shamrin
Active Member
- Reaction score
- 48
- Location
- Lexington, Ky
Remember how much fun we had fixing all the instances of the Poweliks virus last autumn? Well, it looks like it's coming back in a new form.
We brought in a customer's computer today that had all the trappings of Poweliks, runaway processes (PresentationHost.exe, Explorer, Notepad, Conhost) that respawn when you kill them even in Safe Mode. All the antivirus scans were clean but it was still hanging around. Alas, the ESET Poweliks remover did not even work for us so we had to figure it out ourselves. Fortunately the hours and hours we spent last year trying to figure it out finally paid off.
The quick version of the fix is that we found the culprit here:
C:\ProgramData\{CA2FACF7-9029-4A21-892B-E7F60B39FF1A}\zipfldr.dll
If you get that folder deleted (and it doesn't' mutate too much) you should be good. That should be enough to get you started, if you want to see a few more details they are here:
We brought in a customer's computer today that had all the trappings of Poweliks, runaway processes (PresentationHost.exe, Explorer, Notepad, Conhost) that respawn when you kill them even in Safe Mode. All the antivirus scans were clean but it was still hanging around. Alas, the ESET Poweliks remover did not even work for us so we had to figure it out ourselves. Fortunately the hours and hours we spent last year trying to figure it out finally paid off.
The quick version of the fix is that we found the culprit here:
C:\ProgramData\{CA2FACF7-9029-4A21-892B-E7F60B39FF1A}\zipfldr.dll
If you get that folder deleted (and it doesn't' mutate too much) you should be good. That should be enough to get you started, if you want to see a few more details they are here: