I'm having a problem with my computer and I'm concerned it may be a trojan/malware issue, occasionally Firefox will freeze and when it is closed and restarted it will complain that the program is already running. I checked in Task Manager and the application is not visible but the processes pane shows a Firefox.exe process running which can't be killed by task manager.
Once this happens the computer won't shut down or log off and has to be killed with a "hard reset".
The Hijack This! log is below and i've attached attach.txt, any help you could give would be much appreciated.
Many thanks,
Paul
DDS (Ver_09-06-26.01) - NTFSx86
Run by Paul at 20:44:06.08 on 06/07/2009
Internet Explorer: 8.0.6001.18783 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2039.848 [GMT 1:00]
SP: ZoneAlarm Anti-Spyware *enabled* (Outdated) {F245A209-1085-48B4-B927-35D56015EC60}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k rpcss
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\SLsvc.exe
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\windows\system32\taskeng.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\AEADISRV.EXE
C:\Windows\system32\agrsmsvc.exe
C:\windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\windows\System32\svchost.exe -k HPZ12
C:\Program Files\PDF Complete\pdfsvc.exe
C:\windows\System32\svchost.exe -k HPZ12
C:\windows\system32\Dwm.exe
C:\windows\system32\taskeng.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\System32\svchost.exe -k WerSvcGroup
C:\windows\system32\SearchIndexer.exe
C:\windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\PDF Complete\pdfsty.exe
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\regedit.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\explorer.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\Paul\Desktop\dds.scr
C:\windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [PDF Complete] "c:\program files\pdf complete\pdfsty.exe"
mRun: [PTHOSTTR] c:\program files\hewlett-packard\hp protecttools security manager\PTHOSTTR.EXE /Start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
StartupFolder: c:\users\paul\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dvdche~1.lnk - c:\program files\intervideo\dvd check\DVDCheck.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: DeviceNP - DeviceNP.dll
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\paul\appdata\roaming\mozilla\firefox\profiles\csymspz3.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-24 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-24 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-6-24 51792]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\pdf complete\pdfsvc.exe [2008-11-22 540448]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-11-22 193840]
R3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\drivers\NETw5v32.sys [2008-4-28 3658752]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-1-21 179712]
S3 DAMDrv;DAMDrv;c:\windows\system32\drivers\DAMDrv.sys [2007-6-8 30008]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\system32\flcdlock.exe [2007-6-8 172131]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe [2008-4-8 1112560]
SUnknown rpcnetp;rpcnetp; [x]
=============== Created Last 30 ================
2009-07-06 19:36 <DIR> --d----- c:\program files\Trend Micro
2009-07-06 18:22 17,408 a------- c:\windows\system32\rpcnetp.exe
2009-06-27 13:03 <DIR> --d----- c:\users\paul\appdata\roaming\OpenOffice.org
2009-06-26 19:42 1,221,512 a------- c:\windows\system32\zpeng25.dll
2009-06-26 19:41 350,192 a---h--- c:\windows\system32\drivers\vsconfig.xml
2009-06-26 19:41 293,528 a------- c:\windows\system32\drivers\vsdatant.sys
2009-06-26 19:41 <DIR> --d----- c:\windows\system32\ZoneLabs
2009-06-25 01:11 12 a------- c:\windows\bthservsdp.dat
2009-06-24 21:19 170,496 a------- c:\windows\system32\tcpipcfg.dll
2009-06-24 21:19 22,528 a------- c:\windows\system32\netiougc.exe
2009-06-24 21:18 <DIR> --d----- c:\program files\Zone Labs
2009-06-24 21:15 <DIR> --d----- c:\programdata\CheckPoint
2009-06-24 21:15 <DIR> --d----- c:\progra~2\CheckPoint
2009-06-24 21:15 <DIR> --d----- c:\windows\Internet Logs
2009-06-24 21:02 <DIR> --d----- c:\program files\JRE
2009-06-24 21:02 <DIR> --d----- c:\program files\OpenOffice.org 3
2009-06-24 20:07 56 a---h--- c:\programdata\ezsidmv.dat
2009-06-24 20:07 56 a---h--- c:\progra~2\ezsidmv.dat
2009-06-24 20:06 <DIR> --d--r-- c:\program files\Skype
2009-06-24 20:06 <DIR> --d----- c:\programdata\Skype
2009-06-24 20:01 410,984 a------- c:\windows\system32\deploytk.dll
2009-06-24 19:03 51,792 a------- c:\windows\system32\drivers\aswMonFlt.sys
2009-06-24 18:47 72,704 a------- c:\windows\system32\admparse.dll
2009-06-24 18:44 <DIR> --d----- C:\Anquet Map Data
2009-06-24 18:43 <DIR> --d----- c:\program files\Anquet Technology Ltd
2009-06-24 18:20 2,048 a------- c:\windows\system32\tzres.dll
2009-06-24 18:09 105,016 a------- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-24 18:09 97,800 a------- c:\windows\system32\infocardapi.dll
2009-06-24 18:09 622,080 a------- c:\windows\system32\icardagt.exe
2009-06-24 18:09 43,544 a------- c:\windows\system32\PresentationHostProxy.dll
2009-06-24 18:09 37,384 a------- c:\windows\system32\infocardcpl.cpl
2009-06-24 18:09 11,264 a------- c:\windows\system32\icardres.dll
2009-06-24 18:09 781,344 a------- c:\windows\system32\PresentationNative_v0300.dll
2009-06-24 18:09 326,160 a------- c:\windows\system32\PresentationHost.exe
2009-06-24 18:05 96,760 a------- c:\windows\system32\dfshim.dll
2009-06-24 18:05 282,112 a------- c:\windows\system32\mscoree.dll
2009-06-24 18:05 41,984 a------- c:\windows\system32\netfxperf.dll
2009-06-24 18:05 158,720 a------- c:\windows\system32\mscorier.dll
2009-06-24 18:05 83,968 a------- c:\windows\system32\mscories.dll
2009-06-24 18:04 <DIR> --d----- c:\program files\MSXML 4.0
2009-06-24 17:56 428,544 a------- c:\windows\system32\EncDec.dll
2009-06-24 17:56 217,088 a------- c:\windows\system32\psisrndr.ax
2009-06-24 17:56 293,376 a------- c:\windows\system32\psisdecd.dll
2009-06-24 17:56 177,664 a------- c:\windows\system32\mpg2splt.ax
2009-06-24 17:56 80,896 a------- c:\windows\system32\MSNP.ax
2009-06-24 17:56 57,856 a------- c:\windows\system32\MSDvbNP.ax
2009-06-24 17:54 2,868,736 a------- c:\windows\system32\mf.dll
2009-06-24 17:54 996,352 a------- c:\windows\system32\WMNetMgr.dll
2009-06-24 17:54 94,720 a------- c:\windows\system32\logagent.exe
2009-06-24 17:54 2,033,152 a------- c:\windows\system32\win32k.sys
2009-06-24 17:54 376,832 a------- c:\windows\system32\winhttp.dll
2009-06-24 17:54 562,176 a------- c:\windows\system32\msdtcprx.dll
2009-06-24 17:54 38,912 a------- c:\windows\system32\xolehlp.dll
2009-06-24 17:52 288,768 a------- c:\windows\system32\drivers\srv.sys
2009-06-24 17:52 712,704 a------- c:\windows\system32\WindowsCodecs.dll
2009-06-24 17:52 425,472 a------- c:\windows\system32\PhotoMetadataHandler.dll
2009-06-24 17:52 347,136 a------- c:\windows\system32\WindowsCodecsExt.dll
2009-06-24 17:52 2,927,104 a------- c:\windows\explorer.exe
2009-06-24 17:51 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-06-24 17:51 7,680 a------- c:\windows\system32\spwmp.dll
2009-06-24 17:51 4,096 a------- c:\windows\system32\msdxm.ocx
2009-06-24 17:51 4,096 a------- c:\windows\system32\dxmasf.dll
2009-06-24 17:51 241,152 a------- c:\windows\system32\PortableDeviceApi.dll
2009-06-24 17:51 1,191,936 a------- c:\windows\system32\msxml3.dll
2009-06-24 17:51 636,928 a------- c:\windows\system32\localspl.dll
2009-06-24 17:50 1,334,272 a------- c:\windows\system32\msxml6.dll
2009-06-24 17:50 147,456 a------- c:\windows\system32\Faultrep.dll
2009-06-24 17:50 125,952 a------- c:\windows\system32\wersvc.dll
2009-06-24 17:40 1,524,736 a------- c:\windows\system32\wucltux.dll
2009-06-24 17:39 83,456 a------- c:\windows\system32\wudriver.dll
2009-06-24 17:39 162,064 a------- c:\windows\system32\wuwebv.dll
2009-06-24 17:39 31,232 a------- c:\windows\system32\wuapp.exe
2009-06-24 17:38 384 a------- c:\windows\myClean.bat
2009-06-24 17:36 <DIR> --d----- c:\users\paul\Bluetooth Software
2009-06-24 17:36 44 a------- c:\windows\system\hpsysdrv.dat
2009-06-24 17:29 80,936 a------- c:\windows\system32\drivers\btwavdt.sys
2009-06-24 17:29 80,424 a------- c:\windows\system32\drivers\btwaudio.sys
2009-06-24 17:29 16,168 a------- c:\windows\system32\drivers\btwrchid.sys
2009-06-24 17:29 233,472 a------- c:\windows\system32\BtwRSupport.dll
2009-06-24 17:29 <DIR> --d----- c:\windows\system32\es-MX
2009-06-24 17:29 <DIR> --d----- c:\windows\system32\es-AR
2009-06-24 17:29 <DIR> --d----- c:\program files\WIDCOMM
2009-06-24 17:26 204,800 a------- c:\windows\system32\IVIresizeW7.dll
2009-06-24 17:26 188,416 a------- c:\windows\system32\IVIresizePX.dll
2009-06-24 17:26 200,704 a------- c:\windows\system32\IVIresizeA6.dll
2009-06-24 17:26 192,512 a------- c:\windows\system32\IVIresizeP6.dll
2009-06-24 17:26 192,512 a------- c:\windows\system32\IVIresizeM6.dll
2009-06-24 17:26 20,480 a------- c:\windows\system32\IVIresize.dll
2009-06-24 17:24 <DIR> --d----- c:\program files\common files\InterVideo
2009-06-24 17:24 <DIR> --d----- c:\program files\InterVideo
2009-06-24 17:24 0 a--shr-- c:\windows\system32\drivers\103C_HP_bNB_550_Y5336AN_0U_QCNU91030CH_E489318-A42_4A_I3618_SHP_V12.00_68MVU F.05_T090119_WV3-1_L409_M2039_J160_7Intel_86FD_91.80_#081121_N_(NN312EA#ABU)_XMOBILE_CN10_Z_2F.05_G80862A12;80862A13.MRK
2009-06-24 17:23 <DIR> --d----- c:\users\Paul
==================== Find3M ====================
2009-07-06 18:38 17,408 a------- c:\windows\system32\rpcnetp.dll
2009-06-30 09:17 714,398 a------- c:\windows\system32\perfh013.dat
2009-06-30 09:17 151,514 a------- c:\windows\system32\perfc013.dat
2009-06-26 19:42 143,360 a------- c:\windows\inf\infstrng.dat
2009-06-26 19:42 51,200 a------- c:\windows\inf\infpub.dat
2009-06-26 19:42 86,016 a------- c:\windows\inf\infstor.dat
2009-05-09 06:50 915,456 a------- c:\windows\system32\wininet.dll
2009-05-09 06:34 71,680 a------- c:\windows\system32\iesetup.dll
2009-04-23 13:43 784,896 a------- c:\windows\system32\rpcrt4.dll
2008-11-22 08:44 665,600 a------- c:\windows\inf\drvindex.dat
2008-04-16 00:09 336,440 a------- c:\windows\inf\perflib\0413\perfi.dat
2008-04-16 00:09 41,976 a------- c:\windows\inf\perflib\0413\perfd.dat
2008-04-16 00:09 41,976 a------- c:\windows\inf\perflib\0413\perfc.dat
2008-04-16 00:09 336,440 a------- c:\windows\inf\perflib\0413\perfh.dat
2008-01-21 03:43 174 a--sh--- c:\program files\desktop.ini
2006-11-02 13:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 13:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 13:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 13:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 10:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 20:44:32.24 ===============