{"id":438,"date":"2012-03-05T20:43:39","date_gmt":"2012-03-06T03:43:39","guid":{"rendered":"http:\/\/rockblot.wordpress.com\/?p=434"},"modified":"2015-05-13T02:31:13","modified_gmt":"2015-05-13T02:31:13","slug":"eliminating-pc-malware","status":"publish","type":"post","link":"https:\/\/www.rockblotter.com\/DijaKnowThat\/eliminating-pc-malware\/","title":{"rendered":"Eliminating PC Malware"},"content":{"rendered":"<p>In my inbox this week was an email exclaiming, &#8220;my email has been hacked again!&#8221; \u00a0If you&#8217;re using an online free email service like Yahoo, Ymail, Hotmail, Live, MSN or Gmail &#8230;. and you can still use your password to access your account, your account may not have been &#8220;hacked.&#8221; \u00a0What&#8217;s probably happened is that you clicked on some malicious link in an email that allowed a hacker to access your address book and to spoof emails to addresses in your contact list as though they were you.<\/p>\n<p>If folks in your contact list start contacting you saying &#8220;what&#8217;s with all those links you&#8217;re sending me?&#8221; ,,, \u00a0you probably clicked on a malicious link in an email. \u00a0You probably got an email from someone you know and you clicked on it. \u00a0Now your friends are getting emails with just one very malicious link in the message area. \u00a0If you ever get an email that has nothing but a link in the message area &#8230; NEVER, EVER CLICK on that link. Just delete that email. \u00a0That&#8217;s exactly the type of email that could very easily set up a situation I&#8217;ve just described, and it just escalates from there.<\/p>\n<p>If someone you know reports to you that they\u2019re receiving such links, you\u2019re potentially infected \u2026 you apparently may have clicked on one of those links.\u00a0Just for safety&#8217;s sake, you should probably log into your email program and change your password.<\/p>\n<ul>\n<li>If you\u2019re using an online service like Yahoo, Google, Hotmail, etc. \u2026 go change your password. It should be at least 8 characters and should include both letters and numbers.\u00a0 Think of something easy for you to remember.\u00a0 For example, do you know your zip+4 zip code?\u00a0 Something that would be easy to remember might be to use the first letters of your first and last name, the \u201c+4 number\u201d in your zip code, and the first and last letters of your spouse\u2019s name.<\/li>\n<\/ul>\n<p>With that done, you should check out your PC to make sure nothing ugly is installed and resident in your PC. \u00a0Here&#8217;s the way I approach that task:<\/p>\n<ol>\n<li>Turn off System Restore.\u00a0 \u00a0If a virus infects a computer, the virus have been accidentally backed up by this windows feature. In order to completely remove a virus, you should disable\u00a0System\u00a0Restore before cleaning the system, then re-enable it after the system is clean\u00a0 If you don\u2019t know how to do that, just do a search on Google for:\u00a0 <strong><em>turn off system restore\u00a0<\/em><\/strong> followed by your operating system.\u00a0 For example:\u00a0 <em>turn off system restore XP.<\/em><\/li>\n<li>Update your virus protection and then do a FULL scan using your virus protection and delete any viruses it finds.<\/li>\n<li>Download and install <a href=\"http:\/\/www.malwarebytes.org\/\" target=\"_top\">MALWAREBYTES<\/a> (the free version), run a FULL scan and delete any viruses it finds.<\/li>\n<li>Hold down the windows key (the key between the CTRL and ALT keys at the lower left of your keyboard) and while you\u2019re holding that key down type an <strong>R<\/strong>.\u00a0 The RUN window should pop up. Type:\u00a0 <strong>mrt<\/strong>\u00a0 and then tap the \u2018enter\u2019 key.\u00a0 Microsoft\u2019s Malicious Software Removal Tool should start up.\u00a0 Run that tool. It&#8217;s gonna take a while to run, so you might want to go watch a game on TV or do a bit of laundry or shopping and check on what it found a bit later. \u00a0\u00a0Remove any viruses it finds<\/li>\n<li>\u00a0Repeat steps 3 through 5 until no viruses are found after each round.<\/li>\n<li>Once all three steps come up clean, turn your System Restore back on and create a new restore point<\/li>\n<\/ol>\n<p>All of those steps are going to take quite a bit of time to run through, but once you\u2019re done, you should be able to rid your PC of whatever varmint that may have taken up residence.<\/p>\n<p>We use the following applications to secure our PCs:<\/p>\n<ul>\n<li><strong><a href=\"http:\/\/windows.microsoft.com\/en-US\/windows\/products\/security-essentials\">Microsoft Security Essentials<\/a><\/strong>, a FREE anti-virus program from Microsoft<\/li>\n<li><strong><a href=\"http:\/\/www.malwarebytes.org\/\">Malwarebytes<\/a><\/strong>.\u00a0 We paid for the \u2018Pro\u2019 version, a nominal cost, so that it actively runs and protects our PCs.\u00a0 The free version isn&#8217;t residentally active and must be run manually. \u00a0Folks usually find themselves manually running it AFTER they\u2019ve become infected. \u00a0We chose to let it actively protect us from malicious websites.<\/li>\n<li><strong>No longer available: \u00a0<del><a href=\"http:\/\/www.threatfire.com\/\">Threatfire<\/a><\/del><\/strong><del>.\u00a0 Threatfire is FREE, though it will occasionally nag you, asking you if you want to upgrade to the PRO (paid) version (just say no). \u00a0Threatfire is another type of anti-virus application that can run alongside \u201cdefinitions-based\u201d anti-virus programs like Norton, McAfee, Microsoft Security Essentials, etc.\u00a0 Instead of looking at code definitions that a hacker might write, it instead looks at behaviors and will alert you when some \u2018behavior\u2019 is being requested \u2026 for example:\u00a0 \u201cAn application is trying to send an email to everybody in your address book.\u00a0 Is that something you\u2019re attempting to do?\u201d<\/del><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>In my inbox this week was an email exclaiming, &#8220;my email has been hacked again!&#8221; \u00a0If you&#8217;re using an online free email service like Yahoo, Ymail, Hotmail, Live, MSN or Gmail &#8230;. and you can still use your password to access your account, your account may not have been &#8220;hacked.&#8221; \u00a0What&#8217;s probably happened is that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":602,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","footnotes":""},"categories":[8],"tags":[22,29,37,42,58,60,67],"class_list":["post-438","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-pc-trouble","tag-email-virus","tag-google","tag-malwarebytes","tag-microsoft-security-essentials","tag-system-restore","tag-threatfire","tag-ymail"],"_links":{"self":[{"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/posts\/438","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/comments?post=438"}],"version-history":[{"count":2,"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/posts\/438\/revisions"}],"predecessor-version":[{"id":678,"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/posts\/438\/revisions\/678"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/media\/602"}],"wp:attachment":[{"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/media?parent=438"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/categories?post=438"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rockblotter.com\/DijaKnowThat\/wp-json\/wp\/v2\/tags?post=438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}