Remoção de vírus

Ok, log limpo.

Renomeie o Combofix.exe para Uninstall.exe e execute-o para desinstalar. Delete as seguintes pastas em C: rsit, OTM, Qoobox e PenClean.
Desative e ative a restauração do sistema para limpar a pasta System Volume Information.

Vamos então resolver o problema com o ícone do Avast!.

Clique em Iniciar > Executar e digite services.msc. Verifique se os serviços abaixo, referentes ao Avast!, estão com o status Iniciado e Tipo de Inicialização Automático. Se não estiverem, coloque-os neste status.

Vá também no msconfig (Iniciar > Executar > msconfig) e clique em Inicialização. Veja se o item do Avast! está selecionado. Se não estiver, marque-o e reinicie o PC.

Veja se o residente voltou.
Mr. Wolf, verifique o meu por favor, acabei de passar o combofix e logo em seguida tirei o hijack, o problema é o pc lento ha dias, ver os seriados em 1080p ou 720p esta dificil com o processador engasgando! Quem sabe o problema não seja esses vermes...

Última edição:
falcon, aparentemente os logs estão limpos. O ideal seria se você postasse o log do Combofix, já que o rodou na máquina.

Para uma contraprova você poderia efetuar um scan no boot do sistema com algum rescue disk, pois o sistema operacional não estaria carregado.

O problema apareceu repentinamente? Ou após instalar algo, navegar em alguma página, etc...?
mr wolf, eu renomeei o combofix, para uninstal.exe, porem ele fez um novo scan.. será q desinstalou ?...
deixo assim msm e executo o resto das tarefas q vc mandou? ou se não tiver desinstalado, como desinstalo?
mr wolf, eu renomeei o combofix, para uninstal.exe, porem ele fez um novo scan.. será q desinstalou ?...
deixo assim msm e executo o resto das tarefas q vc mandou? ou se não tiver desinstalado, como desinstalo?
É Uninstall.exe (com dois L). Não era para fazer um novo scan, mas agora já foi!

Simplesmente delete este executável normalmente e exclua as pastas que eu citei anteriormente.
ops, escrevi errado aqui, na verdade eu renomeei com "dois L" mesmo, so q ele fez o novo scan, mas bom vou excluir então..
queria agradecer pela ajudar, mto obrigado..
e perguntar, de onde eu peguei esse virus? foi do DVD infectado? (se sim como faço para tirar os arquivos como por ex: videos q tem la de familia)
ou foi de algum site??
ops, escrevi errado aqui, na verdade eu renomeei com "dois L" mesmo, so q ele fez o novo scan
Ué... estranho! Obrigado por informar. Entrarei em contato com o desenvolvedor reportando o ocorrido.

e perguntar, de onde eu peguei esse virus? foi do DVD infectado? ou foi de algum site??
É difícil responder isso. Em seus logs haviam infecções provenientes de dispositivos removíveis sim, mas também haviam infecções de origens distintas. Então não posso esclarecer com exatidão.

De qualquer maneira, muito cuidado com a conexão de aparelhos USB e a inserção de mídias no computador. É recomendável desabilitar o autorun do Windows e efetuar uma verificação antiviral antes de abrir a unidade do dispositivo externo.

(se sim como faço para tirar os arquivos como por ex: videos q tem la de familia)
Primeiro tem que ver se os arquivos não foram afetados por algum código malicioso. Desative o autorun, como comentei anteriormente, e após colocar o DVD na máquina faça uma verificação com o antivirus na unidade correspondente. Se alguma infecção for identificada me informe!
mr wolf, como eu desativo o autorun.. porque eu fiz o caminho "Executar e digite “gpedit.msc” (sem aspas). Configuração do Computador > Modelos Administrativos > Sistema.
mas quando chega em modelos administrativos não tem nada, fica dizendo, que "há itens pra exibição" mais ou menos isso.. e essa janela trava so da pra fechar abrindo o gerenciador de tarefas e finalizando..

quanto akelas pasta eu tinha q excluir, teve uma q não foi possivel excluir a "Qoobox" quando tentei excluir veio uma msgs q um arquivo não poderia ser excluido..
aaaaaaa e fiz as operações pro icone do residente voltar, mas nada.. ainda não aparece...
mr wolf, como eu desativo o autorun
Baixe o AutorunFix, execute-o e clique em Off/Desactivar. Reinicie o PC posteriormente para que a alteração tenha êxito.

quanto akelas pasta eu tinha q excluir, teve uma q não foi possivel excluir a "Qoobox" quando tentei excluir veio uma msgs q um arquivo não poderia ser excluido..
Baixe o OTC e clique em CleanUP. Reinicie o PC e veja se a pasta foi deletada.

aaaaaaa e fiz as operações pro icone do residente voltar, mas nada.. ainda não aparece...
Você atualizou o Avast para a versão 6?
Mr wolf, baixei o autorunfix, excutei como vc mandou, abriu duas vezes a msm pasta Modelos Administrativos. e la travou, como estava travando antes.
e agora?
baixei o OTC cliquei em clean up ele apagou uns.. mas o "Qoobox" continua la...
não atualizei o avast pro 6. porq to com medo da maquina ficar mto lenta. éé q esse processador eh fracquinho e tem 512 de memoria se eu naum me engano..
por esse programa toma i systema todo deixa bem pesado o pc fica sem resposta !!
{ o programa não esta respndendo !!}
Olá Mr. Wolf, a qto tempo? Como estão as coisas na América?

Bom, a cunhada está com problemas no laptop. Inclusive o proxy estava direcionando para uma URL:

Neste momento, executo o ComboFix no Windows 7 64 Bits.

Em seguida pretendo rodar o HiJackThis e fazer uma limpeza manual.

Qual a próxima recomendação?

Grande mash, tudo bem meu amigo? Por aqui está tudo certinho embora muita correria. E por aí?

Olha rapaz, em vez do HijackThis recomendaria a execução do OTL (instruções no primeiro post do tópico), pois é uma ferramenta mais completa e precisa. O HijackThis não suporta muitas entradas importantes que devem ser averiguadas também, inclusive, entradas relacionadas a configurações de outros browsers como Firefox, Chrome e etc.

Não tenho certeza se o ComboFix removerá este proxy, mas certamente fará metade do trabalho, senão ele todo. De qualquer maneira, rodar o MBAM também é uma opção viável. Pela descrição do link (proxy) postado por você é muito provável de que a infecção tenha sido por um banker.

Caso sua cunhada tenha acessado internet banking no laptop, a alteração da senha é bastante aconselhada. Aliás, não só do internet banking!

Se precisar de ajuda com a análise dos logs aí, é só dar alô! :)

Olá Wolf! Sempre com precisão nas respostas.

Sim, era um banker pois direcionava para um phishing e solicitava todas as senhas do cartão de segurança. A minha esposa usou o laptop e qdo viu isto fechou o browser e me avisou.
Executei o ComboFix + Hijackthis + Ccleaner em modo de segurança.

Vou pegar novamente o laptop dela para rodar os programas recomendados.

Posto os logs assim que possível.

Sobre as senhas, informei tanto á ela quanto ao namorado (ele tinha usado o laptop a 2 dias atrás) para verificarem as contas no banco e se possível trocar as senhas.

Obrigado e nos falamos.
Opa mash

Sim, era um banker pois direcionava para um phishing e solicitava todas as senhas do cartão de segurança. A minha esposa usou o laptop e qdo viu isto fechou o browser e me avisou.
Sua esposa foi inteligente. Muitas pessoas iriam dar continuidade no processo pois o phishing ainda é um dos golpes que os usuários mais caem na rede!

Vou pegar novamente o laptop dela para rodar os programas recomendados.

Posto os logs assim que possível.
Sem problemas.

mr.wolf ainda estou no aguardo das respostas das minhas perguntas?
como voltar o residente do avast?
como recuperar os arquivos do DVD infectado?.. enfim todas as perguntas q fiz e naum tive resposta, qualquer coisa desculpe o incomodo,
De uns dois dias pra cá o meu avast me notifica que tem um programa tentando executar, o anti-vírus pergunta se quero abrir o executável em Sandbox, abrir normalmente ou cancelar abertura. Nunca executo nada, aparece do nada essa janela.

Uma screen que achei na net:


Porém, aqui em casa o arquivo vem de: C:\Usuários\Meu nome\e540e9fe089

Estou desconfiado que seja algum vírus ou algo do tipo. Já fiz a varredura completa do sistema com o avast e não encontrou nenhuma ameaça. Gostaria de saber dos mais entendidos o que pode ser isso, e se possuem programas para eu executar para ver se tem algum arquivo infectado, etc.
pauloeduardo15, como eu recomendei anteriormente e você não atendeu, atualize o Avast para a versão 6. É bem leve.
Tente desativar o autorun com o AutoPlayConfig para recuperar os arquivos.

Didjo, poste um log do OTL aqui, conforme o primeiro post do tópico.

pauloeduardo15, como eu recomendei anteriormente e você não atendeu, atualize o Avast para a versão 6. É bem leve.
Tente desativar o autorun com o AutoPlayConfig para recuperar os arquivos.

Didjo, poste um log do OTL aqui, conforme o primeiro post do tópico.


Mandei o avast escanear o PC inteiro e ele não apontou nenhum arquivo infectado. Agora mandei verificar apenas a pasta que citei no post anterior e ele encontrou dois vírus.

De qualquer forma postarei aqui o log do OTL, já está sendo executado, assim que acabar edito esse post.

"ESN Sonar-0.70.4" = ESN Sonar
"Fraps" = Fraps
"Google Chrome" = Google Chrome
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware versão
"Metro 2033 BR" = Metro 2033 Tradução BR v1.01
"Mozilla Firefox 8.0.1 (x86 pt-BR)" = Mozilla Firefox 8.0.1 (x86 pt-BR)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"Origin" = Origin
"PunkBusterSvc" = PunkBuster Services
"Steam App 12210" = Grand Theft Auto IV
"Steam App 12220" = Grand Theft Auto: Episodes from Liberty City
"Steam App 15100" = Assassin's Creed
"Steam App 16450" = F.E.A.R. 2: Project Origin
"Steam App 17470" = Dead Space
"Steam App 21090" = F.E.A.R.
"Steam App 21110" = F.E.A.R.: Extraction Point
"Steam App 21120" = F.E.A.R.: Perseus Mandate
"Steam App 24960" = Battlefield: Bad Company 2
"Steam App 33220" = Tom Clancy's Splinter Cell: Conviction
"Steam App 33230" = Assassin's Creed II
"Steam App 35140" = Batman: Arkham Asylum GOTY Edition
"Steam App 400" = Portal
"Steam App 42910" = Magicka
"Steam App 43110" = Metro 2033
"Steam App 440" = Team Fortress 2
"Steam App 44320" = DiRT 3
"Steam App 48000" = LIMBO
"Steam App 50130" = Mafia II
"Steam App 50620" = Darksiders
"Steam App 550" = Left 4 Dead 2
"Steam App 7670" = BioShock
"Steam App 7940" = Call of Duty 4: Modern Warfare
"Steam App 8850" = BioShock 2
"Steam App 8980" = Borderlands
"Steam App 91310" = Dead Island
"Unigine Heaven DX11 Benchmark 2.5_is1" = Unigine Heaven DX11 Benchmark 2.5 version 2.5
"uTorrent" = µTorrent
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.1
[color=#E56717]========== HKEY_USERS Uninstall List ==========[/color]
"TeamSpeak 3 Client" = TeamSpeak 3 Client
[color=#E56717]========== Last 10 Event Log Errors ==========[/color]
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >

OTL logfile created on: 01/12/2011 17:12:21 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\Giovane\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
4,00 Gb Total Physical Memory | 2,62 Gb Available Physical Memory | 65,57% Memory free
7,99 Gb Paging File | 6,48 Gb Available in Paging File | 81,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 603,28 Gb Free Space | 64,77% Space Free | Partition Type: NTFS
Computer Name: GIOVANE-PC | User Name: Giovane | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2011/12/01 17:08:27 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Giovane\Downloads\OTL.exe
PRC - [2011/11/28 16:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Arquivos de Programas\AVAST Software\Avast\AvastUI.exe
PRC - [2011/11/28 16:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Arquivos de Programas\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/11/22 13:45:45 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011/11/15 03:39:56 | 001,036,344 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2011/11/08 01:51:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/11/07 18:53:32 | 000,381,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/10/22 11:57:28 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/06/06 13:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2011/11/15 03:39:54 | 000,420,920 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
MOD - [2011/11/15 03:39:53 | 003,702,840 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\pdf.dll
MOD - [2011/11/15 03:38:16 | 000,122,952 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\avutil-51.dll
MOD - [2011/11/15 03:38:15 | 000,222,280 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\avformat-53.dll
MOD - [2011/11/15 03:38:14 | 001,746,504 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\avcodec-53.dll
MOD - [2011/11/15 00:36:18 | 008,593,056 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\gcswf32.dll
MOD - [2011/11/15 00:36:18 | 008,593,056 | ---- | M] () -- C:\PROGRA~2\Google\Chrome\APPLIC~1\150874~1.121\gcswf32.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV:[b]64bit:[/b] - [2011/11/28 16:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:[/b] - [2009/07/13 23:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011/11/22 13:45:45 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011/11/08 01:51:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/11/07 18:53:32 | 000,381,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/10/13 11:58:19 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/06/06 13:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/03/01 19:29:58 | 000,130,976 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 19:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV:[b]64bit:[/b] - [2011/11/28 15:54:06 | 000,591,192 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:[b]64bit:[/b] - [2011/11/28 15:53:58 | 000,304,472 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:[b]64bit:[/b] - [2011/11/28 15:52:22 | 000,042,328 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr)
DRV:[b]64bit:[/b] - [2011/11/28 15:52:20 | 000,058,712 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:[b]64bit:[/b] - [2011/11/28 15:52:11 | 000,066,904 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:[b]64bit:[/b] - [2011/11/28 15:51:53 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:[b]64bit:[/b] - [2011/08/31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:[b]64bit:[/b] - [2011/08/01 16:59:06 | 000,045,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:[b]64bit:[/b] - [2011/07/07 21:21:28 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:[b]64bit:[/b] - [2011/03/11 04:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011/03/11 04:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2010/11/20 11:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010/11/20 09:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2010/11/20 09:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2010/11/09 15:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:[b]64bit:[/b] - [2010/01/27 00:09:02 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:[b]64bit:[/b] - [2010/01/05 20:23:18 | 001,847,296 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athurx.sys -- (athur)
DRV:[b]64bit:[/b] - [2009/08/21 06:52:09 | 000,079,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:[b]64bit:[/b] - [2009/07/16 12:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:[b]64bit:[/b] - [2009/07/13 23:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/13 23:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/13 23:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/07/13 22:01:09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xnacc.sys -- (xnacc)
DRV:[b]64bit:[/b] - [2009/06/20 00:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
DRV:[b]64bit:[/b] - [2009/06/10 18:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/10 18:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/10 18:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/10 18:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2008/08/07 03:08:46 | 001,077,760 | ---- | M] (D-Link Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AGUx64.sys -- (A5AGU)
DRV - [2009/07/13 23:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page ={0D029657-07DA-4BAE-9D77-64B20E8FC39C}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-336372419-174131893-1597346273-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = 
IE - HKU\S-1-5-21-336372419-174131893-1597346273-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = 
IE - HKU\S-1-5-21-336372419-174131893-1597346273-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page ={0D029657-07DA-4BAE-9D77-64B20E8FC39C}
IE - HKU\S-1-5-21-336372419-174131893-1597346273-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
IE - HKU\S-1-5-21-336372419-174131893-1597346273-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-BR
IE - HKU\S-1-5-21-336372419-174131893-1597346273-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E3 9A 07 96 2D 4D CC 01  [binary data]
IE - HKU\S-1-5-21-336372419-174131893-1597346273-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-336372419-174131893-1597346273-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[color=#E56717]========== FireFox ==========[/color]
FF - ""
FF - 0
FF - ""
FF - 0
FF - ""
FF - 0
FF - ""
FF - 3128
FF - ""
FF - 3128
FF - true
FF - ""
FF - 3128
FF - ""
FF - 3128
FF - 0
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\ C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\ disabled File not found
FF - HKLM\Software\MozillaPlugins\ C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\,version=:  File not found
FF - HKLM\Software\MozillaPlugins\,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\ C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\ disabled File not found
FF - HKLM\Software\MozillaPlugins\,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\ C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\ C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\ Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\ Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/12/01 09:37:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/26 00:11:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/11/26 00:11:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Giovane\AppData\Roaming\mozilla\Extensions
[2011/11/26 00:11:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011/11/21 02:42:52 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/11/20 23:34:27 | 000,001,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\buscape.xml
[2011/11/20 23:34:27 | 000,001,212 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mercadolivre.xml
[2011/11/20 23:15:19 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
[2011/11/20 23:34:27 | 000,001,168 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-br.xml
[2011/11/20 23:34:27 | 000,000,952 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-br.xml
[color=#E56717]========== Chrome  ==========[/color]
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Users\Giovane\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_0\
CHR - Extension: Classic = C:\Users\Giovane\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkacjpbfdknhflllbcmjibkdeoafencn\1.1_0\
O1 HOSTS File: ([2009/06/10 19:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Arquivos de Programas\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:[b]64bit:[/b] - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:[b]64bit:[/b] - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de Programas\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Arquivos de Programas\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de Programas\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:[b]64bit:[/b] - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-336372419-174131893-1597346273-1000..\Run: [EADM] C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
O4 - HKU\S-1-5-21-336372419-174131893-1597346273-1000..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-336372419-174131893-1597346273-1012..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-336372419-174131893-1597346273-1012..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-336372419-174131893-1597346273-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:[b]64bit:[/b] - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Arquivos de Programas\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1226753E-7691-4904-8C66-A65697346F8C}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF856659-BA9D-44D2-A2A7-6544B3E6494F}: DhcpNameServer =
O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/14 14:31:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\ [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\ [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2011/12/01 15:08:55 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{5C5352F1-1456-4E0B-950F-4FE96784E2E5}
[2011/12/01 15:08:43 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{89755709-94FD-417D-8FC8-CB19789EF784}
[2011/11/30 12:51:41 | 000,000,000 | ---D | C] -- C:\Users\Giovane\e540e9fe089
[2011/11/29 13:35:53 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\Microsoft Games
[2011/11/28 17:14:05 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{F129B1AD-E9B0-4096-AB17-D9088604B090}
[2011/11/28 17:13:52 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{D7D884A5-5F1D-402E-8B09-8C0C9BA9C38C}
[2011/11/28 13:08:15 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Roaming\Leadertech
[2011/11/26 17:12:30 | 000,000,000 | ---D | C] -- C:\Users\Giovane\Documents\DeadIsland
[2011/11/26 00:11:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2011/11/24 19:37:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011/11/24 19:37:39 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2011/11/24 19:37:39 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2011/11/24 19:37:39 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2011/11/24 19:37:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2011/11/21 19:26:34 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mirillis
[2011/11/21 19:26:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mirillis
[2011/11/21 14:41:09 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Roaming\Mirillis
[2011/11/21 14:41:09 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\Mirillis
[2011/11/21 14:41:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Mirillis
[2011/11/21 14:28:16 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Adobe
[2011/11/21 05:33:01 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{BED4497C-36FF-4255-8889-7738B26B3FF4}
[2011/11/21 05:32:49 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{91C9FA7E-EEB8-4B25-9C5A-12E949AD9184}
[2011/11/20 21:15:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2011/11/20 21:14:11 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Roaming\uTorrent
[2011/11/20 21:14:11 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\uTorrent
[2011/11/20 12:53:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/11/20 12:53:03 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/11/20 12:53:02 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/11/15 22:55:51 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{A08E973A-2183-4099-8E57-493E94EE4BFF}
[2011/11/15 22:55:40 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{D061F71C-810A-4D4D-AFA3-EAD6F476C184}
[2011/11/15 21:38:18 | 000,000,000 | ---D | C] -- C:\Users\Giovane\Documents\FIFA 12
[2011/11/15 19:09:09 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2011/11/15 10:55:13 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{26047BC6-05EF-40F1-A3F9-CD60EF082866}
[2011/11/15 10:54:54 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{EC70842A-D3AA-47F1-9622-6AECC097C2C2}
[2011/11/10 16:47:52 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{0BFF62C7-9FDB-4622-8100-773F9938124D}
[2011/11/10 16:47:41 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{BB55AC23-4641-410C-B99D-DD55C15F245E}
[2011/11/10 14:37:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/11/10 14:34:05 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2011/11/10 14:32:55 | 010,406,208 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
[2011/11/10 14:32:55 | 005,067,584 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
[2011/11/10 14:32:55 | 003,074,368 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
[2011/11/10 14:32:55 | 000,837,952 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\easyupdatusapiu64.dll
[2011/11/10 14:32:55 | 000,222,528 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
[2011/11/10 14:32:55 | 000,137,536 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
[2011/11/10 14:30:55 | 001,452,648 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdagenco6420102.dll
[2011/11/10 14:30:55 | 000,174,184 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvhda64v.sys
[2011/11/10 14:30:55 | 000,029,288 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdap64.dll
[2011/11/10 14:30:54 | 024,796,992 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2011/11/10 14:30:54 | 024,742,720 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2011/11/10 14:30:54 | 018,871,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2011/11/10 14:30:54 | 017,248,576 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2011/11/10 14:30:54 | 015,693,120 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll
[2011/11/10 14:30:54 | 013,205,312 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2011/11/10 14:30:54 | 008,792,384 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2011/11/10 14:30:54 | 007,581,504 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2011/11/10 14:30:54 | 007,042,880 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2011/11/10 14:30:54 | 005,578,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2011/11/10 14:30:54 | 002,808,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
[2011/11/10 14:30:54 | 002,542,912 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2011/11/10 14:30:54 | 002,458,432 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2011/11/10 14:30:54 | 002,401,088 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2011/11/10 14:30:54 | 002,232,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2011/11/10 14:30:54 | 002,099,520 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2011/11/10 14:30:54 | 001,543,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco64.dll
[2011/11/10 14:30:54 | 001,454,400 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvgenco64.dll
[2011/11/10 14:30:54 | 000,068,928 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/11/10 14:30:54 | 000,061,248 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/11/10 14:28:15 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2011/11/10 14:22:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\
[2011/11/10 14:22:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\
[2011/11/10 14:16:54 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2011/11/09 16:50:30 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{AC4BE11B-BA08-4514-B4AA-5506980E07C9}
[2011/11/09 16:50:17 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{9925BD94-E016-4753-9B0D-432C129486FC}
[2011/11/08 21:49:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
[2011/11/08 21:30:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 12
[2011/11/08 20:24:40 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{E2692993-B40B-4CC8-A7F5-D17B33DEE50C}
[2011/11/08 20:24:28 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{F99C1847-CC0C-463B-BED2-376F6A02DD7B}
[2011/11/01 19:03:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2011/11/01 19:03:07 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2011/12/01 17:08:51 | 000,001,115 | ---- | M] () -- C:\Users\Giovane\Desktop\OTL - Atalho.lnk
[2011/12/01 17:02:00 | 000,001,070 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/01 12:02:00 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/01 09:45:58 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/01 09:45:58 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/01 09:38:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/01 09:38:28 | 3219,791,872 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/01 09:37:17 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011/11/29 13:36:49 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2011/11/29 13:36:49 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/11/28 16:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/11/28 16:01:23 | 000,199,816 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2011/11/28 16:01:14 | 000,256,960 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011/11/28 15:54:06 | 000,591,192 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2011/11/28 15:53:58 | 000,304,472 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2011/11/28 15:52:22 | 000,042,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2011/11/28 15:52:20 | 000,058,712 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2011/11/28 15:52:11 | 000,066,904 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011/11/28 15:51:53 | 000,024,408 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2011/11/26 12:43:14 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2011/11/26 00:11:03 | 000,001,138 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/24 19:37:30 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2011/11/24 19:37:30 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2011/11/24 19:37:30 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2011/11/24 19:37:30 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2011/11/23 16:37:44 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/22 13:46:21 | 000,001,170 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
[2011/11/22 13:45:45 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/11/21 19:26:35 | 000,002,209 | ---- | M] () -- C:\Users\Giovane\Desktop\Splash PRO.lnk
[2011/11/20 21:15:44 | 000,000,943 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2011/11/20 12:53:18 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/11/15 19:09:10 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/11/10 14:22:48 | 000,001,233 | ---- | M] () -- C:\Users\Public\Desktop\Driver Sweeper.lnk
[2011/11/10 14:00:23 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2011/11/09 19:10:10 | 000,414,272 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/08 21:30:02 | 000,001,234 | ---- | M] () -- C:\Users\Public\Desktop\FIFA 12.lnk
[2011/11/08 01:51:00 | 024,796,992 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2011/11/08 01:51:00 | 024,742,720 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2011/11/08 01:51:00 | 018,871,616 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2011/11/08 01:51:00 | 017,248,576 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2011/11/08 01:51:00 | 015,693,120 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll
[2011/11/08 01:51:00 | 013,205,312 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2011/11/08 01:51:00 | 010,406,208 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
[2011/11/08 01:51:00 | 008,792,384 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2011/11/08 01:51:00 | 007,581,504 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2011/11/08 01:51:00 | 007,042,880 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2011/11/08 01:51:00 | 005,578,560 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2011/11/08 01:51:00 | 005,067,584 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
[2011/11/08 01:51:00 | 003,074,368 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
[2011/11/08 01:51:00 | 002,808,128 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
[2011/11/08 01:51:00 | 002,542,912 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2011/11/08 01:51:00 | 002,458,432 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2011/11/08 01:51:00 | 002,401,088 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2011/11/08 01:51:00 | 002,232,128 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2011/11/08 01:51:00 | 002,099,520 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2011/11/08 01:51:00 | 001,543,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco64.dll
[2011/11/08 01:51:00 | 001,454,400 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvgenco64.dll
[2011/11/08 01:51:00 | 000,837,952 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\easyupdatusapiu64.dll
[2011/11/08 01:51:00 | 000,222,528 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
[2011/11/08 01:51:00 | 000,137,536 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
[2011/11/08 01:51:00 | 000,068,928 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/11/08 01:51:00 | 000,061,248 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/11/08 01:51:00 | 000,007,384 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
[2011/11/07 18:53:44 | 000,321,856 | ---- | M] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/11/06 12:20:03 | 001,524,858 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/06 12:20:03 | 000,666,510 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat
[2011/11/06 12:20:03 | 000,618,714 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/11/06 12:20:03 | 000,128,740 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat
[2011/11/06 12:20:03 | 000,107,034 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/11/01 19:09:21 | 000,175,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msclmd.dll
[2011/11/01 19:09:21 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msclmd.dll
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2011/12/01 17:08:51 | 000,001,115 | ---- | C] () -- C:\Users\Giovane\Desktop\OTL - Atalho.lnk
[2011/11/26 00:11:03 | 000,001,150 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/26 00:11:03 | 000,001,138 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/22 13:46:21 | 000,001,170 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
[2011/11/21 19:26:35 | 000,002,209 | ---- | C] () -- C:\Users\Giovane\Desktop\Splash PRO.lnk
[2011/11/20 21:15:44 | 000,000,943 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2011/11/20 12:53:18 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/11/10 14:22:48 | 000,001,233 | ---- | C] () -- C:\Users\Public\Desktop\Driver Sweeper.lnk
[2011/11/08 21:30:02 | 000,001,234 | ---- | C] () -- C:\Users\Public\Desktop\FIFA 12.lnk
[2011/11/07 18:53:44 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/10/23 21:11:51 | 000,444,283 | ---- | C] () -- C:\Program Files (x86)\Common Files\WinPcapNmap.exe
[2011/10/03 21:33:13 | 001,533,836 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/12 15:37:48 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011/07/07 23:31:09 | 000,280,904 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/07/07 23:31:02 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/07/06 17:38:02 | 000,674,600 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2011/05/14 14:01:08 | 000,000,000 | ---- | C] () -- C:\Users\Giovane\AppData\Local\{5DF2AEB5-3646-4324-B994-5E2E6EEF8227}
[2011/05/04 22:42:53 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2011/05/04 22:42:53 | 000,014,392 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2011/05/01 19:25:29 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2011/04/09 19:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\
[2010/01/27 00:09:02 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2009/07/14 03:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 00:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 22:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 21:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 19:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 19:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[color=#E56717]========== LOP Check ==========[/color]
[2011/08/02 18:56:13 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Ashampoo
[2011/10/15 21:12:10 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Bioshock
[2011/10/03 23:51:25 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\DAEMON Tools Lite
[2011/11/28 13:08:15 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Leadertech
[2011/09/10 18:40:06 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\MAXON
[2011/11/21 19:27:26 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Mirillis
[2011/10/19 14:35:04 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Origin
[2011/09/15 15:01:55 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Rovio
[2011/07/08 12:39:53 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\The Creative Assembly
[2011/07/28 01:23:06 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\TS3Client
[2011/07/12 12:09:12 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Ubisoft
[2011/11/30 22:56:02 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\uTorrent
[2011/10/23 21:13:34 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\VDownloader
[2011/11/15 19:05:46 | 000,032,608 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[color=#E56717]========== Purity Check ==========[/color]

< End of report >
Didjo, peço que mova o OTL.exe para a sua área de trabalho, por gentileza, e execute-o mais uma vez como administrador. Feche todas as janelas abertas (exceto a do OTL, claro). Anote os procedimentos a seguir se quiser.

No campo em branco onde diz Exames Personalizados/Correções cole este script abaixo no QUOTE.

Clique no botão rosa Verificação Rápida, ao lado do botão Verificar, e aguarde alguns instantes. Pode demorar um pouquinho.

O OTL começará a examinar seu computador novamente. Não interrompa o processo e nem use outras janelas até que ele termine.

Quando terminar, dois blocos de notas serão exibidos: OTL.txt e Extras.txt
Ambos ficarão salvos dentro do mesmo diretório onde está o OTL.exe, no seu caso, na sua área de trabalho.

Copie todo o conteúdo do OTL.txt e cole na sua resposta.
Didjo, peço que mova o OTL.exe para a sua área de trabalho, por gentileza, e execute-o mais uma vez como administrador. Feche todas as janelas abertas (exceto a do OTL, claro). Anote os procedimentos a seguir se quiser.

No campo em branco onde diz Exames Personalizados/Correções cole este script abaixo no QUOTE.

Clique no botão rosa Verificação Rápida, ao lado do botão Verificar, e aguarde alguns instantes. Pode demorar um pouquinho.

O OTL começará a examinar seu computador novamente. Não interrompa o processo e nem use outras janelas até que ele termine.

Quando terminar, dois blocos de notas serão exibidos: OTL.txt e Extras.txt
Ambos ficarão salvos dentro do mesmo diretório onde está o OTL.exe, no seu caso, na sua área de trabalho.

Copie todo o conteúdo do OTL.txt e cole na sua resposta.

Mr.Wolf, é necessário marcar as opções: Verificar All Users, Verificar Lop e Verificar Purity conforme explicado no primeiro post do tópico ?
Aqui está:

OTL logfile created on: 01/12/2011 18:40:38 - Run 4
OTL by OldTimer - Version     Folder = C:\Users\Giovane\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
4,00 Gb Total Physical Memory | 2,66 Gb Available Physical Memory | 66,49% Memory free
7,99 Gb Paging File | 6,56 Gb Available in Paging File | 82,10% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 602,95 Gb Free Space | 64,74% Space Free | Partition Type: NTFS
Computer Name: GIOVANE-PC | User Name: Giovane | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2011/12/01 17:08:27 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Giovane\Desktop\OTL.exe
PRC - [2011/11/28 16:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Arquivos de Programas\AVAST Software\Avast\AvastUI.exe
PRC - [2011/11/28 16:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Arquivos de Programas\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/11/22 13:45:45 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011/11/08 01:51:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/11/07 18:53:32 | 000,381,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/10/22 11:57:28 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/06/06 13:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV:[b]64bit:[/b] - [2011/11/28 16:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:[b]64bit:[/b] - [2009/07/13 23:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011/11/22 13:45:45 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011/11/08 01:51:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/11/07 18:53:32 | 000,381,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/10/13 11:58:19 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/06/06 13:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/03/01 19:29:58 | 000,130,976 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 19:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV:[b]64bit:[/b] - [2011/11/28 15:54:06 | 000,591,192 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:[b]64bit:[/b] - [2011/11/28 15:53:58 | 000,304,472 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:[b]64bit:[/b] - [2011/11/28 15:52:22 | 000,042,328 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr)
DRV:[b]64bit:[/b] - [2011/11/28 15:52:20 | 000,058,712 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:[b]64bit:[/b] - [2011/11/28 15:52:11 | 000,066,904 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:[b]64bit:[/b] - [2011/11/28 15:51:53 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:[b]64bit:[/b] - [2011/08/31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:[b]64bit:[/b] - [2011/08/01 16:59:06 | 000,045,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:[b]64bit:[/b] - [2011/07/07 21:21:28 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:[b]64bit:[/b] - [2011/03/11 04:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011/03/11 04:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2010/11/20 11:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010/11/20 09:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2010/11/20 09:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2010/11/09 15:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:[b]64bit:[/b] - [2010/01/27 00:09:02 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:[b]64bit:[/b] - [2010/01/05 20:23:18 | 001,847,296 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athurx.sys -- (athur)
DRV:[b]64bit:[/b] - [2009/08/21 06:52:09 | 000,079,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:[b]64bit:[/b] - [2009/07/16 12:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:[b]64bit:[/b] - [2009/07/13 23:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/13 23:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/13 23:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/07/13 22:01:09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xnacc.sys -- (xnacc)
DRV:[b]64bit:[/b] - [2009/06/20 00:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
DRV:[b]64bit:[/b] - [2009/06/10 18:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/10 18:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/10 18:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/10 18:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:[b]64bit:[/b] - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2008/08/07 03:08:46 | 001,077,760 | ---- | M] (D-Link Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AGUx64.sys -- (A5AGU)
DRV - [2009/07/13 23:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page ={0D029657-07DA-4BAE-9D77-64B20E8FC39C}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page ={0D029657-07DA-4BAE-9D77-64B20E8FC39C}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-BR
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E3 9A 07 96 2D 4D CC 01  [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
[color=#E56717]========== FireFox ==========[/color]
FF - ""
FF - 0
FF - ""
FF - 0
FF - ""
FF - 0
FF - ""
FF - 3128
FF - ""
FF - 3128
FF - true
FF - ""
FF - 3128
FF - ""
FF - 3128
FF - 0
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\ C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\ disabled File not found
FF - HKLM\Software\MozillaPlugins\ C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\,version=:  File not found
FF - HKLM\Software\MozillaPlugins\,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\ C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\ disabled File not found
FF - HKLM\Software\MozillaPlugins\,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\ C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\ C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\ Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\ Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/12/01 09:37:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/26 00:11:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/11/26 00:11:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Giovane\AppData\Roaming\mozilla\Extensions
[2011/11/26 00:11:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2011/11/21 02:42:52 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/11/20 23:34:27 | 000,001,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\buscape.xml
[2011/11/20 23:34:27 | 000,001,212 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mercadolivre.xml
[2011/11/20 23:15:19 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
[2011/11/20 23:34:27 | 000,001,168 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-br.xml
[2011/11/20 23:34:27 | 000,000,952 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-br.xml
[color=#E56717]========== Chrome  ==========[/color]
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Users\Giovane\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_0\
CHR - Extension: Classic = C:\Users\Giovane\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkacjpbfdknhflllbcmjibkdeoafencn\1.1_0\
O1 HOSTS File: ([2009/06/10 19:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Arquivos de Programas\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:[b]64bit:[/b] - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:[b]64bit:[/b] - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de Programas\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Arquivos de Programas\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de Programas\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4:[b]64bit:[/b] - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [EADM] C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:[b]64bit:[/b] - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Arquivos de Programas\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1226753E-7691-4904-8C66-A65697346F8C}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AF856659-BA9D-44D2-A2A7-6544B3E6494F}: DhcpNameServer =
O18:[b]64bit:[/b] - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: VMApplet - (/pagefile) -  File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/14 14:31:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\ [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\ [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
Restore point Set: OTL Restore Point
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2011/12/01 17:08:23 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Giovane\Desktop\OTL.exe
[2011/12/01 15:08:55 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{5C5352F1-1456-4E0B-950F-4FE96784E2E5}
[2011/12/01 15:08:43 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{89755709-94FD-417D-8FC8-CB19789EF784}
[2011/11/30 12:51:41 | 000,000,000 | ---D | C] -- C:\Users\Giovane\e540e9fe089
[2011/11/29 13:35:53 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\Microsoft Games
[2011/11/28 17:14:05 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{F129B1AD-E9B0-4096-AB17-D9088604B090}
[2011/11/28 17:13:52 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{D7D884A5-5F1D-402E-8B09-8C0C9BA9C38C}
[2011/11/28 13:08:15 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Roaming\Leadertech
[2011/11/26 17:12:30 | 000,000,000 | ---D | C] -- C:\Users\Giovane\Documents\DeadIsland
[2011/11/26 00:11:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2011/11/24 19:37:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011/11/24 19:37:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2011/11/21 19:26:34 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mirillis
[2011/11/21 19:26:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mirillis
[2011/11/21 14:41:09 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Roaming\Mirillis
[2011/11/21 14:41:09 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\Mirillis
[2011/11/21 14:41:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Mirillis
[2011/11/21 14:28:16 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Adobe
[2011/11/21 05:33:01 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{BED4497C-36FF-4255-8889-7738B26B3FF4}
[2011/11/21 05:32:49 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{91C9FA7E-EEB8-4B25-9C5A-12E949AD9184}
[2011/11/20 21:15:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2011/11/20 21:14:11 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Roaming\uTorrent
[2011/11/20 21:14:11 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\uTorrent
[2011/11/20 12:53:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/11/20 12:53:03 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/11/20 12:53:02 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/11/15 22:55:51 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{A08E973A-2183-4099-8E57-493E94EE4BFF}
[2011/11/15 22:55:40 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{D061F71C-810A-4D4D-AFA3-EAD6F476C184}
[2011/11/15 21:38:18 | 000,000,000 | ---D | C] -- C:\Users\Giovane\Documents\FIFA 12
[2011/11/15 19:09:09 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2011/11/15 10:55:13 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{26047BC6-05EF-40F1-A3F9-CD60EF082866}
[2011/11/15 10:54:54 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{EC70842A-D3AA-47F1-9622-6AECC097C2C2}
[2011/11/10 16:47:52 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{0BFF62C7-9FDB-4622-8100-773F9938124D}
[2011/11/10 16:47:41 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{BB55AC23-4641-410C-B99D-DD55C15F245E}
[2011/11/10 14:37:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/11/10 14:34:05 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2011/11/10 14:30:54 | 000,068,928 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/11/10 14:30:54 | 000,061,248 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/11/10 14:28:15 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2011/11/10 14:22:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\
[2011/11/10 14:22:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\
[2011/11/10 14:16:54 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2011/11/09 16:50:30 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{AC4BE11B-BA08-4514-B4AA-5506980E07C9}
[2011/11/09 16:50:17 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{9925BD94-E016-4753-9B0D-432C129486FC}
[2011/11/08 21:49:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
[2011/11/08 21:30:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 12
[2011/11/08 20:24:40 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{E2692993-B40B-4CC8-A7F5-D17B33DEE50C}
[2011/11/08 20:24:28 | 000,000,000 | ---D | C] -- C:\Users\Giovane\AppData\Local\{F99C1847-CC0C-463B-BED2-376F6A02DD7B}
[2011/11/01 19:03:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview
[2011/11/01 19:03:07 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2011/12/01 18:02:00 | 000,001,070 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/01 17:08:27 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Giovane\Desktop\OTL.exe
[2011/12/01 12:02:00 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/01 09:45:58 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/01 09:45:58 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/01 09:38:32 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/01 09:38:28 | 3219,791,872 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/01 09:37:17 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011/11/29 13:36:49 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2011/11/29 13:36:49 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/11/28 16:01:25 | 000,041,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/11/28 16:01:23 | 000,199,816 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2011/11/28 16:01:14 | 000,256,960 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011/11/28 15:54:06 | 000,591,192 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2011/11/28 15:53:58 | 000,304,472 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2011/11/28 15:52:22 | 000,042,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2011/11/28 15:52:20 | 000,058,712 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2011/11/28 15:52:11 | 000,066,904 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011/11/28 15:51:53 | 000,024,408 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2011/11/26 12:43:14 | 000,280,904 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2011/11/26 00:11:03 | 000,001,138 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/23 16:37:44 | 000,000,866 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/11/22 13:46:21 | 000,001,170 | ---- | M] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
[2011/11/22 13:45:45 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/11/21 19:26:35 | 000,002,209 | ---- | M] () -- C:\Users\Giovane\Desktop\Splash PRO.lnk
[2011/11/20 21:15:44 | 000,000,943 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2011/11/20 12:53:18 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/11/10 14:22:48 | 000,001,233 | ---- | M] () -- C:\Users\Public\Desktop\Driver Sweeper.lnk
[2011/11/10 14:00:23 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2011/11/09 19:10:10 | 000,414,272 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/08 21:30:02 | 000,001,234 | ---- | M] () -- C:\Users\Public\Desktop\FIFA 12.lnk
[2011/11/08 01:51:00 | 000,068,928 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/11/08 01:51:00 | 000,061,248 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/11/08 01:51:00 | 000,007,384 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
[2011/11/07 18:53:44 | 000,321,856 | ---- | M] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/11/06 12:20:03 | 001,524,858 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/06 12:20:03 | 000,666,510 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat
[2011/11/06 12:20:03 | 000,618,714 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/11/06 12:20:03 | 000,128,740 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat
[2011/11/06 12:20:03 | 000,107,034 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2011/11/26 00:11:03 | 000,001,150 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/26 00:11:03 | 000,001,138 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/11/22 13:46:21 | 000,001,170 | ---- | C] () -- C:\Users\Public\Desktop\Battlefield 3.lnk
[2011/11/21 19:26:35 | 000,002,209 | ---- | C] () -- C:\Users\Giovane\Desktop\Splash PRO.lnk
[2011/11/20 21:15:44 | 000,000,943 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2011/11/20 12:53:18 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/11/10 14:22:48 | 000,001,233 | ---- | C] () -- C:\Users\Public\Desktop\Driver Sweeper.lnk
[2011/11/08 21:30:02 | 000,001,234 | ---- | C] () -- C:\Users\Public\Desktop\FIFA 12.lnk
[2011/11/07 18:53:44 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/10/23 21:11:51 | 000,444,283 | ---- | C] () -- C:\Program Files (x86)\Common Files\WinPcapNmap.exe
[2011/10/03 21:33:13 | 001,533,836 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/07/12 15:37:48 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011/07/07 23:31:09 | 000,280,904 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/07/07 23:31:02 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/07/06 17:38:02 | 000,674,600 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2011/05/14 14:01:08 | 000,000,000 | ---- | C] () -- C:\Users\Giovane\AppData\Local\{5DF2AEB5-3646-4324-B994-5E2E6EEF8227}
[2011/05/04 22:42:53 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2011/05/04 22:42:53 | 000,014,392 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2011/05/01 19:25:29 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2011/04/09 19:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\
[2010/01/27 00:09:02 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2009/07/14 03:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 00:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 22:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 21:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 19:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 19:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[color=#E56717]========== LOP Check ==========[/color]
[2011/08/02 18:56:13 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Ashampoo
[2011/10/15 21:12:10 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Bioshock
[2011/10/03 23:51:25 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\DAEMON Tools Lite
[2011/11/28 13:08:15 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Leadertech
[2011/09/10 18:40:06 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\MAXON
[2011/11/21 19:27:26 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Mirillis
[2011/10/19 14:35:04 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Origin
[2011/09/15 15:01:55 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Rovio
[2011/07/08 12:39:53 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\The Creative Assembly
[2011/07/28 01:23:06 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\TS3Client
[2011/07/12 12:09:12 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\Ubisoft
[2011/11/30 22:56:02 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\uTorrent
[2011/10/23 21:13:34 | 000,000,000 | ---D | M] -- C:\Users\Giovane\AppData\Roaming\VDownloader
[2011/11/15 19:05:46 | 000,032,608 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[color=#E56717]========== Purity Check ==========[/color]
[color=#E56717]========== Custom Scans ==========[/color]
[color=#A23BEC]< netsvc >[/color]
[color=#A23BEC]< %USERPROFILE%\*.* >[/color]
[2011/12/01 18:40:33 | 002,621,440 | -HS- | M] () -- C:\Users\Giovane\ntuser.dat
[2011/12/01 18:40:33 | 000,262,144 | -HS- | M] () -- C:\Users\Giovane\ntuser.dat.LOG1
[2011/05/01 13:27:04 | 000,000,000 | -HS- | M] () -- C:\Users\Giovane\ntuser.dat.LOG2
[2011/05/01 13:29:39 | 000,065,536 | -HS- | M] () -- C:\Users\Giovane\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
[2011/05/01 13:29:39 | 000,524,288 | -HS- | M] () -- C:\Users\Giovane\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2011/05/01 13:29:39 | 000,524,288 | -HS- | M] () -- C:\Users\Giovane\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2011/06/03 00:30:37 | 000,065,536 | -HS- | M] () -- C:\Users\Giovane\ntuser.dat{5dd139d2-8d39-11e0-bf74-485b393888fb}.TM.blf
[2011/06/03 00:30:37 | 000,524,288 | -HS- | M] () -- C:\Users\Giovane\ntuser.dat{5dd139d2-8d39-11e0-bf74-485b393888fb}.TMContainer00000000000000000001.regtrans-ms
[2011/06/03 00:30:37 | 000,524,288 | -HS- | M] () -- C:\Users\Giovane\ntuser.dat{5dd139d2-8d39-11e0-bf74-485b393888fb}.TMContainer00000000000000000002.regtrans-ms
[2011/05/08 14:03:05 | 000,065,536 | -HS- | M] () -- C:\Users\Giovane\NTUSER.DAT{7a0d2008-797d-11e0-9bef-485b393888fb}.TM.blf
[2011/05/08 14:03:05 | 000,524,288 | -HS- | M] () -- C:\Users\Giovane\NTUSER.DAT{7a0d2008-797d-11e0-9bef-485b393888fb}.TMContainer00000000000000000001.regtrans-ms
[2011/05/08 14:03:05 | 000,524,288 | -HS- | M] () -- C:\Users\Giovane\NTUSER.DAT{7a0d2008-797d-11e0-9bef-485b393888fb}.TMContainer00000000000000000002.regtrans-ms
[2011/10/30 22:32:55 | 000,065,536 | -HS- | M] () -- C:\Users\Giovane\ntuser.dat{d4c479b7-0315-11e1-a6bb-485b393888fb}.TM.blf
[2011/10/30 22:32:55 | 000,524,288 | -HS- | M] () -- C:\Users\Giovane\ntuser.dat{d4c479b7-0315-11e1-a6bb-485b393888fb}.TMContainer00000000000000000001.regtrans-ms
[2011/10/30 22:32:55 | 000,524,288 | -HS- | M] () -- C:\Users\Giovane\ntuser.dat{d4c479b7-0315-11e1-a6bb-485b393888fb}.TMContainer00000000000000000002.regtrans-ms
[2011/05/01 13:27:04 | 000,000,020 | -HS- | M] () -- C:\Users\Giovane\ntuser.ini
[color=#A23BEC]< %USERPROFILE%\e540e9fe089\*.* >[/color]
[2011/11/30 12:52:56 | 000,065,536 | ---- | M] () -- C:\Users\Giovane\e540e9fe089\un.exe
[2011/11/30 12:50:30 | 000,159,744 | ---- | M] () -- C:\Users\Giovane\e540e9fe089\unrar.dll

< End of report >
Didjo, o arquivo que o Avast está notificando por acaso é um dos dois a seguir: un.exe ou unrar.dll?

Acesse o VirusTotal e cole os caminhos abaixo na busca, um por vez. Depois clique no botão Send file.

Aguarde o scan do primeiro terminar e posteriormente submeta o próximo.

Ao término, vá para a página do resultado, copie as URLs e cole-as em sua próxima resposta, por favor.

Users who are viewing this thread
