Author Topic: Help Please!  (Read 2079 times)

0 Members and 1 Guest are viewing this topic.

clarkeracer24

  • Guest
Help Please!
« on: September 10, 2008, 05:00:27 PM »
Ok I've never had the pleasure of having a virus on my PC but in my own zoning the other day I clicked on a folder from a download that I shouldn't have and now i'm living in virus hell! Avast is catching a file called byxwnlmm.dll but I can't find any information on it anywhere so I don't know what the virus is called! The file is located at c:\windows\system32\byxwnlmm.dll
I chose for avast to delete it and it comes up several more times before going away but everytime I click on anything to try and perform a function it pops up again with the warning and the delete's all over again. I tried going into safe mode to delete this DLL and search the registry but in safe mode the file is of course not there! ugh. Does anyone have information on this thing?

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89282
  • No support PMs thanks
Re: Help Please!
« Reply #1 on: September 10, 2008, 06:32:16 PM »
The fact that you find no information on it (neither did I) is suspicious in its own right as a legit file, especially a dll would return multiple hits.

This looks like a randomly generated file name, the infection is possibly Vundo though it could be something else and there is another hidden or undetected element that is restoring it.

What was the malware name that avast gave when it is detected ?

Whilst not an issue in this particular case, deletion isn't really a good first option (you have none left), 'first do no harm' don't delete, send virus to the chest and investigate.

If you haven't already got this software (freeware), download, install, update and run it, preferably in safe mode and report the findings (it should product a log file).
1. SUPERantispyware On-Demand only in free version.
2. MalwareBytes Anti-Malware freeware version http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe, right click on the link and select Save As or Save File (As depending on your browser), save it to a location where you can find it easily later. Also Try this tool, RogueRemover, available here http://www.malwarebytes.org/rogueremover.php

The file should still be there in safe mode it it if present in normal mode, but may be hidden.
- Ensure that you have hidden files and folders enabled and disable hide system files in Windows Explorer, Tools, Folder Options, Hidden files and folders, see image.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security