This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Removed Nemucod, IE starts @ boot, right click is hijacked

1 min read

✨ The volunteers who helped with this thread aren't active anymore, but you can still get a personalized answer — click Ask AI below.

This thread's last reply is from November 11, 2016, 4:23 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

clgunz
hello, all
i have a problem with a user who recently was infected with nemucod. i have run many anti (everything) and the system comes up clean. the problems are that when the computer starts IE also starts, and equally troublesome is that when i right click any application or file i get an termination message from hitman pro stating that it has terminated explorer 6.1 to stop it from doing something malicious.


here is the path it seems intent on getting at:
\\"server"\"serverdata"\virtualclonedrive\elbyvcdshell.dll

it give this process trace:
1 c:\windows\explorer.exe (4364)
explorer.exe
2 c:\windows\system32\winlogon.exe (4284)
winlogon.exe
3 c:\windows\system32\smss.exe (896)
\systemroot\system32\smss.exe 00000000 00000048


i can only think of wiping the system. any help would be appreciated.
pgmigg Admin/Teacher
By posting just a description of your problems it is likely that your topic will be passed by and you will not receive the help you're looking for.

We need to know what's running on your computer so we can give you appropriate instructions.

May I draw your attention to THIS topic, which you should have read, and which tells you what we need you to post so that we can help you.

This topic will now be closed.

If you still need help, please start a new thread with:
  • FRST.txt
  • Addition.txt
  • Details of your problems.


If for any reason you can't run FRST, please let us know in your post.

✨ Ask AI about this thread

No ads, no affiliate links — generated on request from this thread's own archived content, not written by forum staff. Never run a scan/removal tool as a self-service step if the original thread describes it being done under a helper's direct supervision, and don't include your name, email, or other personal details in a follow-up question. See our privacy page for details on how this works.