What to do if your computer is already infected with a virus
Please note:
Many virus infections cannot be detected or repaired
from within the affected system while it is running.
The most effective way to remove an infection is to erase (format or "wipe") the entire system drive, and then reinstall and secure your operating system and needed applications.
The most effective way to remove an infection is to erase (format or "wipe") the entire system drive, and then reinstall and secure your operating system and needed applications.
For a more detailed guide: refer to the Safe Computing guide "Securing a Personal Machine", Part Three: Attempt to Repair an Infected Computer.
- Preliminary Steps – To be done on a non-infected computer. NOTE: Do not try to plug an infected computer
into a working Ethernet jack on campus.
- If
your computer does not have Symantec AntiVirus installed on it,
download this at http://www.umn.edu/adcs/software/security/. When you download it, choose the option to
save the file onto your computer.
- Go
to: http://securityresponse.symantec.com/avcenter/download/pages/US-SAVCE.html
to download the latest Intelligent Updater virus definition package. It is the link that ends with ".exe" (for Windows).
- Burn
these two files, the AntiVirus installer and the Intelligent Updater,
onto a CD.
- If
you do not have access to a computer with a CD burner, you can purchase
CD’s with these files at 1-HELP Walk-in
Locations.
- Install Symantec Anti-Virus - NOTE: If your machine has other
antivirus software installed, uninstall it before doing this step by
going to the Control Panel and choosing Add/Remove Programs.
- If
your machine does not have Symantec AntiVirus installed, install it
using the file from step 1.a. Choose the
default options except do not run Live Update. It
will not work if your network connection has been disabled.
- Run
the Intelligent Updater file from step 1.b.
- Turn off System Restore – Windows XP and ME only
- Right
click on My Computer and choose properties.
- Click
on the System Restore tab
- Place
a check mark in the box for “Turn Off System Restore”
- Boot your computer into Safe Mode
- Restart
your computer.
- While
your computer is rebooting, press F8 to bring up a menu of boot options. NOTE: You must press F8 at the moment just
before Windows begins to load. Choose Safe
Mode.
- Scan your computer
- Go
to Start, Programs, Symantec Client Security, Symantec AntiVirus Client.
- Look
on the lower right of the window to confirm that the virus defintion
files are current (they shouldn’t be more than a week old). If the files are not recent, call the 1-HELP Technology
Helpline.
- Choose
Scan, then Scan Computer.
- Select
your local hard drive (usually the C: drive)
- Click the Scan button. NOTE:
this can take a very long time.
- When
Symantec AntiVirus finds an infected file, choose the option to remove
the infection, or quarantine it if removal fails. NOTE:
It may take a day or two for Symantec to release virus definitions
capable of detecting and removing new infections. If
the virus you are infected with is not detected by Symantec AntiVirus,
please call the 1-HELP
Technology Helpline, as we may have manual removal instructions
available.
- Get your connection turned back on
- If
your Internet connection was turned off because of this infection, call
1-HELP and choose option 3 to have your Internet access turned back on.
- It
can take up to two hours for Internet access to be turned back on
depending on how busy the technicians are.
- Protect your computer from future threats
- Follow
the instructions for
protecting (securing) your computer
from future infections.