Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Rodrigo Rocha RJ

[Resolvido!] Janelas do IE abrem sozinhas

Recommended Posts

Olá amigos do iMasters,

Depois de muito pesquisar e não conseguir resolver o problemas com minhas próprias mãos resolvi pedir ajuda a vocês.

 

Pesquisando no google vi que aqui existe uma pessoa com o problema idêntico ao meu (http://forum.imasters.com.br/index.php?/topic/371985-janelas-do-ie-abrem-sozinhas/). Segui a orientação dada pelo Antônio Vieira Sobrinho e agora postarei o log para a anlise.

 

Desde já obrigado pela ajuda.

 

PS.: Meu AV é o Avira free e tenho também o Spybot Search and Destroy.

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:54: Rodrigo, on 17/12/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

C:\WINDOWS\System32\PAStiSvc.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\hkcmd.exe

C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe

C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe

C:\WINDOWS\system32\igfxtray.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Hijack This\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 217.72.199.106:80

R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehuni.dll

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [eSnips] "C:\Arquivos de programas\eSnips\ClientGW.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [AXIS TONS THE MP3] C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons\SOAP PART.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [drvsyskit] C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\drivers\winupgro.exe

O4 - HKCU\..\Run: [mule_st_key] C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\m\flec006.exe

O4 - HKCU\..\Run: [NBJ] "C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\RunOnce: [shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103471 -"Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-BR; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2 (.NET CLR 3.5.30729)" -"http://www.cartoonnetworkla.com/folders/200803/dexter.game.pt.labyrinth.432x330.zip2357934847000454/index.html"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/stg_drm.ocx

O16 - DPF: {31CB2F01-72C2-4CF4-B265-450E8817B039} (Toontown IE Helper Portuguese) - http://idownload.br.toontown.com/sv1.4.22.6/ttinst-portuguese.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab

O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.oifotos.com/custom/send3/ImageUploader5.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/armhelper.ocx

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} (GbPluginObj Class) - https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{27D4895C-B9D5-4547-BE37-98EB075148C3}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS4\Services\Tcpip\..\{27D4895C-B9D5-4547-BE37-98EB075148C3}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS5\Services\Tcpip\..\{27D4895C-B9D5-4547-BE37-98EB075148C3}: NameServer = 200.149.55.140 200.165.132.147

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O20 - Winlogon Notify: GbPluginUni - C:\ARQUIV~1\GbPlugin\gbiehuni.dll

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

 

--

End of file - 13460 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Rodrigo Rocha RJ

 

<@> Baixe: < LopS&D >

<@> Salve-o no Disco Local-C!

<@> Desabilite seu anti-vírus ou Firewall.

<@> Instale o programa e clique em: LopSD.cmd

<@> Na janela que abrir,aperte o "p" --> Aperte Enter.

 

Lop_Choix-large.jpg

 

<@> Em outra janela,aperte a opção: 2 - Fix + Hosts --> Aperte Enter --> Aguarde!

 

Lop_Lang_en-large.jpg

 

<@> Terminando,salve e poste o relatório. ( C:\Lop SD\LopR_1.txt )

<@> Poste,também,HijackThis atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá DigRam,

Obrigado pela ajuda

 

Log do Lop S&D

 

 

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

 

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3

X86-based PC ( Uniprocessor Free : Intel® Celeron® CPU 2.80GHz )

BIOS : Award Modular BIOS v6.00PG

USER : Rodrigo Rocha ( Administrator )

BOOT : Normal boot

Antivirus : AntiVir Desktop 9.0.1.32 (Activated)

A:\ (USB)

C:\ (Local Disk) - NTFS - Total:74 Go (Free:18 Go)

D:\ (CD or DVD)

E:\ (CD or DVD)

F:\ (CD or DVD)

G:\ (USB)

 

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )

Option : [2] ( qui 17/12/2009|13:06 )

 

 

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ REMOVIDOS

 

Deletado! - C:\DOCUME~1\RODRIG~1\CONFIG~1\Temp\sta18C.exe

Deletado! - C:\Arquivos de programas\Circle Developement

-

[ Arquivos/Ficheiros Hosts ] .. RESTAURADO

 

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

 

 

--------------------\\ Lista de pastas em DADOSD~1

 

[27/08/2008|14:54:] C:\DOCUME~1\ADMINI~1\DADOSD~1\<DIR> Microsoft

 

[31/05/2009|11:57:] C:\DOCUME~1\ALINER~1\DADOSD~1\<DIR> Adobe

[14/05/2008|10:31:] C:\DOCUME~1\ALINER~1\DADOSD~1\<DIR> Google

[14/10/2007|03:18:] C:\DOCUME~1\ALINER~1\DADOSD~1\<DIR> Identities

[14/10/2007|12:42:] C:\DOCUME~1\ALINER~1\DADOSD~1\<DIR> Macromedia

[27/08/2008|14:54:] C:\DOCUME~1\ALINER~1\DADOSD~1\<DIR> Microsoft

[31/05/2009|11:05:] C:\DOCUME~1\ALINER~1\DADOSD~1\<DIR> Mozilla

[06/11/2007|22:34:] C:\DOCUME~1\ALINER~1\DADOSD~1\<DIR> Nero

[31/05/2009|11:05:] C:\DOCUME~1\ALINER~1\DADOSD~1\<DIR> Real

[06/11/2008|19:54:] C:\DOCUME~1\ALINER~1\DADOSD~1\<DIR> SecuROM

 

[12/12/2009|12:37:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Adobe

[16/10/2007|20:15:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Ahead

[27/08/2008|14:54:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Avg7

[18/04/2009|22:04:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Avira

[15/02/2008|21:15:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> ConeXware

[27/07/2008|10:27:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> DVD Shrink

[14/04/2009|17:21:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> GbPlugin

[24/09/2009|21:41:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Google

[17/07/2008|21:01:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Hewlett-Packard

[17/07/2008|20:51:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> HP

[17/07/2008|20:51:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> HP Product Assistant

[17/07/2008|20:54:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> HPSSUPPLY

[05/02/2008|13:56:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Messenger Plus!

[17/11/2009|17:55:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Microsoft

[10/12/2009|14:27:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Microsoft Help

[19/01/2008|14:06:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> NCH Swift Sound

[05/12/2007|19:20:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Nero

[17/03/2008|20:24:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Office Genuine Advantage

[27/09/2009|01:44:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> PopCap Games

[23/10/2009|10:28:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Real

[02/02/2009|23:16:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> SlySoft

[14/10/2007|03:09:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Sony

[25/01/2009|23:01:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Spybot - Search & Destroy

[10/12/2009|10:08:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> TEMP

[27/12/2007|01:10:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> vsosdk

[17/07/2008|21:04:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> WEBREG

[13/10/2007|13:25:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> Windows Genuine Advantage

[13/04/2008|19:44:] C:\DOCUME~1\ALLUSE~1\DADOSD~1\<DIR> WLInstaller

 

[13/10/2007|12:38:] C:\DOCUME~1\DEFAUL~1\DADOSD~1\<DIR> Microsoft

 

[27/08/2008|14:54:] C:\DOCUME~1\LNSS_M~1\DADOSD~1\<DIR> Microsoft

 

[14/07/2009|22:28:] C:\DOCUME~1\LOCALS~1\DADOSD~1\<DIR> Adobe

[27/08/2008|14:54:] C:\DOCUME~1\LOCALS~1\DADOSD~1\<DIR> Microsoft

 

[27/08/2008|14:54:] C:\DOCUME~1\NETWOR~1\DADOSD~1\<DIR> Microsoft

 

[12/12/2009|12:37:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Adobe

[20/01/2009|20:18:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Ahead

[17/12/2009|02:10:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> BitTorrent

[15/07/2009|02:20:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> drivers

[05/05/2008|23:07:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Google

[05/11/2007|23:42:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Hamachi

[10/01/2008|22:25:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Help

[17/07/2008|21:08:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> HP

[24/07/2008|17:35:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> HPAppData

[13/10/2007|12:44:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Identities

[14/04/2009|11:41:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> m

[18/05/2008|21:15:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Macromedia

[30/01/2008|01:17:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Media Player Classic

[18/11/2009|13:26:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Microsoft

[26/12/2008|19:10:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Mozilla

[19/01/2008|15:14:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> NCH Swift Sound

[01/11/2007|14:39:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Nero

[10/06/2008|20:13:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> proDAD

[14/10/2007|03:13:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Publish Providers

[23/10/2009|10:54:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Real

[23/07/2009|12:40:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Samsung

[20/10/2009|11:12:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> SecondLife

[05/11/2008|14:32:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> SecuROM

[02/06/2008|00:39:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Sony

[14/10/2007|02:40:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Sony Setup

[27/09/2009|02:54:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> SpinTop

[14/07/2008|01:17:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Sun

[08/05/2008|19:51:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Talkback

[15/04/2009|00:34:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Vso

[14/10/2007|00:22:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> WinRAR

[24/01/2009|18:29:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> Yahoo!

[10/06/2008|21:04:] C:\DOCUME~1\RODRIG~1\DADOSD~1\<DIR> ZC Dream Photo

 

[19/03/2008|10:22:] C:\DOCUME~1\Users\DADOSD~1\<DIR> Adobe

 

--------------------\\ Tarefas Agendadas na pasta C:\WINDOWS\Tasks

 

[17/12/2009 12:49: Rodrigo][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1547161642-2147145749-1003UA.job

[16/12/2009 23:49: Rodrigo][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1547161642-2147145749-1003Core.job

[17/12/2009 10:35: Rodrigo][--ah-----] C:\WINDOWS\tasks\SA.DAT

[28/10/2001 17:07: Rodrigo][-r-h-----] C:\WINDOWS\tasks\desktop.ini

 

--------------------\\ Lista de pastas em C:\Arquivos de programas

 

[18/05/2008|00:27:] C:\Arquivos de programas\<DIR> Aavs 6cc for Vegas

[18/05/2008|00:28:] C:\Arquivos de programas\<DIR> Adam's Plug-ins for Sony Vegas

[01/01/2009|23:24:] C:\Arquivos de programas\<DIR> Adobe

[20/06/2008|23:06:] C:\Arquivos de programas\<DIR> Ahead

[23/08/2009|13:46:] C:\Arquivos de programas\<DIR> Alcohol Soft

[10/12/2009|10:09:] C:\Arquivos de programas\<DIR> Arquivos comuns

[18/04/2009|22:04:] C:\Arquivos de programas\<DIR> Avira

[23/07/2009|12:42:] C:\Arquivos de programas\<DIR> AviSynth 2.5

[24/01/2009|00:14:] C:\Arquivos de programas\<DIR> AvRack

[19/08/2009|01:12:] C:\Arquivos de programas\<DIR> BitTorrent

[14/01/2009|22:21:] C:\Arquivos de programas\<DIR> Combined Community Codec Pack

[16/04/2008|00:17:] C:\Arquivos de programas\<DIR> DebugMode

[24/11/2007|15:31:] C:\Arquivos de programas\<DIR> directx

[07/01/2009|09:25:] C:\Arquivos de programas\<DIR> Disney

[14/10/2007|00:49:] C:\Arquivos de programas\<DIR> DVD Shrink

[18/03/2009|20:36:] C:\Arquivos de programas\<DIR> DVDlabPro2

[20/08/2009|23:46:] C:\Arquivos de programas\<DIR> eMule

[05/07/2009|22:09:] C:\Arquivos de programas\<DIR> Foxit Software

[02/09/2009|12:53:] C:\Arquivos de programas\<DIR> Gabest

[14/04/2009|11:38:] C:\Arquivos de programas\<DIR> GbPlugin

[24/09/2009|21:41:] C:\Arquivos de programas\<DIR> Google

[17/07/2008|20:50:] C:\Arquivos de programas\<DIR> Hewlett-Packard

[17/12/2009|11:54:] C:\Arquivos de programas\<DIR> Hijack This

[17/07/2008|20:54:] C:\Arquivos de programas\<DIR> HP

[17/10/2007|17:19:] C:\Arquivos de programas\<DIR> InCode Solutions

[23/07/2009|12:40:] C:\Arquivos de programas\<DIR> InstallShield Installation Information

[13/10/2007|14:10:] C:\Arquivos de programas\<DIR> Intel

[10/12/2009|15:26:] C:\Arquivos de programas\<DIR> Internet Explorer

[09/09/2009|19:52:] C:\Arquivos de programas\<DIR> Java

[30/01/2008|01:16:] C:\Arquivos de programas\<DIR> K-Lite Codec Pack

[19/02/2008|23:26:] C:\Arquivos de programas\<DIR> Lavasoft

[24/01/2009|12:24:] C:\Arquivos de programas\<DIR> Messenger

[25/11/2009|22:58:] C:\Arquivos de programas\<DIR> Messenger Plus! Live

[17/11/2009|17:57:] C:\Arquivos de programas\<DIR> Microsoft

[26/04/2008|15:14:] C:\Arquivos de programas\<DIR> Microsoft CAPICOM 2.1.0.2

[13/10/2007|12:39:] C:\Arquivos de programas\<DIR> microsoft frontpage

[13/10/2007|13:46:] C:\Arquivos de programas\<DIR> Microsoft Office

[17/11/2009|17:56:] C:\Arquivos de programas\<DIR> Microsoft Office Outlook Connector

[18/11/2009|17:15:] C:\Arquivos de programas\<DIR> Microsoft Silverlight

[14/10/2007|03:09:] C:\Arquivos de programas\<DIR> Microsoft SQL Server

[17/11/2009|17:54:] C:\Arquivos de programas\<DIR> Microsoft SQL Server Compact Edition

[17/11/2009|17:55:] C:\Arquivos de programas\<DIR> Microsoft Sync Framework

[13/10/2007|13:45:] C:\Arquivos de programas\<DIR> Microsoft Visual Studio

[18/11/2009|23:34:] C:\Arquivos de programas\<DIR> Microsoft Works

[06/09/2008|14:42:] C:\Arquivos de programas\<DIR> Movie Maker

[17/12/2009|11:49:] C:\Arquivos de programas\<DIR> Mozilla Firefox

[18/04/2009|16:20:] C:\Arquivos de programas\<DIR> MSBuild

[15/08/2008|19:13:] C:\Arquivos de programas\<DIR> MSECache

[13/10/2007|12:35:] C:\Arquivos de programas\<DIR> MSN Gaming Zone

[02/11/2007|16:38:] C:\Arquivos de programas\<DIR> MSXML 4.0

[19/01/2008|15:14:] C:\Arquivos de programas\<DIR> NCH Swift Sound

[06/09/2008|14:37:] C:\Arquivos de programas\<DIR> NetMeeting

[30/11/2007|09:05:] C:\Arquivos de programas\<DIR> Oi Velox

[22/01/2008|14:04:] C:\Arquivos de programas\<DIR> Ontrack

[13/08/2009|01:19:] C:\Arquivos de programas\<DIR> Outlook Express

[23/07/2009|12:39:] C:\Arquivos de programas\<DIR> Panda Security

[13/10/2007|22:08:] C:\Arquivos de programas\<DIR> PC Camera

[10/06/2008|20:14:] C:\Arquivos de programas\<DIR> Picasa2

[27/09/2009|14:01:] C:\Arquivos de programas\<DIR> PopCap Games

[16/04/2008|00:18:] C:\Arquivos de programas\<DIR> Pure Motion

[04/02/2009|23:40:] C:\Arquivos de programas\<DIR> Rapid-USD NoCaptcha -Th3zone.com Sep2007

[24/01/2009|00:14:] C:\Arquivos de programas\<DIR> Realtek AC97

[13/10/2007|14:11:] C:\Arquivos de programas\<DIR> Realtek Sound Manager

[18/04/2009|16:20:] C:\Arquivos de programas\<DIR> Reference Assemblies

[30/06/2008|18:51:] C:\Arquivos de programas\<DIR> Scpad

[13/10/2007|12:37:] C:\Arquivos de programas\<DIR> Servi‡os on-line

[24/11/2007|15:19:] C:\Arquivos de programas\<DIR> Sierra On-Line

[23/02/2009|17:40:] C:\Arquivos de programas\<DIR> SlySoft

[27/05/2008|00:42:] C:\Arquivos de programas\<DIR> Sonic Foundry

[05/08/2008|02:37:] C:\Arquivos de programas\<DIR> Sony

[02/06/2008|00:31:] C:\Arquivos de programas\<DIR> Sony Setup

[24/01/2009|20:30:] C:\Arquivos de programas\<DIR> Spybot - Search & Destroy

[23/02/2009|17:41:] C:\Arquivos de programas\<DIR> THQ

[08/02/2008|17:53:] C:\Arquivos de programas\<DIR> UltraISO

[14/10/2007|03:09:] C:\Arquivos de programas\<DIR> Uninstall Information

[17/01/2009|20:55:] C:\Arquivos de programas\<DIR> VSO

[14/10/2007|03:05:] C:\Arquivos de programas\<DIR> Vstplugins

[13/05/2009|07:20:] C:\Arquivos de programas\<DIR> Webteh

[14/01/2009|20:32:] C:\Arquivos de programas\<DIR> WinAVI Video Converter

[17/11/2009|17:56:] C:\Arquivos de programas\<DIR> Windows Live

[17/11/2009|17:50:] C:\Arquivos de programas\<DIR> Windows Live SkyDrive

[13/10/2007|13:30:] C:\Arquivos de programas\<DIR> Windows Media Connect 2

[28/11/2009|11:19:] C:\Arquivos de programas\<DIR> Windows Media Player

[06/09/2008|14:37:] C:\Arquivos de programas\<DIR> Windows NT

[13/10/2007|12:37:] C:\Arquivos de programas\<DIR> WindowsUpdate

[13/10/2007|22:21:] C:\Arquivos de programas\<DIR> WinRAR

[13/10/2007|12:39:] C:\Arquivos de programas\<DIR> xerox

[25/06/2008|16:37:] C:\Arquivos de programas\<DIR> YouTube Downloader

 

--------------------\\ Lista de pastas em C:\Arquivos de programas\Arquivos comuns

 

[01/01/2009|23:24:] C:\Arquivos de programas\Arquivos comuns\<DIR> Adobe

[18/01/2007|15:36:] C:\Arquivos de programas\Arquivos comuns\<DIR> Ahead

[10/06/2008|01:48:] C:\Arquivos de programas\Arquivos comuns\<DIR> Bcgsoft

[13/10/2007|13:45:] C:\Arquivos de programas\Arquivos comuns\<DIR> DESIGNER

[01/03/2008|16:36:] C:\Arquivos de programas\Arquivos comuns\<DIR> DirectX

[08/02/2008|17:53:] C:\Arquivos de programas\Arquivos comuns\<DIR> EZB Systems

[21/04/2008|22:29:] C:\Arquivos de programas\Arquivos comuns\<DIR> Hewlett-Packard

[17/07/2008|20:50:] C:\Arquivos de programas\Arquivos comuns\<DIR> HP

[13/10/2007|22:08:] C:\Arquivos de programas\Arquivos comuns\<DIR> InstallShield

[12/07/2008|19:29:] C:\Arquivos de programas\Arquivos comuns\<DIR> Java

[18/11/2009|23:35:] C:\Arquivos de programas\Arquivos comuns\<DIR> Microsoft Shared

[13/10/2007|12:36:] C:\Arquivos de programas\Arquivos comuns\<DIR> MSSoap

[13/10/2007|09:29:] C:\Arquivos de programas\Arquivos comuns\<DIR> ODBC

[13/10/2007|22:08:] C:\Arquivos de programas\Arquivos comuns\<DIR> PCCamera

[23/10/2009|10:21:] C:\Arquivos de programas\Arquivos comuns\<DIR> Real

[13/10/2007|12:36:] C:\Arquivos de programas\Arquivos comuns\<DIR> Servi‡os

[13/10/2007|09:29:] C:\Arquivos de programas\Arquivos comuns\<DIR> SpeechEngines

[08/03/2009|11:39:] C:\Arquivos de programas\Arquivos comuns\<DIR> SWF Studio

[10/01/2009|19:39:] C:\Arquivos de programas\Arquivos comuns\<DIR> Symantec Shared

[17/11/2009|17:56:] C:\Arquivos de programas\Arquivos comuns\<DIR> System

[17/11/2009|17:34:] C:\Arquivos de programas\Arquivos comuns\<DIR> Windows Live

[13/04/2008|19:57:] C:\Arquivos de programas\Arquivos comuns\<DIR> WindowsLiveInstaller

[14/09/2009|19:52:] C:\Arquivos de programas\Arquivos comuns\<DIR> Wise Installation Wizard

[23/10/2009|10:20:] C:\Arquivos de programas\Arquivos comuns\<DIR> xing shared

 

--------------------\\ Process

 

( 44 Processes )

 

... OK !

 

--------------------\\ Procura pelo S_Lop

 

Não foram encontradas pastas com o Lop!

 

--------------------\\ Procura por Arquivos/Ficheiros e pastas do Lop

 

Não foram encontradas pastas com o Lop!

 

--------------------\\ Procura no Registro

 

..... OK !

 

--------------------\\ Verificando o Arquivos/Ficheiros Hosts

 

Arquivos/Ficheiros Hosts LIMPO

 

 

--------------------\\ Procurando Arquivos/Ficheiros ocultos com o Catchme

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-12-17 13:12:37

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden files ...

scan completed successfully

hidden processes: 0

hidden files: 11

 

--------------------\\ Procurando por outras infecções

 

--------------------\\ ROOTKIT !!

 

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA]

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SROSA]

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Enum\Root\LEGACY_SROSA]

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\srosa]

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\srosa]

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa]

 

--------------------\\ Cracks & Keygens ..

 

C:\DOCUME~1\RODRIG~1\Dados de aplicativos\BitTorrent\Bejeweled 2 + Crack [Full Version].rar.torrent

C:\DOCUME~1\RODRIG~1\Dados de aplicativos\BitTorrent\Call.Of.Duty.4.Modern.Warfare.(v1.5).Single.&.Multiplayer.Crack.Incl.KeyGen-XiNiTHAOUS.rar.torrent

C:\DOCUME~1\RODRIG~1\Meus documentos\Downloads\Bejeweled 2 + Crack [Full Version].rar

C:\DOCUME~1\RODRIG~1\Meus documentos\Downloads\Full Spectrum Warrior Ten Hammers\CRACKFIX

C:\DOCUME~1\RODRIG~1\Meus documentos\Downloads\Full Spectrum Warrior Ten Hammers\CRACKFIX\fsw2.exe

C:\DOCUME~1\RODRIG~1\Meus documentos\Downloads\PC-Full.Spectrum.Warrior.Ten.Hammers-DvD.Multi5-By.TXT\Crack

C:\DOCUME~1\RODRIG~1\Meus documentos\Downloads\PC-Full.Spectrum.Warrior.Ten.Hammers-DvD.Multi5-By.TXT\Crack\fsw2.exe

C:\DOCUME~1\RODRIG~1\Meus documentos\L.A.R. V¡deo Produ‡äes\M£sicas\CINEMA\nutcrack.mid

 

 

[F:321][D:23]-> C:\DOCUME~1\RODRIG~1\CONFIG~1\Temp

[F:52][D:0]-> C:\DOCUME~1\RODRIG~1\Cookies

[F:2408][D:16]-> C:\DOCUME~1\RODRIG~1\CONFIG~1\TEMPOR~1\content.IE5

 

1 - "C:\Lop SD\LopR_1.txt" - qui 17/12/2009|13:19 - Option : [2]

 

--------------------\\ Verificação completa em 13:19:37

 

Log do HijackThis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:23: Rodrigo, on 17/12/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

C:\WINDOWS\System32\PAStiSvc.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\hkcmd.exe

C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe

C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe

C:\WINDOWS\system32\igfxtray.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Hijack This\HijackThis.exe

C:\Arquivos de programas\Hijack This\HijackThis.exe

C:\Arquivos de programas\Hijack This\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 217.72.199.106:80

R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehuni.dll

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [eSnips] "C:\Arquivos de programas\eSnips\ClientGW.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [AXIS TONS THE MP3] C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons\SOAP PART.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [drvsyskit] C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\drivers\winupgro.exe

O4 - HKCU\..\Run: [mule_st_key] C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\m\flec006.exe

O4 - HKCU\..\Run: [NBJ] "C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\RunOnce: [shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103471 -"Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-BR; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2 (.NET CLR 3.5.30729)" -"http://www.cartoonnetworkla.com/folders/200803

/dexter.game.pt.labyrinth.432x330.zip2357934847000454/index.html"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User

'Default user')

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9}(SpinTop DRM Control) - file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/stg_drm.ocx

O16 - DPF: {31CB2F01-72C2-4CF4-B265-450E8817B039}(Toontown IE Helper Portuguese) - http://idownload.br.toontown.com/sv1.4.22.6/ttinst-portuguese.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}(MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab

O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3}(Image Uploader Control) - http://www.oifotos.com/custom/send3/ImageUploader5.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}(Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54}(ArmHelper Control) - file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/armhelper.ocx

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}(Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008}(GbPluginObj Class) - https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{27D4895C-B9D5-4547-BE37-98EB075148C3}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS4\Services\Tcpip\..\{27D4895C-B9D5-4547

BE37-98EB075148C3}:NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS5\Services\Tcpip\..\{27D4895C-B9D5-4547-BE37-98EB075148C3}: NameServer = 200.149.55.140 200.165.132.147

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O20 - Winlogon Notify: GbPluginUni - C:\ARQUIV~1\GbPlugin\gbiehuni.dll

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} -

C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Gbp Service (GbpSv) - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

 

--

End of file - 13566 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Rodrigo Rocha RJ

 

<@> Baixe: < EliBagla 13.31 >

<@> Salve-o no Desktop!

<@> Agora,vá ao seu ícone e,execute a ferramenta!

<@> Terminando,reinicie o computador e,à seguir,entre em Modo de Segurança. <-- Importante!

<@> Rode,novamente,o EliBagla.

<@> Poste o relatório: infoSAT.txt,que está na raíz C:\ ( Disco Local-C ),na sua resposta.

°°°°°°°°°°°°°°°°°°°°°°°°

°°°°°°°°°°°°°°°°°°°°°°°°

<@> Baixe: < otlDesktopIcon.png > ( ...by OldTimer Tools )

<@> Salve-o no desktop!

 

OTLI-scan.png

 

<@> Segundo a imagem,mude a opção em "Output" para "Minimal Output".

<@> Duplo-clique em OTL.exe --> Marque a opção "Scan All Users".

<@> Marque as caixas:

 

<!> [] LOP check e [] Purity check

 

<@> Clique em: < runscanbutton.png > --> Aguarde!

<@> Poste:

 

<1> OTL.txt <--

<2> Extra.txt <--

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Log do Eliblaga

 

HP AiO Application Launch Utility 1.0

 

ContextID: #Hewlett-Packard#hp psc 1310 series#1208825164

 

Data File: C:\Arquivos de programas\HP\digital imaging\data\hposid01.ini

 

Section: hp psc 1310 series

 

WindowsDirectory: C:\WINDOWS

 

Looking for: C:\WINDOWS\HPOins20.dat

Looking for: C:\WINDOWS\HPOins19.dat

Looking for: C:\WINDOWS\HPOins18.dat

Looking for: C:\WINDOWS\HPOins17.dat

Looking for: C:\WINDOWS\HPOins16.dat

Looking for: C:\WINDOWS\HPOins15.dat

Looking for: C:\WINDOWS\HPOins14.dat

Looking for: C:\WINDOWS\HPOins13.dat

Looking for: C:\WINDOWS\HPOins12.dat

Looking for: C:\WINDOWS\HPOins11.dat

Looking for: C:\WINDOWS\HPOins10.dat

Looking for: C:\WINDOWS\HPOins09.dat

Looking for: C:\WINDOWS\HPOins08.dat

Looking for: C:\WINDOWS\HPOins07.dat

Looking for: C:\WINDOWS\HPOins06.dat

Looking for: C:\WINDOWS\HPOins05.dat

Looking for: C:\WINDOWS\HPOins04.dat

szInstDat: C:\WINDOWS\HPOins04.dat

 

Getting Strings from:

C:\Arquivos de programas\HP\Digital Imaging\hp psc 1310 series\Data\Hpo1310.sid

Compartilhar este post


Link para o post
Compartilhar em outros sites

Log do OTL

 

OTL logfile created on: 17/12/2009 21:03:37 - Run 1

OTL by OldTimer - Version 3.1.17.0 Folder = C:\Documents and Settings\Rodrigo Rocha\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy

 

495,48 Mb Total Physical Memory | 62,95 Mb Available Physical Memory | 12,71% Memory free

1,13 Gb Paging File | 0,66 Gb Available in Paging File | 58,54% Paging File free

Paging file location(s): C:\pagefile.sys 744 1488 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas

Drive C: | 74,52 Gb Total Space | 18,41 Gb Free Space | 24,70% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: PC_DA_SALA

Current User Name: Rodrigo Rocha

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

PRC - C:\Arquivos de programas\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)

PRC - C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation)

PRC - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)

PRC - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe (Avira GmbH)

PRC - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)

PRC - C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

PRC - C:\Arquivos de programas\GbPlugin\gbpsv.exe ( )

PRC - C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

PRC - C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

PRC - C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)

PRC - C:\Arquivos de programas\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)

PRC - C:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)

PRC - C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

PRC - C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe (LightComm)

PRC - C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)

PRC - C:\WINDOWS\system32\PAStiSvc.exe ()

PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)

PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)

PRC - C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\umdmxfrm.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\serwvdrv.dll (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (JavaQuickStarterService) -- C:\Arquivos de programas\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)

SRV - (AntiVirService) -- C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)

SRV - (npggsvc) -- C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)

SRV - (AntiVirSchedulerService) -- C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe (Avira GmbH)

SRV - (SeaPort) -- C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)

SRV - (gusvc) -- C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)

SRV - (GbpSv) -- C:\Arquivos de programas\GbPlugin\gbpsv.exe ( )

SRV - (odserv) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)

SRV - (Microsoft Office Groove Audit Service) -- C:\Arquivos de programas\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)

SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)

SRV - (Net Driver HPZ12) -- C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)

SRV - (StarWindServiceAE) -- C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)

SRV - (hpqddsvc) -- C:\Arquivos de programas\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)

SRV - (hpqcxs08) -- C:\Arquivos de programas\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)

SRV - (ose) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)

SRV - (STI Simulator) -- C:\WINDOWS\system32\PAStiSvc.exe ()

 

 

========== Driver Services (SafeList) ==========

 

DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)

DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)

DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)

DRV - (GbpKm) -- C:\WINDOWS\system32\drivers\GbpKm.sys (GAS Tecnologia)

DRV - (avgio) -- C:\Arquivos de programas\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)

DRV - (pcouffin) -- C:\WINDOWS\system32\drivers\pcouffin.sys (VSO Software)

DRV - (StarOpen) -- C:\WINDOWS\system32\drivers\StarOpen.sys ()

DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()

DRV - (NCHSSVAD) -- C:\WINDOWS\system32\drivers\nchssvad.sys (NCH Swift Sound)

DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)

DRV - (ISODrive) -- C:\Arquivos de programas\UltraISO\drivers\ISODrive.sys (EZB Systems, Inc.)

DRV - (HPZius12) -- C:\WINDOWS\system32\drivers\HPZius12.sys (HP)

DRV - (HPZipr12) -- C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)

DRV - (HPZid412) -- C:\WINDOWS\system32\drivers\HPZid412.sys (HP)

DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\alcxwdm.sys (Realtek Semiconductor Corp.)

DRV - (PAC207) -- C:\WINDOWS\system32\drivers\PFC027.sys ()

DRV - (Egatebus) -- C:\WINDOWS\system32\drivers\egatebus.sys (axalto)

DRV - (Egaterdr) -- C:\WINDOWS\system32\drivers\egaterdr.sys (axalto)

DRV - (ialm) -- C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)

DRV - (ltmodem5) -- C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)

DRV - (NPF) -- C:\WINDOWS\system32\drivers\npf.sys (Politecnico di Torino)

DRV - (E100B) Intel® -- C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)

DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)

DRV - (MODEMCSA) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

 

 

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://br.msn.com/?ocid=iehp

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-br

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 76 BD 48 03 C8 6E CA 01 [binary data]

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = about:blank

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..\URLSearchHook: {982CB676-38F0-4D9A-BB72-D9371ABE876E} - Reg Error: Key error. File not found

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\S-1-5-21-725345543-1547161642-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\S-1-5-21-725345543-1547161642-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 217.72.199.106:80

 

========== FireFox ==========

 

FF - prefs.js..browser.search.defaultenginename: "Google"

FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - prefs.js..browser.startup.homepage: "www.orkut.com"

 

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox\components [2009/10/23 10:21:11 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox\plugins [2009/10/23 10:21:48 | 00,000,000 | ---D | M]

 

[2008/12/26 19:10:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Extensions

[2009/12/16 13:32:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\extensions

[2009/08/22 13:58:32 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E8873}

[2009/08/29 12:39:55 | 00,000,000 | ---D | M] (The Pirate Bay Toolbar) -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\extensions\{a33fa729-d155-4b23-842b-2c665ecabdb6}

[2009/08/19 17:32:44 | 00,000,373 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\searchplugins\ask.xml

[2009/07/16 15:02:38 | 00,000,890 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\searchplugins\conduit.xml

[2009/12/16 13:32:09 | 00,000,000 | ---D | M] -- C:\Arquivos de programas\Mozilla Firefox\extensions

[2008/05/05 21:39:37 | 00,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Arquivos de programas\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

[2008/06/30 23:02:00 | 00,663,072 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\Mozilla Firefox\plugins\npOGAPlugin.dll

[2008/03/24 21:21:00 | 02,889,088 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\plugins\NPSWF32.dll

[2009/08/19 17:31:36 | 00,001,027 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\buscape.xml

[2009/08/19 17:31:36 | 00,001,135 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\mercadolivre.xml

[2009/08/19 17:31:36 | 00,001,168 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\wikipedia-br.xml

[2009/08/19 17:31:36 | 00,000,648 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\yahoo-br.xml

 

O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.

O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)

O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)

O2 - BHO: (Facilitador de Leitor de Link Adobe PDF) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (ssh2 Class) - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll (Scopus Tecnologia Ltda)

O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)

O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\Arquivos de programas\GbPlugin\gbiehuni.dll (Banco Unibanco)

O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)

O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe File not found

O4 - HKLM..\Run: [AXIS TONS THE MP3] C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons\SOAP PART.exe File not found

O4 - HKLM..\Run: [ClientGW] File not found

O4 - HKLM..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe (LightComm)

O4 - HKLM..\Run: [eSnips] C:\Arquivos de programas\eSnips\ClientGW.exe File not found

O4 - HKLM..\Run: [GrooveMonitor] C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)

O4 - HKLM..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)

O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)

O4 - HKLM..\Run: [NBKeyScan] C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe File not found

O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)

O4 - HKLM..\Run: [PRONoMgr.exe] C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)

O4 - HKLM..\Run: [soundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [TkBellExe] C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMBgMonitor.exe File not found

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [german.exe] C:\WINDOWS\System32\wintems.exe File not found

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [NBJ] C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\RunOnce: [shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103471 -Mozilla\5.0 ( File not found

O4 - Startup: C:\Documents and Settings\Administrador\Menu Iniciar\Programas\Inicializar\Velox.lnk = File not found

O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

O4 - Startup: C:\Documents and Settings\Rodrigo Rocha\Menu Iniciar\Programas\Inicializar\Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de programas\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: Google Sidewiki... - C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)

O9 - Extra Button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)

O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)

O9 - Extra Button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Arquivos de programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe File not found

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe File not found

O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKU\.DEFAULT\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKU\S-1-5-18\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab (Office Genuine Advantage Validation Tool)

O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/stg_drm.ocx (SpinTop DRM Control)

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)

O16 - DPF: {31CB2F01-72C2-4CF4-B265-450E8817B039} http://idownload.br.toontown.com/sv1.4.22.6/ttinst-portuguese.cab (Toontown IE Helper Portuguese)

O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)

O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://www.oifotos.com/custom/send3/ImageUploader5.cab (Image Uploader Control)

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/armhelper.ocx (ArmHelper Control)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab (GbPluginObj Class)

O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Arquivos de programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\ GbPluginUni: DllName - C:\ARQUIV~1\GbPlugin\gbiehuni.dll - C:\Arquivos de programas\GbPlugin\gbiehuni.dll (Banco Unibanco)

O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll (Scopus Tecnologia Ltda)

O22 - SharedTaskScheduler: {A3717295-941D-416F-9384-ED1736729F1C} - scpLIB - C:\Arquivos de programas\Scpad\scpLIB.dll (Scopus Tecnologia Ltda)

O24 - Desktop Components:0 (Minha página inicial atual) - About:Home

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399008} - C:\Arquivos de programas\GbPlugin\gbiehuni.dll (Banco Unibanco)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2007/10/13 12:39:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\{279dfa8e-2210-11dd-a76c-000fead54043}\Shell\AutoRun\command - "" = i9bwjpqc.exe

O33 - MountPoints2\{279dfa8e-2210-11dd-a76c-000fead54043}\Shell\open\Command - "" = i9bwjpqc.exe

O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\AutoRun\command - "" = F:\ugyelo.exe -- File not found

O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\explore\Command - "" = F:\ugyelo.exe -- File not found

O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\open\Command - "" = F:\ugyelo.exe -- File not found

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] -- "%1" %*

O35 - exefile [open] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2009/12/17 21:01:40 | 00,538,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe

[2009/12/17 19:47:15 | 00,073,227 | ---- | C] (Satinfo SL.) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\EliBaglA.exe

[2009/12/17 13:00:29 | 00,000,000 | ---D | C] -- C:\Lop SD

[2009/12/17 11:49:31 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Hijack This

[2009/12/17 11:44:49 | 00,397,312 | ---- | C] (Defaults Twam) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\uninstall.exe

[2009/11/30 14:11:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Rodrigo Rocha\Desktop\30-11-2009

[2009/11/22 15:19:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Rodrigo Rocha\Meus documentos\Faculdade

[2009/11/18 17:19:18 | 00,000,000 | -HSD | C] -- C:\WINDOWS\ftpcache

[2009/07/14 22:28:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dados de aplicativos\Adobe

[2009/05/08 23:54:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft

[2009/04/01 18:35:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Google

[2009/03/28 11:05:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Google

[2008/09/06 15:02:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft

[2008/08/27 14:54:44 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Dados de aplicativos\Microsoft

[2008/08/27 14:54:44 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Dados de aplicativos\Microsoft

[2007/10/14 01:14:23 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.sys

 

========== Files - Modified Within 30 Days ==========

 

[2009/12/17 21:01:58 | 00,538,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe

[2009/12/17 20:51:36 | 00,001,176 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1547161642-2147145749-1003UA.job

[2009/12/17 20:48:35 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009/12/17 20:47:26 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009/12/17 20:47:19 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009/12/17 20:46:25 | 12,582,912 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\NTUSER.DAT

[2009/12/17 20:46:25 | 00,000,210 | -HS- | M] () -- C:\Documents and Settings\Rodrigo Rocha\ntuser.ini

[2009/12/17 19:47:15 | 00,073,227 | ---- | M] (Satinfo SL.) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\EliBaglA.exe

[2009/12/17 13:09:23 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2009/12/17 11:45:05 | 00,397,312 | ---- | M] (Defaults Twam) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\uninstall.exe

[2009/12/16 23:49:13 | 00,001,124 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1547161642-2147145749-1003Core.job

[2009/12/16 00:58:28 | 04,787,416 | -H-- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\IconCache.db

[2009/12/11 10:47:25 | 00,000,935 | ---- | M] () -- C:\WINDOWS\win.ini

[2009/12/10 15:29:15 | 00,581,130 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat

[2009/12/10 15:29:15 | 00,545,322 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2009/12/10 15:29:15 | 00,111,032 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat

[2009/12/10 15:29:15 | 00,099,094 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2009/12/10 15:29:14 | 01,355,578 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2009/12/10 14:29:42 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2009/12/10 09:39:53 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.jwr

[2009/12/09 20:07:04 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.uie

[2009/12/09 12:48:44 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.wxa

[2009/12/08 18:19:36 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.mof

[2009/12/08 17:41:20 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.mvo

[2009/12/08 12:00:09 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.gib

[2009/12/08 09:29:16 | 00,056,816 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys

[2009/11/30 18:35:51 | 00,052,224 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Desktop\Capítulo IV.doc

[2009/11/28 12:04:42 | 00,150,761 | ---- | M] () -- C:\WINDOWS\hpoins15.dat

[2009/11/19 15:36:33 | 00,073,208 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT

[2009/11/19 13:21:44 | 00,276,560 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

 

========== Files Created - No Company Name ==========

 

[2009/11/30 16:38:08 | 00,052,224 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Desktop\Capítulo IV.doc

[2009/08/03 16:07:42 | 00,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll

[2009/07/15 02:20:55 | 00,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI

[2009/02/02 23:16:22 | 00,000,040 | -HS- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\.zreglib

[2009/01/24 00:14:30 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini

[2009/01/17 20:57:30 | 00,000,671 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\vso_ts_preview.xml

[2008/10/18 16:45:52 | 00,000,029 | ---- | C] () -- C:\WINDOWS\RRK.INI

[2008/10/18 16:45:06 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI

[2008/07/29 14:42:08 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\LauncherAccess.dt

[2008/07/22 23:44:37 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\slbmgpg.dll

[2008/06/26 10:50:58 | 00,716,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2008/06/13 17:11:18 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll

[2008/06/07 15:35:30 | 00,000,192 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\momento_log.dat

[2008/05/30 20:54:00 | 00,001,661 | ---- | C] () -- C:\WINDOWS\vbxlrs.dll

[2008/05/30 20:54:00 | 00,001,661 | ---- | C] () -- C:\WINDOWS\MSVB7.dll

[2008/05/19 20:05:48 | 00,002,972 | ---- | C] () -- C:\WINDOWS\ACROREAD.INI

[2008/05/19 20:04:02 | 00,000,059 | ---- | C] () -- C:\WINDOWS\TLCAPPS.INI

[2008/05/14 20:20:26 | 00,081,920 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\ezpinst.exe

[2008/04/21 22:45:26 | 00,000,146 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\fusioncache.dat

[2008/04/21 21:15:55 | 00,008,683 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\hpzinstall.log

[2008/03/29 15:28:38 | 00,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys

[2008/03/16 19:00:43 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI

[2008/01/30 01:16:21 | 01,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2008/01/30 01:16:21 | 00,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2008/01/30 01:16:20 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll

[2008/01/30 01:16:17 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2008/01/30 01:16:17 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest

[2008/01/25 18:33:45 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll

[2008/01/19 15:16:26 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2008/01/15 22:16:01 | 00,000,305 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\addr_file.html

[2008/01/07 23:08:03 | 00,001,070 | ---- | C] () -- C:\WINDOWS\disney.ini

[2007/11/24 15:31:23 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll

[2007/11/24 15:31:01 | 00,000,009 | ---- | C] () -- C:\WINDOWS\sierra.ini

[2007/10/31 21:25:24 | 00,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini

[2007/10/31 20:07:47 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI

[2007/10/30 22:40:17 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll

[2007/10/14 02:26:35 | 00,125,440 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2007/10/14 01:14:31 | 00,000,034 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.log

[2007/10/14 01:14:23 | 00,087,608 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\inst.exe

[2007/10/14 01:14:23 | 00,007,887 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.cat

[2007/10/14 01:14:23 | 00,001,144 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.inf

[2007/10/13 14:11:11 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll

[2007/10/13 14:09:51 | 00,012,288 | R--- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

[2007/10/13 14:03:11 | 00,001,363 | ---- | C] () -- C:\WINDOWS\MEESP.INI

[2006/12/30 19:48:38 | 00,000,453 | ---- | C] () -- C:\WINDOWS\powermp3cutterjoiner.ini

[2005/09/29 16:42:56 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\linstall.dll

[2005/06/10 10:56:06 | 00,120,320 | ---- | C] () -- C:\WINDOWS\System32\UnzDll.dll

[2005/06/10 10:55:04 | 00,123,904 | ---- | C] () -- C:\WINDOWS\System32\ZipDll.dll

[2005/05/27 15:57:16 | 00,162,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\PFC027.sys

[2005/01/25 16:15:42 | 00,010,240 | R--- | C] () -- C:\WINDOWS\System32\PA207USD.DLL

[2004/05/13 20:14:58 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\opencrypto.dll

[2004/03/18 17:43:44 | 00,843,776 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll

[2003/08/07 15:01:52 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2003/02/03 18:12:00 | 00,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll

 

========== LOP Check ==========

 

[2008/08/27 14:54:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Avg7

[2008/02/15 21:15:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\ConeXware

[2009/04/14 17:21:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin

[2008/02/05 13:56:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus!

[2008/01/19 14:06:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\NCH Swift Sound

[2009/09/27 01:44:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\PopCap Games

[2009/02/02 23:16:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\SlySoft

[2007/10/14 03:09:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Sony

[2009/12/10 10:08:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP

[2007/12/27 01:10:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\vsosdk

[2009/12/17 19:27:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\BitTorrent

[2009/04/14 11:41:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\m

[2008/01/19 15:14:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\NCH Swift Sound

[2008/06/10 20:13:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\proDAD

[2007/10/14 03:13:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Publish Providers

[2009/07/23 12:40:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Samsung

[2009/10/20 11:12:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\SecondLife

[2008/06/02 00:39:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Sony

[2007/10/14 02:40:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Sony Setup

[2009/09/27 02:54:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\SpinTop

[2009/04/15 00:34:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Vso

[2008/06/10 21:04:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\ZC Dream Photo

 

========== Purity Check ==========

 

 

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 24 bytes -> C:\WINDOWS:FFAA131FD1EFF6A7

@Alternate Data Stream - 208 bytes -> C:\WINDOWS\System32\drivers:GbpKmAp.lst

@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:C7F04040

@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:A8ADE5D8

@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:DFC5A2B2

< End of report >

 

 

 

 

 

Extras

 

OTL Extras logfile created on: 17/12/2009 21:03:37 - Run 1

OTL by OldTimer - Version 3.1.17.0 Folder = C:\Documents and Settings\Rodrigo Rocha\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy

 

495,48 Mb Total Physical Memory | 62,95 Mb Available Physical Memory | 12,71% Memory free

1,13 Gb Paging File | 0,66 Gb Available in Paging File | 58,54% Paging File free

Paging file location(s): C:\pagefile.sys 744 1488 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas

Drive C: | 74,52 Gb Total Space | 18,41 Gb Free Space | 24,70% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: PC_DA_SALA

Current User Name: Rodrigo Rocha

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

 

[HKEY_USERS\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation)

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Arquivos de programas\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

htmlfile [opennew] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

htmlfile [print] -- "C:\Arquivos de programas\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)

http [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

https [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [OneNote.Open] -- C:\ARQUIV~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Applications\iexplore.exe [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Arquivos de programas\Internet Explorer\iexplore.exe" (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" = C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)

"C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe" = C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Arquivos de programas\eMule\emule.exe" = C:\Arquivos de programas\eMule\emule.exe:*:Enabled:eMule -- (http://www.emule-project.net)

"C:\Arquivos de programas\Anti Trojan\Anti Trojan\atrojans.exe" = C:\Arquivos de programas\Anti Trojan\Anti Trojan\atrojans.exe:*:Enabled:atrojans -- File not found

"C:\WINDOWS\system32\ftp.exe" = C:\WINDOWS\system32\ftp.exe:*:Enabled:Programa de transferência de arquivos -- (Microsoft Corporation)

"C:\Arquivos de programas\valhala\valhala.exe" = C:\Arquivos de programas\valhala\valhala.exe:*:Enabled:Valhala -- File not found

"C:\Arquivos de programas\Java\jre1.6.0_07\bin\javaw.exe" = C:\Arquivos de programas\Java\jre1.6.0_07\bin\javaw.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)

"C:\Arquivos de programas\MegaJogos\jre\jre\bin\javaw.exe" = C:\Arquivos de programas\MegaJogos\jre\jre\bin\javaw.exe:*:Enabled:Java Platform SE binary -- File not found

"C:\Arquivos de programas\SecondLife\SLVoice.exe" = C:\Arquivos de programas\SecondLife\SLVoice.exe:*:Enabled:SLVoice -- File not found

"C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Temp\Rar$EX02.937\Crack\PDFEdit.exe" = C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Temp\Rar$EX02.937\Crack\PDFEdit.exe:*:Enabled:Foxit PDF Editor, the first REAL editor for PDF files! -- File not found

"C:\Level Up! Games\Grand Chase Season 2\main.exe" = C:\Level Up! Games\Grand Chase Season 2\main.exe:*:Enabled:GrandChase -- File not found

"C:\Arquivos de programas\BitTorrent\bittorrent.exe" = C:\Arquivos de programas\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)

"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" = C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)

"C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe" = C:\Arquivos de programas\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{001E7FB6-BB6B-4ED0-BEDC-B5404ED96D4E}" = DocProc

"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

"{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}" = Sony Noise Reduction Plug-In 2.0h

"{0C405D1F-359E-41C5-A1A9-383A04BBD5E2}" = Windows Live Galeria de Fotos

"{0CBADDF4-2CF6-4CDB-B4F5-29B8FCA7FE07}" = Microsoft .NET Framework 1.1 Brazilian Portuguese Language Pack

"{10E1E87C-656C-4D08-86D6-5443D28583BE}" = TrayApp

"{13F00518-807A-4B3A-83B0-A7CD90F3A398}" = MarketResearch

"{1438B41C-658C-35B7-9253-780F2E0A0B8E}" = Microsoft .NET Framework 3.5 Language Pack SP1 - ptb

"{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live

"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{251C3815-7A55-4607-A82D-C3B98F0FBAB8}" = Sony Vegas 7.0

"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer

"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java 6 Update 15

"{29FA38B4-0AE4-4D0D-8A51-6165BB990BB0}" = WebReg

"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan

"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7

"{32BC546A-8AA3-4239-AE92-9CF3291C35A6}" = Windows Live Call

"{350C9416-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant

"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup

"{3F31F3B5-C1FF-3708-8611-869DE39C0CB6}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PTB

"{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing

"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply

"{49FC50FC-F965-40D9-89B4-CBFF80941PTB}" = Windows Movie Maker 2.0

"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack

"{51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}" = Assistente de Conexão do Windows Live

"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport

"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml

"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3

"{624DEAA0-B27D-444B-8BFE-70622B318A4A}" = Windows Live Toolbar

"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder

"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder

"{71A41426-C7A4-4DCF-A9ED-C5B4B105ED1D}" = Sony Media Manager 2.2

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

"{74AD1846-2010-4FB1-8E24-B6F2B87150C2}" = Windows Live Mail

"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.3.4.107

"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

"{819EE51B-9A62-42EE-A789-F5685C80C9BE}" = D-Link DSB-C120 PC Camera

"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01

"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01

"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver

"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)

"{90120000-0010-0416-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Portuguese (Brazil)) 12

"{90120000-0015-0416-0000-0000000FF1CE}" = Microsoft Office Access MUI (Portuguese (Brazil)) 2007

"{90120000-0015-0416-0000-0000000FF1CE}_ENTERPRISE_{02A880E2-B8B9-4BF5-8822-EA1374734E2E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0016-0416-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Portuguese (Brazil)) 2007

"{90120000-0016-0416-0000-0000000FF1CE}_ENTERPRISE_{02A880E2-B8B9-4BF5-8822-EA1374734E2E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0018-0416-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2007

"{90120000-0018-0416-0000-0000000FF1CE}_ENTERPRISE_{02A880E2-B8B9-4BF5-8822-EA1374734E2E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0019-0416-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Portuguese (Brazil)) 2007

"{90120000-0019-0416-0000-0000000FF1CE}_ENTERPRISE_{02A880E2-B8B9-4BF5-8822-EA1374734E2E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001A-0416-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Portuguese (Brazil)) 2007

"{90120000-001A-0416-0000-0000000FF1CE}_ENTERPRISE_{02A880E2-B8B9-4BF5-8822-EA1374734E2E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001B-0416-0000-0000000FF1CE}" = Microsoft Office Word MUI (Portuguese (Brazil)) 2007

"{90120000-001B-0416-0000-0000000FF1CE}_ENTERPRISE_{02A880E2-B8B9-4BF5-8822-EA1374734E2E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007

"{90120000-001F-0416-0000-0000000FF1CE}_ENTERPRISE_{75EBE365-7FC5-4720-A7D3-804BF550D1BC}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)

"{90120000-002C-0416-0000-0000000FF1CE}" = Microsoft Office Proofing (Portuguese (Brazil)) 2007

"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007

"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)

"{90120000-0044-0416-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2007

"{90120000-0044-0416-0000-0000000FF1CE}_ENTERPRISE_{02A880E2-B8B9-4BF5-8822-EA1374734E2E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-006E-0416-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Portuguese (Brazil)) 2007

"{90120000-006E-0416-0000-0000000FF1CE}_ENTERPRISE_{9A141B2B-7C5E-47D2-8E9E-9AC6018F3C42}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-00A1-0416-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Portuguese (Brazil)) 2007

"{90120000-00A1-0416-0000-0000000FF1CE}_ENTERPRISE_{02A880E2-B8B9-4BF5-8822-EA1374734E2E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-00B2-0416-0000-0000000FF1CE}" = Suplemento Microsoft Salvar como PDF ou XPS para programas do Microsoft Office 2007

"{90120000-00BA-0416-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Portuguese (Brazil)) 2007

"{90120000-00BA-0416-0000-0000000FF1CE}_ENTERPRISE_{02A880E2-B8B9-4BF5-8822-EA1374734E2E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{93F54611-2701-454e-94AB-623F458D9E6B}" = DeviceDiscovery

"{9509674F-3972-11DE-806D-005056806466}" = Google Earth

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{95120000-0122-0416-0000-0000000FF1CE}" = Microsoft Office Outlook Connector

"{9555B4ED-09A3-4722-8E8C-57A49401D059}" = Windows Live Writer

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9E2EE2F7-33BD-4D30-9E5D-8469A9F32009}" = Windows Live Sync

"{A036E231-5A03-4d63-94F6-7864CC77EC48}" = PS_AIO_ProductContext

"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI

"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2

"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet

"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder

"{AC76BA86-7AD7-1046-7B44-A81300000003}" = Adobe Reader 8.1.6 - Português

"{AEA07F97-9088-497c-8821-0F36BD5DC251}" = HPProductAssistant

"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan

"{B040FEFE-B45F-4e30-B3C6-035F53F544A9}" = c4200_Help

"{B1FA73D8-AB79-3A2E-81AC-DBBAC155B2FE}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PTB

"{B22C19AE-6A67-4f28-B541-5AE72FB17A25}" = HP Photosmart All-In-One Software 9.0

"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0

"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy

"{B5ED7AB0-3838-4389-8549-7C8E22DD48F4}" = Windows Live Messenger

"{B9F3A6E6-9C77-4535-9ED9-B16C1EBDFEC2}" = C4200

"{BCD6CD1A-0DBE-412E-9F25-3B500D1E6BA1}" = SolutionCenter

"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component

"{D719E8F1-6931-40b4-AC0B-5FE2C097F995}" = C4200_doccd

"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)

"{E2662C24-B31E-4349-A084-32EB76E8B760}" = BufferChm

"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update

"{E39A3770-3DDE-404c-B91F-3522947874A3}" = PS_AIO_Software_min

"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox

"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform

"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS

"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard

"{F2CD4651-F948-467C-B014-71FD981B7F59}" = Windows Live Essentials

"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE

"{FA4FA322-5C90-4d2b-A019-9E588273DED5}" = PS_AIO_Software

"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio

"{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status

"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update

"Adam's Flip Plug-in for Sony Vegas" = Adam's Flip Plug-in for Sony Vegas

"Adobe Acrobat Reader 3.01" = Adobe Acrobat Reader 3.01

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Shockwave Player" = Adobe Shockwave Player 11

"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus

"Bejeweled Twist 1.0" = Bejeweled Twist 1.0

"BSPlayer1" = BSPlayer

"Coelho Sabido Pré" = Coelho Sabido Pré

"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2008-09-21 16:18

"Conexão Oi Velox_is1" = LightDialer 3.0

"DebugMode Wax 2.0" = DebugMode Wax 2.0

"DVD Shrink_is1" = DVD Shrink 3.2

"DVD-lab PRO 2.2_is1" = DVD-lab PRO 2.2

"eMule" = eMule

"ENTERPRISE" = Microsoft Office Enterprise 2007

"HijackThis" = HijackThis 2.0.2

"HP Imaging Device Functions" = HP Imaging Device Functions 9.0

"HP Photosmart Essential" = HP Photosmart Essential 2.01

"HP Solution Center & Imaging Support Tools" = HP Solution Center 9.0

"HPExtendedCapabilities" = HP Customer Participation Program 9.0

"HPOCR" = HP OCR Software 9.0

"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs

"ie7" = Windows Internet Explorer 7

"ie8" = Windows Internet Explorer 8

"InstallShield_{819EE51B-9A62-42EE-A789-F5685C80C9BE}" = D-Link DSB-C120 PC Camera

"KLiteCodecPack_is1" = K-Lite Codec Pack 3.7.0 Full

"MEPOR" = DIC Michaelis Escolar - Espanhol

"Messenger Plus! Live" = Messenger Plus! Live & Sponsor (CiD)

"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1

"Microsoft .NET Framework 3.5 Language Pack SP1 - ptb" = Pacote de Idiomas do Microsoft .NET Framework 3.5 SP1 - PTB

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"Mozilla Firefox (3.5.2)" = Mozilla Firefox (3.5.2)

"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP

"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition

"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs

"Oi Velox Check Up_is1" = Oi Velox Check Up 1.0

"PluginPac" = DebugMode PluginPac (remove only)

"Programador de Modem_is1" = LightModem 3.0

"PROSet" = Intel® PRO Network Adapters and Drivers

"RealPlayer 12.0" = RealPlayer

"UltraISO_is1" = UltraISO Premium V8.63

"Uploader" = Uploader

"WinAVI Video Converter_is1" = WinAVI Video Converter

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"Windows Media Player" = Windows Media Player 11

"Windows XP Service Pack" = Windows XP Service Pack 3

"WinLiveSuite_Wave3" = Windows Live Essentials

"WinRAR archiver" = Arquivo do WinRAR

"WMFDist11" = Windows Media Format 11 runtime

"wmp11" = Windows Media Player 11

"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

 

========== HKEY_USERS Uninstall List ==========

 

[HKEY_USERS\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"BitTorrent" = BitTorrent

 

========== Last 10 Event Log Errors ==========

 

[ Application Events ]

Error - 16/12/2009 13:26:34 | Computer Name = PC_DA_SALA | Source = Application Hang | ID = 1002

Description = Aplicativo com falha firefox.exe, versão 1.9.1.3497, módulo com falha

hungapp, versão 0.0.0.0, endereço com falha 0x00000000.

 

Error - 17/12/2009 00:22:43 | Computer Name = PC_DA_SALA | Source = Application Hang | ID = 1002

Description = Aplicativo com falha firefox.exe, versão 1.9.1.3497, módulo com falha

hungapp, versão 0.0.0.0, endereço com falha 0x00000000.

 

Error - 17/12/2009 00:23:20 | Computer Name = PC_DA_SALA | Source = UserInit | ID = 1000

Description = Não foi possível executar o script C:\Documents and Settings\Rodrigo

Rocha\Desktop\ntosboot.bat. O sistema não pode encontrar o arquivo especificado.

.

 

Error - 17/12/2009 08:08:06 | Computer Name = PC_DA_SALA | Source = crypt32 | ID = 131080

Description = Falha na recuperação de atualização automática do número de seqüência

de lista raiz de terceiros de: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>

com erro: Esta operação foi retornada porque o tempo limite expirou.

 

Error - 17/12/2009 08:36:15 | Computer Name = PC_DA_SALA | Source = crypt32 | ID = 131080

Description = Falha na recuperação de atualização automática do número de seqüência

de lista raiz de terceiros de: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>

com erro: Esta operação foi retornada porque o tempo limite expirou.

 

Error - 17/12/2009 10:05:27 | Computer Name = PC_DA_SALA | Source = Application Hang | ID = 1002

Description = Aplicativo com falha HijackThis.exe, versão 2.0.0.2, módulo com falha

hungapp, versão 0.0.0.0, endereço com falha 0x00000000.

 

Error - 17/12/2009 18:13:06 | Computer Name = PC_DA_SALA | Source = UserInit | ID = 1000

Description = Não foi possível executar o script C:\Documents and Settings\Rodrigo

Rocha\Desktop\ntosboot.bat. O sistema não pode encontrar o arquivo especificado.

.

 

Error - 17/12/2009 18:18:37 | Computer Name = PC_DA_SALA | Source = Application Error | ID = 1000

Description = Aplicativo com falha discador.exe, versão 3.0.0.0, módulo com falha

msvbvm50.dll, versão 5.2.82.44, endereço com falha 0x00013957.

 

Error - 17/12/2009 18:22:23 | Computer Name = PC_DA_SALA | Source = crypt32 | ID = 131080

Description = Falha na recuperação de atualização automática do número de seqüência

de lista raiz de terceiros de: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>

com erro: Esta operação foi retornada porque o tempo limite expirou.

 

Error - 17/12/2009 18:48:07 | Computer Name = PC_DA_SALA | Source = crypt32 | ID = 131080

Description = Falha na recuperação de atualização automática do número de seqüência

de lista raiz de terceiros de: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>

com erro: Esta operação foi retornada porque o tempo limite expirou.

 

[ OSession Events ]

Error - 16/8/2008 02:24:14 | Computer Name = PC_DA_SALA | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application

Version: 12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session

lasted 844 seconds with 840 seconds of active time. This session ended with a crash.

 

Error - 12/11/2008 22:09:46 | Computer Name = PC_DA_SALA | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 0, Application Name: Microsoft Office Word, Application Version:

12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 142

seconds with 60 seconds of active time. This session ended with a crash.

 

Error - 12/11/2008 22:11:33 | Computer Name = PC_DA_SALA | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 0, Application Name: Microsoft Office Word, Application Version:

12.0.6308.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 19

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 12/12/2008 12:47:47 | Computer Name = PC_DA_SALA | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 0, Application Name: Microsoft Office Word, Application Version:

12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 15

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 14/4/2009 11:26:04 | Computer Name = PC_DA_SALA | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application

Version: 12.0.6300.5000, Microsoft Office Version: 12.0.6215.1000. This session

lasted 4205 seconds with 360 seconds of active time. This session ended with a

crash.

 

Error - 5/8/2009 16:18:41 | Computer Name = PC_DA_SALA | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:

12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 21

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 5/8/2009 16:20:33 | Computer Name = PC_DA_SALA | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:

12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 25

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 5/8/2009 16:20:45 | Computer Name = PC_DA_SALA | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:

12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 5/8/2009 16:20:52 | Computer Name = PC_DA_SALA | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:

12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 4

seconds with 0 seconds of active time. This session ended with a crash.

 

Error - 29/11/2009 12:44:58 | Computer Name = PC_DA_SALA | Source = Microsoft Office 12 Sessions | ID = 7001

Description = ID: 0, Application Name: Microsoft Office Word, Application Version:

12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 25

seconds with 0 seconds of active time. This session ended with a crash.

 

[ System Events ]

Error - 17/12/2009 18:26:00 | Computer Name = PC_DA_SALA | Source = sr | ID = 1

Description = O filtro da restauração do sistema encontrou o erro inesperado '0xC0000001'

ao processar o arquivo '' no volume 'HarddiskVolume1'. O monitoramento do volume

foi interrompido.

 

Error - 17/12/2009 18:26:55 | Computer Name = PC_DA_SALA | Source = Service Control Manager | ID = 7001

Description = O serviço Cliente DHCP depende do serviço NetBios em Tcpip, mas não

foi possível iniciá-lo devido ao seguinte erro: %%31

 

Error - 17/12/2009 18:26:55 | Computer Name = PC_DA_SALA | Source = Service Control Manager | ID = 7001

Description = O serviço Cliente DNS depende do serviço Driver de protocolo TCP/IP,

mas não foi possível iniciá-lo devido ao seguinte erro: %%31

 

Error - 17/12/2009 18:26:55 | Computer Name = PC_DA_SALA | Source = Service Control Manager | ID = 7001

Description = O serviço Auxiliar NetBIOS TCP/IP depende do serviço AFD, mas não

foi possível iniciá-lo devido ao seguinte erro: %%31

 

Error - 17/12/2009 18:26:55 | Computer Name = PC_DA_SALA | Source = Service Control Manager | ID = 7001

Description = O serviço Serviços IPSEC depende do serviço Driver IPSEC, mas não

foi possível iniciá-lo devido ao seguinte erro: %%31

 

Error - 17/12/2009 18:26:55 | Computer Name = PC_DA_SALA | Source = Service Control Manager | ID = 7026

Description = Falha ao carregar o(s) seguinte(s) driver(s) de início do sistema

ou de inicialização: AFD avgio avipbb Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss

ssmdrv

StarOpen

Tcpip

 

Error - 17/12/2009 18:27:38 | Computer Name = PC_DA_SALA | Source = DCOM | ID = 10005

Description = Erro "%1084" no DCOM na tentativa de iniciar o serviço EventSystem

com argumentos "" para iniciar o servidor: {1BE1F766-5536-11D1-B726-00C04FB926AF}

 

Error - 17/12/2009 18:27:52 | Computer Name = PC_DA_SALA | Source = DCOM | ID = 10005

Description = Erro "%1084" no DCOM na tentativa de iniciar o serviço netman com

argumentos "" para iniciar o servidor: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

 

Error - 17/12/2009 18:46:23 | Computer Name = PC_DA_SALA | Source = DCOM | ID = 10005

Description = Erro "%1084" no DCOM na tentativa de iniciar o serviço EventSystem

com argumentos "" para iniciar o servidor: {1BE1F766-5536-11D1-B726-00C04FB926AF}

 

Error - 17/12/2009 18:47:31 | Computer Name = PC_DA_SALA | Source = sr | ID = 1

Description = O filtro da restauração do sistema encontrou o erro inesperado '0xC0000001'

ao processar o arquivo '' no volume 'HarddiskVolume1'. O monitoramento do volume

foi interrompido.

 

 

< End of report >

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Rodrigo Rocha RJ

 

<@> Abra o Spybot Search & Destroy!

<@> No menu superior,vá em Modo e selecione a opção Avançado. --> Confirme!

<@> Clique no botão Ferramentas e depois em Residente.

<@> Desmarque a opção: Ativar "TeaTimer" do Residente. ( Proteção geral das configurações de sistema )

°°°°°°°°°°°°°°°°°°°°°

°°°°°°°°°°°°°°°°°°°°°

<@> Execute o OTL.exe.

<@> Copie estas informações que estão no Quote,para o campo clipboard da ferramenta. ( Custom Scans/Fixes )

 

:Reg

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SROSA]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Enum\Root\LEGACY_SROSA]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\srosa]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\srosa]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa]

:Files

C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons\SOAP PART.exe

C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons

@C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:C7F04040

@C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:A8ADE5D8

@C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:DFC5A2B2

C:\WINDOWS\System32\wintems.exe

@C:\WINDOWS:FFAA131FD1EFF6A7

F:\ugyelo.exe

:OTL

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.

O4 - HKLM..\Run: [AXIS TONS THE MP3] C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons\SOAP PART.exe File not found

O4 - HKLM..\Run: [ClientGW] File not found

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [german.exe] C:\WINDOWS\System32\wintems.exe File not found

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\RunOnce: [shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103471 -Mozilla\5.0 ( File not found

O4 - Startup: C:\Documents and Settings\Administrador\Menu Iniciar\Programas\Inicializar\Velox.lnk = File not found

O33 - MountPoints2\{279dfa8e-2210-11dd-a76c-000fead54043}\Shell\AutoRun\command - "" = i9bwjpqc.exe

O33 - MountPoints2\{279dfa8e-2210-11dd-a76c-000fead54043}\Shell\open\Command - "" = i9bwjpqc.exe

O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\AutoRun\command - "" = F:\ugyelo.exe -- File not found

O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\explore\Command - "" = F:\ugyelo.exe -- File not found

O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\open\Command - "" = F:\ugyelo.exe -- File not found

:Services

srosa

:Commands

[purity]

[emptytemp]

[Reboot]

<@> Clique no botão Run Fix --> Aguarde a conclusão!

<@> Terminando,vá até a pasta: C:\_OTL\MovedFiles\*.log <-- Poste!

<@> Poste,também,HijackThis atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite,

 

Estou muito agradecido pela sua ajuda mas o que está acontecendo com a minha máquina?

<><><><><><><><><>

Bom Dia! Rodrigo Rocha RJ

 

<!> Infecções por Lops e traços de rootkit,baixado pelo Bagle.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Log do OTL

 

 

OTL logfile created on: 18/12/2009 10:48:42 - Run 2

OTL by OldTimer - Version 3.1.17.0 Folder = C:\Documents and Settings\Rodrigo Rocha\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

 

 

 

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy

 

495,48 Mb Total Physical Memory | 255,44 Mb Available Physical Memory | 51,55% Memory free

1,13 Gb Paging File | 0,77 Gb Available in Paging File | 67,95% Paging File free

Paging file location(s): C:\pagefile.sys 744 1488 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas

Drive C: | 74,52 Gb Total Space | 18,41 Gb Free Space | 24,70% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: PC_DA_SALA

Current User Name: Rodrigo Rocha

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

 

========== Processes (SafeList) ==========

 

PRC - C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

PRC - C:\Arquivos de programas\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)

PRC - C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation)

PRC - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)

PRC - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe (Avira GmbH)

PRC - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)

PRC - C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

PRC - C:\Arquivos de programas\GbPlugin\gbpsv.exe ( )

PRC - C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

PRC - C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)

PRC - C:\Arquivos de programas\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)

PRC - C:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)

PRC - C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

PRC - C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe (LightComm)

PRC - C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)

PRC - C:\WINDOWS\system32\PAStiSvc.exe ()

PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)

PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)

PRC - C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\umdmxfrm.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\serwvdrv.dll (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (JavaQuickStarterService) -- C:\Arquivos de programas\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)

SRV - (AntiVirService) -- C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)

SRV - (npggsvc) -- C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)

SRV - (AntiVirSchedulerService) -- C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe (Avira GmbH)

SRV - (SeaPort) -- C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)

SRV - (gusvc) -- C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)

SRV - (GbpSv) -- C:\Arquivos de programas\GbPlugin\gbpsv.exe ( )

SRV - (odserv) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)

SRV - (Microsoft Office Groove Audit Service) -- C:\Arquivos de programas\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)

SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)

SRV - (Net Driver HPZ12) -- C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)

SRV - (StarWindServiceAE) -- C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)

SRV - (hpqddsvc) -- C:\Arquivos de programas\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)

SRV - (hpqcxs08) -- C:\Arquivos de programas\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)

SRV - (ose) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)

SRV - (STI Simulator) -- C:\WINDOWS\system32\PAStiSvc.exe ()

 

 

========== Driver Services (SafeList) ==========

 

DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)

DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)

DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)

DRV - (GbpKm) -- C:\WINDOWS\system32\drivers\GbpKm.sys (GAS Tecnologia)

DRV - (avgio) -- C:\Arquivos de programas\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)

DRV - (pcouffin) -- C:\WINDOWS\system32\drivers\pcouffin.sys (VSO Software)

DRV - (StarOpen) -- C:\WINDOWS\system32\drivers\StarOpen.sys ()

DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()

DRV - (NCHSSVAD) -- C:\WINDOWS\system32\drivers\nchssvad.sys (NCH Swift Sound)

DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)

DRV - (ISODrive) -- C:\Arquivos de programas\UltraISO\drivers\ISODrive.sys (EZB Systems, Inc.)

DRV - (HPZius12) -- C:\WINDOWS\system32\drivers\HPZius12.sys (HP)

DRV - (HPZipr12) -- C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)

DRV - (HPZid412) -- C:\WINDOWS\system32\drivers\HPZid412.sys (HP)

DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\alcxwdm.sys (Realtek Semiconductor Corp.)

DRV - (PAC207) -- C:\WINDOWS\system32\drivers\PFC027.sys ()

DRV - (Egatebus) -- C:\WINDOWS\system32\drivers\egatebus.sys (axalto)

DRV - (Egaterdr) -- C:\WINDOWS\system32\drivers\egaterdr.sys (axalto)

DRV - (ialm) -- C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)

DRV - (ltmodem5) -- C:\WINDOWS\system32\drivers\ltmdmnt.sys (LT)

DRV - (NPF) -- C:\WINDOWS\system32\drivers\npf.sys (Politecnico di Torino)

DRV - (E100B) Intel® -- C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)

DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)

DRV - (MODEMCSA) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

 

 

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://br.msn.com/?ocid=iehp

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-br

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 76 BD 48 03 C8 6E CA 01 [binary data]

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = about:blank

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..\URLSearchHook: {982CB676-38F0-4D9A-BB72-D9371ABE876E} - Reg Error: Key error. File not found

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\S-1-5-21-725345543-1547161642-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\S-1-5-21-725345543-1547161642-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 217.72.199.106:80

 

========== FireFox ==========

 

FF - prefs.js..browser.search.defaultenginename: "Google"

FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - prefs.js..browser.startup.homepage: "www.orkut.com"

 

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox\components [2009/10/23 10:21:11 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox\plugins [2009/10/23 10:21:48 | 00,000,000 | ---D | M]

 

[2008/12/26 19:10:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Extensions

[2009/12/16 13:32:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\extensions

[2009/08/22 13:58:32 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E8873}

[2009/08/29 12:39:55 | 00,000,000 | ---D | M] (The Pirate Bay Toolbar) -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\extensions\{a33fa729-d155-4b23-842b-2c665ecabdb6}

[2009/08/19 17:32:44 | 00,000,373 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\searchplugins\ask.xml

[2009/07/16 15:02:38 | 00,000,890 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\searchplugins\conduit.xml

[2009/12/16 13:32:09 | 00,000,000 | ---D | M] -- C:\Arquivos de programas\Mozilla Firefox\extensions

[2008/05/05 21:39:37 | 00,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Arquivos de programas\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

[2008/06/30 23:02:00 | 00,663,072 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\Mozilla Firefox\plugins\npOGAPlugin.dll

[2008/03/24 21:21:00 | 02,889,088 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\plugins\NPSWF32.dll

[2009/08/19 17:31:36 | 00,001,027 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\buscape.xml

[2009/08/19 17:31:36 | 00,001,135 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\mercadolivre.xml

[2009/08/19 17:31:36 | 00,001,168 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\wikipedia-br.xml

[2009/08/19 17:31:36 | 00,000,648 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\yahoo-br.xml

 

O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.

O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)

O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)

O2 - BHO: (Facilitador de Leitor de Link Adobe PDF) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (ssh2 Class) - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll (Scopus Tecnologia Ltda)

O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)

O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\Arquivos de programas\GbPlugin\gbiehuni.dll (Banco Unibanco)

O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)

O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe File not found

O4 - HKLM..\Run: [AXIS TONS THE MP3] C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons\SOAP PART.exe File not found

O4 - HKLM..\Run: [ClientGW] File not found

O4 - HKLM..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe (LightComm)

O4 - HKLM..\Run: [eSnips] C:\Arquivos de programas\eSnips\ClientGW.exe File not found

O4 - HKLM..\Run: [GrooveMonitor] C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)

O4 - HKLM..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)

O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)

O4 - HKLM..\Run: [NBKeyScan] C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe File not found

O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)

O4 - HKLM..\Run: [PRONoMgr.exe] C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)

O4 - HKLM..\Run: [soundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [TkBellExe] C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMBgMonitor.exe File not found

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [german.exe] C:\WINDOWS\System32\wintems.exe File not found

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [NBJ] C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\RunOnce: [shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103471 -Mozilla\5.0 ( File not found

O4 - Startup: C:\Documents and Settings\Administrador\Menu Iniciar\Programas\Inicializar\Velox.lnk = File not found

O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

O4 - Startup: C:\Documents and Settings\Rodrigo Rocha\Menu Iniciar\Programas\Inicializar\Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de programas\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: Google Sidewiki... - C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)

O9 - Extra Button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)

O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)

O9 - Extra Button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Arquivos de programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe File not found

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe File not found

O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKU\.DEFAULT\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKU\S-1-5-18\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab (Office Genuine Advantage Validation Tool)

O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/stg_drm.ocx (SpinTop DRM Control)

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)

O16 - DPF: {31CB2F01-72C2-4CF4-B265-450E8817B039} http://idownload.br.toontown.com/sv1.4.22.6/ttinst-portuguese.cab (Toontown IE Helper Portuguese)

O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)

O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://www.oifotos.com/custom/send3/ImageUploader5.cab (Image Uploader Control)

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/armhelper.ocx (ArmHelper Control)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab (GbPluginObj Class)

O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Arquivos de programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\ GbPluginUni: DllName - C:\ARQUIV~1\GbPlugin\gbiehuni.dll - C:\Arquivos de programas\GbPlugin\gbiehuni.dll (Banco Unibanco)

O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll (Scopus Tecnologia Ltda)

O22 - SharedTaskScheduler: {A3717295-941D-416F-9384-ED1736729F1C} - scpLIB - C:\Arquivos de programas\Scpad\scpLIB.dll (Scopus Tecnologia Ltda)

O24 - Desktop Components:0 (Minha página inicial atual) - About:Home

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399008} - C:\Arquivos de programas\GbPlugin\gbiehuni.dll (Banco Unibanco)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2007/10/13 12:39:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\{279dfa8e-2210-11dd-a76c-000fead54043}\Shell\AutoRun\command - "" = i9bwjpqc.exe

O33 - MountPoints2\{279dfa8e-2210-11dd-a76c-000fead54043}\Shell\open\Command - "" = i9bwjpqc.exe

O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\AutoRun\command - "" = F:\ugyelo.exe -- File not found

O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\explore\Command - "" = F:\ugyelo.exe -- File not found

O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\open\Command - "" = F:\ugyelo.exe -- File not found

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] -- "%1" %*

O35 - exefile [open] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2009/12/17 22:32:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Rodrigo Rocha\Desktop\Ben 10

[2009/12/17 21:01:40 | 00,538,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe

[2009/12/17 19:47:15 | 00,073,227 | ---- | C] (Satinfo SL.) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\EliBaglA.exe

[2009/12/17 13:00:29 | 00,000,000 | ---D | C] -- C:\Lop SD

[2009/12/17 11:49:31 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Hijack This

[2009/12/17 11:44:49 | 00,397,312 | ---- | C] (Defaults Twam) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\uninstall.exe

[2009/11/30 14:11:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Rodrigo Rocha\Desktop\30-11-2009

[2009/11/22 15:19:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Rodrigo Rocha\Meus documentos\Faculdade

[2009/11/18 17:19:18 | 00,000,000 | -HSD | C] -- C:\WINDOWS\ftpcache

[2009/07/14 22:28:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dados de aplicativos\Adobe

[2009/05/08 23:54:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft

[2009/04/01 18:35:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Google

[2009/03/28 11:05:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Google

[2008/09/06 15:02:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft

[2008/08/27 14:54:44 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Dados de aplicativos\Microsoft

[2008/08/27 14:54:44 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Dados de aplicativos\Microsoft

[2007/10/14 01:14:23 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.sys

 

========== Files - Modified Within 30 Days ==========

 

[2009/12/18 10:49:11 | 00,001,176 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1547161642-2147145749-1003UA.job

[2009/12/18 10:16:56 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009/12/18 10:13:09 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009/12/18 10:12:55 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009/12/18 01:55:51 | 12,582,912 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\NTUSER.DAT

[2009/12/18 01:55:51 | 00,000,210 | -HS- | M] () -- C:\Documents and Settings\Rodrigo Rocha\ntuser.ini

[2009/12/17 23:49:01 | 00,001,124 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1547161642-2147145749-1003Core.job

[2009/12/17 21:01:58 | 00,538,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe

[2009/12/17 19:47:15 | 00,073,227 | ---- | M] (Satinfo SL.) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\EliBaglA.exe

[2009/12/17 13:09:23 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2009/12/17 11:45:05 | 00,397,312 | ---- | M] (Defaults Twam) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\uninstall.exe

[2009/12/16 00:58:28 | 04,787,416 | -H-- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\IconCache.db

[2009/12/11 10:47:25 | 00,000,935 | ---- | M] () -- C:\WINDOWS\win.ini

[2009/12/10 15:29:15 | 00,581,130 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat

[2009/12/10 15:29:15 | 00,545,322 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2009/12/10 15:29:15 | 00,111,032 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat

[2009/12/10 15:29:15 | 00,099,094 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2009/12/10 15:29:14 | 01,355,578 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2009/12/10 14:29:42 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2009/12/10 09:39:53 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.jwr

[2009/12/09 20:07:04 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.uie

[2009/12/09 12:48:44 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.wxa

[2009/12/08 18:19:36 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.mof

[2009/12/08 17:41:20 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.mvo

[2009/12/08 12:00:09 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.gib

[2009/12/08 09:29:16 | 00,056,816 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys

[2009/11/30 18:35:51 | 00,052,224 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Desktop\Capítulo IV.doc

[2009/11/28 12:04:42 | 00,150,761 | ---- | M] () -- C:\WINDOWS\hpoins15.dat

[2009/11/19 15:36:33 | 00,073,208 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT

[2009/11/19 13:21:44 | 00,276,560 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

 

========== Files Created - No Company Name ==========

 

[2009/11/30 16:38:08 | 00,052,224 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Desktop\Capítulo IV.doc

[2009/08/03 16:07:42 | 00,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll

[2009/07/15 02:20:55 | 00,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI

[2009/02/02 23:16:22 | 00,000,040 | -HS- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\.zreglib

[2009/01/24 00:14:30 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini

[2009/01/17 20:57:30 | 00,000,671 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\vso_ts_preview.xml

[2008/10/18 16:45:52 | 00,000,029 | ---- | C] () -- C:\WINDOWS\RRK.INI

[2008/10/18 16:45:06 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI

[2008/07/29 14:42:08 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\LauncherAccess.dt

[2008/07/22 23:44:37 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\slbmgpg.dll

[2008/06/26 10:50:58 | 00,716,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2008/06/13 17:11:18 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll

[2008/06/07 15:35:30 | 00,000,192 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\momento_log.dat

[2008/05/30 20:54:00 | 00,001,661 | ---- | C] () -- C:\WINDOWS\vbxlrs.dll

[2008/05/30 20:54:00 | 00,001,661 | ---- | C] () -- C:\WINDOWS\MSVB7.dll

[2008/05/19 20:05:48 | 00,002,972 | ---- | C] () -- C:\WINDOWS\ACROREAD.INI

[2008/05/19 20:04:02 | 00,000,059 | ---- | C] () -- C:\WINDOWS\TLCAPPS.INI

[2008/05/14 20:20:26 | 00,081,920 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\ezpinst.exe

[2008/04/21 22:45:26 | 00,000,146 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\fusioncache.dat

[2008/04/21 21:15:55 | 00,008,683 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\hpzinstall.log

[2008/03/29 15:28:38 | 00,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys

[2008/03/16 19:00:43 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI

[2008/01/30 01:16:21 | 01,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2008/01/30 01:16:21 | 00,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2008/01/30 01:16:20 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll

[2008/01/30 01:16:17 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2008/01/30 01:16:17 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest

[2008/01/25 18:33:45 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll

[2008/01/19 15:16:26 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2008/01/15 22:16:01 | 00,000,305 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\addr_file.html

[2008/01/07 23:08:03 | 00,001,070 | ---- | C] () -- C:\WINDOWS\disney.ini

[2007/11/24 15:31:23 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll

[2007/11/24 15:31:01 | 00,000,009 | ---- | C] () -- C:\WINDOWS\sierra.ini

[2007/10/31 21:25:24 | 00,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini

[2007/10/31 20:07:47 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI

[2007/10/30 22:40:17 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll

[2007/10/14 02:26:35 | 00,125,440 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2007/10/14 01:14:31 | 00,000,034 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.log

[2007/10/14 01:14:23 | 00,087,608 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\inst.exe

[2007/10/14 01:14:23 | 00,007,887 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.cat

[2007/10/14 01:14:23 | 00,001,144 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.inf

[2007/10/13 14:11:11 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll

[2007/10/13 14:09:51 | 00,012,288 | R--- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

[2007/10/13 14:03:11 | 00,001,363 | ---- | C] () -- C:\WINDOWS\MEESP.INI

[2006/12/30 19:48:38 | 00,000,453 | ---- | C] () -- C:\WINDOWS\powermp3cutterjoiner.ini

[2005/09/29 16:42:56 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\linstall.dll

[2005/06/10 10:56:06 | 00,120,320 | ---- | C] () -- C:\WINDOWS\System32\UnzDll.dll

[2005/06/10 10:55:04 | 00,123,904 | ---- | C] () -- C:\WINDOWS\System32\ZipDll.dll

[2005/05/27 15:57:16 | 00,162,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\PFC027.sys

[2005/01/25 16:15:42 | 00,010,240 | R--- | C] () -- C:\WINDOWS\System32\PA207USD.DLL

[2004/05/13 20:14:58 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\opencrypto.dll

[2004/03/18 17:43:44 | 00,843,776 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll

[2003/08/07 15:01:52 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2003/02/03 18:12:00 | 00,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll

 

========== LOP Check ==========

 

[2008/08/27 14:54:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Avg7

[2008/02/15 21:15:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\ConeXware

[2009/04/14 17:21:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin

[2008/02/05 13:56:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus!

[2008/01/19 14:06:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\NCH Swift Sound

[2009/09/27 01:44:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\PopCap Games

[2009/02/02 23:16:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\SlySoft

[2007/10/14 03:09:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Sony

[2009/12/10 10:08:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP

[2007/12/27 01:10:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\vsosdk

[2009/12/17 22:38:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\BitTorrent

[2009/04/14 11:41:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\m

[2008/01/19 15:14:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\NCH Swift Sound

[2008/06/10 20:13:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\proDAD

[2007/10/14 03:13:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Publish Providers

[2009/07/23 12:40:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Samsung

[2009/10/20 11:12:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\SecondLife

[2008/06/02 00:39:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Sony

[2007/10/14 02:40:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Sony Setup

[2009/09/27 02:54:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\SpinTop

[2009/04/15 00:34:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Vso

[2008/06/10 21:04:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\ZC Dream Photo

 

========== Purity Check ==========

 

 

 

========== Custom Scans ==========

 

 

< :Reg >

 

< [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA] >

 

< [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SROSA] >

 

< [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Enum\Root\LEGACY_SROSA] >

 

< [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA] >

 

< [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\srosa] >

 

< [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\srosa] >

 

< [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa] >

 

< :Files >

 

< C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini >

[2009/11/14 09:55:29 | 00,125,440 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

 

< C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons\SOAP PART.exe >

 

< C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons >

 

< @C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:C7F04040 >

 

< @C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:A8ADE5D8 >

 

< @C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:DFC5A2B2 >

 

< C:\WINDOWS\System32\wintems.exe >

 

< @C:\WINDOWS:FFAA131FD1EFF6A7 >

 

< F:\ugyelo.exe >

 

< :OTL >

 

< O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. >

 

< O4 - HKLM..\Run: [AXIS TONS THE MP3] C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons\SOAP PART.exe File not found >

 

< O4 - HKLM..\Run: [ClientGW] File not found >

 

< O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [german.exe] C:\WINDOWS\System32\wintems.exe File not found >

 

< O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\RunOnce: [shockwave Updater] C:\WINDOWS\System32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103471 -Mozilla\5.0 ( File not found >

 

< O4 - Startup: C:\Documents and Settings\Administrador\Menu Iniciar\Programas\Inicializar\Velox.lnk = File not found >

 

< O33 - MountPoints2\{279dfa8e-2210-11dd-a76c-000fead54043}\Shell\AutoRun\command - "" = i9bwjpqc.exe >

 

< O33 - MountPoints2\{279dfa8e-2210-11dd-a76c-000fead54043}\Shell\open\Command - "" = i9bwjpqc.exe >

 

< O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\AutoRun\command - "" = F:\ugyelo.exe -- File not found >

 

< O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\explore\Command - "" = F:\ugyelo.exe -- File not found >

 

< O33 - MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\Shell\open\Command - "" = F:\ugyelo.exe -- File not found >

 

< :Services >

 

< srosa >

 

< :Commands >

 

< [purity] >

 

< [emptytemp] >

 

< [Reboot] >

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 24 bytes -> C:\WINDOWS:FFAA131FD1EFF6A7

@Alternate Data Stream - 208 bytes -> C:\WINDOWS\System32\drivers:GbpKmAp.lst

@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:C7F04040

@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:A8ADE5D8

@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:DFC5A2B2

< End of report >

Compartilhar este post


Link para o post
Compartilhar em outros sites

Não encontrei a pasta C:\_OTL\MovedFiles

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:14: Rodrigo, on 18/12/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

C:\WINDOWS\System32\PAStiSvc.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\hkcmd.exe

C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe

C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe

C:\WINDOWS\system32\igfxtray.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Hijack This\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 217.72.199.106:80

R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehuni.dll

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [eSnips] "C:\Arquivos de programas\eSnips\ClientGW.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [AXIS TONS THE MP3] C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons\SOAP PART.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [NBJ] "C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\RunOnce: [shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~3.EXE -Update -1103471 -"Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-BR; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2 (.NET CLR 3.5.30729)" -"http://www.cartoonnetworkla.com/folders/200803/dexter.game.pt.labyrinth.432x330.zip2357934847000454/index.html"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/stg_drm.ocx

O16 - DPF: {31CB2F01-72C2-4CF4-B265-450E8817B039} (Toontown IE Helper Portuguese) - http://idownload.br.toontown.com/sv1.4.22.6/ttinst-portuguese.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab

O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.oifotos.com/custom/send3/ImageUploader5.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/armhelper.ocx

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} (GbPluginObj Class) - https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{27D4895C-B9D5-4547-BE37-98EB075148C3}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS4\Services\Tcpip\..\{27D4895C-B9D5-4547-BE37-98EB075148C3}: NameServer = 200.149.55.140 200.165.132.147

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O20 - Winlogon Notify: GbPluginUni - C:\ARQUIV~1\GbPlugin\gbiehuni.dll

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

 

--

End of file - 13049 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa! Rodrigo Rocha RJ

 

<!> Houve um erro na execução!

<!> Ps: Ao colar as informações que estão no Code,no campo Custom Scans/Fixes,deveria clicar em Run Fix. Mas...,segundo o relatório,você clicou em Run Scan.

<!> Repita a operação,de modo correto,e poste seu relatório.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

É isso?

 

 

All processes killed

========== REGISTRY ==========

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SROSA\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Enum\Root\LEGACY_SROSA\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\srosa\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\srosa\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa\ not found.

========== FILES ==========

C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.

File\Folder C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons\SOAP PART.exe not found.

File\Folder C:\Documents and Settings\All Users\Dados de aplicativos\Readme Live Axis Tons not found.

ADS C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:C7F04040 deleted successfully.

ADS C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:A8ADE5D8 deleted successfully.

ADS C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:DFC5A2B2 deleted successfully.

File\Folder C:\WINDOWS\System32\wintems.exe not found.

ADS C:\WINDOWS:FFAA131FD1EFF6A7 deleted successfully.

File\Folder F:\ugyelo.exe not found.

========== OTL ==========

Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\AXIS TONS THE MP3 deleted successfully.

Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ClientGW deleted successfully.

Registry value HKEY_USERS\S-1-5-21-725345543-1547161642-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Run\\german.exe deleted successfully.

Registry value HKEY_USERS\S-1-5-21-725345543-1547161642-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Shockwave Updater deleted successfully.

C:\Documents and Settings\Administrador\Menu Iniciar\Programas\Inicializar\Velox.lnk moved successfully.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{279dfa8e-2210-11dd-a76c-000fead54043}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{279dfa8e-2210-11dd-a76c-000fead54043}\ not found.

File i9bwjpqc.exe not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{279dfa8e-2210-11dd-a76c-000fead54043}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{279dfa8e-2210-11dd-a76c-000fead54043}\ not found.

File i9bwjpqc.exe not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7cb65ee-4f13-11de-aa68-000fead54043}\ not found.

File F:\ugyelo.exe not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7cb65ee-4f13-11de-aa68-000fead54043}\ not found.

File F:\ugyelo.exe not found.

Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7cb65ee-4f13-11de-aa68-000fead54043}\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7cb65ee-4f13-11de-aa68-000fead54043}\ not found.

File F:\ugyelo.exe not found.

========== SERVICES/DRIVERS ==========

Error: No service named srosa was found to stop!

Unable to stop service srosa!

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: Administrador

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: Aline Rocha

->Temp folder emptied: 629312 bytes

->Temporary Internet Files folder emptied: 45514348 bytes

->FireFox cache emptied: 19507817 bytes

 

User: All Users

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: LNSS_MONITOR_USR

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: LocalService

->Temp folder emptied: 66016 bytes

->Temporary Internet Files folder emptied: 3235514 bytes

 

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33237 bytes

 

User: Rodrigo Rocha

->Temp folder emptied: 834715 bytes

->Temporary Internet Files folder emptied: 29689033 bytes

->Java cache emptied: 25848297 bytes

->FireFox cache emptied: 60410793 bytes

 

User: Users

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

Windows Temp folder emptied: 4822289 bytes

RecycleBin emptied: 0 bytes

 

Total Files Cleaned = 181,86 mb

 

 

OTL by OldTimer - Version 3.1.17.0 log created on 12182009_132944

 

Files\Folders moved on Reboot...

 

Registry entries deleted on Reboot...

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Rodrigo Rocha RJ

 

É isso?

<!> Sim! Agora veio correto.

°°°°°°°°°°°°°°°°°°°°°°°°°

°°°°°°°°°°°°°°°°°°°°°°°°°

<@> Execute o OTL Quick Scan,onde teremos um rápido escaneamento da ferramenta.

<@> Duplo-clique em: < otlDesktopIcon.png >

<@> Clique em "Scan All Users" --> 2j287qe.png --> Aguarde!

<@> Copie e poste o relatório. ( OTL log )

<@> Ps: Não há necessidade de postar o relatório Extras.

<@> Ps: Se você possui unidades removíveis,teremos que executar o UsbFix.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Eu tenho uma impressora conectada na porta USB e meu drive de CD tem uns 3 e nenhum funciona...

 

 

OTL logfile created on: 18/12/2009 14:14:20 - Run 3

OTL by OldTimer - Version 3.1.17.0 Folder = C:\Documents and Settings\Rodrigo Rocha\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy

 

495,48 Mb Total Physical Memory | 122,23 Mb Available Physical Memory | 24,67% Memory free

1,13 Gb Paging File | 0,64 Gb Available in Paging File | 56,98% Paging File free

Paging file location(s): C:\pagefile.sys 744 1488 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas

Drive C: | 74,52 Gb Total Space | 18,58 Gb Free Space | 24,93% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: PC_DA_SALA

Current User Name: Rodrigo Rocha

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 14 Days

Output = Minimal

Quick Scan

 

========== Processes (SafeList) ==========

 

PRC - C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

PRC - C:\Arquivos de programas\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)

PRC - C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation)

PRC - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)

PRC - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe (Avira GmbH)

PRC - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)

PRC - C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

PRC - C:\Arquivos de programas\GbPlugin\gbpsv.exe ( )

PRC - C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

PRC - C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

PRC - C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)

PRC - C:\Arquivos de programas\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)

PRC - C:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)

PRC - C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

PRC - C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe (LightComm)

PRC - C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)

PRC - C:\WINDOWS\system32\PAStiSvc.exe ()

PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)

PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)

PRC - C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\WINDOWS\system32\framedyn.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\umdmxfrm.dll (Microsoft Corporation)

MOD - C:\WINDOWS\system32\serwvdrv.dll (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (JavaQuickStarterService) -- C:\Arquivos de programas\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)

SRV - (AntiVirService) -- C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)

SRV - (npggsvc) -- C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)

SRV - (AntiVirSchedulerService) -- C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe (Avira GmbH)

SRV - (SeaPort) -- C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)

SRV - (gusvc) -- C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)

SRV - (GbpSv) -- C:\Arquivos de programas\GbPlugin\gbpsv.exe ( )

SRV - (odserv) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)

SRV - (Microsoft Office Groove Audit Service) -- C:\Arquivos de programas\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)

SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)

SRV - (Net Driver HPZ12) -- C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)

SRV - (StarWindServiceAE) -- C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)

SRV - (hpqddsvc) -- C:\Arquivos de programas\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)

SRV - (hpqcxs08) -- C:\Arquivos de programas\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)

SRV - (ose) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)

SRV - (STI Simulator) -- C:\WINDOWS\system32\PAStiSvc.exe ()

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

 

 

IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://br.msn.com/?ocid=iehp

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-br

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 76 BD 48 03 C8 6E CA 01 [binary data]

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = about:blank

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..\URLSearchHook: {982CB676-38F0-4D9A-BB72-D9371ABE876E} - Reg Error: Key error. File not found

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\S-1-5-21-725345543-1547161642-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\S-1-5-21-725345543-1547161642-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 217.72.199.106:80

 

========== FireFox ==========

 

FF - prefs.js..browser.search.defaultenginename: "Google"

FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - prefs.js..browser.startup.homepage: "www.orkut.com"

 

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox\components [2009/10/23 10:21:11 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox\plugins [2009/10/23 10:21:48 | 00,000,000 | ---D | M]

 

[2008/12/26 19:10:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Extensions

[2009/12/18 12:03:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\extensions

[2009/08/22 13:58:32 | 00,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E8873}

[2009/08/29 12:39:55 | 00,000,000 | ---D | M] (The Pirate Bay Toolbar) -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\extensions\{a33fa729-d155-4b23-842b-2c665ecabdb6}

[2009/08/19 17:32:44 | 00,000,373 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\searchplugins\ask.xml

[2009/07/16 15:02:38 | 00,000,890 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Mozilla\Firefox\Profiles\r2xl5d0u.default\searchplugins\conduit.xml

[2009/12/18 12:03:58 | 00,000,000 | ---D | M] -- C:\Arquivos de programas\Mozilla Firefox\extensions

[2008/05/05 21:39:37 | 00,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Arquivos de programas\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

[2008/06/30 23:02:00 | 00,663,072 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\Mozilla Firefox\plugins\npOGAPlugin.dll

[2008/03/24 21:21:00 | 02,889,088 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\plugins\NPSWF32.dll

[2009/08/19 17:31:36 | 00,001,027 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\buscape.xml

[2009/08/19 17:31:36 | 00,001,135 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\mercadolivre.xml

[2009/08/19 17:31:36 | 00,001,168 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\wikipedia-br.xml

[2009/08/19 17:31:36 | 00,000,648 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\yahoo-br.xml

 

O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.

O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)

O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)

O2 - BHO: (Facilitador de Leitor de Link Adobe PDF) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)

O2 - BHO: (ssh2 Class) - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll (Scopus Tecnologia Ltda)

O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)

O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)

O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)

O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)

O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\Arquivos de programas\GbPlugin\gbiehuni.dll (Banco Unibanco)

O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)

O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)

O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O3 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)

O3 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)

O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe File not found

O4 - HKLM..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe (LightComm)

O4 - HKLM..\Run: [eSnips] C:\Arquivos de programas\eSnips\ClientGW.exe File not found

O4 - HKLM..\Run: [GrooveMonitor] C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)

O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)

O4 - HKLM..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)

O4 - HKLM..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)

O4 - HKLM..\Run: [NBKeyScan] C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe File not found

O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)

O4 - HKLM..\Run: [PRONoMgr.exe] C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)

O4 - HKLM..\Run: [soundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [TkBellExe] C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMBgMonitor.exe File not found

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [german.exe] C:\WINDOWS\System32\wintems.exe File not found

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [NBJ] C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)

O4 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

O4 - Startup: C:\Documents and Settings\Rodrigo Rocha\Menu Iniciar\Programas\Inicializar\Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de programas\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)

O8 - Extra context menu item: Google Sidewiki... - C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)

O9 - Extra Button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)

O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)

O9 - Extra Button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)

O9 - Extra Button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Arquivos de programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)

O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe File not found

O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe File not found

O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKU\.DEFAULT\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKU\S-1-5-18\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab (Office Genuine Advantage Validation Tool)

O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/stg_drm.ocx (SpinTop DRM Control)

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)

O16 - DPF: {31CB2F01-72C2-4CF4-B265-450E8817B039} http://idownload.br.toontown.com/sv1.4.22.6/ttinst-portuguese.cab (Toontown IE Helper Portuguese)

O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)

O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} http://www.oifotos.com/custom/send3/ImageUploader5.cab (Image Uploader Control)

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab (Java Plug-in 1.6.0_15)

O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/armhelper.ocx (ArmHelper Control)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab (GbPluginObj Class)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 10.0.0.138

O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)

O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)

O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Arquivos de programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKU\S-1-5-21-725345543-1547161642-2147145749-1003 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\ GbPluginUni: DllName - C:\ARQUIV~1\GbPlugin\gbiehuni.dll - C:\Arquivos de programas\GbPlugin\gbiehuni.dll (Banco Unibanco)

O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll (Scopus Tecnologia Ltda)

O22 - SharedTaskScheduler: {A3717295-941D-416F-9384-ED1736729F1C} - scpLIB - C:\Arquivos de programas\Scpad\scpLIB.dll (Scopus Tecnologia Ltda)

O24 - Desktop Components:0 (Minha página inicial atual) - About:Home

O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)

O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399008} - C:\Arquivos de programas\GbPlugin\gbiehuni.dll (Banco Unibanco)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2007/10/13 12:39:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] -- "%1" %*

O35 - exefile [open] -- "%1" %*

 

========== Files/Folders - Created Within 14 Days ==========

 

[2009/12/18 13:29:44 | 00,000,000 | ---D | C] -- C:\_OTL

[2009/12/18 11:17:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Rodrigo Rocha\Desktop\Log

[2009/12/17 21:01:40 | 00,538,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe

[2009/12/17 19:47:15 | 00,073,227 | ---- | C] (Satinfo SL.) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\EliBaglA.exe

[2009/12/17 13:00:29 | 00,000,000 | ---D | C] -- C:\Lop SD

[2009/12/17 11:49:31 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Hijack This

[2009/12/17 11:44:49 | 00,397,312 | ---- | C] (Defaults Twam) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\uninstall.exe

[2009/07/14 22:28:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Dados de aplicativos\Adobe

[2009/05/08 23:54:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft

[2009/04/01 18:35:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Google

[2009/03/28 11:05:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Google

[2008/09/06 15:02:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft

[2008/08/27 14:54:44 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Dados de aplicativos\Microsoft

[2008/08/27 14:54:44 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Dados de aplicativos\Microsoft

[2007/10/14 01:14:23 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.sys

 

========== Files - Modified Within 14 Days ==========

 

[2009/12/18 13:49:01 | 00,001,176 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1547161642-2147145749-1003UA.job

[2009/12/18 13:34:15 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2009/12/18 13:33:46 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2009/12/18 13:33:38 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2009/12/18 13:32:33 | 12,582,912 | ---- | M] () -- C:\Documents and Settings\Rodrigo Rocha\NTUSER.DAT

[2009/12/18 13:32:33 | 00,000,210 | -HS- | M] () -- C:\Documents and Settings\Rodrigo Rocha\ntuser.ini

[2009/12/17 23:49:01 | 00,001,124 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1547161642-2147145749-1003Core.job

[2009/12/17 21:01:58 | 00,538,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\OTL.exe

[2009/12/17 19:47:15 | 00,073,227 | ---- | M] (Satinfo SL.) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\EliBaglA.exe

[2009/12/17 13:09:23 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts

[2009/12/17 11:45:05 | 00,397,312 | ---- | M] (Defaults Twam) -- C:\Documents and Settings\Rodrigo Rocha\Desktop\uninstall.exe

[2009/12/16 00:58:28 | 04,787,416 | -H-- | M] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\IconCache.db

[2009/12/11 10:47:25 | 00,000,935 | ---- | M] () -- C:\WINDOWS\win.ini

[2009/12/10 15:29:15 | 00,581,130 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat

[2009/12/10 15:29:15 | 00,545,322 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2009/12/10 15:29:15 | 00,111,032 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat

[2009/12/10 15:29:15 | 00,099,094 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2009/12/10 15:29:14 | 01,355,578 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2009/12/10 14:29:42 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2009/12/10 09:39:53 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.jwr

[2009/12/09 20:07:04 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.uie

[2009/12/09 12:48:44 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.wxa

[2009/12/08 18:19:36 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.mof

[2009/12/08 17:41:20 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.mvo

[2009/12/08 12:00:09 | 00,290,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.gib

[2009/12/08 09:29:16 | 00,056,816 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys

 

========== Files Created - No Company Name ==========

 

[2009/08/03 16:07:42 | 00,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll

[2009/07/15 02:20:55 | 00,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI

[2009/02/02 23:16:22 | 00,000,040 | -HS- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\.zreglib

[2009/01/24 00:14:30 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini

[2009/01/17 20:57:30 | 00,000,671 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\vso_ts_preview.xml

[2008/10/18 16:45:52 | 00,000,029 | ---- | C] () -- C:\WINDOWS\RRK.INI

[2008/10/18 16:45:06 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI

[2008/07/29 14:42:08 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\LauncherAccess.dt

[2008/07/22 23:44:37 | 00,053,248 | ---- | C] () -- C:\WINDOWS\System32\slbmgpg.dll

[2008/06/26 10:50:58 | 00,716,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys

[2008/06/13 17:11:18 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll

[2008/06/07 15:35:30 | 00,000,192 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\momento_log.dat

[2008/05/30 20:54:00 | 00,001,661 | ---- | C] () -- C:\WINDOWS\vbxlrs.dll

[2008/05/30 20:54:00 | 00,001,661 | ---- | C] () -- C:\WINDOWS\MSVB7.dll

[2008/05/19 20:05:48 | 00,002,972 | ---- | C] () -- C:\WINDOWS\ACROREAD.INI

[2008/05/19 20:04:02 | 00,000,059 | ---- | C] () -- C:\WINDOWS\TLCAPPS.INI

[2008/05/14 20:20:26 | 00,081,920 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\ezpinst.exe

[2008/04/21 22:45:26 | 00,000,146 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Configurações locais\Dados de aplicativos\fusioncache.dat

[2008/04/21 21:15:55 | 00,008,683 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\hpzinstall.log

[2008/03/29 15:28:38 | 00,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys

[2008/03/16 19:00:43 | 00,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.INI

[2008/01/30 01:16:21 | 01,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2008/01/30 01:16:21 | 00,282,624 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2008/01/30 01:16:20 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll

[2008/01/30 01:16:17 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll

[2008/01/30 01:16:17 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest

[2008/01/25 18:33:45 | 00,034,308 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll

[2008/01/19 15:16:26 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2008/01/15 22:16:01 | 00,000,305 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\addr_file.html

[2008/01/07 23:08:03 | 00,001,070 | ---- | C] () -- C:\WINDOWS\disney.ini

[2007/11/24 15:31:23 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll

[2007/11/24 15:31:01 | 00,000,009 | ---- | C] () -- C:\WINDOWS\sierra.ini

[2007/10/31 21:25:24 | 00,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini

[2007/10/31 20:07:47 | 00,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI

[2007/10/30 22:40:17 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\AVEQT.dll

[2007/10/14 01:14:31 | 00,000,034 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.log

[2007/10/14 01:14:23 | 00,087,608 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\inst.exe

[2007/10/14 01:14:23 | 00,007,887 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.cat

[2007/10/14 01:14:23 | 00,001,144 | ---- | C] () -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\pcouffin.inf

[2007/10/13 14:11:11 | 00,135,168 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll

[2007/10/13 14:09:51 | 00,012,288 | R--- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

[2007/10/13 14:03:11 | 00,001,363 | ---- | C] () -- C:\WINDOWS\MEESP.INI

[2006/12/30 19:48:38 | 00,000,453 | ---- | C] () -- C:\WINDOWS\powermp3cutterjoiner.ini

[2005/09/29 16:42:56 | 00,049,152 | ---- | C] () -- C:\WINDOWS\System32\linstall.dll

[2005/06/10 10:56:06 | 00,120,320 | ---- | C] () -- C:\WINDOWS\System32\UnzDll.dll

[2005/06/10 10:55:04 | 00,123,904 | ---- | C] () -- C:\WINDOWS\System32\ZipDll.dll

[2005/05/27 15:57:16 | 00,162,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\PFC027.sys

[2005/01/25 16:15:42 | 00,010,240 | R--- | C] () -- C:\WINDOWS\System32\PA207USD.DLL

[2004/05/13 20:14:58 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\opencrypto.dll

[2004/03/18 17:43:44 | 00,843,776 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll

[2003/08/07 15:01:52 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2003/02/03 18:12:00 | 00,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll

 

========== LOP Check ==========

 

[2008/08/27 14:54:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Avg7

[2008/02/15 21:15:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\ConeXware

[2009/04/14 17:21:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin

[2008/02/05 13:56:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus!

[2008/01/19 14:06:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\NCH Swift Sound

[2009/09/27 01:44:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\PopCap Games

[2009/02/02 23:16:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\SlySoft

[2007/10/14 03:09:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Sony

[2009/12/10 10:08:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP

[2007/12/27 01:10:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\vsosdk

[2009/12/17 22:38:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\BitTorrent

[2009/04/14 11:41:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\m

[2008/01/19 15:14:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\NCH Swift Sound

[2008/06/10 20:13:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\proDAD

[2007/10/14 03:13:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Publish Providers

[2009/07/23 12:40:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Samsung

[2009/10/20 11:12:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\SecondLife

[2008/06/02 00:39:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Sony

[2007/10/14 02:40:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Sony Setup

[2009/09/27 02:54:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\SpinTop

[2009/04/15 00:34:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\Vso

[2008/06/10 21:04:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\ZC Dream Photo

 

========== Purity Check ==========

 

 

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 208 bytes -> C:\WINDOWS\System32\drivers:GbpKmAp.lst

< End of report >

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Rodrigo Rocha RJ

 

Eu tenho uma impressora conectada na porta USB e meu drive de CD tem uns 3 e nenhum funciona...

<!> Estava referindo-me a pendrives,mas...vamos dar prosseguimento.

°°°°°°°°°°°°°°°°°°°°°°°

°°°°°°°°°°°°°°°°°°°°°°°

<@> Baixe: < FindyKill > ( ...par Chiquitine29 )

 

<!> Mirror-2 < http://findykill.changelog.fr/Setup.exe >

 

<@> Salve-a em Arquivos de Programas!

<@> Feche programas que estejam abertos.

<@> Desabilite a proteção residente de antivírus e antispywares.

<@> Ps: A detecção dessa ferramenta,por antivírus,é um falso positivo!

<@> Instale a ferramenta,e aceite todas as condições pedidas.

<@> Terminando;execute a ferramenta com um duplo-clique,em: C:\Arquivos de Programas\FindyKill\FindyKill.bat

<@> No prompt,aperte o P. --> Enter. <-- Opção de linguas!

<@> À seguir,aperte o 2. ( "Eliminar los ficheros infectados" )

<@> Aperte Enter --> O computador vai reiniciar,por duas vezes! --> Aguarde!

<@> Terminando,clique em uma área vazia do prompt! --> Aperte Enter.

<@> Abrir-se-à o Bloco de Notas,com o relatório: C:\FindyKill.txt <-- Rapport!

°°°°°°°°°°°°°°°°°°°°°°°

°°°°°°°°°°°°°°°°°°°°°°°

<@> Baixe: < UsbFix.exe > ( ...par Chiquitine29 et Chimay8 )

<@> Salve-a em Arquivos de programas!

<@> Desabilite seu antivírus!

<@> Instale e execute a ferramenta,com um duplo-clique em: < r2t69y.jpg >

<@> Nas opções da língua,escolha "PT-BR" --> Enter.

<@> Escolha a opção 2: 2. Suppression des fichiers infectieux --> Aperte Enter.

 

< wrmljk.jpg >

 

<@> Surgirá uma mensagem,pedindo que seja conectada sua(s) mídia(s) removíveis,ao computador. ( pendrive,mp3,mp4,iPods,etc... )

<@> Aceite a solicitação,e dê o Ok. --> À seguir clique,novamente,em Ok.

 

< 6f8nwo.jpg >

 

<@> O computador irá reiniciar. <-- Aguarde!

<@> Terminando,clique em "Continue" e aguarde a finalização da ferramenta.

<@> Ps: Não desconecte,ainda,sua(s) mídia(s) removíveis! <-- Importante!

<@> Surgirá a mensagem: "Nettoyage effectue" --> Aperte Enter.

<@> Poste o relatório,que estará em: C:\UsbFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Findykill

 

 

 

############################## | FindyKill V5.021 |

 

# User : Rodrigo Rocha (Administradores) # PC_DA_SALA

# Update on 10/12/2009 by Chiquitine29

# Start at: 11:04:35 Rodrigo | 20/12/2009

# Website : http://pagesperso-orange.fr/NosTools/index.html

# Contact : FindyKill.Contact@gmail.com

 

# Intel® Celeron® CPU 2.80GHz

# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3

# Internet Explorer 8.0.6001.18702

# Windows Firewall Status : Enabled

# AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

 

# A:\ # Unidade de disquete de 3 1/2 polegadas

# C:\ # Disco fixo local # 74,52 Go (12,12 Go free) [Disco local] # NTFS

# D:\ # Disco CD-ROM

# E:\ # Disco CD-ROM

# F:\ # Disco CD-ROM

# G:\ # Disco removível

# H:\ # Disco removível # 959,12 Mo (673,56 Mo free) [RODRIGO] # FAT

 

############################## | Processos ativos |

 

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\SCardSvr.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\WgaTray.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

C:\WINDOWS\System32\PAStiSvc.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\System32\alg.exe

 

################## | C: |

 

Supprimido ! H:\"autorun.inf"

 

################## | C:\WINDOWS |

 

Supprimido ! C:\WINDOWS\Prefetch\WINUPGRO.EXE-17681AA8.pf

 

################## | C:\WINDOWS\system32 |

 

Supprimido ! C:\WINDOWS\system32\a.bat

Supprimido ! C:\WINDOWS\system32\autorun.inf

 

################## | C:\WINDOWS\system32\drivers |

 

 

################## | C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos |

 

Supprimido ! C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\m\shared\A.M.L. - Source Code

Supprimido ! C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\m\shared\Docsmartz Professional

Supprimido ! C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\m\shared

Supprimido ! C:\Documents and Settings\Rodrigo Rocha\Dados de aplicativos\m

 

################## | Supressão Outros ... |

 

################## | Temporary Internet Files |

 

 

################## | Registro / Chaves infeciosas |

 

Supprimido ! [HKLM\SYSTEM\ControlSet003\Services\sK9Ou0s]

Supprimido ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S]

Supprimido ! [HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S]

Supprimido ! [HKCU\Software\Microsoft\Windows\UI] "KEY540534"

Supprimido ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"

Supprimido ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]

Supprimido ! [HKLM\software\microsoft\security center] "AntiVirusDisableNotify"

Supprimido ! [HKLM\software\microsoft\security center] "AntiVirusOverride"

Supprimido ! [HKLM\software\microsoft\security center] "FirewallDisableNotify"

Supprimido ! [HKLM\software\microsoft\security center] "FirewallOverride"

Supprimido ! [HKLM\software\microsoft\security center] "UpdatesDisableNotify"

 

################## | Estado / Serviços / Informações |

 

# Safe mode : OK

 

 

# Affichagem dos arquivos ocultos : OK

 

# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )

# EapHost -> Start = 2 ( Good = 2 | Bad = 4 )

# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )

# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )

# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )

# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

 

################## | PEH ... |

 

Corrompido : C:\Arquivos de programas\Spybot - Search & Destroy\blindman.exe

[Offset = 00000104 - Valor = 0x0001]

 

Corrompido : C:\Arquivos de programas\Spybot - Search & Destroy\Update.exe

[Offset = 00000104 - Valor = 0x0001]

 

Corrompido : C:\WINDOWS\$hf_mig$\KB873339\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB885835\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB885836\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB886185\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB887472\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB888302\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB890046\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB890859\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB891781\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB893756\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB894391\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB896358\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB896423\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB896428\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB898461\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB899587\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB899591\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB900485\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB900725\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB901017\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB901214\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB902400\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB904706\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB905414\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB905749\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB908519\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB908531\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB910437\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB911280\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB911562\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB911927\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB913580\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB914388\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB914389\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB915865\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB916595\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB917953\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB918118\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB918439\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB919007\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB920213\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB920670\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB920683\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB920685\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB920872\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB921503\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB922582\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB922819\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB923414\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB923980\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB924270\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB925902\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB926255\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB926436\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB927779\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB927802\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB927891\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB928255\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB928843\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB929123\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB930178\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB930916\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB931261\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB931784\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB932168\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB932823-v3\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB933360\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB933729\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB935839\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB935840\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB936021\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB936357\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB937894\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB938828\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB938829\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB939653-IE7\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB941202\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB941568\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB941644\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB941693\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB942615-IE7\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB942763\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB943055\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB943460\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB943485\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB944533-IE7\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB944653\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB945553\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB946026\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB946648\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB947864-IE7\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB948590\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB948881\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB950749\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB950759-IE7\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB950760\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB950762\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB950974\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB951066\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB951376\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB951376-v2\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB951698\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB951748\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB951978\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB952287\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB952954\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB953838-IE7\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB953839\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB954211\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB954459\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB954600\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB955069\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB955839\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB956390-IE7\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB956391\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB956802\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB956803\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB956841\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB957095\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB957097\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB958215-IE7\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB958644\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB958687\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$hf_mig$\KB960714-IE7\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\$NtServicePackUninstall$\sysinfo.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : sysinfo.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\ServicePackFiles\i386\sysinfo.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : sysinfo.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\0368044dcbbc6d7c303082a3061556b0\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\13dbf93b2453bda7ea471c0f92a7ab1f\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\198b253efa6680e35b86964f717bd797\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\1adecf0f49989e4d14f4c8597f3d24a4\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\1c2a6e499bef0315b907eb3085b242db\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\1e218af8415a7cc63a7b4ae0a828dd69\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\1f30f612c91a63e84017e83c76ea9e42\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\270aeaaa6679faef66e6da4371053a9f\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\2716e94267154b4722838e28362d23d0\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\2d4baa067165c627acf81b788b44d62e\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\3110ae9825954e4eef079821207183ba\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\34724ce2be5d963d34d33d37894bf8b1\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\3758f3b38688f313105cf72c6f72fea0\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\3919c5bb9c55ca11c02d2c2fac4e3a1f\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\410887b21fd1b3a2613b52210ed89b8b\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\4366a60ed78e633f2c559bb3e0ac3c12\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\437b3579f0a916decc78e6314058294f\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\484abe732a18f465a6477b75b978d4cc\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\4ee16b507296aedb9339edda2a749ddd\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\4f42f5200e838591abacb19a7d89941e\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\5313203d3b510b8c124765a5448ca9ee\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\55962834f421452707475dbc0912282d\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\590b02689ce92b927198d6ba03e34312\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\5a954afeff62a725a7db9a6a02e14746\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\60e8655260ead946181036b53b5c8c15\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\6107a2d02ce279a9f2449cf5f1fc3f6e\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\630f905c0a8ae5a8ce9a0e8ffcc4aced\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\667c63a16ca897f3f0ce788125fbbf9f\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\66f85ad92aa4ffa0be18ec01bf54d5e9\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\6ad85a8f010c0c029e3da88c5841f47b\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\735f2aaf260c8289286a9de0c9d1fa8a\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\759dc311e792f38c45ef860928f832b0\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\7744da6ad55e1ad447863104440def74\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\786c0b643e9afd559dd95749a1c9ec90\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\7a3dd203d422fd4dd350a1bf6a6c424d\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\84c7a7eb35767517601dd8bf0a90cd61\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\89e38194a06bd59841ed6a7164199f77\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\8a3954f33a41aa7439a4845e89cca905\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\8bfc499865f60096e9c722d09af67a8d\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\8efa2eedc59024b575649cc3a3d8d3b3\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\95e7e07cf2671a70b6ba54a0b6763e5a\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\9f6f0106e30972bb1fbe975013b6da34\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\a1481e7564e6ed69be9bd223d02d3f81\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\a46cb603f6fdb1936ec6e2dacf899ecc\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\a4f12aeae06bbd25e88c1a58e15d3c95\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\acb69290b87220332fb336da34dae8fe\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\ad29682ad80cae491e180de5a2d93d7b\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\ad894427002eb4655f2f1c8f70608210\update\update.exe

[Offset = 000000EC - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000EC - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\b13413f5c6cebc7e0066a563befdf48f\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\b34d11b25a6c7edcc2d1136564a1d3a6\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\b567f33501007488471d6bdfdb147e6b\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\b6af1023bfa1d6cad9ec5c49a5482fe8\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\c55c41438c0a2a388f2558d18cba33eb\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\c67f28fca48200022003dfd7d532fd64\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\c740006f18277419aef502c280a0dfbf\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\c8d92553f495d85d6a2c60da21d28fcb\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\cd86036fd8fce77c5f9c4121444b86d3\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\cef8e0c3a4da815c519850bb604afe80\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\d094751ab7cc9d40619043e81a5f79c0\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\d337e1ef3bd797cc758f30fd11b5919c\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\dfff249bc0d6c71b8609623e07886a3a\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\e571454da085854e25c530c86b6f58d9\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\e61025f4a16c03ae98b6cd3c9021001b\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\e6249adb16685d0d0841f95255ba0181\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\e6ebdc6b8ab5c828574ccbb6e38992df\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\f17fac9caba9b9b457bfdd8b1c9b29bd\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\f8e74424c9b5e24e127ffa2d61cb8916\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\SoftwareDistribution\Download\fa0382bc5a949313ea5a3ccb18a15dbe\update\update.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : update.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

Corrompido : C:\WINDOWS\system32\dllcache\register.exe

[Offset = 000000E4 - Valor = 0x0001]

 

Tentativa de reparação...

Backup : register.exe.REN

[Offset = 000000E4 - Novo Valor = 0x4C01]

Arquivo reparado com sucesso.

 

 

 

################## | Cracks / Keygens / Serials |

 

"C:\Documents and Settings\Rodrigo Rocha\Meus documentos\Downloads\Full Spectrum Warrior Ten Hammers\CRACKFIX\fsw2.exe"

18/12/2009 15:50: Rodrigo |Size 31645696 |Crc32 3ed7b08e |Md5 18f2e4fe4738a5052efa9af89f19e913

 

 

################## | ! Fim do relatório # FindyKill V5.021 ! |

 

USBFix

 

 

 

############################## | UsbFix V6.066 |

 

User : Rodrigo Rocha (Administradores) # PC_DA_SALA

Update on 20/12/2009 by Chiquitine29, C_XX & Chimay8

Start at: 11:33:17 Rodrigo | 20/12/2009

Website : http://pagesperso-orange.fr/NosTools/index.html

Contact : FindyKill.Contact@gmail.com

 

Intel® Celeron® CPU 2.80GHz

Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3

Internet Explorer 8.0.6001.18702

Windows Firewall Status : Enabled

AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

 

A:\ -> Unidade de disquete de 3 1/2 polegadas

C:\ -> Disco fixo local # 74,52 Go (11,92 Go free) [Disco local] # NTFS

D:\ -> Disco CD-ROM

E:\ -> Disco CD-ROM

F:\ -> Disco CD-ROM

G:\ -> Disco removível

H:\ -> Disco removível # 959,12 Mo (673,58 Mo free) [RODRIGO] # FAT

 

############################## | Processos activos |

 

C:\WINDOWS\System32\smss.exe 608

C:\WINDOWS\system32\csrss.exe 676

C:\WINDOWS\system32\winlogon.exe 700

C:\WINDOWS\system32\services.exe 744

C:\WINDOWS\system32\lsass.exe 756

C:\ARQUIV~1\GbPlugin\GbpSv.exe 940

C:\WINDOWS\system32\logonui.exe 972

C:\WINDOWS\system32\svchost.exe 996

C:\WINDOWS\system32\svchost.exe 1080

C:\WINDOWS\System32\svchost.exe 1176

C:\WINDOWS\system32\svchost.exe 1284

C:\WINDOWS\system32\svchost.exe 1380

C:\WINDOWS\system32\spoolsv.exe 1520

C:\WINDOWS\System32\SCardSvr.exe 1568

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe 1588

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe 1608

C:\WINDOWS\system32\svchost.exe 1672

C:\WINDOWS\System32\svchost.exe 1844

C:\WINDOWS\system32\svchost.exe 1868

C:\Arquivos de programas\Java\jre6\bin\jqs.exe 1888

C:\WINDOWS\System32\svchost.exe 1976

C:\WINDOWS\system32\WgaTray.exe 444

C:\WINDOWS\System32\svchost.exe 460

C:\WINDOWS\Explorer.EXE 508

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 548

C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe 760

C:\WINDOWS\System32\PAStiSvc.exe 1032

C:\WINDOWS\system32\svchost.exe 1120

C:\WINDOWS\system32\wuauclt.exe 1340

C:\WINDOWS\system32\wbem\wmiprvse.exe 2288

C:\WINDOWS\System32\alg.exe 2292

 

################## | Ficheiros # pastas infeciosos |

 

Supprimido ! C:\Recycler\S-1-5-18

Supprimido ! C:\Recycler\S-1-5-21-725345543-1547161642-2147145749-1003

Supprimido ! C:\Recycler\S-1-5-21-725345543-1547161642-2147145749-1004

Supprimido ! C:\Recycler\S-1-5-21-725345543-1547161642-2147145749-500

Supprimido ! H:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665

Supprimido ! H:\Recycler\S-1-5-21-1482476501-1644491937-682003330-1013

 

################## | Registro # Chaves infectieuses |

 

 

################## | Registro # Mountpoints2 |

 

 

################## | Listing |

 

[13/10/2007 12:39: Rodrigo|--a------|0] C:\AUTOEXEC.BAT

[23/07/2009 13:02: Rodrigo|---hs----|211] C:\boot.ini

[28/10/2001 17:06: Rodrigo|-rahs----|4952] C:\Bootfont.bin

[13/10/2007 12:39: Rodrigo|--a------|0] C:\CONFIG.SYS

[13/03/1961 06:01: Rodrigo|--a------|9792810] C:\EDATA_HD.DF

[09/12/2008 21:37: Rodrigo|--a------|5222] C:\fairuse.log

[20/12/2009 11:19: Rodrigo|--a------|53472] C:\FindyKill.txt

[17/12/2009 20:45: Rodrigo|--a------|2372] C:\InfoSat.txt

[13/10/2007 12:39: Rodrigo|-rahs----|0] C:\IO.SYS

[17/12/2009 13:19: Rodrigo|--a------|19465] C:\lopR.txt

[13/10/2007 12:39: Rodrigo|-rahs----|0] C:\MSDOS.SYS

[03/08/2004 23:38: Rodrigo|-rahs----|47564] C:\NTDETECT.COM

[06/09/2008 14:33: Rodrigo|-rahs----|251696] C:\ntldr

[23/07/2009 12:49: Rodrigo|--a------|39] C:\ntosboot.bat

[?|?|?] C:\pagefile.sys

[22/07/2008 23:46: Rodrigo|--a------|3408] C:\Regt_1.key

[22/07/2008 23:46: Rodrigo|--a------|308] C:\Regt_2.key

[22/07/2008 23:46: Rodrigo|--a------|10620] C:\Regt_3.key

[10/06/2008 20:29: Rodrigo|--a------|115] C:\RRTW32.INI

[13/03/1961 06:01: Rodrigo|--a------|71680] C:\SMACKW32.DLL

[16/01/2009 14:56: Rodrigo|--a------|610] C:\updatedatfix.log

[26/01/2009 19:39: Rodrigo|--a------|24] C:\url_history.xml

[20/12/2009 11:37: Rodrigo|--a------|4067] C:\UsbFix.txt

[21/04/2008 22:48: Rodrigo|--a------|1183] C:\_Sid.txt

[16/06/2009 20:00: Rodrigo|--a------|38400] H:\cinema.doc

[15/04/2009 18:13: Rodrigo|--a------|46080] H:\Sociologia da Educa‡Æo.doc

[18/06/2009 17:35: Rodrigo|--a------|40448] H:\Resenha filme Tempos Modernos.doc

[15/04/2009 18:00: Rodrigo|--a------|47104] H:\Resenha Janela da Alma.doc

[29/11/2009 22:36: Rodrigo|--a------|32768] H:\Trabalho dupla.doc

[21/11/2009 15:44: Rodrigo|--a------|32768] H:\AV1.doc

 

################## | Vaccinação |

 

# C:\autorun.inf -> Folder criado por UsbFix.

# H:\autorun.inf -> Folder criado por UsbFix.

 

################## | Cracks / Keygens / Serials |

 

"C:\Documents and Settings\Rodrigo Rocha\Meus documentos\Downloads\Full Spectrum Warrior Ten Hammers\CRACKFIX\fsw2.exe"

18/12/2009 15:50: Rodrigo |Size 31645696 |Crc32 3ed7b08e |Md5 18f2e4fe4738a5052efa9af89f19e913

 

"C:\Documents and Settings\Rodrigo Rocha\Meus documentos\Downloads\Bejeweled 2 + Crack [Full Version].rar"

-> contain : Bejeweled 2 + Crack [Full Version]\Bejeweled2Setup.exe

 

"C:\Documents and Settings\Rodrigo Rocha\Meus documentos\Downloads\Bejeweled 2 + Crack [Full Version].rar"

-> contain : Bejeweled 2 + Crack [Full Version]\WinBej2.exe

 

"C:\Documents and Settings\Rodrigo Rocha\Meus documentos\Downloads\Call.Of.Duty.4.Modern.Warfare.(v1.5).Single.&.Multiplayer.Crack.Incl.KeyGen-XiNiTHAOUS.rar"

-> contain : Crack\iw3mp.exe

 

"C:\Documents and Settings\Rodrigo Rocha\Meus documentos\Downloads\Call.Of.Duty.4.Modern.Warfare.(v1.5).Single.&.Multiplayer.Crack.Incl.KeyGen-XiNiTHAOUS.rar"

-> contain : Crack\iw3sp.exe

 

"C:\Documents and Settings\Rodrigo Rocha\Meus documentos\Downloads\Call.Of.Duty.4.Modern.Warfare.(v1.5).Single.&.Multiplayer.Crack.Incl.KeyGen-XiNiTHAOUS.rar"

-> contain : KeyGen\PC_DOX-Call.Of.Duty.4.KeyGen-Razor1911.exe

 

HIJACKTHIS

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:45: Rodrigo, on 20/12/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

C:\WINDOWS\System32\PAStiSvc.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Hijack This\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 217.72.199.106:80

R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehuni.dll

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [eSnips] "C:\Arquivos de programas\eSnips\ClientGW.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\RunOnce: [ GbPluginUni] RunDll32.exe C:\ARQUIV~1\GbPlugin\gbiehUni.dll,Gbieh

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [NBJ] "C:\Arquivos de programas\Ahead\Nero BackItUp\NBJ.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/stg_drm.ocx

O16 - DPF: {31CB2F01-72C2-4CF4-B265-450E8817B039} (Toontown IE Helper Portuguese) - http://idownload.br.toontown.com/sv1.4.22.6/ttinst-portuguese.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab

O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.oifotos.com/custom/send3/ImageUploader5.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Arquivos%20de%20programas/Bejeweled%202/Images/armhelper.ocx

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} (GbPluginObj Class) - https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{27D4895C-B9D5-4547-BE37-98EB075148C3}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS4\Services\Tcpip\..\{27D4895C-B9D5-4547-BE37-98EB075148C3}: NameServer = 200.149.55.140 200.165.132.147

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O20 - Winlogon Notify: GbPluginUni - C:\ARQUIV~1\GbPlugin\gbiehuni.dll

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe

 

--

End of file - 12079 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Rodrigo Rocha RJ

 

Corrompido : C:\Arquivos de programas\Spybot - Search & Destroy\blindman.exe

[Offset = 00000104 - Valor = 0x0001]

 

Corrompido : C:\Arquivos de programas\Spybot - Search & Destroy\Update.exe

[Offset = 00000104 - Valor = 0x0001]

<!> FindyKill reportou arquivos corrompidos em seu antispyware. ( Spybot )

<!> Desinstale-o e instale-o novamente. Procure atualizá-lo!

°°°°°°°°°°°°°°°°°°°°°°°°°°°

°°°°°°°°°°°°°°°°°°°°°°°°°°°

<@> Desinstale o UsbFix,pela sua opção 5,ao executá-lo!

°°°°°°°°°°°°°°°°°°°°°°°°°°°

°°°°°°°°°°°°°°°°°°°°°°°°°°°

<@> Baixe: < Pocket Killbox >

<@> Salve-o no Desktop!

<@> Abra o KillBox --> Marque a opção: Delete on Reboot

<@> Marque a caixa: "End Explorer Shell While Killing File" --> Minimize a ferramenta!

<@> Copie o(s) ficheiro(s),sob o QUOTE,para o Bloco de Notas.

<@> Estando desconectado,acesse o Bloco de Notas e execute estes atalhos: ( ctrl + a ) --> ( ctrl + c )

 

C:\WINDOWS\system32\wintems.exe

<@> No KillBox,que estava minimizado,clique em File --> Paste from Clipboard --> All Files.

<@> Clique no X e,na pergunta,diga Não!

<@> Reinicie o computador! <-- Importante!

<@> Vá até a pasta: C:\!KillBox...que foi gerada!

<@> Poste o relatório,que está em seu interior! ( C:\!KillBox\Logs\kb.log )

°°°°°°°°°°°°°°°°°°°°°°°°°°°

°°°°°°°°°°°°°°°°°°°°°°°°°°°

<@> Abra o HijackThis --> Clique: Do a system scan only

<@> Marque,abaixo,estas entradas:

 

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 217.72.199.106:80

 

R3 - URLSearchHook: (no name) - {982CB676-38F0-4D9A-BB72-D9371ABE876E} - (no file)

 

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

 

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

 

O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe

 

<@> Com todos os programas fechados,clique em Fix checked --> Sim!

<@> Poste: kb.log + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá DigRam,

 

Pocket Killbox version 2.0.0.978

Running on Windows XP as Rodrigo Rocha(Administrator)

was started @ domingo, dezembro 20, 2009, 4:34 PM

 

Killbox Closed(Exit) @ 4:36:04 PM

__________________________________________________

 

Pocket Killbox version 2.0.0.978

Running on Windows XP as Rodrigo Rocha(Administrator)

was started @ domingo, dezembro 20, 2009, 4:36 PM

 

Killbox Closed(Exit) @ 4:37:39 PM

__________________________________________________

 

Pocket Killbox version 2.0.0.978

Running on Windows XP as Rodrigo Rocha(Administrator)

was started @ domingo, dezembro 20, 2009, 4:37 PM

 

Killbox Closed(Exit) @ 4:43:52 PM

__________________________________________________

 

Pocket Killbox version 2.0.0.978

Running on Windows XP as Rodrigo Rocha(Administrator)

was started @ domingo, dezembro 20, 2009, 4:44 PM

 

# 1 [Delete on Reboot]

Path = C:\Arquivos de programas\Spybot - Search & Destroy\blindman.exe

 

 

# 2 [Delete on Reboot]

Path = C:\Arquivos de programas\Spybot - Search & Destroy\Update.exe

 

 

# 3 [Delete on Reboot]

Path = C:\Arquivos de programas\Spybot - Search & Destroy\blindman.exe

 

 

# 4 [Delete on Reboot]

Path = C:\Arquivos de programas\Spybot - Search & Destroy\Update.exe

 

 

Killbox Closed(Exit) @ 4:57:17 PM

__________________________________________________

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.