MRfMM – 3. Detailing the System

Full Segment

While the scanners will remove the malware, you will still need to repair any damage in the form of broken home pages and “file not found” errors you may see when restarting your system. Additionally, unwanted extensions, search engines and plugins may still be present.

It’s time to detail your system.

Checking the browsers

 – Chrome

After starting Chrome:

  1. Click on the three horizontal bars in the upper right of Chrome.
  2. Select Settings.
  3. In the upper left, click on Extensions.
  4. Scroll down and review the list of extensions.
  5. If you see an extension you don’t want, click the trash can to the right to remove it. If you don’t want to remove it, uncheck Enabled.
  6. Click on Settings in the upper left.
  7. In the “On Startup” section, select what you want Chrome to do when started. I prefer the New Tab page.
  8. If you want a particular page to be opened, select “Open a specific page” then click “Set Pages”. Enter the links you want opened at startup.
  9. Scroll down to the Search section and click on “Manage search engines”.
  10.  To delete unwanted search engines, place the mouse pointer over the unwanted search engine and click the “X” on the right.
  11. If your favorite search engine is not the default, place your mouse pointer over it and click “Make default”.
  12. Close and restart chrome.

– Firefox

After starting Firefox:

  1. Click on the three horizontal bars in the upper right of Firefox.
  2. Select Add-Ons.
  3. Select Extensions
  4. Review the list of Extensions and click Disable for those you don’t want.
  5. On the left, click Plugins.
  6. Review the list of Plugins and select “Never Activate” in the drop-down box to the right.
  7. Click on the three horizontal bars in the upper right and click on Options.
  8. Click on the General tab in the upper left of the box that appears.
  9. In the “Home Page” section review the current home page. To change it, enter the link for the home page you want. Or select “Restore to Default” to get the Firefox start page.
  10. Click the Search tab at the top.
  11. Select your desired search engine in the drop-down box.
  12. If you see search engines you don’t want, in the list below, click on one and then click Remove. Repeat as necessary.
  13. Click the Advanced tab in the upper right.
  14. Now select the Network tab.
  15. In the Connection section click the Settings button.
  16. Select “No proxy” or “Use system proxy settings”. Note: If you are using manual proxy settings, make certain the settings are the ones you want to be there.
  17. Click Ok to dismiss the Connection Settings box.
  18. Click Ok to dismiss the Options box.
  19. Restart Firefox.

– Internet Explorer

After starting Internet Explorer:

  1. Click the gar icon in the upper right of Internet Explorer.
  2. Select “Internet Options”.
  3. In the “Home Page” section enter the link or links you want opened when IE starts.
  4. Click Ok.
  5. Click on the gear icon in the upper right and select “Manage Add-ons”.
  6. Select “Toolbars and Extensions” in the upper left.
  7. Review the list of toolbars and extensions. If you see one you don’t want then click on it and click Disable.
  8. Click on “Search Providers” in the upper left.
  9. Review the search providers. If you see one you don’t want, click on it and select Remove.
  10. Restart Internet Explorer.

Reviewing the Task Scheduler

The Task Scheduler is used to start programs at certain time or when certain events occur. Such as starting the system or logging in. Malware may have placed tasks here. When the scanning removes the malware, a scheduled malware task entry may be left resulting in “File not found” errors when the system starts.

  1. Go to the Start menu.
  2. In the search box at the bottom, type in “Task Scheduler”.
  3. Click on “Task Scheduler”.
  4. When the window opens, click on “Task Scheduler Library” in the upper left.
  5. Review the list of tasks for PUP related tasks such registry cleaners or strange update tasks.
  6. To delete or disable a task, right-click over it and select the appropriate action. Repeat as ncessary.

If you are unsure of a task, disable it and then restart the system. If you see no error messages and the system appears to be working ok, then you can delete the task.

Examining Services

A Windows service is a program that operates in the background. Malware often installs itself as a service. You manage these programs through the Services interface.

The scanners usually remove unwanted malware services but sometimes they miss something. You need to take care when disabling services. Disabling the wrong services can prevent your system from running correctly or at all.

  1. Go the Start menu and type “services.msc” in the search box at the bottom.
  2. Click on the Services entry.
  3. In the window that appears, click twice on the Status column to sort the list of services by those that are started.
  4. Carefully go down the list and look for services with PUP related names like registry cleaners, driver updaters, or third party downloader programs. Clicking on a service will display what it does. If you are uncertain of something, it is best to leave it alone.
  5. If you find a shady service, select it.
  6. Right-click over it and select Properties.
  7. In the “Startup Type” section, select Disabled.
  8. In the “Service Status”, click on Stop.
  9. Click Ok.
  10. Repeat as necessary for other services.
  11. Exit the window.

Revisiting MSCONFIG

Lastly, review the Startup items in MSCONFIG to make certain that you and the scanners didn’t miss anything.

  1. Go to the Start menu and type msconfig in the search box at the bottom.
  2. Click on msconfig.
  3. Click the Startup tab in the MSCONFIG window.
  4. Review the startup items and uncheck any you don’t want to start.
  5. Click Ok and if required, restart the system.

NOTE: You may want to disable any torrenting startup items. Many people aren’t aware that they start automatically when you start your system. If your internet plan has data caps, disabling torrenting programs may prevent you getting additional charges from serving torrents you weren’t aware of.

< 2. Scanning the System                    4. Scanning the System Part II >