Nasty unknown virus!

You need to run Regedit from Run (windows key + R) then find it in the software part and end it then end the exe from task manager.
 
Last edited:
Right, this thing sucks.

First off, run combofix: http://www.bleepingcomputer.com/download/combofix/
You might need to run it from safe mode but it will kill the system recovery virus.

Then this: http://www.bleepingcomputer.com/download/unhide/.
This will make your files reappear.

You aren't finished yet!
It's probably part of a rootkit, so run this: http://support.kaspersky.com/downloads/utils/tdsskiller.exe
(I couldn't get this to run, so I had to use a kernel editor to delete a load of callback functions first - ask me if you can't get it to run!).

If it found and removed a rootkit you now need to run a virus scan like Malwarebytes - it will find a ton of viruses it didn't find before.
Good luck!

Edit: Looking at your video again it looks identical to the one I had, so the steps above should work perfectly. Don't miss out the rootkit removal step, you probably have a few other amusing viruses like google redirects that won't be picked up by your antivirus until tdsskiller removes the rootkit!
 
Last edited:
Surely the problem is that system repair is installed?

System repair is Malware that fakes a totally trashed system, check google for how to remove it.

AD
 
Surely the problem is that system repair is installed?

System repair is Malware that fakes a totally trashed system, check google for how to remove it.

AD

Was actually just thinking the same thing. the .exe is usually found under the users profile.
 
Should have made a complete image before doing so, and run the image on a VM and seeing what methods of removal worked.

The thought did cross my mind, but as I'm delegated to a ridiculous amount of tasks in this job role, I didn't have chance :( I do everything from internal IT, to Office 365 consultancy, account management, tech support and handset repairs and loan tracking! :c
 
Back
Top Bottom