Just got my laptop back from the repair shop.
Avast is picking up a file as Win-32:Malware-Gen.
C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.0.6001.18000_none_e1f3ed49c1c122ef\autochk.exe
Virustotal only shows a couple picking it up, 7/42, but it was 4/42 last night, so I don’t think it’s a FP.
Only problem is I can’t move it because I’m getting Access Denied.
EDIT: As I resubmitted to Virustotal, it apparently tried to open, but Avast caught it, and put it in the chest. I couldn’t move it in scan results. I got “Access Denied (5)”
Here is a proposed manual removal routine, start booting your computer into Safe Mode. To boot into Safe Mode, restart your machine and press F8 repeatedly while it boots up. A menu should come up during that boot-up process with different boot options. Now from these choose the one named Safe Mode with Networking.
After the machine has fully booted into Safe Mode, get and find the following files and folders that have been associated with RootKit.Win32.Agent.fky:
%Documents and Settings%\All Users\Application Dataiosejgfse.dll
%Documents and Settings%[UserName]\Desktop\Protection Center.lnk
When you have found them remove them using Shift + Delete,
Now cleansing the registry entries:
Click on the Run button in your Start menu. Type “regedit” into the box that appears and click Okay. In the Registry Editor that opens, select and delete the following references to RootKit.Win32.Agent.fky both in the Registry Key section in the left pane and in the Registry Value section on the right pane:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE \Software \Microsoft \Windows \CurrentVersion \RunServicesOnce
HKEY_CURRENT_USER/Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER \Software \Microsoft\ Windows\ CurrentVersion\ Policies\ Explorer\Run
HKEY_CURRENT_USER\ Software\ Microsoft \Windows\ CurrentVersion
Explorer/ShellFolders Startup="C:\windows/start menu/programs\startup