this is my first time posting here, thanks in advance for your help.
I keep getting a warning from Avast that it has blocked a harmful url. This happens when I dont even have the internet open. This is what I've done so far. The file source in the warning points to this file, docprop32.exe
I ran Malware bytes(dont have the logs from that)it found some stuff, I deleted and restarted. Didn't work.
I ran eset online scanner, found and eliminated some threats, restarted, didn't work.
I ran avast boot time scan which didnt find squat.
When I get the warning from avast I see this in the source file path docprop32.exe, i researched it and it appears to be some sort of virus.
here's my dds log
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
Run by Dave Edwards at 19:14:48 on 2011-08-21
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.473 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\docprop32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\kbdno32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\wuauclt.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuze.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [PRONoMgr.exe] c:\program files\intel\ncs\proset\PRONoMgr.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\daveed~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1312262014437
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{128B4EFD-0BF8-4D58-8F56-D9CFFF86ACD8} : DhcpNameServer = 192.168.1.1
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\dave edwards\application data\mozilla\firefox\profiles\as0zqmqy.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-8-3 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-8-3 309848]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-8-3 19544]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-8-3 42184]
R2 LmHosts32;TCP/IP NetBIOS Helper ;c:\windows\system32\docprop32.exe [2011-8-20 713728]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-18 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-18 136176]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;c:\windows\system32\drivers\rtl8187b.sys --> c:\windows\system32\drivers\RTL8187B.sys [?]
.
=============== Created Last 30 ================
.
2011-08-21 23:59:32 156160 ----a-w- c:\windows\system32\scriptpw32.dll
2011-08-21 23:58:15 332288 ----a-w- c:\windows\system32\avwav32.dll
2011-08-21 18:56:53 -------- d-----w- c:\program files\ESET
2011-08-21 17:05:50 -------- d-----w- c:\documents and settings\dave edwards\application data\Malwarebytes
2011-08-21 00:35:04 0 ---ha-w- c:\documents and settings\dave edwards\wcbxydoywl.tmp
2011-08-20 21:10:45 713728 ----a-w- c:\windows\system32\kbdno32.exe
2011-08-20 21:10:40 713728 ----a-w- c:\windows\system32\docprop32.exe
2011-08-19 02:22:39 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-08-19 02:22:38 1974616 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-08-19 02:22:38 1892184 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-08-16 02:03:26 -------- d-----w- c:\program files\SubmitEaze
2011-08-15 00:12:28 -------- d-----w- c:\documents and settings\dave edwards\local settings\application data\Google
2011-08-14 16:40:50 -------- d-----w- c:\program files\IrfanView
2011-08-11 01:28:13 -------- d-----w- C:\xampp
2011-08-10 05:26:41 -------- d-----w- c:\documents and settings\dave edwards\.ranktracker
2011-08-10 02:44:04 -------- d-----w- c:\program files\common files\Adobe Systems Shared
2011-08-09 04:13:11 -------- d-----w- c:\documents and settings\dave edwards\.seospyglass
2011-08-09 04:11:21 -------- d-----w- c:\program files\SEO PowerSuite
2011-08-09 04:11:16 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-08-09 04:11:16 410984 ----a-w- c:\windows\system32\deploytk.dll
2011-08-09 03:31:29 -------- d-----w- c:\documents and settings\dave edwards\application data\MSNInstaller
2011-08-08 04:34:38 -------- d-----w- c:\documents and settings\dave edwards\local settings\application data\Identities
2011-08-06 22:19:46 -------- d-----w- c:\documents and settings\dave edwards\local settings\application data\Adobe
2011-08-05 05:01:42 -------- d-----w- c:\program files\MSXML 6.0
2011-08-05 01:49:57 -------- d--h--w- c:\windows\PIF
2011-08-04 13:23:51 -------- d-----w- c:\windows\ServicePackFiles
2011-08-04 12:37:57 -------- d-----w- c:\documents and settings\dave edwards\application data\Azureus
2011-08-04 12:35:41 -------- d-----w- c:\program files\Vuze
2011-08-04 12:35:35 -------- d-----w- c:\program files\Conduit
2011-08-04 12:35:35 -------- d-----w- c:\documents and settings\dave edwards\local settings\application data\Vuze_Remote
2011-08-04 12:35:33 -------- d-----w- c:\program files\ConduitEngine
2011-08-04 12:35:33 -------- d-----w- c:\documents and settings\dave edwards\local settings\application data\ConduitEngine
2011-08-04 12:35:30 -------- d-----w- c:\program files\Vuze_Remote
2011-08-04 12:35:30 -------- d-----w- c:\documents and settings\dave edwards\local settings\application data\Temp
2011-08-04 12:35:30 -------- d-----w- c:\documents and settings\dave edwards\local settings\application data\Conduit
2011-08-04 12:34:51 -------- d-----w- c:\windows\system32\CatRoot_bak
2011-08-04 12:31:47 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2011-08-04 12:31:47 272128 ------w- c:\windows\system32\drivers\bthport.sys
2011-08-04 12:31:27 454016 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-08-04 12:30:48 2137088 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-08-04 12:30:47 2181376 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-08-04 12:30:47 2058368 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2011-08-04 12:30:47 2016768 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-08-04 03:46:10 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-04 03:42:21 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-08-04 03:42:08 40112 ----a-w- c:\windows\avastSS.scr
2011-08-04 03:41:58 -------- d-----w- c:\program files\AVAST Software
2011-08-04 03:41:58 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2011-08-04 03:34:33 102400 ----a-r- c:\windows\system32\drivers\ianswxp.sys
2011-08-04 03:34:05 24064 ----a-r- c:\windows\system32\IntelNic.dll
2011-08-04 03:34:05 145408 -c--a-w- c:\windows\system32\dllcache\e100b325.sys
2011-08-04 03:34:05 145408 ----a-r- c:\windows\system32\drivers\e100b325.sys
2011-08-04 03:34:05 12288 ----a-r- c:\windows\system32\e100bmsg.dll
2011-08-04 03:34:05 118784 ----a-r- c:\windows\system32\Prounstl.exe
2011-08-04 03:31:46 -------- d-----w- c:\windows\system32\ReinstallBackups
2011-08-04 03:31:41 77824 ------w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2011-08-04 03:31:41 32768 ------w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2011-08-04 03:31:41 221184 ------w- c:\program files\common files\installshield\iscript\iscript.dll
2011-08-04 03:31:41 221184 ------w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2011-08-04 03:31:40 602244 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2011-08-04 01:25:57 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2011-08-04 01:25:57 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2011-08-04 01:25:54 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2011-08-04 01:25:54 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-08-04 01:25:47 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2011-08-04 01:25:47 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2011-08-03 18:18:36 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-03 18:18:35 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-08-03 18:18:32 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-03 18:18:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-03 18:15:44 -------- d-----w- c:\program files\CCleaner
2011-08-03 16:34:20 18944 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
2011-08-03 16:34:20 17920 ----a-w- c:\windows\system32\mdimon.dll
2011-08-03 16:33:34 -------- d-----w- c:\program files\common files\L&H
2011-08-03 16:33:21 -------- d-----w- c:\program files\Microsoft ActiveSync
2011-08-03 16:32:40 -------- d-----w- c:\windows\SHELLNEW
2011-08-02 06:40:56 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2011-08-02 06:40:56 -------- d-----w- c:\windows\system32\PreInstall
2011-08-02 06:40:55 -------- d--h--w- c:\windows\$hf_mig$
2011-08-02 06:39:21 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
2011-08-02 06:39:21 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
2011-08-02 06:39:21 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2011-08-02 06:39:21 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2011-08-02 06:39:21 -------- d-----w- c:\windows\system32\SoftwareDistribution
.
==================== Find3M ====================
.
2011-08-04 04:56:24 376832 ----a-w- c:\windows\system32\AegisI5Installer.exe
.
============= FINISH: 19:19:41.23 ===============
Attached File(s)
-
attach.txt (7.08K)
Number of downloads: 0

Help
This topic is locked

Back to top









