Here's a TDSSkiller tutorial:
There are a few things to note about TDSSkiller:
- Under options: Tick Loaded modules restarts the machine and loads a Kaspersky monitor - answer yes if prompted on the restart. This option protects the scanner from malware
- Run TDSSKiller twice
The first time accept the default recommendations - it will clean up known malware, but copy potential malware to quarantine (it won't remove the Potential malware). This allows you to send the file(s) to VirusTotal or another service for inspection. If the service finds the file harmful, you should clean it on the 2nd run. - There is a section on VirusTotal tool which points to another tutorial - you can use that or go directly to the VirusTotal website and upload any suspicious files there.
- You may also accept that TDSSkiller knows what's it's doing and clean all suspicious files, although I can't honestly recommend doing that (I'd rather get a 2nd opinion BEFORE deleting a file).
Once you've completed all malware on-demand scans, run the following to check that system files are intact ... each utiltiy might take soem time to complete. Please report back if any integrity errors are shown on the screen.
Command Prompt (Admin)
Dism /Online /Cleanup-Image /RestoreHealth
SFC /ScanNow
The order I usually run the scanners:
- Full scan using the installed AV product
If you use Windows Defender - run it offline
Settings > Update & security > Defender > Offline - TDSSkiller
- Malwarebytes
- Temp File Cleaner
- AdwCleaner
- JRT
- Hitman Pro (trial)
- ESET Online Scanner
-> This scan takes a long time, many people replace this step with Emsisoft Emergency Kit
Please post the logs if you require assistance.
Particularly difficult malware might require another offline scanner, such as Avast or Bitdefender, but the above list is normally more than sufficient to declare victory.
The entire scanning process should be run in one session so that malware has less of a chance to re-infect. Depending on the work to be performed (clean up), it could take an entire day. You don't have to sit there and watch it, but you shouldn't use the machine while cleansing it. Run the scan, come back and if it's done, start the next one