Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8256
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
28/11/2011 14:18:03
mbam-log-2011-11-28 (14-18-02).txt
Scan type: Full scan (C:\|)
Objects scanned: 235997
Time elapsed: 1 hour(s), 6 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit quick scan 2011-11-28 14:19:36
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 ST340016A rev.3.19
Running: 952gk6vn.exe; Driver: C:\Users\suporte\AppData\Local\Temp\kgddypog.sys
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 PE file @ sector 78140199
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 84A811F8
Device \Driver\atapi \Device\Ide\IdePort0 84A811F8
Device \Driver\atapi \Device\Ide\IdePort1 84A811F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 84A811F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-2 84A811F8
Device \FileSystem\Ntfs \Ntfs 84A831F8
Device \FileSystem\fastfat \Fat 86B431F8
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \Driver\tdx \Device\Ip [88F88FAA] \SystemRoot\system32\DRIVERS\tdx.sys[.data]
Device \Driver\tdx \Device\Tcp [88F88FAA] \SystemRoot\system32\DRIVERS\tdx.sys[.data]
Device \Driver\tdx \Device\Udp [88F88FAA] \SystemRoot\system32\DRIVERS\tdx.sys[.data]
Device \Driver\tdx \Device\RawIp [88F88FAA] \SystemRoot\system32\DRIVERS\tdx.sys[.data]
---- Threads - GMER 1.0.15 ----
Thread System [4:276] 88FC63E0
Thread System [4:280] 88FC63E0
Thread System [4:284] 85A5A330
Thread System [4:288] 85A5A330
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by suporte at 14:20:58 on 2011-11-28
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2037.377 [GMT -2:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Cobian Backup 10\cbService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Program Files\S.O.S. Backup\SOSService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Spiceworks\bin\spicetray.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Cobian Backup 10\cbInterface.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
C:\Program Files\Spiceworks\bin\spiceworks.exe
C:\Windows\system32\conhost.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\Users\suporte\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wuauclt.exe
C:\TOTVS\smartclient_Prd\TotvsSmartClient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\SmartCode Solutions\VNC Manager (Enterprise Edition)\VNCManager.exe
C:\Program Files\TeamViewer\Version6\TeamViewer.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Notepad++\notepad++.exe
C:\Users\suporte\AppData\Local\RockMelt\Application\rockmelt.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.br/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [com.apple.dav.bookmarks.daemon] c:\program files\common files\apple\internet services\BookmarkDAV_client.exe
uRun: [RockMelt Update] "c:\users\suporte\appdata\local\rockmelt\update\RockMeltUpdate.exe" /c
uRun: [iCloudServices] c:\program files\common files\apple\internet services\iCloudServices.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [<NO NAME>]
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Spiceworks] "c:\program files\spiceworks\bin\spicetray_silent.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 10.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 10.0\acrobat\Acrotray.exe"
mRun: [Cobian Backup 10 Interface] "c:\program files\cobian backup 10\cbInterface.exe" -service
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\users\suporte\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\suporte\appdata\roaming\dropbox\bin\Dropbox.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &Enviar para o OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105
IE: Anexar a PDF existente - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Anexar destino do link a PDF existente - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Converter destino do link em Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Converter em Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xportar para o Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{C178BC8A-A2DA-4A7F-8498-BA7607971E7E} : NameServer = 192.168.2.250
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\suporte\appdata\roaming\mozilla\firefox\profiles\4q1iyeb3.default\
FF - prefs.js: network.proxy.ftp - 192.168.2.240
FF - prefs.js: network.proxy.ftp_port - 3128
FF - prefs.js: network.proxy.http - 192.168.2.240
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.socks - 192.168.2.240
FF - prefs.js: network.proxy.socks_port - 3128
FF - prefs.js: network.proxy.ssl - 192.168.2.240
FF - prefs.js: network.proxy.ssl_port - 3128
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\acrobat 10.0\acrobat\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\suporte\appdata\local\rockmelt\update\1.2.189.1\npRockMeltOneClick8.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R1 MpKsl078a74c1;MpKsl078a74c1;c:\programdata\microsoft\microsoft antimalware\definition updates\{7f026084-5733-484e-86b7-709e9973b10f}\MpKsl078a74c1.sys [2011-11-28 28752]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\L1C60x86.sys [2011-11-11 49152]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-11-28 22216]
R3 MonitorFunction;Driver for Monitor;c:\windows\system32\drivers\TVMonitor.sys [2011-1-12 13304]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024]
R3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [2011-11-21 25088]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2012\TuneUpUtilitiesDriver32.sys [2011-10-20 10064]
S1 ryiyklku;ryiyklku;c:\windows\system32\drivers\ryiyklku.sys [2011-11-28 41680]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2011-4-12 62464]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392]
.
=============== Created Last 30 ================
.
2011-11-28 13:17:27 54016 ----a-w- c:\windows\system32\drivers\wvytr.sys
2011-11-28 10:46:22 41680 ----a-w- c:\windows\system32\drivers\ryiyklku.sys
2011-11-28 10:42:33 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-28 10:42:17 -------- d-----w- c:\users\suporte\appdata\roaming\Malwarebytes
2011-11-28 10:41:54 -------- d-----w- c:\programdata\Malwarebytes
2011-11-28 10:41:49 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-28 10:41:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-28 10:17:09 28752 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{7f026084-5733-484e-86b7-709e9973b10f}\MpKsl078a74c1.sys
2011-11-28 10:16:54 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{7f026084-5733-484e-86b7-709e9973b10f}\offreg.dll
2011-11-28 10:16:46 6668624 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{7f026084-5733-484e-86b7-709e9973b10f}\mpengine.dll
2011-11-25 16:31:54 -------- d-sh--w- c:\windows\system32\%APPDATA%
2011-11-25 16:27:44 -------- d-sh--w- c:\users\suporte\appdata\local\f01fa9c0
2011-11-25 12:44:49 -------- d-----w- c:\users\suporte\appdata\local\LogMeIn Rescue Applet
2011-11-22 15:33:38 -------- d-----w- c:\users\suporte\appdata\local\{F3F347EF-DC8B-47DE-9725-6D9D2E5D824C}
2011-11-22 15:32:53 -------- d-----w- c:\users\suporte\appdata\local\{3F0A4A21-9B4D-42A5-BC88-AD4FA1476565}
2011-11-21 17:35:43 25088 ----a-w- c:\windows\system32\drivers\teamviewervpn.sys
2011-11-21 17:35:40 -------- d-----w- c:\program files\TeamViewer
2011-11-21 16:48:10 -------- d-----w- c:\users\suporte\appdata\local\{52914921-AB13-4718-B8AC-61CF7B631A90}
2011-11-21 16:47:56 -------- d-----w- c:\users\suporte\appdata\local\{8B379123-56F9-44F1-923B-6748D30B34D2}
2011-11-21 16:47:56 -------- d-----w- c:\users\suporte\appdata\local\{5628937E-81A2-4A39-BAC9-C47EC9D43E71}
2011-11-21 10:56:00 -------- d-----w- c:\users\suporte\appdata\local\Safe mirror
2011-11-21 10:52:00 -------- d-----w- c:\program files\Cobian Backup 10
2011-11-21 10:12:02 -------- d-----w- c:\users\suporte\appdata\roaming\UltraVNC
2011-11-17 12:39:49 19456 ----a-w- c:\windows\system32\ping.exe
2011-11-17 12:07:06 19968 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\spd__pc.dll
2011-11-17 12:06:50 -------- d-----w- c:\program files\Samsung Printers
2011-11-17 12:06:16 218112 ----a-w- c:\windows\system32\SIPDUtil.dll
2011-11-17 12:06:16 141104 ----a-w- c:\windows\system32\SUPDSvcA.dll
2011-11-17 12:06:14 26624 ----a-w- c:\windows\system32\spd__l.dll
2011-11-17 12:06:13 65536 ----a-w- c:\windows\system32\spd__ci.dll
2011-11-17 12:06:13 283136 ----a-w- c:\windows\system32\DscPnt.dll
2011-11-17 12:06:13 259888 ----a-w- c:\windows\SUPDRun.exe
2011-11-17 12:06:13 131888 ----a-w- c:\windows\system32\SUPDSvc.exe
2011-11-17 12:06:12 151552 ----a-w- c:\windows\system32\spd__ci.exe
2011-11-17 11:29:52 -------- d-----w- c:\users\suporte\appdata\roaming\TeamViewer
2011-11-16 12:43:12 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-11-16 11:04:39 -------- d-----w- c:\users\suporte\appdata\local\RockMelt
2011-11-14 11:05:33 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-11-14 11:05:04 -------- d-----w- c:\program files\LSoft Technologies
2011-11-11 19:33:24 -------- d-----w- c:\program files\VMware
2011-11-11 19:26:53 -------- d-----w- c:\users\suporte\Tracing
2011-11-11 19:17:18 -------- d-----w- c:\users\suporte\appdata\roaming\Thinstall
2011-11-11 19:17:18 -------- d-----w- c:\users\suporte\appdata\local\Thinstall
2011-11-11 19:12:38 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2011-11-11 18:57:54 -------- d-----w- c:\windows\pt-br
2011-11-11 18:50:26 -------- d-----w- c:\windows\en
2011-11-11 18:29:13 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2011-11-11 18:29:13 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-11-11 18:29:13 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-11-11 18:28:54 15712 ----a-w- c:\program files\common files\windows live\.cache\c42d34081cca09f07\MeshBetaRemover.exe
2011-11-11 18:28:50 94040 ----a-w- c:\program files\common files\windows live\.cache\c1383e711cca09f06\DSETUP.dll
2011-11-11 18:28:50 525656 ----a-w- c:\program files\common files\windows live\.cache\c1383e711cca09f06\DXSETUP.exe
2011-11-11 18:28:50 1691480 ----a-w- c:\program files\common files\windows live\.cache\c1383e711cca09f06\dsetup32.dll
2011-11-11 18:28:43 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2011-11-11 18:28:30 94040 ----a-w- c:\program files\common files\windows live\.cache\b5692ad51cca09f05\DSETUP.dll
2011-11-11 18:28:30 525656 ----a-w- c:\program files\common files\windows live\.cache\b5692ad51cca09f05\DXSETUP.exe
2011-11-11 18:28:30 1691480 ----a-w- c:\program files\common files\windows live\.cache\b5692ad51cca09f05\dsetup32.dll
2011-11-11 18:26:33 -------- d-----w- c:\users\suporte\appdata\local\Windows Live
2011-11-11 18:26:31 -------- d-----w- c:\program files\common files\Windows Live
2011-11-11 17:59:53 -------- d-----w- c:\program files\S.O.S. Backup
2011-11-11 17:00:08 31552 ----a-w- c:\windows\system32\TURegOpt.exe
2011-11-11 17:00:07 21312 ----a-w- c:\windows\system32\authuitu.dll
2011-11-11 16:59:50 -------- d-----w- c:\users\suporte\appdata\roaming\TuneUp Software
2011-11-11 16:59:31 -------- d-----w- c:\program files\TuneUp Utilities 2012
2011-11-11 16:59:03 -------- d-----w- c:\programdata\TuneUp Software
2011-11-11 16:58:36 -------- d-sh--w- c:\programdata\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2011-11-11 16:35:53 6668624 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-11-11 16:29:03 2616320 ----a-w- c:\windows\explorer.exe
2011-11-11 16:28:43 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-11-11 16:21:03 -------- d-----w- c:\windows\system32\migration
2011-11-11 16:13:02 -------- d-sh--w- c:\programdata\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-11-11 16:10:16 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-11-11 16:10:16 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-11-11 16:10:16 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-11-11 16:10:15 70656 ----a-w- c:\windows\system32\fontsub.dll
2011-11-11 16:10:15 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-11-11 16:10:15 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-11-11 16:10:02 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-11-11 16:10:01 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-11-11 16:10:00 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-11-11 16:10:00 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-11-11 16:10:00 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-11-11 16:08:24 123904 ----a-w- c:\windows\system32\poqexec.exe
2011-11-11 16:08:16 94208 ----a-w- c:\program files\common files\system\ole db\msdaosp.dll
2011-11-11 16:08:16 86016 ----a-w- c:\windows\system32\odbccu32.dll
2011-11-11 16:08:16 81920 ----a-w- c:\windows\system32\odbccr32.dll
2011-11-11 16:08:16 319488 ----a-w- c:\windows\system32\odbcjt32.dll
2011-11-11 16:08:16 163840 ----a-w- c:\windows\system32\odbctrac.dll
2011-11-11 16:08:16 122880 ----a-w- c:\windows\system32\odbccp32.dll
2011-11-11 16:08:14 850944 ----a-w- c:\windows\system32\sbe.dll
2011-11-11 16:08:14 642048 ----a-w- c:\windows\system32\CPFilters.dll
2011-11-11 16:08:14 534528 ----a-w- c:\windows\system32\EncDec.dll
2011-11-11 16:08:14 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2011-11-11 16:08:04 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-11-11 16:08:02 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-11-11 16:04:58 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2011-11-11 15:52:48 -------- d-----w- c:\users\suporte\appdata\local\Apple
2011-11-11 15:52:37 -------- d-----w- c:\program files\Bonjour
2011-11-11 15:42:12 -------- d-----w- c:\program files\Spiceworks
2011-11-11 15:38:05 -------- d-----w- c:\users\suporte\appdata\roaming\Dropbox
2011-11-11 15:33:42 -------- d-----w- c:\users\suporte\appdata\local\Adobe
2011-11-11 15:19:38 -------- d-----w- c:\users\suporte\appdata\roaming\SmartCode Solutions
2011-11-11 15:18:48 -------- d-----w- c:\program files\SmartCode Solutions
2011-11-11 13:59:56 -------- d-----w- c:\users\suporte\appdata\roaming\Thunderbirdtreste
2011-11-11 13:57:58 -------- d-----w- c:\program files\MozBackup
2011-11-11 13:53:04 -------- d-----w- c:\users\suporte\appdata\local\Thunderbird
2011-11-11 13:52:27 -------- d-----w- C:\Thunderbird
2011-11-11 13:48:15 703824 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{da9d58aa-e866-473c-a0ec-21d5076a3e8f}\gapaengine.dll
2011-11-11 13:42:04 -------- d-----w- c:\program files\Microsoft Synchronization Services
2011-11-11 13:41:50 6668624 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{1b9716aa-3678-4e19-866d-5a5fc6f6e026}\mpengine.dll
2011-11-11 13:41:49 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-11-11 13:40:56 -------- d-----w- c:\windows\PCHEALTH
2011-11-11 13:40:55 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-11-11 13:39:13 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-11-11 13:37:28 -------- d-----w- c:\windows\SHELLNEW
2011-11-11 13:37:28 -------- d-----w- c:\program files\Microsoft Analysis Services
2011-11-11 13:37:14 -------- d-----w- c:\users\suporte\appdata\local\Microsoft Help
2011-11-11 13:31:32 -------- d-----w- c:\program files\Microsoft Security Client
2011-11-11 13:10:49 49152 ----a-w- c:\windows\system32\drivers\L1C60x86.sys
2011-11-11 09:28:51 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-11 09:28:04 -------- d-----w- C:\TOTVS
2011-11-11 09:19:15 -------- d-----r- c:\program files\Skype
2011-11-11 09:16:21 -------- d-----w- c:\windows\system32\Atheros_L1e
2011-11-11 09:15:39 -------- d-----w- c:\windows\system32\Lang
2011-11-11 09:15:38 1002008 ----a-w- c:\windows\system32\igxpun.exe
2011-11-11 09:15:34 -------- d-----w- C:\Intel
2011-11-11 08:59:35 -------- d-sh--w- c:\windows\Installer
2011-11-11 08:58:05 494080 ----a-w- c:\windows\system32\ar5211.sys
2011-11-11 08:58:05 -------- d-----w- c:\windows\Options
2011-11-11 08:58:05 -------- d-----w- c:\program files\Atheros
2011-11-11 08:57:47 -------- d-----w- C:\temp
2011-11-11 08:57:46 749568 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iKernel.dll
2011-11-11 08:57:46 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\ctor.dll
2011-11-11 08:57:46 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\DotNetInstaller.exe
2011-11-11 08:57:46 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2011-11-11 08:57:46 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iscript.dll
2011-11-11 08:57:46 180224 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iuser.dll
2011-11-11 08:57:43 323716 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\setup.dll
2011-11-11 08:57:43 192644 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iGdi.dll
2011-11-11 08:51:47 37376 ----a-w- c:\windows\system32\themeservice.dll.backup
2011-11-11 08:51:47 2755072 ----a-w- c:\windows\system32\themeui.dll.backup
2011-11-11 08:51:47 249856 ----a-w- c:\windows\system32\uxtheme.dll.backup
.
==================== Find3M ====================
.
2011-11-11 08:51:47 37376 ----a-w- c:\windows\system32\themeservice.dll
2011-11-11 08:51:47 2755072 ----a-w- c:\windows\system32\themeui.dll
2011-11-11 08:51:47 249856 ----a-w- c:\windows\system32\uxtheme.dll
2011-09-29 16:03:04 1290608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-09-29 03:37:56 2341888 ----a-w- c:\windows\system32\win32k.sys
2011-09-05 17:05:00 47512 ----a-w- c:\windows\system32\AdobePDF.dll
2011-09-05 17:04:58 22936 ----a-w- c:\windows\system32\AdobePDFUI.dll
2011-09-01 02:35:59 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-09-01 02:28:15 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-09-01 02:22:54 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-08-31 01:05:04 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-08-31 01:05:04 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-08-31 01:05:04 50536 ----a-w- c:\windows\system32\jdns_sd.dll
2011-08-31 01:05:04 178536 ----a-w- c:\windows\system32\dnssdX.dll
.
============= FINISH: 14:21:35,31 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 11/11/2011 06:51:23
System Uptime: 28/11/2011 08:07:45 (6 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. | | G31M-ES2L
Processor: Pentium(R) Dual-Core CPU E5500 @ 2.80GHz | Socket 775 | 2800/200mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 37 GiB total, 15,932 GiB free.
D: is FIXED (NTFS) - 146 GiB total, 4,48 GiB free.
E: is FIXED (NTFS) - 152 GiB total, 25,316 GiB free.
F: is CDROM (CDFS)
G: is Removable
H: is Removable
I: is Removable
J: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsl0df609fc
Device ID: ROOT\LEGACY_MPKSL0DF609FC\0000
Manufacturer:
Name: MpKsl0df609fc
PNP Device ID: ROOT\LEGACY_MPKSL0DF609FC\0000
Service: MpKsl0df609fc
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: MpKsl806e86eb
Device ID: ROOT\LEGACY_MPKSL806E86EB\0000
Manufacturer:
Name: MpKsl806e86eb
PNP Device ID: ROOT\LEGACY_MPKSL806E86EB\0000
Service: MpKsl806e86eb
.
==== System Restore Points ===================
.
RP41: 25/11/2011 12:35:40 - Scheduled Checkpoint
RP42: 28/11/2011 08:16:29 - Windows Update
.
==== Installed Programs ======================
.
Active@ ISO Burner
Adobe Acrobat X Pro - Italiano, Español, Nederlands, Português
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Apple Application Support
Apple Software Update
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
Bonjour
Cobian Backup 10
Controle ActiveX do Windows Live Mesh para Conexões Remotas
D3DX10
Definition update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dropbox
FileZilla Client 3.5.2
iCloud
Intel(R) Graphics Media Accelerator Driver
Java Auto Updater
Java(TM) 6 Update 29
Malwarebytes' Anti-Malware versão 1.51.2.1300
Mesh Runtime
Microsoft Antimalware
Microsoft Antimalware Service PT-BR Language Pack
Microsoft Application Error Reporting
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (Portuguese (Brazil)) 2010
Microsoft Office Excel MUI (Portuguese (Brazil)) 2010
Microsoft Office Groove MUI (Portuguese (Brazil)) 2010
Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010
Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010
Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010
Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (Portuguese (Brazil)) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (Portuguese (Brazil)) 2010
Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010
Microsoft Office Shared MUI (Portuguese (Brazil)) 2010
Microsoft Office Word MUI (Portuguese (Brazil)) 2010
Microsoft Security Client
Microsoft Security Client PT-BR Language Pack
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MozBackup 1.5.1
Mozilla Firefox 9.0 (x86 pt-BR)
Mozilla Thunderbird (8.0)
MSVCRT
Notepad++
RockMelt
S.O.S Backup StandardNet 6.0
Samsung Universal Print Driver
Security Update for Microsoft Excel 2010 (KB2553070)
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
Skype™ 5.5
SmartCode VNC Manager (Enterprise Edition) 3.6
Spiceworks
TeamViewer 6
TuneUp Utilities 2012
TuneUp Utilities Language Pack (en-US)
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553455) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553323) 32-Bit Edition
Update for Microsoft Outlook Social Connector (KB2583935)
VMware ThinApp
Windows Live Communications Platform
Windows Live Essentials
Windows Live Galeria de Fotos
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinRAR 4.01 (32-bit)
.
==== Event Viewer Messages From Past Week ========
.
28/11/2011 14:13:57, Error: Microsoft-Windows-DistributedCOM [10009] - DCOM was unable to communicate with the computer 192.168.2.115 using any of the configured protocols.
28/11/2011 11:59:53, Error: Microsoft-Windows-DistributedCOM [10009] - DCOM was unable to communicate with the computer 192.168.2.109 using any of the configured protocols.
28/11/2011 10:16:06, Error: Schannel [36888] - The following fatal alert was generated: 10. The internal error state is 10.
28/11/2011 10:08:38, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
28/11/2011 10:08:09, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Cobian Backup 10 Volume Shadow Copy service service to connect.
28/11/2011 10:08:09, Error: Service Control Manager [7000] - The Cobian Backup 10 Volume Shadow Copy service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
28/11/2011 10:08:09, Error: Microsoft-Windows-TaskScheduler [413] - Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147549183.
28/11/2011 10:06:00, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
28/11/2011 10:05:58, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
28/11/2011 10:05:58, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
28/11/2011 10:05:58, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
28/11/2011 10:05:58, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
28/11/2011 10:05:54, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
28/11/2011 10:05:45, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
28/11/2011 10:05:39, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC discache MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr sptd tdx Wanarpv6 WfpLwf
28/11/2011 10:05:37, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
28/11/2011 10:05:37, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
28/11/2011 10:05:37, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
28/11/2011 10:05:37, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
28/11/2011 10:05:37, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
28/11/2011 10:05:37, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
28/11/2011 10:05:37, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
28/11/2011 10:05:37, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
28/11/2011 10:05:37, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
28/11/2011 10:05:13, Error: sptd [4] - Driver detected an internal error in its data structures for .
28/11/2011 09:11:21, Error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s).
28/11/2011 08:17:15, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
25/11/2011 14:37:58, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: Antimalware protection has stopped functioning for an unknown reason. In some instances, restarting the service may resolve the problem.
25/11/2011 14:35:28, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
25/11/2011 14:32:43, Error: Service Control Manager [7034] - The S.O.S Backup service terminated unexpectedly. It has done this 1 time(s).
25/11/2011 14:32:41, Error: Service Control Manager [7034] - The TuneUp Utilities Service service terminated unexpectedly. It has done this 1 time(s).
25/11/2011 14:32:40, Error: Service Control Manager [7034] - The TeamViewer 6 service terminated unexpectedly. It has done this 1 time(s).
25/11/2011 14:32:39, Error: Service Control Manager [7034] - The Windows Live ID Sign-in Assistant service terminated unexpectedly. It has done this 1 time(s).
25/11/2011 14:32:39, Error: Service Control Manager [7034] - The Serviço do Bonjour service terminated unexpectedly. It has done this 1 time(s).
25/11/2011 14:31:48, Error: Service Control Manager [7034] - The Cobian Backup 10 Volume Shadow Copy service service terminated unexpectedly. It has done this 1 time(s).
25/11/2011 12:34:44, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
25/11/2011 08:28:31, Error: Microsoft-Windows-DistributedCOM [10009] - DCOM was unable to communicate with the computer 192.168.2.107 using any of the configured protocols.
25/11/2011 08:07:47, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
24/11/2011 08:08:03, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
23/11/2011 16:00:46, Error: Microsoft-Windows-DistributedCOM [10006] - DCOM got error "2147944122" from the computer 192.168.2.112 when attempting to activate the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
22/11/2011 14:58:53, Error: Microsoft-Windows-DistributedCOM [10009] - DCOM was unable to communicate with the computer 192.168.2.105 using any of the configured protocols.
21/11/2011 09:43:25, Error: Microsoft-Windows-DistributedCOM [10006] - DCOM got error "2147944122" from the computer 192.168.2.114 when attempting to activate the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
21/11/2011 08:52:32, Error: Service Control Manager [7041] - The CobianBackup10 service was unable to log on as .\suporte with the currently configured password due to the following error: Logon failure: the user has not been granted the requested logon type at this computer. Service: CobianBackup10 Domain and account: .\suporte This service account does not have the required user right "Log on as a service." User Action Assign "Log on as a service" to the service account on this computer. You can use Local Security Settings (Secpol.msc) to do this. If this computer is a node in a cluster, check that this user right is assigned to the Cluster service account on all nodes in the cluster. If you have already assigned this user right to the service account, and the user right appears to be removed, check with your domain administrator to find out if a Group Policy object associated with this node might be removing the right.
21/11/2011 08:52:32, Error: Service Control Manager [7000] - The Cobian Backup 10 service failed to start due to the following error: The service did not start due to a logon failure.
.
==== End Of File ===========================