One with a rootkit detector (although I see no sign of a rootkit)
One with a registry search
I will also get otmoveit to do another sweep, each scan should take no more than a few minutes
FIRST THE REGISTRY SEARCH
1. Launch Notepad, and copy/paste the contents of the quote box below into a new Notepad file. Save it with file name options.txt and save as file type: all files to your desktop.
RegSearch Options File
2. Download Registry Search to your desktop.
- Right click on the compressed RegSearch folder, and choose "Extract All". In the box that pops open, click "Next", then "Next" again, and then "Finish". You now have another RegSearch folder on your desktop.
- Open the new folder, and double click on regsearch.exe
- Click "Import" in the lower left corner and browse to the options.txt file that you just saved on your desktop. Do not choose the one in the RegSearch folder itself.
- Click OK and Registry Search will scan your registry for the file(s), and a Notepad box will open with a report.
- Please reply here with the entire contents of the Notepad file from RegSearch.
THEN THE ROOTKIT
Please Download Avast Rootkit Cleaner to your desktop
Close all running programmes
Run the ASWAR file and select Scan Now
On completion of the scan you will then have this screen up
Now close the programme and on the desktop will be a text file called ASWAR please post that. Do not fix anything yet
The programme will take from 3 to 5 minutes to run.
FINALLY FOR NOW
- Save it to your desktop.
- Please double-click OTMoveIt2.exe to run it.
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
C:\aupd.exe /s Purity
- Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the yellow bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTMoveIt2
Logs required : Aswar, regsearch and otmoveit