This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Crash

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

PLEASE READ ADDITIONAL INFO AT BOTTOM (EDITED TODAY 4/17/09
I HAVE VISTA SP1….PROBLEM SEEMS TO OCCUR WHEN COMPUTER GOES TO SLEEP…SO I,VE BEEN KEEPING IT AWAKE TO AVOID CRASHES.LIKE DRINKING COFFEE WHEN YOU DRIVE!
Logfile of Trend Micro HijackThis v2.0.2

Computer crashes at night….message IRQL_NOT_LESS_OR_EQUAL…STOP:0X0000000A
(0X6C340634,0X00000002,0X00000000,0X81692428
Scan saved at 1:15:25 PM, on 4/16/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905) My operating system is Vista2008
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\filehippo.com\UpdateChecker.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Windows Sidebar\sidebar.exe
c:\Program Files\CyberLink\Power2Go\Power2GoExpressServer.exe
c:\PROGRA~1\CYBERL~1\SHARED~1\RICHVI~1.EXE
C:\Program Files\Sunbelt Software\VIPRE\SBAMUI.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O4 - HKLM\..\Run: [Windows Defender] rem C:\Program Files\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [SunJavaUpdateSched] rem "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] rem c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Logitech Utility] rem Logi_MwX.Exe
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] rem "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] rem "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ink Monitor] rem C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [LDM] rem C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [MRC] "C:\Program Files\Registry Utilities Pro\PCTuneUp.exe" /MBRSTART
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MoneyAgent] rem "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: MRI_DISABLED
O13 - Gopher Prefix:
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Commander Task Manager - Avanquest Publishing USA, Inc. - C:\PROGRA~1\VCOM\RECOVE~1\MXTask.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7746 bytes


StartupList report, 4/16/2009, 1:17:33 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows Vista SP1 (WinNT 6.00.1905)
Detected: Internet Explorer v7.00 (7.00.6001.18226)
* Using default options
==================================================

Running processes:

C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\filehippo.com\UpdateChecker.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Windows Sidebar\sidebar.exe
c:\Program Files\CyberLink\Power2Go\Power2GoExpressServer.exe
c:\PROGRA~1\CYBERL~1\SHARED~1\RICHVI~1.EXE
C:\Program Files\Sunbelt Software\VIPRE\SBAMUI.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\Windows\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

hpsysdrv = c:\hp\support\hpsysdrv.exe
UpdateP2GoShortCut = "c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
UpdatePDIRShortCut = "c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
UpdatePSTShortCut = "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
SunJavaUpdateSched = rem "C:\Program Files\Java\jre6\bin\jusched.exe"
HP Software Update = rem c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
HP Health Check Scheduler = c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
Logitech Utility = rem Logi_MwX.Exe
SBAMTray = C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
QuickTime Task = rem "C:\Program Files\QuickTime\QTTask.exe" -atboottime
iTunesHelper = rem "C:\Program Files\iTunes\iTunesHelper.exe"
Ink Monitor = rem C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

(Default) =

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Sidebar = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
HPAdvisor = C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
LDM = rem C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
MRC = "C:\Program Files\Registry Utilities Pro\PCTuneUp.exe" /MBRSTART
ehTray.exe = C:\Windows\ehome\ehTray.exe
MoneyAgent = rem "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
filehippo.com = "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
WMPNSCFG = C:\Program Files\Windows Media Player\WMPNSCFG.exe

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
=

————————————————–

Shell & screensaver key from C:\Windows\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=explorer.exe
SCRNSAVE.EXE=C:\Windows\system32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - (no file) - MRI_DISABLED
AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
(no name) - (no file) - {549B5CA7-4A86-11D7-A4DF-000874180BB3}
(no name) - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll - {d2ce3e00-f94a-4740-988e-03dc2f38c34f}
(no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}
(no name) - (no file) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC}

————————————————–

Enumerating Task Scheduler jobs:

HPCeeScheduleForUser.job

————————————————–

Enumerating Winsock LSP files:

NameSpace #1: C:\Windows\system32\NLAapi.dll
NameSpace #2: C:\Windows\system32\napinsp.dll
NameSpace #3: C:\Windows\system32\pnrpnsp.dll
NameSpace #4: C:\Windows\system32\pnrpnsp.dll
NameSpace #7: C:\Program Files\Bonjour\mdnsNSP.dll

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: C:\Windows\system32\webcheck.dll

————————————————–
End of report, 6,750 bytes
Report generated in 0.047 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

This is an edit…seems to crash during sleep mode…latest message after crash is….STOP: 0X0000007E (0XC0000005, 0X8A15BA90, 0X8A15B78C)

GEARASPiWDM.sys-Address 8D000005 base AT 8D000000, DateStamp 49c26595 Collecting Data For Crash Dump Dumping physical memory to disk: 100
Hi,

Please do the following

Please download ATF Cleaner by Atribune.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
    • If you use Firefox browser
    • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time.


>>>NEXT<<<


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
Dear Catbyte, Thanks for the help…here is the new log from malwarebytes Malwarebytes' Anti-Malware 1.36 Database version: 2016 Windows 6.0.6001 Service Pack 1 4/20/2009 6:26:35 PM mbam-log-2009-04-20 (18-26-35).txt Scan type: Quick Scan Objects scanned: 61067 Time elapsed: 2 minute(s), 17 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi Catbyte…again THANK YOU!

here is the combofix log…seems to be running better, still crashing in sleep mode up till now, maybe this has fixed that problem…I'll let you know!

ComboFix 09-04-21.07 - User 04/20/2009 22:56.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2942.1944 [GMT -4:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated)
FW: Sunbelt Personal Firewall *enabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-03-21 to 2009-04-21 )))))))))))))))))))))))))))))))
.

2009-04-21 02:24 . 2009-04-21 02:31 3085352098 —-a-w c:\windows\MEMORY.DMP
2009-04-20 23:56 . 2009-04-20 23:56 ——– d—–w c:\users\User\AppData\Roaming\GetRightToGo
2009-04-20 22:22 . 2009-04-20 22:22 ——– d—–w c:\users\User\AppData\Roaming\Malwarebytes
2009-04-20 22:22 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-20 22:22 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-20 22:22 . 2009-04-20 22:22 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-20 22:22 . 2009-04-20 22:22 ——– d—–w c:\users\All Users\Malwarebytes
2009-04-20 22:22 . 2009-04-20 22:22 ——– d—–w c:\programdata\Malwarebytes
2009-04-20 20:04 . 2006-11-22 00:40 65536 —-a-w c:\windows\system32\SSGB6ci.dll
2009-04-20 20:04 . 2006-11-20 21:22 151552 —-a-w c:\windows\system32\SSGB6ci.exe
2009-04-20 20:04 . 2006-11-22 13:52 5120 ——w c:\windows\system32\drivers\SSPORT.SYS
2009-04-20 20:04 . 2009-04-20 20:04 ——– d—–w c:\program files\SAMSUNG
2009-04-20 19:43 . 2009-04-20 19:43 ——– d—–w c:\users\All Users\PC Drivers HeadQuarters
2009-04-20 19:43 . 2009-04-20 19:43 ——– d—–w c:\programdata\PC Drivers HeadQuarters
2009-04-20 19:42 . 2009-04-20 19:42 ——– d—–w c:\users\User\AppData\Local\Downloaded Installations
2009-04-20 19:15 . 2009-04-20 19:15 ——– d—–w c:\program files\Common Files\SWF Studio
2009-04-20 18:43 . 2009-04-20 18:43 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-04-17 08:57 . 2009-04-18 17:43 34 —-a-w c:\windows\cdplayer.ini
2009-04-16 16:43 . 2009-04-16 16:43 ——– d—–w c:\program files\Trend Micro
2009-04-16 07:00 . 2009-04-16 07:00 ——– d—–w c:\program files\MSXML 4.0
2009-04-16 06:46 . 2009-04-16 06:46 ——– d—–w c:\users\All Users\LightScribe
2009-04-16 06:46 . 2009-04-16 06:46 ——– d—–w c:\programdata\LightScribe
2009-04-16 06:08 . 2009-04-16 09:07 ——– d—–w c:\users\User\AppData\Roaming\CyberLink
2009-04-16 06:08 . 2009-04-16 06:08 ——– d—–w c:\users\Public\CyberLink
2009-04-15 23:39 . 2009-04-15 23:39 ——– d—–w c:\users\User\AppData\Roaming\OpenOffice.org
2009-04-15 23:35 . 2009-04-20 16:40 ——– d—–w c:\program files\SpywareBlaster
2009-04-15 23:35 . 2005-08-25 23:18 118784 —-a-w c:\windows\system32\MSSTDFMT.DLL
2009-04-15 23:13 . 2009-04-16 08:09 ——– d—–w c:\program files\Burrrn
2009-04-15 23:10 . 2009-04-17 08:53 ——– d—–w C:\audiograbber
2009-04-15 23:03 . 2009-04-17 09:54 ——– d—–w c:\program files\MP3Gain
2009-04-15 22:52 . 2004-02-11 20:58 24613 —-a-w c:\temp\IadHide5.dll
2009-04-15 22:48 . 2009-04-15 22:48 ——– d—–w c:\users\All Users\Adobe
2009-04-15 22:47 . 2009-04-15 22:48 ——– d—–w c:\program files\Common Files\Adobe
2009-04-15 22:36 . 2009-04-15 22:37 ——– d—–w c:\program files\OpenOffice.org 3
2009-04-15 22:34 . 2009-04-15 22:34 ——– d—–w c:\program files\filehippo.com
2009-04-15 21:22 . 2009-04-15 21:22 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-04-15 21:11 . 2009-04-15 21:11 ——– d—–w c:\windows\system32\BWKDLogs
2009-04-15 21:11 . 2009-04-15 21:11 ——– d—–w c:\program files\Common Files\Kodak
2009-04-15 21:10 . 2009-04-15 21:10 ——– d—–w C:\KPCMS
2009-04-15 21:10 . 2009-04-15 21:10 ——– d—–w c:\windows\system32\color
2009-04-15 21:10 . 2009-04-15 21:11 ——– d—–w c:\program files\Kodak
2009-04-15 21:08 . 2009-04-15 21:08 ——– d—–w c:\users\All Users\Kodak
2009-04-15 21:08 . 2009-04-15 21:08 ——– d—–w c:\programdata\Kodak
2009-04-15 20:36 . 2009-04-15 20:37 ——– d—–w c:\program files\Microsoft Money
2009-04-15 18:20 . 2009-04-15 18:21 453 —-a-w c:\windows\PowerReg.dat
2009-04-15 18:20 . 2009-04-15 18:20 ——– d—–w C:\EPSONREG
2009-04-15 18:16 . 2002-04-15 06:23 70924 —-a-w c:\windows\system32\EBPMON2.DLL
2009-04-15 18:16 . 2002-03-01 05:00 44544 —-a-w c:\windows\system32\EAL32.DLL
2009-04-15 18:16 . 2001-03-29 06:21 57344 —-a-w c:\windows\system32\ECBTEG.DLL
2009-04-15 18:16 . 2000-09-14 06:03 145 —-a-w c:\windows\system32\EBPPORT.DAT
2009-04-15 18:16 . 2000-06-07 05:01 34304 —-a-w c:\windows\system32\EBPCHP.DLL
2009-04-15 18:16 . 2002-03-01 05:00 69120 —-a-w c:\windows\system32\EAL.EXE
2009-04-15 18:16 . 2009-04-20 18:42 ——– d—–w c:\program files\EPSON
2009-04-15 18:16 . 2009-04-15 18:20 45 —-a-w c:\windows\EPSP925.ini
2009-04-15 18:13 . 2003-01-14 12:38 14002 —-a-w c:\windows\system32\ssgb6mon.dll
2009-04-15 18:12 . 2009-04-20 19:30 ——– d—–w c:\windows\Samsung
2009-04-15 18:12 . 2003-09-08 08:36 204800 ——w c:\windows\system32\SSRemove.exe
2009-04-15 18:12 . 2003-07-21 11:50 8478 ——w c:\windows\system32\SP119.ICO
2009-04-15 17:57 . 2009-04-15 17:57 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-04-15 09:22 . 2009-04-15 09:22 ——– d—–w c:\users\All Users\BVRP Software
2009-04-15 09:22 . 2009-04-15 09:22 ——– d—–w c:\programdata\BVRP Software
2009-04-15 07:28 . 2009-04-19 13:54 ——– d—–w c:\program files\Registry Utilities Pro
2009-04-15 07:25 . 2009-04-15 07:25 ——– d–h–w C:\VCOM
2009-04-15 07:25 . 2009-04-15 07:25 ——– d-sh–r C:\_Backup.RC
2009-04-15 07:25 . 2009-04-15 07:25 ——– d—–w c:\users\User\AppData\Roaming\VCOM
2009-04-15 07:24 . 2009-04-15 07:24 ——– d—–w c:\program files\VCOM
2009-04-15 07:00 . 2009-04-15 07:00 ——– d—–w c:\users\User\AppData\Roaming\Template
2009-04-15 07:00 . 2009-04-15 07:42 506 —-a-w c:\users\User\AppData\Roaming\wklnhst.dat
2009-04-15 05:41 . 2009-04-15 05:41 ——– dc—-w c:\windows\system32\DRVSTORE
2009-04-15 05:41 . 2009-03-19 20:32 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-04-15 05:41 . 2008-04-17 16:12 107368 —-a-w c:\windows\system32\GEARAspi.dll
2009-04-15 05:40 . 2009-04-15 05:40 ——– d—–w c:\program files\iPod
2009-04-15 05:40 . 2009-04-15 05:41 ——– d—–w c:\users\All Users\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-15 05:40 . 2009-04-15 05:41 ——– d—–w c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-15 05:40 . 2009-04-15 05:41 ——– d—–w c:\program files\iTunes
2009-04-15 05:38 . 2009-04-15 05:38 ——– d—–w c:\program files\Bonjour
2009-04-15 05:37 . 2009-04-15 05:37 ——– d—–w c:\program files\QuickTime
2009-04-15 05:36 . 2009-04-15 05:36 ——– d—–w c:\program files\Apple Software Update
2009-04-15 05:35 . 2009-04-15 05:40 ——– d—–w c:\program files\Common Files\Apple
2009-04-15 05:35 . 2009-04-15 05:35 ——– d—–w c:\users\All Users\Apple
2009-04-15 05:35 . 2009-04-15 05:35 ——– d—–w c:\programdata\Apple
2009-04-15 05:22 . 2009-04-15 05:22 ——– d—–w c:\users\User\AppData\Roaming\Apple Computer
2009-04-15 05:22 . 2009-04-15 05:22 ——– d—–w c:\users\All Users\QuickTime
2009-04-15 05:22 . 2009-04-15 05:22 ——– d—–w c:\programdata\QuickTime
2009-04-15 05:22 . 2009-04-15 05:37 ——– d—–w c:\users\All Users\Apple Computer
2009-04-15 05:22 . 2009-04-15 05:37 ——– d—–w c:\programdata\Apple Computer
2009-04-15 05:20 . 2009-04-15 05:20 ——– d—–w c:\windows\Downloaded Installations
2009-04-15 03:47 . 2009-04-15 03:47 ——– d—–w c:\users\User\AppData\Local\Mozilla
2009-04-15 03:12 . 2009-04-15 03:12 410984 —-a-w c:\windows\system32\deploytk.dll
2009-04-15 03:11 . 2008-06-21 08:54 65576 —-a-w c:\windows\system32\drivers\SbFwIm.sys
2009-04-15 02:50 . 2009-04-15 02:50 ——– d—–w c:\users\All Users\Sunbelt
2009-04-15 02:50 . 2009-04-15 02:50 ——– d—–w c:\programdata\Sunbelt
2009-04-15 02:50 . 2009-04-15 02:50 ——– d—–w c:\users\User\AppData\Roaming\Sunbelt
2009-04-15 02:49 . 2008-10-09 13:48 202928 —-a-w c:\windows\system32\drivers\sbtis.sys
2009-04-15 02:49 . 2009-04-15 03:11 ——– d—–w c:\program files\Sunbelt Software
2009-04-14 23:31 . 2009-04-15 22:52 ——– d—–w C:\temp
2009-04-14 23:31 . 2009-04-14 23:31 81920 ——r c:\windows\bwUnin-6.1.4.36-8876480L.exe
2009-04-14 17:56 . 2008-10-22 01:22 2048 —-a-w c:\windows\system32\tzres.dll
2009-04-14 17:46 . 2008-06-20 01:14 97800 —-a-w c:\windows\system32\infocardapi.dll
2009-04-14 17:46 . 2008-06-20 01:14 43544 —-a-w c:\windows\system32\PresentationHostProxy.dll
2009-04-14 17:46 . 2008-06-20 01:14 105016 —-a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-04-14 17:46 . 2008-06-20 01:14 37384 —-a-w c:\windows\system32\infocardcpl.cpl
2009-04-14 17:46 . 2008-06-20 01:14 11264 —-a-w c:\windows\system32\icardres.dll
2009-04-14 17:46 . 2008-06-20 01:14 622080 —-a-w c:\windows\system32\icardagt.exe
2009-04-14 17:46 . 2008-06-20 01:14 781344 —-a-w c:\windows\system32\PresentationNative_v0300.dll
2009-04-14 17:46 . 2008-06-20 01:14 326160 —-a-w c:\windows\system32\PresentationHost.exe
2009-04-14 17:36 . 2008-07-27 18:03 96760 —-a-w c:\windows\system32\dfshim.dll
2009-04-14 17:36 . 2008-07-27 18:03 282112 —-a-w c:\windows\system32\mscoree.dll
2009-04-14 17:36 . 2008-07-27 18:03 41984 —-a-w c:\windows\system32\netfxperf.dll
2009-04-14 17:36 . 2008-07-27 18:03 158720 —-a-w c:\windows\system32\mscorier.dll
2009-04-14 17:36 . 2008-07-27 18:03 83968 —-a-w c:\windows\system32\mscories.dll
2009-04-14 17:31 . 2008-11-01 03:44 28672 —-a-w c:\windows\system32\Apphlpdm.dll
2009-04-14 17:31 . 2008-11-01 01:21 4240384 —-a-w c:\windows\system32\GameUXLegacyGDFs.dll
2009-04-14 17:31 . 2008-10-21 05:25 296960 —-a-w c:\windows\system32\gdi32.dll
2009-04-14 17:31 . 2009-02-13 08:49 1255936 —-a-w c:\windows\system32\lsasrv.dll
2009-04-14 17:31 . 2009-03-17 03:38 13824 —-a-w c:\windows\system32\apilogen.dll
2009-04-14 17:31 . 2009-03-17 03:38 24064 —-a-w c:\windows\system32\amxread.dll
2009-04-14 17:31 . 2009-02-13 08:49 72704 —-a-w c:\windows\system32\secur32.dll
2009-04-14 17:31 . 2008-06-06 03:27 38912 —-a-w c:\windows\system32\xolehlp.dll
2009-04-14 17:31 . 2008-06-06 03:27 562176 —-a-w c:\windows\system32\msdtcprx.dll
2009-04-14 17:31 . 2008-09-05 05:14 1191936 —-a-w c:\windows\system32\msxml3.dll
2009-04-14 17:31 . 2008-12-06 04:42 376832 —-a-w c:\windows\system32\winhttp.dll
2009-04-14 17:28 . 2008-09-18 04:56 125952 —-a-w c:\windows\system32\wersvc.dll
2009-04-14 17:28 . 2008-09-18 04:56 147456 —-a-w c:\windows\system32\Faultrep.dll
2009-04-14 17:28 . 2008-10-29 06:29 2927104 —-a-w c:\windows\explorer.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-20 23:41 . 2009-04-20 23:41 ——– d—–w c:\users\User\AppData\Roaming\InstallShield
2009-04-20 20:05 . 2006-11-02 10:25 86016 —-a-w c:\windows\Inf\infstor.dat
2009-04-20 20:05 . 2006-11-02 10:25 51200 —-a-w c:\windows\Inf\infpub.dat
2009-04-20 20:05 . 2006-11-02 10:25 143360 —-a-w c:\windows\Inf\infstrng.dat
2009-04-20 19:51 . 2008-11-13 10:45 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-20 16:40 . 2008-11-13 10:48 ——– d—a-w c:\programdata\Temp
2009-04-16 06:08 . 2008-11-13 10:49 ——– d—–w c:\programdata\CyberLink
2009-04-15 22:51 . 2008-11-13 11:10 ——– d—–w c:\program files\Microsoft Silverlight
2009-04-15 05:46 . 2009-04-15 05:46 900 —-a-w c:\program files\burrrn.ini
2009-04-15 05:20 . 2008-11-13 10:45 ——– d—–w c:\program files\Common Files\InstallShield
2009-04-15 03:12 . 2008-11-13 10:57 ——– d—–w c:\program files\Java
2009-04-14 23:31 . 2009-04-14 23:29 ——– d—–w c:\program files\Logitech
2009-04-14 23:29 . 2009-04-14 23:29 ——– d—–w c:\program files\Common Files\Logitech
2009-04-14 20:26 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-04-14 20:21 . 2008-11-13 11:03 ——– d—–w c:\programdata\WildTangent
2009-04-14 20:21 . 2008-11-13 11:03 ——– d—–w c:\program files\HP Games
2009-04-14 20:20 . 2008-11-13 11:11 ——– d—–w c:\programdata\Norton
2009-04-14 19:31 . 2008-11-13 10:48 ——– d—–w c:\program files\Hewlett-Packard
2009-04-14 19:29 . 2008-11-13 11:12 ——– d—–w c:\program files\SMINST
2009-04-14 17:19 . 2006-11-02 12:37 ——– d—–w c:\program files\Windows Sidebar
2009-04-14 17:15 . 2008-11-13 11:02 ——– d—–w c:\programdata\Hewlett-Packard
2009-03-17 17:26 . 2009-03-17 17:26 65320 —-a-w c:\windows\System32\sbbd.exe
2009-03-17 03:38 . 2009-04-14 17:31 40960 —-a-w c:\windows\AppPatch\apihex86.dll
2009-03-09 23:16 . 2008-11-13 10:46 ——– d—–w c:\programdata\NVIDIA
2009-03-05 03:30 . 2009-03-05 03:30 69936 —-a-w c:\windows\system32\drivers\sbapifs.sys
2009-03-03 04:46 . 2009-04-14 17:29 3547632 —-a-w c:\windows\System32\ntoskrnl.exe
2009-03-03 04:46 . 2009-04-14 17:29 3599328 —-a-w c:\windows\System32\ntkrnlpa.exe
2009-03-03 04:40 . 2009-04-14 17:29 827392 —-a-w c:\windows\System32\wininet.dll
2009-03-03 04:39 . 2009-04-14 17:29 183296 —-a-w c:\windows\System32\sdohlp.dll
2009-03-03 04:39 . 2009-04-14 17:29 551424 —-a-w c:\windows\System32\rpcss.dll
2009-03-03 04:39 . 2009-04-14 17:29 26112 —-a-w c:\windows\System32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-14 17:29 78336 —-a-w c:\windows\System32\ieencode.dll
2009-03-03 04:37 . 2009-04-14 17:29 98304 —-a-w c:\windows\System32\iasrecst.dll
2009-03-03 04:37 . 2009-04-14 17:29 54784 —-a-w c:\windows\System32\iasads.dll
2009-03-03 04:37 . 2009-04-14 17:29 44032 —-a-w c:\windows\System32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-14 17:29 666624 —-a-w c:\windows\System32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-14 17:29 17408 —-a-w c:\windows\System32\iashost.exe
2009-03-03 02:28 . 2009-04-14 17:29 26624 —-a-w c:\windows\System32\ieUnatt.exe
2008-01-21 02:43 . 2006-11-02 12:50 174 –sha-w c:\program files\desktop.ini
2008-11-13 10:24 . 2008-11-13 10:22 8192 –sha-w c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="rem" [X]
"MoneyAgent"="rem" [X]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-10-17 972080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"filehippo.com"="c:\program files\filehippo.com\UpdateChecker.exe" [2009-03-23 146432]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="rem" [X]
"HP Software Update"="rem" [X]
"QuickTime Task"="rem" [X]
"iTunesHelper"="rem" [X]
"Ink Monitor"="rem" [X]
"Adobe Reader Speed Launcher"="rem" [X]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" [2008-09-11 210216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2009-03-17 955688]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED
PictureMover.lnk - c:\program files\PictureMover\Bin\PictureMover.exe [2008-9-8 430080]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{FE225A10-ABBB-4AAE-BD4D-D9243F1ACC8E}"= c:\program files\CyberLink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"TCP Query User{D72EC9C0-8A73-4197-BBE7-51CF127B3548}c:\\program files\\logitech\\desktop messenger\\8876480\\program\\backweb-8876480.exe"= UDP:c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe:backWeb-8876480
"UDP Query User{CBAB4D1A-0C37-4AC9-A2BB-28C02FC4F1CC}c:\\program files\\logitech\\desktop messenger\\8876480\\program\\backweb-8876480.exe"= TCP:c:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe:backWeb-8876480
"{B278426A-3014-411A-A484-48DC935590EE}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{898054DE-DC01-43F8-8CE4-7629BFC52126}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1EF38D8A-1F71-4233-BA9A-D5EBDFFCBB63}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{201D953D-60CE-4EA3-9609-01BF078FBCF1}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R2 Norton Internet Security;Norton Internet Security; [x]
R2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [2009-03-17 894248]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-04-06 38496]
R3 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [2008-10-22 92464]
S1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [2008-10-31 270888]
S1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [2008-06-21 66600]
S1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2008-10-09 202928]
S2 Recovery Commander Task Manager;Recovery Commander Task Manager;c:\progra~1\VCOM\RECOVE~1\MXTask.exe [2006-04-27 147456]
S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [2009-03-05 69936]
S2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
S2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2006-11-22 5120]
S3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\DRIVERS\sbfwim.sys [2008-06-21 65576]

.
Contents of the 'Scheduled Tasks' folder

2009-04-14 c:\windows\Tasks\HPCeeScheduleForUser.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-11-13 19:12]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-Logitech Utility - rem Logi_MwX.Exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=bestbuy&pf=cndt
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=bestbuy&pf=cndt
uInternet Settings,ProxyOverride = localhost;*.local
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\s55np6i2.default\
FF - prefs.js: browser.startup.homepage - hxxp://att.my.yahoo.com/
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-20 23:02
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-04-21 23:05
ComboFix-quarantined-files.txt 2009-04-21 03:05

Pre-Run: 175,443,501,056 bytes free
Post-Run: 174,890,815,488 bytes free

283 — E O F — 2009-04-17 21:25
Hi

Please do the following

Run Scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Hi Catbyte! I ran the Kapersky scan…almost 4 hours…it came out clean, no malware…but the scan log was not there…maybe I didn't get to it soon enough…but it was free of any malware…please advise me for my next step…Thanks!
Hi Catbyte….thanks so much for your help…I'm unemployed right now…but I'll try to get a donation in as soon as I can! All seems well….It doesn't seem to be crashing now at sleep time….what do you think was causing that problem??? Anyway, I'll continue to keep an eye on that…here's the Hijack log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:12:55 PM, on 4/21/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\filehippo.com\UpdateChecker.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
c:\Program Files\CyberLink\Power2Go\Power2GoExpressServer.exe
c:\PROGRA~1\CYBERL~1\SHARED~1\RICHVI~1.EXE
C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\System32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…buy&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…buy&pf=cndt
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [SunJavaUpdateSched] rem "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] rem c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] rem "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] rem "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ink Monitor] rem C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] rem "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [LDM] rem C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MoneyAgent] rem "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: MRI_DISABLED
O13 - Gopher Prefix:
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Commander Task Manager - Avanquest Publishing USA, Inc. - C:\PROGRA~1\VCOM\RECOVE~1\MXTask.exe
O23 - Service: VIPRE Antivirus + Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 6365 bytes
Hi,
Hard to know what caused the crashing, you had a trojan agent and browser hijacker on board, malware can make the computer behave in strange ways, I'm glad your problems are now solved.

My help is always free, so don't worry about a donation - it's more important for you to find employment, I wish you good luck with that.

There are just a couple of house keeping items to take care of, then you'll be good to go.

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - Global Startup: MRI_DISABLED


  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

NEXT:



Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • For Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read the guide by Rorschach112 on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.
Catbyte, Thanks so much…I spoke too soon however….here is the crash message I got with sleep mode…. STOP: 0X0000007E (0XC0000005, 0X8D000005, 0X8A15BA90, 0X8A15B78C) GEARAspiWDM.sys-Address 8D000005 base at 8D000000, Datestamp 49C26595 I will go ahead and do what you have sent…and not let computer go to sleep…which seems to be the only time I have a problem with crashing…I will send info with next post Thanks Again!
Catbyte, Combofix how do I uninstall? Program came on…I accidentally started it…got warning about having anti-spyware running…couldn't seem to get out of it so I booted…how do I uninstall it? I lost my background photo on my computer screen…it's BLACK I can't add new screen picture…Will I have to system restore to fix this?
Hi, the instructions for uninstalling combofix was in my previous instructions:


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If the program has somehow been corrupted and will not uninstall properly then try this tool remover program:

Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program

As for the crashing:

I doubt that the problem is related to malware as you are clean of anymalware, it sounds as though there is some type of hardware failure going on.

We have expert tech gurus in out tech forums. I suggest posting in our hardware forum >>>HERE<<< and describe in detail what is happening
Link back to this topic so they can see what has taken place.

Good luck
CB
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI