OTL logfile created on: 03/10/2012 09:59:50 - Run 1
OTL by OldTimer - Version 3.2.70.1 Folder = C:\Users\Benoit\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
5,99 Gb Total Physical Memory | 3,71 Gb Available Physical Memory | 61,94% Memory free
11,98 Gb Paging File | 9,45 Gb Available in Paging File | 78,87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 165,70 Gb Total Space | 104,44 Gb Free Space | 63,03% Space Free | Partition Type: NTFS
Drive D: | 299,96 Gb Total Space | 208,58 Gb Free Space | 69,54% Space Free | Partition Type: NTFS
Computer Name: BENOIT-PC | User Name: Benoit | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/10/03 09:58:46 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Benoit\Desktop\OTL.exe
PRC - [2012/09/28 13:17:44 | 001,398,680 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\BitTorrent\BitTorrent.exe
PRC - [2012/09/27 12:57:24 | 000,690,096 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_278_ActiveX.exe
PRC - [2012/08/13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/08/13 10:18:06 | 000,274,024 | ---- | M] ( ) -- C:\PROGRA~2\GbPlugin\GbpSv.exe
PRC - [2012/06/06 21:33:42 | 001,564,872 | ---- | M] (Ask) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe
PRC - [2012/03/28 19:11:06 | 004,103,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe InDesign CS6\InDesign.exe
PRC - [2012/03/09 16:26:58 | 001,073,312 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
PRC - [2010/10/25 15:13:42 | 000,821,144 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2010/04/10 09:03:46 | 000,077,824 | ---- | M] () -- C:\Windows\KMService.exe
PRC - [2010/01/11 15:20:48 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Arquivos de Programas\Dell\DellDock\DockLogin.exe
PRC - [2009/02/23 19:43:12 | 000,576,000 | ---- | M] (MagicISO, Inc.) -- C:\Program Files (x86)\MagicDisc\MagicDisc.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2007/01/01 19:54:04 | 003,735,552 | ---- | M] (Google) -- C:\Users\Benoit\googletalk.exe
PRC - [2003/04/18 19:06:26 | 000,008,192 | ---- | M] () -- C:\Windows\SysWOW64\srvany.exe
========== Modules (No Company Name) ========== MOD - [2012/03/28 19:10:18 | 000,067,216 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS6\ASLSupport.dll
MOD - [2012/03/28 12:18:34 | 000,070,776 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS6\unihan.dll
MOD - [2012/03/28 12:18:26 | 000,374,960 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS6\Plug-ins\Filters\Sangam Readers\Reader For PageMaker.smrd
MOD - [2012/03/28 12:18:24 | 000,050,352 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS6\ALDFS32CJK.dll
MOD - [2012/03/28 12:18:24 | 000,046,256 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS6\ALDVM32CJK.dll
MOD - [2012/03/28 12:18:22 | 000,123,056 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe InDesign CS6\PMFileReader.dll
MOD - [2012/03/09 16:26:54 | 000,100,352 | ---- | M] () -- C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\zlib1.dll
========== Services (SafeList) ========== SRV:
64bit: - [2009/08/14 10:15:42 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:
64bit: - [2009/06/23 01:35:04 | 000,033,280 | ---- | M] () [Auto | Running] -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
SRV - [2012/09/05 22:26:40 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/08/13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/08/13 10:18:06 | 000,274,024 | ---- | M] ( ) [Auto | Running] -- C:\PROGRA~2\GbPlugin\GbpSv.exe -- (GbpSv)
SRV - [2012/07/17 15:14:44 | 002,292,480 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/01/11 15:20:48 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Arquivos de Programas\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2010/01/09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Arquivos de Programas\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010/01/09 21:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de Programas\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64)
SRV - [2009/06/10 18:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2003/04/18 19:06:26 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\srvany.exe -- (KMService)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2012/09/27 11:52:57 | 000,231,376 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt)
DRV:
64bit: - [2012/03/01 03:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2011/11/03 03:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:
64bit: - [2011/03/11 03:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011/03/11 03:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2009/08/14 12:30:14 | 006,201,856 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:
64bit: - [2009/07/24 14:49:00 | 000,119,312 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:
64bit: - [2009/07/13 22:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/13 22:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/13 22:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2009/07/13 22:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/07/13 20:31:10 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:
64bit: - [2009/06/26 12:23:30 | 000,272,432 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:
64bit: - [2009/06/23 01:35:02 | 000,022,520 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcm42rly.sys -- (BCM42RLY)
DRV:
64bit: - [2009/06/23 01:34:58 | 002,768,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:
64bit: - [2009/06/10 17:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:
64bit: - [2009/06/10 17:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 17:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 17:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 17:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/02/24 18:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mcdbus.sys -- (mcdbus)
DRV - [2012/04/05 09:34:02 | 000,046,408 | ---- | M] (GAS Tecnologia) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\GbpKm.sys -- (GbpKm)
DRV - [2009/07/13 22:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/02/24 18:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\mcdbus.sys -- (mcdbus)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...ms}&FORM=IE8SRCIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com.brIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com.brIE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...ms}&FORM=IE8SRC IE - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com.brIE - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com.br/IE - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://br.msn.com/?ocid=iehpIE - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-BR
IE - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0B 5F 1C 1B AF 9C CD 01 [binary data]
IE - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...Box&FORM=IE8SRCIE - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.co...g}&sourceid=ie7IE - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..keyword.URL: "
http://websearch.ask...YYYYYYYYUS&&q="FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/09/27 15:38:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/10/02 09:20:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012/10/02 09:20:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Benoit\AppData\Roaming\mozilla\Extensions
[2012/10/02 09:20:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2012/09/05 22:27:05 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/05 22:26:22 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/05 22:26:22 | 000,002,253 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/09/28 11:51:18 | 000,001,266 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O2:
64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:
64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:
64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Arquivos de Programas\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Arquivos de Programas\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-564107981-2342902310-1423014071-1000..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:
64bit: - Extra context menu item: &Enviar para o OneNote - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8:
64bit: - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: &Enviar para o OneNote - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9:
64bit: - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:
64bit: - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:
64bit: - Extra Button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:
64bit: - Extra 'Tools' menuitem : &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:
64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\..Trusted Domains: bancobrasil.com.br ([www] * in Trusted sites)
O15 - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\..Trusted Domains: bancobrasil.com.br ([www14] * in Trusted sites)
O15 - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\..Trusted Domains: bancobrasil.com.br ([www2] * in Trusted sites)
O15 - HKU\S-1-5-21-564107981-2342902310-1423014071-1000\..Trusted Domains: bb.com.br ([www] * in Trusted sites)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.200.5 8.8.8.8 200.175.5.139
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{51EC3280-0725-4E80-B959-54BFE74FBB19}: DhcpNameServer = 192.168.5.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C3C0E3F4-ABFE-40AD-8C74-9401176BA23B}: DhcpNameServer = 172.16.200.5 8.8.8.8 200.175.5.139
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de Programas\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:
64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ GbPluginBb: DllName - (C:\Program Files (x86)\GbPlugin\gbieh.dll) - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399F83} - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{451aa90f-08a1-11e2-afdf-0026b9f17fee}\Shell - "" = AutoRun
O33 - MountPoints2\{451aa90f-08a1-11e2-afdf-0026b9f17fee}\Shell\AutoRun\command - "" = H:\SETUP.EXE
O33 - MountPoints2\{451aa90f-08a1-11e2-afdf-0026b9f17fee}\Shell\configure\command - "" = H:\SETUP.EXE
O33 - MountPoints2\{451aa90f-08a1-11e2-afdf-0026b9f17fee}\Shell\install\command - "" = H:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ========== [2012/10/03 09:58:44 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Benoit\Desktop\OTL.exe
[2012/10/02 13:12:04 | 000,000,000 | ---D | C] -- C:\Users\Benoit\Desktop\SAVITA BHABHI COMPLETE COLLECTION TILL DATE
[2012/10/02 13:04:46 | 000,000,000 | ---D | C] -- C:\Users\Benoit\Desktop\Nikon D7000 Guide to Digital SLR Photography
[2012/10/02 09:20:32 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Mozilla
[2012/10/02 09:20:32 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\Mozilla
[2012/10/02 09:20:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2012/10/02 09:20:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012/10/02 09:20:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/10/01 15:02:35 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webteh
[2012/10/01 08:29:10 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\BSplayer PRO
[2012/09/30 23:03:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/09/30 23:03:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012/09/30 23:03:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012/09/29 10:53:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ask.com
[2012/09/29 10:53:30 | 000,000,000 | ---D | C] -- C:\Users\Benoit\Documents\FFOutput
[2012/09/29 10:53:26 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\SysWow64\pncrt.dll
[2012/09/29 10:53:21 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
[2012/09/29 10:53:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FreeTime
[2012/09/29 09:04:51 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2012/09/29 09:04:51 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2012/09/29 08:07:47 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Adobe
[2012/09/29 08:07:46 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/09/28 17:30:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Webteh
[2012/09/28 13:17:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BitTorrent
[2012/09/28 13:16:29 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\BitTorrent
[2012/09/28 11:52:17 | 000,046,408 | ---- | C] (GAS Tecnologia) -- C:\Windows\SysWow64\drivers\GbpKm.sys
[2012/09/28 11:52:05 | 000,000,000 | ---D | C] -- C:\ProgramData\GbPlugin
[2012/09/28 11:52:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GbPlugin
[2012/09/28 11:49:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[2012/09/28 10:58:26 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\ATI
[2012/09/28 10:58:26 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\ATI
[2012/09/28 10:58:26 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012/09/28 10:58:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012/09/28 10:57:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2012/09/28 10:56:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2012/09/28 10:56:56 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2012/09/28 10:56:33 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2012/09/28 10:56:02 | 000,433,152 | ---- | C] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2012/09/28 10:56:02 | 000,202,752 | ---- | C] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2012/09/28 10:56:02 | 000,120,320 | ---- | C] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2012/09/28 10:56:02 | 000,012,288 | ---- | C] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2012/09/28 10:53:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cisco
[2012/09/28 10:52:38 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Wireless
[2012/09/28 10:51:56 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\InstallShield
[2012/09/28 10:51:06 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2012/09/28 10:50:56 | 000,395,048 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynCOM.dll
[2012/09/28 10:50:56 | 000,260,904 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynCtrl.dll
[2012/09/28 10:50:56 | 000,206,120 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynCtrl.dll
[2012/09/28 10:50:56 | 000,203,560 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynTPAPI.dll
[2012/09/28 10:50:56 | 000,169,256 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynCOM.dll
[2012/09/28 10:50:56 | 000,147,752 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\SynTPCo4.dll
[2012/09/28 10:50:56 | 000,107,816 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysWow64\SynTPCOM.dll
[2012/09/28 10:50:55 | 000,272,432 | ---- | C] (Synaptics Incorporated) -- C:\Windows\SysNative\drivers\SynTP.sys
[2012/09/28 10:50:55 | 000,000,000 | ---D | C] -- C:\dell
[2012/09/28 08:48:16 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\Google
[2012/09/27 15:48:00 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2012/09/27 15:38:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
[2012/09/27 15:30:25 | 000,000,000 | ---D | C] -- C:\Users\Benoit\Tracing
[2012/09/27 15:29:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2012/09/27 15:28:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
[2012/09/27 15:25:36 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\Windows Live
[2012/09/27 15:25:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live
[2012/09/27 15:22:52 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\PACE Anti-Piracy
[2012/09/27 15:22:52 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\PACE Anti-Piracy
[2012/09/27 15:22:52 | 000,000,000 | ---D | C] -- C:\ProgramData\PACE Anti-Piracy
[2012/09/27 15:22:47 | 000,000,000 | ---D | C] -- C:\Users\Benoit\Documents\Adobe
[2012/09/27 13:06:09 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/09/27 12:58:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
[2012/09/27 12:58:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DsNET Corp
[2012/09/27 12:58:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Ask
[2012/09/27 11:53:09 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\TrueCrypt
[2012/09/27 11:53:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TrueCrypt
[2012/09/27 11:52:57 | 000,231,376 | ---- | C] (TrueCrypt Foundation) -- C:\Windows\SysNative\drivers\truecrypt.sys
[2012/09/27 11:52:39 | 000,000,000 | ---D | C] -- C:\Program Files\TrueCrypt
[2012/09/27 11:48:25 | 000,000,000 | ---D | C] -- C:\ProgramData\RICOH
[2012/09/27 10:34:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2BrightSparks
[2012/09/27 10:34:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\2BrightSparks
[2012/09/27 10:08:50 | 000,000,000 | ---D | C] -- C:\Users\Benoit\Documents\Arquivos do Outlook
[2012/09/27 10:00:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012/09/27 10:00:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2012/09/27 10:00:04 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Dell
[2012/09/27 10:00:02 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2012/09/27 10:00:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2012/09/27 09:59:26 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\Stardock_Corporation
[2012/09/27 09:59:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\{8BBA44BE-D722-4F33-ADE1-4A3A86653355}
[2012/09/27 09:59:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
[2012/09/27 09:59:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Dell
[2012/09/27 09:59:19 | 000,000,000 | ---D | C] -- C:\Program Files\Dell
[2012/09/27 09:59:09 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\PackageAware
[2012/09/27 09:58:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
[2012/09/27 09:58:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2012/09/27 09:57:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2012/09/27 09:57:52 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\Microsoft Help
[2012/09/27 09:57:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/09/27 09:57:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2012/09/27 09:57:38 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2012/09/27 09:56:47 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicDisc
[2012/09/27 09:56:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicDisc
[2012/09/27 09:56:28 | 000,255,552 | ---- | C] (MagicISO, Inc.) -- C:\Windows\SysWow64\drivers\mcdbus.sys
[2012/09/27 09:56:28 | 000,255,552 | ---- | C] (MagicISO, Inc.) -- C:\Windows\SysNative\drivers\mcdbus.sys
[2012/09/27 09:56:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MagicDisc
[2012/09/27 09:31:38 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MagicISO
[2012/09/27 09:31:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagicISO
[2012/09/27 09:31:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MagicISO
[2012/09/27 09:30:34 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\WinRAR
[2012/09/27 09:29:47 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/09/27 09:29:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/09/27 09:29:44 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2012/09/27 08:58:05 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Skype
[2012/09/27 08:58:01 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2012/09/27 08:58:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/09/27 08:58:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012/09/27 08:57:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012/09/26 22:27:37 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2012/09/26 22:27:12 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\oem
[2012/09/26 22:26:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\XPSViewer
[2012/09/26 22:26:25 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\pt-BR
[2012/09/26 22:26:25 | 000,000,000 | ---D | C] -- C:\Windows\pt-BR
[2012/09/26 22:26:24 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\pt-BR
[2012/09/26 22:24:18 | 000,004,096 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\SysNative\drivers\pt-BR\pscr.sys.mui
[2012/09/26 22:24:01 | 000,011,264 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\pt-BR\BrSerIb.sys.mui
[2012/09/26 22:24:00 | 000,011,264 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\pt-BR\BrSerId.sys.mui
[2012/09/26 22:24:00 | 000,002,560 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysNative\drivers\pt-BR\BrParwdm.sys.mui
[2012/09/26 21:00:42 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2012/09/26 21:00:40 | 000,000,000 | ---D | C] -- C:\ProgramData\ALM
[2012/09/26 20:57:51 | 000,000,000 | ---D | C] -- C:\Users\Benoit\Adobe Flash Builder 4.6
[2012/09/26 20:54:31 | 000,056,208 | ---- | C] (Rovi Corporation) -- C:\Windows\SysNative\drivers\PxHlpa64.sys
[2012/09/26 20:54:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2012/09/26 20:54:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2012/09/26 20:54:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\My Company Name
[2012/09/26 20:51:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2012/09/26 20:51:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2012/09/26 20:50:18 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2012/09/26 20:49:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
[2012/09/26 20:49:50 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2012/09/26 20:49:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012/09/26 20:46:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2012/09/26 20:45:37 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Macromedia
[2012/09/26 20:45:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2012/09/26 20:45:26 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Adobe
[2012/09/26 20:45:13 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\Adobe
[2012/09/26 20:21:26 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\vmm32
[2012/09/26 20:21:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dell
[2012/09/26 20:20:48 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012/09/26 17:38:18 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012/09/26 17:37:26 | 000,000,000 | R--D | C] -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/09/26 17:37:26 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Searches
[2012/09/26 17:37:26 | 000,000,000 | R--D | C] -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/09/26 17:37:19 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Identities
[2012/09/26 17:37:17 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Contacts
[2012/09/26 17:37:16 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\VirtualStore
[2012/09/26 17:37:10 | 000,000,000 | --SD | C] -- C:\Users\Benoit\AppData\Roaming\Microsoft
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Videos
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Saved Games
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Pictures
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Music
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Links
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Favorites
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Downloads
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Documents
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\Desktop
[2012/09/26 17:37:10 | 000,000,000 | R--D | C] -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\AppData\Local\Temporary Internet Files
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\SendTo
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Recent
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Modelos
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Documents\Minhas músicas
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Documents\Minhas imagens
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Documents\Meus vídeos
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Meus documentos
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Menu Iniciar
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\AppData\Local\Histórico
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Dados de aplicativos
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\AppData\Local\Dados de aplicativos
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Cookies
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Configurações locais
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Ambiente de rede
[2012/09/26 17:37:10 | 000,000,000 | -HSD | C] -- C:\Users\Benoit\Ambiente de impressão
[2012/09/26 17:37:10 | 000,000,000 | -H-D | C] -- C:\Users\Benoit\AppData
[2012/09/26 17:37:10 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\Temp
[2012/09/26 17:37:10 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Local\Microsoft
[2012/09/26 17:37:10 | 000,000,000 | ---D | C] -- C:\Users\Benoit\AppData\Roaming\Media Center Programs
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\Program Files\Common Files\Sistema
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\ProgramData\Modelos
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Minhas músicas
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Minhas imagens
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\Meus vídeos
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\ProgramData\Menu Iniciar
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\ProgramData\Favoritos
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\ProgramData\Documentos
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\ProgramData\Dados de aplicativos
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\Arquivos de Programas
[2012/09/26 17:36:58 | 000,000,000 | -HSD | C] -- C:\Program Files\Arquivos Comuns
[2012/09/26 17:28:40 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2012/09/26 17:28:05 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2007/01/01 19:54:04 | 003,735,552 | ---- | C] (Google) -- C:\Users\Benoit\googletalk.exe
========== Files - Modified Within 30 Days ========== [2012/10/03 09:58:46 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Benoit\Desktop\OTL.exe
[2012/10/03 08:16:48 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/03 08:16:48 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/03 08:14:27 | 001,628,224 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/03 08:14:27 | 000,703,580 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat
[2012/10/03 08:14:27 | 000,652,148 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/10/03 08:14:27 | 000,146,366 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat
[2012/10/03 08:14:27 | 000,121,080 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/10/03 08:09:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/10/03 08:09:22 | 527,835,135 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/02 12:46:47 | 008,019,677 | ---- | M] () -- C:\Users\Benoit\Desktop\T3 V.pdf
[2012/10/02 08:49:12 | 005,659,248 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/10/01 15:02:35 | 000,001,143 | ---- | M] () -- C:\Users\Benoit\Desktop\BS.Player PRO.lnk
[2012/10/01 11:15:39 | 003,053,671 | ---- | M] () -- C:\Users\Benoit\Desktop\Cartilha PDCA - Estudo V2.pdf
[2012/09/29 08:22:19 | 001,596,136 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/09/29 07:51:24 | 003,014,493 | ---- | M] () -- C:\Users\Benoit\Desktop\John Lennon - Imagine Karaoke (With no vocals!).mp3
[2012/09/29 07:50:52 | 003,208,426 | ---- | M] () -- C:\Users\Benoit\Desktop\Imagine - john lennon karaoke.mp3
[2012/09/29 07:50:41 | 000,038,127 | ---- | M] () -- C:\Users\Benoit\Desktop\20120927173813746207u[1].jpg
[2012/09/28 17:30:06 | 013,508,082 | ---- | M] () -- C:\Users\Benoit\Desktop\BSPlayer Pro v2.57 + Key.rar
[2012/09/28 11:51:18 | 000,001,266 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/09/28 10:54:02 | 000,001,735 | ---- | M] () -- C:\Windows\SysNative\Uninst_EAPModules.bat
[2012/09/28 10:52:30 | 000,898,624 | ---- | M] () -- C:\Windows\SysNative\oem5.inf
[2012/09/28 10:51:10 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/09/28 08:48:16 | 000,079,625 | ---- | M] () -- C:\Users\Benoit\uninstall.exe
[2012/09/27 16:35:18 | 000,002,055 | ---- | M] () -- C:\Users\Public\Desktop\Lightroom 4 64-bits.lnk
[2012/09/27 14:39:56 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012/09/27 11:52:57 | 000,231,376 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\SysNative\drivers\truecrypt.sys
[2012/09/27 11:48:26 | 000,000,606 | ---- | M] () -- C:\Windows\SysNative\ricdb.ini
[2012/09/27 09:59:26 | 000,001,978 | ---- | M] () -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2012/09/27 09:56:47 | 000,000,989 | ---- | M] () -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
[2012/09/27 08:25:01 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2012/09/27 08:25:00 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2012/09/26 22:26:17 | 000,323,154 | ---- | M] () -- C:\Windows\SysNative\prfi0416.dat
[2012/09/26 22:26:17 | 000,038,536 | ---- | M] () -- C:\Windows\SysNative\prfd0416.dat
[2012/09/26 17:31:17 | 000,047,762 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2012/09/26 17:31:17 | 000,047,762 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2012/09/26 17:30:19 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
========== Files Created - No Company Name ========== [2012/10/01 16:45:28 | 008,019,677 | ---- | C] () -- C:\Users\Benoit\Desktop\T3 V.pdf
[2012/10/01 15:02:35 | 000,001,143 | ---- | C] () -- C:\Users\Benoit\Desktop\BS.Player PRO.lnk
[2012/10/01 11:07:45 | 003,053,671 | ---- | C] () -- C:\Users\Benoit\Desktop\Cartilha PDCA - Estudo V2.pdf
[2012/09/28 17:30:17 | 010,736,296 | ---- | C] () -- C:\Users\Benoit\Desktop\bsplayer_pro257.1051.exe
[2012/09/28 17:29:26 | 013,508,082 | ---- | C] () -- C:\Users\Benoit\Desktop\BSPlayer Pro v2.57 + Key.rar
[2012/09/28 17:27:48 | 003,014,493 | ---- | C] () -- C:\Users\Benoit\Desktop\John Lennon - Imagine Karaoke (With no vocals!).mp3
[2012/09/28 17:22:36 | 003,208,426 | ---- | C] () -- C:\Users\Benoit\Desktop\Imagine - john lennon karaoke.mp3
[2012/09/28 10:56:02 | 000,332,288 | ---- | C] () -- C:\Windows\SysNative\ATIODE.exe
[2012/09/28 10:56:02 | 000,286,560 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2012/09/28 10:56:02 | 000,286,560 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2012/09/28 10:56:02 | 000,197,654 | ---- | C] () -- C:\Windows\SysNative\atiicdxx.dat
[2012/09/28 10:56:02 | 000,051,200 | ---- | C] () -- C:\Windows\SysNative\ATIODCLI.exe
[2012/09/28 10:56:02 | 000,018,632 | ---- | C] () -- C:\Windows\atiogl.xml
[2012/09/28 10:52:37 | 000,898,624 | ---- | C] () -- C:\Windows\SysNative\oem5.inf
[2012/09/28 10:52:07 | 000,006,656 | ---- | C] () -- C:\Windows\SysNative\bcmwlrc.dll
[2012/09/28 10:52:06 | 000,058,368 | ---- | C] () -- C:\Windows\SysNative\bcmwlrmt.dll
[2012/09/28 10:52:06 | 000,001,735 | ---- | C] () -- C:\Windows\SysNative\Uninst_EAPModules.bat
[2012/09/28 10:52:06 | 000,000,459 | ---- | C] () -- C:\Windows\SysWow64\vcredist_x64.bat
[2012/09/28 10:52:06 | 000,000,457 | ---- | C] () -- C:\Windows\SysNative\vcredist_x64.bat
[2012/09/28 10:51:10 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/09/28 08:53:14 | 000,038,127 | ---- | C] () -- C:\Users\Benoit\Desktop\20120927173813746207u[1].jpg
[2012/09/28 08:48:16 | 000,079,625 | ---- | C] () -- C:\Users\Benoit\uninstall.exe
[2012/09/27 16:35:18 | 000,002,063 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 4 64 bits.lnk
[2012/09/27 16:35:18 | 000,002,055 | ---- | C] () -- C:\Users\Public\Desktop\Lightroom 4 64-bits.lnk
[2012/09/27 15:38:31 | 000,002,465 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller X.lnk
[2012/09/27 15:38:31 | 000,002,453 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat X Pro.lnk
[2012/09/27 15:29:30 | 000,001,305 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
[2012/09/27 15:29:21 | 000,001,374 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
[2012/09/27 15:29:11 | 000,002,486 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2012/09/27 14:39:56 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012/09/27 12:49:50 | 001,596,136 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/09/27 11:56:08 | 000,077,824 | ---- | C] () -- C:\Windows\KMService.exe
[2012/09/27 11:56:08 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2012/09/27 11:48:26 | 000,000,606 | ---- | C] () -- C:\Windows\SysNative\ricdb.ini
[2012/09/27 09:59:26 | 000,001,978 | ---- | C] () -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2012/09/27 09:56:47 | 000,000,989 | ---- | C] () -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
[2012/09/27 08:25:01 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2012/09/27 08:25:00 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2012/09/26 22:27:12 | 000,000,024 | RH-- | C] () -- C:\Windows\DELL_version
[2012/09/26 22:26:44 | 000,703,580 | ---- | C] () -- C:\Windows\SysNative\prfh0416.dat
[2012/09/26 22:26:44 | 000,323,154 | ---- | C] () -- C:\Windows\SysNative\prfi0416.dat
[2012/09/26 22:26:44 | 000,146,366 | ---- | C] () -- C:\Windows\SysNative\prfc0416.dat
[2012/09/26 22:26:44 | 000,038,536 | ---- | C] () -- C:\Windows\SysNative\prfd0416.dat
[2012/09/26 20:54:58 | 000,001,097 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
[2012/09/26 20:51:53 | 000,000,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2012/09/26 17:37:27 | 000,001,513 | ---- | C] () -- C:\Users\Benoit\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/09/26 17:31:10 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012/09/26 17:31:04 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012/09/26 17:30:19 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/09/26 17:28:05 | 527,835,135 | -HS- | C] () -- C:\hiberfil.sys
[2007/01/01 20:00:20 | 000,069,632 | ---- | C] () -- C:\Users\Benoit\gtalkwmp1.dll
========== ZeroAccess Check ========== [2009/07/14 01:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 02:30:56 | 014,165,504 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 01:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 22:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/13 22:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 22:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ========== [2012/10/03 10:02:22 | 000,000,000 | ---D | M] -- C:\Users\Benoit\AppData\Roaming\BitTorrent
[2012/10/01 15:04:33 | 000,000,000 | ---D | M] -- C:\Users\Benoit\AppData\Roaming\BSplayer PRO
[2012/09/29 08:07:46 | 000,000,000 | ---D | M] -- C:\Users\Benoit\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/09/27 15:22:52 | 000,000,000 | ---D | M] -- C:\Users\Benoit\AppData\Roaming\PACE Anti-Piracy
[2012/09/27 13:06:09 | 000,000,000 | ---D | M] -- C:\Users\Benoit\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/09/27 11:54:46 | 000,000,000 | ---D | M] -- C:\Users\Benoit\AppData\Roaming\TrueCrypt
========== Purity Check ========== ========== Custom Scans ========== ========== Base Services ==========SRV:
64bit: - [2009/07/13 22:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:
64bit: - [2009/07/13 22:40:01 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:
64bit: - [2009/07/13 22:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:
64bit: - [2009/07/13 22:41:53 | 000,848,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:
64bit: - [2009/07/13 22:40:10 | 000,703,488 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:
64bit: - [2011/11/17 04:05:16 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
SRV:
64bit: - [2009/07/13 22:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2009/07/13 22:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:
64bit: - [2012/07/04 19:01:38 | 000,136,704 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:
64bit: - [2012/04/24 02:59:45 | 000,182,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV - [2012/04/24 01:47:04 | 000,139,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
SRV:
64bit: - [2009/07/13 22:41:53 | 000,509,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:
64bit: - [2009/07/13 22:40:28 | 000,314,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2009/07/13 22:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:
64bit: - [2011/03/03 03:17:10 | 000,182,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:
64bit: - [2009/07/13 22:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
SRV:
64bit: - [2009/07/13 22:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2009/07/13 22:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:
64bit: - [2009/07/13 22:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:
64bit: - [2009/07/13 22:41:10 | 000,500,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:
64bit: - [2009/07/13 22:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:
64bit: - [2009/07/13 22:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:
64bit: - [2009/07/13 22:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:
64bit: - [2009/07/13 22:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
SRV - [2009/07/13 22:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
SRV:
64bit: - [2009/07/13 22:41:52 | 000,302,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:
64bit: - [2009/07/13 22:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:
64bit: - [2011/05/24 08:21:59 | 000,404,992 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:
64bit: - [2012/02/11 03:29:02 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
SRV:
64bit: - [2011/11/17 04:05:16 | 000,031,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:
64bit: - [2009/07/13 22:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:
64bit: - [2009/07/13 22:41:53 | 000,343,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:
64bit: - [2009/07/13 22:41:53 | 000,509,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:
64bit: - [2009/07/13 22:41:53 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:
64bit: - [2011/11/17 04:05:16 | 000,031,232 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:
64bit: - [2010/12/21 03:16:27 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:
64bit: - [2010/08/27 03:14:02 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:
64bit: - [2009/07/13 22:41:54 | 000,369,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2009/07/13 22:16:14 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:
64bit: - [2010/11/02 02:16:53 | 001,114,624 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:
64bit: - [2009/07/13 22:41:55 | 000,316,416 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2009/07/13 22:16:15 | 000,241,664 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:
64bit: - [2009/07/13 22:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:
64bit: - [2012/05/02 02:32:43 | 000,208,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:
64bit: - [2009/07/13 22:39:50 | 001,598,976 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:
64bit: - [2009/07/13 22:40:04 | 000,676,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
SRV:
64bit: - [2009/07/13 22:40:04 | 000,676,864 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
SRV:
64bit: - [2009/07/13 22:41:53 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
No service found with a name of WinDefend
SRV:
64bit: - [2009/07/13 22:41:56 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
SRV:
64bit: - [2009/07/13 22:41:27 | 000,824,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:
64bit: - [2009/07/13 22:41:56 | 000,578,560 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:
64bit: - [2009/07/13 22:39:21 | 000,127,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV - [2009/07/13 22:14:25 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV:
64bit: - [2009/07/13 22:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:
64bit: - [2012/06/02 19:19:43 | 002,428,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:
64bit: - [2009/07/13 22:40:32 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:
64bit: - [2009/07/13 22:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
SRV:
64bit: - [2009/07/13 22:41:56 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)
< %SYSTEMDRIVE%\*.exe > < MD5 for: EXPLORER.EXE >[2011/02/26 03:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\explorer.exe
[2011/02/26 03:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 02:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 22:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 02:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 02:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 02:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\SysWOW64\explorer.exe
[2011/02/26 02:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 03:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 03:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 09:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 03:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 02:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 03:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 02:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 10:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 03:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 02:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 22:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 03:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 03:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 03:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
< MD5 for: QMGR.DLL >[2010/11/20 10:27:23 | 000,849,920 | ---- | M] (Microsoft Corporation) MD5=1EA7969E3271CBC59E1730697DC74682 -- C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.1.7601.17514_none_81b6ca5c101195cd\qmgr.dll
[2009/07/13 22:41:53 | 000,848,384 | ---- | M] (Microsoft Corporation) MD5=7F0C323FE3DA28AA4AA1BDA3F575707F -- C:\Windows\SysNative\qmgr.dll
[2009/07/13 22:41:53 | 000,848,384 | ---- | M] (Microsoft Corporation) MD5=7F0C323FE3DA28AA4AA1BDA3F575707F -- C:\Windows\winsxs\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.1.7600.16385_none_7f85b69413231233\qmgr.dll
< MD5 for: SERVICES >[2009/06/10 18:00:26 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.AIP >[2012/03/29 20:35:50 | 000,375,952 | ---- | M] (Adobe Systems Incorporated) MD5=5965DFD83E10938A579952EB58C10298 -- C:\Program Files (x86)\Adobe\Adobe Illustrator CS6\Plug-ins\Extensions\Services.aip
[2012/03/29 20:35:50 | 000,297,104 | ---- | M] (Adobe Systems Incorporated) MD5=8311BFD3FD21EB8089259C491406A7B0 -- C:\Program Files\Adobe\Adobe Illustrator CS6 (64 Bit)\Plug-ins\Extensions\Services.aip
< MD5 for: SERVICES.ASFX >[2010/10/25 15:15:46 | 000,000,230 | ---- | M] () MD5=2577B66F38E0DEA25F328DA4A0FED322 -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\fr_FR\Services\Services.asfx
[2010/10/25 15:15:46 | 000,000,231 | ---- | M] () MD5=9F2731666F5771CC5C1E4EEDC8FB8607 -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\Services\Services.asfx
< MD5 for: SERVICES.CFG >[2010/10/25 15:13:46 | 000,032,633 | ---- | M] () MD5=EA1C35DD541D60819D55482130BD585D -- C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Services\Services.cfg
< MD5 for: SERVICES.CFSERVICE.JAR >[2012/03/16 03:33:04 | 000,142,226 | ---- | M] () MD5=18D9FCB12CE658BA4D24D8DC2D641BA6 -- C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.services.CFService_4.6.1.335153\services.CFService.jar
< MD5 for: SERVICES.EXE >[2009/07/13 22:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009/07/13 22:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >[2009/07/13 23:50:42 | 000,018,432 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\Windows\SysNative\pt-BR\services.exe.mui
[2009/07/13 23:50:42 | 000,018,432 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_pt-br_c78e6f42ac5a3207\services.exe.mui
< MD5 for: SERVICES.LNK >[2009/07/14 01:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 01:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 01:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\Users\Todos os Usuários\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >[2009/06/10 17:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\SysNative\wbem\services.mof
[2009/06/10 17:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >[2009/06/10 17:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysNative\services.msc
[2009/06/10 18:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\services.msc
[2009/06/10 17:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/06/10 18:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
[2009/07/13 23:54:28 | 000,092,750 | ---- | M] () MD5=D2C49D7047664C51A9183D4A34C9008C -- C:\Windows\SysNative\pt-BR\services.msc
[2009/07/13 23:46:26 | 000,092,750 | ---- | M] () MD5=D2C49D7047664C51A9183D4A34C9008C -- C:\Windows\SysWOW64\pt-BR\services.msc
[2009/07/13 23:54:28 | 000,092,750 | ---- | M] () MD5=D2C49D7047664C51A9183D4A34C9008C -- C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_pt-br_01d03f2e82c3cbfa\services.msc
[2009/07/13 23:46:26 | 000,092,750 | ---- | M] () MD5=D2C49D7047664C51A9183D4A34C9008C -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_pt-br_a5b1a3aaca665ac4\services.msc
< MD5 for: SERVICES.PHPSERVICE.JAR >[2012/03/16 03:33:06 | 000,149,053 | ---- | M] () MD5=EDDA59974541208844A9FE430268D469 -- C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.services.PHPService_4.6.1.335153\services.PHPService.jar
< MD5 for: SERVICES.PTXML >[2009/07/13 17:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 17:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: SERVICES.SBS >[2011/03/01 04:58:46 | 000,034,818 | ---- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B -- C:\Program Files (x86)\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: SERVICES.STATICCONTENTSERVICE.JAR >[2012/03/16 03:33:06 | 000,072,917 | ---- | M] () MD5=15E17BFD2088059A73A22119D0D1613A -- C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.services.StaticContentService_4.6.1.335153\services.StaticContentService.jar
< MD5 for: SERVICES.WEBSERVICE.DERIVED.JAR >[2012/03/16 03:33:06 | 000,183,653 | ---- | M] () MD5=1BEE56EAF2A85F3662291392C8804E1E -- C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\eclipse\plugins\com.adobe.flexbuilder.services.WEBService.derived_4.6.1.335153\services.WEBService.derived.jar
< MD5 for: SVCHOST.EXE >[2009/07/13 22:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/13 22:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 22:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/13 22:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
< MD5 for: USERINIT.EXE >[2010/11/20 09:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 22:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\SysWOW64\userinit.exe
[2009/07/13 22:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 22:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\SysNative\userinit.exe
[2009/07/13 22:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 10:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
< MD5 for: WINLOGON.EXE >[2010/11/20 10:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 22:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 04:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 03:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\SysNative\winlogon.exe
[2009/10/28 03:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
========== Alternate Data Streams ========== @Alternate Data Stream - 208 bytes -> C:\Windows\SysWow64\drivers:GbpKmAp.lst
@Alternate Data Stream - 1193 bytes -> C:\Users\Benoit\AppData\Local\KKqp5xbrAw:6dS21V2rvlpXdJ5U
@Alternate Data Stream - 1166 bytes -> C:\Users\Benoit\AppData\Local\Temp:w7vIhAl4JhVi7WmIzJZSGTWh8
< End of report >