DDS (Ver_09-10-26.01) - NTFSx86
Run by user at 21:05:41.61 on Sun 11/15/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.382.53 [GMT -8:00]
AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
============== Running Processes ===============
H:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
H:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
H:\Program Files\AVG\AVG9\avgchsvx.exe
H:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
H:\Program Files\AVG\AVG9\avgcsrvx.exe
H:\WINDOWS\system32\LEXBCES.EXE
H:\WINDOWS\system32\LEXPPS.EXE
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
svchost.exe
H:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
H:\Program Files\AVG\AVG9\avgwdsvc.exe
H:\Program Files\AVG\AVG9\avgfws9.exe
H:\Program Files\Bonjour\mDNSResponder.exe
H:\WINDOWS\system32\WgaTray.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\System32\nvsvc32.exe
H:\Program Files\AVG\AVG9\avgam.exe
H:\Program Files\AVG\AVG9\avgnsx.exe
H:\WINDOWS\System32\svchost.exe -k imgsvc
H:\Program Files\AVG\AVG9\avgemc.exe
H:\Program Files\AVG\AVG9\avgcsrvx.exe
H:\WINDOWS\SOUNDMAN.EXE
H:\WINDOWS\system32\RUNDLL32.EXE
H:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
H:\Program Files\Java\jre6\bin\jusched.exe
H:\WINDOWS\system32\rundll32.exe
H:\Program Files\iTunes\iTunesHelper.exe
H:\PROGRA~1\AVG\AVG9\avgtray.exe
H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
H:\Program Files\Pando Networks\Media Booster\PMB.exe
H:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
H:\Program Files\AVG\AVG9\avgcsrvx.exe
H:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
H:\Program Files\iPod\bin\iPodService.exe
H:\WINDOWS\system32\wuauclt.exe
H:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
H:\Program Files\AVG\AVG9\avgscanx.exe
H:\Program Files\AVG\AVG9\avgcsrvx.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\Multi File Downloader\MultiFileDownloader.exe
H:\Documents and Settings\user\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uSearch Page =
hxxp://www.google.comuSearch Bar =
hxxp://www.google.com/iemDefault_Search_URL =
hxxp://www.google.com/iemSearch Bar =
hxxp://www.mirarsearch.com/?useie5=1&q=uInternet Settings,ProxyOverride = *.local
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%smSearchAssistant =
hxxp://www.google.com/ieuURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - h:\program files\avg\avg9\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - h:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - h:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - h:\program files\avg\avg9\avgssie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - h:\program files\java\jre6\bin\ssv.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - h:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - h:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - h:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - h:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - h:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - h:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - h:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - h:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Mirar: {e7d6883c-aa2b-4329-8ece-ff63676d4ca7} - h:\windows\system32\winbe78.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [swg] "h:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [MsnMsgr] "h:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [Pando Media Booster] h:\program files\pando networks\media booster\PMB.exe
uRun: [Multi File Downloader] h:\program files\multi file downloader\MultiFileDownloader.exe
mRun: [NvCplDaemon] RUNDLL32.EXE h:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NvMediaCenter] RUNDLL32.EXE h:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Google Desktop Search] "h:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [SunJavaUpdateSched] "h:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "h:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "h:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "h:\program files\itunes\iTunesHelper.exe"
mRun: [AVG9_TRAY] h:\progra~1\avg\avg9\avgtray.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "h:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRun: [CTFMON.EXE] h:\windows\system32\CTFMON.EXE
StartupFolder: h:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - h:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
IE: Add to AMV Converter... - h:\program files\mp3 player utilities 4.19\amvconverter\grab.html
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - h:\program files\messenger\msmsgs.exe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} -
hxxp://go.microsoft.com/fwlink/?linkid=39204DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -
hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1205984625093DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} -
hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cabDPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} -
hxxp://plugin.driveragent.com/files/driveragent.cabHandler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - h:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: h:\progra~1\google\google~2\GOEC62~1.DLL
================= FIREFOX ===================
FF - ProfilePath - h:\docume~1\user\applic~1\mozilla\firefox\profiles\peiimp6c.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: keyword.URL -
hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_us&p=FF - component: h:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: h:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: h:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: h:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: h:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: h:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - component: h:\program files\mozilla firefox\components\SaveComponent.dll
FF - plugin: h:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: h:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: h:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: h:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: h:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - plugin: h:\program files\unity\webplayer\loader\npUnity3D32.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - h:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - hȋdden: Java Console: No Registry Reference - h:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - hȋdden: Java Console: No Registry Reference - h:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - hȋdden: Java Console: No Registry Reference - h:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - trueh:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrxpx;AVG9IDSErHr;h:\windows\system32\drivers\AVGIDSxx.sys [2009-11-11 25608]
R0 AvgRkx86;avgrkx86.sys;h:\windows\system32\drivers\avgrkx86.sys [2009-11-11 161800]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;h:\windows\system32\drivers\avgldx86.sys [2009-5-16 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;h:\windows\system32\drivers\avgtdix.sys [2009-5-16 360584]
R3 Avgfwdx;Avgfwdx;h:\windows\system32\drivers\avgfwdx.sys [2009-11-11 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;h:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2009-11-11 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;h:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2009-11-11 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;h:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2009-11-11 25736]
S3 Avgfwfd;AVG network filter service;h:\windows\system32\drivers\avgfwdx.sys [2009-11-11 30104]
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;h:\documents and settings\user\desktop\moonlight\moonlight\IlvMoney1224.sys [2008-11-8 30080]
=============== Created Last 30 ================
==================== Find3M ====================
2009-11-11 23:18:55 333192 ----a-w- h:\windows\system32\drivers\avgldx86.sys
2009-11-11 23:18:54 360584 ----a-w- h:\windows\system32\drivers\avgtdix.sys
2009-11-11 23:18:32 12464 ----a-w- h:\windows\system32\avgrsstx.dll
2009-09-26 02:32:45 17532 ---ha-w- h:\windows\system32\mlfcache.dat
2009-09-25 05:56:36 662016 ----a-w- h:\windows\system32\wininet.dll
2009-09-25 05:56:32 81920 ------w- h:\windows\system32\ieencode.dll
2009-09-11 14:33:52 133632 ----a-w- h:\windows\system32\msv1_0.dll
2009-09-04 20:45:26 58880 ----a-w- h:\windows\system32\msasn1.dll
2009-08-26 08:16:37 247326 ----a-w- h:\windows\system32\strmdll.dll
============= FINISH: 21:07:56.73 ===============