This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

virus help

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'll start off by saying a don't have much knowledge of computers outside of the basics. I think my network has been infected with a virus. All of the computers on the network are having the same problem. When I open a webpage on any browser, ie or firefox, it says something along the lines of this webpage does not support your web browswer versions, browser update available. When I go to page source it says something about bank of nikolai and I have a pen. I ran malwarebytes and nothing was found. Any help would be much appreciated. Thanks in advance. Here's my registry.

OTL logfile created on: 8/25/2011 7:30:19 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\g\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.96 Mb Total Physical Memory | 218.13 Mb Available Physical Memory | 21.51% Memory free
2.39 Gb Paging File | 1.48 Gb Available in Paging File | 61.78% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.28 Gb Total Space | 10.62 Gb Free Space | 14.30% Space Free | Partition Type: NTFS
Drive E: | 232.89 Gb Total Space | 149.05 Gb Free Space | 64.00% Space Free | Partition Type: NTFS

Computer Name: G-BPTAEDB76DI1P | User Name: g | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\g\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\PdaNet for Android\PdaNetPC.exe ()
PRC - C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - \\?\globalroot\device\harddiskvolume1\windows\temp\srv804.tmp ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\PdaNet for Android\PdaNetPC.exe ()
MOD - C:\WINDOWS\BDTSupport.dll ()
MOD - C:\Program Files\Spyware Doctor\avengine\sdkBSCtrl.dll ()
MOD - C:\Program Files\Spyware Doctor\UserModeFileCache.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Spyware Doctor\NetworkLayer\PCTCFHook.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\IntStngs.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\acAuth.dll ()


========== Win32 Services (SafeList) ==========

SRV - (RasAuto32) – File not found
SRV - (HidServ) – File not found
SRV - (srv804) – \\?\globalroot\Device\HarddiskVolume1\WINDOWS\Temp\srv804.tmp [WARNING: \\?\globalroot\Device\HarddiskVolume1\WINDOWS\Temp\srv804.tmp] ()
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)


========== Driver Services (SafeList) ==========

DRV - (pneteth) – C:\WINDOWS\system32\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV - (Netaapl) – C:\WINDOWS\system32\drivers\netaapl.sys (Apple Inc.)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (AndDiag) – C:\WINDOWS\system32\drivers\lganddiag.sys (LG Electronics Inc.)
DRV - (AndGps) – C:\WINDOWS\system32\drivers\lgandgps.sys (LG Electronics Inc.)
DRV - (ANDModem) – C:\WINDOWS\system32\drivers\lgandmodem.sys (LG Electronics Inc.)
DRV - (Andbus) – C:\WINDOWS\system32\drivers\lgandbus.sys (LG Electronics Inc.)
DRV - (androidusb) – C:\WINDOWS\system32\drivers\lgandadb.sys (Google Inc)
DRV - (motccgp) – C:\WINDOWS\system32\drivers\motccgp.sys (Motorola)
DRV - (motusbdevice) – C:\WINDOWS\system32\drivers\motusbdevice.sys (Motorola Inc)
DRV - (motccgpfl) – C:\WINDOWS\system32\drivers\motccgpfl.sys (Motorola)
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (BTCFilterService) – C:\WINDOWS\system32\drivers\motfilt.sys (Motorola Inc)
DRV - (Motousbnet) – C:\WINDOWS\system32\drivers\Motousbnet.sys (Motorola)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (MotoSwitchService) – C:\WINDOWS\system32\drivers\motswch.sys (Motorola)
DRV - (pgfilter) – C:\Program Files\PeerGuardian2\pgfilter.sys ()
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 76 67 3C 0E EF 34 A2 4B 8E 5F 61 04 3B 87 C4 4E [binary data]
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\..\URLSearchHook: {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll (America Online, Inc.)
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "Conduit Engine Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=ConduitEngine&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Conduit Engine Customized Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: [removed]:1.1.1
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\3.0.50106.0\npctrl.dll ( Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/01/27 14:41:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/06/15 10:54:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/06/15 10:54:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 12\components [2011/06/18 10:52:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 12\plugins [2011/06/15 10:54:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/08/25 19:16:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/18 11:12:37 | 000,000,000 | —D | M]

[2009/11/27 01:02:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\g\Application Data\Mozilla\Extensions
[2009/11/27 01:02:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\g\Application Data\Mozilla\Extensions\[removed]
[2011/08/22 12:47:56 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\ofyymiss.default\extensions
[2011/07/09 13:39:34 | 000,000,000 | —D | M] (XUL Cache) – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\ofyymiss.default\extensions\{1545ccc1-ae0e-4ef5-90a6-f48da8411a70}
[2011/07/13 17:06:15 | 000,000,000 | —D | M] (XUL Cache) – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\ofyymiss.default\extensions\{3780059c-a491-4b41-8dc2-f6b65cfca204}
[2011/08/20 13:16:24 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\ofyymiss.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/08/15 12:24:03 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\ofyymiss.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/04/17 21:54:46 | 000,000,000 | —D | M] (Download Statusbar) – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\ofyymiss.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2011/03/23 21:55:12 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\ofyymiss.default\extensions\[removed]
[2009/12/02 18:10:48 | 000,004,554 | —- | M] () – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\ofyymiss.default\searchplugins\aim-search.xml
[2010/09/10 14:10:50 | 000,002,253 | —- | M] () – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\ofyymiss.default\searchplugins\askcom.xml
[2010/12/06 23:23:57 | 000,000,913 | —- | M] () – C:\Documents and Settings\g\Application Data\Mozilla\Firefox\Profiles\ofyymiss.default\searchplugins\conduit.xml
[2011/06/18 11:12:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/09/13 16:27:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\G\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OFYYMISS.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\G\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OFYYMISS.DEFAULT\EXTENSIONS\[removed]
[2009/11/27 01:01:40 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/08/25 19:16:12 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/12/09 06:47:06 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2011/08/25 19:15:51 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2001/08/23 11:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {0E3C6776-34EF-4BA2-8E5F-61043B87C44e} - File not found
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AOLSearchHook Class) - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll (America Online, Inc.)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [1A:Stardock TrayMonitor] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\RunServices: [1A:Stardock TrayMonitor] File not found
O4 - HKLM..\RunServices: [AccessAccess] File not found
O4 - HKLM..\RunServices: [Accessjnidispatch] File not found
O4 - HKLM..\RunServices: [JavaTMjnidispatch] File not found
O4 - HKLM..\RunServices: [JavaTMNative] File not found
O4 - HKLM..\RunServices: [jinstallAccess] File not found
O4 - HKLM..\RunServices: [jnidispatchAccess] File not found
O4 - HKLM..\RunServices: [jnidispatchNative] File not found
O4 - HKLM..\RunServices: [jnidispatchSetup3.2.1] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {32564D57-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmv8dmo.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Filter\video/x-flv {08C72DD4-19AD-49f1-83DA-8542B4D302C5} - Reg Error: Key error. File not found
O20 - AppInit_DLLs: (C:\WINDOWS\system32\kbduk32.dll) - C:\WINDOWS\system32\kbduk32.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSTEM32\Userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\g\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\g\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/20 12:49:33 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: srv804 - \\?\globalroot\Device\HarddiskVolume1\WINDOWS\Temp\srv804.tmp ()
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - ffdshow.ax File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/08/18 19:07:34 | 000,000,000 | —D | C] – C:\Documents and Settings\g\My Documents\My Kindle Content
[2011/08/18 19:06:59 | 000,000,000 | —D | C] – C:\Documents and Settings\g\Start Menu\Programs\Amazon
[2011/08/18 19:06:59 | 000,000,000 | —D | C] – C:\Documents and Settings\g\Local Settings\Application Data\Amazon
[2011/08/18 19:06:40 | 000,000,000 | —D | C] – C:\Program Files\Amazon
[2011/08/17 15:24:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Comical
[2011/08/17 15:24:51 | 000,000,000 | —D | C] – C:\Program Files\Comical
[2011/08/16 16:01:56 | 000,000,000 | —D | C] – C:\Documents and Settings\g\Application Data\vlc
