The tools that you have used and tried to use can not be used in the Windows Forums. For this reason I've requested that this topic be moved to the Am I Infected forum where these tools can be used.
RKill is an easy to use tool that kills known processes and removes Windows Registry entries that stop a user from using their normal security applications. RKill will not remove any of the processes it stops, you will need to run security scans to remove any malware found. These settings will remain until the computer is rebooted, for this reason you must run your security applications before the computer is rebooted.
With RKill running do the download and run the scans listed below the Safe Mode instructions. Post the logs in the order they are requested, post the logs in your topic in the order they were run.
If you have any difficulties downloading any of the tool set your computer to boot into Safe Mode with Networking.
How to boot into Safe Mode in Windows 8.1
You will need to use an Administrator account to for this.
Press the Windows key and the X key together. In the menu that opens select Search. When the Search charm opens type in msconfig.
msconfig will appear below the search box, click/tap on it.
When System Configuration opens click/tap on the Boot tab.
Under Boot options click/tap on Safe boot, then click/tap on Network, click/tap on Apply, then OK.
The next time you start the computer it will boot into Safe Mode.
Please note. You computer will continue to boot into Safe Mode when it is started until you go back to System Configuration and remove the check in Safe boot.
Please run Malwarebytes AntiMalware
Please download Malwarebytes Anti-Malware 2.2.
1) Double-click on mbam-setup.exe, then click on Run to install the application, follow the prompts through the installation.
2) Malwarebytes will automatically open. You will see an image like the one below, click on Update Now.
3) Click on Settings, you will see a image like the one below.
When Settings opens click on Detection and Protection, then under Non-Malware Protection, click on the down arrow for PUP (Potentially Unwanted Programs) detections and select Treat detections as malware. Under Detection Options place a check in the box for Scan for rootkits
4) Click on Scan (next to Settings), then click on Scan Now. The scan will automatically run now.
5) When the scan is complete the results will be displayed. Click on Delete All.
6) Please post the Malwarebytes log.
To find your Malwarebytes log,download mbam-check.exe from here and save it to your desktop.
To open the log double click on mbam-check.exe on your desktop. Copy and paste the entire log in your topic.
Please run TDSSKiller.
Please download TDSSKiller from here and save it to your Desktop.
The log for the TDSSKiller can be very long. If you go to the bottom of the log to where you find Scan finished you will see the results of the scan. If it shows Detected object count: 0 and Actual detected object count: 0, this means that nothing malicious was found and you will not need to post the log.
1. Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
2. Check Loaded Modules, Verify Driver Digital Signature, and Detect TDLFS file system.
If you are asked to reboot because an "Extended Monitoring Driver is required" please click Reboot now.
3. Click Start Scan and allow the scan process to run.
4. If threats are detected select Cure (if available) for all of them unless otherwise instructed.
***Do NOT select Delete!
Click on Continue.
5. Click on Reboot computer.
Please copy the TDSSKiller.[Version]_[Date]_[Time]_log.txt file found in your root directory (typically c:\) and paste it into your next reply.
Note: The log may be very long. You may need to break it into parts to post the whole log.
Post this in your topic.
Please run AdwCleaner
Please download AdwCleaner and install it.
When AdwCleaner opens you will see an image like the one below.
Click on Scan to start the scan.
Once the search is complete a list of the pending items will be displayed. If you see any which you do not want removed, remove the check mark next to it.
If there are no malicious programs are found you will receive the following message.
Click on Clean to remove the selected items. If you have any questions about any items in the list please copy and paste the list in your topic so we can review it.
You will receive a message telling you that all programs will be closed so that the infections can be removed. Click on OK. The computer will be restarted to complete the cleaning process.
When the cleaning process is complete a log of what was removed will be presented. Please copy and the paste this log in your topic.
Please run the ESET OnlineScan
This scan takes quite a long time to run, so be prepared to allow this to run
till it is completed.
***Please note. If you run this scan using Internet Explorer you won't need
to download the Eset Smartinstaller.***
ESET Online Scanner
- Click here to download the installer for ESET Online Scanner and save it to your Desktop.
- Disable all your antivirus and antimalware software - see how to do that
- Right click on esetsmartinstaller_enu.exe and select Run as Administrator.
- Select Enable detection of potentially unwanted applications.
- Click Advanced Settings, then place a checkmark in the following:
- Remove found threats
- Scan archives
- Scan for potentially unsafe applications
- Enable Anti-Stealth technology
- Click Start to begin scanning.
- ESET Online Scanner will start downloading signatures and scan. Please be patient, as this scan can take quite some time.
- When the scan is done, click List threats ([color=redonly available if ESET Online Scanner found something
- Click Export, then save the file to your desktop.
- Click Back, then Finish to exit ESET Online Scanner.
Edited by dc3, 25 March 2017 - 11:02 AM.