Vinicius
Posts: 11 +0
Hey guys (and sorry for my poor English)
Since last week, a number of completely random sound clips would just play for 10 seconds or so, then happen again at random intervals. A siren, a typewriter, and a Super Mario song were some of the noises. I'm sure it does not come from a browser tab. Avast shows no virus.
MalwareBytes says "No malicious items detected" for all items checked, both quick and full scan.
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16482
Run by Vinicius at 13:16:27 on 2013-02-16
Microsoft Windows 8 Pro 6.2.9200.0.1252.55.1046.18.4000.1088 [GMT -2:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Opera x64\opera.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Opera x64\pluginwrapper\opera_plugin_wrapper.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\igfxsrvc.exe
D:\TV Vivo\Captvty\Captvty.exe
C:\WINDOWS\explorer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL
BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [Lync] "C:\Program Files\Microsoft Office\Office15\lync.exe" /fromrunkey
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
IE: E&xportar para o Microsoft Excel - C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
TCP: NameServer = 201.6.2.105 201.6.2.185
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA} : DHCPNameServer = 201.6.2.105 201.6.2.185
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA}\25564656030303 : NameServer = 177.71.182.132,177.71.182.149
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA}\25564656030303 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA}\4556E64616F5431353147383 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA}\B69647028323 : NameServer = 177.71.182.132,177.71.182.149
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA}\B69647028323 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{DDF78FA9-45F9-4B48-B8F3-C698264D599E} : DHCPNameServer = 192.168.1.254
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\WINDOWS\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
x64-Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
x64-Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R1 aswnet;avast! AG Firewall Core Driver;C:\WINDOWS\System32\Drivers\aswnet.sys [2012-11-30 468144]
R1 aswSnx;aswSnx;C:\WINDOWS\System32\Drivers\aswSnx.sys [2012-11-30 984144]
R1 aswSP;aswSP;C:\WINDOWS\System32\Drivers\aswSP.sys [2012-11-30 370288]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-7 17536]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\System32\Drivers\aswFsBlk.sys [2012-11-30 25232]
R2 aswMonFlt;aswMonFlt;C:\WINDOWS\System32\Drivers\aswMonFlt.sys [2012-11-30 71600]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-11-30 44808]
R3 RTL8168;Realtek 8168 NT Driver;C:\WINDOWS\System32\Drivers\Rt630x64.sys [2012-6-2 589824]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE [2012-10-1 178824]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\Drivers\usbaapl64.sys [2012-9-28 53760]
S3 vmbusr;Provedor de Barramento de Máquina Virtual;C:\WINDOWS\System32\Drivers\vmbusr.sys [2012-7-26 117248]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2013-02-15 15:20:05 -------- d-----w- C:\Users\Vinicius\AppData\Roaming\Malwarebytes
2013-02-15 15:19:55 -------- d-----w- C:\ProgramData\Malwarebytes
2013-02-15 15:19:52 24176 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2013-02-15 15:19:52 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-15 15:19:36 -------- d-----w- C:\Users\Vinicius\AppData\Local\Programs
2013-02-13 22:25:50 -------- d-----w- C:\Users\Vinicius\AppData\Local\Shutdown8
2013-02-12 23:53:29 4055552 ----a-w- C:\WINDOWS\System32\win32k.sys
2013-02-12 23:49:04 6967016 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2013-02-12 23:49:01 2226408 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2013-02-12 23:47:38 817664 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-12 23:47:38 1084416 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-01-25 12:50:18 5065840 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CMigrate.exe
2013-01-25 12:50:18 4830832 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\Csi.dll
2013-01-25 12:50:18 25357936 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2013-01-25 12:42:00 2948704 ----a-w- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\1046\MSOINTL.DLL
2013-01-25 12:41:58 6779504 ----a-w- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\CMigrate.exe
2013-01-25 12:41:58 6557808 ----a-w- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Csi.dll
2013-01-25 12:41:48 35329632 ----a-w- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2013-01-22 13:01:42 -------- d-----w- C:\Program Files (x86)\MSECache
2013-01-21 09:09:01 78176 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2013-01-21 09:09:00 692576 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2013-01-20 22:56:26 1131520 ----a-w- C:\WINDOWS\System32\AppXDeploymentServer.dll
2013-01-20 22:56:25 707584 ----a-w- C:\WINDOWS\System32\AppXDeploymentExtensions.dll
2013-01-20 22:56:23 178176 ----a-w- C:\WINDOWS\System32\SystemEventsBrokerServer.dll
2013-01-20 22:56:23 170496 ----a-w- C:\WINDOWS\System32\TimeBrokerServer.dll
2013-01-20 22:41:07 368640 ----a-w- C:\WINDOWS\System32\sppwinob.dll
2013-01-20 22:08:44 86016 ----a-w- C:\WINDOWS\System32\ncryptsslp.dll
2013-01-20 22:08:44 71168 ----a-w- C:\WINDOWS\SysWow64\ncryptsslp.dll
2013-01-20 21:47:51 2361344 ----a-w- C:\WINDOWS\System32\msxml6.dll
2013-01-20 21:47:51 1836032 ----a-w- C:\WINDOWS\System32\msxml3.dll
2013-01-20 21:47:51 1802240 ----a-w- C:\WINDOWS\SysWow64\msxml6.dll
2013-01-20 21:47:50 1438720 ----a-w- C:\WINDOWS\SysWow64\msxml3.dll
2013-01-20 21:47:48 2048 ----a-w- C:\WINDOWS\SysWow64\msxml6r.dll
2013-01-20 21:47:48 2048 ----a-w- C:\WINDOWS\SysWow64\msxml3r.dll
2013-01-20 21:47:48 2048 ----a-w- C:\WINDOWS\System32\msxml6r.dll
2013-01-20 21:47:48 2048 ----a-w- C:\WINDOWS\System32\msxml3r.dll
2013-01-20 19:34:13 -------- d-----w- C:\Program Files (x86)\ASUS
2013-01-20 19:31:19 -------- d-----w- C:\WINDOWS\System32\appmgmt
.
==================== Find3M ====================
.
2013-01-16 00:35:49 44032 ----a-w- C:\WINDOWS\SysWow64\UXInit.dll
2013-01-16 00:31:26 53760 ----a-w- C:\WINDOWS\System32\UXInit.dll
2013-01-04 05:32:36 2706432 ----a-w- C:\WINDOWS\SysWow64\mshtml.tlb
2013-01-04 04:19:53 2706432 ----a-w- C:\WINDOWS\System32\mshtml.tlb
2012-12-20 00:37:37 1775616 ----a-w- C:\WINDOWS\SysWow64\wininet.dll
2012-12-20 00:37:04 2881536 ----a-w- C:\WINDOWS\SysWow64\jscript9.dll
2012-12-20 00:37:02 61440 ----a-w- C:\WINDOWS\SysWow64\iesetup.dll
2012-12-20 00:37:02 109056 ----a-w- C:\WINDOWS\SysWow64\iesysprep.dll
2012-12-20 00:36:50 431616 ----a-w- C:\WINDOWS\apppatch\AcSpecfc.dll
2012-12-20 00:29:16 2246656 ----a-w- C:\WINDOWS\System32\wininet.dll
2012-12-20 00:29:11 907776 ----a-w- C:\WINDOWS\System32\uxtheme.dll
2012-12-20 00:28:29 3966464 ----a-w- C:\WINDOWS\System32\jscript9.dll
2012-12-20 00:28:26 136704 ----a-w- C:\WINDOWS\System32\iesysprep.dll
2012-12-20 00:28:04 39936 ----a-w- C:\WINDOWS\apppatch\apppatch64\acspecfc.dll
2012-12-18 01:56:27 534528 ----a-w- C:\WINDOWS\SysWow64\uxtheme.dll
2012-12-17 20:37:52 108008 ----a-w- C:\WINDOWS\System32\WindowsAccessBridge-64.dll
2012-12-17 20:37:47 959976 ----a-w- C:\WINDOWS\System32\deployJava1.dll
2012-12-17 20:37:47 1081320 ----a-w- C:\WINDOWS\System32\npDeployJava1.dll
2012-12-16 08:28:20 46080 ----a-w- C:\WINDOWS\System32\atmlib.dll
2012-12-16 08:20:01 35328 ----a-w- C:\WINDOWS\SysWow64\atmlib.dll
2012-12-16 08:08:33 362496 ----a-w- C:\WINDOWS\System32\atmfd.dll
2012-12-16 07:57:09 300032 ----a-w- C:\WINDOWS\SysWow64\atmfd.dll
2012-12-01 16:09:10 468144 ----a-w- C:\WINDOWS\System32\drivers\aswnet.sys
2012-11-27 07:00:32 194280 ----a-w- C:\WINDOWS\System32\drivers\sdbus.sys
2012-11-27 07:00:29 124648 ----a-w- C:\WINDOWS\System32\drivers\dumpsd.sys
2012-11-27 06:59:13 329960 ----a-w- C:\WINDOWS\System32\drivers\storport.sys
2012-11-27 06:39:46 1122768 ----a-w- C:\WINDOWS\System32\Taskmgr.exe
2012-11-27 04:49:20 1027152 ----a-w- C:\WINDOWS\SysWow64\Taskmgr.exe
2012-11-27 04:20:50 1048064 ----a-w- C:\WINDOWS\SysWow64\mstsc.exe
2012-11-27 04:20:42 179200 ----a-w- C:\WINDOWS\SysWow64\wpnapps.dll
2012-11-27 04:20:35 891904 ----a-w- C:\WINDOWS\SysWow64\winmde.dll
2012-11-27 04:20:31 798208 ----a-w- C:\WINDOWS\SysWow64\WebcamUi.dll
2012-11-27 04:20:29 46592 ----a-w- C:\WINDOWS\SysWow64\vds_ps.dll
2012-11-27 04:20:28 560128 ----a-w- C:\WINDOWS\SysWow64\UserLanguagesCpl.dll
2012-11-27 04:20:23 1217536 ----a-w- C:\WINDOWS\SysWow64\storagewmi.dll
2012-11-27 04:20:15 680960 ----a-w- C:\WINDOWS\System32\vds.exe
2012-11-27 04:20:07 702464 ----a-w- C:\WINDOWS\SysWow64\nshwfp.dll
2012-11-27 04:20:07 1123840 ----a-w- C:\WINDOWS\System32\mstsc.exe
2012-11-27 04:18:59 888832 ----a-w- C:\WINDOWS\System32\nshwfp.dll
2012-11-27 04:18:39 5974528 ----a-w- C:\WINDOWS\System32\mstscax.dll
2012-11-27 04:18:13 1071104 ----a-w- C:\WINDOWS\System32\IKEEXT.DLL
2012-11-27 04:18:06 378880 ----a-w- C:\WINDOWS\System32\FWPUCLNT.DLL
2012-11-27 04:17:32 718848 ----a-w- C:\WINDOWS\System32\BFE.DLL
2012-11-27 04:17:31 2302464 ----a-w- C:\WINDOWS\System32\authui.dll
2012-11-27 03:57:32 18432 ----a-w- C:\WINDOWS\System32\drivers\BtaMPM.sys
2012-11-27 03:56:29 31104 ----a-w- C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
2012-11-27 03:55:44 29952 ----a-w- C:\WINDOWS\System32\drivers\BthhfHid.sys
2012-11-20 05:24:19 1164800 ----a-w- C:\WINDOWS\SysWow64\Display.dll
2012-11-20 05:24:17 36352 ----a-w- C:\WINDOWS\SysWow64\DevDispItemProvider.dll
2012-11-20 05:17:23 1184256 ----a-w- C:\WINDOWS\System32\Display.dll
2012-11-20 05:17:20 49152 ----a-w- C:\WINDOWS\System32\DevDispItemProvider.dll
2012-11-20 05:02:46 6656 ----a-w- C:\WINDOWS\SysWow64\KBDKURD.DLL
2012-11-20 04:59:26 7168 ----a-w- C:\WINDOWS\System32\KBDKURD.DLL
2012-11-20 04:56:27 27136 ----a-w- C:\WINDOWS\System32\drivers\usbohci.sys
2012-11-20 04:56:11 83456 ----a-w- C:\WINDOWS\System32\drivers\hidclass.sys
2012-11-20 04:54:31 39936 ----a-w- C:\WINDOWS\System32\drivers\hidi2c.sys
.
============= FINISH: 13:17:36,28 ===============
Since last week, a number of completely random sound clips would just play for 10 seconds or so, then happen again at random intervals. A siren, a typewriter, and a Super Mario song were some of the noises. I'm sure it does not come from a browser tab. Avast shows no virus.
MalwareBytes says "No malicious items detected" for all items checked, both quick and full scan.
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16482
Run by Vinicius at 13:16:27 on 2013-02-16
Microsoft Windows 8 Pro 6.2.9200.0.1252.55.1046.18.4000.1088 [GMT -2:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Opera x64\opera.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Opera x64\pluginwrapper\opera_plugin_wrapper.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\System32\WUDFHost.exe
C:\WINDOWS\system32\igfxsrvc.exe
D:\TV Vivo\Captvty\Captvty.exe
C:\WINDOWS\explorer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL
BHO: Microsoft SkyDrive Pro Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [Lync] "C:\Program Files\Microsoft Office\Office15\lync.exe" /fromrunkey
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
IE: E&xportar para o Microsoft Excel - C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
TCP: NameServer = 201.6.2.105 201.6.2.185
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA} : DHCPNameServer = 201.6.2.105 201.6.2.185
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA}\25564656030303 : NameServer = 177.71.182.132,177.71.182.149
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA}\25564656030303 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA}\4556E64616F5431353147383 : DHCPNameServer = 192.168.1.254
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA}\B69647028323 : NameServer = 177.71.182.132,177.71.182.149
TCP: Interfaces\{642A19C7-BA40-42F1-83DC-E2A7277643EA}\B69647028323 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{DDF78FA9-45F9-4B48-B8F3-C698264D599E} : DHCPNameServer = 192.168.1.254
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
mASetup: {A6EADE66-0000-0000-484E-7E8A45000000} - "C:\WINDOWS\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Reader 11.0\Esl\AiodLite.dll",CreateReaderUserSettings
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
x64-Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
x64-Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
x64-Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R1 aswnet;avast! AG Firewall Core Driver;C:\WINDOWS\System32\Drivers\aswnet.sys [2012-11-30 468144]
R1 aswSnx;aswSnx;C:\WINDOWS\System32\Drivers\aswSnx.sys [2012-11-30 984144]
R1 aswSP;aswSP;C:\WINDOWS\System32\Drivers\aswSP.sys [2012-11-30 370288]
R1 ATKWMIACPIIO;ATKWMIACPI Driver;C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-9-7 17536]
R2 ASMMAP64;ASMMAP64;C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-7-2 15416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\System32\Drivers\aswFsBlk.sys [2012-11-30 25232]
R2 aswMonFlt;aswMonFlt;C:\WINDOWS\System32\Drivers\aswMonFlt.sys [2012-11-30 71600]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-11-30 44808]
R3 RTL8168;Realtek 8168 NT Driver;C:\WINDOWS\System32\Drivers\Rt630x64.sys [2012-6-2 589824]
R3 WUDFWpdMtp;WUDFWpdMtp;C:\WINDOWS\System32\Drivers\WUDFRd.sys [2012-7-26 198656]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE [2012-10-1 178824]
S3 USBAAPL64;Apple Mobile USB Driver;C:\WINDOWS\System32\Drivers\usbaapl64.sys [2012-9-28 53760]
S3 vmbusr;Provedor de Barramento de Máquina Virtual;C:\WINDOWS\System32\Drivers\vmbusr.sys [2012-7-26 117248]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\WINDOWS\System32\NOTEPAD.EXE %1 [UserChoice]
.
=============== Created Last 30 ================
.
2013-02-15 15:20:05 -------- d-----w- C:\Users\Vinicius\AppData\Roaming\Malwarebytes
2013-02-15 15:19:55 -------- d-----w- C:\ProgramData\Malwarebytes
2013-02-15 15:19:52 24176 ----a-w- C:\WINDOWS\System32\drivers\mbam.sys
2013-02-15 15:19:52 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-02-15 15:19:36 -------- d-----w- C:\Users\Vinicius\AppData\Local\Programs
2013-02-13 22:25:50 -------- d-----w- C:\Users\Vinicius\AppData\Local\Shutdown8
2013-02-12 23:53:29 4055552 ----a-w- C:\WINDOWS\System32\win32k.sys
2013-02-12 23:49:04 6967016 ----a-w- C:\WINDOWS\System32\ntoskrnl.exe
2013-02-12 23:49:01 2226408 ----a-w- C:\WINDOWS\System32\drivers\tcpip.sys
2013-02-12 23:47:38 817664 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-12 23:47:38 1084416 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-01-25 12:50:18 5065840 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CMigrate.exe
2013-01-25 12:50:18 4830832 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\Csi.dll
2013-01-25 12:50:18 25357936 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2013-01-25 12:42:00 2948704 ----a-w- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\1046\MSOINTL.DLL
2013-01-25 12:41:58 6779504 ----a-w- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\CMigrate.exe
2013-01-25 12:41:58 6557808 ----a-w- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Csi.dll
2013-01-25 12:41:48 35329632 ----a-w- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2013-01-22 13:01:42 -------- d-----w- C:\Program Files (x86)\MSECache
2013-01-21 09:09:01 78176 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
2013-01-21 09:09:00 692576 ----a-w- C:\WINDOWS\SysWow64\FlashPlayerApp.exe
2013-01-20 22:56:26 1131520 ----a-w- C:\WINDOWS\System32\AppXDeploymentServer.dll
2013-01-20 22:56:25 707584 ----a-w- C:\WINDOWS\System32\AppXDeploymentExtensions.dll
2013-01-20 22:56:23 178176 ----a-w- C:\WINDOWS\System32\SystemEventsBrokerServer.dll
2013-01-20 22:56:23 170496 ----a-w- C:\WINDOWS\System32\TimeBrokerServer.dll
2013-01-20 22:41:07 368640 ----a-w- C:\WINDOWS\System32\sppwinob.dll
2013-01-20 22:08:44 86016 ----a-w- C:\WINDOWS\System32\ncryptsslp.dll
2013-01-20 22:08:44 71168 ----a-w- C:\WINDOWS\SysWow64\ncryptsslp.dll
2013-01-20 21:47:51 2361344 ----a-w- C:\WINDOWS\System32\msxml6.dll
2013-01-20 21:47:51 1836032 ----a-w- C:\WINDOWS\System32\msxml3.dll
2013-01-20 21:47:51 1802240 ----a-w- C:\WINDOWS\SysWow64\msxml6.dll
2013-01-20 21:47:50 1438720 ----a-w- C:\WINDOWS\SysWow64\msxml3.dll
2013-01-20 21:47:48 2048 ----a-w- C:\WINDOWS\SysWow64\msxml6r.dll
2013-01-20 21:47:48 2048 ----a-w- C:\WINDOWS\SysWow64\msxml3r.dll
2013-01-20 21:47:48 2048 ----a-w- C:\WINDOWS\System32\msxml6r.dll
2013-01-20 21:47:48 2048 ----a-w- C:\WINDOWS\System32\msxml3r.dll
2013-01-20 19:34:13 -------- d-----w- C:\Program Files (x86)\ASUS
2013-01-20 19:31:19 -------- d-----w- C:\WINDOWS\System32\appmgmt
.
==================== Find3M ====================
.
2013-01-16 00:35:49 44032 ----a-w- C:\WINDOWS\SysWow64\UXInit.dll
2013-01-16 00:31:26 53760 ----a-w- C:\WINDOWS\System32\UXInit.dll
2013-01-04 05:32:36 2706432 ----a-w- C:\WINDOWS\SysWow64\mshtml.tlb
2013-01-04 04:19:53 2706432 ----a-w- C:\WINDOWS\System32\mshtml.tlb
2012-12-20 00:37:37 1775616 ----a-w- C:\WINDOWS\SysWow64\wininet.dll
2012-12-20 00:37:04 2881536 ----a-w- C:\WINDOWS\SysWow64\jscript9.dll
2012-12-20 00:37:02 61440 ----a-w- C:\WINDOWS\SysWow64\iesetup.dll
2012-12-20 00:37:02 109056 ----a-w- C:\WINDOWS\SysWow64\iesysprep.dll
2012-12-20 00:36:50 431616 ----a-w- C:\WINDOWS\apppatch\AcSpecfc.dll
2012-12-20 00:29:16 2246656 ----a-w- C:\WINDOWS\System32\wininet.dll
2012-12-20 00:29:11 907776 ----a-w- C:\WINDOWS\System32\uxtheme.dll
2012-12-20 00:28:29 3966464 ----a-w- C:\WINDOWS\System32\jscript9.dll
2012-12-20 00:28:26 136704 ----a-w- C:\WINDOWS\System32\iesysprep.dll
2012-12-20 00:28:04 39936 ----a-w- C:\WINDOWS\apppatch\apppatch64\acspecfc.dll
2012-12-18 01:56:27 534528 ----a-w- C:\WINDOWS\SysWow64\uxtheme.dll
2012-12-17 20:37:52 108008 ----a-w- C:\WINDOWS\System32\WindowsAccessBridge-64.dll
2012-12-17 20:37:47 959976 ----a-w- C:\WINDOWS\System32\deployJava1.dll
2012-12-17 20:37:47 1081320 ----a-w- C:\WINDOWS\System32\npDeployJava1.dll
2012-12-16 08:28:20 46080 ----a-w- C:\WINDOWS\System32\atmlib.dll
2012-12-16 08:20:01 35328 ----a-w- C:\WINDOWS\SysWow64\atmlib.dll
2012-12-16 08:08:33 362496 ----a-w- C:\WINDOWS\System32\atmfd.dll
2012-12-16 07:57:09 300032 ----a-w- C:\WINDOWS\SysWow64\atmfd.dll
2012-12-01 16:09:10 468144 ----a-w- C:\WINDOWS\System32\drivers\aswnet.sys
2012-11-27 07:00:32 194280 ----a-w- C:\WINDOWS\System32\drivers\sdbus.sys
2012-11-27 07:00:29 124648 ----a-w- C:\WINDOWS\System32\drivers\dumpsd.sys
2012-11-27 06:59:13 329960 ----a-w- C:\WINDOWS\System32\drivers\storport.sys
2012-11-27 06:39:46 1122768 ----a-w- C:\WINDOWS\System32\Taskmgr.exe
2012-11-27 04:49:20 1027152 ----a-w- C:\WINDOWS\SysWow64\Taskmgr.exe
2012-11-27 04:20:50 1048064 ----a-w- C:\WINDOWS\SysWow64\mstsc.exe
2012-11-27 04:20:42 179200 ----a-w- C:\WINDOWS\SysWow64\wpnapps.dll
2012-11-27 04:20:35 891904 ----a-w- C:\WINDOWS\SysWow64\winmde.dll
2012-11-27 04:20:31 798208 ----a-w- C:\WINDOWS\SysWow64\WebcamUi.dll
2012-11-27 04:20:29 46592 ----a-w- C:\WINDOWS\SysWow64\vds_ps.dll
2012-11-27 04:20:28 560128 ----a-w- C:\WINDOWS\SysWow64\UserLanguagesCpl.dll
2012-11-27 04:20:23 1217536 ----a-w- C:\WINDOWS\SysWow64\storagewmi.dll
2012-11-27 04:20:15 680960 ----a-w- C:\WINDOWS\System32\vds.exe
2012-11-27 04:20:07 702464 ----a-w- C:\WINDOWS\SysWow64\nshwfp.dll
2012-11-27 04:20:07 1123840 ----a-w- C:\WINDOWS\System32\mstsc.exe
2012-11-27 04:18:59 888832 ----a-w- C:\WINDOWS\System32\nshwfp.dll
2012-11-27 04:18:39 5974528 ----a-w- C:\WINDOWS\System32\mstscax.dll
2012-11-27 04:18:13 1071104 ----a-w- C:\WINDOWS\System32\IKEEXT.DLL
2012-11-27 04:18:06 378880 ----a-w- C:\WINDOWS\System32\FWPUCLNT.DLL
2012-11-27 04:17:32 718848 ----a-w- C:\WINDOWS\System32\BFE.DLL
2012-11-27 04:17:31 2302464 ----a-w- C:\WINDOWS\System32\authui.dll
2012-11-27 03:57:32 18432 ----a-w- C:\WINDOWS\System32\drivers\BtaMPM.sys
2012-11-27 03:56:29 31104 ----a-w- C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
2012-11-27 03:55:44 29952 ----a-w- C:\WINDOWS\System32\drivers\BthhfHid.sys
2012-11-20 05:24:19 1164800 ----a-w- C:\WINDOWS\SysWow64\Display.dll
2012-11-20 05:24:17 36352 ----a-w- C:\WINDOWS\SysWow64\DevDispItemProvider.dll
2012-11-20 05:17:23 1184256 ----a-w- C:\WINDOWS\System32\Display.dll
2012-11-20 05:17:20 49152 ----a-w- C:\WINDOWS\System32\DevDispItemProvider.dll
2012-11-20 05:02:46 6656 ----a-w- C:\WINDOWS\SysWow64\KBDKURD.DLL
2012-11-20 04:59:26 7168 ----a-w- C:\WINDOWS\System32\KBDKURD.DLL
2012-11-20 04:56:27 27136 ----a-w- C:\WINDOWS\System32\drivers\usbohci.sys
2012-11-20 04:56:11 83456 ----a-w- C:\WINDOWS\System32\drivers\hidclass.sys
2012-11-20 04:54:31 39936 ----a-w- C:\WINDOWS\System32\drivers\hidi2c.sys
.
============= FINISH: 13:17:36,28 ===============