Accidentally downloaded an update for adobe flash. Moments later, Bytefence installed itself onto my laptop, as well as an app called 'weatherbuddy'. My browser was also hijacked by Palikan. Finally, I was able to restore my default browser and I installed Malwarebytes and ESET. Both had found and deleted files relating to these apps, but they are still running in the background and appear on my taskbar icon tray but cannot be found in the control panel. Thanks for your help!

Dani AI

Generated

Quick, targeted cleanup steps that build on what described and the good pointers from and . Reformatting (as suggested) will kill every trace, but it’s a last resort — try the checklist below first and keep a verified backup of personal files (do not copy executables or unknown AppData files).

  1. Isolate & backup
  • Disconnect from the network. Copy only documents, pictures and bookmarks to external media. Do not back up program files from Program Files, Program Files (x86) or AppData.
  1. Safe Mode + stop resident processes
  • Boot Safe Mode (or Safe Mode with Networking) and use Task Manager or a process viewer to stop suspicious processes. If a process is visible, right‑click -> Open file location to find the executable.
  1. Remove persistence points (high value)
  • Run an autorun/startup scanner (run as admin) and uncheck/delete entries for unknown items in Run/RunOnce/Services/Scheduled Tasks. Also open Task Scheduler and delete any unfamiliar tasks.
  1. Registry & startup folders (be careful)
  • Inspect these keys for leftovers and export them before editing:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
    %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
    %ProgramData%\Microsoft\Windows\Start Menu\Programs\StartUp
  1. Browsers and network settings
  • Remove unknown extensions, reset homepage/search, check shortcut Target for extra URLs, verify Internet Options -> Connections -> LAN settings (no proxy), and open the hosts file (C:\Windows\System32\drivers\etc\hosts) to remove redirections.
  1. Final system checks
  • Run an offline/second‑opinion scan, then run:
    sfc /scannow

    (on Windows 8/10 also run DISM /Online /Cleanup-Image /RestoreHealth)

  1. When to reformat
  • If persistence remains after the above (unknown services keep returning, new tasks reappear), back up only personal data, wipe the drive and do a clean OS install. After cleanup, change all passwords from a known‑clean device and watch financial accounts for unusual activity.

Notes and cautions: always export logs and paths from your anti‑malware scans before deleting (they help identify leftovers). Back up registry keys before editing. If any step is unclear or the malware resists removal, a clean reinstall or professional help is the safest path.

Recommended Answers

All 3 Replies

See here to get started (Bleeping Computer Palikan removal guide)

Guide by happygeek is very useful. I will add that with hijacking malware, you do need to run the scans a couple of times and to at least one solid PC restart. Using Malware, Hitman pro, adw cleaner and anti-virus of your choice usually will do the job well. After following the guide my additional advice would be to be very careful with

I would try to to reformat the machine with a fresh copy of windows, if possible, or reset the computer to the factory settings. That is the only sure way to get rid of infections.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.