I've been fighting a losing battle with the google redirect virus for a while now. I've tried many different software: hitman pro, norton, etc. I get redirected to 'gimmeanswers' 'get-answers-fast' and 'scour'.
I did not check everything in the malware scan because those files are a part of an anti-virus software I trust.
Also, the GMER scan did not produce a log.
Here are the logs:
===================================================================
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.12.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Alan Kong :: ALANKONG-PC [administrator]
3/12/2012 8:42:01 PM
mbam-log-2012-03-12 (20-42-01).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213749
Time elapsed: 4 minute(s), 32 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 1
C:\Program Files (x86)\360\360Safe\ipc\patchcheck.dll (Trojan.Agent) -> No action taken.
Registry Keys Detected: 2
HKCR\thunder (Trojan.Agent) -> No action taken.
HKLM\SOFTWARE\YingSoft (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 5
C:\Program Files (x86)\360\360Safe\ipc\patchcheck.dll (Trojan.Agent) -> No action taken.
C:\Windows\System32\drivers\ComputerZ.sys (Trojan.Agent) -> No action taken.
C:\Windows\System32\drivers\ComputerZ_x64.sys (Trojan.Agent) -> No action taken.
C:\Windows\SysWOW64\drivers\ComputerZ.sys (Trojan.Agent) -> No action taken.
C:\Windows\SysWOW64\drivers\ComputerZ_x64.sys (Trojan.Agent) -> No action taken.
(end)
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_23
Run by Alan Kong at 21:07:30 on 2012-03-12
Microsoft Windows 7 Home Premium 6.1.7601.1.936.86.1033.18.8140.5654 [GMT -4:00]
.
AV: 360杀毒 *Disabled/Updated* {A0FD413B-F662-C08C-7B21-F57CED225A55}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files (x86)\Stardock\MyColors\VistaSrv.exe
C:\Program Files (x86)\Stardock\MyColors\WBVista.exe
C:\Program Files (x86)\360\360Safe\deepscan\zhudongfangyu.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\AlienRespawn\sftservice.EXE
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\SecureW2\sw2_service.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\AlienRespawn\Components\Scheduler\STService.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe
C:\Program Files (x86)\SecureW2\sw2_tray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\Eap3Host.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\360\360sd\DumpUper.exe
C:\Program Files (x86)\360\360sd\360rp.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
mLocal Page =
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: ??à×?????§3?: {889d2feb-5411-4565-8998-1dd2c5261283} - C:\Alan\Software\Thunder\BHO\XunleiBHO7.1.8.2298.dll
uRun: [360sd] "C:\Program Files (x86)\360\360sd\360sd.exe" /autorun
uRun: [Trojan Killer] "C:\Program Files (x86)\GridinSoft Trojan Killer\trojankiller.exe" 0
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
mRun: [Integrated Webcam Live! Central] "C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe" /mode2
mRun: [<NO NAME>]
mRun: [SecureW2 Tray] C:\Program Files (x86)\SecureW2\sw2_tray.exe
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [360Safetray] "C:\Program Files (x86)\360\360Safe\safemon\360Tray.exe" /start
mRun: [3ddown.com_trojankiller-setup] C:\Users\Public\Gforl\Ieop.exe /3ddown.com_trojankiller-setup
mRunOnce: [Launcher] C:\Program Files (x86)\AlienRespawn\Components\Scheduler\Launcher.exe
mRunOnce: [Malwarebytes Anti-Malware] C:\Alan\Software\Trojan Killer\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\STARDO~1.LNK - C:\Program Files (x86)\Stardock\MyColors\SDDelayedLaunch.exe
mPolicies-explorer: NoInternetIcon = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all by FlashGet3 - C:\Users\Alan Kong\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: Download by FlashGet3 - C:\Users\Alan Kong\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: 使用迅雷下载 - C:\Alan\Software\Thunder\BHO\geturl.htm
IE: 使用迅雷下载全部链接 - C:\Alan\Software\Thunder\BHO\GetAllUrl.htm
IE: 导出到 Microsoft Office Excel(&X) - C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: {682C59F5-478C-4421-9070-AD170D143B77} - hxxp://www.dell.com/support/troubleshooting/Content/Ode/pcd86.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
TCP: DhcpNameServer = 141.211.144.17 141.211.125.17
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721} : DhcpNameServer = 141.211.144.17 141.211.125.17
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\14461616E6464596E616 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\14C616E6B4 : DhcpNameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\2416D626F6F6541676C656 : DhcpNameServer = 141.211.144.17 141.211.125.17 192.168.1.1
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\64D4D213331323 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\74F60224C65756 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\85948594D2A414D49454 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\D475962756C6563737D2341454E4 : DhcpNameServer = 141.212.2.81 141.212.2.69 141.213.73.83 141.211.125.15
TCP: Interfaces\{B6E3C3D8-0B89-4B11-8162-1DBECB7B467F} : DhcpNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: ??à×?????§3?: {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Alan\Software\Thunder\BHO\XunleiBHO7.1.8.2298.dll
BHO-X64: XunleiBHO - No File
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
mRun-x64: [Integrated Webcam Live! Central] "C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe" /mode2
mRun-x64: [(Default)]
mRun-x64: [SecureW2 Tray] C:\Program Files (x86)\SecureW2\sw2_tray.exe
mRun-x64: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [360Safetray] "C:\Program Files (x86)\360\360Safe\safemon\360Tray.exe" /start
mRun-x64: [3ddown.com_trojankiller-setup] C:\Users\Public\Gforl\Ieop.exe /3ddown.com_trojankiller-setup
mRunOnce-x64: [Launcher] C:\Program Files (x86)\AlienRespawn\Components\Scheduler\Launcher.exe
mRunOnce-x64: [Malwarebytes Anti-Malware] C:\Alan\Software\Trojan Killer\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Alan Kong\AppData\Roaming\Mozilla\Firefox\Profiles\m384yeqf.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B8f0a195c-711d-4f8a-bae7-72b68375630f%7D&mid=e0e2a427d1ed47d181a611827e2a541d-d0ed6da425414e7864772c92feef566adace9aad&ds=tg028&v=8.0.0.34.1&lang=en&pr=sa&d=2011-09-15%2017%3A10%3A13&sap=ku&q=
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: C:\Users\Alan Kong\AppData\Roaming\Mozilla\Firefox\Profiles\m384yeqf.default\extensions\{1B33E42F-EF14-4cd3-B6DC-174571C4349C}\components\ThunderComponent.dll
FF - component: C:\Users\Alan Kong\AppData\Roaming\Mozilla\Firefox\Profiles\m384yeqf.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashGetXPI.dll
FF - plugin: C:\Alan\Software\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: C:\Alan\Software\椋庨浄褰遍煶\Mozilla\nppl3260.dll
FF - plugin: C:\Alan\Software\椋庨浄褰遍煶\Mozilla\npqtplugin.dll
FF - plugin: C:\Alan\Software\椋庨浄褰遍煶\Mozilla\nprpjplug.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\np360MMPlugIn.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\Alan Kong\AppData\Roaming\Mozilla\Firefox\Profiles\m384yeqf.default\extensions\{4D144BC3-23FB-47de-90C5-63CCB0139CCF}\plugins\npww.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 EMSC;COMPAL Embedded System Control;C:\Windows\System32\drivers\EMSC.sys [2009-6-26 13680]
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\system32\DRIVERS\stdcfltn.sys --> C:\Windows\system32\DRIVERS\stdcfltn.sys [?]
R1 360Box64;360Box mini-filter driver;C:\Windows\system32\DRIVERS\360Box64.sys --> C:\Windows\system32\DRIVERS\360Box64.sys [?]
R1 360FsFlt;360FsFlt mini-filter driver;C:\Windows\system32\DRIVERS\360FsFlt.sys --> C:\Windows\system32\DRIVERS\360FsFlt.sys [?]
R1 360netmon;360netmon;C:\Windows\system32\DRIVERS\360netmon.sys --> C:\Windows\system32\DRIVERS\360netmon.sys [?]
R1 A2DDA;A2 Direct Disk Access Support Driver;C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [2011-10-29 23208]
R1 BAPIDRV;BAPIDRV;C:\Windows\system32\Drivers\BAPIDRV64.SYS --> C:\Windows\system32\Drivers\BAPIDRV64.SYS [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 360rp;360 杀毒实时防护服务;C:\Program Files (x86)\360\360sd\360rp.exe [2010-12-10 939352]
R2 a2AntiMalware;Emsisoft Anti-Malware 6.0 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2011-10-29 2979280]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-10-21 89600]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-1-24 13336]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\AlienRespawn\SftService.exe [2011-1-24 689472]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-3-9 378472]
R2 SW2SVC;SecureW2 Service;C:\Program Files (x86)\SecureW2\sw2_service.exe [2010-11-12 118152]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-7-13 2655768]
R2 ZhuDongFangYu;主动防御;C:\Program Files (x86)\360\360Safe\deepscan\ZhuDongFangYu.exe [2011-3-15 272728]
R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Accelern.sys --> C:\Windows\system32\DRIVERS\Accelern.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
S1 EfiMon;EfiSystemMon;C:\Windows\system32\Drivers\Efimon.sys --> C:\Windows\system32\Drivers\Efimon.sys [?]
S2 CLKMSVC10_9EC60124;CyberLink Product - 2011/01/24 09:09:40;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-9-28 254448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-9-4 219632]
S3 a2acc;a2acc;C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys [2011-10-29 63880]
S3 btwampfl;Bluetooth AMP USB Filter;C:\Windows\system32\drivers\btwampfl.sys --> C:\Windows\system32\drivers\btwampfl.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\A837.tmp --> C:\Windows\system32\A837.tmp [?]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-1-5 340240]
S3 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-1-24 2009704]
S3 RichVideo64;Cyberlink RichVideo64 Service(CRVS);C:\Program Files\Cyberlink\Shared files\RichVideo64.exe [2011-3-3 386344]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-9-4 1116656]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\system32\DRIVERS\RtsPStor.sys --> C:\Windows\system32\DRIVERS\RtsPStor.sys [?]
S3 SWDUMon;SWDUMon;C:\Windows\system32\DRIVERS\SWDUMon.sys --> C:\Windows\system32\DRIVERS\SWDUMon.sys [?]
S3 tcphoc;tcphoc;C:\Alan\Software\Thunder\XLDoctor\7.1.7.2244_3\Program\tcphoc.sys [2011-3-23 8488]
S3 TFsExDisk;TFsExDisk;\??\C:\Windows\System32\Drivers\TFsExDisk.sys --> C:\Windows\System32\Drivers\TFsExDisk.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\system32\DRIVERS\wdcsam64.sys --> C:\Windows\system32\DRIVERS\wdcsam64.sys [?]
S3 XLDoctor Service;XLDoctor Service;C:\Windows\system32\svchost -k DoctorService --> C:\Windows\system32\svchost -k DoctorService [?]
.
=============== File Associations ===============
.
VBEFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*
VBSFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2012-03-13 00:40:29 -------- d-----w- C:\Users\Alan Kong\AppData\Roaming\Malwarebytes
2012-03-13 00:40:11 -------- d-----w- C:\ProgramData\Malwarebytes
2012-03-13 00:40:10 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-03-13 00:24:37 -------- d-sh--r- C:\360SANDBOX
2012-03-13 00:01:46 18816 ------w- C:\Windows\SysWow64\SAVRKBootTasks.sys
2012-03-12 23:49:12 12872 ----a-w- C:\Windows\System32\bootdelete.exe
2012-03-12 23:42:51 -------- d-----w- C:\ProgramData\HitmanPro
2012-03-12 23:35:05 6144 ------w- C:\Windows\System32\A837.tmp
2012-03-12 23:34:37 6144 ------w- C:\Windows\System32\3A76.tmp
2012-03-12 19:34:44 -------- d-----w- C:\Windows\SysWow64\YingInstall
2012-03-11 08:34:46 413760 ----a-w- C:\Windows\System32\MPG4C32.DLL
2012-03-11 08:34:46 262416 ----a-w- C:\Windows\System32\MPG4DS32.AX
2012-03-09 12:09:38 8643640 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{00795044-9D50-492B-9427-5FD6F3BA3AB5}\mpengine.dll
2012-02-28 02:23:24 -------- d-----w- C:\Program Files\AlienAutopsy
2012-02-24 05:00:29 -------- d-----w- C:\ProgramData\Solidshield
2012-02-24 04:52:59 -------- d-----w- C:\Users\Alan Kong\AppData\Roaming\Ubisoft
2012-02-24 04:51:27 -------- d-----w- C:\ProgramData\Tages
2012-02-24 03:51:36 -------- d-----w- C:\Users\Alan Kong\AppData\Roaming\Stardock
2012-02-24 03:51:24 -------- d-----w- C:\ProgramData\Gibraltar
2012-02-24 03:51:05 -------- d-----w- C:\ProgramData\Stardock
2012-02-24 03:50:39 -------- d--h--w- C:\ProgramData\{F17D9C21-2BB9-4DE6-A952-721D90A7029A}
2012-02-15 03:22:37 3145728 ----a-w- C:\Windows\System32\win32k.sys
2012-02-15 03:20:30 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2012-02-15 03:20:30 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2012-02-15 03:18:19 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
2012-02-15 03:12:27 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2012-02-15 03:12:27 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
2012-02-15 03:12:26 515584 ----a-w- C:\Windows\System32\timedate.cpl
2012-02-15 03:12:26 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
.
==================== Find3M ====================
.
2012-03-06 07:34:29 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-23 14:18:36 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-02-21 15:45:44 354904 ----a-w- C:\Windows\System32\drivers\360fsflt.sys
2011-12-23 08:35:28 274008 ----a-w- C:\Windows\System32\drivers\360Box64.sys
2011-12-20 15:10:48 17192 ----a-w- C:\Windows\System32\nitrolocalui2.dll
2011-12-20 15:10:46 28968 ----a-w- C:\Windows\System32\nitrolocalmon2.dll
2011-12-14 07:11:03 2308096 ----a-w- C:\Windows\System32\jscript9.dll
2011-12-14 07:04:30 1390080 ----a-w- C:\Windows\System32\wininet.dll
2011-12-14 07:03:38 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
2011-12-14 06:57:28 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-12-14 03:04:54 1798656 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-12-14 02:57:18 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-12-14 02:56:58 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-12-14 02:50:04 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 21:07:42.34 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 1/28/2011 7:03:51 PM
System Uptime: 3/12/2012 8:23:43 PM (1 hours ago)
.
Motherboard: Alienware | | M17xR3
Processor: Intel(R) Core(TM) i7-2820QM CPU @ 2.30GHz | CPU1 | 2301/1333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 1383 GiB total, 995.651 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP318: 2/29/2012 2:05:32 AM - Windows Defender Checkpoint
RP319: 2/29/2012 3:00:10 AM - Windows Update
RP320: 3/6/2012 12:56:52 PM - Windows Update
RP321: 3/12/2012 4:30:29 PM - Removed Java(TM) 6 Update 23
.
==== Installed Programs ======================
.
360°2è??àê?
360安全卫士
360杀毒
360硬件大师
A Murder of Crows
AccelerometerP11
Adobe AIR
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 9.5.0
Adobe Stock Photos 1.0
Advanced Audio FX Engine
AlienRespawn
AlienRespawn - Support Software
Alienware M17x Manual
Alienware On-Screen Display
Apple Application Support
Apple Software Update
Artificial Girl 3
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
Banctec Service Agreement
Chinese Simplified Fonts Support For Adobe Reader 9
Cities XL
Collab
Comcast Desktop Software (v1.2.0.9)
Command Center
Compatibility Pack for the 2007 Office system
CyberLink PowerDirector
CyberLink PowerDVD 9.6
CyberLink WaveEditor
DAEMON Tools Lite
Dawn of Discovery
Dawn of Discovery - Gold Edition
Dawn of Discovery? Gold
Dev-C++ 5 beta 9 release (4.9.9.2)
DirectX 9 Runtime
DriverUpdate
EMSC
Emsisoft Anti-Malware
Family Tree Maker 2012
FL Studio 8
FlashGet 3.7
GoToAssist Corporate
Hotfix for Microsoft Visual C++ 2010 Express - ENU (KB2542054)
IDT Audio
IL Download Manager
Impulse?
Impulse?REMOVE
Integrated Webcam Live! Central
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Java Auto Updater
Java(TM) 6 Update 23
K-Lite Codec Pack 8.4.0 (Standard)
LIMBO
Macromedia Dreamweaver 8
Macromedia Extension Manager
Malwarebytes Anti-Malware version 1.60.1.1000
Microsoft .NET Framework 1.1
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft Application Error Reporting
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170)
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office File Validation Add-In
Microsoft Office Professional Edition 2003
Microsoft Primary Interoperability Assemblies 2005
Microsoft Silverlight
Microsoft SQL Server 2008 R2 Management Objects
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft SQL Server System CLR Types
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
Microsoft Visual C++ 2010 Express - ENU
Microsoft Visual Studio 2010 Shell (Isolated) - ENU
Mozilla Firefox 10.0.2 (x86 en-US)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NVIDIA 3D Vision Controller Driver
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
OpenAL
Pando Media Booster
PC Connectivity Solution
PCSX2 黎明破晓前
PhotoShowExpress
PoiZone
PrimoPDF -- brought to you by Nitro PDF Software
QuickTime
r.u.s.e
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek PCIE Card Reader
RealUpgrade 1.1
Renesas Electronics USB 3.0 Host Controller Driver
Rosetta Stone Version 3
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Creator Starter
Roxio Express Labeler 3
SchoolMate
SecureW2 Enterprise Client 3.5.0
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft Visual C++ 2010 Express - ENU (KB2251489)
Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002)
Sid Meier's Civilization IV: Beyond the Sword
Sins of a Solar Empire Trinity
Skype? 4.2
SmartSound Quicktracks 5
Sonic CinePlayer Decoder Pack
Sophos Anti-Rootkit 1.5.20
SotS Tutorial Videos
StarCraft II
Stardock Central
Stardock MyColors
Steam
Stronghold 2 Deluxe
Tech48
Tencent QQ
The Complete National Geographic
The Elder Scrolls V: Skyrim
Toxic Biohazard
Trojan Killer 2.1
Ubisoft Game Launcher
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Wanko to Kurasou English v1.0
Windows Media Encoder 9 Series
WinRAR archiver
World of Warcraft
神鬼寓言3
质量效应2简体中文完整增强版
迅雷7
.
==== Event Viewer Messages From Past Week ========
.
3/8/2012 2:16:21 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/8/2012 12:22:39 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/7/2012 11:15:19 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/6/2012 8:14:02 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/6/2012 3:26:07 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/6/2012 10:23:09 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/5/2012 2:40:10 AM, Error: ACPI [13] - : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.
3/12/2012 8:43:51 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/12/2012 8:31:22 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/12/2012 8:28:00 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/12/2012 8:25:15 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: EfiMon SAVRKBootTasks
3/12/2012 8:25:04 PM, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
3/12/2012 8:24:17 PM, Error: Application Popup [1060] - \SystemRoot\System32\Drivers\Efimon.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
3/12/2012 7:35:05 PM, Error: Service Control Manager [7000] - The MEMSWEEP2 service failed to start due to the following error: This driver has been blocked from loading
3/12/2012 7:35:05 PM, Error: Application Popup [1060] - \??\C:\Windows\system32\A837.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
3/12/2012 7:34:37 PM, Error: Application Popup [1060] - \??\C:\Windows\system32\3A76.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
3/12/2012 6:26:00 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/12/2012 2:57:27 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/12/2012 2:08:27 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: EfiMon
3/12/2012 12:00:11 AM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/11/2012 8:19:41 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR7.
3/11/2012 8:13:59 PM, Error: Disk [11] - The driver detected a controller error on \...\DR1.
3/11/2012 12:08:04 AM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
3/10/2012 6:04:29 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/10/2012 2:10:41 AM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/10/2012 12:20:11 AM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/10/2012 11:11:19 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
.
==== End Of File ===========================
I did not check everything in the malware scan because those files are a part of an anti-virus software I trust.
Also, the GMER scan did not produce a log.
Here are the logs:
===================================================================
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.12.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Alan Kong :: ALANKONG-PC [administrator]
3/12/2012 8:42:01 PM
mbam-log-2012-03-12 (20-42-01).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213749
Time elapsed: 4 minute(s), 32 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 1
C:\Program Files (x86)\360\360Safe\ipc\patchcheck.dll (Trojan.Agent) -> No action taken.
Registry Keys Detected: 2
HKCR\thunder (Trojan.Agent) -> No action taken.
HKLM\SOFTWARE\YingSoft (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 5
C:\Program Files (x86)\360\360Safe\ipc\patchcheck.dll (Trojan.Agent) -> No action taken.
C:\Windows\System32\drivers\ComputerZ.sys (Trojan.Agent) -> No action taken.
C:\Windows\System32\drivers\ComputerZ_x64.sys (Trojan.Agent) -> No action taken.
C:\Windows\SysWOW64\drivers\ComputerZ.sys (Trojan.Agent) -> No action taken.
C:\Windows\SysWOW64\drivers\ComputerZ_x64.sys (Trojan.Agent) -> No action taken.
(end)
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_23
Run by Alan Kong at 21:07:30 on 2012-03-12
Microsoft Windows 7 Home Premium 6.1.7601.1.936.86.1033.18.8140.5654 [GMT -4:00]
.
AV: 360杀毒 *Disabled/Updated* {A0FD413B-F662-C08C-7B21-F57CED225A55}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files (x86)\Stardock\MyColors\VistaSrv.exe
C:\Program Files (x86)\Stardock\MyColors\WBVista.exe
C:\Program Files (x86)\360\360Safe\deepscan\zhudongfangyu.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\IDT\WDM\AESTSr64.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\AlienRespawn\sftservice.EXE
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\SecureW2\sw2_service.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\AlienRespawn\Components\Scheduler\STService.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe
C:\Program Files (x86)\SecureW2\sw2_tray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\Eap3Host.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\360\360sd\DumpUper.exe
C:\Program Files (x86)\360\360sd\360rp.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
mLocal Page =
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: ??à×?????§3?: {889d2feb-5411-4565-8998-1dd2c5261283} - C:\Alan\Software\Thunder\BHO\XunleiBHO7.1.8.2298.dll
uRun: [360sd] "C:\Program Files (x86)\360\360sd\360sd.exe" /autorun
uRun: [Trojan Killer] "C:\Program Files (x86)\GridinSoft Trojan Killer\trojankiller.exe" 0
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
mRun: [Integrated Webcam Live! Central] "C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe" /mode2
mRun: [<NO NAME>]
mRun: [SecureW2 Tray] C:\Program Files (x86)\SecureW2\sw2_tray.exe
mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [360Safetray] "C:\Program Files (x86)\360\360Safe\safemon\360Tray.exe" /start
mRun: [3ddown.com_trojankiller-setup] C:\Users\Public\Gforl\Ieop.exe /3ddown.com_trojankiller-setup
mRunOnce: [Launcher] C:\Program Files (x86)\AlienRespawn\Components\Scheduler\Launcher.exe
mRunOnce: [Malwarebytes Anti-Malware] C:\Alan\Software\Trojan Killer\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\STARDO~1.LNK - C:\Program Files (x86)\Stardock\MyColors\SDDelayedLaunch.exe
mPolicies-explorer: NoInternetIcon = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all by FlashGet3 - C:\Users\Alan Kong\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: Download by FlashGet3 - C:\Users\Alan Kong\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: 使用迅雷下载 - C:\Alan\Software\Thunder\BHO\geturl.htm
IE: 使用迅雷下载全部链接 - C:\Alan\Software\Thunder\BHO\GetAllUrl.htm
IE: 导出到 Microsoft Office Excel(&X) - C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: {682C59F5-478C-4421-9070-AD170D143B77} - hxxp://www.dell.com/support/troubleshooting/Content/Ode/pcd86.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
TCP: DhcpNameServer = 141.211.144.17 141.211.125.17
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721} : DhcpNameServer = 141.211.144.17 141.211.125.17
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\14461616E6464596E616 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\14C616E6B4 : DhcpNameServer = 75.75.76.76 75.75.75.75
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\2416D626F6F6541676C656 : DhcpNameServer = 141.211.144.17 141.211.125.17 192.168.1.1
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\64D4D213331323 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\74F60224C65756 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\85948594D2A414D49454 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{6AD5FA49-BE34-4CD7-91E7-6664C2608721}\D475962756C6563737D2341454E4 : DhcpNameServer = 141.212.2.81 141.212.2.69 141.213.73.83 141.211.125.15
TCP: Interfaces\{B6E3C3D8-0B89-4B11-8162-1DBECB7B467F} : DhcpNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: ??à×?????§3?: {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Alan\Software\Thunder\BHO\XunleiBHO7.1.8.2298.dll
BHO-X64: XunleiBHO - No File
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [AlienwareOn-ScreenDisplay] C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
mRun-x64: [Integrated Webcam Live! Central] "C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe" /mode2
mRun-x64: [(Default)]
mRun-x64: [SecureW2 Tray] C:\Program Files (x86)\SecureW2\sw2_tray.exe
mRun-x64: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [360Safetray] "C:\Program Files (x86)\360\360Safe\safemon\360Tray.exe" /start
mRun-x64: [3ddown.com_trojankiller-setup] C:\Users\Public\Gforl\Ieop.exe /3ddown.com_trojankiller-setup
mRunOnce-x64: [Launcher] C:\Program Files (x86)\AlienRespawn\Components\Scheduler\Launcher.exe
mRunOnce-x64: [Malwarebytes Anti-Malware] C:\Alan\Software\Trojan Killer\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Alan Kong\AppData\Roaming\Mozilla\Firefox\Profiles\m384yeqf.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B8f0a195c-711d-4f8a-bae7-72b68375630f%7D&mid=e0e2a427d1ed47d181a611827e2a541d-d0ed6da425414e7864772c92feef566adace9aad&ds=tg028&v=8.0.0.34.1&lang=en&pr=sa&d=2011-09-15%2017%3A10%3A13&sap=ku&q=
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: C:\Users\Alan Kong\AppData\Roaming\Mozilla\Firefox\Profiles\m384yeqf.default\extensions\{1B33E42F-EF14-4cd3-B6DC-174571C4349C}\components\ThunderComponent.dll
FF - component: C:\Users\Alan Kong\AppData\Roaming\Mozilla\Firefox\Profiles\m384yeqf.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashGetXPI.dll
FF - plugin: C:\Alan\Software\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: C:\Alan\Software\椋庨浄褰遍煶\Mozilla\nppl3260.dll
FF - plugin: C:\Alan\Software\椋庨浄褰遍煶\Mozilla\npqtplugin.dll
FF - plugin: C:\Alan\Software\椋庨浄褰遍煶\Mozilla\nprpjplug.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\np360MMPlugIn.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\Alan Kong\AppData\Roaming\Mozilla\Firefox\Profiles\m384yeqf.default\extensions\{4D144BC3-23FB-47de-90C5-63CCB0139CCF}\plugins\npww.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 EMSC;COMPAL Embedded System Control;C:\Windows\System32\drivers\EMSC.sys [2009-6-26 13680]
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\system32\DRIVERS\stdcfltn.sys --> C:\Windows\system32\DRIVERS\stdcfltn.sys [?]
R1 360Box64;360Box mini-filter driver;C:\Windows\system32\DRIVERS\360Box64.sys --> C:\Windows\system32\DRIVERS\360Box64.sys [?]
R1 360FsFlt;360FsFlt mini-filter driver;C:\Windows\system32\DRIVERS\360FsFlt.sys --> C:\Windows\system32\DRIVERS\360FsFlt.sys [?]
R1 360netmon;360netmon;C:\Windows\system32\DRIVERS\360netmon.sys --> C:\Windows\system32\DRIVERS\360netmon.sys [?]
R1 A2DDA;A2 Direct Disk Access Support Driver;C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [2011-10-29 23208]
R1 BAPIDRV;BAPIDRV;C:\Windows\system32\Drivers\BAPIDRV64.SYS --> C:\Windows\system32\Drivers\BAPIDRV64.SYS [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 360rp;360 杀毒实时防护服务;C:\Program Files (x86)\360\360sd\360rp.exe [2010-12-10 939352]
R2 a2AntiMalware;Emsisoft Anti-Malware 6.0 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2011-10-29 2979280]
R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-10-21 89600]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-1-24 13336]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\AlienRespawn\SftService.exe [2011-1-24 689472]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-3-9 378472]
R2 SW2SVC;SecureW2 Service;C:\Program Files (x86)\SecureW2\sw2_service.exe [2010-11-12 118152]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-7-13 2655768]
R2 ZhuDongFangYu;主动防御;C:\Program Files (x86)\360\360Safe\deepscan\ZhuDongFangYu.exe [2011-3-15 272728]
R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Accelern.sys --> C:\Windows\system32\DRIVERS\Accelern.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
S1 EfiMon;EfiSystemMon;C:\Windows\system32\Drivers\Efimon.sys --> C:\Windows\system32\Drivers\Efimon.sys [?]
S2 CLKMSVC10_9EC60124;CyberLink Product - 2011/01/24 09:09:40;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-9-28 254448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-9-4 219632]
S3 a2acc;a2acc;C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys [2011-10-29 63880]
S3 btwampfl;Bluetooth AMP USB Filter;C:\Windows\system32\drivers\btwampfl.sys --> C:\Windows\system32\drivers\btwampfl.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\A837.tmp --> C:\Windows\system32\A837.tmp [?]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-1-5 340240]
S3 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-1-24 2009704]
S3 RichVideo64;Cyberlink RichVideo64 Service(CRVS);C:\Program Files\Cyberlink\Shared files\RichVideo64.exe [2011-3-3 386344]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-9-4 1116656]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\system32\DRIVERS\RtsPStor.sys --> C:\Windows\system32\DRIVERS\RtsPStor.sys [?]
S3 SWDUMon;SWDUMon;C:\Windows\system32\DRIVERS\SWDUMon.sys --> C:\Windows\system32\DRIVERS\SWDUMon.sys [?]
S3 tcphoc;tcphoc;C:\Alan\Software\Thunder\XLDoctor\7.1.7.2244_3\Program\tcphoc.sys [2011-3-23 8488]
S3 TFsExDisk;TFsExDisk;\??\C:\Windows\System32\Drivers\TFsExDisk.sys --> C:\Windows\System32\Drivers\TFsExDisk.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\system32\DRIVERS\wdcsam64.sys --> C:\Windows\system32\DRIVERS\wdcsam64.sys [?]
S3 XLDoctor Service;XLDoctor Service;C:\Windows\system32\svchost -k DoctorService --> C:\Windows\system32\svchost -k DoctorService [?]
.
=============== File Associations ===============
.
VBEFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*
VBSFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2012-03-13 00:40:29 -------- d-----w- C:\Users\Alan Kong\AppData\Roaming\Malwarebytes
2012-03-13 00:40:11 -------- d-----w- C:\ProgramData\Malwarebytes
2012-03-13 00:40:10 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-03-13 00:24:37 -------- d-sh--r- C:\360SANDBOX
2012-03-13 00:01:46 18816 ------w- C:\Windows\SysWow64\SAVRKBootTasks.sys
2012-03-12 23:49:12 12872 ----a-w- C:\Windows\System32\bootdelete.exe
2012-03-12 23:42:51 -------- d-----w- C:\ProgramData\HitmanPro
2012-03-12 23:35:05 6144 ------w- C:\Windows\System32\A837.tmp
2012-03-12 23:34:37 6144 ------w- C:\Windows\System32\3A76.tmp
2012-03-12 19:34:44 -------- d-----w- C:\Windows\SysWow64\YingInstall
2012-03-11 08:34:46 413760 ----a-w- C:\Windows\System32\MPG4C32.DLL
2012-03-11 08:34:46 262416 ----a-w- C:\Windows\System32\MPG4DS32.AX
2012-03-09 12:09:38 8643640 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{00795044-9D50-492B-9427-5FD6F3BA3AB5}\mpengine.dll
2012-02-28 02:23:24 -------- d-----w- C:\Program Files\AlienAutopsy
2012-02-24 05:00:29 -------- d-----w- C:\ProgramData\Solidshield
2012-02-24 04:52:59 -------- d-----w- C:\Users\Alan Kong\AppData\Roaming\Ubisoft
2012-02-24 04:51:27 -------- d-----w- C:\ProgramData\Tages
2012-02-24 03:51:36 -------- d-----w- C:\Users\Alan Kong\AppData\Roaming\Stardock
2012-02-24 03:51:24 -------- d-----w- C:\ProgramData\Gibraltar
2012-02-24 03:51:05 -------- d-----w- C:\ProgramData\Stardock
2012-02-24 03:50:39 -------- d--h--w- C:\ProgramData\{F17D9C21-2BB9-4DE6-A952-721D90A7029A}
2012-02-15 03:22:37 3145728 ----a-w- C:\Windows\System32\win32k.sys
2012-02-15 03:20:30 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2012-02-15 03:20:30 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2012-02-15 03:18:19 498688 ----a-w- C:\Windows\System32\drivers\afd.sys
2012-02-15 03:12:27 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2012-02-15 03:12:27 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
2012-02-15 03:12:26 515584 ----a-w- C:\Windows\System32\timedate.cpl
2012-02-15 03:12:26 478720 ----a-w- C:\Windows\SysWow64\timedate.cpl
.
==================== Find3M ====================
.
2012-03-06 07:34:29 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-23 14:18:36 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-02-21 15:45:44 354904 ----a-w- C:\Windows\System32\drivers\360fsflt.sys
2011-12-23 08:35:28 274008 ----a-w- C:\Windows\System32\drivers\360Box64.sys
2011-12-20 15:10:48 17192 ----a-w- C:\Windows\System32\nitrolocalui2.dll
2011-12-20 15:10:46 28968 ----a-w- C:\Windows\System32\nitrolocalmon2.dll
2011-12-14 07:11:03 2308096 ----a-w- C:\Windows\System32\jscript9.dll
2011-12-14 07:04:30 1390080 ----a-w- C:\Windows\System32\wininet.dll
2011-12-14 07:03:38 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
2011-12-14 06:57:28 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-12-14 03:04:54 1798656 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-12-14 02:57:18 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-12-14 02:56:58 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-12-14 02:50:04 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 21:07:42.34 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 1/28/2011 7:03:51 PM
System Uptime: 3/12/2012 8:23:43 PM (1 hours ago)
.
Motherboard: Alienware | | M17xR3
Processor: Intel(R) Core(TM) i7-2820QM CPU @ 2.30GHz | CPU1 | 2301/1333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 1383 GiB total, 995.651 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP318: 2/29/2012 2:05:32 AM - Windows Defender Checkpoint
RP319: 2/29/2012 3:00:10 AM - Windows Update
RP320: 3/6/2012 12:56:52 PM - Windows Update
RP321: 3/12/2012 4:30:29 PM - Removed Java(TM) 6 Update 23
.
==== Installed Programs ======================
.
360°2è??àê?
360安全卫士
360杀毒
360硬件大师
A Murder of Crows
AccelerometerP11
Adobe AIR
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 9.5.0
Adobe Stock Photos 1.0
Advanced Audio FX Engine
AlienRespawn
AlienRespawn - Support Software
Alienware M17x Manual
Alienware On-Screen Display
Apple Application Support
Apple Software Update
Artificial Girl 3
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
Banctec Service Agreement
Chinese Simplified Fonts Support For Adobe Reader 9
Cities XL
Collab
Comcast Desktop Software (v1.2.0.9)
Command Center
Compatibility Pack for the 2007 Office system
CyberLink PowerDirector
CyberLink PowerDVD 9.6
CyberLink WaveEditor
DAEMON Tools Lite
Dawn of Discovery
Dawn of Discovery - Gold Edition
Dawn of Discovery? Gold
Dev-C++ 5 beta 9 release (4.9.9.2)
DirectX 9 Runtime
DriverUpdate
EMSC
Emsisoft Anti-Malware
Family Tree Maker 2012
FL Studio 8
FlashGet 3.7
GoToAssist Corporate
Hotfix for Microsoft Visual C++ 2010 Express - ENU (KB2542054)
IDT Audio
IL Download Manager
Impulse?
Impulse?REMOVE
Integrated Webcam Live! Central
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Java Auto Updater
Java(TM) 6 Update 23
K-Lite Codec Pack 8.4.0 (Standard)
LIMBO
Macromedia Dreamweaver 8
Macromedia Extension Manager
Malwarebytes Anti-Malware version 1.60.1.1000
Microsoft .NET Framework 1.1
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft Application Error Reporting
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170)
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office File Validation Add-In
Microsoft Office Professional Edition 2003
Microsoft Primary Interoperability Assemblies 2005
Microsoft Silverlight
Microsoft SQL Server 2008 R2 Management Objects
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft SQL Server System CLR Types
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
Microsoft Visual C++ 2010 Express - ENU
Microsoft Visual Studio 2010 Shell (Isolated) - ENU
Mozilla Firefox 10.0.2 (x86 en-US)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NVIDIA 3D Vision Controller Driver
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
OpenAL
Pando Media Booster
PC Connectivity Solution
PCSX2 黎明破晓前
PhotoShowExpress
PoiZone
PrimoPDF -- brought to you by Nitro PDF Software
QuickTime
r.u.s.e
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek PCIE Card Reader
RealUpgrade 1.1
Renesas Electronics USB 3.0 Host Controller Driver
Rosetta Stone Version 3
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Creator Starter
Roxio Express Labeler 3
SchoolMate
SecureW2 Enterprise Client 3.5.0
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft Visual C++ 2010 Express - ENU (KB2251489)
Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002)
Sid Meier's Civilization IV: Beyond the Sword
Sins of a Solar Empire Trinity
Skype? 4.2
SmartSound Quicktracks 5
Sonic CinePlayer Decoder Pack
Sophos Anti-Rootkit 1.5.20
SotS Tutorial Videos
StarCraft II
Stardock Central
Stardock MyColors
Steam
Stronghold 2 Deluxe
Tech48
Tencent QQ
The Complete National Geographic
The Elder Scrolls V: Skyrim
Toxic Biohazard
Trojan Killer 2.1
Ubisoft Game Launcher
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Wanko to Kurasou English v1.0
Windows Media Encoder 9 Series
WinRAR archiver
World of Warcraft
神鬼寓言3
质量效应2简体中文完整增强版
迅雷7
.
==== Event Viewer Messages From Past Week ========
.
3/8/2012 2:16:21 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/8/2012 12:22:39 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/7/2012 11:15:19 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/6/2012 8:14:02 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/6/2012 3:26:07 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/6/2012 10:23:09 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/5/2012 2:40:10 AM, Error: ACPI [13] - : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.
3/12/2012 8:43:51 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 3 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/12/2012 8:31:22 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/12/2012 8:28:00 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/12/2012 8:25:15 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: EfiMon SAVRKBootTasks
3/12/2012 8:25:04 PM, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
3/12/2012 8:24:17 PM, Error: Application Popup [1060] - \SystemRoot\System32\Drivers\Efimon.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
3/12/2012 7:35:05 PM, Error: Service Control Manager [7000] - The MEMSWEEP2 service failed to start due to the following error: This driver has been blocked from loading
3/12/2012 7:35:05 PM, Error: Application Popup [1060] - \??\C:\Windows\system32\A837.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
3/12/2012 7:34:37 PM, Error: Application Popup [1060] - \??\C:\Windows\system32\3A76.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
3/12/2012 6:26:00 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/12/2012 2:57:27 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/12/2012 2:08:27 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: EfiMon
3/12/2012 12:00:11 AM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/11/2012 8:19:41 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR7.
3/11/2012 8:13:59 PM, Error: Disk [11] - The driver detected a controller error on \...\DR1.
3/11/2012 12:08:04 AM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
3/10/2012 6:04:29 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/10/2012 2:10:41 AM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/10/2012 12:20:11 AM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/10/2012 11:11:19 PM, Error: Service Control Manager [7031] - The 360 杀毒实时防护服务 service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
.
==== End Of File ===========================