DomPlayer

DomPlayer or also known as Adware.DomPlayer is an unwanted program that may download additional application that poses security risks. DomPlayer will be configured to run itself by modifying registry entries on the target computer. The program will embed itself on legitimate executable  files that are shared publicly on different file-sharing networks.

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista, Windows 7

How to Remove DomPlayer:

FIRST AID TO STOP DomPlayer:
When DomPlayer virus infects a computer, it will modify system settings and inject itself to legitimate Windows files. System Restore is the tool-to-go-to in bringing back clean files and restoring earlier configuration. If you have saved previous restore point, please restore Windows to an earlier date.

MANUAL REMOVAL OF DomPlayer:
1. If an anti-virus program is present, update the definition file.
2. Reboot Windows in Safe Mode
- After turning on the power, press F8 on the keyboard.
- From the menu, select Safe Mode.

3. Run a full system scan and clean/delete all infected file(s).
4. Delete/Modify any values added to the registry if present.
- To edit the registry, click on Start. Search or Run regedit.exe.

Note: For a complete guide on Safe Mode and Registry Editor, please see tutorial links on the sidebar.

5. Exit registry editor and restart Windows.

ADDITIONAL TOOLS AND PROGRAMS:

Scan with Norton Power Eraser:
A free removal tool from Norton Antivirus was developed to remove virus and unfamiliar threats without using the traditional AV signatures. Download the tool from this location and start scanning the computer for viruses.

Technical Details and Additional Information:

Other functionalities of this Virus:
- This program will install 3WPlater, another potentially unwanted application.
- It will dropped additional malicious files and add malicious registry entries.

Malicious Files Added by DomPlayer:
%UserProfile%\Desktop\DomPlayer.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DomPlayer\DomPlayer.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DomPlayer\Uninstall DomPlayer.lnk
%ProgramFiles%\DomPlayer\DomPlayer.exe
%ProgramFiles%\DomPlayer\settings.ini
%ProgramFiles%\DomPlayer\settings.stp
%ProgramFiles%\DomPlayer\SkinCrafterDll.dll
%ProgramFiles%\DomPlayer\skins\PlayerSkin.skf
%ProgramFiles%\DomPlayer\test.gif
%ProgramFiles%\DomPlayer\unins000.dat
%ProgramFiles%\DomPlayer\unins000.exe
%ProgramFiles%\DomPlayer\WakeService.exe

File Location for Windows Versions:

  • %UserProfile% for Vista/7 user is C:\Users\<Current User> for Windows Vista/7, for Windows XP/2000 this is C:\Documents and Settings\<Current User>.

Associated Windows Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”DomPlayer Service” = “C:\Program Files\DomPlayer\wakeservice.exe”

What to do next...