estou com um porreiro. Utilizo o combofix e consertou beleza, porém qdo abro o msn, ressuscita o maledito. Eu entro no site do bradesco e abre um clone dele cque no final é /ibanking
Já teste o adawre e ada feito. Utilizo atualizado o eset e pelo jeito não me ajudou. REcorro a ajuda dos profissionais que estão dispostos a ajudar. Agradeço desde já.
Segue os relatorios:
OTL logfile created on: 19/08/2011 20:17:36 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\Andre Voorhees\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
3,25 Gb Total Physical Memory | 1,73 Gb Available Physical Memory | 53,33% Memory free
11,37 Gb Paging File | 9,80 Gb Available in Paging File | 86,21% Paging File free
Paging file location(s): c:\pagefile.sys 0 0d:\pagefile.sys 4990 4990 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48,83 Gb Total Space | 26,16 Gb Free Space | 53,57% Space Free | Partition Type: NTFS
Drive D: | 184,05 Gb Total Space | 176,03 Gb Free Space | 95,64% Space Free | Partition Type: NTFS
Drive F: | 931,51 Gb Total Space | 418,05 Gb Free Space | 44,88% Space Free | Partition Type: NTFS
Computer Name: ANDREVOORHEES | User Name: Andre Voorhees | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/08/19 20:15:21 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Andre Voorhees\Desktop\OTL.exe
PRC - [2011/08/19 00:18:47 | 001,191,216 | ---- | M] (Lavasoft Limited) -- C:\Arquivos de Programas\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/08/19 00:18:45 | 002,151,640 | ---- | M] (Lavasoft Limited) -- C:\Arquivos de Programas\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/08/17 19:44:49 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Arquivos de Programas\Mozilla Firefox\firefox.exe
PRC - [2011/08/03 08:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) -- C:\Arquivos de Programas\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/08/03 08:50:00 | 000,812,648 | ---- | M] (NVIDIA Corporation) -- C:\Arquivos de Programas\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2011/08/03 08:50:00 | 000,373,864 | ---- | M] (NVIDIA Corporation) -- C:\Arquivos de Programas\NVIDIA Corporation\Display\nvtray.exe
PRC - [2011/08/03 03:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) -- C:\Arquivos de Programas\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/07/11 18:48:10 | 001,595,520 | ---- | M] (Nullsoft, Inc.) -- C:\Arquivos de Programas\Winamp\winamp.exe
PRC - [2011/02/25 02:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/01/20 06:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd) -- C:\Arquivos de Programas\DAEMON Tools Lite\DTLite.exe
PRC - [2010/11/20 09:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Windows Media Player\wmpnetwk.exe
PRC - [2010/11/20 09:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/11/20 09:17:41 | 001,174,016 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Windows Sidebar\sidebar.exe
PRC - [2010/11/04 17:15:50 | 000,810,144 | ---- | M] (ESET) -- C:\Arquivos de Programas\ESET\ESET Smart Security\ekrn.exe
PRC - [2010/06/25 09:26:46 | 001,686,128 | R--- | M] (VIA) -- C:\Arquivos de Programas\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2010/04/16 22:12:18 | 003,872,080 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Windows Live\Messenger\msnmsgr.exe
PRC - [2010/04/16 18:36:42 | 000,026,480 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Windows Live\Contacts\wlcomm.exe
PRC - [2009/08/18 11:29:22 | 001,529,728 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009/08/18 11:29:22 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Arquivos de Programas\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2003/06/19 23:25:00 | 000,322,120 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
========== Modules (No Company Name) ==========
MOD - [2011/08/19 20:13:45 | 000,206,336 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\winamp.lng
MOD - [2011/08/19 20:13:45 | 000,149,504 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\vis_milk2.lng
MOD - [2011/08/19 20:13:45 | 000,085,504 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\vis_avs.lng
MOD - [2011/08/19 20:13:45 | 000,007,680 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\vis_nsfs.lng
MOD - [2011/08/19 20:13:45 | 000,004,096 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\winampa.lng
MOD - [2011/08/19 20:13:44 | 000,062,976 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\burnlib.lng
MOD - [2011/08/19 20:13:44 | 000,053,248 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_local.lng
MOD - [2011/08/19 20:13:44 | 000,044,032 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_pmp.lng
MOD - [2011/08/19 20:13:44 | 000,043,008 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_disc.lng
MOD - [2011/08/19 20:13:44 | 000,042,496 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\pmp_wifi.lng
MOD - [2011/08/19 20:13:44 | 000,037,376 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_jumpex.lng
MOD - [2011/08/19 20:13:44 | 000,036,864 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\pmp_ipod.lng
MOD - [2011/08/19 20:13:44 | 000,036,352 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ombrowser.lng
MOD - [2011/08/19 20:13:44 | 000,022,016 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_mp3.lng
MOD - [2011/08/19 20:13:44 | 000,021,504 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_ff.lng
MOD - [2011/08/19 20:13:44 | 000,020,992 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_ml.lng
MOD - [2011/08/19 20:13:44 | 000,019,968 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_midi.lng
MOD - [2011/08/19 20:13:44 | 000,019,456 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\pmp_android.lng
MOD - [2011/08/19 20:13:44 | 000,018,432 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_mod.lng
MOD - [2011/08/19 20:13:44 | 000,016,384 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\out_ds.lng
MOD - [2011/08/19 20:13:44 | 000,014,336 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_wm.lng
MOD - [2011/08/19 20:13:44 | 000,013,824 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\pmp_usb.lng
MOD - [2011/08/19 20:13:44 | 000,013,824 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_wire.lng
MOD - [2011/08/19 20:13:44 | 000,013,824 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_online.lng
MOD - [2011/08/19 20:13:44 | 000,013,824 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\dsp_sps.lng
MOD - [2011/08/19 20:13:44 | 000,012,800 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_playlists.lng
MOD - [2011/08/19 20:13:44 | 000,012,800 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_cdda.lng
MOD - [2011/08/19 20:13:44 | 000,012,288 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_plg.lng
MOD - [2011/08/19 20:13:44 | 000,011,264 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_vorbis.lng
MOD - [2011/08/19 20:13:44 | 000,011,264 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_nsv.lng
MOD - [2011/08/19 20:13:44 | 000,010,752 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_skinmanager.lng
MOD - [2011/08/19 20:13:44 | 000,010,752 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\auth.lng
MOD - [2011/08/19 20:13:44 | 000,010,240 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_undo.lng
MOD - [2011/08/19 20:13:44 | 000,010,240 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_hotkeys.lng
MOD - [2011/08/19 20:13:44 | 000,010,240 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_classicart.lng
MOD - [2011/08/19 20:13:44 | 000,009,728 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\enc_aacplus.lng
MOD - [2011/08/19 20:13:44 | 000,009,216 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_timerestore.lng
MOD - [2011/08/19 20:13:44 | 000,009,216 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_nopro.lng
MOD - [2011/08/19 20:13:44 | 000,008,704 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_history.lng
MOD - [2011/08/19 20:13:44 | 000,008,704 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_downloads.lng
MOD - [2011/08/19 20:13:44 | 000,008,704 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_devices.lng
MOD - [2011/08/19 20:13:44 | 000,007,680 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_transcode.lng
MOD - [2011/08/19 20:13:44 | 000,007,680 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_tray.lng
MOD - [2011/08/19 20:13:44 | 000,007,168 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\out_wave.lng
MOD - [2011/08/19 20:13:44 | 000,007,168 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_dshow.lng
MOD - [2011/08/19 20:13:44 | 000,007,168 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_orgler.lng
MOD - [2011/08/19 20:13:44 | 000,007,168 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_crasher.lng
MOD - [2011/08/19 20:13:44 | 000,006,656 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_autotag.lng
MOD - [2011/08/19 20:13:44 | 000,006,656 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_wav.lng
MOD - [2011/08/19 20:13:44 | 000,006,656 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\enc_fhgaac.lng
MOD - [2011/08/19 20:13:44 | 000,006,144 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\tagz.lng
MOD - [2011/08/19 20:13:44 | 000,006,144 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\out_disk.lng
MOD - [2011/08/19 20:13:44 | 000,006,144 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_flac.lng
MOD - [2011/08/19 20:13:44 | 000,006,144 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\enc_wma.lng
MOD - [2011/08/19 20:13:44 | 000,005,632 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_wave.lng
MOD - [2011/08/19 20:13:44 | 000,005,632 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\enc_lame.lng
MOD - [2011/08/19 20:13:44 | 000,005,120 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_rg.lng
MOD - [2011/08/19 20:13:44 | 000,005,120 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_impex.lng
MOD - [2011/08/19 20:13:44 | 000,005,120 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_bookmarks.lng
MOD - [2011/08/19 20:13:44 | 000,005,120 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_avi.lng
MOD - [2011/08/19 20:13:44 | 000,004,608 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\pmp_activesync.lng
MOD - [2011/08/19 20:13:44 | 000,004,608 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_enqplay.lng
MOD - [2011/08/19 20:13:44 | 000,004,608 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_mp4.lng
MOD - [2011/08/19 20:13:44 | 000,004,608 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_mkv.lng
MOD - [2011/08/19 20:13:44 | 000,004,096 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\pmp_p4s.lng
MOD - [2011/08/19 20:13:44 | 000,004,096 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_wv.lng
MOD - [2011/08/19 20:13:44 | 000,004,096 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\gen_find_on_disk.lng
MOD - [2011/08/19 20:13:44 | 000,004,096 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\enc_wav.lng
MOD - [2011/08/19 20:13:44 | 000,004,096 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\enc_vorbis.lng
MOD - [2011/08/19 20:13:44 | 000,004,096 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\enc_flac.lng
MOD - [2011/08/19 20:13:44 | 000,003,584 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\pmp_njb.lng
MOD - [2011/08/19 20:13:44 | 000,003,584 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\playlist.lng
MOD - [2011/08/19 20:13:44 | 000,003,584 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_nowplaying.lng
MOD - [2011/08/19 20:13:44 | 000,003,584 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\ml_addons.lng
MOD - [2011/08/19 20:13:44 | 000,003,584 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_swf.lng
MOD - [2011/08/19 20:13:44 | 000,003,584 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_linein.lng
MOD - [2011/08/19 20:13:44 | 000,003,584 | ---- | M] () -- C:\Users\ANDREV~1\AppData\Local\Temp\WLZ5792.tmp\in_flv.lng
MOD - [2011/08/17 19:44:48 | 001,846,232 | ---- | M] () -- C:\Arquivos de Programas\Mozilla Firefox\mozjs.dll
MOD - [2011/08/12 19:13:00 | 006,277,280 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2011/08/10 19:49:47 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\6e9a08576157b4aeb91a3aaa452fcb00\System.Management.ni.dll
MOD - [2011/08/10 19:48:48 | 007,963,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\3da7c6c1a0f26ae91883fd8b03ec192d\System.ni.dll
MOD - [2011/08/10 19:48:44 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\16b68fcaff063835ae0ee348a1201f2a\mscorlib.ni.dll
MOD - [2011/08/03 03:31:28 | 000,255,592 | ---- | M] () -- C:\Arquivos de Programas\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2011/07/21 19:30:22 | 000,623,616 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\jnetlib.w5s
MOD - [2011/07/21 19:30:22 | 000,154,624 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\jpeg.w5s
MOD - [2011/07/21 19:30:22 | 000,103,936 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\png.w5s
MOD - [2011/07/21 19:30:22 | 000,090,112 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\xml.w5s
MOD - [2011/07/21 19:30:22 | 000,084,480 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\playlist.w5s
MOD - [2011/07/21 19:30:22 | 000,083,968 | ---- | M] () -- C:\Arquivos de Programas\Winamp\tataki.dll
MOD - [2011/07/21 19:30:22 | 000,052,224 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\out_ds.dll
MOD - [2011/07/21 19:30:22 | 000,047,616 | ---- | M] () -- C:\Arquivos de Programas\Winamp\zlib.dll
MOD - [2011/07/21 19:30:22 | 000,035,328 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\timer.w5s
MOD - [2011/07/21 19:30:22 | 000,023,040 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\albumart.w5s
MOD - [2011/07/21 19:30:22 | 000,022,528 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\out_disk.dll
MOD - [2011/07/21 19:30:22 | 000,021,504 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\tagz.w5s
MOD - [2011/07/21 19:30:22 | 000,019,456 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\gif.w5s
MOD - [2011/07/21 19:30:22 | 000,019,456 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\bmp.w5s
MOD - [2011/07/21 19:30:22 | 000,018,432 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\out_wave.dll
MOD - [2011/07/21 19:30:22 | 000,016,896 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\dlmgr.w5s
MOD - [2011/07/21 19:30:22 | 000,016,384 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\gracenote.w5s
MOD - [2011/07/21 19:30:22 | 000,014,336 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\filereader.w5s
MOD - [2011/07/21 19:30:22 | 000,013,824 | ---- | M] () -- C:\Arquivos de Programas\Winamp\System\primo.w5s
MOD - [2011/07/21 19:30:21 | 000,313,344 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\in_wm.dll
MOD - [2011/07/21 19:30:21 | 000,285,696 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\in_mp3.dll
MOD - [2011/07/21 19:30:21 | 000,252,416 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\in_vorbis.dll
MOD - [2011/07/21 19:30:21 | 000,165,376 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\in_mod.dll
MOD - [2011/07/21 19:30:21 | 000,109,568 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\in_midi.dll
MOD - [2011/07/21 19:30:21 | 000,102,400 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\in_cdda.dll
MOD - [2011/07/21 19:30:21 | 000,060,928 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\in_flac.dll
MOD - [2011/07/21 19:30:21 | 000,050,688 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\in_mp4.dll
MOD - [2011/07/21 19:30:21 | 000,016,896 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\in_wave.dll
MOD - [2011/07/21 19:30:21 | 000,007,168 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\in_linein.dll
MOD - [2011/07/21 19:30:20 | 000,183,808 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\gen_jumpex.dll
MOD - [2011/07/21 19:30:20 | 000,045,056 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\gen_msn.dll
MOD - [2011/07/21 19:30:20 | 000,027,648 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\gen_hotkeys.dll
MOD - [2011/07/21 19:30:20 | 000,025,600 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\gen_tray.dll
MOD - [2011/07/21 19:30:19 | 001,737,728 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\gen_ff.dll
MOD - [2011/07/21 19:30:19 | 000,340,992 | ---- | M] () -- C:\Arquivos de Programas\Winamp\Plugins\freeform\wacs\freetype\freetype.wac
MOD - [2011/07/21 19:30:18 | 000,410,624 | ---- | M] () -- C:\Arquivos de Programas\Winamp\nsutil.dll
MOD - [2011/07/21 19:30:18 | 000,253,440 | ---- | M] () -- C:\Arquivos de Programas\Winamp\libsndfile.dll
MOD - [2011/07/21 19:30:18 | 000,078,848 | ---- | M] () -- C:\Arquivos de Programas\Winamp\nde.dll
MOD - [2011/03/21 06:32:08 | 000,498,760 | ---- | M] () -- C:\Arquivos de Programas\ManyCam\Bin\cximagecrt.dll
MOD - [2010/06/25 09:26:52 | 000,100,976 | R--- | M] () -- C:\Arquivos de Programas\VIA\VIAudioi\VDeck\VMicApi.dll
MOD - [2010/06/25 09:26:42 | 064,663,664 | R--- | M] () -- C:\Arquivos de Programas\VIA\VIAudioi\VDeck\skin.dll
MOD - [2010/06/25 09:26:40 | 000,113,264 | R--- | M] () -- C:\Arquivos de Programas\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2010/06/25 09:26:40 | 000,080,496 | R--- | M] () -- C:\Arquivos de Programas\VIA\VIAudioi\VDeck\QsApoApi.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/08/19 00:18:45 | 002,151,640 | ---- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2011/08/03 08:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Arquivos de Programas\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/08/03 03:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Arquivos de Programas\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2011/04/07 20:21:00 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/11/04 17:18:10 | 000,033,584 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010/11/04 17:15:50 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2009/07/13 22:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 22:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 22:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Arquivos de Programas\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Arquivos de Programas\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2007/05/31 09:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 09:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
========== Driver Services (SafeList) ==========
DRV - [2011/08/19 00:19:26 | 000,015,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Arquivos de Programas\Lavasoft\Ad-Aware\kernexplorer.sys -- (Lavasoft Kernexplorer)
DRV - [2011/08/19 00:19:00 | 000,064,512 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2011/08/03 08:50:00 | 010,304,104 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2011/05/24 20:40:10 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2011/05/10 06:41:28 | 000,139,368 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2011/03/31 23:08:09 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2010/11/20 09:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 09:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 09:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 07:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 07:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 06:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 06:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/09/03 06:13:46 | 000,137,144 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\System32\drivers\eamonm.sys -- (eamonm)
DRV - [2010/07/29 12:31:26 | 000,134,512 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfw.sys -- (epfw)
DRV - [2010/07/29 12:31:26 | 000,115,008 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010/07/29 12:31:26 | 000,041,336 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfp.sys -- (epfwwfp)
DRV - [2010/07/29 12:31:26 | 000,032,608 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010/05/15 08:11:42 | 001,150,880 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009/07/16 00:36:30 | 000,013,216 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2005/11/19 01:29:38 | 010,192,896 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2sxp.sys -- (SNP2STD) USB2.0 PC Camera (SNP2STD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-432924015-704257289-2575384188-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = F:\
IE - HKU\S-1-5-21-432924015-704257289-2575384188-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.hotmail.com.br/
IE - HKU\S-1-5-21-432924015-704257289-2575384188-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-BR
IE - HKU\S-1-5-21-432924015-704257289-2575384188-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 46 50 E1 FC 92 2E CC 01 [binary data]
IE - HKU\S-1-5-21-432924015-704257289-2575384188-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-432924015-704257289-2575384188-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" =
http://otr.iexplorerset.com:8083/connect.dat
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.g1.com.br"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/08/17 19:44:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/08/19 00:49:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011/03/31 00:41:17 | 000,000,000 | ---D | M]
[2011/03/31 00:20:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andre Voorhees\AppData\Roaming\mozilla\Extensions
[2011/08/17 19:56:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Andre Voorhees\AppData\Roaming\mozilla\Firefox\Profiles\04ksm0xu.default\extensions
[2011/07/16 23:12:41 | 000,000,000 | ---D | M] (AddThis) -- C:\Users\Andre Voorhees\AppData\Roaming\mozilla\Firefox\Profiles\04ksm0xu.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2011/05/19 21:40:02 | 000,000,000 | ---D | M] (Orkut Manager) -- C:\Users\Andre Voorhees\AppData\Roaming\mozilla\Firefox\Profiles\04ksm0xu.default\extensions\om.brunolm@gmail.com
[2011/07/10 12:01:28 | 000,002,155 | ---- | M] () -- C:\Users\Andre Voorhees\AppData\Roaming\Mozilla\Firefox\Profiles\04ksm0xu.default\searchplugins\google-brasil.xml
[2011/03/31 20:58:15 | 000,002,067 | ---- | M] () -- C:\Users\Andre Voorhees\AppData\Roaming\Mozilla\Firefox\Profiles\04ksm0xu.default\searchplugins\pesquisa-de-vdeos-do-youtube.xml
[2011/08/19 00:49:14 | 000,000,000 | ---D | M] (No name found) -- C:\Arquivos de Programas\Mozilla Firefox\extensions
[2011/03/31 00:48:36 | 000,000,000 | ---D | M] (Java Console) -- C:\Arquivos de Programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/08/19 00:49:14 | 000,000,000 | ---D | M] (Java Console) -- C:\Arquivos de Programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\USERS\ANDRE VOORHEES\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\04KSM0XU.DEFAULT\EXTENSIONS\PERSONAS@CHRISTOPHER.BEARD.XPI
[2011/08/17 19:44:49 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/08/19 00:49:10 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/07/11 18:48:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2010/01/01 05:00:00 | 000,001,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\buscape.xml
[2010/01/01 05:00:00 | 000,001,212 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mercadolivre.xml
[2010/01/01 05:00:00 | 000,001,168 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-br.xml
[2010/01/01 05:00:00 | 000,000,952 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-br.xml
O1 HOSTS File: ([2011/08/19 19:16:03 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de Programas\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [snp2std] C:\Windows\vsnp2std.exe (Sonix)
O4 - HKU\S-1-5-21-432924015-704257289-2575384188-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-432924015-704257289-2575384188-1000..\Run: [SpybotSD TeaTimer] C:\Arquivos de Programas\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKU\S-1-5-21-432924015-704257289-2575384188-1007..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-432924015-704257289-2575384188-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-432924015-704257289-2575384188-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-432924015-704257289-2575384188-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-432924015-704257289-2575384188-1007\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Arquivos de Programas\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de Programas\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Arquivos de Programas\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de Programas\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de Programas\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de Programas\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de Programas\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Arquivos de Programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de Programas\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de Programas\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Arquivos de Programas\Common Files\microsoft shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Arquivos de Programas\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Arquivos de Programas\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 18:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/08/19 20:18:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Messenger Plus!
[2011/08/19 20:15:18 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\Andre Voorhees\Desktop\OTL.exe
[2011/08/19 20:09:07 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/08/19 20:08:05 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/08/19 19:43:25 | 000,000,000 | ---D | C] -- C:\LinhaDefensiva
[2011/08/19 19:18:16 | 000,000,000 | ---D | C] -- C:\Users\Andre Voorhees\AppData\Local\temp
[2011/08/19 19:09:58 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/08/19 19:09:58 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/08/19 19:09:58 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/08/19 19:09:54 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/08/19 19:07:56 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/08/19 19:07:19 | 004,178,757 | R--- | C] (Swearware) -- C:\Users\Andre Voorhees\Desktop\ComboFix.exe
[2011/08/19 00:49:22 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/08/19 00:49:13 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/08/19 00:49:13 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/08/19 00:49:13 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/08/19 00:19:35 | 000,064,512 | ---- | C] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2011/08/19 00:19:35 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2011/08/19 00:19:33 | 000,101,720 | ---- | C] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2011/08/19 00:11:13 | 000,000,000 | ---D | C] -- C:\Users\Andre Voorhees\AppData\Local\Sunbelt Software
[2011/08/19 00:08:56 | 000,000,000 | -H-D | C] -- C:\ProgramData\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
[2011/08/19 00:08:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011/08/19 00:08:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2011/08/19 00:08:54 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2011/08/18 23:37:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/08/18 23:37:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011/08/18 23:37:35 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011/08/15 21:19:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/08/15 21:17:20 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2011/08/15 21:16:49 | 003,730,024 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcpl.dll
[2011/08/15 21:16:49 | 002,560,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvsvcr.dll
[2011/08/15 21:16:49 | 002,558,568 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvsvc.dll
[2011/08/15 21:16:49 | 000,111,208 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvmctray.dll
[2011/08/15 21:16:49 | 000,066,664 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvshext.dll
[2011/08/15 21:16:46 | 000,600,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\easyupdatusapiu.dll
[2011/08/15 21:16:40 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2011/08/15 21:12:45 | 017,193,576 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll
[2011/08/15 21:12:45 | 016,595,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll
[2011/08/15 21:12:45 | 012,636,776 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvd3dum.dll
[2011/08/15 21:12:45 | 010,304,104 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys
[2011/08/15 21:12:45 | 006,613,096 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvwgf2um.dll
[2011/08/15 21:12:45 | 005,404,776 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll
[2011/08/15 21:12:45 | 002,412,136 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvapi.dll
[2011/08/15 21:12:45 | 002,391,656 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll
[2011/08/15 21:12:45 | 002,090,088 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll
[2011/08/15 21:12:45 | 000,914,024 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco32.dll
[2011/08/15 21:12:45 | 000,865,896 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvhdagenco322040.dll
[2011/08/15 21:12:45 | 000,139,368 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvhda32v.sys
[2011/08/15 21:12:45 | 000,057,960 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2011/08/15 21:12:45 | 000,026,216 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvhdap32.dll
[2011/08/12 21:32:08 | 000,000,000 | ---D | C] -- C:\Traduz Games
[2011/08/12 20:42:32 | 000,000,000 | ---D | C] -- C:\Users\Andre Voorhees\AppData\Local\2K Games
[2011/08/11 21:18:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/08/09 20:30:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2011/08/09 20:30:47 | 000,237,568 | ---- | C] (
www.helixcommunity.org) -- C:\Windows\System32\yv12vfw.dll
[2011/08/09 20:30:47 | 000,232,448 | ---- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) -- C:\Windows\System32\mp3fhg.acm
[2011/08/09 20:30:47 | 000,151,552 | ---- | C] (fccHandler) -- C:\Windows\System32\ac3acm.acm
[2011/08/09 19:03:13 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/08/09 19:03:12 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011/08/09 19:03:12 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/08/09 19:03:12 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011/08/09 19:03:11 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011/08/09 18:58:11 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2011/08/09 18:58:11 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2011/08/09 18:58:11 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2011/08/09 18:58:11 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/09 18:58:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/09 18:58:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2011/08/09 18:58:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2011/08/09 18:58:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/09 18:58:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2011/08/09 18:58:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/09 18:58:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2011/08/09 18:58:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/09 18:58:10 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2011/08/09 18:58:10 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/09 18:58:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2011/08/09 18:58:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/09 18:58:09 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2011/08/09 18:58:08 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcjt32.dll
[2011/08/09 18:58:08 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbctrac.dll
[2011/08/09 18:58:08 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll
[2011/08/09 18:58:08 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccu32.dll
[2011/08/09 18:58:08 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccr32.dll
[2011/08/09 18:58:03 | 003,912,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2011/08/09 18:58:02 | 003,967,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011/08/07 21:33:00 | 000,000,000 | ---D | C] -- C:\Users\Andre Voorhees\AppData\Roaming\Origin
[2011/08/07 14:57:43 | 000,875,112 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco32.dll
[2011/07/31 21:22:37 | 000,000,000 | ---D | C] -- C:\Program Files\Segnas
[2011/07/22 23:56:45 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011/07/21 19:30:15 | 000,000,000 | ---D | C] -- C:\Users\Andre Voorhees\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Detectar Aplicação
[2011/07/21 19:30:15 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp Detect
[2011/07/21 19:30:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
[2011/03/31 20:28:26 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Andre Voorhees\AppData\Roaming\pcouffin.sys
[2005/11/23 20:55:32 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\csnp2std.dll
[4 C:\Users\Andre Voorhees\AppData\Local\*.tmp files -> C:\Users\Andre Voorhees\AppData\Local\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/08/19 20:15:21 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Andre Voorhees\Desktop\OTL.exe
[2011/08/19 19:55:05 | 000,000,156 | ---- | M] () -- C:\Users\Andre Voorhees\Documents\cc_20110819_195449.reg
[2011/08/19 19:26:05 | 000,001,072 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/19 19:16:03 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/08/19 19:05:50 | 004,178,757 | R--- | M] (Swearware) -- C:\Users\Andre Voorhees\Desktop\ComboFix.exe
[2011/08/19 19:02:18 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/19 19:02:18 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/19 18:58:40 | 000,666,510 | ---- | M] () -- C:\Windows\System32\prfh0416.dat
[2011/08/19 18:58:40 | 000,618,714 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/08/19 18:58:40 | 000,128,740 | ---- | M] () -- C:\Windows\System32\prfc0416.dat
[2011/08/19 18:58:40 | 000,107,034 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/08/19 18:54:26 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/19 18:53:53 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/08/19 18:53:47 | 2615,709,696 | -HS- | M] () -- C:\hiberfil.sys
[2011/08/19 00:49:10 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2011/08/19 00:49:10 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2011/08/19 00:49:10 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2011/08/19 00:49:10 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2011/08/19 00:42:43 | 000,000,933 | ---- | M] () -- C:\Users\Public\Desktop\Microsoft Fix*it Center.lnk
[2011/08/19 00:20:02 | 000,000,064 | ---- | M] () -- C:\Windows\System32\rp_stats.dat
[2011/08/19 00:20:02 | 000,000,044 | ---- | M] () -- C:\Windows\System32\rp_rules.dat
[2011/08/19 00:19:32 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2011/08/19 00:19:29 | 000,016,432 | ---- | M] () -- C:\Windows\System32\lsdelete.exe
[2011/08/19 00:19:00 | 000,064,512 | ---- | M] (Lavasoft AB) -- C:\Windows\System32\drivers\Lbd.sys
[2011/08/19 00:08:55 | 000,001,112 | ---- | M] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/08/18 23:37:37 | 000,001,232 | ---- | M] () -- C:\Users\Andre Voorhees\Desktop\Spybot - Search & Destroy.lnk
[2011/08/17 23:41:01 | 000,135,680 | ---- | M] () -- C:\Users\Andre Voorhees\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/17 22:11:16 | 000,001,669 | -HS- | M] () -- C:\Users\Andre Voorhees\amsfx.vbs
[2011/08/13 07:34:58 | 002,258,512 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/08/12 21:27:38 | 000,000,728 | ---- | M] () -- C:\Users\Andre Voorhees\Desktop\Mafia II.lnk
[2011/08/12 19:13:01 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/08/11 21:18:58 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/08/09 20:36:31 | 000,001,034 | ---- | M] () -- C:\Users\Andre Voorhees\Desktop\MP3Gain.lnk
[2011/08/08 05:00:00 | 000,074,752 | ---- | M] () -- C:\Windows\System32\ff_vfw.dll
[2011/08/08 05:00:00 | 000,000,038 | ---- | M] () -- C:\Windows\avisplitter.ini
[2011/08/07 21:32:49 | 000,000,707 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2011/08/03 08:50:00 | 017,193,576 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll
[2011/08/03 08:50:00 | 016,595,560 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll
[2011/08/03 08:50:00 | 012,636,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvd3dum.dll
[2011/08/03 08:50:00 | 010,304,104 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys
[2011/08/03 08:50:00 | 006,613,096 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvwgf2um.dll
[2011/08/03 08:50:00 | 005,404,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll
[2011/08/03 08:50:00 | 003,730,024 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcpl.dll
[2011/08/03 08:50:00 | 002,560,616 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvsvcr.dll
[2011/08/03 08:50:00 | 002,558,568 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvsvc.dll
[2011/08/03 08:50:00 | 002,412,136 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvapi.dll
[2011/08/03 08:50:00 | 002,391,656 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll
[2011/08/03 08:50:00 | 002,090,088 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll
[2011/08/03 08:50:00 | 000,914,024 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco32.dll
[2011/08/03 08:50:00 | 000,600,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\easyupdatusapiu.dll
[2011/08/03 08:50:00 | 000,111,208 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvmctray.dll
[2011/08/03 08:50:00 | 000,066,664 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvshext.dll
[2011/08/03 08:50:00 | 000,057,960 | ---- | M] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2011/08/03 08:50:00 | 000,004,358 | ---- | M] () -- C:\Windows\System32\nvinfo.pb
[2011/08/03 03:31:54 | 000,311,912 | ---- | M] () -- C:\Windows\System32\nvStreaming.exe
[2011/07/30 00:38:14 | 000,000,000 | ---- | M] () -- C:\Users\Andre Voorhees\AppData\Local\{C3989CDC-BF75-4966-BD0D-E06405A4A0AF}
[2011/07/23 15:57:00 | 000,875,112 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco32.dll
[2011/07/21 23:54:43 | 001,797,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011/07/21 23:47:24 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011/07/21 23:46:48 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011/07/21 23:44:36 | 002,382,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/07/21 23:43:07 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/07/21 20:41:35 | 000,000,947 | ---- | M] () -- C:\Users\Andre Voorhees\Desktop\André.lnk
[4 C:\Users\Andre Voorhees\AppData\Local\*.tmp files -> C:\Users\Andre Voorhees\AppData\Local\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/08/19 19:55:03 | 000,000,156 | ---- | C] () -- C:\Users\Andre Voorhees\Documents\cc_20110819_195449.reg
[2011/08/19 19:37:29 | 000,016,432 | ---- | C] () -- C:\Windows\System32\lsdelete.exe
[2011/08/19 19:09:58 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/08/19 19:09:58 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/08/19 19:09:58 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/08/19 19:09:58 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/08/19 19:09:58 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/08/19 00:20:02 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2011/08/19 00:20:02 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
[2011/08/19 00:08:55 | 000,001,112 | ---- | C] () -- C:\Users\Public\Desktop\Ad-Aware.lnk
[2011/08/18 23:37:37 | 000,001,232 | ---- | C] () -- C:\Users\Andre Voorhees\Desktop\Spybot - Search & Destroy.lnk
[2011/08/17 22:11:16 | 000,001,669 | -HS- | C] () -- C:\Users\Andre Voorhees\amsfx.vbs
[2011/08/15 21:12:45 | 000,004,358 | ---- | C] () -- C:\Windows\System32\nvinfo.pb
[2011/08/12 21:27:38 | 000,000,728 | ---- | C] () -- C:\Users\Andre Voorhees\Desktop\Mafia II.lnk
[2011/08/12 20:46:48 | 000,286,208 | ---- | C] () -- C:\Windows\System32\binkw32.dll
[2011/08/11 21:18:58 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/08/09 20:30:49 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/08/09 20:30:47 | 000,650,752 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011/08/09 20:30:47 | 000,243,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/08/09 20:30:46 | 000,074,752 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/08/03 03:31:54 | 000,311,912 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2011/07/30 00:37:28 | 000,000,000 | ---- | C] () -- C:\Users\Andre Voorhees\AppData\Local\{C3989CDC-BF75-4966-BD0D-E06405A4A0AF}
[2011/06/23 18:40:50 | 000,000,000 | ---- | C] () -- C:\Users\Andre Voorhees\AppData\Local\{18BBBEBC-FA9F-4CA8-A163-268CDB25D93D}
[2011/06/05 15:11:56 | 000,000,000 | ---- | C] () -- C:\Users\Andre Voorhees\AppData\Local\{F292E092-28B3-47C8-BC6F-2D87771E1566}
[2011/06/01 20:59:03 | 000,000,000 | ---- | C] () -- C:\Users\Andre Voorhees\AppData\Local\{FFC8EAB1-42C3-498E-B320-C26B0692C931}
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/04/02 16:22:10 | 000,000,418 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/03/31 20:29:08 | 000,200,285 | ---- | C] () -- C:\Users\Andre Voorhees\AppData\Roaming\vso_ts_preview.xml
[2011/03/31 20:28:26 | 000,007,887 | ---- | C] () -- C:\Users\Andre Voorhees\AppData\Roaming\pcouffin.cat
[2011/03/31 20:28:26 | 000,001,144 | ---- | C] () -- C:\Users\Andre Voorhees\AppData\Roaming\pcouffin.inf
[2011/03/31 20:07:44 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/03/31 20:06:13 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/03/31 01:14:52 | 000,135,680 | ---- | C] () -- C:\Users\Andre Voorhees\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/31 00:57:48 | 000,175,616 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011/03/31 00:09:54 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011/03/31 00:09:51 | 000,037,628 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2011/03/21 13:22:06 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2009/07/16 00:36:30 | 000,013,216 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[2009/07/14 05:31:12 | 000,666,510 | ---- | C] () -- C:\Windows\System32\prfh0416.dat
[2009/07/14 05:31:12 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat
[2009/07/14 05:31:12 | 000,128,740 | ---- | C] () -- C:\Windows\System32\prfc0416.dat
[2009/07/14 05:31:12 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat
[2009/07/14 01:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 01:33:53 | 002,258,512 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 23:05:48 | 000,618,714 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 23:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 23:05:48 | 000,107,034 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 23:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 23:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 23:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 20:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 20:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 20:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 18:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/04/02 09:30:14 | 000,010,296 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS
[2009/02/19 00:35:10 | 000,049,152 | R--- | C] () -- C:\Windows\DAOD.exe
[2005/11/19 01:29:38 | 010,192,896 | ---- | C] () -- C:\Windows\System32\drivers\snp2sxp.sys
[2004/12/10 00:23:10 | 000,015,497 | ---- | C] () -- C:\Windows\snp2std.ini
[2003/04/07 11:30:02 | 000,005,383 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
========== LOP Check ==========
[2011/04/10 16:34:05 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\All Free Video Converter
[2011/08/14 11:08:16 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\Audacity
[2011/05/16 21:03:57 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\Auslogics
[2011/07/30 16:43:42 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\Command & Conquer 3 Tiberium Wars
[2011/08/13 00:35:35 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\DAEMON Tools Lite
[2011/03/31 00:42:17 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\ESET
[2011/04/04 20:28:58 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\GlobalSCAPE
[2011/04/01 22:52:28 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\ManyCam
[2011/08/13 15:25:36 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\Mp3tag
[2011/03/31 22:55:34 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\NCH Swift Sound
[2011/08/07 21:33:00 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\Origin
[2011/06/02 21:57:29 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\Publish Providers
[2011/07/11 21:19:44 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\Red Alert 3
[2011/06/02 21:57:27 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\Sony
[2011/08/13 00:35:35 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\uTorrent
[2011/06/23 14:43:38 | 000,000,000 | ---D | M] -- C:\Users\Andre Voorhees\AppData\Roaming\Vso
[2011/08/18 19:04:59 | 000,032,608 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 171 bytes -> C:\ProgramData\TEMP:07BF512B
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:05EE1EEF
< End of report >
=======================
OTL Extras logfile created on: 19/08/2011 20:17:36 - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\Andre Voorhees\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
3,25 Gb Total Physical Memory | 1,73 Gb Available Physical Memory | 53,33% Memory free
11,37 Gb Paging File | 9,80 Gb Available in Paging File | 86,21% Paging File free
Paging file location(s): c:\pagefile.sys 0 0d:\pagefile.sys 4990 4990 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48,83 Gb Total Space | 26,16 Gb Free Space | 53,57% Space Free | Partition Type: NTFS
Drive D: | 184,05 Gb Total Space | 176,03 Gb Free Space | 95,64% Space Free | Partition Type: NTFS
Drive F: | 931,51 Gb Total Space | 418,05 Gb Free Space | 44,88% Space Free | Partition Type: NTFS
Computer Name: ANDREVOORHEES | User Name: Andre Voorhees | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-432924015-704257289-2575384188-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{0650BB10-BCF4-400A-85EE-04097E3046C6}" = Adobe Setup
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0FFEA8EE-7BC7-4C9D-8CC6-5B8C891BA3F2}" = Windows Live Essentials
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{18C9716F-C906-441F-BA66-CABAA5CB2DCE}" = Adobe XMP Panels CS4
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live
"{20A15757-4AE4-3C82-9711-863C84AFE6AA}" = Microsoft .NET Framework 4 Client Profile PTB Language Pack
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback 10
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 26
"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
"{28773E11-6E44-46DC-90BD-273A3FA2CAC1}" = Adobe Setup
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2DF215E0-BD3C-4C98-8616-AFEF09747285}" = Windows Live Sync
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{36A3719F-8A06-451A-935A-B4A5BAE77C87}" = ESET Smart Security
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{45410935-3E72-472B-8C35-AB1000008200}" = Bulletstorm
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{5454083B-1308-4485-BF17-1110000D8301}" = Grand Theft Auto IV
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{590035D9-BFA0-406A-A7F0-479C72C0DDB2}" = Windows Live Call
"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
"{679F739E-5C76-4A41-B562-F9392156B6DD}" = System Requirements Lab CYRI
"{6D4A54DD-C9E2-4647-B872-2E83C188584B}" = Windows Live Movie Maker
"{6D592E30-11EC-11E0-859C-0013D3D69929}" = Vegas Pro 10.0
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7032B400-11EC-11E0-A9BF-0013D3D69929}" = MSVCRT Redists
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}" = Adobe Dreamweaver CS3
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87A9C015-C2BA-44EE-9C20-6E1A764B8E23}" = Windows Live Galeria de Fotos
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{90110416-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edição 2003
"{90120000-0020-0416-0000-0000000FF1CE}" = Pacote de Compatibilidade para o sistema Office 2007
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{91F34319-08DE-457a-99C0-0BCDFAC145B9}" = CuteFTP 8 Professional
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A996B6A-846E-4A89-B9C4-17546B7BE49F}" = Burnout(TM) Paradise The Ultimate Box
"{9ADC3E4F-34DA-48CD-8727-BB26D90257BD}" = Windows Live Messenger
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B0C30E93-D3D9-4F04-A2AC-54749B573275}" = Command & Conquer 3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Driver do 3D Vision 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Painel de controle da NVIDIA 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Driver de gráficos 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Driver de controle do 3D Vision 280.19
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Software do sistema PhysX 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Atualizações da NVIDIA 1.4.28
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA Driver de áudio HD 1.2.23.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
"{C39D3751-2E01-442B-9B98-8037862DD58D}_is1" = JDownloader AntiRecaptcha versão 1 By RoberWii
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.0.10.324
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E7044E25-3038-4A76-9064-344AC038043E}" = Atualização de Driver do Windows Mobile Device Center
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"1489-3350-5074-6281" = JDownloader 0.9
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_7328fdfcb73660ec8b11d5a3d5c6232" = Adobe Dreamweaver CS3
"Adobe_ccb135070a90ff24d6e7cc4bc5a59cb" = Adobe Fireworks CS4
"All Free Video Converter_is1" = All Free Video Converter 4.1.6
"aTube Catcher" = aTube Catcher
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"Capsule" = Capsule
"CCleaner" = CCleaner
"DAEMON Tools Lite" = DAEMON Tools Lite
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.50
"Foxit Reader" = Foxit Reader
"Fraps" = Fraps (remove only)
"GFWL_{45410935-3E72-472B-8C35-AB1000008200}" = Bulletstorm
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Gerenciador de dispositivo de plataforma
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 7.6.0
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"ManyCam" = ManyCam 2.6.43 (remove only)
"Messenger Plus!" = Messenger Plus! 5
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile PTB Language Pack" = Pacote de Idiomas do Microsoft .NET Framework 4 Client Profile - Português (Brasil)
"Mozilla Firefox 6.0 (x86 pt-BR)" = Mozilla Firefox 6.0 (x86 pt-BR)
"Mp3tag" = Mp3tag v2.49
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Origin" = Origin
"Steam App 9930" = Test Drive Unlimited 2
"Switch" = Switch Sound File Converter
"SystemRequirementsLab" = System Requirements Lab
"uTorrent" = µTorrent
"Winamp" = Winamp
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Arquivo do WinRAR
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-432924015-704257289-2575384188-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Detectar Aplicação
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 07/08/2011 22:46:18 | Computer Name = AndreVoorhees | Source = RasClient | ID = 20227
Description =
Error - 07/08/2011 22:46:35 | Computer Name = AndreVoorhees | Source = RasClient | ID = 20227
Description =
Error - 11/08/2011 18:30:26 | Computer Name = AndreVoorhees | Source = Application Error | ID = 1000
Description = Nome de aplicativo com falha: wmplayer.exe, versão: 12.0.7601.17514,
carimbo de hora: 0x4ce7a485 Nome do módulo de falhas: unknown, versão: 0.0.0.0,
carimbo de hora: 0x00000000 Código de exceção: 0xc0000005 Deslocamento com falha:
0xfb1e5cea Identificação do processo com falha: 0xc54 Hora de início do aplicativo
com falha: 0x01cc5875b28a8127 Caminho do aplicativo com falha: C:\Program Files\Windows
Media Player\wmplayer.exe FCaminho do módulo de falhas: unknown Identificação do
Relatório: 82199ac8-c469-11e0-b2a9-20cf30bb98d8
Error - 14/08/2011 10:33:03 | Computer Name = AndreVoorhees | Source = Application Error | ID = 1000
Description = Nome de aplicativo com falha: AUDIODG.EXE, versão: 6.1.7601.17514,
carimbo de hora: 0x4ce7a278 Nome do módulo de falhas: VIASysFx.dll, versão: 1.0.0.0,
carimbo de hora: 0x4beb78d4 Código de exceção: 0xc0000094 Deslocamento com falha:
0x0005b68c Identificação do processo com falha: 0xf24 Hora de início do aplicativo
com falha: 0x01cc5a89e73db23f Caminho do aplicativo com falha: C:\Windows\system32\AUDIODG.EXE
FCaminho
do módulo de falhas: C:\Windows\system32\VIASysFx.dll Identificação do Relatório:
51158c50-c682-11e0-b8c4-20cf30bb98d8
Error - 14/08/2011 10:33:56 | Computer Name = AndreVoorhees | Source = Application Hang | ID = 1002
Description = O programa mpc-hc.exe versão 1.5.3.3611 parou de interagir com o Windows
e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique
o histórico de problemas no painel de controle da Central de Ações. ID de Processo:
e8c Hora de Início: 01cc5a8f282f5007 Hora de Término: 16 Caminho do Aplicativo: C:\Program
Files\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe Id do Relatório: 6f5bddb5-c682-11e0-b8c4-20cf30bb98d8
Error - 15/08/2011 18:15:30 | Computer Name = AndreVoorhees | Source = Application Error | ID = 1000
Description = Nome de aplicativo com falha: AUDIODG.EXE, versão: 6.1.7601.17514,
carimbo de hora: 0x4ce7a278 Nome do módulo de falhas: VIASysFx.dll, versão: 1.0.0.0,
carimbo de hora: 0x4beb78d4 Código de exceção: 0xc0000094 Deslocamento com falha:
0x0005b68c Identificação do processo com falha: 0x430 Hora de início do aplicativo
com falha: 0x01cc5b98ce025017 Caminho do aplicativo com falha: C:\Windows\system32\AUDIODG.EXE
FCaminho
do módulo de falhas: C:\Windows\system32\VIASysFx.dll Identificação do Relatório:
159ba190-c78c-11e0-97cf-20cf30bb98d8
Error - 17/08/2011 19:21:09 | Computer Name = AndreVoorhees | Source = Application Hang | ID = 1002
Description = O programa firefox.exe versão 6.0.0.4240 parou de interagir com o
Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema,
verifique o histórico de problemas no painel de controle da Central de Ações. ID
de Processo: 175c Hora de Início: 01cc5d34469c3589 Hora de Término: 30 Caminho do
Aplicativo: C:\Program Files\Mozilla Firefox\firefox.exe Id do Relatório: 94cabd79-c927-11e0-8260-20cf30bb98d8
Error - 18/08/2011 23:11:04 | Computer Name = AndreVoorhees | Source = Lavasoft Ad-Aware Service | ID = 0
Description =
Error - 18/08/2011 23:42:24 | Computer Name = AndreVoorhees | Source = Application Hang | ID = 1002
Description = O programa Ad-AwareAdmin.exe versão 9.0.0.0 parou de interagir com
o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema,
verifique o histórico de problemas no painel de controle da Central de Ações. ID
de Processo: 4ac Hora de Início: 01cc5e1ed0d00d89 Hora de Término: 13 Caminho do Aplicativo:
C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Id do Relatório: 3f127731-ca15-11e0-9577-20cf30bb98d8
Error - 19/08/2011 19:10:17 | Computer Name = AndreVoorhees | Source = RasClient | ID = 20227
Description =
[ System Events ]
Error - 19/08/2011 17:54:36 | Computer Name = AndreVoorhees | Source = atapi | ID = 262155
Description = O driver detectou um erro de controlador em \Device\Ide\IdePort0.
Error - 19/08/2011 18:10:34 | Computer Name = AndreVoorhees | Source = Service Control Manager | ID = 7030
Description = O serviço PEVSystemStart está marcado como um serviço interativo.
No entanto, o sistema está configurado para não permitir serviços interativos. Esse
serviço pode não funcionar corretamente.
Error - 19/08/2011 18:13:36 | Computer Name = AndreVoorhees | Source = Service Control Manager | ID = 7030
Description = O serviço PEVSystemStart está marcado como um serviço interativo.
No entanto, o sistema está configurado para não permitir serviços interativos. Esse
serviço pode não funcionar corretamente.
Error - 19/08/2011 18:16:05 | Computer Name = AndreVoorhees | Source = Service Control Manager | ID = 7030
Description = O serviço PEVSystemStart está marcado como um serviço interativo.
No entanto, o sistema está configurado para não permitir serviços interativos. Esse
serviço pode não funcionar corretamente.
Error - 19/08/2011 18:45:20 | Computer Name = AndreVoorhees | Source = Service Control Manager | ID = 7030
Description = O serviço PEVSystemStart está marcado como um serviço interativo.
No entanto, o sistema está configurado para não permitir serviços interativos. Esse
serviço pode não funcionar corretamente.
Error - 19/08/2011 18:47:35 | Computer Name = AndreVoorhees | Source = Service Control Manager | ID = 7030
Description = O serviço PEVSystemStart está marcado como um serviço interativo.
No entanto, o sistema está configurado para não permitir serviços interativos. Esse
serviço pode não funcionar corretamente.
Error - 19/08/2011 18:49:48 | Computer Name = AndreVoorhees | Source = Service Control Manager | ID = 7030
Description = O serviço PEVSystemStart está marcado como um serviço interativo.
No entanto, o sistema está configurado para não permitir serviços interativos. Esse
serviço pode não funcionar corretamente.
Error - 19/08/2011 19:03:41 | Computer Name = AndreVoorhees | Source = Service Control Manager | ID = 7030
Description = O serviço PEVSystemStart está marcado como um serviço interativo.
No entanto, o sistema está configurado para não permitir serviços interativos. Esse
serviço pode não funcionar corretamente.
Error - 19/08/2011 19:05:54 | Computer Name = AndreVoorhees | Source = Service Control Manager | ID = 7030
Description = O serviço PEVSystemStart está marcado como um serviço interativo.
No entanto, o sistema está configurado para não permitir serviços interativos. Esse
serviço pode não funcionar corretamente.
Error - 19/08/2011 19:08:08 | Computer Name = AndreVoorhees | Source = Service Control Manager | ID = 7030
Description = O serviço PEVSystemStart está marcado como um serviço interativo.
No entanto, o sistema está configurado para não permitir serviços interativos. Esse
serviço pode não funcionar corretamente.
< End of report >