Both Malware Bytes and GMER didn't found any malicious things.
Here's my DDS logfile.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Run by Wesley at 21:53:11 on 2011-11-18
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.8175.5623 [GMT 1:00]
.
SP: Windows Defender Enabled/Outdated {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\mIRC\mirc.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\aMSN\bin\wish.exe
C:\Users\Wesley\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wesley\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Wesley\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wesley\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Users\Wesley\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wesley\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Wesley\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyServer = http=127.0.0.1:58384
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
StartupFolder: C:\Users\Wesley\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\POWERM~1.LNK - C:\Program Files (x86)\PowerMenu\PowerMenu.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\GAMERS~1.LNK - C:\Program Files (x86)\GamersFirst\LIVE!\Live.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOLREC~1.LNK - C:\Program Files (x86)\LOLReplay\LOLRecorder.exe
mPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: DhcpNameServer = 10.0.0.1
TCP: Interfaces{08E6F36C-1A5B-4F60-BDED-1AC53DC248C1} : DhcpNameServer = 10.0.0.1
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
.
============= SERVICES / DRIVERS ===============
.
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\system32\Drivers\EtronHub3.sys --> C:\Windows\system32\Drivers\EtronHub3.sys [?]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\system32\Drivers\EtronXHCI.sys --> C:\Windows\system32\Drivers\EtronXHCI.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-6 366152]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
.
=============== Created Last 30 ================
.
2011-11-18 20:36:15 -------- d-sh--w- C:\$RECYCLE.BIN
2011-11-16 18:40:24 -------- d-----w- C:\ComboFix
2011-11-16 17:56:18 98816 ----a-w- C:\Windows\sed.exe
2011-11-16 17:56:18 518144 ----a-w- C:\Windows\SWREG.exe
2011-11-16 17:56:18 256000 ----a-w- C:\Windows\PEV.exe
2011-11-16 17:56:18 208896 ----a-w- C:\Windows\MBR.exe
2011-11-12 03:39:29 -------- d-----w- C:\Users\Wesley\AppData\Local\Skyrim
2011-11-12 01:54:59 238088 ----a-w- C:\Windows\SysWow64\xactengine3_0.dll
2011-11-12 01:53:55 3767504 ----a-w- C:\Windows\System32\d3dx9_26.dll
2011-11-12 01:53:55 2297552 ----a-w- C:\Windows\SysWow64\d3dx9_26.dll
2011-11-12 01:50:58 -------- d-----w- C:\Program Files (x86)\The Elder Scrolls V Skyrim
2011-11-09 02:17:09 77656 ----a-w- C:\Windows\System32\XAPOFX1_5.dll
2011-11-09 02:17:09 74072 ----a-w- C:\Windows\SysWow64\XAPOFX1_5.dll
2011-11-09 02:17:09 527192 ----a-w- C:\Windows\SysWow64\XAudio2_7.dll
2011-11-09 02:17:07 239960 ----a-w- C:\Windows\SysWow64\xactengine3_7.dll
2011-11-09 02:17:07 176984 ----a-w- C:\Windows\System32\xactengine3_7.dll
2011-11-09 02:17:05 2526056 ----a-w- C:\Windows\System32\D3DCompiler_43.dll
2011-11-09 02:17:04 1907552 ----a-w- C:\Windows\System32\d3dcsx_43.dll
2011-11-09 02:17:04 1868128 ----a-w- C:\Windows\SysWow64\d3dcsx_43.dll
2011-11-09 02:17:03 276832 ----a-w- C:\Windows\System32\d3dx11_43.dll
2011-11-09 02:17:03 248672 ----a-w- C:\Windows\SysWow64\d3dx11_43.dll
2011-11-09 02:17:00 511328 ----a-w- C:\Windows\System32\d3dx10_43.dll
2011-11-09 02:17:00 470880 ----a-w- C:\Windows\SysWow64\d3dx10_43.dll
2011-11-09 02:16:57 2401112 ----a-w- C:\Windows\System32\D3DX9_43.dll
2011-11-09 02:16:54 24920 ----a-w- C:\Windows\System32\X3DAudio1_7.dll
2011-11-09 02:16:54 22360 ----a-w- C:\Windows\SysWow64\X3DAudio1_7.dll
2011-11-09 02:16:52 81768 ----a-w- C:\Windows\SysWow64\xinput1_3.dll
2011-11-06 21:40:04 -------- d-----w- C:\Program Files (x86)\79443
2011-11-06 21:37:26 -------- d-----w- C:\Users\Wesley\AppData\Roaming\Malwarebytes
2011-11-06 21:37:14 -------- d-----w- C:\ProgramData\Malwarebytes
2011-11-06 21:37:10 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-11-06 21:22:39 -------- d-----w- C:\Users\Wesley\AppData\Local\Google
2011-11-06 15:25:44 -------- d-----w- C:\Users\Wesley\AppData\Roaming\79443
2011-11-06 15:25:25 -------- d-----w- C:\Users\Wesley\AppData\Roaming\EAE79
2011-11-05 00:03:03 388096 ----a-r- C:\Users\Wesley\AppData\Roaming\Microsoft\Installer{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-11-05 00:03:03 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-10-25 17:26:35 -------- d-----w- C:\Users\Wesley\jagexcache
2011-10-24 23:55:19 281656 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-10-24 23:55:16 -------- d-----w- C:\Users\Wesley\AppData\Local\PunkBuster
2011-10-24 22:01:47 281656 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-10-24 22:01:47 281200 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-10-24 22:01:44 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-10-24 22:01:20 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2011-10-24 22:01:13 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2011-10-24 05:16:50 -------- d-----w- C:\Users\Wesley\AppData\Local\GamersFirst LIVE!
2011-10-24 05:16:45 -------- d-----w- C:\Users\Wesley\AppData\Local\PMB Files
2011-10-24 05:16:44 -------- d-----w- C:\ProgramData\PMB Files
2011-10-24 05:16:42 -------- d-----w- C:\Program Files (x86)\Pando Networks
2011-10-24 05:16:37 -------- d-----w- C:\Program Files (x86)\GamersFirst
.
==================== Find3M ====================
.
2011-10-13 20:30:24 28056 ----a-w- C:\Windows\System32\xfcodec64.dll
2011-10-08 20:08:13 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-10-07 20:07:40 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-07 20:02:00 0 ----a-w- C:\Windows\ativpsrm.bin
2011-09-14 09:47:42 60416 ----a-w- C:\Windows\System32\OVDecode64.dll
2011-09-14 09:47:40 53760 ----a-w- C:\Windows\SysWow64\OVDecode.dll
2011-09-14 09:47:22 51200 ----a-w- C:\Windows\System32\OpenCL.dll
2011-09-14 09:47:18 43520 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2011-09-14 09:47:10 16652288 ----a-w- C:\Windows\System32\amdocl64.dll
2011-09-14 09:46:58 13625856 ----a-w- C:\Windows\SysWow64\amdocl.dll
2011-09-14 09:38:30 44032 ----a-w- C:\Windows\System32\amdoclcl64.dll
2011-09-14 09:38:28 37376 ----a-w- C:\Windows\SysWow64\amdoclcl.dll
2011-09-08 18:27:22 10203648 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-09-08 17:59:44 24229376 ----a-w- C:\Windows\System32\atio6axx.dll
2011-09-08 17:39:44 18534912 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2011-09-08 17:34:20 151552 ----a-w- C:\Windows\System32\atiapfxx.exe
2011-09-08 17:34:10 732672 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2011-09-08 17:32:58 862720 ----a-w- C:\Windows\System32\aticfx64.dll
2011-09-08 17:30:38 466944 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2011-09-08 17:30:26 486912 ----a-w- C:\Windows\System32\atieclxx.exe
2011-09-08 17:29:56 204288 ----a-w- C:\Windows\System32\atiesrxx.exe
2011-09-08 17:28:54 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2011-09-08 17:28:38 423424 ----a-w- C:\Windows\System32\atipdl64.dll
2011-09-08 17:28:32 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-09-08 17:28:22 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-09-08 17:28:18 21504 ----a-w- C:\Windows\System32\atimuixx.dll
2011-09-08 17:28:14 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2011-09-08 17:28:10 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-09-08 17:24:38 4204032 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2011-09-08 17:18:56 1113088 ----a-w- C:\Windows\System32\atiumd6v.dll
2011-09-08 17:18:22 1828864 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
2011-09-08 17:18:08 3888640 ----a-w- C:\Windows\System32\atiumd6a.dll
2011-09-08 17:16:00 4944896 ----a-w- C:\Windows\System32\atidxx64.dll
2011-09-08 17:09:42 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2011-09-08 17:09:40 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2011-09-08 17:09:30 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2011-09-08 17:09:28 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2011-09-08 17:09:18 8723456 ----a-w- C:\Windows\System32\aticaldd64.dll
2011-09-08 17:08:24 4064768 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2011-09-08 17:05:52 7331840 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2011-09-08 17:05:44 4289024 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2011-09-08 17:00:02 5428736 ----a-w- C:\Windows\System32\atiumd64.dll
2011-09-08 16:59:48 58880 ----a-w- C:\Windows\System32\coinst.dll
2011-09-08 16:53:20 381952 ----a-w- C:\Windows\System32\atiadlxx.dll
2011-09-08 16:53:12 270336 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-09-08 16:52:58 15360 ----a-w- C:\Windows\System32\atig6pxx.dll
2011-09-08 16:52:56 13312 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2011-09-08 16:52:56 13312 ----a-w- C:\Windows\System32\atiglpxx.dll
2011-09-08 16:52:54 39936 ----a-w- C:\Windows\System32\atig6txx.dll
2011-09-08 16:52:46 32768 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2011-09-08 16:52:40 310784 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2011-09-08 16:52:00 40960 ----a-w- C:\Windows\System32\atiuxp64.dll
2011-09-08 16:51:54 31744 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2011-09-08 16:51:50 38912 ----a-w- C:\Windows\System32\atiu9p64.dll
2011-09-08 16:51:44 29184 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2011-09-08 16:51:12 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-09-08 16:51:02 54784 ----a-w- C:\Windows\System32\atimpc64.dll
2011-09-08 16:51:02 54784 ----a-w- C:\Windows\System32\amdpcom64.dll
2011-09-08 16:50:54 53760 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2011-09-08 16:50:54 53760 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
.
============= FINISH: 21:59:48,34 ===============
and the Attach.txt
<a href="/images/attachments/3/Attach.txt">Attach.txt</a>
My problems are simple; I have internet explorer running in the background that hogs some of my memory, the other part is that when I search on "Google.com" and click a result, I get malicious links that want me to buy their products. Best regards and many thanks on helping me out here.