Nice this is still open. I had some irl problems and I can't came here to say this, sorry about that.
There's the logs:
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.07.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Konishi :: KONISHI-PC [administrator]
07/08/2012 12:37:05
mbam-log-2012-08-07 (12-37-05).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 193475
Time elapsed: 2 minute(s), 41 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
C:\Recycle.Bin (Trojan.Spyeyes) -> Quarantined and deleted successfully.
Files Detected: 1
C:\Recycle.Bin\C39B1064484C84B (Trojan.Spyeyes) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-08-07 12:59:45
Windows 6.1.7601 Service Pack 1
Running: y32o59b4.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC3 0x0E 0x0B 0x11 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xFC 0x6A 0x76 0xB3 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x7B 0x02 0xF3 0xC7 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x21 0x96 0xC6 0x76 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC3 0x0E 0x0B 0x11 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xFC 0x6A 0x76 0xB3 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x7B 0x02 0xF3 0xC7 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x21 0x96 0xC6 0x76 ...
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.4.1
Run by Konishi at 13:02:06 on 2012-08-07
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.55.1046.18.4095.2454 [GMT -3:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Proxy Labs\ProxyCap\pcapsvc.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Proxy Labs\ProxyCap\pcapui.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\AhnLab\ASP\Components\ASPLnchr.exe
C:\Windows\system32\taskhost.exe
C:\Users\Konishi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Konishi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Konishi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Konishi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Konishi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Konishi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Konishi\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://df.nexon.com/
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Auxiliar de Conexão do Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
uRun: [Google Update] "C:\Users\Konishi\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
LSP: pcapwsp.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{5F5BC493-072E-49C4-AC1F-266A9244ED4E} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{8ED7000D-53F7-4487-8809-5B511BFF5EEC} : DhcpNameServer = 7.254.254.254
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: ecojink - C:\Windows\system32\config\systemprofile\AppData\Local\ecojink.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
{9030D464-4C02-4ABF-8ECC-5164760863C6}
{DBC80044-A445-435b-BC74-9C25C1C588A9}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRunOnce-x64: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Konishi\AppData\Roaming\Mozilla\Firefox\Profiles\f8n672gz.default\
FF - prefs.js: browser.startup.homepage -
www.google.com
FF - prefs.js: keyword.URL - hxxp://
www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\AhnLab\ASP\Components\aosmgr\conflict_475\npaosmgr.dll
FF - plugin: C:\Program Files (x86)\AhnLab\ASP\MyKeyDefense 2.5\npmkd25sp.dll
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\NeoplePlugin\npNeopleGameInstaller.dll
FF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
FF - plugin: C:\Users\Konishi\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-8-7 44808]
R2 pcapsvc;ProxyCap Service;C:\Program Files\Proxy Labs\ProxyCap\pcapsvc.exe [2010-9-18 635904]
R3 amdiox64;AMD IO Driver;C:\Windows\system32\DRIVERS\amdiox64.sys --> C:\Windows\system32\DRIVERS\amdiox64.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);C:\Windows\system32\DRIVERS\tap0901t.sys --> C:\Windows\system32\DRIVERS\tap0901t.sys [?]
S2 biafagiz;i8042 Keyboard and PS/2 Mouse Port Helper;C:\Windows\System32\svchost.exe -k netsvcs [2009-7-13 20992]
S3 dfmirage;dfmirage;C:\Windows\system32\DRIVERS\dfmirage.sys --> C:\Windows\system32\DRIVERS\dfmirage.sys [?]
S3 Mkd2Bthf;Mkd2Bthf;C:\Windows\system32\drivers\Mkd2Bthf.sys --> C:\Windows\system32\drivers\Mkd2Bthf.sys [?]
S3 Mkd2Nadr;Mkd2Nadr;C:\Windows\system32\drivers\Mkd2Nadr.sys --> C:\Windows\system32\drivers\Mkd2Nadr.sys [?]
S3 Mkd3kfNt;Mkd3kfNt;C:\Windows\system32\drivers\Mkd3kfNt.sys --> C:\Windows\system32\drivers\Mkd3kfNt.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-11 113120]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TunngleService;TunngleService;C:\Program Files (x86)\Tunngle\TnglCtrl.exe [2012-5-30 736104]
S3 WatAdminSvc;Serviço de Tecnologias de Ativação do Windows;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
S4 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-4-5 361984]
.
=============== Created Last 30 ================
.
2012-08-07 15:19:2324904----a-w-C:\Windows\System32\drivers\mbam.sys
2012-08-07 15:19:23--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-07 15:06:4154072----a-w-C:\Windows\System32\drivers\aswRdr2.sys
2012-08-07 15:06:34958400----a-w-C:\Windows\System32\drivers\aswSnx.sys
2012-08-07 15:06:3271064----a-w-C:\Windows\System32\drivers\aswMonFlt.sys
2012-08-07 15:06:1641224----a-w-C:\Windows\avastSS.scr
2012-08-07 10:28:57--------d-----w-C:\Users\Konishi\AppData\Local\{DDAB8DFE-D797-4143-9A7B-08A28850DD1A}
2012-08-07 10:28:46--------d-----w-C:\Users\Konishi\AppData\Local\{89D32F03-EC65-4C5D-9270-57A942200E5C}
2012-08-06 22:28:21--------d-----w-C:\Users\Konishi\AppData\Local\{C6FC6125-CC8B-41AF-9F21-77694EEF98C5}
2012-08-06 22:28:11--------d-----w-C:\Users\Konishi\AppData\Local\{50639813-FDCA-422E-9D4E-5B7F634BE863}
2012-08-06 21:04:48282696----a-w-C:\Windows\SysWow64\PnkBstrB.exe
2012-08-06 21:04:48282696----a-w-C:\Windows\SysWow64\PnkBstrB.ex0
2012-08-06 21:04:3976888----a-w-C:\Windows\SysWow64\PnkBstrA.exe
2012-08-06 10:27:45--------d-----w-C:\Users\Konishi\AppData\Local\{915CB4AC-772A-4631-A2D1-7A1F08216C81}
2012-08-06 10:27:35--------d-----w-C:\Users\Konishi\AppData\Local\{82974E9C-0B77-4C2C-BAB9-5C3C27554F08}
2012-08-05 16:13:32--------d-----w-C:\Users\Konishi\AppData\Local\{44027318-F02F-412D-8E5E-ABED25A7D9B0}
2012-08-05 16:13:21--------d-----w-C:\Users\Konishi\AppData\Local\{AB468F21-D63C-44DA-B751-FDF8EDB6089A}
2012-08-05 04:12:55--------d-----w-C:\Users\Konishi\AppData\Local\{9540F04C-6C4C-4550-8728-01947DE9C727}
2012-08-05 04:12:43--------d-----w-C:\Users\Konishi\AppData\Local\{4D686B43-D2BF-4BAF-86AC-06179265BFCC}
2012-08-04 10:23:12--------d-----w-C:\Users\Konishi\AppData\Local\{06744DB6-1E5A-4D96-94A7-67570B250146}
2012-08-04 10:23:02--------d-----w-C:\Users\Konishi\AppData\Local\{DFC53409-AD47-4C25-A671-864BE283B44C}
2012-08-03 22:22:49--------d-----w-C:\Users\Konishi\AppData\Local\{2A85ECEA-4C0D-4A38-AF62-50B43CDA9152}
2012-08-03 22:22:39--------d-----w-C:\Users\Konishi\AppData\Local\{FA31A21E-4E20-45B4-A87D-8C210D8F43DD}
2012-08-03 10:22:14--------d-----w-C:\Users\Konishi\AppData\Local\{A5593731-9E52-4C9E-B143-3C78476BA590}
2012-08-03 10:22:03--------d-----w-C:\Users\Konishi\AppData\Local\{0F6B97CA-D2D3-4067-B442-0190D3B88270}
2012-08-02 22:21:38--------d-----w-C:\Users\Konishi\AppData\Local\{8C2B1CDF-E525-4C73-A5D3-A2328956810A}
2012-08-02 22:21:28--------d-----w-C:\Users\Konishi\AppData\Local\{E6D838D5-0513-489C-BD1F-37194F329AA7}
2012-08-02 10:21:02--------d-----w-C:\Users\Konishi\AppData\Local\{9FADF3C2-B1CD-46D2-8F1D-67B17E37829C}
2012-08-02 10:20:51--------d-----w-C:\Users\Konishi\AppData\Local\{0BD4AC85-6482-44AF-8B39-EDE8B22A9332}
2012-08-02 03:53:49--------d-----w-C:\ProgramData\AVAST Software
2012-08-02 03:53:49--------d-----w-C:\Program Files\AVAST Software
2012-08-02 02:16:19--------d-----w-C:\Program Files (x86)\Trend Micro
2012-08-01 17:58:23--------d-----w-C:\Users\Konishi\AppData\Local\{037224F5-AC2B-40B6-A0DC-3F49CCB4F7B7}
2012-08-01 17:58:02--------d-----w-C:\Users\Konishi\AppData\Local\{54F08CFD-F453-45BA-9BC2-31A6D40D3656}
2012-08-01 05:57:37--------d-----w-C:\Users\Konishi\AppData\Local\{FF6C2500-6C2C-4E26-959D-A6D0BE146880}
2012-08-01 05:57:16--------d-----w-C:\Users\Konishi\AppData\Local\{F5706F72-3AFF-47E3-9C7B-ED3EC531B279}
2012-07-31 17:56:51--------d-----w-C:\Users\Konishi\AppData\Local\{79805088-1A99-467C-B769-EBF15CA5223A}
2012-07-31 17:56:29--------d-----w-C:\Users\Konishi\AppData\Local\{0D3E7946-8FAC-4F17-9A0E-799E4D542997}
2012-07-31 05:56:04--------d-----w-C:\Users\Konishi\AppData\Local\{065C4005-83B3-42D1-A9C0-0E0B60A2F0D1}
2012-07-31 05:55:42--------d-----w-C:\Users\Konishi\AppData\Local\{AF4A910A-072C-40C2-9FF9-B28CB9D44F4C}
2012-07-30 17:55:17--------d-----w-C:\Users\Konishi\AppData\Local\{E8EEEFB2-E0CA-4CC0-B37F-2A280281E788}
2012-07-30 17:55:04--------d-----w-C:\Users\Konishi\AppData\Local\{E1379EE4-BD46-4531-B54F-F24F73F960E2}
2012-07-30 03:29:51--------d-----w-C:\Users\Konishi\AppData\Local\{070F2390-5CAC-44E9-A7BC-E82F0330DFF3}
2012-07-30 03:29:30--------d-----w-C:\Users\Konishi\AppData\Local\{0A3AB5C8-3793-48DA-A13A-AB87B7082A4D}
2012-07-29 12:42:46--------d-----w-C:\Users\Konishi\AppData\Local\{27D8BA45-3A5E-4D00-95C1-8832680C62A8}
2012-07-29 12:42:25--------d-----w-C:\Users\Konishi\AppData\Local\{D3DFDF53-8335-4355-9532-8C6A3A755347}
2012-07-29 00:42:03--------d-----w-C:\Users\Konishi\AppData\Local\{483DD499-9867-41D4-A067-22220DE5C50B}
2012-07-29 00:41:51--------d-----w-C:\Users\Konishi\AppData\Local\{213E5C6E-6363-48A2-9C3C-DDFB20C377D0}
2012-07-28 04:04:25--------d-----w-C:\Users\Konishi\AppData\Local\{8F2511B1-C3D8-4436-8C69-9F85C65156EB}
2012-07-28 04:04:04--------d-----w-C:\Users\Konishi\AppData\Local\{0B0352C5-8C7E-4696-AC39-B0CFD1812A74}
2012-07-27 16:03:51--------d-----w-C:\Users\Konishi\AppData\Local\{6E04364B-E41D-4FAF-B4BF-42BC5F72B55C}
2012-07-27 16:03:40--------d-----w-C:\Users\Konishi\AppData\Local\{4B68C8FA-C3EF-4CF7-AA72-FBD4A65E3002}
2012-07-26 22:51:00--------d-----w-C:\Users\Konishi\AppData\Local\{7FD8FA30-62E2-40EB-9CE8-D400B8A554A9}
2012-07-26 22:50:39--------d-----w-C:\Users\Konishi\AppData\Local\{AA46BE7F-5E43-46B8-86F9-19F591BBE827}
2012-07-26 10:50:14--------d-----w-C:\Users\Konishi\AppData\Local\{902C9946-2144-492C-8BD8-395754D3FD0D}
2012-07-26 10:49:52--------d-----w-C:\Users\Konishi\AppData\Local\{E10489BC-24EA-4709-BDE0-462F887AD25A}
2012-07-25 22:49:40--------d-----w-C:\Users\Konishi\AppData\Local\{06CBF655-D695-4891-805D-AD44AD819D11}
2012-07-25 22:49:18--------d-----w-C:\Users\Konishi\AppData\Local\{61B1B9E2-2870-4E66-B9DF-1FA9FB0BF88E}
2012-07-25 10:48:53--------d-----w-C:\Users\Konishi\AppData\Local\{BE867590-7513-4177-B87B-A6D81ABE6CC2}
2012-07-25 10:48:42--------d-----w-C:\Users\Konishi\AppData\Local\{79598CC6-0529-4DCC-9F42-C73BD90FEF67}
2012-07-25 04:10:10--------d-----w-C:\ProgramData\paltiosoft
2012-07-25 00:43:33--------d-----w-C:\Users\Konishi\AppData\Roaming\Nitroplus
2012-07-24 21:38:14--------d-----w-C:\Users\Konishi\AppData\Local\{C8D2E07C-89E7-44F9-8FA5-C95629DDBA5A}
2012-07-24 21:37:40--------d-----w-C:\Users\Konishi\AppData\Local\{6F9D773F-27D5-4C0E-BEEF-2C6398A42FF2}
2012-07-24 09:37:14--------d-----w-C:\Users\Konishi\AppData\Local\{A696F734-A8F1-4408-97F0-D4CA8073D915}
2012-07-24 09:37:03--------d-----w-C:\Users\Konishi\AppData\Local\{7C3937D5-FD69-483A-B36C-D05B610893C8}
2012-07-24 04:20:01--------d-----w-C:\Users\Konishi\AppData\Local\{352208B4-E62C-40C2-92B8-EAFCF69BBE96}
2012-07-23 21:36:51--------d-----w-C:\Users\Konishi\AppData\Local\{9C370723-9165-4327-8C87-16EB7B1265A2}
2012-07-23 21:36:30--------d-----w-C:\Users\Konishi\AppData\Local\{2D95926B-86FD-4A54-AEE3-092029022B37}
2012-07-23 09:36:02--------d-----w-C:\Users\Konishi\AppData\Local\{6C467B33-93E6-4C88-8BF5-B43AC952B20E}
2012-07-23 09:35:25--------d-----w-C:\Users\Konishi\AppData\Local\{36AC4CE2-5620-46AB-ABF1-015111EA5889}
2012-07-23 05:55:04--------d-----w-C:\Users\Konishi\AppData\Local\Chromium
2012-07-23 02:22:00--------d-----w-C:\Program Files (x86)\Rockstar Games
2012-07-23 02:21:18--------d-----w-C:\ProgramData\Rockstar Games
2012-07-22 21:35:13--------d-----w-C:\Users\Konishi\AppData\Local\{091B0562-0505-4C23-ABDA-D89A286C870A}
2012-07-22 21:34:52--------d-----w-C:\Users\Konishi\AppData\Local\{6E347045-CDE7-4522-956C-25BFCFE4600B}
2012-07-22 09:34:15--------d-----w-C:\Users\Konishi\AppData\Local\{B075590A-6E23-48EE-AB4B-4AFA2D542651}
2012-07-22 09:34:04--------d-----w-C:\Users\Konishi\AppData\Local\{E749BC87-F691-4FFA-A749-0031D37C2742}
2012-07-21 21:33:38--------d-----w-C:\Users\Konishi\AppData\Local\{012A229B-0F37-4E7F-BF04-2DA563F1AF59}
2012-07-21 21:33:20--------d-----w-C:\Users\Konishi\AppData\Local\{9B9EFBA8-92F6-4A00-8319-5279A3E79462}
2012-07-21 03:46:28--------d-----w-C:\Users\Konishi\AppData\Local\{BACCCE7C-1683-40D9-8476-162297AA2826}
2012-07-21 03:46:17--------d-----w-C:\Users\Konishi\AppData\Local\{D6A2076A-A44B-4C09-8B90-7256E93E673F}
2012-07-20 15:45:52--------d-----w-C:\Users\Konishi\AppData\Local\{64A46553-CA78-4F9D-9FA7-D2B60BF87038}
2012-07-20 15:45:31--------d-----w-C:\Users\Konishi\AppData\Local\{5C9E36D5-E8EB-4F7B-805C-37E55BA17954}
2012-07-19 20:49:21--------d-----w-C:\Users\Konishi\AppData\Local\{01946584-8002-4F7F-BAD2-59E90D73CA5B}
2012-07-19 20:49:00--------d-----w-C:\Users\Konishi\AppData\Local\{81BEB27F-C258-4583-A9EE-80DA0C34CF86}
2012-07-19 10:20:11--------d-----w-C:\Program Files (x86)\DNF
2012-07-19 08:48:34--------d-----w-C:\Users\Konishi\AppData\Local\{0B3A594A-45B7-4B01-9687-D4D7C4011070}
2012-07-19 08:48:12--------d-----w-C:\Users\Konishi\AppData\Local\{F9546997-9B96-44CF-BC25-533445F1F5EC}
2012-07-19 08:10:31166792----a-w-C:\Windows\System32\drivers\klb64mkd.sys
2012-07-19 02:56:1233856---ha-w-C:\Windows\System32\hamachi.sys
2012-07-18 22:34:14--------d-----w-C:\Users\Konishi\AppData\Local\LogMeIn Hamachi
2012-07-18 20:47:45--------d-----w-C:\Users\Konishi\AppData\Local\{2407B77D-8097-4EB6-A7FE-277E75B9626B}
2012-07-18 20:47:30--------d-----w-C:\Users\Konishi\AppData\Local\{D21665B5-6C3F-4001-8793-E9572D84601F}
2012-07-18 07:40:15--------d-----w-C:\Users\Konishi\AppData\Local\{F00731E3-653A-481E-8999-A9548CD4AF0C}
2012-07-18 07:40:04--------d-----w-C:\Users\Konishi\AppData\Local\{DB0BBB04-41DC-42EB-84BC-0D57E08CF317}
2012-07-17 19:39:52--------d-----w-C:\Users\Konishi\AppData\Local\{91A3C3E6-E91A-46F2-AD99-672165698C09}
2012-07-17 19:39:41--------d-----w-C:\Users\Konishi\AppData\Local\{7ED39633-F0D3-4655-BB82-27D62A7ED1E4}
2012-07-16 19:09:02--------d-----w-C:\Users\Konishi\AppData\Local\{F8FD8ACA-5567-4155-8B14-9EA41FF8B548}
2012-07-16 19:08:51--------d-----w-C:\Users\Konishi\AppData\Local\{08C644F6-BC6A-4D58-91DD-A110A02370FD}
2012-07-16 07:08:26--------d-----w-C:\Users\Konishi\AppData\Local\{EA1C03A5-0F68-4802-A146-72E71123A825}
2012-07-16 07:08:14--------d-----w-C:\Users\Konishi\AppData\Local\{9F857AB5-A206-4B25-9468-4E16932FA8D7}
2012-07-15 19:07:49--------d-----w-C:\Users\Konishi\AppData\Local\{EE28E46D-78FC-487D-B3FD-57722BEF62B2}
2012-07-15 19:07:38--------d-----w-C:\Users\Konishi\AppData\Local\{C11998EC-E0DF-44C1-B15E-1BBC9E1C4A8A}
2012-07-15 06:02:03--------d-----w-C:\Users\Konishi\AppData\Local\{63786BE3-FFDA-45C3-819E-447E9749C9A0}
2012-07-15 06:01:50--------d-----w-C:\Users\Konishi\AppData\Local\{5D8FBEC3-5ACB-4BDB-8436-5A17651267EB}
2012-07-14 15:07:10--------d-----w-C:\Users\Konishi\AppData\Local\{57D91C13-3E1C-4B6B-B79C-DE0DC941ABD4}
2012-07-14 15:06:55--------d-----w-C:\Users\Konishi\AppData\Local\{56F37B71-0671-4F88-BB3A-1FF48D4C2835}
2012-07-14 00:41:00282696----a-w-C:\Windows\SysWow64\PnkBstrB.xtr
2012-07-14 00:12:38--------d-----w-C:\Users\Konishi\AppData\Local\Ubisoft Game Launcher
2012-07-13 22:50:29--------d-----w-C:\Users\Konishi\AppData\Roaming\Ubisoft
2012-07-13 20:12:34--------d-----w-C:\Users\Konishi\AppData\Local\{47907010-0885-4ECC-85F9-DF20AF9E7865}
2012-07-13 20:12:24--------d-----w-C:\Users\Konishi\AppData\Local\{E7634445-1DB6-42C8-96AC-821FE3B14732}
2012-07-13 08:11:59--------d-----w-C:\Users\Konishi\AppData\Local\{B467AD3C-BE9C-4417-A414-06558F976C7D}
2012-07-13 08:11:49--------d-----w-C:\Users\Konishi\AppData\Local\{39B6A384-1F0B-439B-98D1-71C1984DE318}
2012-07-12 20:11:24--------d-----w-C:\Users\Konishi\AppData\Local\{A1B12D24-510C-4251-BCB1-1E86D7AF6D2F}
2012-07-12 20:11:14--------d-----w-C:\Users\Konishi\AppData\Local\{15C386E8-C787-4DD8-8B3C-5690BADFB384}
2012-07-12 08:10:49--------d-----w-C:\Users\Konishi\AppData\Local\{3363AA38-E36E-49E9-8371-5948808BAE5F}
2012-07-12 08:10:38--------d-----w-C:\Users\Konishi\AppData\Local\{6146E002-2683-4548-A033-F072D6F30A1E}
2012-07-11 20:10:14--------d-----w-C:\Users\Konishi\AppData\Local\{FB947022-84E5-4322-B392-1EE32A26CAB7}
2012-07-11 20:10:04--------d-----w-C:\Users\Konishi\AppData\Local\{49106DC8-2CD6-49A7-9B76-E9A1ADF96B81}
2012-07-11 08:09:39--------d-----w-C:\Users\Konishi\AppData\Local\{FCC90C99-26FA-4047-A4DA-47AD7644726C}
2012-07-11 08:09:29--------d-----w-C:\Users\Konishi\AppData\Local\{9085ECEB-291F-4881-9A68-80A3DD0200C9}
2012-07-10 19:59:38--------d-----w-C:\Users\Konishi\AppData\Local\{A1554DC2-4EB3-4BA9-B203-8DE89C1819B6}
2012-07-10 19:59:23--------d-----w-C:\Users\Konishi\AppData\Local\{BA9772F2-EA94-44D2-AA18-0F331DF1FD50}
2012-07-10 07:33:48--------d-----w-C:\Users\Konishi\AppData\Local\{C8C92395-BA01-477F-8D16-4843485E8BCB}
2012-07-10 07:33:38--------d-----w-C:\Users\Konishi\AppData\Local\{0378E9A7-D70F-4D1B-87EA-697B22A79062}
2012-07-09 19:33:11--------d-----w-C:\Users\Konishi\AppData\Local\{0471EA36-EC0A-4B2C-8BC1-7287EDF6DAE2}
2012-07-09 19:33:01--------d-----w-C:\Users\Konishi\AppData\Local\{24E64E74-473F-4B8F-930D-4246856A0C75}
2012-07-09 05:54:00--------d-----w-C:\Users\Konishi\AppData\Local\{6872E242-D94F-43A6-B895-43ED5CAA0B3D}
2012-07-09 05:53:50--------d-----w-C:\Users\Konishi\AppData\Local\{6366BDBE-A77B-4750-A040-A6F2D60B450F}
2012-07-08 17:53:36--------d-----w-C:\Users\Konishi\AppData\Local\{346E7A91-6395-4470-BA02-1306071B87EE}
2012-07-08 17:53:25--------d-----w-C:\Users\Konishi\AppData\Local\{BE011508-3C10-48A0-8BDE-38220B51DAA0}
.
==================== Find3M ====================
.
2012-07-08 04:28:50560184----a-w-C:\Windows\System32\drivers\sptd.sys
2012-06-20 15:28:034145600----a-w-C:\Windows\SysWow64\GameMon.des
2012-05-18 03:03:04772552----a-w-C:\Windows\SysWow64\npDeployJava1.dll
2012-05-14 19:46:0111174400----a-w-C:\Windows\System32\drivers\atikmdag.sys
2012-05-14 19:44:59503808----a-w-C:\Windows\System32\atieclxx.exe
2012-05-14 19:44:5644544----a-w-C:\Windows\System32\atiu9p64.dll
2012-05-14 19:44:5521504----a-w-C:\Windows\System32\atimuixx.dll
2012-05-14 19:44:52159744----a-w-C:\Windows\System32\atiapfxx.exe
2012-05-14 19:44:5195760----a-w-C:\Windows\System32\drivers\AtihdW76.sys
2012-05-14 19:44:5144032----a-w-C:\Windows\SysWow64\aticalcl.dll
2012-05-14 19:44:5141984----a-w-C:\Windows\SysWow64\atiuxpag.dll
2012-05-14 19:44:4959392----a-w-C:\Windows\System32\atiedu64.dll
2012-05-14 19:44:49514560----a-w-C:\Windows\System32\atiadlxx.dll
2012-05-13 10:06:3670304----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-13 10:06:36419488----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
.
============= FINISH: 13:02:40,37 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 13/02/2012 20:10:21
System Uptime: 07/08/2012 12:15:30 (1 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | M4A785TD-V EVO
Processor: AMD Athlon(tm) II X4 620 Processor | AM3 | 2600/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 397 GiB total, 101,745 GiB free.
D: is FIXED (NTFS) - 37 GiB total, 25,314 GiB free.
E: is FIXED (NTFS) - 68 GiB total, 37,146 GiB free.
F: is CDROM ()
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e968-e325-11ce-bfc1-08002be10318}
Description: Mirage Driver
Device ID: ROOT\DISPLAY\0000
Manufacturer: DemoForge
Name: Mirage Driver
PNP Device ID: ROOT\DISPLAY\0000
Service: dfmirage
.
==== System Restore Points ===================
.
RP163: 02/08/2012 11:49:26 - ComboFix created restore point
RP164: 07/08/2012 12:05:46 - Configuração do(a) avast! Free Antivirus
.
==== Installed Programs ======================
.
??????
AhnLab Online Security
AMD VISION Engine Control Center
µTorrent
avast! Free Antivirus
Bandisoft MPEG-1 Decoder
Call of Duty(R) - World at War(TM) 1.2 Patch
Call of Duty(R) - World at War(TM) 1.4 Patch
Call of Duty(R) - World at War(TM) 1.5 Patch
Call of Duty(R) - World at War(TM) 1.6 Patch
Call of Duty(R) - World at War(TM) 1.7 Patch
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
CCC Help Portuguese
D3DX10
DAEMON Tools Lite
DFOLauncher
Diablo III
Directip Launcher 0.8.1
Foxit Reader 5.1
Fraps (remove only)
Google Chrome
HP Deskjet 1050 J410 series Ajuda
IRPF2012 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva do País
Java Auto Updater
Java(TM) 7 Update 4
JavaFX 2.1.0
K-Lite Codec Pack 8.7.0 (Standard)
Malwarebytes Anti-Malware version 1.62.0.1300
MapleStory
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 14.0.1 (x86 pt-BR)
Mozilla Maintenance Service
MSVCRT
MV RegClean 6.0
NeoplePlugin
Nexon Game Manager
NVIDIA PhysX
Payday The Heist (c) OVERKILL Software version 1
Pepakura Viewer 3
PHANTASY STAR ONLINE 2
Receitanet
Revo Uninstaller 1.94
Steam
Tibia
Tom Clancy's Ghost Recon Future Soldier
Tunngle beta
Ubisoft Game Launcher
Vindictus
Windows Live Communications Platform
Windows Live Essentials
Windows Live Galeria de Fotos
Windows Live Installer
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinRAR 4.10 (32-bit)
.
==== End Of File ===========================