Hi everyone.
I have a virus of some sort trying to pass itself off as a 7-zip program, it's harmless for now, but I just can't get rid of it.
It's set itself up as a startup program nag and I cannot remove it or it's weaker clone (I was able to open the clone in notepad, delete everything, then save, then delete the file, but it came back upon log off/on), and the 2 registry keys keep coming back.
It wants to launch a program called dywjsuruukltmbqp.exe, which I deleted no sweat.
The thing I can't get rid of, ltyonspl.exe keeps forcing a popup asking me to let it open the command prompt/console so it can do it's nasty thing (although with dywjsuruukltmbqp.exe deleted, it will probably just fail), but this goes away when you kill it's process.
However, it is still running somehow as I cannot delete the 2 ltyonspl.exe files and I can't even set hijackthis to delete them upon reboot for the same reason, which makes little sense to me. Also cannot delete it's entry in the HijackThis scan, in which it's an 04 item, found in the HKCU group.
One of them sits at my name>AppData>Local>dnhcdpjx>ltyonspl.exe (the one I can temporarily delete with notepad trick)
and the other at my name>AppData>Roaming>Microsoft>Windows>Start Menu>Programs>Startup>ltyonspl.exe
I was hoping I could attack them by making another administrator account but of course I cannot access the other name's files/setup folders.
Not sure where to go from here, any help will be appreciated.