Sorry for the delay, it has been quite a busy week for me.
Bert's checklist is one that you can work through step by step. I'll have you run a couple information gathering tools to see what might be getting in the way and follow up with specific instructions for moving forward following your reply.
Please do not make any changes to your system, by installing new software/hardware, do not run any "fix" programs and/or remove any files unless instructed to do so, by me.
Please read these instructions carefully
before executing and then perform the steps, in the order given.
lf you have any questions or problems, executing these instructions, <<STOP>> do not proceed, post back with the question or problem.Run CKScannerPlease download by clicking here =>
CKScanner ... Save it to your desktop.
Make sure that CKScanner.exe is on the your desktop before running the application! - Double-click on the CKScanner.exe icon... then click the Search For Files button.
Using Vista, you must right click the (CKScanner.exe) icon and choose "Run As Administrator", then click the "Search For Files" button. - When the scan is finished (the cursor hourglass disappears) click the Save List To File button.
A text file will be created on your desktop named "ckfiles.txt" - Click OK at the file saved message box. Double-click on the ckfiles.txt icon on your desktop.
- Please copy/paste the contents of ckfiles.txt in your next reply.
Run GMERPlease download by clicking here =>
GMER... random file name.exe by
GMER.
The downloaded file will have a
random name... this prevents malware from detecting and blocking it.
Note: Do not run any programs while Gmer is running.**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries - Double click on the random named.exe to execute. If asked, allow the gmer.sys driver load.
Using Vista, you must right click random named.exe and choose "Run As Administrator". - If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO <--- Important!
- On the right side panel, several boxes have been checked. Please UNCHECK the following: (see image below)
- Sections
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All <-- don't miss this one
Click on image to enlarge
- If you don't get a warning then... Click the Rootkit/Malware tab at the top of the GMER window.
- Click the Scan button.
- Once the scan has finished... click Copy.
- Open Notepad and paste (Ctrl+V) what you copied.
- Select "Save As" in Notepad...saving the file to your desktop as "gmerRK.txt"... then close Notepad.
- Copy and paste the contents of the files gmerRK.txt in your next reply.
Run RSITPlease download by clicking here =>
RSIT by
random/random... save it to your desktop.
- Right click on RSIT.exe and select "Run As Administrator" to run it. If Windows UAC prompts you, please allow it.
- Please read the disclaimer... click on Continue.
- RSIT will start running. When done... 2 logs files...will be produced.
The first one, "log.txt", <<will be maximized... the second one, "info.txt", <<will be minimized. - Please post both... "log.txt" and "info.txt", file contents in your next reply.
(These logs can be lengthy, so post 1 log per reply please.)
Post BackPlease post back with the following:
- Any problem executing the instructions?
- CKScanner ckfiles.txt file contents.
- GMER gmerRK.txt file contents
- RSIT log.txt and info.txt file contents.
Good Luck
