Sorry for being so late, I was out for christmas.
DDS:
DDS (Ver_09-12-01.01) - NTFSx86
Run by Magazine Alberto at 15:34:08,04 on seg 28/12/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.623.414 [GMT -2:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\SnAgOS.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\SnMgrSvc.exe
C:\WINDOWS\system32\SnLiveUp.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\csrcs.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SnEngine.EXE
C:\Documents and Settings\Magazine Alberto\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com.br/
mWinlogon: Shell=Explorer.exe csrcs.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\arquivos de programas\arquivos comuns\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\arquivos de programas\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\arquivos de programas\arquivos comuns\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\arquivos de programas\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\arquivos de programas\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\arquivos de programas\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\arquivos de programas\windows live\messenger\MsnMsgr.Exe" /background
mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
mRun: [SunJavaUpdateSched] "c:\arquivos de programas\java\jre6\bin\jusched.exe"
mRun: [VTPreset] VTPreset.exe
mRun: [Adobe Reader Speed Launcher] "c:\arquivos de programas\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\arquivos de programas\arquivos comuns\adobe\arm\1.0\AdobeARM.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRunServices: [csrcs] c:\windows\system32\csrcs.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
mExplorerRun: [csrcs] c:\windows\system32\csrcs.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\arquivos de programas\messenger\msmsgs.exe
DPF: {3C8B9651-4E3E-424D-B51C-54544ABF536B} - hxxps://ww7.banrisul.com.br/bxz/data/securecontrol2k.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
TCP: {BC6D6018-BDED-4BEB-AE0F-AA2D97A41595} = 189.7.136.15,189.7.136.16
Hosts: 127.0.0.1
www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\magazi~1\dadosd~1\mozilla\firefox\profiles\3s54hwtz.default\
FF - prefs.js: browser.search.selectedEngine - O Vermelhinho - Farroupilha
FF - plugin: c:\arquivos de programas\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\arquivos de programas\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\arquivos de programas\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\arquivos de programas\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
============= SERVICES / DRIVERS ===============
R1 SNSID;SNSID;c:\windows\system32\drivers\SNSID.SYS [2009-10-28 22272]
R1 SNSMS;SNSMS;c:\windows\system32\drivers\SNSMS.SYS [2009-10-28 34440]
R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2009-10-28 12672]
R2 Ps2KSecureKeyboard;SecureKbd;c:\windows\system32\drivers\psseckbd.sys [2009-10-28 15048]
R2 SNMgrSvc;SNMgrSvc;c:\windows\system32\SnMgrSvc.exe [2009-10-28 280712]
S2 Iasagent;Center Microsoft;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
=============== Created Last 30 ================
2009-12-28 10:57:00 186504 ----a-w- c:\windows\system32\SnAgOS.TMP
2009-12-24 19:37:48 0 d--h--w- c:\windows\PIF
2009-12-22 11:18:07 0 d-----w- c:\documents and settings\magazine alberto\Tracing
2009-12-21 15:51:30 0 d-----w- c:\docume~1\magazi~1\dadosd~1\AVG8
2009-12-12 10:46:18 0 --sha-r- C:\khw
2009-12-02 17:28:43 25 ----a-w- c:\windows\popcinfot.dat
2009-12-02 17:04:10 0 --sha-r- C:\khv
2009-12-02 16:58:44 0 d-----w- c:\docume~1\alluse~1\dadosd~1\PopCap Games
==================== Find3M ====================
2009-12-06 13:15:45 48846 ----a-w- c:\windows\system32\perfc016.dat
2009-12-06 13:15:45 344734 ----a-w- c:\windows\system32\perfh016.dat
2001-11-23 04:08:20 712704 -c--a-r- c:\windows\inf\other\AUDIO3D.DLL
2008-04-13 10:45:14 892730 --sha-r- c:\windows\system32\csrcs.exe
============= FINISH: 15:35:16,68 ===============
I couldn't download GMER either... page not found as always, but I brought it in here from another computer. I tried 3 times, computer will always reboot during scanning.