My laptop seem so be infected, it will only run safe mode. When I start it normally error messages apear and also a questionable window asking me to buy a program so the issue can be fixed.
.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.7600.16385
Run by Usuario at 11:02:06 on 2011-10-27
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.55.1046.18.2008.1429 [GMT 1:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.br/
uURLSearchHooks: uTorrentBar_PT Toolbar: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - c:\program files\utorrentbar_pt\prxtbuTo0.dll
mURLSearchHooks: uTorrentBar_PT Toolbar: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - c:\program files\utorrentbar_pt\prxtbuTo0.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: uTorrentBar_PT Toolbar: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - c:\program files\utorrentbar_pt\prxtbuTo0.dll
TB: uTorrentBar_PT Toolbar: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - c:\program files\utorrentbar_pt\prxtbuTo0.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10w_Plugin.exe -update plugin
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [saXsAQWSemKq.exe] c:\programdata\saXsAQWSemKq.exe
StartupFolder: c:\users\usuario\appdata\roaming\micros~1\windows\startm~1\programs\startup\recort~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xportar para o Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{D580A8A5-FC2A-4A98-B3D0-4A8BEF918912} : DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{D580A8A5-FC2A-4A98-B3D0-4A8BEF918912}\0556F607C656 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{D580A8A5-FC2A-4A98-B3D0-4A8BEF918912}\341627562456162734C65726 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D580A8A5-FC2A-4A98-B3D0-4A8BEF918912}\5435359444 : DhcpNameServer = 192.168.2.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\usuario\appdata\roaming\mozilla\firefox\profiles\v9cpvi1e.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2011-9-2 165888]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-13 311296]
S1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-10-15 36000]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_x86_neutral_028821c569ae5894\AEstSrv.exe [2011-9-2 81920]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-10-15 86224]
S2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2011-10-15 110032]
S2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-10-15 74640]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-9-21 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2011-5-13 1492840]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2011-10-25 21:41:40 1517224 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2011-10-25 19:17:51 343440 ---ha-w- c:\programdata\6DSS92c31Apgjk.exe
2011-10-25 19:06:01 433040 ---ha-w- c:\programdata\saXsAQWSemKq.exe
2011-10-25 14:50:07 56200 ---ha-w- c:\programdata\microsoft\windows defender\definition updates\{46ac3845-3525-492f-a9e5-05afe27a962c}\offreg.dll
2011-10-24 19:27:27 -------- d--h--w- c:\program files\VideoLAN
2011-10-24 19:21:16 159744 ---ha-w- c:\program files\mozilla firefox\plugins\npqtplugin6.dll
2011-10-24 19:21:16 159744 ---ha-w- c:\program files\mozilla firefox\plugins\npqtplugin5.dll
2011-10-24 19:21:16 159744 ---ha-w- c:\program files\mozilla firefox\plugins\npqtplugin4.dll
2011-10-24 19:21:16 159744 ---ha-w- c:\program files\mozilla firefox\plugins\npqtplugin3.dll
2011-10-24 19:21:16 159744 ---ha-w- c:\program files\mozilla firefox\plugins\npqtplugin2.dll
2011-10-24 19:21:16 159744 ---ha-w- c:\program files\mozilla firefox\plugins\npqtplugin.dll
2011-10-24 19:21:11 94208 ---ha-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:21:11 69632 ---ha-w- c:\windows\system32\QuickTime.qts
2011-10-24 19:21:11 180224 ---ha-w- c:\windows\system32\QTCF.dll
2011-10-15 21:57:36 -------- d--h--w- c:\users\usuario\appdata\roaming\Avira
2011-10-15 21:56:47 74640 ---ha-w- c:\windows\system32\drivers\avgntflt.sys
2011-10-15 21:56:47 36000 ---ha-w- c:\windows\system32\drivers\avkmgr.sys
2011-10-15 21:56:46 -------- d--h--w- c:\programdata\Avira
2011-10-15 21:56:46 -------- d--h--w- c:\program files\Avira
2011-10-15 15:59:39 -------- d--h--w- c:\program files\common files\Macrovision Shared
2011-10-15 11:29:38 -------- d--h--w- c:\users\usuario\appdata\local\{A5C5AE9F-D506-4E6F-A37E-75B1DD33DFB8}
2011-10-15 11:28:21 -------- d--h--w- c:\users\usuario\appdata\local\{40BD4D21-BE15-45ED-8CCC-8BBD73441240}
2011-10-14 10:49:10 -------- d--h--w- c:\users\usuario\appdata\local\{9C9B8E53-566E-4970-8458-0C025F84FE7B}
2011-10-13 20:52:35 -------- d--h--w- c:\users\usuario\appdata\local\{2C8CC82C-9747-4470-995A-ED93CC2E5462}
2011-10-13 20:52:11 -------- d--h--w- c:\users\usuario\appdata\local\{196D21B5-4BC9-411E-80E1-278C200E8171}
2011-10-13 08:51:38 -------- d--h--w- c:\users\usuario\appdata\local\{3418DF81-676E-4929-BCBA-8E1C12F2981F}
2011-10-13 08:51:20 -------- d--h--w- c:\users\usuario\appdata\local\{5679F964-B8C4-4E76-A142-BF7663634C95}
2011-10-12 11:26:50 -------- d--h--w- c:\users\usuario\appdata\local\{C6CA40C3-2608-4CE1-855C-0610E0DAEC16}
2011-10-12 11:26:30 -------- d--h--w- c:\users\usuario\appdata\local\{A57DD473-DAFB-414A-819E-F277A64EBC08}
2011-10-11 15:34:29 -------- d--h--w- c:\users\usuario\appdata\local\{3D28BC47-F033-4D86-8708-3A11CD744C51}
2011-10-11 15:33:44 -------- d--h--w- c:\users\usuario\appdata\local\{8DD5DB33-DDDC-41C8-B16B-591E231F2F02}
2011-10-11 12:00:47 -------- d--h--w- c:\users\usuario\appdata\local\{58E4610E-A893-472D-82D6-5C68770DBC1A}
2011-10-10 15:47:29 -------- d--h--w- c:\users\usuario\appdata\local\{AA27B5AF-BE00-4897-8E90-D865B8F81D9C}
2011-10-10 15:47:05 -------- d--h--w- c:\users\usuario\appdata\local\{4469E92A-42A4-4C6A-953B-B01E65E87C33}
2011-10-09 15:53:29 -------- d--h--w- c:\program files\Adobe Download Assistant
2011-10-09 11:26:41 -------- d--h--w- c:\users\usuario\appdata\local\{D37F93F0-312D-4705-A8D6-E318888787D0}
2011-10-09 11:26:16 -------- d--h--w- c:\users\usuario\appdata\local\{A92EDB08-BFEB-404D-AD4D-E42ED28ECDE5}
2011-10-08 21:49:23 7269712 ---ha-w- c:\programdata\microsoft\windows defender\definition updates\{46ac3845-3525-492f-a9e5-05afe27a962c}\mpengine.dll
2011-10-08 21:45:25 -------- d--h--w- c:\programdata\AVAST Software
2011-10-08 21:45:25 -------- d--h--w- c:\program files\AVAST Software
