Virus and malware removal
Cleaning infected machines, checking what was taken, and closing the way it got in.
Removing the malicious program is the easy part. The harder question is what reached your passwords and your mail, because an infection usually continues through accounts rather than through the machine you just cleaned.
How it usually starts
The browser opens pages you did not ask for, the home page has changed, and friends tell you they are getting messages with a link from your address. Or one morning your files have an unfamiliar extension and every folder has a text file with payment instructions. Those are two very different cases and they are not handled in the same order.
What we do
The infected computer comes off the network first. Then we boot it from clean media and scan the disk from outside, because active malware can hide from tools launched inside the same system. After that we go through the places where an infection usually digs in:
- scheduled tasks and startup entries
- extensions in every browser, not only the one you use
- forwarding rules in your mailbox, through which an attacker keeps reading your mail
- active sign-ins to your Google and Microsoft accounts from unknown devices
- passwords saved and synced in the browser
Passwords are changed from a clean device, email first, because everything else gets reset through it, then the bank and the remaining accounts. Wherever possible we switch on two factor authentication, preferably with an authenticator app rather than SMS.
When the files are encrypted
With ransomware, cleaning the computer does not bring the files back. First we check whether there is a backup that was not connected to the machine at the time of the attack, and whether a public decryption tool exists for that strain, which has happened for some older families. We do not recommend paying: it does not guarantee a key, and it shows the attacker you are worth coming back to.
If a business is hit, the attack should be reported to the competent CERT, and if customers' personal data is affected, to the Croatian data protection authority as well.
Common questions
Isn't running an antivirus enough?
For adware, sometimes. For anything more serious, no, because an antivirus launched from an infected system only sees what the malware lets it see.
Should Windows be reinstalled straight away?
Not always. If the infection can be removed reliably, cleaning is enough. If it is a rootkit, or we cannot confirm the system is clean, we recommend a clean install with your data carried over.
How much does a cleanup cost?
It depends on the type of infection and how many devices and accounts need checking. After the first look we know what we are dealing with and give you a quote.