Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

MBR secto of the 0 physical disk / Win32/Olmarik.AJL trojan

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

MBR secto of the 0 physical disk / Win32/Olmarik.AJL trojan

Unread postby Bungawunga » May 31st, 2011, 4:23 pm

Hello,

My NOD32 antivirus is accusing this trojan and can't clean it. Need your help.


DDS Log:



.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.7600.16385
Run by Mauricio at 17:12:40 on 2011-05-31
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.55.1033.18.3315.1226 [GMT -3:00]
.
AV: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Windows\system32\taskhost.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Windows\system32\slserv.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\NewSoft\Presto! PVR (Brazil 1 Seg)\Monitor.exe
C:\Windows\System32\aetcrss1.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\iG\Discador.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Combined Community Codec Pack\MPC\mpc-hc.exe
C:\Users\Mauricio\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mauricio\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
C:\Program Files\WBFS\WBFS Manager 3.0\WBFSManager.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Users\Mauricio\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mauricio\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Mauricio\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat.exe
C:\Users\Mauricio\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Mauricio\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\iTunes\iTunes.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Windows\system32\conhost.exe
C:\Users\Mauricio\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Mauricio\Desktop\dds.scr
C:\Windows\system32\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: GbIehObj Class: {c41a1c0e-ea6c-11d4-b1b8-444553540007} - c:\windows\downloaded program files\gbiehabn.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [RESTART_STICKY_NOTES] c:\windows\system32\StikyNot.exe
uRun: [AdobeBridge]
uRun: [DVBV Service Ctrl] c:\program files\dvbviewer\DVBVCtrl.exe
uRun: [Qebabq] c:\users\mauricio\appdata\roaming\Qebabq.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\users\mauricio\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [<NO NAME>]
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
mRun: [ChangeFilterMerit] c:\program files\newsoft\presto! pvr (brazil 1 seg)\ChangeFilterMerit.exe
mRun: [Presto! PVR (1 Seg) Monitor] c:\program files\newsoft\presto! pvr (brazil 1 seg)\Monitor.exe
mRun: [CertificateRegistration] aetcrss1.exe
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\discad~1.lnk - c:\program files\ig\Discador.exe
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com.br/s/v/60.06/uploader2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} - hxxps://wwws.realsecureweb.com.br/mpr/p ... ginABN.cab
TCP: {5D76510F-FD76-470E-9BA4-F00D44FC145A} = 192.168.0.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: acaptuser32.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: GbPluginObj Class: {e37cb5f0-51f5-4395-a808-5fa49e399007} - c:\windows\downloaded program files\gbiehabn.dll
mASetup: aetsprov - c:\windows\system32\regsvr32.exe /s c:\windows\system32\aetsprov.dll
Hosts: 200.220.182.150 wwws.realsecureweb.com.br # GbPlugin
.
============= SERVICES / DRIVERS ===============
.
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-13 20992]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-11-16 735960]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2009-12-18 95896]
R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S2 DVBVRecorder;DVBViewer Recording Service;"c:\program files\dvbviewer\dvbvservice.exe" --> c:\program files\dvbviewer\DVBVservice.exe [?]
S3 AteksoftAudio;WebCamera Plus Audio;c:\windows\system32\drivers\ateksoftaudio.sys [2010-8-18 12288]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2010-4-19 18432]
.
=============== Created Last 30 ================
.
2011-05-31 02:21:29 -------- d-----w- c:\users\mauricio\appdata\local\{87C83643-1811-43A2-8FB5-AABDE665B277}
2011-05-30 19:56:19 -------- d-----w- c:\users\mauricio\appdata\local\Deployment
2011-05-30 19:56:19 -------- d-----w- c:\users\mauricio\appdata\local\Apps
2011-05-30 18:00:52 -------- d-----w- c:\users\mauricio\appdata\roaming\Malwarebytes
2011-05-30 18:00:41 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-30 18:00:41 -------- d-----w- c:\programdata\Malwarebytes
2011-05-30 18:00:38 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-30 18:00:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-30 14:21:29 2329 ----a-w- c:\users\mauricio\appdata\roaming\5490.tmp
2011-05-30 14:21:27 2336 ----a-w- c:\users\mauricio\appdata\roaming\4CCF.tmp
2011-05-30 14:21:25 2328 ----a-w- c:\users\mauricio\appdata\roaming\4675.tmp
2011-05-30 14:20:56 -------- d-----w- c:\users\mauricio\appdata\local\{AAE55D12-13C5-4E42-B4AB-216D287D0311}
2011-05-28 16:59:53 -------- d-----w- c:\users\mauricio\appdata\local\{5ABCB54F-7D1F-4900-9696-A6FB6CC29531}
2011-05-28 04:59:16 -------- d-----w- c:\users\mauricio\appdata\local\{755A1295-D079-4195-A7A0-E8ECC3971EF0}
2011-05-28 04:59:16 -------- d-----w- c:\users\mauricio\appdata\local\{1D8770A4-E402-4407-9B19-C205641AC445}
2011-05-25 17:39:29 -------- d-----w- c:\users\mauricio\appdata\roaming\eBookConverter
2011-05-25 17:39:04 -------- d-----w- c:\program files\eBookConverter
2011-05-25 17:29:17 -------- d-----w- c:\programdata\A-PDF
2011-05-25 17:25:45 -------- d-----w- c:\program files\PDF Drm Removal
2011-05-25 16:52:13 -------- d-----w- C:\Python27
2011-05-24 22:04:10 -------- d-----w- c:\users\mauricio\appdata\local\{2FA2ED82-7129-499C-A18B-12A2BE189916}
2011-05-24 10:03:34 -------- d-----w- c:\users\mauricio\appdata\local\{B71F0F91-3812-4033-A86B-9CC043338169}
2011-05-23 22:03:08 -------- d-----w- c:\users\mauricio\appdata\local\{C2EC6C44-6A30-444C-B08A-2AAD593F613A}
2011-05-23 21:41:22 -------- d-----w- c:\windows\pt-br
2011-05-23 21:39:55 -------- d-----w- c:\windows\en
2011-05-23 21:38:39 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-05-23 21:33:25 2983424 ----a-w- c:\windows\system32\UIRibbon.dll
2011-05-23 21:33:24 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-05-23 21:32:54 94040 ----a-w- c:\program files\common files\windows live\.cache\f8798a1a1cc19900b\DSETUP.dll
2011-05-23 21:32:54 525656 ----a-w- c:\program files\common files\windows live\.cache\f8798a1a1cc19900b\DXSETUP.exe
2011-05-23 21:32:54 1691480 ----a-w- c:\program files\common files\windows live\.cache\f8798a1a1cc19900b\dsetup32.dll
2011-05-23 21:32:50 525656 ----a-w- c:\program files\common files\windows live\.cache\f49b819e1cc19900a\DXSETUP.exe
2011-05-23 21:32:50 1691480 ----a-w- c:\program files\common files\windows live\.cache\f49b819e1cc19900a\dsetup32.dll
2011-05-23 21:32:49 94040 ----a-w- c:\program files\common files\windows live\.cache\f49b819e1cc19900a\DSETUP.dll
2011-05-23 21:32:38 3181568 ----a-w- c:\windows\system32\mf.dll
2011-05-23 21:32:38 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-05-23 21:32:37 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2011-05-23 21:30:56 -------- d-----w- c:\users\mauricio\appdata\local\Windows Live
2011-05-13 15:17:43 -------- d-----w- c:\program files\Boilsoft Video Joiner
.
==================== Find3M ====================
.
2011-05-29 17:02:35 87608 ----a-w- c:\users\mauricio\appdata\roaming\inst.exe
2011-05-29 17:02:35 47360 ----a-w- c:\users\mauricio\appdata\roaming\pcouffin.sys
2011-04-13 22:40:10 4284416 ----a-w- c:\windows\system32\GPhotos.scr
.
============= FINISH: 17:14:16,84 ===============



Attach.txt Log:



