It appears I have a piece of malware/virus on my computer. I did have something on there that hid all my desktop icons and start menu icons etc., but I removed that. I was also getting the redirect from Google search results, but that appears to have subsided a bit. Now I see popups from IE about different websites randomly appear on my computer, mainly when it is not in use.
I only use firefox, but when I review the history for IE, there are numerous websites that I have not visited in there. The Start menu is also not showing the recently used programs. ixplore.exe is using a tremendous amount of memory as well.
I have used Mcafee, Malwarebytes Anti-Malware and several online scanners, but they do not show up anything. I'm at a bit of a loss as to what to do next..
The system is 64bit so I did not do GMER.
Thanks
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by Polished at 21:43:08 on 2011-11-23
.
============== Running Processes ===============
.
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe
c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files (x86)\Secunia\PSI\PSIA.exe
C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe
C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\AirPort\APAgent.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\netsh.exe
C:\Windows\SysWOW64\netsh.exe
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe
c:\program files (x86)\teamviewer\version6\TeamViewer_Desktop.exe
C:\Program Files (x86)\TeamViewer\Version6\tv_w32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Polished\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www1.ap.dell.com/content/default.aspx?c=au&l=en&s=gen
uDefault_Page_URL = hxxp://www1.ap.dell.com/content/default.aspx?c=au&l=en&s=gen
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111108035342.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
mRun: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [AirPort Base Station Agent] "C:\Program Files (x86)\AirPort\APAgent.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 10.1.1.1
TCP: Interfaces\{19DC6041-39B0-46E6-8D6E-F3D81CFE1483} : DhcpNameServer = 10.1.1.1
TCP: Interfaces\{329F31A1-F8B1-4487-85B6-A82DA9BC6EE3} : DhcpNameServer = 203.21.113.40 203.21.112.40
TCP: Interfaces\{337657AB-F7A9-4BAE-A222-EFFCDF0BA918} : DhcpNameServer = 203.21.113.40 203.21.112.40
TCP: Interfaces\{7BB292B1-CD06-4595-A761-1B94F309F243} : DhcpNameServer = 202.124.65.22 202.124.65.18
TCP: Interfaces\{C6E1B0ED-6B45-4B1E-9953-0D52A8F9D121} : DhcpNameServer = 10.1.1.1
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\MSC\McSnIePl.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO-X64: McAfee Phishing Filter - No File
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111108035342.dll
BHO-X64: scriptproxy - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
mRun-x64: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [AirPort Base Station Agent] "C:\Program Files (x86)\AirPort\APAgent.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Polished\AppData\Roaming\Mozilla\Firefox\Profiles\x8ed4fqj.default\
FF - prefs.js: browser.startup.homepage - hxxp://ninemsn.com.au/
FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Users\Polished\AppData\Roaming\Mozilla\Firefox\Profiles\x8ed4fqj.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R? AdobeARMservice;Adobe Acrobat Update Service
R? Apache2.2;Remote Access Media Server
R? BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver
R? clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64
R? ewusbnet;HUAWEI USB-NDIS miniport
R? hcw85cir;Hauppauge Consumer Infrared Receiver
R? hwusbfake;Huawei DataCard USB Fake
R? massfilter;ZTE Mass Storage Filter Driver
R? mferkdet;McAfee Inc. mferkdet
R? PerfHost;Performance Counter DLL Host
R? USBAAPL64;Apple Mobile USB Driver
S? AERTFilters;Andrea RT Filters Service
S? AMD External Events Utility;AMD External Events Utility
S? cfwids;McAfee Inc. cfwids
S? DockLoginService;Dock Login Service
S? dsl-db;Remote Access DB
S? dsl-fs-sync;Remote Access File Sync Service
S? FontCache;Windows Font Cache Service
S? HCW85BDA;Hauppauge WinTV 885 Video Capture
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
S? McMPFSvc;McAfee Personal Firewall Service
S? McNaiAnn;McAfee VirusScan Announcer
S? McProxy;McAfee Proxy Service
S? McShield;McAfee McShield
S? mfeavfk;McAfee Inc. mfeavfk
S? mfefire;McAfee Firewall Core Service
S? mfefirek;McAfee Inc. mfefirek
S? mfehidk;McAfee Inc. mfehidk
S? mfenlfk;McAfee NDIS Light Filter
S? mfevtp;McAfee Validation Trust Protection Service
S? mfewfpk;McAfee Inc. mfewfpk
S? MSSQL$KRONOS;SQL Server (KRONOS)
S? PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver
S? PSI;PSI
S? PxHlpa64;PxHlpa64
