This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Poor Malware Removal contd.

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi elmkd,

Let's see if some of the problems are from a corrupted service pack install.

First create a new System Restore point

You must be logged on to an administrator account
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create
Wait for it finish.

Next click your start button > control panel > Add/Remove programs and uninstall

Windows XP Service Pack 3

Reboot if not prompted to and see if the symptom persists.

Thanks
Sorry, I tried to perform the steps, but I think I must have deleted the uninstall files with ccleaner at some point. There is no button for REMOVE for Service Pack 3. Thanks for your patience. elmkd
Sorry, I tried to perform the steps, but I think I must have deleted the uninstall files with ccleaner at some point in the distant past. There is no button for REMOVE for Service Pack 3. Thanks for your patience. elmkd
Hi elmkd,

Let's see if this will turn up anything.

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Safe Mode
My original thread was closed (Same Topic Title). I did not get the email notification of a reply in time. I am posting my GMER Log. I was originally assisted by oldman960. Thank you for your help. 📎gmer.txt
Hi elmkd,

Not a whole lot shows in the GMER log. Did you let it run to completion? It would be helpful if we know which infection you removed. That may give us an idea of what damage may have been done. Do you have any of the logs from any of the tools you might have used?

Let's have a look at what it did log.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :reg
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\PropertySheetHandlers
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\{3EA48300-8CF6-101B-84FB-666CCB9BCD32}
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Thank you for your continued help. I honestly cannot recall what I tried to remove. Here is my SystemLook Log: SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 08:31 on 12/04/2010 by Herbalife (Administrator - Elevation successful) ========== reg ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\PropertySheetHandlers] (No values found) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\CryptoSignMenu] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\{3EA48300-,] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\PropertySheetHandlers\{3EA48300-8CF6-101B-84FB-666CCB9BCD32}] (Unable to open key - key not found) -=End Of File=-
The only items I can see in my Antivir Logs are: recognition pattern of APPL/NirCmd.2 application TR/Crypt.XPACK.Gen Trojan But I am pretty sure they were removed after the problems started. I don't see anything in my Malwarebytes Log going back the last 8 Logs (to 5/19/2009). Regards, elmkd

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI