Hey guys, just created the account to solve this possible problem... Today i've downloaded Assassins Creed III, and in the folder had a file which i tried to open and then showed up a message saying like the "Disk A: isn't availabe, could not access explorer.exe". After that, i've restarted the computer and ANYTHING was opening, any shortcut, nothing.
Kaspersky then detected a malware in "C:\Users\<username>\Drivers\explorer.exe". After that, kaspersky deleted all the threats and a full scan on reboot. Seems like the threat is gone, but the internet connection is clearly lagged. Something like 1000ms on Speedtest.
And too, one time the Origin disconnected me, warning me that "this account is in use by another computer". Crazy, but at least suspicious.
The name on Kaspersky is: UDS:DangerousObject.Multi.Generic
Thanks since now!
Here is the log from OTL:
Spoiler
OTL logfile created on: 20/11/2012 19:32:31 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = E:\Downloads\Programs
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
4,00 Gb Total Physical Memory | 1,28 Gb Available Physical Memory | 32,12% Memory free
8,00 Gb Paging File | 4,46 Gb Available in Paging File | 55,82% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 121,81 Gb Total Space | 68,80 Gb Free Space | 56,48% Space Free | Partition Type: NTFS
Drive D: | 74,43 Gb Total Space | 51,18 Gb Free Space | 68,77% Space Free | Partition Type: NTFS
Drive E: | 576,72 Gb Total Space | 157,94 Gb Free Space | 27,39% Space Free | Partition Type: NTFS
Drive F: | 55,87 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: RAFINHA-PC | User Name: Rafinha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/11/20 19:00:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\Downloads\Programs\OTL.exe
PRC - [2012/11/20 06:43:41 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/11/14 12:32:25 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
PRC - [2012/10/30 04:11:14 | 000,166,968 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe
PRC - [2012/10/30 04:11:12 | 000,408,632 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
PRC - [2012/10/29 06:58:16 | 003,389,080 | ---- | M] (Electronic Arts) -- C:\Program Files (x86)\Origin\Origin.exe
PRC - [2012/10/13 14:59:40 | 000,698,240 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\Monitor.exe
PRC - [2012/10/12 15:33:10 | 001,026,432 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe
PRC - [2012/10/06 20:37:22 | 002,059,904 | ---- | M] (John Mautari aka japamd) -- C:\Program Files (x86)\RadeonPro\RadeonPro.exe
PRC - [2012/10/06 20:37:22 | 000,020,608 | ---- | M] (Mr. John aka japamd) -- C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe
PRC - [2012/08/31 23:06:18 | 003,528,128 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2012/08/31 22:00:18 | 000,896,912 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012/08/17 22:38:34 | 000,128,440 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe
PRC - [2012/07/27 18:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/04/26 10:33:16 | 002,743,104 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2012/04/11 14:33:50 | 000,336,896 | ---- | M] (Markus Gehlhaar) -- C:\Program Files (x86)\Media Center Control\MCC Service.exe
PRC - [2012/03/26 15:05:04 | 004,656,632 | ---- | M] (Almico Software (www.almico.com)) -- C:\Program Files (x86)\SpeedFan\speedfan.exe
PRC - [2011/12/09 15:23:30 | 001,596,032 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winamp.exe
========== Modules (No Company Name) ==========
MOD - [2012/11/20 19:12:26 | 000,206,336 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\winamp.lng
MOD - [2012/11/20 19:12:26 | 000,149,504 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\vis_milk2.lng
MOD - [2012/11/20 19:12:26 | 000,085,504 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\vis_avs.lng
MOD - [2012/11/20 19:12:26 | 000,042,496 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_wifi.lng
MOD - [2012/11/20 19:12:26 | 000,036,864 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_ipod.lng
MOD - [2012/11/20 19:12:26 | 000,036,352 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ombrowser.lng
MOD - [2012/11/20 19:12:26 | 000,019,456 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_android.lng
MOD - [2012/11/20 19:12:26 | 000,016,384 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\out_ds.lng
MOD - [2012/11/20 19:12:26 | 000,013,824 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_usb.lng
MOD - [2012/11/20 19:12:26 | 000,013,824 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_wire.lng
MOD - [2012/11/20 19:12:26 | 000,007,680 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\vis_nsfs.lng
MOD - [2012/11/20 19:12:26 | 000,007,680 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_transcode.lng
MOD - [2012/11/20 19:12:26 | 000,007,168 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\out_wave.lng
MOD - [2012/11/20 19:12:26 | 000,006,144 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\tagz.lng
MOD - [2012/11/20 19:12:26 | 000,006,144 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\out_disk.lng
MOD - [2012/11/20 19:12:26 | 000,004,608 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_activesync.lng
MOD - [2012/11/20 19:12:26 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\winampa.lng
MOD - [2012/11/20 19:12:26 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_p4s.lng
MOD - [2012/11/20 19:12:26 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_njb.lng
MOD - [2012/11/20 19:12:26 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\playlist.lng
MOD - [2012/11/20 19:12:25 | 000,052,224 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_local.lng
MOD - [2012/11/20 19:12:25 | 000,044,032 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_pmp.lng
MOD - [2012/11/20 19:12:25 | 000,043,008 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_disc.lng
MOD - [2012/11/20 19:12:25 | 000,037,376 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_jumpex.lng
MOD - [2012/11/20 19:12:25 | 000,022,016 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_mp3.lng
MOD - [2012/11/20 19:12:25 | 000,020,992 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_ml.lng
MOD - [2012/11/20 19:12:25 | 000,019,968 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_midi.lng
MOD - [2012/11/20 19:12:25 | 000,018,432 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_mod.lng
MOD - [2012/11/20 19:12:25 | 000,014,336 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_wm.lng
MOD - [2012/11/20 19:12:25 | 000,013,824 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_online.lng
MOD - [2012/11/20 19:12:25 | 000,012,800 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_playlists.lng
MOD - [2012/11/20 19:12:25 | 000,012,800 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_cdda.lng
MOD - [2012/11/20 19:12:25 | 000,012,288 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_plg.lng
MOD - [2012/11/20 19:12:25 | 000,011,264 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_vorbis.lng
MOD - [2012/11/20 19:12:25 | 000,011,264 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_nsv.lng
MOD - [2012/11/20 19:12:25 | 000,010,752 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_skinmanager.lng
MOD - [2012/11/20 19:12:25 | 000,010,240 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_undo.lng
MOD - [2012/11/20 19:12:25 | 000,010,240 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_hotkeys.lng
MOD - [2012/11/20 19:12:25 | 000,009,216 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_timerestore.lng
MOD - [2012/11/20 19:12:25 | 000,009,216 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_nopro.lng
MOD - [2012/11/20 19:12:25 | 000,008,704 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_history.lng
MOD - [2012/11/20 19:12:25 | 000,008,704 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_downloads.lng
MOD - [2012/11/20 19:12:25 | 000,008,704 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_devices.lng
MOD - [2012/11/20 19:12:25 | 000,007,680 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_tray.lng
MOD - [2012/11/20 19:12:25 | 000,007,168 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_dshow.lng
MOD - [2012/11/20 19:12:25 | 000,007,168 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_orgler.lng
MOD - [2012/11/20 19:12:25 | 000,006,656 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_autotag.lng
MOD - [2012/11/20 19:12:25 | 000,006,656 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_wav.lng
MOD - [2012/11/20 19:12:25 | 000,006,144 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_flac.lng
MOD - [2012/11/20 19:12:25 | 000,005,632 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_wave.lng
MOD - [2012/11/20 19:12:25 | 000,005,120 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_rg.lng
MOD - [2012/11/20 19:12:25 | 000,005,120 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_impex.lng
MOD - [2012/11/20 19:12:25 | 000,005,120 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_bookmarks.lng
MOD - [2012/11/20 19:12:25 | 000,005,120 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_avi.lng
MOD - [2012/11/20 19:12:25 | 000,004,608 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_enqplay.lng
MOD - [2012/11/20 19:12:25 | 000,004,608 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_mp4.lng
MOD - [2012/11/20 19:12:25 | 000,004,608 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_mkv.lng
MOD - [2012/11/20 19:12:25 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_wv.lng
MOD - [2012/11/20 19:12:25 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_nowplaying.lng
MOD - [2012/11/20 19:12:25 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_addons.lng
MOD - [2012/11/20 19:12:25 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_swf.lng
MOD - [2012/11/20 19:12:25 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_linein.lng
MOD - [2012/11/20 19:12:25 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_flv.lng
MOD - [2012/11/20 19:12:24 | 000,062,976 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\burnlib.lng
MOD - [2012/11/20 19:12:24 | 000,021,504 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_ff.lng
MOD - [2012/11/20 19:12:24 | 000,013,824 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\dsp_sps.lng
MOD - [2012/11/20 19:12:24 | 000,010,752 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\auth.lng
MOD - [2012/11/20 19:12:24 | 000,010,240 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_classicart.lng
MOD - [2012/11/20 19:12:24 | 000,009,728 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_aacplus.lng
MOD - [2012/11/20 19:12:24 | 000,007,168 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_crasher.lng
MOD - [2012/11/20 19:12:24 | 000,006,656 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_fhgaac.lng
MOD - [2012/11/20 19:12:24 | 000,006,144 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_wma.lng
MOD - [2012/11/20 19:12:24 | 000,005,632 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_lame.lng
MOD - [2012/11/20 19:12:24 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_find_on_disk.lng
MOD - [2012/11/20 19:12:24 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_wav.lng
MOD - [2012/11/20 19:12:24 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_vorbis.lng
MOD - [2012/11/20 19:12:24 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_flac.lng
MOD - [2012/11/20 15:23:11 | 000,192,512 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\sfamcc00001.dll
MOD - [2012/11/20 15:23:11 | 000,158,720 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\sfareca00001.dll
MOD - [2012/11/14 13:52:27 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\66694f9192bd0dddc2eaf90fbcbcd555\System.Management.ni.dll
MOD - [2012/11/14 12:22:41 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\17796f2951c17ebf92dd4b7c9b3ce556\System.ServiceProcess.ni.dll
MOD - [2012/11/14 12:22:33 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll
MOD - [2012/11/14 12:22:28 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll
MOD - [2012/11/14 12:22:08 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll
MOD - [2012/11/14 12:22:03 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll
MOD - [2012/11/14 12:22:02 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\70705382a499703e7a595fada80b04e6\Accessibility.ni.dll
MOD - [2012/11/14 12:21:53 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\b311b783e1efaa9527f4c2c9680c44d1\WindowsBase.ni.dll
MOD - [2012/11/14 12:21:48 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll
MOD - [2012/11/14 12:21:45 | 007,988,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll
MOD - [2012/11/14 12:21:40 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll
MOD - [2012/10/31 20:15:05 | 000,460,312 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
MOD - [2012/10/31 20:15:04 | 012,455,448 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\PepperFlash\pepflashplayer.dll
MOD - [2012/10/31 20:15:02 | 004,007,448 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\pdf.dll
MOD - [2012/10/31 20:13:47 | 000,587,288 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\libglesv2.dll
MOD - [2012/10/31 20:13:46 | 000,123,928 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\libegl.dll
MOD - [2012/10/31 20:13:35 | 000,156,712 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\avutil-51.dll
MOD - [2012/10/31 20:13:34 | 000,274,984 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\avformat-54.dll
MOD - [2012/10/31 20:13:32 | 002,168,360 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\avcodec-54.dll
MOD - [2012/10/30 04:11:14 | 000,166,968 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe
MOD - [2012/10/30 04:11:12 | 000,408,632 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
MOD - [2012/10/06 20:37:24 | 001,136,256 | ---- | M] () -- C:\Program Files (x86)\RadeonPro\V8.Net.dll
MOD - [2012/09/03 13:59:53 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\xml.w5s
MOD - [2012/09/03 13:59:53 | 000,083,968 | ---- | M] () -- C:\Program Files (x86)\Winamp\tataki.dll
MOD - [2012/09/03 13:59:53 | 000,047,616 | ---- | M] () -- C:\Program Files (x86)\Winamp\zlib.dll
MOD - [2012/09/03 13:59:53 | 000,035,328 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\timer.w5s
MOD - [2012/09/03 13:59:53 | 000,021,504 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\tagz.w5s
MOD - [2012/09/03 13:59:52 | 001,737,728 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_ff.dll
MOD - [2012/09/03 13:59:52 | 000,623,616 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\jnetlib.w5s
MOD - [2012/09/03 13:59:52 | 000,417,280 | ---- | M] () -- C:\Program Files (x86)\Winamp\nsutil.dll
MOD - [2012/09/03 13:59:52 | 000,340,992 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\freeform\wacs\freetype\freetype.wac
MOD - [2012/09/03 13:59:52 | 000,318,464 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_ml.dll
MOD - [2012/09/03 13:59:52 | 000,313,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_wm.dll
MOD - [2012/09/03 13:59:52 | 000,294,400 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_local.dll
MOD - [2012/09/03 13:59:52 | 000,290,304 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mp3.dll
MOD - [2012/09/03 13:59:52 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\libsndfile.dll
MOD - [2012/09/03 13:59:52 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_vorbis.dll
MOD - [2012/09/03 13:59:52 | 000,249,856 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_devices.dll
MOD - [2012/09/03 13:59:52 | 000,241,152 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_pmp.dll
MOD - [2012/09/03 13:59:52 | 000,200,192 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_disc.dll
MOD - [2012/09/03 13:59:52 | 000,185,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_jumpex.dll
MOD - [2012/09/03 13:59:52 | 000,174,080 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\auth.w5s
MOD - [2012/09/03 13:59:52 | 000,170,496 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_ipod.dll
MOD - [2012/09/03 13:59:52 | 000,165,376 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mod.dll
MOD - [2012/09/03 13:59:52 | 000,154,624 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\jpeg.w5s
MOD - [2012/09/03 13:59:52 | 000,124,928 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_online.dll
MOD - [2012/09/03 13:59:52 | 000,118,272 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_p4s.dll
MOD - [2012/09/03 13:59:52 | 000,113,664 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_wifi.dll
MOD - [2012/09/03 13:59:52 | 000,109,568 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_midi.dll
MOD - [2012/09/03 13:59:52 | 000,103,936 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\png.w5s
MOD - [2012/09/03 13:59:52 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_cdda.dll
MOD - [2012/09/03 13:59:52 | 000,084,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\playlist.w5s
MOD - [2012/09/03 13:59:52 | 000,083,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_plg.dll
MOD - [2012/09/03 13:59:52 | 000,082,944 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_playlists.dll
MOD - [2012/09/03 13:59:52 | 000,078,848 | ---- | M] () -- C:\Program Files (x86)\Winamp\nde.dll
MOD - [2012/09/03 13:59:52 | 000,075,264 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_nsv.dll
MOD - [2012/09/03 13:59:52 | 000,072,192 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_dshow.dll
MOD - [2012/09/03 13:59:52 | 000,068,608 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_avi.dll
MOD - [2012/09/03 13:59:52 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_flac.dll
MOD - [2012/09/03 13:59:52 | 000,060,928 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_android.dll
MOD - [2012/09/03 13:59:52 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_impex.dll
MOD - [2012/09/03 13:59:52 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_orgler.dll
MOD - [2012/09/03 13:59:52 | 000,053,760 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_usb.dll
MOD - [2012/09/03 13:59:52 | 000,052,736 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mp4.dll
MOD - [2012/09/03 13:59:52 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_ds.dll
MOD - [2012/09/03 13:59:52 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_history.dll
MOD - [2012/09/03 13:59:52 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mkv.dll
MOD - [2012/09/03 13:59:52 | 000,044,544 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\devices.w5s
MOD - [2012/09/03 13:59:52 | 000,043,008 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_flv.dll
MOD - [2012/09/03 13:59:52 | 000,033,792 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_rg.dll
MOD - [2012/09/03 13:59:52 | 000,032,256 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_transcode.dll
MOD - [2012/09/03 13:59:52 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_autotag.dll
MOD - [2012/09/03 13:59:52 | 000,028,160 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_bookmarks.dll
MOD - [2012/09/03 13:59:52 | 000,027,648 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_hotkeys.dll
MOD - [2012/09/03 13:59:52 | 000,025,600 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_tray.dll
MOD - [2012/09/03 13:59:52 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_swf.dll
MOD - [2012/09/03 13:59:52 | 000,023,040 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\albumart.w5s
MOD - [2012/09/03 13:59:52 | 000,022,528 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_disk.dll
MOD - [2012/09/03 13:59:52 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_njb.dll
MOD - [2012/09/03 13:59:52 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\gif.w5s
MOD - [2012/09/03 13:59:52 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\bmp.w5s
MOD - [2012/09/03 13:59:52 | 000,018,432 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_wave.dll
MOD - [2012/09/03 13:59:52 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_wave.dll
MOD - [2012/09/03 13:59:52 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\dlmgr.w5s
MOD - [2012/09/03 13:59:52 | 000,016,384 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\gracenote.w5s
MOD - [2012/09/03 13:59:52 | 000,014,336 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\filereader.w5s
MOD - [2012/09/03 13:59:52 | 000,013,824 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\primo.w5s
MOD - [2012/09/03 13:59:52 | 000,007,168 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_linein.dll
MOD - [2012/09/01 00:05:47 | 000,109,568 | ---- | M] () -- C:\Program Files (x86)\DAEMON Tools Pro\BRD.dll
MOD - [2012/08/17 22:38:56 | 000,479,160 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll
MOD - [2012/07/21 04:44:58 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
MOD - [2012/07/21 04:44:54 | 000,335,872 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
MOD - [2012/07/21 04:44:38 | 000,225,280 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTCore.dll
MOD - [2012/07/21 04:44:30 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTUI.dll
MOD - [2012/07/21 04:44:22 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTFC.dll
MOD - [2012/06/04 14:23:18 | 000,122,880 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSSHooks.dll
MOD - [2012/06/04 13:03:40 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTMUI.dll
MOD - [2012/06/04 13:02:42 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTUI.dll
MOD - [2012/06/04 13:02:34 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTFC.dll
MOD - [2011/04/30 13:04:54 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTTSH.dll
MOD - [2011/04/30 13:04:54 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTTSH.dll
MOD - [2011/03/17 01:11:16 | 004,297,568 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
MOD - [2010/11/12 22:33:11 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010/11/12 21:35:10 | 000,417,792 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_pt-BR_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2009/09/15 18:20:50 | 000,177,152 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\madBasic_.bpl
MOD - [2009/09/15 18:20:50 | 000,044,544 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\madDisAsm_.bpl
MOD - [2009/09/15 18:20:46 | 000,342,528 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\madExcept_.bpl
MOD - [2009/07/10 10:07:18 | 000,166,912 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL
MOD - [2009/02/06 19:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL
========== Services (SafeList) ==========
SRV:64bit: - [2012/09/27 23:38:16 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/13 23:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 23:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/11/20 06:43:41 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/11/14 12:32:25 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe -- (AVP)
SRV - [2012/11/14 12:20:10 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/10/25 12:21:08 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/10/19 16:14:08 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/10/12 15:33:10 | 001,026,432 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe -- (AdvancedSystemCareService6)
SRV - [2012/10/06 20:37:22 | 000,020,608 | ---- | M] (Mr. John aka japamd) [Auto | Running] -- C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe -- (RadeonPro Support Service)
SRV - [2012/09/03 18:11:07 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2012/08/31 22:35:58 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2012/07/27 18:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/19 19:08:04 | 000,738,152 | ---- | M] (Tunngle.net GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2012/04/11 14:33:50 | 000,336,896 | ---- | M] (Markus Gehlhaar) [Auto | Running] -- C:\Program Files (x86)\Media Center Control\MCC Service.exe -- (MediaCenterControl)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 19:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/11/14 12:35:53 | 000,054,104 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kltdi.sys -- (kltdi)
DRV:64bit: - [2012/11/14 12:32:46 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klmouflt.sys -- (klmouflt)
DRV:64bit: - [2012/11/14 12:32:43 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klkbdflt.sys -- (klkbdflt)
DRV:64bit: - [2012/11/14 12:32:39 | 000,613,720 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\SysNative\drivers\klif.sys -- (KLIF)
DRV:64bit: - [2012/09/28 00:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/09/27 23:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/09/06 16:08:29 | 000,121,416 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV:64bit: - [2012/09/01 00:05:23 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012/08/13 17:49:40 | 000,178,008 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kneps.sys -- (kneps)
DRV:64bit: - [2012/08/02 16:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\klim6.sys -- (KLIM6)
DRV:64bit: - [2012/08/02 06:53:14 | 000,158,944 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP)
DRV:64bit: - [2012/07/31 15:23:02 | 000,070,016 | ---- | M] (Identive) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\S3XXx64.sys -- (S3XXx64)
DRV:64bit: - [2012/07/13 14:02:14 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/07/13 13:39:51 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2012/07/13 13:39:51 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2012/06/19 18:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\kl1.sys -- (kl1)
DRV:64bit: - [2012/05/14 04:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/07/29 14:54:56 | 000,016,776 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\epmntdrv.sys -- (epmntdrv)
DRV:64bit: - [2011/07/29 14:54:56 | 000,009,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\EuGdiDrv.sys -- (EuGdiDrv)
DRV:64bit: - [2010/11/26 18:02:18 | 000,017,720 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV:64bit: - [2010/11/21 01:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/21 01:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 01:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2010/11/21 01:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2010/11/21 01:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/21 01:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2010/11/21 01:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 01:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/08/19 20:24:34 | 000,074,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2010/03/04 19:26:58 | 000,349,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)
DRV:64bit: - [2010/01/27 00:09:02 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:64bit: - [2009/12/30 12:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:64bit: - [2009/10/16 07:44:56 | 001,309,696 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\P17.sys -- (P17)
DRV:64bit: - [2009/09/16 09:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t)
DRV:64bit: - [2009/07/16 12:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009/07/13 23:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 23:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 23:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 18:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 18:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 18:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 18:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 18:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/04/29 17:28:30 | 000,030,208 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2012/10/30 04:11:10 | 000,013,368 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64)
DRV - [2012/09/03 12:03:39 | 000,162,432 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysWOW64\drivers\ithsgt.sys -- (ithsgt)
DRV - [2012/09/03 12:03:39 | 000,012,032 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysWOW64\drivers\lilsgt.sys -- (lilsgt)
DRV - [2011/07/29 14:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\epmntdrv.sys -- (epmntdrv)
DRV - [2011/07/29 14:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2009/07/13 23:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2008/07/26 23:30:36 | 000,014,544 | ---- | M] (OpenLibSys.org) [Kernel | On_Demand | Stopped] -- E:\Documentos\RealTemp\WinRing0x64.sys -- (WinRing0_1_2_0)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://br.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-BR
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 70 89 F9 8F 69 8F CD 01 [binary data]
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...00000ffe0185b82
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.babylo...0000ffb5e5e61e"
FF - prefs.js..extensions.enabledAddons: [email protected]:7.3.19
FF - prefs.js..extensions.enabledAddons: [email protected]:1.2.9.2
FF - prefs.js..extensions.enabledAddons: {87F8774F-B485-47E2-A755-A40A8A5E8874}:2.12.1.1.140
FF - prefs.js..keyword.URL: "http://search.babylo...0ffb5e5e61e&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Rafinha\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Rafinha\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Rafinha\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: C:\Users\Rafinha\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012/09/01 00:29:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012/09/01 00:29:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012/09/01 00:29:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012/09/01 00:29:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012/09/01 00:29:31 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[email protected]: C:\Users\Rafinha\AppData\Roaming\IDM\idmmzcc5 [2012/08/31 22:58:25 | 000,000,000 | ---D | M]
[2012/04/22 20:00:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\Extensions
[2012/09/23 14:31:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\Firefox\Profiles\gk0fxyf8.default\extensions
[2012/08/31 22:10:23 | 000,000,000 | ---D | M] (Modulo de Protecao) -- C:\Users\Rafinha\AppData\Roaming\mozilla\Firefox\Profiles\gk0fxyf8.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E8874}
[2012/11/20 13:54:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\Firefox\Profiles\gk0fxyf8.default\extensions\[email protected]
[2012/08/31 22:10:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\Firefox\Profiles\gk0fxyf8.default\extensions\trash
[2012/07/27 02:53:51 | 000,127,820 | ---- | M] () (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\firefox\profiles\gk0fxyf8.default\extensions\[email protected]
[2012/07/25 01:32:26 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\firefox\profiles\gk0fxyf8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
File not found (No name found) -- C:\USERS\RAFA\APPDATA\ROAMING\IDM\IDMMZCC5
File not found (No name found) -- C:\USERS\RAFA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GK0FXYF8.DEFAULT\EXTENSIONS\{87F8774F-B485-47E2-A755-A40A8A5E8874}
File not found (No name found) -- C:\USERS\RAFA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GK0FXYF8.DEFAULT\EXTENSIONS\[email protected]
========== Chrome ==========
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = http://www.google.co...q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Rafinha\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: Angry Birds = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: Gotas de chuva = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcipapbfhdnmgihoimbjiadmhpcgcnil\1.0.0.2_0\
CHR - Extension: Audiotool = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk\1.1_0\
CHR - Extension: YouTube = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Pesquisa do Google = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0\
CHR - Extension: Street Sesh = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\diibpgacpeaofpflklajpgmkokfkglpb\1.0_0\
CHR - Extension: The Godfather: Five Families = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\edfkoljdeffeedleidebkmmamepgbnbl\1.0_0\
CHR - Extension: Google Agenda = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0\
CHR - Extension: Stylish = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\0.10_0\
CHR - Extension: AdBlock = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.47_0\
CHR - Extension: Safe Money = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0\
CHR - Extension: JustTV - TV pela internet = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbkjhaehebpcjnaipcemkhdnfibifkpl\0.0.0.4_0\
CHR - Extension: FB unseen = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcedcpmfdpjijiamkaeaefgfagnnpei\0.1.3_0\
CHR - Extension: Desprotetor de Links = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\imcbnnnoghiihopefblgehihofbfbmei\1.2.11_0\
CHR - Extension: Virtual Keyboard = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4190_0\
CHR - Extension: Blackball Pool = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjkhefodfbgjpcmahghmfggbcpjabnag\1.0.3_0\
CHR - Extension: Endere\u00E7o IP = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcijdkkommbhnpohidhdpkhendgcpamf\0.4_0\
CHR - Extension: Autodesk Homestyler = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb\2.2_0\
CHR - Extension: Lose The Heat 2 = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\knlpidedajllknkcbnogiahlclkkflne\3.3_0\
CHR - Extension: Evernote Web = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0\
CHR - Extension: Currently = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhmphdkpgbibohbnpbfiefkgieacjmh\2.2.1_0\
CHR - Extension: REC - Rastreamento de Encomendas dos Correios = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\omhclojepaohhgmelpgpnbekblifihoh\0.3_0\
CHR - Extension: Gmail = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Anti-Banner = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0\
O1 HOSTS File: ([2009/06/10 19:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O4:64bit: - HKLM..\Run: [NVRaidService] C:\Program Files\NVIDIA Corporation\Raid\nvraidservice.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [P17RunE] C:\Windows\SysWow64\P17RunE.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1186146817-16379212-3669418587-1001..\Run: [Advanced SystemCare 6] C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe (IObit)
O4 - HKU\S-1-5-21-1186146817-16379212-3669418587-1001..\Run: [DS3 Tool] C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe (www.motioninjoy.com)
O4 - HKU\S-1-5-21-1186146817-16379212-3669418587-1001..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm ()
O8:64bit: - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Fazer o download usando o IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm ()
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Fazer o download usando o IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 189.7.144.15 189.7.144.16
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{10CAD571-CB29-4445-8633-CBCCE21B2B24}: DhcpNameServer = 189.7.144.15 189.7.144.16
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0185B82-2002-4E79-B2BA-0511FC03CAFA}: DhcpNameServer = 7.254.254.254
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/06/27 15:22:13 | 000,000,044 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{61e3115d-f3cf-11e1-ba9a-0004acf75961}\Shell - "" = AutoRun
O33 - MountPoints2\{61e3115d-f3cf-11e1-ba9a-0004acf75961}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{81a2f92c-f3c2-11e1-9f3d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{81a2f92c-f3c2-11e1-9f3d-806e6f6e6963}\Shell\AutoRun\command - "" = F:\CARROSSEL.exe -- [2012/06/27 15:22:10 | 003,289,961 | R--- | M] (Adobe Systems, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (SmartDefragBootTime.exe)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/11/20 14:07:20 | 000,000,000 | ---D | C] -- C:\Windows\tasks\TaskDisabled
[2012/11/20 13:35:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/11/20 13:35:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012/11/20 13:35:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012/11/20 13:05:54 | 000,000,000 | ---D | C] -- E:\DOCUMENTOS\Assassin's Creed III
[2012/11/20 13:03:40 | 000,000,000 | -HSD | C] -- C:\Users\Rafinha\Drivers
[2012/11/20 06:43:37 | 000,000,000 | ---D | C] -- C:\Users\Rafinha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
[2012/11/20 06:43:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ubisoft
[2012/11/18 20:39:54 | 000,000,000 | ---D | C] -- C:\ProgramData\MCC_Service
[2012/11/18 20:39:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Media Center Control
[2012/11/17 14:14:14 | 000,025,472 | ---- | C] (IObit) -- C:\Windows\SysNative\RegistryDefragBootTime.exe
[2012/11/17 04:03:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2013
[2012/11/17 03:09:29 | 000,032,600 | ---- | C] (IObit) -- C:\Windows\SysNative\SmartDefragBootTime.exe
[2012/11/17 03:08:01 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2012/11/17 03:08:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 6
[2012/11/17 03:07:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit
[2012/11/14 06:58:49 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys
[2012/11/14 06:58:49 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wdfres.dll
