This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Spyware Cease 2011

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Cant remove spyware cease 2011. Deleted from add/remove and from registry. Malware bytes and windows malicious does not pick it up. DDS (Ver_2011-06-12.02) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 21:01:23 on 2011-06-22 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2814.1127 [GMT -4:00] . AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\TOSHIBA\IVP\ISM\pinger.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\svchost.exe -k imgsvc c:\TOSHIBA\IVP\swupdate\swupdtmr.exe C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskhost.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\iPod\bin\iPodService.exe C:\TOSHIBA\IVP\ISM\ivpsvmgr.exe C:\Program Files\Windows Doctor\WindowsDoctor.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe C:\Windows\system32\conhost.exe C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe C:\Windows\system32\conhost.exe C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\rundll32.exe C:\Users\rick11\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\svchost.exe -k defragsvc C:\Windows\system32\dfrgui.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ mStart Page = about:blank uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Skytel] Skytel.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.1 [removed] TCP: Interfaces\{02F894CC-F5C6-4C06-8632-E9CCE59C9135} : DhcpNameServer = 192.168.1.1 [removed] TCP: Interfaces\{541D686F-A9FB-4E98-B429-3DE98AC642C6} : DhcpNameServer = 192.168.1.1 [removed] Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Filter: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - c:\program files\citrix\ica client\IcaMimeFilter.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2011-5-14 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2011-5-14 744568] R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20110616.003\BHDrvx86.sys [2011-6-16 810616] R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [2009-9-8 65584] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20110622.001\IDSvix86.sys [2011-6-22 367736] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2011-5-14 136312] R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\system32\drivers\n360\0501000.01d\symnets.sys [2011-5-14 296568] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128] R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2008-4-17 40960] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-6-4 366640] R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccSvcHst.exe [2011-5-14 130008] R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 126976] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-5-22 105592] R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-5-5 7168] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-10-14 22712] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-3-21 362600] R3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\toshiba\smartfacev\SmartFaceVWatchSrv.exe [2008-4-24 73728] S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2009-4-17 20384] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-7 135664] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-22 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-5-5 30192] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-7 135664] S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\jumpstart\jswpsapi.exe [2009-4-17 954368] S3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\drivers\RTL8192su.sys [2010-7-8 603240] S3 SVRPEDRV;SVRPEDRV;c:\windows\system32\sysprep\PEDRV.SYS [2008-5-16 9216] S3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2011-4-2 54136] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-5-27 52224] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-5-24 1343400] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520] S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040] . =============== Created Last 30 ================ . 2011-06-20 02:37:39 ——– d—–w- c:\program files\Windows Doctor 2011-06-18 20:40:31 ——– d—–w- c:\users\rick11\appdata\roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2011-06-16 02:32:28 ——– d—–w- c:\users\rick11\appdata\local\NPE 2011-06-14 23:34:04 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-14 23:15:04 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-06-14 23:15:04 141104 —-a-w- c:\program files\internet explorer\sqmapi.dll 2011-06-14 23:15:03 1797632 —-a-w- c:\windows\system32\jscript9.dll 2011-06-14 22:54:36 571904 —-a-w- c:\windows\system32\oleaut32.dll 2011-06-14 22:54:35 338944 —-a-w- c:\windows\system32\drivers\afd.sys 2011-06-14 22:54:35 1290624 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-06-14 22:54:32 311808 —-a-w- c:\windows\system32\drivers\srv.sys 2011-06-14 22:54:32 310272 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-06-14 22:54:32 114688 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-06-14 22:54:19 741376 —-a-w- c:\windows\system32\inetcomm.dll 2011-06-14 22:54:12 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-06-14 22:54:12 223744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-14 22:54:12 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-06-12 17:41:33 ——– d—–w- c:\program files\iTunes 2011-06-12 17:41:33 ——– d—–w- c:\program files\iPod 2011-06-04 18:54:19 ——– d—–w- c:\program files\Belkin 2011-06-04 18:53:37 ——– d—–w- c:\windows\{26F3D17D-4FF9-46D5-9255-A1F9FF6BD7E4} 2011-06-04 18:45:41 ——– d—–w- c:\users\rick11\appdata\local\Diagnostics 2011-05-28 14:56:47 ——– d—–w- c:\windows\system32\SPReview 2011-05-27 21:45:25 1130824 —-a-w- c:\windows\system32\dfshim.dll 2011-05-27 21:44:25 52224 —-a-w- c:\windows\system32\drivers\TsUsbFlt.sys 2011-05-27 21:44:24 11776 —-a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2011-05-27 21:44:19 3215872 —-a-w- c:\windows\system32\mstscax.dll 2011-05-27 21:42:45 1171456 —-a-w- c:\windows\system32\d3d10warp.dll 2011-05-27 21:42:33 954752 —-a-w- c:\windows\system32\mfc40.dll 2011-05-27 21:42:32 954288 —-a-w- c:\windows\system32\mfc40u.dll 2011-05-27 21:42:20 1159168 —-a-w- c:\windows\system32\sysmain.dll 2011-05-27 21:42:11 423936 —-a-w- c:\windows\system32\secproc_isv.dll 2011-05-27 21:42:06 327168 —-a-w- c:\windows\system32\RMActivate_isv.exe 2011-05-27 21:42:05 428032 —-a-w- c:\windows\system32\secproc.dll 2011-05-27 21:42:00 322048 —-a-w- c:\windows\system32\RMActivate.exe 2011-05-27 21:40:59 517120 —-a-w- c:\windows\system32\wbem\WmiPrvSD.dll 2011-05-27 21:39:59 80256 —-a-w- c:\windows\system32\drivers\amdsata.sys 2011-05-27 21:38:59 86528 —-a-w- c:\windows\system32\isoburn.exe 2011-05-27 21:37:41 606208 —-a-w- c:\windows\system32\wbem\fastprox.dll 2011-05-27 21:37:41 363008 —-a-w- c:\windows\system32\wbemcomn.dll 2011-05-25 04:16:46 ——– d—–w- c:\windows\Panther 2011-05-25 04:02:31 ——– d–h–w- C:\$WINDOWS.~Q 2011-05-25 03:51:19 ——– d–h–w- C:\$INPLACE.~TR 2011-05-25 03:34:07 219136 —-a-w- c:\windows\system32\d3d10_1core.dll 2011-05-25 03:34:07 161792 —-a-w- c:\windows\system32\d3d10_1.dll 2011-05-25 03:34:06 805376 —-a-w- c:\windows\system32\FntCache.dll 2011-05-25 03:34:06 1076736 —-a-w- c:\windows\system32\DWrite.dll 2011-05-25 03:34:05 739840 —-a-w- c:\windows\system32\d2d1.dll 2011-05-25 03:23:24 ——– d—–w- c:\users\rick11\appdata\local\ElevatedDiagnostics 2011-05-25 03:10:32 ——– d—–w- c:\windows\system32\Wat 2011-05-25 02:39:36 31232 —-a-w- c:\windows\system32\prevhost.exe 2011-05-25 02:39:14 870912 —-a-w- c:\windows\system32\XpsPrint.dll 2011-05-25 02:38:23 802304 —-a-w- c:\windows\system32\WFS.exe 2011-05-25 02:38:23 191488 —-a-w- c:\windows\system32\FXSCOVER.exe 2011-05-25 02:38:13 2333184 —-a-w- c:\windows\system32\win32k.sys 2011-05-25 02:38:08 70656 —-a-w- c:\windows\system32\fontsub.dll 2011-05-25 02:38:08 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-05-25 02:38:08 294912 —-a-w- c:\windows\system32\atmfd.dll 2011-05-25 02:38:06 28672 —-a-w- c:\windows\system32\dnscacheugc.exe 2011-05-25 02:38:06 132608 —-a-w- c:\windows\system32\dnsrslvr.dll 2011-05-25 02:38:01 542208 —-a-w- c:\windows\system32\kerberos.dll 2011-05-25 02:32:57 123904 —-a-w- c:\windows\system32\poqexec.exe 2011-05-25 02:31:15 1164288 —-a-w- c:\windows\system32\mfc42u.dll 2011-05-25 02:31:15 1137664 —-a-w- c:\windows\system32\mfc42.dll 2011-05-25 02:30:50 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-05-25 02:30:45 850944 —-a-w- c:\windows\system32\sbe.dll 2011-05-25 02:30:45 642048 —-a-w- c:\windows\system32\CPFilters.dll 2011-05-25 02:30:45 534528 —-a-w- c:\windows\system32\EncDec.dll 2011-05-25 02:30:44 199680 —-a-w- c:\windows\system32\mpg2splt.ax 2011-05-25 02:30:11 2616320 —-a-w- c:\windows\explorer.exe 2011-05-25 02:29:45 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-05-25 02:29:45 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-05-25 02:29:22 69632 —-a-w- c:\windows\system32\drivers\bowser.sys 2011-05-25 02:29:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-25 02:12:37 728448 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2011-05-25 02:12:37 219008 —-a-w- c:\windows\system32\drivers\dxgmms1.sys 2011-05-25 02:12:37 107520 —-a-w- c:\windows\system32\cdd.dll 2011-05-25 02:00:27 ——– d-sh–w- C:\Recovery 2011-05-25 01:43:05 ——– d—–w- c:\windows\system32\wbem\Performance 2011-05-25 00:22:09 ——– d—–w- c:\windows\system32\RTCOM 2011-05-25 00:21:43 ——– d—–w- c:\program files\Synaptics 2011-05-25 00:21:29 0 —-a-w- c:\windows\ativpsrm.bin 2011-05-24 03:59:49 20992 —-a-w- c:\windows\jestertb.dll . ==================== Find3M ==================== . 2011-05-29 13:11:30 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-29 13:11:20 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-05-28 17:54:50 152576 —-a-w- c:\windows\system32\msclmd.dll 2011-05-14 04:33:52 126584 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2011-05-10 12:06:08 4517664 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-05-10 12:06:08 42496 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2011-05-04 08:52:22 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-04-25 19:19:55 1700352 —-a-w- c:\windows\system32\gdiplus.dll 2011-04-06 20:20:16 91424 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 20:20:16 107808 —-a-w- c:\windows\system32\dns-sd.exe 2011-03-31 03:00:09 516216 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys 2011-03-31 03:00:09 50168 —-a-r- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys . ============= FINISH: 21:02:07.32 ===============
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.


Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Next:


Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.




Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI