jvguardianz
2011-10-02, 18:29
Hi
my laptop is being infected since 4 days ago .. when I try to search on Google, it will redirect to another sites ..
and when I tried to scan it with antivirus, it seems to be closed early without any notice ..
here's the DDS log ..
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_27
Run by gagaga at 22:12:25 on 2011-10-02
Microsoft Windows 8 Ultimate 6.1.7600.0.1252.1.1033.18.1909.1047 [GMT 7:00]
.
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\System32\spoolsv.exe
C:\windows\1798245580:871616660.exe
C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
H:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
C:\Program Files\ChiconyCam\CECPLFKT.exe
C:\Program Files\Connectify\Connectifyd.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\windows\system32\lxdpcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\ControlCenter\controlcenter.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Lexmark Z2300 Series\lxdpmon.exe
H:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files\Lexmark Z2300 Series\lxdpMsdMon.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\windows\system32\conhost.exe
C:\Program Files\SpyNoMore\SNM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
H:\Program Files\PC Tools Security\BDT\FGuard.exe
E:\Internet Download Manager\IDMan.exe
C:\Program Files\Connectify\Connectify.exe
H:\eBoostr\eBoostrCP.exe
E:\Rainmeter\Rainmeter.exe
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\windows\system32\svchost.exe -k imgsvc
H:\Program Files\Modem AC2726i UI\bin\MonServiceUDisk.exe
C:\Program Files\Motorola\Bluetooth\obexsrv.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
E:\Internet Download Manager\IEMonitor.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\wbem\unsecapp.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\Motorola\Bluetooth\audiosrv.exe
C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
C:\Program Files\Connectify\ConnectifyNetServices.exe
C:\windows\system32\conhost.exe
C:\windows\system32\sppsvc.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\system32\AUDIODG.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
mStart Page = about:blank
uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - h:\program files\pc tools security\bdt\PCTBrowserDefender.dll
mURLSearchHooks: Winamp Toolbar Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: Hot MP3 Toolbar: {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - c:\program files\hot_mp3\tbHot_.dll
BHO: AutorunsDisabled - No File
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - e:\internet download manager\IDMIECC.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - h:\program files\pc tools security\bdt\PCTBrowserDefender.dll
BHO: SBCONVERT Class: {3017fb3e-9a77-4396-88c5-0ec9548fb42f} - c:\program files\speedbit video downloader\tbu80\tbcore3.dll
BHO: SearchPredictObj Class: {389943b0-c3a2-4e69-82cb-8596a84cb3dc} - c:\progra~1\search~1\SEARCH~1.DLL
BHO: Shop to Win 11: {67d688ec-87da-4a28-bfa5-c4db8be5c9ea} - c:\program files\shop to win 11\Shop to Win 11.dll
BHO: Hot MP3 Toolbar: {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - c:\program files\hot_mp3\tbHot_.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: DAPIELoader Class: {ff6c3cf0-4b15-11d1-abed-709549c10000} - e:\dap\DAPIEL~1.DLL
BHO: GrabberObj Class: {ff7c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\speedb~1\tbu80\grabber.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: SpeedBit Video Downloader: {0329e7d6-6f54-462d-93f6-f5c3118badf2} - c:\program files\speedbit video downloader\tbu80\tbcore3.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} -
TB: SpeedBit: {ebfcd017-bcad-42c3-9ed5-89dbdfc59171} - c:\program files\speedbit toolbar\toolbar\tbcore3.dll
TB: Hot MP3 Toolbar: {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - c:\program files\hot_mp3\tbHot_.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - h:\program files\pc tools security\bdt\PCTBrowserDefender.dll
uRun: [IDMan] e:\internet download manager\IDMan.exe /onboot
uRun: [SM?RT-Protection] c:\program files\smadav\SM?RTP.exe rtp
uRun: [Connectify] c:\program files\connectify\Connectify.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [ControlCenter] c:\program files\controlcenter\ControlCenter.exe
mRun: [IAStorIcon] c:\program files\intel\intel(r) rapid storage technology\IAStorIcon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [BTMTrayAgent] rundll32.exe "c:\program files\motorola\bluetooth\btmshell.dll",TrayApp
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [lxdpmon.exe] "c:\program files\lexmark z2300 series\lxdpmon.exe"
mRun: [lxdpamon] "c:\program files\lexmark z2300 series\lxdpamon.exe"
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [<NO NAME>]
mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SpywareTerminatorShield] c:\program files\spyware terminator\SpywareTerminatorShield.exe
mRun: [SpywareTerminatorUpdater] c:\program files\spyware terminator\SpywareTerminatorUpdate.exe
mRun: [SNM] c:\program files\spynomore\SNM.exe /startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [PCTools FGuard] h:\program files\pc tools security\bdt\FGuard.exe
mRun: [Malwarebytes' Anti-Malware] "h:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\eboost~1.lnk - h:\eboostr\eBoostrCP.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hotkey.lnk - c:\program files\hotkey\Hotkey.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\rainme~1.lnk - e:\rainmeter\Rainmeter.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Download all links with IDM - e:\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - e:\internet download manager\IEGetVL.htm
IE: Download with IDM - e:\internet download manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\motorola\bluetooth\btmiesend.htm
IE: {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "c:\program files\fiddler2\Fiddler.exe"
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
TCP: DhcpNameServer = 202.162.209.26 8.8.8.8
TCP: Interfaces\{10A33F2F-37CE-42B1-B6E8-D52AE9B6547F} : NameServer = 192.168.2.1
TCP: Interfaces\{2B04DE6A-5FCE-4181-8E1B-3C684EF814EB} : NameServer = 10.8.15.15 10.8.17.4
TCP: Interfaces\{E27EC556-CE80-4AB8-9A8A-DD3CDB802EDB} : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{E27EC556-CE80-4AB8-9A8A-DD3CDB802EDB} : DhcpNameServer = 202.162.209.26 8.8.8.8
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - e:\dap\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - e:\dap\dapie.dll
Notify: igfxcui - igfxdev.dll
STS: AveVistaBackgroundFolder Class: {73526e5a-fd53-4be7-b5e2-d3c89d7413dc} - c:\windows\w7fbc\dll.dll
STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll
mASetup: {8BE421A2-13EA-4507-BB04-22A818F9FF74} - c:\program files\win32\windl.exe s
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\gagaga\appdata\roaming\mozilla\firefox\profiles\m9wbz0wb.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: h:\itunes\mozilla plugins\npitunes.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-9-26 263888]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-9-26 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-9-26 656320]
R1 cdrblock;cdrblock;c:\windows\system32\drivers\cdrblock.sys [2008-5-30 27704]
R1 cnnctfy2;Connectify LightWeight Filter;c:\windows\system32\drivers\cnnctfy2.sys [2011-9-26 27248]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2011-9-26 251560]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2011-9-26 32768]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files\motorola\bluetooth\obexsrv.exe [2011-1-18 508680]
R2 Browser Defender Update Service;Browser Defender Update Service;h:\program files\pc tools security\bdt\BDTUpdateService.exe [2011-9-27 337872]
R2 CECFLPKT;CECFLPKT;c:\program files\chiconycam\CECPLFKT.exe [2011-1-18 84592]
R2 Connectify;Connectify;c:\program files\connectify\Connectifyd.exe [2011-3-10 892992]
R2 HWEasyDevice;HWEasyDevice;c:\program files\controlcenter\HWEasy.sys [2010-10-25 16640]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\intel\intel(r) rapid storage technology\IAStorDataMgrSvc.exe [2010-10-25 13336]
R2 IDMWFP;IDMWFP;c:\windows\system32\drivers\idmwfp.sys [2011-2-12 85768]
R2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe -service --> c:\windows\system32\lxdpcoms.exe -service [?]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2011-9-26 160576]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\spyware terminator\st_rsser.exe [2011-9-26 482992]
R2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\drivers\TurboB.sys [2009-9-29 13752]
R2 UDisk Monitor;UDisk Monitor;h:\program files\modem ac2726i ui\bin\MonServiceUDisk.exe [2011-9-2 266240]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\intel\intel(r) management engine components\uns\UNS.exe [2010-10-25 2320920]
R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [2011-5-10 17984]
R3 Bluetooth Device Manager;Bluetooth Device Manager;c:\program files\motorola\bluetooth\devmgrsrv.exe [2011-1-18 3512072]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files\motorola\bluetooth\audiosrv.exe [2011-1-18 901384]
R3 connctfyMP;connctfyMP;c:\windows\system32\drivers\connctfy.sys [2011-3-8 29248]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2002-1-1 132480]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2002-1-1 232960]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2011-1-18 140376]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver;c:\windows\system32\drivers\JME.sys [2011-1-18 110064]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-8-21 22216]
R3 pctNdisMP;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [2011-9-27 56536]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\drivers\rtl8192ce.sys [2011-1-18 984168]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
S2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2011-8-17 402328]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 EBOOSTRSVC;eBoostr Service;h:\eboostr\EBstrSvc.exe [2010-4-15 647296]
S2 lxdpCATSCustConnectService;lxdpCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdpserv.exe [2007-12-1 98984]
S2 MBAMService;MBAMService;h:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-8-21 366152]
S2 PowerBiosServer;PowerBiosServer;c:\program files\hotkey\PowerBiosServer.exe [2010-3-3 33792]
S2 StarWindServiceAE;StarWind AE Service;e:\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2009-12-24 372736]
S2 tuEaglesService;tuEagles Service; [x]
S2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;"c:\program files\webroot\webrootsecurity\spysweeper.exe" --> c:\program files\webroot\webrootsecurity\SpySweeper.exe [?]
S2 WRConsumerService;Webroot Client Service;"c:\program files\webroot\webrootsecurity\wrconsumerservice.exe" --> c:\program files\webroot\webrootsecurity\WRConsumerService.exe [?]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 btmaudio;Motorola Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [2011-1-18 33280]
S3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\drivers\btmcom.sys [2011-1-18 41344]
S3 BTMMODEM;Bluetooth Modem Device;c:\windows\system32\drivers\btmcom.sys [2011-1-18 41344]
S3 BTMNET;Motorola Bluetooth Network Adapter Service;c:\windows\system32\drivers\btmnet.sys [2011-1-18 21760]
S3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\drivers\btmusb.sys [2011-1-18 395776]
S3 connctfy;Connectify Service;c:\windows\system32\drivers\connctfy.sys [2011-3-8 29248]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2011-8-19 200192]
S3 HideMyIpSRV;HideMyIpSRV;e:\hide my ip\HideMyIpSrv.exe [2011-3-3 3039536]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2011-8-19 101376]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2010-10-25 67624]
S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2011-9-27 89472]
S3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\drivers\pctNdis.sys [2011-9-27 56536]
S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2011-9-27 125248]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2011-9-26 70536]
S3 S6000KNT;S6000KNT_WebCam Driver;c:\windows\system32\drivers\S6000KNT.sys [2011-1-18 3314048]
S3 sdAuxService;PC Tools Auxiliary Service;h:\program files\pc tools security\pctsAuxs.exe [2011-9-26 371472]
S3 sdCoreService;PC Tools Security Service;h:\program files\pc tools security\pctsSvc.exe [2011-9-26 1117144]
S3 ThreatFire;ThreatFire;h:\program files\pc tools security\tfengine\tfservice.exe service --> h:\program files\pc tools security\tfengine\TFService.exe service [?]
S3 TrufosAlt;TrufosAlt;c:\windows\system32\drivers\TrufosAlt.sys [2011-10-2 339600]
S3 TurboBoost;TurboBoost;c:\program files\intel\turboboost\TurboBoost.exe [2009-9-29 99768]
S3 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~3\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~3\VideoAcceleratorService.exe -start -scm [?]
S3 ztemtusbser;ZTEMT Legacy Serial Communication;c:\windows\system32\drivers\CT_ZTEMT_U_USBSER.sys [2011-9-2 104704]
.
=============== Created Last 30 ================
.
2011-10-02 14:47:24 94896 ----a-w- c:\windows\system32\drivers\81363479.sys
2011-10-02 14:42:04 -------- d-s---w- C:\ComboFix
2011-10-02 14:14:22 339600 ----a-w- c:\windows\system32\drivers\TrufosAlt.sys
2011-09-29 05:21:35 -------- d-----w- c:\users\gagaga\appdata\local\Threat Expert
2011-09-27 15:58:59 -------- d-----w- c:\users\gagaga\appdata\local\ElevatedDiagnostics
2011-09-27 15:55:11 -------- d-----w- c:\program files\PC Tools Registry Tool
2011-09-27 15:44:13 767952 ----a-w- c:\windows\BDTSupport.dll
2011-09-27 15:44:12 2074576 ----a-w- c:\windows\PCTBDCore.dll
2011-09-27 15:44:12 1533904 ----a-w- c:\windows\PCTBDRes.dll
2011-09-27 15:44:12 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-09-27 15:43:14 233976 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2011-09-27 15:43:13 69392 ----a-w- c:\windows\system32\drivers\TfSysMon.sys
2011-09-27 15:43:12 51984 ----a-w- c:\windows\system32\drivers\TfFsMon.sys
2011-09-27 15:43:12 33552 ----a-w- c:\windows\system32\drivers\TfNetMon.sys
2011-09-27 15:43:02 89472 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2011-09-27 15:43:02 31960 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2011-09-27 15:43:01 56536 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2011-09-27 15:43:01 125248 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2011-09-27 14:31:15 47616 ----a-w- C:\Win32kDiag.exe
2011-09-27 14:30:28 476904 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-09-27 14:17:13 48016 --sha-w- c:\windows\system32\c_50510.nl_
2011-09-27 08:14:58 98816 ----a-w- c:\windows\sed.exe
2011-09-27 08:14:58 518144 ----a-w- c:\windows\SWREG.exe
2011-09-27 08:14:58 256000 ----a-w- c:\windows\PEV.exe
2011-09-27 08:14:58 208896 ----a-w- c:\windows\MBR.exe
2011-09-26 16:53:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-09-26 16:43:51 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2011-09-26 16:43:51 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
2011-09-26 16:43:50 251560 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-09-26 16:43:50 105280 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2011-09-26 16:43:42 263888 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-09-26 16:43:42 160576 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-09-26 16:43:39 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-09-26 16:43:32 -------- d-----w- c:\users\gagaga\appdata\roaming\PC Tools
2011-09-26 16:43:32 -------- d-----w- c:\program files\common files\PC Tools
2011-09-26 16:29:33 -------- d-----w- c:\programdata\PC Tools
2011-09-26 16:13:40 520496 ----a-w- c:\windows\Listdlls.exe
2011-09-26 16:13:31 423288 ----a-w- c:\windows\handle.exe
2011-09-26 16:04:42 1152 ----a-w- c:\windows\system32\windrv.sys
2011-09-26 16:04:24 -------- d-----w- c:\program files\SpyNoMore
2011-09-26 15:44:19 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-09-26 15:44:19 -------- d-----w- c:\users\gagaga\appdata\roaming\Spyware Terminator
2011-09-26 15:44:19 -------- d-----w- c:\programdata\Spyware Terminator
2011-09-26 15:44:18 -------- d-----w- c:\program files\Spyware Terminator
2011-09-26 15:03:14 -------- d-----w- c:\program files\Webroot
2011-09-26 14:51:50 -------- d-----w- c:\users\gagaga\appdata\roaming\AVG
2011-09-26 14:26:38 -------- d-----w- c:\users\gagaga\appdata\roaming\Smadav
2011-09-26 10:58:49 27248 ----a-w- c:\windows\system32\drivers\cnnctfy2.sys
2011-09-21 15:03:29 -------- d-----w- c:\users\gagaga\appdata\roaming\Research In Motion
2011-09-21 15:02:38 -------- d-----w- c:\program files\common files\Research In Motion
2011-09-21 12:09:02 -------- d-----w- c:\users\gagaga\appdata\local\Connectify
2011-09-21 12:08:04 -------- d-----w- c:\program files\Connectify
2011-09-18 10:11:31 -------- d-----w- c:\users\gagaga\appdata\local\PackageAware
2011-09-17 08:01:46 -------- d-----w- c:\users\gagaga\appdata\roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
2011-09-17 05:19:18 -------- d-----w- c:\users\gagaga\appdata\local\Microsoft Help
2011-09-12 11:12:56 -------- d-----w- c:\users\gagaga\appdata\roaming\Password Solutions
2011-09-10 17:57:53 -------- d-----w- c:\users\gagaga\appdata\roaming\Malwarebytes
2011-09-09 15:47:45 -------- d-----w- c:\users\gagaga\appdata\roaming\IDM
2011-09-09 15:47:44 -------- d-----w- c:\users\gagaga\appdata\roaming\DMCache
2011-09-09 14:06:53 -------- d-----w- c:\programdata\ALM
2011-09-09 14:01:41 -------- d-----w- c:\users\gagaga\appdata\local\Adobe
2011-09-09 09:23:52 -------- d-----w- c:\users\gagaga\appdata\local\Apple Computer
2011-09-09 09:12:56 -------- d-----w- c:\users\gagaga\appdata\local\Mozilla
2011-09-09 09:02:00 -------- d-----w- c:\users\gagaga\appdata\local\Microsoft Games
2011-09-09 09:01:49 -------- d-----w- c:\users\gagaga\appdata\local\Winamp Toolbar
2011-09-09 08:57:37 -------- d-----w- c:\users\gagaga\appdata\roaming\DAEMON Tools Pro
2011-09-09 08:57:17 -------- d-----w- c:\users\gagaga\appdata\roaming\Rainmeter
2011-09-09 08:56:58 -------- d-----w- c:\users\gagaga\appdata\roaming\Intel Corporation
2011-09-08 05:21:13 10752 ----a-w- c:\windows\system32\zfeuipcpbleyrbr.exe
2011-09-03 09:42:42 -------- d-----w- c:\program files\YouTube Downloader Toolbar
2011-09-03 09:42:42 -------- d-----w- c:\program files\common files\Spigot
2011-09-03 09:42:42 -------- d-----w- c:\program files\Application Updater
.
==================== Find3M ====================
.
2011-10-02 14:34:20 36352 ----a-w- c:\windows\system32\drivers\netbios.sys
2011-10-02 14:22:33 594600 ----a-w- c:\windows\system32\lxdpcoms.exe
2011-10-02 14:14:34 36352 ----a-w- c:\windows\system32\drivers\netbios.sys_CLN
2011-10-02 02:17:27 187904 ----a-w- c:\windows\system32\drivers\netbt.sys
2011-09-29 16:31:02 78336 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-09-29 13:43:58 74240 ----a-w- c:\windows\system32\drivers\tdx.sys
2011-09-27 23:47:40 35328 ----a-w- c:\windows\system32\drivers\blbdrive.sys
2011-09-27 17:13:51 108544 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-09-27 17:07:56 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-09-27 14:30:12 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-21 17:06:43 256 ----a-w- c:\windows\system32\pool.bin
2011-09-19 15:28:43 3766 --sha-w- c:\programdata\KGyGaAvL.sys
2011-09-19 15:28:43 168 --sh--r- c:\programdata\CD1FD9D0D0.sys
2011-09-09 08:41:19 8107 ----a-w- c:\windows\w7dsd.reg
2011-09-09 08:41:19 8089 ----a-w- c:\windows\w7dse.reg
2011-08-31 10:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-24 11:59:12 233888 ----a-w- c:\windows\system32\DreamScene.dll
2011-07-28 03:52:06 443448 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-03-13 12:22:34 15296 ----a-w- c:\program files\virtual88.ini
.
============= FINISH: 22:13:27.79 ===============
please help me ..
my laptop is being infected since 4 days ago .. when I try to search on Google, it will redirect to another sites ..
and when I tried to scan it with antivirus, it seems to be closed early without any notice ..
here's the DDS log ..
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_27
Run by gagaga at 22:12:25 on 2011-10-02
Microsoft Windows 8 Ultimate 6.1.7600.0.1252.1.1033.18.1909.1047 [GMT 7:00]
.
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\System32\spoolsv.exe
C:\windows\1798245580:871616660.exe
C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
H:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
C:\Program Files\ChiconyCam\CECPLFKT.exe
C:\Program Files\Connectify\Connectifyd.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\windows\system32\lxdpcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\ControlCenter\controlcenter.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Lexmark Z2300 Series\lxdpmon.exe
H:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files\Lexmark Z2300 Series\lxdpMsdMon.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\windows\system32\conhost.exe
C:\Program Files\SpyNoMore\SNM.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
H:\Program Files\PC Tools Security\BDT\FGuard.exe
E:\Internet Download Manager\IDMan.exe
C:\Program Files\Connectify\Connectify.exe
H:\eBoostr\eBoostrCP.exe
E:\Rainmeter\Rainmeter.exe
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\windows\system32\svchost.exe -k imgsvc
H:\Program Files\Modem AC2726i UI\bin\MonServiceUDisk.exe
C:\Program Files\Motorola\Bluetooth\obexsrv.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
E:\Internet Download Manager\IEMonitor.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\windows\system32\wbem\unsecapp.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files\Motorola\Bluetooth\audiosrv.exe
C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
C:\Program Files\Connectify\ConnectifyNetServices.exe
C:\windows\system32\conhost.exe
C:\windows\system32\sppsvc.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\windows\System32\svchost.exe -k secsvcs
C:\windows\system32\AUDIODG.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
mStart Page = about:blank
uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - h:\program files\pc tools security\bdt\PCTBrowserDefender.dll
mURLSearchHooks: Winamp Toolbar Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: Hot MP3 Toolbar: {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - c:\program files\hot_mp3\tbHot_.dll
BHO: AutorunsDisabled - No File
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - e:\internet download manager\IDMIECC.dll
BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - h:\program files\pc tools security\bdt\PCTBrowserDefender.dll
BHO: SBCONVERT Class: {3017fb3e-9a77-4396-88c5-0ec9548fb42f} - c:\program files\speedbit video downloader\tbu80\tbcore3.dll
BHO: SearchPredictObj Class: {389943b0-c3a2-4e69-82cb-8596a84cb3dc} - c:\progra~1\search~1\SEARCH~1.DLL
BHO: Shop to Win 11: {67d688ec-87da-4a28-bfa5-c4db8be5c9ea} - c:\program files\shop to win 11\Shop to Win 11.dll
BHO: Hot MP3 Toolbar: {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - c:\program files\hot_mp3\tbHot_.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: DAPIELoader Class: {ff6c3cf0-4b15-11d1-abed-709549c10000} - e:\dap\DAPIEL~1.DLL
BHO: GrabberObj Class: {ff7c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\speedb~1\tbu80\grabber.dll
TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: SpeedBit Video Downloader: {0329e7d6-6f54-462d-93f6-f5c3118badf2} - c:\program files\speedbit video downloader\tbu80\tbcore3.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} -
TB: SpeedBit: {ebfcd017-bcad-42c3-9ed5-89dbdfc59171} - c:\program files\speedbit toolbar\toolbar\tbcore3.dll
TB: Hot MP3 Toolbar: {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - c:\program files\hot_mp3\tbHot_.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - h:\program files\pc tools security\bdt\PCTBrowserDefender.dll
uRun: [IDMan] e:\internet download manager\IDMan.exe /onboot
uRun: [SM?RT-Protection] c:\program files\smadav\SM?RTP.exe rtp
uRun: [Connectify] c:\program files\connectify\Connectify.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [ControlCenter] c:\program files\controlcenter\ControlCenter.exe
mRun: [IAStorIcon] c:\program files\intel\intel(r) rapid storage technology\IAStorIcon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [BTMTrayAgent] rundll32.exe "c:\program files\motorola\bluetooth\btmshell.dll",TrayApp
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [lxdpmon.exe] "c:\program files\lexmark z2300 series\lxdpmon.exe"
mRun: [lxdpamon] "c:\program files\lexmark z2300 series\lxdpamon.exe"
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [<NO NAME>]
mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SpywareTerminatorShield] c:\program files\spyware terminator\SpywareTerminatorShield.exe
mRun: [SpywareTerminatorUpdater] c:\program files\spyware terminator\SpywareTerminatorUpdate.exe
mRun: [SNM] c:\program files\spynomore\SNM.exe /startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [PCTools FGuard] h:\program files\pc tools security\bdt\FGuard.exe
mRun: [Malwarebytes' Anti-Malware] "h:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\eboost~1.lnk - h:\eboostr\eBoostrCP.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hotkey.lnk - c:\program files\hotkey\Hotkey.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\rainme~1.lnk - e:\rainmeter\Rainmeter.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Download all links with IDM - e:\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - e:\internet download manager\IEGetVL.htm
IE: Download with IDM - e:\internet download manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\motorola\bluetooth\btmiesend.htm
IE: {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "c:\program files\fiddler2\Fiddler.exe"
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab
TCP: DhcpNameServer = 202.162.209.26 8.8.8.8
TCP: Interfaces\{10A33F2F-37CE-42B1-B6E8-D52AE9B6547F} : NameServer = 192.168.2.1
TCP: Interfaces\{2B04DE6A-5FCE-4181-8E1B-3C684EF814EB} : NameServer = 10.8.15.15 10.8.17.4
TCP: Interfaces\{E27EC556-CE80-4AB8-9A8A-DD3CDB802EDB} : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{E27EC556-CE80-4AB8-9A8A-DD3CDB802EDB} : DhcpNameServer = 202.162.209.26 8.8.8.8
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - e:\dap\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - e:\dap\dapie.dll
Notify: igfxcui - igfxdev.dll
STS: AveVistaBackgroundFolder Class: {73526e5a-fd53-4be7-b5e2-d3c89d7413dc} - c:\windows\w7fbc\dll.dll
STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll
mASetup: {8BE421A2-13EA-4507-BB04-22A818F9FF74} - c:\program files\win32\windl.exe s
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\gagaga\appdata\roaming\mozilla\firefox\profiles\m9wbz0wb.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: h:\itunes\mozilla plugins\npitunes.dll
.
============= SERVICES / DRIVERS ===============
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-9-26 263888]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-9-26 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2011-9-26 656320]
R1 cdrblock;cdrblock;c:\windows\system32\drivers\cdrblock.sys [2008-5-30 27704]
R1 cnnctfy2;Connectify LightWeight Filter;c:\windows\system32\drivers\cnnctfy2.sys [2011-9-26 27248]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2011-9-26 251560]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2011-9-26 32768]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files\motorola\bluetooth\obexsrv.exe [2011-1-18 508680]
R2 Browser Defender Update Service;Browser Defender Update Service;h:\program files\pc tools security\bdt\BDTUpdateService.exe [2011-9-27 337872]
R2 CECFLPKT;CECFLPKT;c:\program files\chiconycam\CECPLFKT.exe [2011-1-18 84592]
R2 Connectify;Connectify;c:\program files\connectify\Connectifyd.exe [2011-3-10 892992]
R2 HWEasyDevice;HWEasyDevice;c:\program files\controlcenter\HWEasy.sys [2010-10-25 16640]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\intel\intel(r) rapid storage technology\IAStorDataMgrSvc.exe [2010-10-25 13336]
R2 IDMWFP;IDMWFP;c:\windows\system32\drivers\idmwfp.sys [2011-2-12 85768]
R2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe -service --> c:\windows\system32\lxdpcoms.exe -service [?]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2011-9-26 160576]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\spyware terminator\st_rsser.exe [2011-9-26 482992]
R2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\drivers\TurboB.sys [2009-9-29 13752]
R2 UDisk Monitor;UDisk Monitor;h:\program files\modem ac2726i ui\bin\MonServiceUDisk.exe [2011-9-2 266240]
R2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\intel\intel(r) management engine components\uns\UNS.exe [2010-10-25 2320920]
R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [2011-5-10 17984]
R3 Bluetooth Device Manager;Bluetooth Device Manager;c:\program files\motorola\bluetooth\devmgrsrv.exe [2011-1-18 3512072]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files\motorola\bluetooth\audiosrv.exe [2011-1-18 901384]
R3 connctfyMP;connctfyMP;c:\windows\system32\drivers\connctfy.sys [2011-3-8 29248]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2002-1-1 132480]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\drivers\IntcDAud.sys [2002-1-1 232960]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2011-1-18 140376]
R3 JME;JMicron Ethernet Adapter NDIS6.20 Driver;c:\windows\system32\drivers\JME.sys [2011-1-18 110064]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-8-21 22216]
R3 pctNdisMP;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [2011-9-27 56536]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\drivers\rtl8192ce.sys [2011-1-18 984168]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
S2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2011-8-17 402328]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 EBOOSTRSVC;eBoostr Service;h:\eboostr\EBstrSvc.exe [2010-4-15 647296]
S2 lxdpCATSCustConnectService;lxdpCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdpserv.exe [2007-12-1 98984]
S2 MBAMService;MBAMService;h:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-8-21 366152]
S2 PowerBiosServer;PowerBiosServer;c:\program files\hotkey\PowerBiosServer.exe [2010-3-3 33792]
S2 StarWindServiceAE;StarWind AE Service;e:\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2009-12-24 372736]
S2 tuEaglesService;tuEagles Service; [x]
S2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;"c:\program files\webroot\webrootsecurity\spysweeper.exe" --> c:\program files\webroot\webrootsecurity\SpySweeper.exe [?]
S2 WRConsumerService;Webroot Client Service;"c:\program files\webroot\webrootsecurity\wrconsumerservice.exe" --> c:\program files\webroot\webrootsecurity\WRConsumerService.exe [?]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 btmaudio;Motorola Bluetooth Audio Service;c:\windows\system32\drivers\btmaud.sys [2011-1-18 33280]
S3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\drivers\btmcom.sys [2011-1-18 41344]
S3 BTMMODEM;Bluetooth Modem Device;c:\windows\system32\drivers\btmcom.sys [2011-1-18 41344]
S3 BTMNET;Motorola Bluetooth Network Adapter Service;c:\windows\system32\drivers\btmnet.sys [2011-1-18 21760]
S3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\drivers\btmusb.sys [2011-1-18 395776]
S3 connctfy;Connectify Service;c:\windows\system32\drivers\connctfy.sys [2011-3-8 29248]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2011-8-19 200192]
S3 HideMyIpSRV;HideMyIpSRV;e:\hide my ip\HideMyIpSrv.exe [2011-3-3 3039536]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2011-8-19 101376]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2010-10-25 67624]
S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2011-9-27 89472]
S3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\drivers\pctNdis.sys [2011-9-27 56536]
S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2011-9-27 125248]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2011-9-26 70536]
S3 S6000KNT;S6000KNT_WebCam Driver;c:\windows\system32\drivers\S6000KNT.sys [2011-1-18 3314048]
S3 sdAuxService;PC Tools Auxiliary Service;h:\program files\pc tools security\pctsAuxs.exe [2011-9-26 371472]
S3 sdCoreService;PC Tools Security Service;h:\program files\pc tools security\pctsSvc.exe [2011-9-26 1117144]
S3 ThreatFire;ThreatFire;h:\program files\pc tools security\tfengine\tfservice.exe service --> h:\program files\pc tools security\tfengine\TFService.exe service [?]
S3 TrufosAlt;TrufosAlt;c:\windows\system32\drivers\TrufosAlt.sys [2011-10-2 339600]
S3 TurboBoost;TurboBoost;c:\program files\intel\turboboost\TurboBoost.exe [2009-9-29 99768]
S3 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~3\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~3\VideoAcceleratorService.exe -start -scm [?]
S3 ztemtusbser;ZTEMT Legacy Serial Communication;c:\windows\system32\drivers\CT_ZTEMT_U_USBSER.sys [2011-9-2 104704]
.
=============== Created Last 30 ================
.
2011-10-02 14:47:24 94896 ----a-w- c:\windows\system32\drivers\81363479.sys
2011-10-02 14:42:04 -------- d-s---w- C:\ComboFix
2011-10-02 14:14:22 339600 ----a-w- c:\windows\system32\drivers\TrufosAlt.sys
2011-09-29 05:21:35 -------- d-----w- c:\users\gagaga\appdata\local\Threat Expert
2011-09-27 15:58:59 -------- d-----w- c:\users\gagaga\appdata\local\ElevatedDiagnostics
2011-09-27 15:55:11 -------- d-----w- c:\program files\PC Tools Registry Tool
2011-09-27 15:44:13 767952 ----a-w- c:\windows\BDTSupport.dll
2011-09-27 15:44:12 2074576 ----a-w- c:\windows\PCTBDCore.dll
2011-09-27 15:44:12 1533904 ----a-w- c:\windows\PCTBDRes.dll
2011-09-27 15:44:12 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-09-27 15:43:14 233976 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2011-09-27 15:43:13 69392 ----a-w- c:\windows\system32\drivers\TfSysMon.sys
2011-09-27 15:43:12 51984 ----a-w- c:\windows\system32\drivers\TfFsMon.sys
2011-09-27 15:43:12 33552 ----a-w- c:\windows\system32\drivers\TfNetMon.sys
2011-09-27 15:43:02 89472 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2011-09-27 15:43:02 31960 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2011-09-27 15:43:01 56536 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2011-09-27 15:43:01 125248 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2011-09-27 14:31:15 47616 ----a-w- C:\Win32kDiag.exe
2011-09-27 14:30:28 476904 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-09-27 14:17:13 48016 --sha-w- c:\windows\system32\c_50510.nl_
2011-09-27 08:14:58 98816 ----a-w- c:\windows\sed.exe
2011-09-27 08:14:58 518144 ----a-w- c:\windows\SWREG.exe
2011-09-27 08:14:58 256000 ----a-w- c:\windows\PEV.exe
2011-09-27 08:14:58 208896 ----a-w- c:\windows\MBR.exe
2011-09-26 16:53:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-09-26 16:43:51 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2011-09-26 16:43:51 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
2011-09-26 16:43:50 251560 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-09-26 16:43:50 105280 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2011-09-26 16:43:42 263888 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-09-26 16:43:42 160576 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-09-26 16:43:39 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-09-26 16:43:32 -------- d-----w- c:\users\gagaga\appdata\roaming\PC Tools
2011-09-26 16:43:32 -------- d-----w- c:\program files\common files\PC Tools
2011-09-26 16:29:33 -------- d-----w- c:\programdata\PC Tools
2011-09-26 16:13:40 520496 ----a-w- c:\windows\Listdlls.exe
2011-09-26 16:13:31 423288 ----a-w- c:\windows\handle.exe
2011-09-26 16:04:42 1152 ----a-w- c:\windows\system32\windrv.sys
2011-09-26 16:04:24 -------- d-----w- c:\program files\SpyNoMore
2011-09-26 15:44:19 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-09-26 15:44:19 -------- d-----w- c:\users\gagaga\appdata\roaming\Spyware Terminator
2011-09-26 15:44:19 -------- d-----w- c:\programdata\Spyware Terminator
2011-09-26 15:44:18 -------- d-----w- c:\program files\Spyware Terminator
2011-09-26 15:03:14 -------- d-----w- c:\program files\Webroot
2011-09-26 14:51:50 -------- d-----w- c:\users\gagaga\appdata\roaming\AVG
2011-09-26 14:26:38 -------- d-----w- c:\users\gagaga\appdata\roaming\Smadav
2011-09-26 10:58:49 27248 ----a-w- c:\windows\system32\drivers\cnnctfy2.sys
2011-09-21 15:03:29 -------- d-----w- c:\users\gagaga\appdata\roaming\Research In Motion
2011-09-21 15:02:38 -------- d-----w- c:\program files\common files\Research In Motion
2011-09-21 12:09:02 -------- d-----w- c:\users\gagaga\appdata\local\Connectify
2011-09-21 12:08:04 -------- d-----w- c:\program files\Connectify
2011-09-18 10:11:31 -------- d-----w- c:\users\gagaga\appdata\local\PackageAware
2011-09-17 08:01:46 -------- d-----w- c:\users\gagaga\appdata\roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
2011-09-17 05:19:18 -------- d-----w- c:\users\gagaga\appdata\local\Microsoft Help
2011-09-12 11:12:56 -------- d-----w- c:\users\gagaga\appdata\roaming\Password Solutions
2011-09-10 17:57:53 -------- d-----w- c:\users\gagaga\appdata\roaming\Malwarebytes
2011-09-09 15:47:45 -------- d-----w- c:\users\gagaga\appdata\roaming\IDM
2011-09-09 15:47:44 -------- d-----w- c:\users\gagaga\appdata\roaming\DMCache
2011-09-09 14:06:53 -------- d-----w- c:\programdata\ALM
2011-09-09 14:01:41 -------- d-----w- c:\users\gagaga\appdata\local\Adobe
2011-09-09 09:23:52 -------- d-----w- c:\users\gagaga\appdata\local\Apple Computer
2011-09-09 09:12:56 -------- d-----w- c:\users\gagaga\appdata\local\Mozilla
2011-09-09 09:02:00 -------- d-----w- c:\users\gagaga\appdata\local\Microsoft Games
2011-09-09 09:01:49 -------- d-----w- c:\users\gagaga\appdata\local\Winamp Toolbar
2011-09-09 08:57:37 -------- d-----w- c:\users\gagaga\appdata\roaming\DAEMON Tools Pro
2011-09-09 08:57:17 -------- d-----w- c:\users\gagaga\appdata\roaming\Rainmeter
2011-09-09 08:56:58 -------- d-----w- c:\users\gagaga\appdata\roaming\Intel Corporation
2011-09-08 05:21:13 10752 ----a-w- c:\windows\system32\zfeuipcpbleyrbr.exe
2011-09-03 09:42:42 -------- d-----w- c:\program files\YouTube Downloader Toolbar
2011-09-03 09:42:42 -------- d-----w- c:\program files\common files\Spigot
2011-09-03 09:42:42 -------- d-----w- c:\program files\Application Updater
.
==================== Find3M ====================
.
2011-10-02 14:34:20 36352 ----a-w- c:\windows\system32\drivers\netbios.sys
2011-10-02 14:22:33 594600 ----a-w- c:\windows\system32\lxdpcoms.exe
2011-10-02 14:14:34 36352 ----a-w- c:\windows\system32\drivers\netbios.sys_CLN
2011-10-02 02:17:27 187904 ----a-w- c:\windows\system32\drivers\netbt.sys
2011-09-29 16:31:02 78336 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-09-29 13:43:58 74240 ----a-w- c:\windows\system32\drivers\tdx.sys
2011-09-27 23:47:40 35328 ----a-w- c:\windows\system32\drivers\blbdrive.sys
2011-09-27 17:13:51 108544 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-09-27 17:07:56 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-09-27 14:30:12 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-21 17:06:43 256 ----a-w- c:\windows\system32\pool.bin
2011-09-19 15:28:43 3766 --sha-w- c:\programdata\KGyGaAvL.sys
2011-09-19 15:28:43 168 --sh--r- c:\programdata\CD1FD9D0D0.sys
2011-09-09 08:41:19 8107 ----a-w- c:\windows\w7dsd.reg
2011-09-09 08:41:19 8089 ----a-w- c:\windows\w7dse.reg
2011-08-31 10:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-24 11:59:12 233888 ----a-w- c:\windows\system32\DreamScene.dll
2011-07-28 03:52:06 443448 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-03-13 12:22:34 15296 ----a-w- c:\program files\virtual88.ini
.
============= FINISH: 22:13:27.79 ===============
please help me ..