Following manual instructions found in
But finding differences…the malware has been updated. MCF383.exe instead of mcatcher.exe
killed MCF383.exe from running, but could not find tjd.exe
Found in HKeyROOT
Removed this and prefetch area version.
Searched through registery and deleted anything with mcf383
searched through files to delete…only found pe.drv…removed
regsrv32 appears to be gone or renamed
Reboot did not show
malware catcher returning.