[2011/08/16 15:51:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2011/08/16 15:51:06 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2011/08/14 23:01:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware2
[2011/08/14 23:00:55 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware2
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\g\*.tmp files -> C:\Documents and Settings\g\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/25 19:14:45 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/08/25 19:12:49 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/08/25 19:12:46 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/08/25 17:31:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/08/25 17:31:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2011/08/25 11:31:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2011/08/25 05:31:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2011/08/24 23:31:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2011/08/22 23:12:08 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/18 19:07:03 | 000,001,635 | —- | M] () – C:\Documents and Settings\g\Desktop\Kindle.lnk
[2011/08/16 15:51:50 | 000,000,719 | —- | M] () – C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2011/08/14 23:56:13 | 000,054,016 | —- | M] () – C:\WINDOWS\System32\drivers\fwlcfjsd.sys
[2011/08/14 22:54:28 | 000,000,270 | —- | M] () – C:\Documents and Settings\g\Desktop\Shortcut to wqhat.lnk
[2011/08/14 22:13:19 | 000,000,100 | —- | M] () – C:\WINDOWS\System32\584423031
[2011/08/12 03:20:47 | 000,000,206 | —- | M] () – C:\WINDOWS\System32\8fb8607
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\g\*.tmp files -> C:\Documents and Settings\g\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/18 19:07:03 | 000,001,635 | —- | C] () – C:\Documents and Settings\g\Desktop\Kindle.lnk
[2011/08/16 15:51:50 | 000,000,719 | —- | C] () – C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2011/08/15 15:27:47 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/08/14 23:56:13 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\fwlcfjsd.sys
[2011/08/14 22:54:27 | 000,000,270 | —- | C] () – C:\Documents and Settings\g\Desktop\Shortcut to wqhat.lnk
[2011/07/08 17:55:30 | 000,257,536 | —- | C] () – C:\WINDOWS\System32\kbduk32.dll
[2011/01/26 12:54:01 | 006,814,952 | —- | C] () – C:\WINDOWS\System32\SpoonUninstall.exe
[2011/01/26 12:54:01 | 000,017,766 | —- | C] () – C:\WINDOWS\System32\SpoonUninstall-dBpoweramp Music Converter.dat
[2010/07/11 15:30:04 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/06/16 06:08:24 | 000,000,745 | —- | C] () – C:\Documents and Settings\g\Application Data\AtomicAlarmClock.ini
[2010/06/16 06:07:18 | 000,000,492 | —- | C] () – C:\Documents and Settings\g\Local Settings\Application Data\Notes.stt
[2010/06/16 06:07:18 | 000,000,117 | —- | C] () – C:\Documents and Settings\g\Local Settings\Application Data\Reminders.stt
[2010/04/14 15:24:48 | 000,001,128 | -HS- | C] () – C:\Documents and Settings\g\Local Settings\Application Data\6Y5qPA2XU80
[2010/04/14 15:24:48 | 000,001,128 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\6Y5qPA2XU80
[2010/02/10 16:22:39 | 000,767,928 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2010/01/23 18:39:01 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\26490.exe
[2010/01/18 19:35:36 | 000,015,360 | —- | C] () – C:\Documents and Settings\g\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/03 16:50:57 | 000,025,556 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/12/02 22:58:54 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/11/15 15:59:52 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/10/21 16:50:34 | 000,006,688 | —- | C] () – C:\WINDOWS\System32\Digita.sys
[2009/10/21 16:50:33 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\TransportUSB.dll
[2009/10/21 16:50:33 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\TransportSerial.dll
[2009/10/21 16:50:32 | 000,335,872 | —- | C] () – C:\WINDOWS\System32\ldf252.dll
[2009/10/20 16:21:48 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\RTHDAEQ1.dat
[2009/10/20 16:21:48 | 000,000,176 | —- | C] () – C:\WINDOWS\System32\drivers\RTHDAEQ0.dat
[2009/10/20 16:21:46 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2009/10/20 16:21:46 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2009/10/20 13:35:25 | 000,000,453 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/10/20 12:51:51 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/10/20 12:46:08 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/10/19 19:39:26 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/10/19 19:38:12 | 000,143,624 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2007/08/09 07:26:44 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\ac3config.exe
[2006/12/31 08:57:08 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/11/02 11:10:16 | 000,080,912 | —- | C] () – C:\WINDOWS\System32\sherlock2.exe
[2005/10/14 05:56:50 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/10/14 05:56:50 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 05:56:50 | 000,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 05:56:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2005/10/14 05:56:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2005/10/14 05:56:50 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2005/10/14 05:56:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/08/29 03:57:58 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/08/23 12:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 12:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 11:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 11:00:00 | 000,312,172 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 11:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 11:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 11:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 11:00:00 | 000,040,394 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 11:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 11:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2009/12/02 18:06:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2009/12/02 18:06:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM Toolbar
[2011/08/25 19:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/02 14:14:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/02 23:03:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/12/02 18:06:35 | 000,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\acccore
[2009/10/21 16:50:05 | 000,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\ACD Systems
[2009/10/21 16:49:16 | 000,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\ACDInTouch
[2011/06/15 11:00:22 | 000,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\DDMSettings
[2011/03/19 16:51:30 | 000,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\FrostWire
[2011/08/25 19:14:10 | 000,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\LimeWire
[2011/02/17 03:07:08 | 000,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\Smith Micro
[2011/08/25 19:10:48 | 000,000,000 | —D | M] – C:\Documents and Settings\g\Application Data\uTorrent
[2011/08/25 17:31:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2011/08/24 23:31:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2011/08/25 05:31:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2011/08/25 11:31:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2011/08/25 17:31:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/02/10 16:25:42 | 000,012,484 | —- | M] () – C:\aaw7boot.log
[2009/10/20 12:49:33 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/12/02 22:29:36 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2009/10/20 12:49:33 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/10/20 12:49:33 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/12/02 18:06:31 | 000,000,377 | -H– | M] () – C:\IPH.PH
[2010/01/07 17:07:10 | 001,394,000 | —- | M] (Malwarebytes Corporation) – C:\mbam.exe
[2010/01/28 18:23:48 | 000,000,802 | —- | M] () – C:\mirror_download.php
[2009/10/20 12:49:33 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/12/02 22:20:03 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/12/02 22:20:03 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/08/25 19:12:41 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2010/01/28 18:02:35 | 034,630,056 | —- | M] (PC Tools ) – C:\pepper11.exe
[2010/01/23 20:08:54 | 000,001,594 | —- | M] () – C:\RemoveWGA.exe.htm
[2009/11/30 20:32:28 | 000,000,145 | —- | M] () – C:\Shortcut to CD Drive.lnk
[2010/01/23 17:58:44 | 001,872,472 | —- | M] () – C:\SmitfraudFix.exe
[2010/02/10 15:19:04 | 000,040,926 | —- | M] () – C:\TDSSKiller.2.2.3_10.02.2010_14.19.03_log.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/10/20 12:49:08 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/10/19 19:37:26 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/10/19 19:37:26 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/10/19 19:37:26 | 000,425,984 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/12/02 22:28:40 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/02 22:58:04 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\g\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/10/20 13:12:39 | 000,000,079 | —- | M] () – C:\Documents and Settings\g\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2006/07/05 17:12:00 | 000,186,880 | —- | M] (CEXX.ORG) – C:\Documents and Settings\g\Desktop\LSPFix.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-04-15 07:01:54

