Virus Removal

Video Statistics and Information

Video
Captions Word Cloud
Reddit Comments
Captions
hi my name is Carrie Olson and I'm the co-host of a free podcast called tech bets it's available at wwe.com if you enjoy my videos I think you'll like my podcast be sure to check it out today I've got a customer system here that claims to have a virus now the first thing I need to do is verify the problem so I've got my keyboard and mouse out my and my monitor as you can see that's that a little thing dancing around complaining there's nothing plug into it so the first thing you want to do as I mentioned is verify the problem by plugging in just the bare essentials that we need the bare minimum to boot this computer because it has a potential virus it probably does have a virus we don't want to plug it into the Internet we don't want to plug anything into the land port so let's start with keyboard and mouse first so plug in a mouse there and the keyboard right there like that and let's plug our video in go right there and the last cable we plug in is power mmm now this case is this computer this computer is not one I built this is made by a soos they're a motherboard manufacturer you may have heard of and it's if you've never seen a case like this before it kind of can be difficult to find the power-on button fortunately for me I've seen these before otherwise I might spend the next half hour trying to find a darn power button but actually you see these chrome dividers here they have a little nub that sticks up and the top one is actually power there it goes either start to turn on now one of the things I one of the first things I checked you can do this well the computers moodiness I often get machines where customers have failed to take out a DVD or CD they left in the so now is a good time to just check that let's just open this up and see if we got anything yeah when you know it we've got a music CD in there so let's just set that aside for now we don't want that in there while working on it just slows things down apparently windows set a hard time starting before so let's just go ahead and say start Windows normally another thing when you pick up a computer from a client is you asked ask the client if the computer has a password on it you don't want to wait until you get the machine at your office and if you're like me you worked on it at night and you can't go past the password you've got to learn password cracking software or you just have to wait till the next day until you can call the client and find out what the password is so in this case I know this computer has a user account that has a password on it and I've got that password from the client that told it to me and sure enough there's the account and I've entered their password in and now let's just see what happens here if anything the computer does seem to be a bit slow already although I'm not sure what processor and RAM this has just yet it just seems like it's it should have been to the desktop by now I would have thought but let's see what happens well there's clearly something wrong with this computer it's just sitting there with a white screen I don't know if it's still loading or not clearly something's wrong with it first step one it's going to be to shut the computer off so we can just pull the power plug and then literally turn that off let's just go ahead and unplug everything while we're at so we just have our bare case and we're just going to pull the side panel off and the panel you want to pull off on the case is going to be opposite of raw sar so in this case it's going to be on this side this is the handle to pull this side panel off so we're just going to take these two screws out like that and that then that panel just comes right off down there for now and once that exposes the insides now before I go any further with this I'm going to hit it with my electric leaf blower and blow all the dust and dirt out of it well I've got it open and help keep my hands from getting all dirty and light in my house from getting dusty quite frankly all right so here you see I've got my cordless electric leaf blower and I use these the blow out computers better than that canned air it's a lot cheaper in the long run if you blow out as many as I do and the air pressure that comes out of it's not as strong as a gas-powered leaf blower so it's not going to harm the computer all the pressure that comes out of here is it that much so let's go ahead and get this blown out let's get the dogs away from it you'll see it only takes a few seconds with an electric Leaf Blower versus who would have taken a lot longer with that can of compressed air anyway the dust is blown out of it most of it anyway and that's going to make it a lot easier to work on all right now that we have all the dust and debris blown out of the inside of the case we can look inside just to see if anything looks wrong look for busted or leaking capacitors when we turn it on make sure all the fans are turning and at this point let's see if we can get the boot into safe mode so to do that I'm going to step around here turn this on obviously I've got it all hooked back up again and you just got to know and hit the f8 key so if we start pressing f8 right and do it up just keep repeating like pressing f8 if you see the windows logo then you've waited too long so now what's happened is this this computer's BIOS uses f8 to select your boot device if you have a BIOS like that go ahead and hit enter an F 8 really quick and we'll just keep bidding up 8 here there finally we get our menu up I don't like it when a BIOS uses FA as a as a command option because it makes getting into safe mode a bit difficult now let's try and get into safe mode here see what happens when if you've never seen safe mode before you see a list of all the files that