This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus or malware

61 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ducks won 1 -0 . Good game. Hubby says boring. Only one fight. Look what popped up! DDS (Ver_10-10-21.02) - NTFS_AMD64 Run by [removed] at 16:01:25.58 on Wed 11/10/2010 Internet Explorer: 8.0.6001.18975 BrowserJavaVersion: 1.6.0_22 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4093.1274 [GMT -8:00] AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\AERTSr64.exe C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\McShield.exe C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE C:\Windows\system32\svchost.exe -k imgsvc C:\ProgramData\UltraVNC\winvnc.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Windows\system32\WUDFHost.exe C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe C:\ProgramData\UltraVNC\winvnc.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RAVCpl64.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\Microsoft Office\Office\OSA.EXE C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Windows\splwow64.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Program Files (x86)\Common Files\Dell\apache\php.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\mom\Downloads\dds (1).pif C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.aol.com mURLSearchHooks: H - No File BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\scriptcl.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN\Toolbar\3.0.1125.0\msneshellx.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - C:\Program Files (x86)\MSN\Toolbar\3.0.1125.0\msneshellx.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [Google Update] "C:\Users\mom\AppData\Local\Google\Update\GoogleUpdate.exe" /c mRun: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2 mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE mRun: [McAfeeUpdaterUI] "C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRunOnce: [DSUpdateLauncher] "c:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="c:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "c:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe" mRunOnce: [STToasterLauncher] "C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\OFFICE~1.LNK - C:\Program Files (x86)\Microsoft Office\Office\OSA.EXE mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: &AOL; Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-US\local\search.html IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL Trusted Zone: intuit.com\ttlc DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg64.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun-x64: [RtHDVCpl] RAVCpl64.exe ================= FIREFOX =================== FF - ProfilePath - C:\Users\mom\AppData\Roaming\Mozilla\Firefox\Profiles\0zxqzy8l.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.theprizeday.com/today.php|http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official\n FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\mom\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: C:\Users\mom\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll FF - plugin: C:\Users\mom\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll FF - plugin: C:\Users\mom\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.ytff.general.dontshowhpoffer - trueC:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false); ============= SERVICES / DRIVERS =============== R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-6-25 53488] R2 AERTFilters;Andrea RT Filters Service;C:\Windows\System32\AERTSr64.exe [2009-6-25 86016] R2 Apache2.2;Remote Access Media Server;C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe [2007-9-21 15872] R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 155648] R2 dsl-db;Remote Access DB;C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe [2007-9-14 5730304] R2 dsl-fs-sync;Remote Access File Sync Service;C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe [2009-4-13 189680] R2 McAfeeFramework;McAfee Framework Service;C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe [2009-7-2 104000] R2 McShield;McAfee McShield;C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\McShield.exe [2006-11-30 153664] R2 McTaskManager;McAfee Task Manager;C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe [2006-11-30 54872] R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2009-6-25 689472] R2 uvnc_service;UltraVNC Server;C:\ProgramData\UltraVNC\winvnc.exe -service –> C:\ProgramData\UltraVNC\winvnc.exe -service [?] R3 mfeavfk;McAfee Inc.;C:\Windows\System32\drivers\mfeavfk.sys [2009-7-2 92488] R3 mfehidk;McAfee Inc.;C:\Windows\System32\drivers\mfehidk.sys [2009-7-2 246344] R3 OA002Ufd;Creative Camera OA002 Upper Filter Driver;C:\Windows\System32\drivers\OA002Ufd.sys [2008-6-3 168864] R3 OA002Vid;Creative Camera OA002 Function Driver;C:\Windows\System32\drivers\OA002Vid.sys [2008-7-31 306560] R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;C:\Windows\System32\drivers\livecamv.sys [2009-7-1 49664] S1 mferkdk;VSCore mferkdk;C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mferkdk.sys [2006-11-30 38600] S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-1-28 135664] S3 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648] S3 OA002Afx;Provides a software interface to control audio effects of OA002 camera.;C:\Windows\System32\drivers\OA002Afx.sys [2009-7-1 219544] S3 PCD5SRVC{048DBD20-445E8C82-05040104};PCD5SRVC{048DBD20-445E8C82-05040104} - PCDR Kernel Mode Service Helper Driver;C:\PROGRA~2\DELLSU~1\HWDiag\bin\PCD5SRVC_x64.pkms [2008-11-4 28152] S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-4-19 50688] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768] S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-9-17 89920] ============== File Associations =============== JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %* =============== Created Last 30 ================ 2010-11-10 07:04:04 2409784 —-a-w- C:\Program Files\Windows Mail\OESpamFilter.dat 2010-11-10 07:04:04 2409784 —-a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat 2010-11-09 21:57:21 ——– d—–w- C:\Program Files (x86)\ESET 2010-11-09 08:55:29 8006480 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{5BA7021B-D597-4C41-A542-3E0CAA26B60A}\mpengine.dll 2010-11-09 05:58:24 ——– d—–w- C:\_OTL 2010-11-09 05:52:25 521448 —-a-w- C:\Windows\System32\deployJava1.dll 2010-10-26 23:51:57 1927680 —-a-w- C:\Windows\System32\gameux.dll 2010-10-26 23:51:56 1696256 —-a-w- C:\Windows\SysWow64\gameux.dll 2010-10-26 23:51:41 32256 —-a-w- C:\Windows\System32\Apphlpdm.dll 2010-10-26 23:51:41 28672 —-a-w- C:\Windows\SysWow64\Apphlpdm.dll 2010-10-26 23:51:39 4240384 —-a-w- C:\Windows\SysWow64\GameUXLegacyGDFs.dll 2010-10-26 23:51:38 4240384 —-a-w- C:\Windows\System32\GameUXLegacyGDFs.dll 2010-10-13 00:14:17 954752 —-a-w- C:\Windows\SysWow64\mfc40.dll 2010-10-13 00:14:17 954288 —-a-w- C:\Windows\SysWow64\mfc40u.dll 2010-10-13 00:01:17 633856 —-a-w- C:\Windows\System32\comctl32.dll 2010-10-13 00:01:14 531968 —-a-w- C:\Windows\SysWow64\comctl32.dll 2010-10-12 23:57:18 408064 —-a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe 2010-10-12 23:57:18 1915904 —-a-w- C:\Windows\System32\ole32.dll 2010-10-12 23:57:16 339968 —-a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe 2010-10-12 23:57:16 1316864 —-a-w- C:\Windows\SysWow64\ole32.dll 2010-10-12 23:57:02 189952 —-a-w- C:\Windows\System32\t2embed.dll 2010-10-12 23:57:01 157184 —-a-w- C:\Windows\SysWow64\t2embed.dll 2010-10-12 23:56:54 316928 —-a-w- C:\Windows\System32\msshsq.dll 2010-10-12 23:56:52 231424 —-a-w- C:\Windows\SysWow64\msshsq.dll 2010-10-12 23:56:43 2753024 —-a-w- C:\Windows\System32\win32k.sys 2010-10-12 23:54:01 171008 —-a-w- C:\Program Files\Windows Media Player\wmplayer.exe 2010-10-12 23:54:01 168960 —-a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe 2010-10-12 23:53:56 8147968 —-a-w- C:\Windows\System32\wmploc.DLL 2010-10-12 23:53:56 8147456 —-a-w- C:\Windows\SysWow64\wmploc.DLL 2010-10-12 23:52:53 451584 —-a-w- C:\Windows\System32\drivers\srv.sys 2010-10-12 23:52:51 179712 —-a-w- C:\Windows\System32\srvsvc.dll 2010-10-12 23:52:50 175104 —-a-w- C:\Windows\System32\drivers\srv2.sys 2010-10-12 23:52:50 145920 —-a-w- C:\Windows\System32\drivers\srvnet.sys 2010-10-12 23:52:45 9728 —-a-w- C:\Windows\SysWow64\sscore.dll 2010-10-12 23:52:45 12288 —-a-w- C:\Windows\System32\sscore.dll 2010-10-12 23:52:42 17920 —-a-w- C:\Windows\SysWow64\netevent.dll 2010-10-12 23:52:42 17920 —-a-w- C:\Windows\System32\netevent.dll 2010-10-12 23:52:07 274944 —-a-w- C:\Windows\SysWow64\schannel.dll 2010-10-12 23:52:06 343040 —-a-w- C:\Windows\System32\schannel.dll 2010-10-12 23:45:48 867328 —-a-w- C:\Windows\SysWow64\wmpmde.dll 2010-10-12 23:45:45 1090048 —-a-w- C:\Windows\System32\wmpmde.dll ==================== Find3M ==================== 2010-11-09 01:51:59 472808 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2010-10-19 18:41:44 270720 ——w- C:\Windows\System32\MpSigStub.exe 2010-09-08 06:41:05 1147904 —-a-w- C:\Windows\System32\wininet.dll 2010-09-08 06:36:53 56832 —-a-w- C:\Windows\System32\licmgr10.dll 2010-09-08 06:36:38 1538560 —-a-w- C:\Windows\System32\inetcpl.cpl 2010-09-08 06:36:24 132096 —-a-w- C:\Windows\System32\iesysprep.dll 2010-09-08 06:36:23 77312 —-a-w- C:\Windows\System32\iesetup.dll 2010-09-08 06:01:28 916480 —-a-w- C:\Windows\SysWow64\wininet.dll 2010-09-08 05:57:18 43520 —-a-w- C:\Windows\SysWow64\licmgr10.dll 2010-09-08 05:57:05 1469440 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2010-09-08 05:56:53 71680 —-a-w- C:\Windows\SysWow64\iesetup.dll 2010-09-08 05:56:53 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll 2010-09-08 05:36:07 479232 —-a-w- C:\Windows\System32\html.iec 2010-09-08 05:04:36 385024 —-a-w- C:\Windows\SysWow64\html.iec 2010-09-08 04:51:18 162816 —-a-w- C:\Windows\System32\ieUnatt.exe 2010-09-08 04:49:56 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2010-09-08 04:26:46 133632 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2010-09-08 04:25:15 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2010-08-26 17:40:08 100352 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll 2010-08-26 17:40:07 331776 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2010-08-26 17:40:07 284672 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll 2010-08-26 16:33:06 173056 —-a-w- C:\Windows\apppatch\AcXtrnal.dll 2010-08-26 16:33:04 542720 —-a-w- C:\Windows\apppatch\AcLayers.dll 2010-08-26 16:33:04 458752 —-a-w- C:\Windows\apppatch\AcSpecfc.dll 2010-08-26 16:33:04 2159616 —-a-w- C:\Windows\apppatch\AcGenral.dll 2010-08-17 14:54:20 273920 —-a-w- C:\Windows\System32\spoolsv.exe ============= FINISH: 16:05:02.06 ===============
GLASERDJ,

As far as I know… Apache is only used for servers. Typically personal computers have no reason to run php (as far as I know). Let's do a little housekeeping and then I suggest you post over in the Windows forum and see if the Tech Team can come up with any reason you need it.

Log looks good :D


You need to create a new Clean restore point:

  • Download SysRestorePoint to your desktop and unzip it to it's own folder.
  • Double click SysRestorePoint.exe so that we can make a new system restore point.
  • A box will pop up after it has made a new point, usually after a few seconds. Close that window and exit the program.
Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

You may be asked to choose drive. Choose C: At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Got all that. I do understand. Do I make a donation to you or to the site? Thank you very much. The computer is much faster. I can't believe anyone would infect Jonas Brothers!
GLASERDJ,

I think the Jonas Brothers are an infection. :wacko: (But I guess somebody must be buying their stuff)

You are very welcome. :thumbup:

No donations are necessary. I don't take them… However, if you feel it is something you really want to do, you can donate to the site here: http://www.whatthetech.com/donate or I could find you donation information for a developer of one of the tools we used. If this is something you desire… please PM me.

Good Luck and be Well. :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI