Hi 
Backup the Registry:
Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.
Please navigate to Start >> All Programs >> ERUNT >> ERUNT
Note: If you have uninstalled ERUNT since we last used it, please inform myself before proceeding any further.
Custom OTM Script:
Malwarebytes Anti-Malware:
When completed the above, please post back the following:
Esker License AgreementNot a cause for concern, this most likely occurred because the software was not uninstalled correctly at some point. The service was active actually but we have successfully removed it now.
The app execution is not authorized, The line service could not start, The specified service does not exist as an installed service.
As for the email folder, Id rather just delete the entire contents of folder. Just point me to it.ThanksFine, we will actually target it with the OTM script below.
Backup the Registry:
Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.
Please navigate to Start >> All Programs >> ERUNT >> ERUNT
- Click on OK within the pop-up menu.
- In the next menu under C:\WINDOWS\ERDNT\DD-MM-YYYY under Backup options make sure both the following are selected:
- System registry
- Current user registry
- Next click on OK
- When the Question pop-up appears click on Yes
- After a short duration the Registry backup is complete! popup will appear
- Now click on OK. A backup has been created.
Note: If you have uninstalled ERUNT since we last used it, please inform myself before proceeding any further.
Custom OTM Script:
- Double-click OTM to start the program.
- Copy the lines from the codebox to the clipboard by highlighting ALL of them and pressing CTRL + B (or, after highlighting, right-click and choose Copy):
:Processes
Explorer.EXE
brsvc01a.exe
brss01a.exe
:Services
BrSplService
:Files
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\Documents and Settings\Betty Lovelace\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst
:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"*{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=-
[-HKEY_CLASSES_ROOT\CLSID\*{CFBFAE00-17A6-11D0-99CB-00C04FD64497}]
:Commands
[EmptyTemp]
[Start Explorer]
[Reboot]- Return to OTM, right-click in the "Paste instructions for items to be moved" window (under the yellow bar) and choose Paste
- Then click the red MoveIt! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of it and pressing CTRL + C (or, after highlighting, right-click and choose Copy), and paste it into your next response.
- If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
- Close OTM.
Malwarebytes Anti-Malware:
- Launch the application, Check for Updates >> Perform a Quick Scan
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When completed, a log will open in Notepad. please copy and paste the log into your next reply.
When completed the above, please post back the following:
- Inform myself how your computer is running. Any problems encountered and or further symptoms?
- OTM Log.
- Malwarebytes Anti-Malware Log.
- A new HijackThis Log.
