i tryed to found a solution and runned DDS, and here is the log:
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by Pedro Tenente at 14:58:16 on 2011-08-06
Microsoft Windows 7 Professional 6.1.7601.1.1252.55.1046.18.3069.1771 [GMT -3:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskhost.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\Pedro Tenente\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Pedro Tenente\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Pedro Tenente\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Pedro Tenente\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Pedro Tenente\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://search.minituner.org/
uStart Page = hxxp://search.minituner.org/
uSearch Bar = hxxp://search.minituner.org/
mDefault_Search_URL = hxxp://search.minituner.org/
mSearch Page = hxxp://search.minituner.org/
uSearchURL,(Default) = hxxp://search.minituner.org/q/%s
mSearchAssistant = hxxp://search.minituner.org/
mCustomizeSearch = hxxp://search.minituner.org/
uURLSearchHooks: H - No File
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: Auxiliar de Conexão do Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [Google Update] "c:\users\pedro tenente\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE"
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
uPolicies-explorer: DisallowRun = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &Enviar para o OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: E&xportar para o Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{58588122-152E-441F-8325-5EB3BAE8A399} : NameServer = 200.222.122.132 200.165.132.147
TCP: Interfaces\{BB5E9058-EA08-4C9D-B8DD-5E0480D2A720} : DhcpNameServer = 192.168.1.254
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
IFEO: image file execution options - svchost.exe
Hosts: 66.232.102.249 google.com
Hosts: 66.232.102.249 google.com.au
Hosts: 66.232.102.249 www.google.com.au
Hosts: 66.232.102.249 google.be
Hosts: 66.232.102.249 www.google.be
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-6-14 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-2-23 309848]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-2-23 19544]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-2-23 54104]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2011-7-8 42184]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
S2 KMService;KMService;c:\windows\system32\srvany.exe [2011-1-21 8192]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-3-25 30969208]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 StorSvc;Serviço de Armazenamento;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-13 52224]
S3 WatAdminSvc;Serviço de Tecnologias de Ativação do Windows;c:\windows\system32\wat\WatAdminSvc.exe [2011-1-21 1343400]
.
=============== Created Last 30 ================
.
2011-08-05 10:59:00 6881616 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{ff91ea40-3856-4578-93a1-e5e5ef7f5099}\mpengine.dll
2011-08-04 19:26:46 -------- d-----w- c:\users\pedro tenente\.EasyPmd2
2011-07-31 04:50:53 -------- d-----w- c:\users\pedro tenente\appdata\roaming\ProtectDISC
2011-07-31 04:43:03 -------- d-----w- c:\program files\Kalypso
2011-07-28 11:45:07 -------- d-----w- c:\program files\Disciples 3 Renaissance
2011-07-27 21:02:01 -------- d-----w- c:\users\pedro tenente\appdata\local\Native Instruments
2011-07-24 02:46:31 -------- d-----w- c:\users\pedro tenente\appdata\roaming\The Creative Assembly
2011-07-24 02:42:23 21292360 ----a-r- c:\programdata\microsoft\windows\start menu\programs\razor 1911\napoleon total war\Napoleon.exe
2011-07-21 19:42:58 -------- d-----w- c:\users\pedro tenente\appdata\local\Apple Computer
2011-07-21 19:42:13 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-07-21 19:42:01 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-07-21 19:42:01 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-07-21 19:42:01 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-07-21 19:42:01 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-07-21 19:42:01 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-07-21 19:42:01 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-07-21 19:42:01 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-07-21 19:41:34 -------- d-----w- c:\users\pedro tenente\appdata\local\Apple
2011-07-21 05:05:18 -------- d-----w- c:\users\pedro tenente\appdata\roaming\Octoshape
2011-07-20 03:00:20 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-07-20 02:28:57 -------- d-----w- c:\users\pedro tenente\appdata\roaming\Malwarebytes
2011-07-20 02:28:35 -------- d-----w- c:\programdata\Malwarebytes
2011-07-14 05:11:23 -------- d-----w- c:\users\pedro tenente\.jindent
2011-07-11 06:01:35 -------- d-----w- c:\windows\system32\SPReview
2011-07-11 06:01:10 -------- d-----w- c:\windows\system32\EventProviders
.
==================== Find3M ====================
.
2011-07-11 06:06:19 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-07-04 11:43:53 40112 ----a-w- c:\windows\avastSS.scr
2011-07-04 11:36:43 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-04 11:32:20 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-04 04:50:16 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-06-11 02:29:25 2334208 ----a-w- c:\windows\system32\win32k.sys
2011-06-03 05:59:23 290816 ----a-w- c:\windows\system32\KernelBase.dll
2011-06-03 03:48:32 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-06-03 03:48:31 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-06-03 03:48:31 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-06-03 03:48:31 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-05-24 22:14:10 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 10:44:59 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-05-14 06:30:30 169984 ----a-w- c:\windows\system32\winsrv.dll
2011-05-14 06:23:24 271872 ----a-w- c:\windows\system32\conhost.exe
2011-05-11 22:20:20 12920 ----a-w- c:\windows\system32\apl001.sys
2011-05-11 22:20:20 10872 ----a-w- c:\windows\system32\apf001.sys
.
============= FINISH: 14:58:32,29 ===============
Attached File(s)
-
Attach.txt (5.44K)
Number of downloads: 0

Help
This topic is locked

Back to top












