Computer Hope

Software => Computer viruses and spyware => Topic started by: Rebs on May 21, 2011, 07:24:33 PM

Title: Programs closing down randomly (Vista)
Post by: Rebs on May 21, 2011, 07:24:33 PM
I'm new to these forums but I've noticed this particular issue has been the topic of many threads here. However, I believe this has to be dealt individually, so I decided to create this topic.

To the point:

I've been having this problem for over a week now, programs keep randomly closing (message: Program X stopped working and had to be closed). I've ran a variety of anti-spyware programs, anti-virus, cleaned registry, ran scandisk and the problem persists.

Do you have any idea what this might be?

I suspect it's from  a "codec" (which obv wasn't really a codec)  I downloaded after getting a file from one of those filesharing links.

Anyway, here's Hijack log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:11:01, on 22-05-2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\SysWOW64\conime.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pt_pt&c=92&bd=Pavilion&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.live.com/1rewlive4startup/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pt_pt&c=92&bd=Pavilion&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.duxet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {e0301295-ab3e-4af3-979f-3d453c5f9f48} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Programa Auxiliar de Início de Sessão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Serviço de rede')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
O23 - Service: Serviço de Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Serviço iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7943 bytes


Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 22, 2011, 06:17:22 PM
Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*******************************************************
SUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

Download SuperAntispyware Free Edition (SAS) (http://www.superantispyware.com/download.html)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click Yes
* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the Preferences button.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

•It will open in your default text editor (preferably Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*Copy and Paste the log in your post.
********************************************
(http://i424.photobucket.com/albums/pp322/digistar/mbamicontw5.gif) Please download Malwarebytes Anti-Malware from here. (http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe)
Double Click mbam-setup.exe to install the application.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
*************************************************
Download DDS from HERE (http://download.bleepingcomputer.com/sUBs/dds.scr) or HERE (http://www.forospyware.com/sUBs/dds) and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copying and pasting it into the reply.
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 23, 2011, 12:38:07 AM
Hello Dave, thanks for the answer. Here are the logs as requested:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/23/2011 at 05:23 AM

Application Version : 4.52.1000

Core Rules Database Version : 7109
Trace Rules Database Version: 4921

Scan type       : Complete Scan
Total Scan Time : 02:41:22

Memory items scanned      : 573
Memory threats detected   : 0
Registry items scanned    : 13712
Registry threats detected : 0
File items scanned        : 218841
File threats detected     : 0

----

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Versão da base de dados: 6641

Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421

23-05-2011 06:59:33
mbam-log-2011-05-23 (06-59-33).txt

Tipo de pesquisa: Completa (C:\|D:\|)
Objectos verificados: 385922
Tempo decorrido: 1 hora(s), 8 minuto(s), 54 segundo(s)

Processos de memória infectados: 0
módulos de Memória infectados: 0
Chaves do Registo Infectadas: 0
Valores do Registo infectados: 0
Itens de dados do Registo Infectados: 0
Pastas Infectadas: 0
Ficheiros Infectados: 0

Processos de memória infectados:
(Nenhum item malicioso detectado)

módulos de Memória infectados:
(Nenhum item malicioso detectado)

Chaves do Registo Infectadas:
(Nenhum item malicioso detectado)

Valores do Registo infectados:
(Nenhum item malicioso detectado)

Itens de dados do Registo Infectados:
(Nenhum item malicioso detectado)

Pastas Infectadas:
(Nenhum item malicioso detectado)

Ficheiros Infectados:
(Nenhum item malicioso detectado)

- Sorry I forgot to change the language to English before running the test, but as you can see.. no threats were found.

As for DDS, I can't seem to be able to run it. It stops working and closes down, due to the same problem that brought me here.
Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 23, 2011, 11:37:17 AM
Ok. Let's try this one.

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.

* Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
* When the window appears, underneath Output at the top change it to Minimal Output.
* Check the boxes beside LOP Check and Purity Check.
* Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy and pate the contents of these files, one at a time, into your next reply.

Note: You may need two or more posts to fit them all in.
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 23, 2011, 12:16:06 PM
OTL logfile created on: 23-05-2011 19:10:51 - Run 1
OTL by OldTimer - Version 3.2.23.0     Folder = C:\Users\Ramiro\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy
 
5,00 Gb Total Physical Memory | 3,29 Gb Available Physical Memory | 65,75% Memory free
10,14 Gb Paging File | 8,53 Gb Available in Paging File | 84,17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 915,76 Gb Total Space | 128,62 Gb Free Space | 14,05% Space Free | Partition Type: NTFS
Drive D: | 10,76 Gb Total Space | 1,58 Gb Free Space | 14,70% Space Free | Partition Type: NTFS
Drive E: | 230,58 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: TRINCA-NA-PÊRA | User Name: Ramiro | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Ramiro\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Windows\SysWOW64\conime.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
 
 
========== Modules (SafeList) ==========
 
MOD - C:\Users\Ramiro\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
 
 
========== Win32 Services (SafeList) ==========
 
SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (UxTuneUp) -- C:\Windows\SysNative\uxtuneup.dll (TuneUp Software)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe (TuneUp Software)
SRV - (UxTuneUp) -- C:\Windows\SysWOW64\uxtuneup.dll (TuneUp Software)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel(R) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (ezSharedSvc) -- C:\Windows\SysWOW64\ezsvc7.dll (EasyBits Sofware AS)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Avgldx64) -- C:\Windows\SysNative\DRIVERS\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) -- C:\Windows\SysNative\DRIVERS\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (SBRE) -- C:\Windows\SysNative\drivers\SBREdrv.sys (Sunbelt Software)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\DRIVERS\atipmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\DRIVERS\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (MEMSWEEP2) -- C:\Windows\SysNative\59F1.tmp (Sophos Plc)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iastor.sys (Intel Corporation)
DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation                                            )
DRV:64bit: - (RT73) -- C:\Windows\SysNative\DRIVERS\Dr71WU.sys (Ralink Technology Inc.)
DRV - (Lavasoft Kernexplorer) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys ()
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys (TuneUp Software)
DRV - (SASDIFSV) -- C:\Programas\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Programas\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl (CyberLink Corp.)
DRV - (PCD5SRVC{8AAF211B-043E02A9-05040000}) -- C:\Programas\PC-Doctor for Windows\pcd5srvc_x64.pkms (PC-Doctor, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pt_pt&c=92&bd=Pavilion&pf=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pt_pt&c=92&bd=Pavilion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pt_pt&c=92&bd=Pavilion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.duxet.com/
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pt_pt&c=92&bd=Pavilion&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.live.com/1rewlive4startup/home
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginen ame: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://g.live.com/1rewlive4startup/home"
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.2n
FF - prefs.js..extensions.enabledItems: [email protected]:1.01
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..extensions.enabledItems: {40a1f5d7-afc2-498f-b264-02668d616ff6}:1.1
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:10.0.0.1209
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZVfox000&ptb=v7vjs4NH3LOYKt6.2Gqdsw&ind=2010110605&ptnrS=ZVfox000&si=&n=77cfda8d&psa=&st=kwd&searchfor="
 
 
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\MyWebSearch\bar\3.bin
FF - HKLM\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG10\Firefox4\ [2011-05-23 09:30:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011-05-22 08:10:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011-05-13 13:28:20 | 000,000,000 | ---D | M]
 
[2009-09-15 18:52:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Extensions
[2011-05-23 10:35:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions
[2010-03-26 20:52:02 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010-04-28 02:14:56 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010-10-16 19:08:38 | 000,000,000 | ---D | M] (Mega Manager Integration) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\{40a1f5d7-afc2-498f-b264-02668d616ff6}
[2011-05-13 12:02:17 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010-10-16 17:16:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}-trash
[2011-02-05 04:56:53 | 000,000,000 | ---D | M] (uTorrentBar_PT Community Toolbar) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\{e0301295-ab3e-4af3-979f-3d453c5f9f48}
[2011-04-13 15:45:04 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011-02-24 19:28:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\DefaultManager@Microsoft-trash
[2011-02-05 04:56:53 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\[email protected]
[2010-01-08 18:50:26 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\[email protected]
[2011-05-09 02:51:30 | 000,000,000 | ---D | M] ("Firefox Stats") -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\[email protected]
[2009-12-10 04:56:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\[email protected]
[2011-03-08 20:59:48 | 000,000,000 | ---D | M] (vShare) -- C:\Users\Ramiro\AppData\Roaming\mozilla\Firefox\Profiles\nfxw56s1.default\extensions\vshare@toolbar
[2011-02-24 16:42:49 | 000,001,832 | ---- | M] () -- C:\Users\Ramiro\AppData\Roaming\Mozilla\Firefox\Profiles\nfxw56s1.default\searchplugins\bing.xml
[2010-11-06 10:34:49 | 000,010,017 | ---- | M] () -- C:\Users\Ramiro\AppData\Roaming\Mozilla\Firefox\Profiles\nfxw56s1.default\searchplugins\mywebsearch.xml
[2011-05-23 10:35:12 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2010-07-04 15:24:58 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010-11-02 22:16:06 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011-02-14 20:45:25 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011-02-26 11:07:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011-05-23 09:30:59 | 000,000,000 | ---D | M] (No name found) -- C:\PROGRAM FILES (X86)\AVG\AVG10\FIREFOX4
[2011-02-26 11:07:04 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011-03-05 20:56:29 | 000,001,525 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011-03-05 20:56:29 | 000,001,529 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\priberam.xml
[2011-03-05 20:56:29 | 000,002,071 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\sapo.xml
[2011-03-05 20:56:29 | 000,000,942 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-ptpt.xml
[2011-03-05 20:56:29 | 000,000,953 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-br.xml
 
O1 HOSTS File: ([2010-02-03 05:23:09 | 000,000,761 | R--- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1       localhost
O1 - Hosts: ::1             localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E0301295-AB3E-4AF3-979F-3D453C5F9F48} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY]  File not found
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.113.164.5 212.113.164.6
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programas\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Ramiro\AppData\Roaming\Microsoft\Windows DreamScene\DreamScene.jpg
O24 - Desktop BackupWallPaper: C:\Users\Ramiro\AppData\Roaming\Microsoft\Windows DreamScene\DreamScene.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-11-04 03:29:28 | 000,000,042 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{756deaa4-448e-11de-910d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{756deaa4-448e-11de-910d-806e6f6e6963}\Shell\AutoRun\command - "" = E:\acer.exe -- [2010-11-04 03:29:27 | 005,771,438 | R--- | M] (Adobe Systems, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) -  File not found
O34 - HKLM BootExecute: (lsdelete) -  File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
========== Files/Folders - Created Within 30 Days ==========
 
[2011-05-23 19:08:35 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\Ramiro\Desktop\OTL.exe
[2011-05-23 09:41:45 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2011-05-23 09:41:45 | 000,000,000 | ---D | C] -- C:\Programas\AVAST Software
[2011-05-23 07:25:15 | 000,606,738 | R--- | C] (Swearware) -- C:\Users\Ramiro\Desktop\dds.scr.scr
[2011-05-22 19:43:33 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Roaming\Pixel Studio Pro
[2011-05-22 19:43:26 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pixel Studio Pro
[2011-05-22 19:43:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pixel
[2011-05-22 18:11:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011-05-22 18:11:20 | 007,734,208 | ---- | C] (Malwarebytes Corporation                                    ) -- C:\Users\Ramiro\Desktop\mbam-setup-1.50.1.1100.exe
[2011-05-22 18:10:47 | 003,063,136 | ---- | C] (Piriform Ltd) -- C:\Users\Ramiro\Desktop\ccsetup306.exe
[2011-05-22 04:29:59 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\Desktop\INVedit
[2011-05-22 04:02:18 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Roaming\SUPERAntiSpyware.com
[2011-05-22 04:02:18 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011-05-22 04:02:16 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011-05-22 04:02:16 | 000,000,000 | ---D | C] -- C:\ProgramData\!SASCORE
[2011-05-22 04:02:13 | 000,000,000 | ---D | C] -- C:\Programas\SUPERAntiSpyware
[2011-05-22 03:55:46 | 011,207,392 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Ramiro\Desktop\SUPERAntiSpyware.exe
[2011-05-22 02:09:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis
[2011-05-22 02:09:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2011-05-22 02:02:28 | 000,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Users\Ramiro\Desktop\HJTInstall.exe
[2011-05-22 00:16:18 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\Desktop\Nova pasta
[2011-05-21 23:17:42 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{2BAF77D5-4390-44F8-B5FF-3242B7325071}
[2011-05-21 05:55:49 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\Desktop\MCRedstoneSim22
[2011-05-20 10:15:59 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{61B20B5E-A996-4820-8FEE-F7CC5D9ECD5E}
[2011-05-20 10:15:14 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{0C2C9ED8-28E8-46F9-AC52-D8E93503476C}
[2011-05-20 06:20:53 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\Desktop\World3
[2011-05-19 23:16:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Codec Pack - All In 1
[2011-05-19 22:37:14 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\Desktop\Estática
[2011-05-19 20:20:00 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\Desktop\_Sol(1)[1].Prob.Estática2
[2011-05-19 20:07:47 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{1007B654-7E70-4F19-BACA-DC20F98A555F}
[2011-05-19 04:34:55 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{8377A6F3-1694-45DC-B476-97567D2D5F58}
[2011-05-18 16:34:28 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{AD488AED-95FE-4A07-9DF4-B91644C3A906}
[2011-05-15 10:41:30 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Roaming\.minecraft
[2011-05-15 10:24:18 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\Desktop\DarowsMinecraftBeta1.5_01
[2011-05-14 22:36:47 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\Desktop\ftool212win
[2011-05-14 22:27:44 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{EC408EBE-FF1E-411B-94ED-D6E315A89AC2}
[2011-05-13 14:38:14 | 000,345,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
[2011-05-13 14:36:51 | 010,126,824 | ---- | C] (Microsoft Corporation) -- C:\Users\Ramiro\Desktop\mseinstall.exe
[2011-05-13 14:30:47 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW
[2011-05-13 14:18:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2011
[2011-05-13 14:13:15 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011-05-13 14:13:15 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011-05-13 13:12:55 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011-05-13 13:10:10 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msls31.dll
[2011-05-13 13:10:09 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2011-05-13 13:10:09 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2011-05-13 13:10:09 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2011-05-13 13:10:09 | 000,353,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft.dll
[2011-05-13 13:10:09 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtrans.dll
[2011-05-13 13:10:09 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011-05-13 13:10:09 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2011-05-13 13:10:09 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2011-05-13 13:10:09 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011-05-13 13:10:09 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011-05-13 13:10:09 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2011-05-13 13:10:09 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2011-05-13 13:10:08 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2011-05-13 13:10:08 | 000,580,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2011-05-13 13:10:08 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011-05-13 13:10:08 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2011-05-13 13:10:08 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2011-05-13 13:10:08 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2011-05-13 13:10:08 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2011-05-13 13:10:08 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
[2011-05-13 13:10:08 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011-05-13 13:10:08 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2011-05-13 13:10:08 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2011-05-13 13:10:08 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2011-05-13 13:10:07 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
[2011-05-13 13:10:07 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011-05-13 13:10:07 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
[2011-05-13 13:10:07 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
[2011-05-13 13:10:07 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2011-05-13 13:10:07 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2011-05-13 13:10:07 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2011-05-13 13:10:07 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\advpack.dll
[2011-05-13 13:10:07 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2011-05-13 13:10:07 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
[2011-05-13 13:10:07 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2011-05-13 13:10:07 | 000,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\imgutil.dll
[2011-05-13 13:10:07 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2011-05-13 13:10:06 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
[2011-05-13 13:10:02 | 002,303,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011-05-13 13:10:02 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011-05-13 13:10:02 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll
[2011-05-13 13:10:02 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2011-05-13 13:10:02 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2011-05-13 13:10:02 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieakui.dll
[2011-05-13 13:10:02 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\admparse.dll
[2011-05-13 13:10:02 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011-05-13 13:10:02 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2011-05-13 13:10:02 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2011-05-13 13:10:01 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011-05-13 13:10:01 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieakeng.dll
[2011-05-13 13:10:01 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2011-05-13 13:10:01 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advpack.dll
[2011-05-13 13:10:01 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2011-05-13 13:10:01 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2011-05-13 13:10:01 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2011-05-13 13:10:01 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2011-05-13 13:10:01 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2011-05-13 13:10:01 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2011-05-13 13:10:00 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2011-05-13 13:10:00 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2011-05-13 13:10:00 | 000,452,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2011-05-13 13:10:00 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2011-05-13 13:10:00 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2011-05-13 13:10:00 | 000,236,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011-05-13 13:10:00 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2011-05-13 13:10:00 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2011-05-13 13:10:00 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2011-05-13 13:10:00 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2011-05-13 13:09:59 | 001,492,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2011-05-13 13:09:59 | 000,697,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2011-05-13 13:09:59 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2011-05-13 13:09:59 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2011-05-13 13:09:59 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2011-05-13 13:09:59 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011-05-13 13:09:59 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2011-05-13 13:09:58 | 000,603,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2011-05-13 13:09:58 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2011-05-13 13:09:58 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2011-05-13 13:09:57 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2011-05-13 12:13:55 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Roaming\Malwarebytes
[2011-05-13 12:12:44 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011-05-13 12:12:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011-05-13 12:12:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011-05-13 12:12:41 | 000,024,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011-05-13 12:12:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011-05-10 00:36:01 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\Desktop\MCE - Fichas
[2011-05-10 00:34:20 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\Desktop\MCE - Teórica
[2011-04-30 05:51:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011-04-30 05:51:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavasoft
[2011-04-30 05:51:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2011-04-27 14:17:52 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\Apps
[2011-04-27 10:52:01 | 001,653,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2011-04-27 10:52:01 | 000,876,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2011-04-27 10:51:59 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\GameUXLegacyGDFs.dll
[2011-04-27 10:51:59 | 004,240,384 | ---- | C] (Microsoft) -- C:\Windows\SysNative\GameUXLegacyGDFs.dll
[2011-04-27 10:51:59 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Apphlpdm.dll
[2011-04-27 10:51:59 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Apphlpdm.dll
[2011-04-26 20:07:58 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{912FB8D9-FACD-4A2A-AC41-7F433EF10046}
[2011-04-26 01:21:07 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{593A1866-40EB-4659-AE93-ECB6BF217821}
[2011-04-24 21:20:46 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{4F13303A-A8C9-4662-BF47-51F8FDB6D4ED}
[2011-04-23 21:08:10 | 000,000,000 | ---D | C] -- C:\Users\Ramiro\AppData\Local\{C10ED9FC-E1CB-4060-9439-DB4D6968E69E}
[3 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2011-05-23 19:08:47 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Ramiro\Desktop\OTL.exe
[2011-05-23 19:08:15 | 000,001,026 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1682711522-1043235145-2778782327-1002UA.job
[2011-05-23 19:05:30 | 000,001,356 | ---- | M] () -- C:\Users\Ramiro\AppData\Local\d3d9caps.dat
[2011-05-23 19:02:38 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011-05-23 19:02:38 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011-05-23 19:02:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011-05-23 09:40:46 | 056,923,744 | ---- | M] () -- C:\Users\Ramiro\Desktop\setup_av_free.exe
[2011-05-23 07:25:17 | 000,606,738 | R--- | M] (Swearware) -- C:\Users\Ramiro\Desktop\dds.scr.scr
[2011-05-23 02:46:44 | 000,243,200 | ---- | M] () -- C:\Users\Ramiro\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-05-22 20:22:17 | 000,002,374 | ---- | M] () -- C:\Users\Ramiro\Desktop\livre_1298767676.png
[2011-05-22 19:45:48 | 000,065,169 | ---- | M] () -- C:\Users\Ramiro\Desktop\SimboloFCP.jpg
[2011-05-22 19:43:28 | 000,000,822 | ---- | M] () -- C:\Users\Ramiro\Desktop\Pixel Studio Pro.lnk
[2011-05-22 19:34:19 | 014,296,495 | ---- | M] () -- C:\Users\Ramiro\Desktop\pixeldemo-1.0.740-win32.exe
[2011-05-22 19:18:43 | 000,005,846 | ---- | M] () -- C:\Users\Ramiro\Desktop\mario.jpg
[2011-05-22 18:22:23 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011-05-22 18:21:57 | 000,662,600 | ---- | M] () -- C:\Windows\SysNative\prfh0816.dat
[2011-05-22 18:21:57 | 000,598,702 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011-05-22 18:21:57 | 000,131,810 | ---- | M] () -- C:\Windows\SysNative\prfc0816.dat
[2011-05-22 18:21:57 | 000,104,716 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011-05-22 18:15:27 | 000,000,950 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011-05-22 18:11:49 | 000,000,858 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011-05-22 18:11:43 | 007,734,208 | ---- | M] (Malwarebytes Corporation                                    ) -- C:\Users\Ramiro\Desktop\mbam-setup-1.50.1.1100.exe
[2011-05-22 18:10:58 | 003,063,136 | ---- | M] (Piriform Ltd) -- C:\Users\Ramiro\Desktop\ccsetup306.exe
[2011-05-22 10:08:00 | 000,000,974 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1682711522-1043235145-2778782327-1002Core.job
[2011-05-22 08:11:26 | 439,891,648 | ---- | M] () -- C:\Users\Ramiro\Desktop\City of Angels [www.gamerpy.com].rmvb
[2011-05-22 05:03:16 | 001,506,662 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011-05-22 04:29:39 | 000,169,243 | ---- | M] () -- C:\Users\Ramiro\Desktop\INVedit.zip
[2011-05-22 04:02:16 | 000,001,758 | ---- | M] () -- C:\Users\Ramiro\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011-05-22 04:01:52 | 011,207,392 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Ramiro\Desktop\SUPERAntiSpyware.exe
[2011-05-22 02:09:49 | 000,001,930 | ---- | M] () -- C:\Users\Ramiro\Desktop\HijackThis.lnk
[2011-05-22 02:09:11 | 000,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Users\Ramiro\Desktop\HJTInstall.exe
[2011-05-22 02:02:05 | 001,385,298 | ---- | M] () -- C:\Users\Ramiro\Desktop\HijackThis.msi.part
[2011-05-22 01:53:18 | 000,000,000 | ---- | M] () -- C:\Users\Ramiro\Desktop\HijackThis.msi
[2011-05-22 01:07:20 | 000,003,032 | ---- | M] () -- C:\Users\Ramiro\Desktop\p3ramiro.pos
[2011-05-22 01:07:20 | 000,001,839 | ---- | M] () -- C:\Users\Ramiro\Desktop\p3ramiro.ftl
[2011-05-22 00:16:32 | 000,001,528 | ---- | M] () -- C:\Users\Ramiro\Desktop\paixaop4444.ftl
[2011-05-22 00:16:04 | 000,004,093 | ---- | M] () -- C:\Users\Ramiro\Desktop\Nova pasta.rar
[2011-05-22 00:15:56 | 000,000,194 | ---- | M] () -- C:\Users\Ramiro\Desktop\untitled1.2.html
[2011-05-21 23:59:54 | 001,518,652 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011-05-21 05:53:59 | 000,171,369 | ---- | M] () -- C:\Users\Ramiro\Desktop\MCRedstoneSim22.zip
[2011-05-20 10:56:36 | 000,003,106 | ---- | M] () -- C:\Users\Ramiro\Desktop\micael.pos
[2011-05-20 10:56:36 | 000,001,876 | ---- | M] () -- C:\Users\Ramiro\Desktop\micael.ftl
[2011-05-20 10:08:48 | 000,003,085 | ---- | M] () -- C:\Users\Ramiro\Desktop\untitled.pos
[2011-05-20 06:36:07 | 005,902,038 | ---- | M] () -- C:\Users\Ramiro\Desktop\Rollercoaster v1.1.rar
[2011-05-20 04:36:00 | 004,956,886 | ---- | M] () -- C:\Users\Ramiro\Desktop\World3.zip
[2011-05-20 04:19:55 | 005,894,831 | ---- | M] () -- C:\Users\Ramiro\Desktop\Darknetix-Best_MineCraft_Save_Ever!!!.rar
[2011-05-19 23:15:55 | 000,737,280 | ---- | M] (Indigo Rose Corporation) -- C:\Windows\iun6002.exe
[2011-05-19 22:51:04 | 000,003,308 | ---- | M] () -- C:\Users\Ramiro\Desktop\teste.pos
[2011-05-19 22:51:04 | 000,001,893 | ---- | M] () -- C:\Users\Ramiro\Desktop\teste.ftl
[2011-05-19 22:36:58 | 001,638,537 | ---- | M] () -- C:\Users\Ramiro\Desktop\Estática.zip
[2011-05-19 02:39:15 | 000,001,828 | ---- | M] () -- C:\Users\Ramiro\Desktop\Rainbow Man.png
[2011-05-19 02:35:02 | 596,822,429 | ---- | M] () -- C:\Users\Ramiro\Desktop\PACAD.2010.en.rar
[2011-05-19 01:26:25 | 000,003,010 | ---- | M] () -- C:\Users\Ramiro\Desktop\untitled2.pos
[2011-05-19 01:26:25 | 000,003,010 | ---- | M] () -- C:\Users\Ramiro\Desktop\untitled2 - Cópia.pos
[2011-05-19 01:26:25 | 000,001,614 | ---- | M] () -- C:\Users\Ramiro\Desktop\untitled2micael.ftl
[2011-05-19 01:26:25 | 000,001,614 | ---- | M] () -- C:\Users\Ramiro\Desktop\untitled2.ftl
[2011-05-19 01:26:25 | 000,001,614 | ---- | M] () -- C:\Users\Ramiro\Desktop\untitled2 - Cópia.ftl
[2011-05-19 01:22:22 | 000,003,011 | ---- | M] () -- C:\Users\Ramiro\Desktop\exercicioest2.pos
[2011-05-19 01:22:22 | 000,001,627 | ---- | M] () -- C:\Users\Ramiro\Desktop\exercicioest2.ftl
[2011-05-19 00:37:07 | 000,003,085 | ---- | M] () -- C:\aaa.pos
[2011-05-19 00:37:07 | 000,001,847 | ---- | M] () -- C:\aaa.ftl
[2011-05-19 00:34:12 | 000,003,085 | ---- | M] () -- C:\Users\Ramiro\Desktop\exercicioESTATICA.pos
[2011-05-19 00:34:12 | 000,001,810 | ---- | M] () -- C:\Users\Ramiro\Desktop\exercicioESTATICA.ftl
[2011-05-19 00:23:21 | 000,001,847 | ---- | M] () -- C:\Users\Ramiro\Desktop\untitled.ftl
[2011-05-18 17:50:05 | 000,001,892 | ---- | M] () -- C:\Users\Ramiro\Desktop\exercicioest1.ftl
[2011-05-18 17:50:05 | 000,001,530 | ---- | M] () -- C:\Users\Ramiro\Desktop\exercicioest1.pos
[2011-05-18 17:50:05 | 000,001,470 | ---- | M] () -- C:\Users\Ramiro\Desktop\exercicioest1.dat
[2011-05-17 15:59:59 | 000,000,456 | ---- | M] () -- C:\Windows\tasks\PCDRScheduledMaintenance.job
[2011-05-15 10:21:53 | 044,770,360 | ---- | M] () -- C:\Users\Ramiro\Desktop\DarowsMinecraftBeta1.5_01.zip
[2011-05-15 00:58:25 | 000,040,795 | ---- | M] () -- C:\Users\Ramiro\Desktop\backstabbers.png
[2011-05-14 22:46:45 | 000,041,866 | ---- | M] () -- C:\Users\Ramiro\Desktop\_Sol(1)[1].Prob.Estática2.zip
[2011-05-14 22:36:48 | 003,211,264 | ---- | M] () -- C:\Users\Ramiro\Desktop\Ftool.exe
[2011-05-14 22:36:38 | 001,162,962 | ---- | M] () -- C:\Users\Ramiro\Desktop\ftool212win.zip
[2011-05-14 21:13:05 | 000,270,142 | ---- | M] () -- C:\Users\Ramiro\Desktop\Minecraft.exe
[2011-05-14 12:17:29 | 114,957,371 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011-05-13 14:36:51 | 010,126,824 | ---- | M] (Microsoft Corporation) -- C:\Users\Ramiro\Desktop\mseinstall.exe
[2011-05-13 14:09:47 | 000,000,975 | ---- | M] () -- C:\Users\Ramiro\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011-05-13 13:10:24 | 000,008,798 | ---- | M] () -- C:\Windows\SysWow64\icrav03.rat
[2011-05-13 13:10:24 | 000,008,798 | ---- | M] () -- C:\Windows\SysNative\icrav03.rat
[2011-05-13 13:10:24 | 000,001,988 | ---- | M] () -- C:\Windows\SysWow64\ticrf.rat
[2011-05-13 13:10:24 | 000,001,988 | ---- | M] () -- C:\Windows\SysNative\ticrf.rat
[2011-05-13 13:10:10 | 000,161,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msls31.dll
[2011-05-13 13:10:09 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2011-05-13 13:10:09 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2011-05-13 13:10:09 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2011-05-13 13:10:09 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtmsft.dll
[2011-05-13 13:10:09 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\dxtrans.dll
[2011-05-13 13:10:09 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011-05-13 13:10:09 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2011-05-13 13:10:09 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2011-05-13 13:10:09 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011-05-13 13:10:09 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011-05-13 13:10:09 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2011-05-13 13:10:09 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2011-05-13 13:10:08 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2011-05-13 13:10:08 | 000,580,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2011-05-13 13:10:08 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011-05-13 13:10:08 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2011-05-13 13:10:08 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2011-05-13 13:10:08 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2011-05-13 13:10:08 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2011-05-13 13:10:08 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
[2011-05-13 13:10:08 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2011-05-13 13:10:08 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011-05-13 13:10:08 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2011-05-13 13:10:08 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2011-05-13 13:10:08 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2011-05-13 13:10:07 | 001,797,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9.dll
[2011-05-13 13:10:07 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011-05-13 13:10:07 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
[2011-05-13 13:10:07 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
[2011-05-13 13:10:07 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2011-05-13 13:10:07 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2011-05-13 13:10:07 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2011-05-13 13:10:07 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\advpack.dll
[2011-05-13 13:10:07 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2011-05-13 13:10:07 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
[2011-05-13 13:10:07 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2011-05-13 13:10:07 | 000,035,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\imgutil.dll
[2011-05-13 13:10:07 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2011-05-13 13:10:06 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
[2011-05-13 13:10:02 | 002,303,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011-05-13 13:10:02 | 000,818,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011-05-13 13:10:02 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll
[2011-05-13 13:10:02 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2011-05-13 13:10:02 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2011-05-13 13:10:02 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieakui.dll
[2011-05-13 13:10:02 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\admparse.dll
[2011-05-13 13:10:02 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011-05-13 13:10:02 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2011-05-13 13:10:02 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2011-05-13 13:10:01 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011-05-13 13:10:01 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieakeng.dll
[2011-05-13 13:10:01 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2011-05-13 13:10:01 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\advpack.dll
[2011-05-13 13:10:01 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2011-05-13 13:10:01 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2011-05-13 13:10:01 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2011-05-13 13:10:01 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2011-05-13 13:10:01 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2011-05-13 13:10:01 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2011-05-13 13:10:00 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2011-05-13 13:10:00 | 000,534,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2011-05-13 13:10:00 | 000,452,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2011-05-13 13:10:00 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2011-05-13 13:10:00 | 000,282,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2011-05-13 13:10:00 | 000,236,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011-05-13 13:10:00 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2011-05-13 13:10:00 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2011-05-13 13:10:00 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2011-05-13 13:10:00 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2011-05-13 13:10:00 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2011-05-13 13:09:59 | 001,492,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2011-05-13 13:09:59 | 000,697,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2011-05-13 13:09:59 | 000,165,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2011-05-13 13:09:59 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2011-05-13 13:09:59 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2011-05-13 13:09:59 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011-05-13 13:09:59 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2011-05-13 13:09:58 | 000,603,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2011-05-13 13:09:58 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2011-05-13 13:09:58 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2011-05-13 13:09:57 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2011-05-13 08:27:13 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2011-05-13 08:27:13 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2011-05-13 08:25:55 | 000,236,688 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011-05-12 01:06:47 | 000,000,897 | ---- | M] () -- C:\Users\Ramiro\Desktop\TABTRIG.8xp
[2011-05-09 22:49:30 | 000,002,419 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011-05-08 20:10:18 | 000,000,600 | ---- | M] () -- C:\Users\Ramiro\AppData\Local\PUTTY.RND
[2011-04-30 05:53:27 | 000,016,432 | ---- | M] () -- C:\Windows\SysNative\lsdelete.exe
[2011-04-30 05:51:42 | 000,000,969 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[3 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2011-05-23 09:38:45 | 056,923,744 | ---- | C] () -- C:\Users\Ramiro\Desktop\setup_av_free.exe
[2011-05-22 20:22:17 | 000,002,374 | ---- | C] () -- C:\Users\Ramiro\Desktop\livre_1298767676.png
[2011-05-22 19:45:48 | 000,065,169 | ---- | C] () -- C:\Users\Ramiro\Desktop\SimboloFCP.jpg
[2011-05-22 19:43:28 | 000,000,822 | ---- | C] () -- C:\Users\Ramiro\Desktop\Pixel Studio Pro.lnk
[2011-05-22 19:34:06 | 014,296,495 | ---- | C] () -- C:\Users\Ramiro\Desktop\pixeldemo-1.0.740-win32.exe
[2011-05-22 19:18:43 | 000,005,846 | ---- | C] () -- C:\Users\Ramiro\Desktop\mario.jpg
[2011-05-22 18:11:49 | 000,000,858 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011-05-22 08:04:09 | 439,891,648 | ---- | C] () -- C:\Users\Ramiro\Desktop\City of Angels [www.gamerpy.com].rmvb
[2011-05-22 04:28:15 | 000,169,243 | ---- | C] () -- C:\Users\Ramiro\Desktop\INVedit.zip
[2011-05-22 04:02:16 | 000,001,758 | ---- | C] () -- C:\Users\Ramiro\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011-05-22 02:09:49 | 000,001,930 | ---- | C] () -- C:\Users\Ramiro\Desktop\HijackThis.lnk
[2011-05-22 01:53:18 | 000,000,000 | ---- | C] () -- C:\Users\Ramiro\Desktop\HijackThis.msi
[2011-05-22 01:50:34 | 001,385,298 | ---- | C] () -- C:\Users\Ramiro\Desktop\HijackThis.msi.part
[2011-05-22 00:16:32 | 000,001,528 | ---- | C] () -- C:\Users\Ramiro\Desktop\paixaop4444.ftl
[2011-05-22 00:16:04 | 000,004,093 | ---- | C] () -- C:\Users\Ramiro\Desktop\Nova pasta.rar
[2011-05-22 00:15:54 | 000,000,194 | ---- | C] () -- C:\Users\Ramiro\Desktop\untitled1.2.html
[2011-05-21 05:53:58 | 000,171,369 | ---- | C] () -- C:\Users\Ramiro\Desktop\MCRedstoneSim22.zip
[2011-05-21 03:49:09 | 000,003,032 | ---- | C] () -- C:\Users\Ramiro\Desktop\p3ramiro.pos
[2011-05-21 03:49:09 | 000,001,839 | ---- | C] () -- C:\Users\Ramiro\Desktop\p3ramiro.ftl
[2011-05-20 10:08:48 | 000,003,085 | ---- | C] () -- C:\Users\Ramiro\Desktop\untitled.pos
[2011-05-20 09:48:10 | 000,003,106 | ---- | C] () -- C:\Users\Ramiro\Desktop\micael.pos
[2011-05-20 09:48:08 | 000,001,876 | ---- | C] () -- C:\Users\Ramiro\Desktop\micael.ftl
[2011-05-20 06:35:57 | 005,902,038 | ---- | C] () -- C:\Users\Ramiro\Desktop\Rollercoaster v1.1.rar
[2011-05-20 04:35:29 | 004,956,886 | ---- | C] () -- C:\Users\Ramiro\Desktop\World3.zip
[2011-05-20 04:18:04 | 005,894,831 | ---- | C] () -- C:\Users\Ramiro\Desktop\Darknetix-Best_MineCraft_Save_Ever!!!.rar
[2011-05-19 22:36:58 | 001,638,537 | ---- | C] () -- C:\Users\Ramiro\Desktop\Estática.zip
[2011-05-19 22:16:34 | 000,001,614 | ---- | C] () -- C:\Users\Ramiro\Desktop\untitled2micael.ftl
[2011-05-19 22:04:15 | 000,003,308 | ---- | C] () -- C:\Users\Ramiro\Desktop\teste.pos
[2011-05-19 22:04:15 | 000,001,893 | ---- | C] () -- C:\Users\Ramiro\Desktop\teste.ftl
[2011-05-19 16:49:37 | 000,003,010 | ---- | C] () -- C:\Users\Ramiro\Desktop\untitled2 - Cópia.pos
[2011-05-19 16:49:37 | 000,001,614 | ---- | C] () -- C:\Users\Ramiro\Desktop\untitled2 - Cópia.ftl
[2011-05-19 02:39:15 | 000,001,828 | ---- | C] () -- C:\Users\Ramiro\Desktop\Rainbow Man.png
[2011-05-19 01:37:35 | 596,822,429 | ---- | C] () -- C:\Users\Ramiro\Desktop\PACAD.2010.en.rar
[2011-05-19 00:59:49 | 000,003,010 | ---- | C] () -- C:\Users\Ramiro\Desktop\untitled2.pos
[2011-05-19 00:56:04 | 000,001,614 | ---- | C] () -- C:\Users\Ramiro\Desktop\untitled2.ftl
[2011-05-19 00:37:07 | 000,003,085 | ---- | C] () -- C:\aaa.pos
[2011-05-19 00:37:07 | 000,001,847 | ---- | C] () -- C:\aaa.ftl
[2011-05-19 00:23:09 | 000,001,847 | ---- | C] () -- C:\Users\Ramiro\Desktop\untitled.ftl
[2011-05-18 23:33:25 | 000,003,011 | ---- | C] () -- C:\Users\Ramiro\Desktop\exercicioest2.pos
[2011-05-18 18:08:54 | 000,003,085 | ---- | C] () -- C:\Users\Ramiro\Desktop\exercicioESTATICA.pos
[2011-05-18 18:08:54 | 000,001,810 | ---- | C] () -- C:\Users\Ramiro\Desktop\exercicioESTATICA.ftl
[2011-05-18 17:48:36 | 000,001,530 | ---- | C] () -- C:\Users\Ramiro\Desktop\exercicioest1.pos
[2011-05-18 17:48:36 | 000,001,470 | ---- | C] () -- C:\Users\Ramiro\Desktop\exercicioest1.dat
[2011-05-15 10:19:53 | 044,770,360 | ---- | C] () -- C:\Users\Ramiro\Desktop\DarowsMinecraftBeta1.5_01.zip
[2011-05-15 00:58:25 | 000,040,795 | ---- | C] () -- C:\Users\Ramiro\Desktop\backstabbers.png
[2011-05-15 00:12:09 | 000,001,627 | ---- | C] () -- C:\Users\Ramiro\Desktop\exercicioest2.ftl
[2011-05-14 23:30:38 | 000,001,892 | ---- | C] () -- C:\Users\Ramiro\Desktop\exercicioest1.ftl
[2011-05-14 22:46:45 | 000,041,866 | ---- | C] () -- C:\Users\Ramiro\Desktop\_Sol(1)[1].Prob.Estática2.zip
[2011-05-14 22:36:33 | 001,162,962 | ---- | C] () -- C:\Users\Ramiro\Desktop\ftool212win.zip
[2011-05-14 21:13:04 | 000,270,142 | ---- | C] () -- C:\Users\Ramiro\Desktop\Minecraft.exe
[2011-05-13 14:41:42 | 000,001,912 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011-05-13 13:10:08 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2011-05-13 13:10:00 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2011-05-13 12:12:44 | 000,000,950 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011-05-12 01:06:47 | 000,000,897 | ---- | C] () -- C:\Users\Ramiro\Desktop\TABTRIG.8xp
[2011-05-10 05:52:53 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011-05-10 05:52:53 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011-04-30 06:26:57 | 000,016,432 | ---- | C] () -- C:\Windows\SysNative\lsdelete.exe
[2011-04-30 05:51:42 | 000,000,969 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2011-03-07 20:10:29 | 000,000,600 | ---- | C] () -- C:\Users\Ramiro\AppData\Local\PUTTY.RND
[2010-12-21 03:27:20 | 000,001,105 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010-11-03 20:28:45 | 000,143,864 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2010-10-05 22:17:52 | 001,518,652 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010-07-16 20:44:23 | 000,000,000 | ---- | C] () -- C:\ProgramData\3960018112
[2010-07-14 20:43:47 | 000,000,000 | ---- | C] () -- C:\ProgramData\3128923618
[2010-07-14 11:53:14 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010-07-13 23:26:05 | 000,000,000 | ---- | C] () -- C:\ProgramData\2677997683
[2010-07-13 02:25:05 | 000,000,000 | ---- | C] () -- C:\ProgramData\2022031000
[2010-07-11 22:57:19 | 000,000,000 | ---- | C] () -- C:\ProgramData\479065052
[2010-07-09 22:16:41 | 000,000,000 | ---- | C] () -- C:\ProgramData\3753761618
[2010-07-09 20:04:40 | 000,041,872 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2010-07-08 23:27:18 | 000,000,000 | ---- | C] () -- C:\ProgramData\3932246234
[2010-07-08 18:21:54 | 000,000,000 | ---- | C] () -- C:\ProgramData\561810586
[2010-07-08 18:15:39 | 000,000,000 | ---- | C] () -- C:\ProgramData\1532693532
[2010-07-08 18:15:10 | 000,000,000 | ---- | C] () -- C:\ProgramData\1736043003
[2010-07-08 18:05:51 | 000,000,000 | ---- | C] () -- C:\ProgramData\3261860909
[2010-06-03 06:37:24 | 000,000,000 | ---- | C] () -- C:\ProgramData\2610168015
[2010-06-03 03:45:16 | 000,000,000 | ---- | C] () -- C:\ProgramData\2422947355
[2010-06-03 03:41:13 | 000,000,000 | ---- | C] () -- C:\ProgramData\2680800125
[2010-06-03 03:34:27 | 000,000,000 | ---- | C] () -- C:\ProgramData\4202166769
[2010-06-03 02:46:03 | 000,000,000 | ---- | C] () -- C:\ProgramData\3796208030
[2010-06-03 00:39:37 | 000,000,000 | ---- | C] () -- C:\ProgramData\3315461514
[2010-06-02 23:14:17 | 000,000,000 | ---- | C] () -- C:\ProgramData\2836823284
[2010-06-01 01:04:51 | 000,271,200 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010-06-01 01:04:51 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010-05-11 23:56:08 | 000,000,000 | ---- | C] () -- C:\ProgramData\3557768672
[2010-05-10 18:17:16 | 000,000,000 | ---- | C] () -- C:\ProgramData\2076479517
[2010-05-10 14:01:05 | 000,000,000 | ---- | C] () -- C:\ProgramData\2618299969
[2010-05-10 05:45:48 | 000,000,510 | ---- | C] () -- C:\Windows\wordpad.INI
[2010-05-10 05:03:32 | 000,000,000 | ---- | C] () -- C:\ProgramData\3336244796
[2010-05-09 05:53:53 | 000,000,000 | ---- | C] () -- C:\ProgramData\2266778060
[2010-05-09 01:04:16 | 000,000,000 | ---- | C] () -- C:\ProgramData\3573279311
[2010-05-08 21:50:47 | 000,000,000 | ---- | C] () -- C:\ProgramData\1182322599
[2010-05-08 01:27:11 | 000,000,000 | ---- | C] () -- C:\ProgramData\1907348517
[2010-05-07 23:39:31 | 000,000,000 | ---- | C] () -- C:\ProgramData\1572917460
[2010-05-06 23:37:10 | 000,000,000 | ---- | C] () -- C:\ProgramData\2659817469
[2010-05-06 21:29:10 | 000,000,000 | ---- | C] () -- C:\ProgramData\1909318870
[2010-05-06 19:28:11 | 000,000,000 | ---- | C] () -- C:\ProgramData\2649077057
[2010-05-06 19:04:44 | 000,000,000 | ---- | C] () -- C:\ProgramData\2674626008
[2010-05-06 02:30:40 | 000,000,000 | ---- | C] () -- C:\ProgramData\3910187123
[2010-05-05 23:50:53 | 000,000,000 | ---- | C] () -- C:\ProgramData\2501230040
[2010-05-05 21:34:11 | 000,000,000 | ---- | C] () -- C:\ProgramData\280395400
[2010-05-03 00:39:18 | 000,000,000 | ---- | C] () -- C:\ProgramData\1289102523
[2010-05-02 01:02:08 | 000,000,000 | ---- | C] () -- C:\ProgramData\4261205932
[2010-05-01 01:37:30 | 000,000,000 | ---- | C] () -- C:\ProgramData\1031708563
[2010-04-30 22:40:18 | 000,000,000 | ---- | C] () -- C:\ProgramData\1782638393
[2010-04-30 19:49:34 | 000,000,000 | ---- | C] () -- C:\ProgramData\458447532
[2010-04-30 19:38:14 | 000,000,000 | ---- | C] () -- C:\ProgramData\1431524218
[2010-04-30 03:45:54 | 000,000,000 | ---- | C] () -- C:\ProgramData\652983959
[2010-04-30 00:58:22 | 000,000,000 | ---- | C] () -- C:\ProgramData\1435226942
[2010-04-29 22:01:34 | 000,000,000 | ---- | C] () -- C:\ProgramData\4083023734
[2010-04-29 19:38:50 | 000,000,000 | ---- | C] () -- C:\ProgramData\3708157698
[2010-04-29 05:26:56 | 000,000,000 | ---- | C] () -- C:\ProgramData\2215393236
[2010-04-29 03:18:24 | 000,000,000 | ---- | C] () -- C:\ProgramData\1359465149
[2010-04-29 02:51:51 | 000,000,000 | ---- | C] () -- C:\ProgramData\929510127
[2010-04-28 22:45:32 | 000,000,000 | ---- | C] () -- C:\ProgramData\871424518
[2010-04-28 22:07:31 | 000,000,000 | ---- | C] () -- C:\ProgramData\1819339477
[2010-04-28 21:47:40 | 000,000,000 | ---- | C] () -- C:\ProgramData\1995256862
[2010-04-27 22:52:46 | 000,000,000 | ---- | C] () -- C:\ProgramData\401540024
[2010-04-27 18:28:10 | 000,000,000 | ---- | C] () -- C:\ProgramData\929482734
[2010-04-27 18:23:41 | 000,000,000 | ---- | C] () --
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 23, 2011, 12:16:41 PM
OTL Extras logfile created on: 23-05-2011 19:10:51 - Run 1
OTL by OldTimer - Version 3.2.23.0     Folder = C:\Users\Ramiro\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy
 
5,00 Gb Total Physical Memory | 3,29 Gb Available Physical Memory | 65,75% Memory free
10,14 Gb Paging File | 8,53 Gb Available in Paging File | 84,17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 915,76 Gb Total Space | 128,62 Gb Free Space | 14,05% Space Free | Partition Type: NTFS
Drive D: | 10,76 Gb Total Space | 1,58 Gb Free Space | 14,70% Space Free | Partition Type: NTFS
Drive E: | 230,58 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
 
Computer Name: TRINCA-NA-PÊRA | User Name: Ramiro | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] -- C:\Program Files (x86)\Opera\Opera.exe (Opera Software)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" File not found
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
https [open] -- "C:\Program Files (x86)\Opera\Opera.exe" "%1" (Opera Software)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L"
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AntiVirusDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01  [binary data]
"VistaSp2" = 02 35 A2 C8 E1 A2 CA 01  [binary data]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{17B64440-B824-4FEA-9A5E-EF0819044D6C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{244F102A-0DD9-415B-83DF-3C1C84946F7F}" = lport=49161 | protocol=6 | dir=in | name=akamai netsession interface |
"{3301B4E0-95C4-4112-976F-836D9ABE81CA}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{53555E8D-FC02-490A-B053-F8CB9ECFDC79}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{94E65D5B-0015-4799-A426-CA4A242A3C31}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{A5474B44-5644-4A15-A934-073997B55D28}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{F147512D-0862-4B35-81E7-5189DF926E61}" = lport=2869 | protocol=6 | dir=in | app=system |
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{080CB5E1-6B1C-4E33-8C31-6414353731B8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0AF8FBCF-E85D-4FB5-8842-042E53DD3B56}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{0D2877C1-00D9-4335-A4AA-582A57E846EB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty 4\iw3mp.exe |
"{0DCDFC0B-7C99-4A37-A6C9-0F44422B5BE4}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{0DE1D09C-86F1-40B0-897C-170146B755E2}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{12441626-70CD-4879-8B6D-07FA59CB80D9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{18F89E6A-6BEB-4A66-A450-96844F069D49}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{27AC9DD3-4962-45B3-B53D-3327FFC4EEA1}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{31D2B94A-FE79-4A1F-815F-31C423A2FB2D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"{360EEEB5-3B27-47D4-8054-3A3622ADC48E}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\tv\qpservice.exe |
"{3668C7B3-FF38-404A-85CC-3C723D2A4646}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\robsfiker\counter-strike\hl.exe |
"{3D7C8B4E-4796-4584-927C-A4B14BC685E7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\virtua tennis 2009\config.exe |
"{3ECFE3EC-F201-478C-B0DA-BCA9CA4D1C83}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{46A77BAB-6E06-4E76-8112-1E6AC51F54D3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4EBAFBF2-8E15-4E39-AB84-32589222F0AA}" = protocol=17 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{5871C738-145B-4DB8-8749-9004E64AE4EC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5F24CD40-0658-46CA-B2BA-6ECB3BFE7F3E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{6332F1A7-E5F1-424A-8D6B-3EA65D1F5DED}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{671A12DB-8718-4ED7-B4A0-251D4F57C900}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\tv\qp.exe |
"{68C7F7E5-FD49-4642-9AB4-A714433D8B60}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{68D403BA-D09F-49BB-89C8-62E83F656FF3}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{6A992663-11E2-4909-A404-284ECE884D82}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{6B18FA02-3FE5-4049-9F88-127BD977BBB6}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
"{6C5049F8-C144-4C14-907A-E58FA0AA29A8}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe |
"{7B90F0A1-FE5B-4FDA-91DC-B5BDABBBC733}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{7E81BE31-E35D-4910-928A-9B4887FE1C40}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{7FBE7EB0-A2A3-46AD-987B-CFEB27CFD912}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8400E309-370D-4BB3-A7BC-718D8D33A41C}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{854A3DAE-0521-4CAB-8AB6-FB870E59B328}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{876C0FE5-9F1A-4125-8B1A-90AA6D82FAE3}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{8B73EC94-A5AD-4FF3-BEF6-9ED74F263E67}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty 4\iw3sp.exe |
"{8D19F0F3-988C-425B-B06E-8DE8B82958C0}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe |
"{B0987716-5191-489F-9871-F9CF9583A4DE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\robsfiker\counter-strike\hl.exe |
"{B188CE00-90AF-4BFE-BD26-997D0B6CE8F9}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe |
"{B2AED131-4F1D-4843-A51E-639E9F58AEAC}" = dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{BA89F795-5C86-43CC-8C47-075B1E8C3071}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"{BB4537FC-830D-4659-9965-4DC072A28923}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{BB5DF0ED-2400-4292-979A-6EF52E8D4EF4}" = protocol=6 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{BCEF1EF1-245D-4944-AB02-8D1CD53793F6}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{C08921C5-1BDE-41A4-8A50-467B3A775ECF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C1CA0F7E-56A6-48CF-9C62-CED8F0E9B622}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgemca.exe |
"{C6738991-2C99-4F71-BC24-BA33906A549B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{C8A802E5-7040-45EF-84D5-80CB53D08B78}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{CDC4C512-59F1-4A6A-AD96-2C3127FC920C}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgmfapx.exe |
"{CE834EE0-251C-401A-ADF0-37582B1E100C}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg10\avgdiagex.exe |
"{D170E97A-8DE6-484B-8921-A8E40DAF387F}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{D23E9985-2927-4724-84A0-178178E7CD11}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D35649CB-9416-486E-8267-7D96DB233840}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{D3BD1A49-D731-440E-A9F5-0E639E950ADD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{D4AB2E67-3EAA-483D-8230-7C8C29BCF8BF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty 4\iw3mp.exe |
"{D51A1B3B-C2F7-43D0-98C1-9B927FB7453F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\virtua tennis 2009\config.exe |
"{D6D462F2-F423-4C34-8592-5E293BFDDE3F}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"{D9A67B6E-89D5-4787-B387-AF8F7313762D}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{DB36B2BB-42DF-4DFB-A240-EA1244B25AF5}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{DF74388A-F111-41B0-8CF2-43D5A574BD76}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg10\avgnsa.exe |
"{E0028A84-579E-443C-939A-2C572F8D6F57}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{ED63E357-0CA9-4F63-A4F1-ACEAB4028B3B}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{EF738CE5-73E0-488A-ACA6-CDA2CD8D4F57}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{F18D0B9D-E866-4BA6-B994-52D20764902E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F3C4CC17-EEC5-4A89-AB11-4F9F55246E6F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{F3F4341C-61A3-4157-83A2-55ABB207077F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty 4\iw3sp.exe |
"{F74BF07C-5FE9-4679-B812-8CBDAD70C1C7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"TCP Query User{33B9A295-4B7B-4E36-A56F-E7398C8B8724}C:\program files (x86)\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mirc\mirc.exe |
"TCP Query User{926619FF-5DA9-4873-B8A5-59D2EA5FFBC3}C:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=6 | dir=in | app=c:\program files (x86)\tmnationsforever\tmforever.exe |
"TCP Query User{94409EDA-1BC8-4750-A70C-906788C2073B}C:\users\ramiro\desktop\xtreme9\xtreme9\mirc.exe" = protocol=6 | dir=in | app=c:\users\ramiro\desktop\xtreme9\xtreme9\mirc.exe |
"UDP Query User{1BA23329-65ED-49EE-9895-0D29D77E9BC6}C:\users\ramiro\desktop\xtreme9\xtreme9\mirc.exe" = protocol=17 | dir=in | app=c:\users\ramiro\desktop\xtreme9\xtreme9\mirc.exe |
"UDP Query User{482C4619-6DC3-4A47-B4A2-6E622990B793}C:\program files (x86)\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mirc\mirc.exe |
"UDP Query User{4E1F03AE-1ADD-4576-87FE-BF895494B494}C:\program files (x86)\tmnationsforever\tmforever.exe" = protocol=17 | dir=in | app=c:\program files (x86)\tmnationsforever\tmforever.exe |
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{17E02F38-FF2D-4c3d-83DF-ECE2A1D20A5E}" = AIO_CDB_ToolboxIni64
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{22441735-5983-AD2A-5CC5-FA2CCD7EF732}" = ATI Stream SDK v2 Developer
"{23236FC2-648D-4ACF-AD16-68492D0F0AC9}" = FileBox eXtender
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{42FBA9A9-A14D-3918-BFE1-4FC8FEDDEF5C}" = Microsoft .NET Framework 4 Client Profile PTG Language Pack
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{742DF898-7ABE-4CF4-8557-5D17C400D49C}" = AVG 2011
"{7B1DBCBE-DF17-3B58-844C-F572F70EF5C4}" = Microsoft .NET Framework 3.5 Language Pack SP1 - ptg
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F560BEB-021F-43AC-825F-AA60442D8DE4}" = 64 Bit HP CIO Components Installer
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{AE57C044-8912-A181-A0E4-BC2DAB3A092A}" = ATI Catalyst Install Manager
"{B24A47E5-F196-461E-A7A4-AADB72CB19DD}" = iTunes
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{D49110AD-34A7-485C-901D-DFBBFF70D3EC}" = AVG 2011
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
"{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F1568AA6-5982-4AFB-A871-C68E4328BC3B}" = HP MediaSmart SmartMenu
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"Microsoft .NET Framework 3.5 Language Pack SP1 - ptg" = Microsoft .NET Framework 3.5 Language Pack SP1 - PTG
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile PTG Language Pack" = Microsoft .NET Framework 4 Client Profile PTG Language Pack
"OfficeTrial" = Microsoft Office Casa e Estudantes 2007 Avaliação
"PC-Doctor for Windows" = Ferramentas de Diagnóstico de Hardware
"VistaGlazz_is1" = VistaGlazz 2.3
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0295F89F-F698-4101-9A7D-49F407EC2D82}" = HP Active Support Library
"{03BF5CB1-B72E-4CA6-A278-F65680F05420}" = HP Picasso Media Center Add-In
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B26A979-EC68-4624-A647-98A506CEE048}" = GoGear Mix Device Manager
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1CC069FA-1A86-402E-9787-3F04E652C67A}" = HP Support Information
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{23BE4DF2-293D-4077-82F4-1FD8C269277C}" = TuneUp Utilities Language Pack (en-US)
"{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24
"{2AD2DD70-27F7-4343-BB4E-DE50A32D854B}" = Windows Live Messenger
"{2B7E4354-0492-460A-BDB1-1F59EE141025}" = AirPlus G
"{2C33926E-9468-A9DD-0739-1708BF2A4070}" = Catalyst Control Center InstallProxy
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common
"{3889988F-762B-4B85-AB17-71C9CC3AE445}" = Messenger Companion
"{3A09ED0F-8DDF-47BB-B53D-841AB9D1D3A7}" = Complemento Messenger
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{43B43577-2514-4CE0-B14A-7E85C17C0453}" = Windows Live Essentials
"{4664ED39-C80A-48F7-93CD-EBDCAFAB6CC5}" = Windows Live Writer Resources
"{47F36D92-E58E-456D-B73C-3382737E4C42}" = HP Update
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{506FC723-8E6C-4417-9CFF-351F99130425}" = Windows Live UX Platform Language Pack
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79F86C69-2B17-4368-9234-472A23639E16}" = Ad-Aware
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{85B39C57-D7DA-4944-A6AB-F26894188B6B}" = GoGear Mix Device Manager
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{95A747E0-DF19-46CB-A622-20A0107201BD}" = HP Total Care Setup
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{99BEB67F-B288-44F5-8B2A-23F5F522A1AE}_is1" = Universal Anticheat 2 v2.42
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9CC89170-000B-457D-91F1-53691F85B223}" = Python 2.6.1
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DA3F03B-2CEE-4344-838E-117861E61FAF}" = Windows Live Mail
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A589DA26-51BD-475D-8C32-E19E34145842}" = Camtasia Studio 6
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1046-7B44-A94000000001}" = Adobe Reader 9.4.3 - Português
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B33B61FE-701F-425F-98AB-2B85725CBF68}" = Windows Live Photo Common
"{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C260343B-6282-42A2-939F-1FF7E503F608}" = Wolfram Notebook Indexer 2.0
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC29B835-95A5-3CD9-087B-F94D7B9ECC9B}" = Catalyst Control Center InstallProxy
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D54A52A8-DF24-4CE8-850B-074CA47DFA74}" = Windows Live Messenger
"{D722CF4B-4B06-BF11-FDEA-BD1B319FEA57}" = muvee Reveal
"{D7A1C3CB-1F27-4EAA-98DF-D266CA6B67D3}" = Microsoft Works
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources
"{DF71ABBB-B834-41C0-BB58-80B0545D754C}" = Windows Live UX Platform Language Pack
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1591139-8B44-411B-A81B-D35F83A0565A}" = HP Customer Experience Enhancements
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"12345_is1" = WeGame Client Public Beta 2.0
"Actual Transparent Windows_is1" = Actual Transparent Window 3.8
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FileBox eXtender" = FileBox eXtender
"FileZilla Client" = FileZilla Client 3.3.5.1
"HijackThis" = HijackThis 2.0.2
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"mIRC" = mIRC
"Mozilla Firefox (3.6.17)" = Mozilla Firefox (3.6.17)
"Opera 11.10.2092" = Opera 11.10
"PunkBusterSvc" = PunkBuster Services
"Steam App 10" = Counter-Strike
"Steam App 10690" = Virtua Tennis 2009
"Steam App 7940" = Call of Duty 4: Modern Warfare
"TuneUp Utilities 2011" = TuneUp Utilities 2011
"Veetle TV" = Veetle TV 0.9.18
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = Arquivo do WinRAR
"Xfire" = Xfire (remove only)
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 12-05-2011 18:31:17 | Computer Name = Trinca-na-pêra | Source = Application Error | ID = 1000
Description = Aplicação em falha firefox.exe, versão 1.9.2.4127, carimbo de data/hora
 0x4daf6302, módulo em falha unknown, versão 0.0.0.0, carimbo de data/hora 0x00000000,
 código de excepção 0xc0000005, desvio da falha 0x771b442a,  ID do processo 0x16e8,
 hora de início da aplicação 0x01cc10f44ec50401.
 
Error - 12-05-2011 18:39:27 | Computer Name = Trinca-na-pêra | Source = Application Error | ID = 1000
Description = Aplicação em falha RealPlay.exe, versão 12.0.0.301, carimbo de data/hora
 0x4a9ded49, módulo em falha unknown, versão 0.0.0.0, carimbo de data/hora 0x00000000,
 código de excepção 0xc0000005, desvio da falha 0x771b442a,  ID do processo 0x1fec,
 hora de início da aplicação 0x01cc10f57308cf31.
 
Error - 12-05-2011 18:40:07 | Computer Name = Trinca-na-pêra | Source = Application Error | ID = 1000
Description = Aplicação em falha avgcmgr.exe, versão 10.0.0.1160, carimbo de data/hora
 0x4cc0f41e, módulo em falha unknown, versão 0.0.0.0, carimbo de data/hora 0x00000000,
 código de excepção 0xc0000005, desvio da falha 0x771b442a,  ID do processo 0x4724,
 hora de início da aplicação 0x01cc10f58ae21851.
 
Error - 12-05-2011 18:48:38 | Computer Name = Trinca-na-pêra | Source = Application Error | ID = 1000
Description = Aplicação em falha DivXsm.exe, versão 0.0.0.0, carimbo de data/hora
 0x4383deef, módulo em falha unknown, versão 0.0.0.0, carimbo de data/hora 0x00000000,
 código de excepção 0xc0000005, desvio da falha 0x771b442a,  ID do processo 0x29c0,
 hora de início da aplicação 0x01cc10f6bbccdf31.
 
Error - 12-05-2011 18:52:50 | Computer Name = Trinca-na-pêra | Source = Application Error | ID = 1000
Description = Aplicação em falha msiexec.exe, versão 4.5.6002.18005, carimbo de
data/hora 0x49e01c42, módulo em falha unknown, versão 0.0.0.0, carimbo de data/hora
 0x00000000, código de excepção 0xc0000005, desvio da falha 0x771b442a,  ID do processo
 0x3aac, hora de início da aplicação 0x01cc10f751fb1991.
 
Error - 12-05-2011 18:52:59 | Computer Name = Trinca-na-pêra | Source = Application Error | ID = 1000
Description = Aplicação em falha steam.exe, versão 1.0.968.628, carimbo de data/hora
 0x4cda0db5, módulo em falha unknown, versão 0.0.0.0, carimbo de data/hora 0x00000000,
 código de excepção 0xc0000005, desvio da falha 0x771b442a,  ID do processo 0x3a50,
 hora de início da aplicação 0x01cc10f7577a4bc1.
 
Error - 12-05-2011 19:39:42 | Computer Name = Trinca-na-pêra | Source = Application Error | ID = 1000
Description = Aplicação em falha DivXsm.exe, versão 0.0.0.0, carimbo de data/hora
 0x4383deef, módulo em falha unknown, versão 0.0.0.0, carimbo de data/hora 0x00000000,
 código de excepção 0xc0000005, desvio da falha 0x7542a57d,  ID do processo 0x22fc4,
 hora de início da aplicação 0x01cc10fddd98f481.
 
Error - 12-05-2011 19:46:45 | Computer Name = Trinca-na-pêra | Source = Application Error | ID = 1000
Description = Aplicação em falha wmplayer.exe, versão 11.0.6002.18311, carimbo de
 data/hora 0x4c8e2d72, módulo em falha unknown, versão 0.0.0.0, carimbo de data/hora
 0x00000000, código de excepção 0xc0000005, desvio da falha 0x771b442a,  ID do processo
 0x240d0, hora de início da aplicação 0x01cc10fed9f4af31.
 
Error - 12-05-2011 19:54:21 | Computer Name = Trinca-na-pêra | Source = Application Error | ID = 1000
Description = Aplicação em falha RarExtLoader.exe, versão 0.0.0.0, carimbo de data/hora
 0x4a242929, módulo em falha unknown, versão 0.0.0.0, carimbo de data/hora 0x00000000,
 código de excepção 0xc0000005, desvio da falha 0x771b442a,  ID do processo 0x2e770,
 hora de início da aplicação 0x01cc10ffe9293e21.
 
Error - 12-05-2011 19:54:23 | Computer Name = Trinca-na-pêra | Source = Application Error | ID = 1000
Description = Aplicação em falha wermgr.exe, versão 6.0.6001.18000, carimbo de data/hora
 0x47918ca1, módulo em falha unknown, versão 0.0.0.0, carimbo de data/hora 0x00000000,
 código de excepção 0xc0000005, desvio da falha 0x771b442a,  ID do processo 0x2e828,
 hora de início da aplicação 0x01cc10ffeaa49381.
 
[ System Events ]
Error - 23-05-2011 13:05:40 | Computer Name = Trinca-na-pêra | Source = Service Control Manager | ID = 7001
Description =
 
Error - 23-05-2011 13:05:40 | Computer Name = Trinca-na-pêra | Source = Service Control Manager | ID = 7000
Description =
 
Error - 23-05-2011 13:05:40 | Computer Name = Trinca-na-pêra | Source = Service Control Manager | ID = 7009
Description =
 
Error - 23-05-2011 13:05:40 | Computer Name = Trinca-na-pêra | Source = Service Control Manager | ID = 7000
Description =
 
Error - 23-05-2011 13:05:40 | Computer Name = Trinca-na-pêra | Source = Service Control Manager | ID = 7009
Description =
 
Error - 23-05-2011 13:05:40 | Computer Name = Trinca-na-pêra | Source = Service Control Manager | ID = 7000
Description =
 
Error - 23-05-2011 13:05:40 | Computer Name = Trinca-na-pêra | Source = Service Control Manager | ID = 7026
Description =
 
Error - 23-05-2011 14:02:54 | Computer Name = Trinca-na-pêra | Source = Service Control Manager | ID = 7001
Description =
 
Error - 23-05-2011 14:02:54 | Computer Name = Trinca-na-pêra | Source = Service Control Manager | ID = 7000
Description =
 
Error - 23-05-2011 14:02:54 | Computer Name = Trinca-na-pêra | Source = Service Control Manager | ID = 7026
Description =
 
 
< End of report >
Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 23, 2011, 05:01:19 PM
The log shows that you only have 14.05% free space on your C drive. Windows requires 15% or more to function properly. You should keep an eye on this to make sure it doesn't drop any further or you could have problems like the one you're presently experiencing. You could transfer important documents, files, pictures, movies and music to one of your other drives.

* Open OTL
* Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

Code: [Select]
:OTL
IE - HKCU\..\URLSearchHook: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - Reg Error: Key error. File not found
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\MyWebSearch\bar\3.bin

:folders -- this is the command for deleting folders.
C:\Program Files (x86)\MyWebSearch

:COMMANDS
[resethosts]
[purity]
[emptytemp]
[start explorer]

* Click Run Fix
* OTLI2 may ask to reboot the machine. Please do so if asked.
* Click OK
* A report will open. Copy and Paste that report in your next reply.
*********************************************************
This next tool may not work with AVG on your computer. If you receive this message, please let me know and we'll do a work-around.

Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

link # 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link # 2 (http://subs.geekstogo.com/ComboFix.exe)
If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of security programs that should be disabled and how to disable them.

Right-click combofix.exe and select Run as Administrator and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix login your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 23, 2011, 06:55:20 PM
Thanks again for the answer.

I've been meaning to clean up the PC. Actually, before I even read your last reply I was doing just that. It should be fine now, the disk has over 30% free space.

OTC log:

All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{e0301295-ab3e-4af3-979f-3d453c5f9f48} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0301295-ab3e-4af3-979f-3d453c5f9f48}\ not found.
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected] deleted successfully.
File C:\Program Files (x86)\MyWebSearch\bar\3.bin not found.
Error: Unable to interpret <:folders -- this is the command for deleting folders.> in the current context!
Error: Unable to interpret <C:\Program Files (x86)\MyWebSearch> in the current context!
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
 
[EMPTYTEMP]
 
User: All Users
 
User: AppData
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: HP
->Temp folder emptied: 31832 bytes
->Temporary Internet Files folder emptied: 33572 bytes
->Java cache emptied: 1425920 bytes
 
User: HP(23)
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes
 
User: Public
 
User: Ramiro
->Temp folder emptied: 54447166 bytes
->Temporary Internet Files folder emptied: 295046 bytes
->Java cache emptied: 87818689 bytes
->FireFox cache emptied: 85165060 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 7351 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 1345856 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1665098 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33237 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 222,00 mb
 
 
OTL by OldTimer - Version 3.2.23.0 log created on 05242011_005640

Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\1FAF.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\59F1.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\SET886C.tmp scheduled to be moved on reboot.
File\Folder C:\Windows\SysNative\uxt3BB8.tmp not found!

Registry entries deleted on Reboot...

---

I can't RUN Combofix. As soon as I try to run it, it gets around 15 programs to stop working, i.e.

grep.cfxxe stopped working
NirCmd stopped working
pev.exe stopped working
Console IME stopped working
FireFox.exe stopped working
hidec.exe stopped working
Freeware implememntation of REG.EXE stopped working

etc.

(these aren't even supose to be running processes)

Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 24, 2011, 12:51:56 PM
P2P - I see you have P2P software installed on your machine (uTorrent). We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
**************************************************
Sorry. I made an error with the script. Please run this again

Download OTL (http://oldtimer.geekstogo.com/OTL.exe) to your desktop.

* Open OTL
* Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

Code: [Select]
:OTL
:folders
C:\Program Files (x86)\MyWebSearch

:COMMANDS
[resethosts]
[purity]
[emptytemp]
[start explorer]

* Click Run Fix
* OTLI2 may ask to reboot the machine. Please do so if asked.
* Click OK
* A report will open. Copy and Paste that report in your next reply.
**************************************************************
Please try this to get ComboFix to run.

Delete your copy of ComboFix; download a fresh copy, except before you download it, rename it to blackpudding.bat

Navigate to Start --> Run, and enter the following command exactly as shown:

"%userprofile%\desktop\blackpudding.bat" /killall

See if ComboFix will run now
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 24, 2011, 02:57:18 PM
I've used uTorrent like two times total and it's been removed from my HD for more than a week now afaik.

Anyway, I got a couple of blue screens while doing this, first one when coming back from reboot after OTL, second one was with ComboFix, which made me lose the log for OTL.

So I'll just start over from OTL.

OTL log:

All processes killed
========== OTL ==========
Error: Unable to interpret <:folders> in the current context!
Error: Unable to interpret <C:\Program Files (x86)\MyWebSearch> in the current context!
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
 
[EMPTYTEMP]
 
User: All Users
 
User: AppData
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: HP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
 
User: HP(23)
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
User: Ramiro
->Temp folder emptied: 2039998 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 20652346 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 456 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 1309696 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 11442 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 23,00 mb
 
 
OTL by OldTimer - Version 3.2.23.0 log created on 05242011_220000

Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\1FAF.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\59F1.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\SET886C.tmp scheduled to be moved on reboot.

Registry entries deleted on Reboot...

----

I'll edit this post in a few minutes with ComboFix log.
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 24, 2011, 03:51:40 PM
Combo Fix Log

ComboFix 11-05-24.01 - Ramiro 24-05-2011  22:14:06.1.4 - x64
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.351.2070.18.5118.3305 [GMT 1:00]
Executando de: c:\users\Ramiro\Desktop\blackpudding.bat.exe
Comandos utilizados :: /killall
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((   Outras Exclusões   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Ramiro\AppData\Roaming\chrtmp
.
.
((((((((((((((((   Arquivos/Ficheiros criados de 2011-04-24 to 2011-05-24  ))))))))))))))))))))))))))))
.
.
2011-05-24 21:33 . 2011-05-24 21:46   --------   d-----w-   c:\users\Ramiro\AppData\Local\temp
2011-05-24 21:33 . 2011-05-24 21:33   --------   d-----w-   c:\users\HP\AppData\Local\temp
2011-05-24 21:33 . 2011-05-24 21:33   --------   d-----w-   c:\users\HP(23)\AppData\Local\temp
2011-05-24 21:33 . 2011-05-24 21:33   --------   d-----w-   c:\users\Default\AppData\Local\temp
2011-05-24 20:47 . 2011-05-24 21:08   --------   d-----w-   C:\32788R22FWJFW
2011-05-24 15:35 . 2011-05-10 12:10   253888   ----a-w-   c:\windows\system32\aswBoot.exe
2011-05-24 13:47 . 2011-05-24 15:35   --------   d-----w-   C:\323c8cf74f4e74d64f240e
2011-05-24 01:41 . 2011-02-23 16:04   18232   ----a-w-   c:\windows\system32\drivers\SmartDefragDriver.sys
2011-05-24 01:41 . 2011-02-23 15:50   32648   ----a-w-   c:\windows\system32\SmartDefragBootTime.exe
2011-05-24 01:41 . 2011-05-24 01:41   --------   d-----w-   c:\users\Ramiro\AppData\Roaming\IObit
2011-05-24 01:40 . 2011-05-24 01:40   --------   d-----w-   c:\program files (x86)\IObit
2011-05-23 23:56 . 2011-05-23 23:56   --------   d-----w-   C:\_OTL
2011-05-23 21:28 . 2011-05-24 13:45   --------   d-----w-   c:\program files (x86)\SpeedFan
2011-05-23 08:41 . 2011-05-24 21:07   --------   d-----w-   c:\programdata\AVAST Software
2011-05-23 08:41 . 2011-05-24 13:47   --------   d-----w-   c:\program files\AVAST Software
2011-05-23 07:54 . 2011-05-18 11:37   8718160   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{29DA49A7-2CEB-458C-9088-E8E92338D65E}\mpengine.dll
2011-05-22 18:43 . 2011-05-22 18:50   --------   d-----w-   c:\users\Ramiro\AppData\Roaming\Pixel Studio Pro
2011-05-22 18:43 . 2011-05-22 18:43   --------   d-----w-   c:\program files (x86)\Pixel
2011-05-22 03:02 . 2011-05-22 03:02   --------   d-----w-   c:\users\Ramiro\AppData\Roaming\SUPERAntiSpyware.com
2011-05-22 03:02 . 2011-05-22 03:02   --------   d-----w-   c:\programdata\SUPERAntiSpyware.com
2011-05-22 03:02 . 2011-05-22 03:02   --------   d-----w-   c:\programdata\!SASCORE
2011-05-22 03:02 . 2011-05-24 00:38   --------   d-----w-   c:\program files\SUPERAntiSpyware
2011-05-22 01:09 . 2011-05-22 01:09   --------   d-----w-   c:\program files (x86)\Trend Micro
2011-05-21 22:17 . 2011-05-21 22:18   --------   d-----w-   c:\users\Ramiro\AppData\Local\{2BAF77D5-4390-44F8-B5FF-3242B7325071}
2011-05-20 09:15 . 2011-05-20 21:16   --------   d-----w-   c:\users\Ramiro\AppData\Local\{61B20B5E-A996-4820-8FEE-F7CC5D9ECD5E}
2011-05-20 09:15 . 2011-05-20 09:15   --------   d-----w-   c:\users\Ramiro\AppData\Local\{0C2C9ED8-28E8-46F9-AC52-D8E93503476C}
2011-05-19 22:16 . 2011-05-19 22:16   --------   d-----w-   c:\program files (x86)\Codec Pack - All In 1
2011-05-19 19:07 . 2011-05-19 19:08   --------   d-----w-   c:\users\Ramiro\AppData\Local\{1007B654-7E70-4F19-BACA-DC20F98A555F}
2011-05-19 03:34 . 2011-05-19 03:35   --------   d-----w-   c:\users\Ramiro\AppData\Local\{8377A6F3-1694-45DC-B476-97567D2D5F58}
2011-05-18 15:34 . 2011-05-18 15:34   --------   d-----w-   c:\users\Ramiro\AppData\Local\{AD488AED-95FE-4A07-9DF4-B91644C3A906}
2011-05-15 09:41 . 2011-05-19 01:12   --------   d-----w-   c:\users\Ramiro\AppData\Roaming\.minecraft
2011-05-14 21:27 . 2011-05-14 21:28   --------   d-----w-   c:\users\Ramiro\AppData\Local\{EC408EBE-FF1E-411B-94ED-D6E315A89AC2}
2011-05-13 13:38 . 2010-04-06 08:34   345984   ----a-w-   c:\windows\system32\drivers\netio.sys
2011-05-13 11:13 . 2011-05-13 11:13   --------   d-----w-   c:\users\Ramiro\AppData\Roaming\Malwarebytes
2011-05-13 11:12 . 2011-05-13 11:12   --------   d-----w-   c:\programdata\Malwarebytes
2011-05-13 11:12 . 2010-12-20 17:09   38224   ----a-w-   c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-05-13 11:12 . 2011-05-22 17:15   --------   d-----w-   c:\program files (x86)\Malwarebytes' Anti-Malware
2011-05-13 11:12 . 2010-12-20 17:08   24152   ----a-w-   c:\windows\system32\drivers\mbam.sys
2011-05-10 19:26 . 2011-04-07 12:02   2409784   ----a-w-   c:\program files\Windows Mail\OESpamFilter.dat
2011-05-10 19:26 . 2011-04-07 12:01   2409784   ----a-w-   c:\program files (x86)\Windows Mail\OESpamFilter.dat
2011-04-30 05:26 . 2011-04-30 04:53   16432   ----a-w-   c:\windows\system32\lsdelete.exe
2011-04-30 04:51 . 2011-04-30 04:51   --------   d-----w-   c:\program files (x86)\Lavasoft
2011-04-30 04:51 . 2011-04-30 04:51   --------   d-----w-   c:\programdata\Lavasoft
2011-04-27 13:17 . 2011-04-27 13:17   --------   d-----w-   c:\users\Ramiro\AppData\Local\Apps
2011-04-27 09:52 . 2011-03-12 22:52   1653760   ----a-w-   c:\windows\system32\XpsPrint.dll
2011-04-27 09:52 . 2011-03-12 21:55   876032   ----a-w-   c:\windows\SysWow64\XpsPrint.dll
2011-04-27 09:51 . 2011-03-03 15:59   32256   ----a-w-   c:\windows\system32\Apphlpdm.dll
2011-04-27 09:51 . 2011-03-03 15:40   28672   ----a-w-   c:\windows\SysWow64\Apphlpdm.dll
2011-04-27 09:51 . 2011-03-03 14:00   4240384   ----a-w-   c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-27 09:51 . 2011-03-03 13:35   4240384   ----a-w-   c:\windows\SysWow64\GameUXLegacyGDFs.dll
2011-04-26 19:07 . 2011-04-26 19:07   --------   d-----w-   c:\users\Ramiro\AppData\Local\{912FB8D9-FACD-4A2A-AC41-7F433EF10046}
2011-04-26 00:21 . 2011-04-26 00:21   --------   d-----w-   c:\users\Ramiro\AppData\Local\{593A1866-40EB-4659-AE93-ECB6BF217821}
.
.
.
(((((((((((((((((((((((((((((((((((((   Relatório Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-19 22:15 . 2009-09-15 22:35   737280   ----a-w-   c:\windows\iun6002.exe
2011-03-10 17:18 . 2011-04-13 10:54   1360384   ----a-w-   c:\windows\system32\mfc42u.dll
2011-03-10 17:18 . 2011-04-13 10:54   1398784   ----a-w-   c:\windows\system32\mfc42.dll
2011-03-10 17:03 . 2011-04-13 10:54   1162240   ----a-w-   c:\windows\SysWow64\mfc42u.dll
2011-03-10 17:03 . 2011-04-13 10:54   1136640   ----a-w-   c:\windows\SysWow64\mfc42.dll
2011-03-09 21:10 . 2010-06-24 11:33   18328   ----a-w-   c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-03 16:02 . 2011-04-13 10:55   975872   ----a-w-   c:\windows\system32\inetcomm.dll
2011-03-03 15:59 . 2011-04-27 09:51   100352   ----a-w-   c:\windows\apppatch\AppPatch64\acspecfc.dll
2011-03-03 15:59 . 2011-04-27 09:51   331776   ----a-w-   c:\windows\apppatch\AppPatch64\AcLayers.dll
2011-03-03 15:59 . 2011-04-27 09:51   284672   ----a-w-   c:\windows\apppatch\AppPatch64\AcGenral.dll
2011-03-03 15:42 . 2011-04-13 10:55   739328   ----a-w-   c:\windows\SysWow64\inetcomm.dll
2011-03-03 15:40 . 2011-04-27 09:51   173056   ----a-w-   c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-04-27 09:51   542720   ----a-w-   c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-04-27 09:51   458752   ----a-w-   c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-04-27 09:51   2159616   ----a-w-   c:\windows\apppatch\AcGenral.dll
2011-03-03 13:46 . 2011-04-13 10:54   2762240   ----a-w-   c:\windows\system32\win32k.sys
2011-03-02 16:12 . 2011-04-13 10:54   117760   ----a-w-   c:\windows\system32\dnsrslvr.dll
2011-02-26 10:07 . 2010-07-04 14:24   472808   ----a-w-   c:\windows\SysWow64\deployJava1.dll
2011-02-24 16:38 . 2011-04-13 10:55   991104   ----a-w-   c:\windows\system32\winresume.efi
2011-02-24 16:38 . 2011-04-13 10:55   979840   ----a-w-   c:\windows\system32\winresume.exe
2011-02-24 16:37 . 2011-04-13 10:55   1076608   ----a-w-   c:\windows\system32\winload.efi
2011-02-24 16:37 . 2011-04-13 10:55   1063296   ----a-w-   c:\windows\system32\winload.exe
2011-02-24 16:37 . 2011-04-13 10:55   20864   ----a-w-   c:\windows\system32\kdusb.dll
2011-02-24 16:37 . 2011-04-13 10:55   18816   ----a-w-   c:\windows\system32\kd1394.dll
2011-02-24 16:37 . 2011-04-13 10:55   17792   ----a-w-   c:\windows\system32\kdcom.dll
.
.
------- Sigcheck -------
.
[7] 2009-07-10 . 9235EC680D3DB17464B39C7C7DECB4DD . 301568 . . [6.0.6001.18287] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18287_none_28ff7f1fd585934f\shsvcs.dll
[7] 2009-07-10 . 3F6101365E6319171054ADD75788516C . 300032 . . [6.0.6000.21081] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6000.21081_none_279cb3aaf1823d60\shsvcs.dll
[7] 2009-07-10 . C2409C9B7C7E422E7680AE4E1738BFC8 . 302080 . . [6.0.6001.22467] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.22467_none_299ebda8ee92f85e\shsvcs.dll
[7] 2009-07-10 . F33C4D0B9EEFCDE346F8753DC4D6867F . 299520 . . [6.0.6000.16883] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6000.16883_none_27153f51d8629d02\shsvcs.dll
[7] 2009-07-10 . 00DD742B99B278429714DEE859A73DD0 . 302080 . . [6.0.6002.22169] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.22169_none_2b873024ebb78030\shsvcs.dll
[7] 2009-07-10 . 56793271ECDEDD350C5ADD305603E963 . 302080 . . [6.0.6002.18063] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18063_none_2af7919dd29f485c\shsvcs.dll
[7] 2009-04-11 . 2AD15758174DCC7993FF3C00A955DD66 . 301568 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18005_none_2b3a71b9d26cd364\shsvcs.dll
[7] 2008-01-21 . EB3114330236CF030E8EDF62881BAF67 . 301568 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_294ef8add54b0818\shsvcs.dll
[-] 2011-03-19 . 66CFDF478939DD6388858DE06F2CE14C . 302080 . . [6.0.6000.16386] .. c:\windows\system32\shsvcs.dll
.
((((((((((((((((((((((((((   Pontos de Carregamento do Registro   )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"KBD"="c:\program files (x86)\Hewlett-Packard\KBD\KbdStub.EXE"
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"TkBellExe"="c:\program files (x86)\Common Files\Real\Update_OB\realsched.exe"  -osboot
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
.
R0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH6.sys
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\59F1.tmp
R3 PCD5SRVC{8AAF211B-043E02A9-05040000};PCD5SRVC{8AAF211B-043E02A9-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC_x64.pkms [2008-11-04 25888]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
R4 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys
R4 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys
R4 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys
R4 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/04/17 17:05];c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2008-11-28 17:04 146928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 27648]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-05-16 2151128]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2011-04-30 17152]
.
.
--- =Outros Serviços/Drivers Na Memória ---
.
*NewlyCreated* - LAVASOFT_KERNEXPLORER
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
ezSharedSvc
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2011-05-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1682711522-1043235145-2778782327-1002Core.job
- c:\users\Ramiro\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-01 17:58]
.
2011-05-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1682711522-1043235145-2778782327-1002UA.job
- c:\users\Ramiro\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-01 17:58]
.
2011-05-17 c:\windows\Tasks\PCDRScheduledMaintenance.job
- c:\program files\PC-Doctor for Windows\pcdr5cuiw32.exe [2008-11-05 18:26]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Scan Suplementar -------
.
uStart Page = hxxp://g.live.com/1rewlive4startup/home
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.duxet.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Ramiro\AppData\Roaming\Mozilla\Firefox\Profiles\nfxw56s1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
FF - prefs.js: browser.startup.homepage - hxxp://g.live.com/1rewlive4startup/home
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZVfox000&ptb=v7vjs4NH3LOYKt6.2Gqdsw&ind=2010110605&ptnrS=ZVfox000&si=&n=77cfda8d&psa=&st=kwd&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Firefox Stats: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: Mega Manager Integration: {40a1f5d7-afc2-498f-b264-02668d616ff6} - %profile%\extensions\{40a1f5d7-afc2-498f-b264-02668d616ff6}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - ORFÃOS REMOVIDOS - - - -
.
WebBrowser-{E0301295-AB3E-4AF3-979F-3D453C5F9F48} - (no file)
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\59F1.tmp"
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\PCD5SRVC{8AAF211B-043E02A9-05040000}]
"ImagePath"="\??\c:\progra~1\PC-DOC~1\PCD5SRVC_x64.pkms"
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@SACL=
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10a.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
@SACL=
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10a.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@SACL=
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Control]
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage]
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories]
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@SACL=
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@SACL=
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Control]
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@SACL=
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Programmable]
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@SACL=
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10a.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@SACL=
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@SACL=
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@SACL=
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@SACL=
@="IFlashBroker2"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid]
@Denied: (A 2) (Everyone)
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@SACL=
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@SACL=
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@SACL=
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@SACL=
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@SACL=
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Outros Processos em Execução ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
c:\program files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Tempo para conclusão: 2011-05-24  22:50:38 - Máquina reiniciou
ComboFix-quarantined-files.txt  2011-05-24 21:50
.
Pré-execução: 258.234.142.720 bytes livres
Pós execução: 256.608.624.640 bytes livres
.
- - End Of File - - 549354A5C2E464EE73DC040B6EE85149
Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 24, 2011, 04:46:46 PM
SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/ (http://sites.google.com/site/sysprotantirootkit/)

Unzip it into a folder on your desktop.
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 24, 2011, 05:09:09 PM
I get some error while creating the Sysprot log (I can open it anyway). It says 'Failed to start service. Sysprot Antirootkit needs to be run with Admin Privileges!'. The same message shows even when I run the exe as an administrator.

I can still get to the next phase, the log is created, but after choosing to scan root drive the program just doesn't seem to be doing anything.. I'm not sure if it's actually scanning or not.
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 24, 2011, 05:15:41 PM
Oh yeah, I think it's because the program doesn't support Vista 64-bit
Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 24, 2011, 05:45:05 PM
Quote
Oh yeah, I think it's because the program doesn't support Vista 64-bit
Sorry. I missed that. Try this one.

Please download Rooter (http://eric71.geekstogo.com/tools/Rooter.exe) and Save it to your desktop.
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 24, 2011, 05:58:44 PM
"Malware Finder has stopped working"

Stops working as soon as I press scan. Just my luck :(
Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 25, 2011, 04:52:02 PM
Please re-boot in Safe Mode and try run these two scans.
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 25, 2011, 06:59:36 PM
Doesn't work in safe mode either
Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 26, 2011, 01:28:49 PM
Ok Let's try this:

Note:It will also create a log in the C:\ directory..
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 26, 2011, 03:38:43 PM
It did detect some rootkit problem I've encountered before and was having a hard time removing.


2011/05/26 22:33:36.0475 4888   TDSS rootkit removing tool 2.5.3.0 May 25 2011 07:09:24
2011/05/26 22:33:36.0598 4888   ================================================================================
2011/05/26 22:33:36.0598 4888   SystemInfo:
2011/05/26 22:33:36.0598 4888   
2011/05/26 22:33:36.0598 4888   OS Version: 6.0.6002 ServicePack: 2.0
2011/05/26 22:33:36.0598 4888   Product type: Workstation
2011/05/26 22:33:36.0598 4888   ComputerName: TRINCA-NA-PÊRA
2011/05/26 22:33:36.0598 4888   UserName: Ramiro
2011/05/26 22:33:36.0598 4888   Windows directory: C:\Windows
2011/05/26 22:33:36.0598 4888   System windows directory: C:\Windows
2011/05/26 22:33:36.0598 4888   Running under WOW64
2011/05/26 22:33:36.0598 4888   Processor architecture: Intel x64
2011/05/26 22:33:36.0598 4888   Number of processors: 4
2011/05/26 22:33:36.0598 4888   Page size: 0x1000
2011/05/26 22:33:36.0599 4888   Boot type: Normal boot
2011/05/26 22:33:36.0599 4888   ================================================================================
2011/05/26 22:33:37.0001 4888   Initialize success
2011/05/26 22:33:46.0110 4576   ================================================================================
2011/05/26 22:33:46.0110 4576   Scan started
2011/05/26 22:33:46.0110 4576   Mode: Manual;
2011/05/26 22:33:46.0110 4576   ================================================================================
2011/05/26 22:33:46.0660 4576   ACPI            (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
2011/05/26 22:33:46.0709 4576   adp94xx         (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
2011/05/26 22:33:46.0743 4576   adpahci         (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
2011/05/26 22:33:46.0764 4576   adpu160m        (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
2011/05/26 22:33:46.0780 4576   adpu320         (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
2011/05/26 22:33:46.0846 4576   AFD             (12415ccfd3e7cec55b5184e67b039fe4) C:\Windows\system32\drivers\afd.sys
2011/05/26 22:33:46.0877 4576   agp440          (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
2011/05/26 22:33:46.0899 4576   aic78xx         (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
2011/05/26 22:33:46.0933 4576   aliide          (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
2011/05/26 22:33:47.0002 4576   amdide          (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
2011/05/26 22:33:47.0025 4576   AmdK8           (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
2011/05/26 22:33:47.0222 4576   amdkmdag        (d1d06810bf7e21f5763eb06cb7e7262b) C:\Windows\system32\DRIVERS\atipmdag.sys
2011/05/26 22:33:47.0336 4576   amdkmdap        (6ba71d6616b56816e57394d77dd1bb6f) C:\Windows\system32\DRIVERS\atikmpag.sys
2011/05/26 22:33:47.0398 4576   arc             (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
2011/05/26 22:33:47.0428 4576   arcsas          (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
2011/05/26 22:33:47.0478 4576   AsyncMac        (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/05/26 22:33:47.0493 4576   atapi           (1898fae8e07d97f2f6c2d5326c633fac) C:\Windows\system32\drivers\atapi.sys
2011/05/26 22:33:47.0589 4576   AtiHdmiService  (08fa104f07b243508ecd8d59007d2b2f) C:\Windows\system32\drivers\AtiHdmi.sys
2011/05/26 22:33:47.0767 4576   atikmdag        (d1d06810bf7e21f5763eb06cb7e7262b) C:\Windows\system32\DRIVERS\atikmdag.sys
2011/05/26 22:33:48.0020 4576   Avgldx64        (91be0147bc27059aba6d0a478adeb1ee) C:\Windows\system32\DRIVERS\avgldx64.sys
2011/05/26 22:33:48.0044 4576   Avgmfx64        (f5ffa3053d26c55edc112e66197eed09) C:\Windows\system32\DRIVERS\avgmfx64.sys
2011/05/26 22:33:48.0144 4576   blbdrive        (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
2011/05/26 22:33:48.0191 4576   bowser          (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys
2011/05/26 22:33:48.0213 4576   BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
2011/05/26 22:33:48.0235 4576   BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
2011/05/26 22:33:48.0263 4576   Brserid         (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
2011/05/26 22:33:48.0285 4576   BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
2011/05/26 22:33:48.0302 4576   BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
2011/05/26 22:33:48.0321 4576   BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
2011/05/26 22:33:48.0335 4576   BTHMODEM        (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
2011/05/26 22:33:48.0378 4576   cdfs            (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
2011/05/26 22:33:48.0419 4576   cdrom           (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
2011/05/26 22:33:48.0446 4576   circlass        (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
2011/05/26 22:33:48.0497 4576   CLFS            (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
2011/05/26 22:33:48.0562 4576   cmdide          (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
2011/05/26 22:33:48.0584 4576   Compbatt        (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys
2011/05/26 22:33:48.0608 4576   crcdisk         (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
2011/05/26 22:33:48.0659 4576   DfsC            (36cd31121f228e7e79bae60aa45764c6) C:\Windows\system32\Drivers\dfsc.sys
2011/05/26 22:33:48.0691 4576   disk            (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
2011/05/26 22:33:48.0750 4576   Dot4            (74c02b1717740c3b8039539e23e4b53f) C:\Windows\system32\DRIVERS\Dot4.sys
2011/05/26 22:33:48.0772 4576   Dot4Print       (08321d1860235bf42cf2854234337aea) C:\Windows\system32\DRIVERS\Dot4Prt.sys
2011/05/26 22:33:48.0818 4576   dot4usb         (4adccf0124f2b6911d3786a5d0e779e5) C:\Windows\system32\DRIVERS\dot4usb.sys
2011/05/26 22:33:48.0860 4576   drmkaud         (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
2011/05/26 22:33:48.0925 4576   DXGKrnl         (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys
2011/05/26 22:33:48.0957 4576   E1G60           (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
2011/05/26 22:33:48.0977 4576   Ecache          (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
2011/05/26 22:33:49.0027 4576   elxstor         (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
2011/05/26 22:33:49.0064 4576   ErrDev          (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
2011/05/26 22:33:49.0103 4576   exfat           (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
2011/05/26 22:33:49.0147 4576   fastfat         (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
2011/05/26 22:33:49.0172 4576   fdc             (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
2011/05/26 22:33:49.0207 4576   FileInfo        (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
2011/05/26 22:33:49.0235 4576   Filetrace       (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
2011/05/26 22:33:49.0268 4576   flpydisk        (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/05/26 22:33:49.0319 4576   FltMgr          (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
2011/05/26 22:33:49.0348 4576   Fs_Rec          (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
2011/05/26 22:33:49.0366 4576   gagp30kx        (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
2011/05/26 22:33:49.0419 4576   GEARAspiWDM     (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/05/26 22:33:49.0488 4576   HdAudAddService (68e732382b32417ff61fd663259b4b09) C:\Windows\system32\drivers\HdAudio.sys
2011/05/26 22:33:49.0682 4576   HDAudBus        (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/05/26 22:33:49.0708 4576   HidBth          (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
2011/05/26 22:33:49.0726 4576   HidIr           (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
2011/05/26 22:33:49.0778 4576   HidUsb          (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
2011/05/26 22:33:49.0801 4576   HpCISSs         (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
2011/05/26 22:33:49.0930 4576   HTTP            (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
2011/05/26 22:33:49.0976 4576   i2omp           (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
2011/05/26 22:33:50.0002 4576   i8042prt        (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/05/26 22:33:50.0044 4576   iaStor          (5979854e6fda990107e3170327022117) C:\Windows\system32\drivers\iastor.sys
2011/05/26 22:33:50.0073 4576   iaStorV         (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
2011/05/26 22:33:50.0134 4576   iirsp           (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
2011/05/26 22:33:50.0208 4576   IntcAzAudAddService (490947a9aff7ca31ef2e08f5776105eb) C:\Windows\system32\drivers\RTKVHD64.sys
2011/05/26 22:33:50.0299 4576   intelide        (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
2011/05/26 22:33:50.0316 4576   intelppm        (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
2011/05/26 22:33:50.0368 4576   IpFilterDriver  (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/05/26 22:33:50.0432 4576   IPMIDRV         (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
2011/05/26 22:33:50.0459 4576   IPNAT           (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
2011/05/26 22:33:50.0490 4576   IRENUM          (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
2011/05/26 22:33:50.0524 4576   isapnp          (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
2011/05/26 22:33:50.0568 4576   iScsiPrt        (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/05/26 22:33:50.0597 4576   iteatapi        (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
2011/05/26 22:33:50.0622 4576   iteraid         (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
2011/05/26 22:33:50.0643 4576   kbdclass        (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/05/26 22:33:50.0689 4576   kbdhid          (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
2011/05/26 22:33:50.0753 4576   KSecDD          (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
2011/05/26 22:33:50.0777 4576   ksthunk         (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
2011/05/26 22:33:50.0950 4576   Lavasoft Kernexplorer (9a7fa6371f68335fd3c3d6488bc5a9f8) C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys
2011/05/26 22:33:50.0977 4576   lltdio          (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
2011/05/26 22:33:51.0057 4576   LSI_FC          (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
2011/05/26 22:33:51.0086 4576   LSI_SAS         (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
2011/05/26 22:33:51.0112 4576   LSI_SCSI        (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
2011/05/26 22:33:51.0127 4576   luafv           (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
2011/05/26 22:33:51.0166 4576   megasas         (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
2011/05/26 22:33:51.0197 4576   MegaSR          (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
2011/05/26 22:33:51.0245 4576   MEMSWEEP2       (1595fecffbe9ea2417e06d5fd0bfa4c4) C:\Windows\system32\59F1.tmp
2011/05/26 22:33:51.0278 4576   Modem           (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
2011/05/26 22:33:51.0317 4576   monitor         (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
2011/05/26 22:33:51.0358 4576   mouclass        (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
2011/05/26 22:33:51.0372 4576   mouhid          (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
2011/05/26 22:33:51.0412 4576   MountMgr        (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
2011/05/26 22:33:51.0440 4576   mpio            (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
2011/05/26 22:33:51.0464 4576   mpsdrv          (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
2011/05/26 22:33:51.0498 4576   Mraid35x        (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
2011/05/26 22:33:51.0576 4576   MRxDAV          (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
2011/05/26 22:33:51.0622 4576   mrxsmb          (dc434b4769e18da09ce1b7755d4c64e9) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/05/26 22:33:51.0667 4576   mrxsmb10        (64713fcfe3de8881d62f8f3f2f794241) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/05/26 22:33:51.0742 4576   mrxsmb20        (0005c599a2abf767a815afcd32e523e3) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/05/26 22:33:51.0770 4576   msahci          (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
2011/05/26 22:33:51.0796 4576   msdsm           (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
2011/05/26 22:33:51.0824 4576   Msfs            (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
2011/05/26 22:33:51.0854 4576   msisadrv        (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
2011/05/26 22:33:51.0899 4576   MSKSSRV         (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
2011/05/26 22:33:51.0917 4576   MSPCLOCK        (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/05/26 22:33:51.0933 4576   MSPQM           (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
2011/05/26 22:33:51.0978 4576   MsRPC           (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
2011/05/26 22:33:52.0004 4576   mssmbios        (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/05/26 22:33:52.0032 4576   MSTEE           (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
2011/05/26 22:33:52.0054 4576   Mup             (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
2011/05/26 22:33:52.0119 4576   NativeWifiP     (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
2011/05/26 22:33:52.0177 4576   NDIS            (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
2011/05/26 22:33:52.0207 4576   NdisTapi        (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/05/26 22:33:52.0226 4576   Ndisuio         (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/05/26 22:33:52.0271 4576   NdisWan         (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/05/26 22:33:52.0294 4576   NDProxy         (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
2011/05/26 22:33:52.0312 4576   NetBIOS         (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
2011/05/26 22:33:52.0358 4576   netbt           (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
2011/05/26 22:33:52.0410 4576   nfrd960         (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
2011/05/26 22:33:52.0465 4576   Npfs            (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
2011/05/26 22:33:52.0484 4576   nsiproxy        (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
2011/05/26 22:33:52.0560 4576   Ntfs            (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
2011/05/26 22:33:52.0593 4576   Null            (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
2011/05/26 22:33:52.0624 4576   nvraid          (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
2011/05/26 22:33:52.0647 4576   nvstor          (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
2011/05/26 22:33:52.0683 4576   nv_agp          (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
2011/05/26 22:33:52.0766 4576   ohci1394        (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/05/26 22:33:52.0814 4576   Parport         (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
2011/05/26 22:33:52.0869 4576   partmgr         (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
2011/05/26 22:33:52.0983 4576   PCD5SRVC{8AAF211B-043E02A9-05040000} (7204f835a4355d1ab2853e57c9ff177c) C:\PROGRA~1\PC-DOC~1\PCD5SRVC_x64.pkms
2011/05/26 22:33:53.0012 4576   pci             (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
2011/05/26 22:33:53.0042 4576   pciide          (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys
2011/05/26 22:33:53.0077 4576   pcmcia          (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
2011/05/26 22:33:53.0114 4576   PEAUTH          (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
2011/05/26 22:33:53.0244 4576   PptpMiniport    (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
2011/05/26 22:33:53.0285 4576   Processor       (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
2011/05/26 22:33:53.0325 4576   PSched          (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
2011/05/26 22:33:53.0373 4576   ql2300          (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
2011/05/26 22:33:53.0430 4576   ql40xx          (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
2011/05/26 22:33:53.0467 4576   QWAVEdrv        (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
2011/05/26 22:33:53.0492 4576   RasAcd          (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
2011/05/26 22:33:53.0524 4576   Rasl2tp         (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/05/26 22:33:53.0574 4576   RasPppoe        (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/05/26 22:33:53.0611 4576   RasSstp         (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
2011/05/26 22:33:53.0662 4576   rdbss           (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
2011/05/26 22:33:53.0677 4576   RDPCDD          (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/05/26 22:33:53.0708 4576   rdpdr           (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
2011/05/26 22:33:53.0724 4576   RDPENCDD        (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
2011/05/26 22:33:53.0770 4576   RDPWD           (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
2011/05/26 22:33:53.0820 4576   rspndr          (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
2011/05/26 22:33:53.0867 4576   RT73            (13ab57d5aff258e8713a9b65cc04120e) C:\Windows\system32\DRIVERS\Dr71WU.sys
2011/05/26 22:33:53.0917 4576   RTL8169         (8b91737da75add21cb1554b38089196a) C:\Windows\system32\DRIVERS\Rtlh64.sys
2011/05/26 22:33:53.0973 4576   SASDIFSV        (99df79c258b3342b6c8a5f802998de56) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
2011/05/26 22:33:53.0984 4576   SASKUTIL        (2859c35c0651e8eb0d86d48e740388f2) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
2011/05/26 22:33:54.0010 4576   sbp2port        (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
2011/05/26 22:33:54.0045 4576   SBRE            (7e07d2a5b910c71d6474e9aa0eaa1825) C:\Windows\system32\drivers\SBREdrv.sys
2011/05/26 22:33:54.0088 4576   secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2011/05/26 22:33:54.0118 4576   Serenum         (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys
2011/05/26 22:33:54.0144 4576   Serial          (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys
2011/05/26 22:33:54.0172 4576   sermouse        (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
2011/05/26 22:33:54.0219 4576   sffdisk         (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
2011/05/26 22:33:54.0250 4576   sffp_mmc        (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
2011/05/26 22:33:54.0263 4576   sffp_sd         (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
2011/05/26 22:33:54.0287 4576   sfloppy         (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
2011/05/26 22:33:54.0319 4576   SiSRaid2        (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
2011/05/26 22:33:54.0349 4576   SiSRaid4        (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
2011/05/26 22:33:54.0421 4576   SmartDefragDriver (327383124d31ac398b98f4ae300421e8) C:\Windows\system32\Drivers\SmartDefragDriver.sys
2011/05/26 22:33:54.0470 4576   Smb             (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
2011/05/26 22:33:54.0540 4576   spldr           (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
2011/05/26 22:33:54.0610 4576   srv             (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys
2011/05/26 22:33:54.0656 4576   srv2            (fa36d119249bf27bc4c0079734e1f33b) C:\Windows\system32\DRIVERS\srv2.sys
2011/05/26 22:33:54.0701 4576   srvnet          (cfe7bc92d52c7e79427545909a0182f8) C:\Windows\system32\DRIVERS\srvnet.sys
2011/05/26 22:33:54.0754 4576   swenum          (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
2011/05/26 22:33:54.0794 4576   Symc8xx         (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
2011/05/26 22:33:54.0826 4576   Sym_hi          (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
2011/05/26 22:33:54.0853 4576   Sym_u3          (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
2011/05/26 22:33:54.0939 4576   Tcpip           (0011810b5211fdacd784de585262ecfe) C:\Windows\system32\drivers\tcpip.sys
2011/05/26 22:33:55.0017 4576   Tcpip6          (0011810b5211fdacd784de585262ecfe) C:\Windows\system32\DRIVERS\tcpip.sys
2011/05/26 22:33:55.0059 4576   tcpipreg        (ce3ae2ba7a076f0ade9f48c598c1d15d) C:\Windows\system32\drivers\tcpipreg.sys
2011/05/26 22:33:55.0084 4576   TDPIPE          (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
2011/05/26 22:33:55.0113 4576   TDTCP           (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
2011/05/26 22:33:55.0158 4576   tdx             (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
2011/05/26 22:33:55.0195 4576   TermDD          (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
2011/05/26 22:33:55.0245 4576   tssecsrv        (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/05/26 22:33:55.0299 4576   tunmp           (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
2011/05/26 22:33:55.0332 4576   tunnel          (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
2011/05/26 22:33:55.0367 4576   uagp35          (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
2011/05/26 22:33:55.0411 4576   udfs            (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
2011/05/26 22:33:55.0452 4576   uliagpkx        (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
2011/05/26 22:33:55.0484 4576   uliahci         (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
2011/05/26 22:33:55.0517 4576   UlSata          (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
2011/05/26 22:33:55.0544 4576   ulsata2         (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
2011/05/26 22:33:55.0559 4576   umbus           (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
2011/05/26 22:33:55.0624 4576   USBAAPL64       (54d4b48d443e7228bf64cf7cdc3118ac) C:\Windows\system32\Drivers\usbaapl64.sys
2011/05/26 22:33:55.0657 4576   usbccgp         (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/05/26 22:33:55.0686 4576   usbcir          (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
2011/05/26 22:33:55.0739 4576   usbehci         (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
2011/05/26 22:33:55.0796 4576   usbhub          (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
2011/05/26 22:33:55.0824 4576   usbohci         (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
2011/05/26 22:33:55.0859 4576   usbprint        (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
2011/05/26 22:33:55.0893 4576   usbscan         (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys
2011/05/26 22:33:55.0920 4576   USBSTOR         (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/05/26 22:33:55.0936 4576   usbuhci         (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/05/26 22:33:55.0970 4576   vga             (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/05/26 22:33:55.0997 4576   VgaSave         (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
2011/05/26 22:33:56.0023 4576   viaide          (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
2011/05/26 22:33:56.0047 4576   volmgr          (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
2011/05/26 22:33:56.0102 4576   volmgrx         (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
2011/05/26 22:33:56.0150 4576   volsnap         (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
2011/05/26 22:33:56.0184 4576   vsmraid         (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
2011/05/26 22:33:56.0237 4576   WacomPen        (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
2011/05/26 22:33:56.0287 4576   Wanarp          (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/26 22:33:56.0298 4576   Wanarpv6        (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
2011/05/26 22:33:56.0340 4576   Wd              (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
2011/05/26 22:33:56.0380 4576   Wdf01000        (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
2011/05/26 22:33:56.0508 4576   WmiAcpi         (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\drivers\wmiacpi.sys
2011/05/26 22:33:56.0578 4576   ws2ifsl         (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
2011/05/26 22:33:56.0620 4576   WUDFRd          (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/05/26 22:33:56.0709 4576   {55662437-DA8C-40c0-AADA-2C816A897A49} (1cacfef9e5dd866c5b79a135ee729e18) c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl
2011/05/26 22:33:56.0726 4576   MBR (0x1B8)     (13af81ffe36981a6a5910f5f7a43b4f8) \Device\Harddisk0\DR0
2011/05/26 22:33:56.0734 4576   \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2011/05/26 22:33:56.0739 4576   ================================================================================
2011/05/26 22:33:56.0739 4576   Scan finished
2011/05/26 22:33:56.0739 4576   ================================================================================
2011/05/26 22:33:56.0755 4372   Detected object count: 1
2011/05/26 22:33:56.0755 4372   Actual detected object count: 1
2011/05/26 22:34:09.0589 4372   \Device\Harddisk0\DR0 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot
2011/05/26 22:34:09.0589 4372   \Device\Harddisk0\DR0 - ok
2011/05/26 22:34:09.0589 4372   Rootkit.Win32.TDSS.tdl4(\Device\Harddisk0\DR0) - User select action: Cure
2011/05/26 22:34:12.0188 3188   Deinitialize success
Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 26, 2011, 04:18:30 PM
Please try running Rooter.exe again.
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 26, 2011, 04:49:38 PM
Still not working
Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 26, 2011, 05:11:17 PM
Ok. Let's try this:

AVENGER

Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 26, 2011, 05:30:03 PM
I ran the avenger and then rebooted the PC as asked, but there weren't any logs saved.
Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 27, 2011, 01:35:10 PM
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
 ESET OnlineScan (http://eset.com/onlinescan)
•Click the (http://i424.photobucket.com/albums/pp322/digistar/esetOnline.png) button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Check (http://i424.photobucket.com/albums/pp322/digistar/esetAcceptTerms.png)
•Click the (http://i424.photobucket.com/albums/pp322/digistar/esetStart.png) button.
•Accept any security warnings from your browser.
•Check (http://i424.photobucket.com/albums/pp322/digistar/esetScanArchives.png)
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push (http://i424.photobucket.com/albums/pp322/digistar/esetListThreats.png)
•Push (http://i424.photobucket.com/albums/pp322/digistar/esetExport.png), and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the (http://i424.photobucket.com/albums/pp322/digistar/esetBack.png) button.
•Push (http://i424.photobucket.com/albums/pp322/digistar/esetFinish.png)
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 27, 2011, 05:00:04 PM
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6427
# api_version=3.0.2
# EOSSerial=4cd547e8b930814f8818bec7ba500350
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-05-27 10:43:45
# local_time=2011-05-27 11:43:45 (+0000, Hora de Verão de GMT)
# country="Portugal"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 502107 502107 0 0
# compatibility_mode=1024 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776574 100 56 391430 144052601 0 0
# compatibility_mode=8192 67108863 100 0 348 348 0 0
# scanned=209108
# found=1
# cleaned=1
# scan_time=7529
C:\Users\Ramiro\Desktop\Stuff\FCT\Wolfram Mathematica\M7Win.part1.rar   probably a variant of Win32/Agent.HCHLLEJ trojan (deleted - quarantined)   00000000000000000000000000000000   C
Title: Re: Programs closing down randomly (Vista)
Post by: Rebs on May 27, 2011, 05:11:48 PM
I really don't mind continuing these procedures (as there's always malware that we're not aware of  ;D ), but it seems like the problem that first made me come here, has been fixed.  Adding to that, my internet connection seems to be working a lot better (even though the signal has been oscilating a lot according my Internet Provider), the PC boot time and the general flow of the computer has been great since you've started to help me.

I also took the liberty to follow other tutorials, such as cleaning the hardware, used different defragment software, free'd disk space, etc.


I appreciate all the help and the patience Dave.  :P
Title: Re: Programs closing down randomly (Vista)
Post by: SuperDave on May 28, 2011, 01:07:48 PM
That's ok. We're finished. Let's do some clean up

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
*************************************************
To set a new Restore Point.

Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
Click the Start button , click Control Panel, click System and Maintenance, and then click System.
In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
This will give you a new, clean Restore Point.
****************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer (http://oldtimer.geekstogo.com/TFC.exe) to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
**************************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (http://www.majorgeeks.com/Comodo_Personal_Firewall_d5033.html) (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor (http://www.majorgeeks.com/Online_Armor_Free_d4872.html)
3) Agnitum Outpost (http://www.majorgeeks.com/Outpost_Firewall_Free_d1056.html)
4) PC Tools Firewall Plus (http://www.majorgeeks.com/PC_Tools_Firewall_Plus_d5470.html)

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
***************************************************************
Use the Secunia Software Inspector (http://secunia.com/software_inspector) to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update (http://windowsupdate.microsoft.com/) and get all critical updates.

----------

I suggest using WOT - Web of Trust (http://www.mywot.com/). WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html)- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer (http://www.bleepingcomputer.com/forums/tutorial49.html) from Spyware and Malware
* If you don't know what ActiveX controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. (http://www.safer-networking.org/en/spybotsd/index.html) Guide: Use Spybot's Immunize Feature (http://www.bleepingcomputer.com/tutorials/tutorial43.html#immunize) to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ (http://www.safer-networking.org/en/faq/index.html)

Check out Keeping Yourself Safe On The Web  (http://evilfantasy.wordpress.com/2008/05/20/keeping-yourself-safe-on-the-web/) for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware (http://evilfantasy.wordpress.com/2008/05/24/slow-computer-it-may-not-be-malware/) for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Title: Re: Programs closing down randomly (Vista)
Post by: Kaderina on May 30, 2011, 03:45:38 PM
Hi SuperDave,

I'm still working through your last instructions and just wanted to Thank You for all your assistance.  I really appreciate your time and skilled knowledge.