Need help removing systempre.exe
[I did double post this (see post in breaking news) as this seems like a new name at least. My intention was not to clog the forums, but since google only gave me three hits (two here, one at sdfix, it seemed that this one was new enough to warrant mention as a news item. I will happily nuke the other post if instructed.]
O4 - HKLM\..\Run: [System Presets] systempre.exe
- taskmgr disabled
- msconfig disabled
- regedit disabled
- many websites blocked (including bleeping computer)
- hijackthis prevented from running (runs if renamed)
NOTE: gpedit.msc is not disabled and will run, allowing you to manually throw DISABLE on the taskmanager blocking etc.
On next reboot the DISABLE setting is ignored and must be bounced.
- systempre.exe sitting in WINDOWS\system32\
- <random named exe file> sitting in WINDOWS\system32\ (examples iafxqxs.exe, ygyvosm.exe, vscnnq.exe)
- HKLM\..\Run: [System Presets] systempre.exe
- HKLM\..\Run: [System Presets] <random named file>.exe
SDFix fails to remove as virus reinstates
Andy Manchesta just added mention of this one to SDFix on Aug 18th. http://andymanchesta.com/SDFix_Changelog.htm
His fix of removing from HKLM\...\Run is not sufficient to remove the virus. The virus is also running under a random name and reinstalls/renames itself on each boot and reinstates systempre.exe as well. It seems to have a delayed start. Doing a manual cleanup (remove exes and lines from HKLM\...\run) in safe mode along with running SDFIX to reset the user policies seems to work, but after a few minutes the policies revert to the restricted mode and systempre.exe is back in place.
My next step is to install process manager. All suggestions welcome.