Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

RafaeL Icassati 2

[Arquivado] Pc - lento

Recommended Posts

Bom dia! Meu pc esta meio lento para a velocidade dele.

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 08:37:09, on 16/01/2012

Platform: Windows 7 SP1 (WinNT 6.00.3505)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

 

Running processes:

C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe

C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe

C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe

C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe

C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe

C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe

C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

C:\Program Files (x86)\Ask.com\Updater\Updater.exe

C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccSvcHst.exe

C:\Program Files (x86)\Common Files\SystemEngines\lupdater.exe

c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe

C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe

C:\Users\My\Downloads\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/3

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

R3 - URLSearchHook: (no name) - {e0301295-ab3e-4af3-979f-3d453c5f9f48} - (no file)

F2 - REG:system.ini: UserInit=userinit.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: DigitalPersona Personal Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\DigitalPersona\Bin\DpOtsPluginIe8.dll

O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\coIEPlg.dll

O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\IPSBHO.DLL

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL

O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Program Files (x86)\GbPlugin\gbieh.dll

O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\PROGRA~2\GbPlugin\gbiehuni.dll

O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)

O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\coIEPlg.dll

O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)

O4 - HKLM\..\Run: [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam"

O4 - HKLM\..\Run: [DpAgent] C:\Program Files (x86)\DigitalPersona\Bin\dpagent.exe

O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start

O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot

O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

O4 - HKLM\..\Run: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"

O4 - HKLM\..\Run: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [sysEng] wscript.exe "C:\Program Files (x86)\Common Files\SystemEngines\out.js"

O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [AdobeBridge] "C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe" -stealth

O4 - HKCU\..\Run: [NitroPC] "C:\Program Files (x86)\NitroPC\NitroPC.exe" -minimized

O4 - HKCU\..\Run: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [ManyCam] "C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe" /silent

O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe" -automount

O4 - HKCU\..\Run: [Facebook Update] "C:\Users\My\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO DE REDE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO DE REDE')

O4 - Global Startup: Bluetooth.lnk = ?

O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000

O8 - Extra context menu item: Enviar imagem para Dispositivo &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

O8 - Extra context menu item: Enviar página para Dispositivo &Bluetooth ... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\My\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra button: Enviar para Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: Enviar para Dispositivo &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} (GbPluginObj Class) - https://clickbanking.itau.com.br/itau/gbplugin/gbplugin2/cab/GbPluginUni.cab

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

O20 - Winlogon Notify: GbPluginBb - C:\Program Files (x86)\GbPlugin\gbieh.dll

O20 - Winlogon Notify: GbPluginUni - C:\PROGRA~2\GbPlugin\gbiehUni.dll

O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe

O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

O23 - Service: @C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe

O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\SPLASH.SYS\config\DVMExportService.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: Gbp Service (GbpSv) - - C:\PROGRA~2\GbPlugin\GbpSv.exe

O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe

O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe

O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe

O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccSvcHst.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\STacSV64.exe

O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe

O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

 

--

End of file - 17221 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! RafaeL lcassati2

 

|- Baixe: < marcinsig.gif >

 

|- < Link - 2 >

 

|- < Link - 3 >

 

|- Atualize o programa!

|- Escolha o escaneamento Completo!

|- Desabilite programas de proteção,ao executar o malwarebytes.

|- Ps: Para Windows Vista ou 7,execute-o como administrador!

|- Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme!

|- Ao concluir,clique em "Remover itens".

|- Poste,o relatório: mbam-log-2012-xx-xx (00-00-00).txt

 

/////°°°°°/////

 

|- Baixe: < ToolbarShooter > ( ... de 2011N2 )

|- Salve-o no desktop!

|- Desabilite seu antivírus.

|- Execute a ferramenta,e escolha a opção 2. ( Suppression )

|- Ps: Para Windows Vista ou 7,execute-o como administrador!

|- Ao concluir,aperte Enter,para dispormos do relatório.

|- Poste o relatório: "Rapport de suppression de ToolbarShooter"

 

/////°°°°°/////

 

|- Baixe: < otlDesktopIcon.png > ( ...by OldTimer Tools )

 

|- Clique em Salvar! < 0e5c629f14858f5bf77e61d46c160e317c6d8c5d3ee101e311e440e99d7fd7b06g.jpg >

 

|- Salve-o no desktop! < 98c0f1ab3823c58ea05c695fd153839feac6fb6b44aaa3f7f5a2cd4a87354c946g.jpg >

 

|- Duplo clique em OTL.exe --> Executar: c19ede0bf8817fba1b9a9c0e9dae6ede3b8983c41017d8926efac3638b95aee16g.jpg

 

d41bced8f81abf469a7cf15e79602cabb454822f22ab6c1f99de153199e8cbe96g.jpg

 

|- Configure "Verificação de Arquivos",segundo a screenshot!

 

687fb9a7d9845ff2c797b59c02e4c506f5fa7a198b362ef138918286753b42da6g.jpg

 

|- Ps: Faça o mesmo para estes!

|- Ps: Altere para "Usar SafeList",menos para "Exame Extra do Registro",que será assinalado "Nenhum".

 

CREATERESTOREPOINT

netsvcs

msconfig

%SYSTEMDRIVE%\*.*

%systemdrive%\drivers\*.* /s

%systemdrive%\drivers\*.exe

%systemroot%\system32\drivers\*.* /30

%PROGRAMFILES%\*.*

%userprofile%\configurações locais\dados de aplicativos\*.exe

%userprofile%\configurações locais\dados de aplicativos\*.txt

%userprofile%\configurações locais\dados de aplicativos\*.ini

%userprofile%\configurações locais\dados de aplicativos\*.dat /30

%userprofile%\configurações locais\dados de aplicativos\*.dll

/md5start

explorer.exe

/md5stop

%userprofile%\*.exe

%userprofile%\.txt

%userprofile%\.ini

%userprofile%\.dat /30

%userprofile%\.dll

%systemroot%\system32\Tasks\*.* /30

%windir%\tasks\*.* /s

%systemroot%\*.scr

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DateTime\Servers

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

6659d256325569c6e621117dc332966313a07d11cb5fb0ea4d9176217c7aefa76g.jpg

 

|- Cole estas informações,que estão na tag "Citar",para o campo "Exames Personalizados/Correções".

 

|- Clique em Verificar< 49e6f2665be35b3681ba584e7c765651ce4e159059fd54e9cc162579633ccaf56g.jpg >

 

|- Concluindo,poste o relatório: C:\_OTM\MovedFiles\xxxx2011_xxxxxx.log

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde DigRam, em primeiro obrigado elo suporte.

Segui o que voce disse:

 

Malwarebytes Anti-Malware (Trial) 1.60.0.1800

www.malwarebytes.org

 

Versão da Base de Dados: v2012.01.16.02

 

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

My :: MY-PC [administrador]

 

Proteção: Permitir

 

16/01/2012 14:41:06

mbam-log-2012-01-16 (15-53-21).txt

 

Tipo de Verificação: Verificação Completa

Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM

Opções de verificação desativadas: P2P

Objetos escaneados: 396907

Tempo decorrido: 1 hora(s), 11 minuto(s), 59 segundo(s)

 

Processos de Memória Detectados: 0

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Detectados: 0

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Valores de Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Pastas Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Arquivos Detectados: 1

C:\Program Files (x86)\Online Services\UOL\discador.exe (Trojan.Agent) -> Nenhuma ação foi feita.

 

(fim)

 

 

=========== Informations ===========

 

Mis à jour le : 13/11/2011 à 15h00 par 2011N2

Rapport de suppression de ToolbarShooter par 2011N2

Contact : lot12@hotmail.fr

Site : http://2011n2.forumgratuit.fr/

 

Début du scan de suppression : 16:11:54

 

################################## Toolbars, pups et adwares néfastes supprimés ################################

 

 

Clé supprimée avec succès : HKLM\Software\Conduit

Clé supprimée avec succès : HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}

Clé supprimée avec succès : HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}

Clé supprimée avec succès : HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}

Clé supprimée avec succès : HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}

Clé supprimée avec succès : HKLM\SOFTWARE\Classes\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}

Clé supprimée avec succès : HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}

Clé supprimée avec succès : HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}

Clé supprimée avec succès : HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}

Clé supprimée avec succès : HKLM\Software\WOW6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}

Clé supprimée avec succès : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4

 

 

Clé supprimée avec succès : HKCU\Software\AppDataLow\Software\Conduit

Clé supprimée avec succès : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}

Clé supprimée avec succès : HKCU\Software\Ask.com

Clé supprimée avec succès : HKCU\Software\APN

Clé supprimée avec succès : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}

Clé supprimée avec succès : HKCU\Software\AppDataLow\Software\AskToolbar

 

 

 

 

Dossier supprimé avec succès : "C:\Users\My\AppData\Local\Conduit"

Dossier supprimé avec succès : "C:\Program Files (x86)\Conduit"

Dossier supprimé avec succès : "C:\Users\My\AppData\LocalLow\Conduit"

Dossier supprimé avec succès : "C:\Users\My\AppData\Local\Temp\AskSearch"

Dossier supprimé avec succès : "C:\Users\My\AppData\LocalLow\AskToolbar"

Dossier supprimé avec succès : "C:\Users\My\AppData\LocalLow\PriceGong"

Dossier supprimé avec succès : "C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}"

 

======== Page de démarrage Internet Explorer ========

 

Page de démarrage d'Internet Explorer restaurée avec succès.

 

===================================

 

Fin du nettoyage : 16:14:17

 

 

======== EOF ========

 

Merci d'envoyer le rapport à cette adresse, en précisant la raison d'emploi de cet outil. Cela permettera au développeur d'effectuer d'éventuelles modifications : lot12@hotmail.fr

 

Merci de votre contribution !

 

 

L'utilisateur à décidé de redémarrer l'ordinateur ultérieurement

 

 

 

 

 

OTL logfile created on: 16/01/2012 16:20:50 - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\My\Desktop

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

 

3,80 Gb Total Physical Memory | 1,43 Gb Available Physical Memory | 37,60% Memory free

7,61 Gb Paging File | 4,92 Gb Available in Paging File | 64,72% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 448,20 Gb Total Space | 299,98 Gb Free Space | 66,93% Space Free | Partition Type: NTFS

Drive D: | 17,27 Gb Total Space | 2,81 Gb Free Space | 16,25% Space Free | Partition Type: NTFS

Drive E: | 99,02 Mb Total Space | 94,93 Mb Free Space | 95,87% Space Free | Partition Type: FAT32

Drive H: | 488,25 Mb Total Space | 71,17 Mb Free Space | 14,58% Space Free | Partition Type: FAT

 

Computer Name: MY-PC | User Name: My | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 14 Days

 

========== Processes (All) ==========

 

PRC - [2012/01/16 14:37:49 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\My\Desktop\OTL.exe

PRC - [2012/01/06 14:09:34 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

PRC - [2012/01/06 14:09:32 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

PRC - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

PRC - [2011/12/24 17:50:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

PRC - [2011/12/12 02:33:46 | 001,760,328 | ---- | M] (ManyCam LLC) -- C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe

PRC - [2011/09/27 09:44:40 | 000,273,528 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

PRC - [2011/08/23 21:20:18 | 000,887,976 | ---- | M] (Ask) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe

PRC - [2011/08/11 16:22:56 | 000,170,608 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealUpgrade\realupgrade.exe

PRC - [2011/08/08 12:23:18 | 000,208,672 | ---- | M] ( ) -- C:\Program Files (x86)\GbPlugin\GbpSv.exe

PRC - [2011/08/04 02:18:43 | 000,126,400 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccsvchst.exe

PRC - [2011/06/09 23:52:40 | 012,002,664 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe

PRC - [2011/06/09 13:06:06 | 000,254,696 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

PRC - [2011/05/13 16:03:34 | 004,283,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

PRC - [2011/03/28 18:03:24 | 000,799,800 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe

PRC - [2011/03/28 17:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

PRC - [2011/03/28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE

PRC - [2010/04/01 11:58:04 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Common Files\SystemEngines\lupdater.exe

PRC - [2010/03/26 10:52:24 | 001,234,216 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe

PRC - [2010/03/25 14:39:22 | 000,490,280 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe

PRC - [2010/03/06 05:04:24 | 000,310,224 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe

PRC - [2010/02/25 15:21:32 | 000,227,896 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe

PRC - [2010/02/25 15:19:48 | 000,323,640 | ---- | M] ( Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

PRC - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

PRC - [2009/12/23 19:34:20 | 000,370,688 | ---- | M] (StarWind Software) -- C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe

PRC - [2009/10/16 13:59:58 | 000,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe

PRC - [2009/10/16 13:51:30 | 002,363,392 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe

PRC - [2009/10/06 00:08:42 | 000,210,216 | ---- | M] (CyberLink) -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe

PRC - [2009/10/01 02:01:32 | 002,320,920 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

PRC - [2009/10/01 02:01:30 | 000,268,824 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

PRC - [2009/07/08 20:55:26 | 000,323,584 | -H-- | M] (DeviceVM, Inc.) -- C:\SPLASH.SYS\config\DVMExportService.exe

PRC - [2009/07/06 17:20:18 | 000,247,152 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe

PRC - [2009/07/01 19:43:54 | 000,842,816 | ---- | M] (DigitalPersona, Inc.) -- C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe

PRC - [2009/07/01 19:43:54 | 000,322,624 | ---- | M] (DigitalPersona, Inc.) -- C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe

PRC - [2009/07/01 15:44:34 | 000,632,888 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe

PRC - [2008/12/08 14:50:04 | 000,054,576 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe

 

 

========== Modules (All) ==========

 

MOD - [2012/01/16 14:37:49 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\My\Desktop\OTL.exe

MOD - [2012/01/06 14:09:34 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

MOD - [2012/01/06 14:09:34 | 000,269,272 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\freebl3.dll

MOD - [2012/01/06 14:09:34 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll

MOD - [2012/01/06 14:09:33 | 002,124,760 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

MOD - [2012/01/06 14:09:33 | 000,814,040 | ---- | M] (sqlite.org) -- C:\Program Files (x86)\Mozilla Firefox\mozsqlite3.dll

MOD - [2012/01/06 14:09:33 | 000,646,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\nss3.dll

MOD - [2012/01/06 14:09:33 | 000,371,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\nssckbi.dll

MOD - [2012/01/06 14:09:33 | 000,187,352 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\nspr4.dll

MOD - [2012/01/06 14:09:33 | 000,109,528 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll

MOD - [2012/01/06 14:09:33 | 000,105,432 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\nssutil3.dll

MOD - [2012/01/06 14:09:33 | 000,043,992 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\mozutils.dll

MOD - [2012/01/06 14:09:33 | 000,015,832 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll

MOD - [2012/01/06 14:09:32 | 000,170,968 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\softokn3.dll

MOD - [2012/01/06 14:09:32 | 000,105,432 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\smime3.dll

MOD - [2012/01/06 14:09:32 | 000,021,976 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\plc4.dll

MOD - [2012/01/06 14:09:32 | 000,020,440 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\plds4.dll

MOD - [2012/01/06 14:09:32 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

MOD - [2012/01/06 14:09:31 | 016,096,216 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\xul.dll

MOD - [2012/01/06 14:09:31 | 000,154,584 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\ssl3.dll

MOD - [2012/01/06 14:09:31 | 000,019,928 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\xpcom.dll

MOD - [2011/12/25 22:42:08 | 008,527,008 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

MOD - [2011/12/24 17:50:18 | 000,460,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

MOD - [2011/12/24 17:50:16 | 002,227,784 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamnet.dll

MOD - [2011/12/24 17:50:16 | 000,472,136 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.dll

MOD - [2011/12/12 02:33:54 | 000,220,232 | ---- | M] (ManyCam LLC) -- C:\Program Files (x86)\ManyCam\Bin\VideoSrclcj.dll

MOD - [2011/12/12 02:33:52 | 000,498,760 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\cximagecrt.dll

MOD - [2011/12/12 02:33:48 | 000,123,976 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\CrashRpt.dll

MOD - [2011/12/12 02:33:46 | 001,760,328 | ---- | M] (ManyCam LLC) -- C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe

MOD - [2011/12/07 02:50:28 | 000,679,936 | ---- | M] (Intel Corporation.) -- C:\Program Files (x86)\ManyCam\Bin\cv099.dll

MOD - [2011/12/07 02:50:20 | 000,397,312 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\ManyCam\Bin\highgui099.dll

MOD - [2011/12/07 02:49:52 | 000,929,792 | ---- | M] (Intel Corporation.) -- C:\Program Files (x86)\ManyCam\Bin\cxcore099.dll

MOD - [2011/11/23 10:56:30 | 000,193,536 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\ieproxy.dll

MOD - [2011/11/23 10:56:30 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msls31.dll

MOD - [2011/11/17 03:38:39 | 001,292,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdll.dll

MOD - [2011/11/17 03:35:02 | 000,314,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\webio.dll

MOD - [2011/11/17 03:34:52 | 000,224,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\schannel.dll

MOD - [2011/11/17 03:34:52 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\secur32.dll

MOD - [2011/11/17 03:28:48 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sspicli.dll

MOD - [2011/11/03 20:46:47 | 009,705,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ieframe.dll

MOD - [2011/11/03 20:40:43 | 001,103,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\urlmon.dll

MOD - [2011/11/03 20:39:47 | 001,127,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wininet.dll

MOD - [2011/11/03 20:32:17 | 001,792,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\iertutil.dll

MOD - [2011/10/28 11:56:34 | 000,140,648 | ---- | M] (Microsoft Corporation) -- C:\Users\My\AppData\Local\Microsoft\Windows Live\Installer\Catalog\wlsres.dll.mui

MOD - [2011/10/26 02:32:11 | 001,328,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\quartz.dll

MOD - [2011/10/10 20:14:53 | 001,093,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_cbf5e994470a1a8f\mfc80u.dll

MOD - [2011/10/10 20:14:52 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll

MOD - [2011/10/10 20:14:52 | 000,554,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcp80.dll

MOD - [2011/09/27 09:45:01 | 000,170,496 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\lang\rpbrp_br.dll

MOD - [2011/09/27 09:45:01 | 000,010,240 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\lang\upgrade_br.dll

MOD - [2011/09/27 09:44:51 | 000,380,592 | ---- | M] (RealPlayer) -- C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll

MOD - [2011/09/27 09:44:51 | 000,047,616 | ---- | M] (RealNetworks, Inc.) -- C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll

MOD - [2011/09/27 09:44:51 | 000,046,592 | ---- | M] (RealNetworks, Inc.) -- C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll

MOD - [2011/09/27 09:44:51 | 000,043,520 | ---- | M] (RealNetworks, Inc.) -- C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchrome10browserrecordhelper.dll

MOD - [2011/09/27 09:44:40 | 000,273,528 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

MOD - [2011/09/24 16:43:26 | 000,569,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll

MOD - [2011/09/24 16:43:25 | 000,653,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll

MOD - [2011/09/24 16:43:13 | 000,159,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.6161_none_51cd0a7abbe4e19b\ATL90.dll

MOD - [2011/09/19 20:05:20 | 000,529,848 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\uialert.dll

MOD - [2011/09/19 20:04:52 | 000,534,968 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\isdatapr.dll

MOD - [2011/09/19 20:04:44 | 000,179,128 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\fwsesal.dll

MOD - [2011/09/19 20:04:36 | 000,288,696 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\avpapp32.dll

MOD - [2011/09/19 20:04:31 | 000,415,160 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\asoehook.dll

MOD - [2011/09/19 20:04:30 | 000,383,928 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ashelper.dll

MOD - [2011/09/16 13:55:16 | 019,467,424 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\Plug-Ins\CS5\File Formats\Camera Raw.8bi

MOD - [2011/09/15 10:25:56 | 001,719,584 | ---- | M] (Banco do Brasil) -- C:\Program Files (x86)\GbPlugin\gbieh.dll

MOD - [2011/08/30 18:58:36 | 003,519,488 | ---- | M] (Microsoft Corporation) -- c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\coreclr.dll

MOD - [2011/08/30 18:58:36 | 000,004,096 | ---- | M] (Microsoft Corporation) -- c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\pt-BR\mscorrc.dll

MOD - [2011/08/30 17:48:52 | 005,969,224 | ---- | M] (Microsoft Corporation) -- c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\agcore.dll

MOD - [2011/08/30 17:48:52 | 001,025,864 | ---- | M] ( Microsoft Corporation) -- c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll

MOD - [2011/08/30 02:21:25 | 012,872,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shell32.dll

MOD - [2011/08/27 02:26:27 | 000,571,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleaut32.dll

MOD - [2011/08/27 02:26:27 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleacc.dll

MOD - [2011/08/23 21:20:18 | 000,887,976 | ---- | M] (Ask) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe

MOD - [2011/08/22 00:53:35 | 000,066,472 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\efacli.dll

MOD - [2011/08/11 16:23:26 | 000,380,416 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealUpgrade\Common\hxmedpltfm.dll

MOD - [2011/08/11 16:22:56 | 000,268,288 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealUpgrade\Plugins\upgrade.dll

MOD - [2011/08/11 16:22:56 | 000,170,608 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealUpgrade\realupgrade.exe

MOD - [2011/08/04 02:24:55 | 000,646,016 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccl90u.dll

MOD - [2011/08/04 02:19:05 | 000,284,544 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccgevt.dll

MOD - [2011/08/04 02:19:04 | 000,380,800 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccjobmgr.dll

MOD - [2011/08/04 02:19:02 | 000,152,960 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccipc.dll

MOD - [2011/08/04 02:18:44 | 000,085,376 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccvrtrst.dll

MOD - [2011/08/04 02:18:43 | 000,135,040 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccsvc.dll

MOD - [2011/08/04 02:18:43 | 000,126,400 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccsvchst.exe

MOD - [2011/08/04 02:18:42 | 000,268,160 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccset.dll

MOD - [2011/07/16 02:24:22 | 001,114,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\kernel32.dll

MOD - [2011/07/16 02:24:22 | 000,272,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\KernelBase.dll

MOD - [2011/07/13 17:05:35 | 001,132,984 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\acctmgr.dll

MOD - [2011/07/13 17:05:25 | 000,323,512 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\codatapr.dll

MOD - [2011/06/16 02:33:18 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\xmllite.dll

MOD - [2011/06/12 12:15:00 | 004,221,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

MOD - [2011/06/09 23:52:46 | 000,398,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Required\PhotoShopAdapter.apl

MOD - [2011/06/09 23:52:46 | 000,329,064 | ---- | M] (Adobe Systems, Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Plug-Ins\MultiProcessor Support.8BX

MOD - [2011/06/09 23:52:44 | 000,209,256 | ---- | M] (Adobe Systems, Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Plug-Ins\MMXCore.8BX

MOD - [2011/06/09 23:52:44 | 000,039,272 | ---- | M] (Adobe Systems, Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Plug-Ins\FastCore.8BX

MOD - [2011/06/09 23:52:42 | 002,887,680 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\libmmd.dll

MOD - [2011/06/09 23:52:42 | 002,748,416 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\libmysqld.dll

MOD - [2011/06/09 23:52:42 | 000,587,232 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\ScCore.dll

MOD - [2011/06/09 23:52:42 | 000,073,728 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Symlib.dll

MOD - [2011/06/09 23:52:42 | 000,050,536 | ---- | M] (Adobe Systems, Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Plugin.dll

MOD - [2011/06/09 23:52:40 | 012,002,664 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe

MOD - [2011/06/09 23:52:40 | 000,671,200 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\ExtendScript.dll

MOD - [2011/06/09 13:06:06 | 000,254,696 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

MOD - [2011/05/24 08:40:05 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devobj.dll

MOD - [2011/05/24 08:40:05 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devrtl.dll

MOD - [2011/05/24 08:39:38 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cfgmgr32.dll

MOD - [2011/05/13 16:03:34 | 004,283,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

MOD - [2011/05/13 16:03:34 | 000,540,024 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\vvpltfrm.dll

MOD - [2011/05/13 16:03:34 | 000,189,304 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\shareanything.dll

MOD - [2011/05/13 15:31:38 | 000,889,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Contacts\PresenceIM.dll

MOD - [2011/05/13 15:31:38 | 000,651,664 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Contacts\livetransport.dll

MOD - [2011/05/13 15:31:38 | 000,396,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Contacts\ObjectStore.dll

MOD - [2011/05/13 15:31:38 | 000,292,752 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Contacts\liveNatTrav.dll

MOD - [2011/05/13 15:23:38 | 000,551,784 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Installer\wlshim.dll

MOD - [2011/05/13 14:55:50 | 003,164,008 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Shared\uxctl.dll

MOD - [2011/05/13 14:55:50 | 002,817,896 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Shared\wlidux.dll

MOD - [2011/05/13 14:55:50 | 002,457,448 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Shared\uxcore.dll

MOD - [2011/05/13 14:55:50 | 000,592,744 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Shared\uxcontacts.dll

MOD - [2011/05/13 14:55:50 | 000,104,296 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Shared\uxcalendar.dll

MOD - [2011/05/13 14:55:50 | 000,071,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Shared\wldcore.dll

MOD - [2011/05/13 14:55:50 | 000,040,296 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Shared\wldlog.dll

MOD - [2011/05/03 02:30:02 | 000,741,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\inetcomm.dll

MOD - [2011/03/28 20:33:28 | 000,856,984 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\wlidcli.dll

MOD - [2011/03/28 20:31:14 | 000,145,280 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL

MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF

MOD - [2011/03/11 03:33:59 | 001,137,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mfc42.dll

MOD - [2011/03/03 03:38:01 | 000,270,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dnsapi.dll

MOD - [2011/02/19 04:30:51 | 001,076,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\DWrite.dll

MOD - [2011/02/19 04:30:50 | 000,739,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d2d1.dll

MOD - [2011/01/20 07:15:26 | 008,887,752 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Office\Office14\1046\GrooveIntlResource.dll

MOD - [2011/01/17 03:47:13 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d10_1.dll

MOD - [2010/11/20 10:21:39 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wtsapi32.dll

MOD - [2010/11/20 10:21:39 | 000,036,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wshbth.dll

MOD - [2010/11/20 10:21:38 | 002,311,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wpdshext.dll

MOD - [2010/11/20 10:21:38 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ws2_32.dll

MOD - [2010/11/20 10:21:36 | 001,010,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WindowsCodecs.dll

MOD - [2010/11/20 10:21:36 | 000,351,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winhttp.dll

MOD - [2010/11/20 10:21:36 | 000,269,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wldap32.dll

MOD - [2010/11/20 10:21:36 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winmm.dll

MOD - [2010/11/20 10:21:36 | 000,172,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wintrust.dll

MOD - [2010/11/20 10:21:36 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winsta.dll

MOD - [2010/11/20 10:21:36 | 000,134,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WinSCard.dll

MOD - [2010/11/20 10:21:36 | 000,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wkscli.dll

MOD - [2010/11/20 10:21:35 | 000,381,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wer.dll

MOD - [2010/11/20 10:21:34 | 001,128,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vssapi.dll

MOD - [2010/11/20 10:21:34 | 000,363,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbemcomn.dll

MOD - [2010/11/20 10:21:33 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\usp10.dll

MOD - [2010/11/20 10:21:33 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\userenv.dll

MOD - [2010/11/20 10:21:30 | 000,082,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\thumbcache.dll

MOD - [2010/11/20 10:21:28 | 000,505,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\taskschd.dll

MOD - [2010/11/20 10:21:27 | 000,380,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sxs.dll

MOD - [2010/11/20 10:21:27 | 000,363,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\StructuredQuery.dll

MOD - [2010/11/20 10:21:27 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\t2embed.dll

MOD - [2010/11/20 10:21:26 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srvcli.dll

MOD - [2010/11/20 10:21:24 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\spp.dll

MOD - [2010/11/20 10:21:19 | 000,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shlwapi.dll

MOD - [2010/11/20 10:21:15 | 000,179,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shdocvw.dll

MOD - [2010/11/20 10:21:14 | 001,667,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\setupapi.dll

MOD - [2010/11/20 10:21:06 | 000,646,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\SearchFolder.dll

MOD - [2010/11/20 10:21:04 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samcli.dll

MOD - [2010/11/20 10:21:03 | 000,473,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\riched20.dll

MOD - [2010/11/20 10:21:03 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\RpcRtRemote.dll

MOD - [2010/11/20 10:21:03 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rtutils.dll

MOD - [2010/11/20 10:21:03 | 000,008,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\riched32.dll

MOD - [2010/11/20 10:20:57 | 002,504,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WMVCORE.DLL

MOD - [2010/11/20 10:20:57 | 000,988,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\propsys.dll

MOD - [2010/11/20 10:20:57 | 000,190,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\qcap.dll

MOD - [2010/11/20 10:20:55 | 000,547,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\PortableDeviceApi.dll

MOD - [2010/11/20 10:20:49 | 001,414,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ole32.dll

MOD - [2010/11/20 10:20:49 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\olepro32.dll

MOD - [2010/11/20 10:20:48 | 000,573,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\odbc32.dll

MOD - [2010/11/20 10:20:46 | 000,442,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntshrui.dll

MOD - [2010/11/20 10:20:46 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntlanman.dll

MOD - [2010/11/20 10:20:30 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nlaapi.dll

MOD - [2010/11/20 10:20:29 | 001,661,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\networkexplorer.dll

MOD - [2010/11/20 10:20:29 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netutils.dll

MOD - [2010/11/20 10:20:28 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netapi32.dll

MOD - [2010/11/20 10:19:56 | 001,390,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msxml6.dll

MOD - [2010/11/20 10:19:56 | 001,236,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msxml3.dll

MOD - [2010/11/20 10:19:56 | 000,232,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mswsock.dll

MOD - [2010/11/20 10:19:55 | 000,120,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvfw32.dll

MOD - [2010/11/20 10:19:48 | 002,341,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msi.dll

MOD - [2010/11/20 10:19:46 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msdmo.dll

MOD - [2010/11/20 10:19:45 | 000,481,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mscms.dll

MOD - [2010/11/20 10:19:45 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msasn1.dll

MOD - [2010/11/20 10:19:39 | 000,213,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\MMDevAPI.dll

MOD - [2010/11/20 10:19:23 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\IPHLPAPI.DLL

MOD - [2010/11/20 10:19:21 | 000,155,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imagehlp.dll

MOD - [2010/11/20 10:19:03 | 000,216,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\FWPUCLNT.DLL

MOD - [2010/11/20 10:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\fastprox.dll

MOD - [2010/11/20 10:19:02 | 000,320,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Faultrep.dll

MOD - [2010/11/20 10:19:01 | 001,493,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ExplorerFrame.dll

MOD - [2010/11/20 10:18:38 | 000,128,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\EhStorAPI.dll

MOD - [2010/11/20 10:18:36 | 000,508,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dxgi.dll

MOD - [2010/11/20 10:18:27 | 000,854,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dbghelp.dll

MOD - [2010/11/20 10:18:26 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\davclnt.dll

MOD - [2010/11/20 10:18:25 | 001,828,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d9.dll

MOD - [2010/11/20 10:18:25 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d10_1core.dll

MOD - [2010/11/20 10:18:25 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cscapi.dll

MOD - [2010/11/20 10:18:24 | 001,154,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\crypt32.dll

MOD - [2010/11/20 10:18:24 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\credssp.dll

MOD - [2010/11/20 10:18:23 | 000,530,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll

MOD - [2010/11/20 10:18:23 | 000,485,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll

MOD - [2010/11/20 10:18:09 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cabinet.dll

MOD - [2010/11/20 10:18:09 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\browcli.dll

MOD - [2010/11/20 10:18:05 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\AudioSes.dll

MOD - [2010/11/20 10:18:05 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\avifil32.dll

MOD - [2010/11/20 10:18:03 | 000,295,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\apphelp.dll

MOD - [2010/11/20 10:18:02 | 000,640,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\advapi32.dll

MOD - [2010/11/20 10:18:01 | 000,309,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\actxprxy.dll

MOD - [2010/11/20 10:16:52 | 000,193,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ksproxy.ax

MOD - [2010/11/20 10:16:52 | 000,107,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Kswdmcap.ax

MOD - [2010/11/20 10:16:50 | 000,320,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winspool.drv

MOD - [2010/11/20 10:16:50 | 000,172,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wdmaud.drv

MOD - [2010/11/20 10:08:57 | 000,833,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\user32.dll

MOD - [2010/11/20 10:08:57 | 000,663,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rpcrt4.dll

MOD - [2010/11/20 10:08:51 | 000,311,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gdi32.dll

MOD - [2010/11/20 10:08:51 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imm32.dll

MOD - [2010/11/20 09:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll

MOD - [2010/11/20 09:55:08 | 001,624,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll

MOD - [2010/09/13 02:24:04 | 003,258,632 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\uccapi.dll

MOD - [2010/09/13 02:24:02 | 005,914,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Messenger\rtmpltfm.dll

MOD - [2010/09/13 02:20:56 | 000,196,416 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Live\Shared\sqmapi.dll

MOD - [2010/08/26 23:19:04 | 000,698,248 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\cltaldis.dll

MOD - [2010/08/26 23:19:01 | 000,091,528 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\cltlmc.dll

MOD - [2010/08/23 14:12:00 | 000,106,464 | ---- | M] (Adobe Systems, Incorporated ) -- C:\Program Files (x86)\Common Files\Adobe\APE\3.1\adbeapecore.dll

MOD - [2010/07/11 15:47:40 | 000,453,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3dx10_41.dll

MOD - [2010/04/22 00:29:52 | 000,301,936 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\srtsp32.dll

MOD - [2010/04/02 10:56:06 | 000,020,336 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\MUI\17.6.0.32\16\01\cltres.loc

MOD - [2010/04/01 11:58:18 | 000,138,712 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\components\brwsrcmp.dll

MOD - [2010/04/01 11:58:18 | 000,023,000 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\components\browserdirprovider.dll

MOD - [2010/04/01 11:58:16 | 011,676,632 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\xul.dll

MOD - [2010/04/01 11:58:16 | 000,017,880 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\xpcom.dll

MOD - [2010/04/01 11:58:14 | 000,140,760 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\ssl3.dll

MOD - [2010/04/01 11:58:12 | 000,458,200 | ---- | M] (sqlite.org) -- C:\Program Files (x86)\Common Files\SystemEngines\sqlite3.dll

MOD - [2010/04/01 11:58:12 | 000,103,896 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\smime3.dll

MOD - [2010/04/01 11:58:10 | 000,087,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\nssutil3.dll

MOD - [2010/04/01 11:58:10 | 000,020,440 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\plc4.dll

MOD - [2010/04/01 11:58:10 | 000,017,368 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\plds4.dll

MOD - [2010/04/01 11:58:08 | 000,644,568 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\nss3.dll

MOD - [2010/04/01 11:58:08 | 000,349,656 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\nssckbi.dll

MOD - [2010/04/01 11:58:06 | 000,718,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\mozcrt19.dll

MOD - [2010/04/01 11:58:06 | 000,169,432 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\nspr4.dll

MOD - [2010/04/01 11:58:04 | 001,015,256 | ---- | M] () -- C:\Program Files (x86)\Common Files\SystemEngines\js3250.dll

MOD - [2010/04/01 11:58:04 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Common Files\SystemEngines\lupdater.exe

MOD - [2010/04/01 09:56:18 | 000,249,856 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\freebl3.dll

MOD - [2010/04/01 09:56:18 | 000,155,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\softokn3.dll

MOD - [2010/04/01 09:56:18 | 000,098,304 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Common Files\SystemEngines\nssdbm3.dll

MOD - [2010/03/26 10:52:24 | 001,234,216 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe

MOD - [2010/03/26 10:52:20 | 001,594,664 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NB.dll

MOD - [2010/03/26 10:52:20 | 000,472,360 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\LBFC.dll

MOD - [2010/03/26 10:52:20 | 000,279,848 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBRes_pt-BR.nls

MOD - [2010/03/26 10:52:20 | 000,121,952 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBTask.dll

MOD - [2010/03/19 08:16:18 | 006,182,184 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Nero\AdvrCntr5\AdvrCntr5.dll

MOD - [2010/03/09 02:51:48 | 000,578,528 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\FileInfo.dll

MOD - [2010/03/09 02:51:48 | 000,473,056 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\AdobeXMPFiles.dll

MOD - [2010/03/09 02:51:48 | 000,303,072 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\AdobeXMP.dll

MOD - [2010/03/09 02:51:04 | 000,704,264 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\SwitchboardClient.dll

MOD - [2010/03/09 02:42:50 | 001,053,608 | ---- | M] (IBM Corporation and others) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\icuuc36.dll

MOD - [2010/03/09 02:42:50 | 000,969,128 | ---- | M] (IBM Corporation and others) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\icuin36.dll

MOD - [2010/03/09 02:42:42 | 010,165,160 | ---- | M] (IBM Corporation and others) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\icudt36.dll

MOD - [2010/03/09 02:41:42 | 000,174,560 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\AXE8SharedExpat.dll

MOD - [2010/03/09 02:41:34 | 003,394,016 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\AGM.dll

MOD - [2010/03/09 02:41:34 | 003,042,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\CoolType.dll

MOD - [2010/03/09 02:41:34 | 000,284,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\BIB.dll

MOD - [2010/03/09 02:41:34 | 000,248,288 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\BIBUtils.dll

MOD - [2010/03/09 02:41:32 | 001,006,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\ACE.dll

MOD - [2010/03/09 02:40:34 | 000,030,176 | ---- | M] (Adobe Systems, Incorporated ) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\adbeape.dll

MOD - [2010/03/09 02:38:38 | 000,911,800 | ---- | M] (Adobe Systems, Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\AMTLib.dll

MOD - [2010/03/09 02:38:38 | 000,423,872 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\adobe_caps.dll

MOD - [2010/03/06 05:04:24 | 000,310,224 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe

MOD - [2010/03/06 04:44:34 | 002,191,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updatercore.dll

MOD - [2010/03/06 04:44:34 | 000,552,896 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\LogSession.dll

MOD - [2010/02/28 03:13:36 | 000,049,024 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

MOD - [2010/02/25 15:19:48 | 000,323,640 | ---- | M] ( Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe

MOD - [2010/02/25 15:19:26 | 000,364,088 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBSERVICE.dll

MOD - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

MOD - [2010/01/20 17:59:20 | 000,027,456 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\SolutionExplorer.dll

MOD - [2009/12/11 13:50:12 | 004,490,536 | R--- | M] (BCGSoft Ltd) -- C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\BCGCBPRO100u80.dll

MOD - [2009/12/10 03:39:30 | 000,334,192 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\sdkcmn.dll

MOD - [2009/10/30 17:15:00 | 004,489,216 | ---- | M] (Intel Corporation) -- C:\Windows\SysWOW64\igdumd32.dll

MOD - [2009/10/30 17:06:22 | 000,550,912 | ---- | M] (Intel Corporation) -- C:\Windows\SysWOW64\igdumdx32.dll

MOD - [2009/10/30 16:56:20 | 003,888,640 | ---- | M] (Intel Corporation) -- C:\Windows\SysWOW64\igd10umd32.dll

MOD - [2009/10/16 13:51:30 | 002,363,392 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe

MOD - [2009/10/16 13:10:14 | 007,745,536 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll

MOD - [2009/10/16 13:10:14 | 002,121,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll

MOD - [2009/10/16 13:10:14 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll

MOD - [2009/10/07 18:56:06 | 000,238,888 | ---- | M] (CyberLink) -- c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCWebCameraSource.ax

MOD - [2009/10/06 00:08:42 | 000,210,216 | ---- | M] (CyberLink) -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe

MOD - [2009/10/06 00:08:38 | 000,931,112 | ---- | M] () -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll

MOD - [2009/10/02 13:41:12 | 000,103,720 | ---- | M] (Cyberlink) -- c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCRgl.ax

MOD - [2009/10/02 13:41:04 | 000,353,576 | ---- | M] (Microsoft Corporation) -- c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\msvcr71.dll

MOD - [2009/10/02 13:41:00 | 001,052,968 | ---- | M] (Microsoft Corporation) -- c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MFC71u.dll

MOD - [2009/10/02 13:41:00 | 000,505,128 | ---- | M] (Microsoft Corporation) -- c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\msvcp71.dll

MOD - [2009/07/21 12:22:24 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcp71.dll

MOD - [2009/07/21 12:22:24 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcr71.dll

MOD - [2009/07/13 23:17:54 | 000,249,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcryptprimitives.dll

MOD - [2009/07/13 23:17:54 | 000,242,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rsaenh.dll

MOD - [2009/07/13 23:16:20 | 000,308,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wpc.dll

MOD - [2009/07/13 23:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wsock32.dll

MOD - [2009/07/13 23:16:20 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wship6.dll

MOD - [2009/07/13 23:16:20 | 000,009,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WSHTCPIP.DLL

MOD - [2009/07/13 23:16:19 | 000,237,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WMASF.DLL

MOD - [2009/07/13 23:16:19 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wlanapi.dll

MOD - [2009/07/13 23:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winrnr.dll

MOD - [2009/07/13 23:16:19 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winnsi.dll

MOD - [2009/07/13 23:16:19 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wlanutil.dll

MOD - [2009/07/13 23:16:18 | 000,262,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wevtapi.dll

MOD - [2009/07/13 23:16:18 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WcnApi.dll

MOD - [2009/07/13 23:16:17 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vsstrace.dll

MOD - [2009/07/13 23:16:17 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\wbemsvc.dll

MOD - [2009/07/13 23:16:17 | 000,029,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\wbemprox.dll

MOD - [2009/07/13 23:16:17 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\version.dll

MOD - [2009/07/13 23:16:15 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srclient.dll

MOD - [2009/07/13 23:16:15 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\slc.dll

MOD - [2009/07/13 23:16:14 | 000,040,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sfc_os.dll

MOD - [2009/07/13 23:16:14 | 000,007,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shfolder.dll

MOD - [2009/07/13 23:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sechost.dll

MOD - [2009/07/13 23:16:13 | 000,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samlib.dll

MOD - [2009/07/13 23:16:13 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\SensApi.dll

MOD - [2009/07/13 23:16:12 | 000,791,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\opengl32.dll

MOD - [2009/07/13 23:16:12 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasapi32.dll

MOD - [2009/07/13 23:16:12 | 000,316,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\PhotoMetadataHandler.dll

MOD - [2009/07/13 23:16:12 | 000,159,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\PortableDeviceTypes.dll

MOD - [2009/07/13 23:16:12 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\powrprof.dll

MOD - [2009/07/13 23:16:12 | 000,103,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oledlg.dll

MOD - [2009/07/13 23:16:12 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasman.dll

MOD - [2009/07/13 23:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\pnrpnsp.dll

MOD - [2009/07/13 23:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\profapi.dll

MOD - [2009/07/13 23:16:12 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasadhlp.dll

MOD - [2009/07/13 23:16:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\psapi.dll

MOD - [2009/07/13 23:16:11 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntmarta.dll

MOD - [2009/07/13 23:16:11 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdsapi.dll

MOD - [2009/07/13 23:16:11 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\npmproxy.dll

MOD - [2009/07/13 23:16:11 | 000,008,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nsi.dll

MOD - [2009/07/13 23:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netprofm.dll

MOD - [2009/07/13 23:16:03 | 000,040,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\networkitemfactory.dll

MOD - [2009/07/13 23:16:02 | 000,219,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ncrypt.dll

MOD - [2009/07/13 23:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\NapiNSP.dll

MOD - [2009/07/13 23:15:50 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcrt.dll

MOD - [2009/07/13 23:15:48 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mssprxy.dll

MOD - [2009/07/13 23:15:46 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msoert2.dll

MOD - [2009/07/13 23:15:44 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msimg32.dll

MOD - [2009/07/13 23:15:43 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msctf.dll

MOD - [2009/07/13 23:15:42 | 000,072,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msacm32.dll

MOD - [2009/07/13 23:15:41 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mpr.dll

MOD - [2009/07/13 23:15:41 | 000,054,784 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Defender\MpOAV.dll

MOD - [2009/07/13 23:15:40 | 000,177,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mlang.dll

MOD - [2009/07/13 23:15:40 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\midimap.dll

MOD - [2009/07/13 23:15:36 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\linkinfo.dll

MOD - [2009/07/13 23:15:35 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ksuser.dll

MOD - [2009/07/13 23:15:27 | 000,215,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\icm32.dll

MOD - [2009/07/13 23:15:27 | 000,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\IconCodecService.dll

MOD - [2009/07/13 23:15:24 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\hid.dll

MOD - [2009/07/13 23:15:22 | 000,130,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\glu32.dll

MOD - [2009/07/13 23:15:22 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gpapi.dll

MOD - [2009/07/13 23:15:21 | 000,462,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\FirewallAPI.dll

MOD - [2009/07/13 23:15:21 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fundisc.dll

MOD - [2009/07/13 23:15:21 | 000,014,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fltLib.dll

MOD - [2009/07/13 23:15:20 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fdWCN.dll

MOD - [2009/07/13 23:15:20 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\feclient.dll

MOD - [2009/07/13 23:15:20 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fdProxy.dll

MOD - [2009/07/13 23:15:20 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fdWNet.dll

MOD - [2009/07/13 23:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\es.dll

MOD - [2009/07/13 23:15:14 | 000,189,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\EhStorShell.dll

MOD - [2009/07/13 23:15:13 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dui70.dll

MOD - [2009/07/13 23:15:13 | 000,453,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dsound.dll

MOD - [2009/07/13 23:15:13 | 000,181,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\duser.dll

MOD - [2009/07/13 23:15:13 | 000,088,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dxva2.dll

MOD - [2009/07/13 23:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dwmapi.dll

MOD - [2009/07/13 23:15:13 | 000,032,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dtsh.dll

MOD - [2009/07/13 23:15:13 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\drprov.dll

MOD - [2009/07/13 23:15:11 | 000,136,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dinput.dll

MOD - [2009/07/13 23:15:11 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc.dll

MOD - [2009/07/13 23:15:11 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc6.dll

MOD - [2009/07/13 23:15:11 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dfscli.dll

MOD - [2009/07/13 23:15:10 | 000,531,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ddraw.dll

MOD - [2009/07/13 23:15:10 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devenum.dll

MOD - [2009/07/13 23:15:09 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dciman32.dll

MOD - [2009/07/13 23:15:08 | 000,019,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\davhlpr.dll

MOD - [2009/07/13 23:15:08 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d8thk.dll

MOD - [2009/07/13 23:15:07 | 000,103,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptnet.dll

MOD - [2009/07/13 23:15:07 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptsp.dll

MOD - [2009/07/13 23:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptbase.dll

MOD - [2009/07/13 23:15:03 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\clbcatq.dll

MOD - [2009/07/13 23:14:58 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\avrt.dll

MOD - [2009/07/13 23:14:57 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\atl.dll

MOD - [2009/07/13 23:14:57 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\avicap32.dll

MOD - [2009/07/13 23:14:11 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vidcap.ax

MOD - [2009/07/13 23:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx

MOD - [2009/07/13 23:14:08 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msacm32.drv

MOD - [2009/07/13 23:11:24 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\uxtheme.dll

MOD - [2009/07/13 23:11:23 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\lpk.dll

MOD - [2009/07/13 23:11:20 | 000,080,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcrypt.dll

MOD - [2009/07/13 23:10:22 | 000,002,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sfc.dll

MOD - [2009/07/13 23:09:14 | 000,229,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\odbcint.dll

MOD - [2009/07/13 23:09:00 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\normaliz.dll

MOD - [2009/07/13 23:06:08 | 000,084,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\INETRES.dll

MOD - [2009/07/01 19:43:54 | 000,842,816 | ---- | M] (DigitalPersona, Inc.) -- C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe

MOD - [2009/07/01 19:43:52 | 000,670,784 | ---- | M] (DigitalPersona, Inc.) -- C:\Program Files (x86)\DigitalPersona\Bin\DpOCache.dll

MOD - [2009/07/01 19:43:52 | 000,494,656 | ---- | M] (DigitalPersona, Inc.) -- C:\Program Files (x86)\DigitalPersona\Bin\DpOFeedb.dll

MOD - [2009/07/01 19:43:52 | 000,363,584 | ---- | M] (DigitalPersona, Inc.) -- C:\Program Files (x86)\DigitalPersona\Bin\DpOSet.dll

MOD - [2009/07/01 19:43:52 | 000,334,912 | ---- | M] (DigitalPersona, Inc.) -- C:\Windows\SysWOW64\DPFPApi.dll

MOD - [2009/07/01 19:43:50 | 000,240,704 | ---- | M] (DigitalPersona, Inc.) -- C:\Windows\SysWOW64\DpClback.dll

MOD - [2009/07/01 15:44:34 | 000,632,888 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe

MOD - [2008/12/08 14:50:04 | 000,054,576 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe

MOD - [2008/11/05 07:06:16 | 000,489,984 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\ManyCam\Bin\dbghelp.dll

 

 

========== Win32 Services (All) ==========

 

SRV:64bit: - [2011/11/17 04:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (VaultSvc)

SRV:64bit: - [2011/11/17 04:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)

SRV:64bit: - [2011/11/17 04:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)

SRV:64bit: - [2011/11/17 04:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (Netlogon)

SRV:64bit: - [2011/11/17 04:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)

SRV:64bit: - [2011/11/17 04:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\SysNative\lsass.exe -- (EFS)

SRV:64bit: - [2011/09/24 16:31:02 | 001,255,736 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\SysNative\Wat\WatAdminSvc.exe -- (WatAdminSvc)

SRV:64bit: - [2011/06/12 12:43:28 | 051,740,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)

SRV:64bit: - [2011/05/24 09:42:55 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)

SRV:64bit: - [2011/05/13 18:58:10 | 000,030,520 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Windows\SysNative\hpservice.exe -- (hpsrv)

SRV:64bit: - [2011/05/04 03:19:28 | 000,591,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SearchIndexer.exe -- (WSearch)

SRV:64bit: - [2011/03/28 21:11:06 | 002,292,096 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)

SRV:64bit: - [2011/03/03 04:24:16 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)

SRV:64bit: - [2011/02/19 10:05:15 | 001,139,200 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\FntCache.dll -- (FontCache)

SRV:64bit: - [2010/11/20 11:27:32 | 002,420,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)

SRV:64bit: - [2010/11/20 11:27:32 | 000,078,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\WUDFSvc.dll -- (wudfsvc)

SRV:64bit: - [2010/11/20 11:27:29 | 002,018,304 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WsmSvc.dll -- (WinRM)

SRV:64bit: - [2010/11/20 11:27:28 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)

SRV:64bit: - [2010/11/20 11:27:28 | 000,580,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)

SRV:64bit: - [2010/11/20 11:27:28 | 000,444,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\winhttp.dll -- (WinHttpAutoProxySvc)

SRV:64bit: - [2010/11/20 11:27:28 | 000,258,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WebClnt.dll -- (WebClient)

SRV:64bit: - [2010/11/20 11:27:28 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

SRV:64bit: - [2010/11/20 11:27:28 | 000,117,248 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wpdbusenum.dll -- (WPDBusEnum)

SRV:64bit: - [2010/11/20 11:27:27 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wcncsvc.dll -- (wcncsvc)

SRV:64bit: - [2010/11/20 11:27:26 | 001,743,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\sysmain.dll -- (SysMain)

SRV:64bit: - [2010/11/20 11:27:26 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\termsrv.dll -- (TermService)

SRV:64bit: - [2010/11/20 11:27:26 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)

SRV:64bit: - [2010/11/20 11:27:26 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)

SRV:64bit: - [2010/11/20 11:27:26 | 000,092,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\TabSvc.dll -- (TabletInputService)

SRV:64bit: - [2010/11/20 11:27:25 | 001,110,016 | ---- | M] (Microsoft Corporation) [unknown | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)

SRV:64bit: - [2010/11/20 11:27:25 | 000,370,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)

SRV:64bit: - [2010/11/20 11:27:25 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)

SRV:64bit: - [2010/11/20 11:27:25 | 000,121,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SessEnv.dll -- (SessionEnv)

SRV:64bit: - [2010/11/20 11:27:25 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)

SRV:64bit: - [2010/11/20 11:27:24 | 000,512,000 | ---- | M] (Microsoft Corporation) [unknown | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)

SRV:64bit: - [2010/11/20 11:27:24 | 000,512,000 | ---- | M] (Microsoft Corporation) [unknown | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)

SRV:64bit: - [2010/11/20 11:27:24 | 000,344,064 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)

SRV:64bit: - [2010/11/20 11:27:23 | 001,389,056 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pla.dll -- (pla)

SRV:64bit: - [2010/11/20 11:27:23 | 000,849,920 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)

SRV:64bit: - [2010/11/20 11:27:23 | 000,476,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\QAGENTRT.DLL -- (napagent)

SRV:64bit: - [2010/11/20 11:27:23 | 000,209,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)

SRV:64bit: - [2010/11/20 11:27:23 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\provsvc.dll -- (HomeGroupProvider)

SRV:64bit: - [2010/11/20 11:27:22 | 000,303,616 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)

SRV:64bit: - [2010/11/20 11:26:59 | 000,828,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)

SRV:64bit: - [2010/11/20 11:26:50 | 000,084,992 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Mcx2Svc.dll -- (Mcx2Svc)

SRV:64bit: - [2010/11/20 11:26:46 | 000,232,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ListSvc.dll -- (HomeGroupListener)

SRV:64bit: - [2010/11/20 11:26:42 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\KMSVC.DLL -- (hkmsvc)

SRV:64bit: - [2010/11/20 11:26:39 | 000,569,344 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\iphlpsvc.dll -- (iphlpsvc)

SRV:64bit: - [2010/11/20 11:26:39 | 000,501,248 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)

SRV:64bit: - [2010/11/20 11:26:36 | 000,853,504 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\IKEEXT.DLL -- (IKEEXT)

SRV:64bit: - [2010/11/20 11:26:28 | 000,777,728 | ---- | M] (Microsoft Corporation) [unknown | Running] -- C:\Windows\SysNative\gpsvc.dll -- (gpsvc)

SRV:64bit: - [2010/11/20 11:26:07 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)

SRV:64bit: - [2010/11/20 11:26:07 | 000,162,816 | ---- | M] (Microsoft Corporation) [unknown | Running] -- C:\Windows\SysNative\dps.dll -- (DPS)

SRV:64bit: - [2010/11/20 11:26:04 | 000,317,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)

SRV:64bit: - [2010/11/20 11:25:59 | 000,177,152 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)

SRV:64bit: - [2010/11/20 11:25:49 | 000,080,384 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\SysNative\certprop.dll -- (SCPolicySvc)

SRV:64bit: - [2010/11/20 11:25:49 | 000,080,384 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\SysNative\certprop.dll -- (CertPropSvc)

SRV:64bit: - [2010/11/20 11:25:47 | 000,136,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\browser.dll -- (Browser)

SRV:64bit: - [2010/11/20 11:25:45 | 000,705,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)

SRV:64bit: - [2010/11/20 11:25:44 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AxInstSv.dll -- (AxInstSV)

SRV:64bit: - [2010/11/20 11:25:42 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)

SRV:64bit: - [2010/11/20 11:25:42 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)

SRV:64bit: - [2010/11/20 11:25:40 | 000,070,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)

SRV:64bit: - [2010/11/20 11:25:33 | 001,525,248 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)

SRV:64bit: - [2010/11/20 11:25:28 | 001,504,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbengine.exe -- (wbengine)

SRV:64bit: - [2010/11/20 11:25:27 | 001,600,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)

SRV:64bit: - [2010/11/20 11:25:25 | 000,533,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vds.exe -- (vds)

SRV:64bit: - [2010/11/20 11:25:21 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)

SRV:64bit: - [2010/11/20 11:25:04 | 003,524,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\sppsvc.exe -- (sppsvc)

SRV:64bit: - [2010/11/20 11:24:58 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)

SRV:64bit: - [2010/11/20 11:24:47 | 000,689,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FXSSVC.exe -- (Fax)

SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)

SRV:64bit: - [2010/01/09 22:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)

SRV:64bit: - [2010/01/09 22:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64)

SRV:64bit: - [2009/10/21 05:35:26 | 000,240,640 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\stacsv64.exe -- (STacSV)

SRV:64bit: - [2009/07/13 23:41:59 | 000,229,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wwansvc.dll -- (WwanSvc)

SRV:64bit: - [2009/07/13 23:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)

SRV:64bit: - [2009/07/13 23:41:57 | 000,012,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wpcsvc.dll -- (WPCSvc)

SRV:64bit: - [2009/07/13 23:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)

SRV:64bit: - [2009/07/13 23:41:56 | 000,381,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\w32time.dll -- (W32Time)

SRV:64bit: - [2009/07/13 23:41:56 | 000,353,792 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\upnphost.dll -- (upnphost)

SRV:64bit: - [2009/07/13 23:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)

SRV:64bit: - [2009/07/13 23:41:56 | 000,237,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wecsvc.dll -- (Wecsvc)

SRV:64bit: - [2009/07/13 23:41:56 | 000,202,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbiosrvc.dll -- (WbioSrvc)

SRV:64bit: - [2009/07/13 23:41:56 | 000,163,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpo.dll -- (Power)

SRV:64bit: - [2009/07/13 23:41:56 | 000,090,624 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\SysNative\wdi.dll -- (WdiSystemHost)

SRV:64bit: - [2009/07/13 23:41:56 | 000,090,624 | ---- | M] (Microsoft Corporation) [unknown | Running] -- C:\Windows\SysNative\wdi.dll -- (WdiServiceHost)

SRV:64bit: - [2009/07/13 23:41:56 | 000,084,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wercplsupport.dll -- (wercplsupport)

SRV:64bit: - [2009/07/13 23:41:56 | 000,076,800 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wersvc.dll -- (WerSvc)

SRV:64bit: - [2009/07/13 23:41:56 | 000,040,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WcsPlugInService.dll -- (WcsPlugInService)

SRV:64bit: - [2009/07/13 23:41:56 | 000,038,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\uxsms.dll -- (UxSms)

SRV:64bit: - [2009/07/13 23:41:55 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\trkwks.dll -- (TrkWks)

SRV:64bit: - [2009/07/13 23:41:55 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tbssvc.dll -- (TBS)

SRV:64bit: - [2009/07/13 23:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)

SRV:64bit: - [2009/07/13 23:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)

SRV:64bit: - [2009/07/13 23:41:54 | 000,193,024 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ssdpsrv.dll -- (SSDPSRV)

SRV:64bit: - [2009/07/13 23:41:54 | 000,075,264 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\sstpsvc.dll -- (SstpSvc)

SRV:64bit: - [2009/07/13 23:41:54 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sppuinotify.dll -- (sppuinotify)

SRV:64bit: - [2009/07/13 23:41:54 | 000,029,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sensrsvc.dll -- (SensrSvc)

SRV:64bit: - [2009/07/13 23:41:53 | 000,438,784 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\p2psvc.dll -- (p2psvc)

SRV:64bit: - [2009/07/13 23:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\pnrpsvc.dll -- (PNRPsvc)

SRV:64bit: - [2009/07/13 23:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\pnrpsvc.dll -- (p2pimsvc)

SRV:64bit: - [2009/07/13 23:41:53 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\qwave.dll -- (QWAVE)

SRV:64bit: - [2009/07/13 23:41:53 | 000,190,976 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\SysNative\SCardSvr.dll -- (SCardSvr)

SRV:64bit: - [2009/07/13 23:41:53 | 000,186,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\pcasvc.dll -- (PcaSvc)

SRV:64bit: - [2009/07/13 23:41:53 | 000,159,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\regsvc.dll -- (RemoteRegistry)

SRV:64bit: - [2009/07/13 23:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)

SRV:64bit: - [2009/07/13 23:41:53 | 000,067,072 | ---- | M] (Microsoft Corporation) [unknown | Running] -- C:\Windows\SysNative\RpcEpMap.dll -- (RpcEptMapper)

SRV:64bit: - [2009/07/13 23:41:53 | 000,064,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\Sens.dll -- (SENS)

SRV:64bit: - [2009/07/13 23:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)

SRV:64bit: - [2009/07/13 23:41:53 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpauto.dll -- (PNRPAutoReg)

SRV:64bit: - [2009/07/13 23:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)

SRV:64bit: - [2009/07/13 23:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman)

SRV:64bit: - [2009/07/13 23:41:28 | 000,368,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msdtckrm.dll -- (KtmRm)

SRV:64bit: - [2009/07/13 23:41:27 | 000,097,792 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\mprdim.dll -- (RemoteAccess)

SRV:64bit: - [2009/07/13 23:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (THREADORDER)

SRV:64bit: - [2009/07/13 23:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)

SRV:64bit: - [2009/07/13 23:41:18 | 000,300,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lltdsvc.dll -- (lltdsvc)

SRV:64bit: - [2009/07/13 23:41:18 | 000,023,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lmhsvc.dll -- (lmhosts)

SRV:64bit: - [2009/07/13 23:41:11 | 000,156,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\iscsiexe.dll -- (MSiSCSI)

SRV:64bit: - [2009/07/13 23:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)

SRV:64bit: - [2009/07/13 23:41:09 | 000,101,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IPBusEnum.dll -- (IPBusEnum)

SRV:64bit: - [2009/07/13 23:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)

SRV:64bit: - [2009/07/13 23:40:52 | 000,034,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\FDResPub.dll -- (FDResPub)

SRV:64bit: - [2009/07/13 23:40:52 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\fdPHost.dll -- (fdPHost)

SRV:64bit: - [2009/07/13 23:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)

SRV:64bit: - [2009/07/13 23:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)

SRV:64bit: - [2009/07/13 23:40:28 | 000,291,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\defragsvc.dll -- (defragsvc)

SRV:64bit: - [2009/07/13 23:40:13 | 000,083,968 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\bthserv.dll -- (bthserv)

SRV:64bit: - [2009/07/13 23:40:10 | 000,100,864 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\SysNative\bdesvc.dll -- (BDESVC)

SRV:64bit: - [2009/07/13 23:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)

SRV:64bit: - [2009/07/13 23:40:01 | 000,032,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appidsvc.dll -- (AppIDSvc)

SRV:64bit: - [2009/07/13 23:39:55 | 000,203,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbem\WmiApSrv.exe -- (wmiApSrv)

SRV:64bit: - [2009/07/13 23:39:48 | 000,040,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\UI0Detect.exe -- (UI0Detect)

SRV:64bit: - [2009/07/13 23:39:41 | 000,014,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\snmptrap.exe -- (SNMPTRAP)

SRV:64bit: - [2009/07/13 23:39:21 | 000,141,824 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\SysNative\msdtc.exe -- (MSDTC)

SRV:64bit: - [2009/07/13 23:39:15 | 000,010,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Locator.exe -- (RpcLocator)

SRV:64bit: - [2009/07/13 23:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dllhost.exe -- (COMSysApp)

SRV:64bit: - [2009/07/13 23:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)

SRV:64bit: - [2009/07/12 23:18:24 | 001,924,400 | ---- | M] (Validity Sensors, Inc.) [Auto | Running] -- C:\Windows\SysNative\vcsFPService.exe -- (vcsFPService)

SRV:64bit: - [2009/03/03 08:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_d15ed671de43d681\AESTSr64.exe -- (AESTFilters)

SRV - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)

SRV - [2011/12/08 23:15:38 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)

SRV - [2011/09/09 17:10:28 | 000,086,072 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe -- (HP Support Assistant Service)

SRV - [2011/08/08 12:23:18 | 000,208,672 | ---- | M] ( ) [unknown | Running] -- C:\Program Files (x86)\GbPlugin\GbpSv.exe -- (GbpSv)

SRV - [2011/08/04 02:18:43 | 000,126,400 | R--- | M] (Symantec Corporation) [unknown | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ccSvcHst.exe -- (NIS)

SRV - [2011/05/13 15:27:02 | 001,492,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)

SRV - [2011/05/04 02:28:31 | 000,427,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWow64\SearchIndexer.exe -- (WSearch)

SRV - [2011/04/01 11:14:30 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)

SRV - [2011/03/28 18:03:24 | 000,799,800 | ---- | M] (Hewlett-Packard Company) [On_Demand | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe -- (hpqwmiex)

SRV - [2011/03/28 17:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)

SRV - [2011/03/28 11:21:16 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)

SRV - [2010/11/20 11:25:23 | 000,194,048 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\servicing\TrustedInstaller.exe -- (TrustedInstaller)

SRV - [2010/11/20 11:24:42 | 000,696,832 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\ehome\ehrecvr.exe -- (ehRecvr)

SRV - [2010/11/20 10:21:39 | 001,175,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WsmSvc.dll -- (WinRM) Windows Remote Management (WS-Management)

SRV - [2010/11/20 10:21:36 | 000,351,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\winhttp.dll -- (WinHttpAutoProxySvc)

SRV - [2010/11/20 10:21:35 | 000,276,992 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\wcncsvc.dll -- (wcncsvc)

SRV - [2010/11/20 10:21:35 | 000,204,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WebClnt.dll -- (WebClient)

SRV - [2010/11/20 10:21:28 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)

SRV - [2010/11/20 10:21:19 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)

SRV - [2010/11/20 10:21:08 | 000,113,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\SessEnv.dll -- (SessionEnv)

SRV - [2010/11/20 10:20:57 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\provsvc.dll -- (HomeGroupProvider)

SRV - [2010/11/20 10:20:54 | 001,508,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\pla.dll -- (pla)

SRV - [2010/11/20 10:18:30 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)

SRV - [2010/11/20 10:18:24 | 000,136,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)

SRV - [2010/11/20 10:17:22 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)

SRV - [2010/11/04 23:53:03 | 000,042,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)

SRV - [2010/11/04 23:52:14 | 000,856,400 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)

SRV - [2010/03/25 14:39:22 | 000,490,280 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)

SRV - [2010/03/18 14:27:14 | 000,138,576 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)

SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2010/02/25 15:21:32 | 000,227,896 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe -- (Com4QLBEx)

SRV - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)

SRV - [2009/12/23 19:34:20 | 000,370,688 | ---- | M] (StarWind Software) [Auto | Running] -- C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)

SRV - [2009/10/16 13:59:58 | 000,073,728 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService)

SRV - [2009/10/01 02:01:32 | 002,320,920 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®

SRV - [2009/10/01 02:01:30 | 000,268,824 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®

SRV - [2009/07/30 18:42:34 | 000,864,032 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Arquivos de Programas\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)

SRV - [2009/07/13 23:39:09 | 000,127,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\ehome\ehsched.exe -- (ehSched)

SRV - [2009/07/13 23:16:20 | 000,010,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\wpcsvc.dll -- (WPCSvc)

SRV - [2009/07/13 23:16:18 | 000,076,288 | ---- | M] (Microsoft Corporation) [unknown | Stopped] -- C:\Windows\SysWOW64\wdi.dll -- (WdiSystemHost)

SRV - [2009/07/13 23:16:18 | 000,076,288 | ---- | M] (Microsoft Corporation) [unknown | Running] -- C:\Windows\SysWOW64\wdi.dll -- (WdiServiceHost)

SRV - [2009/07/13 23:16:18 | 000,032,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WcsPlugInService.dll -- (WcsPlugInService)

SRV - [2009/07/13 23:16:17 | 000,266,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\upnphost.dll -- (upnphost)

SRV - [2009/07/13 23:16:13 | 000,049,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\Sens.dll -- (SENS)

SRV - [2009/07/13 23:16:12 | 000,210,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\qwave.dll -- (QWAVE)

SRV - [2009/07/13 23:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)

SRV - [2009/07/13 23:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\mprdim.dll -- (RemoteAccess)

SRV - [2009/07/13 23:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)

SRV - [2009/07/13 23:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)

SRV - [2009/07/13 23:14:28 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\perfhost.exe -- (PerfHost)

SRV - [2009/07/13 23:14:18 | 000,007,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\dllhost.exe -- (COMSysApp)

SRV - [2009/07/12 23:04:26 | 001,656,112 | ---- | M] (Validity Sensors, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vcsFPService.exe -- (vcsFPService)

SRV - [2009/07/08 20:55:26 | 000,323,584 | -H-- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\SPLASH.SYS\config\DVMExportService.exe -- (DvmMDES)

SRV - [2009/07/06 17:20:18 | 000,247,152 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe -- (RichVideo) Cyberlink RichVideo Service(CRVS)

SRV - [2009/07/01 19:43:54 | 000,322,624 | ---- | M] (DigitalPersona, Inc.) [Auto | Running] -- C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe -- (DpHost)

SRV - [2009/06/10 19:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2009/06/10 18:39:58 | 000,089,920 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)

 

 

========== Driver Services (All) ==========

 

DRV:64bit: - [2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)

DRV:64bit: - [2011/11/17 04:49:14 | 000,152,432 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ksecpkg.sys -- (KSecPkg)

DRV:64bit: - [2011/11/17 04:49:14 | 000,095,600 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ksecdd.sys -- (KSecDD)

DRV:64bit: - [2011/11/17 04:44:43 | 000,459,232 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\cng.sys -- (CNG)

DRV:64bit: - [2011/11/02 13:05:08 | 000,082,048 | ---- | M] (VSO Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pcouffin64a.sys -- (Pcouffin64)

DRV:64bit: - [2011/10/09 11:24:29 | 000,503,352 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)

DRV:64bit: - [2011/09/29 14:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tcpip.sys -- (TCPIP6)

DRV:64bit: - [2011/09/29 14:29:28 | 001,923,952 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tcpip.sys -- (Tcpip)

DRV:64bit: - [2011/09/22 16:32:50 | 000,173,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)

DRV:64bit: - [2011/08/22 00:53:36 | 000,451,704 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1109000.00C\symtdiv.sys -- (SYMTDIv)

DRV:64bit: - [2011/08/22 00:53:35 | 000,221,304 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1109000.00C\symefa64.sys -- (SymEFA)

DRV:64bit: - [2011/08/04 02:19:26 | 000,593,544 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1109000.00C\cchpx64.sys -- (ccHP)

DRV:64bit: - [2011/07/09 00:46:28 | 000,288,768 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb10.sys -- (mrxsmb10)

DRV:64bit: - [2011/06/10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2011/05/13 18:58:16 | 000,030,008 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hpdskflt.sys -- (hpdskflt)

DRV:64bit: - [2011/05/13 18:57:58 | 000,043,320 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelerometer.sys -- (Accelerometer)

DRV:64bit: - [2011/05/13 15:37:54 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)

DRV:64bit: - [2011/04/29 01:06:10 | 000,467,456 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srv.sys -- (srv)

DRV:64bit: - [2011/04/29 01:05:49 | 000,410,112 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srv2.sys -- (srv2)

DRV:64bit: - [2011/04/29 01:05:37 | 000,168,448 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\srvnet.sys -- (srvnet)

DRV:64bit: - [2011/04/28 01:55:08 | 000,552,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthport.sys -- (BTHPORT)

DRV:64bit: - [2011/04/28 01:54:56 | 000,080,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BTHUSB.SYS -- (BTHUSB)

DRV:64bit: - [2011/04/27 00:40:40 | 000,158,208 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb.sys -- (mrxsmb)

DRV:64bit: - [2011/04/27 00:39:37 | 000,128,000 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mrxsmb20.sys -- (mrxsmb20)

DRV:64bit: - [2011/04/25 00:34:03 | 000,499,200 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\afd.sys -- (AFD)

DRV:64bit: - [2011/03/25 01:29:26 | 000,343,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbhub.sys -- (usbhub)

DRV:64bit: - [2011/03/25 01:29:14 | 000,098,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbccgp.sys -- (usbccgp)

DRV:64bit: - [2011/03/25 01:29:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbehci.sys -- (usbehci)

DRV:64bit: - [2011/03/25 01:29:04 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbohci.sys -- (usbohci)

DRV:64bit: - [2011/03/25 01:29:03 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbuhci.sys -- (usbuhci)

DRV:64bit: - [2011/03/11 04:41:34 | 001,659,776 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\ntfs.sys -- (Ntfs)

DRV:64bit: - [2011/03/11 04:41:34 | 000,166,272 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvstor.sys -- (nvstor)

DRV:64bit: - [2011/03/11 04:41:34 | 000,148,352 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvraid.sys -- (nvraid)

DRV:64bit: - [2011/03/11 04:41:26 | 000,410,496 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorV.sys -- (iaStorV)

DRV:64bit: - [2011/03/11 04:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 04:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV:64bit: - [2011/03/11 02:37:16 | 000,091,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\USBSTOR.SYS -- (USBSTOR)

DRV:64bit: - [2011/02/23 02:55:04 | 000,090,624 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\bowser.sys -- (bowser)

DRV:64bit: - [2010/11/20 11:34:02 | 000,295,808 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volsnap.sys -- (volsnap)

DRV:64bit: - [2010/11/20 11:34:01 | 000,363,392 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volmgrx.sys -- (volmgrx)

DRV:64bit: - [2010/11/20 11:34:01 | 000,071,552 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\volmgr.sys -- (volmgr)

DRV:64bit: - [2010/11/20 11:34:00 | 000,215,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhdmp.sys -- (vhdmp)

DRV:64bit: - [2010/11/20 11:33:57 | 000,063,360 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\termdd.sys -- (TermDD)

DRV:64bit: - [2010/11/20 11:33:54 | 000,103,808 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sbp2port.sys -- (sbp2port)

DRV:64bit: - [2010/11/20 11:33:53 | 000,213,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\rdyboost.sys -- (rdyboost)

DRV:64bit: - [2010/11/20 11:33:48 | 000,184,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pci.sys -- (pci)

DRV:64bit: - [2010/11/20 11:33:48 | 000,075,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\partmgr.sys -- (partmgr)

DRV:64bit: - [2010/11/20 11:33:45 | 000,951,680 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ndis.sys -- (NDIS)

DRV:64bit: - [2010/11/20 11:33:45 | 000,366,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msrpc.sys -- (MsRPC)

DRV:64bit: - [2010/11/20 11:33:45 | 000,273,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msiscsi.sys -- (iScsiPrt)

DRV:64bit: - [2010/11/20 11:33:44 | 000,155,008 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mpio.sys -- (mpio)

DRV:64bit: - [2010/11/20 11:33:44 | 000,140,672 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\msdsm.sys -- (msdsm)

DRV:64bit: - [2010/11/20 11:33:44 | 000,031,104 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\msahci.sys -- (msahci)

DRV:64bit: - [2010/11/20 11:33:43 | 000,094,592 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mountmgr.sys -- (mountmgr)

DRV:64bit: - [2010/11/20 11:33:36 | 000,014,720 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hwpolicy.sys -- (hwpolicy)

DRV:64bit: - [2010/11/20 11:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2010/11/20 11:33:34 | 000,289,664 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\fltMgr.sys -- (FltMgr)

DRV:64bit: - [2010/11/20 11:33:25 | 000,982,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dxgkrnl.sys -- (DXGKrnl)

DRV:64bit: - [2010/11/20 11:32:46 | 000,334,208 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpi.sys -- (ACPI)

DRV:64bit: - [2010/11/20 11:28:59 | 000,223,248 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fvevol.sys -- (fvevol)

DRV:64bit: - [2010/11/20 09:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)

DRV:64bit: - [2010/11/20 09:04:37 | 000,210,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpwd.sys -- (RDPWD)

DRV:64bit: - [2010/11/20 09:04:09 | 000,039,424 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tssecsrv.sys -- (tssecsrv)

DRV:64bit: - [2010/11/20 08:52:37 | 000,088,576 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\wanarp.sys -- (Wanarpv6)

DRV:64bit: - [2010/11/20 08:52:37 | 000,088,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wanarp.sys -- (WANARP)

DRV:64bit: - [2010/11/20 08:52:35 | 000,129,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rasl2tp.sys -- (Rasl2tp) Miniporta WAN (L2TP)

DRV:64bit: - [2010/11/20 08:52:34 | 000,164,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ndiswan.sys -- (NdisWan)

DRV:64bit: - [2010/11/20 08:52:32 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\raspptp.sys -- (PptpMiniport) Miniporta WAN (PPTP)

DRV:64bit: - [2010/11/20 08:52:20 | 000,131,584 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\pacer.sys -- (Psched)

DRV:64bit: - [2010/11/20 08:52:20 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ndproxy.sys -- (NDProxy)

DRV:64bit: - [2010/11/20 08:52:19 | 000,082,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ipfltdrv.sys -- (IpFilterDriver)

DRV:64bit: - [2010/11/20 08:51:50 | 000,125,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tunnel.sys -- (tunnel)

DRV:64bit: - [2010/11/20 08:51:48 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tcpipreg.sys -- (tcpipreg)

DRV:64bit: - [2010/11/20 08:50:08 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ndisuio.sys -- (Ndisuio)

DRV:64bit: - [2010/11/20 08:44:56 | 000,229,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\1394ohci.sys -- (1394ohci)

DRV:64bit: - [2010/11/20 08:44:37 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\umbus.sys -- (umbus)

DRV:64bit: - [2010/11/20 08:44:34 | 000,184,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbvideo.sys -- (usbvideo) Dispositivo de vídeo USB (WDM)

DRV:64bit: - [2010/11/20 08:44:23 | 000,350,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HdAudio.sys -- (HdAudAddService)

DRV:64bit: - [2010/11/20 08:43:56 | 000,041,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\winusb.sys -- (WinUSB)

DRV:64bit: - [2010/11/20 08:43:49 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hidusb.sys -- (HidUsb)

DRV:64bit: - [2010/11/20 08:43:43 | 000,122,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hdaudbus.sys -- (HDAudBus)

DRV:64bit: - [2010/11/20 08:43:32 | 000,172,544 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WUDFRd.sys -- (WUDFRd)

DRV:64bit: - [2010/11/20 08:42:44 | 000,112,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WUDFPf.sys -- (WudfPf)

DRV:64bit: - [2010/11/20 08:34:00 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sffp_sd.sys -- (sffp_sd)

DRV:64bit: - [2010/11/20 08:33:25 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbdhid.sys -- (kbdhid)

DRV:64bit: - [2010/11/20 08:33:17 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CompositeBus.sys -- (CompositeBus)

DRV:64bit: - [2010/11/20 08:14:37 | 000,061,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\appid.sys -- (AppID)

DRV:64bit: - [2010/11/20 08:09:59 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\SysNative\drivers\scfilter.sys -- (scfilter)

DRV:64bit: - [2010/11/20 08:04:53 | 000,078,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IPMIDrv.sys -- (IPMIDRV)

DRV:64bit: - [2010/11/20 07:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)

DRV:64bit: - [2010/11/20 07:30:42 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipmi.sys -- (AcpiPmi)

DRV:64bit: - [2010/11/20 07:27:54 | 000,309,248 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\rdbss.sys -- (rdbss)

DRV:64bit: - [2010/11/20 07:26:42 | 000,140,800 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mrxdav.sys -- (MRxDAV)

DRV:64bit: - [2010/11/20 07:26:32 | 000,102,400 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\dfsc.sys -- (DfsC)

DRV:64bit: - [2010/11/20 07:26:11 | 000,328,192 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\udfs.sys -- (udfs)

DRV:64bit: - [2010/11/20 07:25:14 | 000,753,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\http.sys -- (HTTP)

DRV:64bit: - [2010/11/20 07:23:20 | 000,261,632 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\netbt.sys -- (NetBT)

DRV:64bit: - [2010/11/20 07:21:56 | 000,119,296 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tdx.sys -- (tdx)

DRV:64bit: - [2010/11/20 07:19:21 | 000,147,456 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\cdrom.sys -- (cdrom)

DRV:64bit: - [2010/04/29 03:03:51 | 000,150,064 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1109000.00C\ironx64.sys -- (SymIRON)

DRV:64bit: - [2010/04/22 00:29:51 | 000,505,392 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1109000.00C\srtsp64.sys -- (SRTSP)

DRV:64bit: - [2010/04/22 00:29:51 | 000,032,304 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1109000.00C\srtspx64.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)

DRV:64bit: - [2010/01/13 17:37:18 | 007,675,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) Driver do adaptador Intel®

DRV:64bit: - [2009/11/12 18:07:18 | 000,200,736 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)

DRV:64bit: - [2009/11/12 18:07:10 | 000,232,480 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)

DRV:64bit: - [2009/10/30 17:23:16 | 007,770,048 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)

DRV:64bit: - [2009/10/21 05:35:26 | 000,501,760 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)

DRV:64bit: - [2009/10/13 00:00:52 | 000,151,040 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)

DRV:64bit: - [2009/09/26 12:42:58 | 000,233,984 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Áudio do vídeo Intel®

DRV:64bit: - [2009/09/17 18:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64) Intel®

DRV:64bit: - [2009/08/29 22:17:18 | 000,433,200 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1109000.00C\symds64.sys -- (SymDS)

DRV:64bit: - [2009/08/07 11:24:14 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)

DRV:64bit: - [2009/07/13 23:52:31 | 000,367,696 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Running] -- C:\Windows\SysNative\clfs.sys -- (CLFS) Log Comum (CLFS)

DRV:64bit: - [2009/07/13 23:52:31 | 000,021,584 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\compbatt.sys -- (Compbatt)

DRV:64bit: - [2009/07/13 23:52:31 | 000,017,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\cmdide.sys -- (cmdide)

DRV:64bit: - [2009/07/13 23:52:21 | 000,491,088 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\adp94xx.sys -- (adp94xx)

DRV:64bit: - [2009/07/13 23:52:21 | 000,339,536 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\adpahci.sys -- (adpahci)

DRV:64bit: - [2009/07/13 23:52:21 | 000,182,864 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\adpu320.sys -- (adpu320)

DRV:64bit: - [2009/07/13 23:52:21 | 000,097,856 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\arcsas.sys -- (arcsas)

DRV:64bit: - [2009/07/13 23:52:21 | 000,087,632 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\arc.sys -- (arc)

DRV:64bit: - [2009/07/13 23:52:21 | 000,061,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AGP440.sys -- (agp440)

DRV:64bit: - [2009/07/13 23:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\atapi.sys -- (atapi)

DRV:64bit: - [2009/07/13 23:52:21 | 000,015,440 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdide.sys -- (amdide)

DRV:64bit: - [2009/07/13 23:52:21 | 000,015,440 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aliide.sys -- (aliide)

DRV:64bit: - [2009/07/13 23:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/13 23:48:27 | 000,060,496 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\mup.sys -- (Mup)

DRV:64bit: - [2009/07/13 23:48:27 | 000,049,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mouclass.sys -- (mouclass)

DRV:64bit: - [2009/07/13 23:48:27 | 000,032,320 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mssmbios.sys -- (mssmbios)

DRV:64bit: - [2009/07/13 23:48:27 | 000,015,424 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\msisadrv.sys -- (msisadrv)

DRV:64bit: - [2009/07/13 23:48:26 | 000,122,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NV_AGP.SYS -- (nv_agp)

DRV:64bit: - [2009/07/13 23:48:26 | 000,051,264 | ---- | M] (IBM Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nfrd960.sys -- (nfrd960)

DRV:64bit: - [2009/07/13 23:48:04 | 000,284,736 | ---- | M] (LSI Corporation, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\MegaSR.sys -- (MegaSR)

DRV:64bit: - [2009/07/13 23:48:04 | 000,115,776 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\lsi_scsi.sys -- (LSI_SCSI)

DRV:64bit: - [2009/07/13 23:48:04 | 000,114,752 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\lsi_fc.sys -- (LSI_FC)

DRV:64bit: - [2009/07/13 23:48:04 | 000,106,560 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\lsi_sas.sys -- (LSI_SAS)

DRV:64bit: - [2009/07/13 23:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/13 23:48:04 | 000,050,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kbdclass.sys -- (kbdclass)

DRV:64bit: - [2009/07/13 23:48:04 | 000,044,112 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iirsp.sys -- (iirsp)

DRV:64bit: - [2009/07/13 23:48:04 | 000,035,392 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\megasas.sys -- (megasas)

DRV:64bit: - [2009/07/13 23:48:04 | 000,020,544 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\isapnp.sys -- (isapnp)

DRV:64bit: - [2009/07/13 23:48:04 | 000,016,960 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelide.sys -- (intelide)

DRV:64bit: - [2009/07/13 23:47:49 | 000,055,376 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fsdepends.sys -- (FsDepends)

DRV:64bit: - [2009/07/13 23:47:48 | 000,530,496 | ---- | M] (Emulex) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\elxstor.sys -- (elxstor)

DRV:64bit: - [2009/07/13 23:47:48 | 000,073,280 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\disk.sys -- (Disk)

DRV:64bit: - [2009/07/13 23:47:48 | 000,070,224 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\fileinfo.sys -- (FileInfo)

DRV:64bit: - [2009/07/13 23:47:48 | 000,065,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\GAGP30KX.SYS -- (gagp30kx)

DRV:64bit: - [2009/07/13 23:47:48 | 000,024,144 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\crcdisk.sys -- (crcdisk)

DRV:64bit: - [2009/07/13 23:45:56 | 000,022,096 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wimmount.sys -- (WIMMount)

DRV:64bit: - [2009/07/13 23:45:55 | 000,654,928 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Wdf01000.sys -- (Wdf01000)

DRV:64bit: - [2009/07/13 23:45:55 | 000,161,872 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vsmraid.sys -- (vsmraid)

DRV:64bit: - [2009/07/13 23:45:55 | 000,064,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ULIAGPKX.SYS -- (uliagpkx)

DRV:64bit: - [2009/07/13 23:45:55 | 000,064,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UAGP35.SYS -- (uagp35)

DRV:64bit: - [2009/07/13 23:45:55 | 000,036,432 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vdrvroot.sys -- (vdrvroot)

DRV:64bit: - [2009/07/13 23:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/13 23:45:55 | 000,021,056 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wd.sys -- (Wd)

DRV:64bit: - [2009/07/13 23:45:55 | 000,019,008 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spldr.sys -- (spldr)

DRV:64bit: - [2009/07/13 23:45:55 | 000,017,488 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\viaide.sys -- (viaide)

DRV:64bit: - [2009/07/13 23:45:55 | 000,012,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\swenum.sys -- (swenum)

DRV:64bit: - [2009/07/13 23:45:46 | 001,524,816 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ql2300.sys -- (ql2300)

DRV:64bit: - [2009/07/13 23:45:46 | 000,080,464 | ---- | M] (Silicon Integrated Systems) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sisraid4.sys -- (SiSRaid4)

DRV:64bit: - [2009/07/13 23:45:45 | 000,220,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pcmcia.sys -- (pcmcia)

DRV:64bit: - [2009/07/13 23:45:45 | 000,128,592 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\ql40xx.sys -- (ql40xx)

DRV:64bit: - [2009/07/13 23:45:45 | 000,050,768 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pcw.sys -- (pcw)

DRV:64bit: - [2009/07/13 23:45:45 | 000,043,584 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sisraid2.sys -- (SiSRaid2)

DRV:64bit: - [2009/07/13 23:45:45 | 000,012,352 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pciide.sys -- (pciide)

DRV:64bit: - [2009/07/13 23:19:07 | 000,286,720 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrSerId.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)

DRV:64bit: - [2009/07/13 23:01:19 | 000,651,264 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\PEAuth.sys -- (PEAUTH)

DRV:64bit: - [2009/07/13 22:38:18 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbprint.sys -- (usbprint)

DRV:64bit: - [2009/07/13 22:17:46 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpbus.sys -- (rdpbus)

DRV:64bit: - [2009/07/13 22:16:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RDPREFMP.sys -- (RDPREFMP)

DRV:64bit: - [2009/07/13 22:16:34 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RDPENCDD.sys -- (RDPENCDD)

DRV:64bit: - [2009/07/13 22:16:34 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\RDPCDD.sys -- (RDPCDD)

DRV:64bit: - [2009/07/13 22:16:32 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tdtcp.sys -- (TDTCP)

DRV:64bit: - [2009/07/13 22:16:32 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tdpipe.sys -- (TDPIPE)

DRV:64bit: - [2009/07/13 22:10:48 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\modem.sys -- (Modem)

DRV:64bit: - [2009/07/13 22:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\ws2ifsl.sys -- (ws2ifsl)

DRV:64bit: - [2009/07/13 22:10:25 | 000,083,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rassstp.sys -- (RasSstp) Miniporta WAN (SSTP)

DRV:64bit: - [2009/07/13 22:10:24 | 000,060,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)

DRV:64bit: - [2009/07/13 22:10:17 | 000,092,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\raspppoe.sys -- (RasPppoe)

DRV:64bit: - [2009/07/13 22:10:13 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\asyncmac.sys -- (AsyncMac)

DRV:64bit: - [2009/07/13 22:10:09 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rasacd.sys -- (RasAcd)

DRV:64bit: - [2009/07/13 22:10:03 | 000,116,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ipnat.sys -- (IPNAT)

DRV:64bit: - [2009/07/13 22:10:00 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ndistapi.sys -- (NdisTapi)

DRV:64bit: - [2009/07/13 22:09:48 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\qwavedrv.sys -- (QWAVEdrv)

DRV:64bit: - [2009/07/13 22:09:26 | 000,044,544 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\netbios.sys -- (NetBIOS)

DRV:64bit: - [2009/07/13 22:09:26 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\wfplwf.sys -- (WfpLwf)

DRV:64bit: - [2009/07/13 22:09:09 | 000,093,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\smb.sys -- (Smb) Protocolos TCP/IP e TCP/IPv6 Orientados a Mensagens

 

continuaçao..

 

(sessão SMB)

DRV:64bit: - [2009/07/13 22:08:59 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\irenum.sys -- (IRENUM)

DRV:64bit: - [2009/07/13 22:08:51 | 000,076,800 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rspndr.sys -- (rspndr)

DRV:64bit: - [2009/07/13 22:08:51 | 000,060,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lltdio.sys -- (lltdio)

DRV:64bit: - [2009/07/13 22:08:25 | 000,077,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mpsdrv.sys -- (mpsdrv)

DRV:64bit: - [2009/07/13 22:08:13 | 000,035,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ndiscap.sys -- (NdisCap)

DRV:64bit: - [2009/07/13 22:07:23 | 000,318,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nwifi.sys -- (NativeWifiP)

DRV:64bit: - [2009/07/13 22:07:22 | 000,059,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vwififlt.sys -- (vwififlt)

DRV:64bit: - [2009/07/13 22:07:21 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vwifibus.sys -- (vwifibus)

DRV:64bit: - [2009/07/13 22:07:00 | 000,118,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bthpan.sys -- (BthPan) Dispositivo Bluetooth (Rede Pessoal)

DRV:64bit: - [2009/07/13 22:06:56 | 000,158,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rfcomm.sys -- (RFCOMM) Dispositivo Bluetooth (TDI de Protocolo RFCOMM)

DRV:64bit: - [2009/07/13 22:06:53 | 000,041,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bthenum.sys -- (BthEnum)

DRV:64bit: - [2009/07/13 22:06:52 | 000,100,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidbth.sys -- (HidBth)

DRV:64bit: - [2009/07/13 22:06:52 | 000,072,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthmodem.sys -- (BTHMODEM)

DRV:64bit: - [2009/07/13 22:06:52 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\umpass.sys -- (UmPass)

DRV:64bit: - [2009/07/13 22:06:45 | 000,072,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ohci1394.sys -- (ohci1394) 1394 OHCI Compliant Host Controller (Herdado)

DRV:64bit: - [2009/07/13 22:06:37 | 000,100,352 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbcir.sys -- (usbcir) eHome Infrared Receiver (USBCIR)

DRV:64bit: - [2009/07/13 22:06:34 | 000,045,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\circlass.sys -- (circlass)

DRV:64bit: - [2009/07/13 22:06:24 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mshidkmdf.sys -- (mshidkmdf)

DRV:64bit: - [2009/07/13 22:06:23 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hidir.sys -- (HidIr)

DRV:64bit: - [2009/07/13 22:06:16 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\drmkaud.sys -- (drmkaud)

DRV:64bit: - [2009/07/13 22:02:08 | 000,015,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MTConfig.sys -- (MTConfig)

DRV:64bit: - [2009/07/13 22:02:07 | 000,027,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wacompen.sys -- (WacomPen)

DRV:64bit: - [2009/07/13 22:01:03 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sffp_mmc.sys -- (sffp_mmc)

DRV:64bit: - [2009/07/13 22:01:02 | 000,016,896 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sfloppy.sys -- (sfloppy)

DRV:64bit: - [2009/07/13 22:01:01 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sffdisk.sys -- (sffdisk)

DRV:64bit: - [2009/07/13 22:00:54 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fdc.sys -- (fdc)

DRV:64bit: - [2009/07/13 22:00:54 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\flpydisk.sys -- (flpydisk)

DRV:64bit: - [2009/07/13 22:00:41 | 000,097,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\parport.sys -- (Parport)

DRV:64bit: - [2009/07/13 22:00:40 | 000,094,208 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\serial.sys -- (Serial)

DRV:64bit: - [2009/07/13 22:00:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serenum.sys -- (Serenum)

DRV:64bit: - [2009/07/13 22:00:20 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mouhid.sys -- (mouhid)

DRV:64bit: - [2009/07/13 22:00:20 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sermouse.sys -- (sermouse)

DRV:64bit: - [2009/07/13 22:00:19 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ksthunk.sys -- (ksthunk)

DRV:64bit: - [2009/07/13 22:00:18 | 000,011,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mskssrv.sys -- (MSKSSRV)

DRV:64bit: - [2009/07/13 22:00:17 | 000,008,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mstee.sys -- (MSTEE)

DRV:64bit: - [2009/07/13 22:00:17 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mspclock.sys -- (MSPCLOCK)

DRV:64bit: - [2009/07/13 22:00:17 | 000,006,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mspqm.sys -- (MSPQM)

DRV:64bit: - [2009/07/13 22:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\beep.sys -- (Beep)

DRV:64bit: - [2009/07/13 21:38:52 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\monitor.sys -- (monitor)

DRV:64bit: - [2009/07/13 21:38:47 | 000,029,184 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vga.sys -- (VgaSave)

DRV:64bit: - [2009/07/13 21:38:47 | 000,029,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vgapnp.sys -- (vga)

DRV:64bit: - [2009/07/13 21:37:18 | 000,040,448 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\discache.sys -- (discache)

DRV:64bit: - [2009/07/13 21:35:59 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\blbdrive.sys -- (blbdrive)

DRV:64bit: - [2009/07/13 21:31:06 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidbatt.sys -- (HidBatt)

DRV:64bit: - [2009/07/13 21:31:04 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\errdev.sys -- (ErrDev)

DRV:64bit: - [2009/07/13 21:31:03 | 000,017,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CmBatt.sys -- (CmBatt)

DRV:64bit: - [2009/07/13 21:31:02 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wmiacpi.sys -- (WmiAcpi)

DRV:64bit: - [2009/07/13 21:26:13 | 000,113,152 | ---- | M] (Microsoft Corporation) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\luafv.sys -- (luafv)

DRV:64bit: - [2009/07/13 21:25:40 | 000,034,304 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\filetrace.sys -- (Filetrace)

DRV:64bit: - [2009/07/13 21:23:29 | 000,204,800 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\fastfat.sys -- (fastfat)

DRV:64bit: - [2009/07/13 21:23:29 | 000,195,072 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\exfat.sys -- (exfat)

DRV:64bit: - [2009/07/13 21:21:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\nsiproxy.sys -- (nsiproxy)

DRV:64bit: - [2009/07/13 21:19:57 | 000,105,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\i8042prt.sys -- (i8042prt)

DRV:64bit: - [2009/07/13 21:19:48 | 000,044,032 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\npfs.sys -- (Npfs)

DRV:64bit: - [2009/07/13 21:19:47 | 000,092,160 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cdfs.sys -- (cdfs)

DRV:64bit: - [2009/07/13 21:19:47 | 000,026,112 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\msfs.sys -- (Msfs)

DRV:64bit: - [2009/07/13 21:19:38 | 000,006,144 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\null.sys -- (Null)

DRV:64bit: - [2009/07/13 21:19:25 | 000,064,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdk8.sys -- (AmdK8)

DRV:64bit: - [2009/07/13 21:19:25 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\intelppm.sys -- (intelppm)

DRV:64bit: - [2009/07/13 21:19:25 | 000,060,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdppm.sys -- (AmdPPM)

DRV:64bit: - [2009/07/13 21:19:25 | 000,060,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\processr.sys -- (Processor)

DRV:64bit: - [2009/07/01 18:46:52 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)

DRV:64bit: - [2009/07/01 18:46:48 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)

DRV:64bit: - [2009/07/01 18:46:40 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)

DRV:64bit: - [2009/06/29 16:17:00 | 000,070,656 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\enecir.sys -- (enecir)

DRV:64bit: - [2009/06/10 19:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)

DRV:64bit: - [2009/06/10 19:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)

DRV:64bit: - [2009/06/10 19:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)

DRV:64bit: - [2009/06/10 18:41:10 | 000,047,104 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrSerWdm.sys -- (BrSerWdm)

DRV:64bit: - [2009/06/10 18:41:10 | 000,014,976 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrUsbMdm.sys -- (BrUsbMdm)

DRV:64bit: - [2009/06/10 18:41:10 | 000,014,720 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrUsbSer.sys -- (BrUsbSer)

DRV:64bit: - [2009/06/10 18:41:06 | 000,018,432 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrFiltLo.sys -- (BrFiltLo)

DRV:64bit: - [2009/06/10 18:41:06 | 000,008,704 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BrFiltUp.sys -- (BrFiltUp)

DRV:64bit: - [2009/06/10 18:37:19 | 000,023,040 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\secdrv.sys -- (secdrv)

DRV:64bit: - [2009/06/10 18:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)

DRV:64bit: - [2009/06/10 18:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel®

DRV:64bit: - [2009/06/10 18:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)

DRV:64bit: - [2009/06/10 18:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/10 18:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/10 18:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/10 18:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/05/13 00:39:00 | 000,239,152 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)

DRV:64bit: - [2009/04/29 08:48:32 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)

DRV:64bit: - [2009/04/07 21:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)

DRV:64bit: - [2008/03/13 05:46:00 | 000,027,136 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ManyCam_x64.sys -- (ManyCam)

DRV - [2011/11/14 17:28:01 | 001,156,216 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20111114.002\BHDrvx64.sys -- (BHDrvx64)

DRV - [2011/11/10 10:30:03 | 002,048,632 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20111121.036\EX64.SYS -- (NAVEX15)

DRV - [2011/11/10 10:30:03 | 000,117,880 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20111121.036\ENG64.SYS -- (NAVENG)

DRV - [2011/11/09 08:42:26 | 000,482,936 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)

DRV - [2011/11/09 08:42:26 | 000,138,360 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)

DRV - [2011/09/22 07:57:56 | 000,488,568 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20111119.031\IDSviA64.sys -- (IDSVia64)

DRV - [2011/08/08 12:23:42 | 000,044,064 | ---- | M] (GAS Tecnologia) [Kernel | Boot | Stopped] -- C:\Windows\system32\drivers\gbpkm.sys -- (GbpKm)

DRV - [2009/09/27 14:47:24 | 000,021,624 | -H-- | M] (DeviceVM, Inc.) [Kernel | System | Running] -- C:\SPLASH.SYS\config\dvmio.sys -- (DVMIO)

DRV - [2009/07/13 23:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/3

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/3

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.fr

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com.br/

IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)

IE - HKCU\..\URLSearchHook: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - No CLSID value found

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..browser.search.defaultengine: "Ask.com"

FF - prefs.js..browser.search.defaultenginename: "Ask.com"

FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar_PT Customized Web Search"

FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2851643&SearchSource=3&q={searchTerms}"

FF - prefs.js..browser.search.order.1: "Ask.com"

FF - prefs.js..browser.search.selectedEngine: "Ask.com"

FF - prefs.js..browser.search.useDBForOrder: true

FF - prefs.js..browser.startup.homepage: "http://www.google.com.br/"

FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=MYC-ST&o=102869&locale=pt_BR&apn_uid=8307a1cb-9dcb-431e-850c-72a87b4a7e2e&apn_ptnrs=5J&apn_sauid=54A570CF-6DFF-40AB-A3B2-975AA5C26544&apn_dtid=YYYYYYYYBR&&q="

 

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\My\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\My\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\ [2011/09/25 23:48:24 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\otis@digitalpersona.com: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2011/09/22 15:37:16 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn_2010_9_0_6 [2012/01/16 08:26:00 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/09/27 09:44:51 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/06 14:09:34 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/16 08:38:16 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\otis@digitalpersona.com: C:\Program Files (x86)\DigitalPersona\Bin\firefoxext [2011/09/22 15:37:16 | 000,000,000 | ---D | M]

 

[2012/01/11 15:57:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\My\AppData\Roaming\mozilla\Extensions

[2012/01/11 08:08:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\My\AppData\Roaming\mozilla\Firefox\Profiles\1q6lsz8d.default\extensions

[2011/11/29 19:51:15 | 000,000,000 | ---D | M] (Modulo de Seguranca - Banco do Brasil) -- C:\Users\My\AppData\Roaming\mozilla\Firefox\Profiles\1q6lsz8d.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}

[2012/01/11 08:08:43 | 000,000,000 | ---D | M] (Guardiao Itau 30 horas) -- C:\Users\My\AppData\Roaming\mozilla\Firefox\Profiles\1q6lsz8d.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E8873}

[2012/01/09 11:05:57 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\My\AppData\Roaming\mozilla\Firefox\Profiles\1q6lsz8d.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}

[2011/12/25 21:54:56 | 000,002,405 | ---- | M] () -- C:\Users\My\AppData\Roaming\Mozilla\Firefox\Profiles\1q6lsz8d.default\searchplugins\askcom.xml

[2011/10/13 23:09:55 | 000,000,931 | ---- | M] () -- C:\Users\My\AppData\Roaming\Mozilla\Firefox\Profiles\1q6lsz8d.default\searchplugins\conduit.xml

[2012/01/06 14:16:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

[2011/09/27 09:44:51 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT

[2012/01/06 14:09:34 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll

[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll

[2012/01/06 14:09:32 | 000,001,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\buscape.xml

[2012/01/06 14:09:32 | 000,001,212 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mercadolivre.xml

[2012/01/06 14:09:32 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

[2012/01/06 14:09:32 | 000,001,168 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-br.xml

[2012/01/06 14:09:32 | 000,000,952 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-br.xml

 

========== Chrome ==========

 

 

O1 HOSTS File: ([2011/10/01 16:45:08 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O2:64bit: - BHO: (DigitalPersona Personal Extension) - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Arquivos de Programas\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)

O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de Programas\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)

O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)

O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Arquivos de Programas\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)

O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)

O2 - BHO: (DigitalPersona Personal Extension) - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)

O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\coieplg.dll (Symantec Corporation)

O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\ipsbho.dll (Symantec Corporation)

O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)

O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\Program Files (x86)\GbPlugin\gbiehuni.dll (Banco Unibanco)

O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)

O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\17.9.0.12\coieplg.dll (Symantec Corporation)

O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)

O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E0301295-AB3E-4AF3-979F-3D453C5F9F48} - No CLSID value found.

O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)

O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [igfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [smartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()

O4:64bit: - HKLM..\Run: [sysTrayApp] C:\Arquivos de Programas\IDT\WDM\sttray64.exe (IDT, Inc.)

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)

O4 - HKLM..\Run: [DpAgent] C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)

O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [NBAgent] C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)

O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)

O4 - HKLM..\Run: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)

O4 - HKCU..\Run: [AdobeBridge] C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe (Adobe Systems, Inc.)

O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe (Alcohol Soft Development Team)

O4 - HKCU..\Run: [Facebook Update] C:\Users\My\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)

O4 - HKCU..\Run: [ManyCam] C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe (ManyCam LLC)

O4 - HKCU..\Run: [NitroPC] C:\Program Files (x86)\NitroPC\NitroPC.exe (Intelliclick Informatica)

O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()

O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1

O8:64bit: - Extra context menu item: &Enviar para o OneNote - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O8:64bit: - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)

O8:64bit: - Extra context menu item: Enviar imagem para Dispositivo &Bluetooth... - C:\Arquivos de Programas\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()

O8:64bit: - Extra context menu item: Enviar página para Dispositivo &Bluetooth ... - C:\Arquivos de Programas\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\My\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()

O8 - Extra context menu item: &Enviar para o OneNote - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: Enviar imagem para Dispositivo &Bluetooth... - C:\Arquivos de Programas\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()

O8 - Extra context menu item: Enviar página para Dispositivo &Bluetooth ... - C:\Arquivos de Programas\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\My\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()

O9:64bit: - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O9:64bit: - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O9:64bit: - Extra Button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)

O9:64bit: - Extra 'Tools' menuitem : &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)

O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Arquivos de Programas\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Arquivos de Programas\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O9 - Extra Button: Enviar para Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Arquivos de Programas\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O9 - Extra 'Tools' menuitem : Enviar para Dispositivo &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Arquivos de Programas\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()

O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)

O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)

O1364bit: - gopher Prefix: missing

O13 - gopher Prefix: missing

O15 - HKCU\..Trusted Domains: bancobrasil.com.br ([www] * in Trusted sites)

O15 - HKCU\..Trusted Domains: bancobrasil.com.br ([www14] * in Trusted sites)

O15 - HKCU\..Trusted Domains: bancobrasil.com.br ([www2] * in Trusted sites)

O15 - HKCU\..Trusted Domains: bb.com.br ([www] * in Trusted sites)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)

O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} https://clickbanking.itau.com.br/itau/gbplugin/gbplugin2/cab/GbPluginUni.cab (GbPluginObj Class)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 201.6.2.40 201.6.2.160

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0FE7BCAE-57AA-4BD5-A5FA-8D289C391731}: DhcpNameServer = 201.6.2.40 201.6.2.160

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2C60A594-4E99-47B1-AA49-8AA92D3EC910}: DhcpNameServer = 192.168.0.1

O18:64bit: - Protocol\Handler\livecall - No CLSID value found

O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de Programas\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found

O18:64bit: - Protocol\Handler\msnim - No CLSID value found

O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found

O18:64bit: - Protocol\Handler\wlpg - No CLSID value found

O18 - Protocol\Handler\ms-help - No CLSID value found

O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)

O20 - Winlogon\Notify\ GbPluginBb: DllName - (C:\Program Files (x86)\GbPlugin\gbieh.dll) - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)

O20 - Winlogon\Notify\ GbPluginUni: DllName - (C:\PROGRA~2\GbPlugin\gbiehUni.dll) - C:\Program Files (x86)\GbPlugin\gbiehuni.dll (Banco Unibanco)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de Programas\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)

O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399008} - C:\Program Files (x86)\GbPlugin\gbiehuni.dll (Banco Unibanco)

O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399F83} - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)

O32 - HKLM CDRom: AutoRun - 1

O33 - MountPoints2\{f428c4a4-1302-11e1-a113-0027139bf0ab}\Shell - "" = AutoRun

O33 - MountPoints2\{f428c4a4-1302-11e1-a113-0027139bf0ab}\Shell\AutoRun\command - "" = I:\AutoRun.exe

O33 - MountPoints2\{f428c4b3-1302-11e1-a113-0027139bf0ab}\Shell - "" = AutoRun

O33 - MountPoints2\{f428c4b3-1302-11e1-a113-0027139bf0ab}\Shell\AutoRun\command - "" = J:\AutoRun.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

CREATERESTOREPOINT

Restore point Set: OTL Restore Point

 

 

 

========== Files/Folders - Created Within 14 Days ==========

 

[2012/01/16 14:37:47 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\My\Desktop\OTL.exe

[2012/01/16 14:37:08 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Roaming\Malwarebytes

[2012/01/16 14:37:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2012/01/16 14:37:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2012/01/16 14:37:01 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2012/01/16 14:37:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2012/01/16 11:31:52 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{52C643F6-73E8-4A80-8B7D-450F615177A7}

[2012/01/16 11:31:21 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{8DB33BA0-F643-48A0-A55E-A4B5C63DD851}

[2012/01/15 23:30:53 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{C8BB9343-E968-469C-A015-FCCE24A93DF5}

[2012/01/15 23:30:31 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{8E9E56E3-36F4-4B84-A037-0C57F8E9BFD8}

[2012/01/15 22:38:40 | 000,000,000 | ---D | C] -- C:\Users\My\Desktop\DVD_01_1

[2012/01/15 11:29:49 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{C5FFA7E2-AF38-4A0C-9EB5-F77259FE5FDE}

[2012/01/15 11:29:16 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{B7F3C999-89C5-48D3-B6DF-DB1B91FC4785}

[2012/01/14 21:31:23 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{C2C613AE-8466-48A4-9F64-1B944C2D9D7E}

[2012/01/14 21:31:00 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{69CA3331-A93B-4592-8E22-CF33416061F6}

[2012/01/14 15:55:46 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\Facebook

[2012/01/14 09:30:15 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{96408633-ED87-4D99-8107-2C2E52843009}

[2012/01/14 09:29:56 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{61534FAC-B462-4F39-867C-9BC807143A97}

[2012/01/13 21:15:36 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{B5E0CD2D-B2C1-47A9-96CC-F5C4E269D37F}

[2012/01/13 21:15:13 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{9F5AD6AB-D010-4142-9036-450F4B96584B}

[2012/01/13 15:24:47 | 001,998,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3dx9_43.dll

[2012/01/13 09:13:58 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{1C268B59-8A59-43A7-B2D4-D5744D28D1FD}

[2012/01/13 09:13:42 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{86ED835F-FA47-4634-95D6-CD346F662BE0}

[2012/01/12 19:41:24 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll

[2012/01/12 19:41:24 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll

[2012/01/12 19:41:24 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll

[2012/01/12 19:41:24 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll

[2012/01/12 19:41:23 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll

[2012/01/12 19:41:23 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll

[2012/01/12 13:21:21 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{3F9A537B-F7E1-4B6C-B545-DC4F1A37D7A0}

[2012/01/12 13:20:59 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{814E9AC1-B6B4-4AB6-820B-CB7D029CE657}

[2012/01/11 21:57:47 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{4E11DC42-0AEB-43CF-93A3-7A3311F0D0F0}

[2012/01/11 21:57:19 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{A3A38472-2A7E-4FF6-96D3-C4B111E7B80D}

[2012/01/11 15:57:04 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\AMozilla

[2012/01/11 15:56:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SystemEngines

[2012/01/11 15:56:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Temp

[2012/01/11 15:56:03 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Roaming\AMozilla

[2012/01/11 15:54:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 52%

[2012/01/11 11:19:51 | 001,572,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll

[2012/01/11 11:19:51 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll

[2012/01/11 11:19:50 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll

[2012/01/11 11:19:50 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll

[2012/01/11 11:19:49 | 001,731,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll

[2012/01/11 11:19:49 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll

[2012/01/11 11:19:49 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll

[2012/01/11 08:05:45 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{30C48E52-867B-4C80-9BFD-9C3668C8EB24}

[2012/01/11 08:05:31 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{AAF2BCA6-027E-4775-A4B6-2FBF34D47F05}

[2012/01/10 19:47:05 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{296723C4-8738-4099-9F1D-5D2D1B46B7BF}

[2012/01/10 19:46:43 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{271408B1-D85C-4121-8706-D59606FAEC1B}

[2012/01/10 07:46:09 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{B5307176-4CAF-40C8-90FC-048A73CE86FE}

[2012/01/10 07:45:58 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{173C0DDD-7046-40A1-8FAF-3C501704899E}

[2012/01/09 11:06:02 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Roaming\DVDVideoSoft

[2012/01/09 11:05:57 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Roaming\DVDVideoSoftIEHelpers

[2012/01/09 11:05:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft

[2012/01/09 11:05:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DVDVideoSoft

[2012/01/09 11:05:43 | 000,000,000 | ---D | C] -- C:\Users\My\Documents\DVDVideoSoft

[2012/01/09 11:05:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDVideoSoft

[2012/01/09 08:31:53 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{C3000DA1-77BE-4FAF-9134-F17EEF350E00}

[2012/01/09 08:31:26 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{944C6514-BA96-4BA8-917B-CF90D81766D5}

[2012/01/08 12:42:54 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{CDEF99AE-08B4-4D53-AC10-A547CFEC39A1}

[2012/01/08 12:42:21 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{CB701CD9-3485-4447-8EE4-F4EC5DCA3EF8}

[2012/01/08 07:52:33 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{F50D3BEF-AE5E-4049-A134-4876B0BB919A}

[2012/01/07 09:10:36 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{13F8D4D3-F44A-4209-AC84-87369C417E73}

[2012/01/07 09:10:20 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{F333AAF8-E093-4B35-AEB7-9D62285CF1C7}

[2012/01/06 14:17:10 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{1A4235BD-7D0B-4A03-8CCE-31F1FEFEDCAB}

[2012/01/06 14:16:55 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{8B442EFB-6202-4D3C-9357-6DA667A102C7}

[2012/01/06 00:11:20 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{6A84EA27-8968-492A-A964-0FE6B33AA734}

[2012/01/06 00:11:06 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{B03E218E-A70A-4E89-8B73-D407BC486A66}

[2012/01/05 10:10:21 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{C2EEA1FF-BA9F-46FE-BF4C-A8B0FDE6EF1C}

[2012/01/05 10:09:58 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{0311DA21-8C2E-44A6-AD63-CA410C3369CC}

[2012/01/04 22:09:32 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{BCB59AF4-FC0D-4474-A552-E30B93E8017D}

[2012/01/04 08:49:58 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{30526FFE-A58E-49A3-8DDB-177167F4823B}

[2012/01/04 08:49:27 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{CECDFAED-AB6C-424E-A91C-7E1483426D2E}

[2012/01/03 19:29:39 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{1451A753-9201-410F-B515-01C9568A5040}

[2012/01/03 19:29:26 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{C5D9482D-00DF-43AD-95FA-C5FBE71331E2}

[2012/01/02 23:12:48 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{9DC2E8CC-5BA7-4A86-80AB-4407B79237BF}

[2012/01/02 23:12:21 | 000,000,000 | ---D | C] -- C:\Users\My\AppData\Local\{9A9F6DD4-1C92-4169-9D05-D52DBEF38CE4}

[1 C:\Users\My\Desktop\*.tmp files -> C:\Users\My\Desktop\*.tmp -> ]

 

========== Files - Modified Within 14 Days ==========

 

[2012/01/16 16:06:02 | 000,000,177 | -H-- | M] () -- C:\dvmexp.idx

[2012/01/16 16:00:05 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001UA.job

[2012/01/16 16:00:02 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001Core.job

[2012/01/16 14:37:49 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\My\Desktop\OTL.exe

[2012/01/16 14:37:29 | 000,226,816 | ---- | M] () -- C:\Users\My\Desktop\ToolbarShooter.exe

[2012/01/16 14:37:03 | 000,001,069 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2012/01/16 08:35:08 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2012/01/16 08:35:08 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2012/01/16 08:25:53 | 000,196,608 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl

[2012/01/16 08:25:48 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2012/01/16 08:25:46 | 3063,025,664 | -HS- | M] () -- C:\hiberfil.sys

[2012/01/15 23:55:34 | 000,088,872 | ---- | M] () -- C:\Users\My\Desktop\2.jpg

[2012/01/13 15:31:12 | 000,000,320 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForMy.job

[2012/01/13 15:29:43 | 000,000,935 | ---- | M] () -- C:\Users\My\Documents\ax_files.xml

[2012/01/10 11:06:06 | 001,517,030 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2012/01/10 11:06:06 | 000,663,804 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat

[2012/01/10 11:06:06 | 000,616,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2012/01/10 11:06:06 | 000,128,094 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat

[2012/01/10 11:06:06 | 000,106,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2012/01/08 16:56:20 | 000,002,741 | ---- | M] () -- C:\Users\My\Documents\careca.nrd

[2012/01/05 22:02:18 | 000,095,597 | ---- | M] () -- C:\Users\My\Desktop\inss rosane.pdf

[2012/01/03 11:28:52 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf

[2012/01/03 08:42:18 | 000,001,932 | ---- | M] () -- C:\Users\My\Desktop\comprovante.pdf

[1 C:\Users\My\Desktop\*.tmp files -> C:\Users\My\Desktop\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2012/01/16 14:37:23 | 000,226,816 | ---- | C] () -- C:\Users\My\Desktop\ToolbarShooter.exe

[2012/01/16 14:37:03 | 000,001,069 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2012/01/15 23:55:34 | 000,088,872 | ---- | C] () -- C:\Users\My\Desktop\2.jpg

[2012/01/14 15:55:52 | 000,000,916 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001UA.job

[2012/01/14 15:55:52 | 000,000,894 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001Core.job

[2012/01/13 15:29:43 | 000,000,935 | ---- | C] () -- C:\Users\My\Documents\ax_files.xml

[2012/01/08 16:56:20 | 000,002,741 | ---- | C] () -- C:\Users\My\Documents\careca.nrd

[2012/01/05 22:02:34 | 000,095,597 | ---- | C] () -- C:\Users\My\Desktop\inss rosane.pdf

[2012/01/03 11:28:52 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf

[2012/01/03 08:42:18 | 000,001,932 | ---- | C] () -- C:\Users\My\Desktop\comprovante.pdf

[2011/11/23 10:27:10 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll

[2011/11/23 10:27:10 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll

[2011/11/23 10:27:09 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll

[2011/11/02 21:13:37 | 000,003,584 | ---- | C] () -- C:\Users\My\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011/11/02 13:11:42 | 000,014,848 | ---- | C] () -- C:\Windows\SysWow64\BASSMOD.dll

[2011/11/02 12:56:50 | 000,000,000 | ---- | C] () -- C:\Users\My\AppData\Roaming\.NANotifyHere

[2011/10/28 00:30:57 | 001,053,056 | ---- | C] () -- C:\Windows\SysWow64\drivers\V2WCDRV.sys

[2011/10/01 12:29:04 | 000,419,492 | ---- | C] () -- C:\Users\My\AppData\Local\tmp230920111009.3

[2011/10/01 12:29:03 | 000,420,137 | ---- | C] () -- C:\Users\My\AppData\Local\tmp230920111009.2

[2011/10/01 12:29:02 | 000,423,514 | ---- | C] () -- C:\Users\My\AppData\Local\tmp230920111009.1

[2011/10/01 12:29:01 | 000,606,631 | ---- | C] () -- C:\Users\My\AppData\Local\tmp230920111009.JPG

[2011/10/01 12:29:01 | 000,606,631 | ---- | C] () -- C:\Users\My\AppData\Local\tmp230920111009.0

[2011/09/26 19:36:04 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll

[2011/09/22 15:09:42 | 000,000,283 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog2.ini

[2011/09/22 15:09:42 | 000,000,224 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog.ini

[2011/04/09 19:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat

[2010/06/30 00:12:16 | 000,013,312 | ---- | C] () -- C:\Windows\LPRES.DLL

[2009/10/30 17:21:18 | 000,870,544 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin

[2009/10/30 17:21:18 | 000,127,896 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin

[2009/10/30 17:21:18 | 000,050,028 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin

[2009/10/30 16:06:24 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll

[2009/10/30 16:06:24 | 000,147,456 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll

[2009/09/27 14:49:50 | 000,362,029 | ---- | C] () -- C:\Windows\SysWow64\sqlite3.dll

[2009/07/14 03:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat

[2009/07/14 00:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT

[2009/07/14 00:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat

[2009/07/13 22:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin

[2009/07/13 21:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll

[2009/07/13 19:59:36 | 001,498,564 | ---- | C] () -- C:\Windows\SysWow64\igkrng400.bin

[2009/07/13 19:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

[2009/06/19 21:06:22 | 000,197,912 | ---- | C] () -- C:\Windows\SysWow64\physxcudart_20.dll

[2009/06/19 21:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll

[2009/06/19 21:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll

[2009/06/19 21:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll

[2009/06/19 21:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll

[2009/06/19 21:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll

[2009/06/19 21:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll

[2009/06/19 21:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll

[2009/06/19 21:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll

[2009/06/19 21:06:22 | 000,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll

[2009/06/10 19:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

 

========== LOP Check ==========

 

[2012/01/11 15:56:03 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\AMozilla

[2011/09/22 16:31:22 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\DigitalPersona

[2012/01/09 11:06:06 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\DVDVideoSoft

[2012/01/09 11:05:57 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\DVDVideoSoftIEHelpers

[2012/01/02 00:10:51 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\GetRightToGo

[2011/12/25 23:19:00 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\ManyCam

[2011/10/06 00:19:40 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\Unity

[2011/11/03 22:22:00 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\uTorrent

[2011/10/28 00:31:00 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\Video2Webcam

[2011/12/05 09:06:19 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\VIVO INTERNET

[2011/11/22 18:48:56 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\Vso

[2011/11/13 13:31:40 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\WinAVI

[2011/11/15 10:31:19 | 000,000,000 | ---D | M] -- C:\Users\My\AppData\Roaming\Windows Live Writer

[2012/01/16 16:00:02 | 000,000,894 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001Core.job

[2012/01/16 16:00:05 | 000,000,916 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001UA.job

[2011/12/23 22:13:22 | 000,032,608 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

 

========== Purity Check ==========

 

 

 

========== Custom Scans ==========

 

 

< %SYSTEMDRIVE%\*.* >

[2009/07/13 23:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr

[2012/01/16 16:06:02 | 000,000,177 | -H-- | M] () -- C:\dvmexp.idx

[2012/01/16 08:25:46 | 3063,025,664 | -HS- | M] () -- C:\hiberfil.sys

[2012/01/03 11:29:31 | 000,000,186 | ---- | M] () -- C:\hpqlb.log

[2012/01/16 08:25:46 | 4084,035,584 | -HS- | M] () -- C:\pagefile.sys

[2011/09/22 16:26:30 | 000,000,064 | -H-- | M] () -- C:\splash.idx

[2012/01/16 16:16:12 | 000,003,130 | ---- | M] () -- C:\ToolbarShooterSUP.txt

[2009/11/11 19:22:28 | 000,006,832 | -H-- | M] () -- C:\version

 

< %systemdrive%\drivers\*.* /s >

 

< %systemdrive%\drivers\*.exe >

 

< %systemroot%\system32\drivers\*.* /30 >

 

< %PROGRAMFILES%\*.* >

[2009/07/14 02:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

 

< %userprofile%\configurações locais\dados de aplicativos\*.exe >

 

< %userprofile%\configurações locais\dados de aplicativos\*.txt >

 

< %userprofile%\configurações locais\dados de aplicativos\*.ini >

 

< %userprofile%\configurações locais\dados de aplicativos\*.dat /30 >

 

< %userprofile%\configurações locais\dados de aplicativos\*.dll >

 

 

< MD5 for: EXPLORER.EXE >

[2009/12/23 20:33:18 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe

[2011/02/26 04:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe

[2011/02/26 03:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe

[2009/07/13 23:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe

[2011/02/26 03:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe

[2009/10/31 03:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe

[2011/02/26 03:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe

[2011/02/25 04:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe

[2011/02/25 04:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe

[2011/02/26 04:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe

[2010/11/20 10:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe

[2009/12/23 20:33:18 | 002,868,736 | ---- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe

[2009/08/03 04:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe

[2011/02/25 03:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe

[2011/02/25 03:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe

[2009/10/31 04:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe

[2009/08/03 03:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe

[2010/11/20 11:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

[2009/10/31 04:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe

[2009/08/03 03:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe

[2009/07/13 23:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe

[2009/10/31 04:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe

[2009/12/23 20:33:18 | 002,868,736 | ---- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe

[2011/02/26 04:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe

[2009/08/03 04:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

[2009/12/23 20:33:18 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe

 

< %userprofile%\*.exe >

 

< %userprofile%\.txt >

 

< %userprofile%\.ini >

 

< %userprofile%\.dat /30 >

 

< %userprofile%\.dll >

 

< %systemroot%\system32\Tasks\*.* /30 >

 

< %windir%\tasks\*.* /s >

[2012/01/16 16:00:02 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001Core.job

[2012/01/16 16:00:05 | 000,000,916 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001UA.job

[2012/01/13 15:31:12 | 000,000,320 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForMy.job

[2012/01/16 08:25:52 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT

[2011/12/23 22:13:22 | 000,032,608 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT

 

< %systemroot%\*.scr >

[2011/05/13 15:42:24 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR

 

< HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main >

"Disable Script Debugger" = yes

"Default_Page_URL" = http://g.msn.com/HPCON/3

"Anchor Underline" = yes

"Cache_Update_Frequency" = Once_Per_Session

"Display Inline Images" = yes

"Do404Search" = 01 00 00 00 [binary data]

"Local Page" = C:\Windows\system32\blank.htm

"Save_Session_History_On_Exit" = no

"Show_FullURL" = no

"Show_StatusBar" = yes

"Show_ToolBar" = yes

"Show_URLinStatusBar" = yes

"Show_URLToolBar" = yes

"Use_DlgBox_Colors" = yes

"Search Page" = http://go.microsoft.com/fwlink/?LinkId=54896

"XMLHTTP" = 1

"NoUpdateCheck" = 1

"UseClearType" = no

"Play_Background_Sounds" = yes

"Play_Animations" = yes

"CompatibilityFlags" = 0

"IE8TourNoShow" = 1

"FullScreen" = no

"Window_Placement" = 2C 00 00 00 02 00 00 00 03 00 00 00 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF CA 00 00 00 B0 00 00 00 EA 03 00 00 F8 02 00 00 [binary data]

"IE8RunOnceLastShown" = 1

"IE8RunOnceLastShown_TIMESTAMP" = A8 5C D0 E0 F5 9F CC 01 [binary data]

"NotifyDownloadComplete" = no

"AlwaysShowMenus" = 0

"Use FormSuggest" = no

"FormSuggest PW Ask" = no

"Start Page Restore" = http://www.google.com.br/

"Check_Associations" = no

"Use Search Asst" = no

"IE8RunOncePerInstallCompleted" = 1

"IE8RunOnceCompletionTime" = D9 C0 D1 EB F5 9F CC 01 [binary data]

"DisableScriptDebuggerIE" = yes

"Enable Browser Extensions" = yes

"IE9RunOncePerInstallCompleted" = 1

"IE9RunOnceCompletionTime" = B5 07 78 2F F1 A9 CC 01 [binary data]

"IE9TourShown" = 1

"IE9TourShownTime" = 56 8E 79 2F F1 A9 CC 01 [binary data]

"IconCache" = zu22lmn

"DownloadWindowPlacement" = 2C 00 00 00 00 00 00 00 00 00 00 00 00 83 FF FF 00 83 FF FF FF FF FF FF FF FF FF FF 10 01 00 00 65 00 00 00 90 03 00 00 45 02 00 00 [binary data]

"Start Page" = http://google.fr

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default Feeds]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch]

 

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DateTime\Servers >

"" = 1

"1" = time.windows.com

"2" = time.nist.gov

"3" = time-nw.nist.gov

"4" = time-a.nist.gov

"5" = time-b.nist.gov

 

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections >

"DefaultConnectionSettings" = [binary data over 100 bytes]

"SavedLegacySettings" = [binary data over 100 bytes]

 

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings >

"IE5_UA_Backup_Flag" = 5.0

"User Agent" = Mozilla/4.0 (compatible; MSIE 8.0; Win32)

"EmailName" = User@

"PrivDiscUiShown" = 1

"EnableHttp1_1" = 1

"WarnOnIntranet" = 1

"MimeExclusionListForCache" = multipart/mixed multipart/x-mixed-replace multipart/x-byteranges

"AutoConfigProxy" = wininet.dll -- [2011/11/03 20:39:47 | 001,127,424 | ---- | M] (Microsoft Corporation)

"UseSchannelDirectly" = 01 00 00 00 [binary data]

"EnableNegotiate" = 1

"MigrateProxy" = 1

"ProxyEnable" = 0

"WarnOnPost" = 01 00 00 00 [binary data]

"UrlEncoding" = 0

"SecureProtocols" = 160

"PrivacyAdvanced" = 0

"ZonesSecurityUpgrade" = 83 25 AE C2 E0 A9 CC 01 [binary data]

"DisableCachingOfSSLPages" = 0

"WarnonZoneCrossing" = 0

"CertificateRevocation" = 1

"GlobalUserOffline" = 0

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CACHE]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones]

 

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System >

 

< HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer >

 

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders >

"Common Desktop" = %PUBLIC%\Desktop -- [2012/01/16 14:37:03 | 000,000,000 | RH-D | M]

"Common Documents" = %PUBLIC%\Documents -- [2011/09/22 16:26:00 | 000,000,000 | R--D | M]

"CommonPictures" = %PUBLIC%\Pictures -- [2009/07/14 02:54:24 | 000,000,000 | R--D | M]

"CommonMusic" = %PUBLIC%\Music -- [2009/07/14 02:54:24 | 000,000,000 | R--D | M]

"CommonVideo" = %PUBLIC%\Videos -- [2009/07/14 02:54:24 | 000,000,000 | R--D | M]

"{3D644C9B-1FB8-4f30-9B45-F670235F79C0}" = %PUBLIC%\Downloads -- [2009/07/14 02:54:24 | 000,000,000 | R--D | M]

"Common Start Menu" = %ProgramData%\Microsoft\Windows\Start Menu -- [2011/11/03 22:22:00 | 000,000,000 | R--D | M]

"Common Programs" = %ProgramData%\Microsoft\Windows\Start Menu\Programs -- [2012/01/16 14:37:03 | 000,000,000 | R--D | M]

"Common Startup" = %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup -- [2011/10/11 23:45:24 | 000,000,000 | R--D | M]

"Common AppData" = %ProgramData% -- [2012/01/16 14:37:02 | 000,000,000 | -H-D | M]

"Common Templates" = %ProgramData%\Microsoft\Windows\Templates -- [2009/07/14 00:34:59 | 000,000,000 | ---D | M]

 

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List >

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 304 bytes -> C:\Windows\SysWow64\drivers:GbpKmAp.lst

 

< End of report >

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! RafaeL lcassati2

 

|- Baixe: < RogueKiller > ( ... par tigzy )

|- Salve-o no desktop!

|- Feche aplicativos que estejam abertos!

 

RogueKiller_614.jpg

 

|- Execute a ferramenta,escolhendo a opção ( 1 ) Recherche ou Scan <- Confirme!

|- Ps: Para Windows Vista ou 7,execute-o como administrador.

|- Poste o relatório: RKreport[1].txt

 

/////°°°°°/////

 

|- Execute o OTL.exe.

|- Copie estas informações que estão em vermelho,para o campo clipboard da ferramenta. ( "Exames Personalizados Correções" )

 

:OTL

O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E0301295-AB3E-4AF3-979F-3D453C5F9F48} - No CLSID value found.

O4 - HKLM..\Run: [] File not found

O13:64bit: - gopher Prefix: missing

O13 - gopher Prefix: missing

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)

O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)

O18:64bit: - Protocol\Handler\livecall - No CLSID value found

O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found

O18:64bit: - Protocol\Handler\msnim - No CLSID value found

O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found

O18:64bit: - Protocol\Handler\wlpg - No CLSID value found

O18 - Protocol\Handler\ms-help - No CLSID value found

O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O33 - MountPoints2\{f428c4a4-1302-11e1-a113-0027139bf0ab}\Shell - "" = AutoRun

O33 - MountPoints2\{f428c4a4-1302-11e1-a113-0027139bf0ab}\Shell\AutoRun\command - "" = I:\AutoRun.exe

O33 - MountPoints2\{f428c4b3-1302-11e1-a113-0027139bf0ab}\Shell - "" = AutoRun

O33 - MountPoints2\{f428c4b3-1302-11e1-a113-0027139bf0ab}\Shell\AutoRun\command - "" = J:\AutoRun.exe

[1 C:\Users\My\Desktop\*.tmp files -> C:\Users\My\Desktop\*.tmp -> ]

 

:Files

C:\Users\My\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001Core.job

C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001UA.job

 

:reg

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes]

"Gopher"="gopher://"

 

:Commands

[emptyflash]

[emptytemp]

[reboot]

|- Clique no botão Consertar.

|- Ps: A ferramenta irá reiniciar o computador.

|- Ao surgir,clique em executar.

|- Poste o relatório: C:\_OTL\MovedFiles\*.log

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia, DigRam.

mais uma vez obrigado pelo suporte.

 

 

RogueKiller V6.2.4 [01/12/2012] by Tigzy

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/

Blog: http://tigzyrk.blogspot.com

 

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Started in : Normal mode

User: My [Admin rights]

Mode: Scan -- Date : 01/17/2012 09:12:13

 

¤¤¤ Bad processes: 0 ¤¤¤

 

¤¤¤ Registry Entries: 2 ¤¤¤

[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND

[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

 

¤¤¤ Particular Files / Folders: ¤¤¤

 

¤¤¤ Driver: [NOT LOADED] ¤¤¤

 

¤¤¤ Infection : ¤¤¤

 

¤¤¤ HOSTS File: ¤¤¤

 

 

¤¤¤ MBR Check: ¤¤¤

 

+++++ PhysicalDrive0: +++++

--- User ---

[MBR] a7299bc90d59f63d2a7953972b5cb9e2

[bSP] 72af755d83eed470540442895deb84b0 : Windows Vista/7 MBR Code

Partition table:

0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 2048 | Size: 208 Mo

1 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 409600 | Size: 481247 Mo

2 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 940345344 | Size: 18541 Mo

3 - [XXXXXX] FAT32 [VISIBLE] Offset (sectors): 976560128 | Size: 108 Mo

User = LL1 ... OK!

User = LL2 ... OK!

 

+++++ PhysicalDrive1: +++++

--- User ---

[MBR] de9cdbebc5f643f9445f4153909e8439

[bSP] df4f83c1f72e36823a12b0dfc7617313 : MBR Code unknown

Partition table:

0 - [XXXXXX] FAT16 [VISIBLE] Offset (sectors): 233 | Size: 512 Mo

User = LL1 ... OK!

Error reading LL2 MBR!

 

Finished : << RKreport[1].txt >>

RKreport[1].txt

 

 

 

 

 

All processes killed

========== OTL ==========

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.

Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E0301295-AB3E-4AF3-979F-3D453C5F9F48} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0301295-AB3E-4AF3-979F-3D453C5F9F48}\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!

Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.

Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.

Starting removal of ActiveX control {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ deleted successfully.

Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ not found.

Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.

Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.

Starting removal of ActiveX control {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully.

Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ not found.

Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.

64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.

File Protocol\Handler\livecall - No CLSID value found not found.

64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-itss\ deleted successfully.

File Protocol\Handler\ms-itss - No CLSID value found not found.

64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.

File Protocol\Handler\msnim - No CLSID value found not found.

64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.

File Protocol\Handler\wlmailhtml - No CLSID value found not found.

64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.

File Protocol\Handler\wlpg - No CLSID value found not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.

File Protocol\Handler\ms-help - No CLSID value found not found.

64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.

64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.

64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.

Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f428c4a4-1302-11e1-a113-0027139bf0ab}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f428c4a4-1302-11e1-a113-0027139bf0ab}\ not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f428c4a4-1302-11e1-a113-0027139bf0ab}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f428c4a4-1302-11e1-a113-0027139bf0ab}\ not found.

File I:\AutoRun.exe not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f428c4b3-1302-11e1-a113-0027139bf0ab}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f428c4b3-1302-11e1-a113-0027139bf0ab}\ not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f428c4b3-1302-11e1-a113-0027139bf0ab}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f428c4b3-1302-11e1-a113-0027139bf0ab}\ not found.

File J:\AutoRun.exe not found.

C:\Users\My\Desktop\~WRL1272.tmp deleted successfully.

========== FILES ==========

C:\Users\My\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.

C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001Core.job moved successfully.

C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1825749246-3439649273-815915689-1001UA.job moved successfully.

========== REGISTRY ==========

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\"Gopher"|"gopher://" /E : value set successfully!

========== COMMANDS ==========

 

[EMPTYFLASH]

 

User: All Users

 

User: Default

->Flash cache emptied: 41620 bytes

 

User: Default User

->Flash cache emptied: 0 bytes

 

User: My

->Flash cache emptied: 8325143 bytes

 

User: Public

 

User: Todos os Usuários

 

User: Usuário Padrão

->Flash cache emptied: 0 bytes

 

Total Flash Files Cleaned = 8,00 mb

 

 

[EMPTYTEMP]

 

User: All Users

 

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

->Flash cache emptied: 0 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

 

User: My

->Temp folder emptied: 11995239 bytes

->Temporary Internet Files folder emptied: 18501260 bytes

->Java cache emptied: 971573 bytes

->FireFox cache emptied: 1082815157 bytes

->Flash cache emptied: 0 bytes

 

User: Public

 

User: Todos os Usuários

 

User: Usuário Padrão

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 24442 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67872 bytes

RecycleBin emptied: 22219423391 bytes

 

Total Files Cleaned = 22.253,00 mb

 

 

OTL by OldTimer - Version 3.2.31.0 log created on 01172012_091446

 

Files\Folders moved on Reboot...

C:\Users\My\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

File\Folder C:\Users\My\AppData\Local\Mozilla\Firefox\Profiles\1q6lsz8d.default\Cache\0\20\D11C8m01 not found!

File\Folder C:\Users\My\AppData\Local\Mozilla\Firefox\Profiles\1q6lsz8d.default\Cache\0\20\D98F2d01 not found!

C:\Users\My\AppData\Local\Mozilla\Firefox\Profiles\1q6lsz8d.default\urlclassifier3.sqlite moved successfully.

 

Registry entries deleted on Reboot...

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! RafaeL lcassati2

 

|- Acesse: 5ddd15a0a515ee4d2c0ec8b4dcd87f0892b31334364ee054c605f091c3a9d7ad6g.jpg

 

83e4aac23f4afef13a3ebabeac5a83a9c3d09bc26d01ffd8e9659b806fce2f476g.jpg

 

|- Em "Arquivo para verificar",coloque:

 

|- <!> C:\Program Files (x86)\Online Services\UOL\discador.exe

 

|- Clique em "Enviar".

|- Ps: Copie e poste,o resultado deste exame.

 

/////°°°°°/////

 

|- Desinstale o Malwarebytes.

|- Dê um duplo-clique no arquivo em destaque:

 

|- C:\Arquivos de programas\Malwarebytes' Anti-Malware\unins000.exe <--

 

|- Reinicie o computador,após a conclusão!

 

/////°°°°°/////

 

|- Abra,novamente,a ferramenta RogueKiller e lance a opção 2. Delete.

|- Poste o relatório: RKreport[2].txt

 

/////°°°°°/////

 

|- Baixe: < adwcleaner0.zip >

 

Badongo_Download.jpg

 

|- Estando na página,clique em "Faça o download do seu fich..."

 

Badongo_Esperesff.jpg

 

|- Aguarde até que zere a contagem Sfff...,que fica ao da página.

 

Badongo_Faa_o_download.jpg

 

|- Clique em "Faça o download do seu ficheiro aqui".

|- Aguarde,até que apareça a janela: "Opening adwcleaner0.zip"

|- Marque: Save file --> OK.

 

|- Descompacte-a para o desktop!

 

|- Dê início ao scan,clicando em "Suppression" < AdwCleaner_Suppression.jpg >

 

|- Ao concluir,poste o relatório: C:\AdwCleaner[S].txt

|- Ps: Informe a situação em que encontra-se o PC.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite DigRam!

 

Antivírus

[ArcaVir]

2012-01-18 Nada encontrado

[Frisk F-Prot Antivirus]

2012-01-18 Nada encontrado

[Avast! antivirus]

2012-01-18 Nada encontrado

[F-Secure Anti-Virus]

2012-01-18 Nada encontrado

[Grisoft AVG Anti-Virus]

2012-01-18 Nada encontrado

[G DATA]

2012-01-18 Nada encontrado

[Avira AntiVir]

2012-01-18 Nada encontrado

[ikarus]

2012-01-18 Nada encontrado

[softwin BitDefender]

2012-01-18 Nada encontrado

[Kaspersky Anti-Virus]

2012-01-18 Nada encontrado

[ClamAV]

2012-01-18 Nada encontrado

[Panda Antivirus]

2012-01-18 Nada encontrado

[CPsecure]

2012-01-18 Nada encontrado

[Quick Heal]

2012-01-18 Nada encontrado

[Dr.Web]

2012-01-18 Nada encontrado

[sophos]

2012-01-18 Nada encontrado

[Emsisoft Anti-Malware]

2012-01-18 Nada encontrado

[VirusBlokAda VBA32]

2012-01-18 Nada encontrado

[ESET]

2012-01-18 Nada encontrado

[VirusBuster]

2012-01-18 Nada encontrado

 

 

RogueKiller V6.2.4 [01/12/2012] by Tigzy

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/

Blog: http://tigzyrk.blogspot.com

 

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Started in : Normal mode

User: My [Admin rights]

Mode: Remove -- Date : 01/19/2012 22:15:44

 

¤¤¤ Bad processes: 0 ¤¤¤

 

¤¤¤ Registry Entries: 2 ¤¤¤

[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)

[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

 

¤¤¤ Particular Files / Folders: ¤¤¤

 

¤¤¤ Driver: [NOT LOADED] ¤¤¤

 

¤¤¤ Infection : ¤¤¤

 

¤¤¤ HOSTS File: ¤¤¤

 

 

¤¤¤ MBR Check: ¤¤¤

 

+++++ PhysicalDrive0: +++++

--- User ---

[MBR] a7299bc90d59f63d2a7953972b5cb9e2

[bSP] 72af755d83eed470540442895deb84b0 : Windows Vista/7 MBR Code

Partition table:

0 - [ACTIVE] NTFS [VISIBLE] Offset (sectors): 2048 | Size: 208 Mo

1 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 409600 | Size: 481247 Mo

2 - [XXXXXX] NTFS [VISIBLE] Offset (sectors): 940345344 | Size: 18541 Mo

3 - [XXXXXX] FAT32 [VISIBLE] Offset (sectors): 976560128 | Size: 108 Mo

User = LL1 ... OK!

User = LL2 ... OK!

 

+++++ PhysicalDrive1: +++++

--- User ---

[MBR] de9cdbebc5f643f9445f4153909e8439

[bSP] df4f83c1f72e36823a12b0dfc7617313 : MBR Code unknown

Partition table:

0 - [XXXXXX] FAT16 [VISIBLE] Offset (sectors): 233 | Size: 512 Mo

User = LL1 ... OK!

Error reading LL2 MBR!

 

Finished : << RKreport[2].txt >>

RKreport[1].txt ; RKreport[2].txt

 

 

 

# AdwCleaner v1.309 - Rapport créé le 19/01/2012 à 22:19:13

# Mis à jour le 29/09/11 à 20h par Xplode

# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)

# Nom d'utilisateur : My - MY-PC (Administrateur)

# Exécuté depuis : C:\Users\My\Desktop\adwcleaner0.exe

# Option [suppression]

 

 

***** [KillNav] *****

 

# firefox.exe [PID:6992] -> Tué

 

***** [Processus] *****

 

Tué : [PID:3300] Updater.exe

 

***** [services] *****

 

 

***** [Fichiers / Dossiers] *****

 

Dossier Supprimé : C:\Program Files (x86)\Ask.com

Dossier Supprimé : C:\Users\My\AppData\Roaming\Mozilla\Firefox\Profiles\1q6lsz8d.default\ConduitCommon

Fichier Supprimé : C:\Users\My\AppData\Roaming\Mozilla\Firefox\Profiles\1q6lsz8d.default\searchplugins\askcom.xml

Fichier Supprimé : C:\Users\My\AppData\Roaming\Mozilla\Firefox\Profiles\1q6lsz8d.default\searchplugins\conduit.xml

 

***** [Registre] *****

 

Clé Supprimée : HKCU\Software\APN

Clé Supprimée : HKCU\Software\Zugo

Clé Supprimée : HKCU\Software\AppDataLow\Software\AskToolbar

Clé Supprimée : HKCU\Software\AppDataLow\Software\PriceGong

Clé Supprimée : HKLM\SOFTWARE\AskToolbar

Clé Supprimée : HKLM\SOFTWARE\APN

Clé Supprimée : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd

Clé Supprimée : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1

Clé Supprimée : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL

Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}

Clé Supprimée : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF

Clé Supprimée : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF

Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}

Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

Valeur Supprimée : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{00000000-6E41-4FD3-8538-502F5495E5FC}]

Valeur Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]

 

***** [Registre (64 bits)] *****

 

[x64] Clé Supprimée : HKLM64\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}

[x64] Clé Supprimée : HKLM64\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}

[x64] Clé Supprimée : HKLM64\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}

[x64] Clé Supprimée : HKLM64\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

 

***** [Navigateurs] *****

 

-\\ Internet Explorer v9.0.8112.16421

 

[OK] Le registre ne contient aucune entrée illégitime.

 

-\\ Mozilla Firefox v9.0.1 (pt-BR)

 

Profil : 1q6lsz8d.default

Fichier : C:\Users\My\AppData\Roaming\Mozilla\Firefox\Profiles\1q6lsz8d.default\prefs.js

 

Supprimée : user_pref("CT2851643..clientLogIsEnabled", false);

Supprimée : user_pref("CT2851643..clientLogServiceUrl", "http://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");

Supprimée : user_pref("CT2851643..uninstallLogServiceUrl", "http://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");

Supprimée : user_pref("CT2851643.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);

Supprimée : user_pref("CT2851643.AboutPrivacyUrl", "http://www.conduit.com/privacy/Default.aspx");

Supprimée : user_pref("CT2851643.CTID", "CT2851643");

Supprimée : user_pref("CT2851643.CurrentServerDate", "26-12-2011");

Supprimée : user_pref("CT2851643.DSInstall", true);

Supprimée : user_pref("CT2851643.DialogsAlignMode", "LTR");

Supprimée : user_pref("CT2851643.DialogsGetterLastCheckTime", "Sun Dec 25 2011 22:25:58 GMT-0200");

Supprimée : user_pref("CT2851643.DownloadReferralCookieData", "");

Supprimée : user_pref("CT2851643.EMailNotifierPollDate", "Sun Dec 25 2011 22:25:55 GMT-0200");

Supprimée : user_pref("CT2851643.FeedLastCount1733423638652034402", 324);

Supprimée : user_pref("CT2851643.FeedPollDate2429156812186649977", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedPollDate2429156813040823546", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedPollDate2429156813130095866", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedPollDate2429156813224203613", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedPollDate2429156813230837251", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedPollDate2429156813454291735", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedPollDate2429156813729834876", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedPollDate2429156813860870021", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedPollDate2429156814264681793", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedPollDate2429156814863075366", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedPollDate2429156815257761081", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.FeedTTL2429156813040823546", 15);

Supprimée : user_pref("CT2851643.FeedTTL2429156813130095866", 10);

Supprimée : user_pref("CT2851643.FeedTTL2429156813454291735", 5);

Supprimée : user_pref("CT2851643.FeedTTL2429156814264681793", 5);

Supprimée : user_pref("CT2851643.FirstServerDate", "14-10-2011");

Supprimée : user_pref("CT2851643.FirstTime", true);

Supprimée : user_pref("CT2851643.FirstTimeFF3", true);

Supprimée : user_pref("CT2851643.FixPageNotFoundErrors", false);

Supprimée : user_pref("CT2851643.GroupingServerCheckInterval", 1440);

Supprimée : user_pref("CT2851643.GroupingServiceUrl", "http://grouping.services.conduit.com/");

Supprimée : user_pref("CT2851643.HPInstall", false);

Supprimée : user_pref("CT2851643.HasUserGlobalKeys", true);

Supprimée : user_pref("CT2851643.HomePageProtectorEnabled", false);

Supprimée : user_pref("CT2851643.HomepageBeforeUnload", "http://search.conduit.com/?ctid=CT2851643&SearchSource=13");

Supprimée : user_pref("CT2851643.Initialize", true);

Supprimée : user_pref("CT2851643.InitializeCommonPrefs", true);

Supprimée : user_pref("CT2851643.InstallationAndCookieDataSentCount", 3);

Supprimée : user_pref("CT2851643.InstallationType", "UnknownIntegration");

Supprimée : user_pref("CT2851643.InstalledDate", "Fri Oct 14 2011 08:54:48 GMT-0300 (Hora oficial do Brasil)");

Supprimée : user_pref("CT2851643.IsAlertDBUpdated", true);

Supprimée : user_pref("CT2851643.IsGrouping", false);

Supprimée : user_pref("CT2851643.IsInitSetupIni", true);

Supprimée : user_pref("CT2851643.IsMulticommunity", false);

Supprimée : user_pref("CT2851643.IsOpenThankYouPage", true);

Supprimée : user_pref("CT2851643.IsOpenUninstallPage", false);

Supprimée : user_pref("CT2851643.IsProtectorsInit", true);

Supprimée : user_pref("CT2851643.LanguagePackLastCheckTime", "Sun Dec 25 2011 22:25:55 GMT-0200");

Supprimée : user_pref("CT2851643.LanguagePackReloadIntervalMM", 1440);

Supprimée : user_pref("CT2851643.LanguagePackServiceUrl", "http://translation.users.conduit.com/Translation.ashx");

Supprimée : user_pref("CT2851643.LastLogin_3.7.0.6", "Thu Nov 03 2011 22:21:28 GMT-0200");

Supprimée : user_pref("CT2851643.LastLogin_3.8.1.0", "Sun Dec 25 2011 22:25:55 GMT-0200");

Supprimée : user_pref("CT2851643.LatestVersion", "3.8.1.0");

Supprimée : user_pref("CT2851643.Locale", "pt");

Supprimée : user_pref("CT2851643.MCDetectTooltipHeight", "83");

Supprimée : user_pref("CT2851643.MCDetectTooltipUrl", "http://@EB_INSTALL_LINK@/rank/tooltip/?version=1");

Supprimée : user_pref("CT2851643.MCDetectTooltipWidth", "295");

Supprimée : user_pref("CT2851643.MyStuffEnabledAtInstallation", true);

Supprimée : user_pref("CT2851643.OriginalFirstVersion", "3.7.0.6");

Supprimée : user_pref("CT2851643.SavedHomepage", "http://www.google.com.br/");

Supprimée : user_pref("CT2851643.SearchCaption", "uTorrentBar_PT Customized Web Search");

Supprimée : user_pref("CT2851643.SearchEngineBeforeUnload", "uTorrentBar_PT Customized Web Search");

Supprimée : user_pref("CT2851643.SearchFromAddressBarIsInit", true);

Supprimée : user_pref("CT2851643.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2851643&q=");

Supprimée : user_pref("CT2851643.SearchInNewTabEnabled", true);

Supprimée : user_pref("CT2851643.SearchInNewTabIntervalMM", 1440);

Supprimée : user_pref("CT2851643.SearchInNewTabLastCheckTime", "Sun Dec 25 2011 22:25:55 GMT-0200");

Supprimée : user_pref("CT2851643.SearchInNewTabServiceUrl", "http://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID");

Supprimée : user_pref("CT2851643.SearchInNewTabUsageUrl", "http://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID");

Supprimée : user_pref("CT2851643.SearchProtectorEnabled", false);

Supprimée : user_pref("CT2851643.SearchProtectorToolbarDisabled", false);

Supprimée : user_pref("CT2851643.SendProtectorDataViaLogin", true);

Supprimée : user_pref("CT2851643.ServiceMapLastCheckTime", "Sun Dec 25 2011 22:25:55 GMT-0200");

Supprimée : user_pref("CT2851643.SettingsLastCheckTime", "Sun Dec 25 2011 22:25:54 GMT-0200");

Supprimée : user_pref("CT2851643.SettingsLastUpdate", "1321973092");

Supprimée : user_pref("CT2851643.TBHomePageUrl", "http://search.conduit.com/?ctid=CT2851643&SearchSource=13");

Supprimée : user_pref("CT2851643.ThirdPartyComponentsInterval", 504);

Supprimée : user_pref("CT2851643.ThirdPartyComponentsLastCheck", "Sun Dec 25 2011 22:25:54 GMT-0200");

Supprimée : user_pref("CT2851643.ThirdPartyComponentsLastUpdate", "1311768090");

Supprimée : user_pref("CT2851643.ToolbarShrinkedFromSetup", false);

Supprimée : user_pref("CT2851643.TrusteLinkUrl", "http://trust.conduit.com/CT2851643");

Supprimée : user_pref("CT2851643.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com,MyBlogToolbar.com,MyCityToolbar.com,MyCollegeToolbar.com,MyFamilyToolbar.com,MyForumToolbar.com,MyLibraryToolbar.com,MyRadioToolbar.com,MyStoreToolbar.com,MyTownToolbar.com,MyUniversityToolbar.com,OurChurchToolbar.com,MyXangaToolbar.com,Media-Toolbar.com,LoyaltyToolbar.com,MyTeamToolbar.com,GreatToolbars.com,OurOrganizationToolbar.com,OurBusinessToolbar.com,Toolbar.fm");

Supprimée : user_pref("CT2851643.Uninstall", true);

Supprimée : user_pref("CT2851643.UserID", "UN91712353108009787");

Supprimée : user_pref("CT2851643.WeatherNetwork", "");

Supprimée : user_pref("CT2851643.WeatherPollDate", "Sun Dec 25 2011 22:25:57 GMT-0200");

Supprimée : user_pref("CT2851643.WeatherUnit", "C");

Supprimée : user_pref("CT2851643.alertChannelId", "1243677");

Supprimée : user_pref("CT2851643.backendstorage.cbfirsttime", "467269204F637420313420323031312030383A35343A353020474D542D303330302028486F7261206F66696369616C20646F2042726173696C29");

Supprimée : user_pref("CT2851643.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F6775692F");

Supprimée : user_pref("CT2851643.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlPattern\":\"http://appdownload.conduit.com/\",\"RevertSettingsEnabled\":\"FALSE\"}");

Supprimée : user_pref("CT2851643.globalFirstTimeInfoLastCheckTime", "Sun Dec 25 2011 22:25:56 GMT-0200");

Supprimée : user_pref("CT2851643.homepageProtectorEnableByLogin", true);

Supprimée : user_pref("CT2851643.initDone", true);

Supprimée : user_pref("CT2851643.isAppTrackingManagerOn", true);

Supprimée : user_pref("CT2851643.myStuffEnabled", true);

Supprimée : user_pref("CT2851643.myStuffPublihserMinWidth", 400);

Supprimée : user_pref("CT2851643.myStuffSearchUrl", "http://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");

Supprimée : user_pref("CT2851643.myStuffServiceIntervalMM", 1440);

Supprimée : user_pref("CT2851643.myStuffServiceUrl", "http://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");

Supprimée : user_pref("CT2851643.oldAppsList", "129351530870587943,129351530870900444,1000234,129351530871056696,1000034,129422837839831266,129351530871369199,1733423638652034402,129351530873244213,129351530873244214,129544680660102367,1000080,1000082,111,1000,1001,1002,1003,1004,1005,1006,1007,1008,1009,1010,1011,1012");

Supprimée : user_pref("CT2851643.revertSettingsEnabled", true);

Supprimée : user_pref("CT2851643.searchProtectorDialogDelayInSec", 10);

Supprimée : user_pref("CT2851643.searchProtectorEnableByLogin", true);

Supprimée : user_pref("CT2851643.testingCtid", "");

Supprimée : user_pref("CT2851643.toolbarAppMetaDataLastCheckTime", "Sun Dec 25 2011 22:25:55 GMT-0200");

Supprimée : user_pref("CT2851643.toolbarContextMenuLastCheckTime", "Sun Dec 25 2011 22:25:55 GMT-0200");

Supprimée : user_pref("CT2851643.usagesFlag", 2);

Supprimée : user_pref("CommunityToolbar.ConduitHomepagesList", "http://search.conduit.com/?ctid=CT2851643&SearchSource=13");

Supprimée : user_pref("CommunityToolbar.ConduitSearchList", "uTorrentBar_PT Customized Web Search");

Supprimée : user_pref("CommunityToolbar.ETag.http://alerts.conduit-services.com/root/1243677/1239350/BR", "\"0\"");

Supprimée : user_pref("CommunityToolbar.ETag.http://appsmetadata.toolbar.conduit-services.com/?ctid=CT2851643", "\"1290675877\"");

Supprimée : user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=pt", "U/3p7eJTzvlTz61sYwNiFQ==");

Supprimée : user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=pt", "CwHar2ZC70gbZ6z0u7oTCQ==");

Supprimée : user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=pt", "ndPO8CvPbpItCXkq/3FQXw==");

Supprimée : user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=pt", "n4yFMLbCy6BwZr5WlAn1LA==");

Supprimée : user_pref("CommunityToolbar.ETag.http://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"07879643d3acc1:1254\"");

Supprimée : user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.0.6", "\"6a637346d78ccc1:0\"");

Supprimée : user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.1.0", "\"6a637346d78ccc1:127c\"");

Supprimée : user_pref("CommunityToolbar.ETag.http://servicemap.conduit-services.com/Toolbar/?ownerId=CT2851643", "\"3e5a4f275840b518b14c5ff3d7391b70\"");

Supprimée : user_pref("CommunityToolbar.ETag.http://settings.toolbar.conduit-services.com/?ctid=CT2851643&octid=CT2851643", "\"1321973093\"");

Supprimée : user_pref("CommunityToolbar.ETag.http://translation.toolbar.conduit-services.com/?locale=pt", "\"ea9b2eebd2fa29a94b04d396762b8f03\"");

Supprimée : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\My\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\1q6lsz8d.default\\conduitCommon\\modules\\3.7.0.6");

Supprimée : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.7.0.6");

Supprimée : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=");

Supprimée : user_pref("CommunityToolbar.ToolbarsList", "CT2851643");

Supprimée : user_pref("CommunityToolbar.ToolbarsList2", "CT2851643");

Supprimée : user_pref("CommunityToolbar.ToolbarsList4", "CT2851643");

Supprimée : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun Dec 25 2011 22:25:55 GMT-0200");

Supprimée : user_pref("CommunityToolbar.globalUserId", "b86d55a7-80f2-4ea7-8116-ba3ab5c668a8");

Supprimée : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);

Supprimée : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);

Supprimée : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2851643");

Supprimée : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Thu Nov 03 2011 22:21:29 GMT-0200");

Supprimée : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);

Supprimée : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Thu Nov 03 2011 22:21:35 GMT-0200");

Supprimée : user_pref("CommunityToolbar.notifications.clientsServerUrl", "http://alert.client.conduit.com");

Supprimée : user_pref("CommunityToolbar.notifications.locale", "en");

Supprimée : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);

Supprimée : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Thu Nov 03 2011 22:21:28 GMT-0200");

Supprimée : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");

Supprimée : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);

Supprimée : user_pref("CommunityToolbar.notifications.servicesServerUrl", "http://alert.services.conduit.com");

Supprimée : user_pref("CommunityToolbar.notifications.showTrayIcon", false);

Supprimée : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);

Supprimée : user_pref("CommunityToolbar.notifications.userId", "6683f10e-396d-4a64-b52a-8ee44a6530b1");

Supprimée : user_pref("CommunityToolbar.originalHomepage", "http://www.google.com.br/");

Supprimée : user_pref("CommunityToolbar.originalSearchEngine", "Google");

Supprimée : user_pref("browser.search.defaulturl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2851643&SearchSource=3&q={searchTerms}");

Supprimée : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\");

Supprimée : user_pref("extensions.asktb.abar-war-timeout", "4000");

Supprimée : user_pref("extensions.asktb.apn_dbr", "ff_7.0.1");

Supprimée : user_pref("extensions.asktb.autofill-competitor-query-enabled", true);

Supprimée : user_pref("extensions.asktb.autofill-text-highlight-enabled", true);

Supprimée : user_pref("extensions.asktb.cbid", "5J");

Supprimée : user_pref("extensions.asktb.config-updated", true);

Supprimée : user_pref("extensions.asktb.crumb", "2011.10.27+19.04.39-toolbar001iad-BR-U2FvIFBhdWxvLEJyYXppbA%3D%3D");

Supprimée : user_pref("extensions.asktb.default-channel-url-mask", "http://br.ask.com/web?q={query}&qsrc={qsrc}&o={o}&l={l}&gct=bar");

Supprimée : user_pref("extensions.asktb.displaybehavior", "");

Supprimée : user_pref("extensions.asktb.displaytext", "");

Supprimée : user_pref("extensions.asktb.dtid", "YYYYYYYYBR");

Supprimée : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false);

Supprimée : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "BRXX0232");

Supprimée : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C");

Supprimée : user_pref("extensions.asktb.ff-original-keyword-url", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2851643&q=");

Supprimée : user_pref("extensions.asktb.fresh-install", false);

Supprimée : user_pref("extensions.asktb.guid", "8307a1cb-9dcb-431e-850c-72a87b4a7e2e");

Supprimée : user_pref("extensions.asktb.hpr", "YES");

Supprimée : user_pref("extensions.asktb.http-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \"WWW.google.com\", \"https://websearch.ask.com\", \"http://wiki.jeeves.ask.info\", \"69.147.125.65\", \"10.0.2.85\", \"sp.ask.com\", \"websearch.ask.com\", \"www.ask.com\", \"ask.com\"]");

Supprimée : user_pref("extensions.asktb.if", "first");

Supprimée : user_pref("extensions.asktb.l", "dis");

Supprimée : user_pref("extensions.asktb.last-config-req", "1324857295953");

Supprimée : user_pref("extensions.asktb.locale", "pt_BR");

Supprimée : user_pref("extensions.asktb.location", "Sao Paulo,Brazil");

Supprimée : user_pref("extensions.asktb.lstation", "");

Supprimée : user_pref("extensions.asktb.o", "102869");

Supprimée : user_pref("extensions.asktb.overlay-reloaded-using-restart", true);

Supprimée : user_pref("extensions.asktb.pstate", "");

Supprimée : user_pref("extensions.asktb.qsrc", "2871");

Supprimée : user_pref("extensions.asktb.r", "4");

Supprimée : user_pref("extensions.asktb.sa", "YES");

Supprimée : user_pref("extensions.asktb.saguid", "54A570CF-6DFF-40AB-A3B2-975AA5C26544");

Supprimée : user_pref("extensions.asktb.search-suggestions-enabled", true);

Supprimée : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);

Supprimée : user_pref("extensions.asktb.socialmini-first", true);

Supprimée : user_pref("extensions.asktb.socialmini-interval", "1200000");

Supprimée : user_pref("extensions.asktb.socialmini-max-char-ticker", "33");

Supprimée : user_pref("extensions.asktb.socialmini-max-items", "30");

Supprimée : user_pref("extensions.asktb.socialmini-native-on", true);

Supprimée : user_pref("extensions.asktb.socialmini-speed", "10000");

Supprimée : user_pref("extensions.asktb.socialmini-transition-first-open", false);

Supprimée : user_pref("extensions.asktb.themeid", "");

Supprimée : user_pref("extensions.asktb.timeinstalled", "28/10/2011 00:04:55");

Supprimée : user_pref("extensions.asktb.to", "");

Supprimée : user_pref("extensions.asktb.v", "3.13.1.100009");

Supprimée : user_pref("extensions.asktb.version", "5.13.1.18107");

Supprimée : user_pref("extensions.asktb.volume", "");

Supprimée : user_pref("keyword.URL", "http://websearch.ask.com/redirect?client=ff&src=kw&tb=MYC-ST&o=102869&locale=pt_BR&apn_uid=8307a1cb-9dcb-431e-850c-72a87b4a7e2e&apn_ptnrs=5J&apn_sauid=54A570CF-6DFF-40AB-A3B2-975AA5C26544&apn_dtid=YYYYYYYYBR&&q=");

 

-\\ Google Chrome v [impossible d'obtenir la version]

 

Fichier : C:\Users\My\AppData\Local\Google\Chrome\User Data\Default\Preferences

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! RafaeL lcassati2

 

|- Baixe: < AD-Remover > ( ... de C-XX )

 

|- Ou... < Aqui! > <- Link!

 

|- Salve-o em C:\ ( Disco local )

|- Duplo clique em AD-R.exe

|- Para Windows Vista ou 7,execute-o como administrador!

 

AD-Remover_Clean.jpg

 

|- Aperte a opção "Clean".

|- Ao concluir,aceite/confirme o reboot,para que Adwares sejam removidos.

|- Ou seja,o computador irá reiniciar!

|- Poste o relatório: C:\Ad-Report-CLEAN[1].txt

 

////°°°°°////

 

|- Baixe: < GabKiller > ( ... par 2011N2 )

|- Salve-o no desktop!

|- Feche pastas que estejam abertas e execute a ferramenta.

|- Para Windows Vista ou 7,clique direito e execute como administrador.

 

GabKiller.jpg

 

|- Escolha a opção 1. Recherche -> Aperte Enter!

|- Aguarde a conclusão e poste o relatório: Rapport de recherche de GabKiller

|- Para sair,aperte a opção "4. Quitter" -> Enter!

 

////°°°°°////

 

|- Baixe: < 37ae6cbade5b149987c311d9597676e05d7fd887dbd3c7eff70cdbb46a8368c36g.jpg > < NicolasCoolman.jpg > ( ...par Nicolas Coolman )

 

|- Estando na página,clique em: < Tlcharger_ZHPDiag.jpg >

|- Salve-o em Arquivos de programas.

 

f275ef34005c23a087af2e8ec43f12a3a83b20f2d86fa52748e34ecd064fe90b6g.jpg

 

|- Ps: Descompacte-o em Arquivos de programas.

|- Abra a ferramenta ZHPDiag e habilite todas as opções de diagnóstico,clicando em ZHPDiag_Opes_Update.jpg ( Ícone da chave de fenda )

 

ZHPDiag_All.jpg

 

|- Clique em All.

|- Dê início ao diagnóstico ( Diag ),clicando no ícone da lupa.

 

ZHPDiag_Save_Report2.jpg

 

|- Ao concluir,clique em "Save Report",para dispormos do relatório.

|- Salve-o em um local conveniente!

|- Poste-o,na sua resposta: ZHPDiag.txt

|- Ps: Caso tenha problemas ao postar esse relatório,acesse < Cjoint_Logo.jpg >

|- Maiores informações: |Aqui!| ou |pjjoint.malekal.com|

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 10 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.