[2012/11/14 06:54:48 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/11/14 06:54:48 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/11/14 06:54:47 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/11/14 06:54:47 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/11/14 06:54:47 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/11/14 06:54:47 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/11/14 06:54:47 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/11/14 06:54:47 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/11/14 06:54:46 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/11/14 06:54:46 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/11/14 06:54:46 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/11/14 06:54:46 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012/11/14 06:54:45 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/11/14 06:54:45 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/11/14 06:54:45 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2012/11/14 06:53:02 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFPlatform.dll
[2012/11/14 06:53:01 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFx.dll
[2012/11/14 06:53:01 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFHost.exe
[2012/11/14 06:53:01 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFCoinstaller.dll
[2012/11/14 04:07:07 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcore6.dll
[2012/11/14 04:07:07 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcore6.dll
[2012/11/14 04:07:07 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcsvc6.dll
[2012/11/14 04:07:04 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcorehc.dll
[2012/11/14 04:07:04 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncsi.dll
[2012/11/14 04:07:04 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcorehc.dll
[2012/11/14 04:07:04 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
[2012/11/14 04:07:04 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll
[2012/11/14 04:07:04 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netevent.dll
[2012/11/14 04:06:56 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\synceng.dll
[2012/11/14 04:06:56 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\synceng.dll
[2012/11/11 02:14:11 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012/11/11 02:14:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2012/11/11 02:13:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012/11/11 02:13:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2012/11/11 02:13:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2012/11/11 02:13:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012/11/11 02:11:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2012/11/11 02:10:58 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2012/11/09 23:01:43 | 000,000,000 | ---D | C] -- C:\Users\Rafinha\Desktop\musicas treino
[2012/11/08 21:42:00 | 000,000,000 | ---D | C] -- C:\Users\Rafinha\AppData\Roaming\Skype
[2012/11/08 21:41:51 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2012/11/08 21:41:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/11/08 21:41:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012/11/08 21:41:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012/11/01 12:46:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/11/01 12:46:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2012/11/01 12:43:20 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2012/10/29 10:28:25 | 000,000,000 | ---D | C] -- C:\Users\Rafinha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/10/29 10:28:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/10/29 07:53:58 | 000,000,000 | ---D | C] -- E:\DOCUMENTOS\MOHW
[2012/10/22 02:35:46 | 000,000,000 | ---D | C] -- C:\Users\Rafinha\Desktop\churras turma funk
[1 C:\Users\Rafinha\*.tmp files -> C:\Users\Rafinha\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/11/20 18:53:01 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/20 15:23:41 | 001,636,212 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/20 15:23:41 | 000,706,312 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat
[2012/11/20 15:23:41 | 000,654,880 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/11/20 15:23:41 | 000,147,038 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat
[2012/11/20 15:23:41 | 000,121,752 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/11/20 15:17:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/20 15:17:22 | 3220,086,784 | -HS- | M] () -- C:\hiberfil.sys
[2012/11/20 13:35:35 | 000,001,282 | ---- | M] () -- C:\Users\Rafinha\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/11/20 13:35:35 | 000,001,258 | ---- | M] () -- C:\Users\Rafinha\Desktop\Spybot - Search & Destroy.lnk
[2012/11/20 12:06:41 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/20 12:06:41 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/20 06:43:48 | 000,189,248 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/11/20 06:43:41 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/11/20 06:43:37 | 000,001,201 | ---- | M] () -- C:\Users\Rafinha\Desktop\Uplay.lnk
[2012/11/17 22:25:52 | 000,000,000 | ---- | M] () -- C:\asc_rdflag
[2012/11/17 11:32:17 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1186146817-16379212-3669418587-1001UA.job
[2012/11/17 11:32:17 | 000,001,034 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1186146817-16379212-3669418587-1001Core.job
[2012/11/17 04:03:07 | 000,001,146 | ---- | M] () -- C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
[2012/11/14 12:35:53 | 000,054,104 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\kltdi.sys
[2012/11/14 12:32:46 | 000,029,528 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klmouflt.sys
[2012/11/14 12:32:43 | 000,029,016 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klkbdflt.sys
[2012/11/14 12:32:39 | 000,613,720 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2012/11/14 12:25:35 | 000,001,086 | ---- | M] () -- C:\Users\Rafinha\Desktop\MSI Afterburner.lnk
[2012/11/14 12:20:09 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/11/14 12:20:09 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/11/14 12:15:48 | 000,417,632 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/11/11 02:52:44 | 000,002,517 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[1 C:\Users\Rafinha\*.tmp files -> C:\Users\Rafinha\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/11/20 13:35:35 | 000,001,282 | ---- | C] () -- C:\Users\Rafinha\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/11/20 13:35:35 | 000,001,258 | ---- | C] () -- C:\Users\Rafinha\Desktop\Spybot - Search & Destroy.lnk
[2012/11/20 06:43:48 | 000,189,248 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/11/20 06:43:41 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/11/20 06:43:37 | 000,001,201 | ---- | C] () -- C:\Users\Rafinha\Desktop\Uplay.lnk
[2012/11/18 20:39:49 | 000,001,133 | ---- | C] () -- C:\Users\Rafinha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Media Center Control.lnk
[2012/11/17 22:25:52 | 000,000,000 | ---- | C] () -- C:\asc_rdflag
[2012/11/17 04:03:21 | 000,001,146 | ---- | C] () -- C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
[2012/11/17 03:09:14 | 000,017,720 | ---- | C] () -- C:\Windows\SysNative\drivers\SmartDefragDriver.sys
[2012/11/14 06:58:51 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/14 06:53:01 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/08 21:41:51 | 000,002,517 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/11/01 12:43:21 | 000,002,059 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Web Platform Installer.lnk
[2012/09/23 14:33:19 | 000,444,283 | ---- | C] () -- C:\Program Files\Common Files\WinPcapNmap.exe
[2012/09/20 11:08:13 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2012/09/03 18:09:38 | 000,166,912 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2012/09/03 18:09:38 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2012/09/03 11:37:11 | 000,162,432 | ---- | C] () -- C:\Windows\SysWow64\drivers\ithsgt.sys
[2012/09/03 11:37:11 | 000,012,032 | ---- | C] () -- C:\Windows\SysWow64\drivers\lilsgt.sys
[2012/09/01 00:25:01 | 001,595,976 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/08/31 22:34:39 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/08/31 22:22:42 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2012/08/31 22:22:42 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2012/08/31 22:22:42 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2012/08/31 22:22:42 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012/08/31 22:22:40 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/08/31 22:10:59 | 000,017,408 | ---- | C] () -- C:\Users\Rafinha\AppData\Local\WebpageIcons.db
[2012/08/31 22:10:59 | 000,000,017 | ---- | C] () -- C:\Users\Rafinha\AppData\Local\resmon.resmoncfg
[2012/08/31 22:05:09 | 002,469,760 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
[2012/08/31 22:05:09 | 000,019,840 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2012/08/31 22:05:08 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
[2012/08/31 22:05:08 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2012/08/31 22:05:08 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2012/06/19 10:02:17 | 003,123,272 | R--- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2012/06/11 14:50:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/06/11 14:50:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/05/02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011/09/19 11:03:40 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\rtvcvfw32.dll
[2011/09/12 20:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009/07/14 02:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/07/13 14:09:42 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/07/13 14:09:42 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 23:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 01:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 23:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/10/07 17:53:09 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\2K Sports
[2012/11/20 13:20:44 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\DAEMON Tools Pro
[2012/11/20 19:19:28 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\DMCache
[2012/08/31 22:09:31 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Dropbox
[2012/08/31 22:09:32 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Easeware
[2012/10/06 04:37:33 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Electronic Arts
[2012/09/01 14:55:34 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\ExtremeCopy
[2012/08/31 22:09:32 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\FMRTEv5
[2012/08/31 22:09:32 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\foobar2000
[2012/08/31 22:09:38 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\GameSave Manager 2
[2012/08/31 22:09:38 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\HD Tune Pro
[2012/11/20 19:00:35 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\IDM
[2012/11/17 03:09:14 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\IObit
[2012/08/31 22:10:14 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\liQeNSoft
[2012/08/31 22:10:20 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Milestone
[2012/08/31 22:10:20 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Mirillis
[2012/08/31 22:10:20 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\MotioninJoy
[2012/11/09 23:01:02 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\MP3Rocket
[2012/10/16 23:22:20 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Origin
[2012/08/31 22:10:34 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\PunkBuster
[2012/10/14 13:15:06 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\RadeonPro
[2012/08/31 22:10:34 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Sports Interactive
[2012/08/31 22:10:51 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Stardock
[2012/08/31 22:10:51 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\TechSmith
[2012/08/31 22:10:51 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\TuneUp Software
[2012/09/20 04:11:48 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Tunngle
[2012/08/31 22:10:52 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Ubisoft
[2012/11/20 19:37:58 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\uTorrent
[2012/08/31 22:10:57 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\VDownloader
[2012/08/31 22:10:58 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\VS Revo Group
========== Purity Check ==========
< End of report >
OTL by OldTimer - Version 3.2.69.0 Folder = E:\Downloads\Programs
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
4,00 Gb Total Physical Memory | 1,28 Gb Available Physical Memory | 32,12% Memory free
8,00 Gb Paging File | 4,46 Gb Available in Paging File | 55,82% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 121,81 Gb Total Space | 68,80 Gb Free Space | 56,48% Space Free | Partition Type: NTFS
Drive D: | 74,43 Gb Total Space | 51,18 Gb Free Space | 68,77% Space Free | Partition Type: NTFS
Drive E: | 576,72 Gb Total Space | 157,94 Gb Free Space | 27,39% Space Free | Partition Type: NTFS
Drive F: | 55,87 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: RAFINHA-PC | User Name: Rafinha | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/11/20 19:00:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- E:\Downloads\Programs\OTL.exe
PRC - [2012/11/20 06:43:41 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/11/14 12:32:25 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
PRC - [2012/10/30 04:11:14 | 000,166,968 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe
PRC - [2012/10/30 04:11:12 | 000,408,632 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
PRC - [2012/10/29 06:58:16 | 003,389,080 | ---- | M] (Electronic Arts) -- C:\Program Files (x86)\Origin\Origin.exe
PRC - [2012/10/13 14:59:40 | 000,698,240 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\Monitor.exe
PRC - [2012/10/12 15:33:10 | 001,026,432 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe
PRC - [2012/10/06 20:37:22 | 002,059,904 | ---- | M] (John Mautari aka japamd) -- C:\Program Files (x86)\RadeonPro\RadeonPro.exe
PRC - [2012/10/06 20:37:22 | 000,020,608 | ---- | M] (Mr. John aka japamd) -- C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe
PRC - [2012/08/31 23:06:18 | 003,528,128 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2012/08/31 22:00:18 | 000,896,912 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012/08/17 22:38:34 | 000,128,440 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe
PRC - [2012/07/27 18:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/04/26 10:33:16 | 002,743,104 | ---- | M] (DT Soft Ltd) -- C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2012/04/11 14:33:50 | 000,336,896 | ---- | M] (Markus Gehlhaar) -- C:\Program Files (x86)\Media Center Control\MCC Service.exe
PRC - [2012/03/26 15:05:04 | 004,656,632 | ---- | M] (Almico Software (www.almico.com)) -- C:\Program Files (x86)\SpeedFan\speedfan.exe
PRC - [2011/12/09 15:23:30 | 001,596,032 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\Winamp\winamp.exe
========== Modules (No Company Name) ==========
MOD - [2012/11/20 19:12:26 | 000,206,336 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\winamp.lng
MOD - [2012/11/20 19:12:26 | 000,149,504 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\vis_milk2.lng
MOD - [2012/11/20 19:12:26 | 000,085,504 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\vis_avs.lng
MOD - [2012/11/20 19:12:26 | 000,042,496 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_wifi.lng
MOD - [2012/11/20 19:12:26 | 000,036,864 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_ipod.lng
MOD - [2012/11/20 19:12:26 | 000,036,352 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ombrowser.lng
MOD - [2012/11/20 19:12:26 | 000,019,456 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_android.lng
MOD - [2012/11/20 19:12:26 | 000,016,384 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\out_ds.lng
MOD - [2012/11/20 19:12:26 | 000,013,824 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_usb.lng
MOD - [2012/11/20 19:12:26 | 000,013,824 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_wire.lng
MOD - [2012/11/20 19:12:26 | 000,007,680 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\vis_nsfs.lng
MOD - [2012/11/20 19:12:26 | 000,007,680 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_transcode.lng
MOD - [2012/11/20 19:12:26 | 000,007,168 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\out_wave.lng
MOD - [2012/11/20 19:12:26 | 000,006,144 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\tagz.lng
MOD - [2012/11/20 19:12:26 | 000,006,144 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\out_disk.lng
MOD - [2012/11/20 19:12:26 | 000,004,608 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_activesync.lng
MOD - [2012/11/20 19:12:26 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\winampa.lng
MOD - [2012/11/20 19:12:26 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_p4s.lng
MOD - [2012/11/20 19:12:26 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\pmp_njb.lng
MOD - [2012/11/20 19:12:26 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\playlist.lng
MOD - [2012/11/20 19:12:25 | 000,052,224 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_local.lng
MOD - [2012/11/20 19:12:25 | 000,044,032 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_pmp.lng
MOD - [2012/11/20 19:12:25 | 000,043,008 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_disc.lng
MOD - [2012/11/20 19:12:25 | 000,037,376 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_jumpex.lng
MOD - [2012/11/20 19:12:25 | 000,022,016 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_mp3.lng
MOD - [2012/11/20 19:12:25 | 000,020,992 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_ml.lng
MOD - [2012/11/20 19:12:25 | 000,019,968 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_midi.lng
MOD - [2012/11/20 19:12:25 | 000,018,432 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_mod.lng
MOD - [2012/11/20 19:12:25 | 000,014,336 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_wm.lng
MOD - [2012/11/20 19:12:25 | 000,013,824 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_online.lng
MOD - [2012/11/20 19:12:25 | 000,012,800 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_playlists.lng
MOD - [2012/11/20 19:12:25 | 000,012,800 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_cdda.lng
MOD - [2012/11/20 19:12:25 | 000,012,288 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_plg.lng
MOD - [2012/11/20 19:12:25 | 000,011,264 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_vorbis.lng
MOD - [2012/11/20 19:12:25 | 000,011,264 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_nsv.lng
MOD - [2012/11/20 19:12:25 | 000,010,752 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_skinmanager.lng
MOD - [2012/11/20 19:12:25 | 000,010,240 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_undo.lng
MOD - [2012/11/20 19:12:25 | 000,010,240 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_hotkeys.lng
MOD - [2012/11/20 19:12:25 | 000,009,216 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_timerestore.lng
MOD - [2012/11/20 19:12:25 | 000,009,216 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_nopro.lng
MOD - [2012/11/20 19:12:25 | 000,008,704 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_history.lng
MOD - [2012/11/20 19:12:25 | 000,008,704 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_downloads.lng
MOD - [2012/11/20 19:12:25 | 000,008,704 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_devices.lng
MOD - [2012/11/20 19:12:25 | 000,007,680 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_tray.lng
MOD - [2012/11/20 19:12:25 | 000,007,168 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_dshow.lng
MOD - [2012/11/20 19:12:25 | 000,007,168 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_orgler.lng
MOD - [2012/11/20 19:12:25 | 000,006,656 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_autotag.lng
MOD - [2012/11/20 19:12:25 | 000,006,656 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_wav.lng
MOD - [2012/11/20 19:12:25 | 000,006,144 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_flac.lng
MOD - [2012/11/20 19:12:25 | 000,005,632 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_wave.lng
MOD - [2012/11/20 19:12:25 | 000,005,120 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_rg.lng
MOD - [2012/11/20 19:12:25 | 000,005,120 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_impex.lng
MOD - [2012/11/20 19:12:25 | 000,005,120 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_bookmarks.lng
MOD - [2012/11/20 19:12:25 | 000,005,120 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_avi.lng
MOD - [2012/11/20 19:12:25 | 000,004,608 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_enqplay.lng
MOD - [2012/11/20 19:12:25 | 000,004,608 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_mp4.lng
MOD - [2012/11/20 19:12:25 | 000,004,608 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_mkv.lng
MOD - [2012/11/20 19:12:25 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_wv.lng
MOD - [2012/11/20 19:12:25 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_nowplaying.lng
MOD - [2012/11/20 19:12:25 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\ml_addons.lng
MOD - [2012/11/20 19:12:25 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_swf.lng
MOD - [2012/11/20 19:12:25 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_linein.lng
MOD - [2012/11/20 19:12:25 | 000,003,584 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\in_flv.lng
MOD - [2012/11/20 19:12:24 | 000,062,976 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\burnlib.lng
MOD - [2012/11/20 19:12:24 | 000,021,504 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_ff.lng
MOD - [2012/11/20 19:12:24 | 000,013,824 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\dsp_sps.lng
MOD - [2012/11/20 19:12:24 | 000,010,752 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\auth.lng
MOD - [2012/11/20 19:12:24 | 000,010,240 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_classicart.lng
MOD - [2012/11/20 19:12:24 | 000,009,728 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_aacplus.lng
MOD - [2012/11/20 19:12:24 | 000,007,168 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_crasher.lng
MOD - [2012/11/20 19:12:24 | 000,006,656 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_fhgaac.lng
MOD - [2012/11/20 19:12:24 | 000,006,144 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_wma.lng
MOD - [2012/11/20 19:12:24 | 000,005,632 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_lame.lng
MOD - [2012/11/20 19:12:24 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\gen_find_on_disk.lng
MOD - [2012/11/20 19:12:24 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_wav.lng
MOD - [2012/11/20 19:12:24 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_vorbis.lng
MOD - [2012/11/20 19:12:24 | 000,004,096 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\WLZ5573.tmp\enc_flac.lng
MOD - [2012/11/20 15:23:11 | 000,192,512 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\sfamcc00001.dll
MOD - [2012/11/20 15:23:11 | 000,158,720 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Temp\sfareca00001.dll
MOD - [2012/11/14 13:52:27 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\66694f9192bd0dddc2eaf90fbcbcd555\System.Management.ni.dll
MOD - [2012/11/14 12:22:41 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\17796f2951c17ebf92dd4b7c9b3ce556\System.ServiceProcess.ni.dll
MOD - [2012/11/14 12:22:33 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll
MOD - [2012/11/14 12:22:28 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll
MOD - [2012/11/14 12:22:08 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d040079bc7148afeca03c5abb6fc3c61\System.Windows.Forms.ni.dll
MOD - [2012/11/14 12:22:03 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\4e80768a2d88c7a333e43cbb7a6c0705\System.Drawing.ni.dll
MOD - [2012/11/14 12:22:02 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\70705382a499703e7a595fada80b04e6\Accessibility.ni.dll
MOD - [2012/11/14 12:21:53 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\b311b783e1efaa9527f4c2c9680c44d1\WindowsBase.ni.dll
MOD - [2012/11/14 12:21:48 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\25e672ea505e50ab058258ac72a54f02\System.Xml.ni.dll
MOD - [2012/11/14 12:21:45 | 007,988,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll
MOD - [2012/11/14 12:21:40 | 011,493,376 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll
MOD - [2012/10/31 20:15:05 | 000,460,312 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
MOD - [2012/10/31 20:15:04 | 012,455,448 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\PepperFlash\pepflashplayer.dll
MOD - [2012/10/31 20:15:02 | 004,007,448 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\pdf.dll
MOD - [2012/10/31 20:13:47 | 000,587,288 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\libglesv2.dll
MOD - [2012/10/31 20:13:46 | 000,123,928 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\libegl.dll
MOD - [2012/10/31 20:13:35 | 000,156,712 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\avutil-51.dll
MOD - [2012/10/31 20:13:34 | 000,274,984 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\avformat-54.dll
MOD - [2012/10/31 20:13:32 | 002,168,360 | ---- | M] () -- C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\avcodec-54.dll
MOD - [2012/10/30 04:11:14 | 000,166,968 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSS.exe
MOD - [2012/10/30 04:11:12 | 000,408,632 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
MOD - [2012/10/06 20:37:24 | 001,136,256 | ---- | M] () -- C:\Program Files (x86)\RadeonPro\V8.Net.dll
MOD - [2012/09/03 13:59:53 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\xml.w5s
MOD - [2012/09/03 13:59:53 | 000,083,968 | ---- | M] () -- C:\Program Files (x86)\Winamp\tataki.dll
MOD - [2012/09/03 13:59:53 | 000,047,616 | ---- | M] () -- C:\Program Files (x86)\Winamp\zlib.dll
MOD - [2012/09/03 13:59:53 | 000,035,328 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\timer.w5s
MOD - [2012/09/03 13:59:53 | 000,021,504 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\tagz.w5s
MOD - [2012/09/03 13:59:52 | 001,737,728 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_ff.dll
MOD - [2012/09/03 13:59:52 | 000,623,616 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\jnetlib.w5s
MOD - [2012/09/03 13:59:52 | 000,417,280 | ---- | M] () -- C:\Program Files (x86)\Winamp\nsutil.dll
MOD - [2012/09/03 13:59:52 | 000,340,992 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\freeform\wacs\freetype\freetype.wac
MOD - [2012/09/03 13:59:52 | 000,318,464 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_ml.dll
MOD - [2012/09/03 13:59:52 | 000,313,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_wm.dll
MOD - [2012/09/03 13:59:52 | 000,294,400 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_local.dll
MOD - [2012/09/03 13:59:52 | 000,290,304 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mp3.dll
MOD - [2012/09/03 13:59:52 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\libsndfile.dll
MOD - [2012/09/03 13:59:52 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_vorbis.dll
MOD - [2012/09/03 13:59:52 | 000,249,856 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_devices.dll
MOD - [2012/09/03 13:59:52 | 000,241,152 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_pmp.dll
MOD - [2012/09/03 13:59:52 | 000,200,192 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_disc.dll
MOD - [2012/09/03 13:59:52 | 000,185,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_jumpex.dll
MOD - [2012/09/03 13:59:52 | 000,174,080 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\auth.w5s
MOD - [2012/09/03 13:59:52 | 000,170,496 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_ipod.dll
MOD - [2012/09/03 13:59:52 | 000,165,376 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mod.dll
MOD - [2012/09/03 13:59:52 | 000,154,624 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\jpeg.w5s
MOD - [2012/09/03 13:59:52 | 000,124,928 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_online.dll
MOD - [2012/09/03 13:59:52 | 000,118,272 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_p4s.dll
MOD - [2012/09/03 13:59:52 | 000,113,664 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_wifi.dll
MOD - [2012/09/03 13:59:52 | 000,109,568 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_midi.dll
MOD - [2012/09/03 13:59:52 | 000,103,936 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\png.w5s
MOD - [2012/09/03 13:59:52 | 000,102,400 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_cdda.dll
MOD - [2012/09/03 13:59:52 | 000,084,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\playlist.w5s
MOD - [2012/09/03 13:59:52 | 000,083,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_plg.dll
MOD - [2012/09/03 13:59:52 | 000,082,944 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_playlists.dll
MOD - [2012/09/03 13:59:52 | 000,078,848 | ---- | M] () -- C:\Program Files (x86)\Winamp\nde.dll
MOD - [2012/09/03 13:59:52 | 000,075,264 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_nsv.dll
MOD - [2012/09/03 13:59:52 | 000,072,192 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_dshow.dll
MOD - [2012/09/03 13:59:52 | 000,068,608 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_avi.dll
MOD - [2012/09/03 13:59:52 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_flac.dll
MOD - [2012/09/03 13:59:52 | 000,060,928 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_android.dll
MOD - [2012/09/03 13:59:52 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_impex.dll
MOD - [2012/09/03 13:59:52 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_orgler.dll
MOD - [2012/09/03 13:59:52 | 000,053,760 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_usb.dll
MOD - [2012/09/03 13:59:52 | 000,052,736 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mp4.dll
MOD - [2012/09/03 13:59:52 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_ds.dll
MOD - [2012/09/03 13:59:52 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_history.dll
MOD - [2012/09/03 13:59:52 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_mkv.dll
MOD - [2012/09/03 13:59:52 | 000,044,544 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\devices.w5s
MOD - [2012/09/03 13:59:52 | 000,043,008 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_flv.dll
MOD - [2012/09/03 13:59:52 | 000,033,792 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_rg.dll
MOD - [2012/09/03 13:59:52 | 000,032,256 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_transcode.dll
MOD - [2012/09/03 13:59:52 | 000,028,672 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_autotag.dll
MOD - [2012/09/03 13:59:52 | 000,028,160 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\ml_bookmarks.dll
MOD - [2012/09/03 13:59:52 | 000,027,648 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_hotkeys.dll
MOD - [2012/09/03 13:59:52 | 000,025,600 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\gen_tray.dll
MOD - [2012/09/03 13:59:52 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_swf.dll
MOD - [2012/09/03 13:59:52 | 000,023,040 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\albumart.w5s
MOD - [2012/09/03 13:59:52 | 000,022,528 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_disk.dll
MOD - [2012/09/03 13:59:52 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\pmp_njb.dll
MOD - [2012/09/03 13:59:52 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\gif.w5s
MOD - [2012/09/03 13:59:52 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\bmp.w5s
MOD - [2012/09/03 13:59:52 | 000,018,432 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\out_wave.dll
MOD - [2012/09/03 13:59:52 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_wave.dll
MOD - [2012/09/03 13:59:52 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\dlmgr.w5s
MOD - [2012/09/03 13:59:52 | 000,016,384 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\gracenote.w5s
MOD - [2012/09/03 13:59:52 | 000,014,336 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\filereader.w5s
MOD - [2012/09/03 13:59:52 | 000,013,824 | ---- | M] () -- C:\Program Files (x86)\Winamp\System\primo.w5s
MOD - [2012/09/03 13:59:52 | 000,007,168 | ---- | M] () -- C:\Program Files (x86)\Winamp\Plugins\in_linein.dll
MOD - [2012/09/01 00:05:47 | 000,109,568 | ---- | M] () -- C:\Program Files (x86)\DAEMON Tools Pro\BRD.dll
MOD - [2012/08/17 22:38:56 | 000,479,160 | ---- | M] () -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll
MOD - [2012/07/21 04:44:58 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
MOD - [2012/07/21 04:44:54 | 000,335,872 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
MOD - [2012/07/21 04:44:38 | 000,225,280 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTCore.dll
MOD - [2012/07/21 04:44:30 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTUI.dll
MOD - [2012/07/21 04:44:22 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTFC.dll
MOD - [2012/06/04 14:23:18 | 000,122,880 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTSSHooks.dll
MOD - [2012/06/04 13:03:40 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTMUI.dll
MOD - [2012/06/04 13:02:42 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTUI.dll
MOD - [2012/06/04 13:02:34 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTFC.dll
MOD - [2011/04/30 13:04:54 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTTSH.dll
MOD - [2011/04/30 13:04:54 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\Bundle\OSDServer\RTTSH.dll
MOD - [2011/03/17 01:11:16 | 004,297,568 | ---- | M] () -- C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
MOD - [2010/11/12 22:33:11 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
MOD - [2010/11/12 21:35:10 | 000,417,792 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms.resources\2.0.0.0_pt-BR_b77a5c561934e089\System.Windows.Forms.resources.dll
MOD - [2009/09/15 18:20:50 | 000,177,152 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\madBasic_.bpl
MOD - [2009/09/15 18:20:50 | 000,044,544 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\madDisAsm_.bpl
MOD - [2009/09/15 18:20:46 | 000,342,528 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\madExcept_.bpl
MOD - [2009/07/10 10:07:18 | 000,166,912 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL
MOD - [2009/02/06 19:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL
========== Services (SafeList) ==========
SRV:64bit: - [2012/09/27 23:38:16 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/13 23:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 23:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/11/20 06:43:41 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/11/14 12:32:25 | 000,356,376 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe -- (AVP)
SRV - [2012/11/14 12:20:10 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/10/25 12:21:08 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/10/19 16:14:08 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/10/12 15:33:10 | 001,026,432 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe -- (AdvancedSystemCareService6)
SRV - [2012/10/06 20:37:22 | 000,020,608 | ---- | M] (Mr. John aka japamd) [Auto | Running] -- C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe -- (RadeonPro Support Service)
SRV - [2012/09/03 18:11:07 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2012/08/31 22:35:58 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2012/07/27 18:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/19 19:08:04 | 000,738,152 | ---- | M] (Tunngle.net GmbH) [On_Demand | Stopped] -- C:\Program Files (x86)\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2012/04/11 14:33:50 | 000,336,896 | ---- | M] (Markus Gehlhaar) [Auto | Running] -- C:\Program Files (x86)\Media Center Control\MCC Service.exe -- (MediaCenterControl)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 19:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/11/14 12:35:53 | 000,054,104 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kltdi.sys -- (kltdi)
DRV:64bit: - [2012/11/14 12:32:46 | 000,029,528 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klmouflt.sys -- (klmouflt)
DRV:64bit: - [2012/11/14 12:32:43 | 000,029,016 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\klkbdflt.sys -- (klkbdflt)
DRV:64bit: - [2012/11/14 12:32:39 | 000,613,720 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\SysNative\drivers\klif.sys -- (KLIF)
DRV:64bit: - [2012/09/28 00:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/09/27 23:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/09/06 16:08:29 | 000,121,416 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV:64bit: - [2012/09/01 00:05:23 | 000,283,200 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2012/08/13 17:49:40 | 000,178,008 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\kneps.sys -- (kneps)
DRV:64bit: - [2012/08/02 16:09:34 | 000,028,504 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\klim6.sys -- (KLIM6)
DRV:64bit: - [2012/08/02 06:53:14 | 000,158,944 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP)
DRV:64bit: - [2012/07/31 15:23:02 | 000,070,016 | ---- | M] (Identive) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\S3XXx64.sys -- (S3XXx64)
DRV:64bit: - [2012/07/13 14:02:14 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/07/13 13:39:51 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2012/07/13 13:39:51 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2012/06/19 18:28:12 | 000,458,584 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\kl1.sys -- (kl1)
DRV:64bit: - [2012/05/14 04:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/07/29 14:54:56 | 000,016,776 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\epmntdrv.sys -- (epmntdrv)
DRV:64bit: - [2011/07/29 14:54:56 | 000,009,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\EuGdiDrv.sys -- (EuGdiDrv)
DRV:64bit: - [2010/11/26 18:02:18 | 000,017,720 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV:64bit: - [2010/11/21 01:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/21 01:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 01:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2010/11/21 01:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2010/11/21 01:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/21 01:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2010/11/21 01:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 01:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/08/19 20:24:34 | 000,074,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2010/03/04 19:26:58 | 000,349,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)
DRV:64bit: - [2010/01/27 00:09:02 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:64bit: - [2009/12/30 12:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:64bit: - [2009/10/16 07:44:56 | 001,309,696 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\P17.sys -- (P17)
DRV:64bit: - [2009/09/16 09:02:42 | 000,031,232 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901t.sys -- (tap0901t)
DRV:64bit: - [2009/07/16 12:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2009/07/13 23:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 23:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 23:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 18:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 18:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 18:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 18:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 18:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/04/29 17:28:30 | 000,030,208 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\KMWDFILTER.sys -- (KMWDFILTER)
DRV - [2012/10/30 04:11:10 | 000,013,368 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64)
DRV - [2012/09/03 12:03:39 | 000,162,432 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysWOW64\drivers\ithsgt.sys -- (ithsgt)
DRV - [2012/09/03 12:03:39 | 000,012,032 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysWOW64\drivers\lilsgt.sys -- (lilsgt)
DRV - [2011/07/29 14:54:56 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\epmntdrv.sys -- (epmntdrv)
DRV - [2011/07/29 14:54:56 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2009/07/13 23:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2008/07/26 23:30:36 | 000,014,544 | ---- | M] (OpenLibSys.org) [Kernel | On_Demand | Stopped] -- E:\Documentos\RealTemp\WinRing0x64.sys -- (WinRing0_1_2_0)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://br.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-BR
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 70 89 F9 8F 69 8F CD 01 [binary data]
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...00000ffe0185b82
IE - HKU\S-1-5-21-1186146817-16379212-3669418587-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.babylo...0000ffb5e5e61e"
FF - prefs.js..extensions.enabledAddons: [email protected]:7.3.19
FF - prefs.js..extensions.enabledAddons: [email protected]:1.2.9.2
FF - prefs.js..extensions.enabledAddons: {87F8774F-B485-47E2-A755-A40A8A5E8874}:2.12.1.1.140
FF - prefs.js..keyword.URL: "http://search.babylo...0ffb5e5e61e&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_110.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Rafinha\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Rafinha\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Rafinha\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: C:\Users\Rafinha\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012/09/01 00:29:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012/09/01 00:29:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012/09/01 00:29:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012/09/01 00:29:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected] [2012/09/01 00:29:31 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[email protected]: C:\Users\Rafinha\AppData\Roaming\IDM\idmmzcc5 [2012/08/31 22:58:25 | 000,000,000 | ---D | M]
[2012/04/22 20:00:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\Extensions
[2012/09/23 14:31:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\Firefox\Profiles\gk0fxyf8.default\extensions
[2012/08/31 22:10:23 | 000,000,000 | ---D | M] (Modulo de Protecao) -- C:\Users\Rafinha\AppData\Roaming\mozilla\Firefox\Profiles\gk0fxyf8.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E8874}
[2012/11/20 13:54:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\Firefox\Profiles\gk0fxyf8.default\extensions\[email protected]
[2012/08/31 22:10:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\Firefox\Profiles\gk0fxyf8.default\extensions\trash
[2012/07/27 02:53:51 | 000,127,820 | ---- | M] () (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\firefox\profiles\gk0fxyf8.default\extensions\[email protected]
[2012/07/25 01:32:26 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Rafinha\AppData\Roaming\mozilla\firefox\profiles\gk0fxyf8.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
File not found (No name found) -- C:\USERS\RAFA\APPDATA\ROAMING\IDM\IDMMZCC5
File not found (No name found) -- C:\USERS\RAFA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GK0FXYF8.DEFAULT\EXTENSIONS\{87F8774F-B485-47E2-A755-A40A8A5E8874}
File not found (No name found) -- C:\USERS\RAFA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\GK0FXYF8.DEFAULT\EXTENSIONS\[email protected]
========== Chrome ==========
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = http://www.google.co...q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Rafinha\AppData\Local\Google\Chrome\Application\23.0.1271.64\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Rafinha\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: Angry Birds = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: Gotas de chuva = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcipapbfhdnmgihoimbjiadmhpcgcnil\1.0.0.2_0\
CHR - Extension: Audiotool = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk\1.1_0\
CHR - Extension: YouTube = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Pesquisa do Google = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Kaspersky URL Advisor = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\13.0.1.4190_0\
CHR - Extension: Street Sesh = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\diibpgacpeaofpflklajpgmkokfkglpb\1.0_0\
CHR - Extension: The Godfather: Five Families = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\edfkoljdeffeedleidebkmmamepgbnbl\1.0_0\
CHR - Extension: Google Agenda = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0\
CHR - Extension: Stylish = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\0.10_0\
CHR - Extension: AdBlock = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.47_0\
CHR - Extension: Safe Money = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\13.0.1.4190_0\
CHR - Extension: JustTV - TV pela internet = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbkjhaehebpcjnaipcemkhdnfibifkpl\0.0.0.4_0\
CHR - Extension: FB unseen = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihcedcpmfdpjijiamkaeaefgfagnnpei\0.1.3_0\
CHR - Extension: Desprotetor de Links = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\imcbnnnoghiihopefblgehihofbfbmei\1.2.11_0\
CHR - Extension: Virtual Keyboard = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\13.0.1.4190_0\
CHR - Extension: Blackball Pool = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjkhefodfbgjpcmahghmfggbcpjabnag\1.0.3_0\
CHR - Extension: Endere\u00E7o IP = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcijdkkommbhnpohidhdpkhendgcpamf\0.4_0\
CHR - Extension: Autodesk Homestyler = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb\2.2_0\
CHR - Extension: Lose The Heat 2 = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\knlpidedajllknkcbnogiahlclkkflne\3.3_0\
CHR - Extension: Evernote Web = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0\
CHR - Extension: Currently = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhmphdkpgbibohbnpbfiefkgieacjmh\2.2.1_0\
CHR - Extension: REC - Rastreamento de Encomendas dos Correios = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\omhclojepaohhgmelpgpnbekblifihoh\0.3_0\
CHR - Extension: Gmail = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Anti-Banner = C:\Users\Rafinha\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\13.0.1.4190_0\
O1 HOSTS File: ([2009/06/10 19:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O4:64bit: - HKLM..\Run: [NVRaidService] C:\Program Files\NVIDIA Corporation\Raid\nvraidservice.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [P17RunE] C:\Windows\SysWow64\P17RunE.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1186146817-16379212-3669418587-1001..\Run: [Advanced SystemCare 6] C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe (IObit)
O4 - HKU\S-1-5-21-1186146817-16379212-3669418587-1001..\Run: [DS3 Tool] C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe (www.motioninjoy.com)
O4 - HKU\S-1-5-21-1186146817-16379212-3669418587-1001..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm ()
O8:64bit: - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Fazer o download usando o IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm ()
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Fazer o download usando o IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O9:64bit: - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 189.7.144.15 189.7.144.16
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{10CAD571-CB29-4445-8633-CBCCE21B2B24}: DhcpNameServer = 189.7.144.15 189.7.144.16
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0185B82-2002-4E79-B2BA-0511FC03CAFA}: DhcpNameServer = 7.254.254.254
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\ScCertProp: DllName - (wlnotify.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/06/27 15:22:13 | 000,000,044 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{61e3115d-f3cf-11e1-ba9a-0004acf75961}\Shell - "" = AutoRun
O33 - MountPoints2\{61e3115d-f3cf-11e1-ba9a-0004acf75961}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{81a2f92c-f3c2-11e1-9f3d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{81a2f92c-f3c2-11e1-9f3d-806e6f6e6963}\Shell\AutoRun\command - "" = F:\CARROSSEL.exe -- [2012/06/27 15:22:10 | 003,289,961 | R--- | M] (Adobe Systems, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (SmartDefragBootTime.exe)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/11/20 14:07:20 | 000,000,000 | ---D | C] -- C:\Windows\tasks\TaskDisabled
[2012/11/20 13:35:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/11/20 13:35:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012/11/20 13:35:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012/11/20 13:05:54 | 000,000,000 | ---D | C] -- E:\DOCUMENTOS\Assassin's Creed III
[2012/11/20 13:03:40 | 000,000,000 | -HSD | C] -- C:\Users\Rafinha\Drivers
[2012/11/20 06:43:37 | 000,000,000 | ---D | C] -- C:\Users\Rafinha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
[2012/11/20 06:43:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ubisoft
[2012/11/18 20:39:54 | 000,000,000 | ---D | C] -- C:\ProgramData\MCC_Service
[2012/11/18 20:39:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Media Center Control
[2012/11/17 14:14:14 | 000,025,472 | ---- | C] (IObit) -- C:\Windows\SysNative\RegistryDefragBootTime.exe
[2012/11/17 04:03:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2013
[2012/11/17 03:09:29 | 000,032,600 | ---- | C] (IObit) -- C:\Windows\SysNative\SmartDefragBootTime.exe
[2012/11/17 03:08:01 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2012/11/17 03:08:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 6
[2012/11/17 03:07:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit
[2012/11/14 06:58:49 | 000,054,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WdfLdr.sys
[2012/11/14 06:58:49 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wdfres.dll
[2012/11/14 06:54:48 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/11/14 06:54:48 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/11/14 06:54:47 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/11/14 06:54:47 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/11/14 06:54:47 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/11/14 06:54:47 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/11/14 06:54:47 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/11/14 06:54:47 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/11/14 06:54:46 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/11/14 06:54:46 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/11/14 06:54:46 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/11/14 06:54:46 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2012/11/14 06:54:45 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/11/14 06:54:45 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/11/14 06:54:45 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2012/11/14 06:53:02 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFPlatform.dll
[2012/11/14 06:53:01 | 000,744,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFx.dll
[2012/11/14 06:53:01 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFHost.exe
[2012/11/14 06:53:01 | 000,045,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WUDFCoinstaller.dll
[2012/11/14 04:07:07 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcore6.dll
[2012/11/14 04:07:07 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dhcpcore6.dll
[2012/11/14 04:07:07 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcsvc6.dll
[2012/11/14 04:07:04 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netcorehc.dll
[2012/11/14 04:07:04 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncsi.dll
[2012/11/14 04:07:04 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netcorehc.dll
[2012/11/14 04:07:04 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ncsi.dll
[2012/11/14 04:07:04 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netevent.dll
[2012/11/14 04:07:04 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netevent.dll
[2012/11/14 04:06:56 | 000,095,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\synceng.dll
[2012/11/14 04:06:56 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\synceng.dll
[2012/11/11 02:14:11 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012/11/11 02:14:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2012/11/11 02:13:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012/11/11 02:13:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2012/11/11 02:13:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2012/11/11 02:13:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012/11/11 02:11:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2012/11/11 02:10:58 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2012/11/09 23:01:43 | 000,000,000 | ---D | C] -- C:\Users\Rafinha\Desktop\musicas treino
[2012/11/08 21:42:00 | 000,000,000 | ---D | C] -- C:\Users\Rafinha\AppData\Roaming\Skype
[2012/11/08 21:41:51 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2012/11/08 21:41:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/11/08 21:41:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012/11/08 21:41:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012/11/01 12:46:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/11/01 12:46:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2012/11/01 12:43:20 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2012/10/29 10:28:25 | 000,000,000 | ---D | C] -- C:\Users\Rafinha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/10/29 10:28:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/10/29 07:53:58 | 000,000,000 | ---D | C] -- E:\DOCUMENTOS\MOHW
[2012/10/22 02:35:46 | 000,000,000 | ---D | C] -- C:\Users\Rafinha\Desktop\churras turma funk
[1 C:\Users\Rafinha\*.tmp files -> C:\Users\Rafinha\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/11/20 18:53:01 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/20 15:23:41 | 001,636,212 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/11/20 15:23:41 | 000,706,312 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat
[2012/11/20 15:23:41 | 000,654,880 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/11/20 15:23:41 | 000,147,038 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat
[2012/11/20 15:23:41 | 000,121,752 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/11/20 15:17:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/20 15:17:22 | 3220,086,784 | -HS- | M] () -- C:\hiberfil.sys
[2012/11/20 13:35:35 | 000,001,282 | ---- | M] () -- C:\Users\Rafinha\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/11/20 13:35:35 | 000,001,258 | ---- | M] () -- C:\Users\Rafinha\Desktop\Spybot - Search & Destroy.lnk
[2012/11/20 12:06:41 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/20 12:06:41 | 000,016,640 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/20 06:43:48 | 000,189,248 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/11/20 06:43:41 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/11/20 06:43:37 | 000,001,201 | ---- | M] () -- C:\Users\Rafinha\Desktop\Uplay.lnk
[2012/11/17 22:25:52 | 000,000,000 | ---- | M] () -- C:\asc_rdflag
[2012/11/17 11:32:17 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1186146817-16379212-3669418587-1001UA.job
[2012/11/17 11:32:17 | 000,001,034 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1186146817-16379212-3669418587-1001Core.job
[2012/11/17 04:03:07 | 000,001,146 | ---- | M] () -- C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
[2012/11/14 12:35:53 | 000,054,104 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\kltdi.sys
[2012/11/14 12:32:46 | 000,029,528 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klmouflt.sys
[2012/11/14 12:32:43 | 000,029,016 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klkbdflt.sys
[2012/11/14 12:32:39 | 000,613,720 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2012/11/14 12:25:35 | 000,001,086 | ---- | M] () -- C:\Users\Rafinha\Desktop\MSI Afterburner.lnk
[2012/11/14 12:20:09 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/11/14 12:20:09 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/11/14 12:15:48 | 000,417,632 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/11/11 02:52:44 | 000,002,517 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[1 C:\Users\Rafinha\*.tmp files -> C:\Users\Rafinha\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/11/20 13:35:35 | 000,001,282 | ---- | C] () -- C:\Users\Rafinha\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/11/20 13:35:35 | 000,001,258 | ---- | C] () -- C:\Users\Rafinha\Desktop\Spybot - Search & Destroy.lnk
[2012/11/20 06:43:48 | 000,189,248 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/11/20 06:43:41 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/11/20 06:43:37 | 000,001,201 | ---- | C] () -- C:\Users\Rafinha\Desktop\Uplay.lnk
[2012/11/18 20:39:49 | 000,001,133 | ---- | C] () -- C:\Users\Rafinha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Media Center Control.lnk
[2012/11/17 22:25:52 | 000,000,000 | ---- | C] () -- C:\asc_rdflag
[2012/11/17 04:03:21 | 000,001,146 | ---- | C] () -- C:\Users\Public\Desktop\Kaspersky Internet Security 2013.lnk
[2012/11/17 03:09:14 | 000,017,720 | ---- | C] () -- C:\Windows\SysNative\drivers\SmartDefragDriver.sys
[2012/11/14 06:58:51 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/11/14 06:53:01 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/11/08 21:41:51 | 000,002,517 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/11/01 12:43:21 | 000,002,059 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Web Platform Installer.lnk
[2012/09/23 14:33:19 | 000,444,283 | ---- | C] () -- C:\Program Files\Common Files\WinPcapNmap.exe
[2012/09/20 11:08:13 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2012/09/03 18:09:38 | 000,166,912 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2012/09/03 18:09:38 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2012/09/03 11:37:11 | 000,162,432 | ---- | C] () -- C:\Windows\SysWow64\drivers\ithsgt.sys
[2012/09/03 11:37:11 | 000,012,032 | ---- | C] () -- C:\Windows\SysWow64\drivers\lilsgt.sys
[2012/09/01 00:25:01 | 001,595,976 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/08/31 22:34:39 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/08/31 22:22:42 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2012/08/31 22:22:42 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2012/08/31 22:22:42 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2012/08/31 22:22:42 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012/08/31 22:22:40 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/08/31 22:10:59 | 000,017,408 | ---- | C] () -- C:\Users\Rafinha\AppData\Local\WebpageIcons.db
[2012/08/31 22:10:59 | 000,000,017 | ---- | C] () -- C:\Users\Rafinha\AppData\Local\resmon.resmoncfg
[2012/08/31 22:05:09 | 002,469,760 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
[2012/08/31 22:05:09 | 000,019,840 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2012/08/31 22:05:08 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
[2012/08/31 22:05:08 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2012/08/31 22:05:08 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2012/06/19 10:02:17 | 003,123,272 | R--- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2012/06/11 14:50:16 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/06/11 14:50:16 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/05/02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011/09/19 11:03:40 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\rtvcvfw32.dll
[2011/09/12 20:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== ZeroAccess Check ==========
[2009/07/14 02:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/07/13 14:09:42 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/07/13 14:09:42 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 23:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 01:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 23:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/10/07 17:53:09 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\2K Sports
[2012/11/20 13:20:44 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\DAEMON Tools Pro
[2012/11/20 19:19:28 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\DMCache
[2012/08/31 22:09:31 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Dropbox
[2012/08/31 22:09:32 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Easeware
[2012/10/06 04:37:33 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Electronic Arts
[2012/09/01 14:55:34 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\ExtremeCopy
[2012/08/31 22:09:32 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\FMRTEv5
[2012/08/31 22:09:32 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\foobar2000
[2012/08/31 22:09:38 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\GameSave Manager 2
[2012/08/31 22:09:38 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\HD Tune Pro
[2012/11/20 19:00:35 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\IDM
[2012/11/17 03:09:14 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\IObit
[2012/08/31 22:10:14 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\liQeNSoft
[2012/08/31 22:10:20 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Milestone
[2012/08/31 22:10:20 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Mirillis
[2012/08/31 22:10:20 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\MotioninJoy
[2012/11/09 23:01:02 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\MP3Rocket
[2012/10/16 23:22:20 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Origin
[2012/08/31 22:10:34 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\PunkBuster
[2012/10/14 13:15:06 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\RadeonPro
[2012/08/31 22:10:34 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Sports Interactive
[2012/08/31 22:10:51 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Stardock
[2012/08/31 22:10:51 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\TechSmith
[2012/08/31 22:10:51 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\TuneUp Software
[2012/09/20 04:11:48 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Tunngle
[2012/08/31 22:10:52 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\Ubisoft
[2012/11/20 19:37:58 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\uTorrent
[2012/08/31 22:10:57 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\VDownloader
[2012/08/31 22:10:58 | 000,000,000 | ---D | M] -- C:\Users\Rafinha\AppData\Roaming\VS Revo Group
========== Purity Check ==========
< End of report >