• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

So, my user got a new virus/malware and hosed her PC

Oyeve

Lifer
User was getting many popups on her screen. Normal looking virus/malware/trojan thing. But, I couldnt fix it. I ended up swapping PCs and DFS profile kicked in so all was good. In her local settings there were a few hundred new folders of all varying names and such. NPE found nothing. I noticed several services running as batyyxd.exe and I could kill them but they kept popping up using 2gb of memory. The file is in local settings and could be deleted but just comes back again. Googling batyyxd.exe and the folder name udweinxa where that file is located yields no results.

All my users are locked down but I am concerned as I could find nothing on the web with those folder and file names.
 
if your user is just a user, not an admin, i don't see why you need to do anything more than delete the user profile, all their files, and create new one

Thats what I did but it was still on her old PC. Shes fine with the spare but I just want to mess with her old fubared PC.
 
Sometimes I am able to remove viruses manually and I use StartupCPL to stop the process or find it's location. If you install StartupCPL it will be found in the control panel.
 
Those look to be randomly generated names. This is probably why you aren't finding anything for them. As others have mentioned, use an offline tool and roguekiller. Or better yet, wipe and reinstall. Sounds like what ever virus scanner you are using is missing the loader and it is just downloading new malware right after you remove it.
 
Obvious randomly generated application and folder name is obvious. That's why you didn't find any specific references to the directory and executable names online. Use KAV rescue disk and do an offline scan.
 
Kaspersky Rescue Disc works well. Good offline scanner.

This. I had a coworker that had something on his laptop that several other scanners wouldn't find (bitdefender, AVG, trend housecall online, malwarebytes, superantispyware). Kaspersky found 5 active viruses and removed them. Problem (so far) solved.
 
Back
Top