This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Something is seriously wrong with my computer

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Everything that I click to open literally takes about 2-3 minutes to pop up. I.e google chrome, skype, mozilla fox, aim, ventrilo etc. Sometimes it even takes 5 minutes to open up some things and my computer has been acting up lately aka freezing more than usual and just being really slow and it's really frustrating. It's been going on for 2 days so far and my Malwarebytes' Anti-Malware has expired a couple of weeks ago so yeah.. Can someone help me with this problem that I have?
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.


IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Having said that….Let's get going!! :thumbup:
Hi contemplator,

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs created by DDS, GMER and aswMBR. :)
Here is the DDS.txt and the attach.txt . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.6000.17037 BrowserJavaVersion: 1.6.0_26 Run by [removed] at 15:24:06 on 2011-09-12 Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.2.1033.18.2035.739 [GMT -4:00] . . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\vVX3000.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\HP\HP Software Update\hpwuschd2.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Users\client\AppData\Local\Facebook\Update\FacebookUpdate.exe C:\Users\client\AppData\Local\Google\Update\GoogleUpdate.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Microsoft LifeCam\MSCamS32.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskeng.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\taskeng.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\taskeng.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\conime.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = ;*.local BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Shop to Win 18: {ca2f8e90-0e43-46ad-89c0-7634a233ed00} - c:\program files\shop to win 18\Shop to Win 18.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe" uRun: [ooVoo.exe] c:\program files\oovoo\oovoo.exe /minimized uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [Facebook Update] "c:\users\client\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver uRun: [Google Update] "c:\users\client\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe" mRun: [VX3000] c:\windows\vVX3000.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [PMBVolumeWatcher] c:\program files\sony\pmb\PMBVolumeWatcher.exe mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [] StartupFolder: c:\users\client\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{26769760-8106-47D2-852B-6B73BD219D0F} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{7D2EA435-939B-44FD-8E55-7CBF70B9D294} : DhcpNameServer = [removed] [removed] TCP: Interfaces\{9E02E2CA-95E2-4166-94B8-2D2531364C65} : DhcpNameServer = 192.168.0.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Notify: igfxcui - igfxdev.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\client\appdata\roaming\mozilla\firefox\profiles\kl6gjpcx.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://urlseek40.vmn.net/search.php?lg=en&type=dns&tbn=oovoo2_0dn&q= FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\program files\veetle\player\npvlc.dll FF - plugin: c:\program files\veetle\plugins\npVeetle.dll FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll FF - plugin: c:\users\client\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll FF - plugin: c:\users\client\appdata\local\google\update\1.3.21.69\npGoogleUpdate3.dll . —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true . ============= SERVICES / DRIVERS =============== . R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-5-31 366640] R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\sony\pmb\PMBDeviceInfoProvider.exe [2009-10-24 360224] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-9-11 24652] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-5-31 22712] S2 gupdate1ca77a318b0b950;Google Update Service (gupdate1ca77a318b0b950);c:\program files\google\update\GoogleUpdate.exe [2009-12-7 133104] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-12-7 133104] S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2010-4-12 15944] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-5-31 39984] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?] . =============== Created Last 30 ================ . 