Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Laurentino Mello

[Resolvido!] Log para Analise

Recommended Posts

MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\system32\SMon2.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\UltraVnc\winvnc.exe

C:\Arquivos de programas\internet explorer\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Documents and Settings\Luciano Peças\Desktop\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://grupolbezerra.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [sMon2] C:\WINDOWS\system32\SMon2.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Startup: Run server as application.lnk = C:\Arquivos de programas\UltraVnc\winvnc.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1228243184421

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O17 - HKLM\System\CS1\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O17 - HKLM\System\CS2\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O17 - HKLM\System\CS3\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

 

--

End of file - 5006 bytes

 

Aguardo Resposta...

 

Abraços...

Compartilhar este post


Link para o post
Compartilhar em outros sites

Acesse o site VirusTotal e clique em Arquivo. Selecione o arquivo azul abaixo em seu sistema e clique no botão Enviar Arquivo.

 

C:\WINDOWS\system32\SMon2.exe

 

Aguarde a análise. Copie e cole aqui o link que estará em frente ao nome Permalink.

 

- Faça o download do RSIT e salve no seu desktop;

 

● Dê dois cliques em RSIT.exe para executar o programa;

● Na janela que abrir clique no botão Continue para que a ferramenta comece a rodar;

● Quando a ferramenta terminar de rodar, abrirá um log automaticamente no bloco de notas contendo o resultado do scan. Cole o resultado desse log (log.txt) na sua próxima resposta;

● Cole também o conteúdo do arquivo info.txt que estará em C:\rsit\info.txt.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Caro Mguitar, esse arquivo que você me mandou analisar no Virus total, é um programa de monitoramento que uso (é de confiança), mas de toda forma segue abaixo o resultado abaixo.

 

fico no aguardo.

 

http://www.virustotal.com/pt/analisis/3ba0...073c15f1807d5ea

 

 

Logfile of random's system information tool 1.04 (written by random/random)

Run by Luciano Peças at 2008-12-05 16:21:14

Microsoft Windows XP Professional Service Pack 3

System drive C: has 22 GB (73%) free of 30 GB

Total RAM: 479 MB (38% free)

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:21:38, on 5/12/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\SMon2.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\UltraVnc\winvnc.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Documents and Settings\Luciano Peças\Desktop\RSIT.exe

C:\Documents and Settings\Luciano Peças\Desktop\Luciano Peças.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://grupolbezerra.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [sMon2] C:\WINDOWS\system32\SMon2.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Startup: Run server as application.lnk = C:\Arquivos de programas\UltraVnc\winvnc.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1228243184421

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O17 - HKLM\System\CS1\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O17 - HKLM\System\CS2\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O17 - HKLM\System\CS3\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

 

--

End of file - 5067 bytes

 

======Scheduled tasks folder======

 

C:\WINDOWS\tasks\MP Scheduled Scan.job

 

======Registry dump======

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]

Adobe PDF Link Helper - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]

Skype add-on (mastermind) - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-11-07 1088296]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

Click-to-Call BHO - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll [2008-09-02 75272]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

Auxiliar de Conexão do Windows Live - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-02-22 401968]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"avast!"=C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-26 81000]

"SMon2"=C:\WINDOWS\system32\SMon2.exe [2006-12-08 134144]

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

 

C:\Documents and Settings\Luciano Peças\Menu Iniciar\Programas\Inicializar

Run server as application.lnk - C:\Arquivos de programas\UltraVnc\winvnc.exe

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]

C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 267304]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\ARQUIV~1\WINDOW~4\MpShHook.dll [2006-11-03 83224]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

 

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveTypeAutoRun"=323

"NoDrives"=0

"NoDriveAutoRun"=67108863

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDrives"=

"NoDriveAutoRun"=

"NoDriveTypeAutoRun"=

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\WINDOWS\system32\SMon2.exe"="C:\WINDOWS\system32\SMon2.exe:*:Enabled:SMon2"

"C:\Arquivos de programas\r2 Studios\Tonic\Tonic.exe"="C:\Arquivos de programas\r2 Studios\Tonic\Tonic.exe:*:Enabled:Tonic"

"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"

"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"C:\Arquivos de programas\Skype\Phone\Skype.exe"="C:\Arquivos de programas\Skype\Phone\Skype.exe:*:Enabled:Skype"

"C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"

"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7aaf576-c2b3-11dd-a65b-000feaa4fb9c}]

shell\AutoRun\command - F:\rcukd.cmd

shell\explore\command - F:\rcukd.cmd

shell\open\command - F:\rcukd.cmd

 

 

======List of files/folders created in the last 1 months======

 

2008-12-05 17:01:55 ----A---- C:\WINDOWS\NeroDigital.ini

2008-12-05 16:44:32 ----D---- C:\WINDOWS\ERDNT

2008-12-05 16:21:14 ----D---- C:\rsit

2008-12-05 10:21:30 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Malwarebytes

2008-12-05 10:21:23 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Malwarebytes

2008-12-05 10:21:22 ----D---- C:\Arquivos de programas\Malwarebytes' Anti-Malware

2008-12-05 10:20:49 ----D---- C:\ComboFix

2008-12-05 10:16:30 ----A---- C:\ComboFix.txt

2008-12-04 15:48:38 ----A---- C:\imp2.bat

2008-12-04 15:47:51 ----D---- C:\Arquivos de programas\MSECache

2008-12-04 08:28:13 ----D---- C:\Arquivos de programas\Microsoft Works

2008-12-04 08:27:28 ----D---- C:\Arquivos de programas\Microsoft Visual Studio

2008-12-04 08:27:27 ----D---- C:\Arquivos de programas\Arquivos comuns\DESIGNER

2008-12-04 08:21:26 ----D---- C:\WINDOWS\SHELLNEW

2008-12-04 08:19:35 ----D---- C:\Arquivos de programas\Microsoft Office

2008-12-04 08:19:31 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help

2008-12-04 08:18:53 ----RHD---- C:\MSOCache

2008-12-04 08:16:49 ----D---- C:\WINDOWS\pss

2008-12-03 18:13:36 ----A---- C:\WINDOWS\cat_fiat.ini

2008-12-03 18:08:51 ----A---- C:\WINDOWS\cat_vw.ini

2008-12-03 18:08:01 ----A---- C:\WINDOWS\cat_perf.ini

2008-12-03 18:00:18 ----D---- C:\CAT_VW

2008-12-03 17:55:45 ----D---- C:\OiC

2008-12-03 17:55:45 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\OiC

2008-12-03 17:54:20 ----D---- C:\Arquivos de programas\CepChev2

2008-12-03 17:46:00 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Ahead

2008-12-03 17:43:43 ----D---- C:\Arquivos de programas\Nero

2008-12-03 17:43:43 ----D---- C:\Arquivos de programas\Arquivos comuns\Ahead

2008-12-03 17:41:07 ----A---- C:\WINDOWS\cdplayer.ini

2008-12-03 17:40:40 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\FreeRIP

2008-12-03 17:40:26 ----D---- C:\Arquivos de programas\FreeRIP3

2008-12-03 17:29:02 ----HD---- C:\WINDOWS\system32\GroupPolicy

2008-12-03 17:16:12 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\skypePM

2008-12-03 13:00:30 ----HD---- C:\WINDOWS\PIF

2008-12-03 10:59:30 ----D---- C:\Arquivos de programas\Microsoft

2008-12-03 10:57:21 ----D---- C:\Arquivos de programas\Windows Live

2008-12-03 10:36:02 ----D---- C:\Arquivos de programas\Windows Defender

2008-12-03 10:34:58 ----D---- C:\Arquivos de programas\Arquivos comuns\Windows Live

2008-12-03 10:34:45 ----D---- C:\Arquivos de programas\WinZip

2008-12-03 10:34:27 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Adobe

2008-12-03 10:34:02 ----D---- C:\Arquivos de programas\Arquivos comuns\Adobe

2008-12-03 10:34:02 ----D---- C:\Arquivos de programas\Adobe

2008-12-03 10:32:42 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Skype

2008-12-03 10:32:18 ----D---- C:\Arquivos de programas\UsbFix

2008-12-03 10:32:11 ----D---- C:\Arquivos de programas\Skype

2008-12-03 10:32:10 ----D---- C:\Arquivos de programas\Arquivos comuns\Skype

2008-12-03 10:31:59 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Skype

2008-12-03 10:31:42 ----D---- C:\Arquivos de programas\CCleaner

2008-12-03 10:28:45 ----D---- C:\Arquivos de programas\UltraVnc

2008-12-03 10:24:12 ----D---- C:\Arquivos de programas\r2 Studios

2008-12-03 10:23:27 ----A---- C:\WINDOWS\system32\SMon2.exe

2008-12-02 17:19:29 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$

2008-12-02 17:18:34 ----A---- C:\WINDOWS\system32\MRT.exe

2008-12-02 17:18:24 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$

2008-12-02 17:18:16 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$

2008-12-02 17:18:08 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$

2008-12-02 17:17:27 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$

2008-12-02 17:17:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$

2008-12-02 17:17:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$

2008-12-02 17:16:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$

2008-12-02 17:16:48 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$

2008-12-02 17:16:15 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$

2008-12-02 17:16:08 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$

2008-12-02 17:16:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$

2008-12-02 17:15:51 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$

2008-12-02 17:15:44 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$

2008-12-02 17:15:37 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$

2008-12-02 17:15:30 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$

2008-12-02 17:15:22 ----D---- C:\WINDOWS\ie7updates

2008-12-02 17:15:12 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$

2008-12-02 17:15:04 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$

2008-12-02 17:14:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$

2008-12-02 17:14:47 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$

2008-12-02 16:45:06 ----D---- C:\WINDOWS\system32\PreInstall

2008-12-02 16:45:04 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$

2008-12-02 16:41:25 ----A---- C:\WINDOWS\system32\wups2.dll

2008-12-02 16:41:25 ----A---- C:\WINDOWS\system32\wucltui.dll.mui

2008-12-02 16:41:24 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui

2008-12-02 16:41:23 ----D---- C:\WINDOWS\system32\SoftwareDistribution

2008-12-02 16:41:23 ----A---- C:\WINDOWS\system32\wuapi.dll.mui

2008-12-02 15:17:30 ----D---- C:\WINDOWS\Prefetch

2008-12-02 11:54:46 ----N---- C:\WINDOWS\system32\msxml6r.dll

2008-12-02 11:54:46 ----A---- C:\WINDOWS\system32\msxml6.dll

2008-12-02 11:54:31 ----N---- C:\WINDOWS\system32\smtpapi.dll

2008-12-02 11:54:31 ----N---- C:\WINDOWS\system32\rwnh.dll

2008-12-02 11:54:31 ----N---- C:\WINDOWS\system32\comsdupd.exe

2008-12-02 11:54:28 ----N---- C:\WINDOWS\system32\ati2dvaa.dll

2008-12-02 11:54:28 ----N---- C:\WINDOWS\system32\ati2cqag.dll

2008-12-02 11:54:28 ----N---- C:\WINDOWS\system32\aaclient.dll

2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\bitsprx4.dll

2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\azroles.dll

2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\ativvaxx.dll

2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\ativtmxx.dll

2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\ati3duag.dll

2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\ati3d1ag.dll

2008-12-02 11:54:27 ----N---- C:\WINDOWS\system32\ati2dvag.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3ui.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3svc.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3msm.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3dlg.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3cfg.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dot3api.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dimsroam.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dimsntfy.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\dhcpqec.dll

2008-12-02 11:54:26 ----N---- C:\WINDOWS\system32\credssp.dll

2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\hsfcisp2.dll

2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eapsvc.dll

2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eapqec.dll

2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eappprxy.dll

2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eapphost.dll

2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eappgnui.dll

2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eappcfg.dll

2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eapp3hst.dll

2008-12-02 11:54:25 ----N---- C:\WINDOWS\system32\eapolqec.dll

2008-12-02 11:54:24 ----N---- C:\WINDOWS\system32\kbdiultn.dll

2008-12-02 11:54:24 ----N---- C:\WINDOWS\system32\kbdbhc.dll

2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\mmcperf.exe

2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll

2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\mmcex.dll

2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll

2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\mdmxsdk.dll

2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\l2gpstore.dll

2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\kmsvc.dll

2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\kbdpash.dll

2008-12-02 11:54:23 ----N---- C:\WINDOWS\system32\kbdnepr.dll

2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\nv4_disp.dll

2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\napstat.exe

2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\napmontr.dll

2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\napipsec.dll

2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\mtxparhd.dll

2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\msshavmsg.dll

2008-12-02 11:54:22 ----N---- C:\WINDOWS\system32\mssha.dll

2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\rhttpaa.dll

2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\rasqec.dll

2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\qutil.dll

2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\qcliprov.dll

2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\qagentrt.dll

2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\qagent.dll

2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\photometadatahandler.dll

2008-12-02 11:54:21 ----N---- C:\WINDOWS\system32\onex.dll

2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\slserv.exe

2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\slrundll.exe

2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\slgen.dll

2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\slextspk.dll

2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\slcoinst.dll

2008-12-02 11:54:20 ----N---- C:\WINDOWS\system32\setupn.exe

2008-12-02 11:54:19 ----N---- C:\WINDOWS\system32\xpsp3res.dll

2008-12-02 11:54:19 ----N---- C:\WINDOWS\system32\verclsid.exe

2008-12-02 11:54:19 ----N---- C:\WINDOWS\system32\tzchange.exe

2008-12-02 11:54:19 ----N---- C:\WINDOWS\system32\tspkg.dll

2008-12-02 11:54:19 ----N---- C:\WINDOWS\system32\tsgqec.dll

2008-12-02 11:54:18 ----N---- C:\WINDOWS\system32\wmphoto.dll

2008-12-02 11:54:18 ----N---- C:\WINDOWS\system32\wlanapi.dll

2008-12-02 11:54:18 ----N---- C:\WINDOWS\system32\windowscodecsext.dll

2008-12-02 11:54:18 ----N---- C:\WINDOWS\system32\windowscodecs.dll

2008-12-02 11:54:16 ----N---- C:\WINDOWS\slrundll.exe

2008-12-02 11:54:15 ----D---- C:\WINDOWS\l2schemas

2008-12-02 11:54:14 ----D---- C:\WINDOWS\system32\bits

2008-12-02 11:51:50 ----D---- C:\WINDOWS\ServicePackFiles

2008-12-02 11:49:49 ----D---- C:\WINDOWS\network diagnostic

2008-12-02 11:47:50 ----A---- C:\WINDOWS\002674_.tmp

2008-12-02 11:43:12 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$

2008-12-02 11:03:54 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Macromedia

2008-12-02 11:03:54 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Adobe

2008-12-02 10:48:16 ----D---- C:\WINDOWS\WBEM

2008-12-02 10:48:15 ----D---- C:\WINDOWS\system32\pt-br

2008-12-02 10:46:55 ----HDC---- C:\WINDOWS\ie7

2008-12-02 10:46:24 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$

2008-12-02 10:46:03 ----A---- C:\WINDOWS\system32\spupdsvc.exe

2008-12-02 10:46:01 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$

2008-12-02 10:45:28 ----N---- C:\WINDOWS\system32\spmsg.dll

2008-12-02 10:45:23 ----HDC---- C:\WINDOWS\$NtUninstallKB915865$

2008-12-02 10:45:23 ----HD---- C:\WINDOWS\$hf_mig$

2008-12-02 10:45:19 ----N---- C:\WINDOWS\system32\xmllite.dll

2008-12-02 10:44:34 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Windows Genuine Advantage

2008-12-02 08:19:26 ----A---- C:\imp.bat

2008-12-02 08:19:25 ----A---- C:\WINDOWS\ARJ.EXE

2008-12-02 08:19:04 ----A---- C:\WINDOWS\system32\MSVCR71.dll

2008-12-02 08:19:04 ----A---- C:\WINDOWS\system32\MSVCP71.dll

2008-12-02 08:19:04 ----A---- C:\WINDOWS\system32\MFC71.dll

2008-12-02 08:19:04 ----A---- C:\WINDOWS\system32\aswBoot.exe

2008-12-02 08:19:02 ----D---- C:\Arquivos de programas\Alwil Software

2008-12-01 11:00:37 ----A---- C:\WINDOWS\system32\ksuser.dll

2008-12-01 11:00:30 ----A---- C:\WINDOWS\system32\UnAudioNT.dll

2008-12-01 11:00:25 ----D---- C:\Arquivos de programas\VIAudioi

2008-12-01 11:00:23 ----A---- C:\WINDOWS\IsUn0416.exe

2008-12-01 10:04:07 ----SHD---- C:\WINDOWS\CSC

2008-12-01 10:03:13 ----D---- C:\WINDOWS\system32\ReinstallBackups

2008-12-01 10:03:08 ----A---- C:\WINDOWS\IsUninst.exe

2008-11-29 08:59:19 ----D---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Identities

2008-11-29 08:59:16 ----HD---- C:\Arquivos de programas\Uninstall Information

2008-11-29 08:59:10 ----ASH---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\desktop.ini

2008-11-29 08:59:09 ----SD---- C:\Documents and Settings\Luciano Peças\Dados de aplicativos\Microsoft

2008-11-29 08:58:15 ----D---- C:\WINDOWS\SoftwareDistribution

2008-11-29 08:58:05 ----SD---- C:\WINDOWS\system32\Microsoft

2008-11-29 08:58:04 ----A---- C:\WINDOWS\SchedLgU.Txt

2008-11-29 08:53:26 ----D---- C:\WINDOWS\system32\xircom

2008-11-29 08:53:26 ----D---- C:\Arquivos de programas\xerox

2008-11-29 08:53:26 ----D---- C:\Arquivos de programas\microsoft frontpage

2008-11-29 08:52:59 ----A---- C:\WINDOWS\control.ini

2008-11-29 08:52:59 ----A---- C:\AUTOEXEC.BAT

2008-11-29 08:52:35 ----A---- C:\WINDOWS\system32\mapi32.dll

2008-11-29 08:51:11 ----SD---- C:\WINDOWS\Downloaded Program Files

2008-11-29 08:51:11 ----RD---- C:\WINDOWS\Offline Web Pages

2008-11-29 08:51:11 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest

2008-11-29 08:51:02 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest

2008-11-29 08:50:56 ----HD---- C:\Arquivos de programas\WindowsUpdate

2008-11-29 08:50:51 ----D---- C:\Arquivos de programas\Serviços on-line

2008-11-29 08:50:34 ----D---- C:\WINDOWS\system32\DirectX

2008-11-29 08:50:17 ----A---- C:\WINDOWS\system32\atrace.dll

2008-11-29 08:50:15 ----A---- C:\WINDOWS\system32\desktop.ini

2008-11-29 08:50:15 ----A---- C:\WINDOWS\desktop.ini

2008-11-29 08:50:09 ----A---- C:\WINDOWS\system32\nmevtmsg.dll

2008-11-29 08:50:08 ----A---- C:\WINDOWS\system32\acctres.dll

2008-11-29 08:50:07 ----D---- C:\Arquivos de programas\Arquivos comuns\Serviços

2008-11-29 08:50:05 ----SD---- C:\WINDOWS\Tasks

2008-11-29 08:50:05 ----A---- C:\WINDOWS\system32\icfgnt5.dll

2008-11-29 08:50:04 ----D---- C:\Arquivos de programas\Arquivos comuns\MSSoap

2008-11-29 08:50:01 ----D---- C:\WINDOWS\srchasst

2008-11-29 08:50:00 ----D---- C:\WINDOWS\system32\Macromed

2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuweb.dll

2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wups.dll

2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wucltui.dll

2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuauserv.dll

2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuaueng1.dll

2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuaueng.dll

2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuauclt1.exe

2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuauclt.exe

2008-11-29 08:49:57 ----A---- C:\WINDOWS\system32\wuapi.dll

2008-11-29 08:49:56 ----A---- C:\WINDOWS\system32\qmgrprxy.dll

2008-11-29 08:49:56 ----A---- C:\WINDOWS\system32\qmgr.dll

2008-11-29 08:49:56 ----A---- C:\WINDOWS\system32\bitsprx3.dll

2008-11-29 08:49:56 ----A---- C:\WINDOWS\system32\bitsprx2.dll

2008-11-29 08:49:53 ----D---- C:\Arquivos de programas\Movie Maker

2008-11-29 08:49:49 ----A---- C:\WINDOWS\system32\safrslv.dll

2008-11-29 08:49:49 ----A---- C:\WINDOWS\system32\safrdm.dll

2008-11-29 08:49:49 ----A---- C:\WINDOWS\system32\safrcdlg.dll

2008-11-29 08:49:49 ----A---- C:\WINDOWS\system32\racpldlg.dll

2008-11-29 08:49:46 ----D---- C:\WINDOWS\system32\Restore

2008-11-29 08:49:46 ----A---- C:\WINDOWS\system32\srsvc.dll

2008-11-29 08:49:46 ----A---- C:\WINDOWS\system32\srrstr.dll

2008-11-29 08:49:46 ----A---- C:\WINDOWS\system32\srclient.dll

2008-11-29 08:49:46 ----A---- C:\WINDOWS\system32\fltmc.exe

2008-11-29 08:49:46 ----A---- C:\WINDOWS\system32\fltlib.dll

2008-11-29 08:49:45 ----A---- C:\WINDOWS\system32\nmmkcert.dll

2008-11-29 08:49:45 ----A---- C:\WINDOWS\system32\mnmsrvc.exe

2008-11-29 08:49:45 ----A---- C:\WINDOWS\system32\mnmdd.dll

2008-11-29 08:49:45 ----A---- C:\WINDOWS\system32\isrdbg32.dll

2008-11-29 08:49:45 ----A---- C:\WINDOWS\system32\ils.dll

2008-11-29 08:49:44 ----A---- C:\WINDOWS\system32\msconf.dll

2008-11-29 08:49:42 ----D---- C:\Arquivos de programas\NetMeeting

2008-11-29 08:49:42 ----A---- C:\WINDOWS\system32\msoert2.dll

2008-11-29 08:49:42 ----A---- C:\WINDOWS\system32\msoeacct.dll

2008-11-29 08:49:41 ----A---- C:\WINDOWS\system32\inetres.dll

2008-11-29 08:49:41 ----A---- C:\WINDOWS\system32\inetcomm.dll

2008-11-29 08:49:39 ----D---- C:\Arquivos de programas\Outlook Express

2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\schedsvc.dll

2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\mstinit.exe

2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\mstask.dll

2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\isign32.dll

2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\icwphbk.dll

2008-11-29 08:49:39 ----A---- C:\WINDOWS\system32\icwdial.dll

2008-11-29 08:49:38 ----A---- C:\WINDOWS\system32\inetcfg.dll

2008-11-29 08:49:33 ----D---- C:\Arquivos de programas\Arquivos comuns\System

2008-11-29 08:49:32 ----D---- C:\Arquivos de programas\Internet Explorer

2008-11-29 08:48:45 ----D---- C:\Arquivos de programas\ComPlus Applications

2008-11-29 08:48:43 ----A---- C:\WINDOWS\vbaddin.ini

2008-11-29 08:48:43 ----A---- C:\WINDOWS\vb.ini

2008-11-29 08:48:38 ----D---- C:\WINDOWS\Registration

2008-11-29 08:48:29 ----D---- C:\Arquivos de programas\Windows Media Player

2008-11-29 08:48:23 ----D---- C:\Arquivos de programas\Messenger

2008-11-29 08:48:19 ----D---- C:\Arquivos de programas\MSN Gaming Zone

2008-11-29 08:48:19 ----A---- C:\WINDOWS\system32\write.exe

2008-11-29 08:48:11 ----A---- C:\WINDOWS\system32\sndvol32.exe

2008-11-29 08:48:11 ----A---- C:\WINDOWS\system32\hticons.dll

2008-11-29 08:48:11 ----A---- C:\WINDOWS\system32\avwav.dll

2008-11-29 08:48:11 ----A---- C:\WINDOWS\system32\avtapi.dll

2008-11-29 08:48:11 ----A---- C:\WINDOWS\system32\avmeter.dll

2008-11-29 08:48:10 ----A---- C:\WINDOWS\system32\winchat.exe

2008-11-29 08:48:05 ----A---- C:\WINDOWS\system32\getuname.dll

2008-11-29 08:48:04 ----A---- C:\WINDOWS\system32\charmap.exe

2008-11-29 08:48:04 ----A---- C:\WINDOWS\system32\calc.exe

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\usrlogon.cmd

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\tsshutdn.exe

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\tslabels.ini

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\tskill.exe

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\tsdiscon.exe

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\tscon.exe

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\shadow.exe

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\rwinsta.exe

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\reset.exe

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\regini.exe

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\rdpcfgex.dll

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\qwinsta.exe

2008-11-29 08:48:03 ----A---- C:\WINDOWS\system32\qappsrv.exe

2008-11-29 08:48:02 ----A---- C:\WINDOWS\system32\msg.exe

2008-11-29 08:48:02 ----A---- C:\WINDOWS\system32\msdtcprf.ini

2008-11-29 08:48:02 ----A---- C:\WINDOWS\system32\logoff.exe

2008-11-29 08:48:02 ----A---- C:\WINDOWS\system32\dcomcnfg.exe

2008-11-29 08:48:02 ----A---- C:\WINDOWS\system32\cdmodem.dll

2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\stclient.dll

2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\mtxlegih.dll

2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\mtxex.dll

2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\mtxdm.dll

2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\comsnap.dll

2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\comrepl.dll

2008-11-29 08:48:01 ----A---- C:\WINDOWS\system32\comaddin.dll

2008-11-29 08:47:56 ----A---- C:\WINDOWS\system32\wmimgmt.msc

2008-11-29 08:47:56 ----A---- C:\WINDOWS\system32\accwiz.exe

2008-11-29 08:47:55 ----D---- C:\Arquivos de programas\Windows NT

2008-11-29 08:47:55 ----A---- C:\WINDOWS\system32\sndrec32.exe

2008-11-29 08:47:55 ----A---- C:\WINDOWS\system32\mspaint.exe

2008-11-29 08:47:55 ----A---- C:\WINDOWS\system32\mplay32.exe

2008-11-29 08:47:55 ----A---- C:\WINDOWS\system32\hypertrm.dll

2008-11-29 08:47:54 ----A---- C:\WINDOWS\system32\tscfgwmi.dll

2008-11-29 08:47:54 ----A---- C:\WINDOWS\system32\clipbrd.exe

2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\tscupgrd.exe

2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\termsrv.dll

2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\sessmgr.exe

2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\remotepg.dll

2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\rdshost.exe

2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\rdsaddin.exe

2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\rdchost.dll

2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\mstscax.dll

2008-11-29 08:47:53 ----A---- C:\WINDOWS\system32\mstsc.exe

2008-11-29 08:47:52 ----D---- C:\WINDOWS\system32\MsDtc

2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\rdpwsx.dll

2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\rdpsnd.dll

2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\rdpclip.exe

2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\qprocess.exe

2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\mtxoci.dll

2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\msdtcuiu.dll

2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\msdtcprx.dll

2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\icaapi.dll

2008-11-29 08:47:52 ----A---- C:\WINDOWS\system32\cfgbkend.dll

2008-11-29 08:47:51 ----A---- C:\WINDOWS\system32\xolehlp.dll

2008-11-29 08:47:51 ----A---- C:\WINDOWS\system32\msdtctm.dll

2008-11-29 08:47:51 ----A---- C:\WINDOWS\system32\msdtclog.dll

2008-11-29 08:47:51 ----A---- C:\WINDOWS\system32\msdtc.exe

2008-11-29 08:47:50 ----D---- C:\WINDOWS\system32\Com

2008-11-29 08:47:50 ----A---- C:\WINDOWS\system32\colbact.dll

2008-11-29 08:47:50 ----A---- C:\WINDOWS\system32\clbcatex.dll

2008-11-29 08:47:50 ----A---- C:\WINDOWS\system32\catsrvut.dll

2008-11-29 08:47:50 ----A---- C:\WINDOWS\system32\catsrvps.dll

2008-11-29 08:47:50 ----A---- C:\WINDOWS\system32\catsrv.dll

2008-11-29 08:47:49 ----A---- C:\WINDOWS\system32\comuid.dll

2008-11-29 08:47:49 ----A---- C:\WINDOWS\system32\comsvcs.dll

2008-11-29 08:47:49 ----A---- C:\WINDOWS\system32\clbcatq.dll

2008-11-29 08:47:43 ----A---- C:\WINDOWS\system32\servdeps.dll

2008-11-29 08:47:43 ----A---- C:\WINDOWS\system32\mmfutil.dll

2008-11-29 08:47:43 ----A---- C:\WINDOWS\system32\licwmi.dll

2008-11-29 08:47:43 ----A---- C:\WINDOWS\system32\cmprops.dll

2008-11-29 06:45:37 ----A---- C:\WINDOWS\system32\h323log.txt

2008-11-29 06:33:13 ----A---- C:\WINDOWS\system32\s3gnb.dll

2008-11-29 06:32:39 ----A---- C:\WINDOWS\system32\usbui.dll

2008-11-29 06:31:18 ----SHD---- C:\WINDOWS\Installer

2008-11-29 06:31:18 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

2008-11-29 06:31:17 ----D---- C:\Arquivos de programas\Arquivos comuns\ODBC

2008-11-29 06:31:17 ----A---- C:\WINDOWS\ODBCINST.INI

2008-11-29 06:31:14 ----D---- C:\Arquivos de programas\Arquivos comuns\SpeechEngines

2008-11-29 06:31:14 ----D---- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared

2008-11-29 06:31:13 ----RD---- C:\Arquivos de programas

2008-11-29 06:31:13 ----D---- C:\Arquivos de programas\Arquivos comuns

2008-11-29 06:31:10 ----RA---- C:\WINDOWS\system32\kbdtuq.dll

2008-11-29 06:31:10 ----RA---- C:\WINDOWS\system32\kbdtuf.dll

2008-11-29 06:31:10 ----RA---- C:\WINDOWS\system32\kbdazel.dll

2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbduzb.dll

2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdur.dll

2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdtat.dll

2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdmon.dll

2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdkyr.dll

2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdkaz.dll

2008-11-29 06:31:09 ----RA---- C:\WINDOWS\system32\kbdaze.dll

2008-11-29 06:31:08 ----RA---- C:\WINDOWS\system32\kbdycc.dll

2008-11-29 06:31:08 ----RA---- C:\WINDOWS\system32\kbdru1.dll

2008-11-29 06:31:08 ----RA---- C:\WINDOWS\system32\kbdru.dll

2008-11-29 06:31:08 ----RA---- C:\WINDOWS\system32\kbdbu.dll

2008-11-29 06:31:08 ----RA---- C:\WINDOWS\system32\kbdblr.dll

2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhept.dll

2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhela3.dll

2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhela2.dll

2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhe319.dll

2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhe220.dll

2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdhe.dll

2008-11-29 06:31:07 ----RA---- C:\WINDOWS\system32\kbdgkl.dll

2008-11-29 06:31:06 ----RA---- C:\WINDOWS\system32\kbdlv1.dll

2008-11-29 06:31:06 ----RA---- C:\WINDOWS\system32\kbdlv.dll

2008-11-29 06:31:06 ----RA---- C:\WINDOWS\system32\kbdlt1.dll

2008-11-29 06:31:06 ----RA---- C:\WINDOWS\system32\kbdlt.dll

2008-11-29 06:31:06 ----RA---- C:\WINDOWS\system32\kbdest.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdycl.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdsl1.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdsl.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdro.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdpl1.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdpl.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdhu1.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdhu.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdcz2.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdcz1.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdcz.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\kbdcr.dll

2008-11-29 06:31:04 ----RA---- C:\WINDOWS\system32\KBDAL.DLL

2008-11-29 06:31:01 ----A---- C:\WINDOWS\system32\spxcoins.dll

2008-11-29 06:31:01 ----A---- C:\WINDOWS\system32\irclass.dll

2008-11-29 06:31:01 ----A---- C:\WINDOWS\system32\EqnClass.Dll

2008-11-29 06:31:01 ----A---- C:\WINDOWS\system32\dgsetup.dll

2008-11-29 06:31:01 ----A---- C:\WINDOWS\system32\dgrpsetu.dll

2008-11-29 06:30:59 ----N---- C:\WINDOWS\system32\CONFIG.TMP

2008-11-29 06:30:59 ----A---- C:\WINDOWS\TASKMAN.EXE

2008-11-29 06:30:59 ----A---- C:\WINDOWS\system32\batt.dll

2008-11-29 06:30:58 ----A---- C:\WINDOWS\notepad.exe

2008-11-29 06:30:57 ----A---- C:\WINDOWS\system32\storprop.dll

2008-11-29 06:30:48 ----ASH---- C:\Documents and Settings\All Users\Dados de aplicativos\desktop.ini

2008-11-29 06:30:43 ----RA---- C:\WINDOWS\SET8.tmp

2008-11-29 06:30:40 ----RA---- C:\WINDOWS\SET4.tmp

2008-11-29 06:30:39 ----RA---- C:\WINDOWS\SET3.tmp

2008-11-29 06:30:32 ----D---- C:\WINDOWS\system32\CatRoot2

2008-11-29 06:30:32 ----D---- C:\WINDOWS\system32\CatRoot

2008-11-29 06:30:27 ----SD---- C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft

2008-11-29 06:30:02 ----D---- C:\Documents and Settings

2008-11-29 06:30:01 ----SHD---- C:\System Volume Information

2008-11-29 06:29:09 ----ASH---- C:\boot.ini

2008-11-29 06:25:00 ----RSHDC---- C:\WINDOWS\system32\dllcache

2008-11-29 06:25:00 ----RSD---- C:\WINDOWS\Fonts

2008-11-29 06:25:00 ----RD---- C:\WINDOWS\Web

2008-11-29 06:25:00 ----HD---- C:\WINDOWS\inf

2008-11-29 06:25:00 ----D---- C:\WINDOWS\WinSxS

2008-11-29 06:25:00 ----D---- C:\WINDOWS\twain_32

2008-11-29 06:25:00 ----D---- C:\WINDOWS\Temp

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\wins

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\wbem

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\usmt

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\spool

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\ShellExt

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\Setup

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\ras

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\oobe

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\npp

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\mui

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\inetsrv

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\IME

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\icsxml

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\ias

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\export

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\drivers

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\dhcp

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\config

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\3com_dmi

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\3076

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\2052

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1054

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1046

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1042

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1041

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1037

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1033

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1031

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1028

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32\1025

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system32

2008-11-29 06:25:00 ----D---- C:\WINDOWS\system

2008-11-29 06:25:00 ----D---- C:\WINDOWS\security

2008-11-29 06:25:00 ----D---- C:\WINDOWS\Resources

2008-11-29 06:25:00 ----D---- C:\WINDOWS\repair

2008-11-29 06:25:00 ----D---- C:\WINDOWS\Provisioning

2008-11-29 06:25:00 ----D---- C:\WINDOWS\PeerNet

2008-11-29 06:25:00 ----D---- C:\WINDOWS\pchealth

2008-11-29 06:25:00 ----D---- C:\WINDOWS\mui

2008-11-29 06:25:00 ----D---- C:\WINDOWS\msapps

2008-11-29 06:25:00 ----D---- C:\WINDOWS\msagent

2008-11-29 06:25:00 ----D---- C:\WINDOWS\Media

2008-11-29 06:25:00 ----D---- C:\WINDOWS\java

2008-11-29 06:25:00 ----D---- C:\WINDOWS\ime

2008-11-29 06:25:00 ----D---- C:\WINDOWS\Help

2008-11-29 06:25:00 ----D---- C:\WINDOWS\ehome

2008-11-29 06:25:00 ----D---- C:\WINDOWS\Driver Cache

2008-11-29 06:25:00 ----D---- C:\WINDOWS\Debug

2008-11-29 06:25:00 ----D---- C:\WINDOWS\Cursors

2008-11-29 06:25:00 ----D---- C:\WINDOWS\Connection Wizard

2008-11-29 06:25:00 ----D---- C:\WINDOWS\Config

2008-11-29 06:25:00 ----D---- C:\WINDOWS\AppPatch

2008-11-29 06:25:00 ----D---- C:\WINDOWS\addins

2008-11-29 06:25:00 ----D---- C:\WINDOWS

 

======List of files/folders modified in the last 1 months======

 

2008-12-05 10:15:25 ----A---- C:\WINDOWS\system.ini

2008-12-04 08:21:58 ----A---- C:\WINDOWS\win.ini

 

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

 

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-11-26 26944]

R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-11-26 111184]

R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-11-26 50864]

R1 intelppm;Driver de Processador Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40448]

R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560]

R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-11-26 94032]

R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-11-26 23152]

R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]

R3 mf;mf; C:\WINDOWS\system32\DRIVERS\mf.sys [2008-04-13 63744]

R3 S3SavageNB;S3SavageNB; C:\WINDOWS\system32\DRIVERS\s3gnbm.sys [2004-08-03 166912]

R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]

R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]

R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]

R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\viaudios.sys [2004-03-17 117248]

S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []

S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]

S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

 

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

 

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe [2008-11-26 18752]

R2 avast! Antivirus;avast! Antivirus; C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe [2008-11-26 155160]

R2 WinDefend;Windows Defender; C:\Arquivos de programas\Windows Defender\MsMpEng.exe [2006-11-03 13592]

R3 avast! Mail Scanner;avast! Mail Scanner; C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe [2008-11-26 254040]

R3 avast! Web Scanner;avast! Web Scanner; C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe [2008-11-26 352920]

S3 odserv;Microsoft Office Diagnostics Service; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]

S3 ose;Office Source Engine; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

 

-----------------EOF-----------------

 

 

 

 

info.txt logfile of random's system information tool 1.04 2008-12-05 16:21:42

 

======Uninstall list======

 

-->C:\Arquivos de programas\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL

-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL

-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL

-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL

-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL

-->C:\WINDOWS\UNRecode.exe /UNINSTALL

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf

Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe

Adobe Reader 9 - Português-->MsiExec.exe /I{AC76BA86-7AD7-1046-7B44-A90000000001}

Assistente de Conexão do Windows Live-->MsiExec.exe /I{8984E374-6C93-427C-A3B9-AD92472FDCA0}

Atualização de Segurança para Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"

Atualização de Segurança para Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"

Atualização de Segurança para Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"

Atualização para Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"

Atualização para Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"

Atualização para Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"

avast! Antivirus-->C:\Arquivos de programas\Alwil Software\Avast4\aswRunDll.exe "C:\Arquivos de programas\Alwil Software\Avast4\Setup\setiface.dll",RunSetup

Catálogo de Peças - FORD Personalizado-->C:\OiC\cat_perf\uninstall.exe /uninstall

CCleaner (remove only)-->"C:\Arquivos de programas\CCleaner\uninst.exe"

Choice Guard-->MsiExec.exe /I{EBD5E7A9-DBB8-4E24-AE3A-CF9390AF1CCB}

Contacts-->MsiExec.exe /I{C6BDA6E5-B391-4CE5-8D86-B53AC96FFE03}

Easy Parts Fiat-->C:\OiC\cat_fiat\uninstall.exe /uninstall

FreeRIP v3.091-->"C:\Arquivos de programas\FreeRIP3\unins000.exe"

HijackThis 2.0.2-->"C:\Documents and Settings\Luciano Peças\Desktop\HijackThis.exe" /uninstall

Hotfix para Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"

Malwarebytes' Anti-Malware-->"C:\Arquivos de programas\Malwarebytes' Anti-Malware\unins000.exe"

Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"

Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"

Microsoft Office Access MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0015-0416-0000-0000000FF1CE}

Microsoft Office Enterprise 2007-->"C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL

Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}

Microsoft Office Excel MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0016-0416-0000-0000000FF1CE}

Microsoft Office Groove MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-00BA-0416-0000-0000000FF1CE}

Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0044-0416-0000-0000000FF1CE}

Microsoft Office OneNote MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-00A1-0416-0000-0000000FF1CE}

Microsoft Office Outlook MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-001A-0416-0000-0000000FF1CE}

Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0018-0416-0000-0000000FF1CE}

Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}

Microsoft Office Proof (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-001F-0416-0000-0000000FF1CE}

Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}

Microsoft Office Proofing (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-002C-0416-0000-0000000FF1CE}

Microsoft Office Publisher MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0019-0416-0000-0000000FF1CE}

Microsoft Office Shared MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-006E-0416-0000-0000000FF1CE}

Microsoft Office Word MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-001B-0416-0000-0000000FF1CE}

Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs-->MsiExec.exe /X{90120000-00B2-0409-0000-0000000FF1CE}

MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}

Nero 7 Demo-->MsiExec.exe /I{1CBCC734-E92F-C744-D86C-3699D5351046}

NetMos Multi-IO Controller-->NmUninst.exe

Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}

Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}

Tonic v1.0 (build 990)-->C:\Arquivos de programas\r2 Studios\Tonic\Uninstall.exe

UltraVnc v1.0.4-->"C:\Arquivos de programas\UltraVnc\unins000.exe"

UsbFix-->C:\Arquivos de programas\UsbFix\Uninstal.exe

VIA Audio Driver Setup Program-->RunDll32.exe UnAudioNT.dll,UninstallAudio C:\WINDOWS\IsUninst.exe -y-f"C:\ARQUIV~1\VIAudioi\SBASetup\Uninst.isu"

Windows Defender-->MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}

Windows Live Beta (todos os programas)-->C:\Arquivos de programas\Windows Live\Installer\wlarp.exe

Windows Live Beta (todos os programas)-->MsiExec.exe /I{4FE37B71-AB78-4F4A-8327-A8401E5BD12A}

Windows Live Call-->MsiExec.exe /I{F99EE599-A088-4037-831E-587E9BB35826}

Windows Live Messenger-->MsiExec.exe /X{2B3D758E-DEE0-4868-B2F6-9CE435A13400}

Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

WinZip-->"C:\Arquivos de programas\WinZip\WINZIP32.EXE" /uninstall

 

======Security center information======

 

AV: avast! antivirus 4.8.1296 [VPS 081208-0]

 

======Environment variables======

 

"ComSpec"=%SystemRoot%\system32\cmd.exe

"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem

"windir"=%SystemRoot%

"FP_NO_HOST_CHECK"=NO

"OS"=Windows_NT

"PROCESSOR_ARCHITECTURE"=x86

"PROCESSOR_LEVEL"=15

"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel

"PROCESSOR_REVISION"=0401

"NUMBER_OF_PROCESSORS"=1

"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH

"TEMP"=%SystemRoot%\TEMP

"TMP"=%SystemRoot%\TEMP

 

-----------------EOF-----------------

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa TINOtec.

 

Por acaso este arquivo que pedi que enviasse ao VirusTotal (que você diz ser de confiança), trata-se de um keylogger ou algo do tipo? Porque pelo resultado do VirusTotal o arquivo é potencialmente perigoso!

 

Bem vamos continuar.

 

1ª Etapa

 

Delete as pasta do ComboFix que está em sua máquina e seu log (ComboFix.txt), ambos em C:. Caso esteja com a ferramenta ComboFix ainda no PC, vá em Iniciar > Executar, digite: combofix /u e dê um Enter. Delete também a ferramenta USBFix em Painel de Controle > Adicionar ou Remover Programas. Após isso, delete sua pasta em C:\Arquivos de Programas.

 

 

2ª Etapa

 

- Faça novamente o download do ComboFix e salve-o na área de trabalho;

 

● Desative temporariamente o seu antivirus para não detectar a ferramenta como vírus;

● Duplo clique no ícone combofix.exe para iniciar o scan;

● Leia o contrato que aparecerá e clique em Sim para continuar;

● Abrirá uma janela do Console de Recuperação, clique em Sim para instalar. Se aparecer outra janela do Console, clique em OK > Sim;

● Aguarde enquanto o ComboFix faz o scan;

● Se ocorrer algum problema durante o scan, reinicie seu computador em Modo de Segurança e repita o procedimento;

Não clique na janela do ComboFix e procure não utilizar o teclado também, para não atrapalhar a varredura da ferramenta;

● Se quiser sair ou parar o ComboFix, tecle N;

● Quando terminar seu micro será reiniciado. Após o reinicio, a ferramenta executará novamente, aguarde;

● Será gerado um log em C:\ComboFix.txt.

 

Cole este log em sua próxima resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aquele arquivo que você me pediu para analisar no virus total, é de um programa que me permite visualizar a tela de todas as estações da rede.

 

Segue abaixo relatório do combofix:

 

ComboFix 08-12-07.04 - Luciano Peças 2008-12-09 8:53:59.4 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.207 [GMT -2:00]

Executando de: c:\documents and settings\Luciano Peças\Desktop\ComboFix.exe

* Criado um novo ponto de restauro

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-09 to 2008-12-09 ))))))))))))))))))))))))))))

.

 

2008-12-05 17:01 . 2008-12-05 17:01 116 --a------ c:\windows\NeroDigital.ini

2008-12-05 16:21 . 2008-12-05 16:21 <DIR> d-------- C:\rsit

2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Malwarebytes

2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware

2008-12-05 10:21 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2008-12-05 10:21 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2008-12-04 15:48 . 2008-12-04 15:48 65 --a------ C:\imp2.bat

2008-12-04 15:47 . 2008-12-04 15:47 <DIR> d-------- c:\arquivos de programas\MSECache

2008-12-04 08:28 . 2008-12-04 08:28 <DIR> d-------- c:\arquivos de programas\Microsoft Works

2008-12-04 08:21 . 2008-12-04 08:22 <DIR> d-------- c:\windows\SHELLNEW

2008-12-04 08:19 . 2008-12-04 08:31 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help

2008-12-04 08:18 . 2008-12-04 08:18 <DIR> dr-h----- C:\MSOCache

2008-12-03 18:13 . 2008-12-03 21:13 493 --a------ c:\windows\cat_fiat.ini

2008-12-03 18:08 . 2008-12-03 18:13 492 --a------ c:\windows\cat_perf.ini

2008-12-03 18:08 . 2008-12-03 08:12 453 --a------ c:\windows\cat_vw.ini

2008-12-03 18:08 . 2008-12-03 21:13 327 --ahs---- c:\windows\CHCT

2008-12-03 18:00 . 2008-12-03 18:15 <DIR> d-------- C:\CAT_VW

2008-12-03 17:55 . 2008-12-03 17:58 <DIR> d-------- C:\OiC

2008-12-03 17:55 . 2008-12-03 17:58 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\OiC

2008-12-03 17:54 . 2008-12-03 18:05 <DIR> d-------- c:\arquivos de programas\CepChev2

2008-12-03 17:46 . 2008-12-03 17:46 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Ahead

2008-12-03 17:43 . 2008-12-03 17:43 <DIR> d-------- c:\arquivos de programas\Nero

2008-12-03 17:43 . 2008-12-03 17:48 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Ahead

2008-12-03 17:41 . 2008-12-04 15:51 163 --a------ c:\windows\cdplayer.ini

2008-12-03 17:40 . 2008-12-03 17:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\FreeRIP

2008-12-03 17:40 . 2008-12-03 17:40 <DIR> d-------- c:\arquivos de programas\FreeRIP3

2008-12-03 17:29 . 2008-12-03 17:29 <DIR> d--h----- c:\windows\system32\GroupPolicy

2008-12-03 17:20 . 2008-12-03 17:20 <DIR> d-------- c:\documents and settings\Luciano Peças\Tracing

2008-12-03 17:20 . 2008-12-03 17:20 <DIR> d-------- c:\documents and settings\Luciano Peças\Tracing

2008-12-03 17:16 . 2008-12-03 17:16 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\skypePM

2008-12-03 17:16 . 2008-12-03 17:16 56 --ah----- c:\windows\system32\ezsidmv.dat

2008-12-03 13:00 . 2008-12-03 13:00 <DIR> d--h----- c:\windows\PIF

2008-12-03 10:59 . 2008-12-03 10:59 <DIR> d-------- c:\arquivos de programas\Microsoft

2008-12-03 10:57 . 2008-12-03 10:59 <DIR> d-------- c:\arquivos de programas\Windows Live

2008-12-03 10:36 . 2008-12-03 10:36 <DIR> d-------- c:\arquivos de programas\Windows Defender

2008-12-03 10:34 . 2008-12-03 10:34 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live

2008-12-03 10:34 . 2008-12-03 10:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe

2008-12-03 10:32 . 2008-12-04 15:52 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Skype

2008-12-03 10:32 . 2008-12-03 10:32 <DIR> d-------- c:\arquivos de programas\Skype

2008-12-03 10:32 . 2008-12-03 10:32 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Skype

2008-12-03 10:31 . 2008-12-03 10:32 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Skype

2008-12-03 10:31 . 2008-12-03 10:31 <DIR> d-------- c:\arquivos de programas\CCleaner

2008-12-03 10:28 . 2008-12-03 10:29 <DIR> d-------- c:\arquivos de programas\UltraVnc

2008-12-03 10:24 . 2008-12-03 10:24 <DIR> d-------- c:\arquivos de programas\r2 Studios

2008-12-03 10:23 . 2006-12-08 16:19 134,144 --a------ c:\windows\system32\SMon2.exe

2008-12-02 17:14 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2008-12-02 17:04 . 2008-09-04 15:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll

2008-12-02 17:04 . 2008-10-15 14:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll

2008-12-02 16:57 . 2008-08-14 11:24 2,193,408 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe

2008-12-02 16:57 . 2008-08-14 11:24 2,149,376 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe

2008-12-02 16:57 . 2008-08-14 11:24 2,070,272 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe

2008-12-02 16:57 . 2008-08-14 11:24 2,028,032 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe

2008-12-02 16:57 . 2008-09-08 08:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys

2008-12-02 16:56 . 2008-08-14 08:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys

2008-12-02 16:55 . 2008-09-15 13:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys

2008-12-02 16:53 . 2008-05-01 12:36 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll

2008-12-02 16:51 . 2008-04-11 17:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll

2008-12-02 16:50 . 2008-05-09 08:55 512,000 -----c--- c:\windows\system32\dllcache\jscript.dll

2008-12-02 16:50 . 2008-05-09 08:55 430,080 -----c--- c:\windows\system32\dllcache\vbscript.dll

2008-12-02 16:50 . 2008-05-09 08:55 180,224 -----c--- c:\windows\system32\dllcache\scrobj.dll

2008-12-02 16:50 . 2008-05-09 08:55 172,032 -----c--- c:\windows\system32\dllcache\scrrun.dll

2008-12-02 16:50 . 2008-05-08 09:24 155,648 -----c--- c:\windows\system32\dllcache\wscript.exe

2008-12-02 16:50 . 2008-05-09 06:45 135,168 -----c--- c:\windows\system32\dllcache\cscript.exe

2008-12-02 16:50 . 2008-05-09 08:55 90,112 -----c--- c:\windows\system32\dllcache\wshext.dll

2008-12-02 16:48 . 2008-06-14 15:34 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys

2008-12-02 16:47 . 2008-05-08 12:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys

2008-12-02 16:41 . 2008-10-16 14:09 43,544 --a------ c:\windows\system32\wups2.dll

2008-12-02 16:41 . 2008-10-16 14:09 31,768 --a------ c:\windows\system32\wucltui.dll.mui

2008-12-02 16:41 . 2008-10-16 14:08 27,672 --a------ c:\windows\system32\wuaucpl.cpl.mui

2008-12-02 16:41 . 2008-10-16 14:08 27,672 --a------ c:\windows\system32\wuapi.dll.mui

2008-12-02 16:41 . 2008-10-16 14:07 18,968 --a------ c:\windows\system32\wuaueng.dll.mui

2008-12-02 11:51 . 2008-12-02 11:54 <DIR> d-------- c:\windows\ServicePackFiles

2008-12-02 11:51 . 2008-04-13 19:20 294,912 -----c--- c:\windows\system32\dllcache\dlimport.exe

2008-12-02 11:47 . 2006-12-28 12:01 19,569 --a------ c:\windows\002674_.tmp

2008-12-02 10:48 . 2008-12-02 17:17 <DIR> d-------- c:\windows\system32\pt-br

2008-12-02 10:46 . 2007-08-10 08:12 26,488 --a------ c:\windows\system32\spupdsvc.exe

2008-12-02 10:45 . 2008-12-02 17:19 <DIR> d--h----- c:\windows\$hf_mig$

2008-12-02 08:19 . 2008-12-02 08:19 <DIR> d-------- c:\arquivos de programas\Alwil Software

2008-12-01 11:01 . 2008-04-13 12:17 83,072 --a------ c:\windows\system32\drivers\wdmaud.sys

2008-12-01 11:01 . 2008-04-13 11:45 6,272 --a------ c:\windows\system32\drivers\splitter.sys

2008-12-01 11:00 . 2008-12-01 11:00 <DIR> d-------- c:\arquivos de programas\VIAudioi

2008-12-01 10:03 . 2004-10-05 16:54 306,688 --a------ c:\windows\IsUninst.exe

2008-12-01 10:03 . 2003-07-01 18:42 27,904 -ra------ c:\windows\system32\drivers\VIAAGP1.SYS

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-02 12:50 65 ----a-w C:\imp.bat

2008-11-29 10:53 --------- d-----w c:\arquivos de programas\microsoft frontpage

2008-11-29 10:50 --------- d-----w c:\arquivos de programas\Serviços on-line

2008-11-29 10:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços

2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys

2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys

2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll

2008-09-09 02:03 51,712 ----a-w c:\windows\system32\sirenacm.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

"SMon2"="c:\windows\system32\SMon2.exe" [2006-12-08 134144]

 

c:\documents and settings\Luciano Pe‡as\Menu Iniciar\Programas\Inicializar\

Run server as application.lnk - c:\arquivos de programas\UltraVnc\winvnc.exe [2008-12-03 1144384]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

--a------ 2008-06-12 02:38 34672 c:\arquivos de programas\Adobe\Reader 9.0\Reader\reader_sl.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

--a------ 2006-01-12 15:40 155648 c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\WINDOWS\\system32\\SMon2.exe"=

"c:\\Arquivos de programas\\r2 Studios\\Tonic\\Tonic.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"5900:TCP"= 5900:TCP:vnc5900

"5800:TCP"= 5800:TCP:vnc5800

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-02 111184]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-02 20560]

R2 WinDefend;Windows Defender;"c:\arquivos de programas\Windows Defender\MsMpEng.exe" [2006-11-03 13592]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7aaf576-c2b3-11dd-a65b-000feaa4fb9c}]

\Shell\AutoRun\command - F:\rcukd.cmd

\Shell\explore\Command - F:\rcukd.cmd

\Shell\open\Command - F:\rcukd.cmd

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-06 c:\windows\Tasks\MP Scheduled Scan.job

- c:\arquivos de programas\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-09 08:55:45

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-12-09 8:56:37

ComboFix-quarantined-files.txt 2008-12-09 10:56:33

 

Pré-execução: 12 pasta(s) 22.851.895.296 bytes disponíveis

Pós execução: 12 pasta(s) 22,860,939,264 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

172 --- E O F --- 2008-12-06 10:01:54

Compartilhar este post


Link para o post
Compartilhar em outros sites

Selecione e copie o texto abaixo dentro do quote. Cole-o dentro do bloco de notas e salve no desktop como CFScript.txt

 

File::

C:\imp2.bat

C:\imp.bat

F:\rcukd.cmd

Registry::

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7aaf576-c2b3-11dd-a65b-000feaa4fb9c}]

 

Arraste o CFScript para o ComboFix como na imagem aqui abaixo e aguarde a execução automática da ferramenta:

 

CFScript.gif

 

● Se for solicitado à você, pressione Enter para iniciar o processo de remoção;

Não use o mouse nem o teclado quando o ComboFix estiver rodando;

● Quando terminar, será gerado um novo log que estará em C:\ComboFix.txt;

● Seu computador será reiniciado automaticamente;

 

Na sua próxima resposta, cole o ComboFix.txt e um novo log do HijackThis.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Brother, no arquivo CFScript, não inclui os arquivos .bat, pois os mesmos são do meu uso, para mapeamento de impressoras na rede.

 

Segue abaixo, relatórios:

 

ComboFix 08-12-09.02 - Luciano Peças 2008-12-10 8:15:56.5 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.166 [GMT -2:00]

Executando de: c:\documents and settings\Luciano Peças\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\Luciano Peças\Desktop\CFScript.txt

* Criado um novo ponto de restauro

 

FILE ::

F:\rcukd.cmd

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-10 to 2008-12-10 ))))))))))))))))))))))))))))

.

 

2008-12-09 16:28 . 2008-12-09 16:28 <DIR> d-------- c:\arquivos de programas\CygNET Systems Pvt. Ltd

2008-12-09 16:28 . 2008-12-09 16:28 12 --a------ c:\windows\system32\usbsys.tmp

2008-12-05 17:01 . 2008-12-05 17:01 116 --a------ c:\windows\NeroDigital.ini

2008-12-05 16:21 . 2008-12-05 16:21 <DIR> d-------- C:\rsit

2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Malwarebytes

2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2008-12-05 10:21 . 2008-12-05 10:21 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware

2008-12-05 10:21 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2008-12-05 10:21 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2008-12-04 15:48 . 2008-12-04 15:48 65 --a------ C:\imp2.bat

2008-12-04 15:47 . 2008-12-04 15:47 <DIR> d-------- c:\arquivos de programas\MSECache

2008-12-04 08:28 . 2008-12-04 08:28 <DIR> d-------- c:\arquivos de programas\Microsoft Works

2008-12-04 08:21 . 2008-12-04 08:22 <DIR> d-------- c:\windows\SHELLNEW

2008-12-04 08:19 . 2008-12-04 08:31 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help

2008-12-04 08:18 . 2008-12-04 08:18 <DIR> dr-h----- C:\MSOCache

2008-12-03 18:13 . 2008-12-03 21:13 493 --a------ c:\windows\cat_fiat.ini

2008-12-03 18:08 . 2008-12-03 18:13 492 --a------ c:\windows\cat_perf.ini

2008-12-03 18:08 . 2008-12-03 08:12 453 --a------ c:\windows\cat_vw.ini

2008-12-03 18:08 . 2008-12-03 21:13 327 --ahs---- c:\windows\CHCT

2008-12-03 18:00 . 2008-12-03 18:15 <DIR> d-------- C:\CAT_VW

2008-12-03 17:55 . 2008-12-03 17:58 <DIR> d-------- C:\OiC

2008-12-03 17:55 . 2008-12-03 17:58 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\OiC

2008-12-03 17:54 . 2008-12-03 18:05 <DIR> d-------- c:\arquivos de programas\CepChev2

2008-12-03 17:46 . 2008-12-03 17:46 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Ahead

2008-12-03 17:43 . 2008-12-03 17:43 <DIR> d-------- c:\arquivos de programas\Nero

2008-12-03 17:43 . 2008-12-03 17:48 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Ahead

2008-12-03 17:41 . 2008-12-04 15:51 163 --a------ c:\windows\cdplayer.ini

2008-12-03 17:40 . 2008-12-03 17:40 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\FreeRIP

2008-12-03 17:40 . 2008-12-03 17:40 <DIR> d-------- c:\arquivos de programas\FreeRIP3

2008-12-03 17:29 . 2008-12-03 17:29 <DIR> d--h----- c:\windows\system32\GroupPolicy

2008-12-03 17:20 . 2008-12-03 17:20 <DIR> d-------- c:\documents and settings\Luciano Peças\Tracing

2008-12-03 17:20 . 2008-12-03 17:20 <DIR> d-------- c:\documents and settings\Luciano Peças\Tracing

2008-12-03 17:16 . 2008-12-03 17:16 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\skypePM

2008-12-03 17:16 . 2008-12-03 17:16 56 --ah----- c:\windows\system32\ezsidmv.dat

2008-12-03 13:00 . 2008-12-03 13:00 <DIR> d--h----- c:\windows\PIF

2008-12-03 10:59 . 2008-12-03 10:59 <DIR> d-------- c:\arquivos de programas\Microsoft

2008-12-03 10:57 . 2008-12-03 10:59 <DIR> d-------- c:\arquivos de programas\Windows Live

2008-12-03 10:36 . 2008-12-03 10:36 <DIR> d-------- c:\arquivos de programas\Windows Defender

2008-12-03 10:34 . 2008-12-03 10:34 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live

2008-12-03 10:34 . 2008-12-03 10:35 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe

2008-12-03 10:32 . 2008-12-04 15:52 <DIR> d-------- c:\documents and settings\Luciano Peças\Dados de aplicativos\Skype

2008-12-03 10:32 . 2008-12-03 10:32 <DIR> d-------- c:\arquivos de programas\Skype

2008-12-03 10:32 . 2008-12-03 10:32 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Skype

2008-12-03 10:31 . 2008-12-03 10:32 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Skype

2008-12-03 10:31 . 2008-12-03 10:31 <DIR> d-------- c:\arquivos de programas\CCleaner

2008-12-03 10:28 . 2008-12-09 16:36 <DIR> d-------- c:\arquivos de programas\UltraVnc

2008-12-03 10:24 . 2008-12-03 10:24 <DIR> d-------- c:\arquivos de programas\r2 Studios

2008-12-03 10:23 . 2006-12-08 16:19 134,144 --a------ c:\windows\system32\SMon2.exe

2008-12-02 17:14 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2008-12-02 17:04 . 2008-09-04 15:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll

2008-12-02 17:04 . 2008-10-15 14:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll

2008-12-02 16:57 . 2008-08-14 11:24 2,193,408 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe

2008-12-02 16:57 . 2008-08-14 11:24 2,149,376 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe

2008-12-02 16:57 . 2008-08-14 11:24 2,070,272 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe

2008-12-02 16:57 . 2008-08-14 11:24 2,028,032 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe

2008-12-02 16:57 . 2008-09-08 08:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys

2008-12-02 16:56 . 2008-08-14 08:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys

2008-12-02 16:55 . 2008-09-15 13:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys

2008-12-02 16:53 . 2008-05-01 12:36 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll

2008-12-02 16:51 . 2008-04-11 17:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll

2008-12-02 16:50 . 2008-05-09 08:55 512,000 -----c--- c:\windows\system32\dllcache\jscript.dll

2008-12-02 16:50 . 2008-05-09 08:55 430,080 -----c--- c:\windows\system32\dllcache\vbscript.dll

2008-12-02 16:50 . 2008-05-09 08:55 180,224 -----c--- c:\windows\system32\dllcache\scrobj.dll

2008-12-02 16:50 . 2008-05-09 08:55 172,032 -----c--- c:\windows\system32\dllcache\scrrun.dll

2008-12-02 16:50 . 2008-05-08 09:24 155,648 -----c--- c:\windows\system32\dllcache\wscript.exe

2008-12-02 16:50 . 2008-05-09 06:45 135,168 -----c--- c:\windows\system32\dllcache\cscript.exe

2008-12-02 16:50 . 2008-05-09 08:55 90,112 -----c--- c:\windows\system32\dllcache\wshext.dll

2008-12-02 16:48 . 2008-06-14 15:34 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys

2008-12-02 16:47 . 2008-05-08 12:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys

2008-12-02 16:41 . 2008-10-16 14:09 43,544 --a------ c:\windows\system32\wups2.dll

2008-12-02 16:41 . 2008-10-16 14:09 31,768 --a------ c:\windows\system32\wucltui.dll.mui

2008-12-02 16:41 . 2008-10-16 14:08 27,672 --a------ c:\windows\system32\wuaucpl.cpl.mui

2008-12-02 16:41 . 2008-10-16 14:08 27,672 --a------ c:\windows\system32\wuapi.dll.mui

2008-12-02 16:41 . 2008-10-16 14:07 18,968 --a------ c:\windows\system32\wuaueng.dll.mui

2008-12-02 11:51 . 2008-12-02 11:54 <DIR> d-------- c:\windows\ServicePackFiles

2008-12-02 11:51 . 2008-04-13 19:20 294,912 -----c--- c:\windows\system32\dllcache\dlimport.exe

2008-12-02 11:47 . 2006-12-28 12:01 19,569 --a------ c:\windows\002674_.tmp

2008-12-02 10:48 . 2008-12-02 17:17 <DIR> d-------- c:\windows\system32\pt-br

2008-12-02 10:46 . 2007-08-10 08:12 26,488 --a------ c:\windows\system32\spupdsvc.exe

2008-12-02 10:45 . 2008-12-02 17:19 <DIR> d--h----- c:\windows\$hf_mig$

2008-12-02 08:19 . 2008-12-02 08:19 <DIR> d-------- c:\arquivos de programas\Alwil Software

2008-12-01 11:01 . 2008-04-13 12:17 83,072 --a------ c:\windows\system32\drivers\wdmaud.sys

2008-12-01 11:01 . 2008-04-13 11:45 6,272 --a------ c:\windows\system32\drivers\splitter.sys

2008-12-01 11:00 . 2008-12-01 11:00 <DIR> d-------- c:\arquivos de programas\VIAudioi

2008-12-01 10:03 . 2004-10-05 16:54 306,688 --a------ c:\windows\IsUninst.exe

2008-12-01 10:03 . 2003-07-01 18:42 27,904 -ra------ c:\windows\system32\drivers\VIAAGP1.SYS

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-02 12:50 65 ----a-w C:\imp.bat

2008-11-29 10:53 --------- d-----w c:\arquivos de programas\microsoft frontpage

2008-11-29 10:50 --------- d-----w c:\arquivos de programas\Serviços on-line

2008-11-29 10:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços

2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys

2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys

2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

"SMon2"="c:\windows\system32\SMon2.exe" [2006-12-08 134144]

"Tonic"="c:\arquivos de programas\r2 Studios\Tonic\Tonic.exe" [2006-09-03 840192]

 

c:\documents and settings\Luciano Pe‡as\Menu Iniciar\Programas\Inicializar\

Run server as application.lnk - c:\arquivos de programas\UltraVnc\winvnc.exe [2008-12-03 1144384]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\WINDOWS\\system32\\SMon2.exe"=

"c:\\Arquivos de programas\\r2 Studios\\Tonic\\Tonic.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"5900:TCP"= 5900:TCP:vnc5900

"5800:TCP"= 5800:TCP:vnc5800

"5553:TCP"= 5553:TCP:USBCopyNotify!

"5555:UDP"= 5555:UDP:USBCopyNotify!

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-02 111184]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-02 20560]

R2 USBCopyNotifyClient;USBCopyNotify Client Service;"c:\arquivos de programas\CygNET Systems Pvt. Ltd\USB CopyNotify!\USBCopyNotifyClient.exe" [2008-12-09 344064]

R2 WinDefend;Windows Defender;"c:\arquivos de programas\Windows Defender\MsMpEng.exe" [2006-11-03 13592]

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-10 c:\windows\Tasks\MP Scheduled Scan.job

- c:\arquivos de programas\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-10 08:18:00

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

Tempo para conclusão: 2008-12-10 8:18:59

ComboFix-quarantined-files.txt 2008-12-10 10:18:56

ComboFix2.txt 2008-12-09 10:56:39

 

Pré-execução: 12 pasta(s) 22.904.852.480 bytes disponíveis

Pós execução: 12 pasta(s) 22,897,582,080 bytes disponíveis

 

166 --- E O F --- 2008-12-06 10:01:54

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 08:24:04, on 10/12/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\CygNET Systems Pvt. Ltd\USB CopyNotify!\USBCopyNotifyClient.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\SMon2.exe

C:\Arquivos de programas\r2 Studios\Tonic\Tonic.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\UltraVnc\winvnc.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Arquivos de programas\internet explorer\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Documents and Settings\Luciano Peças\Configurações locais\Temporary Internet Files\Content.IE5\091RDWN2\HiJackThis[1].exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://grupolbezerra.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Arquivos de programas\Windows Live\Messenger\wlchtc.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [sMon2] C:\WINDOWS\system32\SMon2.exe

O4 - HKLM\..\Run: [Tonic] "C:\Arquivos de programas\r2 Studios\Tonic\Tonic.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Startup: Run server as application.lnk = C:\Arquivos de programas\UltraVnc\winvnc.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1228243184421

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O17 - HKLM\System\CS1\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O17 - HKLM\System\CS2\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O17 - HKLM\System\CS3\Services\Tcpip\..\{7690AB5F-AB85-41A1-8F92-572F26DC619E}: NameServer = 200.168.132.155,200.149.55.142

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: USBCopyNotify Client Service (USBCopyNotifyClient) - CygNET Systems Pvt. Ltd. - C:\Arquivos de programas\CygNET Systems Pvt. Ltd\USB CopyNotify!\USBCopyNotifyClient.exe

 

--

End of file - 5511 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

O log está limpo.

 

Vá em Iniciar > Executar, digite: combofix /u e tecle Enter. Delete a pasta C:\Qoobox e o log ComboFix.txt. Delete também a ferramenta RSIT e sua pasta C:\rsit.

 

Há algum problema na máquina ainda?

Compartilhar este post


Link para o post
Compartilhar em outros sites
O log está limpo.

Maravilha...

 

Vá em Iniciar > Executar, digite: combofix /u e tecle Enter. Delete a pasta C:\Qoobox e o log ComboFix.txt. Delete também a ferramenta RSIT e sua pasta C:\rsit.

Feito.

 

Há algum problema na máquina ainda?

Negativo, está uma bala novamente.

 

 

Obrigado e abraços. :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.