Hi Brant,
Happy 4th to you also. Just a few more steps...
First of all, reboot to SAFE MODE.
Once in Safe Mode go to Start, Control Panel, Administrative Tools, Services.
Scroll through and look for
DomainService. If it is Running click Stop. Then Double Click on Domain Service and set Start Up Type to Disabled. Click OK.
Then go to C:\WINDOWS\System32\
Look for gtndpsyt.exe
It says in the log that it is gone. But if you do find it, delete it.
Next go to Control Panel, Add/Remove and look for ZenoBrowserEnhancer or any programs labled Zeno.
Uninstall all of them that you find.
Next go to C:\WINDOWS\
look for this file itpb_11.exe SKY003
If you find it, remove it.
Reboot to normal mode.
Run HJT again and place a checkmark next to the following if still present;
O2 - BHO: (no name) - {48E5651B-2335-41FE-A71D-64332BB9ACDF} - C:\WINDOWS\System32\sstro.dll (file missing)
O2 - BHO: (no name) - {8C5DD480-BEB0-436A-A18C-16458422CCF8} - C:\Program Files\Internet Explorer\holenu83122.dll
O4 - HKLM\..\Run: [{ZN}] C:\WINDOWS\itpb_11.exe SKY003
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\System32\gtndpsyt.exe (file missing)
Once you have placed the checkmarks click the FIX button.
Exit HJT.
Reboot again to Normal Mode.
Run one more Kaspersky Scan and save the log.
Run a new scan with HJT and save the log.
Post back here with both new logs.
Judy


Reply With Quote