Adlice forum
General Category => Malware removal help => Topic started by: Kagezod on April 06, 2023, 12:04:30 AM
-
Error 5 when removing a virus.
Attaching the report.
How to decide?
The program finds a virus, but cannot remove it. Sometimes you can change how the command console opens and closes (which really annoys me)
-
Hi Kagezod,
Welcome to Adlice.com Forum.
Please download SystemLook (x64) (http://images.malwareremoval.com/jpshortstuff/SystemLook_x64.exe) and save it to your desktop.
- Double-click SystemLook_X64.exe to run it.
- Copy the content of the following codebox into the main textfield:
:dir /s /md5
%SystemRoot%\Fonts\Mysql
- Click the Look button to start the scan.
- When finished, a notepad window will open with the results of the scan. Please attach this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Regards.
-
Here. I don't quite understand why it didn't work. By the way, the log report shows that it is in %SystemRoot%\Fonts\Mysql .
But I find it when I scan C:\Windows\Fonts . (Well, or when I scan the entire system completely)
-
when I scanned with slightly different parameters, this came out
-
Hi Kagezod,
Sorry, I messed up the parameters.
Let's try with these.
- Double-click SystemLook_X64.exe to run it.
- Copy the content of the following codebox into the main textfield:
:dir
%SystemRoot%\Fonts\Mysql /s /md5
- Click the Look button to start the scan.
- When finished, a notepad window will open with the results of the scan. Please attach this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Regards.
-
There is nothing. It seems that such a file simply does not exist, but it is present on all RogueKiller checks no matter how many times I run it
-
Hi Kagezod,
This is quite strange
Please download Handle (x64) (https://live.sysinternals.com/handle64.exe) and save it on your desktop.
Launch the command prompt windows (cmd) with admin rights and copy/paste the following command :
"%USERPROFILE%\Desktop\handle64.exe" -a -u -nobanner Fonts\Mysql > "%USERPROFILE%\Desktop\Handle.log"
A new file named Handle.log should has been created on your desktop.
Please attach it with your next reply.
Regards.
-
It's empty
-
I will also attach a screenshot from what the scanner shows, so that it would not seem that I came up with it myself
-
Hi Kagezod,
Could you try renaming the "Mysql" folder ?
Does an error occurs ?
Regards.
-
This folder doesn't even show up in the fonts folder. I have show hidden folders enabled.Even scanning the entire C drive for a MySQL file does not work.
I found the mysql.vim file on drive D in the Git folder (I installed it from the official site a few months ago)
-
Hi Kagezod,
Let's try another way.
Launch the command prompt windows (cmd) with admin rights and copy/paste the following command :
rmdir %SystemRoot%\Fonts\Mysql > "%USERPROFILE%\Desktop\Remove.log"
A new file named Remove.log should has been created on your desktop.
Please attach it with your next reply.
Regards.
-
I was denied access
+ rmdir %SystemRoot%\Fonts\Mysql > "%USERPROFILE%\Desktop\Remove.log"
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : OpenError: (:) [Out-File], DirectoryNotFoundException
+ FullyQualifiedErrorId : FileOpenFailure,Microsoft.PowerShell.Commands.OutFileCommand
-
Hi Kagezod,
Could you please try with CMD and not Powershell ?
Regards.
-
C:\Users\AdminStar>rmdir %SystemRoot%\Fonts\Mysql > "%USERPROFILE%\Desktop\Remove.log"
Access denied.
-
I got access now writes this
%SystemRoot%\Fonts\Mysql > "%USERPROFILE%\Desktop\Remove.log"
The specified file cannot be found.
-
Updated, checked this folder with an antivirus again and the virus is no longer found.
That's just for this, I made myself the owner of the Windows folder. Does it pose any problems or risks?
-
Hi Kagezod,
Thanks for your feedback.
I suspect there is a bug within RogueKiller. We will try to reproduce it.
Your system is clean. There is no risk anymore.
Regards.
-
There was no removal. It's just that the antivirus stopped finding this virus in this folder. I'm not sure of the exact reasons, maybe the virus just didn't display correctly or I don't know. Submitting a report on the next full scan.
-
Hi Kagezod,
Sorry for the very late answer.
It was a hard nut to crack. During the removal process, RogueKiller cleared ACL only on files and subdirectories but not the root directory itself.
This will be fixed in RogueKiller next release.
Again, thank you very much for helping us fixing this.
Regards.