Usamos cookies para medir audiência e melhorar sua experiência. Você pode aceitar ou recusar a qualquer momento. Veja sobre o iMasters.
Olá equipe do imasters.
Há uns dias atras peguei um virus de pen drive q simplesmente transformou todas as pastas do pen drive, cartao de memoria em atalhos, e foi passando para meus outros pen driver e cartoes de memoria dos celulares. ¬¬
formatei o computador e agora quero saber como excluir o virus do pen drive sem que eu contamine o computador.
fiz um log do hijackthis so para constar, uma vez que eu ainda nao pluguei nenhum dos cartoes pen drivesLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:06:56, on 12/8/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMTray.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\uTorrent\uTorrent.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Felipe Rodrigues\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [siSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [smapp] C:\Arquivos de programas\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O23 - Service: Avira AntiVir Programador (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 5778 bytes
no pc ainda.
Agradeço desde já.
Felipe.
mais tpw ele transformou todos as pastas em tpw atalhos....
nao reconhece e nao da pra abrir.
no celular nao da pra abrir as pastas do cartao mas o reprodutor de musica do celular aida atualiza a lista e reproduz as musicas.
queria ver se tinha como salvar os arquivos pq tem fotos e talz...
antes eu formatava o cartao e voltava tudo de novo.
criava umas pastas tpw minhas musicas (atalho) minhas imagens password meus videos.
Bom...vamos ver se isso ajuda.
*Conecte o pen drive no PC, aperte e mantenha pressionada a tecla Shift até seu pendrive ser reconhecido e constar na lista do Explorer.
*Abra o prompt de comando e digite:
**attrib -h -r -s /s /d #:\*.***
Atenção: # é a unidade do seu pendrive
*Tecle [ENTER]
Veja se as pastas estão acessíveis para que você possa salvar seus arquivos.
/applications/core/interface/imageproxy/imageproxy.php?img=http://img33.imageshack.us/img33/5086/90525313.jpg&key=a4431e8500a130300b3309751c861b312143ec43d3ca08eb1944bed6129695be" alt="90525313.jpg" />
deu isso ae... do mesmo jeito q tava antes...
cliquei 2 vezes na pasta ai abriu janela do anti virus...
¬¬
*Baixe o RSIT e salve-o no desktop
*Execute o RSIT e clique em [Continue]
*Ao término do processo, cole o relatório criado em C:\rsit\log.txt
Logfile of random's system information tool 1.08 (written by random/random)
Run by Felipe Rodrigues at 2010-08-17 18:43:21
Microsoft Windows XP Professional Service Pack 3
System drive C: has 2 GB (12%) free of 20 GB
Total RAM: 512 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:43:53, on 17/8/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMTray.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\uTorrent\uTorrent.exe
C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe
C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
C:\Arquivos de programas\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Felipe Rodrigues\Desktop\RSIT.exe
C:\Arquivos de programas\trend micro\Felipe Rodrigues.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [siSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [smapp] C:\Arquivos de programas\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Arquivos de programas\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Programador (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 6200 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\User_Feed_Synchronization-{DC7CC9CB-5A25-4964-90FD-95484DD9A87E}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Auxiliar de Conexão do Windows Live - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"=C:\WINDOWS\SiSUSBrg.exe [2002-07-12 106496]
"Smapp"=C:\Arquivos de programas\Analog Devices\SoundMAX\SMTray.exe [2003-05-05 143360]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-02 13529088]
"nwiz"=nwiz.exe /install []
"avgnt"=C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-02 86016]
"Adobe Reader Speed Launcher"=C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-19 35760]
"Adobe ARM"=C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"uTorrent"=C:\Arquivos de programas\uTorrent\uTorrent.exe [2010-08-12 382840]
"msnmsgr"=C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe [2010-04-16 3872080]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-19 35760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
C:\Arquivos de programas\HP\hpcoretech\hpcmpmgr.exe [2004-05-12 241664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe [2004-02-12 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Arquivos de programas\Nero\Nero 7\InCD\InCD.exe [2007-02-12 1050112]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
C:\Arquivos de programas\Nero\Nero 7\InCD\NBHGui.exe [2007-02-12 1620480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^HP Digital Imaging Monitor.lnk]
C:\ARQUIV~1\HP\DIGITA~1\bin\hpqtra08.exe [2004-05-28 241664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Inicialização rápida do HP Image Zone.lnk]
C:\ARQUIV~1\HP\DIGITA~1\bin\hpqthb08.exe [2004-05-28 53248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Arquivos de programas\uTorrent\uTorrent.exe"="C:\Arquivos de programas\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
======List of files/folders created in the last 1 months======
2010-08-17 18:43:24 ----D---- C:\Arquivos de programas\trend micro
2010-08-17 18:43:21 ----D---- C:\rsit
2010-08-10 22:21:20 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-08-10 22:21:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-08-10 22:20:34 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-08-10 22:20:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-08-10 22:19:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2160329$
2010-08-10 22:19:21 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-08-10 22:17:19 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-08-10 22:17:03 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-08-02 21:46:21 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-08-01 23:02:35 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-08-01 23:02:24 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-07-30 20:25:38 ----A---- C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2010-07-30 20:04:26 ----A---- C:\WINDOWS\system32\MRT.exe
2010-07-30 20:04:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-07-30 20:02:40 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-07-30 20:02:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-07-30 20:02:24 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-07-30 20:02:17 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-07-30 20:02:04 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-07-30 20:01:57 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-07-30 20:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-07-30 20:01:43 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-07-30 20:01:34 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-07-30 20:01:18 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-07-30 20:01:05 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-07-30 20:00:57 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-07-30 20:00:42 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-07-30 20:00:35 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-07-30 20:00:26 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-07-30 20:00:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-07-30 20:00:04 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-07-30 19:59:54 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-07-30 19:59:42 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-07-30 19:59:24 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-07-30 19:59:15 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-07-30 19:59:04 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-07-30 19:58:54 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-07-30 19:58:44 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-07-30 19:58:36 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-07-30 19:58:28 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-07-30 19:58:17 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-07-30 19:58:10 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-07-30 19:58:03 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-07-30 19:57:54 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-07-30 19:57:50 ----D---- C:\Arquivos de programas\MSXML 4.0
2010-07-30 19:57:39 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-07-30 19:57:34 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-07-30 19:57:27 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-07-30 19:57:22 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-07-30 19:57:16 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-07-30 19:57:11 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-07-30 19:57:06 ----D---- C:\WINDOWS\ie8updates
2010-07-30 19:57:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-07-30 19:56:55 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-07-30 19:56:49 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-07-30 19:56:43 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-07-30 19:56:38 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-07-30 19:56:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-07-30 19:56:24 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-07-30 19:56:12 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-07-30 19:56:04 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-07-30 19:55:56 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-07-30 19:54:28 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2010-07-30 19:54:19 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-07-30 19:54:11 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-07-30 19:53:59 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-07-30 19:53:39 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-07-30 19:53:26 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-07-30 19:50:39 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-07-30 19:50:29 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-07-30 19:50:20 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-07-30 19:50:11 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-07-30 19:50:02 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-07-30 19:49:53 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-07-30 19:49:44 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-07-30 19:49:36 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2010-07-30 19:49:29 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-07-30 19:49:23 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-07-30 19:49:16 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-07-30 19:49:09 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-07-30 19:49:01 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-07-30 19:48:42 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2010-07-30 19:48:22 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-07-30 19:48:13 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-07-30 19:48:03 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-07-30 19:47:57 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-07-30 19:47:48 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-07-30 19:47:32 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-07-30 09:01:54 ----D---- C:\WINDOWS\Minidump
2010-07-29 11:15:16 ----D---- C:\The Book Of Eli.2010.BdRip.Xvid {1337x}-Noir
2010-07-28 19:20:44 ----D---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\Real
2010-07-28 14:10:05 ----A---- C:\WINDOWS\ModemLog_HUAWEI Mobile Connect - 3G Modem.txt
2010-07-28 14:08:04 ----D---- C:\Arquivos de programas\Claro
2010-07-28 10:56:21 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2010-07-28 10:56:05 ----A---- C:\WINDOWS\system32\drivers\hidusb.sys
2010-07-27 14:00:15 ----N---- C:\WINDOWS\system32\drivers\bthport.sys
2010-07-27 13:18:54 ----D---- C:\WINDOWS\pss
2010-07-27 01:10:54 ----D---- C:\WINDOWS\system32\PreInstall
2010-07-27 01:10:52 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-07-27 01:10:52 ----HD---- C:\WINDOWS\$hf_mig$
2010-07-26 21:37:38 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-07-26 21:08:27 ----A---- C:\WINDOWS\NeroDigital.ini
2010-07-26 21:08:20 ----D---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\Media Player Classic
2010-07-26 20:17:58 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2010-07-26 19:24:15 ----SHD---- C:\RECYCLER
2010-07-26 18:11:28 ----D---- C:\Arquivos de programas\PluginLetras
2010-07-26 18:02:48 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus!
2010-07-26 18:02:28 ----D---- C:\Arquivos de programas\Messenger Plus! Live
2010-07-26 18:00:55 ----D---- C:\Arquivos de programas\Microsoft
2010-07-26 18:00:35 ----D---- C:\Arquivos de programas\Windows Live SkyDrive
2010-07-26 18:00:09 ----D---- C:\Arquivos de programas\Windows Live
2010-07-26 17:46:03 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-07-26 17:45:58 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2010-07-26 17:45:45 ----D---- C:\Arquivos de programas\Windows Media Connect 2
2010-07-26 17:45:34 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2010-07-26 17:44:57 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-07-26 17:44:35 ----D---- C:\WINDOWS\system32\LogFiles
2010-07-26 17:44:35 ----D---- C:\WINDOWS\system32\drivers\UMDF
2010-07-26 17:44:26 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-07-26 17:43:51 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Windows Genuine Advantage
2010-07-26 17:43:07 ----D---- C:\Arquivos de programas\uTorrent
2010-07-26 17:41:53 ----D---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\uTorrent
2010-07-26 17:37:51 ----D---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\Ahead
2010-07-26 17:36:32 ----D---- C:\Arquivos de programas\Arquivos comuns\Windows Live
2010-07-26 17:36:18 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Nero
2010-07-26 17:36:17 ----D---- C:\Arquivos de programas\Nero
2010-07-26 17:36:17 ----D---- C:\Arquivos de programas\Arquivos comuns\Ahead
2010-07-26 17:35:32 ----D---- C:\WINDOWS\RegisteredPackages
2010-07-26 17:34:23 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Adobe
2010-07-26 17:33:34 ----D---- C:\Arquivos de programas\Arquivos comuns\Adobe
2010-07-26 17:33:34 ----D---- C:\Arquivos de programas\Adobe
2010-07-26 17:17:45 ----D---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\WinRAR
2010-07-26 17:16:29 ----D---- C:\Arquivos de programas\WinRAR
2010-07-26 17:13:34 ----D---- C:\WINDOWS\WBEM
2010-07-26 17:12:56 ----D---- C:\WINDOWS\nvidia icons
2010-07-26 17:12:42 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-07-26 17:11:06 ----D---- C:\Arquivos de programas\Google
2010-07-26 17:10:57 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2010-07-26 17:10:42 ----HDC---- C:\WINDOWS\ie8
2010-07-26 17:10:33 ----D---- C:\Arquivos de programas\Arquivos comuns\HP
2010-07-26 17:08:47 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Hewlett-Packard
2010-07-26 17:08:47 ----D---- C:\Arquivos de programas\Hewlett-Packard
2010-07-26 17:08:41 ----RA---- C:\WINDOWS\system32\MSXML4r.dll
2010-07-26 17:08:41 ----RA---- C:\WINDOWS\system32\MSXML4a.dll
2010-07-26 17:08:41 ----RA---- C:\WINDOWS\system32\hpvcr70.dll
2010-07-26 17:08:41 ----RA---- C:\WINDOWS\system32\hpvcp70.dll
2010-07-26 17:08:41 ----RA---- C:\WINDOWS\system32\hpvaut32.dll
2010-07-26 17:07:46 ----D---- C:\Arquivos de programas\Arquivos comuns\Hewlett-Packard
2010-07-26 17:07:22 ----D---- C:\Program Files
2010-07-26 17:06:24 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2010-07-26 17:06:24 ----A---- C:\WINDOWS\system32\pndx5032.dll
2010-07-26 17:06:24 ----A---- C:\WINDOWS\system32\pndx5016.dll
2010-07-26 17:06:24 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-07-26 17:06:22 ----A---- C:\WINDOWS\system32\unrar.dll
2010-07-26 17:06:22 ----A---- C:\WINDOWS\avisplitter.ini
2010-07-26 17:06:19 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2010-07-26 17:06:19 ----A---- C:\WINDOWS\system32\huffyuv.dll
2010-07-26 17:06:18 ----A---- C:\WINDOWS\system32\x264vfw.dll
2010-07-26 17:06:18 ----A---- C:\WINDOWS\system32\vp7vfw.dll
2010-07-26 17:06:18 ----A---- C:\WINDOWS\system32\vp6vfw.dll
2010-07-26 17:06:18 ----A---- C:\WINDOWS\system32\DivXc32f.dll
2010-07-26 17:06:18 ----A---- C:\WINDOWS\system32\DivXc32.dll
2010-07-26 17:06:17 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2010-07-26 17:06:17 ----A---- C:\WINDOWS\system32\xvidcore.dll
2010-07-26 17:06:16 ----A---- C:\WINDOWS\system32\qt-dx331.dll
2010-07-26 17:06:16 ----A---- C:\WINDOWS\system32\dpl100.dll
2010-07-26 17:06:16 ----A---- C:\WINDOWS\system32\divx.dll
2010-07-26 17:06:12 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2010-07-26 17:06:11 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2010-07-26 17:06:09 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-07-26 17:06:09 ----A---- C:\WINDOWS\system32\msvcp71.dll
2010-07-26 17:06:06 ----D---- C:\Arquivos de programas\K-Lite Codec Pack
2010-07-26 17:06:05 ----RSD---- C:\WINDOWS\assembly
2010-07-26 17:06:05 ----D---- C:\WINDOWS\Microsoft.NET
2010-07-26 17:06:03 ----D---- C:\WINDOWS\system32\URTTemp
2010-07-26 17:04:39 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Google
2010-07-26 17:02:55 ----A---- C:\WINDOWS\system32\drivers\avipbb.sys
2010-07-26 17:02:55 ----A---- C:\WINDOWS\system32\drivers\avgntmgr.sys
2010-07-26 17:02:55 ----A---- C:\WINDOWS\system32\drivers\avgntflt.sys
2010-07-26 17:02:55 ----A---- C:\WINDOWS\system32\drivers\avgntdd.sys
2010-07-26 17:02:54 ----A---- C:\WINDOWS\system32\drivers\ssmdrv.sys
2010-07-26 17:02:53 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Avira
2010-07-26 17:02:53 ----D---- C:\Arquivos de programas\Avira
2010-07-26 17:01:30 ----A---- C:\WINDOWS\system32\drivers\usbprint.sys
2010-07-26 17:01:23 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2010-07-26 17:01:19 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2010-07-26 17:00:29 ----A---- C:\WINDOWS\system32\HPZisn12.dll
2010-07-26 17:00:29 ----A---- C:\WINDOWS\system32\HPZipt12.dll
2010-07-26 17:00:29 ----A---- C:\WINDOWS\system32\HPZipr12.dll
2010-07-26 17:00:29 ----A---- C:\WINDOWS\system32\HPZipm12.exe
2010-07-26 17:00:29 ----A---- C:\WINDOWS\system32\HPZinw12.exe
2010-07-26 17:00:29 ----A---- C:\WINDOWS\system32\HPZidr12.dll
2010-07-26 17:00:28 ----A---- C:\WINDOWS\IsUninst.exe
2010-07-26 16:59:41 ----D---- C:\Arquivos de programas\HP
2010-07-26 16:59:16 ----D---- C:\NVIDIA
2010-07-26 16:59:10 ----HD---- C:\Config.Msi
2010-07-26 16:58:49 ----A---- C:\WINDOWS\system32\drivers\HPZius12.sys
2010-07-26 16:58:49 ----A---- C:\WINDOWS\system32\drivers\HPZipr12.sys
2010-07-26 16:58:49 ----A---- C:\WINDOWS\system32\drivers\hpzid412.sys
2010-07-26 16:58:41 ----A---- C:\WINDOWS\system32\HPZc3212.dll
2010-07-26 16:58:41 ----A---- C:\WINDOWS\system32\hpovst08.dll
2010-07-26 16:58:41 ----A---- C:\WINDOWS\system32\hpotscl.dll
2010-07-26 16:58:41 ----A---- C:\WINDOWS\system32\hpgwiamd.dll
2010-07-26 16:58:27 ----A---- C:\WINDOWS\system32\hpzsnt10.dll
2010-07-26 16:58:26 ----D---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\Mozilla
2010-07-26 16:58:24 ----A---- C:\WINDOWS\system32\hpzcon10.dll
2010-07-26 16:58:24 ----A---- C:\WINDOWS\system32\hpzcoi10.dll
2010-07-26 16:58:08 ----D---- C:\Arquivos de programas\Mozilla Firefox
2010-07-26 16:53:19 ----D---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\Adobe
2010-07-26 16:52:01 ----A---- C:\WINDOWS\ODBC.INI
2010-07-26 16:51:56 ----A---- C:\WINDOWS\system32\mdimon.dll
2010-07-26 16:50:25 ----D---- C:\Arquivos de programas\Microsoft.NET
2010-07-26 16:50:08 ----D---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\Macromedia
2010-07-26 16:48:10 ----A---- C:\WINDOWS\system32\drivers\MODEMCSA.sys
2010-07-26 16:48:08 ----A---- C:\WINDOWS\system32\csamsp.dll
2010-07-26 16:47:56 ----D---- C:\Arquivos de programas\Arquivos comuns\DESIGNER
2010-07-26 16:47:39 ----D---- C:\Arquivos de programas\Microsoft Works
2010-07-26 16:46:31 ----D---- C:\Arquivos de programas\Microsoft Visual Studio
2010-07-26 16:45:24 ----D---- C:\WINDOWS\SHELLNEW
2010-07-26 16:44:50 ----D---- C:\Arquivos de programas\Microsoft Office
2010-07-26 16:41:07 ----RA---- C:\WINDOWS\system32\nvwrszht.dll
2010-07-26 16:41:07 ----RA---- C:\WINDOWS\system32\nvwrszhc.dll
2010-07-26 16:41:07 ----RA---- C:\WINDOWS\system32\nvrszht.dll
2010-07-26 16:41:07 ----RA---- C:\WINDOWS\system32\nvrszhc.dll
2010-07-26 16:41:06 ----RA---- C:\WINDOWS\system32\nvwrstr.dll
2010-07-26 16:41:06 ----RA---- C:\WINDOWS\system32\nvwrssv.dll
2010-07-26 16:41:06 ----RA---- C:\WINDOWS\system32\nvrstr.dll
2010-07-26 16:41:05 ----RA---- C:\WINDOWS\system32\nvwrssl.dll
2010-07-26 16:41:05 ----RA---- C:\WINDOWS\system32\nvwrssk.dll
2010-07-26 16:41:05 ----RA---- C:\WINDOWS\system32\nvrssv.dll
2010-07-26 16:41:05 ----RA---- C:\WINDOWS\system32\nvrssl.dll
2010-07-26 16:41:05 ----RA---- C:\WINDOWS\system32\nvrssk.dll
2010-07-26 16:41:04 ----RA---- C:\WINDOWS\system32\nvwrsru.dll
2010-07-26 16:41:04 ----RA---- C:\WINDOWS\system32\nvwrsptb.dll
2010-07-26 16:41:04 ----RA---- C:\WINDOWS\system32\nvrsru.dll
2010-07-26 16:41:04 ----RA---- C:\WINDOWS\system32\nvrsptb.dll
2010-07-26 16:41:03 ----RA---- C:\WINDOWS\system32\nvwrspt.dll
2010-07-26 16:41:03 ----RA---- C:\WINDOWS\system32\nvwrspl.dll
2010-07-26 16:41:03 ----RA---- C:\WINDOWS\system32\nvwrsno.dll
2010-07-26 16:41:03 ----RA---- C:\WINDOWS\system32\nvrspt.dll
2010-07-26 16:41:03 ----RA---- C:\WINDOWS\system32\nvrspl.dll
2010-07-26 16:41:02 ----RA---- C:\WINDOWS\system32\nvwrsnl.dll
2010-07-26 16:41:02 ----RA---- C:\WINDOWS\system32\nvwrsko.dll
2010-07-26 16:41:02 ----RA---- C:\WINDOWS\system32\nvrsno.dll
2010-07-26 16:41:02 ----RA---- C:\WINDOWS\system32\nvrsnl.dll
2010-07-26 16:41:02 ----RA---- C:\WINDOWS\system32\nvrsko.dll
2010-07-26 16:41:01 ----RA---- C:\WINDOWS\system32\nvwrsja.dll
2010-07-26 16:41:01 ----RA---- C:\WINDOWS\system32\nvwrsit.dll
2010-07-26 16:41:01 ----RA---- C:\WINDOWS\system32\nvrsja.dll
2010-07-26 16:41:01 ----RA---- C:\WINDOWS\system32\nvrsit.dll
2010-07-26 16:41:00 ----RA---- C:\WINDOWS\system32\nvwrshu.dll
2010-07-26 16:41:00 ----RA---- C:\WINDOWS\system32\nvwrshe.dll
2010-07-26 16:41:00 ----RA---- C:\WINDOWS\system32\nvrshu.dll
2010-07-26 16:41:00 ----RA---- C:\WINDOWS\system32\nvrshe.dll
2010-07-26 16:40:59 ----RA---- C:\WINDOWS\system32\nvwrsfr.dll
2010-07-26 16:40:59 ----RA---- C:\WINDOWS\system32\nvwrsfi.dll
2010-07-26 16:40:59 ----RA---- C:\WINDOWS\system32\nvrsfr.dll
2010-07-26 16:40:59 ----RA---- C:\WINDOWS\system32\nvrsfi.dll
2010-07-26 16:40:58 ----RA---- C:\WINDOWS\system32\nvwrsesm.dll
2010-07-26 16:40:58 ----RA---- C:\WINDOWS\system32\nvwrses.dll
2010-07-26 16:40:58 ----RA---- C:\WINDOWS\system32\nvwrseng.dll
2010-07-26 16:40:58 ----RA---- C:\WINDOWS\system32\nvrsesm.dll
2010-07-26 16:40:58 ----RA---- C:\WINDOWS\system32\nvrses.dll
2010-07-26 16:40:58 ----RA---- C:\WINDOWS\system32\nvrseng.dll
2010-07-26 16:40:57 ----RA---- C:\WINDOWS\system32\nvwrsel.dll
2010-07-26 16:40:57 ----RA---- C:\WINDOWS\system32\nvwrsde.dll
2010-07-26 16:40:57 ----RA---- C:\WINDOWS\system32\nvrsel.dll
2010-07-26 16:40:57 ----RA---- C:\WINDOWS\system32\nvrsde.dll
2010-07-26 16:40:56 ----RA---- C:\WINDOWS\system32\nvwrsda.dll
2010-07-26 16:40:56 ----RA---- C:\WINDOWS\system32\nvwrscs.dll
2010-07-26 16:40:56 ----RA---- C:\WINDOWS\system32\nvrsda.dll
2010-07-26 16:40:56 ----RA---- C:\WINDOWS\system32\nvrscs.dll
2010-07-26 16:40:55 ----RA---- C:\WINDOWS\system32\nvwrsar.dll
2010-07-26 16:40:55 ----RA---- C:\WINDOWS\system32\nvrsar.dll
2010-07-26 16:40:55 ----A---- C:\WINDOWS\system32\nwiz.exe
2010-07-26 16:40:55 ----A---- C:\WINDOWS\system32\nvwimg.dll
2010-07-26 16:40:54 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
2010-07-26 16:40:54 ----A---- C:\WINDOWS\system32\nvshell.dll
2010-07-26 16:40:54 ----A---- C:\WINDOWS\system32\nview.dll
2010-07-26 16:40:53 ----D---- C:\WINDOWS\nview
2010-07-26 16:40:53 ----A---- C:\WINDOWS\system32\nvudisp.exe
2010-07-26 16:40:53 ----A---- C:\WINDOWS\system32\nvdspsch.exe
2010-07-26 16:40:53 ----A---- C:\WINDOWS\system32\nvappbar.exe
2010-07-26 16:40:53 ----A---- C:\WINDOWS\system32\keystone.exe
2010-07-26 16:40:52 ----A---- C:\WINDOWS\system32\nvwddi.dll
2010-07-26 16:40:52 ----A---- C:\WINDOWS\system32\nvnt4cpl.dll
2010-07-26 16:40:52 ----A---- C:\WINDOWS\system32\nvmctray.dll
2010-07-26 16:40:51 ----A---- C:\WINDOWS\system32\nvcpl.dll
2010-07-26 16:40:50 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2010-07-26 16:40:48 ----A---- C:\WINDOWS\system32\nvcodins.dll
2010-07-26 16:40:48 ----A---- C:\WINDOWS\system32\nvcod.dll
2010-07-26 16:40:47 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2010-07-26 16:38:42 ----D---- C:\Progra~1
2010-07-26 16:38:23 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2010-07-26 16:38:21 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2010-07-26 16:38:20 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2010-07-26 16:38:19 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2010-07-26 16:38:17 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2010-07-26 16:38:16 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2010-07-26 16:38:15 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2010-07-26 16:38:14 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2010-07-26 16:38:12 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010-07-26 16:38:11 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2010-07-26 16:38:09 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010-07-26 16:38:04 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-07-26 16:38:04 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2010-07-26 16:38:04 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2010-07-26 16:38:03 ----A---- C:\WINDOWS\system32\drivers\aeaudio.sys
2010-07-26 16:38:02 ----A---- C:\WINDOWS\system32\wdmioctl.dll
2010-07-26 16:38:02 ----A---- C:\WINDOWS\system32\drivers\smsens.sys
2010-07-26 16:38:01 ----A---- C:\WINDOWS\system32\SMMedia.dll
2010-07-26 16:38:00 ----A---- C:\WINDOWS\SynthCoreA.Dll
2010-07-26 16:38:00 ----A---- C:\WINDOWS\SynCor.exe
2010-07-26 16:37:59 ----A---- C:\WINDOWS\system32\Syncor11.dll
2010-07-26 16:37:59 ----A---- C:\WINDOWS\system32\S11thk32.dll
2010-07-26 16:37:58 ----A---- C:\WINDOWS\system32\SynthCore11Resources.dll
2010-07-26 16:37:55 ----D---- C:\WINDOWS\VirtualEar
2010-07-26 16:37:55 ----A---- C:\WINDOWS\system32\Audio3d.dll
2010-07-26 16:37:54 ----A---- C:\WINDOWS\system32\virtear.dll
2010-07-26 16:37:53 ----A---- C:\WINDOWS\system32\drivers\smwdm.sys
2010-07-26 16:37:53 ----A---- C:\WINDOWS\system32\a3d.dll
2010-07-26 16:37:51 ----D---- C:\Arquivos de programas\Analog Devices
2010-07-26 16:37:51 ----A---- C:\WINDOWS\system32\DSndUp.exe
2010-07-26 16:37:51 ----A---- C:\WINDOWS\system32\CleanUp.exe
2010-07-26 16:37:50 ----HD---- C:\Arquivos de programas\InstallShield Installation Information
2010-07-26 16:37:50 ----A---- C:\WINDOWS\system32\msssc.dll
2010-07-26 16:37:44 ----D---- C:\Arquivos de programas\Arquivos comuns\InstallShield
2010-07-26 16:37:18 ----A---- C:\WINDOWS\SiSport.sys
2010-07-26 16:37:18 ----A---- C:\WINDOWS\SIS_LIB.DLL
2010-07-26 16:37:17 ----A---- C:\WINDOWS\SiSUSBrg.exe
2010-07-26 16:37:16 ----RA---- C:\WINDOWS\system32\drivers\SISAGPX.SYS
2010-07-26 16:37:15 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-07-26 16:37:07 ----A---- C:\WINDOWS\IsUn0416.exe
2010-07-26 16:36:54 ----A---- C:\WINDOWS\Ascd_tmp.ini
2010-07-26 16:36:53 ----A---- C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2010-07-26 16:34:35 ----D---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\Identities
2010-07-26 16:34:33 ----HD---- C:\Arquivos de programas\Uninstall Information
2010-07-26 16:34:27 ----SD---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\Microsoft
2010-07-26 16:34:27 ----ASH---- C:\Documents and Settings\Felipe Rodrigues\Dados de aplicativos\desktop.ini
2010-07-26 16:30:38 ----D---- C:\WINDOWS\SoftwareDistribution
2010-07-26 16:29:26 ----SD---- C:\WINDOWS\system32\Microsoft
2010-07-26 16:29:26 ----D---- C:\WINDOWS\Prefetch
2010-07-26 16:29:26 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-26 16:25:55 ----D---- C:\WINDOWS\system32\xircom
2010-07-26 16:25:55 ----D---- C:\Arquivos de programas\xerox
2010-07-26 16:25:55 ----D---- C:\Arquivos de programas\microsoft frontpage
2010-07-26 16:25:35 ----RASH---- C:\MSDOS.SYS
2010-07-26 16:25:35 ----RASH---- C:\IO.SYS
2010-07-26 16:25:35 ----A---- C:\WINDOWS\control.ini
2010-07-26 16:25:35 ----A---- C:\CONFIG.SYS
2010-07-26 16:25:35 ----A---- C:\AUTOEXEC.BAT
2010-07-26 16:25:24 ----A---- C:\WINDOWS\OEWABLog.txt
2010-07-26 16:25:19 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-07-26 16:24:17 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-07-26 16:24:17 ----RD---- C:\WINDOWS\Offline Web Pages
2010-07-26 16:24:17 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-07-26 16:24:10 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-07-26 16:24:05 ----HD---- C:\Arquivos de programas\WindowsUpdate
2010-07-26 16:24:01 ----D---- C:\Arquivos de programas\Serviços on-line
2010-07-26 16:23:45 ----D---- C:\WINDOWS\system32\DirectX
2010-07-26 16:23:40 ----A---- C:\WINDOWS\system32\atrace.dll
2010-07-26 16:23:37 ----A---- C:\WINDOWS\system32\desktop.ini
2010-07-26 16:23:37 ----A---- C:\WINDOWS\desktop.ini
2010-07-26 16:23:30 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-07-26 16:23:29 ----A---- C:\WINDOWS\system32\acctres.dll
2010-07-26 16:23:28 ----D---- C:\Arquivos de programas\Arquivos comuns\Serviços
2010-07-26 16:23:26 ----SD---- C:\WINDOWS\Tasks
2010-07-26 16:23:26 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-07-26 16:23:25 ----D---- C:\Arquivos de programas\Arquivos comuns\MSSoap
2010-07-26 16:23:21 ----D---- C:\WINDOWS\srchasst
2010-07-26 16:23:20 ----D---- C:\WINDOWS\system32\Macromed
2010-07-26 16:23:17 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-07-26 16:23:17 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-07-26 16:23:17 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-07-26 16:23:17 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-07-26 16:23:16 ----A---- C:\WINDOWS\system32\wups.dll
2010-07-26 16:23:16 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-07-26 16:23:16 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-07-26 16:23:16 ----A---- C:\WINDOWS\system32\wuauclt.exe
2010-07-26 16:23:16 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-07-26 16:23:16 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-07-26 16:23:16 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-07-26 16:23:16 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2010-07-26 16:23:16 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-07-26 16:23:16 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-07-26 16:23:12 ----D---- C:\Arquivos de programas\Movie Maker
2010-07-26 16:22:54 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-07-26 16:22:54 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-07-26 16:22:54 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-07-26 16:22:54 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-07-26 16:22:50 ----D---- C:\WINDOWS\system32\Restore
2010-07-26 16:22:50 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-07-26 16:22:50 ----A---- C:\WINDOWS\system32\fltMc.exe
2010-07-26 16:22:50 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-07-26 16:22:50 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2010-07-26 16:22:49 ----A---- C:\WINDOWS\system32\srsvc.dll
2010-07-26 16:22:49 ----A---- C:\WINDOWS\system32\srclient.dll
2010-07-26 16:22:49 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-07-26 16:22:49 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-07-26 16:22:49 ----A---- C:\WINDOWS\system32\ils.dll
2010-07-26 16:22:49 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2010-07-26 16:22:48 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-07-26 16:22:48 ----A---- C:\WINDOWS\system32\msconf.dll
2010-07-26 16:22:48 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-07-26 16:22:45 ----D---- C:\Arquivos de programas\NetMeeting
2010-07-26 16:22:45 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-07-26 16:22:45 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-07-26 16:22:44 ----A---- C:\WINDOWS\system32\inetres.dll
2010-07-26 16:22:44 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-07-26 16:22:42 ----D---- C:\Arquivos de programas\Outlook Express
2010-07-26 16:22:42 ----A---- C:\WINDOWS\system32\schedsvc.dll
2010-07-26 16:22:42 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-07-26 16:22:42 ----A---- C:\WINDOWS\system32\mstask.dll
2010-07-26 16:22:41 ----A---- C:\WINDOWS\system32\isign32.dll
2010-07-26 16:22:41 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-07-26 16:22:41 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-07-26 16:22:41 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-07-26 16:22:36 ----D---- C:\Arquivos de programas\Arquivos comuns\System
2010-07-26 16:22:35 ----D---- C:\Arquivos de programas\Internet Explorer
2010-07-26 16:21:57 ----D---- C:\Arquivos de programas\ComPlus Applications
2010-07-26 16:21:54 ----A---- C:\WINDOWS\vbaddin.ini
2010-07-26 16:21:54 ----A---- C:\WINDOWS\vb.ini
2010-07-26 16:21:49 ----D---- C:\WINDOWS\Registration
2010-07-26 16:21:41 ----D---- C:\Arquivos de programas\Windows Media Player
2010-07-26 16:21:34 ----D---- C:\Arquivos de programas\Messenger
2010-07-26 16:21:30 ----D---- C:\Arquivos de programas\MSN Gaming Zone
2010-07-26 16:21:30 ----A---- C:\WINDOWS\system32\write.exe
2010-07-26 16:21:22 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-07-26 16:21:22 ----A---- C:\WINDOWS\system32\hticons.dll
2010-07-26 16:21:21 ----A---- C:\WINDOWS\system32\winchat.exe
2010-07-26 16:21:21 ----A---- C:\WINDOWS\system32\avwav.dll
2010-07-26 16:21:21 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-07-26 16:21:21 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-07-26 16:21:14 ----A---- C:\WINDOWS\system32\getuname.dll
2010-07-26 16:21:14 ----A---- C:\WINDOWS\system32\charmap.exe
2010-07-26 16:21:13 ----A---- C:\WINDOWS\system32\winmine.exe
2010-07-26 16:21:13 ----A---- C:\WINDOWS\system32\sol.exe
2010-07-26 16:21:13 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-07-26 16:21:13 ----A---- C:\WINDOWS\system32\calc.exe
2010-07-26 16:21:12 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-07-26 16:21:12 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-07-26 16:21:12 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-07-26 16:21:12 ----A---- C:\WINDOWS\system32\tskill.exe
2010-07-26 16:21:12 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-07-26 16:21:12 ----A---- C:\WINDOWS\system32\tscon.exe
2010-07-26 16:21:12 ----A---- C:\WINDOWS\system32\shadow.exe
2010-07-26 16:21:12 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-07-26 16:21:12 ----A---- C:\WINDOWS\system32\reset.exe
2010-07-26 16:21:12 ----A---- C:\WINDOWS\system32\freecell.exe
2010-07-26 16:21:11 ----A---- C:\WINDOWS\system32\regini.exe
2010-07-26 16:21:11 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-07-26 16:21:11 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-07-26 16:21:11 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-07-26 16:21:11 ----A---- C:\WINDOWS\system32\msg.exe
2010-07-26 16:21:11 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-07-26 16:21:11 ----A---- C:\WINDOWS\system32\logoff.exe
2010-07-26 16:21:11 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-07-26 16:21:05 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-07-26 16:21:04 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-07-26 16:21:04 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-07-26 16:21:04 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-07-26 16:21:03 ----D---- C:\Arquivos de programas\Windows NT
2010-07-26 16:21:03 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-07-26 16:21:03 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-07-26 16:21:03 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-07-26 16:21:02 ----A---- C:\WINDOWS\system32\spider.exe
2010-07-26 16:21:02 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2010-07-26 16:21:01 ----A---- C:\WINDOWS\system32\tsgqec.dll
2010-07-26 16:21:01 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-07-26 16:21:01 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2010-07-26 16:21:01 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2010-07-26 16:21:01 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2010-07-26 16:21:01 ----A---- C:\WINDOWS\system32\aaclient.dll
2010-07-26 16:21:00 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-07-26 16:21:00 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-07-26 16:21:00 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-07-26 16:21:00 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-07-26 16:20:59 ----A---- C:\WINDOWS\system32\termsrv.dll
2010-07-26 16:20:59 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-07-26 16:20:59 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-07-26 16:20:59 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-07-26 16:20:59 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-07-26 16:20:59 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-07-26 16:20:59 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-07-26 16:20:59 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-07-26 16:20:59 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-07-26 16:20:58 ----D---- C:\WINDOWS\system32\MsDtc
2010-07-26 16:20:58 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-07-26 16:20:58 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-07-26 16:20:58 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-07-26 16:20:58 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-07-26 16:20:58 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-07-26 16:20:57 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-07-26 16:20:57 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-07-26 16:20:57 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-07-26 16:20:56 ----D---- C:\WINDOWS\system32\Com
2010-07-26 16:20:56 ----A---- C:\WINDOWS\system32\stclient.dll
2010-07-26 16:20:56 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-07-26 16:20:56 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-07-26 16:20:56 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-07-26 16:20:56 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-07-26 16:20:56 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-07-26 16:20:56 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-07-26 16:20:56 ----A---- C:\WINDOWS\system32\colbact.dll
2010-07-26 16:20:55 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-07-26 16:20:55 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-07-26 16:20:55 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-07-26 16:20:55 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-07-26 16:20:55 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-07-26 16:20:54 ----A---- C:\WINDOWS\system32\comuid.dll
2010-07-26 16:20:54 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-07-26 16:20:54 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-07-26 16:20:48 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-07-26 16:20:48 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-07-26 16:20:48 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-07-26 16:20:47 ----A---- C:\WINDOWS\system32\cmprops.dll
2010-07-26 16:20:44 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys
2010-07-26 16:20:43 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2010-07-26 13:15:19 ----A---- C:\WINDOWS\system32\h323log.txt
2010-07-26 13:09:46 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2010-07-26 13:09:18 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2010-07-26 13:09:13 ----A---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2010-07-26 13:09:12 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2010-07-26 13:08:56 ----A---- C:\WINDOWS\system32\drivers\gameenum.sys
2010-07-26 13:08:44 ----A---- C:\WINDOWS\system32\drivers\UAGP35.SYS
2010-07-26 13:08:38 ----RA---- C:\WINDOWS\system32\drivers\sisnic.sys
2010-07-26 13:08:31 ----A---- C:\WINDOWS\system32\usbui.dll
2010-07-26 13:07:25 ----A---- C:\WINDOWS\imsins.BAK
2010-07-26 13:07:22 ----SHD---- C:\WINDOWS\Installer
2010-07-26 13:07:22 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-26 13:07:21 ----D---- C:\Arquivos de programas\Arquivos comuns\ODBC
2010-07-26 13:07:21 ----A---- C:\WINDOWS\ODBCINST.INI
2010-07-26 13:07:17 ----D---- C:\Arquivos de programas\Arquivos comuns\SpeechEngines
2010-07-26 13:07:17 ----D---- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared
2010-07-26 13:07:16 ----D---- C:\Arquivos de programas\Arquivos comuns
2010-07-26 13:07:16 ----D---- C:\Arquivos de programas
2010-07-26 13:07:12 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2010-07-26 13:07:12 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2010-07-26 13:07:12 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdur.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdru.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2010-07-26 13:07:10 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2010-07-26 13:07:08 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2010-07-26 13:07:08 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2010-07-26 13:07:08 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2010-07-26 13:07:08 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2010-07-26 13:07:08 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2010-07-26 13:07:08 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2010-07-26 13:07:08 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2010-07-26 13:07:06 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2010-07-26 13:07:06 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2010-07-26 13:07:06 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2010-07-26 13:07:06 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2010-07-26 13:07:06 ----RA---- C:\WINDOWS\system32\kbdest.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdro.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2010-07-26 13:07:04 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2010-07-26 13:07:02 ----A---- C:\WINDOWS\system32\irclass.dll
2010-07-26 13:07:01 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-07-26 13:07:01 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-07-26 13:07:01 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-07-26 13:07:01 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-07-26 13:06:59 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-07-26 13:06:58 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2010-07-26 13:06:58 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2010-07-26 13:06:58 ----A---- C:\WINDOWS\system32\batt.dll
2010-07-26 13:06:58 ----A---- C:\WINDOWS\NOTEPAD.EXE
2010-07-26 13:06:57 ----A---- C:\WINDOWS\system32\storprop.dll
2010-07-26 13:06:48 ----ASH---- C:\Documents and Settings\All Users\Dados de aplicativos\desktop.ini
2010-07-26 13:06:44 ----RA---- C:\WINDOWS\SET8.tmp
2010-07-26 13:06:41 ----RA---- C:\WINDOWS\SET4.tmp
2010-07-26 13:06:39 ----RA---- C:\WINDOWS\SET3.tmp
2010-07-26 13:06:35 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-26 13:06:35 ----D---- C:\WINDOWS\system32\CatRoot
2010-07-26 13:06:29 ----SD---- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft
2010-07-26 13:06:08 ----A---- C:\WINDOWS\setuplog.txt
2010-07-26 13:06:04 ----D---- C:\Documents and Settings
2010-07-26 13:06:03 ----SHD---- C:\System Volume Information
2010-07-26 13:05:07 ----SH---- C:\boot.ini
2010-07-26 12:59:01 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-26 12:59:01 ----RSD---- C:\WINDOWS\Fonts
2010-07-26 12:59:01 ----RD---- C:\WINDOWS\Web
2010-07-26 12:59:01 ----HD---- C:\WINDOWS\inf
2010-07-26 12:59:01 ----D---- C:\WINDOWS\WinSxS
2010-07-26 12:59:01 ----D---- C:\WINDOWS\twain_32
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Temp
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\wins
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\wbem
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\usmt
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\spool
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\ShellExt
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\Setup
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\ras
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\pt-BR
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\oobe
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\npp
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\mui
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\inetsrv
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\IME
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\icsxml
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\ias
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\export
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\drivers\etc
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\drivers\disdn
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\drivers
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\dhcp
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\config
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\3com_dmi
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\3076
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\2052
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\1054
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\1046
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\1042
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\1041
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\1037
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\1033
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\1031
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\1028
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32\1025
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system32
2010-07-26 12:59:01 ----D---- C:\WINDOWS\system
2010-07-26 12:59:01 ----D---- C:\WINDOWS\security
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Resources
2010-07-26 12:59:01 ----D---- C:\WINDOWS\repair
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Provisioning
2010-07-26 12:59:01 ----D---- C:\WINDOWS\PeerNet
2010-07-26 12:59:01 ----D---- C:\WINDOWS\pchealth
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Network Diagnostic
2010-07-26 12:59:01 ----D---- C:\WINDOWS\mui
2010-07-26 12:59:01 ----D---- C:\WINDOWS\msapps
2010-07-26 12:59:01 ----D---- C:\WINDOWS\msagent
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Media
2010-07-26 12:59:01 ----D---- C:\WINDOWS\L2Schemas
2010-07-26 12:59:01 ----D---- C:\WINDOWS\java
2010-07-26 12:59:01 ----D---- C:\WINDOWS\ime
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Help
2010-07-26 12:59:01 ----D---- C:\WINDOWS\ehome
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Driver Cache
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Debug
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Cursors
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Connection Wizard
2010-07-26 12:59:01 ----D---- C:\WINDOWS\Config
2010-07-26 12:59:01 ----D---- C:\WINDOWS\AppPatch
2010-07-26 12:59:01 ----D---- C:\WINDOWS\addins
2010-07-26 12:59:01 ----D---- C:\WINDOWS
2010-07-26 12:59:01 ----ASH---- C:\pagefile.sys
======List of files/folders modified in the last 1 months======
2010-07-27 20:22:06 ----A---- C:\WINDOWS\win.ini
2010-07-27 20:22:06 ----A---- C:\WINDOWS\system.ini
2010-07-27 03:29:57 ----A---- C:\WINDOWS\system32\shell32.dll
2010-07-26 16:25:06 ----ASH---- C:\WINDOWS\fonts\desktop.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 RecAgent;RecAgent; C:\WINDOWS\system32\DRIVERS\RecAgent.sys [2008-04-13 13776]
R0 SISAGP;SiS AGP Filter; C:\WINDOWS\system32\DRIVERS\SISAGPX.sys [2003-07-17 36992]
R0 uagp35;Filtro Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-13 44672]
R1 avgio;avgio; \??\C:\Arquivos de programas\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys [2007-02-12 31360]
R1 incdrm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys [2007-02-12 33792]
R1 intelppm;Driver de Processador Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 Tcpip6;Microsoft IPv6 Protocol Driver; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-11-25 56816]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 MODEMCSA;Dispositivo de filtro de fluxo unimodem; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 Mtlmnt5;Mtlmnt5; C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys [2008-04-13 126686]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-02 6554496]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\sisnic.sys [2003-08-28 32256]
R3 Slntamr;NetoDragon AMR_PCI Driver; C:\WINDOWS\system32\DRIVERS\slntamr.sys [2008-04-13 404990]
R3 SlWdmSup;SlWdmSup; C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys [2008-04-13 13240]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-08-29 578304]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288]
R4 InCDfs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys [2007-02-12 112384]
S3 HidUsb;Driver de classe HID da Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-22 51088]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-22 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-22 21744]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys []
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-09-05 12288]
S3 Mtlstrm;Mtlstrm; C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys [2008-04-13 1309184]
S3 SlNtHal;SlNtHal; C:\WINDOWS\system32\DRIVERS\Slnthal.sys [2008-04-13 95424]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 6to4;Serviço auxiliar IPv6; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 AntiVirSchedulerService;Avira AntiVir Programador; C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 InCDsrv;InCD Helper; C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe [2007-02-12 924160]
R2 MDM;Machine Debug Manager; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-02 159812]
R2 SLService;SmartLinkService; C:\WINDOWS\system32\slserv.exe [2004-08-24 57344]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
S3 aspnet_state;Serviço de estado do ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 gusvc;Google Updater Service; C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 NBService;NBService; C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-01-05 774144]
S3 NMIndexingService;NMIndexingService; C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe [2006-12-23 262144]
S3 ose;Office Source Engine; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-03-18 65536]
S3 WMPNetworkSvc;Serviço de Compartilhamento de Rede do Windows Media Player; C:\Arquivos de programas\Windows Media Player\WMPNetwk.exe [2006-11-02 914944]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------
Tinha que estar com o cartao plugado?
1.
*Delete o RSIT e a pasta C:\rsit
2.
*Abra o Windows explorer
*Conecte o pen drive no PC e mantenha a tecla [shift] apertada até que o pen drive seja reconhecido.
3.
*Desative temporariamente seu antivírus
Clique com o botão direito do mouse no ícone do Avira ao lado do relógio Clique na opção "Antivir Guard enable".
*Baixe o USBFix e salve-o no desktop
*Execute o UsbFix
*Clique em [Pesquisa] e aguarde o término
*Remova o Pendrive
*Cole o relatório criado em C:\UsbFix.txt
############################## | UsbFix 7.020 | [Pesquisa]
Usuário: Felipe Rodrigues (Administrador) # FELIPE [ ]
Atualizado em 12/08/10 por El Desaparecido / C_XX
Começou em 21:46:37 | 17/08/2010
Site: http://pagesperso-orange.fr/NosTools/index.html
Contato: FindyKill.Contact@gmail.com
CPU: Intel® Pentium® 4 CPU 3.20GHz
CPU 2: Intel® Pentium® 4 CPU 3.20GHz
Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall: Habilitado
Antivirus: AntiVir Desktop 9.0.1.32 [(!) Disabled | Updated]
RAM -> 512 Mb
C:\ (%systemdrive%) -> Disco fixo # 20 Gb (2 Mb livre - 12%) [] # NTFS
D:\ -> Disco fixo # 92 Gb (565 Mb livre - 1%) [DADOS] # NTFS
E:\ -> CD-ROM
F:\ -> Disco removível # 4 Gb (115 Mb livre - 3%) [Felipe] # FAT32
################## | Ficheiros # pastas infeciosos |
Presente ! F:\levic.exe
Presente ! F:\levic.scr
Presente ! F:\autorun.inf
Presente ! F:\Documents.lnk
Presente ! F:\Music.lnk
Presente ! F:\New Folder.lnk
Presente ! F:\Passwords.lnk
Presente ! F:\Pictures.lnk
Presente ! F:\Videos.lnk
Presente ! F:\Video.lnk
Presente ! F:\RECYCLER32
################## | Registro |
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{a3f2676c-9a6a-11df-bb82-001fd0f11875}
Shell\AutoRun\Command = F:\AutoRun.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{a3f2676f-9a6a-11df-bb82-001fd0f11875}
Shell\AutoRun\Command = F:\AutoRun.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{a7e9ded6-a6f9-11df-bb9f-001fd0f11875}
Shell\AutoRun\Command = F:\pbudsara.exe
Shell\open\Command = F:\pbudsara.exe
################## | Vaccin |
F:\Autorun.inf -> Folder criado por Panda USB Vaccine
################## | E.O.F |
Acredito que possas perder estas pastas do pen drive....
Desejas continuar?
É o jeito né...
n tem como salvar nem tem como acessar os arquivos....
pode continuar o q vier ta no lucro!
Disse tudo...
*Conecte novamente o Pendrive no PC da mesma forma que descrevi antes
*Execute o UsbFix
*Clique em [supressão] e aguarde o término
*Remova o Pendrive
*Cole o relatório criado em C:\UsbFix.txt
############################## | UsbFix 7.020 | [supressão]
Usuário: Felipe Rodrigues (Administrador) # FELIPE [ ]
Atualizado em 12/08/10 por El Desaparecido / C_XX
Começou em 14:38:29 | 18/08/2010
Site: http://pagesperso-orange.fr/NosTools/index.html
Contato: FindyKill.Contact@gmail.com
CPU: Intel® Pentium® 4 CPU 3.20GHz
CPU 2: Intel® Pentium® 4 CPU 3.20GHz
Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall: Habilitado
Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
RAM -> 512 Mb
C:\ (%systemdrive%) -> Disco fixo # 20 Gb (2 Mb livre - 12%) [] # NTFS
D:\ -> Disco fixo # 92 Gb (565 Mb livre - 1%) [DADOS] # NTFS
E:\ -> CD-ROM
F:\ -> Disco removível # 4 Gb (115 Mb livre - 3%) [Felipe] # FAT32
################## | Ficheiros # pastas infeciosos |
Supprimido ! F:\levic.exe
Supprimido ! F:\levic.scr
Não supprimido ! F:\autorun.inf
Supprimido ! F:\Documents.lnk
Supprimido ! F:\Music.lnk
Supprimido ! F:\New Folder.lnk
Supprimido ! F:\Passwords.lnk
Supprimido ! F:\Pictures.lnk
Supprimido ! F:\Videos.lnk
Supprimido ! F:\Video.lnk
Supprimido ! F:\RECYCLER32
################## | Registro |
################## | Mountpoints2 |
Supprimido ! HKCU\.\.\.\.\Explorer\MountPoints2\{a3f2676c-9a6a-11df-bb82-001fd0f11875}
Supprimido ! HKCU\.\.\.\.\Explorer\MountPoints2\{a7e9ded6-a6f9-11df-bb9f-001fd0f11875}
################## | Listing |
[17/08/2010 - 18:43:24 | D ] C:\Arquivos de programas
[26/07/2010 - 16:25:35 | A | 0] C:\AUTOEXEC.BAT
[27/07/2010 - 20:22:06 | SH | 211] C:\boot.ini
[14/04/2008 - 09:00:00 | RASH | 4952] C:\Bootfont.bin
[02/08/2010 - 21:47:10 | HD ] C:\Config.Msi
[26/07/2010 - 16:25:35 | A | 0] C:\CONFIG.SYS
[26/07/2010 - 16:34:27 | D ] C:\Documents and Settings
[06/02/2004 - 17:20:46 | RA | 16384] C:\hpqimgrc.resources.dll
[26/07/2010 - 16:25:35 | RASH | 0] C:\IO.SYS
[26/07/2010 - 16:25:35 | RASH | 0] C:\MSDOS.SYS
[14/04/2008 - 09:00:00 | RASH | 47564] C:\NTDETECT.COM
[14/04/2008 - 09:00:00 | RASH | 251696] C:\ntldr
[26/07/2010 - 17:08:24 | D ] C:\NVIDIA
[18/08/2010 - 14:29:55 | ASH | 805306368] C:\pagefile.sys
[26/07/2010 - 17:07:22 | D ] C:\Program Files
[26/07/2010 - 16:38:42 | D ] C:\Progra~1
[18/08/2010 - 14:41:24 | SHD ] C:\RECYCLER
[26/07/2010 - 16:30:38 | SHD ] C:\System Volume Information
[29/07/2010 - 11:15:16 | D ] C:\The Book Of Eli.2010.BdRip.Xvid {1337x}-Noir
[18/08/2010 - 14:41:25 | D ] C:\UsbFix
[18/08/2010 - 14:41:25 | A | 1231] C:\UsbFix.txt
[10/08/2010 - 22:36:04 | D ] C:\WINDOWS
[09/06/2010 - 22:50:19 | D ] D:\333d92130049bcad831e4141
[25/10/2001 - 14:11:14 | A | 34944] D:\actionj.ttf
[01/01/2002 - 17:30:20 | A | 0] D:\AUTOEXEC.BAT
[26/07/2010 - 16:45:28 | D ] D:\Backup
[21/05/2010 - 09:29:33 | D ] D:\Backup C
[01/04/2010 - 22:25:28 | D ] D:\BywifiSave
[17/08/2010 - 17:09:16 | RD ] D:\Carolina
[03/07/2010 - 15:14:01 | D ] D:\CD
[01/01/2002 - 17:30:20 | A | 0] D:\CONFIG.SYS
[01/01/2002 - 17:30:20 | RASH | 0] D:\IO.SYS
[11/05/2010 - 18:59:42 | RD ] D:\MEUS DOCUMENTOS
[05/08/2010 - 17:00:47 | RD ] D:\Minhas músicas
[01/01/2002 - 17:30:20 | RASH | 0] D:\MSDOS.SYS
[15/08/2010 - 13:36:16 | D ] D:\Musicas
[18/08/2010 - 14:41:24 | SHD ] D:\RECYCLER
[10/07/2010 - 10:59:27 | D ] D:\Seriados
[14/07/2010 - 06:50:21 | A | 2886] D:\Seven Loader 7 Remove Wat 2.2.5 + Ghost Mode Infos.rar.torrent
[30/07/2010 - 20:42:59 | RD ] D:\Sony DSC S-600
[12/05/2010 - 15:21:13 | SHD ] D:\System Volume Information
[14/07/2010 - 07:09:08 | D ] D:\Torrents
[31/05/2010 - 00:12:40 | RD ] E:\AC DC
[11/11/2009 - 13:42:35 | RD ] E:\AC-DC - Electrified Toronto DVD 2009-LzY
[12/03/2009 - 16:38:11 | RD ] E:\ACDC
[21/05/2010 - 23:22:43 | RD ] E:\AETH9
[14/06/2010 - 20:40:10 | RD ] E:\Accept
[11/11/2009 - 22:20:58 | RD ] E:\Aerosmith
[07/11/2009 - 13:26:44 | RD ] E:\Anastacia
[12/11/2009 - 10:28:05 | RD ] E:\Aphex Twins
[07/02/2009 - 16:15:20 | RD ] E:\Appaloosa Soundtrack
[02/02/2009 - 00:45:45 | RD ] E:\Armandinho
[07/11/2009 - 14:06:09 | RD ] E:\Ashlee Simpson
[12/11/2009 - 11:08:03 | RD ] E:\Ashley Tisdale
[12/11/2009 - 11:16:15 | RD ] E:\AudioSlave
[12/11/2009 - 12:18:57 | RD ] E:\Avril Lavigne
[12/11/2009 - 12:32:12 | RD ] E:\Badfinger
[12/11/2009 - 12:40:16 | RD ] E:\Barão Vermelho
[12/11/2009 - 12:46:42 | RD ] E:\Basshunter
[12/11/2009 - 13:28:12 | RD ] E:\Bebel Gilberto
[21/01/2009 - 12:41:47 | RD ] E:\Bee Gees
[02/02/2009 - 00:53:43 | RD ] E:\Benny Benassi
[04/01/2009 - 11:38:09 | RD ] E:\Best of Adrenalina Remixes 2008 - Rede Transamérica
[02/02/2009 - 00:55:00 | RD ] E:\Beth Orton
[31/05/2010 - 00:40:07 | RD ] E:\Beyonce
[02/02/2009 - 00:55:23 | RD ] E:\Billy Corgan
[06/02/2009 - 15:51:26 | RD ] E:\Black Eyed Peas
[17/02/2009 - 15:59:13 | RD ] E:\Blind Melon
[02/02/2009 - 00:56:13 | RD ] E:\Blink 182
[31/05/2010 - 00:40:34 | RD ] E:\Bob Dylan - Together Through Life
[14/02/2009 - 19:34:48 | RD ] E:\Bob Marley
[14/02/2009 - 19:59:42 | RD ] E:\Bob Sinclair
[01/06/2010 - 20:30:26 | RD ] E:\Bon Jovi
[02/02/2009 - 00:44:34 | RD ] E:\Bossa cuca nova
[31/05/2010 - 00:41:12 | RD ] E:\Britney Spears
[07/02/2009 - 00:06:53 | RD ] E:\Bruce Dickinson
[27/11/2009 - 00:53:09 | RD ] E:\Bruce Springsteen
[07/06/2009 - 22:13:39 | RD ] E:\Bush - 1996 - Razorblade Suitcase
[19/04/2009 - 22:53:51 | RD ] E:\Capital Inicial
[02/02/2009 - 01:01:22 | RD ] E:\Cascada
[02/02/2009 - 01:01:55 | RD ] E:\Cassia Eller
[02/02/2009 - 01:02:19 | RD ] E:\Celine Dion
[02/02/2009 - 01:03:04 | RD ] E:\Chemical Brothers
[03/01/2010 - 13:00:57 | RD ] E:\Lie To Me
[12/09/2009 - 21:33:34 | SHD ] F:\RECYCLER
[25/10/2009 - 14:45:12 | SHD ] F:\FOUND.000
[04/02/2010 - 14:52:12 | SHD ] F:\FOUND.001
[02/07/2010 - 19:26:18 | SHD ] F:\CD
[03/07/2010 - 14:34:38 | N | 0] F:\352948021606375.ndif
[09/07/2010 - 00:06:44 | SHD ] F:\Dj Budu Dj Kilesse - Funk Mania (2010)
[09/07/2010 - 00:09:00 | SHD ] F:\Mega Dance Live vol 2
[22/07/2010 - 13:59:58 | A | 289] F:\CD.lnk
[22/07/2010 - 13:59:58 | A | 289] F:\Dj Budu Dj Kilesse - Funk Mania (2010).lnk
[22/07/2010 - 13:59:58 | A | 289] F:\Mega Dance Live vol 2.lnk
[22/07/2010 - 13:59:58 | A | 289] F:\Imagens.lnk
[22/07/2010 - 14:00:00 | A | 289] F:\Jogos.lnk
[22/07/2010 - 13:50:50 | | 131] F:\autorun.inf
[22/07/2010 - 13:51:10 | SHD ] F:\Playlists
[22/07/2010 - 13:59:58 | A | 289] F:\Playlists.lnk
[22/07/2010 - 13:55:12 | SH | 70] F:\Bin
[22/07/2010 - 13:55:12 | SH | 70] F:\Driver
[22/07/2010 - 13:55:12 | SH | 70] F:\MSOCache
[22/07/2010 - 13:55:12 | SH | 70] F:\Recycled
[22/07/2010 - 13:55:12 | SH | 70] F:\Restore
[22/07/2010 - 13:55:12 | SH | 70] F:\System Volume Information
[09/08/2010 - 16:42:42 | AD ] F:\Videoclipes
[22/07/2010 - 13:59:56 | A | 289] F:\RECYCLER.lnk
[22/07/2010 - 13:59:58 | A | 289] F:\FOUND.000.lnk
[22/07/2010 - 13:59:58 | A | 289] F:\FOUND.001.lnk
[22/07/2010 - 13:59:58 | A | 289] F:\Others.lnk
[22/07/2010 - 13:59:58 | A | 289] F:\RECYCLER32.lnk
[27/01/2010 - 16:13:58 | ASH | 135168] F:\WMLicense.dat
[23/04/2009 - 23:35:04 | SHD ] F:\Videos
[27/04/2009 - 21:54:08 | SHD ] F:\Imagens
[23/04/2009 - 23:35:20 | SHD ] F:\Others
[23/04/2009 - 23:36:42 | SHD ] F:\Music
[18/03/2010 - 01:08:46 | SHD ] F:\Jogos
################## | Vaccin |
C:\Autorun.inf -> Folder criado por UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Folder criado por UsbFix (El Desaparecido & C_XX)
F:\Autorun.inf -> Folder criado por Panda USB Vaccine
################## | Upload |
Favor enviar o arquivo: C:\UsbFix_Upload_Me_FELIPE.zip
http://chiquitine.changelog.fr/Sample/Upload.php
Obrigado pela sua contribuição.
################## | E.O.F |
E agora? posso formatar o cartao que nao vai voltar as paradas das pastas transformadas em atalhos nao?
1.
Favor enviar o arquivo: C:\UsbFix_Upload_Me_FELIPE.zip para o link abaixo
http://chiquitine.changelog.fr/Sample/Upload.php
Obrigado pela sua contribuição.
2.
*Execute o UsbFix
*Clique em [uninstall]
3.
Conecte o pendrive no PC
Informe se alguma pasta já tem acesso. Apenas visualize.
Nao tinha acesso a nenhuma pasta...
ai eu formatei o pen drive, botei o usbfix pra pesquisar de novo e no log nao tinha nada...
acho q ta resolvido!
Obrigado!
PROBLEMA RESOLVIDO!
Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.
Bom...o que você pode fazer é desativar o autorun das unidades removíveis.
http://support.microsoft.com/kb/967715/pt-br
Se der para salvar algum programa ou arquivo conhecido no pen drive, faça. Porém, já vi casos em que só formatando o pen drive.
Depois de formatar, basta ativar novamente o autorun se desejar.
Outra possibilidade é usar um live cd do Linux para copiar e gravar os seus arquivos.