- Install Autorun from sysinternals and upload hash from everything that runs to Virustotal.com (the autorun app has this feature integrated) - Install ProcessMonitor from sysinternals and look for suspicious process, check if System PID is 4. If is not, it's not System. - Install Malwarebytes, activate rootkit detection and deep analysis, then run a scan. - Execute a DISM restorehealth, and AFTER it finishes, run a sfc /scannow - Update your Windows - Reboot - Install HitmanPro and scan with it. - DISM restorehealth again and then sfc /scannow again; if corrupted files found again, somethings fucky. - If no corrupted files encountered, run an OFFLINE WINDOWS DEFENDER SCAN.
- Purge your system
RE: [Tutorial] If your Windows system has been compromised