This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Slow computer and programs not running

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My mom's computer is running extreme slow and sometimes IE explorer does not load. I downloaded DDS to the desktop and disabled Norton System Works. I ran DDS and it didn't do anything. After about 10 minutes I closed the DOS window and retried it. after a couple of times, it finally gave me the files. Here are the files: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/09/02 07:22 Program Version: Version 1.3.5.0 Windows Version: Windows Vista SP1 ================================================== Drivers ——————- Name: dump_dumpata.sys Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys Address: 0x92152000 Size: 45056 File Visible: No Signed: - Status: - Name: dump_msahci.sys Image Path: C:\Windows\System32\Drivers\dump_msahci.sys Address: 0x9215D000 Size: 40960 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\Windows\system32\drivers\rootrepeal.sys Address: 0xB4DCA000 Size: 49152 File Visible: No Signed: - Status: - Processes ——————- Path: System PID: 4 Status: Locked to the Windows API! Path: C:\Windows\System32\audiodg.exe PID: 1204 Status: Locked to the Windows API! SSDT ——————- #: 013 Function Name: NtAlertResumeThread Status: Hooked by "" at address 0x8cea9958 #: 014 Function Name: NtAlertThread Status: Hooked by "" at address 0x8cea9a18 #: 018 Function Name: NtAllocateVirtualMemory Status: Hooked by "" at address 0x8c32a9c0 #: 054 Function Name: NtConnectPort Status: Hooked by "" at address 0x8cf11e80 #: 067 Function Name: NtCreateMutant Status: Hooked by "" at address 0x8cea9708 #: 078 Function Name: NtCreateThread Status: Hooked by "" at address 0x8c32ab08 #: 147 Function Name: NtFreeVirtualMemory Status: Hooked by "" at address 0x8c32a820 #: 156 Function Name: NtImpersonateAnonymousToken Status: Hooked by "" at address 0x8cea97d8 #: 158 Function Name: NtImpersonateThread Status: Hooked by "" at address 0x8cea9898 #: 177 Function Name: NtMapViewOfSection Status: Hooked by "" at address 0x8c32a740 #: 184 Function Name: NtOpenEvent Status: Hooked by "" at address 0x8cea9648 #: 195 Function Name: NtOpenProcessToken Status: Hooked by "" at address 0x8c32aa90 #: 202 Function Name: NtOpenThreadToken Status: Hooked by "" at address 0x8cea9e30 #: 282 Function Name: NtResumeThread Status: Hooked by "" at address 0x8c288ad8 #: 289 Function Name: NtSetContextThread Status: Hooked by "" at address 0x8cea9d70 #: 305 Function Name: NtSetInformationProcess Status: Hooked by "" at address 0x8cea9f00 #: 306 Function Name: NtSetInformationThread Status: Hooked by "" at address 0x8cea9ca0 #: 330 Function Name: NtSuspendProcess Status: Hooked by "" at address 0x8cea9588 #: 331 Function Name: NtSuspendThread Status: Hooked by "" at address 0x8cea9b20 #: 334 Function Name: NtTerminateProcess Status: Hooked by "" at address 0x8c32a208 #: 335 Function Name: NtTerminateThread Status: Hooked by "" at address 0x8cea9be0 #: 348 Function Name: NtUnmapViewOfSection Status: Hooked by "" at address 0x8cea9fd0 #: 358 Function Name: NtWriteVirtualMemory Status: Hooked by "" at address 0x8c32a8f0 ==EOF== DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 7:33:27.74 on Wed 09/02/2009 Internet Explorer: 8.0.6001.18813 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1013.187 [GMT -7:00] AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: Norton Internet Security *enabled* (Updated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Common Files\AOL\1189663422\ee\aolsoftware.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Hp\QuickPlay\QPService.exe C:\Program Files\Mediafour\XPlay 3\XPlay.exe C:\Windows\vsnp2uvc.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\msiexec.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe C:\Users\Wilma\Desktop\RootRepeal.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Wilma\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.charter.net/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.5\NppBho.dll BHO: Mediafour XPlay Explorer notifications: {4907c0ad-874d-44d9-b13e-7b0a4d8b9d3e} - c:\program files\mediafour\xplay 3\XPBHO.DLL BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autoRun uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [HostManager] c:\program files\common files\aol\1189663422\ee\AOLSoftware.exe mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [{914C5BF8-EEDD-4F3A-A8BE-34EE71CF1B29}] "c:\program files\mediafour\xplay 3\XPlay.exe" mRun: [snp2uvc] c:\windows\vsnp2uvc.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [2009-4-30 284416] R1 CbFs;CbFs;c:\windows\system32\drivers\cbfs.sys [2009-7-31 136744] R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20090826.001\IDSvix86.sys [2009-9-1 272432] R2 M4iPodWPDService;M4iPodWPDService;c:\program files\common files\mediafour\ipod\M4iPodWPDService.exe [2009-7-6 208896] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-27 102448] R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2009-8-3 38448] =============== Created Last 30 ================ 2009-09-02 06:53 –d—– c:\programdata\Office Genuine Advantage 2009-09-01 22:44 28,672 a——- c:\windows\system32\Apphlpdm.dll 2009-09-01 22:44 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2009-09-01 22:38 499,712 a——- c:\windows\system32\kerberos.dll 2009-09-01 22:38 213,504 a——- c:\windows\system32\msv1_0.dll 2009-09-01 22:38 175,104 a——- c:\windows\system32\wdigest.dll 2009-09-01 22:38 1,256,448 a——- c:\windows\system32\lsasrv.dll 2009-09-01 22:38 270,848 a——- c:\windows\system32\schannel.dll 2009-09-01 22:38 439,896 a——- c:\windows\system32\drivers\ksecdd.sys 2009-09-01 22:38 72,704 a——- c:\windows\system32\secur32.dll 2009-09-01 22:38 9,728 a——- c:\windows\system32\lsass.exe 2009-09-01 21:31 2,048 a——- c:\windows\system32\tzres.dll 2009-08-16 14:50 160,256 a——- c:\windows\system32\wkssvc.dll 2009-08-16 14:50 71,680 a——- c:\windows\system32\atl.dll 2009-08-16 14:50 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-08-16 14:50 91,136 a——- c:\windows\system32\avifil32.dll 2009-08-16 14:49 313,344 a——- c:\windows\system32\wmpdxm.dll 2009-08-16 14:49 7,680 a——- c:\windows\system32\spwmp.dll 2009-08-16 14:49 4,096 a——- c:\windows\system32\dxmasf.dll 2009-08-16 14:49 4,096 a——- c:\windows\system32\msdxm.ocx 2009-08-16 14:49 8,147,456 a——- c:\windows\system32\wmploc.DLL 2009-08-16 14:48 18,432 a——- c:\windows\system32\amcompat.tlb 2009-08-16 14:48 43,520 a——- c:\windows\system32\msdxm.tlb 2009-08-08 03:02 6,103,040 a——- c:\windows\system32\chtbrkr.dll 2009-08-08 03:02 1,671,680 a——- c:\windows\system32\chsbrkr.dll 2009-08-08 03:02 184,832 a——- c:\windows\system32\SearchProtocolHost.exe 2009-08-08 03:02 1,582,592 a——- c:\windows\system32\tquery.dll 2009-08-08 03:02 1,418,240 a——- c:\windows\system32\mssrch.dll 2009-08-08 03:02 439,808 a——- c:\windows\system32\SearchIndexer.exe 2009-08-08 03:02 670,208 a——- c:\windows\system32\mssvp.dll 2009-08-08 03:02 350,208 a——- c:\windows\system32\mssph.dll 2009-08-08 03:02 203,776 a——- c:\windows\system32\mssphtb.dll 2009-08-07 17:48 891,448 a——- c:\windows\system32\drivers\tcpip.sys 2009-08-07 17:48 72,192 a——- c:\windows\system32\drivers\pacer.sys 2009-08-07 17:48 15,360 a——- c:\windows\system32\pacerprf.dll 2009-08-07 17:41 147,456 a——- c:\windows\system32\Faultrep.dll 2009-08-07 17:41 125,952 a——- c:\windows\system32\wersvc.dll 2009-08-07 17:38 565,248 a——- c:\windows\system32\emdmgmt.dll 2009-08-07 17:38 625,152 a——- c:\windows\system32\drivers\dxgkrnl.sys 2009-08-07 17:38 148,480 a——- c:\windows\system32\drivers\nwifi.sys 2009-08-07 17:38 45,056 a——- c:\windows\system32\dataclen.dll 2009-08-07 17:38 36,864 a——- c:\windows\system32\cdd.dll 2009-08-07 17:38 155,648 a——- c:\windows\system32\wscript.exe 2009-08-07 17:38 135,168 a——- c:\windows\system32\wshom.ocx 2009-08-07 17:38 90,112 a——- c:\windows\system32\wshext.dll 2009-08-07 17:38 180,224 a——- c:\windows\system32\scrobj.dll 2009-08-07 17:38 172,032 a——- c:\windows\system32\scrrun.dll 2009-08-07 17:38 135,168 a——- c:\windows\system32\cscript.exe 2009-08-03 19:07 9,892 a——- c:\windows\system32\drivers\SymRedir.cat 2009-08-03 19:07 1,356 a——- c:\windows\system32\drivers\SymRedir.inf 2009-08-03 19:07 38,448 a——- c:\windows\system32\drivers\symndisv.sys 2009-08-03 19:07 188,080 a——- c:\windows\system32\drivers\symtdi.sys 2009-08-03 19:07 145,968 a——- c:\windows\system32\drivers\symfw.sys 2009-08-03 19:07 39,856 a——- c:\windows\system32\drivers\symids.sys 2009-08-03 19:07 26,416 a——- c:\windows\system32\drivers\symredrv.sys 2009-08-03 19:07 12,720 a——- c:\windows\system32\drivers\symdns.sys 2009-08-03 15:07 403,816 a——- c:\windows\system32\OGACheckControl.dll 2009-08-03 15:07 322,928 a——- c:\windows\system32\OGAAddin.dll 2009-08-03 15:07 230,768 a——- c:\windows\system32\OGAEXEC.exe ==================== Find3M ==================== 2009-08-28 05:39 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2009-08-28 05:38 2,153,984 a——- c:\windows\apppatch\AcGenral.dll 2009-08-28 05:38 541,696 a——- c:\windows\apppatch\AcLayers.dll 2009-08-28 05:38 459,776 a——- c:\windows\apppatch\AcSpecfc.dll 2009-08-16 22:23 143,360 a——- c:\windows\inf\infstrng.dat 2009-08-16 22:23 86,016 a——- c:\windows\inf\infstor.dat 2009-08-16 22:23 51,200 a——- c:\windows\inf\infpub.dat 2009-08-01 08:52 174 a–sh— c:\program files\desktop.ini 2009-08-01 08:28 665,600 a——- c:\windows\inf\drvindex.dat 2009-08-01 07:58 101,888 a——- c:\windows\system32\ifxcardm.dll 2009-08-01 07:57 82,432 a——- c:\windows\system32\axaltocm.dll 2009-07-31 23:48 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2009-07-25 05:23 411,368 a——- c:\windows\system32\deploytk.dll 2009-07-21 14:52 915,456 a——- c:\windows\system32\wininet.dll 2009-07-21 14:47 109,056 a——- c:\windows\system32\iesysprep.dll 2009-07-21 14:47 71,680 a——- c:\windows\system32\iesetup.dll 2009-07-21 13:13 133,632 a——- c:\windows\system32\ieUnatt.exe 2009-06-30 15:36 18,696 a——- c:\windows\help\oem\scripts\HC_BatteryReplaceNew.exe 2009-06-30 15:10 18,696 a——- c:\windows\help\oem\scripts\HC_BatteryNoTravel.exe 2009-06-30 15:03 18,696 a——- c:\windows\help\oem\scripts\HC_BatteryAccessories.exe 2009-06-30 12:44 18,184 a——- c:\windows\help\oem\scripts\HC_BatteryWeakNew.exe 2009-06-26 18:36 18,184 a——- c:\windows\help\oem\scripts\HC_BatteryUpgrade.exe 2009-06-15 08:24 156,672 a——- c:\windows\system32\t2embed.dll 2009-06-15 08:20 72,704 a——- c:\windows\system32\fontsub.dll 2009-06-15 08:20 10,240 a——- c:\windows\system32\dciman32.dll 2009-06-15 05:52 289,792 a——- c:\windows\system32\atmfd.dll 2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 7:35:39.43 ===============

Attachments:

Hello and welcome to WTT.

I apologize for the delay in response.

If you still require assistance post a new set of DDS Logs and a description of any remaining problems or symptoms you may still have please.

Download and run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results soon.
  • Follow the instructions that pop up for posting the results and then click Ok.
  • The black and message box window shall then disappear.
  • Please save both log files on your desktop and post the DDS.txt and zip up and attach Attach.txt as instructed.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

Then, please run RootRepeal:

Download and run RootRepeal CR

Please download RootRepeal to your desktop
Alternative Download Link 2
Alternative Download Link 3
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Unzip it to it's own folder
  • Close/Disable all other programs especially your security programs (anti-spyware, anti-virus, and firewall) Refer to this page, if you are unsure how.
  • Double-click on RootRepeal.exe to run it. If you are using Vista, please right-click and run as Administrator…
  • Click the Report tab at the bottom.
  • Now click the Scan button in the Report Tab. [external image: Posted Image]
  • A box will pop up, check the boxes beside ALL Seven options/scan area
    🖼Click to load external image (Posted Image)
  • Now click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button. [external image: Posted Image]
  • Save it as RepealScan and save it to your desktop
  • Reconnect to the internet.
  • Post the contents of that log in your reply please.

For your next reply I would like to see:
-The DDS logs
—DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy
Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 from the last day I replied initially, the topic will need to be closed.

Thanks for understanding.

With Regards,
Extremeboy

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI