Usamos cookies para medir audiência e melhorar sua experiência. Você pode aceitar ou recusar a qualquer momento. Veja sobre o iMasters.
segue o log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:00:48, on 16/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\windowsmp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: LocalStrike_English Toolbar - {41fe951c-2aaf-4f08-ab67-aebd1ed636f2} - C:\Arquivos de programas\LocalStrike_English\tbLoca.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\WINDOWS\system32\init.exe,
O2 - BHO: LocalStrike_English Toolbar - {41fe951c-2aaf-4f08-ab67-aebd1ed636f2} - C:\Arquivos de programas\LocalStrike_English\tbLoca.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: LocalStrike_English Toolbar - {41fe951c-2aaf-4f08-ab67-aebd1ed636f2} - C:\Arquivos de programas\LocalStrike_English\tbLoca.dll
O4 - HKLM\..\Run: [windowsmp] C:\WINDOWS\windowsmp.exe
O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TPPOLL] C:\Program Files\Topro\tppoll.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O17 - HKLM\System\CCS\Services\Tcpip\..\{300EDF33-DB30-43FA-AC3E-CF080FC6BB5F}: NameServer = 200.165.132.154
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 5058 bytes
>
Boa Tarde! danmex
<@> Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.malwarebytes.org/images/marcinsig.gif&key=2c45e7fd674c4b18d376ffbe83bf82547806ac60e230409c7eb4c31999009760" alt="marcinsig.gif" /> > Malwarebytes
<@> < Link - 2 >
<@> < Link - 3 >
<@> Atualize o programa!
<@> Escolha o escaneamento Completo!
<@> Desabilite programas de proteção,ao executar o malwarebytes.
<@> Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme!
<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.
<@> Para maiores detalhes: < Link >
<@> Poste: mbam-log-2009-xx-xx (00-00-00).txt <--
<><><><><><><><><><><>
<@> Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://billy-oneal.com/Canned%2520Speeches/speechimages/OTL/otlDesktopIcon.png&key=1894e5d356219721410c3360cbf9af74877ae24ccc81ed88026fc2d95dd96a07" alt="otlDesktopIcon.png" /> > ( ...by OldTimer Tools )
<@> Salve-o no desktop!
/applications/core/interface/imageproxy/imageproxy.php?img=http://www.geekstogo.com/misc/guide_icons/OTLI-scan.png&key=c1c0ea9de59a575dc1bed2c1a05aea719a59b87835a783b5874a791386bbd330" alt="OTLI-scan.png" />
<@> Segundo a imagem,mude a opção em "Output" para "Minimal Output".
<@> Duplo-clique em OTL.exe --> Marque a opção "Scan All Users".
<@> Clique em: < /applications/core/interface/imageproxy/imageproxy.php?img=http://billy-oneal.com/Canned%2520Speeches/speechimages/otli2/runscanbutton.png&key=e923c4e99200b3f328913bcb139cdc3df2bca2ef774057dc8a5231d49c60a872" alt="runscanbutton.png" /> > --> Aguarde!
<@> Poste:
<1> OTL.txt <--
<2> Extra.txt <--
Abraços!
boa tarde DIGRAM, muito obrigado por me ajudar ae vai os logs q você pediu
Malwarebytes' Anti-Malware 1.41
Versão do banco de dados: 2817
Windows 5.1.2600 Service Pack 3
17/9/2009 17:34:13
mbam-log-2009-09-17 (17-34-13).txt
Tipo de Verificação: Completa (C:\|D:\|)
Objetos verificados: 141067
Tempo decorrido: 14 minute(s), 43 second(s)
Processos da Memória infectados: 1
Módulos de Memória Infectados: 0
Chaves do Registro infectadas: 3
Valores do Registro infectados: 1
Ítens do Registro infectados: 2
Pastas infectadas: 0
Arquivos infectados: 9
Processos da Memória infectados:
C:\WINDOWS\windowsmp.exe (Worm.AutoRun) -> Unloaded process successfully.
Módulos de Memória Infectados:
(Nenhum ítem malicioso foi detectado)
Chaves do Registro infectadas:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\4lli (Worm.AutoRun) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\4lli (Worm.AutoRun) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\4lli (Worm.AutoRun) -> Quarantined and deleted successfully.
Valores do Registro infectados:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windowsmp (Worm.AutoRun) -> Quarantined and deleted successfully.
Ítens do Registro infectados:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,,C:\WINDOWS\system32\init.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.
Pastas infectadas:
(Nenhum ítem malicioso foi detectado)
Arquivos infectados:
D:\anderson arquivos\HD 2\Programas\DVD Anderson\WinRAR 3.60 beta 4\Crack\Unipatch.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Sonic Foundry Sound Forge 7.0\KEYGEN - SONIC FOUNDRY.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Sonic Foundry Sound Forge 7.0\SoundForge8Crack\SF8_Retail.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Sonic Foundry Sound Forge 7.0\SoundForge8Crack\SF8_Trial.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Sonic Foundry Vegas Vídeo 4.0\keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\autorun.inf (SuspectAutorun.Rootdrive.H) -> Quarantined and deleted successfully.
C:\explorer.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\WINDOWS\Windowsmp.exe (Worm.AutoRun) -> Quarantined and deleted successfully.
C:\WINDOWS\yoos.b (Worm.AutoRun) -> Quarantined and deleted successfully.
OTL logfile created on: 17/9/2009 17:38:34 - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\and\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy
1022,48 Mb Total Physical Memory | 694,55 Mb Available Physical Memory | 67,93% Memory free
2,40 Gb Paging File | 2,16 Gb Available in Paging File | 89,84% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas
Drive C: | 14,65 Gb Total Space | 4,22 Gb Free Space | 28,83% Space Free | Partition Type: NTFS
Drive D: | 134,39 Gb Total Space | 70,73 Gb Free Space | 52,63% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CASA
Current User Name: and
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Arquivos de programas\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Arquivos de programas\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Arquivos de programas\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Arquivos de programas\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\and\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Irmon [Auto | Running]) -- C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Arquivos de programas\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Arquivos de programas\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (asc3360pr [On_Demand | Running]) -- File not found
DRV - (DCamUSBIntel [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\TP6800.sys (Microsoft Corporation)
DRV - (FETNDIS [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (irsir [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\irsir.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (ViBus [boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ViBus.sys (VIA Technologies, Inc.)
DRV - (ViPrt [boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ViPrt.sys (VIA Technologies, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\S-1-5-21-1409082233-1637723038-1177238915-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ff [2009/09/14 22:41:07 | 00,000,000 | ---D | M]
O1 HOSTS File: (776 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [soundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Arquivos de programas\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TPPOLL] C:\Program Files\Topro\tppoll.exe File not found
O4 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001..\Run: [msnmsgr] C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.DLL (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de programas\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab](http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab) (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab](http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab) (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab](http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab) (Java Plug-in 1.6.0_15)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Minha página inicial atual) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/14 22:34:44 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/09/17 17:34:12 | 00,000,102 | -HS- | M] () - D:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/09/17 17:37:15 | 00,514,560 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\and\Desktop\OTL.exe
[2009/09/17 17:16:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Malwarebytes
[2009/09/17 17:16:57 | 00,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/09/17 17:16:55 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/17 17:16:54 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/17 17:16:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Malwarebytes
[2009/09/17 17:16:54 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Malwarebytes' Anti-Malware
[2009/09/17 17:16:18 | 04,045,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\and\Desktop\mbam-setup.exe
[2009/09/17 15:38:06 | 24,689,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/09/17 12:05:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Meus documentos\Os Meus Registos
[2009/09/17 09:20:25 | 00,074,240 | ---- | C] () -- C:\Documents and Settings\and\Meus documentos\fatura mama.doc
[2009/09/17 09:09:07 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbprint.sys
[2009/09/17 09:09:07 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbprint.sys
[2009/09/17 04:36:00 | 04,842,409 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Regis Danese - Faz Um Milagre Em Mim .mp3
[2009/09/16 20:00:04 | 00,475,448 | ---- | C] (Trend Micro Inc.) -- C:\HiJackThis.exe
[2009/09/16 02:47:28 | 04,319,360 | ---- | C] () -- C:\Documents and Settings\and\Desktop\William Nascimento - Deus vai na frente.mp3
[2009/09/15 22:55:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Windows Genuine Advantage
[2009/09/15 22:50:20 | 00,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmpns.dll
[2009/09/15 20:38:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Media Player Classic
[2009/09/15 16:15:15 | 00,000,786 | ---- | C] () -- C:\Documents and Settings\and\Desktop\sXe Injected.lnk
[2009/09/15 16:15:14 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\sXe Injected
[2009/09/15 16:12:56 | 00,000,000 | ---D | C] -- C:\temp
[2009/09/15 14:59:22 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\PluginLetras
[2009/09/15 14:20:32 | 00,272,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bthport.sys
[2009/09/15 14:20:32 | 00,272,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys
[2009/09/15 14:18:32 | 02,193,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2009/09/15 14:18:30 | 02,149,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2009/09/15 14:18:30 | 02,028,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2009/09/15 14:17:29 | 00,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/09/15 14:17:27 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll
[2009/09/15 14:17:26 | 01,985,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/09/15 14:17:26 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll
[2009/09/15 14:17:25 | 00,594,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/09/15 14:10:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/09/15 12:47:20 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2009/09/15 12:47:19 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2009/09/15 03:58:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2009/09/15 03:45:15 | 05,889,036 | -H-- | C] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\IconCache.db
[2009/09/15 03:45:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Avg7
[2009/09/15 01:53:34 | 00,001,227 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Atalho para minhas musics.lnk
[2009/09/15 01:50:31 | 00,001,650 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Counter-Strike Source.lnk
[2009/09/15 01:09:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus!
[2009/09/15 00:58:18 | 00,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MSTEE.sys
[2009/09/15 00:58:18 | 00,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstee.sys
[2009/09/15 00:58:17 | 00,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\NdisIP.sys
[2009/09/15 00:58:17 | 00,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndisip.sys
[2009/09/15 00:58:16 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipsink.ax
[2009/09/15 00:58:16 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipsink.ax
[2009/09/15 00:58:16 | 00,015,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\StreamIP.sys
[2009/09/15 00:58:16 | 00,015,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\streamip.sys
[2009/09/15 00:58:16 | 00,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\SLIP.sys
[2009/09/15 00:58:16 | 00,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\slip.sys
[2009/09/15 00:58:15 | 00,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\WSTCODEC.SYS
[2009/09/15 00:58:15 | 00,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wstcodec.sys
[2009/09/15 00:58:14 | 00,085,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\NABTSFEC.sys
[2009/09/15 00:58:14 | 00,085,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nabtsfec.sys
[2009/09/15 00:58:13 | 00,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\CCDECODE.sys
[2009/09/15 00:58:13 | 00,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ccdecode.sys
[2009/09/15 00:58:03 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\vidcap.ax
[2009/09/15 00:58:02 | 00,054,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\vfwwdm32.dll
[2009/09/15 00:58:01 | 00,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\kswdmcap.ax
[2009/09/15 00:58:01 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\kstvtune.ax
[2009/09/15 00:58:01 | 00,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\ksxbar.ax
[2009/09/15 00:58:00 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\dshowext.ax
[2009/09/15 00:50:33 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Messenger Plus! Live
[2009/09/15 00:50:11 | 00,013,496 | ---- | C] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT
[2009/09/15 00:25:24 | 00,221,184 | ---- | C] () -- C:\WINDOWS\ToproUI.exe
[2009/09/15 00:25:24 | 00,196,548 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\TP6800.SYS
[2009/09/15 00:25:24 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\CamLib.Dll
[2009/09/15 00:25:24 | 00,049,152 | ---- | C] (MyCompanyName) -- C:\WINDOWS\System32\drivers\CUSTPAGE.AX
[2009/09/15 00:25:24 | 00,049,152 | ---- | C] (MyCompanyName) -- C:\WINDOWS\CUSTPAGE.AX
[2009/09/15 00:25:23 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Topro
[2009/09/15 00:13:44 | 00,001,800 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Counter-Strike.lnk
[2009/09/15 00:06:07 | 00,002,241 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2009/09/15 00:06:07 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Steam
[2009/09/15 00:04:02 | 00,001,793 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Counter Strike 1.6 Non Steam.lnk
[2009/09/15 00:03:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\WinRAR
[2009/09/14 23:59:55 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Valve
[2009/09/14 23:37:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Meus documentos\Meus arquivos recebidos
[2009/09/14 23:27:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\nView_Profiles
[2009/09/14 23:26:10 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009/09/14 23:24:45 | 00,043,209 | ---- | C] () -- C:\WINDOWS\System32\nvapps.xml
[2009/09/14 23:24:40 | 00,016,356 | ---- | C] () -- C:\WINDOWS\System32\nvdisp.nvu
[2009/09/14 23:24:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\nview
[2009/09/14 23:24:30 | 00,141,016 | ---- | C] () -- C:\WINDOWS\System32\ALSNDMGR.WAV
[2009/09/14 23:24:30 | 00,000,000 | -H-D | C] -- C:\Arquivos de programas\InstallShield Installation Information
[2009/09/14 23:24:07 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\InstallShield
[2009/09/14 23:10:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Macromedia
[2009/09/14 23:06:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Adobe
[2009/09/14 22:54:37 | 00,000,000 | R--D | C] -- C:\Documents and Settings\and\Meus documentos\Meus vídeos
[2009/09/14 22:52:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Identities
[2009/09/14 22:52:04 | 00,000,000 | R--D | C] -- C:\Documents and Settings\and\Meus documentos\Minhas imagens
[2009/09/14 22:52:04 | 00,000,000 | -H-D | C] -- C:\Arquivos de programas\Uninstall Information
[2009/09/14 22:51:41 | 00,000,874 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Foxit Reader.lnk
[2009/09/14 22:51:41 | 00,000,704 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Total Video Player.lnk
[2009/09/14 22:51:41 | 00,000,704 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Total Video Converter.lnk
[2009/09/14 22:51:41 | 00,000,217 | ---- | C] () -- C:\Documents and Settings\and\Desktop\TUDO GRATIS.url
[2009/09/14 22:51:41 | 00,000,000 | --SD | C] -- C:\Documents and Settings\and\Dados de aplicativos\Microsoft
[2009/09/14 22:51:41 | 00,000,000 | R--D | C] -- C:\Documents and Settings\and\Meus documentos\Minhas músicas
[2009/09/14 22:51:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Sun
[2009/09/14 22:51:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Real
[2009/09/14 22:51:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\Real
[2009/09/14 22:51:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\Microsoft
[2009/09/14 22:51:37 | 00,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2009/09/14 22:49:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2009/09/14 22:49:20 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2009/09/14 22:49:11 | 00,000,006 | -H-- | C] () -- C:\WINDOWS\tasks\SA.DAT
[2009/09/14 22:49:04 | 00,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2009/09/14 22:47:44 | 00,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/09/14 22:47:09 | 00,028,288 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xjis.nls
[2009/09/14 22:47:03 | 00,031,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\weitekp9.sys
[2009/09/14 22:47:02 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wamreg51.dll
[2009/09/14 22:47:02 | 00,041,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\weitekp9.dll
[2009/09/14 22:47:01 | 00,368,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3svc.dll
[2009/09/14 22:47:01 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wam51.dll
[2009/09/14 22:47:01 | 00,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3ext.dll
[2009/09/14 22:47:01 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wamps51.dll
[2009/09/14 22:47:01 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3svapi.dll
[2009/09/14 22:47:01 | 00,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w3ctrs51.dll
[2009/09/14 22:47:00 | 00,048,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\w32.dll
[2009/09/14 22:46:59 | 00,103,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uihelper.dll
[2009/09/14 22:46:58 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tools.dll
[2009/09/14 22:46:58 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsprof.exe
[2009/09/14 22:46:57 | 00,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\thawbrkr.dll
[2009/09/14 22:46:57 | 00,021,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdipx.sys
[2009/09/14 22:46:57 | 00,019,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdspx.sys
[2009/09/14 22:46:57 | 00,013,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdasync.sys
[2009/09/14 22:46:56 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\svcext51.dll
[2009/09/14 22:46:56 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\status.dll
[2009/09/14 22:46:55 | 00,101,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srusbusd.dll
[2009/09/14 22:46:55 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sspifilt.dll
[2009/09/14 22:46:55 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ssinc51.dll
[2009/09/14 22:46:54 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmptrap.exe
[2009/09/14 22:46:54 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_snprfdll.dll
[2009/09/14 22:46:53 | 00,358,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpincl.dll
[2009/09/14 22:46:53 | 00,259,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpcl.dll
[2009/09/14 22:46:53 | 00,188,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpsmir.dll
[2009/09/14 22:46:53 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpthrd.dll
[2009/09/14 22:46:53 | 00,033,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmp.exe
[2009/09/14 22:46:53 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpstup.dll
[2009/09/14 22:46:53 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\snmpmib.dll
[2009/09/14 22:46:52 | 00,463,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpsvc.dll
[2009/09/14 22:46:52 | 00,236,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smi2smir.exe
[2009/09/14 22:46:52 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smierrsm.dll
[2009/09/14 22:46:52 | 00,012,800 | ---- | C] (Microsoft Corporation
) -- C:\WINDOWS\System32\dllcache\EXCH_smtpctrs.dll
[2009/09/14 22:46:52 | 00,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpapi.dll
[2009/09/14 22:46:52 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smimsgif.dll
[2009/09/14 22:46:52 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smierrsy.dll
[2009/09/14 22:46:51 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm9aw.dll
[2009/09/14 22:46:51 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smb6w.dll
[2009/09/14 22:46:51 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sma3w.dll
[2009/09/14 22:46:51 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8cw.dll
[2009/09/14 22:46:51 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm93w.dll
[2009/09/14 22:46:51 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm92w.dll
[2009/09/14 22:46:51 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm90w.dll
[2009/09/14 22:46:51 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8dw.dll
[2009/09/14 22:46:51 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm8aw.dll
[2009/09/14 22:46:51 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm89w.dll
[2009/09/14 22:46:50 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm87w.dll
[2009/09/14 22:46:50 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm81w.dll
[2009/09/14 22:46:50 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sm59w.dll
[2009/09/14 22:46:50 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\simptcp.dll
[2009/09/14 22:46:49 | 00,435,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\class_ss.dll
[2009/09/14 22:46:48 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_seos.dll
[2009/09/14 22:46:47 | 00,221,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\seo.dll
[2009/09/14 22:46:47 | 00,057,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_scripto.dll
[2009/09/14 22:46:47 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rwnh.dll
[2009/09/14 22:46:46 | 00,080,896 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2009/09/14 22:46:46 | 00,080,896 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2009/09/14 22:46:46 | 00,029,184 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2009/09/14 22:46:46 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rw001ext.dll
[2009/09/14 22:46:46 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcref.dll
[2009/09/14 22:46:45 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_regtrace.exe
[2009/09/14 22:46:45 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\register.exe
[2009/09/14 22:46:44 | 00,020,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ramdisk.sys
[2009/09/14 22:46:44 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\quser.exe
[2009/09/14 22:46:44 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\query.exe
[2009/09/14 22:46:43 | 00,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prcp.nls
[2009/09/14 22:46:43 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pwsdata.dll
[2009/09/14 22:46:42 | 00,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxviceo.dll
[2009/09/14 22:46:42 | 00,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prc.nls
[2009/09/14 22:46:42 | 00,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\permchk.dll
[2009/09/14 22:46:42 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxmcro.dll
[2009/09/14 22:46:42 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pmxgl.dll
[2009/09/14 22:46:41 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pagecnt.dll
[2009/09/14 22:46:39 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nextlink.dll
[2009/09/14 22:46:39 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nsepm.dll
[2009/09/14 22:46:39 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_ntfsdrv.dll
[2009/09/14 22:46:37 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtstocom.exe
[2009/09/14 22:46:34 | 01,875,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msir3jp.lex
[2009/09/14 22:46:34 | 00,098,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msir3jp.dll
[2009/09/14 22:46:34 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msiregmv.exe
[2009/09/14 22:46:30 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\migregdb.exe
[2009/09/14 22:46:29 | 00,092,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mga.sys
[2009/09/14 22:46:29 | 00,092,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mga.dll
[2009/09/14 22:46:29 | 00,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\metada51.dll
[2009/09/14 22:46:28 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_mailmsg.dll
[2009/09/14 22:46:28 | 00,037,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\md5filt.dll
[2009/09/14 22:46:28 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mdsync.dll
[2009/09/14 22:46:27 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lmmib2.dll
[2009/09/14 22:46:27 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lpdsvc.dll
[2009/09/14 22:46:27 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\logscrpt.dll
[2009/09/14 22:46:27 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lprmon.dll
[2009/09/14 22:46:27 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lonsint.dll
[2009/09/14 22:46:26 | 01,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2009/09/14 22:46:26 | 00,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\korwbrkr.dll
[2009/09/14 22:46:26 | 00,047,066 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ksc.nls
[2009/09/14 22:46:25 | 00,027,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iscomlog.dll
[2009/09/14 22:46:25 | 00,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jupiw.dll
[2009/09/14 22:46:25 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iwrps.dll
[2009/09/14 22:46:25 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isapips.dll
[2009/09/14 22:46:24 | 00,257,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\infocomm.dll
[2009/09/14 22:46:24 | 00,035,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iprip.dll
[2009/09/14 22:46:24 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\infoctrs.dll
[2009/09/14 22:46:23 | 00,311,359 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imepadsv.exe
[2009/09/14 22:46:23 | 00,102,463 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imepadsm.dll
[2009/09/14 22:46:23 | 00,102,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imlang.dll
[2009/09/14 22:46:23 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetin51.exe
[2009/09/14 22:46:22 | 00,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iische51.dll
[2009/09/14 22:46:22 | 00,079,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iislog51.dll
[2009/09/14 22:46:22 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisclex4.dll
[2009/09/14 22:46:22 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisadmin.dll
[2009/09/14 22:46:22 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iiscrmap.dll
[2009/09/14 22:46:22 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisfecnv.dll
[2009/09/14 22:46:22 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iissync.exe
[2009/09/14 22:46:22 | 00,003,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iismui.dll
[2009/09/14 22:46:21 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieencode.dll
[2009/09/14 22:46:20 | 00,268,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpext.dll
[2009/09/14 22:46:20 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpod51.dll
[2009/09/14 22:46:20 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hostmib.dll
[2009/09/14 22:46:20 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\httpmb51.dll
[2009/09/14 22:46:19 | 00,032,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\gzip.dll
[2009/09/14 22:46:18 | 00,562,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsst.dll
[2009/09/14 22:46:18 | 00,400,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsxp32.dll
[2009/09/14 22:46:18 | 00,397,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxstiff.dll
[2009/09/14 22:46:18 | 00,268,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxssvc.exe
[2009/09/14 22:46:18 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxst30.dll
[2009/09/14 22:46:18 | 00,195,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxswzrd.dll
[2009/09/14 22:46:18 | 00,155,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsui.dll
[2009/09/14 22:46:18 | 00,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsroute.dll
[2009/09/14 22:46:18 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxssend.exe
[2009/09/14 22:46:17 | 00,285,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscomex.dll
[2009/09/14 22:46:17 | 00,234,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscover.exe
[2009/09/14 22:46:17 | 00,137,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsclntr.dll
[2009/09/14 22:46:17 | 00,072,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscom.dll
[2009/09/14 22:46:17 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsevent.dll
[2009/09/14 22:46:17 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsdrv.dll
[2009/09/14 22:46:17 | 00,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsmon.dll
[2009/09/14 22:46:17 | 00,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsext32.dll
[2009/09/14 22:46:17 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsperf.dll
[2009/09/14 22:46:17 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsres.dll
[2009/09/14 22:46:16 | 00,451,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsapi.dll
[2009/09/14 22:46:16 | 00,142,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxsclnt.exe
[2009/09/14 22:46:16 | 00,127,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpsv251.dll
[2009/09/14 22:46:16 | 00,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fxscfgwz.dll
[2009/09/14 22:46:16 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpctrs2.dll
[2009/09/14 22:46:16 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpmib.dll
[2009/09/14 22:46:15 | 00,618,605 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4autl.dll
[2009/09/14 22:46:15 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2009/09/14 22:46:15 | 00,024,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpadmcgi.exe
[2009/09/14 22:46:15 | 00,020,541 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpadmdll.dll
[2009/09/14 22:46:15 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\flattemp.exe
[2009/09/14 22:46:14 | 00,106,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\evntagnt.dll
[2009/09/14 22:46:14 | 00,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\evntwin.exe
[2009/09/14 22:46:14 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_fcachdll.dll
[2009/09/14 22:46:14 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\evntcmd.exe
[2009/09/14 22:46:14 | 00,014,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\exstrace.dll
[2009/09/14 22:46:13 | 00,057,856 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimgd.dll
[2009/09/14 22:46:13 | 00,045,568 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunid.dll
[2009/09/14 22:46:13 | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucmd.dll
[2009/09/14 22:46:13 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\et4000.sys
[2009/09/14 22:46:12 | 00,514,587 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\edb500.dll
[2009/09/14 22:46:09 | 00,042,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\davcdata.exe
[2009/09/14 22:46:09 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cprofile.exe
[2009/09/14 22:46:08 | 00,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\convlog.exe
[2009/09/14 22:46:08 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\controt.dll
[2009/09/14 22:46:08 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\counters.dll
[2009/09/14 22:46:07 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\compfilt.dll
[2009/09/14 22:46:06 | 01,677,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chsbrkr.dll
[2009/09/14 22:46:06 | 00,838,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chtbrkr.dll
[2009/09/14 22:46:05 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chgport.exe
[2009/09/14 22:46:05 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chgusr.exe
[2009/09/14 22:46:05 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chglogon.exe
[2009/09/14 22:46:05 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\change.exe
[2009/09/14 22:46:04 | 00,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2009/09/14 22:46:03 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_720.nls
[2009/09/14 22:46:02 | 00,082,172 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bopomofo.nls
[2009/09/14 22:46:02 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\browscap.dll
[2009/09/14 22:46:01 | 00,066,728 | ---- | C] () -- C:\WINDOWS\System32\dllcache\big5.nls
[2009/09/14 22:46:01 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\authfilt.dll
[2009/09/14 22:46:00 | 00,374,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asp51.dll
[2009/09/14 22:46:00 | 00,332,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aqueue.dll
[2009/09/14 22:46:00 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_aqadmin.dll
[2009/09/14 22:46:00 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\asptxn.dll
[2009/09/14 22:46:00 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aspperf.dll
[2009/09/14 22:45:59 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\appconf.dll
[2009/09/14 22:45:58 | 00,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adrot.dll
[2009/09/14 22:45:58 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admxprox.dll
[2009/09/14 22:45:58 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll
[2009/09/14 22:45:57 | 00,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admexs.dll
[2009/09/14 22:45:54 | 00,032,827 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcptest.exe
[2009/09/14 22:45:54 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tcptsat.dll
[2009/09/14 22:45:54 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wamregps.dll
[2009/09/14 22:45:53 | 02,134,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpsnap.dll
[2009/09/14 22:45:53 | 00,189,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpadm.dll
[2009/09/14 22:45:53 | 00,020,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shtml.dll
[2009/09/14 22:45:53 | 00,016,437 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shtml.exe
[2009/09/14 22:45:53 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\staxmem.dll
[2009/09/14 22:45:50 | 00,077,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\logui.ocx
[2009/09/14 22:45:49 | 00,837,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetmgr.dll
[2009/09/14 22:45:49 | 00,171,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisui.dll
[2009/09/14 22:45:49 | 00,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isatq.dll
[2009/09/14 22:45:49 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetsloc.dll
[2009/09/14 22:45:49 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\infoadmn.dll
[2009/09/14 22:45:49 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetmgr.exe
[2009/09/14 22:45:48 | 00,133,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrtl.dll
[2009/09/14 22:45:48 | 00,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisext51.dll
[2009/09/14 22:45:48 | 00,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iismap.dll
[2009/09/14 22:45:48 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrstas.exe
[2009/09/14 22:45:48 | 00,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisreset.exe
[2009/09/14 22:45:48 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ftpsapi2.dll
[2009/09/14 22:45:48 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iisrstap.dll
[2009/09/14 22:45:47 | 00,598,071 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmc.dll
[2009/09/14 22:45:47 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpmmcsat.dll
[2009/09/14 22:45:47 | 00,188,494 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpcount.exe
[2009/09/14 22:45:47 | 00,109,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98swin.exe
[2009/09/14 22:45:47 | 00,020,541 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpexedll.dll
[2009/09/14 22:45:47 | 00,020,538 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fpremadm.exe
[2009/09/14 22:45:46 | 00,876,653 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4awel.dll
[2009/09/14 22:45:46 | 00,147,513 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4apws.dll
[2009/09/14 22:45:46 | 00,102,509 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4atxt.dll
[2009/09/14 22:45:46 | 00,049,212 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4awebs.dll
[2009/09/14 22:45:46 | 00,049,210 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4areg.dll
[2009/09/14 22:45:46 | 00,041,020 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4avnb.dll
[2009/09/14 22:45:46 | 00,032,826 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4avss.dll
[2009/09/14 22:45:46 | 00,014,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp98sadm.exe
[2009/09/14 22:45:45 | 00,188,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cfgwiz.exe
[2009/09/14 22:45:45 | 00,184,435 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4amsft.dll
[2009/09/14 22:45:45 | 00,082,035 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fp4anscp.dll
[2009/09/14 22:45:45 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cnfgprts.ocx
[2009/09/14 22:45:45 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\coadmin.dll
[2009/09/14 22:45:44 | 00,290,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\adsiis51.dll
[2009/09/14 22:45:44 | 00,280,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\certwiz.ocx
[2009/09/14 22:45:44 | 00,096,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\certmap.ocx
[2009/09/14 22:45:44 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admwprox.dll
[2009/09/14 22:45:44 | 00,020,540 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\author.dll
[2009/09/14 22:45:44 | 00,016,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\author.exe
[2009/09/14 22:45:43 | 00,020,540 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admin.dll
[2009/09/14 22:45:43 | 00,016,439 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\admin.exe
[2009/09/14 22:45:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2009/09/14 22:45:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2009/09/14 22:45:41 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\xerox
[2009/09/14 22:45:41 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\microsoft frontpage
[2009/09/14 22:45:23 | 00,608,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comctl32.ocx
[2009/09/14 22:45:21 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Total Video Converter
[2009/09/14 22:45:19 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Microsoft
[2009/09/14 22:45:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documentos\microsoft
[2009/09/14 22:45:15 | 00,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2009/09/14 22:43:52 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Windows Live
[2009/09/14 22:43:29 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\Windows Live
[2009/09/14 22:43:08 | 00,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/09/14 22:42:39 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Microsoft.NET
[2009/09/14 22:42:37 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\DESIGNER
[2009/09/14 22:42:35 | 00,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2009/09/14 22:42:35 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Microsoft Office
[2009/09/14 22:41:51 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Foxit Reader
[2009/09/14 22:41:48 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/09/14 22:41:48 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/09/14 22:41:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\ESTsoft
[2009/09/14 22:41:47 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\WinRAR
[2009/09/14 22:41:39 | 00,278,528 | ---- | C] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2009/09/14 22:41:39 | 00,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/09/14 22:41:39 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2009/09/14 22:41:38 | 00,860,160 | ---- | C] (http://www.mp3dev.org/) -- C:\WINDOWS\System32\lameACM.acm
[2009/09/14 22:41:38 | 00,217,088 | ---- | C] (www.helixcommunity.org) -- C:\WINDOWS\System32\yv12vfw.dll
[2009/09/14 22:41:38 | 00,118,784 | ---- | C] (fccHandler) -- C:\WINDOWS\System32\ac3acm.acm
[2009/09/14 22:41:38 | 00,000,414 | ---- | C] () -- C:\WINDOWS\System32\lame_acm.xml
[2009/09/14 22:41:37 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009/09/14 22:41:37 | 00,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/09/14 22:41:37 | 00,683,520 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divx.dll
[2009/09/14 22:41:37 | 00,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/09/14 22:41:37 | 00,081,920 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\dpl100.dll
[2009/09/14 22:41:36 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/09/14 22:41:36 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/09/14 22:41:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Real
[2009/09/14 22:41:35 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\K-Lite Codec Pack
[2009/09/14 22:40:35 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Java
[2009/09/14 22:39:38 | 00,799,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3D10WARP_beta.dll
[2009/09/14 22:39:38 | 00,799,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3D10WARP.dll
[2009/09/14 22:39:38 | 00,728,858 | ---- | C] () -- C:\WINDOWS\System32\unins000.exe
[2009/09/14 22:39:38 | 00,513,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3D11_beta.dll
[2009/09/14 22:39:38 | 00,513,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3D11.dll
[2009/09/14 22:39:38 | 00,496,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX10d_40.dll
[2009/09/14 22:39:38 | 00,496,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX10d.dll
[2009/09/14 22:39:38 | 00,484,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\DXGI_beta.dll
[2009/09/14 22:39:38 | 00,484,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\DXGI.dll
[2009/09/14 22:39:38 | 00,480,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3D11Ref.dll
[2009/09/14 22:39:38 | 00,471,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3D10Level9_beta.dll
[2009/09/14 22:39:38 | 00,471,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3D10Level9.dll
[2009/09/14 22:39:38 | 00,462,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3D11SDKLayers.dll
[2009/09/14 22:39:38 | 00,234,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX11_40.dll
[2009/09/14 22:39:38 | 00,208,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3d10_1core.dll
[2009/09/14 22:39:38 | 00,159,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3d10_1.dll
[2009/09/14 22:39:38 | 00,004,096 | ---- | C] (My Company) -- C:\WINDOWS\System32\MyProg.exe
[2009/09/14 22:39:38 | 00,002,161 | ---- | C] () -- C:\WINDOWS\System32\unins000.dat
[2009/09/14 22:39:31 | 00,499,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp71.dll
[2009/09/14 22:39:31 | 00,348,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr71.dll
[2009/09/14 22:38:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2009/09/14 22:36:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2009/09/14 22:35:52 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/09/14 22:35:27 | 00,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2009/09/14 22:35:27 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2009/09/14 22:35:22 | 00,017,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2009/09/14 22:35:14 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\umdf
[2009/09/14 22:35:00 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Windows Media Connect 2
[2009/09/14 22:34:59 | 00,026,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdsvc.exe
[2009/09/14 22:34:44 | 00,002,969 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/09/14 22:34:44 | 00,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2009/09/14 22:34:44 | 00,000,000 | RHS- | C] () -- C:\IO.SYS
[2009/09/14 22:34:44 | 00,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2009/09/14 22:34:44 | 00,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2009/09/14 22:34:41 | 00,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/09/14 22:34:41 | 00,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/09/14 22:34:40 | 00,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2009/09/14 22:34:32 | 00,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mapi32.dll
[2009/09/14 22:34:01 | 00,000,488 | RH-- | C] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2009/09/14 22:34:01 | 00,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2009/09/14 22:34:01 | 00,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2009/09/14 22:34:01 | 00,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\WindowsShell.Manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2009/09/14 22:33:56 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documentos\Minhas músicas
[2009/09/14 22:33:56 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documentos\Minhas imagens
[2009/09/14 22:33:52 | 00,000,000 | -H-D | C] -- C:\Arquivos de programas\WindowsUpdate
[2009/09/14 22:33:49 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Serviços on-line
[2009/09/14 22:33:35 | 00,118,784 | ---- | C] (Microsoft Corporation
) -- C:\WINDOWS\System32\msg723.acm
[2009/09/14 22:33:35 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srdiag.exe
[2009/09/14 22:33:35 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nmevtmsg.dll
[2009/09/14 22:33:35 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wb32.exe
[2009/09/14 22:33:35 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nmevtmsg.dll
[2009/09/14 22:33:35 | 00,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2009/09/14 22:33:34 | 00,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\acctres.dll
[2009/09/14 22:33:34 | 00,068,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\acctres.dll
[2009/09/14 22:33:34 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cb32.exe
[2009/09/14 22:33:34 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\Serviços
[2009/09/14 22:33:32 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\trialoc.dll
[2009/09/14 22:33:32 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icfgnt5.dll
[2009/09/14 22:33:32 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icfgnt5.dll
[2009/09/14 22:33:32 | 00,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2009/09/14 22:33:31 | 00,235,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mssoap1.dll
[2009/09/14 22:33:31 | 00,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwtutor.exe
[2009/09/14 22:33:31 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwres.dll
[2009/09/14 22:33:31 | 00,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wisc10.dll
[2009/09/14 22:33:31 | 00,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mssoapr.dll
[2009/09/14 22:33:31 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isignup.exe
[2009/09/14 22:33:31 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\MSSoap
[2009/09/14 22:33:30 | 00,851,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vgx.dll
[2009/09/14 22:33:30 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieinfo5.ocx
[2009/09/14 22:33:29 | 01,674,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\setup_wm.exe
[2009/09/14 22:33:29 | 00,096,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmpband.dll
[2009/09/14 22:33:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2009/09/14 22:33:28 | 00,786,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\migrate.exe
[2009/09/14 22:33:28 | 00,244,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mpvis.dll
[2009/09/14 22:33:28 | 00,226,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\npdrmv2.dll
[2009/09/14 22:33:28 | 00,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmpns.dll
[2009/09/14 22:33:28 | 00,064,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmplayer.exe
[2009/09/14 22:33:28 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\custsat.dll
[2009/09/14 22:33:28 | 00,010,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\npwmsdrm.dll
[2009/09/14 22:33:27 | 00,364,544 | ---- | C] (Microsoft Corporation (written by Digital Renaissance Inc.)) -- C:\WINDOWS\System32\dllcache\npdsplay.dll
[2009/09/14 22:33:27 | 00,323,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll
[2009/09/14 22:33:27 | 00,323,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wucltui.dll
[2009/09/14 22:33:27 | 00,202,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuweb.dll
[2009/09/14 22:33:27 | 00,202,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuweb.dll
[2009/09/14 22:33:27 | 00,183,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaueng1.dll
[2009/09/14 22:33:27 | 00,183,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuaueng1.dll
[2009/09/14 22:33:27 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauserv.dll
[2009/09/14 22:33:27 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuauserv.dll
[2009/09/14 22:33:27 | 00,004,639 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mplayer2.exe
[2009/09/14 22:33:26 | 01,809,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaueng.dll
[2009/09/14 22:33:26 | 01,809,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuaueng.dll
[2009/09/14 22:33:26 | 00,561,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll
[2009/09/14 22:33:26 | 00,561,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuapi.dll
[2009/09/14 22:33:26 | 00,409,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qmgr.dll
[2009/09/14 22:33:26 | 00,409,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qmgr.dll
[2009/09/14 22:33:26 | 00,213,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaucpl.cpl
[2009/09/14 22:33:26 | 00,213,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuaucpl.cpl
[2009/09/14 22:33:26 | 00,167,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauclt1.exe
[2009/09/14 22:33:26 | 00,167,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuauclt1.exe
[2009/09/14 22:33:26 | 00,051,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauclt.exe
[2009/09/14 22:33:26 | 00,051,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wuauclt.exe
[2009/09/14 22:33:26 | 00,034,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wups.dll
[2009/09/14 22:33:26 | 00,034,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wups.dll
[2009/09/14 22:33:26 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qmgrprxy.dll
[2009/09/14 22:33:26 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qmgrprxy.dll
[2009/09/14 22:33:26 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bitsprx2.dll
[2009/09/14 22:33:26 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx2.dll
[2009/09/14 22:33:26 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bitsprx4.dll
[2009/09/14 22:33:26 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bitsprx3.dll
[2009/09/14 22:33:26 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx4.dll
[2009/09/14 22:33:26 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx3.dll
[2009/09/14 22:33:25 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2res2.dll
[2009/09/14 22:33:25 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2eres.dll
[2009/09/14 22:33:24 | 04,274,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2res.dll
[2009/09/14 22:33:24 | 00,502,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2fxa.dll
[2009/09/14 22:33:24 | 00,402,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2filt.dll
[2009/09/14 22:33:24 | 00,325,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2fxb.dll
[2009/09/14 22:33:24 | 00,167,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2ae.dll
[2009/09/14 22:33:24 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmm2ext.dll
[2009/09/14 22:33:23 | 03,558,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\moviemk.exe
[2009/09/14 22:33:23 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Movie Maker
[2009/09/14 22:33:10 | 00,566,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msobmain.dll
[2009/09/14 22:33:10 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msobdl.dll
[2009/09/14 22:33:09 | 00,122,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msobcomm.dll
[2009/09/14 22:33:09 | 00,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oobebaln.exe
[2009/09/14 22:33:09 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msobshel.dll
[2009/09/14 22:33:09 | 00,029,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msoobe.exe
[2009/09/14 22:33:09 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msobweb.dll
[2009/09/14 22:33:06 | 00,382,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rstrui.exe
[2009/09/14 22:33:06 | 00,129,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fltMgr.sys
[2009/09/14 22:33:06 | 00,129,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fltmgr.sys
[2009/09/14 22:33:06 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fltMc.exe
[2009/09/14 22:33:06 | 00,023,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fltmc.exe
[2009/09/14 22:33:06 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fltlib.dll
[2009/09/14 22:33:06 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fltlib.dll
[2009/09/14 22:33:05 | 00,240,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srrstr.dll
[2009/09/14 22:33:05 | 00,240,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srrstr.dll
[2009/09/14 22:33:05 | 00,188,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msh261.drv
[2009/09/14 22:33:05 | 00,171,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srsvc.dll
[2009/09/14 22:33:05 | 00,171,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srsvc.dll
[2009/09/14 22:33:05 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ils.dll
[2009/09/14 22:33:05 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ils.dll
[2009/09/14 22:33:05 | 00,073,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sr.sys
[2009/09/14 22:33:05 | 00,073,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sr.sys
[2009/09/14 22:33:05 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msconf.dll
[2009/09/14 22:33:05 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msconf.dll
[2009/09/14 22:33:05 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srclient.dll
[2009/09/14 22:33:05 | 00,067,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\srclient.dll
[2009/09/14 22:33:05 | 00,034,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mnmdd.dll
[2009/09/14 22:33:05 | 00,034,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mnmdd.dll
[2009/09/14 22:33:05 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mnmsrvc.exe
[2009/09/14 22:33:05 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mnmsrvc.exe
[2009/09/14 22:33:05 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nmmkcert.dll
[2009/09/14 22:33:05 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nmmkcert.dll
[2009/09/14 22:33:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2009/09/14 22:33:04 | 00,385,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\callcont.dll
[2009/09/14 22:33:04 | 00,229,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nmas.dll
[2009/09/14 22:33:04 | 00,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nac.dll
[2009/09/14 22:33:04 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rrcm.dll
[2009/09/14 22:33:04 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\h323cc.dll
[2009/09/14 22:33:04 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dcap32.dll
[2009/09/14 22:33:04 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nmasnt.dll
[2009/09/14 22:33:03 | 01,040,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\conf.exe
[2009/09/14 22:33:03 | 00,274,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mst120.dll
[2009/09/14 22:33:03 | 00,192,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nmwb.dll
[2009/09/14 22:33:03 | 00,172,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nmoldwb.dll
[2009/09/14 22:33:03 | 00,155,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nmft.dll
[2009/09/14 22:33:03 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nmchat.dll
[2009/09/14 22:33:03 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nmcom.dll
[2009/09/14 22:33:03 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mst123.dll
[2009/09/14 22:33:03 | 00,045,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\confmrsl.dll
[2009/09/14 22:33:02 | 00,510,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab32.dll
[2009/09/14 22:33:02 | 00,260,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab32res.dll
[2009/09/14 22:33:02 | 00,252,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msoeacct.dll
[2009/09/14 22:33:02 | 00,252,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msoeacct.dll
[2009/09/14 22:33:02 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msoert2.dll
[2009/09/14 22:33:02 | 00,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msoert2.dll
[2009/09/14 22:33:02 | 00,086,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\directdb.dll
[2009/09/14 22:33:02 | 00,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wabimp.dll
[2009/09/14 22:33:02 | 00,049,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetres.dll
[2009/09/14 22:33:02 | 00,049,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetres.dll
[2009/09/14 22:33:02 | 00,046,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wab.exe
[2009/09/14 22:33:02 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wabfind.dll
[2009/09/14 22:33:02 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wabmig.exe
[2009/09/14 22:33:02 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\NetMeeting
[2009/09/14 22:33:01 | 02,512,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msoeres.dll
[2009/09/14 22:33:01 | 01,315,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msoe.dll
[2009/09/14 22:33:01 | 00,691,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcomm.dll
[2009/09/14 22:33:01 | 00,691,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcomm.dll
[2009/09/14 22:33:01 | 00,104,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oeimport.dll
[2009/09/14 22:33:01 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oemig50.exe
[2009/09/14 22:33:01 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msimn.exe
[2009/09/14 22:33:01 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oemiglib.dll
[2009/09/14 22:33:00 | 00,278,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstask.dll
[2009/09/14 22:33:00 | 00,278,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcfg.dll
[2009/09/14 22:33:00 | 00,278,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstask.dll
[2009/09/14 22:33:00 | 00,278,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcfg.dll
[2009/09/14 22:33:00 | 00,193,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\schedsvc.dll
[2009/09/14 22:33:00 | 00,193,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\schedsvc.dll
[2009/09/14 22:33:00 | 00,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\isign32.dll
[2009/09/14 22:33:00 | 00,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\isign32.dll
[2009/09/14 22:33:00 | 00,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icwdial.dll
[2009/09/14 22:33:00 | 00,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\setup50.exe
[2009/09/14 22:33:00 | 00,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwdial.dll
[2009/09/14 22:33:00 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icwphbk.dll
[2009/09/14 22:33:00 | 00,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwphbk.dll
[2009/09/14 22:33:00 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstinit.exe
[2009/09/14 22:33:00 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstinit.exe
[2009/09/14 22:33:00 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Outlook Express
[2009/09/14 22:32:59 | 00,217,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwconn1.exe
[2009/09/14 22:32:59 | 00,176,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwhelp.dll
[2009/09/14 22:32:59 | 00,086,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwconn2.exe
[2009/09/14 22:32:59 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwconn.dll
[2009/09/14 22:32:59 | 00,049,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwutil.dll
[2009/09/14 22:32:59 | 00,032,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwdl.dll
[2009/09/14 22:32:59 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icwrmind.exe
[2009/09/14 22:32:59 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetwiz.exe
[2009/09/14 22:32:58 | 00,554,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dao360.dll
[2009/09/14 22:32:58 | 00,487,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oledb32.dll
[2009/09/14 22:32:58 | 00,217,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sqlxmlx.dll
[2009/09/14 22:32:58 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdaps.dll
[2009/09/14 22:32:58 | 00,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdatl3.dll
[2009/09/14 22:32:58 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdaosp.dll
[2009/09/14 22:32:58 | 00,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oledb32r.dll
[2009/09/14 22:32:57 | 00,315,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdasql.dll
[2009/09/14 22:32:57 | 00,233,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdaora.dll
[2009/09/14 22:32:57 | 00,200,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadox.dll
[2009/09/14 22:32:57 | 00,180,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadomd.dll
[2009/09/14 22:32:57 | 00,102,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msjro.dll
[2009/09/14 22:32:57 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msado27.tlb
[2009/09/14 22:32:57 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadrh15.dll
[2009/09/14 22:32:57 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msador15.dll
[2009/09/14 22:32:57 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msxactps.dll
[2009/09/14 22:32:57 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdatt.dll
[2009/09/14 22:32:57 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdaorar.dll
[2009/09/14 22:32:57 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdasqlr.dll
[2009/09/14 22:32:57 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdaurl.dll
[2009/09/14 22:32:57 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdasc.dll
[2009/09/14 22:32:57 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdaer.dll
[2009/09/14 22:32:57 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdaenum.dll
[2009/09/14 22:32:57 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdadc.dll
[2009/09/14 22:32:56 | 00,536,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msado15.dll
[2009/09/14 22:32:56 | 00,200,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdaprst.dll
[2009/09/14 22:32:56 | 00,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdarem.dll
[2009/09/14 22:32:56 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msado26.tlb
[2009/09/14 22:32:56 | 00,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msado25.tlb
[2009/09/14 22:32:56 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msado21.tlb
[2009/09/14 22:32:56 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msado20.tlb
[2009/09/14 22:32:56 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdfmap.dll
[2009/09/14 22:32:56 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msader15.dll
[2009/09/14 22:32:56 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdaremr.dll
[2009/09/14 22:32:56 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdaprsr.dll
[2009/09/14 22:32:55 | 00,331,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadce.dll
[2009/09/14 22:32:55 | 00,155,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadds.dll
[2009/09/14 22:32:55 | 00,153,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\triedit.dll
[2009/09/14 22:32:55 | 00,143,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadco.dll
[2009/09/14 22:32:55 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadcf.dll
[2009/09/14 22:32:55 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadcs.dll
[2009/09/14 22:32:55 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msaddsr.dll
[2009/09/14 22:32:55 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadcer.dll
[2009/09/14 22:32:55 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadcor.dll
[2009/09/14 22:32:55 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msadcfr.dll
[2009/09/14 22:32:55 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\System
[2009/09/14 22:32:54 | 00,128,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dhtmled.ocx
[2009/09/14 22:32:54 | 00,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hmmapi.dll
[2009/09/14 22:32:54 | 00,018,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedw.exe
[2009/09/14 22:32:53 | 00,093,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/09/14 22:32:51 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Internet Explorer
[2009/09/14 22:32:26 | 00,021,844 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/09/14 22:32:17 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\ComPlus Applications
[2009/09/14 22:32:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2009/09/14 22:32:05 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Windows Media Player
[2009/09/14 22:32:00 | 00,042,577 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bckgzm.exe
[2009/09/14 22:31:59 | 02,178,131 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shvlres.dll
[2009/09/14 22:31:59 | 01,817,687 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bckgres.dll
[2009/09/14 22:31:59 | 00,781,397 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chkrres.dll
[2009/09/14 22:31:59 | 00,753,236 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rvseres.dll
[2009/09/14 22:31:59 | 00,082,501 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bckg.dll
[2009/09/14 22:31:59 | 00,066,113 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shvl.dll
[2009/09/14 22:31:59 | 00,048,706 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rvse.dll
[2009/09/14 22:31:59 | 00,042,575 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chkrzm.exe
[2009/09/14 22:31:59 | 00,042,574 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rvsezm.exe
[2009/09/14 22:31:59 | 00,042,573 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shvlzm.exe
[2009/09/14 22:31:59 | 00,040,515 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\chkr.dll
[2009/09/14 22:31:58 | 01,175,635 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hrtzres.dll
[2009/09/14 22:31:58 | 01,042,003 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cmnresm.dll
[2009/09/14 22:31:58 | 00,113,222 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zoneclim.dll
[2009/09/14 22:31:58 | 00,057,409 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hrtz.dll
[2009/09/14 22:31:58 | 00,042,573 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hrtzzm.exe
[2009/09/14 22:31:58 | 00,041,029 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zcorem.dll
[2009/09/14 22:31:58 | 00,032,339 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uniansi.dll
[2009/09/14 22:31:58 | 00,013,894 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zonelibm.dll
[2009/09/14 22:31:58 | 00,004,677 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zeeverm.dll
[2009/09/14 22:31:57 | 00,217,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cmnclim.dll
[2009/09/14 22:31:57 | 00,036,937 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\zclientm.exe
[2009/09/14 22:31:57 | 00,029,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\znetm.dll
[2009/09/14 22:31:57 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\write.exe
[2009/09/14 22:31:57 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\write.exe
[2009/09/14 22:31:57 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\MSN Gaming Zone
[2009/09/14 22:31:52 | 00,139,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sndvol32.exe
[2009/09/14 22:31:52 | 00,139,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sndvol32.exe
[2009/09/14 22:31:51 | 00,231,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avtapi.dll
[2009/09/14 22:31:51 | 00,231,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avtapi.dll
[2009/09/14 22:31:51 | 00,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avwav.dll
[2009/09/14 22:31:51 | 00,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avwav.dll
[2009/09/14 22:31:51 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winchat.exe
[2009/09/14 22:31:51 | 00,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winchat.exe
[2009/09/14 22:31:51 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\avmeter.dll
[2009/09/14 22:31:51 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avmeter.dll
[2009/09/14 22:31:47 | 00,093,702 | ---- | C] () -- C:\WINDOWS\System32\subrange.uce
[2009/09/14 22:31:47 | 00,016,740 | ---- | C] () -- C:\WINDOWS\System32\shiftjis.uce
[2009/09/14 22:31:46 | 00,640,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\getuname.dll
[2009/09/14 22:31:46 | 00,640,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\getuname.dll
[2009/09/14 22:31:46 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winmine.exe
[2009/09/14 22:31:46 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winmine.exe
[2009/09/14 22:31:46 | 00,115,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\calc.exe
[2009/09/14 22:31:46 | 00,115,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\calc.exe
[2009/09/14 22:31:46 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\charmap.exe
[2009/09/14 22:31:46 | 00,080,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\charmap.exe
[2009/09/14 22:31:46 | 00,060,458 | ---- | C] () -- C:\WINDOWS\System32\ideograf.uce
[2009/09/14 22:31:46 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sol.exe
[2009/09/14 22:31:46 | 00,057,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sol.exe
[2009/09/14 22:31:46 | 00,024,006 | ---- | C] () -- C:\WINDOWS\System32\gb2312.uce
[2009/09/14 22:31:46 | 00,022,984 | ---- | C] () -- C:\WINDOWS\System32\bopomofo.uce
[2009/09/14 22:31:46 | 00,012,876 | ---- | C] () -- C:\WINDOWS\System32\korean.uce
[2009/09/14 22:31:46 | 00,008,484 | ---- | C] () -- C:\WINDOWS\System32\kanji_2.uce
[2009/09/14 22:31:46 | 00,006,948 | ---- | C] () -- C:\WINDOWS\System32\kanji_1.uce
[2009/09/14 22:31:45 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mshearts.exe
[2009/09/14 22:31:45 | 00,128,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshearts.exe
[2009/09/14 22:31:45 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\freecell.exe
[2009/09/14 22:31:45 | 00,055,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\freecell.exe
[2009/09/14 22:31:45 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsshutdn.exe
[2009/09/14 22:31:45 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsshutdn.exe
[2009/09/14 22:31:45 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tskill.exe
[2009/09/14 22:31:45 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwinsta.exe
[2009/09/14 22:31:45 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tskill.exe
[2009/09/14 22:31:45 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rwinsta.exe
[2009/09/14 22:31:45 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsdiscon.exe
[2009/09/14 22:31:45 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscon.exe
[2009/09/14 22:31:45 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shadow.exe
[2009/09/14 22:31:45 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsdiscon.exe
[2009/09/14 22:31:45 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tscon.exe
[2009/09/14 22:31:45 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\shadow.exe
[2009/09/14 22:31:45 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\reset.exe
[2009/09/14 22:31:45 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\reset.exe
[2009/09/14 22:31:45 | 00,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2009/09/14 22:31:45 | 00,001,221 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2009/09/14 22:31:44 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\regini.exe
[2009/09/14 22:31:44 | 00,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\regini.exe
[2009/09/14 22:31:44 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qwinsta.exe
[2009/09/14 22:31:44 | 00,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qwinsta.exe
[2009/09/14 22:31:44 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msg.exe
[2009/09/14 22:31:44 | 00,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msg.exe
[2009/09/14 22:31:44 | 00,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtsadmin.tlb
[2009/09/14 22:31:44 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qappsrv.exe
[2009/09/14 22:31:44 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qappsrv.exe
[2009/09/14 22:31:44 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\logoff.exe
[2009/09/14 22:31:44 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\logoff.exe
[2009/09/14 22:31:44 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cdmodem.dll
[2009/09/14 22:31:44 | 00,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cdmodem.dll
[2009/09/14 22:31:44 | 00,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpcfgex.dll
[2009/09/14 22:31:44 | 00,004,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdpcfgex.dll
[2009/09/14 22:31:44 | 00,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2009/09/14 22:31:43 | 00,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmi2xml.dll
[2009/09/14 22:31:40 | 00,116,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\updprov.dll
[2009/09/14 22:31:40 | 00,076,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmipicmp.dll
[2009/09/14 22:31:40 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmimsg.dll
[2009/09/14 22:31:40 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemdisp.tlb
[2009/09/14 22:31:40 | 00,052,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmitimep.dll
[2009/09/14 22:31:40 | 00,031,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemads.tlb
[2009/09/14 22:31:40 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winmgmtr.dll
[2009/09/14 22:31:40 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\winmgmt.exe
[2009/09/14 22:31:40 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemads.dll
[2009/09/14 22:31:39 | 00,273,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msiprov.dll
[2009/09/14 22:31:39 | 00,120,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dsprov.dll
[2009/09/14 22:31:39 | 00,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2009/09/14 22:31:39 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tmplprov.dll
[2009/09/14 22:31:39 | 00,059,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\trnsprov.dll
[2009/09/14 22:31:39 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fwdprov.dll
[2009/09/14 22:31:39 | 00,040,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\smtpcons.dll
[2009/09/14 22:31:39 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\unsecapp.exe
[2009/09/14 22:31:38 | 00,216,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/09/14 22:31:38 | 00,188,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\accwiz.exe
[2009/09/14 22:31:38 | 00,188,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\accwiz.exe
[2009/09/14 22:31:38 | 00,132,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sndrec32.exe
[2009/09/14 22:31:38 | 00,132,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sndrec32.exe
[2009/09/14 22:31:38 | 00,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mplay32.exe
[2009/09/14 22:31:38 | 00,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mplay32.exe
[2009/09/14 22:31:38 | 00,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\access.cpl
[2009/09/14 22:31:38 | 00,070,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\access.cpl
[2009/09/14 22:31:37 | 00,545,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dialer.exe
[2009/09/14 22:31:37 | 00,539,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spider.exe
[2009/09/14 22:31:37 | 00,539,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spider.exe
[2009/09/14 22:31:37 | 00,345,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mspaint.exe
[2009/09/14 22:31:37 | 00,345,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspaint.exe
[2009/09/14 22:31:37 | 00,104,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\clipbrd.exe
[2009/09/14 22:31:37 | 00,104,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clipbrd.exe
[2009/09/14 22:31:37 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Windows NT
[2009/09/14 22:31:36 | 00,290,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rhttpaa.dll
[2009/09/14 22:31:36 | 00,290,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rhttpaa.dll
[2009/09/14 22:31:36 | 00,139,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rdpwd.sys
[2009/09/14 22:31:36 | 00,139,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdpwd.sys
[2009/09/14 22:31:36 | 00,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscfgwmi.dll
[2009/09/14 22:31:36 | 00,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tscfgwmi.dll
[2009/09/14 22:31:36 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsgqec.dll
[2009/09/14 22:31:36 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tsgqec.dll
[2009/09/14 22:31:36 | 00,021,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tdtcp.sys
[2009/09/14 22:31:36 | 00,021,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdtcp.sys
[2009/09/14 22:31:36 | 00,012,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tdpipe.sys
[2009/09/14 22:31:36 | 00,012,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\tdpipe.sys
[2009/09/14 22:31:35 | 02,066,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstscax.dll
[2009/09/14 22:31:35 | 02,061,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lhmstscx.dll
[2009/09/14 22:31:35 | 00,677,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstsc.exe
[2009/09/14 22:31:35 | 00,677,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lhmstsc.exe
[2009/09/14 22:31:35 | 00,142,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sessmgr.exe
[2009/09/14 22:31:35 | 00,142,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sessmgr.exe
[2009/09/14 22:31:35 | 00,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aaclient.dll
[2009/09/14 22:31:35 | 00,136,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aaclient.dll
[2009/09/14 22:31:35 | 00,067,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdshost.exe
[2009/09/14 22:31:35 | 00,067,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdshost.exe
[2009/09/14 22:31:35 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\remotepg.dll
[2009/09/14 22:31:35 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\remotepg.dll
[2009/09/14 22:31:35 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdsaddin.exe
[2009/09/14 22:31:35 | 00,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdsaddin.exe
[2009/09/14 22:31:34 | 00,296,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\termsrv.dll
[2009/09/14 22:31:34 | 00,296,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\termsrv.dll
[2009/09/14 22:31:34 | 00,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdchost.dll
[2009/09/14 22:31:34 | 00,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdchost.dll
[2009/09/14 22:31:34 | 00,087,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpwsx.dll
[2009/09/14 22:31:34 | 00,087,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdpwsx.dll
[2009/09/14 22:31:34 | 00,062,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpclip.exe
[2009/09/14 22:31:34 | 00,062,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdpclip.exe
[2009/09/14 22:31:34 | 00,039,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cfgbkend.dll
[2009/09/14 22:31:34 | 00,039,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cfgbkend.dll
[2009/09/14 22:31:34 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qprocess.exe
[2009/09/14 22:31:34 | 00,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\qprocess.exe
[2009/09/14 22:31:34 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpsnd.dll
[2009/09/14 22:31:34 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rdpsnd.dll
[2009/09/14 22:31:34 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icaapi.dll
[2009/09/14 22:31:34 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\icaapi.dll
[2009/09/14 22:31:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2009/09/14 22:31:33 | 00,956,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtctm.dll
[2009/09/14 22:31:33 | 00,956,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtctm.dll
[2009/09/14 22:31:33 | 00,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcprx.dll
[2009/09/14 22:31:33 | 00,428,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtcprx.dll
[2009/09/14 22:31:33 | 00,161,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcuiu.dll
[2009/09/14 22:31:33 | 00,161,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtcuiu.dll
[2009/09/14 22:31:33 | 00,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxoci.dll
[2009/09/14 22:31:33 | 00,091,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtxoci.dll
[2009/09/14 22:31:33 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtclog.dll
[2009/09/14 22:31:33 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtclog.dll
[2009/09/14 22:31:33 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xolehlp.dll
[2009/09/14 22:31:33 | 00,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xolehlp.dll
[2009/09/14 22:31:33 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtc.exe
[2009/09/14 22:31:33 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdtc.exe
[2009/09/14 22:31:32 | 00,195,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comadmin.dll
[2009/09/14 22:31:32 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comrepl.dll
[2009/09/14 22:31:32 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comrepl.dll
[2009/09/14 22:31:32 | 00,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\catsrvps.dll
[2009/09/14 22:31:32 | 00,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrvps.dll
[2009/09/14 22:31:32 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\colbact.dll
[2009/09/14 22:31:32 | 00,060,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\colbact.dll
[2009/09/14 22:31:32 | 00,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\stclient.dll
[2009/09/14 22:31:32 | 00,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\stclient.dll
[2009/09/14 22:31:32 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxlegih.dll
[2009/09/14 22:31:32 | 00,034,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtxlegih.dll
[2009/09/14 22:31:32 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxdm.dll
[2009/09/14 22:31:32 | 00,030,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtxdm.dll
[2009/09/14 22:31:32 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comaddin.dll
[2009/09/14 22:31:32 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comaddin.dll
[2009/09/14 22:31:32 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comrepl.exe
[2009/09/14 22:31:32 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dcomcnfg.exe
[2009/09/14 22:31:32 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comrereg.exe
[2009/09/14 22:31:32 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dcomcnfg.exe
[2009/09/14 22:31:32 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxex.dll
[2009/09/14 22:31:32 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mtxex.dll
[2009/09/14 22:31:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2009/09/14 22:31:31 | 01,267,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comsvcs.dll
[2009/09/14 22:31:31 | 01,267,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsvcs.dll
[2009/09/14 22:31:31 | 00,625,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\catsrvut.dll
[2009/09/14 22:31:31 | 00,625,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrvut.dll
[2009/09/14 22:31:31 | 00,539,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comuid.dll
[2009/09/14 22:31:31 | 00,539,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comuid.dll
[2009/09/14 22:31:31 | 00,498,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\clbcatq.dll
[2009/09/14 22:31:31 | 00,498,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clbcatq.dll
[2009/09/14 22:31:31 | 00,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\catsrv.dll
[2009/09/14 22:31:31 | 00,226,304 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrv.dll
[2009/09/14 22:31:31 | 00,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comsnap.dll
[2009/09/14 22:31:31 | 00,167,424 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsnap.dll
[2009/09/14 22:31:31 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\clbcatex.dll
[2009/09/14 22:31:31 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clbcatex.dll
[2009/09/14 22:31:29 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/09/14 22:31:29 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/09/14 22:31:29 | 00,156,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmipcima.dll
[2009/09/14 22:31:29 | 00,145,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmisvc.dll
[2009/09/14 22:31:29 | 00,144,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprov.dll
[2009/09/14 22:31:29 | 00,132,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmipdskq.dll
[2009/09/14 22:31:29 | 00,097,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiutils.dll
[2009/09/14 22:31:29 | 00,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmipjobj.dll
[2009/09/14 22:31:29 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmipiprt.dll
[2009/09/14 22:31:29 | 00,041,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmipsess.dll
[2009/09/14 22:31:28 | 00,531,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemcore.dll
[2009/09/14 22:31:28 | 00,365,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmic.exe
[2009/09/14 22:31:28 | 00,273,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemess.dll
[2009/09/14 22:31:28 | 00,197,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemupgd.dll
[2009/09/14 22:31:28 | 00,196,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiadap.exe
[2009/09/14 22:31:28 | 00,178,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemdisp.dll
[2009/09/14 22:31:28 | 00,140,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmidcprv.dll
[2009/09/14 22:31:28 | 00,126,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiapsrv.exe
[2009/09/14 22:31:28 | 00,118,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemtest.exe
[2009/09/14 22:31:28 | 00,088,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiaprpl.dll
[2009/09/14 22:31:28 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmicookr.dll
[2009/09/14 22:31:28 | 00,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemsvc.dll
[2009/09/14 22:31:28 | 00,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemprox.dll
[2009/09/14 22:31:28 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiapres.dll
[2009/09/14 22:31:27 | 00,237,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\provthrd.dll
[2009/09/14 22:31:27 | 00,214,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemcomn.dll
[2009/09/14 22:31:27 | 00,199,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemcntl.dll
[2009/09/14 22:31:27 | 00,178,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\repdrvfs.dll
[2009/09/14 22:31:27 | 00,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\viewprov.dll
[2009/09/14 22:31:27 | 00,092,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\policman.dll
[2009/09/14 22:31:27 | 00,086,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\stdprov.dll
[2009/09/14 22:31:27 | 00,071,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wbemcons.dll
[2009/09/14 22:31:27 | 00,036,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\scrcons.exe
[2009/09/14 22:31:26 | 00,473,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/09/14 22:31:26 | 00,247,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\esscli.dll
[2009/09/14 22:31:26 | 00,212,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntevt.dll
[2009/09/14 22:31:26 | 00,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\framedyn.dll
[2009/09/14 22:31:26 | 00,124,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mofd.dll
[2009/09/14 22:31:26 | 00,047,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ncprov.dll
[2009/09/14 22:31:26 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\krnlprov.dll
[2009/09/14 22:31:26 | 00,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mofcomp.exe
[2009/09/14 22:31:25 | 01,359,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cimwin32.dll
[2009/09/14 22:31:25 | 00,188,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\cmprops.dll
[2009/09/14 22:31:25 | 00,188,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmprops.dll
[2009/09/14 22:31:25 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\licwmi.dll
[2009/09/14 22:31:25 | 00,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\licwmi.dll
[2009/09/14 22:31:25 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\servdeps.dll
[2009/09/14 22:31:25 | 00,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\servdeps.dll
[2009/09/14 22:31:25 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmfutil.dll
[2009/09/14 22:31:25 | 00,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mmfutil.dll
[2009/09/14 22:31:20 | 00,040,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\termdd.sys
[2009/09/14 22:31:19 | 00,196,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rdpdr.sys
[2009/09/14 22:31:19 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documentos\Meus vídeos
[2009/09/14 19:29:44 | 00,006,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\splitter.sys
[2009/09/14 19:29:43 | 00,142,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aec.sys
[2009/09/14 19:29:43 | 00,056,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\swmidi.sys
[2009/09/14 19:29:41 | 00,052,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\DMusic.sys
[2009/09/14 19:29:41 | 00,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MSKSSRV.sys
[2009/09/14 19:29:40 | 00,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MSPCLOCK.sys
[2009/09/14 19:29:39 | 00,060,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sysaudio.sys
[2009/09/14 19:29:38 | 00,172,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\kmixer.sys
[2009/09/14 19:29:37 | 00,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmkaud.sys
[2009/09/14 19:29:36 | 00,083,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wdmaud.sys
[2009/09/14 19:29:35 | 00,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MSPQM.sys
[2009/09/14 19:29:32 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\audstub.sys
[2009/09/14 19:28:57 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hidserv.dll
[2009/09/14 19:28:54 | 00,146,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\portcls.sys
[2009/09/14 19:28:54 | 00,146,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\portcls.sys
[2009/09/14 19:28:54 | 00,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax
[2009/09/14 19:28:54 | 00,129,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksproxy.ax
[2009/09/14 19:28:54 | 00,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys
[2009/09/14 19:28:54 | 00,060,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drmk.sys
[2009/09/14 19:28:54 | 00,060,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2009/09/14 19:28:54 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksuser.dll
[2009/09/14 19:28:54 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksuser.dll
[2009/09/14 19:28:40 | 00,058,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\redbook.sys
[2009/09/14 19:28:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2009/09/14 19:27:49 | 00,076,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\usbui.dll
[2009/09/14 19:27:41 | 00,044,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\UAGP35.SYS
[2009/09/14 19:27:37 | 00,152,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irftp.exe
[2009/09/14 19:27:37 | 00,088,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irda.sys
[2009/09/14 19:27:37 | 00,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irmon.dll
[2009/09/14 19:27:37 | 00,019,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rasirda.sys
[2009/09/14 19:27:37 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wshirda.dll
[2009/09/14 19:27:36 | 00,018,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irsir.sys
[2009/09/14 19:26:32 | 00,004,444 | ---- | C] () -- C:\WINDOWS\System32\pid.PNF
[2009/09/14 19:26:31 | 00,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2009/09/14 19:26:28 | 00,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2009/09/14 19:26:28 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\ODBC
[2009/09/14 19:26:26 | 01,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2009/09/14 19:26:26 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spcommon.dll
[2009/09/14 19:26:26 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spcplui.dll
[2009/09/14 19:26:26 | 00,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2009/09/14 19:26:25 | 00,774,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spttseng.dll
[2009/09/14 19:26:25 | 00,741,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sapi.dll
[2009/09/14 19:26:25 | 00,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2009/09/14 19:26:25 | 00,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2009/09/14 19:26:25 | 00,159,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sapi.cpl
[2009/09/14 19:26:25 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sapisvr.exe
[2009/09/14 19:26:25 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\SpeechEngines
[2009/09/14 19:26:24 | 00,000,000 | R--D | C] -- C:\Arquivos de programas
[2009/09/14 19:26:24 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared
[2009/09/14 19:26:24 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns
[2009/09/14 19:26:23 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28603.nls
[2009/09/14 19:26:23 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_869.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_866.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_857.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_855.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_852.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_737.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_869.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_866.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_857.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_855.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_852.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_737.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_875.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10082.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10081.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10029.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10017.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10010.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10007.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10006.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_875.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10082.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10081.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10029.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10017.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10010.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10007.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10006.nls
[2009/09/14 19:26:17 | 00,013,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WFWNET.DRV
[2009/09/14 19:26:17 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irclass.dll
[2009/09/14 19:26:17 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irclass.dll
[2009/09/14 19:26:16 | 00,127,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MSVIDEO.DLL
[2009/09/14 19:26:16 | 00,083,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLECLI.DLL
[2009/09/14 19:26:16 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLESVR.DLL
[2009/09/14 19:26:16 | 00,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TAPI.DLL
[2009/09/14 19:26:16 | 00,009,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VER.DLL
[2009/09/14 19:26:16 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SHELL.DLL
[2009/09/14 19:26:16 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TIMER.DRV
[2009/09/14 19:26:16 | 00,003,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SYSTEM.DRV
[2009/09/14 19:26:16 | 00,002,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VGA.DRV
[2009/09/14 19:26:16 | 00,002,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MOUSE.DRV
[2009/09/14 19:26:16 | 00,001,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SOUND.DRV
[2009/09/14 19:26:16 | 00,001,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMTASK.TSK
[2009/09/14 19:26:15 | 00,109,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVIFILE.DLL
[2009/09/14 19:26:15 | 00,073,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIAVI.DRV
[2009/09/14 19:26:15 | 00,070,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVICAP.DLL
[2009/09/14 19:26:15 | 00,033,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\COMMDLG.DLL
[2009/09/14 19:26:15 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIWAVE.DRV
[2009/09/14 19:26:15 | 00,025,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCISEQ.DRV
[2009/09/14 19:26:15 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE
[2009/09/14 19:26:15 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\taskman.exe
[2009/09/14 19:26:15 | 00,009,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\LZEXPAND.DLL
[2009/09/14 19:26:15 | 00,002,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\KEYBOARD.DRV
[2009/09/14 19:26:14 | 00,146,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WINSPOOL.DRV
[2009/09/14 19:26:14 | 00,075,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\storprop.dll
[2009/09/14 19:26:14 | 00,070,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\NOTEPAD.EXE
[2009/09/14 19:26:14 | 00,070,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMSYSTEM.DLL
[2009/09/14 19:26:14 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irenum.sys
[2009/09/14 19:26:14 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irenum.sys
[2009/09/14 19:26:14 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\batt.dll
[2009/09/14 19:26:14 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\batt.dll
[2009/09/14 19:26:14 | 00,000,515 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2009/09/14 19:26:04 | 00,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2009/09/14 19:26:03 | 01,088,840 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NTPRINT.CAT
[2009/09/14 19:26:03 | 00,809,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2009/09/14 19:26:03 | 00,399,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2009/09/14 19:26:03 | 00,105,628 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2009/09/14 19:26:03 | 00,037,509 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2009/09/14 19:26:03 | 00,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2009/09/14 19:26:03 | 00,033,765 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2009/09/14 19:26:03 | 00,016,825 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2009/09/14 19:26:03 | 00,013,497 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2009/09/14 19:26:03 | 00,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2009/09/14 19:26:03 | 00,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2009/09/14 19:26:03 | 00,008,599 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2009/09/14 19:26:03 | 00,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2009/09/14 19:26:03 | 00,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2009/09/14 19:26:02 | 02,038,809 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2009/09/14 19:26:02 | 01,233,746 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT
[2009/09/14 19:26:02 | 00,634,592 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2009/09/14 19:25:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2009/09/14 19:25:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2009/09/14 19:25:46 | 00,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft
[2009/09/14 19:25:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings
[2009/09/14 19:25:28 | 00,097,456 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/14 19:25:28 | 00,000,000 | -HSD | C] -- C:\System Volume Information
[2009/09/14 19:24:28 | 00,000,211 | -HS- | C] () -- C:\boot.ini
[2009/09/14 19:24:25 | 00,000,974 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2009/09/14 19:20:42 | 00,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2009/09/14 19:20:42 | 00,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2009/09/14 19:20:42 | 00,000,000 | R--D | C] -- C:\WINDOWS\Web
[2009/09/14 19:20:42 | 00,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\pt-BR
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1046
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\system32
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\system
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\security
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\repair
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\PCHealth
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\NLDRV
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Network Diagnostic
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\mui
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Media
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\L2Schemas
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\java
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\ime
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Help
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\ehome
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Config
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\addins
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS
[2009/09/14 16:03:55 | 00,012,800 | ---- | C] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/14 16:01:42 | 00,000,776 | ---- | C] () -- C:\WINDOWS\System32\drivers\etc\hosts.msn
[2009/07/14 15:10:15 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/07/14 15:10:15 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/07/14 15:10:14 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009/07/14 15:10:14 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2009/07/14 15:10:13 | 01,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/07/14 15:10:13 | 00,573,440 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2009/07/14 15:10:12 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2009/04/17 18:21:12 | 00,000,165 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2008/04/14 04:00:00 | 00,000,507 | ---- | C] () -- C:\WINDOWS\win.ini
[2008/04/14 04:00:00 | 00,000,267 | ---- | C] () -- C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/09/17 17:37:32 | 00,514,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\and\Desktop\OTL.exe
[2009/09/17 17:36:39 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/09/17 17:36:30 | 00,043,209 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/09/17 17:36:28 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/09/17 17:36:27 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/09/17 17:16:57 | 00,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/09/17 17:16:25 | 04,045,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\and\Desktop\mbam-setup.exe
[2009/09/17 15:35:09 | 00,013,496 | ---- | M] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT
[2009/09/17 15:35:04 | 00,097,456 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/17 09:20:26 | 00,074,240 | ---- | M] () -- C:\Documents and Settings\and\Meus documentos\fatura mama.doc
[2009/09/17 05:08:17 | 05,889,036 | -H-- | M] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\IconCache.db
[2009/09/17 04:37:19 | 04,842,409 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Regis Danese - Faz Um Milagre Em Mim .mp3
[2009/09/16 21:16:09 | 00,002,241 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2009/09/16 20:00:32 | 00,475,448 | ---- | M] (Trend Micro Inc.) -- C:\HiJackThis.exe
[2009/09/16 02:56:45 | 04,319,360 | ---- | M] () -- C:\Documents and Settings\and\Desktop\William Nascimento - Deus vai na frente.mp3
[2009/09/16 01:51:25 | 00,012,800 | ---- | M] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/15 22:58:59 | 00,752,010 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/09/15 22:58:59 | 00,344,380 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat
[2009/09/15 22:58:59 | 00,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/09/15 22:58:59 | 00,048,628 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat
[2009/09/15 22:58:59 | 00,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/09/15 22:51:36 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/09/15 16:15:15 | 00,000,786 | ---- | M] () -- C:\Documents and Settings\and\Desktop\sXe Injected.lnk
[2009/09/15 03:47:42 | 00,000,217 | ---- | M] () -- C:\Documents and Settings\and\Desktop\TUDO GRATIS.url
[2009/09/15 01:53:54 | 00,001,227 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Atalho para minhas musics.lnk
[2009/09/15 01:50:31 | 00,001,650 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Counter-Strike Source.lnk
[2009/09/15 00:42:09 | 00,001,800 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Counter-Strike.lnk
[2009/09/15 00:12:43 | 00,001,793 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Counter Strike 1.6 Non Steam.lnk
[2009/09/14 22:53:08 | 00,000,267 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/09/14 22:49:04 | 00,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2009/09/14 22:47:44 | 00,000,974 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2009/09/14 22:45:23 | 00,000,704 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Total Video Player.lnk
[2009/09/14 22:45:23 | 00,000,704 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Total Video Converter.lnk
[2009/09/14 22:43:08 | 00,000,421 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2009/09/14 22:41:51 | 00,000,874 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Foxit Reader.lnk
[2009/09/14 22:39:38 | 00,002,161 | ---- | M] () -- C:\WINDOWS\System32\unins000.dat
[2009/09/14 22:39:37 | 00,728,858 | ---- | M] () -- C:\WINDOWS\System32\unins000.exe
[2009/09/14 22:35:27 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2009/09/14 22:35:05 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/09/14 22:35:05 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/09/14 22:34:44 | 00,002,969 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/09/14 22:34:44 | 00,000,507 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/09/14 22:34:44 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009/09/14 22:34:44 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/09/14 22:34:44 | 00,000,000 | ---- | M] () -- C:\WINDOWS\control.ini
[2009/09/14 22:34:44 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/09/14 22:34:44 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/09/14 22:34:40 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2009/09/14 22:34:32 | 00,004,205 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2009/09/14 22:34:01 | 00,000,488 | RH-- | M] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2009/09/14 22:34:01 | 00,000,488 | RH-- | M] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\WindowsShell.Manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2009/09/14 22:32:26 | 00,021,844 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/09/14 22:32:16 | 00,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini
[2009/09/14 22:32:16 | 00,000,036 | ---- | M] () -- C:\WINDOWS\vb.ini
[2009/09/14 22:30:24 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/09/14 19:26:32 | 00,004,444 | ---- | M] () -- C:\WINDOWS\System32\pid.PNF
[2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/28 14:38:22 | 24,689,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
< End of report >
OTL Extras logfile created on: 17/9/2009 17:38:34 - Run 1
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\and\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy
1022,48 Mb Total Physical Memory | 694,55 Mb Available Physical Memory | 67,93% Memory free
2,40 Gb Paging File | 2,16 Gb Available in Paging File | 89,84% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas
Drive C: | 14,65 Gb Total Space | 4,22 Gb Free Space | 28,83% Space Free | Partition Type: NTFS
Drive D: | 134,39 Gb Total Space | 70,73 Gb Free Space | 52,63% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CASA
Current User Name: and
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "C:\Arquivos de programas\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Arquivos de programas\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Arquivos de programas\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" = C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" = C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" = C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:ipsec -- (Microsoft Corporation)
"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" = C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"D:\explorer.exe" = D:\explorer.exe:*:Enabled:ipsec -- (Microsoft Corporation)
"C:\WINDOWS\Explorer.EXE" = C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec -- (Microsoft Corporation)
"C:\WINDOWS\yoos.b" = C:\WINDOWS\yoos.b:*:Enabled:ipsec
"C:\WINDOWS\system32\init.exe" = C:\WINDOWS\system32\init.exe:*:Enabled:ipsec -- (Microsoft Corporation)
"C:\WINDOWS\windowsmp.exe" = C:\WINDOWS\windowsmp.exe:*:Enabled:ipsec -- File not found
"C:\Arquivos de programas\Valve\hl.exe" = C:\Arquivos de programas\Valve\hl.exe:*:Enabled:Half-Life Launcher -- (Valve)
"C:\Arquivos de programas\Steam\steamapps\hishi601\counter-strike\hl.exe" = C:\Arquivos de programas\Steam\steamapps\hishi601\counter-strike\hl.exe:*:Enabled:Half-Life Launcher -- (Valve)
"C:\Arquivos de programas\Steam\Steam.exe" = C:\Arquivos de programas\Steam\Steam.exe:*:Enabled:ipsec -- (Valve Corporation)
"C:\Arquivos de programas\Steam\steamapps\hishi601\counter-strike source\hl2.exe" = C:\Arquivos de programas\Steam\steamapps\hishi601\counter-strike source\hl2.exe:*:Enabled:hl2 -- ()
"C:\Arquivos de programas\Java\jre6\bin\jusched.exe" = C:\Arquivos de programas\Java\jre6\bin\jusched.exe:*:Enabled:ipsec -- (Sun Microsystems, Inc.)
"C:\Arquivos de programas\ESET\nod32.exe" = C:\Arquivos de programas\ESET\nod32.exe:*:Disabled:NOD32 -- File not found
"C:\Arquivos de programas\ESET\nod32kui.exe" = C:\Arquivos de programas\ESET\nod32kui.exe:*:Disabled:NOD32 Control Center -- File not found
"C:\Arquivos de programas\Internet Explorer\iexplore.exe" = C:\Arquivos de programas\Internet Explorer\iexplore.exe:*:Enabled:ipsec -- (Microsoft Corporation)
"C:\WINDOWS\system32\nwiz.exe" = C:\WINDOWS\system32\nwiz.exe:*:Enabled:ipsec -- ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{13B792AA-C078-43A4-8A3A-8B12D629940D}" = Counter-Strike 1.6
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 15
"{32BC546A-8AA3-4239-AE92-9CF3291C35A6}" = Windows Live Call
"{350C9416-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3B96F4EA-CD82-4C57-B86A-646A017CAF18}" = Windows Live Essentials
"{51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}" = Assistente de Conexão do Windows Live
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90110416-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edição 2003
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{AF52AC44-8AE8-44C4-83A4-F9921AB72B83}_is1" = Dirrect X11Beta
"{B8410225-2F65-4BD6-A771-416CC1EAD58D}" = USB PC Camera Driver
"{C8DD4EAD-674B-461B-94D5-4C80CCFB8401}" = Windows Live Messenger
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.1.7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"Steam App 10" = Counter-Strike
"Steam App 240" = Counter-Strike: Source
"sXe Injected" = sXe Injected
"Total Video Converter 3.11_is1" = Total Video Converter 3.11 070908
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 14/9/2009 21:38:04 | Computer Name = CASA | Source = MsiInstaller | ID = 10005
Description = Produto: Microsoft .NET Framework 2.0 -- Error 25007.Erro durante
inicialização de fusão. A instalação não carregou a fusão com LoadLibraryShim().
Erro: Identificador inválido.
Error - 14/9/2009 21:41:15 | Computer Name = CASA | Source = PerfNet | ID = 2004
Description = Não foi possível abrir o serviço do servidor. Os dados do desempenho
do servidor não serão retornados. O código de erro retornado está no dado DWORD
0.
[ System Events ]
Error - 16/9/2009 18:32:02 | Computer Name = CASA | Source = Service Control Manager | ID = 7009
Description = Tempo limite (30000 milissegundos) de espera para que o serviço Microsoft
Services se conecte.
Error - 16/9/2009 18:32:02 | Computer Name = CASA | Source = Service Control Manager | ID = 7000
Description = Não foi possível iniciar o serviço Microsoft Services devido ao seguinte
erro: %%1053
Error - 16/9/2009 19:29:17 | Computer Name = CASA | Source = Service Control Manager | ID = 7009
Description = Tempo limite (30000 milissegundos) de espera para que o serviço Microsoft
Services se conecte.
Error - 16/9/2009 19:29:17 | Computer Name = CASA | Source = Service Control Manager | ID = 7000
Description = Não foi possível iniciar o serviço Microsoft Services devido ao seguinte
erro: %%1053
Error - 16/9/2009 20:05:39 | Computer Name = CASA | Source = Service Control Manager | ID = 7009
Description = Tempo limite (30000 milissegundos) de espera para que o serviço Microsoft
Services se conecte.
Error - 16/9/2009 20:05:39 | Computer Name = CASA | Source = Service Control Manager | ID = 7000
Description = Não foi possível iniciar o serviço Microsoft Services devido ao seguinte
erro: %%1053
Error - 17/9/2009 07:49:15 | Computer Name = CASA | Source = Service Control Manager | ID = 7009
Description = Tempo limite (30000 milissegundos) de espera para que o serviço Microsoft
Services se conecte.
Error - 17/9/2009 07:49:15 | Computer Name = CASA | Source = Service Control Manager | ID = 7000
Description = Não foi possível iniciar o serviço Microsoft Services devido ao seguinte
erro: %%1053
Error - 17/9/2009 14:36:31 | Computer Name = CASA | Source = Service Control Manager | ID = 7009
Description = Tempo limite (30000 milissegundos) de espera para que o serviço Microsoft
Services se conecte.
Error - 17/9/2009 14:36:31 | Computer Name = CASA | Source = Service Control Manager | ID = 7000
Description = Não foi possível iniciar o serviço Microsoft Services devido ao seguinte
erro: %%1053
< End of report >
Boa Noite! danmex
<@> Execute o OTL.exe.
<@> Copie estas informações que estão no Quote,para o campo clipboard da ferramenta. ( Custom Scans/Fixes )
>
:Reg[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000\Control]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASC3360PR]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASC3360PR\0000]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASC3360PR\0000\Control]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000\Control]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asc3360pr]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asc3360pr\Security]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asc3360pr\Enum]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASC3360PR]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASC3360PR\0000]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASC3360PR\0000\Control]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3360pr]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3360pr\Security]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3360pr\Enum]
[-HKEY_CURRENT_USER\Software\%UserName%\914]
[-HKEY_CURRENT_USER\Software\%UserName%\914\-72398023]
:OTL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [TPPOLL] C:\Program Files\Topro\tppoll.exe File not found
DRV - (asc3360pr [On_Demand | Running]) -- File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
:Services
asc3360pr
:Commands
[resethosts]
[Reboot]
<@> Clique no botão Run Fix --> Aguarde a conclusão!
<@> Terminando,vá até a pasta: C:\_OTL\MovedFiles\.log <-- Poste!*
<><><><><><><><><><>
<@> Execute o OTL Quick Scan,aonde teremos um rápido escaneamento pela ferramenta.
<@> Duplo-clique em: < /applications/core/interface/imageproxy/imageproxy.php?img=http://billy-oneal.com/Canned%2520Speeches/speechimages/OTL/otlDesktopIcon.png&key=1894e5d356219721410c3360cbf9af74877ae24ccc81ed88026fc2d95dd96a07" alt="otlDesktopIcon.png" /> >
<@> Clique em "Scan All Users" --> /applications/core/interface/imageproxy/imageproxy.php?img=http://i27.tinypic.com/2j287qe.png&key=ed81a672e2ffbf39739363233aa436c32b4bb92bded0c687a6bac5431ff58e96" alt="2j287qe.png" /> --> Aguarde!
<@> Copie e poste o relatório. ( OTL log )
Abraços!
Boa noite DigRam..
aqui vai os logs que você pediu..
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000\Control\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASC3360PR\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASC3360PR\0000\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASC3360PR\0000\Control\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER\0000\Control\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asc3360pr\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asc3360pr\Security\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\asc3360pr\Enum\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASC3360PR\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASC3360PR\0000\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASC3360PR\0000\Control\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPFILTERDRIVER\0000\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3360pr\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3360pr\Security\ not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\asc3360pr\Enum\ not found.
Registry key HKEY_CURRENT_USER\Software\%UserName%\914\ not found.
Registry key HKEY_CURRENT_USER\Software\%UserName%\914\-72398023\ not found.
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\TPPOLL deleted successfully.
Service\Driver asc3360pr deleted successfully.
File File not found not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
========== SERVICES/DRIVERS ==========
Service\Driver asc3360pr not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.0.14.0 log created on 09172009_204358
OTL logfile created on: 17/9/2009 20:48:58 - Run 2
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Documents and Settings\and\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy
1022,48 Mb Total Physical Memory | 688,95 Mb Available Physical Memory | 67,38% Memory free
2,40 Gb Paging File | 2,16 Gb Available in Paging File | 89,74% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas
Drive C: | 14,65 Gb Total Space | 3,91 Gb Free Space | 26,71% Space Free | Partition Type: NTFS
Drive D: | 134,39 Gb Total Space | 70,70 Gb Free Space | 52,61% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CASA
Current User Name: and
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Arquivos de programas\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\windowsmp.exe (Microsoft Corporation)
PRC - C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Arquivos de programas\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Arquivos de programas\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Arquivos de programas\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\WINMINE.EXE (Microsoft Corporation)
PRC - C:\Documents and Settings\and\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (4LLI [Auto | Stopped]) -- C:\WINDOWS\yoos.b (Microsoft Corporation)
SRV - (Irmon [Auto | Running]) -- C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Arquivos de programas\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Arquivos de programas\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s
IE - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\S-1-5-21-1409082233-1637723038-1177238915-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ff [2009/09/14 22:41:07 | 00,000,000 | ---D | M]
O1 HOSTS File: (56 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [soundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Arquivos de programas\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [windowsmp] C:\WINDOWS\windowsmp.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001..\Run: [msnmsgr] C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [nltide_3] C:\WINDOWS\System32\advpack.DLL (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 1
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1409082233-1637723038-1177238915-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de programas\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\init.exe) - C:\WINDOWS\System32\init.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Minha página inicial atual) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/14 22:34:44 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/09/17 20:49:00 | 00,000,102 | -HS- | M] () - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009/09/17 20:49:00 | 00,000,102 | -HS- | M] () - D:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{24477cda-a17c-11de-b892-806d6172696f}\Shell\auto\command - "" = D:\explorer.exe -- [2008/09/20 00:22:58 | 00,139,264 | -HS- | M] (Microsoft Corporation)
O33 - MountPoints2\{24477cdc-a17c-11de-b892-806d6172696f}\Shell\auto\command - "" = C:\explorer.exe -- [2008/09/20 00:22:58 | 00,139,264 | -HS- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 14 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/09/17 20:43:58 | 00,000,000 | ---D | C] -- C:\_OTL
[2009/09/17 19:52:08 | 06,971,836 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Epica - Triumph Of Defeat.mp3
[2009/09/17 18:03:36 | 00,000,102 | -HS- | C] () -- C:\autorun.inf
[2009/09/17 17:37:15 | 00,514,560 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\and\Desktop\OTL.exe
[2009/09/17 17:16:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Malwarebytes
[2009/09/17 17:16:57 | 00,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/09/17 17:16:55 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/17 17:16:54 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/09/17 17:16:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Malwarebytes
[2009/09/17 17:16:54 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Malwarebytes' Anti-Malware
[2009/09/17 17:16:18 | 04,045,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\and\Desktop\mbam-setup.exe
[2009/09/17 12:05:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Meus documentos\Os Meus Registos
[2009/09/17 09:20:25 | 00,074,240 | ---- | C] () -- C:\Documents and Settings\and\Meus documentos\fatura mama.doc
[2009/09/17 04:36:00 | 04,842,409 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Regis Danese - Faz Um Milagre Em Mim .mp3
[2009/09/16 20:00:04 | 00,475,448 | ---- | C] (Trend Micro Inc.) -- C:\HiJackThis.exe
[2009/09/16 02:47:28 | 04,319,360 | ---- | C] () -- C:\Documents and Settings\and\Desktop\William Nascimento - Deus vai na frente.mp3
[2009/09/15 22:55:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Windows Genuine Advantage
[2009/09/15 20:38:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Media Player Classic
[2009/09/15 16:15:15 | 00,000,786 | ---- | C] () -- C:\Documents and Settings\and\Desktop\sXe Injected.lnk
[2009/09/15 16:15:14 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\sXe Injected
[2009/09/15 16:12:56 | 00,000,000 | ---D | C] -- C:\temp
[2009/09/15 14:59:22 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\PluginLetras
[2009/09/15 14:10:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/09/15 12:47:20 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2009/09/15 12:47:19 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2009/09/15 03:58:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2009/09/15 03:45:15 | 05,889,036 | -H-- | C] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\IconCache.db
[2009/09/15 03:45:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Avg7
[2009/09/15 01:53:34 | 00,001,227 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Atalho para minhas musics.lnk
[2009/09/15 01:50:31 | 00,001,650 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Counter-Strike Source.lnk
[2009/09/15 01:09:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus!
[2009/09/15 00:50:33 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Messenger Plus! Live
[2009/09/15 00:50:11 | 00,013,496 | ---- | C] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT
[2009/09/15 00:25:24 | 00,221,184 | ---- | C] () -- C:\WINDOWS\ToproUI.exe
[2009/09/15 00:25:24 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\CamLib.Dll
[2009/09/15 00:25:24 | 00,049,152 | ---- | C] (MyCompanyName) -- C:\WINDOWS\System32\drivers\CUSTPAGE.AX
[2009/09/15 00:25:24 | 00,049,152 | ---- | C] (MyCompanyName) -- C:\WINDOWS\CUSTPAGE.AX
[2009/09/15 00:25:23 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Topro
[2009/09/15 00:13:44 | 00,001,800 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Counter-Strike.lnk
[2009/09/15 00:06:07 | 00,002,241 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2009/09/15 00:06:07 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Steam
[2009/09/15 00:04:02 | 00,001,793 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Counter Strike 1.6 Non Steam.lnk
[2009/09/15 00:03:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\WinRAR
[2009/09/14 23:59:55 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Valve
[2009/09/14 23:37:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Meus documentos\Meus arquivos recebidos
[2009/09/14 23:27:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\nView_Profiles
[2009/09/14 23:26:10 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009/09/14 23:24:45 | 00,043,209 | ---- | C] () -- C:\WINDOWS\System32\nvapps.xml
[2009/09/14 23:24:40 | 00,016,356 | ---- | C] () -- C:\WINDOWS\System32\nvdisp.nvu
[2009/09/14 23:24:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\nview
[2009/09/14 23:24:30 | 00,141,016 | ---- | C] () -- C:\WINDOWS\System32\ALSNDMGR.WAV
[2009/09/14 23:24:30 | 00,000,000 | -H-D | C] -- C:\Arquivos de programas\InstallShield Installation Information
[2009/09/14 23:24:07 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\InstallShield
[2009/09/14 23:10:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Macromedia
[2009/09/14 23:06:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Adobe
[2009/09/14 22:54:37 | 00,000,000 | R--D | C] -- C:\Documents and Settings\and\Meus documentos\Meus vídeos
[2009/09/14 22:52:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Identities
[2009/09/14 22:52:04 | 00,000,000 | R--D | C] -- C:\Documents and Settings\and\Meus documentos\Minhas imagens
[2009/09/14 22:52:04 | 00,000,000 | -H-D | C] -- C:\Arquivos de programas\Uninstall Information
[2009/09/14 22:51:41 | 00,000,874 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Foxit Reader.lnk
[2009/09/14 22:51:41 | 00,000,704 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Total Video Player.lnk
[2009/09/14 22:51:41 | 00,000,704 | ---- | C] () -- C:\Documents and Settings\and\Desktop\Total Video Converter.lnk
[2009/09/14 22:51:41 | 00,000,217 | ---- | C] () -- C:\Documents and Settings\and\Desktop\TUDO GRATIS.url
[2009/09/14 22:51:41 | 00,000,000 | --SD | C] -- C:\Documents and Settings\and\Dados de aplicativos\Microsoft
[2009/09/14 22:51:41 | 00,000,000 | R--D | C] -- C:\Documents and Settings\and\Meus documentos\Minhas músicas
[2009/09/14 22:51:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Sun
[2009/09/14 22:51:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Dados de aplicativos\Real
[2009/09/14 22:51:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\Real
[2009/09/14 22:51:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\Microsoft
[2009/09/14 22:51:37 | 00,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2009/09/14 22:49:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2009/09/14 22:49:20 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2009/09/14 22:49:11 | 00,000,006 | -H-- | C] () -- C:\WINDOWS\tasks\SA.DAT
[2009/09/14 22:49:04 | 00,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2009/09/14 22:47:44 | 00,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/09/14 22:47:09 | 00,028,288 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xjis.nls
[2009/09/14 22:46:46 | 00,080,896 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2009/09/14 22:46:46 | 00,080,896 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2009/09/14 22:46:46 | 00,029,184 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2009/09/14 22:46:43 | 00,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prcp.nls
[2009/09/14 22:46:42 | 00,083,748 | ---- | C] () -- C:\WINDOWS\System32\dllcache\prc.nls
[2009/09/14 22:46:26 | 01,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2009/09/14 22:46:26 | 00,047,066 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ksc.nls
[2009/09/14 22:46:15 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2009/09/14 22:46:13 | 00,057,856 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esuimgd.dll
[2009/09/14 22:46:13 | 00,045,568 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esunid.dll
[2009/09/14 22:46:13 | 00,031,744 | ---- | C] (SEIKO EPSON CORP.) -- C:\WINDOWS\System32\dllcache\esucmd.dll
[2009/09/14 22:46:04 | 00,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2009/09/14 22:46:03 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_720.nls
[2009/09/14 22:46:02 | 00,082,172 | ---- | C] () -- C:\WINDOWS\System32\dllcache\bopomofo.nls
[2009/09/14 22:46:01 | 00,066,728 | ---- | C] () -- C:\WINDOWS\System32\dllcache\big5.nls
[2009/09/14 22:45:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2009/09/14 22:45:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2009/09/14 22:45:41 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\xerox
[2009/09/14 22:45:41 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\microsoft frontpage
[2009/09/14 22:45:21 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Total Video Converter
[2009/09/14 22:45:19 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Microsoft
[2009/09/14 22:45:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documentos\microsoft
[2009/09/14 22:45:15 | 00,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2009/09/14 22:43:52 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Windows Live
[2009/09/14 22:43:29 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\Windows Live
[2009/09/14 22:43:08 | 00,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/09/14 22:42:39 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Microsoft.NET
[2009/09/14 22:42:37 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\DESIGNER
[2009/09/14 22:42:35 | 00,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2009/09/14 22:42:35 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Microsoft Office
[2009/09/14 22:41:51 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Foxit Reader
[2009/09/14 22:41:48 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/09/14 22:41:48 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/09/14 22:41:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\ESTsoft
[2009/09/14 22:41:47 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\WinRAR
[2009/09/14 22:41:39 | 00,278,528 | ---- | C] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2009/09/14 22:41:39 | 00,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/09/14 22:41:39 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2009/09/14 22:41:38 | 00,860,160 | ---- | C] (http://www.mp3dev.org/) -- C:\WINDOWS\System32\lameACM.acm
[2009/09/14 22:41:38 | 00,217,088 | ---- | C] (www.helixcommunity.org) -- C:\WINDOWS\System32\yv12vfw.dll
[2009/09/14 22:41:38 | 00,118,784 | ---- | C] (fccHandler) -- C:\WINDOWS\System32\ac3acm.acm
[2009/09/14 22:41:38 | 00,000,414 | ---- | C] () -- C:\WINDOWS\System32\lame_acm.xml
[2009/09/14 22:41:37 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009/09/14 22:41:37 | 00,755,027 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/09/14 22:41:37 | 00,683,520 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\divx.dll
[2009/09/14 22:41:37 | 00,159,839 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/09/14 22:41:37 | 00,081,920 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\dpl100.dll
[2009/09/14 22:41:36 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/09/14 22:41:36 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/09/14 22:41:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Real
[2009/09/14 22:41:35 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\K-Lite Codec Pack
[2009/09/14 22:40:35 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Java
[2009/09/14 22:39:38 | 00,728,858 | ---- | C] () -- C:\WINDOWS\System32\unins000.exe
[2009/09/14 22:39:38 | 00,004,096 | ---- | C] (My Company) -- C:\WINDOWS\System32\MyProg.exe
[2009/09/14 22:39:38 | 00,002,161 | ---- | C] () -- C:\WINDOWS\System32\unins000.dat
[2009/09/14 22:38:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2009/09/14 22:36:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2009/09/14 22:35:52 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/09/14 22:35:27 | 00,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2009/09/14 22:35:27 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2009/09/14 22:35:14 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\umdf
[2009/09/14 22:35:00 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Windows Media Connect 2
[2009/09/14 22:34:44 | 00,002,969 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/09/14 22:34:44 | 00,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2009/09/14 22:34:44 | 00,000,000 | RHS- | C] () -- C:\IO.SYS
[2009/09/14 22:34:44 | 00,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2009/09/14 22:34:44 | 00,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2009/09/14 22:34:41 | 00,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/09/14 22:34:41 | 00,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/09/14 22:34:40 | 00,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2009/09/14 22:34:01 | 00,000,488 | RH-- | C] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2009/09/14 22:34:01 | 00,000,488 | RH-- | C] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2009/09/14 22:34:01 | 00,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2009/09/14 22:34:01 | 00,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\WindowsShell.Manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | C] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2009/09/14 22:33:56 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documentos\Minhas músicas
[2009/09/14 22:33:56 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documentos\Minhas imagens
[2009/09/14 22:33:52 | 00,000,000 | -H-D | C] -- C:\Arquivos de programas\WindowsUpdate
[2009/09/14 22:33:49 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Serviços on-line
[2009/09/14 22:33:35 | 00,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2009/09/14 22:33:34 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\Serviços
[2009/09/14 22:33:32 | 00,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2009/09/14 22:33:31 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\MSSoap
[2009/09/14 22:33:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2009/09/14 22:33:23 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Movie Maker
[2009/09/14 22:33:05 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2009/09/14 22:33:02 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\NetMeeting
[2009/09/14 22:33:00 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Outlook Express
[2009/09/14 22:32:55 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\System
[2009/09/14 22:32:51 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Internet Explorer
[2009/09/14 22:32:26 | 00,021,844 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/09/14 22:32:17 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\ComPlus Applications
[2009/09/14 22:32:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2009/09/14 22:32:05 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Windows Media Player
[2009/09/14 22:31:57 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\MSN Gaming Zone
[2009/09/14 22:31:47 | 00,093,702 | ---- | C] () -- C:\WINDOWS\System32\subrange.uce
[2009/09/14 22:31:47 | 00,016,740 | ---- | C] () -- C:\WINDOWS\System32\shiftjis.uce
[2009/09/14 22:31:46 | 00,060,458 | ---- | C] () -- C:\WINDOWS\System32\ideograf.uce
[2009/09/14 22:31:46 | 00,024,006 | ---- | C] () -- C:\WINDOWS\System32\gb2312.uce
[2009/09/14 22:31:46 | 00,022,984 | ---- | C] () -- C:\WINDOWS\System32\bopomofo.uce
[2009/09/14 22:31:46 | 00,012,876 | ---- | C] () -- C:\WINDOWS\System32\korean.uce
[2009/09/14 22:31:46 | 00,008,484 | ---- | C] () -- C:\WINDOWS\System32\kanji_2.uce
[2009/09/14 22:31:46 | 00,006,948 | ---- | C] () -- C:\WINDOWS\System32\kanji_1.uce
[2009/09/14 22:31:45 | 00,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2009/09/14 22:31:45 | 00,001,221 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2009/09/14 22:31:44 | 00,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2009/09/14 22:31:39 | 00,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2009/09/14 22:31:37 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Windows NT
[2009/09/14 22:31:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2009/09/14 22:31:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2009/09/14 22:31:19 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documentos\Meus vídeos
[2009/09/14 19:28:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2009/09/14 19:26:32 | 00,004,444 | ---- | C] () -- C:\WINDOWS\System32\pid.PNF
[2009/09/14 19:26:31 | 00,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2009/09/14 19:26:28 | 00,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2009/09/14 19:26:28 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\ODBC
[2009/09/14 19:26:26 | 01,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2009/09/14 19:26:26 | 00,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2009/09/14 19:26:25 | 00,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2009/09/14 19:26:25 | 00,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2009/09/14 19:26:25 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\SpeechEngines
[2009/09/14 19:26:24 | 00,000,000 | R--D | C] -- C:\Arquivos de programas
[2009/09/14 19:26:24 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared
[2009/09/14 19:26:24 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns
[2009/09/14 19:26:23 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28603.nls
[2009/09/14 19:26:23 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_869.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_866.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_857.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_855.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_852.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_737.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_869.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_866.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_857.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_855.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_852.nls
[2009/09/14 19:26:22 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_737.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_875.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10082.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10081.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10029.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10017.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10010.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10007.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10006.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_875.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10082.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10081.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10029.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10017.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10010.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10007.nls
[2009/09/14 19:26:22 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10006.nls
[2009/09/14 19:26:14 | 00,000,515 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2009/09/14 19:26:04 | 00,144,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2009/09/14 19:26:03 | 01,088,840 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NTPRINT.CAT
[2009/09/14 19:26:03 | 00,809,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2009/09/14 19:26:03 | 00,399,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2009/09/14 19:26:03 | 00,105,628 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2009/09/14 19:26:03 | 00,037,509 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2009/09/14 19:26:03 | 00,034,747 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2009/09/14 19:26:03 | 00,033,765 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2009/09/14 19:26:03 | 00,016,825 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2009/09/14 19:26:03 | 00,013,497 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2009/09/14 19:26:03 | 00,012,363 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2009/09/14 19:26:03 | 00,010,027 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2009/09/14 19:26:03 | 00,008,599 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2009/09/14 19:26:03 | 00,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2009/09/14 19:26:03 | 00,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2009/09/14 19:26:02 | 02,038,809 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2009/09/14 19:26:02 | 01,233,746 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP3.CAT
[2009/09/14 19:26:02 | 00,634,592 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2009/09/14 19:25:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2009/09/14 19:25:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2009/09/14 19:25:46 | 00,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft
[2009/09/14 19:25:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings
[2009/09/14 19:25:28 | 00,097,456 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/14 19:25:28 | 00,000,000 | -HSD | C] -- C:\System Volume Information
[2009/09/14 19:24:28 | 00,000,211 | -HS- | C] () -- C:\boot.ini
[2009/09/14 19:24:25 | 00,000,974 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2009/09/14 19:20:42 | 00,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2009/09/14 19:20:42 | 00,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2009/09/14 19:20:42 | 00,000,000 | R--D | C] -- C:\WINDOWS\Web
[2009/09/14 19:20:42 | 00,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\pt-BR
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1046
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\system32
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\system
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\security
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\repair
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\PCHealth
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\NLDRV
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Network Diagnostic
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\mui
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Media
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\L2Schemas
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\java
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\ime
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Help
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\ehome
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\Config
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\addins
[2009/09/14 19:20:42 | 00,000,000 | ---D | C] -- C:\WINDOWS
[2009/09/14 16:03:55 | 00,012,800 | ---- | C] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/14 16:01:42 | 00,000,776 | ---- | C] () -- C:\WINDOWS\System32\drivers\etc\hosts.msn
========== Files - Modified Within 14 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/09/17 20:49:30 | 00,000,102 | -HS- | M] () -- C:\autorun.inf
[2009/09/17 20:45:41 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/09/17 20:45:29 | 00,043,209 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/09/17 20:45:27 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/09/17 20:45:26 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/09/17 20:44:03 | 00,000,056 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2009/09/17 19:52:08 | 06,971,836 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Epica - Triumph Of Defeat.mp3
[2009/09/17 18:15:20 | 00,002,241 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2009/09/17 17:37:32 | 00,514,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\and\Desktop\OTL.exe
[2009/09/17 17:16:57 | 00,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/09/17 17:16:25 | 04,045,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\and\Desktop\mbam-setup.exe
[2009/09/17 15:35:09 | 00,013,496 | ---- | M] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT
[2009/09/17 15:35:04 | 00,097,456 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/17 09:20:26 | 00,074,240 | ---- | M] () -- C:\Documents and Settings\and\Meus documentos\fatura mama.doc
[2009/09/17 05:08:17 | 05,889,036 | -H-- | M] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\IconCache.db
[2009/09/17 04:37:19 | 04,842,409 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Regis Danese - Faz Um Milagre Em Mim .mp3
[2009/09/16 20:00:32 | 00,475,448 | ---- | M] (Trend Micro Inc.) -- C:\HiJackThis.exe
[2009/09/16 02:56:45 | 04,319,360 | ---- | M] () -- C:\Documents and Settings\and\Desktop\William Nascimento - Deus vai na frente.mp3
[2009/09/16 01:51:25 | 00,012,800 | ---- | M] () -- C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/15 22:58:59 | 00,752,010 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/09/15 22:58:59 | 00,344,380 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat
[2009/09/15 22:58:59 | 00,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/09/15 22:58:59 | 00,048,628 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat
[2009/09/15 22:58:59 | 00,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/09/15 22:51:36 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/09/15 16:15:15 | 00,000,786 | ---- | M] () -- C:\Documents and Settings\and\Desktop\sXe Injected.lnk
[2009/09/15 03:47:42 | 00,000,217 | ---- | M] () -- C:\Documents and Settings\and\Desktop\TUDO GRATIS.url
[2009/09/15 01:53:54 | 00,001,227 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Atalho para minhas musics.lnk
[2009/09/15 01:50:31 | 00,001,650 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Counter-Strike Source.lnk
[2009/09/15 00:42:09 | 00,001,800 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Counter-Strike.lnk
[2009/09/15 00:12:43 | 00,001,793 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Counter Strike 1.6 Non Steam.lnk
[2009/09/14 22:53:08 | 00,000,267 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/09/14 22:49:04 | 00,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2009/09/14 22:47:44 | 00,000,974 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2009/09/14 22:45:23 | 00,000,704 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Total Video Player.lnk
[2009/09/14 22:45:23 | 00,000,704 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Total Video Converter.lnk
[2009/09/14 22:43:08 | 00,000,421 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2009/09/14 22:41:51 | 00,000,874 | ---- | M] () -- C:\Documents and Settings\and\Desktop\Foxit Reader.lnk
[2009/09/14 22:39:38 | 00,002,161 | ---- | M] () -- C:\WINDOWS\System32\unins000.dat
[2009/09/14 22:39:37 | 00,728,858 | ---- | M] () -- C:\WINDOWS\System32\unins000.exe
[2009/09/14 22:35:27 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\umdf\MsftWdf_user_01_00_00.Wdf
[2009/09/14 22:35:05 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/09/14 22:35:05 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/09/14 22:34:44 | 00,002,969 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/09/14 22:34:44 | 00,000,507 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/09/14 22:34:44 | 00,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2009/09/14 22:34:44 | 00,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/09/14 22:34:44 | 00,000,000 | ---- | M] () -- C:\WINDOWS\control.ini
[2009/09/14 22:34:44 | 00,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/09/14 22:34:44 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/09/14 22:34:40 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2009/09/14 22:34:32 | 00,004,205 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2009/09/14 22:34:01 | 00,000,488 | RH-- | M] () -- C:\WINDOWS\System32\WindowsLogon.manifest
[2009/09/14 22:34:01 | 00,000,488 | RH-- | M] () -- C:\WINDOWS\System32\logonui.exe.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\WindowsShell.Manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\sapi.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\nwc.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\ncpa.cpl.manifest
[2009/09/14 22:33:56 | 00,000,749 | RH-- | M] () -- C:\WINDOWS\System32\cdplayer.exe.manifest
[2009/09/14 22:32:26 | 00,021,844 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2009/09/14 22:32:16 | 00,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini
[2009/09/14 22:32:16 | 00,000,036 | ---- | M] () -- C:\WINDOWS\vb.ini
[2009/09/14 22:30:24 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/09/14 19:26:32 | 00,004,444 | ---- | M] () -- C:\WINDOWS\System32\pid.PNF
[2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
========== LOP Check ==========
[2009/09/17 17:16:54 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos
[2009/09/15 03:45:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Avg7
[2009/09/14 22:41:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\ESTsoft
[2009/09/16 22:07:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus!
[2009/09/17 17:16:58 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\and\Dados de aplicativos
[2009/09/14 22:41:35 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Default User\Dados de aplicativos
[2009/09/15 03:45:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dados de aplicativos
[2009/09/14 22:49:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dados de aplicativos
[2008/04/14 04:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/09/17 20:45:27 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
< End of report >
Obrigado e Abraços..
Boa Noite! danmex
<@> Abra o OTL.exe --> Clique em /applications/core/interface/imageproxy/imageproxy.php?img=http://i517.photobucket.com/albums/u338/Eextremeboy/CleanUp.jpg&key=016573111ad9c169c0d3ea5a93ca37e71831cd749205c5cef20ab141f5efc42e" alt="CleanUp.jpg" /> --> Sim!
<@> Reinicie o computador!
<><><><><><><><><><>
<@> Baixe: < FindyKill > ( ...par Chiquitine29 )
<@> Salve-a em Arquivos de Programas!
<@> Feche programas que estejam abertos.
<@> Desabilite a proteção residente de antivírus e antispywares.
<@> Ps: A detecção dessa ferramenta,por antivírus,é um falso positivo!
<@> Instale a ferramenta,e aceite todas as condições pedidas.
<@> Terminando;execute a ferramenta com um duplo-clique,em: C:\Arquivos de Programas\FindyKill\FindyKill.bat
<@> No prompt,aperte o P. --> Enter. <-- Opção de linguas!
<@> À seguir,aperte o 2. ( "Eliminar los ficheros infectados" )
<@> Aperte Enter --> O computador vai reiniciar,por duas vezes! --> Aguarde!
<@> Terminando,clique em uma área vazia do prompt! --> Aperte Enter.
<@> Abrir-se-à o Bloco de Notas,com o relatório: C:\FindyKill.txt <-- Rapport!
<><><><><><><><><><>
<@> Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://billy-oneal.com/Canned%2520Speeches/speechimages/combofix/desktopicon.png&key=c972c7524cf2a0d4771101cc561140ae5696a3aad55bcf64c111bf1861d92e85" alt="desktopicon.png" /> > ( ...by sUBs )
<!> Link-2 --> < ForoSpyware >
<!> Link-3 --> < GeeksToGo >
<@> Salve-o no desktop!
<@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! )
<@> Feche todas as janelas e execute a ferramenta!
<@> Ps: A execução,por comando,também é possível:<@> Vá em Iniciar --> Executar --> Digite ou cole: "%userprofile%\desktop\Combofix.exe" /killall
/applications/core/interface/imageproxy/imageproxy.php?img=http://img181.imageshack.us/img181/5825/combofixejr8.gif&key=0d882a59a7a65b06e1b50e837804afc9002b25433ef74e0c3f66f43a58058f7b" alt="combofixejr8.gif" />
<@> Clique em Ok.
<@> Na solicitação: "Negação de garantia de software" --> Clique em Sim!
/applications/core/interface/imageproxy/imageproxy.php?img=http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif&key=0010234c6eff8b98a829fe5910d3fd47cc8c551f0c1836fc4748c11079a71d03" alt="RcAuto1.gif" />
<@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo!
<@> Terminando,clique Sim ou Yes. --> Aguarde!
<!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta ComboFix.exe e faça,novamente,seu download.<!> Salve-a no desktop,renomeada como: Kombo.exe
<!> Ps: Nomeie durante o salvamento,e não após salvá-la!
<!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em "Modo de Segurança". <-- Link!
<!> Ps: Na presença de atividades rootkit,teremos a seguinte janela de notificação:
/applications/core/interface/imageproxy/imageproxy.php?img=http://img.photobucket.com/albums/v666/sUBs/Rookit_found.gif&key=eb1b849776e4208479b15adbf0e86845810495533720ff18c63647e4d0943f29" alt="Rookit_found.gif" />
<!> Ps: Anote essas detecções,e dê o OK.
<!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!
<!> Ps: Evite executar,voluntariamente,esta ferramenta!
<!> Ps: Para evitar problemas,siga todas as recomendações propostas.
<!> /applications/core/interface/imageproxy/imageproxy.php?img=http://www.bleepingcomputer.com/forums/style_emoticons/default/nuke.gif&key=c0e9c30559b25d185ea1b32a97bf019e216efb610a0bc1537235cd4f76019ff4" alt="nuke.gif" />*O **ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão** profissional.*
<@> Abrir-se-á a janela Auto Scan. --> Aguarde!
<@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador.
<@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!
<@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante!
<@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter!
<><><><><><><><><><>
<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.
Abraços!
Boa noite DigRAM
aqui estão os 2 logs atualizados
ComboFix 09-09-17.04 - and 17/09/2009 22:14.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1022.677 [GMT -3:00]
Executando de: c:\documents and settings\and\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\and\Dados de aplicativos\Microsoft\Clip Organizer\mstore10.mgc
c:\documents and settings\and\Dados de aplicativos\Microsoft\Clip Organizer\Offic10.MGC
C:\explorer.exe
c:\windows\system32\init.exe
c:\windows\system32\msconfig.exe
c:\windows\windowsmp.exe
c:\windows\yoos.b
D:\Autorun.inf
D:\explorer.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_4LLI
-------\Legacy_ASC3360PR
-------\Service_4LLI
-------\Service_asc3360pr
(((((((((((((((( Arquivos/Ficheiros criados de 2009-08-18 to 2009-09-18 ))))))))))))))))))))))))))))
.
2009-09-18 00:47 . 2009-09-18 00:57 -------- d-----w- C:\FindyKill
2009-09-18 00:46 . 2009-09-18 00:47 1288640 ----a-w- c:\arquivos de programas\FindyKill.exe
2009-09-17 20:16 . 2009-09-17 20:16 -------- d-----w- c:\documents and settings\and\Dados de aplicativos\Malwarebytes
2009-09-17 20:16 . 2009-09-10 17:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-17 20:16 . 2009-09-17 20:16 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware
2009-09-17 20:16 . 2009-09-17 20:16 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes
2009-09-17 20:16 . 2009-09-10 17:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-17 20:15 . 2009-09-17 20:15 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-09-17 12:09 . 2008-04-13 14:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-09-17 12:09 . 2008-04-13 14:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-09-16 23:00 . 2009-09-16 23:00 475448 ----a-w- C:\HiJackThis.exe
2009-09-16 01:50 . 2008-04-14 07:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-09-15 23:38 . 2009-09-15 23:38 -------- d-----w- c:\documents and settings\and\Dados de aplicativos\Media Player Classic
2009-09-15 19:15 . 2009-09-15 19:24 -------- d-----w- c:\arquivos de programas\sXe Injected
2009-09-15 19:12 . 2009-09-15 19:12 -------- d-----w- c:\temp\gentee01
2009-09-15 19:12 . 2009-09-15 19:12 -------- d-----w- C:\temp
2009-09-15 17:59 . 2009-09-15 17:59 -------- d-----w- c:\arquivos de programas\PluginLetras
2009-09-15 17:20 . 2008-06-14 17:34 272384 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-09-15 17:20 . 2008-06-14 17:34 272384 ------w- c:\windows\system32\drivers\bthport.sys
2009-09-15 17:18 . 2009-02-09 11:25 2193280 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-15 17:18 . 2009-02-09 11:25 2028032 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-09-15 17:18 . 2009-02-09 11:25 2149376 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-15 17:17 . 2009-07-03 16:59 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-15 17:17 . 2009-07-03 16:59 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-09-15 17:17 . 2009-07-03 16:59 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-09-15 17:17 . 2009-07-03 16:59 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-09-15 17:17 . 2009-07-03 16:59 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-09-15 17:10 . 2009-09-15 17:10 -------- d-----w- c:\windows\ie8updates
2009-09-15 15:47 . 2009-09-16 01:51 -------- d--h--w- c:\windows\$hf_mig$
2009-09-15 06:45 . 2009-09-15 06:45 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Avg7
2009-09-15 04:09 . 2009-09-17 01:07 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!
2009-09-15 03:50 . 2009-09-15 03:50 -------- d-----w- c:\arquivos de programas\Messenger Plus! Live
2009-09-15 03:25 . 2008-02-29 10:40 196548 ----a-w- c:\windows\system32\drivers\TP6800.SYS
2009-09-15 03:25 . 2007-06-04 05:54 57344 ----a-w- c:\windows\system32\CamLib.Dll
2009-09-15 02:24 . 2002-11-27 17:46 730700 ----a-w- c:\windows\system32\drivers\ALCXWDM.SYS
2009-09-15 02:24 . 2002-11-21 18:07 765952 ----a-w- c:\windows\system\crlds3d.dll
2009-09-15 02:24 . 2002-11-19 21:01 124416 ----a-w- c:\windows\SOUNDMAN.EXE
2009-09-15 02:24 . 2002-10-21 16:33 208896 ----a-w- c:\windows\alcupd.exe
2009-09-15 02:24 . 2002-10-17 15:54 131072 ----a-w- c:\windows\alcrmv.exe
2009-09-15 02:24 . 2002-08-27 19:23 720896 -c--a-w- c:\windows\system32\dllcache\a3d.dll
2009-09-15 02:24 . 2002-08-27 19:23 720896 ----a-w- c:\windows\system32\Audio3D.dll
2009-09-15 02:24 . 2002-08-27 19:23 720896 ----a-w- c:\windows\system32\a3d.dll
2009-09-15 02:24 . 2005-11-11 10:19 180224 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-09-15 02:24 . 2009-09-15 02:24 -------- d-----w- c:\arquivos de programas\Arquivos comuns\InstallShield
2009-09-15 02:06 . 2009-09-15 02:06 -------- d-sh--w- c:\documents and settings\and\IECompatCache
2009-09-15 02:05 . 2009-09-15 02:05 -------- d-sh--w- c:\documents and settings\and\PrivacIE
2009-09-15 02:05 . 2009-09-18 01:18 -------- d-----w- c:\documents and settings\and\Tracing
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-18 00:58 . 2008-04-14 07:00 48628 ----a-w- c:\windows\system32\perfc016.dat
2009-09-18 00:58 . 2008-04-14 07:00 344380 ----a-w- c:\windows\system32\perfh016.dat
2009-09-18 00:20 . 2009-09-15 03:06 -------- d-----w- c:\arquivos de programas\Steam
2009-09-17 21:02 . 2009-09-15 01:45 -------- d-----w- c:\arquivos de programas\Total Video Converter
2009-09-15 05:14 . 2009-09-15 02:59 -------- d-----w- c:\arquivos de programas\Valve
2009-09-15 03:25 . 2009-09-15 03:25 -------- d-----w- c:\arquivos de programas\Topro
2009-09-15 03:25 . 2009-09-15 02:24 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information
2009-09-15 03:02 . 2009-09-15 01:40 -------- d-----w- c:\arquivos de programas\Java
2009-09-15 02:27 . 2009-09-15 02:27 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\nView_Profiles
2009-09-15 01:45 . 2009-09-15 01:45 -------- d-----w- c:\arquivos de programas\microsoft frontpage
2009-09-15 01:45 . 2009-09-15 01:45 -------- d-----w- c:\arquivos de programas\Microsoft
2009-09-15 01:43 . 2009-09-15 01:43 -------- d-----w- c:\arquivos de programas\Windows Live
2009-09-15 01:43 . 2009-09-15 01:43 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Windows Live
2009-09-15 01:42 . 2009-09-15 01:42 -------- d-----w- c:\arquivos de programas\Microsoft.NET
2009-09-15 01:41 . 2009-09-15 01:41 -------- d-----w- c:\arquivos de programas\Foxit Reader
2009-09-15 01:41 . 2009-09-15 01:41 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\ESTsoft
2009-09-15 01:41 . 2009-09-15 01:41 -------- d-----w- c:\arquivos de programas\K-Lite Codec Pack
2009-09-15 01:39 . 2009-09-15 01:39 2161 ----a-w- c:\windows\system32\unins000.dat
2009-09-15 01:39 . 2009-09-15 01:39 728858 ----a-w- c:\windows\system32\unins000.exe
2009-09-15 01:38 . 2009-09-15 01:51 71680 ----a-w- c:\documents and settings\and\GLB799.tmp
2009-09-15 01:38 . 2009-09-15 01:47 71680 ----a-w- c:\windows\system32\config\systemprofile\GLB799.tmp
2009-09-15 01:38 . 2009-09-15 01:38 71680 ----a-w- c:\documents and settings\Default User\GLB799.tmp
2009-09-15 01:35 . 2009-09-15 01:35 -------- d-----w- c:\arquivos de programas\Windows Media Connect 2
2009-09-15 01:33 . 2009-09-15 01:33 -------- d-----w- c:\arquivos de programas\Serviços on-line
2009-09-15 01:33 . 2009-09-15 01:33 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Serviços
2009-09-15 01:32 . 2009-09-15 01:32 21844 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-05 09:00 . 2008-04-14 07:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:36 . 2008-04-14 07:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:36 . 2008-04-14 07:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-25 00:53 . 2009-09-15 01:41 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:03 . 2008-04-14 07:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 02:43 . 2006-10-18 19:47 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 16:59 . 2008-04-14 07:00 915456 ----a-w- c:\windows\system32\wininet.dll
.
------- Sigcheck -------
[-] 2009-04-17 . 2A293D04F15B5D25FF3615D8ED8DD1B7 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
c:\windows\system32\wscntfy.exe ... está faltando !!
c:\windows\system32\regsvc.dll ... está faltando !!
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
Nota entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3959136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-11 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-11-11 86016]
"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-07-25 231200]
"Malwarebytes Anti-Malware (reboot)"="c:\arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1389904]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2002-11-19 124416]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-11-11 1597440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Arquivos de programas\\Valve\\hl.exe"=
"c:\\Arquivos de programas\\Steam\\steamapps\\hishi601\\counter-strike\\hl.exe"=
"c:\\Arquivos de programas\\Steam\\Steam.exe"=
"c:\\Arquivos de programas\\Steam\\steamapps\\hishi601\\counter-strike source\\hl2.exe"=
"c:\\Arquivos de programas\\Java\\jre6\\bin\\jusched.exe"=
"c:\\WINDOWS\\system32\\nwiz.exe"=
"c:\\WINDOWS\\SOUNDMAN.EXE"=
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [17/4/2009 17:51 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [17/4/2009 17:51 52736]
R3 DCamUSBIntel;USB Video Camera;c:\windows\system32\drivers\TP6800.SYS [15/9/2009 00:25 196548]
--- =Outros Serviços/Drivers Na Memória ---
NewlyCreated - HELPSVC
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.google.com/
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: {300EDF33-DB30-43FA-AC3E-CF080FC6BB5F} = 200.165.132.154
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-17 22:18
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
c:\windows\system32\WININET.dll
c:\arquivos de programas\Windows Media Player\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Outros Processos em Execução ------------------------
.
c:\windows\system32\rundll32.exe
c:\arquivos de programas\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
.
**************************************************************************
.
Tempo para conclusão: 2009-09-18 22:20 - Máquina reiniciou
ComboFix-quarantined-files.txt 2009-09-18 01:19
Pré-execução: 3.540.369.408 bytes disponíveis
Pós execução: 3.452.674.048 bytes disponíveis
WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
205 --- E O F --- 2009-09-17 18:39
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:21:42, on 17/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O17 - HKLM\System\CCS\Services\Tcpip\..\{300EDF33-DB30-43FA-AC3E-CF080FC6BB5F}: NameServer = 200.165.132.154
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 3871 bytes
Abraços
Bom Dia! danmex
<!> Restou postar o relatório FindyKill.
<><><><><><><><><><>
<@> Baixe: < DrWebCureIt >
<@> Caso tenha dificuldades para o download,utilize outro computador ou proxy.
<@> Vá em: < Proxify >
<@> Digite,na caixa,a URL ao DrWebCureIt.
<@> Clique em Proxify.
<@> Salve a ferramenta no desktop!
<@> Reinicie o computador em Modo de Segurança.
<@> Inicie a instalação/execução,com um duplo-clique em drweb-cureit.
<@> Na janela que abrir,clique em Iniciar --> OK.
<@> Será dado início a "Verificação rápida" --> Feche a janela de propaganda!
<@> Terminando,marque a caixa de "Verificação Completa".
<@> Click em "Options" --> Em Change settings,desmarque a "Heuristic analysis".
>
Neste modo são verificados os seguintes objectos:
***** Sectores de Arranque de Todos os Discos. <--
***** Todas as Unidades Removíveis. <--
***** Todos os Discos Locais. <--
<@> Clique em "Iniciar verificação" --> Aguarde!
<@> Surgindo mensagens para mover ou desinfectar arquivos,clique em Sim.
<@> Terminando,clique em "Ficheiro" --> "Guardar lista de relatórios".
<@> Procure salvá-lo em um local adequado. ( DrWeb.csv ) <-- Converta em Texto!
<@> Poste: DrWeb.csv + HijackThis,atualizado
Abraços!
bom dia amigo Dig RAM
mas nao consigo baixar esse arquivo (DrWebCureIt)de forma alguma fui no link ai fechou o IE..
tenso :S.. ai fui da otra forma eh entro nesse site aqui http://proxify.com/p/011010A1000100/687474703a2f2f73707977617272656d6f76616c6c2e6f72672f3f7269643d313631333233333226726e616d653d64727765626375726569742e636f6d264f707449643d3131
aqui estáo log do findkill
############################## | FindyKill V5.011 |
############################## | Processos ativos |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | C: |
Supprimido ! C:\autorun.inf
Supprimido ! D:\autorun.inf
Supprimido ! D:\anderson arquivos\HD 2\Programas\DVD Anderson\dicionario aurelio\Autorun.inf
Supprimido ! D:\anderson arquivos\HD 2\Programas\DVD Anderson\drivers video,som\nvidia\driver nvidia\AUTORUN.INF
Supprimido ! D:\anderson arquivos\HD 2\Programas\DVD Anderson\drivers video,som\sound\A£dio\C-Media 9738\AUTORUN.INF
Supprimido ! D:\anderson arquivos\HD 2\Programas\DVD Anderson\drivers video,som\sound\A£dio\Media 9738\AUTORUN.INF
Supprimido ! D:\anderson arquivos\HD 2\Programas\DVD Anderson\Easy Creator 6.0 Br\Autorun.inf
Supprimido ! D:\anderson arquivos\HD 2\Programas\DVD Anderson\NERO 8\Autorun.inf
Supprimido ! D:\anderson arquivos\HD 2\Programas\DVD Anderson\OFFICE2007\autorun.inf
Supprimido ! D:\anderson arquivos\HD 2\Programas\DVD Anderson\OFICCE2003\AUTORUN.INF
Supprimido ! D:\anderson arquivos\HD 2\Programas\DVD Anderson\Pinnacle 9.3\AUTORUN.INF
Supprimido ! D:\anderson arquivos\HD 2\Programas\Meus documentos\C¢mo recargar cartuchos de tinta (Refilling Cartridges)\manual recarga universal para cartuchos de impresoras\Autorun.inf
Supprimido ! D:\wagner\LG_Sync_MG185\Autorun.inf
################## | C:\WINDOWS |
Supprimido ! C:\WINDOWS\Prefetch\WINUPGRO.EXE-17681AA8.pf
################## | C:\WINDOWS\system32 |
################## | C:\WINDOWS\system32\drivers |
################## | C:\Documents and Settings\and\Dados de aplicativos |
################## | Supressão Outros ... |
################## | Temporary Internet Files |
################## | Registro / Chaves infeciosas |
################## | Estado / Serviços / Informações |
################## | PEH ... |
################## | Cracks / Keygens / Serials |
################## | ! Fim do relatório # FindyKill V5.011 ! |
Abraços estou esperando aqui ansiosamente..
Bom Dia! danmex
<!> Voçê teve,ou ainda pode ter infecções oriundas de um infector ( Sality ) que além de outros efeitos perniciosos,impede ou dificulta a instalação de antivírus.
<><><><><><><><><><>
c:\windows\system32\wscntfy.exe ... está faltando !!c:\windows\system32\regsvc.dll ... está faltando !!
<!> ComboFix,aponta a ausência de 2 ficheiros,que poderão ser copiados de algum cache interno.
<!> Baixe: < regsvc.dll >
<!> Salve-o no diretório system32. --> Reinicie!
<!> Ps: Posteriormente,registraremos essa dll.
<><><><><><><><><><><>
<!> Ps: Baixe,daqui,o DrWebCureIt: < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.baixaki.com.br/imagens/galeria/115200934355PM.jpg&key=f3e50ee23e58cfa8f3a86b8a12fa8fe2df7e135d607fbf84f63f6e63e06004b3" alt="115200934355PM.jpg" /> >
<!> Execute-o,conforme instruções anteriores.
<!> Poste seu relatório!
Abraços!
Boa Noite DigRam..
não consegui entrar no modo de segurança do windows (o pc reinicia).. tentei executar o programa pelo modo normal ai deu um erro.. (obs: nao consegui baixar o programa pedi pra um amigo baixar e instalei atraves do pen drive)
você não me mandou esse executavel c:\windows\system32\wscntfy.exe ... está faltando !!
Abraços..
>
Boa Noite DigRam..
não consegui entrar no modo de segurança do windows (o pc reinicia).. tentei executar o programa pelo modo normal ai deu um erro.. (obs: nao consegui baixar o programa pedi pra um amigo baixar e instalei atraves do pen drive)
você não me mandou esse executavel c:\windows\system32\wscntfy.exe ... está faltando !!
Abraços..
Opa! danmex
você não me mandou esse executavel c:\windows\system32\wscntfy.exe ... está faltando !!
<!> Utilise a pesquisa do Windows,na busca ao arquivo. Encontrando,copie-o para a pasta system32.
<><><><><><><><><><>
<@> Baixe: < SafeBootKeyRepair >
<@> Salve,diretamente,no Disco-local ©.
<@> Execute-a!E,ao terminar,gerará um relatório: C:\SafeBoot_Repair.txt <-- Não poste!
<@> Verifique se já pode entrar,em Modo de Segurança!
<><><><><><><><><><>
<@> Ps: Execute DrWebCureIt,e poste seu relatório.
Abraços!
Bom dia DigRam..
OBS: o arquivo wscntfy.exe q você pediu pra me encontrar no windows meu pc nao achou. você me indica algum local pra baixar ou posso pegar de algum amigo do pc dele?
aqui estão os 2 logs que você pediu
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:33:34, on 20/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\HiJackThis.exe
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O17 - HKLM\System\CCS\Services\Tcpip\..\{300EDF33-DB30-43FA-AC3E-CF080FC6BB5F}: NameServer = 200.165.132.154
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL
O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 4901 bytes
DrWeb.csv Log
jusched.exe;c:\arquivos de programas\java\jre6\bin;Win32.Sector.5;Desinfectado.;
mbam.exe;c:\arquivos de programas\malwarebytes' anti-malware;Win32.Sector.5;Desinfectado.;
msnmsgr.exe;c:\arquivos de programas\windows live\messenger;Win32.Sector.5;Desinfectado.;
soundman.exe;c:\windows;Win32.Sector.5;Desinfectado.;
ctfmon.exe;c:\windows\system32;Win32.Sector.5;Desinfectado.;
nwiz.exe;c:\windows\system32;Win32.Sector.5;Desinfectado.;
rundll32.exe;c:\windows\system32;Win32.Sector.5;Desinfectado.;
shimgvw.dll;c:\windows\system32;Win32.Sector.5;Desinfectado.;
hpztsb10.exe;c:\windows\system32\spool\drivers\w32x86\3;Win32.Sector.5;Desinfectado.;
HiJackThis.exe;C:\;Win32.Sector.5;Desinfectado.;
FindyKill.exe;C:\Arquivos de programas;Win32.Sector.5;Desinfectado.;
Foxit Reader.exe;C:\Arquivos de programas\Foxit Reader;Win32.Sector.5;Desinfectado.;
setup.exe;C:\Arquivos de programas\InstallShield Installation Information\{B8410225-2F65-4BD6-A771-416CC1EAD58D};Win32.Sector.5;Desinfectado.;
iexplore.exe;C:\Arquivos de programas\Internet Explorer;Win32.Sector.5;Desinfectado.;
jqsnotify.exe;C:\Arquivos de programas\Java\jre6\bin;Win32.Sector.5;Desinfectado.;
jucheck.exe;C:\Arquivos de programas\Java\jre6\bin;Win32.Sector.5;Desinfectado.;
jusched.exe;C:\Arquivos de programas\Java\jre6\bin;Win32.Sector.5;Desinfectado.;
mbam.exe;C:\Arquivos de programas\Malwarebytes' Anti-Malware;Win32.Sector.5;Desinfectado.;
mbamgui.exe;C:\Arquivos de programas\Malwarebytes' Anti-Malware;Win32.Sector.5;Desinfectado.;
MPTools.exe;C:\Arquivos de programas\Messenger Plus! Live;Win32.Sector.5;Desinfectado.;
Steam.exe;C:\Arquivos de programas\Steam;Win32.Sector.5;Desinfectado.;
hl.exe;C:\Arquivos de programas\Steam\steamapps\hishi601\counter-strike;Win32.Sector.5;Desinfectado.;
hl2.exe;C:\Arquivos de programas\Steam\steamapps\hishi601\counter-strike source;Win32.Sector.5;Desinfectado.;
tppoll.exe;C:\Arquivos de programas\Topro\TP6800;Win32.Sector.5;Desinfectado.;
hl.exe;C:\Arquivos de programas\Valve;Win32.Sector.5;Desinfectado.;
wlarp.exe;C:\Arquivos de programas\Windows Live\Installer;Win32.Sector.5;Desinfectado.;
wloobe.exe;C:\Arquivos de programas\Windows Live\Installer;Win32.Sector.5;Desinfectado.;
msnmsgr.exe;C:\Arquivos de programas\Windows Live\Messenger;Win32.Sector.5;Desinfectado.;
msvs.exe;C:\Arquivos de programas\Windows Live\Messenger;Win32.Sector.5;Desinfectado.;
wmplayer.exe;C:\Arquivos de programas\Windows Media Player;Win32.Sector.5;Desinfectado.;
wmpshare.exe;C:\Arquivos de programas\Windows Media Player;Win32.Sector.5;Desinfectado.;
wordpad.exe;C:\Arquivos de programas\Windows NT\Acessórios;Win32.Sector.5;Desinfectado.;
desktop.exe;C:\Documents and Settings\and\7zS773.tmp;Win32.Sector.5;Desinfectado.;
NETFramework2.0.exe;C:\Documents and Settings\and\7zS773.tmp;Win32.Sector.5;Desinfectado.;
flashplayer10_install_plugin_051508.exe;C:\Documents and Settings\and\7zS791.tmp;Win32.Sector.5;Desinfectado.;
Plugin Flash IE v9.0.124.exe;C:\Documents and Settings\and\7zS795.tmp;Win32.Sector.5;Desinfectado.;
WALLPAPERS.exe;C:\Documents and Settings\and\7zS79F.tmp;Win32.Sector.5;Desinfectado.;
c.exe;C:\Documents and Settings\and\7zS7B7.tmp;Win32.Sector.5;Desinfectado.;
d.exe;C:\Documents and Settings\and\7zS7B7.tmp;Win32.Sector.5;Desinfectado.;
KEY.exe;C:\Documents and Settings\and\7zS7B7.tmp;Win32.Sector.5;Desinfectado.;
pt.exe;C:\Documents and Settings\and\7zS7B7.tmp;Win32.Sector.5;Desinfectado.;
RAR.EXE;C:\Documents and Settings\and\7zS7B7.tmp;Win32.Sector.5;Desinfectado.;
br.exe;C:\Documents and Settings\and\7zS7B8.tmp;Win32.Sector.5;Desinfectado.;
d.exe;C:\Documents and Settings\and\7zS7B8.tmp;Win32.Sector.5;Desinfectado.;
PDF.EXE;C:\Documents and Settings\and\7zS7B8.tmp;Win32.Sector.5;Desinfectado.;
FoxitReader-23.exe;C:\Documents and Settings\and\7zS7B9.tmp;Win32.Sector.5;Desinfectado.;
cache.exe;C:\Documents and Settings\and\7zS7FE.tmp;Win32.Sector.5;Desinfectado.;
d.exe;C:\Documents and Settings\and\7zS7FF.tmp;Win32.Sector.5;Desinfectado.;
MsgPlusLive-481.exe;C:\Documents and Settings\and\7zS7FF.tmp;Win32.Sector.5;Desinfectado.;
MsgPlusLive-481.exe;C:\Documents and Settings\and\7zS800.tmp;Win32.Sector.5;Desinfectado.;
d.exe;C:\Documents and Settings\and\7zS801.tmp;Win32.Sector.5;Desinfectado.;
Kaspersky.exe;C:\Documents and Settings\and\7zS801.tmp;Win32.Sector.5;Desinfectado.;
desktop.exe;C:\Documents and Settings\and\7zS830.tmp;Win32.Sector.5;Desinfectado.;
agsetup183se.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
CrystalPro.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
daemon tools347.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
Firefox Setup 3.0.1.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
flash_player.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
install_flash_player.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
inst_discadorOiInternet.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
Java 2 Runtime Environment SE v1.5.0_06.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
kav8.0.0.506pb.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
MsgPlusLive-450.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
Total_video_convert_3.10_en_su_version_portable_by_Madestro.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
Vista Transformation Pack 7.0.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
winamp5552_lite_pt-br.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
WLinstaller.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
YouTubeCatcher_1_0_rc2_setup.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;Win32.Sector.5;Desinfectado.;
zlsSetup_70_483_000_en.exe/Z4BARSPINSTALL.EXE/data001\data001;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7\zlsSetup_70_483_000_en.exe/Z4BARSPINSTALL.EX;Adware.MyWebSearch.22;;
data001;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;A pasta contem objectos infectados;;
Z4BARSPINSTALL.EXE;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;A pasta contem objectos infectados;;
zlsSetup_70_483_000_en.exe;C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7;O arquivo contém objectos infectados;Movido.;
p6j2wme.exe;C:\Documents and Settings\and\Configurações locais\temp\RarSFX0;Win32.Sector.5;Desinfectado.;
wscntfy.exe;C:\Documents and Settings\and\Meus documentos\Meus arquivos recebidos;Win32.Sector.5;Desinfectado.;
desktop.exe;C:\Documents and Settings\Default User\7zS773.tmp;Win32.Sector.5;Desinfectado.;
NETFramework2.0.exe;C:\Documents and Settings\Default User\7zS773.tmp;Win32.Sector.5;Desinfectado.;
flashplayer10_install_plugin_051508.exe;C:\Documents and Settings\Default User\7zS791.tmp;Win32.Sector.5;Desinfectado.;
Plugin Flash IE v9.0.124.exe;C:\Documents and Settings\Default User\7zS795.tmp;Win32.Sector.5;Desinfectado.;
WALLPAPERS.exe;C:\Documents and Settings\Default User\7zS79F.tmp;Win32.Sector.5;Desinfectado.;
c.exe;C:\Documents and Settings\Default User\7zS7B7.tmp;Win32.Sector.5;Desinfectado.;
d.exe;C:\Documents and Settings\Default User\7zS7B7.tmp;Win32.Sector.5;Desinfectado.;
KEY.exe;C:\Documents and Settings\Default User\7zS7B7.tmp;Win32.Sector.5;Desinfectado.;
pt.exe;C:\Documents and Settings\Default User\7zS7B7.tmp;Win32.Sector.5;Desinfectado.;
RAR.EXE;C:\Documents and Settings\Default User\7zS7B7.tmp;Win32.Sector.5;Desinfectado.;
br.exe;C:\Documents and Settings\Default User\7zS7B8.tmp;Win32.Sector.5;Desinfectado.;
d.exe;C:\Documents and Settings\Default User\7zS7B8.tmp;Win32.Sector.5;Desinfectado.;
PDF.EXE;C:\Documents and Settings\Default User\7zS7B8.tmp;Win32.Sector.5;Desinfectado.;
FoxitReader-23.exe;C:\Documents and Settings\Default User\7zS7B9.tmp;Win32.Sector.5;Desinfectado.;
cache.exe;C:\Documents and Settings\Default User\7zS7FE.tmp;Win32.Sector.5;Desinfectado.;
d.exe;C:\Documents and Settings\Default User\7zS7FF.tmp;Win32.Sector.5;Desinfectado.;
MsgPlusLive-481.exe;C:\Documents and Settings\Default User\7zS7FF.tmp;Win32.Sector.5;Desinfectado.;
MsgPlusLive-481.exe;C:\Documents and Settings\Default User\7zS800.tmp;Win32.Sector.5;Desinfectado.;
d.exe;C:\Documents and Settings\Default User\7zS801.tmp;Win32.Sector.5;Desinfectado.;
Kaspersky.exe;C:\Documents and Settings\Default User\7zS801.tmp;Win32.Sector.5;Desinfectado.;
desktop.exe;C:\Documents and Settings\Default User\7zS830.tmp;Win32.Sector.5;Desinfectado.;
ByPass.exe;C:\FindyKill;Win32.Sector.5;Desinfectado.;
fsum.exe;C:\FindyKill\Tools;Win32.Sector.5;Desinfectado.;
SniffC.exe;C:\FindyKill\Tools;Win32.Sector.5;Desinfectado.;
winupgro.exe;C:\FindyKill\Tools;Win32.Sector.5;Desinfectado.;
explorer.exe.vir;C:\Qoobox\Quarantine\C;Win32.Sector.5;Desinfectado.;
explorer.exe.vir;C:\Qoobox\Quarantine\C;Win32.HLLW.Autoruner.5479;Eliminado.;
windowsmp.exe.vir;C:\Qoobox\Quarantine\C\WINDOWS;Win32.Sector.5;Desinfectado.;
windowsmp.exe.vir;C:\Qoobox\Quarantine\C\WINDOWS;Win32.HLLW.Autoruner.5479;Eliminado.;
yoos.b.vir;C:\Qoobox\Quarantine\C\WINDOWS;Win32.Sector.5;Desinfectado.;
yoos.b.vir;C:\Qoobox\Quarantine\C\WINDOWS;Win32.HLLW.Autoruner.5479;Eliminado.;
init.exe.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Win32.Sector.5;Desinfectado.;
init.exe.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Win32.HLLW.Autoruner.5479;Eliminado.;
explorer.exe.vir;C:\Qoobox\Quarantine\D;Win32.Sector.5;Desinfectado.;
explorer.exe.vir;C:\Qoobox\Quarantine\D;Win32.HLLW.Autoruner.5479;Eliminado.;
A0019429.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019431.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019432.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019433.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019434.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019436.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019439.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019440.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019442.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019443.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019455.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019458.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019459.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019460.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019461.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019463.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019469.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019470.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019471.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019475.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019476.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019478.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019480.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019482.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019483.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019484.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019485.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019492.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019496.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019498.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019502.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019503.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019504.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019506.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019509.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019510.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019513.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019514.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019518.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019519.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019520.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019521.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019522.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019524.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019525.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019526.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019527.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019528.EXE;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019530.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019531.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019532.EXE;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019533.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019535.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019663.rbf;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019868.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019872.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019873.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019877.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019878.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019880.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019883.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019884.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019886.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019888.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019896.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019902.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019906.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019907.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019908.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019910.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019913.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019914.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019917.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019918.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019925.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019926.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019927.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019928.EXE;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019929.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019930.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019931.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019932.dll;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019933.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019934.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019936.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019937.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019939.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019940.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019942.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019945.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019946.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019947.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019948.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019950.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019951.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019952.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019953.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019954.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019956.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019957.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019958.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019959.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019960.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019962.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019963.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019964.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019965.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019966.EXE;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019968.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019969.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019970.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019971.EXE;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019972.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019973.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019974.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019976.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019977.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019978.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019980.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019981.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019982.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019984.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019986.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019987.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019988.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019989.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019990.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019991.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019992.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019994.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019995.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019996.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019997.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019998.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020000.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020001.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020002.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020003.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020004.EXE;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020006.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020007.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020008.EXE;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020009.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020010.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020012.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020013.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020014.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020016.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020017.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020019.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020021.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020023.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020026.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020028.exe;C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
SOUNDMAN.EXE;C:\WINDOWS;Win32.Sector.5;Desinfectado.;
EXCEL.EXE;C:\WINDOWS\Installer\$PatchCache$\Managed\6140110900063D11C8EF10054038389C\11.0.7969;Win32.Sector.5;Desinfectado.;
calc.exe;C:\WINDOWS\system32;Win32.Sector.5;Desinfectado.;
ctfmon.exe;C:\WINDOWS\system32;Win32.Sector.5;Desinfectado.;
mspaint.exe;C:\WINDOWS\system32;Win32.Sector.5;Desinfectado.;
notepad.exe;C:\WINDOWS\system32;Win32.Sector.5;Desinfectado.;
nwiz.exe;C:\WINDOWS\system32;Win32.Sector.5;Desinfectado.;
rundll32.exe;C:\WINDOWS\system32;Win32.Sector.5;Desinfectado.;
shimgvw.dll;C:\WINDOWS\system32;Win32.Sector.5;Desinfectado.;
sndvol32.exe;C:\WINDOWS\system32;Win32.Sector.5;Desinfectado.;
hpzstc10.exe;C:\WINDOWS\system32\spool\drivers\w32x86\3;Win32.Sector.5;Desinfectado.;
hpzstw10.exe;C:\WINDOWS\system32\spool\drivers\w32x86\3;Win32.Sector.5;Desinfectado.;
hpztsb10.exe;C:\WINDOWS\system32\spool\drivers\w32x86\3;Win32.Sector.5;Desinfectado.;
avg75free_476a1048.exe;D:\anderson arquivos\HD 2\Meus doc\Anti virus;Win32.Sector.5;Desinfectado.;
avg_free_stf_en_8_169a1359.exe;D:\anderson arquivos\HD 2\Meus doc\Anti virus;Win32.Sector.5;Desinfectado.;
AVAST_PROFISSIONAL_17_JUNHO_2008.exe;D:\anderson arquivos\HD 2\Meus doc\Anti virus\Avast + serial\AVAST_PROFISSIONAL;Win32.Sector.5;Desinfectado.;
configurador510v6.exe;D:\anderson arquivos\HD 2\Programas\DVD Anderson\SpeedTouch_upgrade_wizard_R4421;Win32.Sector.5;Desinfectado.;
upgradeST.exe;D:\anderson arquivos\HD 2\Programas\DVD Anderson\SpeedTouch_upgrade_wizard_R4421;Win32.Sector.5;Desinfectado.;
stInstall.exe;D:\anderson arquivos\HD 2\Programas\Meus documentos\roteadores\SpeedTouch_upgrade_wizard_R4421\SpeedTouch 510 v6\SetupWizard;Win32.Sector.5;Desinfectado.;
setup.exe;D:\DAN ARQUIVOS\0109_driver\birght-Vista DRIVER\970229 TP6801 cx0342 Vista;Win32.Sector.5;Desinfectado.;
cs16patch_full_V23.exe;D:\DAN ARQUIVOS\COUNTERSTRIKE;Win32.Sector.5;Desinfectado.;
sc.exe;D:\DAN ARQUIVOS\COUNTERSTRIKE\Adminmod\scripting\compiler;Win32.Sector.5;Desinfectado.;
sc64.exe;D:\DAN ARQUIVOS\COUNTERSTRIKE\Adminmod\scripting\compiler;Win32.Sector.5;Desinfectado.;
encrypt.exe;D:\DAN ARQUIVOS\COUNTERSTRIKE\Adminmod\tools;Win32.Sector.5;Desinfectado.;
ComboFix.exe;D:\DAN ARQUIVOS\DAN PC;Win32.Sector.5;Desinfectado.;
DW20.EXE;D:\MSOCache\All Users\90000416-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW;Win32.Sector.5;Desinfectado.;
DWTRIG20.EXE;D:\MSOCache\All Users\90000416-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW;Win32.Sector.5;Desinfectado.;
OFFCLN.EXE;D:\MSOCache\All Users\90000416-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\OFFICE11;Win32.Sector.5;Desinfectado.;
OSE.EXE;D:\MSOCache\All Users\90000416-6000-11D3-8CFE-0150048383C9\FILES\SETUP;Win32.Sector.5;Desinfectado.;
A0019447.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019457.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019465.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019466.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019472.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019477.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019495.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019499.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019500.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019505.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019511.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019515.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP20;Win32.Sector.5;Desinfectado.;
A0019871.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019874.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019876.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019879.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019887.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019889.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019899.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019903.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019904.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019909.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019915.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0019919.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020032.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020033.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020034.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020035.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020036.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020037.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020038.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020039.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020040.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020041.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020042.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020043.exe;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020044.EXE;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020045.EXE;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020046.EXE;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0020047.EXE;D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP21;Win32.Sector.5;Desinfectado.;
A0063020.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063020.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.HLLW.Autoruner.5479;Eliminado.;
A0063067.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063068.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063069.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063070.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063073.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063074.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063076.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063077.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063086.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063087.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063088.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063089.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063091.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063092.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063094.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063142.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063145.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063150.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063150.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.HLLW.Autoruner.5479;Eliminado.;
A0063152.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063153.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063160.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063163.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063176.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063177.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063184.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063185.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063186.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063187.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063189.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063190.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063192.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063219.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063228.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063228.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.HLLW.Autoruner.5479;Eliminado.;
A0063233.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063234.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063235.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063242.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063245.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063258.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063259.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063266.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063267.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063268.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063269.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063270.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063271.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063273.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063338.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063341.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063346.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063346.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.HLLW.Autoruner.5479;Eliminado.;
A0063348.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063349.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063354.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063357.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063371.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063372.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063379.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063380.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063381.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063382.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063383.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063384.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063386.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91;Win32.Sector.5;Desinfectado.;
A0063409.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063409.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.HLLW.Autoruner.5479;Eliminado.;
A0063452.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063455.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063460.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063460.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.HLLW.Autoruner.5479;Eliminado.;
A0063462.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063463.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063468.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063472.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063484.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063485.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063492.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063493.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063494.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063495.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063496.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063497.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063499.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063522.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063525.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063531.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063531.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.HLLW.Autoruner.5479;Eliminado.;
A0063532.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063533.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063538.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063542.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063556.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063557.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063593.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063594.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063595.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063596.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063597.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063598.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0063600.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0064522.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0064529.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0064534.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0064534.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.HLLW.Autoruner.5479;Eliminado.;
A0064536.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0064537.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0064543.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0064546.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065522.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065525.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065530.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065530.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.HLLW.Autoruner.5479;Eliminado.;
A0065532.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065533.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065539.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065543.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065556.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065557.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065566.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065567.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065568.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065569.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065570.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065571.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065573.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065609.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065612.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065617.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065617.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.HLLW.Autoruner.5479;Eliminado.;
A0065618.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065619.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065624.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065628.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065643.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065644.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065651.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065652.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065653.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065654.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065655.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065656.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065658.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92;Win32.Sector.5;Desinfectado.;
A0065679.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065679.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.HLLW.Autoruner.5479;Eliminado.;
A0065707.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065720.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065721.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065722.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065725.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065726.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065729.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065730.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065746.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065752.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065752.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.HLLW.Autoruner.5479;Eliminado.;
A0065753.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065756.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065758.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065762.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065767.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065785.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065786.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065793.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065794.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065795.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065796.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065798.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065799.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065801.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065859.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065866.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065866.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.HLLW.Autoruner.5479;Eliminado.;
A0065867.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065870.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065871.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065878.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065880.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065895.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065896.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065904.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065905.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065906.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065907.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065908.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065909.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065911.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93;Win32.Sector.5;Desinfectado.;
A0065962.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0065962.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.HLLW.Autoruner.5479;Eliminado.;
A0065993.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0065999.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0065999.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.HLLW.Autoruner.5479;Eliminado.;
A0066000.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066007.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066008.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066014.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066017.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066033.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066034.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066188.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066189.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066190.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066191.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066192.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066193.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066195.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066206.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066213.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066213.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.HLLW.Autoruner.5479;Eliminado.;
A0066214.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066217.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066218.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066223.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066226.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066252.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066253.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066254.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066255.EXE;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066256.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066257.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066259.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94;Win32.Sector.5;Desinfectado.;
A0066324.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066324.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.HLLW.Autoruner.5479;Eliminado.;
A0066354.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066358.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066391.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066391.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.HLLW.Autoruner.5479;Eliminado.;
A0066407.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066414.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066414.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.HLLW.Autoruner.5479;Eliminado.;
A0066415.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066418.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066419.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066425.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066427.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066463.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066463.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.HLLW.Autoruner.5479;Eliminado.;
A0066466.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066469.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066470.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066471.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066483.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066519.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066519.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.HLLW.Autoruner.5479;Eliminado.;
A0066522.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066526.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066527.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066528.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066535.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0066538.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0067519.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0067519.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.HLLW.Autoruner.5479;Eliminado.;
A0067522.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0067525.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0067526.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0067527.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0067535.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
A0067537.exe;D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95;Win32.Sector.5;Desinfectado.;
Installer.exe;D:\wagner\LG_Sync_MG185;Win32.Sector.5;Desinfectado.;
Setup.exe;D:\wagner\LG_Sync_MG185\MG185_EN;Win32.Sector.5;Desinfectado.;
Setup.exe;D:\wagner\LG_Sync_MG185\MG185_PT;Win32.Sector.5;Desinfectado.;Bom Dia! danmex
OBS: o arquivo wscntfy.exe q você pediu pra me encontrar no windows meu pc nao achou. você me indica algum local pra baixar ou posso pegar de algum amigo do pc dele?
<!> Tendo essa disponibilidade,pode pegar.
<><><><><><><><><><><><>
<@> Baixe: < sality_off.zip >
<@> Extraia seu conteúdo,para o C:\. <-- Disco local ©
<@> Desative seu antivírus temporariamente!
<@> Desabilite a Restauração do sistema.
<@> Ps: A vacina será executada,simultaneamente,em 2 janelas:
<1> A primeira janela:
<@> Vá em Iniciar --> Executar > Digite: C:\Sality_off.exe -m
/applications/core/interface/imageproxy/imageproxy.php?img=http://f.imagehost.org/0007/sality.jpg&key=684f2c23c3a44a80327e16dad0182c4ae5c22b637f337a44bcf754667bfdd6c6" alt="sality.jpg" />
<@> Clique OK!
<@> Ps: Aguarde a finalização,que é demorada!
<2> A segunda janela:
<@> Dê duplo-clique em: C:\Sality_off.exe
<@> Ps: Aguarde a finalização,que é demorada!
<@> Terminando,aperte ENTER! --> Habilite,novamente,a Restauração do sistema.
<><><><><><><><><><><><>
<@> Vá até a pasta "Virus Removal Tool". <-- Localize-a!
<@> Clique no ícone "Kaspersky",cujo nome é Start.
<@> Feche a pasta Virus Removal Tool.
<@> Localize e clique em "Statistics". <-- *Log **não**-desinfectado!*
<@> Com a caixa "Show neutralized objetcs" estando selecionada/marcada,clique no botão "Neutralize all".
<@> Ps: Ignore seus efeitos e clique na caixa "Aplly to all".
<@> À seguir,clique em "Disinfect",caso esteja habilitada.
<@> Ps: Caso a janela de alerta abra novamente,repita o procedimento.
<@> Ps: Se a opção "Disinfect" estiver desabilitada,procure desinstalar a ferramenta indo ao arquivo "unins000.exe",que encontra-se na pasta Kaspersky AVP Tool.
<@> Baixe-a ou instale-a,novamente,e repita o scan,seguindo instruções anteriores.
<@> Ps: O computador poderá ser reiniciado,para completar sua desinstalação ou remoção de algum malware.
<@> Habilitada a desinfecção,aguarde a finalização do processo.
<@> Clique no botão "Reports" --> Clique em "Save to file".
<@> Nomeie esse relatório,e poste-o na sua resposta.
<@> Saia da ferramenta,clicando no "X" da janela. --> Clique em "Yes",nas solicitações!
<@> Ps: Ignore o pedido da senha,caso surja,clicando em "Skip".
Abraços!
Boa Tarde DiGRam
bom executei os dois programas simultaneamente..mas so o da segunda janela teve iniciação e fim
o da primeira janela fico nessas frases aqui : Scanning processes...
Monitoring memory...
sendo q o da primeira janela ficou bastante tempo assim (quase 1 hr) sem progresso nenhum..
terminei o da segunda janela.. eh nao axei o arquivo "Virus Removal Tool"
:(
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:19:54, on 20/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\DllHost.exe
C:\Sality_off.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\HiJackThis.exe
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\RunOnce: [uninstall Adobe Download Manager] "C:\WINDOWS\system32\rundll32.exe" "C:\Arquivos de programas\NOS\bin\getPlus_Helper.dll",Uninstall /Get1noarp
O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O17 - HKLM\System\CCS\Services\Tcpip\..\{300EDF33-DB30-43FA-AC3E-CF080FC6BB5F}: NameServer = 200.165.132.154
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL
O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 4597 bytes
Boa tarde
Boa Tarde! danmex
bom executei os dois programas simultaneamente..mas so o da segunda janela teve iniciação e fimo da primeira janela fico nessas frases aqui : Scanning processes...
Monitoring memory...
<!> Travou ao monitorar algum ficheiro na memória.
sendo q o da primeira janela ficou bastante tempo assim (quase 1 hr) sem progresso nenhum..terminei o da segunda janela.. eh nao axei o arquivo "Virus Removal Tool"
<!> É uma pasta eivada de arquivos da ferramenta AVPTool.
<!> Caso à encontre,siga com a desinfecção.
<><><><><><><><><><>
<@> Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.paules-pc-forum.de/images/a2/a2ppf_banner.jpg&key=3c2b716d91fd866606e67e92d567ab369edeebed33eceea4fa86ab3bbaf49355" alt="a2ppf_banner.jpg" /> > ( ...by EmsiSoft )
<@> Salve-o em Arquivos de programas.
<@> Abra o programa e clique em: Atualizar agora --> Aguarde!
<@> Terminando,clique em: "Scan PC"
<@> Escolha a opção: "A fundo" --> Clique,à seguir,em "Analisar".
<@> Terminando,marque as caixinhas dos ítens encontrados e clique em "Enviar marcados à Quarentena".
<@> Salve e poste o relatório desta verificação. ( a2scan_xxyy09-xxxxxx.txt ) <--
Abraços!
Boa tarde DigRAM
continuo não encontrado o arquivo AVPTool (sera q o arquivo nao foi criado pq nao terminei as vacinas daquela primeira janela q travo na hr di scaniar a memoria?)
aqui esta o log
a-squared Free - Versão 4.5
Última atualização 20/9/2009 16:45:22
Configurações da análise:
Scan type: deep
Objetos: Memória, Rastros, Cookies, C:\, D:\
Análise de arquivos: Ligado
Heurística: Desligado
Análise de ADS: Ligado
Início da análise: 20/9/2009 16:46:52
C:\Documents and Settings\and\Cookies\and@adserver.dialhost.com[2].txt detectado: Trace.TrackingCookie.adserv!A2
C:\Documents and Settings\and\Cookies\and@atdmt[1].txt detectado: Trace.TrackingCookie.atdmt!A2
C:\Documents and Settings\and\Cookies\and@doubleclick[2].txt detectado: Trace.TrackingCookie.doubleclick!A2
C:\Documents and Settings\and\Cookies\and@google.com[1].txt detectado: Trace.TrackingCookie.google.com!A2
C:\Documents and Settings\and\Cookies\and@google.com[2].txt detectado: Trace.TrackingCookie.google.com!A2
C:\Documents and Settings\and\Cookies\and@ig.com[1].txt detectado: Trace.TrackingCookie.ig.com!A2
C:\Documents and Settings\and\Cookies\and@specificclick[1].txt detectado: Trace.TrackingCookie.specificclick!A2
C:\Documents and Settings\and\Cookies\and@statcounter[1].txt detectado: Trace.TrackingCookie.statcounter!A2
C:\Documents and Settings\and\Cookies\and@zedo[1].txt detectado: Trace.TrackingCookie.zedo!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253311626546875 detectado: Trace.TrackingCookie.doubleclick.net!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253311626734381 detectado: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253311626734382 detectado: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253311626734383 detectado: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253311875421875 detectado: Trace.TrackingCookie.adserv!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312859656250 detectado: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312864609375 detectado: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312865843750 detectado: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312866375001 detectado: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312867031250 detectado: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312870390625 detectado: Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253318753015627 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253318753015629 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253404104390625 detectado: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253404104390626 detectado: Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428676171875 detectado: Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428676171876 detectado: Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428676171877 detectado: Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428676171878 detectado: Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428676171879 detectado: Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428693656251 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428693656253 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428767781252 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428773156250 detectado: Trace.TrackingCookie.be.sitestat.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428773156251 detectado: Trace.TrackingCookie.be.sitestat.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253429378953125 detectado: Trace.TrackingCookie.m.webtrends.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253454777875001 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253463269750000 detectado: Trace.TrackingCookie.adbrite.com!A2
C:\Arquivos de programas\Messenger Plus! Live\MPTools.exe detectado: Virus.Win32.Sality!IK
C:\Arquivos de programas\Steam\steamapps\hishi601\counter-strike\hl.exe detectado: Virus.Win32.Sality!IK
C:\Arquivos de programas\Valve\hl.exe detectado: Virus.Win32.Sality!IK
C:\Arquivos de programas\Valve\Steam.dll detectado: Riskware.Hacktool.No-Steam!IK
C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\Cache\429CEBD0d01/Sality_off.exe detectado: Trojan.Generic!IK
C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7\kav8.0.0.506pb.exe detectado: Virus.Win32.Sality!IK
C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7\RealPlayer11GOLD_br.exe detectado: Virus.Win32.Sality!IK
C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7\Total_video_convert_3.10_en_su_version_portable_by_Madestro.exe detectado: Trojan.Win32.AutoHK!IK
C:\Documents and Settings\and\Desktop\sality_off.zip/Sality_off.exe detectado: Trojan.Generic!IK
C:\Documents and Settings\and\Meus documentos\Meus arquivos recebidos\sality_off.zip/Sality_off.exe detectado: Trojan.Generic!IK
C:\FindyKill\Tools\winupgro.exe detectado: Trojan-Downloader.Win32.QQHelper!IK
C:\Qoobox\Quarantine\C\autorun.inf.vir detectado: Trojan.Win32.VB!IK
C:\Qoobox\Quarantine\D\autorun.inf.vir detectado: Trojan.Win32.VB!IK
C:\Sality_off.exe detectado: Trojan.Generic!IK
C:\WINDOWS\system32\config\systemprofile\7zS7B7.tmp\RAR.EXE detectado: Riskware.Crack.WinRAR!IK
C:\WINDOWS\system32\notepad.exe detectado: Virus.W32.Sality!IK
D:\anderson arquivos\anderson arquivos\doc\aknust\arquivos\arq winrar\Vertus_Fluid_Mask_v3.0.8-WWW.HOAXFREE.COM.rar/FluidMask3.exe detectado: Virus.Win32.Swizzor!IK
D:\anderson arquivos\anderson arquivos\doc\aknust\arquivos\arq winrar\Vertus_Fluid_Mask_v3.0.8-WWW.HOAXFREE.COM.rar/AccessControl.dll detectado: Virus.Win32.Swizzor!IK
D:\anderson arquivos\anderson arquivos\doc\aknust\emuladores & roms\Dreamcast\ChankastAlpha025\ChankastAlpha025\chankast_cdrom.dll detectado: Trojan.Win32.Vapsup.uvu!A2
D:\anderson arquivos\anderson arquivos\doc\aknust\emuladores & roms\Dreamcast\ChankastAlpha025\ChankastAlpha025\chankast_cdrom_aspi.dll detectado: Trojan.Win32.Vapsup!IK
D:\anderson arquivos\anderson arquivos\doc\aknust\emuladores & roms\Dreamcast\ChankastAlpha025\ChankastAlpha025\chankast_input.dll detectado: Trojan.Win32.Vapsup.uvw!A2
D:\anderson arquivos\anderson arquivos\doc\aknust\emuladores & roms\Dreamcast\ChankastAlpha025\ChankastAlpha025\vmsbrowser.exe detectado: Trojan.Win32.Vapsup.uwb!A2
D:\anderson arquivos\HD 2\Meus doc\Anti virus\NOD32.rar/NOD32.FiX.v2.2-nsane.exe detectado: Virus.Win32.Trojan!IK
D:\anderson arquivos\HD 2\Meus doc\Anti virus\RemoveWGA.zip/RemoveWGA.exe detectado: Riskware.Risktool.RemoveWGA!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Driver_Genius_Professional_8.0.316.rar/keygen.exe detectado: Riskware.Keygen.drivergenius!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Nero 7\Nero KeyGen.exe detectado: Riskware.Keygen.Nero!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Pinnacle 9.3\KEYGEN\Pinnacle Studio Plus 9.3.2.48 Trial - Parisa\KeyMaker.exe detectado: Riskware.Keygen.Pinnacle!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Software\RealPlayer11GOLD_br.exe detectado: Virus.Win32.Sality!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Virtual.DJ.Studio.v5.3\keygen.exe detectado: Trojan-Downloader.Win32.Small!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\xp original\Vista+Ativador.rar/Vista key!.exe detectado: Riskware.Hacktool.Patch.vistasp1!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\xp original\WinXP_keyChanger.exe/findkey.exe detectado: Riskware.HackTool.Findkey!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\xp original\WinXP_keyChanger.exe/xpkey.exe detectado: not-a-Virus:Hacktool.Keygen.xpkeyfinder!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\xp original\WinXP_keyChanger.exe/officekey.exe detectado: Riskware.Hacktool.OfficeKey!IK
D:\anderson arquivos\HD 2\Programas\Meus documentos\Downloads\PCDJ FX VRM 7.0 + KJ PLUGIN WITH KEYGEN [markwright]\PCDJ FX VRM 7.0 + KEYGEN\pcdj fx vrm 7.0 keygen.exe detectado: Trojan.Crypt.ULPM!IK
D:\DAN ARQUIVOS\COUNTERSTRIKE\Adminmod\install_admin.vbs detectado: Virus.VBS.Zulu.d!IK
D:\DAN ARQUIVOS\COUNTERSTRIKE\Adminmod.zip/install_admin.vbs detectado: Virus.VBS.Zulu.d!IK
D:\DAN ARQUIVOS\donw dan\image141.exe.dap detectado: Trojan-Downloader.Win32.Homa!IK
D:\Meus documentos\My DAP Downloads\image141.exe.dap detectado: Trojan-Downloader.Win32.Homa!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063019.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063076.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063149.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063176.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063227.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063258.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063345.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063371.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0063408.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0063459.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0063484.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0063530.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0063556.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0064533.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0065529.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0065556.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0065616.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0065643.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065678.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065729.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065751.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065785.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065865.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065895.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94\A0065974.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94\A0065998.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94\A0066033.exe detectado: Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94\A0066212.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95\A0066322.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95\A0066413.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95\A0066462.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95\A0066518.inf detectado: Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95\A0067518.inf detectado: Trojan.Win32.VB!IK
Analisado
Arquivos: 109443
Objetos: 632927
Cookies: 515
Processos: 24
Encontrado
Arquivos: 71
Objetos: 0
Cookies: 39
Processos: 0
Chaves do registro: 0
Fim da análise: 20/9/2009 17:45:26
Duração da análise: 0:58:34
D:\DAN ARQUIVOS\donw dan\image141.exe.dap Em quarentena Trojan-Downloader.Win32.Homa!IK
D:\Meus documentos\My DAP Downloads\image141.exe.dap Em quarentena Trojan-Downloader.Win32.Homa!IK
D:\DAN ARQUIVOS\COUNTERSTRIKE\Adminmod\install_admin.vbs Em quarentena Virus.VBS.Zulu.d!IK
D:\DAN ARQUIVOS\COUNTERSTRIKE\Adminmod.zip/install_admin.vbs Em quarentena Virus.VBS.Zulu.d!IK
D:\anderson arquivos\HD 2\Programas\Meus documentos\Downloads\PCDJ FX VRM 7.0 + KJ PLUGIN WITH KEYGEN [markwright]\PCDJ FX VRM 7.0 + KEYGEN\pcdj fx vrm 7.0 keygen.exe Em quarentena Trojan.Crypt.ULPM!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\xp original\WinXP_keyChanger.exe/xpkey.exe Em quarentena not-a-Virus:Hacktool.Keygen.xpkeyfinder!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Virtual.DJ.Studio.v5.3\keygen.exe Em quarentena Trojan-Downloader.Win32.Small!IK
D:\anderson arquivos\HD 2\Meus doc\Anti virus\NOD32.rar/NOD32.FiX.v2.2-nsane.exe Em quarentena Virus.Win32.Trojan!IK
D:\anderson arquivos\anderson arquivos\doc\aknust\emuladores & roms\Dreamcast\ChankastAlpha025\ChankastAlpha025\vmsbrowser.exe Em quarentena Trojan.Win32.Vapsup.uwb!A2
D:\anderson arquivos\anderson arquivos\doc\aknust\emuladores & roms\Dreamcast\ChankastAlpha025\ChankastAlpha025\chankast_input.dll Em quarentena Trojan.Win32.Vapsup.uvw!A2
D:\anderson arquivos\anderson arquivos\doc\aknust\emuladores & roms\Dreamcast\ChankastAlpha025\ChankastAlpha025\chankast_cdrom_aspi.dll Em quarentena Trojan.Win32.Vapsup!IK
D:\anderson arquivos\anderson arquivos\doc\aknust\emuladores & roms\Dreamcast\ChankastAlpha025\ChankastAlpha025\chankast_cdrom.dll Em quarentena Trojan.Win32.Vapsup.uvu!A2
D:\anderson arquivos\anderson arquivos\doc\aknust\arquivos\arq winrar\Vertus_Fluid_Mask_v3.0.8-WWW.HOAXFREE.COM.rar/FluidMask3.exe Em quarentena Virus.Win32.Swizzor!IK
D:\anderson arquivos\anderson arquivos\doc\aknust\arquivos\arq winrar\Vertus_Fluid_Mask_v3.0.8-WWW.HOAXFREE.COM.rar/AccessControl.dll Em quarentena Virus.Win32.Swizzor!IK
C:\WINDOWS\system32\notepad.exe Em quarentena Virus.W32.Sality!IK
C:\Qoobox\Quarantine\C\autorun.inf.vir Em quarentena Trojan.Win32.VB!IK
C:\Qoobox\Quarantine\D\autorun.inf.vir Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063019.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063149.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063227.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063345.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0063408.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0063459.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0063530.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0064533.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0065529.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0065616.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065678.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065751.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065865.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94\A0065974.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94\A0065998.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94\A0066212.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95\A0066322.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95\A0066413.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95\A0066462.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95\A0066518.inf Em quarentena Trojan.Win32.VB!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP95\A0067518.inf Em quarentena Trojan.Win32.VB!IK
C:\FindyKill\Tools\winupgro.exe Em quarentena Trojan-Downloader.Win32.QQHelper!IK
C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7\Total_video_convert_3.10_en_su_version_portable_by_Madestro.exe Em quarentena Trojan.Win32.AutoHK!IK
C:\Documents and Settings\and\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\Cache\429CEBD0d01/Sality_off.exe Em quarentena Trojan.Generic!IK
C:\Documents and Settings\and\Desktop\sality_off.zip/Sality_off.exe Em quarentena Trojan.Generic!IK
C:\Documents and Settings\and\Meus documentos\Meus arquivos recebidos\sality_off.zip/Sality_off.exe Em quarentena Trojan.Generic!IK
C:\Sality_off.exe Em quarentena Trojan.Generic!IK
C:\Arquivos de programas\Messenger Plus! Live\MPTools.exe Em quarentena Virus.Win32.Sality!IK
C:\Arquivos de programas\Steam\steamapps\hishi601\counter-strike\hl.exe Em quarentena Virus.Win32.Sality!IK
C:\Arquivos de programas\Valve\hl.exe Em quarentena Virus.Win32.Sality!IK
C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7\kav8.0.0.506pb.exe Em quarentena Virus.Win32.Sality!IK
C:\Documents and Settings\and\Configurações locais\temp\091818230000038cllge3oqyg7\RealPlayer11GOLD_br.exe Em quarentena Virus.Win32.Sality!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Software\RealPlayer11GOLD_br.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063076.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063176.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063258.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP91\A0063371.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0063484.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0063556.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0065556.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP92\A0065643.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065729.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065785.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP93\A0065895.exe Em quarentena Virus.Win32.Sality!IK
D:\System Volume Information\_restore{9F0639EE-2584-42A5-AB45-44009385779D}\RP94\A0066033.exe Em quarentena Virus.Win32.Sality!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\xp original\WinXP_keyChanger.exe/officekey.exe Em quarentena Riskware.Hacktool.OfficeKey!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\xp original\WinXP_keyChanger.exe/findkey.exe Em quarentena Riskware.HackTool.Findkey!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\xp original\Vista+Ativador.rar/Vista key!.exe Em quarentena Riskware.Hacktool.Patch.vistasp1!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Pinnacle 9.3\KEYGEN\Pinnacle Studio Plus 9.3.2.48 Trial - Parisa\KeyMaker.exe Em quarentena Riskware.Keygen.Pinnacle!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Nero 7\Nero KeyGen.exe Em quarentena Riskware.Keygen.Nero!IK
D:\anderson arquivos\HD 2\Programas\DVD Anderson\Driver_Genius_Professional_8.0.316.rar/keygen.exe Em quarentena Riskware.Keygen.drivergenius!IK
D:\anderson arquivos\HD 2\Meus doc\Anti virus\RemoveWGA.zip/RemoveWGA.exe Em quarentena Riskware.Risktool.RemoveWGA!IK
C:\WINDOWS\system32\config\systemprofile\7zS7B7.tmp\RAR.EXE Em quarentena Riskware.Crack.WinRAR!IK
C:\Arquivos de programas\Valve\Steam.dll Em quarentena Riskware.Hacktool.No-Steam!IK
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253429378953125 Em quarentena Trace.TrackingCookie.m.webtrends.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428773156250 Em quarentena Trace.TrackingCookie.be.sitestat.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428773156251 Em quarentena Trace.TrackingCookie.be.sitestat.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428676171875 Em quarentena Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428676171876 Em quarentena Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428676171877 Em quarentena Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428676171878 Em quarentena Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428676171879 Em quarentena Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253463269750000 Em quarentena Trace.TrackingCookie.adbrite.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253404104390625 Em quarentena Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253404104390626 Em quarentena Trace.TrackingCookie.myspace.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253318753015627 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253318753015629 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428693656251 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428693656253 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253428767781252 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253454777875001 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312859656250 Em quarentena Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312864609375 Em quarentena Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312865843750 Em quarentena Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312866375001 Em quarentena Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312867031250 Em quarentena Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253312870390625 Em quarentena Trace.TrackingCookie.go.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253311626734381 Em quarentena Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253311626734382 Em quarentena Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253311626734383 Em quarentena Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253311626546875 Em quarentena Trace.TrackingCookie.doubleclick.net!A2
C:\Documents and Settings\and\Cookies\and@zedo[1].txt Em quarentena Trace.TrackingCookie.zedo!A2
C:\Documents and Settings\and\Cookies\and@statcounter[1].txt Em quarentena Trace.TrackingCookie.statcounter!A2
C:\Documents and Settings\and\Cookies\and@specificclick[1].txt Em quarentena Trace.TrackingCookie.specificclick!A2
C:\Documents and Settings\and\Cookies\and@ig.com[1].txt Em quarentena Trace.TrackingCookie.ig.com!A2
C:\Documents and Settings\and\Cookies\and@google.com[1].txt Em quarentena Trace.TrackingCookie.google.com!A2
C:\Documents and Settings\and\Cookies\and@google.com[2].txt Em quarentena Trace.TrackingCookie.google.com!A2
C:\Documents and Settings\and\Cookies\and@doubleclick[2].txt Em quarentena Trace.TrackingCookie.doubleclick!A2
C:\Documents and Settings\and\Cookies\and@atdmt[1].txt Em quarentena Trace.TrackingCookie.atdmt!A2
C:\Documents and Settings\and\Cookies\and@adserver.dialhost.com[2].txt Em quarentena Trace.TrackingCookie.adserv!A2
C:\Documents and Settings\and\Dados de aplicativos\Mozilla\Firefox\Profiles\9ohuzfd1.default\cookies.sqlite:1253311875421875 Em quarentena Trace.TrackingCookie.adserv!A2
Em quarentena
Arquivos: 71
Objetos: 0
Cookies: 37
ABraçoss!
Boa Noite! danmex
continuo não encontrado o arquivo AVPTool (sera q o arquivo nao foi criado pq nao terminei as vacinas daquela primeira janela q travo na hr di scaniar a memoria?)
<!> Creio que lhe devo desculpas,pois jamais você iria encontrar a pasta AVPTool,pois essa ferramenta ainda não foi lhe passada.
<><><><><><><><><><><>
<@> Baixe: < AVPTool > ( by Kaspersky Labs )
<@> Salve-o em Arquivos de Programas,e instale-o aí mesmo!
<@> Reinicie o computador,em Modo de Segurança! <-- Importante!
<@> Dê início ao exame,clicando em "Scan".
<@> A verificação é muito demorada. <-- Aguarde!
<@> Caso sejam encontradas infecções,clique em "disinfect" se a opção estiver habilitada.
<@> Ps: Para algumas detecções ( Cracks ou Keygens ),conhecidas,clique em skip.
<@> Evite,para esses casos,a opção "Delete".
<@> Terminando,clique na aba Events.
<@> Desmarque a caixa de seleção "Show all events".
<@> Clique em "Save to file".
<@> Nomeie-o e salve-o no desktop! <-- Relatório para postagem!
Abraços!
Bom dia DigRam
que isso amigo se preocupe não eu entendo seu trabalho, acontece ;)
rsrsrrsrss
aqui está o log que você pediu
Scan
----
Scanned: 588825
Detected: 0
Untreated: 0
Start time: 20/9/2009 22:46:47
Duration: 02:58:39
Finish time: 21/9/2009 01:45:26
Detected
--------
Status Object
------ ------
Events
------
Time Name Status Reason
---- ---- ------ ------
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/Ad-Aware SE Default.skn password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/arrow1.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/arrow2.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bck1.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt11.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt12.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt13.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt21.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt22.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt23.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt31.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt32.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt33.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt41.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt42.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt43.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt51.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt52.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt53.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt61.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt62.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/checkbox1.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/checkbox2.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/checkbox3.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/checkbox4.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/defbtn1.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/defbtn2.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/defbtn3.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph1.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph2.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph3.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph4.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph5.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph6.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph7.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/main.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/preview.bmp password protected
20/9/2009 23:16:46 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/sprite1.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/Ad-Aware SE Default.skn password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/arrow1.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/arrow2.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bck1.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt11.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt12.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt13.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt21.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt22.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt23.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt31.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt32.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt33.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt41.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt42.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt43.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt51.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt52.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt53.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt61.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/bt62.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/checkbox1.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/checkbox2.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/checkbox3.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/checkbox4.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/defbtn1.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/defbtn2.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/defbtn3.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph1.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph2.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph3.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph4.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph5.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph6.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/glyph7.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/main.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/preview.bmp password protected
21/9/2009 00:43:44 File: D:\anderson arquivos\HD 2\Meus doc\Anti virus\Anti trojan\aawsepersonal.exe//WISE0020.BIN/sprite1.bmp password protected
Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------
All objects 437423 0 0 0 0 14901 2490 76 5
System memory 747 0 0 0 0 1 0 0 0
Startup objects 651 0 0 0 0 0 141 0 0
Disk boot sectors 3 0 0 0 0 0 0 0 0
Meus documentos 34 0 0 0 0 0 2 0 0
Mail databases 0 0 0 0 0 0 0 0 0
Meu computador 281996 0 0 0 0 7954 1457 38 3
(C:) Disco local 53869 0 0 0 0 745 630 0 0
(D:) documentos 100123 0 0 0 0 6201 260 38 2
(E:) Unidade de CD 0 0 0 0 0 0 0 0 0
Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology No
Enable iSwift technology No
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes
Quarantine
----------
Status Object Size Added
------ ------ ---- -----
Backup
------
Status Object Size
------ ------ ----
Muito Obrigado e Abraços
Boa Tarde! danmex
<@> Baixe: < wscntfy.zip >
<@> Retire-o do zip,descompactando-o para a pasta system32.
<@> Reinicie ao concluir!
<><><><><><><><><><>
<@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /u --> Clique OK.
<@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança )
<@> Clique em Executar --> Aguarde!
<@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK.
<@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório!
<><><><><><><><><><>
<@> Copie estas informações,sob o CODE,para o Bloco de Notas.
; VArestorepolicies.inf ; Created by: miekiemoes; http://miekiemoes.blogspot.com/[Version]Signature = "$CHICAGO$"[DefaultInstall]DelReg=Removepolicies[Removepolicies]HKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",Start_ShowControlPanelHKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",StartMenuAdminToolsHKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",Start_ShowRunHKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",Start_ShowSearchHKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",Start_ShowHelpHKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",StartMenuFavoritesHKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",Start_ShowRecentDocsHKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",Start_ShowMyDocsHKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",Start_ShowMyPicsHKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",Start_ShowMyComputerHKCU,"Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced",Start_ShowMyMusicHKCU,"Software\Microsoft\Windows\CurrentVersion\Policies\Explorer",NoToolbarCustomizeHKCU,"Software\Microsoft\Windows\CurrentVersion\Policies\Explorer",NoDrivesHKCU,"Software\Microsoft\Windows\CurrentVersion\Policies\Explorer",StartMenuLogoffHKCU,"Software\Microsoft\Windows\CurrentVersion\Policies\Explorer",NoStartMenuMoreProgramsHKCU,"Software\Microsoft\Windows\CurrentVersion\Policies\Explorer",NoSetFoldersHKCU,"Software\Microsoft\Windows\CurrentVersion\Policies\System",DisableRegistryToolsHKCU,"Software\Microsoft\Windows\CurrentVersion\Policies\System",DisableTaskMgrHKCU,"Software\Microsoft\Windows\CurrentVersion\Policies\System",DisableCMDHKCU,"Software\Microsoft\Windows\CurrentVersion\Policies\System",NoDispCPLHKCU,"Software\Policies\Microsoft\Windows\System",DisableCMDHKCU,"Software\Policies\Microsoft\Internet Explorer\Restrictions",NoBrowserOptions
<@> Em "Salvar como tipo",coloque: "Todos os arquivos"
<@> Em "Nome do arquivo",digite: VArestorepolicies.inf <-- Não esqueça o ( .inf )
<@> Salve-o no desktop.
<@> Agora,siga com sua instalação!
<@> Vá ao arquivo --> Clique direito --> Instalar. <-- Clique esquerdo!
<><><><><><><><><><>
<@> Faça um escaneamento de desinfecção,em: < BitDefender >
<@> Ps: Utilize o navegador Internet Explorer!
<@> Abrirá a página: < BitDefender OnLine Scanner >
<@> Clique em: < /applications/core/interface/imageproxy/imageproxy.php?img=http://download.bitdefender.com/resources/scan8/images/agree2.gif&key=8a0323e2c684d5ae59014251de80036e265826c904a9013169d010738e2b288c" alt="agree2.gif" /> >
<@> Aguarde e aceite a instalação do ActiveX,para que possa ocorrer o scan.
<@> Terminando,poste o relatório: C:\Windows\BDOSCAN8\bdoscan.log <--
Abraços!
Bom dia DigRam
fiz todo procedimento,mas na hora de desinstalar o combofix nao pegou, ele ficou sem carregar (mais de meia hr) tentei por varias vezes o mesmo procedimento eh nada :(
mas o restante eu fiz como você pediu
aqui esta o log
bdoscan.log
[General]
App = "楂䑴晥湥敤湏楬敮匠慣湮牥 v8"
Date = 21:09:2009
Time = 21:39:54
Scan Path = C:\;D:\;E:\;
[Engines Info]
Virus Definitions = 4245212
Engine build = "AVCORE v2.1 Windows/i386 11.0.0.26 (Aug 27 2009)"
Scan plugins = 17
Archive plugins = 44
Unpack plugins = 8
E-mail plugins = 6
System plugins = 4
[scan Statistics]
Folders = 4124
Files = 242990
Archives = 10831
Packed files = 18496
Identified viruses = 6
Infected files = 10
Warnings = 0
Suspect files = 0
Disinfected files = 0
Deleted files = 10
Copied files = 0
Moved files = 0
Renamed files = 0
I/O Errors = 29
[scan Settings]
SecondAction = Delete
FirstAction = Disinfect
Heuristics = 1
Enable Warnings = 1
Exclude Ext =
Extensions = *;
Scan Emails = 1
Scan Archives = 1
Scan Packed = 1
Scan Files = 1
Scan Boot = 1
Verify Memory = 0
[scan Results]
Line00000028 = "C:\Arquivos de programas\Valve\Steam.dll Infected with: Trojan.Generic.IS.581108"
Line00000027 = "C:\Arquivos de programas\Valve\Steam.dll Deleted"
Line00000026 = "C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP3\A0000035.exe Infected with: Trojan.Generic.1065512"
Line00000025 = "C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP3\A0000035.exe Deleted"
Line00000024 = "C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP3\A0000045.dll Infected with: Trojan.Generic.IS.581108"
Line00000023 = "C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP3\A0000045.dll Deleted"
Line00000022 = "C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP6\A0000343.exe=>(Instyler o)=>(Instyler Module 9) Infected with: Trojan.Generic.IS.581108"
Line00000021 = "C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP6\A0000343.exe=>(Instyler o)=>(Instyler Module 9) Deleted"
Line00000020 = "C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP6\A0000343.exe=>(Instyler o) Update failed"
Line00000019 = "C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP6\A0000346.dll Infected with: Trojan.Generic.IS.581108"
Line00000018 = "C:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP6\A0000346.dll Deleted"
Line00000017 = "D:\anderson arquivos\HD 2\Programas\DVD Anderson\winxpportable-www.DownGratis.com.rar=>Extra.Small.Windows.XP.USB.Flash.Edition.iso=>I386/SYSTEM32/ACLUI.DLL Infected with: Trojan.Generic.1618691"
Line00000016 = "D:\anderson arquivos\HD 2\Programas\DVD Anderson\winxpportable-www.DownGratis.com.rar=>Extra.Small.Windows.XP.USB.Flash.Edition.iso=>I386/SYSTEM32/ACLUI.DLL Deleted"
Line00000015 = "D:\anderson arquivos\HD 2\Programas\DVD Anderson\winxpportable-www.DownGratis.com.rar=>Extra.Small.Windows.XP.USB.Flash.Edition.iso Update failed"
Line00000014 = "D:\anderson arquivos\HD 2\Programas\DVD Anderson\winxpportable-www.DownGratis.com.rar=>Extra.Small.Windows.XP.USB.Flash.Edition.iso=>I386/SYSTEM32/CLB.DLL Infected with: Gen:Trojan.Heur.amSfyeNTQWdi"
Line00000013 = "D:\anderson arquivos\HD 2\Programas\DVD Anderson\winxpportable-www.DownGratis.com.rar=>Extra.Small.Windows.XP.USB.Flash.Edition.iso=>I386/SYSTEM32/CLB.DLL Disinfection failed"
Line00000012 = "D:\anderson arquivos\HD 2\Programas\DVD Anderson\winxpportable-www.DownGratis.com.rar=>Extra.Small.Windows.XP.USB.Flash.Edition.iso=>I386/SYSTEM32/CLB.DLL Deleted"
Line00000011 = "D:\anderson arquivos\HD 2\Programas\DVD Anderson\winxpportable-www.DownGratis.com.rar=>Extra.Small.Windows.XP.USB.Flash.Edition.iso Update failed"
Line00000010 = "D:\DAN ARQUIVOS\donw dan\Adobe Page Maker 7.01.rar=>Adobe Page Maker 7.01\PM7ext.exe Infected with: Gen:Trojan.Heur.YmJerXA@ughIC"
Line00000009 = "D:\DAN ARQUIVOS\donw dan\Adobe Page Maker 7.01.rar=>Adobe Page Maker 7.01\PM7ext.exe Disinfection failed"
Line00000008 = "D:\DAN ARQUIVOS\donw dan\Adobe Page Maker 7.01.rar=>Adobe Page Maker 7.01\PM7ext.exe Deleted"
Line00000007 = "D:\DAN ARQUIVOS\donw dan\Adobe Page Maker 7.01.rar Update failed"
Line00000006 = "D:\Meus documentos\My DAP Downloads\Adobe Page Maker 7.01.rar=>Adobe Page Maker 7.01\PM7ext.exe Infected with: Gen:Trojan.Heur.YmJerXA@ughIC"
Line00000005 = "D:\Meus documentos\My DAP Downloads\Adobe Page Maker 7.01.rar=>Adobe Page Maker 7.01\PM7ext.exe Disinfection failed"
Line00000004 = "D:\Meus documentos\My DAP Downloads\Adobe Page Maker 7.01.rar=>Adobe Page Maker 7.01\PM7ext.exe Deleted"
Line00000003 = "D:\Meus documentos\My DAP Downloads\Adobe Page Maker 7.01.rar Update failed"
Line00000002 = "D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP3\A0000027.exe Detected with: Application.Findkeyxp.F"
Line00000001 = "D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP3\A0000027.exe Disinfection failed"
Line00000000 = "D:\System Volume Information\_restore{4B61B3AB-368B-4D63-8634-B220CCAD1557}\RP3\A0000027.exe Deleted"
ABRAÇOS..
PS : me avise se eu puder excluir ou remover otros programas (e logs) q você mandou eu baixar, ou posso fazer isso so quando resolver o problema? ou alguns deles podem me ser uteis para a vida do pc?
Bom Dia! danmex
fiz todo procedimento,mas na hora de desinstalar o combofix nao pegou, ele ficou sem carregar (mais de meia hr) tentei por varias vezes o mesmo procedimento eh nada
<!> Será desinstalado por outro(s) procedimento. ( ToolsCleaner )
PS : me avise se eu puder excluir ou remover otros programas (e logs) q você mandou eu baixar, ou posso fazer isso so quando resolver o problema? ou alguns deles podem me ser uteis para a vida do pc?
<!> Fique,somente,com a-squared e desinstale Ad-Aware.
<!> Ps: A ferramenta AVPTool indica apenas,verificações em sua unidade D:\. Instale-a em C:\ e repita seu scan,alterando sua configuração em Settings. <-- Change settings
<!> Ps: Busque habilitar,somente,a desinfecção de arquivos. ( disinfect )
<!> Terminando a configuração,dê prosseguimento ao scan.
<!> Ao concluir,poste o relatório.
<><><><><><><><><><>
<@> Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://img48.imageshack.us/img48/4476/imagemus0.jpg&key=ea7bc0c907a5e38f00e266b145e5f02b8cabf695069b6fc4c1bd4f227ed49071" alt="imagemus0.jpg" /> > (...par A.Rothstein & dj Quiou )
<@> Salve-o no desktop!
<@> Feche programas que estejam abertos,e execute a ferramenta.
<@> Clique no botão Recherche,para iniciar o scan. <-- Aguarde!
<@> Terminando,teremos relacionados os itens que serão removidos.
<@> Clique no botão Supression para remover os itens encontrados.
<@> Clique,à seguir,em Quitter.
<@> Poste o relatório: ( C:\TCleaner.txt ) <--
<><><><><><><><><><>
<@> Baixe: < msconfig.zip >
<@> Descompacte-o para o diretório: C:\WINDOWS\pchealth\helpctr\binaries <--
<><><><><><><><><><>
<@> Baixe: < Runscanner v. 1.8.0.0 >
<@> Salve-o no Disco local(C) ou Desktop.
<@> Descompacte-o e reserve o executável. ( RunScanner.exe )
<@> Abra o programa e,com o botão Expert mode já marcado,clique Ok.
<@> Feche todas as janelas/programas,antes de executar este utilitário.
<@> Rode-o,clicando em Scan computer. --> Aguarde!
<@> Terminando,clique no menu: "Online analysis" <-- Esteja conectado!
<@> Abrirá a página: "online malware analysis report"
<@> Copie o resultado desta análise;Report Url:,para o seu computador. ( report.aspx )
<@> Coloque-o em um zip,dispondo-o no Desktop.
<@> Mantenha a extenção ( .aspx ),ao copiá-lo!
<@> Não desejando a verificação OnLine,salve-o como Arquivo RUN.
<@> Execute-o e,ao terminar,clique em "Save Run File" --> Coloque-o em um zip,dispondo-o na área de trabalho.
<@> Vá,agora,à este endereço: < Badongo >
<@> Faça upload do report.aspx.zip ou runscanner.run,que estão no desktop,para esse servidor. <-- Badongo!
<@> Copie o(s) endereço(s),que lhe serão fornecidos,para este Tópico. ( Report Url: ) ou ( Arquivo RUN )
Abraços!
Bom dia DigRam..
Bom esse foi o processo mais dificil que ja fiz, nao sei se fiz correto
mas vo postar o que consegui fazer
aqui vão os relatorios..
relátorio do AVPTOOL
Scan
----
Scanned: 52857
Detected: 0
Untreated: 0
Start time: 22/9/2009 19:35:53
Duration: 00:23:24
Finish time: 22/9/2009 19:59:17
Detected
--------
Status Object
------ ------
Events
------
Time Name Status Reason
---- ---- ------ ------
Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------
All objects 52857 0 0 0 0 615 428 0 0
(C:) Disco local 52857 0 0 0 0 615 428 0 0
Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Disinfect, do not delete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology Yes
Enable iSwift technology Yes
Show detected threats on "Detected" tab Yes
Rootkits search Yes
Deep rootkits search No
Use heuristic analyzer Yes
Quarantine
----------
Status Object Size Added
------ ------ ---- -----
Backup
------
Status Object Size
------ ------ ----
TCleaner.txt
[ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]
--> Recherche:
C:\HijackThis.exe: trouvé !
C:\hijackthis.log: trouvé !
C:\FindyKill.txt: trouvé !
C:\Qoobox: trouvé !
C:\FindyKill: trouvé !
C:\Documents and Settings\and\Desktop\ComboFix.exe: trouvé !
C:\Qoobox\Quarantine\catchme.log: trouvé !
---------------------------------
--> Suppression:
C:\HijackThis.exe: supprimé !
C:\Documents and Settings\and\Desktop\ComboFix.exe: supprimé !
C:\hijackthis.log: supprimé !
C:\FindyKill.txt: supprimé !
C:\Qoobox\Quarantine\catchme.log: supprimé !
C:\Qoobox: supprimé !
C:\FindyKill: supprimé !
eh aqui estão os 2 endereços que você pediu (essa parte eu nao sei se fiz correto =/)
report.aspx.zip
http://www.badongo.com/file/17373091
runscanner0.zip
http://www.badongo.com/file/17373132
OBS: por via das duvidas vo postar um log do runscanner
runscanner.log
Runscanner logfile
* = signed file
General info
------------
Computer name : CASA
Creation time : 23/9/2009 02:50:43
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 6.0.2900.5512
OS : Microsoft Windows XP
OS Build : 2600
OS SP : Service Pack 3
RunScanner Version : 1.9.0.9
User Language : Português (Brasil)
User rights : Administrator
Windows folder : C:\WINDOWS
Running processes
-----------------
* C:\WINDOWS\system32\winlogon.exe (Microsoft Corporation)
* C:\WINDOWS\system32\services.exe (Microsoft Corporation)
C:\Arquivos de programas\a-squared Free\a2service.exe (Emsi Software GmbH)
* C:\WINDOWS\system32\csrss.exe (Microsoft Corporation)
* C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
* C:\WINDOWS\system32\RUNDLL32.EXE (Microsoft Corporation)
* C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* c:\windows\System32\smss.exe (Microsoft Corporation)
* C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
* C:\Documents and Settings\and\Desktop\RunScanner.exe (Runscanner.net)
* C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation)
* C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
* C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe (Microsoft Corporation)
Unrated items
-------------
002 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
002 C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
002 C:\WINDOWS\system32\NvCpl.dll (NVIDIA Corporation)
002 C:\WINDOWS\system32\NvMcTray.dll (NVIDIA Corporation)
002 C:\WINDOWS\system32\nwiz.exe
002 C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
003 C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe (Microsoft Corporation)
004 C:\ARQUIV~1\VIRUSR~1\is-UBM6P\startup.exe
010 C:\Arquivos de programas\a-squared Free\a2service.exe (a-squared Free Service)
010 C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Display Driver Service)
011 * C:\WINDOWS\system32\DRIVERS\65670948.sys (is-UBM6Pdrv)
011 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (nv)
011 C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Service for Realtek AC97 Audio (WDM))
011 C:\WINDOWS\System32\Drivers\TP6800.sys (USB Video Camera)
011 C:\WINDOWS\system32\DRIVERS\ViPrt.sys (VIA SATA IDE Device Driver)
011 C:\WINDOWS\system32\DRIVERS\ViBus.sys (ViBus)
035 C:\WINDOWS\system32\ieudinit.exe (Microsoft Corporation) <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
042 C:\WINDOWS\bdoscandel.exe {85d1f590-48f4-11d9-9669-0800200c9a66}
042 C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) {e2e2dd38-d088-4134-82b7-f2ba38496583}
052 GUID / CLSID not found {5C255C8A-E604-49b4-9D64-90988571CECB}
061 C:\Arquivos de programas\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}
061 C:\WINDOWS\system32\nvshell.dll {1CDB2949-8F65-4355-8456-263E7C208A5D}
061 C:\WINDOWS\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A47}
061 C:\WINDOWS\system32\nvcpl.dll (NVIDIA Corporation) {A70C977A-BF00-412C-90B7-034C51DA2439}
061 C:\WINDOWS\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A48}
061 C:\WINDOWS\system32\nvcpl.dll (NVIDIA Corporation) {FFB699E0-306A-11d3-8BD1-00104B6F7516}
061 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
069 C:\WINDOWS\system32\hpzsnt10.dll (HP)
104 C:\WINDOWS\DOWNLO~1\oscan82.ocx (BitDefender) {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
105 E&xportar para o Microsoft Excel : res://C:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
120 NameServer {300EDF33-DB30-43FA-AC3E-CF080FC6BB5F} : 200.165.132.154
170 {066e2da5-a482-11de-8e1e-0016ec4b124b} : F:\chyw.exe
173 GUID / CLSID not found
173 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
221 GUID / CLSID not found
221 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
223 C:\Arquivos de programas\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}
225 C:\Arquivos de programas\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}
225 C:\Arquivos de programas\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}
225 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
227 GUID / CLSID not found
227 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
229 C:\WINDOWS\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A48}
229 C:\WINDOWS\system32\nvcpl.dll (NVIDIA Corporation) {A70C977A-BF00-412C-90B7-034C51DA2439}
251 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Missing files
-------------
011 C:\WINDOWS\system32\drivers\Abiosdsk.sys
011 C:\WINDOWS\system32\drivers\abp480n5.sys
011 C:\WINDOWS\system32\drivers\adpu160m.sys
011 C:\WINDOWS\system32\drivers\Aha154x.sys
011 C:\WINDOWS\system32\drivers\aic78u2.sys
011 C:\WINDOWS\system32\drivers\aic78xx.sys
011 C:\WINDOWS\system32\drivers\AliIde.sys
011 C:\WINDOWS\system32\drivers\amsint.sys
011 C:\WINDOWS\system32\drivers\asc.sys
011 C:\WINDOWS\system32\drivers\asc3350p.sys
011 C:\WINDOWS\system32\drivers\asc3550.sys
011 C:\WINDOWS\system32\drivers\Atdisk.sys
011 C:\ComboFix\catchme.sys
011 C:\WINDOWS\system32\drivers\cd20xrnt.sys
011 C:\WINDOWS\system32\drivers\Changer.sys
011 C:\WINDOWS\system32\drivers\CmdIde.sys
011 C:\WINDOWS\system32\drivers\Cpqarray.sys
011 C:\WINDOWS\system32\drivers\dac2w2k.sys
011 C:\WINDOWS\system32\drivers\dac960nt.sys
011 C:\WINDOWS\system32\drivers\dpti2o.sys
011 C:\WINDOWS\system32\drivers\hpn.sys
011 C:\WINDOWS\system32\drivers\i2omgmt.sys
011 C:\WINDOWS\system32\drivers\i2omp.sys
011 C:\WINDOWS\system32\drivers\ini910u.sys
011 C:\WINDOWS\system32\drivers\IntelIde.sys
011 C:\WINDOWS\system32\drivers\lbrtfdc.sys
011 C:\WINDOWS\system32\drivers\mraid35x.sys
011 C:\WINDOWS\system32\drivers\PCIDump.sys
011 C:\WINDOWS\system32\drivers\PDCOMP.sys
011 C:\WINDOWS\system32\drivers\PDFRAME.sys
011 C:\WINDOWS\system32\drivers\PDRELI.sys
011 C:\WINDOWS\system32\drivers\PDRFRAME.sys
011 C:\WINDOWS\system32\drivers\perc2.sys
011 C:\WINDOWS\system32\drivers\perc2hib.sys
011 C:\WINDOWS\system32\drivers\ql1080.sys
011 C:\WINDOWS\system32\drivers\Ql10wnt.sys
011 C:\WINDOWS\system32\drivers\ql12160.sys
011 C:\WINDOWS\system32\drivers\ql1240.sys
011 C:\WINDOWS\system32\drivers\ql1280.sys
011 C:\WINDOWS\system32\drivers\Simbad.sys
011 C:\WINDOWS\system32\drivers\Sparrow.sys
011 C:\WINDOWS\system32\drivers\sym_hi.sys
011 C:\WINDOWS\system32\drivers\sym_u3.sys
011 C:\WINDOWS\system32\drivers\symc810.sys
011 C:\WINDOWS\system32\drivers\symc8xx.sys
011 C:\WINDOWS\system32\drivers\TosIde.sys
011 C:\WINDOWS\system32\drivers\ultra.sys
011 C:\WINDOWS\system32\drivers\WDICA.sys
052 C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
061 deskpan.dll
214
Obrigado e Abraços
Bom Dia! danmex
Bom esse foi o processo mais dificil que ja fiz, nao sei se fiz corretomas vo postar o que consegui fazer
<!> Até agora,voçê foi o 2° usuário à cumprir corretamente,a postagem do arquivo RUN.
<!> Vai aqui o link,para efeito de pesquisas,ao report.aspx: < http://www.runscanner.net/report.aspx?report=f0b491a3-6cee-4533-b87e-20d539c5c38b >
OBS: por via das duvidas vo postar um log do runscanner
<!> :thumbsup: :thumbsup: Os emoticons já dizem tudo!! Pois permitiu-me editar procedimentos seguros de remoções. Aonde,tudo que estiver assinalado em vermelho,será removido.
<!> Já os que estão destacados na cor laranja,pedem seus arquivos. Principalmente,os que fazem parte do sistema. ( Windows )
<!> Ps: O fileinfector,corrompeu serviços essenciais,que deverão ser reparados. ( BITS/WUAUSERV )
<><><><><><><><><><>
<@> Reinicie em Modo de Segurança.
<@> Escolha,para algumas alterações,a conta Administrador.
<@> Vá em Iniciar --> Executar --> Digite: regedit --> OK.
<@> Estando no "Editor do Registro",navegue até a chave: HKey_Local_Machine --> System --> CurrentControlSet --> Services
<@> Altere as permissões,para Administrador,em "Bits" e "Wuauserv".
<@> Permita "Controle total" e "Leitura",para os mesmos,incluindo a subchave "Parâmetros".
<@> Altere os valores: "%fystemroot%" para "%SystemRoot%"
<@> Salve essas alterações e reinicie o computador!
Item: 010 HKLM\SYSTEM\CurrentControlSet\Services (Services)Description: Serviço de transferência inteligente de plano de fundo
Path: %fystemRoot%\system32\svchost.exe
MD5: File not found
FileDescription: svchost.exe
Registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS
Certificate: File not found
Item: 010 HKLM\SYSTEM\CurrentControlSet\Services (Services)
Description: Atualizações Automáticas
Path: %fystemroot%\system32\svchost.exe
MD5: File not found
FileDescription: svchost.exe
Registry path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv
Certificate: File not found
.....................................
.....................................
<@> Àcima,temos indicações das corrupções sofridas por BITS e WUAUSERV.
<@> Caso não tenha êxito,no reparo,pode incluí-los nas remoções.
<><><><><><><><><><>
<@> Execute,novamente,RunScanner.
<@> Clique,com o direito do Mouse,nas linhas destacadas em vermelho.
<@> Clique em: Mark/unmark item Space
<@> Clique na aba: Item fixer --> Fix selected items.
<@> Na mensagem,dê o OK.
<@> Em Information,confirme!
<@> Clique em Unrated items,para confirmar-mos as remoções efetuadas.
<@> Ps: Se optar pela remoção das linhas que indicam serviços/drivers,tenha em mãos o CD do Windows,para o devido reparo.
<@> Poste,após os procedimentos: runscanner.run <-- Arquivo RUN.
Abraços!
Bom dia DigRam..
primeiramente gostaria de lhe informar que esse processo aqui :
"<@> Reinicie em Modo de Segurança.
<@> Escolha,para algumas alterações,a conta Administrador.
<@> Vá em Iniciar --> Executar --> Digite: regedit --> OK.
<@> Estando no "Editor do Registro",navegue até a chave: HKey_Local_Machine --> System --> CurrentControlSet --> Services
<@> Altere as permissões,para Administrador,em "Bits" e "Wuauserv".
<@> Permita "Controle total" e "Leitura",para os mesmos,incluindo a subchave "Parâmetros".
<@> Altere os valores: "%fystemroot%" para "%SystemRoot%"
<@> Salve essas alterações e reinicie o computador!"
entrei no modo seguro > administrador..
fui conferir no meu pc eh ja estava tudo OK
estava tudo marcado ja, e o ""%SystemRoot%" ja estava la tambem..
EH AQUI está a URL que você pediu
runscanner.run
http://www.badongo.com/file/17395260
eh aqui vai o log..
Runscanner logfile
* = signed file
General info
------------
Computer name : CASA
Creation time : 24/9/2009 03:03:40
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 7.0.5730.13
OS : Microsoft Windows XP
OS Build : 2600
OS SP : Service Pack 3
RunScanner Version : 1.9.0.9
User Language : Português (Brasil)
User rights : Administrator
Windows folder : C:\WINDOWS
Running processes
-----------------
* C:\WINDOWS\system32\winlogon.exe (Microsoft Corporation)
* C:\WINDOWS\system32\services.exe (Microsoft Corporation)
C:\Arquivos de programas\a-squared Free\a2service.exe (Emsi Software GmbH)
* C:\WINDOWS\system32\csrss.exe (Microsoft Corporation)
* C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
* C:\WINDOWS\system32\RUNDLL32.EXE (Microsoft Corporation)
* C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* c:\windows\System32\smss.exe (Microsoft Corporation)
* C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
* C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
* C:\Documents and Settings\and\Desktop\RunScanner.exe (Runscanner.net)
* C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation)
* C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe (Microsoft Corporation)
* C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
Unrated items
-------------
002 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
002 C:\WINDOWS\system32\NvCpl.dll (NVIDIA Corporation)
002 C:\WINDOWS\system32\NvMcTray.dll (NVIDIA Corporation)
002 C:\WINDOWS\system32\nwiz.exe
002 C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
003 C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe (Microsoft Corporation)
004 C:\ARQUIV~1\VIRUSR~1\is-UBM6P\startup.exe
010 C:\Arquivos de programas\a-squared Free\a2service.exe (a-squared Free Service)
010 C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Display Driver Service)
011 * C:\WINDOWS\system32\DRIVERS\65670948.sys (is-UBM6Pdrv)
011 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (nv)
011 C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Service for Realtek AC97 Audio (WDM))
011 C:\WINDOWS\System32\Drivers\TP6800.sys (USB Video Camera)
011 C:\WINDOWS\system32\DRIVERS\ViPrt.sys (VIA SATA IDE Device Driver)
011 C:\WINDOWS\system32\DRIVERS\ViBus.sys (ViBus)
042 C:\WINDOWS\bdoscandel.exe {85d1f590-48f4-11d9-9669-0800200c9a66}
042 C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation) {e2e2dd38-d088-4134-82b7-f2ba38496583}
061 C:\Arquivos de programas\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}
061 C:\WINDOWS\system32\nvshell.dll {1CDB2949-8F65-4355-8456-263E7C208A5D}
061 C:\WINDOWS\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A47}
061 C:\WINDOWS\system32\nvcpl.dll (NVIDIA Corporation) {A70C977A-BF00-412C-90B7-034C51DA2439}
061 C:\WINDOWS\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A48}
061 C:\WINDOWS\system32\nvcpl.dll (NVIDIA Corporation) {FFB699E0-306A-11d3-8BD1-00104B6F7516}
061 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
069 C:\WINDOWS\system32\hpzsnt10.dll (HP)
104 C:\WINDOWS\DOWNLO~1\oscan82.ocx (BitDefender) {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
105 E&xportar para o Microsoft Excel : res://C:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
120 NameServer {300EDF33-DB30-43FA-AC3E-CF080FC6BB5F} : 200.165.132.154
170 {066e2da5-a482-11de-8e1e-0016ec4b124b} : F:\chyw.exe
173 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
221 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
223 C:\Arquivos de programas\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}
225 C:\Arquivos de programas\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}
225 C:\Arquivos de programas\a-squared Free\a2freecontmenu.dll (Emsi Software GmbH) {A155339D-CCCD-4714-85EB-3754B804C9DF}
225 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
227 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
229 C:\WINDOWS\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A48}
229 C:\WINDOWS\system32\nvcpl.dll (NVIDIA Corporation) {A70C977A-BF00-412C-90B7-034C51DA2439}
251 C:\Arquivos de programas\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Missing files
-------------
011 C:\WINDOWS\system32\drivers\Abiosdsk.sys
011 C:\WINDOWS\system32\drivers\abp480n5.sys
011 C:\WINDOWS\system32\drivers\adpu160m.sys
011 C:\WINDOWS\system32\drivers\Aha154x.sys
011 C:\WINDOWS\system32\drivers\aic78u2.sys
011 C:\WINDOWS\system32\drivers\aic78xx.sys
011 C:\WINDOWS\system32\drivers\AliIde.sys
011 C:\WINDOWS\system32\drivers\amsint.sys
011 C:\WINDOWS\system32\drivers\asc.sys
011 C:\WINDOWS\system32\drivers\asc3350p.sys
011 C:\WINDOWS\system32\drivers\asc3550.sys
011 C:\WINDOWS\system32\drivers\Atdisk.sys
011 C:\WINDOWS\system32\drivers\cd20xrnt.sys
011 C:\WINDOWS\system32\drivers\CmdIde.sys
011 C:\WINDOWS\system32\drivers\Cpqarray.sys
011 C:\WINDOWS\system32\drivers\dac2w2k.sys
011 C:\WINDOWS\system32\drivers\dac960nt.sys
011 C:\WINDOWS\system32\drivers\dpti2o.sys
011 C:\WINDOWS\system32\drivers\hpn.sys
011 C:\WINDOWS\system32\drivers\i2omp.sys
011 C:\WINDOWS\system32\drivers\ini910u.sys
011 C:\WINDOWS\system32\drivers\IntelIde.sys
011 C:\WINDOWS\system32\drivers\mraid35x.sys
011 C:\WINDOWS\system32\drivers\perc2.sys
011 C:\WINDOWS\system32\drivers\perc2hib.sys
011 C:\WINDOWS\system32\drivers\ql1080.sys
011 C:\WINDOWS\system32\drivers\Ql10wnt.sys
011 C:\WINDOWS\system32\drivers\ql12160.sys
011 C:\WINDOWS\system32\drivers\ql1240.sys
011 C:\WINDOWS\system32\drivers\ql1280.sys
011 C:\WINDOWS\system32\drivers\Simbad.sys
011 C:\WINDOWS\system32\drivers\Sparrow.sys
011 C:\WINDOWS\system32\drivers\sym_hi.sys
011 C:\WINDOWS\system32\drivers\sym_u3.sys
011 C:\WINDOWS\system32\drivers\symc810.sys
011 C:\WINDOWS\system32\drivers\symc8xx.sys
011 C:\WINDOWS\system32\drivers\TosIde.sys
011 C:\WINDOWS\system32\drivers\ultra.sys
ABraços ;)
Boa Tarde! danmex
<@> Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://www.malwarebytes.org/images/marcinsig.gif&key=2c45e7fd674c4b18d376ffbe83bf82547806ac60e230409c7eb4c31999009760" alt="marcinsig.gif" /> > Malwarebytes
<@> < Link - 2 >
<@> < Link - 3 >
<@> Atualize o programa!
<@> Escolha o escaneamento Completo!
<@> Desabilite programas de proteção,ao executar o malwarebytes.
<@> Ps: Para determinadas infecções,a ferramenta pedirá reboot. <-- Confirme!
<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.
<@> Para maiores detalhes: < Link >
<@> Poste: mbam-log-2009-xx-xx (00-00-00).txt <--
<><><><><><><><><><><>
<@> Baixe: < /applications/core/interface/imageproxy/imageproxy.php?img=http://billy-oneal.com/Canned%2520Speeches/speechimages/OTL/otlDesktopIcon.png&key=1894e5d356219721410c3360cbf9af74877ae24ccc81ed88026fc2d95dd96a07" alt="otlDesktopIcon.png" /> > ( ...by OldTimer Tools )
<@> Salve-o no desktop!
/applications/core/interface/imageproxy/imageproxy.php?img=http://www.geekstogo.com/misc/guide_icons/OTLI-scan.png&key=c1c0ea9de59a575dc1bed2c1a05aea719a59b87835a783b5874a791386bbd330" alt="OTLI-scan.png" />
<@> Segundo a imagem,mude a opção em "Output" para "Minimal Output".
<@> Duplo-clique em OTL.exe --> Marque a opção "Scan All Users".
<@> Clique em: < /applications/core/interface/imageproxy/imageproxy.php?img=http://billy-oneal.com/Canned%2520Speeches/speechimages/otli2/runscanbutton.png&key=e923c4e99200b3f328913bcb139cdc3df2bca2ef774057dc8a5231d49c60a872" alt="runscanbutton.png" /> > --> Aguarde!
<@> Poste:
<1> OTL.txt <--
<2> Extra.txt <--
Abraços!