DDS (Ver_09-01-07.01) - NTFSx86 Run by Kurt at 15:52:19.28 on Thu 08/01/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.357 [GMT 11:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\System32\svchost.exe -k NetworkService C:\WINDOWS\System32\svchost.exe -k LocalService C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\System32\alg.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\AVG\AVG8\avgscanx.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spyware Doctor\pctsGui.exe C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\Kurt\Desktop\dds(2).com C:\WINDOWS\System32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} uInternet Settings,ProxyOverride = *.local mWinlogon: SFCDisable=4 (0x4) BHO: {3bd7e47c-c75f-4fe2-ba58-7ebedbf753b8} - c:\windows\system32\ddabx.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL BHO: {ab646cb3-0486-4541-bcbc-150ac7541b23} - c:\windows\system32\jkkJaYqQ.dll TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background uRun: [NBJ] "c:\program files\ahead\nero backitup\NBJ.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe" mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript IE: &Winamp Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll TCP: NameServer = 208.67.220.220,208.67.222.222 TCP: {5439E578-8B3A-4905-B6B4-682977E5ADF2} = 192.189.54.33,203.8.183.1 TCP: {C401D776-8FBC-42B0-A7E7-F5E23D5C2999} = 208.67.220.220,208.67.222.222 TCP: {CF241CDB-B572-4782-B9F3-9722998D683A} = 208.67.220.220,208.67.222.222 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Authentication Packages = msv1_0 c:\windows\system32\jkkJaYqQ ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\kurt\applic~1\mozilla\firefox\profiles\y7w03vcd.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - yahoo.com.au FF - prefs.js: network.proxy.type - 4 FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg8\toolbarff\components\vmAVGConnector.dll FF - component: c:\program files\mozilla firefox\components\iamfamous.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\np32dsw.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npLegitCheckPlugin.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npmozax.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npmusicn.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npnul32.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\NPOFFICE.DLL FF - plugin: c:\progra~1\mozilla firefox\plugins\nppdf32.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\nppl3260.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin2.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin3.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin4.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin5.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin6.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin7.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\nprpjplug.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\NPSibelius.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npupd62.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npyaxmpb.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll ============= SERVICES / DRIVERS =============== R0 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2009-1-8 40840] R0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [2005-12-23 25067] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-28 97928] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-12-28 26824] R1 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2009-1-8 66952] R1 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2009-1-8 81288] R1 oreans32;oreans32;c:\windows\system32\drivers\oreans32.sys [2007-9-12 33824] R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-12-28 231704] R4 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-1-8 356920] R4 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-1-8 1079176] S3 iMSPQMn;iMSPQMn;\??\c:\docume~1\kurt\locals~1\temp\imspqmn.sys --> c:\docume~1\kurt\locals~1\temp\iMSPQMn.sys [?] S3 MEGAUSB0101;MegawinMa100;c:\windows\system32\drivers\usbscan.sys [2008-3-1 15104] S3 VundoFixSvc;VundoFix Service;VundoFixSVC.exe --> VundoFixSVC.exe [?] S3 WlanUIB;NETGEAR 802.11b USB Driver;c:\windows\system32\drivers\ma111nd5.sys --> c:\windows\system32\drivers\MA111nd5.sys [?] =============== Created Last 30 ================ 2009-01-08 15:40 81,288 a------- c:\windows\system32\drivers\iksyssec.sys 2009-01-08 15:40 66,952 a------- c:\windows\system32\drivers\iksysflt.sys 2009-01-08 15:40 40,840 a------- c:\windows\system32\drivers\ikfilesec.sys 2009-01-08 15:40 29,576 a------- c:\windows\system32\drivers\kcom.sys 2009-01-08 15:40