Ask Leo! by Leo A. Notenboom

My computer's infected with a virus, how do I clean it up?

Search First! Then browse: Categories | Full Archive | By Date | Newsletter

Home » Viruses and Malware » Malware Detection

Summary: Once infected it's difficult to guarantee that your cleaning efforts succeed. Best is to make sure that you never get infected in the first place.

As a Mom of a couple teens, I get viruses all of the time. This latest one I cannot find a solution to; here goes - my control panel is GONE! There is a popup every time I start the 'puter with the filename of "mustafx2.exe" I can't find it anywhere in English. I am using AVG, Ad Aware and Spy-Bot as well as Windows Defender. I have Windows XP version - never mind; can't look that up anymore either....UGH! Nothing has helped. Got any clues?

I have a couple of reactions to this question.

One, of course, will be the steps I'd take to try and recover in this case. I'll outline those in a second.

But first, my other reaction, which you may not like Smile.

"... I get viruses all of the time."

This is unacceptable.

In my opinion you must change that mindset. Getting a virus, any virus, should be considered a very serious thing. Your teens, or whomever is using your computer in such a way as to get infected by these viruses, must learn to use the computer safely and properly.

There's simply no substitute for that.

If this is a computer you share with your teens, I'd be doubly concerned. In fact, in your shoes I'd be barring their access ... letting them allow your machine to become infected with viruses is putting everything on your computer at risk. You could lose everything stored on your computer.

"The only way to absolutely, positively clean a machine from a virus is to completely reformat the machine and reinstall the operating system, updates, applications and data from scratch."

So why am I so passionate about this?

It's simple really: consider the possibilities after you're infected with a virus:

  1. Your anti-virus program successfully cleans it off.

  2. Your anti-virus program thinks it successfully cleans it off, but in fact the virus has hidden itself so well that it remains. You're still infected, and you don't know it.

  3. Your anti-virus program doesn't catch it and doesn't even try to clean it off. You're still infected, and you don't know it.

  4. Your anti-virus program fails to clean it off and tells you. You're still infected, but at least you know.

Because we trust that #1 will happen all the time, it's easy to become complacent. It's easy to assume that viruses are a fact of (teenage?) life, and that we can just clean them up after they happen.

That's just not true. A lot of malware can't be so simply swept away.

The only way to absolutely, positively clean a machine from a virus is to completely reformat the machine and reinstall the operating system, updates, applications and data from scratch.

Re-read that sentence. It's important and absolutely true.

Most of the time we don't do that. We assume, we hope, that the anti-malware software we have running will clean things up for us. But there's actually no way to know for sure.

Each time we allow an infection to happen, each time we then use anti-malware software to clean off an infection, we're gambling. Most of the time, we're ok. But sometimes we're not. (I do have to mention that finding a virus on your machine and finding a virus installed on your machine are two different things. Anti-virus programs will report both, but it's the later case that is the problem scenario.)

Rant over.

Let's look at your situation.

As you can guess by now the only guaranteed way to rid yourself of this malware is to reformat your machine and reinstall everything. That's very painful and something I know that most people would want to avoid, including me.

So here are steps I would try first:

  • Backup your system. Yes, we're backing up the infected system, but in case subsequent attempts go horribly wrong we'll always then have this backup to revert to as we attempt other approaches to recovery.

  • Run the System File Checker. Many viruses operate by replacing system components - the System File Checker will attempt to restore them. Make sure to have your original Windows installation CD ready, as SFC will typically ask for it if it finds it needs to restore files.

  • Perform a repair install of Windows. This works very much like an full install, replacing and updating system files and other components, but it attempts to preserve all data and installed programs in the process.

If those don't work ... well, by now you know what's next.

Once your machine is clean, I'm going to strongly recommend you implement a frequent backup regimen. Daily would be nice, making sure that you save each day's information so that if necessary you can revert to a backup from "x days ago".

The reason I say this is that as much as we might want to make sure that your teens never, ever allow your machine to get infected again (and that should absolutely be the goal), the practical reality is that it ain't gonna happen. At least not right away.

With a sequence of daily backups, if you do get infected again you could simply restore the machine to the most recent backup prior to the infection. Yep, you'll lose any changes made after that backup, but my guess is that'll be a lot less painful than a full reinstall.

And it might even act as an incentive to avoid infections in the future.

Article C3263 - January 10, 2008

Was this article helpful? «Yes» «No»

Recent Comments
34 Comments

What are some of the symptoms of an infected computer please. What am I looking for?

Thanks,

Jackie

Posted by: Jackie at February 6, 2010 11:29 PM

my computer affected by virus.when i open my computer there is a message coming."there is no disk in the drive.please insert a disk into drive"then there is three buttons ie,cancel,tryagain,continue.i press both this is not closing.i make to restart the computer.i try to open task manager.ii can not open.please give me a reply what i do.

Posted by: kumar at February 9, 2010 11:45 PM

my computer had been affected by khatra virus, i used protector plus to remove it.after this i an not able to open taskmanager,realplayer and certain websites and my comp is too slow,what is the problem??im using intel hp atom

Posted by: fahath at March 3, 2010 10:06 PM

Hi! I just wanted to ask if you know anything about the virus: "XP antispyware 2010", please? It installed itself on my computer yesterday and I think I have got rid of it as it doesn't pop up any more trying to get me to subscribe to their company, but although I am using the internet normally again, it is still quite slow, although that could be the Superantispyware I installed..? Anyway please could you tell me if you know whether the virus can get into my personal information ie. my paypal account and should I avoid using it and putting in my password till I know for a fact that it's gone? Thank you very much for your help, Clara

Once your machine is known to be infected you should never do anything potentially sensitive with it. Two recommendations: malwarebytes.org and then also How do I remove a virus?.
Leo
08-Mar-2010

Posted by: Clara at March 6, 2010 1:31 PM

my computer keeps saying its not responding, like in internet explorer and when im under a program... whats wrong with it?

Posted by: Jessica at March 14, 2010 10:14 AM

Post a comment on "My computer's infected with a virus, how do I clean it up?":



(Name will be included when your comment is published.)



(Email Address will not be published.)

Remember Me?

By popular demand...
my tip jar
Cuppa Joe
Buy Leo a Latte!

(you may use HTML tags for style)

RSS feed Subscribe to the RSS Feed specifically for comments on this article.

Before commenting, please...

  • Read the article at the top of this page. If your comment shows you didn't, it'll be deleted and ignored.

  • Comment only on this article. Use the Google search box at the top of the page if you have a question about something else.

  • Don't include personal information in the comment. No email addresses. No phone numbers. No physical addresses.

  • Don't spam. Excessive links to unrelated sites within a comment or across multiple comments will cause all such comments to be removed.

  • Don't ask me to recover lost passwords or hacked accounts. I can't, and those comments will be deleted.

  • I can't respond to every comment. And I can't vouch for the accuracy of others who do.

Please wait. Your comment is being processed ...




Question? Ask Leo!