the operating system is loading and it's just out it's just loading the basic stuff the bare minimum that it needs and it's normally going to take a bit longer to boot than a normal boot but in our case it'll probably be faster since our previous boot just never finished you guys you're going to see your basic video driver loads which means your screen may look a bit different everything they look larger so let's go ahead and put our password in here let's see if we can get to a desktop this time okay so that worked that's great that's going to make getting this virus off a lot easier I'll tell you that so this little help window comes up about Windows help and support explains what safe mode is in more detail if you're unfamiliar with it I'd suggest you take a few minutes to read that now this is a USB flash drive and on it I've got to my favorite antique malware products combofix and malwarebytes you can find both for free on the internet I'll have links to those in the video notes below and we'll just go ahead and plug this flash drive in one of our available USB ports right up front here and you should just come up and then there it is right there and let's just go ahead and run combofix first what I'm going to do is I'm going to just go ahead and copy this combofix file right over to the desktop so it'll run a little bit faster than running off the USB so let's go ahead and run combofix we want to do is right-click on the file and run it as administrator we can go ahead and close that back window down and you know come up and probably tell us that it doesn't like our Microsoft Security Essentials that we should disable it you don't have to worry about that in Safe Mode that's a Microsoft Security Essentials doesn't offer real-time protection and safe mode anyway so you can just ignore that it wants you to disable them you know saying hey you didn't disable that if you continue it's at your own risk that's fine it doesn't matter click OK and I'll just let combofix run and let it do its thing and hopefully it'll it'll find this virus and remove it so let's uh let's see what happens you all right now that our combofix is finished running it's open this file up in notepad to tell us everything it's done and I don't know if it's uh removed anything or not so you can look through this and and and check but I'm just gonna go ahead and close it and then the next thing I want to do is install the malwarebytes so we'll go right back to the flash drive here and we'll run our bite setup and yes it does allow you to install in safe mode and it lets you enable a free trial mode and everything will go ahead and do that because we're not connected to the Internet we won't be able to get the latest updates but we are running the latest version of malwarebytes so here we get an error that it couldn't update that's that's normal because as I mentioned we're not going to compute it the database is updated by 38 days that's not good but let's go ahead and do a full scan and it's select just the C Drive and let's see if it finds anything so we'll there scan completed we go ahead and remove our flash drive we don't need that right now let's just reboot the computer and see if if combofix has made any difference at all here we'll just select restart and that's see what happens and look at that we got our desktop back all the icons are back that may not mean that the virus is completely removed though it'd be a good idea to pick a couple other virus scanners just to make sure that you've got the virus completely removed you know get a couple of opinions third second and third opinions we can hurt and then of course we'll hit Windows Update make sure we have all the latest updates installed make sure that the latest version of Java is installed make sure the latest version of Adobe Reader and Adobe Flash are installed delete all the temp files if there's any updated drivers we'll install them and you can defragment the hard drive and you know check the start-up of windows to make sure that nothing is starting that doesn't need to be starting to speed that startup process and then the computer will be ready to give right back to the client so this virus appears still not been too difficult to remove and like I said it's still there still may be traces of the virus on there so at this point at least we've got our desktop back when we can run pretty much any antivirus program right now it doesn't matter what you choose but try out you know at least I would say two more antivirus programs or anti-malware programs and do full scans of the hard drive you want to make sure you delete all the previous system restore points too because if they give the customer back the system and then they have a problem and they go to your system restore they can end up putting the virus potentially right back on the system so that's something I always do anytime I work on a computer even if it's not a virus even if it's uh just a optimization the customer can undo all my work by going back with system restore very easily you can go in to your system restore and turn it off and then turn it back on again and that will reset your system restore points and create just one new one at that very moment so that's as far back as the customer will be able to go so I always do that before giving a computer back to the client I hope this video was helpful to you and I'll see you next time thanks watch
Info
Channel: CareyHolzman
Views: 515,092
Rating: undefined out of 5
Keywords: yt:stretch=16:9, virus removal, how to remove virus, how to uninstall, remove, virus, fix, repair, carey, holzman
Id: 8g5eYTrMdvE
Channel Id: undefined
Length: 14min 2sec (842 seconds)
Published: Sun Nov 11 2012
Related Videos
Note
Please note that this website is currently a work in progress! Lots of interesting data and statistics to come.