Usamos cookies para medir audiência e melhorar sua experiência. Você pode aceitar ou recusar a qualquer momento. Veja sobre o iMasters.
Olá!!Boa Noite tem alguem que possa me ajudar novamente com meu PC,estou achando que ele esta com Virus. :rolleyes:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:40:24, on 1/2/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe
C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe
C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\WINDOWS\system32\rundll32.exe
C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe
C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\sistray.exe
C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe
C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\explorer.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe
C:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Arquivos de programas\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARQUIV~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [synTPEnh] C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avast] "C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NielsenOnline] C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [PlusService] C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB001" /M "Stylus C45"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nielsen Update (NielsenUpdate) - The Nielsen Company - C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe
O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
--
End of file - 8411 bytes
>
Boa Noite! karoline ferreira
|- O que ocorre com a máquina? Poderia nos relatar?
///°°°///
|- < Link - 2 >
|- < Link - 3 >
|- Atualize o programa!
|- Escolha o escaneamento Completo!
|- Desabilite programas de proteção,ao executar o malwarebytes.
|- Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme!
|- Ao concluir,clique em "Remover itens".
|- Poste,o relatório: mbam-log-2012-xx-xx (00-00-00).txt
///°°°///
|- Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://billy-oneal.com/Canned%2520Speeches/speechimages/OTL/otlDesktopIcon.png&key=1894e5d356219721410c3360cbf9af74877ae24ccc81ed88026fc2d95dd96a07" alt="otlDesktopIcon.png" /> > ( ...by OldTimer Tools )
|- Clique em Salvar! < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/0e5c629f14858f5bf77e61d46c160e317c6d8c5d3ee101e311e440e99d7fd7b06g.jpg&key=3b5f68b982954852820a7b1c44c7d4ba5f9d81d9cc9adb16f3359408e8cb0d2c" alt="0e5c629f14858f5bf77e61d46c160e317c6d8c5d3ee101e311e440e99d7fd7b06g.jpg" /> >
|- Salve-o no desktop! < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/98c0f1ab3823c58ea05c695fd153839feac6fb6b44aaa3f7f5a2cd4a87354c946g.jpg&key=fdd081d7d566e9ee7a4326a3039dd79a57a2005ed7e54a981d560e259f22d658" alt="98c0f1ab3823c58ea05c695fd153839feac6fb6b44aaa3f7f5a2cd4a87354c946g.jpg" /> >
|- Duplo clique em OTL.exe --> Executar: /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/c19ede0bf8817fba1b9a9c0e9dae6ede3b8983c41017d8926efac3638b95aee16g.jpg&key=422d6e6777df6b11458399b7f42d7cf2ca878f8e09b61a66ff681dacba971926" alt="c19ede0bf8817fba1b9a9c0e9dae6ede3b8983c41017d8926efac3638b95aee16g.jpg" />
|- Execute o OTL,em seu rápido escaneamento. ( Verificação rápida )
|- Ps: Para Windows 7,clique direito e execute-o como "Administrador".
|- Copie e poste o relatório. ( C:\_OTM\MovedFiles\xxxx2012_xxxxxx.log )
|- Poste,também,o relatório "Extras".
Abraços!
Boa Noite!DigRam...Primeiramente obrigada,meu pc está travando muito e tambem demorando para carregar.
>
Boa Noite!DigRam...Primeiramente obrigada,meu pc está travando muito e tambem demorando para carregar.
Olá!
|- Ok! Siga então com as ferramentas sugeridas.
|- Faça antes a limpeza de temporários,com "Temp".
///°°°///
|- Baixe: < Temp.zip >
|- Descompacte-o para o desktop!
|- Execute-o com um duplo-clique. ( Temp.bat )
|- Onde surgirá,rapidamente,uma tela preta.
///°°°///
|- Siga com o MBAM e o OTL.
|- Poste seus relatórios!
Abraços!
>
Olá!
|- Ok! Siga então com as ferramentas sugeridas.
|- Faça antes a limpeza de temporários,com "Temp".
///°°°///
|- Baixe: < Temp.zip >
|- Descompacte-o para o desktop!
|- Execute-o com um duplo-clique. ( Temp.bat )
|- Onde surgirá,rapidamente,uma tela preta.
///°°°///
|- Siga com o MBAM e o OTL.
|- Poste seus relatórios!
Abraços!
Boa Noite!! 'DigRam'...
'DigRam'
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Versão da Base de Dados: v2012.02.03.09
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 6.0.2900.5512
Filho e karol :: GTEC-A93A9F1435 [administrador]
Proteção: Não permitir
3/2/2012 17:54:05
mbam-log-2012-02-03 (17-54-05).txt
Tipo de Verificação: Verificação Completa
Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM
Opções de verificação desativadas: P2P
Objetos escaneados: 205780
Tempo decorrido: 35 minuto(s), 43 segundo(s)
Processos de Memória Detectados: 0
(Não foram detectados ítens maliciosos)
Módulos de Memória Detectados: 0
(Não foram detectados ítens maliciosos)
Chaves de Registro Detectadas: 0
(Não foram detectados ítens maliciosos)
Valores de Registro Detectadas: 0
(Não foram detectados ítens maliciosos)
Itens de Dados no Registro Detectadas: 0
(Não foram detectados ítens maliciosos)
Pastas Detectadas: 0
(Não foram detectados ítens maliciosos)
Arquivos Detectados: 2
C:\Documents and Settings\Filho e karol\Meus documentos\Downloads\SoftonicDownloader_para_audacity.exe (PUP.BundleOffer.Downloader.S) -> Enviado para a Quarentena e deletado com sucesso.
C:\Documents and Settings\Filho e karol\Meus documentos\Downloads\SoftonicDownloader_para_vso-convertxtodvd.exe (PUP.BundleOffer.Downloader.S) -> Enviado para a Quarentena e deletado com sucesso.
(fim)
OTL logfile created on: 3/2/2012 20:20:00 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Filho e karol\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy
893,10 Mb Total Physical Memory | 328,86 Mb Available Physical Memory | 36,82% Memory free
2,12 Gb Paging File | 1,66 Gb Available in Paging File | 78,62% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas
Drive C: | 48,83 Gb Total Space | 30,36 Gb Free Space | 62,18% Space Free | Partition Type: NTFS
Drive D: | 62,95 Gb Total Space | 62,78 Gb Free Space | 99,73% Space Free | Partition Type: NTFS
Computer Name: GTEC-A93A9F1435 | User Name: Filho e karol | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/02/03 20:16:29 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Filho e karol\Desktop\OTL.exe
PRC - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/01/07 22:12:37 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe
PRC - [2011/11/28 16:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Arquivos de programas\AVAST Software\Avast\AvastUI.exe
PRC - [2011/11/28 16:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/11/02 15:17:41 | 000,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe
PRC - [2011/10/24 16:51:19 | 000,801,792 | ---- | M] (Yuna Software) -- C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe
PRC - [2011/05/03 18:46:26 | 000,306,496 | ---- | M] (The Nielsen Company) -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe
PRC - [2010/11/17 11:38:00 | 000,047,424 | ---- | M] (The Nielsen Company) -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe
PRC - [2009/03/10 22:18:18 | 000,969,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\WgaTray.exe
PRC - [2008/04/13 19:21:00 | 001,035,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/25 16:45:42 | 000,262,144 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\sistray.exe
PRC - [2007/06/01 10:21:30 | 001,209,904 | ---- | M] (Nero AG) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007/06/01 10:21:30 | 000,271,920 | ---- | M] (Nero AG) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
PRC - [2007/06/01 10:21:08 | 000,153,136 | ---- | M] (Nero AG) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
PRC - [2004/01/14 09:00:00 | 000,099,840 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I4T1.EXE
========== Modules (No Company Name) ==========
MOD - [2012/02/03 16:41:52 | 001,688,576 | ---- | M] () -- C:\Arquivos de programas\AVAST Software\Avast\defs\12020301\algo.dll
MOD - [2012/01/08 13:57:00 | 000,076,800 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\extensions\{192a6019-26d2-4611-aead-07cd7733b146}\components\RadioWMPCoreGecko9.dll
MOD - [2012/01/07 22:12:35 | 002,124,760 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\mozjs.dll
MOD - [2011/11/19 08:21:56 | 008,527,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/05/03 18:41:32 | 000,247,296 | ---- | M] () -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\nsmmc.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/04 17:55:30 | 000,264,704 | ---- | M] () -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\meter3\npwmi.dll
MOD - [2010/10/04 17:55:14 | 000,292,864 | ---- | M] () -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\meter3\npsurvey.dll
MOD - [2010/10/04 17:55:04 | 000,184,320 | ---- | M] () -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\meter3\npsp1.dll
MOD - [2010/10/04 17:48:26 | 000,485,376 | ---- | M] () -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\meter3\communication.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/11/28 16:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/06/12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2011/05/03 18:46:26 | 000,306,496 | ---- | M] (The Nielsen Company) [Auto | Running] -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe -- (NielsenUpdate)
SRV - [2010/01/09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010/01/09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2007/06/01 10:21:30 | 000,271,920 | ---- | M] (Nero AG) [On_Demand | Running] -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
========== Driver Services (SafeList) ==========
DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/11/28 15:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/11/28 15:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/11/28 15:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/11/28 15:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/11/28 15:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/11/28 15:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/11/28 15:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/08/17 09:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2010/10/04 17:57:20 | 000,015,360 | ---- | M] (The Nielsen Company) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\nnrnstdi.sys -- (nnrnstdi)
DRV - [2010/10/04 17:57:16 | 000,010,368 | ---- | M] (The Nielsen Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\km_filter.sys -- (km_filter)
DRV - [2007/12/20 18:00:06 | 004,637,696 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/06/25 07:10:28 | 000,018,432 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)
DRV - [2007/06/25 06:49:08 | 000,321,536 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
DRV - [2007/06/01 03:06:42 | 000,238,976 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rtl8187B.sys -- (RTL8187B)
DRV - [2006/12/20 02:00:00 | 000,041,600 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys -- (SiSGbeXP)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "Stardoll Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2836015&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..network.proxy.http: "81.84.241.147"
FF - prefs.js..network.proxy.http_port: 2183
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Arquivos de programas\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\ARQUIV~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\ARQUIV~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Arquivos de programas\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46: C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Arquivos de programas\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Arquivos de programas\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Arquivos de programas\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Arquivos de programas\Real\RealPlayer\browserrecord [2011/11/02 15:17:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Arquivos de programas\AVAST Software\Avast\WebRep\FF [2011/11/29 16:36:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D908A1CC-54B4-4af9-9BB4-964F5BD3CDB7}: C:\Arquivos de programas\NetRatingsNetSight\NetSight\meter3\FFAddon\ [2012/01/31 10:49:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox\components [2012/01/07 22:12:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox\plugins
[2011/11/02 14:57:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Extensions
[2012/01/08 17:16:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\extensions
[2012/01/08 17:16:44 | 000,000,000 | ---D | M] (Stardoll Community Toolbar) -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\extensions\{192a6019-26d2-4611-aead-07cd7733b146}
[2011/11/03 13:44:18 | 000,000,919 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\searchplugins\conduit.xml
[2012/01/01 08:15:55 | 000,002,774 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\searchplugins\Plusnetwork.xml
[2011/11/02 14:57:25 | 000,000,000 | ---D | M] (No name found) -- C:\Arquivos de programas\Mozilla Firefox\extensions
[2012/01/31 10:49:08 | 000,000,000 | ---D | M] (Nielsen) -- C:\ARQUIVOS DE PROGRAMAS\NETRATINGSNETSIGHT\NETSIGHT\METER3\FFADDON
[2012/01/07 22:12:38 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Arquivos de programas\mozilla firefox\components\browsercomps.dll
[2012/01/07 22:12:30 | 000,001,027 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\buscape.xml
[2012/01/07 22:12:30 | 000,001,212 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\mercadolivre.xml
[2012/01/07 22:12:30 | 000,002,040 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\twitter.xml
[2012/01/07 22:12:30 | 000,001,168 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\wikipedia-br.xml
[2012/01/07 22:12:30 | 000,000,952 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\yahoo-br.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Arquivos de programas\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Arquivos de programas\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Arquivos de programas\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Arquivos de programas\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\ARQUIV~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\ARQUIV~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Arquivos de programas\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Arquivos de programas\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Arquivos de programas\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Arquivos de programas\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Arquivos de programas\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Pesquisa do Google = C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: avast! WebRep = C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1374_0\
CHR - Extension: Nielsen = C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\jgceplfonlgodadnpognljgdjlcnpjnh\1.3.0_0\
CHR - Extension: Gmail = C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2000/01/11 20:38:34 | 000,000,776 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Arquivos de programas\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Arquivos de programas\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [avast] C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [bluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe (Epson)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NielsenOnline] C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe (The Nielsen Company)
O4 - HKLM..\Run: [PlusService] C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe (Yuna Software)
O4 - HKLM..\Run: [siSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Enviar para o OneNote - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de programas\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{129BC170-D18B-4D71-A3CE-166C42F67025}: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F344BE1-A5C6-4A31-989C-28C50E04E85D}: DhcpNameServer = 200.222.145.84 200.149.55.142
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Minha página inicial atual) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de programas\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/11/02 14:21:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{ea1989a6-0570-11e1-b97b-001644da8ece}\Shell\AutoRun\command - "" = H:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/03 20:16:17 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Filho e karol\Desktop\OTL.exe
[2012/01/30 18:23:18 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Filho e karol\Recent
[2012/01/25 09:38:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Unity
[2012/01/25 09:15:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Filho e karol\Meus documentos\Messenger Plus
[2012/01/23 20:02:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Iniciar\Programas\Ink Monitor
[2012/01/23 20:01:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Iniciar\Programas\Impressoras EPSON
[2012/01/23 19:52:29 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\EPSON
[2012/01/19 15:54:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\WMTools Downloaded Files
[2012/01/19 15:38:35 | 001,343,488 | ---- | C] (MultiMedia Soft) -- C:\WINDOWS\System32\AdjMmsEng.dll
[2012/01/19 15:38:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Pianosoft
[2012/01/19 14:40:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Audacity
[2004/11/24 16:25:52 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll
[4 C:\WINDOWS\.tmp files -> C:\WINDOWS\.tmp -> ]
[1 C:\WINDOWS\System32\.tmp files -> C:\WINDOWS\System32\.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/03 20:16:29 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Filho e karol\Desktop\OTL.exe
[2012/02/03 20:12:47 | 000,002,262 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/03 20:12:45 | 000,001,082 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/03 20:05:00 | 000,001,086 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/03 20:03:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/03 17:40:47 | 000,000,840 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/03 12:29:27 | 000,201,929 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\1.PNG
[2012/02/03 12:28:04 | 000,355,730 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\2.PNG
[2012/02/01 16:01:20 | 000,092,392 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\trans.JPG
[2012/02/01 16:00:45 | 000,099,065 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\tns.JPG
[2012/01/24 12:10:22 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/01/23 20:02:02 | 000,000,066 | ---- | M] () -- C:\WINDOWS\EPSC45.ini
[2012/01/21 11:30:50 | 000,040,620 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\pagamento dvd.PNG
[2012/01/19 15:56:32 | 000,000,116 | ---- | M] () -- C:\Documents and Settings\Filho e karol\default.pls
[2012/01/19 15:47:56 | 000,012,288 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/19 14:06:13 | 005,085,019 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\preview.mp3
[2012/01/19 11:29:13 | 000,041,402 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\fgts.PNG
[2012/01/16 19:36:28 | 000,084,321 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 4.PNG
[2012/01/16 19:34:29 | 000,081,899 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 3.PNG
[2012/01/16 19:34:15 | 000,078,099 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 2.PNG
[2012/01/16 19:11:14 | 000,084,052 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita.PNG
[2012/01/16 19:10:52 | 000,058,047 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao vsita 1.PNG
[2012/01/16 15:59:55 | 000,152,632 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\0012.jpg
[2012/01/16 15:38:55 | 000,027,669 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\auto_cartao_dos_carros_cartao_visita-p240736084886866179z74gr_400.jpg
[2012/01/04 21:18:33 | 000,471,614 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat
[2012/01/04 21:18:33 | 000,435,594 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/04 21:18:33 | 000,080,396 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat
[2012/01/04 21:18:33 | 000,068,490 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[4 C:\WINDOWS\.tmp files -> C:\WINDOWS\.tmp -> ]
[1 C:\WINDOWS\System32\.tmp files -> C:\WINDOWS\System32\.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/03 17:40:47 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/03 12:22:11 | 000,355,730 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\2.PNG
[2012/02/03 12:22:02 | 000,201,929 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\1.PNG
[2012/02/01 16:01:20 | 000,092,392 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\trans.JPG
[2012/02/01 16:00:45 | 000,099,065 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\tns.JPG
[2012/01/23 20:01:34 | 000,000,182 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT4.DAT
[2012/01/23 19:52:08 | 000,000,066 | ---- | C] () -- C:\WINDOWS\EPSC45.ini
[2012/01/21 11:30:50 | 000,040,620 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\pagamento dvd.PNG
[2012/01/19 15:38:36 | 000,157,696 | ---- | C] () -- C:\WINDOWS\System32\OggEnc.exe
[2012/01/19 15:38:36 | 000,145,408 | ---- | C] () -- C:\WINDOWS\System32\Lame.exe
[2012/01/19 15:38:36 | 000,006,832 | ---- | C] () -- C:\WINDOWS\System32\PulseSoundTouchForVB.tlb
[2012/01/19 15:38:35 | 000,098,708 | ---- | C] () -- C:\WINDOWS\System32\activesoundeditor.tlb
[2012/01/19 15:38:35 | 000,076,800 | ---- | C] () -- C:\WINDOWS\System32\Faac.exe
[2012/01/19 15:29:46 | 005,085,019 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\preview.mp3
[2012/01/19 11:29:13 | 000,041,402 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\fgts.PNG
[2012/01/16 19:36:28 | 000,084,321 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 4.PNG
[2012/01/16 19:34:29 | 000,081,899 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 3.PNG
[2012/01/16 19:34:15 | 000,078,099 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 2.PNG
[2012/01/16 19:11:14 | 000,084,052 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita.PNG
[2012/01/16 19:10:52 | 000,058,047 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao vsita 1.PNG
[2012/01/16 15:57:40 | 000,152,632 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\0012.jpg
[2012/01/16 15:38:45 | 000,027,669 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\auto_cartao_dos_carros_cartao_visita-p240736084886866179z74gr_400.jpg
[2011/12/12 21:59:00 | 000,000,085 | -HS- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\.zreglib
[2011/11/28 10:54:02 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2011/11/02 20:02:56 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2011/11/02 19:30:09 | 000,012,288 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/02 15:40:09 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/11/02 15:40:09 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/11/02 14:34:49 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2011/11/02 14:30:16 | 000,092,761 | ---- | C] () -- C:\WINDOWS\VGAsetup.ini
[2011/11/02 14:29:39 | 000,208,896 | R--- | C] () -- C:\WINDOWS\Progress.exe
[2011/11/02 14:29:39 | 000,049,152 | R--- | C] () -- C:\WINDOWS\InstFunc.exe
[2011/11/02 14:29:31 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\sis760.bin
[2011/11/02 14:29:31 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\sis741.bin
[2011/11/02 14:29:31 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\sis660.bin
[2011/11/02 14:29:15 | 000,133,021 | ---- | C] () -- C:\WINDOWS\System32\VGAunistlog.ini
[2011/11/02 14:23:42 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/11/02 14:18:20 | 000,021,844 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/11/02 12:08:02 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/11/02 12:06:50 | 000,280,536 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2004/11/29 12:43:20 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\sherlock2.exe
[2004/10/12 03:40:58 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2004/10/12 03:39:48 | 000,028,160 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2004/10/12 03:39:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2004/10/09 03:40:16 | 000,454,144 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2004/10/05 05:16:08 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2004/10/03 14:50:54 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/09/01 13:49:17 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2004/08/04 01:57:52 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/02 15:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2000/01/11 20:38:34 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2000/01/11 20:38:34 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2000/01/11 20:38:34 | 000,471,614 | ---- | C] () -- C:\WINDOWS\System32\perfh016.dat
[2000/01/11 20:38:34 | 000,435,594 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2000/01/11 20:38:34 | 000,301,776 | ---- | C] () -- C:\WINDOWS\System32\perfi016.dat
[2000/01/11 20:38:34 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2000/01/11 20:38:34 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2000/01/11 20:38:34 | 000,080,396 | ---- | C] () -- C:\WINDOWS\System32\perfc016.dat
[2000/01/11 20:38:34 | 000,068,490 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2000/01/11 20:38:34 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2000/01/11 20:38:34 | 000,035,178 | ---- | C] () -- C:\WINDOWS\System32\perfd016.dat
[2000/01/11 20:38:34 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2000/01/11 20:38:34 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2000/01/11 20:38:34 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2012/01/19 15:31:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Audacity
[2011/12/05 23:34:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Windows Live Writer
[2011/11/02 15:47:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\AVAST Software
[2011/11/02 20:06:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus!
[2012/01/19 15:38:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Pianosoft
========== Purity Check ==========
< End of report >
OTL Extras logfile created on: 3/2/2012 20:20:00 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Filho e karol\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy
893,10 Mb Total Physical Memory | 328,86 Mb Available Physical Memory | 36,82% Memory free
2,12 Gb Paging File | 1,66 Gb Available in Paging File | 78,62% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas
Drive C: | 48,83 Gb Total Space | 30,36 Gb Free Space | 62,18% Space Free | Partition Type: NTFS
Drive D: | 62,95 Gb Total Space | 62,78 Gb Free Space | 99,73% Space Free | Partition Type: NTFS
Computer Name: GTEC-A93A9F1435 | User Name: Filho e karol | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Arquivos de programas\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Arquivos de programas\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.EXE" = C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace -- (Microsoft Corporation)
"C:\Arquivos de programas\Microsoft Office\Office14\ONENOTE.EXE" = C:\Arquivos de programas\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)
"C:\Arquivos de programas\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Arquivos de programas\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Documents and Settings\Filho e karol\Configurações locais\Temp\196.tmp\KMService.exe" = C:\Documents and Settings\Filho e karol\Configurações locais\Temp\196.tmp\KMService.exe:*:Enabled:KMService
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0FFEA8EE-7BC7-4C9D-8CC6-5B8C891BA3F2}" = Windows Live Essentials
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2DF215E0-BD3C-4C98-8616-AFEF09747285}" = Windows Live Sync
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C9416-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}" = Assistente de Conexão do Windows Live
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{590035D9-BFA0-406A-A7F0-479C72C0DDB2}" = Windows Live Call
"{66EBD70F-A42C-475F-AEDF-277378151046}" = Nero 7 Essentials
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{7095FD27-37F0-4750-9DE8-D37DC0043706}" = REALTEK USB Wireless LAN Driver
"{74AD1846-2010-4FB1-8E24-B6F2B87150C2}" = Windows Live Mail
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{87A9C015-C2BA-44EE-9C20-6E1A764B8E23}" = Windows Live Galeria de Fotos
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90140000-0010-0416-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Portuguese (Brazil)) 14
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-0416-0000-0000000FF1CE}" = Microsoft Office Access MUI (Portuguese (Brazil)) 2010
"{90140000-0015-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0416-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Portuguese (Brazil)) 2010
"{90140000-0016-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0416-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010
"{90140000-0018-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0416-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010
"{90140000-0019-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0416-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010
"{90140000-001A-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0416-0000-0000000FF1CE}" = Microsoft Office Word MUI (Portuguese (Brazil)) 2010
"{90140000-001B-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2010
"{90140000-001F-0416-0000-0000000FF1CE}_Office14.PROPLUS_{A7200E61-DC93-42E0-BB74-EE59021016EA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0416-0000-0000000FF1CE}" = Microsoft Office Proofing (Portuguese (Brazil)) 2010
"{90140000-002C-0416-0000-0000000FF1CE}_Office14.PROPLUS_{13291F79-D997-49AD-9F31-5FAEE1F0FCF5}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0416-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010
"{90140000-0044-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0416-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Portuguese (Brazil)) 2010
"{90140000-006E-0416-0000-0000000FF1CE}_Office14.PROPLUS_{2134F8C8-2AD8-44EE-B86B-1B577FBD8D0E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0416-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010
"{90140000-00A1-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0416-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Portuguese (Brazil)) 2010
"{90140000-00BA-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9555B4ED-09A3-4722-8E8C-57A49401D059}" = Windows Live Writer
"{9ADC3E4F-34DA-48CD-8727-BB26D90257BD}" = Windows Live Messenger
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1046-7B44-AA1000000001}" = Adobe Reader X (10.1.2) - Português
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C50BF854-E881-434F-9C67-5A73EBB58F06}" = Windows Live Toolbar
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DC226AC9-0314-496C-BE6A-B6A132628466}" = SiSAGP driver
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"DVD Flick_is1" = DVD Flick 1.3.0.7
"EPSON Printer and Utilities" = Software para Impressoras EPSON
"Google Chrome" = Google Chrome
"Ink Monitor" = Ink Monitor
"L&H Power Translator Pro 7.0" = L&H Power Translator Pro 7.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versão 1.60.1.1000
"Messenger Plus!" = Messenger Plus! 5
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 9.0.1 (x86 pt-BR)" = Mozilla Firefox 9.0.1 (x86 pt-BR)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NetSight" = Nielsen
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"QuicktimeAlt_is1" = QuickTime Alternative 1.77
"RealPlayer 6.0" = RealPlayer
"SiS VGA Driver" = SiS VGA Utilities
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Arquivo do WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XP Codec Pack" = XP Codec Pack
"XviD_is1" = XviD 1.1 final uninstall
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/12/2011 11:13:06 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1002
Description = Aplicativo com falha firefox.exe, versão 8.0.1.4341, módulo com falha
hungapp, versão 0.0.0.0, endereço com falha 0x00000000.
Error - 5/12/2011 11:13:19 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1001
Description = Falha no compartimento de memória -1589266322.
Error - 5/12/2011 11:13:59 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1001
Description = Falha no compartimento de memória -1589266322.
Error - 5/12/2011 11:13:59 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1001
Description = Falha no compartimento de memória -1589266322.
Error - 5/12/2011 11:14:00 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1001
Description = Falha no compartimento de memória -1589266322.
Error - 7/12/2011 18:29:28 | Computer Name = GTEC-A93A9F1435 | Source = ESENT | ID = 489
Description = wuauclt (3580) Falha na tentativa de abrir o arquivo "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
para acesso somente leitura, com erro de sistema 32 (0x00000020): "O arquivo já
está sendo usado por outro processo. ". A operação de abertura do arquivo falhará
com o erro -1032 (0xfffffbf8).
Error - 7/12/2011 18:29:28 | Computer Name = GTEC-A93A9F1435 | Source = ESENT | ID = 455
Description = wuaueng.dll (3580) SUS20ClientDataStore: Erro -1032 (0xfffffbf8) ao
abrir o arquivo de log C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 7/12/2011 18:29:38 | Computer Name = GTEC-A93A9F1435 | Source = ESENT | ID = 489
Description = wuauclt (3580) Falha na tentativa de abrir o arquivo "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
para acesso somente leitura, com erro de sistema 32 (0x00000020): "O arquivo já
está sendo usado por outro processo. ". A operação de abertura do arquivo falhará
com o erro -1032 (0xfffffbf8).
Error - 7/12/2011 18:29:38 | Computer Name = GTEC-A93A9F1435 | Source = ESENT | ID = 455
Description = wuaueng.dll (3580) SUS20ClientDataStore: Erro -1032 (0xfffffbf8) ao
abrir o arquivo de log C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Error - 10/12/2011 20:42:50 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1002
Description = Aplicativo com falha firefox.exe, versão 8.0.1.4341, módulo com falha
hungapp, versão 0.0.0.0, endereço com falha 0x00000000.
[ System Events ]
Error - 2/2/2012 18:09:59 | Computer Name = GTEC-A93A9F1435 | Source = Disk | ID = 262155
Description = O driver detectou um erro de controlador em \Device\Harddisk1\D.
Error - 3/2/2012 08:39:21 | Computer Name = GTEC-A93A9F1435 | Source = Dhcp | ID = 1002
Description = A concessão 192.168.254.1 do endereço IP para a placa de rede com
endereço de rede 00030DA7B51F foi negada pelo servidor DHCP 192.168.254.254 (O servidor
DHCP enviou uma mensagem DHCPNACK).
Error - 3/2/2012 09:46:33 | Computer Name = GTEC-A93A9F1435 | Source = Disk | ID = 262155
Description = O driver detectou um erro de controlador em \Device\Harddisk1\D.
Error - 3/2/2012 11:56:07 | Computer Name = GTEC-A93A9F1435 | Source = ACPI | ID = 327685
Description = AMLI: o BIOS da ACPI está tentando gravar em um endereço de porta
de E/S inválido (0x70), que está no intervalo de endereços protegido 0x70 - 0x71.
Isso pode causar instabilidade no sistema. Contate o fornecedor do sistema para
obter assistência técnica.
Error - 3/2/2012 11:56:07 | Computer Name = GTEC-A93A9F1435 | Source = ACPI | ID = 327684
Description = AMLI: o BIOS da ACPI está tentando ler um endereço de porta de E/S
(0x71) inválido, que está no intervalo de endereços protegido 0x70 - 0x71. Isso
pode causar instabilidade no sistema. Contate o fornecedor do sistema para obter
assistência técnica.
Error - 3/2/2012 12:14:52 | Computer Name = GTEC-A93A9F1435 | Source = Disk | ID = 262155
Description = O driver detectou um erro de controlador em \Device\Harddisk1\D.
Error - 3/2/2012 16:52:40 | Computer Name = GTEC-A93A9F1435 | Source = Disk | ID = 262155
Description = O driver detectou um erro de controlador em \Device\Harddisk1\D.
Error - 3/2/2012 17:58:23 | Computer Name = GTEC-A93A9F1435 | Source = ACPI | ID = 327685
Description = AMLI: o BIOS da ACPI está tentando gravar em um endereço de porta
de E/S inválido (0x70), que está no intervalo de endereços protegido 0x70 - 0x71.
Isso pode causar instabilidade no sistema. Contate o fornecedor do sistema para
obter assistência técnica.
Error - 3/2/2012 17:58:23 | Computer Name = GTEC-A93A9F1435 | Source = ACPI | ID = 327684
Description = AMLI: o BIOS da ACPI está tentando ler um endereço de porta de E/S
(0x71) inválido, que está no intervalo de endereços protegido 0x70 - 0x71. Isso
pode causar instabilidade no sistema. Contate o fornecedor do sistema para obter
assistência técnica.
Error - 3/2/2012 18:03:39 | Computer Name = GTEC-A93A9F1435 | Source = sr | ID = 1
Description = O filtro da restauração do sistema encontrou o erro inesperado '0xC0000001'
ao processar o arquivo '' no volume 'HarddiskVolume1'. O monitoramento do volume
foi interrompido.
< End of report >
Abraços... :thumbsup:
Boa Noite! karoline ferreira
|- Abra o Firefox!
|- Vá em Ferramentas -> Opções -> Avançado -> Rede -> Configurar Conexão.
|- Clique em "Sem Proxy" -> Ok.
///°°°///
|- Baixe: < AdwCleaner > ( ... par Xplode )
|- Clique em Télécharger! < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/d210af57fdd8237cca69ae792bc6ffcff89cacc6c0ce5568f2a323e9d67c467a6g.jpg&key=0666191f94deb805495963fd1daa9b248aa5ffc251a3570a5be2e3c3f2247d34" alt="d210af57fdd8237cca69ae792bc6ffcff89cacc6c0ce5568f2a323e9d67c467a6g.jpg" /> >
|- Salve-o no desktop!
|- Dê início ao scan,clicando em "Recherche" < /applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/AdwCleaner_Suppression.jpg&key=ea7f314988c364d38f61f15aee7583e1c9e325cba8a0d859f1c7cd594582e777" alt="AdwCleaner_Suppression.jpg" /> >
|- Ao concluir,poste o relatório: C:\AdwCleaner[R].txt
///°°°///
|- Execute o OTL.exe.
|- Copie estas informações que estão em vermelho,para o campo clipboard da ferramenta. ( "Exames Personalizados Correções" )
>
:FilesC:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\searchplugins\conduit.xml
:OTL
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2836015&SearchSource=3&q={searchTerms}"
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O33 - MountPoints2\{ea1989a6-0570-11e1-b97b-001644da8ece}\Shell\AutoRun\command - "" = H:\setup.exe
[4 C:\WINDOWS\.tmp files -> C:\WINDOWS\.tmp -> ]
[1 C:\WINDOWS\System32\.tmp files -> C:\WINDOWS\System32\.tmp -> ]
:Commands
[emptyflash]
[emptytemp]
[reboot]
|- Clique no botão Consertar.
|- Ps: A ferramenta irá reiniciar o computador.
|- Ao surgir,clique em executar.
|- Poste o relatório: C:\_OTL\MovedFiles\*.log
Abraços!
>
Boa Noite! karoline ferreira
|- Abra o Firefox!
|- Vá em Ferramentas -> Opções -> Avançado -> Rede -> Configurar Conexão.
|- Clique em "Sem Proxy" -> Ok.
///°°°///
|- Baixe: < AdwCleaner > ( ... par Xplode )
|- Clique em Télécharger! < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/d210af57fdd8237cca69ae792bc6ffcff89cacc6c0ce5568f2a323e9d67c467a6g.jpg&key=0666191f94deb805495963fd1daa9b248aa5ffc251a3570a5be2e3c3f2247d34" alt="d210af57fdd8237cca69ae792bc6ffcff89cacc6c0ce5568f2a323e9d67c467a6g.jpg" /> >
|- Salve-o no desktop!
|- Dê início ao scan,clicando em "Recherche" < /applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/AdwCleaner_Suppression.jpg&key=ea7f314988c364d38f61f15aee7583e1c9e325cba8a0d859f1c7cd594582e777" alt="AdwCleaner_Suppression.jpg" /> >
|- Ao concluir,poste o relatório: C:\AdwCleaner[R].txt
///°°°///
|- Execute o OTL.exe.
|- Copie estas informações que estão em vermelho,para o campo clipboard da ferramenta. ( "Exames Personalizados Correções" )
|- Clique no botão Consertar.
|- Ps: A ferramenta irá reiniciar o computador.
|- Ao surgir,clique em executar.
|- Poste o relatório: C:\_OTL\MovedFiles\*.log
Abraços!
Bom Dia!! 'DigRam'
Fiz como você escreveu todos os passos,só que o OTL.exe não gerou relatório e nem reiniciou o meu pc,quando termina de consertar pedi para reiniciar o pc,clico em ok mais nada acontece.Não sei o que fazer!!! :upset: :cry:
Esse o relatório do AdwCleaner.
*** [services] ***
*** [Files / Folders] ***
Folder Found : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\ConduitCommon
File Found : C:\Arquivos de programas\Windows live\messenger\msimg32.dll
File Found : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\searchplugins\Conduit.xml
*** [Registry] ***
Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4
Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe
*** [internet Browsers] ***
-\\ Internet Explorer v6.0.2900.5512
[OK] Registry is clean.
-\\ Mozilla Firefox v9.0.1 (pt-BR)
Profile : 3o20c2zd.default
File : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\prefs.js
Found : user_pref("CT2836015..clientLogIsEnabled", false);
Found : user_pref("CT2836015..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2836015..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2836015.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT2836015.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2836015.AppTrackingLastCheckTime", "Thu Jan 26 2012 20:51:00 GMT-0200");
Found : user_pref("CT2836015.BrowserCompStateIsOpen_1000515", true);
Found : user_pref("CT2836015.CT2836015", "CT2836015");
Found : user_pref("CT2836015.CommunitiesChangesLastCheckTime", "0");
Found : user_pref("CT2836015.CurrentServerDate", "4-2-2012");
Found : user_pref("CT2836015.DSChangedManually", true);
Found : user_pref("CT2836015.DSInstall", true);
Found : user_pref("CT2836015.DialogsAlignMode", "LTR");
Found : user_pref("CT2836015.DialogsGetterLastCheckTime", "Fri Feb 03 2012 10:48:51 GMT-0200");
Found : user_pref("CT2836015.DownloadReferralCookieData", "{\"BannerName\":\"\",\"BannerTypeId\":\"\",\"Bann[...]
Found : user_pref("CT2836015.EMailNotifierPollDate", "Fri Nov 04 2011 13:37:48 GMT-0200 (Hora oficial do Bra[...]
Found : user_pref("CT2836015.EnableClickToSearchBox", false);
Found : user_pref("CT2836015.EnableSearchHistory", false);
Found : user_pref("CT2836015.EnableSearchSuggest", false);
Found : user_pref("CT2836015.FirstServerDate", "4-11-2011");
Found : user_pref("CT2836015.FirstTime", true);
Found : user_pref("CT2836015.FirstTimeFF3", true);
Found : user_pref("CT2836015.FixPageNotFoundErrors", false);
Found : user_pref("CT2836015.GroupingInvalidateCache", false);
Found : user_pref("CT2836015.GroupingLastCheckTime", "0");
Found : user_pref("CT2836015.GroupingLastServerUpdateTime", "0");
Found : user_pref("CT2836015.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2836015.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2836015.HPInstall", false);
Found : user_pref("CT2836015.HasUserGlobalKeys", true);
Found : user_pref("CT2836015.HomePageProtectorEnabled", false);
Found : user_pref("CT2836015.HomepageBeforeUnload", "chrome://branding/locale/browserconfig.properties");
Found : user_pref("CT2836015.Initialize", true);
Found : user_pref("CT2836015.InitializeCommonPrefs", true);
Found : user_pref("CT2836015.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT2836015.InstallationType", "DirectDownload");
Found : user_pref("CT2836015.InstalledDate", "Fri Nov 04 2011 13:37:38 GMT-0200 (Hora oficial do Brasil)");
Found : user_pref("CT2836015.InvalidateCache", false);
Found : user_pref("CT2836015.IsAlertDBUpdated", true);
Found : user_pref("CT2836015.IsGrouping", false);
Found : user_pref("CT2836015.IsInitSetupIni", true);
Found : user_pref("CT2836015.IsMulticommunity", false);
Found : user_pref("CT2836015.IsOpenThankYouPage", true);
Found : user_pref("CT2836015.IsOpenUninstallPage", true);
Found : user_pref("CT2836015.IsProtectorsInit", true);
Found : user_pref("CT2836015.LanguagePackLastCheckTime", "Fri Feb 03 2012 17:37:10 GMT-0200");
Found : user_pref("CT2836015.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2836015.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2836015.LastLogin_3.8.0.8", "Mon Dec 05 2011 13:14:53 GMT-0200");
Found : user_pref("CT2836015.LastLogin_3.8.1.0", "Sun Jan 08 2012 13:45:56 GMT-0200");
Found : user_pref("CT2836015.LastLogin_3.9.0.3", "Fri Feb 03 2012 20:14:09 GMT-0200");
Found : user_pref("CT2836015.LatestVersion", "3.9.0.3");
Found : user_pref("CT2836015.Locale", "en");
Found : user_pref("CT2836015.MCDetectTooltipHeight", "83");
Found : user_pref("CT2836015.MCDetectTooltipShow", false);
Found : user_pref("CT2836015.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2836015.MCDetectTooltipWidth", "295");
Found : user_pref("CT2836015.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT2836015.OriginalFirstVersion", "3.8.0.8");
Found : user_pref("CT2836015.RadioIsPodcast", false);
Found : user_pref("CT2836015.RadioLastCheckTime", "0");
Found : user_pref("CT2836015.RadioLastUpdateIPServer", "0");
Found : user_pref("CT2836015.RadioLastUpdateServer", "0");
Found : user_pref("CT2836015.RadioMediaID", "6827");
Found : user_pref("CT2836015.RadioMediaType", "Media Player");
Found : user_pref("CT2836015.RadioMenuSelectedID", "EBRadioMenu_CT28360156827");
Found : user_pref("CT2836015.RadioShrinkedFromSetup", false);
Found : user_pref("CT2836015.RadioStationName", "Boa%20Vista");
Found : user_pref("CT2836015.RadioStationURL", "hxxp://200.202.254.131/radio/radio.asx");
Found : user_pref("CT2836015.SHRINK_TOOLBAR", 1);
Found : user_pref("CT2836015.SearchBackToDefaultEngine", false);
Found : user_pref("CT2836015.SearchCaption", "Stardoll Customized Web Search");
Found : user_pref("CT2836015.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Found : user_pref("CT2836015.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2836015.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT283[...]
Found : user_pref("CT2836015.SearchInNewTabEnabled", true);
Found : user_pref("CT2836015.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2836015.SearchInNewTabLastCheckTime", "Fri Feb 03 2012 17:36:02 GMT-0200");
Found : user_pref("CT2836015.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2836015.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
Found : user_pref("CT2836015.SearchInNewTabUserEnabled", false);
Found : user_pref("CT2836015.SearchProtectorEnabled", false);
Found : user_pref("CT2836015.SearchProtectorToolbarDisabled", false);
Found : user_pref("CT2836015.SendProtectorDataViaLogin", true);
Found : user_pref("CT2836015.ServiceMapLastCheckTime", "Fri Feb 03 2012 20:14:09 GMT-0200");
Found : user_pref("CT2836015.SettingsLastCheckTime", "Fri Feb 03 2012 23:45:09 GMT-0200");
Found : user_pref("CT2836015.SettingsLastUpdate", "1326723880");
Found : user_pref("CT2836015.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2836015&SearchSource=13");
Found : user_pref("CT2836015.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2836015.ThirdPartyComponentsLastCheck", "Sat Jan 28 2012 12:53:32 GMT-0200");
Found : user_pref("CT2836015.ThirdPartyComponentsLastUpdate", "1312887586");
Found : user_pref("CT2836015.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT2836015.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2836015");
Found : user_pref("CT2836015.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT2836015.UserID", "UN42829468452553987");
Found : user_pref("CT2836015.ValidationData_Search", 2);
Found : user_pref("CT2836015.ValidationData_Toolbar", 2);
Found : user_pref("CT2836015.WeatherNetwork", "");
Found : user_pref("CT2836015.WeatherPollDate", "Fri Feb 03 2012 23:15:39 GMT-0200");
Found : user_pref("CT2836015.WeatherUnit", "C");
Found : user_pref("CT2836015.alertChannelId", "1228076");
Found : user_pref("CT2836015.approveUntrustedApps", true);
Found : user_pref("CT2836015.backendstorage.for_aoi", "31333238333037363732");
Found : user_pref("CT2836015.backendstorage.for_ccid", "6E756C6C");
Found : user_pref("CT2836015.backendstorage.for_cdtr6", "31333238333037363732");
Found : user_pref("CT2836015.backendstorage.for_cid", "4252");
Found : user_pref("CT2836015.backendstorage.for_ip", "3138372E34312E3234372E3336");
Found : user_pref("CT2836015.backendstorage.for_lcut", "31333238333037363732");
Found : user_pref("CT2836015.backendstorage.for_rid", "3133");
Found : user_pref("CT2836015.backendstorage.for_zoneid", "37383138");
Found : user_pref("CT2836015.componentAlertEnabled", false);
Found : user_pref("CT2836015.components.1000034", false);
Found : user_pref("CT2836015.components.1000082", false);
Found : user_pref("CT2836015.components.1000234", true);
Found : user_pref("CT2836015.components.1000515", false);
Found : user_pref("CT2836015.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT2836015.globalFirstTimeInfoLastCheckTime", "Fri Jan 27 2012 12:31:31 GMT-0200");
Found : user_pref("CT2836015.homepageProtectorEnableByLogin", true);
Found : user_pref("CT2836015.initDone", true);
Found : user_pref("CT2836015.isAppTrackingManagerOn", true);
Found : user_pref("CT2836015.isFirstRadioInstallation", false);
Found : user_pref("CT2836015.isSearchProtectorNotifyChanges", false);
Found : user_pref("CT2836015.myStuffEnabled", true);
Found : user_pref("CT2836015.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2836015.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2836015.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2836015.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2836015.oldAppsList", "129336860020050106,129336860020050107,111,129351721820319552,100[...]
Found : user_pref("CT2836015.revertSettingsEnabled", true);
Found : user_pref("CT2836015.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT2836015.searchProtectorEnableByLogin", true);
Found : user_pref("CT2836015.testingCtid", "");
Found : user_pref("CT2836015.toolbarAppMetaDataLastCheckTime", "Fri Feb 03 2012 13:42:18 GMT-0200");
Found : user_pref("CT2836015.toolbarContextMenuLastCheckTime", "Sat Jan 21 2012 10:13:44 GMT-0200");
Found : user_pref("CT2836015.usageEnabled", false);
Found : user_pref("CT2836015.usagesFlag", 2);
Found : user_pref("CommunityToolbar.ConduitSearchList", "Stardoll Customized Web Search");
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2836015/CT2836015[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1228076/1223749/BR", "\"0\"[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2836015", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2836015",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2836015&octid=[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"cde[...]
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Documents and Settings\\Filho e karol\\Dad[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.9.0.3");
Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
Found : user_pref("CommunityToolbar.ToolbarsList", "CT2836015");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2836015");
Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2836015");
Found : user_pref("CommunityToolbar.globalUserId", "1a8d6af3-0778-455e-b198-8521e6646a04");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sat Jan 28 2012 12:53:3[...]
Found : user_pref("CommunityToolbar.notifications.alertEnabled", true);
Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Fri Feb 03 2012 23:45:09 GMT-020[...]
Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true);
Found : user_pref("CommunityToolbar.notifications.locale", "en");
Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Fri Feb 03 2012 20:14:09 GMT-0200");
Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.notifications.userId", "46e0e6c1-d93e-4c5c-b2eb-3afd6149ef0c");
Found : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
Found : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties[...]
Found : user_pref("browser.search.defaultthis.engineName", "Stardoll Customized Web Search");
Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2836015&Sea[...]
*************************
AdwCleaner[R1].txt - [15646 octets] - [03/02/2012 23:52:16]
########## EOF - C:\AdwCleaner[R1].txt - [15775 octets] ##########
Abraços.... :)
Boa Noite! karoline ferreira
|- Lance,novamente,AdwCleaner e clique em "Suppression" ou "Delete".
/applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/AdwCleaner_Suppression.jpg&key=ea7f314988c364d38f61f15aee7583e1c9e325cba8a0d859f1c7cd594582e777" alt="AdwCleaner_Suppression.jpg" />
|- Ao concluir,poste o relatório: C:\AdwCleaner[S].txt
///°°°///
|- Abra o OTL.exe -> Clique em Limpeza. <-- Confirme!
|- Ps: O computador irá reiniciar!
///°°°///
|- Baixe: < ToolbarShooter > ( ... de 2011N2 )
|- Salve-o no desktop!
|- Desabilite seu antivírus.
|- Execute a ferramenta,e escolha a opção 2. ( Suppression )
|- Ps: Para Windows Vista ou 7,execute-o como administrador!
|- Ao concluir,aperte Enter,para dispormos do relatório.
|- Poste o relatório: "Rapport de suppression de ToolbarShooter"
|- Poste,também,HijackThis atualizado.
Abraços!
>
Boa Noite! karoline ferreira
|- Lance,novamente,AdwCleaner e clique em "Suppression" ou "Delete".
/applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/AdwCleaner_Suppression.jpg&key=ea7f314988c364d38f61f15aee7583e1c9e325cba8a0d859f1c7cd594582e777" alt="AdwCleaner_Suppression.jpg" />
|- Ao concluir,poste o relatório: C:\AdwCleaner[S].txt
///°°°///
|- Abra o OTL.exe -> Clique em Limpeza. <-- Confirme!
|- Ps: O computador irá reiniciar!
///°°°///
|- Baixe: < ToolbarShooter > ( ... de 2011N2 )
|- Salve-o no desktop!
|- Desabilite seu antivírus.
|- Execute a ferramenta,e escolha a opção 2. ( Suppression )
|- Ps: Para Windows Vista ou 7,execute-o como administrador!
|- Ao concluir,aperte Enter,para dispormos do relatório.
|- Poste o relatório: "Rapport de suppression de ToolbarShooter"
|- Poste,também,HijackThis atualizado.
Abraços!
Boa Tarde!! DigRam....
*** [services] ***
*** [Files / Folders] ***
Folder Deleted : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\ConduitCommon
File Deleted : C:\Arquivos de programas\Windows live\messenger\msimg32.dll
File Deleted : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\searchplugins\Conduit.xml
*** [Registry] ***
Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4
Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe
*** [internet Browsers] ***
-\\ Internet Explorer v6.0.2900.5512
[OK] Registry is clean.
-\\ Mozilla Firefox v9.0.1 (pt-BR)
Profile : 3o20c2zd.default
File : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\prefs.js
Deleted : user_pref("CT2836015..clientLogIsEnabled", true);
Deleted : user_pref("CT2836015..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2836015..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2836015.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT2836015.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2836015.AppTrackingLastCheckTime", "Thu Jan 26 2012 20:51:00 GMT-0200");
Deleted : user_pref("CT2836015.BrowserCompStateIsOpen_1000515", true);
Deleted : user_pref("CT2836015.CT2836015", "CT2836015");
Deleted : user_pref("CT2836015.CommunitiesChangesLastCheckTime", "0");
Deleted : user_pref("CT2836015.CurrentServerDate", "6-2-2012");
Deleted : user_pref("CT2836015.DSChangedManually", true);
Deleted : user_pref("CT2836015.DSInstall", true);
Deleted : user_pref("CT2836015.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2836015.DialogsGetterLastCheckTime", "Fri Feb 03 2012 10:48:51 GMT-0200");
Deleted : user_pref("CT2836015.DownloadReferralCookieData", "{\"BannerName\":\"\",\"BannerTypeId\":\"\",\"Bann[...]
Deleted : user_pref("CT2836015.EMailNotifierPollDate", "Fri Nov 04 2011 13:37:48 GMT-0200 (Hora oficial do Bra[...]
Deleted : user_pref("CT2836015.EnableClickToSearchBox", false);
Deleted : user_pref("CT2836015.EnableSearchHistory", false);
Deleted : user_pref("CT2836015.EnableSearchSuggest", false);
Deleted : user_pref("CT2836015.FirstServerDate", "4-11-2011");
Deleted : user_pref("CT2836015.FirstTime", true);
Deleted : user_pref("CT2836015.FirstTimeFF3", true);
Deleted : user_pref("CT2836015.FixPageNotFoundErrors", false);
Deleted : user_pref("CT2836015.GroupingInvalidateCache", false);
Deleted : user_pref("CT2836015.GroupingLastCheckTime", "0");
Deleted : user_pref("CT2836015.GroupingLastServerUpdateTime", "0");
Deleted : user_pref("CT2836015.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2836015.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2836015.HPInstall", false);
Deleted : user_pref("CT2836015.HasUserGlobalKeys", true);
Deleted : user_pref("CT2836015.HomePageProtectorEnabled", false);
Deleted : user_pref("CT2836015.HomepageBeforeUnload", "chrome://branding/locale/browserconfig.properties");
Deleted : user_pref("CT2836015.Initialize", true);
Deleted : user_pref("CT2836015.InitializeCommonPrefs", true);
Deleted : user_pref("CT2836015.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2836015.InstallationType", "DirectDownload");
Deleted : user_pref("CT2836015.InstalledDate", "Fri Nov 04 2011 13:37:38 GMT-0200 (Hora oficial do Brasil)");
Deleted : user_pref("CT2836015.InvalidateCache", false);
Deleted : user_pref("CT2836015.IsAlertDBUpdated", true);
Deleted : user_pref("CT2836015.IsGrouping", false);
Deleted : user_pref("CT2836015.IsInitSetupIni", true);
Deleted : user_pref("CT2836015.IsMulticommunity", false);
Deleted : user_pref("CT2836015.IsOpenThankYouPage", true);
Deleted : user_pref("CT2836015.IsOpenUninstallPage", true);
Deleted : user_pref("CT2836015.IsProtectorsInit", true);
Deleted : user_pref("CT2836015.LanguagePackLastCheckTime", "Sun Feb 05 2012 19:13:26 GMT-0200");
Deleted : user_pref("CT2836015.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2836015.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2836015.LastLogin_3.8.0.8", "Mon Dec 05 2011 13:14:53 GMT-0200");
Deleted : user_pref("CT2836015.LastLogin_3.8.1.0", "Sun Jan 08 2012 13:45:56 GMT-0200");
Deleted : user_pref("CT2836015.LastLogin_3.9.0.3", "Mon Feb 06 2012 10:09:19 GMT-0200");
Deleted : user_pref("CT2836015.LatestVersion", "3.9.0.3");
Deleted : user_pref("CT2836015.Locale", "en");
Deleted : user_pref("CT2836015.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2836015.MCDetectTooltipShow", false);
Deleted : user_pref("CT2836015.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2836015.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2836015.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT2836015.OriginalFirstVersion", "3.8.0.8");
Deleted : user_pref("CT2836015.RadioIsPodcast", false);
Deleted : user_pref("CT2836015.RadioLastCheckTime", "0");
Deleted : user_pref("CT2836015.RadioLastUpdateIPServer", "0");
Deleted : user_pref("CT2836015.RadioLastUpdateServer", "0");
Deleted : user_pref("CT2836015.RadioMediaID", "6827");
Deleted : user_pref("CT2836015.RadioMediaType", "Media Player");
Deleted : user_pref("CT2836015.RadioMenuSelectedID", "EBRadioMenu_CT28360156827");
Deleted : user_pref("CT2836015.RadioShrinkedFromSetup", false);
Deleted : user_pref("CT2836015.RadioStationName", "Boa%20Vista");
Deleted : user_pref("CT2836015.RadioStationURL", "hxxp://200.202.254.131/radio/radio.asx");
Deleted : user_pref("CT2836015.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2836015.SearchBackToDefaultEngine", false);
Deleted : user_pref("CT2836015.SearchCaption", "Stardoll Customized Web Search");
Deleted : user_pref("CT2836015.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Deleted : user_pref("CT2836015.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2836015.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT283[...]
Deleted : user_pref("CT2836015.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2836015.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2836015.SearchInNewTabLastCheckTime", "Sun Feb 05 2012 19:13:25 GMT-0200");
Deleted : user_pref("CT2836015.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2836015.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
Deleted : user_pref("CT2836015.SearchInNewTabUserEnabled", false);
Deleted : user_pref("CT2836015.SearchProtectorEnabled", false);
Deleted : user_pref("CT2836015.SearchProtectorToolbarDisabled", false);
Deleted : user_pref("CT2836015.SendProtectorDataViaLogin", true);
Deleted : user_pref("CT2836015.ServiceMapLastCheckTime", "Mon Feb 06 2012 10:09:18 GMT-0200");
Deleted : user_pref("CT2836015.SettingsLastCheckTime", "Mon Feb 06 2012 10:09:55 GMT-0200");
Deleted : user_pref("CT2836015.SettingsLastUpdate", "1326723880");
Deleted : user_pref("CT2836015.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2836015&SearchSource=13");
Deleted : user_pref("CT2836015.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2836015.ThirdPartyComponentsLastCheck", "Sat Jan 28 2012 12:53:32 GMT-0200");
Deleted : user_pref("CT2836015.ThirdPartyComponentsLastUpdate", "1312887586");
Deleted : user_pref("CT2836015.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT2836015.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2836015");
Deleted : user_pref("CT2836015.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Deleted : user_pref("CT2836015.UserID", "UN42829468452553987");
Deleted : user_pref("CT2836015.ValidationData_Search", 2);
Deleted : user_pref("CT2836015.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2836015.WeatherNetwork", "");
Deleted : user_pref("CT2836015.WeatherPollDate", "Mon Feb 06 2012 10:09:19 GMT-0200");
Deleted : user_pref("CT2836015.WeatherUnit", "C");
Deleted : user_pref("CT2836015.alertChannelId", "1228076");
Deleted : user_pref("CT2836015.approveUntrustedApps", true);
Deleted : user_pref("CT2836015.backendstorage.for_aoi", "31333238333037363732");
Deleted : user_pref("CT2836015.backendstorage.for_ccid", "6E756C6C");
Deleted : user_pref("CT2836015.backendstorage.for_cdtr6", "31333238333037363732");
Deleted : user_pref("CT2836015.backendstorage.for_cid", "4252");
Deleted : user_pref("CT2836015.backendstorage.for_ip", "3138372E34302E37382E313436");
Deleted : user_pref("CT2836015.backendstorage.for_lcut", "31333238353330313738");
Deleted : user_pref("CT2836015.backendstorage.for_rid", "3133");
Deleted : user_pref("CT2836015.backendstorage.for_zoneid", "37383138");
Deleted : user_pref("CT2836015.componentAlertEnabled", false);
Deleted : user_pref("CT2836015.components.1000034", false);
Deleted : user_pref("CT2836015.components.1000082", false);
Deleted : user_pref("CT2836015.components.1000234", true);
Deleted : user_pref("CT2836015.components.1000515", false);
Deleted : user_pref("CT2836015.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT2836015.globalFirstTimeInfoLastCheckTime", "Fri Jan 27 2012 12:31:31 GMT-0200");
Deleted : user_pref("CT2836015.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT2836015.initDone", true);
Deleted : user_pref("CT2836015.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2836015.isFirstRadioInstallation", false);
Deleted : user_pref("CT2836015.isSearchProtectorNotifyChanges", false);
Deleted : user_pref("CT2836015.myStuffEnabled", true);
Deleted : user_pref("CT2836015.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2836015.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2836015.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2836015.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2836015.oldAppsList", "129336860020050106,129336860020050107,111,129351721820319552,100[...]
Deleted : user_pref("CT2836015.revertSettingsEnabled", true);
Deleted : user_pref("CT2836015.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT2836015.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT2836015.testingCtid", "");
Deleted : user_pref("CT2836015.toolbarAppMetaDataLastCheckTime", "Sun Feb 05 2012 19:13:26 GMT-0200");
Deleted : user_pref("CT2836015.toolbarContextMenuLastCheckTime", "Sat Feb 04 2012 10:27:24 GMT-0200");
Deleted : user_pref("CT2836015.usageEnabled", false);
Deleted : user_pref("CT2836015.usagesFlag", 2);
Deleted : user_pref("CommunityToolbar.ConduitSearchList", "Stardoll Customized Web Search");
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2836015/CT2836015[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1228076/1223749/BR", "\"0\"[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2836015", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2836015",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2836015&octid=[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"cde[...]
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Documents and Settings\\Filho e karol\\Dad[...]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.9.0.3");
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2836015");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2836015");
Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2836015");
Deleted : user_pref("CommunityToolbar.globalUserId", "1a8d6af3-0778-455e-b198-8521e6646a04");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sat Feb 04 2012 17:31:4[...]
Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", true);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Mon Feb 06 2012 10:09:55 GMT-020[...]
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true);
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Mon Feb 06 2012 10:09:18 GMT-0200");
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "46e0e6c1-d93e-4c5c-b2eb-3afd6149ef0c");
Deleted : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
Deleted : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties[...]
Deleted : user_pref("browser.search.defaultthis.engineName", "Stardoll Customized Web Search");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2836015&Sea[...]
*************************
AdwCleaner[R1].txt - [15777 octets] - [03/02/2012 23:52:16]
AdwCleaner[R2].txt - [15837 octets] - [04/02/2012 08:22:42]
AdwCleaner[s1].txt - [16139 octets] - [06/02/2012 14:02:18]
*************************
Temporary folder : : 14 folder(s) and 31 file(s) deleted
########## EOF - C:\AdwCleaner[s1].txt - [16358 octets] ##########
___________________________________________________________
=========== Informations ===========
Mis à jour le : 20/01/2012 à 19h45 par 2011N2
Rapport de suppression de ToolbarShooter par 2011N2
Contact : lot12@hotmail.fr
Site : http://2011n2.forumgratuit.fr/
Début du scan de suppression : 14:19:21
################################## Toolbars, pups et adwares néfastes supprimés ################################
Clé supprimée avec succès : HKLM\Software\Classes\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}
Clé supprimée avec succès : HKCR\CLSID\{72B3882F-453A-4633-AAC9-8C3DCED62AFF}
======== Page de démarrage Internet Explorer ========
Page de démarrage d'Internet Explorer restaurée avec succès.
===================================
Fin du nettoyage : 14:21:35
======== EOF ========
Merci d'envoyer le rapport à cette adresse, en précisant la raison d'emploi de cet outil. Cela permettera au développeur d'effectuer d'éventuelles modifications : lot12@hotmail.fr
Merci de votre contribution !
L'utilisateur à décidé de redémarrer l'ordinateur ultérieurement
_____________________________________________________________
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:39:02, on 6/2/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe
C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe
C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\WINDOWS\system32\rundll32.exe
C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe
C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Arquivos de programas\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARQUIV~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [synTPEnh] C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avast] "C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NielsenOnline] C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [PlusService] C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB001" /M "Stylus C45"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nielsen Update (NielsenUpdate) - The Nielsen Company - C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe
O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
--
End of file - 8470 bytes
Abraços...
Boa Tarde! karoline ferreira
|- Como está seu PC,tudo Ok?
///°°°///
|- Baixe: < ZHPDiag > ( ... par Nicolas Coolman )
|- Estando na página,clique em: < /applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/Tlcharger_ZHPDiag.jpg&key=88816ce0d223eab3298d8070b21eab527acf8ca8c0e91f236979078f33c528e9" alt="Tlcharger_ZHPDiag.jpg" /> >
|- Salve-o em Arquivos de programas.
|- Ps: Descompacte-o em Arquivos de programas.
|- Desabilite seu antivírus e execute "ZHPDiag2.exe". < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/b1213ab5b1c6c82da85cd782fc66e21829baa55668d621f18000599eb2f818666g.jpg&key=87999318949eb13eac70b5cc1f4abf7c046dc6f4161c785fd582e81d29f0eaf9" alt="b1213ab5b1c6c82da85cd782fc66e21829baa55668d621f18000599eb2f818666g.jpg" /> >
|- Ps: Siga os procedimentos na instalação.
|- Clique em /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/4804a19ee52052e68b5900ce67a6566890b7a2f79506eeabaac40aefe1d31a086g.jpg&key=6e30daef28f79652faba4d3c21df89ef533d07556b8471008122f7c23e2a0010" alt="4804a19ee52052e68b5900ce67a6566890b7a2f79506eeabaac40aefe1d31a086g.jpg" /> |-- Termine.
/applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/ZHPDiag_Pergaminho.jpg&key=b3d540bf3b350f97d67873bfea05861a2a13efba23dfa3fc29561b424b394ba1" alt="ZHPDiag_Pergaminho.jpg" />
|- Abra a ferramenta,clicando no ícone do pergaminho. ( ZHPDiag )
/applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/ZHPDiag_IconedoChapeu.jpg&key=dbb03d22d2f9c9c7859f6f28b2e95dc2cf46b90c98bd7329e4f2ba22509e8eb1" alt="ZHPDiag_IconedoChapeu.jpg" />
|- Escolha a opção de idiomas que desejar!
|- Atualize-a,clicando na seta verde. < /applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/ZHPDiag_Opes_Update.jpg&key=0cbb763c2ca50ab78fc29ea165a926eb3099320064ebcdb392bc33dbdf76efa7" alt="ZHPDiag_Opes_Update.jpg" /> >
|- Clique no ícone do 'capetinha!' < /applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/ZHPDiag_Icone_diabinho.jpg&key=066381406e6760522ec1aae79307adb2576e9befb54c0458ee0b9a403c4b499e" alt="ZHPDiag_Icone_diabinho.jpg" /> >
|- Poste o relatório: Rapport de ZHPScan
Abraços!
>
Boa Tarde! karoline ferreira
|- Como está seu PC,tudo Ok?
///°°°///
|- Baixe: < ZHPDiag > ( ... par Nicolas Coolman )
|- Estando na página,clique em: < /applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/Tlcharger_ZHPDiag.jpg&key=88816ce0d223eab3298d8070b21eab527acf8ca8c0e91f236979078f33c528e9" alt="Tlcharger_ZHPDiag.jpg" /> >
|- Salve-o em Arquivos de programas.
|- Ps: Descompacte-o em Arquivos de programas.
|- Desabilite seu antivírus e execute "ZHPDiag2.exe". < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/b1213ab5b1c6c82da85cd782fc66e21829baa55668d621f18000599eb2f818666g.jpg&key=87999318949eb13eac70b5cc1f4abf7c046dc6f4161c785fd582e81d29f0eaf9" alt="b1213ab5b1c6c82da85cd782fc66e21829baa55668d621f18000599eb2f818666g.jpg" /> >
|- Ps: Siga os procedimentos na instalação.
|- Clique em /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/4804a19ee52052e68b5900ce67a6566890b7a2f79506eeabaac40aefe1d31a086g.jpg&key=6e30daef28f79652faba4d3c21df89ef533d07556b8471008122f7c23e2a0010" alt="4804a19ee52052e68b5900ce67a6566890b7a2f79506eeabaac40aefe1d31a086g.jpg" /> |-- Termine.
/applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/ZHPDiag_Pergaminho.jpg&key=b3d540bf3b350f97d67873bfea05861a2a13efba23dfa3fc29561b424b394ba1" alt="ZHPDiag_Pergaminho.jpg" />
|- Abra a ferramenta,clicando no ícone do pergaminho. ( ZHPDiag )
/applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/ZHPDiag_IconedoChapeu.jpg&key=dbb03d22d2f9c9c7859f6f28b2e95dc2cf46b90c98bd7329e4f2ba22509e8eb1" alt="ZHPDiag_IconedoChapeu.jpg" />
|- Escolha a opção de idiomas que desejar!
|- Atualize-a,clicando na seta verde. < /applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/ZHPDiag_Opes_Update.jpg&key=0cbb763c2ca50ab78fc29ea165a926eb3099320064ebcdb392bc33dbdf76efa7" alt="ZHPDiag_Opes_Update.jpg" /> >
|- Clique no ícone do 'capetinha!' < /applications/core/interface/imageproxy/imageproxy.php?img=http://i1143.photobucket.com/albums/n629/j2ram/ZHPDiag_Icone_diabinho.jpg&key=066381406e6760522ec1aae79307adb2576e9befb54c0458ee0b9a403c4b499e" alt="ZHPDiag_Icone_diabinho.jpg" /> >
|- Poste o relatório: Rapport de ZHPScan
Abraços!
Boa Noite !! "DigRam"
Está mais rapido,quando ligo está carregando logo e nao esta mais travando como antes.
Rapport de ZHPDiag v1.28.32 par Nicolas Coolman, Update du 05/02/2012
Run by Filho e karol at 8/2/2012 20:11:22
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
Web site : http://nicolascoolman.skyrock.com/
State : Your version is update.
---\\ Web Browser
MSIE: Internet Explorer v6.0.2900.5512
MFIE: Mozilla Firefox 9.0.1 v9.0.1 (Defaut)
GCIE: Google Chrome v16.0.912.77
---\\ Windows Product Information
~ Langage: Anglais
Windows XP Professional Service Pack 3 (Build 2600)
Windows Automatic Updates : OK
Windows Genuine Advantage : OK
---\\ System Information
~ Processor: x86 Family 6 Model 22 Stepping 1, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 893 MB (70% free)
System Restore: Activé (Enable)
System drive C: has 29 GB (59%) free of 49 GB
---\\ Logged in mode
~ Computer Name: GTEC-A93A9F1435
~ User Name: Filho e karol
~ All Users Names: SUPPORT_388945a0, HelpAssistant, Filho e karol, Convidado, Administrador,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator
---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Documents and Settings\Filho e karol\Dados de aplicativos\
~ %Desktop% : C:\Documents and Settings\Filho e karol\Desktop\
~ %Favorites% : C:\Documents and Settings\Filho e karol\Favorites\
~ %LocalAppData% : C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\
~ %StartMenu% : C:\Documents and Settings\Filho e karol\Menu Iniciar\
~ %Windir% : C:\WINDOWS\
~ %System% : C:\WINDOWS\system32\
---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 29 Go of 49 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 63 Go of 63 Go)
E:\ CD-ROM drive (Not Inserted)
F:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : Out Of Date
~ Scan Security Center in 00mn 00s
---\\ Search Generic System Files
[MD5.064EC7FF5F58B928C3E119402977FA6D] - (.Microsoft Corporation - Windows Explorer.) (.13/4/2008 - 18:21:00.) -- C:\WINDOWS\Explorer.exe [1035776]
[MD5.E715412E47D20EB0EBF77B65F9157343] - (.Microsoft Corporation - Executa uma DLL como um aplicativo.) (.13/4/2008 - 18:21:18.) -- C:\WINDOWS\system32\rundll32.exe [33280]
[MD5.FE85EC0BCDC74A604A9A4C470DCD707E] - (.Microsoft Corporation - Internet Extensions para Win32.) (.1/11/2011 - 17:35:23.) -- C:\WINDOWS\system32\wininet.dll [669184]
[MD5.71D440F79B711627B12B567FB2EADB42] - (.Microsoft Corporation - Aplicativo de logon do Windows NT.) (.13/4/2008 - 18:21:24.) -- C:\WINDOWS\system32\Winlogon.exe [509952]
[MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.17/8/2011 - 10:49:54.) -- C:\WINDOWS\system32\drivers\AFD.sys [138496]
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.13/4/2008 - 10:40:32.) -- C:\WINDOWS\system32\drivers\atapi.sys [96512]
[MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) (.13/4/2008 - 11:14:22.) -- C:\WINDOWS\system32\drivers\Cdfs.sys [63744]
[MD5.1F4260CC5B42272D71F79E570A27A4FE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.13/4/2008 - 10:40:48.) -- C:\WINDOWS\system32\drivers\Cdrom.sys [62976]
[MD5.A8D31E836CCF2F51009CE7DFFECF6D51] - (.Microsoft Corporation - FIPS Crypto Driver.) (.13/4/2008 - 17:52:44.) -- C:\WINDOWS\system32\drivers\Fips.sys [44672]
[MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows ® Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) (.13/4/2008 - 08:36:06.) -- C:\WINDOWS\system32\drivers\HDAudBus.sys [144384]
[MD5.485BC6BEB778B5E9702E6AA3D384C0CB] - (.Microsoft Corporation - Driver de porta i8042.) (.13/4/2008 - 17:55:20.) -- C:\WINDOWS\system32\drivers\i8042prt.sys [53504]
[MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) (.13/4/2008 - 10:41:00.) -- C:\WINDOWS\system32\drivers\Imapi.sys [42112]
[MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) (.13/4/2008 - 10:57:16.) -- C:\WINDOWS\system32\drivers\IpNat.sys [152832]
[MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) (.13/4/2008 - 11:19:44.) -- C:\WINDOWS\system32\drivers\IPSec.sys [75264]
[MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.15/7/2011 - 10:29:31.) -- C:\WINDOWS\system32\drivers\MRxSmb.sys [456320]
[MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) (.13/4/2008 - 11:21:02.) -- C:\WINDOWS\system32\drivers\netBT.sys [162816]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.13/4/2008 - 11:15:54.) -- C:\WINDOWS\system32\drivers\ntfs.sys [574976]
[MD5.9BADEE6B698BF1AF36E25A1A64A89EAB] - (.Microsoft Corporation - Driver de porta paralela.) (.13/4/2008 - 18:02:26.) -- C:\WINDOWS\system32\drivers\Parport.sys [80384]
[MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.13/4/2008 - 11:19:44.) -- C:\WINDOWS\system32\drivers\Rasl2tp.sys [51328]
[MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.13/4/2008 - 10:32:52.) -- C:\WINDOWS\system32\drivers\rdpdr.sys [196224]
[MD5.68D749B04BFBBD4D4D15CC5185AFA4DD] - (.Microsoft Corporation - Redbook Audio Filter Driver.) (.13/4/2008 - 17:53:18.) -- C:\WINDOWS\system32\drivers\redbook.sys [58240]
[MD5.EB6B1E2C984D84470FF4FE7EF98CD44A] - (.Microsoft Corporation - Driver de cópia de sombra de volume.) (.13/4/2008 - 17:53:02.) -- C:\WINDOWS\system32\drivers\volsnap.sys [53248]
~ Scan Generic Processes in 00mn 00s
---\\ Hidden files state (Hidden/Total)
~ Mes images (My Pictures) : 3/359
~ Mes musiques (My Musics) : 29/458
~ Mes Videos (My Video) : 0/0
~ Mes Favoris (My Favorites) : Non accessible (Not found)
~ Mes Documents (My Documents) : 44/1540
~ Mon Bureau (My Desktop) : 1/21
~ Menu demarrer (Programs) : 6/38
~ Scan Hidden Files in 00mn 03s
---\\ Running Processes
[MD5.996E6D052438E8D8DFD501F31560B2E0] - (.AVAST Software - avast! Service.) -- C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe [44768] [PID.]
[MD5.F8DF5D4F62D5A6AA04D7D3FEB51D1D7E] - (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe [737369] [PID.1868]
[MD5.9C3CDB8964BA91FA3029508D870466DB] - (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.EXE [16860672] [PID.1876]
[MD5.89D583FC41D48328128A974C25AFAEB7] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe [185896] [PID.1892]
[MD5.F7226AA410954185160067D5FA82F3F2] - (.AVAST Software - avast! Antivirus.) -- C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe [3744552] [PID.1908]
[MD5.DE9BC3722D7846B594FD4602ABBDBCFB] - (.The Nielsen Company - NielsenOnline.) -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe [47424] [PID.1916]
[MD5.30183A68E8EFDE4CB7D65C815081DADA] - (.Yuna Software - Messenger Plus! 5.) -- C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe [801792] [PID.1952]
[MD5.ECE648CDC3A09421E996DFFDA76F5C53] - (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [153136] [PID.1988]
[MD5.525F03A1964CA81BF4B37256650E7498] - (.Silicon Integrated Systems Corporation - SiS Compatible Super VGA Tray Application.) -- C:\WINDOWS\system32\sistray.exe [262144] [PID.2000]
[MD5.056B19651BD7B7CE5F89A3AC46DBDC08] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe [652360] [PID.]
[MD5.33FEA967497E9F6B2457D1C4E8EB11A0] - (.The Nielsen Company - NielsenOnline.) -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe [306496] [PID.]
[MD5.060DAF68493AD7ADF104413E5A62AFA8] - (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe [271920] [PID.]
[MD5.B920AAF7ABEA489AC415DD38AD7B76CD] - (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe [1209904] [PID.3084]
[MD5.588E6EA6A56BEC337F5752E289BB942A] - (.Microsoft Corporation - Paint.) -- C:\WINDOWS\system32\mspaint.exe [345600] [PID.2280]
[MD5.B02C35F6E1DD6707C5976A9629B93A2E] - (.Nicolas Coolman - Nettoyeur de rapport ZHPDiag.) -- C:\Arquivos de programas\ZHPDiag\ZHPFix.exe [1438208] [PID.3412]
[MD5.4309B75F125067EF805F3125B01FCC30] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Arquivos de programas\ZHPDiag\ZHPDiag.exe [2210816] [PID.1016]
~ Scan Processes Running in 00mn 02s
---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (P2,M0,M1,M2,M3)
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.60831.0.) -- C:\Arquivos de programas\Microsoft Silverlight\4.0.60831.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/OfficeAuthz,version=14.0] - (.Microsoft Corporation - Office Authorization plug-in for NPAPI browsers.) -- C:\Arquivos de programas\Microsoft Office\Office14\NPAUTHZ.dll
P2 - FPN: [HKLM] [@microsoft.com/SharePoint,version=14.0] - (.Microsoft Corporation - The plug-in allows you to open and edit files using Microsoft Office a.) -- C:\Arquivos de programas\Microsoft Office\Office14\NPSPWRAP.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8117.0416] - (.Microsoft Corporation - NPWLPG.) -- C:\Arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@real.com/nppl3260;version=6.0.12.46] - (.RealNetworks, Inc. - RealPlayer LiveConnect-Enabled Plug-In.) -- C:\Arquivos de programas\Real\RealPlayer\Netscape6\nppl3260.dll
P2 - FPN: [HKLM] [@real.com/nprjplug;version=1.0.3.46] - (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprjplug.dll
P2 - FPN: [HKLM] [@real.com/nprpjplug;version=6.0.12.46] - (.RealNetworks, Inc. - 6.0.12.46.) -- C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprpjplug.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Arquivos de programas\Google\Update\1.3.21.99\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Arquivos de programas\Google\Update\1.3.21.99\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.2.) -- C:\Arquivos de programas\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
P2 - FPN: [HKCU] [@unity3d.com/UnityPlayer,version=1.0] - (.Unity Technologies ApS - Unity Player 2.6.1f3.) -- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Unity\WebPlayer\loader\npUnity3D32.dll
~ Scan Firefox Browser in 00mn 00s
---\\ Internet Explorer Extensions, Start, Search (R4,R3,R0,R1)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.fr
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Biblioteca Shell de controles e objetos-doc.) (6.00.2900.6168 (xpsp_sp3_gdr.111101-1829)) -- C:\WINDOWS\system32\shdocvw.dll
~ Scan IE Browser in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s
---\\ Changed inifile Value, Mapped to Registry (F2)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Scan Keys in 00mn 00s
---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Scan Hosts File in 00mn 00s
~ Nombre de lignes (Lines number): 19
---\\ Browser Helper Objects (O2)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} . (.RealPlayer - RealPlayer Download and Record Plugin for I.) -- C:\Arquivos de programas\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Orphean Key
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corp. - Microsoft Search Helper Extention.) -- C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Arquivos de programas\Microsoft Office\Office14\GROOVEEX.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Arquivos de programas\Microsoft Office\Office14\URLREDIR.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
~ Scan BHO in 00mn 00s
---\\ Internet Explorer toolbars (O3)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll
~ Scan Toolbar in 00mn 00s
---\\ Auto loading programs from Registry and folders (O4)
O4 - HKLM\..\Run: [siSPower] . (.Silicon Integrated Systems Corporation - Dynamic link library for setting Power Sche.) -- C:\WINDOWS\system32\SiSPower.dll
O4 - HKLM\..\Run: [synTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RTHDCPL] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.exe
O4 - HKLM\..\Run: [Alcmtr] . (.Realtek Semiconductor Corp. - Realtek Azalia Audio - Event Monitor.) -- C:\WINDOWS\Alcmtr.exe
O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] . (.Nero AG - NeroCheck.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Arquivos de programas\AVAST Software\Avast\AvastUI.exe
O4 - HKLM\..\Run: [NielsenOnline] . (.The Nielsen Company - NielsenOnline.) -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe
O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] bthprops.cpl
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [PlusService] . (.Yuna Software - Messenger Plus! 5.) -- C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKLM\..\Run: [ink Monitor] . (.Epson - Ink Monitor by Bill Pytlovany.) -- C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [EPSON Stylus C45 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I4T1.exe
O4 - HKCU\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-57989841-1085031214-839522115-1003\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-57989841-1085031214-839522115-1003\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
~ Scan Application in 00mn 00s
---\\ Other User Links (O4)
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk . (.Malwarebytes Corporation.) -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\MBRCheck.lnk . (...) -- C:\Arquivos de programas\ZHPDiag\mbrcheck.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Nero StartSmart Essentials.lnk . (.Nero AG.) -- C:\Arquivos de programas\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ZHPDiag.lnk . (.Nicolas Coolman.) -- C:\Arquivos de programas\ZHPDiag\ZHPDiag.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ZHPFix.lnk . (.Nicolas Coolman.) -- C:\Arquivos de programas\ZHPDiag\ZHPFix.exe
O4 - Global Startup: C:\Documents And Settings\Filho e karol\Desktop\DVD Flick.lnk . (.Dennis "Exl" Meuwissen.) -- C:\Arquivos de programas\DVD Flick\dvdflick.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk . (.Malwarebytes Corporation.) -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\MBRCheck.lnk . (...) -- C:\Arquivos de programas\ZHPDiag\mbrcheck.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Nero StartSmart Essentials.lnk . (.Nero AG.) -- C:\Arquivos de programas\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ZHPDiag.lnk . (.Nicolas Coolman.) -- C:\Arquivos de programas\ZHPDiag\ZHPDiag.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ZHPFix.lnk . (.Nicolas Coolman.) -- C:\Arquivos de programas\ZHPDiag\ZHPFix.exe
O4 - Global Startup: C:\Documents And Settings\Filho e karol\Desktop\DVD Flick.lnk . (.Dennis "Exl" Meuwissen.) -- C:\Arquivos de programas\DVD Flick\dvdflick.exe
~ Scan Global Startup in 00mn 00s
---\\ Extra items in the IE right-click menu (O8)
O8 - Extra context menu item: &Enviar para o OneNote . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll
O8 - Extra context menu item: E&xportar para o Microsoft Excel . (.Microsoft Corporation - Microsoft Excel.) -- C:\ARQUIV~1\MICROS~2\Office14\EXCEL.exe
~ Scan IE Menu Contextuel in 00mn 00s
---\\ Extra buttons on main IE button toolbar, or extra items in IE 'Tools' menu (O9)
O9 - Extra button: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\ARQUIV~1\MICROS~2\Office14\ONBTTN~1.dll
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Arquivos de programas\Messenger\msmsgs.exe
~ Scan IE Extra Buttons in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fornecedor de serviços do Microsoft Windows Sockets 2.0.) -- C:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fornecedor de serviços do Microsoft Windows Sockets 2.0.) -- C:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\WINDOWS\system32\wshBth.dll
~ Scan Winsock in 00mn 00s
---\\ ActiveX Objects (Downloaded Program Files) (O16)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
~ Scan Objets ActiveX in 00mn 00s
---\\ Lop.com/Domain Hijackers (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{129BC170-D18B-4D71-A3CE-166C42F67025}: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F344BE1-A5C6-4A31-989C-28C50E04E85D}: DhcpNameServer = 200.222.145.86 200.149.55.142
O17 - HKLM\System\CS1\Services\Tcpip\..\{129BC170-D18B-4D71-A3CE-166C42F67025}: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{4F344BE1-A5C6-4A31-989C-28C50E04E85D}: DhcpNameServer = 200.222.145.86 200.149.55.142
O17 - HKLM\System\CS3\Services\Tcpip\..\{129BC170-D18B-4D71-A3CE-166C42F67025}: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CS3\Services\Tcpip\..\{4F344BE1-A5C6-4A31-989C-28C50E04E85D}: DhcpNameServer = 200.222.145.86 200.149.55.142
~ Scan Domain in 00mn 00s
---\\ Extra protocols (O18)
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Controle ActiveX para fluxo de vídeo.) -- C:\WINDOWS\system32\msvidctl.dll
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API.) -- C:\WINDOWS\system32\inetcomm.dll
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll
O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Controle ActiveX para fluxo de vídeo.) -- C:\WINDOWS\system32\msvidctl.dll
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll
O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Arquivos de programas\Windows Live\Mail\mailcomm.dll
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\shell32.dll
O18 - Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\MSOXMLMF.dll
~ Scan Protocole Additionnel in 00mn 00s
---\\ AppInit_DLLs Registry value Autorun (O20)
O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll
O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll
O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agente de rede off-line.) -- C:\WINDOWS\system32\cscdll.dll
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\system32\dimsntfy.dll
O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL de notificação do serviço de logon secu.) -- C:\WINDOWS\system32\sclgntfy.dll
O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\WlNotify.dll
O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: WgaLogon . (...) -- WgaLogon.dll
O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll
~ Scan Winlogon in 00mn 00s
---\\ ShellServiceObjectDelayLoad (O21)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Monitor de sites da Web.) -- C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objeto de serviço do shell de Systray.) -- C:\WINDOWS\system32\stobject.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll
~ Scan SSODL in 00mn 00s
---\\ SharedTaskScheduler (O22)
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} . (.Microsoft Corporation - Biblioteca da interface de usuário do naveg.) -- C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Biblioteca da interface de usuário do naveg.) -- C:\WINDOWS\system32\browseui.dll
~ Scan STS/SSO in 00mn 00s
---\\ non Microsoft non disabled Windows XP/NT/2000 Services (O23)
O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nielsen Update (NielsenUpdate) . (.The Nielsen Company - NielsenOnline.) - C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe
~ Scan Services in 00mn 00s
---\\ Windows Active Desktop & MHTML Editor (O24)
O24 - Desktop Component 0: Minha página inicial atual - file:About:Home
O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Word.) - C:\Arquivos de programas\Microsoft Office\Office14\WINWORD.exe
~ Scan Desktop Component in 00mn 00s
---\\
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ Scan Keys in 00mn 00s
---\\ Task Planned Automatically(039)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
~ Scan Scheduled Task in 00mn 01s
---\\ ActiveSetup Installed Components (O40)
O40 - ASIC: Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Utilitário de Instalação do Microsoft Windows Media Player.) -- C:\WINDOWS\inf\unregmp2.exe
O40 - ASIC: Microsoft NetShow Player - {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\system32\wmpdxm.dll
O40 - ASIC: Microsoft Windows Media Player 6.4 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\system32\wmpdxm.dll
O40 - ASIC: DirectAnimation - {283807B5-2C60-11D0-A31D-00AA00B92C03} . (.Microsoft Corporation - Mídia DirectX -- DirectAnimation.) -- C:\WINDOWS\system32\danim.dll
O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (...) -- C:\WINDOWS\INF\msnetmtg.inf
O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (...) -- C:\WINDOWS\INF\msmsgs.inf
O40 - ASIC: Recursos de navegação - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extensão shell da pasta FTP do Microsoft Internet Explorer.) -- C:\WINDOWS\system32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (...) -- C:\WINDOWS\INF\wmp11.inf
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\WINDOWS\system32\mscories.dll
O40 - ASIC: Shockwave Flash - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 11.1 r102.) -- C:\WINDOWS\system32\Macromed\Flash\Flash11e.ocx
~ Scan Active Setup in 00mn 00s
---\\ Drivers launched at startup (O41)
O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys
O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\WINDOWS\system32\DRIVERS\cdrom.sys
O41 - Driver: (i8042prt) . (.Microsoft Corporation - Driver de porta i8042.) - C:\WINDOWS\system32\DRIVERS\i8042prt.sys
O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\WINDOWS\system32\DRIVERS\imapi.sys
O41 - Driver: (intelppm) . (.Microsoft Corporation - Driver de dispositivo de processador.) - C:\WINDOWS\system32\DRIVERS\intelppm.sys
O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\WINDOWS\system32\DRIVERS\ipsec.sys
O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Driver de classe teclado.) - C:\WINDOWS\system32\DRIVERS\kbdclass.sys
O41 - Driver: (Mouclass) . (.Microsoft Corporation - Driver de classe modem.) - C:\WINDOWS\system32\DRIVERS\mouclass.sys
O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\WINDOWS\system32\DRIVERS\netbios.sys
O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\WINDOWS\system32\DRIVERS\netbt.sys
O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\WINDOWS\system32\DRIVERS\rasacd.sys
O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\WINDOWS\system32\DRIVERS\rdbss.sys
O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
O41 - Driver: (redbook) . (.Microsoft Corporation - Redbook Audio Filter Driver.) - C:\WINDOWS\system32\DRIVERS\redbook.sys
O41 - Driver: (SiSkp) . (.Silicon Integrated Systems Corporation - SiS VGA Driver Manager.) - C:\WINDOWS\system32\DRIVERS\srvkp.sys
O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\WINDOWS\system32\DRIVERS\tcpip.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\WINDOWS\system32\DRIVERS\termdd.sys
O41 - Driver: Controlador de vídeo VGA. (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys
~ Scan Drivers in 00mn 00s
---\\ Software installed (O42)
O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
O42 - Logiciel: Adobe Reader X (10.1.2) - Português - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1046-7B44-AA1000000001}
O42 - Logiciel: Arquivo do WinRAR - (.Unknown owner.) [HKLM] -- WinRAR archiver
O42 - Logiciel: Assistente de Conexão do Windows Live - (.Microsoft Corporation.) [HKLM] -- {51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}
O42 - Logiciel: Atualização de Segurança para Microsoft Windows (KB2564958) - (.Microsoft Corporation.) [HKLM] -- KB2564958
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2079403) - (.Microsoft Corporation.) [HKLM] -- KB2079403
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2115168) - (.Microsoft Corporation.) [HKLM] -- KB2115168
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2229593) - (.Microsoft Corporation.) [HKLM] -- KB2229593
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2296011) - (.Microsoft Corporation.) [HKLM] -- KB2296011
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2347290) - (.Microsoft Corporation.) [HKLM] -- KB2347290
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2387149) - (.Microsoft Corporation.) [HKLM] -- KB2387149
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2393802) - (.Microsoft Corporation.) [HKLM] -- KB2393802
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2412687) - (.Microsoft Corporation.) [HKLM] -- KB2412687
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2419632) - (.Microsoft Corporation.) [HKLM] -- KB2419632
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2440591) - (.Microsoft Corporation.) [HKLM] -- KB2440591
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2443105) - (.Microsoft Corporation.) [HKLM] -- KB2443105
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2476490) - (.Microsoft Corporation.) [HKLM] -- KB2476490
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2478960) - (.Microsoft Corporation.) [HKLM] -- KB2478960
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2478971) - (.Microsoft Corporation.) [HKLM] -- KB2478971
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2479943) - (.Microsoft Corporation.) [HKLM] -- KB2479943
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2481109) - (.Microsoft Corporation.) [HKLM] -- KB2481109
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2483185) - (.Microsoft Corporation.) [HKLM] -- KB2483185
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2485663) - (.Microsoft Corporation.) [HKLM] -- KB2485663
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2506212) - (.Microsoft Corporation.) [HKLM] -- KB2506212
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2507618) - (.Microsoft Corporation.) [HKLM] -- KB2507618
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2507938) - (.Microsoft Corporation.) [HKLM] -- KB2507938
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2508272) - (.Microsoft Corporation.) [HKLM] -- KB2508272
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2508429) - (.Microsoft Corporation.) [HKLM] -- KB2508429
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2509553) - (.Microsoft Corporation.) [HKLM] -- KB2509553
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2510581) - (.Microsoft Corporation.) [HKLM] -- KB2510581
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2535512) - (.Microsoft Corporation.) [HKLM] -- KB2535512
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2536276-v2) - (.Microsoft Corporation.) [HKLM] -- KB2536276-v2
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2544521) - (.Microsoft Corporation.) [HKLM] -- KB2544521
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2544893) - (.Microsoft Corporation.) [HKLM] -- KB2544893
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2544893-v2) - (.Microsoft Corporation.) [HKLM] -- KB2544893-v2
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2562937) - (.Microsoft Corporation.) [HKLM] -- KB2562937
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2567053) - (.Microsoft Corporation.) [HKLM] -- KB2567053
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2567680) - (.Microsoft Corporation.) [HKLM] -- KB2567680
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2570222) - (.Microsoft Corporation.) [HKLM] -- KB2570222
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2570947) - (.Microsoft Corporation.) [HKLM] -- KB2570947
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2584146) - (.Microsoft Corporation.) [HKLM] -- KB2584146
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2585542) - (.Microsoft Corporation.) [HKLM] -- KB2585542
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2586448) - (.Microsoft Corporation.) [HKLM] -- KB2586448
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2592799) - (.Microsoft Corporation.) [HKLM] -- KB2592799
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2598479) - (.Microsoft Corporation.) [HKLM] -- KB2598479
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2603381) - (.Microsoft Corporation.) [HKLM] -- KB2603381
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2618444) - (.Microsoft Corporation.) [HKLM] -- KB2618444
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2618451) - (.Microsoft Corporation.) [HKLM] -- KB2618451
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2619339) - (.Microsoft Corporation.) [HKLM] -- KB2619339
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2620712) - (.Microsoft Corporation.) [HKLM] -- KB2620712
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2624667) - (.Microsoft Corporation.) [HKLM] -- KB2624667
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2631813) - (.Microsoft Corporation.) [HKLM] -- KB2631813
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2633171) - (.Microsoft Corporation.) [HKLM] -- KB2633171
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2639417) - (.Microsoft Corporation.) [HKLM] -- KB2639417
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2646524) - (.Microsoft Corporation.) [HKLM] -- KB2646524
O42 - Logiciel: Atualização de Segurança para Windows XP (KB923561) - (.Microsoft Corporation.) [HKLM] -- KB923561
O42 - Logiciel: Atualização de Segurança para Windows XP (KB923789) - (.Microsoft Corporation.) [HKLM] -- KB923789
O42 - Logiciel: Atualização de Segurança para Windows XP (KB941569) - (.Microsoft Corporation.) [HKLM] -- KB941569
O42 - Logiciel: Atualização de Segurança para Windows XP (KB946648) - (.Microsoft Corporation.) [HKLM] -- KB946648
O42 - Logiciel: Atualização de Segurança para Windows XP (KB950762) - (.Microsoft Corporation.) [HKLM] -- KB950762
O42 - Logiciel: Atualização de Segurança para Windows XP (KB950974) - (.Microsoft Corporation.) [HKLM] -- KB950974
O42 - Logiciel: Atualização de Segurança para Windows XP (KB951376-v2) - (.Microsoft Corporation.) [HKLM] -- KB951376-v2
O42 - Logiciel: Atualização de Segurança para Windows XP (KB952004) - (.Microsoft Corporation.) [HKLM] -- KB952004
O42 - Logiciel: Atualização de Segurança para Windows XP (KB952954) - (.Microsoft Corporation.) [HKLM] -- KB952954
O42 - Logiciel: Atualização de Segurança para Windows XP (KB954459) - (.Microsoft Corporation.) [HKLM] -- KB954459
O42 - Logiciel: Atualização de Segurança para Windows XP (KB956572) - (.Microsoft Corporation.) [HKLM] -- KB956572
O42 - Logiciel: Atualização de Segurança para Windows XP (KB956744) - (.Microsoft Corporation.) [HKLM] -- KB956744
O42 - Logiciel: Atualização de Segurança para Windows XP (KB956802) - (.Microsoft Corporation.) [HKLM] -- KB956802
O42 - Logiciel: Atualização de Segurança para Windows XP (KB956844) - (.Microsoft Corporation.) [HKLM] -- KB956844
O42 - Logiciel: Atualização de Segurança para Windows XP (KB958644) - (.Microsoft Corporation.) [HKLM] -- KB958644
O42 - Logiciel: Atualização de Segurança para Windows XP (KB959426) - (.Microsoft Corporation.) [HKLM] -- KB959426
O42 - Logiciel: Atualização de Segurança para Windows XP (KB960803) - (.Microsoft Corporation.) [HKLM] -- KB960803
O42 - Logiciel: Atualização de Segurança para Windows XP (KB960859) - (.Microsoft Corporation.) [HKLM] -- KB960859
O42 - Logiciel: Atualização de Segurança para Windows XP (KB961501) - (.Microsoft Corporation.) [HKLM] -- KB961501
O42 - Logiciel: Atualização de Segurança para Windows XP (KB969059) - (.Microsoft Corporation.) [HKLM] -- KB969059
O42 - Logiciel: Atualização de Segurança para Windows XP (KB971657) - (.Microsoft Corporation.) [HKLM] -- KB971657
O42 - Logiciel: Atualização de Segurança para Windows XP (KB972270) - (.Microsoft Corporation.) [HKLM] -- KB972270
O42 - Logiciel: Atualização de Segurança para Windows XP (KB973507) - (.Microsoft Corporation.) [HKLM] -- KB973507
O42 - Logiciel: Atualização de Segurança para Windows XP (KB973869) - (.Microsoft Corporation.) [HKLM] -- KB973869
O42 - Logiciel: Atualização de Segurança para Windows XP (KB973904) - (.Microsoft Corporation.) [HKLM] -- KB973904
O42 - Logiciel: Atualização de Segurança para Windows XP (KB974112) - (.Microsoft Corporation.) [HKLM] -- KB974112
O42 - Logiciel: Atualização de Segurança para Windows XP (KB974318) - (.Microsoft Corporation.) [HKLM] -- KB974318
O42 - Logiciel: Atualização de Segurança para Windows XP (KB974392) - (.Microsoft Corporation.) [HKLM] -- KB974392
O42 - Logiciel: Atualização de Segurança para Windows XP (KB974571) - (.Microsoft Corporation.) [HKLM] -- KB974571
O42 - Logiciel: Atualização de Segurança para Windows XP (KB975025) - (.Microsoft Corporation.) [HKLM] -- KB975025
O42 - Logiciel: Atualização de Segurança para Windows XP (KB975560) - (.Microsoft Corporation.) [HKLM] -- KB975560
O42 - Logiciel: Atualização de Segurança para Windows XP (KB975562) - (.Microsoft Corporation.) [HKLM] -- KB975562
O42 - Logiciel: Atualização de Segurança para Windows XP (KB975713) - (.Microsoft Corporation.) [HKLM] -- KB975713
O42 - Logiciel: Atualização de Segurança para Windows XP (KB977816) - (.Microsoft Corporation.) [HKLM] -- KB977816
O42 - Logiciel: Atualização de Segurança para Windows XP (KB977914) - (.Microsoft Corporation.) [HKLM] -- KB977914
O42 - Logiciel: Atualização de Segurança para Windows XP (KB978338) - (.Microsoft Corporation.) [HKLM] -- KB978338
O42 - Logiciel: Atualização de Segurança para Windows XP (KB978542) - (.Microsoft Corporation.) [HKLM] -- KB978542
O42 - Logiciel: Atualização de Segurança para Windows XP (KB978601) - (.Microsoft Corporation.) [HKLM] -- KB978601
O42 - Logiciel: Atualização de Segurança para Windows XP (KB978706) - (.Microsoft Corporation.) [HKLM] -- KB978706
O42 - Logiciel: Atualização de Segurança para Windows XP (KB979309) - (.Microsoft Corporation.) [HKLM] -- KB979309
O42 - Logiciel: Atualização de Segurança para Windows XP (KB979482) - (.Microsoft Corporation.) [HKLM] -- KB979482
O42 - Logiciel: Atualização de Segurança para Windows XP (KB979687) - (.Microsoft Corporation.) [HKLM] -- KB979687
O42 - Logiciel: Atualização de Segurança para Windows XP (KB980436) - (.Microsoft Corporation.) [HKLM] -- KB980436
O42 - Logiciel: Atualização de Segurança para Windows XP (KB981322) - (.Microsoft Corporation.) [HKLM] -- KB981322
O42 - Logiciel: Atualização de Segurança para Windows XP (KB981997) - (.Microsoft Corporation.) [HKLM] -- KB981997
O42 - Logiciel: Atualização de Segurança para Windows XP (KB982132) - (.Microsoft Corporation.) [HKLM] -- KB982132
O42 - Logiciel: Atualização de Segurança para Windows XP (KB982665) - (.Microsoft Corporation.) [HKLM] -- KB982665
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB2378111) - (.Microsoft Corporation.) [HKLM] -- KB2378111_WM9
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB952069) - (.Microsoft Corporation.) [HKLM] -- KB952069_WM9
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB954155) - (.Microsoft Corporation.) [HKLM] -- KB954155_WM9
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB973540) - (.Microsoft Corporation.) [HKLM] -- KB973540_WM9
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB975558) - (.Microsoft Corporation.) [HKLM] -- KB975558_WM8
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB978695) - (.Microsoft Corporation.) [HKLM] -- KB978695_WM9
O42 - Logiciel: Atualização de Segurança para o Windows Media Player 11 (KB954154) - (.Microsoft Corporation.) [HKLM] -- KB954154_WM11
O42 - Logiciel: Atualização para Windows XP (KB2541763) - (.Microsoft Corporation.) [HKLM] -- KB2541763
O42 - Logiciel: Atualização para Windows XP (KB2616676-v2) - (.Microsoft Corporation.) [HKLM] -- KB2616676-v2
O42 - Logiciel: Atualização para Windows XP (KB2641690) - (.Microsoft Corporation.) [HKLM] -- KB2641690
O42 - Logiciel: Atualização para Windows XP (KB898461) - (.Microsoft Corporation.) [HKLM] -- KB898461
O42 - Logiciel: Atualização para Windows XP (KB951978) - (.Microsoft Corporation.) [HKLM] -- KB951978
O42 - Logiciel: Atualização para Windows XP (KB955759) - (.Microsoft Corporation.) [HKLM] -- KB955759
O42 - Logiciel: Atualização para Windows XP (KB961503) - (.Microsoft Corporation.) [HKLM] -- KB961503
O42 - Logiciel: Atualização para Windows XP (KB971029) - (.Microsoft Corporation.) [HKLM] -- KB971029
O42 - Logiciel: Atualização para Windows XP (KB973687) - (.Microsoft Corporation.) [HKLM] -- KB973687
O42 - Logiciel: Atualização para Windows XP (KB973815) - (.Microsoft Corporation.) [HKLM] -- KB973815
O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
O42 - Logiciel: DVD Flick 1.3.0.7 - (.Dennis Meuwissen.) [HKLM] -- DVD Flick_is1
O42 - Logiciel: Definition update for Microsoft Office 2010 (KB982726) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EFBA0F11-6CF9-4611-BFD4-648FA4EBE8C1}
O42 - Logiciel: DivX - (.DivXNetworks, Inc..) [HKLM] -- {7B63B2922B174135AFC0E1377DD81EC2}
O42 - Logiciel: DivX Player - (.DivXNetworks, Inc..) [HKLM] -- {8ADFC4160D694100B5B8A22DE9DCABD9}
O42 - Logiciel: Ferramenta de Carregamento do Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: High Definition Audio Driver Package - KB888111 - (.Microsoft Corporation.) [HKLM] -- KB888111WXPSP2
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
O42 - Logiciel: Hotfix for Windows Media Format 11 SDK (KB929399) - (.Microsoft Corporation.) [HKLM] -- KB929399
O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5
O42 - Logiciel: Hotfix para Windows XP (KB2570791) - (.Microsoft Corporation.) [HKLM] -- KB2570791
O42 - Logiciel: Hotfix para Windows XP (KB2633952) - (.Microsoft Corporation.) [HKLM] -- KB2633952
O42 - Logiciel: Hotfix para Windows XP (KB952287) - (.Microsoft Corporation.) [HKLM] -- KB952287
O42 - Logiciel: Hotfix para Windows XP (KB961118) - (.Microsoft Corporation.) [HKLM] -- KB961118
O42 - Logiciel: Hotfix para o Windows Media Player 11 (KB939683) - (.Microsoft Corporation.) [HKLM] -- KB939683
O42 - Logiciel: Ink Monitor - (.Unknown owner.) [HKLM] -- Ink Monitor
O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {8E5233E1-7495-44FB-8DEB-4BE906D59619}
O42 - Logiciel: L&H Power Translator Pro 7.0 - (.Unknown owner.) [HKLM] -- L&H Power Translator Pro 7.0
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Malwarebytes Anti-Malware versão 1.60.1.1000 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
O42 - Logiciel: Messenger Plus! 5 - (.Yuna Software.) [HKLM] -- Messenger Plus!
O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1
O42 - Logiciel: Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 - (.Microsoft Corporation.) [HKLM] -- Wdf01007
O42 - Logiciel: Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 - (.Microsoft Corporation.) [HKLM] -- Wdf01009
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0015-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0016-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0018-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0019-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-001A-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-001B-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-001F-0416-0000-0000000FF1CE}_Office14.PROPLUS_{A7200E61-DC93-42E0-BB74-EE59021016EA}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-002C-0416-0000-0000000FF1CE}_Office14.PROPLUS_{13291F79-D997-49AD-9F31-5FAEE1F0FCF5}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0044-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-006E-0416-0000-0000000FF1CE}_Office14.PROPLUS_{2134F8C8-2AD8-44EE-B86B-1B577FBD8D0E}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-00A1-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}
O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-00BA-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}
O42 - Logiciel: Microsoft Office Access MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0015-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0016-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00BA-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0044-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00A1-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001A-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0018-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Professional Plus 2010 - (.Microsoft Corporation.) [HKLM] -- Office14.PROPLUS
O42 - Logiciel: Microsoft Office Professional Plus 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0409-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Spanish) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0C0A-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-002C-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0019-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-006E-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Word MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001B-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
O42 - Logiciel: Microsoft Search Enhancement Pack - (.Microsoft Corporation.) [HKLM] -- {9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Microsoft Sync Framework Runtime Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {8A74E887-8F0F-4017-AF53-CBA42211AAA5}
O42 - Logiciel: Microsoft Sync Framework Services Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 - (.Microsoft Corporation.) [HKLM] -- {9BE518E6-ECC6-35A9-88E4-87755C07200F}
O42 - Logiciel: Mozilla Firefox 9.0.1 (x86 pt-BR) - (.Mozilla.) [HKLM] -- Mozilla Firefox 9.0.1 (x86 pt-BR)
O42 - Logiciel: Nero 7 Essentials - (.Nero AG.) [HKLM] -- {66EBD70F-A42C-475F-AEDF-277378151046}
O42 - Logiciel: Nielsen - (.Unknown owner.) [HKLM] -- NetSight
O42 - Logiciel: PowerDVD - (.Unknown owner.) [HKLM] -- {6811CAA0-BF12-11D4-9EA1-0050BAE317E1}
O42 - Logiciel: QuickTime Alternative 1.77 - (.Unknown owner.) [HKLM] -- QuicktimeAlt_is1
O42 - Logiciel: REALTEK USB Wireless LAN Driver - (.REALTEK Semiconductor Corp..) [HKLM] -- {7095FD27-37F0-4750-9DE8-D37DC0043706}
O42 - Logiciel: RealPlayer - (.RealNetworks.) [HKLM] -- RealPlayer 6.0
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Realtek USB 2.0 Card Reader - (.Realtek Semiconductor Corp..) [HKLM] -- {DC24971E-1946-445D-8A82-CE685433FA7D}
O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2657424
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2553091) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{07CA44F3-F5B3-4D12-8C91-EDC5FE91D45C}
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2553096) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{10802A6D-EDBF-4383-BCBD-9D5B32F56D35}
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2553353) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{02421C16-2C31-47F8-81FA-CF3B25999D31}
O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DCE6D0BF-93E4-46C5-9A7C-F1EFF9707C02}
O42 - Logiciel: Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{61461470-8168-4F4B-97B7-617AF354F028}
O42 - Logiciel: Security Update for Microsoft SharePoint Workspace 2010 (KB2566445) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{337A3FB9-281D-4EC8-9CC1-7F6DDAC2359F}
O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
O42 - Logiciel: SiS VGA Utilities - (.Unknown owner.) [HKLM] -- SiS VGA Driver
O42 - Logiciel: SiSAGP driver - (.Unknown owner.) [HKLM] -- {DC226AC9-0314-496C-BE6A-B6A132628466}
O42 - Logiciel: Software para Impressoras EPSON - (.Unknown owner.) [HKLM] -- EPSON Printer and Utilities
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: Unity Web Player - (.Unity Technologies ApS.) [HKCU] -- UnityWebPlayer
O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
O42 - Logiciel: Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{3D1F379C-AA64-4823-90A4-A8DDD4B48C21}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553065) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{A8686D24-1E89-43A1-973E-05A258D2B3F8}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553092) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7AC49FC8-F8D2-4DD8-9086-09E52385A21F}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{48E1B6C2-7299-4F3F-AA63-42F0ACE55AA4}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{17E7B9AB-2DD2-457D-8D8E-CD14ACA973FE}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001F-0416-0000-0000000FF1CE}_Office14.PROPLUS_{ACBCC818-8E67-43A8-B877-A821A3C6FAD2}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{995A7832-B512-46D5-87C9-2D71FB541435}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{C8694FF0-8203-483B-A07A-2BC40433167D}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-006E-0416-0000-0000000FF1CE}_Office14.PROPLUS_{BDE8DD25-D017-443C-AD04-B4FC21489EFB}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{28FAC187-7C0E-413A-B90A-76F19D0FBF30}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2553455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{147E3669-1EA6-454C-B53E-A2BE51D8E520}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2566458) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EFB525A0-E1C0-4E32-9968-FE401BC87363}
O42 - Logiciel: Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{ED31DE9A-3E13-4E2C-9106-E0D8AFFB9FA6}
O42 - Logiciel: Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BEBC2484-290C-46AD-9834-6DAD1FA80273}
O42 - Logiciel: Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-00A1-0416-0000-0000000FF1CE}_Office14.PROPLUS_{435C0D41-8F38-42CE-9DCB-23676CB6A6A1}
O42 - Logiciel: Update for Microsoft Outlook 2010 (KB2553323) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{29E94638-D92F-4C40-BDA1-FEDCC92F478D}
O42 - Logiciel: Update for Microsoft Outlook Social Connector (KB2583935) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EDF9874C-9E37-4110-9FC3-094247E114DF}
O42 - Logiciel: Update for Microsoft Outlook Social Connector (KB2583935) - (.Microsoft.) [HKLM] -- {90140000-001A-0416-0000-0000000FF1CE}_Office14.PROPLUS_{4DA00DA4-FD2B-4FC2-B351-E712FC3EA458}
O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify
O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {590035D9-BFA0-406A-A7F0-479C72C0DDB2}
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {3175E049-F9A9-4A3D-8F19-AC9FB04514D1}
O42 - Logiciel: Windows Live Essentials - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
O42 - Logiciel: Windows Live Essentials - (.Microsoft Corporation.) [HKLM] -- {0FFEA8EE-7BC7-4C9D-8CC6-5B8C891BA3F2}
O42 - Logiciel: Windows Live Galeria de Fotos - (.Microsoft Corporation.) [HKLM] -- {87A9C015-C2BA-44EE-9C20-6E1A764B8E23}
O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {74AD1846-2010-4FB1-8E24-B6F2B87150C2}
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {9ADC3E4F-34DA-48CD-8727-BB26D90257BD}
O42 - Logiciel: Windows Live Sync - (.Microsoft Corporation.) [HKLM] -- {2DF215E0-BD3C-4C98-8616-AFEF09747285}
O42 - Logiciel: Windows Live Toolbar - (.Microsoft Corporation.) [HKLM] -- {C50BF854-E881-434F-9C67-5A73EBB58F06}
O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {9555B4ED-09A3-4722-8E8C-57A49401D059}
O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11
O42 - Logiciel: Windows Media Format 11 runtime - (.Unknown owner.) [HKLM] -- Windows Media Format Runtime
O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM] -- wmp11
O42 - Logiciel: Windows Media Player 11 - (.Unknown owner.) [HKLM] -- Windows Media Player
O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM] -- Windows XP Service Pack
O42 - Logiciel: XP Codec Pack - (.Unknown owner.) [HKLM] -- XP Codec Pack
O42 - Logiciel: XviD 1.1 final uninstall - (.XviD team (Koepi).) [HKLM] -- XviD_is1
O42 - Logiciel: avast! Free Antivirus - (.AVAST Software.) [HKLM] -- avast
O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}
---\\ HKCU & HKLM Software Keys
[HKCU\Software\AC3Filter]
[HKCU\Software\AVAST Software]
[HKCU\Software\Adobe]
[HKCU\Software\Ahead]
[HKCU\Software\Audacity]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\Cyberlink]
[HKCU\Software\DivXNetworks]
[HKCU\Software\EPSON]
[HKCU\Software\GNU]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\IM Providers]
[HKCU\Software\Intel]
[HKCU\Software\L&H]
[HKCU\Software\Lake]
[HKCU\Software\Macromedia]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Netscape]
[HKCU\Software\ODBC]
[HKCU\Software\Piriform]
[HKCU\Software\Policies]
[HKCU\Software\RealNetworks]
[HKCU\Software\Realtek]
[HKCU\Software\RtWLan]
[HKCU\Software\Softonic]
[HKCU\Software\Synaptics]
[HKCU\Software\Unity]
[HKCU\Software\VB and VBA Program Settings]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\Windows Live Writer]
[HKCU\Software\XP Codec Pack]
[HKCU\Software\Yuna Software]
[HKLM\Software\AVAST Software]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Ahead]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Audible]
[HKLM\Software\C07ft5Y]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\CyberLink]
[HKLM\Software\DivXNetworks]
[HKLM\Software\EPSON]
[HKLM\Software\GNU]
[HKLM\Software\Gabest]
[HKLM\Software\Gemplus]
[HKLM\Software\Google]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\L&H Language Technology]
[HKLM\Software\L&H]
[HKLM\Software\Lake]
[HKLM\Software\Macromedia]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\NSCPID]
[HKLM\Software\Nero]
[HKLM\Software\NetRatingsNetSight]
[HKLM\Software\ODBC]
[HKLM\Software\Piriform]
[HKLM\Software\Policies]
[HKLM\Software\Program Groups]
[HKLM\Software\QTAlternative]
[HKLM\Software\RealNetworks]
[HKLM\Software\Realtek Semiconductor Corp.]
[HKLM\Software\Realtek USB 2.0 Card Reader]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\RichFX]
[HKLM\Software\RtWLan]
[HKLM\Software\Schlumberger]
[HKLM\Software\Secure]
[HKLM\Software\Set8187B]
[HKLM\Software\SiS]
[HKLM\Software\Silicon Integrated Systems Corp.]
[HKLM\Software\Synaptics]
[HKLM\Software\TrendMicro]
[HKLM\Software\WinRAR]
[HKLM\Software\Windows 3.1 Migration Status]
[HKLM\Software\Xing Technology Corp.]
[HKLM\Software\Yuna Software]
[HKLM\Software\mozilla.org]
~ Scan Softwares in 00mn 01s
---\\ Contents of the Common Files folders (O43)
O43 - CFD: 17/1/2012 - 22:35:50 - [1,532] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Adobe
O43 - CFD: 10/12/2011 - 22:22:28 - [0,063] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Ahead
O43 - CFD: 19/1/2012 - 15:31:58 - [0,026] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Audacity
O43 - CFD: 19/11/2011 - 10:44:30 - [0,002] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\CyberLink
O43 - CFD: 13/12/2011 - 12:52:14 - [0,010] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\DVD Flick
O43 - CFD: 2/11/2011 - 14:26:16 - [0] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Identities
O43 - CFD: 2/11/2011 - 14:28:44 - [0] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\InstallShield
O43 - CFD: 2/11/2011 - 16:21:02 - [7,817] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Macromedia
O43 - CFD: 20/11/2011 - 00:01:48 - [0] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Malwarebytes
O43 - CFD: 17/1/2012 - 22:35:50 - [17,995] -S--D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Microsoft
O43 - CFD: 2/11/2011 - 14:57:42 - [19,853] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla
O43 - CFD: 2/11/2011 - 23:30:56 - [1,577] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Real
O43 - CFD: 5/12/2011 - 23:34:08 - [0] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Windows Live Writer
O43 - CFD: 21/11/2011 - 19:35:06 - [0,000] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\WinRAR
O43 - CFD: 9/11/2011 - 17:57:08 - [14,194] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Adobe
O43 - CFD: 19/1/2012 - 15:56:10 - [8,841] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Ahead
O43 - CFD: 2/11/2011 - 16:00:06 - [24,287] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google
O43 - CFD: 2/11/2011 - 16:27:14 - [0,508] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Identities
O43 - CFD: 5/2/2012 - 19:27:32 - [194,695] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Microsoft
O43 - CFD: 2/11/2011 - 15:01:58 - [0] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Microsoft Help
O43 - CFD: 2/11/2011 - 14:57:30 - [300,501] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Mozilla
O43 - CFD: 7/11/2011 - 06:38:50 - [0] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\PCHealth
O43 - CFD: 17/1/2012 - 22:35:50 - [0] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Temp
O43 - CFD: 25/1/2012 - 09:38:46 - [11,033] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Unity
O43 - CFD: 5/12/2011 - 23:34:18 - [0,620] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Windows Live Writer
O43 - CFD: 19/1/2012 - 15:57:50 - [0] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\WMTools Downloaded Files
~ Scan Program Folder in 00mn 16s
---\\ Last modified or created files under Windows and System32 (O44)
O44 - LFC:[MD5.C64209D282FC5F67AAEE6B5E34838CF5] - 13/1/2005 - 14:28:50 ---A- . (...) -- C:\WINDOWS\system32\PulseSoundTouchForVB.tlb [6832]
O44 - LFC:[MD5.5B9277B9DB672E59B94E81D6D8F98507] - 17/5/2005 - 14:37:10 ---A- . (...) -- C:\WINDOWS\system32\Faac.exe [76800]
O44 - LFC:[MD5.E6FD64139902D0B84C174EDCDBE50FB9] - 17/6/2008 - 22:42:48 ---A- . (...) -- C:\WINDOWS\system32\activesoundeditor.tlb [98708]
O44 - LFC:[MD5.97C1831B9D872F6EA5FA44013F045878] - 19/1/2012 - 14:38:35 ---A- . (.MultiMedia Soft - AdjMmsEng DLL.) -- C:\WINDOWS\system32\AdjMmsEng.dll [1343488]
O44 - LFC:[MD5.B3ECA5E1BDA96380F1D2741D82FE3161] - 19/7/2002 - 10:48:22 ---A- . (...) -- C:\WINDOWS\system32\OggEnc.exe [157696]
O44 - LFC:[MD5.7DE09AA2D6D215D55B09CBB3995F2249] - 23/1/2012 - 18:58:43 ---A- . (...) -- C:\WINDOWS\EPSMTL32.TXT [62]
O44 - LFC:[MD5.53C58B79608BAA3F312CF4CB980AAAEC] - 23/1/2012 - 19:01:34 ---A- . (.SEIKO EPSON CORPORATION - EBAPI SAgent4 control module.) -- C:\WINDOWS\system32\E_SAGSET.DLL [91648]
O44 - LFC:[MD5.287D9CFC80A94E62437E7CAC7EB32979] - 23/1/2012 - 19:01:34 ---A- . (.SEIKO EPSON CORPORATION - ECBTEG.) -- C:\WINDOWS\system32\ECBTEG.DLL [64000]
O44 - LFC:[MD5.2F615DBB76AB23885FCFBF0BD261B63D] - 23/1/2012 - 19:01:34 ---A- . (.SEIKO EPSON CORPORATION - EPSON Bi-directional Monitor.) -- C:\WINDOWS\system32\EBPMON24.DLL [76054]
O44 - LFC:[MD5.3670675EEA8136995287DFB1B7650A5D] - 23/1/2012 - 19:01:35 ---A- . (.SEIKO EPSON CORPORATION - EPSON Bidirectional Printer Driver.) -- C:\WINDOWS\system32\EBPCHP.DLL [34304]
O44 - LFC:[MD5.0FA14D47B02F83B2AE8E062BC052F3A1] - 23/1/2012 - 19:02:02 ---A- . (...) -- C:\WINDOWS\EPSC45.ini [66]
O44 - LFC:[MD5.DE1BBC132C4CD3BC888C23391EB9B6F4] - 3/2/2012 - 22:58:01 ---A- . (...) -- C:\AdwCleaner[R1].txt [15777]
O44 - LFC:[MD5.DF1CD0873CDD372A982C43C649B7CF3F] - 4/2/2012 - 07:22:48 ---A- . (...) -- C:\AdwCleaner[R2].txt [15837]
O44 - LFC:[MD5.93E4B4C54DC3391C9988592C5075B9F3] - 4/9/2001 - 07:04:00 ---A- . (...) -- C:\WINDOWS\system32\EBPPORT4.DAT [182]
O44 - LFC:[MD5.6B6BE3176D58A76DA4F335EDF5A75289] - 5/11/2005 - 17:34:50 ---A- . (...) -- C:\WINDOWS\system32\Lame.exe [145408]
O44 - LFC:[MD5.C7BC96C3711C0D269DA26D1F0ECEC547] - 5/2/2012 - 10:09:52 ---A- . (...) -- C:\WINDOWS\NeroDigital.ini [69]
O44 - LFC:[MD5.C860C14AD78CBA1FDFA522AA479DE48F] - 5/2/2012 - 18:32:42 ---A- . (...) -- C:\WINDOWS\setuplog.txt [58232]
O44 - LFC:[MD5.872312FCA646788B6FECC961FB142063] - 6/2/2012 - 13:02:24 ---A- . (...) -- C:\AdwCleaner[s1].txt [16360]
O44 - LFC:[MD5.D49C570A7965F89EDCC58D3E6E66A9E2] - 6/2/2012 - 13:38:25 ---A- . (...) -- C:\ToolbarShooterSUP.txt [371]
O44 - LFC:[MD5.77FA2588DA3E3612ADD5D76CEC0C886E] - 6/2/2012 - 13:39:02 ---A- . (...) -- C:\hijackthis.log [8471]
O44 - LFC:[MD5.8E6248733A459FEC71F0320DE4060F73] - 7/2/2012 - 08:17:42 ---A- . (...) -- C:\WINDOWS\system32\FNTCACHE.DAT [280536]
O44 - LFC:[MD5.2237D037AEF103C364407F8153689971] - 7/2/2012 - 15:45:54 ---A- . (...) -- C:\WINDOWS\setupapi.log [4160]
O44 - LFC:[MD5.EDD163C469DCD74AC84CF6CAADE22C29] - 8/2/2012 - 08:23:48 ---A- . (...) -- C:\WINDOWS\system32\wpa.dbl [2262]
O44 - LFC:[MD5.4BF4034C7EAA76470E3353E833B5FC2D] - 8/2/2012 - 16:58:08 ---A- . (...) -- C:\WINDOWS\SchedLgU.Txt [32574]
O44 - LFC:[MD5.FACC8686A1F458B7F32CE774266EC74A] - 8/2/2012 - 16:58:11 ---A- . (...) -- C:\WINDOWS\WindowsUpdate.log [1226777]
O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 8/2/2012 - 17:34:37 -S-A- . (...) -- C:\WINDOWS\bootstat.dat [2048]
O44 - LFC:[MD5.0C398AF83BEE23B9C529369163BDE66F] - 8/2/2012 - 17:34:59 ---A- . (...) -- C:\RTHDCPL_Dump.txt [558]
O44 - LFC:[MD5.AE04D54D548E897F8298B38E891201D4] - 8/2/2012 - 17:35:03 ---A- . (...) -- C:\WINDOWS\wiaservc.log [48]
O44 - LFC:[MD5.ACAF83EAF237EE40B7B5FDE61C8A388C] - 8/2/2012 - 17:35:04 ---A- . (...) -- C:\WINDOWS\wiadebug.log [159]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 8/2/2012 - 17:35:05 ---A- . (...) -- C:\WINDOWS\0.log [0]
~ Scan Files in 00mn 04s
---\\ Export authorized application key (O47)
O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gerenciador de sessão de ajuda de área de trabalho remota da Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.EXE" [Enabled] .(.Microsoft Corporation - Microsoft SharePoint Workspace.) -- C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Microsoft Office\Office14\ONENOTE.EXE" [Enabled] .(.Microsoft Corporation - Microsoft OneNote.) -- C:\Arquivos de programas\Microsoft Office\Office14\ONENOTE.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Microsoft Office\Office14\OUTLOOK.EXE" [Enabled] .(.Microsoft Corporation - Microsoft Outlook.) -- C:\Arquivos de programas\Microsoft Office\Office14\OUTLOOK.exe
O47 - AAKE:Key Export SP - "C:\Documents and Settings\Filho e karol\Configurações locais\Temp\196.tmp\KMService.exe" [Enabled] .(...) -- C:\Documents and Settings\Filho e karol\Configurações locais\Temp\196.tmp\KMService.exe (.not file.)
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Microsoft Corporation - Windows Live Sync.) -- C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe
O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gerenciador de sessão de ajuda de área de trabalho remota da Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export DP - "C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe
O47 - AAKE:Key Export DP - "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
O47 - AAKE:Key Export DP - "C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Microsoft Corporation - Windows Live Sync.) -- C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe
~ Scan Keys in 00mn 00s
---\\ Local Security Authority-LSA Deny (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Mecanismo cliente do 'Editor de configuração de segurança Windows'.) -- C:\WINDOWS\system32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Kerberos Security Package.) -- C:\WINDOWS\system32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\WINDOWS\system32\wdigest.dll
~ Scan Keys in 00mn 00s
---\\ Safe Boot Control (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmboot.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmboot.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmio.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager I/O Driver.) -- C:\WINDOWS\system32\Drivers\dmio.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sr.sys . (.Microsoft Corporation - Driver de filtro do sistema de arquivos da restauração do sistema.) -- C:\WINDOWS\system32\Drivers\sr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\Wdf01000.sys . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) -- C:\WINDOWS\system32\Drivers\Wdf01000.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmboot.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmboot.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmio.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager I/O Driver.) -- C:\WINDOWS\system32\Drivers\dmio.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ip6fw.sys . (.Microsoft Corporation - IPv6 Windows Firewall Driver.) -- C:\WINDOWS\system32\Drivers\ip6fw.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\system32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpcdd.sys . (.Microsoft Corporation - RDP Miniport.) -- C:\WINDOWS\system32\Drivers\rdpcdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpdd.sys . (...) -- C:\WINDOWS\system32\Drivers\rdpdd.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpwd.sys . (.Microsoft Corporation - RDP Terminal Stack Driver (US/Canada Only, Not for Export).) -- C:\WINDOWS\system32\Drivers\rdpwd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sr.sys . (.Microsoft Corporation - Driver de filtro do sistema de arquivos da restauração do sistema.) -- C:\WINDOWS\system32\Drivers\sr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdpipe.sys . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdpipe.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdtcp.sys . (.Microsoft Corporation - TCP Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdtcp.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\Wdf01000.sys . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) -- C:\WINDOWS\system32\Drivers\Wdf01000.sys
~ Scan CSB in 00mn 00s
---\\ Image File Execution Options (IFEO) (O50)
O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d
~ Scan IFEO in 00mn 00s
---\\ MountPoints2 Shell Key (MPKS) (O51) (None)
---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec de áudio DSP Group TrueSpeech para MSACM V3.50.) -- C:\WINDOWS\system32\tssoft32.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\system32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\WINDOWS\system32\ir41_32.ax
O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm
O52 - TDSD: \Drivers32\"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\WINDOWS\system32\ir50_32.dll
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.DIVX"="DivX.dll" . (.DivXNetworks, Inc. - DivX® Codec for Windows.) -- C:\WINDOWS\system32\DivX.dll
O52 - TDSD: \Drivers32\"vidc.ffds"="ffdshow.ax" . (.Unknown owner - DirectShow and VFW video and audio decoding/encoding/processing filter.) -- C:\WINDOWS\system32\ffdshow.ax
O52 - TDSD: \Drivers32\"vidc.XVID"="xvidvfw.dll" . (...) -- C:\WINDOWS\system32\xvidvfw.dll
O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm
O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \drivers.desc\"ir50_32.dll"="Indeo® video 5.10" . (...) -- (.not file.)
O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \drivers.desc\"DivX.dll"="DivX 5.2.1 Codec" . (...) -- (.not file.)
O52 - TDSD: \drivers.desc\"xvidvfw.dll"="XviD MPEG-4 Video Codec" . (...) -- C:\WINDOWS\system32\xvidvfw.dll
~ Scan Keys in 00mn 00s
---\\ ShareTools MSconfig StartupReg (SMSR) (O53) (None)
---\\ Microsoft Control Security Providers (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Cliente DPA para plataformas de 32 bits.) -- C:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Digest SSPI Authentication Package.) -- C:\WINDOWS\system32\digest.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Cliente DPA para plataformas de 32 bits.) -- C:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Digest SSPI Authentication Package.) -- C:\WINDOWS\system32\digest.dll
~ Scan Keys in 00mn 00s
---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
~ Scan Keys in 00mn 00s
---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
~ Scan Keys in 00mn 00s
---\\ System Drivers List (SDL) (O58)
O58 - SDL:[MD5.B6DE0336F9F4B687B4FF57939F7B657A] - 28/11/2011 - 14:48:49 ---A- . (.AVAST Software - avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP.) -- C:\WINDOWS\system32\drivers\aavmker4.sys [30808]
O58 - SDL:[MD5.054DF24C92B55427E0757CFFF160E4F2] - 28/11/2011 - 14:51:50 ---A- . (.AVAST Software - avast! File System Access Blocking Driver.) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys [20568]
O58 - SDL:[MD5.05A9CF1C69B553260C4927E33F0BF3EC] - 28/11/2011 - 14:51:59 ---A- . (.AVAST Software - avast! File System Filter Driver for Windows NT/2000.) -- C:\WINDOWS\system32\drivers\aswmon.sys [105176]
O58 - SDL:[MD5.EF0E9AD83380724BD6FBBB51D2D0F5B8] - 28/11/2011 - 14:52:02 ---A- . (.AVAST Software - avast! File System Filter Driver for Windows XP.) -- C:\WINDOWS\system32\drivers\aswmon2.sys [111320]
O58 - SDL:[MD5.352D5A48EBAB35A7693B048679304831] - 28/11/2011 - 14:52:19 ---A- . (.AVAST Software - avast! TDI RDR Driver.) -- C:\WINDOWS\system32\drivers\aswRdr.sys [34392]
O58 - SDL:[MD5.8D34D2B24297E27D93E847319ABFDEC4] - 28/11/2011 - 14:53:53 ---A- . (.AVAST Software - avast! Virtualization Driver.) -- C:\WINDOWS\system32\drivers\aswSnx.sys [435032]
O58 - SDL:[MD5.010012597333DA1F46C3243F33F8409E] - 28/11/2011 - 14:53:35 ---A- . (.AVAST Software - avast! self protection module.) -- C:\WINDOWS\system32\drivers\aswSP.sys [314456]
O58 - SDL:[MD5.F9F84364416658E9786235904D448D37] - 28/11/2011 - 14:52:16 ---A- . (.AVAST Software - avast! TDI Filter Driver.) -- C:\WINDOWS\system32\drivers\aswTdi.sys [52952]
O58 - SDL:[MD5.B0A67DE1A128389AEA4D42C5A56215FD] - 17/8/2011 - 08:56:22 ---A- . (.Nokia - Nokia USB Phone Bus Driver.) -- C:\WINDOWS\system32\drivers\ccdcmb.sys [18176]
O58 - SDL:[MD5.DA6675E1400D58412C93180F8651A9FB] - 11/1/2000 - 19:38:34 ---A- . (.RAVISENT Technologies Inc. - CineMaster C 1.2 WDM Main Driver.) -- C:\WINDOWS\system32\drivers\cinemst2.sys [262528]
O58 - SDL:[MD5.9624293E55AD405415862B504CA95B73] - 11/1/2000 - 19:38:34 ---A- . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINDOWS\system32\drivers\cpqdap01.sys [11776]
O58 - SDL:[MD5.D59657714E1C85A6584663970C052CB6] - 4/10/2010 - 16:57:16 ---A- . (.The Nielsen Company - Audio Filter Driver.) -- C:\WINDOWS\system32\drivers\km_filter.sys [10368]
O58 - SDL:[MD5.B7CA8CC3F978201856B6AB82F40953C3] - 10/12/2011 - 14:24:06 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\system32\drivers\mbam.sys [20464]
O58 - SDL:[MD5.BE984D604D91C217355CDD3737AAD25D] - 11/1/2000 - 19:38:34 ---A- . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINDOWS\system32\drivers\nikedrv.sys [12032]
O58 - SDL:[MD5.66F6952248ECE6B791629BA6C1FF7568] - 4/10/2010 - 16:57:20 ---A- . (.The Nielsen Company - NNRNSTDI helper driver.) -- C:\WINDOWS\system32\drivers\nnrnstdi.sys [15360]
O58 - SDL:[MD5.80D317BD1C3DBC5D4FE7B1678C60CADD] - 11/1/2000 - 19:38:34 ---A- . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Library.) -- C:\WINDOWS\system32\drivers\ptilink.sys [17792]
O58 - SDL:[MD5.A56FE08EC7473E8580A390BB1081CDD7] - 11/1/2000 - 19:38:34 ---A- . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINDOWS\system32\drivers\rio8drv.sys [12032]
O58 - SDL:[MD5.0A854DF84C77A0BE205BFEAB2AE4F0EC] - 11/1/2000 - 19:38:34 ---A- . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINDOWS\system32\drivers\riodrv.sys [12032]
O58 - SDL:[MD5.811B31E0E0AC7BE484EFBFFC42AFCBBE] - 20/12/2007 - 17:00:06 R---- . (.Realtek Semiconductor Corp. - Realtek® High Definition Audio Function Driver.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys [4637696]
O58 - SDL:[MD5.1C507A537140FA2E1FC6AB832901EC04] - 1/6/2007 - 02:06:42 R---- . (.Realtek Semiconductor Corporation - Realtek RTL8187B NDIS Driver.) -- C:\WINDOWS\system32\drivers\rtl8187B.sys [238976]
O58 - SDL:[MD5.362CB1D7498216F7B2686FDC5BBBA58C] - 18/9/2007 - 14:08:22 ---A- . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP.) -- C:\WINDOWS\system32\drivers\RTSTOR.sys [44032]
O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 13/4/2008 - 08:39:18 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\WINDOWS\system32\drivers\secdrv.sys [20480]
O58 - SDL:[MD5.37DAA9F59A3FF30A314FD98EE8F47000] - 20/12/2006 - 01:00:00 R--A- . (.Silicon Integrated Systems Corp. - NDIS 5.1 Miniport Driver for SiS191/SiS190 Ethernet Device.) -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys [41600]
O58 - SDL:[MD5.DFF19DFD9AC111C7C68162CAAE96A203] - 25/6/2007 - 05:49:08 R--A- . (.Silicon Integrated Systems Corporation - SiS Compatible Super VGA Driver.) -- C:\WINDOWS\system32\drivers\sisgrp.sys [321536]
O58 - SDL:[MD5.6FAF3014EE1CC1A5146A5D2B29F94B8C] - 25/6/2007 - 06:10:28 R--A- . (.Silicon Integrated Systems Corporation - SiS VGA Driver Manager.) -- C:\WINDOWS\system32\drivers\srvkp.sys [18432]
O58 - SDL:[MD5.9D7385AD343EEED23A61D4AC5AE44601] - 25/8/2005 - 12:12:56 ---A- . (.Synaptics, Inc. - Synaptics Touchpad Driver.) -- C:\WINDOWS\system32\drivers\SynTP.sys [191168]
O58 - SDL:[MD5.D74A8EC75305F1D3CFDE7C7FC1BD62A9] - 11/1/2000 - 19:38:34 ---A- . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINDOWS\system32\drivers\tsbvcap.sys [21376]
O58 - SDL:[MD5.55E01061C74A8CEFFF58DC36114A8D3F] - 11/1/2000 - 19:38:34 ---A- . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\system32\drivers\vdmindvd.sys [58112]
O58 - SDL:[MD5.C1E76718BAB6BCA0D18E5670F074F821] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ansi.sys [9032]
O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\country.sys [27097]
O58 - SDL:[MD5.912150FE88E79AFEE0BB72216FAB2617] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\himem.sys [4896]
O58 - SDL:[MD5.582BCDD47CF4B68B5CB528F18E3CB808] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\key01.sys [42809]
O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 3/8/2004 - 22:46:56 ---A- . (...) -- C:\WINDOWS\system32\keyboard.sys [42537]
O58 - SDL:[MD5.19D4F0DAD3F393C13DE7F849ADE72EFE] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ntdos.sys [27900]
O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ntdos404.sys [29146]
O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ntdos411.sys [29370]
O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ntdos412.sys [29274]
O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ntdos804.sys [29146]
O58 - SDL:[MD5.86BB7AF2533B342B8E274590AD2190FA] - 3/8/2004 - 22:45:20 ---A- . (...) -- C:\WINDOWS\system32\ntio.sys [33984]
O58 - SDL:[MD5.6F73F50162DEF60C84B725C18CD9140F] - 3/8/2004 - 22:45:16 ---A- . (...) -- C:\WINDOWS\system32\ntio404.sys [34560]
O58 - SDL:[MD5.0FDD5E69C1FF3B58043D44F2CC743D45] - 3/8/2004 - 22:45:12 ---A- . (...) -- C:\WINDOWS\system32\ntio411.sys [35648]
O58 - SDL:[MD5.8842837C4D8311BF8E72BEE8CCC42217] - 3/8/2004 - 22:45:16 ---A- . (...) -- C:\WINDOWS\system32\ntio412.sys [35424]
O58 - SDL:[MD5.6B56CEB3C6F9D5CD7293DBD9FE23B311] - 3/8/2004 - 22:45:14 ---A- . (...) -- C:\WINDOWS\system32\ntio804.sys [34560]
~ Scan Drivers in 00mn 03s
---\\ List all tools cleaner (LATC) (O63)
O63 - Logiciel: ZHPDiag 1.28 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
O63 - Logiciel: OTL - (.OldTimer.)
~ Scan ADS in 00mn 00s
---\\ List all legacy services(LALS) (O64)
O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\Aavmker4.sys (Aavmker4) .(.AVAST Software - avast! Base Kernel-Mode Device Driver for W.) - LEGACY_AAVMKER4
O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswFsBlk.sys (aswFsBlk) .(.AVAST Software - avast! File System Access Blocking Driver.) - LEGACY_ASWFSBLK
O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswMon2.sys (aswMon2) .(.AVAST Software - avast! File System Filter Driver for Window.) - LEGACY_ASWMON2
O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswRdr.sys (aswRdr) .(.AVAST Software - avast! TDI RDR Driver.) - LEGACY_ASWRDR
O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswSnx.sys (aswSnx) .(.AVAST Software - avast! Virtualization Driver.) - LEGACY_ASWSNX
O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswSP.sys (aswSP) .(.AVAST Software - avast! self protection module.) - LEGACY_ASWSP
O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswTdi.sys (aswTdi) .(.AVAST Software - avast! TDI Filter Driver.) - LEGACY_ASWTDI
O64 - Services: CurCS - 28/11/2011 - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe (avast! Antivirus) .(.AVAST Software - avast! Service.) - LEGACY_AVAST!_ANTIVIRUS
O64 - Services: CurCS - ??\??\???? - (DcomLaunch) .(. - .) - LEGACY_DCOMLAUNCH
O64 - Services: CurCS - 13/4/2008 - C:\WINDOWS\system32\drivers\dmboot.sys (dmboot) .(.Microsoft Corp., Veritas Software - NT Disk Manager Startup Driver.) - LEGACY_DMBOOT
O64 - Services: CurCS - 11/1/2000 - C:\WINDOWS\system32\drivers\dmload.sys (dmload) .(.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) - LEGACY_DMLOAD
O64 - Services: CurCS - 2/11/2011 - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe (gupdate) .(.Google Inc. - Google Installer.) - LEGACY_GUPDATE
O64 - Services: CurCS - 10/12/2011 - C:\WINDOWS\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) - LEGACY_MBAMPROTECTOR
O64 - Services: CurCS - 13/1/2012 - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe (MBAMService) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMSERVICE
O64 - Services: CurCS - 3/5/2011 - C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe (NielsenUpdate) .(.The Nielsen Company - NielsenOnline.) - LEGACY_NIELSENUPDATE
O64 - Services: CurCS - 1/6/2007 - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (NMIndexingService) .(.Nero AG - Nero Home.) - LEGACY_NMINDEXINGSERVICE
O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\nnrnstdi.sys (nnrnstdi) .(.The Nielsen Company - NNRNSTDI helper driver.) - LEGACY_NNRNSTDI
O64 - Services: CurCS - ??\??\???? - (RpcSs) .(. - .) - LEGACY_RPCSS
O64 - Services: CurCS - 14/1/2009 - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (SeaPort) .(.Microsoft Corp. - Microsoft SeaPort Search Enhancement Broker.) - LEGACY_SEAPORT
O64 - Services: CurCS - ??\??\???? - (TermService) .(. - .) - LEGACY_TERMSERVICE
~ Scan Services in 00mn 01s
---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Arquivos de programas\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\WINDOWS\regedit.exe
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\WINDOWS\regedit.exe
~ Scan Keys in 00mn 00s
---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.exe (.not file.)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
~ Scan Keys in 00mn 00s
---\\ Search Svchost Services (SSS) (O83)
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Serviço de instalação do software.) -- C:\WINDOWS\system32\appmgmts.dll [172032]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\system32\audiosrv.dll [42496]
O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\system32\browser.dll [77824]
O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINDOWS\system32\cryptsvc.dll [62464]
O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - Dll do serviço do Gerenciador de discos lógicos.) -- C:\WINDOWS\system32\dmserver.dll [23552]
O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - Serviço do Cliente DHCP.) -- C:\WINDOWS\system32\dhcpcsvc.dll [126976]
O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINDOWS\system32\ersvc.dll [23040]
O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - No comment.) -- C:\WINDOWS\system32\es.dll [253952]
O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\WINDOWS\system32\shsvcs.dll [135168]
O83 - Search Svchost Services: HidServ (HidServ) . (...) -- C:\WINDOWS\system32\hidserv.dll [0]
O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [96768]
O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINDOWS\system32\wkssvc.dll [132096]
O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINDOWS\system32\msgsvc.dll [33792]
O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Gerenciador de conexões de rede.) -- C:\WINDOWS\system32\netman.dll [198144]
O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Fornecedor de serviços do Microsoft Windows Sockets 2.0.) -- C:\WINDOWS\system32\mswsock.dll [247808]
O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Gerenciador de armazenamento removível.) -- C:\WINDOWS\system32\ntmssvc.dll [437248]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\system32\rasauto.dll [88576]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\system32\rasmans.dll [186368]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\system32\mprdim.dll [53248]
O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Mecanismo do 'Agendador de tarefas'.) -- C:\WINDOWS\system32\schedsvc.dll [193536]
O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL de serviço de logon secundário.) -- C:\WINDOWS\system32\seclogon.dll [18944]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\system32\sens.dll [39424]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\WINDOWS\system32\ipnathlp.dll [331264]
O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Serviço de restauração do sistema.) -- C:\WINDOWS\system32\srsvc.dll [171520]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia do Microsoft® Windows.) -- C:\WINDOWS\system32\tapisrv.dll [249856]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\WINDOWS\system32\shsvcs.dll [135168]
O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINDOWS\system32\trkwks.dll [90112]
O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Windows Time Service.) -- C:\WINDOWS\system32\w32time.dll [176128]
O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Serviço de configuração zero sem fio.) -- C:\WINDOWS\system32\wzcsvc.dll [483840]
O83 - Search Svchost Services: Wmi (Wmi) . (.Microsoft Corporation - API de base do Windows 32 avançada.) -- C:\WINDOWS\system32\advapi32.dll [683520]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [145408]
O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINDOWS\system32\wscsvc.dll [80896]
O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINDOWS\system32\xmlprov.dll [129024]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de plano de fundo.) -- C:\WINDOWS\system32\qmgr.dll [409088]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINDOWS\system32\wuauserv.dll [6656]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\WINDOWS\system32\shsvcs.dll [135168]
O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400]
O83 - Search Svchost Services: WmdmPmSN (WmdmPmSN) . (.Microsoft Corporation - Microsoft Media Device Service Provider.) -- C:\WINDOWS\system32\mspmsnsv.dll [27136]
O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Tempo de Execução de Serviço de Agente de Quarentena.) -- C:\WINDOWS\system32\qagentrt.dll [292864]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Serviço de Gerenciamento de Chaves.) -- C:\WINDOWS\system32\kmsvc.dll [61440]
~ Scan Services in 00mn 00s
---\\ Search Particular Root Folder (SPRF) (O84)
[MD5.E7B562231BE0C5617F1516EC6DA16782] [sPRF][3/2/2012] (...) -- C:\Documents and Settings\Filho e karol\Desktop\adwcleaner.exe [578643]
[MD5.3270CB86F79B3E23720BAFC2E48BE3BE] [sPRF][3/2/2012] (.OldTimer Tools - No comment.) -- C:\Documents and Settings\Filho e karol\Desktop\OTL.exe [584192]
[MD5.ABD6ADAC98B1BE9DFED93F290B6CC105] [sPRF][15/11/2009] (...) -- C:\Documents and Settings\Filho e karol\Desktop\Temp.bat [359]
[MD5.A37E08226423BBD4994FE7C66DDF0C9D] [sPRF][6/2/2012] (...) -- C:\Documents and Settings\Filho e karol\Desktop\ToolbarShooter.exe [227328]
~ Scan Files in 00mn 00s
---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto 28/11/2011 44768 | (avast! Antivirus) . (.AVAST Software.) - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe
SS - | Demand 13/4/2008 225280 | (dmadmin) . (.Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\dmadmin.exe
SS - | Auto 2/11/2011 136176 | (gupdate) . (.Google Inc..) - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
SS - | Demand 2/11/2011 136176 | (gupdatem) . (.Google Inc..) - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
SR - | Auto 13/1/2012 652360 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe
SS - | Demand 13/4/2007 792112 | (NBService) . (.Nero AG.) - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe
SR - | Auto 3/5/2011 306496 | (NielsenUpdate) . (.The Nielsen Company.) - C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe
SR - | Demand 1/6/2007 271920 | (NMIndexingService) . (.Nero AG.) - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
~ Scan Services in 00mn 09s
End of the scan (1151 lines in 00mn 52s)(0)
Abraços... :grin:
Bom Dia! karoline ferreira
|- Desculpe-me,pois não reparei o canned repetido e apliquei procedimentos inócuos.
|- Seu caso está praticamente resolvido!
///°°°///
|- Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://img48.imageshack.us/img48/4476/imagemus0.jpg&key=ea7bc0c907a5e38f00e266b145e5f02b8cabf695069b6fc4c1bd4f227ed49071" alt="imagemus0.jpg" /> > (...par A.Rothstein & dj Quiou )
|- Clique em "Télécharger",para o download.
|- Salve-o no desktop!
|- Feche programas que estejam abertos,e execute a ferramenta.
|- Clique no botão Recherche,para iniciar o scan.
|- Ao concluir,teremos relacionados as ferramentas que serão removidas.
|- Clique,à seguir,no botão "Supression" para remover os itens encontrados.
|- Clique em Quitter para sair! --> OK.
|- Caso queira,poste os relatórios: Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU)
|- Selecione e copie para o Bloco de Notas.
|- Seu computador está limpo!
Abraços!
>
Bom Dia! karoline ferreira
|- Desculpe-me,pois não reparei o canned repetido e apliquei procedimentos inócuos.
|- Seu caso está praticamente resolvido!
///°°°///
|- Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://img48.imageshack.us/img48/4476/imagemus0.jpg&key=ea7bc0c907a5e38f00e266b145e5f02b8cabf695069b6fc4c1bd4f227ed49071" alt="imagemus0.jpg" /> > (...par A.Rothstein & dj Quiou )
|- Clique em "Télécharger",para o download.
|- Salve-o no desktop!
|- Feche programas que estejam abertos,e execute a ferramenta.
|- Clique no botão Recherche,para iniciar o scan.
|- Ao concluir,teremos relacionados as ferramentas que serão removidas.
|- Clique,à seguir,no botão "Supression" para remover os itens encontrados.
|- Clique em Quitter para sair! --> OK.
|- Caso queira,poste os relatórios: Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU)
|- Selecione e copie para o Bloco de Notas.
|- Seu computador está limpo!
Abraços!
Olá!! 'DigRam'.
Eu nem cheguei a olhar o esse poste antes de você postar,obrigada por tudo.
[ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]
--> Recherche:
C:\HijackThis.exe: trouvé !
C:\hijackthis.log: trouvé !
C:\Arquivos de programas\ZHPDiag: trouvé !
C:\Arquivos de programas\ZHPDiag\ZHPdiag.exe: trouvé !
C:\Arquivos de programas\ZHPDiag\catchme.exe: trouvé !
C:\Arquivos de programas\ZHPDiag\mbr.exe: trouvé !
---------------------------------
--> Suppression:
C:\HijackThis.exe: supprimé !
C:\Arquivos de programas\ZHPDiag\ZHPdiag.exe: supprimé !
C:\Arquivos de programas\ZHPDiag\catchme.exe: supprimé !
C:\hijackthis.log: supprimé !
C:\Arquivos de programas\ZHPDiag\mbr.exe: supprimé !
C:\Arquivos de programas\ZHPDiag: supprimé !
Abraços... :clap:
PROBLEMA RESOLVIDO
Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.
Boa Noite! karoline ferreira
|- O que ocorre com a máquina? Poderia nos relatar?
///°°°///
|- Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.malwarebytes.org/images/marcinsig.gif&key=2c45e7fd674c4b18d376ffbe83bf82547806ac60e230409c7eb4c31999009760" alt="marcinsig.gif" /> >
|- < Link - 2 >
|- < Link - 3 >
|- Atualize o programa!
|- Escolha o escaneamento Completo!
|- Desabilite programas de proteção,ao executar o malwarebytes.
|- Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme!
|- Ao concluir,clique em "Remover itens".
|- Poste,o relatório: mbam-log-2012-xx-xx (00-00-00).txt
///°°°///
|- Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://billy-oneal.com/Canned%2520Speeches/speechimages/OTL/otlDesktopIcon.png&key=1894e5d356219721410c3360cbf9af74877ae24ccc81ed88026fc2d95dd96a07" alt="otlDesktopIcon.png" /> > ( ...by OldTimer Tools )
|- Clique em Salvar! < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/0e5c629f14858f5bf77e61d46c160e317c6d8c5d3ee101e311e440e99d7fd7b06g.jpg&key=3b5f68b982954852820a7b1c44c7d4ba5f9d81d9cc9adb16f3359408e8cb0d2c" alt="0e5c629f14858f5bf77e61d46c160e317c6d8c5d3ee101e311e440e99d7fd7b06g.jpg" /> >
|- Salve-o no desktop! < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/98c0f1ab3823c58ea05c695fd153839feac6fb6b44aaa3f7f5a2cd4a87354c946g.jpg&key=fdd081d7d566e9ee7a4326a3039dd79a57a2005ed7e54a981d560e259f22d658" alt="98c0f1ab3823c58ea05c695fd153839feac6fb6b44aaa3f7f5a2cd4a87354c946g.jpg" /> >
|- Duplo clique em OTL.exe --> Executar: /applications/core/interface/imageproxy/imageproxy.php?img=http://www.mediafire.com/imgbnc.php/c19ede0bf8817fba1b9a9c0e9dae6ede3b8983c41017d8926efac3638b95aee16g.jpg&key=422d6e6777df6b11458399b7f42d7cf2ca878f8e09b61a66ff681dacba971926" alt="c19ede0bf8817fba1b9a9c0e9dae6ede3b8983c41017d8926efac3638b95aee16g.jpg" />
|- Execute o OTL,em seu rápido escaneamento. ( Verificação rápida )
|- Ps: Para Windows 7,clique direito e execute-o como "Administrador".
|- Copie e poste o relatório. ( C:\_OTM\MovedFiles\xxxx2012_xxxxxx.log )
|- Poste,também,o relatório "Extras".
Abraços!