ItaloCCSL 0 Denunciar post Postado Julho 9, 2008 Pessoal apareceu um erro na minha maquina no aplicativo update.exe. Ele vem assim: ---------------------------------------------------------------------------------------------------------------- updadt,exe - Erro de aplicativo A instrução no "0x7c35042b" fez referência no "0x00000000". A memória não pôde ser "written". Clique em 'OK' para encerrar o programa Clique em 'Cancelar' para depurar o programa ---------------------------------------------------------------------------------------------------------------- Alguém sabe o que devo fazer? Meu log do hijackthis tai: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:27, on 2008-07-08 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PCSuite.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\cmpe.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe C:\Arquivos de programas\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Arquivos de programas\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Ares\Ares.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\system32\dwwin.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ibest.com.br/site/default_ck.js...odigo=001.00001 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll O2 - BHO: (no name) - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - (no file) O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [sMSERIAL] sm56hlpr.exe O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKCU\..\Run: [TaskSwitchXP] C:\Arquivos de programas\TaskSwitchXP\TaskSwitchXP.exe O4 - HKCU\..\Run: [XPize Darkside Reloader] C:\WINDOWS\XPize Darkside\XPize Darkside Reloader.exe /S O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h O4 - HKCU\..\Run: [PC Suite Tray] "C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Arquivos de programas\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user') O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{34BD16B8-3235-463F-AF47-A34F1D4535A4}: NameServer = 200.165.132.155 200.149.55.140 O17 - HKLM\System\CS2\Services\Tcpip\..\{34BD16B8-3235-463F-AF47-A34F1D4535A4}: NameServer = 200.165.132.155 200.149.55.140 O20 - Winlogon Notify: GbiehCef - C:\ARQUIV~1\GBPLUG~1\gbiehcef.dll (file missing) O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe -- End of file - 8152 bytes Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Julho 10, 2008 Opa ItaloCCSL, Baixe o ComboFix em: ComboFix 1) Desabilite o seu anti-vírus temporariamente; 2) Dê um duplo-clique no combofix.exe e tecle "1" para prosseguir. O processo vai durar, em média, 10 minutos; 3) O ComboFix reiniciará o PC automaticamente, a fim de que o processo de remoção seja finalizado (somente se houver infecção); 4) Quando a varredura acabar, será gerado um log, que estará em C:\ComboFix.txt; 5) Não clique na janela do ComboFix, nem feche clicando no X, enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco); 6) Para parar ou sair do ComboFix, tecle "N"; 7) Reabilite o seu anti-vírus; 8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
ItaloCCSL 0 Denunciar post Postado Julho 11, 2008 Caro jgarcia, Aqui está o conteúdo do ComboFix.txt: ComboFix 08-07-11.1 - Ítalo César 2008-07-11 18:47:13.4 - NTFSx86 MINIMAL Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.114 [GMT -3:00] Executando de: C:\Documents and Settings\Ítalo César.HOME\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((( Ficheiros criados de 2008-06-11 to 2008-07-11 )))))))))))))))))))))))))))))))) . 2008-07-06 10:15 . 2008-07-06 10:15 <DIR> d----c--- C:\!KillBox 2008-07-05 23:09 . 2008-07-05 23:10 <DIR> d----c--- C:\Arquivos de programas\eMule 2008-07-05 22:17 . 2008-07-05 22:18 <DIR> d----c--- C:\Arquivos de programas\Ares 2008-07-05 20:54 . 2008-07-05 20:54 <DIR> d----c--- C:\Arquivos de programas\Trend Micro 2008-07-04 20:47 . 2008-07-04 20:47 <DIR> d----c--- C:\HijackThis 2008-07-03 18:57 . 2006-10-04 11:06 1,197,294 --a--c--- C:\WINDOWS\system32\dllcache\SETA0.tmp 2008-07-02 22:51 . 2008-07-03 19:14 <DIR> d----c--- C:\Arquivos de programas\NitroPC 2008-06-26 19:05 . 2008-06-26 19:05 <DIR> d----c--- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Yahoo! Companion 2008-06-26 19:04 . 2008-06-26 19:04 <DIR> d----c--- C:\WINDOWS\Sun 2008-06-11 09:57 . 2008-06-14 14:59 272,384 -----c--- C:\WINDOWS\system32\drivers\bthport.sys 2008-06-11 09:57 . 2008-06-14 14:59 272,384 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-27 02:23 --------- dc----w C:\Documents and Settings\Ítalo César.HOME\Dados de aplicativos\Shareaza 2008-06-26 19:31 --------- dc----w C:\Arquivos de programas\RocketDock 2008-06-26 19:30 --------- dc----w C:\Arquivos de programas\OnGame 2008-06-26 17:23 --------- dc----w C:\Arquivos de programas\MediaCoder 2008-06-26 04:45 --------- dc----w C:\Arquivos de programas\Microsoft Works 2008-06-20 17:41 247,808 -c--a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 -c--a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 -c--a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-18 08:57 --------- dc----w C:\Arquivos de programas\Yahoo! 2008-06-08 18:32 --------- dc----w C:\Arquivos de programas\VideoLAN 2008-06-08 18:30 --------- dc----w C:\Arquivos de programas\Megacubo 2008-06-07 00:07 --------- dc----w C:\Arquivos de programas\SopCast 2008-05-22 17:39 --------- dc----w C:\Arquivos de programas\VisualTaskTips 2008-05-22 17:37 --------- dc----w C:\Arquivos de programas\FlashGet 2008-05-07 05:15 2,660,864 -c--a-w C:\WINDOWS\system32\quartz.dll 2008-04-21 07:02 661,504 -c--a-w C:\WINDOWS\system32\wininet.dll 2007-07-20 04:19 855,886 -c--a-w C:\Arquivos de programas\AUG2007_d3dx10_35_x64.cab 2007-07-20 04:19 800,467 -c--a-w C:\Arquivos de programas\AUG2007_d3dx10_35_x86.cab 2007-07-20 04:19 1,803,760 -c--a-w C:\Arquivos de programas\AUG2007_d3dx9_35_x64.cab 2007-07-20 04:18 44,684 -c--a-w C:\Arquivos de programas\dxdllreg_x86.cab 2007-07-20 04:18 201,696 -c--a-w C:\Arquivos de programas\AUG2007_XACT_x64.cab 2007-07-20 04:18 156,612 -c--a-w C:\Arquivos de programas\AUG2007_XACT_x86.cab 2007-07-20 04:18 1,711,752 -c--a-w C:\Arquivos de programas\AUG2007_d3dx9_35_x86.cab 2007-07-03 01:43 171,008 -c--a-w C:\Arquivos de programas\FLV PlayerRCSetup.exe 2007-03-15 00:36 87,608 -c--a-w C:\Documents and Settings\Ítalo César\Dados de aplicativos\ezpinst.exe 2007-03-15 00:36 47,360 -c--a-w C:\Documents and Settings\Ítalo César\Dados de aplicativos\pcouffin.sys 2007-01-29 22:17 18,096 -c--a-w C:\Documents and Settings\Ítalo César\Dados de aplicativos\GDIPFONTCACHEV1.DAT 2004-10-01 18:00 40,960 -c--a-w C:\Arquivos de programas\Uninstall_CDS.exe . ------- Sigcheck ------- 2007-06-13 10:21 1697280 07a1a28907a5f2a251b3b2564884d730 C:\WINDOWS\explorer.exe 2007-06-13 10:10 1035264 45d521506825a10b80833b4e9621ccf6 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe 2004-08-04 00:45 1034240 fa61a19050ae14bec1a26de82390dd65 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe 2007-06-13 10:21 1697280 07a1a28907a5f2a251b3b2564884d730 C:\WINDOWS\system32\dllcache\explorer.exe 2007-06-13 10:21 1035264 dccbf18e94d651393a3ffa060f88e0a0 C:\WINDOWS\XPize Darkside\Backup\explorer.exe 2004-08-04 00:45 30208 c44b39505116f6961988b8681793e572 C:\WINDOWS\system32\ctfmon.exe 2004-08-04 00:45 30208 c44b39505116f6961988b8681793e572 C:\WINDOWS\system32\dllcache\ctfmon.exe 2004-08-04 00:45 15360 f40bc97996b8e53799eef1d63996674b C:\WINDOWS\XPize Darkside\Backup\ctfmon.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TaskSwitchXP"="C:\Arquivos de programas\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 19:29 62976] "XPize Darkside Reloader"="C:\WINDOWS\XPize Darkside\XPize Darkside Reloader.exe" [2007-10-12 12:12 112737] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 30208] "ares"="C:\Arquivos de programas\Ares\Ares.exe" [2007-07-16 18:54 961536] "PC Suite Tray"="C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 09:12 695808] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-07 21:31 155648] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-07 21:27 126976] "QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-03-02 21:24 282624] "avgnt"="C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-30 13:37 262401] "desp2k"="C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe" [2006-08-03 16:05 65536] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "SoundMan"="SOUNDMAN.EXE" [2005-12-14 18:06 593920 C:\WINDOWS\Soundman.exe] "SMSERIAL"="sm56hlpr.exe" [2005-07-05 17:47 544768 C:\WINDOWS\sm56hlpr.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Nokia.PCSync"="C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 16:35 1294336] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3codecp"= l3codecp.acm [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\Arquivos de programas\\Ares\\Ares.exe"= "C:\\Arquivos de programas\\eMule\\eMule.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "34162:TCP"= 34162:TCP:AresChatServer S2 cmpe;Context Manager Process Extension;C:\WINDOWS\system32\cmpe.exe [2007-02-26 11:11] S3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS [2002-06-10 00:09] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6eb05430-d7f5-11dc-9398-000fead92af6}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wbsinstalls.exe \Shell\infected\command - F:\wbsinstalls.exe *Newly Created Service* - MDMXSDK . Conteúdo da pasta 'Tarefas Agendadas' "2008-07-11 21:00:03 C:\WINDOWS\Tasks\A5C7D765918C52D1.job" - c:\docume~1\talocs~1.hom\dadosd~1\slownu~1\Bird Wave Find.exe "2008-07-11 20:43:27 C:\WINDOWS\Tasks\Verificar Atualizações para a Barra de Ferramentas do Windows Live.job" - C:\Arquivos de programas\Windows Live Toolbar\MSNTBUP.EXE . - - - - ORPHANS REMOVED - - - - HKLM-Run-Cmaudio - cmicnfg.cpl HKU-Default-Run-Picasa Media Detector - C:\Arquivos de programas\Picasa2\PicasaMediaDetector.exe Notify- GbiehCef - C:\ARQUIV~1\GBPLUG~1\gbiehcef.dll Notify-WgaLogon - (no file) ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-11 18:51:27 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\system32\winlogon.exe -> C:\WINDOWS\system32\tsd32.dll . Tempo para conclusão: 2008-07-11 18:56:36 ComboFix-quarantined-files.txt 2008-07-11 21:55:26 Pre-Run: 35,075,280,896 bytes disponíveis Post-Run: 35,066,839,040 bytes disponíveis 131 --- E O F --- 2008-07-09 23:44:41 :!: Cara tem um membro que está me ajudando com outro erro aqui nesse fórum tem algum problema? Eu criei três tópicos: O primeiro foi "RUNDLL GBPLUG" fui ajudado por um membro chamado Silas. Ele resolveu o problema do tópico, mas no decorrer das ações surgiu outro erro que foi postado no mesmo tópico. E agora o Silas disse que um moderador iria me atender e até hoje não fui atendido. Só houve uma resposta do Administrador mas era falando com o Silas para ele voltar a me ajudar mas o cara parece que não sabe como resolver esse erro. O segundo que criei foi "Problemas com o windows media player" e nesse novamente o Silas está me ajudando agora. O terceiro é esse. jgarcia o que eu fiz foi correto? Ter criado outros tópicos só que com erros diferentes. Você poderia dar uma olhada nos outros e me ajudar com o primeiro?( Todos estão nessa área)(Segurança & Malwares) Eu te agradecerei muito se puderes. :thumbsup: Não tenho muita experiência com computadores. :mellow: Desculpa se cometi algum erro, que é contra as normas do fórum. :unsure: Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Julho 12, 2008 Opa ItaloCCSL, Siga as instruções: 1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": File::C:\Documents and Settings\Ítalo César\Dados de aplicativos\ezpinst.exe C:\Documents and Settings\Ítalo César\Dados de aplicativos\pcouffin.sys C:\Documents and Settings\Ítalo César\Dados de aplicativos\GDIPFONTCACHEV1.DAT c:\docume~1\talocs~1.hom\dadosd~1\slownu~1\Bird Wave Find.exe C:\WINDOWS\Tasks\A5C7D765918C52D1.job F:\wbsinstalls.exe Folder:: c:\docume~1\talocs~1.hom\dadosd~1\slownu~1 Registry:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6eb05430-d7f5-11dc-9398-000fead92af6}] ATENÇÃO: O script acima foi elaborado especifícamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 2. Salve o arquivo como CFScript.txt; 3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. PS.: Darei uma olhada em seus outros tópicos. Dica: Quando os problemas pertencerem à uma mesma máquina basta criar um tópico. :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
ItaloCCSL 0 Denunciar post Postado Julho 13, 2008 jgarcia, No término do combofix ele gerou isso: ComboFix 08-07-11.1 - Ítalo César 2008-07-13 9:21:06.5 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.78 [GMT -3:00] Executando de: C:\Documents and Settings\Ítalo César.HOME\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Ítalo César.HOME\Desktop\CFScript.txt * Criado um novo ponto de restauro WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE :: c:\docume~1\talocs~1.hom\dadosd~1\slownu~1\Bird Wave Find.exe C:\Documents and Settings\Ítalo César\Dados de aplicativos\ezpinst.exe C:\Documents and Settings\Ítalo César\Dados de aplicativos\GDIPFONTCACHEV1.DAT C:\Documents and Settings\Ítalo César\Dados de aplicativos\pcouffin.sys C:\WINDOWS\Tasks\A5C7D765918C52D1.job F:\wbsinstalls.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\talocs~1.hom\dadosd~1\slownu~1 c:\docume~1\talocs~1.hom\dadosd~1\slownu~1\0 C:\Documents and Settings\Ítalo César\Dados de aplicativos\ezpinst.exe C:\Documents and Settings\Ítalo César\Dados de aplicativos\GDIPFONTCACHEV1.DAT C:\Documents and Settings\Ítalo César\Dados de aplicativos\pcouffin.sys C:\WINDOWS\Tasks\A5C7D765918C52D1.job . ((((((((((((((((((((((( Ficheiros criados de 2008-06-13 to 2008-07-13 )))))))))))))))))))))))))))))))) . 2008-07-10 13:06 . 2008-07-10 13:06 <DIR> d----c--- C:\Documents and Settings\Ítalo César.HOME\Start Menu 2008-07-10 13:06 . 2008-07-10 13:06 <DIR> d----c--- C:\Documents and Settings\Ítalo César.HOME\Start Menu 2008-07-06 10:15 . 2008-07-06 10:15 <DIR> d----c--- C:\!KillBox 2008-07-05 23:09 . 2008-07-05 23:10 <DIR> d----c--- C:\Arquivos de programas\eMule 2008-07-05 22:17 . 2008-07-05 22:18 <DIR> d----c--- C:\Arquivos de programas\Ares 2008-07-05 20:54 . 2008-07-05 20:54 <DIR> d----c--- C:\Arquivos de programas\Trend Micro 2008-07-05 19:56 . 2008-07-13 09:14 <DIR> dr-h-c--- C:\Documents and Settings\Ítalo César.HOME\Recent 2008-07-05 19:56 . 2008-07-13 09:14 <DIR> dr-h-c--- C:\Documents and Settings\Ítalo César.HOME\Recent 2008-07-04 20:47 . 2008-07-04 20:47 <DIR> d----c--- C:\HijackThis 2008-07-03 18:57 . 2006-10-04 11:06 1,197,294 --a--c--- C:\WINDOWS\system32\dllcache\SETA0.tmp 2008-07-02 22:51 . 2008-07-03 19:14 <DIR> d----c--- C:\Arquivos de programas\NitroPC 2008-07-02 12:53 . 2008-07-12 22:07 8,388,608 --a------ C:\Documents and Settings\Ítalo César.HOME\ntuser.dat 2008-07-02 12:53 . 2008-07-12 22:07 8,388,608 --a------ C:\Documents and Settings\Ítalo César.HOME\ntuser.dat 2008-06-26 19:05 . 2008-06-26 19:05 <DIR> d----c--- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Yahoo! Companion 2008-06-26 19:04 . 2008-06-26 19:04 <DIR> d----c--- C:\WINDOWS\Sun 2008-06-26 19:04 . 2008-06-26 19:04 <DIR> d----c--- C:\Documents and Settings\Ítalo César.HOME\Dados de aplicativos\Sun . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-27 02:23 --------- dc----w C:\Documents and Settings\Ítalo César.HOME\Dados de aplicativos\Shareaza 2008-06-26 19:31 --------- dc----w C:\Arquivos de programas\RocketDock 2008-06-26 19:30 --------- dc----w C:\Arquivos de programas\OnGame 2008-06-26 17:23 --------- dc----w C:\Arquivos de programas\MediaCoder 2008-06-26 04:45 --------- dc----w C:\Arquivos de programas\Microsoft Works 2008-06-20 17:41 247,808 -c--a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 -c--a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 -c--a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-18 08:57 --------- dc----w C:\Arquivos de programas\Yahoo! 2008-06-14 17:59 272,384 -c----w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-08 18:32 --------- dc----w C:\Arquivos de programas\VideoLAN 2008-06-08 18:30 --------- dc----w C:\Arquivos de programas\Megacubo 2008-06-07 00:07 --------- dc----w C:\Arquivos de programas\SopCast 2008-05-22 17:39 --------- dc----w C:\Arquivos de programas\VisualTaskTips 2008-05-22 17:37 --------- dc----w C:\Arquivos de programas\FlashGet 2008-05-07 05:15 2,660,864 -c--a-w C:\WINDOWS\system32\quartz.dll 2008-04-21 07:02 661,504 -c--a-w C:\WINDOWS\system32\wininet.dll 2007-07-20 04:19 855,886 -c--a-w C:\Arquivos de programas\AUG2007_d3dx10_35_x64.cab 2007-07-20 04:19 800,467 -c--a-w C:\Arquivos de programas\AUG2007_d3dx10_35_x86.cab 2007-07-20 04:19 1,803,760 -c--a-w C:\Arquivos de programas\AUG2007_d3dx9_35_x64.cab 2007-07-20 04:18 44,684 -c--a-w C:\Arquivos de programas\dxdllreg_x86.cab 2007-07-20 04:18 201,696 -c--a-w C:\Arquivos de programas\AUG2007_XACT_x64.cab 2007-07-20 04:18 156,612 -c--a-w C:\Arquivos de programas\AUG2007_XACT_x86.cab 2007-07-20 04:18 1,711,752 -c--a-w C:\Arquivos de programas\AUG2007_d3dx9_35_x86.cab 2007-07-03 01:43 171,008 -c--a-w C:\Arquivos de programas\FLV PlayerRCSetup.exe 2004-10-01 18:00 40,960 -c--a-w C:\Arquivos de programas\Uninstall_CDS.exe . ------- Sigcheck ------- 2007-06-13 10:21 1697280 07a1a28907a5f2a251b3b2564884d730 C:\WINDOWS\explorer.exe 2007-06-13 10:10 1035264 45d521506825a10b80833b4e9621ccf6 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe 2004-08-04 00:45 1034240 fa61a19050ae14bec1a26de82390dd65 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe 2007-06-13 10:21 1697280 07a1a28907a5f2a251b3b2564884d730 C:\WINDOWS\system32\dllcache\explorer.exe 2007-06-13 10:21 1035264 dccbf18e94d651393a3ffa060f88e0a0 C:\WINDOWS\XPize Darkside\Backup\explorer.exe 2004-08-04 00:45 30208 c44b39505116f6961988b8681793e572 C:\WINDOWS\system32\ctfmon.exe 2004-08-04 00:45 30208 c44b39505116f6961988b8681793e572 C:\WINDOWS\system32\dllcache\ctfmon.exe 2004-08-04 00:45 15360 f40bc97996b8e53799eef1d63996674b C:\WINDOWS\XPize Darkside\Backup\ctfmon.exe . ((((((((((((((((((((((((((((( snapshot@2008-07-11_18.54.33.89 ))))))))))))))))))))))))))))))))))))))))) . - 2008-07-11 21:41:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-07-13 11:25:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TaskSwitchXP"="C:\Arquivos de programas\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 19:29 62976] "XPize Darkside Reloader"="C:\WINDOWS\XPize Darkside\XPize Darkside Reloader.exe" [2007-10-12 12:12 112737] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 30208] "ares"="C:\Arquivos de programas\Ares\Ares.exe" [2007-07-16 18:54 961536] "PC Suite Tray"="C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 09:12 695808] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-07 21:31 155648] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-07 21:27 126976] "QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-03-02 21:24 282624] "avgnt"="C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-30 13:37 262401] "desp2k"="C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe" [2006-08-03 16:05 65536] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "SoundMan"="SOUNDMAN.EXE" [2005-12-14 18:06 593920 C:\WINDOWS\Soundman.exe] "SMSERIAL"="sm56hlpr.exe" [2005-07-05 17:47 544768 C:\WINDOWS\sm56hlpr.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Nokia.PCSync"="C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 16:35 1294336] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3codecp"= l3codecp.acm [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\Arquivos de programas\\Ares\\Ares.exe"= "C:\\Arquivos de programas\\eMule\\eMule.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "34162:TCP"= 34162:TCP:AresChatServer R2 cmpe;Context Manager Process Extension;C:\WINDOWS\system32\cmpe.exe [2007-02-26 11:11] R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS [2002-06-10 00:09] . Conteúdo da pasta 'Tarefas Agendadas' "2008-07-13 11:43:09 C:\WINDOWS\Tasks\Verificar Atualizações para a Barra de Ferramentas do Windows Live.job" - C:\Arquivos de programas\Windows Live Toolbar\MSNTBUP.EXE . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-13 09:25:16 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-07-13 9:33:50 ComboFix-quarantined-files.txt 2008-07-13 12:33:10 ComboFix2.txt 2008-07-11 21:56:38 Pre-Run: 34,622,357,504 bytes disponíveis Post-Run: 34,630,045,696 bytes disponíveis 145 --- E O F --- 2008-07-09 23:44:41 Amigo não sei se já é o que você me pediu eu sei que o do combofix, mas foi o próprio combofix que gerou ele. Mesmo assim segue o que você me pediu (C:\ComboFix.txt): ComboFix 08-07-11.1 - Ítalo César 2008-07-13 9:21:06.5 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.78 [GMT -3:00] Executando de: C:\Documents and Settings\Ítalo César.HOME\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Ítalo César.HOME\Desktop\CFScript.txt * Criado um novo ponto de restauro WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE :: c:\docume~1\talocs~1.hom\dadosd~1\slownu~1\Bird Wave Find.exe C:\Documents and Settings\Ítalo César\Dados de aplicativos\ezpinst.exe C:\Documents and Settings\Ítalo César\Dados de aplicativos\GDIPFONTCACHEV1.DAT C:\Documents and Settings\Ítalo César\Dados de aplicativos\pcouffin.sys C:\WINDOWS\Tasks\A5C7D765918C52D1.job F:\wbsinstalls.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\talocs~1.hom\dadosd~1\slownu~1 c:\docume~1\talocs~1.hom\dadosd~1\slownu~1\0 C:\Documents and Settings\Ítalo César\Dados de aplicativos\ezpinst.exe C:\Documents and Settings\Ítalo César\Dados de aplicativos\GDIPFONTCACHEV1.DAT C:\Documents and Settings\Ítalo César\Dados de aplicativos\pcouffin.sys C:\WINDOWS\Tasks\A5C7D765918C52D1.job . ((((((((((((((((((((((( Ficheiros criados de 2008-06-13 to 2008-07-13 )))))))))))))))))))))))))))))))) . 2008-07-10 13:06 . 2008-07-10 13:06 <DIR> d----c--- C:\Documents and Settings\Ítalo César.HOME\Start Menu 2008-07-10 13:06 . 2008-07-10 13:06 <DIR> d----c--- C:\Documents and Settings\Ítalo César.HOME\Start Menu 2008-07-06 10:15 . 2008-07-06 10:15 <DIR> d----c--- C:\!KillBox 2008-07-05 23:09 . 2008-07-05 23:10 <DIR> d----c--- C:\Arquivos de programas\eMule 2008-07-05 22:17 . 2008-07-05 22:18 <DIR> d----c--- C:\Arquivos de programas\Ares 2008-07-05 20:54 . 2008-07-05 20:54 <DIR> d----c--- C:\Arquivos de programas\Trend Micro 2008-07-05 19:56 . 2008-07-13 09:14 <DIR> dr-h-c--- C:\Documents and Settings\Ítalo César.HOME\Recent 2008-07-05 19:56 . 2008-07-13 09:14 <DIR> dr-h-c--- C:\Documents and Settings\Ítalo César.HOME\Recent 2008-07-04 20:47 . 2008-07-04 20:47 <DIR> d----c--- C:\HijackThis 2008-07-03 18:57 . 2006-10-04 11:06 1,197,294 --a--c--- C:\WINDOWS\system32\dllcache\SETA0.tmp 2008-07-02 22:51 . 2008-07-03 19:14 <DIR> d----c--- C:\Arquivos de programas\NitroPC 2008-07-02 12:53 . 2008-07-12 22:07 8,388,608 --a------ C:\Documents and Settings\Ítalo César.HOME\ntuser.dat 2008-07-02 12:53 . 2008-07-12 22:07 8,388,608 --a------ C:\Documents and Settings\Ítalo César.HOME\ntuser.dat 2008-06-26 19:05 . 2008-06-26 19:05 <DIR> d----c--- C:\Documents and Settings\All Users.WINDOWS\Dados de aplicativos\Yahoo! Companion 2008-06-26 19:04 . 2008-06-26 19:04 <DIR> d----c--- C:\WINDOWS\Sun 2008-06-26 19:04 . 2008-06-26 19:04 <DIR> d----c--- C:\Documents and Settings\Ítalo César.HOME\Dados de aplicativos\Sun . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-27 02:23 --------- dc----w C:\Documents and Settings\Ítalo César.HOME\Dados de aplicativos\Shareaza 2008-06-26 19:31 --------- dc----w C:\Arquivos de programas\RocketDock 2008-06-26 19:30 --------- dc----w C:\Arquivos de programas\OnGame 2008-06-26 17:23 --------- dc----w C:\Arquivos de programas\MediaCoder 2008-06-26 04:45 --------- dc----w C:\Arquivos de programas\Microsoft Works 2008-06-20 17:41 247,808 -c--a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 10:45 360,320 -c--a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44 138,368 -c--a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52 225,920 -c--a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-18 08:57 --------- dc----w C:\Arquivos de programas\Yahoo! 2008-06-14 17:59 272,384 -c----w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-08 18:32 --------- dc----w C:\Arquivos de programas\VideoLAN 2008-06-08 18:30 --------- dc----w C:\Arquivos de programas\Megacubo 2008-06-07 00:07 --------- dc----w C:\Arquivos de programas\SopCast 2008-05-22 17:39 --------- dc----w C:\Arquivos de programas\VisualTaskTips 2008-05-22 17:37 --------- dc----w C:\Arquivos de programas\FlashGet 2008-05-07 05:15 2,660,864 -c--a-w C:\WINDOWS\system32\quartz.dll 2008-04-21 07:02 661,504 -c--a-w C:\WINDOWS\system32\wininet.dll 2007-07-20 04:19 855,886 -c--a-w C:\Arquivos de programas\AUG2007_d3dx10_35_x64.cab 2007-07-20 04:19 800,467 -c--a-w C:\Arquivos de programas\AUG2007_d3dx10_35_x86.cab 2007-07-20 04:19 1,803,760 -c--a-w C:\Arquivos de programas\AUG2007_d3dx9_35_x64.cab 2007-07-20 04:18 44,684 -c--a-w C:\Arquivos de programas\dxdllreg_x86.cab 2007-07-20 04:18 201,696 -c--a-w C:\Arquivos de programas\AUG2007_XACT_x64.cab 2007-07-20 04:18 156,612 -c--a-w C:\Arquivos de programas\AUG2007_XACT_x86.cab 2007-07-20 04:18 1,711,752 -c--a-w C:\Arquivos de programas\AUG2007_d3dx9_35_x86.cab 2007-07-03 01:43 171,008 -c--a-w C:\Arquivos de programas\FLV PlayerRCSetup.exe 2004-10-01 18:00 40,960 -c--a-w C:\Arquivos de programas\Uninstall_CDS.exe . ------- Sigcheck ------- 2007-06-13 10:21 1697280 07a1a28907a5f2a251b3b2564884d730 C:\WINDOWS\explorer.exe 2007-06-13 10:10 1035264 45d521506825a10b80833b4e9621ccf6 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe 2004-08-04 00:45 1034240 fa61a19050ae14bec1a26de82390dd65 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe 2007-06-13 10:21 1697280 07a1a28907a5f2a251b3b2564884d730 C:\WINDOWS\system32\dllcache\explorer.exe 2007-06-13 10:21 1035264 dccbf18e94d651393a3ffa060f88e0a0 C:\WINDOWS\XPize Darkside\Backup\explorer.exe 2004-08-04 00:45 30208 c44b39505116f6961988b8681793e572 C:\WINDOWS\system32\ctfmon.exe 2004-08-04 00:45 30208 c44b39505116f6961988b8681793e572 C:\WINDOWS\system32\dllcache\ctfmon.exe 2004-08-04 00:45 15360 f40bc97996b8e53799eef1d63996674b C:\WINDOWS\XPize Darkside\Backup\ctfmon.exe . ((((((((((((((((((((((((((((( snapshot@2008-07-11_18.54.33.89 ))))))))))))))))))))))))))))))))))))))))) . - 2008-07-11 21:41:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-07-13 11:25:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & legítimas por defeito não são mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TaskSwitchXP"="C:\Arquivos de programas\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 19:29 62976] "XPize Darkside Reloader"="C:\WINDOWS\XPize Darkside\XPize Darkside Reloader.exe" [2007-10-12 12:12 112737] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:45 30208] "ares"="C:\Arquivos de programas\Ares\Ares.exe" [2007-07-16 18:54 961536] "PC Suite Tray"="C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 09:12 695808] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-07 21:31 155648] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-07 21:27 126976] "QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-03-02 21:24 282624] "avgnt"="C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-30 13:37 262401] "desp2k"="C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe" [2006-08-03 16:05 65536] "SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784] "SoundMan"="SOUNDMAN.EXE" [2005-12-14 18:06 593920 C:\WINDOWS\Soundman.exe] "SMSERIAL"="sm56hlpr.exe" [2005-07-05 17:47 544768 C:\WINDOWS\sm56hlpr.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Nokia.PCSync"="C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 16:35 1294336] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.l3codecp"= l3codecp.acm [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "C:\\Arquivos de programas\\Ares\\Ares.exe"= "C:\\Arquivos de programas\\eMule\\eMule.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "34162:TCP"= 34162:TCP:AresChatServer R2 cmpe;Context Manager Process Extension;C:\WINDOWS\system32\cmpe.exe [2007-02-26 11:11] R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS [2002-06-10 00:09] . Conteúdo da pasta 'Tarefas Agendadas' "2008-07-13 11:43:09 C:\WINDOWS\Tasks\Verificar Atualizações para a Barra de Ferramentas do Windows Live.job" - C:\Arquivos de programas\Windows Live Toolbar\MSNTBUP.EXE . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-13 09:25:16 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-07-13 9:33:50 ComboFix-quarantined-files.txt 2008-07-13 12:33:10 ComboFix2.txt 2008-07-11 21:56:38 Pre-Run: 34,622,357,504 bytes disponíveis Post-Run: 34,630,045,696 bytes disponíveis 145 --- E O F --- 2008-07-09 23:44:41 E o log do hijackthis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:40:04, on 13/7/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PCSuite.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\cmpe.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe C:\Arquivos de programas\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Arquivos de programas\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ibest.com.br/site/default_ck.js...odigo=001.00001 R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Arquivos de programas\Windows Live Toolbar\msntb.dll O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [sMSERIAL] sm56hlpr.exe O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKCU\..\Run: [TaskSwitchXP] C:\Arquivos de programas\TaskSwitchXP\TaskSwitchXP.exe O4 - HKCU\..\Run: [XPize Darkside Reloader] C:\WINDOWS\XPize Darkside\XPize Darkside Reloader.exe /S O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h O4 - HKCU\..\Run: [PC Suite Tray] "C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user') O8 - Extra context menu item: &Windows Live Search - res://C:\Arquivos de programas\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{34BD16B8-3235-463F-AF47-A34F1D4535A4}: NameServer = 200.165.132.155 200.149.55.140 O17 - HKLM\System\CS2\Services\Tcpip\..\{34BD16B8-3235-463F-AF47-A34F1D4535A4}: NameServer = 200.165.132.155 200.149.55.140 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe -- End of file - 7533 bytes Espero a sua resposta e que se possivel ajude-me com esse erro do desp2k.exe na wpcap.dll que postei no no meu primeiro tópico que foi o Rundll Gbplug. :thumbsup: Desculpa por ter criado outros tópicos. :unsure: Compartilhar este post Link para o post Compartilhar em outros sites
ItaloCCSL 0 Denunciar post Postado Julho 18, 2008 "Espero a sua resposta e que se possível ajude-me com esse erro do desp2k.exe na wpcap.dll que postei no no meu primeiro tópico que foi o Rundll Gbplug." O Silas voltou a me ajudar com esse erro. Você pode me ajudar com outra coisa? Eu estava realizando um limpeza no meu pc com o CClean e depois da limpeza vi que algumas caixas que ele analisa estavam desmarcadas. (Acho que elas já vem assim e creio que seja o recomendado.) Ai resolvi marca-las para ver o que aparecia e ele mostrou essa análise: ANÁLISE CONCLUÍDA - (232.717 segundo(s)) ------------------------------------------------------------------------------------------ 317,2MB para ser removido. (Tamanho aproximado) ------------------------------------------------------------------------------------------ Detalhes dos arquivos que serão removidos (Nota: Nenhum arquivo foi removido ainda) ------------------------------------------------------------------------------------------ C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log 1,49KB C:\WINDOWS\$NtUninstallKB873339$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB873339$\hypertrm.dll 0,33MB C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe 0,16MB C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.inf 5,30KB C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.txt 190 bytes C:\WINDOWS\$NtUninstallKB885835$\mrxsmb.sys 0,43MB C:\WINDOWS\$NtUninstallKB885835$\rdbss.sys 0,17MB C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe 0,16MB C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.inf 6,41KB C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.txt 330 bytes C:\WINDOWS\$NtUninstallKB885836$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB885836$\mswrd6.wpc 0,18MB C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe 0,16MB C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.inf 7,74KB C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.txt 213 bytes C:\WINDOWS\$NtUninstallKB886185$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB886185$\ipnat.sys 0,13MB C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe 0,16MB C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.inf 6,59KB C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.txt 286 bytes C:\WINDOWS\$NtUninstallKB887472$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB887472$\msmsgs.exe 1,59MB C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe 0,16MB C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.inf 7,08KB C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.txt 201 bytes C:\WINDOWS\$NtUninstallKB888302$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe 0,16MB C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.inf 6,64KB C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.txt 282 bytes C:\WINDOWS\$NtUninstallKB888302$\srvsvc.dll 94,50KB C:\WINDOWS\$NtUninstallKB890046$\agentdpv.dll 57,50KB C:\WINDOWS\$NtUninstallKB890046$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.inf 5,87KB C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.txt 330 bytes C:\WINDOWS\$NtUninstallKB890046$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB890859$\authz.dll 55,50KB C:\WINDOWS\$NtUninstallKB890859$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe 1,97MB C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe 2,08MB C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.inf 6,78KB C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.txt 1,18KB C:\WINDOWS\$NtUninstallKB890859$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB890859$\user32.dll 0,55MB C:\WINDOWS\$NtUninstallKB890859$\win32k.sys 1,75MB C:\WINDOWS\$NtUninstallKB890859$\winsrv.dll 0,28MB C:\WINDOWS\$NtUninstallKB891781$\dhtmled.ocx 0,12MB C:\WINDOWS\$NtUninstallKB891781$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe 0,16MB C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.inf 7,31KB C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.txt 332 bytes C:\WINDOWS\$NtUninstallKB893756$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB893756$\remotesp.tsp 75,00KB C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.inf 8,11KB C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.txt 477 bytes C:\WINDOWS\$NtUninstallKB893756$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB893756$\tapisrv.dll 0,23MB C:\WINDOWS\$NtUninstallKB894391$\ole32.dll 1,22MB C:\WINDOWS\$NtUninstallKB894391$\olecli32.dll 67,50KB C:\WINDOWS\$NtUninstallKB894391$\olecnv32.dll 33,50KB C:\WINDOWS\$NtUninstallKB894391$\rpcss.dll 0,38MB C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.inf 7,39KB C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.txt 740 bytes C:\WINDOWS\$NtUninstallKB894391$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB896358$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB896358$\hh.exe 10,50KB C:\WINDOWS\$NtUninstallKB896358$\hhctrl.ocx 0,50MB C:\WINDOWS\$NtUninstallKB896358$\hhsetup.dll 38,00KB C:\WINDOWS\$NtUninstallKB896358$\itircl.dll 0,14MB C:\WINDOWS\$NtUninstallKB896358$\itss.dll 0,13MB C:\WINDOWS\$NtUninstallKB896358$\reg00001 8,00KB C:\WINDOWS\$NtUninstallKB896358$\reg00002 8,00KB C:\WINDOWS\$NtUninstallKB896358$\reg00004 8,00KB C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.inf 7,29KB C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.txt 985 bytes C:\WINDOWS\$NtUninstallKB896358$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB896423$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe 56,50KB C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.inf 5,92KB C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.txt 286 bytes C:\WINDOWS\$NtUninstallKB896423$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB896428$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.inf 4,77KB C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.txt 282 bytes C:\WINDOWS\$NtUninstallKB896428$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB896428$\telnet.exe 75,00KB C:\WINDOWS\$NtUninstallKB898461$\eula.txt 3,98KB C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.inf 5,39KB C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.txt 562 bytes C:\WINDOWS\$NtUninstallKB898461$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB899587$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB899587$\kerberos.dll 0,28MB C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.inf 6,44KB C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.txt 290 bytes C:\WINDOWS\$NtUninstallKB899587$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB899591$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB899591$\rdpwd.sys 0,13MB C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.inf 7,91KB C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.txt 286 bytes C:\WINDOWS\$NtUninstallKB899591$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB900485$\aec.sys 0,14MB C:\WINDOWS\$NtUninstallKB900485$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.inf 8,41KB C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.txt 497 bytes C:\WINDOWS\$NtUninstallKB900485$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB900725$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB900725$\linkinfo.dll 18,50KB C:\WINDOWS\$NtUninstallKB900725$\shell32.dll 8,02MB C:\WINDOWS\$NtUninstallKB900725$\shlwapi.dll 0,45MB C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.inf 6,18KB C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.txt 851 bytes C:\WINDOWS\$NtUninstallKB900725$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB900725$\winsrv.dll 0,28MB C:\WINDOWS\$NtUninstallKB900725$\winsrv.dll.000 0,28MB C:\WINDOWS\$NtUninstallKB901017$\cdosys.dll 1,97MB C:\WINDOWS\$NtUninstallKB901017$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.inf 6,26KB C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.txt 282 bytes C:\WINDOWS\$NtUninstallKB901017$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB901214$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB901214$\icm32.dll 0,24MB C:\WINDOWS\$NtUninstallKB901214$\mscms.dll 72,00KB C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.inf 5,46KB C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.txt 457 bytes C:\WINDOWS\$NtUninstallKB901214$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB902400$\catsrv.dll 0,22MB C:\WINDOWS\$NtUninstallKB902400$\catsrvut.dll 0,60MB C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll 0,10MB C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll 0,48MB C:\WINDOWS\$NtUninstallKB902400$\colbact.dll 61,00KB C:\WINDOWS\$NtUninstallKB902400$\comadmin.dll 0,19MB C:\WINDOWS\$NtUninstallKB902400$\comrepl.dll 80,50KB C:\WINDOWS\$NtUninstallKB902400$\comsvcs.dll 1,19MB C:\WINDOWS\$NtUninstallKB902400$\comuid.dll 0,52MB C:\WINDOWS\$NtUninstallKB902400$\es.dll 0,23MB C:\WINDOWS\$NtUninstallKB902400$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB902400$\migregdb.exe 7,50KB C:\WINDOWS\$NtUninstallKB902400$\ole32.dll 1,23MB C:\WINDOWS\$NtUninstallKB902400$\ole32.dll.000 1,23MB C:\WINDOWS\$NtUninstallKB902400$\olecli32.dll 73,50KB C:\WINDOWS\$NtUninstallKB902400$\olecli32.dll.000 73,50KB C:\WINDOWS\$NtUninstallKB902400$\olecnv32.dll 37,00KB C:\WINDOWS\$NtUninstallKB902400$\rpcss.dll 0,38MB C:\WINDOWS\$NtUninstallKB902400$\rpcss.dll.000 0,38MB C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.inf 12,59KB C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.txt 2,92KB C:\WINDOWS\$NtUninstallKB902400$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB902400$\txflog.dll 99,00KB C:\WINDOWS\$NtUninstallKB904706$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB904706$\quartz.dll 1,23MB C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.inf 5,31KB C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.txt 459 bytes C:\WINDOWS\$NtUninstallKB904706$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB905414$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB905414$\netman.dll 0,19MB C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.inf 7,05KB C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.txt 282 bytes C:\WINDOWS\$NtUninstallKB905414$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB905749$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.inf 4,44KB C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.txt 290 bytes C:\WINDOWS\$NtUninstallKB905749$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB905749$\umpnpmgr.dll 0,11MB C:\WINDOWS\$NtUninstallKB908519$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB908519$\fontsub.dll 77,50KB C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.inf 5,42KB C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.txt 707 bytes C:\WINDOWS\$NtUninstallKB908519$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB908519$\t2embed.dll 0,20MB C:\WINDOWS\$NtUninstallKB908531$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB908531$\shell32.dll 8,09MB C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.inf 8,36KB C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.txt 619 bytes C:\WINDOWS\$NtUninstallKB908531$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB910437$\esent.dll 1,04MB C:\WINDOWS\$NtUninstallKB910437$\eula.txt 497 bytes C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.inf 4,92KB C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.txt 454 bytes C:\WINDOWS\$NtUninstallKB910437$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB911280$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB911280$\rasmans.dll 0,17MB C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.inf 8,16KB C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.txt 464 bytes C:\WINDOWS\$NtUninstallKB911280$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB911562$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB911562$\msadco.dll 0,14MB C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.inf 6,58KB C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.txt 493 bytes C:\WINDOWS\$NtUninstallKB911562$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB911564$\npdsplay.dll 0,35MB C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.inf 7,67KB C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.txt 339 bytes C:\WINDOWS\$NtUninstallKB911564$\spuninst\updspapi.dll 0,35MB C:\WINDOWS\$NtUninstallKB911927$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.inf 8,34KB C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.txt 464 bytes C:\WINDOWS\$NtUninstallKB911927$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB911927$\webclnt.dll 66,00KB C:\WINDOWS\$NtUninstallKB913580$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB913580$\msdtcprx.dll 0,41MB C:\WINDOWS\$NtUninstallKB913580$\msdtctm.dll 0,91MB C:\WINDOWS\$NtUninstallKB913580$\msdtcuiu.dll 0,15MB C:\WINDOWS\$NtUninstallKB913580$\mtxclu.dll 65,00KB C:\WINDOWS\$NtUninstallKB913580$\mtxoci.dll 88,00KB C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.inf 8,67KB C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.txt 1,64KB C:\WINDOWS\$NtUninstallKB913580$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB913580$\xolehlp.dll 11,50KB C:\WINDOWS\$NtUninstallKB914388$\dhcpcsvc.dll 0,11MB C:\WINDOWS\$NtUninstallKB914388$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB914388$\iphlpapi.dll 93,50KB C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.inf 8,14KB C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.txt 772 bytes C:\WINDOWS\$NtUninstallKB914388$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB914389$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB914389$\mrxsmb.sys 0,43MB C:\WINDOWS\$NtUninstallKB914389$\rdbss.sys 0,17MB C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.inf 7,81KB C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.txt 756 bytes C:\WINDOWS\$NtUninstallKB914389$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB916595$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB916595$\http.sys 0,25MB C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.inf 5,33KB C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.txt 411 bytes C:\WINDOWS\$NtUninstallKB916595$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB917344$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB917344$\jscript.dll 0,43MB C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.inf 5,72KB C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.txt 464 bytes C:\WINDOWS\$NtUninstallKB917344$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.txt 370 bytes C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.inf 8,13KB C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.txt 313 bytes C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\updspapi.dll 0,35MB C:\WINDOWS\$NtUninstallKB917734_WMP9$\wmp.dll 4,65MB C:\WINDOWS\$NtUninstallKB917953$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.inf 5,74KB C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.txt 466 bytes C:\WINDOWS\$NtUninstallKB917953$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys 0,34MB C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys.000 0,34MB C:\WINDOWS\$NtUninstallKB918118$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB918118$\msftedit.dll 0,51MB C:\WINDOWS\$NtUninstallKB918118$\riched20.dll 0,41MB C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.inf 7,65KB C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.txt 717 bytes C:\WINDOWS\$NtUninstallKB918118$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB918439$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB918439$\jgdw400.dll 0,14MB C:\WINDOWS\$NtUninstallKB918439$\jgpl400.dll 41,50KB C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.inf 6,19KB C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.txt 609 bytes C:\WINDOWS\$NtUninstallKB918439$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB919007$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB919007$\rmcast.sys 0,19MB C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.inf 5,83KB C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.txt 467 bytes C:\WINDOWS\$NtUninstallKB919007$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB920213$\agentdp2.dll 41,00KB C:\WINDOWS\$NtUninstallKB920213$\agentdpv.dll 56,00KB C:\WINDOWS\$NtUninstallKB920213$\agentsvr.exe 0,24MB C:\WINDOWS\$NtUninstallKB920213$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.inf 8,00KB C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.txt 1.019 bytes C:\WINDOWS\$NtUninstallKB920213$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB920670$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB920670$\hlink.dll 76,03KB C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.inf 5,96KB C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.txt 454 bytes C:\WINDOWS\$NtUninstallKB920670$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB920683$\dnsapi.dll 0,14MB C:\WINDOWS\$NtUninstallKB920683$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB920683$\rasadhlp.dll 8,00KB C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.inf 5,14KB C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.txt 707 bytes C:\WINDOWS\$NtUninstallKB920683$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB920685$\ciodm.dll 67,50KB C:\WINDOWS\$NtUninstallKB920685$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB920685$\query.dll 1,37MB C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.inf 6,81KB C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.txt 687 bytes C:\WINDOWS\$NtUninstallKB920685$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB920872$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB920872$\kmixer.sys 0,16MB C:\WINDOWS\$NtUninstallKB920872$\splitter.sys 6,25KB C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.inf 7,00KB C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.txt 1,09KB C:\WINDOWS\$NtUninstallKB920872$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB920872$\wdmaud.sys 81,00KB C:\WINDOWS\$NtUninstallKB921503$\oleaut32.dll 0,53MB C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.inf 8,62KB C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.txt 370 bytes C:\WINDOWS\$NtUninstallKB921503$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB922582$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB922582$\fltlib.dll 16,50KB C:\WINDOWS\$NtUninstallKB922582$\fltmc.exe 22,00KB C:\WINDOWS\$NtUninstallKB922582$\fltmgr.sys 0,12MB C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.inf 6,38KB C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.txt 938 bytes C:\WINDOWS\$NtUninstallKB922582$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB922819$\6to4svc.dll 98,00KB C:\WINDOWS\$NtUninstallKB922819$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.inf 7,30KB C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.txt 710 bytes C:\WINDOWS\$NtUninstallKB922819$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB922819$\tcpip6.sys 0,21MB C:\WINDOWS\$NtUninstallKB923191$\comctl32.dll 0,58MB C:\WINDOWS\$NtUninstallKB923191$\spuninst\KB923191.asms 1,21KB C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.inf 6,85KB C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.txt 313 bytes C:\WINDOWS\$NtUninstallKB923191$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB923414$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.inf 6,72KB C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.txt 452 bytes C:\WINDOWS\$NtUninstallKB923414$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB923414$\srv.sys 0,32MB C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.inf 4,70KB C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.txt 309 bytes C:\WINDOWS\$NtUninstallKB923689$\spuninst\updspapi.dll 0,35MB C:\WINDOWS\$NtUninstallKB923689$\wmvcore.dll 2,01MB C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.txt 1,38KB C:\WINDOWS\$NtUninstallKB923980$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB923980$\nwapi32.dll 57,50KB C:\WINDOWS\$NtUninstallKB923980$\nwprovau.dll 0,14MB C:\WINDOWS\$NtUninstallKB923980$\nwrdr.sys 0,16MB C:\WINDOWS\$NtUninstallKB923980$\nwwks.dll 62,50KB C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.inf 7,76KB C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.txt 1,16KB C:\WINDOWS\$NtUninstallKB923980$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB924191$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB924191$\msxml3.dll 1,18MB C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.inf 9,78KB C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.txt 459 bytes C:\WINDOWS\$NtUninstallKB924191$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB924270$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB924270$\lsasrv.dll 0,69MB C:\WINDOWS\$NtUninstallKB924270$\netapi32.dll 0,32MB C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.inf 7,11KB C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.txt 945 bytes C:\WINDOWS\$NtUninstallKB924270$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB924270$\wkssvc.dll 0,13MB C:\WINDOWS\$NtUninstallKB924496$\reg00002 8,00KB C:\WINDOWS\$NtUninstallKB924496$\reg00003 8,00KB C:\WINDOWS\$NtUninstallKB924496$\reg00005 8,00KB C:\WINDOWS\$NtUninstallKB924496$\reg00006 8,00KB C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.txt 365 bytes C:\WINDOWS\$NtUninstallKB924667$\mfc40u.dll 0,88MB C:\WINDOWS\$NtUninstallKB924667$\mfc42u.dll 0,98MB C:\WINDOWS\$NtUninstallKB924667$\spuninst\KB924667.asms 1,31KB C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.inf 7,80KB C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.txt 488 bytes C:\WINDOWS\$NtUninstallKB924667$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB925398_WMP64$\dxmasf.dll 0,48MB C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.inf 7,77KB C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.txt 528 bytes C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\updspapi.dll 0,35MB C:\WINDOWS\$NtUninstallKB925398_WMP64$\strmdll.dll 0,23MB C:\WINDOWS\$NtUninstallKB925902$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB925902$\gdi32.dll 0,27MB C:\WINDOWS\$NtUninstallKB925902$\mf3216.dll 39,00KB C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.inf 7,16KB C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.txt 1,14KB C:\WINDOWS\$NtUninstallKB925902$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB925902$\user32.dll 0,55MB C:\WINDOWS\$NtUninstallKB925902$\user32.dll.000 0,55MB C:\WINDOWS\$NtUninstallKB925902$\win32k.sys 1,75MB C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.txt 724 bytes C:\WINDOWS\$NtUninstallKB926255$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.inf 5,49KB C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.txt 444 bytes C:\WINDOWS\$NtUninstallKB926255$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB926255$\sxs.dll 0,68MB C:\WINDOWS\$NtUninstallKB926436$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB926436$\oledlg.dll 0,11MB C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.inf 7,64KB C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.txt 459 bytes C:\WINDOWS\$NtUninstallKB926436$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB927779$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB927779$\msado15.dll 0,51MB C:\WINDOWS\$NtUninstallKB927779$\msadomd.dll 0,17MB C:\WINDOWS\$NtUninstallKB927779$\msadox.dll 0,19MB C:\WINDOWS\$NtUninstallKB927779$\msjro.dll 100,00KB C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.inf 9,87KB C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.txt 1,28KB C:\WINDOWS\$NtUninstallKB927779$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB927802$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.inf 6,82KB C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.txt 469 bytes C:\WINDOWS\$NtUninstallKB927802$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB927802$\wiaservc.dll 0,32MB C:\WINDOWS\$NtUninstallKB927891$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB927891$\msi.dll 2,76MB C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.inf 6,17KB C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.txt 446 bytes C:\WINDOWS\$NtUninstallKB927891$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB928255$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB928255$\shell32.dll 8,09MB C:\WINDOWS\$NtUninstallKB928255$\shell32.dll.000 8,09MB C:\WINDOWS\$NtUninstallKB928255$\shsvcs.dll 0,13MB C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.inf 9,92KB C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.txt 763 bytes C:\WINDOWS\$NtUninstallKB928255$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB928843$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB928843$\hhctrl.ocx 0,52MB C:\WINDOWS\$NtUninstallKB928843$\reg00001 8,00KB C:\WINDOWS\$NtUninstallKB928843$\reg00002 8,00KB C:\WINDOWS\$NtUninstallKB928843$\reg00003 8,00KB C:\WINDOWS\$NtUninstallKB928843$\reg00004 8,00KB C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.inf 7,26KB C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.txt 459 bytes C:\WINDOWS\$NtUninstallKB928843$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB929123$\directdb.dll 79,50KB C:\WINDOWS\$NtUninstallKB929123$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB929123$\inetcomm.dll 0,65MB C:\WINDOWS\$NtUninstallKB929123$\msoe.dll 1,25MB C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.inf 9,64KB C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.txt 1,48KB C:\WINDOWS\$NtUninstallKB929123$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB929123$\wab32.dll 0,48MB C:\WINDOWS\$NtUninstallKB929123$\wabimp.dll 83,00KB C:\WINDOWS\$NtUninstallKB929399$\msscp.dll 0,40MB C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.inf 9,09KB C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.txt 301 bytes C:\WINDOWS\$NtUninstallKB929399$\spuninst\updspapi.dll 0,35MB C:\WINDOWS\$NtUninstallKB929969$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.inf 6,81KB C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.txt 486 bytes C:\WINDOWS\$NtUninstallKB929969$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB929969$\vgx.dll 0,81MB C:\WINDOWS\$NtUninstallKB930178$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.inf 7,59KB C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.txt 459 bytes C:\WINDOWS\$NtUninstallKB930178$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB930178$\winsrv.dll 0,28MB C:\WINDOWS\$NtUninstallKB930916$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB930916$\ntfs.sys 0,55MB C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.inf 7,17KB C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.txt 457 bytes C:\WINDOWS\$NtUninstallKB930916$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB931261$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.inf 8,05KB C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.txt 469 bytes C:\WINDOWS\$NtUninstallKB931261$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB931261$\upnphost.dll 0,18MB C:\WINDOWS\$NtUninstallKB931768$\plugin.ocx.000 67,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00002 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00003 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00004 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00005 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00006 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00007 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00010 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00011 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00012 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00013 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00014 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00015 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00016 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00017 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00018 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00019 8,00KB C:\WINDOWS\$NtUninstallKB931768$\reg00022 36,00KB C:\WINDOWS\$NtUninstallKB931768$\spuninst\spuninst.txt 4,85KB C:\WINDOWS\$NtUninstallKB931784$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB931784$\ntkrnlmp.exe 2,04MB C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe 1,97MB C:\WINDOWS\$NtUninstallKB931784$\ntkrpamp.exe 1,93MB C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe 2,08MB C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.inf 9,79KB C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.txt 1,20KB C:\WINDOWS\$NtUninstallKB931784$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB931836$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.inf 6,85KB C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.txt 319 bytes C:\WINDOWS\$NtUninstallKB931836$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB932168$\agentdpv.dll 56,00KB C:\WINDOWS\$NtUninstallKB932168$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.inf 7,54KB C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.txt 525 bytes C:\WINDOWS\$NtUninstallKB932168$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.inf 9,37KB C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.txt 270 bytes C:\WINDOWS\$NtUninstallKB933360$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB933360$\tzchange.exe 59,00KB C:\WINDOWS\$NtUninstallKB933566$\browseui.dll 0,97MB C:\WINDOWS\$NtUninstallKB933566$\cdfview.dll 0,14MB C:\WINDOWS\$NtUninstallKB933566$\danim.dll 1,01MB C:\WINDOWS\$NtUninstallKB933566$\dxtmsft.dll 0,34MB C:\WINDOWS\$NtUninstallKB933566$\dxtrans.dll 0,19MB C:\WINDOWS\$NtUninstallKB933566$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB933566$\extmgr.dll 54,50KB C:\WINDOWS\$NtUninstallKB933566$\iedw.exe 18,00KB C:\WINDOWS\$NtUninstallKB933566$\iepeers.dll 0,24MB C:\WINDOWS\$NtUninstallKB933566$\inseng.dll 94,50KB C:\WINDOWS\$NtUninstallKB933566$\jsproxy.dll 15,50KB C:\WINDOWS\$NtUninstallKB933566$\mshtml.dll 2,86MB C:\WINDOWS\$NtUninstallKB933566$\mshtmled.dll 0,43MB C:\WINDOWS\$NtUninstallKB933566$\msrating.dll 0,14MB C:\WINDOWS\$NtUninstallKB933566$\mstime.dll 0,51MB C:\WINDOWS\$NtUninstallKB933566$\plugin.ocx 67,00KB C:\WINDOWS\$NtUninstallKB933566$\plugin.ocx.000 67,00KB C:\WINDOWS\$NtUninstallKB933566$\pngfilt.dll 38,50KB C:\WINDOWS\$NtUninstallKB933566$\reg00003 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00004 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00006 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00007 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00010 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00011 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00012 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00013 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00014 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00015 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00016 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00017 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00018 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00019 8,00KB C:\WINDOWS\$NtUninstallKB933566$\reg00022 32,00KB C:\WINDOWS\$NtUninstallKB933566$\shdocvw.dll 1,41MB C:\WINDOWS\$NtUninstallKB933566$\shlwapi.dll 0,45MB C:\WINDOWS\$NtUninstallKB933566$\shlwapi.dll.000 0,45MB C:\WINDOWS\$NtUninstallKB933566$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB933566$\spuninst\spuninst.inf 14,66KB C:\WINDOWS\$NtUninstallKB933566$\spuninst\spuninst.txt 5,04KB C:\WINDOWS\$NtUninstallKB933566$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB933566$\urlmon.dll 0,57MB C:\WINDOWS\$NtUninstallKB933566$\wininet.dll 0,63MB C:\WINDOWS\$NtUninstallKB933566$\xpsp3res.dll 15,50KB C:\WINDOWS\$NtUninstallKB933729$\reg00001 32,00KB C:\WINDOWS\$NtUninstallKB933729$\rpcrt4.dll 0,55MB C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.inf 9,43KB C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.txt 417 bytes C:\WINDOWS\$NtUninstallKB933729$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB935839$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB935839$\kernel32.dll 0,98MB C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.inf 5,18KB C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.txt 469 bytes C:\WINDOWS\$NtUninstallKB935839$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB935840$\eula.txt 812 bytes C:\WINDOWS\$NtUninstallKB935840$\schannel.dll 0,14MB C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.inf 5,44KB C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.txt 469 bytes C:\WINDOWS\$NtUninstallKB935840$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB936021$\msxml3.dll 1,03MB C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.inf 8,74KB C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.txt 360 bytes C:\WINDOWS\$NtUninstallKB936021$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.inf 7,85KB C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.txt 368 bytes C:\WINDOWS\$NtUninstallKB936357$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB936357$\update.sys 0,20MB C:\WINDOWS\$NtUninstallKB936782_WMP11$\kb936782.cat 10,67KB C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.inf 9,06KB C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.txt 317 bytes C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\updspapi.dll 0,35MB C:\WINDOWS\$NtUninstallKB936782_WMP11$\wmp.dll 10,3MB C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.inf 8,57KB C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.txt 313 bytes C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\updspapi.dll 0,35MB C:\WINDOWS\$NtUninstallKB936782_WMP9$\wmp.dll 4,51MB C:\WINDOWS\$NtUninstallKB937143$\browseui.dll 0,98MB C:\WINDOWS\$NtUninstallKB937143$\cdfview.dll 0,14MB C:\WINDOWS\$NtUninstallKB937143$\danim.dll 1,01MB C:\WINDOWS\$NtUninstallKB937143$\dxtmsft.dll 0,34MB C:\WINDOWS\$NtUninstallKB937143$\dxtrans.dll 0,20MB C:\WINDOWS\$NtUninstallKB937143$\extmgr.dll 54,50KB C:\WINDOWS\$NtUninstallKB937143$\iedw.exe 18,00KB C:\WINDOWS\$NtUninstallKB937143$\iepeers.dll 0,24MB C:\WINDOWS\$NtUninstallKB937143$\inseng.dll 94,50KB C:\WINDOWS\$NtUninstallKB937143$\jsproxy.dll 16,00KB C:\WINDOWS\$NtUninstallKB937143$\mshtml.dll 2,94MB C:\WINDOWS\$NtUninstallKB937143$\mshtmled.dll 0,43MB C:\WINDOWS\$NtUninstallKB937143$\msrating.dll 0,14MB C:\WINDOWS\$NtUninstallKB937143$\mstime.dll 0,51MB C:\WINDOWS\$NtUninstallKB937143$\pngfilt.dll 38,50KB C:\WINDOWS\$NtUninstallKB937143$\reg00001 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00002 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00003 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00004 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00005 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00006 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00007 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00008 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00009 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00010 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00011 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00012 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00013 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00014 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00015 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00016 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00017 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00018 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00019 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00020 12,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00021 8,00KB C:\WINDOWS\$NtUninstallKB937143$\reg00022 80,00KB C:\WINDOWS\$NtUninstallKB937143$\shdocvw.dll 1,43MB C:\WINDOWS\$NtUninstallKB937143$\shlwapi.dll 0,45MB C:\WINDOWS\$NtUninstallKB937143$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB937143$\spuninst\spuninst.inf 17,09KB C:\WINDOWS\$NtUninstallKB937143$\spuninst\spuninst.txt 4,76KB C:\WINDOWS\$NtUninstallKB937143$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB937143$\urlmon.dll 0,59MB C:\WINDOWS\$NtUninstallKB937143$\wininet.dll 0,63MB C:\WINDOWS\$NtUninstallKB937143$\xpsp3res.dll 0,11MB C:\WINDOWS\$NtUninstallKB937894$\mqac.sys 71,25KB C:\WINDOWS\$NtUninstallKB937894$\mqad.dll 0,13MB C:\WINDOWS\$NtUninstallKB937894$\mqdscli.dll 46,00KB C:\WINDOWS\$NtUninstallKB937894$\mqise.dll 16,50KB C:\WINDOWS\$NtUninstallKB937894$\mqqm.dll 0,63MB C:\WINDOWS\$NtUninstallKB937894$\mqrt.dll 0,17MB C:\WINDOWS\$NtUninstallKB937894$\mqsec.dll 93,50KB C:\WINDOWS\$NtUninstallKB937894$\mqupgrd.dll 47,50KB C:\WINDOWS\$NtUninstallKB937894$\mqutil.dll 0,50MB C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.inf 12,66KB C:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.txt 2,18KB C:\WINDOWS\$NtUninstallKB937894$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.inf 8,67KB C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.txt 387 bytes C:\WINDOWS\$NtUninstallKB938127$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB938127$\vgx.dll 0,81MB C:\WINDOWS\$NtUninstallKB938828$\explorer.exe 0,99MB C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.inf 8,63KB C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.txt 361 bytes C:\WINDOWS\$NtUninstallKB938828$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB938829$\gdi32.dll 0,27MB C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.inf 8,53KB C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.txt 355 bytes C:\WINDOWS\$NtUninstallKB938829$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB939653$\browseui.dll 0,98MB C:\WINDOWS\$NtUninstallKB939653$\cdfview.dll 0,14MB C:\WINDOWS\$NtUninstallKB939653$\danim.dll 1,01MB C:\WINDOWS\$NtUninstallKB939653$\dxtmsft.dll 0,34MB C:\WINDOWS\$NtUninstallKB939653$\dxtrans.dll 0,20MB C:\WINDOWS\$NtUninstallKB939653$\extmgr.dll 54,50KB C:\WINDOWS\$NtUninstallKB939653$\iedw.exe 18,00KB C:\WINDOWS\$NtUninstallKB939653$\iepeers.dll 0,24MB C:\WINDOWS\$NtUninstallKB939653$\inseng.dll 94,50KB C:\WINDOWS\$NtUninstallKB939653$\jsproxy.dll 16,00KB C:\WINDOWS\$NtUninstallKB939653$\mshtml.dll 2,94MB C:\WINDOWS\$NtUninstallKB939653$\mshtmled.dll 0,43MB C:\WINDOWS\$NtUninstallKB939653$\msrating.dll 0,14MB C:\WINDOWS\$NtUninstallKB939653$\mstime.dll 0,51MB C:\WINDOWS\$NtUninstallKB939653$\pngfilt.dll 38,50KB C:\WINDOWS\$NtUninstallKB939653$\reg00001 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00002 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00003 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00004 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00005 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00006 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00007 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00008 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00009 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00010 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00011 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00012 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00013 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00014 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00015 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00016 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00017 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00018 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00019 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00020 12,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00021 8,00KB C:\WINDOWS\$NtUninstallKB939653$\reg00022 84,00KB C:\WINDOWS\$NtUninstallKB939653$\shdocvw.dll 1,43MB C:\WINDOWS\$NtUninstallKB939653$\shlwapi.dll 0,45MB C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.inf 17,84KB C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.txt 4,76KB C:\WINDOWS\$NtUninstallKB939653$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB939653$\urlmon.dll 0,59MB C:\WINDOWS\$NtUninstallKB939653$\wininet.dll 0,63MB C:\WINDOWS\$NtUninstallKB939653$\xpsp3res.dll 0,11MB C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.inf 8,77KB C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.txt 308 bytes C:\WINDOWS\$NtUninstallKB939683$\spuninst\updspapi.dll 0,35MB C:\WINDOWS\$NtUninstallKB939683$\unregmp2.exe 0,30MB C:\WINDOWS\$NtUninstallKB941202$\inetcomm.dll 0,65MB C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.inf 8,93KB C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.txt 370 bytes C:\WINDOWS\$NtUninstallKB941202$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB941568$\quartz.dll 2,54MB C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.inf 9,82KB C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.txt 360 bytes C:\WINDOWS\$NtUninstallKB941568$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.inf 9,56KB C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.txt 301 bytes C:\WINDOWS\$NtUninstallKB941569$\spuninst\updspapi.dll 0,35MB C:\WINDOWS\$NtUninstallKB941569$\wmasf.dll 0,21MB C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.inf 10,34KB C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.txt 367 bytes C:\WINDOWS\$NtUninstallKB941644$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys 0,34MB C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys.000 0,34MB C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.inf 10,77KB C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.txt 360 bytes C:\WINDOWS\$NtUninstallKB941693$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB941693$\win32k.sys 1,76MB C:\WINDOWS\$NtUninstallKB942615$\browseui.dll 0,98MB C:\WINDOWS\$NtUninstallKB942615$\cdfview.dll 0,31MB C:\WINDOWS\$NtUninstallKB942615$\danim.dll 1,01MB C:\WINDOWS\$NtUninstallKB942615$\dxtmsft.dll 0,34MB C:\WINDOWS\$NtUninstallKB942615$\dxtrans.dll 0,20MB C:\WINDOWS\$NtUninstallKB942615$\extmgr.dll 54,50KB C:\WINDOWS\$NtUninstallKB942615$\iedw.exe 18,00KB C:\WINDOWS\$NtUninstallKB942615$\iepeers.dll 0,24MB C:\WINDOWS\$NtUninstallKB942615$\inseng.dll 94,50KB C:\WINDOWS\$NtUninstallKB942615$\jsproxy.dll 16,00KB C:\WINDOWS\$NtUninstallKB942615$\mshtml.dll 3,00MB C:\WINDOWS\$NtUninstallKB942615$\mshtmled.dll 0,43MB C:\WINDOWS\$NtUninstallKB942615$\msrating.dll 0,14MB C:\WINDOWS\$NtUninstallKB942615$\mstime.dll 0,51MB C:\WINDOWS\$NtUninstallKB942615$\pngfilt.dll 38,50KB C:\WINDOWS\$NtUninstallKB942615$\reg00001 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00002 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00003 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00004 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00005 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00006 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00007 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00008 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00009 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00010 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00011 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00012 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00013 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00014 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00015 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00016 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00017 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00018 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00019 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00020 12,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00021 8,00KB C:\WINDOWS\$NtUninstallKB942615$\reg00022 84,00KB C:\WINDOWS\$NtUninstallKB942615$\shdocvw.dll 2,07MB C:\WINDOWS\$NtUninstallKB942615$\shlwapi.dll 0,46MB C:\WINDOWS\$NtUninstallKB942615$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB942615$\spuninst\spuninst.inf 18,63KB C:\WINDOWS\$NtUninstallKB942615$\spuninst\spuninst.txt 4,67KB C:\WINDOWS\$NtUninstallKB942615$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB942615$\urlmon.dll 0,60MB C:\WINDOWS\$NtUninstallKB942615$\wininet.dll 0,63MB C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.inf 10,62KB C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.txt 270 bytes C:\WINDOWS\$NtUninstallKB942763$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB942763$\tzchange.exe 59,00KB C:\WINDOWS\$NtUninstallKB942840$\jscript.dll 0,43MB C:\WINDOWS\$NtUninstallKB942840$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB942840$\spuninst\spuninst.inf 9,94KB C:\WINDOWS\$NtUninstallKB942840$\spuninst\spuninst.txt 365 bytes C:\WINDOWS\$NtUninstallKB942840$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB943055$\oleaut32.dll 0,52MB C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.inf 10,37KB C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.txt 370 bytes C:\WINDOWS\$NtUninstallKB943055$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB943460$\shell32.dll 21,4MB C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.inf 10,84KB C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.txt 513 bytes C:\WINDOWS\$NtUninstallKB943460$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB943460$\xpsp3res.dll 0,11MB C:\WINDOWS\$NtUninstallKB943485$\lsasrv.dll 0,69MB C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.inf 10,23KB C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.txt 360 bytes C:\WINDOWS\$NtUninstallKB943485$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB944338$\jscript.dll 0,43MB C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.inf 10,97KB C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.txt 613 bytes C:\WINDOWS\$NtUninstallKB944338$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB944338$\vbscript.dll 0,40MB C:\WINDOWS\$NtUninstallKB944533$\browseui.dll 0,98MB C:\WINDOWS\$NtUninstallKB944533$\cdfview.dll 0,31MB C:\WINDOWS\$NtUninstallKB944533$\danim.dll 1,01MB C:\WINDOWS\$NtUninstallKB944533$\dxtmsft.dll 0,34MB C:\WINDOWS\$NtUninstallKB944533$\dxtrans.dll 0,20MB C:\WINDOWS\$NtUninstallKB944533$\extmgr.dll 54,50KB C:\WINDOWS\$NtUninstallKB944533$\iedw.exe 18,00KB C:\WINDOWS\$NtUninstallKB944533$\iepeers.dll 0,24MB C:\WINDOWS\$NtUninstallKB944533$\inseng.dll 94,50KB C:\WINDOWS\$NtUninstallKB944533$\jsproxy.dll 16,00KB C:\WINDOWS\$NtUninstallKB944533$\mshtml.dll 3,00MB C:\WINDOWS\$NtUninstallKB944533$\mshtmled.dll 0,43MB C:\WINDOWS\$NtUninstallKB944533$\msrating.dll 0,14MB C:\WINDOWS\$NtUninstallKB944533$\mstime.dll 0,51MB C:\WINDOWS\$NtUninstallKB944533$\pngfilt.dll 38,50KB C:\WINDOWS\$NtUninstallKB944533$\reg00001 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00002 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00003 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00004 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00005 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00006 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00007 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00008 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00009 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00010 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00011 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00012 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00013 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00014 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00015 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00016 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00017 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00018 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00019 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00020 12,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00021 8,00KB C:\WINDOWS\$NtUninstallKB944533$\reg00022 88,00KB C:\WINDOWS\$NtUninstallKB944533$\shdocvw.dll 2,07MB C:\WINDOWS\$NtUninstallKB944533$\shlwapi.dll 0,46MB C:\WINDOWS\$NtUninstallKB944533$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB944533$\spuninst\spuninst.inf 19,12KB C:\WINDOWS\$NtUninstallKB944533$\spuninst\spuninst.txt 4,76KB C:\WINDOWS\$NtUninstallKB944533$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB944533$\urlmon.dll 0,60MB C:\WINDOWS\$NtUninstallKB944533$\wininet.dll 0,63MB C:\WINDOWS\$NtUninstallKB944533$\xpsp3res.dll 0,11MB C:\WINDOWS\$NtUninstallKB944653$\secdrv.sys 26,80KB C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.inf 9,54KB C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.txt 272 bytes C:\WINDOWS\$NtUninstallKB944653$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB945553$\dnsapi.dll 0,14MB C:\WINDOWS\$NtUninstallKB945553$\dnsrslvr.dll 44,50KB C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.inf 10,91KB C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.txt 608 bytes C:\WINDOWS\$NtUninstallKB945553$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB946026$\mrxdav.sys 0,17MB C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.inf 10,45KB C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.txt 368 bytes C:\WINDOWS\$NtUninstallKB946026$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB946627$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB946627$\spuninst\spuninst.inf 9,40KB C:\WINDOWS\$NtUninstallKB946627$\spuninst\spuninst.txt 122 bytes C:\WINDOWS\$NtUninstallKB946627$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB947864$\browseui.dll 0,98MB C:\WINDOWS\$NtUninstallKB947864$\cdfview.dll 0,31MB C:\WINDOWS\$NtUninstallKB947864$\danim.dll 1,01MB C:\WINDOWS\$NtUninstallKB947864$\dxtmsft.dll 0,34MB C:\WINDOWS\$NtUninstallKB947864$\dxtrans.dll 0,20MB C:\WINDOWS\$NtUninstallKB947864$\extmgr.dll 54,50KB C:\WINDOWS\$NtUninstallKB947864$\iedw.exe 18,00KB C:\WINDOWS\$NtUninstallKB947864$\iepeers.dll 0,24MB C:\WINDOWS\$NtUninstallKB947864$\inseng.dll 94,50KB C:\WINDOWS\$NtUninstallKB947864$\jsproxy.dll 16,00KB C:\WINDOWS\$NtUninstallKB947864$\mshtml.dll 3,00MB C:\WINDOWS\$NtUninstallKB947864$\mshtmled.dll 0,43MB C:\WINDOWS\$NtUninstallKB947864$\msrating.dll 0,14MB C:\WINDOWS\$NtUninstallKB947864$\mstime.dll 0,51MB C:\WINDOWS\$NtUninstallKB947864$\pngfilt.dll 38,50KB C:\WINDOWS\$NtUninstallKB947864$\reg00001 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00002 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00003 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00004 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00005 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00006 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00007 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00008 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00009 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00010 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00011 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00012 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00013 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00014 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00015 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00016 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00017 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00018 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00019 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00020 12,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00021 8,00KB C:\WINDOWS\$NtUninstallKB947864$\reg00022 88,00KB C:\WINDOWS\$NtUninstallKB947864$\shdocvw.dll 2,07MB C:\WINDOWS\$NtUninstallKB947864$\shlwapi.dll 0,46MB C:\WINDOWS\$NtUninstallKB947864$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB947864$\spuninst\spuninst.inf 19,47KB C:\WINDOWS\$NtUninstallKB947864$\spuninst\spuninst.txt 4,76KB C:\WINDOWS\$NtUninstallKB947864$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB947864$\urlmon.dll 0,60MB C:\WINDOWS\$NtUninstallKB947864$\wininet.dll 0,63MB C:\WINDOWS\$NtUninstallKB947864$\xpsp3res.dll 0,34MB C:\WINDOWS\$NtUninstallKB948590$\gdi32.dll 0,27MB C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.inf 10,69KB C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.txt 355 bytes C:\WINDOWS\$NtUninstallKB948590$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB948881$\reg00001 88,00KB C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.inf 10,10KB C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.txt 122 bytes C:\WINDOWS\$NtUninstallKB948881$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB950749$\dao360.dll 0,54MB C:\WINDOWS\$NtUninstallKB950749$\msexch40.dll 0,49MB C:\WINDOWS\$NtUninstallKB950749$\msexcl40.dll 0,30MB C:\WINDOWS\$NtUninstallKB950749$\msjet40.dll 1,44MB C:\WINDOWS\$NtUninstallKB950749$\msjetol1.dll 0,34MB C:\WINDOWS\$NtUninstallKB950749$\msjetoledb40.dll 0,34MB C:\WINDOWS\$NtUninstallKB950749$\msjint40.dll 0,17MB C:\WINDOWS\$NtUninstallKB950749$\msjter40.dll 52,03KB C:\WINDOWS\$NtUninstallKB950749$\msjtes40.dll 0,23MB C:\WINDOWS\$NtUninstallKB950749$\msltus40.dll 0,20MB C:\WINDOWS\$NtUninstallKB950749$\mspbde40.dll 0,33MB C:\WINDOWS\$NtUninstallKB950749$\msrd2x40.dll 0,40MB C:\WINDOWS\$NtUninstallKB950749$\msrd3x40.dll 0,30MB C:\WINDOWS\$NtUninstallKB950749$\msrepl40.dll 0,53MB C:\WINDOWS\$NtUninstallKB950749$\mstext40.dll 0,25MB C:\WINDOWS\$NtUninstallKB950749$\mswdat10.dll 0,79MB C:\WINDOWS\$NtUninstallKB950749$\mswstr10.dll 0,59MB C:\WINDOWS\$NtUninstallKB950749$\msxbde40.dll 0,33MB C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe 0,21MB C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.inf 17,33KB C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.txt 4,27KB C:\WINDOWS\$NtUninstallKB950749$\spuninst\updspapi.dll 0,37MB C:\WINDOWS\$NtUninstallKB950759$\browseui.dll 0,98MB C:\WINDOWS\$NtUninstallKB950759$\cdfview.dll 0,31MB C:\WINDOWS\$NtUninstallKB950759$\danim.dll 1,01MB C:\WINDOWS\$NtUninstallKB950759$\dxtmsft.dll 0,34MB C:\WINDOWS\$NtUninstallKB950759$\dxtrans.dll 0,20MB C:\WINDOWS\$NtUninstallKB950759$\extmgr.dll 54,50KB C:\WINDOWS\$NtUninstallKB950759$\iedw.exe 18,00KB C:\WINDOWS\$NtUninstallKB950759$\iepeers.dll 0,24MB C:\WINDOWS\$NtUninstallKB950759$\inseng.dll 94,50KB C:\WINDOWS\$NtUninstallKB950759$\jsproxy.dll 16,00KB C:\WINDOWS\$NtUninstallKB950759$\mshtml.dll 3,01MB C:\WINDOWS\$NtUninstallKB950759$\mshtmled.dll 0,43MB C:\WINDOWS\$NtUninstallKB950759$\msrating.dll 0,14MB C:\WINDOWS\$NtUninstallKB950759$\mstime.dll 0,51MB C:\WINDOWS\$NtUninstallKB950759$\pngfilt.dll 38,50KB C:\WINDOWS\$NtUninstallKB950759$\reg00001 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00002 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00003 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00004 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00005 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00006 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00007 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00008 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00009 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00010 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00011 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00012 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00013 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00014 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00015 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00016 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00017 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00018 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00019 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00020 12,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00021 8,00KB C:\WINDOWS\$NtUninstallKB950759$\reg00022 0,10MB C:\WINDOWS\$NtUninstallKB950759$\shdocvw.dll 2,07MB C:\WINDOWS\$NtUninstallKB950759$\shlwapi.dll 0,46MB C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe 0,22MB C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.inf 20,53KB C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.txt 4,98KB C:\WINDOWS\$NtUninstallKB950759$\spuninst\updspapi.dll 0,38MB C:\WINDOWS\$NtUninstallKB950759$\urlmon.dll 0,60MB C:\WINDOWS\$NtUninstallKB950759$\wininet.dll 0,63MB C:\WINDOWS\$NtUninstallKB950759$\xpsp3res.dll 0,34MB C:\WINDOWS\$NtUninstallKB950760$\reg00001 0,10MB C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe 0,22MB C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.inf 10,24KB C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.txt 122 bytes C:\WINDOWS\$NtUninstallKB950760$\spuninst\updspapi.dll 0,38MB C:\WINDOWS\$NtUninstallKB950762$\rmcast.sys 0,19MB C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe 0,22MB C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.inf 11,77KB C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.txt 478 bytes C:\WINDOWS\$NtUninstallKB950762$\spuninst\updspapi.dll 0,38MB C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe 0,22MB C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.inf 11,82KB C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.txt 436 bytes C:\WINDOWS\$NtUninstallKB951376$\spuninst\updspapi.dll 0,38MB C:\WINDOWS\$NtUninstallKB951376-v2$\bthport.sys 0,26MB C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe 0,22MB C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.inf 12,29KB C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.txt 607 bytes C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\updspapi.dll 0,38MB C:\WINDOWS\$NtUninstallKB951698$\quartz.dll 2,54MB C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe 0,22MB C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.inf 11,76KB C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.txt 470 bytes C:\WINDOWS\$NtUninstallKB951698$\spuninst\updspapi.dll 0,38MB C:\WINDOWS\$NtUninstallKB951748$\afd.sys 0,13MB C:\WINDOWS\$NtUninstallKB951748$\dnsapi.dll 0,14MB C:\WINDOWS\$NtUninstallKB951748$\mswsock.dll 0,24MB C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe 0,22MB C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.inf 14,28KB C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.txt 1,88KB C:\WINDOWS\$NtUninstallKB951748$\spuninst\updspapi.dll 0,38MB C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys 0,34MB C:\WINDOWS\$NtUninstallKB951748$\tcpip6.sys 0,22MB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msi.dll 2,67MB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msiexec.exe 75,50KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msihnd.dll 0,32MB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msimsg.dll 0,84MB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\msisip.dll 43,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00013 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00014 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00015 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00016 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00017 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00018 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00019 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00020 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00021 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00022 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00023 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00024 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00025 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00026 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00027 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00028 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00029 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00030 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00031 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00032 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00033 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00034 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00035 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00036 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00037 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00038 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00039 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00040 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00041 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00042 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00043 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00044 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00045 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00046 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00047 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00048 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00051 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00052 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00053 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00054 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00055 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00056 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00057 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00058 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00059 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00060 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00061 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00062 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00063 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00064 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00065 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00066 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00067 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00068 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00069 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00070 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00071 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00072 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00073 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00074 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00075 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00076 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00077 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00078 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00079 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00080 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00081 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00082 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00083 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00084 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00085 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00086 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00087 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00088 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00089 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00090 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00091 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00092 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00093 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00094 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00095 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00096 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00097 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00098 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00099 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00100 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00101 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00102 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00103 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00104 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00105 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00106 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00107 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00108 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00109 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00110 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00111 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00112 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00113 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00114 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00115 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\reg00116 8,00KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe 0,20MB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.inf 13,58KB C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.txt 967 bytes C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\updspapi.dll 0,37MB C:\Documents and Settings\Ítalo César.HOME\Dados de aplicativos\Mozilla\Firefox\Profiles\4mbzb1yt.default\formhistory.dat 0,14MB C:\Documents and Settings\Ítalo César.HOME\Dados de aplicativos\Mozilla\Firefox\Profiles\4mbzb1yt.default\formhistory.sqlite 92,00KB ------------------------------------------------------------------------------------------ Eu marquei as seguintes caixas que estavam desmarcadas: Na área do Windows Duas do SISTEMA: Atalhos no Menu Iniciar; Atalhos na área de trabalho. Todas de AVANÇADO: Dados do Prefetch antigos; Cache da ordem dos menus; Cache da área de notificação; Janelas (tamanho e localização); Histórico do Assistente do usuário; Relatórios do IIS; Desinstaladores de pacotes de atualização; Arquivos e pastas personalizadas. E só uma na área de Programas que foi a da parte de Mozilla/Firefox chamada "Informações de formulários salvos" Só essas estavam desmarcadas e eu marquei para gerar essa análise. Posso executar essa limpeza? Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Julho 21, 2008 Posso executar essa limpeza? Sim. :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
ItaloCCSL 0 Denunciar post Postado Julho 24, 2008 :!: Apareceu hoje de novo! O erro no "update.exe" "0x7c350516" "0x000005f7" E agora jgarcia? Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Julho 24, 2008 Opa ItaloCCSL, Baixe o SilentRunners. Extraia o arquivo SilentRunners.vbs para o C. Dê duplo clique sobre o arquivo para executá-lo. Após executá-lo aguarde até que seja gerado um documento denominado Startup Programs (USUÁRIO) data. Copie o conteúdo deste documento e cole em sua próxima resposta. Abraços. Obs.: Caso o seu AV detecte o arquivo como sendo um script malicioso não se preocupe e autorize a execução. Compartilhar este post Link para o post Compartilhar em outros sites
ItaloCCSL 0 Denunciar post Postado Julho 25, 2008 Está ai. "Silent Runners.vbs", revision 58, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} "XPize Darkside Reloader" = "C:\WINDOWS\XPize Darkside\XPize Darkside Reloader.exe /S" [null data] "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS] "ares" = ""C:\Arquivos de programas\Ares\Ares.exe" -h" ["Ares Development Group"] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} "IgfxTray" = "C:\WINDOWS\system32\igfxtray.exe" ["Intel Corporation"] "HotKeysCmds" = "C:\WINDOWS\system32\hkcmd.exe" ["Intel Corporation"] "SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."] "QuickTime Task" = ""C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."] "avgnt" = ""C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min" ["Avira GmbH"] "SMSERIAL" = "sm56hlpr.exe" ["Motorola Inc."] "SunJavaUpdateSched" = ""C:\Arquivos de programas\Java\jre1.6.0_05\bin\jusched.exe"" ["Sun Microsystems, Inc."] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided) -> {HKLM...CLSID} = "Yahoo! Toolbar Helper" \InProcServer32\(Default) = "C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided) -> {HKLM...CLSID} = "AcroIEHlprObj Class" \InProcServer32\(Default) = "C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided) -> {HKLM...CLSID} = "SSVHelper Class" \InProcServer32\(Default) = "C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll" ["Sun Microsystems, Inc."] {9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided) -> {HKLM...CLSID} = "Auxiliar de Conexão do Windows Live" \InProcServer32\(Default) = "C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS] {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = (no title provided) -> {HKLM...CLSID} = "Windows Live Toolbar Helper" \InProcServer32\(Default) = "C:\Arquivos de programas\Windows Live Toolbar\msntb.dll" [MS] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extensão do 'Painel de controle' para panorâmica de vídeo" -> {HKLM...CLSID} = "Extensão do 'Painel de controle' para panorâmica de vídeo" \InProcServer32\(Default) = "deskpan.dll" [file not found] "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extensão de ícone do HyperTerminal" -> {HKLM...CLSID} = "HyperTerminal Icon Ext" \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."] "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler" -> {HKLM...CLSID} = "Microsoft Office Outlook" \InProcServer32\(Default) = "C:\ARQUIV~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS] "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler" -> {HKLM...CLSID} = "Extensão de ícone de arquivo do Outlook" \InProcServer32\(Default) = "C:\ARQUIV~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS] "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Arquivos de programas\Microsoft Office\OFFICE11\msohev.dll" [MS] "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders" -> {HKLM...CLSID} = "Minhas Pastas de Compartilhamento" \InProcServer32\(Default) = "C:\Arquivos de programas\Windows Live\Messenger\fsshext.8.5.1302.1018.dll" [MS] "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Arquivos de programas\WinRAR\rarext.dll" [null data] "{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}" = "Nokia Phone Browser" -> {HKLM...CLSID} = "Nokia Phone Browser" \InProcServer32\(Default) = "C:\Arquivos de programas\Nokia\Nokia PC Suite 6\phonebrowser.dll" ["Nokia"] "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" = "Shell Extension for Malware scanning" -> {HKLM...CLSID} = "Shell Extension for Malware scanning" \InProcServer32\(Default) = "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"] "{0563DB41-F538-4B37-A92D-4659049B7766}" = "WLMD Message Handler" -> {HKLM...CLSID} = "CLSID_WLMCMimeFilter" \InProcServer32\(Default) = "C:\Arquivos de programas\Windows Live\Mail\mailcomm.dll" [MS] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" -> {HKLM...CLSID} = "WPDShServiceObj Class" \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ <<!>> igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"] HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\ <<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS] HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" -> {HKLM...CLSID} = "Shell Extension for Malware scanning" \InProcServer32\(Default) = "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Arquivos de programas\WinRAR\rarext.dll" [null data] HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Arquivos de programas\WinRAR\rarext.dll" [null data] HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\ Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" -> {HKLM...CLSID} = "Shell Extension for Malware scanning" \InProcServer32\(Default) = "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"] WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Arquivos de programas\WinRAR\rarext.dll" [null data] Default executables: -------------------- <<!>> HKLM\SOFTWARE\Classes\.com\(Default) = "ComFile" Group Policies {GPedit.msc branch and setting}: ----------------------------------------------- Note: detected settings may not have any effect. HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ "NoDrives" = (REG_DWORD) dword:0x00000000 {unrecognized setting} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ "NoDrives" = (REG_DWORD) dword:0x00000000 {unrecognized setting} HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\ "HideLegacyLogonScripts" = (REG_DWORD) dword:0x00000000 {unrecognized setting} "HideLogoffScripts" = (REG_DWORD) dword:0x00000000 {unrecognized setting} "RunLogonScriptSync" = (REG_DWORD) dword:0x00000001 {unrecognized setting} "RunStartupScriptSync" = (REG_DWORD) dword:0x00000000 {unrecognized setting} "HideStartupScripts" = (REG_DWORD) dword:0x00000000 {unrecognized setting} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Shutdown: Allow system to be shut down without having to log on} "undockwithoutlogon" = (REG_DWORD) dword:0x00000001 {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options| Devices: Allow undock without having to log on} "DisableRegistryTools" = (REG_DWORD) dword:0x00000000 {unrecognized setting} "HideLegacyLogonScripts" = (REG_DWORD) dword:0x00000000 {unrecognized setting} "HideLogoffScripts" = (REG_DWORD) dword:0x00000000 {unrecognized setting} "RunLogonScriptSync" = (REG_DWORD) dword:0x00000001 {unrecognized setting} "RunStartupScriptSync" = (REG_DWORD) dword:0x00000000 {unrecognized setting} "HideStartupScripts" = (REG_DWORD) dword:0x00000000 {unrecognized setting} Active Desktop and Wallpaper: ----------------------------- Active Desktop may be disabled at this entry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState Displayed if Active Desktop enabled and wallpaper not set by Group Policy: HKCU\Software\Microsoft\Internet Explorer\Desktop\General\ "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Configurações locais\Dados de aplicativos\Microsoft\Wallpaper1.bmp" Displayed if Active Desktop disabled and wallpaper not set by Group Policy: HKCU\Control Panel\Desktop\ "Wallpaper" = "C:\Documents and Settings\Ítalo César.HOME\Configurações locais\Dados de aplicativos\Microsoft\Wallpaper1.bmp" Windows Portable Device AutoPlay Handlers ----------------------------------------- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\ MSWPDShellNamespaceHandler\ "Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501" "CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}" "InitCmdLine" = " " -> {HKLM...CLSID} = "WPDShextAutoplay" \LocalServer32\(Default) = "C:\WINDOWS\system32\WPDShextAutoplay.exe" [MS] NeroAutoPlay2CDAudio\ "Provider" = "Nero Express" "InvokeProgID" = "Nero.AutoPlay2" "InvokeVerb" = "HandleCDBurningOnArrival_CDAudio" HKLM\SOFTWARE\Classes\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_CDAudio\command\(Default) = "C:\Arquivos de programas\Ahead\nero\nero.exe /w /New:AudioCD /Drive:%L" ["Ahead Software AG"] NeroAutoPlay2CopyCD\ "Provider" = "Nero Express" "InvokeProgID" = "Nero.AutoPlay2" "InvokeVerb" = "PlayCDAudioOnArrival_CopyCD" HKLM\SOFTWARE\Classes\Nero.AutoPlay2\shell\PlayCDAudioOnArrival_CopyCD\command\(Default) = "C:\Arquivos de programas\Ahead\nero\nero.exe /w /Dialog:DiscCopy /Drive:%L" ["Ahead Software AG"] NeroAutoPlay2DataDisc\ "Provider" = "Nero Express" "InvokeProgID" = "Nero.AutoPlay2" "InvokeVerb" = "HandleCDBurningOnArrival_DataDisc" HKLM\SOFTWARE\Classes\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_DataDisc\command\(Default) = "C:\Arquivos de programas\Ahead\nero\nero.exe /w /New:ISODisc /Drive:%L" ["Ahead Software AG"] NeroAutoPlay2LaunchNeroStartSmart\ "Provider" = "Nero StartSmart" "InvokeProgID" = "Nero.AutoPlay2" "InvokeVerb" = "HandleCDBurningOnArrival_LaunchNeroStartSmart" HKLM\SOFTWARE\Classes\Nero.AutoPlay2\shell\HandleCDBurningOnArrival_LaunchNeroStartSmart\command\(Default) = "C:\Arquivos de programas\Ahead\Nero StartSmart\NeroStartSmart.exe /AutoPlay /Drive:%L" ["Ahead Software AG"] NMMPlayCDAudioOnArrival\ "Provider" = "Nokia Music Manager" "InvokeProgID" = "NokiaMusicManager" "InvokeVerb" = "NMMPlayCD" HKLM\SOFTWARE\Classes\NokiaMusicManager\shell\NMMPlayCD\command\(Default) = "C:\Arquivos de programas\Nokia\Nokia PC Suite 6\MusicManager.exe /playCD "%L"" ["Nokia"] NMMRipCDAudioOnArrival\ "Provider" = "Nokia Music Manager" "InvokeProgID" = "NokiaMusicManager" "InvokeVerb" = "NMMRipCD" HKLM\SOFTWARE\Classes\NokiaMusicManager\shell\NMMRipCD\command\(Default) = "C:\Arquivos de programas\Nokia\Nokia PC Suite 6\MusicManager.exe /ripCD "%L"" ["Nokia"] Startup items in "Ítalo César" & "All Users" startup folders: ------------------------------------------------------------- WARNING! "All Users" startup folder not found! Enabled Scheduled Tasks: ------------------------ "Verificar Atualizações para a Barra de Ferramentas do Windows Live" -> launches: "C:\Arquivos de programas\Windows Live Toolbar\MSNTBUP.EXE" [MS] Winsock2 Service Provider DLLs: ------------------------------- Namespace Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++} 000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] 000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS] 000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS] Transport Service Providers HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++} 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range: %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15 %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05 Toolbars, Explorer Bars, Extensions: ------------------------------------ Toolbars HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\ "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" -> {HKLM...CLSID} = "Windows Live Toolbar" \InProcServer32\(Default) = "C:\Arquivos de programas\Windows Live Toolbar\msntb.dll" [MS] HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" -> {HKLM...CLSID} = "Windows Live Toolbar" \InProcServer32\(Default) = "C:\Arquivos de programas\Windows Live Toolbar\msntb.dll" [MS] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" -> {HKLM...CLSID} = "Barra de Ferramentas do Yahoo! com bloqueador de pop-up" \InProcServer32\(Default) = "C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = (no title provided) -> {HKLM...CLSID} = "Windows Live Toolbar" \InProcServer32\(Default) = "C:\Arquivos de programas\Windows Live Toolbar\msntb.dll" [MS] "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided) -> {HKLM...CLSID} = "Barra de Ferramentas do Yahoo! com bloqueador de pop-up" \InProcServer32\(Default) = "C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."] Explorer Bars HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Pesquisar" Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar] InProcServer32\(Default) = "C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS] Extensions (Tools menu items, main toolbar menu buttons) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\ {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ "MenuText" = "Sun Java Console" "CLSIDExtension" = "{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}" -> {HKCU...CLSID} = "Java Plug-in 1.6.0_05" \InProcServer32\(Default) = "C:\Arquivos de programas\Java\jre1.6.0_05\bin\ssv.dll" ["Sun Microsystems, Inc."] -> {HKLM...CLSID} = "Java Plug-in 1.6.0_05" \InProcServer32\(Default) = "C:\Arquivos de programas\Java\jre1.6.0_05\bin\npjpi160_05.dll" ["Sun Microsystems, Inc."] {92780B25-18CC-41C8-B9BE-3C9C571A8263}\ "ButtonText" = "Pesquisar" {FB5F1910-F110-11D2-BB9E-00C04F795683}\ "ButtonText" = "Messenger" "MenuText" = "Windows Messenger" "Exec" = "C:\Arquivos de programas\Messenger\msmsgs.exe" [MS] Miscellaneous IE Hijack Points ------------------------------ C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings") Added lines (compared with English-language version): [strings]: SEARCH_PAGE_URL="&http://home.microsoft.com/intl/br/access/allinone.asp" [strings]: SAFESITE_VALUE="search.msn.com.br" Missing lines (compared with English-language version): [strings]: 2 lines HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\ <<H>> "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "*Z" (unwritable string) -> {HKLM...CLSID} = "Barra de Ferramentas do Yahoo! com bloqueador de pop-up" \InProcServer32\(Default) = "C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."] Running Services (Display Name, Service Name, Path {Service DLL}): ------------------------------------------------------------------ AntiVir PersonalEdition Classic Guard, AntiVirService, ""C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe"" ["Avira GmbH"] AntiVir PersonalEdition Classic Scheduler, AntiVirScheduler, ""C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe"" ["Avira GmbH"] Context Manager Process Extension, cmpe, "C:\WINDOWS\system32\cmpe.exe" ["LightComm"] Machine Debug Manager, MDM, ""C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE"" [MS] Windows Driver Foundation - User-mode Driver Framework, WudfSvc, "C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup" {"C:\WINDOWS\System32\WUDFSvc.dll" [MS]} Print Monitors: --------------- HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS] ---------- (launch time: 2008-07-25 12:48:46) <<!>>: Suspicious data at a malware launch point. <<H>>: Suspicious data at a browser hijack point. + This report excludes default entries except where indicated. + To see *everywhere* the script checks and *everything* it finds, launch it from a command prompt or a shortcut with the -all parameter. + To search all directories of local fixed drives for DESKTOP.INI DLL launch points, use the -supp parameter or answer "No" at the first message box and "Yes" at the second message box. ---------- (total run time: 181 seconds, including 15 seconds for message boxes) Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Julho 28, 2008 Opa ItaloCCSL, O Malwarebytes AntiMalware é um produto relativamente novo, porém com grande eficácia na remoção de infecções comuns. O programa é pequeno, gratuito e em português. A sua instalação é o primeiro passo para a limpeza de um sistema operacional infectado. Neste tutorial você aprenderá a instalá-lo e executá-lo. 1) Primeiramente faça o download do programa: http://www.malwarebytes.org/mbam/program/mbam-setup.exe 2) Agora proceda a instalação do programa, conforme segue: Execute o programa de instalação: Logo após a execução do arquivo de instalação, será exibida a seguinte tela: Agora, clique em Instalar para concluir: Ao término da instalação deixe marcadas as opções de Atualização e Execução: Será exibida então a tela de atualização do programa: 3) Essa é a tela inicial do programa. Marque a opção Verificação Completa e clique no botão Verificar. Aguarde até o final da verificação: Ao concluir a verificação, será exibida essa mensagem: O resultado da verificação será exibido, com o nome dos arquivos e malwares encontrados. Para efetivar a limpeza, clique em Remover selecionados: Para concluir a limpeza haverá a necessidade da reinicialização do computador: O programa guarda os logs das verificações feitas na pasta C:\Documents and Settings\Seu nome de Usuario\Dados de aplicativos\Malwarebytes\Malwarebytes' Anti-Malware\Logs, que também pode ser acessados na aba Logs, dentro do programa. Retorne com o resultado da varredura. Créditos: Fabio Assolini. Link para a postagem original: aqui. Compartilhar este post Link para o post Compartilhar em outros sites
ItaloCCSL 0 Denunciar post Postado Julho 29, 2008 Jgarcia, Já fiz o que você me pediu. Tai: Malwarebytes' Anti-Malware 1.23 Versão do banco de dados: 1002 Windows 5.1.2600 Service Pack 2 19:04:44 28/7/2008 mbam-log-7-28-2008 (19-04-44).txt Tipo de Verificação: Completa (C:\|) Objetos verificados: 105639 Tempo decorrido: 57 minute(s), 33 second(s) Processos da Memória infectados: 0 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 5 Valores do Registro infectados: 0 Ítens do Registro infectados: 5 Pastas infectadas: 0 Arquivos infectados: 5 Processos da Memória infectados: (Nenhum ítem malicioso foi detectado) Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. Valores do Registro infectados: (Nenhum ítem malicioso foi detectado) Ítens do Registro infectados: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{44341c22-c643-42ba-a0fd-37020cd34d0c}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.115.2,85.255.112.6 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{3b0fda29-8843-46be-a4b8-15f1ce65190c}\NameServer (Trojan.DNSChanger) -> Data: 85.255.115.2,85.255.112.6 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{44341c22-c643-42ba-a0fd-37020cd34d0c}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.115.2,85.255.112.6 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{44341c22-c643-42ba-a0fd-37020cd34d0c}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.115.2,85.255.112.6 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{44341c22-c643-42ba-a0fd-37020cd34d0c}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.115.2,85.255.112.6 -> Quarantined and deleted successfully. Pastas infectadas: (Nenhum ítem malicioso foi detectado) Arquivos infectados: C:\Arquivos de programas\Oi Velox\Manager\dll\wpcap.dll (Spyware.Agent) -> Quarantined and deleted successfully. C:\Arquivos de programas\Oi Velox\Manager\dll\win2k\packet.dll (Spyware.Agent) -> Quarantined and deleted successfully. C:\Program Files\Fantasy Codecs\Codecs\DCT.exe (Adware.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{FEBDBD40-C60D-4481-AC4D-EF35DC5B3CF0}\RP314\A0045493.dll (Spyware.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{FEBDBD40-C60D-4481-AC4D-EF35DC5B3CF0}\RP314\A0045495.dll (Spyware.Agent) -> Quarantined and deleted successfully. Tai cara... Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Julho 29, 2008 :!: Apareceu hoje de novo! O erro no "update.exe" "0x7c350516" "0x000005f7" E agora jgarcia? Observe se, coincidentemente, o erro não está ocorrendo quando o Antivir tenta efetivar a atualização. Compartilhar este post Link para o post Compartilhar em outros sites
ItaloCCSL 0 Denunciar post Postado Julho 30, 2008 Jgarcia, Realmente há essa coincidência. Ontem eu estava com alguns programas em execução e notei que o meu anti-vírus estava realizando alguma atualização. Depois de um tempo tudo parou e voltou a aparecer esse problema. Depois de um tempo tudo voltou ao normal e hoje quando eu iria colocar o anti-vírus para fazer a varredura do computador ele mostrava que ontem não foi feita a atualização que ele deveria ter feito ontem. Creio que, realmente, esse seja o problema. :mellow: Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Julho 30, 2008 Jgarcia, Realmente há essa coincidência. Ontem eu estava com alguns programas em execução e notei que o meu anti-vírus estava realizando alguma atualização. Depois de um tempo tudo parou e voltou a aparecer esse problema. Depois de um tempo tudo voltou ao normal e hoje quando eu iria colocar o anti-vírus para fazer a varredura do computador ele mostrava que ontem não foi feita a atualização que ele deveria ter feito ontem. Creio que, realmente, esse seja o problema. :mellow: Exatamente. Eu fiz o teste e o erro se fez presente. A princípio a única solução é finalizar o processo via Gerenciador de Tarefas (CTRL + DEL). Vou reportar o problema para a Avira (fabricante do Antivir), a fim de que o problema seja sanado. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
ItaloCCSL 0 Denunciar post Postado Julho 30, 2008 Obrigado Jgarcia pela sua ajuda e paciência. Desculpa se cheguei a lhe incomodar quando mandava MP's. Já que o erro do tópico foi "resolvido" agora terei que abrir outro tópico caso outros erros apareçam e não sejam os mesmo, não é? Obrigado mais uma vez. :thumbsup: "RESOLVIDO" :!: Compartilhar este post Link para o post Compartilhar em outros sites
ItaloCCSL 0 Denunciar post Postado Julho 30, 2008 Sim só mais uma dúvida. Devo continuar com esses programas: Combofix, Msnfix, hijackthis, Malwarebytes' Anti-Malware e bankerfix ? Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Agosto 2, 2008 So se quando precisar denovo voce nao pudesse baixar novamente Mas é melhor excluir pois alguns o antivirus vive entendendo como virus Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Agosto 2, 2008 Sim só mais uma dúvida. Devo continuar com esses programas: Combofix, Msnfix, hijackthis, Malwarebytes' Anti-Malware e bankerfix ? Você pode manter o HijackThis, pois ele não necessita de atualização e praticamente não consome memória. Os demais você pode remover. :thumbsup: Ah, caso você tenha outro problema basta criar um novo tópico. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
ItaloCCSL 0 Denunciar post Postado Agosto 2, 2008 Valeu! :thumbsup: Obrigado por tudo! :bye: Compartilhar este post Link para o post Compartilhar em outros sites