Pessoal,
Perdão pela demora. A correria do mês de fevereiro foi tamanha que não tive tempo de acessar o fórum. Quem estiver necessitando de ajuda ainda peço que poste novamente.
Olá wmh, seus logs estão limpos amigo. Sem indícios de infecção. Algum problema que queira relatar?
Abraços
Caro,
Havia postado há umas semanas atrás q meu pc está infectado com o Rootkit TDSS.v2. Segue a repostagem com os logs:
Segue o log do OTL:
OTL logfile created on: 16/02/2012 18:53:24 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Anderson Backup\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
3,00 Gb Total Physical Memory | 1,74 Gb Available Physical Memory | 57,95% Memory free
6,00 Gb Paging File | 4,23 Gb Available in Paging File | 70,54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 54,52 Gb Total Space | 11,84 Gb Free Space | 21,71% Space Free | Partition Type: NTFS
Drive D: | 199,29 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 20,00 Gb Total Space | 4,45 Gb Free Space | 22,26% Space Free | Partition Type: NTFS
Computer Name: AND-PC | User Name: Anderson Backup | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/02/15 19:21:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Anderson Backup\Desktop\OTL.exe
PRC - [2012/02/12 01:30:03 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/01/29 20:29:10 | 000,341,920 | ---- | M] () -- C:\Program Files\TIM Communicator\orolixcommunicator.exe
PRC - [2012/01/27 22:49:39 | 000,026,528 | ---- | M] (Orolix Desenvolvimento de Software LTDA.) -- C:\Program Files\TIM Communicator\module\devicemon.exe
PRC - [2012/01/16 16:28:30 | 000,546,768 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
PRC - [2012/01/11 16:18:14 | 002,659,768 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe
PRC - [2012/01/11 16:18:14 | 001,117,624 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe
PRC - [2012/01/11 14:56:12 | 000,402,336 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe
PRC - [2012/01/11 14:56:08 | 000,071,008 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools\PC Tools Security\TFEngine\TFService.exe
PRC - [2011/11/12 14:56:14 | 001,479,168 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\Explorer++.exe
PRC - [2011/10/15 06:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/10/15 06:53:00 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2011/10/15 06:53:00 | 001,328,960 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
PRC - [2011/10/15 00:54:40 | 000,381,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/08/15 15:17:06 | 000,603,456 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\OneClick.exe
PRC - [2011/08/15 15:16:42 | 001,051,968 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\Integrator.exe
PRC - [2011/08/15 15:11:40 | 000,671,552 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
PRC - [2011/08/15 15:09:06 | 001,526,080 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
PRC - [2011/08/15 15:05:48 | 000,426,304 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TUDefragBackend32.exe
PRC - [2011/06/24 02:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/06/06 13:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/06 18:33:00 | 000,393,112 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
PRC - [2011/02/25 03:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/11/20 04:17:48 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/12/23 19:34:20 | 000,370,688 | ---- | M] (StarWind Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2009/08/10 15:59:50 | 000,178,720 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2009/08/10 15:59:48 | 000,387,616 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt. exe
PRC - [2009/08/04 17:29:54 | 000,219,360 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2009/08/04 17:29:52 | 000,346,320 | ---- | M] (DeviceVM, Inc.) -- C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2008/06/25 03:08:20 | 001,855,488 | ---- | M] (C-Media Electronic Inc. (
C-Media Electronics, Inc.)) -- C:\Windows\mixer.exe
========== Modules (No Company Name) ==========
MOD - [2012/02/12 01:30:03 | 001,911,768 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/01/29 20:29:10 | 000,341,920 | ---- | M] () -- C:\Program Files\TIM Communicator\orolixcommunicator.exe
MOD - [2012/01/29 20:24:34 | 000,032,160 | ---- | M] () -- C:\Program Files\TIM Communicator\module\modqoscommunicator.dll
MOD - [2012/01/27 21:32:02 | 000,968,704 | ---- | M] () -- C:\Users\Anderson Backup\AppData\Roaming\Mozilla\Firefox\Profiles\ce 9qzd59.default\extensions\support@lastpass.com\pla tform\WINNT_x86-msvc\components\lpxpcom.dll
MOD - [2012/01/11 16:18:42 | 000,861,112 | ---- | M] () -- C:\Program Files\PC Tools\PC Tools Security\SpamMonitor\SMPlugin.dll
MOD - [2012/01/11 16:18:16 | 000,376,248 | ---- | M] () -- C:\Program Files\PC Tools\PC Tools Security\PCTUI\PCTUI.dll
MOD - [2012/01/09 16:56:56 | 000,079,872 | ---- | M] () -- C:\Users\Anderson Backup\AppData\Roaming\Mozilla\Firefox\Profiles\ce 9qzd59.default\extensions\{8c311d0a-7d76-4f96-a7b6-0a2758dee5a4}\components\RadioWMPCoreGecko10.dll
MOD - [2011/11/12 14:56:14 | 001,479,168 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\Explorer++.exe
MOD - [2011/10/15 00:54:26 | 000,265,536 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2011/08/15 15:14:16 | 000,544,064 | ---- | M] () -- C:\Program Files\TuneUp Utilities 2011\TUSqlDB32.dll
MOD - [2011/03/17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/06/29 19:15:40 | 000,337,312 | ---- | M] () -- C:\Program Files\TIM Communicator\module\plugins\sqldrivers\qsqlite4.dl l
MOD - [2010/06/29 19:15:40 | 000,222,624 | ---- | M] () -- C:\Program Files\TIM Communicator\module\plugins\phonon_backend\phonon_ ds94.dll
MOD - [2010/06/29 19:15:40 | 000,189,856 | ---- | M] () -- C:\Program Files\TIM Communicator\module\plugins\imageformats\qjpeg4.dl l
MOD - [2010/06/29 19:15:40 | 000,075,168 | ---- | M] () -- C:\Program Files\TIM Communicator\module\plugins\imageformats\qico4.dll
MOD - [2010/06/29 19:15:40 | 000,075,168 | ---- | M] () -- C:\Program Files\TIM Communicator\module\plugins\imageformats\qgif4.dll
MOD - [2010/06/29 11:15:56 | 007,796,128 | ---- | M] () -- C:\Program Files\TIM Communicator\module\QtWebKit4.dll
MOD - [2010/06/29 11:15:56 | 006,350,240 | ---- | M] () -- C:\Program Files\TIM Communicator\module\QtGui4.dll
MOD - [2010/06/29 11:15:56 | 001,770,912 | ---- | M] () -- C:\Program Files\TIM Communicator\module\QtCore4.dll
MOD - [2010/06/29 11:15:56 | 001,451,424 | ---- | M] () -- C:\Program Files\TIM Communicator\module\QtNetwork4.dll
MOD - [2010/06/29 11:15:56 | 000,263,584 | ---- | M] () -- C:\Program Files\TIM Communicator\module\QtXml4.dll
MOD - [2010/06/29 11:15:56 | 000,206,240 | ---- | M] () -- C:\Program Files\TIM Communicator\module\phonon4.dll
MOD - [2010/06/29 11:15:56 | 000,152,992 | ---- | M] () -- C:\Program Files\TIM Communicator\module\QtSql4.dll
MOD - [2009/07/30 18:15:32 | 000,503,202 | ---- | M] () -- C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll
========== Win32 Services (SafeList) ==========
SRV - [2012/02/11 22:26:26 | 000,481,064 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/01/27 22:49:39 | 000,026,528 | ---- | M] (Orolix Desenvolvimento de Software LTDA.) [Auto | Running] -- C:\Program Files\TIM Communicator\module\devicemon.exe -- (OrolixDeviceMonitor)
SRV - [2012/01/16 16:28:30 | 000,546,768 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2012/01/11 16:18:14 | 001,117,624 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe -- (sdCoreService)
SRV - [2012/01/11 14:56:12 | 000,402,336 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2012/01/11 14:56:08 | 000,071,008 | ---- | M] (PC Tools) [On_Demand | Running] -- C:\Program Files\PC Tools\PC Tools Security\TFEngine\TFService.exe -- (ThreatFire)
SRV - [2011/10/15 06:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/10/15 00:54:40 | 000,381,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/08/15 15:09:06 | 001,526,080 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2011/08/15 15:03:24 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2011/06/12 12:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2011/06/06 13:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/05/06 18:33:00 | 000,393,112 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2011/01/24 14:49:34 | 000,310,640 | ---- | M] (CybelSoft) [On_Demand | Stopped] -- C:\Program Files\ma-config.com\maconfservice.exe -- (maconfservice)
SRV - [2011/01/08 13:44:41 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2009/12/23 19:34:20 | 000,370,688 | ---- | M] (StarWind Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2009/08/10 15:59:50 | 000,178,720 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)
SRV - [2009/08/10 15:59:48 | 000,387,616 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt. exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2009/08/04 17:29:54 | 000,219,360 | ---- | M] (DeviceVM, Inc.) [Auto | Running] -- C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe -- (BCUService)
SRV - [2009/07/13 23:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 23:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 23:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - [2012/02/13 20:01:42 | 000,054,624 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\0ca6E9B.sys -- (0ca6E9B)
DRV - [2012/02/13 19:47:57 | 000,054,624 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\6c3223.sys -- (6c3223)
DRV - [2012/02/13 19:37:05 | 000,054,624 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\6c67A4E.sys -- (6c67A4E)
DRV - [2012/02/13 19:28:17 | 000,054,624 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\19bB13E.sys -- (19bB13E)
DRV - [2012/01/11 16:19:24 | 000,070,536 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\pctplsg.sys -- (pctplsg)
DRV - [2012/01/11 16:19:12 | 000,125,888 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\pctplfw.sys -- (pctplfw)
DRV - [2012/01/11 16:19:02 | 000,185,560 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\System32\drivers\PCTSD.sys -- (PCTSD)
DRV - [2012/01/11 16:14:30 | 000,253,352 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\System32\drivers\pctgntdi.sys -- (pctgntdi)
DRV - [2012/01/11 14:56:12 | 000,574,424 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\TfSysMon.sys -- (TFSysMon)
DRV - [2012/01/11 14:56:12 | 000,054,328 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\TfFsMon.sys -- (TfFsMon)
DRV - [2012/01/11 14:56:12 | 000,035,264 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\TfNetMon.sys -- (TfNetMon)
DRV - [2011/12/01 16:07:06 | 000,909,728 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\Windows\system32\drivers\pctEFA.sys -- (pctEFA)
DRV - [2011/12/01 16:07:06 | 000,342,168 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\pctDS.sys -- (pctDS)
DRV - [2011/11/30 09:19:48 | 000,058,400 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\System32\drivers\pctNdisLW.sys -- (pctNdisLW)
DRV - [2011/11/14 15:12:26 | 000,331,880 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2011/11/14 15:12:24 | 000,162,584 | ---- | M] (PC Tools) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\PCTAppEvent.sys -- (PCTAppEvent)
DRV - [2011/11/09 16:33:30 | 000,091,136 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\pctNdis-PacketFilter.sys -- (PCTFW-PacketFilter)
DRV - [2011/10/15 06:53:00 | 010,327,360 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2011/09/28 13:14:02 | 000,056,840 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PCTBD.sys -- (PCTBD)
DRV - [2011/05/31 15:03:04 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2011/01/08 16:57:36 | 000,436,792 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010/11/20 04:30:16 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 04:30:16 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 04:30:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 02:24:42 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 02:21:16 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 01:59:46 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 01:14:46 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 01:14:42 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/10/24 22:25:38 | 000,054,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2010/10/24 22:25:38 | 000,043,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2010/08/30 11:19:54 | 000,014,336 | ---- | M] (CybelSoft) [Kernel | On_Demand | Stopped] -- C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys -- (driverhardwarev2)
DRV - [2010/08/12 12:07:48 | 000,298,216 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmf6232.sys -- (NVNET)
DRV - [2010/07/14 13:51:56 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2010/06/02 10:50:36 | 000,105,088 | ---- | M] (Onda Communication) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ONDAusbvoice.sys -- (ONDAusbvoice)
DRV - [2010/06/02 10:50:36 | 000,105,088 | ---- | M] (Onda Communication) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Ondausbser6k.sys -- (ONDAusbser6k)
DRV - [2010/06/02 10:50:36 | 000,105,088 | ---- | M] (Onda Communication) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Ondausbnmea.sys -- (ONDAusbnmea)
DRV - [2010/06/02 10:50:36 | 000,105,088 | ---- | M] (Onda Communication) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Ondausbmdm6k.sys -- (ONDAusbmdm6k)
DRV - [2009/08/04 17:43:40 | 000,213,024 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2009/07/13 20:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009/04/29 15:37:26 | 000,025,088 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\KMWDFILTER.sys -- (KMWDFILTERx86)
DRV - [2008/06/25 03:08:20 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2007/11/08 11:30:08 | 000,454,656 | ---- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PAC7302.sys -- (PAC7302)
DRV - [2007/06/29 15:47:34 | 000,034,304 | ---- | M] (AMD, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AmdLLD.sys -- (AmdLLD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVer sion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Inter net Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-497863422-237361048-368514812-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
A maioria dos profissionais diretório websites, mais próximos os serviços vivos
IE - HKU\S-1-5-21-497863422-237361048-368514812-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-BR
IE - HKU\S-1-5-21-497863422-237361048-368514812-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B0 CE EF 32 65 4E CC 01 [binary data]
IE - HKU\S-1-5-21-497863422-237361048-368514812-1007\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKU\S-1-5-21-497863422-237361048-368514812-1007\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-497863422-237361048-368514812-1007\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "socialbrowser Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3083266&SearchSource=3&q={s earchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=642886"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.facebook.com/"
FF - prefs.js..extensions.enabledItems:
iobit@mybrowserbar.com:4.4
FF - prefs.js..extensions.enabledItems:
wtxpcom@mybrowserbar.com:4.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.5
FF - prefs.js..extensions.enabledItems:
foxmarks@kei.com:4.0.1
FF - prefs.js..extensions.enabledItems:
support@lastpass.com:1.74.0
FF - prefs.js..extensions.enabledItems:
glasser@sixxgate.com:3.5.2
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.2
FF - prefs.js..extensions.enabledItems: {d3f4b70a-92e0-4393-a0f3-976d03b1ebf5}:3.5.0.12
FF - prefs.js..extensions.enabledItems:
wrc@avast.com:6.0.1203
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3083266&SearchSource=2&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@ma-config.com/HardwareDetection: C:\Program Files\ma-config.com\nphardwaredetection.dll (Cybelsoft)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin \MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin \MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extens ions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin \Firefox\Ext [2012/02/01 22:40:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extens ions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\ [2012/02/11 17:00:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/12 01:30:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/01 22:40:27 | 000,000,000 | ---D | M]
[2011/07/28 21:49:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Anderson Backup\AppData\Roaming\mozilla\Extensions
[2012/02/10 06:23:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Anderson Backup\AppData\Roaming\mozilla\Firefox\Profiles\ce 9qzd59.default\extensions
[2012/01/30 22:19:36 | 000,000,000 | ---D | M] (socialbrowser Community Toolbar) -- C:\Users\Anderson Backup\AppData\Roaming\mozilla\Firefox\Profiles\ce 9qzd59.default\extensions\{8c311d0a-7d76-4f96-a7b6-0a2758dee5a4}
[2012/01/29 23:29:21 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Anderson Backup\AppData\Roaming\mozilla\Firefox\Profiles\ce 9qzd59.default\extensions\foxmarks@kei.com
[2012/01/29 23:29:23 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Anderson Backup\AppData\Roaming\mozilla\Firefox\Profiles\ce 9qzd59.default\extensions\support@lastpass.com
[2012/02/10 06:23:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Anderson Backup\AppData\Roaming\mozilla\Firefox\Profiles\ce 9qzd59.default\extensions\trash
[2011/08/02 07:15:01 | 000,002,394 | ---- | M] () -- C:\Users\Anderson Backup\AppData\Roaming\Mozilla\Firefox\Profiles\ce 9qzd59.default\searchplugins\askcom.xml
[2011/09/01 02:35:48 | 000,000,929 | ---- | M] () -- C:\Users\Anderson Backup\AppData\Roaming\Mozilla\Firefox\Profiles\ce 9qzd59.default\searchplugins\conduit.xml
[2012/01/31 19:34:42 | 000,001,390 | ---- | M] () -- C:\Users\Anderson Backup\AppData\Roaming\Mozilla\Firefox\Profiles\ce 9qzd59.default\searchplugins\yahoo-zugo.xml
[2012/02/01 22:17:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\ANDERSON BACKUP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CE 9QZD59.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) -- C:\USERS\ANDERSON BACKUP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CE 9QZD59.DEFAULT\EXTENSIONS\{46551EC9-40F0-4E47-8E18-8E5CF550CFB8}.XPI
() (No name found) -- C:\USERS\ANDERSON BACKUP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\CE 9QZD59.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/02/12 01:30:03 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/10/12 17:33:32 | 000,124,344 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CCMSDK.dll
[2010/10/12 17:37:06 | 000,070,592 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2010/10/12 17:35:42 | 000,091,576 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\confmgr.dll
[2010/10/12 17:34:56 | 000,022,464 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2011/05/04 05:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/10/12 19:16:54 | 000,484,768 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npicaN.dll
[2010/10/12 17:37:02 | 000,024,000 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
[2012/02/01 22:17:18 | 000,001,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\buscape.xml
[2012/02/01 22:17:18 | 000,001,212 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\mercadolivre.xml
[2012/02/01 22:17:18 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/02/01 22:17:18 | 000,001,168 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-br.xml
[2012/02/01 22:17:18 | 000,000,952 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-br.xml
O1 HOSTS File: ([2012/02/02 21:05:48 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin \IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-497863422-237361048-368514812-1007\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [C-Media Mixer] C:\Windows\mixer.exe (C-Media Electronic Inc. (
C-Media Electronics, Inc.))
O4 - HKLM..\Run: [C-Media Speaker Configuration] C:\Program Files\C-Media\WIN_ME\Setup.exe ()
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKU\S-1-5-21-497863422-237361048-368514812-1007..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-497863422-237361048-368514812-1006..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-497863422-237361048-368514812-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-497863422-237361048-368514812-1007\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-497863422-237361048-368514812-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-497863422-237361048-368514812-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-497863422-237361048-368514812-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-497863422-237361048-368514812-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: &Enviar para o OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE}
http://download.gigabyte.com.tw/object/Dldrv.ocx (Dldrv2 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D}
http://content.systemrequirementslab...i_4.4.13.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{2DF936A8-3AA1-425E-BE05-C82D535A9FEE}: NameServer = 200.220.227.56 200.142.130.202
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.ex e (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 19:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/16 06:37:52 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012/02/16 06:37:51 | 001,798,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012/02/16 06:37:51 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012/02/16 06:37:50 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012/02/16 06:37:50 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012/02/16 06:37:47 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012/02/15 19:23:46 | 002,061,360 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Anderson Backup\Desktop\tdsskiller.exe
[2012/02/15 19:21:17 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Anderson Backup\Desktop\OTL.exe
[2012/02/15 06:53:14 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl
[2012/02/15 06:47:34 | 002,343,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012/02/13 22:26:01 | 003,932,160 | ---- | C] (PC Tools ) -- C:\Users\Anderson Backup\Desktop\tfinstall(1).exe
[2012/02/13 21:29:18 | 002,901,264 | ---- | C] (PC Tools ) -- C:\Users\Anderson Backup\Desktop\tfinstall.exe
[2012/02/13 19:53:19 | 000,000,000 | -HSD | C] -- C:\found.000
[2012/02/13 19:27:41 | 001,774,432 | ---- | C] (McAfee, Inc.) -- C:\Users\Anderson Backup\Desktop\Rootkit_Detective.exe
[2012/02/12 13:00:12 | 000,000,000 | ---D | C] -- C:\Users\Anderson Backup\Desktop\explorer++_1.3.4_x86
[2012/02/12 03:40:28 | 000,000,000 | ---D | C] -- C:\Users\Anderson Backup\Desktop\best
[2012/02/12 03:00:44 | 000,000,000 | ---D | C] -- C:\Users\Anderson Backup\Desktop\captchatrader
[2012/02/12 02:38:29 | 000,000,000 | ---D | C] -- C:\!KillBox
[2012/02/12 02:37:22 | 000,092,672 | ---- | C] (Option^Explicit Software
vbtechcd@gmail.com) -- C:\Users\Anderson Backup\Desktop\KillBox.exe
[2012/02/12 02:26:31 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Anderson Backup\Desktop\HijackThis.exe
[2012/02/12 01:49:34 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/02/12 01:49:24 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/02/12 01:40:06 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/02/12 01:40:06 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/02/12 01:40:06 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/02/12 01:39:59 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/02/12 01:29:21 | 000,000,000 | ---D | C] -- C:\60329_combofix_1112282301016
[2012/02/11 17:44:57 | 000,000,000 | ---D | C] -- C:\Users\Anderson Backup\AppData\Roaming\PC Tools
[2012/02/11 17:44:54 | 000,000,000 | ---D | C] -- C:\Users\Anderson Backup\AppData\Roaming\Spam Monitor
[2012/02/11 17:00:50 | 000,056,840 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTBD.sys
[2012/02/11 17:00:49 | 000,149,456 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2012/02/11 17:00:48 | 002,246,608 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2012/02/11 17:00:48 | 001,681,360 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2012/02/11 16:59:50 | 000,253,352 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2012/02/11 16:59:50 | 000,107,864 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2012/02/11 16:59:36 | 000,017,848 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctBTFix.sys
[2012/02/11 16:59:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2012/02/11 16:59:34 | 000,574,424 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfSysMon.sys
[2012/02/11 16:59:34 | 000,054,328 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfFsMon.sys
[2012/02/11 16:59:34 | 000,035,264 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfNetMon.sys
[2012/02/11 16:59:24 | 000,091,136 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2012/02/11 16:59:24 | 000,058,400 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdisLW.sys
[2012/02/11 16:59:23 | 000,125,888 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplfw.sys
[2012/02/11 16:59:23 | 000,032,936 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdis-DNS.sys
[2012/02/11 16:59:20 | 000,070,536 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2012/02/11 16:59:00 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
[2012/02/11 13:53:23 | 000,909,728 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctEFA.sys
[2012/02/11 13:53:22 | 000,342,168 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctDS.sys
[2012/02/11 13:53:21 | 000,331,880 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2012/02/11 13:53:21 | 000,162,584 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2012/02/11 13:53:19 | 000,185,560 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2012/02/11 13:40:12 | 000,000,000 | ---D | C] -- C:\Users\Anderson Backup\AppData\Roaming\TestApp
[2012/02/11 07:39:38 | 000,000,000 | ---D | C] -- C:\60329_combofix_1112282219266
[2012/02/11 07:30:35 | 004,354,969 | R--- | C] (Swearware) -- C:\Users\Anderson Backup\Desktop\60329_combofix_1112282.exe
[2012/02/11 07:19:40 | 000,000,000 | ---D | C] -- C:\60329_combofix_1112282
[2012/02/08 19:42:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2012/02/08 19:42:24 | 000,000,000 | ---D | C] -- C:\Program Files\Steam
[2012/02/06 20:34:38 | 000,000,000 | ---D | C] -- C:\Users\Anderson Backup\AppData\Local\Ubisoft Game Launcher
[2012/02/06 19:41:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassins Creed Revelations
[2012/02/06 19:40:58 | 000,000,000 | ---D | C] -- C:\Program Files\AC Revelations
[2012/02/04 11:24:27 | 000,000,000 | ---D | C] -- C:\Users\Anderson Backup\Documents\Assassin's Creed Revelations
[2012/02/01 22:40:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2012/02/01 22:40:09 | 000,198,832 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2012/02/01 22:39:54 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2012/02/01 22:39:54 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2012/02/01 22:39:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2012/01/31 19:34:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2012/01/31 19:34:26 | 000,839,680 | ---- | C] (
www) -- C:\Windows\System32\lameACM.acm
[2012/01/31 19:34:17 | 000,151,552 | ---- | C] (fccHandler) -- C:\Windows\System32\ac3acm.acm
[2012/01/30 00:59:22 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2012/01/30 00:59:22 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2012/01/30 00:18:30 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2012/01/30 00:18:29 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2012/01/30 00:16:21 | 003,967,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012/01/30 00:16:21 | 003,912,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012/01/30 00:15:29 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012/01/30 00:02:06 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2012/01/29 23:58:30 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2012/01/29 23:57:21 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2012/01/29 23:53:59 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2012/01/29 23:53:59 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2012/01/29 22:16:23 | 000,000,000 | ---D | C] -- C:\Users\Anderson Backup\Desktop\License(6).avastlic
[2012/01/29 14:17:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Motorola Shared
[2012/01/29 14:17:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Motorola Driver Installer
[2012/01/28 15:32:44 | 018,871,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll
[2012/01/28 15:32:44 | 013,205,312 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvd3dum.dll
[2012/01/28 15:32:44 | 010,327,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys
[2012/01/28 15:32:44 | 000,061,248 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2012/01/28 15:32:43 | 017,248,576 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll
[2012/01/28 15:32:43 | 005,578,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll
[2012/01/28 15:32:43 | 002,401,088 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll
[2012/01/28 15:32:43 | 002,099,520 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll
[2012/01/27 20:05:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TIM Communicator
[2012/01/27 20:05:20 | 000,000,000 | ---D | C] -- C:\ProgramData\OrolixCommunicator
[2012/01/27 20:05:11 | 000,114,688 | ---- | C] (ONDA Corporation) -- C:\Windows\System32\drivers\ONDAusbnet.sys
[2012/01/27 20:05:11 | 000,105,088 | ---- | C] (Onda Communication) -- C:\Windows\System32\drivers\ONDAusbvoice.sys
[2012/01/27 20:05:11 | 000,105,088 | ---- | C] (Onda Communication) -- C:\Windows\System32\drivers\Ondausbser6k.sys
[2012/01/27 20:05:11 | 000,105,088 | ---- | C] (Onda Communication) -- C:\Windows\System32\drivers\Ondausbnmea.sys
[2012/01/27 20:05:11 | 000,105,088 | ---- | C] (Onda Communication) -- C:\Windows\System32\drivers\Ondausbmdm6k.sys
[2012/01/27 20:05:03 | 000,000,000 | ---D | C] -- C:\Program Files\TIM Communicator
[2011/08/01 23:06:39 | 003,486,088 | ---- | C] (Ask) -- C:\Program Files\Common Files\ApnToolbarInstaller.exe
[2011/08/01 23:06:39 | 000,143,240 | ---- | C] (Ask.com) -- C:\Program Files\Common Files\ApnStub.exe
[7 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/16 07:19:15 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/16 07:19:15 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/16 07:11:56 | 001,856,693 | ---- | M] () -- C:\Windows\System32\drivers\Cat.DB
[2012/02/16 07:09:34 | 000,413,000 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/02/16 07:08:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/02/16 06:40:13 | 000,675,200 | ---- | M] () -- C:\Windows\System32\prfh0416.dat
[2012/02/16 06:40:13 | 000,626,678 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/02/16 06:40:13 | 000,133,936 | ---- | M] () -- C:\Windows\System32\prfc0416.dat
[2012/02/16 06:40:13 | 000,111,216 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/02/15 19:26:31 | 002,061,360 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Anderson Backup\Desktop\tdsskiller.exe
[2012/02/15 19:21:59 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Anderson Backup\Desktop\OTL.exe
[2012/02/13 22:33:10 | 003,932,160 | ---- | M] (PC Tools ) -- C:\Users\Anderson Backup\Desktop\tfinstall(1).exe
[2012/02/13 22:20:08 | 002,901,264 | ---- | M] (PC Tools ) -- C:\Users\Anderson Backup\Desktop\tfinstall.exe
[2012/02/13 20:03:07 | 295,042,925 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/02/13 20:01:42 | 000,054,624 | ---- | M] () -- C:\Windows\System32\0ca6E9B.sys
[2012/02/13 20:01:39 | 002,335,270 | ---- | M] () -- C:\Windows\System32\9f96547.mht
[2012/02/13 19:47:57 | 000,054,624 | ---- | M] () -- C:\Windows\System32\6c3223.sys
[2012/02/13 19:47:49 | 002,335,270 | ---- | M] () -- C:\Windows\System32\88eE06F.mht
[2012/02/13 19:37:05 | 000,054,624 | ---- | M] () -- C:\Windows\System32\6c67A4E.sys
[2012/02/13 19:36:52 | 002,335,270 | ---- | M] () -- C:\Windows\System32\0404826.mht
[2012/02/13 19:28:17 | 000,054,624 | ---- | M] () -- C:\Windows\System32\19bB13E.sys
[2012/02/13 19:28:14 | 002,335,270 | ---- | M] () -- C:\Windows\System32\a77A5D8.mht
[2012/02/13 19:27:59 | 002,335,270 | ---- | M] () -- C:\Windows\System32\e096ABC.mht
[2012/02/13 19:22:07 | 000,744,853 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\PAVARK.exe
[2012/02/12 18:47:04 | 000,097,953 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\and.jpg
[2012/02/12 03:14:18 | 000,000,038 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\captchatrader.properties
[2012/02/12 03:08:24 | 000,592,189 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\explorer++_1.3.4_x86.zip
[2012/02/12 02:59:58 | 000,382,525 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\captchatrader4jdownloader_win.zip
[2012/02/12 02:36:29 | 000,090,350 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\Killbox 2.0.0.881.rar
[2012/02/12 02:27:47 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Anderson Backup\Desktop\HijackThis.exe
[2012/02/11 17:34:52 | 000,000,000 | ---- | M] () -- C:\Windows\System32\SM.lock
[2012/02/11 16:59:42 | 000,002,159 | ---- | M] () -- C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2012/02/11 13:40:13 | 000,001,544 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\sdsetup.exe.lnk
[2012/02/11 07:37:41 | 004,354,969 | R--- | M] (Swearware) -- C:\Users\Anderson Backup\Desktop\60329_combofix_1112282.exe
[2012/02/09 18:36:25 | 000,001,634 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\Dungeon Siege III.exe - Atalho.lnk
[2012/02/09 06:43:36 | 000,002,664 | ---- | M] () -- C:\Users\Anderson Backup\Documents\ax_files.xml
[2012/02/08 19:42:26 | 000,000,835 | ---- | M] () -- C:\Users\Public\Desktop\Steam.lnk
[2012/02/06 20:33:55 | 000,001,124 | ---- | M] () -- C:\Users\Anderson Backup\Desktop\UbisoftGameLauncher.exe - Atalho.lnk
[2012/02/06 19:41:03 | 000,001,884 | ---- | M] () -- C:\Users\Public\Desktop\Ñêà÷àòü Åùå Èãðû.lnk
[2012/02/06 19:41:03 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\Assassin's Creed Revelations.lnk
[2012/02/02 21:05:48 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/02/02 06:36:05 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/02 06:36:04 | 000,001,046 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/01 22:40:24 | 000,001,040 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012/02/01 22:40:09 | 000,198,832 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2012/02/01 22:39:54 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2012/02/01 22:39:54 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2012/02/01 22:39:53 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2012/01/31 23:21:31 | 000,001,750 | ---- | M] () -- C:\Users\Public\Desktop\Vuze.lnk
[2012/01/29 23:35:22 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012/01/29 21:35:20 | 000,000,921 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/27 20:05:20 | 000,000,850 | ---- | M] () -- C:\Users\Public\Desktop\TIM Communicator.lnk
[2012/01/27 00:21:24 | 000,237,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2012/01/25 16:00:00 | 000,079,360 | ---- | M] () -- C:\Windows\System32\ff_vfw.dll
[7 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/13 20:01:42 | 000,054,624 | ---- | C] () -- C:\Windows\System32\0ca6E9B.sys
[2012/02/13 20:01:39 | 002,335,270 | ---- | C] () -- C:\Windows\System32\9f96547.mht
[2012/02/13 19:49:47 | 295,042,925 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/02/13 19:47:57 | 000,054,624 | ---- | C] () -- C:\Windows\System32\6c3223.sys
[2012/02/13 19:47:49 | 002,335,270 | ---- | C] () -- C:\Windows\System32\88eE06F.mht
[2012/02/13 19:37:05 | 000,054,624 | ---- | C] () -- C:\Windows\System32\6c67A4E.sys
[2012/02/13 19:36:52 | 002,335,270 | ---- | C] () -- C:\Windows\System32\0404826.mht
[2012/02/13 19:28:17 | 000,054,624 | ---- | C] () -- C:\Windows\System32\19bB13E.sys
[2012/02/13 19:28:14 | 002,335,270 | ---- | C] () -- C:\Windows\System32\a77A5D8.mht
[2012/02/13 19:27:59 | 002,335,270 | ---- | C] () -- C:\Windows\System32\e096ABC.mht
[2012/02/13 19:19:54 | 000,744,853 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\PAVARK.exe
[2012/02/12 18:47:01 | 000,097,953 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\and.jpg
[2012/02/12 13:01:13 | 001,479,168 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\Explorer++.exe
[2012/02/12 03:14:17 | 000,000,038 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\captchatrader.properties
[2012/02/12 03:07:15 | 000,592,189 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\explorer++_1.3.4_x86.zip
[2012/02/12 02:59:31 | 000,382,525 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\captchatrader4jdownloader_win.zip
[2012/02/12 02:37:22 | 000,001,710 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\Mina de Download.url
[2012/02/12 02:35:30 | 000,090,350 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\Killbox 2.0.0.881.rar
[2012/02/12 01:40:06 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/02/12 01:40:06 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/02/12 01:40:06 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/02/12 01:40:06 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/02/12 01:40:06 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/02/11 17:34:52 | 000,000,000 | ---- | C] () -- C:\Windows\System32\SM.lock
[2012/02/11 17:00:49 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2012/02/11 17:00:49 | 000,003,488 | ---- | C] () -- C:\Windows\UDB.zip
[2012/02/11 17:00:49 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2012/02/11 17:00:49 | 000,000,879 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2012/02/11 17:00:49 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2012/02/11 16:59:42 | 000,002,159 | ---- | C] () -- C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2012/02/11 13:40:13 | 000,001,544 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\sdsetup.exe.lnk
[2012/02/09 18:36:25 | 000,001,634 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\Dungeon Siege III.exe - Atalho.lnk
[2012/02/08 19:42:26 | 000,000,835 | ---- | C] () -- C:\Users\Public\Desktop\Steam.lnk
[2012/02/06 20:33:55 | 000,001,124 | ---- | C] () -- C:\Users\Anderson Backup\Desktop\UbisoftGameLauncher.exe - Atalho.lnk
[2012/02/06 19:41:03 | 000,001,884 | ---- | C] () -- C:\Users\Public\Desktop\Ñêà÷àòü Åùå Èãðû.lnk
[2012/02/06 19:41:03 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\Assassin's Creed Revelations.lnk
[2012/02/01 22:40:24 | 000,001,040 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012/01/31 19:34:26 | 000,650,752 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2012/01/31 19:34:26 | 000,243,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2012/01/31 19:34:26 | 000,000,414 | ---- | C] () -- C:\Windows\System32\lame_acm.xml
[2012/01/31 19:34:15 | 000,079,360 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2012/01/27 20:05:20 | 000,000,850 | ---- | C] () -- C:\Users\Public\Desktop\TIM Communicator.lnk
[2011/10/15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2011/09/27 20:12:00 | 000,637,215 | ---- | C] () -- C:\ProgramData\bdinstall.bin
[2011/07/31 12:50:06 | 000,007,887 | ---- | C] () -- C:\Users\Anderson Backup\AppData\Roaming\pcouffin.cat
[2011/07/31 12:50:06 | 000,001,144 | ---- | C] () -- C:\Users\Anderson Backup\AppData\Roaming\pcouffin.inf
[2011/07/28 23:59:51 | 000,062,464 | ---- | C] () -- C:\Users\Anderson Backup\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/28 22:45:44 | 000,000,272 | ---- | C] () -- C:\Windows\reimage.ini
[2011/04/09 19:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/04/09 17:09:20 | 000,000,022 | ---- | C] () -- C:\Windows\cmm.dat
[2011/04/09 17:09:11 | 000,000,186 | ---- | C] () -- C:\Windows\System32\CleanMem.ini
[2011/04/05 09:54:49 | 000,129,024 | ---- | C] () -- C:\Windows\System32\AVERM.dll
[2011/04/05 09:54:49 | 000,028,672 | ---- | C] () -- C:\Windows\System32\AVEQT.dll
[2011/02/27 19:52:39 | 000,286,208 | ---- | C] () -- C:\Windows\System32\binkw32.dll
[2011/02/06 01:53:19 | 000,101,072 | ---- | C] () -- C:\Windows\UTP.exe
[2011/01/22 17:36:42 | 000,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2011/01/20 21:17:05 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/01/20 21:16:47 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/01/08 17:24:00 | 000,175,616 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011/01/08 15:46:49 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll
[2011/01/08 15:46:47 | 000,004,333 | ---- | C] () -- C:\Windows\mixerdef.ini
[2011/01/08 15:46:27 | 000,039,279 | ---- | C] () -- C:\Windows\cmijack.dat
[2011/01/08 15:46:27 | 000,028,165 | ---- | C] () -- C:\Windows\cmijack.ini
[2011/01/08 15:46:27 | 000,023,041 | ---- | C] () -- C:\Windows\cmaudio.dat
[2011/01/08 15:46:27 | 000,018,240 | ---- | C] () -- C:\Windows\cmaudio.ini
[2011/01/08 15:46:26 | 000,000,462 | ---- | C] () -- C:\Windows\CMISETUP.INI
[2011/01/08 15:10:37 | 000,006,136 | R--- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2011/01/08 12:58:28 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/01/27 00:09:02 | 000,053,299 | ---- | C] () -- C:\Windows\System32\pthreadVC.dll
[2009/07/14 06:31:12 | 000,675,200 | ---- | C] () -- C:\Windows\System32\prfh0416.dat
[2009/07/14 06:31:12 | 000,323,154 | ---- | C] () -- C:\Windows\System32\prfi0416.dat
[2009/07/14 06:31:12 | 000,133,936 | ---- | C] () -- C:\Windows\System32\prfc0416.dat
[2009/07/14 06:31:12 | 000,038,536 | ---- | C] () -- C:\Windows\System32\prfd0416.dat
[2009/07/14 02:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 02:33:53 | 000,413,000 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 00:05:48 | 000,626,678 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 00:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 00:05:48 | 000,111,216 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 00:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 00:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 00:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 21:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 21:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 21:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 19:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2007/06/21 04:34:08 | 000,203,328 | R--- | C] () -- C:\Windows\GSetup.exe
[2007/01/31 14:50:32 | 000,913,408 | ---- | C] () -- C:\Windows\System32\xreglib.dll
========== LOP Check ==========
[2011/12/08 21:07:49 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\Activision
[2012/02/10 22:31:55 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\Azureus
[2011/08/17 22:16:22 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\bizarre creations
[2011/08/10 21:27:36 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\FreeArc
[2011/08/04 20:36:11 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\ICAClient
[2012/02/10 22:13:19 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\IObit
[2011/09/18 21:06:51 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\Need for Speed World
[2011/09/27 20:12:25 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\QuickScan
[2012/02/11 17:44:54 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\Spam Monitor
[2012/02/11 13:40:12 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\TestApp
[2011/10/10 23:54:08 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\TuneUp Software
[2012/02/01 23:14:53 | 000,000,000 | ---D | M] -- C:\Users\Anderson Backup\AppData\Roaming\Vso
[2012/02/10 20:20:46 | 000,032,608 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2011/10/11 20:33:39 | 000,000,000 | ---- | M] ()(C:\Windows\System32\?????) -- C:\Windows\System32\wlboa
[2011/10/11 20:28:28 | 000,000,000 | ---- | C] ()(C:\Windows\System32\?????) -- C:\Windows\System32\wlboa
========== Alternate Data Streams ==========
@Alternate Data Stream - 272 bytes -> C:\ProgramData\TEMPFC5A2B2
@Alternate Data Stream - 20 bytes -> C:\Users\Anderson Backup\Desktop\PAVARK.exe:License
@Alternate Data Stream - 193 bytes -> C:\ProgramData\TEMP: DE406C3E
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP: 430C6D84
< End of report >
< End of report >
------------