Hi Curson,
Before seeing your reply I found this thread
http://forum.adlice.com/index.php?topic=273.0 and downloaded Processhacker, where I terminated the iexplorer.exe process tree, which was giving the background iexplorer pages. Task manager shows that they are no longer running, for now anyway.
I then saw your reply and followed the instructions.
Here is the latest report run with Roguekiller(x64):
Hope you can help.
Thanks
Dave
RogueKiller V10.5.9.0 (x64) [Apr 7 2015] by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/softwares/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Dave [Administrator]
Started from : C:\Users\Dave\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1TSJTDUW\RogueKillerX64.exe
Mode : Delete -- Date : 04/13/2015 18:22:16
¤¤¤ Processes : 1 ¤¤¤
[Suspicious.Path] (SVC) RapportCerberus_43926 -- \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys[7] -> ERROR [41c]
¤¤¤ Registry : 3 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RapportCerberus_43926 (\??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys) -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RapportCerberus_43926 (\??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys) -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet003\Services\RapportCerberus_43926 (\??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys) -> Deleted
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS547575A9E384 +++++
--- User ---
[MBR] 9c50ca4918e89af5c43423daea0b5f77
[BSP] 450a4243d6e193ea8fdc87af2a3def53 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 199 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 409600 | Size: 700789 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1435625472 | Size: 14312 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
3 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 1464936448 | Size: 102 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_04092015_172117.log - RKreport_DEL_04092015_172439.log - RKreport_SCN_04102015_000703.log - RKreport_DEL_04102015_002419.log
RKreport_SCN_04102015_152317.log - RKreport_DEL_04102015_153400.log - RKreport_SCN_04112015_003307.log - RKreport_DEL_04112015_003408.log
RKreport_SCN_04112015_113057.log - RKreport_DEL_04112015_113843.log - RKreport_DEL_04112015_113906.log - RKreport_SCN_04112015_121327.log
RKreport_DEL_04112015_123147.log - RKreport_SCN_04122015_085229.log - RKreport_DEL_04122015_085909.log - RKreport_SCN_04122015_092810.log
RKreport_SCN_04122015_203612.log - RKreport_SCN_04132015_002004.log - RKreport_DEL_04132015_083301.log - RKreport_SCN_04132015_091040.log
RKreport_DEL_04132015_091115.log - RKreport_SCN_04132015_115021.log - RKreport_DEL_04132015_115123.log - RKreport_SCN_04132015_181016.log