ComboFix didn't work. At all. Not even in safe mode =/
So I followed your advice and I ran that other program. Here are the logs:
OTL.txt
OTL logfile created on: 23-04-2012 20:05:55 - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = C:\Users\coimbra\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy
3,00 Gb Total Physical Memory | 1,82 Gb Available Physical Memory | 60,66% Memory free
6,20 Gb Paging File | 5,09 Gb Available in Paging File | 82,13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 151,64 Gb Total Space | 21,98 Gb Free Space | 14,49% Space Free | Partition Type: NTFS
Drive E: | 144,99 Gb Total Space | 45,68 Gb Free Space | 31,51% Space Free | Partition Type: NTFS
Computer Name: COMPUTADOR | User Name: coimbra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\coimbra\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programas\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Programas\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programas\DAZ 3D\Content Management Service\ContentManagementServer.exe ()
PRC - C:\Programas\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Programas\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programas\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Programas\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Programas\Toshiba\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - c:\Programas\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Programas\O2Micro Flash Memory Card Driver\o2flash.exe (O2Micro International)
PRC - C:\Programas\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Programas\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Programas\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\Programas\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Programas\WinRAR\RarExt.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Programas\Toshiba\PCDiag\NotifyPCD.dll ()
MOD - C:\Programas\Toshiba\FlashCards\TWarnMsg\TWarnMsg.dll ()
MOD - C:\Programas\Toshiba\FlashCards\BlackPng.dll ()
MOD - C:\Programas\Toshiba\TBS\NotifyTBS.dll ()
MOD - C:\Programas\Toshiba\TOSHIBA Assist\NotifyX.dll ()
MOD - C:\Programas\Toshiba\TOSHIBA Disc Creator\NotifyTDC.dll ()
========== Win32 Services (SafeList) ==========
SRV - (StarWindServiceAE) – File not found
SRV - (Automatic CDROM Monitor) – File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (sdCoreService) – C:\Programas\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Programas\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Programas\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (AdobeARMservice) – C:\Programas\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (odserv) – C:\Programas\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (DAZContentManagementService) – C:\Programas\DAZ 3D\Content Management Service\ContentManagementServer.exe ()
SRV - (fsssvc) – C:\Programas\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (ServiceLayer) – C:\Programas\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (SeaPort) – C:\Programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Programas\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (VMCService) – C:\Programas\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (TNaviSrv) – C:\Programas\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Programas\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) – C:\Programas\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (TosCoSrv) – C:\Programas\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:\Programas\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) – C:\Programas\Toshiba\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA Bluetooth Service) – c:\Programas\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (o2flash) – C:\Programas\O2Micro Flash Memory Card Driver\o2flash.exe (O2Micro International)
SRV - (SSScsiSV) – C:\Programas\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (SonicStage Back-End Service) – C:\Programas\Common Files\Sony Shared\AVLib\SsBeSvc.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Programas\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Programas\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Programas\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (ose) – C:\Programas\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (UleadBurningHelper) – C:\Programas\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (lxcj_device) – C:\Windows\System32\lxcjcoms.exe ( )
========== Driver Services (SafeList) ==========
DRV - (ZTEusbser6k) – File not found
DRV - (ZTEusbnmea) – File not found
DRV - (ZTEusbmdm6k) – File not found
DRV - (zlportio) – C:\Program Files\UltraStar Deluxe\zlportio.sys File not found
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – File not found
DRV - (NwlnkFwd) – File not found
DRV - (NwlnkFlt) – File not found
DRV - (IpInIp) – File not found
DRV - (IntcHdmiAddService) Intel® – File not found
DRV - (igfx) – File not found
DRV - (catchme) – C:\Users\coimbra\AppData\Local\Temp\catchme.sys File not found
DRV - (ad06h4do) – File not found
DRV - (pctplfw) – C:\Windows\System32\drivers\pctplfw.sys (PC Tools)
DRV - (pctNdisLW) – C:\Windows\System32\drivers\pctNdisLW.sys (PC Tools)
DRV - (apf001) – C:\Windows\System32\apf001.sys ()
DRV - (pctplsg) – C:\Windows\System32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) – C:\Windows\System32\drivers\PCTSD.sys (PC Tools)
DRV - (pctBTFix) – C:\Windows\System32\drivers\pctBTFix.sys (PC Tools)
DRV - (pctgntdi) – C:\Windows\System32\drivers\pctgntdi.sys (PC Tools)
DRV - (TFSysMon) – C:\Windows\System32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\Windows\System32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\Windows\System32\drivers\TfNetMon.sys (PC Tools)
DRV - (pctEFA) – C:\Windows\System32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\Windows\System32\drivers\pctDS.sys (PC Tools)
DRV - (PCTCore) – C:\Windows\System32\drivers\PCTCore.sys (PC Tools)
DRV - (PCTAppEvent) – C:\Windows\System32\drivers\PCTAppEvent.sys (PC Tools)
DRV - (PCTBD) – C:\Windows\System32\drivers\PCTBD.sys (PC Tools)
DRV - (libusb0) – C:\Windows\System32\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV - (MotioninJoyXFilter) – C:\Windows\System32\drivers\MijXfilt.sys (MotioninJoy)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdnsu) – C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdnsuc) – C:\Windows\System32\drivers\nmwcdnsuc.sys (Nokia)
DRV - (Mkd2kfNt) – C:\Windows\System32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (Mkd2Nadr) – C:\Windows\System32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (sptd) – C:\Windows\System32\drivers\sptd.sys ()
DRV - (NETw5v32) Intel® – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (CnxtHdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (tos_sps32) – C:\Windows\System32\drivers\tos_sps32.sys (TOSHIBA Corporation)
DRV - (O2MDRDR) – C:\Windows\System32\drivers\o2media.sys (O2Micro )
DRV - (tosrfbd) – C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (Tosrfhid) – C:\Windows\System32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosrfbnp) – C:\Windows\System32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfcom) – C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (NETw4v32) Controlador do Adaptador da ligação WiFi sem fios Intel® – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (QIOMem) – C:\Windows\System32\drivers\QIOMem.sys (TOSHIBA)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (tosrfec) – C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (tosporte) – C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\Windows\System32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
IE - HKLM\..\SearchScopes,DefaultScope = {98E36557-BAF2-43F5-AF12-E20791AC3A09}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://startsear.ch/?aff=1&src;=sp&…q={searchTerms}
IE - HKLM\..\SearchScopes\{98E36557-BAF2-43F5-AF12-E20791AC3A09}: "URL" =
http://www.google.pt/search?q={searchTerms…p;sourceid=ie7;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.pt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://pt.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Programas\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://startsear.ch/?aff=1&src;=sp&…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "
http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Google.pt"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.pt/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: multilinks@plugin:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.4
FF - prefs.js..extensions.enabledItems: {9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}:3.0.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [removed]:1.3.4
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.1829
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src;=sp&cf;=a6c18f78-08af-11e1-8b63-8ad0386e9ad0&q;="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\coimbra\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\coimbra\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\coimbra\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009-07-05 02:37:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2012-04-18 15:26:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-04-17 14:39:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-04-14 17:06:58 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Veoh Networks\VeohWebPlayer\FFVideoFinder [2009-06-21 18:30:16 | 000,000,000 | —D | M]
[2010-02-20 20:26:47 | 000,000,000 | —D | M] (No name found) – C:\Users\coimbra\AppData\Roaming\mozilla\Extensions
[2010-02-20 20:26:47 | 000,000,000 | —D | M] (No name found) – C:\Users\coimbra\AppData\Roaming\mozilla\Extensions\[removed]
[2012-04-17 14:39:48 | 000,000,000 | —D | M] (No name found) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions
[2010-04-07 21:35:13 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010-03-14 22:44:46 | 000,000,000 | —D | M] (CookieSafe) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}
[2012-04-17 14:39:48 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012-03-08 00:14:17 | 000,000,000 | —D | M] (Corretor para Português de Portugal) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\[removed]
[2010-11-04 23:16:34 | 000,001,927 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\encyclopedia-search.xml
[2010-11-04 23:13:46 | 000,005,419 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\googlept.xml
[2011-07-11 19:04:02 | 000,000,633 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\startsear.xml
[2010-11-04 23:09:50 | 000,004,140 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\youtube.xml
[2012-04-17 14:39:37 | 000,000,000 | —D | M] (No name found) – C:\Programas\Mozilla Firefox\extensions
() (No name found) – C:\USERS\COIMBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\85ZY9BWZ.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\USERS\COIMBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\85ZY9BWZ.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\COIMBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\85ZY9BWZ.DEFAULT\EXTENSIONS\[removed]
[2012-03-13 05:38:06 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012-02-16 04:26:37 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009-09-21 02:11:17 | 000,072,960 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2011-10-03 10:14:54 | 000,083,456 | —- | M] (vShare.tv ) – C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2011-03-22 19:38:12 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012-03-13 06:51:17 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012-03-13 06:51:17 | 000,001,529 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\priberam.xml
[2012-03-13 06:51:17 | 000,002,071 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\sapo.xml
[2012-03-13 06:51:17 | 000,000,942 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-ptpt.xml
========== Chrome ==========
CHR - default_search_provider: Google (Predefini\u00E7\u00E3o) (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npvsharetvplg.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\coimbra\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: FB Chat Sidebar Disabler = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\beeidigicffecnkbanlfnmaplmkafdje\2.4.8_0\
CHR - Extension: YouTube = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus (Beta) = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Pesquisa do Google = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: SmallringFX DarkBlue Theme = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfijmgohofmpjlcgmjplbpmkpchdhpk\1.7_0\
CHR - Extension: Linkclump = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfpjkncokllnfokkgpkobnkbkmelfefj\2.0.17_0\
CHR - Extension: Gmail = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2006-09-18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Programas\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Programas\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O2 - BHO: (Programa Auxiliar de Início de Sessão do Windows Live ID) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programas\Free Download Manager\iefdm2.dll ()
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programas\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Programas\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Programas\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HSON] C:\Programas\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [LXCJCATS] C:\Windows\System32\spool\DRIVERS\W32X86\3\LXCJtime.DLL ()
O4 - HKLM..\Run: [SmoothView] C:\Programas\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Programas\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - Startup: C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\coimbra\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O8 - Extra context menu item: Transferência seleccionada pelo FDM - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Transferir com FDM - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Transferir todos com FDM - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Transferir vídeo com FDM - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O9 - Extra Button: Publicar em Blogue - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Publicar; no Blogue no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar; para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programas\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653}
http://messenger.zone.msn.com/MessengerGam…S.cab109791.cab ()
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D}
http://content.systemrequirementslab.com.s…yri_4.3.1.0.cab (SysInfo Class)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A4C3FC56-EE04-4EE7-82B7-3BF50C28986C}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programas\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programas\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programas\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSTEM32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - File not found
O24 - Desktop WallPaper: C:\Users\coimbra\Pictures\Wallpapers\[animepaper.net]wallpaper-art-artists-sena-way-out-of-here-226993-fnatt-1280x800-b369d999.jpg
O24 - Desktop BackupWallPaper: C:\Users\coimbra\Pictures\Wallpapers\[animepaper.net]wallpaper-art-artists-sena-way-out-of-here-226993-fnatt-1280x800-b369d999.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0050a06f-ea7e-11de-bfe8-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{0050a06f-ea7e-11de-bfe8-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0050a070-ea7e-11de-bfe8-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{0050a070-ea7e-11de-bfe8-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{047897fb-7809-11e1-9904-8b027e70d36c}\Shell - "" = AutoRun
O33 - MountPoints2\{047897fb-7809-11e1-9904-8b027e70d36c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{04789804-7809-11e1-9904-8b027e70d36c}\Shell - "" = AutoRun
O33 - MountPoints2\{04789804-7809-11e1-9904-8b027e70d36c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{0ba442ef-7dc7-11dd-a121-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{0ba442ef-7dc7-11dd-a121-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{0ba442f6-7dc7-11dd-a121-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{0ba442f6-7dc7-11dd-a121-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{22acd90c-b9b7-11de-b592-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{22acd90c-b9b7-11de-b592-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{22acd924-b9b7-11de-b592-00037a8a3848}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Fixer32.exe
O33 - MountPoints2\{22acd924-b9b7-11de-b592-00037a8a3848}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Fixer32.exe
O33 - MountPoints2\{3c652fab-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{3c652fab-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{3c652fb6-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{3c652fb6-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{3c652fb8-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{3c652fb8-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{3c652fba-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{3c652fba-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{4a8cd8b0-c3c4-11de-be15-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{4a8cd8b0-c3c4-11de-be15-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{52c82829-7735-11df-80ad-efd5b989612a}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\kazEwAShI.eXE
O33 - MountPoints2\{580a38a1-7b99-11dd-91ed-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{580a38a1-7b99-11dd-91ed-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{633cc66b-6c61-11e1-9284-c9f1be4eb307}\Shell - "" = AutoRun
O33 - MountPoints2\{633cc66b-6c61-11e1-9284-c9f1be4eb307}\Shell\AutoRun\command - "" = G:\setup.exe AUTORUN=1
O33 - MountPoints2\{63be626d-dabe-11de-baec-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{63be626d-dabe-11de-baec-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{63faee14-bc2e-11de-a49c-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{63faee14-bc2e-11de-a49c-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell\AutoRun\command - "" = D:\autorun.exe
O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell\setup\command - "" = D:\setup.exe
O33 - MountPoints2\{6865071c-b74f-11de-9b69-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{6865071c-b74f-11de-9b69-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{736d7796-be78-11de-95f3-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{736d7796-be78-11de-95f3-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{73b9bb8b-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{73b9bb8b-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{73b9bba8-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{73b9bba8-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{73b9bbab-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{73b9bbab-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{7b1ee4a3-7ad4-11dd-b6d1-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{7b1ee4a3-7ad4-11dd-b6d1-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{7b1ee4a9-7ad4-11dd-b6d1-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{7b1ee4a9-7ad4-11dd-b6d1-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{8e051f9c-e902-11de-a649-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{8e051f9c-e902-11de-a649-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{956ec7de-0cbf-11df-ba60-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{956ec7de-0cbf-11df-ba60-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ad1a8282-8733-11dd-b4ea-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{ad1a8282-8733-11dd-b4ea-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{ae9e76a9-bda4-11de-bae2-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{ae9e76a9-bda4-11de-bae2-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ae9e76c2-bda4-11de-bae2-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{ae9e76c2-bda4-11de-bae2-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b2187d5e-ddac-11de-af9d-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{b2187d5e-ddac-11de-af9d-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b4b72941-8654-11dd-b3e1-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{b4b72941-8654-11dd-b3e1-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{c032af19-b710-11de-ae35-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{c032af19-b710-11de-ae35-00037a8a3848}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{c756d7f2-a48b-11de-be0b-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{c756d7f2-a48b-11de-be0b-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{da664491-1e76-11e0-9edc-ac4d52f2073d}\Shell - "" = AutoRun
O33 - MountPoints2\{da664491-1e76-11e0-9edc-ac4d52f2073d}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\{e7849982-7da1-11dd-9ff8-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{e7849982-7da1-11dd-9ff8-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{e7849985-7da1-11dd-9ff8-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{e7849985-7da1-11dd-9ff8-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{e92b0683-e41e-11de-81cc-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{e92b0683-e41e-11de-81cc-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{eb03467f-24b6-11df-ab77-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{eb03467f-24b6-11df-ab77-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{eb0346a2-24b6-11df-ab77-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{eb0346a2-24b6-11df-ab77-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{f4f40baf-2b7e-11df-9201-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f4f40baf-2b7e-11df-9201-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk /r \??\E:)
O34 - HKLM BootExecute: (autocheck autochk /r \??\C:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012-04-23 20:02:17 | 000,594,944 | —- | C] (OldTimer Tools) – C:\Users\coimbra\Desktop\OTL.exe
[2012-04-23 19:45:20 | 000,000,000 | —D | C] – C:\ComboFix
[2012-04-23 00:38:30 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012-04-23 00:38:30 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012-04-23 00:38:30 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012-04-23 00:38:19 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012-04-23 00:38:14 | 000,000,000 | —D | C] – C:\Qoobox
[2012-04-22 20:40:25 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2012-04-22 20:38:50 | 004,472,002 | R— | C] (Swearware) – C:\Users\coimbra\Desktop\ComboFix.exe
[2012-04-22 20:36:01 | 000,000,000 | R–D | C] – C:\Users\coimbra\Dropbox
[2012-04-22 20:33:49 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012-04-22 20:32:57 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Dropbox
[2012-04-22 16:42:07 | 002,072,624 | —- | C] (Kaspersky Lab ZAO) – C:\Users\coimbra\Desktop\tdsskiller.exe
[2012-04-22 15:05:50 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\coimbra\Desktop\aswMBR.exe
[2012-04-22 15:04:39 | 000,607,260 | R— | C] (Swearware) – C:\Users\coimbra\Desktop\dds.com
[2012-04-21 20:45:55 | 000,000,000 | —D | C] – C:\sh4ldr
[2012-04-21 20:45:55 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012-04-21 20:27:30 | 000,000,000 | —D | C] – C:\Program Files\ExpressFiles
[2012-04-21 20:07:55 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\SpeedyPC Software
[2012-04-21 20:07:55 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\DriverCure
[2012-04-21 20:07:49 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012-04-20 04:21:19 | 000,000,000 | -HSD | C] – C:\found.002
[2012-04-19 23:17:25 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012-04-19 00:17:29 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\PCTools
[2012-04-18 15:44:02 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\PC Tools
[2012-04-18 15:44:01 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Spam Monitor
[2012-04-18 15:38:11 | 000,574,424 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys
[2012-04-18 15:38:11 | 000,054,328 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2012-04-18 15:38:11 | 000,035,264 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2012-04-18 15:33:33 | 000,125,888 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2012-04-18 15:33:30 | 000,091,136 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2012-04-18 15:33:30 | 000,058,400 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdisLW.sys
[2012-04-18 15:33:30 | 000,032,936 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2012-04-18 15:26:32 | 000,056,840 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTBD.sys
[2012-04-18 15:26:31 | 002,250,704 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll
[2012-04-18 15:26:31 | 000,149,456 | —- | C] (PC Tools) – C:\Windows\SGDetectionTool.dll
[2012-04-18 15:26:30 | 001,681,360 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDRes.dll
[2012-04-18 15:24:12 | 000,909,728 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctEFA.sys
[2012-04-18 15:24:12 | 000,342,168 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctDS.sys
[2012-04-18 15:24:10 | 000,253,352 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2012-04-18 15:24:10 | 000,107,864 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctwfpfilter.sys
[2012-04-18 15:24:04 | 000,331,880 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2012-04-18 15:24:04 | 000,162,584 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2012-04-18 15:24:01 | 000,185,560 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTSD.sys
[2012-04-18 15:24:01 | 000,017,848 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctBTFix.sys
[2012-04-18 15:24:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2012-04-18 15:23:56 | 000,070,536 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplsg.sys
[2012-04-18 15:23:45 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2012-04-18 15:23:45 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2012-04-18 15:23:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2012-04-17 18:42:50 | 000,418,464 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012-04-15 19:33:56 | 000,000,000 | —D | C] – C:\Users\coimbra\Documents\Cenas da mãe
[2012-04-12 18:24:23 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ragray
[2012-04-12 18:05:57 | 000,000,000 | —D | C] – C:\Program Files\Ragray
[2012-04-12 17:54:06 | 000,000,000 | —D | C] – C:\Program Files\1RO
[2012-04-11 10:56:20 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012-04-11 10:56:18 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012-04-11 10:56:17 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012-04-11 10:56:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012-04-11 10:56:16 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012-04-11 10:56:15 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012-04-11 10:53:47 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012-04-11 10:53:47 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012-04-02 19:39:33 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\LolClient
[2012-04-02 18:20:01 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_39.dll
[2012-04-02 18:20:01 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_39.dll
[2012-04-02 18:19:58 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_39.dll
[2012-04-02 18:09:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2012-04-02 16:38:32 | 000,000,000 | —D | C] – C:\Program Files\Pando Networks
[2012-03-30 00:59:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAZ Productions
[2012-03-30 00:58:58 | 000,090,112 | —- | C] (MindVision Software) – C:\Windows\unvise32.exe
[2012-03-27 14:26:53 | 000,000,000 | —D | C] – C:\ProgramData\Vodafone
[2012-03-27 14:26:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vodafone
[2012-03-27 14:26:42 | 000,000,000 | —D | C] – C:\Program Files\Vodafone
[2012-03-27 14:25:32 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Local\{D53238E8-3427-491E-A57E-097FA966AAC1}
[2012-03-26 17:40:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
[2012-03-26 17:40:18 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2012-03-26 17:39:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Canon
[2012-03-25 04:22:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DAZ
[2012-03-25 04:18:44 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D
[2012-03-25 04:18:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAZ 3D
[2012-03-25 04:18:16 | 000,000,000 | —D | C] – C:\ProgramData\DAZ 3D
[2012-03-25 04:17:32 | 000,000,000 | —D | C] – C:\Users\coimbra\Documents\DAZ 3D
[2012-03-25 04:16:17 | 000,000,000 | —D | C] – C:\Program Files\DAZ 3D
[2012-03-25 04:14:19 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\DAZ 3D
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-04-23 20:07:16 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-04-23 20:02:23 | 000,044,544 | —- | M] (Absolute Software Corp.) – C:\Windows\System32\agremove.exe
[2012-04-23 20:02:12 | 000,594,944 | —- | M] (OldTimer Tools) – C:\Users\coimbra\Desktop\OTL.exe
[2012-04-23 19:58:42 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012-04-23 19:58:42 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012-04-23 19:58:12 | 000,000,998 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-04-23 19:56:45 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012-04-23 19:56:30 | 3219,578,880 | -HS- | M] () – C:\hiberfil.sys
[2012-04-23 19:33:17 | 000,001,002 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-04-23 19:33:16 | 000,001,030 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2519787931-4213243981-2891937994-1000UA.job
[2012-04-23 00:37:31 | 004,472,002 | R— | M] (Swearware) – C:\Users\coimbra\Desktop\ComboFix.exe
[2012-04-22 21:14:05 | 002,402,047 | —- | M] () – C:\Windows\System32\drivers\Cat.DB
[2012-04-22 20:36:01 | 000,000,987 | —- | M] () – C:\Users\coimbra\Desktop\Dropbox.lnk
[2012-04-22 20:34:11 | 000,000,967 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012-04-22 20:04:08 | 000,222,625 | —- | M] () – C:\Users\coimbra\Documents\marcadores_22_04_12.html
[2012-04-22 16:42:06 | 002,072,624 | —- | M] (Kaspersky Lab ZAO) – C:\Users\coimbra\Desktop\tdsskiller.exe
[2012-04-22 16:06:00 | 000,000,512 | —- | M] () – C:\Users\coimbra\Documents\MBR.dat
[2012-04-22 15:05:56 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\coimbra\Desktop\aswMBR.exe
[2012-04-22 15:04:35 | 000,607,260 | R— | M] (Swearware) – C:\Users\coimbra\Desktop\dds.com
[2012-04-22 01:55:00 | 000,000,978 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2519787931-4213243981-2891937994-1000Core.job
[2012-04-21 22:07:09 | 000,002,527 | —- | M] () – C:\Users\coimbra\Desktop\HiJackThis.lnk
[2012-04-21 00:10:45 | 000,662,798 | —- | M] () – C:\Windows\System32\prfh0816.dat
[2012-04-21 00:10:45 | 000,598,900 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012-04-21 00:10:45 | 000,131,986 | —- | M] () – C:\Windows\System32\prfc0816.dat
[2012-04-21 00:10:45 | 000,104,914 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012-04-19 02:26:15 | 000,303,902 | —- | M] () – C:\Users\coimbra\Documents\Formulário.pdf
[2012-04-18 17:21:28 | 000,000,000 | —- | M] () – C:\Windows\System32\SM.lock
[2012-04-18 15:33:33 | 000,125,888 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2012-04-18 15:33:30 | 000,091,136 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2012-04-18 15:33:30 | 000,058,400 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdisLW.sys
[2012-04-18 15:33:30 | 000,032,936 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2012-04-18 15:32:24 | 000,001,817 | —- | M] () – C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2012-04-17 19:07:30 | 000,418,464 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012-04-17 19:07:30 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012-04-17 14:39:41 | 000,000,875 | —- | M] () – C:\Users\coimbra\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012-04-17 14:39:40 | 000,000,851 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012-04-14 19:57:43 | 000,002,019 | —- | M] () – C:\Users\coimbra\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012-04-14 19:57:42 | 000,002,057 | —- | M] () – C:\Users\coimbra\Desktop\Google Chrome.lnk
[2012-04-11 10:24:12 | 000,001,356 | —- | M] () – C:\Users\coimbra\AppData\Local\d3d9caps.dat
[2012-04-07 23:14:44 | 000,024,064 | —- | M] () – C:\Users\coimbra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-04-06 20:41:05 | 000,054,338 | —- | M] () – C:\Users\coimbra\Documents\Guião Trabalho de Grupo TOIV.pdf
[2012-04-04 02:04:49 | 000,000,718 | —- | M] () – C:\Users\coimbra\Desktop\Play League of Legends.lnk
[2012-04-02 00:46:34 | 000,000,809 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012-03-27 16:40:34 | 000,075,757 | —- | M] () – C:\Users\coimbra\Documents\Trabalho Prático 3.pdf
[2012-03-26 18:23:01 | 000,554,858 | —- | M] () – C:\Users\coimbra\Documents\Documentos ENETO.pdf
[2012-03-25 04:18:45 | 000,001,849 | —- | M] () – C:\Users\coimbra\Desktop\DAZ Studio 4.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-04-23 19:48:39 | 3219,578,880 | -HS- | C] () – C:\hiberfil.sys
[2012-04-23 00:38:30 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012-04-23 00:38:30 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012-04-23 00:38:30 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012-04-23 00:38:30 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012-04-23 00:38:30 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012-04-22 20:36:01 | 000,000,987 | —- | C] () – C:\Users\coimbra\Desktop\Dropbox.lnk
[2012-04-22 20:34:11 | 000,000,967 | —- | C] () – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012-04-22 20:04:07 | 000,222,625 | —- | C] () – C:\Users\coimbra\Documents\marcadores_22_04_12.html
[2012-04-22 16:06:00 | 000,000,512 | —- | C] () – C:\Users\coimbra\Documents\MBR.dat
[2012-04-19 02:13:00 | 000,303,902 | —- | C] () – C:\Users\coimbra\Documents\Formulário.pdf
[2012-04-18 17:21:28 | 000,000,000 | —- | C] () – C:\Windows\System32\SM.lock
[2012-04-18 15:32:24 | 000,001,817 | —- | C] () – C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2012-04-18 15:26:32 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll
[2012-04-18 15:26:31 | 000,003,488 | —- | C] () – C:\Windows\UDB.zip
[2012-04-18 15:26:31 | 000,000,882 | —- | C] () – C:\Windows\RegSDImport.xml
[2012-04-18 15:26:31 | 000,000,879 | —- | C] () – C:\Windows\RegISSImport.xml
[2012-04-18 15:26:31 | 000,000,131 | —- | C] () – C:\Windows\IDB.zip
[2012-04-18 15:24:13 | 002,402,047 | —- | C] () – C:\Windows\System32\drivers\Cat.DB
[2012-04-17 18:42:51 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-04-06 20:41:01 | 000,054,338 | —- | C] () – C:\Users\coimbra\Documents\Guião Trabalho de Grupo TOIV.pdf
[2012-04-04 02:04:49 | 000,000,718 | —- | C] () – C:\Users\coimbra\Desktop\Play League of Legends.lnk
[2012-03-27 16:39:19 | 000,075,757 | —- | C] () – C:\Users\coimbra\Documents\Trabalho Prático 3.pdf
[2012-03-26 18:17:02 | 000,554,858 | —- | C] () – C:\Users\coimbra\Documents\Documentos ENETO.pdf
[2012-03-25 04:18:45 | 000,001,849 | —- | C] () – C:\Users\coimbra\Desktop\DAZ Studio 4.lnk
[2012-03-12 03:09:33 | 000,012,920 | —- | C] () – C:\Windows\System32\apl001.sys
[2012-03-12 03:09:33 | 000,010,872 | —- | C] () – C:\Windows\System32\apf001.sys
[2011-08-09 20:44:41 | 000,000,056 | —- | C] () – C:\Windows\wininit.ini
[2011-07-08 16:52:55 | 000,175,616 | —- | C] () – C:\Windows\System32\unrar.dll
[2011-06-19 18:04:33 | 000,532,480 | —- | C] () – C:\Windows\System32\CddbPlaylist2Sony.dll
[2011-04-17 21:57:44 | 000,000,496 | —- | C] () – C:\Windows\System32\lxcjplc.ini
[2010-12-21 00:06:58 | 000,000,136 | —- | C] () – C:\Windows\System32\winsusrm.dll
[2010-12-21 00:06:09 | 000,000,120 | —- | C] () – C:\Windows\System32\winsusrx.dll
========== LOP Check ==========
[2011-01-12 15:09:58 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Aegisub
[2011-01-07 12:40:26 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Aunsoft
[2011-02-13 05:24:41 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\AVG
[2010-01-27 03:38:03 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Azureus
[2011-01-10 16:20:14 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\BadApple!!
[2011-11-15 03:20:50 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Canneverbe Limited
[2009-05-01 02:24:45 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\DAEMON Tools
[2012-04-17 18:55:44 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\DAEMON Tools Lite
[2012-03-25 06:14:58 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\DAZ 3D
[2010-04-10 19:25:23 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Downloaded Installations
[2012-04-21 20:07:55 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\DriverCure
[2012-04-23 19:58:42 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Dropbox
[2010-06-17 14:35:40 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Facebook
[2010-01-24 20:24:23 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\fltk.org
[2009-04-10 18:11:59 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Foxit
[2009-10-12 11:18:56 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Foxit Software
[2012-04-21 20:48:41 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Free Download Manager
[2009-05-02 21:09:58 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\fretsonfire
[2011-06-10 23:09:05 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\GetRightToGo
[2011-10-27 12:12:06 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Leawo
[2010-07-10 22:01:56 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\LimeWire
[2012-04-02 19:39:33 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\LolClient
[2009-07-01 01:07:31 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Nokia
[2009-07-01 00:29:45 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\PC Suite
[2012-04-19 00:17:29 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\PCTools
[2010-02-03 17:03:03 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\PeerNetworking
[2012-03-24 07:03:57 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Poser
[2009-12-09 22:29:07 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\PrimoPDF
[2011-02-08 21:06:11 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Publish Providers
[2010-12-12 00:00:48 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Sony
[2011-02-08 20:04:36 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Sony Creative Software
[2012-04-18 15:44:01 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Spam Monitor
[2012-04-21 20:07:55 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\SpeedyPC Software
[2009-03-22 01:40:17 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\SYSTEMAX Software Development
[2011-12-07 03:56:14 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\SystemRequirementsLab
[2012-04-22 20:20:56 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\TOSHIBA
[2012-04-18 15:24:12 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\uTorrent
[2008-09-04 23:59:02 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Vodafone
[2011-10-27 12:04:58 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Xilisoft
[2012-04-23 19:36:20 | 000,032,600 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:888AFB86
< End of report >
Extras.txt
OTL Extras logfile created on: 23-04-2012 20:05:55 - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = C:\Users\coimbra\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy
3,00 Gb Total Physical Memory | 1,82 Gb Available Physical Memory | 60,66% Memory free
6,20 Gb Paging File | 5,09 Gb Available in Paging File | 82,13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 151,64 Gb Total Space | 21,98 Gb Free Space | 14,49% Space Free | Partition Type: NTFS
Drive E: | 144,99 Gb Total Space | 45,68 Gb Free Space | 31,51% Space Free | Partition Type: NTFS
Computer Name: COMPUTADOR | User Name: coimbra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00A8CF55-FF0B-4693-905D-9BCF548B9050}" = lport=138 | protocol=17 | dir=in | app=system |
"{1F7A589B-512C-4EE6-AB0E-C70A4E6FF5A8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{30F1F62F-B950-421B-B871-93C1D7457837}" = rport=445 | protocol=6 | dir=out | app=system |
"{56B3D76F-6B81-4B5C-BA10-8C198F1B5679}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6191AF5E-F098-4611-9FAC-8AF00C99E441}" = rport=137 | protocol=17 | dir=out | app=system |
"{6541933E-7945-41A4-8F8C-25235D115F20}" = rport=139 | protocol=6 | dir=out | app=system |
"{74C23442-2FAF-4A88-849A-135E0BF73944}" = lport=139 | protocol=6 | dir=in | app=system |
"{842D7319-0A88-40F4-9754-B19ADDFD46BB}" = rport=138 | protocol=17 | dir=out | app=system |
"{A23FE6FF-175D-4AFB-9B68-B923236C8986}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{ACF90FE1-0EA8-4CE0-BBEF-81AB1A0B986A}" = lport=137 | protocol=17 | dir=in | app=system |
"{B30F85E3-474E-4D4B-ADF7-567C55B179D3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F4BDA566-45ED-4B4A-A1D0-854D626F38E1}" = lport=445 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04B659DA-1BA4-4FCD-B041-F0481848F271}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{15C26647-661F-4CE4-9397-0FCADEFDF8DF}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{15D895D4-9471-434F-8AEB-2A11D3D800F3}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{1C4E735A-AA72-4E76-823B-2728220EE5A1}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{1FBAFADC-3800-4368-BEF7-F63FDFF98CF7}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{2159F005-CA2A-440B-9902-07C0F93D7CEC}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{2ACE4A16-2E90-4A55-8D82-EF271A10F9E1}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{2D563A6F-2D3E-4AB9-9182-1FDCC52F62F7}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
"{2F61CF34-C7CC-4741-A9A7-81792D0860EF}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3054DFF0-EE34-486D-8D38-9599236257A4}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{3153A9CC-E5DE-437A-8515-19EB3F8567E5}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
"{34D792FF-50B5-4110-B8D7-5D2BB3E50887}" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3y.exe |
"{46D3707D-8C17-4425-9666-DE29A88E5412}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
"{49DC2A34-10C8-4788-84D3-8254E7FD9D99}" = protocol=6 | dir=in | app=c:\users\coimbra\appdata\roaming\dropbox\bin\dropbox.exe |
"{543CCD9B-7527-4EE0-A945-61B0165B0E43}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
"{69B93AFE-69B7-45CE-881C-8AC3B3E15BED}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6AB39284-B46F-454E-81F7-57EB89DC9CBD}" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"{7213BFEE-C89B-41D8-A4BC-26A4C56C8F4F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{7756D0ED-F6EC-408F-8C40-9F63FAFA04EF}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{7B770FD1-B11D-401B-A7CC-13BCC2FF85F2}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{8D613B80-8697-42AC-8D26-36160AECCCA2}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
"{97D1A932-3232-454A-9D4E-9DCDBEC9FC32}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{B4260D3E-9E8D-476A-A345-9DF952C8515D}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{BB66FA76-FB5D-4497-8DEC-8F807C84AC90}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{BD452660-A3D6-4255-9050-CFF43343AB1F}" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"{BDE77B38-6C99-4E8E-8F7E-DF98E2EB834E}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
"{C1188DB4-3CA9-4598-9D71-952B8EB02D87}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{C798D1D4-E3CF-43CA-A46E-20AB69D9B123}" = protocol=17 | dir=in | app=c:\users\coimbra\appdata\roaming\dropbox\bin\dropbox.exe |
"{DF9F2DBE-2DDB-42E0-A6DA-E03A7357F9BC}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{E08F5410-2CE3-4603-B224-A66950475F21}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{E32AE8C6-CC5D-48F9-BDDF-64D6448EA82F}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{E862A10F-94B2-40A3-B11C-CD59BE181AE5}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
"{EAC1638E-0222-460E-A1B2-0BBB8E2790D7}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{ED1814E6-E326-433D-888F-493EB95C5C41}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
"{EE4A744D-3855-4499-9615-3CA1D0957A24}" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3y.exe |
"{EEC53CB2-1BDC-47E8-97EC-0D7F39ACDD07}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{F05E0896-030B-4CEB-8AC2-7ABB7210F140}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"TCP Query User{14427A67-EBCD-4720-9842-CDCA114D4794}C:\program files\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files\winamp\winamp.exe |
"UDP Query User{71C6E3BA-1EE1-423C-9493-FBA920072577}C:\program files\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files\winamp\winamp.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{024558D8-272F-C7C8-4F6D-6FE689B5DC52}" = Catalyst Control Center Localization Japanese
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{074C5857-D87B-4E1B-9977-FE623E4CBE88}" = Samsung PC Studio
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Assistente de Início de Sessão do Windows Live ID
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0C973594-7DDF-4BD0-84ED-3517F7622037}" = PC Connectivity Solution
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1A5A851C-B8B4-CD8E-920B-EE21B9E4FE31}" = Catalyst Control Center Graphics Full Existing
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2D7D6A0E-A6A7-1080-980C-67FB8E20D93D}" = ccc-utility
"{2F2C3691-E3CB-6066-514D-729BB881216D}" = CCC Help Dutch
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{372B31CF-77FB-4E29-860C-A0EA2985AB7F}" = O2Micro Flash Memory Card Reader Driver (x86)
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D39E775-DDDA-4327-B747-0BDC5F191331}" = Nokia PC Suite
"{3E1E4AB9-C017-746E-92E6-B30A0429E986}" = CCC Help Korean
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{43DCF766-6838-4F9A-8C91-D92DA586DFA8}" = Microsoft Windows Journal Viewer
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{491DD193-1B57-4D1C-8B14-18B96992A89F}" = TOSHIBA Supervisor Password
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A130340-74D9-27C0-0F3D-3F9A69CF938C}" = CCC Help French
"{4A944E94-F6E9-9D38-5C5B-B1E5597EB742}" = CCC Help Spanish
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{502DBACB-D72F-276E-9B51-1CC980633BDC}" = CCC Help German
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{50831C51-70E7-CF72-3B5E-53413B1598E9}" = Catalyst Control Center Localization Dutch
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{52573F8D-F099-4CB5-9EDE-5C27ECB4A02B}" = TOSHIBA Hardware Setup
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{56A29640-7334-2E21-8169-5F23EEEE4958}" = CCC Help Chinese Standard
"{5721A8EA-A30F-4F66-9046-3F40C43AE1DC}" = Driver Detective
"{587139F5-9B76-4D5A-94C6-76E6B219BF7F}" = Windows Live Sync
"{5980B928-1C95-4B3E-957B-B02D8147FF9E}" = Desktop SMS
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{60D7B2C5-5824-753E-D091-382D312C5590}" = Catalyst Control Center Localization French
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{6275D380-371D-6D6E-32AF-97009138EBE3}" = Skins
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{650E2ABD-270A-499C-BA9F-09180DDDDA16}" = Nokia Software Updater
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67905A54-F074-6F13-3C61-DA40552079BB}" = Catalyst Control Center Graphics Light
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6E4F5172-7A60-E18C-D1F2-C8D783197A7C}" = Catalyst Control Center Localization German
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75E9A522-65D2-4200-A95F-C3EF89703263}" = Lyrics Plugin for Winamp
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{7988ba74-4a27-4685-991a-53f072f22808}" = F2200_Help
"{7B1DBCBE-DF17-3B58-844C-F572F70EF5C4}" = Microsoft .NET Framework 3.5 Language Pack SP1 - ptg
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{7BA57438-E0E4-46D1-9161-480FFB76FB62}" = Windows Live Writer
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7FADEAAE-1AAD-2635-809E-C92477AF1794}" = Catalyst Control Center Localization Italian
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{80533B67-C407-485D-8B5D-63BB8ED9D878}" = Scan
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{88771941-E487-0F1C-7242-554D82BC8740}" = CCC Help Japanese
"{89DCBAD2-592B-A42C-18D7-78601056FBD9}" = Catalyst Control Center Localization Chinese Standard
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8D90017E-FFE1-3077-9113-F4002ED7EB13}" = Catalyst Control Center Localization Swedish
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0015-0816-0000-0000000FF1CE}" = Microsoft Office Access MUI (Portuguese (Portugal)) 2007
"{90120000-0015-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0816-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Portuguese (Portugal)) 2007
"{90120000-0016-0816-0000-0000000FF1CE}_HOMESTUDENTR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0816-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2007
"{90120000-0018-0816-0000-0000000FF1CE}_HOMESTUDENTR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0816-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Portuguese (Portugal)) 2007
"{90120000-0019-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0816-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Portuguese (Portugal)) 2007
"{90120000-001A-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0816-0000-0000000FF1CE}" = Microsoft Office Word MUI (Portuguese (Portugal)) 2007
"{90120000-001B-0816-0000-0000000FF1CE}_HOMESTUDENTR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0816-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Portugal)) 2007
"{90120000-001F-0816-0000-0000000FF1CE}_HOMESTUDENTR_{C8246FCF-12F8-4212-BC89-6ED049BA2FB8}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0816-0000-0000000FF1CE}_PROR_{C8246FCF-12F8-4212-BC89-6ED049BA2FB8}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0816-0000-0000000FF1CE}" = Microsoft Office Proofing (Portuguese (Portugal)) 2007
"{90120000-006E-0816-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Portuguese (Portugal)) 2007
"{90120000-006E-0816-0000-0000000FF1CE}_HOMESTUDENTR_{5E03E01D-304F-474D-B85F-06B2C9AE0583}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0816-0000-0000000FF1CE}_PROR_{5E03E01D-304F-474D-B85F-06B2C9AE0583}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0816-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Portuguese (Portugal)) 2007
"{90120000-00A1-0816-0000-0000000FF1CE}_HOMESTUDENTR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AE196A8-A8DC-4287-BCBA-AF35C578FEA2}" = Manuais da TOSHIBA
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9DDABBD9-B4D1-F927-8970-03E7CF4605F1}" = Catalyst Control Center Localization Korean
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{9F67D8FC-2A5F-440E-855C-E26A7FE88D28}" = Windows Live Essentials
"{9FD7C77D-5657-49C1-8FB5-5C7BFCAFC6DB}" = Windows Live Call
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = Silenciador Acústico da Unidade de CD/DVD
"{A07EC392-26B6-E1AE-AFE8-A73F7BFC1C4C}" = CCC Help Chinese Traditional
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 4.3
"{A12F36B5-E11F-0128-7D8F-DEC927105BE2}" = CCC Help Swedish
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1046-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Português
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B158BAE0-C912-3697-256D-A9FCEDFAA536}" = Catalyst Control Center Localization Portuguese
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B4E343DD-BAAB-4D59-AD9C-DEA0AFE09DF1}" = Mumble 1.2.3
"{B5897EDD-E78B-067B-DB8F-D85E60B71967}" = Catalyst Control Center Localization Spanish
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{B785106B-C3EC-4999-8A89-A3B335559E82}_is1" = uv-RO 2011-06-03
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Os Sims™ 3
"{C13A8E73-7E98-4295-BA94-6931701CD1F9}" = Topaz Vivacity
"{C42601B6-CBA8-7879-D310-7B2E97215D82}" = CCC Help Italian
"{C43C1415-3DFC-4089-9A32-0BECF28A6046}" = Age of Empires III - The Asian Dynasties
"{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}" = Vodafone Mobile Connect Lite
"{c6922d7f-c698-4d9e-9671-8b3de04d1511}" = DJ_AIO_03_F2200_Software_Min
"{C6DCC59B-48D8-5092-2F69-8C423BFAB27F}" = Catalyst Control Center Graphics Previews Vista
"{C7128EEC-088D-051A-E8F9-DD4E6F2C3F3E}" = CCC Help Portuguese
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{C970757C-FD82-ED94-66C4-AF7C0266699E}" = ATI Catalyst Install Manager
"{CB22A47C-EFEA-2400-DB68-8F9B1D24BF43}" = Catalyst Control Center Graphics Full New
"{CC1D4F42-5F8B-4487-A35D-C994429EA8F1}" = Segurança Familiar do Windows Live
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE8B9F6B-7D9E-3C56-7B27-1E484CD41D78}" = ccc-core-static
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D00EAB9D-C698-D4F6-214F-6FFC496B7F71}" = Catalyst Control Center Core Implementation
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D16161BC-2A98-412C-902C-B063F6B9C566}_is1" = DarkSideRO version 1.2
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D305D4F8-0820-5DFA-F175-E7D06ED60364}" = CCC Help English
"{D58A1E94-9EEA-4C6E-B9FB-D7C63DC6C941}" = Catalyst Control Center - Branding
"{D77D43B5-ED55-426b-B67B-E21F804F6102}" = HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{db18dc72-cd20-4801-be82-f5d2caeec4d7}" = DJ_AIO_03_F2200_Software
"{DC785DB7-D389-48C3-B146-96FE99BF4E2B}" = Vegas Pro 9.0
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5B86403-C054-400B-86F5-7F1D66FBDDC6}" = Windows Live Mail
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{e97a9fd7-2fa1-4474-820d-3f8893a5b78a}" = F2200
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{eca3039b-e429-420f-bd5e-7dec0683fc32}" = DJ_AIO_03_F2200_ProductContext
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F0AF91F4-D1ED-490E-8751-997AF2A3FF0D}_is1" = Leawo FLV Converter version 4.1.0.1
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1FDAA01-988C-423F-AC12-0D8F333943FD}" = Nokia Connectivity Cable Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy
"{F855451C-21E2-3034-B042-E1E66923548A}" = Microsoft .NET Framework 4 Client Profile PTG Language Pack
"{FD702B54-2FD4-459B-97F3-977BDF2C3C5C}" = Windows Live Messenger
"{FEBF75B0-9D67-6178-8737-92A81B3FEA47}" = Catalyst Control Center Localization Chinese Traditional
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"0C5EDC3653FED5B121F464339EAC12534D253B25" = Pacote de controladores do Windows - Nokia Modem (02/15/2007 3.1)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"B726756F5B5A5AA9D798B399386FC6205A45F19E" = Pacote de controladores do Windows - Nokia Modem (02/15/2007 3.1)
"Browser Defender_is1" = Browser Defender 4.0
"Canon RAW Codec" = Canon RAW Codec
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_5051&SUBSYS;_1179" = HDAUDIO Soft Data Fax Modem with SmartCP
"DAZ Content Management Service [removed]" = DAZ Content Management Service
"DAZ Studio 4 [removed]" = DAZ Studio 4
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = Instalação do DivX
"DS4 Default Content [removed]" = DS4 Default Content
"EvilLyrics" = EvilLyrics
"Foxit PDF Creator" = Foxit PDF Creator
"Foxit PDF Editor" = Foxit PDF Editor
"Foxit Reader" = Foxit Reader
"Free Download Manager_is1" = Free Download Manager 3.0
"Hexagon 2 2.5.1.79" = Hexagon 2
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"InstallShield_{491DD193-1B57-4D1C-8B14-18B96992A89F}" = TOSHIBA Supervisor Password
"InstallShield_{52573F8D-F099-4CB5-9EDE-5C27ECB4A02B}" = TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder
"InstallShield_{C43C1415-3DFC-4089-9A32-0BECF28A6046}" = Age of Empires III - The Asian Dynasties
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"KLiteCodecPack_is1" = K-Lite Codec Pack 8.4.0 (Full)
"LastFM_is1" = Last.fm 1.5.4.27091
"Lexmark 8300 Series" = Lexmark 8300 Series
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 3.5 Language Pack SP1 - ptg" = Microsoft .NET Framework 3.5 Language Pack SP1 - PTG
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile PTG Language Pack" = Microsoft .NET Framework 4 Client Profile PTG Language Pack
"mIRC" = mIRC
"Mozilla Firefox 11.0 (x86 pt-PT)" = Mozilla Firefox 11.0 (x86 pt-PT)
"Nokia PC Suite" = Nokia PC Suite
"PaintToolSAI" = PaintTool SAI Ver.1
"pcsx2-r3878" = PCSX2 - Playstation 2 Emulator
"PROR" = Versão de Avaliação do Microsoft Office Professional 2007
"Rise of Dragonian Era" = Rise of Dragonian Era
"Shop for HP Supplies" = Shop for HP Supplies
"SopCast" = SopCast 3.3.2
"Spyware Doctor" = PC Tools Internet Security
"StepMania" = StepMania (remove only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"UT2004-Demo" = Unreal Tournament 2004 Demo
"uTorrent" = µTorrent
"Veetle TV" = Veetle TV 0.9.18
"Veoh Web Player Beta" = Veoh Web Player
"vShare.tv plugin" = vShare.tv plugin 1.3
"Vuze" = Vuze
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Compressor WinRAR
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"CrystalRO" = CrystalRO
"Dropbox" = Dropbox
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"NCsoft-Lineage2" = Lineage II
"Winamp Detect" = Winamp Detectar Aplicação
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 22-04-2012 09:53:30 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 22-04-2012 16:14:30 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 22-04-2012 16:20:54 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 22-04-2012 20:32:04 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 22-04-2012 20:37:49 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 23-04-2012 04:30:35 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 23-04-2012 14:38:21 | Computer Name = Computador | Source = EventSystem | ID = 4609
Description =
Error - 23-04-2012 14:43:57 | Computer Name = Computador | Source = EventSystem | ID = 4609
Description =
Error - 23-04-2012 14:48:52 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
Error - 23-04-2012 14:58:03 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue
[ OSession Events ]
Error - 11-07-2011 10:47:46 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11-07-2011 10:47:52 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11-07-2011 10:47:56 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11-07-2011 10:48:11 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.
Error - 26-07-2011 10:54:57 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.
Error - 26-07-2011 12:59:11 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1
seconds with 0 seconds of active time. This session ended with a crash.
Error - 29-07-2011 11:57:49 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8
seconds with 0 seconds of active time. This session ended with a crash.
Error - 19-10-2011 10:25:48 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6565.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.
Error - 23-11-2011 21:30:58 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 22
seconds with 0 seconds of active time. This session ended with a crash.
Error - 06-12-2011 23:24:43 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 23-04-2012 14:44:39 | Computer Name = Computador | Source = Service Control Manager | ID = 7001
Description =
Error - 23-04-2012 14:49:02 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =
Error - 23-04-2012 14:49:02 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =
Error - 23-04-2012 14:49:02 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =
Error - 23-04-2012 14:50:20 | Computer Name = Computador | Source = Service Control Manager | ID = 7022
Description =
Error - 23-04-2012 14:56:52 | Computer Name = Computador | Source = EventLog | ID = 6008
Description = O anterior encerramento do sistema, 23-04-2012 às 19:51:33, foi inesperado.
Error - 23-04-2012 14:58:10 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =
Error - 23-04-2012 14:58:10 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =
Error - 23-04-2012 14:58:10 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =
Error - 23-04-2012 15:00:15 | Computer Name = Computador | Source = Service Control Manager | ID = 7022
Description =
< End of report >