Hello and welcome to Bleeping Computer.
*Please Subscribe to this Thread to get immediate notification of replies. See HERE
*It is important
not to make any further changes or run any other tools/updates unless instructed to. This may hinder the cleaning process of your machine.
*Please be patient, all Bleeping Computer helpers
are volunteers and have lives outside this forum.
*You must reply within 5 days otherwise this topic will be closed.
to your Desktop.
- Double click on the OTL icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- Copy and Paste the following code into the Custom Scan/Fixes box. Do not include the word "Code"
%ALLUSERSPROFILE%\Application Data\*.exe /s
%systemroot%\*. /mp /s
- Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them when you reply.
Download GMER Rootkit Scanner from here
- Extract the contents of the zipped file to the desktop.
- Double click GMER.exe and if you are asked if you want to allow gmer.sys driver to load, please allow it to do so.
- If it gives you a warning about rootkit activity and asks if you want to run scan, please click on NO.
- In the right panel you will see several boxes that have been checked. Unchecked the following checkboxes:
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Now click on the Scan button and wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in ark.txt and save it to your desktop.
- Post the contents of that report when you reply.
You can help me continue the fight against malware by making a donation, Thank you.
If I am helping you and I didn't reply within 48 hours... Please send me a private message.
Topics that are not replied within 5 days will be close. Please don't PM asking for support, post on the Forums instead.
Member of UNITE (Unified Network of Instructors and Trained Eliminators)