use an empty space on the task menu (that’s the bar on the bottom where you see your programs) right click, you will see Task Manager as a choice. Select Task Manager from there.
     Once you have opened the Task Manager, you will see the following window.
antivirus2009     From the applications tab you will see all programs that are currently running.  You should highlight any program that is connected to the internet (Internet Explorer, Firefox, Chrome, etc and Anything email) and select End Task. You will be prompted with end program
and select End Now. Continue doing that until you remove everything that is connected to the internet.
empty task manager
Once you have closed the Window – what next?
     This may take a little time, but its best to check you pc and make sure nothing stayed on it that shouldn’t be there.  There are 4 things you need to do at this point.
Step#1 -
If you use Internet Explorer
     Go to Tools –> Internet Options –>  select delete in the browser history section and delete all
Internet options IE
If your using Firefox
     Go to Tools –> Options –> Privacy and select clear your recent history and remove individual cookies ( you may need to change the setting to remember history to get to the settings)
FF cacheIf you use any other browser look for the area to remove, cache, temp or cookies and remove all.
***Also make sure you empty your recycling bin.***
Step# 2-
     If you don’t already have a copy on your pc, download Super Antispyware (LINK: http://superantispyware.com/) and install Super Antispyware. **There is a Free and Pro edition, all you will need is the free edition.**
- During the install you will see the following screens. Make sure you say YES to “Would you like Super Antispyware to check for the latest updates….” then select the default or recommended setting for the remaining screens. On the screen asking for email address you do NOT have to enter anything, you can just select the next button.
superantispyware update
image image image image 
     Once installed you will see the following screen, just make sure that the definition date (on the bottom right) is current (shouldn’t be more than a day or two old, if not click on check for updates) then select scan your computer (on top left)
image You will then see
superantispyware full At which point, select all your hard drives and select “Perform complete scan” and hit next.
Once the scan completes,
image You will see the list of items found.  I would recommend that all shown items remain with checks and then select next.
imageThe lastly once the clean up completes. You will be prompted to reboot.  I recommend you close anything that is still open and select yes to reboot.
 Step# 3
If you don’t already have Malwarebytes, download and install (LINK: http://www.malwarebytes.org/). **There is both a free and paid version, home users just need to get the free version.
  – During the install you will see the following screens, you can select the default choices. Toward the end of the install you will see a choice for “Update Malwarebytes Anti-Malware” make sure you have a check next to that choice.
image image image image image image image image     image
As soon as it is installed, you will see the following screen.  Make sure to select “Perform full scan” and select all your drives and run your scan.
image
Once completed you will see a list of all items found.  Select all and remove.  Then reboot pc.
Step# 4
     Lastly, whatever Anti-virus you have, make sure you update it to the latest updates or signature file (depending on which one you have) and run a full scan of all your drives.  If it finds anything select removal and then reboot.
     If you don’t have an Anti-Virus program or yours is expired, TGM recommends Microsoft Security Essentials which is free. (LINK: http://www.microsoft.com/Security_Essentials/ )
     I know this was a long post, but the steps listed above would be exactly the steps I would take if you called me (and probably most other techs) to take care of your pc.  Hopefully this information helps you stay informed and helps you save a headache and some money in the future.