0

I wasn't paying attention when downloading some apps today and have successfully installed some malware on my PC.

I had Safefinder installed and I am currently removing its components and running Spybot and Malwarebytes to clean up.

Part of Safefinders issues was that it disabled Windows Defender via group policy, I removed the registry key value that set this and it appears to be working again.

The issue I have is that there is an application now installed that I do not recognise and can't identify, it's in Chinese, screenshot below. Though from the icons I assume it's some kind of system clean up/network monitoring tool.

So I have three questions.

  1. Is the disabling of Windows Defender by Safefinder standard behaviour of this malware or is this another issue alongside it?

  2. What is the second piece of software and how do I get rid of it? I can't see it in the list of installed programs. Is there a hidden file perhaps?

  3. What further steps should I look at to completely remove malware, registry key changes etc.

All help much appreciated and yes, I know I should be more careful!

enter image description here

enter image description here

3therk1ll
  • 149
  • 1
  • 1
  • 11
  • 5
    The only real option is to [nuke from orbit](https://security.stackexchange.com/questions/39231/how-do-i-deal-with-a-compromised-server/39232#39232). IMO, this seems even more necessary after hearing that the malware messed with group policy. Just wipe and reinstall – Neil Smithline May 22 '16 at 22:41

1 Answers1

0

The programme in the screenshots was called Tencent. I found a file location in its options, dug around and got and got the name from there.

I had to reboot in safe mode, to kill the processes as it restarts itself automatically, then uninstall the application, delete the files and remove the app data.

Followed this video guide.

Tencent Removal Guide

The following files all came bundled with this pain in the ass.

  1. QMDownload
  2. Tencent
  3. Qiimu
  4. TuneUp Software
  5. Easy Hotspot
  6. Sound+

enter image description here

3therk1ll
  • 149
  • 1
  • 1
  • 11