This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help removing Rootkit.tdss.v3 [Solved]

111 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi! Before explaining what happened, I just want to say that english is not my main language, so sorry if I'm not clear enough. But I'll give my best. I had AVG Internet Security 2012 as my anti-virus and it always said that everything was fine with my computer. I'm quite obsessive with keeping my computer clean and free of viruses (I usually do weekly cleanups and scans). But then the computer started freezing a lot (sometimes, I even had blue screens whenever I logged on the computer). I erased much of what I had since I thought it could be lack of free space and it still didn't help. That's when I started getting suspicious about a possible virus. My e-mail was weird as well (I was receiving spam from myself). The only reason for it was a virus or someone that was hacking my account. I do know about recognizing if it's one or another, so I checked my sent e-mail box and there was nothing there besides the ones I sent. It was a virus for sure. I downloaded PC Tools Internet Security (which has been said as the best for now, although I don't know if I can believe it) and it detected Rootkit.tdss.v3. I didn't know what that was, so I looked for some info around the internet and I realized it was quite a tricky and dangerous one. And it seems I have it for quite a few days now. I'm really mad with AVG for not detecting it (I don't even know how I got it with all my cautiousness with downloads and links). I tried everything to remove it (not even PC Tools worked). So you're really my last resource. I don't want to format my computer and lose everything I have. I hope you can help me!
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-


Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
Hi Jeff! Thanks for your reply! I forgot adding my Hijackthis log to my post and I was looking for an edit button, but since there wasn't one, I thought it would be better to wait for an answer. ^^ Here are the logs that you requested: DDS.txt . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31 Run by [removed] at 15:05:20 on 2012-04-22 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.351.2070.18.3069.1498 [GMT 1:00] . AV: PC Tools Internet Security Anti-Virus *Enabled/Updated* {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: PC Tools Internet Security Anti-Spyware *Enabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F} FW: PC Tools Internet Security Firewall *Disabled* {175D0B73-9F8F-2CA9-8BF1-62277A276DC9} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\DAZ 3D\Content Management Service\ContentManagementServer.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\rpcnetp.exe C:\Program Files\PC Tools Security\pctsAuxs.exe C:\Program Files\PC Tools Security\pctsSvc.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Toshiba\Power Saver\TPwrMain.exe C:\Program Files\Toshiba\SmoothView\SmoothView.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Toshiba\FlashCards\TCrdMain.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\System32\mobsync.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe C:\Program Files\PC Tools Security\pctsGui.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\PC Tools Security\TFEngine\TFService.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Users\coimbra\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\coimbra\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\coimbra\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\coimbra\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\coimbra\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\coimbra\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\PC Tools Security\Update.exe C:\Program Files\PC Tools Security\TFEngine\TFUN.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\conime.exe . ============== Pseudo HJT Report =============== . uSearch Bar = Preserve uStart Page = hxxp://startsear.ch/?aff=1 uDefault_Page_URL = hxxp://www.google.pt mStart Page = hxxp://startsear.ch/?aff=1 uInternet Settings,ProxyOverride = uURLSearchHooks: PC Tools Browser Defender: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: PC Tools Browser Defender BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll BHO: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - c:\program files\windows live\family safety\fssbho.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: IE5BarLauncherBHO Class: {78f3a323-798e-4aea-9a57-88f4b05fd5dd} - c:\program files\vshare.tv plugin\BarLcher.dll BHO: Programa Auxiliar de Início de Sessão do Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll TB: VShareToolBar: {7ac3e13b-3bca-4158-b330-f66dbb03c1b5} - c:\program files\vshare.tv plugin\BarLcher.dll TB: PC Tools Browser Defender: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [Google Update] "c:\users\coimbra\appdata\local\google\update\GoogleUpdate.exe" /c mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe mRun: [fssui] "c:\program files\windows live\family safety\fsui.exe" -autorun mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [LXCJCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXCJtime.dll,_RunDLLEntry@16 mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [ISTray] "c:\program files\pc tools security\pctsGui.exe" /hideGUI mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Transferir com FDM - file://c:\program files\free download manager\dllink.htm IE: Transferir todos com FDM - file://c:\program files\free download manager\dlall.htm IE: Transferir vídeo com FDM - file://c:\program files\free download manager\dlfvideo.htm IE: Transferência seleccionada pelo FDM - file://c:\program files\free download manager\dlselected.htm IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/mjss/MJSS.cab109791.cab DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{A4C3FC56-EE04-4EE7-82B7-3BF50C28986C} : DhcpNameServer = 192.168.1.1 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\coimbra\appdata\roaming\mozilla\firefox\profiles\85zy9bwz.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google.pt FF - prefs.js: browser.startup.homepage - hxxp://www.google.pt/ FF - prefs.js: keyword.URL - hxxp://startsear.ch/?aff=1&src=sp&cf=a6c18f78-08af-11e1-8b63-8ad0386e9ad0&q= FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff4.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff5.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff6.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff7.dll FF - component: c:\program files\free download manager\firefox\extension\components\vmsfdmff.dll FF - component: c:\users\coimbra\appdata\roaming\mozilla\firefox\profiles\85zy9bwz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\mozilla firefox\plugins\npvsharetvplg.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\users\coimbra\appdata\local\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\users\coimbra\appdata\roaming\facebook\npfbplugin_1_0_3.dll . ============= SERVICES / DRIVERS =============== . R0 pctBTFix;PC Tools Boot Fix Driver;c:\windows\system32\drivers\pctBTFix.sys [2012-4-18 17848] R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2012-4-18 331880] R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2012-4-18 342168] R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2012-4-18 909728] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2012-4-18 54328] R0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2012-4-18 574424] R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2012-4-18 253352] R1 pctNdisLW;pctNdisLW;c:\windows\system32\drivers\pctNdisLW.sys [2012-4-18 58400] R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2012-4-18 185560] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928] R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\pc tools security\bdt\BDTUpdateService.exe [2012-4-18 550864] R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2007-12-25 40960] R2 DAZContentManagementService;DAZ Content Management Service;c:\program files\daz 3d\content management service\ContentManagementServer.exe [2012-3-25 18432] R2 FontCache;Serviço de Cache de Tipos de Letra do Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-11-2 21504] R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2012-4-18 162584] R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2012-4-18 402336] R2 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2012-4-18 1117624] R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\toshiba\smartlogservice\TosIPCSrv.exe [2007-12-3 126976] R2 VMCService;Vodafone Mobile Connect Service;c:\program files\vodafone\vodafone mobile connect\bin\VMCService.exe [2008-7-4 14336] R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDART.sys [2008-3-5 187904] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-11-17 3668480] R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2008-1-15 48472] R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\drivers\PCTBD.sys [2012-4-18 56840] R3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2012-4-18 70536] R3 QIOMem;Generic IO & Memory Access;c:\windows\system32\drivers\QIOMem.sys [2007-4-9 8192] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2012-4-18 35264] R3 ThreatFire;ThreatFire;c:\program files\pc tools security\tfengine\tfservice.exe service –> c:\program files\pc tools security\tfengine\TFService.exe service [?] RUnknown rpcnetp;rpcnetp; [x] S2 Automatic CDROM Monitor;Automatic CDROM Monitor; [x] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Serviço Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-25 135664] S2 StarWindServiceAE;StarWind AE Service; [x] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-17 253088] S3 apf001;apf001;c:\windows\system32\apf001.sys [2012-3-12 10872] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-10-4 54632] S3 fsssvc;Serviço Segurança Familiar do Windows Live;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872] S3 gupdatem;Serviço Google Update (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-12-25 135664] S3 libusb0;libusb-win32 - Kernel Driver 10/02/2010 1.2.2.0;c:\windows\system32\drivers\libusb0.sys [2011-1-26 35392] S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [2011-9-5 133632] S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2011-9-5 79360] S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\drivers\MijXfilt.sys [2011-1-26 81168] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-2-26 137344] S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-2-26 8320] S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2012-4-18 125888] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2012-04-21 20:10:17 17408 —-a-w- c:\windows\system32\rpcnetp.exe 2012-04-21 19:45:55 ——– d—–w- C:\sh4ldr 2012-04-21 19:45:55 ——– d—–w- c:\program files\Enigma Software Group 2012-04-21 19:27:30 ——– d—–w- c:\program files\ExpressFiles 2012-04-21 19:07:55 ——– d—–w- c:\users\coimbra\appdata\roaming\SpeedyPC Software 2012-04-21 19:07:55 ——– d—–w- c:\users\coimbra\appdata\roaming\DriverCure 2012-04-21 19:07:49 ——– d—–w- c:\programdata\SpeedyPC Software 2012-04-21 01:10:26 6734704 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{69be57cc-97d0-44d6-b87c-23b9fee0dc8c}\mpengine.dll 2012-04-20 22:40:27 17408 —-a-w- c:\windows\system32\rpcnetp.dll 2012-04-20 03:21:19 ——– d-sh–w- C:\found.002 2012-04-19 22:17:25 ——– d—–w- c:\program files\Microsoft Security Client 2012-04-18 23:17:29 ——– d—–w- c:\users\coimbra\appdata\roaming\PCTools 2012-04-18 14:44:02 ——– d—–w- c:\users\coimbra\appdata\roaming\PC Tools 2012-04-18 14:44:01 ——– d—–w- c:\users\coimbra\appdata\roaming\Spam Monitor 2012-04-18 14:38:11 574424 –s—w- c:\windows\system32\drivers\TfSysMon.sys 2012-04-18 14:38:11 54328 –s—w- c:\windows\system32\drivers\TfFsMon.sys 2012-04-18 14:38:11 35264 –s—w- c:\windows\system32\drivers\TfNetMon.sys 2012-04-18 14:33:33 125888 —-a-w- c:\windows\system32\drivers\pctplfw.sys 2012-04-18 14:33:30 91136 —-a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys 2012-04-18 14:33:30 58400 —-a-w- c:\windows\system32\drivers\pctNdisLW.sys 2012-04-18 14:33:30 32936 —-a-w- c:\windows\system32\drivers\pctNdis-DNS.sys 2012-04-18 14:26:32 767952 —-a-w- c:\windows\BDTSupport.dll 2012-04-18 14:26:32 56840 —-a-w- c:\windows\system32\drivers\PCTBD.sys 2012-04-18 14:26:31 2250704 —-a-w- c:\windows\PCTBDCore.dll 2012-04-18 14:26:31 149456 —-a-w- c:\windows\SGDetectionTool.dll 2012-04-18 14:26:30 1681360 —-a-w- c:\windows\PCTBDRes.dll 2012-04-18 14:24:12 909728 —-a-w- c:\windows\system32\drivers\pctEFA.sys 2012-04-18 14:24:12 342168 —-a-w- c:\windows\system32\drivers\pctDS.sys 2012-04-18 14:24:10 253352 —-a-w- c:\windows\system32\drivers\pctgntdi.sys 2012-04-18 14:24:10 107864 —-a-w- c:\windows\system32\drivers\pctwfpfilter.sys 2012-04-18 14:24:04 331880 —-a-w- c:\windows\system32\drivers\PCTCore.sys 2012-04-18 14:24:04 162584 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2012-04-18 14:24:01 185560 —-a-w- c:\windows\system32\drivers\PCTSD.sys 2012-04-18 14:24:01 17848 —-a-w- c:\windows\system32\drivers\pctBTFix.sys 2012-04-18 14:23:56 70536 —-a-w- c:\windows\system32\drivers\pctplsg.sys 2012-04-18 14:23:45 ——– d—–w- c:\programdata\PC Tools 2012-04-18 14:23:45 ——– d—–w- c:\program files\PC Tools Security 2012-04-18 14:23:45 ——– d—–w- c:\program files\common files\PC Tools 2012-04-17 17:42:50 418464 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-04-17 13:39:38 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2012-04-17 13:39:37 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll 2012-04-17 13:39:37 592824 —-a-w- c:\program files\mozilla firefox\gkmedias.dll 2012-04-17 13:39:37 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll 2012-04-17 13:39:37 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll 2012-04-17 13:39:37 44472 —-a-w- c:\program files\mozilla firefox\mozglue.dll 2012-04-12 17:05:57 ——– d—–w- c:\program files\Ragray 2012-04-12 16:54:06 ——– d—–w- c:\program files\1RO 2012-04-11 09:55:25 5120 —-a-w- c:\windows\system32\wmi.dll 2012-04-11 09:55:24 172032 —-a-w- c:\windows\system32\wintrust.dll 2012-04-11 09:55:24 157696 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-11 09:55:24 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-11 09:53:47 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-11 09:53:47 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-11 09:40:21 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2012-04-07 23:11:38 388096 —-a-r- c:\users\coimbra\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2012-04-04 05:53:56 182160 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2012-04-04 05:53:56 182160 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2012-04-02 18:39:33 ——– d—–w- c:\users\coimbra\appdata\roaming\LolClient 2012-04-02 17:20:01 467984 —-a-w- c:\windows\system32\d3dx10_39.dll 2012-04-02 17:20:01 1493528 —-a-w- c:\windows\system32\D3DCompiler_39.dll 2012-04-02 17:19:58 3851784 —-a-w- c:\windows\system32\D3DX9_39.dll 2012-04-02 15:38:32 ——– d—–w- c:\program files\Pando Networks 2012-03-29 23:58:58 90112 —-a-w- c:\windows\unvise32.exe 2012-03-27 13:26:53 ——– d—–w- c:\programdata\Vodafone 2012-03-27 13:26:42 ——– d—–w- c:\program files\Vodafone 2012-03-27 13:25:32 ——– d—–w- c:\users\coimbra\appdata\local\{D53238E8-3427-491E-A57E-097FA966AAC1} 2012-03-26 16:40:18 ——– d—–w- c:\program files\Canon 2012-03-26 16:39:45 ——– d—–w- c:\program files\common files\Canon 2012-03-25 03:22:52 ——– d—–w- c:\program files\common files\DAZ 2012-03-25 03:18:16 ——– d—–w- c:\programdata\DAZ 3D 2012-03-25 03:16:17 ——– d—–w- c:\program files\DAZ 3D 2012-03-25 03:14:19 ——– d—–w- c:\users\coimbra\appdata\roaming\DAZ 3D . ==================== Find3M ==================== . 2012-04-20 14:18:44 44544 —-a-w- c:\windows\system32\agremove.exe 2012-04-17 18:07:30 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-03-12 02:09:33 12920 —-a-w- c:\windows\system32\apl001.sys 2012-03-12 02:09:33 10872 —-a-w- c:\windows\system32\apf001.sys 2012-02-28 01:18:55 1799168 —-a-w- c:\windows\system32\jscript9.dll 2012-02-28 01:11:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl 2012-02-28 01:11:07 1127424 —-a-w- c:\windows\system32\wininet.dll 2012-02-28 01:03:16 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-02-23 09:18:36 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-02-16 03:26:37 472808 —-a-w- c:\windows\system32\deployJava1.dll 2012-02-14 15:45:30 219648 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-02-14 15:45:30 160768 —-a-w- c:\windows\system32\d3d10_1.dll 2012-02-13 14:12:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll 2012-02-13 13:47:57 683008 —-a-w- c:\windows\system32\d2d1.dll 2012-02-13 13:44:40 1068544 —-a-w- c:\windows\system32\DWrite.dll 2012-02-07 10:02:40 1070352 —-a-w- c:\windows\system32\MSCOMCTL.OCX 2012-02-02 15:16:25 2044416 —-a-w- c:\windows\system32\win32k.sys . ============= FINISH: 15:08:16,91 =============== Attach.txt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 04-09-2008 22:20:05 System Uptime: 22-04-2012 14:50:20 (1 hours ago) . Motherboard: TOSHIBA | | Satellite A300 Processor: Intel® Core™2 Duo CPU T9300 @ 2.50GHz | U2E1 | 800/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 152 GiB total, 22,921 GiB free. D: is CDROM () E: is FIXED (NTFS) - 145 GiB total, 47,758 GiB free. F: is CDROM () H: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Placa Microsoft ISATAP Device ID: ROOT\*ISATAP\0010 Manufacturer: Microsoft Name: Placa Microsoft ISATAP #9 PNP Device ID: ROOT\*ISATAP\0010 Service: tunnel . ==== System Restore Points =================== . . ==== Installed Programs ====================== . . Leawo FLV Converter version 4.1.0.1 Update for Microsoft Office 2007 (KB2508958) 32 Bit HP CIO Components Installer Actualização do Microsoft Office Excel 2007 Help (KB963678) Actualização do Microsoft Office Powerpoint 2007 Help (KB963669) Actualização do Microsoft Office Word 2007 Help (KB963665) Adobe Anchor Service CS3 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge Start Meeting Adobe Camera Raw 4.0 Adobe CMaps Adobe Color - Photoshop Specific Adobe Color Common Settings Adobe Color EU Extra Settings Adobe Color JA Extra Settings Adobe Color NA Recommended Settings Adobe Default Language CS3 Adobe Device Central CS3 Adobe ExtendScript Toolkit 2 Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Fonts All Adobe Help Viewer CS3 Adobe Linguistics CS3 Adobe PDF Library Files Adobe Photoshop CS3 Adobe Reader X (10.1.3) - Português Adobe Setup Adobe Shockwave Player 11.5 Adobe Stock Photos CS3 Adobe Type Support Adobe Update Manager CS3 Adobe Version Cue CS3 Client Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS3 Age of Empires III Age of Empires III - The Asian Dynasties Akamai NetSession Interface Apple Application Support Apple Software Update Assistente de Início de Sessão do Windows Live ID ATI Catalyst Install Manager µTorrent AVG PC Tuneup 2011 Bluetooth Stack for Windows by Toshiba Browser Defender 4.0 BufferChm Camera Assistant Software for Toshiba Canon RAW Codec Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Vista Catalyst Control Center Localization Chinese Standard Catalyst Control Center Localization Chinese Traditional Catalyst Control Center Localization Dutch Catalyst Control Center Localization French Catalyst Control Center Localization German Catalyst Control Center Localization Italian Catalyst Control Center Localization Japanese Catalyst Control Center Localization Korean Catalyst Control Center Localization Portuguese Catalyst Control Center Localization Spanish Catalyst Control Center Localization Swedish ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Dutch CCC Help English CCC Help French CCC Help German CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Portuguese CCC Help Spanish CCC Help Swedish CCleaner CDBurnerXP Compressor WinRAR Conexant HD Audio Copy CrystalRO CustomerResearchQFolder DarkSideRO version 1.2 DAZ Content Management Service DAZ Studio 4 Desktop SMS Destination Component DeviceDiscovery DeviceManagementQFolder DivX Converter DivX Plus DirectShow Filters DivX Version Checker DJ_AIO_03_F2200_ProductContext DJ_AIO_03_F2200_Software DJ_AIO_03_F2200_Software_Min Driver Detective DS4 Default Content DVD MovieFactory for TOSHIBA eSupportQFolder EvilLyrics F2200 F2200_Help Facebook Plug-In Ferramenta de Carregamento do Windows Live Foxit PDF Creator Foxit PDF Editor Foxit Reader Free Download Manager 3.0 Google Chrome Google Earth Plug-in Google Update Helper GPBaseService HDAUDIO Soft Data Fax Modem with SmartCP Hexagon 2 HiJackThis HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Customer Participation Program 10.0 HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3 HP Imaging Device Functions 10.0 HP Photosmart Essential 2.5 HP Smart Web Printing HP Solution Center 10.0 HP Update HPProductAssistant HPSSupply Instalação do DivX Intel® Matrix Storage Manager Java Auto Updater Java™ 6 Update 31 Junk Mail filter update K-Lite Codec Pack 8.4.0 (Full) Last.fm 1.5.4.27091 League of Legends Lexmark 8300 Series Lineage II Lyrics Plugin for Winamp Manuais da TOSHIBA MarketResearch Marvell Miniport Driver Messenger Plus! Live Microsoft .NET Framework 3.5 Language Pack SP1 - PTG Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile PTG Language Pack Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (Portuguese (Portugal)) 2007 Microsoft Office Excel MUI (Portuguese (Portugal)) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office Live Add-in 1.5 Microsoft Office OneNote MUI (Portuguese (Portugal)) 2007 Microsoft Office Outlook MUI (Portuguese (Portugal)) 2007 Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2007 Microsoft Office Professional 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Portuguese (Portugal)) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (Portuguese (Portugal)) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (Portuguese (Portugal)) 2007 Microsoft Office Shared MUI (Portuguese (Portugal)) 2007 Microsoft Office Word MUI (Portuguese (Portugal)) 2007 Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Microsoft Windows Journal Viewer Microsoft WSE 3.0 Runtime Microsoft XML Parser mIRC Mozilla Firefox 11.0 (x86 pt-PT) MSVC80_x86 MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Mumble 1.2.3 NetWaiting Nokia Connectivity Cable Driver Nokia PC Suite Nokia Software Updater NVIDIA PhysX O2Micro Flash Memory Card Reader Driver (x86) OpenMG Secure Module 4.7.00 Os Sims™ 3 Pacote de controladores do Windows - Nokia Modem (02/15/2007 3.1) PaintTool SAI Ver.1 Pando Media Booster PC Connectivity Solution PC Tools Internet Security PCSX2 - Playstation 2 Emulator PDF Settings PSSWCORE QuickTime Rise of Dragonian Era Samsung PC Studio Scan Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile PTG Language Pack (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile PTG Language Pack (KB2518870) Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Encoder (KB954156) Security Update for Windows Media Encoder (KB979332) Segurança Familiar do Windows Live Shop for HP Supplies Silenciador Acústico da Unidade de CD/DVD Skins Skype™ 5.1 SmartWebPrintingOC SolutionCenter SonicStage 4.3 SopCast 3.3.2 Status StepMania (remove only) Synaptics Pointing Device Driver System Requirements Lab System Requirements Lab CYRI Toolbox Topaz Vivacity TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA Disc Creator TOSHIBA DVD PLAYER TOSHIBA Extended Tiles for Windows Mobility Center TOSHIBA Face Recognition TOSHIBA Hardware Setup Toshiba Online Product Information TOSHIBA Recovery Disc Creator TOSHIBA SD Memory Utilities TOSHIBA Supervisor Password TOSHIBA Value Added Package TrayApp TRDCReminder TRORDCLauncher UnloadSupport Unreal Tournament 2004 Demo Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2598306) 32-Bit Edition Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition uv-RO 2011-06-03 Veetle TV 0.9.18 Vegas Pro 9.0 Veoh Web Player Versão de Avaliação do Microsoft Office Professional 2007 VideoToolkit01 Vodafone Mobile Connect Lite vShare.tv plugin 1.3 Vuze WebReg Winamp Winamp Detectar Aplicação Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Sync Windows Live Writer Windows Media Encoder 9 Series Windows Media Player Firefox Plugin . ==== End Of File =========================== aswMBR.txt aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-04-22 15:13:10 —————————– 15:13:10.470 OS Version: Windows 6.0.6002 Service Pack 2 15:13:10.471 Number of processors: 2 586 0x1706 15:13:10.472 ComputerName: COMPUTADOR UserName: coimbra 15:13:22.246 Initialize success 15:16:04.221 AVAST engine defs: 12042200 15:16:13.889 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 15:16:13.896 Disk 0 Vendor: TOSHIBA_ LV01 Size: 305245MB BusType: 3 15:16:13.927 Disk 0 MBR read successfully 15:16:13.935 Disk 0 MBR scan 15:16:14.107 Disk 0 Windows VISTA default MBR code 15:16:14.129 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048 15:16:14.253 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 155278 MB offset 3074048 15:16:14.383 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 148466 MB offset 321083392 15:16:14.527 Disk 0 scanning sectors +625141760 15:16:14.761 Disk 0 scanning C:\Windows\system32\drivers 15:16:51.975 Service scanning 15:17:41.759 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 15:18:04.521 Modules scanning 15:18:17.241 Disk 0 trace - called modules: 15:18:17.280 ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys acpi.sys hal.dll iaStor.sys spvk.sys >>UNKNOWN [0x866ea938]<< 15:18:17.290 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87259ac8] 15:18:17.303 3 CLASSPNP.SYS[8bd0c8b3] -> nt!IofCallDriver -> [0x8723d430] 15:18:17.314 5 PCTCore.sys[8b677407] -> nt!IofCallDriver -> [0x867c2900] 15:18:17.326 7 acpi.sys[8b4176bc] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x867c6028] 15:18:19.368 AVAST engine scan C:\Windows 15:18:25.192 AVAST engine scan C:\Windows\system32 15:26:58.938 AVAST engine scan C:\Windows\system32\drivers 15:27:37.551 AVAST engine scan C:\Users\coimbra 15:51:58.247 AVAST engine scan C:\ProgramData 15:56:25.183 Scan finished successfully 16:06:00.595 Disk 0 MBR has been saved successfully to "C:\Users\coimbra\Documents\MBR.dat" 16:06:00.608 The log file has been saved successfully to "C:\Users\coimbra\Documents\aswMBR.txt"
Hi,

Please download TDSSKiller
  • Right-click and Run as Administrator TDSSKiller.exe
  • Press Change Parameters
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
  • Click on the Start Scan button
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
    • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • Copy and paste the log in your next reply
    • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
———-
It didn't find anything malicious. Here's the log: 16:42:30.0563 5136 TDSS rootkit removing tool 2.7.31.0 Apr 20 2012 19:49:47 16:42:30.0735 5136 ============================================================ 16:42:30.0736 5136 Current date / time: 2012/04/22 16:42:30.0735 16:42:30.0736 5136 SystemInfo: 16:42:30.0736 5136 16:42:30.0736 5136 OS Version: 6.0.6002 ServicePack: 2.0 16:42:30.0736 5136 Product type: Workstation 16:42:30.0736 5136 ComputerName: COMPUTADOR 16:42:30.0736 5136 UserName: coimbra 16:42:30.0736 5136 Windows directory: C:\Windows 16:42:30.0737 5136 System windows directory: C:\Windows 16:42:30.0737 5136 Processor architecture: Intel x86 16:42:30.0737 5136 Number of processors: 2 16:42:30.0737 5136 Page size: 0x1000 16:42:30.0737 5136 Boot type: Normal boot 16:42:30.0737 5136 ============================================================ 16:42:32.0597 5136 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 16:42:32.0604 5136 \Device\Harddisk0\DR0: 16:42:32.0616 5136 MBR partitions: 16:42:32.0616 5136 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x12F47000 16:42:32.0616 5136 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x13235800, BlocksNum 0x121F9000 16:42:32.0690 5136 C: <-> \Device\Harddisk0\DR0\Partition0 16:42:32.0778 5136 E: <-> \Device\Harddisk0\DR0\Partition1 16:42:32.0780 5136 Initialize success 16:42:32.0780 5136 ============================================================ 16:42:46.0500 0672 ============================================================ 16:42:46.0500 0672 Scan started 16:42:46.0500 0672 Mode: Manual; SigCheck; TDLFS; 16:42:46.0500 0672 ============================================================ 16:42:48.0797 0672 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 16:42:49.0092 0672 ACPI - ok 16:42:49.0248 0672 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 16:42:49.0281 0672 AdobeARMservice - ok 16:42:49.0568 0672 AdobeFlashPlayerUpdateSvc (459ac130c6ab892b1cd5d7544626efc5) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 16:42:49.0612 0672 AdobeFlashPlayerUpdateSvc - ok 16:42:49.0861 0672 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys 16:42:49.0926 0672 adp94xx - ok 16:42:50.0159 0672 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys 16:42:50.0214 0672 adpahci - ok 16:42:50.0437 0672 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys 16:42:50.0481 0672 adpu160m - ok 16:42:50.0699 0672 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys 16:42:50.0744 0672 adpu320 - ok 16:42:50.0929 0672 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll 16:42:51.0105 0672 AeLookupSvc - ok 16:42:51.0324 0672 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 16:42:51.0425 0672 AFD - ok 16:42:51.0640 0672 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys 16:42:51.0681 0672 agp440 - ok 16:42:51.0892 0672 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 16:42:51.0952 0672 aic78xx - ok 16:42:52.0126 0672 ALG (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe 16:42:52.0310 0672 ALG - ok 16:42:52.0524 0672 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys 16:42:52.0567 0672 aliide - ok 16:42:52.0782 0672 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys 16:42:52.0826 0672 amdagp - ok 16:42:53.0047 0672 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys 16:42:53.0086 0672 amdide - ok 16:42:53.0315 0672 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys 16:42:53.0570 0672 AmdK7 - ok 16:42:53.0778 0672 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys 16:42:53.0922 0672 AmdK8 - ok 16:42:54.0086 0672 apf001 (7b4beb577c5d0171f9b66f390ec29284) C:\Windows\system32\apf001.sys 16:42:54.0519 0672 apf001 - ok 16:42:54.0714 0672 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll 16:42:54.0812 0672 Appinfo - ok 16:42:55.0030 0672 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys 16:42:55.0072 0672 arc - ok 16:42:55.0278 0672 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys 16:42:55.0319 0672 arcsas - ok 16:42:55.0512 0672 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 16:42:55.0610 0672 AsyncMac - ok 16:42:55.0809 0672 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 16:42:55.0854 0672 atapi - ok 16:42:56.0096 0672 athr (6046a55f79de9c581b8d5e9c1366cc81) C:\Windows\system32\DRIVERS\athr.sys 16:42:56.0261 0672 athr - ok 16:42:56.0460 0672 Ati External Event Utility (26757a5a06c37ef44be544eb7e98d9d3) C:\Windows\system32\Ati2evxx.exe 16:42:56.0570 0672 Ati External Event Utility - ok 16:42:56.0870 0672 atikmdag (d5ab32f003780f21325f1c1df613f867) C:\Windows\system32\DRIVERS\atikmdag.sys 16:42:57.0131 0672 atikmdag - ok 16:42:57.0316 0672 AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll 16:42:57.0424 0672 AudioEndpointBuilder - ok 16:42:57.0437 0672 Audiosrv (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll 16:42:57.0503 0672 Audiosrv - ok 16:42:57.0759 0672 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 16:42:57.0858 0672 Beep - ok 16:42:58.0065 0672 BFE (c789af0f724fda5852fb9a7d3a432381) C:\Windows\System32\bfe.dll 16:42:58.0144 0672 BFE - ok 16:42:58.0336 0672 BITS (93952506c6d67330367f7e7934b6a02f) C:\Windows\System32\qmgr.dll 16:42:58.0474 0672 BITS - ok 16:42:58.0652 0672 blbdrive - ok 16:42:58.0715 0672 Bonjour Service (73686fe0b2e0469f89fd2075be724704) C:\Program Files\Bonjour\mDNSResponder.exe 16:42:58.0760 0672 Bonjour Service ( UnsignedFile.Multi.Generic ) - warning 16:42:58.0761 0672 Bonjour Service - detected UnsignedFile.Multi.Generic (1) 16:42:58.0959 0672 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 16:42:59.0054 0672 bowser - ok 16:42:59.0251 0672 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 16:42:59.0323 0672 BrFiltLo - ok 16:42:59.0528 0672 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 16:42:59.0609 0672 BrFiltUp - ok 16:42:59.0787 0672 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll 16:42:59.0879 0672 Browser - ok 16:43:00.0006 0672 Browser Defender Update Service (335219836821cb675533ab4731779754) C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe 16:43:00.0060 0672 Browser Defender Update Service - ok 16:43:00.0289 0672 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 16:43:00.0433 0672 Brserid - ok 16:43:00.0649 0672 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 16:43:00.0784 0672 BrSerWdm - ok 16:43:00.0998 0672 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 16:43:01.0137 0672 BrUsbMdm - ok 16:43:01.0342 0672 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 16:43:01.0473 0672 BrUsbSer - ok 16:43:01.0693 0672 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 16:43:01.0831 0672 BTHMODEM - ok 16:43:02.0033 0672 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 16:43:02.0127 0672 cdfs - ok 16:43:02.0308 0672 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 16:43:02.0394 0672 cdrom - ok 16:43:02.0560 0672 CertPropSvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll 16:43:02.0637 0672 CertPropSvc - ok 16:43:02.0854 0672 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys 16:43:02.0987 0672 circlass - ok 16:43:03.0172 0672 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 16:43:03.0226 0672 CLFS - ok 16:43:03.0353 0672 clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 16:43:03.0394 0672 clr_optimization_v2.0.50727_32 - ok 16:43:03.0441 0672 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 16:43:03.0494 0672 clr_optimization_v4.0.30319_32 - ok 16:43:03.0689 0672 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 16:43:03.0784 0672 CmBatt - ok 16:43:04.0000 0672 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys 16:43:04.0040 0672 cmdide - ok 16:43:04.0273 0672 CnxtHdAudAddService (76ffd950394c45196d09239edc9b006b) C:\Windows\system32\drivers\CHDART.sys 16:43:04.0332 0672 CnxtHdAudAddService - ok 16:43:04.0536 0672 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 16:43:04.0578 0672 Compbatt - ok 16:43:04.0715 0672 COMSysApp - ok 16:43:04.0820 0672 ConfigFree Service (596e452b5152ec9afe8153d296459d2b) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe 16:43:04.0859 0672 ConfigFree Service ( UnsignedFile.Multi.Generic ) - warning 16:43:04.0859 0672 ConfigFree Service - detected UnsignedFile.Multi.Generic (1) 16:43:05.0068 0672 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys 16:43:05.0108 0672 crcdisk - ok 16:43:05.0323 0672 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys 16:43:05.0443 0672 Crusoe - ok 16:43:05.0622 0672 CryptSvc (fb27772beaf8e1d28ccd825c09da939b) C:\Windows\system32\cryptsvc.dll 16:43:05.0700 0672 CryptSvc - ok 16:43:05.0821 0672 DAZContentManagementService (db66841a22e3f51030c7671f33b2d290) C:\Program Files\DAZ 3D\Content Management Service\ContentManagementServer.exe 16:43:05.0854 0672 DAZContentManagementService ( UnsignedFile.Multi.Generic ) - warning 16:43:05.0854 0672 DAZContentManagementService - detected UnsignedFile.Multi.Generic (1) 16:43:06.0067 0672 DcomLaunch (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll 16:43:06.0181 0672 DcomLaunch - ok 16:43:06.0379 0672 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 16:43:06.0458 0672 DfsC - ok 16:43:06.0689 0672 DFSR (2cc3dcfb533a1035b13dcab6160ab38b) C:\Windows\system32\DFSR.exe 16:43:06.0867 0672 DFSR - ok 16:43:07.0051 0672 Dhcp (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll 16:43:07.0135 0672 Dhcp - ok 16:43:07.0335 0672 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 16:43:07.0381 0672 disk - ok 16:43:07.0555 0672 Dnscache (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll 16:43:07.0638 0672 Dnscache - ok 16:43:07.0810 0672 dot3svc (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll 16:43:07.0894 0672 dot3svc - ok 16:43:08.0102 0672 Dot4 (4f59c172c094e1a1d46463a8dc061cbd) C:\Windows\system32\DRIVERS\Dot4.sys 16:43:08.0210 0672 Dot4 - ok 16:43:08.0420 0672 Dot4Print (80bf3ba09f6f2523c8f6b7cc6dbf7bd5) C:\Windows\system32\DRIVERS\Dot4Prt.sys 16:43:08.0516 0672 Dot4Print - ok 16:43:08.0725 0672 dot4usb (c55004ca6b419b6695970dfe849b122f) C:\Windows\system32\DRIVERS\dot4usb.sys 16:43:08.0832 0672 dot4usb - ok 16:43:09.0005 0672 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll 16:43:09.0106 0672 DPS - ok 16:43:09.0301 0672 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 16:43:09.0382 0672 drmkaud - ok 16:43:09.0598 0672 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 16:43:09.0680 0672 DXGKrnl - ok 16:43:09.0897 0672 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys 16:43:10.0030 0672 E1G60 - ok 16:43:10.0221 0672 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll 16:43:10.0309 0672 EapHost - ok 16:43:10.0515 0672 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 16:43:10.0565 0672 Ecache - ok 16:43:10.0668 0672 ehRecvr (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe 16:43:10.0725 0672 ehRecvr - ok 16:43:10.0769 0672 ehSched (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe 16:43:10.0847 0672 ehSched - ok 16:43:10.0937 0672 ehstart (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll 16:43:10.0995 0672 ehstart - ok 16:43:11.0170 0672 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys 16:43:11.0224 0672 elxstor - ok 16:43:11.0415 0672 EMDMgmt (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll 16:43:11.0549 0672 EMDMgmt - ok 16:43:11.0766 0672 EventSystem (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll 16:43:11.0836 0672 EventSystem - ok 16:43:12.0047 0672 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 16:43:12.0144 0672 exfat - ok 16:43:12.0368 0672 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 16:43:12.0449 0672 fastfat - ok 16:43:12.0656 0672 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys 16:43:12.0792 0672 fdc - ok 16:43:12.0967 0672 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll 16:43:13.0057 0672 fdPHost - ok 16:43:13.0242 0672 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll 16:43:13.0397 0672 FDResPub - ok 16:43:13.0590 0672 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 16:43:13.0634 0672 FileInfo - ok 16:43:13.0846 0672 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 16:43:13.0942 0672 Filetrace - ok 16:43:14.0054 0672 FLEXnet Licensing Service (227846995afeefa70d328bf5334a86a5) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 16:43:14.0127 0672 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning 16:43:14.0127 0672 FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1) 16:43:14.0353 0672 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys 16:43:14.0485 0672 flpydisk - ok 16:43:14.0688 0672 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 16:43:14.0740 0672 FltMgr - ok 16:43:14.0925 0672 FontCache (8ce364388c8eca59b14b539179276d44) C:\Windows\system32\FntCache.dll 16:43:15.0047 0672 FontCache - ok 16:43:15.0170 0672 FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 16:43:15.0209 0672 FontCache3.0.0.0 - ok 16:43:15.0360 0672 fssfltr (b74b0578fd1d3f897e95f2a2b69ea051) C:\Windows\system32\DRIVERS\fssfltr.sys 16:43:15.0398 0672 fssfltr - ok 16:43:15.0508 0672 fsssvc (45b52394f9624237f33a8a3d73c0b221) C:\Program Files\Windows Live\Family Safety\fsssvc.exe 16:43:15.0583 0672 fsssvc - ok 16:43:15.0781 0672 Fs_Rec (b972a66758577e0bfd1de0f91aaa27b5) C:\Windows\system32\drivers\Fs_Rec.sys 16:43:15.0840 0672 Fs_Rec - ok 16:43:16.0051 0672 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys 16:43:16.0092 0672 gagp30kx - ok 16:43:16.0298 0672 gpsvc (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll 16:43:16.0407 0672 gpsvc - ok 16:43:16.0509 0672 gupdate (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe 16:43:16.0546 0672 gupdate - ok 16:43:16.0571 0672 gupdatem (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files\Google\Update\GoogleUpdate.exe 16:43:16.0606 0672 gupdatem - ok 16:43:16.0802 0672 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys 16:43:16.0903 0672 HdAudAddService - ok 16:43:17.0127 0672 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 16:43:17.0256 0672 HDAudBus - ok 16:43:17.0485 0672 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 16:43:17.0655 0672 HidBth - ok 16:43:17.0878 0672 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 16:43:18.0004 0672 HidIr - ok 16:43:18.0178 0672 hidserv (84067081f3318162797385e11a8f0582) C:\Windows\system32\hidserv.dll 16:43:18.0254 0672 hidserv - ok 16:43:18.0458 0672 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 16:43:18.0532 0672 HidUsb - ok 16:43:18.0715 0672 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll 16:43:18.0809 0672 hkmsvc - ok 16:43:19.0009 0672 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys 16:43:19.0049 0672 HpCISSs - ok 16:43:19.0140 0672 hpqcxs08 (ed377b3c83fdea8d906109a085d219ba) C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll 16:43:19.0180 0672 hpqcxs08 ( UnsignedFile.Multi.Generic ) - warning 16:43:19.0180 0672 hpqcxs08 - detected UnsignedFile.Multi.Generic (1) 16:43:19.0235 0672 hpqddsvc (ee4c7a4cf2316701ffde90f404520265) C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll 16:43:19.0287 0672 hpqddsvc ( UnsignedFile.Multi.Generic ) - warning 16:43:19.0287 0672 hpqddsvc - detected UnsignedFile.Multi.Generic (1) 16:43:19.0519 0672 HSF_DPV (ee4b433cf5b77ca55d2b7f6111c23c8b) C:\Windows\system32\DRIVERS\HSX_DPV.sys 16:43:19.0655 0672 HSF_DPV - ok 16:43:19.0874 0672 HSXHWAZL (155c5a5e499ef780286b0731b5b72dbf) C:\Windows\system32\DRIVERS\HSXHWAZL.sys 16:43:19.0934 0672 HSXHWAZL - ok 16:43:20.0153 0672 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 16:43:20.0255 0672 HTTP - ok 16:43:20.0463 0672 hwdatacard (19e6885a061011d8dabe8f64498423fa) C:\Windows\system32\DRIVERS\ewusbmdm.sys 16:43:20.0538 0672 hwdatacard - ok 16:43:20.0758 0672 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys 16:43:20.0798 0672 i2omp - ok 16:43:21.0008 0672 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 16:43:21.0085 0672 i8042prt - ok 16:43:21.0304 0672 iaStor (e5a0034847537eaee3c00349d5c34c5f) C:\Windows\system32\DRIVERS\iaStor.sys 16:43:21.0352 0672 iaStor - ok 16:43:21.0580 0672 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys 16:43:21.0630 0672 iaStorV - ok 16:43:21.0744 0672 IDriverT (daf66902f08796f9c694901660e5a64a) C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe 16:43:21.0774 0672 IDriverT ( UnsignedFile.Multi.Generic ) - warning 16:43:21.0774 0672 IDriverT - detected UnsignedFile.Multi.Generic (1) 16:43:21.0924 0672 idsvc (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 16:43:22.0012 0672 idsvc - ok 16:43:22.0133 0672 igfx - ok 16:43:22.0241 0672 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 16:43:22.0282 0672 iirsp - ok 16:43:22.0408 0672 IKEEXT (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll 16:43:22.0504 0672 IKEEXT - ok 16:43:22.0733 0672 IntcHdmiAddService - ok 16:43:22.0949 0672 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 16:43:22.0992 0672 intelide - ok 16:43:23.0215 0672 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 16:43:23.0307 0672 intelppm - ok 16:43:23.0490 0672 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll 16:43:23.0585 0672 IPBusEnum - ok 16:43:23.0800 0672 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 16:43:23.0892 0672 IpFilterDriver - ok 16:43:24.0067 0672 iphlpsvc (1998bd97f950680bb55f55a7244679c2) C:\Windows\System32\iphlpsvc.dll 16:43:24.0158 0672 iphlpsvc - ok 16:43:24.0333 0672 IpInIp - ok 16:43:24.0562 0672 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys 16:43:24.0713 0672 IPMIDRV - ok 16:43:24.0920 0672 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 16:43:25.0031 0672 IPNAT - ok 16:43:25.0229 0672 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 16:43:25.0323 0672 IRENUM - ok 16:43:25.0535 0672 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys 16:43:25.0577 0672 isapnp - ok 16:43:25.0790 0672 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 16:43:25.0851 0672 iScsiPrt - ok 16:43:26.0057 0672 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 16:43:26.0098 0672 iteatapi - ok 16:43:26.0317 0672 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 16:43:26.0358 0672 iteraid - ok 16:43:26.0566 0672 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 16:43:26.0610 0672 kbdclass - ok 16:43:26.0809 0672 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 16:43:26.0906 0672 kbdhid - ok 16:43:27.0089 0672 KeyIso (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 16:43:27.0177 0672 KeyIso - ok 16:43:27.0408 0672 KSecDD (2b2f1638466e8cb091400c9019cc730e) C:\Windows\system32\Drivers\ksecdd.sys 16:43:27.0475 0672 KSecDD - ok 16:43:27.0657 0672 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll 16:43:27.0774 0672 KtmRm - ok 16:43:27.0951 0672 LanmanServer (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\system32\srvsvc.dll 16:43:28.0023 0672 LanmanServer - ok 16:43:28.0199 0672 LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll 16:43:28.0291 0672 LanmanWorkstation - ok 16:43:28.0519 0672 libusb0 (05c10e70b437841f31e1bfa8812895ba) C:\Windows\system32\DRIVERS\libusb0.sys 16:43:28.0562 0672 libusb0 - ok 16:43:28.0771 0672 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 16:43:28.0846 0672 lltdio - ok 16:43:29.0023 0672 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll 16:43:29.0126 0672 lltdsvc - ok 16:43:29.0304 0672 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll 16:43:29.0448 0672 lmhosts - ok 16:43:29.0671 0672 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys 16:43:29.0712 0672 LSI_FC - ok 16:43:29.0935 0672 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys 16:43:29.0977 0672 LSI_SAS - ok 16:43:30.0183 0672 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys 16:43:30.0225 0672 LSI_SCSI - ok 16:43:30.0426 0672 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 16:43:30.0516 0672 luafv - ok 16:43:30.0662 0672 lxcj_device - ok 16:43:30.0713 0672 Mcx2Svc (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll 16:43:30.0760 0672 Mcx2Svc - ok 16:43:30.0962 0672 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys 16:43:31.0020 0672 mdmxsdk - ok 16:43:31.0235 0672 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys 16:43:31.0276 0672 megasas - ok 16:43:31.0519 0672 Mkd2kfNt (6f4d79ea861137ef2f9078e265c2aa83) C:\Windows\system32\drivers\Mkd2kfNt.sys 16:43:31.0561 0672 Mkd2kfNt ( UnsignedFile.Multi.Generic ) - warning 16:43:31.0562 0672 Mkd2kfNt - detected UnsignedFile.Multi.Generic (1) 16:43:31.0775 0672 Mkd2Nadr (fe7925784f6801e983b41ec118ef62ac) C:\Windows\system32\drivers\Mkd2Nadr.sys 16:43:31.0806 0672 Mkd2Nadr ( UnsignedFile.Multi.Generic ) - warning 16:43:31.0806 0672 Mkd2Nadr - detected UnsignedFile.Multi.Generic (1) 16:43:31.0995 0672 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll 16:43:32.0090 0672 MMCSS - ok 16:43:32.0296 0672 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 16:43:32.0386 0672 Modem - ok 16:43:32.0623 0672 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 16:43:32.0721 0672 monitor - ok 16:43:32.0947 0672 MotioninJoyXFilter (61448ba3cca3063541437694a5527af2) C:\Windows\system32\DRIVERS\MijXfilt.sys 16:43:32.0988 0672 MotioninJoyXFilter - ok 16:43:33.0197 0672 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 16:43:33.0239 0672 mouclass - ok 16:43:33.0438 0672 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 16:43:33.0534 0672 mouhid - ok 16:43:33.0742 0672 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 16:43:33.0787 0672 MountMgr - ok 16:43:33.0999 0672 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys 16:43:34.0042 0672 mpio - ok 16:43:34.0247 0672 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 16:43:34.0326 0672 mpsdrv - ok 16:43:34.0542 0672 MpsSvc (5de62c6e9108f14f6794060a9bdecaec) C:\Windows\system32\mpssvc.dll 16:43:34.0652 0672 MpsSvc - ok 16:43:34.0869 0672 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 16:43:34.0909 0672 Mraid35x - ok 16:43:35.0126 0672 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 16:43:35.0196 0672 MRxDAV - ok 16:43:35.0394 0672 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 16:43:35.0476 0672 mrxsmb - ok 16:43:35.0700 0672 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 16:43:35.0767 0672 mrxsmb10 - ok 16:43:35.0973 0672 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 16:43:36.0034 0672 mrxsmb20 - ok 16:43:36.0245 0672 msahci (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys 16:43:36.0284 0672 msahci - ok 16:43:36.0404 0672 MSCSPTISRV (8e46a7bac823dd82d4fb2a34c3df4c1d) C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe 16:43:36.0443 0672 MSCSPTISRV ( UnsignedFile.Multi.Generic ) - warning 16:43:36.0443 0672 MSCSPTISRV - detected UnsignedFile.Multi.Generic (1) 16:43:36.0677 0672 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys 16:43:36.0719 0672 msdsm - ok 16:43:36.0898 0672 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe 16:43:36.0977 0672 MSDTC - ok 16:43:37.0192 0672 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 16:43:37.0285 0672 Msfs - ok 16:43:37.0492 0672 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 16:43:37.0534 0672 msisadrv - ok 16:43:37.0730 0672 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll 16:43:37.0829 0672 MSiSCSI - ok 16:43:37.0974 0672 msiserver - ok 16:43:38.0060 0672 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 16:43:38.0151 0672 MSKSSRV - ok 16:43:38.0363 0672 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 16:43:38.0458 0672 MSPCLOCK - ok 16:43:38.0686 0672 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 16:43:38.0787 0672 MSPQM - ok 16:43:38.0998 0672 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 16:43:39.0049 0672 MsRPC - ok 16:43:39.0267 0672 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 16:43:39.0309 0672 mssmbios - ok 16:43:39.0509 0672 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 16:43:39.0609 0672 MSTEE - ok 16:43:39.0806 0672 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 16:43:39.0852 0672 Mup - ok 16:43:40.0030 0672 napagent (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll 16:43:40.0125 0672 napagent - ok 16:43:40.0352 0672 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 16:43:40.0416 0672 NativeWifiP - ok 16:43:40.0682 0672 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 16:43:40.0754 0672 NDIS - ok 16:43:40.0952 0672 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 16:43:41.0035 0672 NdisTapi - ok 16:43:41.0256 0672 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 16:43:41.0332 0672 Ndisuio - ok 16:43:41.0533 0672 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 16:43:41.0599 0672 NdisWan - ok 16:43:41.0812 0672 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 16:43:41.0894 0672 NDProxy - ok 16:43:42.0078 0672 Net Driver HPZ12 (2969d26eee289be7422aa46fc55f4e38) C:\Windows\system32\HPZinw12.dll 16:43:42.0100 0672 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning 16:43:42.0100 0672 Net Driver HPZ12 - detected UnsignedFile.Multi.Generic (1) 16:43:42.0312 0672 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 16:43:42.0400 0672 NetBIOS - ok 16:43:42.0604 0672 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 16:43:42.0697 0672 netbt - ok 16:43:42.0891 0672 Netlogon (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 16:43:42.0937 0672 Netlogon - ok 16:43:43.0106 0672 Netman (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll 16:43:43.0190 0672 Netman - ok 16:43:43.0286 0672 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll 16:43:43.0393 0672 netprofm - ok 16:43:43.0518 0672 NetTcpPortSharing (d6c4e4a39a36029ac0813d476fbd0248) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 16:43:43.0570 0672 NetTcpPortSharing - ok 16:43:43.0763 0672 NETw3v32 (a15f219208843a5a210c8cb391384453) C:\Windows\system32\DRIVERS\NETw3v32.sys 16:43:43.0971 0672 NETw3v32 - ok 16:43:44.0246 0672 NETw4v32 (6522dd40a5f67ced020bd81b856613fb) C:\Windows\system32\DRIVERS\NETw4v32.sys 16:43:44.0453 0672 NETw4v32 - ok 16:43:44.0810 0672 NETw5v32 (8de67bd902095a13329fd82c85a1fa09) C:\Windows\system32\DRIVERS\NETw5v32.sys 16:43:45.0079 0672 NETw5v32 - ok 16:43:45.0297 0672 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 16:43:45.0339 0672 nfrd960 - ok 16:43:45.0514 0672 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll 16:43:45.0614 0672 NlaSvc - ok 16:43:45.0876 0672 nmwcd (c3963d85b721a7f80d8a55f4e2867a3a) C:\Windows\system32\drivers\ccdcmb.sys 16:43:46.0008 0672 nmwcd - ok 16:43:46.0205 0672 nmwcdc (3859c69a77793180548802dac9f34a38) C:\Windows\system32\drivers\ccdcmbo.sys 16:43:46.0280 0672 nmwcdc - ok 16:43:46.0491 0672 nmwcdnsu (338f83ee9cb9e15eeacf0cbb90218cbf) C:\Windows\system32\drivers\nmwcdnsu.sys 16:43:46.0572 0672 nmwcdnsu - ok 16:43:46.0813 0672 nmwcdnsuc (d15bac979144fb69ed28f97b2dd84d48) C:\Windows\system32\drivers\nmwcdnsuc.sys 16:43:46.0917 0672 nmwcdnsuc - ok 16:43:47.0129 0672 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 16:43:47.0191 0672 Npfs - ok 16:43:47.0367 0672 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll 16:43:47.0465 0672 nsi - ok 16:43:47.0681 0672 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 16:43:47.0798 0672 nsiproxy - ok 16:43:48.0041 0672 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 16:43:48.0144 0672 Ntfs - ok 16:43:48.0423 0672 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 16:43:48.0582 0672 ntrigdigi - ok 16:43:48.0807 0672 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 16:43:48.0885 0672 Null - ok 16:43:49.0118 0672 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys 16:43:49.0162 0672 nvraid - ok 16:43:49.0382 0672 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys 16:43:49.0423 0672 nvstor - ok 16:43:49.0670 0672 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys 16:43:49.0716 0672 nv_agp - ok 16:43:49.0930 0672 NwlnkFlt - ok 16:43:50.0225 0672 NwlnkFwd - ok 16:43:50.0329 0672 o2flash (d955d5de998db2476bf0892be3a96c26) C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe 16:43:50.0364 0672 o2flash ( UnsignedFile.Multi.Generic ) - warning 16:43:50.0364 0672 o2flash - detected UnsignedFile.Multi.Generic (1) 16:43:50.0595 0672 O2MDRDR (d51942f12090fc947ca8aa01736dade2) C:\Windows\system32\DRIVERS\o2media.sys 16:43:50.0642 0672 O2MDRDR - ok 16:43:50.0803 0672 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 16:43:50.0865 0672 odserv - ok 16:43:51.0072 0672 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 16:43:51.0156 0672 ohci1394 - ok 16:43:51.0289 0672 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 16:43:51.0333 0672 ose - ok 16:43:51.0569 0672 p2pimsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 16:43:51.0704 0672 p2pimsvc - ok 16:43:51.0733 0672 p2psvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 16:43:51.0802 0672 p2psvc - ok 16:43:51.0913 0672 PACSPTISVR (753a8f339f231d2b857e2ccd51a6e6ca) C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe 16:43:51.0928 0672 PACSPTISVR ( UnsignedFile.Multi.Generic ) - warning 16:43:51.0928 0672 PACSPTISVR - detected UnsignedFile.Multi.Generic (1) 16:43:52.0138 0672 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 16:43:52.0289 0672 Parport - ok 16:43:52.0511 0672 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 16:43:52.0557 0672 partmgr - ok 16:43:52.0770 0672 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 16:43:52.0918 0672 Parvdm - ok 16:43:53.0090 0672 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll 16:43:53.0182 0672 PcaSvc - ok 16:43:53.0401 0672 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys 16:43:53.0482 0672 pccsmcfd - ok 16:43:53.0699 0672 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 16:43:53.0751 0672 pci - ok 16:43:53.0987 0672 pciide (3b1901e401473e03eb8c874271e50c26) C:\Windows\system32\drivers\pciide.sys 16:43:54.0027 0672 pciide - ok 16:43:54.0308 0672 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 16:43:54.0355 0672 pcmcia - ok 16:43:54.0775 0672 PCTAppEvent (4bb87c2afb75f8ab3c24f2af59e3b172) C:\Windows\system32\drivers\PCTAppEvent.sys 16:43:54.0830 0672 PCTAppEvent - ok 16:43:55.0073 0672 PCTBD (3a0262b85b5bb4d4cfc096ea00ed610b) C:\Windows\system32\Drivers\PCTBD.sys 16:43:55.0109 0672 PCTBD - ok 16:43:55.0344 0672 pctBTFix (7466e60eb713396e168a2e2c9b4594c2) C:\Windows\system32\Drivers\pctBTFix.sys 16:43:55.0378 0672 pctBTFix - ok 16:43:55.0624 0672 PCTCore (0edb74bd0d52d6d94cf862322e48b94e) C:\Windows\system32\drivers\PCTCore.sys 16:43:55.0682 0672 PCTCore - ok 16:43:55.0946 0672 pctDS (8734f7346b39a710491e0ddb136da2a3) C:\Windows\system32\drivers\pctDS.sys 16:43:55.0999 0672 pctDS - ok 16:43:56.0277 0672 pctEFA (653d8079cc000ec454789740a07b84a8) C:\Windows\system32\drivers\pctEFA.sys 16:43:56.0340 0672 pctEFA - ok 16:43:56.0548 0672 pctgntdi (cee55a1df92cb30f87280b6a04aadce8) C:\Windows\System32\drivers\pctgntdi.sys 16:43:56.0595 0672 pctgntdi - ok 16:43:56.0840 0672 pctNdisLW (1623220615f0afabf9027c6f8d4da58a) C:\Windows\system32\drivers\pctNdisLW.sys 16:43:56.0876 0672 pctNdisLW - ok 16:43:57.0094 0672 pctplfw (92dcd373d14fd37d20e442cce252a6e4) C:\Windows\System32\drivers\pctplfw.sys 16:43:57.0133 0672 pctplfw - ok 16:43:57.0377 0672 pctplsg (061b86fd64a61ad187efc788d6c408b0) C:\Windows\System32\drivers\pctplsg.sys 16:43:57.0415 0672 pctplsg - ok 16:43:57.0632 0672 PCTSD (eb98f7514dcf1b922b318e6182d836b1) C:\Windows\system32\Drivers\PCTSD.sys 16:43:57.0679 0672 PCTSD - ok 16:43:57.0950 0672 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 16:43:58.0106 0672 PEAUTH - ok 16:43:58.0380 0672 pla (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll 16:43:58.0555 0672 pla - ok 16:43:58.0736 0672 PlugPlay (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll 16:43:58.0827 0672 PlugPlay - ok 16:43:59.0034 0672 Pml Driver HPZ12 (bafc9706bdf425a02b66468ab2605c59) C:\Windows\system32\HPZipm12.dll 16:43:59.0068 0672 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning 16:43:59.0068 0672 Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1) 16:43:59.0259 0672 PNRPAutoReg (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 16:43:59.0327 0672 PNRPAutoReg - ok 16:43:59.0356 0672 PNRPsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 16:43:59.0425 0672 PNRPsvc - ok 16:43:59.0621 0672 PolicyAgent (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll 16:43:59.0699 0672 PolicyAgent - ok 16:43:59.0921 0672 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 16:43:59.0996 0672 PptpMiniport - ok 16:44:00.0595 0672 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys 16:44:00.0729 0672 Processor - ok 16:44:00.0938 0672 ProfSvc (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll 16:44:01.0004 0672 ProfSvc - ok 16:44:01.0426 0672 ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 16:44:01.0492 0672 ProtectedStorage - ok 16:44:01.0882 0672 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 16:44:01.0965 0672 PSched - ok 16:44:02.0411 0672 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\Windows\system32\Drivers\PxHelp20.sys 16:44:02.0449 0672 PxHelp20 - ok 16:44:02.0891 0672 QIOMem (674eba70a52c02696e503b0a57ae6372) C:\Windows\system32\DRIVERS\QIOMem.sys 16:44:02.0963 0672 QIOMem - ok 16:44:03.0689 0672 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys 16:44:03.0778 0672 ql2300 - ok 16:44:04.0102 0672 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 16:44:04.0146 0672 ql40xx - ok 16:44:04.0561 0672 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll 16:44:04.0646 0672 QWAVE - ok 16:44:05.0246 0672 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 16:44:05.0292 0672 QWAVEdrv - ok 16:44:05.0742 0672 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 16:44:05.0843 0672 RasAcd - ok 16:44:06.0045 0672 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll 16:44:06.0149 0672 RasAuto - ok 16:44:06.0713 0672 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 16:44:06.0788 0672 Rasl2tp - ok 16:44:06.0999 0672 RasMan (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll 16:44:07.0085 0672 RasMan - ok 16:44:07.0669 0672 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 16:44:07.0734 0672 RasPppoe - ok 16:44:08.0064 0672 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 16:44:08.0134 0672 RasSstp - ok 16:44:08.0514 0672 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 16:44:08.0581 0672 rdbss - ok 16:44:08.0926 0672 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 16:44:09.0025 0672 RDPCDD - ok 16:44:09.0509 0672 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys 16:44:09.0670 0672 rdpdr - ok 16:44:10.0064 0672 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 16:44:10.0164 0672 RDPENCDD - ok 16:44:10.0595 0672 RDPWD (79c6df8477250f5c54f7c5ae1d6b814e) C:\Windows\system32\drivers\RDPWD.sys 16:44:10.0680 0672 RDPWD - ok 16:44:11.0014 0672 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll 16:44:11.0093 0672 RemoteAccess - ok 16:44:11.0675 0672 RemoteRegistry (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll 16:44:11.0789 0672 RemoteRegistry - ok 16:44:12.0129 0672 ROOTMODEM (75e8a6bfa7374aba833ae92bf41ae4e6) C:\Windows\system32\Drivers\RootMdm.sys 16:44:12.0246 0672 ROOTMODEM - ok 16:44:12.0697 0672 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe 16:44:12.0775 0672 RpcLocator - ok 16:44:13.0251 0672 RpcSs (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll 16:44:13.0332 0672 RpcSs - ok 16:44:13.0794 0672 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 16:44:13.0901 0672 rspndr - ok 16:44:14.0167 0672 SamSs (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 16:44:14.0276 0672 SamSs - ok 16:44:14.0594 0672 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 16:44:14.0639 0672 sbp2port - ok 16:44:14.0870 0672 SCardSvr (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll 16:44:14.0949 0672 SCardSvr - ok 16:44:15.0289 0672 Schedule (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll 16:44:15.0418 0672 Schedule - ok 16:44:15.0679 0672 SCPolicySvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll 16:44:15.0734 0672 SCPolicySvc - ok 16:44:15.0903 0672 sdAuxService (17d6a03103586d7954ba74c2219ce1bb) C:\Program Files\PC Tools Security\pctsAuxs.exe 16:44:16.0040 0672 sdAuxService - ok 16:44:16.0581 0672 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys 16:44:16.0629 0672 sdbus - ok 16:44:16.0817 0672 sdCoreService (d2b30a5a8f57c00b0fa84a8880e9ec5b) C:\Program Files\PC Tools Security\pctsSvc.exe 16:44:16.0908 0672 sdCoreService - ok 16:44:17.0270 0672 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll 16:44:17.0379 0672 SDRSVC - ok 16:44:17.0544 0672 SeaPort (271077b91d7ad1b616f8afdfe8e3f981) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 16:44:17.0619 0672 SeaPort - ok 16:44:17.0998 0672 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 16:44:18.0090 0672 secdrv - ok 16:44:18.0399 0672 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll 16:44:18.0498 0672 seclogon - ok 16:44:19.0048 0672 SENS (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll 16:44:19.0131 0672 SENS - ok 16:44:19.0983 0672 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 16:44:20.0115 0672 Serenum - ok 16:44:20.0994 0672 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 16:44:21.0134 0672 Serial - ok 16:44:21.0486 0672 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 16:44:21.0560 0672 sermouse - ok 16:44:21.0728 0672 ServiceLayer (58d5bfdf3adf49fe9cabd78cc61d92f6) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe 16:44:21.0777 0672 ServiceLayer ( UnsignedFile.Multi.Generic ) - warning 16:44:21.0777 0672 ServiceLayer - detected UnsignedFile.Multi.Generic (1) 16:44:22.0089 0672 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll 16:44:22.0196 0672 SessionEnv - ok 16:44:22.0506 0672 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys 16:44:22.0594 0672 sffdisk - ok 16:44:23.0077 0672 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys 16:44:23.0221 0672 sffp_mmc - ok 16:44:24.0747 0672 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys 16:44:24.0832 0672 sffp_sd - ok 16:44:25.0356 0672 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 16:44:25.0474 0672 sfloppy - ok 16:44:25.0788 0672 SharedAccess (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll 16:44:25.0889 0672 SharedAccess - ok 16:44:26.0155 0672 ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll 16:44:26.0247 0672 ShellHWDetection - ok 16:44:26.0475 0672 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys 16:44:26.0515 0672 sisagp - ok 16:44:26.0740 0672 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys 16:44:26.0781 0672 SiSRaid2 - ok 16:44:27.0018 0672 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys 16:44:27.0061 0672 SiSRaid4 - ok 16:44:27.0374 0672 slsvc (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe 16:44:27.0593 0672 slsvc - ok 16:44:27.0778 0672 SLUINotify (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll 16:44:27.0844 0672 SLUINotify - ok 16:44:27.0930 0672 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 16:44:28.0007 0672 Smb - ok 16:44:28.0238 0672 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe 16:44:28.0283 0672 SNMPTRAP - ok 16:44:28.0418 0672 SonicStage Back-End Service (977aaa4398d7d6fa65d973f5b3f54e40) C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe 16:44:28.0460 0672 SonicStage Back-End Service - ok 16:44:28.0699 0672 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 16:44:28.0741 0672 spldr - ok 16:44:28.0924 0672 Spooler (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe 16:44:29.0037 0672 Spooler - ok 16:44:29.0277 0672 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\Windows\system32\Drivers\sptd.sys 16:44:29.0278 0672 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9 16:44:29.0290 0672 sptd ( LockedFile.Multi.Generic ) - warning 16:44:29.0290 0672 sptd - detected LockedFile.Multi.Generic (1) 16:44:29.0411 0672 SPTISRV (e3e6c96b0ef4492c3c8fd0deef4e35a1) C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe 16:44:29.0448 0672 SPTISRV ( UnsignedFile.Multi.Generic ) - warning 16:44:29.0449 0672 SPTISRV - detected UnsignedFile.Multi.Generic (1) 16:44:29.0667 0672 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 16:44:29.0759 0672 srv - ok 16:44:30.0002 0672 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 16:44:30.0062 0672 srv2 - ok 16:44:30.0302 0672 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 16:44:30.0371 0672 srvnet - ok 16:44:30.0551 0672 sscdbus - ok 16:44:30.0733 0672 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll 16:44:30.0815 0672 SSDPSRV - ok 16:44:30.0926 0672 SSScsiSV (756e371b3b86a3d3039926d32eac0e8d) C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe 16:44:30.0961 0672 SSScsiSV - ok 16:44:31.0155 0672 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll 16:44:31.0225 0672 SstpSvc - ok 16:44:31.0427 0672 stisvc (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll 16:44:31.0495 0672 stisvc - ok 16:44:31.0713 0672 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 16:44:31.0755 0672 swenum - ok 16:44:31.0945 0672 swprv (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll 16:44:32.0019 0672 swprv - ok 16:44:32.0240 0672 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 16:44:32.0282 0672 Symc8xx - ok 16:44:32.0523 0672 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 16:44:32.0563 0672 Sym_hi - ok 16:44:32.0782 0672 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 16:44:32.0822 0672 Sym_u3 - ok 16:44:33.0047 0672 SynTP (91ac243740ca09a907e7cbd2da274c96) C:\Windows\system32\DRIVERS\SynTP.sys 16:44:33.0092 0672 SynTP - ok 16:44:33.0331 0672 SysMain (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll 16:44:33.0454 0672 SysMain - ok 16:44:33.0645 0672 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll 16:44:33.0698 0672 TabletInputService - ok 16:44:33.0881 0672 TapiSrv (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll 16:44:33.0964 0672 TapiSrv - ok 16:44:34.0157 0672 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll 16:44:34.0238 0672 TBS - ok 16:44:34.0519 0672 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys 16:44:34.0613 0672 Tcpip - ok 16:44:34.0885 0672 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys 16:44:34.0966 0672 Tcpip6 - ok 16:44:35.0188 0672 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 16:44:35.0273 0672 tcpipreg - ok 16:44:35.0492 0672 tdcmdpst (1825bceb47bf41c5a9f0e44de82fc27a) C:\Windows\system32\DRIVERS\tdcmdpst.sys 16:44:35.0560 0672 tdcmdpst - ok 16:44:35.0762 0672 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 16:44:35.0857 0672 TDPIPE - ok 16:44:36.0081 0672 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 16:44:36.0156 0672 TDTCP - ok 16:44:36.0392 0672 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 16:44:36.0462 0672 tdx - ok 16:44:36.0680 0672 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 16:44:36.0726 0672 TermDD - ok 16:44:36.0918 0672 TermService (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll 16:44:37.0034 0672 TermService - ok 16:44:37.0271 0672 TfFsMon (754f8fd78ea7fa2b9a0cb8a69e0f0822) C:\Windows\system32\drivers\TfFsMon.sys 16:44:37.0307 0672 TfFsMon - ok 16:44:37.0568 0672 TfNetMon (697f66899b4f0c2d8ae3e7473b4b6244) C:\Windows\system32\drivers\TfNetMon.sys 16:44:37.0603 0672 TfNetMon - ok 16:44:37.0842 0672 TFSysMon (e02f47b841be86bfdf4d7269ed0b95e4) C:\Windows\system32\drivers\TfSysMon.sys 16:44:37.0909 0672 TFSysMon - ok 16:44:38.0145 0672 Themes (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll 16:44:38.0204 0672 Themes - ok 16:44:38.0414 0672 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll 16:44:38.0488 0672 THREADORDER - ok 16:44:38.0583 0672 ThreatFire - ok 16:44:38.0676 0672 TNaviSrv (e47f35a87ff0da38def37a0eb0c2d2df) C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe 16:44:38.0713 0672 TNaviSrv - ok 16:44:38.0907 0672 TODDSrv (c5ac715b65b01788abc22d10749dddd8) C:\Windows\system32\TODDSrv.exe 16:44:38.0950 0672 TODDSrv - ok 16:44:39.0039 0672 TosCoSrv (da6903958cbdc091ffcbbca70ccff34c) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe 16:44:39.0093 0672 TosCoSrv - ok 16:44:39.0228 0672 TOSHIBA Bluetooth Service (2e7315b147e524e055026e6634b14ea6) c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe 16:44:39.0280 0672 TOSHIBA Bluetooth Service - ok 16:44:39.0377 0672 TOSHIBA SMART Log Service (22690dffc7f2a18279a7a0489aa02bac) C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe 16:44:39.0397 0672 TOSHIBA SMART Log Service ( UnsignedFile.Multi.Generic ) - warning 16:44:39.0397 0672 TOSHIBA SMART Log Service - detected UnsignedFile.Multi.Generic (1) 16:44:39.0615 0672 tosporte (8d624d3bd1f2d78bd1c01a2d4e954b4e) C:\Windows\system32\DRIVERS\tosporte.sys 16:44:39.0699 0672 tosporte - ok 16:44:39.0919 0672 tosrfbd (ae43138b0dea239b3621b0faf1bb1fe7) C:\Windows\system32\DRIVERS\tosrfbd.sys 16:44:39.0997 0672 tosrfbd - ok 16:44:40.0205 0672 tosrfbnp (181e217a7a326817d97946d045b3cb46) C:\Windows\system32\Drivers\tosrfbnp.sys 16:44:40.0286 0672 tosrfbnp - ok 16:44:40.0497 0672 Tosrfcom (e90ace3b4fa7a85f992bc21eb779c407) C:\Windows\system32\Drivers\tosrfcom.sys 16:44:40.0582 0672 Tosrfcom - ok 16:44:40.0813 0672 tosrfec (5c4103544612e5011ef46301b93d1aa6) C:\Windows\system32\DRIVERS\tosrfec.sys 16:44:40.0864 0672 tosrfec - ok 16:44:41.0098 0672 Tosrfhid (87700714f25131ed21901d617b8b321f) C:\Windows\system32\DRIVERS\Tosrfhid.sys 16:44:41.0172 0672 Tosrfhid - ok 16:44:41.0377 0672 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\Windows\system32\DRIVERS\tosrfnds.sys 16:44:41.0447 0672 tosrfnds - ok 16:44:41.0664 0672 Tosrfusb (98c04a6432ce9c2ad328f57b9384d348) C:\Windows\system32\DRIVERS\tosrfusb.sys 16:44:41.0722 0672 Tosrfusb - ok 16:44:41.0944 0672 tos_sps32 (1ea5f27c29405bf49799feca77186da9) C:\Windows\system32\DRIVERS\tos_sps32.sys 16:44:42.0003 0672 tos_sps32 - ok 16:44:42.0191 0672 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll 16:44:42.0273 0672 TrkWks - ok 16:44:42.0393 0672 TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe 16:44:42.0485 0672 TrustedInstaller - ok 16:44:42.0658 0672 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 16:44:42.0744 0672 tssecsrv - ok 16:44:42.0988 0672 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 16:44:43.0034 0672 tunmp - ok 16:44:43.0246 0672 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 16:44:43.0307 0672 tunnel - ok 16:44:43.0524 0672 TVALZ (792a8b80f8188aba4b2be271583f3e46) C:\Windows\system32\DRIVERS\TVALZ_O.SYS 16:44:43.0560 0672 TVALZ - ok 16:44:43.0767 0672 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys 16:44:43.0809 0672 uagp35 - ok 16:44:44.0021 0672 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 16:44:44.0107 0672 udfs - ok 16:44:44.0330 0672 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe 16:44:44.0423 0672 UI0Detect - ok 16:44:44.0566 0672 UleadBurningHelper (332d341d92b933600d41953b08360dfb) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe 16:44:44.0584 0672 UleadBurningHelper ( UnsignedFile.Multi.Generic ) - warning 16:44:44.0584 0672 UleadBurningHelper - detected UnsignedFile.Multi.Generic (1) 16:44:44.0802 0672 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys 16:44:44.0843 0672 uliagpkx - ok 16:44:45.0088 0672 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys 16:44:45.0137 0672 uliahci - ok 16:44:45.0366 0672 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 16:44:45.0411 0672 UlSata - ok 16:44:45.0622 0672 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 16:44:45.0669 0672 ulsata2 - ok 16:44:45.0885 0672 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 16:44:45.0973 0672 umbus - ok 16:44:46.0175 0672 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll 16:44:46.0260 0672 upnphost - ok 16:44:46.0468 0672 upperdev (0ccadc7391021376edbb8aa649d04e68) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys 16:44:46.0543 0672 upperdev - ok 16:44:46.0779 0672 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys 16:44:46.0863 0672 usbaudio - ok 16:44:47.0095 0672 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 16:44:47.0172 0672 usbccgp - ok 16:44:47.0396 0672 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 16:44:47.0517 0672 usbcir - ok 16:44:47.0726 0672 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 16:44:47.0803 0672 usbehci - ok 16:44:48.0019 0672 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 16:44:48.0103 0672 usbhub - ok 16:44:48.0335 0672 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 16:44:48.0489 0672 usbohci - ok 16:44:48.0703 0672 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 16:44:48.0776 0672 usbprint - ok 16:44:49.0013 0672 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 16:44:49.0074 0672 usbscan - ok 16:44:49.0291 0672 usbser (d575246188f63de0accf6eac5fb59e6a) C:\Windows\system32\drivers\usbser.sys 16:44:49.0366 0672 usbser - ok 16:44:49.0596 0672 UsbserFilt (68b4f83cccf70a2ff32ee142c234332a) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys 16:44:49.0678 0672 UsbserFilt - ok 16:44:49.0897 0672 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 16:44:49.0980 0672 USBSTOR - ok 16:44:50.0192 0672 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 16:44:50.0253 0672 usbuhci - ok 16:44:50.0465 0672 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 16:44:50.0561 0672 usbvideo - ok 16:44:50.0786 0672 UVCFTR (8c5094a8ab24de7496c7c19942f2df04) C:\Windows\system32\Drivers\UVCFTR_S.SYS 16:44:50.0830 0672 UVCFTR - ok 16:44:51.0029 0672 UxSms (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll 16:44:51.0114 0672 UxSms - ok 16:44:51.0306 0672 vds (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe 16:44:51.0388 0672 vds - ok 16:44:51.0628 0672 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys 16:44:51.0781 0672 vga - ok 16:44:52.0001 0672 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 16:44:52.0097 0672 VgaSave - ok 16:44:52.0337 0672 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys 16:44:52.0377 0672 viaagp - ok 16:44:52.0611 0672 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys 16:44:52.0731 0672 ViaC7 - ok 16:44:52.0940 0672 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys 16:44:52.0979 0672 viaide - ok 16:44:53.0097 0672 VMCService (6e021d6da429ad7288fe8322e2bba96b) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe 16:44:53.0114 0672 VMCService ( UnsignedFile.Multi.Generic ) - warning 16:44:53.0114 0672 VMCService - detected UnsignedFile.Multi.Generic (1) 16:44:53.0325 0672 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 16:44:53.0369 0672 volmgr - ok 16:44:53.0585 0672 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 16:44:53.0643 0672 volmgrx - ok 16:44:53.0865 0672 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 16:44:53.0919 0672 volsnap - ok 16:44:54.0137 0672 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys 16:44:54.0181 0672 vsmraid - ok 16:44:54.0403 0672 VSS (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe 16:44:54.0517 0672 VSS - ok 16:44:54.0726 0672 W32Time (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll 16:44:54.0816 0672 W32Time - ok 16:44:55.0064 0672 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 16:44:55.0205 0672 WacomPen - ok 16:44:55.0428 0672 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 16:44:55.0509 0672 Wanarp - ok 16:44:55.0533 0672 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 16:44:55.0594 0672 Wanarpv6 - ok 16:44:55.0784 0672 wcncsvc (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll 16:44:55.0853 0672 wcncsvc - ok 16:44:56.0043 0672 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll 16:44:56.0130 0672 WcsPlugInService - ok 16:44:56.0358 0672 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys 16:44:56.0397 0672 Wd - ok 16:44:56.0619 0672 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 16:44:56.0688 0672 Wdf01000 - ok 16:44:56.0858 0672 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll 16:44:56.0958 0672 WdiServiceHost - ok 16:44:56.0979 0672 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll 16:44:57.0057 0672 WdiSystemHost - ok 16:44:57.0242 0672 WebClient (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll 16:44:57.0320 0672 WebClient - ok 16:44:57.0533 0672 Wecsvc (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll 16:44:57.0649 0672 Wecsvc - ok 16:44:57.0836 0672 wercplsupport (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll 16:44:57.0924 0672 wercplsupport - ok 16:44:58.0131 0672 WerSvc (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll 16:44:58.0200 0672 WerSvc - ok 16:44:58.0473 0672 winachsf (5b08eb7a6e2aba210a218636fa65927d) C:\Windows\system32\DRIVERS\HSX_CNXT.sys 16:44:58.0564 0672 winachsf - ok 16:44:58.0680 0672 WinDefend (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll 16:44:58.0732 0672 WinDefend - ok 16:44:58.0768 0672 WinHttpAutoProxySvc - ok 16:44:59.0268 0672 Winmgmt (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll 16:44:59.0333 0672 Winmgmt - ok 16:44:59.0978 0672 WinRM (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll 16:45:00.0110 0672 WinRM - ok 16:45:00.0369 0672 Wlansvc (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll 16:45:00.0461 0672 Wlansvc - ok 16:45:00.0611 0672 wlidsvc (5144ae67d60ec653f97ddf3feed29e77) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 16:45:00.0761 0672 wlidsvc - ok 16:45:00.0982 0672 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 16:45:01.0056 0672 WmiAcpi - ok 16:45:01.0305 0672 wmiApSrv (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe 16:45:01.0369 0672 wmiApSrv - ok 16:45:01.0489 0672 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe 16:45:01.0630 0672 WMPNetworkSvc - ok 16:45:01.0825 0672 WPCSvc (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll 16:45:01.0914 0672 WPCSvc - ok 16:45:02.0102 0672 WPDBusEnum (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll 16:45:02.0192 0672 WPDBusEnum - ok 16:45:02.0412 0672 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 16:45:02.0457 0672 WpdUsb - ok 16:45:02.0675 0672 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 16:45:02.0752 0672 WPFFontCache_v0400 - ok 16:45:02.0971 0672 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 16:45:03.0045 0672 ws2ifsl - ok 16:45:03.0237 0672 wscsvc (1ca6c40261ddc0425987980d0cd2aaab) C:\Windows\System32\wscsvc.dll 16:45:03.0289 0672 wscsvc - ok 16:45:03.0487 0672 WSearch - ok 16:45:03.0631 0672 wuauserv (6298277b73c77fa99106b271a7525163) C:\Windows\system32\wuaueng.dll 16:45:03.0788 0672 wuauserv - ok 16:45:04.0003 0672 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 16:45:04.0080 0672 WUDFRd - ok 16:45:04.0266 0672 wudfsvc (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll 16:45:04.0345 0672 wudfsvc - ok 16:45:04.0567 0672 XAudio (725e96971f22fe237e553eb35fc83564) C:\Windows\system32\DRIVERS\xaudio.sys 16:45:04.0624 0672 XAudio - ok 16:45:04.0888 0672 XAudioService (46aa0fe850264152e2ba74fbe9a6aad1) C:\Windows\system32\DRIVERS\xaudio.exe 16:45:04.0940 0672 XAudioService - ok 16:45:05.0183 0672 xusb21 (ee9144207ee0211eb5656ba6808ac4a0) C:\Windows\system32\DRIVERS\xusb21.sys 16:45:05.0221 0672 xusb21 - ok 16:45:05.0468 0672 yukonwlh (d51febb9f6869512ea2b636e2b30df7b) C:\Windows\system32\DRIVERS\yk60x86.sys 16:45:05.0549 0672 yukonwlh - ok 16:45:05.0592 0672 zlportio - ok 16:45:05.0791 0672 ZTEusbmdm6k - ok 16:45:06.0000 0672 ZTEusbnmea - ok 16:45:06.0189 0672 ZTEusbser6k - ok 16:45:06.0305 0672 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 16:45:07.0293 0672 \Device\Harddisk0\DR0 - ok 16:45:07.0331 0672 Boot (0x1200) (f1e0a6b1300c7da7ce68d13d02ae294d) \Device\Harddisk0\DR0\Partition0 16:45:07.0334 0672 \Device\Harddisk0\DR0\Partition0 - ok 16:45:07.0362 0672 Boot (0x1200) (f46b1ff558a2044f134cf989796d43d1) \Device\Harddisk0\DR0\Partition1 16:45:07.0364 0672 \Device\Harddisk0\DR0\Partition1 - ok 16:45:07.0365 0672 ============================================================ 16:45:07.0366 0672 Scan finished 16:45:07.0366 0672 ============================================================ 16:45:07.0387 3192 Detected object count: 20 16:45:07.0387 3192 Actual detected object count: 20 16:45:46.0140 3192 Bonjour Service ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0140 3192 Bonjour Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0143 3192 ConfigFree Service ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0144 3192 ConfigFree Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0146 3192 DAZContentManagementService ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0146 3192 DAZContentManagementService ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0148 3192 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0148 3192 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0151 3192 hpqcxs08 ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0151 3192 hpqcxs08 ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0151 3192 hpqddsvc ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0152 3192 hpqddsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0154 3192 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0154 3192 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0157 3192 Mkd2kfNt ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0157 3192 Mkd2kfNt ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0159 3192 Mkd2Nadr ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0159 3192 Mkd2Nadr ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0162 3192 MSCSPTISRV ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0162 3192 MSCSPTISRV ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0164 3192 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0164 3192 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0167 3192 o2flash ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0167 3192 o2flash ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0169 3192 PACSPTISVR ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0170 3192 PACSPTISVR ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0171 3192 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0171 3192 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0173 3192 ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0173 3192 ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0176 3192 sptd ( LockedFile.Multi.Generic ) - skipped by user 16:45:46.0176 3192 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 16:45:46.0179 3192 SPTISRV ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0179 3192 SPTISRV ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0182 3192 TOSHIBA SMART Log Service ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0182 3192 TOSHIBA SMART Log Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0184 3192 UleadBurningHelper ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0184 3192 UleadBurningHelper ( UnsignedFile.Multi.Generic ) - User select action: Skip 16:45:46.0185 3192 VMCService ( UnsignedFile.Multi.Generic ) - skipped by user 16:45:46.0185 3192 VMCService ( UnsignedFile.Multi.Generic ) - User select action: Skip
Hi,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.


Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Hi! I had problems with ComboFix and, since you told me not to re-run it, here I am. I downloaded it and then I clicked on it for it to start scanning. It started extracting its files and closed my Google Chrome. But then no window appeared. After a bit, the computer completely freezed. Not even the mouse was moving. I had to force a restart. What should I do now?
Well, everything went well until stage 2. Then it stopped and the whole Windows freezed. Again. These freezings have been usual, something that is scarying me. My computer might be quite infected… Moving on… ComboFix never finished the scan. So, should I retry it?
Hi,

Yes malware may be blocking it. If I understand you correctly you were able to get ComboFix downloaded this time but not run all the way through? If that is the case please boot to Safe Mode and run ComboFix from there.

If you were not able to get ComboFix downloaded or you can't get it to run through in Safe Mode please do the following:

  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please attach the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
ComboFix didn't work. At all. Not even in safe mode =/
So I followed your advice and I ran that other program. Here are the logs:

OTL.txt


OTL logfile created on: 23-04-2012 20:05:55 - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = C:\Users\coimbra\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy

3,00 Gb Total Physical Memory | 1,82 Gb Available Physical Memory | 60,66% Memory free
6,20 Gb Paging File | 5,09 Gb Available in Paging File | 82,13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 151,64 Gb Total Space | 21,98 Gb Free Space | 14,49% Space Free | Partition Type: NTFS
Drive E: | 144,99 Gb Total Space | 45,68 Gb Free Space | 31,51% Space Free | Partition Type: NTFS

Computer Name: COMPUTADOR | User Name: coimbra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\coimbra\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programas\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Programas\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programas\DAZ 3D\Content Management Service\ContentManagementServer.exe ()
PRC - C:\Programas\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Programas\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programas\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Programas\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Programas\Toshiba\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - c:\Programas\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Programas\O2Micro Flash Memory Card Driver\o2flash.exe (O2Micro International)
PRC - C:\Programas\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Programas\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Programas\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\Programas\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Programas\WinRAR\RarExt.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Programas\Toshiba\PCDiag\NotifyPCD.dll ()
MOD - C:\Programas\Toshiba\FlashCards\TWarnMsg\TWarnMsg.dll ()
MOD - C:\Programas\Toshiba\FlashCards\BlackPng.dll ()
MOD - C:\Programas\Toshiba\TBS\NotifyTBS.dll ()
MOD - C:\Programas\Toshiba\TOSHIBA Assist\NotifyX.dll ()
MOD - C:\Programas\Toshiba\TOSHIBA Disc Creator\NotifyTDC.dll ()


========== Win32 Services (SafeList) ==========

SRV - (StarWindServiceAE) – File not found
SRV - (Automatic CDROM Monitor) – File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (sdCoreService) – C:\Programas\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Programas\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Programas\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (AdobeARMservice) – C:\Programas\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (odserv) – C:\Programas\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (DAZContentManagementService) – C:\Programas\DAZ 3D\Content Management Service\ContentManagementServer.exe ()
SRV - (fsssvc) – C:\Programas\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (ServiceLayer) – C:\Programas\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (SeaPort) – C:\Programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Programas\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (VMCService) – C:\Programas\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (TNaviSrv) – C:\Programas\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Programas\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) – C:\Programas\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (TosCoSrv) – C:\Programas\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:\Programas\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) – C:\Programas\Toshiba\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA Bluetooth Service) – c:\Programas\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (o2flash) – C:\Programas\O2Micro Flash Memory Card Driver\o2flash.exe (O2Micro International)
SRV - (SSScsiSV) – C:\Programas\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (SonicStage Back-End Service) – C:\Programas\Common Files\Sony Shared\AVLib\SsBeSvc.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Programas\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Programas\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Programas\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (ose) – C:\Programas\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (UleadBurningHelper) – C:\Programas\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (lxcj_device) – C:\Windows\System32\lxcjcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (ZTEusbser6k) – File not found
DRV - (ZTEusbnmea) – File not found
DRV - (ZTEusbmdm6k) – File not found
DRV - (zlportio) – C:\Program Files\UltraStar Deluxe\zlportio.sys File not found
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – File not found
DRV - (NwlnkFwd) – File not found
DRV - (NwlnkFlt) – File not found
DRV - (IpInIp) – File not found
DRV - (IntcHdmiAddService) Intel® – File not found
DRV - (igfx) – File not found
DRV - (catchme) – C:\Users\coimbra\AppData\Local\Temp\catchme.sys File not found
DRV - (ad06h4do) – File not found
DRV - (pctplfw) – C:\Windows\System32\drivers\pctplfw.sys (PC Tools)
DRV - (pctNdisLW) – C:\Windows\System32\drivers\pctNdisLW.sys (PC Tools)
DRV - (apf001) – C:\Windows\System32\apf001.sys ()
DRV - (pctplsg) – C:\Windows\System32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) – C:\Windows\System32\drivers\PCTSD.sys (PC Tools)
DRV - (pctBTFix) – C:\Windows\System32\drivers\pctBTFix.sys (PC Tools)
DRV - (pctgntdi) – C:\Windows\System32\drivers\pctgntdi.sys (PC Tools)
DRV - (TFSysMon) – C:\Windows\System32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\Windows\System32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\Windows\System32\drivers\TfNetMon.sys (PC Tools)
DRV - (pctEFA) – C:\Windows\System32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\Windows\System32\drivers\pctDS.sys (PC Tools)
DRV - (PCTCore) – C:\Windows\System32\drivers\PCTCore.sys (PC Tools)
DRV - (PCTAppEvent) – C:\Windows\System32\drivers\PCTAppEvent.sys (PC Tools)
DRV - (PCTBD) – C:\Windows\System32\drivers\PCTBD.sys (PC Tools)
DRV - (libusb0) – C:\Windows\System32\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV - (MotioninJoyXFilter) – C:\Windows\System32\drivers\MijXfilt.sys (MotioninJoy)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdnsu) – C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdnsuc) – C:\Windows\System32\drivers\nmwcdnsuc.sys (Nokia)
DRV - (Mkd2kfNt) – C:\Windows\System32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (Mkd2Nadr) – C:\Windows\System32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (sptd) – C:\Windows\System32\drivers\sptd.sys ()
DRV - (NETw5v32) Intel® – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (CnxtHdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (tos_sps32) – C:\Windows\System32\drivers\tos_sps32.sys (TOSHIBA Corporation)
DRV - (O2MDRDR) – C:\Windows\System32\drivers\o2media.sys (O2Micro )
DRV - (tosrfbd) – C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (Tosrfhid) – C:\Windows\System32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosrfbnp) – C:\Windows\System32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfcom) – C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (NETw4v32) Controlador do Adaptador da ligação WiFi sem fios Intel® – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (QIOMem) – C:\Windows\System32\drivers\QIOMem.sys (TOSHIBA)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (tosrfec) – C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (tosporte) – C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\Windows\System32\drivers\tosrfnds.sys (TOSHIBA Corporation.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
IE - HKLM\..\SearchScopes,DefaultScope = {98E36557-BAF2-43F5-AF12-E20791AC3A09}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=1&src;=sp&…q={searchTerms}
IE - HKLM\..\SearchScopes\{98E36557-BAF2-43F5-AF12-E20791AC3A09}: "URL" = http://www.google.pt/search?q={searchTerms…p;sourceid=ie7;

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.pt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://pt.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Programas\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=1&src;=sp&…q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Web Search"
FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Google.pt"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.pt/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: multilinks@plugin:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.4
FF - prefs.js..extensions.enabledItems: {9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}:3.0.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [removed]:1.3.4
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.1829
FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src;=sp&cf;=a6c18f78-08af-11e1-8b63-8ad0386e9ad0&q;="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\coimbra\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\coimbra\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\coimbra\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009-07-05 02:37:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2012-04-18 15:26:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-04-17 14:39:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-04-14 17:06:58 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Veoh Networks\VeohWebPlayer\FFVideoFinder [2009-06-21 18:30:16 | 000,000,000 | —D | M]

[2010-02-20 20:26:47 | 000,000,000 | —D | M] (No name found) – C:\Users\coimbra\AppData\Roaming\mozilla\Extensions
[2010-02-20 20:26:47 | 000,000,000 | —D | M] (No name found) – C:\Users\coimbra\AppData\Roaming\mozilla\Extensions\[removed]
[2012-04-17 14:39:48 | 000,000,000 | —D | M] (No name found) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions
[2010-04-07 21:35:13 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010-03-14 22:44:46 | 000,000,000 | —D | M] (CookieSafe) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}
[2012-04-17 14:39:48 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012-03-08 00:14:17 | 000,000,000 | —D | M] (Corretor para Português de Portugal) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\[removed]
[2010-11-04 23:16:34 | 000,001,927 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\encyclopedia-search.xml
[2010-11-04 23:13:46 | 000,005,419 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\googlept.xml
[2011-07-11 19:04:02 | 000,000,633 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\startsear.xml
[2010-11-04 23:09:50 | 000,004,140 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\youtube.xml
[2012-04-17 14:39:37 | 000,000,000 | —D | M] (No name found) – C:\Programas\Mozilla Firefox\extensions
() (No name found) – C:\USERS\COIMBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\85ZY9BWZ.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\USERS\COIMBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\85ZY9BWZ.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\COIMBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\85ZY9BWZ.DEFAULT\EXTENSIONS\[removed]
[2012-03-13 05:38:06 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012-02-16 04:26:37 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009-09-21 02:11:17 | 000,072,960 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2011-10-03 10:14:54 | 000,083,456 | —- | M] (vShare.tv ) – C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2011-03-22 19:38:12 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012-03-13 06:51:17 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012-03-13 06:51:17 | 000,001,529 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\priberam.xml
[2012-03-13 06:51:17 | 000,002,071 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\sapo.xml
[2012-03-13 06:51:17 | 000,000,942 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-ptpt.xml

========== Chrome ==========

CHR - default_search_provider: Google (Predefini\u00E7\u00E3o) (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npvsharetvplg.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\coimbra\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: FB Chat Sidebar Disabler = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\beeidigicffecnkbanlfnmaplmkafdje\2.4.8_0\
CHR - Extension: YouTube = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus (Beta) = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Pesquisa do Google = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: SmallringFX DarkBlue Theme = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfijmgohofmpjlcgmjplbpmkpchdhpk\1.7_0\
CHR - Extension: Linkclump = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfpjkncokllnfokkgpkobnkbkmelfefj\2.0.17_0\
CHR - Extension: Gmail = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2006-09-18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Programas\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Programas\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O2 - BHO: (Programa Auxiliar de Início de Sessão do Windows Live ID) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programas\Free Download Manager\iefdm2.dll ()
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programas\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Programas\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
O4 - HKLM..\Run: [00TCrdMain] C:\Programas\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HSON] C:\Programas\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [LXCJCATS] C:\Windows\System32\spool\DRIVERS\W32X86\3\LXCJtime.DLL ()
O4 - HKLM..\Run: [SmoothView] C:\Programas\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Programas\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - Startup: C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\coimbra\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O8 - Extra context menu item: Transferência seleccionada pelo FDM - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Transferir com FDM - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Transferir todos com FDM - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Transferir vídeo com FDM - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O9 - Extra Button: Publicar em Blogue - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Publicar; no Blogue no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar; para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programas\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} http://messenger.zone.msn.com/MessengerGam…S.cab109791.cab ()
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…yri_4.3.1.0.cab (SysInfo Class)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A4C3FC56-EE04-4EE7-82B7-3BF50C28986C}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programas\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programas\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programas\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSTEM32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - File not found
O24 - Desktop WallPaper: C:\Users\coimbra\Pictures\Wallpapers\[animepaper.net]wallpaper-art-artists-sena-way-out-of-here-226993-fnatt-1280x800-b369d999.jpg
O24 - Desktop BackupWallPaper: C:\Users\coimbra\Pictures\Wallpapers\[animepaper.net]wallpaper-art-artists-sena-way-out-of-here-226993-fnatt-1280x800-b369d999.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0050a06f-ea7e-11de-bfe8-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{0050a06f-ea7e-11de-bfe8-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0050a070-ea7e-11de-bfe8-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{0050a070-ea7e-11de-bfe8-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{047897fb-7809-11e1-9904-8b027e70d36c}\Shell - "" = AutoRun
O33 - MountPoints2\{047897fb-7809-11e1-9904-8b027e70d36c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{04789804-7809-11e1-9904-8b027e70d36c}\Shell - "" = AutoRun
O33 - MountPoints2\{04789804-7809-11e1-9904-8b027e70d36c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{0ba442ef-7dc7-11dd-a121-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{0ba442ef-7dc7-11dd-a121-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{0ba442f6-7dc7-11dd-a121-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{0ba442f6-7dc7-11dd-a121-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{22acd90c-b9b7-11de-b592-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{22acd90c-b9b7-11de-b592-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{22acd924-b9b7-11de-b592-00037a8a3848}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Fixer32.exe
O33 - MountPoints2\{22acd924-b9b7-11de-b592-00037a8a3848}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Fixer32.exe
O33 - MountPoints2\{3c652fab-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{3c652fab-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{3c652fb6-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{3c652fb6-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{3c652fb8-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{3c652fb8-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{3c652fba-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{3c652fba-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{4a8cd8b0-c3c4-11de-be15-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{4a8cd8b0-c3c4-11de-be15-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{52c82829-7735-11df-80ad-efd5b989612a}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\kazEwAShI.eXE
O33 - MountPoints2\{580a38a1-7b99-11dd-91ed-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{580a38a1-7b99-11dd-91ed-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{633cc66b-6c61-11e1-9284-c9f1be4eb307}\Shell - "" = AutoRun
O33 - MountPoints2\{633cc66b-6c61-11e1-9284-c9f1be4eb307}\Shell\AutoRun\command - "" = G:\setup.exe AUTORUN=1
O33 - MountPoints2\{63be626d-dabe-11de-baec-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{63be626d-dabe-11de-baec-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{63faee14-bc2e-11de-a49c-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{63faee14-bc2e-11de-a49c-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell\AutoRun\command - "" = D:\autorun.exe
O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell\setup\command - "" = D:\setup.exe
O33 - MountPoints2\{6865071c-b74f-11de-9b69-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{6865071c-b74f-11de-9b69-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{736d7796-be78-11de-95f3-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{736d7796-be78-11de-95f3-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{73b9bb8b-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{73b9bb8b-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{73b9bba8-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{73b9bba8-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{73b9bbab-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{73b9bbab-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{7b1ee4a3-7ad4-11dd-b6d1-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{7b1ee4a3-7ad4-11dd-b6d1-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{7b1ee4a9-7ad4-11dd-b6d1-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{7b1ee4a9-7ad4-11dd-b6d1-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{8e051f9c-e902-11de-a649-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{8e051f9c-e902-11de-a649-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{956ec7de-0cbf-11df-ba60-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{956ec7de-0cbf-11df-ba60-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ad1a8282-8733-11dd-b4ea-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{ad1a8282-8733-11dd-b4ea-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{ae9e76a9-bda4-11de-bae2-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{ae9e76a9-bda4-11de-bae2-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ae9e76c2-bda4-11de-bae2-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{ae9e76c2-bda4-11de-bae2-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b2187d5e-ddac-11de-af9d-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{b2187d5e-ddac-11de-af9d-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b4b72941-8654-11dd-b3e1-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{b4b72941-8654-11dd-b3e1-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{c032af19-b710-11de-ae35-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{c032af19-b710-11de-ae35-00037a8a3848}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{c756d7f2-a48b-11de-be0b-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{c756d7f2-a48b-11de-be0b-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{da664491-1e76-11e0-9edc-ac4d52f2073d}\Shell - "" = AutoRun
O33 - MountPoints2\{da664491-1e76-11e0-9edc-ac4d52f2073d}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\{e7849982-7da1-11dd-9ff8-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{e7849982-7da1-11dd-9ff8-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\{e7849985-7da1-11dd-9ff8-001e687cfad6}\Shell - "" = AutoRun
O33 - MountPoints2\{e7849985-7da1-11dd-9ff8-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{e92b0683-e41e-11de-81cc-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{e92b0683-e41e-11de-81cc-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{eb03467f-24b6-11df-ab77-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{eb03467f-24b6-11df-ab77-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{eb0346a2-24b6-11df-ab77-00037a8a3848}\Shell - "" = AutoRun
O33 - MountPoints2\{eb0346a2-24b6-11df-ab77-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{f4f40baf-2b7e-11df-9201-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f4f40baf-2b7e-11df-9201-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk /r \??\E:)
O34 - HKLM BootExecute: (autocheck autochk /r \??\C:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012-04-23 20:02:17 | 000,594,944 | —- | C] (OldTimer Tools) – C:\Users\coimbra\Desktop\OTL.exe
[2012-04-23 19:45:20 | 000,000,000 | —D | C] – C:\ComboFix
[2012-04-23 00:38:30 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012-04-23 00:38:30 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012-04-23 00:38:30 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012-04-23 00:38:19 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012-04-23 00:38:14 | 000,000,000 | —D | C] – C:\Qoobox
[2012-04-22 20:40:25 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2012-04-22 20:38:50 | 004,472,002 | R— | C] (Swearware) – C:\Users\coimbra\Desktop\ComboFix.exe
[2012-04-22 20:36:01 | 000,000,000 | R–D | C] – C:\Users\coimbra\Dropbox
[2012-04-22 20:33:49 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012-04-22 20:32:57 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Dropbox
[2012-04-22 16:42:07 | 002,072,624 | —- | C] (Kaspersky Lab ZAO) – C:\Users\coimbra\Desktop\tdsskiller.exe
[2012-04-22 15:05:50 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\coimbra\Desktop\aswMBR.exe
[2012-04-22 15:04:39 | 000,607,260 | R— | C] (Swearware) – C:\Users\coimbra\Desktop\dds.com
[2012-04-21 20:45:55 | 000,000,000 | —D | C] – C:\sh4ldr
[2012-04-21 20:45:55 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012-04-21 20:27:30 | 000,000,000 | —D | C] – C:\Program Files\ExpressFiles
[2012-04-21 20:07:55 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\SpeedyPC Software
[2012-04-21 20:07:55 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\DriverCure
[2012-04-21 20:07:49 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012-04-20 04:21:19 | 000,000,000 | -HSD | C] – C:\found.002
[2012-04-19 23:17:25 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012-04-19 00:17:29 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\PCTools
[2012-04-18 15:44:02 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\PC Tools
[2012-04-18 15:44:01 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Spam Monitor
[2012-04-18 15:38:11 | 000,574,424 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys
[2012-04-18 15:38:11 | 000,054,328 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2012-04-18 15:38:11 | 000,035,264 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2012-04-18 15:33:33 | 000,125,888 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2012-04-18 15:33:30 | 000,091,136 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2012-04-18 15:33:30 | 000,058,400 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdisLW.sys
[2012-04-18 15:33:30 | 000,032,936 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2012-04-18 15:26:32 | 000,056,840 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTBD.sys
[2012-04-18 15:26:31 | 002,250,704 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll
[2012-04-18 15:26:31 | 000,149,456 | —- | C] (PC Tools) – C:\Windows\SGDetectionTool.dll
[2012-04-18 15:26:30 | 001,681,360 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDRes.dll
[2012-04-18 15:24:12 | 000,909,728 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctEFA.sys
[2012-04-18 15:24:12 | 000,342,168 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctDS.sys
[2012-04-18 15:24:10 | 000,253,352 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2012-04-18 15:24:10 | 000,107,864 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctwfpfilter.sys
[2012-04-18 15:24:04 | 000,331,880 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2012-04-18 15:24:04 | 000,162,584 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2012-04-18 15:24:01 | 000,185,560 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTSD.sys
[2012-04-18 15:24:01 | 000,017,848 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctBTFix.sys
[2012-04-18 15:24:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2012-04-18 15:23:56 | 000,070,536 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplsg.sys
[2012-04-18 15:23:45 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2012-04-18 15:23:45 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2012-04-18 15:23:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2012-04-17 18:42:50 | 000,418,464 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012-04-15 19:33:56 | 000,000,000 | —D | C] – C:\Users\coimbra\Documents\Cenas da mãe
[2012-04-12 18:24:23 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ragray
[2012-04-12 18:05:57 | 000,000,000 | —D | C] – C:\Program Files\Ragray
[2012-04-12 17:54:06 | 000,000,000 | —D | C] – C:\Program Files\1RO
[2012-04-11 10:56:20 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012-04-11 10:56:18 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012-04-11 10:56:17 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012-04-11 10:56:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012-04-11 10:56:16 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012-04-11 10:56:15 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012-04-11 10:53:47 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012-04-11 10:53:47 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012-04-02 19:39:33 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\LolClient
[2012-04-02 18:20:01 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_39.dll
[2012-04-02 18:20:01 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_39.dll
[2012-04-02 18:19:58 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_39.dll
[2012-04-02 18:09:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2012-04-02 16:38:32 | 000,000,000 | —D | C] – C:\Program Files\Pando Networks
[2012-03-30 00:59:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAZ Productions
[2012-03-30 00:58:58 | 000,090,112 | —- | C] (MindVision Software) – C:\Windows\unvise32.exe
[2012-03-27 14:26:53 | 000,000,000 | —D | C] – C:\ProgramData\Vodafone
[2012-03-27 14:26:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vodafone
[2012-03-27 14:26:42 | 000,000,000 | —D | C] – C:\Program Files\Vodafone
[2012-03-27 14:25:32 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Local\{D53238E8-3427-491E-A57E-097FA966AAC1}
[2012-03-26 17:40:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
[2012-03-26 17:40:18 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2012-03-26 17:39:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Canon
[2012-03-25 04:22:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DAZ
[2012-03-25 04:18:44 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D
[2012-03-25 04:18:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAZ 3D
[2012-03-25 04:18:16 | 000,000,000 | —D | C] – C:\ProgramData\DAZ 3D
[2012-03-25 04:17:32 | 000,000,000 | —D | C] – C:\Users\coimbra\Documents\DAZ 3D
[2012-03-25 04:16:17 | 000,000,000 | —D | C] – C:\Program Files\DAZ 3D
[2012-03-25 04:14:19 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\DAZ 3D
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012-04-23 20:07:16 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-04-23 20:02:23 | 000,044,544 | —- | M] (Absolute Software Corp.) – C:\Windows\System32\agremove.exe
[2012-04-23 20:02:12 | 000,594,944 | —- | M] (OldTimer Tools) – C:\Users\coimbra\Desktop\OTL.exe
[2012-04-23 19:58:42 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012-04-23 19:58:42 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012-04-23 19:58:12 | 000,000,998 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-04-23 19:56:45 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012-04-23 19:56:30 | 3219,578,880 | -HS- | M] () – C:\hiberfil.sys
[2012-04-23 19:33:17 | 000,001,002 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-04-23 19:33:16 | 000,001,030 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2519787931-4213243981-2891937994-1000UA.job
[2012-04-23 00:37:31 | 004,472,002 | R— | M] (Swearware) – C:\Users\coimbra\Desktop\ComboFix.exe
[2012-04-22 21:14:05 | 002,402,047 | —- | M] () – C:\Windows\System32\drivers\Cat.DB
[2012-04-22 20:36:01 | 000,000,987 | —- | M] () – C:\Users\coimbra\Desktop\Dropbox.lnk
[2012-04-22 20:34:11 | 000,000,967 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012-04-22 20:04:08 | 000,222,625 | —- | M] () – C:\Users\coimbra\Documents\marcadores_22_04_12.html
[2012-04-22 16:42:06 | 002,072,624 | —- | M] (Kaspersky Lab ZAO) – C:\Users\coimbra\Desktop\tdsskiller.exe
[2012-04-22 16:06:00 | 000,000,512 | —- | M] () – C:\Users\coimbra\Documents\MBR.dat
[2012-04-22 15:05:56 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\coimbra\Desktop\aswMBR.exe
[2012-04-22 15:04:35 | 000,607,260 | R— | M] (Swearware) – C:\Users\coimbra\Desktop\dds.com
[2012-04-22 01:55:00 | 000,000,978 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2519787931-4213243981-2891937994-1000Core.job
[2012-04-21 22:07:09 | 000,002,527 | —- | M] () – C:\Users\coimbra\Desktop\HiJackThis.lnk
[2012-04-21 00:10:45 | 000,662,798 | —- | M] () – C:\Windows\System32\prfh0816.dat
[2012-04-21 00:10:45 | 000,598,900 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012-04-21 00:10:45 | 000,131,986 | —- | M] () – C:\Windows\System32\prfc0816.dat
[2012-04-21 00:10:45 | 000,104,914 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012-04-19 02:26:15 | 000,303,902 | —- | M] () – C:\Users\coimbra\Documents\Formulário.pdf
[2012-04-18 17:21:28 | 000,000,000 | —- | M] () – C:\Windows\System32\SM.lock
[2012-04-18 15:33:33 | 000,125,888 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2012-04-18 15:33:30 | 000,091,136 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2012-04-18 15:33:30 | 000,058,400 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdisLW.sys
[2012-04-18 15:33:30 | 000,032,936 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2012-04-18 15:32:24 | 000,001,817 | —- | M] () – C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2012-04-17 19:07:30 | 000,418,464 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012-04-17 19:07:30 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012-04-17 14:39:41 | 000,000,875 | —- | M] () – C:\Users\coimbra\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012-04-17 14:39:40 | 000,000,851 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012-04-14 19:57:43 | 000,002,019 | —- | M] () – C:\Users\coimbra\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012-04-14 19:57:42 | 000,002,057 | —- | M] () – C:\Users\coimbra\Desktop\Google Chrome.lnk
[2012-04-11 10:24:12 | 000,001,356 | —- | M] () – C:\Users\coimbra\AppData\Local\d3d9caps.dat
[2012-04-07 23:14:44 | 000,024,064 | —- | M] () – C:\Users\coimbra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-04-06 20:41:05 | 000,054,338 | —- | M] () – C:\Users\coimbra\Documents\Guião Trabalho de Grupo TOIV.pdf
[2012-04-04 02:04:49 | 000,000,718 | —- | M] () – C:\Users\coimbra\Desktop\Play League of Legends.lnk
[2012-04-02 00:46:34 | 000,000,809 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012-03-27 16:40:34 | 000,075,757 | —- | M] () – C:\Users\coimbra\Documents\Trabalho Prático 3.pdf
[2012-03-26 18:23:01 | 000,554,858 | —- | M] () – C:\Users\coimbra\Documents\Documentos ENETO.pdf
[2012-03-25 04:18:45 | 000,001,849 | —- | M] () – C:\Users\coimbra\Desktop\DAZ Studio 4.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-04-23 19:48:39 | 3219,578,880 | -HS- | C] () – C:\hiberfil.sys
[2012-04-23 00:38:30 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012-04-23 00:38:30 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012-04-23 00:38:30 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012-04-23 00:38:30 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012-04-23 00:38:30 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012-04-22 20:36:01 | 000,000,987 | —- | C] () – C:\Users\coimbra\Desktop\Dropbox.lnk
[2012-04-22 20:34:11 | 000,000,967 | —- | C] () – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012-04-22 20:04:07 | 000,222,625 | —- | C] () – C:\Users\coimbra\Documents\marcadores_22_04_12.html
[2012-04-22 16:06:00 | 000,000,512 | —- | C] () – C:\Users\coimbra\Documents\MBR.dat
[2012-04-19 02:13:00 | 000,303,902 | —- | C] () – C:\Users\coimbra\Documents\Formulário.pdf
[2012-04-18 17:21:28 | 000,000,000 | —- | C] () – C:\Windows\System32\SM.lock
[2012-04-18 15:32:24 | 000,001,817 | —- | C] () – C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2012-04-18 15:26:32 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll
[2012-04-18 15:26:31 | 000,003,488 | —- | C] () – C:\Windows\UDB.zip
[2012-04-18 15:26:31 | 000,000,882 | —- | C] () – C:\Windows\RegSDImport.xml
[2012-04-18 15:26:31 | 000,000,879 | —- | C] () – C:\Windows\RegISSImport.xml
[2012-04-18 15:26:31 | 000,000,131 | —- | C] () – C:\Windows\IDB.zip
[2012-04-18 15:24:13 | 002,402,047 | —- | C] () – C:\Windows\System32\drivers\Cat.DB
[2012-04-17 18:42:51 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-04-06 20:41:01 | 000,054,338 | —- | C] () – C:\Users\coimbra\Documents\Guião Trabalho de Grupo TOIV.pdf
[2012-04-04 02:04:49 | 000,000,718 | —- | C] () – C:\Users\coimbra\Desktop\Play League of Legends.lnk
[2012-03-27 16:39:19 | 000,075,757 | —- | C] () – C:\Users\coimbra\Documents\Trabalho Prático 3.pdf
[2012-03-26 18:17:02 | 000,554,858 | —- | C] () – C:\Users\coimbra\Documents\Documentos ENETO.pdf
[2012-03-25 04:18:45 | 000,001,849 | —- | C] () – C:\Users\coimbra\Desktop\DAZ Studio 4.lnk
[2012-03-12 03:09:33 | 000,012,920 | —- | C] () – C:\Windows\System32\apl001.sys
[2012-03-12 03:09:33 | 000,010,872 | —- | C] () – C:\Windows\System32\apf001.sys
[2011-08-09 20:44:41 | 000,000,056 | —- | C] () – C:\Windows\wininit.ini
[2011-07-08 16:52:55 | 000,175,616 | —- | C] () – C:\Windows\System32\unrar.dll
[2011-06-19 18:04:33 | 000,532,480 | —- | C] () – C:\Windows\System32\CddbPlaylist2Sony.dll
[2011-04-17 21:57:44 | 000,000,496 | —- | C] () – C:\Windows\System32\lxcjplc.ini
[2010-12-21 00:06:58 | 000,000,136 | —- | C] () – C:\Windows\System32\winsusrm.dll
[2010-12-21 00:06:09 | 000,000,120 | —- | C] () – C:\Windows\System32\winsusrx.dll

========== LOP Check ==========

[2011-01-12 15:09:58 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Aegisub
[2011-01-07 12:40:26 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Aunsoft
[2011-02-13 05:24:41 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\AVG
[2010-01-27 03:38:03 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Azureus
[2011-01-10 16:20:14 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\BadApple!!
[2011-11-15 03:20:50 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Canneverbe Limited
[2009-05-01 02:24:45 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\DAEMON Tools
[2012-04-17 18:55:44 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\DAEMON Tools Lite
[2012-03-25 06:14:58 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\DAZ 3D
[2010-04-10 19:25:23 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Downloaded Installations
[2012-04-21 20:07:55 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\DriverCure
[2012-04-23 19:58:42 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Dropbox
[2010-06-17 14:35:40 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Facebook
[2010-01-24 20:24:23 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\fltk.org
[2009-04-10 18:11:59 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Foxit
[2009-10-12 11:18:56 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Foxit Software
[2012-04-21 20:48:41 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Free Download Manager
[2009-05-02 21:09:58 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\fretsonfire
[2011-06-10 23:09:05 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\GetRightToGo
[2011-10-27 12:12:06 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Leawo
[2010-07-10 22:01:56 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\LimeWire
[2012-04-02 19:39:33 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\LolClient
[2009-07-01 01:07:31 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Nokia
[2009-07-01 00:29:45 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\PC Suite
[2012-04-19 00:17:29 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\PCTools
[2010-02-03 17:03:03 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\PeerNetworking
[2012-03-24 07:03:57 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Poser
[2009-12-09 22:29:07 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\PrimoPDF
[2011-02-08 21:06:11 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Publish Providers
[2010-12-12 00:00:48 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Sony
[2011-02-08 20:04:36 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Sony Creative Software
[2012-04-18 15:44:01 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Spam Monitor
[2012-04-21 20:07:55 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\SpeedyPC Software
[2009-03-22 01:40:17 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\SYSTEMAX Software Development
[2011-12-07 03:56:14 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\SystemRequirementsLab
[2012-04-22 20:20:56 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\TOSHIBA
[2012-04-18 15:24:12 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\uTorrent
[2008-09-04 23:59:02 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Vodafone
[2011-10-27 12:04:58 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\Xilisoft
[2012-04-23 19:36:20 | 000,032,600 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:888AFB86

< End of report >

Extras.txt

OTL Extras logfile created on: 23-04-2012 20:05:55 - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = C:\Users\coimbra\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy

3,00 Gb Total Physical Memory | 1,82 Gb Available Physical Memory | 60,66% Memory free
6,20 Gb Paging File | 5,09 Gb Available in Paging File | 82,13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 151,64 Gb Total Space | 21,98 Gb Free Space | 14,49% Space Free | Partition Type: NTFS
Drive E: | 144,99 Gb Total Space | 45,68 Gb Free Space | 31,51% Space Free | Partition Type: NTFS

Computer Name: COMPUTADOR | User Name: coimbra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00A8CF55-FF0B-4693-905D-9BCF548B9050}" = lport=138 | protocol=17 | dir=in | app=system |
"{1F7A589B-512C-4EE6-AB0E-C70A4E6FF5A8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{30F1F62F-B950-421B-B871-93C1D7457837}" = rport=445 | protocol=6 | dir=out | app=system |
"{56B3D76F-6B81-4B5C-BA10-8C198F1B5679}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6191AF5E-F098-4611-9FAC-8AF00C99E441}" = rport=137 | protocol=17 | dir=out | app=system |
"{6541933E-7945-41A4-8F8C-25235D115F20}" = rport=139 | protocol=6 | dir=out | app=system |
"{74C23442-2FAF-4A88-849A-135E0BF73944}" = lport=139 | protocol=6 | dir=in | app=system |
"{842D7319-0A88-40F4-9754-B19ADDFD46BB}" = rport=138 | protocol=17 | dir=out | app=system |
"{A23FE6FF-175D-4AFB-9B68-B923236C8986}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{ACF90FE1-0EA8-4CE0-BBEF-81AB1A0B986A}" = lport=137 | protocol=17 | dir=in | app=system |
"{B30F85E3-474E-4D4B-ADF7-567C55B179D3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F4BDA566-45ED-4B4A-A1D0-854D626F38E1}" = lport=445 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04B659DA-1BA4-4FCD-B041-F0481848F271}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{15C26647-661F-4CE4-9397-0FCADEFDF8DF}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{15D895D4-9471-434F-8AEB-2A11D3D800F3}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{1C4E735A-AA72-4E76-823B-2728220EE5A1}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{1FBAFADC-3800-4368-BEF7-F63FDFF98CF7}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{2159F005-CA2A-440B-9902-07C0F93D7CEC}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{2ACE4A16-2E90-4A55-8D82-EF271A10F9E1}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{2D563A6F-2D3E-4AB9-9182-1FDCC52F62F7}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
"{2F61CF34-C7CC-4741-A9A7-81792D0860EF}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3054DFF0-EE34-486D-8D38-9599236257A4}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{3153A9CC-E5DE-437A-8515-19EB3F8567E5}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
"{34D792FF-50B5-4110-B8D7-5D2BB3E50887}" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3y.exe |
"{46D3707D-8C17-4425-9666-DE29A88E5412}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
"{49DC2A34-10C8-4788-84D3-8254E7FD9D99}" = protocol=6 | dir=in | app=c:\users\coimbra\appdata\roaming\dropbox\bin\dropbox.exe |
"{543CCD9B-7527-4EE0-A945-61B0165B0E43}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
"{69B93AFE-69B7-45CE-881C-8AC3B3E15BED}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6AB39284-B46F-454E-81F7-57EB89DC9CBD}" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"{7213BFEE-C89B-41D8-A4BC-26A4C56C8F4F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{7756D0ED-F6EC-408F-8C40-9F63FAFA04EF}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{7B770FD1-B11D-401B-A7CC-13BCC2FF85F2}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{8D613B80-8697-42AC-8D26-36160AECCCA2}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
"{97D1A932-3232-454A-9D4E-9DCDBEC9FC32}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{B4260D3E-9E8D-476A-A345-9DF952C8515D}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{BB66FA76-FB5D-4497-8DEC-8F807C84AC90}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{BD452660-A3D6-4255-9050-CFF43343AB1F}" = protocol=17 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3.exe |
"{BDE77B38-6C99-4E8E-8F7E-DF98E2EB834E}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
"{C1188DB4-3CA9-4598-9D71-952B8EB02D87}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{C798D1D4-E3CF-43CA-A46E-20AB69D9B123}" = protocol=17 | dir=in | app=c:\users\coimbra\appdata\roaming\dropbox\bin\dropbox.exe |
"{DF9F2DBE-2DDB-42E0-A6DA-E03A7357F9BC}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{E08F5410-2CE3-4603-B224-A66950475F21}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{E32AE8C6-CC5D-48F9-BDDF-64D6448EA82F}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{E862A10F-94B2-40A3-B11C-CD59BE181AE5}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
"{EAC1638E-0222-460E-A1B2-0BBB8E2790D7}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{ED1814E6-E326-433D-888F-493EB95C5C41}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
"{EE4A744D-3855-4499-9615-3CA1D0957A24}" = protocol=6 | dir=in | app=c:\program files\microsoft games\age of empires iii\age3y.exe |
"{EEC53CB2-1BDC-47E8-97EC-0D7F39ACDD07}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{F05E0896-030B-4CEB-8AC2-7ABB7210F140}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"TCP Query User{14427A67-EBCD-4720-9842-CDCA114D4794}C:\program files\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files\winamp\winamp.exe |
"UDP Query User{71C6E3BA-1EE1-423C-9493-FBA920072577}C:\program files\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files\winamp\winamp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{024558D8-272F-C7C8-4F6D-6FE689B5DC52}" = Catalyst Control Center Localization Japanese
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{074C5857-D87B-4E1B-9977-FE623E4CBE88}" = Samsung PC Studio
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Assistente de Início de Sessão do Windows Live ID
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0C973594-7DDF-4BD0-84ED-3517F7622037}" = PC Connectivity Solution
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1A5A851C-B8B4-CD8E-920B-EE21B9E4FE31}" = Catalyst Control Center Graphics Full Existing
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{2290A680-4083-410A-ADCC-7092C67FC052}" = Toshiba Online Product Information
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2D7D6A0E-A6A7-1080-980C-67FB8E20D93D}" = ccc-utility
"{2F2C3691-E3CB-6066-514D-729BB881216D}" = CCC Help Dutch
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{372B31CF-77FB-4E29-860C-A0EA2985AB7F}" = O2Micro Flash Memory Card Reader Driver (x86)
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D39E775-DDDA-4327-B747-0BDC5F191331}" = Nokia PC Suite
"{3E1E4AB9-C017-746E-92E6-B30A0429E986}" = CCC Help Korean
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{43DCF766-6838-4F9A-8C91-D92DA586DFA8}" = Microsoft Windows Journal Viewer
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{491DD193-1B57-4D1C-8B14-18B96992A89F}" = TOSHIBA Supervisor Password
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A130340-74D9-27C0-0F3D-3F9A69CF938C}" = CCC Help French
"{4A944E94-F6E9-9D38-5C5B-B1E5597EB742}" = CCC Help Spanish
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{502DBACB-D72F-276E-9B51-1CC980633BDC}" = CCC Help German
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup 2011
"{50831C51-70E7-CF72-3B5E-53413B1598E9}" = Catalyst Control Center Localization Dutch
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{52573F8D-F099-4CB5-9EDE-5C27ECB4A02B}" = TOSHIBA Hardware Setup
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{56A29640-7334-2E21-8169-5F23EEEE4958}" = CCC Help Chinese Standard
"{5721A8EA-A30F-4F66-9046-3F40C43AE1DC}" = Driver Detective
"{587139F5-9B76-4D5A-94C6-76E6B219BF7F}" = Windows Live Sync
"{5980B928-1C95-4B3E-957B-B02D8147FF9E}" = Desktop SMS
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{60D7B2C5-5824-753E-D091-382D312C5590}" = Catalyst Control Center Localization French
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{6275D380-371D-6D6E-32AF-97009138EBE3}" = Skins
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{650E2ABD-270A-499C-BA9F-09180DDDDA16}" = Nokia Software Updater
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67905A54-F074-6F13-3C61-DA40552079BB}" = Catalyst Control Center Graphics Light
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6E4F5172-7A60-E18C-D1F2-C8D783197A7C}" = Catalyst Control Center Localization German
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75E9A522-65D2-4200-A95F-C3EF89703263}" = Lyrics Plugin for Winamp
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{7988ba74-4a27-4685-991a-53f072f22808}" = F2200_Help
"{7B1DBCBE-DF17-3B58-844C-F572F70EF5C4}" = Microsoft .NET Framework 3.5 Language Pack SP1 - ptg
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{7BA57438-E0E4-46D1-9161-480FFB76FB62}" = Windows Live Writer
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7FADEAAE-1AAD-2635-809E-C92477AF1794}" = Catalyst Control Center Localization Italian
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{80533B67-C407-485D-8B5D-63BB8ED9D878}" = Scan
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{88771941-E487-0F1C-7242-554D82BC8740}" = CCC Help Japanese
"{89DCBAD2-592B-A42C-18D7-78601056FBD9}" = Catalyst Control Center Localization Chinese Standard
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8D90017E-FFE1-3077-9113-F4002ED7EB13}" = Catalyst Control Center Localization Swedish
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90120000-0015-0816-0000-0000000FF1CE}" = Microsoft Office Access MUI (Portuguese (Portugal)) 2007
"{90120000-0015-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0816-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Portuguese (Portugal)) 2007
"{90120000-0016-0816-0000-0000000FF1CE}_HOMESTUDENTR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0816-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2007
"{90120000-0018-0816-0000-0000000FF1CE}_HOMESTUDENTR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0816-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Portuguese (Portugal)) 2007
"{90120000-0019-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0816-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Portuguese (Portugal)) 2007
"{90120000-001A-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0816-0000-0000000FF1CE}" = Microsoft Office Word MUI (Portuguese (Portugal)) 2007
"{90120000-001B-0816-0000-0000000FF1CE}_HOMESTUDENTR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0816-0000-0000000FF1CE}_PROR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0816-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Portugal)) 2007
"{90120000-001F-0816-0000-0000000FF1CE}_HOMESTUDENTR_{C8246FCF-12F8-4212-BC89-6ED049BA2FB8}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0816-0000-0000000FF1CE}_PROR_{C8246FCF-12F8-4212-BC89-6ED049BA2FB8}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0816-0000-0000000FF1CE}" = Microsoft Office Proofing (Portuguese (Portugal)) 2007
"{90120000-006E-0816-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Portuguese (Portugal)) 2007
"{90120000-006E-0816-0000-0000000FF1CE}_HOMESTUDENTR_{5E03E01D-304F-474D-B85F-06B2C9AE0583}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0816-0000-0000000FF1CE}_PROR_{5E03E01D-304F-474D-B85F-06B2C9AE0583}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0816-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Portuguese (Portugal)) 2007
"{90120000-00A1-0816-0000-0000000FF1CE}_HOMESTUDENTR_{F812A9CD-23C6-4BBC-B168-ED2C68B0F003}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AE196A8-A8DC-4287-BCBA-AF35C578FEA2}" = Manuais da TOSHIBA
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9DDABBD9-B4D1-F927-8970-03E7CF4605F1}" = Catalyst Control Center Localization Korean
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{9F67D8FC-2A5F-440E-855C-E26A7FE88D28}" = Windows Live Essentials
"{9FD7C77D-5657-49C1-8FB5-5C7BFCAFC6DB}" = Windows Live Call
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = Silenciador Acústico da Unidade de CD/DVD
"{A07EC392-26B6-E1AE-AFE8-A73F7BFC1C4C}" = CCC Help Chinese Traditional
"{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 4.3
"{A12F36B5-E11F-0128-7D8F-DEC927105BE2}" = CCC Help Swedish
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1046-7B44-AA1000000001}" = Adobe Reader X (10.1.3) - Português
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B158BAE0-C912-3697-256D-A9FCEDFAA536}" = Catalyst Control Center Localization Portuguese
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B4E343DD-BAAB-4D59-AD9C-DEA0AFE09DF1}" = Mumble 1.2.3
"{B5897EDD-E78B-067B-DB8F-D85E60B71967}" = Catalyst Control Center Localization Spanish
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{B785106B-C3EC-4999-8A89-A3B335559E82}_is1" = uv-RO 2011-06-03
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Os Sims™ 3
"{C13A8E73-7E98-4295-BA94-6931701CD1F9}" = Topaz Vivacity
"{C42601B6-CBA8-7879-D310-7B2E97215D82}" = CCC Help Italian
"{C43C1415-3DFC-4089-9A32-0BECF28A6046}" = Age of Empires III - The Asian Dynasties
"{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}" = Vodafone Mobile Connect Lite
"{c6922d7f-c698-4d9e-9671-8b3de04d1511}" = DJ_AIO_03_F2200_Software_Min
"{C6DCC59B-48D8-5092-2F69-8C423BFAB27F}" = Catalyst Control Center Graphics Previews Vista
"{C7128EEC-088D-051A-E8F9-DD4E6F2C3F3E}" = CCC Help Portuguese
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{C970757C-FD82-ED94-66C4-AF7C0266699E}" = ATI Catalyst Install Manager
"{CB22A47C-EFEA-2400-DB68-8F9B1D24BF43}" = Catalyst Control Center Graphics Full New
"{CC1D4F42-5F8B-4487-A35D-C994429EA8F1}" = Segurança Familiar do Windows Live
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE8B9F6B-7D9E-3C56-7B27-1E484CD41D78}" = ccc-core-static
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D00EAB9D-C698-D4F6-214F-6FFC496B7F71}" = Catalyst Control Center Core Implementation
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D16161BC-2A98-412C-902C-B063F6B9C566}_is1" = DarkSideRO version 1.2
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D305D4F8-0820-5DFA-F175-E7D06ED60364}" = CCC Help English
"{D58A1E94-9EEA-4C6E-B9FB-D7C63DC6C941}" = Catalyst Control Center - Branding
"{D77D43B5-ED55-426b-B67B-E21F804F6102}" = HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{DA909E62-3B45-4BA1-8B58-FCAEBA4BCEC9}" = NVIDIA PhysX
"{db18dc72-cd20-4801-be82-f5d2caeec4d7}" = DJ_AIO_03_F2200_Software
"{DC785DB7-D389-48C3-B146-96FE99BF4E2B}" = Vegas Pro 9.0
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5B86403-C054-400B-86F5-7F1D66FBDDC6}" = Windows Live Mail
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{e97a9fd7-2fa1-4474-820d-3f8893a5b78a}" = F2200
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{eca3039b-e429-420f-bd5e-7dec0683fc32}" = DJ_AIO_03_F2200_ProductContext
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F0AF91F4-D1ED-490E-8751-997AF2A3FF0D}_is1" = Leawo FLV Converter version 4.1.0.1
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1FDAA01-988C-423F-AC12-0D8F333943FD}" = Nokia Connectivity Cable Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy
"{F855451C-21E2-3034-B042-E1E66923548A}" = Microsoft .NET Framework 4 Client Profile PTG Language Pack
"{FD702B54-2FD4-459B-97F3-977BDF2C3C5C}" = Windows Live Messenger
"{FEBF75B0-9D67-6178-8737-92A81B3FEA47}" = Catalyst Control Center Localization Chinese Traditional
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"0C5EDC3653FED5B121F464339EAC12534D253B25" = Pacote de controladores do Windows - Nokia Modem (02/15/2007 3.1)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"B726756F5B5A5AA9D798B399386FC6205A45F19E" = Pacote de controladores do Windows - Nokia Modem (02/15/2007 3.1)
"Browser Defender_is1" = Browser Defender 4.0
"Canon RAW Codec" = Canon RAW Codec
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_5051&SUBSYS;_1179" = HDAUDIO Soft Data Fax Modem with SmartCP
"DAZ Content Management Service [removed]" = DAZ Content Management Service
"DAZ Studio 4 [removed]" = DAZ Studio 4
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = Instalação do DivX
"DS4 Default Content [removed]" = DS4 Default Content
"EvilLyrics" = EvilLyrics
"Foxit PDF Creator" = Foxit PDF Creator
"Foxit PDF Editor" = Foxit PDF Editor
"Foxit Reader" = Foxit Reader
"Free Download Manager_is1" = Free Download Manager 3.0
"Hexagon 2 2.5.1.79" = Hexagon 2
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"InstallShield_{491DD193-1B57-4D1C-8B14-18B96992A89F}" = TOSHIBA Supervisor Password
"InstallShield_{52573F8D-F099-4CB5-9EDE-5C27ECB4A02B}" = TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TRDCReminder
"InstallShield_{C43C1415-3DFC-4089-9A32-0BECF28A6046}" = Age of Empires III - The Asian Dynasties
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}" = TRORDCLauncher
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"KLiteCodecPack_is1" = K-Lite Codec Pack 8.4.0 (Full)
"LastFM_is1" = Last.fm 1.5.4.27091
"Lexmark 8300 Series" = Lexmark 8300 Series
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 3.5 Language Pack SP1 - ptg" = Microsoft .NET Framework 3.5 Language Pack SP1 - PTG
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile PTG Language Pack" = Microsoft .NET Framework 4 Client Profile PTG Language Pack
"mIRC" = mIRC
"Mozilla Firefox 11.0 (x86 pt-PT)" = Mozilla Firefox 11.0 (x86 pt-PT)
"Nokia PC Suite" = Nokia PC Suite
"PaintToolSAI" = PaintTool SAI Ver.1
"pcsx2-r3878" = PCSX2 - Playstation 2 Emulator
"PROR" = Versão de Avaliação do Microsoft Office Professional 2007
"Rise of Dragonian Era" = Rise of Dragonian Era
"Shop for HP Supplies" = Shop for HP Supplies
"SopCast" = SopCast 3.3.2
"Spyware Doctor" = PC Tools Internet Security
"StepMania" = StepMania (remove only)
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"UT2004-Demo" = Unreal Tournament 2004 Demo
"uTorrent" = µTorrent
"Veetle TV" = Veetle TV 0.9.18
"Veoh Web Player Beta" = Veoh Web Player
"vShare.tv plugin" = vShare.tv plugin 1.3
"Vuze" = Vuze
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Compressor WinRAR

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"CrystalRO" = CrystalRO
"Dropbox" = Dropbox
"Facebook Plug-In" = Facebook Plug-In
"Google Chrome" = Google Chrome
"NCsoft-Lineage2" = Lineage II
"Winamp Detect" = Winamp Detectar Aplicação

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 22-04-2012 09:53:30 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 22-04-2012 16:14:30 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 22-04-2012 16:20:54 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 22-04-2012 20:32:04 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 22-04-2012 20:37:49 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 23-04-2012 04:30:35 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 23-04-2012 14:38:21 | Computer Name = Computador | Source = EventSystem | ID = 4609
Description =

Error - 23-04-2012 14:43:57 | Computer Name = Computador | Source = EventSystem | ID = 4609
Description =

Error - 23-04-2012 14:48:52 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

Error - 23-04-2012 14:58:03 | Computer Name = Computador | Source = VMCService | ID = 0
Description = conflictManagerTypeValue

[ OSession Events ]
Error - 11-07-2011 10:47:46 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.

Error - 11-07-2011 10:47:52 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.

Error - 11-07-2011 10:47:56 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.

Error - 11-07-2011 10:48:11 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.

Error - 26-07-2011 10:54:57 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.

Error - 26-07-2011 12:59:11 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1
seconds with 0 seconds of active time. This session ended with a crash.

Error - 29-07-2011 11:57:49 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 8
seconds with 0 seconds of active time. This session ended with a crash.

Error - 19-10-2011 10:25:48 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6565.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.

Error - 23-11-2011 21:30:58 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 22
seconds with 0 seconds of active time. This session ended with a crash.

Error - 06-12-2011 23:24:43 | Computer Name = Computador | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 23-04-2012 14:44:39 | Computer Name = Computador | Source = Service Control Manager | ID = 7001
Description =

Error - 23-04-2012 14:49:02 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =

Error - 23-04-2012 14:49:02 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =

Error - 23-04-2012 14:49:02 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =

Error - 23-04-2012 14:50:20 | Computer Name = Computador | Source = Service Control Manager | ID = 7022
Description =

Error - 23-04-2012 14:56:52 | Computer Name = Computador | Source = EventLog | ID = 6008
Description = O anterior encerramento do sistema, 23-04-2012 às 19:51:33, foi inesperado.

Error - 23-04-2012 14:58:10 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =

Error - 23-04-2012 14:58:10 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =

Error - 23-04-2012 14:58:10 | Computer Name = Computador | Source = Service Control Manager | ID = 7000
Description =

Error - 23-04-2012 15:00:15 | Computer Name = Computador | Source = Service Control Manager | ID = 7022
Description =


< End of report >
Hi,

Please download ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
    IE - HKLM\..\SearchScopes,DefaultScope = {98E36557-BAF2-43F5-AF12-E20791AC3A09}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=1&src=sp&…q={searchTerms}
    IE - HKLM\..\SearchScopes\{98E36557-BAF2-43F5-AF12-E20791AC3A09}: "URL" = http://www.google.pt/search?q={searchTerms…p;sourceid=ie7;
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.pt
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://pt.msn.com/?ocid=iehp
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt
    IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=1&src=sp&…q={searchTerms}
    FF - prefs.js..browser.search.defaultengine: "Web Search"
    FF - prefs.js..browser.search.defaultenginename: "Web Search"
    FF - prefs.js..browser.search.order.1: "Web Search"
    FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src=sp&cf=a6c18f78-08af-11e1-8b63-8ad0386e9ad0&q="
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
    O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
    O33 - MountPoints2\{0050a06f-ea7e-11de-bfe8-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{0050a06f-ea7e-11de-bfe8-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{0050a070-ea7e-11de-bfe8-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{0050a070-ea7e-11de-bfe8-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{047897fb-7809-11e1-9904-8b027e70d36c}\Shell - "" = AutoRun
    O33 - MountPoints2\{047897fb-7809-11e1-9904-8b027e70d36c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{04789804-7809-11e1-9904-8b027e70d36c}\Shell - "" = AutoRun
    O33 - MountPoints2\{04789804-7809-11e1-9904-8b027e70d36c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{0ba442ef-7dc7-11dd-a121-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{0ba442ef-7dc7-11dd-a121-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{0ba442f6-7dc7-11dd-a121-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{0ba442f6-7dc7-11dd-a121-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{22acd90c-b9b7-11de-b592-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{22acd90c-b9b7-11de-b592-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{22acd924-b9b7-11de-b592-00037a8a3848}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Fixer32.exe
    O33 - MountPoints2\{22acd924-b9b7-11de-b592-00037a8a3848}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Fixer32.exe
    O33 - MountPoints2\{3c652fab-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{3c652fab-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{3c652fb6-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{3c652fb6-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{3c652fb8-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{3c652fb8-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{3c652fba-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{3c652fba-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{4a8cd8b0-c3c4-11de-be15-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{4a8cd8b0-c3c4-11de-be15-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{52c82829-7735-11df-80ad-efd5b989612a}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\kazEwAShI.eXE
    O33 - MountPoints2\{580a38a1-7b99-11dd-91ed-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{580a38a1-7b99-11dd-91ed-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{633cc66b-6c61-11e1-9284-c9f1be4eb307}\Shell - "" = AutoRun
    O33 - MountPoints2\{633cc66b-6c61-11e1-9284-c9f1be4eb307}\Shell\AutoRun\command - "" = G:\setup.exe AUTORUN=1
    O33 - MountPoints2\{63be626d-dabe-11de-baec-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{63be626d-dabe-11de-baec-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{63faee14-bc2e-11de-a49c-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{63faee14-bc2e-11de-a49c-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell\AutoRun\command - "" = D:\autorun.exe
    O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell\setup\command - "" = D:\setup.exe
    O33 - MountPoints2\{6865071c-b74f-11de-9b69-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{6865071c-b74f-11de-9b69-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{736d7796-be78-11de-95f3-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{736d7796-be78-11de-95f3-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{73b9bb8b-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{73b9bb8b-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{73b9bba8-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{73b9bba8-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{73b9bbab-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{73b9bbab-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{7b1ee4a3-7ad4-11dd-b6d1-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{7b1ee4a3-7ad4-11dd-b6d1-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{7b1ee4a9-7ad4-11dd-b6d1-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{7b1ee4a9-7ad4-11dd-b6d1-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{8e051f9c-e902-11de-a649-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{8e051f9c-e902-11de-a649-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{956ec7de-0cbf-11df-ba60-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{956ec7de-0cbf-11df-ba60-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{ad1a8282-8733-11dd-b4ea-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{ad1a8282-8733-11dd-b4ea-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{ae9e76a9-bda4-11de-bae2-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{ae9e76a9-bda4-11de-bae2-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{ae9e76c2-bda4-11de-bae2-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{ae9e76c2-bda4-11de-bae2-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{b2187d5e-ddac-11de-af9d-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{b2187d5e-ddac-11de-af9d-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{b4b72941-8654-11dd-b3e1-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{b4b72941-8654-11dd-b3e1-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{c032af19-b710-11de-ae35-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{c032af19-b710-11de-ae35-00037a8a3848}\Shell\AutoRun\command - "" = I:\AutoRun.exe
    O33 - MountPoints2\{c756d7f2-a48b-11de-be0b-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{c756d7f2-a48b-11de-be0b-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{da664491-1e76-11e0-9edc-ac4d52f2073d}\Shell - "" = AutoRun
    O33 - MountPoints2\{da664491-1e76-11e0-9edc-ac4d52f2073d}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
    O33 - MountPoints2\{e7849982-7da1-11dd-9ff8-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{e7849982-7da1-11dd-9ff8-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{e7849985-7da1-11dd-9ff8-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{e7849985-7da1-11dd-9ff8-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{e92b0683-e41e-11de-81cc-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{e92b0683-e41e-11de-81cc-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{eb03467f-24b6-11df-ab77-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{eb03467f-24b6-11df-ab77-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{eb0346a2-24b6-11df-ab77-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{eb0346a2-24b6-11df-ab77-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{f4f40baf-2b7e-11df-9201-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{f4f40baf-2b7e-11df-9201-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\D\Shell - "" = AutoRun
    O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\G\Shell - "" = AutoRun
    O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\H\Shell - "" = AutoRun
    O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\setup.exe
    O34 - HKLM BootExecute: (autocheck autochk /r \??\E:)
    O34 - HKLM BootExecute: (autocheck autochk /r \??\C:)
    [2012-04-20 04:21:19 | 000,000,000 | -HSD | C] – C:\found.002
    [2012-04-02 16:38:32 | 000,000,000 | —D | C] – C:\Program Files\Pando Networks
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [2012-04-07 23:14:44 | 000,024,064 | —- | M] () – C:\Users\coimbra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011-06-10 23:09:05 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\GetRightToGo
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Hi!
I'm having a bit of trouble with OTL now. Whenever it gets to:
O34 - HKLM BootExecute: (autocheck autochk /r \??\E:)
It simply crashes. The program doesn't respond anymore, no matter how much I wait… I even tried in safe mode, but the same thing happened again. Is this supposed to happen?
Hi,

Use the following:


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    :Services
    
    :OTL
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
    IE - HKLM\..\SearchScopes,DefaultScope = {98E36557-BAF2-43F5-AF12-E20791AC3A09}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=1&src=sp&…q={searchTerms}
    IE - HKLM\..\SearchScopes\{98E36557-BAF2-43F5-AF12-E20791AC3A09}: "URL" = http://www.google.pt/search?q={searchTerms…p;sourceid=ie7;
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.pt
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://startsear.ch/?aff=1
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://pt.msn.com/?ocid=iehp
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt
    IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://startsear.ch/?aff=1&src=sp&…q={searchTerms}
    FF - prefs.js..browser.search.defaultengine: "Web Search"
    FF - prefs.js..browser.search.defaultenginename: "Web Search"
    FF - prefs.js..browser.search.order.1: "Web Search"
    FF - prefs.js..keyword.URL: "http://startsear.ch/?aff=1&src=sp&cf=a6c18f78-08af-11e1-8b63-8ad0386e9ad0&q="
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    O2 - BHO: (IE5BarLauncherBHO Class) - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
    O3 - HKLM\..\Toolbar: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (VShareToolBar) - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Programas\vShare.tv plugin\BarLcher.dll (VShare Inc.)
    O33 - MountPoints2\{0050a06f-ea7e-11de-bfe8-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{0050a06f-ea7e-11de-bfe8-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{0050a070-ea7e-11de-bfe8-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{0050a070-ea7e-11de-bfe8-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{047897fb-7809-11e1-9904-8b027e70d36c}\Shell - "" = AutoRun
    O33 - MountPoints2\{047897fb-7809-11e1-9904-8b027e70d36c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{04789804-7809-11e1-9904-8b027e70d36c}\Shell - "" = AutoRun
    O33 - MountPoints2\{04789804-7809-11e1-9904-8b027e70d36c}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{0ba442ef-7dc7-11dd-a121-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{0ba442ef-7dc7-11dd-a121-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{0ba442f6-7dc7-11dd-a121-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{0ba442f6-7dc7-11dd-a121-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{22acd90c-b9b7-11de-b592-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{22acd90c-b9b7-11de-b592-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{22acd924-b9b7-11de-b592-00037a8a3848}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Fixer32.exe
    O33 - MountPoints2\{22acd924-b9b7-11de-b592-00037a8a3848}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Fixer32.exe
    O33 - MountPoints2\{3c652fab-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{3c652fab-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{3c652fb6-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{3c652fb6-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{3c652fb8-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{3c652fb8-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{3c652fba-5331-11de-855e-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{3c652fba-5331-11de-855e-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup_vmc_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{4a8cd8b0-c3c4-11de-be15-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{4a8cd8b0-c3c4-11de-be15-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{52c82829-7735-11df-80ad-efd5b989612a}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\kazEwAShI.eXE
    O33 - MountPoints2\{580a38a1-7b99-11dd-91ed-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{580a38a1-7b99-11dd-91ed-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{633cc66b-6c61-11e1-9284-c9f1be4eb307}\Shell - "" = AutoRun
    O33 - MountPoints2\{633cc66b-6c61-11e1-9284-c9f1be4eb307}\Shell\AutoRun\command - "" = G:\setup.exe AUTORUN=1
    O33 - MountPoints2\{63be626d-dabe-11de-baec-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{63be626d-dabe-11de-baec-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{63faee14-bc2e-11de-a49c-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{63faee14-bc2e-11de-a49c-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell\AutoRun\command - "" = D:\autorun.exe
    O33 - MountPoints2\{67e5eefd-35ee-11de-bafa-00037a8a3848}\Shell\setup\command - "" = D:\setup.exe
    O33 - MountPoints2\{6865071c-b74f-11de-9b69-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{6865071c-b74f-11de-9b69-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{736d7796-be78-11de-95f3-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{736d7796-be78-11de-95f3-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{73b9bb8b-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{73b9bb8b-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{73b9bba8-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{73b9bba8-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{73b9bbab-e973-11de-8134-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{73b9bbab-e973-11de-8134-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{7b1ee4a3-7ad4-11dd-b6d1-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{7b1ee4a3-7ad4-11dd-b6d1-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{7b1ee4a9-7ad4-11dd-b6d1-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{7b1ee4a9-7ad4-11dd-b6d1-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{8e051f9c-e902-11de-a649-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{8e051f9c-e902-11de-a649-00037a8a3848}\Shell\AutoRun\command - "" = H:\AutoRun.exe
    O33 - MountPoints2\{956ec7de-0cbf-11df-ba60-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{956ec7de-0cbf-11df-ba60-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{ad1a8282-8733-11dd-b4ea-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{ad1a8282-8733-11dd-b4ea-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{ae9e76a9-bda4-11de-bae2-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{ae9e76a9-bda4-11de-bae2-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{ae9e76c2-bda4-11de-bae2-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{ae9e76c2-bda4-11de-bae2-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{b2187d5e-ddac-11de-af9d-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{b2187d5e-ddac-11de-af9d-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{b4b72941-8654-11dd-b3e1-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{b4b72941-8654-11dd-b3e1-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{c032af19-b710-11de-ae35-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{c032af19-b710-11de-ae35-00037a8a3848}\Shell\AutoRun\command - "" = I:\AutoRun.exe
    O33 - MountPoints2\{c756d7f2-a48b-11de-be0b-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{c756d7f2-a48b-11de-be0b-00037a8a3848}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{da664491-1e76-11e0-9edc-ac4d52f2073d}\Shell - "" = AutoRun
    O33 - MountPoints2\{da664491-1e76-11e0-9edc-ac4d52f2073d}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
    O33 - MountPoints2\{e7849982-7da1-11dd-9ff8-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{e7849982-7da1-11dd-9ff8-001e687cfad6}\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\{e7849985-7da1-11dd-9ff8-001e687cfad6}\Shell - "" = AutoRun
    O33 - MountPoints2\{e7849985-7da1-11dd-9ff8-001e687cfad6}\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\{e92b0683-e41e-11de-81cc-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{e92b0683-e41e-11de-81cc-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{eb03467f-24b6-11df-ab77-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{eb03467f-24b6-11df-ab77-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{eb0346a2-24b6-11df-ab77-00037a8a3848}\Shell - "" = AutoRun
    O33 - MountPoints2\{eb0346a2-24b6-11df-ab77-00037a8a3848}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\{f4f40baf-2b7e-11df-9201-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{f4f40baf-2b7e-11df-9201-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
    O33 - MountPoints2\D\Shell - "" = AutoRun
    O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\setup.exe
    O33 - MountPoints2\G\Shell - "" = AutoRun
    O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setup.exe
    O33 - MountPoints2\H\Shell - "" = AutoRun
    O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\setup.exe
    [2012-04-20 04:21:19 | 000,000,000 | -HSD | C] – C:\found.002
    [2012-04-02 16:38:32 | 000,000,000 | —D | C] – C:\Program Files\Pando Networks
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [2012-04-07 23:14:44 | 000,024,064 | —- | M] () – C:\Users\coimbra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011-06-10 23:09:05 | 000,000,000 | —D | M] – C:\Users\coimbra\AppData\Roaming\GetRightToGo
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-
Thank you! Here's the log:


OTL logfile created on: 24-04-2012 01:10:16 - Run 2
OTL by OldTimer - Version 3.2.41.0 Folder = C:\Users\coimbra\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy

3,00 Gb Total Physical Memory | 2,06 Gb Available Physical Memory | 68,88% Memory free
6,19 Gb Paging File | 5,36 Gb Available in Paging File | 86,56% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 151,64 Gb Total Space | 22,01 Gb Free Space | 14,51% Space Free | Partition Type: NTFS
Drive E: | 144,99 Gb Total Space | 45,68 Gb Free Space | 31,51% Space Free | Partition Type: NTFS

Computer Name: COMPUTADOR | User Name: coimbra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Windows\System32\rpcnetp.exe ()
PRC - C:\Users\coimbra\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Programas\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Programas\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Programas\DAZ 3D\Content Management Service\ContentManagementServer.exe ()
PRC - C:\Programas\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Programas\AVG\AVG PC Tuneup 2011\BoostSpeed.exe (AVG)
PRC - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Programas\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Programas\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Programas\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Programas\Toshiba\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - c:\Programas\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Programas\O2Micro Flash Memory Card Driver\o2flash.exe (O2Micro International)
PRC - C:\Programas\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Programas\AVG\AVG PC Tuneup 2011\madExcept_.bpl ()
MOD - C:\Programas\AVG\AVG PC Tuneup 2011\madDisAsm_.bpl ()
MOD - C:\Programas\AVG\AVG PC Tuneup 2011\madBasic_.bpl ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Programas\Toshiba\PCDiag\NotifyPCD.dll ()
MOD - C:\Programas\Toshiba\FlashCards\TWarnMsg\TWarnMsg.dll ()
MOD - C:\Programas\Toshiba\FlashCards\BlackPng.dll ()
MOD - C:\Programas\Toshiba\TBS\NotifyTBS.dll ()
MOD - C:\Programas\Toshiba\TOSHIBA Assist\NotifyX.dll ()
MOD - C:\Programas\Toshiba\TOSHIBA Disc Creator\NotifyTDC.dll ()


========== Win32 Services (SafeList) ==========

SRV - (StarWindServiceAE) – File not found
SRV - (Automatic CDROM Monitor) – File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (sdCoreService) – C:\Programas\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Programas\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Programas\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (AdobeARMservice) – C:\Programas\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (odserv) – C:\Programas\Common Files\microsoft shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (DAZContentManagementService) – C:\Programas\DAZ 3D\Content Management Service\ContentManagementServer.exe ()
SRV - (fsssvc) – C:\Programas\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (ServiceLayer) – C:\Programas\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (SeaPort) – C:\Programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Programas\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (VMCService) – C:\Programas\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (TNaviSrv) – C:\Programas\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Programas\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) – C:\Programas\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (TosCoSrv) – C:\Programas\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:\Programas\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) – C:\Programas\Toshiba\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA Bluetooth Service) – c:\Programas\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (o2flash) – C:\Programas\O2Micro Flash Memory Card Driver\o2flash.exe (O2Micro International)
SRV - (SSScsiSV) – C:\Programas\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (SonicStage Back-End Service) – C:\Programas\Common Files\Sony Shared\AVLib\SsBeSvc.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Programas\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Programas\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Programas\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (ose) – C:\Programas\Common Files\microsoft shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (UleadBurningHelper) – C:\Programas\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (lxcj_device) – C:\Windows\System32\lxcjcoms.exe ( )


========== Driver Services (SafeList) ==========

DRV - (ZTEusbser6k) – File not found
DRV - (ZTEusbnmea) – File not found
DRV - (ZTEusbmdm6k) – File not found
DRV - (zlportio) – C:\Program Files\UltraStar Deluxe\zlportio.sys File not found
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – File not found
DRV - (NwlnkFwd) – File not found
DRV - (NwlnkFlt) – File not found
DRV - (IpInIp) – File not found
DRV - (IntcHdmiAddService) Intel® – File not found
DRV - (igfx) – File not found
DRV - (catchme) – C:\Users\coimbra\AppData\Local\Temp\catchme.sys File not found
DRV - (aqmph3y9) – File not found
DRV - (pctplfw) – C:\Windows\System32\drivers\pctplfw.sys (PC Tools)
DRV - (pctNdisLW) – C:\Windows\System32\drivers\pctNdisLW.sys (PC Tools)
DRV - (apf001) – C:\Windows\System32\apf001.sys ()
DRV - (pctplsg) – C:\Windows\System32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) – C:\Windows\System32\drivers\PCTSD.sys (PC Tools)
DRV - (pctBTFix) – C:\Windows\System32\drivers\pctBTFix.sys (PC Tools)
DRV - (pctgntdi) – C:\Windows\System32\drivers\pctgntdi.sys (PC Tools)
DRV - (TFSysMon) – C:\Windows\System32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\Windows\System32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\Windows\System32\drivers\TfNetMon.sys (PC Tools)
DRV - (pctEFA) – C:\Windows\System32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\Windows\System32\drivers\pctDS.sys (PC Tools)
DRV - (PCTCore) – C:\Windows\System32\drivers\PCTCore.sys (PC Tools)
DRV - (PCTAppEvent) – C:\Windows\System32\drivers\PCTAppEvent.sys (PC Tools)
DRV - (PCTBD) – C:\Windows\System32\drivers\PCTBD.sys (PC Tools)
DRV - (libusb0) – C:\Windows\System32\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV - (MotioninJoyXFilter) – C:\Windows\System32\drivers\MijXfilt.sys (MotioninJoy)
DRV - (UsbserFilt) – C:\Windows\System32\drivers\usbser_lowerfltj.sys (Nokia)
DRV - (upperdev) – C:\Windows\System32\drivers\usbser_lowerflt.sys (Nokia)
DRV - (nmwcdc) – C:\Windows\System32\drivers\ccdcmbo.sys (Nokia)
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdnsu) – C:\Windows\System32\drivers\nmwcdnsu.sys (Nokia)
DRV - (nmwcdnsuc) – C:\Windows\System32\drivers\nmwcdnsuc.sys (Nokia)
DRV - (Mkd2kfNt) – C:\Windows\System32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (Mkd2Nadr) – C:\Windows\System32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (sptd) – C:\Windows\System32\drivers\sptd.sys ()
DRV - (NETw5v32) Intel® – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (CnxtHdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (tos_sps32) – C:\Windows\System32\drivers\tos_sps32.sys (TOSHIBA Corporation)
DRV - (O2MDRDR) – C:\Windows\System32\drivers\o2media.sys (O2Micro )
DRV - (tosrfbd) – C:\Windows\System32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (Tosrfhid) – C:\Windows\System32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosrfbnp) – C:\Windows\System32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\Windows\System32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfcom) – C:\Windows\System32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (NETw4v32) Controlador do Adaptador da ligação WiFi sem fios Intel® – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (QIOMem) – C:\Windows\System32\drivers\QIOMem.sys (TOSHIBA)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel® Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (tosrfec) – C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (tosporte) – C:\Windows\System32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\Windows\System32\drivers\tosrfnds.sys (TOSHIBA Corporation.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs =
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Programas\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: "Google.pt"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.pt/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: multilinks@plugin:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.4
FF - prefs.js..extensions.enabledItems: {9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}:3.0.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [removed]:1.3.4
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.1829
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\coimbra\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\coimbra\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\coimbra\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009-07-05 02:37:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2012-04-18 15:26:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-04-17 14:39:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-04-14 17:06:58 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Veoh Networks\VeohWebPlayer\FFVideoFinder [2009-06-21 18:30:16 | 000,000,000 | —D | M]

[2010-02-20 20:26:47 | 000,000,000 | —D | M] (No name found) – C:\Users\coimbra\AppData\Roaming\mozilla\Extensions
[2010-02-20 20:26:47 | 000,000,000 | —D | M] (No name found) – C:\Users\coimbra\AppData\Roaming\mozilla\Extensions\[removed]
[2012-04-17 14:39:48 | 000,000,000 | —D | M] (No name found) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions
[2010-04-07 21:35:13 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010-03-14 22:44:46 | 000,000,000 | —D | M] (CookieSafe) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\{9D23D0AA-D8F5-11DA-B3FC-0928ABF316DD}
[2012-04-17 14:39:48 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012-03-08 00:14:17 | 000,000,000 | —D | M] (Corretor para Português de Portugal) – C:\Users\coimbra\AppData\Roaming\mozilla\Firefox\Profiles\85zy9bwz.default\extensions\[removed]
[2010-11-04 23:16:34 | 000,001,927 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\encyclopedia-search.xml
[2010-11-04 23:13:46 | 000,005,419 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\googlept.xml
[2011-07-11 19:04:02 | 000,000,633 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\startsear.xml
[2010-11-04 23:09:50 | 000,004,140 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Mozilla\Firefox\Profiles\85zy9bwz.default\searchplugins\youtube.xml
[2012-04-17 14:39:37 | 000,000,000 | —D | M] (No name found) – C:\Programas\Mozilla Firefox\extensions
() (No name found) – C:\USERS\COIMBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\85ZY9BWZ.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\USERS\COIMBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\85ZY9BWZ.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\COIMBRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\85ZY9BWZ.DEFAULT\EXTENSIONS\[removed]
[2012-03-13 05:38:06 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012-02-16 04:26:37 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009-09-21 02:11:17 | 000,072,960 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2011-10-03 10:14:54 | 000,083,456 | —- | M] (vShare.tv ) – C:\Program Files\mozilla firefox\plugins\npvsharetvplg.dll
[2011-03-22 19:38:12 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012-03-13 06:51:17 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012-03-13 06:51:17 | 000,001,529 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\priberam.xml
[2012-03-13 06:51:17 | 000,002,071 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\sapo.xml
[2012-03-13 06:51:17 | 000,000,942 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-ptpt.xml

========== Chrome ==========

CHR - default_search_provider: Google (Predefini\u00E7\u00E3o) (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\coimbra\AppData\Local\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: vShare.tv plug-in (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npvsharetvplg.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\coimbra\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: FB Chat Sidebar Disabler = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\beeidigicffecnkbanlfnmaplmkafdje\2.4.8_0\
CHR - Extension: YouTube = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus (Beta) = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Pesquisa do Google = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: SmallringFX DarkBlue Theme = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfijmgohofmpjlcgmjplbpmkpchdhpk\1.7_0\
CHR - Extension: Linkclump = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfpjkncokllnfokkgpkobnkbkmelfefj\2.0.17_0\
CHR - Extension: Gmail = C:\Users\coimbra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2006-09-18 22:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Programas\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Programas\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programas\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Programa Auxiliar de Início de Sessão do Windows Live ID) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Programas\Free Download Manager\iefdm2.dll ()
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Programas\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Programas\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [00TCrdMain] C:\Programas\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HSON] C:\Programas\Toshiba\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [LXCJCATS] C:\Windows\System32\spool\DRIVERS\W32X86\3\LXCJtime.DLL ()
O4 - HKLM..\Run: [SmoothView] C:\Programas\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Programas\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - Startup: C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\coimbra\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Programas\ERUNT\AUTOBACK.EXE ()
O8 - Extra context menu item: Transferência seleccionada pelo FDM - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Transferir com FDM - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Transferir todos com FDM - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Transferir vídeo com FDM - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O9 - Extra Button: Publicar em Blogue - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Publicar; no Blogue no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar; para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Programas\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab (SysInfo Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} http://messenger.zone.msn.com/MessengerGam…S.cab109791.cab ()
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…yri_4.3.1.0.cab (SysInfo Class)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A4C3FC56-EE04-4EE7-82B7-3BF50C28986C}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programas\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programas\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programas\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSTEM32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - File not found
O24 - Desktop WallPaper: C:\Users\coimbra\Pictures\Wallpapers\[animepaper.net]wallpaper-art-artists-sena-way-out-of-here-226993-fnatt-1280x800-b369d999.jpg
O24 - Desktop BackupWallPaper: C:\Users\coimbra\Pictures\Wallpapers\[animepaper.net]wallpaper-art-artists-sena-way-out-of-here-226993-fnatt-1280x800-b369d999.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 22:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012-04-23 22:30:02 | 000,000,000 | —D | C] – C:\_OTL
[2012-04-23 22:27:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012-04-23 22:27:03 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012-04-23 22:25:58 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Users\coimbra\Desktop\erunt-setup.exe
[2012-04-23 20:02:17 | 000,594,944 | —- | C] (OldTimer Tools) – C:\Users\coimbra\Desktop\OTL.exe
[2012-04-23 19:45:20 | 000,000,000 | —D | C] – C:\ComboFix
[2012-04-23 00:38:30 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012-04-23 00:38:30 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012-04-23 00:38:30 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012-04-23 00:38:19 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012-04-23 00:38:14 | 000,000,000 | —D | C] – C:\Qoobox
[2012-04-22 20:40:25 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2012-04-22 20:38:50 | 004,472,002 | R— | C] (Swearware) – C:\Users\coimbra\Desktop\ComboFix.exe
[2012-04-22 20:36:01 | 000,000,000 | R–D | C] – C:\Users\coimbra\Dropbox
[2012-04-22 20:33:49 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012-04-22 20:32:57 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Dropbox
[2012-04-22 16:42:07 | 002,072,624 | —- | C] (Kaspersky Lab ZAO) – C:\Users\coimbra\Desktop\tdsskiller.exe
[2012-04-22 15:05:50 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\coimbra\Desktop\aswMBR.exe
[2012-04-22 15:04:39 | 000,607,260 | R— | C] (Swearware) – C:\Users\coimbra\Desktop\dds.com
[2012-04-21 20:45:55 | 000,000,000 | —D | C] – C:\sh4ldr
[2012-04-21 20:45:55 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2012-04-21 20:27:30 | 000,000,000 | —D | C] – C:\Program Files\ExpressFiles
[2012-04-21 20:07:55 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\SpeedyPC Software
[2012-04-21 20:07:55 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\DriverCure
[2012-04-21 20:07:49 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012-04-19 23:17:25 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012-04-19 00:17:29 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\PCTools
[2012-04-18 15:44:02 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\PC Tools
[2012-04-18 15:44:01 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Spam Monitor
[2012-04-18 15:38:11 | 000,574,424 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfSysMon.sys
[2012-04-18 15:38:11 | 000,054,328 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfFsMon.sys
[2012-04-18 15:38:11 | 000,035,264 | –S- | C] (PC Tools) – C:\Windows\System32\drivers\TfNetMon.sys
[2012-04-18 15:33:33 | 000,125,888 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2012-04-18 15:33:30 | 000,091,136 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2012-04-18 15:33:30 | 000,058,400 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdisLW.sys
[2012-04-18 15:33:30 | 000,032,936 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2012-04-18 15:26:32 | 000,056,840 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTBD.sys
[2012-04-18 15:26:31 | 002,250,704 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll
[2012-04-18 15:26:31 | 000,149,456 | —- | C] (PC Tools) – C:\Windows\SGDetectionTool.dll
[2012-04-18 15:26:30 | 001,681,360 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDRes.dll
[2012-04-18 15:24:12 | 000,909,728 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctEFA.sys
[2012-04-18 15:24:12 | 000,342,168 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctDS.sys
[2012-04-18 15:24:10 | 000,253,352 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2012-04-18 15:24:10 | 000,107,864 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctwfpfilter.sys
[2012-04-18 15:24:04 | 000,331,880 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2012-04-18 15:24:04 | 000,162,584 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2012-04-18 15:24:01 | 000,185,560 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTSD.sys
[2012-04-18 15:24:01 | 000,017,848 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctBTFix.sys
[2012-04-18 15:24:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2012-04-18 15:23:56 | 000,070,536 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplsg.sys
[2012-04-18 15:23:45 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2012-04-18 15:23:45 | 000,000,000 | —D | C] – C:\ProgramData\PC Tools
[2012-04-18 15:23:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2012-04-17 18:42:50 | 000,418,464 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012-04-15 19:33:56 | 000,000,000 | —D | C] – C:\Users\coimbra\Documents\Cenas da mãe
[2012-04-12 18:24:23 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ragray
[2012-04-12 18:05:57 | 000,000,000 | —D | C] – C:\Program Files\Ragray
[2012-04-12 17:54:06 | 000,000,000 | —D | C] – C:\Program Files\1RO
[2012-04-11 10:56:20 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012-04-11 10:56:18 | 001,799,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012-04-11 10:56:17 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012-04-11 10:56:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012-04-11 10:56:16 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012-04-11 10:56:15 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012-04-11 10:53:47 | 003,602,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012-04-11 10:53:47 | 003,550,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012-04-02 19:39:33 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\LolClient
[2012-04-02 18:20:01 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_39.dll
[2012-04-02 18:20:01 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_39.dll
[2012-04-02 18:19:58 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_39.dll
[2012-04-02 18:09:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2012-03-30 00:59:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAZ Productions
[2012-03-30 00:58:58 | 000,090,112 | —- | C] (MindVision Software) – C:\Windows\unvise32.exe
[2012-03-27 14:26:53 | 000,000,000 | —D | C] – C:\ProgramData\Vodafone
[2012-03-27 14:26:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vodafone
[2012-03-27 14:26:42 | 000,000,000 | —D | C] – C:\Program Files\Vodafone
[2012-03-27 14:25:32 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Local\{D53238E8-3427-491E-A57E-097FA966AAC1}
[2012-03-26 17:40:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
[2012-03-26 17:40:18 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2012-03-26 17:39:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Canon
[2012-03-25 04:22:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DAZ
[2012-03-25 04:18:44 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D
[2012-03-25 04:18:16 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAZ 3D
[2012-03-25 04:18:16 | 000,000,000 | —D | C] – C:\ProgramData\DAZ 3D
[2012-03-25 04:17:32 | 000,000,000 | —D | C] – C:\Users\coimbra\Documents\DAZ 3D
[2012-03-25 04:16:17 | 000,000,000 | —D | C] – C:\Program Files\DAZ 3D
[2012-03-25 04:14:19 | 000,000,000 | —D | C] – C:\Users\coimbra\AppData\Roaming\DAZ 3D

========== Files - Modified Within 30 Days ==========

[2012-04-24 01:08:24 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-04-24 01:06:58 | 000,000,998 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-04-24 01:06:41 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012-04-24 01:06:38 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012-04-24 01:06:21 | 000,017,408 | —- | M] () – C:\Windows\System32\rpcnetp.dll
[2012-04-24 01:05:46 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012-04-24 01:05:31 | 3219,578,880 | -HS- | M] () – C:\hiberfil.sys
[2012-04-24 01:05:27 | 000,017,408 | —- | M] () – C:\Windows\System32\rpcnetp.exe
[2012-04-24 00:52:09 | 000,001,002 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-04-24 00:07:22 | 000,168,900 | —- | M] () – C:\Users\coimbra\Documents\ESTÁGIO III.pdf
[2012-04-23 23:55:00 | 000,001,030 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2519787931-4213243981-2891937994-1000UA.job
[2012-04-23 23:18:28 | 000,044,544 | —- | M] (Absolute Software Corp.) – C:\Windows\System32\agremove.exe
[2012-04-23 23:03:15 | 000,000,918 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012-04-23 23:03:12 | 000,000,738 | —- | M] () – C:\Users\coimbra\Desktop\NTREGOPT.lnk
[2012-04-23 23:03:12 | 000,000,719 | —- | M] () – C:\Users\coimbra\Desktop\ERUNT.lnk
[2012-04-23 22:25:55 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Users\coimbra\Desktop\erunt-setup.exe
[2012-04-23 20:02:12 | 000,594,944 | —- | M] (OldTimer Tools) – C:\Users\coimbra\Desktop\OTL.exe
[2012-04-23 00:37:31 | 004,472,002 | R— | M] (Swearware) – C:\Users\coimbra\Desktop\ComboFix.exe
[2012-04-22 21:14:05 | 002,402,047 | —- | M] () – C:\Windows\System32\drivers\Cat.DB
[2012-04-22 20:36:01 | 000,000,987 | —- | M] () – C:\Users\coimbra\Desktop\Dropbox.lnk
[2012-04-22 20:34:11 | 000,000,967 | —- | M] () – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012-04-22 20:04:08 | 000,222,625 | —- | M] () – C:\Users\coimbra\Documents\marcadores_22_04_12.html
[2012-04-22 16:42:06 | 002,072,624 | —- | M] (Kaspersky Lab ZAO) – C:\Users\coimbra\Desktop\tdsskiller.exe
[2012-04-22 16:06:00 | 000,000,512 | —- | M] () – C:\Users\coimbra\Documents\MBR.dat
[2012-04-22 15:05:56 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\coimbra\Desktop\aswMBR.exe
[2012-04-22 15:04:35 | 000,607,260 | R— | M] (Swearware) – C:\Users\coimbra\Desktop\dds.com
[2012-04-22 01:55:00 | 000,000,978 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2519787931-4213243981-2891937994-1000Core.job
[2012-04-21 22:07:09 | 000,002,527 | —- | M] () – C:\Users\coimbra\Desktop\HiJackThis.lnk
[2012-04-21 00:10:45 | 000,662,798 | —- | M] () – C:\Windows\System32\prfh0816.dat
[2012-04-21 00:10:45 | 000,598,900 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012-04-21 00:10:45 | 000,131,986 | —- | M] () – C:\Windows\System32\prfc0816.dat
[2012-04-21 00:10:45 | 000,104,914 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012-04-19 02:26:15 | 000,303,902 | —- | M] () – C:\Users\coimbra\Documents\Formulário.pdf
[2012-04-18 17:21:28 | 000,000,000 | —- | M] () – C:\Windows\System32\SM.lock
[2012-04-18 15:33:33 | 000,125,888 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctplfw.sys
[2012-04-18 15:33:30 | 000,091,136 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2012-04-18 15:33:30 | 000,058,400 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdisLW.sys
[2012-04-18 15:33:30 | 000,032,936 | —- | M] (PC Tools) – C:\Windows\System32\drivers\pctNdis-DNS.sys
[2012-04-18 15:32:24 | 000,001,817 | —- | M] () – C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2012-04-17 19:07:30 | 000,418,464 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012-04-17 19:07:30 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012-04-17 14:39:41 | 000,000,875 | —- | M] () – C:\Users\coimbra\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012-04-17 14:39:40 | 000,000,851 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012-04-14 19:57:43 | 000,002,019 | —- | M] () – C:\Users\coimbra\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012-04-14 19:57:42 | 000,002,057 | —- | M] () – C:\Users\coimbra\Desktop\Google Chrome.lnk
[2012-04-11 10:24:12 | 000,001,356 | —- | M] () – C:\Users\coimbra\AppData\Local\d3d9caps.dat
[2012-04-06 20:41:05 | 000,054,338 | —- | M] () – C:\Users\coimbra\Documents\Guião Trabalho de Grupo TOIV.pdf
[2012-04-04 02:04:49 | 000,000,718 | —- | M] () – C:\Users\coimbra\Desktop\Play League of Legends.lnk
[2012-04-02 00:46:34 | 000,000,809 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012-03-27 16:40:34 | 000,075,757 | —- | M] () – C:\Users\coimbra\Documents\Trabalho Prático 3.pdf
[2012-03-26 18:23:01 | 000,554,858 | —- | M] () – C:\Users\coimbra\Documents\Documentos ENETO.pdf
[2012-03-25 04:18:45 | 000,001,849 | —- | M] () – C:\Users\coimbra\Desktop\DAZ Studio 4.lnk

========== Files Created - No Company Name ==========

[2012-04-24 01:06:21 | 000,017,408 | —- | C] () – C:\Windows\System32\rpcnetp.dll
[2012-04-24 01:05:31 | 3219,578,880 | -HS- | C] () – C:\hiberfil.sys
[2012-04-24 00:53:34 | 000,017,408 | —- | C] () – C:\Windows\System32\rpcnetp.exe
[2012-04-24 00:07:20 | 000,168,900 | —- | C] () – C:\Users\coimbra\Documents\ESTÁGIO III.pdf
[2012-04-23 22:27:12 | 000,000,918 | —- | C] () – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012-04-23 22:27:03 | 000,000,738 | —- | C] () – C:\Users\coimbra\Desktop\NTREGOPT.lnk
[2012-04-23 22:27:03 | 000,000,719 | —- | C] () – C:\Users\coimbra\Desktop\ERUNT.lnk
[2012-04-23 00:38:30 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012-04-23 00:38:30 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012-04-23 00:38:30 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012-04-23 00:38:30 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012-04-23 00:38:30 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012-04-22 20:36:01 | 000,000,987 | —- | C] () – C:\Users\coimbra\Desktop\Dropbox.lnk
[2012-04-22 20:34:11 | 000,000,967 | —- | C] () – C:\Users\coimbra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012-04-22 20:04:07 | 000,222,625 | —- | C] () – C:\Users\coimbra\Documents\marcadores_22_04_12.html
[2012-04-22 16:06:00 | 000,000,512 | —- | C] () – C:\Users\coimbra\Documents\MBR.dat
[2012-04-19 02:13:00 | 000,303,902 | —- | C] () – C:\Users\coimbra\Documents\Formulário.pdf
[2012-04-18 17:21:28 | 000,000,000 | —- | C] () – C:\Windows\System32\SM.lock
[2012-04-18 15:32:24 | 000,001,817 | —- | C] () – C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2012-04-18 15:26:32 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll
[2012-04-18 15:26:31 | 000,003,488 | —- | C] () – C:\Windows\UDB.zip
[2012-04-18 15:26:31 | 000,000,882 | —- | C] () – C:\Windows\RegSDImport.xml
[2012-04-18 15:26:31 | 000,000,879 | —- | C] () – C:\Windows\RegISSImport.xml
[2012-04-18 15:26:31 | 000,000,131 | —- | C] () – C:\Windows\IDB.zip
[2012-04-18 15:24:13 | 002,402,047 | —- | C] () – C:\Windows\System32\drivers\Cat.DB
[2012-04-17 18:42:51 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-04-06 20:41:01 | 000,054,338 | —- | C] () – C:\Users\coimbra\Documents\Guião Trabalho de Grupo TOIV.pdf
[2012-04-04 02:04:49 | 000,000,718 | —- | C] () – C:\Users\coimbra\Desktop\Play League of Legends.lnk
[2012-03-27 16:39:19 | 000,075,757 | —- | C] () – C:\Users\coimbra\Documents\Trabalho Prático 3.pdf
[2012-03-26 18:17:02 | 000,554,858 | —- | C] () – C:\Users\coimbra\Documents\Documentos ENETO.pdf
[2012-03-25 04:18:45 | 000,001,849 | —- | C] () – C:\Users\coimbra\Desktop\DAZ Studio 4.lnk
[2012-03-12 03:09:33 | 000,012,920 | —- | C] () – C:\Windows\System32\apl001.sys
[2012-03-12 03:09:33 | 000,010,872 | —- | C] () – C:\Windows\System32\apf001.sys
[2011-08-09 20:44:41 | 000,000,056 | —- | C] () – C:\Windows\wininit.ini
[2011-07-08 16:52:55 | 000,175,616 | —- | C] () – C:\Windows\System32\unrar.dll
[2011-06-19 18:04:33 | 000,532,480 | —- | C] () – C:\Windows\System32\CddbPlaylist2Sony.dll
[2011-04-17 21:57:44 | 000,000,496 | —- | C] () – C:\Windows\System32\lxcjplc.ini
[2010-12-21 00:06:58 | 000,000,136 | —- | C] () – C:\Windows\System32\winsusrm.dll
[2010-12-21 00:06:09 | 000,000,120 | —- | C] () – C:\Windows\System32\winsusrx.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:888AFB86

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI