First Response Recipe

This page is intended to document steps you can take to clean up a machine that is suspected to be infected.

Windows

Without networking

If possible, checking the system without a network connection prevents any viruses or malware from doing anything "bad" while you're trying to clean it up. The disadvantage is that you can't download any updates first.

Disable the network

  • unplug the network connection

Boot in "Safe Mode"

  • reboot the PC into Windows Safe Mode, by pressing F8 as the machine starts up
  • select "Safe Mode without networking"

run scans in Safe Mode

  • with whatever software is installed (Spybot S&D, Symantec A/V or others), run a scan
  • you won't be able to update at this point, or install new A/V software

With networking

  • reboot the PC into Windows Safe Mode, by pressing F8 as the machine starts up
  • select "Safe Mode with networking"

Linux

Without networking

With networking

Edit | Attach | Watch | Print version | History: r5 | r4 < r3 < r2 < r1 | Backlinks | Raw View | Raw edit | More topic actions...
Topic revision: r1 - 2007-10-22 - LawrenceFolland
 
This site is powered by the TWiki collaboration platform Powered by PerlCopyright © 2008-2025 by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback