- Set your computer to boot into the safemode with networking. To do this Boot to the Safe Mode with Networking. Click start and then in the run window type "msconfig" now click msconfig and select the Boot Tab. Place a check in the safeboot and a dot in Network. Click apply and clock ok. Now you can restart the computer and it will always boot to the safe mode with networking. Remember to perform this at the end, uncheck safeboot, apply, ok and reboot the computer. Now the computer should boot normally.
- Download and save Rogue Killer 32bit and 64bit, Symantec Poweliks Removal Tool and ESET Poweliks Removal Tool to a Folder On A Flash Drive. Also save Combofix and Free Malwarebytes.
- Once the Computer is in the Safemode Run The Combofix Program. When finished it will give a log file. I save the log file to the Root Drive C: .
- Do Not Reboot The Computer again when combofix is done.
- Run the Rogue Killer and Select All Found and Delete. Do Not Reboot The Computer.
- Run Symantec Poweliks Removal Tool and ESET Poweliks Removal Tools. Save all Log Files.
- Run The Combofix program again and verify that Poweliks is no longer found.
- Reboot the Computer again stay in the Safe Mode with Networking.
- Install Free Malwarbytes, update and run a custom scan. Make sure check for rootkits is selected, check all drive except optical drives and run the scan. It can sometimes run 2 or 3 hours. Choose to delete all quarantined files found.
- Reboot the computer 4 or 5 times in a row, press CTRL, ALT and Del Keys at the same time. Check the Processes to make sure there are no more dllhost.exe files running. NOTE: I have seen a few occasions where a dllhost.exe is running and it is not from the virus. I right click and select file location to determine what program it may be associated with.
- I generally have not had the Poweliks Virus return.
Thank You for reading.
No comments:
Post a Comment