This was a nasty trojan virus to remove. Drop us a LIKE 👍
@f9k4ksu8goij2 жыл бұрын
pretty sure you need XMrigminer when running cudo, mining monero. not to say this one wasnt a virus particularly. but the program is for mining
@Paintwritelive2 жыл бұрын
This was after I put it in excluded folder in windows defender
@arthurshugars19742 жыл бұрын
Nice video and thanks! It really is a shame that some people take pleasure in screwing other people over with these trojans/malware. It is a nice breathe of fresh air having you show us on what to do in cases like these happening to us! :)
@Britec092 жыл бұрын
Love removing malware
@CPUjunkie2 жыл бұрын
@@Britec09 pppppppoppooooooooooooo
@Narobloxx2 жыл бұрын
@@Britec09 same
@philonutube1002 жыл бұрын
Excellent work.... I learn so much from your flicks and a pleasure to watch as well.
@Britec092 жыл бұрын
Great to hear!
@sebastian197452 жыл бұрын
I had the same issue many years ago (2007 or so). I worked with a P3 computer with XP that commanded a machine through a proprietary software. One day, when I started the computer in the morning I noticed that was slower than usual (I made a coffee and the machine was ready to go usually, but then I drank half of the cup until the program was ready). Well, the program was very lagged, it took minutes to send a command to the machine. The antivirus (avast I think it was) did not started and could not install anything, IT guy tried Panda, malware-something and nothing installed. So, I took the same approach: with taskmanager I tried to find the program that hog the CPU, but taskmanager did not started: need admin privileges. When browsing to its location was nowhere to be found, only a .lnk file instead (and I used Total Commander instead Windows explorer). I disconnected the network cable and form a CD (that I made in the IT office) I ran Process Explorer (that I made default taskmanager later). So I was able to find where its program was. Rebooted in safe mode, deleted its files, checked the registry for its name/location and deleted all the entries. Also checked the startup sequence to make sure that no other instance was ran. Rebooted and was OK. Virus removed. All in less than one hour. My colleague from the other shift was playing a new game at the time that he had on CD (some swf flash thing) while the machine was doing its job and that infected the computer. I disconnected the CD drive and no problems again. For that, we lost half day of work (almost all my shift), but I got a nice bonus for being the antivirus. The IT guy at the time was busy searching for another machine to replace that computer and eventually found one next day, so we had a spare (that we never used). And for the next two years while I worked there, I was called for every problem with the staff personal computers (viruses, BSOD, installing the OS, downgrading from Vista to XP, upgrading the hardware, etc). Often I took same approach, used same technique and always worked. That is why I only have the Windows default antivirus and never installed an antivirus program on my computers.
@ionamygdalon22632 жыл бұрын
Very smart thinking Brian! Really enjoyed this video, as if it were a crime/thriller movie haha :)
@film49uk2 жыл бұрын
Wow, really impressed with this clip. Glad you showed us your method and keep them coming, many thanks Paul
@MrTr3D2 жыл бұрын
what if the trojan is still in the registry? Why not just use bitdefender to eliminate the trojan, rather than doing each one? It might be hidden in another folder
@sludgefactory2412 жыл бұрын
Hell yeah, always wondered how to manually remove that crap, cuz I don't really trust any one program myself to remove things properly. Another great video where I learned alot
@Britec092 жыл бұрын
Glad I could help
@dreamdream0112 жыл бұрын
restart in safe mode and delete the folder, no need for extra programs
@JCO20022 жыл бұрын
Here's the best way - insert a USB live stick with Linux on it, then select erase disk and install. No more viruses.
@lenn80892 жыл бұрын
Great work Brian sorting that out, bit beyond me tho, I appreciate your knowhow.
@Britec092 жыл бұрын
Thanks 👍
@1965kings2 жыл бұрын
In an Enterprise environment this would be painstakingly done if at all. Also, MSI's Rivatuner statistics side kick upon attempt to uninstall, it stops you from uninstalling. If you go to task manager and kill process, it restarts making impossible to do so. One scheme is to do as per uploader video. Instead I used a process lasso which I have been using for 2-3 years to kill off RTSS.
@_Jay_Maker_2 жыл бұрын
Awesome instructional guide, and very easy to do, too. I'll definitely add this practice to my typical removal process if other programs don't work. Great stuff.
@MortalRhythm2 жыл бұрын
When I open task manager it's turn off automatically can make me a solution
@babakgholian34672 жыл бұрын
Hi I got a question . How do you see all the extentions in the browser Taskbar opera or other if you have more than 5 extentions you can't see them and then you can't use them ! How do you get tow rows of extentions in the browser bar ?
@proulxr20022 жыл бұрын
Great video. I think my system is pretty clean but this is a super helpful video for future use. Thank you!
@Britec092 жыл бұрын
Glad it was helpful!
@nonavailable40002 жыл бұрын
Great Job Mr Britec !!! , i really missed these trojans & virus removing videos !!! :-) , this really kinda made my boring day lol
@Britec092 жыл бұрын
Glad you enjoyed!
@11Stormtrooper2 жыл бұрын
Nice solution suspending the processes! Wouldn't something like LockHunter work too for this case?
@fookingsog2 жыл бұрын
Interesting!!! When you rename the files, it breaks the reference links between the files as well as nullifying the executable attribute!!!
@Britec092 жыл бұрын
That is correct .exe to .old it can't run. But you need to kill process first
@fookingsog2 жыл бұрын
@@Britec09 Suspend Process!!!😉👍🏻...remember you had to put it to sleep before renaming?!
@saddamhossen82492 жыл бұрын
A@aaaaa
@deciodasilva39602 жыл бұрын
This was very useful mate thanks...i would actually go into a live CD and remove them...I like the technique you used
@Britec092 жыл бұрын
I could not do that when in remote session
@deciodasilva39602 жыл бұрын
@@Britec09 ahh forgot you mentioned that at the beginning 😅😅
@geraldthorburn11232 жыл бұрын
One of your best vids ever, Brian
@digitalillustration6042 жыл бұрын
As always, save this video in case I need it 👍Thank you!
@Britec092 жыл бұрын
Glad it was helpful!
@stevevivien4431 Жыл бұрын
Hi britec09 I have a problem where I can't connect to the internet. I've tried everything to fix it but no cigar. I get err_connection_failed, not even the network troubleshooting works, it can't detect the problem. Funny thing is every else seems to work with the internet except my PC. Help!
@MrCino0002 жыл бұрын
maybe some idea, it doesn't want me to install the latest update in W 11. W 11Pro is installed without TPM verification.
@jessevokal71272 жыл бұрын
@Britec09 Hey, so I do have a problem. I tried to suspend the suspected malware with this program and it keeps telling me "Access Denied" not sure how to get around this? Also do you fix PCs like this guys? I'll pay you to fix mine please🙏 I've been trying for over a month
@climjames2 жыл бұрын
The only thing remaining is to find it in the 'start up list' and 'registry' and remove it there too. Well I would try that but it might not be the thing others should try. What do you think?
@o0Sazie0o2 жыл бұрын
Very helpful tips, I'll definitely try this if I get a similar problem
@ParisubalanCreations2 жыл бұрын
Hai Bro I am Tamilnadu and my laptop was attacked for moia ransomware then my files are corrupted, it also added .moia extension for example my file name is Parisubalan.jpeg.moia so how to recover my files please ask me bro please... Waiting for your reply 🤝
@200andahalf2 жыл бұрын
How about using Rkill to stop those processes?
@vincemorath6762 жыл бұрын
Great video. Thanks for sharing. That was a rather nasty critter to kill.
@Frobard2 жыл бұрын
So where did the malware come from? How did it start at boot? Any service involved? Registry entries?
@KANKIT_TOOLSONINSTAGRAM2 жыл бұрын
👆👆👆👆👆 contact him for help, he is the best.
@MrSonic19532 жыл бұрын
what about running rkill ?
@thestudioroom58832 жыл бұрын
Hi Brian. Something like this happened to me last week. a thing called "tailhook" was flooding my computer. uninstalled it and it reappears. All my junior sport tricks to repair failed. End up reloading Windows 10. Many thanks for the advice.
@PaulHoyle7772 жыл бұрын
Thank you so very much. I learn a great deal from you. 🙂
@Britec092 жыл бұрын
You are so welcome
@tombecker20552 жыл бұрын
Would booting up in safe mode have allowed normal deletion of these programs?
@obasaar682 жыл бұрын
Hello, Thank for a very detailed informative video!
@Britec092 жыл бұрын
Glad it was helpful!
@user-si5tr5wg4p2 жыл бұрын
@@Britec09 Hello, I'm grateful to you for taking a moment to reply!
@BeltsandBuckles012 жыл бұрын
Nice work great work👍
@dreamdream0112 жыл бұрын
Instead of downloading additional programs and and doing all that work, just start in safe mode, and delete the folder, then scan with good anti-malware program.
@Robinrpv2 жыл бұрын
Why not just boot to safe mode and delete the program file then go through regedit and after that run something like Advanced System Repair Pro
@Doris-y5v Жыл бұрын
This is so good for us to know thank you .
@erwinperciva57082 жыл бұрын
Nice my pc is infected by trojan that infecting all .exe files. And anti-virus can't remove it. I'll try it manually Thank for sharing
@Revolutionized2 жыл бұрын
Yeah, you could do that, or you could have some essential system security (premium version with auto update functionality and routine background scanning) installed in the first place and have these stuff avoided for close to a hundred percent of the time.
@sanamthapa87862 жыл бұрын
MME ramsomware virus has infected my PC. Can you please help me and how can I decrypt the files
@anshumanmishraw2 жыл бұрын
Thanks for great content video it's much more helpful I learned about it.
@Britec092 жыл бұрын
Glad it was helpful!
@speckles47832 жыл бұрын
I just watched a video from 2 years ago about the 144 hertz monitors. My screen runs at 144hz but when I go into a game such as seige. It will default back to 60hz. When I change the games screen to 144hz. It still stays on 60hz. This happens to overwatch aswell. I've done what you've said and went through amd drivers and still its not working. Any ideas on what is causing this
@Britec092 жыл бұрын
Pop on our discord for help
@123IGRACH2 жыл бұрын
Check for autorun and reboot in safe mode?
@Britec092 жыл бұрын
It was a remote support session, so I needed internet
@crumblingsanity64552 жыл бұрын
Would it have been better to try and run malwarebytes in safe mode?
@tridens67082 жыл бұрын
Wouldn't pc antivirus softwear find and delete the trojan?
@djdoolittle13152 жыл бұрын
Yes, Malwarebytes Free 😉
@reducetheme5852 жыл бұрын
How did you record this?
@samvictor14722 жыл бұрын
My laptop was affected with udla malware please help me to remove that malware
@raylopez992 жыл бұрын
Sounds pretty ad hoc. I'm sure a competent virus writer will make it so you cannot suspend or sleep any active malware app to prevent this fix in the future.
@diveallz10442 жыл бұрын
I'm curious how long it took you to remote into that PC since the CPU usage was at 100%🤔
@Britec092 жыл бұрын
Malware has a tendency of utilising all of the system resources
@diveallz10442 жыл бұрын
@@Britec09 I'm well aware of that sir 😂 🤦 as you mentioned numerous times in the video. You had said that you remoted into that system and I'm curious how long it took you to do that with the system resources being at 100% like that.
@Mobenforcer2 жыл бұрын
Another great video, thanks.
@Britec092 жыл бұрын
Glad you enjoyed it
@rasedul_islam_rashed2 жыл бұрын
Very nice video. Thanks a lot.
@Britec092 жыл бұрын
Always welcome
@garyalexander56862 жыл бұрын
Brilliant work. Thanks.
@Britec092 жыл бұрын
Many thanks!
@journeyon19832 жыл бұрын
Brian. Couldn't you have booted into "Safe Mode" rather than manually putting to sleep all those running processes from the virus? If this idea works, then you could just delete the folder with the infected files and you're done.
@Britec092 жыл бұрын
I was remoted in to machine.
@JimInYamaguchi2 жыл бұрын
Your tips are pretty good, so I've got a question for you: I have my taskbar set to a specific height, but every time Windows updates something, it readjusts the taskbar height to what looks like two lines high (my preference is four). Do you know how I can stop/prevent it doing that?
@Britec092 жыл бұрын
Windows updates has a habit of changing settings back, especially feature updates. Make a batch files will all your settings and run it after update.
@JimInYamaguchi2 жыл бұрын
@@Britec09 Sounds good. But, how? Output my settings to a .reg file and have the batch file load it on startup? Not sure how to output the settings (what registry entries they're in). :/
@MrLuiszao2 жыл бұрын
great job amazing thinking
@welshtony12 жыл бұрын
This was fun to watch live.
@Britec092 жыл бұрын
Yes sir
@V530-15ICR2 жыл бұрын
Oh it's that annoying xmrig, I saw it on a pc and had to do ctrl alt delete the whole time
@Britec092 жыл бұрын
ctrl alt delete would not do anything with the trojan
@V530-15ICR2 жыл бұрын
@@Britec09 but i would have to click log out and log back in to be able to delete the file before it runs
@ASO-F5B2 жыл бұрын
Good review
@mike56362 жыл бұрын
There's is tron, why didn't you use that?
@Bunyi_Logam2 жыл бұрын
I will try this.. 🙏🙏🙏 Thanks
@RootTheLucario2 жыл бұрын
I wouldn’t advise clicking on related sites as some of them are infected websites with malicious download files. To be honest i’d say be careful about sites you click on.
@johnsenchak14282 жыл бұрын
That sounds like a file less malware that hides in memory , A lot of that comes from drive by down loads from websites that run aggressive ads. This is one of the main reason why you have to use a ad-blocker extensions At the very end I would use a clean folder and files utility to remove all garbage including what's in the trash bin from all the terminating
@Britec092 жыл бұрын
It was a nasty one.
@puyat20002 жыл бұрын
the very simple question is why computer viruses is created in any kind of it. then you want to remove it using another created program called anti-virus or vise versa. look if computer viruses not created, the anti-virus not created also. imagine you are using any types of operating system without existing of viruses i think you are happy with them.
@RebMordechaiReviews2 жыл бұрын
I do use Process Explorer and Process Monitor, but would have used UVK to deal with this. Are you sure that there wasn't an associated Windows Service which was restarting the processes? I would have also done a search for files created at the same time, looked for an associated Windows Service. Your method of renaming the exe files is exactly what I would have done except I rename them .BAD.😀
@Britec092 жыл бұрын
What ever works I guess.
@RebMordechaiReviews2 жыл бұрын
@@Britec09 It was you who recommended Ultra Virus Killer to me in the first place! Great product. there is an option to kill ALL non essential processes as well. Very useful. Also to list associated processes and services..great for problems like this.
@Britec092 жыл бұрын
@@RebMordechaiReviews Yes its a very good product, wanted to show how to manually remove it.
@Duraputer2 жыл бұрын
How I remove Corona viris
@anshumanmishraw2 жыл бұрын
That's correct...🦧
@WillyEckaslike2 жыл бұрын
will a system restore to an earlier point g3t rid of it?
@Britec092 жыл бұрын
Nope and the restore points could hold malware
@ivanlimzg2 жыл бұрын
Would a pc reset work?
@Britec092 жыл бұрын
Yes
@djdoolittle13152 жыл бұрын
Wotcha Bri ,Malwarebytes Free. Job done ✅
@Britec092 жыл бұрын
Nope, he tried that
@renew27812 жыл бұрын
Thanks brother pls help to remove Usb Write protected issue
@Britec092 жыл бұрын
join discord
@renew27812 жыл бұрын
@@Britec09 didn't understand is this Ur KZbin channel ?
@BrianJohnson-lh2ek8 ай бұрын
Wow. Great job.
@robpet44242 жыл бұрын
Nice.... now I know what to do !
@karthiksarmavalluri50222 жыл бұрын
Bro please make a video on high cpu usage of windows 10 in vmware
@MrTr3D2 жыл бұрын
use revo to remove all files, rather than doing it manually
@boiseptic1382 жыл бұрын
Just use autoruns to disable it perm then get tron to destroy the malware
@edw6114 Жыл бұрын
what if i cant suspend ?
@-WhizzBang-2 жыл бұрын
If you can rename them, why not just delete them?
@MrBadboy4182 жыл бұрын
The king!
@anthonynowlan97652 жыл бұрын
Taskkill from cmd?
@Britec092 жыл бұрын
taskkill /F /PID pid_number
@spektrumB2 жыл бұрын
Learn a few tricks. Big thumb up.
@Britec092 жыл бұрын
Thanks
@garymucher40822 жыл бұрын
Nice video. Obviously this isn't for the computer illiterate type folks. So many things to do to clean a PC up to work correct again. The average user probably won't have the knowledge of how to accomplish such things. But a great idea all the same.
@ninonicebx2 жыл бұрын
Bro too much bullshit just freaking wipe the shit clean and reinstall everything.
@markae02 жыл бұрын
Thanks for the education.
@Britec092 жыл бұрын
Our pleasure!
@Paintwritelive2 жыл бұрын
Just to let you know I downloaded test disk to remove malware and windows defender flagged it as a trojan. it was the wrong link. It was me. Now I feel stupid. Sorry.
@thesnare1002 жыл бұрын
the clickable image for this video said remove any virus 100% very bold claim I'd like to see how it stands up to tests
@sleepwalker68252 жыл бұрын
Snore Fest ... So many easier ways to kill these processes ... Brian Used to be a GOTO channel but the the Lag is now painful
@tony-_-doge2 жыл бұрын
I'm going to say this it could have came from cheat engine or any cheating software he has installed could've came from those as some cheat devs sometimes even add back doors and stuff to make threats so you don't steal their code it's crazy what they will do I would advise him to not download cheats even from legit and cheat devs with a reputation because they can give u a virus and just disappear and you can't do anything about it and some cheat devs make it so you need to give admin privileges so you can use their cheats and they basically have full control of ur PC and shouldn't be trusted
@LifeByKpop2 жыл бұрын
Weird stuff is happening Brain. I have left a couple of comments on this video and they keep getting deleted. 🤔
@mkskrakusnh2 жыл бұрын
Same
@Britec092 жыл бұрын
Not sure what's going on, its happening a lot.
@MrJavapiet2 жыл бұрын
Nice one
@Britec092 жыл бұрын
Thanks for watching
@johnsenchak14282 жыл бұрын
Brian the process "TERMINATOR" "Another bites the dust" and another gone and another gone "Another bites the dust"
@Britec092 жыл бұрын
lol
@fernandozornosa63982 жыл бұрын
Great worlk killing and delete nasty stuff from a system,Is great to Learn about security on Windows,thanks
@Georgegossamer6423 Жыл бұрын
How does your average George know what files are part of malware?
@breakingthe4thwall2602 жыл бұрын
Out of curiosity is this client running a paid version of antivirus?
@Britec092 жыл бұрын
No, just windows security
@lupzyluo47722 жыл бұрын
whats the discord
@DCS0262 жыл бұрын
Nice!
@Knards2 жыл бұрын
Brilliant.
@Britec092 жыл бұрын
Thanks
@АндрійЦевух2 жыл бұрын
У нас 6 летний установит "unlocker" и завершит все ненужные процессы с последующим удалением зараженных папок. Людям нужно проще и быстрее решать проблемы. В этом видео все хорошо.... все в ручную с пониманием всех действий, но это много кому будет лень учить. А ведь лень, это двигатель прогресса.
@maxthecaddy84512 жыл бұрын
would Malwarebytes be good to sort that viruses out👍
@Britec092 жыл бұрын
He run Malwarebytes and could not remove it. Think he said it was crashing the program.
@aasimraza44572 жыл бұрын
Can you please help me I also have irjg malware I will pay you your charge please help me