2011-09-05 23:56:06 ——– d—–w- c:\users\client\appdata\roaming\HpUpdate 2011-09-05 23:56:02 ——– d—–w- c:\windows\Hewlett-Packard 2011-08-16 18:46:26 ——– d—–w- c:\program files\iPod 2011-08-16 18:46:21 ——– d—–w- c:\program files\iTunes 2011-08-16 18:43:10 ——– d—–w- c:\program files\Bonjour 2011-08-16 11:20:32 4892320 —-a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll . ==================== Find3M ==================== . 2011-07-12 15:20:54 83816 —-a-w- c:\windows\system32\dns-sd.exe 2011-07-12 15:20:54 73064 —-a-w- c:\windows\system32\dnssd.dll 2011-07-12 15:20:54 50536 —-a-w- c:\windows\system32\jdns_sd.dll 2011-07-12 15:20:54 178536 —-a-w- c:\windows\system32\dnssdX.dll 2011-07-05 22:37:00 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2011-07-05 22:37:00 69632 —-a-w- c:\windows\system32\QuickTime.qts . ============= FINISH: 15:24:51.24 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Basic Boot Device: \Device\HarddiskVolume1 Install Date: 9/7/2009 12:36:45 PM System Uptime: 9/12/2011 3:08:23 PM (0 hours ago) . Motherboard: Intel Corporation | | DG31PR Processor: Pentium® Dual-Core CPU E5300 @ 2.60GHz | J3E1 | 1200/800mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 233 GiB total, 116.475 GiB free. D: is CDROM (CDFS) E: is Removable F: is Removable G: is Removable H: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP820: 6/23/2011 12:00:05 AM - Scheduled Checkpoint . ==== Installed Programs ====================== . 32 Bit HP CIO Components Installer Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Shockwave Player 11.5 AIM 6 Apple Application Support Apple Mobile Device Support Apple Software Update Bonjour BufferChm C4600 Click to Call with Skype Destinations DeviceDiscovery EasyBits GO ERUNT 1.1j Facebook Video Calling 1.0.0.8177 Foxit Reader Google Chrome Google Update Helper GPBaseService2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Customer Participation Program 13.0 HP Imaging Device Functions 13.0 HP Photosmart C4600 All-In-One Driver Software 13.0 Rel .5 HP Print Projects 1.0 HP Smart Web Printing 4.5 HP Solution Center 13.0 HP Update HPPhotoGadget hpPrintProjects HPProductAssistant HPSSupply hpWLPGInstaller Intel® Graphics Media Accelerator Driver iTunes Java Auto Updater Java™ 6 Update 26 K-Lite Codec Pack 4.0.0 (Full) KhalSetup League of Legends Linksys Wireless-G USB Network Adapter Malwarebytes' Anti-Malware version 1.51.0.1200 MapleStory MarketResearch McAfee Security Scan Plus Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft LifeCam Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 MobileMe Control Panel Mozilla Firefox 6.0.2 (x86 en-US) MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK neroxml Nexon Game Manager ooVoo OpenOffice.org 3.2 Pando Media Booster PMB PS_AIO_05_C4600_Software_Min QuickTime Safari Scan Shop for HP Supplies Shop To Win Skype™ 5.5 SmartWebPrinting SolutionCenter Status The Sims 2 Toolbox TrayApp Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Veetle TV 0.9.16 Ventrilo Client Viewpoint Media Player WebReg Winamp Winamp Detector Plug-in Windows Live Communications Platform Windows Live Essentials Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Movie Maker 2.6 WinRAR archiver . ==== Event Viewer Messages From Past Week ======== . 9/8/2011 3:43:38 PM, Error: EventLog [6008] - The previous system shutdown at 3:42:02 PM on 08/09/2011 was unexpected. 9/7/2011 10:14:36 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt 9/6/2011 2:45:13 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.7 for the Network Card with network address 000F66723B95 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 9/10/2011 6:59:49 PM, Error: EventLog [6008] - The previous system shutdown at 6:58:14 PM on 10/09/2011 was unexpected. 9/10/2011 12:04:26 AM, Error: EventLog [6008] - The previous system shutdown at 12:03:11 AM on 10/09/2011 was unexpected. . ==== End Of File ===========================
this is gmer and aswmbr

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-09-12 16:22:43
Windows 6.0.6000 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2 WDC_WD2500AAJS-61B4A0 rev.01.03A01
Running: gmer.exe; Driver: C:\Users\client\AppData\Local\Temp\kxtdapob.sys


—- Kernel code sections - GMER 1.0.15 —-

? C:\Users\client\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[2068] ntdll.dll!LdrLoadDll 774DEB00 5 Bytes JMP 00C11410 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2068] USER32.dll!GetWindowInfo 776600DB 5 Bytes JMP 679B92D0 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2108] USER32.dll!SetWindowLongA 7765B211 5 Bytes JMP 67BAA800 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2108] USER32.dll!GetWindowInfo 776600DB 5 Bytes JMP 679B229C C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2108] USER32.dll!SetWindowLongW 7767244A 5 Bytes JMP 67BAA792 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2108] USER32.dll!TrackPopupMenu 7767CFF8 5 Bytes JMP 679B2861 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

—- EOF - GMER 1.0.15 —-

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-09-12 16:23:49
—————————–
16:23:49.176 OS Version: Windows 6.0.6000
16:23:49.176 Number of processors: 2 586 0x170A
16:23:49.177 ComputerName: USER-PC UserName: client
16:23:52.132 Initialize success
16:24:07.648 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2
16:24:07.651 Disk 0 Vendor: WDC_WD2500AAJS-61B4A0 01.03A01 Size: 238475MB BusType: 3
16:24:10.047 Disk 0 MBR read successfully
16:24:10.047 Disk 0 MBR scan
16:24:10.048 Disk 0 Windows VISTA default MBR code
16:24:10.150 Disk 0 scanning sectors +488395120
16:24:10.645 Disk 0 scanning C:\Windows\system32\drivers
16:25:28.994 Service scanning
16:25:30.551 Modules scanning
16:27:18.827 Disk 0 trace - called modules:
16:27:18.914 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll intelide.sys
16:27:18.918 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84ea9790]
16:27:18.921 3 ntkrnlpa.exe[820b07e2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-2[0x847f9bb0]
16:27:18.925 Scan finished successfully
16:28:57.504 Disk 0 MBR has been saved successfully to "C:\Users\client\Desktop\MBR.dat"
16:28:57.514 The log file has been saved successfully to "C:\Users\client\Desktop\aswMBR.txt"
Hi contemplator,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Thank you so much for helping me out here!

ComboFix 11-09-12.03 - client 09/12/2011 18:41:02.7.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.2.1033.18.2035.386 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-08-12 to 2011-09-12 )))))))))))))))))))))))))))))))
.
.
2011-09-12 22:48 . 2011-09-12 22:48 ——– d—–w- c:\users\client\AppData\Local\temp
2011-09-05 23:56 . 2011-09-05 23:57 ——– d—–w- c:\users\client\AppData\Roaming\HpUpdate
2011-09-05 23:56 . 2011-09-05 23:56 ——– d—–w- c:\windows\Hewlett-Packard
2011-08-16 18:46 . 2011-08-16 18:46 ——– d—–w- c:\program files\iPod
2011-08-16 18:46 . 2011-08-16 18:46 ——– d—–w- c:\program files\iTunes
2011-08-16 18:43 . 2011-08-16 18:43 ——– d—–w- c:\program files\Bonjour
2011-08-16 18:37 . 2011-08-16 18:37 ——– d—–w- c:\program files\Apple Software Update
2011-08-16 11:20 . 2011-08-16 11:20 4892320 —-a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-12 15:20 . 2011-07-12 15:20 83816 —-a-w- c:\windows\system32\dns-sd.exe
2011-07-12 15:20 . 2011-07-12 15:20 73064 —-a-w- c:\windows\system32\dnssd.dll
2011-07-12 15:20 . 2011-07-12 15:20 50536 —-a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 15:20 . 2011-07-12 15:20 178536 —-a-w- c:\windows\system32\dnssdX.dll
2011-07-05 22:37 . 2011-07-05 22:37 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 22:37 . 2011-07-05 22:37 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-09-08 11:44 . 2011-04-03 04:22 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-10-11 1232896]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-07-09 49968]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-11-20 2590456]
"ooVoo.exe"="c:\program files\ooVoo\oovoo.exe" [2011-05-18 22631608]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"Facebook Update"="c:\users\client\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-07-14 137536]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-08-26 17361032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2009-10-24 597792]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-12-09 74752]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-07-19 421736]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
.
c:\users\client\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0bootdelete
.
R2 gupdate1ca77a318b0b950;Google Update Service (gupdate1ca77a318b0b950);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 133104]
R3 apf001;apf001;c:\game\SoftnyxGame\GunBoundIS\apf001.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 133104]
R3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2010-06-03 15944]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-05-29 39984]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-10-29 3407292]
R3 XDva281;XDva281;c:\windows\system32\XDva281.sys [x]
R3 XDva300;XDva300;c:\windows\system32\XDva300.sys [x]
R3 XDva380;XDva380;c:\windows\system32\XDva380.sys [x]
R3 XDva385;XDva385;c:\windows\system32\XDva385.sys [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-11 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001Core.job
- c:\users\client\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-07-08 03:13]
.
2011-09-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001UA.job
- c:\users\client\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-07-08 03:13]
.
2011-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 01:09]
.
2011-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 01:09]
.
2011-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001Core.job
- c:\users\client\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-28 22:36]
.
2011-09-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001UA.job
- c:\users\client\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-28 22:36]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = ;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://urlseek40.vmn.net/search.php?lg=en&type=dns&tbn=oovoo2_0dn&q=
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-12 18:48
Windows 6.0.6000 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
Completion time: 2011-09-12 18:50:41
ComboFix-quarantined-files.txt 2011-09-12 22:50
.
Pre-Run: 124,171,476,992 bytes free
Post-Run: 124,247,326,720 bytes free
.
- - End Of File - - A349297FC52919E951C791351BA8CD58
Hi contemplator,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

DDS::
uInternet Settings,ProxyOverride = ;*.local
BHO: Shop to Win 18: {ca2f8e90-0e43-46ad-89c0-7634a233ed00} - c:\program files\shop to win 18\Shop to Win 18.dll

Firefox::
FF - ProfilePath - c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\
FF - prefs.js: keyword.URL -


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
———-
ComboFix 11-09-12.03 - client 09/13/2011 16:16:23.8.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.2.1033.18.2035.1152 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\client\Desktop\CFScript.txt.txt
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-08-13 to 2011-09-13 )))))))))))))))))))))))))))))))
.
.
2011-09-13 20:22 . 2011-09-13 20:22 ——– d—–w- c:\users\client\AppData\Local\temp
2011-09-13 20:22 . 2011-09-13 20:22 ——– d—–w- c:\users\user\AppData\Local\temp
2011-09-13 20:22 . 2011-09-13 20:22 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-09-13 20:22 . 2011-09-13 20:22 ——– d—–w- c:\users\Guest\AppData\Local\temp
2011-09-13 20:22 . 2011-09-13 20:22 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-09-05 23:56 . 2011-09-05 23:57 ——– d—–w- c:\users\client\AppData\Roaming\HpUpdate
2011-09-05 23:56 . 2011-09-05 23:56 ——– d—–w- c:\windows\Hewlett-Packard
2011-08-16 18:46 . 2011-08-16 18:46 ——– d—–w- c:\program files\iPod
2011-08-16 18:46 . 2011-08-16 18:46 ——– d—–w- c:\program files\iTunes
2011-08-16 18:43 . 2011-08-16 18:43 ——– d—–w- c:\program files\Bonjour
2011-08-16 18:37 . 2011-08-16 18:37 ——– d—–w- c:\program files\Apple Software Update
2011-08-16 11:20 . 2011-08-16 11:20 4892320 —-a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-12 15:20 . 2011-07-12 15:20 83816 —-a-w- c:\windows\system32\dns-sd.exe
2011-07-12 15:20 . 2011-07-12 15:20 73064 —-a-w- c:\windows\system32\dnssd.dll
2011-07-12 15:20 . 2011-07-12 15:20 50536 —-a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 15:20 . 2011-07-12 15:20 178536 —-a-w- c:\windows\system32\dnssdX.dll
2011-07-05 22:37 . 2011-07-05 22:37 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 22:37 . 2011-07-05 22:37 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-09-08 11:44 . 2011-04-03 04:22 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-10-11 1232896]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-07-09 49968]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-11-20 2590456]
"ooVoo.exe"="c:\program files\ooVoo\oovoo.exe" [2011-05-18 22631608]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"Facebook Update"="c:\users\client\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-07-14 137536]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-08-26 17361032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2009-10-24 597792]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-12-09 74752]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-07-19 421736]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
.
c:\users\client\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0bootdelete
.
R2 gupdate1ca77a318b0b950;Google Update Service (gupdate1ca77a318b0b950);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 133104]
R3 apf001;apf001;c:\game\SoftnyxGame\GunBoundIS\apf001.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 133104]
R3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2010-06-03 15944]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-05-29 39984]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-10-29 3407292]
R3 XDva281;XDva281;c:\windows\system32\XDva281.sys [x]
R3 XDva300;XDva300;c:\windows\system32\XDva300.sys [x]
R3 XDva380;XDva380;c:\windows\system32\XDva380.sys [x]
R3 XDva385;XDva385;c:\windows\system32\XDva385.sys [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-11 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001Core.job
- c:\users\client\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-07-08 03:13]
.
2011-09-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001UA.job
- c:\users\client\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-07-08 03:13]
.
2011-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 01:09]
.
2011-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 01:09]
.
2011-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001Core.job
- c:\users\client\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-28 22:36]
.
2011-09-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001UA.job
- c:\users\client\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-28 22:36]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = ;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://urlseek40.vmn.net/search.php?lg=en&type=dns&tbn=oovoo2_0dn&q=
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-13 16:22
Windows 6.0.6000 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
Completion time: 2011-09-13 16:24:06
ComboFix-quarantined-files.txt 2011-09-13 20:24
ComboFix2.txt 2011-09-12 22:50
.
Pre-Run: 125,006,348,288 bytes free
Post-Run: 124,479,811,584 bytes free
.
- - End Of File - - 06E83FC331D99FFF045F6F1EF185F839
Hi contemplator,

It looks like there is one entry that is wanting to be stubborn. :) Lets try this again. When you save the CFScript.txt be sure to save the Type as All Files
———

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Firefox::
FF - ProfilePath - c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\
FF - prefs.js: keyword.URL -


Save this as CFScript.txt, and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
———-
ComboFix 11-09-12.03 - client 09/14/2011 15:28:39.9.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.2.1033.18.2035.1084 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\client\Desktop\CFScript.txt.txt
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-08-14 to 2011-09-14 )))))))))))))))))))))))))))))))
.
.
2011-09-14 19:35 . 2011-09-14 19:35 ——– d—–w- c:\users\client\AppData\Local\temp
2011-09-14 19:35 . 2011-09-14 19:35 ——– d—–w- c:\users\user\AppData\Local\temp
2011-09-14 19:35 . 2011-09-14 19:35 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-09-14 19:35 . 2011-09-14 19:35 ——– d—–w- c:\users\Guest\AppData\Local\temp
2011-09-14 19:35 . 2011-09-14 19:35 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-09-05 23:56 . 2011-09-05 23:57 ——– d—–w- c:\users\client\AppData\Roaming\HpUpdate
2011-09-05 23:56 . 2011-09-05 23:56 ——– d—–w- c:\windows\Hewlett-Packard
2011-08-16 18:46 . 2011-08-16 18:46 ——– d—–w- c:\program files\iPod
2011-08-16 18:46 . 2011-08-16 18:46 ——– d—–w- c:\program files\iTunes
2011-08-16 18:43 . 2011-08-16 18:43 ——– d—–w- c:\program files\Bonjour
2011-08-16 18:37 . 2011-08-16 18:37 ——– d—–w- c:\program files\Apple Software Update
2011-08-16 11:20 . 2011-08-16 11:20 4892320 —-a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-12 15:20 . 2011-07-12 15:20 83816 —-a-w- c:\windows\system32\dns-sd.exe
2011-07-12 15:20 . 2011-07-12 15:20 73064 —-a-w- c:\windows\system32\dnssd.dll
2011-07-12 15:20 . 2011-07-12 15:20 50536 —-a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 15:20 . 2011-07-12 15:20 178536 —-a-w- c:\windows\system32\dnssdX.dll
2011-07-05 22:37 . 2011-07-05 22:37 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 22:37 . 2011-07-05 22:37 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-09-08 11:44 . 2011-04-03 04:22 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-10-11 1232896]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-07-09 49968]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-11-20 2590456]
"ooVoo.exe"="c:\program files\ooVoo\oovoo.exe" [2011-05-18 22631608]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"Facebook Update"="c:\users\client\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-07-14 137536]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-09-12 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2009-10-24 597792]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-12-09 74752]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-07-19 421736]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
.
c:\users\client\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0bootdelete
.
R2 gupdate1ca77a318b0b950;Google Update Service (gupdate1ca77a318b0b950);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 133104]
R3 apf001;apf001;c:\game\SoftnyxGame\GunBoundIS\apf001.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 133104]
R3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2010-06-03 15944]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-05-29 39984]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-10-29 3407292]
R3 XDva281;XDva281;c:\windows\system32\XDva281.sys [x]
R3 XDva300;XDva300;c:\windows\system32\XDva300.sys [x]
R3 XDva380;XDva380;c:\windows\system32\XDva380.sys [x]
R3 XDva385;XDva385;c:\windows\system32\XDva385.sys [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-11 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001Core.job
- c:\users\client\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-07-08 03:13]
.
2011-09-14 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001UA.job
- c:\users\client\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-07-08 03:13]
.
2011-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 01:09]
.
2011-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-08 01:09]
.
2011-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001Core.job
- c:\users\client\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-28 22:36]
.
2011-09-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3684193004-2906459474-1321494355-1001UA.job
- c:\users\client\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-28 22:36]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = ;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\client\AppData\Roaming\Mozilla\Firefox\Profiles\kl6gjpcx.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-14 15:35
Windows 6.0.6000 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
Completion time: 2011-09-14 15:37:31
ComboFix-quarantined-files.txt 2011-09-14 19:37
ComboFix2.txt 2011-09-13 20:24
ComboFix3.txt 2011-09-12 22:50
.
Pre-Run: 124,492,165,120 bytes free
Post-Run: 124,494,635,008 bytes free
.
- - End Of File - - CA6BD0CF2E1861DEA2A9996F6E1A6D7F
Hi contemplator,

There we go. It worked that time. :thumbup:


I notice that you have Malwarebytes on your computer. Please open the program, Update it and then run a Quick Scan. Once complete it will produce a log that I will need in your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs created by Malwarebytes and ESET Online Scanner. :)
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7718 Windows 6.0.6000 Internet Explorer 7.0.6000.17037 9/14/2011 6:25:37 PM mbam-log-2011-09-14 (18-25-32).txt Scan type: Quick scan Objects scanned: 196413 Time elapsed: 6 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 8 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Windows\System32\config\systemprofile\AppData\Roaming\020000007a57a9991270c.manifest (Malware.Trace) -> No action taken. c:\Windows\System32\config\systemprofile\AppData\Roaming\020000007a57a9991270o.manifest (Malware.Trace) -> No action taken. c:\Windows\System32\config\systemprofile\AppData\Roaming\020000007a57a9991270p.manifest (Malware.Trace) -> No action taken. c:\Windows\System32\config\systemprofile\AppData\Roaming\020000007a57a9991270s.manifest (Malware.Trace) -> No action taken. c:\Windows\System32\020000007a57a9991270c.manifest (Malware.Trace) -> No action taken. c:\Windows\System32\020000007a57a9991270o.manifest (Malware.Trace) -> No action taken. c:\Windows\System32\020000007a57a9991270p.manifest (Malware.Trace) -> No action taken. c:\Windows\System32\020000007a57a9991270s.manifest (Malware.Trace) -> No action taken.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI