Just saved it in c and started it in safe mode..only click in the first 1, it was supposed to click on the 2 or thats ok..?..i saw that rapid balck window..rebbot in normal mode and did the deckard scan..hers the logs..
Deckard's System Scanner v20071014.68
Run by Jo on 2008-01-31 12:34:25
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
18: 2008-01-30 23:38:15 UTC - RP108 - Ponto de Verificação Agendado
17: 2008-01-28 15:52:46 UTC - RP107 - Installed Kaspersky Anti-Virus 7.0.
16: 2008-01-27 03:53:53 UTC - RP106 - Installed FaceGen Modeller
15: 2008-01-27 03:53:06 UTC - RP104 - Removed FaceGen Modeller
14: 2008-01-27 03:50:22 UTC - RP102 - Configured AVG 7.5
-- First Restore Point --
1: 2008-01-17 15:05:56 UTC - RP87 - Ponto de Verificação Agendado
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-01-31 12:36:34
Platform: Windows Vista (6.00.6000)
MSIE: Internet Explorer (7.00.6000.16386)
Boot mode: Normal
Running processes:
C:\Windows\System32\dwm.exe
C:\Windows\System32\taskeng.exe
C:\Windows\explorer.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxsrvc.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Windows\vsnpstd.exe
C:\Program Files\My Lockbox\flockbox.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\System32\SearchFilterHost.exe
C:\Users\Jo\Desktop\dss.exe
C:\Windows\System32\conime.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.pt/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [snpstd] C:\Windows\vsnpstd.exe
O4 - HKLM\..\Run: [flockbox] C:\Program Files\My Lockbox\flockbox.exe /a
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O10 - Unknown file in Winsock LSP: C:\Windows\System32\wpclsp.dll
O10 - Unknown file in Winsock LSP: C:\Windows\System32\wpclsp.dll
O10 - Unknown file in Winsock LSP: C:\Windows\System32\wpclsp.dll
O15 - Trusted Zone:
http://good-times.webshots.com (HKCU)
O16 - DPF: ServerPushBox () -
http://www.turismodo...ort/servp14.cabO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://download.micr...heckControl.cabO16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) -
http://www.myheritag...EngineQuery.dllO16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx...owserPlugin.cabO16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () -
http://fpdownload.ma...t/ultrashim.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\system32\avgwlntf.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgrssvc.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 8739 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 srosa (Megadrv3) - \??\c:\windows\system32\drivers\srosa.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R3 NMIndexingService - "c:\program files\common files\ahead\lib\nmindexingservice.exe" <Not Verified; Nero AG; Nero Home>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2007-12-31 and 2008-01-31 -----------------------------
2008-01-31 12:33:56 686630 --a------ C:\dss.exe
2008-01-31 12:19:40 1063 --a------ C:\Save2.bat
2008-01-31 12:19:40 51 --a------ C:\Save1.bat
2008-01-30 14:55:02 0 d-------- C:\Combo-Fix
2008-01-29 15:38:54 53248 --a------ C:\Windows\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-01-28 17:54:59 0 d-------- C:\Windows\system32\Kaspersky Lab
2008-01-28 15:54:12 91492 --a------ C:\Windows\system32\drivers\klin.dat
2008-01-28 15:54:12 85860 --a------ C:\Windows\system32\drivers\klick.dat
2008-01-28 15:53:22 41240608 --ahs---- C:\Windows\system32\drivers\fidbox.dat
2008-01-28 15:53:22 0 d-------- C:\Users\All Users\Kaspersky Lab
2008-01-28 15:53:22 0 d-------- C:\Program Files\Kaspersky Lab
2008-01-28 15:52:16 0 d-------- C:\Users\All Users\Kaspersky Lab Setup Files
2008-01-28 15:49:59 0 d-------- C:\Program Files\Eusing Free Registry Cleaner
2008-01-27 04:07:19 0 d-------- C:\Program Files\MediaCoder Audio Edition
2008-01-27 03:55:43 52224 --a------ C:\Windows\system32\Crypserv.exe <Not Verified; Kenonic Controls Ltd.; CrypKey Software Licensing System>
2008-01-27 03:55:43 24608 --a------ C:\Windows\system32\Ckldrv.sys
2008-01-27 03:55:43 27648 -ra------ C:\Windows\Setup_ck.exe
2008-01-27 03:55:43 18432 --a------ C:\Windows\Setup_ck.dll
2008-01-27 03:55:43 11776 --a------ C:\Windows\Ckrfresh.exe
2008-01-27 03:55:43 165888 --a------ C:\Windows\Ckconfig.exe <Not Verified; Kenonic Controls; CKCONFIG Application>
2008-01-27 03:47:35 0 d-------- C:\Program Files\Easy RM to MP3 Converter
2008-01-27 03:08:44 71172 --a------ C:\Windows\system32\mdelk.exe
2008-01-27 02:31:54 164352 --a------ C:\Windows\system32\unrar.dll
2008-01-27 02:31:53 217088 --a------ C:\Windows\system32\yv12vfw.dll <Not Verified; www.helixcommunity.org; Helix YV12 YUV Codec>
2008-01-27 02:31:53 1559040 --a------ C:\Windows\system32\xvidcore.dll
2008-01-27 02:31:52 282624 --a------ C:\Windows\system32\xvidvfw.dll
2008-01-27 02:31:52 682496 --a------ C:\Windows\system32\divx.dll <Not Verified; DivX, Inc.; DivX®>
2008-01-27 02:31:51 7680 --a------ C:\Windows\system32\ff_vfw.dll
2008-01-27 02:31:51 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-01-27 01:18:24 0 d-------- C:\Program Files\RM to MP3 Converter
2008-01-26 14:09:37 0 d--h----- C:\Windows\msdownld.tmp
2008-01-26 14:09:34 0 d-------- C:\Windows\system32\directx
2008-01-26 12:02:40 0 d-------- C:\Program Files\Free RM to MP3 Converter
2008-01-26 12:01:14 0 d-------- C:\Program Files\Real Alternative
2008-01-26 12:01:09 0 d-------- C:\Program Files\Magic RM to MP3 Converter
2008-01-04 15:21:21 0 d-------- C:\Program Files\Alwil Software
2008-01-04 14:36:54 0 dr------- C:\Users\Jani\Searches
2008-01-04 14:36:44 0 dr------- C:\Users\Jani\Contacts
2008-01-04 14:36:37 0 dr------- C:\Users\Jani\Videos
2008-01-04 14:36:37 0 d--hs---- C:\Users\Jani\SendTo
2008-01-04 14:36:37 0 dr------- C:\Users\Jani\Saved Games
2008-01-04 14:36:37 0 d--hs---- C:\Users\Jani\Recent
2008-01-04 14:36:37 0 d--hs---- C:\Users\Jani\PrintHood
2008-01-04 14:36:37 0 dr------- C:\Users\Jani\Pictures
2008-01-04 14:36:37 0 d--hs---- C:\Users\Jani\Os meus documentos
2008-01-04 14:36:37 0 d--hs---- C:\Users\Jani\NetHood
2008-01-04 14:36:37 0 dr------- C:\Users\Jani\Music
2008-01-04 14:36:37 0 d--hs---- C:\Users\Jani\Modelos
2008-01-04 14:36:37 0 d--hs---- C:\Users\Jani\Menu Iniciar
2008-01-04 14:36:37 0 dr------- C:\Users\Jani\Links
2008-01-04 14:36:37 0 dr------- C:\Users\Jani\Favorites
2008-01-04 14:36:37 0 dr------- C:\Users\Jani\Downloads
2008-01-04 14:36:37 0 dr------- C:\Users\Jani\Documents
2008-01-04 14:36:37 0 dr------- C:\Users\Jani\Desktop
2008-01-04 14:36:37 0 d--hs---- C:\Users\Jani\Definições locais
2008-01-04 14:36:37 0 d--hs---- C:\Users\Jani\Cookies
2008-01-04 14:36:37 0 d--hs---- C:\Users\Jani\Application Data
2008-01-04 14:36:37 0 d--h----- C:\Users\Jani\AppData
2008-01-04 14:36:36 1310720 --ahs---- C:\Users\Jani\NTUSER.DAT
2008-01-04 11:15:39 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-01-02 08:08:43 0 d-------- C:\Program Files\WinMX
2007-12-31 06:37:25 0 d-------- C:\Users\All Users\TEMP
2007-12-31 06:37:15 45056 --a------ C:\Windows\system32\Wnaspi32.dll <Not Verified; Adaptec; Adaptec's ASPI Layer>
2007-12-31 06:37:15 16877 --a------ C:\Windows\system32\drivers\Aspi32.sys <Not Verified; Adaptec; Adaptec's ASPI Layer>
2007-12-31 06:37:15 3535 --a------ C:\Windows\system\Wowpost.exe
2007-12-31 06:37:15 4455 --a------ C:\Windows\system\Winaspi.dll
2007-12-31 06:37:10 0 d-------- C:\Program Files\AoA DVD Ripper
2007-12-31 05:27:01 227840 --a------ C:\Windows\system32\Deco_32.dll <Not Verified; Iterated Systems, Inc.; Fractal Image Decoder>
2007-12-31 05:27:00 0 d-------- C:\Program Files\onOne Software
2007-12-31 01:39:01 0 d-------- C:\Program Files\XviD
2007-12-31 01:38:44 120320 --a------ C:\Windows\system32\apexchanger.exe
2007-12-31 01:38:44 109568 --a------ C:\Windows\system32\apex3gp.exe
2007-12-31 01:38:43 312320 --a------ C:\Windows\system32\NCTVideoView.dll <Not Verified; Online Media Technologies Ltd.; NCTVideoView ActiveX DLL>
2007-12-31 01:38:43 188416 --a------ C:\Windows\system32\NCTVideoFile.dll <Not Verified; NCT Company Ltd.; NCTVideoFile ActiveX DLL>
2007-12-31 01:38:43 495104 --a------ C:\Windows\system32\NCTVideoCoreM.dll <Not Verified; NCT Company Ltd.; NCTVideoCoreM ActiveX DLL>
2007-12-31 01:38:43 780288 --a------ C:\Windows\system32\NCTVideoCompress.dll <Not Verified; NCT Company Ltd.; NCTVideoCompress ActiveX DLL>
2007-12-31 01:38:43 764416 --a------ C:\Windows\system32\NCTRMFile.dll <Not Verified; NCT Company Ltd.; NCTRMFile ActiveX DLL>
2007-12-31 01:38:43 249856 --a------ C:\Windows\system32\NCTQuickTimeFile.dll <Not Verified; Online Media Technologies Company Ltd.; NCTQuickTimeFile Module>
2007-12-31 01:38:43 626688 --a------ C:\Windows\system32\NCTImageFile.dll <Not Verified; Online Media Technologies Ltd.; NCTImageFile ActiveX DLL>
2007-12-31 01:38:43 382464 --a------ C:\Windows\system32\NCTAVIFile.dll <Not Verified; NCT Company Ltd.; NCTAVIFile ActiveX DLL>
2007-12-31 01:38:43 90112 --a------ C:\Windows\system32\NCTAudioFormatSettings3.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioFormatSettings3 Module>
2007-12-31 01:38:43 2846720 --a------ C:\Windows\system32\NCTAudioCompress3.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCompress3 Module>
2007-12-31 01:38:43 61440 --a------ C:\Windows\system32\cygz.dll
2007-12-31 01:38:43 1295582 --a------ C:\Windows\system32\cygwin1.dll <Not Verified; Red Hat; Cygwin>
2007-12-31 01:38:43 3138048 --a------ C:\Windows\system32\apexxbox.exe
2007-12-31 01:38:43 398798 --a------ C:\Windows\system32\apexpmp.exe <Not Verified; IndigoSTAR Software; IndigoPerl>
2007-12-31 01:38:43 4755968 --a------ C:\Windows\system32\apexconverter.exe
2007-12-31 01:38:43 86016 --a------ C:\Windows\system32\AddiTunes.exe
2007-12-31 01:38:42 215552 --a------ C:\Windows\system32\NCTWMVFile.dll <Not Verified; NCT Company Ltd.; NCTWMVFile ActiveX DLL>
2007-12-31 01:38:42 778240 --a------ C:\Windows\system32\NCTAudioCompress2.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCompress2 Module>
2007-12-31 01:38:42 237568 --a------ C:\Windows\system32\lame_enc.dll
2007-12-31 01:38:41 81920 --a------ C:\Windows\system32\viscomwave.dll <Not Verified; Viscom Software; >
2007-12-31 01:38:41 147456 --a------ C:\Windows\system32\viscomqtenc.dll <Not Verified; Viscom Software www.viscomsoft.com; >
2007-12-31 01:38:41 139264 --a------ C:\Windows\system32\viscomqtde.dll <Not Verified; Viscom Software www.viscomsoft.com; >
2007-12-31 01:38:41 0 d-------- C:\Windows\system32\RMBin
2007-12-31 01:38:40 0 d-------- C:\Program Files\Apex
2007-12-31 01:38:40 0 d-------- C:\Apex
-- Find3M Report ---------------------------------------------------------------
2008-01-29 14:08:42 0 d-------- C:\Users\Jo\AppData\Roaming\Adobe
2008-01-28 18:26:15 0 d-------- C:\Program Files\Common Files\Adobe
2008-01-27 03:56:32 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-27 03:53:59 114688 --a------ C:\Windows\system32\wmatimer.dll
2008-01-27 03:47:47 0 d-------- C:\Users\Jo\AppData\Roaming\Real
2008-01-27 03:47:00 0 d-------- C:\Program Files\Singular Inversions
2008-01-27 03:46:20 0 d-------- C:\Program Files\Common Files\InstallShield
2008-01-27 02:45:57 0 d-------- C:\Program Files\Winamp
2008-01-27 02:39:53 0 d-------- C:\Program Files\WM Recorder 10
2008-01-27 02:30:18 0 d-------- C:\Program Files\DivX
2008-01-26 08:58:24 0 d-------- C:\Program Files\WMR11
2008-01-26 08:00:04 0 d-------- C:\Users\Jo\AppData\Roaming\AVG7
2008-01-23 02:29:11 520986 --a------ C:\Windows\system32\prfh0816.dat
2008-01-23 02:29:11 86310 --a------ C:\Windows\system32\prfc0816.dat
2008-01-16 18:07:51 0 d-------- C:\Users\Jo\AppData\Roaming\LimeWire
2008-01-10 03:20:36 0 d-------- C:\Program Files\Windows Mail
2008-01-10 03:20:35 0 d-------- C:\Program Files\Windows Sidebar
2008-01-05 05:09:03 0 d-------- C:\Users\Jo\AppData\Roaming\Google
2008-01-04 10:46:34 0 d-------- C:\Users\Jo\AppData\Roaming\PeerNetworking
2008-01-02 06:41:34 0 d-------- C:\Program Files\WinPcap
2007-12-30 05:41:34 0 d-------- C:\Users\Jo\AppData\Roaming\BitTorrent
2007-12-30 05:41:30 0 d-------- C:\Users\Jo\AppData\Roaming\uTorrent
2007-12-30 03:28:08 0 d-------- C:\Program Files\AV Vcs 4.0 DIAMOND
2007-12-29 22:48:51 0 d-------- C:\Program Files\BitComet
2007-12-29 05:12:29 0 d-------- C:\Program Files\WinAVIVideoConverter
2007-12-29 04:41:14 0 d-------- C:\Users\Jo\AppData\Roaming\GeoVid
2007-12-29 03:44:21 0 d-------- C:\Users\Jo\AppData\Roaming\DivX
2007-12-29 03:42:46 0 d-------- C:\Program Files\NeXus RV10 & MKV Filtres
2007-12-29 03:34:40 0 d-------- C:\Users\Jo\AppData\Roaming\Ahead
2007-12-26 07:51:59 0 d-------- C:\Users\Jo\AppData\Roaming\Media Player Classic
2007-12-26 07:51:09 0 d-------- C:\Users\Jo\AppData\Roaming\vlc
2007-12-26 05:16:50 0 d-------- C:\Users\Jo\AppData\Roaming\WinRAR
2007-12-26 04:23:56 0 d-------- C:\Users\Jo\AppData\Roaming\Winamp
2007-12-26 00:55:46 0 d-------- C:\Users\Jo\AppData\Roaming\Macromedia
2007-12-25 03:28:28 737280 --a------ C:\Windows\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2007-12-25 02:46:11 0 d-------- C:\Program Files\Google
2007-12-23 06:26:10 0 d-------- C:\Program Files\Common Files\PX Storage Engine
2007-12-23 06:26:06 0 d-------- C:\Program Files\Common Files
2007-12-23 04:08:05 0 d-------- C:\Program Files\eMule
2007-12-23 02:37:28 0 d-------- C:\Program Files\LimeWire
2007-12-23 02:37:20 0 d-------- C:\Program Files\Java
2007-12-23 02:36:16 0 d-------- C:\Program Files\Common Files\Java
2007-12-23 01:49:56 0 d-------- C:\Program Files\My Lockbox
2007-12-23 00:24:04 0 d-------- C:\Program Files\WinDirStat
2007-12-22 22:43:16 0 d-------- C:\Program Files\PC Wizard 2008
2007-12-15 23:37:51 0 d-------- C:\Program Files\Common Files\DVDVideoSoft
2007-12-15 01:36:59 0 d-------- C:\Program Files\Kjofol
2007-12-12 04:03:25 0 d-------- C:\Program Files\VideoLAN
2007-12-11 22:33:14 196608 --a------ C:\Windows\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2007-12-10 04:11:36 0 d-------- C:\Program Files\GeoVid
2007-12-03 02:37:05 0 d-------- C:\Program Files\Riva
2007-12-03 02:13:53 0 d-------- C:\Program Files\BitTorrent
2007-12-02 03:40:58 0 d-------- C:\Program Files\uTorrent
2007-12-01 05:29:05 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-12-01 04:21:51 0 d-------- C:\Program Files\ActivationManager
2007-12-01 04:21:50 0 d-------- C:\Program Files\ADSTechnology
2007-11-29 23:30:28 3596288 --a------ C:\Windows\system32\qt-dx331.dll
2007-11-29 23:28:24 81920 --a------ C:\Windows\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2007-11-24 01:47:13 413184 --a------ C:\Windows\system32\paintball.scr
2007-11-24 01:47:13 35 --a------ C:\Windows\brassi.dat
2007-11-21 20:07:40 174 --ahs---- C:\Program Files\desktop.ini
2007-11-16 17:43:23 268435456 --ahs---- C:\WinPEpge.sys
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-11-21 20:01]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-05-04 06:10]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-05-04 06:10]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-05-04 06:10]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2004-10-14 08:08]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 07:51 C:\Windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-04-13 07:36 C:\Windows\SkyTel.exe]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-31 12:33]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-24 18:15]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"snpstd"="C:\Windows\vsnpstd.exe" [2005-10-11 20:54]
"flockbox"="C:\Program Files\My Lockbox\flockbox.exe" [2007-04-17 23:52]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-12-20 15:16]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-01-31 12:33]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-01-31 12:33]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 03:01]
"WindowsWelcomeCenter"="oobefldr.dll,ShowWelcomeCenter" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 18:05]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 12:34]
C:\Users\Jo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableLUA"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"=2 (0x2)
"DontDisplayLogonHoursWarnings"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-11-21 20:19 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc wlansvc EMDMgmt TabletInputService WPDBusEnum
LocalServiceNoNetwork PLA DPS BFE mpssvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-01-31 12:37:50 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft® Windows Vista™ Home Basic (build 6000)
Architecture: X86; Language: Portuguese
CPU 0: Intel® Core2 Quad CPU Q6600 @ 2.40GHz
Percentage of Memory in Use: 34%
Physical Memory (total/avail): 2037.63 MiB / 1329.54 MiB
Pagefile Memory (total/avail): 4293.72 MiB / 3467.57 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1924.55 MiB
C: is Fixed (NTFS) - 465.76 GiB total, 299.41 GiB free.
D: is CDROM (No Media)
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is Removable (No Media)
\\.\PHYSICALDRIVE0 - WDC WD5000AAKS-00YGA0 ATA Device - 465.76 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 465.76 GiB - C:
\\.\PHYSICALDRIVE1 - Generic USB CF Reader USB Device
\\.\PHYSICALDRIVE3 - Generic USB MS Reader USB Device
\\.\PHYSICALDRIVE2 - Generic USB SD Reader USB Device
\\.\PHYSICALDRIVE4 - Generic USB SM Reader USB Device
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
AV: AVG 7.5.516 v7.5.516 (Grisoft)
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation)
Disabled[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Jo\AppData\Roaming
CLASSPATH=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=JO-PC
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Jo
LOCALAPPDATA=C:\Users\Jo\AppData\Local
LOGONSERVER=\\JO-PC
NUMBER_OF_PROCESSORS=4
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Adobe\AGL
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 11, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0b
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
QTJAVA=C:\Program Files\QuickTime\QTSystem\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Jo\AppData\Local\Temp
TMP=C:\Users\Jo\AppData\Local\Temp
USERDOMAIN=Jo-PC
USERNAME=Jo
USERPROFILE=C:\Users\Jo
windir=C:\Windows
-- User Profiles ---------------------------------------------------------------
Jo
(admin)Jani
Convidado.Jo-PC.000
(guest)-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
--> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\Windows\UNNeroMediaHome.exe /UNINSTALL
--> C:\Windows\UNNeroShowTime.exe /UNINSTALL
--> C:\Windows\UNNeroVision.exe /UNINSTALL
--> C:\Windows\UNRecode.exe /UNINSTALL
2007 Microsoft Office system --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROHYBRIDR /dll OSETUP.DLL
Adobe Bridge 1.0 --> MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}
Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player 9 ActiveX --> C:\Windows\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
Adobe Help Center 1.0 --> MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Reader 8.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}
Adobe Stock Photos 1.0 --> MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
AoA DVD Ripper --> "C:\Program Files\AoA DVD Ripper\unins000.exe"
Apex Video Converter Super 6.12 --> "C:\Program Files\Apex\Apex Video Converter Super\unins000.exe"
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Arquivo do WinRAR --> C:\Program Files\WinRAR\uninstall.exe
µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Audacity 1.2.6 --> "C:\Program Files\Audacity\unins000.exe"
AV Voice Changer Software DIAMOND 4.0 --> C:\PROGRA~1\AVVCS4~1.0DI\UNWISE.EXE C:\PROGRA~1\AVVCS4~1.0DI\INSTALL.LOG
avast! Antivirus --> rundll32 C:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll,RunSetup
AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
BitTorrent 6.0 --> C:\Program Files\BitTorrent\uninst.exe
DivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Easy RM to MP3 Converter 1.59.20 --> "C:\Program Files\Easy RM to MP3 Converter\unins000.exe"
eMule --> "C:\Program Files\eMule\Uninstall.exe"
Eusing Free Registry Cleaner --> C:\PROGRA~1\EUSING~1\UNWISE.EXE C:\PROGRA~1\EUSING~1\INSTALL.LOG
FaceGen Modeller --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{5455CB33-E3FF-4E71-9FAD-0D5DCA2686B7}
Free RM to MP3 Converter 1.12 --> "C:\Program Files\Free RM to MP3 Converter\unins000.exe"
Free Video to Mp3 Converter version 2.8 --> "C:\Program Files\DVDVideoSoft\Free Video to Mp3 Converter\unins000.exe"
Genuine Fractals 5.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC38B36B-90F8-4C1F-8AC9-236B851B8871}\setup.exe" -l0x9 -uninst -removeonly
Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
Google SketchUp 6 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x9 -removeonly
Google SketchUp 6 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x9 -removeonly
Hearing Range Checker --> MsiExec.exe /I{00808BAC-1C52-4D9E-B6D4-93EC47A4D579}
Intel® Graphics Media Accelerator Driver --> C:\Windows\system32\igxpun.exe -uninstall
Java 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
K-Jöfol 2000 --> C:\PROGRA~1\Kjofol\UNWISE.EXE C:\PROGRA~1\Kjofol\INSTALL.LOG
K-Lite Mega Codec Pack 3.7.0 --> "C:\Program Files\K-Lite Codec Pack\unins000.exe"
Kaspersky Anti-Virus 7.0 --> MsiExec.exe /I{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
Kaspersky Anti-Virus 7.0 --> MsiExec.exe /I{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
Kaspersky Online Scanner --> C:\Windows\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
LimeWire 4.14.12 --> "C:\Program Files\LimeWire\uninstall.exe"
Magic RM RAM to MP3 Converter 3.5 --> "C:\Program Files\Magic RM to MP3 Converter\unins000.exe"
MediaCoder Audio Edition 0.6.1 --> C:\Program Files\MediaCoder Audio Edition\uninst.exe
Microsoft Office Access MUI (Portuguese (Portugal)) 2007 --> MsiExec.exe /X{90120000-0015-0816-0000-0000000FF1CE}
Microsoft Office Excel MUI (Portuguese (Portugal)) 2007 --> MsiExec.exe /X{90120000-0016-0816-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Portuguese (Portugal)) 2007 --> MsiExec.exe /X{90120000-001A-0816-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2007 --> MsiExec.exe /X{90120000-0018-0816-0000-0000000FF1CE}
Microsoft Office Professional Hybrid 2007 --> MsiExec.exe /X{91120000-0031-0000-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Portuguese (Portugal)) 2007 --> MsiExec.exe /X{90120000-001F-0816-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (Portuguese (Portugal)) 2007 --> MsiExec.exe /X{90120000-002C-0816-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Portuguese (Portugal)) 2007 --> MsiExec.exe /X{90120000-0019-0816-0000-0000000FF1CE}
Microsoft Office Shared MUI (Portuguese (Portugal)) 2007 --> MsiExec.exe /X{90120000-006E-0816-0000-0000000FF1CE}
Microsoft Office Word MUI (Portuguese (Portugal)) 2007 --> MsiExec.exe /X{90120000-001B-0816-0000-0000000FF1CE}
My Lockbox 1.1 for Windows 2000/XP --> "C:\Program Files\My Lockbox\unins000.exe"
Nero 7 Essentials --> MsiExec.exe /X{B28B351F-1232-46EA-85EF-B8EA91642070}
PC Wizard 2008.1.81 --> "C:\Program Files\PC Wizard 2008\unins000.exe"
QuickTime --> MsiExec.exe /I{5B09BD67-4C99-46A1-8161-B7208CE18121}
Real Alternative 1.60 Lite --> "C:\Program Files\Real Alternative\unins000.exe"
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x816 -removeonly
Riva FLV Player --> "C:\Program Files\Riva\Riva FLV Player\unins000.exe"
RM to MP3 Converter 1.48 --> "C:\Program Files\RM to MP3 Converter\unins000.exe"
Security Update for Excel 2007 (KB936509) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {A00724F5-82C4-4924-B707-0E5A84B52471}
Security Update for Office 2007 (KB934062) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {305D509B-F194-4638-9F0F-D9E4C05F9D33}
Security Update for Office 2007 (KB936514) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C7A78F7F-EF32-4477-BAD7-3439EA7571BF}
Security Update for Publisher 2007 (KB936646) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {A32E4BAF-6477-45FA-B8AB-E743FA8D63FF}
Security Update for the 2007 Microsoft Office System (KB936960) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {5E5BD655-7AA9-47F9-BB6D-A1D8CE29AC86}
Sweet Home 3D version 1.2 --> "C:\Program Files\Sweet Home 3D\unins000.exe"
Uninstall 1.0.0.0 --> "C:\Program Files\Common Files\DVDVideoSoft\unins000.exe"
Update for Office 2007 (KB932080) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {EDC9CA29-6BC1-471C-828C-7A36109005D7}
Update for Office 2007 (KB934391) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {B3091818-7C56-4C45-BE7D-CA23027A5EA5}
Update for Office 2007 (KB934393) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {92FBAD46-E7F6-49FA-89B5-C39FC5BFAD15}
Update for Outlook 2007 (KB937608) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {CBB2454D-193F-4523-8A31-FEB343B7C30E}
Update for Outlook 2007 Junk Email Filter (kb943597) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {A751F0DB-8476-4207-956E-20AEBBA4B1DA}
Update for Word 2007 (KB934173) --> msiexec /package {91120000-0031-0000-0000-0000000FF1CE} /uninstall {C6A89125-5473-45E3-B413-ED8186437475}
VideoAvatar --> "C:\Program Files\GeoVid\Video Avatar\unins000.exe"
VideoLAN VLC media player 0.8.6c --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Winamp --> "C:\Program Files\Winamp\UninstWA.exe"
WinAVIVideoConverter --> "C:\Program Files\WinAVIVideoConverter\unins000.exe"
WinDirStat 1.1.2 --> "C:\Program Files\WinDirStat\Uninstall.exe"
Windows Live installer --> MsiExec.exe /X{3A417047-2E30-4D05-8977-F706D40BFF39}
Windows Live Messenger --> MsiExec.exe /X{8EADB73B-026D-4978-A8F0-1EEF5E1ECEC7}
WinMX --> C:\Program Files\WinMX\uninstall.exe
WinPcap 3.1 beta3 --> "C:\Program Files\WinPcap\Uninstall.exe" "C:\Program Files\WinPcap\install.log"
WM Recorder + RM Recorder 10.1 --> C:\Windows\iun6002.exe "C:\Program Files\WM Recorder 10\irunin.ini"
WM Recorder 11.3 --> C:\Program Files\WMR11\Uninstal.exe
Xvid 1.1.3 final uninstall --> "C:\Program Files\Xvid\unins000.exe"
XviD MPEG-4 Codec --> "C:\Program Files\XviD\UninstXviD.exe"
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe
-- Application Event Log -------------------------------------------------------
Event Record #/Type5263 / Success
Event Submitted/Written: 01/31/2008 00:32:08 PM
Event ID/Source: 5617 / WinMgmt
Event Description:
Event Record #/Type5262 / Success
Event Submitted/Written: 01/31/2008 00:32:08 PM
Event ID/Source: 5615 / WinMgmt
Event Description:
Event Record #/Type5260 / Success
Event Submitted/Written: 01/31/2008 00:32:02 PM
Event ID/Source: 902 / Software Licensing Service
Event Description:
O serviço de Licenciamento de Software foi iniciado.
Event Record #/Type5248 / Success
Event Submitted/Written: 01/31/2008 00:24:22 PM
Event ID/Source: 5617 / WinMgmt
Event Description:
Event Record #/Type5247 / Success
Event Submitted/Written: 01/31/2008 00:24:21 PM
Event ID/Source: 5615 / WinMgmt
Event Description:
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type30390 / Error
Event Submitted/Written: 01/31/2008 00:32:09 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
Kaspersky Anti-Virus 7.0%%193
Event Record #/Type30389 / Error
Event Submitted/Written: 01/31/2008 00:32:09 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
AVG7 Resident Shield Service%%193
Event Record #/Type30353 / Error
Event Submitted/Written: 01/31/2008 00:31:59 PM
Event ID/Source: 6008 / EventLog
Event Description:
O anterior encerramento do sistema, 31-01-2008 às 12:29:08, foi inesperado.
Event Record #/Type30331 / Error
Event Submitted/Written: 01/31/2008 00:22:49 PM
Event ID/Source: 10005 / DCOM
Event Description:
1068netprofm{A47979D2-C419-11D9-A5B4-001185AD2B89}
Event Record #/Type30330 / Error
Event Submitted/Written: 01/31/2008 00:22:49 PM
Event ID/Source: 10005 / DCOM
Event Description:
1068netman{BA126AD1-2166-11D1-B1D0-00805FC1270E}
-- End of Deckard's System Scanner: finished at 2008-01-31 12:37:50 ------------