Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

LSkyWalker

[Resolvido!] desktop limpo

Recommended Posts

bom dia!

Ao ligar o meu pc, ele entra direto no explorer, e meu desktop so mostra o meu papel de parede!

Pesquisei e achei varias coisas sobre esse erro, mas achei melhor pedir ajuda a vcs.

Muito obrigado!

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:35:50, on 2010/04/01

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\windows\System32\smss.exe

C:\windows\system32\winlogon.exe

C:\windows\system32\services.exe

C:\windows\system32\lsass.exe

C:\windows\system32\nvsvc32.exe

C:\windows\system32\svchost.exe

C:\windows\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\windows\system32\spoolsv.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Google\Update\GoogleUpdate.exe

C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

C:\Program Files\CyberLink\Shared Files\RichVideo.exe

C:\windows\system32\sdra64.exe

C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

C:\windows\system32\svchost.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

C:\windows\system32\ctfmon.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\hijack\HiJackThis.exe

 

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\windows\system32\sdra64.exe,

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [updateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"

O4 - HKLM\..\Run: [updatePPShortCut] "C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerProducer" update "Software\CyberLink\PowerProducer\5.0"

O4 - HKLM\..\Run: [updatePSTShortCut] "C:\Program Files\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Blu-ray Disc Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [iTSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe

O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Bluetooth Manager.lnk = ?

O4 - Global Startup: McAfee Security Scan.lnk = ?

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O15 - ESC Trusted Zone: http://*.update.microsoft.com

O16 - DPF: {0172828C-CB7D-4C10-AF96-0ED9B52DCFDC} (GameOnG2GCtrl Class) - http://update.g2gcdn.com/g2g/g2gdownloader/GameOnG2G.cab

O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} (DMM Downloader) - http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab

O16 - DPF: {134DD8EF-7716-4538-A430-EFEB7517E6E7} (StWbJpn Control) - http://sting.gamecom.jp/GameAuth/Launcher100218.cab

O16 - DPF: {1D17175E-48B7-40EC-BEC2-E91C80A89237} (GamehiSpecCheck Control) - http://cp-tekki.gameyarou.jp/_include/_common/Cab/GamehiSpecCheck.cab

O16 - DPF: {1DC420F0-D89A-40D0-B5CC-92B9AD19A1AC} (HGPluginJP28 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP28.cab

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab

O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlcdnet.asus.com/pub/ASUS/misc/dlm-activex-2.2.5.0.cab

O16 - DPF: {5082D9B5-5538-4C50-BDB1-C5F44BFB98CC} (HgRunPub Class) - http://www.hangame.co.jp/publish/HgRunPub.cab

O16 - DPF: {7216BF69-1FB3-438C-9A51-9DA82B676BC0} (ArarioGameStarter6 Class) - http://crossfire.arario.jp/activeX/AraGameStarterW6.cab

O16 - DPF: {7602172A-95A0-407E-9D03-783803BD6E21} (PubPlugin Class) - http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab

O16 - DPF: {8C2E6E01-D1F6-4A94-B314-7C5DF4EE1853} (SpecAnalyzer Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGReport.cab

O16 - DPF: {9BEEA7FF-FF76-403C-B124-86D9835435F0} (GameChu Login Control) - https://file.eafifaonline.jp/dl/download/sessionctrl.cab

O16 - DPF: {BBA1ABFD-C9A1-41E8-959A-161F17E145D4} (G2GDownloader Class) - http://update.g2gcdn.com/g2g/g2gdownloader/G2GDownloader.cab

O16 - DPF: {D6855164-25C2-40D2-BA39-D8A57FF0B49C} (RedbananaVistaPlay Class) - http://cp-tekki.gameyarou.jp/_include/_common/cab/RedbananaAutoPlay.cab

O16 - DPF: {E2729F99-A050-4F4D-AE9F-7492C5532F49} (HgTAgent2 Extension Class) - http://down.hangame.co.jp/jp/dist/hgtagent2/hgtagent2.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab

O16 - DPF: {F8160836-0C11-4CA4-AD87-944542C7BCBD} (PubPlugin Class) - http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe

O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod サービス (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\windows\system32\GameMon.des.exe (file missing)

O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

 

--

End of file - 11480 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! LSkyWalke

 

<@> Baixe: < marcinsig.gif >

 

<@> < Link - 2 >

 

<@> < Link - 3 >

 

<@> Atualize o programa!

<@> Escolha o escaneamento Completo!

<@> Desabilite programas de proteção,ao executar o malwarebytes.

<@> Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme!

<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

<@> Para maiores detalhes: < Link >

<@> Poste: mbam-log-2010-xx-xx (00-00-00).txt

00000000000000000000000

00000000000000000000000

<@> Baixe: < otlDesktopIcon.png > ( ...by OldTimer Tools )

<@> Salve-o no desktop!

 

OTLI-scan.png

 

<@> Segundo a imagem,mude a opção em "Output" para "Minimal Output".

<@> Duplo-clique em OTL.exe --> Marque a opção "Scan All Users".

<@> Marque as caixas:

 

<!> [] LOP check e [] Purity check

 

<@> Clique em: < runscanbutton.png > --> Aguarde!

<@> Poste:

 

<1> OTL.txt <--

<2> Extra.txt <--

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

nossa volto ao normal na hora!! :joia:

muito obrigado!!!

 

so q n consigo achar o log do malwarebytes, tento acessar o log pelo programa mas da erro ao tentar entrar.

mas tai o "OTL" e o "estra".

 

 

OTL logfile created on: 2010/04/01 23:13:49 - Run 1

OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Lucas\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000411 | Country: Japan | Language: JPN | Date Format: yyyy/MM/dd

 

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free

5.00 Gb Paging File | 4.00 Gb Available in Paging File | 88.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files

Drive C: | 244.14 Gb Total Space | 198.55 Gb Free Space | 81.32% Space Free | Partition Type: NTFS

Drive D: | 931.51 Gb Total Space | 274.85 Gb Free Space | 29.51% Space Free | Partition Type: NTFS

Drive E: | 221.62 Gb Total Space | 95.62 Gb Free Space | 43.15% Space Free | Partition Type: NTFS

Drive F: | 2.09 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

G: Drive not present or media not loaded

Drive H: | 0.00 Mb Total Space | 219.36 Mb Free Space | 44.62% Space Free | Partition Type: FAT

Drive I: | 1.89 Gb Total Space | 0.34 Gb Free Space | 17.78% Space Free | Partition Type: FAT

 

Computer Name: HIRAOKA-PC

Current User Name: Lucas

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - C:\Documents and Settings\Lucas\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)

PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)

PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)

PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)

PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)

PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)

PRC - C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe (McAfee, Inc.)

PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)

PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)

PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)

PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)

PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)

PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)

PRC - C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe ()

PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)

PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()

PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA Corporation)

PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA Corporation)

PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Documents and Settings\Lucas\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll (ALWIL Software)

MOD - C:\WINDOWS\system32\imjp81k.dll (Microsoft Corporation)

MOD - C:\WINDOWS\ime\IMJP8_1\imjpcic.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\imjp81.ime (Microsoft Corporation)

MOD - C:\WINDOWS\ime\IMJP8_1\DICTS\imjpcd.dic (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (npggsvc) -- C:\windows\System32\GameMon.des (INCA Internet Co., Ltd.)

SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)

SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)

SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)

SRV - (aswUpdSv) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)

SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)

SRV - (ASKUpgrade) -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()

SRV - (TOSHIBA Bluetooth Service) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)

SRV - (StarWindServiceAE) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)

SRV - (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()

SRV - (nSvcIp) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA Corporation)

SRV - (nSvcLog) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA Corporation)

SRV - (ForcewareWebInterface) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe (Apache Software Foundation)

 

 

========== Driver Services (SafeList) ==========

 

DRV - (sptd) -- C:\windows\System32\Drivers\sptd.sys ()

DRV - (aswMon2) -- C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)

DRV - (aswSP) -- C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)

DRV - (aswFsBlk) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)

DRV - (aswTdi) -- C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)

DRV - (aswRdr) -- C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)

DRV - (Aavmker4) -- C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)

DRV - (tosrfnds) -- C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)

DRV - (Tosrfusb) -- C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)

DRV - (Tosrfhid) -- C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)

DRV - (TosRfSnd) -- C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)

DRV - (tosrfbnp) -- C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)

DRV - ({B154377D-700F-42cc-9474-23858FBDF4BD}) -- C:\Program Files\CyberLink\PowerDVD9\000.fcl (CyberLink Corp.)

DRV - (Tosrfcom) -- C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)

DRV - (CLBUDFR) -- C:\WINDOWS\system32\drivers\CLBUDFR.sys (CyberLink Corporation.)

DRV - (CLBStor) -- C:\WINDOWS\system32\drivers\CLBStor.sys (Cyberlink Co.,Ltd.)

DRV - ({95808DC4-FA4A-4C74-92FE-5B863F82066B}) -- C:\Program Files\CyberLink\PowerDVD\000.fcl (Cyberlink Corp.)

DRV - (tosrfbd) -- C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)

DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)

DRV - (tosporte) -- C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)

DRV - (P17) -- C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)

DRV - (AmdLLD) -- C:\WINDOWS\system32\drivers\AmdLLD.sys (AMD, Inc.)

DRV - (TBPanel) -- C:\WINDOWS\system32\drivers\TBPanel.sys (Windows ® 2000 DDK provider)

DRV - (Cardex) -- C:\WINDOWS\system32\drivers\TBPanel.sys (Windows ® 2000 DDK provider)

DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)

DRV - (ADIHdAudAddService) -- C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)

DRV - (AsIO) -- C:\WINDOWS\system32\drivers\AsIO.sys ()

DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)

DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)

DRV - (NVTCP) -- C:\WINDOWS\system32\drivers\nvtcp.sys (NVIDIA Corporation)

DRV - (nvata) -- C:\windows\system32\DRIVERS\nvata.sys (NVIDIA Corporation)

DRV - (AmdK8) -- C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)

DRV - (SenFiltService) -- C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)

DRV - (SI3132) -- C:\windows\system32\DRIVERS\SI3132.sys (Silicon Image, Inc.)

DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)

DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)

DRV - (SiFilter) -- C:\windows\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)

DRV - (MTsensor) -- C:\WINDOWS\system32\drivers\ASACPI.sys ()

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

 

 

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

[2009/07/27 07:50:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Mozilla\Firefox\extensions

[2009/07/27 07:50:07 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Lucas\Application Data\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}

 

O1 HOSTS File: ([2008/04/14 21:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)

O3 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe ()

O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)

O4 - HKLM..\Run: [bluetoothAuthenticationAgent] C:\windows\System32\bthprops.cpl (Microsoft Corporation)

O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)

O4 - HKLM..\Run: [iMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)

O4 - HKLM..\Run: [iTSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)

O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)

O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKLM..\Run: [updateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\Run: [updatePPShortCut] C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\Run: [updatePSTShortCut] C:\Program Files\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003..\Run: [steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)

O4 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan.lnk = C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe (McAfee, Inc.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0

O7 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0

O7 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0

O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)

O16 - DPF: {0172828C-CB7D-4C10-AF96-0ED9B52DCFDC} http://update.g2gcdn.com/g2g/g2gdownloader/GameOnG2G.cab (GameOnG2GCtrl Class)

O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab (DMM Downloader)

O16 - DPF: {134DD8EF-7716-4538-A430-EFEB7517E6E7} http://sting.gamecom.jp/GameAuth/Launcher100218.cab (StWbJpn Control)

O16 - DPF: {1D17175E-48B7-40EC-BEC2-E91C80A89237} http://cp-tekki.gameyarou.jp/_include/_common/Cab/GamehiSpecCheck.cab (GamehiSpecCheck Control)

O16 - DPF: {1DC420F0-D89A-40D0-B5CC-92B9AD19A1AC} http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP28.cab (HGPluginJP28 Class)

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)

O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)

O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlcdnet.asus.com/pub/ASUS/misc/dlm-activex-2.2.5.0.cab (DLM Control)

O16 - DPF: {5082D9B5-5538-4C50-BDB1-C5F44BFB98CC} http://www.hangame.co.jp/publish/HgRunPub.cab (HgRunPub Class)

O16 - DPF: {7216BF69-1FB3-438C-9A51-9DA82B676BC0} http://crossfire.arario.jp/activeX/AraGameStarterW6.cab (ArarioGameStarter6 Class)

O16 - DPF: {7602172A-95A0-407E-9D03-783803BD6E21} http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab (PubPlugin Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {8C2E6E01-D1F6-4A94-B314-7C5DF4EE1853} http://down.hangame.co.jp/jp/dist/hgstart/HGReport.cab (SpecAnalyzer Class)

O16 - DPF: {9BEEA7FF-FF76-403C-B124-86D9835435F0} https://file.eafifaonline.jp/dl/download/sessionctrl.cab (GameChu Login Control)

O16 - DPF: {BBA1ABFD-C9A1-41E8-959A-161F17E145D4} http://update.g2gcdn.com/g2g/g2gdownloader/G2GDownloader.cab (G2GDownloader Class)

O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {D6855164-25C2-40D2-BA39-D8A57FF0B49C} http://cp-tekki.gameyarou.jp/_include/_common/cab/RedbananaAutoPlay.cab (RedbananaVistaPlay Class)

O16 - DPF: {E2729F99-A050-4F4D-AE9F-7492C5532F49} http://down.hangame.co.jp/jp/dist/hgtagent2/hgtagent2.cab (HgTAgent2 Extension Class)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab (Creative Software AutoUpdate Support Package)

O16 - DPF: {F8160836-0C11-4CA4-AD87-944542C7BCBD} http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab (PubPlugin Class)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\Documents and Settings\Lucas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lucas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2006/05/10 20:01:08 | 000,000,054 | R--- | M] () - F:\Autorun.inf -- [ CDFS ]

O33 - MountPoints2\{35ad2ddb-7a33-11de-bed4-806d6172696f}\Shell - "" = AutoRun

O33 - MountPoints2\{35ad2ddb-7a33-11de-bed4-806d6172696f}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{35ad2ddb-7a33-11de-bed4-806d6172696f}\Shell\AutoRun\command - "" = F:\.\Bin\Assetup.exe -- [2006/09/22 20:45:00 | 000,147,456 | R--- | M] ()

O33 - MountPoints2\{3e46d5ea-79f7-11de-bf80-806d6172696f}\Shell - "" = AutoRun

O33 - MountPoints2\{3e46d5ea-79f7-11de-bf80-806d6172696f}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{3e46d5ea-79f7-11de-bf80-806d6172696f}\Shell\AutoRun\command - "" = F:\.\Bin\Assetup.exe -- [2006/09/22 20:45:00 | 000,147,456 | R--- | M] ()

O33 - MountPoints2\F\Shell - "" = AutoRun

O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\.\Bin\Assetup.exe -- [2006/09/22 20:45:00 | 000,147,456 | R--- | M] ()

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2010/04/01 23:12:32 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Lucas\Desktop\OTL.exe

[2010/04/01 23:11:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google

[2010/04/01 23:10:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2010/04/01 23:10:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft

[2010/04/01 23:10:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee Security Scan

[2010/04/01 22:21:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Application Data\Malwarebytes

[2010/04/01 22:21:38 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys

[2010/04/01 22:21:37 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys

[2010/04/01 22:21:37 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2010/04/01 15:35:26 | 000,000,000 | ---D | C] -- C:\hijack

[2010/04/01 12:44:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\nView_Profiles

[2010/03/30 20:19:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype

[2010/03/29 19:19:13 | 000,000,000 | ---D | C] -- C:\Program Files\Siena the Queen

[2010/03/28 23:51:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\My Documents\CFSystem

[2010/03/28 23:50:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Application Data\Arario

[2010/03/28 23:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\Arario

[2010/03/28 09:53:47 | 000,000,000 | ---D | C] -- C:\Program Files\OGPlanet

[2010/03/26 22:52:35 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar

[2010/03/26 22:52:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Application Data\DAEMON Tools Lite

[2010/03/26 21:45:53 | 000,000,000 | ---D | C] -- C:\windows\B83FC356B7C0441F8A4DD71E088E7974.TMP

[2010/03/25 18:39:20 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\windows\System32\drivers\SBREDrv.sys

[2010/03/18 12:35:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment

[2010/03/18 12:13:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Application Data\ヤブサメ

[2010/03/17 17:52:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Application Data\Thinstall

[2010/03/09 20:42:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Local Settings\Application Data\CoreEdge

[2010/03/09 20:41:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Local Settings\Application Data\Downloaded Installations

[2010/03/09 02:22:13 | 000,000,000 | ---D | C] -- C:\Program Files\Silver

[2010/03/09 02:22:04 | 000,304,128 | ---- | C] (InstallShield Software Corporation) -- C:\windows\IsUninst.exe

[2010/03/09 02:22:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\WINDOWS

[2010/03/07 10:13:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Application Data\Ubisoft

[2010/03/07 10:13:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Ubisoft

[2010/03/07 09:54:26 | 000,000,000 | ---D | C] -- C:\Program Files\Ubisoft

[2010/03/06 00:18:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Real

[2010/03/05 10:43:17 | 000,000,000 | -H-D | C] -- C:\windows\PIF

[2010/02/05 18:44:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google

[2010/02/05 18:39:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google

[2009/08/27 17:45:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple

[2009/07/29 15:56:16 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Lucas\Application Data\pcouffin.sys

[2009/07/26 23:55:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft

[2009/07/26 23:55:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

[2009/07/26 23:52:45 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft

[2009/07/26 23:52:45 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

[2003/06/25 10:31:10 | 000,019,456 | ---- | C] ( ) -- C:\windows\System32\cook3260.dll

[4 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

[2 C:\Documents and Settings\Lucas\My Documents\*.tmp files -> C:\Documents and Settings\Lucas\My Documents\*.tmp -> ]

[1 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2010/04/01 23:15:00 | 000,000,422 | -H-- | M] () -- C:\windows\tasks\User_Feed_Synchronization-{03C27DEC-8CCD-4BC9-B350-2A61B9AA147B}.job

[2010/04/01 23:12:34 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lucas\Desktop\OTL.exe

[2010/04/01 23:10:14 | 000,001,028 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job

[2010/04/01 23:10:14 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT

[2010/04/01 23:10:10 | 000,002,048 | --S- | M] () -- C:\windows\bootstat.dat

[2010/04/01 23:09:00 | 007,077,888 | -H-- | M] () -- C:\Documents and Settings\Lucas\NTUSER.DAT

[2010/04/01 23:09:00 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Lucas\ntuser.ini

[2010/04/01 23:08:54 | 005,854,788 | -H-- | M] () -- C:\Documents and Settings\Lucas\Local Settings\Application Data\IconCache.db

[2010/04/01 22:30:18 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\Lucas\Desktop\Skype.lnk

[2010/04/01 22:29:00 | 000,001,032 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job

[2010/04/01 22:21:41 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/04/01 17:45:00 | 000,000,284 | ---- | M] () -- C:\windows\tasks\AppleSoftwareUpdate.job

[2010/04/01 12:44:49 | 000,093,460 | ---- | M] () -- C:\windows\System32\NvApps.xml

[2010/04/01 03:34:18 | 000,002,206 | ---- | M] () -- C:\windows\System32\wpa.dbl

[2010/04/01 03:03:15 | 000,059,392 | ---- | M] () -- C:\Documents and Settings\Lucas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/03/31 17:03:34 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk

[2010/03/30 00:46:30 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys

[2010/03/30 00:45:52 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys

[2010/03/29 23:22:00 | 000,000,472 | ---- | M] () -- C:\windows\tasks\Ad-Aware Update (Weekly).job

[2010/03/29 20:38:09 | 000,000,824 | ---- | M] () -- C:\Documents and Settings\Lucas\Desktop\Shortcut to CabalMain.lnk

[2010/03/29 20:25:15 | 000,000,796 | ---- | M] () -- C:\Documents and Settings\Lucas\Desktop\BS.Player PRO.lnk

[2010/03/29 20:14:26 | 000,000,241 | ---- | M] () -- C:\Documents and Settings\Lucas\Application Data\default.rss

[2010/03/29 20:14:14 | 000,000,069 | ---- | M] () -- C:\windows\NeroDigital.ini

[2010/03/28 23:49:09 | 000,000,817 | ---- | M] () -- C:\Documents and Settings\Lucas\Desktop\クロスファイア.lnk

[2010/03/27 09:28:55 | 000,000,033 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini

[2010/03/26 23:33:25 | 000,000,064 | ---- | M] () -- C:\windows\System32\rp_stats.dat

[2010/03/26 23:33:25 | 000,000,044 | ---- | M] () -- C:\windows\System32\rp_rules.dat

[2010/03/26 22:52:22 | 000,691,696 | ---- | M] () -- C:\windows\System32\drivers\sptd.sys

[2010/03/25 18:39:15 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\windows\System32\drivers\SBREDrv.sys

[2010/03/25 01:27:08 | 000,001,499 | ---- | M] () -- C:\Documents and Settings\Lucas\My Documents\mus.m3u

[2010/03/23 18:31:38 | 000,000,073 | ---- | M] () -- C:\windows\cdplayer.ini

[2010/03/23 18:28:10 | 000,001,074 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\ss.ini

[2010/03/18 19:14:24 | 000,033,813 | ---- | M] () -- C:\windows\Ascd_tmp.ini

[2010/03/18 14:54:36 | 000,031,744 | ---- | M] () -- C:\Documents and Settings\Lucas\My Documents\職務経歴書.doc

[2010/03/18 08:56:09 | 000,000,234 | ---- | M] () -- C:\windows\wininit.ini

[2010/03/11 22:12:29 | 000,196,960 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT

[2010/03/11 21:18:33 | 000,045,320 | ---- | M] () -- C:\Documents and Settings\Lucas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2010/03/11 03:02:01 | 000,001,374 | ---- | M] () -- C:\windows\imsins.BAK

[2010/03/09 02:35:53 | 000,000,666 | ---- | M] () -- C:\Documents and Settings\Lucas\Desktop\Silver.lnk

[4 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

[2 C:\Documents and Settings\Lucas\My Documents\*.tmp files -> C:\Documents and Settings\Lucas\My Documents\*.tmp -> ]

[1 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2010/04/01 22:21:41 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/03/29 20:38:09 | 000,000,824 | ---- | C] () -- C:\Documents and Settings\Lucas\Desktop\Shortcut to CabalMain.lnk

[2010/03/28 23:49:09 | 000,000,817 | ---- | C] () -- C:\Documents and Settings\Lucas\Desktop\クロスファイア.lnk

[2010/03/27 09:28:55 | 000,000,033 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini

[2010/03/26 22:55:31 | 000,000,064 | ---- | C] () -- C:\windows\System32\rp_stats.dat

[2010/03/26 22:55:31 | 000,000,044 | ---- | C] () -- C:\windows\System32\rp_rules.dat

[2010/03/25 18:40:23 | 000,000,472 | ---- | C] () -- C:\windows\tasks\Ad-Aware Update (Weekly).job

[2010/03/25 01:27:08 | 000,001,499 | ---- | C] () -- C:\Documents and Settings\Lucas\My Documents\mus.m3u

[2010/03/23 18:31:23 | 000,000,073 | ---- | C] () -- C:\windows\cdplayer.ini

[2010/03/23 18:28:10 | 000,001,074 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ss.ini

[2010/03/18 19:14:23 | 000,033,813 | ---- | C] () -- C:\windows\Ascd_tmp.ini

[2010/03/18 11:20:28 | 000,031,744 | ---- | C] () -- C:\Documents and Settings\Lucas\My Documents\職務経歴書.doc

[2010/03/18 00:58:32 | 000,000,234 | ---- | C] () -- C:\windows\wininit.ini

[2010/03/09 02:35:53 | 000,000,666 | ---- | C] () -- C:\Documents and Settings\Lucas\Desktop\Silver.lnk

[2010/02/15 01:51:47 | 000,000,121 | ---- | C] () -- C:\windows\SeraphInstall.INI

[2009/09/15 02:22:07 | 000,102,832 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

[2009/09/13 20:31:05 | 000,000,361 | ---- | C] () -- C:\windows\lgfwup.ini

[2009/09/03 15:16:40 | 000,000,558 | ---- | C] () -- C:\windows\DFC.INI

[2009/09/03 08:52:31 | 001,662,976 | ---- | C] () -- C:\windows\System32\nvwdmcpl.dll

[2009/09/03 08:52:31 | 001,019,904 | ---- | C] () -- C:\windows\System32\nvwimg.dll

[2009/09/03 08:52:30 | 001,470,464 | ---- | C] () -- C:\windows\System32\nview.dll

[2009/09/03 08:52:30 | 000,581,632 | ---- | C] () -- C:\windows\System32\nvhwvid.dll

[2009/09/03 08:52:30 | 000,466,944 | ---- | C] () -- C:\windows\System32\nvshell.dll

[2009/09/03 08:52:30 | 000,286,720 | ---- | C] () -- C:\windows\System32\nvnt4cpl.dll

[2009/08/20 22:59:59 | 000,000,241 | ---- | C] () -- C:\Documents and Settings\Lucas\Application Data\default.rss

[2009/08/06 16:29:18 | 000,000,025 | ---- | C] () -- C:\windows\CDE PXA640.ini

[2009/08/03 00:21:54 | 000,197,912 | ---- | C] () -- C:\windows\System32\physxcudart_20.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelTraditionalChinese.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelSwedish.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelSpanish.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelSimplifiedChinese.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelPortugese.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelKorean.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelJapanese.dll

[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelGerman.dll

[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelFrench.dll

[2009/07/29 19:04:47 | 000,005,112 | ---- | C] () -- C:\windows\version.ini

[2009/07/29 15:56:22 | 000,000,014 | ---- | C] () -- C:\windows\System32\systeminfo3.dll

[2009/07/29 15:56:19 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\Lucas\Application Data\pcouffin.log

[2009/07/29 15:56:16 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Lucas\Application Data\inst.exe

[2009/07/29 15:56:16 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Lucas\Application Data\pcouffin.cat

[2009/07/29 15:56:16 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Lucas\Application Data\pcouffin.inf

[2009/07/29 09:01:02 | 000,005,194 | ---- | C] () -- C:\windows\System32\Setup2k.ini

[2009/07/29 09:01:02 | 000,000,197 | ---- | C] () -- C:\windows\System32\presetup.ini

[2009/07/27 22:47:41 | 000,691,696 | ---- | C] () -- C:\windows\System32\drivers\sptd.sys

[2009/07/27 21:38:28 | 000,059,392 | ---- | C] () -- C:\Documents and Settings\Lucas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/07/27 20:07:13 | 000,000,069 | ---- | C] () -- C:\windows\NeroDigital.ini

[2009/07/27 18:35:28 | 000,004,767 | ---- | C] () -- C:\windows\Irremote.ini

[2009/07/27 00:39:56 | 000,212,992 | ---- | C] () -- C:\windows\System32\nvapi.dll

[2009/07/27 00:28:38 | 000,003,628 | ---- | C] () -- C:\windows\System32\AudioDrv.ini

[2009/07/27 00:28:06 | 000,005,663 | ---- | C] () -- C:\windows\System32\ludap17.ini

[2009/07/27 00:28:06 | 000,000,072 | ---- | C] () -- C:\windows\System32\ctzapxx.ini

[2009/07/27 00:23:27 | 000,024,576 | ---- | C] () -- C:\windows\System32\AsIO.dll

[2009/07/27 00:23:27 | 000,012,664 | ---- | C] () -- C:\windows\System32\drivers\AsIO.sys

[2009/07/27 00:23:26 | 000,012,096 | ---- | C] () -- C:\windows\System32\drivers\AsInsHelp64.sys

[2009/07/27 00:23:26 | 000,010,304 | ---- | C] () -- C:\windows\System32\drivers\AsInsHelp32.sys

[2009/07/26 23:59:55 | 000,000,962 | ---- | C] () -- C:\windows\System32\AsusSetup.ini

[2009/07/26 23:59:55 | 000,000,403 | ---- | C] () -- C:\windows\System32\raidmgmt.ini

[2009/07/26 23:57:53 | 000,034,186 | ---- | C] () -- C:\windows\Ascd_log.ini

[2009/07/26 23:57:32 | 000,005,810 | ---- | C] () -- C:\windows\System32\drivers\ASACPI.sys

[2009/07/26 23:57:16 | 000,010,288 | ---- | C] () -- C:\windows\System32\drivers\ASUSHWIO.SYS

[2007/12/28 17:32:14 | 000,065,536 | ---- | C] () -- C:\windows\System32\P17.dll

[2003/10/02 19:48:18 | 000,053,248 | ---- | C] () -- C:\windows\System32\P17CPI.dll

 

========== LOP Check ==========

 

[2010/02/07 02:18:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TOSHIBA

[2010/03/07 10:13:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft

[2009/10/11 10:37:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\TOSHIBA

[2010/03/28 23:50:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Arario

[2010/02/15 01:51:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\BDL+D

[2009/09/10 00:41:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Beelzebub

[2010/03/29 20:27:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\BSplayer PRO

[2010/03/26 23:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\DAEMON Tools Lite

[2010/04/01 23:07:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Desktopicon

[2009/08/09 23:47:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\DooGA Co.,Ltd

[2009/11/07 10:13:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Flood Light Games

[2010/03/08 00:26:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Lucas\Application Data\Hangame

[2010/02/28 22:56:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\HgTAgent

[2009/09/14 22:23:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\ImgBurn

[2009/08/16 22:53:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\SEGA

[2010/03/17 17:52:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Thinstall

[2009/10/11 18:28:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\TOSHIBA

[2010/03/07 10:13:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Ubisoft

[2010/04/01 23:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\uTorrent

[2009/07/29 15:56:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Vso

[2010/03/18 12:13:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\ヤブサメ

[2009/10/11 10:37:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lucas2\Application Data\TOSHIBA

[2010/03/29 23:22:00 | 000,000,472 | ---- | M] () -- C:\windows\Tasks\Ad-Aware Update (Weekly).job

[2010/04/01 23:15:00 | 000,000,422 | -H-- | M] () -- C:\windows\Tasks\User_Feed_Synchronization-{03C27DEC-8CCD-4BC9-B350-2A61B9AA147B}.job

 

========== Purity Check ==========

 

 

< End of report >

 

 

OTL Extras logfile created on: 2010/04/01 23:14:01 - Run 1

OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Lucas\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000411 | Country: Japan | Language: JPN | Date Format: yyyy/MM/dd

 

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free

5.00 Gb Paging File | 4.00 Gb Available in Paging File | 88.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files

Drive C: | 244.14 Gb Total Space | 198.55 Gb Free Space | 81.32% Space Free | Partition Type: NTFS

Drive D: | 931.51 Gb Total Space | 274.85 Gb Free Space | 29.51% Space Free | Partition Type: NTFS

Drive E: | 221.62 Gb Total Space | 95.62 Gb Free Space | 43.15% Space Free | Partition Type: NTFS

Drive F: | 2.09 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

G: Drive not present or media not loaded

Drive H: | 0.00 Mb Total Space | 219.36 Mb Free Space | 44.62% Space Free | Partition Type: FAT

Drive I: | 1.89 Gb Total Space | 0.34 Gb Free Space | 17.78% Space Free | Partition Type: FAT

 

Computer Name: HIRAOKA-PC

Current User Name: Lucas

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)

Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)

Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"c:\sting_h\game_sting_pak\sting.exe" = c:\sting_h\game_sting_pak\sting.exe:*:Enabled: -- File not found

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe" = C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server -- (Apache Software Foundation)

"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:μTorrent -- (BitTorrent, Inc.)

"C:\Program Files\G2G\G2GDownloader\GameOn\GameOnG2G_Engine.exe" = C:\Program Files\G2G\G2GDownloader\GameOn\GameOnG2G_Engine.exe:*:Enabled:G2GDownloaderGameOn_Engine -- ()

"C:\GameOn\Alliance of Valiant Arms\Binaries\AVA.exe" = C:\GameOn\Alliance of Valiant Arms\Binaries\AVA.exe:*:Enabled:AVA -- (Redduck)

"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)

"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)

"C:\Program Files\G2G\G2GDownloader\G2GDownloader_Engine.exe" = C:\Program Files\G2G\G2GDownloader\G2GDownloader_Engine.exe:*:Enabled:G2GDownloader_Engine -- ()

"c:\sting_h\game_sting_pak\sting.exe" = c:\sting_h\game_sting_pak\sting.exe:*:Enabled: -- File not found

"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe" = C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher -- (Ubisoft)

"C:\Program Files\StarCraft II Beta\StarCraft II.exe" = C:\Program Files\StarCraft II Beta\StarCraft II.exe:*:Enabled:Blizzard Launcher -- File not found

"C:\Program Files\StarCraft II Beta\Versions\Base13891\SC2.exe" = C:\Program Files\StarCraft II Beta\Versions\Base13891\SC2.exe:*:Enabled:StarCraft II -- File not found

"C:\Program Files\StarCraft II Beta\Versions\Base14356\SC2.exe" = C:\Program Files\StarCraft II Beta\Versions\Base14356\SC2.exe:*:Enabled:StarCraft II -- File not found

"C:\HanPurple\J_SPECIALF\j_specialf.exe" = C:\HanPurple\J_SPECIALF\j_specialf.exe:*:Enabled:j_specialf -- ()

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam

"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}" = Cool & Quiet

"{1F6423DE-7959-4178-80E0-023C7EAA5347}" = NVIDIA ForceWare Network Access Manager

"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Blu-ray Disc Suite

"{22D90DD2-8654-4E8A-B2F1-B6B86A2BF390}" = CyberLink UDF Reader 5.0

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java 6 Update 17

"{2D2D8FE2-605C-4D3C-B706-36E981E7EEF0}" = CyberLink BD Advisor 2.0

"{2D33B338-EA1B-34EA-BD7F-BBD59487E03A}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - JPN

"{2EAF7E61-068E-11DF-953C-005056806466}" = Google Earth

"{310BC5E2-31AF-49BB-904D-E71EB93645DC}" = AI Suite

"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode

"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent

"{3E354FBA-C7CE-402A-BB0D-225230BB1918}" = Logitech G15 Keyboard Software 1.04

"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go

"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision

"{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}" = EPSON Scan OCR コンポーネント

"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml

"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate

"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress

"{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG ODD Auto Firmware Update

"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner

"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = CyberLink PowerDVD

"{68F19BCC-49D3-49FF-BAAC-A147C66A9710}" = AMD Power Monitor

"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart

"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights

"{7B4C59F3-A36D-4444-AFCF-4B0A58B4FAEA}" = Tekki

"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow

"{81C2613B-FAD3-402C-AEBC-77EAF6692F0B}" = ハンゲームActiveX自動インストーラー

"{82D040D1-F95B-4C96-AF5C-B6A1E138EC6E}" = 沙耶の唄

"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed

"{86BCF503-3A8F-45BE-ADA4-AA0717DA3EB4}" = Cabal Online

"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher

"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system

"{90850416-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003

"{932245FB-2F3B-3E2E-B8AB-BDE96E434F21}" = Microsoft .NET Framework 3.5 Language Pack SP1 - jpn

"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap

"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget

"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor

"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2

"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime

"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9

"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AC76BA86-7AD7-1046-7B44-A92000000001}" = Adobe Reader 9.2 - Português

"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9

"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles

"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center

"{B3A1EF98-079F-4E7B-B992-91154D53496E}_is1" = 戦場のカルマ 1.0

"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit

"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer

"{B81959C4-909B-4DD1-979B-48F84D35E923}" = LPV3

"{BBCC4C9A-14C9-4EE4-9099-DB2C7316666B}" = Sound Blaster 5.1 VX

"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter

"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax

"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX

"{CA567AD5-33A4-403D-86D1-EE2D38251951}_is1" = VDownloader 1.1

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba

"{CFA05440-A429-4A60-84C9-16919C12876F}_is1" = Cabal Online 8.6.30.1

"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM

"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2

"{D85BDA1A-983E-3C61-8F03-E5F9C394075C}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - JPN

"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime

"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes

"{dba713cf-fed6-4eb6-a899-880e65613754}" = Nero 9 Trial

"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live

"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit

"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer

"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)

"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01

"{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II

"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool

"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Ask Toolbar_is1" = Ask Toolbar

"avast!" = avast! Antivirus

"black shuck" = black shuck

"BSPlayerp" = BS.Player PRO

"CABAL ONLINE(Japan)_is1" = CABAL ONLINE(Japan) v6.0

"CDisplay_is1" = CDisplay 1.8

"Creative Software AutoUpdate" = Creative Software AutoUpdate

"EPSON Scanner" = EPSON Scan

"GameChu" = ゲームチューインストールマネージャー

"Gamechu_" =

"Gamechu_AVA" = Alliance of Valiant Arms

"Google Chrome" = Google Chrome

"HijackThis" = HijackThis 2.0.2

"ie8" = Windows Internet Explorer 8

"ImgBurn" = ImgBurn

"InstallShield_{1F6423DE-7959-4178-80E0-023C7EAA5347}" = NVIDIA ForceWare Network Access Manager

"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Blu-ray Disc Suite

"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go

"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow

"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9

"InstallShield_{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = CyberLink PowerProducer

"JAIELangPack" = Japanese Language Support

"JC-U2312F Vibration Game Pad" = JC-U2312F Vibration Game Pad

"Love×Evolution" = Love×Evolution

"MainApp.exe_is1" = CloneDVD 4.3.0.3

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"McAfee Security Scan" = McAfee Security Scan

"Micro DVD Player" = Micro DVD Player

"Microsoft .NET Framework 3.5 Language Pack SP1 - jpn" = Microsoft .NET Framework 3.5 Language Pack SP1 - 日本語

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"MouseSuite98" = ELECOM Mouse Driver(P1)

"NVIDIA Drivers" = NVIDIA Drivers

"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager

"OpenAL" = OpenAL

"PHOENIX DRIVE" = PHOENIX DRIVE

"RealPlayer 6.0" = RealPlayer

"Silver" = Silver

"SpecialForce" = Specialf Force

"SysInfo" = Creative System Information

"SystemRequirementsLab" = System Requirements Lab

"Vtune_is1" = Vtune 5.0

"WaveStudio 7" = Creative WaveStudio 7

"Winamp" = Winamp

"Windows Media Format Runtime" = Windows Media Format Runtime

"WinRAR archiver" = Arquivo do WinRAR

"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

"クロスファイア" = クロスファイア

 

========== HKEY_USERS Uninstall List ==========

 

[HKEY_USERS\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Hangame.com" = Hangame

"uTorrent" = µTorrent

 

========== Last 10 Event Log Errors ==========

 

[ Antivirus Events ]

Error - 2009/11/04 19:39:59 | Computer Name = HIRAOKA-PC | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

http://clients1.google.co.jp/complete/search?q=double+soft+cream&client=tbrs&hl=pt-BR

failed, 0000A413.

 

Error - 2009/11/10 4:40:59 | Computer Name = HIRAOKA-PC | Source = avast! | ID = 33554522

Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of

http://www.youtube.com/ failed, 0000A413.

 

[ Application Events ]

Error - 2010/03/07 11:18:28 | Computer Name = HIRAOKA-PC | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 2010/03/07 12:45:20 | Computer Name = HIRAOKA-PC | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 2010/03/08 8:31:15 | Computer Name = HIRAOKA-PC | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 2010/03/09 8:45:14 | Computer Name = HIRAOKA-PC | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 2010/03/10 12:04:26 | Computer Name = HIRAOKA-PC | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 2010/03/10 12:27:27 | Computer Name = HIRAOKA-PC | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 2010/03/11 3:53:07 | Computer Name = HIRAOKA-PC | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 2010/03/11 4:01:49 | Computer Name = HIRAOKA-PC | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 2010/03/11 6:44:36 | Computer Name = HIRAOKA-PC | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

Error - 2010/03/11 8:54:37 | Computer Name = HIRAOKA-PC | Source = Application Hang | ID = 1002

Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module

hungapp, version 0.0.0.0, hang address 0x00000000.

 

[ System Events ]

Error - 2010/04/01 10:10:50 | Computer Name = HIRAOKA-PC | Source = Disk | ID = 262155

Description = The driver detected a controller error on \Device\Harddisk3\D.

 

Error - 2010/04/01 10:11:25 | Computer Name = HIRAOKA-PC | Source = Disk | ID = 262155

Description = The driver detected a controller error on \Device\Harddisk3\D.

 

Error - 2010/04/01 10:11:26 | Computer Name = HIRAOKA-PC | Source = Disk | ID = 262155

Description = The driver detected a controller error on \Device\Harddisk3\D.

 

Error - 2010/04/01 10:11:27 | Computer Name = HIRAOKA-PC | Source = Disk | ID = 262155

Description = The driver detected a controller error on \Device\Harddisk3\D.

 

Error - 2010/04/01 10:11:28 | Computer Name = HIRAOKA-PC | Source = Disk | ID = 262155

Description = The driver detected a controller error on \Device\Harddisk3\D.

 

Error - 2010/04/01 10:11:33 | Computer Name = HIRAOKA-PC | Source = Disk | ID = 262155

Description = The driver detected a controller error on \Device\Harddisk3\D.

 

Error - 2010/04/01 10:13:49 | Computer Name = HIRAOKA-PC | Source = Disk | ID = 262155

Description = The driver detected a controller error on \Device\Harddisk3\D.

 

Error - 2010/04/01 10:13:59 | Computer Name = HIRAOKA-PC | Source = Disk | ID = 262155

Description = The driver detected a controller error on \Device\Harddisk3\D.

 

Error - 2010/04/01 10:14:01 | Computer Name = HIRAOKA-PC | Source = Disk | ID = 262155

Description = The driver detected a controller error on \Device\Harddisk3\D.

 

Error - 2010/04/01 10:14:10 | Computer Name = HIRAOKA-PC | Source = Disk | ID = 262155

Description = The driver detected a controller error on \Device\Harddisk3\D.

 

 

< End of report >

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 23:52:01, on 2010/04/01

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\windows\System32\smss.exe

C:\windows\system32\winlogon.exe

C:\windows\system32\services.exe

C:\windows\system32\lsass.exe

C:\windows\system32\nvsvc32.exe

C:\windows\system32\svchost.exe

C:\windows\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\windows\system32\spoolsv.exe

C:\windows\Explorer.EXE

C:\windows\system32\ctfmon.exe

C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\windows\system32\rundll32.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Program Files\Google\Update\GoogleUpdate.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

C:\Program Files\CyberLink\Shared Files\RichVideo.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\windows\system32\svchost.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe

C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Java\jre6\bin\jucheck.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Skype\Plugin Manager\skypePM.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\hijack\HiJackThis.exe

 

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [updateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"

O4 - HKLM\..\Run: [updatePPShortCut] "C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerProducer" update "Software\CyberLink\PowerProducer\5.0"

O4 - HKLM\..\Run: [updatePSTShortCut] "C:\Program Files\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Blu-ray Disc Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [iTSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe

O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Bluetooth Manager.lnk = ?

O4 - Global Startup: McAfee Security Scan.lnk = ?

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O15 - ESC Trusted Zone: http://*.update.microsoft.com

O16 - DPF: {0172828C-CB7D-4C10-AF96-0ED9B52DCFDC} (GameOnG2GCtrl Class) - http://update.g2gcdn.com/g2g/g2gdownloader/GameOnG2G.cab

O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} (DMM Downloader) - http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab

O16 - DPF: {134DD8EF-7716-4538-A430-EFEB7517E6E7} (StWbJpn Control) - http://sting.gamecom.jp/GameAuth/Launcher100218.cab

O16 - DPF: {1D17175E-48B7-40EC-BEC2-E91C80A89237} (GamehiSpecCheck Control) - http://cp-tekki.gameyarou.jp/_include/_common/Cab/GamehiSpecCheck.cab

O16 - DPF: {1DC420F0-D89A-40D0-B5CC-92B9AD19A1AC} (HGPluginJP28 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP28.cab

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab

O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlcdnet.asus.com/pub/ASUS/misc/dlm-activex-2.2.5.0.cab

O16 - DPF: {5082D9B5-5538-4C50-BDB1-C5F44BFB98CC} (HgRunPub Class) - http://www.hangame.co.jp/publish/HgRunPub.cab

O16 - DPF: {7216BF69-1FB3-438C-9A51-9DA82B676BC0} (ArarioGameStarter6 Class) - http://crossfire.arario.jp/activeX/AraGameStarterW6.cab

O16 - DPF: {7602172A-95A0-407E-9D03-783803BD6E21} (PubPlugin Class) - http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab

O16 - DPF: {8C2E6E01-D1F6-4A94-B314-7C5DF4EE1853} (SpecAnalyzer Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGReport.cab

O16 - DPF: {9BEEA7FF-FF76-403C-B124-86D9835435F0} (GameChu Login Control) - https://file.eafifaonline.jp/dl/download/sessionctrl.cab

O16 - DPF: {BBA1ABFD-C9A1-41E8-959A-161F17E145D4} (G2GDownloader Class) - http://update.g2gcdn.com/g2g/g2gdownloader/G2GDownloader.cab

O16 - DPF: {D6855164-25C2-40D2-BA39-D8A57FF0B49C} (RedbananaVistaPlay Class) - http://cp-tekki.gameyarou.jp/_include/_common/cab/RedbananaAutoPlay.cab

O16 - DPF: {E2729F99-A050-4F4D-AE9F-7492C5532F49} (HgTAgent2 Extension Class) - http://down.hangame.co.jp/jp/dist/hgtagent2/hgtagent2.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab

O16 - DPF: {F8160836-0C11-4CA4-AD87-944542C7BCBD} (PubPlugin Class) - http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe

O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod サービス (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\windows\system32\GameMon.des.exe (file missing)

O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

 

--

End of file - 12295 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! LSkyWalker

 

<!> Se não for de seu conhecimento,ou aceitação,a instalação deste software:

 

<!> C:\Program Files\AskBarDis ou Ask Toolbar

 

<!> Pode desinstalar,se for o caso!

0000000000000000000000

<@> Abra a pasta AskBarDis e busque o arquivo: C:\Arquivos de programas\AskBarDis\unins000.exe <--

<@> Execute-o com um duplo-clique --> Confirme! --> Reinicie o computador!

0000000000000000000000

<@> Baixe: < Flash Disinfector >

<@> Salve-o,diretamente,no Disco Local-C.

<@> Tire-o do zip!

<@> Conecte,na entrada USB,suas unidades removíveis!

<@> Dê um duplo clique em: Flash_Disinfector.exe

<@> Aguarde a conclusão!

0000000000000000000000

0000000000000000000000

<@> Execute o OTL.exe.

<@> Copie estas informações que estão no Quote,para o campo clipboard da ferramenta. ( Custom Scans/Fixes )

 

:files

C:\Documents and Settings\Lucas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

:reg

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"c:\sting_h\game_sting_pak\sting.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"c:\sting_h\game_sting_pak\sting.exe"=-

"C:\Program Files\StarCraft II Beta\StarCraft II.exe"=-

"C:\Program Files\StarCraft II Beta\Versions\Base13891\SC2.exe"=-

"C:\Program Files\StarCraft II Beta\Versions\Base14356\SC2.exe"=-

:otl

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

[4 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

[2 C:\Documents and Settings\Lucas\My Documents\*.tmp files -> C:\Documents and Settings\Lucas\My Documents\*.tmp -> ]

[1 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]

:Commands

[purity]

[emptytemp]

[Reboot]

<@> Clique no botão Run Fix --> Aguarde a conclusão!

<@> Terminando,vá até a pasta: C:\_OTL\MovedFiles\*.log <-- Poste!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde!

ta aqui o log! muito obrigado.

 

ll processes killed

========== FILES ==========

C:\Documents and Settings\Lucas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.

========== REGISTRY ==========

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\c:\sting_h\game_sting_pak\sting.exe deleted successfully.

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\c:\sting_h\game_sting_pak\sting.exe deleted successfully.

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\StarCraft II Beta\StarCraft II.exe deleted successfully.

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\StarCraft II Beta\Versions\Base13891\SC2.exe deleted successfully.

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\StarCraft II Beta\Versions\Base14356\SC2.exe deleted successfully.

========== OTL ==========

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully.

C:\windows\B83FC356B7C0441F8A4DD71E088E7974.TMP\WiseCustomCalla.dll deleted successfully.

C:\windows\B83FC356B7C0441F8A4DD71E088E7974.TMP folder deleted successfully.

C:\windows\SET3.tmp deleted successfully.

C:\windows\SET4.tmp deleted successfully.

C:\windows\SET8.tmp deleted successfully.

C:\Documents and Settings\Lucas\My Documents\PP_MOTION.TMP folder deleted successfully.

C:\Documents and Settings\Lucas\My Documents\PP_ROTATE_SLIDE.TMP folder deleted successfully.

C:\windows\System32\CONFIG.TMP deleted successfully.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: All Users

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: LocalService

->Temp folder emptied: 66016 bytes

->Temporary Internet Files folder emptied: 4231438 bytes

 

User: Lucas

->Temp folder emptied: 1910438684 bytes

->Temporary Internet Files folder emptied: 44686843 bytes

->Java cache emptied: 37870532 bytes

->Flash cache emptied: 15920 bytes

 

User: lucas2

->Temp folder emptied: 310 bytes

->Temporary Internet Files folder emptied: 54926 bytes

 

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 1097010 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 4271496 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23859790 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes

RecycleBin emptied: 0 bytes

 

Total Files Cleaned = 1,933.00 mb

 

 

OTL by OldTimer - Version 3.1.37.3 log created on 04022010_044958

 

Files\Folders moved on Reboot...

C:\Documents and Settings\Lucas\Local Settings\Temp\Google Toolbar\GoogleToolbarWelcome.log moved successfully.

File\Folder C:\Documents and Settings\Lucas\Local Settings\Temp\~DF1B03.tmp not found!

File\Folder C:\Documents and Settings\Lucas\Local Settings\Temp\~DF1B18.tmp not found!

File\Folder C:\Documents and Settings\Lucas\Local Settings\Temp\~DF1B77.tmp not found!

File\Folder C:\Documents and Settings\Lucas\Local Settings\Temp\~DF1B89.tmp not found!

File\Folder C:\Documents and Settings\Lucas\Local Settings\Temp\~DF1BD7.tmp not found!

File\Folder C:\Documents and Settings\Lucas\Local Settings\Temp\~DF1BE9.tmp not found!

C:\Documents and Settings\Lucas\Local Settings\Temporary Internet Files\Content.IE5\PLDS0ENN\ads[1].htm moved successfully.

C:\Documents and Settings\Lucas\Local Settings\Temporary Internet Files\Content.IE5\P2L1SL21\barra[1].htm moved successfully.

C:\Documents and Settings\Lucas\Local Settings\Temporary Internet Files\Content.IE5\KM3E2JCZ\ads[6].htm moved successfully.

C:\Documents and Settings\Lucas\Local Settings\Temporary Internet Files\Content.IE5\EQ5KG214\index[5].php moved successfully.

C:\Documents and Settings\Lucas\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.

C:\Documents and Settings\Lucas\Local Settings\Temporary Internet Files\SuggestedSites.dat moved successfully.

File move failed. C:\windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.

C:\windows\temp\Perflib_Perfdata_6a4.dat moved successfully.

 

Registry entries deleted on Reboot...

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 5:02:30, on 2010/04/02

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\windows\System32\smss.exe

C:\windows\system32\winlogon.exe

C:\windows\system32\services.exe

C:\windows\system32\lsass.exe

C:\windows\system32\nvsvc32.exe

C:\windows\system32\svchost.exe

C:\windows\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\windows\Explorer.EXE

C:\windows\system32\ctfmon.exe

C:\windows\system32\spoolsv.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Google\Update\GoogleUpdate.exe

C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

C:\Program Files\CyberLink\Shared Files\RichVideo.exe

C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

C:\windows\system32\svchost.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe

C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\windows\system32\rundll32.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Skype\Plugin Manager\skypePM.exe

C:\Program Files\Java\jre6\bin\jucheck.exe

C:\hijack\HiJackThis.exe

 

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [updateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"

O4 - HKLM\..\Run: [updatePPShortCut] "C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerProducer" update "Software\CyberLink\PowerProducer\5.0"

O4 - HKLM\..\Run: [updatePSTShortCut] "C:\Program Files\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Blu-ray Disc Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [iTSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe

O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Bluetooth Manager.lnk = ?

O4 - Global Startup: McAfee Security Scan.lnk = ?

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O15 - ESC Trusted Zone: http://*.update.microsoft.com

O16 - DPF: {0172828C-CB7D-4C10-AF96-0ED9B52DCFDC} (GameOnG2GCtrl Class) - http://update.g2gcdn.com/g2g/g2gdownloader/GameOnG2G.cab

O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} (DMM Downloader) - http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab

O16 - DPF: {134DD8EF-7716-4538-A430-EFEB7517E6E7} (StWbJpn Control) - http://sting.gamecom.jp/GameAuth/Launcher100218.cab

O16 - DPF: {1D17175E-48B7-40EC-BEC2-E91C80A89237} (GamehiSpecCheck Control) - http://cp-tekki.gameyarou.jp/_include/_common/Cab/GamehiSpecCheck.cab

O16 - DPF: {1DC420F0-D89A-40D0-B5CC-92B9AD19A1AC} (HGPluginJP28 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP28.cab

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab

O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlcdnet.asus.com/pub/ASUS/misc/dlm-activex-2.2.5.0.cab

O16 - DPF: {5082D9B5-5538-4C50-BDB1-C5F44BFB98CC} (HgRunPub Class) - http://www.hangame.co.jp/publish/HgRunPub.cab

O16 - DPF: {7216BF69-1FB3-438C-9A51-9DA82B676BC0} (ArarioGameStarter6 Class) - http://crossfire.arario.jp/activeX/AraGameStarterW6.cab

O16 - DPF: {7602172A-95A0-407E-9D03-783803BD6E21} (PubPlugin Class) - http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab

O16 - DPF: {8C2E6E01-D1F6-4A94-B314-7C5DF4EE1853} (SpecAnalyzer Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGReport.cab

O16 - DPF: {9BEEA7FF-FF76-403C-B124-86D9835435F0} (GameChu Login Control) - https://file.eafifaonline.jp/dl/download/sessionctrl.cab

O16 - DPF: {BBA1ABFD-C9A1-41E8-959A-161F17E145D4} (G2GDownloader Class) - http://update.g2gcdn.com/g2g/g2gdownloader/G2GDownloader.cab

O16 - DPF: {D6855164-25C2-40D2-BA39-D8A57FF0B49C} (RedbananaVistaPlay Class) - http://cp-tekki.gameyarou.jp/_include/_common/cab/RedbananaAutoPlay.cab

O16 - DPF: {E2729F99-A050-4F4D-AE9F-7492C5532F49} (HgTAgent2 Extension Class) - http://down.hangame.co.jp/jp/dist/hgtagent2/hgtagent2.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab

O16 - DPF: {F8160836-0C11-4CA4-AD87-944542C7BCBD} (PubPlugin Class) - http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe

O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod サービス (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\windows\system32\GameMon.des.exe (file missing)

O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe

O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

 

--

End of file - 11963 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! LSkyWalker

 

<@> Execute o OTL Quick Scan,onde teremos um rápido escaneamento da ferramenta.

<@> Duplo-clique em: < otlDesktopIcon.png >

<@> Clique em "Scan All Users" --> 2j287qe.png --> Aguarde!

<@> Copie e poste o relatório. ( OTL log )

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

bom dia!

ta aqui.

 

 

OTL logfile created on: 2010/04/02 18:06:41 - Run 2

OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Lucas\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000411 | Country: Japan | Language: JPN | Date Format: yyyy/MM/dd

 

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 68.00% Memory free

5.00 Gb Paging File | 4.00 Gb Available in Paging File | 81.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files

Drive C: | 244.14 Gb Total Space | 200.50 Gb Free Space | 82.12% Space Free | Partition Type: NTFS

Drive D: | 931.51 Gb Total Space | 274.85 Gb Free Space | 29.51% Space Free | Partition Type: NTFS

Drive E: | 221.62 Gb Total Space | 95.82 Gb Free Space | 43.24% Space Free | Partition Type: NTFS

Drive F: | 2.09 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

G: Drive not present or media not loaded

Drive H: | 491.60 Mb Total Space | 219.35 Mb Free Space | 44.62% Space Free | Partition Type: FAT

Drive I: | 1.89 Gb Total Space | 0.34 Gb Free Space | 17.78% Space Free | Partition Type: FAT

 

Computer Name: HIRAOKA-PC

Current User Name: Lucas

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 14 Days

Output = Minimal

Quick Scan

 

========== Processes (SafeList) ==========

 

PRC - C:\Documents and Settings\Lucas\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Program Files\Webteh\BSplayerPro\bsplayer.exe (Webteh)

PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)

PRC - C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)

PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)

PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)

PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)

PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)

PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)

PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)

PRC - C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe (McAfee, Inc.)

PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)

PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)

PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)

PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)

PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)

PRC - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)

PRC - C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe ()

PRC - C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)

PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()

PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA Corporation)

PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA Corporation)

PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Documents and Settings\Lucas\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\Program Files\Alwil Software\Avast4\AhJsctNs.dll (ALWIL Software)

MOD - C:\Program Files\Webteh\BSplayerPro\mmkeybsupp.dll (BST)

MOD - C:\WINDOWS\system32\imjp81k.dll (Microsoft Corporation)

MOD - C:\WINDOWS\ime\IMJP8_1\imjpcic.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\imjp81.ime (Microsoft Corporation)

MOD - C:\WINDOWS\ime\IMJP8_1\DICTS\imjpcd.dic (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (npggsvc) -- C:\windows\System32\GameMon.des (INCA Internet Co., Ltd.)

SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)

SRV - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)

SRV - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)

SRV - (aswUpdSv) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)

SRV - (Nero BackItUp Scheduler 4.0) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)

SRV - (TOSHIBA Bluetooth Service) -- C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)

SRV - (StarWindServiceAE) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)

SRV - (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()

SRV - (nSvcIp) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA Corporation)

SRV - (nSvcLog) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA Corporation)

SRV - (ForcewareWebInterface) -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe (Apache Software Foundation)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

 

 

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com

IE - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

O1 HOSTS File: ([2008/04/14 21:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe ()

O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)

O4 - HKLM..\Run: [bluetoothAuthenticationAgent] C:\windows\System32\bthprops.cpl (Microsoft Corporation)

O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)

O4 - HKLM..\Run: [iMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)

O4 - HKLM..\Run: [iTSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)

O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)

O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKLM..\Run: [updateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\Run: [updatePPShortCut] C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\Run: [updatePSTShortCut] C:\Program Files\CyberLink\Blu-ray Disc Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003..\Run: [steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)

O4 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan.lnk = C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe (McAfee, Inc.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36

O7 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0

O7 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0

O7 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0

O7 - HKU\S-1-5-21-2025429265-1078145449-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]

O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)

O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)

O16 - DPF: {0172828C-CB7D-4C10-AF96-0ED9B52DCFDC} http://update.g2gcdn.com/g2g/g2gdownloader/GameOnG2G.cab (GameOnG2GCtrl Class)

O16 - DPF: {0725D9DE-4CB8-4BC3-8219-3E74C0D544F7} http://sample3.dmm.co.jp/downloader5/DMMDownloader.cab (DMM Downloader)

O16 - DPF: {134DD8EF-7716-4538-A430-EFEB7517E6E7} http://sting.gamecom.jp/GameAuth/Launcher100218.cab (StWbJpn Control)

O16 - DPF: {1D17175E-48B7-40EC-BEC2-E91C80A89237} http://cp-tekki.gameyarou.jp/_include/_common/Cab/GamehiSpecCheck.cab (GamehiSpecCheck Control)

O16 - DPF: {1DC420F0-D89A-40D0-B5CC-92B9AD19A1AC} http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP28.cab (HGPluginJP28 Class)

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)

O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)

O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlcdnet.asus.com/pub/ASUS/misc/dlm-activex-2.2.5.0.cab (DLM Control)

O16 - DPF: {5082D9B5-5538-4C50-BDB1-C5F44BFB98CC} http://www.hangame.co.jp/publish/HgRunPub.cab (HgRunPub Class)

O16 - DPF: {7216BF69-1FB3-438C-9A51-9DA82B676BC0} http://crossfire.arario.jp/activeX/AraGameStarterW6.cab (ArarioGameStarter6 Class)

O16 - DPF: {7602172A-95A0-407E-9D03-783803BD6E21} http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab (PubPlugin Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {8C2E6E01-D1F6-4A94-B314-7C5DF4EE1853} http://down.hangame.co.jp/jp/dist/hgstart/HGReport.cab (SpecAnalyzer Class)

O16 - DPF: {9BEEA7FF-FF76-403C-B124-86D9835435F0} https://file.eafifaonline.jp/dl/download/sessionctrl.cab (GameChu Login Control)

O16 - DPF: {BBA1ABFD-C9A1-41E8-959A-161F17E145D4} http://update.g2gcdn.com/g2g/g2gdownloader/G2GDownloader.cab (G2GDownloader Class)

O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {D6855164-25C2-40D2-BA39-D8A57FF0B49C} http://cp-tekki.gameyarou.jp/_include/_common/cab/RedbananaAutoPlay.cab (RedbananaVistaPlay Class)

O16 - DPF: {E2729F99-A050-4F4D-AE9F-7492C5532F49} http://down.hangame.co.jp/jp/dist/hgtagent2/hgtagent2.cab (HgTAgent2 Extension Class)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab (Creative Software AutoUpdate Support Package)

O16 - DPF: {F8160836-0C11-4CA4-AD87-944542C7BCBD} http://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab (PubPlugin Class)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)

O24 - Desktop WallPaper: C:\Documents and Settings\Lucas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lucas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2010/04/02 04:48:26 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2010/04/02 04:48:26 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2010/04/02 04:48:26 | 000,000,000 | RHSD | M] - E:\autorun.inf -- [ NTFS ]

O32 - AutoRun File - [2006/05/10 20:01:08 | 000,000,054 | R--- | M] () - F:\Autorun.inf -- [ CDFS ]

O32 - AutoRun File - [2010/04/02 04:48:28 | 000,000,000 | RHSD | M] - H:\autorun.inf -- [ FAT ]

O32 - AutoRun File - [2010/04/02 04:48:28 | 000,000,000 | RHSD | M] - I:\autorun.inf -- [ FAT ]

O33 - MountPoints2\{35ad2ddb-7a33-11de-bed4-806d6172696f}\Shell - "" = AutoRun

O33 - MountPoints2\{35ad2ddb-7a33-11de-bed4-806d6172696f}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{35ad2ddb-7a33-11de-bed4-806d6172696f}\Shell\AutoRun\command - "" = F:\.\Bin\Assetup.exe -- [2006/09/22 20:45:00 | 000,147,456 | R--- | M] ()

O33 - MountPoints2\{3e46d5ea-79f7-11de-bf80-806d6172696f}\Shell - "" = AutoRun

O33 - MountPoints2\{3e46d5ea-79f7-11de-bf80-806d6172696f}\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\{3e46d5ea-79f7-11de-bf80-806d6172696f}\Shell\AutoRun\command - "" = F:\.\Bin\Assetup.exe -- [2006/09/22 20:45:00 | 000,147,456 | R--- | M] ()

O33 - MountPoints2\F\Shell - "" = AutoRun

O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play

O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\.\Bin\Assetup.exe -- [2006/09/22 20:45:00 | 000,147,456 | R--- | M] ()

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 14 Days ==========

 

[2010/04/02 12:43:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2010/04/02 04:49:58 | 000,000,000 | ---D | C] -- C:\_OTL

[2010/04/02 04:48:26 | 000,000,000 | RHSD | C] -- C:\autorun.inf

[2010/04/02 04:45:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe

[2010/04/02 01:49:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Google

[2010/04/02 01:48:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft

[2010/04/02 01:47:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee Security Scan

[2010/04/01 23:12:32 | 000,555,520 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Lucas\Desktop\OTL.exe

[2010/04/01 22:21:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Application Data\Malwarebytes

[2010/04/01 22:21:38 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys

[2010/04/01 22:21:37 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys

[2010/04/01 22:21:37 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2010/04/01 15:35:26 | 000,000,000 | ---D | C] -- C:\hijack

[2010/04/01 12:44:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\nView_Profiles

[2010/03/30 20:19:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype

[2010/03/29 19:19:13 | 000,000,000 | ---D | C] -- C:\Program Files\Siena the Queen

[2010/03/28 23:51:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\My Documents\CFSystem

[2010/03/28 23:50:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Application Data\Arario

[2010/03/28 23:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\Arario

[2010/03/28 09:53:47 | 000,000,000 | ---D | C] -- C:\Program Files\OGPlanet

[2010/03/26 22:52:35 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar

[2010/03/26 22:52:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Lucas\Application Data\DAEMON Tools Lite

[2010/03/25 18:39:20 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\windows\System32\drivers\SBREDrv.sys

[2010/02/05 18:44:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google

[2010/02/05 18:39:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google

[2009/08/27 17:45:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple

[2009/07/29 15:56:16 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Lucas\Application Data\pcouffin.sys

[2009/07/26 23:55:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft

[2009/07/26 23:55:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

[2009/07/26 23:52:45 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft

[2009/07/26 23:52:45 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

[2003/06/25 10:31:10 | 000,019,456 | ---- | C] ( ) -- C:\windows\System32\cook3260.dll

 

========== Files - Modified Within 14 Days ==========

 

[2010/04/02 18:05:00 | 000,000,422 | -H-- | M] () -- C:\windows\tasks\User_Feed_Synchronization-{03C27DEC-8CCD-4BC9-B350-2A61B9AA147B}.job

[2010/04/02 17:29:00 | 000,001,032 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job

[2010/04/02 17:20:29 | 000,002,267 | ---- | M] () -- C:\Documents and Settings\Lucas\Desktop\Skype.lnk

[2010/04/02 14:29:00 | 000,001,028 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job

[2010/04/02 05:20:26 | 007,077,888 | -H-- | M] () -- C:\Documents and Settings\Lucas\NTUSER.DAT

[2010/04/02 04:51:39 | 000,000,006 | -H-- | M] () -- C:\windows\tasks\SA.DAT

[2010/04/02 04:51:34 | 000,002,048 | --S- | M] () -- C:\windows\bootstat.dat

[2010/04/02 04:50:30 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Lucas\ntuser.ini

[2010/04/02 04:43:51 | 005,855,536 | -H-- | M] () -- C:\Documents and Settings\Lucas\Local Settings\Application Data\IconCache.db

[2010/04/02 04:43:22 | 000,128,710 | ---- | M] () -- C:\Flash_Disinfector_www.pplware.com.rar

[2010/04/02 01:52:32 | 000,005,116 | ---- | M] () -- C:\windows\version.ini

[2010/04/01 23:12:34 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Lucas\Desktop\OTL.exe

[2010/04/01 22:21:41 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/04/01 17:45:00 | 000,000,284 | ---- | M] () -- C:\windows\tasks\AppleSoftwareUpdate.job

[2010/04/01 12:44:49 | 000,093,460 | ---- | M] () -- C:\windows\System32\NvApps.xml

[2010/04/01 03:34:18 | 000,002,206 | ---- | M] () -- C:\windows\System32\wpa.dbl

[2010/03/31 17:03:34 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk

[2010/03/30 00:46:30 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbamswissarmy.sys

[2010/03/30 00:45:52 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\windows\System32\drivers\mbam.sys

[2010/03/29 23:22:00 | 000,000,472 | ---- | M] () -- C:\windows\tasks\Ad-Aware Update (Weekly).job

[2010/03/29 20:38:09 | 000,000,824 | ---- | M] () -- C:\Documents and Settings\Lucas\Desktop\Shortcut to CabalMain.lnk

[2010/03/29 20:25:15 | 000,000,796 | ---- | M] () -- C:\Documents and Settings\Lucas\Desktop\BS.Player PRO.lnk

[2010/03/29 20:14:26 | 000,000,241 | ---- | M] () -- C:\Documents and Settings\Lucas\Application Data\default.rss

[2010/03/29 20:14:14 | 000,000,069 | ---- | M] () -- C:\windows\NeroDigital.ini

[2010/03/28 23:49:09 | 000,000,817 | ---- | M] () -- C:\Documents and Settings\Lucas\Desktop\クロスファイア.lnk

[2010/03/27 09:28:55 | 000,000,033 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini

[2010/03/26 23:33:25 | 000,000,064 | ---- | M] () -- C:\windows\System32\rp_stats.dat

[2010/03/26 23:33:25 | 000,000,044 | ---- | M] () -- C:\windows\System32\rp_rules.dat

[2010/03/26 22:52:22 | 000,691,696 | ---- | M] () -- C:\windows\System32\drivers\sptd.sys

[2010/03/25 18:39:15 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\windows\System32\drivers\SBREDrv.sys

[2010/03/25 01:27:08 | 000,001,499 | ---- | M] () -- C:\Documents and Settings\Lucas\My Documents\mus.m3u

[2010/03/23 18:31:38 | 000,000,073 | ---- | M] () -- C:\windows\cdplayer.ini

[2010/03/23 18:28:10 | 000,001,074 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\ss.ini

 

========== Files Created - No Company Name ==========

 

[2010/04/02 04:43:30 | 000,132,597 | ---- | C] () -- C:\Flash_Disinfector.exe

[2010/04/02 04:43:21 | 000,128,710 | ---- | C] () -- C:\Flash_Disinfector_www.pplware.com.rar

[2010/04/01 22:21:41 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk

[2010/03/29 20:38:09 | 000,000,824 | ---- | C] () -- C:\Documents and Settings\Lucas\Desktop\Shortcut to CabalMain.lnk

[2010/03/28 23:49:09 | 000,000,817 | ---- | C] () -- C:\Documents and Settings\Lucas\Desktop\クロスファイア.lnk

[2010/03/27 09:28:55 | 000,000,033 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini

[2010/03/26 22:55:31 | 000,000,064 | ---- | C] () -- C:\windows\System32\rp_stats.dat

[2010/03/26 22:55:31 | 000,000,044 | ---- | C] () -- C:\windows\System32\rp_rules.dat

[2010/03/25 18:40:23 | 000,000,472 | ---- | C] () -- C:\windows\tasks\Ad-Aware Update (Weekly).job

[2010/03/25 01:27:08 | 000,001,499 | ---- | C] () -- C:\Documents and Settings\Lucas\My Documents\mus.m3u

[2010/03/23 18:31:23 | 000,000,073 | ---- | C] () -- C:\windows\cdplayer.ini

[2010/03/23 18:28:10 | 000,001,074 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ss.ini

[2010/03/18 19:14:23 | 000,033,813 | ---- | C] () -- C:\windows\Ascd_tmp.ini

[2010/03/18 00:58:32 | 000,000,234 | ---- | C] () -- C:\windows\wininit.ini

[2010/02/15 01:51:47 | 000,000,121 | ---- | C] () -- C:\windows\SeraphInstall.INI

[2009/09/15 02:22:07 | 000,102,832 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

[2009/09/13 20:31:05 | 000,000,361 | ---- | C] () -- C:\windows\lgfwup.ini

[2009/09/03 15:16:40 | 000,000,558 | ---- | C] () -- C:\windows\DFC.INI

[2009/09/03 08:52:31 | 001,662,976 | ---- | C] () -- C:\windows\System32\nvwdmcpl.dll

[2009/09/03 08:52:31 | 001,019,904 | ---- | C] () -- C:\windows\System32\nvwimg.dll

[2009/09/03 08:52:30 | 001,470,464 | ---- | C] () -- C:\windows\System32\nview.dll

[2009/09/03 08:52:30 | 000,581,632 | ---- | C] () -- C:\windows\System32\nvhwvid.dll

[2009/09/03 08:52:30 | 000,466,944 | ---- | C] () -- C:\windows\System32\nvshell.dll

[2009/09/03 08:52:30 | 000,286,720 | ---- | C] () -- C:\windows\System32\nvnt4cpl.dll

[2009/08/20 22:59:59 | 000,000,241 | ---- | C] () -- C:\Documents and Settings\Lucas\Application Data\default.rss

[2009/08/06 16:29:18 | 000,000,025 | ---- | C] () -- C:\windows\CDE PXA640.ini

[2009/08/03 00:21:54 | 000,197,912 | ---- | C] () -- C:\windows\System32\physxcudart_20.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelTraditionalChinese.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelSwedish.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelSpanish.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelSimplifiedChinese.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelPortugese.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelKorean.dll

[2009/08/03 00:21:54 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelJapanese.dll

[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelGerman.dll

[2009/08/03 00:21:52 | 000,058,648 | ---- | C] () -- C:\windows\System32\AgCPanelFrench.dll

[2009/07/29 19:04:47 | 000,005,116 | ---- | C] () -- C:\windows\version.ini

[2009/07/29 15:56:22 | 000,000,014 | ---- | C] () -- C:\windows\System32\systeminfo3.dll

[2009/07/29 15:56:19 | 000,000,034 | ---- | C] () -- C:\Documents and Settings\Lucas\Application Data\pcouffin.log

[2009/07/29 15:56:16 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Lucas\Application Data\inst.exe

[2009/07/29 15:56:16 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Lucas\Application Data\pcouffin.cat

[2009/07/29 15:56:16 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Lucas\Application Data\pcouffin.inf

[2009/07/29 09:01:02 | 000,005,194 | ---- | C] () -- C:\windows\System32\Setup2k.ini

[2009/07/29 09:01:02 | 000,000,197 | ---- | C] () -- C:\windows\System32\presetup.ini

[2009/07/27 22:47:41 | 000,691,696 | ---- | C] () -- C:\windows\System32\drivers\sptd.sys

[2009/07/27 20:07:13 | 000,000,069 | ---- | C] () -- C:\windows\NeroDigital.ini

[2009/07/27 18:35:28 | 000,004,767 | ---- | C] () -- C:\windows\Irremote.ini

[2009/07/27 00:39:56 | 000,212,992 | ---- | C] () -- C:\windows\System32\nvapi.dll

[2009/07/27 00:28:38 | 000,003,628 | ---- | C] () -- C:\windows\System32\AudioDrv.ini

[2009/07/27 00:28:06 | 000,005,663 | ---- | C] () -- C:\windows\System32\ludap17.ini

[2009/07/27 00:28:06 | 000,000,072 | ---- | C] () -- C:\windows\System32\ctzapxx.ini

[2009/07/27 00:23:27 | 000,024,576 | ---- | C] () -- C:\windows\System32\AsIO.dll

[2009/07/27 00:23:27 | 000,012,664 | ---- | C] () -- C:\windows\System32\drivers\AsIO.sys

[2009/07/27 00:23:26 | 000,012,096 | ---- | C] () -- C:\windows\System32\drivers\AsInsHelp64.sys

[2009/07/27 00:23:26 | 000,010,304 | ---- | C] () -- C:\windows\System32\drivers\AsInsHelp32.sys

[2009/07/26 23:59:55 | 000,000,962 | ---- | C] () -- C:\windows\System32\AsusSetup.ini

[2009/07/26 23:59:55 | 000,000,403 | ---- | C] () -- C:\windows\System32\raidmgmt.ini

[2009/07/26 23:57:53 | 000,034,186 | ---- | C] () -- C:\windows\Ascd_log.ini

[2009/07/26 23:57:32 | 000,005,810 | ---- | C] () -- C:\windows\System32\drivers\ASACPI.sys

[2009/07/26 23:57:16 | 000,010,288 | ---- | C] () -- C:\windows\System32\drivers\ASUSHWIO.SYS

[2007/12/28 17:32:14 | 000,065,536 | ---- | C] () -- C:\windows\System32\P17.dll

[2003/10/02 19:48:18 | 000,053,248 | ---- | C] () -- C:\windows\System32\P17CPI.dll

 

========== LOP Check ==========

 

[2010/02/07 02:18:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TOSHIBA

[2010/03/07 10:13:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft

[2009/10/11 10:37:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\TOSHIBA

[2010/03/28 23:50:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Arario

[2010/02/15 01:51:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\BDL+D

[2009/09/10 00:41:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Beelzebub

[2010/03/29 20:27:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\BSplayer PRO

[2010/03/26 23:26:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\DAEMON Tools Lite

[2010/04/01 23:07:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Desktopicon

[2009/08/09 23:47:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\DooGA Co.,Ltd

[2009/11/07 10:13:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Flood Light Games

[2010/03/08 00:26:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\Lucas\Application Data\Hangame

[2010/02/28 22:56:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\HgTAgent

[2009/09/14 22:23:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\ImgBurn

[2009/08/16 22:53:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\SEGA

[2010/03/17 17:52:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Thinstall

[2009/10/11 18:28:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\TOSHIBA

[2010/03/07 10:13:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Ubisoft

[2010/04/02 18:08:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\uTorrent

[2009/07/29 15:56:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\Vso

[2010/03/18 12:13:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Lucas\Application Data\ヤブサメ

[2009/10/11 10:37:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\lucas2\Application Data\TOSHIBA

[2010/03/29 23:22:00 | 000,000,472 | ---- | M] () -- C:\windows\Tasks\Ad-Aware Update (Weekly).job

[2010/04/02 18:05:00 | 000,000,422 | -H-- | M] () -- C:\windows\Tasks\User_Feed_Synchronization-{03C27DEC-8CCD-4BC9-B350-2A61B9AA147B}.job

 

========== Purity Check ==========

 

 

< End of report >

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! LSkyWalker

 

<@> Abra o OTL.exe --> Clique em CleanUp.jpg --> Aguarde!

<@> Na solicitação,clique OK --> Reinicie o computador!

00000000000000000000

00000000000000000000

<!> Seus logs estão limpos!

<!> Tudo Ok?

 

Abraços! :)

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.