DDS (Ver_09-12-01.01) - NTFSx86 Run by User at 19:14:24,20 on 05.03.2010 Internet Explorer: 6.0.2900.3180 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1671 [GMT 1:00] AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\User\Desktop\dds.com ============== Pseudo HJT Report =============== BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: Ask Toolbar BHO: {fe063db1-4ec0-403e-8dd8-394c54984b2c} - c:\program files\asktbar\bar\1.bin\ASKTBAR.DLL TB: Ask Toolbar: {fe063db9-4ec0-403e-8dd8-394c54984b2c} - c:\program files\asktbar\bar\1.bin\ASKTBAR.DLL uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe" mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab ============= SERVICES / DRIVERS =============== R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-3-4 11608] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-3-4 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-3-4 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-3-4 55656] =============== Created Last 30 ================ 2010-03-05 15:48:47 0 d-----w- c:\program files\EA SPORTS 2010-03-05 15:36:13 107888 ----a-w- c:\windows\system32\CmdLineExt.dll 2010-03-05 15:35:29 459 ----a-w- c:\windows\EngMac.ini 2010-03-05 15:33:38 425 ----a-w- c:\windows\EVSAPP.INI 2010-03-05 15:27:56 0 d-----w- c:\windows\Formula 1 2010-03-05 15:27:56 0 d-----w- c:\program files\Formula 1 2007 2010-03-05 15:27:56 0 d-----w- c:\program files\Formula 1 2010-03-05 15:18:48 0 d-----w- c:\docume~1\alluse~1\applic~1\Firefly Studios 2010-03-05 15:11:21 0 d-----w- c:\program files\common files\DirectX 2010-03-05 14:25:35 0 d-----w- c:\docume~1\alluse~1\applic~1\Kristanix Games 2010-03-05 14:24:43 0 d-----w- c:\docume~1\user\applic~1\cerasus.media 2010-03-05 14:23:49 0 d-----w- c:\documents and settings\user\Saved Games 2010-03-04 20:32:32 0 d-----w- c:\program files\Symantec 2010-03-04 20:26:04 0 d-----w- c:\program files\common files\ODBC 2010-03-04 20:26:02 0 d-----w- c:\program files\common files\SpeechEngines 2010-03-04 20:25:44 0 d-----r- c:\documents and settings\all users\Documents 2010-03-04 20:09:20 0 d-----w- c:\program files\VirtualDJ 2010-03-04 20:07:51 0 d-----w- c:\program files\USB Camera 2010-03-04 20:07:51 0 d-----w- c:\program files\EETI 2010-03-04 20:06:35 0 d-----w- c:\program files\Avira 2010-03-04 20:06:35 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira 2010-03-04 20:05:34 0 d-----w- c:\docume~1\user\applic~1\Xilisoft Corporation 2010-03-04 20:05:22 0 d-----w- c:\program files\Xilisoft 2010-03-04 20:03:04 0 d-----w- c:\program files\Microsoft ActiveSync 2010-03-04 20:02:49 0 d-----w- c:\program files\The KMPlayer 2010-03-04 20:01:28 0 d-----w- c:\docume~1\user\applic~1\ACD Systems 2010-03-04 20:01:04 0 d-----w- c:\docume~1\user\applic~1\AccurateRip 2010-03-04 20:00:59 0 d-----w- c:\program files\Illustrate 2010-03-04 20:00:48 0 d-----w- c:\docume~1\alluse~1\applic~1\ACD Systems 2010-03-04 20:00:45 0 d-----w- c:\program files\common files\ACD Systems 2010-03-04 20:00:45 0 d-----w- c:\program files\ACD Systems 2010-03-04 19:58:34 0 d-----w- c:\program files\Microsoft 2010-03-04 19:58:21 0 d-----w- c:\program files\Windows Live SkyDrive 2010-03-04 19:56:25 0 d-----w- c:\program files\Nero 2010-03-04 19:56:25 0 d-----w- c:\program files\common files\Windows Live 2010-03-04 19:56:25 0 d-----w- c:\docume~1\alluse~1\applic~1\Nero 2010-03-04 19:54:42 0 d-----w- c:\program files\AskTBar 2010-03-04 19:52:28 0 d-----r- c:\program files\Skype 2010-03-04 19:48:17 0 d-----w- c:\program files\WinampPlugins 2010-03-04 19:41:15 0 d-----w- c:\program files\AMD 2010-03-04 19:36:57 0 d-----w- c:\program files\Realtek 2010-03-04 19:32:14 0 d-sh--w- c:\documents and settings\all users\DRM 2010-03-04 19:32:00 0 d--h--w- c:\program files\WindowsUpdate 2010-03-04 19:31:26 0 d-----w- c:\program files\common files\MSSoap 2010-03-04 19:30:29 0 d-----w- c:\program files\Online Services 2010-03-04 19:30:25 0 d-----w- c:\program files\Messenger 2010-03-04 19:30:22 0 d-----w- c:\program files\MSN Gaming Zone 2010-03-04 19:29:55 0 d-----w- c:\program files\Windows NT ==================== Find3M ==================== 2010-03-04 20:01:02 10099 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp DSP Effects.dat 2010-03-04 20:01:01 2857336 ----a-w- c:\windows\system32\SpoonUninstall.exe 2010-03-04 20:01:00 14051 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat 2010-03-04 19:59:15 410984 ----a-w- c:\windows\system32\deploytk.dll 2010-03-04 19:30:47 21640 ----a-w- c:\windows\system32\emptyregdb.dat ============= FINISH: 19:14:33,95 ===============