I first restored my pc to factory state so there were no antispyware or antivirus program on it. Then I disabled windows defender and firewall.
I downloaded, extracted the zip file and then run it as administrator.
At first it loaded and started running a program named 12145.exe but I was able to kill the process. Then I extracted and ran 21157.exe as administrator again and it started a program called 9683.exe. This also was able to be killed through task manager.
I noted the file path and it was
C:\users\username\AppData\Roaming\microsoft\dtsc\9683.exe
I had a couple more goes installing 21157.exe and rebooting.
Eventually it took hold and locked my pc up totally!!! I tried to reboot into safe mode and that locked up too!
I tried a couple of more reboots and eventually I was able to boot into safe mode with networking. As soon as I could I went into task manager and killed the process (this time named 30118.exe)
I then downloaded HiJackthis and run a scan. I fixed the line that showed the random exe:
O4 - HKCU\..\Run: [Microsoft Windows Installer] C:\Users\username\AppData\Roaming\Microsoft\dtsc\30118.exe
Still in safe mode I navigated to and deleted this folder:
C:\users\username\AppData\Roaming\microsoft\ dtsc <------
I then downloaded Combofix and ran it... It detected and fixed couple of problems. Now I'm reviewing the log to see if there is anything left behind. So far I've noticed these 2 lines which don't belong because Utorrent has never been installed on this machine and it was backed up to factory state.
"{452EF2AA-CE3D-4171-80E7-C6374C6AB31C}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{DB640CAE-CD5E-4AD3-BD8C-39D575026400}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
I know that the malware hasn't acted in the same way on this machine as it has on yours. I could only ever see one instance of the malware running at any given time. But I hope it can help with the removal of it on your machine.