Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Earth Bound Misfit

(3,556 posts)
4. No quick fix, sorry.
Sat Nov 15, 2014, 05:24 PM
Nov 2014

MBAM is a teriffic program (I install it on every one of my machines & recommend it highly) but it alone cannot completely remove this malware. Poweliks is a malware with rootkit-like features, it resides in the registry (loads in memory) is persistent and is not present as a file which can be scanned & removed easily. The payload (malware file) is stored in an encrypted registry value and is loaded at boot time by a RUN key calling rundll32 process with an encrypted javascript payload. It has been seen to reside in (at least) these 2 keys:

HKCU\software\microsoft\windows\currentversion\run\(default)
HKEY_LOCAL_MACHINE\Software\classes\clsid\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\LocalServer32

Once the payload is loaded, it tries to execute an embedded powershell script in "interactive" (silent) mode. That powershell scripts contains another encoded payload which will be injected into a (legitimate) dllhost process (the persistent item), which acts as a trojan downloader for other malware& is also responsible for protecting the registry value by recreating it when removed.

RogueKiller (by French malware analyst Tigzy) claims to be able to remove Poweliks as does ESET Poweliks Cleaner & Malwarebytes Anti Rootkit Beta, links below.

http://www.adlice.com/poweliks-removal-with-roguekiller/
http://kb.eset.com/esetkb/index?page=content&id=SOLN3587
https://blog.malwarebytes.org/security-threat/2014/11/no-more-poweliks/

Me? I'd restore from backup if available or re-install the OS, YMMV.

Some interesting analyses:
https://blog.gdatasoftware.com/blog/article/poweliks-the-persistent-malware-without-a-file.html
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=3377

Anyone have a quick fix to remove poweliks? [View all] Baitball Blogger Nov 2014 OP
Did you try Malwarebytes? MannyGoldstein Nov 2014 #1
I'll give it a shot. Thanks! Baitball Blogger Nov 2014 #2
the virus may be blocking it. hobbit709 Nov 2014 #3
No quick fix, sorry. Earth Bound Misfit Nov 2014 #4
This is what I was experiencing. Baitball Blogger Nov 2014 #5
I would. Earth Bound Misfit Nov 2014 #6
I did the usual things. Baitball Blogger Nov 2014 #7
Trojan.Poweliks Removal Tool Sunlei Nov 2014 #8
Thanks. I might try it on my good laptop just to make sure. Baitball Blogger Nov 2014 #9
***UPDATE*** Earth Bound Misfit Dec 2014 #10
I wish threads like this would be pinned. Baitball Blogger Dec 2014 #11
Yup. Earth Bound Misfit Dec 2014 #12
I will pin this for a while, good idea nt steve2470 Dec 2014 #13
thanks! Baitball Blogger Dec 2014 #14
Message auto-removed Name removed Aug 2015 #18
poweliks - powershell has stopped working glenmarth Jan 2015 #15
Message auto-removed Name removed Feb 2015 #16
remove poweliks? AirSurf May 2015 #17
Eset Node32 is not good Maxbala Sep 2015 #19
Message auto-removed Name removed Dec 2015 #20
useful DivenParker Feb 2016 #21
AUTOMATED MESSAGE: Results of your Jury Service mahatmakanejeeves Feb 2016 #22
Message auto-removed Name removed Feb 2019 #23
Thank you. Bookmarked in case I need it later. Baitball Blogger Feb 2019 #24
Latest Discussions»Help & Search»Computer Help and Support»Anyone have a quick fix t...»Reply #4