S? RtNdPt60;Realtek NDIS Protocol Driver
S? Secunia PSI Agent;Secunia PSI Agent
S? Secunia Update Agent;Secunia Update Agent
S? TeamViewer6;TeamViewer 6
S? VMCService;Vodafone Mobile Connect Service
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-11-23 10:49:29 -------- d-----w- C:\Users\Polished\AppData\Roaming\QuickScan
2011-11-15 22:31:24 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E2482A17-FB6D-4419-8830-0C1D94E9FB5E}\offreg.dll
2011-11-15 22:31:21 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E2482A17-FB6D-4419-8830-0C1D94E9FB5E}\mpengine.dll
2011-11-15 05:00:41 -------- d-----w- C:\Program Files\iPod
2011-11-15 05:00:40 -------- d-----w- C:\Program Files\iTunes
2011-11-15 05:00:40 -------- d-----w- C:\Program Files (x86)\iTunes
2011-11-15 04:54:28 -------- d-----w- C:\Program Files (x86)\AirPort
2011-11-14 08:04:42 -------- d-----w- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-11-14 08:00:03 -------- d-----w- C:\Program Files\Bonjour
2011-11-14 08:00:03 -------- d-----w- C:\Program Files (x86)\Bonjour
2011-11-10 14:02:57 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-10 14:00:12 476904 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2011-11-10 14:00:12 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-11-09 03:19:06 1426304 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-09 03:19:02 893440 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 03:19:01 707584 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 03:19:01 50688 ----a-w- C:\Program Files\Windows Mail\wabimp.dll
2011-11-08 01:52:56 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-11-08 01:51:34 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-11-08 01:38:45 -------- d-----w- C:\Users\Polished\AppData\Local\Secunia PSI
2011-11-08 01:38:37 -------- d-----w- C:\Program Files (x86)\Secunia
2011-11-08 00:58:11 -------- d-----w- C:\Users\Polished\AppData\Roaming\Malwarebytes
2011-11-08 00:58:01 -------- d-----w- C:\ProgramData\Malwarebytes
2011-11-08 00:57:57 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-11-08 00:57:57 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-11-07 08:41:24 -------- dc----w- C:\ProgramData\{03B86DF2-EB61-41C0-AC4A-A4F0EB62E708}
.
==================== Find3M ====================
.
2011-10-24 03:59:02 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2011-10-24 03:59:02 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2011-10-15 02:46:16 75808 ----a-w- C:\Windows\System32\drivers\mfenlfk.sys
2011-10-15 02:46:16 65264 ----a-w- C:\Windows\System32\drivers\cfwids.sys
2011-10-15 02:46:16 647080 ----a-w- C:\Windows\System32\drivers\mfehidk.sys
2011-10-15 02:46:16 481768 ----a-w- C:\Windows\System32\drivers\mfefirek.sys
2011-10-15 02:46:16 284648 ----a-w- C:\Windows\System32\drivers\mfewfpk.sys
2011-10-15 02:46:16 229528 ----a-w- C:\Windows\System32\drivers\mfeavfk.sys
2011-10-15 02:46:16 160280 ----a-w- C:\Windows\System32\drivers\mfeapfk.sys
2011-10-15 02:46:16 10248 ----a-w- C:\Windows\System32\drivers\mfeclnk.sys
2011-10-15 02:46:16 100912 ----a-w- C:\Windows\System32\drivers\mferkdet.sys
2011-09-06 13:56:50 2764288 ----a-w- C:\Windows\System32\win32k.sys
2011-09-01 05:24:07 2309120 ----a-w- C:\Windows\System32\jscript9.dll
2011-09-01 05:17:57 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-09-01 05:12:04 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-09-01 02:35:59 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-09-01 02:28:15 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-09-01 02:22:54 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-08-30 12:35:32 96104 ----a-w- C:\Windows\System32\dns-sd.exe
2011-08-30 12:35:32 85864 ----a-w- C:\Windows\System32\dnssd.dll
2011-08-30 12:35:32 212840 ----a-w- C:\Windows\System32\dnssdX.dll
2011-08-30 12:35:04 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-08-30 12:35:04 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-08-30 12:35:04 178536 ----a-w- C:\Windows\SysWow64\dnssdX.dll
2011-08-25 16:20:38 735744 ----a-w- C:\Windows\System32\UIAutomationCore.dll
2011-08-25 16:19:32 847360 ----a-w- C:\Windows\System32\oleaut32.dll
2011-08-25 16:19:32 332288 ----a-w- C:\Windows\System32\oleacc.dll
2011-08-25 16:15:04 555520 ----a-w- C:\Windows\SysWow64\UIAutomationCore.dll
2011-08-25 16:14:01 563712 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-08-25 16:14:01 238080 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-08-25 13:54:14 4096 ----a-w- C:\Windows\System32\oleaccrc.dll
2011-08-25 13:31:01 4096 ----a-w- C:\Windows\SysWow64\oleaccrc.dll
.
============= FINISH: 21:51:36.94 ===============
Attached File(s)
-
Attach.txt (6.4K)
Number of downloads: 0

Help
This topic is locked

Back to top












