Hello Jack ,
I need you to upload a few suspicious files to VirusTotal (VT) for an online scan. Click here.
- Click on the Browse button or the white box beside it. A File Upload prompt will open.
- Copy and paste the following file and its path to upload:
Code:C:\Documents and Settings\Joycellen Floyd\Desktop\win32k two- Press Open, then Send file. The file will be uploaded for testing.
- If there is any indication or prompt that the file has been scanned before, please proceed to have the file rescanned or reanalyzed.
- Please wait for all the scanners to finish, then copy and paste the result into Notepad and save it to a convenient place.
- Repeat for
Code:C:\Documents and Settings\Joycellen Floyd\Desktop\win32k.sys C:\Documents and Settings\Joycellen Floyd\Desktop\7z920.exe- Post the results in your next response.
Alternatively, if VirusTotal is busy or inaccessible, you may try Jotti or VirScan (VS) with similar steps.
A result from either one of the above scanners would be sufficient.
--------------------
Check some files with OTL
- Double click on OTL.exe to run it.
- Make sure all the None options is checked (ticked). There are eight of them.
- Copy and paste the following into the white box under Custom Scans/Fixes:
Code:%SYSTEMDRIVE%\*.* %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles %systemroot%\Tasks\*.job /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\system32\drivers\*.sys /md5 %systemroot%\system32\user32.dll /md5 %systemroot%\system32\ws2_32.dll /md5 %systemroot%\system32\ws2help.dll /md5 DRIVERS32 NETSVCS- Click on Run Scan at the top left hand corner. This might take a while.
- When done, the OTL.txt file will open. Please post back the contents of this log.
--------------------
Increase paging file
- Go to Start, then right click on My Computer. Select Properties. You can also do the same via the My Computer icon on the desktop.
- Click on the Advanced tab, then Settings under the Performance section.
- Go to the Advanced tab in this new window. Click Change under the Virtual Memory section.
- Select Custom size, then in the two white boxes, key in 2046 into both and press Set. You will be prompted, click Yes. OK your way out and restart your computer if requested.
--------------------
Now, try RootRepeal again.
--------------------
Please post back:
1. VT / Jotti / VirScan results
2. OTL log
3. RootRepeal log