Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

karoline  ferreira

[Resolvido] &nbspPC com Malwares.

Recommended Posts

Olá!!Boa Noite tem alguem que possa me ajudar novamente com meu PC,estou achando que ele esta com Virus. :rolleyes:

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 20:40:24, on 1/2/2012

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\WgaTray.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe

C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe

C:\WINDOWS\system32\rundll32.exe

C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe

C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\WINDOWS\system32\sistray.exe

C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Arquivos de programas\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office14\GROOVEEX.DLL

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARQUIV~1\MICROS~2\Office14\URLREDIR.DLL

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [synTPEnh] C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [avast] "C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe" /nogui

O4 - HKLM\..\Run: [NielsenOnline] C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [PlusService] C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe

O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB001" /M "Stylus C45"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: &Enviar para o OneNote - res://C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office14\EXCEL.EXE/3000

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: Nielsen Update (NielsenUpdate) - The Nielsen Company - C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 8411 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! karoline ferreira

 

|- O que ocorre com a máquina? Poderia nos relatar?

 

///°°°///

 

|- Baixe: < marcinsig.gif >

 

|- < Link - 2 >

 

|- < Link - 3 >

 

|- Atualize o programa!

|- Escolha o escaneamento Completo!

|- Desabilite programas de proteção,ao executar o malwarebytes.

|- Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme!

|- Ao concluir,clique em "Remover itens".

|- Poste,o relatório: mbam-log-2012-xx-xx (00-00-00).txt

 

///°°°///

 

|- Baixe: < otlDesktopIcon.png > ( ...by OldTimer Tools )

 

|- Clique em Salvar! < 0e5c629f14858f5bf77e61d46c160e317c6d8c5d3ee101e311e440e99d7fd7b06g.jpg >

 

|- Salve-o no desktop! < 98c0f1ab3823c58ea05c695fd153839feac6fb6b44aaa3f7f5a2cd4a87354c946g.jpg >

 

|- Duplo clique em OTL.exe --> Executar: c19ede0bf8817fba1b9a9c0e9dae6ede3b8983c41017d8926efac3638b95aee16g.jpg

 

|- Execute o OTL,em seu rápido escaneamento. ( Verificação rápida )

|- Ps: Para Windows 7,clique direito e execute-o como "Administrador".

|- Copie e poste o relatório. ( C:\_OTM\MovedFiles\xxxx2012_xxxxxx.log )

|- Poste,também,o relatório "Extras".

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! karoline ferreira

 

|- O que ocorre com a máquina? Poderia nos relatar?

 

///°°°///

 

|- Baixe: < marcinsig.gif >

 

|- < Link - 2 >

 

|- < Link - 3 >

 

|- Atualize o programa!

|- Escolha o escaneamento Completo!

|- Desabilite programas de proteção,ao executar o malwarebytes.

|- Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme!

|- Ao concluir,clique em "Remover itens".

|- Poste,o relatório: mbam-log-2012-xx-xx (00-00-00).txt

 

///°°°///

 

|- Baixe: < otlDesktopIcon.png > ( ...by OldTimer Tools )

 

|- Clique em Salvar! < 0e5c629f14858f5bf77e61d46c160e317c6d8c5d3ee101e311e440e99d7fd7b06g.jpg >

 

|- Salve-o no desktop! < 98c0f1ab3823c58ea05c695fd153839feac6fb6b44aaa3f7f5a2cd4a87354c946g.jpg >

 

|- Duplo clique em OTL.exe --> Executar: c19ede0bf8817fba1b9a9c0e9dae6ede3b8983c41017d8926efac3638b95aee16g.jpg

 

|- Execute o OTL,em seu rápido escaneamento. ( Verificação rápida )

|- Ps: Para Windows 7,clique direito e execute-o como "Administrador".

|- Copie e poste o relatório. ( C:\_OTM\MovedFiles\xxxx2012_xxxxxx.log )

|- Poste,também,o relatório "Extras".

 

Abraços!

 

Boa Noite!DigRam...Primeiramente obrigada,meu pc está travando muito e tambem demorando para carregar.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite!DigRam...Primeiramente obrigada,meu pc está travando muito e tambem demorando para carregar.

Olá!

 

|- Ok! Siga então com as ferramentas sugeridas.

|- Faça antes a limpeza de temporários,com "Temp".

 

///°°°///

 

|- Baixe: < Temp.zip >

|- Descompacte-o para o desktop!

|- Execute-o com um duplo-clique. ( Temp.bat )

|- Onde surgirá,rapidamente,uma tela preta.

 

///°°°///

 

|- Siga com o MBAM e o OTL.

|- Poste seus relatórios!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá!

 

|- Ok! Siga então com as ferramentas sugeridas.

|- Faça antes a limpeza de temporários,com "Temp".

 

///°°°///

 

|- Baixe: < Temp.zip >

|- Descompacte-o para o desktop!

|- Execute-o com um duplo-clique. ( Temp.bat )

|- Onde surgirá,rapidamente,uma tela preta.

 

///°°°///

 

|- Siga com o MBAM e o OTL.

|- Poste seus relatórios!

 

Abraços!

 

 

Boa Noite!! 'DigRam'...

'DigRam'

 

Malwarebytes Anti-Malware (Trial) 1.60.1.1000

www.malwarebytes.org

 

Versão da Base de Dados: v2012.02.03.09

 

Windows XP Service Pack 3 x86 NTFS

Internet Explorer 6.0.2900.5512

Filho e karol :: GTEC-A93A9F1435 [administrador]

 

Proteção: Não permitir

 

3/2/2012 17:54:05

mbam-log-2012-02-03 (17-54-05).txt

 

Tipo de Verificação: Verificação Completa

Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM

Opções de verificação desativadas: P2P

Objetos escaneados: 205780

Tempo decorrido: 35 minuto(s), 43 segundo(s)

 

Processos de Memória Detectados: 0

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Detectados: 0

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Valores de Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Pastas Detectadas: 0

(Não foram detectados ítens maliciosos)

 

Arquivos Detectados: 2

C:\Documents and Settings\Filho e karol\Meus documentos\Downloads\SoftonicDownloader_para_audacity.exe (PUP.BundleOffer.Downloader.S) -> Enviado para a Quarentena e deletado com sucesso.

C:\Documents and Settings\Filho e karol\Meus documentos\Downloads\SoftonicDownloader_para_vso-convertxtodvd.exe (PUP.BundleOffer.Downloader.S) -> Enviado para a Quarentena e deletado com sucesso.

 

(fim)

 

 

 

 

OTL logfile created on: 3/2/2012 20:20:00 - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Filho e karol\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.5512)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy

 

893,10 Mb Total Physical Memory | 328,86 Mb Available Physical Memory | 36,82% Memory free

2,12 Gb Paging File | 1,66 Gb Available in Paging File | 78,62% Paging File free

Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas

Drive C: | 48,83 Gb Total Space | 30,36 Gb Free Space | 62,18% Space Free | Partition Type: NTFS

Drive D: | 62,95 Gb Total Space | 62,78 Gb Free Space | 99,73% Space Free | Partition Type: NTFS

 

Computer Name: GTEC-A93A9F1435 | User Name: Filho e karol | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2012/02/03 20:16:29 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Filho e karol\Desktop\OTL.exe

PRC - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe

PRC - [2012/01/07 22:12:37 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe

PRC - [2011/11/28 16:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Arquivos de programas\AVAST Software\Avast\AvastUI.exe

PRC - [2011/11/28 16:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe

PRC - [2011/11/02 15:17:41 | 000,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

PRC - [2011/10/24 16:51:19 | 000,801,792 | ---- | M] (Yuna Software) -- C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe

PRC - [2011/05/03 18:46:26 | 000,306,496 | ---- | M] (The Nielsen Company) -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe

PRC - [2010/11/17 11:38:00 | 000,047,424 | ---- | M] (The Nielsen Company) -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe

PRC - [2009/03/10 22:18:18 | 000,969,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\WgaTray.exe

PRC - [2008/04/13 19:21:00 | 001,035,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2007/06/25 16:45:42 | 000,262,144 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\sistray.exe

PRC - [2007/06/01 10:21:30 | 001,209,904 | ---- | M] (Nero AG) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

PRC - [2007/06/01 10:21:30 | 000,271,920 | ---- | M] (Nero AG) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

PRC - [2007/06/01 10:21:08 | 000,153,136 | ---- | M] (Nero AG) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

PRC - [2004/01/14 09:00:00 | 000,099,840 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I4T1.EXE

 

 

========== Modules (No Company Name) ==========

 

MOD - [2012/02/03 16:41:52 | 001,688,576 | ---- | M] () -- C:\Arquivos de programas\AVAST Software\Avast\defs\12020301\algo.dll

MOD - [2012/01/08 13:57:00 | 000,076,800 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\extensions\{192a6019-26d2-4611-aead-07cd7733b146}\components\RadioWMPCoreGecko9.dll

MOD - [2012/01/07 22:12:35 | 002,124,760 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\mozjs.dll

MOD - [2011/11/19 08:21:56 | 008,527,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

MOD - [2011/05/03 18:41:32 | 000,247,296 | ---- | M] () -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\nsmmc.dll

MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF

MOD - [2010/10/04 17:55:30 | 000,264,704 | ---- | M] () -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\meter3\npwmi.dll

MOD - [2010/10/04 17:55:14 | 000,292,864 | ---- | M] () -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\meter3\npsurvey.dll

MOD - [2010/10/04 17:55:04 | 000,184,320 | ---- | M] () -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\meter3\npsp1.dll

MOD - [2010/10/04 17:48:26 | 000,485,376 | ---- | M] () -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\meter3\communication.dll

 

 

========== Win32 Services (SafeList) ==========

 

SRV - File not found [Disabled | Stopped] -- -- (HidServ)

SRV - [2012/01/13 14:53:18 | 000,652,360 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)

SRV - [2011/11/28 16:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)

SRV - [2011/06/12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)

SRV - [2011/05/03 18:46:26 | 000,306,496 | ---- | M] (The Nielsen Company) [Auto | Running] -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe -- (NielsenUpdate)

SRV - [2010/01/09 21:37:50 | 004,640,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)

SRV - [2010/01/09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE -- (ose)

SRV - [2007/06/01 10:21:30 | 000,271,920 | ---- | M] (Nero AG) [On_Demand | Running] -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)

 

 

========== Driver Services (SafeList) ==========

 

DRV - [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)

DRV - [2011/11/28 15:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)

DRV - [2011/11/28 15:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)

DRV - [2011/11/28 15:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)

DRV - [2011/11/28 15:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)

DRV - [2011/11/28 15:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)

DRV - [2011/11/28 15:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)

DRV - [2011/11/28 15:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)

DRV - [2011/08/17 09:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)

DRV - [2010/10/04 17:57:20 | 000,015,360 | ---- | M] (The Nielsen Company) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\nnrnstdi.sys -- (nnrnstdi)

DRV - [2010/10/04 17:57:16 | 000,010,368 | ---- | M] (The Nielsen Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\km_filter.sys -- (km_filter)

DRV - [2007/12/20 18:00:06 | 004,637,696 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2007/06/25 07:10:28 | 000,018,432 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)

DRV - [2007/06/25 06:49:08 | 000,321,536 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)

DRV - [2007/06/01 03:06:42 | 000,238,976 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rtl8187B.sys -- (RTL8187B)

DRV - [2006/12/20 02:00:00 | 000,041,600 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys -- (SiSGbeXP)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..browser.search.defaultthis.engineName: "Stardoll Customized Web Search"

FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2836015&SearchSource=3&q={searchTerms}"

FF - prefs.js..browser.startup.homepage: "http://www.google.com"

FF - prefs.js..network.proxy.http: "81.84.241.147"

FF - prefs.js..network.proxy.http_port: 2183

FF - prefs.js..network.proxy.type: 0

 

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Arquivos de programas\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\ARQUIV~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\ARQUIV~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Arquivos de programas\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46: C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Arquivos de programas\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Arquivos de programas\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Arquivos de programas\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Arquivos de programas\Real\RealPlayer\browserrecord [2011/11/02 15:17:52 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Arquivos de programas\AVAST Software\Avast\WebRep\FF [2011/11/29 16:36:50 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D908A1CC-54B4-4af9-9BB4-964F5BD3CDB7}: C:\Arquivos de programas\NetRatingsNetSight\NetSight\meter3\FFAddon\ [2012/01/31 10:49:08 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox\components [2012/01/07 22:12:40 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox\plugins

 

[2011/11/02 14:57:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Extensions

[2012/01/08 17:16:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\extensions

[2012/01/08 17:16:44 | 000,000,000 | ---D | M] (Stardoll Community Toolbar) -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\extensions\{192a6019-26d2-4611-aead-07cd7733b146}

[2011/11/03 13:44:18 | 000,000,919 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\searchplugins\conduit.xml

[2012/01/01 08:15:55 | 000,002,774 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\searchplugins\Plusnetwork.xml

[2011/11/02 14:57:25 | 000,000,000 | ---D | M] (No name found) -- C:\Arquivos de programas\Mozilla Firefox\extensions

[2012/01/31 10:49:08 | 000,000,000 | ---D | M] (Nielsen) -- C:\ARQUIVOS DE PROGRAMAS\NETRATINGSNETSIGHT\NETSIGHT\METER3\FFADDON

[2012/01/07 22:12:38 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Arquivos de programas\mozilla firefox\components\browsercomps.dll

[2012/01/07 22:12:30 | 000,001,027 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\buscape.xml

[2012/01/07 22:12:30 | 000,001,212 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\mercadolivre.xml

[2012/01/07 22:12:30 | 000,002,040 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\twitter.xml

[2012/01/07 22:12:30 | 000,001,168 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\wikipedia-br.xml

[2012/01/07 22:12:30 | 000,000,952 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\yahoo-br.xml

 

========== Chrome ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}

CHR - plugin: Shockwave Flash (Enabled) = C:\Arquivos de programas\Google\Chrome\Application\16.0.912.77\gcswf32.dll

CHR - plugin: Adobe Acrobat (Disabled) = C:\Arquivos de programas\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll

CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Arquivos de programas\Real\RealPlayer\Netscape6\nppl3260.dll

CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprpjplug.dll

CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Arquivos de programas\Windows Media Player\npdsplay.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\ARQUIV~1\MICROS~2\Office14\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\ARQUIV~1\MICROS~2\Office14\NPSPWRAP.DLL

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Arquivos de programas\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Arquivos de programas\Google\Chrome\Application\16.0.912.77\pdf.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Arquivos de programas\Windows Media Player\npdrmv2.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Arquivos de programas\Windows Media Player\npwmsdrm.dll

CHR - plugin: Google Update (Enabled) = C:\Arquivos de programas\Google\Update\1.2.183.39\npGoogleOneClick8.dll

CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprjplug.dll

CHR - plugin: Default Plug-in (Enabled) = default_plugin

CHR - Extension: YouTube = C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\

CHR - Extension: Pesquisa do Google = C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\

CHR - Extension: avast! WebRep = C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1374_0\

CHR - Extension: Nielsen = C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\jgceplfonlgodadnpognljgdjlcnpjnh\1.3.0_0\

CHR - Extension: Gmail = C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

 

O1 HOSTS File: ([2000/01/11 20:38:34 | 000,000,776 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Arquivos de programas\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)

O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)

O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Arquivos de programas\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)

O4 - HKLM..\Run: [Adobe ARM] C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [avast] C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe (AVAST Software)

O4 - HKLM..\Run: [bluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)

O4 - HKLM..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE (SEIKO EPSON CORPORATION)

O4 - HKLM..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe (Epson)

O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe (Nero AG)

O4 - HKLM..\Run: [NielsenOnline] C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe (The Nielsen Company)

O4 - HKLM..\Run: [PlusService] C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe (Yuna Software)

O4 - HKLM..\Run: [siSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)

O4 - HKLM..\Run: [TkBellExe] C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKCU..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe (Nero AG)

O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation)

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: &Enviar para o OneNote - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de programas\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)

O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{129BC170-D18B-4D71-A3CE-166C42F67025}: DhcpNameServer = 192.168.254.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F344BE1-A5C6-4A31-989C-28C50E04E85D}: DhcpNameServer = 200.222.145.84 200.149.55.142

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O24 - Desktop Components:0 (Minha página inicial atual) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de programas\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2011/11/02 14:21:25 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\{ea1989a6-0570-11e1-b97b-001644da8ece}\Shell\AutoRun\command - "" = H:\setup.exe

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2012/02/03 20:16:17 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Filho e karol\Desktop\OTL.exe

[2012/01/30 18:23:18 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Filho e karol\Recent

[2012/01/25 09:38:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Unity

[2012/01/25 09:15:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Filho e karol\Meus documentos\Messenger Plus

[2012/01/23 20:02:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Iniciar\Programas\Ink Monitor

[2012/01/23 20:01:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Iniciar\Programas\Impressoras EPSON

[2012/01/23 19:52:29 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\EPSON

[2012/01/19 15:54:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\WMTools Downloaded Files

[2012/01/19 15:38:35 | 001,343,488 | ---- | C] (MultiMedia Soft) -- C:\WINDOWS\System32\AdjMmsEng.dll

[2012/01/19 15:38:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Pianosoft

[2012/01/19 14:40:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Audacity

[2004/11/24 16:25:52 | 000,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2012/02/03 20:16:29 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Filho e karol\Desktop\OTL.exe

[2012/02/03 20:12:47 | 000,002,262 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2012/02/03 20:12:45 | 000,001,082 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2012/02/03 20:05:00 | 000,001,086 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2012/02/03 20:03:25 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2012/02/03 17:40:47 | 000,000,840 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk

[2012/02/03 12:29:27 | 000,201,929 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\1.PNG

[2012/02/03 12:28:04 | 000,355,730 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\2.PNG

[2012/02/01 16:01:20 | 000,092,392 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\trans.JPG

[2012/02/01 16:00:45 | 000,099,065 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\tns.JPG

[2012/01/24 12:10:22 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2012/01/23 20:02:02 | 000,000,066 | ---- | M] () -- C:\WINDOWS\EPSC45.ini

[2012/01/21 11:30:50 | 000,040,620 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\pagamento dvd.PNG

[2012/01/19 15:56:32 | 000,000,116 | ---- | M] () -- C:\Documents and Settings\Filho e karol\default.pls

[2012/01/19 15:47:56 | 000,012,288 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2012/01/19 14:06:13 | 005,085,019 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\preview.mp3

[2012/01/19 11:29:13 | 000,041,402 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\fgts.PNG

[2012/01/16 19:36:28 | 000,084,321 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 4.PNG

[2012/01/16 19:34:29 | 000,081,899 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 3.PNG

[2012/01/16 19:34:15 | 000,078,099 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 2.PNG

[2012/01/16 19:11:14 | 000,084,052 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita.PNG

[2012/01/16 19:10:52 | 000,058,047 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao vsita 1.PNG

[2012/01/16 15:59:55 | 000,152,632 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\0012.jpg

[2012/01/16 15:38:55 | 000,027,669 | ---- | M] () -- C:\Documents and Settings\Filho e karol\Desktop\auto_cartao_dos_carros_cartao_visita-p240736084886866179z74gr_400.jpg

[2012/01/04 21:18:33 | 000,471,614 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat

[2012/01/04 21:18:33 | 000,435,594 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2012/01/04 21:18:33 | 000,080,396 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat

[2012/01/04 21:18:33 | 000,068,490 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2012/02/03 17:40:47 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk

[2012/02/03 12:22:11 | 000,355,730 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\2.PNG

[2012/02/03 12:22:02 | 000,201,929 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\1.PNG

[2012/02/01 16:01:20 | 000,092,392 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\trans.JPG

[2012/02/01 16:00:45 | 000,099,065 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\tns.JPG

[2012/01/23 20:01:34 | 000,000,182 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT4.DAT

[2012/01/23 19:52:08 | 000,000,066 | ---- | C] () -- C:\WINDOWS\EPSC45.ini

[2012/01/21 11:30:50 | 000,040,620 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\pagamento dvd.PNG

[2012/01/19 15:38:36 | 000,157,696 | ---- | C] () -- C:\WINDOWS\System32\OggEnc.exe

[2012/01/19 15:38:36 | 000,145,408 | ---- | C] () -- C:\WINDOWS\System32\Lame.exe

[2012/01/19 15:38:36 | 000,006,832 | ---- | C] () -- C:\WINDOWS\System32\PulseSoundTouchForVB.tlb

[2012/01/19 15:38:35 | 000,098,708 | ---- | C] () -- C:\WINDOWS\System32\activesoundeditor.tlb

[2012/01/19 15:38:35 | 000,076,800 | ---- | C] () -- C:\WINDOWS\System32\Faac.exe

[2012/01/19 15:29:46 | 005,085,019 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\preview.mp3

[2012/01/19 11:29:13 | 000,041,402 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\fgts.PNG

[2012/01/16 19:36:28 | 000,084,321 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 4.PNG

[2012/01/16 19:34:29 | 000,081,899 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 3.PNG

[2012/01/16 19:34:15 | 000,078,099 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita 2.PNG

[2012/01/16 19:11:14 | 000,084,052 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao visita.PNG

[2012/01/16 19:10:52 | 000,058,047 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Meus documentos\cartao vsita 1.PNG

[2012/01/16 15:57:40 | 000,152,632 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\0012.jpg

[2012/01/16 15:38:45 | 000,027,669 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Desktop\auto_cartao_dos_carros_cartao_visita-p240736084886866179z74gr_400.jpg

[2011/12/12 21:59:00 | 000,000,085 | -HS- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\.zreglib

[2011/11/28 10:54:02 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI

[2011/11/02 20:02:56 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2011/11/02 19:30:09 | 000,012,288 | ---- | C] () -- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011/11/02 15:40:09 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2011/11/02 15:40:09 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2011/11/02 14:34:49 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\ChCfg.exe

[2011/11/02 14:30:16 | 000,092,761 | ---- | C] () -- C:\WINDOWS\VGAsetup.ini

[2011/11/02 14:29:39 | 000,208,896 | R--- | C] () -- C:\WINDOWS\Progress.exe

[2011/11/02 14:29:39 | 000,049,152 | R--- | C] () -- C:\WINDOWS\InstFunc.exe

[2011/11/02 14:29:31 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\sis760.bin

[2011/11/02 14:29:31 | 000,065,536 | R--- | C] () -- C:\WINDOWS\System32\sis741.bin

[2011/11/02 14:29:31 | 000,049,152 | R--- | C] () -- C:\WINDOWS\System32\sis660.bin

[2011/11/02 14:29:15 | 000,133,021 | ---- | C] () -- C:\WINDOWS\System32\VGAunistlog.ini

[2011/11/02 14:23:42 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2011/11/02 14:18:20 | 000,021,844 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2011/11/02 12:08:02 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2011/11/02 12:06:50 | 000,280,536 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2004/11/29 12:43:20 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\sherlock2.exe

[2004/10/12 03:40:58 | 002,255,360 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll

[2004/10/12 03:39:48 | 000,028,160 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll

[2004/10/12 03:39:08 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll

[2004/10/09 03:40:16 | 000,454,144 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll

[2004/10/05 05:16:08 | 000,395,776 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll

[2004/10/03 14:50:54 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll

[2004/09/01 13:49:17 | 003,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll

[2004/08/04 01:57:52 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin

[2004/08/02 15:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2000/01/11 20:38:34 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[2000/01/11 20:38:34 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[2000/01/11 20:38:34 | 000,471,614 | ---- | C] () -- C:\WINDOWS\System32\perfh016.dat

[2000/01/11 20:38:34 | 000,435,594 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[2000/01/11 20:38:34 | 000,301,776 | ---- | C] () -- C:\WINDOWS\System32\perfi016.dat

[2000/01/11 20:38:34 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[2000/01/11 20:38:34 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[2000/01/11 20:38:34 | 000,080,396 | ---- | C] () -- C:\WINDOWS\System32\perfc016.dat

[2000/01/11 20:38:34 | 000,068,490 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[2000/01/11 20:38:34 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[2000/01/11 20:38:34 | 000,035,178 | ---- | C] () -- C:\WINDOWS\System32\perfd016.dat

[2000/01/11 20:38:34 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[2000/01/11 20:38:34 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[2000/01/11 20:38:34 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

 

========== LOP Check ==========

 

[2012/01/19 15:31:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Audacity

[2011/12/05 23:34:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Windows Live Writer

[2011/11/02 15:47:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\AVAST Software

[2011/11/02 20:06:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus!

[2012/01/19 15:38:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Pianosoft

 

========== Purity Check ==========

 

 

 

< End of report >

 

 

 

OTL Extras logfile created on: 3/2/2012 20:20:00 - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Filho e karol\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.5512)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy

 

893,10 Mb Total Physical Memory | 328,86 Mb Available Physical Memory | 36,82% Memory free

2,12 Gb Paging File | 1,66 Gb Available in Paging File | 78,62% Paging File free

Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas

Drive C: | 48,83 Gb Total Space | 30,36 Gb Free Space | 62,18% Space Free | Partition Type: NTFS

Drive D: | 62,95 Gb Total Space | 62,78 Gb Free Space | 99,73% Space Free | Partition Type: NTFS

 

Computer Name: GTEC-A93A9F1435 | User Name: Filho e karol | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

 

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation)

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Arquivos de programas\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [print] -- "C:\Arquivos de programas\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)

InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

========== System Restore Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.EXE" = C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace -- (Microsoft Corporation)

"C:\Arquivos de programas\Microsoft Office\Office14\ONENOTE.EXE" = C:\Arquivos de programas\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote -- (Microsoft Corporation)

"C:\Arquivos de programas\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Arquivos de programas\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)

"C:\Documents and Settings\Filho e karol\Configurações locais\Temp\196.tmp\KMService.exe" = C:\Documents and Settings\Filho e karol\Configurações locais\Temp\196.tmp\KMService.exe:*:Enabled:KMService

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{0FFEA8EE-7BC7-4C9D-8CC6-5B8C891BA3F2}" = Windows Live Essentials

"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live

"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT

"{2DF215E0-BD3C-4C98-8616-AFEF09747285}" = Windows Live Sync

"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform

"{350C9416-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}" = Assistente de Conexão do Windows Live

"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml

"{590035D9-BFA0-406A-A7F0-479C72C0DDB2}" = Windows Live Call

"{66EBD70F-A42C-475F-AEDF-277378151046}" = Nero 7 Essentials

"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD

"{7095FD27-37F0-4750-9DE8-D37DC0043706}" = REALTEK USB Wireless LAN Driver

"{74AD1846-2010-4FB1-8E24-B6F2B87150C2}" = Windows Live Mail

"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX

"{87A9C015-C2BA-44EE-9C20-6E1A764B8E23}" = Windows Live Galeria de Fotos

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)

"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player

"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update

"{90140000-0010-0416-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Portuguese (Brazil)) 14

"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010

"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0015-0416-0000-0000000FF1CE}" = Microsoft Office Access MUI (Portuguese (Brazil)) 2010

"{90140000-0015-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0016-0416-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Portuguese (Brazil)) 2010

"{90140000-0016-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0018-0416-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010

"{90140000-0018-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0019-0416-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010

"{90140000-0019-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001A-0416-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010

"{90140000-001A-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001B-0416-0000-0000000FF1CE}" = Microsoft Office Word MUI (Portuguese (Brazil)) 2010

"{90140000-001B-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010

"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2010

"{90140000-001F-0416-0000-0000000FF1CE}_Office14.PROPLUS_{A7200E61-DC93-42E0-BB74-EE59021016EA}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010

"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002C-0416-0000-0000000FF1CE}" = Microsoft Office Proofing (Portuguese (Brazil)) 2010

"{90140000-002C-0416-0000-0000000FF1CE}_Office14.PROPLUS_{13291F79-D997-49AD-9F31-5FAEE1F0FCF5}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0044-0416-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010

"{90140000-0044-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-006E-0416-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Portuguese (Brazil)) 2010

"{90140000-006E-0416-0000-0000000FF1CE}_Office14.PROPLUS_{2134F8C8-2AD8-44EE-B86B-1B577FBD8D0E}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-00A1-0416-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010

"{90140000-00A1-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-00BA-0416-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Portuguese (Brazil)) 2010

"{90140000-00BA-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{9555B4ED-09A3-4722-8E8C-57A49401D059}" = Windows Live Writer

"{9ADC3E4F-34DA-48CD-8727-BB26D90257BD}" = Windows Live Messenger

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack

"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI

"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AC76BA86-7AD7-1046-7B44-AA1000000001}" = Adobe Reader X (10.1.2) - Português

"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{C50BF854-E881-434F-9C67-5A73EBB58F06}" = Windows Live Toolbar

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{DC226AC9-0314-496C-BE6A-B6A132628466}" = SiSAGP driver

"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader

"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin

"avast" = avast! Free Antivirus

"CCleaner" = CCleaner

"DVD Flick_is1" = DVD Flick 1.3.0.7

"EPSON Printer and Utilities" = Software para Impressoras EPSON

"Google Chrome" = Google Chrome

"Ink Monitor" = Ink Monitor

"L&H Power Translator Pro 7.0" = L&H Power Translator Pro 7.0

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versão 1.60.1.1000

"Messenger Plus!" = Messenger Plus! 5

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"Mozilla Firefox 9.0.1 (x86 pt-BR)" = Mozilla Firefox 9.0.1 (x86 pt-BR)

"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP

"NetSight" = Nielsen

"Office14.PROPLUS" = Microsoft Office Professional Plus 2010

"QuicktimeAlt_is1" = QuickTime Alternative 1.77

"RealPlayer 6.0" = RealPlayer

"SiS VGA Driver" = SiS VGA Utilities

"SynTPDeinstKey" = Synaptics Pointing Device Driver

"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7

"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"Windows Media Player" = Windows Media Player 11

"Windows XP Service Pack" = Windows XP Service Pack 3

"WinLiveSuite_Wave3" = Windows Live Essentials

"WinRAR archiver" = Arquivo do WinRAR

"WMFDist11" = Windows Media Format 11 runtime

"wmp11" = Windows Media Player 11

"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

"XP Codec Pack" = XP Codec Pack

"XviD_is1" = XviD 1.1 final uninstall

 

========== HKEY_CURRENT_USER Uninstall List ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"UnityWebPlayer" = Unity Web Player

 

========== Last 10 Event Log Errors ==========

 

[ Application Events ]

Error - 5/12/2011 11:13:06 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1002

Description = Aplicativo com falha firefox.exe, versão 8.0.1.4341, módulo com falha

hungapp, versão 0.0.0.0, endereço com falha 0x00000000.

 

Error - 5/12/2011 11:13:19 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1001

Description = Falha no compartimento de memória -1589266322.

 

Error - 5/12/2011 11:13:59 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1001

Description = Falha no compartimento de memória -1589266322.

 

Error - 5/12/2011 11:13:59 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1001

Description = Falha no compartimento de memória -1589266322.

 

Error - 5/12/2011 11:14:00 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1001

Description = Falha no compartimento de memória -1589266322.

 

Error - 7/12/2011 18:29:28 | Computer Name = GTEC-A93A9F1435 | Source = ESENT | ID = 489

Description = wuauclt (3580) Falha na tentativa de abrir o arquivo "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"

para acesso somente leitura, com erro de sistema 32 (0x00000020): "O arquivo já

está sendo usado por outro processo. ". A operação de abertura do arquivo falhará

com o erro -1032 (0xfffffbf8).

 

Error - 7/12/2011 18:29:28 | Computer Name = GTEC-A93A9F1435 | Source = ESENT | ID = 455

Description = wuaueng.dll (3580) SUS20ClientDataStore: Erro -1032 (0xfffffbf8) ao

abrir o arquivo de log C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

 

Error - 7/12/2011 18:29:38 | Computer Name = GTEC-A93A9F1435 | Source = ESENT | ID = 489

Description = wuauclt (3580) Falha na tentativa de abrir o arquivo "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"

para acesso somente leitura, com erro de sistema 32 (0x00000020): "O arquivo já

está sendo usado por outro processo. ". A operação de abertura do arquivo falhará

com o erro -1032 (0xfffffbf8).

 

Error - 7/12/2011 18:29:38 | Computer Name = GTEC-A93A9F1435 | Source = ESENT | ID = 455

Description = wuaueng.dll (3580) SUS20ClientDataStore: Erro -1032 (0xfffffbf8) ao

abrir o arquivo de log C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.

 

Error - 10/12/2011 20:42:50 | Computer Name = GTEC-A93A9F1435 | Source = Application Hang | ID = 1002

Description = Aplicativo com falha firefox.exe, versão 8.0.1.4341, módulo com falha

hungapp, versão 0.0.0.0, endereço com falha 0x00000000.

 

[ System Events ]

Error - 2/2/2012 18:09:59 | Computer Name = GTEC-A93A9F1435 | Source = Disk | ID = 262155

Description = O driver detectou um erro de controlador em \Device\Harddisk1\D.

 

Error - 3/2/2012 08:39:21 | Computer Name = GTEC-A93A9F1435 | Source = Dhcp | ID = 1002

Description = A concessão 192.168.254.1 do endereço IP para a placa de rede com

endereço de rede 00030DA7B51F foi negada pelo servidor DHCP 192.168.254.254 (O servidor

DHCP enviou uma mensagem DHCPNACK).

 

Error - 3/2/2012 09:46:33 | Computer Name = GTEC-A93A9F1435 | Source = Disk | ID = 262155

Description = O driver detectou um erro de controlador em \Device\Harddisk1\D.

 

Error - 3/2/2012 11:56:07 | Computer Name = GTEC-A93A9F1435 | Source = ACPI | ID = 327685

Description = AMLI: o BIOS da ACPI está tentando gravar em um endereço de porta

de E/S inválido (0x70), que está no intervalo de endereços protegido 0x70 - 0x71.

Isso pode causar instabilidade no sistema. Contate o fornecedor do sistema para

obter assistência técnica.

 

Error - 3/2/2012 11:56:07 | Computer Name = GTEC-A93A9F1435 | Source = ACPI | ID = 327684

Description = AMLI: o BIOS da ACPI está tentando ler um endereço de porta de E/S

(0x71) inválido, que está no intervalo de endereços protegido 0x70 - 0x71. Isso

pode causar instabilidade no sistema. Contate o fornecedor do sistema para obter

assistência técnica.

 

Error - 3/2/2012 12:14:52 | Computer Name = GTEC-A93A9F1435 | Source = Disk | ID = 262155

Description = O driver detectou um erro de controlador em \Device\Harddisk1\D.

 

Error - 3/2/2012 16:52:40 | Computer Name = GTEC-A93A9F1435 | Source = Disk | ID = 262155

Description = O driver detectou um erro de controlador em \Device\Harddisk1\D.

 

Error - 3/2/2012 17:58:23 | Computer Name = GTEC-A93A9F1435 | Source = ACPI | ID = 327685

Description = AMLI: o BIOS da ACPI está tentando gravar em um endereço de porta

de E/S inválido (0x70), que está no intervalo de endereços protegido 0x70 - 0x71.

Isso pode causar instabilidade no sistema. Contate o fornecedor do sistema para

obter assistência técnica.

 

Error - 3/2/2012 17:58:23 | Computer Name = GTEC-A93A9F1435 | Source = ACPI | ID = 327684

Description = AMLI: o BIOS da ACPI está tentando ler um endereço de porta de E/S

(0x71) inválido, que está no intervalo de endereços protegido 0x70 - 0x71. Isso

pode causar instabilidade no sistema. Contate o fornecedor do sistema para obter

assistência técnica.

 

Error - 3/2/2012 18:03:39 | Computer Name = GTEC-A93A9F1435 | Source = sr | ID = 1

Description = O filtro da restauração do sistema encontrou o erro inesperado '0xC0000001'

ao processar o arquivo '' no volume 'HarddiskVolume1'. O monitoramento do volume

foi interrompido.

 

 

< End of report >

Abraços... :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! karoline ferreira

 

|- Abra o Firefox!

|- Vá em Ferramentas -> Opções -> Avançado -> Rede -> Configurar Conexão.

|- Clique em "Sem Proxy" -> Ok.

 

///°°°///

 

|- Baixe: < AdwCleaner > ( ... par Xplode )

 

|- Clique em Télécharger! < d210af57fdd8237cca69ae792bc6ffcff89cacc6c0ce5568f2a323e9d67c467a6g.jpg >

 

|- Salve-o no desktop!

 

|- Dê início ao scan,clicando em "Recherche" < AdwCleaner_Suppression.jpg >

 

|- Ao concluir,poste o relatório: C:\AdwCleaner[R].txt

 

///°°°///

 

|- Execute o OTL.exe.

|- Copie estas informações que estão em vermelho,para o campo clipboard da ferramenta. ( "Exames Personalizados Correções" )

 

:Files

C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\searchplugins\conduit.xml

 

:OTL

SRV - File not found [Disabled | Stopped] -- -- (HidServ)

FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2836015&SearchSource=3&q={searchTerms}"

O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)

O33 - MountPoints2\{ea1989a6-0570-11e1-b97b-001644da8ece}\Shell\AutoRun\command - "" = H:\setup.exe

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

:Commands

[emptyflash]

[emptytemp]

[reboot]

|- Clique no botão Consertar.

|- Ps: A ferramenta irá reiniciar o computador.

|- Ao surgir,clique em executar.

|- Poste o relatório: C:\_OTL\MovedFiles\*.log

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! karoline ferreira

 

|- Abra o Firefox!

|- Vá em Ferramentas -> Opções -> Avançado -> Rede -> Configurar Conexão.

|- Clique em "Sem Proxy" -> Ok.

 

///°°°///

 

|- Baixe: < AdwCleaner > ( ... par Xplode )

 

|- Clique em Télécharger! < d210af57fdd8237cca69ae792bc6ffcff89cacc6c0ce5568f2a323e9d67c467a6g.jpg >

 

|- Salve-o no desktop!

 

|- Dê início ao scan,clicando em "Recherche" < AdwCleaner_Suppression.jpg >

 

|- Ao concluir,poste o relatório: C:\AdwCleaner[R].txt

 

///°°°///

 

|- Execute o OTL.exe.

|- Copie estas informações que estão em vermelho,para o campo clipboard da ferramenta. ( "Exames Personalizados Correções" )

 

 

|- Clique no botão Consertar.

|- Ps: A ferramenta irá reiniciar o computador.

|- Ao surgir,clique em executar.

|- Poste o relatório: C:\_OTL\MovedFiles\*.log

 

Abraços!

 

Bom Dia!! 'DigRam'

Fiz como você escreveu todos os passos,só que o OTL.exe não gerou relatório e nem reiniciou o meu pc,quando termina de consertar pedi para reiniciar o pc,clico em ok mais nada acontece.Não sei o que fazer!!! :upset: :cry:

 

 

Esse o relatório do AdwCleaner.

# AdwCleaner v1.408 - Logfile created 02/03/2012 at 23:52:16

# Updated 29/01/2012 by Xplode

# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)

# User : Filho e karol - GTEC-A93A9F1435 (Administrator)

# Running from : C:\Documents and Settings\Filho e karol\Desktop\adwcleaner.exe

# Option [search]

 

 

***** [services] *****

 

 

***** [Files / Folders] *****

 

Folder Found : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\ConduitCommon

File Found : C:\Arquivos de programas\Windows live\messenger\msimg32.dll

File Found : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\searchplugins\Conduit.xml

 

***** [Registry] *****

 

Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4

Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212

Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe

 

***** [internet Browsers] *****

 

-\\ Internet Explorer v6.0.2900.5512

 

[OK] Registry is clean.

 

-\\ Mozilla Firefox v9.0.1 (pt-BR)

 

Profile : 3o20c2zd.default

File : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\prefs.js

 

Found : user_pref("CT2836015..clientLogIsEnabled", false);

Found : user_pref("CT2836015..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]

Found : user_pref("CT2836015..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]

Found : user_pref("CT2836015.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);

Found : user_pref("CT2836015.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");

Found : user_pref("CT2836015.AppTrackingLastCheckTime", "Thu Jan 26 2012 20:51:00 GMT-0200");

Found : user_pref("CT2836015.BrowserCompStateIsOpen_1000515", true);

Found : user_pref("CT2836015.CT2836015", "CT2836015");

Found : user_pref("CT2836015.CommunitiesChangesLastCheckTime", "0");

Found : user_pref("CT2836015.CurrentServerDate", "4-2-2012");

Found : user_pref("CT2836015.DSChangedManually", true);

Found : user_pref("CT2836015.DSInstall", true);

Found : user_pref("CT2836015.DialogsAlignMode", "LTR");

Found : user_pref("CT2836015.DialogsGetterLastCheckTime", "Fri Feb 03 2012 10:48:51 GMT-0200");

Found : user_pref("CT2836015.DownloadReferralCookieData", "{\"BannerName\":\"\",\"BannerTypeId\":\"\",\"Bann[...]

Found : user_pref("CT2836015.EMailNotifierPollDate", "Fri Nov 04 2011 13:37:48 GMT-0200 (Hora oficial do Bra[...]

Found : user_pref("CT2836015.EnableClickToSearchBox", false);

Found : user_pref("CT2836015.EnableSearchHistory", false);

Found : user_pref("CT2836015.EnableSearchSuggest", false);

Found : user_pref("CT2836015.FirstServerDate", "4-11-2011");

Found : user_pref("CT2836015.FirstTime", true);

Found : user_pref("CT2836015.FirstTimeFF3", true);

Found : user_pref("CT2836015.FixPageNotFoundErrors", false);

Found : user_pref("CT2836015.GroupingInvalidateCache", false);

Found : user_pref("CT2836015.GroupingLastCheckTime", "0");

Found : user_pref("CT2836015.GroupingLastServerUpdateTime", "0");

Found : user_pref("CT2836015.GroupingServerCheckInterval", 1440);

Found : user_pref("CT2836015.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");

Found : user_pref("CT2836015.HPInstall", false);

Found : user_pref("CT2836015.HasUserGlobalKeys", true);

Found : user_pref("CT2836015.HomePageProtectorEnabled", false);

Found : user_pref("CT2836015.HomepageBeforeUnload", "chrome://branding/locale/browserconfig.properties");

Found : user_pref("CT2836015.Initialize", true);

Found : user_pref("CT2836015.InitializeCommonPrefs", true);

Found : user_pref("CT2836015.InstallationAndCookieDataSentCount", 3);

Found : user_pref("CT2836015.InstallationType", "DirectDownload");

Found : user_pref("CT2836015.InstalledDate", "Fri Nov 04 2011 13:37:38 GMT-0200 (Hora oficial do Brasil)");

Found : user_pref("CT2836015.InvalidateCache", false);

Found : user_pref("CT2836015.IsAlertDBUpdated", true);

Found : user_pref("CT2836015.IsGrouping", false);

Found : user_pref("CT2836015.IsInitSetupIni", true);

Found : user_pref("CT2836015.IsMulticommunity", false);

Found : user_pref("CT2836015.IsOpenThankYouPage", true);

Found : user_pref("CT2836015.IsOpenUninstallPage", true);

Found : user_pref("CT2836015.IsProtectorsInit", true);

Found : user_pref("CT2836015.LanguagePackLastCheckTime", "Fri Feb 03 2012 17:37:10 GMT-0200");

Found : user_pref("CT2836015.LanguagePackReloadIntervalMM", 1440);

Found : user_pref("CT2836015.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]

Found : user_pref("CT2836015.LastLogin_3.8.0.8", "Mon Dec 05 2011 13:14:53 GMT-0200");

Found : user_pref("CT2836015.LastLogin_3.8.1.0", "Sun Jan 08 2012 13:45:56 GMT-0200");

Found : user_pref("CT2836015.LastLogin_3.9.0.3", "Fri Feb 03 2012 20:14:09 GMT-0200");

Found : user_pref("CT2836015.LatestVersion", "3.9.0.3");

Found : user_pref("CT2836015.Locale", "en");

Found : user_pref("CT2836015.MCDetectTooltipHeight", "83");

Found : user_pref("CT2836015.MCDetectTooltipShow", false);

Found : user_pref("CT2836015.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");

Found : user_pref("CT2836015.MCDetectTooltipWidth", "295");

Found : user_pref("CT2836015.MyStuffEnabledAtInstallation", true);

Found : user_pref("CT2836015.OriginalFirstVersion", "3.8.0.8");

Found : user_pref("CT2836015.RadioIsPodcast", false);

Found : user_pref("CT2836015.RadioLastCheckTime", "0");

Found : user_pref("CT2836015.RadioLastUpdateIPServer", "0");

Found : user_pref("CT2836015.RadioLastUpdateServer", "0");

Found : user_pref("CT2836015.RadioMediaID", "6827");

Found : user_pref("CT2836015.RadioMediaType", "Media Player");

Found : user_pref("CT2836015.RadioMenuSelectedID", "EBRadioMenu_CT28360156827");

Found : user_pref("CT2836015.RadioShrinkedFromSetup", false);

Found : user_pref("CT2836015.RadioStationName", "Boa%20Vista");

Found : user_pref("CT2836015.RadioStationURL", "hxxp://200.202.254.131/radio/radio.asx");

Found : user_pref("CT2836015.SHRINK_TOOLBAR", 1);

Found : user_pref("CT2836015.SearchBackToDefaultEngine", false);

Found : user_pref("CT2836015.SearchCaption", "Stardoll Customized Web Search");

Found : user_pref("CT2836015.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");

Found : user_pref("CT2836015.SearchFromAddressBarIsInit", true);

Found : user_pref("CT2836015.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT283[...]

Found : user_pref("CT2836015.SearchInNewTabEnabled", true);

Found : user_pref("CT2836015.SearchInNewTabIntervalMM", 1440);

Found : user_pref("CT2836015.SearchInNewTabLastCheckTime", "Fri Feb 03 2012 17:36:02 GMT-0200");

Found : user_pref("CT2836015.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]

Found : user_pref("CT2836015.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]

Found : user_pref("CT2836015.SearchInNewTabUserEnabled", false);

Found : user_pref("CT2836015.SearchProtectorEnabled", false);

Found : user_pref("CT2836015.SearchProtectorToolbarDisabled", false);

Found : user_pref("CT2836015.SendProtectorDataViaLogin", true);

Found : user_pref("CT2836015.ServiceMapLastCheckTime", "Fri Feb 03 2012 20:14:09 GMT-0200");

Found : user_pref("CT2836015.SettingsLastCheckTime", "Fri Feb 03 2012 23:45:09 GMT-0200");

Found : user_pref("CT2836015.SettingsLastUpdate", "1326723880");

Found : user_pref("CT2836015.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2836015&SearchSource=13");

Found : user_pref("CT2836015.ThirdPartyComponentsInterval", 504);

Found : user_pref("CT2836015.ThirdPartyComponentsLastCheck", "Sat Jan 28 2012 12:53:32 GMT-0200");

Found : user_pref("CT2836015.ThirdPartyComponentsLastUpdate", "1312887586");

Found : user_pref("CT2836015.ToolbarShrinkedFromSetup", false);

Found : user_pref("CT2836015.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2836015");

Found : user_pref("CT2836015.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]

Found : user_pref("CT2836015.UserID", "UN42829468452553987");

Found : user_pref("CT2836015.ValidationData_Search", 2);

Found : user_pref("CT2836015.ValidationData_Toolbar", 2);

Found : user_pref("CT2836015.WeatherNetwork", "");

Found : user_pref("CT2836015.WeatherPollDate", "Fri Feb 03 2012 23:15:39 GMT-0200");

Found : user_pref("CT2836015.WeatherUnit", "C");

Found : user_pref("CT2836015.alertChannelId", "1228076");

Found : user_pref("CT2836015.approveUntrustedApps", true);

Found : user_pref("CT2836015.backendstorage.for_aoi", "31333238333037363732");

Found : user_pref("CT2836015.backendstorage.for_ccid", "6E756C6C");

Found : user_pref("CT2836015.backendstorage.for_cdtr6", "31333238333037363732");

Found : user_pref("CT2836015.backendstorage.for_cid", "4252");

Found : user_pref("CT2836015.backendstorage.for_ip", "3138372E34312E3234372E3336");

Found : user_pref("CT2836015.backendstorage.for_lcut", "31333238333037363732");

Found : user_pref("CT2836015.backendstorage.for_rid", "3133");

Found : user_pref("CT2836015.backendstorage.for_zoneid", "37383138");

Found : user_pref("CT2836015.componentAlertEnabled", false);

Found : user_pref("CT2836015.components.1000034", false);

Found : user_pref("CT2836015.components.1000082", false);

Found : user_pref("CT2836015.components.1000234", true);

Found : user_pref("CT2836015.components.1000515", false);

Found : user_pref("CT2836015.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]

Found : user_pref("CT2836015.globalFirstTimeInfoLastCheckTime", "Fri Jan 27 2012 12:31:31 GMT-0200");

Found : user_pref("CT2836015.homepageProtectorEnableByLogin", true);

Found : user_pref("CT2836015.initDone", true);

Found : user_pref("CT2836015.isAppTrackingManagerOn", true);

Found : user_pref("CT2836015.isFirstRadioInstallation", false);

Found : user_pref("CT2836015.isSearchProtectorNotifyChanges", false);

Found : user_pref("CT2836015.myStuffEnabled", true);

Found : user_pref("CT2836015.myStuffPublihserMinWidth", 400);

Found : user_pref("CT2836015.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]

Found : user_pref("CT2836015.myStuffServiceIntervalMM", 1440);

Found : user_pref("CT2836015.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]

Found : user_pref("CT2836015.oldAppsList", "129336860020050106,129336860020050107,111,129351721820319552,100[...]

Found : user_pref("CT2836015.revertSettingsEnabled", true);

Found : user_pref("CT2836015.searchProtectorDialogDelayInSec", 10);

Found : user_pref("CT2836015.searchProtectorEnableByLogin", true);

Found : user_pref("CT2836015.testingCtid", "");

Found : user_pref("CT2836015.toolbarAppMetaDataLastCheckTime", "Fri Feb 03 2012 13:42:18 GMT-0200");

Found : user_pref("CT2836015.toolbarContextMenuLastCheckTime", "Sat Jan 21 2012 10:13:44 GMT-0200");

Found : user_pref("CT2836015.usageEnabled", false);

Found : user_pref("CT2836015.usagesFlag", 2);

Found : user_pref("CommunityToolbar.ConduitSearchList", "Stardoll Customized Web Search");

Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2836015/CT2836015[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1228076/1223749/BR", "\"0\"[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2836015", [...]

Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2836015",[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2836015&octid=[...]

Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"cde[...]

Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Documents and Settings\\Filho e karol\\Dad[...]

Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.9.0.3");

Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");

Found : user_pref("CommunityToolbar.ToolbarsList", "CT2836015");

Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2836015");

Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2836015");

Found : user_pref("CommunityToolbar.globalUserId", "1a8d6af3-0778-455e-b198-8521e6646a04");

Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);

Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);

Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sat Jan 28 2012 12:53:3[...]

Found : user_pref("CommunityToolbar.notifications.alertEnabled", true);

Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);

Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Fri Feb 03 2012 23:45:09 GMT-020[...]

Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");

Found : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true);

Found : user_pref("CommunityToolbar.notifications.locale", "en");

Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);

Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Fri Feb 03 2012 20:14:09 GMT-0200");

Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");

Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);

Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");

Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);

Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);

Found : user_pref("CommunityToolbar.notifications.userId", "46e0e6c1-d93e-4c5c-b2eb-3afd6149ef0c");

Found : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");

Found : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties[...]

Found : user_pref("browser.search.defaultthis.engineName", "Stardoll Customized Web Search");

Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2836015&Sea[...]

 

*************************

 

AdwCleaner[R1].txt - [15646 octets] - [03/02/2012 23:52:16]

 

########## EOF - C:\AdwCleaner[R1].txt - [15775 octets] ##########

 

Abraços.... :)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! karoline ferreira

 

|- Lance,novamente,AdwCleaner e clique em "Suppression" ou "Delete".

 

AdwCleaner_Suppression.jpg

 

|- Ao concluir,poste o relatório: C:\AdwCleaner[S].txt

 

///°°°///

 

|- Abra o OTL.exe -> Clique em Limpeza. <-- Confirme!

|- Ps: O computador irá reiniciar!

 

///°°°///

 

|- Baixe: < ToolbarShooter > ( ... de 2011N2 )

|- Salve-o no desktop!

|- Desabilite seu antivírus.

|- Execute a ferramenta,e escolha a opção 2. ( Suppression )

|- Ps: Para Windows Vista ou 7,execute-o como administrador!

|- Ao concluir,aperte Enter,para dispormos do relatório.

|- Poste o relatório: "Rapport de suppression de ToolbarShooter"

|- Poste,também,HijackThis atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! karoline ferreira

 

|- Lance,novamente,AdwCleaner e clique em "Suppression" ou "Delete".

 

AdwCleaner_Suppression.jpg

 

|- Ao concluir,poste o relatório: C:\AdwCleaner[S].txt

 

///°°°///

 

|- Abra o OTL.exe -> Clique em Limpeza. <-- Confirme!

|- Ps: O computador irá reiniciar!

 

///°°°///

 

|- Baixe: < ToolbarShooter > ( ... de 2011N2 )

|- Salve-o no desktop!

|- Desabilite seu antivírus.

|- Execute a ferramenta,e escolha a opção 2. ( Suppression )

|- Ps: Para Windows Vista ou 7,execute-o como administrador!

|- Ao concluir,aperte Enter,para dispormos do relatório.

|- Poste o relatório: "Rapport de suppression de ToolbarShooter"

|- Poste,também,HijackThis atualizado.

 

Abraços!

 

Boa Tarde!! DigRam....

 

# AdwCleaner v1.408 - Logfile created 02/06/2012 at 14:02:18

# Updated 29/01/2012 by Xplode

# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)

# User : Filho e karol - GTEC-A93A9F1435 (Administrator)

# Running from : C:\Documents and Settings\Filho e karol\Desktop\adwcleaner.exe

# Option [Delete]

 

 

***** [services] *****

 

 

***** [Files / Folders] *****

 

Folder Deleted : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\ConduitCommon

File Deleted : C:\Arquivos de programas\Windows live\messenger\msimg32.dll

File Deleted : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\searchplugins\Conduit.xml

 

***** [Registry] *****

 

Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4

Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}

Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe

 

***** [internet Browsers] *****

 

-\\ Internet Explorer v6.0.2900.5512

 

[OK] Registry is clean.

 

-\\ Mozilla Firefox v9.0.1 (pt-BR)

 

Profile : 3o20c2zd.default

File : C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla\Firefox\Profiles\3o20c2zd.default\prefs.js

 

Deleted : user_pref("CT2836015..clientLogIsEnabled", true);

Deleted : user_pref("CT2836015..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]

Deleted : user_pref("CT2836015..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]

Deleted : user_pref("CT2836015.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);

Deleted : user_pref("CT2836015.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");

Deleted : user_pref("CT2836015.AppTrackingLastCheckTime", "Thu Jan 26 2012 20:51:00 GMT-0200");

Deleted : user_pref("CT2836015.BrowserCompStateIsOpen_1000515", true);

Deleted : user_pref("CT2836015.CT2836015", "CT2836015");

Deleted : user_pref("CT2836015.CommunitiesChangesLastCheckTime", "0");

Deleted : user_pref("CT2836015.CurrentServerDate", "6-2-2012");

Deleted : user_pref("CT2836015.DSChangedManually", true);

Deleted : user_pref("CT2836015.DSInstall", true);

Deleted : user_pref("CT2836015.DialogsAlignMode", "LTR");

Deleted : user_pref("CT2836015.DialogsGetterLastCheckTime", "Fri Feb 03 2012 10:48:51 GMT-0200");

Deleted : user_pref("CT2836015.DownloadReferralCookieData", "{\"BannerName\":\"\",\"BannerTypeId\":\"\",\"Bann[...]

Deleted : user_pref("CT2836015.EMailNotifierPollDate", "Fri Nov 04 2011 13:37:48 GMT-0200 (Hora oficial do Bra[...]

Deleted : user_pref("CT2836015.EnableClickToSearchBox", false);

Deleted : user_pref("CT2836015.EnableSearchHistory", false);

Deleted : user_pref("CT2836015.EnableSearchSuggest", false);

Deleted : user_pref("CT2836015.FirstServerDate", "4-11-2011");

Deleted : user_pref("CT2836015.FirstTime", true);

Deleted : user_pref("CT2836015.FirstTimeFF3", true);

Deleted : user_pref("CT2836015.FixPageNotFoundErrors", false);

Deleted : user_pref("CT2836015.GroupingInvalidateCache", false);

Deleted : user_pref("CT2836015.GroupingLastCheckTime", "0");

Deleted : user_pref("CT2836015.GroupingLastServerUpdateTime", "0");

Deleted : user_pref("CT2836015.GroupingServerCheckInterval", 1440);

Deleted : user_pref("CT2836015.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");

Deleted : user_pref("CT2836015.HPInstall", false);

Deleted : user_pref("CT2836015.HasUserGlobalKeys", true);

Deleted : user_pref("CT2836015.HomePageProtectorEnabled", false);

Deleted : user_pref("CT2836015.HomepageBeforeUnload", "chrome://branding/locale/browserconfig.properties");

Deleted : user_pref("CT2836015.Initialize", true);

Deleted : user_pref("CT2836015.InitializeCommonPrefs", true);

Deleted : user_pref("CT2836015.InstallationAndCookieDataSentCount", 3);

Deleted : user_pref("CT2836015.InstallationType", "DirectDownload");

Deleted : user_pref("CT2836015.InstalledDate", "Fri Nov 04 2011 13:37:38 GMT-0200 (Hora oficial do Brasil)");

Deleted : user_pref("CT2836015.InvalidateCache", false);

Deleted : user_pref("CT2836015.IsAlertDBUpdated", true);

Deleted : user_pref("CT2836015.IsGrouping", false);

Deleted : user_pref("CT2836015.IsInitSetupIni", true);

Deleted : user_pref("CT2836015.IsMulticommunity", false);

Deleted : user_pref("CT2836015.IsOpenThankYouPage", true);

Deleted : user_pref("CT2836015.IsOpenUninstallPage", true);

Deleted : user_pref("CT2836015.IsProtectorsInit", true);

Deleted : user_pref("CT2836015.LanguagePackLastCheckTime", "Sun Feb 05 2012 19:13:26 GMT-0200");

Deleted : user_pref("CT2836015.LanguagePackReloadIntervalMM", 1440);

Deleted : user_pref("CT2836015.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]

Deleted : user_pref("CT2836015.LastLogin_3.8.0.8", "Mon Dec 05 2011 13:14:53 GMT-0200");

Deleted : user_pref("CT2836015.LastLogin_3.8.1.0", "Sun Jan 08 2012 13:45:56 GMT-0200");

Deleted : user_pref("CT2836015.LastLogin_3.9.0.3", "Mon Feb 06 2012 10:09:19 GMT-0200");

Deleted : user_pref("CT2836015.LatestVersion", "3.9.0.3");

Deleted : user_pref("CT2836015.Locale", "en");

Deleted : user_pref("CT2836015.MCDetectTooltipHeight", "83");

Deleted : user_pref("CT2836015.MCDetectTooltipShow", false);

Deleted : user_pref("CT2836015.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");

Deleted : user_pref("CT2836015.MCDetectTooltipWidth", "295");

Deleted : user_pref("CT2836015.MyStuffEnabledAtInstallation", true);

Deleted : user_pref("CT2836015.OriginalFirstVersion", "3.8.0.8");

Deleted : user_pref("CT2836015.RadioIsPodcast", false);

Deleted : user_pref("CT2836015.RadioLastCheckTime", "0");

Deleted : user_pref("CT2836015.RadioLastUpdateIPServer", "0");

Deleted : user_pref("CT2836015.RadioLastUpdateServer", "0");

Deleted : user_pref("CT2836015.RadioMediaID", "6827");

Deleted : user_pref("CT2836015.RadioMediaType", "Media Player");

Deleted : user_pref("CT2836015.RadioMenuSelectedID", "EBRadioMenu_CT28360156827");

Deleted : user_pref("CT2836015.RadioShrinkedFromSetup", false);

Deleted : user_pref("CT2836015.RadioStationName", "Boa%20Vista");

Deleted : user_pref("CT2836015.RadioStationURL", "hxxp://200.202.254.131/radio/radio.asx");

Deleted : user_pref("CT2836015.SHRINK_TOOLBAR", 1);

Deleted : user_pref("CT2836015.SearchBackToDefaultEngine", false);

Deleted : user_pref("CT2836015.SearchCaption", "Stardoll Customized Web Search");

Deleted : user_pref("CT2836015.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");

Deleted : user_pref("CT2836015.SearchFromAddressBarIsInit", true);

Deleted : user_pref("CT2836015.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT283[...]

Deleted : user_pref("CT2836015.SearchInNewTabEnabled", true);

Deleted : user_pref("CT2836015.SearchInNewTabIntervalMM", 1440);

Deleted : user_pref("CT2836015.SearchInNewTabLastCheckTime", "Sun Feb 05 2012 19:13:25 GMT-0200");

Deleted : user_pref("CT2836015.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]

Deleted : user_pref("CT2836015.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]

Deleted : user_pref("CT2836015.SearchInNewTabUserEnabled", false);

Deleted : user_pref("CT2836015.SearchProtectorEnabled", false);

Deleted : user_pref("CT2836015.SearchProtectorToolbarDisabled", false);

Deleted : user_pref("CT2836015.SendProtectorDataViaLogin", true);

Deleted : user_pref("CT2836015.ServiceMapLastCheckTime", "Mon Feb 06 2012 10:09:18 GMT-0200");

Deleted : user_pref("CT2836015.SettingsLastCheckTime", "Mon Feb 06 2012 10:09:55 GMT-0200");

Deleted : user_pref("CT2836015.SettingsLastUpdate", "1326723880");

Deleted : user_pref("CT2836015.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2836015&SearchSource=13");

Deleted : user_pref("CT2836015.ThirdPartyComponentsInterval", 504);

Deleted : user_pref("CT2836015.ThirdPartyComponentsLastCheck", "Sat Jan 28 2012 12:53:32 GMT-0200");

Deleted : user_pref("CT2836015.ThirdPartyComponentsLastUpdate", "1312887586");

Deleted : user_pref("CT2836015.ToolbarShrinkedFromSetup", false);

Deleted : user_pref("CT2836015.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2836015");

Deleted : user_pref("CT2836015.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]

Deleted : user_pref("CT2836015.UserID", "UN42829468452553987");

Deleted : user_pref("CT2836015.ValidationData_Search", 2);

Deleted : user_pref("CT2836015.ValidationData_Toolbar", 2);

Deleted : user_pref("CT2836015.WeatherNetwork", "");

Deleted : user_pref("CT2836015.WeatherPollDate", "Mon Feb 06 2012 10:09:19 GMT-0200");

Deleted : user_pref("CT2836015.WeatherUnit", "C");

Deleted : user_pref("CT2836015.alertChannelId", "1228076");

Deleted : user_pref("CT2836015.approveUntrustedApps", true);

Deleted : user_pref("CT2836015.backendstorage.for_aoi", "31333238333037363732");

Deleted : user_pref("CT2836015.backendstorage.for_ccid", "6E756C6C");

Deleted : user_pref("CT2836015.backendstorage.for_cdtr6", "31333238333037363732");

Deleted : user_pref("CT2836015.backendstorage.for_cid", "4252");

Deleted : user_pref("CT2836015.backendstorage.for_ip", "3138372E34302E37382E313436");

Deleted : user_pref("CT2836015.backendstorage.for_lcut", "31333238353330313738");

Deleted : user_pref("CT2836015.backendstorage.for_rid", "3133");

Deleted : user_pref("CT2836015.backendstorage.for_zoneid", "37383138");

Deleted : user_pref("CT2836015.componentAlertEnabled", false);

Deleted : user_pref("CT2836015.components.1000034", false);

Deleted : user_pref("CT2836015.components.1000082", false);

Deleted : user_pref("CT2836015.components.1000234", true);

Deleted : user_pref("CT2836015.components.1000515", false);

Deleted : user_pref("CT2836015.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]

Deleted : user_pref("CT2836015.globalFirstTimeInfoLastCheckTime", "Fri Jan 27 2012 12:31:31 GMT-0200");

Deleted : user_pref("CT2836015.homepageProtectorEnableByLogin", true);

Deleted : user_pref("CT2836015.initDone", true);

Deleted : user_pref("CT2836015.isAppTrackingManagerOn", true);

Deleted : user_pref("CT2836015.isFirstRadioInstallation", false);

Deleted : user_pref("CT2836015.isSearchProtectorNotifyChanges", false);

Deleted : user_pref("CT2836015.myStuffEnabled", true);

Deleted : user_pref("CT2836015.myStuffPublihserMinWidth", 400);

Deleted : user_pref("CT2836015.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]

Deleted : user_pref("CT2836015.myStuffServiceIntervalMM", 1440);

Deleted : user_pref("CT2836015.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]

Deleted : user_pref("CT2836015.oldAppsList", "129336860020050106,129336860020050107,111,129351721820319552,100[...]

Deleted : user_pref("CT2836015.revertSettingsEnabled", true);

Deleted : user_pref("CT2836015.searchProtectorDialogDelayInSec", 10);

Deleted : user_pref("CT2836015.searchProtectorEnableByLogin", true);

Deleted : user_pref("CT2836015.testingCtid", "");

Deleted : user_pref("CT2836015.toolbarAppMetaDataLastCheckTime", "Sun Feb 05 2012 19:13:26 GMT-0200");

Deleted : user_pref("CT2836015.toolbarContextMenuLastCheckTime", "Sat Feb 04 2012 10:27:24 GMT-0200");

Deleted : user_pref("CT2836015.usageEnabled", false);

Deleted : user_pref("CT2836015.usagesFlag", 2);

Deleted : user_pref("CommunityToolbar.ConduitSearchList", "Stardoll Customized Web Search");

Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2836015/CT2836015[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1228076/1223749/BR", "\"0\"[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2836015", [...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2836015",[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2836015&octid=[...]

Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"cde[...]

Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Documents and Settings\\Filho e karol\\Dad[...]

Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.9.0.3");

Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");

Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2836015");

Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2836015");

Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2836015");

Deleted : user_pref("CommunityToolbar.globalUserId", "1a8d6af3-0778-455e-b198-8521e6646a04");

Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);

Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);

Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sat Feb 04 2012 17:31:4[...]

Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", true);

Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);

Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Mon Feb 06 2012 10:09:55 GMT-020[...]

Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");

Deleted : user_pref("CommunityToolbar.notifications.firstTimeAlertShown", true);

Deleted : user_pref("CommunityToolbar.notifications.locale", "en");

Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);

Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Mon Feb 06 2012 10:09:18 GMT-0200");

Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");

Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);

Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");

Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);

Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);

Deleted : user_pref("CommunityToolbar.notifications.userId", "46e0e6c1-d93e-4c5c-b2eb-3afd6149ef0c");

Deleted : user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");

Deleted : user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties[...]

Deleted : user_pref("browser.search.defaultthis.engineName", "Stardoll Customized Web Search");

Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2836015&Sea[...]

 

*************************

 

AdwCleaner[R1].txt - [15777 octets] - [03/02/2012 23:52:16]

AdwCleaner[R2].txt - [15837 octets] - [04/02/2012 08:22:42]

AdwCleaner[s1].txt - [16139 octets] - [06/02/2012 14:02:18]

 

*************************

 

Temporary folder : : 14 folder(s) and 31 file(s) deleted

 

########## EOF - C:\AdwCleaner[s1].txt - [16358 octets] ##########

 

 

___________________________________________________________

 

 

=========== Informations ===========

 

Mis à jour le : 20/01/2012 à 19h45 par 2011N2

Rapport de suppression de ToolbarShooter par 2011N2

Contact : lot12@hotmail.fr

Site : http://2011n2.forumgratuit.fr/

 

Début du scan de suppression : 14:19:21

 

################################## Toolbars, pups et adwares néfastes supprimés ################################

 

 

Clé supprimée avec succès : HKLM\Software\Classes\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}

 

 

 

 

Clé supprimée avec succès : HKCR\CLSID\{72B3882F-453A-4633-AAC9-8C3DCED62AFF}

 

 

 

======== Page de démarrage Internet Explorer ========

 

Page de démarrage d'Internet Explorer restaurée avec succès.

 

===================================

 

Fin du nettoyage : 14:21:35

 

 

======== EOF ========

 

Merci d'envoyer le rapport à cette adresse, en précisant la raison d'emploi de cet outil. Cela permettera au développeur d'effectuer d'éventuelles modifications : lot12@hotmail.fr

 

Merci de votre contribution !

 

 

L'utilisateur à décidé de redémarrer l'ordinateur ultérieurement

 

_____________________________________________________________

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 14:39:02, on 6/2/2012

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe

C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe

C:\WINDOWS\system32\rundll32.exe

C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe

C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\WINDOWS\system32\sistray.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Arquivos de programas\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office14\GROOVEEX.DLL

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARQUIV~1\MICROS~2\Office14\URLREDIR.DLL

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [synTPEnh] C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [avast] "C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe" /nogui

O4 - HKLM\..\Run: [NielsenOnline] C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [PlusService] C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe

O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB001" /M "Stylus C45"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: &Enviar para o OneNote - res://C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office14\EXCEL.EXE/3000

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIE.dll

O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: Nielsen Update (NielsenUpdate) - The Nielsen Company - C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 8470 bytes

 

 

Abraços...

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! karoline ferreira

 

|- Como está seu PC,tudo Ok?

 

///°°°///

 

|- Baixe: < ZHPDiag > ( ... par Nicolas Coolman )

 

|- Estando na página,clique em: < Tlcharger_ZHPDiag.jpg >

|- Salve-o em Arquivos de programas.

|- Ps: Descompacte-o em Arquivos de programas.

|- Desabilite seu antivírus e execute "ZHPDiag2.exe". < b1213ab5b1c6c82da85cd782fc66e21829baa55668d621f18000599eb2f818666g.jpg >

|- Ps: Siga os procedimentos na instalação.

|- Clique em 4804a19ee52052e68b5900ce67a6566890b7a2f79506eeabaac40aefe1d31a086g.jpg |-- Termine.

 

ZHPDiag_Pergaminho.jpg

 

|- Abra a ferramenta,clicando no ícone do pergaminho. ( ZHPDiag )

 

ZHPDiag_IconedoChapeu.jpg

 

|- Escolha a opção de idiomas que desejar!

|- Atualize-a,clicando na seta verde. < ZHPDiag_Opes_Update.jpg >

 

|- Clique no ícone do 'capetinha!' < ZHPDiag_Icone_diabinho.jpg >

|- Poste o relatório: Rapport de ZHPScan

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! karoline ferreira

 

|- Como está seu PC,tudo Ok?

 

///°°°///

 

|- Baixe: < ZHPDiag > ( ... par Nicolas Coolman )

 

|- Estando na página,clique em: < Tlcharger_ZHPDiag.jpg >

|- Salve-o em Arquivos de programas.

|- Ps: Descompacte-o em Arquivos de programas.

|- Desabilite seu antivírus e execute "ZHPDiag2.exe". < b1213ab5b1c6c82da85cd782fc66e21829baa55668d621f18000599eb2f818666g.jpg >

|- Ps: Siga os procedimentos na instalação.

|- Clique em 4804a19ee52052e68b5900ce67a6566890b7a2f79506eeabaac40aefe1d31a086g.jpg |-- Termine.

 

ZHPDiag_Pergaminho.jpg

 

|- Abra a ferramenta,clicando no ícone do pergaminho. ( ZHPDiag )

 

ZHPDiag_IconedoChapeu.jpg

 

|- Escolha a opção de idiomas que desejar!

|- Atualize-a,clicando na seta verde. < ZHPDiag_Opes_Update.jpg >

 

|- Clique no ícone do 'capetinha!' < ZHPDiag_Icone_diabinho.jpg >

|- Poste o relatório: Rapport de ZHPScan

 

Abraços!

 

 

Boa Noite !! "DigRam"

Está mais rapido,quando ligo está carregando logo e nao esta mais travando como antes.

 

Rapport de ZHPDiag v1.28.32 par Nicolas Coolman, Update du 05/02/2012

Run by Filho e karol at 8/2/2012 20:11:22

Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html

Web site : http://nicolascoolman.skyrock.com/

State : Your version is update.

 

 

---\\ Web Browser

MSIE: Internet Explorer v6.0.2900.5512

MFIE: Mozilla Firefox 9.0.1 v9.0.1 (Defaut)

GCIE: Google Chrome v16.0.912.77

 

---\\ Windows Product Information

~ Langage: Anglais

Windows XP Professional Service Pack 3 (Build 2600)

Windows Automatic Updates : OK

Windows Genuine Advantage : OK

 

---\\ System Information

~ Processor: x86 Family 6 Model 22 Stepping 1, GenuineIntel

~ Operating System: 32 Bits

Boot mode: Normal (Normal boot)

Total RAM: 893 MB (70% free)

System Restore: Activé (Enable)

System drive C: has 29 GB (59%) free of 49 GB

 

---\\ Logged in mode

~ Computer Name: GTEC-A93A9F1435

~ User Name: Filho e karol

~ All Users Names: SUPPORT_388945a0, HelpAssistant, Filho e karol, Convidado, Administrador,

~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89

Logged in as Administrator

 

---\\ Environnement Variables

~ System Unit : C:\

~ %AppData% : C:\Documents and Settings\Filho e karol\Dados de aplicativos\

~ %Desktop% : C:\Documents and Settings\Filho e karol\Desktop\

~ %Favorites% : C:\Documents and Settings\Filho e karol\Favorites\

~ %LocalAppData% : C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\

~ %StartMenu% : C:\Documents and Settings\Filho e karol\Menu Iniciar\

~ %Windir% : C:\WINDOWS\

~ %System% : C:\WINDOWS\system32\

 

---\\ DOS/Devices

C:\ Hard drive, Flash drive, Thumb drive (Free 29 Go of 49 Go)

D:\ Hard drive, Flash drive, Thumb drive (Free 63 Go of 63 Go)

E:\ CD-ROM drive (Not Inserted)

F:\ Floppy drive, Flash card reader, USB Key (Not Inserted)

 

 

 

---\\ Security Center & Tools Informations

[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK

[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK

[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: Modified

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK

[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK

[HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : Out Of Date

~ Scan Security Center in 00mn 00s

 

 

 

---\\ Search Generic System Files

[MD5.064EC7FF5F58B928C3E119402977FA6D] - (.Microsoft Corporation - Windows Explorer.) (.13/4/2008 - 18:21:00.) -- C:\WINDOWS\Explorer.exe [1035776]

[MD5.E715412E47D20EB0EBF77B65F9157343] - (.Microsoft Corporation - Executa uma DLL como um aplicativo.) (.13/4/2008 - 18:21:18.) -- C:\WINDOWS\system32\rundll32.exe [33280]

[MD5.FE85EC0BCDC74A604A9A4C470DCD707E] - (.Microsoft Corporation - Internet Extensions para Win32.) (.1/11/2011 - 17:35:23.) -- C:\WINDOWS\system32\wininet.dll [669184]

[MD5.71D440F79B711627B12B567FB2EADB42] - (.Microsoft Corporation - Aplicativo de logon do Windows NT.) (.13/4/2008 - 18:21:24.) -- C:\WINDOWS\system32\Winlogon.exe [509952]

[MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.17/8/2011 - 10:49:54.) -- C:\WINDOWS\system32\drivers\AFD.sys [138496]

[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.13/4/2008 - 10:40:32.) -- C:\WINDOWS\system32\drivers\atapi.sys [96512]

[MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) (.13/4/2008 - 11:14:22.) -- C:\WINDOWS\system32\drivers\Cdfs.sys [63744]

[MD5.1F4260CC5B42272D71F79E570A27A4FE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.13/4/2008 - 10:40:48.) -- C:\WINDOWS\system32\drivers\Cdrom.sys [62976]

[MD5.A8D31E836CCF2F51009CE7DFFECF6D51] - (.Microsoft Corporation - FIPS Crypto Driver.) (.13/4/2008 - 17:52:44.) -- C:\WINDOWS\system32\drivers\Fips.sys [44672]

[MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows ® Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) (.13/4/2008 - 08:36:06.) -- C:\WINDOWS\system32\drivers\HDAudBus.sys [144384]

[MD5.485BC6BEB778B5E9702E6AA3D384C0CB] - (.Microsoft Corporation - Driver de porta i8042.) (.13/4/2008 - 17:55:20.) -- C:\WINDOWS\system32\drivers\i8042prt.sys [53504]

[MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) (.13/4/2008 - 10:41:00.) -- C:\WINDOWS\system32\drivers\Imapi.sys [42112]

[MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) (.13/4/2008 - 10:57:16.) -- C:\WINDOWS\system32\drivers\IpNat.sys [152832]

[MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) (.13/4/2008 - 11:19:44.) -- C:\WINDOWS\system32\drivers\IPSec.sys [75264]

[MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.15/7/2011 - 10:29:31.) -- C:\WINDOWS\system32\drivers\MRxSmb.sys [456320]

[MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) (.13/4/2008 - 11:21:02.) -- C:\WINDOWS\system32\drivers\netBT.sys [162816]

[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.13/4/2008 - 11:15:54.) -- C:\WINDOWS\system32\drivers\ntfs.sys [574976]

[MD5.9BADEE6B698BF1AF36E25A1A64A89EAB] - (.Microsoft Corporation - Driver de porta paralela.) (.13/4/2008 - 18:02:26.) -- C:\WINDOWS\system32\drivers\Parport.sys [80384]

[MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.13/4/2008 - 11:19:44.) -- C:\WINDOWS\system32\drivers\Rasl2tp.sys [51328]

[MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.13/4/2008 - 10:32:52.) -- C:\WINDOWS\system32\drivers\rdpdr.sys [196224]

[MD5.68D749B04BFBBD4D4D15CC5185AFA4DD] - (.Microsoft Corporation - Redbook Audio Filter Driver.) (.13/4/2008 - 17:53:18.) -- C:\WINDOWS\system32\drivers\redbook.sys [58240]

[MD5.EB6B1E2C984D84470FF4FE7EF98CD44A] - (.Microsoft Corporation - Driver de cópia de sombra de volume.) (.13/4/2008 - 17:53:02.) -- C:\WINDOWS\system32\drivers\volsnap.sys [53248]

~ Scan Generic Processes in 00mn 00s

 

 

 

---\\ Hidden files state (Hidden/Total)

~ Mes images (My Pictures) : 3/359

~ Mes musiques (My Musics) : 29/458

~ Mes Videos (My Video) : 0/0

~ Mes Favoris (My Favorites) : Non accessible (Not found)

~ Mes Documents (My Documents) : 44/1540

~ Mon Bureau (My Desktop) : 1/21

~ Menu demarrer (Programs) : 6/38

~ Scan Hidden Files in 00mn 03s

 

 

 

---\\ Running Processes

[MD5.996E6D052438E8D8DFD501F31560B2E0] - (.AVAST Software - avast! Service.) -- C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe [44768] [PID.]

[MD5.F8DF5D4F62D5A6AA04D7D3FEB51D1D7E] - (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe [737369] [PID.1868]

[MD5.9C3CDB8964BA91FA3029508D870466DB] - (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.EXE [16860672] [PID.1876]

[MD5.89D583FC41D48328128A974C25AFAEB7] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe [185896] [PID.1892]

[MD5.F7226AA410954185160067D5FA82F3F2] - (.AVAST Software - avast! Antivirus.) -- C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe [3744552] [PID.1908]

[MD5.DE9BC3722D7846B594FD4602ABBDBCFB] - (.The Nielsen Company - NielsenOnline.) -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe [47424] [PID.1916]

[MD5.30183A68E8EFDE4CB7D65C815081DADA] - (.Yuna Software - Messenger Plus! 5.) -- C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe [801792] [PID.1952]

[MD5.ECE648CDC3A09421E996DFFDA76F5C53] - (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [153136] [PID.1988]

[MD5.525F03A1964CA81BF4B37256650E7498] - (.Silicon Integrated Systems Corporation - SiS Compatible Super VGA Tray Application.) -- C:\WINDOWS\system32\sistray.exe [262144] [PID.2000]

[MD5.056B19651BD7B7CE5F89A3AC46DBDC08] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe [652360] [PID.]

[MD5.33FEA967497E9F6B2457D1C4E8EB11A0] - (.The Nielsen Company - NielsenOnline.) -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe [306496] [PID.]

[MD5.060DAF68493AD7ADF104413E5A62AFA8] - (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe [271920] [PID.]

[MD5.B920AAF7ABEA489AC415DD38AD7B76CD] - (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe [1209904] [PID.3084]

[MD5.588E6EA6A56BEC337F5752E289BB942A] - (.Microsoft Corporation - Paint.) -- C:\WINDOWS\system32\mspaint.exe [345600] [PID.2280]

[MD5.B02C35F6E1DD6707C5976A9629B93A2E] - (.Nicolas Coolman - Nettoyeur de rapport ZHPDiag.) -- C:\Arquivos de programas\ZHPDiag\ZHPFix.exe [1438208] [PID.3412]

[MD5.4309B75F125067EF805F3125B01FCC30] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Arquivos de programas\ZHPDiag\ZHPDiag.exe [2210816] [PID.1016]

~ Scan Processes Running in 00mn 02s

 

 

 

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (P2,M0,M1,M2,M3)

P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.60831.0.) -- C:\Arquivos de programas\Microsoft Silverlight\4.0.60831.0\npctrl.dll

P2 - FPN: [HKLM] [@microsoft.com/OfficeAuthz,version=14.0] - (.Microsoft Corporation - Office Authorization plug-in for NPAPI browsers.) -- C:\Arquivos de programas\Microsoft Office\Office14\NPAUTHZ.dll

P2 - FPN: [HKLM] [@microsoft.com/SharePoint,version=14.0] - (.Microsoft Corporation - The plug-in allows you to open and edit files using Microsoft Office a.) -- C:\Arquivos de programas\Microsoft Office\Office14\NPSPWRAP.dll

P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8117.0416] - (.Microsoft Corporation - NPWLPG.) -- C:\Arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll

P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

P2 - FPN: [HKLM] [@real.com/nppl3260;version=6.0.12.46] - (.RealNetworks, Inc. - RealPlayer LiveConnect-Enabled Plug-In.) -- C:\Arquivos de programas\Real\RealPlayer\Netscape6\nppl3260.dll

P2 - FPN: [HKLM] [@real.com/nprjplug;version=1.0.3.46] - (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprjplug.dll

P2 - FPN: [HKLM] [@real.com/nprpjplug;version=6.0.12.46] - (.RealNetworks, Inc. - 6.0.12.46.) -- C:\Arquivos de programas\Real\RealPlayer\Netscape6\nprpjplug.dll

P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Arquivos de programas\Google\Update\1.3.21.99\npGoogleUpdate3.dll

P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Arquivos de programas\Google\Update\1.3.21.99\npGoogleUpdate3.dll

P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.2.) -- C:\Arquivos de programas\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

P2 - FPN: [HKCU] [@unity3d.com/UnityPlayer,version=1.0] - (.Unity Technologies ApS - Unity Player 2.6.1f3.) -- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Unity\WebPlayer\loader\npUnity3D32.dll

~ Scan Firefox Browser in 00mn 00s

 

 

 

---\\ Internet Explorer Extensions, Start, Search (R4,R3,R0,R1)

R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.fr

R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com

R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com

R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Biblioteca Shell de controles e objetos-doc.) (6.00.2900.6168 (xpsp_sp3_gdr.111101-1829)) -- C:\WINDOWS\system32\shdocvw.dll

~ Scan IE Browser in 00mn 00s

 

 

 

---\\ Internet Explorer, Proxy Management (R5)

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0

R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

~ Scan Proxy management in 00mn 00s

 

 

 

---\\ Changed inifile Value, Mapped to Registry (F2)

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,

F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

~ Scan Keys in 00mn 00s

 

 

 

---\\ Hosts file redirection (O1)

~ Le fichier hosts est sain (The hosts file is clean).

~ Scan Hosts File in 00mn 00s

~ Nombre de lignes (Lines number): 19

 

 

 

---\\ Browser Helper Objects (O2)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} . (.RealPlayer - RealPlayer Download and Record Plugin for I.) -- C:\Arquivos de programas\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Orphean Key

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corp. - Microsoft Search Helper Extention.) -- C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} . (.Microsoft Corporation - Microsoft SharePoint Workspace Extensions.) -- C:\Arquivos de programas\Microsoft Office\Office14\GROOVEEX.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Arquivos de programas\Microsoft Office\Office14\URLREDIR.dll

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

~ Scan BHO in 00mn 00s

 

 

 

---\\ Internet Explorer toolbars (O3)

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

~ Scan Toolbar in 00mn 00s

 

 

 

---\\ Auto loading programs from Registry and folders (O4)

O4 - HKLM\..\Run: [siSPower] . (.Silicon Integrated Systems Corporation - Dynamic link library for setting Power Sche.) -- C:\WINDOWS\system32\SiSPower.dll

O4 - HKLM\..\Run: [synTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [RTHDCPL] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- C:\WINDOWS\RTHDCPL.exe

O4 - HKLM\..\Run: [Alcmtr] . (.Realtek Semiconductor Corp. - Realtek Azalia Audio - Event Monitor.) -- C:\WINDOWS\Alcmtr.exe

O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

O4 - HKLM\..\Run: [NeroFilterCheck] . (.Nero AG - NeroCheck.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Arquivos de programas\AVAST Software\Avast\AvastUI.exe

O4 - HKLM\..\Run: [NielsenOnline] . (.The Nielsen Company - NielsenOnline.) -- C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenOnline.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] bthprops.cpl

O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

O4 - HKLM\..\Run: [PlusService] . (.Yuna Software - Messenger Plus! 5.) -- C:\Arquivos de programas\Yuna Software\Messenger Plus!\PlusService.exe

O4 - HKLM\..\Run: [ink Monitor] . (.Epson - Ink Monitor by Bill Pytlovany.) -- C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

O4 - HKLM\..\Run: [EPSON Stylus C45 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I4T1.exe

O4 - HKCU\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-21-57989841-1085031214-839522115-1003\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-21-57989841-1085031214-839522115-1003\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

~ Scan Application in 00mn 00s

 

 

 

---\\ Other User Links (O4)

O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk . (.Malwarebytes Corporation.) -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe

O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\MBRCheck.lnk . (...) -- C:\Arquivos de programas\ZHPDiag\mbrcheck.exe

O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Nero StartSmart Essentials.lnk . (.Nero AG.) -- C:\Arquivos de programas\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe

O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ZHPDiag.lnk . (.Nicolas Coolman.) -- C:\Arquivos de programas\ZHPDiag\ZHPDiag.exe

O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ZHPFix.lnk . (.Nicolas Coolman.) -- C:\Arquivos de programas\ZHPDiag\ZHPFix.exe

O4 - Global Startup: C:\Documents And Settings\Filho e karol\Desktop\DVD Flick.lnk . (.Dennis "Exl" Meuwissen.) -- C:\Arquivos de programas\DVD Flick\dvdflick.exe

O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk . (.Malwarebytes Corporation.) -- C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe

O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\MBRCheck.lnk . (...) -- C:\Arquivos de programas\ZHPDiag\mbrcheck.exe

O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Nero StartSmart Essentials.lnk . (.Nero AG.) -- C:\Arquivos de programas\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe

O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ZHPDiag.lnk . (.Nicolas Coolman.) -- C:\Arquivos de programas\ZHPDiag\ZHPDiag.exe

O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ZHPFix.lnk . (.Nicolas Coolman.) -- C:\Arquivos de programas\ZHPDiag\ZHPFix.exe

O4 - Global Startup: C:\Documents And Settings\Filho e karol\Desktop\DVD Flick.lnk . (.Dennis "Exl" Meuwissen.) -- C:\Arquivos de programas\DVD Flick\dvdflick.exe

~ Scan Global Startup in 00mn 00s

 

 

 

---\\ Extra items in the IE right-click menu (O8)

O8 - Extra context menu item: &Enviar para o OneNote . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll

O8 - Extra context menu item: E&xportar para o Microsoft Excel . (.Microsoft Corporation - Microsoft Excel.) -- C:\ARQUIV~1\MICROS~2\Office14\EXCEL.exe

~ Scan IE Menu Contextuel in 00mn 00s

 

 

 

---\\ Extra buttons on main IE button toolbar, or extra items in IE 'Tools' menu (O9)

O9 - Extra button: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\ARQUIV~1\MICROS~2\Office14\ONBttnIE.dll

O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\ARQUIV~1\MICROS~2\Office14\ONBTTN~1.dll

O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Arquivos de programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Arquivos de programas\Messenger\msmsgs.exe

~ Scan IE Extra Buttons in 00mn 00s

 

 

 

---\\ Winsock hijacker (Layered Service Provider) (O10)

O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fornecedor de serviços do Microsoft Windows Sockets 2.0.) -- C:\WINDOWS\system32\mswsock.dll

O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll

O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fornecedor de serviços do Microsoft Windows Sockets 2.0.) -- C:\WINDOWS\system32\mswsock.dll

O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\WINDOWS\system32\wshBth.dll

~ Scan Winsock in 00mn 00s

 

 

 

---\\ ActiveX Objects (Downloaded Program Files) (O16)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

~ Scan Objets ActiveX in 00mn 00s

 

 

 

---\\ Lop.com/Domain Hijackers (O17)

O17 - HKLM\System\CCS\Services\Tcpip\..\{129BC170-D18B-4D71-A3CE-166C42F67025}: DhcpNameServer = 192.168.254.254

O17 - HKLM\System\CCS\Services\Tcpip\..\{4F344BE1-A5C6-4A31-989C-28C50E04E85D}: DhcpNameServer = 200.222.145.86 200.149.55.142

O17 - HKLM\System\CS1\Services\Tcpip\..\{129BC170-D18B-4D71-A3CE-166C42F67025}: DhcpNameServer = 192.168.254.254

O17 - HKLM\System\CS1\Services\Tcpip\..\{4F344BE1-A5C6-4A31-989C-28C50E04E85D}: DhcpNameServer = 200.222.145.86 200.149.55.142

O17 - HKLM\System\CS3\Services\Tcpip\..\{129BC170-D18B-4D71-A3CE-166C42F67025}: DhcpNameServer = 192.168.254.254

O17 - HKLM\System\CS3\Services\Tcpip\..\{4F344BE1-A5C6-4A31-989C-28C50E04E85D}: DhcpNameServer = 200.222.145.86 200.149.55.142

~ Scan Domain in 00mn 00s

 

 

 

---\\ Extra protocols (O18)

O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll

O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Controle ActiveX para fluxo de vídeo.) -- C:\WINDOWS\system32\msvidctl.dll

O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll

O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll

O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll

O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll

O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API.) -- C:\WINDOWS\system32\inetcomm.dll

O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll

O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll

O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll

O18 - Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll

O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Controle ActiveX para fluxo de vídeo.) -- C:\WINDOWS\system32\msvidctl.dll

O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visualizador de HTML da Microsoft ®.) -- C:\WINDOWS\system32\mshtml.dll

O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll

O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Arquivos de programas\Windows Live\Mail\mailcomm.dll

O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll

O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll

O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll

O18 - Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensões OLE32 para Win32.) -- C:\WINDOWS\system32\urlmon.dll

O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\shell32.dll

O18 - Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE14\MSOXMLMF.dll

~ Scan Protocole Additionnel in 00mn 00s

 

 

 

---\\ AppInit_DLLs Registry value Autorun (O20)

O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll

O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll

O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agente de rede off-line.) -- C:\WINDOWS\system32\cscdll.dll

O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\system32\dimsntfy.dll

O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll

O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll

O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL de notificação do serviço de logon secu.) -- C:\WINDOWS\system32\sclgntfy.dll

O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\WlNotify.dll

O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll

O20 - Winlogon Notify: WgaLogon . (...) -- WgaLogon.dll

O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll

~ Scan Winlogon in 00mn 00s

 

 

 

---\\ ShellServiceObjectDelayLoad (O21)

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\SHELL32.dll

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\SHELL32.dll

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Monitor de sites da Web.) -- C:\WINDOWS\system32\webcheck.dll

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objeto de serviço do shell de Systray.) -- C:\WINDOWS\system32\stobject.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll

~ Scan SSODL in 00mn 00s

 

 

 

---\\ SharedTaskScheduler (O22)

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} . (.Microsoft Corporation - Biblioteca da interface de usuário do naveg.) -- C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Biblioteca da interface de usuário do naveg.) -- C:\WINDOWS\system32\browseui.dll

~ Scan STS/SSO in 00mn 00s

 

 

 

---\\ non Microsoft non disabled Windows XP/NT/2000 Services (O23)

O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe

O23 - Service: Google Update Service (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: Nielsen Update (NielsenUpdate) . (.The Nielsen Company - NielsenOnline.) - C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe

~ Scan Services in 00mn 00s

 

 

 

---\\ Windows Active Desktop & MHTML Editor (O24)

O24 - Desktop Component 0: Minha página inicial atual - file:About:Home

O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Word.) - C:\Arquivos de programas\Microsoft Office\Office14\WINWORD.exe

~ Scan Desktop Component in 00mn 00s

 

 

 

---\\

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

~ Scan Keys in 00mn 00s

 

 

 

---\\ Task Planned Automatically(039)

O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

[MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

~ Scan Scheduled Task in 00mn 01s

 

 

 

---\\ ActiveSetup Installed Components (O40)

O40 - ASIC: Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Utilitário de Instalação do Microsoft Windows Media Player.) -- C:\WINDOWS\inf\unregmp2.exe

O40 - ASIC: Microsoft NetShow Player - {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\system32\wmpdxm.dll

O40 - ASIC: Microsoft Windows Media Player 6.4 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\system32\wmpdxm.dll

O40 - ASIC: DirectAnimation - {283807B5-2C60-11D0-A31D-00AA00B92C03} . (.Microsoft Corporation - Mídia DirectX -- DirectAnimation.) -- C:\WINDOWS\system32\danim.dll

O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (...) -- C:\WINDOWS\INF\msnetmtg.inf

O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (...) -- C:\WINDOWS\INF\msmsgs.inf

O40 - ASIC: Recursos de navegação - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extensão shell da pasta FTP do Microsoft Internet Explorer.) -- C:\WINDOWS\system32\msieftp.dll

O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (...) -- C:\WINDOWS\INF\wmp11.inf

O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\WINDOWS\system32\mscories.dll

O40 - ASIC: Shockwave Flash - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 11.1 r102.) -- C:\WINDOWS\system32\Macromed\Flash\Flash11e.ocx

~ Scan Active Setup in 00mn 00s

 

 

 

---\\ Drivers launched at startup (O41)

O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys

O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\WINDOWS\system32\DRIVERS\cdrom.sys

O41 - Driver: (i8042prt) . (.Microsoft Corporation - Driver de porta i8042.) - C:\WINDOWS\system32\DRIVERS\i8042prt.sys

O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\WINDOWS\system32\DRIVERS\imapi.sys

O41 - Driver: (intelppm) . (.Microsoft Corporation - Driver de dispositivo de processador.) - C:\WINDOWS\system32\DRIVERS\intelppm.sys

O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\WINDOWS\system32\DRIVERS\ipsec.sys

O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Driver de classe teclado.) - C:\WINDOWS\system32\DRIVERS\kbdclass.sys

O41 - Driver: (Mouclass) . (.Microsoft Corporation - Driver de classe modem.) - C:\WINDOWS\system32\DRIVERS\mouclass.sys

O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\WINDOWS\system32\DRIVERS\netbios.sys

O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\WINDOWS\system32\DRIVERS\netbt.sys

O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\WINDOWS\system32\DRIVERS\rasacd.sys

O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\WINDOWS\system32\DRIVERS\rdbss.sys

O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

O41 - Driver: (redbook) . (.Microsoft Corporation - Redbook Audio Filter Driver.) - C:\WINDOWS\system32\DRIVERS\redbook.sys

O41 - Driver: (SiSkp) . (.Silicon Integrated Systems Corporation - SiS VGA Driver Manager.) - C:\WINDOWS\system32\DRIVERS\srvkp.sys

O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\WINDOWS\system32\DRIVERS\tcpip.sys

O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\WINDOWS\system32\DRIVERS\termdd.sys

O41 - Driver: Controlador de vídeo VGA. (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys

~ Scan Drivers in 00mn 00s

 

 

 

---\\ Software installed (O42)

O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX

O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin

O42 - Logiciel: Adobe Reader X (10.1.2) - Português - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1046-7B44-AA1000000001}

O42 - Logiciel: Arquivo do WinRAR - (.Unknown owner.) [HKLM] -- WinRAR archiver

O42 - Logiciel: Assistente de Conexão do Windows Live - (.Microsoft Corporation.) [HKLM] -- {51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}

O42 - Logiciel: Atualização de Segurança para Microsoft Windows (KB2564958) - (.Microsoft Corporation.) [HKLM] -- KB2564958

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2079403) - (.Microsoft Corporation.) [HKLM] -- KB2079403

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2115168) - (.Microsoft Corporation.) [HKLM] -- KB2115168

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2229593) - (.Microsoft Corporation.) [HKLM] -- KB2229593

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2296011) - (.Microsoft Corporation.) [HKLM] -- KB2296011

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2347290) - (.Microsoft Corporation.) [HKLM] -- KB2347290

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2387149) - (.Microsoft Corporation.) [HKLM] -- KB2387149

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2393802) - (.Microsoft Corporation.) [HKLM] -- KB2393802

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2412687) - (.Microsoft Corporation.) [HKLM] -- KB2412687

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2419632) - (.Microsoft Corporation.) [HKLM] -- KB2419632

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2440591) - (.Microsoft Corporation.) [HKLM] -- KB2440591

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2443105) - (.Microsoft Corporation.) [HKLM] -- KB2443105

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2476490) - (.Microsoft Corporation.) [HKLM] -- KB2476490

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2478960) - (.Microsoft Corporation.) [HKLM] -- KB2478960

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2478971) - (.Microsoft Corporation.) [HKLM] -- KB2478971

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2479943) - (.Microsoft Corporation.) [HKLM] -- KB2479943

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2481109) - (.Microsoft Corporation.) [HKLM] -- KB2481109

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2483185) - (.Microsoft Corporation.) [HKLM] -- KB2483185

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2485663) - (.Microsoft Corporation.) [HKLM] -- KB2485663

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2506212) - (.Microsoft Corporation.) [HKLM] -- KB2506212

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2507618) - (.Microsoft Corporation.) [HKLM] -- KB2507618

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2507938) - (.Microsoft Corporation.) [HKLM] -- KB2507938

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2508272) - (.Microsoft Corporation.) [HKLM] -- KB2508272

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2508429) - (.Microsoft Corporation.) [HKLM] -- KB2508429

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2509553) - (.Microsoft Corporation.) [HKLM] -- KB2509553

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2510581) - (.Microsoft Corporation.) [HKLM] -- KB2510581

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2535512) - (.Microsoft Corporation.) [HKLM] -- KB2535512

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2536276-v2) - (.Microsoft Corporation.) [HKLM] -- KB2536276-v2

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2544521) - (.Microsoft Corporation.) [HKLM] -- KB2544521

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2544893) - (.Microsoft Corporation.) [HKLM] -- KB2544893

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2544893-v2) - (.Microsoft Corporation.) [HKLM] -- KB2544893-v2

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2562937) - (.Microsoft Corporation.) [HKLM] -- KB2562937

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2567053) - (.Microsoft Corporation.) [HKLM] -- KB2567053

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2567680) - (.Microsoft Corporation.) [HKLM] -- KB2567680

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2570222) - (.Microsoft Corporation.) [HKLM] -- KB2570222

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2570947) - (.Microsoft Corporation.) [HKLM] -- KB2570947

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2584146) - (.Microsoft Corporation.) [HKLM] -- KB2584146

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2585542) - (.Microsoft Corporation.) [HKLM] -- KB2585542

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2586448) - (.Microsoft Corporation.) [HKLM] -- KB2586448

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2592799) - (.Microsoft Corporation.) [HKLM] -- KB2592799

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2598479) - (.Microsoft Corporation.) [HKLM] -- KB2598479

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2603381) - (.Microsoft Corporation.) [HKLM] -- KB2603381

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2618444) - (.Microsoft Corporation.) [HKLM] -- KB2618444

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2618451) - (.Microsoft Corporation.) [HKLM] -- KB2618451

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2619339) - (.Microsoft Corporation.) [HKLM] -- KB2619339

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2620712) - (.Microsoft Corporation.) [HKLM] -- KB2620712

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2624667) - (.Microsoft Corporation.) [HKLM] -- KB2624667

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2631813) - (.Microsoft Corporation.) [HKLM] -- KB2631813

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2633171) - (.Microsoft Corporation.) [HKLM] -- KB2633171

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2639417) - (.Microsoft Corporation.) [HKLM] -- KB2639417

O42 - Logiciel: Atualização de Segurança para Windows XP (KB2646524) - (.Microsoft Corporation.) [HKLM] -- KB2646524

O42 - Logiciel: Atualização de Segurança para Windows XP (KB923561) - (.Microsoft Corporation.) [HKLM] -- KB923561

O42 - Logiciel: Atualização de Segurança para Windows XP (KB923789) - (.Microsoft Corporation.) [HKLM] -- KB923789

O42 - Logiciel: Atualização de Segurança para Windows XP (KB941569) - (.Microsoft Corporation.) [HKLM] -- KB941569

O42 - Logiciel: Atualização de Segurança para Windows XP (KB946648) - (.Microsoft Corporation.) [HKLM] -- KB946648

O42 - Logiciel: Atualização de Segurança para Windows XP (KB950762) - (.Microsoft Corporation.) [HKLM] -- KB950762

O42 - Logiciel: Atualização de Segurança para Windows XP (KB950974) - (.Microsoft Corporation.) [HKLM] -- KB950974

O42 - Logiciel: Atualização de Segurança para Windows XP (KB951376-v2) - (.Microsoft Corporation.) [HKLM] -- KB951376-v2

O42 - Logiciel: Atualização de Segurança para Windows XP (KB952004) - (.Microsoft Corporation.) [HKLM] -- KB952004

O42 - Logiciel: Atualização de Segurança para Windows XP (KB952954) - (.Microsoft Corporation.) [HKLM] -- KB952954

O42 - Logiciel: Atualização de Segurança para Windows XP (KB954459) - (.Microsoft Corporation.) [HKLM] -- KB954459

O42 - Logiciel: Atualização de Segurança para Windows XP (KB956572) - (.Microsoft Corporation.) [HKLM] -- KB956572

O42 - Logiciel: Atualização de Segurança para Windows XP (KB956744) - (.Microsoft Corporation.) [HKLM] -- KB956744

O42 - Logiciel: Atualização de Segurança para Windows XP (KB956802) - (.Microsoft Corporation.) [HKLM] -- KB956802

O42 - Logiciel: Atualização de Segurança para Windows XP (KB956844) - (.Microsoft Corporation.) [HKLM] -- KB956844

O42 - Logiciel: Atualização de Segurança para Windows XP (KB958644) - (.Microsoft Corporation.) [HKLM] -- KB958644

O42 - Logiciel: Atualização de Segurança para Windows XP (KB959426) - (.Microsoft Corporation.) [HKLM] -- KB959426

O42 - Logiciel: Atualização de Segurança para Windows XP (KB960803) - (.Microsoft Corporation.) [HKLM] -- KB960803

O42 - Logiciel: Atualização de Segurança para Windows XP (KB960859) - (.Microsoft Corporation.) [HKLM] -- KB960859

O42 - Logiciel: Atualização de Segurança para Windows XP (KB961501) - (.Microsoft Corporation.) [HKLM] -- KB961501

O42 - Logiciel: Atualização de Segurança para Windows XP (KB969059) - (.Microsoft Corporation.) [HKLM] -- KB969059

O42 - Logiciel: Atualização de Segurança para Windows XP (KB971657) - (.Microsoft Corporation.) [HKLM] -- KB971657

O42 - Logiciel: Atualização de Segurança para Windows XP (KB972270) - (.Microsoft Corporation.) [HKLM] -- KB972270

O42 - Logiciel: Atualização de Segurança para Windows XP (KB973507) - (.Microsoft Corporation.) [HKLM] -- KB973507

O42 - Logiciel: Atualização de Segurança para Windows XP (KB973869) - (.Microsoft Corporation.) [HKLM] -- KB973869

O42 - Logiciel: Atualização de Segurança para Windows XP (KB973904) - (.Microsoft Corporation.) [HKLM] -- KB973904

O42 - Logiciel: Atualização de Segurança para Windows XP (KB974112) - (.Microsoft Corporation.) [HKLM] -- KB974112

O42 - Logiciel: Atualização de Segurança para Windows XP (KB974318) - (.Microsoft Corporation.) [HKLM] -- KB974318

O42 - Logiciel: Atualização de Segurança para Windows XP (KB974392) - (.Microsoft Corporation.) [HKLM] -- KB974392

O42 - Logiciel: Atualização de Segurança para Windows XP (KB974571) - (.Microsoft Corporation.) [HKLM] -- KB974571

O42 - Logiciel: Atualização de Segurança para Windows XP (KB975025) - (.Microsoft Corporation.) [HKLM] -- KB975025

O42 - Logiciel: Atualização de Segurança para Windows XP (KB975560) - (.Microsoft Corporation.) [HKLM] -- KB975560

O42 - Logiciel: Atualização de Segurança para Windows XP (KB975562) - (.Microsoft Corporation.) [HKLM] -- KB975562

O42 - Logiciel: Atualização de Segurança para Windows XP (KB975713) - (.Microsoft Corporation.) [HKLM] -- KB975713

O42 - Logiciel: Atualização de Segurança para Windows XP (KB977816) - (.Microsoft Corporation.) [HKLM] -- KB977816

O42 - Logiciel: Atualização de Segurança para Windows XP (KB977914) - (.Microsoft Corporation.) [HKLM] -- KB977914

O42 - Logiciel: Atualização de Segurança para Windows XP (KB978338) - (.Microsoft Corporation.) [HKLM] -- KB978338

O42 - Logiciel: Atualização de Segurança para Windows XP (KB978542) - (.Microsoft Corporation.) [HKLM] -- KB978542

O42 - Logiciel: Atualização de Segurança para Windows XP (KB978601) - (.Microsoft Corporation.) [HKLM] -- KB978601

O42 - Logiciel: Atualização de Segurança para Windows XP (KB978706) - (.Microsoft Corporation.) [HKLM] -- KB978706

O42 - Logiciel: Atualização de Segurança para Windows XP (KB979309) - (.Microsoft Corporation.) [HKLM] -- KB979309

O42 - Logiciel: Atualização de Segurança para Windows XP (KB979482) - (.Microsoft Corporation.) [HKLM] -- KB979482

O42 - Logiciel: Atualização de Segurança para Windows XP (KB979687) - (.Microsoft Corporation.) [HKLM] -- KB979687

O42 - Logiciel: Atualização de Segurança para Windows XP (KB980436) - (.Microsoft Corporation.) [HKLM] -- KB980436

O42 - Logiciel: Atualização de Segurança para Windows XP (KB981322) - (.Microsoft Corporation.) [HKLM] -- KB981322

O42 - Logiciel: Atualização de Segurança para Windows XP (KB981997) - (.Microsoft Corporation.) [HKLM] -- KB981997

O42 - Logiciel: Atualização de Segurança para Windows XP (KB982132) - (.Microsoft Corporation.) [HKLM] -- KB982132

O42 - Logiciel: Atualização de Segurança para Windows XP (KB982665) - (.Microsoft Corporation.) [HKLM] -- KB982665

O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB2378111) - (.Microsoft Corporation.) [HKLM] -- KB2378111_WM9

O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB952069) - (.Microsoft Corporation.) [HKLM] -- KB952069_WM9

O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB954155) - (.Microsoft Corporation.) [HKLM] -- KB954155_WM9

O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB973540) - (.Microsoft Corporation.) [HKLM] -- KB973540_WM9

O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB975558) - (.Microsoft Corporation.) [HKLM] -- KB975558_WM8

O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB978695) - (.Microsoft Corporation.) [HKLM] -- KB978695_WM9

O42 - Logiciel: Atualização de Segurança para o Windows Media Player 11 (KB954154) - (.Microsoft Corporation.) [HKLM] -- KB954154_WM11

O42 - Logiciel: Atualização para Windows XP (KB2541763) - (.Microsoft Corporation.) [HKLM] -- KB2541763

O42 - Logiciel: Atualização para Windows XP (KB2616676-v2) - (.Microsoft Corporation.) [HKLM] -- KB2616676-v2

O42 - Logiciel: Atualização para Windows XP (KB2641690) - (.Microsoft Corporation.) [HKLM] -- KB2641690

O42 - Logiciel: Atualização para Windows XP (KB898461) - (.Microsoft Corporation.) [HKLM] -- KB898461

O42 - Logiciel: Atualização para Windows XP (KB951978) - (.Microsoft Corporation.) [HKLM] -- KB951978

O42 - Logiciel: Atualização para Windows XP (KB955759) - (.Microsoft Corporation.) [HKLM] -- KB955759

O42 - Logiciel: Atualização para Windows XP (KB961503) - (.Microsoft Corporation.) [HKLM] -- KB961503

O42 - Logiciel: Atualização para Windows XP (KB971029) - (.Microsoft Corporation.) [HKLM] -- KB971029

O42 - Logiciel: Atualização para Windows XP (KB973687) - (.Microsoft Corporation.) [HKLM] -- KB973687

O42 - Logiciel: Atualização para Windows XP (KB973815) - (.Microsoft Corporation.) [HKLM] -- KB973815

O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner

O42 - Logiciel: DVD Flick 1.3.0.7 - (.Dennis Meuwissen.) [HKLM] -- DVD Flick_is1

O42 - Logiciel: Definition update for Microsoft Office 2010 (KB982726) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EFBA0F11-6CF9-4611-BFD4-648FA4EBE8C1}

O42 - Logiciel: DivX - (.DivXNetworks, Inc..) [HKLM] -- {7B63B2922B174135AFC0E1377DD81EC2}

O42 - Logiciel: DivX Player - (.DivXNetworks, Inc..) [HKLM] -- {8ADFC4160D694100B5B8A22DE9DCABD9}

O42 - Logiciel: Ferramenta de Carregamento do Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}

O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome

O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

O42 - Logiciel: High Definition Audio Driver Package - KB888111 - (.Microsoft Corporation.) [HKLM] -- KB888111WXPSP2

O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595

O42 - Logiciel: Hotfix for Windows Media Format 11 SDK (KB929399) - (.Microsoft Corporation.) [HKLM] -- KB929399

O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5

O42 - Logiciel: Hotfix para Windows XP (KB2570791) - (.Microsoft Corporation.) [HKLM] -- KB2570791

O42 - Logiciel: Hotfix para Windows XP (KB2633952) - (.Microsoft Corporation.) [HKLM] -- KB2633952

O42 - Logiciel: Hotfix para Windows XP (KB952287) - (.Microsoft Corporation.) [HKLM] -- KB952287

O42 - Logiciel: Hotfix para Windows XP (KB961118) - (.Microsoft Corporation.) [HKLM] -- KB961118

O42 - Logiciel: Hotfix para o Windows Media Player 11 (KB939683) - (.Microsoft Corporation.) [HKLM] -- KB939683

O42 - Logiciel: Ink Monitor - (.Unknown owner.) [HKLM] -- Ink Monitor

O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {8E5233E1-7495-44FB-8DEB-4BE906D59619}

O42 - Logiciel: L&H Power Translator Pro 7.0 - (.Unknown owner.) [HKLM] -- L&H Power Translator Pro 7.0

O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}

O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}

O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}

O42 - Logiciel: Malwarebytes Anti-Malware versão 1.60.1.1000 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1

O42 - Logiciel: Messenger Plus! 5 - (.Yuna Software.) [HKLM] -- Messenger Plus!

O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}

O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}

O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1

O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}

O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}

O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1

O42 - Logiciel: Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 - (.Microsoft Corporation.) [HKLM] -- Wdf01007

O42 - Logiciel: Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 - (.Microsoft Corporation.) [HKLM] -- Wdf01009

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0015-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0016-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0018-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0019-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-001A-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-001B-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-001F-0416-0000-0000000FF1CE}_Office14.PROPLUS_{A7200E61-DC93-42E0-BB74-EE59021016EA}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-002C-0416-0000-0000000FF1CE}_Office14.PROPLUS_{13291F79-D997-49AD-9F31-5FAEE1F0FCF5}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-0044-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-006E-0416-0000-0000000FF1CE}_Office14.PROPLUS_{2134F8C8-2AD8-44EE-B86B-1B577FBD8D0E}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-00A1-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}

O42 - Logiciel: Microsoft Office 2010 Service Pack 1 (SP1) - (.Microsoft.) [HKLM] -- {90140000-00BA-0416-0000-0000000FF1CE}_Office14.PROPLUS_{8E0FD78B-F726-43C8-8D53-44A7E495F3D2}

O42 - Logiciel: Microsoft Office Access MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0015-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0016-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00BA-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0044-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00A1-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001A-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0018-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Professional Plus 2010 - (.Microsoft Corporation.) [HKLM] -- Office14.PROPLUS

O42 - Logiciel: Microsoft Office Professional Plus 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proof (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0409-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proof (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proof (Spanish) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0C0A-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Proofing (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-002C-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0019-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-006E-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft Office Word MUI (Portuguese (Brazil)) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001B-0416-0000-0000000FF1CE}

O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}

O42 - Logiciel: Microsoft Search Enhancement Pack - (.Microsoft Corporation.) [HKLM] -- {9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}

O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}

O42 - Logiciel: Microsoft Sync Framework Runtime Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {8A74E887-8F0F-4017-AF53-CBA42211AAA5}

O42 - Logiciel: Microsoft Sync Framework Services Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {BD64AF4A-8C80-4152-AD77-FCDDF05208AB}

O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000

O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}

O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 - (.Microsoft Corporation.) [HKLM] -- {9BE518E6-ECC6-35A9-88E4-87755C07200F}

O42 - Logiciel: Mozilla Firefox 9.0.1 (x86 pt-BR) - (.Mozilla.) [HKLM] -- Mozilla Firefox 9.0.1 (x86 pt-BR)

O42 - Logiciel: Nero 7 Essentials - (.Nero AG.) [HKLM] -- {66EBD70F-A42C-475F-AEDF-277378151046}

O42 - Logiciel: Nielsen - (.Unknown owner.) [HKLM] -- NetSight

O42 - Logiciel: PowerDVD - (.Unknown owner.) [HKLM] -- {6811CAA0-BF12-11D4-9EA1-0050BAE317E1}

O42 - Logiciel: QuickTime Alternative 1.77 - (.Unknown owner.) [HKLM] -- QuicktimeAlt_is1

O42 - Logiciel: REALTEK USB Wireless LAN Driver - (.REALTEK Semiconductor Corp..) [HKLM] -- {7095FD27-37F0-4750-9DE8-D37DC0043706}

O42 - Logiciel: RealPlayer - (.RealNetworks.) [HKLM] -- RealPlayer 6.0

O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}

O42 - Logiciel: Realtek USB 2.0 Card Reader - (.Realtek Semiconductor Corp..) [HKLM] -- {DC24971E-1946-445D-8A82-CE685433FA7D}

O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2657424

O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2553091) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{07CA44F3-F5B3-4D12-8C91-EDC5FE91D45C}

O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2553096) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{10802A6D-EDBF-4383-BCBD-9D5B32F56D35}

O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2553353) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{02421C16-2C31-47F8-81FA-CF3B25999D31}

O42 - Logiciel: Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DCE6D0BF-93E4-46C5-9A7C-F1EFF9707C02}

O42 - Logiciel: Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{61461470-8168-4F4B-97B7-617AF354F028}

O42 - Logiciel: Security Update for Microsoft SharePoint Workspace 2010 (KB2566445) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{337A3FB9-281D-4EC8-9CC1-7F6DDAC2359F}

O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}

O42 - Logiciel: SiS VGA Utilities - (.Unknown owner.) [HKLM] -- SiS VGA Driver

O42 - Logiciel: SiSAGP driver - (.Unknown owner.) [HKLM] -- {DC226AC9-0314-496C-BE6A-B6A132628466}

O42 - Logiciel: Software para Impressoras EPSON - (.Unknown owner.) [HKLM] -- EPSON Printer and Utilities

O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM] -- SynTPDeinstKey

O42 - Logiciel: Unity Web Player - (.Unity Technologies ApS.) [HKCU] -- UnityWebPlayer

O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707

O42 - Logiciel: Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{3D1F379C-AA64-4823-90A4-A8DDD4B48C21}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2553065) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{A8686D24-1E89-43A1-973E-05A258D2B3F8}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2553092) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7AC49FC8-F8D2-4DD8-9086-09E52385A21F}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{48E1B6C2-7299-4F3F-AA63-42F0ACE55AA4}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{17E7B9AB-2DD2-457D-8D8E-CD14ACA973FE}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001F-0416-0000-0000000FF1CE}_Office14.PROPLUS_{ACBCC818-8E67-43A8-B877-A821A3C6FAD2}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{995A7832-B512-46D5-87C9-2D71FB541435}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{C8694FF0-8203-483B-A07A-2BC40433167D}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-006E-0416-0000-0000000FF1CE}_Office14.PROPLUS_{BDE8DD25-D017-443C-AD04-B4FC21489EFB}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{28FAC187-7C0E-413A-B90A-76F19D0FBF30}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2553455) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{147E3669-1EA6-454C-B53E-A2BE51D8E520}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2566458) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EFB525A0-E1C0-4E32-9968-FE401BC87363}

O42 - Logiciel: Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{ED31DE9A-3E13-4E2C-9106-E0D8AFFB9FA6}

O42 - Logiciel: Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BEBC2484-290C-46AD-9834-6DAD1FA80273}

O42 - Logiciel: Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-00A1-0416-0000-0000000FF1CE}_Office14.PROPLUS_{435C0D41-8F38-42CE-9DCB-23676CB6A6A1}

O42 - Logiciel: Update for Microsoft Outlook 2010 (KB2553323) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{29E94638-D92F-4C40-BDA1-FEDCC92F478D}

O42 - Logiciel: Update for Microsoft Outlook Social Connector (KB2583935) - (.Microsoft.) [HKLM] -- {90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{EDF9874C-9E37-4110-9FC3-094247E114DF}

O42 - Logiciel: Update for Microsoft Outlook Social Connector (KB2583935) - (.Microsoft.) [HKLM] -- {90140000-001A-0416-0000-0000000FF1CE}_Office14.PROPLUS_{4DA00DA4-FD2B-4FC2-B351-E712FC3EA458}

O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify

O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {590035D9-BFA0-406A-A7F0-479C72C0DDB2}

O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {3175E049-F9A9-4A3D-8F19-AC9FB04514D1}

O42 - Logiciel: Windows Live Essentials - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3

O42 - Logiciel: Windows Live Essentials - (.Microsoft Corporation.) [HKLM] -- {0FFEA8EE-7BC7-4C9D-8CC6-5B8C891BA3F2}

O42 - Logiciel: Windows Live Galeria de Fotos - (.Microsoft Corporation.) [HKLM] -- {87A9C015-C2BA-44EE-9C20-6E1A764B8E23}

O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {74AD1846-2010-4FB1-8E24-B6F2B87150C2}

O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {9ADC3E4F-34DA-48CD-8727-BB26D90257BD}

O42 - Logiciel: Windows Live Sync - (.Microsoft Corporation.) [HKLM] -- {2DF215E0-BD3C-4C98-8616-AFEF09747285}

O42 - Logiciel: Windows Live Toolbar - (.Microsoft Corporation.) [HKLM] -- {C50BF854-E881-434F-9C67-5A73EBB58F06}

O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {9555B4ED-09A3-4722-8E8C-57A49401D059}

O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11

O42 - Logiciel: Windows Media Format 11 runtime - (.Unknown owner.) [HKLM] -- Windows Media Format Runtime

O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM] -- wmp11

O42 - Logiciel: Windows Media Player 11 - (.Unknown owner.) [HKLM] -- Windows Media Player

O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM] -- Windows XP Service Pack

O42 - Logiciel: XP Codec Pack - (.Unknown owner.) [HKLM] -- XP Codec Pack

O42 - Logiciel: XviD 1.1 final uninstall - (.XviD team (Koepi).) [HKLM] -- XviD_is1

O42 - Logiciel: avast! Free Antivirus - (.AVAST Software.) [HKLM] -- avast

O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}

 

---\\ HKCU & HKLM Software Keys

[HKCU\Software\AC3Filter]

[HKCU\Software\AVAST Software]

[HKCU\Software\Adobe]

[HKCU\Software\Ahead]

[HKCU\Software\Audacity]

[HKCU\Software\Classes]

[HKCU\Software\Clients]

[HKCU\Software\Cyberlink]

[HKCU\Software\DivXNetworks]

[HKCU\Software\EPSON]

[HKCU\Software\GNU]

[HKCU\Software\Gabest]

[HKCU\Software\Google]

[HKCU\Software\IM Providers]

[HKCU\Software\Intel]

[HKCU\Software\L&H]

[HKCU\Software\Lake]

[HKCU\Software\Macromedia]

[HKCU\Software\Malwarebytes' Anti-Malware]

[HKCU\Software\MozillaPlugins]

[HKCU\Software\Mozilla]

[HKCU\Software\Netscape]

[HKCU\Software\ODBC]

[HKCU\Software\Piriform]

[HKCU\Software\Policies]

[HKCU\Software\RealNetworks]

[HKCU\Software\Realtek]

[HKCU\Software\RtWLan]

[HKCU\Software\Softonic]

[HKCU\Software\Synaptics]

[HKCU\Software\Unity]

[HKCU\Software\VB and VBA Program Settings]

[HKCU\Software\WinRAR SFX]

[HKCU\Software\WinRAR]

[HKCU\Software\Windows Live Writer]

[HKCU\Software\XP Codec Pack]

[HKCU\Software\Yuna Software]

[HKLM\Software\AVAST Software]

[HKLM\Software\Adobe]

[HKLM\Software\AdwCleaner]

[HKLM\Software\Ahead]

[HKLM\Software\Apple Computer, Inc.]

[HKLM\Software\Audible]

[HKLM\Software\C07ft5Y]

[HKLM\Software\Classes]

[HKLM\Software\Clients]

[HKLM\Software\CyberLink]

[HKLM\Software\DivXNetworks]

[HKLM\Software\EPSON]

[HKLM\Software\GNU]

[HKLM\Software\Gabest]

[HKLM\Software\Gemplus]

[HKLM\Software\Google]

[HKLM\Software\InstalledOptions]

[HKLM\Software\Intel]

[HKLM\Software\L&H Language Technology]

[HKLM\Software\L&H]

[HKLM\Software\Lake]

[HKLM\Software\Macromedia]

[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]

[HKLM\Software\Malwarebytes' Anti-Malware]

[HKLM\Software\MozillaPlugins]

[HKLM\Software\Mozilla]

[HKLM\Software\NSCPID]

[HKLM\Software\Nero]

[HKLM\Software\NetRatingsNetSight]

[HKLM\Software\ODBC]

[HKLM\Software\Piriform]

[HKLM\Software\Policies]

[HKLM\Software\Program Groups]

[HKLM\Software\QTAlternative]

[HKLM\Software\RealNetworks]

[HKLM\Software\Realtek Semiconductor Corp.]

[HKLM\Software\Realtek USB 2.0 Card Reader]

[HKLM\Software\Realtek]

[HKLM\Software\RegisteredApplications]

[HKLM\Software\RichFX]

[HKLM\Software\RtWLan]

[HKLM\Software\Schlumberger]

[HKLM\Software\Secure]

[HKLM\Software\Set8187B]

[HKLM\Software\SiS]

[HKLM\Software\Silicon Integrated Systems Corp.]

[HKLM\Software\Synaptics]

[HKLM\Software\TrendMicro]

[HKLM\Software\WinRAR]

[HKLM\Software\Windows 3.1 Migration Status]

[HKLM\Software\Xing Technology Corp.]

[HKLM\Software\Yuna Software]

[HKLM\Software\mozilla.org]

~ Scan Softwares in 00mn 01s

 

 

 

---\\ Contents of the Common Files folders (O43)

O43 - CFD: 17/1/2012 - 22:35:50 - [1,532] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Adobe

O43 - CFD: 10/12/2011 - 22:22:28 - [0,063] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Ahead

O43 - CFD: 19/1/2012 - 15:31:58 - [0,026] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Audacity

O43 - CFD: 19/11/2011 - 10:44:30 - [0,002] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\CyberLink

O43 - CFD: 13/12/2011 - 12:52:14 - [0,010] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\DVD Flick

O43 - CFD: 2/11/2011 - 14:26:16 - [0] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Identities

O43 - CFD: 2/11/2011 - 14:28:44 - [0] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\InstallShield

O43 - CFD: 2/11/2011 - 16:21:02 - [7,817] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Macromedia

O43 - CFD: 20/11/2011 - 00:01:48 - [0] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Malwarebytes

O43 - CFD: 17/1/2012 - 22:35:50 - [17,995] -S--D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Microsoft

O43 - CFD: 2/11/2011 - 14:57:42 - [19,853] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Mozilla

O43 - CFD: 2/11/2011 - 23:30:56 - [1,577] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Real

O43 - CFD: 5/12/2011 - 23:34:08 - [0] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\Windows Live Writer

O43 - CFD: 21/11/2011 - 19:35:06 - [0,000] ----D- C:\Documents and Settings\Filho e karol\Dados de aplicativos\WinRAR

O43 - CFD: 9/11/2011 - 17:57:08 - [14,194] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Adobe

O43 - CFD: 19/1/2012 - 15:56:10 - [8,841] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Ahead

O43 - CFD: 2/11/2011 - 16:00:06 - [24,287] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Google

O43 - CFD: 2/11/2011 - 16:27:14 - [0,508] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Identities

O43 - CFD: 5/2/2012 - 19:27:32 - [194,695] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Microsoft

O43 - CFD: 2/11/2011 - 15:01:58 - [0] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Microsoft Help

O43 - CFD: 2/11/2011 - 14:57:30 - [300,501] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Mozilla

O43 - CFD: 7/11/2011 - 06:38:50 - [0] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\PCHealth

O43 - CFD: 17/1/2012 - 22:35:50 - [0] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Temp

O43 - CFD: 25/1/2012 - 09:38:46 - [11,033] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Unity

O43 - CFD: 5/12/2011 - 23:34:18 - [0,620] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\Windows Live Writer

O43 - CFD: 19/1/2012 - 15:57:50 - [0] ----D- C:\Documents and Settings\Filho e karol\Configurações locais\Dados de aplicativos\WMTools Downloaded Files

~ Scan Program Folder in 00mn 16s

 

 

 

---\\ Last modified or created files under Windows and System32 (O44)

O44 - LFC:[MD5.C64209D282FC5F67AAEE6B5E34838CF5] - 13/1/2005 - 14:28:50 ---A- . (...) -- C:\WINDOWS\system32\PulseSoundTouchForVB.tlb [6832]

O44 - LFC:[MD5.5B9277B9DB672E59B94E81D6D8F98507] - 17/5/2005 - 14:37:10 ---A- . (...) -- C:\WINDOWS\system32\Faac.exe [76800]

O44 - LFC:[MD5.E6FD64139902D0B84C174EDCDBE50FB9] - 17/6/2008 - 22:42:48 ---A- . (...) -- C:\WINDOWS\system32\activesoundeditor.tlb [98708]

O44 - LFC:[MD5.97C1831B9D872F6EA5FA44013F045878] - 19/1/2012 - 14:38:35 ---A- . (.MultiMedia Soft - AdjMmsEng DLL.) -- C:\WINDOWS\system32\AdjMmsEng.dll [1343488]

O44 - LFC:[MD5.B3ECA5E1BDA96380F1D2741D82FE3161] - 19/7/2002 - 10:48:22 ---A- . (...) -- C:\WINDOWS\system32\OggEnc.exe [157696]

O44 - LFC:[MD5.7DE09AA2D6D215D55B09CBB3995F2249] - 23/1/2012 - 18:58:43 ---A- . (...) -- C:\WINDOWS\EPSMTL32.TXT [62]

O44 - LFC:[MD5.53C58B79608BAA3F312CF4CB980AAAEC] - 23/1/2012 - 19:01:34 ---A- . (.SEIKO EPSON CORPORATION - EBAPI SAgent4 control module.) -- C:\WINDOWS\system32\E_SAGSET.DLL [91648]

O44 - LFC:[MD5.287D9CFC80A94E62437E7CAC7EB32979] - 23/1/2012 - 19:01:34 ---A- . (.SEIKO EPSON CORPORATION - ECBTEG.) -- C:\WINDOWS\system32\ECBTEG.DLL [64000]

O44 - LFC:[MD5.2F615DBB76AB23885FCFBF0BD261B63D] - 23/1/2012 - 19:01:34 ---A- . (.SEIKO EPSON CORPORATION - EPSON Bi-directional Monitor.) -- C:\WINDOWS\system32\EBPMON24.DLL [76054]

O44 - LFC:[MD5.3670675EEA8136995287DFB1B7650A5D] - 23/1/2012 - 19:01:35 ---A- . (.SEIKO EPSON CORPORATION - EPSON Bidirectional Printer Driver.) -- C:\WINDOWS\system32\EBPCHP.DLL [34304]

O44 - LFC:[MD5.0FA14D47B02F83B2AE8E062BC052F3A1] - 23/1/2012 - 19:02:02 ---A- . (...) -- C:\WINDOWS\EPSC45.ini [66]

O44 - LFC:[MD5.DE1BBC132C4CD3BC888C23391EB9B6F4] - 3/2/2012 - 22:58:01 ---A- . (...) -- C:\AdwCleaner[R1].txt [15777]

O44 - LFC:[MD5.DF1CD0873CDD372A982C43C649B7CF3F] - 4/2/2012 - 07:22:48 ---A- . (...) -- C:\AdwCleaner[R2].txt [15837]

O44 - LFC:[MD5.93E4B4C54DC3391C9988592C5075B9F3] - 4/9/2001 - 07:04:00 ---A- . (...) -- C:\WINDOWS\system32\EBPPORT4.DAT [182]

O44 - LFC:[MD5.6B6BE3176D58A76DA4F335EDF5A75289] - 5/11/2005 - 17:34:50 ---A- . (...) -- C:\WINDOWS\system32\Lame.exe [145408]

O44 - LFC:[MD5.C7BC96C3711C0D269DA26D1F0ECEC547] - 5/2/2012 - 10:09:52 ---A- . (...) -- C:\WINDOWS\NeroDigital.ini [69]

O44 - LFC:[MD5.C860C14AD78CBA1FDFA522AA479DE48F] - 5/2/2012 - 18:32:42 ---A- . (...) -- C:\WINDOWS\setuplog.txt [58232]

O44 - LFC:[MD5.872312FCA646788B6FECC961FB142063] - 6/2/2012 - 13:02:24 ---A- . (...) -- C:\AdwCleaner[s1].txt [16360]

O44 - LFC:[MD5.D49C570A7965F89EDCC58D3E6E66A9E2] - 6/2/2012 - 13:38:25 ---A- . (...) -- C:\ToolbarShooterSUP.txt [371]

O44 - LFC:[MD5.77FA2588DA3E3612ADD5D76CEC0C886E] - 6/2/2012 - 13:39:02 ---A- . (...) -- C:\hijackthis.log [8471]

O44 - LFC:[MD5.8E6248733A459FEC71F0320DE4060F73] - 7/2/2012 - 08:17:42 ---A- . (...) -- C:\WINDOWS\system32\FNTCACHE.DAT [280536]

O44 - LFC:[MD5.2237D037AEF103C364407F8153689971] - 7/2/2012 - 15:45:54 ---A- . (...) -- C:\WINDOWS\setupapi.log [4160]

O44 - LFC:[MD5.EDD163C469DCD74AC84CF6CAADE22C29] - 8/2/2012 - 08:23:48 ---A- . (...) -- C:\WINDOWS\system32\wpa.dbl [2262]

O44 - LFC:[MD5.4BF4034C7EAA76470E3353E833B5FC2D] - 8/2/2012 - 16:58:08 ---A- . (...) -- C:\WINDOWS\SchedLgU.Txt [32574]

O44 - LFC:[MD5.FACC8686A1F458B7F32CE774266EC74A] - 8/2/2012 - 16:58:11 ---A- . (...) -- C:\WINDOWS\WindowsUpdate.log [1226777]

O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 8/2/2012 - 17:34:37 -S-A- . (...) -- C:\WINDOWS\bootstat.dat [2048]

O44 - LFC:[MD5.0C398AF83BEE23B9C529369163BDE66F] - 8/2/2012 - 17:34:59 ---A- . (...) -- C:\RTHDCPL_Dump.txt [558]

O44 - LFC:[MD5.AE04D54D548E897F8298B38E891201D4] - 8/2/2012 - 17:35:03 ---A- . (...) -- C:\WINDOWS\wiaservc.log [48]

O44 - LFC:[MD5.ACAF83EAF237EE40B7B5FDE61C8A388C] - 8/2/2012 - 17:35:04 ---A- . (...) -- C:\WINDOWS\wiadebug.log [159]

O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 8/2/2012 - 17:35:05 ---A- . (...) -- C:\WINDOWS\0.log [0]

~ Scan Files in 00mn 04s

 

 

 

---\\ Export authorized application key (O47)

O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gerenciador de sessão de ajuda de área de trabalho remota da Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe

O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.EXE" [Enabled] .(.Microsoft Corporation - Microsoft SharePoint Workspace.) -- C:\Arquivos de programas\Microsoft Office\Office14\GROOVE.exe

O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Microsoft Office\Office14\ONENOTE.EXE" [Enabled] .(.Microsoft Corporation - Microsoft OneNote.) -- C:\Arquivos de programas\Microsoft Office\Office14\ONENOTE.exe

O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Microsoft Office\Office14\OUTLOOK.EXE" [Enabled] .(.Microsoft Corporation - Microsoft Outlook.) -- C:\Arquivos de programas\Microsoft Office\Office14\OUTLOOK.exe

O47 - AAKE:Key Export SP - "C:\Documents and Settings\Filho e karol\Configurações locais\Temp\196.tmp\KMService.exe" [Enabled] .(...) -- C:\Documents and Settings\Filho e karol\Configurações locais\Temp\196.tmp\KMService.exe (.not file.)

O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe

O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Microsoft Corporation - Windows Live Sync.) -- C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe

O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gerenciador de sessão de ajuda de área de trabalho remota da Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe

O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O47 - AAKE:Key Export DP - "C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe

O47 - AAKE:Key Export DP - "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

O47 - AAKE:Key Export DP - "C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Microsoft Corporation - Windows Live Sync.) -- C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe

~ Scan Keys in 00mn 00s

 

 

 

---\\ Local Security Authority-LSA Deny (O48)

O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll

O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Mecanismo cliente do 'Editor de configuração de segurança Windows'.) -- C:\WINDOWS\system32\scecli.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Kerberos Security Package.) -- C:\WINDOWS\system32\kerberos.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\WINDOWS\system32\wdigest.dll

~ Scan Keys in 00mn 00s

 

 

 

---\\ Safe Boot Control (O49)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmboot.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmboot.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmio.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager I/O Driver.) -- C:\WINDOWS\system32\Drivers\dmio.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sr.sys . (.Microsoft Corporation - Driver de filtro do sistema de arquivos da restauração do sistema.) -- C:\WINDOWS\system32\Drivers\sr.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\Wdf01000.sys . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) -- C:\WINDOWS\system32\Drivers\Wdf01000.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmboot.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmboot.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmio.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager I/O Driver.) -- C:\WINDOWS\system32\Drivers\dmio.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ip6fw.sys . (.Microsoft Corporation - IPv6 Windows Firewall Driver.) -- C:\WINDOWS\system32\Drivers\ip6fw.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\system32\Drivers\ipnat.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpcdd.sys . (.Microsoft Corporation - RDP Miniport.) -- C:\WINDOWS\system32\Drivers\rdpcdd.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpdd.sys . (...) -- C:\WINDOWS\system32\Drivers\rdpdd.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpwd.sys . (.Microsoft Corporation - RDP Terminal Stack Driver (US/Canada Only, Not for Export).) -- C:\WINDOWS\system32\Drivers\rdpwd.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sr.sys . (.Microsoft Corporation - Driver de filtro do sistema de arquivos da restauração do sistema.) -- C:\WINDOWS\system32\Drivers\sr.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdpipe.sys . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdpipe.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdtcp.sys . (.Microsoft Corporation - TCP Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdtcp.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\Wdf01000.sys . (.Microsoft Corporation - Kernel Mode Driver Framework Runtime.) -- C:\WINDOWS\system32\Drivers\Wdf01000.sys

~ Scan CSB in 00mn 00s

 

 

 

---\\ Image File Execution Options (IFEO) (O50)

O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d

~ Scan IFEO in 00mn 00s

 

 

 

---\\ MountPoints2 Shell Key (MPKS) (O51) (None)

 

---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)

O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec de áudio DSP Group TrueSpeech para MSACM V3.50.) -- C:\WINDOWS\system32\tssoft32.acm

O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\system32\iccvid.dll

O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll

O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll

O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\WINDOWS\system32\ir41_32.ax

O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm

O52 - TDSD: \Drivers32\"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax

O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\WINDOWS\system32\ir50_32.dll

O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm

O52 - TDSD: \Drivers32\"vidc.DIVX"="DivX.dll" . (.DivXNetworks, Inc. - DivX® Codec for Windows.) -- C:\WINDOWS\system32\DivX.dll

O52 - TDSD: \Drivers32\"vidc.ffds"="ffdshow.ax" . (.Unknown owner - DirectShow and VFW video and audio decoding/encoding/processing filter.) -- C:\WINDOWS\system32\ffdshow.ax

O52 - TDSD: \Drivers32\"vidc.XVID"="xvidvfw.dll" . (...) -- C:\WINDOWS\system32\xvidvfw.dll

O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm

O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax

O52 - TDSD: \drivers.desc\"ir50_32.dll"="Indeo® video 5.10" . (...) -- (.not file.)

O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm

O52 - TDSD: \drivers.desc\"DivX.dll"="DivX 5.2.1 Codec" . (...) -- (.not file.)

O52 - TDSD: \drivers.desc\"xvidvfw.dll"="XviD MPEG-4 Video Codec" . (...) -- C:\WINDOWS\system32\xvidvfw.dll

~ Scan Keys in 00mn 00s

 

 

 

---\\ ShareTools MSconfig StartupReg (SMSR) (O53) (None)

 

---\\ Microsoft Control Security Providers (MCSP) (O54)

O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Cliente DPA para plataformas de 32 bits.) -- C:\WINDOWS\system32\msapsspc.dll

O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll

O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Digest SSPI Authentication Package.) -- C:\WINDOWS\system32\digest.dll

O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Cliente DPA para plataformas de 32 bits.) -- C:\WINDOWS\system32\msapsspc.dll

O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll

O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Digest SSPI Authentication Package.) -- C:\WINDOWS\system32\digest.dll

~ Scan Keys in 00mn 00s

 

 

 

---\\ Microsoft Windows Policies System (MWPS) (O55)

O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=

O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1

~ Scan Keys in 00mn 00s

 

 

 

---\\ Microsoft Windows Policies Explorer (MWPE) (O56)

O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145

~ Scan Keys in 00mn 00s

 

 

 

---\\ System Drivers List (SDL) (O58)

O58 - SDL:[MD5.B6DE0336F9F4B687B4FF57939F7B657A] - 28/11/2011 - 14:48:49 ---A- . (.AVAST Software - avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP.) -- C:\WINDOWS\system32\drivers\aavmker4.sys [30808]

O58 - SDL:[MD5.054DF24C92B55427E0757CFFF160E4F2] - 28/11/2011 - 14:51:50 ---A- . (.AVAST Software - avast! File System Access Blocking Driver.) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys [20568]

O58 - SDL:[MD5.05A9CF1C69B553260C4927E33F0BF3EC] - 28/11/2011 - 14:51:59 ---A- . (.AVAST Software - avast! File System Filter Driver for Windows NT/2000.) -- C:\WINDOWS\system32\drivers\aswmon.sys [105176]

O58 - SDL:[MD5.EF0E9AD83380724BD6FBBB51D2D0F5B8] - 28/11/2011 - 14:52:02 ---A- . (.AVAST Software - avast! File System Filter Driver for Windows XP.) -- C:\WINDOWS\system32\drivers\aswmon2.sys [111320]

O58 - SDL:[MD5.352D5A48EBAB35A7693B048679304831] - 28/11/2011 - 14:52:19 ---A- . (.AVAST Software - avast! TDI RDR Driver.) -- C:\WINDOWS\system32\drivers\aswRdr.sys [34392]

O58 - SDL:[MD5.8D34D2B24297E27D93E847319ABFDEC4] - 28/11/2011 - 14:53:53 ---A- . (.AVAST Software - avast! Virtualization Driver.) -- C:\WINDOWS\system32\drivers\aswSnx.sys [435032]

O58 - SDL:[MD5.010012597333DA1F46C3243F33F8409E] - 28/11/2011 - 14:53:35 ---A- . (.AVAST Software - avast! self protection module.) -- C:\WINDOWS\system32\drivers\aswSP.sys [314456]

O58 - SDL:[MD5.F9F84364416658E9786235904D448D37] - 28/11/2011 - 14:52:16 ---A- . (.AVAST Software - avast! TDI Filter Driver.) -- C:\WINDOWS\system32\drivers\aswTdi.sys [52952]

O58 - SDL:[MD5.B0A67DE1A128389AEA4D42C5A56215FD] - 17/8/2011 - 08:56:22 ---A- . (.Nokia - Nokia USB Phone Bus Driver.) -- C:\WINDOWS\system32\drivers\ccdcmb.sys [18176]

O58 - SDL:[MD5.DA6675E1400D58412C93180F8651A9FB] - 11/1/2000 - 19:38:34 ---A- . (.RAVISENT Technologies Inc. - CineMaster C 1.2 WDM Main Driver.) -- C:\WINDOWS\system32\drivers\cinemst2.sys [262528]

O58 - SDL:[MD5.9624293E55AD405415862B504CA95B73] - 11/1/2000 - 19:38:34 ---A- . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINDOWS\system32\drivers\cpqdap01.sys [11776]

O58 - SDL:[MD5.D59657714E1C85A6584663970C052CB6] - 4/10/2010 - 16:57:16 ---A- . (.The Nielsen Company - Audio Filter Driver.) -- C:\WINDOWS\system32\drivers\km_filter.sys [10368]

O58 - SDL:[MD5.B7CA8CC3F978201856B6AB82F40953C3] - 10/12/2011 - 14:24:06 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\system32\drivers\mbam.sys [20464]

O58 - SDL:[MD5.BE984D604D91C217355CDD3737AAD25D] - 11/1/2000 - 19:38:34 ---A- . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINDOWS\system32\drivers\nikedrv.sys [12032]

O58 - SDL:[MD5.66F6952248ECE6B791629BA6C1FF7568] - 4/10/2010 - 16:57:20 ---A- . (.The Nielsen Company - NNRNSTDI helper driver.) -- C:\WINDOWS\system32\drivers\nnrnstdi.sys [15360]

O58 - SDL:[MD5.80D317BD1C3DBC5D4FE7B1678C60CADD] - 11/1/2000 - 19:38:34 ---A- . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Library.) -- C:\WINDOWS\system32\drivers\ptilink.sys [17792]

O58 - SDL:[MD5.A56FE08EC7473E8580A390BB1081CDD7] - 11/1/2000 - 19:38:34 ---A- . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINDOWS\system32\drivers\rio8drv.sys [12032]

O58 - SDL:[MD5.0A854DF84C77A0BE205BFEAB2AE4F0EC] - 11/1/2000 - 19:38:34 ---A- . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINDOWS\system32\drivers\riodrv.sys [12032]

O58 - SDL:[MD5.811B31E0E0AC7BE484EFBFFC42AFCBBE] - 20/12/2007 - 17:00:06 R---- . (.Realtek Semiconductor Corp. - Realtek® High Definition Audio Function Driver.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys [4637696]

O58 - SDL:[MD5.1C507A537140FA2E1FC6AB832901EC04] - 1/6/2007 - 02:06:42 R---- . (.Realtek Semiconductor Corporation - Realtek RTL8187B NDIS Driver.) -- C:\WINDOWS\system32\drivers\rtl8187B.sys [238976]

O58 - SDL:[MD5.362CB1D7498216F7B2686FDC5BBBA58C] - 18/9/2007 - 14:08:22 ---A- . (.Realtek Semiconductor Corp. - Realtek USB Mass Storage Driver for 2K/XP.) -- C:\WINDOWS\system32\drivers\RTSTOR.sys [44032]

O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 13/4/2008 - 08:39:18 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\WINDOWS\system32\drivers\secdrv.sys [20480]

O58 - SDL:[MD5.37DAA9F59A3FF30A314FD98EE8F47000] - 20/12/2006 - 01:00:00 R--A- . (.Silicon Integrated Systems Corp. - NDIS 5.1 Miniport Driver for SiS191/SiS190 Ethernet Device.) -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys [41600]

O58 - SDL:[MD5.DFF19DFD9AC111C7C68162CAAE96A203] - 25/6/2007 - 05:49:08 R--A- . (.Silicon Integrated Systems Corporation - SiS Compatible Super VGA Driver.) -- C:\WINDOWS\system32\drivers\sisgrp.sys [321536]

O58 - SDL:[MD5.6FAF3014EE1CC1A5146A5D2B29F94B8C] - 25/6/2007 - 06:10:28 R--A- . (.Silicon Integrated Systems Corporation - SiS VGA Driver Manager.) -- C:\WINDOWS\system32\drivers\srvkp.sys [18432]

O58 - SDL:[MD5.9D7385AD343EEED23A61D4AC5AE44601] - 25/8/2005 - 12:12:56 ---A- . (.Synaptics, Inc. - Synaptics Touchpad Driver.) -- C:\WINDOWS\system32\drivers\SynTP.sys [191168]

O58 - SDL:[MD5.D74A8EC75305F1D3CFDE7C7FC1BD62A9] - 11/1/2000 - 19:38:34 ---A- . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINDOWS\system32\drivers\tsbvcap.sys [21376]

O58 - SDL:[MD5.55E01061C74A8CEFFF58DC36114A8D3F] - 11/1/2000 - 19:38:34 ---A- . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\system32\drivers\vdmindvd.sys [58112]

O58 - SDL:[MD5.C1E76718BAB6BCA0D18E5670F074F821] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ansi.sys [9032]

O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\country.sys [27097]

O58 - SDL:[MD5.912150FE88E79AFEE0BB72216FAB2617] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\himem.sys [4896]

O58 - SDL:[MD5.582BCDD47CF4B68B5CB528F18E3CB808] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\key01.sys [42809]

O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 3/8/2004 - 22:46:56 ---A- . (...) -- C:\WINDOWS\system32\keyboard.sys [42537]

O58 - SDL:[MD5.19D4F0DAD3F393C13DE7F849ADE72EFE] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ntdos.sys [27900]

O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ntdos404.sys [29146]

O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ntdos411.sys [29370]

O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ntdos412.sys [29274]

O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 11/1/2000 - 19:38:34 ---A- . (...) -- C:\WINDOWS\system32\ntdos804.sys [29146]

O58 - SDL:[MD5.86BB7AF2533B342B8E274590AD2190FA] - 3/8/2004 - 22:45:20 ---A- . (...) -- C:\WINDOWS\system32\ntio.sys [33984]

O58 - SDL:[MD5.6F73F50162DEF60C84B725C18CD9140F] - 3/8/2004 - 22:45:16 ---A- . (...) -- C:\WINDOWS\system32\ntio404.sys [34560]

O58 - SDL:[MD5.0FDD5E69C1FF3B58043D44F2CC743D45] - 3/8/2004 - 22:45:12 ---A- . (...) -- C:\WINDOWS\system32\ntio411.sys [35648]

O58 - SDL:[MD5.8842837C4D8311BF8E72BEE8CCC42217] - 3/8/2004 - 22:45:16 ---A- . (...) -- C:\WINDOWS\system32\ntio412.sys [35424]

O58 - SDL:[MD5.6B56CEB3C6F9D5CD7293DBD9FE23B311] - 3/8/2004 - 22:45:14 ---A- . (...) -- C:\WINDOWS\system32\ntio804.sys [34560]

~ Scan Drivers in 00mn 03s

 

 

 

---\\ List all tools cleaner (LATC) (O63)

O63 - Logiciel: ZHPDiag 1.28 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1

O63 - Logiciel: OTL - (.OldTimer.)

~ Scan ADS in 00mn 00s

 

 

 

---\\ List all legacy services(LALS) (O64)

O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\Aavmker4.sys (Aavmker4) .(.AVAST Software - avast! Base Kernel-Mode Device Driver for W.) - LEGACY_AAVMKER4

O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswFsBlk.sys (aswFsBlk) .(.AVAST Software - avast! File System Access Blocking Driver.) - LEGACY_ASWFSBLK

O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswMon2.sys (aswMon2) .(.AVAST Software - avast! File System Filter Driver for Window.) - LEGACY_ASWMON2

O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswRdr.sys (aswRdr) .(.AVAST Software - avast! TDI RDR Driver.) - LEGACY_ASWRDR

O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswSnx.sys (aswSnx) .(.AVAST Software - avast! Virtualization Driver.) - LEGACY_ASWSNX

O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswSP.sys (aswSP) .(.AVAST Software - avast! self protection module.) - LEGACY_ASWSP

O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\aswTdi.sys (aswTdi) .(.AVAST Software - avast! TDI Filter Driver.) - LEGACY_ASWTDI

O64 - Services: CurCS - 28/11/2011 - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe (avast! Antivirus) .(.AVAST Software - avast! Service.) - LEGACY_AVAST!_ANTIVIRUS

O64 - Services: CurCS - ??\??\???? - (DcomLaunch) .(. - .) - LEGACY_DCOMLAUNCH

O64 - Services: CurCS - 13/4/2008 - C:\WINDOWS\system32\drivers\dmboot.sys (dmboot) .(.Microsoft Corp., Veritas Software - NT Disk Manager Startup Driver.) - LEGACY_DMBOOT

O64 - Services: CurCS - 11/1/2000 - C:\WINDOWS\system32\drivers\dmload.sys (dmload) .(.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) - LEGACY_DMLOAD

O64 - Services: CurCS - 2/11/2011 - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe (gupdate) .(.Google Inc. - Google Installer.) - LEGACY_GUPDATE

O64 - Services: CurCS - 10/12/2011 - C:\WINDOWS\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) - LEGACY_MBAMPROTECTOR

O64 - Services: CurCS - 13/1/2012 - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe (MBAMService) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMSERVICE

O64 - Services: CurCS - 3/5/2011 - C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe (NielsenUpdate) .(.The Nielsen Company - NielsenOnline.) - LEGACY_NIELSENUPDATE

O64 - Services: CurCS - 1/6/2007 - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (NMIndexingService) .(.Nero AG - Nero Home.) - LEGACY_NMINDEXINGSERVICE

O64 - Services: CurCS - ??\??\???? - C:\WINDOWS\system32\Drivers\nnrnstdi.sys (nnrnstdi) .(.The Nielsen Company - NNRNSTDI helper driver.) - LEGACY_NNRNSTDI

O64 - Services: CurCS - ??\??\???? - (RpcSs) .(. - .) - LEGACY_RPCSS

O64 - Services: CurCS - 14/1/2009 - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (SeaPort) .(.Microsoft Corp. - Microsoft SeaPort Search Enhancement Broker.) - LEGACY_SEAPORT

O64 - Services: CurCS - ??\??\???? - (TermService) .(. - .) - LEGACY_TERMSERVICE

~ Scan Services in 00mn 01s

 

 

 

---\\ File Associations Shell Spawning (O67)

O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\shell32.dll

O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Arquivos de programas\Internet Explorer\iexplore.exe

O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\WINDOWS\regedit.exe

O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe

O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\shell32.dll

O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe

O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\WINDOWS\regedit.exe

~ Scan Keys in 00mn 00s

 

 

 

---\\ Start Menu Internet (SMI) (O68)

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.exe (.not file.)

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

~ Scan Keys in 00mn 00s

 

 

 

---\\ Search Svchost Services (SSS) (O83)

O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Serviço de instalação do software.) -- C:\WINDOWS\system32\appmgmts.dll [172032]

O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\system32\audiosrv.dll [42496]

O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\system32\browser.dll [77824]

O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINDOWS\system32\cryptsvc.dll [62464]

O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - Dll do serviço do Gerenciador de discos lógicos.) -- C:\WINDOWS\system32\dmserver.dll [23552]

O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - Serviço do Cliente DHCP.) -- C:\WINDOWS\system32\dhcpcsvc.dll [126976]

O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINDOWS\system32\ersvc.dll [23040]

O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - No comment.) -- C:\WINDOWS\system32\es.dll [253952]

O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\WINDOWS\system32\shsvcs.dll [135168]

O83 - Search Svchost Services: HidServ (HidServ) . (...) -- C:\WINDOWS\system32\hidserv.dll [0]

O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [96768]

O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINDOWS\system32\wkssvc.dll [132096]

O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINDOWS\system32\msgsvc.dll [33792]

O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Gerenciador de conexões de rede.) -- C:\WINDOWS\system32\netman.dll [198144]

O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Fornecedor de serviços do Microsoft Windows Sockets 2.0.) -- C:\WINDOWS\system32\mswsock.dll [247808]

O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Gerenciador de armazenamento removível.) -- C:\WINDOWS\system32\ntmssvc.dll [437248]

O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\system32\rasauto.dll [88576]

O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\system32\rasmans.dll [186368]

O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\system32\mprdim.dll [53248]

O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Mecanismo do 'Agendador de tarefas'.) -- C:\WINDOWS\system32\schedsvc.dll [193536]

O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL de serviço de logon secundário.) -- C:\WINDOWS\system32\seclogon.dll [18944]

O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\system32\sens.dll [39424]

O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\WINDOWS\system32\ipnathlp.dll [331264]

O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Serviço de restauração do sistema.) -- C:\WINDOWS\system32\srsvc.dll [171520]

O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia do Microsoft® Windows.) -- C:\WINDOWS\system32\tapisrv.dll [249856]

O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\WINDOWS\system32\shsvcs.dll [135168]

O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINDOWS\system32\trkwks.dll [90112]

O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Windows Time Service.) -- C:\WINDOWS\system32\w32time.dll [176128]

O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Serviço de configuração zero sem fio.) -- C:\WINDOWS\system32\wzcsvc.dll [483840]

O83 - Search Svchost Services: Wmi (Wmi) . (.Microsoft Corporation - API de base do Windows 32 avançada.) -- C:\WINDOWS\system32\advapi32.dll [683520]

O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [145408]

O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINDOWS\system32\wscsvc.dll [80896]

O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINDOWS\system32\xmlprov.dll [129024]

O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de plano de fundo.) -- C:\WINDOWS\system32\qmgr.dll [409088]

O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINDOWS\system32\wuauserv.dll [6656]

O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\WINDOWS\system32\shsvcs.dll [135168]

O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400]

O83 - Search Svchost Services: WmdmPmSN (WmdmPmSN) . (.Microsoft Corporation - Microsoft Media Device Service Provider.) -- C:\WINDOWS\system32\mspmsnsv.dll [27136]

O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Tempo de Execução de Serviço de Agente de Quarentena.) -- C:\WINDOWS\system32\qagentrt.dll [292864]

O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Serviço de Gerenciamento de Chaves.) -- C:\WINDOWS\system32\kmsvc.dll [61440]

~ Scan Services in 00mn 00s

 

 

 

---\\ Search Particular Root Folder (SPRF) (O84)

[MD5.E7B562231BE0C5617F1516EC6DA16782] [sPRF][3/2/2012] (...) -- C:\Documents and Settings\Filho e karol\Desktop\adwcleaner.exe [578643]

[MD5.3270CB86F79B3E23720BAFC2E48BE3BE] [sPRF][3/2/2012] (.OldTimer Tools - No comment.) -- C:\Documents and Settings\Filho e karol\Desktop\OTL.exe [584192]

[MD5.ABD6ADAC98B1BE9DFED93F290B6CC105] [sPRF][15/11/2009] (...) -- C:\Documents and Settings\Filho e karol\Desktop\Temp.bat [359]

[MD5.A37E08226423BBD4994FE7C66DDF0C9D] [sPRF][6/2/2012] (...) -- C:\Documents and Settings\Filho e karol\Desktop\ToolbarShooter.exe [227328]

~ Scan Files in 00mn 00s

 

 

 

---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped)

SR - | Auto 28/11/2011 44768 | (avast! Antivirus) . (.AVAST Software.) - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe

SS - | Demand 13/4/2008 225280 | (dmadmin) . (.Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\dmadmin.exe

SS - | Auto 2/11/2011 136176 | (gupdate) . (.Google Inc..) - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

SS - | Demand 2/11/2011 136176 | (gupdatem) . (.Google Inc..) - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

SR - | Auto 13/1/2012 652360 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe

SS - | Demand 13/4/2007 792112 | (NBService) . (.Nero AG.) - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

SR - | Auto 3/5/2011 306496 | (NielsenUpdate) . (.The Nielsen Company.) - C:\Arquivos de programas\NetRatingsNetSight\NetSight\NielsenUpdate.exe

SR - | Demand 1/6/2007 271920 | (NMIndexingService) . (.Nero AG.) - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

~ Scan Services in 00mn 09s

 

 

 

End of the scan (1151 lines in 00mn 52s)(0)

 

 

Abraços... :grin:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! karoline ferreira

 

|- Desculpe-me,pois não reparei o canned repetido e apliquei procedimentos inócuos.

|- Seu caso está praticamente resolvido!

 

///°°°///

 

|- Baixe: < imagemus0.jpg > (...par A.Rothstein & dj Quiou )

 

|- Clique em "Télécharger",para o download.

|- Salve-o no desktop!

|- Feche programas que estejam abertos,e execute a ferramenta.

|- Clique no botão Recherche,para iniciar o scan.

|- Ao concluir,teremos relacionados as ferramentas que serão removidas.

|- Clique,à seguir,no botão "Supression" para remover os itens encontrados.

|- Clique em Quitter para sair! --> OK.

|- Caso queira,poste os relatórios: Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU)

|- Selecione e copie para o Bloco de Notas.

|- Seu computador está limpo!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! karoline ferreira

 

|- Desculpe-me,pois não reparei o canned repetido e apliquei procedimentos inócuos.

|- Seu caso está praticamente resolvido!

 

///°°°///

 

|- Baixe: < imagemus0.jpg > (...par A.Rothstein & dj Quiou )

 

|- Clique em "Télécharger",para o download.

|- Salve-o no desktop!

|- Feche programas que estejam abertos,e execute a ferramenta.

|- Clique no botão Recherche,para iniciar o scan.

|- Ao concluir,teremos relacionados as ferramentas que serão removidas.

|- Clique,à seguir,no botão "Supression" para remover os itens encontrados.

|- Clique em Quitter para sair! --> OK.

|- Caso queira,poste os relatórios: Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU)

|- Selecione e copie para o Bloco de Notas.

|- Seu computador está limpo!

 

Abraços!

 

 

Olá!! 'DigRam'.

Eu nem cheguei a olhar o esse poste antes de você postar,obrigada por tudo.

 

 

[ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

 

--> Recherche:

 

C:\HijackThis.exe: trouvé !

C:\hijackthis.log: trouvé !

C:\Arquivos de programas\ZHPDiag: trouvé !

C:\Arquivos de programas\ZHPDiag\ZHPdiag.exe: trouvé !

C:\Arquivos de programas\ZHPDiag\catchme.exe: trouvé !

C:\Arquivos de programas\ZHPDiag\mbr.exe: trouvé !

 

---------------------------------

--> Suppression:

 

C:\HijackThis.exe: supprimé !

C:\Arquivos de programas\ZHPDiag\ZHPdiag.exe: supprimé !

C:\Arquivos de programas\ZHPDiag\catchme.exe: supprimé !

C:\hijackthis.log: supprimé !

C:\Arquivos de programas\ZHPDiag\mbr.exe: supprimé !

C:\Arquivos de programas\ZHPDiag: supprimé !

 

 

Abraços... :clap:

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.