OK lets start
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL
IE - HKU\S-1-5-21-2100727508-797518319-1439027893-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..network.proxy.type: 1
[2010/06/21 23:24:49 | 000,001,456 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\WebSearchober11054012.xml
O2:64bit: - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner64.dll (Google Inc.)
O2 - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll (Google Inc.)
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [RTHDBPL] C:\Users\jerry\AppData\Roaming\SystemProc\lsass.exe File not found
O20 - AppInit_DLLs: (C:\Windows\system32\dsdmo32.dll) - C:\Windows\SysWOW64\dsdmo32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\crtdll32.dll) - C:\Windows\SysWOW64\crtdll32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\dbnetlib32.dll) - C:\Windows\SysWOW64\dbnetlib32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\dmutil32.dll) - C:\Windows\SysWOW64\dmutil32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\dskquoui32.dll) - C:\Windows\SysWOW64\dskquoui32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\cryptbase32.dll) - C:\Windows\SysWOW64\cryptbase32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\dbnmpntw32.dll) - C:\Windows\SysWOW64\dbnmpntw32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\dmutil3232.dll) - C:\Windows\SysWOW64\dmutil3232.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\dskquoui32.dllgo4t9zy32.dll) - C:\Windows\SysWOW64\dskquoui32.dllgo4t9zy32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\cryptsvc32.dll) - C:\Windows\SysWOW64\cryptsvc32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\dskquoui32.dllgo4t9zy32.dll0dp1v5e1t32.dll) - C:\Windows\SysWOW64\dskquoui32.dllgo4t9zy32.dll0dp1v5e1t32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\docprop32.dll) - C:\Windows\SysWOW64\docprop32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\dskquoui32.dllgo4t9zy32.dll0dp1v5e1t32.dllpcqoeo32.dll) - C:\Windows\SysWOW64\dskquoui32.dllgo4t9zy32.dll0dp1v5e1t32.dllpcqoeo32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\docprop32.dlln1sanjmrrcm32.dll) - C:\Windows\SysWOW64\docprop32.dlln1sanjmrrcm32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\dskquoui32.dllgo4t9zy32.dll0dp1v5e1t32.dllpcqoeo32.dllb1eo2c23whe9o932.dll) - C:\Windows\SysWOW64\dskquoui32.dllgo4t9zy32.dll0dp1v5e1t32.dllpcqoeo32.dllb1eo2c23whe9o932.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\docprop32.dlln1sanjmrrcm32.dllxv7jv32.dll) - C:\Windows\SysWOW64\docprop32.dlln1sanjmrrcm32.dllxv7jv32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\docprop32.dlln1sanjmrrcm32.dllxv7jv32.dll441t6xoa7apn32.dll) - C:\Windows\SysWOW64\docprop32.dlln1sanjmrrcm32.dllxv7jv32.dll441t6xoa7apn32.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\docprop32.dlln1sanjmrrcm32.dllxv7jv32.dll441t6xoa7apn32.dll6e70uamlt32.dll) - C:\Windows\SysWOW64\docprop32.dlln1sanjmrrcm32.dllxv7jv32.dll441t6xoa7apn32.dll6e70uamlt32.dll ()
2010/05/08 14:39:37 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\docprop32.dlln1sanjmrrcm32.dllxv7jv32.dll441t6xoa7apn32.dll6e70uamlt32.dll
[2010/05/08 14:39:07 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\docprop32.dlln1sanjmrrcm32.dllxv7jv32.dll441t6xoa7apn32.dll
[2010/05/08 14:38:48 | 000,285,696 | ---- | C] () -- C:\Windows\SysWow64\dsound32.dll
[2010/05/08 14:38:36 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\docprop32.dlln1sanjmrrcm32.dllxv7jv32.dll
[2010/05/08 14:38:18 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\dskquoui32.dllgo4t9zy32.dll0dp1v5e1t32.dllpcqoeo32.dllb1eo2c23whe9o932.dll
[2010/05/08 14:38:06 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\docprop32.dlln1sanjmrrcm32.dll
[2010/05/08 14:37:48 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\dskquoui32.dllgo4t9zy32.dll0dp1v5e1t32.dllpcqoeo32.dll
[2010/05/08 14:37:36 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\docprop32.dll
[2010/05/08 14:37:18 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\dskquoui32.dllgo4t9zy32.dll0dp1v5e1t32.dll
[2010/05/08 14:37:06 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\cryptsvc32.dll
[2010/05/08 14:36:47 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\dskquoui32.dllgo4t9zy32.dll
[2010/05/08 14:36:35 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\dmutil3232.dll
[2010/05/08 14:36:17 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\dbnmpntw32.dll
[2010/05/08 14:36:05 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\cryptbase32.dll
[2010/05/08 14:35:47 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\dskquoui32.dll
[2010/05/08 14:35:35 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\dmutil32.dll
[2010/05/08 14:35:17 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\dbnetlib32.dll
[2010/05/08 14:35:05 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\crtdll32.dll
[2010/05/08 14:34:46 | 000,190,464 | ---- | C] () -- C:\Windows\SysWow64\dsdmo32.dll
:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN
http://img233.imageshack.us/img233/7729/mbamicontw5.gif
Please download Malwarebytes’ Anti-Malware from Here.
Double Click mbam-setup.exe to install the application.
[*]Make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.
[*]If an update is found, it will download and install the latest version.
[*]Once the program has loaded, select “Perform Quick Scan”, then click Scan.
[*]The scan may take some time to finish,so please be patient.
[*]When the scan is complete, click OK, then Show Results to view the results.
[*]Make sure that everything is checked, and click Remove Selected.
[]When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
[]The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
[*]Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.