# Removing malware?

**URL:** https://boards.straightdope.com/t/removing-malware/531429
**Category:** Factual Questions
**Created:** [March 5, 2010, 4:27pm UTC](https://boards.straightdope.com/t/removing-malware/531429 "2010-03-05T16:27:48Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Little\_Nemo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/little_nemo/32/3120_2.png) [@Little\_Nemo](https://boards.straightdope.com/u/Little_Nemo)
#### Post date: [March 5, 2010, 4:27pm UTC](https://boards.straightdope.com/t/removing-malware/531429/1 "2010-03-05T16:27:48Z")

</div>

I’ve been attacked by malware. Specifically XP Internet Security 2010. My PC is basically out of service. I’ve been trying various remedies but the malware itself is preventing me from doing a lot of things I’d like to try.

I can’t get online (I’m doing this from a library). I’ve run AVG and Avast to no effect. I’ve run the free diagnostic of SpyDoctor and it tells me I have malware but I have to buy the registered version to fix it. I’d be willing to buy the registered version but the malware prevents me from doing this. I’ve downloaded a copy of Windows Defender and I’m going to try that next.

Any advice?

ETA: Standard PC (a Gateway model) running Windows XP.

---

<div class="post-metadata">

### Author: ![HorseloverFat](https://avatars.discourse-cdn.com/v4/letter/h/8e8cbc/32.png) [@HorseloverFat](https://boards.straightdope.com/u/HorseloverFat)
#### Post date: [March 5, 2010, 4:28pm UTC](https://boards.straightdope.com/t/removing-malware/531429/2 "2010-03-05T16:28:43Z")

</div>

Download the MSRT and run it in safe mode.

[http://www.microsoft.com/security/malwareremove/default.aspx](http://www.microsoft.com/security/malwareremove/default.aspx)

If that doesnt work try ComboFix in safe mode.

---

<div class="post-metadata">

### Author: ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)
#### Post date: [March 5, 2010, 4:32pm UTC](https://boards.straightdope.com/t/removing-malware/531429/3 "2010-03-05T16:32:16Z")

</div>

You may want to read a [similar thread](http://boards.straightdope.com/sdmb/showthread.php?t=554317) in ATMB.

My answer remains the same. Read the [sticky](http://boards.straightdope.com/sdmb/showthread.php?t=538187), try it, and if that doesn’t work, get back to us.

---

<div class="post-metadata">

### Author: ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)
#### Post date: [March 5, 2010, 4:32pm UTC](https://boards.straightdope.com/t/removing-malware/531429/4 "2010-03-05T16:32:40Z")

</div>

First solution is to try [Malwarebytes](http://www.malwarebytes.org/). It’s usually pretty effective – though malware nowadays often shuts it down before it can work or install.

If that doesn’t work, the next step is [Super Antispyware](http://www.superantispyware.com/). It’s more effective, but, again, malware often shuts it down.

After that, it gets tricky. [GMER](http://www.gmer.net/) searches for rootkits; if it finds one, be sure to delete it (they will be highlighted in red).

If all else fails, you may need to create a boot disk with BART PE to find the rootkits in your C:\windows\system32 folder.

---

<div class="post-metadata">

### Author: ![Bewildebeest](https://avatars.discourse-cdn.com/v4/letter/b/779978/32.png) [@Bewildebeest](https://boards.straightdope.com/u/Bewildebeest)
#### Post date: [March 6, 2010, 2:44am UTC](https://boards.straightdope.com/t/removing-malware/531429/5 "2010-03-06T02:44:19Z")

</div>

> [@RealityChuck](#):
>
> First solution is to try [Malwarebytes](http://www.malwarebytes.org/). It’s usually pretty effective – though malware nowadays often shuts it down before it can work or install.

I removed the 2008 and 2009 versions of this thing by renaming the downloaded installer file before running it, and then running it from the installer. I don’t know if this still works or not.

---

<div class="post-metadata">

### Author: ![Little\_Nemo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/little_nemo/32/3120_2.png) [@Little\_Nemo](https://boards.straightdope.com/u/Little_Nemo)
#### Post date: [March 7, 2010, 6:16am UTC](https://boards.straightdope.com/t/removing-malware/531429/6 "2010-03-07T06:16:57Z")

</div>

My thanks for everyone’s help. I spent several hours running anti-malware program today and it appears to have worked.
