Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

MSE [Solved]


  • This topic is locked This topic is locked

#1
bgomes8

bgomes8

    New Member

  • Member
  • Pip
  • 7 posts
I recently was infected with some Malware that I removed with Malwarebyte's Antimalware program. However, I'm having problems now:

(1) MS Security Essentials will not open or run, and

(2) My Google searches in Firefox sometimes are redirected to strange sites.

More info:
1. I do not have any other Anti-virus software running that I know of that would be stopping MS Security Essentials from running(unless Malwarebyte's counts).

2. The google redirection doesn't always happen. Sometimes it goes to the thing I searched for, sometimes it doesn't.

Here is my OTL log:




created on: 24-10-2012 09:31:28 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bruno\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy

1014,43 Mb Total Physical Memory | 120,75 Mb Available Physical Memory | 11,90% Memory free
1,99 Gb Paging File | 0,73 Gb Available in Paging File | 36,60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 28,31 Gb Free Space | 37,99% Space Free | Partition Type: NTFS
Drive D: | 74,13 Gb Total Space | 69,42 Gb Free Space | 93,64% Space Free | Partition Type: NTFS

Computer Name: BRUNO-PEPE | User Name: Bruno | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012-10-24 01:11:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
PRC - [2012-09-12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Security Client\NisSrv.exe
PRC - [2012-09-12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Security Client\MsMpEng.exe
PRC - [2012-08-26 22:20:10 | 000,307,856 | ---- | M] (Google Inc.) -- C:\Programas\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2012-08-24 08:34:41 | 000,748,680 | ---- | M] (Microsoft Corporation) -- C:\Programas\Internet Explorer\iexplore.exe
PRC - [2012-08-20 18:37:58 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2012-06-11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) -- C:\Programas\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2012-03-08 18:50:28 | 004,280,184 | ---- | M] (Microsoft Corporation) -- C:\Programas\Windows Live\Messenger\msnmsgr.exe
PRC - [2011-08-05 12:29:56 | 000,159,456 | ---- | M] (Microsoft Corporation) -- C:\Programas\Zune\ZuneLauncher.exe
PRC - [2011-03-28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011-03-28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011-02-25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011-02-10 10:25:42 | 001,546,720 | ---- | M] (Toshiba Europe GmbH) -- C:\Programas\Toshiba TEMPRO\TemproTray.exe
PRC - [2011-02-10 10:25:36 | 000,112,080 | ---- | M] (Toshiba Europe GmbH) -- C:\Programas\Toshiba TEMPRO\TemproSvc.exe
PRC - [2010-11-20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programas\Windows Media Player\wmpnetwk.exe
PRC - [2010-11-20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009-09-03 16:06:32 | 000,304,496 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2009-08-27 14:37:10 | 000,185,712 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TECO\TecoService.exe
PRC - [2009-08-26 19:00:06 | 001,324,384 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TECO\TEco.exe
PRC - [2009-08-21 10:29:40 | 000,464,224 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2009-08-21 10:29:20 | 000,476,512 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\Power Saver\TPwrMain.exe
PRC - [2009-08-13 13:31:24 | 000,521,528 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\SmoothView\SmoothView.exe
PRC - [2009-08-12 11:30:42 | 006,203,296 | ---- | M] (TOSHIBA) -- C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe
PRC - [2009-08-10 20:55:46 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
PRC - [2009-08-07 05:47:46 | 000,354,640 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosHdpProc.exe
PRC - [2009-08-06 19:36:56 | 002,680,160 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2009-08-06 18:05:18 | 000,583,024 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TPHM\TPCHWMsg.exe
PRC - [2009-08-06 18:04:56 | 000,685,424 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TPHM\TPCHSrv.exe
PRC - [2009-08-06 15:02:02 | 000,029,528 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
PRC - [2009-08-06 13:06:58 | 000,466,792 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\BulletinBoard\TosNcCore.exe
PRC - [2009-08-05 15:04:54 | 000,738,616 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\FlashCards\TCrdMain.exe
PRC - [2009-08-03 18:16:50 | 001,021,272 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
PRC - [2009-08-03 18:16:32 | 000,111,960 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
PRC - [2009-07-30 06:20:04 | 000,144,752 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2009-07-28 21:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009-07-28 15:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2009-07-21 04:58:52 | 002,651,512 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtProc.exe
PRC - [2009-07-08 09:40:58 | 000,518,720 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\ThpSrv.exe
PRC - [2009-07-06 19:44:22 | 000,341,320 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosOBEX.exe
PRC - [2009-07-02 11:05:00 | 000,252,288 | ---- | M] (TOSHIBA) -- C:\Programas\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
PRC - [2009-06-07 23:34:58 | 000,660,808 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2009-06-03 00:33:14 | 000,308,552 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe
PRC - [2009-04-23 06:36:26 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Programas\BrOffice.org 3\program\soffice.bin
PRC - [2009-04-23 06:33:18 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Programas\BrOffice.org 3\program\soffice.exe
PRC - [2009-04-03 03:17:42 | 000,447,816 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosAVRC.exe
PRC - [2009-03-29 14:51:56 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programas\Apoint2K\hidfind.exe
PRC - [2009-03-10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2009-02-26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2009-01-13 21:33:40 | 000,034,088 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\Utilities\KeNotify.exe
PRC - [2008-07-23 20:24:24 | 000,083,272 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe


========== Modules (No Company Name) ==========

MOD - [2012-06-15 01:48:56 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll
MOD - [2012-06-15 00:52:13 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll
MOD - [2012-06-15 00:47:42 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012-06-15 00:47:03 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012-06-15 00:46:40 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
MOD - [2012-05-10 11:53:20 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012-05-10 11:45:44 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012-05-10 11:45:13 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012-05-10 11:44:33 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012-05-10 11:44:14 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012-05-10 11:43:03 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2009-08-26 18:55:06 | 000,520,192 | ---- | M] () -- C:\Programas\TOSHIBA\TECO\TecoPower.dll
MOD - [2009-08-06 13:08:04 | 002,878,824 | ---- | M] () -- C:\Programas\TOSHIBA\BulletinBoard\TosNcUi.dll
MOD - [2009-08-03 18:17:24 | 000,079,192 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll
MOD - [2009-07-16 16:27:48 | 000,052,536 | ---- | M] () -- C:\Programas\TOSHIBA\FlashCards\Hotkey\FnZ.dll
MOD - [2009-07-16 16:27:44 | 007,263,544 | ---- | M] () -- C:\Programas\TOSHIBA\FlashCards\BlackPng.dll
MOD - [2009-06-22 15:38:40 | 000,015,160 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA Assist\NotifyX.dll
MOD - [2009-04-16 13:02:16 | 000,970,752 | ---- | M] () -- C:\Programas\BrOffice.org 3\program\libxml2.dll
MOD - [2009-03-12 20:08:04 | 000,049,152 | ---- | M] () -- C:\Programas\TOSHIBA\PCDiag\NotifyPCD.dll
MOD - [2006-10-07 12:57:04 | 000,053,248 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll


========== Services (SafeList) ==========

SRV - [2012-10-09 01:48:49 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-09-12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programas\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012-09-12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programas\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012-06-11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Programas\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012-06-11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Programas\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2012-06-07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programas\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012-03-08 18:32:24 | 001,492,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2011-08-05 12:30:02 | 000,444,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV - [2011-08-05 12:30:02 | 000,268,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV - [2011-08-05 12:29:56 | 006,363,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2011-07-20 05:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2011-03-28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011-02-10 10:25:36 | 000,112,080 | ---- | M] (Toshiba Europe GmbH) [Auto | Running] -- C:\Programas\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService)
SRV - [2010-11-20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programas\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010-09-22 16:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programas\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2009-08-27 14:37:10 | 000,185,712 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programas\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV - [2009-08-21 10:29:40 | 000,464,224 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programas\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2009-08-17 11:48:42 | 000,051,512 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Programas\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2009-08-10 20:55:46 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Programas\TOSHIBA\ConfigFree\CFIWmxSvcs.exe -- (cfWiMAXService)
SRV - [2009-08-06 18:04:56 | 000,685,424 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programas\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV - [2009-08-03 18:16:32 | 000,111,960 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV - [2009-07-30 06:20:04 | 000,144,752 | ---- | M] (TOSHIBA CORPORATION) [On_Demand | Running] -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2009-07-28 15:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009-07-08 09:40:58 | 000,518,720 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\ThpSrv.exe -- (Thpsrv)
SRV - [2009-03-10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2007-05-31 16:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007-05-31 16:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006-10-26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RtsUCcid.sys -- (USBCCID)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Rts516xIR.sys -- (RtsUIR)
DRV - [2012-08-30 22:03:50 | 000,099,272 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012-08-23 15:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012-08-23 15:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010-11-20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2009-09-21 18:58:28 | 001,218,048 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009-08-05 15:44:44 | 000,049,400 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2009-08-05 13:55:08 | 000,061,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV - [2009-07-30 21:02:34 | 000,036,208 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LPCFilter.sys -- (LPCFilter)
DRV - [2009-07-30 17:45:56 | 000,022,912 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2009-07-30 17:45:22 | 000,171,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009-07-28 21:01:26 | 000,069,480 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2009-07-24 12:31:58 | 000,021,608 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2009-07-14 16:28:42 | 000,023,512 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2009-07-13 23:13:10 | 000,015,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfec.sys -- (tosrfec)
DRV - [2009-07-07 22:38:34 | 000,168,936 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2009-06-29 16:16:22 | 000,013,120 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\Thpevm.sys -- (Thpevm)
DRV - [2009-06-29 10:25:24 | 000,030,272 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\thpdrv.sys -- (Thpdrv)
DRV - [2009-06-22 18:04:58 | 000,024,064 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PGEffect.sys -- (PGEffect)
DRV - [2009-06-19 20:31:08 | 000,012,920 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\TVALZFL.sys -- (TVALZFL)
DRV - [2009-06-19 10:57:20 | 000,079,872 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2009-06-19 10:56:48 | 000,042,472 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV - [2009-06-17 12:59:46 | 000,046,984 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosporte.sys -- (tosporte)
DRV - [2008-03-17 12:05:30 | 000,101,632 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008-02-07 01:23:46 | 000,166,448 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-re...q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=TSEI&bmod=TSEI
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...=TSEI&bmod=TSEI
IE - HKCU\..\URLSearchHook: {55d7c7bc-12a7-4f9b-81c0-600d9a182395} - No CLSID value found
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshare.toolba...Terms}&srch=dsp
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask...35-B7415893853C
IE - HKCU\..\SearchScopes\{1E99E41B-E211-406F-9952-7AAF7186A3BF}: "URL" = http://www.amazon.co...ed&linkCode=ur2
IE - HKCU\..\SearchScopes\{5D3A5735-DE55-417D-A646-16EC0CFD46ED}: "URL" = http://rover.ebay.co...e={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...pt-PTPT367PT369
IE - HKCU\..\SearchScopes\{978E0DE2-0143-454F-B92F-9E322E469ED9}: "URL" = http://search.condui...&ctid=CT3202918
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-10-11 23:14:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-10-11 23:14:44 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://search.imesh.com
CHR - Extension: No name found = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\eibdjcmcmfggjoiaaoojhicjnkghbkbe\0.1.5_1\

O1 HOSTS File: ([2009-06-10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Programas\vShare\vshare_toolbar.dll ()
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programas\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Programas\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Programas\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Programas\vShare\vshare_toolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Programas\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KeNotify] C:\Programas\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RegTask] C:\Program Files\RegTask\RegTask.exe File not found
O4 - HKLM..\Run: [SmoothView] C:\Programas\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ThpSrv] C:\Windows\System32\thpsrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Programas\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [TosNC] C:\Programas\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosReelTimeMonitor] C:\Programas\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosSENotify] C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosWaitSrv] C:\Programas\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Programas\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TUSBSleepChargeSrv] C:\Programas\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe (TOSHIBA)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [fnosxy] C:\Users\Bruno\AppData\Roaming\wevtapie.dll ()
O4 - HKCU..\Run: [TOSHIBA Online Product Information] C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
O4 - Startup: C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BrOffice.org 3.1.lnk = C:\Programas\BrOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Iniciação Rápida do Microsoft Office OneNote 2007.lnk = C:\Programas\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Programas\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programas\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.appl...ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2....re/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{297ED7F6-3D73-40D0-A964-0D3237ED7731}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programas\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programas\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Programas\vShare\vshare_toolbar.dll ()
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programas\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programas\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{62c0314a-ca3b-11df-84ba-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{62c0314a-ca3b-11df-84ba-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a776-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a776-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a79c-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a79c-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a7a0-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a7a0-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{fe34b9e7-d69a-11df-b041-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{fe34b9e7-d69a-11df-b041-002622ed90d8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012-10-24 01:11:14 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
[2012-10-23 22:01:13 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{76BE6E11-2456-45B8-8DED-C33899F40C71}
[2012-10-23 12:24:26 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Malwarebytes
[2012-10-23 12:23:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012-10-23 11:35:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012-10-23 09:36:17 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{79C65D2B-5AD0-4B16-AEAA-86AE3FAAB826}
[2012-10-22 20:27:49 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012-10-22 16:12:39 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{8C6CE4A5-CBAF-4B7C-A4EF-8EFC69E5903B}
[2012-10-21 13:06:06 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{5F1E1D76-E752-4411-B68F-3A81FDD70144}
[2012-10-21 00:05:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{925473B4-0B1E-4048-B272-B43B02B10E3B}
[2012-10-19 09:48:28 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{F4F8D4F7-945F-4231-AE41-B04DF03C5B86}
[2012-10-18 10:01:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{37FB29E7-ED65-49D6-AACF-7034A761A9AF}
[2012-10-17 14:15:30 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{1F5A42B9-806E-416A-BFA6-92E2325378BD}
[2012-10-16 09:15:03 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{4049AC65-3DAA-4F45-AF27-39F0D7C4EEEA}
[2012-10-15 17:34:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{8E8AA3D5-98D7-44D5-BD09-613C101402DA}
[2012-10-15 02:01:51 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DEB5E6C1-786A-47E7-B63F-D329906F8614}
[2012-10-13 10:18:24 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E62A536C-E875-4D8F-B9D9-4A37B47EC8CD}
[2012-10-12 01:41:29 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{2FC75F44-9B73-45EC-8C00-275625907143}
[2012-10-11 09:16:15 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{D65F8A63-8746-40D7-B79B-84365454728E}
[2012-10-10 17:48:37 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{534BBD51-BD19-4BCC-B8A0-1ECBCF25D878}
[2012-10-10 01:58:45 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{D4CA5F12-06E0-48D1-AED1-BC9E344204F6}
[2012-10-09 13:46:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{CD92EAFA-511E-4197-9613-3F9577BA59C7}
[2012-10-08 12:03:17 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{1768C40A-80D5-4767-80C1-BD2BE8DAD01D}
[2012-10-07 09:21:39 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DF54BC6F-9574-419F-8F15-5803ACCC461D}
[2012-10-06 16:40:15 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{0260AB2B-D68F-4CE6-9096-115B497D4447}
[2012-10-05 22:02:48 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Desktop\Constructor
[2012-10-05 14:47:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DC823420-2871-4BB9-B7ED-D9FE2AFB2089}
[2012-10-04 16:56:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Desktop\PM2
[2012-10-04 09:28:52 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E600E9ED-3103-4FB8-BF5B-5710090CF3B8}
[2012-10-03 14:47:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{7AE07EA2-84BE-4D5D-9BEB-EFB255179173}
[2012-10-03 02:46:40 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{3955745F-E8FB-4DA6-A159-3709959E3FD8}
[2012-10-01 09:40:31 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{00BCB191-FA4C-4DC2-AD5A-312A7F71E234}
[2012-09-30 10:36:09 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{B9F8A37B-457D-4C4F-AECA-343997E4E8D2}
[2012-09-29 19:03:00 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{3E3AE1E8-F03E-4923-A93E-C5B579315C0B}
[2012-09-26 09:41:44 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E37BE0FB-75FB-4A93-918F-660116EF1BC7}
[2012-09-25 14:26:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{569FE158-6614-4FF2-8D64-5AEE934108D0}
[2012-09-24 11:55:07 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{D02C6AD0-3FE4-49BE-A110-2F049FB81D3F}
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012-10-24 09:21:12 | 000,001,000 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-10-24 09:18:03 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-10-24 09:09:51 | 000,014,304 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-10-24 09:09:51 | 000,014,304 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-10-24 09:00:30 | 000,000,996 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-10-24 09:00:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012-10-24 09:00:03 | 797,777,920 | -HS- | M] () -- C:\hiberfil.sys
[2012-10-24 01:11:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
[2012-10-23 11:36:21 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012-10-22 10:30:01 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\RegTask.job
[2012-10-14 01:51:52 | 000,082,250 | ---- | M] () -- C:\Users\Bruno\Desktop\Publicitação_Recrutamento_TS_RefªA_Erasmus_1.sflb.pdf
[2012-10-10 18:31:48 | 000,002,331 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012-10-04 16:36:25 | 003,092,694 | ---- | M] () -- C:\Users\Bruno\Desktop\pmanager2.rar
[2012-10-04 16:35:22 | 002,316,579 | ---- | M] () -- C:\Users\Bruno\Desktop\premierm3.rar
[2012-10-04 00:18:58 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012-10-03 13:49:42 | 000,118,784 | RHS- | M] () -- C:\Users\Bruno\AppData\Roaming\wevtapie.dll
[2012-10-02 09:47:18 | 000,679,342 | ---- | M] () -- C:\Windows\System32\prfh0816.dat
[2012-10-02 09:47:18 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012-10-02 09:47:18 | 000,133,752 | ---- | M] () -- C:\Windows\System32\prfc0816.dat
[2012-10-02 09:47:18 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-10-23 11:36:12 | 000,002,124 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012-10-14 01:51:49 | 000,082,250 | ---- | C] () -- C:\Users\Bruno\Desktop\Publicitação_Recrutamento_TS_RefªA_Erasmus_1.sflb.pdf
[2012-10-04 16:36:17 | 003,092,694 | ---- | C] () -- C:\Users\Bruno\Desktop\pmanager2.rar
[2012-10-04 16:35:20 | 002,316,579 | ---- | C] () -- C:\Users\Bruno\Desktop\premierm3.rar
[2012-10-03 13:49:39 | 000,118,784 | RHS- | C] () -- C:\Users\Bruno\AppData\Roaming\wevtapie.dll
[2012-09-17 22:49:07 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2010-08-14 00:41:29 | 000,776,408 | ---- | C] () -- C:\Users\Bruno\iqgf2x.jpg
[2010-08-14 00:41:29 | 000,102,326 | ---- | C] () -- C:\Users\Bruno\32zjtqo.jpg
[2010-08-14 00:41:29 | 000,063,155 | ---- | C] () -- C:\Users\Bruno\mcat1_122_850lo.jpg
[2010-08-14 00:41:29 | 000,037,163 | ---- | C] () -- C:\Users\Bruno\dcqzk7.jpg
[2010-08-14 00:41:29 | 000,029,777 | ---- | C] () -- C:\Users\Bruno\dpzpco.jpg
[2010-08-14 00:41:29 | 000,018,785 | ---- | C] () -- C:\Users\Bruno\2214706410_0591a1bfcb.jpg
[2010-08-14 00:41:29 | 000,016,050 | ---- | C] () -- C:\Users\Bruno\25i3y4z.jpg
[2010-08-14 00:41:29 | 000,010,818 | ---- | C] () -- C:\Users\Bruno\46305_27361_59a719c363_p.jpg
[2010-02-21 16:59:49 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat

========== ZeroAccess Check ==========

[2009-07-14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2011-12-01 19:12:52 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Azureus
[2010-10-25 23:30:34 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\BrOffice.org
[2012-02-19 21:25:07 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\MusicNet
[2010-03-08 00:33:10 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Toshiba
[2012-03-23 01:48:53 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\WinBatch
[2010-12-08 13:24:34 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



< End of report >

Attached Files

  • Attached File  OTL.Txt   89.64KB   88 downloads

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there lets get this fixed for you

CLEAR THE BAD TOOLBARS

Download AdwCleaner from here to your desktop
Run AdwCleaner and select Delete

Posted Image

Once done it will ask to reboot, allow this
On reboot a log will be produced please attach that

THEN

I will need a deeper OTL scan

  • Run OTL.

    Posted Image
  • Select All Users
  • Under the Custom Scan box paste this in

    netsvcs
    BASESERVICES
    %SYSTEMDRIVE%\*.exe
    /md5start
    services.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    winsock.*
    /md5stop
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window.

  • 0

#3
bgomes8

bgomes8

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Ok so here U have it


The OTL log is_


OTL logfile created on: 24-10-2012 18:30:11 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bruno\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy

1014,43 Mb Total Physical Memory | 172,43 Mb Available Physical Memory | 17,00% Memory free
1,99 Gb Paging File | 0,69 Gb Available in Paging File | 34,51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 36,78 Gb Free Space | 49,36% Space Free | Partition Type: NTFS
Drive D: | 74,13 Gb Total Space | 69,42 Gb Free Space | 93,64% Space Free | Partition Type: NTFS

Computer Name: BRUNO-PEPE | User Name: Bruno | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012-10-24 01:11:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
PRC - [2012-09-12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Security Client\NisSrv.exe
PRC - [2012-09-12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Security Client\MsMpEng.exe
PRC - [2012-08-26 22:20:10 | 000,307,856 | ---- | M] (Google Inc.) -- C:\Programas\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2012-08-24 08:34:41 | 000,748,680 | ---- | M] (Microsoft Corporation) -- C:\Programas\Internet Explorer\iexplore.exe
PRC - [2012-08-20 18:37:58 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2012-06-11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) -- C:\Programas\Microsoft\BingBar\7.1.391.0\BBSvc.EXE
PRC - [2012-03-08 18:50:28 | 004,280,184 | ---- | M] (Microsoft Corporation) -- C:\Programas\Windows Live\Messenger\msnmsgr.exe
PRC - [2011-08-05 12:29:56 | 000,159,456 | ---- | M] (Microsoft Corporation) -- C:\Programas\Zune\ZuneLauncher.exe
PRC - [2011-03-28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011-03-28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011-02-25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011-02-10 10:25:42 | 001,546,720 | ---- | M] (Toshiba Europe GmbH) -- C:\Programas\Toshiba TEMPRO\TemproTray.exe
PRC - [2011-02-10 10:25:36 | 000,112,080 | ---- | M] (Toshiba Europe GmbH) -- C:\Programas\Toshiba TEMPRO\TemproSvc.exe
PRC - [2010-11-20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programas\Windows Media Player\wmpnetwk.exe
PRC - [2010-11-20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009-09-03 16:06:32 | 000,304,496 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2009-08-27 14:37:10 | 000,185,712 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TECO\TecoService.exe
PRC - [2009-08-26 19:00:06 | 001,324,384 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TECO\TEco.exe
PRC - [2009-08-21 10:29:40 | 000,464,224 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2009-08-21 10:29:20 | 000,476,512 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\Power Saver\TPwrMain.exe
PRC - [2009-08-13 13:31:24 | 000,521,528 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\SmoothView\SmoothView.exe
PRC - [2009-08-12 11:30:42 | 006,203,296 | ---- | M] (TOSHIBA) -- C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe
PRC - [2009-08-10 20:55:46 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
PRC - [2009-08-07 05:47:46 | 000,354,640 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosHdpProc.exe
PRC - [2009-08-06 19:36:56 | 002,680,160 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2009-08-06 18:05:18 | 000,583,024 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TPHM\TPCHWMsg.exe
PRC - [2009-08-06 18:04:56 | 000,685,424 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TPHM\TPCHSrv.exe
PRC - [2009-08-06 15:02:02 | 000,029,528 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
PRC - [2009-08-06 13:06:58 | 000,466,792 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\BulletinBoard\TosNcCore.exe
PRC - [2009-08-05 15:04:54 | 000,738,616 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\FlashCards\TCrdMain.exe
PRC - [2009-08-03 18:16:50 | 001,021,272 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
PRC - [2009-08-03 18:16:32 | 000,111,960 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
PRC - [2009-07-30 06:20:04 | 000,144,752 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2009-07-28 21:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009-07-28 15:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2009-07-21 04:58:52 | 002,651,512 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtProc.exe
PRC - [2009-07-08 09:40:58 | 000,518,720 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\ThpSrv.exe
PRC - [2009-07-06 19:44:22 | 000,341,320 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosOBEX.exe
PRC - [2009-07-02 11:05:00 | 000,252,288 | ---- | M] (TOSHIBA) -- C:\Programas\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
PRC - [2009-06-07 23:34:58 | 000,660,808 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2009-06-03 00:33:14 | 000,308,552 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe
PRC - [2009-04-23 06:36:26 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Programas\BrOffice.org 3\program\soffice.bin
PRC - [2009-04-23 06:33:18 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Programas\BrOffice.org 3\program\soffice.exe
PRC - [2009-04-03 03:17:42 | 000,447,816 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosAVRC.exe
PRC - [2009-03-29 14:51:56 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programas\Apoint2K\hidfind.exe
PRC - [2009-03-10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2009-02-26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2009-01-13 21:33:40 | 000,034,088 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\Utilities\KeNotify.exe
PRC - [2008-07-23 20:24:24 | 000,083,272 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe


========== Modules (No Company Name) ==========

MOD - [2012-06-15 01:48:56 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll
MOD - [2012-06-15 00:52:13 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll
MOD - [2012-06-15 00:47:42 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012-06-15 00:47:03 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012-06-15 00:46:40 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
MOD - [2012-05-10 11:53:20 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012-05-10 11:45:44 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012-05-10 11:45:13 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012-05-10 11:44:33 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012-05-10 11:44:14 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012-05-10 11:43:03 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2009-08-26 18:55:06 | 000,520,192 | ---- | M] () -- C:\Programas\TOSHIBA\TECO\TecoPower.dll
MOD - [2009-08-06 13:08:04 | 002,878,824 | ---- | M] () -- C:\Programas\TOSHIBA\BulletinBoard\TosNcUi.dll
MOD - [2009-08-03 18:17:24 | 000,079,192 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll
MOD - [2009-07-16 16:27:48 | 000,052,536 | ---- | M] () -- C:\Programas\TOSHIBA\FlashCards\Hotkey\FnZ.dll
MOD - [2009-07-16 16:27:44 | 007,263,544 | ---- | M] () -- C:\Programas\TOSHIBA\FlashCards\BlackPng.dll
MOD - [2009-06-22 15:38:40 | 000,015,160 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA Assist\NotifyX.dll
MOD - [2009-04-16 13:02:16 | 000,970,752 | ---- | M] () -- C:\Programas\BrOffice.org 3\program\libxml2.dll
MOD - [2009-03-12 20:08:04 | 000,049,152 | ---- | M] () -- C:\Programas\TOSHIBA\PCDiag\NotifyPCD.dll
MOD - [2006-10-07 12:57:04 | 000,053,248 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll


========== Services (SafeList) ==========

SRV - [2012-10-09 01:48:49 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-09-12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programas\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012-09-12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programas\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012-06-11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Programas\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012-06-11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Running] -- C:\Programas\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2012-06-07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programas\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012-03-08 18:32:24 | 001,492,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2011-08-05 12:30:02 | 000,444,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV - [2011-08-05 12:30:02 | 000,268,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV - [2011-08-05 12:29:56 | 006,363,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2011-07-20 05:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2011-03-28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011-02-10 10:25:36 | 000,112,080 | ---- | M] (Toshiba Europe GmbH) [Auto | Running] -- C:\Programas\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService)
SRV - [2010-11-20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programas\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010-09-22 16:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programas\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2009-08-27 14:37:10 | 000,185,712 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programas\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV - [2009-08-21 10:29:40 | 000,464,224 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programas\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2009-08-17 11:48:42 | 000,051,512 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Programas\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2009-08-10 20:55:46 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Programas\TOSHIBA\ConfigFree\CFIWmxSvcs.exe -- (cfWiMAXService)
SRV - [2009-08-06 18:04:56 | 000,685,424 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programas\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV - [2009-08-03 18:16:32 | 000,111,960 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV - [2009-07-30 06:20:04 | 000,144,752 | ---- | M] (TOSHIBA CORPORATION) [On_Demand | Running] -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2009-07-28 15:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009-07-08 09:40:58 | 000,518,720 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\ThpSrv.exe -- (Thpsrv)
SRV - [2009-03-10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2007-05-31 16:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007-05-31 16:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006-10-26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RtsUCcid.sys -- (USBCCID)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Rts516xIR.sys -- (RtsUIR)
DRV - [2012-08-30 22:03:50 | 000,099,272 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012-08-23 15:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012-08-23 15:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010-11-20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2009-09-21 18:58:28 | 001,218,048 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009-08-05 15:44:44 | 000,049,400 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2009-08-05 13:55:08 | 000,061,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV - [2009-07-30 21:02:34 | 000,036,208 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LPCFilter.sys -- (LPCFilter)
DRV - [2009-07-30 17:45:56 | 000,022,912 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2009-07-30 17:45:22 | 000,171,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009-07-28 21:01:26 | 000,069,480 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2009-07-24 12:31:58 | 000,021,608 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2009-07-14 16:28:42 | 000,023,512 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2009-07-13 23:13:10 | 000,015,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfec.sys -- (tosrfec)
DRV - [2009-07-07 22:38:34 | 000,168,936 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2009-06-29 16:16:22 | 000,013,120 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\Thpevm.sys -- (Thpevm)
DRV - [2009-06-29 10:25:24 | 000,030,272 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\thpdrv.sys -- (Thpdrv)
DRV - [2009-06-22 18:04:58 | 000,024,064 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PGEffect.sys -- (PGEffect)
DRV - [2009-06-19 20:31:08 | 000,012,920 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\TVALZFL.sys -- (TVALZFL)
DRV - [2009-06-19 10:57:20 | 000,079,872 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2009-06-19 10:56:48 | 000,042,472 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV - [2009-06-17 12:59:46 | 000,046,984 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosporte.sys -- (tosporte)
DRV - [2008-03-17 12:05:30 | 000,101,632 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008-02-07 01:23:46 | 000,166,448 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=TSEI&bmod=TSEI
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...=TSEI&bmod=TSEI
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\URLSearchHook: {55d7c7bc-12a7-4f9b-81c0-600d9a182395} - No CLSID value found
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{1E99E41B-E211-406F-9952-7AAF7186A3BF}: "URL" = http://www.amazon.co...ed&linkCode=ur2
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{5D3A5735-DE55-417D-A646-16EC0CFD46ED}: "URL" = http://rover.ebay.co...e={searchTerms}
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...pt-PTPT367PT369
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{978E0DE2-0143-454F-B92F-9E322E469ED9}: "URL" = http://search.condui...&ctid=CT3202918
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-10-11 23:14:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-10-11 23:14:44 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://search.imesh.com
CHR - Extension: No name found = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\eibdjcmcmfggjoiaaoojhicjnkghbkbe\0.1.5_1\

O1 HOSTS File: ([2009-06-10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programas\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Programas\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\Toolbar\WebBrowser: (no name) - {55D7C7BC-12A7-4F9B-81C0-600D9A182395} - No CLSID value found.
O3 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\Toolbar\WebBrowser: (no name) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Programas\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KeNotify] C:\Programas\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RegTask] C:\Program Files\RegTask\RegTask.exe File not found
O4 - HKLM..\Run: [SmoothView] C:\Programas\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ThpSrv] C:\Windows\System32\thpsrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Programas\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [TosNC] C:\Programas\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosReelTimeMonitor] C:\Programas\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosSENotify] C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosWaitSrv] C:\Programas\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Programas\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TUSBSleepChargeSrv] C:\Programas\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe (TOSHIBA)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [TOSHIBA Online Product Information] C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
O4 - HKU\S-1-5-18..\Run: [TOSHIBA Online Product Information] C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
O4 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000..\Run: [fnosxy] C:\Users\Bruno\AppData\Roaming\wevtapie.dll ()
O4 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000..\Run: [TOSHIBA Online Product Information] C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BrOffice.org 3.1.lnk = C:\Programas\BrOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Iniciação Rápida do Microsoft Office OneNote 2007.lnk = C:\Programas\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Programas\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Programas\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Programas\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programas\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.appl...ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2....re/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{297ED7F6-3D73-40D0-A964-0D3237ED7731}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programas\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programas\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programas\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programas\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{62c0314a-ca3b-11df-84ba-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{62c0314a-ca3b-11df-84ba-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a776-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a776-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a79c-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a79c-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a7a0-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a7a0-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{fe34b9e7-d69a-11df-b041-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{fe34b9e7-d69a-11df-b041-002622ed90d8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012-10-24 10:48:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012-10-24 10:47:59 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012-10-24 10:44:30 | 003,941,312 | ---- | C] (Piriform Ltd) -- C:\Users\Bruno\Desktop\ccsetup323.exe
[2012-10-24 10:02:06 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{2DE2999C-B117-4C11-9584-9FF09B998C69}
[2012-10-24 01:11:14 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
[2012-10-23 22:01:13 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{76BE6E11-2456-45B8-8DED-C33899F40C71}
[2012-10-23 18:39:44 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
[2012-10-23 18:39:40 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rdpvideominiport.sys
[2012-10-23 18:39:37 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
[2012-10-23 18:39:36 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RdpGroupPolicyExtension.dll
[2012-10-23 18:39:31 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\TsUsbFlt.sys
[2012-10-23 18:39:23 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsRdpWebAccess.dll
[2012-10-23 18:39:23 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsgqec.dll
[2012-10-23 18:39:23 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbGDCoInstaller.dll
[2012-10-23 18:39:23 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprtPS.dll
[2012-10-23 18:39:22 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll
[2012-10-23 18:39:22 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpudd.dll
[2012-10-23 18:39:22 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSWbPrxy.exe
[2012-10-23 18:39:21 | 000,317,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprt.exe
[2012-10-23 18:39:21 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpendp_winip.dll
[2012-10-23 18:39:17 | 002,739,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll
[2012-10-23 18:35:53 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2012-10-23 12:24:26 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Malwarebytes
[2012-10-23 12:23:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012-10-23 11:35:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012-10-23 09:36:17 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{79C65D2B-5AD0-4B16-AEAA-86AE3FAAB826}
[2012-10-22 20:27:49 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012-10-22 16:12:39 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{8C6CE4A5-CBAF-4B7C-A4EF-8EFC69E5903B}
[2012-10-21 13:06:06 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{5F1E1D76-E752-4411-B68F-3A81FDD70144}
[2012-10-21 00:05:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{925473B4-0B1E-4048-B272-B43B02B10E3B}
[2012-10-19 09:48:28 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{F4F8D4F7-945F-4231-AE41-B04DF03C5B86}
[2012-10-18 10:01:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{37FB29E7-ED65-49D6-AACF-7034A761A9AF}
[2012-10-17 14:15:30 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{1F5A42B9-806E-416A-BFA6-92E2325378BD}
[2012-10-16 09:15:03 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{4049AC65-3DAA-4F45-AF27-39F0D7C4EEEA}
[2012-10-15 17:34:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{8E8AA3D5-98D7-44D5-BD09-613C101402DA}
[2012-10-15 02:01:51 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DEB5E6C1-786A-47E7-B63F-D329906F8614}
[2012-10-13 10:18:24 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E62A536C-E875-4D8F-B9D9-4A37B47EC8CD}
[2012-10-12 01:41:29 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{2FC75F44-9B73-45EC-8C00-275625907143}
[2012-10-11 09:16:15 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{D65F8A63-8746-40D7-B79B-84365454728E}
[2012-10-10 18:08:03 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012-10-10 18:07:10 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2012-10-10 18:07:10 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2012-10-10 18:07:07 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2012-10-10 18:07:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-10-10 18:07:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2012-10-10 18:07:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2012-10-10 18:07:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2012-10-10 18:07:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-10-10 18:07:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-10-10 18:07:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2012-10-10 18:07:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-10-10 18:07:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2012-10-10 18:07:05 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2012-10-10 18:07:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2012-10-10 18:07:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-10-10 18:07:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2012-10-10 18:07:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2012-10-10 18:07:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2012-10-10 18:07:00 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2012-10-10 18:07:00 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2012-10-10 18:07:00 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2012-10-10 18:07:00 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012-10-10 18:06:59 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2012-10-10 18:06:59 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012-10-10 18:05:09 | 003,914,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012-10-10 18:05:00 | 003,968,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012-10-10 17:48:37 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{534BBD51-BD19-4BCC-B8A0-1ECBCF25D878}
[2012-10-10 01:58:45 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{D4CA5F12-06E0-48D1-AED1-BC9E344204F6}
[2012-10-09 13:46:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{CD92EAFA-511E-4197-9613-3F9577BA59C7}
[2012-10-08 12:03:17 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{1768C40A-80D5-4767-80C1-BD2BE8DAD01D}
[2012-10-07 09:21:39 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DF54BC6F-9574-419F-8F15-5803ACCC461D}
[2012-10-06 16:40:15 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{0260AB2B-D68F-4CE6-9096-115B497D4447}
[2012-10-05 22:02:48 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Desktop\Constructor
[2012-10-05 14:47:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DC823420-2871-4BB9-B7ED-D9FE2AFB2089}
[2012-10-04 16:56:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Desktop\PM2
[2012-10-04 09:28:52 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E600E9ED-3103-4FB8-BF5B-5710090CF3B8}
[2012-10-03 14:47:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{7AE07EA2-84BE-4D5D-9BEB-EFB255179173}
[2012-10-03 02:46:40 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{3955745F-E8FB-4DA6-A159-3709959E3FD8}
[2012-10-01 09:40:31 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{00BCB191-FA4C-4DC2-AD5A-312A7F71E234}
[2012-09-30 10:36:09 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{B9F8A37B-457D-4C4F-AECA-343997E4E8D2}
[2012-09-29 19:03:00 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{3E3AE1E8-F03E-4923-A93E-C5B579315C0B}
[2012-09-26 09:50:30 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OxpsConverter.exe
[2012-09-26 09:41:44 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E37BE0FB-75FB-4A93-918F-660116EF1BC7}
[2012-09-25 14:26:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{569FE158-6614-4FF2-8D64-5AEE934108D0}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012-10-24 18:36:00 | 000,014,304 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-10-24 18:36:00 | 000,014,304 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-10-24 18:22:41 | 000,000,996 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-10-24 18:22:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012-10-24 18:22:08 | 797,777,920 | -HS- | M] () -- C:\hiberfil.sys
[2012-10-24 18:21:19 | 000,001,000 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-10-24 18:18:29 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-10-24 18:15:00 | 000,538,941 | ---- | M] () -- C:\Users\Bruno\Desktop\adwcleaner.exe
[2012-10-24 10:48:10 | 000,000,976 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-24 10:44:32 | 003,941,312 | ---- | M] (Piriform Ltd) -- C:\Users\Bruno\Desktop\ccsetup323.exe
[2012-10-24 01:11:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
[2012-10-23 11:36:21 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012-10-22 10:30:01 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\RegTask.job
[2012-10-14 01:51:52 | 000,082,250 | ---- | M] () -- C:\Users\Bruno\Desktop\Publicitação_Recrutamento_TS_RefªA_Erasmus_1.sflb.pdf
[2012-10-10 18:31:48 | 000,002,331 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012-10-09 01:48:31 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012-10-09 01:48:30 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012-10-04 16:36:25 | 003,092,694 | ---- | M] () -- C:\Users\Bruno\Desktop\pmanager2.rar
[2012-10-04 16:35:22 | 002,316,579 | ---- | M] () -- C:\Users\Bruno\Desktop\premierm3.rar
[2012-10-04 00:18:58 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012-10-03 13:49:42 | 000,118,784 | RHS- | M] () -- C:\Users\Bruno\AppData\Roaming\wevtapie.dll
[2012-10-02 09:47:18 | 000,679,342 | ---- | M] () -- C:\Windows\System32\prfh0816.dat
[2012-10-02 09:47:18 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012-10-02 09:47:18 | 000,133,752 | ---- | M] () -- C:\Windows\System32\prfc0816.dat
[2012-10-02 09:47:18 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-10-24 18:14:34 | 000,538,941 | ---- | C] () -- C:\Users\Bruno\Desktop\adwcleaner.exe
[2012-10-24 10:48:09 | 000,000,976 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-23 11:36:12 | 000,002,124 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012-10-14 01:51:49 | 000,082,250 | ---- | C] () -- C:\Users\Bruno\Desktop\Publicitação_Recrutamento_TS_RefªA_Erasmus_1.sflb.pdf
[2012-10-04 16:36:17 | 003,092,694 | ---- | C] () -- C:\Users\Bruno\Desktop\pmanager2.rar
[2012-10-04 16:35:20 | 002,316,579 | ---- | C] () -- C:\Users\Bruno\Desktop\premierm3.rar
[2012-10-03 13:49:39 | 000,118,784 | RHS- | C] () -- C:\Users\Bruno\AppData\Roaming\wevtapie.dll
[2012-09-17 22:49:07 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2010-08-14 00:41:29 | 000,776,408 | ---- | C] () -- C:\Users\Bruno\iqgf2x.jpg
[2010-08-14 00:41:29 | 000,102,326 | ---- | C] () -- C:\Users\Bruno\32zjtqo.jpg
[2010-08-14 00:41:29 | 000,063,155 | ---- | C] () -- C:\Users\Bruno\mcat1_122_850lo.jpg
[2010-08-14 00:41:29 | 000,037,163 | ---- | C] () -- C:\Users\Bruno\dcqzk7.jpg
[2010-08-14 00:41:29 | 000,029,777 | ---- | C] () -- C:\Users\Bruno\dpzpco.jpg
[2010-08-14 00:41:29 | 000,018,785 | ---- | C] () -- C:\Users\Bruno\2214706410_0591a1bfcb.jpg
[2010-08-14 00:41:29 | 000,016,050 | ---- | C] () -- C:\Users\Bruno\25i3y4z.jpg
[2010-08-14 00:41:29 | 000,010,818 | ---- | C] () -- C:\Users\Bruno\46305_27361_59a719c363_p.jpg
[2010-02-21 16:59:49 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat

========== ZeroAccess Check ==========

[2009-07-14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

========== Base Services ==========
SRV - [2009-07-14 02:14:53 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\aelupsvc.dll -- (AeLookupSvc)
SRV - [2010-11-20 13:18:03 | 000,047,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\appinfo.dll -- (Appinfo)
SRV - [2009-07-14 02:14:11 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\alg.exe -- (ALG)
SRV - [2010-11-20 13:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\qmgr.dll -- (BITS)
SRV - [2010-11-20 13:18:06 | 000,494,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE)
SRV - [2011-11-17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (KeyIso)
SRV - [2009-07-14 02:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem)
SRV - [2012-07-04 22:14:34 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\browser.dll -- (Browser)
SRV - [2012-06-02 05:36:29 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc)
SRV - [2010-11-20 13:21:03 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch)
SRV - [2010-11-20 13:18:30 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2011-03-03 06:38:01 | 000,132,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache)
SRV - [2009-07-14 02:15:13 | 000,098,304 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\eapsvc.dll -- (EapHost)
SRV - [2009-07-14 02:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\hidserv.dll -- (hidserv)
SRV - [2009-07-14 02:15:33 | 000,300,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess)
SRV - [2010-11-20 13:19:23 | 000,350,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent)
SRV - [2012-09-12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programas\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012-09-12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programas\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2009-07-14 02:16:15 | 000,313,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv)
SRV - [2009-07-14 02:15:41 | 000,049,664 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\mmcss.dll -- (MMCSS)
SRV - [2009-07-14 02:16:03 | 000,280,576 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman)
SRV - [2009-07-14 02:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofm.dll -- (netprofm)
SRV - [2010-11-20 13:20:30 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc)
SRV - [2009-07-14 02:16:11 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi)
SRV - [2011-05-24 11:44:59 | 000,293,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay)
SRV - [2012-02-11 06:37:49 | 000,317,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler)
SRV - [2011-11-17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV - [2009-07-14 02:16:12 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto)
SRV - [2010-11-20 13:21:00 | 000,286,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\rasmans.dll -- (RasMan)
SRV - [2010-11-20 13:21:03 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs)
SRV - [2009-07-14 02:16:13 | 000,021,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2011-11-17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs)
SRV - [2009-07-14 02:16:20 | 000,073,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc)
SRV - [2010-11-20 13:21:26 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer)
SRV - [2010-11-20 13:21:19 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV - [2010-11-20 13:21:05 | 000,750,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule)
SRV - [2010-11-20 13:21:28 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv)
SRV - [2009-07-14 02:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2012-05-01 05:44:12 | 000,164,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc)
SRV - [2010-11-20 13:17:51 | 001,025,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS)
SRV - [2010-11-20 13:18:05 | 000,473,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv)
SRV - [2010-11-20 13:18:05 | 000,473,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (AudioEndpointBuilder)
SRV - [2010-11-20 13:21:06 | 000,125,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sdrsvc.dll -- (SDRSVC)
SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010-11-20 13:21:35 | 001,086,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (eventlog)
SRV - [2010-11-20 13:19:40 | 000,566,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc)
SRV - [2010-11-20 13:21:35 | 000,463,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wiaservc.dll -- (StiSvc)
SRV - [2010-11-20 13:17:22 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\msiexec.exe -- (msiserver)
SRV - [2009-07-14 02:16:19 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (Winmgmt)
SRV - [2012-06-02 23:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv)
SRV - [2010-11-20 13:18:34 | 000,214,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc)
SRV - [2009-07-14 02:16:19 | 000,829,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wlansvc.dll -- (Wlansvc)
SRV - [2010-11-20 13:21:36 | 000,084,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation)

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011-02-26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009-07-14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011-02-26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009-10-31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011-02-26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010-11-20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011-02-25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe
[2011-02-25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009-08-03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009-08-03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009-10-31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: SERVICES >
[2009-06-10 22:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\System32\drivers\etc\services
[2009-06-10 22:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.EXE >
[2009-07-14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\System32\services.exe
[2009-07-14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009-07-14 09:30:26 | 000,018,944 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\pt-PT\services.exe.mui
[2009-07-14 09:30:26 | 000,018,944 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_pt-pt_6c51a32af36c30ad\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009-07-14 05:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009-07-14 05:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009-06-10 22:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\System32\wbem\services.mof
[2009-06-10 22:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2009-06-10 22:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\services.msc
[2009-06-10 22:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
[2009-07-14 09:30:23 | 000,092,750 | ---- | M] () MD5=D10CEC9EE745D47F175851A96897BA51 -- C:\Windows\System32\pt-PT\services.msc
[2009-07-14 09:30:23 | 000,092,750 | ---- | M] () MD5=D10CEC9EE745D47F175851A96897BA51 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_pt-pt_a6937316c9d5caa0\services.msc

< MD5 for: SERVICES.PTXML >
[2009-07-13 21:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009-07-13 21:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: SERVICES.RDB >
[2009-04-27 06:36:18 | 005,472,256 | ---- | M] () Unable to obtain MD5 -- C:\Program Files\BrOffice.org 3\Basis\program\services.rdb
[2009-04-27 06:41:54 | 000,262,144 | ---- | M] () Unable to obtain MD5 -- C:\Program Files\BrOffice.org 3\URE\misc\services.rdb

< MD5 for: SVCHOST.EXE >
[2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe

< MD5 for: USERINIT.EXE >
[2010-11-20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010-11-20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009-07-14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009-10-28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009-10-28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010-11-20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010-11-20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009-07-14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< MD5 for: WINSOCK.DLL >
[2009-07-13 22:41:34 | 000,002,864 | ---- | M] (Microsoft Corporation) MD5=68485C5EF0E2EFCEBF21BBB1042B823B -- C:\Windows\System32\WINSOCK.DLL
[2009-07-13 22:41:34 | 000,002,864 | ---- | M] (Microsoft Corporation) MD5=68485C5EF0E2EFCEBF21BBB1042B823B -- C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d\WINSOCK.DLL
[2009-07-13 22:41:34 | 000,002,864 | ---- | M] (Microsoft Corporation) MD5=68485C5EF0E2EFCEBF21BBB1042B823B -- C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7601.17514_none_0014e305d0cff0a7\WINSOCK.DLL

< >

< >

< End of report >

Attached Files


  • 0

#4
bgomes8

bgomes8

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
I forgot to add there on the las line CREATERESTOREPOINT
  • 0

#5
bgomes8

bgomes8

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Ok so now here it goes the OTL log:


OTL logfile created on: 24-10-2012 23:45:37 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bruno\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy

1014,43 Mb Total Physical Memory | 273,17 Mb Available Physical Memory | 26,93% Memory free
1,99 Gb Paging File | 0,90 Gb Available in Paging File | 45,08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 36,88 Gb Free Space | 49,49% Space Free | Partition Type: NTFS
Drive D: | 74,13 Gb Total Space | 69,42 Gb Free Space | 93,64% Space Free | Partition Type: NTFS

Computer Name: BRUNO-PEPE | User Name: Bruno | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012-10-24 01:11:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
PRC - [2012-09-12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Security Client\NisSrv.exe
PRC - [2012-09-12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Security Client\MsMpEng.exe
PRC - [2012-08-26 22:20:10 | 000,307,856 | ---- | M] (Google Inc.) -- C:\Programas\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2012-08-24 08:34:41 | 000,748,680 | ---- | M] (Microsoft Corporation) -- C:\Programas\Internet Explorer\iexplore.exe
PRC - [2012-08-20 18:37:58 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2012-06-11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) -- C:\Programas\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2012-03-08 18:50:28 | 004,280,184 | ---- | M] (Microsoft Corporation) -- C:\Programas\Windows Live\Messenger\msnmsgr.exe
PRC - [2011-08-05 12:29:56 | 000,159,456 | ---- | M] (Microsoft Corporation) -- C:\Programas\Zune\ZuneLauncher.exe
PRC - [2011-03-28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011-03-28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011-02-25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011-02-10 10:25:42 | 001,546,720 | ---- | M] (Toshiba Europe GmbH) -- C:\Programas\Toshiba TEMPRO\TemproTray.exe
PRC - [2011-02-10 10:25:36 | 000,112,080 | ---- | M] (Toshiba Europe GmbH) -- C:\Programas\Toshiba TEMPRO\TemproSvc.exe
PRC - [2010-11-20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programas\Windows Media Player\wmpnetwk.exe
PRC - [2010-11-20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009-09-03 16:06:32 | 000,304,496 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2009-08-27 14:37:10 | 000,185,712 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TECO\TecoService.exe
PRC - [2009-08-26 19:00:06 | 001,324,384 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TECO\TEco.exe
PRC - [2009-08-21 10:29:40 | 000,464,224 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2009-08-21 10:29:20 | 000,476,512 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\Power Saver\TPwrMain.exe
PRC - [2009-08-13 13:31:24 | 000,521,528 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\SmoothView\SmoothView.exe
PRC - [2009-08-12 11:30:42 | 006,203,296 | ---- | M] (TOSHIBA) -- C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe
PRC - [2009-08-10 20:55:46 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
PRC - [2009-08-07 05:47:46 | 000,354,640 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosHdpProc.exe
PRC - [2009-08-06 19:36:56 | 002,680,160 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2009-08-06 18:05:18 | 000,583,024 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TPHM\TPCHWMsg.exe
PRC - [2009-08-06 18:04:56 | 000,685,424 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TPHM\TPCHSrv.exe
PRC - [2009-08-06 15:02:02 | 000,029,528 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
PRC - [2009-08-06 13:06:58 | 000,466,792 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\BulletinBoard\TosNcCore.exe
PRC - [2009-08-05 15:04:54 | 000,738,616 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\FlashCards\TCrdMain.exe
PRC - [2009-08-03 18:16:50 | 001,021,272 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
PRC - [2009-08-03 18:16:32 | 000,111,960 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
PRC - [2009-07-30 06:20:04 | 000,144,752 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2009-07-28 21:26:42 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009-07-28 15:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2009-07-21 04:58:52 | 002,651,512 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtProc.exe
PRC - [2009-07-08 09:40:58 | 000,518,720 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\ThpSrv.exe
PRC - [2009-07-06 19:44:22 | 000,341,320 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosOBEX.exe
PRC - [2009-07-02 11:05:00 | 000,252,288 | ---- | M] (TOSHIBA) -- C:\Programas\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
PRC - [2009-06-07 23:34:58 | 000,660,808 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2009-06-03 00:33:14 | 000,308,552 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe
PRC - [2009-04-23 06:36:26 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Programas\BrOffice.org 3\program\soffice.bin
PRC - [2009-04-23 06:33:18 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Programas\BrOffice.org 3\program\soffice.exe
PRC - [2009-04-03 03:17:42 | 000,447,816 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosAVRC.exe
PRC - [2009-03-29 14:51:56 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programas\Apoint2K\hidfind.exe
PRC - [2009-03-10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2009-02-26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2009-01-13 21:33:40 | 000,034,088 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\Utilities\KeNotify.exe
PRC - [2008-07-23 20:24:24 | 000,083,272 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe


========== Modules (No Company Name) ==========

MOD - [2012-06-15 01:48:56 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll
MOD - [2012-06-15 00:52:13 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll
MOD - [2012-06-15 00:47:42 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012-06-15 00:47:03 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012-06-15 00:46:40 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
MOD - [2012-05-10 11:53:20 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012-05-10 11:45:44 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012-05-10 11:45:13 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012-05-10 11:44:33 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012-05-10 11:44:14 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012-05-10 11:43:03 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2009-08-26 18:55:06 | 000,520,192 | ---- | M] () -- C:\Programas\TOSHIBA\TECO\TecoPower.dll
MOD - [2009-08-06 13:08:04 | 002,878,824 | ---- | M] () -- C:\Programas\TOSHIBA\BulletinBoard\TosNcUi.dll
MOD - [2009-08-03 18:17:24 | 000,079,192 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll
MOD - [2009-07-16 16:27:48 | 000,052,536 | ---- | M] () -- C:\Programas\TOSHIBA\FlashCards\Hotkey\FnZ.dll
MOD - [2009-07-16 16:27:44 | 007,263,544 | ---- | M] () -- C:\Programas\TOSHIBA\FlashCards\BlackPng.dll
MOD - [2009-06-22 15:38:40 | 000,015,160 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA Assist\NotifyX.dll
MOD - [2009-04-16 13:02:16 | 000,970,752 | ---- | M] () -- C:\Programas\BrOffice.org 3\program\libxml2.dll
MOD - [2009-03-12 20:08:04 | 000,049,152 | ---- | M] () -- C:\Programas\TOSHIBA\PCDiag\NotifyPCD.dll
MOD - [2006-10-07 12:57:04 | 000,053,248 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll


========== Services (SafeList) ==========

SRV - [2012-10-09 01:48:49 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-09-12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programas\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012-09-12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programas\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012-06-11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Programas\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012-06-11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Programas\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2012-06-07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programas\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012-03-08 18:32:24 | 001,492,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2011-08-05 12:30:02 | 000,444,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV - [2011-08-05 12:30:02 | 000,268,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV - [2011-08-05 12:29:56 | 006,363,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2011-07-20 05:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2011-03-28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011-02-10 10:25:36 | 000,112,080 | ---- | M] (Toshiba Europe GmbH) [Auto | Running] -- C:\Programas\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService)
SRV - [2010-11-20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programas\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010-09-22 16:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programas\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2009-08-27 14:37:10 | 000,185,712 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programas\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV - [2009-08-21 10:29:40 | 000,464,224 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programas\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2009-08-17 11:48:42 | 000,051,512 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Programas\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2009-08-10 20:55:46 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Programas\TOSHIBA\ConfigFree\CFIWmxSvcs.exe -- (cfWiMAXService)
SRV - [2009-08-06 18:04:56 | 000,685,424 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programas\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV - [2009-08-03 18:16:32 | 000,111,960 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV - [2009-07-30 06:20:04 | 000,144,752 | ---- | M] (TOSHIBA CORPORATION) [On_Demand | Running] -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2009-07-28 15:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009-07-08 09:40:58 | 000,518,720 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\ThpSrv.exe -- (Thpsrv)
SRV - [2009-03-10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2007-05-31 16:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007-05-31 16:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006-10-26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RtsUCcid.sys -- (USBCCID)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Rts516xIR.sys -- (RtsUIR)
DRV - [2012-08-30 22:03:50 | 000,099,272 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012-08-23 15:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012-08-23 15:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010-11-20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2009-09-21 18:58:28 | 001,218,048 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009-08-05 15:44:44 | 000,049,400 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2009-08-05 13:55:08 | 000,061,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV - [2009-07-30 21:02:34 | 000,036,208 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LPCFilter.sys -- (LPCFilter)
DRV - [2009-07-30 17:45:56 | 000,022,912 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2009-07-30 17:45:22 | 000,171,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009-07-28 21:01:26 | 000,069,480 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2009-07-24 12:31:58 | 000,021,608 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2009-07-14 16:28:42 | 000,023,512 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2009-07-13 23:13:10 | 000,015,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfec.sys -- (tosrfec)
DRV - [2009-07-07 22:38:34 | 000,168,936 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2009-06-29 16:16:22 | 000,013,120 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\Thpevm.sys -- (Thpevm)
DRV - [2009-06-29 10:25:24 | 000,030,272 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\thpdrv.sys -- (Thpdrv)
DRV - [2009-06-22 18:04:58 | 000,024,064 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PGEffect.sys -- (PGEffect)
DRV - [2009-06-19 20:31:08 | 000,012,920 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\TVALZFL.sys -- (TVALZFL)
DRV - [2009-06-19 10:57:20 | 000,079,872 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2009-06-19 10:56:48 | 000,042,472 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV - [2009-06-17 12:59:46 | 000,046,984 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosporte.sys -- (tosporte)
DRV - [2008-03-17 12:05:30 | 000,101,632 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008-02-07 01:23:46 | 000,166,448 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=TSEI&bmod=TSEI
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...=TSEI&bmod=TSEI
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\URLSearchHook: {55d7c7bc-12a7-4f9b-81c0-600d9a182395} - No CLSID value found
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\System32\ieframe.dll (Microsoft Corporation)
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{1E99E41B-E211-406F-9952-7AAF7186A3BF}: "URL" = http://www.amazon.co...ed&linkCode=ur2
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{5D3A5735-DE55-417D-A646-16EC0CFD46ED}: "URL" = http://rover.ebay.co...e={searchTerms}
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...pt-PTPT367PT369
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{978E0DE2-0143-454F-B92F-9E322E469ED9}: "URL" = http://search.condui...&ctid=CT3202918
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-10-11 23:14:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-10-11 23:14:44 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://search.imesh.com
CHR - Extension: No name found = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\eibdjcmcmfggjoiaaoojhicjnkghbkbe\0.1.5_1\

O1 HOSTS File: ([2009-06-10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Programas\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programas\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programas\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Programas\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programas\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Programas\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Programas\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Programas\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Programas\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Programas\HP\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KeNotify] C:\Programas\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [RegTask] C:\Program Files\RegTask\RegTask.exe File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Programas\Realtek\Audio\HDA\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Programas\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ThpSrv] C:\Windows\System32\thpsrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Programas\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [TosNC] C:\Programas\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosReelTimeMonitor] C:\Programas\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosSENotify] C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosWaitSrv] C:\Programas\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Programas\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TUSBSleepChargeSrv] C:\Programas\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe (TOSHIBA)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [TOSHIBA Online Product Information] C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
O4 - HKU\S-1-5-18..\Run: [TOSHIBA Online Product Information] C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000..\Run: [fnosxy] C:\Users\Bruno\AppData\Roaming\wevtapie.dll ()
O4 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000..\Run: [TOSHIBA Online Product Information] C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BrOffice.org 3.1.lnk = C:\Programas\BrOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Iniciação Rápida do Microsoft Office OneNote 2007.lnk = C:\Programas\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Programas\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Programas\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Programas\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programas\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Exibir ou ocultar HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Programas\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\System32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Windows\System32\mswsock.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.appl...ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2....re/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{297ED7F6-3D73-40D0-A964-0D3237ED7731}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\System32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programas\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programas\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programas\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programas\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\System32\credssp.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\Windows\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\Windows\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\Windows\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\Windows\System32\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) - C:\Windows\System32\tspkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corp.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{62c0314a-ca3b-11df-84ba-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{62c0314a-ca3b-11df-84ba-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a776-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a776-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a79c-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a79c-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a7a0-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a7a0-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{fe34b9e7-d69a-11df-b041-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{fe34b9e7-d69a-11df-b041-002622ed90d8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012-10-24 22:02:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{F929FC71-B0EC-45DE-928F-5E80D72E6ED4}
[2012-10-24 10:48:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012-10-24 10:47:59 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012-10-24 10:44:30 | 003,941,312 | ---- | C] (Piriform Ltd) -- C:\Users\Bruno\Desktop\ccsetup323.exe
[2012-10-24 10:02:06 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{2DE2999C-B117-4C11-9584-9FF09B998C69}
[2012-10-24 01:11:14 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
[2012-10-23 22:01:13 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{76BE6E11-2456-45B8-8DED-C33899F40C71}
[2012-10-23 18:39:44 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
[2012-10-23 18:39:40 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\rdpvideominiport.sys
[2012-10-23 18:39:37 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
[2012-10-23 18:39:36 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RdpGroupPolicyExtension.dll
[2012-10-23 18:39:31 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\TsUsbFlt.sys
[2012-10-23 18:39:23 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsRdpWebAccess.dll
[2012-10-23 18:39:23 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tsgqec.dll
[2012-10-23 18:39:23 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TsUsbGDCoInstaller.dll
[2012-10-23 18:39:23 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprtPS.dll
[2012-10-23 18:39:22 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aaclient.dll
[2012-10-23 18:39:22 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpudd.dll
[2012-10-23 18:39:22 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TSWbPrxy.exe
[2012-10-23 18:39:21 | 000,317,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wksprt.exe
[2012-10-23 18:39:21 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpendp_winip.dll
[2012-10-23 18:39:17 | 002,739,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll
[2012-10-23 18:35:53 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2012-10-23 12:24:26 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Malwarebytes
[2012-10-23 12:23:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012-10-23 11:35:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012-10-23 09:36:17 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{79C65D2B-5AD0-4B16-AEAA-86AE3FAAB826}
[2012-10-22 20:27:49 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012-10-22 16:12:39 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{8C6CE4A5-CBAF-4B7C-A4EF-8EFC69E5903B}
[2012-10-21 13:06:06 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{5F1E1D76-E752-4411-B68F-3A81FDD70144}
[2012-10-21 00:05:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{925473B4-0B1E-4048-B272-B43B02B10E3B}
[2012-10-19 09:48:28 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{F4F8D4F7-945F-4231-AE41-B04DF03C5B86}
[2012-10-18 10:01:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{37FB29E7-ED65-49D6-AACF-7034A761A9AF}
[2012-10-17 14:15:30 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{1F5A42B9-806E-416A-BFA6-92E2325378BD}
[2012-10-16 09:15:03 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{4049AC65-3DAA-4F45-AF27-39F0D7C4EEEA}
[2012-10-15 17:34:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{8E8AA3D5-98D7-44D5-BD09-613C101402DA}
[2012-10-15 02:01:51 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DEB5E6C1-786A-47E7-B63F-D329906F8614}
[2012-10-13 10:18:24 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E62A536C-E875-4D8F-B9D9-4A37B47EC8CD}
[2012-10-12 01:41:29 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{2FC75F44-9B73-45EC-8C00-275625907143}
[2012-10-11 09:16:15 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{D65F8A63-8746-40D7-B79B-84365454728E}
[2012-10-10 18:08:03 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2012-10-10 18:07:10 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2012-10-10 18:07:10 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2012-10-10 18:07:07 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2012-10-10 18:07:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2012-10-10 18:07:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2012-10-10 18:07:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2012-10-10 18:07:07 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2012-10-10 18:07:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2012-10-10 18:07:06 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2012-10-10 18:07:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2012-10-10 18:07:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012-10-10 18:07:06 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2012-10-10 18:07:05 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2012-10-10 18:07:05 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2012-10-10 18:07:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2012-10-10 18:07:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2012-10-10 18:07:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2012-10-10 18:07:04 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2012-10-10 18:07:03 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2012-10-10 18:07:00 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2012-10-10 18:07:00 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2012-10-10 18:07:00 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2012-10-10 18:07:00 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2012-10-10 18:06:59 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2012-10-10 18:06:59 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2012-10-10 18:05:09 | 003,914,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2012-10-10 18:05:00 | 003,968,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2012-10-10 17:48:37 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{534BBD51-BD19-4BCC-B8A0-1ECBCF25D878}
[2012-10-10 01:58:45 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{D4CA5F12-06E0-48D1-AED1-BC9E344204F6}
[2012-10-09 13:46:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{CD92EAFA-511E-4197-9613-3F9577BA59C7}
[2012-10-08 12:03:17 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{1768C40A-80D5-4767-80C1-BD2BE8DAD01D}
[2012-10-07 09:21:39 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DF54BC6F-9574-419F-8F15-5803ACCC461D}
[2012-10-06 16:40:15 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{0260AB2B-D68F-4CE6-9096-115B497D4447}
[2012-10-05 22:02:48 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Desktop\Constructor
[2012-10-05 14:47:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DC823420-2871-4BB9-B7ED-D9FE2AFB2089}
[2012-10-04 16:56:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Desktop\PM2
[2012-10-04 09:28:52 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E600E9ED-3103-4FB8-BF5B-5710090CF3B8}
[2012-10-03 14:47:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{7AE07EA2-84BE-4D5D-9BEB-EFB255179173}
[2012-10-03 02:46:40 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{3955745F-E8FB-4DA6-A159-3709959E3FD8}
[2012-10-01 09:40:31 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{00BCB191-FA4C-4DC2-AD5A-312A7F71E234}
[2012-09-30 10:36:09 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{B9F8A37B-457D-4C4F-AECA-343997E4E8D2}
[2012-09-29 19:03:00 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{3E3AE1E8-F03E-4923-A93E-C5B579315C0B}
[2012-09-26 09:50:30 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OxpsConverter.exe
[2012-09-26 09:41:44 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E37BE0FB-75FB-4A93-918F-660116EF1BC7}
[2012-09-25 14:26:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{569FE158-6614-4FF2-8D64-5AEE934108D0}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012-10-24 23:21:00 | 000,001,000 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-10-24 23:18:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-10-24 19:38:16 | 000,000,996 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-10-24 18:36:00 | 000,014,304 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-10-24 18:36:00 | 000,014,304 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-10-24 18:22:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012-10-24 18:22:08 | 797,777,920 | -HS- | M] () -- C:\hiberfil.sys
[2012-10-24 18:15:00 | 000,538,941 | ---- | M] () -- C:\Users\Bruno\Desktop\adwcleaner.exe
[2012-10-24 10:48:10 | 000,000,976 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-24 10:44:32 | 003,941,312 | ---- | M] (Piriform Ltd) -- C:\Users\Bruno\Desktop\ccsetup323.exe
[2012-10-24 01:11:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
[2012-10-23 11:36:21 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012-10-22 10:30:01 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\RegTask.job
[2012-10-14 01:51:52 | 000,082,250 | ---- | M] () -- C:\Users\Bruno\Desktop\Publicitação_Recrutamento_TS_RefªA_Erasmus_1.sflb.pdf
[2012-10-10 18:31:48 | 000,002,331 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012-10-09 01:48:31 | 000,696,760 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012-10-09 01:48:30 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012-10-04 16:36:25 | 003,092,694 | ---- | M] () -- C:\Users\Bruno\Desktop\pmanager2.rar
[2012-10-04 16:35:22 | 002,316,579 | ---- | M] () -- C:\Users\Bruno\Desktop\premierm3.rar
[2012-10-04 00:18:58 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012-10-03 13:49:42 | 000,118,784 | RHS- | M] () -- C:\Users\Bruno\AppData\Roaming\wevtapie.dll
[2012-10-02 09:47:18 | 000,679,342 | ---- | M] () -- C:\Windows\System32\prfh0816.dat
[2012-10-02 09:47:18 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012-10-02 09:47:18 | 000,133,752 | ---- | M] () -- C:\Windows\System32\prfc0816.dat
[2012-10-02 09:47:18 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-10-24 18:14:34 | 000,538,941 | ---- | C] () -- C:\Users\Bruno\Desktop\adwcleaner.exe
[2012-10-24 10:48:09 | 000,000,976 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-23 11:36:12 | 000,002,124 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012-10-14 01:51:49 | 000,082,250 | ---- | C] () -- C:\Users\Bruno\Desktop\Publicitação_Recrutamento_TS_RefªA_Erasmus_1.sflb.pdf
[2012-10-04 16:36:17 | 003,092,694 | ---- | C] () -- C:\Users\Bruno\Desktop\pmanager2.rar
[2012-10-04 16:35:20 | 002,316,579 | ---- | C] () -- C:\Users\Bruno\Desktop\premierm3.rar
[2012-10-03 13:49:39 | 000,118,784 | RHS- | C] () -- C:\Users\Bruno\AppData\Roaming\wevtapie.dll
[2012-09-17 22:49:07 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2010-08-14 00:41:29 | 000,776,408 | ---- | C] () -- C:\Users\Bruno\iqgf2x.jpg
[2010-08-14 00:41:29 | 000,102,326 | ---- | C] () -- C:\Users\Bruno\32zjtqo.jpg
[2010-08-14 00:41:29 | 000,063,155 | ---- | C] () -- C:\Users\Bruno\mcat1_122_850lo.jpg
[2010-08-14 00:41:29 | 000,037,163 | ---- | C] () -- C:\Users\Bruno\dcqzk7.jpg
[2010-08-14 00:41:29 | 000,029,777 | ---- | C] () -- C:\Users\Bruno\dpzpco.jpg
[2010-08-14 00:41:29 | 000,018,785 | ---- | C] () -- C:\Users\Bruno\2214706410_0591a1bfcb.jpg
[2010-08-14 00:41:29 | 000,016,050 | ---- | C] () -- C:\Users\Bruno\25i3y4z.jpg
[2010-08-14 00:41:29 | 000,010,818 | ---- | C] () -- C:\Users\Bruno\46305_27361_59a719c363_p.jpg
[2010-02-21 16:59:49 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat

========== ZeroAccess Check ==========

[2009-07-14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

========== Base Services ==========
SRV - [2009-07-14 02:14:53 | 000,062,464 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\aelupsvc.dll -- (AeLookupSvc)
SRV - [2010-11-20 13:18:03 | 000,047,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\appinfo.dll -- (Appinfo)
SRV - [2009-07-14 02:14:11 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\alg.exe -- (ALG)
SRV - [2010-11-20 13:20:58 | 000,585,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\qmgr.dll -- (BITS)
SRV - [2010-11-20 13:18:06 | 000,494,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE)
SRV - [2011-11-17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (KeyIso)
SRV - [2009-07-14 02:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem)
SRV - [2012-07-04 22:14:34 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\browser.dll -- (Browser)
SRV - [2012-06-02 05:36:29 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc)
SRV - [2010-11-20 13:21:03 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch)
SRV - [2010-11-20 13:18:30 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2011-03-03 06:38:01 | 000,132,608 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache)
SRV - [2009-07-14 02:15:13 | 000,098,304 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\eapsvc.dll -- (EapHost)
SRV - [2009-07-14 02:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\hidserv.dll -- (hidserv)
SRV - [2009-07-14 02:15:33 | 000,300,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess)
SRV - [2010-11-20 13:19:23 | 000,350,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent)
SRV - [2012-09-12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programas\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012-09-12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programas\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2009-07-14 02:16:15 | 000,313,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv)
SRV - [2009-07-14 02:15:41 | 000,049,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\mmcss.dll -- (MMCSS)
SRV - [2009-07-14 02:16:03 | 000,280,576 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman)
SRV - [2009-07-14 02:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofm.dll -- (netprofm)
SRV - [2010-11-20 13:20:30 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc)
SRV - [2009-07-14 02:16:11 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi)
SRV - [2011-05-24 11:44:59 | 000,293,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay)
SRV - [2012-02-11 06:37:49 | 000,317,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler)
SRV - [2011-11-17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV - [2009-07-14 02:16:12 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto)
SRV - [2010-11-20 13:21:00 | 000,286,208 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\rasmans.dll -- (RasMan)
SRV - [2010-11-20 13:21:03 | 000,376,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs)
SRV - [2009-07-14 02:16:13 | 000,021,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2011-11-17 06:29:50 | 000,022,528 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs)
SRV - [2009-07-14 02:16:20 | 000,073,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc)
SRV - [2010-11-20 13:21:26 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer)
SRV - [2010-11-20 13:21:19 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV - [2010-11-20 13:21:05 | 000,750,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule)
SRV - [2010-11-20 13:21:28 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv)
SRV - [2009-07-14 02:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2012-05-01 05:44:12 | 000,164,352 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc)
SRV - [2010-11-20 13:17:51 | 001,025,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS)
SRV - [2010-11-20 13:18:05 | 000,473,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv)
SRV - [2010-11-20 13:18:05 | 000,473,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (AudioEndpointBuilder)
SRV - [2010-11-20 13:21:06 | 000,125,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sdrsvc.dll -- (SDRSVC)
SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010-11-20 13:21:35 | 001,086,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (eventlog)
SRV - [2010-11-20 13:19:40 | 000,566,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc)
SRV - [2010-11-20 13:21:35 | 000,463,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wiaservc.dll -- (StiSvc)
SRV - [2010-11-20 13:17:22 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\msiexec.exe -- (msiserver)
SRV - [2009-07-14 02:16:19 | 000,168,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (Winmgmt)
SRV - [2012-06-02 23:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv)
SRV - [2010-11-20 13:18:34 | 000,214,016 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc)
SRV - [2009-07-14 02:16:19 | 000,829,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wlansvc.dll -- (Wlansvc)
SRV - [2010-11-20 13:21:36 | 000,084,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation)

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011-02-26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009-07-14 02:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011-02-26 06:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009-10-31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011-02-26 06:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010-11-20 13:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011-02-25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe
[2011-02-25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009-08-03 06:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009-08-03 06:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009-10-31 07:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: SERVICES >
[2009-06-10 22:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\System32\drivers\etc\services
[2009-06-10 22:39:37 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.EXE >
[2009-07-14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\System32\services.exe
[2009-07-14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009-07-14 09:30:26 | 000,018,944 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\pt-PT\services.exe.mui
[2009-07-14 09:30:26 | 000,018,944 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_pt-pt_6c51a32af36c30ad\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009-07-14 05:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009-07-14 05:41:45 | 000,001,288 | ---- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009-06-10 22:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\System32\wbem\services.mof
[2009-06-10 22:26:14 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2009-06-10 22:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\services.msc
[2009-06-10 22:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
[2009-07-14 09:30:23 | 000,092,750 | ---- | M] () MD5=D10CEC9EE745D47F175851A96897BA51 -- C:\Windows\System32\pt-PT\services.msc
[2009-07-14 09:30:23 | 000,092,750 | ---- | M] () MD5=D10CEC9EE745D47F175851A96897BA51 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_pt-pt_a6937316c9d5caa0\services.msc

< MD5 for: SERVICES.PTXML >
[2009-07-13 21:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009-07-13 21:20:01 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: SERVICES.RDB >
[2009-04-27 06:36:18 | 005,472,256 | ---- | M] () Unable to obtain MD5 -- C:\Program Files\BrOffice.org 3\Basis\program\services.rdb
[2009-04-27 06:41:54 | 000,262,144 | ---- | M] () Unable to obtain MD5 -- C:\Program Files\BrOffice.org 3\URE\misc\services.rdb

< MD5 for: SVCHOST.EXE >
[2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009-07-14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe

< MD5 for: USERINIT.EXE >
[2010-11-20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010-11-20 13:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009-07-14 02:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009-10-28 07:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009-10-28 06:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010-11-20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010-11-20 13:17:54 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009-07-14 02:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< MD5 for: WINSOCK.DLL >
[2009-07-13 22:41:34 | 000,002,864 | ---- | M] (Microsoft Corporation) MD5=68485C5EF0E2EFCEBF21BBB1042B823B -- C:\Windows\System32\WINSOCK.DLL
[2009-07-13 22:41:34 | 000,002,864 | ---- | M] (Microsoft Corporation) MD5=68485C5EF0E2EFCEBF21BBB1042B823B -- C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7600.16385_none_fde3cf3dd3e16d0d\WINSOCK.DLL
[2009-07-13 22:41:34 | 000,002,864 | ---- | M] (Microsoft Corporation) MD5=68485C5EF0E2EFCEBF21BBB1042B823B -- C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.1.7601.17514_none_0014e305d0cff0a7\WINSOCK.DLL

< >

< End of report >
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
When you try to run MSE what error do you get ?

This fix should stop the redirects, let me know if that is the case

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Posted Image
:OTL
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{978E0DE2-0143-454F-B92F-9E322E469ED9}: "URL" = http://search.condui...&ctid=CT3202918
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\Toolbar\WebBrowser: (no name) - {55D7C7BC-12A7-4F9B-81C0-600D9A182395} - No CLSID value found.
O3 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\Toolbar\WebBrowser: (no name) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000..\Run: [fnosxy] C:\Users\Bruno\AppData\Roaming\wevtapie.dll ()
[2012-10-04 00:18:58 | 083,023,306 | ---- | M] () -- C:\ProgramData\dsgsdgdsgdsgw.pad
[2012-10-03 13:49:42 | 000,118,784 | RHS- | M] () -- C:\Users\Bruno\AppData\Roaming\wevtapie.dll

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

#7
bgomes8

bgomes8

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
It doesn't appear any error, it just doesn't get started, as for the redirects it seems that is solved, now I'll run OTL and I'll get back to U pretty soon, thanks
  • 0

#8
bgomes8

bgomes8

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
It seems MSE it's already working normally now, but anyways here U have my last OTL log:

OTL logfile created on: 25-10-2012 15:36:33 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Bruno\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy

1014,43 Mb Total Physical Memory | 230,41 Mb Available Physical Memory | 22,71% Memory free
1,99 Gb Paging File | 0,72 Gb Available in Paging File | 36,27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 36,67 Gb Free Space | 49,21% Space Free | Partition Type: NTFS
Drive D: | 74,13 Gb Total Space | 69,42 Gb Free Space | 93,64% Space Free | Partition Type: NTFS

Computer Name: BRUNO-PEPE | User Name: Bruno | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012-10-24 01:11:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
PRC - [2012-09-12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Security Client\NisSrv.exe
PRC - [2012-09-12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Security Client\MsMpEng.exe
PRC - [2012-09-12 17:19:44 | 000,947,176 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Security Client\msseces.exe
PRC - [2012-08-26 22:20:10 | 000,307,856 | ---- | M] (Google Inc.) -- C:\Programas\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2012-08-24 08:34:41 | 000,748,680 | ---- | M] (Microsoft Corporation) -- C:\Programas\Internet Explorer\iexplore.exe
PRC - [2012-08-20 18:37:58 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2012-06-11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) -- C:\Programas\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2012-03-08 18:50:28 | 004,280,184 | ---- | M] (Microsoft Corporation) -- C:\Programas\Windows Live\Messenger\msnmsgr.exe
PRC - [2011-08-05 12:29:56 | 000,159,456 | ---- | M] (Microsoft Corporation) -- C:\Programas\Zune\ZuneLauncher.exe
PRC - [2011-03-28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011-03-28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011-02-25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011-02-10 10:25:42 | 001,546,720 | ---- | M] (Toshiba Europe GmbH) -- C:\Programas\Toshiba TEMPRO\TemproTray.exe
PRC - [2011-02-10 10:25:36 | 000,112,080 | ---- | M] (Toshiba Europe GmbH) -- C:\Programas\Toshiba TEMPRO\TemproSvc.exe
PRC - [2010-11-20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programas\Windows Media Player\wmpnetwk.exe
PRC - [2010-11-20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009-08-27 14:37:10 | 000,185,712 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TECO\TecoService.exe
PRC - [2009-08-26 19:00:06 | 001,324,384 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TECO\TEco.exe
PRC - [2009-08-21 10:29:40 | 000,464,224 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2009-08-21 10:29:20 | 000,476,512 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\Power Saver\TPwrMain.exe
PRC - [2009-08-13 13:31:24 | 000,521,528 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\SmoothView\SmoothView.exe
PRC - [2009-08-12 11:30:42 | 006,203,296 | ---- | M] (TOSHIBA) -- C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe
PRC - [2009-08-10 20:55:46 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
PRC - [2009-08-07 05:47:46 | 000,354,640 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosHdpProc.exe
PRC - [2009-08-06 19:36:56 | 002,680,160 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe
PRC - [2009-08-06 18:05:18 | 000,583,024 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TPHM\TPCHWMsg.exe
PRC - [2009-08-06 18:04:56 | 000,685,424 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TPHM\TPCHSrv.exe
PRC - [2009-08-06 15:02:02 | 000,029,528 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
PRC - [2009-08-06 13:06:58 | 000,466,792 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\BulletinBoard\TosNcCore.exe
PRC - [2009-08-05 15:04:54 | 000,738,616 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\FlashCards\TCrdMain.exe
PRC - [2009-08-03 18:16:50 | 001,021,272 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
PRC - [2009-08-03 18:16:32 | 000,111,960 | ---- | M] (TOSHIBA Corporation) -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
PRC - [2009-07-30 06:20:04 | 000,144,752 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe
PRC - [2009-07-28 15:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2009-07-21 04:58:52 | 002,651,512 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtProc.exe
PRC - [2009-07-08 09:40:58 | 000,518,720 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\ThpSrv.exe
PRC - [2009-07-06 19:44:22 | 000,341,320 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosOBEX.exe
PRC - [2009-07-02 11:05:00 | 000,252,288 | ---- | M] (TOSHIBA) -- C:\Programas\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
PRC - [2009-06-07 23:34:58 | 000,660,808 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe
PRC - [2009-06-03 00:33:14 | 000,308,552 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe
PRC - [2009-04-23 06:36:26 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Programas\BrOffice.org 3\program\soffice.bin
PRC - [2009-04-23 06:33:18 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Programas\BrOffice.org 3\program\soffice.exe
PRC - [2009-04-03 03:17:42 | 000,447,816 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosAVRC.exe
PRC - [2009-03-29 14:51:56 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Programas\Apoint2K\hidfind.exe
PRC - [2009-03-10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2009-02-26 15:24:50 | 000,097,680 | ---- | M] (Microsoft Corporation) -- C:\Programas\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2009-01-13 21:33:40 | 000,034,088 | ---- | M] (TOSHIBA CORPORATION) -- C:\Programas\TOSHIBA\Utilities\KeNotify.exe
PRC - [2008-07-23 20:24:24 | 000,083,272 | ---- | M] (TOSHIBA CORPORATION.) -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe


========== Modules (No Company Name) ==========

MOD - [2012-06-15 01:48:56 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6c59a14a23f734093e80d6093e25302a\Microsoft.VisualBasic.ni.dll
MOD - [2012-06-15 00:52:13 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll
MOD - [2012-06-15 00:47:42 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012-06-15 00:47:03 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012-06-15 00:46:40 | 012,237,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
MOD - [2012-05-10 11:53:20 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012-05-10 11:45:44 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012-05-10 11:45:13 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012-05-10 11:44:33 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012-05-10 11:44:14 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012-05-10 11:43:03 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2009-08-26 18:55:06 | 000,520,192 | ---- | M] () -- C:\Programas\TOSHIBA\TECO\TecoPower.dll
MOD - [2009-08-06 13:08:04 | 002,878,824 | ---- | M] () -- C:\Programas\TOSHIBA\BulletinBoard\TosNcUi.dll
MOD - [2009-08-03 18:17:24 | 000,079,192 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll
MOD - [2009-07-16 16:27:48 | 000,052,536 | ---- | M] () -- C:\Programas\TOSHIBA\FlashCards\Hotkey\FnZ.dll
MOD - [2009-07-16 16:27:44 | 007,263,544 | ---- | M] () -- C:\Programas\TOSHIBA\FlashCards\BlackPng.dll
MOD - [2009-06-22 15:38:40 | 000,015,160 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA Assist\NotifyX.dll
MOD - [2009-04-16 13:02:16 | 000,970,752 | ---- | M] () -- C:\Programas\BrOffice.org 3\program\libxml2.dll
MOD - [2009-03-12 20:08:04 | 000,049,152 | ---- | M] () -- C:\Programas\TOSHIBA\PCDiag\NotifyPCD.dll
MOD - [2006-10-07 12:57:04 | 000,053,248 | ---- | M] () -- C:\Programas\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll


========== Services (SafeList) ==========

SRV - [2012-10-09 01:48:49 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-09-12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programas\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012-09-12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programas\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012-06-11 16:22:16 | 000,240,208 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Programas\Microsoft\BingBar\7.1.391.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012-06-11 16:22:16 | 000,193,616 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Programas\Microsoft\BingBar\7.1.391.0\BBSvc.EXE -- (BBSvc)
SRV - [2012-06-07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Programas\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012-03-08 18:32:24 | 001,492,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2011-08-05 12:30:02 | 000,444,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV - [2011-08-05 12:30:02 | 000,268,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV - [2011-08-05 12:29:56 | 006,363,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2011-07-20 05:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2011-03-28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011-02-10 10:25:36 | 000,112,080 | ---- | M] (Toshiba Europe GmbH) [Auto | Running] -- C:\Programas\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService)
SRV - [2010-11-20 13:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Programas\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010-09-22 16:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Programas\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2009-08-27 14:37:10 | 000,185,712 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programas\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV - [2009-08-21 10:29:40 | 000,464,224 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Programas\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2009-08-17 11:48:42 | 000,051,512 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Programas\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2009-08-10 20:55:46 | 000,185,712 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Programas\TOSHIBA\ConfigFree\CFIWmxSvcs.exe -- (cfWiMAXService)
SRV - [2009-08-06 18:04:56 | 000,685,424 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programas\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV - [2009-08-03 18:16:32 | 000,111,960 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV - [2009-07-30 06:20:04 | 000,144,752 | ---- | M] (TOSHIBA CORPORATION) [On_Demand | Running] -- C:\Programas\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2009-07-28 15:43:04 | 000,128,344 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2009-07-14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009-07-08 09:40:58 | 000,518,720 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\ThpSrv.exe -- (Thpsrv)
SRV - [2009-03-10 19:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2007-05-31 16:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007-05-31 16:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006-10-26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programas\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RtsUCcid.sys -- (USBCCID)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\Rts516xIR.sys -- (RtsUIR)
DRV - [2012-10-25 14:40:50 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{21A4F5B1-8EA5-44FB-8D23-EEB6B3FCB1E2}\MpKsl0dc98fc5.sys -- (MpKsl0dc98fc5)
DRV - [2012-08-30 22:03:50 | 000,099,272 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012-08-23 15:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012-08-23 15:40:25 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010-11-20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2009-09-21 18:58:28 | 001,218,048 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009-08-05 15:44:44 | 000,049,400 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfusb.sys -- (Tosrfusb)
DRV - [2009-08-05 13:55:08 | 000,061,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TosRfSnd.sys -- (TosRfSnd)
DRV - [2009-07-30 21:02:34 | 000,036,208 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LPCFilter.sys -- (LPCFilter)
DRV - [2009-07-30 17:45:56 | 000,022,912 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2009-07-30 17:45:22 | 000,171,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009-07-28 21:01:26 | 000,069,480 | ---- | M] (TOSHIBA Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\tosrfcom.sys -- (Tosrfcom)
DRV - [2009-07-24 12:31:58 | 000,021,608 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfnds.sys -- (tosrfnds)
DRV - [2009-07-14 16:28:42 | 000,023,512 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV - [2009-07-13 23:13:10 | 000,015,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfec.sys -- (tosrfec)
DRV - [2009-07-07 22:38:34 | 000,168,936 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosrfbd.sys -- (tosrfbd)
DRV - [2009-06-29 16:16:22 | 000,013,120 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\Thpevm.sys -- (Thpevm)
DRV - [2009-06-29 10:25:24 | 000,030,272 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\thpdrv.sys -- (Thpdrv)
DRV - [2009-06-22 18:04:58 | 000,024,064 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PGEffect.sys -- (PGEffect)
DRV - [2009-06-19 20:31:08 | 000,012,920 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\TVALZFL.sys -- (TVALZFL)
DRV - [2009-06-19 10:57:20 | 000,079,872 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV - [2009-06-19 10:56:48 | 000,042,472 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tosrfbnp.sys -- (tosrfbnp)
DRV - [2009-06-17 12:59:46 | 000,046,984 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tosporte.sys -- (tosporte)
DRV - [2008-03-17 12:05:30 | 000,101,632 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008-02-07 01:23:46 | 000,166,448 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=TSEI&bmod=TSEI
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co...=TSEI&bmod=TSEI
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\URLSearchHook: {55d7c7bc-12a7-4f9b-81c0-600d9a182395} - No CLSID value found
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{1E99E41B-E211-406F-9952-7AAF7186A3BF}: "URL" = http://www.amazon.co...ed&linkCode=ur2
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{5D3A5735-DE55-417D-A646-16EC0CFD46ED}: "URL" = http://rover.ebay.co...e={searchTerms}
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...pt-PTPT367PT369
IE - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-10-11 23:14:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-10-11 23:14:44 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: http://search.imesh.com
CHR - Extension: No name found = C:\Users\Bruno\AppData\Local\Google\Chrome\User Data\Default\Extensions\eibdjcmcmfggjoiaaoojhicjnkghbkbe\0.1.5_1\

O1 HOSTS File: ([2012-10-25 14:12:42 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programas\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Programas\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Programas\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [00TCrdMain] C:\Programas\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KeNotify] C:\Programas\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RegTask] C:\Program Files\RegTask\RegTask.exe File not found
O4 - HKLM..\Run: [SmoothView] C:\Programas\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ThpSrv] C:\Windows\System32\thpsrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Toshiba TEMPRO] C:\Programas\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4 - HKLM..\Run: [TosNC] C:\Programas\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosReelTimeMonitor] C:\Programas\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosSENotify] C:\Programas\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosWaitSrv] C:\Programas\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Programas\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TUSBSleepChargeSrv] C:\Programas\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe (TOSHIBA)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [TOSHIBA Online Product Information] C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
O4 - HKU\S-1-5-18..\Run: [TOSHIBA Online Product Information] C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
O4 - HKU\S-1-5-21-4090958751-3629888302-3201404800-1000..\Run: [TOSHIBA Online Product Information] C:\Programas\TOSHIBA\Toshiba Online Product Information\TOPI.exe (TOSHIBA)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BrOffice.org 3.1.lnk = C:\Programas\BrOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Bruno\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Iniciação Rápida do Microsoft Office OneNote 2007.lnk = C:\Programas\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Programas\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Programas\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Programas\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Programas\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.appl...ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2....re/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{297ED7F6-3D73-40D0-A964-0D3237ED7731}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Programas\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programas\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programas\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programas\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Programas\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{62c0314a-ca3b-11df-84ba-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{62c0314a-ca3b-11df-84ba-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a776-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a776-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a79c-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a79c-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85d6a7a0-2712-11df-b1f0-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{85d6a7a0-2712-11df-b1f0-002622ed90d8}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{fe34b9e7-d69a-11df-b041-002622ed90d8}\Shell - "" = AutoRun
O33 - MountPoints2\{fe34b9e7-d69a-11df-b041-002622ed90d8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012-10-25 14:11:57 | 000,000,000 | ---D | C] -- C:\_OTL
[2012-10-25 10:03:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{3FAB2012-B934-433A-BBE4-C203B22DC849}
[2012-10-24 22:02:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{F929FC71-B0EC-45DE-928F-5E80D72E6ED4}
[2012-10-24 10:48:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012-10-24 10:47:59 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012-10-24 10:44:30 | 003,941,312 | ---- | C] (Piriform Ltd) -- C:\Users\Bruno\Desktop\ccsetup323.exe
[2012-10-24 10:02:06 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{2DE2999C-B117-4C11-9584-9FF09B998C69}
[2012-10-24 01:11:14 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
[2012-10-23 22:01:13 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{76BE6E11-2456-45B8-8DED-C33899F40C71}
[2012-10-23 12:24:26 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Roaming\Malwarebytes
[2012-10-23 12:23:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012-10-23 11:35:50 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012-10-23 09:36:17 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{79C65D2B-5AD0-4B16-AEAA-86AE3FAAB826}
[2012-10-22 20:27:49 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012-10-22 16:12:39 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{8C6CE4A5-CBAF-4B7C-A4EF-8EFC69E5903B}
[2012-10-21 13:06:06 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{5F1E1D76-E752-4411-B68F-3A81FDD70144}
[2012-10-21 00:05:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{925473B4-0B1E-4048-B272-B43B02B10E3B}
[2012-10-19 09:48:28 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{F4F8D4F7-945F-4231-AE41-B04DF03C5B86}
[2012-10-18 10:01:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{37FB29E7-ED65-49D6-AACF-7034A761A9AF}
[2012-10-17 14:15:30 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{1F5A42B9-806E-416A-BFA6-92E2325378BD}
[2012-10-16 09:15:03 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{4049AC65-3DAA-4F45-AF27-39F0D7C4EEEA}
[2012-10-15 17:34:50 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{8E8AA3D5-98D7-44D5-BD09-613C101402DA}
[2012-10-15 02:01:51 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DEB5E6C1-786A-47E7-B63F-D329906F8614}
[2012-10-13 10:18:24 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E62A536C-E875-4D8F-B9D9-4A37B47EC8CD}
[2012-10-12 01:41:29 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{2FC75F44-9B73-45EC-8C00-275625907143}
[2012-10-11 09:16:15 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{D65F8A63-8746-40D7-B79B-84365454728E}
[2012-10-10 17:48:37 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{534BBD51-BD19-4BCC-B8A0-1ECBCF25D878}
[2012-10-10 01:58:45 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{D4CA5F12-06E0-48D1-AED1-BC9E344204F6}
[2012-10-09 13:46:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{CD92EAFA-511E-4197-9613-3F9577BA59C7}
[2012-10-08 12:03:17 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{1768C40A-80D5-4767-80C1-BD2BE8DAD01D}
[2012-10-07 09:21:39 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DF54BC6F-9574-419F-8F15-5803ACCC461D}
[2012-10-06 16:40:15 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{0260AB2B-D68F-4CE6-9096-115B497D4447}
[2012-10-05 22:02:48 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Desktop\Constructor
[2012-10-05 14:47:11 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{DC823420-2871-4BB9-B7ED-D9FE2AFB2089}
[2012-10-04 16:56:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\Desktop\PM2
[2012-10-04 09:28:52 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E600E9ED-3103-4FB8-BF5B-5710090CF3B8}
[2012-10-03 14:47:25 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{7AE07EA2-84BE-4D5D-9BEB-EFB255179173}
[2012-10-03 02:46:40 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{3955745F-E8FB-4DA6-A159-3709959E3FD8}
[2012-10-01 09:40:31 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{00BCB191-FA4C-4DC2-AD5A-312A7F71E234}
[2012-09-30 10:36:09 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{B9F8A37B-457D-4C4F-AECA-343997E4E8D2}
[2012-09-29 19:03:00 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{3E3AE1E8-F03E-4923-A93E-C5B579315C0B}
[2012-09-26 09:41:44 | 000,000,000 | ---D | C] -- C:\Users\Bruno\AppData\Local\{E37BE0FB-75FB-4A93-918F-660116EF1BC7}

========== Files - Modified Within 30 Days ==========

[2012-10-25 15:21:06 | 000,001,000 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-10-25 15:18:05 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012-10-25 14:27:44 | 000,014,304 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-10-25 14:27:44 | 000,014,304 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-10-25 14:19:04 | 000,000,996 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-10-25 14:18:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012-10-25 14:18:25 | 797,777,920 | -HS- | M] () -- C:\hiberfil.sys
[2012-10-25 14:12:42 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2012-10-24 18:15:00 | 000,538,941 | ---- | M] () -- C:\Users\Bruno\Desktop\adwcleaner.exe
[2012-10-24 10:48:10 | 000,000,976 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-24 01:11:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bruno\Desktop\OTL.exe
[2012-10-23 11:36:21 | 000,001,912 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012-10-22 10:30:01 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\RegTask.job
[2012-10-14 01:51:52 | 000,082,250 | ---- | M] () -- C:\Users\Bruno\Desktop\Publicitação_Recrutamento_TS_RefªA_Erasmus_1.sflb.pdf
[2012-10-10 18:31:48 | 000,002,331 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012-10-04 16:36:25 | 003,092,694 | ---- | M] () -- C:\Users\Bruno\Desktop\pmanager2.rar
[2012-10-04 16:35:22 | 002,316,579 | ---- | M] () -- C:\Users\Bruno\Desktop\premierm3.rar
[2012-10-02 09:47:18 | 000,679,342 | ---- | M] () -- C:\Windows\System32\prfh0816.dat
[2012-10-02 09:47:18 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012-10-02 09:47:18 | 000,133,752 | ---- | M] () -- C:\Windows\System32\prfc0816.dat
[2012-10-02 09:47:18 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat

========== Files Created - No Company Name ==========

[2012-10-24 18:14:34 | 000,538,941 | ---- | C] () -- C:\Users\Bruno\Desktop\adwcleaner.exe
[2012-10-24 10:48:09 | 000,000,976 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012-10-23 11:36:12 | 000,002,124 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012-10-14 01:51:49 | 000,082,250 | ---- | C] () -- C:\Users\Bruno\Desktop\Publicitação_Recrutamento_TS_RefªA_Erasmus_1.sflb.pdf
[2012-10-04 16:36:17 | 003,092,694 | ---- | C] () -- C:\Users\Bruno\Desktop\pmanager2.rar
[2012-10-04 16:35:20 | 002,316,579 | ---- | C] () -- C:\Users\Bruno\Desktop\premierm3.rar
[2010-08-14 00:41:29 | 000,776,408 | ---- | C] () -- C:\Users\Bruno\iqgf2x.jpg
[2010-08-14 00:41:29 | 000,102,326 | ---- | C] () -- C:\Users\Bruno\32zjtqo.jpg
[2010-08-14 00:41:29 | 000,063,155 | ---- | C] () -- C:\Users\Bruno\mcat1_122_850lo.jpg
[2010-08-14 00:41:29 | 000,037,163 | ---- | C] () -- C:\Users\Bruno\dcqzk7.jpg
[2010-08-14 00:41:29 | 000,029,777 | ---- | C] () -- C:\Users\Bruno\dpzpco.jpg
[2010-08-14 00:41:29 | 000,018,785 | ---- | C] () -- C:\Users\Bruno\2214706410_0591a1bfcb.jpg
[2010-08-14 00:41:29 | 000,016,050 | ---- | C] () -- C:\Users\Bruno\25i3y4z.jpg
[2010-08-14 00:41:29 | 000,010,818 | ---- | C] () -- C:\Users\Bruno\46305_27361_59a719c363_p.jpg
[2010-02-21 16:59:49 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat

========== ZeroAccess Check ==========

[2009-07-14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012-10-24 11:06:31 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Azureus
[2010-10-25 23:30:34 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\BrOffice.org
[2012-02-19 21:25:07 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\MusicNet
[2010-03-08 00:33:10 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Toshiba
[2012-03-23 01:48:53 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\WinBatch
[2010-12-08 13:24:34 | 000,000,000 | ---D | M] -- C:\Users\Bruno\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



< End of report >


So tell me if I need to do anything else, since as I've said it all seems that now everything is working properly ... Thanks a lot
  • 0

#9
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
I believe that MSE was blocked by the file that I removed

Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

Posted Image Your Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:
  • Go to this site and click Do I have Java
  • It will check your current version and then offer to update to the latest version


Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Posted Image Malwarebytes.

Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?Keep safe :wave:
  • 0

#10
bgomes8

bgomes8

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Thanks a lot :))... I'll go through all these steps, and I'll try to keep my notebook safe ;)
  • 0

#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP