heres the dds log
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.6001.18702
Run by Administrator at 21:22:14 on 2012-01-16
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2551.2366 [GMT -6:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\BN9.tmp
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.searchqu.com/406
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: mefeediaTest: {154d932f-dc51-4a4f-9d52-b78b1419d3b4} - c:\program files\mefeediatest\w3itemplateX.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll
BHO: DataMngr: {9d717f81-9148-4f12-8568-69135f087db0} - c:\progra~1\wi371a~1\datamngr\BROWSE~1.DLL
BHO: CNisExtBho Class: {9ecb9560-04f9-4bbc-943d-298ddf1699e1} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll
BHO: CNavExtBho Class: {a8f38d8d-e480-4d52-b7a2-731bb6995fdd} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: WhIeHelperObj Class: {c900b400-cdfe-11d3-976a-00e02913a9e0} - c:\progra~1\webhan~1\programs\whiehlpr.dll
BHO: WeCareReminder Class: {d824f0de-3d60-4f57-9eb1-66033ecd8abb} - c:\documents and settings\all users\application data\wecarereminder\IEHelperv2.5.0.dll
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~1\wi371a~1\datamngr\toolbar\searchqudtx.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: mefeediaTest: {154d932f-dc51-4a4f-9d52-b78b1419d3b4} - c:\program files\mefeediatest\w3itemplateX.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: Norton Internet Security 2006: {0b53eac3-8d69-4b9e-9b19-a37c9a5676a7} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll
TB: Norton AntiVirus: {c4069e3a-68f1-403e-b40e-20066696354b} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
EB: {BDEADE7F-C265-11D0-BCED-00A0C90AB50F} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [tcpudp] c:\windows\BN6.tmp
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil11c_ActiveX.exe -update activex
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [LayoutM] KLayMgr.exe
mRun: [webHancer Agent] "c:\program files\webhancer\programs\whAgent.exe"
mRun: [DC6_check] "c:\program files\common files\dc6_startupmon.exe"
mRun: [ERS_check] "c:\program files\common files\ers_startupmon.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [DigidesignMMERefresh] c:\program files\digidesign\drivers\MMERefresh.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [DATAMNGR] c:\progra~1\wi371a~1\datamngr\DATAMN~1.EXE
mRun: [kblxrhoj] c:\windows\system32\kblxrhoj.exe
mRun: [LHUnnGkTMirhwy.exe] c:\documents and settings\all users\application data\LHUnnGkTMirhwy.exe
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
dRun: [kblxrhoj] c:\documents and settings\administrator\kblxrhoj.exe
dRun: [tcpudp] c:\windows\BN9.tmp
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\flipto~1.lnk - c:\program files\fliptoast\fliptoast.exe
IE: &Search -
http://tbedits.televisionfanatic.co...D760-879A-41BB-838A-573F19F37738&n=2011101020
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\wi371a~1\datamngr\datamngr.dll c:\progra~1\wi371a~1\datamngr\IEBHO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 122.224.6.164 zeus.sunke.info
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\dv6prpfb.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/406
FF - prefs.js: keyword.URL - hxxp://search.internet-search-results.com/?sid=10101199100&s=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
.
---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - Search
FF - user.js: browser.search.order.1 - Search
FF - user.js: keyword.URL - hxxp://search.internet-search-results.com/?sid=10101199100&s=
============= SERVICES / DRIVERS ===============
.
R3 MBX2DFU;MBX2DFU;c:\windows\system32\drivers\mbx2dfu.sys [2011-11-2 21648]
S0 wjcpcy;wjcpcy;c:\windows\system32\drivers\wygvotb.sys --> c:\windows\system32\drivers\wygvotb.sys [?]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-1-16 435032]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-1-16 314456]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-1-16 20568]
S2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-1-16 44768]
S2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [2011-11-2 16400]
S2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\firebird\firebird_2_5\bin\fbguard.exe [2011-10-18 118784]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-10-10 136176]
S3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [2011-11-2 97808]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys --> c:\windows\system32\drivers\ew_hwusbdev.sys [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys --> c:\windows\system32\drivers\ewusbnet.sys [?]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\firebird\firebird_2_5\bin\fbserver.exe [2011-10-18 3756032]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-10-10 136176]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys --> c:\windows\system32\drivers\ew_jubusenum.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 MBX2MIDK;Digidesign Mbox 2 Midi Driver;c:\windows\system32\drivers\mbx2midk.sys [2011-11-2 21904]
S3 uts_bus;UTStarcom USB Composite Device driver (WDM);c:\windows\system32\drivers\uts_bus.sys [2010-9-23 84352]
S3 uts_mdfl;UTStarcom USB Modem Filter;c:\windows\system32\drivers\uts_mdfl.sys [2010-9-23 14976]
S3 uts_mdm;UTStarcom USB Modem Drivers;c:\windows\system32\drivers\uts_mdm.sys [2010-9-23 110848]
S3 uts_serd;UTStarcom USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\uts_serd.sys [2010-9-23 90880]
.
=============== Created Last 30 ================
.
2012-01-17 03:17:22 -------- d-----w- C:\62bf302e7f51a6a67e9f70
2012-01-17 03:07:09 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-01-17 03:07:00 41184 ----a-w- c:\windows\avastSS.scr
2012-01-17 03:06:39 -------- d-----w- c:\program files\AVAST Software
2012-01-17 03:06:39 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2012-01-17 03:02:16 -------- d-----w- C:\8e0396cf9782e310139902f668de4d
2012-01-17 01:53:50 196608 ---ha-w- c:\windows\BN2.tmp
2012-01-17 01:43:50 196608 ---ha-w- c:\windows\BN9.tmp
2012-01-16 04:59:25 -------- d-----w- C:\Recovered Files
2012-01-15 04:58:14 215552 ---ha-w- c:\windows\BN8.tmp
2012-01-15 04:31:02 215552 ---ha-w- c:\windows\BN7.tmp
2012-01-15 04:24:49 215552 ---ha-w- c:\windows\BN6.tmp
2012-01-15 04:21:30 215552 ---ha-w- c:\windows\BN5.tmp
2012-01-15 04:16:15 -------- d--h--w- c:\documents and settings\administrator\local settings\application data\Help
2012-01-15 04:13:09 215552 ---ha-w- c:\windows\BN4.tmp
2012-01-15 04:06:35 357632 ---ha-w- c:\documents and settings\all users\application data\I3NvjJDZntUHz0.exe
2012-01-15 04:03:27 215552 ---ha-w- c:\windows\BNEF.tmp
2012-01-15 04:03:03 -------- d--h--w- c:\documents and settings\all users\application data\WSTB
2012-01-15 04:03:01 453376 ---ha-w- c:\documents and settings\all users\application data\LHUnnGkTMirhwy.exe
2012-01-15 04:02:59 60928 ---ha-w- c:\windows\system32\kblxrhoj.exe
2012-01-15 04:02:59 60928 ---ha-w- c:\documents and settings\administrator\kblxrhoj.exe
2012-01-11 22:58:46 -------- d--h--w- c:\documents and settings\administrator\application data\com.w3i.FlipToast
2012-01-11 22:58:37 -------- d--h--w- c:\program files\fliptoast
2012-01-11 22:58:11 -------- d--h--w- c:\documents and settings\administrator\application data\w3itemplate
2012-01-11 22:58:00 -------- d--h--w- c:\documents and settings\administrator\local settings\application data\Adobe
2012-01-11 22:57:59 -------- d--h--w- c:\documents and settings\administrator\application data\mefeediatest
2012-01-11 22:57:48 -------- d--h--w- c:\program files\mefeediatest
2012-01-11 22:57:14 -------- d--h--w- c:\program files\ChicaLogic
2012-01-11 22:57:06 -------- d--h--w- c:\documents and settings\all users\application data\Norton
2012-01-11 22:57:02 -------- d--h--w- c:\documents and settings\all users\application data\NortonInstaller
2012-01-09 06:20:28 626688 ---ha-w- c:\program files\mozilla firefox\msvcr80.dll
2012-01-09 06:20:28 548864 ---ha-w- c:\program files\mozilla firefox\msvcp80.dll
2012-01-09 06:20:28 479232 ---ha-w- c:\program files\mozilla firefox\msvcm80.dll
2012-01-09 06:20:28 43992 ---ha-w- c:\program files\mozilla firefox\mozutils.dll
2012-01-07 01:45:37 -------- d--h--w- c:\documents and settings\administrator\application data\Waves Audio
2012-01-07 01:45:32 -------- d--h--w- c:\documents and settings\all users\application data\Waves Audio
2012-01-07 01:41:45 -------- d--h--w- c:\program files\Steinberg
2012-01-07 01:41:45 -------- d--h--w- c:\program files\common files\VST3
2012-01-07 01:38:52 -------- d--h--w- c:\program files\Waves
2012-01-02 23:34:35 -------- d-sh--w- c:\windows\system32\AI_RecycleBin
2012-01-02 23:34:35 -------- d--h--w- c:\program files\Free Offers from Freeze.com
2012-01-02 23:34:10 -------- d--h--w- c:\documents and settings\all users\application data\WeCareReminder
2011-12-22 02:21:23 -------- d--h--w- c:\documents and settings\administrator\local settings\application data\WinZip
.
==================== Find3M ====================
.
2011-12-11 02:41:58 406528 ---ha-w- c:\windows\system32\ReWire.dll
2011-12-11 02:41:58 338432 ---ha-w- c:\windows\system32\REX Shared Library.dll
2011-11-15 03:20:44 77824 --sh--r- c:\documents and settings\administrator\puoiw.scr
2011-11-14 22:25:19 414368 ---ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-12 00:25:53 1053696 ---ha-w- c:\windows\explorer.exe
2011-10-24 19:29:02 94208 ---ha-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29:02 69632 ---ha-w- c:\windows\system32\QuickTime.qts
.
============= FINISH: 21:23:27.32 ===============