How To Manually Remove a Virus From Your Computer

Krazeee

Honorable
Aug 12, 2012
236
0
10,710
How To Manually Remove a Virus From Your Computer

Learn how to manually remove virus easily from your PC by watching this video:
[video="https://www.youtube.com/watch?v=NbRQc1nLOEo"][/video]

This guide focuses on manually removing viruses and malware from your computer. If you want to use an anti-virus program instead, please check out this tutorial written by Burritobob. This tutorial's best intention is focused around removing RAT and Keylogger viruses.

Step 1
Run msconfig and look for suspicious files. Here we see one. It’s unknown, and it also has a startup key that we’ve never seen until recently. Uncheck it from start up and/or from services.
5bkh.png


If you think you are being monitored. Open Command Prompt and do the following
4f5f.png


Step 2
Boot into safe mode. This can be done by checking the box in the “boot” tab in msconfig.
gm1d.png


Step 3
Run msconfig in safe mode and we can see it’s checked because the virus is persistent. The virus will not be running however, due to the fact that we are currently in safe mode.
670b.png


Step 4
Navigate to the registry. We are doing this in safe mode because some viruses disable the registry.
Note: Be sure your folder options are set to show hidden files and folders
qzu1.png


Step 5
Navigate to the location of the virus. If you are not sure which one is a virus, locate to all of the following possible locations:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
4ntb.png


Step 6
Section a) if you are unsure if it is a virus of not, right click the suspected file{s} and click modify
iutl.png


Since you are unsure of the integrity of the file, put a “:” in front of the value data. This will disable the start up of the virus but it will still be in your computer.
8prp.png


Section b) if you are certain that you’ve found the virus (like I have in the picture) you can delete the registry entry.
nufa.png


Step 7
Be certain it is gone; it shouldn’t even be listed as a startup item anymore.
gabh.png


Step 8
To be certain, use CCleaner to scan the registry and fix any issues there are.
azkj.png


Recap
Hopefully this should’ve gotten your computer rid of any viruses. It is recommended to download the latest version of an Anti-Virus program and scan your computer fully even after doing this.

Please Note: If you still feel insecure it is recommended to do a clean reinstall of Windows. After reinstalling, install Microsoft Security Essentials as it is the most trusted anti-virus.

Thank you for reading :)