Pry
Topic Starter
Evening,
My browser was seeeeriously slow and sometimes blocking my computer totally. PC is only a few months old which made me suspicious something was wrong. I have to admit due to laziness I didnt update NOD32 for a while, so I had no real antivirus running at all. I updated NOD32 and after scanning it found the trojan on title, but cant clean it or treat it ofc. MSPAHOST.DLL is the infected file that NOD32 keeps popping up with, tho there are 21 infected files according to it, not all from same tho.
Here are the logs:
OTL LOG:
OTL logfile created on: 28-12-2011 23:58:59 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Nery\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy
2,97 Gb Total Physical Memory | 1,25 Gb Available Physical Memory | 42,29% Memory free
5,93 Gb Paging File | 4,09 Gb Available in Paging File | 69,03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453,66 Gb Total Space | 311,37 Gb Free Space | 68,64% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive J: | 534,43 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive K: | 616,23 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive L: | 462,84 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive M: | 579,67 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: DESKTOP | User Name: Nery | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Nery\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (DT Soft Ltd)
PRC - C:\Programas\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (ESET)
PRC - C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Programas\eMachines\eMachines Updater\UpdaterService.exe (Acer)
PRC - C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\mspahost.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (EhttpSrv) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV:64bit: - (ekrn) – C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (ESET)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Macromedia Licensing Service) – C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (npggsvc) – C:\Windows\SysWow64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Greg_Service) – C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (Updater Service) – C:\Programas\eMachines\eMachines Updater\UpdaterService.exe (Acer)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (EuMusDesignVirtualAudioCableWdm) Virtual Audio Cable (WDM) – C:\Windows\SysNative\drivers\vrtaucbl.sys (Eugene V. Muzychenko)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (epfwwfpr) – C:\Windows\SysNative\drivers\epfwwfpr.sys (ESET)
DRV:64bit: - (ehdrv) – C:\Windows\SysNative\drivers\ehdrv.sys (ESET)
DRV:64bit: - (eamon) – C:\Windows\SysNative\drivers\eamon.sys (ESET)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (1394hub) – C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
DRV:64bit: - (netr7364) – C:\Windows\SysNative\drivers\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (PAC207) – C:\Windows\SysNative\drivers\PFC027.SYS (PixArt Imaging Inc.)
DRV - (cpudrv64) – C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (PAC207) – C:\Windows\SysWOW64\drivers\PFC027.sys (PixArt Imaging Inc.)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Nery\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Nery\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Nery\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Nery\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011-06-21 02:38:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011-12-27 01:22:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011-10-28 18:23:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011-03-23 20:45:25 | 000,000,000 | —D | M]
[2011-12-27 01:23:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Nery\AppData\Roaming\mozilla\Extensions
[2011-12-28 22:31:33 | 000,000,000 | —D | M] (No name found) – C:\Users\Nery\AppData\Roaming\mozilla\Firefox\Profiles\hnalx0c0.default\extensions
[2011-12-28 22:31:33 | 000,000,000 | —D | M] (BitDefender QuickScan) – C:\Users\Nery\AppData\Roaming\mozilla\Firefox\Profiles\hnalx0c0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2011-12-27 01:22:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\mozilla firefox\extensions
[2011-12-16 23:01:52 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011-12-21 08:04:32 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011-02-02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011-12-21 05:10:22 | 000,001,525 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011-12-21 05:10:22 | 000,001,529 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\priberam.xml
[2011-12-21 05:10:22 | 000,002,071 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\sapo.xml
[2011-12-21 05:10:22 | 000,000,942 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-ptpt.xml
O1 HOSTS File: ([2009-06-10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Monitor] C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe (NEXON Inc.)
O4 - HKCU..\Run: [PlayNC Launcher] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{10377748-9BDA-4EF9-9AC7-53A0E6A3A86C}: DhcpNameServer = 192.168.1.254 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{401A86F1-6A29-4A62-B436-1C95B5E24BA5}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{42599A28-12DB-4C3B-AE8D-5AA6374FEE3C}: DhcpNameServer = 192.168.1.254 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{475446E1-C539-479D-9300-68736E9B13BE}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005-05-18 23:59:05 | 000,000,228 | R— | M] () - J:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2005-07-05 23:05:52 | 001,019,904 | R— | M] (Microsoft Corporation) - J:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2005-05-11 20:22:44 | 000,000,066 | R— | M] () - K:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2005-05-11 20:22:59 | 000,000,066 | R— | M] () - L:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2005-05-27 23:20:11 | 000,000,066 | R— | M] () - M:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{6174142e-dbba-11e0-8d78-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{6174142e-dbba-11e0-8d78-4487fc68dd18}\Shell\AutoRun\command - "" = I:\Autorun.exe
O33 - MountPoints2\{76f1d766-879b-11e0-a95e-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{76f1d766-879b-11e0-a95e-4487fc68dd18}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{86342249-2e59-11e1-ac7c-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{86342249-2e59-11e1-ac7c-4487fc68dd18}\Shell\AutoRun\command - "" = J:\autorun.exe – [2005-07-05 23:05:52 | 001,019,904 | R— | M] (Microsoft Corporation)
O33 - MountPoints2\{86342249-2e59-11e1-ac7c-4487fc68dd18}\Shell\directx\command - "" = J:\directx9\DXSETUP.exe – [2005-03-19 01:19:41 | 000,480,976 | R— | M] (Microsoft Corporation)
O33 - MountPoints2\{86342249-2e59-11e1-ac7c-4487fc68dd18}\Shell\setup\command - "" = J:\setup.exe – [2005-07-15 19:19:47 | 000,253,952 | R— | M] (Microsoft Game Studios )
O33 - MountPoints2\{86342252-2e59-11e1-ac7c-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{86342252-2e59-11e1-ac7c-4487fc68dd18}\Shell\AutoRun\command - "" = K:\CDCheck.exe – [2005-05-16 22:23:09 | 000,049,152 | R— | M] ()
O33 - MountPoints2\{86342256-2e59-11e1-ac7c-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{86342256-2e59-11e1-ac7c-4487fc68dd18}\Shell\AutoRun\command - "" = L:\CDCheck.exe – [2005-05-16 22:23:09 | 000,049,152 | R— | M] ()
O33 - MountPoints2\{8634225a-2e59-11e1-ac7c-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{8634225a-2e59-11e1-ac7c-4487fc68dd18}\Shell\AutoRun\command - "" = M:\CDCheck.exe – [2005-05-16 22:23:09 | 000,049,152 | R— | M] ()
O33 - MountPoints2\{bff6fa3f-9a77-11df-8c2b-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{bff6fa3f-9a77-11df-8c2b-4487fc68dd18}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{c6668c83-8a57-11e0-9d6b-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{c6668c83-8a57-11e0-9d6b-4487fc68dd18}\Shell\AutoRun\command - "" = H:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: javaK_32 - (C:\Windows\system32\mspahost64.dll) - File not found
O36 - AppCertDlls: nslo - (C:\Windows\system32\mspahost.dll) -C:\Windows\SysWOW64\mspahost.dll ()
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.bdmpeg - bdmpega64.acm ()
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: vidc.mjpg - bdmjpeg64.dll ()
Drivers32:64bit: vidc.mpeg - bdmpegv64.dll ()
Drivers32:64bit: VIDC.XFR1 - xfcodec64.dll ()
Drivers32: msacm.bdmpeg - C:\Windows\SysWow64\bdmpega.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.mjpg - C:\Windows\SysWow64\bdmjpeg.dll ()
Drivers32: vidc.mpeg - C:\Windows\SysWow64\bdmpegv.dll ()
Drivers32: vidc.tscc - C:\PROGRA~2\MpcStar\Codecs\tscc\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.XFR1 - C:\Windows\SysWow64\xfcodec.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011-12-28 23:59:43 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Nery\Desktop\HiJackThis.exe
[2011-12-28 23:57:49 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Nery\Desktop\OTL.exe
[2011-12-28 23:36:35 | 000,000,000 | —D | C] – C:\491fffec89cd4ac94f55
[2011-12-28 23:24:26 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2011-12-27 01:19:30 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011-12-25 16:37:45 | 000,000,000 | —D | C] – C:\Users\Nery\Documents\My Games
[2011-12-25 16:31:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
[2011-12-25 16:19:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Games
[2011-12-16 23:01:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011-12-16 03:01:30 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011-12-16 03:01:30 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011-12-16 03:01:29 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011-12-16 03:01:29 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011-12-16 03:01:28 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011-12-16 03:01:28 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011-12-16 03:01:27 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011-12-16 03:01:26 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011-12-16 03:01:26 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011-12-16 03:01:26 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011-12-16 03:01:26 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011-12-15 22:30:19 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011-12-15 22:30:15 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011-12-15 22:30:15 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011-12-01 01:25:06 | 000,476,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011-12-01 01:25:05 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011-12-01 01:25:03 | 002,871,808 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011-12-01 01:25:03 | 002,616,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2011-12-01 01:24:50 | 002,315,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2011-12-01 01:24:50 | 002,223,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2011-12-01 01:24:49 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2011-12-01 01:24:48 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2011-12-01 01:24:48 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2011-12-01 01:24:47 | 000,778,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2011-12-01 01:24:47 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2011-12-01 01:24:47 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2011-12-01 01:24:47 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssphtb.dll
[2011-12-01 01:24:47 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2011-12-01 01:24:46 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2011-12-01 01:24:46 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2011-12-01 01:24:46 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2011-12-01 01:24:41 | 002,565,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2011-12-01 01:24:41 | 001,699,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[2011-12-01 01:24:41 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsutil.exe
[2011-12-01 01:24:40 | 000,189,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2011-12-01 01:24:40 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdsata.sys
[2011-12-01 01:24:40 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fsutil.exe
[2011-12-01 01:24:40 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdxata.sys
[2011-12-01 01:24:28 | 001,465,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011-12-01 01:24:28 | 000,870,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011-12-01 01:24:26 | 001,544,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011-12-01 01:24:26 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011-12-01 01:24:25 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2011-12-01 01:24:23 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011-12-01 01:24:22 | 000,027,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011-12-01 01:24:21 | 000,325,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011-12-01 01:24:21 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2011-12-01 01:24:19 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\prevhost.exe
[2011-12-01 01:24:19 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\prevhost.exe
[2011-12-01 01:21:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\SystemRequirementsLab
[2011-12-01 01:21:14 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Roaming\SystemRequirementsLab
[2011-12-01 00:24:46 | 000,000,000 | —D | C] – C:\Program Files\Perfect World Entertainment
[2011-11-29 23:54:23 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Local\Microsoft Help
[2011-11-29 09:45:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free FLAC to MP3 Converter
[2011-11-29 09:45:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free FLAC to MP3 Converter
[2011-11-29 09:42:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic FLAC to MP3 Converter
[2011-11-29 09:42:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\FLAC to MP3 Converter
[2011-11-29 02:27:39 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Roaming\Python-Eggs
[2011-11-29 02:27:33 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Roaming\BitLord
[2011-11-29 02:27:12 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitLord
[2011-11-29 02:25:37 | 000,000,000 | —D | C] – C:\Users\Nery\Documents\BitLord
[2011-11-29 02:25:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\BitLord 2
[2011-11-29 02:14:06 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Local\uTorrent
[2009-12-17 18:08:41 | 000,036,136 | —- | C] (Oberon Media) – C:\ProgramData\FullRemove.exe
========== Files - Modified Within 30 Days ==========
[2011-12-28 23:59:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Nery\Desktop\HiJackThis.exe
[2011-12-28 23:57:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nery\Desktop\OTL.exe
[2011-12-28 23:35:02 | 000,001,018 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1715959346-4031595088-2119382840-1000UA.job
[2011-12-28 23:35:02 | 000,000,966 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1715959346-4031595088-2119382840-1000Core.job
[2011-12-28 23:23:42 | 000,512,992 | —- | M] () – C:\Users\Nery\Desktop\sdasetup_revwire207.exe
[2011-12-28 23:23:28 | 000,001,012 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011-12-28 22:32:26 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011-12-28 22:32:26 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011-12-28 22:25:17 | 000,001,008 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011-12-28 22:25:02 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011-12-28 22:24:56 | 2388,582,400 | -HS- | M] () – C:\hiberfil.sys
[2011-12-27 01:22:54 | 000,001,151 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011-12-26 23:57:20 | 000,001,083 | —- | M] () – C:\Users\Nery\Desktop\TeamSpeak 3 Client.lnk
[2011-12-26 00:45:05 | 000,001,386 | —- | M] () – C:\Users\Nery\Desktop\Forsaken World.lnk
[2011-12-25 17:00:02 | 000,000,412 | —- | M] () – C:\Windows\tasks\RegCure Program Check.job
[2011-12-25 16:31:33 | 000,002,240 | —- | M] () – C:\Users\Public\Desktop\Fable - The Lost Chapters.lnk
[2011-12-25 16:03:56 | 000,000,218 | —- | M] () – C:\Users\Nery\.recently-used.xbel
[2011-12-25 03:00:49 | 000,000,394 | —- | M] () – C:\Windows\tasks\RegCure.job
[2011-12-16 03:21:11 | 002,291,536 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011-12-01 01:40:42 | 000,015,154 | —- | M] () – C:\Windows\SysNative\results.xml
[2011-11-29 22:24:41 | 000,679,184 | —- | M] () – C:\Windows\SysNative\prfh0816.dat
[2011-11-29 22:24:41 | 000,615,760 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011-11-29 22:24:41 | 000,135,218 | —- | M] () – C:\Windows\SysNative\prfc0816.dat
[2011-11-29 22:24:41 | 000,107,396 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011-11-29 22:24:40 | 001,541,104 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011-11-29 09:43:43 | 000,011,264 | —- | M] () – C:\Users\Nery\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-11-29 02:27:12 | 000,002,036 | —- | M] () – C:\Users\Nery\Desktop\BitLord.lnk
========== Files Created - No Company Name ==========
[2011-12-28 23:24:26 | 000,512,992 | —- | C] () – C:\Users\Nery\Desktop\sdasetup_revwire207.exe
[2011-12-27 01:22:54 | 000,001,163 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011-12-27 01:22:54 | 000,001,151 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011-12-26 23:56:35 | 000,001,083 | —- | C] () – C:\Users\Nery\Desktop\TeamSpeak 3 Client.lnk
[2011-12-25 16:31:33 | 000,002,240 | —- | C] () – C:\Users\Public\Desktop\Fable - The Lost Chapters.lnk
[2011-12-25 16:03:56 | 000,000,218 | —- | C] () – C:\Users\Nery\.recently-used.xbel
[2011-12-01 00:31:23 | 000,001,386 | —- | C] () – C:\Users\Nery\Desktop\Forsaken World.lnk
[2011-11-29 02:27:12 | 000,002,036 | —- | C] () – C:\Users\Nery\Desktop\BitLord.lnk
[2011-11-26 17:10:05 | 000,055,296 | —- | C] () – C:\Windows\SysWow64\mspahost.dll
[2011-09-02 06:54:36 | 000,000,000 | —- | C] () – C:\Windows\PanelExe.INI
[2011-09-02 06:54:36 | 000,000,000 | —- | C] () – C:\Windows\EngineExe.INI
[2011-08-26 22:21:30 | 000,042,392 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2011-06-17 00:59:10 | 000,109,788 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011-05-31 06:39:50 | 000,058,368 | —- | C] () – C:\Windows\SysWow64\bdmpegv.dll
[2011-05-31 06:38:18 | 000,015,360 | —- | C] () – C:\Windows\SysWow64\bdmjpeg.dll
[2011-04-09 17:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011-03-16 00:12:32 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2011-03-16 00:12:31 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011-02-26 05:42:21 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010-12-29 22:12:55 | 000,011,264 | —- | C] () – C:\Users\Nery\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-12-15 19:20:44 | 000,000,092 | —- | C] () – C:\Users\Nery\AppData\Local\fusioncache.dat
[2010-12-15 19:19:36 | 001,556,128 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010-11-09 23:42:22 | 000,000,027 | —- | C] () – C:\ProgramData\SDGLYBMPWPP.SYS
[2010-08-25 19:34:30 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2010-08-25 19:34:30 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2010-08-25 19:34:30 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2010-08-02 13:43:29 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010-07-28 18:46:04 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2009-07-14 05:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009-07-14 02:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009-07-14 02:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009-07-14 00:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009-07-13 23:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 21:59:36 | 000,139,824 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009-07-13 21:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009-06-10 21:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2007-06-29 10:07:36 | 000,000,566 | —- | C] () – C:\Windows\SysWow64\SP207.ini
[2004-11-22 12:37:38 | 000,040,960 | —- | C] () – C:\Windows\98Setup.exe
========== LOP Check ==========
[2011-01-18 22:50:43 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\.minecraft
[2011-07-02 14:06:38 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\360safe
[2011-06-30 23:37:26 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\360safebox
[2011-12-25 16:03:56 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\BitLord
[2011-03-08 21:27:52 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\CleanMyPC Software
[2010-07-29 15:56:55 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011-03-16 21:49:50 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\CometPlayer
[2011-05-29 23:42:32 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\DAEMON Tools Pro
[2010-12-08 22:31:58 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\LolClient
[2011-09-01 21:45:48 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\Mobile Action
[2011-07-28 21:50:36 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\OpenOffice.org
[2011-11-29 02:27:39 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\Python-Eggs
[2011-12-28 22:31:57 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\QuickScan
[2011-05-23 20:42:55 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\RIFT
[2011-06-30 23:34:20 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\sdDown
[2011-12-01 01:21:14 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\SystemRequirementsLab
[2010-09-02 21:55:25 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\TeamViewer
[2011-03-15 23:54:02 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\tigerplayer
[2010-12-02 19:55:19 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\Trion Worlds
[2011-12-27 00:00:57 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\TS3Client
[2011-12-25 17:00:02 | 000,000,412 | —- | M] () – C:\Windows\Tasks\RegCure Program Check.job
[2011-12-25 03:00:49 | 000,000,394 | —- | M] () – C:\Windows\Tasks\RegCure.job
[2011-09-08 19:05:14 | 000,032,568 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009-12-17 17:49:28 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007-11-07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007-11-07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007-11-07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011-12-28 22:24:56 | 2388,582,400 | -HS- | M] () – C:\hiberfil.sys
[2007-11-07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007-11-07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007-11-07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007-11-07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007-11-07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007-11-07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007-11-07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007-11-07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007-11-07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007-11-07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007-11-07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006-12-02 07:37:14 | 000,904,704 | -H– | M] (Microsoft Corporation) – C:\msdia80.dll
[2011-12-28 22:24:59 | 3184,779,264 | -HS- | M] () – C:\pagefile.sys
[2010-03-10 08:50:45 | 000,002,206 | —- | M] () – C:\RHDSetup.log
[2007-11-07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007-11-07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007-11-07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009-07-14 05:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009-07-14 05:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009-07-14 05:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009-07-14 05:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009-06-10 20:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010-04-17 00:21:52 | 000,307,056 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009-07-14 04:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011-09-10 14:38:45 | 000,000,221 | -HS- | M] () – C:\Users\Nery\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011-12-28 23:59:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Nery\Desktop\HiJackThis.exe
[2011-12-28 23:57:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nery\Desktop\OTL.exe
[2011-12-28 23:23:42 | 000,512,992 | —- | M] () – C:\Users\Nery\Desktop\sdasetup_revwire207.exe
< %PROGRAMFILES%\Common Files\*.* >
[2008-04-29 14:04:40 | 000,157,442 | —- | M] () – C:\Program Files (x86)\Common Files\emachines.ico
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2011-12-08 00:22:01 | 000,001,368 | —- | M] ()(C:\Users\Nery\Documents\??? ????af? ?e?µ???? (2).txt) – C:\Users\Nery\Documents\Νέο έγγραφο κειμένου (2).txt
[2011-12-08 00:22:00 | 000,001,368 | —- | C] ()(C:\Users\Nery\Documents\??? ????af? ?e?µ???? (2).txt) – C:\Users\Nery\Documents\Νέο έγγραφο κειμένου (2).txt
========== Alternate Data Streams ==========
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:ECF54A0E
< End of report >
HijackThis:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 00:00:04, on 29-12-2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Nery\Desktop\OTL.exe
C:\Users\Nery\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Nery\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'Serviço de rede')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'Serviço de rede')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: Publicar em Blogue - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Publicar no Blogue no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Serviço de estado do ASP.NET (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe
O23 - Service: Serviço Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 10496 bytes
DDS 1:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 0:00:59,75 on 29-12-2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.351.2070.18.3037.1233 [GMT 0:00]
.
AV: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\taskhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Nery\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V14HI7FZ\windows-kb890830-x64-v4.3.exe
c:\491fffec89cd4ac94f55\mrtstub.exe
C:\Windows\system32\MRT.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Nery\Desktop\OTL.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Nery\Desktop\HiJackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Nery\Downloads\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0816&m=el1850&r=17360710q306pe405v145r45n2s323
uDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0816&m=el1850&r=17360710q306pe405v145r45n2s323
mDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0816&m=el1850&r=17360710q306pe405v145r45n2s323
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0816&m=el1850&r=17360710q306pe405v145r45n2s323
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Google Update] "C:\Users\Nery\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [PlayNC Launcher]
uRun: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
uRun: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49}
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6}
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
mRun-x64: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
mRun-x64: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Nery\AppData\Roaming\Mozilla\Firefox\Profiles\hnalx0c0.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll
FF - plugin: C:\Users\Nery\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\Nery\AppData\Roaming\Mozilla\Firefox\Profiles\hnalx0c0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: C:\Users\Nery\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Nery\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2011-5-29 272448]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
R2 epfwwfpr;epfwwfpr;C:\Windows\System32\drivers\epfwwfpr.sys [2009-11-16 123200]
R2 Greg_Service;GRegService;C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe [2009-8-28 1150496]
R2 Updater Service;Updater Service;C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [2009-12-17 240160]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\System32\drivers\vrtaucbl.sys [2010-12-30 66728]
R3 netr7364;Controlador sem Fios Conceptronic RT73 para Vista;C:\Windows\System32\drivers\netr7364.sys [2009-6-10 707072]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-12-17 291328]
S2 gupdate;Serviço Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-28 135664]
S3 cpudrv64;cpudrv64;C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2009-12-18 17864]
S3 gupdatem;Serviço Google Update (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-28 135664]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?]
S3 PAC207;SoC PC-Camera;C:\Windows\System32\drivers\PFC027.SYS [2006-12-5 572416]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-25 59392]
S3 WatAdminSvc;Serviço de Tecnologias de Activação do Windows;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-7-30 1255736]
.
=============== Created Last 30 ================
.
2011-12-28 23:36:35 ——– d—–w- C:\491fffec89cd4ac94f55
2011-12-28 23:24:26 ——– d—–w- C:\PROGRA~3\PC Tools
2011-12-28 21:58:36 69000 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{3E159B74-667D-49CE-89CD-A91BCB9813DF}\offreg.dll
2011-12-27 22:04:35 8822856 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{3E159B74-667D-49CE-89CD-A91BCB9813DF}\mpengine.dll
2011-12-25 16:19:46 ——– d—–w- C:\Program Files (x86)\Microsoft Games
2011-12-15 22:30:19 43520 —-a-w- C:\Windows\System32\csrsrv.dll
2011-12-15 22:30:17 3145216 —-a-w- C:\Windows\System32\win32k.sys
2011-12-15 22:30:15 723456 —-a-w- C:\Windows\System32\EncDec.dll
2011-12-15 22:30:15 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll
2011-12-15 22:30:04 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2011-12-15 22:30:04 2048 —-a-w- C:\Windows\System32\tzres.dll
2011-12-01 01:25:06 476160 —-a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-12-01 01:25:05 288256 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-12-01 01:25:03 2871808 —-a-w- C:\Windows\explorer.exe
2011-12-01 01:25:03 2616320 —-a-w- C:\Windows\SysWow64\explorer.exe
2011-12-01 01:21:22 ——– d—–w- C:\Program Files (x86)\SystemRequirementsLab
2011-12-01 00:24:46 ——– d—–w- C:\Program Files\Perfect World Entertainment
2011-11-29 23:54:23 ——– d—–w- C:\Users\Nery\AppData\Local\Microsoft Help
2011-11-29 09:45:23 ——– d—–w- C:\Program Files (x86)\Free FLAC to MP3 Converter
2011-11-29 09:42:41 ——– d—–w- C:\Program Files (x86)\FLAC to MP3 Converter
2011-11-29 02:27:39 ——– d—–w- C:\Users\Nery\AppData\Roaming\Python-Eggs
2011-11-29 02:27:33 ——– d—–w- C:\Users\Nery\AppData\Roaming\BitLord
2011-11-29 02:25:10 ——– d—–w- C:\Program Files (x86)\BitLord 2
2011-11-29 02:14:06 ——– d—–w- C:\Users\Nery\AppData\Local\uTorrent
.
==================== Find3M ====================
.
2011-11-26 17:10:05 63488 —ha-w- C:\Windows\System32\mspahost64.dll
2011-11-26 17:10:05 55296 ——w- C:\Windows\SysWow64\mspahost.dll
2011-11-15 14:29:56 270720 ——w- C:\Windows\System32\MpSigStub.exe
2011-11-04 01:53:39 2309120 —-a-w- C:\Windows\System32\jscript9.dll
2011-11-04 01:44:47 1390080 —-a-w- C:\Windows\System32\wininet.dll
2011-11-04 01:44:21 1493504 —-a-w- C:\Windows\System32\inetcpl.cpl
2011-11-04 01:34:43 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2011-11-03 22:47:42 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll
2011-11-03 22:40:21 1427456 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-11-03 22:39:47 1127424 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-11-03 22:31:57 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-22 11:21:42 71680 —-a-w- C:\Windows\System32\frapsv64.dll
2011-10-22 11:21:38 65536 —-a-w- C:\Windows\SysWow64\frapsvid.dll
2011-10-13 12:14:46 162584 —-a-w- C:\Windows\System32\igfxtray.exe
2011-10-13 12:14:44 510232 —-a-w- C:\Windows\System32\igfxsrvc.exe
2011-10-13 12:14:42 417560 —-a-w- C:\Windows\System32\igfxpers.exe
2011-10-13 12:14:40 224024 —-a-w- C:\Windows\System32\igfxext.exe
2011-10-13 12:14:38 386840 —-a-w- C:\Windows\System32\hkcmd.exe
2011-10-13 12:14:32 3157784 —-a-w- C:\Windows\System32\GfxUI.exe
2011-10-13 12:14:30 152856 —-a-w- C:\Windows\System32\difx64.exe
2011-10-13 12:10:12 90112 —-a-w- C:\Windows\System32\igfxCoIn_v2555.dll
2011-10-13 12:05:50 6549504 —-a-w- C:\Windows\System32\igdumd64.dll
2011-10-13 12:05:50 10629184 —-a-w- C:\Windows\System32\drivers\igdkmd64.sys
2011-10-13 12:01:28 4967424 —-a-w- C:\Windows\SysWow64\igdumd32.dll
2011-10-13 11:58:56 571904 —-a-w- C:\Windows\SysWow64\igdumdx32.dll
2011-10-13 11:57:46 4722176 —-a-w- C:\Windows\System32\igd10umd64.dll
2011-10-13 11:55:16 4411392 —-a-w- C:\Windows\SysWow64\igd10umd32.dll
2011-10-13 11:50:04 15546880 —-a-w- C:\Windows\System32\ig4icd64.dll
2011-10-13 11:42:40 11405312 —-a-w- C:\Windows\SysWow64\ig4icd32.dll
2011-10-13 11:37:36 244224 —-a-w- C:\Windows\System32\igfxpph.dll
2011-10-13 11:37:32 380416 —-a-w- C:\Windows\System32\igfxTMM.dll
2011-10-13 11:37:30 27648 —-a-w- C:\Windows\System32\igfxexps.dll
2011-10-13 11:37:12 61952 —-a-w- C:\Windows\System32\igfxsrvc.dll
2011-10-13 11:36:44 108544 —-a-w- C:\Windows\System32\hccutils.dll
2011-10-13 11:36:36 119808 —-a-w- C:\Windows\System32\gfxSrvc.dll
2011-10-13 11:36:34 4096 —-a-w- C:\Windows\System32\IGFXDEVLib.dll
2011-10-13 11:36:34 272896 —-a-w- C:\Windows\System32\igfxdev.dll
2011-10-13 11:36:08 87552 —-a-w- C:\Windows\System32\igfxrenu.lrc
2011-10-13 11:36:04 142336 —-a-w- C:\Windows\System32\igfxdo.dll
2011-10-13 11:36:02 830464 —-a-w- C:\Windows\System32\igfxress.dll
2011-10-13 11:32:34 23552 —-a-w- C:\Windows\SysWow64\igfxexps32.dll
2011-10-13 11:31:48 228864 —-a-w- C:\Windows\SysWow64\igfxdv32.dll
2011-10-13 11:30:12 208896 —-a-w- C:\Windows\SysWow64\iglhsip32.dll
2011-10-13 11:30:12 206336 —-a-w- C:\Windows\System32\iglhsip64.dll
2011-10-13 11:30:12 188416 —-a-w- C:\Windows\System32\iglhcp64.dll
2011-10-13 11:30:12 147456 —-a-w- C:\Windows\SysWow64\iglhcp32.dll
.
============= FINISH: 0:03:34,85 ===============
DDS2:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 28-07-2010 19:36:03
System Uptime: 28-12-2011 22:24:48 (2 hours ago)
.
Motherboard: eMachines | | EL1850
Processor: Intel® Celeron® CPU E3300 @ 2.50GHz | CPU 1 | 2500/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 454 GiB total, 314,485 GiB free.
D: is CDROM (CDFS)
E: is Removable
F: is Removable
G: is CDROM ()
H: is CDROM ()
I: is CDROM ()
J: is CDROM (CDFS)
K: is CDROM (CDFS)
L: is CDROM (CDFS)
M: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP196: 06-12-2011 20:54:34 - Windows Update
RP197: 10-12-2011 23:07:08 - Windows Update
RP198: 15-12-2011 22:25:27 - Windows Update
RP199: 16-12-2011 03:00:14 - Windows Update
RP200: 20-12-2011 23:16:20 - Windows Update
RP201: 25-12-2011 16:18:30 - Installed Fable - The Lost Chapters
RP202: 27-12-2011 22:03:32 - Windows Update
.
==== Installed Programs ======================
.
Acrobat.com
Actualização do Microsoft Office Excel 2007 Help (KB963678)
Actualização do Microsoft Office Powerpoint 2007 Help (KB963669)
Actualização do Microsoft Office Word 2007 Help (KB963665)
Adobe AIR
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Illustrator CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Reader X (10.1.1) - Português
Adobe Setup
Adobe Shockwave Player 11.5
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
Advertising Center
Alice Greenfingers
Amazonia
Android Sync Manager WiFi
AVIcodec (remove only)
Bandisoft MPEG-1 Decoder
BitLord 2.0
Blue Byte Game Channel
Chicken Invaders 2
DAEMON Tools Pro
Dairy Dash
DivX Setup
Dragon Nest SEA
Dream Day First Home
eMachines GameZone Console
eMachines Recovery Management
eMachines Registration
eMachines ScreenSaver
eMachines Updater
Fable - The Lost Chapters
Farm Frenzy 2
Ferramenta de Carregamento do Windows Live
First Class Flurry
FormatFactory 2.60
Fraps
Free FLAC to MP3 Converter 1.0
Galeria de Fotografias do Windows Live
Gangsters 2
Google Chrome
Google Earth
Google Talk Plugin
Google Update Helper
Granny In Paradise
Identity Card
ImagXpress
Intel® Control Center
Intel® Graphics Media Accelerator Driver
Java Auto Updater
Java™ 6 Update 24
Junk Mail filter update
K-Lite Mega Codec Pack 7.0.0
League of Legends
Macromedia FreeHand 10
Macromedia FreeHand MXa
Magic FLAC to MP3 Converter 3.72
Merriam Websters Spell Jam
Microsoft .NET Framework 1.1
Microsoft Choice Guard
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (Portuguese (Portugal)) 2007
Microsoft Office Excel MUI (Portuguese (Portugal)) 2007
Microsoft Office Groove MUI (Portuguese (Portugal)) 2007
Microsoft Office InfoPath MUI (Portuguese (Portugal)) 2007
Microsoft Office Language Pack 2007 - Portuguese/Português
Microsoft Office O MUI (Portuguese (Portugal)) 2007
Microsoft Office OneNote MUI (Portuguese (Portugal)) 2007
Microsoft Office Outlook MUI (Portuguese (Portugal)) 2007
Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Portuguese (Portugal)) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (Portuguese (Portugal)) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (Portuguese (Portugal)) 2007
Microsoft Office Shared MUI (Portuguese (Portugal)) 2007
Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)
Microsoft Office SharePoint Designer MUI (Portuguese (Portugal)) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (Portuguese (Portugal)) 2007
Microsoft Office X MUI (Portuguese (Portugal)) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
mIRC
Mozilla Firefox 9.0.1 (x86 pt-PT)
MpcStar 5.0
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NCsoft Launcher
Nero 9 Essentials
Nero ControlCenter
Nero DiscSpeed
Nero DiscSpeed Help
Nero DriveSpeed
Nero DriveSpeed Help
Nero Express Help
Nero InfoTool
Nero InfoTool Help
Nero Installer
Nero Online Upgrade
Nero StartSmart
Nero StartSmart Help
Nero StartSmart OEM
NeroExpress
neroxml
Nexon Game Manager
OpenOffice.org 3.3
Pando Media Booster
PDF Settings
PDFCreator
Pizza Syndicate
Quick Memory Editor 4.2
Realtek High Definition Audio Driver
RegCure
Rift BETA Patcher
RollerCoaster Tycoon 2
Skype Click to Call
Skype™ 5.5
System Requirements Lab for Intel
The Settlers IV
USB PC CAMERA P227
VC80CRTRedist - 8.0.50727.4053
Vindictus
VLC media player 1.1.7
Welcome Center
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live OneCare safety scanner
Windows Live Sync
Windows Live Writer
Xfire (remove only)
.
==== End Of File ===========================
My browser was seeeeriously slow and sometimes blocking my computer totally. PC is only a few months old which made me suspicious something was wrong. I have to admit due to laziness I didnt update NOD32 for a while, so I had no real antivirus running at all. I updated NOD32 and after scanning it found the trojan on title, but cant clean it or treat it ofc. MSPAHOST.DLL is the infected file that NOD32 keeps popping up with, tho there are 21 infected files according to it, not all from same tho.
Here are the logs:
OTL LOG:
OTL logfile created on: 28-12-2011 23:58:59 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Nery\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy
2,97 Gb Total Physical Memory | 1,25 Gb Available Physical Memory | 42,29% Memory free
5,93 Gb Paging File | 4,09 Gb Available in Paging File | 69,03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453,66 Gb Total Space | 311,37 Gb Free Space | 68,64% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive J: | 534,43 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive K: | 616,23 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive L: | 462,84 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive M: | 579,67 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: DESKTOP | User Name: Nery | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Nery\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe (DT Soft Ltd)
PRC - C:\Programas\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (ESET)
PRC - C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Programas\eMachines\eMachines Updater\UpdaterService.exe (Acer)
PRC - C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\mspahost.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (EhttpSrv) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV:64bit: - (ekrn) – C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (ESET)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Macromedia Licensing Service) – C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (npggsvc) – C:\Windows\SysWow64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (Greg_Service) – C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (Updater Service) – C:\Programas\eMachines\eMachines Updater\UpdaterService.exe (Acer)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (EuMusDesignVirtualAudioCableWdm) Virtual Audio Cable (WDM) – C:\Windows\SysNative\drivers\vrtaucbl.sys (Eugene V. Muzychenko)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (epfwwfpr) – C:\Windows\SysNative\drivers\epfwwfpr.sys (ESET)
DRV:64bit: - (ehdrv) – C:\Windows\SysNative\drivers\ehdrv.sys (ESET)
DRV:64bit: - (eamon) – C:\Windows\SysNative\drivers\eamon.sys (ESET)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (1394hub) – C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
DRV:64bit: - (netr7364) – C:\Windows\SysNative\drivers\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (PAC207) – C:\Windows\SysNative\drivers\PFC027.SYS (PixArt Imaging Inc.)
DRV - (cpudrv64) – C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (PAC207) – C:\Windows\SysWOW64\drivers\PFC027.sys (PixArt Imaging Inc.)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Nery\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Nery\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Nery\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Nery\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011-06-21 02:38:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011-12-27 01:22:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011-10-28 18:23:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011-03-23 20:45:25 | 000,000,000 | —D | M]
[2011-12-27 01:23:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Nery\AppData\Roaming\mozilla\Extensions
[2011-12-28 22:31:33 | 000,000,000 | —D | M] (No name found) – C:\Users\Nery\AppData\Roaming\mozilla\Firefox\Profiles\hnalx0c0.default\extensions
[2011-12-28 22:31:33 | 000,000,000 | —D | M] (BitDefender QuickScan) – C:\Users\Nery\AppData\Roaming\mozilla\Firefox\Profiles\hnalx0c0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2011-12-27 01:22:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\mozilla firefox\extensions
[2011-12-16 23:01:52 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011-12-21 08:04:32 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011-02-02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011-12-21 05:10:22 | 000,001,525 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011-12-21 05:10:22 | 000,001,529 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\priberam.xml
[2011-12-21 05:10:22 | 000,002,071 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\sapo.xml
[2011-12-21 05:10:22 | 000,000,942 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-ptpt.xml
O1 HOSTS File: ([2009-06-10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Monitor] C:\Windows\PixArt\Pac207\Monitor.exe (PixArt Imaging Incorporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe (NEXON Inc.)
O4 - HKCU..\Run: [PlayNC Launcher] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html File not found
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{10377748-9BDA-4EF9-9AC7-53A0E6A3A86C}: DhcpNameServer = 192.168.1.254 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{401A86F1-6A29-4A62-B436-1C95B5E24BA5}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{42599A28-12DB-4C3B-AE8D-5AA6374FEE3C}: DhcpNameServer = 192.168.1.254 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{475446E1-C539-479D-9300-68736E9B13BE}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005-05-18 23:59:05 | 000,000,228 | R— | M] () - J:\Autorun.inf – [ CDFS ]
O32 - AutoRun File - [2005-07-05 23:05:52 | 001,019,904 | R— | M] (Microsoft Corporation) - J:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2005-05-11 20:22:44 | 000,000,066 | R— | M] () - K:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2005-05-11 20:22:59 | 000,000,066 | R— | M] () - L:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2005-05-27 23:20:11 | 000,000,066 | R— | M] () - M:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{6174142e-dbba-11e0-8d78-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{6174142e-dbba-11e0-8d78-4487fc68dd18}\Shell\AutoRun\command - "" = I:\Autorun.exe
O33 - MountPoints2\{76f1d766-879b-11e0-a95e-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{76f1d766-879b-11e0-a95e-4487fc68dd18}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{86342249-2e59-11e1-ac7c-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{86342249-2e59-11e1-ac7c-4487fc68dd18}\Shell\AutoRun\command - "" = J:\autorun.exe – [2005-07-05 23:05:52 | 001,019,904 | R— | M] (Microsoft Corporation)
O33 - MountPoints2\{86342249-2e59-11e1-ac7c-4487fc68dd18}\Shell\directx\command - "" = J:\directx9\DXSETUP.exe – [2005-03-19 01:19:41 | 000,480,976 | R— | M] (Microsoft Corporation)
O33 - MountPoints2\{86342249-2e59-11e1-ac7c-4487fc68dd18}\Shell\setup\command - "" = J:\setup.exe – [2005-07-15 19:19:47 | 000,253,952 | R— | M] (Microsoft Game Studios )
O33 - MountPoints2\{86342252-2e59-11e1-ac7c-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{86342252-2e59-11e1-ac7c-4487fc68dd18}\Shell\AutoRun\command - "" = K:\CDCheck.exe – [2005-05-16 22:23:09 | 000,049,152 | R— | M] ()
O33 - MountPoints2\{86342256-2e59-11e1-ac7c-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{86342256-2e59-11e1-ac7c-4487fc68dd18}\Shell\AutoRun\command - "" = L:\CDCheck.exe – [2005-05-16 22:23:09 | 000,049,152 | R— | M] ()
O33 - MountPoints2\{8634225a-2e59-11e1-ac7c-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{8634225a-2e59-11e1-ac7c-4487fc68dd18}\Shell\AutoRun\command - "" = M:\CDCheck.exe – [2005-05-16 22:23:09 | 000,049,152 | R— | M] ()
O33 - MountPoints2\{bff6fa3f-9a77-11df-8c2b-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{bff6fa3f-9a77-11df-8c2b-4487fc68dd18}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{c6668c83-8a57-11e0-9d6b-4487fc68dd18}\Shell - "" = AutoRun
O33 - MountPoints2\{c6668c83-8a57-11e0-9d6b-4487fc68dd18}\Shell\AutoRun\command - "" = H:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: javaK_32 - (C:\Windows\system32\mspahost64.dll) - File not found
O36 - AppCertDlls: nslo - (C:\Windows\system32\mspahost.dll) -C:\Windows\SysWOW64\mspahost.dll ()
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.bdmpeg - bdmpega64.acm ()
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: vidc.mjpg - bdmjpeg64.dll ()
Drivers32:64bit: vidc.mpeg - bdmpegv64.dll ()
Drivers32:64bit: VIDC.XFR1 - xfcodec64.dll ()
Drivers32: msacm.bdmpeg - C:\Windows\SysWow64\bdmpega.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.mjpg - C:\Windows\SysWow64\bdmjpeg.dll ()
Drivers32: vidc.mpeg - C:\Windows\SysWow64\bdmpegv.dll ()
Drivers32: vidc.tscc - C:\PROGRA~2\MpcStar\Codecs\tscc\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.XFR1 - C:\Windows\SysWow64\xfcodec.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011-12-28 23:59:43 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Nery\Desktop\HiJackThis.exe
[2011-12-28 23:57:49 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Nery\Desktop\OTL.exe
[2011-12-28 23:36:35 | 000,000,000 | —D | C] – C:\491fffec89cd4ac94f55
[2011-12-28 23:24:26 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2011-12-27 01:19:30 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011-12-25 16:37:45 | 000,000,000 | —D | C] – C:\Users\Nery\Documents\My Games
[2011-12-25 16:31:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
[2011-12-25 16:19:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Games
[2011-12-16 23:01:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011-12-16 03:01:30 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011-12-16 03:01:30 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011-12-16 03:01:29 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011-12-16 03:01:29 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011-12-16 03:01:28 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011-12-16 03:01:28 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011-12-16 03:01:27 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011-12-16 03:01:26 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011-12-16 03:01:26 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011-12-16 03:01:26 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011-12-16 03:01:26 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011-12-15 22:30:19 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011-12-15 22:30:15 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011-12-15 22:30:15 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011-12-01 01:25:06 | 000,476,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011-12-01 01:25:05 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011-12-01 01:25:03 | 002,871,808 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011-12-01 01:25:03 | 002,616,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2011-12-01 01:24:50 | 002,315,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2011-12-01 01:24:50 | 002,223,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2011-12-01 01:24:49 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2011-12-01 01:24:48 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2011-12-01 01:24:48 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2011-12-01 01:24:47 | 000,778,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2011-12-01 01:24:47 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2011-12-01 01:24:47 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2011-12-01 01:24:47 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssphtb.dll
[2011-12-01 01:24:47 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2011-12-01 01:24:46 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2011-12-01 01:24:46 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2011-12-01 01:24:46 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2011-12-01 01:24:41 | 002,565,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2011-12-01 01:24:41 | 001,699,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[2011-12-01 01:24:41 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsutil.exe
[2011-12-01 01:24:40 | 000,189,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2011-12-01 01:24:40 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdsata.sys
[2011-12-01 01:24:40 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fsutil.exe
[2011-12-01 01:24:40 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdxata.sys
[2011-12-01 01:24:28 | 001,465,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011-12-01 01:24:28 | 000,870,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011-12-01 01:24:26 | 001,544,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011-12-01 01:24:26 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011-12-01 01:24:25 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2011-12-01 01:24:23 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011-12-01 01:24:22 | 000,027,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011-12-01 01:24:21 | 000,325,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011-12-01 01:24:21 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2011-12-01 01:24:19 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\prevhost.exe
[2011-12-01 01:24:19 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\prevhost.exe
[2011-12-01 01:21:22 | 000,000,000 | —D | C] – C:\Program Files (x86)\SystemRequirementsLab
[2011-12-01 01:21:14 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Roaming\SystemRequirementsLab
[2011-12-01 00:24:46 | 000,000,000 | —D | C] – C:\Program Files\Perfect World Entertainment
[2011-11-29 23:54:23 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Local\Microsoft Help
[2011-11-29 09:45:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free FLAC to MP3 Converter
[2011-11-29 09:45:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free FLAC to MP3 Converter
[2011-11-29 09:42:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic FLAC to MP3 Converter
[2011-11-29 09:42:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\FLAC to MP3 Converter
[2011-11-29 02:27:39 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Roaming\Python-Eggs
[2011-11-29 02:27:33 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Roaming\BitLord
[2011-11-29 02:27:12 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitLord
[2011-11-29 02:25:37 | 000,000,000 | —D | C] – C:\Users\Nery\Documents\BitLord
[2011-11-29 02:25:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\BitLord 2
[2011-11-29 02:14:06 | 000,000,000 | —D | C] – C:\Users\Nery\AppData\Local\uTorrent
[2009-12-17 18:08:41 | 000,036,136 | —- | C] (Oberon Media) – C:\ProgramData\FullRemove.exe
========== Files - Modified Within 30 Days ==========
[2011-12-28 23:59:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Nery\Desktop\HiJackThis.exe
[2011-12-28 23:57:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nery\Desktop\OTL.exe
[2011-12-28 23:35:02 | 000,001,018 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1715959346-4031595088-2119382840-1000UA.job
[2011-12-28 23:35:02 | 000,000,966 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1715959346-4031595088-2119382840-1000Core.job
[2011-12-28 23:23:42 | 000,512,992 | —- | M] () – C:\Users\Nery\Desktop\sdasetup_revwire207.exe
[2011-12-28 23:23:28 | 000,001,012 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011-12-28 22:32:26 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011-12-28 22:32:26 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011-12-28 22:25:17 | 000,001,008 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011-12-28 22:25:02 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011-12-28 22:24:56 | 2388,582,400 | -HS- | M] () – C:\hiberfil.sys
[2011-12-27 01:22:54 | 000,001,151 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011-12-26 23:57:20 | 000,001,083 | —- | M] () – C:\Users\Nery\Desktop\TeamSpeak 3 Client.lnk
[2011-12-26 00:45:05 | 000,001,386 | —- | M] () – C:\Users\Nery\Desktop\Forsaken World.lnk
[2011-12-25 17:00:02 | 000,000,412 | —- | M] () – C:\Windows\tasks\RegCure Program Check.job
[2011-12-25 16:31:33 | 000,002,240 | —- | M] () – C:\Users\Public\Desktop\Fable - The Lost Chapters.lnk
[2011-12-25 16:03:56 | 000,000,218 | —- | M] () – C:\Users\Nery\.recently-used.xbel
[2011-12-25 03:00:49 | 000,000,394 | —- | M] () – C:\Windows\tasks\RegCure.job
[2011-12-16 03:21:11 | 002,291,536 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011-12-01 01:40:42 | 000,015,154 | —- | M] () – C:\Windows\SysNative\results.xml
[2011-11-29 22:24:41 | 000,679,184 | —- | M] () – C:\Windows\SysNative\prfh0816.dat
[2011-11-29 22:24:41 | 000,615,760 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011-11-29 22:24:41 | 000,135,218 | —- | M] () – C:\Windows\SysNative\prfc0816.dat
[2011-11-29 22:24:41 | 000,107,396 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011-11-29 22:24:40 | 001,541,104 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011-11-29 09:43:43 | 000,011,264 | —- | M] () – C:\Users\Nery\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-11-29 02:27:12 | 000,002,036 | —- | M] () – C:\Users\Nery\Desktop\BitLord.lnk
========== Files Created - No Company Name ==========
[2011-12-28 23:24:26 | 000,512,992 | —- | C] () – C:\Users\Nery\Desktop\sdasetup_revwire207.exe
[2011-12-27 01:22:54 | 000,001,163 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011-12-27 01:22:54 | 000,001,151 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011-12-26 23:56:35 | 000,001,083 | —- | C] () – C:\Users\Nery\Desktop\TeamSpeak 3 Client.lnk
[2011-12-25 16:31:33 | 000,002,240 | —- | C] () – C:\Users\Public\Desktop\Fable - The Lost Chapters.lnk
[2011-12-25 16:03:56 | 000,000,218 | —- | C] () – C:\Users\Nery\.recently-used.xbel
[2011-12-01 00:31:23 | 000,001,386 | —- | C] () – C:\Users\Nery\Desktop\Forsaken World.lnk
[2011-11-29 02:27:12 | 000,002,036 | —- | C] () – C:\Users\Nery\Desktop\BitLord.lnk
[2011-11-26 17:10:05 | 000,055,296 | —- | C] () – C:\Windows\SysWow64\mspahost.dll
[2011-09-02 06:54:36 | 000,000,000 | —- | C] () – C:\Windows\PanelExe.INI
[2011-09-02 06:54:36 | 000,000,000 | —- | C] () – C:\Windows\EngineExe.INI
[2011-08-26 22:21:30 | 000,042,392 | —- | C] () – C:\Windows\SysWow64\xfcodec.dll
[2011-06-17 00:59:10 | 000,109,788 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011-05-31 06:39:50 | 000,058,368 | —- | C] () – C:\Windows\SysWow64\bdmpegv.dll
[2011-05-31 06:38:18 | 000,015,360 | —- | C] () – C:\Windows\SysWow64\bdmjpeg.dll
[2011-04-09 17:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011-03-16 00:12:32 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2011-03-16 00:12:31 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011-02-26 05:42:21 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010-12-29 22:12:55 | 000,011,264 | —- | C] () – C:\Users\Nery\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-12-15 19:20:44 | 000,000,092 | —- | C] () – C:\Users\Nery\AppData\Local\fusioncache.dat
[2010-12-15 19:19:36 | 001,556,128 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010-11-09 23:42:22 | 000,000,027 | —- | C] () – C:\ProgramData\SDGLYBMPWPP.SYS
[2010-08-25 19:34:30 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2010-08-25 19:34:30 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2010-08-25 19:34:30 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2010-08-02 13:43:29 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010-07-28 18:46:04 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2009-07-14 05:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009-07-14 02:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009-07-14 02:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009-07-14 00:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009-07-13 23:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 21:59:36 | 000,139,824 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009-07-13 21:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009-06-10 21:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2007-06-29 10:07:36 | 000,000,566 | —- | C] () – C:\Windows\SysWow64\SP207.ini
[2004-11-22 12:37:38 | 000,040,960 | —- | C] () – C:\Windows\98Setup.exe
========== LOP Check ==========
[2011-01-18 22:50:43 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\.minecraft
[2011-07-02 14:06:38 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\360safe
[2011-06-30 23:37:26 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\360safebox
[2011-12-25 16:03:56 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\BitLord
[2011-03-08 21:27:52 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\CleanMyPC Software
[2010-07-29 15:56:55 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011-03-16 21:49:50 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\CometPlayer
[2011-05-29 23:42:32 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\DAEMON Tools Pro
[2010-12-08 22:31:58 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\LolClient
[2011-09-01 21:45:48 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\Mobile Action
[2011-07-28 21:50:36 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\OpenOffice.org
[2011-11-29 02:27:39 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\Python-Eggs
[2011-12-28 22:31:57 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\QuickScan
[2011-05-23 20:42:55 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\RIFT
[2011-06-30 23:34:20 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\sdDown
[2011-12-01 01:21:14 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\SystemRequirementsLab
[2010-09-02 21:55:25 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\TeamViewer
[2011-03-15 23:54:02 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\tigerplayer
[2010-12-02 19:55:19 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\Trion Worlds
[2011-12-27 00:00:57 | 000,000,000 | —D | M] – C:\Users\Nery\AppData\Roaming\TS3Client
[2011-12-25 17:00:02 | 000,000,412 | —- | M] () – C:\Windows\Tasks\RegCure Program Check.job
[2011-12-25 03:00:49 | 000,000,394 | —- | M] () – C:\Windows\Tasks\RegCure.job
[2011-09-08 19:05:14 | 000,032,568 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009-12-17 17:49:28 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007-11-07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007-11-07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007-11-07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007-11-07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011-12-28 22:24:56 | 2388,582,400 | -HS- | M] () – C:\hiberfil.sys
[2007-11-07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007-11-07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007-11-07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007-11-07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007-11-07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007-11-07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007-11-07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007-11-07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007-11-07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007-11-07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007-11-07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2006-12-02 07:37:14 | 000,904,704 | -H– | M] (Microsoft Corporation) – C:\msdia80.dll
[2011-12-28 22:24:59 | 3184,779,264 | -HS- | M] () – C:\pagefile.sys
[2010-03-10 08:50:45 | 000,002,206 | —- | M] () – C:\RHDSetup.log
[2007-11-07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007-11-07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007-11-07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009-07-14 05:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009-07-14 05:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009-07-14 05:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009-07-14 05:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009-06-10 20:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010-04-17 00:21:52 | 000,307,056 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009-07-14 04:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011-09-10 14:38:45 | 000,000,221 | -HS- | M] () – C:\Users\Nery\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011-12-28 23:59:46 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Nery\Desktop\HiJackThis.exe
[2011-12-28 23:57:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nery\Desktop\OTL.exe
[2011-12-28 23:23:42 | 000,512,992 | —- | M] () – C:\Users\Nery\Desktop\sdasetup_revwire207.exe
< %PROGRAMFILES%\Common Files\*.* >
[2008-04-29 14:04:40 | 000,157,442 | —- | M] () – C:\Program Files (x86)\Common Files\emachines.ico
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2011-12-08 00:22:01 | 000,001,368 | —- | M] ()(C:\Users\Nery\Documents\??? ????af? ?e?µ???? (2).txt) – C:\Users\Nery\Documents\Νέο έγγραφο κειμένου (2).txt
[2011-12-08 00:22:00 | 000,001,368 | —- | C] ()(C:\Users\Nery\Documents\??? ????af? ?e?µ???? (2).txt) – C:\Users\Nery\Documents\Νέο έγγραφο κειμένου (2).txt
========== Alternate Data Streams ==========
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:ECF54A0E
< End of report >
HijackThis:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 00:00:04, on 29-12-2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Nery\Desktop\OTL.exe
C:\Users\Nery\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=A…05v145r45n2s323
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\Nery\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'Serviço de rede')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'Serviço de rede')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: Publicar em Blogue - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Publicar no Blogue no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Serviço de estado do ASP.NET (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe
O23 - Service: Serviço Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 10496 bytes
DDS 1:
.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 0:00:59,75 on 29-12-2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.351.2070.18.3037.1233 [GMT 0:00]
.
AV: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\taskhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Nery\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V14HI7FZ\windows-kb890830-x64-v4.3.exe
c:\491fffec89cd4ac94f55\mrtstub.exe
C:\Windows\system32\MRT.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Nery\Desktop\OTL.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Nery\Desktop\HiJackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Nery\Downloads\dds.scr
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0816&m=el1850&r=17360710q306pe405v145r45n2s323
uDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0816&m=el1850&r=17360710q306pe405v145r45n2s323
mDefault_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0816&m=el1850&r=17360710q306pe405v145r45n2s323
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0816&m=el1850&r=17360710q306pe405v145r45n2s323
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Google Update] "C:\Users\Nery\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [PlayNC Launcher]
uRun: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
uRun: [KPeerNexonEU] C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49}
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6}
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
mRun-x64: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
mRun-x64: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Nery\AppData\Roaming\Mozilla\Firefox\Profiles\hnalx0c0.default\
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\NexonEU\NGM\npNxGameeu.dll
FF - plugin: C:\Users\Nery\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Users\Nery\AppData\Roaming\Mozilla\Firefox\Profiles\hnalx0c0.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: C:\Users\Nery\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\Nery\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2011-5-29 272448]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
R2 epfwwfpr;epfwwfpr;C:\Windows\System32\drivers\epfwwfpr.sys [2009-11-16 123200]
R2 Greg_Service;GRegService;C:\Program Files (x86)\eMachines\Registration\GregHSRW.exe [2009-8-28 1150496]
R2 Updater Service;Updater Service;C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [2009-12-17 240160]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\System32\drivers\vrtaucbl.sys [2010-12-30 66728]
R3 netr7364;Controlador sem Fios Conceptronic RT73 para Vista;C:\Windows\System32\drivers\netr7364.sys [2009-6-10 707072]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-12-17 291328]
S2 gupdate;Serviço Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-28 135664]
S3 cpudrv64;cpudrv64;C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2009-12-18 17864]
S3 gupdatem;Serviço Google Update (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-7-28 135664]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?]
S3 PAC207;SoC PC-Camera;C:\Windows\System32\drivers\PFC027.SYS [2006-12-5 572416]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-25 59392]
S3 WatAdminSvc;Serviço de Tecnologias de Activação do Windows;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-7-30 1255736]
.
=============== Created Last 30 ================
.
2011-12-28 23:36:35 ——– d—–w- C:\491fffec89cd4ac94f55
2011-12-28 23:24:26 ——– d—–w- C:\PROGRA~3\PC Tools
2011-12-28 21:58:36 69000 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{3E159B74-667D-49CE-89CD-A91BCB9813DF}\offreg.dll
2011-12-27 22:04:35 8822856 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{3E159B74-667D-49CE-89CD-A91BCB9813DF}\mpengine.dll
2011-12-25 16:19:46 ——– d—–w- C:\Program Files (x86)\Microsoft Games
2011-12-15 22:30:19 43520 —-a-w- C:\Windows\System32\csrsrv.dll
2011-12-15 22:30:17 3145216 —-a-w- C:\Windows\System32\win32k.sys
2011-12-15 22:30:15 723456 —-a-w- C:\Windows\System32\EncDec.dll
2011-12-15 22:30:15 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll
2011-12-15 22:30:04 2048 —-a-w- C:\Windows\SysWow64\tzres.dll
2011-12-15 22:30:04 2048 —-a-w- C:\Windows\System32\tzres.dll
2011-12-01 01:25:06 476160 —-a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-12-01 01:25:05 288256 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-12-01 01:25:03 2871808 —-a-w- C:\Windows\explorer.exe
2011-12-01 01:25:03 2616320 —-a-w- C:\Windows\SysWow64\explorer.exe
2011-12-01 01:21:22 ——– d—–w- C:\Program Files (x86)\SystemRequirementsLab
2011-12-01 00:24:46 ——– d—–w- C:\Program Files\Perfect World Entertainment
2011-11-29 23:54:23 ——– d—–w- C:\Users\Nery\AppData\Local\Microsoft Help
2011-11-29 09:45:23 ——– d—–w- C:\Program Files (x86)\Free FLAC to MP3 Converter
2011-11-29 09:42:41 ——– d—–w- C:\Program Files (x86)\FLAC to MP3 Converter
2011-11-29 02:27:39 ——– d—–w- C:\Users\Nery\AppData\Roaming\Python-Eggs
2011-11-29 02:27:33 ——– d—–w- C:\Users\Nery\AppData\Roaming\BitLord
2011-11-29 02:25:10 ——– d—–w- C:\Program Files (x86)\BitLord 2
2011-11-29 02:14:06 ——– d—–w- C:\Users\Nery\AppData\Local\uTorrent
.
==================== Find3M ====================
.
2011-11-26 17:10:05 63488 —ha-w- C:\Windows\System32\mspahost64.dll
2011-11-26 17:10:05 55296 ——w- C:\Windows\SysWow64\mspahost.dll
2011-11-15 14:29:56 270720 ——w- C:\Windows\System32\MpSigStub.exe
2011-11-04 01:53:39 2309120 —-a-w- C:\Windows\System32\jscript9.dll
2011-11-04 01:44:47 1390080 —-a-w- C:\Windows\System32\wininet.dll
2011-11-04 01:44:21 1493504 —-a-w- C:\Windows\System32\inetcpl.cpl
2011-11-04 01:34:43 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2011-11-03 22:47:42 1798144 —-a-w- C:\Windows\SysWow64\jscript9.dll
2011-11-03 22:40:21 1427456 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-11-03 22:39:47 1127424 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-11-03 22:31:57 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-22 11:21:42 71680 —-a-w- C:\Windows\System32\frapsv64.dll
2011-10-22 11:21:38 65536 —-a-w- C:\Windows\SysWow64\frapsvid.dll
2011-10-13 12:14:46 162584 —-a-w- C:\Windows\System32\igfxtray.exe
2011-10-13 12:14:44 510232 —-a-w- C:\Windows\System32\igfxsrvc.exe
2011-10-13 12:14:42 417560 —-a-w- C:\Windows\System32\igfxpers.exe
2011-10-13 12:14:40 224024 —-a-w- C:\Windows\System32\igfxext.exe
2011-10-13 12:14:38 386840 —-a-w- C:\Windows\System32\hkcmd.exe
2011-10-13 12:14:32 3157784 —-a-w- C:\Windows\System32\GfxUI.exe
2011-10-13 12:14:30 152856 —-a-w- C:\Windows\System32\difx64.exe
2011-10-13 12:10:12 90112 —-a-w- C:\Windows\System32\igfxCoIn_v2555.dll
2011-10-13 12:05:50 6549504 —-a-w- C:\Windows\System32\igdumd64.dll
2011-10-13 12:05:50 10629184 —-a-w- C:\Windows\System32\drivers\igdkmd64.sys
2011-10-13 12:01:28 4967424 —-a-w- C:\Windows\SysWow64\igdumd32.dll
2011-10-13 11:58:56 571904 —-a-w- C:\Windows\SysWow64\igdumdx32.dll
2011-10-13 11:57:46 4722176 —-a-w- C:\Windows\System32\igd10umd64.dll
2011-10-13 11:55:16 4411392 —-a-w- C:\Windows\SysWow64\igd10umd32.dll
2011-10-13 11:50:04 15546880 —-a-w- C:\Windows\System32\ig4icd64.dll
2011-10-13 11:42:40 11405312 —-a-w- C:\Windows\SysWow64\ig4icd32.dll
2011-10-13 11:37:36 244224 —-a-w- C:\Windows\System32\igfxpph.dll
2011-10-13 11:37:32 380416 —-a-w- C:\Windows\System32\igfxTMM.dll
2011-10-13 11:37:30 27648 —-a-w- C:\Windows\System32\igfxexps.dll
2011-10-13 11:37:12 61952 —-a-w- C:\Windows\System32\igfxsrvc.dll
2011-10-13 11:36:44 108544 —-a-w- C:\Windows\System32\hccutils.dll
2011-10-13 11:36:36 119808 —-a-w- C:\Windows\System32\gfxSrvc.dll
2011-10-13 11:36:34 4096 —-a-w- C:\Windows\System32\IGFXDEVLib.dll
2011-10-13 11:36:34 272896 —-a-w- C:\Windows\System32\igfxdev.dll
2011-10-13 11:36:08 87552 —-a-w- C:\Windows\System32\igfxrenu.lrc
2011-10-13 11:36:04 142336 —-a-w- C:\Windows\System32\igfxdo.dll
2011-10-13 11:36:02 830464 —-a-w- C:\Windows\System32\igfxress.dll
2011-10-13 11:32:34 23552 —-a-w- C:\Windows\SysWow64\igfxexps32.dll
2011-10-13 11:31:48 228864 —-a-w- C:\Windows\SysWow64\igfxdv32.dll
2011-10-13 11:30:12 208896 —-a-w- C:\Windows\SysWow64\iglhsip32.dll
2011-10-13 11:30:12 206336 —-a-w- C:\Windows\System32\iglhsip64.dll
2011-10-13 11:30:12 188416 —-a-w- C:\Windows\System32\iglhcp64.dll
2011-10-13 11:30:12 147456 —-a-w- C:\Windows\SysWow64\iglhcp32.dll
.
============= FINISH: 0:03:34,85 ===============
DDS2:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 28-07-2010 19:36:03
System Uptime: 28-12-2011 22:24:48 (2 hours ago)
.
Motherboard: eMachines | | EL1850
Processor: Intel® Celeron® CPU E3300 @ 2.50GHz | CPU 1 | 2500/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 454 GiB total, 314,485 GiB free.
D: is CDROM (CDFS)
E: is Removable
F: is Removable
G: is CDROM ()
H: is CDROM ()
I: is CDROM ()
J: is CDROM (CDFS)
K: is CDROM (CDFS)
L: is CDROM (CDFS)
M: is CDROM (CDFS)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP196: 06-12-2011 20:54:34 - Windows Update
RP197: 10-12-2011 23:07:08 - Windows Update
RP198: 15-12-2011 22:25:27 - Windows Update
RP199: 16-12-2011 03:00:14 - Windows Update
RP200: 20-12-2011 23:16:20 - Windows Update
RP201: 25-12-2011 16:18:30 - Installed Fable - The Lost Chapters
RP202: 27-12-2011 22:03:32 - Windows Update
.
==== Installed Programs ======================
.
Acrobat.com
Actualização do Microsoft Office Excel 2007 Help (KB963678)
Actualização do Microsoft Office Powerpoint 2007 Help (KB963669)
Actualização do Microsoft Office Word 2007 Help (KB963665)
Adobe AIR
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Illustrator CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Reader X (10.1.1) - Português
Adobe Setup
Adobe Shockwave Player 11.5
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
Advertising Center
Alice Greenfingers
Amazonia
Android Sync Manager WiFi
AVIcodec (remove only)
Bandisoft MPEG-1 Decoder
BitLord 2.0
Blue Byte Game Channel
Chicken Invaders 2
DAEMON Tools Pro
Dairy Dash
DivX Setup
Dragon Nest SEA
Dream Day First Home
eMachines GameZone Console
eMachines Recovery Management
eMachines Registration
eMachines ScreenSaver
eMachines Updater
Fable - The Lost Chapters
Farm Frenzy 2
Ferramenta de Carregamento do Windows Live
First Class Flurry
FormatFactory 2.60
Fraps
Free FLAC to MP3 Converter 1.0
Galeria de Fotografias do Windows Live
Gangsters 2
Google Chrome
Google Earth
Google Talk Plugin
Google Update Helper
Granny In Paradise
Identity Card
ImagXpress
Intel® Control Center
Intel® Graphics Media Accelerator Driver
Java Auto Updater
Java™ 6 Update 24
Junk Mail filter update
K-Lite Mega Codec Pack 7.0.0
League of Legends
Macromedia FreeHand 10
Macromedia FreeHand MXa
Magic FLAC to MP3 Converter 3.72
Merriam Websters Spell Jam
Microsoft .NET Framework 1.1
Microsoft Choice Guard
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (Portuguese (Portugal)) 2007
Microsoft Office Excel MUI (Portuguese (Portugal)) 2007
Microsoft Office Groove MUI (Portuguese (Portugal)) 2007
Microsoft Office InfoPath MUI (Portuguese (Portugal)) 2007
Microsoft Office Language Pack 2007 - Portuguese/Português
Microsoft Office O MUI (Portuguese (Portugal)) 2007
Microsoft Office OneNote MUI (Portuguese (Portugal)) 2007
Microsoft Office Outlook MUI (Portuguese (Portugal)) 2007
Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Portuguese (Portugal)) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (Portuguese (Portugal)) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (Portuguese (Portugal)) 2007
Microsoft Office Shared MUI (Portuguese (Portugal)) 2007
Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)
Microsoft Office SharePoint Designer MUI (Portuguese (Portugal)) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (Portuguese (Portugal)) 2007
Microsoft Office X MUI (Portuguese (Portugal)) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
mIRC
Mozilla Firefox 9.0.1 (x86 pt-PT)
MpcStar 5.0
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NCsoft Launcher
Nero 9 Essentials
Nero ControlCenter
Nero DiscSpeed
Nero DiscSpeed Help
Nero DriveSpeed
Nero DriveSpeed Help
Nero Express Help
Nero InfoTool
Nero InfoTool Help
Nero Installer
Nero Online Upgrade
Nero StartSmart
Nero StartSmart Help
Nero StartSmart OEM
NeroExpress
neroxml
Nexon Game Manager
OpenOffice.org 3.3
Pando Media Booster
PDF Settings
PDFCreator
Pizza Syndicate
Quick Memory Editor 4.2
Realtek High Definition Audio Driver
RegCure
Rift BETA Patcher
RollerCoaster Tycoon 2
Skype Click to Call
Skype™ 5.5
System Requirements Lab for Intel
The Settlers IV
USB PC CAMERA P227
VC80CRTRedist - 8.0.50727.4053
Vindictus
VLC media player 1.1.7
Welcome Center
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live OneCare safety scanner
Windows Live Sync
Windows Live Writer
Xfire (remove only)
.
==== End Of File ===========================