.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-05-19.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume3
Install Date: 04/03/2010 17:55:21
System Uptime: 30/05/2011 16:50:07 (25 hours ago)
.
Motherboard: Intel Corporation | | DG33BU
Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz | J1PR | 1580/266mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 233 GiB total, 1,648 GiB free.
D: is FIXED (NTFS) - 1397 GiB total, 128,801 GiB free.
E: is FIXED (NTFS) - 233 GiB total, 98,221 GiB free.
F: is CDROM ()
G: is CDROM ()
I: is FIXED (FAT32) - 205 GiB total, 185,408 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {50dd5230-ba8a-11d1-bf5d-0000f805f530}
Description: Microsoft Usbccid Smartcard Reader (WUDF)
Device ID: USB\VID_08E6&PID_3437\5&2C5EF02D&0&2
Manufacturer: Microsoft
Name: Microsoft Usbccid Smartcard Reader (WUDF)
PNP Device ID: USB\VID_08E6&PID_3437\5&2C5EF02D&0&2
Service: WUDFRd
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: archlp
Device ID: ROOT\LEGACY_ARCSEC\0000
Manufacturer:
Name: archlp
PNP Device ID: ROOT\LEGACY_ARCSEC\0000
Service: ArcSec
.
Class GUID:
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_8086&DEV_29C4&SUBSYS_50448086&REV_02\3&2ACF1E9&0&18
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_8086&DEV_29C4&SUBSYS_50448086&REV_02\3&2ACF1E9&0&18
Service:
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
2007 Microsoft Office Suite Service Pack 1 (SP1)
abgx360 v1.0.5
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
Adobe AIR
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles CS CS4
Adobe CS4 American English Speech Analysis Models
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe Dynamiclink Support
Adobe Encore CS4
Adobe Encore CS4 Codecs
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Linguistics CS4
Adobe Media Encoder CS4
Adobe Media Encoder CS4 Additional Exporter
Adobe Media Encoder CS4 Dolby
Adobe Media Encoder CS4 Exporter
Adobe Media Encoder CS4 Importer
Adobe Media Player
Adobe OnLocation CS4
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Premiere Pro CS4
Adobe Premiere Pro CS4 Functional Content
Adobe Premiere Pro CS4 Third Party Content
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
AIFF MP3 Converter v3.1 build 946
Akamai NetSession Interface
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Assistente de Instalação Certisign
µTorrent
aTube Catcher
Audacity 1.2.6
Audiograbber 1.83 SE
blueMSX
Boilsoft Video Joiner 5.32
Boilsoft Video Splitter 5.21
Bonjour
BrettspielWelt
calibre
CNPJ (PGD) - versão 3.0
Combined Community Codec Pack 2009-09-09
Connect
Corel Graphics - Windows Shell Extension
CorelDRAW Graphics Suite X5
CorelDRAW Graphics Suite X5 - Capture
CorelDRAW Graphics Suite X5 - Common
CorelDRAW Graphics Suite X5 - Connect
CorelDRAW Graphics Suite X5 - Custom Data
CorelDRAW Graphics Suite X5 - Draw
CorelDRAW Graphics Suite X5 - EN
CorelDRAW Graphics Suite X5 - Filters
CorelDRAW Graphics Suite X5 - FontNav
CorelDRAW Graphics Suite X5 - IPM
CorelDRAW Graphics Suite X5 - PHOTO-PAINT
CorelDRAW Graphics Suite X5 - Photozoom Plugin
CorelDRAW Graphics Suite X5 - Redist
CorelDRAW Graphics Suite X5 - Setup Files
CorelDRAW Graphics Suite X5 - VBA
CorelDRAW Graphics Suite X5 - VideoBrowser
CorelDRAW Graphics Suite X5 - VSTA
CorelDRAW Graphics Suite X5 - WT
CorelDRAW(R) Graphics Suite X5
D3DX10
DHTML Editing Component
Discador iG 09.00
EGS Recipe Center
ESET NOD32 Antivirus
FileZilla Client 3.3.2.1
Google Chrome
GrabIt 1.7.2 Beta 4 (build 997)
GroupMail :: Personal Edition
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)
ImgBurn
IrfanView (remove only)
IRPF2011 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva do País
iTunes
Java Auto Updater
Java(TM) 6 Update 24
kuler
KVIrc
Luxor 2
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft Application Error Reporting
Microsoft Office Access MUI (English) 2007
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2007
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2007
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional 2010
Microsoft Office Proof (English) 2007
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2007
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Ultimate 2007
Microsoft Office Word MUI (English) 2007
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual Studio Tools for Applications 2.0 - ENU
Microsoft Visual Studio Tools for Applications 2.0 Runtime
MiraScan 6.3 (5000 series)
MSVCRT
NSIS HeadOverHeels (remove only)
Password Agent 2.5.1
PDF Settings CS4
Photoshop Camera Raw
Picasa 3
Pidgin
Pod to PC 3.245
Presto! PVR (Brazil 1 Seg)
Puerto Rico
Puerto Rico Update 1.060227
Python 2.7 pycrypto-2.3
Python 2.7.1
QuickPar 0.9
QuickTime
Receitanet 2010
Receitanet Java 2010.02d
Rooms - The Main Building 1.00 Patriot Games
SafeSign
Sigil 0.3.4
Skype Toolbars
Skype™ 4.2
Suite Shared Configuration CS4
The Lost Cases Of Sherlock Holmes
Time Adjuster STANDARD 3.1
TweetDeck
Unity Web Player
VirtualCloneDrive
Visual Basic for Applications (R) Core
Visual Basic for Applications (R) Core - English
VOB2MPG v3
VobSub v2.23 (Remove Only)
WBFS Manager 3.0
WinAVI MP4 Converter
WinAVI Video Converter 9.0
Windows Live Communications Platform
Windows Live Essentials
Windows Live Galeria de Fotos
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Media Player Firefox Plugin
Windows Mobile Device Center
Windows Mobile Device Center Driver Update
WinPcap 4.1.1
WinRAR archiver
Winsyntax 2.0
XviD MPEG4 Video Codec (remove only)
.
==== Event Viewer Messages From Past Week ========
.
31/05/2011 17:12:44, Error: Service Control Manager [7016] - The SmartLinkService service has reported an invalid current state 0.
31/05/2011 17:11:32, Error: Microsoft-Windows-SharedAccess_NAT [34001] - The ICS_IPV6 failed to configure IPv6 stack.
30/05/2011 16:50:58, Error: Microsoft-Windows-SharedAccess_NAT [30013] - The DHCP allocator has disabled itself on IP address 192.168.0.1, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.
30/05/2011 16:50:55, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ArcSec
30/05/2011 16:50:36, Error: Service Control Manager [7000] - The DVBViewer Recording Service service failed to start due to the following error: The system cannot find the file specified.
30/05/2011 14:49:05, Error: Microsoft-Windows-SharedAccess_NAT [31004] - The DNS proxy agent was unable to allocate 0 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.
30/05/2011 14:48:58, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.
30/05/2011 14:48:58, Error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
30/05/2011 14:19:17, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
30/05/2011 14:18:54, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
30/05/2011 14:18:52, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
30/05/2011 14:18:45, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
30/05/2011 14:18:45, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
30/05/2011 14:18:41, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
30/05/2011 14:18:34, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
30/05/2011 14:18:27, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD ArcSec CSC DfsC discache ehdrv ElbyCDIO NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The Network Connections service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
30/05/2011 14:18:25, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
30/05/2011 14:12:47, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service VSS with arguments "" in order to run the server: {0B5A2C52-3EB9-470A-96E2-6C6D4570E40F}
30/05/2011 12:33:55, Error: WudfUsbccidDriver [12] - The device generated 472 unknown interrupt(s) in 985 ms. Last Unknown Interrupt Message: 0x63.
30/05/2011 12:33:55, Error: Microsoft-Windows-Smartcard-Server [610] - Smart Card Reader 'Gemplus USB SmartCard Reader 0' rejected IOCTL GET_STATE: The I/O operation has been aborted because of either a thread exit or an application request. If this error persists, your smart card or reader may not be functioning correctly. Command Header: XX XX XX XX
30/05/2011 11:21:13, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
30/05/2011 11:19:46, Error: WudfUsbccidDriver [11] - A Request has returned failure. MsgType: 0x80 ICCStatus: 0x1 CmdStatus: 0x1 Error: 0xfe SW1: 0x0 SW2: 0x0
30/05/2011 11:17:40, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Live ID Sign-in Assistant service to connect.
30/05/2011 11:17:40, Error: Service Control Manager [7000] - The Windows Live ID Sign-in Assistant service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
30/05/2011 11:16:41, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
29/05/2011 11:07:25, Error: WudfUsbccidDriver [12] - The device generated 385 unknown interrupt(s) in 687 ms. Last Unknown Interrupt Message: 0x4.
29/05/2011 11:07:25, Error: WudfUsbccidDriver [1] - An operation has failed (0xa, 0x0, 0x0, 0x0). ScReadWrite: Failed to write request. HResult: The I/O request was canceled.
29/05/2011 11:07:25, Error: WudfUsbccidDriver [1] - An operation has failed (0xa, 0x0, 0x0, 0x0). ScReadWrite: Failed to write request. HResult: A device which does not exist was specified.
29/05/2011 11:07:25, Error: WudfUsbccidDriver [1] - An operation has failed (0x3, 0x0, 0x0, 0x0). ScCardPowerColdReset: IccPowerOff failed. HResult: The I/O request was canceled.
29/05/2011 11:07:25, Error: WudfUsbccidDriver [1] - An operation has failed (0x3, 0x0, 0x0, 0x0). ScCardPowerColdReset: IccPowerOff failed. HResult: A device which does not exist was specified.
29/05/2011 11:07:25, Error: Microsoft-Windows-Smartcard-Server [610] - Smart Card Reader 'Gemplus USB SmartCard Reader 0' rejected IOCTL POWER: The system cannot find the file specified. If this error persists, your smart card or reader may not be functioning correctly. Command Header: 01 00 00 00
29/05/2011 11:07:25, Error: Microsoft-Windows-Smartcard-Server [610] - Smart Card Reader 'Gemplus USB SmartCard Reader 0' rejected IOCTL POWER: The I/O operation has been aborted because of either a thread exit or an application request. If this error persists, your smart card or reader may not be functioning correctly. Command Header: 01 00 00 00
29/05/2011 11:07:24, Error: WudfUsbccidDriver [1] - An operation has failed (0xa, 0x0, 0x0, 0x0). ScReadWrite: Failed to write request. HResult: {Operation Failed} The requested operation was unsuccessful.
29/05/2011 11:07:24, Error: WudfUsbccidDriver [1] - An operation has failed (0x4a, 0x0, 0x0, 0x0). ScReadWrite: Failed to read reply. HResult: {Operation Failed} The requested operation was unsuccessful.
29/05/2011 11:07:24, Error: WudfUsbccidDriver [1] - An operation has failed (0x3, 0x2, 0x0, 0x0). ScCardPowerColdReset: IccPowerOnStatusError HResult: {Operation Failed} The requested operation was unsuccessful.
29/05/2011 11:07:24, Error: WudfUsbccidDriver [1] - An operation has failed (0x3, 0x0, 0x0, 0x0). ScCardPowerColdReset: IccPowerOff failed. HResult: {Operation Failed} The requested operation was unsuccessful.
29/05/2011 11:07:24, Error: Microsoft-Windows-Smartcard-Server [610] - Smart Card Reader 'Gemplus USB SmartCard Reader 0' rejected IOCTL POWER: A device attached to the system is not functioning. If this error persists, your smart card or reader may not be functioning correctly. Command Header: 01 00 00 00
29/05/2011 11:07:23, Error: WudfUsbccidDriver [12] - The device generated 425 unknown interrupt(s) in 125 ms. Last Unknown Interrupt Message: 0x0.
29/05/2011 11:07:13, Error: WudfUsbccidDriver [12] - The device generated 594 unknown interrupt(s) in 360 ms. Last Unknown Interrupt Message: 0x0.
27/05/2011 15:18:09, Error: WudfUsbccidDriver [12] - The device generated 448 unknown interrupt(s) in 312 ms. Last Unknown Interrupt Message: 0x4.
27/05/2011 15:18:01, Error: WudfUsbccidDriver [12] - The device generated 458 unknown interrupt(s) in 203 ms. Last Unknown Interrupt Message: 0x0.
27/05/2011 15:17:45, Error: WudfUsbccidDriver [12] - The device generated 413 unknown interrupt(s) in 968 ms. Last Unknown Interrupt Message: 0x30.
27/05/2011 15:17:38, Error: WudfUsbccidDriver [12] - The device generated 511 unknown interrupt(s) in 265 ms. Last Unknown Interrupt Message: 0x4.
27/05/2011 15:17:19, Error: WudfUsbccidDriver [12] - The device generated 486 unknown interrupt(s) in 640 ms. Last Unknown Interrupt Message: 0x0.
27/05/2011 15:17:14, Error: WudfUsbccidDriver [12] - The device generated 456 unknown interrupt(s) in 468 ms. Last Unknown Interrupt Message: 0x0.
27/05/2011 15:16:52, Error: WudfUsbccidDriver [12] - The device generated 416 unknown interrupt(s) in 46 ms. Last Unknown Interrupt Message: 0x0.
27/05/2011 15:13:24, Error: WudfUsbccidDriver [12] - The device generated 509 unknown interrupt(s) in 656 ms. Last Unknown Interrupt Message: 0x0.
27/05/2011 15:13:24, Error: WudfUsbccidDriver [10] - Request[0](CLS=0x0,INS=0xb0,P1=0x0,P2=0x0,Lc=0,Le=128,.NETServiceMethod=0x0)
27/05/2011 15:13:24, Error: WudfUsbccidDriver [10] - Request[0](CLS=0x0,INS=0xa4,P1=0x4,P2=0xc,Lc=12,Le=0,.NETServiceMethod=0x0)
27/05/2011 15:13:24, Error: WudfUsbccidDriver [10] - Request[0](CLS=0x0,INS=0xa4,P1=0x2,P2=0x0,Lc=2,Le=256,.NETServiceMethod=0x0)
27/05/2011 15:13:24, Error: WudfUsbccidDriver [1] - An operation has failed (0xf, 0x0, 0x0, 0x0). ScReadWrite: Failed to write request. HResult: The I/O request was canceled.
27/05/2011 15:13:24, Error: WudfUsbccidDriver [1] - An operation has failed (0xf, 0x0, 0x0, 0x0). ScReadWrite: Failed to write request. HResult: A device which does not exist was specified.
27/05/2011 15:13:24, Error: WudfUsbccidDriver [1] - An operation has failed (0xf, 0x0, 0x0, 0x0). ScReadWrite: Failed to write request. HResult: {Operation Failed} The requested operation was unsuccessful.
27/05/2011 15:13:24, Error: WudfUsbccidDriver [1] - An operation has failed (0x10d, 0x0, 0x0, 0x0). ScReadWrite: Failed to read reply. HResult: {Operation Failed} The requested operation was unsuccessful.
27/05/2011 15:13:24, Error: WudfUsbccidDriver [1] - An operation has failed (0x0, 0x0, 0x0, 0x0). ScT1Transmit: Failed to send TPDU level request. HResult: The I/O request was canceled.
27/05/2011 15:13:24, Error: WudfUsbccidDriver [1] - An operation has failed (0x0, 0x0, 0x0, 0x0). ScT1Transmit: Failed to send TPDU level request. HResult: A device which does not exist was specified.
27/05/2011 15:13:24, Error: WudfUsbccidDriver [1] - An operation has failed (0x0, 0x0, 0x0, 0x0). ScT1Transmit: Failed to send TPDU level request. HResult: {Operation Failed} The requested operation was unsuccessful.
27/05/2011 15:13:24, Error: Microsoft-Windows-Smartcard-Server [610] - Smart Card Reader 'Gemplus USB SmartCard Reader 0' rejected IOCTL TRANSMIT: The system cannot find the file specified. If this error persists, your smart card or reader may not be functioning correctly. Command Header: 00 a4 04 0c
27/05/2011 15:13:24, Error: Microsoft-Windows-Smartcard-Server [610] - Smart Card Reader 'Gemplus USB SmartCard Reader 0' rejected IOCTL TRANSMIT: The system cannot find the file specified. If this error persists, your smart card or reader may not be functioning correctly. Command Header: 00 a4 02 00
27/05/2011 15:13:24, Error: Microsoft-Windows-Smartcard-Server [610] - Smart Card Reader 'Gemplus USB SmartCard Reader 0' rejected IOCTL TRANSMIT: The I/O operation has been aborted because of either a thread exit or an application request. If this error persists, your smart card or reader may not be functioning correctly. Command Header: 00 a4 04 0c
27/05/2011 15:13:24, Error: Microsoft-Windows-Smartcard-Server [610] - Smart Card Reader 'Gemplus USB SmartCard Reader 0' rejected IOCTL TRANSMIT: A device attached to the system is not functioning. If this error persists, your smart card or reader may not be functioning correctly. Command Header: 00 b0 00 00
27/05/2011 15:13:24, Error: Microsoft-Windows-Smartcard-Server [610] - Smart Card Reader 'Gemplus USB SmartCard Reader 0' rejected IOCTL TRANSMIT: A device attached to the system is not functioning. If this error persists, your smart card or reader may not be functioning correctly. Command Header: 00 a4 04 0c
27/05/2011 15:13:23, Error: WudfUsbccidDriver [12] - The device generated 390 unknown interrupt(s) in 1640 ms. Last Unknown Interrupt Message: 0x0.
27/05/2011 15:13:22, Error: WudfUsbccidDriver [10] - Request[0](CLS=0x80,INS=0xf2,P1=0x0,P2=0x83,Lc=0,Le=1,.NETServiceMethod=0x0)
27/05/2011 15:13:22, Error: WudfUsbccidDriver [1] - An operation has failed (0x13, 0x0, 0x0, 0x0). ScReadWrite: Failed to write request. HResult: {Operation Failed} The requested operation was unsuccessful.
27/05/2011 15:13:22, Error: Microsoft-Windows-Smartcard-Server [610] - Smart Card Reader 'Gemplus USB SmartCard Reader 0' rejected IOCTL TRANSMIT: A device attached to the system is not functioning. If this error persists, your smart card or reader may not be functioning correctly. Command Header: 80 f2 00 83
27/05/2011 15:13:21, Error: WudfUsbccidDriver [12] - The device generated 439 unknown interrupt(s) in 578 ms. Last Unknown Interrupt Message: 0x4.
27/05/2011 15:03:14, Error: WudfUsbccidDriver [12] - The device generated 1497 unknown interrupt(s) in 328 ms. Last Unknown Interrupt Message: 0x0.
25/05/2011 14:27:41, Error: WudfUsbccidDriver [12] - The device generated 757 unknown interrupt(s) in 813 ms. Last Unknown Interrupt Message: 0x0.
25/05/2011 09:18:07, Error: WudfUsbccidDriver [12] - The device generated 451 unknown interrupt(s) in 46 ms. Last Unknown Interrupt Message: 0x4.
25/05/2011 08:46:39, Error: WudfUsbccidDriver [12] - The device generated 465 unknown interrupt(s) in 46 ms. Last Unknown Interrupt Message: 0x0.
25/05/2011 01:41:46, Error: WudfUsbccidDriver [12] - The device generated 461 unknown interrupt(s) in 657 ms. Last Unknown Interrupt Message: 0x0.
25/05/2011 01:09:40, Error: WudfUsbccidDriver [11] - A Request has returned failure. MsgType: 0x80 ICCStatus: 0x1 CmdStatus: 0x1 Error: 0xf8 SW1: 0x0 SW2: 0x0
25/05/2011 01:09:40, Error: WudfUsbccidDriver [1] - An operation has failed (0x3, 0x3, 0x41, 0xf8). ScCardPowerColdReset: IccPowerOnStatusError HResult: A protocol error was detected between the driver and the device.
.
==== End Of File ===========================


Can you help me?

Thanks.
Bungawunga
Active Member
 
Posts: 3
Joined: May 31st, 2011, 4:19 pm
Advertisement
Register to Remove

Re: MBR secto of the 0 physical disk / Win32/Olmarik.AJL tro

Unread postby deltalima » June 3rd, 2011, 5:35 am

Checking your log - back soon.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: MBR secto of the 0 physical disk / Win32/Olmarik.AJL tro

Unread postby deltalima » June 3rd, 2011, 5:44 am

Hi Bungawunga,

Welcome to the forum.

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Please note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please do not run any scans or make any changes to the system unless I ask you too.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • If after 3 days you have not responded to this topic, it will be closed, and you will need to start a new one.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please Note:
The programs I ask you to run need to be run in Administrator Mode by... Right clicking the program file and selecting: Run as Administrator.
Additionally, the built-in User Account Control (UAC) utility, if enabled, may prompt you for permission to run the program.
When prompted, please select: Allow. Reference: User Account Control (UAC) and Running as Administrator

Remove P2P Programs

  • I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    µTorrent


  • Please read the Guidelines for P2P Programs where we explain why it's not a good idea to have them.
  • Note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

  • Click on start
  • Then Run
  • In the open text entry box please copy/paste appwiz.cpl Then click enter.
  • Press the "Remove" or "Change/Remove"...button to uninstall the programs listed above (in red) and any other P2P you have installed NOW.
  • Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.

CKScanner

  • Please download CKScanner from here to your Desktop.
  • Make sure that CKScanner.exe is on the your Desktop before running the application!
  • Right click on CKScanner.exe and select: Run as Administrator then click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify the file saved
  • Double-click on the CKFiles.txt icon on your Desktop and copy/paste the contents in your next reply.

Next

  • Please download this tool from Microsoft.
  • Right click on MGADiag.exe and select: Run as Administrator.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in the window.
  • Save this file and copy/paste it in your next reply.

Please let me know if the computer is used for home or for business use.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: MBR secto of the 0 physical disk / Win32/Olmarik.AJL tro

Unread postby Bungawunga » June 5th, 2011, 6:44 pm

Hi,

This computer is a home computer.


CKScanner:

CKScanner - Additional Security Risks - These are not necessarily bad
c:\program files\adobe\adobe premiere pro cs4\plug-ins\en_us\vstplugins\decrackler1.dll
c:\program files\adobe\adobe premiere pro cs4\plug-ins\en_us\vstplugins\decrackler2.dll
c:\program files\adobe\adobe premiere pro cs4\plug-ins\en_us\vstplugins\decrackler6.dll
c:\program files\corel\coreldraw graphics suite x5\custom data\bumpmap\cracks.cpt
c:\users\mauricio\downloads\ebooks\ibooks\the mirror crack's from side to side - christie_ agatha.epub
scanner sequence 3.EM.11
----- EOF -----



MGAdiag:

Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->

Validation Code: 0
Cached Online Validation Code: N/A, hr = 0xc004f012
Windows Product Key: *****-*****-YG69F-9M66D-PMJBM
Windows Product Key Hash: /kehptF9HHVxM5d8dUnqgcfndXw=
Windows Product ID: 00426-OEM-8992662-00497
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7600.2.00010100.0.0.001
ID: {8909E4B6-066E-4665-99F8-6DF4FD675EF7}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Ultimate
Architecture: 0x00000000
Build lab: 7600.win7_rtm.090713-1255
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 100 Genuine
Microsoft Office Ultimate 2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-2ee7_E2AD56EA-148-80004005_16E0B333-89-80004005_B4D0AA8B-1029-80004005

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Users\Mauricio\AppData\Local\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->
File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[Hr = 0x80070003]
File Mismatch: C:\Windows\system32\wat\npwatweb.dll[Hr = 0x80070003]
File Mismatch: C:\Windows\system32\wat\watux.exe[Hr = 0x80070003]
File Mismatch: C:\Windows\system32\wat\watweb.dll[Hr = 0x80070003]
File Mismatch: C:\Windows\system32\sppcomapi.dll[Hr = 0x80070005]
File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7600.16385], Hr = 0x800b0100
File Mismatch: C:\Windows\system32\en-US\user32.dll.mui[6.1.7600.16385], Hr = 0x800b0100

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{8909E4B6-066E-4665-99F8-6DF4FD675EF7}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7600.2.00010100.0.0.001</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-PMJBM</PKey><PID>00426-OEM-8992662-00497</PID><PIDType>2</PIDType><SID>S-1-5-21-960887255-1984203283-169081182</SID><SYSTEM><Manufacturer>INTEL_</Manufacturer><Model>DG33BU__</Model></SYSTEM><BIOS><Manufacturer>Intel Corp.</Manufacturer><Version>DPP3510J.86A.0293.2007.1002.1519</Version><SMBIOSVersion major="2" minor="4"/><Date>20071002000000.000000+000</Date></BIOS><HWID>2AB93607018400FA</HWID><UserLCID>0416</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>SA Eastern Standard Time(GMT-03:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>_ASUS_</OEMID><OEMTableID>Notebook</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-002E-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Ultimate 2007</Name><Ver>12</Ver><Val>537D6E002A8C6BA</Val><Hash>YGJCgB5N0/NvS6CEg++RnrU1NUk=</Hash><Pid>81608-861-1030037-65171</Pid><PidType>8</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="44" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/><App Id="BA" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>

Spsys.log Content: 0x80070002

Licensing Data-->
Input Error: Can not find script file "C:\Windows\system32\slmgr.vbs".

Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: N/A
HealthStatus: 0x0000000000000000
Event Time Stamp: N/A
ActiveX: Not Registered - 0x80040154
Admin Service: Not Registered - 0x80040154
HealthStatus Bitmask Output:


HWID Data-->
HWID Hash Current: OgAAAAIABgABAAEAAQABAAAAAgABAAEA6GHq2U403Kxk/t7UiP3GmBSrFvE2OmKE3oiE+la4BOvMMQ==

OEM Activation 1.0 Data-->
N/A

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC INTEL DG33BU
FACP INTEL DG33BU
MCFG INTEL DG33BU
WDDT INTEL DG33BU
ASF! INTEL DG33BU
SSDT INTEL CpuPm
SSDT INTEL CpuPm
SSDT INTEL CpuPm
SSDT INTEL CpuPm
SSDT INTEL CpuPm
SSDT INTEL CpuPm
SSDT INTEL CpuPm
SSDT INTEL CpuPm
SSDT INTEL CpuPm
SLIC _ASUS_ Notebook

Thanks.
Bungawunga
Active Member
 
Posts: 3
Joined: May 31st, 2011, 4:19 pm

Re: MBR secto of the 0 physical disk / Win32/Olmarik.AJL tro

Unread postby deltalima » June 5th, 2011, 7:08 pm

Hi Bungawunga,

Upload a File to Virustotal

Please go to Virustotal

Copy/paste this file and path into the white box at the top:
c:\users\mauricio\appdata\roaming\Qebabq.exe

Press Submit - this will submit the file for testing.
Please wait for all the scanners to finish then copy and paste the results in your next response.

Download and run OTL
Download OTL by Old Timer and save it to your Desktop.
  • Right click on OTL.exe and select: Run as Administrator.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened
    • Extras.txt <-- Will be minimized
  • Please post the contents of these 2 Notepad files in your next reply.

Please download GMER Rootkit Scanner from here.
  • Right click the .exe file and select: Run as Administrator.. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
  • Run Gmer again and click on the Rootkit tab.
  • Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
  • Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
  • Click on the "Scan" and wait for the scan to finish.
    Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
  • When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
  • Note: If you have any problems, try running GMER in SAFE MODE
Important! Please do not select the "Show all" checkbox during the scan..

Please post the GMER log along with OTL.txt and Extras.txt from the OTL scan into your next reply.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: MBR secto of the 0 physical disk / Win32/Olmarik.AJL tro

Unread postby Bungawunga » June 6th, 2011, 1:43 pm

Hi,

Couldn't upload c:\users\mauricio\appdata\roaming\Qebabq.exe to Virustotal - this file does not exist.

OTL.txt:

OTL logfile created on: 06/06/2011 13:28:19 - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Mauricio\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

3,24 Gb Total Physical Memory | 0,86 Gb Available Physical Memory | 26,55% Memory free
6,47 Gb Paging File | 3,60 Gb Available in Paging File | 55,63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 1,57 Gb Free Space | 0,67% Space Free | Partition Type: NTFS
Drive D: | 1397,26 Gb Total Space | 230,80 Gb Free Space | 16,52% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 98,22 Gb Free Space | 42,18% Space Free | Partition Type: NTFS
Drive F: | 4,20 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive I: | 205,49 Gb Total Space | 194,16 Gb Free Space | 94,49% Space Free | Partition Type: FAT32
Drive J: | 7,39 Gb Total Space | 7,39 Gb Free Space | 100,00% Space Free | Partition Type: FAT32

Computer Name: DESKTOP-PC | User Name: Mauricio | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mauricio\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
PRC - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\iG\Discador.exe ()
PRC - C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\NewSoft\Presto! PVR (Brazil 1 Seg)\Monitor.exe (NewSoft)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Windows\System32\aetcrss1.exe (A.E.T. Europe B.V.)


========== Modules (SafeList) ==========

MOD - C:\Users\Mauricio\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (DVBVRecorder) -- File not found
SRV - (Akamai) -- c:\Program Files\Common Files\Akamai\netsession_win_8832f4b.dll ()
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (PSI_SVC_2) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (EhttpSrv) -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WAS) -- C:\Windows\System32\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (W3SVC) -- C:\Windows\System32\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (AppHostSvc) -- C:\Windows\System32\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV - (SLService) -- C:\Windows\System32\slserv.exe ( )
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (Netaapl) -- C:\Windows\System32\drivers\netaapl.sys (Apple Inc.)
DRV - (epfwwfpr) -- C:\Windows\System32\drivers\epfwwfpr.sys (ESET)
DRV - (npf) -- C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (ehdrv) -- C:\Windows\System32\drivers\ehdrv.sys (ESET)
DRV - (eamon) -- C:\Windows\System32\drivers\eamon.sys (ESET)
DRV - (AteksoftAudio) -- C:\Windows\System32\drivers\ateksoftaudio.sys (Ateksoft)
DRV - (vmbus) -- C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WINUSB) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (RTL8023xp) -- C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (e1express) Intel(R) -- C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (Slntamr) -- C:\Windows\System32\drivers\slntamr.sys ( )
DRV - (SlNtHal) -- C:\Windows\System32\drivers\slnthal.sys ( )
DRV - (SlWdmSup) -- C:\Windows\System32\drivers\slwdmsup.sys (Vireo Software)
DRV - (Mtlstrm) -- C:\Windows\System32\drivers\mtlstrm.sys ( )
DRV - (Mtlmnt5) -- C:\Windows\System32\drivers\mtlmnt5.sys ( )
DRV - (NtMtlFax) -- C:\Windows\System32\drivers\ntmtlfax.sys ( )
DRV - (mod7700) -- C:\Windows\System32\drivers\mod7700.sys (DiBcom SA)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-960887255-1984203283-169081182-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://br.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-960887255-1984203283-169081182-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://br.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-960887255-1984203283-169081182-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-br
IE - HKU\S-1-5-21-960887255-1984203283-169081182-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 5C 66 DD DE 49 1D CC 01 [binary data]
IE - HKU\S-1-5-21-960887255-1984203283-169081182-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-960887255-1984203283-169081182-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/03/05 09:17:18 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2011/05/30 11:23:07 | 000,000,056 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 200.220.182.150 wwws.realsecureweb.com.br # GbPlugin
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\Windows\Downloaded Program Files\gbiehabn.dll (Banco Real)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-960887255-1984203283-169081182-1003\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CertificateRegistration] C:\Windows\System32\aetcrss1.exe (A.E.T. Europe B.V.)
O4 - HKLM..\Run: [ChangeFilterMerit] C:\Program Files\NewSoft\Presto! PVR (Brazil 1 Seg)\ChangeFilterMerit.exe (NewSoft)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Presto! PVR (1 Seg) Monitor] C:\Program Files\NewSoft\Presto! PVR (Brazil 1 Seg)\Monitor.exe (NewSoft)
O4 - HKU\S-1-5-21-960887255-1984203283-169081182-1003..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-960887255-1984203283-169081182-1003..\Run: [DVBV Service Ctrl] File not found
O4 - HKU\S-1-5-21-960887255-1984203283-169081182-1003..\Run: [Qebabq] File not found
O4 - HKU\S-1-5-21-960887255-1984203283-169081182-1003..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-960887255-1984203283-169081182-1003..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10m_ActiveX.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-960887255-1984203283-169081182-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com.br/s/v/60.06/uploader2.cab (UploadListView Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} https://wwws.realsecureweb.com.br/mpr/p ... ginABN.cab (GbPluginObj Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 201.6.0.106 201.6.0.104
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (acaptuser32.dll) - C:\Windows\System32\acaptuser32.dll (Adobe Systems, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399007} - C:\Windows\Downloaded Program Files\gbiehabn.dll (Banco Real)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 18:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{1e355a8c-6a81-11e0-93a1-f6220c7756ac}\Shell - "" = AutoRun
O33 - MountPoints2\{1e355a8c-6a81-11e0-93a1-f6220c7756ac}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/06 13:26:46 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\Mauricio\Desktop\OTL.exe
[2011/06/06 12:34:57 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\{323D7024-AD3D-4045-846F-17BD78F3CB50}
[2011/06/05 19:38:56 | 000,000,000 | ---D | C] -- C:\MGADiagToolOutput
[2011/06/05 19:33:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage
[2011/06/05 19:25:42 | 002,031,992 | ---- | C] (Microsoft Corporation) -- C:\Users\Mauricio\Desktop\MGADiag.exe
[2011/06/02 15:04:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aiseesoft
[2011/06/02 15:04:17 | 000,000,000 | ---D | C] -- C:\Program Files\Aiseesoft Studio
[2011/06/02 14:46:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Aiseesoft Studio
[2011/06/02 14:37:58 | 000,000,000 | ---D | C] -- C:\ConverterOutput
[2011/06/02 14:37:56 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\Documents\Cucusoft
[2011/06/01 15:54:04 | 000,000,000 | ---D | C] -- C:\Windows\System32\appmgmt
[2011/05/31 17:12:32 | 000,606,738 | R--- | C] (Swearware) -- C:\Users\Mauricio\Desktop\dds.scr
[2011/05/30 23:21:29 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\{87C83643-1811-43A2-8FB5-AABDE665B277}
[2011/05/30 16:58:33 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/05/30 16:56:19 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\Deployment
[2011/05/30 16:56:19 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\Apps
[2011/05/30 15:00:52 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Roaming\Malwarebytes
[2011/05/30 15:00:41 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/30 15:00:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/30 15:00:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/05/30 15:00:38 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/05/30 15:00:38 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/30 14:58:51 | 007,734,240 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Mauricio\Desktop\mbam-setup.exe
[2011/05/30 11:20:56 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\{AAE55D12-13C5-4E42-B4AB-216D287D0311}
[2011/05/28 13:59:53 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\{5ABCB54F-7D1F-4900-9696-A6FB6CC29531}
[2011/05/28 01:59:16 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\{755A1295-D079-4195-A7A0-E8ECC3971EF0}
[2011/05/28 01:59:16 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\{1D8770A4-E402-4407-9B19-C205641AC445}
[2011/05/25 14:39:29 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\Documents\PDF ePub DRM Removal
[2011/05/25 14:39:29 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Roaming\eBookConverter
[2011/05/25 14:39:04 | 000,000,000 | ---D | C] -- C:\Program Files\eBookConverter
[2011/05/25 14:29:17 | 000,000,000 | ---D | C] -- C:\ProgramData\A-PDF
[2011/05/25 14:25:45 | 000,000,000 | ---D | C] -- C:\Program Files\PDF Drm Removal
[2011/05/25 13:59:17 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\Documents\My Digital Editions
[2011/05/25 13:52:13 | 000,000,000 | ---D | C] -- C:\Python27
[2011/05/24 19:04:10 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\{2FA2ED82-7129-499C-A18B-12A2BE189916}
[2011/05/24 07:03:34 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\{B71F0F91-3812-4033-A86B-9CC043338169}
[2011/05/23 19:03:08 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\{C2EC6C44-6A30-444C-B08A-2AAD593F613A}
[2011/05/23 18:41:22 | 000,000,000 | ---D | C] -- C:\Windows\pt-br
[2011/05/23 18:39:55 | 000,000,000 | ---D | C] -- C:\Windows\en
[2011/05/23 18:38:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2011/05/23 18:33:25 | 002,983,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbon.dll
[2011/05/23 18:33:24 | 001,164,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UIRibbonRes.dll
[2011/05/23 18:32:38 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mf.dll
[2011/05/23 18:32:38 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfreadwrite.dll
[2011/05/23 18:32:37 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2011/05/23 18:30:56 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\AppData\Local\Windows Live
[2011/05/13 12:17:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boilsoft Video Joiner
[2011/05/13 12:17:43 | 000,000,000 | ---D | C] -- C:\Program Files\Boilsoft Video Joiner
[2011/05/10 12:39:15 | 000,000,000 | ---D | C] -- C:\Users\Mauricio\Documents\Assessoria de Imprensa
[2010/05/17 18:15:19 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Mauricio\AppData\Roaming\pcouffin.sys
[2009/11/04 10:34:48 | 000,545,528 | ---- | C] ( ) -- C:\Windows\System32\drivers\slntamr.sys
[2009/11/04 10:34:48 | 000,086,128 | ---- | C] ( ) -- C:\Windows\System32\drivers\slnthal.sys
[2009/11/04 10:34:48 | 000,045,056 | ---- | C] ( ) -- C:\Windows\System32\slserv.exe
[2009/11/04 10:34:47 | 001,301,128 | ---- | C] ( ) -- C:\Windows\System32\drivers\mtlstrm.sys
[2009/11/04 10:34:47 | 000,221,736 | ---- | C] ( ) -- C:\Windows\System32\drivers\mtlmnt5.sys
[2009/11/04 10:34:47 | 000,167,384 | ---- | C] ( ) -- C:\Windows\System32\drivers\ntmtlfax.sys
[3 C:\Users\Mauricio\AppData\Roaming\*.tmp files -> C:\Users\Mauricio\AppData\Roaming\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/06/06 13:27:06 | 000,302,592 | ---- | M] () -- C:\Users\Mauricio\Desktop\zflojcqf.exe
[2011/06/06 13:26:56 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Mauricio\Desktop\OTL.exe
[2011/06/06 13:02:00 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-960887255-1984203283-169081182-1003UA.job
[2011/06/05 23:03:07 | 000,002,414 | ---- | M] () -- C:\Users\Mauricio\Desktop\Google Chrome.lnk
[2011/06/05 19:38:54 | 000,021,904 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/05 19:38:54 | 000,021,904 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/05 19:25:48 | 002,031,992 | ---- | M] (Microsoft Corporation) -- C:\Users\Mauricio\Desktop\MGADiag.exe
[2011/06/05 19:25:26 | 000,453,632 | ---- | M] () -- C:\Users\Mauricio\Desktop\CKScanner.exe
[2011/06/05 19:00:00 | 000,000,382 | ---- | M] () -- C:\Windows\tasks\At1.job
[2011/06/05 17:07:37 | 000,001,014 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-960887255-1984203283-169081182-1003Core.job
[2011/06/02 15:04:20 | 000,001,464 | ---- | M] () -- C:\Users\Mauricio\Desktop\Aiseesoft iPhone 4 Movie Converter.lnk
[2011/06/02 12:24:38 | 000,673,456 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/06/02 12:24:38 | 000,126,628 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/05/31 17:12:30 | 000,606,738 | R--- | M] (Swearware) -- C:\Users\Mauricio\Desktop\dds.scr
[2011/05/30 16:50:59 | 000,000,436 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2011/05/30 16:50:36 | 000,000,312 | -HS- | M] () -- C:\Windows\tasks\Wtiap.job
[2011/05/30 16:50:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/05/30 16:50:17 | 2606,866,432 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/30 15:12:20 | 007,734,240 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Mauricio\Desktop\mbam-setup.exe
[2011/05/30 15:10:30 | 001,007,108 | ---- | M] () -- C:\Users\Mauricio\Desktop\iExplore.exe
[2011/05/30 15:00:41 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/30 14:48:01 | 000,011,036 | -HS- | M] () -- C:\Users\Mauricio\AppData\Local\i6v0d26k4nt402vp5151nj05o4cqr4i5
[2011/05/30 14:22:02 | 000,011,040 | -HS- | M] () -- C:\ProgramData\i6v0d26k4nt402vp5151nj05o4cqr4i5
[2011/05/30 14:17:10 | 000,000,000 | ---- | M] () -- C:\Users\Mauricio\AppData\Local\{3E9EC71D-7935-4AA7-BFE5-DB610E04FE53}
[2011/05/30 11:23:07 | 000,000,056 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/05/30 11:10:12 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2011/05/30 11:10:12 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2011/05/29 14:02:35 | 000,087,608 | ---- | M] () -- C:\Users\Mauricio\AppData\Roaming\inst.exe
[2011/05/29 14:02:35 | 000,047,360 | ---- | M] (VSO Software) -- C:\Users\Mauricio\AppData\Roaming\pcouffin.sys
[2011/05/29 14:02:35 | 000,007,887 | ---- | M] () -- C:\Users\Mauricio\AppData\Roaming\pcouffin.cat
[2011/05/29 14:02:35 | 000,001,144 | ---- | M] () -- C:\Users\Mauricio\AppData\Roaming\pcouffin.inf
[2011/05/23 18:38:39 | 000,000,020 | ---- | M] () -- C:\Windows\xôI
[2011/05/22 20:13:25 | 000,136,438 | ---- | M] () -- C:\Users\Mauricio\Desktop\Aniversário Kátia_Valéria_Márcio_2.jpg
[2011/05/22 20:13:25 | 000,132,430 | ---- | M] () -- C:\Users\Mauricio\Desktop\Aniversário Kátia_Valéria_Márcio_1.jpg
[2011/05/13 20:13:22 | 002,398,144 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/05/08 01:44:32 | 000,140,760 | ---- | M] () -- C:\Users\Mauricio\Desktop\vilacidadejardim.jpg
[3 C:\Users\Mauricio\AppData\Roaming\*.tmp files -> C:\Users\Mauricio\AppData\Roaming\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/06 13:27:03 | 000,302,592 | ---- | C] () -- C:\Users\Mauricio\Desktop\zflojcqf.exe
[2011/06/05 19:25:21 | 000,453,632 | ---- | C] () -- C:\Users\Mauricio\Desktop\CKScanner.exe
[2011/06/02 15:04:20 | 000,001,464 | ---- | C] () -- C:\Users\Mauricio\Desktop\Aiseesoft iPhone 4 Movie Converter.lnk
[2011/05/30 16:58:37 | 000,002,414 | ---- | C] () -- C:\Users\Mauricio\Desktop\Google Chrome.lnk
[2011/05/30 16:57:23 | 000,001,066 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-960887255-1984203283-169081182-1003UA.job
[2011/05/30 16:57:23 | 000,001,014 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-960887255-1984203283-169081182-1003Core.job
[2011/05/30 15:00:41 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/30 14:58:51 | 001,007,108 | ---- | C] () -- C:\Users\Mauricio\Desktop\iExplore.exe
[2011/05/30 14:17:10 | 000,000,000 | ---- | C] () -- C:\Users\Mauricio\AppData\Local\{3E9EC71D-7935-4AA7-BFE5-DB610E04FE53}
[2011/05/30 11:10:25 | 000,000,312 | -HS- | C] () -- C:\Windows\tasks\Wtiap.job
[2011/05/30 11:10:12 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2011/05/30 11:10:12 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2011/05/30 11:10:00 | 000,011,040 | -HS- | C] () -- C:\ProgramData\i6v0d26k4nt402vp5151nj05o4cqr4i5
[2011/05/30 11:10:00 | 000,011,036 | -HS- | C] () -- C:\Users\Mauricio\AppData\Local\i6v0d26k4nt402vp5151nj05o4cqr4i5
[2011/05/23 18:39:34 | 000,001,251 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/05/23 18:38:51 | 000,001,320 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/05/23 18:38:39 | 000,000,020 | ---- | C] () -- C:\Windows\xôI
[2011/05/23 18:37:37 | 000,002,432 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/05/22 20:13:25 | 000,136,438 | ---- | C] () -- C:\Users\Mauricio\Desktop\Aniversário Kátia_Valéria_Márcio_2.jpg
[2011/05/22 20:13:25 | 000,132,430 | ---- | C] () -- C:\Users\Mauricio\Desktop\Aniversário Kátia_Valéria_Márcio_1.jpg
[2011/05/08 01:44:53 | 000,140,760 | ---- | C] () -- C:\Users\Mauricio\Desktop\vilacidadejardim.jpg
[2011/04/18 12:41:15 | 000,069,632 | ---- | C] () -- C:\Windows\System32\MSJCE.dll
[2011/04/07 00:27:44 | 000,000,917 | ---- | C] () -- C:\Windows\System32\CLWatson.ini
[2010/12/25 08:38:50 | 000,000,551 | ---- | C] () -- C:\Users\Mauricio\AppData\Roaming\AutoGK.ini
[2010/12/06 10:58:56 | 002,496,715 | ---- | C] () -- C:\Windows\System32\abgx360.exe
[2010/10/20 16:38:51 | 000,000,039 | ---- | C] () -- C:\Windows\cnpj010.INI
[2010/08/09 16:24:23 | 000,057,344 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010/07/22 16:48:26 | 000,128,000 | ---- | C] () -- C:\Windows\DesinstWRecnet.EXE
[2010/07/22 16:48:26 | 000,122,880 | ---- | C] () -- C:\Windows\DesinstRecnet.exe
[2010/07/22 16:48:26 | 000,005,361 | ---- | C] () -- C:\Windows\DesinstWRecnet.ini
[2010/07/22 16:48:26 | 000,000,129 | ---- | C] () -- C:\Windows\REC-NET.INI
[2010/07/22 16:47:57 | 000,027,136 | ---- | C] () -- C:\Windows\System32\WiseDLL.dll
[2010/06/23 19:00:48 | 000,000,600 | ---- | C] () -- C:\Users\Mauricio\AppData\Local\PUTTY.RND
[2010/05/17 18:21:58 | 000,001,041 | ---- | C] () -- C:\Users\Mauricio\AppData\Roaming\vso_ts_preview.xml
[2010/05/17 18:15:19 | 000,087,608 | ---- | C] () -- C:\Users\Mauricio\AppData\Roaming\inst.exe
[2010/05/17 18:15:19 | 000,007,887 | ---- | C] () -- C:\Users\Mauricio\AppData\Roaming\pcouffin.cat
[2010/05/17 18:15:19 | 000,001,144 | ---- | C] () -- C:\Users\Mauricio\AppData\Roaming\pcouffin.inf
[2010/05/10 18:04:01 | 000,005,632 | ---- | C] () -- C:\Users\Mauricio\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/10 15:58:07 | 000,000,096 | ---- | C] () -- C:\Users\Mauricio\AppData\Local\fusioncache.dat
[2010/03/11 11:22:21 | 000,003,452 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010/03/11 11:22:21 | 000,000,008 | RHS- | C] () -- C:\ProgramData\2E9D1D68D0.sys
[2010/03/05 14:09:34 | 000,683,801 | ---- | C] () -- C:\Users\Mauricio\AppData\Roaming\unins000.exe
[2010/03/05 14:09:34 | 000,019,421 | ---- | C] () -- C:\Users\Mauricio\AppData\Roaming\unins000.dat
[2010/03/05 10:13:59 | 000,024,576 | ---- | C] () -- C:\Windows\System32\snEUps.dll
[2010/03/05 09:16:56 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/11/16 13:33:38 | 000,053,299 | ---- | C] () -- C:\Windows\System32\pthreadVC.dll
[2009/11/04 10:34:48 | 000,188,416 | ---- | C] () -- C:\Windows\System32\slextspk.dll
[2009/11/04 10:34:48 | 000,159,744 | ---- | C] () -- C:\Windows\System32\SLGen.dll
[2009/11/04 10:34:48 | 000,024,576 | ---- | C] () -- C:\Windows\slrundll.exe
[2009/11/04 10:34:47 | 000,049,152 | ---- | C] () -- C:\Windows\System32\coinst.dll
[2009/07/14 01:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 01:33:53 | 002,398,144 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 23:05:48 | 000,673,456 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 23:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 23:05:48 | 000,126,628 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 23:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 23:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 23:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 21:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 20:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 20:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 20:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/07/13 20:36:08 | 000,193,024 | ---- | C] () -- C:\Windows\System32\sppcomapi.dll
[2009/06/10 18:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/06/07 08:27:20 | 000,073,728 | ---- | C] () -- C:\Windows\System32\vbzlib1.dll
[2009/01/25 18:10:48 | 000,179,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/01/08 20:01:22 | 000,629,760 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2007/04/21 10:45:38 | 000,118,586 | -H-- | C] () -- C:\Windows\CheckOldRCS.exe
[2002/10/15 19:54:04 | 000,153,088 | ---- | C] () -- C:\Windows\System32\unrar.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 2 bytes -> C:\Windows\System32:C9DACA9F_Abn.gbp
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:F9E10A82
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:47626ACA
@Alternate Data Stream - 100 bytes -> C:\Windows\System32\drivers:GbpKmAp.lst

< End of report >



Extras.txt:

OTL Extras logfile created on: 06/06/2011 13:28:19 - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Mauricio\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

3,24 Gb Total Physical Memory | 0,86 Gb Available Physical Memory | 26,55% Memory free
6,47 Gb Paging File | 3,60 Gb Available in Paging File | 55,63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 1,57 Gb Free Space | 0,67% Space Free | Partition Type: NTFS
Drive D: | 1397,26 Gb Total Space | 230,80 Gb Free Space | 16,52% Space Free | Partition Type: NTFS
Drive E: | 232,88 Gb Total Space | 98,22 Gb Free Space | 42,18% Space Free | Partition Type: NTFS
Drive F: | 4,20 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive I: | 205,49 Gb Total Space | 194,16 Gb Free Space | 94,49% Space Free | Partition Type: FAT32
Drive J: | 7,39 Gb Total Space | 7,39 Gb Free Space | 100,00% Space Free | Partition Type: FAT32

Computer Name: DESKTOP-PC | User Name: Mauricio | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView] -- "C:\Program Files\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{72DB27D3-FE05-4227-AF5A-11CD101ECF09}" = Corel Graphics - Windows Shell Extension
"_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW(R) Graphics Suite X5
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{05C02EE9-9F0A-4052-A4DA-8621F729B1F5}" = blueMSX
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{118B9B3E-F425-4A11-B640-1C743DD10128}" = Puerto Rico
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{24D9A3E0-D086-4B62-AF93-63CF6B05CB48}" = CorelDRAW Graphics Suite X5 - Custom Data
"{260ED378-2B8C-4831-ADAE-D0712D119AC5}" = CorelDRAW Graphics Suite X5 - VSTA
"{26945917-E053-45F6-AF98-309730CFC318}" = Visual Basic for Applications (R) Core
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 24
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3472C84E-2FD0-439F-B27F-C290C1E4CD8B}" = CorelDRAW Graphics Suite X5 - Filters
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{43B43577-2514-4CE0-B14A-7E85C17C0453}" = Windows Live Essentials
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5462D5EE-107A-41E9-ABBF-8FBA2B3631C3}" = EGS Recipe Center
"{5494AFBC-3EC2-463A-BD6C-EAFB62EB6EE9}_is1" = AIFF MP3 Converter v3.1 build 946
"{54B8F4A1-02B0-4D32-8F37-925526C0EEC6}" = CorelDRAW Graphics Suite X5 - Connect
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{566BB41D-F006-4956-A5D3-94D8DFFA7F51}" = Adobe Setup
"{57400C1E-BC51-4ECE-AD2A-A6096204DDEC}" = CorelDRAW Graphics Suite X5 - VBA
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{59123CCF-FED2-46FF-9293-D1DC80042219}" = CorelDRAW Graphics Suite X5 - Redist
"{5ADF4DBD-6F9A-42F5-A861-8EF5FAF927B1}" = Presto! PVR (Brazil 1 Seg)
"{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{62978C1C-FE2E-4A4E-851D-3EB406C9EBC2}" = CorelDRAW Graphics Suite X5 - Draw
"{6347401C-C260-4B30-9816-8F5A1419CC49}" = SafeSign
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6864ABC3-A982-436B-BEF1-5652D6303361}" = ESET NOD32 Antivirus
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6FBA74BD-149F-4521-B921-FFCC84876864}" = Assistente de Instalação Certisign
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72DB27D3-FE05-4227-AF5A-11CD101ECF09}" = Corel Graphics - Windows Shell Extension
"{72FC0445-FE6D-4E12-815B-3A8C5E3704DA}_is1" = GroupMail :: Personal Edition
"{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{9244E956-5939-4B88-930C-0699D4AB2B95}" = CorelDRAW Graphics Suite X5 - WT
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{94DCBD4E-72BA-4338-8977-530EF33C42A1}" = calibre
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{983F7145-CABF-4EDD-9F3D-E06B2F024BD3}" = CorelDRAW Graphics Suite X5 - FontNav
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A199DB88-E22D-4CE7-90AC-B8BE396D7BF4}" = Windows Live Movie Maker
"{A1B04B6B-25BB-48AD-8BD9-D31A86E89F3E}" = CorelDRAW Graphics Suite X5 - PHOTO-PAINT
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B33B61FE-701F-425F-98AB-2B85725CBF68}" = Windows Live Photo Common
"{B399C91E-96F2-4265-9884-1C9A10E9FCF4}" = CorelDRAW Graphics Suite X5
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CA3861BA-1D96-4D66-B577-318E1602C4F3}" = CorelDRAW Graphics Suite X5 - Common
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW Graphics Suite X5 - Setup Files
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D3D1D696-84A8-465A-BC61-CDAC852B24CD}_is1" = Pod to PC 3.245
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{D54A52A8-DF24-4CE8-850B-074CA47DFA74}" = Windows Live Messenger
"{D596EEA2-C6C8-45D3-89DF-FA2DBE99F829}" = Visual Basic for Applications (R) Core - English
"{D642FF8D-438D-4545-A1D5-2EDB4BCAE3BA}" = CorelDRAW Graphics Suite X5 - Photozoom Plugin
"{DE3BB35E-C0CE-4CA1-9CB4-CD9E69364BD9}" = Adobe Premiere Pro CS4
"{DE6CBC04-8673-4DBA-BA81-07F1639CEB5F}" = CorelDRAW Graphics Suite X5 - IPM
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{DF71ABBB-B834-41C0-BB58-80B0545D754C}" = Windows Live UX Platform Language Pack
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E34C6AA4-AE8E-4677-912A-92FC2E039DD9}" = CorelDRAW Graphics Suite X5 - EN
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
"{EA2E8D6D-EE50-4689-B7ED-1E580BC04CC1}" = MiraScan 6.3 (5000 series)
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EC6B304A-044A-46AE-B761-D1202720D93A}" = VOB2MPG v3
"{EDB98D5A-A6FB-425C-BFB7-51A0924B762D}" = CorelDRAW Graphics Suite X5 - Capture
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F7A46527-DF1F-4B0F-9637-98547E189442}" = Windows Live Galeria de Fotos
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE4B83DE-85CF-4DE5-90CE-A2735A0E1F21}" = CorelDRAW Graphics Suite X5 - VideoBrowser
"abgx360" = abgx360 v1.0.5
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_26b63376f4efc354dae41af6b5e3343" = Adobe Premiere Pro CS4
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"Aiseesoft iPhone 4 Movie Converter_is1" = Aiseesoft iPhone 4 Movie Converter
"Akamai" = Akamai NetSession Interface
"aTube Catcher" = aTube Catcher
"Audacity_is1" = Audacity 1.2.6
"Audiograbber" = Audiograbber 1.83 SE
"Boilsoft Video Joiner_is1" = Boilsoft Video Joiner 5.32
"Boilsoft Video Splitter_is1" = Boilsoft Video Splitter 5.21
"BSW" = BrettspielWelt
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"Discador iG" = Discador iG 09.00
"FileZilla Client" = FileZilla Client 3.3.2.1
"GrabIt_is1" = GrabIt 1.7.2 Beta 4 (build 997)
"HeadOverHeels" = NSIS HeadOverHeels (remove only)
"ImgBurn" = ImgBurn
"IrfanView" = IrfanView (remove only)
"IRPF2011" = IRPF2011 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva do País
"KVIrc" = KVIrc
"Luxor 2_is1" = Luxor 2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Office14.SingleImage" = Microsoft Office Professional 2010
"Password Agent 2" = Password Agent 2.5.1
"PGD-CNPJ" = CNPJ (PGD) - versão 3.0
"Picasa 3" = Picasa 3
"Pidgin" = Pidgin
"Puerto Rico_is1" = Puerto Rico Update 1.060227
"QuickPar" = QuickPar 0.9
"Receitanet" = Receitanet 2010
"Receitanet Java 2010.02d" = Receitanet Java 2010.02d
"Sigil_is1" = Sigil 0.3.4
"ULTIMATER" = Microsoft Office Ultimate 2007
"VirtualCloneDrive" = VirtualCloneDrive
"VobSub" = VobSub v2.23 (Remove Only)
"WBFS Manager 3.0" = WBFS Manager 3.0
"WinAVI Video Converter 9.09.0" = WinAVI Video Converter 9.0
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.1
"WinRAR archiver" = WinRAR archiver
"Winsyntax" = Winsyntax 2.0
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-960887255-1984203283-169081182-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"TimeAdjuster" = Time Adjuster STANDARD 3.1
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >


GMER log:

GMER 1.0.15.15640 - http://www.gmer.net
Rootkit scan 2011-06-06 14:26:42
Windows 6.1.7600 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-6 SAMSUNG_HD250HJ rev.FH100-05
Running: zflojcqf.exe; Driver: C:\Users\Mauricio\AppData\Local\Temp\fxliifoc.sys


---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82250579 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82274F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text pci.sys 8AF1EE68 1 Byte [DC]

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\ACPI_HAL \Device\00000067 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ????ne???????4???????????4?4?o?p?p??t????????0??USBAAPL?????Microsoft???Net?Rd????????N??????????????d??input.inf_x86_neutral_5a80b94d3045438a???????m?o?n?n?o?o?????????????????????o??? J??????9???????r??storage\volume?rks????:??????-?g3E????N????????????D????????????volume_install??????????????????????usbhub?????????o???????o????????Microsoft?????????????<??????d????h40|???????????????????????????????????3???????2?2?????o????????X???????????????2??????9????h10????????0?????????eSC???4?4?p??????????? p?????????????????volsnap?????USB??????????????o??????????????????????????????6.??????????????????????????????????disk.inf????????Pl??????????????????????Type?????????????????????8???????????f???????u??????????????????{8ECC055D-047F-11D1-A537-0000F8753ED1}??is??@%SystemRoot%\system32\drivers\mountmgr.sys,-100?i??@%SystemRoot%\system32\FirewallAPI.dll,-23092???@volume.inf,%msft%;Microsoft????{71a27cdd-812a-11d0-bec7-08002be2092f}?0B2???????????{??dc????????????????????????:????????g?????????????????????????????o?
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ???o??????????????????????6??o????????h??????????p???????????????p??????????????t????????p???4?4?4?4?4?4?4??????????????????????????????A1???????????????????????o??????p???????????????????????PerfMon_Open????????????????????? ??? ???????f??????00???? ??6???f???e????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????Interface Un-quarantine filter?????????????????????????????????????????????????????????????????????????????????????? ??????????? ????(??????P????????????(??????P????????????(??????P????????????(??????P????????????(??????P????????????(??????P?????????????P???????????????????????????????????extended base?????(??????A??pI????N??????????????????????z??????????????????????????-9??FAT12/16/32 File System Driver??????H????o???o????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????Interface Un-quarantine filter???????????????????????????????????????????????????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export ?????3???????g????????????????`?????????????????????????.NTx86???????????????????????????????????????????????????????????????????????????????????h???????????3???????4??? P??????t?????Tcp??gencdrom????11??????{94A54C26-C57B-40D1-9D77-796B0217DCFA}??D2???????}????????c??????????????????h???????????????????????????y??????VSO devices?????????*6to4mp?????????????????????????????????????????.NT??????????????????e????????????????????????*??????T????d" "???????g??????????????????????????????????????????*6to4mp?????MSAFD NetBIOS [\Device\NetBT_Tcpip6_{2DE53F38-FAF9-48DB-96E4-9B3E12913984}] DATAGRAM 32?D7??MSAFD NetBIOS [\Device\NetBT_Tcpip6_{A20595C1-6A90-450B-82C7-D7DFA7D376FF}] SEQPACKET 31?1??? ???????????????????,????????"???'???????????????????????????????m?????????????????????????????????????ip???????????????&???~???????????????????????????&???~???????????????????????????&???~???????????????????????????&???~???????????????????????????&???~???????????????????????????&???~???????????????????????????&???~?????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export ???o?3?????????????????????g????????????RpcSs??e|N??????????????????????????????????t???????er??0???Sony?E?????q?????????~?~????i8042 Keyboard and PS/2 Mouse Port Driver????????i???????????????????:??@cpu.inf,%intel%;Intel???????????o???3???4???????p??acpi\genuineintel_-_x86?@????3?o?o?o?o?o?o?o?o??? ???????o?????o???????1????????????????????? ???????o???????????l?1????????0?????????????0??p???r??l_??????????????81???u?u???????o???p???p???o?o????P??p????????h??????????????????????e???????}???????????5?4?p?v?v?o?m??int?t???????????????????????????????Keyboard Class Driver???r????????<??????????????Intel Processor Driver??????????????????t???? ???o???????????t??????? ???????o?????o???????????????????? ???????????? ???????o???????????n????????L????????????????????????g????????????system32\drivers\modem.sys??????????????????????????????????????t???????????????????????t????????????????????????????o????????N??p?????????e??????Z??p????????h???????????????Z??o?????????e????????????N???????????.NT?"????a?????o???????

---- Disk sectors - GMER 1.0.15 ----

Disk \Device\Harddisk1\DR1 TDL4@MBR code has been found <-- ROOTKIT !!!

---- EOF - GMER 1.0.15 ----

Thanks.
Bungawunga
Active Member
 
Posts: 3
Joined: May 31st, 2011, 4:19 pm

Re: MBR secto of the 0 physical disk / Win32/Olmarik.AJL tro

Unread postby deltalima » June 6th, 2011, 2:20 pm

Hi Bungawunga,

Disk \Device\Harddisk1\DR1 TDL4@MBR code has been found <-- ROOTKIT !!!


Rootkit Warning

Your computer has multiple infections, including a rootkit.
A rootkit is a set of software tools intended for concealing running processes, files or system data from the operating system.

You are strongly advised to do the following:
  1. Disconnect the computer from the Internet and from any networked computers until it is cleaned.
  2. Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft and put a watch on your accounts.
    If you don't mind the hassle, change all your account numbers.
  3. From a clean computer, change all your passwords
    (Internet login, your email address(es), financial accounts, PayPal, eBay, Amazon...any online activities you carry out which require a username and password).
    Do NOT change your passwords from this computer, the attacker can still get all the new passwords and transaction records.
  4. Back up all your important data except programs. The programs can be reinstalled back from the original disc or from the Net.

Due to its rootkit functionality, your computer is very likely to have been compromised and there is no way that it can be trusted again.
Many experts in the security community believe that once infected with this type of trojan, the best course of action would be to do a reformat and re-installation of the operating system (OS).
This decision will have to be made by you...

To help you understand more, please take some time to read the following articles:
When should I re-format and reinstall my OS
What are Remote Access Trojans and why are they dangerous
How do I respond to a possible identity theft and how do I prevent it
How and Where to backup your files
Restoring your backups

Please let me know how you wish to proceed.

If you wish to continue and clean the computer please be aware that BitLocker Drive Encryption Driver is configured on this computer and could interfere with the fix so it is vital to make good backups of any important data.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: MBR secto of the 0 physical disk / Win32/Olmarik.AJL tro

Unread postby deltalima » June 9th, 2011, 2:19 pm

Due to lack of response, this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK
Advertisement
Register to Remove


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 61 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware