Virus & Malware Removal Procedure
Procedure: SP-005 | Version: 2.2 | Last Updated: 20 April 2025 | Owner: Marcus Chen
Isolation First: Before connecting any suspect device to any network, ensure it's bootable and assess the infection severity. Ransomware may encrypt network shares if connected.
Step 1: Assessment
- Ask the customer about symptoms: pop-ups, slow performance, unknown programs, browser redirects, ransom notes
- Note the infection type if known (virus, trojan, ransomware, spyware, adware, PUP)
- Check if the customer has any antivirus installed and what state it's in
- Boot into Safe Mode (F8 or via Settings → Recovery) to assess
Step 2: Boot from Diagnostic USB
For severe infections, boot from the KangaByte Diagnostic USB (Hiren's BootCD PE):
- Insert the diagnostic USB drive
- Enter BIOS (Del/F2) and set USB as first boot device
- Boot into Hiren's PE environment
- Run preliminary scans from the live environment
Step 3: Malware Removal — Tool Sequence
Run these tools in order on the infected system (in Safe Mode with Networking where possible):
| # | Tool | Purpose | Notes |
|---|---|---|---|
| 1 | RKill | Terminate known malware processes | Run first — disables malware that blocks other tools |
| 2 | Malwarebytes (Free trial) | Full system scan | Quarantine all detections; restart if prompted |
| 3 | AdwCleaner | Adware & PUP removal | Focuses on browser hijackers and unwanted programs |
| 4 | HitmanPro | Second-opinion cloud scanner | Good for catching things Malwarebytes missed |
| 5 | ESET Online Scanner | Deep scan | Thorough scan — may take 1-2 hours |
| 6 | TDSSKiller | Rootkit detection | Run if rootkit infection is suspected |
Step 4: Browser Cleanup
- Reset all browsers to default settings
- Remove all unknown extensions and add-ons
- Clear browsing data, cache, and cookies
- Verify the homepage and default search engine are correct
- Check browser shortcuts for appended URLs
Step 5: System Cleanup
- Run
disk cleanupto remove temporary files - Check Startup items (Task Manager → Startup) — disable unknown entries
- Check Services (
services.msc) — look for suspicious services - Verify Windows Defender is enabled and up to date
- Run
sfc /scannowandDISM /Online /Cleanup-Image /RestoreHealth - Check installed programs — uninstall anything unfamiliar
- Verify Windows Update is current
Step 6: Verification
- Reboot normally (not Safe Mode)
- Run a final Malwarebytes scan — should come back clean
- Test internet connectivity and browser functionality
- Verify no pop-ups or redirects occur
- Check Task Manager for unusual CPU/memory usage
- Confirm the system is stable for 15+ minutes under normal use
Step 7: Prevention Recommendations
- Install Malwarebytes (recommend premium trial, then advise on subscription)
- Ensure Windows Defender real-time protection is ON
- Recommend a backup solution (external drive or cloud backup)
- Educate the customer on safe browsing habits:
- Don't click on suspicious links or email attachments
- Only download software from official sources
- Keep the system and browser updated
- Use an ad blocker (uBlock Origin)
Special Cases — Ransomware
- Do NOT pay the ransom — ever
- Check nomoreransom.org for known decryptors
- Document the ransomware variant (note file extensions, ransom note text)
- If data is critical and no decryptor exists, discuss options with the customer
- Report to the ACSC (Australian Cyber Security Centre): 1300 292 939
Time Estimate: Standard malware removal takes 1–3 hours. Severe infections or ransomware may require extended time or a reinstall. Always communicate realistic timeframes to the customer.
