urm, I might have forgotten some of the steps i taken since it's quite long since then
I'll repeat my problem, my IE8 and FF autoloads a chinese web site on browser startup,even though homepage is set to google, pressing the homepage button still takes me to google though, and it only affects browser startup, starting a new tab wont have the same problem, links are on the first post
I've tried full scan with updated eset smart security, scanned with updated ad aware, resetted IE settings, cleared temp files, tried removing weird files from startup, deleted suspicious files while manually checking my HDD, tried using System repair engineer to do diagnostic, also with HJT, still can't find anything weird.
DDS log
DDS (Ver_09-10-26.01) - NTFSx86
Run by Jacky at 23:43:40,42 on 03/11/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.936.86.1033.18.3070.2314 [GMT 8:00]
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
============== Running Processes ===============
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe
D:\WINDOWS\system32\RUNDLL32.EXE
D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\Internet Download Manager\IDMan.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\ESET\ESET Smart Security\ekrn.exe
D:\Program Files\LogMeIn Hamachi\hamachi-2.exe
D:\WINDOWS\system32\PnkBstrA.exe
D:\WINDOWS\system32\svchost.exe -k imgsvc
D:\Program Files\Internet Download Manager\IEMonitor.exe
D:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\Program Files\Garena\Garena.exe
D:\WINDOWS\system32\conime.exe
D:\Program Files\ESET\ESET Smart Security\egui.exe
D:\WINDOWS\System32\svchost.exe -k HTTPFilter
D:\WINDOWS\system32\PnkBstrB.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\Jacky\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com.my/
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 119.70.40.101:8080
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - d:\program files\internet download manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - d:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: DwHlperOX3688 Class: {78a11a73-6d8a-11db-a78b-000bcdb692db} - d:\windows\system32\DwMgr3.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - d:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - d:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - d:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - d:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {B580CF65-E151-49C3-B73F-70B13FCA8E86} - No File
uRun: [MsnMsgr] "d:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [uTorrent] "d:\program files\utorrent\uTorrent.exe"
uRun: [IDMan] d:\program files\internet download manager\IDMan.exe /onboot
uRun: [DAEMON Tools] ; "d:\program files\daemon tools\daemon.exe" -lang 1033
uRun: [swg] "d:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
uRunOnce: [Shockwave Updater] ; d:\windows\system32\adobe\shockw~1\SWHELP~1.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; InfoPath.1; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.armoredlegion.com/legionlaunch.php"
mRun: [HDAudDeck] ; d:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [egui] ; "d:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [Google Pinyin 2 Autoupdater] "d:\program files\google\google pinyin 2\GooglePinyinDaemon.exe"
mRun: [Adobe Reader Speed Launcher] ; "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [IMMON] ; "d:\program files\im magician\Vicamon.exe"
mRun: [LogMeIn GUI] ; "d:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [SunJavaUpdateSched] ; "d:\program files\java\jre6\bin\jusched.exe"
mRun: [TkBellExe] "d:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [NvCplDaemon] RUNDLL32.EXE d:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE d:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] ; "d:\program files\quicktime\qttask.exe" -atboottime
mRun: [IMJPMIG8.1] "d:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] d:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [MSPY2002] d:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] ; d:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] ; d:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
IE: Download all links with IDM - d:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - d:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - d:\program files\internet download manager\IEExt.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - d:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1D17175E-48B7-40EC-BEC2-E91C80A89237} - hxxp://img.gamehi.co.kr/cabs/GamehiLauncher.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://play.battlefield-heroes.com/static/updater/BFHUpdater_4.0.15.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/RACtrl.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - d:\docume~1\jacky\applic~1\mozilla\firefox\profiles\pajct6ox.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: d:\documents and settings\jacky\application data\idm\idmmzcc2\components\idmmzcc.dll
FF - plugin: d:\documents and settings\all users.windows\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: d:\documents and settings\all users.windows\application data\zylom\zylomgamesplayer\npzylomgamesplayer.dll
FF - plugin: d:\documents and settings\jacky\application data\mozilla\firefox\profiles\pajct6ox.default\extensions\battlefieldheroespatcher@ea.com\platform\winnt_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: d:\documents and settings\jacky\local settings\application data\yahoo!\browserplus\2.4.17\plugins\npybrowserplus_2.4.17.dll
FF - plugin: d:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: d:\program files\mozilla firefox\plugins\npijjiCHPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;d:\windows\system32\drivers\Lbd.sys [2009-10-23 64288]
R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256]
R2 ekrn;ESET Service;d:\program files\eset\eset smart security\ekrn.exe [2009-5-14 731840]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\program files\logmein hamachi\hamachi-2.exe [2009-10-9 1078664]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;d:\windows\system32\drivers\viahduaa.sys [2008-11-13 876288]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;d:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1179232]
S3 GarenaPEngine;GarenaPEngine;\??\d:\docume~1\jacky\locals~1\temp\jwu1530.tmp --> d:\docume~1\jacky\locals~1\temp\JWU1530.tmp [?]
S3 npggsvc;nProtect GameGuard Service;d:\windows\system32\gamemon.des -service --> d:\windows\system32\GameMon.des -service [?]
S3 tap0901;TAP-Win32 Adapter V9;d:\windows\system32\drivers\tap0901.sys [2009-7-23 28592]
S3 wip0204;Wippien Network Adapter 2.4;d:\windows\system32\drivers\wip0204.sys [2009-9-25 23480]
=============== Created Last 30 ================
2009-12-24 13:34:23 8192 ----a-w- d:\windows\d3dx.dat
2009-12-24 12:31:54 0 d-----w- d:\docume~1\alluse~1.win\applic~1\UClick
2009-11-03 15:39:20 0 d-----w- d:\windows\system32\NtmsData
2009-10-31 20:26:01 0 d-----w- d:\program files\SD GUNDAM Online
2009-10-30 12:19:37 93360 ----a-w- d:\windows\system32\drivers\SBREDrv.sys
2009-10-30 11:41:46 1808880 ----a-w- d:\windows\system32\GooglePinyin2.ime
2009-10-28 11:44:46 0 d-----w- d:\program files\OUTPOP Digital
2009-10-28 04:04:18 8012 ----a-w- D:\Harvest Moon - Friends of Mineral Town.clt
2009-10-27 08:28:30 0 d-----w- d:\program files\LGInternetKit
2009-10-27 08:27:50 0 d-----w- d:\program files\LG Electronics
2009-10-26 17:10:28 0 d-----w- d:\program files\UlisesSoft
2009-10-25 14:54:17 59904 ----a-w- d:\windows\system32\zlib.dll
2009-10-23 19:20:21 0 d-sh--w- d:\documents and settings\jacky\IECompatCache
2009-10-23 12:35:44 15688 ----a-w- d:\windows\system32\lsdelete.exe
2009-10-23 12:17:55 64288 ----a-w- d:\windows\system32\drivers\Lbd.sys
2009-10-23 12:08:49 0 dc-h--w- d:\docume~1\alluse~1.win\applic~1\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-23 12:08:38 0 d-----w- d:\program files\Lavasoft
2009-10-22 21:02:03 0 d-----w- d:\docume~1\alluse~1.win\applic~1\NVIDIA Corporation
2009-10-22 21:00:39 0 d-----w- d:\program files\NVIDIA Corporation
2009-10-21 20:26:56 0 d-----w- D:\Soldat
2009-10-21 20:26:56 0 d-----w- d:\docume~1\jacky\applic~1\Soldat
2009-10-19 18:00:01 0 d-----w- d:\program files\Reality Gap
2009-10-17 00:39:09 0 d-----w- D:\Garena
2009-10-16 22:08:37 0 d-----w- D:\VertigoGames
2009-10-14 21:09:40 0 d-----w- d:\program files\LogMeIn Hamachi
2009-10-14 06:33:03 153088 -c----w- d:\windows\system32\dllcache\triedit.dll
2009-10-12 15:22:08 26176 ---ha-w- d:\windows\system32\hamachi.sys
2009-10-12 08:53:24 0 d-----w- d:\docume~1\alluse~1.win\applic~1\Sandlot Games
2009-10-12 06:28:04 0 d-----w- d:\program files\ReflexiveArcade
==================== Find3M ====================
2009-11-03 15:31:47 215104 ----a-w- d:\windows\system32\PnkBstrB.exe
2009-11-03 14:48:36 138576 ----a-w- d:\windows\system32\drivers\PnkBstrK.sys
2009-09-27 10:20:04 2173544 ----a-w- d:\windows\system32\nvcplui.exe
2009-09-27 10:20:00 81920 ----a-w- d:\windows\system32\nvwddi.dll
2009-09-27 10:19:52 3166208 ----a-w- d:\windows\system32\nvwss.dll
2009-09-27 10:19:50 4026368 ----a-w- d:\windows\system32\nvvitvs.dll
2009-09-27 10:19:48 3547136 ----a-w- d:\windows\system32\nvgames.dll
2009-09-27 10:19:48 188416 ----a-w- d:\windows\system32\nvmccss.dll
2009-09-27 10:19:48 1286144 ----a-w- d:\windows\system32\nvmobls.dll
2009-09-27 10:19:46 86016 ----a-w- d:\windows\system32\nvmctray.dll
2009-09-27 10:19:46 4935680 ----a-w- d:\windows\system32\nvdisps.dll
2009-09-27 10:19:46 172100 ----a-w- d:\windows\system32\nvsvc32.exe
2009-09-27 10:19:46 143360 ----a-w- d:\windows\system32\nvcolor.exe
2009-09-27 10:19:46 13918208 ----a-w- d:\windows\system32\nvcpl.dll
2009-09-27 10:19:40 229376 ----a-w- d:\windows\system32\nvmccs.dll
2009-09-27 08:12:22 888832 ----a-w- d:\windows\system32\nvapi.dll
2009-09-27 08:12:22 7655872 ----a-w- d:\windows\system32\drivers\nv4_mini.sys
2009-09-27 08:12:22 5900416 ----a-w- d:\windows\system32\nv4_disp.dll
2009-09-27 08:12:22 490088 ----a-w- d:\windows\system32\nvudisp.exe
2009-09-27 08:12:22 2194024 ----a-w- d:\windows\system32\nvcuvid.dll
2009-09-27 08:12:22 2007040 ----a-w- d:\windows\system32\nvcuda.dll
2009-09-27 08:12:22 1714792 ----a-w- d:\windows\system32\nvcuvenc.dll
2009-09-27 08:12:22 170600 ----a-w- d:\windows\system32\nvcodins.dll
2009-09-27 08:12:22 170600 ----a-w- d:\windows\system32\nvcod.dll
2009-09-27 08:12:22 1604482 ----a-w- d:\windows\system32\nvdata.bin
2009-09-27 08:12:22 10756096 ----a-w- d:\windows\system32\nvoglnt.dll
2009-09-24 01:24:18 490088 ----a-w- d:\windows\system32\nvuninst.exe
2009-09-16 00:02:40 27136 ----a-w- d:\windows\system32\drivers\tap0901t.sys
2009-09-11 14:18:39 136192 ----a-w- d:\windows\system32\msv1_0.dll
2009-09-04 21:03:36 58880 ----a-w- d:\windows\system32\msasn1.dll
2009-08-29 08:08:21 916480 ----a-w- d:\windows\system32\wininet.dll
2009-08-26 08:00:21 247326 ----a-w- d:\windows\system32\strmdll.dll
2009-08-23 07:13:55 94208 ----a-w- d:\docume~1\jacky\applic~1\ezplay.sys
2009-08-23 07:13:55 87608 ----a-w- d:\docume~1\jacky\applic~1\inst.exe
2009-08-23 07:13:46 47360 ----a-w- d:\docume~1\jacky\applic~1\pcouffin.sys
2009-08-12 19:06:35 75064 ----a-w- d:\windows\system32\PnkBstrA.exe
2009-08-07 11:51:54 15308424 ----a-w- d:\windows\system32\xlive.dll
2009-08-07 11:51:54 13642888 ----a-w- d:\windows\system32\xlivefnt.dll
2009-05-18 14:54:53 25 ----a-w- d:\program files\popcinfot.dat
2006-05-03 09:06:54 163328 --sh--r- d:\windows\system32\flvDX.dll
2007-02-21 10:47:16 31232 --sh--r- d:\windows\system32\msfDX.dll
2008-03-16 12:30:52 216064 --sh--r- d:\windows\system32\nbDX.dll
============= FINISH: 23:43:58,17 ===============