Helping people with computers... one answer at a time.

Tools, techniques, and mechanisms related to detecting malware both before and after it's reached your machine.

Can a virus be transmitted in a picture?

In general, it's very unlikely that a picture would become infected with a virus, but there are related scenarios to be aware of.

Can a virus destroy my computer or hard drive?

A virus attacks the software installed on your machine. Fixing it may take work, but hardware should not need to be replaced due to malware.

How can I stop my anti-virus software from filling up my hard drive with updates?

Anti-virus updates (from well written anti-malware tools) should not be accumulating virus definitions on your hard drive.

How can I tell if my computer is being hacked?

Unfortunately, it's extremely difficult for an average user to tell if a hack is in progress. I'll touch on a few ways and discuss prevention as best.

How can I tell if my computer is infected?

Sometimes it seems obvious, sometimes not, but ultimately there's no way to prove that a computer is not infected. Best we can do is increase the odds.

How did you clean up your friend's infected machine?

A friend brought me his machine infected with several viruses. I'll review the steps I took to clean it up.

How do I fix Windows after removing a virus?

Once you've removed malware from an infected machine it's possible that Windows may suffer lingering side-effects. I'll look at why and what to do.

How do I remove a file that my anti-virus says can't be quarantined?

Anti-virus programs are good at removing more problems, but occasionally they can't. We'll look at approaches to manually dealing with the issue.

How do I remove a virus from a memory card?

Lately memory cards, such as used in digital cameras, have been used as "carriers" of malware. The card is easy to clean. Your system may not be.

How do I remove a virus if it prevents me from download or installing anything?

Some malware go through great lengths to prevent you from downloading, running or trying to apply a fix. I'll look at what you can try.

How do I remove a virus?

Once you've been infected with a virus or other malware, there are steps you can take to try to remove it, but only one approach is guaranteed to work.

How do I remove this error on startup after a virus removal?

Most malware tools can remove most malware fairly well. Occasionally a removal will leave behind startup entries that I'll show you how to clean up.

How do I scan computers at my nuclear power station for viruses without an internet connection?

Scanning your nuclear power station's Windows computers for malware can present some challenges if the machines have been secured properly.

How do I stop my computer from being a zombie?

If your machine is sending lots of email without you knowing it, it may be a zombie. Zombies are preventable, but may be difficult to clean up.

How do I temporarily turn off Microsoft Security Essentials for an install?

Many setup programs ask you to temporarily disable anti-virus tools. I'll show the setting in Microsoft Security Essentials and discuss if you need to.

How do i totally delete a virus on my computer?

Once infected knowing that you've removed a virus totally is theoretically impossible. In reality we most often assume that it can be done anyway.

I have a massive malware infection, should I just get a new machine?

For some reason many people's gut reaction to a malware infestation is to consider a new machine. That's just ... wrong.

I have annoying malware, but my anti-malware tools don't remove it. What do I do?

Every so often malware comes along that the current crop of anti-malware tools don't remove. We'll look at why, and what steps you should take.

I suspect spyware or a worm, how do I get rid of it?

In most cases getting rid of malware involves running up to date scanners for viruses and spyware, and then making sure you're behind a firewall.

Is Microsoft's new Anti-Spyware program any good?

Microsoft's Anti-Spyware (now called Windows Defender) turns out to be a reasonable anti-spyware solution.

Is it safe to install an infected drive into a working machine to clean it?

One approach to disinfecting a drive is to install it into another machine for cleaning. It's common, reasonable even, but there are risks.

Microsoft Standalone System Sweeper - Clean malware from your machine

The Microsoft Standalone System Sweeper is a standalone, bootable tool from Microsoft that allows you to scan for and remove malware in difficult situations.

My anti-virus cleared something off my machine. Should I change my passwords?

When your anti-virus program tells you that it caught something, your next steps depend on what, when and how it was caught. And it depends on prudence.

My computer has a virus infection; how much has been compromised?

Once infected it's often difficult to know what malware has done to a machine. What you do next depends on your concern and some legitimate paranoia.

My computer logs out immediately on login, what do I do?

If you're logged out as soon as you log in to Windows it's likely that your anti-malware tools removed an infection along with your ability to login.

My computer's infected with a virus, how do I clean it up?

Once infected it's difficult to guarantee that your cleaning efforts succeed. Best is to make sure that you never get infected in the first place.

What are (and how do I get rid of) "Antivirus 2010" and "Vista Spyware 2010"?

Antivirus 2010 and similar are malware that tries to fool you into installing viruses or spyware, and then charges you for the promise of removal.

What happens when my anti-malware tool quarantines something?

Anti-malware tools, on identifying malicious software, will "quarantine" it. I'll look at what that means, and if there's any residual threat.

What is "signature scanning"?

"Signatures" are the unique data patterns that malware scanners use to detect viruses as they scan your files or data.

What is a "broken digital signature", and is it a problem? If so, why?

Digital signatures are used to confirm the integrity of things from web sites to software. I'll look at what it means when software signatures "break".

What is msmsger.exe?

Msmsger.exe is, most likely, an imposter. Trying to look like something legitimate, msmsger.exe is probably malware.

When do I actually need to run a virus scan?

There are two types of virus scans: continuous or periodic. Which and how many you need and how often they're needed depends on your situation.

Where can I get a free antivirus for my computer?

There are many free antivirus programs available for your computer. We'll look at some of them, including the one I'm currently evaluating.

Why can't my anti-virus program open certain files?

Depending on how anti-virus programs work, certain files may not be scanned. In some cases that's expected and nothing to worry about.

Why can't this trojan be removed?

Occasionally, malware will infect files that are critical to Windows own operation. Repairing these types of infections can be difficult, at best.

Why do I get "This operation is canceled due to restrictions in effect on this computer"?

'This operation is canceled ...' is an unfortunately common symptom of an all-too-common problem: a virus infection. We'll look at your options.

Why do some programs say to "disable anti-virus" before installing, and should I turn it on again after?

It's not uncommon for setup programs to recommend disabling anti-virus programs first. We'll look at why. But do turn it back on when you're done.

Why won't this "Your Computer Is Infected" warning go away?

If you're getting messages that you computer is infected, it might be. But you MUST be skeptical and extremely careful about the steps you take next.

Will I lose internet access in July?

When a major malware infection was discovered last year, a temporary solution was created on the internet. On July 9th, 2012, it's scheduled to go away.