2011-10-08 21:39:43 -------- d--h--w- c:\users\usuario\appdata\roaming\Malwarebytes
2011-10-08 21:35:20 -------- d--h--w- c:\programdata\Malwarebytes
2011-10-08 21:35:17 22216 ---ha-w- c:\windows\system32\drivers\mbam.sys
2011-10-08 21:35:17 -------- d--h--w- c:\program files\Malwarebytes' Anti-Malware
2011-10-08 21:07:25 -------- d--h--w- c:\program files\CCleaner
2011-10-08 15:41:30 282624 ---ha-w- c:\program files\common files\installshield\updateservice\agent.exe
2011-10-08 15:40:02 -------- d--h--w- c:\programdata\UDL
2011-10-08 15:37:38 696320 ---ha-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iKernel.dll
2011-10-08 15:37:38 57344 ---ha-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\ctor.dll
2011-10-08 15:37:38 5632 ---ha-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\DotNetInstaller.exe
2011-10-08 15:37:38 32768 ---ha-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2011-10-08 15:37:38 237568 ---ha-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iscript.dll
2011-10-08 15:37:38 155648 ---ha-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iuser.dll
2011-10-08 15:37:37 282756 ---ha-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\setup.dll
2011-10-08 15:37:37 163972 ---ha-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iGdi.dll
2011-10-08 15:34:04 80024 ---ha-w- c:\windows\system32\PICSDK.dll
2011-10-08 15:34:04 501912 ---ha-w- c:\windows\system32\PICSDK2.dll
2011-10-08 15:34:04 120992 ---ha-w- c:\windows\system32\EpPicPrt.dll
2011-10-08 15:34:04 108704 ---ha-w- c:\windows\system32\PICEntry.dll
2011-10-08 15:34:03 71840 ---ha-w- c:\windows\system32\EPPicMgr.dll
2011-10-08 15:30:10 8192 ---ha-w- c:\windows\system32\E_DCINST.DLL
2011-10-08 15:30:04 86528 ---ha-w- c:\windows\system32\E_FLBEFE.DLL
2011-10-08 15:30:01 78848 ---ha-w- c:\windows\system32\E_FD4BEFE.DLL
2011-10-08 15:29:21 -------- d--h--w- c:\programdata\EPSON
2011-10-08 15:28:55 71680 ---ha-w- c:\windows\system32\escwiad.dll
2011-10-08 15:28:54 -------- d--h--w- c:\program files\epson
2011-10-08 10:34:07 -------- d--h--w- c:\users\usuario\appdata\local\{CD83AA54-AA5B-4852-AB6E-DDB90EBB3ECD}
2011-10-08 10:33:54 -------- d--h--w- c:\users\usuario\appdata\local\{1BFF3A33-C536-46B0-B12D-11437701B3C9}
2011-10-07 16:46:48 -------- d--h--w- c:\windows\PAC207
2011-10-07 09:56:41 -------- d--h--w- c:\users\usuario\appdata\local\{813F2038-8995-489C-934C-546B3A84107F}
2011-10-07 09:56:25 -------- d--h--w- c:\users\usuario\appdata\local\{7BC9169D-D12E-464B-9C71-CF292CE3DB10}
2011-10-06 09:03:08 -------- d--h--w- c:\users\usuario\appdata\local\{C67FE23C-1B80-43B3-976D-F124F5A260DC}
2011-10-06 09:02:50 -------- d--h--w- c:\users\usuario\appdata\local\{E45BEDE0-457C-47F7-8BA4-531B5466863E}
2011-10-05 21:02:17 -------- d--h--w- c:\users\usuario\appdata\local\{CFA64C7C-B632-484E-8D53-47C7BB25DE7D}
2011-10-05 21:01:04 -------- d--h--w- c:\users\usuario\appdata\local\{61FFEAE5-72E7-4CD6-B8CC-3CAE98D0ECCC}
2011-10-05 20:30:53 293376 ----a-w- c:\windows\system32\browserchoice.exe
2011-10-05 15:25:08 -------- d--h--w- c:\users\usuario\appdata\local\Spotify
2011-10-05 15:25:05 -------- d--h--w- c:\users\usuario\appdata\roaming\Spotify
2011-10-05 14:45:40 -------- d--h--w- c:\users\usuario\appdata\local\{953F2EFF-B1B9-49B9-AFCE-5ADD703AC167}
2011-10-05 10:58:50 -------- d--h--w- c:\users\usuario\appdata\local\{96FB2576-48C3-45C4-970B-14BE6186520E}
2011-10-04 11:18:45 -------- d--h--w- c:\users\usuario\appdata\local\{900E7791-0DB4-43EC-AB7D-C2BFB8EE7904}
2011-10-02 12:54:24 -------- d--h--w- c:\users\usuario\appdata\local\{67745256-7758-4BD7-A849-E852E769A826}
2011-10-02 12:50:07 -------- d--h--w- c:\users\usuario\appdata\local\{B1A5386E-58DD-42DF-8D69-4A2F88BB7C5E}
2011-10-02 11:50:11 -------- d--h--w- c:\users\usuario\appdata\local\{B88B712E-3CCA-46C1-92D0-AF7D6852C28F}
2011-09-30 09:26:28 -------- d--h--w- c:\users\usuario\appdata\local\{52A31B5C-1F64-4FE4-A402-C9A4D5C389CB}
2011-09-30 09:25:53 -------- d--h--w- c:\users\usuario\appdata\local\{2670F2A9-992B-47F3-92D8-82456AE2A792}
2011-09-30 03:32:01 -------- d--h--w- c:\users\usuario\appdata\local\{A3D70027-CE8D-4E32-A16A-D4442FC9D9B5}
2011-09-30 03:31:36 -------- d--h--w- c:\users\usuario\appdata\local\{2D3FE9D9-885C-4890-BA5C-21AA71766D50}
2011-09-29 13:55:05 -------- d--h--w- c:\users\usuario\appdata\local\{A5A232B8-F490-4557-B164-798BA3F6C5EA}
2011-09-29 13:54:33 -------- d--h--w- c:\users\usuario\appdata\local\{46805252-1561-4C3A-ACD4-4544FA07CFEB}
2011-09-28 16:53:21 -------- d--h--w- c:\users\usuario\appdata\local\{C51F2924-2C91-41B1-B6FD-88BAA005D0C5}
2011-09-28 16:53:03 -------- d--h--w- c:\users\usuario\appdata\local\{6E4F077E-D048-4963-9DDF-BED4E4678F44}
2011-09-28 04:17:36 -------- d--h--w- c:\users\usuario\appdata\local\{7785DC73-5C54-4AA7-877A-892852C931B3}
2011-09-28 04:16:45 -------- d--h--w- c:\users\usuario\appdata\local\{34F0F832-3705-4626-ADA1-CF75E3E79057}
2011-09-27 15:40:52 -------- d--h--w- c:\users\usuario\appdata\local\{64298D18-16B1-4C10-B889-B642DBAAB32F}
2011-09-27 15:40:40 -------- d--h--w- c:\users\usuario\appdata\local\{6A97733F-4B15-43A0-A4DD-D72E763E33B0}
.
==================== Find3M ====================
.
2011-10-01 02:59:14 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-09-14 02:39:15 0 ---ha-w- c:\windows\system32\ConduitEngine.tmp
2011-09-14 02:14:48 520192 ---ha-w- c:\windows\system32\LastFM Motorokr Screensaver.scr
2011-09-06 03:49:48 1227295 ---ha-w- c:\program files\unins000.exe
2011-09-06 02:38:14 2332672 ----a-w- c:\windows\system32\win32k.sys
2011-09-05 17:04:10 404640 ---ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-29 08:00:00 74752 ---ha-w- c:\windows\system32\ff_vfw.dll
2011-08-27 04:43:07 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-08-27 04:43:06 233472 ----a-w- c:\windows\system32\oleacc.dll
2011-08-20 04:38:10 981504 ----a-w- c:\windows\system32\wininet.dll
2011-08-20 04:35:20 44544 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-20 03:26:38 386048 ----a-w- c:\windows\system32\html.iec
2011-08-17 04:26:02 465408 ----a-w- c:\windows\system32\psisdecd.dll
2011-08-17 04:22:23 75776 ----a-w- c:\windows\system32\psisrndr.ax
2011-08-17 04:22:23 72704 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-08-17 04:22:23 59904 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-08-17 04:22:23 204288 ----a-w- c:\windows\system32\MSNP.ax
.
============= FINISH: 11:03:11.67 ===============