cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

ÿþOTL logfile created on: 1/5/2016 10:58:30 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\ppc\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18124)
Locale: 00000409 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

3.80 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 33.42% Memory free
7.60 Gb Paging File | 4.49 Gb Available in Paging File | 59.11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 231.00 Gb Total Space | 13.36 Gb Free Space | 5.79% Space Free | Partition Type: NTFS
Drive D: | 343.24 Gb Total Space | 78.59 Gb Free Space | 22.90% Space Free | Partition Type: NTFS

Computer Name: PPC-PC | User Name: ppc | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2016/01/05 22:56:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ppc\Desktop\OTL.exe
PRC - [2016/01/05 18:02:43 | 004,231,632 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\Microsoft\Network\Dsq\network\sysnetwk.exe
PRC - [2016/01/05 11:26:38 | 004,628,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\winsecurity\winsecurity.exe
PRC - [2015/12/11 01:54:14 | 000,741,704 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2015/12/08 10:24:45 | 007,142,328 | ---- | M] () -- C:\Users\ppc\AppData\Roaming\XBox\XBLive.exe
PRC - [2015/11/12 10:39:52 | 000,260,896 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
PRC - [2015/10/28 18:49:06 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2015/10/12 09:28:42 | 001,773,696 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2015/10/05 09:48:34 | 009,832,760 | ---- | M] (Malwarebytes) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
PRC - [2015/09/22 18:08:32 | 000,593,120 | ---- | M] (GAS Tecnologia) -- C:\PROGRA~2\GbPlugin\GbpSv.exe
PRC - [2015/06/11 14:43:00 | 000,660,768 | ---- | M] (IOBit) -- C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ascavsvc.exe
PRC - [2015/05/22 13:52:14 | 002,596,640 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASCTray.exe
PRC - [2015/04/28 17:53:43 | 004,383,008 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Smart Defrag 4\SmartDefrag.exe
PRC - [2015/04/26 15:02:14 | 000,043,816 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2015/04/26 15:02:04 | 000,043,816 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
PRC - [2015/04/26 15:01:50 | 000,043,816 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
PRC - [2014/11/22 13:01:26 | 000,911,648 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASCService.exe
PRC - [2014/10/11 13:05:40 | 000,060,712 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
PRC - [2014/10/08 19:18:56 | 000,211,104 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2014/10/08 19:18:50 | 000,534,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2014/10/08 11:13:28 | 000,366,904 | ---- | M] (Power Software Ltd) -- C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
PRC - [2014/08/12 16:05:40 | 000,271,160 | ---- | M] (Azureus Software, Inc) -- C:\Program Files (x86)\Vuze\Azureus.exe
PRC - [2013/10/21 09:56:44 | 000,863,232 | ---- | M] (Zepetto Co.) -- C:\ongame\Pointblank\PBLauncher.exe
PRC - [2012/12/24 09:30:14 | 001,868,432 | ---- | M] () -- C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
PRC - [2012/06/18 20:03:29 | 000,186,760 | ---- | M] () -- C:\Program Files (x86)\Photodex\ProShowGold\ScsiAccess.exe
PRC - [2011/09/04 12:45:26 | 003,398,736 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
PRC - [2011/06/15 19:09:18 | 000,146,592 | ---- | M] (Atheros) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2010/11/28 08:44:42 | 000,943,984 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2010/11/28 06:09:40 | 007,053,168 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
PRC - [2010/11/17 06:24:54 | 004,387,632 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
PRC - [2010/11/10 02:03:52 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2010/09/20 01:24:42 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
PRC - [2010/08/26 23:52:12 | 002,782,064 | ---- | M] (Samsung Electronics) -- C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
PRC - [2010/07/01 18:10:26 | 002,533,400 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010/07/01 18:10:22 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2009/11/02 03:21:26 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2015/12/25 17:01:32 | 000,096,768 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\chrome_elf.dll
MOD - [2015/12/11 01:54:11 | 001,583,432 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libglesv2.dll
MOD - [2015/12/11 01:54:09 | 000,081,224 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libegl.dll
MOD - [2015/11/17 18:21:28 | 002,601,400 | ---- | M] () -- C:\ProgramData\System32\SafeGuard32.dll
MOD - [2014/10/11 13:05:58 | 001,044,776 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2014/06/24 16:12:10 | 000,176,128 | ---- | M] () -- C:\Users\ppc\AppData\Roaming\Azureus\plugins\azitunes\jacob-1.17-M2-x86.dll
MOD - [2014/06/24 16:12:10 | 000,014,304 | ---- | M] () -- C:\Users\ppc\AppData\Roaming\Azureus\plugins\azitunes\libProcessAccess.dll
MOD - [2014/04/25 15:02:52 | 000,086,840 | ---- | M] () -- C:\Program Files (x86)\Vuze\aereg.dll
MOD - [2013/01/15 19:47:56 | 000,893,248 | ---- | M] () -- C:\Program Files (x86)\IObit\Smart Defrag 4\webres.dll
MOD - [2013/01/15 18:48:26 | 000,348,992 | ---- | M] () -- C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
MOD - [2013/01/15 18:48:26 | 000,051,008 | ---- | M] () -- C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
MOD - [2013/01/15 18:48:24 | 000,183,616 | ---- | M] () -- C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
MOD - [2013/01/15 18:47:56 | 000,893,248 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\webres.dll
MOD - [2010/05/07 12:22:18 | 001,636,864 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
MOD - [2009/11/02 03:23:36 | 000,013,096 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
MOD - [2009/11/02 03:20:10 | 000,619,816 | ---- | M] () -- C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
MOD - [2006/08/12 01:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV:[b]64bit:[/b] - [2015/11/08 20:01:25 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2015/11/04 09:01:24 | 000,904,928 | ---- | M] (GAS Tecnologia LTDA) [Auto | Running] -- C:\Program Files\Diebold\Warsaw\core.exe -- (Warsaw Technology)
SRV:[b]64bit:[/b] - [2015/08/26 09:24:17 | 001,390,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:[b]64bit:[/b] - [2013/05/27 03:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:[b]64bit:[/b] - [2010/10/08 03:24:16 | 000,150,016 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:[b]64bit:[/b] - [2010/09/22 07:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:[b]64bit:[/b] - [2010/08/09 17:04:12 | 000,166,704 | ---- | M] (Samsung Electronics CO., LTD.) [On_Demand | Stopped] -- C:\Windows\SysNative\SUPDSvc.exe -- (Samsung UPD Service)
SRV - [2016/01/05 11:26:38 | 004,628,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\winsecurity\winsecurity.exe -- (WindowsSecurity)
SRV - [2015/12/08 10:24:45 | 007,142,328 | ---- | M] () [Auto | Running] -- C:\Users\ppc\AppData\Roaming\XBox\XBLive.exe -- (XBox)
SRV - [2015/11/02 14:18:46 | 002,934,048 | ---- | M] (IObit) [Auto | Stopped] -- C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe -- (LiveUpdateSvc)
SRV - [2015/10/28 18:49:06 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2015/10/12 09:28:44 | 001,433,216 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2015/10/12 09:28:42 | 001,773,696 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2015/10/05 09:48:46 | 001,135,416 | ---- | M] (Malwarebytes) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2015/09/22 18:08:32 | 000,593,120 | ---- | M] (GAS Tecnologia) [Auto | Running] -- C:\PROGRA~2\GbPlugin\GbpSv.exe -- (GbpSv)
SRV - [2015/06/11 14:43:00 | 000,660,768 | ---- | M] (IOBit) [Auto | Running] -- C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ascavsvc.exe -- (ASCAntivirusSrv)
SRV - [2014/12/11 11:30:48 | 000,315,496 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2014/11/22 13:01:26 | 000,911,648 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASCService.exe -- (AdvancedSystemCareService8)
SRV - [2014/11/01 21:38:39 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014/10/08 19:18:56 | 000,211,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2014/10/08 19:18:50 | 000,534,184 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2014/04/12 00:08:08 | 000,103,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/12/24 09:30:14 | 001,868,432 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe -- (DragonUpdater)
SRV - [2012/06/18 20:03:29 | 000,186,760 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Photodex\ProShowGold\ScsiAccess.exe -- (ScsiAccess)
SRV - [2011/06/15 19:09:18 | 000,146,592 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)
SRV - [2011/06/15 19:07:56 | 000,091,296 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe -- (AtherosSvc)
SRV - [2010/07/01 18:10:26 | 002,533,400 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/07/01 18:10:22 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV:[b]64bit:[/b] - [2016/01/05 21:10:58 | 000,101,080 | ---- | M] (GAS Tecnologia) [File_System | System | Running] -- C:\Windows\SysNative\drivers\wsddfac.sys -- (wsddfac)
DRV:[b]64bit:[/b] - [2015/10/05 09:50:18 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:[b]64bit:[/b] - [2015/10/05 09:50:06 | 000,025,816 | ---- | M] (Malwarebytes) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:[b]64bit:[/b] - [2015/07/07 17:06:58 | 000,038,104 | ---- | M] (Basil) [Kernel | Disabled | Running] -- C:\Program Files\Diebold\Warsaw\WinDivert64.sys -- (WinDivert1.1)
DRV:[b]64bit:[/b] - [2015/03/18 11:23:04 | 000,103,640 | ---- | M] (GAS Tecnologia) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\wsddpp.sys -- (wsddpp)
DRV:[b]64bit:[/b] - [2014/11/01 21:23:58 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2014/11/01 21:23:58 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2014/11/01 21:23:58 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2014/10/08 19:18:54 | 000,273,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:[b]64bit:[/b] - [2014/10/08 19:18:54 | 000,029,352 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:[b]64bit:[/b] - [2014/10/08 19:18:54 | 000,023,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:[b]64bit:[/b] - [2014/10/08 19:18:50 | 000,766,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:[b]64bit:[/b] - [2014/10/08 11:13:10 | 000,127,760 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:[b]64bit:[/b] - [2014/08/15 23:35:00 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:[b]64bit:[/b] - [2014/08/15 23:13:34 | 000,023,040 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:[b]64bit:[/b] - [2014/06/04 16:17:30 | 000,021,184 | ---- | M] (IObit) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV:[b]64bit:[/b] - [2014/05/27 02:13:18 | 000,034,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xb1usb.sys -- (xb1usb)
DRV:[b]64bit:[/b] - [2012/10/03 16:14:56 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:[b]64bit:[/b] - [2012/03/01 04:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2012/01/02 11:35:42 | 002,797,056 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:[b]64bit:[/b] - [2011/11/21 19:59:02 | 000,329,800 | ---- | M] (BitDefender S.R.L.) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\trufos.sys -- (Trufos)
DRV:[b]64bit:[/b] - [2011/06/15 19:08:16 | 000,289,440 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:[b]64bit:[/b] - [2011/06/15 19:08:14 | 000,283,296 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:[b]64bit:[/b] - [2011/06/15 19:08:14 | 000,166,048 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:[b]64bit:[/b] - [2011/06/15 19:08:14 | 000,059,040 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:[b]64bit:[/b] - [2011/06/15 19:08:14 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:[b]64bit:[/b] - [2011/06/15 19:08:14 | 000,029,344 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:[b]64bit:[/b] - [2011/06/15 19:08:12 | 000,259,744 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:[b]64bit:[/b] - [2011/06/15 19:08:12 | 000,109,216 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_avdt.sys -- (btath_avdt)
DRV:[b]64bit:[/b] - [2011/03/24 16:36:24 | 000,431,176 | ---- | M] (BitDefender) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\bdfsfltr.sys -- (bdfsfltr)
DRV:[b]64bit:[/b] - [2011/03/11 04:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2011/03/11 04:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2011/01/27 03:35:26 | 000,425,064 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:[b]64bit:[/b] - [2010/11/21 01:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2010/11/10 02:04:14 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:[b]64bit:[/b] - [2010/10/08 03:23:38 | 000,019,192 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:[b]64bit:[/b] - [2010/10/07 00:59:00 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI)
DRV:[b]64bit:[/b] - [2010/08/30 09:17:36 | 000,289,280 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2010/08/25 17:36:02 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2010/05/21 02:02:40 | 001,377,840 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:[b]64bit:[/b] - [2010/04/27 05:57:04 | 000,540,696 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:[b]64bit:[/b] - [2010/02/26 22:32:12 | 000,158,976 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:[b]64bit:[/b] - [2009/12/30 11:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:[b]64bit:[/b] - [2009/09/17 18:54:54 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (HECIx64)
DRV:[b]64bit:[/b] - [2009/07/13 23:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2009/07/13 23:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2009/07/13 23:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2009/07/13 22:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:[b]64bit:[/b] - [2009/06/10 18:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2009/06/10 18:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2009/06/10 18:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:[b]64bit:[/b] - [2009/06/10 18:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2015/11/10 15:48:38 | 000,029,912 | ---- | M] (GAS Tecnologia) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\GbPlugin\gbprcm64.sys -- (GBPRCM)
DRV - [2015/01/20 19:38:52 | 000,024,792 | ---- | M] (GAS Tecnologia LTDA) [Kernel | On_Demand | Running] -- C:\PROGRA~2\GbPlugin\wsftprp64.sys -- (Warsaw_PP)
DRV - [2009/07/13 23:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE:[b]64bit:[/b] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nav.brotlab.net?uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://nav.brotlab.net?uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {E921F400-D383-4B1B-9DE6-FCFCACFC1173}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{E921F400-D383-4B1B-9DE6-FCFCACFC1173}: "URL" = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nav.brotlab.net?uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://nav.brotlab.net?uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {E921F400-D383-4B1B-9DE6-FCFCACFC1173}
IE - HKU\.DEFAULT\..\SearchScopes\{E921F400-D383-4B1B-9DE6-FCFCACFC1173}: "URL" = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nav.brotlab.net?uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://nav.brotlab.net?uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {E921F400-D383-4B1B-9DE6-FCFCACFC1173}
IE - HKU\S-1-5-18\..\SearchScopes\{E921F400-D383-4B1B-9DE6-FCFCACFC1173}: "URL" = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKU\S-1-5-21-127006611-4033051029-833413259-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nav.brotlab.net?uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\S-1-5-21-127006611-4033051029-833413259-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\S-1-5-21-127006611-4033051029-833413259-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\S-1-5-21-127006611-4033051029-833413259-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com.br/?gfe_rd=cr&ei=eEGMVoeaD5Sq8wfliIroBQ&gws_rd=ssl
IE - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..\SearchScopes\{E921F400-D383-4B1B-9DE6-FCFCACFC1173}: "URL" = http://search.navegaki.com?q={searchTerms}&uid={002fec6cdeeb4d4689b6416e7cfccf89}&r=eg
IE - HKU\S-1-5-21-127006611-4033051029-833413259-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-127006611-4033051029-833413259-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8080;https=127.0.0.1:8080

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.countryCode: "BR"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.region: "BR"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:40.0
FF - user.js - File not found

FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@photodex.com/PhotodexPresenter: C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll ( )
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.3088: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.3146: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.11.3006: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\ppc\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\ppc\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: C:\Users\ppc\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts)
FF - HKCU\Software\MozillaPlugins\gastecnologia.com.br/sf/cef: C:\Users\ppc\AppData\Local\GAS Tecnologia\GBBD\npsf_cef.dll (GAS Tecnologia)
FF - HKCU\Software\MozillaPlugins\gastecnologia.com.br/sf/cef64: C:\Users\ppc\AppData\Local\GAS Tecnologia\GBBD\npsf_cef_64.dll (GAS Tecnologia)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files (x86)\Real\RealPlayer\browserrecord [2012/06/18 20:09:53 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{87F8774F-B485-47E2-A755-A40A8A5E886D}: C:\Users\ppc\AppData\Local\GAS Tecnologia\GBBD\cef\xpi [2015/05/12 16:09:39 | 000,000,000 | ---D | M]

[2015/05/02 18:50:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ppc\AppData\Roaming\mozilla\Extensions
[2015/12/12 00:24:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ppc\AppData\Roaming\mozilla\Firefox\Profiles\2e0ws0cf.default-1436494071782\extensions
[2015/12/12 00:24:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ppc\AppData\Roaming\mozilla\Firefox\Profiles\69jhk1l3.default-1435190245818\extensions
[2015/12/12 00:24:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ppc\AppData\Roaming\mozilla\Firefox\Profiles\74h4s286.default-1435202319743\extensions
[2015/12/08 09:32:44 | 000,000,674 | ---- | M] () -- C:\Users\ppc\AppData\Roaming\mozilla\firefox\profiles\69jhk1l3.default-1435190245818\searchplugins\navegaki.xml

[color=#E56717]========== Chrome ==========[/color]


O1 HOSTS File: ([2009/06/10 19:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:[b]64bit:[/b] - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O2 - BHO: (Samsung BHO Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [Diebold - Warsaw] C:\Program Files\Diebold\Warsaw\core.exe (GAS Tecnologia LTDA)
O4:[b]64bit:[/b] - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Power Software Ltd)
O4 - HKU\.DEFAULT..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto File not found
O4 - HKU\S-1-5-18..\Run: [Advanced SystemCare 8] "C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" /Auto File not found
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-127006611-4033051029-833413259-1000..\Run: [Advanced SystemCare Ultimate] C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASCTray.exe (IObit)
O4 - HKU\S-1-5-21-127006611-4033051029-833413259-1000..\Run: [Azureus] C:\Program Files (x86)\Vuze\Azureus.exe (Azureus Software, Inc)
O4 - HKU\S-1-5-21-127006611-4033051029-833413259-1000..\Run: [Facebook Update] C:\Users\ppc\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\.DEFAULT..\RunOnce: [iCloud] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe (Apple Inc.)
O4 - HKU\S-1-5-18..\RunOnce: [iCloud] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe (Apple Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-127006611-4033051029-833413259-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\ProgramData\System32\SafeGuard64.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\ProgramData\System32\SafeGuard32.dll ()
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..Trusted Domains: bancobrasil.com.br ([www] * in Trusted sites)
O15 - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..Trusted Domains: bancobrasil.com.br ([www14] * in Trusted sites)
O15 - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..Trusted Domains: bancobrasil.com.br ([www14] https in Trusted sites)
O15 - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..Trusted Domains: bancobrasil.com.br ([www2] * in Trusted sites)
O15 - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..Trusted Domains: bancobrasil.com.br ([www2] https in Trusted sites)
O15 - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..Trusted Domains: bb.com.br ([seg] https in Trusted sites)
O15 - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..Trusted Domains: bb.com.br ([www] * in Trusted sites)
O15 - HKU\S-1-5-21-127006611-4033051029-833413259-1000\..Trusted Domains: bb.com.br ([www] http in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2B97104C-CDE7-4557-8FBE-6A03219C8FB0}: DhcpNameServer = 172.20.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D02A354F-3DF7-4349-A7BB-6501AB495C82}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D02A354F-3DF7-4349-A7BB-6501AB495C82}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E0164ED2-228F-4192-992E-8E876E99BA5E}: DhcpNameServer = 200.175.5.139 200.175.89.139 192.168.25.1
O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ GbPluginBb: DllName - (C:\Program Files (x86)\GbPlugin\gbieh.dll) - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399F83} - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2015/10/13 10:16:23 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2016/01/05 22:56:48 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\ppc\Desktop\OTL.exe
[2016/01/05 22:28:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2016/01/05 22:28:21 | 000,109,272 | ---- | C] (Malwarebytes) -- C:\windows\SysNative\drivers\mbamchameleon.sys
[2016/01/05 22:28:21 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mwac.sys
[2016/01/05 22:28:21 | 000,025,816 | ---- | C] (Malwarebytes) -- C:\windows\SysNative\drivers\mbam.sys
[2016/01/05 22:28:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2016/01/05 22:20:46 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\GPBAK
[2016/01/05 21:16:47 | 000,000,000 | R--D | C] -- C:\Users\ppc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2016/01/05 20:03:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PointBlank
[2016/01/05 19:57:58 | 000,000,000 | ---D | C] -- C:\ongame
[2016/01/05 17:58:57 | 000,000,000 | ---D | C] -- C:\windows\19
[2016/01/04 10:16:09 | 000,000,000 | ---D | C] -- C:\ProgramData\AdobeCatchTemp
[2015/12/19 16:24:07 | 000,000,000 | -H-D | C] -- C:\windows\SysNative\GroupPolicy
[2015/12/18 02:03:53 | 000,000,000 | ---D | C] -- C:\ProgramData\System32
[2015/12/13 13:34:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2015/12/13 13:20:28 | 000,000,000 | ---D | C] -- C:\zoek_backup
[2015/12/13 13:19:37 | 000,148,088 | ---- | C] (GAS Tecnologia) -- C:\windows\SysNative\drivers\wsddin64.sys
[2015/12/13 13:08:46 | 000,103,640 | ---- | C] (GAS Tecnologia) -- C:\windows\SysNative\drivers\wsddpp.sys
[2015/12/13 13:08:46 | 000,101,080 | ---- | C] (GAS Tecnologia) -- C:\windows\SysNative\drivers\wsddfac.sys
[2015/12/13 13:08:41 | 000,000,000 | ---D | C] -- C:\Program Files\Diebold
[2015/12/13 00:05:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2015/12/12 00:21:31 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015/12/10 02:08:37 | 000,000,000 | ---D | C] -- C:\windows\7
[2015/12/07 10:03:13 | 000,000,000 | ---D | C] -- C:\Users\ppc\Documents\MTN2 Game 02
[2015/12/07 08:34:10 | 000,000,000 | ---D | C] -- C:\Users\ppc\AppData\Roaming\stetic
[2015/12/07 08:32:57 | 000,000,000 | ---D | C] -- C:\Users\ppc\AppData\Roaming\MonoDevelop-Unity-4.0
[2015/12/07 08:32:22 | 000,000,000 | ---D | C] -- C:\Users\ppc\AppData\Local\MonoDevelop-Unity-4.0
[2015/12/06 23:54:00 | 000,000,000 | ---D | C] -- C:\Users\ppc\Documents\MTN2 Game 001
[7 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2016/01/05 23:02:54 | 000,000,034 | ---- | M] () -- C:\Users\Public\Documents\{DE764086-1C0A-4DD3-90BA-0B93BDD794BE}
[2016/01/05 22:56:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ppc\Desktop\OTL.exe
[2016/01/05 22:49:18 | 000,028,848 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016/01/05 22:49:18 | 000,028,848 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016/01/05 22:28:24 | 000,001,102 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2016/01/05 22:20:45 | 000,001,527 | ---- | M] () -- C:\windows\unins000.dat
[2016/01/05 22:20:34 | 000,707,354 | ---- | M] () -- C:\windows\unins000.exe
[2016/01/05 22:16:00 | 000,001,070 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2016/01/05 21:11:10 | 000,000,990 | ---- | M] () -- C:\windows\tasks\GneizA2WxPMsg.job
[2016/01/05 21:11:10 | 000,000,986 | ---- | M] () -- C:\windows\tasks\dhubZMSmzIj.job
[2016/01/05 21:11:10 | 000,000,980 | ---- | M] () -- C:\windows\tasks\mJVhfgUd.job
[2016/01/05 21:11:09 | 000,001,066 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2016/01/05 21:10:58 | 000,101,080 | ---- | M] (GAS Tecnologia) -- C:\windows\SysNative\drivers\wsddfac.sys
[2016/01/05 21:10:35 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2016/01/05 21:10:28 | 4081,647,616 | -HS- | M] () -- C:\hiberfil.sys
[2016/01/05 21:09:49 | 000,000,000 | -H-- | M] () -- C:\asc_rdflag
[2016/01/05 20:50:02 | 000,001,066 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-127006611-4033051029-833413259-1000UA.job
[2016/01/05 20:03:46 | 000,000,745 | ---- | M] () -- C:\Users\ppc\Desktop\PointBlank.lnk
[2016/01/05 19:27:03 | 1175,338,337 | ---- | M] () -- C:\Users\ppc\Desktop\PointBlankSetup_20150813.exe
[2016/01/05 18:02:07 | 000,001,044 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-127006611-4033051029-833413259-1000Core.job
[2016/01/04 14:22:34 | 000,002,190 | ---- | M] () -- C:\Users\Public\Desktop\Advanced SystemCare Ultimate 8.lnk
[2016/01/04 10:43:27 | 000,002,315 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2016/01/04 07:44:48 | 000,000,286 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2015/12/27 11:54:32 | 001,241,766 | ---- | M] () -- C:\windows\SysNative\prfh0416.dat
[2015/12/27 11:54:32 | 001,190,098 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2015/12/27 11:54:32 | 000,658,446 | ---- | M] () -- C:\windows\SysNative\prfc0416.dat
[2015/12/27 11:54:32 | 000,632,666 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2015/12/27 11:54:32 | 000,006,550 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2015/12/27 01:38:10 | 033,370,537 | ---- | M] () -- C:\Users\ppc\Desktop\Video_20151227011759_by_videoshow.mp4
[2015/12/19 16:23:53 | 000,000,337 | ---- | M] () -- C:\Users\ppc\Desktop\Ajuste Navegador.bat
[2015/12/17 10:04:06 | 000,001,258 | ---- | M] () -- C:\Users\ppc\Desktop\Internet Explore.lnk
[2015/12/15 16:58:24 | 000,076,487 | ---- | M] () -- C:\Users\ppc\Desktop\óculos-Star-Wars.jpg
[2015/12/15 14:38:14 | 000,061,964 | ---- | M] () -- C:\Users\ppc\Desktop\Star Wars.jpg
[2015/12/13 14:06:48 | 000,290,952 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2015/12/13 13:09:19 | 000,001,024 | ---- | M] () -- C:\.rnd
[2015/12/12 12:28:04 | 000,001,067 | ---- | M] () -- C:\Users\ppc\AppData\Roaming\Launch Internet Explorer Browser.lnk
[2015/12/10 01:50:46 | 000,724,797 | ---- | M] () -- C:\Users\ppc\Desktop\Uniforme Goias E. C. ---.png
[2015/12/10 01:09:22 | 000,312,366 | ---- | M] () -- C:\Users\ppc\Desktop\Uniforme Goias.png
[2015/12/10 01:03:56 | 000,009,089 | ---- | M] () -- C:\Users\ppc\Desktop\Goias_Esporte_Clube 02.gif
[2015/12/10 01:03:31 | 000,037,125 | ---- | M] () -- C:\Users\ppc\Desktop\goias-esporte-clube 01.gif
[7 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2016/01/05 22:28:24 | 000,001,102 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2016/01/05 22:20:47 | 000,034,871 | ---- | C] () -- C:\windows\SysWow64\gpedit.msc
[2016/01/05 22:20:45 | 000,707,354 | ---- | C] () -- C:\windows\unins000.exe
[2016/01/05 22:20:45 | 000,001,527 | ---- | C] () -- C:\windows\unins000.dat
[2016/01/05 21:09:49 | 000,000,000 | -H-- | C] () -- C:\asc_rdflag
[2016/01/05 20:03:46 | 000,000,745 | ---- | C] () -- C:\Users\ppc\Desktop\PointBlank.lnk
[2016/01/05 19:32:25 | 1175,338,337 | ---- | C] () -- C:\Users\ppc\Desktop\PointBlankSetup_20150813.exe
[2016/01/04 10:13:08 | 000,000,034 | ---- | C] () -- C:\Users\Public\Documents\{DE764086-1C0A-4DD3-90BA-0B93BDD794BE}
[2015/12/27 11:51:49 | 033,370,537 | ---- | C] () -- C:\Users\ppc\Desktop\Video_20151227011759_by_videoshow.mp4
[2015/12/19 16:23:57 | 000,000,337 | ---- | C] () -- C:\Users\ppc\Desktop\Ajuste Navegador.bat
[2015/12/15 16:58:22 | 000,076,487 | ---- | C] () -- C:\Users\ppc\Desktop\óculos-Star-Wars.jpg
[2015/12/15 14:38:08 | 000,061,964 | ---- | C] () -- C:\Users\ppc\Desktop\Star Wars.jpg
[2015/12/15 13:13:08 | 000,000,236 | ---- | C] () -- C:\Users\ppc\Desktop\Chrome Policies.reg
[2015/12/13 00:05:15 | 000,002,315 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2015/12/13 00:04:46 | 000,001,070 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/12/13 00:04:45 | 000,001,066 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/12/10 01:50:46 | 000,724,797 | ---- | C] () -- C:\Users\ppc\Desktop\Uniforme Goias E. C. ---.png
[2015/12/10 01:04:21 | 000,312,366 | ---- | C] () -- C:\Users\ppc\Desktop\Uniforme Goias.png
[2015/12/10 01:03:56 | 000,009,089 | ---- | C] () -- C:\Users\ppc\Desktop\Goias_Esporte_Clube 02.gif
[2015/12/10 01:03:15 | 000,037,125 | ---- | C] () -- C:\Users\ppc\Desktop\goias-esporte-clube 01.gif
[2015/12/03 07:54:44 | 000,015,464 | ---- | C] () -- C:\windows\DelYac64.sys
[2015/05/12 16:09:38 | 000,730,322 | ---- | C] () -- C:\Users\ppc\AppData\Roaming\unins001.exe
[2015/05/12 16:09:37 | 000,017,767 | ---- | C] () -- C:\Users\ppc\AppData\Roaming\unins001.dat
[2015/04/28 17:45:41 | 000,001,067 | ---- | C] () -- C:\Users\ppc\AppData\Roaming\Launch Internet Explorer Browser.lnk
[2015/04/28 10:08:45 | 000,007,605 | ---- | C] () -- C:\Users\ppc\AppData\Local\Resmon.ResmonCfg
[2015/04/27 15:50:28 | 000,000,286 | RHS- | C] () -- C:\ProgramData\ntuser.pol

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009/07/14 02:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015/08/06 16:04:07 | 014,176,768 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015/08/06 15:44:51 | 012,875,776 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 23:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 01:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 23:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections >[/color]
"DefaultConnectionSettings" = 46 00 00 00 20 0B 00 00 03 00 00 00 28 00 00 00 68 74 74 70 3D 31 32 37 2E 30 2E 30 2E 31 3A 38 30 38 30 3B 68 74 74 70 73 3D 31 32 37 2E 30 2E 30 2E 31 3A 38 30 38 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 63 67 81 8B FE 73 CE 01 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 01 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [Binary data over 200 bytes]
"SavedLegacySettings" = 46 00 00 00 6E 0D 00 00 03 00 00 00 28 00 00 00 68 74 74 70 3D 31 32 37 2E 30 2E 30 2E 31 3A 38 30 38 30 3B 68 74 74 70 73 3D 31 32 37 2E 30 2E 30 2E 31 3A 38 30 38 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 63 67 81 8B FE 73 CE 01 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 01 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [Binary data over 200 bytes]

[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 32 bytes -> C:\Program Files (x86)\GbPlugin:u6eBQrM0Z2K3FKLVBMG8dY3IkKT2rqFO+Sf68h8fDg==
@Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:436DEE1E
@Alternate Data Stream - 10 bytes -> C:\Program Files (x86)\GbPlugin:IncompleteStartProcessProtection.cnt

< End of report >

Publicité


Signaler le contenu de ce document

Publicité