{"id":1397,"date":"2022-12-10T07:00:00","date_gmt":"2022-12-10T15:00:00","guid":{"rendered":"https:\/\/gmr.dev\/blog\/?p=1397"},"modified":"2023-12-10T15:40:41","modified_gmt":"2023-12-10T23:40:41","slug":"help-ive-been-infected","status":"publish","type":"post","link":"https:\/\/rose.dev\/blog\/2022\/12\/10\/help-ive-been-infected\/","title":{"rendered":"Help! I&#8217;ve been hacked! What do I do?! My PC Has a Virus or is Infected Recovery Guide"},"content":{"rendered":"\n<p>This is a guide for virus removal for Windows PCs. If you have a computer\/computers that you believe have a virus or have been hacked, here are the steps you must take to protect yourself.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Isolate from the internet<\/h2>\n\n\n\n<p>This is the most important step. A lot of functionality is limited if they don&#8217;t have a connection.<\/p>\n\n\n\n<p>Make sure the device you believe has been compromised is disconnected from all forms of connectivity. Bluetooth should be off, airplane mode should be on, Ethernet should be unplugged. WiFi should be turned off, and device should be powered down until ready to perform other necessary recovery steps. This will prevent any malware from getting worse, ransomware from progressing, or hackers from sending remote instructions to your computer. <\/p>\n\n\n\n<p>Additionally, <em>immediately<\/em> boot your computer into Safe Mode (as fast as possible), to prevent malware processes like ransomware from progressing further.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Booting into safe mode (with networking)<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Safe Mode is a diagnostic operating mode, used mainly to troubleshoot problems affecting the normal operation of Windows. Such problems range from conflicting drivers to viruses preventing Windows from starting normally. In Safe Mode, only a few applications work and Windows loads just the basic drivers and a minimum of operating system components. <mark>This is why most viruses are inactive when using Windows in Safe Mode<\/mark>, and they can be easily removed.<\/p>\n<cite>bitdefender.com<\/cite><\/blockquote>\n\n\n\n<h4 class=\"wp-block-heading\">From Settings app<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Press the Windows logo key windows key + I on your keyboard to open Settings. If that doesn\u2019t work, click the Start windows key button in the lower-left corner of your screen, then select Settings Settings icon.<\/li>\n\n\n\n<li>Select Update &amp; security Update and security icon, then click on Recovery Recovery icon.<\/li>\n\n\n\n<li>Under Advanced startup, select Restart now.<\/li>\n\n\n\n<li>After your PC restarts to the Choose an option screen, go to Troubleshoot &gt; Advanced options &gt; Startup Settings &gt; Restart.<\/li>\n\n\n\n<li>After your PC restarts, you\u2019ll see a list of options. Press 4 or F4 to start your PC in Safe Mode. Or if you\u2019ll need to use the Internet, select 5 or F5 for Safe Mode with Networking.<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">From sign in screen<\/h4>\n\n\n\n<p>1. Restart your PC. When you get to the Windows sign-in (login) screen, hold the <strong>Shift<\/strong> key down while you click the&nbsp;<strong>Power&nbsp;<\/strong>&nbsp;icon in the lower-right corner of the screen then select <strong>Restart<\/strong>.<br>2. After your PC restarts to the <strong>Choose an option<\/strong> screen, go to <strong>Troubleshoot<\/strong> &gt; <strong>Advanced options<\/strong> &gt; <strong>Startup Settings<\/strong> &gt; <strong>Restart<\/strong>.<br>3. After your PC restarts, you\u2019ll see a list of options. Press&nbsp;<strong>4<\/strong> or <strong>F4<\/strong> to start your PC in <strong>Safe Mode<\/strong>. Or if you\u2019ll need to use the Internet, select <strong>5<\/strong> or <strong>F5<\/strong> for <strong>Safe Mode<\/strong> with <strong>Networking<\/strong>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">From system configuration<\/h4>\n\n\n\n<p>1. Launch&nbsp;System Configuration&nbsp;in Windows by simultaneously pressing the&nbsp;<strong>Windows<\/strong>&nbsp;<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.bitdefender.com\/media\/uploads\/2017\/07\/windows-key.png\" alt=\"windows key\" width=\"19\" height=\"18\"> + <strong>R&nbsp;<\/strong>keys on your keyboard. Then write&nbsp;<strong>msconfig<\/strong>&nbsp;in the text field and press <strong>OK<\/strong>.<br>2. Switch to&nbsp;<strong>Boot&nbsp;<\/strong>tab and, in the&nbsp;<strong>Boot options&nbsp;<\/strong>section, select the&nbsp;<strong>Safe Boot&nbsp;<\/strong>with<strong>&nbsp;Network.&nbsp;<\/strong>Then click <strong>OK<\/strong>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>If you have an Ethernet cable, plug the computer in directly. <\/p>\n\n\n\n<p><strong><em>NOTE<\/em><\/strong>: After you finished your work in Safe Mode, please open&nbsp;<strong>System Configuration<\/strong>&nbsp;again (step 1) and&nbsp;<strong>uncheck<\/strong>&nbsp;the&nbsp;<strong>Safe Boot&nbsp;<\/strong>option (step 2). Click OK and restart your machine. Your computer will now boot normally.<br><img loading=\"lazy\" decoding=\"async\" width=\"571\" height=\"385\" class=\"wp-image-1501\" style=\"\" src=\"https:\/\/gmr.dev\/blog\/wp-content\/uploads\/2022\/03\/systemconfigurationsafeboot.png\" alt=\"safe mode checkbox system configuration\" srcset=\"https:\/\/rose.dev\/blog\/wp-content\/uploads\/2022\/03\/systemconfigurationsafeboot.png 571w, https:\/\/rose.dev\/blog\/wp-content\/uploads\/2022\/03\/systemconfigurationsafeboot-300x202.png 300w\" sizes=\"auto, (max-width: 571px) 100vw, 571px\" \/><\/p>\n\n\n\n<p>3. Windows will tell you that you need to reboot your computer in order for the new setting to take effect. After the reboot, your computer will automatically boot into&nbsp;<strong>Safe Mode.<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">IMPORTANT: You may not have internet because of drivers and Safe Mode<\/h3>\n\n\n\n<p>Safe Mode doesn&#8217;t load most third party drivers as a precaution. This <em>could<\/em> lead to the scenario where you can&#8217;t access the internet. In this instance, you can use another computer to download the .exe setup file and transfer it with a USB drive. You could even use your phone to download and transfer from your phone with a hard wire. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Use Virus removal tools<\/h2>\n\n\n\n<p><strong><mark>AFTER YOU HAVE REBOOTED INTO SAFE MODE<\/mark><\/strong> I recommend:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Download <a aria-label=\"undefined (opens in a new tab)\" href=\"https:\/\/www.malwarebytes.com\/premium\" target=\"_blank\" rel=\"noreferrer noopener\">Malwarebytes<\/a> FREE, install and run<br>(they will push you to buy the premium version, it is unneeded for our usage) \n<ul class=\"wp-block-list\">\n<li><a href=\"http:\/\/downloads.malwarebytes.com\/file\/mb4_offline\" target=\"_blank\" rel=\"noreferrer noopener\">Here is the offline installer link<\/a><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Download <a aria-label=\"undefined (opens in a new tab)\" href=\"https:\/\/www.malwarebytes.com\/adwcleaner\" target=\"_blank\" rel=\"noreferrer noopener\">AdwCleaner<\/a>, install and run<\/li>\n\n\n\n<li>Download <a aria-label=\"undefined (opens in a new tab)\" href=\"https:\/\/www.sophos.com\/en-us\/products\/free-tools\/virus-removal-tool\" target=\"_blank\" rel=\"noreferrer noopener\">Sophos on demand Scan &amp; Clean<\/a>. If you want a faster download I&#8217;ve mirrored it, but this may be an out of date (3\/9\/2022) version. This is a &#8216;second opinion&#8217; scanner that should be run after Malwarebytes.<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>32 BIT<\/strong><\/td><td><strong>64 BIT<\/strong><\/td><\/tr><tr><td><a href=\"https:\/\/gmr.dev\/blog\/wp-content\/uploads\/2022\/03\/SophosScanAndClean32bit_3.9.2022.zip\" rel=\"nofollow\">DOWNLOAD<\/a><\/td><td><a href=\"https:\/\/gmr.dev\/blog\/wp-content\/uploads\/2022\/03\/SophosScanAndClean_x64_3.9.2022.zip\" rel=\"nofollow\">DOWNLOAD<\/a><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>If you prefer, you can use your own antivirus removal tools. <\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>If you are sure the virus is removed off the device, you can start recovery steps<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">After removing all traces of Malware<\/h2>\n\n\n\n<p>Okay, you&#8217;ve restarted your machine. You&#8217;ve run Malwarebytes. You&#8217;ve run Adwcleaner. You&#8217;ve turned off safe mode and now you&#8217;re back on the desktop. What now?<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Run another virus scan<\/h4>\n\n\n\n<p>Seriously, you want to be 100% sure your device is at ground 0 again, especially after a breach. It&#8217;s better to be safe than sorry. Now that your device is at a &#8220;normal&#8221; state, it&#8217;s best to be sure some sneaky process isn&#8217;t running in the background again somehow. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Change your passwords<\/h4>\n\n\n\n<p>Depending on the type of virus, it may be prudent to update the passwords you use for online sites that are important to you. Especially any financial accounts or important email passwords. Trojans frequently exfiltrate passwords as one of the first actions taken upon an infected system.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Check your files<\/h4>\n\n\n\n<p>Double check that none of your important files were affected. If they were, this is a great reminder to do a backup! Or at least backup the files that are important to you.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Check antivirus settings<\/h4>\n\n\n\n<p>Make sure everything is functioning again and there aren&#8217;t any settings turned off from the attack.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Monitor site logins<\/h4>\n\n\n\n<p>Watch for site logins (via email or sms) over the next few weeks. If you&#8217;ve changed your passwords this shouldn&#8217;t be an issue but you can never be too careful.<\/p>\n<hr>\r\nIt helps me if you share this post\r\n<br\/>\r\n<br\/>\r\nPublished 2022-12-10 07:00:00 ","protected":false},"excerpt":{"rendered":"<p>Make sure the device you believe has been compromised is disconnected from all forms of connectivity. Bluetooth should be off, airplane mode should be on, Ethernet should be unplugged. WiFi should be turned off, and device should be powered down until ready to perform other necessary recovery steps.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"footnotes":""},"categories":[835,832,833],"tags":[1033,1026,1023,1030,1028,1032,1031,1025,1034,1029,1027,838],"class_list":["post-1397","post","type-post","status-publish","format-standard","hentry","category-misc","category-software","category-technology","tag-adwcleaner","tag-guide","tag-help","tag-horse","tag-infected","tag-malwarebytes","tag-passwords","tag-recovery","tag-sophos","tag-trojan","tag-virus","tag-windows"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/rose.dev\/blog\/wp-json\/wp\/v2\/posts\/1397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rose.dev\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rose.dev\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rose.dev\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rose.dev\/blog\/wp-json\/wp\/v2\/comments?post=1397"}],"version-history":[{"count":16,"href":"https:\/\/rose.dev\/blog\/wp-json\/wp\/v2\/posts\/1397\/revisions"}],"predecessor-version":[{"id":2865,"href":"https:\/\/rose.dev\/blog\/wp-json\/wp\/v2\/posts\/1397\/revisions\/2865"}],"wp:attachment":[{"href":"https:\/\/rose.dev\/blog\/wp-json\/wp\/v2\/media?parent=1397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rose.dev\/blog\/wp-json\/wp\/v2\/categories?post=1397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rose.dev\/blog\/wp-json\/wp\/v2\/tags?post=1397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}