0

I have been hit by a virus, i noticed the virus infection during the setup of infectious scam app. It installed so many other apps and registry keys, the usual viral changes.

i was able to clean my pc so far, but there's one file left in the system32/drivers folder ... eyfmunxx.sys file

i can't find the corresponding service in the list of services, and i suspect it's the reasonthat trustedinstaller is being invoked after everytime i clean my pc and somehow without even internet access, two viral processes "winsrv.exe" and "winxsrv.exe" are recreated in my windows folder...

Anyway, i think that's the only thing left if i remove this .sys file i'll be able to completely remove this infection. The problem is, for this particular file, i'm not even able to take ownership of it. Everything is access denied, from copying it, renaming it, deleting it of course... as well as trying to view permissions or change permission to the extent of not being able to take ownership.

I mean how can such a file get so much priority in my windows? Or is it cheating locking resources or something like interrupting intentionally to disallow any way for windows to deal with it?

I still have two other solutions, system restore, or get some other booting system and connect to the harddisk and delete while windows is down.

I'm asking here maybe there's another solution, coz usually this type of virus might corrupt/infect system restore.

I tried unlocker, didn't help, it doesn't show any open handle on it.

Any ideas?

LolaRun
  • 103

2 Answers2

1

If you are really shure that you need to delete it then you can use a linux live USB, like Linux Mint or Ubuntu linux, you can also try using a USB bootable disk, select Troubleshoot > Advanced Options > Command Prompt and delete the file using the command console

I would try using a linux USB because it wont load any windows files at all

https://community.linuxmint.com/tutorial/view/744

Chico3001
  • 284
0

Boot into safe mode and then delete eyfmunxx.sys. To boot to safe mode:

  1. Restart your computer
  2. Rapidly hit the F8 key
  3. Press the key and then press Enter
  4. Now delete that file

This way, only critical drivers are loaded. I don't think Windows will think that file is a critical driver.