- Aug 30, 2012
- 6,598
Using the Trend Micro Anti-Threat Toolkit to analyze malware issues and clean infections - For Home and Home Office users
Learn how to use the Trend Micro Anti-Threat Toolkit (ATTK) to perform system forensic scans and clean the following infections:
To use the Trend Micro Anti-Threat Toolkit (ATTK) with Clean Boot, follow the steps below:
Clean ZBot Or Cryptolocker Infection Using ATTK
Learn how to use the Trend Micro Anti-Threat Toolkit (ATTK) to perform system forensic scans and clean the following infections:
- General malware infection
- Master boot record Infection
- CIDOX/ RODNIX infection
- Rootkit infection
- Zbot infection
- Cryptolocker infection
- Download the Anti-Threat Toolkit by clicking your operating system version below:
- Read the Trend Micro License Agreement. Once you click I Accept, the download will start.
- Choose the preferred directory where the tool will be stored then click Save.
- Log on to the computer that is possibly infected by a malware. Copy the Anti-Threat Toolkit into the infected computer.
- After copying the Anti-Threat Toolkit, right-click the tool and then click Run as administrator.
- Click Yes when the User Account Control window appears.
A Command Prompt window will appear to show the system forensic analysis progress.
A browser window will appear after the analysis finishes. - Click Proceedto send the information the tool collected to Trend Micro Technical Support. You will receive a temporary ID number that you can use when you contact Trend Micro Technical Support.
The Trend Micro Anti-Threat Toolkit folder will appear on the same folder where you ran the tool. - Go to Trend Micro Anti-Threat Toolkit folder > Output.
You will find a .ZIP file with the filename containing the timestamp and GUID.
- Do either of the following:
- If you have an existing case, send a copy of the .ZIP file together with the temporary ID number to the engineer who is handling your case.
- If you do not have an existing case, send the .ZIP file to Trend Micro Consumer Support for analysis.
- Download the Anti-Threat Toolkit:
- For computers with internet connection
- For computers without internet connection
- Read the Trend Micro License Agreement, then click I Accept to agree with the EULA and download the tool.
- Click Save when the File Download window appears.
- Select Desktop as the download location, then click Save.
- Log on to the computer that is possibly infected by a malware. Copy the Anti-Threat Toolkit into the infected computer.
- After copying the Anti-Threat Toolkit, right-click the tool and then click Run as administrator.
- Click Yes when the User Account Control window appears.
- Click Scan Nowwhen the Trend Micro Anti-Threat Toolkit window appears.
The scan may take some time. The tool will scan your computer and list the threats it finds.
- The tool will show a summary of the scan. Click Fix Now to clean your computer.
- Click Close to close the Anti-Threat Toolkit after your computer has been cleaned.
- Click Proceed to send the information the tool collected to Trend Micro Technical Support.
You will receive a temporary ID number that you can use when you contact Trend Micro Technical Support and a Trend Micro Anti-Threat Toolkit folder will appear on the same folder where you ran the tool. - Go to Trend Micro Anti-Threat Toolkit folder > Output.
You will find a .ZIP file with the filename containing the timestamp and GUID.
- Do either of the following if you still need help after you have cleaned your computer:
- If you have an existing case, send the .ZIP file together with the temporary ID number to the engineer who is handling your case.
- If you do not have an existing case, send the .ZIP file to Trend Micro Consumer Support for analysis.
To use the Trend Micro Anti-Threat Toolkit (ATTK) with Clean Boot, follow the steps below:
- Download the Anti-Threat Toolkit by clicking your operating system type below:Notes:
- To check your system type, refer to this Knowledge Base article: Check if you are running a 32-bit or 64-bit version of Windows operating system
- Due to the file's large size, it may take a while to download, depending on the speed of your Internet connection.
- Read the License Agreement, then click I Agree.
- A download will be initiated, run the downloaded tool to start using it.
- Once the tool is open, click on Scan Now to check the computer for threats.
- After the scan, detected threats should be displayed. Click on Fix Now to begin with the clean-up process.
Some threats require a special tool such as Clean Boot. If you get this option just click on Clean Boot to continue.
- Click OK to confirm the installation of Clean Boot.
- Click OK to restart the computer.
- After the computer restarts, the computer will now start with Clean Boot. On the boot manager, press enter on Trend Micro Clean Boot.
On the next screen, you will get the Startup and initialization screen.
Once the tool has been successfully initialized, the Quick scan will automatically trigger.
- After the scan, the computer needs to be restarted. On the boot menu, select on your operating system then press enter.
- After loading the operating system, ATTK will automatically run and display the results of the scan
Clean ZBot Or Cryptolocker Infection Using ATTK
- Click any of the links below to download the tool:
- Read the Trend Micro License Agreement, then click I Accept to agree with the EULA and download the tool.
- Click Save when the File Download window appears.
- Select Desktop as the download location, then click Save.
- Once the download completes, right-click the tool, then click Run as administrator.
- Click Yes when the User Account Control window appears.
- Click Scan Now when the Trend Micro Anti-Threat Toolkit window appears.
The scan may take some time. The tool will scan your computer and list the threats it finds.
- The tool will show a summary of the scan. Click Fix Now to clean your computer.
- Click Close to close the Anti-Threat Toolkit after your computer has been cleaned.