Need help removing malware

Associate
Joined
16 Dec 2008
Posts
1,091
Somehow I have managed to get a virus on my PC for the first time in atleast a decade so i'm a little rusty on how to go about removing it wthout reformatting.

I'm not entirely sure how I got it although I suspect it was through a link to what I thought to be a legit website, so possbly adverts or something. Anyway a few seconds after I clicked the link avg free 2012 popped up saying a trojan horse of some variety had been detected and so i moved it to the virus vault, updated AVG and began a scan. 2 minutes into the scan firefox closes and some windows lookalike error message pops up 20 times saying my HDD has bad sectors and I need to do some form of scan plus a load of other BS.

So I've unplugged the internet, done a restart and found a startup process called byxmuyduwsvn.exe located in C:/programdata through msconfig that seems to be the malware. A load of other stuff happended as well like setting all desktop items / C:/users / C:/programdata etc to hidden, screwing up the start menu and auto closing task manager amongst others. I disabled it through msconfig and sorted some stuff out after rebooting so I'm back in control apart from annoying things like no start menu so have to do everything through run/search and a black desktop.

I'm just about to run malwarebites in safe mode but is there anythng else would need to do except that then restoring everything from windows backup if malwarebites takescare of it? I'm unsure if anythng else managed to sneak in and how extensively I'd need to clean everything if this isn't enough to deal wth all possible threats. My backup is on my external HDD which was connected at the time but nothing appears to of infected it.

Also does anyone have any ideas what this is as I couldn't find anything with a quick google search.
 
Run Malwarebytes, Combofix and Trend Micro Househall. Kaspersky also have some free malware removal tools on their website. May as well do a full AVG scan as well. Run these to remove all the viruses. Then keep running them until the scans comes up clean for each.

Once you have removed all viruses then run unhide.exe. This will bring back your start menu and desktop items.

This will work for the majority of viruses however if you have Ramnit virus then you might have to format and start again. This is notoriously difficult to get rid of :(

Protip: Combofix uses system restore so it will need to be enabled to run this. Disable System restore before running anything else as sometimes viruses store themselves here and then restore themselves on bootup.
 
Last edited:
Yep the Kaspersky tool is worth running and only takes a moment - http://support.kaspersky.com/faq/?qid=208283363.

Sometimes it will be a virus on the boot block of the HD, which means no matter what you do within Windows it will keep coming back. The only way to check this is to scan the disk via another computer (i.e just temporarily slave it into another PC). I would suggest with something like NOD32 or Kaspersky.
 
Back
Top Bottom