My PC was brutally attacked by avsystemcare malicious software which advanced into mezzia trojan's and vundo...'s. I've managed to take all the steps to getting rid of eveything....or so it seemed. The second i think it is cleaned up...it appears again in the registry. I have reinstalled windows as a frustration end but it's back. Please help before i jump. It's a relatively new PC, it's worth the pain. Thanks

Dani AI

Generated

Persistent reinfection of the kind describes usually means something outside the normal AV scan is re-introducing the malware. and called out two important vectors: hidden restore points and an install that didn’t wipe the disk. Below are focused, practical actions that expand on those points without repeating earlier posts.

A clean offline scan is essential. Use a known-good rescue/live environment (Kaspersky, ESET, Bitdefender rescue media) to boot the machine and run full scans and rootkit checks before mounting the infected Windows install. After that, use a startup/driver examiner to find stubborn entries and scheduled tasks; Autoruns from Sysinternals is the tool to review and remove persistent autostart locations safely.

When updates are blocked, common non-obvious causes include a poisoned HOSTS file, a rogue proxy, or corrupted network stacks. Verify the HOSTS file at C:\Windows\System32\drivers\etc\hosts for unexpected entries, check LAN/proxy settings in Internet options, and reset networking components. Example commands that help clear networking issues:

netsh winsock reset
netsh int ip reset
ipconfig /flushdns

Follow those scans with an on-demand Windows scanner such as the Microsoft Safety Scanner and a current copy of Malwarebytes to catch PUPs and leftovers.

If persistence remains after offline scans and cleaning, a full disk wipe and reinstall from verified media is the reliable cure: format the system drive, reinstall, and scan any user backups offline before restoring files. Also audit removable drives and local router/DNS settings (malware can redirect update servers). If uncertain about MBR/rootkit work, professional support is recommended rather than guessing recovery commands.

Recommended Answers

All 5 Replies

Did you turn off system restore while you were doing all the removal etc. If not then ther is a real chance that a lot of it will return a the next reboot!
Turn off system restore and then clean up then reboot and then reclean and then turn on system restore!
Best of luck

I did the system restore instructions and then rescanned and removed ect... Looks like it worked, however....theres always a however, i can't get any updates, like windows defender, norton or even windows updates. Any help there?

P.S. I did not format the hard drive for reinstallation of windows.

negative, you may just have to reconfigure manually each one!
M


P.S. I did not format the hard drive for reinstallation of windows.

Doing a reinstall that way only replace missing window system file and will do nothing to get rid of viruses .

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.