========== Alternate Data Streams ==========

@Alternate Data Stream - 206 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >

OTL Extras logfile created on: 8/25/2011 7:30:19 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\g\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.96 Mb Total Physical Memory | 218.13 Mb Available Physical Memory | 21.51% Memory free
2.39 Gb Paging File | 1.48 Gb Available in Paging File | 61.78% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.28 Gb Total Space | 10.62 Gb Free Space | 14.30% Space Free | Partition Type: NTFS
Drive E: | 232.89 Gb Total Space | 149.05 Gb Free Space | 64.00% Space Free | Partition Type: NTFS

Computer Name: G-BPTAEDB76DI1P | User Name: g | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\Program Files\ACD Systems\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"67:UDP" = 67:UDP:*:Enabled:DHCP Server

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\stobject32.exe" = C:\WINDOWS\system32\stobject32.exe:*:Enabled:Windows Update Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (AOL LLC)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Winamp\winamp.exe" = C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp – (Nullsoft, Inc.)
"C:\WINDOWS\system32\stobject32.exe" = C:\WINDOWS\system32\stobject32.exe:*:Enabled:Windows Update Service


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00170409-78E1-11D2-B60F-006097C998E7}" = Microsoft Word 2000
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = MSN Toolbar
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08DEC21F-F7E5-46F9-81D1-3ED30BD3AEC9}" = CASIO USB Driver V1.2.2474.0623
"{0DB93918-2A77-11D3-805A-00C04FA329AA}" = Word in Works Suite add-in
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{2656D0AB-9EA4-4C58-A117-635F3CED8B93}" = Microsoft UI Engine
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 18
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56364334-9530-11D2-BFFC-00C04FA329AA}" = Microsoft Works 2000
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5D51C5DC-3604-4C3B-981B-309340755447}" = Pantech Handset Driver
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61BEA823-ECAF-49F1-8378-A59B3B8AD247}" = Microsoft Default Manager
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7E6066E6-8B5B-4100-B0FA-1D9E9B663CBA}" = iTunes
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86B32074-0F48-4CF9-BA4B-529B470FB47F}" = BlackBerry Desktop Software 5.0
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{90CC4231-94AC-45CD-991A-0253BFAC0650}" = mDrWiFi
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A65F7CF8-6F76-40CE-B44D-D5A89D9881C7}" = MSN Toolbar Platform
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.4.2 MUI
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F843C6A3-224D-4615-94F8-3C461BD9AEA0}" = Jasc Paint Shop Pro 9
"{F8A3C1B6-D2E0-4CE1-80A2-555D6F71C639}" = Microsoft Search Enhancement Pack
"{FB068BA4-C6EA-4D47-A491-C40E23E77F89}" = Motorola Driver Installation 3.9.0
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FDF64A37-4842-48CD-A424-2C38444D36FD}" = LG Android Drivers
"7-Zip" = 7-Zip 4.65
"ACDSee" = ACDSee
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIM Search" = AIM Search
"AIM Toolbar" = AIM Toolbar
"AIM_7" = AIM 7
"Amazon Kindle" = Amazon Kindle
"audcle" = Plus! MP3 Audio Converter LE
"BlackBerry_{86B32074-0F48-4CF9-BA4B-529B470FB47F}" = BlackBerry Desktop Software 5.0
"Browser Defender_is1" = Browser Defender 2.0.6.15
"CCleaner" = CCleaner
"Comical_is1" = Comical 0.8
"conduitEngine" = Conduit Engine
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"DivX Setup.divx.com" = DivX Setup
"drmtool.inf" = Personal License Update Wizard for Windows Media Player
"Free M4a to MP3 Converter_is1" = Free M4a to MP3 Converter 6.2
"HijackThis" = HijackThis 2.0.2
"HTC_WModemDriver" = WModem Driver Installer
"InstallShield_{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"LimeWire" = LimeWire 5.5.16
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"mmmusic" = Movie Maker Background Music Files
"mmsounds" = Movie Maker Sound Effects
"mmtitle" = Movie Maker Title Images
"Mozilla Firefox 5.0 (x86 en-US)" = Mozilla Firefox 5.0 (x86 en-US)
"Mozilla Firefox 6.0 (x86 en-US)" = Mozilla Firefox 6.0 (x86 en-US)
"mplibwiz.inf" = Media Library Management Wizard
"mpxlswiz.inf" = Windows Media Player Playlist Import to Excel Wizard
"mpxptray.inf" = Windows Media Player Tray Control
"PdaNet_is1" = PdaNet for Android 2.45
"PeerGuardian_is1" = PeerGuardian 2.0
"PicaView" = PicaView
"ProInst" = Intel® PROSet/Wireless Software
"PROSet" = Intel® PRO Network Connections Drivers
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Spyware Doctor" = Spyware Doctor 7.0
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"VLC media player" = VLC media player 1.1.11
"wa2wmp" = Windows Media Player Skin Importer
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"winusb0100" = Microsoft WinUsb 1.0
"WMBK2" = Windows Media Bonus Pack for Windows XP
"WMFDist11" = Windows Media Format 11 runtime
"Works2kSetup" = Microsoft Works 2000 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/8/2011 2:02:36 PM | Computer Name = G-BPTAEDB76DI1P | Source = Application Hang | ID = 1002
Description = Hanging application winamp.exe, version 5.6.0.3091, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 6/8/2011 4:34:21 PM | Computer Name = G-BPTAEDB76DI1P | Source = Application Hang | ID = 1002
Description = Hanging application winamp.exe, version 5.6.0.3091, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 6/8/2011 5:57:14 PM | Computer Name = G-BPTAEDB76DI1P | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/8/2011 5:57:14 PM | Computer Name = G-BPTAEDB76DI1P | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/8/2011 10:07:06 PM | Computer Name = G-BPTAEDB76DI1P | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/8/2011 10:07:06 PM | Computer Name = G-BPTAEDB76DI1P | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/9/2011 4:28:57 PM | Computer Name = G-BPTAEDB76DI1P | Source = Application Hang | ID = 1002
Description = Hanging application winamp.exe, version 5.6.0.3091, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 6/9/2011 4:45:41 PM | Computer Name = G-BPTAEDB76DI1P | Source = Application Hang | ID = 1002
Description = Hanging application winamp.exe, version 5.6.0.3091, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 6/9/2011 9:22:46 PM | Computer Name = G-BPTAEDB76DI1P | Source = Application Hang | ID = 1002
Description = Hanging application winamp.exe, version 5.6.0.3091, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 6/15/2011 11:06:05 AM | Computer Name = G-BPTAEDB76DI1P | Source = Application Hang | ID = 1002
Description = Hanging application winamp.exe, version 5.6.0.3091, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 8/25/2011 5:19:25 PM | Computer Name = G-BPTAEDB76DI1P | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 8/25/2011 5:19:27 PM | Computer Name = G-BPTAEDB76DI1P | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 8/25/2011 5:19:27 PM | Computer Name = G-BPTAEDB76DI1P | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 8/25/2011 5:25:17 PM | Computer Name = G-BPTAEDB76DI1P | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 8/25/2011 5:25:17 PM | Computer Name = G-BPTAEDB76DI1P | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 15 minutes. NtpClient has no source of accurate
time.

