Useless 0 Denunciar post Postado Novembro 9, 2008 Ola pessoal conforme regras do forum segue um log do hjt(so para constar qdo executei o programa ele apresentou um erro e pediu q o mesmo fosse reportado so q a pagina q abre nao e valida ) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:22:47, on 9/11/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\fxstaller.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\HiJackThis.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Windows UDP Control Center] fxstaller.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Arquivos de programas\Eset\nod32krn.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 3579 bytes espero q possam me ajudar tambei fiz um sacan on line no panda e ele encontrou alguns virus so q nao removi nenhum pois alguns deles so eram possiveis de remover com a versão paga do scanner... hoje tambem o antivir detectou um virus :TR/Dropper.Gen q estava nesse diretorio:C:\Documents and Settings\-\Configurações locais\Temporary Internet Files\Content.IE5\EX7ZD5BC\spy[1].exe por favor ajudem !!!! agradecido desde ja. :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Novembro 11, 2008 Opa Useless, Baixe o ComboFix em: ComboFix 1) Desabilite o seu anti-vírus temporariamente; 2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos); 3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Leia atentamente o texto contido nesta janela e clique sobre “SIM” para continuar. PS.: Caso não concorde com os termos clique sobre “NÃO” para sair do software, cabendo lembrar que o processo de desinfecção não será possível sem a continuidade do ComboFix. 4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console ante de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura. Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente. Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA. Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADA COM SUCESSO”. Clique sobre “SIM” para continuar a varredura. 5) O ComboFix iniciará o AUTOSCAN (aguarde). ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco). Ao término do processo a máquina será reiniciada para a emissão do relatório. 6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log ficará alocado em C:\ComboFix.txt. 7) Reabilite o seu anti-vírus; 8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta. OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Em último caso, tente utilizar o ComboFix em MODO SEGURO. OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Useless 0 Denunciar post Postado Novembro 11, 2008 Olá bem eu fiz o q me foi instruido mas na resposta você diz q o combo fix reinicia a maqina para gerara o relatorio aqui nao ocorreu isso ele gerou um relatorio sem reiniciar a maquina aqui esta o relatorio gerado : ComboFix 08-11-10.01 - - 2008-11-11 13:19:25.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.745 [GMT -2:00] Executando de: c:\documents and settings\-\Desktop\ComboFix.exe . (((((((((((((((( Arquivos/Ficheiros criados de 2008-10-11 to 2008-11-11 )))))))))))))))))))))))))))) . 2008-11-11 00:26 . 2008-11-11 12:58 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\FrostWire 2008-11-10 21:49 . 2008-11-11 13:06 <DIR> d-------- c:\documents and settings\-\Tracing 2008-11-10 21:48 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Microsoft 2008-11-10 21:47 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Windows Live 2008-11-10 21:35 . 2008-11-10 21:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live 2008-11-10 18:38 . 2007-07-30 19:19 43,352 --a------ c:\windows\system32\wups2.dll 2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy 2008-11-09 14:20 . 2008-11-09 14:20 401,720 --a------ C:\HiJackThis.exe 2008-11-09 11:02 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys 2008-11-09 11:01 . 2008-11-09 11:01 <DIR> d-------- c:\arquivos de programas\Panda Security 2008-11-09 10:37 . 2008-11-09 14:29 <DIR> d-------- c:\windows\SxsCaPendDel 2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\drivers\mouhid.sys 2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\dllcache\mouhid.sys 2008-10-16 21:01 . 2008-11-04 20:30 <DIR> d-------- c:\documents and settings\Samanta\Dados de aplicativos\skypePM 2008-10-16 21:01 . 2008-10-16 21:01 56 --ah----- c:\documents and settings\All Users\Dados de aplicativos\ezsidmv.dat 2008-10-16 20:56 . 2008-11-04 20:47 <DIR> d-------- c:\documents and settings\Samanta\Dados de aplicativos\Skype 2008-10-16 20:56 . 2008-10-16 20:56 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Skype 2008-10-15 18:37 . 2008-11-10 21:58 <DIR> dr-h----- c:\documents and settings\-\Recent 2008-10-15 18:33 . 2008-11-11 00:26 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\Mozilla 2008-10-15 18:33 . 2008-10-15 18:33 <DIR> d-------- c:\arquivos de programas\uTorrent . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-11 15:01 --------- d-----w c:\arquivos de programas\ESET 2008-10-15 20:37 --------- d-----w c:\documents and settings\-\Dados de aplicativos\uTorrent 2008-10-15 20:33 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SpeedBit 2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield 2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2008-09-19 04:54 --------- d-----w c:\arquivos de programas\CAPCOM 2008-09-09 02:03 51,712 ----a-w c:\windows\system32\sirenacm.dll . ((((((((((((((((((((((((((((( snapshot@2008-11-11_13.11.20,14 ))))))))))))))))))))))))))))))))))))))))) . - 2008-11-06 23:14:47 171,488 ----a-w c:\windows\system32\FNTCACHE.DAT + 2008-11-11 15:17:04 174,672 ----a-w c:\windows\system32\FNTCACHE.DAT . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-21 7700480] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Synchronizer.lnk backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Reboot.exe] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Reboot.exe backup=c:\windows\pss\Reboot.exeCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] --a------ 2008-01-11 23:16 39792 c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] --a------ 2006-11-16 19:04 139264 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2004-08-04 01:45 15360 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] --a------ 2007-04-03 20:29 165784 c:\arquivos de programas\DAEMON Tools\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --------- 2004-08-04 00:56 1667584 c:\arquivos de programas\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2006-01-12 15:40 155648 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2007-05-21 05:31 7700480 c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2007-05-21 05:31 86016 c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL] -ra------ 2006-09-14 03:00 577536 c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-06-10 05:27 144784 c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] -r------- 2005-05-03 08:43 69632 c:\windows\Alcmtr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2007-05-21 05:31 1622016 c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] -r------- 2007-01-30 08:54 16116224 c:\windows\RTHDCPL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] -r------- 2006-05-16 08:04 2879488 c:\windows\SkyTel.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "h:\\e mule\\e mule novo\\eMule\\emule.exe"= "h:\\quake 4\\Quake4Ded.exe"= "c:\\Arquivos de programas\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"= "c:\\Documents and Settings\\-\\Desktop\\avaliaçoes\\Steam\\SteamApps\\maule\\counter-strike\\hl.exe"= "h:\\metin2\\metin2.bin"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\Documents and Settings\\Samanta\\Configurações locais\\Dados de aplicativos\\Skype\\Phone\\Skype.exe"= "h:\\cc3\\CABAL Online (BRAZIL)\\launcher\\update\\ESTdnheadless.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-19 28544] S3 XDva186;XDva186;c:\windows\system32\XDva186.sys [ ] S3 XDva205;XDva205;c:\windows\system32\XDva205.sys [ ] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{493e56d7-9b67-11dc-b0e3-c9a503b11bf9}] \Shell\AutoRun\command - J:\LaunchU3.exe -a . . ------- Scan Suplementar ------- . R0 -: HKCU-Main,Start Page = hxxp://www.google.com.br/ R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s O8 -: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab c:\windows\Downloaded Program Files\gbpdist.inf c:\windows\Downloaded Program Files\gbpdist.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-11 13:20:22 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-11-11 13:20:57 ComboFix-quarantined-files.txt 2008-11-11 15:20:55 ComboFix2.txt 2008-11-11 15:11:47 Pré-execução: 10 pasta(s) 23.819.268.096 bytes disponíveis Pós execução: 10 pasta(s) 23,811,842,048 bytes disponíveis 137 Grato. :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Novembro 17, 2008 Opa Useless, 1. Baixe o BankerFix 3.0. 2. Desative o seu anti-vírus temporariamente. 3. Dê um duplo-clique sobre o bankerfix.exe. A janela do Banker Fix 3.0 abrir-se-á com a seguinte pergunta Instalar o BankerFix 3.0 / Install BankerFix 3.0 ? >> clique em SIM. 4. Uma janela informando que o BankerFix 3.0 será baixado via internet abrir-se-á >> clique sobre OK e aguarde. Na próxima janela clique em OK mais uma vez, a fim de que o BankerFix 3.0 seja iniciado. 5. Pressione qualquer tecla para dar continuidade ao processo e aguarde até que a varredura se complete. Tenha paciência, pois ela pode demorar alguns minutos. 6. Terminado o scan, leia a mensagem na tela e aperte Enter. 7. Habilite o seu anti-vírus. 8. Retorne com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\). 9. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C. Abraços. PS.: Caso apareça a seguinte mensagem: Site denunciado como foco de ataques!, não se preocupe e clique sobre Ignorar este alerta. Compartilhar este post Link para o post Compartilhar em outros sites
Useless 0 Denunciar post Postado Novembro 19, 2008 ola aqui segue o relatorio do banker fix: BankerFix 3.0 VALKYRIE - Removedor de Bankers Linha Defensiva | http://www.linhadefensiva.org http://www.linhadefensiva.org/bankerfix/ ------------------------------------------------------- Data: 2008-11-18 - 22:30 ------------------------------------------------------- Lista de Definição: 2008-10-08-1 | CORE: 2008-09-30-2 ======================================================= ----- Fim ------------------------- obrigado pela ajuda :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Novembro 19, 2008 Opa Useless, Poste um novo log do ComboFix. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Useless 0 Denunciar post Postado Novembro 20, 2008 opa, aqui esta esta o log do combofix: ComboFix 08-11-19.08 - - 2008-11-20 10:36:07.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.727 [GMT -2:00] Executando de: c:\documents and settings\-\Desktop\ComboFix.exe * Criado um novo ponto de restauro . (((((((((((((((( Arquivos/Ficheiros criados de 2008-10-20 to 2008-11-20 )))))))))))))))))))))))))))) . 2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7020 2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\AVIFiles 2008-11-19 23:09 . 2005-02-03 18:58 425,984 --a------ c:\windows\system32\GeoCodec.dll 2008-11-19 23:09 . 2005-02-03 18:58 425,984 -ra------ c:\windows\GeoCodec.dll 2008-11-19 23:09 . 2001-05-04 12:05 413,760 --a------ c:\windows\mpg4c32.dll 2008-11-19 23:09 . 2005-08-04 10:37 107,242 --a------ c:\windows\Stable_7000.xml 2008-11-19 23:09 . 2003-12-02 10:03 12,045 --a------ c:\windows\buzzer.wav 2008-11-19 23:08 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7040 2008-11-12 20:17 . 2008-11-12 20:18 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SimCity Societies 2008-11-12 19:51 . 2008-11-12 19:51 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\SPORE Creature Creator 2008-11-12 19:50 . 2008-11-12 19:50 <DIR> d-------- c:\arquivos de programas\Electronic Arts 2008-11-12 12:50 . 2008-11-20 03:08 <DIR> dr-h----- c:\documents and settings\-\Recent 2008-11-11 00:26 . 2008-11-14 10:26 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\FrostWire 2008-11-10 21:49 . 2008-11-20 10:29 <DIR> d-------- c:\documents and settings\-\Tracing 2008-11-10 21:48 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Microsoft 2008-11-10 21:47 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Windows Live 2008-11-10 21:35 . 2008-11-10 21:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live 2008-11-10 18:38 . 2007-07-30 19:19 43,352 --a------ c:\windows\system32\wups2.dll 2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy 2008-11-09 14:20 . 2008-11-09 14:20 401,720 --a------ C:\HiJackThis.exe 2008-11-09 11:02 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys 2008-11-09 11:01 . 2008-11-09 11:01 <DIR> d-------- c:\arquivos de programas\Panda Security 2008-11-09 10:37 . 2008-11-09 14:29 <DIR> d-------- c:\windows\SxsCaPendDel 2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\drivers\mouhid.sys 2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\dllcache\mouhid.sys . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-18 21:04 --------- d-----w c:\documents and settings\Samanta\Dados de aplicativos\Skype 2008-11-18 21:03 --------- d-----w c:\documents and settings\Samanta\Dados de aplicativos\skypePM 2008-11-12 21:51 107,888 ----a-w c:\windows\system32\CmdLineExt.dll 2008-11-12 21:50 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-11-11 15:01 --------- d-----w c:\arquivos de programas\ESET 2008-10-16 23:01 56 ---ha-w c:\documents and settings\All Users\Dados de aplicativos\ezsidmv.dat 2008-10-16 22:56 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Skype 2008-10-15 20:37 --------- d-----w c:\documents and settings\-\Dados de aplicativos\uTorrent 2008-10-15 20:33 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SpeedBit 2008-10-15 20:33 --------- d-----w c:\arquivos de programas\uTorrent 2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield 2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2008-09-09 02:03 51,712 ----a-w c:\windows\system32\sirenacm.dll . ((((((((((((((((((((((((((((( snapshot@2008-11-11_13.11.20,14 ))))))))))))))))))))))))))))))))))))))))) . + 2008-11-12 21:39:43 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll + 2008-11-12 21:39:43 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll + 2008-11-12 21:39:43 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll + 2008-11-12 21:39:38 2,676,224 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2008-11-12 21:39:38 2,846,720 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2008-11-12 21:39:39 563,712 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2008-11-12 21:39:39 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2008-11-12 21:39:39 576,000 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2008-11-12 21:39:40 577,024 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2008-11-12 21:39:40 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2008-11-12 21:39:41 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2008-11-12 21:39:41 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2008-11-12 21:39:43 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll + 2008-11-12 21:39:43 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll + 2008-11-12 21:39:44 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll + 2008-11-12 21:39:44 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll + 2008-11-12 21:39:44 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll + 2008-11-12 21:39:42 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll + 2008-11-12 21:15:28 68,608 ----a-w c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll + 2008-11-12 21:15:33 72,192 ----a-w c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll + 2008-11-12 21:15:33 4,308,992 ----a-w c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll + 2008-11-12 21:15:34 482,304 ----a-w c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll + 2008-11-12 21:15:31 2,878,976 ----a-w c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll + 2008-11-12 21:15:26 258,048 ----a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll + 2008-11-12 21:15:26 114,176 ----a-w c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll + 2008-11-12 21:15:37 260,096 ----a-w c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll + 2008-11-12 21:15:30 5,025,792 ----a-w c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll + 2008-11-12 21:15:28 10,752 ----a-w c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll + 2008-11-12 21:15:26 503,808 ----a-w c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll + 2008-11-12 21:15:27 13,312 ----a-w c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll + 2008-11-12 21:15:32 8,192 ----a-w c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll + 2008-11-12 21:15:32 36,864 ----a-w c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll + 2008-11-12 21:15:32 5,632 ----a-w c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll + 2008-11-12 21:15:27 413,696 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll + 2008-11-12 21:15:27 36,864 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll + 2008-11-12 21:15:28 647,168 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll + 2008-11-12 21:15:28 73,728 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll + 2008-11-12 21:15:27 745,472 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll + 2008-11-12 21:15:38 110,592 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll + 2008-11-12 21:15:38 372,736 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll + 2008-11-12 21:15:25 28,672 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll + 2008-11-12 21:15:38 667,648 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll + 2008-11-12 21:15:39 5,632 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll + 2008-11-12 21:15:25 12,800 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2008-11-12 21:15:25 32,768 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll + 2008-11-12 21:15:25 7,168 ----a-w c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll + 2008-11-12 21:15:36 110,592 ----a-w c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll + 2008-11-12 21:15:29 81,920 ----a-w c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll + 2008-11-12 21:15:36 389,120 ----a-w c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll + 2008-11-12 21:15:35 716,800 ----a-w c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll + 2008-11-12 21:15:26 884,736 ----a-w c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll + 2008-11-12 21:15:32 5,050,368 ----a-w c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll + 2008-11-12 21:15:29 188,416 ----a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll + 2008-11-12 21:15:29 397,312 ----a-w c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll + 2008-11-12 21:15:29 81,920 ----a-w c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll + 2008-11-12 21:15:37 700,416 ----a-w c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll + 2008-11-12 21:15:35 368,640 ----a-w c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll + 2008-11-12 21:15:37 258,048 ----a-w c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll + 2008-11-12 21:15:35 299,008 ----a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll + 2008-11-12 21:15:36 131,072 ----a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll + 2008-11-12 21:15:28 258,048 ----a-w c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll + 2008-11-12 21:15:29 114,688 ----a-w c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll + 2008-11-12 21:15:38 835,584 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll + 2008-11-12 21:15:30 86,016 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll + 2008-11-12 21:15:30 823,296 ----a-w c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll + 2008-11-12 21:15:31 5,316,608 ----a-w c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll + 2008-11-12 21:15:31 2,035,712 ----a-w c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll + 2008-11-12 21:15:36 3,018,752 ----a-w c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll + 2008-11-12 21:44:58 26,624 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\83737f387b6d484a8faf51b0c452d0ab\Accessibility.ni.dll + 2008-11-12 21:45:07 860,160 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\5fe1824966ebc14b9a4e48ee0d588049\AspNetMMCExt.ni.dll + 2008-11-12 21:45:09 237,568 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3628ad3c4c940d48858df80510458a80\CustomMarshalers.ni.dll + 2008-11-12 21:45:08 15,360 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\1fb12cc689cdbd459005c8158ae0bd32\dfsvc.ni.exe + 2008-11-12 21:45:13 880,640 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6265f955e7b1f443baff82c89f98fc1f\Microsoft.Build.Engine.ni.dll + 2008-11-12 21:45:14 81,920 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\eefbc61c1aeadb4fabe9f1bd7c1bfe8b\Microsoft.Build.Framework.ni.dll + 2008-11-12 21:45:20 1,691,648 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\416cfce08d2ea0439a83ff7e7c848d5d\Microsoft.Build.Tasks.ni.dll + 2008-11-12 21:45:22 163,840 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\5850e74d7d3a454583f0bfe96fde8121\Microsoft.Build.Utilities.ni.dll + 2008-11-12 21:45:26 1,724,416 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\bafbbf202d18644fa7e14479aecbd1d2\Microsoft.VisualBasic.ni.dll + 2008-11-12 21:16:05 11,411,456 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9e28a04773999f489ce00eaf6897e8c8\mscorlib.ni.dll + 2008-11-12 21:45:29 962,560 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e62c8edb8799ba478b5676ac7dfc3c34\System.Configuration.ni.dll + 2008-11-12 21:16:59 6,688,768 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3beed49f719354c90937acb8ba63327\System.Data.ni.dll + 2008-11-12 21:45:31 1,716,224 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\0a445ff1ad9de049933d3be755030b25\System.Deployment.ni.dll + 2008-11-12 21:17:15 10,723,328 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\67ef7e7a5eae2e4786c424b502230bba\System.Design.ni.dll + 2008-11-12 21:45:36 512,000 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\3b426be44bf71f4788ef48ac6890fb3e\System.DirectoryServices.Protocols.ni.dll + 2008-11-12 21:45:34 1,220,608 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\d54c129977828c4d921833d5ad4104a2\System.DirectoryServices.ni.dll + 2008-11-12 21:16:20 229,376 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\d51e8cd737566b4ba93c44cee6ffce58\System.Drawing.Design.ni.dll + 2008-11-12 21:16:24 1,626,112 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\e343d4c95a53d6409e9a31aecbbffad6\System.Drawing.ni.dll + 2008-11-12 21:45:38 659,456 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\09b967d32a63dd46946a61f934503b6a\System.EnterpriseServices.ni.dll + 2008-11-12 21:45:38 294,912 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\09b967d32a63dd46946a61f934503b6a\System.EnterpriseServices.Wrapper.dll + 2008-11-12 21:45:40 729,088 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\55c338490f5e5f428dbf56c82cf3a663\System.Security.ni.dll + 2008-11-12 21:45:41 684,032 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\b763d2d3d60ed14ea7e090b66b3a4ee9\System.Transactions.ni.dll + 2008-11-12 21:46:12 2,310,144 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\6cc82df51cca6a4b9faaacb47aca43a6\System.Web.Mobile.ni.dll + 2008-11-12 21:46:12 237,568 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\1d5c3bd3cef3774f8474772647968db0\System.Web.RegularExpressions.ni.dll + 2008-11-12 21:46:17 1,945,600 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\b67fdc138937ee4fbe2d2e638a5152f1\System.Web.Services.ni.dll + 2008-11-12 21:46:04 11,808,768 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\27c60184ee07314ba83cf4cfc7b04483\System.Web.ni.dll + 2008-11-12 21:16:41 13,107,200 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\db7b155a53353f48a4473258c532ecd4\System.Windows.Forms.ni.dll + 2008-11-12 21:16:49 5,640,192 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f5fa18256e71a049b698a1878cf6feff\System.Xml.ni.dll + 2008-11-12 21:16:19 8,093,696 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System\68833cab64645f47b3439bad715e9b95\System.ni.dll + 2008-11-12 21:36:46 13,309,192 ----a-r c:\windows\Installer\{0B5154C0-8F00-4616-B0AB-6240AE80D9CE}\SimcitySocieties.exe + 2008-11-12 21:47:02 13,624,584 ----a-r c:\windows\Installer\{D1C7BB12-BE01-11DC-AAC9-EEBA55D89593}\SCSDestinations.exe + 2005-03-18 18:23:10 53,248 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll + 2005-03-18 18:23:10 12,800 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll + 2005-03-18 18:23:14 473,600 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll + 2004-09-29 14:38:58 2,676,224 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll + 2005-03-18 18:23:10 145,920 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll + 2005-03-18 18:23:10 159,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll + 2005-03-18 18:23:14 364,544 