Virus & Malware Removal Procedure

Procedure: SP-005  |  Version: 2.2  |  Last Updated: 20 April 2025  |  Owner: Marcus Chen

Isolation First: Before connecting any suspect device to any network, ensure it's bootable and assess the infection severity. Ransomware may encrypt network shares if connected.

Step 1: Assessment

  • Ask the customer about symptoms: pop-ups, slow performance, unknown programs, browser redirects, ransom notes
  • Note the infection type if known (virus, trojan, ransomware, spyware, adware, PUP)
  • Check if the customer has any antivirus installed and what state it's in
  • Boot into Safe Mode (F8 or via Settings → Recovery) to assess

Step 2: Boot from Diagnostic USB

For severe infections, boot from the KangaByte Diagnostic USB (Hiren's BootCD PE):

  1. Insert the diagnostic USB drive
  2. Enter BIOS (Del/F2) and set USB as first boot device
  3. Boot into Hiren's PE environment
  4. Run preliminary scans from the live environment

Step 3: Malware Removal — Tool Sequence

Run these tools in order on the infected system (in Safe Mode with Networking where possible):

#ToolPurposeNotes
1RKillTerminate known malware processesRun first — disables malware that blocks other tools
2Malwarebytes (Free trial)Full system scanQuarantine all detections; restart if prompted
3AdwCleanerAdware & PUP removalFocuses on browser hijackers and unwanted programs
4HitmanProSecond-opinion cloud scannerGood for catching things Malwarebytes missed
5ESET Online ScannerDeep scanThorough scan — may take 1-2 hours
6TDSSKillerRootkit detectionRun if rootkit infection is suspected

Step 4: Browser Cleanup

  • Reset all browsers to default settings
  • Remove all unknown extensions and add-ons
  • Clear browsing data, cache, and cookies
  • Verify the homepage and default search engine are correct
  • Check browser shortcuts for appended URLs

Step 5: System Cleanup

  1. Run disk cleanup to remove temporary files
  2. Check Startup items (Task Manager → Startup) — disable unknown entries
  3. Check Services (services.msc) — look for suspicious services
  4. Verify Windows Defender is enabled and up to date
  5. Run sfc /scannow and DISM /Online /Cleanup-Image /RestoreHealth
  6. Check installed programs — uninstall anything unfamiliar
  7. Verify Windows Update is current

Step 6: Verification

  • Reboot normally (not Safe Mode)
  • Run a final Malwarebytes scan — should come back clean
  • Test internet connectivity and browser functionality
  • Verify no pop-ups or redirects occur
  • Check Task Manager for unusual CPU/memory usage
  • Confirm the system is stable for 15+ minutes under normal use

Step 7: Prevention Recommendations

  • Install Malwarebytes (recommend premium trial, then advise on subscription)
  • Ensure Windows Defender real-time protection is ON
  • Recommend a backup solution (external drive or cloud backup)
  • Educate the customer on safe browsing habits:
    • Don't click on suspicious links or email attachments
    • Only download software from official sources
    • Keep the system and browser updated
    • Use an ad blocker (uBlock Origin)

Special Cases — Ransomware

  • Do NOT pay the ransom — ever
  • Check nomoreransom.org for known decryptors
  • Document the ransomware variant (note file extensions, ransom note text)
  • If data is critical and no decryptor exists, discuss options with the customer
  • Report to the ACSC (Australian Cyber Security Centre): 1300 292 939
Time Estimate: Standard malware removal takes 1–3 hours. Severe infections or ransomware may require extended time or a reinstall. Always communicate realistic timeframes to the customer.