I am having an issue deleting Trojan.Fakealert virus my PC, ot at least thats what i think it is.
Yesterday i noticed my laptop was a bit slow so i tried going into task manager to have a look and it would just instantly close, same with command prompt or regedit. So i did what you would normally do and boot up in safe mode with networking, run malware bytes / spyhunter / rkill / rootkit remover and spybot when the above didnt help. Only malwarebytes and spyhunter detect anything, however as soon as they remove the trojan it replicates elsewhere on my system EVEN in safemode. I am unable to access task manager or cmd in safemode either. Malware bytes idetifies the trojan in multiple locations, gives you an option to delete it but the trojan replicates to another location as soon as its done.
This is the latest scan report from malwarebytes
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\*devauditcsc.exe (Trojan.FakeAlert) -> Value: *devauditcsc.exe -> No action taken.
c:\Windows\System32\config\systemprofile\AppData\Local\devauditcsc.exe (Trojan.FakeAlert) -> No action taken.
c:\$RECYCLE.BIN\s-1-5-21-1410236154-1455553273-2078879821-1000\$RHLXT54.exe (Trojan.FakeAlert) -> No action taken.
c:\Windows\System32\config\systemprofile\AppData\Local\Temp\FY1248.tmp (Trojan.FakeAlert) -> No action taken.
c:\Windows\System32\config\systemprofile\AppData\Local\Temp\FY92DC.tmp (Trojan.FakeAlert) -> No action taken.
c:\Windows\System32\config\systemprofile\local settings\devauditcsc.exe (Trojan.FakeAlert) -> No action taken.
c:\Windows\System32\config\systemprofile\local settings\application data\devauditcsc.exe (Trojan.FakeAlert) -> No action taken.
I can locate those files and in the description it says KwertiryWare and original file name is xfiqo.exe
Normally it replicates somewhere on the C drive or in user folders but this time it replicated into a windows folder.
Im running Windows 7 32-bit.
I am not sure where to go at this point and would really appreciate any help provided.