Daily BITS popup window after restoring WMI won't go away

Sarah91

Honorable
Dec 22, 2013
4
0
10,510
0
After System Mechanic decided to corrupt my WMI, I had to rebuild it with some online program. Ever since, however, I get a daily, usually right after booting up, Command Prompt-window, that downloads some mysterious numbers.exe files - a new one each time. None of them can be googled. Sometimes my Avast! Antivirus informs me it has quarantined an at least similar .exe file afterwards.

Screendump: https://imgur.com/a/T5NI4

I can't find the cause for this! I've scanned with Avast, Malwarebyte's and adwcleaner, where the former comes up short while the other two usually picks up PUP and FileTour files but nothing seems to remedy the issue.

Has anyone ever experienced something similar?

Edit - Updated the title in light of recent events

Thanks in advance.
 

Avast-Team

Respectable
Mar 3, 2017
223
0
2,160
52
It sounds like whatever this malware is, it's re-populating itself. I'd recommend setting up a USB/boot disk with an Avast boot-time scan, pull the computer from the Internet, and scan on boot (at least once) https://support.avast.com/en-us/article/132

Hopefully, this will quarantine the threat once and for all -- it sounds like these are being detected, but that there may be another process happening somewhere that is re-populating it. Do you have Avast running actively (e.g. with real-time behavioral detection, Behavior Shield) or are you just doing on-demand scans?
 

Sarah91

Honorable
Dec 22, 2013
4
0
10,510
0
Thank you for contributing.

All my Avast shields are on, thankfully.

I did try boot time scans, though not, being too lazy, from a usb, two times - one without net access and one without. It didn't work and once I reconnected to the network, the window appeared. I promise I'll try the usb version now though.


 

Sarah91

Honorable
Dec 22, 2013
4
0
10,510
0
Update: Something failed today and thus I believe I located the culprit. I can't find other cases of this liflingren on my computer though - making manual removal somewhat uphill. Perhaps Avast has some ideas? :)

gotcha
 

Sarah91

Honorable
Dec 22, 2013
4
0
10,510
0
Update 2: Just before the download window appears, there's a lightning fast first one. Today I managed to catch it!



Sooo... how can I make this one go away. Is there a better BITS-service out there?
 
Thread starter Similar threads Forum Replies Date
G Antivirus / Security / Privacy 9
K Antivirus / Security / Privacy 5
S Antivirus / Security / Privacy 2
J Antivirus / Security / Privacy 3
Z Antivirus / Security / Privacy 6
F Antivirus / Security / Privacy 3
B Antivirus / Security / Privacy 2
K Antivirus / Security / Privacy 12
R Antivirus / Security / Privacy 7
C Antivirus / Security / Privacy 4
P Antivirus / Security / Privacy 4
N Antivirus / Security / Privacy 9
S Antivirus / Security / Privacy 8
R Antivirus / Security / Privacy 1
M Antivirus / Security / Privacy 1
C Antivirus / Security / Privacy 2
A Antivirus / Security / Privacy 8
F Antivirus / Security / Privacy 2
S Antivirus / Security / Privacy 5
Jamok23 Antivirus / Security / Privacy 3

Similar threads


ASK THE COMMUNITY