When Starup the computer one proccess called "eroticw32.exe" open a lot of windows & popups. I search in wondows/profiles/starup and the registry and I can´t find anything. Additionally I run "SPYBOT" & "AD-AWARE" software and clean all the issue with them; but the problem continue. Attach you can find the Hijackthis log when you can fid all the proccess that the PC are running. Please, help me, I´m tired....
Logfile of HijackThis v1.98.2
Scan saved at 10:51:42 AM, on 11/9/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\Novadigm\RADEXECD.exe
C:\PROGRA~1\Novadigm\RADSCHED.exe
C:\PROGRA~1\Novadigm\RADSTGMS.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\wm.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SymTray.exe
C:\WINNT\system32\dpmw32.exe
C:\WINNT\system32\NWTRAY.EXE
C:\WINNT\system32\PRPCUI.exe
C:\Program Files\DELL\AccessDirect\dadapp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Netropa\Multimedia Keyboard\mmusbkb2.exe
C:\Program Files\Windows AdTools\WinAdTools.exe
C:\WINNT\system32\swxrqka.exe
C:\Program Files\Windows AdTools\WinRatchet.exe
C:\WINNT\system32\WLSSvc.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
C:\Documents and Settings\blackgw\Application Data\Map Maker\MMManager.exe
C:\WINNT\system32\taskmgr.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Registry Medic\RegMedical.exe
C:\WINNT\regedit.exe
D:\WUTemp\hijackthis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\rundll32.exe
C:\EroticW32.exe
C:\EroticW32.exe
C:\EroticW32.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by GrupoAlvica
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxyiv.fdnet.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fdnet.com;*fluormembers.com;141.197.*;10.*;mtfdlvweb1;*.icafd.com.mx;*.ihserc.com;*dupont.com;;127.0.0.1;<local>
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NDPS] C:\WINNT\system32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\DELL\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft media services] winmplayer.exe
O4 - HKLM\..\Run: [Microsoft Security Updater] bling.exe
O4 - HKLM\..\Run: [Secure Svc 7.0] WLSSvc.exe
O4 - HKLM\..\Run: [Windows AdTools] C:\Program Files\Windows AdTools\WinAdTools.exe
O4 - HKLM\..\Run: [uuqjitwgzydkb] C:\WINNT\system32\swxrqka.exe
O4 - HKLM\..\Run: [conscorr] C:\WINNT\conscorr.exe
O4 - HKLM\..\RunServices: [Microsoft media services] winmplayer.exe
O4 - HKLM\..\RunServices: [Microsoft Security Updater] bling.exe
O4 - HKLM\..\RunServices: [Secure Svc 7.0] WLSSvc.exe
O4 - HKLM\..\RunOnce: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
O4 - HKLM\..\RunOnce: [ICDRegOCX0] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX1] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX2] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX3] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX4] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX5] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX6] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX7] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX8] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX9] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX10] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKCU\..\Run: [Microsoft Security Updater] bling.exe
O4 - HKCU\..\Run: [Secure Svc 7.0] WLSSvc.exe
O4 - Startup: SunClock5.lnk = C:\Documents and Settings\blackgw\Application Data\Map Maker\MMManager.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Global Startup: Novell Login.lnk = C:\WINNT\system32\loginw32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Highlight - C:\WINNT\WEB\highlight.htm
O8 - Extra context menu item: &Links List - C:\WINNT\WEB\urllist.htm
O8 - Extra context menu item: &Web Search - C:\WINNT\WEB\selsearch.htm
O8 - Extra context menu item: I&mages List - C:\WINNT\Web\imglist.htm
O8 - Extra context menu item: Open Frame in &New Window - C:\WINNT\WEB\frm2new.htm
O8 - Extra context menu item: Zoom &In - C:\WINNT\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINNT\WEB\zoomout.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://grupoalvica.net
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = fdnet.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{485DE5F5-9F9A-45A2-BDB4-C748940C68A7}: NameServer = 200.44.32.12,200.44.32.13
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F930C43-30E1-4539-8682-3BD772E11119}: NameServer = 200.44.32.12,200.44.32.13
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = fdnet.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = fdnet.com
Logfile of HijackThis v1.98.2
Scan saved at 10:51:42 AM, on 11/9/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\Novadigm\RADEXECD.exe
C:\PROGRA~1\Novadigm\RADSCHED.exe
C:\PROGRA~1\Novadigm\RADSTGMS.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\wm.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SymTray.exe
C:\WINNT\system32\dpmw32.exe
C:\WINNT\system32\NWTRAY.EXE
C:\WINNT\system32\PRPCUI.exe
C:\Program Files\DELL\AccessDirect\dadapp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Netropa\Multimedia Keyboard\mmusbkb2.exe
C:\Program Files\Windows AdTools\WinAdTools.exe
C:\WINNT\system32\swxrqka.exe
C:\Program Files\Windows AdTools\WinRatchet.exe
C:\WINNT\system32\WLSSvc.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
C:\Documents and Settings\blackgw\Application Data\Map Maker\MMManager.exe
C:\WINNT\system32\taskmgr.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Registry Medic\RegMedical.exe
C:\WINNT\regedit.exe
D:\WUTemp\hijackthis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\rundll32.exe
C:\EroticW32.exe
C:\EroticW32.exe
C:\EroticW32.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by GrupoAlvica
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=proxyiv.fdnet.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.fdnet.com;*fluormembers.com;141.197.*;10.*;mtfdlvweb1;*.icafd.com.mx;*.ihserc.com;*dupont.com;;127.0.0.1;<local>
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NDPS] C:\WINNT\system32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\DELL\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft media services] winmplayer.exe
O4 - HKLM\..\Run: [Microsoft Security Updater] bling.exe
O4 - HKLM\..\Run: [Secure Svc 7.0] WLSSvc.exe
O4 - HKLM\..\Run: [Windows AdTools] C:\Program Files\Windows AdTools\WinAdTools.exe
O4 - HKLM\..\Run: [uuqjitwgzydkb] C:\WINNT\system32\swxrqka.exe
O4 - HKLM\..\Run: [conscorr] C:\WINNT\conscorr.exe
O4 - HKLM\..\RunServices: [Microsoft media services] winmplayer.exe
O4 - HKLM\..\RunServices: [Microsoft Security Updater] bling.exe
O4 - HKLM\..\RunServices: [Secure Svc 7.0] WLSSvc.exe
O4 - HKLM\..\RunOnce: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
O4 - HKLM\..\RunOnce: [ICDRegOCX0] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX1] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX2] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX3] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX4] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX5] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX6] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX7] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX8] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX9] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKLM\..\RunOnce: [ICDRegOCX10] rundll32.exe advpack.dll,RegisterOCX C:\WINNT\Downloaded Program Files\WinAdToolsX.dll
O4 - HKCU\..\Run: [Microsoft Security Updater] bling.exe
O4 - HKCU\..\Run: [Secure Svc 7.0] WLSSvc.exe
O4 - Startup: SunClock5.lnk = C:\Documents and Settings\blackgw\Application Data\Map Maker\MMManager.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Global Startup: Novell Login.lnk = C:\WINNT\system32\loginw32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Highlight - C:\WINNT\WEB\highlight.htm
O8 - Extra context menu item: &Links List - C:\WINNT\WEB\urllist.htm
O8 - Extra context menu item: &Web Search - C:\WINNT\WEB\selsearch.htm
O8 - Extra context menu item: I&mages List - C:\WINNT\Web\imglist.htm
O8 - Extra context menu item: Open Frame in &New Window - C:\WINNT\WEB\frm2new.htm
O8 - Extra context menu item: Zoom &In - C:\WINNT\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINNT\WEB\zoomout.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://grupoalvica.net
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = fdnet.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{485DE5F5-9F9A-45A2-BDB4-C748940C68A7}: NameServer = 200.44.32.12,200.44.32.13
O17 - HKLM\System\CCS\Services\Tcpip\..\{8F930C43-30E1-4539-8682-3BD772E11119}: NameServer = 200.44.32.12,200.44.32.13
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = fdnet.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = fdnet.com