DDS (Ver_09-01-19.01) - NTFSx86 Run by [removed] at 0:55:05.68 on Fri 01/30/2009 Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_11 Microsoft� Windows Vista� Home Premium 6.0.6001.1.1252.1.1033.18.2037.863 [GMT -5:00] AV: AVG 7.5.552 *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Acer\ALaunch\ALaunchSvc.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Acer\Empowering Technology\eNet\eNet Service.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Acer\Empowering Technology\eAudio\eAudio.exe C:\Acer\Mobility Center\MobilityService.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe C:\Windows\system32\IoctlSvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\PSIService.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe C:\Acer\Empowering Technology\ePower\ePowerSvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Grisoft\AVG7\avgcc.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\System32\mobsync.exe C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Windows\system32\taskeng.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\defrag.exe C:\Windows\system32\notepad.exe C:\Windows\system32\NOTEPAD.EXE C:\Program Files\uTorrent\uTorrent.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\User\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\windows\system32\ActiveToolBand.dll BHO: Cole2k Media Toolbar Helper: {c672f4ab-780b-45c0-baec-91f455c86f8d} - c:\program files\cole2k media toolbar\v3.3.0.1\Cole2k_Media_Toolbar.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll TB: Cole2k Media Toolbar: {2d2de234-ab9f-4345-9d17-94fa78ba37e3} - c:\program files\cole2k media toolbar\v3.3.0.1\Cole2k_Media_Toolbar.dll mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [eAudio] "c:\acer\empowering technology\eaudio\eAudio.exe" mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [AVG7_CC] c:\progra~1\grisoft\avg7\avgcc.exe /STARTUP mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: avgwlntf - avgwlntf.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: eNetHook.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\user\appdata\roaming\mozilla\firefox\profiles\qh76n8ud.default\ FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - plugin: c:\users\user\appdata\roaming\mozilla\firefox\profiles\qh76n8ud.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp07076007.dll ============= SERVICES / DRIVERS =============== R3 AvgWFP;AVG7 Firewall Driver x86;c:\windows\system32\drivers\avgwfp.sys [2008-4-15 53768] R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-8-8 179712] R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2007-8-8 32256] R4 ALaunchService;ALaunch Service;c:\acer\alaunch\ALaunchSvc.exe [2007-8-8 50688] R4 NeroRegInCDSrv;Nero Registry InCD Service;c:\program files\nero\nero8\incd\NBHRegInCDSrv.exe [2008-2-28 53032] =============== Created Last 30 ================ 2009-01-29 23:52 250 a------- c:\windows\gmer.ini 2009-01-25 22:25 --d----- c:\program files\Trend Micro 2009-01-15 20:58 4,838 a------- c:\windows\system32\PerfStringBackup.TMP 2009-01-13 18:06 288,768 a------- c:\windows\system32\drivers\srv.sys 2009-01-10 17:42 230,749 a------- c:\windows\Cole2k_Media_Toolbar_Uninstaller_8082.exe 2009-01-10 17:42 --d----- c:\program files\Cole2k Media Toolbar 2009-01-10 17:42 --d----- c:\windows\system32\C2MP 2009-01-10 17:19 15,464 a------- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-01-10 17:18 --d----- c:\program files\iPod 2009-01-10 17:18 --d----- c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2009-01-10 17:18 --d----- c:\program files\iTunes 2009-01-10 17:18 --d----- c:\progra~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} ==================== Find3M ==================== 2009-01-23 12:22 2,932 a------- c:\windows\system32\KGyGaAvL.sys 2009-01-10 17:13 143,360 a------- c:\windows\inf\infstrng.dat 2009-01-10 17:13 143,360 a------- c:\windows\inf\infstor.dat 2009-01-10 17:13 86,016 a------- c:\windows\inf\infpub.dat 2008-12-27 13:23 107,888 -------- c:\windows\system32\CmdLineExt.dll 2008-12-10 19:33 200,704 a------- c:\windows\system32\dtu100.dll 2008-12-10 19:33 86,016 a------- c:\windows\system32\dpl100.dll 2008-12-08 21:28 593,920 a------- c:\windows\system32\dpuGUI11.dll 2008-12-08 21:28 344,064 a------- c:\windows\system32\dpus11.dll 2008-12-08 21:28 294,912 a------- c:\windows\system32\dpu11.dll 2008-12-08 21:28 57,344 a------- c:\windows\system32\dpv11.dll 2008-11-06 11:37 524,288 a------- c:\windows\system32\DivXsm.exe 2008-11-06 11:37 3,596,288 a------- c:\windows\system32\qt-dx331.dll 2008-11-06 11:35 1,044,480 a------- c:\windows\system32\libdivx.dll 2008-11-06 11:35 200,704 a------- c:\windows\system32\ssldivx.dll 2008-11-06 11:33 823,296 a------- c:\windows\system32\divx_xx0c.dll 2008-11-06 11:33 823,296 a------- c:\windows\system32\divx_xx07.dll 2008-11-06 11:33 815,104 a------- c:\windows\system32\divx_xx0a.dll 2008-11-06 11:33 802,816 a------- c:\windows\system32\divx_xx11.dll 2008-11-06 11:33 684,032 a------- c:\windows\system32\DivX.dll 2008-11-06 11:33 12,288 a------- c:\windows\system32\DivXWMPExtType.dll 2008-09-28 15:54 56 a---h--- c:\programdata\ezsidmv.dat 2008-09-28 15:54 56 a---h--- c:\progra~2\ezsidmv.dat 2008-06-11 02:17 665,600 a------- c:\windows\inf\drvindex.dat 2008-05-03 09:02 174 a--sh--- c:\program files\desktop.ini 2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat 2008-10-21 16:14 88 ---shr-- c:\windows\system32\0777FC4060.sys ============= FINISH: 0:55:40.78 ===============