I think I got infected due to a porn file but I can't be sure. Problems arose next time I booted the PC.
My SO is Windows 7 Professional, 32 bits. I had McAfee at the time and the problem was that it would pop a warning saying its real-time protection was disabled, its Firewall was disabled as well and I wasn't able to scan (it'd say it found an error). I'd click to activate and done. Last month the problem got worse and clicking on activate wouldn't activate anything. I tried reinstalling but nothing would work so I got rid of McAfee and started using Avira alongside Windows Firewall. In an attempt to resolve those problems I ran Farbar's Quick Scan at request of another Forum. Farbar is said to be unobtrusive on scans and so I believe nothing was modified.
Avira worked properly for a few days then it started giving the same warnings, clicking on activate would activate it. Now Saturday night I downloaded and ran several files into my PC, including an executable, videos, images and music files. I have no idea wether this new problem is related to the old one or just some new infection I managed to get but when booting up my PC on Sunday (next day) the taskbar wouldn't pop up, the background is black and shows no icons, as if explorer.exe wasn't running, plus I got an error message from Avira saying it had failed to access a certain value in some position of memory. I restarted the PC and got the same problem.
Now, I was unable to access anything except ctrl+alt+del, using this I can access Task Manager and it has an option to run a new task and through this I can run .exes in my pc. Explorer.exe shows up as running normally in task manager and I can finish it and then run it again but when I run it again the taskbar will appear just to disappear in a sec. I ran CCleaner.exe and unninstalled Avira thinking that its failure was causing the errors but whilst the Avira warning has stopped the Explorer.exe is still unresponsive.
I ran Control.exe (Control Panel) and although it'll open some options (sound and keyboard, for exemple) it'll not open "Backup and Restoration" nor "Recovery", using the address bar on Control Panel I can access My Computer but the Drives (C: and D:) are nameless, their names and any info like size or used space won't show up, checking their properties they're ok. Opening folders through the left menu (like Images or Documents) shows as if they were empty (even though they are not and content hasn't been deleted as you'll see later). Using Notepad.exe and clicking either Open or Save As won't show any window and I'm still unable to see my folders and files.
I tried updating CCleaner (through Chrome.exe) and fixing the Registry but nothing. Whenever I fix the Registry I save a backup so I used Cmd.exe to restore a 1 month old backup and although it restored successfully the problem persists. I've since rerestored it to the state it was yesterday. Through Cmd.exe I can check that my files weren't deleted and I still can open them. Below follows the OTL Log:
OTL logfile created on: 16/02/2014 23:34:36 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Danilo\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy
1,60 Gb Total Physical Memory | 0,89 Gb Available Physical Memory | 55,62% Memory free
3,21 Gb Paging File | 1,45 Gb Available in Paging File | 45,21% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 254,14 Gb Total Space | 155,28 Gb Free Space | 61,10% Space Free | Partition Type: NTFS
Drive D: | 29,00 Gb Total Space | 11,46 Gb Free Space | 39,53% Space Free | Partition Type: NTFS
Computer Name: DANILO-PC | User Name: Danilo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/02/16 23:33:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Danilo\Downloads\OTL.exe
PRC - [2014/01/02 21:46:10 | 030,714,328 | ---- | M] (Dropbox, Inc.) -- C:\Users\Danilo\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012/11/22 23:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2011/12/10 11:51:50 | 000,095,584 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2011/03/28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011/03/28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011/03/02 12:20:58 | 000,224,256 | ---- | M] () -- C:\Arquivos de Programas\GNU\GnuPG\dirmngr.exe
PRC - [2011/02/25 02:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/01/26 01:00:32 | 000,393,216 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2011/01/26 01:00:04 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2011/01/25 23:46:48 | 000,284,160 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Arquivos de Programas\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
PRC - [2011/01/06 18:47:54 | 005,646,272 | ---- | M] (Lenovo(beijing) Limited) -- C:\Arquivos de Programas\Lenovo\Energy Management\utility.exe
PRC - [2011/01/06 18:47:18 | 008,951,744 | ---- | M] (Lenovo (Beijing) Limited) -- C:\Arquivos de Programas\Lenovo\Energy Management\Energy Management.exe
PRC - [2010/12/24 11:19:36 | 000,136,488 | ---- | M] (CyberLink) -- C:\Arquivos de Programas\Lenovo\YouCam\YCMMirage.exe
PRC - [2010/11/20 18:29:49 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Windows Media Player\wmpnetwk.exe
PRC - [2010/06/17 06:23:34 | 000,140,224 | ---- | M] (Advanced Micro Devices) -- C:\Arquivos de Programas\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
PRC - [2009/07/13 22:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\IgrsSvcs.exe
PRC - [2008/05/20 20:19:54 | 000,075,016 | ---- | M] (CA) -- C:\Arquivos de Programas\CA\SharedComponents\CA_LIC\LogWatNT.exe
PRC - [2008/05/20 20:19:40 | 000,029,960 | ---- | M] (CA) -- C:\Arquivos de Programas\CA\SharedComponents\CA_LIC\lic98Service.exe
PRC - [2007/03/09 18:00:18 | 001,167,360 | ---- | M] (Lenovo (Beijing) Limited) -- C:\Arquivos de Programas\Lenovo\EnergyCut\EnergyCut.exe
PRC - [2006/02/01 23:49:14 | 000,204,800 | ---- | M] () -- C:\oraclexe\app\oracle\product\10.2.0\server\BIN\TNSLSNR.EXE
PRC - [2006/02/01 23:43:44 | 059,064,320 | ---- | M] (Oracle Corporation) -- c:\oraclexe\app\oracle\product\10.2.0\server\BIN\oracle.exe
========== Modules (No Company Name) ==========
MOD - [2014/02/01 20:42:37 | 013,616,456 | ---- | M] () -- C:\Users\Danilo\AppData\Local\Google\Chrome\Application\32.0.1700.107\PepperFlash\pepflashplayer.dll
MOD - [2014/02/01 20:42:37 | 000,399,688 | ---- | M] () -- C:\Users\Danilo\AppData\Local\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll
MOD - [2014/02/01 20:42:35 | 004,055,368 | ---- | M] () -- C:\Users\Danilo\AppData\Local\Google\Chrome\Application\32.0.1700.107\pdf.dll
MOD - [2014/02/01 20:41:45 | 000,715,592 | ---- | M] () -- C:\Users\Danilo\AppData\Local\Google\Chrome\Application\32.0.1700.107\libglesv2.dll
MOD - [2014/02/01 20:41:45 | 000,100,168 | ---- | M] () -- C:\Users\Danilo\AppData\Local\Google\Chrome\Application\32.0.1700.107\libegl.dll
MOD - [2014/02/01 20:41:43 | 001,634,632 | ---- | M] () -- C:\Users\Danilo\AppData\Local\Google\Chrome\Application\32.0.1700.107\ffmpegsumo.dll
MOD - [2014/01/02 21:45:04 | 003,558,400 | ---- | M] () -- C:\Users\Danilo\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2013/10/18 20:55:02 | 025,100,288 | ---- | M] () -- C:\Users\Danilo\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2008/12/20 03:20:50 | 000,063,304 | ---- | M] () -- C:\Arquivos de Programas\Lenovo\Energy Management\KbdHook.dll
MOD - [2008/12/20 03:20:08 | 000,051,016 | ---- | M] () -- C:\Arquivos de Programas\Lenovo\Energy Management\HookLib.dll
MOD - [2005/06/24 18:05:02 | 000,045,056 | ---- | M] () -- C:\Arquivos de Programas\Lenovo\EnergyCut\HookLib.dll
========== Services (SafeList) ==========
SRV - [2014/02/06 06:47:18 | 000,108,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014/02/05 13:34:34 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/12/05 16:21:56 | 000,174,488 | ---- | M] (McAfee, Inc.) [Unavailable | Unknown] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2013/05/27 01:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Arquivos de Programas\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013/04/10 03:56:49 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Arquivos de Programas\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/02/28 22:48:58 | 000,118,520 | ---- | M] (Riverbed Technology, Inc.) [On_Demand | Stopped] -- C:\Arquivos de Programas\WinPcap\rpcapd.exe -- (rpcapd)
SRV - [2012/04/21 03:01:59 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/12/10 11:51:50 | 000,095,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Arquivos de Programas\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2011/03/28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011/03/02 12:20:58 | 000,224,256 | ---- | M] () [Auto | Running] -- C:\Arquivos de Programas\GNU\GnuPG\dirmngr.exe -- (DirMngr)
SRV - [2011/01/26 01:00:04 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011/01/25 23:46:48 | 000,284,160 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2010/12/28 00:44:32 | 000,578,912 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Arquivos de Programas\Lenovo\ReadyComm\ConnSvc.exe -- (Lenovo ReadyComm ConnSvc)
SRV - [2010/12/28 00:44:16 | 000,509,280 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Arquivos de Programas\Lenovo\ReadyComm\AppSvc.exe -- (Lenovo ReadyComm AppSvc)
SRV - [2010/11/20 18:29:49 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Arquivos de Programas\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010/06/17 06:23:34 | 000,140,224 | ---- | M] (Advanced Micro Devices) [Auto | Running] -- C:\Arquivos de Programas\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe -- (AMD Reservation Manager)
SRV - [2009/07/16 18:12:42 | 000,276,296 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Arquivos de Programas\Lenovo\ReadyComm\PS_MDP.dll -- (PS_MDP)
SRV - [2009/07/15 05:27:26 | 000,038,152 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Arquivos de Programas\Lenovo\ReadyComm\common\IGRS.exe -- (IGRS)
SRV - [2009/07/15 05:27:20 | 000,103,688 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Arquivos de Programas\Lenovo\ReadyComm\common\router.dll -- (ReadyComm.DirectRouter)
SRV - [2009/07/13 22:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 22:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 22:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2008/05/20 20:19:54 | 000,075,016 | ---- | M] (CA) [Auto | Running] -- C:\Arquivos de Programas\CA\SharedComponents\CA_LIC\LogWatNT.exe -- (LogWatch)
SRV - [2006/02/01 23:51:06 | 000,045,056 | ---- | M] () [On_Demand | Stopped] -- C:\oraclexe\app\oracle\product\10.2.0\server\bin\OraClrAgnt.exe -- (OracleXEClrAgent)
SRV - [2006/02/01 23:49:14 | 000,204,800 | ---- | M] () [Auto | Running] -- C:\oraclexe\app\oracle\product\10.2.0\server\BIN\TNSLSNR.EXE -- (OracleXETNSListener)
SRV - [2006/02/01 23:47:28 | 000,057,616 | ---- | M] (Oracle Corporation) [On_Demand | Stopped] -- C:\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe -- (OracleMTSRecoveryService)
SRV - [2006/02/01 23:44:06 | 000,102,400 | ---- | M] () [Disabled | Stopped] -- c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe -- (OracleJobSchedulerXE)
SRV - [2006/02/01 23:43:44 | 059,064,320 | ---- | M] (Oracle Corporation) [Auto | Running] -- c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE -- (OracleServiceXE)
SRV - [2003/07/28 08:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de Programas\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
========== Driver Services (SafeList) ==========
DRV - [2013/12/05 16:16:44 | 000,572,688 | ---- | M] (McAfee, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2013/12/05 16:12:06 | 000,133,992 | ---- | M] (McAfee, Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2013/07/04 16:38:20 | 000,188,176 | ---- | M] (Oracle Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\VBoxDrv.sys -- (VBoxDrv)
DRV - [2013/07/04 16:37:08 | 000,115,984 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VBoxNetFlt.sys -- (VBoxNetFlt)
DRV - [2013/07/04 16:37:08 | 000,104,720 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV - [2013/07/04 16:37:08 | 000,094,480 | ---- | M] (Oracle Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\VBoxUSBMon.sys -- (VBoxUSBMon)
DRV - [2013/02/28 22:48:42 | 000,036,600 | ---- | M] (Riverbed Technology, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\npf.sys -- (NPF)
DRV - [2013/02/24 23:07:47 | 000,231,760 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\System32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2013/02/02 20:45:18 | 000,015,616 | ---- | M] () [Kernel | On_Demand | Unknown] -- C:\Windows\System32\drivers\TrueSight.sys -- (TrueSight)
DRV - [2011/09/23 16:36:20 | 000,232,512 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011/02/14 01:42:26 | 001,283,200 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2011/01/26 02:50:02 | 006,575,104 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2011/01/26 00:22:56 | 000,229,888 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2010/12/24 11:19:56 | 000,027,632 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\clwvd.sys -- (clwvd)
DRV - [2010/11/29 05:50:40 | 000,035,968 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2010/11/24 11:30:40 | 002,128,384 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2010/11/20 18:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 18:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 18:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2010/11/20 18:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 18:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 18:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2010/11/20 18:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 18:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/10/21 07:05:44 | 000,196,352 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vm331avs.sys -- (vm331avs)
DRV - [2010/09/30 05:44:32 | 000,218,624 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUVStor.sys -- (RSUSBVSTOR)
DRV - [2010/08/16 06:28:50 | 000,005,888 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vmuvcflt.sys -- (vmuvcflt)
DRV - [2010/06/24 23:33:28 | 000,068,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C)
DRV - [2010/05/14 19:04:14 | 000,062,592 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\amd_sata.sys -- (amd_sata)
DRV - [2010/05/14 19:04:14 | 000,024,192 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\amd_xata.sys -- (amd_xata)
DRV - [2010/02/18 09:18:22 | 000,037,944 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\amdiox86.sys -- (amdiox86)
DRV - [2010/01/15 18:08:42 | 000,032,352 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\LhdX86.sys -- (LHDmgr)
DRV - [2009/07/28 05:09:38 | 000,063,240 | ---- | M] (Lenovo) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdbridge.sys -- (Bridge0)
DRV - [2009/07/21 21:14:58 | 000,081,704 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wsvd.sys -- (wsvd)
DRV - [2009/07/15 20:37:16 | 000,011,792 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\WDMirror.sys -- (wdmirror)
DRV - [2009/07/13 20:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 20:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2008/11/16 18:39:44 | 000,131,984 | ---- | M] (Deterministic Networks, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE)
DRV - [2007/04/09 18:07:48 | 000,011,776 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV - [2007/01/18 20:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.br/
IE - HKCU\..\SearchScopes,DefaultScope = {62CB8808-0EAA-4724-A910-77B798653904}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\..\SearchScopes\{62CB8808-0EAA-4724-A910-77B798653904}: "URL" = http://br.search.yah...p={SearchTerms}
IE - HKCU\..\SearchScopes\{BC2C7794-A351-4F22-B31E-0391D1908B4E}: "URL" = http://www.google.co...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Pesquisa Segura"
FF - prefs.js..browser.startup.homepage: "http://www.google.com.br/"
FF - prefs.js..extensions.enabledAddons: %7B4ED1F68A-5463-4931-9384-8FFF5ED91D92%7D:3.6.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0
FF - prefs.js..keyword.URL: "http://br.search.yah...h?fr=mcafee&p="
FF - prefs.js..network.proxy.type: 0
FF - prefs.js..browser.search.defaultenginename: "Pesquisa Segura"
FF - prefs.js..browser.search.order.1: "Pesquisa Segura"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.5: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Danilo\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Danilo\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Danilo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/09/23 18:28:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Danilo\AppData\Roaming\mozilla\Extensions
[2014/01/27 16:42:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Danilo\AppData\Roaming\mozilla\Firefox\Profiles\1lw49e0c.default\extensions
[2014/01/27 16:42:12 | 000,000,000 | ---D | M] (McAfee SafeKey) -- C:\Users\Danilo\AppData\Roaming\mozilla\Firefox\Profiles\1lw49e0c.default\extensions\{072844D3-7DEE-45F6-A406-E87F76302E4B}
File not found (No name found) -- C:\PROGRAM FILES\MCAFEE\SITEADVISOR
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - Extension: Google Wallet = C:\Users\Danilo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0\
O1 HOSTS File: ([2013/05/26 19:02:45 | 000,000,849 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de Programas\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de Programas\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [Energy Management] C:\Arquivos de Programas\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4 - HKLM..\Run: [EnergyCut] C:\Arquivos de Programas\Lenovo\EnergyCut\EnergyCut.exe (Lenovo (Beijing) Limited)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jaureg.exe (Oracle Corporation)
O4 - Startup: C:\Users\Danilo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Danilo\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: safekey - file://C:\Users\Danilo\AppData\LocalLow\safekey\context.html?cmd=lastpass File not found
O8 - Extra context menu item: SafeKey Fill Forms - file://C:\Users\Danilo\AppData\LocalLow\safekey\context.html?cmd=fillforms File not found
O9 - Extra Button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Arquivos de Programas\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C7F9E1A4-504D-420F-A592-AC4F66CE413B}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de Programas\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de Programas\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Arquivos de Programas\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Arquivos de Programas\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/02/16 05:03:56 | 000,000,000 | ---D | C] -- C:\FRST
[2014/02/12 16:00:37 | 000,000,000 | R--D | C] -- C:\Users\Danilo\Searches
[2014/01/27 15:34:27 | 000,174,488 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
[2014/01/20 16:15:57 | 000,000,000 | ---D | C] -- C:\Users\Danilo\AppData\Local\DOSBox
[2014/01/20 16:15:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DOSBox-0.74
[2014/01/20 16:15:34 | 000,000,000 | ---D | C] -- C:\Program Files\DOSBox-0.74
[2013/09/02 01:00:06 | 026,838,560 | ---- | C] (McAfee) -- C:\Program Files\Common Files\lpuninstall.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/02/16 23:33:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/02/16 22:57:03 | 000,001,082 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3440027988-2761262164-3458294289-1000UA.job
[2014/02/16 22:11:55 | 000,031,312 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/02/16 22:11:55 | 000,031,312 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/02/16 22:09:02 | 000,717,994 | ---- | M] () -- C:\Windows\System32\prfh0416.dat
[2014/02/16 22:09:02 | 000,666,224 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/02/16 22:09:02 | 000,152,872 | ---- | M] () -- C:\Windows\System32\prfc0416.dat
[2014/02/16 22:09:02 | 000,127,234 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/02/16 22:07:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/02/16 22:03:11 | 000,000,022 | ---- | M] () -- C:\Windows\S.dirmngr
[2014/02/16 22:02:41 | 1292,029,952 | -HS- | M] () -- C:\hiberfil.sys
[2014/02/16 04:57:00 | 000,001,030 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3440027988-2761262164-3458294289-1000Core.job
[2014/02/12 02:40:57 | 001,048,819 | ---- | M] () -- C:\Users\Danilo\Desktop\favoritos_12_02_14.html
[2014/01/27 16:42:21 | 026,838,560 | ---- | M] (McAfee) -- C:\Program Files\Common Files\lpuninstall.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/02/16 21:57:59 | 000,000,022 | ---- | C] () -- C:\Windows\S.dirmngr
[2014/02/12 02:40:56 | 001,048,819 | ---- | C] () -- C:\Users\Danilo\Desktop\favoritos_12_02_14.html
[2013/11/05 20:54:03 | 1073,741,823 | ---- | C] () -- C:\Users\Danilo\Zword
[2013/10/09 23:57:52 | 000,007,666 | ---- | C] () -- C:\Users\Danilo\AppData\Local\Resmon.ResmonCfg
[2013/07/20 14:34:28 | 000,030,002 | ---- | C] () -- C:\Windows\System32\drivers\fvstore.dat
[2013/07/13 22:33:55 | 000,000,170 | ---- | C] () -- C:\Users\Danilo\.packettracer
[2013/05/29 00:07:15 | 000,000,076 | ---- | C] () -- C:\Users\Danilo\.gitconfig
[2013/02/28 22:47:36 | 000,053,299 | ---- | C] () -- C:\Windows\System32\pthreadVC.dll
[2013/02/19 19:43:58 | 000,000,407 | ---- | C] () -- C:\Users\Danilo\AppData\Roaming\Checksum.ini
[2013/02/01 16:30:09 | 000,015,616 | ---- | C] () -- C:\Windows\System32\drivers\TrueSight.sys
[2012/10/01 14:04:48 | 000,154,112 | ---- | C] () -- C:\Windows\System32\Tngremov.exe
[2011/11/27 17:32:15 | 000,011,126 | ---- | C] () -- C:\Users\Danilo\gsview32.ini
[2011/11/07 19:51:34 | 000,000,036 | ---- | C] () -- C:\Users\Danilo\.org.eclipse.epp.usagedata.recording.userId
[2011/10/29 20:42:04 | 000,000,094 | ---- | C] () -- C:\Users\Danilo\AppData\Local\fusioncache.dat
[2011/09/23 16:06:01 | 000,001,412 | ---- | C] () -- C:\ProgramData\profile.xml
========== ZeroAccess Check ==========
[2009/07/14 01:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 22:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 18:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 22:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/09/01 16:20:56 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\.minecraft
[2011/11/05 20:43:38 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\Blender Foundation
[2013/12/09 03:11:36 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\DAEMON Tools Lite
[2013/10/12 22:29:16 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\Dev-Cpp
[2014/02/16 22:11:45 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\Dropbox
[2013/05/01 17:37:27 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\Foxit Software
[2013/02/21 19:39:33 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\gnupg
[2012/08/09 15:33:19 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\JabRef 2.8.1
[2011/09/23 15:09:04 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\Lenovo
[2011/10/28 00:39:43 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\LibreOffice
[2014/01/02 21:47:34 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\Rags
[2012/10/10 15:51:53 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\Sublime Text 2
[2012/11/13 15:22:31 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\Subversion
[2013/11/24 17:10:20 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\TrueCrypt
[2014/02/12 02:33:47 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\uTorrent
[2013/07/20 13:03:56 | 000,000,000 | ---D | M] -- C:\Users\Danilo\AppData\Roaming\Wireshark
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:425759C6
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:7ADB695A
< End of report >