Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Useless

[Arquivado] Computador lento e com erros...

Recommended Posts

Ola pessoal conforme regras do forum segue um log do hjt(so para constar qdo executei o programa ele apresentou um erro e pediu q o mesmo fosse reportado so q a pagina q abre nao e valida )

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:22:47, on 9/11/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\fxstaller.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AcroRd32.exe

C:\HiJackThis.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

 

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [Windows UDP Control Center] fxstaller.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Arquivos de programas\Eset\nod32krn.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 3579 bytes

 

 

espero q possam me ajudar tambei fiz um sacan on line no panda e ele encontrou alguns virus so q nao removi nenhum pois alguns deles so eram possiveis de remover com a versão paga do scanner...

 

hoje tambem o antivir detectou um virus :TR/Dropper.Gen q estava nesse diretorio:C:\Documents and Settings\-\Configurações locais\Temporary Internet Files\Content.IE5\EX7ZD5BC\spy[1].exe

por favor ajudem !!!!

 

agradecido desde ja. :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Useless,

 

Baixe o ComboFix em:

ComboFix

 

1) Desabilite o seu anti-vírus temporariamente;

 

2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos);

 

3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Leia atentamente o texto contido nesta janela e clique sobre “SIM” para continuar.

 

PS.: Caso não concorde com os termos clique sobre “NÃO” para sair do software, cabendo lembrar que o processo de desinfecção não será possível sem a continuidade do ComboFix.

 

4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console ante de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura.

 

Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente.

 

Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA.

 

Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADA COM SUCESSO”.

 

Clique sobre “SIM” para continuar a varredura.

 

5) O ComboFix iniciará o AUTOSCAN (aguarde).

 

ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco).

 

Ao término do processo a máquina será reiniciada para a emissão do relatório.

 

6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log ficará alocado em C:\ComboFix.txt.

 

7) Reabilite o seu anti-vírus;

 

8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta.

 

OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Em último caso, tente utilizar o ComboFix em MODO SEGURO.

 

OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá

 

bem eu fiz o q me foi instruido mas na resposta você diz q o combo fix reinicia a maqina para gerara o relatorio

aqui nao ocorreu isso ele gerou um relatorio sem reiniciar a maquina

 

aqui esta o relatorio gerado :

 

ComboFix 08-11-10.01 - - 2008-11-11 13:19:25.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.745 [GMT -2:00]

Executando de: c:\documents and settings\-\Desktop\ComboFix.exe

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2008-10-11 to 2008-11-11 ))))))))))))))))))))))))))))

.

 

2008-11-11 00:26 . 2008-11-11 12:58 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\FrostWire

2008-11-10 21:49 . 2008-11-11 13:06 <DIR> d-------- c:\documents and settings\-\Tracing

2008-11-10 21:48 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Microsoft

2008-11-10 21:47 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Windows Live

2008-11-10 21:35 . 2008-11-10 21:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live

2008-11-10 18:38 . 2007-07-30 19:19 43,352 --a------ c:\windows\system32\wups2.dll

2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy

2008-11-09 14:20 . 2008-11-09 14:20 401,720 --a------ C:\HiJackThis.exe

2008-11-09 11:02 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys

2008-11-09 11:01 . 2008-11-09 11:01 <DIR> d-------- c:\arquivos de programas\Panda Security

2008-11-09 10:37 . 2008-11-09 14:29 <DIR> d-------- c:\windows\SxsCaPendDel

2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\drivers\mouhid.sys

2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\dllcache\mouhid.sys

2008-10-16 21:01 . 2008-11-04 20:30 <DIR> d-------- c:\documents and settings\Samanta\Dados de aplicativos\skypePM

2008-10-16 21:01 . 2008-10-16 21:01 56 --ah----- c:\documents and settings\All Users\Dados de aplicativos\ezsidmv.dat

2008-10-16 20:56 . 2008-11-04 20:47 <DIR> d-------- c:\documents and settings\Samanta\Dados de aplicativos\Skype

2008-10-16 20:56 . 2008-10-16 20:56 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Skype

2008-10-15 18:37 . 2008-11-10 21:58 <DIR> dr-h----- c:\documents and settings\-\Recent

2008-10-15 18:33 . 2008-11-11 00:26 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\Mozilla

2008-10-15 18:33 . 2008-10-15 18:33 <DIR> d-------- c:\arquivos de programas\uTorrent

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-11-11 15:01 --------- d-----w c:\arquivos de programas\ESET

2008-10-15 20:37 --------- d-----w c:\documents and settings\-\Dados de aplicativos\uTorrent

2008-10-15 20:33 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SpeedBit

2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield

2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2008-09-19 04:54 --------- d-----w c:\arquivos de programas\CAPCOM

2008-09-09 02:03 51,712 ----a-w c:\windows\system32\sirenacm.dll

.

 

((((((((((((((((((((((((((((( snapshot@2008-11-11_13.11.20,14 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-11-06 23:14:47 171,488 ----a-w c:\windows\system32\FNTCACHE.DAT

+ 2008-11-11 15:17:04 174,672 ----a-w c:\windows\system32\FNTCACHE.DAT

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-21 7700480]

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Synchronizer.lnk

backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Reboot.exe]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Reboot.exe

backup=c:\windows\pss\Reboot.exeCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

--a------ 2008-01-11 23:16 39792 c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

--a------ 2006-11-16 19:04 139264 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

--a------ 2004-08-04 01:45 15360 c:\windows\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

--a------ 2007-04-03 20:29 165784 c:\arquivos de programas\DAEMON Tools\daemon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

--------- 2004-08-04 00:56 1667584 c:\arquivos de programas\Messenger\msmsgs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2006-01-12 15:40 155648 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

--a------ 2007-05-21 05:31 7700480 c:\windows\system32\nvcpl.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

--a------ 2007-05-21 05:31 86016 c:\windows\system32\nvmctray.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]

-ra------ 2006-09-14 03:00 577536 c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2008-06-10 05:27 144784 c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

-r------- 2005-05-03 08:43 69632 c:\windows\Alcmtr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

--a------ 2007-05-21 05:31 1622016 c:\windows\system32\nwiz.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

-r------- 2007-01-30 08:54 16116224 c:\windows\RTHDCPL.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]

-r------- 2006-05-16 08:04 2879488 c:\windows\SkyTel.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"h:\\e mule\\e mule novo\\eMule\\emule.exe"=

"h:\\quake 4\\Quake4Ded.exe"=

"c:\\Arquivos de programas\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=

"c:\\Documents and Settings\\-\\Desktop\\avaliaçoes\\Steam\\SteamApps\\maule\\counter-strike\\hl.exe"=

"h:\\metin2\\metin2.bin"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\Documents and Settings\\Samanta\\Configurações locais\\Dados de aplicativos\\Skype\\Phone\\Skype.exe"=

"h:\\cc3\\CABAL Online (BRAZIL)\\launcher\\update\\ESTdnheadless.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

 

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]

S3 XDva186;XDva186;c:\windows\system32\XDva186.sys [ ]

S3 XDva205;XDva205;c:\windows\system32\XDva205.sys [ ]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{493e56d7-9b67-11dc-b0e3-c9a503b11bf9}]

\Shell\AutoRun\command - J:\LaunchU3.exe -a

.

.

------- Scan Suplementar -------

.

R0 -: HKCU-Main,Start Page = hxxp://www.google.com.br/

R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s

O8 -: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

 

O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab

c:\windows\Downloaded Program Files\gbpdist.inf

c:\windows\Downloaded Program Files\gbpdist.dll

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-11-11 13:20:22

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-11-11 13:20:57

ComboFix-quarantined-files.txt 2008-11-11 15:20:55

ComboFix2.txt 2008-11-11 15:11:47

 

Pré-execução: 10 pasta(s) 23.819.268.096 bytes disponíveis

Pós execução: 10 pasta(s) 23,811,842,048 bytes disponíveis

 

137

 

 

 

Grato. :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Useless,

 

1. Baixe o BankerFix 3.0.

 

2. Desative o seu anti-vírus temporariamente.

 

3. Dê um duplo-clique sobre o bankerfix.exe. A janela do Banker Fix 3.0 abrir-se-á com a seguinte pergunta Instalar o BankerFix 3.0 / Install BankerFix 3.0 ? >> clique em SIM.

 

4. Uma janela informando que o BankerFix 3.0 será baixado via internet abrir-se-á >> clique sobre OK e aguarde. Na próxima janela clique em OK mais uma vez, a fim de que o BankerFix 3.0 seja iniciado.

 

5. Pressione qualquer tecla para dar continuidade ao processo e aguarde até que a varredura se complete. Tenha paciência, pois ela pode demorar alguns minutos.

 

6. Terminado o scan, leia a mensagem na tela e aperte Enter.

 

7. Habilite o seu anti-vírus.

 

8. Retorne com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\).

 

9. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C.

 

Abraços.

 

PS.: Caso apareça a seguinte mensagem: Site denunciado como foco de ataques!, não se preocupe e clique sobre Ignorar este alerta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

ola aqui segue o relatorio do banker fix:

 

BankerFix 3.0 VALKYRIE - Removedor de Bankers

Linha Defensiva | http://www.linhadefensiva.org

http://www.linhadefensiva.org/bankerfix/

-------------------------------------------------------

Data: 2008-11-18 - 22:30

-------------------------------------------------------

Lista de Definição: 2008-10-08-1 | CORE: 2008-09-30-2

=======================================================

 

 

 

----- Fim -------------------------

 

 

 

obrigado pela ajuda :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

opa, aqui esta esta o log do combofix:

 

 

ComboFix 08-11-19.08 - - 2008-11-20 10:36:07.4 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.727 [GMT -2:00]

Executando de: c:\documents and settings\-\Desktop\ComboFix.exe

* Criado um novo ponto de restauro

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2008-10-20 to 2008-11-20 ))))))))))))))))))))))))))))

.

 

2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7020

2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\AVIFiles

2008-11-19 23:09 . 2005-02-03 18:58 425,984 --a------ c:\windows\system32\GeoCodec.dll

2008-11-19 23:09 . 2005-02-03 18:58 425,984 -ra------ c:\windows\GeoCodec.dll

2008-11-19 23:09 . 2001-05-04 12:05 413,760 --a------ c:\windows\mpg4c32.dll

2008-11-19 23:09 . 2005-08-04 10:37 107,242 --a------ c:\windows\Stable_7000.xml

2008-11-19 23:09 . 2003-12-02 10:03 12,045 --a------ c:\windows\buzzer.wav

2008-11-19 23:08 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7040

2008-11-12 20:17 . 2008-11-12 20:18 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SimCity Societies

2008-11-12 19:51 . 2008-11-12 19:51 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\SPORE Creature Creator

2008-11-12 19:50 . 2008-11-12 19:50 <DIR> d-------- c:\arquivos de programas\Electronic Arts

2008-11-12 12:50 . 2008-11-20 03:08 <DIR> dr-h----- c:\documents and settings\-\Recent

2008-11-11 00:26 . 2008-11-14 10:26 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\FrostWire

2008-11-10 21:49 . 2008-11-20 10:29 <DIR> d-------- c:\documents and settings\-\Tracing

2008-11-10 21:48 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Microsoft

2008-11-10 21:47 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Windows Live

2008-11-10 21:35 . 2008-11-10 21:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live

2008-11-10 18:38 . 2007-07-30 19:19 43,352 --a------ c:\windows\system32\wups2.dll

2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy

2008-11-09 14:20 . 2008-11-09 14:20 401,720 --a------ C:\HiJackThis.exe

2008-11-09 11:02 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys

2008-11-09 11:01 . 2008-11-09 11:01 <DIR> d-------- c:\arquivos de programas\Panda Security

2008-11-09 10:37 . 2008-11-09 14:29 <DIR> d-------- c:\windows\SxsCaPendDel

2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\drivers\mouhid.sys

2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\dllcache\mouhid.sys

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-11-18 21:04 --------- d-----w c:\documents and settings\Samanta\Dados de aplicativos\Skype

2008-11-18 21:03 --------- d-----w c:\documents and settings\Samanta\Dados de aplicativos\skypePM

2008-11-12 21:51 107,888 ----a-w c:\windows\system32\CmdLineExt.dll

2008-11-12 21:50 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2008-11-11 15:01 --------- d-----w c:\arquivos de programas\ESET

2008-10-16 23:01 56 ---ha-w c:\documents and settings\All Users\Dados de aplicativos\ezsidmv.dat

2008-10-16 22:56 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Skype

2008-10-15 20:37 --------- d-----w c:\documents and settings\-\Dados de aplicativos\uTorrent

2008-10-15 20:33 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SpeedBit

2008-10-15 20:33 --------- d-----w c:\arquivos de programas\uTorrent

2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield

2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2008-09-09 02:03 51,712 ----a-w c:\windows\system32\sirenacm.dll

.

 

((((((((((((((((((((((((((((( snapshot@2008-11-11_13.11.20,14 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-11-12 21:39:43 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll

+ 2008-11-12 21:39:43 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll

+ 2008-11-12 21:39:43 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll

+ 2008-11-12 21:39:38 2,676,224 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2008-11-12 21:39:38 2,846,720 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2008-11-12 21:39:39 563,712 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2008-11-12 21:39:39 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2008-11-12 21:39:39 576,000 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2008-11-12 21:39:40 577,024 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2008-11-12 21:39:40 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2008-11-12 21:39:41 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2008-11-12 21:39:41 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2008-11-12 21:39:43 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2008-11-12 21:39:43 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll

+ 2008-11-12 21:39:44 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll

+ 2008-11-12 21:39:44 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll

+ 2008-11-12 21:39:44 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll

+ 2008-11-12 21:39:42 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll

+ 2008-11-12 21:15:28 68,608 ----a-w c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll

+ 2008-11-12 21:15:33 72,192 ----a-w c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll

+ 2008-11-12 21:15:33 4,308,992 ----a-w c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll

+ 2008-11-12 21:15:34 482,304 ----a-w c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll

+ 2008-11-12 21:15:31 2,878,976 ----a-w c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll

+ 2008-11-12 21:15:26 258,048 ----a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll

+ 2008-11-12 21:15:26 114,176 ----a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll

+ 2008-11-12 21:15:37 260,096 ----a-w c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll

+ 2008-11-12 21:15:30 5,025,792 ----a-w c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll

+ 2008-11-12 21:15:28 10,752 ----a-w c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll

+ 2008-11-12 21:15:26 503,808 ----a-w c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll

+ 2008-11-12 21:15:27 13,312 ----a-w c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll

+ 2008-11-12 21:15:32 8,192 ----a-w c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll

+ 2008-11-12 21:15:32 36,864 ----a-w c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll

+ 2008-11-12 21:15:32 5,632 ----a-w c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll

+ 2008-11-12 21:15:27 413,696 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll

+ 2008-11-12 21:15:27 36,864 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll

+ 2008-11-12 21:15:28 647,168 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll

+ 2008-11-12 21:15:28 73,728 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll

+ 2008-11-12 21:15:27 745,472 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll

+ 2008-11-12 21:15:38 110,592 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll

+ 2008-11-12 21:15:38 372,736 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll

+ 2008-11-12 21:15:25 28,672 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll

+ 2008-11-12 21:15:38 667,648 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll

+ 2008-11-12 21:15:39 5,632 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll

+ 2008-11-12 21:15:25 12,800 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll

+ 2008-11-12 21:15:25 32,768 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll

+ 2008-11-12 21:15:25 7,168 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll

+ 2008-11-12 21:15:36 110,592 ----a-w c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll

+ 2008-11-12 21:15:29 81,920 ----a-w c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll

+ 2008-11-12 21:15:36 389,120 ----a-w c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll

+ 2008-11-12 21:15:35 716,800 ----a-w c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll

+ 2008-11-12 21:15:26 884,736 ----a-w c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll

+ 2008-11-12 21:15:32 5,050,368 ----a-w c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll

+ 2008-11-12 21:15:29 188,416 ----a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll

+ 2008-11-12 21:15:29 397,312 ----a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll

+ 2008-11-12 21:15:29 81,920 ----a-w c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll

+ 2008-11-12 21:15:37 700,416 ----a-w c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll

+ 2008-11-12 21:15:35 368,640 ----a-w c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll

+ 2008-11-12 21:15:37 258,048 ----a-w c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll

+ 2008-11-12 21:15:35 299,008 ----a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll

+ 2008-11-12 21:15:36 131,072 ----a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll

+ 2008-11-12 21:15:28 258,048 ----a-w c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll

+ 2008-11-12 21:15:29 114,688 ----a-w c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll

+ 2008-11-12 21:15:38 835,584 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll

+ 2008-11-12 21:15:30 86,016 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll

+ 2008-11-12 21:15:30 823,296 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll

+ 2008-11-12 21:15:31 5,316,608 ----a-w c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll

+ 2008-11-12 21:15:31 2,035,712 ----a-w c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll

+ 2008-11-12 21:15:36 3,018,752 ----a-w c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll

+ 2008-11-12 21:44:58 26,624 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\83737f387b6d484a8faf51b0c452d0ab\Accessibility.ni.dll

+ 2008-11-12 21:45:07 860,160 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\5fe1824966ebc14b9a4e48ee0d588049\AspNetMMCExt.ni.dll

+ 2008-11-12 21:45:09 237,568 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3628ad3c4c940d48858df80510458a80\CustomMarshalers.ni.dll

+ 2008-11-12 21:45:08 15,360 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\1fb12cc689cdbd459005c8158ae0bd32\dfsvc.ni.exe

+ 2008-11-12 21:45:13 880,640 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6265f955e7b1f443baff82c89f98fc1f\Microsoft.Build.Engine.ni.dll

+ 2008-11-12 21:45:14 81,920 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\eefbc61c1aeadb4fabe9f1bd7c1bfe8b\Microsoft.Build.Framework.ni.dll

+ 2008-11-12 21:45:20 1,691,648 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\416cfce08d2ea0439a83ff7e7c848d5d\Microsoft.Build.Tasks.ni.dll

+ 2008-11-12 21:45:22 163,840 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\5850e74d7d3a454583f0bfe96fde8121\Microsoft.Build.Utilities.ni.dll

+ 2008-11-12 21:45:26 1,724,416 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\bafbbf202d18644fa7e14479aecbd1d2\Microsoft.VisualBasic.ni.dll

+ 2008-11-12 21:16:05 11,411,456 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9e28a04773999f489ce00eaf6897e8c8\mscorlib.ni.dll

+ 2008-11-12 21:45:29 962,560 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e62c8edb8799ba478b5676ac7dfc3c34\System.Configuration.ni.dll

+ 2008-11-12 21:16:59 6,688,768 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3beed49f719354c90937acb8ba63327\System.Data.ni.dll

+ 2008-11-12 21:45:31 1,716,224 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\0a445ff1ad9de049933d3be755030b25\System.Deployment.ni.dll

+ 2008-11-12 21:17:15 10,723,328 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\67ef7e7a5eae2e4786c424b502230bba\System.Design.ni.dll

+ 2008-11-12 21:45:36 512,000 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\3b426be44bf71f4788ef48ac6890fb3e\System.DirectoryServices.Protocols.ni.dll

+ 2008-11-12 21:45:34 1,220,608 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\d54c129977828c4d921833d5ad4104a2\System.DirectoryServices.ni.dll

+ 2008-11-12 21:16:20 229,376 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\d51e8cd737566b4ba93c44cee6ffce58\System.Drawing.Design.ni.dll

+ 2008-11-12 21:16:24 1,626,112 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\e343d4c95a53d6409e9a31aecbbffad6\System.Drawing.ni.dll

+ 2008-11-12 21:45:38 659,456 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\09b967d32a63dd46946a61f934503b6a\System.EnterpriseServices.ni.dll

+ 2008-11-12 21:45:38 294,912 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\09b967d32a63dd46946a61f934503b6a\System.EnterpriseServices.Wrapper.dll

+ 2008-11-12 21:45:40 729,088 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\55c338490f5e5f428dbf56c82cf3a663\System.Security.ni.dll

+ 2008-11-12 21:45:41 684,032 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\b763d2d3d60ed14ea7e090b66b3a4ee9\System.Transactions.ni.dll

+ 2008-11-12 21:46:12 2,310,144 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\6cc82df51cca6a4b9faaacb47aca43a6\System.Web.Mobile.ni.dll

+ 2008-11-12 21:46:12 237,568 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\1d5c3bd3cef3774f8474772647968db0\System.Web.RegularExpressions.ni.dll

+ 2008-11-12 21:46:17 1,945,600 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\b67fdc138937ee4fbe2d2e638a5152f1\System.Web.Services.ni.dll

+ 2008-11-12 21:46:04 11,808,768 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\27c60184ee07314ba83cf4cfc7b04483\System.Web.ni.dll

+ 2008-11-12 21:16:41 13,107,200 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\db7b155a53353f48a4473258c532ecd4\System.Windows.Forms.ni.dll

+ 2008-11-12 21:16:49 5,640,192 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f5fa18256e71a049b698a1878cf6feff\System.Xml.ni.dll

+ 2008-11-12 21:16:19 8,093,696 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System\68833cab64645f47b3439bad715e9b95\System.ni.dll

+ 2008-11-12 21:36:46 13,309,192 ----a-r c:\windows\Installer\{0B5154C0-8F00-4616-B0AB-6240AE80D9CE}\SimcitySocieties.exe

+ 2008-11-12 21:47:02 13,624,584 ----a-r c:\windows\Installer\{D1C7BB12-BE01-11DC-AAC9-EEBA55D89593}\SCSDestinations.exe

+ 2005-03-18 18:23:10 53,248 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll

+ 2005-03-18 18:23:10 12,800 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll

+ 2005-03-18 18:23:14 473,600 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll

+ 2004-09-29 14:38:58 2,676,224 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll

+ 2005-03-18 18:23:10 145,920 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll

+ 2005-03-18 18:23:10 159,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll

+ 2005-03-18 18:23:14 364,544 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll

+ 2005-03-18 18:23:12 178,176 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll

+ 2005-03-18 18:23:14 223,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll

+ 2004-12-01 17:53:06 2,846,720 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll

+ 2005-02-05 21:32:54 563,712 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll

+ 2005-03-18 19:23:14 567,296 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll

+ 2005-05-26 17:15:56 576,000 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll

+ 2005-07-22 19:21:34 577,024 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll

+ 2005-09-28 16:11:52 577,536 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll

+ 2005-12-05 19:20:50 577,536 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll

+ 2006-02-03 09:40:48 578,560 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll

+ 2006-03-31 13:27:50 578,560 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll

+ 2005-09-23 09:28:52 72,704 ----a-w c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_iehost.dll

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll

+ 2005-09-23 09:29:04 5,632 ----a-w c:\windows\Microsoft.NET\Framework\sbs_microsoft.vsa.vb.codedomprocessor.dll

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_system.data.dll

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_VsaVb7rt.dll

+ 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll

+ 2005-09-23 09:28:52 7,680 ----a-w c:\windows\Microsoft.NET\Framework\sbscmp10.dll

+ 2005-09-23 09:28:56 7,680 ----a-w c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll

+ 2005-09-23 09:28:58 7,680 ----a-w c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll

+ 2005-09-23 09:28:56 7,680 ----a-w c:\windows\Microsoft.NET\Framework\SharedReg12.dll

+ 2005-09-23 09:28:52 86,528 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll

+ 2005-09-23 09:28:36 18,944 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll

+ 2005-09-23 09:28:42 136,192 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll

+ 2005-09-23 09:28:44 4,608 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll

+ 2005-09-23 09:29:04 183,808 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll

+ 2005-09-23 09:28:28 208,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll

+ 2005-09-23 09:28:56 10,752 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll

+ 2005-09-23 09:28:58 138,240 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll

+ 2005-09-23 09:28:36 87,552 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll

+ 2005-09-23 09:28:58 55,488 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe

+ 2005-09-23 09:28:32 36,864 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe

+ 2005-09-23 09:28:32 10,752 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll

+ 2005-09-23 09:28:32 8,192 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll

+ 2005-09-23 09:28:32 23,552 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll

+ 2005-09-23 09:28:32 70,656 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll

+ 2005-09-23 09:28:32 13,824 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe

+ 2005-09-23 09:28:32 26,824 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe

+ 2005-09-23 09:28:32 106,496 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe

+ 2005-09-23 09:28:32 29,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe

+ 2005-09-23 09:28:32 29,888 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe

+ 2005-09-23 09:28:32 503,808 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll

+ 2005-09-23 09:28:56 106,496 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe

+ 2005-09-23 09:28:56 88,576 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll

+ 2005-09-23 09:28:42 76,984 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe

+ 2005-09-23 09:28:42 1,144,832 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll

+ 2005-09-23 09:28:42 13,312 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll

+ 2005-09-23 09:28:58 17,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll

+ 2005-09-23 09:28:56 68,608 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll

+ 2005-09-23 09:28:44 31,936 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe

+ 2005-09-23 09:28:38 52,736 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll

+ 2005-09-23 09:28:38 4,608 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe

+ 2005-09-23 09:29:12 547,840 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll

+ 2005-09-23 09:28:56 788,992 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll

+ 2005-09-23 09:28:50 9,216 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll

+ 2005-09-23 09:28:56 9,728 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe

+ 2005-09-23 09:28:56 8,192 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll

+ 2005-09-23 09:28:56 36,864 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll

+ 2005-09-23 09:28:56 5,632 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll

+ 2005-09-23 09:28:56 224,952 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe

+ 2005-09-23 09:28:56 28,672 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe

+ 2005-09-23 09:28:56 55,296 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll

+ 2005-09-23 09:28:56 72,192 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll

+ 2005-09-23 09:28:48 40,960 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe

+ 2005-09-23 09:01:16 609,472 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe

+ 2005-09-23 08:29:48 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1025.dll

+ 2005-09-23 08:32:24 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1028.dll

+ 2005-09-23 08:34:10 82,944 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1029.dll

+ 2005-09-23 08:34:12 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1030.dll

+ 2005-09-23 08:34:44 85,504 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1031.dll

+ 2005-09-23 08:36:24 87,552 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1032.dll

+ 2005-09-23 05:46:14 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1033.dll

+ 2005-09-23 08:38:26 81,408 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1035.dll

+ 2005-09-23 08:38:52 86,016 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1036.dll

+ 2005-09-23 08:40:30 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1037.dll

+ 2005-09-23 08:40:32 83,968 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1038.dll

+ 2005-09-23 08:40:56 84,480 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1040.dll

+ 2005-09-23 08:42:58 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1041.dll

+ 2005-09-23 08:44:58 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1042.dll

+ 2005-09-23 08:46:38 83,456 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1043.dll

+ 2005-09-23 08:46:38 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1044.dll

+ 2005-09-23 08:46:40 83,456 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1045.dll

+ 2005-09-23 08:47:04 82,432 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1046.dll

+ 2005-09-23 08:47:30 82,432 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1049.dll

+ 2005-09-23 08:47:32 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1053.dll

+ 2005-09-23 08:47:32 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1055.dll

+ 2005-09-23 08:30:18 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2052.dll

+ 2005-09-23 08:47:06 84,480 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2070.dll

+ 2005-09-23 08:29:50 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3076.dll

+ 2005-09-23 08:36:48 85,504 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3082.dll

+ 2005-09-23 09:57:06 245,408 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\unicows.dll

+ 2005-09-23 09:28:48 413,696 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll

+ 2005-09-23 09:28:48 36,864 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll

+ 2005-09-23 09:28:48 647,168 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll

+ 2005-09-23 09:28:48 73,728 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll

+ 2005-09-23 09:28:48 745,472 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll

+ 2005-09-23 09:29:10 110,592 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll

+ 2005-09-23 09:29:10 372,736 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll

+ 2005-09-23 09:29:08 667,648 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll

+ 2005-09-23 09:28:30 28,672 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll

+ 2005-09-23 09:29:10 5,632 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll

+ 2005-09-23 09:28:30 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll

+ 2005-09-23 09:28:30 12,800 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll

+ 2005-09-23 09:28:30 7,168 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll

+ 2005-09-23 09:28:32 87,552 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll

+ 2005-09-23 09:28:48 69,632 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe

+ 2005-09-23 09:28:56 800,768 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll

+ 2005-09-23 09:28:56 73,216 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll

+ 2005-09-23 09:28:56 288,768 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll

+ 2005-09-23 09:28:56 36,864 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll

+ 2005-09-23 09:28:56 326,144 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll

+ 2005-09-23 09:28:56 81,408 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll

+ 2005-09-23 09:28:56 4,308,992 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll

+ 2005-09-23 09:28:56 102,400 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll

+ 2005-09-23 09:29:00 330,752 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll

+ 2005-09-23 09:28:56 67,072 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll

+ 2005-09-23 09:28:50 9,216 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll

+ 2005-09-23 09:28:56 226,816 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll

+ 2005-09-23 09:28:56 66,240 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

+ 2005-09-23 09:28:56 10,240 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll

+ 2005-09-23 09:28:50 5,615,616 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll

+ 2005-09-23 09:29:00 22,528 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll

+ 2005-09-23 09:28:56 96,440 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe

+ 2005-09-23 09:28:56 14,848 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll

+ 2005-09-23 09:28:56 78,336 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll

+ 2005-09-23 09:28:50 136,192 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll

+ 2005-09-23 09:28:56 53,248 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe

+ 2005-09-23 09:28:56 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe

+ 2005-09-23 09:29:02 59,072 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe

+ 2005-09-23 09:28:58 7,680 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll

+ 2005-09-23 09:28:56 107,520 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\shfusion.dll

+ 2005-09-23 09:29:00 85,504 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll

+ 2005-09-23 09:28:56 377,344 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll

+ 2005-09-23 09:28:56 110,592 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll

+ 2005-09-23 09:28:58 389,120 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll

+ 2005-09-23 09:28:56 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll

+ 2005-09-23 09:28:56 2,878,976 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll

+ 2005-09-23 09:28:56 482,304 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll

+ 2005-09-23 09:28:56 716,800 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll

+ 2005-09-23 09:28:38 884,736 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll

+ 2005-09-23 09:28:56 5,050,368 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll

+ 2005-09-23 09:28:56 397,312 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll

+ 2005-09-23 09:28:56 188,416 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll

+ 2005-09-23 09:28:56 3,018,752 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll

+ 2005-09-23 09:28:56 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll

+ 2005-09-23 09:28:56 700,416 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll

+ 2005-09-23 09:28:56 258,048 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll

+ 2005-09-23 09:28:56 47,616 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll

+ 2005-09-23 09:28:56 114,176 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll

+ 2005-09-23 09:28:56 368,640 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll

+ 2005-09-23 09:28:56 258,048 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll

+ 2005-09-23 09:28:56 299,008 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll

+ 2005-09-23 09:28:56 131,072 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll

+ 2005-09-23 09:28:56 258,048 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll

+ 2005-09-23 09:28:56 114,688 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll

+ 2005-09-23 09:28:56 260,096 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll

+ 2005-09-23 09:28:56 5,025,792 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll

+ 2005-09-23 09:28:56 835,584 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll

+ 2005-09-23 09:28:56 86,016 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll

+ 2005-09-23 09:28:56 823,296 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll

+ 2005-09-23 09:28:56 5,316,608 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll

+ 2005-09-23 09:28:56 2,035,712 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll

+ 2005-09-23 09:28:56 71,680 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL

+ 2005-09-23 09:29:06 1,140,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe

+ 2005-09-23 09:28:30 1,306,624 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll

+ 2005-09-23 09:28:32 298,496 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll

+ 2005-09-23 09:28:56 28,160 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll

+ 2005-09-23 09:28:38 83,456 ----a-w c:\windows\system32\dfshim.dll

- 2008-11-06 23:14:47 171,488 ----a-w c:\windows\system32\FNTCACHE.DAT

+ 2008-11-12 19:24:08 173,872 ----a-w c:\windows\system32\FNTCACHE.DAT

+ 2005-09-23 09:28:52 270,848 ----a-w c:\windows\system32\mscoree.dll

+ 2005-09-23 09:28:52 150,016 ----a-w c:\windows\system32\mscorier.dll

+ 2005-09-23 09:28:52 74,240 ----a-w c:\windows\system32\mscories.dll

+ 2005-09-23 09:29:00 6,144 ----a-w c:\windows\system32\mui\0409\mscorees.dll

+ 2005-09-23 09:28:56 32,768 ----a-w c:\windows\system32\netfxperf.dll

- 2008-10-20 20:27:48 40,128 ----a-w c:\windows\system32\perfc009.dat

+ 2008-11-12 21:17:18 58,732 ----a-w c:\windows\system32\perfc009.dat

- 2008-10-20 20:27:48 48,846 ----a-w c:\windows\system32\perfc016.dat

+ 2008-11-12 21:17:18 67,450 ----a-w c:\windows\system32\perfc016.dat

- 2008-10-20 20:27:48 311,740 ----a-w c:\windows\system32\perfh009.dat

+ 2008-11-12 21:17:18 392,432 ----a-w c:\windows\system32\perfh009.dat

- 2008-10-20 20:27:48 344,734 ----a-w c:\windows\system32\perfh016.dat

+ 2008-11-12 21:17:18 425,426 ----a-w c:\windows\system32\perfh016.dat

+ 2005-07-14 20:23:54 143,360 ----a-w c:\windows\v7020\GvCrypto.dll

+ 2005-08-18 17:00:46 221,184 ----a-w c:\windows\v7020\LiveClient_7020.dll

+ 2005-07-14 20:23:54 143,360 ----a-w c:\windows\v7040\GvCrypto.dll

+ 2008-11-20 01:09:38 1,018,077 ----a-w c:\windows\v7040\Install.exe

+ 2005-08-18 17:00:46 221,184 ----a-w c:\windows\v7040\LiveClient_7020.dll

+ 2006-12-02 00:56:00 96,256 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll

+ 2006-12-02 02:25:52 1,101,824 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll

+ 2006-12-02 02:25:56 1,093,120 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll

+ 2006-12-02 02:25:58 69,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll

+ 2006-12-02 02:26:00 57,856 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll

+ 2006-12-02 02:08:00 40,960 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll

+ 2006-12-02 02:08:00 45,056 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll

+ 2006-12-02 02:08:00 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll

+ 2006-12-02 02:08:00 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll

+ 2006-12-02 02:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll

+ 2006-12-02 02:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll

+ 2006-12-02 02:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll

+ 2006-12-02 02:08:00 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll

+ 2006-12-02 02:08:00 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll

+ 2006-12-02 02:46:44 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll

+ 2008-11-12 21:15:26 258,048 ----a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll

+ 2008-11-12 21:15:26 114,176 ----a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll

.

-- Snapshot resetado para data atual --

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-21 7700480]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.mpg4"= c:\windows\mpg4c32.dll

"vidc.mpg2"= c:\windows\mpg4c32.dll

"vidc.mpg3"= c:\windows\mpg4c32.dll

"vidc.GEOX"= c:\windows\system32\GeoCodec.dll

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Synchronizer.lnk

backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Reboot.exe]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Reboot.exe

backup=c:\windows\pss\Reboot.exeCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

--a------ 2008-01-11 23:16 39792 c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

--a------ 2006-11-16 19:04 139264 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

--a------ 2004-08-04 01:45 15360 c:\windows\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

--a------ 2007-04-03 20:29 165784 c:\arquivos de programas\DAEMON Tools\daemon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

--------- 2004-08-04 00:56 1667584 c:\arquivos de programas\Messenger\msmsgs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2006-01-12 15:40 155648 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

--a------ 2007-05-21 05:31 7700480 c:\windows\system32\nvcpl.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

--a------ 2007-05-21 05:31 86016 c:\windows\system32\nvmctray.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]

-ra------ 2006-09-14 03:00 577536 c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2008-06-10 05:27 144784 c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

-r------- 2005-05-03 08:43 69632 c:\windows\Alcmtr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

--a------ 2007-05-21 05:31 1622016 c:\windows\system32\nwiz.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

-r------- 2007-01-30 08:54 16116224 c:\windows\RTHDCPL.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]

-r------- 2006-05-16 08:04 2879488 c:\windows\SkyTel.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"h:\\e mule\\e mule novo\\eMule\\emule.exe"=

"h:\\quake 4\\Quake4Ded.exe"=

"c:\\Arquivos de programas\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=

"c:\\Documents and Settings\\-\\Desktop\\avaliaçoes\\Steam\\SteamApps\\maule\\counter-strike\\hl.exe"=

"h:\\metin2\\metin2.bin"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\Documents and Settings\\Samanta\\Configurações locais\\Dados de aplicativos\\Skype\\Phone\\Skype.exe"=

"h:\\cc3\\CABAL Online (BRAZIL)\\launcher\\update\\ESTdnheadless.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

 

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-09 28544]

S3 XDva186;XDva186;\??\c:\windows\system32\XDva186.sys []

S3 XDva205;XDva205;\??\c:\windows\system32\XDva205.sys []

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{493e56d7-9b67-11dc-b0e3-c9a503b11bf9}]

\Shell\AutoRun\command - J:\LaunchU3.exe -a

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

LSP: c:\windows\system32\imon.dll

 

c:\windows\Downloaded Program Files\OCXDownloadChecker_6110.ocx - O16 -: {1DB93715-3B60-43EE-93E6-279BB3E1DF76}

hxxp://www.fredericoaovivo.com.br/site/cab/OCXChecker_6110.cab

c:\windows\Downloaded Program Files\OCXDownloadChecker.inf

 

c:\windows\Downloaded Program Files\gbpdist.dll - O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931}

hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab

c:\windows\Downloaded Program Files\gbpdist.inf

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-11-20 10:37:06

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-11-20 10:37:47

ComboFix-quarantined-files.txt 2008-11-20 12:37:44

ComboFix2.txt 2008-11-11 15:20:58

ComboFix3.txt 2008-11-11 15:11:47

 

Pré-execução: 10 pasta(s) 23.152.185.344 bytes disponíveis

Pós execução: 10 pasta(s) 23,151,853,568 bytes disponíveis

 

477

 

 

agradecido,

 

jgarcia você q e uma referencia em segurança e malwares,qdo li sua entrevista começei a usar o q você recomendou como

proteçao o antivir e o spybot....

esses ainda são as melhores proteçoes free??

 

 

vlw!!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Useless,

 

Siga as instruções:

 

1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote":

File::

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Reboot.exe

c:\documents and settings\All Users\Dados de aplicativos\ezsidmv.dat

c:\windows\pss\Reboot.exe

J:\LaunchU3.exe

Registry::

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Reboot.exe]

path=-

backup=-

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000000

"UpdatesDisableNotify"=dword:00000000

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{493e56d7-9b67-11dc-b0e3-c9a503b11bf9}]

ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário.

  • 2. Salve o arquivo como CFScript.txt;
     
    3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe.
    cfscript.gif
     
    4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis.

Abraços.

 

PS.: Execute a ação com o seu pendrive conectado ao PC.

Compartilhar este post


Link para o post
Compartilhar em outros sites

ola jgarcia !! desculpe pela demora em retornar os logs...tive problemas com minha internet....

 

 

ComboFix 08-11-30.01 - - 2008-11-30 19:59:17.5 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.732 [GMT -2:00]

Executando de: c:\documents and settings\-\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\-\Desktop\CFScript.txt.txt

* Criado um novo ponto de restauro

 

FILE ::

c:\documents and settings\All Users\Dados de aplicativos\ezsidmv.dat

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Reboot.exe

c:\windows\pss\Reboot.exe

J:\LaunchU3.exe

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\documents and settings\All Users\Dados de aplicativos\ezsidmv.dat

c:\windows\IE4 Error Log.txt

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2008-10-28 to 2008-11-30 ))))))))))))))))))))))))))))

.

 

2008-11-30 15:55 . 2008-11-30 15:55 <DIR> d-------- c:\arquivos de programas\SystemRequirementsLab

2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7020

2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\AVIFiles

2008-11-19 23:09 . 2005-02-03 18:58 425,984 --a------ c:\windows\system32\GeoCodec.dll

2008-11-19 23:09 . 2005-02-03 18:58 425,984 -ra------ c:\windows\GeoCodec.dll

2008-11-19 23:09 . 2001-05-04 12:05 413,760 --a------ c:\windows\mpg4c32.dll

2008-11-19 23:09 . 2005-08-04 10:37 107,242 --a------ c:\windows\Stable_7000.xml

2008-11-19 23:09 . 2003-12-02 10:03 12,045 --a------ c:\windows\buzzer.wav

2008-11-19 23:08 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7040

2008-11-12 20:17 . 2008-11-12 20:18 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SimCity Societies

2008-11-12 19:51 . 2008-11-12 19:51 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\SPORE Creature Creator

2008-11-12 19:50 . 2008-11-12 19:50 <DIR> d-------- c:\arquivos de programas\Electronic Arts

2008-11-12 12:50 . 2008-11-30 19:47 <DIR> dr-h----- c:\documents and settings\-\Recent

2008-11-11 00:26 . 2008-11-30 09:32 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\FrostWire

2008-11-10 21:49 . 2008-11-30 16:26 <DIR> d-------- c:\documents and settings\-\Tracing

2008-11-10 21:48 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Microsoft

2008-11-10 21:47 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Windows Live

2008-11-10 21:35 . 2008-11-10 21:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live

2008-11-10 18:38 . 2007-07-30 19:19 43,352 --a------ c:\windows\system32\wups2.dll

2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy

2008-11-09 14:20 . 2008-11-09 14:20 401,720 --a------ C:\HiJackThis.exe

2008-11-09 11:02 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys

2008-11-09 11:01 . 2008-11-09 11:01 <DIR> d-------- c:\arquivos de programas\Panda Security

2008-11-09 10:37 . 2008-11-09 14:29 <DIR> d-------- c:\windows\SxsCaPendDel

2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\drivers\mouhid.sys

2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\dllcache\mouhid.sys

2008-10-16 21:01 . 2008-11-29 08:09 <DIR> d-------- c:\documents and settings\Samanta\Dados de aplicativos\skypePM

2008-10-16 20:56 . 2008-11-29 19:33 <DIR> d-------- c:\documents and settings\Samanta\Dados de aplicativos\Skype

2008-10-16 20:56 . 2008-10-16 20:56 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Skype

2008-10-15 18:33 . 2008-11-11 00:26 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\Mozilla

2008-10-15 18:33 . 2008-10-15 18:33 <DIR> d-------- c:\arquivos de programas\uTorrent

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-11-25 02:28 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2008-11-12 21:51 107,888 ----a-w c:\windows\system32\CmdLineExt.dll

2008-11-12 21:50 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2008-11-11 15:01 --------- d-----w c:\arquivos de programas\ESET

2008-10-15 20:37 --------- d-----w c:\documents and settings\-\Dados de aplicativos\uTorrent

2008-10-15 20:33 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SpeedBit

2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield

2008-09-09 02:03 51,712 ----a-w c:\windows\system32\sirenacm.dll

.

 

((((((((((((((((((((((((((((( snapshot_2008-11-20_10.37.19,68 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-10-06 13:48:50 267,568 ----a-w c:\windows\Downloaded Program Files\sysreqlab_srl.dll

+ 2008-11-25 02:29:14 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1046-7B44-A81300000003}\SC_Reader.exe

- 2008-11-11 02:24:51 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys

+ 2008-11-26 00:53:31 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-21 7700480]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.mpg4"= c:\windows\mpg4c32.dll

"vidc.mpg2"= c:\windows\mpg4c32.dll

"vidc.mpg3"= c:\windows\mpg4c32.dll

"vidc.GEOX"= c:\windows\system32\GeoCodec.dll

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Synchronizer.lnk

backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Reboot.exe]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Reboot.exe

backup=c:\windows\pss\Reboot.exeCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

--a------ 2008-10-15 01:04 39792 c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

--a------ 2006-11-16 19:04 139264 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

--a------ 2004-08-04 01:45 15360 c:\windows\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

--a------ 2007-04-03 20:29 165784 c:\arquivos de programas\DAEMON Tools\daemon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

--------- 2004-08-04 00:56 1667584 c:\arquivos de programas\Messenger\msmsgs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2006-01-12 15:40 155648 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

--a------ 2007-05-21 05:31 7700480 c:\windows\system32\nvcpl.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

--a------ 2007-05-21 05:31 86016 c:\windows\system32\nvmctray.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]

-ra------ 2006-09-14 03:00 577536 c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2008-06-10 05:27 144784 c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

-r------- 2005-05-03 08:43 69632 c:\windows\Alcmtr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

--a------ 2007-05-21 05:31 1622016 c:\windows\system32\nwiz.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

-r------- 2007-01-30 08:54 16116224 c:\windows\RTHDCPL.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]

-r------- 2006-05-16 08:04 2879488 c:\windows\SkyTel.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"h:\\e mule\\e mule novo\\eMule\\emule.exe"=

"h:\\quake 4\\Quake4Ded.exe"=

"c:\\Arquivos de programas\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=

"c:\\Documents and Settings\\-\\Desktop\\avaliaçoes\\Steam\\SteamApps\\maule\\counter-strike\\hl.exe"=

"h:\\metin2\\metin2.bin"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\Documents and Settings\\Samanta\\Configurações locais\\Dados de aplicativos\\Skype\\Phone\\Skype.exe"=

"h:\\cc3\\CABAL Online (BRAZIL)\\launcher\\update\\ESTdnheadless.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

 

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-09 28544]

S3 XDva186;XDva186;\??\c:\windows\system32\XDva186.sys []

S3 XDva205;XDva205;\??\c:\windows\system32\XDva205.sys []

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-11-30 20:01:18

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'lsass.exe'(804)

c:\windows\system32\imon.dll

.

Tempo para conclusão: 2008-11-30 20:01:47

ComboFix-quarantined-files.txt 2008-11-30 22:01:45

ComboFix2.txt 2008-11-20 12:37:48

ComboFix3.txt 2008-11-11 15:20:58

ComboFix4.txt 2008-11-11 15:11:47

 

Pré-execução: 10 pasta(s) 21.661.913.088 bytes disponíveis

Pós execução: 10 pasta(s) 21,939,716,096 bytes disponíveis

 

160

 

 

 

aki segue log do hjt:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:06:30, on 30/11/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\WINDOWS\system32\notepad.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\internet explorer\iexplore.exe

C:\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} (OCXDownloadChecker Control) - http://www.fredericoaovivo.com.br/site/cab...hecker_6110.cab

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1226348371312

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Arquivos de programas\Eset\nod32krn.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 4946 bytes

 

 

não sei se o procedimento de desinfecção foi bem sussedido no pen drive pois venho notando q o computador nao o reconheçeu...

 

agradecido useless

 

ah e eu uso esta maqina para acessar coisas pessoais... não estou correndo nenhum risco de roubo de senhas ne??? =)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa Useless,

 

Siga as instruções:

 

1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote":

Registry::

[-HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Reboot.exe]

ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário.

  • 2. Salve o arquivo como CFScript.txt;
     
    3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe.
    cfscript.gif
     
    4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis.

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

log do combo fix:

 

 

 

 

ComboFix 08-12-05.01 - - 2008-12-05 15:14:07.6 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.727 [GMT -2:00]

Executando de: c:\documents and settings\-\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\-\Desktop\CFScript.txt.txt

* Criado um novo ponto de restauro

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-05 to 2008-12-05 ))))))))))))))))))))))))))))

.

 

2008-11-30 20:11 . 2008-11-30 20:17 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\NexonUS

2008-11-30 15:55 . 2008-11-30 15:55 <DIR> d-------- c:\arquivos de programas\SystemRequirementsLab

2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7020

2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\AVIFiles

2008-11-19 23:09 . 2005-02-03 18:58 425,984 --a------ c:\windows\system32\GeoCodec.dll

2008-11-19 23:09 . 2005-02-03 18:58 425,984 -ra------ c:\windows\GeoCodec.dll

2008-11-19 23:09 . 2001-05-04 12:05 413,760 --a------ c:\windows\mpg4c32.dll

2008-11-19 23:09 . 2005-08-04 10:37 107,242 --a------ c:\windows\Stable_7000.xml

2008-11-19 23:09 . 2003-12-02 10:03 12,045 --a------ c:\windows\buzzer.wav

2008-11-19 23:08 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7040

2008-11-12 20:17 . 2008-11-12 20:18 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SimCity Societies

2008-11-12 12:50 . 2008-12-05 11:56 <DIR> dr-h----- c:\documents and settings\-\Recent

2008-11-11 00:26 . 2008-11-30 09:32 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\FrostWire

2008-11-10 21:49 . 2008-12-04 00:14 <DIR> d-------- c:\documents and settings\-\Tracing

2008-11-10 21:48 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Microsoft

2008-11-10 21:47 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Windows Live

2008-11-10 21:35 . 2008-11-10 21:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live

2008-11-10 18:38 . 2007-07-30 19:19 43,352 --a------ c:\windows\system32\wups2.dll

2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy

2008-11-09 14:20 . 2008-11-09 14:20 401,720 --a------ C:\HiJackThis.exe

2008-11-09 11:01 . 2008-11-30 20:21 <DIR> d-------- c:\arquivos de programas\Panda Security

2008-11-09 10:37 . 2008-11-09 14:29 <DIR> d-------- c:\windows\SxsCaPendDel

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-11-30 22:20 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2008-11-29 21:33 --------- d-----w c:\documents and settings\Samanta\Dados de aplicativos\Skype

2008-11-29 10:09 --------- d-----w c:\documents and settings\Samanta\Dados de aplicativos\skypePM

2008-11-25 02:28 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2008-11-12 21:51 107,888 ----a-w c:\windows\system32\CmdLineExt.dll

2008-11-11 15:01 --------- d-----w c:\arquivos de programas\ESET

2008-10-16 22:56 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Skype

2008-10-15 20:37 --------- d-----w c:\documents and settings\-\Dados de aplicativos\uTorrent

2008-10-15 20:33 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SpeedBit

2008-10-15 20:33 --------- d-----w c:\arquivos de programas\uTorrent

2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield

2008-09-09 02:03 51,712 ----a-w c:\windows\system32\sirenacm.dll

.

 

((((((((((((((((((((((((((((( snapshot_2008-11-20_10.37.19,68 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-10-06 13:48:50 267,568 ----a-w c:\windows\Downloaded Program Files\sysreqlab_srl.dll

+ 2008-11-25 02:29:14 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1046-7B44-A81300000003}\SC_Reader.exe

- 2008-11-11 02:24:51 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys

+ 2008-11-26 00:53:31 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-21 7700480]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.mpg4"= c:\windows\mpg4c32.dll

"vidc.mpg2"= c:\windows\mpg4c32.dll

"vidc.mpg3"= c:\windows\mpg4c32.dll

"vidc.GEOX"= c:\windows\system32\GeoCodec.dll

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Synchronizer.lnk

backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

--a------ 2008-10-15 01:04 39792 c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

--a------ 2006-11-16 19:04 139264 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

--a------ 2004-08-04 01:45 15360 c:\windows\system32\ctfmon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]

--a------ 2007-04-03 20:29 165784 c:\arquivos de programas\DAEMON Tools\daemon.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

--------- 2004-08-04 00:56 1667584 c:\arquivos de programas\Messenger\msmsgs.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2006-01-12 15:40 155648 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]

--a------ 2007-05-21 05:31 7700480 c:\windows\system32\nvcpl.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]

--a------ 2007-05-21 05:31 86016 c:\windows\system32\nvmctray.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]

-ra------ 2006-09-14 03:00 577536 c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

--a------ 2008-06-10 05:27 144784 c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

-r------- 2005-05-03 08:43 69632 c:\windows\Alcmtr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]

--a------ 2007-05-21 05:31 1622016 c:\windows\system32\nwiz.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

-r------- 2007-01-30 08:54 16116224 c:\windows\RTHDCPL.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]

-r------- 2006-05-16 08:04 2879488 c:\windows\SkyTel.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"h:\\e mule\\e mule novo\\eMule\\emule.exe"=

"h:\\quake 4\\Quake4Ded.exe"=

"c:\\Arquivos de programas\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=

"c:\\Documents and Settings\\-\\Desktop\\avaliaçoes\\Steam\\SteamApps\\maule\\counter-strike\\hl.exe"=

"h:\\metin2\\metin2.bin"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\Documents and Settings\\Samanta\\Configurações locais\\Dados de aplicativos\\Skype\\Phone\\Skype.exe"=

"h:\\cc3\\CABAL Online (BRAZIL)\\launcher\\update\\ESTdnheadless.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"=

"h:\combat arms\Combat Arms\CombatArms.exe"= h:\combat arms\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe

"h:\combat arms\Combat Arms\Engine.exe"= h:\combat arms\Combat Arms\Engine.exe:*Enabled:Engine.exe

"h:\\combat arms\\Combat Arms\\NMService.exe"=

 

S3 XDva186;XDva186;\??\c:\windows\system32\XDva186.sys []

S3 XDva205;XDva205;\??\c:\windows\system32\XDva205.sys []

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

LSP: c:\windows\system32\imon.dll

 

c:\windows\Downloaded Program Files\OCXDownloadChecker_6110.ocx - O16 -: {1DB93715-3B60-43EE-93E6-279BB3E1DF76}

hxxp://www.fredericoaovivo.com.br/site/cab/OCXChecker_6110.cab

c:\windows\Downloaded Program Files\OCXDownloadChecker.inf

 

c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}

hxxp://www.srtest.com/srl_bin/sysreqlab_srl.cab

c:\windows\Downloaded Program Files\sysreqlab.osd

 

c:\windows\Downloaded Program Files\gbpdist.dll - O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931}

hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab

c:\windows\Downloaded Program Files\gbpdist.inf

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-05 15:15:34

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'lsass.exe'(804)

c:\windows\system32\imon.dll

.

Tempo para conclusão: 2008-12-05 15:16:06

ComboFix-quarantined-files.txt 2008-12-05 17:16:04

ComboFix2.txt 2008-11-30 22:01:48

ComboFix3.txt 2008-11-20 12:37:48

ComboFix4.txt 2008-11-11 15:20:58

ComboFix5.txt 2008-12-05 17:13:28

 

Pré-execução: 10 pasta(s) 20.586.512.384 bytes disponíveis

Pós execução: 10 pasta(s) 22,111,547,392 bytes disponíveis

 

163

 

 

 

 

log do hijackthis:

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:19:52, on 5/12/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\internet explorer\iexplore.exe

C:\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} (OCXDownloadChecker Control) - http://www.fredericoaovivo.com.br/site/cab...hecker_6110.cab

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1226348371312

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Arquivos de programas\Eset\nod32krn.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 4800 bytes

 

 

 

 

agradecido...

Compartilhar este post


Link para o post
Compartilhar em outros sites

Contagem de que?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá...o q eu quis dizer foi q eu ja havia postado o que me foi pedido mas na visualizaçao dos posts gerais ainda constava la como ultimo post sendo do jgarcia que esta me ajudando,quando na verdade o ultimo post ja havia sido meu...

 

obrigado ^^

Compartilhar este post


Link para o post
Compartilhar em outros sites

isso as vezes occorre por causa de cache no forum mas o importante é que seu post foi registrado

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.