Usamos cookies para medir audiência e melhorar sua experiência. Você pode aceitar ou recusar a qualquer momento. Veja sobre o iMasters.
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\SMon2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\UltraVnc\winvnc.exe
C:\Arquivos de programas\internet explorer\iexplore.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Luciano Peças\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://grupolbezerra.com.br/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [sMon2] C:\WINDOWS\system32\SMon2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Run server as application.lnk = C:\Arquivos de programas\UltraVnc\winvnc.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1228243184421
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O17 - HKLM\System\CS1\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O17 - HKLM\System\CS2\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O17 - HKLM\System\CS3\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
--
End of file - 5006 bytes
Aguardo Resposta...
Abraços...
Caro Mguitar, esse arquivo que você me mandou analisar no Virus total, é um programa de monitoramento que uso (é de confiança), mas de toda forma segue abaixo o resultado abaixo.
fico no aguardo.
http://www.virustotal.com/pt/analisis/3ba0...073c15f1807d5ea
Logfile of random's system information tool 1.04 (written by random/random)
Run by Luciano Peças at 2008-12-05 16:21:14
Microsoft Windows XP Professional Service Pack 3
System drive C: has 22 GB (73%) free of 30 GB
Total RAM: 479 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:21:38, on 5/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\SMon2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\UltraVnc\winvnc.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Luciano Peças\Desktop\RSIT.exe
C:\Documents and Settings\Luciano Peças\Desktop\Luciano Peças.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://grupolbezerra.com.br/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [sMon2] C:\WINDOWS\system32\SMon2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Run server as application.lnk = C:\Arquivos de programas\UltraVnc\winvnc.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1228243184421
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O17 - HKLM\System\CS1\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O17 - HKLM\System\CS2\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O17 - HKLM\System\CS3\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
--
End of file - 5067 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\MP Scheduled Scan.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-11-07 1088296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
Click-to-Call BHO - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll [2008-09-02 75272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Auxiliar de Conexão do Windows Live - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-02-22 401968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast!"=C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-26 81000]
"SMon2"=C:\WINDOWS\system32\SMon2.exe [2006-12-08 134144]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
C:\Documents and Settings\Luciano Peças\Menu Iniciar\Programas\Inicializar
Run server as application.lnk - C:\Arquivos de programas\UltraVnc\winvnc.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 267304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\ARQUIV~1\WINDOW~4\MpShHook.dll [2006-11-03 83224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\SMon2.exe"="C:\WINDOWS\system32\SMon2.exe:*:Enabled:SMon2"
"C:\Arquivos de programas\r2 Studios\Tonic\Tonic.exe"="C:\Arquivos de programas\r2 Studios\Tonic\Tonic.exe:*:Enabled:Tonic"
"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Arquivos de programas\Skype\Phone\Skype.exe"="C:\Arquivos de programas\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7aaf576-c2b3-11dd-a65b-000feaa4fb9c}]
shell\AutoRun\command - F:\rcukd.cmd
shell\explore\command - F:\rcukd.cmd
shell\open\command - F:\rcukd.cmd
======List of files/folders created in the last 1 months======
2008-12-05 17:01:55 ----A---- C:\WINDOWS\NeroDigital.ini
2008-12-05 16:44:32 ----D---- C:\WINDOWS\ERDNT
2008-12-05 16:21:14 ----D---- C:\rsit
2008-12-05 10:21:30 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Malwarebytes
2008-12-05 10:21:23 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Malwarebytes
2008-12-05 10:21:22 ----D---- C:\Arquivos de programas\Malwarebytes' Anti-Malware
2008-12-05 10:20:49 ----D---- C:\ComboFix
2008-12-05 10:16:30 ----A---- C:\ComboFix.txt
2008-12-04 15:48:38 ----A---- C:\imp2.bat
2008-12-04 15:47:51 ----D---- C:\Arquivos de programas\MSECache
2008-12-04 08:28:13 ----D---- C:\Arquivos de programas\Microsoft Works
2008-12-04 08:27:28 ----D---- C:\Arquivos de programas\Microsoft Visual Studio
2008-12-04 08:27:27 ----D---- C:\Arquivos de programas\Arquivos comuns\DESIGNER
2008-12-04 08:21:26 ----D---- C:\WINDOWS\SHELLNEW
2008-12-04 08:19:35 ----D---- C:\Arquivos de programas\Microsoft Office
2008-12-04 08:19:31 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help
2008-12-04 08:18:53 ----RHD---- C:\MSOCache
2008-12-04 08:16:49 ----D---- C:\WINDOWS\pss
2008-12-03 18:13:36 ----A---- C:\WINDOWS\cat_fiat.ini
2008-12-03 18:08:51 ----A---- C:\WINDOWS\cat_vw.ini
2008-12-03 18:08:01 ----A---- C:\WINDOWS\cat_perf.ini
2008-12-03 18:00:18 ----D---- C:\CAT_VW
2008-12-03 17:55:45 ----D---- C:\OiC
2008-12-03 17:55:45 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\OiC
2008-12-03 17:54:20 ----D---- C:\Arquivos de programas\CepChev2
2008-12-03 17:46:00 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Ahead
2008-12-03 17:43:43 ----D---- C:\Arquivos de programas\Nero
2008-12-03 17:43:43 ----D---- C:\Arquivos de programas\Arquivos comuns\Ahead
2008-12-03 17:41:07 ----A---- C:\WINDOWS\cdplayer.ini
2008-12-03 17:40:40 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\FreeRIP
2008-12-03 17:40:26 ----D---- C:\Arquivos de programas\FreeRIP3
2008-12-03 17:29:02 ----HD---- C:\WINDOWS\system32\GroupPolicy
2008-12-03 17:16:12 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\skypePM
2008-12-03 13:00:30 ----HD---- C:\WINDOWS\PIF
2008-12-03 10:59:30 ----D---- C:\Arquivos de programas\Microsoft
2008-12-03 10:57:21 ----D---- C:\Arquivos de programas\Windows Live
2008-12-03 10:36:02 ----D---- C:\Arquivos de programas\Windows Defender
2008-12-03 10:34:58 ----D---- C:\Arquivos de programas\Arquivos comuns\Windows Live
2008-12-03 10:34:45 ----D---- C:\Arquivos de programas\WinZip
2008-12-03 10:34:27 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Adobe
2008-12-03 10:34:02 ----D---- C:\Arquivos de programas\Arquivos comuns\Adobe
2008-12-03 10:34:02 ----D---- C:\Arquivos de programas\Adobe
2008-12-03 10:32:42 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Skype
2008-12-03 10:32:18 ----D---- C:\Arquivos de programas\UsbFix
2008-12-03 10:32:11 ----D---- C:\Arquivos de programas\Skype
2008-12-03 10:32:10 ----D---- C:\Arquivos de programas\Arquivos comuns\Skype
2008-12-03 10:31:59 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Skype
2008-12-03 10:31:42 ----D---- C:\Arquivos de programas\CCleaner
2008-12-03 10:28:45 ----D---- C:\Arquivos de programas\UltraVnc
2008-12-03 10:24:12 ----D---- C:\Arquivos de programas\r2 Studios
2008-12-03 10:23:27 ----A---- C:\WINDOWS\system32\SMon2.exe
2008-12-02 17:19:29 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2008-12-02 17:18:34 ----A---- C:\WINDOWS\system32\MRT.exe
2008-12-02 17:18:24 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2008-12-02 17:18:16 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2008-12-02 17:18:08 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2008-12-02 17:17:27 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-12-02 17:17:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-12-02 17:17:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-12-02 17:16:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-12-02 17:16:48 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-12-02 17:16:15 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-12-02 17:16:08 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-12-02 17:16:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-12-02 17:15:51 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-12-02 17:15:44 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-12-02 17:15:37 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-12-02 17:15:30 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-12-02 17:15:22 ----D---- C:\WINDOWS\ie7updates
2008-12-02 17:15:12 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-12-02 17:15:04 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-12-02 17:14:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-12-02 17:14:47 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-12-02 16:45:06 ----D---- C:\WINDOWS\system32\PreInstall
2008-12-02 16:45:04 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2008-12-02 16:41:25 ----A---- C:\WINDOWS\system32\wups2.dll
2008-12-02 16:41:25 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2008-12-02 16:41:24 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2008-12-02 16:41:23 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2008-12-02 16:41:23 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2008-12-02 15:17:30 ----D---- C:\WINDOWS\Prefetch
2008-12-02 11:54:46 ----N---- C:\WINDOWS\system32\msxml6r.dll
2008-12-02 11:54:46 ----A---- C:\WINDOWS\system32\msxml6.dll
2008-12-02 11:54:31 ----N---- C:\WINDOWS\system32\smtpapi.dll
2008-12-02 11:54:31 ----N---- C:\WINDOWS\system32\rwnh.dll
2008-12-02 11:54:31 ----N---- C:\WINDOWS\system32\comsdupd.exe
2008-12-02 11:54:28 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2008-12-02 11:54:28 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2008-12-02 11:54:28 ----N---- C:\WINDOWS\system32\aaclient.dll
2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\azroles.dll
2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\ati3duag.dll
2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3ui.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3svc.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3msm.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3api.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dimsroam.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\credssp.dll
2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eapsvc.dll
2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eapqec.dll
2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eappprxy.dll
2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eapphost.dll
2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eappgnui.dll
2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eappcfg.dll
2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eapolqec.dll
2008-12-02 11:54:24 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2008-12-02 11:54:24 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\mmcperf.exe
2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\mmcex.dll
2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\kmsvc.dll
2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\kbdpash.dll
2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\nv4_disp.dll
2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\napstat.exe
2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\napmontr.dll
2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\napipsec.dll
2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\mssha.dll
2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\rasqec.dll
2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\qutil.dll
2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\qcliprov.dll
2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\qagentrt.dll
2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\qagent.dll
2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\onex.dll
2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\slserv.exe
2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\slrundll.exe
2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\slgen.dll
2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\slextspk.dll
2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\slcoinst.dll
2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\setupn.exe
2008-12-02 11:54:19 ----N---- C:\WINDOWS\system32\xpsp3res.dll
2008-12-02 11:54:19 ----N---- C:\WINDOWS\system32\verclsid.exe
2008-12-02 11:54:19 ----N---- C:\WINDOWS\system32\tzchange.exe
2008-12-02 11:54:19 ----N---- C:\WINDOWS\system32\tspkg.dll
2008-12-02 11:54:19 ----N---- C:\WINDOWS\system32\tsgqec.dll
2008-12-02 11:54:18 ----N---- C:\WINDOWS\system32\wmphoto.dll
2008-12-02 11:54:18 ----N---- C:\WINDOWS\system32\wlanapi.dll
2008-12-02 11:54:18 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2008-12-02 11:54:18 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2008-12-02 11:54:16 ----N---- C:\WINDOWS\slrundll.exe
2008-12-02 11:54:15 ----D---- C:\WINDOWS\l2schemas
2008-12-02 11:54:14 ----D---- C:\WINDOWS\system32\bits
2008-12-02 11:51:50 ----D---- C:\WINDOWS\ServicePackFiles
2008-12-02 11:49:49 ----D---- C:\WINDOWS\network diagnostic
2008-12-02 11:47:50 ----A---- C:\WINDOWS\002674_.tmp
2008-12-02 11:43:12 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-12-02 11:03:54 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Macromedia
2008-12-02 11:03:54 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Adobe
2008-12-02 10:48:16 ----D---- C:\WINDOWS\WBEM
2008-12-02 10:48:15 ----D---- C:\WINDOWS\system32\pt-br
2008-12-02 10:46:55 ----HDC---- C:\WINDOWS\ie7
2008-12-02 10:46:24 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2008-12-02 10:46:03 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2008-12-02 10:46:01 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2008-12-02 10:45:28 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-12-02 10:45:23 ----HDC---- C:\WINDOWS\$NtUninstallKB915865$
2008-12-02 10:45:23 ----HD---- C:\WINDOWS\$hf_mig$
2008-12-02 10:45:19 ----N---- C:\WINDOWS\system32\xmllite.dll
2008-12-02 10:44:34 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Windows Genuine Advantage
2008-12-02 08:19:26 ----A---- C:\imp.bat
2008-12-02 08:19:25 ----A---- C:\WINDOWS\ARJ.EXE
2008-12-02 08:19:04 ----A---- C:\WINDOWS\system32\MSVCR71.dll
2008-12-02 08:19:04 ----A---- C:\WINDOWS\system32\MSVCP71.dll
2008-12-02 08:19:04 ----A---- C:\WINDOWS\system32\MFC71.dll
2008-12-02 08:19:04 ----A---- C:\WINDOWS\system32\aswBoot.exe
2008-12-02 08:19:02 ----D---- C:\Arquivos de programas\Alwil Software
2008-12-01 11:00:37 ----A---- C:\WINDOWS\system32\ksuser.dll
2008-12-01 11:00:30 ----A---- C:\WINDOWS\system32\UnAudioNT.dll
2008-12-01 11:00:25 ----D---- C:\Arquivos de programas\VIAudioi
2008-12-01 11:00:23 ----A---- C:\WINDOWS\IsUn0416.exe
2008-12-01 10:04:07 ----SHD---- C:\WINDOWS\CSC
2008-12-01 10:03:13 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-12-01 10:03:08 ----A---- C:\WINDOWS\IsUninst.exe
2008-11-29 08:59:19 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Identities
2008-11-29 08:59:16 ----HD---- C:\Arquivos de programas\Uninstall Information
2008-11-29 08:59:10 ----ASH---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\desktop.ini
2008-11-29 08:59:09 ----SD---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Microsoft
2008-11-29 08:58:15 ----D---- C:\WINDOWS\SoftwareDistribution
2008-11-29 08:58:05 ----SD---- C:\WINDOWS\system32\Microsoft
2008-11-29 08:58:04 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-11-29 08:53:26 ----D---- C:\WINDOWS\system32\xircom
2008-11-29 08:53:26 ----D---- C:\Arquivos de programas\xerox
2008-11-29 08:53:26 ----D---- C:\Arquivos de programas\microsoft frontpage
2008-11-29 08:52:59 ----A---- C:\WINDOWS\control.ini
2008-11-29 08:52:59 ----A---- C:\AUTOEXEC.BAT
2008-11-29 08:52:35 ----A---- C:\WINDOWS\system32\mapi32.dll
2008-11-29 08:51:11 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-11-29 08:51:11 ----RD---- C:\WINDOWS\Offline Web Pages
2008-11-29 08:51:11 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2008-11-29 08:51:02 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2008-11-29 08:50:56 ----HD---- C:\Arquivos de programas\WindowsUpdate
2008-11-29 08:50:51 ----D---- C:\Arquivos de programas\Serviços on-line
2008-11-29 08:50:34 ----D---- C:\WINDOWS\system32\DirectX
2008-11-29 08:50:17 ----A---- C:\WINDOWS\system32\atrace.dll
2008-11-29 08:50:15 ----A---- C:\WINDOWS\system32\desktop.ini
2008-11-29 08:50:15 ----A---- C:\WINDOWS\desktop.ini
2008-11-29 08:50:09 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2008-11-29 08:50:08 ----A---- C:\WINDOWS\system32\acctres.dll
2008-11-29 08:50:07 ----D---- C:\Arquivos de programas\Arquivos comuns\Serviços
2008-11-29 08:50:05 ----SD---- C:\WINDOWS\Tasks
2008-11-29 08:50:05 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2008-11-29 08:50:04 ----D---- C:\Arquivos de programas\Arquivos comuns\MSSoap
2008-11-29 08:50:01 ----D---- C:\WINDOWS\srchasst
2008-11-29 08:50:00 ----D---- C:\WINDOWS\system32\Macromed
2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wups.dll
2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuauserv.dll
2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-11-29 08:49:56 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2008-11-29 08:49:56 ----A---- C:\WINDOWS\system32\qmgr.dll
2008-11-29 08:49:56 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2008-11-29 08:49:56 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2008-11-29 08:49:53 ----D---- C:\Arquivos de programas\Movie Maker
2008-11-29 08:49:49 ----A---- C:\WINDOWS\system32\safrslv.dll
2008-11-29 08:49:49 ----A---- C:\WINDOWS\system32\safrdm.dll
2008-11-29 08:49:49 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2008-11-29 08:49:49 ----A---- C:\WINDOWS\system32\racpldlg.dll
2008-11-29 08:49:46 ----D---- C:\WINDOWS\system32\Restore
2008-11-29 08:49:46 ----A---- C:\WINDOWS\system32\srsvc.dll
2008-11-29 08:49:46 ----A---- C:\WINDOWS\system32\srrstr.dll
2008-11-29 08:49:46 ----A---- C:\WINDOWS\system32\srclient.dll
2008-11-29 08:49:46 ----A---- C:\WINDOWS\system32\fltmc.exe
2008-11-29 08:49:46 ----A---- C:\WINDOWS\system32\fltlib.dll
2008-11-29 08:49:45 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2008-11-29 08:49:45 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2008-11-29 08:49:45 ----A---- C:\WINDOWS\system32\mnmdd.dll
2008-11-29 08:49:45 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2008-11-29 08:49:45 ----A---- C:\WINDOWS\system32\ils.dll
2008-11-29 08:49:44 ----A---- C:\WINDOWS\system32\msconf.dll
2008-11-29 08:49:42 ----D---- C:\Arquivos de programas\NetMeeting
2008-11-29 08:49:42 ----A---- C:\WINDOWS\system32\msoert2.dll
2008-11-29 08:49:42 ----A---- C:\WINDOWS\system32\msoeacct.dll
2008-11-29 08:49:41 ----A---- C:\WINDOWS\system32\inetres.dll
2008-11-29 08:49:41 ----A---- C:\WINDOWS\system32\inetcomm.dll
2008-11-29 08:49:39 ----D---- C:\Arquivos de programas\Outlook Express
2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\schedsvc.dll
2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\mstinit.exe
2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\mstask.dll
2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\isign32.dll
2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\icwphbk.dll
2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\icwdial.dll
2008-11-29 08:49:38 ----A---- C:\WINDOWS\system32\inetcfg.dll
2008-11-29 08:49:33 ----D---- C:\Arquivos de programas\Arquivos comuns\System
2008-11-29 08:49:32 ----D---- C:\Arquivos de programas\Internet Explorer
2008-11-29 08:48:45 ----D---- C:\Arquivos de programas\ComPlus Applications
2008-11-29 08:48:43 ----A---- C:\WINDOWS\vbaddin.ini
2008-11-29 08:48:43 ----A---- C:\WINDOWS\vb.ini
2008-11-29 08:48:38 ----D---- C:\WINDOWS\Registration
2008-11-29 08:48:29 ----D---- C:\Arquivos de programas\Windows Media Player
2008-11-29 08:48:23 ----D---- C:\Arquivos de programas\Messenger
2008-11-29 08:48:19 ----D---- C:\Arquivos de programas\MSN Gaming Zone
2008-11-29 08:48:19 ----A---- C:\WINDOWS\system32\write.exe
2008-11-29 08:48:11 ----A---- C:\WINDOWS\system32\sndvol32.exe
2008-11-29 08:48:11 ----A---- C:\WINDOWS\system32\hticons.dll
2008-11-29 08:48:11 ----A---- C:\WINDOWS\system32\avwav.dll
2008-11-29 08:48:11 ----A---- C:\WINDOWS\system32\avtapi.dll
2008-11-29 08:48:11 ----A---- C:\WINDOWS\system32\avmeter.dll
2008-11-29 08:48:10 ----A---- C:\WINDOWS\system32\winchat.exe
2008-11-29 08:48:05 ----A---- C:\WINDOWS\system32\getuname.dll
2008-11-29 08:48:04 ----A---- C:\WINDOWS\system32\charmap.exe
2008-11-29 08:48:04 ----A---- C:\WINDOWS\system32\calc.exe
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\tslabels.ini
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\tskill.exe
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\tscon.exe
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\shadow.exe
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\rwinsta.exe
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\reset.exe
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\regini.exe
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\qwinsta.exe
2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\qappsrv.exe
2008-11-29 08:48:02 ----A---- C:\WINDOWS\system32\msg.exe
2008-11-29 08:48:02 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2008-11-29 08:48:02 ----A---- C:\WINDOWS\system32\logoff.exe
2008-11-29 08:48:02 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2008-11-29 08:48:02 ----A---- C:\WINDOWS\system32\cdmodem.dll
2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\stclient.dll
2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\mtxex.dll
2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\mtxdm.dll
2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\comsnap.dll
2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\comrepl.dll
2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\comaddin.dll
2008-11-29 08:47:56 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2008-11-29 08:47:56 ----A---- C:\WINDOWS\system32\accwiz.exe
2008-11-29 08:47:55 ----D---- C:\Arquivos de programas\Windows NT
2008-11-29 08:47:55 ----A---- C:\WINDOWS\system32\sndrec32.exe
2008-11-29 08:47:55 ----A---- C:\WINDOWS\system32\mspaint.exe
2008-11-29 08:47:55 ----A---- C:\WINDOWS\system32\mplay32.exe
2008-11-29 08:47:55 ----A---- C:\WINDOWS\system32\hypertrm.dll
2008-11-29 08:47:54 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2008-11-29 08:47:54 ----A---- C:\WINDOWS\system32\clipbrd.exe
2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\termsrv.dll
2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\sessmgr.exe
2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\remotepg.dll
2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\rdshost.exe
2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\rdchost.dll
2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\mstscax.dll
2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\mstsc.exe
2008-11-29 08:47:52 ----D---- C:\WINDOWS\system32\MsDtc
2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\rdpclip.exe
2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\qprocess.exe
2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\mtxoci.dll
2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\icaapi.dll
2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2008-11-29 08:47:51 ----A---- C:\WINDOWS\system32\xolehlp.dll
2008-11-29 08:47:51 ----A---- C:\WINDOWS\system32\msdtctm.dll
2008-11-29 08:47:51 ----A---- C:\WINDOWS\system32\msdtclog.dll
2008-11-29 08:47:51 ----A---- C:\WINDOWS\system32\msdtc.exe
2008-11-29 08:47:50 ----D---- C:\WINDOWS\system32\Com
2008-11-29 08:47:50 ----A---- C:\WINDOWS\system32\colbact.dll
2008-11-29 08:47:50 ----A---- C:\WINDOWS\system32\clbcatex.dll
2008-11-29 08:47:50 ----A---- C:\WINDOWS\system32\catsrvut.dll
2008-11-29 08:47:50 ----A---- C:\WINDOWS\system32\catsrvps.dll
2008-11-29 08:47:50 ----A---- C:\WINDOWS\system32\catsrv.dll
2008-11-29 08:47:49 ----A---- C:\WINDOWS\system32\comuid.dll
2008-11-29 08:47:49 ----A---- C:\WINDOWS\system32\comsvcs.dll
2008-11-29 08:47:49 ----A---- C:\WINDOWS\system32\clbcatq.dll
2008-11-29 08:47:43 ----A---- C:\WINDOWS\system32\servdeps.dll
2008-11-29 08:47:43 ----A---- C:\WINDOWS\system32\mmfutil.dll
2008-11-29 08:47:43 ----A---- C:\WINDOWS\system32\licwmi.dll
2008-11-29 08:47:43 ----A---- C:\WINDOWS\system32\cmprops.dll
2008-11-29 06:45:37 ----A---- C:\WINDOWS\system32\h323log.txt
2008-11-29 06:33:13 ----A---- C:\WINDOWS\system32\s3gnb.dll
2008-11-29 06:32:39 ----A---- C:\WINDOWS\system32\usbui.dll
2008-11-29 06:31:18 ----SHD---- C:\WINDOWS\Installer
2008-11-29 06:31:18 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-11-29 06:31:17 ----D---- C:\Arquivos de programas\Arquivos comuns\ODBC
2008-11-29 06:31:17 ----A---- C:\WINDOWS\ODBCINST.INI
2008-11-29 06:31:14 ----D---- C:\Arquivos de programas\Arquivos comuns\SpeechEngines
2008-11-29 06:31:14 ----D---- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared
2008-11-29 06:31:13 ----RD---- C:\Arquivos de programas
2008-11-29 06:31:13 ----D---- C:\Arquivos de programas\Arquivos comuns
2008-11-29 06:31:10 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2008-11-29 06:31:10 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2008-11-29 06:31:10 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdur.dll
2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2008-11-29 06:31:08 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2008-11-29 06:31:08 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2008-11-29 06:31:08 ----RA---- C:\WINDOWS\system32\kbdru.dll
2008-11-29 06:31:08 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2008-11-29 06:31:08 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2008-11-29 06:31:06 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2008-11-29 06:31:06 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2008-11-29 06:31:06 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2008-11-29 06:31:06 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2008-11-29 06:31:06 ----RA---- C:\WINDOWS\system32\kbdest.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdro.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2008-11-29 06:31:01 ----A---- C:\WINDOWS\system32\spxcoins.dll
2008-11-29 06:31:01 ----A---- C:\WINDOWS\system32\irclass.dll
2008-11-29 06:31:01 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2008-11-29 06:31:01 ----A---- C:\WINDOWS\system32\dgsetup.dll
2008-11-29 06:31:01 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2008-11-29 06:30:59 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2008-11-29 06:30:59 ----A---- C:\WINDOWS\TASKMAN.EXE
2008-11-29 06:30:59 ----A---- C:\WINDOWS\system32\batt.dll
2008-11-29 06:30:58 ----A---- C:\WINDOWS\notepad.exe
2008-11-29 06:30:57 ----A---- C:\WINDOWS\system32\storprop.dll
2008-11-29 06:30:48 ----ASH---- C:\Documents and Settings\All Users\Dados de aplicativos\desktop.ini
2008-11-29 06:30:43 ----RA---- C:\WINDOWS\SET8.tmp
2008-11-29 06:30:40 ----RA---- C:\WINDOWS\SET4.tmp
2008-11-29 06:30:39 ----RA---- C:\WINDOWS\SET3.tmp
2008-11-29 06:30:32 ----D---- C:\WINDOWS\system32\CatRoot2
2008-11-29 06:30:32 ----D---- C:\WINDOWS\system32\CatRoot
2008-11-29 06:30:27 ----SD---- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft
2008-11-29 06:30:02 ----D---- C:\Documents and Settings
2008-11-29 06:30:01 ----SHD---- C:\System Volume Information
2008-11-29 06:29:09 ----ASH---- C:\boot.ini
2008-11-29 06:25:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-11-29 06:25:00 ----RSD---- C:\WINDOWS\Fonts
2008-11-29 06:25:00 ----RD---- C:\WINDOWS\Web
2008-11-29 06:25:00 ----HD---- C:\WINDOWS\inf
2008-11-29 06:25:00 ----D---- C:\WINDOWS\WinSxS
2008-11-29 06:25:00 ----D---- C:\WINDOWS\twain_32
2008-11-29 06:25:00 ----D---- C:\WINDOWS\Temp
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\wins
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\wbem
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\usmt
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\spool
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\ShellExt
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\Setup
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\ras
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\oobe
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\npp
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\mui
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\inetsrv
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\IME
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\icsxml
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\ias
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\export
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\drivers
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\dhcp
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\config
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\3com_dmi
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\3076
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\2052
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1054
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1046
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1042
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1041
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1037
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1033
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1031
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1028
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1025
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32
2008-11-29 06:25:00 ----D---- C:\WINDOWS\system
2008-11-29 06:25:00 ----D---- C:\WINDOWS\security
2008-11-29 06:25:00 ----D---- C:\WINDOWS\Resources
2008-11-29 06:25:00 ----D---- C:\WINDOWS\repair
2008-11-29 06:25:00 ----D---- C:\WINDOWS\Provisioning
2008-11-29 06:25:00 ----D---- C:\WINDOWS\PeerNet
2008-11-29 06:25:00 ----D---- C:\WINDOWS\pchealth
2008-11-29 06:25:00 ----D---- C:\WINDOWS\mui
2008-11-29 06:25:00 ----D---- C:\WINDOWS\msapps
2008-11-29 06:25:00 ----D---- C:\WINDOWS\msagent
2008-11-29 06:25:00 ----D---- C:\WINDOWS\Media
2008-11-29 06:25:00 ----D---- C:\WINDOWS\java
2008-11-29 06:25:00 ----D---- C:\WINDOWS\ime
2008-11-29 06:25:00 ----D---- C:\WINDOWS\Help
2008-11-29 06:25:00 ----D---- C:\WINDOWS\ehome
2008-11-29 06:25:00 ----D---- C:\WINDOWS\Driver Cache
2008-11-29 06:25:00 ----D---- C:\WINDOWS\Debug
2008-11-29 06:25:00 ----D---- C:\WINDOWS\Cursors
2008-11-29 06:25:00 ----D---- C:\WINDOWS\Connection Wizard
2008-11-29 06:25:00 ----D---- C:\WINDOWS\Config
2008-11-29 06:25:00 ----D---- C:\WINDOWS\AppPatch
2008-11-29 06:25:00 ----D---- C:\WINDOWS\addins
2008-11-29 06:25:00 ----D---- C:\WINDOWS
======List of files/folders modified in the last 1 months======
2008-12-05 10:15:25 ----A---- C:\WINDOWS\system.ini
2008-12-04 08:21:58 ----A---- C:\WINDOWS\win.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-11-26 26944]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-11-26 111184]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-11-26 50864]
R1 intelppm;Driver de Processador Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40448]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-11-26 94032]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-11-26 23152]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 mf;mf; C:\WINDOWS\system32\DRIVERS\mf.sys [2008-04-13 63744]
R3 S3SavageNB;S3SavageNB; C:\WINDOWS\system32\DRIVERS\s3gnbm.sys [2004-08-03 166912]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\viaudios.sys [2004-03-17 117248]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe [2008-11-26 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe [2008-11-26 155160]
R2 WinDefend;Windows Defender; C:\Arquivos de programas\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe [2008-11-26 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe [2008-11-26 352920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.04 2008-12-05 16:21:42
======Uninstall list======
-->C:\Arquivos de programas\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 9 - Português-->MsiExec.exe /I{AC76BA86-7AD7-1046-7B44-A90000000001}
Assistente de Conexão do Windows Live-->MsiExec.exe /I{8984E374-6C93-427C-A3B9-AD92472FDCA0}
Atualização de Segurança para Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Atualização de Segurança para Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Atualização para Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Atualização para Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Atualização para Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
avast! Antivirus-->C:\Arquivos de programas\Alwil Software\Avast4\aswRunDll.exe "C:\Arquivos de programas\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Catálogo de Peças - FORD Personalizado-->C:\OiC\cat_perf\uninstall.exe /uninstall
CCleaner (remove only)-->"C:\Arquivos de programas\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{EBD5E7A9-DBB8-4E24-AE3A-CF9390AF1CCB}
Contacts-->MsiExec.exe /I{C6BDA6E5-B391-4CE5-8D86-B53AC96FFE03}
Easy Parts Fiat-->C:\OiC\cat_fiat\uninstall.exe /uninstall
FreeRIP v3.091-->"C:\Arquivos de programas\FreeRIP3\unins000.exe"
HijackThis 2.0.2-->"C:\Documents and Settings\Luciano Peças\Desktop\HijackThis.exe" /uninstall
Hotfix para Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Malwarebytes' Anti-Malware-->"C:\Arquivos de programas\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Access MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0015-0416-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0016-0416-0000-0000000FF1CE}
Microsoft Office Groove MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-00BA-0416-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0044-0416-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-00A1-0416-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-001A-0416-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0018-0416-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-001F-0416-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-002C-0416-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0019-0416-0000-0000000FF1CE}
Microsoft Office Shared MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-006E-0416-0000-0000000FF1CE}
Microsoft Office Word MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-001B-0416-0000-0000000FF1CE}
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs-->MsiExec.exe /X{90120000-00B2-0409-0000-0000000FF1CE}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Nero 7 Demo-->MsiExec.exe /I{1CBCC734-E92F-C744-D86C-3699D5351046}
NetMos Multi-IO Controller-->NmUninst.exe
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Tonic v1.0 (build 990)-->C:\Arquivos de programas\r2 Studios\Tonic\Uninstall.exe
UltraVnc v1.0.4-->"C:\Arquivos de programas\UltraVnc\unins000.exe"
UsbFix-->C:\Arquivos de programas\UsbFix\Uninstal.exe
VIA Audio Driver Setup Program-->RunDll32.exe UnAudioNT.dll,UninstallAudio C:\WINDOWS\IsUninst.exe -y-f"C:\ARQUIV~1\VIAudioi\SBASetup\Uninst.isu"
Windows Defender-->MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
Windows Live Beta (todos os programas)-->C:\Arquivos de programas\Windows Live\Installer\wlarp.exe
Windows Live Beta (todos os programas)-->MsiExec.exe /I{4FE37B71-AB78-4F4A-8327-A8401E5BD12A}
Windows Live Call-->MsiExec.exe /I{F99EE599-A088-4037-831E-587E9BB35826}
Windows Live Messenger-->MsiExec.exe /X{2B3D758E-DEE0-4868-B2F6-9CE435A13400}
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinZip-->"C:\Arquivos de programas\WinZip\WINZIP32.EXE" /uninstall
======Security center information======
AV: avast! antivirus 4.8.1296 [VPS 081208-0]
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
"PROCESSOR_REVISION"=0401
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
Opa TINOtec.
Por acaso este arquivo que pedi que enviasse ao VirusTotal (que você diz ser de confiança), trata-se de um keylogger ou algo do tipo? Porque pelo resultado do VirusTotal o arquivo é potencialmente perigoso!
Bem vamos continuar.
1ª Etapa
Delete as pasta do ComboFix que está em sua máquina e seu log (ComboFix.txt), ambos em C:. Caso esteja com a ferramenta ComboFix ainda no PC, vá em Iniciar > Executar, digite: combofix /u e dê um Enter. Delete também a ferramenta USBFix em Painel de Controle > Adicionar ou Remover Programas. Após isso, delete sua pasta em C:\Arquivos de Programas.
2ª Etapa
- Faça novamente o download do [ComboFix](http://download.bleepingcomputer.com/sUBs/ComboFix.exe) e salve-o na área de trabalho;
● Desative temporariamente o seu antivirus para não detectar a ferramenta como vírus;
● Duplo clique no ícone *combofix.exe* para iniciar o scan;
● Leia o contrato que aparecerá e clique em **Sim** para continuar;
● Abrirá uma janela do *Console de Recuperação*, clique em **Sim** para instalar. Se aparecer outra janela do Console, clique em OK > Sim;
● Aguarde enquanto o ComboFix faz o scan;
● Se ocorrer algum problema durante o scan, reinicie seu computador em Modo de Segurança e repita o procedimento;
● Não clique na janela do ComboFix e procure não utilizar o teclado também, para não atrapalhar a varredura da ferramenta;
● Se quiser sair ou parar o ComboFix, tecle **N**;
● Quando terminar seu micro será reiniciado. Após o reinicio, a ferramenta executará novamente, aguarde;
● Será gerado um log em C:\ComboFix.txt.
Cole este log em sua próxima resposta.
Aquele arquivo que você me pediu para analisar no virus total, é de um programa que me permite visualizar a tela de todas as estações da rede.
Segue abaixo relatório do combofix:
ComboFix 08-12-07.04 - Luciano Peças 2008-12-09 8:53:59.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.207 [GMT -2:00]
Executando de: c:\documents and settings\Luciano Peças\Desktop\ComboFix.exe
* Criado um novo ponto de restauro
.
(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-09 to 2008-12-09 ))))))))))))))))))))))))))))
.
2008-12-05 17:01 . 2008-12-05 17:01 116 --a------ c:\windows\NeroDigital.ini
2008-12-05 16:21 . 2008-12-05 16:21 <DIR> d-------- C:\rsit
2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Malwarebytes
2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes
2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware
2008-12-05 10:21 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-05 10:21 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-04 15:48 . 2008-12-04 15:48 65 --a------ C:\imp2.bat
2008-12-04 15:47 . 2008-12-04 15:47 <DIR> d-------- c:\arquivos de programas\MSECache
2008-12-04 08:28 . 2008-12-04 08:28 <DIR> d-------- c:\arquivos de programas\Microsoft Works
2008-12-04 08:21 . 2008-12-04 08:22 <DIR> d-------- c:\windows\SHELLNEW
2008-12-04 08:19 . 2008-12-04 08:31 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help
2008-12-04 08:18 . 2008-12-04 08:18 <DIR> dr-h----- C:\MSOCache
2008-12-03 18:13 . 2008-12-03 21:13 493 --a------ c:\windows\cat_fiat.ini
2008-12-03 18:08 . 2008-12-03 18:13 492 --a------ c:\windows\cat_perf.ini
2008-12-03 18:08 . 2008-12-03 08:12 453 --a------ c:\windows\cat_vw.ini
2008-12-03 18:08 . 2008-12-03 21:13 327 --ahs---- c:\windows\CHCT
2008-12-03 18:00 . 2008-12-03 18:15 <DIR> d-------- C:\CAT_VW
2008-12-03 17:55 . 2008-12-03 17:58 <DIR> d-------- C:\OiC
2008-12-03 17:55 . 2008-12-03 17:58 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\OiC
2008-12-03 17:54 . 2008-12-03 18:05 <DIR> d-------- c:\arquivos de programas\CepChev2
2008-12-03 17:46 . 2008-12-03 17:46 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Ahead
2008-12-03 17:43 . 2008-12-03 17:43 <DIR> d-------- c:\arquivos de programas\Nero
2008-12-03 17:43 . 2008-12-03 17:48 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Ahead
2008-12-03 17:41 . 2008-12-04 15:51 163 --a------ c:\windows\cdplayer.ini
2008-12-03 17:40 . 2008-12-03 17:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\FreeRIP
2008-12-03 17:40 . 2008-12-03 17:40 <DIR> d-------- c:\arquivos de programas\FreeRIP3
2008-12-03 17:29 . 2008-12-03 17:29 <DIR> d--h----- c:\windows\system32\GroupPolicy
2008-12-03 17:20 . 2008-12-03 17:20 <DIR> d-------- c:\documents and settings\Luciano Peças\Tracing
2008-12-03 17:20 . 2008-12-03 17:20 <DIR> d-------- c:\documents and settings\Luciano Peças\Tracing
2008-12-03 17:16 . 2008-12-03 17:16 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\skypePM
2008-12-03 17:16 . 2008-12-03 17:16 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-12-03 13:00 . 2008-12-03 13:00 <DIR> d--h----- c:\windows\PIF
2008-12-03 10:59 . 2008-12-03 10:59 <DIR> d-------- c:\arquivos de programas\Microsoft
2008-12-03 10:57 . 2008-12-03 10:59 <DIR> d-------- c:\arquivos de programas\Windows Live
2008-12-03 10:36 . 2008-12-03 10:36 <DIR> d-------- c:\arquivos de programas\Windows Defender
2008-12-03 10:34 . 2008-12-03 10:34 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live
2008-12-03 10:34 . 2008-12-03 10:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe
2008-12-03 10:32 . 2008-12-04 15:52 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Skype
2008-12-03 10:32 . 2008-12-03 10:32 <DIR> d-------- c:\arquivos de programas\Skype
2008-12-03 10:32 . 2008-12-03 10:32 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Skype
2008-12-03 10:31 . 2008-12-03 10:32 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Skype
2008-12-03 10:31 . 2008-12-03 10:31 <DIR> d-------- c:\arquivos de programas\CCleaner
2008-12-03 10:28 . 2008-12-03 10:29 <DIR> d-------- c:\arquivos de programas\UltraVnc
2008-12-03 10:24 . 2008-12-03 10:24 <DIR> d-------- c:\arquivos de programas\r2 Studios
2008-12-03 10:23 . 2006-12-08 16:19 134,144 --a------ c:\windows\system32\SMon2.exe
2008-12-02 17:14 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-02 17:04 . 2008-09-04 15:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-12-02 17:04 . 2008-10-15 14:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-12-02 16:57 . 2008-08-14 11:24 2,193,408 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-02 16:57 . 2008-08-14 11:24 2,149,376 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-02 16:57 . 2008-08-14 11:24 2,070,272 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-02 16:57 . 2008-08-14 11:24 2,028,032 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-02 16:57 . 2008-09-08 08:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-12-02 16:56 . 2008-08-14 08:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-12-02 16:55 . 2008-09-15 13:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-12-02 16:53 . 2008-05-01 12:36 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2008-12-02 16:51 . 2008-04-11 17:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-12-02 16:50 . 2008-05-09 08:55 512,000 -----c--- c:\windows\system32\dllcache\jscript.dll
2008-12-02 16:50 . 2008-05-09 08:55 430,080 -----c--- c:\windows\system32\dllcache\vbscript.dll
2008-12-02 16:50 . 2008-05-09 08:55 180,224 -----c--- c:\windows\system32\dllcache\scrobj.dll
2008-12-02 16:50 . 2008-05-09 08:55 172,032 -----c--- c:\windows\system32\dllcache\scrrun.dll
2008-12-02 16:50 . 2008-05-08 09:24 155,648 -----c--- c:\windows\system32\dllcache\wscript.exe
2008-12-02 16:50 . 2008-05-09 06:45 135,168 -----c--- c:\windows\system32\dllcache\cscript.exe
2008-12-02 16:50 . 2008-05-09 08:55 90,112 -----c--- c:\windows\system32\dllcache\wshext.dll
2008-12-02 16:48 . 2008-06-14 15:34 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-02 16:47 . 2008-05-08 12:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2008-12-02 16:41 . 2008-10-16 14:09 43,544 --a------ c:\windows\system32\wups2.dll
2008-12-02 16:41 . 2008-10-16 14:09 31,768 --a------ c:\windows\system32\wucltui.dll.mui
2008-12-02 16:41 . 2008-10-16 14:08 27,672 --a------ c:\windows\system32\wuaucpl.cpl.mui
2008-12-02 16:41 . 2008-10-16 14:08 27,672 --a------ c:\windows\system32\wuapi.dll.mui
2008-12-02 16:41 . 2008-10-16 14:07 18,968 --a------ c:\windows\system32\wuaueng.dll.mui
2008-12-02 11:51 . 2008-12-02 11:54 <DIR> d-------- c:\windows\ServicePackFiles
2008-12-02 11:51 . 2008-04-13 19:20 294,912 -----c--- c:\windows\system32\dllcache\dlimport.exe
2008-12-02 11:47 . 2006-12-28 12:01 19,569 --a------ c:\windows\002674_.tmp
2008-12-02 10:48 . 2008-12-02 17:17 <DIR> d-------- c:\windows\system32\pt-br
2008-12-02 10:46 . 2007-08-10 08:12 26,488 --a------ c:\windows\system32\spupdsvc.exe
2008-12-02 10:45 . 2008-12-02 17:19 <DIR> d--h----- c:\windows\$hf_mig$
2008-12-02 08:19 . 2008-12-02 08:19 <DIR> d-------- c:\arquivos de programas\Alwil Software
2008-12-01 11:01 . 2008-04-13 12:17 83,072 --a------ c:\windows\system32\drivers\wdmaud.sys
2008-12-01 11:01 . 2008-04-13 11:45 6,272 --a------ c:\windows\system32\drivers\splitter.sys
2008-12-01 11:00 . 2008-12-01 11:00 <DIR> d-------- c:\arquivos de programas\VIAudioi
2008-12-01 10:03 . 2004-10-05 16:54 306,688 --a------ c:\windows\IsUninst.exe
2008-12-01 10:03 . 2003-07-01 18:42 27,904 -ra------ c:\windows\system32\drivers\VIAAGP1.SYS
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 12:50 65 ----a-w C:\imp.bat
2008-11-29 10:53 --------- d-----w c:\arquivos de programas\microsoft frontpage
2008-11-29 10:50 --------- d-----w c:\arquivos de programas\Serviços on-line
2008-11-29 10:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-09 02:03 51,712 ----a-w c:\windows\system32\sirenacm.dll
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
Nota entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"SMon2"="c:\windows\system32\SMon2.exe" [2006-12-08 134144]
c:\documents and settings\Luciano Pe‡as\Menu Iniciar\Programas\Inicializar\
Run server as application.lnk - c:\arquivos de programas\UltraVnc\winvnc.exe [2008-12-03 1144384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 c:\arquivos de programas\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\SMon2.exe"=
"c:\\Arquivos de programas\\r2 Studios\\Tonic\\Tonic.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-02 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-02 20560]
R2 WinDefend;Windows Defender;"c:\arquivos de programas\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7aaf576-c2b3-11dd-a65b-000feaa4fb9c}]
\Shell\AutoRun\command - F:\rcukd.cmd
\Shell\explore\Command - F:\rcukd.cmd
\Shell\open\Command - F:\rcukd.cmd
.
Conteúdo da pasta 'Tarefas Agendadas'
2008-12-06 c:\windows\Tasks\MP Scheduled Scan.job
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-09 08:55:45
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
Tempo para conclusão: 2008-12-09 8:56:37
ComboFix-quarantined-files.txt 2008-12-09 10:56:33
Pré-execução: 12 pasta(s) 22.851.895.296 bytes disponíveis
Pós execução: 12 pasta(s) 22,860,939,264 bytes disponíveis
WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
172 --- E O F --- 2008-12-06 10:01:54
Selecione e copie o texto abaixo dentro do quote. Cole-o dentro do bloco de notas e salve no desktop como CFScript.txt
File::C:\imp2.bat
C:\imp.bat
F:\rcukd.cmd
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7aaf576-c2b3-11dd-a65b-000feaa4fb9c}]
Arraste o CFScript para o ComboFix como na imagem aqui abaixo e aguarde a execução automática da ferramenta:
/applications/core/interface/imageproxy/imageproxy.php?img=http://i14.photobucket.com/albums/a332/josemelo/CFScript.gif&key=fcdd916a6dfeb6dc54e698afb8a40991fe59f3a547da59080bd5ca22c62d63f3" alt="CFScript.gif" />
● Se for solicitado à você, pressione **Enter** para iniciar o processo de remoção;
● Não use o mouse nem o teclado quando o ComboFix estiver rodando;
● Quando terminar, será gerado um novo log que estará em C:\**ComboFix.txt**;
● Seu computador será reiniciado automaticamente;
Na sua próxima resposta, cole o ComboFix.txt e um novo log do HijackThis.
Brother, no arquivo CFScript, não inclui os arquivos .bat, pois os mesmos são do meu uso, para mapeamento de impressoras na rede.
Segue abaixo, relatórios:
ComboFix 08-12-09.02 - Luciano Peças 2008-12-10 8:15:56.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.166 [GMT -2:00]
Executando de: c:\documents and settings\Luciano Peças\Desktop\ComboFix.exe
Comandos utilizados :: c:\documents and settings\Luciano Peças\Desktop\CFScript.txt
* Criado um novo ponto de restauro
FILE ::
F:\rcukd.cmd
.
(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-10 to 2008-12-10 ))))))))))))))))))))))))))))
.
2008-12-09 16:28 . 2008-12-09 16:28 <DIR> d-------- c:\arquivos de programas\CygNET Systems Pvt. Ltd
2008-12-09 16:28 . 2008-12-09 16:28 12 --a------ c:\windows\system32\usbsys.tmp
2008-12-05 17:01 . 2008-12-05 17:01 116 --a------ c:\windows\NeroDigital.ini
2008-12-05 16:21 . 2008-12-05 16:21 <DIR> d-------- C:\rsit
2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Malwarebytes
2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes
2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware
2008-12-05 10:21 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-05 10:21 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-04 15:48 . 2008-12-04 15:48 65 --a------ C:\imp2.bat
2008-12-04 15:47 . 2008-12-04 15:47 <DIR> d-------- c:\arquivos de programas\MSECache
2008-12-04 08:28 . 2008-12-04 08:28 <DIR> d-------- c:\arquivos de programas\Microsoft Works
2008-12-04 08:21 . 2008-12-04 08:22 <DIR> d-------- c:\windows\SHELLNEW
2008-12-04 08:19 . 2008-12-04 08:31 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help
2008-12-04 08:18 . 2008-12-04 08:18 <DIR> dr-h----- C:\MSOCache
2008-12-03 18:13 . 2008-12-03 21:13 493 --a------ c:\windows\cat_fiat.ini
2008-12-03 18:08 . 2008-12-03 18:13 492 --a------ c:\windows\cat_perf.ini
2008-12-03 18:08 . 2008-12-03 08:12 453 --a------ c:\windows\cat_vw.ini
2008-12-03 18:08 . 2008-12-03 21:13 327 --ahs---- c:\windows\CHCT
2008-12-03 18:00 . 2008-12-03 18:15 <DIR> d-------- C:\CAT_VW
2008-12-03 17:55 . 2008-12-03 17:58 <DIR> d-------- C:\OiC
2008-12-03 17:55 . 2008-12-03 17:58 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\OiC
2008-12-03 17:54 . 2008-12-03 18:05 <DIR> d-------- c:\arquivos de programas\CepChev2
2008-12-03 17:46 . 2008-12-03 17:46 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Ahead
2008-12-03 17:43 . 2008-12-03 17:43 <DIR> d-------- c:\arquivos de programas\Nero
2008-12-03 17:43 . 2008-12-03 17:48 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Ahead
2008-12-03 17:41 . 2008-12-04 15:51 163 --a------ c:\windows\cdplayer.ini
2008-12-03 17:40 . 2008-12-03 17:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\FreeRIP
2008-12-03 17:40 . 2008-12-03 17:40 <DIR> d-------- c:\arquivos de programas\FreeRIP3
2008-12-03 17:29 . 2008-12-03 17:29 <DIR> d--h----- c:\windows\system32\GroupPolicy
2008-12-03 17:20 . 2008-12-03 17:20 <DIR> d-------- c:\documents and settings\Luciano Peças\Tracing
2008-12-03 17:20 . 2008-12-03 17:20 <DIR> d-------- c:\documents and settings\Luciano Peças\Tracing
2008-12-03 17:16 . 2008-12-03 17:16 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\skypePM
2008-12-03 17:16 . 2008-12-03 17:16 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-12-03 13:00 . 2008-12-03 13:00 <DIR> d--h----- c:\windows\PIF
2008-12-03 10:59 . 2008-12-03 10:59 <DIR> d-------- c:\arquivos de programas\Microsoft
2008-12-03 10:57 . 2008-12-03 10:59 <DIR> d-------- c:\arquivos de programas\Windows Live
2008-12-03 10:36 . 2008-12-03 10:36 <DIR> d-------- c:\arquivos de programas\Windows Defender
2008-12-03 10:34 . 2008-12-03 10:34 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live
2008-12-03 10:34 . 2008-12-03 10:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe
2008-12-03 10:32 . 2008-12-04 15:52 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Skype
2008-12-03 10:32 . 2008-12-03 10:32 <DIR> d-------- c:\arquivos de programas\Skype
2008-12-03 10:32 . 2008-12-03 10:32 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Skype
2008-12-03 10:31 . 2008-12-03 10:32 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Skype
2008-12-03 10:31 . 2008-12-03 10:31 <DIR> d-------- c:\arquivos de programas\CCleaner
2008-12-03 10:28 . 2008-12-09 16:36 <DIR> d-------- c:\arquivos de programas\UltraVnc
2008-12-03 10:24 . 2008-12-03 10:24 <DIR> d-------- c:\arquivos de programas\r2 Studios
2008-12-03 10:23 . 2006-12-08 16:19 134,144 --a------ c:\windows\system32\SMon2.exe
2008-12-02 17:14 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-02 17:04 . 2008-09-04 15:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-12-02 17:04 . 2008-10-15 14:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-12-02 16:57 . 2008-08-14 11:24 2,193,408 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-02 16:57 . 2008-08-14 11:24 2,149,376 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-02 16:57 . 2008-08-14 11:24 2,070,272 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-02 16:57 . 2008-08-14 11:24 2,028,032 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-02 16:57 . 2008-09-08 08:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-12-02 16:56 . 2008-08-14 08:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-12-02 16:55 . 2008-09-15 13:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-12-02 16:53 . 2008-05-01 12:36 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2008-12-02 16:51 . 2008-04-11 17:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-12-02 16:50 . 2008-05-09 08:55 512,000 -----c--- c:\windows\system32\dllcache\jscript.dll
2008-12-02 16:50 . 2008-05-09 08:55 430,080 -----c--- c:\windows\system32\dllcache\vbscript.dll
2008-12-02 16:50 . 2008-05-09 08:55 180,224 -----c--- c:\windows\system32\dllcache\scrobj.dll
2008-12-02 16:50 . 2008-05-09 08:55 172,032 -----c--- c:\windows\system32\dllcache\scrrun.dll
2008-12-02 16:50 . 2008-05-08 09:24 155,648 -----c--- c:\windows\system32\dllcache\wscript.exe
2008-12-02 16:50 . 2008-05-09 06:45 135,168 -----c--- c:\windows\system32\dllcache\cscript.exe
2008-12-02 16:50 . 2008-05-09 08:55 90,112 -----c--- c:\windows\system32\dllcache\wshext.dll
2008-12-02 16:48 . 2008-06-14 15:34 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-02 16:47 . 2008-05-08 12:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2008-12-02 16:41 . 2008-10-16 14:09 43,544 --a------ c:\windows\system32\wups2.dll
2008-12-02 16:41 . 2008-10-16 14:09 31,768 --a------ c:\windows\system32\wucltui.dll.mui
2008-12-02 16:41 . 2008-10-16 14:08 27,672 --a------ c:\windows\system32\wuaucpl.cpl.mui
2008-12-02 16:41 . 2008-10-16 14:08 27,672 --a------ c:\windows\system32\wuapi.dll.mui
2008-12-02 16:41 . 2008-10-16 14:07 18,968 --a------ c:\windows\system32\wuaueng.dll.mui
2008-12-02 11:51 . 2008-12-02 11:54 <DIR> d-------- c:\windows\ServicePackFiles
2008-12-02 11:51 . 2008-04-13 19:20 294,912 -----c--- c:\windows\system32\dllcache\dlimport.exe
2008-12-02 11:47 . 2006-12-28 12:01 19,569 --a------ c:\windows\002674_.tmp
2008-12-02 10:48 . 2008-12-02 17:17 <DIR> d-------- c:\windows\system32\pt-br
2008-12-02 10:46 . 2007-08-10 08:12 26,488 --a------ c:\windows\system32\spupdsvc.exe
2008-12-02 10:45 . 2008-12-02 17:19 <DIR> d--h----- c:\windows\$hf_mig$
2008-12-02 08:19 . 2008-12-02 08:19 <DIR> d-------- c:\arquivos de programas\Alwil Software
2008-12-01 11:01 . 2008-04-13 12:17 83,072 --a------ c:\windows\system32\drivers\wdmaud.sys
2008-12-01 11:01 . 2008-04-13 11:45 6,272 --a------ c:\windows\system32\drivers\splitter.sys
2008-12-01 11:00 . 2008-12-01 11:00 <DIR> d-------- c:\arquivos de programas\VIAudioi
2008-12-01 10:03 . 2004-10-05 16:54 306,688 --a------ c:\windows\IsUninst.exe
2008-12-01 10:03 . 2003-07-01 18:42 27,904 -ra------ c:\windows\system32\drivers\VIAAGP1.SYS
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 12:50 65 ----a-w C:\imp.bat
2008-11-29 10:53 --------- d-----w c:\arquivos de programas\microsoft frontpage
2008-11-29 10:50 --------- d-----w c:\arquivos de programas\Serviços on-line
2008-11-29 10:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
Nota entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"SMon2"="c:\windows\system32\SMon2.exe" [2006-12-08 134144]
"Tonic"="c:\arquivos de programas\r2 Studios\Tonic\Tonic.exe" [2006-09-03 840192]
c:\documents and settings\Luciano Pe‡as\Menu Iniciar\Programas\Inicializar\
Run server as application.lnk - c:\arquivos de programas\UltraVnc\winvnc.exe [2008-12-03 1144384]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\SMon2.exe"=
"c:\\Arquivos de programas\\r2 Studios\\Tonic\\Tonic.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"5553:TCP"= 5553:TCP:USBCopyNotify!
"5555:UDP"= 5555:UDP:USBCopyNotify!
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-02 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-02 20560]
R2 USBCopyNotifyClient;USBCopyNotify Client Service;"c:\arquivos de programas\CygNET Systems Pvt. Ltd\USB CopyNotify!\USBCopyNotifyClient.exe" [2008-12-09 344064]
R2 WinDefend;Windows Defender;"c:\arquivos de programas\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
.
Conteúdo da pasta 'Tarefas Agendadas'
2008-12-10 c:\windows\Tasks\MP Scheduled Scan.job
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-10 08:18:00
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
Tempo para conclusão: 2008-12-10 8:18:59
ComboFix-quarantined-files.txt 2008-12-10 10:18:56
ComboFix2.txt 2008-12-09 10:56:39
Pré-execução: 12 pasta(s) 22.904.852.480 bytes disponíveis
Pós execução: 12 pasta(s) 22,897,582,080 bytes disponíveis
166 --- E O F --- 2008-12-06 10:01:54
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:24:04, on 10/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\CygNET Systems Pvt. Ltd\USB CopyNotify!\USBCopyNotifyClient.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\SMon2.exe
C:\Arquivos de programas\r2 Studios\Tonic\Tonic.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\UltraVnc\winvnc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Arquivos de programas\internet explorer\iexplore.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Luciano Peças\Configurações locais\Temporary Internet Files\Content.IE5\091RDWN2\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://grupolbezerra.com.br/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [sMon2] C:\WINDOWS\system32\SMon2.exe
O4 - HKLM\..\Run: [Tonic] "C:\Arquivos de programas\r2 Studios\Tonic\Tonic.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Run server as application.lnk = C:\Arquivos de programas\UltraVnc\winvnc.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1228243184421
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O17 - HKLM\System\CS1\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O17 - HKLM\System\CS2\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O17 - HKLM\System\CS3\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: USBCopyNotify Client Service (USBCopyNotifyClient) - CygNET Systems Pvt. Ltd. - C:\Arquivos de programas\CygNET Systems Pvt. Ltd\USB CopyNotify!\USBCopyNotifyClient.exe
--
End of file - 5511 bytes
O log está limpo.
Vá em Iniciar > Executar, digite: combofix /u e tecle Enter. Delete a pasta C:\Qoobox e o log ComboFix.txt. Delete também a ferramenta RSIT e sua pasta C:\rsit.
Há algum problema na máquina ainda?
O log está limpo.
Maravilha...
Vá em Iniciar > Executar, digite: combofix /u e tecle Enter. Delete a pasta C:\Qoobox e o log ComboFix.txt. Delete também a ferramenta RSIT e sua pasta C:\rsit.
Feito.
Há algum problema na máquina ainda?
Negativo, está uma bala novamente.
Obrigado e abraços. :thumbsup:
PROBLEMA RESOLVIDO!
Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.
Acesse o site VirusTotal e clique em Arquivo. Selecione o arquivo azul abaixo em seu sistema e clique no botão Enviar Arquivo.
Aguarde a análise. Copie e cole aqui o link que estará em frente ao nome Permalink.
● Cole também o conteúdo do arquivo info.txt que estará em C:\rsit\info.txt.