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll + 2005-03-18 18:23:12 178,176 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll + 2005-03-18 18:23:14 223,232 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll + 2004-12-01 17:53:06 2,846,720 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll + 2005-02-05 21:32:54 563,712 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll + 2005-03-18 19:23:14 567,296 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll + 2005-05-26 17:15:56 576,000 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll + 2005-07-22 19:21:34 577,024 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll + 2005-09-28 16:11:52 577,536 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll + 2005-12-05 19:20:50 577,536 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll + 2006-02-03 09:40:48 578,560 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll + 2006-03-31 13:27:50 578,560 ----a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll + 2005-09-23 09:28:52 72,704 ----a-w c:\windows\Microsoft.NET\Framework\NETFXSBS10.exe + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_diasymreader.dll + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_iehost.dll + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_microsoft.jscript.dll + 2005-09-23 09:29:04 5,632 ----a-w c:\windows\Microsoft.NET\Framework\sbs_microsoft.vsa.vb.codedomprocessor.dll + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_mscordbi.dll + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_mscorrc.dll + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_mscorsec.dll + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_system.configuration.install.dll + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_system.data.dll + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_system.enterpriseservices.dll + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_VsaVb7rt.dll + 2005-09-23 09:29:04 5,120 ----a-w c:\windows\Microsoft.NET\Framework\sbs_wminet_utils.dll + 2005-09-23 09:28:52 7,680 ----a-w c:\windows\Microsoft.NET\Framework\sbscmp10.dll + 2005-09-23 09:28:56 7,680 ----a-w c:\windows\Microsoft.NET\Framework\sbscmp20_mscorwks.dll + 2005-09-23 09:28:58 7,680 ----a-w c:\windows\Microsoft.NET\Framework\sbscmp20_perfcounter.dll + 2005-09-23 09:28:56 7,680 ----a-w c:\windows\Microsoft.NET\Framework\SharedReg12.dll + 2005-09-23 09:28:52 86,528 ----a-w c:\windows\Microsoft.NET\Framework\v1.0.3705\mscormmc.dll + 2005-09-23 09:28:36 18,944 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\alinkui.dll + 2005-09-23 09:28:42 136,192 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\cscompui.dll + 2005-09-23 09:28:44 4,608 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\CvtResUI.dll + 2005-09-23 09:29:04 183,808 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\vbc7ui.dll + 2005-09-23 09:28:28 208,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\1033\Vsavb7rtUI.dll + 2005-09-23 09:28:56 10,752 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Accessibility.dll + 2005-09-23 09:28:58 138,240 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\AdoNetDiag.dll + 2005-09-23 09:28:36 87,552 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\alink.dll + 2005-09-23 09:28:58 55,488 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\AppLaunch.exe + 2005-09-23 09:28:32 36,864 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe + 2005-09-23 09:28:32 10,752 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_filter.dll + 2005-09-23 09:28:32 8,192 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll + 2005-09-23 09:28:32 23,552 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll + 2005-09-23 09:28:32 70,656 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_rc.dll + 2005-09-23 09:28:32 13,824 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe + 2005-09-23 09:28:32 26,824 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe + 2005-09-23 09:28:32 106,496 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe + 2005-09-23 09:28:32 29,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe + 2005-09-23 09:28:32 29,888 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe + 2005-09-23 09:28:32 503,808 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\AspNetMMCExt.dll + 2005-09-23 09:28:56 106,496 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\CasPol.exe + 2005-09-23 09:28:56 88,576 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\CORPerfMonExt.dll + 2005-09-23 09:28:42 76,984 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\csc.exe + 2005-09-23 09:28:42 1,144,832 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll + 2005-09-23 09:28:42 13,312 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\cscompmgd.dll + 2005-09-23 09:28:58 17,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll + 2005-09-23 09:28:56 68,608 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\CustomMarshalers.dll + 2005-09-23 09:28:44 31,936 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe + 2005-09-23 09:28:38 52,736 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\dfdll.dll + 2005-09-23 09:28:38 4,608 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe + 2005-09-23 09:29:12 547,840 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll + 2005-09-23 09:28:56 788,992 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\EventLogMessages.dll + 2005-09-23 09:28:50 9,216 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\fusion.dll + 2005-09-23 09:28:56 9,728 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExec.exe + 2005-09-23 09:28:56 8,192 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IEExecRemote.dll + 2005-09-23 09:28:56 36,864 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IEHost.dll + 2005-09-23 09:28:56 5,632 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\IIEHost.dll + 2005-09-23 09:28:56 224,952 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ilasm.exe + 2005-09-23 09:28:56 28,672 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe + 2005-09-23 09:28:56 55,296 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\InstallUtilLib.dll + 2005-09-23 09:28:56 72,192 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ISymWrapper.dll + 2005-09-23 09:28:48 40,960 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\jsc.exe + 2005-09-23 09:01:16 609,472 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe + 2005-09-23 08:29:48 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1025.dll + 2005-09-23 08:32:24 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1028.dll + 2005-09-23 08:34:10 82,944 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1029.dll + 2005-09-23 08:34:12 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1030.dll + 2005-09-23 08:34:44 85,504 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1031.dll + 2005-09-23 08:36:24 87,552 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1032.dll + 2005-09-23 05:46:14 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1033.dll + 2005-09-23 08:38:26 81,408 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1035.dll + 2005-09-23 08:38:52 86,016 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1036.dll + 2005-09-23 08:40:30 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1037.dll + 2005-09-23 08:40:32 83,968 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1038.dll + 2005-09-23 08:40:56 84,480 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1040.dll + 2005-09-23 08:42:58 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1041.dll + 2005-09-23 08:44:58 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1042.dll + 2005-09-23 08:46:38 83,456 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1043.dll + 2005-09-23 08:46:38 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1044.dll + 2005-09-23 08:46:40 83,456 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1045.dll + 2005-09-23 08:47:04 82,432 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1046.dll + 2005-09-23 08:47:30 82,432 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1049.dll + 2005-09-23 08:47:32 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1053.dll + 2005-09-23 08:47:32 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.1055.dll + 2005-09-23 08:30:18 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2052.dll + 2005-09-23 08:47:06 84,480 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.2070.dll + 2005-09-23 08:29:50 80,896 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3076.dll + 2005-09-23 08:36:48 85,504 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.res.3082.dll + 2005-09-23 09:57:06 245,408 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\unicows.dll + 2005-09-23 09:28:48 413,696 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Engine.dll + 2005-09-23 09:28:48 36,864 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Framework.dll + 2005-09-23 09:28:48 647,168 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Tasks.dll + 2005-09-23 09:28:48 73,728 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Build.Utilities.dll + 2005-09-23 09:28:48 745,472 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.JScript.dll + 2005-09-23 09:29:10 110,592 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.Data.dll + 2005-09-23 09:29:10 372,736 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Compatibility.dll + 2005-09-23 09:29:08 667,648 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.dll + 2005-09-23 09:28:30 28,672 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualBasic.Vsa.dll + 2005-09-23 09:29:10 5,632 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.VisualC.Dll + 2005-09-23 09:28:30 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.dll + 2005-09-23 09:28:30 12,800 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft.Vsa.Vb.CodeDOMProcessor.dll + 2005-09-23 09:28:30 7,168 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft_VsaVb.dll + 2005-09-23 09:28:32 87,552 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\MmcAspExt.dll + 2005-09-23 09:28:48 69,632 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe + 2005-09-23 09:28:56 800,768 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll + 2005-09-23 09:28:56 73,216 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbc.dll + 2005-09-23 09:28:56 288,768 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscordbi.dll + 2005-09-23 09:28:56 36,864 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorie.dll + 2005-09-23 09:28:56 326,144 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll + 2005-09-23 09:28:56 81,408 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorld.dll + 2005-09-23 09:28:56 4,308,992 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll + 2005-09-23 09:28:56 102,400 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorpe.dll + 2005-09-23 09:29:00 330,752 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll + 2005-09-23 09:28:56 67,072 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll + 2005-09-23 09:28:50 9,216 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsn.dll + 2005-09-23 09:28:56 226,816 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll + 2005-09-23 09:28:56 66,240 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe + 2005-09-23 09:28:56 10,240 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscortim.dll + 2005-09-23 09:28:50 5,615,616 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll + 2005-09-23 09:29:00 22,528 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\MUI\0409\mscorsecr.dll + 2005-09-23 09:28:56 96,440 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ngen.exe + 2005-09-23 09:28:56 14,848 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\normalization.dll + 2005-09-23 09:28:56 78,336 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\PerfCounter.dll + 2005-09-23 09:28:50 136,192 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\peverify.dll + 2005-09-23 09:28:56 53,248 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe + 2005-09-23 09:28:56 32,768 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe + 2005-09-23 09:29:02 59,072 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\regtlibv12.exe + 2005-09-23 09:28:58 7,680 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\sbscmp20_mscorlib.dll + 2005-09-23 09:28:56 107,520 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\shfusion.dll + 2005-09-23 09:29:00 85,504 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll + 2005-09-23 09:28:56 377,344 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll + 2005-09-23 09:28:56 110,592 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\sysglobl.dll + 2005-09-23 09:28:58 389,120 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.configuration.dll + 2005-09-23 09:28:56 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Configuration.Install.dll + 2005-09-23 09:28:56 2,878,976 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll + 2005-09-23 09:28:56 482,304 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.OracleClient.dll + 2005-09-23 09:28:56 716,800 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.SqlXml.dll + 2005-09-23 09:28:38 884,736 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Deployment.dll + 2005-09-23 09:28:56 5,050,368 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll + 2005-09-23 09:28:56 397,312 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.dll + 2005-09-23 09:28:56 188,416 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.DirectoryServices.Protocols.dll + 2005-09-23 09:28:56 3,018,752 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll + 2005-09-23 09:28:56 81,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.Design.dll + 2005-09-23 09:28:56 700,416 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll + 2005-09-23 09:28:56 258,048 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.dll + 2005-09-23 09:28:56 47,616 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Thunk.dll + 2005-09-23 09:28:56 114,176 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.EnterpriseServices.Wrapper.dll + 2005-09-23 09:28:56 368,640 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Management.dll + 2005-09-23 09:28:56 258,048 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Messaging.dll + 2005-09-23 09:28:56 299,008 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Remoting.dll + 2005-09-23 09:28:56 131,072 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Runtime.Serialization.Formatters.Soap.dll + 2005-09-23 09:28:56 258,048 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Security.dll + 2005-09-23 09:28:56 114,688 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.ServiceProcess.dll + 2005-09-23 09:28:56 260,096 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Transactions.dll + 2005-09-23 09:28:56 5,025,792 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll + 2005-09-23 09:28:56 835,584 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Mobile.dll + 2005-09-23 09:28:56 86,016 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.RegularExpressions.dll + 2005-09-23 09:28:56 823,296 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.Services.dll + 2005-09-23 09:28:56 5,316,608 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll + 2005-09-23 09:28:56 2,035,712 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll + 2005-09-23 09:28:56 71,680 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\TLBREF.DLL + 2005-09-23 09:29:06 1,140,920 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe + 2005-09-23 09:28:30 1,306,624 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll + 2005-09-23 09:28:32 298,496 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\webengine.dll + 2005-09-23 09:28:56 28,160 ----a-w c:\windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll + 2005-09-23 09:28:38 83,456 ----a-w c:\windows\system32\dfshim.dll - 2008-11-06 23:14:47 171,488 ----a-w c:\windows\system32\FNTCACHE.DAT + 2008-11-12 19:24:08 173,872 ----a-w c:\windows\system32\FNTCACHE.DAT + 2005-09-23 09:28:52 270,848 ----a-w c:\windows\system32\mscoree.dll + 2005-09-23 09:28:52 150,016 ----a-w c:\windows\system32\mscorier.dll + 2005-09-23 09:28:52 74,240 ----a-w c:\windows\system32\mscories.dll + 2005-09-23 09:29:00 6,144 ----a-w c:\windows\system32\mui\0409\mscorees.dll + 2005-09-23 09:28:56 32,768 ----a-w c:\windows\system32\netfxperf.dll - 2008-10-20 20:27:48 40,128 ----a-w c:\windows\system32\perfc009.dat + 2008-11-12 21:17:18 58,732 ----a-w c:\windows\system32\perfc009.dat - 2008-10-20 20:27:48 48,846 ----a-w c:\windows\system32\perfc016.dat + 2008-11-12 21:17:18 67,450 ----a-w c:\windows\system32\perfc016.dat - 2008-10-20 20:27:48 311,740 ----a-w c:\windows\system32\perfh009.dat + 2008-11-12 21:17:18 392,432 ----a-w c:\windows\system32\perfh009.dat - 2008-10-20 20:27:48 344,734 ----a-w c:\windows\system32\perfh016.dat + 2008-11-12 21:17:18 425,426 ----a-w c:\windows\system32\perfh016.dat + 2005-07-14 20:23:54 143,360 ----a-w c:\windows\v7020\GvCrypto.dll + 2005-08-18 17:00:46 221,184 ----a-w c:\windows\v7020\LiveClient_7020.dll + 2005-07-14 20:23:54 143,360 ----a-w c:\windows\v7040\GvCrypto.dll + 2008-11-20 01:09:38 1,018,077 ----a-w c:\windows\v7040\Install.exe + 2005-08-18 17:00:46 221,184 ----a-w c:\windows\v7040\LiveClient_7020.dll + 2006-12-02 00:56:00 96,256 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll + 2006-12-02 02:25:52 1,101,824 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll + 2006-12-02 02:25:56 1,093,120 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll + 2006-12-02 02:25:58 69,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll + 2006-12-02 02:26:00 57,856 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll + 2006-12-02 02:08:00 40,960 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll + 2006-12-02 02:08:00 45,056 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll + 2006-12-02 02:08:00 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll + 2006-12-02 02:08:00 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll + 2006-12-02 02:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll + 2006-12-02 02:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll + 2006-12-02 02:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll + 2006-12-02 02:08:00 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll + 2006-12-02 02:08:00 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll + 2006-12-02 02:46:44 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll + 2008-11-12 21:15:26 258,048 ----a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll + 2008-11-12 21:15:26 114,176 ----a-w c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll . -- Snapshot resetado para data atual -- . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-21 7700480] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.mpg4"= c:\windows\mpg4c32.dll "vidc.mpg2"= c:\windows\mpg4c32.dll "vidc.mpg3"= c:\windows\mpg4c32.dll "vidc.GEOX"= c:\windows\system32\GeoCodec.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Synchronizer.lnk backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Reboot.exe] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Reboot.exe backup=c:\windows\pss\Reboot.exeCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] --a------ 2008-01-11 23:16 39792 c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] --a------ 2006-11-16 19:04 139264 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2004-08-04 01:45 15360 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] --a------ 2007-04-03 20:29 165784 c:\arquivos de programas\DAEMON Tools\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --------- 2004-08-04 00:56 1667584 c:\arquivos de programas\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2006-01-12 15:40 155648 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2007-05-21 05:31 7700480 c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2007-05-21 05:31 86016 c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL] -ra------ 2006-09-14 03:00 577536 c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-06-10 05:27 144784 c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] -r------- 2005-05-03 08:43 69632 c:\windows\Alcmtr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2007-05-21 05:31 1622016 c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] -r------- 2007-01-30 08:54 16116224 c:\windows\RTHDCPL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] -r------- 2006-05-16 08:04 2879488 c:\windows\SkyTel.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "h:\\e mule\\e mule novo\\eMule\\emule.exe"= "h:\\quake 4\\Quake4Ded.exe"= "c:\\Arquivos de programas\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"= "c:\\Documents and Settings\\-\\Desktop\\avaliaçoes\\Steam\\SteamApps\\maule\\counter-strike\\hl.exe"= "h:\\metin2\\metin2.bin"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\Documents and Settings\\Samanta\\Configurações locais\\Dados de aplicativos\\Skype\\Phone\\Skype.exe"= "h:\\cc3\\CABAL Online (BRAZIL)\\launcher\\update\\ESTdnheadless.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-09 28544] S3 XDva186;XDva186;\??\c:\windows\system32\XDva186.sys [] S3 XDva205;XDva205;\??\c:\windows\system32\XDva205.sys [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{493e56d7-9b67-11dc-b0e3-c9a503b11bf9}] \Shell\AutoRun\command - J:\LaunchU3.exe -a . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 LSP: c:\windows\system32\imon.dll c:\windows\Downloaded Program Files\OCXDownloadChecker_6110.ocx - O16 -: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} hxxp://www.fredericoaovivo.com.br/site/cab/OCXChecker_6110.cab c:\windows\Downloaded Program Files\OCXDownloadChecker.inf c:\windows\Downloaded Program Files\gbpdist.dll - O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab c:\windows\Downloaded Program Files\gbpdist.inf . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-20 10:37:06 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . Tempo para conclusão: 2008-11-20 10:37:47 ComboFix-quarantined-files.txt 2008-11-20 12:37:44 ComboFix2.txt 2008-11-11 15:20:58 ComboFix3.txt 2008-11-11 15:11:47 Pré-execução: 10 pasta(s) 23.152.185.344 bytes disponíveis Pós execução: 10 pasta(s) 23,151,853,568 bytes disponíveis 477 agradecido, jgarcia você q e uma referencia em segurança e malwares,qdo li sua entrevista começei a usar o q você recomendou como proteçao o antivir e o spybot.... esses ainda são as melhores proteçoes free?? vlw!!! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Novembro 27, 2008 Opa Useless, Siga as instruções: 1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": File::c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Reboot.exe c:\documents and settings\All Users\Dados de aplicativos\ezsidmv.dat c:\windows\pss\Reboot.exe J:\LaunchU3.exe Registry:: [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Reboot.exe] path=- backup=- [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000000 "UpdatesDisableNotify"=dword:00000000 [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{493e56d7-9b67-11dc-b0e3-c9a503b11bf9}] ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 2. Salve o arquivo como CFScript.txt; 3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. PS.: Execute a ação com o seu pendrive conectado ao PC. Compartilhar este post Link para o post Compartilhar em outros sites
Useless 0 Denunciar post Postado Novembro 30, 2008 ola jgarcia !! desculpe pela demora em retornar os logs...tive problemas com minha internet.... ComboFix 08-11-30.01 - - 2008-11-30 19:59:17.5 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.732 [GMT -2:00] Executando de: c:\documents and settings\-\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\-\Desktop\CFScript.txt.txt * Criado um novo ponto de restauro FILE :: c:\documents and settings\All Users\Dados de aplicativos\ezsidmv.dat c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Reboot.exe c:\windows\pss\Reboot.exe J:\LaunchU3.exe . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Dados de aplicativos\ezsidmv.dat c:\windows\IE4 Error Log.txt . (((((((((((((((( Arquivos/Ficheiros criados de 2008-10-28 to 2008-11-30 )))))))))))))))))))))))))))) . 2008-11-30 15:55 . 2008-11-30 15:55 <DIR> d-------- c:\arquivos de programas\SystemRequirementsLab 2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7020 2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\AVIFiles 2008-11-19 23:09 . 2005-02-03 18:58 425,984 --a------ c:\windows\system32\GeoCodec.dll 2008-11-19 23:09 . 2005-02-03 18:58 425,984 -ra------ c:\windows\GeoCodec.dll 2008-11-19 23:09 . 2001-05-04 12:05 413,760 --a------ c:\windows\mpg4c32.dll 2008-11-19 23:09 . 2005-08-04 10:37 107,242 --a------ c:\windows\Stable_7000.xml 2008-11-19 23:09 . 2003-12-02 10:03 12,045 --a------ c:\windows\buzzer.wav 2008-11-19 23:08 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7040 2008-11-12 20:17 . 2008-11-12 20:18 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SimCity Societies 2008-11-12 19:51 . 2008-11-12 19:51 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\SPORE Creature Creator 2008-11-12 19:50 . 2008-11-12 19:50 <DIR> d-------- c:\arquivos de programas\Electronic Arts 2008-11-12 12:50 . 2008-11-30 19:47 <DIR> dr-h----- c:\documents and settings\-\Recent 2008-11-11 00:26 . 2008-11-30 09:32 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\FrostWire 2008-11-10 21:49 . 2008-11-30 16:26 <DIR> d-------- c:\documents and settings\-\Tracing 2008-11-10 21:48 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Microsoft 2008-11-10 21:47 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Windows Live 2008-11-10 21:35 . 2008-11-10 21:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live 2008-11-10 18:38 . 2007-07-30 19:19 43,352 --a------ c:\windows\system32\wups2.dll 2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy 2008-11-09 14:20 . 2008-11-09 14:20 401,720 --a------ C:\HiJackThis.exe 2008-11-09 11:02 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys 2008-11-09 11:01 . 2008-11-09 11:01 <DIR> d-------- c:\arquivos de programas\Panda Security 2008-11-09 10:37 . 2008-11-09 14:29 <DIR> d-------- c:\windows\SxsCaPendDel 2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\drivers\mouhid.sys 2008-10-25 12:01 . 2001-09-05 23:20 12,288 --a------ c:\windows\system32\dllcache\mouhid.sys 2008-10-16 21:01 . 2008-11-29 08:09 <DIR> d-------- c:\documents and settings\Samanta\Dados de aplicativos\skypePM 2008-10-16 20:56 . 2008-11-29 19:33 <DIR> d-------- c:\documents and settings\Samanta\Dados de aplicativos\Skype 2008-10-16 20:56 . 2008-10-16 20:56 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Skype 2008-10-15 18:33 . 2008-11-11 00:26 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\Mozilla 2008-10-15 18:33 . 2008-10-15 18:33 <DIR> d-------- c:\arquivos de programas\uTorrent . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-25 02:28 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2008-11-12 21:51 107,888 ----a-w c:\windows\system32\CmdLineExt.dll 2008-11-12 21:50 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-11-11 15:01 --------- d-----w c:\arquivos de programas\ESET 2008-10-15 20:37 --------- d-----w c:\documents and settings\-\Dados de aplicativos\uTorrent 2008-10-15 20:33 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SpeedBit 2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield 2008-09-09 02:03 51,712 ----a-w c:\windows\system32\sirenacm.dll . ((((((((((((((((((((((((((((( snapshot_2008-11-20_10.37.19,68 ))))))))))))))))))))))))))))))))))))))))) . + 2008-10-06 13:48:50 267,568 ----a-w c:\windows\Downloaded Program Files\sysreqlab_srl.dll + 2008-11-25 02:29:14 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1046-7B44-A81300000003}\SC_Reader.exe - 2008-11-11 02:24:51 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys + 2008-11-26 00:53:31 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-21 7700480] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.mpg4"= c:\windows\mpg4c32.dll "vidc.mpg2"= c:\windows\mpg4c32.dll "vidc.mpg3"= c:\windows\mpg4c32.dll "vidc.GEOX"= c:\windows\system32\GeoCodec.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Synchronizer.lnk backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Reboot.exe] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Reboot.exe backup=c:\windows\pss\Reboot.exeCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] --a------ 2008-10-15 01:04 39792 c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] --a------ 2006-11-16 19:04 139264 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2004-08-04 01:45 15360 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] --a------ 2007-04-03 20:29 165784 c:\arquivos de programas\DAEMON Tools\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --------- 2004-08-04 00:56 1667584 c:\arquivos de programas\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2006-01-12 15:40 155648 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2007-05-21 05:31 7700480 c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2007-05-21 05:31 86016 c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL] -ra------ 2006-09-14 03:00 577536 c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-06-10 05:27 144784 c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] -r------- 2005-05-03 08:43 69632 c:\windows\Alcmtr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2007-05-21 05:31 1622016 c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] -r------- 2007-01-30 08:54 16116224 c:\windows\RTHDCPL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] -r------- 2006-05-16 08:04 2879488 c:\windows\SkyTel.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "h:\\e mule\\e mule novo\\eMule\\emule.exe"= "h:\\quake 4\\Quake4Ded.exe"= "c:\\Arquivos de programas\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"= "c:\\Documents and Settings\\-\\Desktop\\avaliaçoes\\Steam\\SteamApps\\maule\\counter-strike\\hl.exe"= "h:\\metin2\\metin2.bin"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\Documents and Settings\\Samanta\\Configurações locais\\Dados de aplicativos\\Skype\\Phone\\Skype.exe"= "h:\\cc3\\CABAL Online (BRAZIL)\\launcher\\update\\ESTdnheadless.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-09 28544] S3 XDva186;XDva186;\??\c:\windows\system32\XDva186.sys [] S3 XDva205;XDva205;\??\c:\windows\system32\XDva205.sys [] . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-30 20:01:18 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'lsass.exe'(804) c:\windows\system32\imon.dll . Tempo para conclusão: 2008-11-30 20:01:47 ComboFix-quarantined-files.txt 2008-11-30 22:01:45 ComboFix2.txt 2008-11-20 12:37:48 ComboFix3.txt 2008-11-11 15:20:58 ComboFix4.txt 2008-11-11 15:11:47 Pré-execução: 10 pasta(s) 21.661.913.088 bytes disponíveis Pós execução: 10 pasta(s) 21,939,716,096 bytes disponíveis 160 aki segue log do hjt: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:06:30, on 30/11/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\internet explorer\iexplore.exe C:\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} (OCXDownloadChecker Control) - http://www.fredericoaovivo.com.br/site/cab...hecker_6110.cab O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1226348371312 O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Arquivos de programas\Eset\nod32krn.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 4946 bytes não sei se o procedimento de desinfecção foi bem sussedido no pen drive pois venho notando q o computador nao o reconheçeu... agradecido useless ah e eu uso esta maqina para acessar coisas pessoais... não estou correndo nenhum risco de roubo de senhas ne??? =) Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Dezembro 2, 2008 Opa Useless, Siga as instruções: 1. Abra o Bloco de Notas -> Copie (Control + C) e Cole (Control + V) todo o texto incluído no "Quote": Registry::[-HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Reboot.exe] ATENÇÃO: O script acima foi elaborado especificamente para a infecção contida neste computador. Utilizá-lo em outra máquina poderá originar graves problemas ao usuário. 2. Salve o arquivo como CFScript.txt; 3. Tal como exemplificado na foto abaixo, arraste o arquivo CFScript.txt para o ComboFix.exe. 4. Ao término do processo a ferramenta irá gerar um log. Poste-o (C:\ComboFix.txt) em sua próxima resposta, juntamente com um novo log do HijackThis. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Useless 0 Denunciar post Postado Dezembro 5, 2008 log do combo fix: ComboFix 08-12-05.01 - - 2008-12-05 15:14:07.6 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.727 [GMT -2:00] Executando de: c:\documents and settings\-\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\-\Desktop\CFScript.txt.txt * Criado um novo ponto de restauro . (((((((((((((((( Arquivos/Ficheiros criados de 2008-11-05 to 2008-12-05 )))))))))))))))))))))))))))) . 2008-11-30 20:11 . 2008-11-30 20:17 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\NexonUS 2008-11-30 15:55 . 2008-11-30 15:55 <DIR> d-------- c:\arquivos de programas\SystemRequirementsLab 2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7020 2008-11-19 23:09 . 2008-11-19 23:09 <DIR> d-------- c:\windows\AVIFiles 2008-11-19 23:09 . 2005-02-03 18:58 425,984 --a------ c:\windows\system32\GeoCodec.dll 2008-11-19 23:09 . 2005-02-03 18:58 425,984 -ra------ c:\windows\GeoCodec.dll 2008-11-19 23:09 . 2001-05-04 12:05 413,760 --a------ c:\windows\mpg4c32.dll 2008-11-19 23:09 . 2005-08-04 10:37 107,242 --a------ c:\windows\Stable_7000.xml 2008-11-19 23:09 . 2003-12-02 10:03 12,045 --a------ c:\windows\buzzer.wav 2008-11-19 23:08 . 2008-11-19 23:09 <DIR> d-------- c:\windows\v7040 2008-11-12 20:17 . 2008-11-12 20:18 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SimCity Societies 2008-11-12 12:50 . 2008-12-05 11:56 <DIR> dr-h----- c:\documents and settings\-\Recent 2008-11-11 00:26 . 2008-11-30 09:32 <DIR> d-------- c:\documents and settings\-\Dados de aplicativos\FrostWire 2008-11-10 21:49 . 2008-12-04 00:14 <DIR> d-------- c:\documents and settings\-\Tracing 2008-11-10 21:48 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Microsoft 2008-11-10 21:47 . 2008-11-10 21:48 <DIR> d-------- c:\arquivos de programas\Windows Live 2008-11-10 21:35 . 2008-11-10 21:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live 2008-11-10 18:38 . 2007-07-30 19:19 43,352 --a------ c:\windows\system32\wups2.dll 2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-11-09 21:31 . 2008-11-10 11:40 <DIR> d-------- c:\arquivos de programas\Spybot - Search & Destroy 2008-11-09 14:20 . 2008-11-09 14:20 401,720 --a------ C:\HiJackThis.exe 2008-11-09 11:01 . 2008-11-30 20:21 <DIR> d-------- c:\arquivos de programas\Panda Security 2008-11-09 10:37 . 2008-11-09 14:29 <DIR> d-------- c:\windows\SxsCaPendDel . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-30 22:20 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information 2008-11-29 21:33 --------- d-----w c:\documents and settings\Samanta\Dados de aplicativos\Skype 2008-11-29 10:09 --------- d-----w c:\documents and settings\Samanta\Dados de aplicativos\skypePM 2008-11-25 02:28 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2008-11-12 21:51 107,888 ----a-w c:\windows\system32\CmdLineExt.dll 2008-11-11 15:01 --------- d-----w c:\arquivos de programas\ESET 2008-10-16 22:56 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Skype 2008-10-15 20:37 --------- d-----w c:\documents and settings\-\Dados de aplicativos\uTorrent 2008-10-15 20:33 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SpeedBit 2008-10-15 20:33 --------- d-----w c:\arquivos de programas\uTorrent 2008-10-15 20:33 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield 2008-09-09 02:03 51,712 ----a-w c:\windows\system32\sirenacm.dll . ((((((((((((((((((((((((((((( snapshot_2008-11-20_10.37.19,68 ))))))))))))))))))))))))))))))))))))))))) . + 2008-10-06 13:48:50 267,568 ----a-w c:\windows\Downloaded Program Files\sysreqlab_srl.dll + 2008-11-25 02:29:14 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1046-7B44-A81300000003}\SC_Reader.exe - 2008-11-11 02:24:51 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys + 2008-11-26 00:53:31 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-21 7700480] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.mpg4"= c:\windows\mpg4c32.dll "vidc.mpg2"= c:\windows\mpg4c32.dll "vidc.mpg3"= c:\windows\mpg4c32.dll "vidc.GEOX"= c:\windows\system32\GeoCodec.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk] path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Synchronizer.lnk backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] --a------ 2008-10-15 01:04 39792 c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] --a------ 2006-11-16 19:04 139264 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] --a------ 2004-08-04 01:45 15360 c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] --a------ 2007-04-03 20:29 165784 c:\arquivos de programas\DAEMON Tools\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --------- 2004-08-04 00:56 1667584 c:\arquivos de programas\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2006-01-12 15:40 155648 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2007-05-21 05:31 7700480 c:\windows\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2007-05-21 05:31 86016 c:\windows\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL] -ra------ 2006-09-14 03:00 577536 c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-06-10 05:27 144784 c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] -r------- 2005-05-03 08:43 69632 c:\windows\Alcmtr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2007-05-21 05:31 1622016 c:\windows\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] -r------- 2007-01-30 08:54 16116224 c:\windows\RTHDCPL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] -r------- 2006-05-16 08:04 2879488 c:\windows\SkyTel.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "h:\\e mule\\e mule novo\\eMule\\emule.exe"= "h:\\quake 4\\Quake4Ded.exe"= "c:\\Arquivos de programas\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"= "c:\\Documents and Settings\\-\\Desktop\\avaliaçoes\\Steam\\SteamApps\\maule\\counter-strike\\hl.exe"= "h:\\metin2\\metin2.bin"= "c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"= "c:\\Documents and Settings\\Samanta\\Configurações locais\\Dados de aplicativos\\Skype\\Phone\\Skype.exe"= "h:\\cc3\\CABAL Online (BRAZIL)\\launcher\\update\\ESTdnheadless.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"= "h:\combat arms\Combat Arms\CombatArms.exe"= h:\combat arms\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe "h:\combat arms\Combat Arms\Engine.exe"= h:\combat arms\Combat Arms\Engine.exe:*Enabled:Engine.exe "h:\\combat arms\\Combat Arms\\NMService.exe"= S3 XDva186;XDva186;\??\c:\windows\system32\XDva186.sys [] S3 XDva205;XDva205;\??\c:\windows\system32\XDva205.sys [] . . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com.br/ uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 LSP: c:\windows\system32\imon.dll c:\windows\Downloaded Program Files\OCXDownloadChecker_6110.ocx - O16 -: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} hxxp://www.fredericoaovivo.com.br/site/cab/OCXChecker_6110.cab c:\windows\Downloaded Program Files\OCXDownloadChecker.inf c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E} hxxp://www.srtest.com/srl_bin/sysreqlab_srl.cab c:\windows\Downloaded Program Files\sysreqlab.osd c:\windows\Downloaded Program Files\gbpdist.dll - O16 -: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab c:\windows\Downloaded Program Files\gbpdist.inf . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-05 15:15:34 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'lsass.exe'(804) c:\windows\system32\imon.dll . Tempo para conclusão: 2008-12-05 15:16:06 ComboFix-quarantined-files.txt 2008-12-05 17:16:04 ComboFix2.txt 2008-11-30 22:01:48 ComboFix3.txt 2008-11-20 12:37:48 ComboFix4.txt 2008-11-11 15:20:58 ComboFix5.txt 2008-12-05 17:13:28 Pré-execução: 10 pasta(s) 20.586.512.384 bytes disponíveis Pós execução: 10 pasta(s) 22,111,547,392 bytes disponíveis 163 log do hijackthis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:19:52, on 5/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\internet explorer\iexplore.exe C:\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} (OCXDownloadChecker Control) - http://www.fredericoaovivo.com.br/site/cab...hecker_6110.cab O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1226348371312 O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Arquivos de programas\Eset\nod32krn.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 4800 bytes agradecido... Compartilhar este post Link para o post Compartilhar em outros sites
Useless 0 Denunciar post Postado Dezembro 9, 2008 ^_^ meu ultimo post n foi contabilizado na contagem... Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Dezembro 11, 2008 Contagem de que? Compartilhar este post Link para o post Compartilhar em outros sites
Useless 0 Denunciar post Postado Dezembro 14, 2008 Olá...o q eu quis dizer foi q eu ja havia postado o que me foi pedido mas na visualizaçao dos posts gerais ainda constava la como ultimo post sendo do jgarcia que esta me ajudando,quando na verdade o ultimo post ja havia sido meu... obrigado ^^ Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Dezembro 15, 2008 isso as vezes occorre por causa de cache no forum mas o importante é que seu post foi registrado Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Janeiro 15, 2009 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites