Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

LFABER

[Resolvido] &nbspPropagandas na Página do Google!

Recommended Posts

Olá, deixo aqui Log do Hijackthis para ser analisado:


Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 14:54:09, on 3/5/2002

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal


Running processes:

C:\WINDOWS\System32\smss.exe

C:\ARQUIV~1\AVG\AVG2013\avgrsx.exe

C:\Arquivos de programas\AVG\AVG2013\avgcsrvx.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\WINDOWS\system32\RunDll32.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\AVG\AVG2013\avgui.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\AVG\AVG2013\avgidsagent.exe

C:\Arquivos de programas\AVG\AVG2013\avgwdsvc.exe

C:\Arquivos de programas\Java\jre7\bin\jqs.exe

C:\Arquivos de programas\AVG\AVG2013\avgnsx.exe

C:\Arquivos de programas\AVG\AVG2013\avgemcx.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Google\Chrome\Application\chrome.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\Oddir\Meus documentos\Downloads\HiJackThis (2).exe


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Lyrics Finder - {398C01F1-E584-46AD-A649-4F78B435DCFE} - C:\Arquivos de programas\LyricsFinder\lfind.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre7\bin\ssv.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre7\bin\jp2ssv.dll

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [searchProtection] C:\Documents and Settings\All Users\Dados de aplicativos\Search Protection\_run.bat

O4 - HKLM\..\Run: [AVG_UI] "C:\Arquivos de programas\AVG\AVG2013\avgui.exe" /TRAYONLY

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1363136561921

O17 - HKLM\System\CCS\Services\Tcpip\..\{CD7D9B73-DD02-46EF-890D-29CAC754DFB0}: NameServer = 200.225.197.37,200.225.197.34

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Arquivos de programas\AVG\AVG2013\avgidsagent.exe

O23 - Service: Watchdog do AVG (avgwd) - AVG Technologies CZ, s.r.o. - C:\Arquivos de programas\AVG\AVG2013\avgwdsvc.exe

O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Arquivos de programas\Java\jre7\bin\jqs.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: PSafeSVC - Unknown owner - C:\Arquivos de programas\PSafe\PSafesvc.exe (file missing)

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Arquivos de programas\Skype\Updater\Updater.exe


--

End of file - 7878 bytes


Desde já agradeço pelo suporte e atenção!


LFABER

Compartilhar este post


Link para o post
Compartilhar em outros sites
Bom Dia! LFABER


|- Baixe: < adwcleaner_logo.jpg > ( ... par Xplode )


|- Ao acessar,clique na imagem: < AdwCleaner_Tlcharger.jpg >


|- Ps: Se utilizar o navegador IE9,desabilite o filtro "SmartScreen".

|- Salve-o no desktop!

|- Clique direito em adwcleaner.exe,e escolha sua execução como Executar_Administrador.jpg

|- Ps: Dê início ao scan,clicando em "Remover". < abpXmu2U.jpg >


acuDr4Nb.jpg


|- Ao concluir,poste o relatório: C:\AdwCleaner[S1].txt


-/-


|- Baixe: < ZHPDiag_Silent.jpg > ( ... par Nicolas Coolman )


|- Salve-o no desktop!


ZHPDiag_silent_Abrir_link_zps77a6fb10.jp


|- Ou clique direto na imagem,e escolha: "Abrir link em uma nova guia"

|- Salve-o no desktop!

|- Desabilite seu antivírus!

|- Caso utilize o Avast,estabeleça esta configuração à SandBox.

|- Para Windows Vista ou 7,clique direito e execute o arquivo como Executar_Administrador.jpg

|- Aguarde a conclusão do scan e clique em "Copier". <- Aguarde!


ZHPDiag_4cones.jpg


|- Além do relatório,teremos no desktop: ZHP_uninstall, MBRCheck, ZHPDiag, ZHPFix


abi6rX9e.jpg


|- Poste e/ou cole aqui,o link que será gerado,logo após o relatório.


|- Ou acesse: Cjoint_Logo.jpg


|- Ou acesse: abmdaZsE.jpg


|- Maiores informações: < |Link| >


A+

Compartilhar este post


Link para o post
Compartilhar em outros sites

# AdwCleaner v2.300 - Relatório criado em 04/05/2002 às 04:18:42
# Atualizado em 28/04/2013 por Xplode
# Sistema Operacional : Microsoft Windows XP Service Pack 3 (32 bits)
# Usuário : Oddir - ODADIR-PC
# Modo de Boot : Normal
# Executado de : C:\Documents and Settings\Oddir\Meus documentos\Downloads\adwcleaner.exe
# Opção [Remover]


***** [serviços] *****


***** [Arquivos/Pastas] *****


***** [Registro] *****


***** [Navegadores] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registro está limpo.

-\\ Mozilla Firefox v19.0.2 (pt-BR)

Arquivo : C:\Documents and Settings\Oddir\Dados de aplicativos\Mozilla\Firefox\Profiles\evoez0rf.default\prefs.js

[OK] Arquivo está limpo.

-\\ Google Chrome v26.0.1410.64

Arquivo : C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Preferences

Removida [l.20] : icon_url = "hxxp://www.delta-search.com/favicon.ico",
Removida [l.23] : keyword = "delta-search.com",
Removida [l.27] : search_url = "hxxp://mixidj.delta-search.com/?q={searchTerms}&affID=121139&tt=gc_&babsrc=SP_s[...]

*************************

AdwCleaner[s2].txt - [1157 octets] - [04/05/2002 04:18:42]

########## EOF - C:\AdwCleaner[s2].txt - [1217 octets] ##########

# AdwCleaner v2.300 - Relatório criado em 04/05/2002 às 04:18:42
# Atualizado em 28/04/2013 por Xplode
# Sistema Operacional : Microsoft Windows XP Service Pack 3 (32 bits)
# Usuário : Oddir - ODADIR-PC
# Modo de Boot : Normal
# Executado de : C:\Documents and Settings\Oddir\Meus documentos\Downloads\adwcleaner.exe
# Opção [Remover]


***** [serviços] *****


***** [Arquivos/Pastas] *****


***** [Registro] *****


***** [Navegadores] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registro está limpo.

-\\ Mozilla Firefox v19.0.2 (pt-BR)

Arquivo : C:\Documents and Settings\Oddir\Dados de aplicativos\Mozilla\Firefox\Profiles\evoez0rf.default\prefs.js

[OK] Arquivo está limpo.

-\\ Google Chrome v26.0.1410.64

Arquivo : C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Preferences

Removida [l.20] : icon_url = "hxxp://www.delta-search.com/favicon.ico",
Removida [l.23] : keyword = "delta-search.com",
Removida [l.27] : search_url = "hxxp://mixidj.delta-search.com/?q={searchTerms}&affID=121139&tt=gc_&babsrc=SP_s[...]

*************************

AdwCleaner[s2].txt - [1157 octets] - [04/05/2002 04:18:42]

########## EOF - C:\AdwCleaner[s2].txt - [1217 octets] ##########




Rapport de ZHPDiag v1.31.31 par Nicolas Coolman, Update du 19/10/2012
Run by Oddir at 4/5/2002 04:42:24
Web site : http://nicolascoolman.skyrock.com/
State :
UAC : Not Found or deactivate by user


---\\ Web Browser
MSIE: Internet Explorer v8.0.6001.18702
MFIE: Mozilla Firefox 19.0.2 v19.0.2
GCIE: Google Chrome v26.0.1410.64 (Defaut)

---\\ Windows Product Information
~ Langage: Anglais
Windows XP Home Edition Service Pack 3 (Build 2600)
Windows Automatic Updates : OK
Windows Genuine Advantage : OK

---\\ System Information
~ Processor: x86 Family 15 Model 4 Stepping 3, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 511 MB (21% free)
System Restore: Activé (Enable)
System drive C: has 124 GB (82%) free of 149 GB

---\\ Logged in mode
~ Computer Name: ODADIR-PC
~ User Name: Oddir
~ All Users Names: SUPPORT_388945a0, Oddir, HelpAssistant, Convidado, ASPNET, Administrador,
~ Unselected Option: O45,O61,O62,O65,O82
Logged in as Administrator

---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Documents and Settings\Oddir\Dados de aplicativos\
~ %Desktop% : C:\Documents and Settings\Oddir\Desktop\
~ %Favorites% : C:\Documents and Settings\Oddir\Favoritos\
~ %LocalAppData% : C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\
~ %StartMenu% : C:\Documents and Settings\Oddir\Menu Iniciar\
~ %Windir% : C:\WINDOWS\
~ %System% : C:\WINDOWS\system32\

---\\ DOS/Devices
A:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
C:\ Hard drive, Flash drive, Thumb drive (Free 124 Go of 149 Go)
D:\ CD-ROM drive (Not Inserted)



---\\ Security Center & Tools Informations
~ UAC deactivate by user
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Scan Security Center in 00mn 00s



---\\ Search Generic System Files
[MD5.064EC7FF5F58B928C3E119402977FA6D] - (.Microsoft Corporation - Windows Explorer.) (.13/4/2008 - 18:21:00.) -- C:\WINDOWS\Explorer.exe [1035776]
[MD5.EB9431247B025996B39D44044463AA55] - (.Microsoft Corporation - Internet Extensions for Win32.) (.1/3/2013 - 23:07:05.) -- C:\WINDOWS\system32\wininet.dll [916480]
[MD5.ABA93202586AFC4EB73547A74D6AAEA4] - (.Microsoft Corporation - Aplicativo de logon do Windows NT.) (.12/3/2013 - 13:39:58.) -- C:\WINDOWS\system32\Winlogon.exe [509952]
[MD5.1E44BC1E83D8FD2305F8D452DB109CF9] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.17/8/2011 - 10:49:54.) -- C:\WINDOWS\system32\Drivers\AFD.sys [138496]
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.13/4/2008 - 11:40:32.) -- C:\WINDOWS\system32\Drivers\atapi.sys [96512]
[MD5.C885B02847F5D2FD45A24E219ED93B32] - (.Microsoft Corporation - CD-ROM File System Driver.) (.13/4/2008 - 11:14:22.) -- C:\WINDOWS\system32\Drivers\Cdfs.sys [63744]
[MD5.1F4260CC5B42272D71F79E570A27A4FE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.13/4/2008 - 10:40:48.) -- C:\WINDOWS\system32\Drivers\Cdrom.sys [62976]
[MD5.A8D31E836CCF2F51009CE7DFFECF6D51] - (.Microsoft Corporation - FIPS Crypto Driver.) (.13/4/2008 - 17:52:44.) -- C:\WINDOWS\system32\Drivers\Fips.sys [44672]
[MD5.573C7D0A32852B48F3058CFD8026F511] - (.Windows ® Server 2003 DDK provider - High Definition Audio Bus Driver v1.0a.) (.13/4/2008 - 08:36:06.) -- C:\WINDOWS\system32\Drivers\HDAudBus.sys [144384]
[MD5.485BC6BEB778B5E9702E6AA3D384C0CB] - (.Microsoft Corporation - Driver de porta i8042.) (.13/4/2008 - 17:55:20.) -- C:\WINDOWS\system32\Drivers\i8042prt.sys [53504]
[MD5.083A052659F5310DD8B6A6CB05EDCF8E] - (.Microsoft Corporation - IMAPI Kernel Driver.) (.13/4/2008 - 10:41:00.) -- C:\WINDOWS\system32\Drivers\Imapi.sys [42112]
[MD5.CC748EA12C6EFFDE940EE98098BF96BB] - (.Microsoft Corporation - IP Network Address Translator.) (.13/4/2008 - 10:57:16.) -- C:\WINDOWS\system32\Drivers\IpNat.sys [152832]
[MD5.23C74D75E36E7158768DD63D92789A91] - (.Microsoft Corporation - IPSec Driver.) (.13/4/2008 - 11:19:44.) -- C:\WINDOWS\system32\Drivers\IPSec.sys [75264]
[MD5.7D304A5EB4344EBEEAB53A2FE3FFB9F0] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.15/7/2011 - 10:29:31.) -- C:\WINDOWS\system32\Drivers\MRxSmb.sys [456320]
[MD5.74B2B2F5BEA5E9A3DC021D685551BD3D] - (.Microsoft Corporation - MBT Transport driver.) (.13/4/2008 - 11:21:02.) -- C:\WINDOWS\system32\Drivers\netBT.sys [162816]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.13/4/2008 - 11:15:54.) -- C:\WINDOWS\system32\Drivers\ntfs.sys [574976]
[MD5.9BADEE6B698BF1AF36E25A1A64A89EAB] - (.Microsoft Corporation - Driver de porta paralela.) (.13/4/2008 - 18:34:10.) -- C:\WINDOWS\system32\Drivers\Parport.sys [80384]
[MD5.11B4A627BC9614B885C4969BFA5FF8A6] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.13/4/2008 - 11:19:44.) -- C:\WINDOWS\system32\Drivers\Rasl2tp.sys [51328]
[MD5.15CABD0F7C00C47C70124907916AF3F1] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.13/4/2008 - 11:32:52.) -- C:\WINDOWS\system32\Drivers\rdpdr.sys [196224]
[MD5.68D749B04BFBBD4D4D15CC5185AFA4DD] - (.Microsoft Corporation - Redbook Audio Filter Driver.) (.13/4/2008 - 15:53:18.) -- C:\WINDOWS\system32\Drivers\redbook.sys [58240]
[MD5.EB6B1E2C984D84470FF4FE7EF98CD44A] - (.Microsoft Corporation - Driver de cópia de sombra de volume.) (.13/4/2008 - 17:53:02.) -- C:\WINDOWS\system32\Drivers\volsnap.sys [53248]
~ Scan Generic Processes in 00mn 00s



---\\ Hidden files state (Hidden/Total)
~ Mes images (My Pictures) : 2/820
~ Mes musiques (My Musics) : 1/3
~ Mes Favoris (My Favorites) : 1/50
~ Mes Documents (My Documents) : 1/3599
~ Mon Bureau (My Desktop) : 0/13
~ Menu demarrer (Programs) : 1/29
~ Scan Hidden Files in 00mn 03s



---\\ Running Processes
[MD5.0D8244A9DB70BC6C36E2FB56F6039AB6] - (.AVG Technologies CZ, s.r.o. - AVG Identity Protection Service.) -- C:\Arquivos de programas\AVG\AVG2013\avgidsagent.exe [4937264] [PID.]
[MD5.DC98337F0D2A9F6C0B6FB682297ECE3B] - (.AVG Technologies CZ, s.r.o. - AVG Watchdog Service.) -- C:\Arquivos de programas\AVG\AVG2013\avgwdsvc.exe [282624] [PID.]
[MD5.C5A75EB48E2344ABDC162BDA79E16841] - (.Microsoft Corporation - .NET Runtime Optimization Service.) -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [130384] [PID.]
[MD5.999DB5F88C8E145CCA9D471E33227143] - (.Oracle Corporation - Java Quick Starter Service.) -- C:\Arquivos de programas\Java\jre7\bin\jqs.exe [170912] [PID.]
[MD5.0108C4CDDC5C34998A317C8C0193DEF7] - (.TuneUp Software - TuneUp Utilities Service.) -- C:\Arquivos de programas\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1723744] [PID.]
[MD5.E365ABAA34D50987B33E02E53AEC30B4] - (.AVG Technologies CZ, s.r.o. - AVG Online Shield Service.) -- C:\Arquivos de programas\AVG\AVG2013\avgnsx.exe [1116720] [PID.]
[MD5.C899F9459AF5358B7B9C3B6D19647B8B] - (.AVG Technologies CZ, s.r.o. - AVG E-mail Scanner.) -- C:\Arquivos de programas\AVG\AVG2013\avgemcx.exe [799792] [PID.]
[MD5.0E34B7BB1FCF22BCC1E394D16F9E992B] - (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe [30040] [PID.]
[MD5.E715412E47D20EB0EBF77B65F9157343] - (...) -- ystem32\RunDll32.exe [0] [PID.]
[MD5.12916E0642E92561C98B18A2A2D01B14] - (.Sun Microsystems, Inc. - Java Update Scheduler.) -- C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe [252848] [PID.]
[MD5.BA92C496F08D78F7DB263A20C36AA546] - (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Arquivos de programas\AVG\AVG2013\avgui.exe [4394032] [PID.]
[MD5.AC116F16A7716A720A45D7EA47CFD983] - (.Hewlett-Packard Co. - Hewlett-Packard Product Assistant.) -- C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe [49152] [PID.]
[MD5.59D9856CD1420E2AF778821B7E1B81D0] - (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [153136] [PID.]
[MD5.80F33BB3510469E0CFC5B0664EBAD8DC] - (.TuneUp Software - TuneUp Utilities.) -- C:\Arquivos de programas\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe [1926496] [PID.]
[MD5.E32686B4E27D11F83E3F2844E104C66C] - (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe [271920] [PID.]
[MD5.6DC177F1626545F087892E73E7609DD0] - (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe [1209904] [PID.]
[MD5.4E9592BB2C100E571F82640E59E9ECD5] - (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe [1312720] [PID.]
[MD5.E897110EE5E67FABB83B154DF9C68D6A] - (...) -- C:\Documents and Settings\Oddir\Meus documentos\Downloads\ZHPDiag_silent.exe [794216] [PID.]
[MD5.56873D899C0707AA017AA2D74EC190AE] - (...) -- C:\Arquivos de programas\ZHPDiag\ZHPDiag.exe [3770368] [PID.]
[MD5.B9CB6D4E5A30968330F6E32ACB945641] - (.AVG Technologies CZ, s.r.o. - AVG Resident Shield Service.) -- C:\Arquivos de programas\AVG\AVG2013\avgrsx.exe [763440] [PID.]
[MD5.53B18D940D7155C49D507F076AF43554] - (.AVG Technologies CZ, s.r.o. - AVG Scanning Core Module - Server Part.) -- C:\Arquivos de programas\AVG\AVG2013\avgcsrvx.exe [448560] [PID.]
[MD5.6D2018AEE93285F2A8BEF55D722187A3] - (.Microsoft Corporation - Application Layer Gateway Service.) -- C:\WINDOWS\System32\alg.exe [44544] [PID.]
~ Scan Processes Running in 00mn 01s



---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (P2,M0,M1,M2,M3)
M3 - MFPP: Plugins - [Oddir] -- C:\Arquivos de programas\Mozilla FireFox\searchplugins\buscape.xml
M3 - MFPP: Plugins - [Oddir] -- C:\Arquivos de programas\Mozilla FireFox\searchplugins\google.xml
M3 - MFPP: Plugins - [Oddir] -- C:\Arquivos de programas\Mozilla FireFox\searchplugins\mercadolivre.xml
M3 - MFPP: Plugins - [Oddir] -- C:\Arquivos de programas\Mozilla FireFox\searchplugins\portaldosites.xml
M3 - MFPP: Plugins - [Oddir] -- C:\Arquivos de programas\Mozilla FireFox\searchplugins\twitter.xml
M3 - MFPP: Plugins - [Oddir] -- C:\Arquivos de programas\Mozilla FireFox\searchplugins\wikipedia-br.xml
M3 - MFPP: Plugins - [Oddir] -- C:\Arquivos de programas\Mozilla FireFox\searchplugins\yahoo-br.xml
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=10.17.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java Deploy.) -- C:\WINDOWS\system32\npDeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=10.17.2] - (.Oracle Corporation - Next Generation Java Plug-in 10.17.2 for Mozilla browsers.) -- C:\Arquivos de programas\Java\jre7\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.20125.0.) -- c:\Arquivos de programas\Microsoft Silverlight\5.1.20125.0\npctrl.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Arquivos de programas\Google\Update\1.3.21.135\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Arquivos de programas\Google\Update\1.3.21.135\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.02.) -- C:\Arquivos de programas\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
~ Scan Firefox Browser in 00mn 00s



---\\ Internet Explorer Extensions, Start, Search (R4,R3,R0,R1)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 11.0.02.) (No version) -- (.not file.)
~ Scan IE Browser in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s



---\\ Changed inifile Value, Mapped to Registry (F2)
F2 - REG:system.ini: USERINIT=C:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\WINDOWS\explorer.exe
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Scan Keys in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Scan Hosts File in 00mn 00s
~ Nombre de lignes (Lines number): 19



---\\ Browser Helper Objects (O2)
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} Orphean Key
O2 - BHO: (no name) - {44C9CC91-6A4A-4579-B4B5-899ECDC18DC6} Orphean Key
O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} Orphean Key
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} Orphean Key
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} Orphean Key
~ Scan BHO in 00mn 00s



---\\ Auto loading programs from Registry and folders (O4)
O4 - HKLM\..\Run: [GrooveMonitor] . (.Microsoft Corporation - GrooveMonitor Utility.) -- C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] . (.Nero AG - NeroCheck.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl
O4 - HKLM\..\Run: [sunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java Update Scheduler.) -- C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [searchProtection] C:\Documents and Settings\All Users\Dados de aplicativos\Search Protection\_run.bat (.not file.)
O4 - HKLM\..\Run: [AVG_UI] . (.AVG Technologies CZ, s.r.o. - AVG User Interface.) -- C:\Arquivos de programas\AVG\AVG2013\avgui.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] . (.HP - No comment.) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard Co. - Hewlett-Packard Product Assistant.) -- C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VDownloader] . (.Vitzo - VDownloader.) -- C:\Arquivos de programas\VDownloader\VDownloader.exe
O4 - HKCU\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] . (.Microsoft Corporation - Watson Subscriber for SENS Network Notifica.) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\DW\DWTRIG20.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] . (.Microsoft Corporation - Watson Subscriber for SENS Network Notifica.) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\DW\DWTRIG20.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
O4 - HKUS\S-1-5-21-436374069-308236825-1644491937-1004\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-436374069-308236825-1644491937-1004\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
~ Scan Application in 00mn 00s



---\\ Other User Links (O4)
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\AVG 2013.lnk . (.AVG Technologies CZ, s.r.o..) -- C:\Arquivos de programas\AVG\AVG2013\avgui.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Central de Soluções HP.lnk . (.Hewlett-Packard Company.) -- C:\Arquivos de programas\HP\Digital Imaging\bin\hpqdirec.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Google Chrome.lnk . (.Google Inc..) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\MercadoLivre.url . (.Google Inc..) -- C:\Documents And Settings\All Users\Desktop\MercadoLivre.url
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Nero StartSmart.lnk . (.Nero AG.) -- C:\Arquivos de programas\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\NETESITE.lnk - Orphean Key
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ODADIR.lnk - Orphean Key
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Receitanet 1.03 .lnk . (.SERPRO - Serviço Federal de Processamento d.) -- C:\Arquivos de programas\Programas RFB\Receitanet\Windows\Receitanet.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Skype.lnk . (...) -- C:\WINDOWS\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\TuneUp Manutenção em um Clique.lnk . (.TuneUp Software.) -- C:\Arquivos de programas\TuneUp Utilities 2013\OneClick.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\TuneUp Utilities 2013.lnk . (.TuneUp Software.) -- C:\Arquivos de programas\TuneUp Utilities 2013\Integrator.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\VDownloader.lnk . (.Vitzo.) -- C:\Arquivos de programas\VDownloader\VDownloader.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\Iniciar o navegador Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Arquivos de programas\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\IRPF2012 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva do País.lnk . (...) -- C:\Arquivos de Programas RFB\IRPF2012\IRPF2012.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\IRPF2013 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva do País.lnk . (...) -- C:\Arquivos de Programas RFB\IRPF2013\IRPF2013.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\MBRCheck.lnk . (...) -- C:\Arquivos de programas\ZHPDiag\mbrcheck.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\ZHPDiag.lnk . (...) -- C:\Arquivos de programas\ZHPDiag\ZHPDiags.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\ZHPFix.lnk . (...) -- C:\Arquivos de programas\ZHPDiag\ZHPFix.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\AVG 2013.lnk . (.AVG Technologies CZ, s.r.o..) -- C:\Arquivos de programas\AVG\AVG2013\avgui.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Central de Soluções HP.lnk . (.Hewlett-Packard Company.) -- C:\Arquivos de programas\HP\Digital Imaging\bin\hpqdirec.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Google Chrome.lnk . (.Google Inc..) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\MercadoLivre.url . (.Google Inc..) -- C:\Documents And Settings\All Users\Desktop\MercadoLivre.url
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Nero StartSmart.lnk . (.Nero AG.) -- C:\Arquivos de programas\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\NETESITE.lnk - Orphean Key
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ODADIR.lnk - Orphean Key
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Receitanet 1.03 .lnk . (.SERPRO - Serviço Federal de Processamento d.) -- C:\Arquivos de programas\Programas RFB\Receitanet\Windows\Receitanet.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\Skype.lnk . (...) -- C:\WINDOWS\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\TuneUp Manutenção em um Clique.lnk . (.TuneUp Software.) -- C:\Arquivos de programas\TuneUp Utilities 2013\OneClick.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\TuneUp Utilities 2013.lnk . (.TuneUp Software.) -- C:\Arquivos de programas\TuneUp Utilities 2013\Integrator.exe
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\VDownloader.lnk . (.Vitzo.) -- C:\Arquivos de programas\VDownloader\VDownloader.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\Iniciar o navegador Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Arquivos de programas\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\IRPF2012 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva do País.lnk . (...) -- C:\Arquivos de Programas RFB\IRPF2012\IRPF2012.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\IRPF2013 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva do País.lnk . (...) -- C:\Arquivos de Programas RFB\IRPF2013\IRPF2013.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\MBRCheck.lnk . (...) -- C:\Arquivos de programas\ZHPDiag\mbrcheck.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\ZHPDiag.lnk . (...) -- C:\Arquivos de programas\ZHPDiag\ZHPDiags.exe
O4 - Global Startup: C:\Documents And Settings\Oddir\Desktop\ZHPFix.lnk . (...) -- C:\Arquivos de programas\ZHPDiag\ZHPFix.exe
~ Scan Global Startup in 00mn 01s



---\\ Extra buttons on main IE button toolbar, or extra items in IE 'Tools' menu (O9)
O9 - Extra button: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft Office OneNote Internet Explorer Add-in.) -- C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: &Enviar para o OneNote - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Arquivos de programas\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (...) -- C:\Arquivos de programas\Microsoft Office\Office12\REFBARH.ICO
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Arquivos de programas\Messenger\msmsgs.exe
~ Scan IE Extra Buttons in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fornecedor de serviços do Microsoft Windows Sockets 2.0.) -- C:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fornecedor de serviços do Microsoft Windows Sockets 2.0.) -- C:\WINDOWS\system32\mswsock.dll
~ Scan Winsock in 00mn 00s



---\\ Extra group in IE 'Advanced Options'window (O11)
O11 - Options group: [java_sun] Java (Oracle). (.Oracle Corporation - Java Deployment Library .) - C:\Arquivos de programas\Java\jre7\bin\deploy.dll
O11 - Options group: [java_vm] Java (Oracle). (.Oracle Corporation - Java Deployment Library .) - C:\Arquivos de programas\Java\jre7\bin\deploy.dll
~ Scan IE Plugins in 00mn 00s



---\\ 'Reset Web Settings' hijack (O14)
O14 - IERESET.INF: SEARCH_PAGE_URL=SEARCH_PAGE_URL="&http://home.microsoft.com/intl/br/access/allinone.asp"
O14 - IERESET.INF: SAFESITE_VALUE=SAFESITE_VALUE="search.msn.com.br"
~ Scan IE Paramètres WEB in 00mn 00s



---\\ ActiveX Objects (Downloaded Program Files) (O16)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1363112500471
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1363136561921
~ Scan Objets ActiveX in 00mn 00s



---\\ Lop.com/Domain Hijackers (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{CD7D9B73-DD02-46EF-890D-29CAC754DFB0}: NameServer = 200.225.197.37,200.225.197.34
O17 - HKLM\System\CS1\Services\Tcpip\..\{CD7D9B73-DD02-46EF-890D-29CAC754DFB0}: NameServer = 200.225.197.37,200.225.197.34
O17 - HKLM\System\CS2\Services\Tcpip\..\{CD7D9B73-DD02-46EF-890D-29CAC754DFB0}: NameServer = 200.225.197.37,200.225.197.34
~ Scan Domain in 00mn 00s



---\\ Extra protocols (O18)
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft ® HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Controle ActiveX para fluxo de vídeo.) -- C:\WINDOWS\system32\msvidctl.dll
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} . (.Microsoft Corporation - GrooveSystemServices Module.) -- C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft ® HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft ® HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API.) -- C:\WINDOWS\system32\inetcomm.dll
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\WINDOWS\system32\itss.dll
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft ® HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype for COM API.) -- C:\Arquivos de programas\Arquivos comuns\Skype\Skype4COM.dll
O18 - Handler: sysimage - {76E67A63-06E9-11D2-A840-006008059382} . (.Microsoft Corporation - Microsoft ® HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Controle ActiveX para fluxo de vídeo.) -- C:\WINDOWS\system32\msvidctl.dll
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft ® HTML Viewer.) -- C:\WINDOWS\system32\mshtml.dll
O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- C:\WINDOWS\system32\wiascr.dll
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\WINDOWS\system32\mscoree.dll
O18 - Filter: Class Install Handler - {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: lzdhtml - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\WINDOWS\system32\urlmon.dll
O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\MSOXMLMF.dll
~ Scan Protocole Additionnel in 00mn 00s



---\\ AppInit_DLLs Registry value Autorun (O20)
O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\WINDOWS\system32\crypt32.dll
O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\WINDOWS\system32\cryptnet.dll
O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agente de rede off-line.) -- C:\WINDOWS\system32\cscdll.dll
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\system32\dimsntfy.dll
O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL de notificação do serviço de logon secu.) -- C:\WINDOWS\system32\sclgntfy.dll
O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\WlNotify.dll
O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll
O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL comum para receber notificações do Winl.) -- C:\WINDOWS\system32\wlnotify.dll
~ Scan Winlogon in 00mn 00s



---\\ ShellServiceObjectDelayLoad (O21)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objeto de serviço do shell de Systray.) -- C:\WINDOWS\system32\stobject.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll
~ Scan SSODL in 00mn 00s



---\\ SharedTaskScheduler (O22)
O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - (.not file.)
~ Scan STS/SSO in 00mn 00s



---\\ non Microsoft non disabled Windows XP/NT/2000 Services (O23)
O23 - Service: AVGIDSAgent (AVGIDSAgent) . (.AVG Technologies CZ, s.r.o. - AVG Identity Protection Service.) - C:\Arquivos de programas\AVG\AVG2013\avgidsagent.exe
O23 - Service: Watchdog do AVG (avgwd) . (.AVG Technologies CZ, s.r.o. - AVG Watchdog Service.) - C:\Arquivos de programas\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) . (.Oracle Corporation - Java Quick Starter Service.) - C:\Arquivos de programas\Java\jre7\bin\jqs.exe
O23 - Service: PSafeSVC (PSafeSVC) . (...) - C:\Arquivos de programas\PSafe\PSafesvc.exe (.not file.)
O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Arquivos de programas\Skype\Updater\Updater.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) . (.TuneUp Software - TuneUp Utilities Service.) - C:\Arquivos de programas\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
~ Scan Services in 00mn 00s



---\\ Windows Active Desktop & MHTML Editor (O24)
O24 - Desktop Component 0: Minha página inicial atual - file:About:Home
O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Arquivos de programas\Microsoft Office\Office12\WINWORD.exe
O24 - Desktop General: BackupWallPaper - .(...) - C:\WINDOWS\Web\Wallpaper\Alegria.bmp
O24 - Desktop General: WallPaper - .(...) - C:\WINDOWS\Web\Wallpaper\Alegria.bmp
~ Scan Desktop Component in 00mn 00s



---\\
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\ARQUIV~1\AVG\AVG2013\avgrsx.exe /sync /restart) (.AVG Technologies CZ, s.r.o. - AVG Resident Shield Service.) -- C:\ARQUIV~1\AVG\AVG2013\avgrsx.exe
~ Scan Keys in 00mn 00s



---\\ Task Planned Automatically(039)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Ad-Aware Antivirus Scheduled Scan.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\FindLyrics Update.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\User_Feed_Synchronization-{1FA2999B-DA22-434A-BB9B-EB274EEE8B7A}.job
~ Scan Scheduled Task in 00mn 00s



---\\ ActiveSetup Installed Components (O40)
O40 - ASIC: Atualização de Versão do Internet Explorer - <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} . (.Microsoft Corporation - IE Per User Active Setup Uninstall Utility.) -- C:\WINDOWS\system32\ieudinit.exe
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Utilitário de Instalação do Microsoft Windows Media Player.) -- C:\WINDOWS\inf\unregmp2.exe
O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitário de Inicialização por Usuário do Internet Explorer.) -- C:\WINDOWS\system32\ie4uinit.exe.mui
O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - IEAK branding.) -- C:\WINDOWS\system32\iedkcs32.dll
O40 - ASIC: Outlook Express - >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} . (.Microsoft Corporation - Windows NT User Data Migration Tool.) -- C:\WINDOWS\system32\shmgrate.exe
O40 - ASIC: Microsoft NetShow Player - {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\system32\wmpdxm.dll
O40 - ASIC: Microsoft Windows Media Player 6.4 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\system32\wmpdxm.dll
O40 - ASIC: Themes Setup - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API de tema do Windows.) -- C:\WINDOWS\system32\themeui.dll
O40 - ASIC: Microsoft Outlook Express 6 - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Biblioteca de instalação do Outlook Express.) -- C:\Arquivos de programas\Outlook Express\setup50.exe
O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (...) -- C:\WINDOWS\INF\msnetmtg.inf
O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (...) -- C:\WINDOWS\INF\msmsgs.inf
O40 - ASIC: Browsing Enhancements - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extensão shell da pasta FTP do Microsoft Internet Explorer.) -- C:\WINDOWS\system32\msieftp.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (...) -- C:\WINDOWS\INF\wmp11.inf
O40 - ASIC: Catálogo de endereços 6 - {7790769C-0471-11d2-AF11-00C04FA35D02} . (.Microsoft Corporation - Biblioteca de instalação do Outlook Express.) -- C:\Arquivos de programas\Outlook Express\setup50.exe
O40 - ASIC: Atualização da área de trabalho do Windows - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\shell32.dll
O40 - ASIC: Internet Explorer - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitário de Inicialização por Usuário do Internet Explorer.) -- C:\WINDOWS\system32\ie4uinit.exe.mui
O40 - ASIC: Google Chrome - {8A69D345-D564-463c-AFF1-A69D9E530F96} . (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
O40 - ASIC: Shockwave Flash - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 11.6 r602.) -- C:\WINDOWS\system32\Macromed\Flash\Flash32_11_6_602_180.ocx
O40 - ASIC: Installed Component - S-1-5-21-436374069-308236825-1644491937-1004 - <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} -- Not Hexadécimal CLSID
O40 - ASIC: Installed Component - S-1-5-21-436374069-308236825-1644491937-1004 - >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS -- Not Hexadécimal CLSID
~ Scan Active Setup in 00mn 00s



---\\ Drivers launched at startup (O41)
O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys
O41 - Driver: (AsIO) . (...) - C:\WINDOWS\system32\drivers\AsIO.sys
O41 - Driver: (AsUpIO) . (...) - C:\WINDOWS\system32\drivers\AsUpIO.sys
O41 - Driver: (AVGIDSDriver) . (.AVG Technologies CZ, s.r.o. - IDS Application Activity Monitor Driver..) - C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys
O41 - Driver: (AVGIDSShim) . (.AVG Technologies CZ, s.r.o. - IDS Application Activity Monitor Loader Dri.) - C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys
O41 - Driver: (Avgldx86) . (.AVG Technologies CZ, s.r.o. - AVG AVI Loader Driver.) - C:\WINDOWS\system32\DRIVERS\avgldx86.sys
O41 - Driver: (Avgtdix) . (.AVG Technologies CZ, s.r.o. - AVG Network connection watcher.) - C:\WINDOWS\system32\DRIVERS\avgtdix.sys
O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\WINDOWS\system32\DRIVERS\cdrom.sys
O41 - Driver: (i8042prt) . (.Microsoft Corporation - Driver de porta i8042.) - C:\WINDOWS\system32\DRIVERS\i8042prt.sys
O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\WINDOWS\system32\DRIVERS\imapi.sys
O41 - Driver: (intelppm) . (.Microsoft Corporation - Driver de dispositivo de processador.) - C:\WINDOWS\system32\DRIVERS\intelppm.sys
O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\WINDOWS\system32\DRIVERS\ipsec.sys
O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Driver de classe teclado.) - C:\WINDOWS\system32\DRIVERS\kbdclass.sys
O41 - Driver: (Mouclass) . (.Microsoft Corporation - Driver de classe modem.) - C:\WINDOWS\system32\DRIVERS\mouclass.sys
O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\WINDOWS\system32\DRIVERS\netbios.sys
O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\WINDOWS\system32\DRIVERS\netbt.sys
O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\WINDOWS\system32\DRIVERS\rasacd.sys
O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\WINDOWS\system32\DRIVERS\rdbss.sys
O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
O41 - Driver: (redbook) . (.Microsoft Corporation - Redbook Audio Filter Driver.) - C:\WINDOWS\system32\DRIVERS\redbook.sys
O41 - Driver: (Serial) . (.Microsoft Corporation - Driver de dispositivo serial.) - C:\WINDOWS\system32\DRIVERS\serial.sys
O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\WINDOWS\system32\DRIVERS\tcpip.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\WINDOWS\system32\DRIVERS\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys
~ Scan Drivers in 00mn 00s



---\\ Software installed (O42)
O42 - Logiciel: AVG 2013 - (.AVG Technologies.) [HKLM] -- AVG
O42 - Logiciel: AVG 2013 - (.AVG Technologies.) [HKLM] -- {48A5AB54-6327-43DC-A376-4AC74C5D40B0}
O42 - Logiciel: AVG 2013 - (.AVG Technologies.) [HKLM] -- {7735BD50-87C5-4838-A276-4A3621BBD306}
O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Reader XI (11.0.02) - Português - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1046-7B44-AB0000000001}
O42 - Logiciel: Atualização de Segurança para Microsoft Windows (KB2564958) - (.Microsoft Corporation.) [HKLM] -- KB2564958
O42 - Logiciel: Atualização de Segurança para Windows Internet Explorer 8 (KB2510531) - (.Microsoft Corporation.) [HKLM] -- KB2510531-IE8
O42 - Logiciel: Atualização de Segurança para Windows Internet Explorer 8 (KB2618444) - (.Microsoft Corporation.) [HKLM] -- KB2618444-IE8
O42 - Logiciel: Atualização de Segurança para Windows Internet Explorer 8 (KB2744842) - (.Microsoft Corporation.) [HKLM] -- KB2744842-IE8
O42 - Logiciel: Atualização de Segurança para Windows Internet Explorer 8 (KB2797052) - (.Microsoft Corporation.) [HKLM] -- KB2797052-IE8
O42 - Logiciel: Atualização de Segurança para Windows Internet Explorer 8 (KB2809289) - (.Microsoft Corporation.) [HKLM] -- KB2809289-IE8
O42 - Logiciel: Atualização de Segurança para Windows Internet Explorer 8 (KB2817183) - (.Microsoft Corporation.) [HKLM] -- KB2817183-IE8
O42 - Logiciel: Atualização de Segurança para Windows Internet Explorer 8 (KB982381) - (.Microsoft Corporation.) [HKLM] -- KB982381-IE8
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2115168) - (.Microsoft Corporation.) [HKLM] -- KB2115168
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2229593) - (.Microsoft Corporation.) [HKLM] -- KB2229593
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2296011) - (.Microsoft Corporation.) [HKLM] -- KB2296011
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2347290) - (.Microsoft Corporation.) [HKLM] -- KB2347290
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2360937) - (.Microsoft Corporation.) [HKLM] -- KB2360937
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2387149) - (.Microsoft Corporation.) [HKLM] -- KB2387149
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2393802) - (.Microsoft Corporation.) [HKLM] -- KB2393802
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2419632) - (.Microsoft Corporation.) [HKLM] -- KB2419632
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2423089) - (.Microsoft Corporation.) [HKLM] -- KB2423089
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2440591) - (.Microsoft Corporation.) [HKLM] -- KB2440591
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2443105) - (.Microsoft Corporation.) [HKLM] -- KB2443105
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2478960) - (.Microsoft Corporation.) [HKLM] -- KB2478960
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2478971) - (.Microsoft Corporation.) [HKLM] -- KB2478971
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2479943) - (.Microsoft Corporation.) [HKLM] -- KB2479943
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2481109) - (.Microsoft Corporation.) [HKLM] -- KB2481109
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2483185) - (.Microsoft Corporation.) [HKLM] -- KB2483185
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2485663) - (.Microsoft Corporation.) [HKLM] -- KB2485663
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2506212) - (.Microsoft Corporation.) [HKLM] -- KB2506212
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2507938) - (.Microsoft Corporation.) [HKLM] -- KB2507938
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2508429) - (.Microsoft Corporation.) [HKLM] -- KB2508429
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2509553) - (.Microsoft Corporation.) [HKLM] -- KB2509553
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2510581) - (.Microsoft Corporation.) [HKLM] -- KB2510581
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2535512) - (.Microsoft Corporation.) [HKLM] -- KB2535512
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2536276-v2) - (.Microsoft Corporation.) [HKLM] -- KB2536276-v2
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2544893-v2) - (.Microsoft Corporation.) [HKLM] -- KB2544893-v2
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2566454) - (.Microsoft Corporation.) [HKLM] -- KB2566454
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2570947) - (.Microsoft Corporation.) [HKLM] -- KB2570947
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2584146) - (.Microsoft Corporation.) [HKLM] -- KB2584146
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2585542) - (.Microsoft Corporation.) [HKLM] -- KB2585542
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2592799) - (.Microsoft Corporation.) [HKLM] -- KB2592799
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2598479) - (.Microsoft Corporation.) [HKLM] -- KB2598479
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2603381) - (.Microsoft Corporation.) [HKLM] -- KB2603381
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2618451) - (.Microsoft Corporation.) [HKLM] -- KB2618451
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2619339) - (.Microsoft Corporation.) [HKLM] -- KB2619339
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2620712) - (.Microsoft Corporation.) [HKLM] -- KB2620712
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2624667) - (.Microsoft Corporation.) [HKLM] -- KB2624667
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2631813) - (.Microsoft Corporation.) [HKLM] -- KB2631813
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2646524) - (.Microsoft Corporation.) [HKLM] -- KB2646524
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2653956) - (.Microsoft Corporation.) [HKLM] -- KB2653956
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2655992) - (.Microsoft Corporation.) [HKLM] -- KB2655992
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2659262) - (.Microsoft Corporation.) [HKLM] -- KB2659262
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2661637) - (.Microsoft Corporation.) [HKLM] -- KB2661637
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2676562) - (.Microsoft Corporation.) [HKLM] -- KB2676562
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2686509) - (.Microsoft Corporation.) [HKLM] -- KB2686509
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2691442) - (.Microsoft Corporation.) [HKLM] -- KB2691442
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2698365) - (.Microsoft Corporation.) [HKLM] -- KB2698365
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2705219-v2) - (.Microsoft Corporation.) [HKLM] -- KB2705219-v2
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2712808) - (.Microsoft Corporation.) [HKLM] -- KB2712808
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2719985) - (.Microsoft Corporation.) [HKLM] -- KB2719985
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2723135-v2) - (.Microsoft Corporation.) [HKLM] -- KB2723135-v2
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2727528) - (.Microsoft Corporation.) [HKLM] -- KB2727528
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2753842-v2) - (.Microsoft Corporation.) [HKLM] -- KB2753842-v2
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2757638) - (.Microsoft Corporation.) [HKLM] -- KB2757638
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2758857) - (.Microsoft Corporation.) [HKLM] -- KB2758857
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2770660) - (.Microsoft Corporation.) [HKLM] -- KB2770660
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2778344) - (.Microsoft Corporation.) [HKLM] -- KB2778344
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2780091) - (.Microsoft Corporation.) [HKLM] -- KB2780091
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2797052) - (.Microsoft Corporation.) [HKLM] -- KB2797052
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2799494) - (.Microsoft Corporation.) [HKLM] -- KB2799494
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2802968) - (.Microsoft Corporation.) [HKLM] -- KB2802968
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2807986) - (.Microsoft Corporation.) [HKLM] -- KB2807986
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2808735) - (.Microsoft Corporation.) [HKLM] -- KB2808735
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2809289) - (.Microsoft Corporation.) [HKLM] -- KB2809289
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2813170) - (.Microsoft Corporation.) [HKLM] -- KB2813170
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2813345) - (.Microsoft Corporation.) [HKLM] -- KB2813345
O42 - Logiciel: Atualização de Segurança para Windows XP (KB2820917) - (.Microsoft Corporation.) [HKLM] -- KB2820917
O42 - Logiciel: Atualização de Segurança para Windows XP (KB923561) - (.Microsoft Corporation.) [HKLM] -- KB923561
O42 - Logiciel: Atualização de Segurança para Windows XP (KB923789) - (.Microsoft Corporation.) [HKLM] -- KB923789
O42 - Logiciel: Atualização de Segurança para Windows XP (KB941569) - (.Microsoft Corporation.) [HKLM] -- KB941569
O42 - Logiciel: Atualização de Segurança para Windows XP (KB946648) - (.Microsoft Corporation.) [HKLM] -- KB946648
O42 - Logiciel: Atualização de Segurança para Windows XP (KB950762) - (.Microsoft Corporation.) [HKLM] -- KB950762
O42 - Logiciel: Atualização de Segurança para Windows XP (KB950974) - (.Microsoft Corporation.) [HKLM] -- KB950974
O42 - Logiciel: Atualização de Segurança para Windows XP (KB951376-v2) - (.Microsoft Corporation.) [HKLM] -- KB951376-v2
O42 - Logiciel: Atualização de Segurança para Windows XP (KB952004) - (.Microsoft Corporation.) [HKLM] -- KB952004
O42 - Logiciel: Atualização de Segurança para Windows XP (KB952954) - (.Microsoft Corporation.) [HKLM] -- KB952954
O42 - Logiciel: Atualização de Segurança para Windows XP (KB956572) - (.Microsoft Corporation.) [HKLM] -- KB956572
O42 - Logiciel: Atualização de Segurança para Windows XP (KB956744) - (.Microsoft Corporation.) [HKLM] -- KB956744
O42 - Logiciel: Atualização de Segurança para Windows XP (KB956802) - (.Microsoft Corporation.) [HKLM] -- KB956802
O42 - Logiciel: Atualização de Segurança para Windows XP (KB956844) - (.Microsoft Corporation.) [HKLM] -- KB956844
O42 - Logiciel: Atualização de Segurança para Windows XP (KB959426) - (.Microsoft Corporation.) [HKLM] -- KB959426
O42 - Logiciel: Atualização de Segurança para Windows XP (KB960803) - (.Microsoft Corporation.) [HKLM] -- KB960803
O42 - Logiciel: Atualização de Segurança para Windows XP (KB960859) - (.Microsoft Corporation.) [HKLM] -- KB960859
O42 - Logiciel: Atualização de Segurança para Windows XP (KB969059) - (.Microsoft Corporation.) [HKLM] -- KB969059
O42 - Logiciel: Atualização de Segurança para Windows XP (KB970430) - (.Microsoft Corporation.) [HKLM] -- KB970430
O42 - Logiciel: Atualização de Segurança para Windows XP (KB971657) - (.Microsoft Corporation.) [HKLM] -- KB971657
O42 - Logiciel: Atualização de Segurança para Windows XP (KB972270) - (.Microsoft Corporation.) [HKLM] -- KB972270
O42 - Logiciel: Atualização de Segurança para Windows XP (KB973507) - (.Microsoft Corporation.) [HKLM] -- KB973507
O42 - Logiciel: Atualização de Segurança para Windows XP (KB973869) - (.Microsoft Corporation.) [HKLM] -- KB973869
O42 - Logiciel: Atualização de Segurança para Windows XP (KB973904) - (.Microsoft Corporation.) [HKLM] -- KB973904
O42 - Logiciel: Atualização de Segurança para Windows XP (KB974112) - (.Microsoft Corporation.) [HKLM] -- KB974112
O42 - Logiciel: Atualização de Segurança para Windows XP (KB974318) - (.Microsoft Corporation.) [HKLM] -- KB974318
O42 - Logiciel: Atualização de Segurança para Windows XP (KB974392) - (.Microsoft Corporation.) [HKLM] -- KB974392
O42 - Logiciel: Atualização de Segurança para Windows XP (KB974571) - (.Microsoft Corporation.) [HKLM] -- KB974571
O42 - Logiciel: Atualização de Segurança para Windows XP (KB975025) - (.Microsoft Corporation.) [HKLM] -- KB975025
O42 - Logiciel: Atualização de Segurança para Windows XP (KB975467) - (.Microsoft Corporation.) [HKLM] -- KB975467
O42 - Logiciel: Atualização de Segurança para Windows XP (KB975560) - (.Microsoft Corporation.) [HKLM] -- KB975560
O42 - Logiciel: Atualização de Segurança para Windows XP (KB975713) - (.Microsoft Corporation.) [HKLM] -- KB975713
O42 - Logiciel: Atualização de Segurança para Windows XP (KB977816) - (.Microsoft Corporation.) [HKLM] -- KB977816
O42 - Logiciel: Atualização de Segurança para Windows XP (KB977914) - (.Microsoft Corporation.) [HKLM] -- KB977914
O42 - Logiciel: Atualização de Segurança para Windows XP (KB978338) - (.Microsoft Corporation.) [HKLM] -- KB978338
O42 - Logiciel: Atualização de Segurança para Windows XP (KB978542) - (.Microsoft Corporation.) [HKLM] -- KB978542
O42 - Logiciel: Atualização de Segurança para Windows XP (KB978706) - (.Microsoft Corporation.) [HKLM] -- KB978706
O42 - Logiciel: Atualização de Segurança para Windows XP (KB979309) - (.Microsoft Corporation.) [HKLM] -- KB979309
O42 - Logiciel: Atualização de Segurança para Windows XP (KB979482) - (.Microsoft Corporation.) [HKLM] -- KB979482
O42 - Logiciel: Atualização de Segurança para Windows XP (KB979687) - (.Microsoft Corporation.) [HKLM] -- KB979687
O42 - Logiciel: Atualização de Segurança para Windows XP (KB981322) - (.Microsoft Corporation.) [HKLM] -- KB981322
O42 - Logiciel: Atualização de Segurança para Windows XP (KB981997) - (.Microsoft Corporation.) [HKLM] -- KB981997
O42 - Logiciel: Atualização de Segurança para Windows XP (KB982132) - (.Microsoft Corporation.) [HKLM] -- KB982132
O42 - Logiciel: Atualização de Segurança para Windows XP (KB982665) - (.Microsoft Corporation.) [HKLM] -- KB982665
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB2378111) - (.Microsoft Corporation.) [HKLM] -- KB2378111_WM9
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB952069) - (.Microsoft Corporation.) [HKLM] -- KB952069_WM9
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB954155) - (.Microsoft Corporation.) [HKLM] -- KB954155_WM9
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB973540) - (.Microsoft Corporation.) [HKLM] -- KB973540_WM9
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB975558) - (.Microsoft Corporation.) [HKLM] -- KB975558_WM8
O42 - Logiciel: Atualização de Segurança para o Windows Media Player (KB978695) - (.Microsoft Corporation.) [HKLM] -- KB978695_WM9
O42 - Logiciel: Atualização de Segurança para o Windows Media Player 11 (KB954154) - (.Microsoft Corporation.) [HKLM] -- KB954154_WM11
O42 - Logiciel: Atualização do Microsoft Windows (KB971513) - (.Microsoft Corporation.) [HKLM] -- KB971513
O42 - Logiciel: Atualização do produto Microsoft Office Excel 2007 Help (KB963678) - (.Microsoft.) [HKLM] -- {90120000-0016-0416-0000-0000000FF1CE}_ENTERPRISE_{717C9095-8AAE-41CB-B046-BD6E8399F4F3}
O42 - Logiciel: Atualização do produto Microsoft Office Outlook 2007 Help (KB963677) - (.Microsoft.) [HKLM] -- {90120000-001A-0416-0000-0000000FF1CE}_ENTERPRISE_{5016CB22-B9A7-44FB-AA72-AF28B27B15EA}
O42 - Logiciel: Atualização do produto Microsoft Office Powerpoint 2007 Help (KB963669) - (.Microsoft.) [HKLM] -- {90120000-0018-0416-0000-0000000FF1CE}_ENTERPRISE_{BE3A7C0C-0081-4694-B5F9-980DD66BDDF8}
O42 - Logiciel: Atualização do produto Microsoft Office Word 2007 Help (KB963665) - (.Microsoft.) [HKLM] -- {90120000-001B-0416-0000-0000000FF1CE}_ENTERPRISE_{7297E3A9-FCD4-4E0E-A306-7A90359E50E3}
O42 - Logiciel: Atualização para Windows Internet Explorer 8 (KB2598845) - (.Microsoft Corporation.) [HKLM] -- KB2598845-IE8
O42 - Logiciel: Atualização para Windows XP (KB2345886) - (.Microsoft Corporation.) [HKLM] -- KB2345886
O42 - Logiciel: Atualização para Windows XP (KB2467659) - (.Microsoft Corporation.) [HKLM] -- KB2467659
O42 - Logiciel: Atualização para Windows XP (KB2492386) - (.Microsoft Corporation.) [HKLM] -- KB2492386
O42 - Logiciel: Atualização para Windows XP (KB2661254-v2) - (.Microsoft Corporation.) [HKLM] -- KB2661254-v2
O42 - Logiciel: Atualização para Windows XP (KB2736233) - (.Microsoft Corporation.) [HKLM] -- KB2736233
O42 - Logiciel: Atualização para Windows XP (KB2749655) - (.Microsoft Corporation.) [HKLM] -- KB2749655
O42 - Logiciel: Atualização para Windows XP (KB898461) - (.Microsoft Corporation.) [HKLM] -- KB898461
O42 - Logiciel: Atualização para Windows XP (KB951978) - (.Microsoft Corporation.) [HKLM] -- KB951978
O42 - Logiciel: Atualização para Windows XP (KB968389) - (.Microsoft Corporation.) [HKLM] -- KB968389
O42 - Logiciel: Atualização para Windows XP (KB971029) - (.Microsoft Corporation.) [HKLM] -- KB971029
O42 - Logiciel: Atualização para Windows XP (KB973815) - (.Microsoft Corporation.) [HKLM] -- KB973815
O42 - Logiciel: C-Media High Definition Audio Driver - (.Unknown owner.) [HKLM] -- C-Media Audio Driver
O42 - Logiciel: FindLyrics - (.FindLyrics.) [HKLM] -- findlyrics@findlyrics.co
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM] -- Google Chrome
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
O42 - Logiciel: HP Deskjet 3900 series - (.HP.) [HKLM] -- {3819891A-030B-4a4e-98ED-B28A649E48AB}
O42 - Logiciel: HP Software Update - (.Hewlett-Packard.) [HKLM] -- {15EE79F4-4ED1-4267-9B0F-351009325D7D}
O42 - Logiciel: HP Solution Center & Imaging Support Tools 5.0 - (.HP.) [HKLM] -- HP Solution Center & Imaging Support Tools
O42 - Logiciel: HighMAT Extension to Microsoft Windows XP CD Writing Wizard - (.Microsoft Corporation.) [HKLM] -- {FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
O42 - Logiciel: Hotfix for Windows Media Format 11 SDK (KB929399) - (.Microsoft Corporation.) [HKLM] -- KB929399
O42 - Logiciel: Hotfix para Windows XP (KB2779562) - (.Microsoft Corporation.) [HKLM] -- KB2779562
O42 - Logiciel: Hotfix para Windows XP (KB952287) - (.Microsoft Corporation.) [HKLM] -- KB952287
O42 - Logiciel: Hotfix para o Windows Media Player 11 (KB939683) - (.Microsoft Corporation.) [HKLM] -- KB939683
O42 - Logiciel: IRPF2012 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva - (.Receita Federal do Brasil.) [HKLM] -- IRPF2012
O42 - Logiciel: IRPF2013 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva - (.Receita Federal do Brasil.) [HKLM] -- IRPF2013
O42 - Logiciel: Java 7 Update 17 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83217017FF}
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
O42 - Logiciel: Marvell Miniport Driver - (.Marvell.) [HKLM] -- {C950420B-4182-49EA-850A-A6A2ABF06C6B}
O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile
O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}
O42 - Logiciel: Microsoft .NET Framework 4 Client Profile PTB Language Pack - (.Microsoft Corporation.) [HKLM] -- {20A15757-4AE4-3C82-9711-863C84AFE6AA}
O42 - Logiciel: Microsoft .NET Framework 4 Extended - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Extended
O42 - Logiciel: Microsoft .NET Framework 4 Extended - (.Microsoft Corporation.) [HKLM] -- {0A0CADCF-78DA-33C4-A350-CD51849B9702}
O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0015-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0016-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0018-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0019-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-001A-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-001B-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-0044-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-006E-0416-0000-0000000FF1CE}_ENTERPRISE_{51530CD1-8244-4E0F-B536-BCCC05325C7F}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-00A1-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}
O42 - Logiciel: Microsoft Office 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-00BA-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}
O42 - Logiciel: Microsoft Office Access MUI (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0015-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Enterprise 2007 - (.Microsoft Corporation.) [HKLM] -- ENTERPRISE
O42 - Logiciel: Microsoft Office Enterprise 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Excel MUI (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0016-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office File Validation Add-In - (.Microsoft Corporation.) [HKLM] -- {90140000-2005-0000-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Groove MUI (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-00BA-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0044-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office OneNote MUI (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-00A1-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Outlook MUI (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001A-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0018-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-001F-0416-0000-0000000FF1CE}_ENTERPRISE_{8A524694-0CA4-476A-9301-B1E9D70FC952}
O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}
O42 - Logiciel: Microsoft Office Publisher MUI (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0019-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared MUI (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Word MUI (Portuguese (Brazil)) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001B-0416-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM] -- {9A25302D-30C0-39D9-BD6F-21E6EC160475}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 - (.Microsoft Corporation.) [HKLM] -- {9BE518E6-ECC6-35A9-88E4-87755C07200F}
O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM] -- {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
O42 - Logiciel: Mozilla Firefox 19.0.2 (x86 pt-BR) - (.Mozilla.) [HKLM] -- Mozilla Firefox 19.0.2 (x86 pt-BR)
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM] -- MozillaMaintenanceService
O42 - Logiciel: Nero 7 Premium - (.Nero AG.) [HKLM] -- {A20A58C4-6784-4B4B-86CC-94E2E3671046}
O42 - Logiciel: Pacote de Idiomas do Microsoft .NET Framework 4 Client Profile - Português - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile PTB Language Pack
O42 - Logiciel: Receitanet - (.Serpro - Serviço Federal de Processamento de Dados.) [HKLM] -- ECC16E3C-16D1-4DC2-9D8A-6AC06B3005A5
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2604121
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2656351
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2729449
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2737019
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2742595
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2789642
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Extended (KB2656351) - (.Microsoft Corporation.) [HKLM] -- {0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2656351
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Extended (KB2742595) - (.Microsoft Corporation.) [HKLM] -- {0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2742595
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C6997D22-CC93-4ED9-AD8A-02C3F3D2F1F9}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{5DD3FF90-B302-45B2-A188-C5EA7ACD5D46}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{D33B9EF5-3801-496A-A2D6-B7F4BE972D75}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{B145DBBB-7778-4A5D-9D2B-DA6569F02391}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A0D5F849-D9D5-48ED-99D0-C74D7BFA6A09}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E34960DB-2A93-45DB-A208-02650F7AB09C}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{293FB6BE-D3EB-4162-B522-F9108040B9FE}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{2B3C041A-A7F2-4A24-968D-4BEB6A123D15}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{43171CAD-DC60-4E7B-9703-B2EC18001B9F}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2687439) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3579CE34-B225-4B19-A3AF-DE5F562A212F}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{EF5B5C7F-20CB-4A3A-AC3D-F5DE2C2BFDC7}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{020B65AD-B2ED-4B35-92CA-DB56EFB864A5}
O42 - Logiciel: Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CAB47CC0-A98C-47DD-9FA1-C0416EC96ED5}
O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{488F0918-97F9-4CD0-8AD5-8986A46AC962}
O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Editi - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{8F311D6C-D8DD-4C32-9457-1A129CABD1A5}
O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edi - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{AEA16A27-0B97-4670-818F-A98D06EC0A6F}
O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edi - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0EF0D4FB-BB23-4515-AAEA-1240AC2DA525}
O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edit - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{5A8732F0-C20F-4A9B-A2A9-66FE7A586C35}
O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{718E87EC-6590-485A-B12D-C01D290EDB12}
O42 - Logiciel: Skype™ 6.3 - (.Skype Technologies S.A..) [HKLM] -- {4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}
O42 - Logiciel: TuneUp Utilities 2013 - (.TuneUp Software.) [HKLM] -- TuneUp Utilities 2013
O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
O42 - Logiciel: Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}
O42 - Logiciel: Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{620E77C0-CDFE-4C14-AAEB-830ABB65864C}
O42 - Logiciel: Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{525A4A44-8940-40AD-ABA0-14501199D2F0}
O42 - Logiciel: Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{8153EC80-C988-4336-8DAF-6D99C0D26E0C}
O42 - Logiciel: Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}
O42 - Logiciel: Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition - (.Microsoft.) [HKLM] -- {90120000-001A-0416-0000-0000000FF1CE}_ENTERPRISE_{52F3455A-9ADB-41A6-BCE7-8D99F3770590}
O42 - Logiciel: Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2768021) 32-B - (.Microsoft.) [HKLM] -- {90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{2FAC8CEF-F191-4A30-A107-F33D92D52AEE}
O42 - Logiciel: VDownloader 3.9.1421 - (.Vitzo Limited.) [HKLM] -- {A7E19604-93AF-4611-8C9F-CE509C2B286E}_is1
O42 - Logiciel: VIA Rhine-Family Fast Ethernet Adapter - (.Unknown owner.) [HKLM] -- VN_VUIns_Rhine_VIA
O42 - Logiciel: WinPcap 4.1.1 - (.CACE Technologies.) [HKLM] -- WinPcapInst
O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- KB892130
O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8
O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11
O42 - Logiciel: Windows Media Format 11 runtime - (.Unknown owner.) [HKLM] -- Windows Media Format Runtime
O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM] -- wmp11
O42 - Logiciel: Windows Media Player 11 - (.Unknown owner.) [HKLM] -- Windows Media Player
O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}

---\\ HKCU & HKLM Software Keys
[HKCU\Software\(null)]
[HKCU\Software\Ad-Aware Search Protection]
[HKCU\Software\Adobe]
[HKCU\Software\Ahead]
[HKCU\Software\AppDataLow\Software\Microsoft]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Avg]
[HKCU\Software\Baixaki]
[HKCU\Software\Classes]
[HKCU\Software\Clients]
[HKCU\Software\DSiteProducts]
[HKCU\Software\Google]
[HKCU\Software\Hewlett-Packard]
[HKCU\Software\IM Providers]
[HKCU\Software\Intel]
[HKCU\Software\JavaSoft]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKCU\Software\LyricsFinder]
[HKCU\Software\Macromedia]
[HKCU\Software\MozillaPlugins]
[HKCU\Software\Mozilla]
[HKCU\Software\Netscape]
[HKCU\Software\ODBC]
[HKCU\Software\Policies]
[HKCU\Software\SERPRO]
[HKCU\Software\Sensaura]
[HKCU\Software\Skype]
[HKCU\Software\Trolltech]
[HKCU\Software\TuneUp]
[HKCU\Software\Wow6432Node]
[HKCU\Software\b1.org]
[HKCU\Software\findlyrics]
[HKLM\Software\360Safe]
[HKLM\Software\Adobe]
[HKLM\Software\AdwCleaner]
[HKLM\Software\Ahead]
[HKLM\Software\Audible]
[HKLM\Software\Avg]
[HKLM\Software\C07ft5Y]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Gemplus]
[HKLM\Software\Google]
[HKLM\Software\Hewlett-Packard]
[HKLM\Software\IM Providers]
[HKLM\Software\INTEL]
[HKLM\Software\InstallShield]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\Lavasoft]
[HKLM\Software\Licenses]
[HKLM\Software\Macromedia]
[HKLM\Software\Marvell]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\Nero]
[HKLM\Software\ODBC]
[HKLM\Software\Policies]
[HKLM\Software\Program Groups]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Schlumberger]
[HKLM\Software\Secure]
[HKLM\Software\Skype]
[HKLM\Software\TrendMicro]
[HKLM\Software\TuneUp]
[HKLM\Software\VDownloader]
[HKLM\Software\VN_VUIns]
[HKLM\Software\WinPcap]
[HKLM\Software\Windows 3.1 Migration Status]
[HKLM\Software\Wow6432Node]
[HKLM\Software\b1.org]
[HKLM\Software\hdcode]
[HKLM\Software\mozilla.org]
~ Scan Softwares in 00mn 00s



---\\ Contents of the Common Files folders (O43)
O43 - CFD: 13/3/2013 - 18:34:49 - [119,125] ----D C:\Arquivos de programas\Adobe
O43 - CFD: 3/5/2002 - 23:29:50 - [337,000] ----D C:\Arquivos de programas\Arquivos comuns
O43 - CFD: 13/3/2013 - 19:36:17 - [0,112] ----D C:\Arquivos de programas\ASUS
O43 - CFD: 20/4/2002 - 17:19:33 - [95,393] ----D C:\Arquivos de programas\AVG
O43 - CFD: 12/3/2013 - 13:25:53 - [0] ----D C:\Arquivos de programas\ComPlus Applications
O43 - CFD: 3/5/2002 - 22:12:01 - [0,382] ----D C:\Arquivos de programas\FindLyrics
O43 - CFD: 13/3/2013 - 20:10:51 - [399,441] ----D C:\Arquivos de programas\Google
O43 - CFD: 2/1/2002 - 23:06:47 - [2,093] ----D C:\Arquivos de programas\Hewlett-Packard
O43 - CFD: 20/4/2002 - 22:12:12 - [2,141] ----D C:\Arquivos de programas\HighMAT CD Writing Wizard
O43 - CFD: 2/1/2002 - 23:06:39 - [68,850] ----D C:\Arquivos de programas\HP
O43 - CFD: 1/1/2002 - 01:06:34 - [1,556] --H-D C:\Arquivos de programas\InstallJammer Registry
O43 - CFD: 13/3/2013 - 20:39:17 - [1,941] --H-D C:\Arquivos de programas\InstallShield Installation Information
O43 - CFD: 13/3/2013 - 20:40:19 - [0,045] ----D C:\Arquivos de programas\Intel
O43 - CFD: 14/4/2013 - 18:23:26 - [4,170] ----D C:\Arquivos de programas\Internet Explorer
O43 - CFD: 13/3/2013 - 18:30:42 - [122,273] ----D C:\Arquivos de programas\Java
O43 - CFD: 22/4/2002 - 13:28:16 - [0,566] ----D C:\Arquivos de programas\Marvell
O43 - CFD: 13/3/2013 - 19:50:50 - [2,069] ----D C:\Arquivos de programas\Messenger
O43 - CFD: 12/3/2013 - 13:29:12 - [0] ----D C:\Arquivos de programas\microsoft frontpage
O43 - CFD: 2/4/2013 - 20:47:45 - [622,213] ----D C:\Arquivos de programas\Microsoft Office
O43 - CFD: 1/1/2002 - 00:00:49 - [40,835] ----D C:\Arquivos de programas\Microsoft Silverlight
O43 - CFD: 12/3/2013 - 13:46:25 - [0,014] ----D C:\Arquivos de programas\Microsoft Visual Studio
O43 - CFD: 13/3/2013 - 19:52:36 - [3,554] ----D C:\Arquivos de programas\Microsoft Works
O43 - CFD: 13/3/2013 - 18:52:01 - [0,023] ----D C:\Arquivos de programas\Microsoft.NET
O43 - CFD: 13/3/2013 - 19:51:22 - [9,864] ----D C:\Arquivos de programas\Movie Maker
O43 - CFD: 13/3/2013 - 20:14:42 - [43,655] ----D C:\Arquivos de programas\Mozilla Firefox
O43 - CFD: 13/3/2013 - 20:15:11 - [0,212] ----D C:\Arquivos de programas\Mozilla Maintenance Service
O43 - CFD: 12/3/2013 - 13:46:37 - [0,001] ----D C:\Arquivos de programas\MSBuild
O43 - CFD: 12/3/2013 - 13:25:10 - [8,340] ----D C:\Arquivos de programas\MSN Gaming Zone
O43 - CFD: 13/3/2013 - 19:51:43 - [0] ----D C:\Arquivos de programas\MSXML 4.0
O43 - CFD: 12/3/2013 - 15:07:20 - [353,875] ----D C:\Arquivos de programas\Nero
O43 - CFD: 12/3/2013 - 13:27:17 - [3,131] ----D C:\Arquivos de programas\NetMeeting
O43 - CFD: 13/3/2013 - 19:53:54 - [4,155] ----D C:\Arquivos de programas\Outlook Express
O43 - CFD: 1/1/2002 - 01:08:24 - [8,843] ----D C:\Arquivos de programas\Programas RFB
O43 - CFD: 12/3/2013 - 13:27:55 - [0,001] ----D C:\Arquivos de programas\Serviços on-line
O43 - CFD: 13/3/2013 - 23:53:36 - [18,031] R---D C:\Arquivos de programas\Skype
O43 - CFD: 3/5/2002 - 22:17:26 - [73,219] ----D C:\Arquivos de programas\TuneUp Utilities 2013
O43 - CFD: 12/3/2013 - 13:34:55 - [0] --H-D C:\Arquivos de programas\Uninstall Information
O43 - CFD: 3/5/2002 - 22:14:51 - [45,454] ----D C:\Arquivos de programas\VDownloader
O43 - CFD: 13/3/2013 - 19:50:46 - [3,415] ----D C:\Arquivos de programas\Windows Media Connect 2
O43 - CFD: 13/3/2013 - 19:50:46 - [7,930] ----D C:\Arquivos de programas\Windows Media Player
O43 - CFD: 12/3/2013 - 13:24:58 - [3,752] ----D C:\Arquivos de programas\Windows NT
O43 - CFD: 12/3/2013 - 13:27:58 - [0] --H-D C:\Arquivos de programas\WindowsUpdate
O43 - CFD: 3/5/2002 - 22:14:55 - [0,182] ----D C:\Arquivos de programas\WinPcap
O43 - CFD: 12/3/2013 - 13:29:12 - [0] ----D C:\Arquivos de programas\xerox
O43 - CFD: 4/5/2002 - 04:42:31 - [10,362] ----D C:\Arquivos de programas\ZHPDiag
O43 - CFD: 13/3/2013 - 19:36:34 - [11,753] ----D C:\Arquivos de programas\Arquivos comuns\Adobe
O43 - CFD: 12/3/2013 - 15:08:06 - [113,064] ----D C:\Arquivos de programas\Arquivos comuns\Ahead
O43 - CFD: 13/3/2013 - 19:50:24 - [0,089] ----D C:\Arquivos de programas\Arquivos comuns\DESIGNER
O43 - CFD: 22/4/2002 - 13:27:45 - [3,391] ----D C:\Arquivos de programas\Arquivos comuns\InstallShield
O43 - CFD: 13/3/2013 - 18:31:12 - [1,184] ----D C:\Arquivos de programas\Arquivos comuns\Java
O43 - CFD: 19/4/2002 - 11:45:09 - [161,951] ----D C:\Arquivos de programas\Arquivos comuns\Microsoft Shared
O43 - CFD: 12/3/2013 - 13:27:10 - [0,271] ----D C:\Arquivos de programas\Arquivos comuns\MSSoap
O43 - CFD: 12/3/2013 - 10:18:35 - [0] ----D C:\Arquivos de programas\Arquivos comuns\ODBC
O43 - CFD: 12/3/2013 - 13:27:15 - [0,008] ----D C:\Arquivos de programas\Arquivos comuns\Serviços
O43 - CFD: 13/3/2013 - 23:53:35 - [1,904] ----D C:\Arquivos de programas\Arquivos comuns\Skype
O43 - CFD: 12/3/2013 - 10:18:32 - [3,612] ----D C:\Arquivos de programas\Arquivos comuns\SpeechEngines
O43 - CFD: 14/3/2013 - 15:32:02 - [39,352] ----D C:\Arquivos de programas\Arquivos comuns\System
O43 - CFD: 3/5/2002 - 23:29:48 - [479,159] R-H-D C:\Documents and Settings\All Users\Dados de aplicativos
O43 - CFD: 3/5/2002 - 23:29:58 - [0,016] ----D C:\Documents and Settings\All Users\Desktop
O43 - CFD: 19/4/2002 - 09:50:27 - [1,654] R---D C:\Documents and Settings\All Users\Documentos
O43 - CFD: 13/3/2013 - 05:49:21 - [0,178] -SH-D C:\Documents and Settings\All Users\DRM
O43 - CFD: 12/3/2013 - 10:17:45 - [0] ----D C:\Documents and Settings\All Users\Favoritos
O43 - CFD: 2/1/2002 - 23:07:03 - [0,253] R---D C:\Documents and Settings\All Users\Menu Iniciar
O43 - CFD: 12/3/2013 - 10:17:45 - [0] --H-D C:\Documents and Settings\All Users\Modelos
O43 - CFD: 31/3/2013 - 12:19:09 - [1,467] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\Adobe
O43 - CFD: 20/4/2002 - 21:35:10 - [0,043] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\Ahead
O43 - CFD: 20/4/2002 - 17:24:33 - [0,053] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\AVG2013
O43 - CFD: 21/4/2002 - 13:11:25 - [0,000] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\DSite
O43 - CFD: 21/4/2002 - 11:44:29 - [0,021] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\HP
O43 - CFD: 12/3/2013 - 13:34:56 - [0] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\Identities
O43 - CFD: 19/4/2002 - 11:41:07 - [0,001] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\LavasoftStatistics
O43 - CFD: 13/3/2013 - 18:36:09 - [0,002] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\Macromedia
O43 - CFD: 31/3/2013 - 12:19:09 - [7,074] -S--D C:\Documents and Settings\Oddir\Dados de aplicativos\Microsoft
O43 - CFD: 13/3/2013 - 20:15:34 - [13,075] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\Mozilla
O43 - CFD: 3/5/2002 - 22:06:52 - [0,016] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\player
O43 - CFD: 19/4/2002 - 11:44:40 - [0,014] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\SecureSearch
O43 - CFD: 14/3/2013 - 14:30:20 - [2,180] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\Skype
O43 - CFD: 13/3/2013 - 17:49:43 - [0,909] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\Sun
O43 - CFD: 3/5/2002 - 22:17:09 - [0,004] ----D C:\Documents and Settings\Oddir\Dados de aplicativos\TuneUp Software
O43 - CFD: 31/3/2013 - 12:19:09 - [17,023] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Adobe
O43 - CFD: 12/3/2013 - 15:12:19 - [19,097] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Ahead
O43 - CFD: 20/4/2002 - 18:29:39 - [1,856] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Avg2013
O43 - CFD: 13/3/2013 - 20:11:24 - [396,118] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Google
O43 - CFD: 12/3/2013 - 15:12:22 - [0,508] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Identities
O43 - CFD: 20/4/2002 - 17:05:44 - [11,204] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\MFAData
O43 - CFD: 19/4/2002 - 10:09:55 - [23,897] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Microsoft
O43 - CFD: 12/3/2013 - 13:43:54 - [0] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Microsoft Help
O43 - CFD: 13/3/2013 - 20:15:23 - [15,992] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Mozilla
O43 - CFD: 13/3/2013 - 19:35:33 - [0] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\PCHealth
O43 - CFD: 13/3/2013 - 19:21:56 - [0,000] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\Sun
O43 - CFD: 3/5/2002 - 22:14:54 - [0] ----D C:\Documents and Settings\Oddir\Configurações locais\Dados de aplicativos\VDownloader
O43 - CFD: 13/3/2013 - 19:37:01 - [0,014] R---D C:\Documents and Settings\Oddir\Menu Iniciar\Programas\Acessórios
O43 - CFD: 12/3/2013 - 10:17:45 - [0,000] R---D C:\Documents and Settings\Oddir\Menu Iniciar\Programas\Inicializar
O43 - CFD: 13/3/2013 - 19:55:03 - [0,004] ----D C:\Documents and Settings\Oddir\Menu Iniciar\Programas\Programas RFB2012
O43 - CFD: 13/3/2013 - 19:55:04 - [0,004] ----D C:\Documents and Settings\Oddir\Menu Iniciar\Programas\Programas RFB2013
~ Scan Program Folder in 00mn 12s



---\\ Last modified or created files under Windows and System32 (O44)
O44 - LFC:[MD5.483924F92E55A5F9423201EC635E2CED] - 19/4/2002 - 11:41:10 ---A- . (.GFI Software - GFI Boot Time Operations Driver.) -- C:\WINDOWS\system32\Drivers\gfibto.sys [13560]
O44 - LFC:[MD5.7D7A100919F0416FAC602F5345005058] - 19/4/2002 - 11:41:11 ---A- . (.GFI Software - Boot Delete Utility.) -- C:\WINDOWS\system32\sbbd.exe [44424]
O44 - LFC:[MD5.E185BDA84E5F03F4E1D8DCA30E209277] - 20/4/2002 - 17:08:04 ---A- . (...) -- C:\WINDOWS\epplauncher.mif [1912]
O44 - LFC:[MD5.187B944F719C5915BF5C615F56C0395A] - 21/4/2002 - 11:50:19 R--A- . (.Hewlett-Packard - Hewlett-Packard WIA minidriver..) -- C:\WINDOWS\system32\hpgwiamd.dll [278528]
O44 - LFC:[MD5.D20A45796B4CBB26865085FF643A28AD] - 21/4/2002 - 11:50:22 R--A- . (.Hewlett-Packard Co. - HP AiO Scan Driver - Tulip SCL.) -- C:\WINDOWS\system32\hpotscl.dll [606208]
O44 - LFC:[MD5.97F27C8BA1B7998D34B03651D1A77F10] - 21/4/2002 - 11:50:24 R--A- . (.Hewlett-Packard Co. - HP Scan VendorSetup/Co-Installer.) -- C:\WINDOWS\system32\hpovst08.dll [258122]
O44 - LFC:[MD5.AE9D15AF3F437060A8E2C80A5D61CF72] - 21/4/2002 - 13:03:00 ---A- . (...) -- C:\WINDOWS\HpBestModeUpdatePatchLog.ini [208]
O44 - LFC:[MD5.092E3658FC760F3D9694A848CAB1E43E] - 21/4/2002 - 13:21:35 R--A- . (.360???? - 360HookOem.) -- C:\WINDOWS\system32\Drivers\360HookOem.sys [54912]
O44 - LFC:[MD5.BDECE634F62B3656DE73D51CA8EA32A9] - 21/4/2002 - 13:21:36 R--A- . (.360.cn - 360FileOem.) -- C:\WINDOWS\system32\Drivers\360FileOem.sys [146304]
O44 - LFC:[MD5.4CDB39659C17FAA5BE56AC4F89387520] - 21/4/2002 - 13:21:36 R--A- . (.360???? - 360RegOem.) -- C:\WINDOWS\system32\Drivers\360RegOem.sys [23168]
O44 - LFC:[MD5.9C40906B712F83ED4C5C8AB451B8ED38] - 22/4/2002 - 13:28:31 ---A- . (...) -- C:\WINDOWS\ydi.log [17774]
O44 - LFC:[MD5.7C5D7E80FAC9F45206D9E6CD24B13FA1] - 28/5/2002 - 08:54:40 ---A- . (...) -- C:\WINDOWS\system32\oembios.dat [4605]
O44 - LFC:[MD5.3179E2826B617282E36BFFEA83B962BE] - 28/5/2002 - 08:54:40 ---A- . (...) -- C:\WINDOWS\system32\oembios.sig [6788]
O44 - LFC:[MD5.3598A33C8DE2E13BB3F5DBD22BC8CB76] - 28/5/2002 - 08:55:42 ---A- . (...) -- C:\WINDOWS\system32\oembios.bin [13107200]
O44 - LFC:[MD5.A9DB3D4A9DBB1C66634754160FB9B15F] - 3/5/2002 - 13:25:28 ---A- . (...) -- C:\WINDOWS\system32\wpa.dbl [2278]
O44 - LFC:[MD5.C7BC96C3711C0D269DA26D1F0ECEC547] - 3/5/2002 - 13:31:12 ---A- . (...) -- C:\WINDOWS\NeroDigital.ini [69]
O44 - LFC:[MD5.F6647C0CAA99C7592EE8D3BD7E28637C] - 3/5/2002 - 16:04:52 ---A- . (...) -- C:\WINDOWS\setupact.log [186916]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 3/5/2002 - 21:42:07 ---A- . (...) -- C:\AUTOEXEC.BAT [0]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 3/5/2002 - 21:42:07 ---A- . (...) -- C:\CONFIG.SYS [0]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 3/5/2002 - 21:42:07 ---A- . (...) -- C:\WINDOWS\Sti_Trace.log [0]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 3/5/2002 - 21:42:07 ---A- . (...) -- C:\WINDOWS\control.ini [0]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 3/5/2002 - 21:42:07 ---A- . (...) -- C:\WINDOWS\setuperr.log [0]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 3/5/2002 - 21:42:08 RSHA- . (...) -- C:\IO.SYS [0]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 3/5/2002 - 21:42:08 RSHA- . (...) -- C:\MSDOS.SYS [0]
O44 - LFC:[MD5.9B08E672435DF9A832F0680A3557715E] - 3/5/2002 - 21:45:15 ---A- . (...) -- C:\WINDOWS\KB893803v2.log [709]
O44 - LFC:[MD5.AD480BC258D6D39F320192AB6F23A044] - 3/5/2002 - 22:17:31 ---A- . (.TuneUp Software - TuneUp Registry Optimization Boot Applicati.) -- C:\WINDOWS\system32\TURegOpt.exe [31584]
O44 - LFC:[MD5.B1E710193A4C7D73259253DB89A589D7] - 3/5/2002 - 23:24:28 ---A- . (...) -- C:\WINDOWS\setupapi.log [839721]
O44 - LFC:[MD5.AC281D3D057C8F3F7A0EF0D32705AEF8] - 3/5/2002 - 23:44:07 ---A- . (...) -- C:\WINDOWS\wiaservc.log [48]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 3/5/2002 - 23:48:10 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [0]
O44 - LFC:[MD5.A8713B5D4F0502BAABB17BFBCB1CA67F] - 4/5/2002 - 00:20:03 ---A- . (...) -- C:\WINDOWS\wiadebug.log [216]
O44 - LFC:[MD5.3E9AFE1A98E6F1909CD5D777439CED12] - 4/5/2002 - 04:19:31 ---A- . (...) -- C:\AdwCleaner[s2].txt [1286]
O44 - LFC:[MD5.F9490813C7DD83B001B1292E43F0CE73] - 4/5/2002 - 04:28:31 ---A- . (...) -- C:\WINDOWS\system32\PerfStringBackup.INI [1046466]
O44 - LFC:[MD5.FF32724A5E6667784A9F955E72F7E424] - 4/5/2002 - 04:28:31 ---A- . (...) -- C:\WINDOWS\system32\perfc009.dat [70174]
O44 - LFC:[MD5.7FA91334DDAFCDAE484FE4F2832CE72E] - 4/5/2002 - 04:28:31 ---A- . (...) -- C:\WINDOWS\system32\perfc016.dat [80280]
O44 - LFC:[MD5.63FD91D881B545F0234C163619374F5C] - 4/5/2002 - 04:28:31 ---A- . (...) -- C:\WINDOWS\system32\perfh009.dat [443524]
O44 - LFC:[MD5.C49588613F494BB34AAD6D4D1EF34C41] - 4/5/2002 - 04:28:31 ---A- . (...) -- C:\WINDOWS\system32\perfh016.dat [482236]
O44 - LFC:[MD5.FA033365512283E1BB18CD2777D90080] - 4/5/2002 - 04:29:15 ---A- . (...) -- C:\WINDOWS\SchedLgU.Txt [32528]
O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 4/5/2002 - 04:30:29 -S-A- . (...) -- C:\WINDOWS\bootstat.dat [2048]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 4/5/2002 - 04:32:11 ---A- . (...) -- C:\WINDOWS\0.log [0]
O44 - LFC:[MD5.546BFD1484847CBC80003BA4BACD81E9] - 4/5/2002 - 04:32:52 ---A- . (...) -- C:\WINDOWS\WindowsUpdate.log [1150525]
~ Scan Files in 00mn 05s



---\\ Operations and functions at Windows Explorer startup (O46)
O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll
O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll
~ Scan ShellExecuteHooks in 00mn 00s



---\\ Export authorized application key (O47)
O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gerenciador de sessão de ajuda de área de trabalho remota da Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE" [Enabled] .(.Microsoft Corporation - Microsoft Office Outlook.) -- C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Microsoft Office\Office12\GROOVE.EXE" [Enabled] .(.Microsoft Corporation - Microsoft Office Groove.) -- C:\Arquivos de programas\Microsoft Office\Office12\GROOVE.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Microsoft Office\Office12\ONENOTE.EXE" [Enabled] .(.Microsoft Corporation - Microsoft Office OneNote.) -- C:\Arquivos de programas\Microsoft Office\Office12\ONENOTE.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Skype\Phone\Skype.exe" [Enabled] .(.Skype Technologies S.A. - Skype.) -- C:\Arquivos de programas\Skype\Phone\Skype.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\Java\jre7\launch4j-tmp\IRPF2013.exe" [Enabled] .(.Oracle Corporation - Java Platform SE binary.) -- C:\Arquivos de programas\Java\jre7\launch4j-tmp\IRPF2013.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\AVG\AVG2013\avgnsx.exe" [Enabled] .(.AVG Technologies CZ, s.r.o. - AVG Online Shield Service.) -- C:\Arquivos de programas\AVG\AVG2013\avgnsx.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\AVG\AVG2013\avgdiagex.exe" [Enabled] .(.AVG Technologies CZ, s.r.o. - AVG Diagnostics.) -- C:\Arquivos de programas\AVG\AVG2013\avgdiagex.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\AVG\AVG2013\avgmfapx.exe" [Enabled] .(.AVG Technologies CZ, s.r.o. - AVG Installer Application.) -- C:\Arquivos de programas\AVG\AVG2013\avgmfapx.exe
O47 - AAKE:Key Export SP - "C:\Arquivos de programas\AVG\AVG2013\avgemcx.exe" [Enabled] .(.AVG Technologies CZ, s.r.o. - AVG E-mail Scanner.) -- C:\Arquivos de programas\AVG\AVG2013\avgemcx.exe
O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gerenciador de sessão de ajuda de área de trabalho remota da Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
~ Scan Keys in 00mn 00s



---\\ Local Security Authority-LSA Deny (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Mecanismo cliente do 'Editor de configuração de segurança Windows'.) -- C:\WINDOWS\system32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Kerberos Security Package.) -- C:\WINDOWS\system32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\system32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\WINDOWS\system32\wdigest.dll
~ Scan Keys in 00mn 00s



---\\ Safe Boot Control (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmboot.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmboot.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmio.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager I/O Driver.) -- C:\WINDOWS\system32\Drivers\dmio.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sr.sys . (.Microsoft Corporation - Driver de filtro do sistema de arquivos da restauração do sistema.) -- C:\WINDOWS\system32\Drivers\sr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmboot.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmboot.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmio.sys . (.Microsoft Corp., Veritas Software - NT Disk Manager I/O Driver.) -- C:\WINDOWS\system32\Drivers\dmio.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- C:\WINDOWS\system32\Drivers\dmload.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ip6fw.sys . (.Microsoft Corporation - IPv6 Windows Firewall Driver.) -- C:\WINDOWS\system32\Drivers\ip6fw.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\WINDOWS\system32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpcdd.sys . (.Microsoft Corporation - RDP Miniport.) -- C:\WINDOWS\system32\Drivers\rdpcdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpdd.sys . (...) -- C:\WINDOWS\system32\Drivers\rdpdd.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpwd.sys . (.Microsoft Corporation - RDP Terminal Stack Driver (US/Canada Only, Not for Export).) -- C:\WINDOWS\system32\Drivers\rdpwd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (...) -- C:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sr.sys . (.Microsoft Corporation - Driver de filtro do sistema de arquivos da restauração do sistema.) -- C:\WINDOWS\system32\Drivers\sr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdpipe.sys . (.Microsoft Corporation - Named Pipe Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdpipe.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdtcp.sys . (.Microsoft Corporation - TCP Transport Driver.) -- C:\WINDOWS\system32\Drivers\tdtcp.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\WINDOWS\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)
~ Scan CSB in 00mn 00s



---\\ Image File Execution Options (IFEO) (O50)
O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d
~ Scan IFEO in 00mn 00s



---\\ MountPoints2 Shell Key (MPKS) (O51) (None)

---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec de áudio DSP Group TrueSpeech para MSACM V3.50.) -- C:\WINDOWS\system32\tssoft32.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\system32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (...) -- C:\WINDOWS\system32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\WINDOWS\system32\ir41_32.ax
O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm
O52 - TDSD: \Drivers32\"msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\WINDOWS\system32\ir50_32.dll
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\system32\sl_anet.acm
O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \drivers.desc\"C:\WINDOWS\system32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\system32\l3codeca.acm
~ Scan Keys in 00mn 00s



---\\ ShareTools MSconfig StartupReg (SMSR) (O53) (None)

---\\ Microsoft Control Security Providers (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Cliente DPA para plataformas de 32 bits.) -- C:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Digest SSPI Authentication Package.) -- C:\WINDOWS\system32\digest.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Cliente DPA para plataformas de 32 bits.) -- C:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Digest SSPI Authentication Package.) -- C:\WINDOWS\system32\digest.dll
~ Scan Keys in 00mn 00s



---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
~ Scan Keys in 00mn 00s



---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
~ Scan Keys in 00mn 00s



---\\ System Drivers List (SDL) (O58)
O58 - SDL:[MD5.BDECE634F62B3656DE73D51CA8EA32A9] - 31/5/2012 - 21:21:04 R--A- . (.360.cn - 360FileOem.) -- C:\WINDOWS\system32\Drivers\360FileOem.sys [146304]
O58 - SDL:[MD5.C1E76718BAB6BCA0D18E5670F074F821] - 4/8/2004 - 03:00:00 ---A- . (...) -- C:\WINDOWS\system32\ansi.sys [9032]
~ Scan Drivers in 00mn 00s



---\\ List all tools cleaner (LATC) (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ Scan ADS in 00mn 00s



---\\ List all legacy services(LALS) (O64)
O64 - Services: CurCS - 31/5/2012 - C:\WINDOWS\system32\drivers\360HookOem.sys (360HookOem) .(.360???? - 360HookOem.) - LEGACY_360HOOKOEM
O64 - Services: CurCS - 13/3/2013 - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (AdobeFlashPlayerUpdateSvc) .(.Adobe Systems Incorporated - Adobe® Flash® Player Update Service 11.6 r6.) - LEGACY_ADOBEFLASHPLAYERUPDATESVC
O64 - Services: CurCS - 13/3/2013 - C:\WINDOWS\system32\drivers\AsIO.sys - AsIO (AsIO) .(...) - LEGACY_ASIO
O64 - Services: CurCS - 13/3/2013 - C:\WINDOWS\system32\drivers\AsUpIO.sys - AsUpIO (AsUpIO) .(...) - LEGACY_ASUPIO
O64 - Services: CurCS - 27/2/2013 - C:\Arquivos de programas\AVG\AVG2013\avgidsagent.exe (AVGIDSAgent) .(.AVG Technologies CZ, s.r.o. - AVG Identity Protection Service.) - LEGACY_AVGIDSAGENT
O64 - Services: CurCS - 26/2/2013 - C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys (AVGIDSDriver) .(.AVG Technologies CZ, s.r.o. - IDS Application Activity Monitor Driver..) - LEGACY_AVGIDSDRIVER
O64 - Services: CurCS - 8/2/2013 - C:\WINDOWS\system32\DRIVERS\avgidshx.sys (AVGIDSHX) .(.AVG Technologies CZ, s.r.o. - IDS Application Activity Monitor Helper Dri.) - LEGACY_AVGIDSHX
O64 - Services: CurCS - 1/3/2013 - C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys (AVGIDSShim) .(.AVG Technologies CZ, s.r.o. - IDS Application Activity Monitor Loader Dri.) - LEGACY_AVGIDSSHIM
O64 - Services: CurCS - 8/2/2013 - C:\WINDOWS\system32\DRIVERS\avgldx86.sys (Avgldx86) .(.AVG Technologies CZ, s.r.o. - AVG AVI Loader Driver.) - LEGACY_AVGLDX86
O64 - Services: CurCS - 8/2/2013 - C:\WINDOWS\system32\DRIVERS\avglogx.sys (Avglogx) .(.AVG Technologies CZ, s.r.o. - AVG Logging Driver.) - LEGACY_AVGLOGX
O64 - Services: CurCS - 8/2/2013 - C:\WINDOWS\system32\DRIVERS\avgmfx86.sys (Avgmfx86) .(.AVG Technologies CZ, s.r.o. - AVG Resident Shield Minifilter Driver.) - LEGACY_AVGMFX86
O64 - Services: CurCS - 8/2/2013 - C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (Avgrkx86) .(.AVG Technologies CZ, s.r.o. - AVG Anti-Rootkit Driver.) - LEGACY_AVGRKX86
O64 - Services: CurCS - 14/2/2013 - C:\WINDOWS\system32\DRIVERS\avgtdix.sys (Avgtdix) .(.AVG Technologies CZ, s.r.o. - AVG Network connection watcher.) - LEGACY_AVGTDIX
O64 - Services: CurCS - 19/2/2013 - C:\Arquivos de programas\AVG\AVG2013\avgwdsvc.exe (avgwd) .(.AVG Technologies CZ, s.r.o. - AVG Watchdog Service.) - LEGACY_AVGWD
O64 - Services: CurCS - 13/4/2008 - C:\WINDOWS\system32\dllhost.exe (COMSysApp) .(.Microsoft Corporation - COM Surrogate.) - LEGACY_COMSYSAPP
O64 - Services: CurCS - ??\??\???? - (DcomLaunch) .(. - .) - LEGACY_DCOMLAUNCH
O64 - Services: CurCS - 13/4/2008 - C:\WINDOWS\system32\drivers\dmboot.sys (dmboot) .(.Microsoft Corp., Veritas Software - NT Disk Manager Startup Driver.) - LEGACY_DMBOOT
O64 - Services: CurCS - 4/8/2004 - C:\WINDOWS\system32\drivers\dmload.sys (dmload) .(.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) - LEGACY_DMLOAD
O64 - Services: CurCS - 19/4/2002 - C:\WINDOWS\system32\drivers\gfibto.sys (gfibto) .(.GFI Software - GFI Boot Time Operations Driver.) - LEGACY_GFIBTO
O64 - Services: CurCS - 13/3/2013 - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe (gupdate) .(.Google Inc. - Google Installer.) - LEGACY_GUPDATE
O64 - Services: CurCS - 13/3/2013 - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe (gupdatem) .(.Google Inc. - Google Installer.) - LEGACY_GUPDATEM
O64 - Services: CurCS - 13/3/2013 - C:\Arquivos de programas\Java\jre7\bin\jqs.exe (JavaQuickStarterService) .(.Oracle Corporation - Java Quick Starter Service.) - LEGACY_JAVAQUICKSTARTERSERVICE
O64 - Services: CurCS - 16/5/2007 - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (NMIndexingService) .(.Nero AG - Nero Home.) - LEGACY_NMINDEXINGSERVICE
O64 - Services: CurCS - 26/1/2010 - C:\WINDOWS\system32\drivers\npf.sys (npf) .(.CACE Technologies, Inc. - npf.sys (NT5/6 x86) Kernel Driver.) - LEGACY_NPF
O64 - Services: CurCS - ??\??\???? - (RpcSs) .(. - .) - LEGACY_RPCSS
O64 - Services: CurCS - 28/2/2013 - C:\Arquivos de programas\Skype\Updater\Updater.exe (SkypeUpdate) .(.Skype Technologies - Skype Updater Service.) - LEGACY_SKYPEUPDATE
O64 - Services: CurCS - ??\??\???? - (TermService) .(. - .) - LEGACY_TERMSERVICE
O64 - Services: CurCS - 30/11/2012 - C:\Arquivos de programas\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (TuneUp.UtilitiesSvc) .(.TuneUp Software - TuneUp Utilities Service.) - LEGACY_TUNEUP.UTILITIESSVC
O64 - Services: CurCS - 16/11/2012 - C:\Arquivos de programas\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys (TuneUpUtilitiesDrv) .(.TuneUp Software - TuneUp Utilities Driver.) - LEGACY_TUNEUPUTILITIESDRV
~ Scan Services in 00mn 00s



---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Arquivos de programas\Internet Explorer\IEXPLORE.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\WINDOWS\regedit.exe
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL comum do Shell do Windows.) -- C:\WINDOWS\system32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCR\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\WINDOWS\system32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Editor do Registro.) -- C:\WINDOWS\regedit.exe
~ Scan Keys in 00mn 00s



---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: <chrome.exe> <>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Arquivos de programas\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe (.not file.)
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\WINDOWS\system32\ie4uinit.exe (.not file.)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe (.not file.)
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\WINDOWS\system32\ie4uinit.exe (.not file.)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe (.not file.)
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Arquivos de programas\Google\Chrome\Application\chrome.exe (.not file.)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\WINDOWS\system32\ie4uinit.exe (.not file.)
~ Scan Keys in 00mn 00s



---\\ Search Browser Infection (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (@ieframe.dll,-12512) - http://www.bing.com
~ Scan Keys in 00mn 00s



---\\ Search Svchost Services (SSS) (O83)
O83 - Search Svchost Services: AppMgmt (AppMgmt) . (...) -- C:\WINDOWS\system32\appmgmts.dll [0]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\WINDOWS\system32\audiosrv.dll [42496]
O83 - Search Svchost Services: Browser (Browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\WINDOWS\system32\browser.dll [78336]
O83 - Search Svchost Services: CryptSvc (CryptSvc) . (.Microsoft Corporation - Cryptographic Services.) -- C:\WINDOWS\system32\cryptsvc.dll [62464]
O83 - Search Svchost Services: DMServer (DMServer) . (.Microsoft Corp. - Dll do serviço do Gerenciador de discos lógicos.) -- C:\WINDOWS\system32\dmserver.dll [23552]
O83 - Search Svchost Services: DHCP (DHCP) . (.Microsoft Corporation - Serviço do Cliente DHCP.) -- C:\WINDOWS\system32\dhcpcsvc.dll [126976]
O83 - Search Svchost Services: ERSvc (ERSvc) . (.Microsoft Corporation - Windows Error Reporting Service.) -- C:\WINDOWS\system32\ersvc.dll [23040]
O83 - Search Svchost Services: EventSystem (EventSystem) . (.Microsoft Corporation - No comment.) -- C:\WINDOWS\system32\es.dll [253952]
O83 - Search Svchost Services: FastUserSwitchingCompatibility (FastUserSwitchingCompatibility) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\WINDOWS\system32\shsvcs.dll [135168]
O83 - Search Svchost Services: HidServ (HidServ) . (...) -- C:\WINDOWS\system32\hidserv.dll [0]
O83 - Search Svchost Services: LanmanServer (LanmanServer) . (.Microsoft Corporation - Server Service DLL.) -- C:\WINDOWS\system32\srvsvc.dll [99840]
O83 - Search Svchost Services: LanmanWorkstation (LanmanWorkstation) . (.Microsoft Corporation - Workstation Service DLL.) -- C:\WINDOWS\system32\wkssvc.dll [132096]
O83 - Search Svchost Services: Messenger (Messenger) . (.Microsoft Corporation - NT Messenger Service.) -- C:\WINDOWS\system32\msgsvc.dll [33792]
O83 - Search Svchost Services: Netman (Netman) . (.Microsoft Corporation - Gerenciador de conexões de rede.) -- C:\WINDOWS\system32\netman.dll [198144]
O83 - Search Svchost Services: Nla (Nla) . (.Microsoft Corporation - Fornecedor de serviços do Microsoft Windows Sockets 2.0.) -- C:\WINDOWS\system32\mswsock.dll [247808]
O83 - Search Svchost Services: Ntmssvc (Ntmssvc) . (.Microsoft Corporation - Gerenciador de armazenamento removível.) -- C:\WINDOWS\system32\ntmssvc.dll [437248]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\WINDOWS\system32\rasauto.dll [88576]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\WINDOWS\system32\rasmans.dll [186368]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\WINDOWS\system32\mprdim.dll [53248]
O83 - Search Svchost Services: Schedule (Schedule) . (.Microsoft Corporation - Mecanismo do 'Agendador de tarefas'.) -- C:\WINDOWS\system32\schedsvc.dll [193536]
O83 - Search Svchost Services: Seclogon (Seclogon) . (.Microsoft Corporation - DLL de serviço de logon secundário.) -- C:\WINDOWS\system32\seclogon.dll [18944]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\WINDOWS\system32\sens.dll [39424]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Componentes do Microsoft NAT Helper.) -- C:\WINDOWS\system32\ipnathlp.dll [331264]
O83 - Search Svchost Services: SRService (SRService) . (.Microsoft Corporation - Serviço de restauração do sistema.) -- C:\WINDOWS\system32\srsvc.dll [171520]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Servidor de telefonia do Microsoft® Windows.) -- C:\WINDOWS\system32\tapisrv.dll [249856]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\WINDOWS\system32\shsvcs.dll [135168]
O83 - Search Svchost Services: TrkWks (TrkWks) . (.Microsoft Corporation - Distributed Link Tracking Client.) -- C:\WINDOWS\system32\trkwks.dll [90112]
O83 - Search Svchost Services: W32Time (W32Time) . (.Microsoft Corporation - Windows Time Service.) -- C:\WINDOWS\system32\w32time.dll [176128]
O83 - Search Svchost Services: WZCSVC (WZCSVC) . (.Microsoft Corporation - Serviço de configuração zero sem fio.) -- C:\WINDOWS\system32\wzcsvc.dll [483840]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\WINDOWS\system32\wbem\WMIsvc.dll [145408]
O83 - Search Svchost Services: wscsvc (wscsvc) . (.Microsoft Corporation - Windows Security Center Service.) -- C:\WINDOWS\system32\wscsvc.dll [80896]
O83 - Search Svchost Services: xmlprov (xmlprov) . (.Microsoft Corporation - Network Provisioning Service.) -- C:\WINDOWS\system32\xmlprov.dll [129024]
O83 - Search Svchost Services: napagent (napagent) . (.Microsoft Corporation - Tempo de Execução de Serviço de Agente de Quarentena.) -- C:\WINDOWS\system32\qagentrt.dll [292864]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Serviço de Gerenciamento de Chaves.) -- C:\WINDOWS\system32\kmsvc.dll [61440]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Serviço de transferência inteligente de plano de fundo.) -- C:\WINDOWS\system32\qmgr.dll [409088]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update AutoUpdate Service.) -- C:\WINDOWS\system32\wuauserv.dll [6656]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - DLL de serviços do Shell do Windows.) -- C:\WINDOWS\system32\shsvcs.dll [135168]
O83 - Search Svchost Services: helpsvc (helpsvc) . (.Microsoft Corporation - Microsoft PCHealth Service Holder.) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400]
O83 - Search Svchost Services: WmdmPmSN (WmdmPmSN) . (.Microsoft Corporation - Microsoft Media Device Service Provider.) -- C:\WINDOWS\system32\MsPMSNSv.dll [27136]
~ Scan Services in 00mn 00s



---\\ Search Particular Root Folder (SPRF) (O84)
[MD5.8B078DA370299FED373C92AD98C0C7AD] [sPRF][3/5/2002] (...) -- C:\Documents and Settings\Oddir\Desktop\FlashPlayer.exe [436400]
[MD5.00E22B3ED82BB39750CCE10316380192] [sPRF][1/1/2002] (.Serpro - Serviço Federal de Processamento d - Instalador do Receitanet 1.03.) -- C:\Documents and Settings\Oddir\Desktop\Receitanet-1.03.exe [6182539]
[MD5.2AFD80A8ED202E8118575F524BF85AC0] [sPRF][3/5/2002] (...) -- C:\Documents and Settings\Oddir\Desktop\VDownloaderInstallerIC.exe [665816]
[MD5.AE326A97F634217CAC29739D376DF934] [sPRF][15/8/2011] (...) -- C:\Documents and Settings\Oddir\Desktop\ZHP_uninstall.exe [344187]
~ Scan Files in 00mn 00s



---\\ Router Hijack DNS (O89) (None)

---\\ General States of Services not Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 13/3/2013 253656 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SR - | Auto 27/2/2013 4937264 | (AVGIDSAgent) . (.AVG Technologies CZ, s.r.o..) - C:\Arquivos de programas\AVG\AVG2013\avgidsagent.exe
SR - | Auto 19/2/2013 282624 | (avgwd) . (.AVG Technologies CZ, s.r.o..) - C:\Arquivos de programas\AVG\AVG2013\avgwdsvc.exe
SS - | Demand 13/4/2008 225280 | (dmadmin) . (.Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\dmadmin.exe
SS - | Auto 13/3/2013 116648 | (gupdate) . (.Google Inc..) - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
SS - | Demand 13/3/2013 116648 | (gupdatem) . (.Google Inc..) - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
SR - | Auto 13/3/2013 170912 | (JavaQuickStarterService) . (.Oracle Corporation.) - C:\Arquivos de programas\Java\jre7\bin\jqs.exe
SS - | Demand 7/3/2013 115608 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 13/4/2007 792112 | (NBService) . (.Nero AG.) - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe
SR - | Demand 16/5/2007 271920 | (NMIndexingService) . (.Nero AG.) - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
SS - | Auto 0 | (PSafeSVC) . (...) - C:\Arquivos de programas\PSafe\PSafesvc.exe
SS - | Auto 28/2/2013 161384 | (SkypeUpdate) . (.Skype Technologies.) - C:\Arquivos de programas\Skype\Updater\Updater.exe
SR - | Auto 30/11/2012 1723744 | (TuneUp.UtilitiesSvc) . (.TuneUp Software.) - C:\Arquivos de programas\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
~ Scan Services in 00mn 03s



---\\ Search Master Boot Record Infection (MBR)(O80) (None)

---\\ Search Master Boot Record Infection (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog
Run by Oddir at 4/5/2002 04:43:17

********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ Scan MBR in 00mn 04s



End of the scan (1247 lines in 00mn 53s)(0)



http://pjjoint.malekal.com/files.php?read=ZHPDiag_20130504_f9s5y14m15f6

Compartilhar este post


Link para o post
Compartilhar em outros sites
Bom Dia! LFABER


|- Feche programas/pastas que estejam abertas.

|- Feche,também,o navegador!



ZHPFix_silent_zps532d2db6.jpg


|- Para Windows Vista ou 7,clique direito em ZHPFix.exe e execute-o como administrador.

|- Selecione e copie estas informações,que estão no Code,para o "Bloco de Notas".


[MD5.E715412E47D20EB0EBF77B65F9157343] - (...) -- ystem32\RunDll32.exe   [0] [PID.]
M3 - MFPP: Plugins - [Oddir] -- C:\Arquivos de programas\Mozilla FireFox\searchplugins\portaldosites.xml
O2 - BHO: (no name) - {44C9CC91-6A4A-4579-B4B5-899ECDC18DC6} Orphean Key
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} Orphean Key
O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} Orphean Key
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} Orphean Key
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} Orphean Key
O4 - HKLM\..\Run: [SearchProtection] C:\Documents and Settings\All Users\Dados de aplicativos\Search Protection\_run.bat (.not file.)
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\NETESITE.lnk - Orphean Key
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ODADIR.lnk - Orphean Key
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\NETESITE.lnk - Orphean Key
O4 - Global Startup: C:\Documents And Settings\All Users\Desktop\ODADIR.lnk - Orphean Key
O23 - Service: PSafeSVC (PSafeSVC) . (...) - C:\Arquivos de programas\PSafe\PSafesvc.exe (.not file.)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Ad-Aware Antivirus Scheduled Scan.job
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\FindLyrics Update.job
O42 - Logiciel: FindLyrics - (.FindLyrics.) [HKLM] -- findlyrics@findlyrics.co
O43 - CFD: 3/5/2002 - 22:12:01 - [0,382] ----D C:\Arquivos de programas\FindLyrics
O44 - LFC:[MD5.9C40906B712F83ED4C5C8AB451B8ED38] - 22/4/2002 - 13:28:31 ---A- . (...) -- C:\WINDOWS\ydi.log [17774]
O44 - LFC:[MD5.3E9AFE1A98E6F1909CD5D777439CED12] - 4/5/2002 - 04:19:31 ---A- . (...) -- C:\AdwCleaner[S2].txt [1286]
O64 - Services: CurCS - 13/3/2013 - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe (gupdate) .(.Google Inc. - Google Installer.) - LEGACY_GUPDATE
O64 - Services: CurCS - 13/3/2013 - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe (gupdatem) .(.Google Inc. - Google Installer.) - LEGACY_GUPDATEM

[HKCU\Software\Ad-Aware Search Protection]
[HKCU\Software\b1.org]
[HKCU\Software\findlyrics]
[HKLM\Software\360Safe]
[HKLM\Software\b1.org]

proxyfix
emptytemp
emptyclsid
emptyflash
firewallraz
sysrestore

|- Estando com o Bloco de Notas aberto,acione os atalhos: "Ctrl+A" -> "Ctrl+C"

|- Minimize o Bloco de Notas.


ZHPDiag_PasteClipboard.jpg


|- Clique no menu,"Paste ClipBoard".




|- Clique "GO" -> Oui.


ZHPFix_GO.jpg


|- Ps: Temos,àcima,sequência de imagens para maior exclarecimento.

|- Poste o relatório: C:\ZHP\ZHPFix[R1].txt


A+

Compartilhar este post


Link para o post
Compartilhar em outros sites

Rapport de ZHPFix 1.3.05 par Nicolas Coolman, Update du 09/10/2012
Fichier d'export Registre : C:\ZHP\ZHPExportRegistry-5-5-2002-00-42-11.txt
Run by Oddir at 5/5/2002 00:42:11
Windows XP Home Edition Service Pack 3 (Build 2600)
Web site : http://nicolascoolman.skyrock.com/



========== Software ==========
NOT FOUND Software Key: findlyrics@findlyrics.co

========== Registry Key ==========
NOT FOUND Key: CLSID BHO: {44C9CC91-6A4A-4579-B4B5-899ECDC18DC6}
NOT FOUND Key: CLSID BHO: {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
NOT FOUND Key: CLSID BHO: {72853161-30C5-4D22-B7F9-0BBC1D38A37E}
NOT FOUND Key: CLSID BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
NOT FOUND Key: CLSID BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9}
NOT FOUND Key: Service: PSafeSVC
ERROR Key: Service Legacy: LEGACY_GUPDATE
ERROR Key: Service Legacy: LEGACY_GUPDATEM
NOT FOUND Key: HKCU\Software\Ad-Aware Search Protection
NOT FOUND Key: HKCU\Software\b1.org
NOT FOUND Key: HKCU\Software\findlyrics
NOT FOUND Key: HKLM\Software\360Safe
NOT FOUND Key: HKLM\Software\b1.org

========== Registry Value ==========
NOT FOUND RunValue: SearchProtection
ProxyFix : Proxy killed successfully
DELETED ProxyServer Value
DELETED ProxyEnable Value
DELETED EnableHttp1_1 Value
DELETED ProxyHttp1.1 Value
DELETED ProxyOverride Value
No Value in Domain Profile Register Key FirewallRaz :
No Value in Firewall Exception Register Key (FirewallRaz)

========== Repertory ==========
DELETED Flash Cookies:

========== File ==========
NOT FOUND File: c:\arquivos de programas\mozilla firefox\searchplugins\portaldosites.xml
NOT FOUND File: c:\documents and settings\all users\dados de aplicativos\search protection\_run.bat
NOT FOUND File: c:\documents and settings\all users\desktop\netesite.lnk
NOT FOUND File: c:\documents and settings\all users\desktop\odadir.lnk
NOT FOUND File: c:\arquivos de programas\psafe\psafesvc.exe
NOT FOUND File: c:\windows\tasks\ad-aware antivirus scheduled scan.job
NOT FOUND File: c:\windows\tasks\findlyrics update.job
NOT FOUND File: c:\windows\ydi.log
NOT FOUND File: c:\adwcleaner[s2].txt
DELETED Window Temporary:
DELETED Flash Cookies:

========== Restoration ==========
Restore System Point created succefully

========== Other ==========
NOT SUPPORTED ystem32\RunDll32.exe


========== Summary ==========
13 : Registry Key
9 : Registry Value
1 : Repertory
11 : File
1 : Software
1 : Restoration
1 : Other


End of clean in 00mn 04s

========== Report File ==========
C:\ZHP\ZHPFix[R1].txt - 5/5/2002 00:08:31 [388]
C:\ZHP\ZHPFix[R2].txt - 5/5/2002 00:40:47 [2871]
C:\ZHP\ZHPFix[R3].txt - 5/5/2002 00:42:11 [2631]



DigRam ,

vejamos se eu segui os passos corretamente :rolleyes: !!

 

Abs,

LFABER

Compartilhar este post


Link para o post
Compartilhar em outros sites
Boa Tarde! LFABER




DelFix_SetaVerde.jpg


|- Estando na página,clique na seta verde para o download.

|- Salve-a em um local conveniente! ( desktop! )

|- Feche aplicativos que estejam abertos.




|- Execute-a!

|- Com as duas checkbox marcadas!

|- Clique "Run".

|- As propagandas,ainda,lhe incomodam?


Abs!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oi DigRam,

 

Aqui vai o relatório do DELFIX:

# DelFix v10.2 - Logfile created 05/05/2002 at 21:39:40
# Updated 02/04/2013 by Xplode
# Username : Oddir - ODADIR-PC

~ Removing disinfection tools ...

Deleted : C:\ZHP
Deleted : C:\Arquivos de programas\ZHPDiag
Deleted : C:\PhysicalDisk0_MBR.bin
Deleted : C:\Documents and Settings\Oddir\Meus documentos\Downloads\adwcleaner.exe
Deleted : C:\Documents and Settings\Oddir\Meus documentos\Downloads\ZHPDiag_silent.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1

~ Cleaning system restore ...

Deleted : RP #1 [Ponto de verificação do sistema | 03/12/2013 16:35:07]
Deleted : RP #2 [installed Microsoft Office Enterprise 2007 | 03/12/2013 16:43:29]
Deleted : RP #3 [Driver de impressão Send To Microsoft OneNote Driver instalado | 03/12/2013 16:47:21]
Deleted : RP #4 [DirectX instalado | 03/12/2013 18:06:40]
Deleted : RP #5 [instalado Nero 7 Premium | 03/12/2013 18:07:16]
Deleted : RP #6 [software Distribution Service 3.0 | 03/13/2013 05:01:35]
Deleted : RP #7 [software Distribution Service 3.0 | 03/13/2013 08:47:22]
Deleted : RP #8 [software Distribution Service 3.0 | 03/13/2013 10:47:42]
Deleted : RP #9 [instalado Java 7 Update 17 | 03/13/2013 21:30:40]
Deleted : RP #10 [installed ASUSUpdate | 03/13/2013 22:04:37]
Deleted : RP #11 [Removed Iminent Toolbar For Internet Explorer | 03/13/2013 22:20:26]
Deleted : RP #12 [Removed ASUSUpdate | 03/13/2013 22:20:55]
Deleted : RP #13 [Operação de restauração | 03/13/2013 22:35:34]
Deleted : RP #14 [Configured Microsoft Office Enterprise 2007 | 03/13/2013 22:41:08]
Deleted : RP #15 [Operação de restauração | 03/13/2013 22:49:48]
Deleted : RP #16 [software Distribution Service 3.0 | 03/13/2013 23:29:25]
Deleted : RP #17 [software Distribution Service 3.0 | 03/14/2013 03:44:45]
Deleted : RP #18 [software Distribution Service 3.0 | 03/14/2013 10:49:01]
Deleted : RP #19 [software Distribution Service 3.0 | 03/14/2013 18:31:24]
Deleted : RP #20 [software Distribution Service 3.0 | 03/15/2013 01:08:16]
Deleted : RP #21 [software Distribution Service 3.0 | 03/16/2013 01:45:44]
Deleted : RP #22 [software Distribution Service 3.0 | 03/17/2013 01:50:12]
Deleted : RP #23 [software Distribution Service 3.0 | 03/17/2013 02:39:13]
Deleted : RP #24 [software Distribution Service 3.0 | 03/19/2013 20:46:45]
Deleted : RP #25 [software Distribution Service 3.0 | 03/24/2013 01:09:26]
Deleted : RP #26 [Ponto de verificação do sistema | 01/01/2002 03:41:57]
Deleted : RP #27 [software Distribution Service 3.0 | 03/25/2013 01:54:11]
Deleted : RP #28 [software Distribution Service 3.0 | 03/26/2013 20:14:43]
Deleted : RP #29 [software Distribution Service 3.0 | 03/28/2013 01:50:34]
Deleted : RP #30 [software Distribution Service 3.0 | 03/30/2013 14:31:15]
Deleted : RP #31 [software Distribution Service 3.0 | 03/31/2013 15:09:44]
Deleted : RP #32 [software Distribution Service 3.0 | 04/02/2013 01:39:48]
Deleted : RP #33 [software Distribution Service 3.0 | 04/02/2013 02:29:35]
Deleted : RP #34 [software Distribution Service 3.0 | 04/02/2013 23:47:41]
Deleted : RP #35 [software Distribution Service 3.0 | 04/05/2013 01:48:26]
Deleted : RP #36 [software Distribution Service 3.0 | 04/07/2013 12:43:08]
Deleted : RP #37 [software Distribution Service 3.0 | 04/07/2013 14:29:36]
Deleted : RP #38 [software Distribution Service 3.0 | 04/10/2013 02:02:19]
Deleted : RP #39 [Ponto de verificação do sistema | 01/01/2002 03:32:30]
Deleted : RP #40 [software Distribution Service 3.0 | 04/14/2013 21:07:14]
Deleted : RP #41 [software Distribution Service 3.0 | 04/15/2013 02:01:22]
Deleted : RP #42 [software Distribution Service 3.0 | 04/16/2013 11:30:32]
Deleted : RP #43 [Ponto de verificação do sistema | 04/17/2013 11:47:32]
Deleted : RP #44 [software Distribution Service 3.0 | 04/17/2013 17:16:23]
Deleted : RP #45 [software Distribution Service 3.0 | 04/18/2013 18:47:36]
Deleted : RP #46 [Removed Ad-Aware Antivirus. | 04/20/2002 19:37:52]
Deleted : RP #47 [instalado AVG 2013 | 04/20/2002 20:19:32]
Deleted : RP #48 [instalado AVG 2013 | 04/20/2002 20:19:49]
Deleted : RP #49 [installed HighMAT Extension to Microsoft Windows XP CD Writing Wizard | 04/21/2002 01:12:11]
Deleted : RP #50 [Ponto de verificação do sistema | 04/22/2002 12:11:12]
Deleted : RP #51 [instalado Marvell Miniport Driver | 04/22/2002 16:28:15]
Deleted : RP #52 [Ponto de verificação do sistema | 01/01/2002 03:40:17]
Deleted : RP #53 [Ponto de verificação do sistema | 01/01/2002 02:22:29]
Deleted : RP #54 [Ponto de verificação do sistema | 01/02/2002 02:37:32]
Deleted : RP #55 [Driver de impressora não assinado hp instant share instalado. | 01/02/2002 03:05:05]
Deleted : RP #56 [Driver de impressora não assinado hp instant share instalado. | 01/02/2002 03:07:41]
Deleted : RP #57 [Driver de impressora não assinado hp instant share instalado. | 01/02/2002 03:10:11]
Deleted : RP #58 [Driver de impressora não assinado hp instant share instalado. | 01/02/2002 03:13:48]
Deleted : RP #59 [Ponto de verificação do sistema | 01/03/2002 03:48:17]
Deleted : RP #60 [Ponto de verificação do sistema | 05/03/2002 18:19:59]
Deleted : RP #61 [Quitado VAFPlayer | 05/04/2002 01:06:42]
Deleted : RP #62 [software Distribution Service 3.0 | 05/04/2002 07:19:05]
Deleted : RP #63 [P | 05/05/2002 03:40:43]
Deleted : RP #64 [P | 05/05/2002 03:42:11]
Deleted : RP #65 [Removido TuneUp Utilities 2013 | 05/06/2002 00:31:02]
Deleted : RP #66 [Removido TuneUp Utilities Language Pack (pt-BR) | 05/06/2002 00:31:41]
Deleted : RP #67 [Removido AVG 2013 | 05/06/2002 00:33:55]
Deleted : RP #68 [Removido AVG 2013 | 05/06/2002 00:35:50]

New restore point created !

########## - EOF - ##########

 

As propagandas não continuam e muitas outras limpesas creio que foram efetuadas!!!

Fico muito grata e te desejo um ano produtivo!!

Felicidades!!

LFABER

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.