Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

dllhost.exe / Poweliks


  • This topic is locked This topic is locked
4 replies to this topic

#1 babyfaceb

babyfaceb

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:31 PM

Posted 25 October 2014 - 11:12 PM

Hello,

I have been infected by he Poweliks virus.  I started to clean this myself as I am usually good about keeping core cleaning programs available. Netstat showed the many connections it was making.  I disabled my NIC to atleast stop it from reaching out. I have already ran RogueKiller which found the first registry entry and removed it. After a reboot, I still noticed the dllhost.exe popping up for a few seconds. I already had Malwarebytes which did not find anything.  Downloaded Spybot while researching and the deep scan for rootkits found nothing useful.  I used FRST and found the second Registry key and removed it.  Rebooted and still infected. ComboFix was ran as well but didn't remove it.  That's when I went looking here.

 

I have cleaned many viruses and spyware for family, friends, and co-workers and comfortable with these tools. This type of virus without an actual file is difficult to kill.

 

Here is my FRST log ran after everything I did.  I have the first one that I ran which helped me remove the second registry entry if you would like to see it.

 

Any help will be appreciated.

Brad

Attached Files

  • Attached File  FRST.txt   23.45KB   1 downloads


BC AdBot (Login to Remove)

 


m

#2 babyfaceb

babyfaceb
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:31 PM

Posted 26 October 2014 - 08:44 AM

I ended up doing a system restore to a few days ago but that didn't fix the issue.  Here is a new FRST log.

Attached Files

  • Attached File  FRST.txt   30.99KB   2 downloads


#3 babyfaceb

babyfaceb
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:31 PM

Posted 26 October 2014 - 07:57 PM

Hello all.

I ended up formatting. I had a second hard drive to move files to and I had my DVDs available.  The whole process wasn't too bad.

 

If anyone wants to check the logs and tell me what I missed, I would like to learn.  After removing both registry keys, I thought I had it.



#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 35,534 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:31 PM

Posted 30 October 2014 - 12:55 PM

Thanks for the update and sorry for the delay. Due to the backlog of people waiting for assistance I trust you would understand that since your issue is resolved it would be best to focus on individuals still requiring assistance.

Thanks for your understanding,

Gary
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 35,534 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:31 PM

Posted 30 October 2014 - 12:55 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users