DDS (Ver_09-01-19.01) - NTFSx86
Run by Deborah at 9:54:38.37 on Thu 01/22/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.766.355 [GMT -7:00]
AV: AVG 7.5.476 *On-access scanning enabled* (Outdated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Deborah\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.msn.com
mStart Page = hxxp://www.msn.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>;127.0.0.1;*.local
mSearchAssistant = hxxp://www.google.com/ie
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
BHO: NoExplorer - No File
BHO: {4339d995-436b-0da8-0204-2f4e0c68fd87}: {78df86c0-e4f2-4020-8ad0-b634599d9334} - c:\windows\system32\yupogt.dll
BHO: {83d505c2-cab9-4500-9aab-3f93e940f5e8} - c:\windows\system32\advapi3.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: ST: {9394ede7-c8b5-483e-8773-474bf36af6e4} - c:\program files\msn apps\st\01.03.0000.1005\en-xu\stmain.dll
BHO: Viewpoint Toolbar BHO: {a7327c09-b521-4edb-8509-7d2660c9ec98} - c:\program files\viewpoint\viewpoint toolbar\3.8.0\ViewBarBHO.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.0.1225.9868\swg.dll
BHO: MSNToolBandBHO: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
TB: MSN: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\msn apps\msn toolbar\msn toolbar\01.02.5000.1021\en-us\msntb.dll
TB: {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A} - No File
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
DPF: ChatSpace Full Java Client 4.0.0.301 - hxxp://www.ldschat.com:8569/Java/cfs40301.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: Yahoo! Chat - hxxp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
DPF: Yahoo! Fleet - hxxp://download.games.yahoo.com/games/clients/y/fltt3_x.cab
DPF: Yahoo! Literati - hxxp://download.games.yahoo.com/games/clients/y/tt1_x.cab
DPF: Yahoo! MahJong Solitaire - hxxp://download.games.yahoo.com/games/clients/y/mjst4_x.cab
DPF: Yahoo! Poker - hxxp://download.games.yahoo.com/games/clients/y/pt3_x.cab
DPF: Yahoo! Pool 2 - hxxp://download2.games.yahoo.com/games/clients/y/poti_x.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37614.9391898148
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio5_0_2_7.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\deborah\applic~1\mozilla\firefox\profiles\4mbwwpvd.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnI=I%27m+Feeling+Lucky&ie=UTF-8&oe=UTF-8&q=
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npracplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: XUL Cache: {B120FE16-4705-4598-872C-3890DC5A9A82} - c:\windows\system32\config\systemprofile\local settings\application data\{b120fe16-
4705-4598-872c-3890dc5a9a82}\
FF - HiddenExtension: XUL Cache: {C5560414-9EFE-41B0-8C97-1EC2BC701427} - c:\documents and settings\deborah\local settings\application data\{C5560414-9EFE-
41B0-8C97-1EC2BC701427}
============= SERVICES / DRIVERS ===============
R0 cdngfeml;cdngfeml;c:\windows\system32\drivers\ckebptsn.dat --> c:\windows\system32\drivers\ckebptsn.dat [?]
R0 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-9-15 40840]
R1 Avg7Core;AVG7 Kernel;c:\windows\system32\drivers\avg7core.sys [2007-6-24 820928]
R1 Avg7RsW;AVG7 Wrap Driver;c:\windows\system32\drivers\avg7rsw.sys [2007-6-24 4224]
R1 Avg7RsXP;AVG7 Resident Driver XP;c:\windows\system32\drivers\avg7rsxp.sys [2007-6-24 27776]
R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2007-6-24 3968]
R1 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-9-15 66952]
R1 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-9-15 81288]
R1 mchInjDrv;madCodeHook DLL injection driver;c:\windows\system32\drivers\mchInjDrv.sys [2007-10-5 2560]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2007-8-24 21920]
R4 AvgTdi;AVG Network Redirector;c:\windows\system32\drivers\avgtdi.sys [2007-6-24 4960]
S0 stwlfbus;stwlfbus;c:\windows\system32\drivers\stwlfbus.sys [2003-4-27 8704]
S3 PsSdk30;PsSdk30;\??\c:\windows\system32\drivers\pssdk30.drv --> c:\windows\system32\drivers\PsSdk30.drv [?]
S3 st3wolf;st3wolf;c:\windows\system32\drivers\st3wolf.sys [2003-4-27 99360]
S3 xbreader;MaxDrive XBox Driver (xbreader.sys);c:\windows\system32\drivers\xbreader.sys [2001-1-2 19677]
S4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
S4 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2007-6-24 353280]
S4 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2007-6-24 49664]
S4 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avg7\avgemc.exe [2007-6-24 352768]
S4 mrtRate;mrtRate; [x]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-9-15 356920]
S4 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-9-15 1077640]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-4-26 24652]
=============== Created Last 30 ================
2009-01-19 11:28 54,156 a---h--- c:\windows\QTFont.qfn
2009-01-19 11:28 1,409 a------- c:\windows\QTFont.for
2009-01-16 04:57 135,168 a------- c:\windows\avanerokowucafo.dll
2009-01-16 04:45 41,984 a------- c:\windows\Dxevodowur.dll
2009-01-16 04:45 41,984 a------- c:\windows\system32\chert5-998.exe
2009-01-15 10:46 1 a------- c:\windows\system32\uniq.tll
2009-01-14 22:21 125,440 a------- c:\windows\system32\znabtw.dll
2009-01-14 22:21 125,440 a------- c:\windows\system32\wsmypvdl.dll
2009-01-14 16:42 125,440 a------- c:\windows\system32\bszyer.dll
2009-01-14 16:42 125,440 a------- c:\windows\system32\uxmnxgno.dll
2009-01-14 16:42 1,372,550 a--sh--- c:\windows\system32\ysbjuwvm.ini
2009-01-13 16:42 123,904 a------- c:\windows\system32\tekvrl.dll
2009-01-13 16:42 123,904 a------- c:\windows\system32\ogqnxoon.dll
2009-01-13 16:42 1,352,104 a--sh--- c:\windows\system32\opmrieer.ini
2009-01-12 16:41 124,928 a------- c:\windows\system32\jgypuc.dll
2009-01-12 16:41 1,266,872 a--sh--- c:\windows\system32\nflgxbem.ini
2009-01-12 16:41 124,928 a------- c:\windows\system32\qxycfojc.dll
2009-01-12 11:52 125,440 a------- c:\windows\system32\ntdll64.exe
2009-01-12 11:22 1,347 a------- c:\windows\system32\ahtn.htm
2009-01-12 11:22 4,785 a------- c:\windows\system32\warning.gif
2009-01-12 11:22 491 a------- c:\windows\system32\win32hlp.cnf
2009-01-12 11:21 111,616 ac------ c:\windows\system32\dllcache\userinit.exe
2009-01-12 11:20 1 a------- c:\windows\system32\test.ttt
2009-01-12 11:20 31,232 a------- c:\windows\system32\frmwrk32.exe
2009-01-12 11:20 31,232 a------- c:\windows\system32\pcload.exe
2009-01-12 00:21 <DIR> --d----- c:\program files\Trend Micro
2009-01-11 16:39 123,392 a------- c:\windows\system32\yupogt.dll
2009-01-11 16:39 123,392 a------- c:\windows\system32\ecollldy.dll
2009-01-10 20:30 1,256,329 a--sh--- c:\windows\system32\hwyimjup.ini
2009-01-10 20:27 124,928 a------- c:\windows\system32\unxszu.dll
2009-01-10 20:27 124,928 a------- c:\windows\system32\ampncpno.dll
2009-01-09 15:50 388,640 a------- C:\temp3131.tmp
2009-01-09 12:06 133,120 a------- c:\windows\system32\mlzmfm.dll
2009-01-09 12:06 133,120 a------- c:\windows\system32\awmgngmd.dll
2009-01-08 12:05 139,264 a------- c:\windows\system32\ocprsx.dll
2009-01-08 12:04 139,264 a------- c:\windows\system32\iklpnbdf.dll
2009-01-07 12:04 129,536 a------- c:\windows\system32\urnzqz.dll
2009-01-07 12:04 129,536 a------- c:\windows\system32\ptmlbjma.dll
2009-01-07 12:01 1,326,815 a--sh--- c:\windows\system32\etpkcnmm.ini
2009-01-07 09:34 73,216 a------- c:\windows\system32\ffkuz.dll
2009-01-06 14:49 31 a------- c:\windows\system32\k9261108.exe
2009-01-06 12:06 137,728 a------- c:\windows\system32\sxnjjr.dll
2009-01-06 12:06 137,728 a------- c:\windows\system32\jlrxrwhe.dll
2009-01-05 11:59 1,321,922 a--sh--- c:\windows\system32\dwobrwia.ini
2009-01-05 11:59 126,976 a------- c:\windows\system32\auhmvguy.dll
2009-01-05 11:50 50,176 a------- c:\windows\system32\jkkHBSJA.dll
2009-01-05 11:34 114,688 a------- c:\windows\system32\prunnet.exe
2009-01-02 16:42 388,640 a------- C:\temp8876.tmp
2008-12-31 18:27 388,640 a------- C:\temp9878.tmp
2008-12-30 17:03 388,640 a------- C:\temp6020.tmp
2008-12-30 17:03 388,640 a------- C:\temp2547.tmp
2008-12-30 17:03 388,640 a------- C:\temp8278.tmp
==================== Find3M ====================
2009-01-21 21:01 2,560 a------- c:\windows\system32\drivers\mchInjDrv.sys
2009-01-18 13:58 303,104 a------- c:\windows\help\TIBIA MULTI-IP CHANGER.EXE
2009-01-15 16:43 96,256 a------- c:\windows\system32\drivers\sptd0349.sys
2009-01-12 11:21 111,616 a------- c:\windows\system32\userinit.exe
2008-11-14 09:25 116,480 a------- c:\windows\system32\advapi3.dll
2008-09-23 19:38 16,380 a------- c:\program files\D&D - Warriors of the Eternal Sun (U) [!].srm
2008-03-16 07:23 67,840 a------- c:\docume~1\deborah\applic~1\GDIPFONTCACHEV1.DAT
2007-07-04 10:26 9 a------- c:\program files\install_log.dat
2007-04-03 15:42 10,993,720 a------- c:\program files\BackCompat_01-2007.zip
2007-03-25 14:39 114 a------- c:\documents and settings\deborah\hhjj.bat
2007-03-25 14:39 41,792 a------- c:\documents and settings\deborah\nek.exe
2007-03-23 12:30 201 a------- c:\documents and settings\deborah\q.bat
2001-04-04 17:11 184 a---hr-- c:\program files\AUTORUN.INF
2007-12-08 08:02 458,637 a--sh--- c:\windows\system32\qqtss.ini2
2005-08-28 18:02 216 a--sh--- c:\windows\system32\pkixwkk\csrss.dat
============= FINISH: 9:56:50.87 ===============
Attachment text is attached.
I am very thankful for any help you can provide on this problem! Thank you very much!