Malware Clean-up Guidance
NOTE: the steps below works only if you are on the latest retail versions of ZA (Version 13 / ZA 2015 onwards). If you are not, please update.
Try to perform a full Antivirus/Antispyware scan but in SAFE MODE WITH NETWORKING**.
1. Set ZA Antivirus/antispyware to "Full Scan" under the computer tab --> Antivirus & Antispyware section (settings) --> "Scan mode is set to...."
2. Reboot in SAFE MODE WITH NETWORKING;
3. Manual run ZA (ZA firewall will be OFF but Antivirus/Antispyware will be functional);
4. Run a full ZA AV/AS scan;
5. Reboot in Normal Mode
6. Set ZA Antivirus/Antispyware back to default Quick scan
How to start in SAFE MODE WITH NETWORKING
If the above fails try to clean your system with:
A. Download update and scan with MBAM
WARNING: Some malware will block the running of this software, if this is the case run "chameleon.chm" from (...\Program Files\Malwarebytes’ Anti-Malware\Chameleon).
B. Use the superantispyware online cleaning tool --> Here or download, update and scan with superantispyware FREE
WARNING: Some malware will block the download of this software, rename the installer to a random name before saving and running.
C. Download, update and scan with Emsisoft Emergency Kit --> HERE
Still Problems? Try the ZA Rescue Disk or a bootable CD fromDrWeb
For a final check that your PC is clean run Hitman Pro cloud scanning (the scanner is free not the cleaning)
if ALL the above fails please post your Hijackthis log to Bleepingcomputer or SpywareHammer
Once you have cleaned the system please remember to purge the windows system restore points. You may be reinfected otherwise.
- Disable system restore (How to disable windows SYSTEM RESTORE);
- Reboot the PC
- Re-ensable system restore
** Scan in SAFE MODE with networking may not work in most recent versions of ZA (14.0.X.X). Just skip this step if it is the case.
** If you use a DNS service other then your ISP (e.g OpenDNS / DNSCrypt) you may need to disable it to be able to update the virus definitions in ZA while in SAFE MODE with Networking.