CMD starts downloading a file after startup

iasonstv

Prominent
Nov 26, 2017
1
0
510
Today i accidentally installed some kind of malware named Mail.ru. I deleted everthing in context to it and let malwarebites check my pc. There still comes up a cmd window after every start, which downloads some kind of file.

DISPLAY: 'KKUFv' TYPE: DOWNLOAD STATE: TRANSIENT_ERROR
PRIORITY: HIGH FILES: 0 / 1 BYTES: 4671 / 387392 (1%)
ERROR FILE: http://solikenezw.com/gpr.zip -> C:\Users\Iason\AppData\Local\Temp\7780306.zip
ERROR CODE: 0x801901f4 - HTTP-Status 500: Der Server kann die Anforderung aufgrund eines unbekannten Fehlers nicht e
ERROR CONTEXT: 0x00000005 - Fehler beim Verarbeiten der Remotedatei.
 
Solution
Two choices. Do a clean Windows re-installation with the first step being deleting all partitions.

The other is to spend a lot of time troubleshooting, usually only worth it if you have a lot of irreplaceable data.

If you go that way, start with using Kaspersky Rescue Disk 10 (freeware) to boot and clean the machine. You can download it on another computer from the link HERE then boot from it either CD or USB, let it update its definitions and run fully. It will clean anything out but won't repair any broken registry entries.

RealBeast

Titan
Moderator
Two choices. Do a clean Windows re-installation with the first step being deleting all partitions.

The other is to spend a lot of time troubleshooting, usually only worth it if you have a lot of irreplaceable data.

If you go that way, start with using Kaspersky Rescue Disk 10 (freeware) to boot and clean the machine. You can download it on another computer from the link HERE then boot from it either CD or USB, let it update its definitions and run fully. It will clean anything out but won't repair any broken registry entries.
 
Solution
Whichever way you go about this, I suggest disconnecting from the Net in case it's phoning home with your personal files. Only connect to update any malware scanners you use then take it off afterwards.

I also recommend creating another User Account without Administrative rights to work on the problem.