I've been getting some random redirects when I try and google something, where I get redirected to sites like directrdr and others, but they always end up being blank pages. In addition, random popups for those sites have also occurred. I've tried using spybot search and destroy, Malwarbytes, and updating my Java, but the problem still persists. Any help is appreciated.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.
Log research takes time, so please be patient and I'd be grateful if you would note the following:
The fixes are specific to your problem and should only be used for the issues on this machine.
Do not install/uninstall anything on your computer unless advised.
Do not run any other scanning tools other than those instructed for you to use.
Follow the instructions on the order they are given.
Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 24 hours then the topic will be closed.
And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.
_________________________________________________
If you are using Vista or Windows 7, you will need to right click and choose "Run as Administrator" to run the tools we will use.
OTL:
Download OTL to your desktop.
Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output
Check the boxes beside LOP Check and Purity Check.
Copy and paste the following bold text into the box under Custom Scan
In the right panel, you will see several boxes that have been checked. Uncheck the following …
Sections
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
To post in your next reply:
1. OTL logs.
2. GMER log.
Sorry for the late response, but I'm having problems with the GMER program, more specifically, every time I run the program, the scan goes fine (albeit, it slows my computer down, but I've done the scans with nothing in the background), but when the scan finishes, my computer freezes and I can't save the .txt file.
Here are the OTL logs however:
OTL Extras logfile created on: 3/22/2010 4:36:36 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = D:\Documents and Settings\Dad\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 392.00 Mb Available Physical Memory | 38.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 66.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 29.30 Gb Free Space | 60.00% Space Free | Partition Type: NTFS
Drive D: | 249.26 Gb Total Space | 182.49 Gb Free Space | 73.21% Space Free | Partition Type: NTFS
Drive E: | 624.83 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NUMBER-ONE
Current User Name: Dad
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player
"{063F3C4A-1263-436F-91A9-83BEB989501F}" = Internet Client 2.4
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{07A540AB-D785-11D5-8E89-0090275862A0}" = Corel Graphics Suite 11
"{0933AFF4-3376-4C44-8569-BD7534B4B4E8}" = QuickTax 2002 Platinum
"{107254A0-0ADF-11D4-9397-00D0B7020B38}" =
"{117CD9C0-0F15-4633-93D7-F957B50535A5}" = Popup Blocker (Windows Live Toolbar)
"{1707BF02-0F5C-4A6C-8F17-053BB73E443F}" = Tabbed Browsing (Windows Live Toolbar)
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{212F5777-1190-4DEF-8E4D-6B2F313B45E7}" = PerfectDisk
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22EC35BD-F8F2-45EB-8DCB-1C7FB65D0A71}" = QuickTax 2007
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 18
"{28E24092-3BAE-4D38-A57B-F830862E3A31}" = QuickTax 2003 Platinum
"{294A97F8-CC15-41F7-8718-CEE6B0C7D7E0}" = D-Link Xtreme N Dual Band DWA-160
"{2C464EC1-2B0C-4490-9CAC-D4562DD8377A}" = Soap 3.0 Toolkit
"{30383EB1-E954-4CA3-B7DE-9C3A68B69D26}" = RPS Privacy Manager
"{31DABA20-10A1-4746-9D9F-57955B8DFF66}" = Free Games Offer, Desktop Shortcut
"{3249C40F-A3BF-4ECC-9824-2F3EB9BFE6A1}" = RPS Ksdk
"{332BCC03-A1B7-4BE7-8C8A-2B1333E22C33}" = Opera 10.50
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35CB5932-AE03-491E-9674-DF8E1F38D253}" = RPS Performance Tool
"{3686AE6A-D426-402A-9A49-973867C92BC4}" = RPS App Detector
"{3727B920-F5A3-46A4-AC02-94F421A039C7}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{3838AF48-56E2-4E52-8482-D17CABF63441}" = RPS CRT
"{3BC805C1-1AA9-4A1D-9F21-958F1F3F2D6D}" = ErrorSmart
"{4229B337-0C40-4181-9C41-CAC4C5952A7A}" = RPS Burn
"{43DCF766-6838-4F9A-8C91-D92DA586DFA8}" = Microsoft Windows Journal Viewer
"{451BB54C-8B23-4455-8BDC-14FC7D43E056}" = MSXML4SP2
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{46DDF76F-ACD4-42BC-B48F-B89C4EE2E1A9}" = Easy CD & DVD Creator 6
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C590030-7469-453E-8589-D15DA9D03F52}" = ANIWZCS2 Service
"{4C68AB1C-95CB-4699-BBDE-EC4FA2931E3A}" = RPS Security Cleanup
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4FC19392-E4A5-4CCB-B45A-AB7E8126D3C9}" = Microsoft Easy Assist
"{53337CA9-E9A4-4C59-9D1C-D980EF9BF0C2}" = QuickTax 2004
"{53EF6570-21A4-47ED-A40A-E6470A5677A3}" = Studio 8
"{55DBDE34-2CAE-455C-A1CD-D91F5EE8E4E0}" = TELUS security services
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{5D995085-1609-40D6-85CD-654C13430EE1}" = RPS ParentalControl
"{5DE9ADA1-B9F0-45C5-947F-12E667B01F69}" = RPS Diagnostic Utility
"{5EF2B896-B1C1-46E8-83AD-4F940B7A5982}" = MathGV 4
"{65C1C87A-02D9-4557-BC0D-131F1C419D61}" = Britannica Almanac 2005 CD
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{6924B6B2-EEA2-441D-A939-A6C26EE278F9}" = ATIRW15
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69B02159-7624-4DBB-B9EE-F933039830AD}" = QuickBooks Premier Edition 2006
"{7694E0B1-2332-448B-9235-929F84B41E3F}" = Active@ ISO Burner
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77E1B36B-2C8F-4D89-ABF0-F3FC85516AC5}" = RPS Ad Blocker
"{7B5CE976-C7A9-4E38-A7F3-6C8EF025DD8E}" = ANIO Service
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Application Accelerator RAID Edition
"{929A59BE-1E16-41EF-88CA-1006DE77D480}" = RPS AntiSpyware
"{94A065E8-455D-41C1-AF1F-F0C1AF8F50F3}" = Microsoft IntelliType Pro 7.0
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95FC661A-A0C5-4B18-92CE-90347DA79CC9}" = Smart Menus (Windows Live Toolbar)
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A1BDA87-7C0D-4B3A-8C05-026FA41F188F}" = QuickTax 2001
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A296E88E-8459-4CF7-A7C8-AA65A04CAF75}" = RPS Zip
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A40D6757-B145-4FE7-B694-89180A9F3F64}" = Windows Live Outlook Toolbar (Windows Live Toolbar)
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{AA0D2D5F-612B-45D3-8759-DA87206E5CC9}" = QuickTax 2008
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{AC76BA86-7AD7-1033-7B44-A80000000002}" = Adobe Reader 8
"{ADAF6BDD-EC42-4239-B191-FDE6FFD6E1D6}" = ATI RADEON 9700 Car Paint Demo v1.1
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B21DE8E2-03E6-4CFD-A94D-95CC42CD49C8}" = RPS Backup
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B41FA933-8D07-4AD8-A3A7-F9AA394E93A8}" =
"{B607C354-CD79-4D22-86D1-92DC94153F42}" = Apple Application Support
"{B6DC0CAF-0D27-4ACE-8E34-8594C8D7C1DA}" = MMC85
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B747E7F6-7A2B-4E57-B6A5-AFF21325EE2D}" = ATI RADEON 9700 Bear Demo v1.1
"{B8D0BC3E-67DF-48A3-ACC9-EEAA8DBFBF29}" = QuickTax 2005
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDC74FE6-5224-11D6-B27F-00E0181A6FA8}" = D-Link AirPlus
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0C5C43F-C534-4A35-AC67-98E64242A3FF}" = RPS AntiFraud
"{D1A74FBB-CA8D-4CCA-9B89-BAAA436DB178}" = iTunes
"{D1AD7439-FBCA-4345-A780-2A5617EBA9DE}" = neoDVDplus5
"{D3661269-10B6-495F-B4EE-539ABE3F9AA9}" = DVDDec
"{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}" = Windows Live Favorites for Windows Live Toolbar
"{DF821FC5-C198-452B-A0D4-82433EFEAE9B}" = OneCare Advisor (Windows Live Toolbar)
"{E1374244-A8FE-4FDF-B823-184061FE16C5}" = RPS PopupBlocker
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E503069C-7681-4AEF-ADBD-131957FE5D6D}" = Quicken 2008
"{ECDA9BD9-A54E-462A-8191-A2B569D9AB34}" = Map Button (Windows Live Toolbar)
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EE8B9C76-1E07-4C26-8587-8184024FA345}" = Hoyle Card Games 2005
"{EED7DDDC-A01A-4A0D-884A-272C02E96903}" = RPS Firewall
"{EF71A531-5B6C-4B20-8D1E-E6379C7FB6D3}" = Microsoft IntelliPoint 7.0
"{F06D2782-4C7B-4778-901D-79D63E1B9BB9}" = RPS AntiVirus
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8B6FBC3-C28F-49D9-A00A-16283E9A1180}" = ATI RADEON 9700 Pipe Dream Demo v1.1
"{FAFDA89B-1031-4BDB-8619-DE20CBDEDF32}" = QuickTax 2006
"{FDDA11D6-00DE-4957-8761-F97145F438B7}" = RPS RpsCore
"7-Zip" = 7-Zip 4.65
"8461-7759-5462-8226" = Vuze
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Ask Toolbar_is1" = Vuze Toolbar
"Browser Defender_is1" = Browser Defender 2.0.6.15
"ClickArt 10,000 Image Pack 1.0" = ClickArt® 10,000 Image Pack
"ClickArt Gallery 1.0" = ClickArt® Gallery
"DSMT6" = MathType 6
"Hollywood FX 4.6" = Pinnacle Hollywood FX 4.6
"Hoyle Casino 4" = Hoyle Casino 4
"hp officejet g series 1080896469" = hp officejet g series
"ICCup Launcher_is1" = ICCup Launcher
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{07A540AB-D785-11D5-8E89-0090275862A0}" = Corel Graphics Suite 11
"InstallShield_{6924B6B2-EEA2-441D-A939-A6C26EE278F9}" = ATI Remote Wonder 1.5
"InstallShield_{B6DC0CAF-0D27-4ACE-8E34-8594C8D7C1DA}" = ATI Multimedia Center [removed]
"InstallShield_{C88E49AA-41C5-4420-A08D-BE1B6C5A3A74}" = DAO
"InstallShield_{D1AD7439-FBCA-4345-A780-2A5617EBA9DE}" = neoDVDplus
"InstallShield_{D3661269-10B6-495F-B4EE-539ABE3F9AA9}" = ATI DVD Decoder 2.2.0.0
"Lexmark_HostCD" = Lexmark Software Uninstall
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MGI_PRISM_V4_0" = MGI PhotoSuite 4 (Remove Only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Pinnacle Hollywood FX Pack - ATI FX" = Pinnacle Hollywood FX Pack - ATI FX
"PROSet" = Intel® PRO Network Adapters and Drivers
"P-touch Editor ver 3.2" = P-touch Editor 3.2
"RadialpointClientGateway_is1" = TELUS security advisor 2.0.21
"SiSoftware Sandra Professional MAX3! (Jagged Onl~74D864A4_is1" = SiSoftware Sandra Professional MAX3! (Jagged Online Ltd Edition
"SmartSuite V98.0" = Lotus SmartSuite Release 9
"Spyware Doctor" = Spyware Doctor 7.0
"Starcraft" = Starcraft
"VLC media player" = VLC media player 1.0.3
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WolfTeam International_is1" = WolfTeam International
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 11/22/2008 5:39:44 AM | Computer Name = NUMBER-ONE | Source = WinMgmt | ID = 24
Description = Event provider attempted to register query "SELECT * FROM PDEvent"
whose target class "PDEvent" does not exist. The query will be ignored.
[ System Events ]
Error - 3/21/2010 6:19:13 AM | Computer Name = NUMBER-ONE | Source = Print | ID = 23
Description = Printer Microsoft Office Document Image Writer failed to initialize
because a suitable Microsoft Office Document Image Writer Driver driver could not
be found.
Error - 3/21/2010 6:19:30 AM | Computer Name = NUMBER-ONE | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 3/21/2010 6:19:30 AM | Computer Name = NUMBER-ONE | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 3/21/2010 1:43:35 PM | Computer Name = NUMBER-ONE | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.
Error - 3/21/2010 1:43:35 PM | Computer Name = NUMBER-ONE | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 3/21/2010 1:43:35 PM | Computer Name = NUMBER-ONE | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 3/21/2010 1:43:43 PM | Computer Name = NUMBER-ONE | Source = Print | ID = 23
Description = Printer Microsoft Office Document Image Writer failed to initialize
because a suitable Microsoft Office Document Image Writer Driver driver could not
be found.
Error - 3/21/2010 5:40:40 PM | Computer Name = NUMBER-ONE | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
Error - 3/22/2010 1:59:36 AM | Computer Name = NUMBER-ONE | Source = NetBT | ID = 4321
Description = The name "HOME :1d" could not be registered on the Interface
with IP address 192.168.0.101. The machine with the IP address 192.168.0.102 did
not allow the name to be claimed by this machine.
Error - 3/22/2010 2:14:06 AM | Computer Name = NUMBER-ONE | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
JUSTINWONG-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{828DF857-0552-. The master browser is stopping or an election is being
forced.
OTL logfile created on: 3/22/2010 4:36:36 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = D:\Documents and Settings\Dad\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 392.00 Mb Available Physical Memory | 38.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 66.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 29.30 Gb Free Space | 60.00% Space Free | Partition Type: NTFS
Drive D: | 249.26 Gb Total Space | 182.49 Gb Free Space | 73.21% Space Free | Partition Type: NTFS
Drive E: | 624.83 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NUMBER-ONE
Current User Name: Dad
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
@Alternate Data Stream - 163 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >
There is also suppose to be a firefox log information after IE, but for some reason, every time I try and post it, I get a "the connection was reset". I'm only getting it when the firefox logs are included.
I'm only getting it when the firefox logs are included.
Try posting the logs again but now attach it. Thanks.
–Next–
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
On the File Upload window, copy/paste the text below into the File name box: C:\WINDOWS\System32\drivers\PciBus.sys
Click Submit. Allow the file to be scanned. If it says already scanned – click Reanalyze Now
Repeat the procedure with the following file: C:\WINDOWS\System32\32askey.dll
Please post the results in your next reply.
–Next–
Can you tell me more about these files (don't double click on them)? D:\Documents and Settings\Dad\Desktop\fix.reg
D:\Documents and Settings\Dad\Desktop\exefix.reg
D:\Documents and Settings\Dad\Desktop\ecefix.reg
–Next–
Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
The application window will appear
Click the Disable button to disable your CD Emulation drivers
Click Yes to continue
A 'Finished!' message will appear
Click OK
DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop. Do not re-enable these drivers until otherwise instructed.
–Next–
Try running GMER again, click on "Files" on the right hand corner to uncheck it, if that fails, try running it in safe mode.
To do this,
Restart your computer.
Keep on tapping f8 when windows starts to boot. Do this before you see the windows screen.
When a list of menu appears, scroll to Safe Mode using the arrow keys then press Enter.
To post in your next reply:
1. OTL log with the firefox section.
2. VirSCAN log.
3. About those .reg files.
4. Defogger log.
5. GMER log.