Error - 8/25/2011 6:49:48 PM | Computer Name = G-BPTAEDB76DI1P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 8/25/2011 6:50:02 PM | Computer Name = G-BPTAEDB76DI1P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 8/25/2011 6:50:02 PM | Computer Name = G-BPTAEDB76DI1P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 8/25/2011 6:50:02 PM | Computer Name = G-BPTAEDB76DI1P | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 8/25/2011 7:14:11 PM | Computer Name = G-BPTAEDB76DI1P | Source = Service Control Manager | ID = 7023
Description = The srv804 service terminated with the following error: %%127


< End of report >
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!



P2P - I see you have P2P software ( µTorrent and Limewire ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

If you choose to leave them on the machine, please refrain from using them while we are cleaning the machine to prevent further infection.



You mention that all the computers on your network have this issue. Can you please tell me how many computers there are on your network?
Depending on what we find, we may need to look at each machine after we've identified the malware. I only want to work with one machine at a time - I just want to know the possible scope of this.

I'm assuming you are using a router on your network. I'd like to have you do the following. If it resolves the immediate redirect problem that's great, but we still need to ensure the machines are not further infected.
If it does not help with the initial problem please let me know.

I would like to have you reset your router. Most routers have a reset pin hole on the back.

1. With the unit on, place an straightend paperclip into the hole on the back on the unit labeled Reset.
2. Hold the paperclip/reset down for 10 seconds and then release it.
3. The unit will reboot on its own.
4. As soon as the lights stop blinking, the unit is ready.
5. You may need to reinstall the router to regain your internet access.

Note: If you changed your password, it will be gone so refer to your user's guide for your router.

If you have not already done so after doing this, please go into your router's settings and change the default password to a stronger one.




I'd like to get a couple of more logs so I can be sure we get your machine as malware free as possible.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and the second file; Attach.txt.



Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that may have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one - make sure it is UNCHECKED)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI