to the Malware Removal forum! My online alias is Blade Zephon
, or Blade
for short, and I will be assisting you with your malware issues!If you have since resolved the original problem you were having, we would appreciate you letting us know.
In the upper right hand corner of the topic you will see a button called Options
. If you click on this in the drop-down menu you can choose Track this topic
. By doing this and then choosing Immediate E-Mail notification
and then clicking on Proceed
you will be advised when we respond to your topic and facilitate the cleaning of your machine.
Before we begin cleaning your machine, I'd like to lay out some guidelines for us to follow while we are working together.
- I will be assisting you with your malware issues. This may or may not resolve other problems you are having with your computer. If you are still having problems after your machine has been determined clean, I will be glad to direct you to the proper forum for assistance.
- Even if things appear better, that does not mean we are finished. Please continue to follow my instructions until I give you the all clean. Absence of symptoms does not mean that all the malware has been removed. If a piece of the infection is left, it can regenerate and reinfect your machine.
- Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
- I ask that you please refrain from running tools other than those I suggest to you while I am cleaning up your computer. The reason for this is so I know what is going on with the machine at any time. If you act independently it will cause changes to your system that I will not be aware of, which will make the process of cleaning the machine a much slower and more difficult process. Additionally, some programs can interfere with others and hamper the recovery process.
- Please perform all steps in the order received. If you are unsure or confused about any instructions I give you, you should ask me to clarify before doing anything. Additionally, if you run into any problems while carrying out instructions, you should STOP and reply back here explaining what happened.
- After 5 days if a topic is not replied to we assume it has been abandoned and it is closed. If you need additional time, that is perfectly alright; you just need to let us know beforehand.
Please perform the following steps below so we can have a look at the current condition of your machine.
If you have not done so, include a clear description of the problems you're having
, along with any steps you may have performed so far.
If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.
We need to see some information about what is happening in your machine. Please perform the following scan:
- Download DDS by sUBs from one of the following links. Save it to your desktop.
- Double click on the DDS icon, allow it to run.
- A small box will open, with an explanation about the tool. No input is needed, the scan is running.
- Notepad will open with the results.
- Follow the instructions that pop up for posting the results.
- Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE
Please install RootRepealNote
: Vista users
,, right click on desktop icon and select "Run as Administrator."
Disconnect from the Internet
- Direct Download (Recommended)
- Zip Mirrors (Recommended if you have a slower connection or if the Direct Download mirror is down)
- Rar Mirrors - Only if you know what a RAR is and can extract it.
or physically unplug your Internet cable connection.Close all open programs
, scheduling/updating tasks and background processes that might activate during the scan including the screensaver.
your anti-virus and real-time anti-spyware protection.
After starting the scan, do not use the computer
until the scan has completed.
When finished, re-enable
your anti-virus/anti-malware (or reboot) and then you can reconnect
to the Internet.
- Extract RootRepeal.exe from the zip archive.
- Open on your desktop.
- At the top of the window, click Settings, then Options.
- Click the Ssdt & Shadow Ssdt Tab.
- Make sure the box next to "Only display hooked functions." is checked.
- Click the "X" in the top right corner of the Settings window to close it.
- Click the tab.
- Click the button.
- Check all seven boxes:
- Push Ok
- Check the box for your main system drive (Usually C:), and press Ok.
- Allow RootRepeal to run a scan of your system. This may take some time.
- Once the scan completes, push the button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
~BladeIn your next reply, please include the following:RootRepeal log
Edited by Blade Zephon, 24 February 2010 - 08:32 PM.