raphaelfx 0 Denunciar post Postado Maio 4, 2010 Olá, Meu Windows XP depois de um certo tempo (tempo varia, não tem um tempo fixo) perde conexão com a internet. Já testei meu modem em outros computadores e a conexão somente perde neste. O estranho é que a internet para de funcionar do nada, o ícone de conexão continua ativo porém para de responder. Ao tentar reparar a conexão recebo um erro, e não repara de jeito nenhum. O único modo é reiniciar o computador dai volta tudo ao normal, e depois de algum tempo cai novamente. Já tentei verificar se era algum programa desconectando mas não achei nada anormal, o estranho é que o ícone de conexão fica ativo como se a internet estivesse funcionando. Penso também que não seja o driver da placa de rede, já que meu modem banda larga tem conexões ethernet e usb, e isso acontece nas duas conexões. Todos os dias acontece isso, porém ontem a conexão permaneceu ativa o dia todo Segue log: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 20:37:20, on 4/5/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Eset\nod32kui.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\vsnpstd3.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\REALTEK\RTL8187 Wireless LAN Utility\RtWLan.exe C:\Arquivos de programas\Clarus\Samsung SecretZone\MSSvc.exe C:\Arquivos de programas\Eset\nod32krn.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE C:\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Arquivos de programas\Megaupload\Mega Manager\MegaIEMn.dll O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll O4 - HKLM\..\Run: [nod32kui] "C:\Arquivos de programas\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user') O4 - Global Startup: REALTEK RTL8187 Wireless LAN Utility.lnk = C:\Arquivos de programas\REALTEK\RTL8187 Wireless LAN Utility\RtWLan.exe O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Dados de aplicativos\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.1.66.0.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing) O23 - Service: ClipSrv - Unknown owner - C:\WINDOWS\system32\clipsrv.exe (file missing) O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe (file missing) O23 - Service: Virtual Disk Service Manager (MSR Service) - Unknown owner - C:\Arquivos de programas\Clarus\Samsung SecretZone\MSSvc.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Arquivos de programas\Eset\nod32krn.exe O23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing) -- End of file - 6151 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Maio 8, 2010 Bom Dia! raphaelfx <@> Baixe: < ToolBar S&D > <@> Salve-o no Disco Local-C,em uma pasta própria. <@> Reinicie o computador,em Modo de Segurança. <-- Importante! <@> Execute o programa,e à seguir,aperte o "p" --> Enter --> Ok. <@> Digite o dois! ( 2 ) --> Aperte Enter --> Aguarde! <@> Terminando,poste o relatório. ( C:\ToolBar SD\TB_1.txt ) <-- 000000000000000000000 ooooooooooooooooooooo <@> Baixe: < Malwarebytes' Anti-Malware > <@> Link - 2: < > <@> Ps: Salve ou imprima estas instruções: - Dê um duplo-clique no mbam-setup.exe;escolha a linguagem e,na instalação,aceite todas as opções padrão.- Verifique se as caixas: "Atualizar Malwarebytes Anti-Malware" e "Executar Malwarebytes Anti-Malware" estão marcadas. - Clique,à seguir,em Concluir - Ps: Se houver atualizações a serem feitas,serão baixadas e instaladas. - Ao final da atualização,com o programa aberto, marque: Verificação Rápida - Clique no botão Verificar. - Começará então o exame. -> Aguarde,pois pode demorar! - Concluindo,clique em OK e depois no botão "Mostrar Resultados",para dispormos do relatório. - Ps: Se houver ítens encontrados,marque-os e clique no botão "Remover". - Ps: Ao final da desinfecção,abrir-se-á o Bloco de notas contendo o relatório. - Ps: O log será armazenado,automáticamente,pela ferramenta. - Ps: Obtenha-o clicando na aba "Logs" na janela principal do Programa. <@> Ps: Caso o MBAM encontre arquivos que não consiga remover,poderá ter de reiniciar o PC. Talvez mais de uma vez! <@> Ps: Faça isso imediatamente,ao ser perguntado se quer reiniciar. 0000000000000000000 <!> Selecione, copie e cole o conteúdo do log do MBAM,na sua próxima resposta. <!> Poste,também,HijackThis atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
raphaelfx 0 Denunciar post Postado Maio 9, 2010 ToolBar S&D -----------\\ ToolBar S&D 1.2.9 XP/Vista Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3 X86-based PC ( Multiprocessor Free : Intel® Core2 Duo CPU T5250 @ 1.50GHz ) BIOS : BIOS Version : 1.00 USER : Administrador ( Administrator ) BOOT : Fail-safe with network boot C:\ (Local Disk) - NTFS - Total:111 Go (Free:85 Go) D:\ (CD or DVD) "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 ) Option : [2] ( s b 08/05/2010|21:19 ) -----------\\ Procura por Arquivos / Ficheiros ... -----------\\ Extensions (Administrador) - {12e4c684-c03e-4e4d-85bc-0c065e7a9489} => shoutcasttoolbar (Administrador) - {87F8774F-B485-47E2-A755-A40A8A5E8874} => gbmzhabn -----------\\ [..\Internet Explorer\Main] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Local Page"="C:\\WINDOWS\\system32\\blank.htm" "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome" "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"'>http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://www.msn.com/" --------------------\\ Procurando por outras infecções Não foram encontradas outras infecções. 1 - "C:\ToolBar SD\TB_1.txt" - s b 08/05/2010|21:19 - Option : [2] ------------------------ ------------------------ Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Versão da Base de Dados: 4079 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 8/5/2010 21:42:34 mbam-log-2010-05-08 (21-42-34).txt Tipo de Verificação: Verificação Rápida Objetos escaneados: 120330 Tempo decorrido: 4 minuto(s), 54 segundo(s) Processos de Memória Infectados: 0 Módulos de Memória Infectados: 0 Chaves de Registro Infectadas: 0 Valores de Registro Infectados: 0 Itens de Dados no Registro Infectados: 0 Pastas Infectadas: 0 Arquivos Infectados: 0 Processos de Memória Infectados: (Não foram detectados ítens maliciosos) Módulos de Memória Infectados: (Não foram detectados ítens maliciosos) Chaves de Registro Infectadas: (Não foram detectados ítens maliciosos) Valores de Registro Infectados: (Não foram detectados ítens maliciosos) Itens de Dados no Registro Infectados: (Não foram detectados ítens maliciosos) Pastas Infectadas: (Não foram detectados ítens maliciosos) Arquivos Infectados: (Não foram detectados ítens maliciosos) HIJACKTHIS: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 21:43:47, on 8/5/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Eset\nod32kui.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Clarus\Samsung SecretZone\MSSvc.exe C:\WINDOWS\vsnpstd3.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Arquivos de programas\Eset\nod32krn.exe C:\WINDOWS\system32\igfxpers.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\REALTEK\RTL8187 Wireless LAN Utility\RtWLan.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Arquivos de programas\Megaupload\Mega Manager\MegaIEMn.dll O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll O4 - HKLM\..\Run: [nod32kui] "C:\Arquivos de programas\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [steam] "C:\Arquivos de programas\Steam\Steam.exe" -silent O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user') O4 - Global Startup: REALTEK RTL8187 Wireless LAN Utility.lnk = C:\Arquivos de programas\REALTEK\RTL8187 Wireless LAN Utility\RtWLan.exe O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Dados de aplicativos\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.1.66.0.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing) O23 - Service: ClipSrv - Unknown owner - C:\WINDOWS\system32\clipsrv.exe (file missing) O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe (file missing) O23 - Service: Virtual Disk Service Manager (MSR Service) - Unknown owner - C:\Arquivos de programas\Clarus\Samsung SecretZone\MSSvc.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Arquivos de programas\Eset\nod32krn.exe O23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing) -- End of file - 6219 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Maio 9, 2010 Boa Tarde! raphaelfx <@> Baixe: < OTL > ( ...by OldTimer Tools ) <@> Salve-o no desktop! <@> Clique duplo em: < > <@> Ps: Sigamos,agora,com sua configuração! 1 - Em "Saída",deixe marcado o botão "Resumida". 2 - Marque as caixas: Verificar All Users e Incluir Verificação 64bit <-- Ps: Caso o SO seja 64 bit! 3 - Processos: Usar SafeList <-- Marque! 4 - Módulos: Usar SafeList <-- Marque! 5 - Serviços: Usar SafeList <-- Marque! 6 - Drivers: Usar SafeList <-- Marque! 7 - Exame Padrão do Registro: Usar SafeList <-- Marque! 8 - Exame Extra do Registro: Usar SafeList <-- Marque! 9 - Verificação de Arquivos: <!> Data de Criação >> Escolha: 14 dias <!> Marque: Usar WhiteList para Nomes de Companhias <!> Marque: Ignorar Arquivos Microsoft 10 - Arquivos Criados Desde: <!> Marque: Data de Criação 11 - Arquivos Modificados Desde: <!> Marque: Data de Criação <!> Marque as caixas: [] Verificar Lop [] Verificar Purity <@> Ps: Sugiro que imprima estas orientações,para posterior leitura. <@> Clique em: Verificar --> Aguarde! <@> Concluindo,poste: <1> OTL.txt <-- <2> Extra.txt <-- Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
raphaelfx 0 Denunciar post Postado Maio 9, 2010 EXTRAS TXT: OTL Extras logfile created on: 9/5/2010 15:34:46 - Run 1 OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\Administrador\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 78,00% Memory free 5,00 Gb Paging File | 4,00 Gb Available in Paging File | 90,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas Drive C: | 111,78 Gb Total Space | 85,97 Gb Free Space | 76,91% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ADMIN Current User Name: Administrador Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation) [HKEY_USERS\S-1-5-21-1177238915-1229272821-1606980848-500\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. https [open] -- "C:\Arquivos de programas\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\ARQUIV~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Directory [Winamp.Bookmark] -- "C:\Arquivos de programas\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.) Directory [Winamp.Enqueue] -- "C:\Arquivos de programas\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.) Directory [Winamp.Play] -- "C:\Arquivos de programas\Winamp\winamp.exe" "%1" (Nullsoft, Inc.) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirewallDisableNotify" = 0 "AntiVirusDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "3316:TCP" = 3316:TCP:*:Enabled:vblowdrn ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" = C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" = C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation) "C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation) "C:\Arquivos de programas\Microsoft Office\Office12\GROOVE.EXE" = C:\Arquivos de programas\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- (Microsoft Corporation) "C:\Arquivos de programas\Microsoft Office\Office12\ONENOTE.EXE" = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation) "C:\Arquivos de programas\uTorrent\uTorrent.exe" = C:\Arquivos de programas\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- () "C:\Arquivos de programas\Steam\Steam.exe" = C:\Arquivos de programas\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "_{51DD370C-6690-424E-9674-5F14468B323F}" = Corel Graphics - Windows Shell Extension "_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW® Graphics Suite X5 "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam "{08C0729E-3E50-11DF-9D81-005056806466}" = Google Earth "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{24D9A3E0-D086-4B62-AF93-63CF6B05CB48}" = CorelDRAW Graphics Suite X5 - Custom Data "{260ED378-2B8C-4831-ADAE-D0712D119AC5}" = CorelDRAW Graphics Suite X5 - VSTA "{26945917-E053-45F6-AF98-309730CFC318}" = Visual Basic for Applications ® Core "{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime "{32BC546A-8AA3-4239-AE92-9CF3291C35A6}" = Windows Live Call "{3472C84E-2FD0-439F-B27F-C290C1E4CD8B}" = CorelDRAW Graphics Suite X5 - Filters "{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager "{41BB38A4-ED84-4682-8329-042FEBD8C30B}" = Mega Manager "{51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}" = Assistente de Conexão do Windows Live "{51DD370C-6690-424E-9674-5F14468B323F}" = Corel Graphics - Windows Shell Extension "{54B8F4A1-02B0-4D32-8F37-925526C0EEC6}" = CorelDRAW Graphics Suite X5 - Connect "{57400C1E-BC51-4ECE-AD2A-A6096204DDEC}" = CorelDRAW Graphics Suite X5 - VBA "{59123CCF-FED2-46FF-9293-D1DC80042219}" = CorelDRAW Graphics Suite X5 - Redist "{62978C1C-FE2E-4A4E-851D-3EB406C9EBC2}" = CorelDRAW Graphics Suite X5 - Draw "{66491E5A-7899-4863-A2E9-057E10BCB578}" = Samsung SecretZone "{89B078C4-50B0-453E-BF53-3A7E6A0D85FA}" = Windows Support Tools "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{90120000-0010-0416-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Portuguese (Brazil)) 12 "{90120000-0015-0416-0000-0000000FF1CE}" = Microsoft Office Access MUI (Portuguese (Brazil)) 2007 "{90120000-0015-0416-0000-0000000FF1CE}_ENTERPRISE_{B818F15C-FA76-4262-AB26-C04D0772EED8}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0016-0416-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Portuguese (Brazil)) 2007 "{90120000-0016-0416-0000-0000000FF1CE}_ENTERPRISE_{B818F15C-FA76-4262-AB26-C04D0772EED8}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0018-0416-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2007 "{90120000-0018-0416-0000-0000000FF1CE}_ENTERPRISE_{B818F15C-FA76-4262-AB26-C04D0772EED8}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0019-0416-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Portuguese (Brazil)) 2007 "{90120000-0019-0416-0000-0000000FF1CE}_ENTERPRISE_{B818F15C-FA76-4262-AB26-C04D0772EED8}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001A-0416-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Portuguese (Brazil)) 2007 "{90120000-001A-0416-0000-0000000FF1CE}_ENTERPRISE_{B818F15C-FA76-4262-AB26-C04D0772EED8}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001B-0416-0000-0000000FF1CE}" = Microsoft Office Word MUI (Portuguese (Brazil)) 2007 "{90120000-001B-0416-0000-0000000FF1CE}_ENTERPRISE_{B818F15C-FA76-4262-AB26-C04D0772EED8}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007 "{90120000-001F-0416-0000-0000000FF1CE}_ENTERPRISE_{669EB263-0AFE-4FCB-A068-DB082CA6273C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-002C-0416-0000-0000000FF1CE}" = Microsoft Office Proofing (Portuguese (Brazil)) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-0044-0416-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2007 "{90120000-0044-0416-0000-0000000FF1CE}_ENTERPRISE_{B818F15C-FA76-4262-AB26-C04D0772EED8}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-006E-0416-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Portuguese (Brazil)) 2007 "{90120000-006E-0416-0000-0000000FF1CE}_ENTERPRISE_{98003BDC-1B68-4970-B28E-ACC8000D2F3E}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-00A1-0416-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Portuguese (Brazil)) 2007 "{90120000-00A1-0416-0000-0000000FF1CE}_ENTERPRISE_{B818F15C-FA76-4262-AB26-C04D0772EED8}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{90120000-00B0-0409-0000-0000000FF1CE}" = Microsoft Save as PDF Add-in for 2007 Microsoft Office programs "{90120000-00BA-0416-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Portuguese (Brazil)) 2007 "{90120000-00BA-0416-0000-0000000FF1CE}_ENTERPRISE_{B818F15C-FA76-4262-AB26-C04D0772EED8}" = 2007 Microsoft Office Suite Service Pack 1 (SP1) "{9244E956-5939-4B88-930C-0699D4AB2B95}" = CorelDRAW Graphics Suite X5 - WT "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{983F7145-CABF-4EDD-9F3D-E06B2F024BD3}" = CorelDRAW Graphics Suite X5 - FontNav "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{A1B04B6B-25BB-48AD-8BD9-D31A86E89F3E}" = CorelDRAW Graphics Suite X5 - PHOTO-PAINT "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU "{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver "{B399C91E-96F2-4265-9884-1C9A10E9FCF4}" = CorelDRAW Graphics Suite X5 "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B5ED7AB0-3838-4389-8549-7C8E22DD48F4}" = Windows Live Messenger "{BE686891-3C56-4714-AFEF-341A7867BA80}" = REALTEK RTL8187 Wireless LAN Driver and Utility "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C676866D-A632-4FC0-AA28-8989088BC320}_is1" = Foxit PDF Reader 2.3 Build 2825 "{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver "{CA3861BA-1D96-4D66-B577-318E1602C4F3}" = CorelDRAW Graphics Suite X5 - Common "{CA86CD92-22BB-4BBE-A6A5-BF1B4BAD791A}" = SMS "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW Graphics Suite X5 - Setup Files "{D596EEA2-C6C8-45D3-89DF-FA2DBE99F829}" = Visual Basic for Applications ® Core - English "{D642FF8D-438D-4545-A1D5-2EDB4BCAE3BA}" = CorelDRAW Graphics Suite X5 - Photozoom Plugin "{DBC3FDEC-D5F4-439C-9A18-EF454A74E3DE}_is1" = NOD32 FiX v2.1 "{DE6CBC04-8673-4DBA-BA81-07F1639CEB5F}" = CorelDRAW Graphics Suite X5 - IPM "{E29D8938-2E48-498C-832D-9663DCABD55F}" = Visual Basic for Applications ® Core - Portuguese (Brazil) "{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = LG_webpro2 camera "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform "{EDB98D5A-A6FB-425C-BFB7-51A0924B762D}" = CorelDRAW Graphics Suite X5 - Capture "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F2CD4651-F948-467C-B014-71FD981B7F59}" = Windows Live Essentials "{F7FC9307-374E-4017-8E9D-DE1154780480}" = System Requirements Lab for Intel "{FD8AE9E2-B61E-4826-9CE7-937E1E9A9EEC}" = CorelDRAW Graphics Suite X5 - BR "{FE4B83DE-85CF-4DE5-90CE-A2735A0E1F21}" = CorelDRAW Graphics Suite X5 - VideoBrowser "7-Zip" = 7-Zip 4.57 "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "BlazeDTV 6.0_is1" = BlazeDTV 6.0 "ENTERPRISE" = Microsoft Office Enterprise 2007 "FBDBServer_1_5_is1" = Firebird 1.5.3.4870 "HDMI" = Intel® Graphics Media Accelerator Driver "HospitalTycoon" = Hospital Tycoon "InstallShield_{CA86CD92-22BB-4BBE-A6A5-BF1B4BAD791A}" = SMS "KLiteCodecPack_is1" = K-Lite Codec Pack 5.8.3 (Full) "LeechFTP" = LeechFTP "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.5.9)" = Mozilla Firefox (3.5.9) "NOD32" = NOD32 sistema antivírus "SHOUTcast Radio Toolbar" = SHOUTcast Radio Toolbar "SHOUTcastDSP" = SHOUTcast Source DSP 1.9.1 (remove only) "SimpleCast" = SimpleCast (remove only) "Steam App 240" = Counter-Strike: Source "The KMPlayer" = The KMPlayer (remove only) "Winamp" = Winamp "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = Arquivo do WinRAR ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1177238915-1229272821-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "uTorrent" = µTorrent "Winamp Detect" = Winamp: Detectar Aplicação ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 28/4/2010 13:51:24 | Computer Name = ADMIN | Source = Google Update | ID = 20 Description = Error - 29/4/2010 06:04:28 | Computer Name = ADMIN | Source = Google Update | ID = 20 Description = Error - 29/4/2010 07:04:28 | Computer Name = ADMIN | Source = Google Update | ID = 20 Description = Error - 30/4/2010 21:57:43 | Computer Name = ADMIN | Source = Google Update | ID = 20 Description = Error - 1/5/2010 07:09:23 | Computer Name = ADMIN | Source = Google Update | ID = 20 Description = Error - 1/5/2010 18:16:55 | Computer Name = ADMIN | Source = Google Update | ID = 20 Description = Error - 2/5/2010 11:13:26 | Computer Name = ADMIN | Source = Google Update | ID = 20 Description = Error - 3/5/2010 03:28:21 | Computer Name = ADMIN | Source = Google Update | ID = 20 Description = Error - 3/5/2010 04:28:21 | Computer Name = ADMIN | Source = Google Update | ID = 20 Description = Error - 3/5/2010 05:28:21 | Computer Name = ADMIN | Source = Google Update | ID = 20 Description = [ System Events ] Error - 3/5/2010 11:43:31 | Computer Name = ADMIN | Source = DCOM | ID = 10005 Description = Erro "%1058" no DCOM na tentativa de iniciar o serviço BITS com argumentos "" para iniciar o servidor: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 3/5/2010 14:01:20 | Computer Name = ADMIN | Source = DCOM | ID = 10005 Description = Erro "%1058" no DCOM na tentativa de iniciar o serviço BITS com argumentos "" para iniciar o servidor: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 3/5/2010 16:17:48 | Computer Name = ADMIN | Source = DCOM | ID = 10005 Description = Erro "%1058" no DCOM na tentativa de iniciar o serviço BITS com argumentos "" para iniciar o servidor: {4991D34B-80A1-4291-83B6-3328366B9097} Error - 5/5/2010 16:47:06 | Computer Name = ADMIN | Source = Dhcp | ID = 1002 Description = A concessão 192.168.100.2 do endereço IP para a placa de rede com endereço de rede 00240147EBE7 foi negada pelo servidor DHCP 10.15.1.5 (O servidor DHCP enviou uma mensagem DHCPNACK). Error - 7/5/2010 09:40:45 | Computer Name = ADMIN | Source = Dhcp | ID = 1002 Description = A concessão 192.168.100.2 do endereço IP para a placa de rede com endereço de rede 00240147EBE7 foi negada pelo servidor DHCP 10.15.1.5 (O servidor DHCP enviou uma mensagem DHCPNACK). Error - 7/5/2010 09:48:32 | Computer Name = ADMIN | Source = Dhcp | ID = 1002 Description = A concessão 200.160.83.2 do endereço IP para a placa de rede com endereço de rede 00240147EBE7 foi negada pelo servidor DHCP 192.168.100.1 (O servidor DHCP enviou uma mensagem DHCPNACK). Error - 7/5/2010 09:49:35 | Computer Name = ADMIN | Source = Dhcp | ID = 1002 Description = A concessão 192.168.100.2 do endereço IP para a placa de rede com endereço de rede 00240147EBE7 foi negada pelo servidor DHCP 10.15.1.5 (O servidor DHCP enviou uma mensagem DHCPNACK). Error - 8/5/2010 20:18:29 | Computer Name = ADMIN | Source = DCOM | ID = 10005 Description = Erro "%1084" no DCOM na tentativa de iniciar o serviço EventSystem com argumentos "" para iniciar o servidor: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error - 8/5/2010 20:18:39 | Computer Name = ADMIN | Source = DCOM | ID = 10005 Description = Erro "%1084" no DCOM na tentativa de iniciar o serviço StiSvc com argumentos "" para iniciar o servidor: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Error - 8/5/2010 20:20:20 | Computer Name = ADMIN | Source = DCOM | ID = 10005 Description = Erro "%1084" no DCOM na tentativa de iniciar o serviço EventSystem com argumentos "" para iniciar o servidor: {1BE1F766-5536-11D1-B726-00C04FB926AF} < End of report > ________________________________________ OTL.TXT: OTL logfile created on: 9/5/2010 15:34:46 - Run 1 OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\Administrador\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.5512) Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy 3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 78,00% Memory free 5,00 Gb Paging File | 4,00 Gb Available in Paging File | 90,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas Drive C: | 111,78 Gb Total Space | 85,97 Gb Free Space | 76,91% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ADMIN Current User Name: Administrador Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 14 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Administrador\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Arquivos de programas\Eset\nod32kui.exe (Eset ) PRC - C:\Arquivos de programas\Eset\nod32krn.exe (Eset ) PRC - C:\Arquivos de programas\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Arquivos de programas\Clarus\Samsung SecretZone\MSSvc.exe () PRC - C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\Arquivos de programas\Outlook Express\msimn.exe (Microsoft Corporation) PRC - C:\Arquivos de programas\REALTEK\RTL8187 Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.) PRC - C:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE (Microsoft Corporation) PRC - C:\WINDOWS\vsnpstd3.exe (Sonix) ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Administrador\Desktop\OTL.exe (OldTimer Tools) MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (UPS) -- File not found SRV - (gupdate) Google Update Service (gupdate) -- File not found SRV - (ClipSrv) -- File not found SRV - (CiSvc) -- File not found SRV - (NOD32krn) -- C:\Arquivos de programas\Eset\nod32krn.exe (Eset ) SRV - (MSR Service) -- C:\Arquivos de programas\Clarus\Samsung SecretZone\MSSvc.exe () SRV - (odserv) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation) SRV - (ose) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (mvd20) -- File not found DRV - (mdf15) -- File not found DRV - (AMON) -- C:\WINDOWS\system32\drivers\amon.sys (Eset ) DRV - (nod32drv) -- C:\WINDOWS\system32\drivers\nod32drv.sys () DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.) DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation ) DRV - (ialm) -- C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation) DRV - (cpudrv) -- C:\Arquivos de programas\SystemRequirementsLab\cpudrv.sys () DRV - (smsbda) -- C:\WINDOWS\system32\drivers\smsbda.sys (Siano) DRV - (Monfilt) -- C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.) DRV - (Ambfilt) -- C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative) DRV - (RTLWUSB) -- C:\WINDOWS\system32\drivers\RTL8187.sys (Realtek Semiconductor Corporation ) DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider) DRV - (USB_RNDIS) -- C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation) DRV - (MPE) -- C:\WINDOWS\system32\drivers\MPE.sys (Microsoft Corporation) DRV - (usbaudio) Driver de áudio USB (WDM) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation) DRV - (SNPSTD3) USB PC Camera (SNPSTD3) -- C:\WINDOWS\system32\drivers\snpstd3.sys () DRV - (Aspi32) -- C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/ IE - HKLM\..\URLSearchHook: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC) IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\..\URLSearchHook: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC) IE - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Winamp Search" FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50-ff-shoutcast-chromesbox-en-us&query=" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..extensions.enabledItems: {87F8774F-B485-47E2-A755-A40A8A5E8874}:1.0.7.10 FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50-ff-shoutcast-ab-en-us&query=" FF - prefs.js..network.proxy.http: "200.162.112.16" FF - prefs.js..network.proxy.http_port: 80 FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox\components [2010/05/04 09:58:30 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox\plugins [2010/05/04 09:58:30 | 000,000,000 | ---D | M] [2010/04/22 12:23:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Extensions [2010/05/07 22:17:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\snqwy47q.default\extensions [2010/04/21 23:08:48 | 000,000,000 | ---D | M] (SHOUTcast Radio Toolbar) -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\snqwy47q.default\extensions\{12e4c684-c03e-4e4d-85bc-0c065e7a9489} [2010/04/24 12:03:06 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\snqwy47q.default\extensions\{87F8774F-B485-47E2-A755-A40A8A5E8874} [2010/04/21 23:08:55 | 000,001,184 | ---- | M] () -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\snqwy47q.default\searchplugins\winamp-search.xml [2010/04/22 12:23:30 | 000,000,000 | ---D | M] -- C:\Arquivos de programas\Mozilla Firefox\extensions [2009/08/03 15:07:42 | 000,373,104 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\Mozilla Firefox\plugins\npOGAPlugin.dll [2010/01/13 19:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Arquivos de programas\Mozilla Firefox\plugins\npwachk.dll [2010/03/15 14:24:11 | 000,001,027 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\buscape.xml [2010/03/15 14:24:11 | 000,001,212 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\mercadolivre.xml [2010/03/15 14:24:11 | 000,001,168 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\wikipedia-br.xml [2010/03/15 14:24:11 | 000,000,648 | ---- | M] () -- C:\Arquivos de programas\Mozilla Firefox\searchplugins\yahoo-br.xml O1 HOSTS File: ([2008/04/14 09:00:00 | 000,000,776 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Arquivos de programas\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited) O2 - BHO: (SHOUTcast Loader) - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC) O3 - HKLM\..\Toolbar: (SHOUTcast Radio Toolbar) - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC) O3 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\..\Toolbar\WebBrowser: (SHOUTcast Radio Toolbar) - {0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC) O4 - HKLM..\Run: [nod32kui] C:\Arquivos de programas\Eset\nod32kui.exe (Eset ) O4 - HKLM..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe (Sonix) O4 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O4 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500..\Run: [steam] C:\Arquivos de programas\Steam\Steam.exe (Valve Corporation) O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\REALTEK RTL8187 Wireless LAN Utility.lnk = C:\Arquivos de programas\REALTEK\RTL8187 Wireless LAN Utility\RtWLan.exe (Realtek Semiconductor Corp.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideRunAsVerb = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\S-1-5-21-1177238915-1229272821-1606980848-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0 O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Dados de aplicativos\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html () O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de programas\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Arquivos de programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\imon.dll (Eset ) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\imon.dll (Eset ) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\imon.dll (Eset ) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\imon.dll (Eset ) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\imon.dll (Eset ) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\imon.dll (Eset ) O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.1.66.0.cab (SysInfo Class) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - c:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation) O24 - Desktop Components:0 (Minha página inicial atual) - About:Home O24 - Desktop BackupWallPaper: O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010/04/19 10:59:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 14 Days ========== [2010/05/09 15:32:53 | 000,570,880 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrador\Desktop\OTL.exe [2010/05/08 21:13:38 | 000,000,000 | ---D | C] -- C:\ToolBar SD [2010/05/06 23:46:56 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Steam [2010/05/06 21:28:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Desktop\nocster [2010/05/06 00:15:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Help [2010/05/06 00:15:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Help [2010/05/04 20:37:02 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\HiJackThis.exe [2010/05/04 18:58:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Media Player Classic [2010/05/04 10:03:18 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Support Tools [2010/05/04 10:00:10 | 000,099,865 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\xlog.exe [2010/05/04 10:00:07 | 000,016,970 | ---- | C] (US Robotics MCD (Megahertz)) -- C:\WINDOWS\System32\dllcache\xem336n5.sys [2010/05/04 09:59:39 | 000,154,624 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\wlluc48.sys [2010/05/04 09:59:39 | 000,034,890 | ---- | C] (Raytheon Corp.) -- C:\WINDOWS\System32\dllcache\wlandrv2.sys [2010/05/04 09:59:30 | 000,771,581 | ---- | C] (Rockwell) -- C:\WINDOWS\System32\dllcache\winacisa.sys [2010/05/04 09:59:19 | 000,035,871 | ---- | C] (Winbond Electronics Corp.) -- C:\WINDOWS\System32\dllcache\wbfirdma.sys [2010/05/04 09:59:02 | 000,016,925 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w940nd.sys [2010/05/04 09:59:01 | 000,019,016 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w926nd.sys [2010/05/04 09:58:59 | 000,019,528 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w840nd.sys [2010/05/04 09:58:56 | 000,064,605 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vvoice.sys [2010/05/04 09:58:55 | 000,397,502 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vpctcom.sys [2010/05/04 09:58:50 | 000,604,253 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\vmodem.sys [2010/05/04 09:58:49 | 000,249,402 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\vinwm.sys [2010/05/04 09:58:40 | 000,765,884 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usrti.sys [2010/05/04 09:58:36 | 000,794,399 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806v.sys [2010/05/04 09:58:35 | 000,793,598 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806.sys [2010/05/04 09:58:33 | 000,794,654 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1801.sys [2010/05/04 09:58:24 | 000,032,384 | ---- | C] (KLSI USA, Inc.) -- C:\WINDOWS\System32\dllcache\usb101et.sys [2010/05/04 09:58:09 | 000,525,568 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxp.dll [2010/05/04 09:58:09 | 000,166,784 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxpm.sys [2010/05/04 09:58:08 | 000,440,576 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkb.dll [2010/05/04 09:58:08 | 000,159,232 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkbm.sys [2010/05/04 09:58:05 | 000,315,520 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3d.dll [2010/05/04 09:58:05 | 000,222,336 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3dm.sys [2010/05/04 09:57:57 | 000,123,995 | ---- | C] (Tiger Jet Network) -- C:\WINDOWS\System32\dllcache\tjisdn.sys [2010/05/04 09:57:51 | 000,138,528 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiulnt5.sys [2010/05/04 09:57:51 | 000,081,408 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiul50.dll [2010/05/04 09:57:50 | 000,149,376 | ---- | C] (M-Systems) -- C:\WINDOWS\System32\dllcache\tffsport.sys [2010/05/04 09:57:47 | 000,037,961 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdk100b.sys [2010/05/04 09:57:47 | 000,017,129 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdkcd31.sys [2010/05/04 09:57:36 | 000,036,640 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\t2r4mini.sys [2010/05/04 09:57:35 | 000,172,768 | ---- | C] (Number Nine Visual Technology) -- C:\WINDOWS\System32\dllcache\t2r4disp.dll [2010/05/04 09:57:27 | 000,017,024 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\stcusb.sys [2010/05/04 09:57:24 | 000,048,736 | ---- | C] (3Com) -- C:\WINDOWS\System32\dllcache\srwlnd5.sys [2010/05/04 09:57:15 | 000,019,072 | ---- | C] (Adaptec, Inc.) -- C:\WINDOWS\System32\dllcache\sparrow.sys [2010/05/04 09:56:51 | 000,058,368 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smiminib.sys [2010/05/04 09:56:50 | 000,147,200 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smidispb.dll [2010/05/04 09:56:46 | 000,036,425 | ---- | C] (SMC) -- C:\WINDOWS\System32\dllcache\smcirda.sys [2010/05/04 09:56:46 | 000,025,034 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smcpwr2n.sys [2010/05/04 09:56:45 | 000,024,576 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smc8000n.sys [2010/05/04 09:56:35 | 000,094,890 | ---- | C] (SysKonnect GmbH.) -- C:\WINDOWS\System32\dllcache\sk98xwin.sys [2010/05/04 09:56:35 | 000,091,294 | ---- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) -- C:\WINDOWS\System32\dllcache\skfpwin.sys [2010/05/04 09:56:35 | 000,063,547 | ---- | C] (Symbol Technologies) -- C:\WINDOWS\System32\dllcache\sla30nd5.sys [2010/05/04 09:56:33 | 000,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\dllcache\sisnic.sys [2010/05/04 09:56:18 | 000,161,632 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmusb.sys [2010/05/04 09:56:16 | 000,018,400 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmld.sys [2010/05/04 09:56:15 | 000,386,560 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiul50.dll [2010/05/04 09:56:15 | 000,098,080 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiulnt5.sys [2010/05/04 09:55:53 | 000,017,408 | ---- | C] (SCM Microsystems) -- C:\WINDOWS\System32\dllcache\scr111.sys [2010/05/04 09:55:50 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmusbm.sys [2010/05/04 09:55:49 | 000,024,064 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmn50m.sys [2010/05/04 09:55:44 | 000,198,400 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4.dll [2010/05/04 09:55:44 | 000,077,824 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4m.sys [2010/05/04 09:55:42 | 000,210,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mvirge.dll [2010/05/04 09:55:42 | 000,179,264 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3d.dll [2010/05/04 09:55:42 | 000,062,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mtrio.dll [2010/05/04 09:55:42 | 000,061,504 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3dm.sys [2010/05/04 09:55:41 | 000,041,216 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.sys [2010/05/04 09:55:40 | 000,182,272 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.dll [2010/05/04 09:55:39 | 000,166,720 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3m.sys [2010/05/04 09:55:33 | 000,020,992 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8139.sys [2010/05/04 09:55:33 | 000,019,017 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\dllcache\rtl8029.sys [2010/05/04 09:55:24 | 000,037,563 | ---- | C] (RadioLAN) -- C:\WINDOWS\System32\dllcache\rlnet5.sys [2010/05/04 09:55:21 | 000,086,097 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\reslog32.dll [2010/05/04 09:55:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution [2010/05/04 09:54:55 | 000,715,242 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\r2mdmkxx.sys [2010/05/04 09:54:54 | 000,899,658 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\r2mdkxga.sys [2010/05/04 09:54:34 | 000,130,942 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserlv.sys [2010/05/04 09:54:34 | 000,128,286 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserli.sys [2010/05/04 09:54:34 | 000,112,574 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserlp.sys [2010/05/04 09:54:32 | 000,016,512 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\pscr.sys [2010/05/04 09:54:04 | 000,169,984 | ---- | C] (Cisco Systems) -- C:\WINDOWS\System32\dllcache\pcx500.sys [2010/05/04 09:54:03 | 000,086,016 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\pctspk.exe [2010/05/04 09:54:02 | 000,026,153 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pcmlm56.sys [2010/05/04 09:53:59 | 000,030,495 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pc100nds.sys [2010/05/04 09:53:59 | 000,029,502 | ---- | C] (Marconi Communications, Inc.) -- C:\WINDOWS\System32\dllcache\pca200e.sys [2010/05/04 09:53:49 | 000,054,698 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otcsercb.sys [2010/05/04 09:53:47 | 000,027,209 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otc06x5.sys [2010/05/04 09:53:45 | 000,054,528 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\opl3sax.sys [2010/05/04 09:53:33 | 000,051,552 | ---- | C] (Kensington Technology Group) -- C:\WINDOWS\System32\dllcache\ntgrip.sys [2010/05/04 09:53:20 | 000,087,040 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm6wdm.sys [2010/05/04 09:53:19 | 000,126,080 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm5a2wdm.sys [2010/05/04 09:53:18 | 000,032,840 | ---- | C] (NETGEAR Corporation.) -- C:\WINDOWS\System32\dllcache\ngrpci.sys [2010/05/04 09:53:16 | 000,132,695 | ---- | C] (802.11b) -- C:\WINDOWS\System32\dllcache\netwlan5.sys [2010/05/04 09:53:06 | 000,039,264 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.sys [2010/05/04 09:53:05 | 000,060,480 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.dll [2010/05/04 09:53:01 | 000,091,488 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i3disp.dll [2010/05/04 09:52:59 | 000,027,936 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i3d.sys [2010/05/04 09:52:58 | 000,059,104 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128v2.dll [2010/05/04 09:52:58 | 000,033,088 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128v2.sys [2010/05/04 09:52:57 | 000,035,392 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128.dll [2010/05/04 09:52:57 | 000,013,664 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128.sys [2010/05/04 09:52:54 | 000,019,968 | ---- | C] (Macronix International Co., Ltd. ) -- C:\WINDOWS\System32\dllcache\mxnic.sys [2010/05/04 09:52:51 | 000,103,296 | ---- | C] (Matrox Graphics Inc) -- C:\WINDOWS\System32\dllcache\mtxvideo.sys [2010/05/04 09:52:05 | 000,017,280 | ---- | C] (American Megatrends Inc.) -- C:\WINDOWS\System32\dllcache\mraid35x.sys [2010/05/04 09:51:36 | 000,165,290 | ---- | C] (Madge Networks Ltd) -- C:\WINDOWS\System32\dllcache\mdgndis5.sys [2010/05/04 09:51:24 | 000,797,500 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltsmt.sys [2010/05/04 09:51:22 | 000,802,683 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\ltsm.sys [2010/05/04 09:51:20 | 000,607,196 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmnt.sys [2010/05/04 09:51:20 | 000,577,226 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmntl.sys [2010/05/04 09:51:20 | 000,422,016 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmntt.sys [2010/05/04 09:51:19 | 000,728,298 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ltck000c.sys [2010/05/04 09:51:12 | 000,070,730 | ---- | C] (Linksys Group, Inc.) -- C:\WINDOWS\System32\dllcache\lne100tx.sys [2010/05/04 09:51:11 | 000,025,065 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\lmndis3.sys [2010/05/04 09:51:11 | 000,020,573 | ---- | C] (The Linksts Group ) -- C:\WINDOWS\System32\dllcache\lne100.sys [2010/05/04 09:51:06 | 000,016,128 | ---- | C] (Litronic Industries) -- C:\WINDOWS\System32\dllcache\lit220p.sys [2010/05/04 09:51:03 | 000,026,634 | ---- | C] (SMSC) -- C:\WINDOWS\System32\dllcache\lanepic5.sys [2010/05/04 09:51:02 | 000,019,016 | ---- | C] (Kingston Technology Company ) -- C:\WINDOWS\System32\dllcache\ktc111.sys [2010/05/04 09:50:27 | 000,023,552 | ---- | C] (MKNet Corporation) -- C:\WINDOWS\System32\dllcache\irmk7.sys [2010/05/04 09:50:13 | 000,045,632 | ---- | C] (Interphase ® Corporation a Windows ® 2000 DDK Driver Provider) -- C:\WINDOWS\System32\dllcache\ip5515.sys [2010/05/04 09:49:30 | 000,372,824 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\iconf32.dll [2010/05/04 09:48:38 | 000,028,544 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grserial.sys [2010/05/04 09:48:37 | 000,082,432 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grclass.sys [2010/05/04 09:48:34 | 000,017,664 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\gpr400.sys [2010/05/04 09:48:25 | 000,455,296 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fusbbase.sys [2010/05/04 09:48:25 | 000,454,912 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fxusbase.sys [2010/05/04 09:48:24 | 000,455,680 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fus2base.sys [2010/05/04 09:48:17 | 000,442,240 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpnpbase.sys [2010/05/04 09:48:16 | 000,444,416 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpcibase.sys [2010/05/04 09:48:16 | 000,441,728 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpcmbase.sys [2010/05/04 09:48:16 | 000,034,173 | ---- | C] (Marconi Communications, Inc.) -- C:\WINDOWS\System32\dllcache\forehe.sys [2010/05/04 09:48:06 | 000,024,618 | ---- | C] (NETGEAR) -- C:\WINDOWS\System32\dllcache\fa410nd5.sys [2010/05/04 09:48:05 | 000,012,362 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xi.sys [2010/05/04 09:48:05 | 000,011,850 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xj.sys [2010/05/04 09:47:47 | 000,072,192 | ---- | C] (ESS Technology Inc.) -- C:\WINDOWS\System32\dllcache\es1969.sys [2010/05/04 09:46:07 | 000,334,208 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\ds1wdm.sys [2010/05/04 09:46:00 | 000,028,062 | ---- | C] (National Semiconductor Coproration) -- C:\WINDOWS\System32\dllcache\dp83820.sys [2010/05/04 09:45:48 | 000,029,696 | ---- | C] (CNet Technology, Inc. ) -- C:\WINDOWS\System32\dllcache\dm9pci5.sys [2010/05/04 09:45:46 | 000,952,007 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\diwan.sys [2010/05/04 09:45:46 | 000,026,698 | ---- | C] (D-Link Corporation) -- C:\WINDOWS\System32\dllcache\dlh5xnd5.sys [2010/05/04 09:45:44 | 000,236,060 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\ditrace.exe [2010/05/04 09:45:43 | 000,038,985 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvsu.dll [2010/05/04 09:45:43 | 000,006,729 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvci.dll [2010/05/04 09:45:41 | 000,091,305 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\dimaint.sys [2010/05/04 09:45:37 | 000,024,649 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650d.sys [2010/05/04 09:45:36 | 000,024,648 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650.sys [2010/05/04 09:45:33 | 000,020,928 | ---- | C] (Digital Networks, LLC) -- C:\WINDOWS\System32\dllcache\defpa.sys [2010/05/04 09:45:20 | 000,048,640 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwrwdm.sys [2010/05/04 09:45:18 | 000,093,952 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcwdm.sys [2010/05/04 09:45:17 | 000,111,872 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcspud.sys [2010/05/04 09:45:17 | 000,003,584 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcosnt5.sys [2010/05/04 09:45:16 | 000,072,832 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbwdm.sys [2010/05/04 09:45:15 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbmidi.sys [2010/05/04 09:45:15 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbase.sys [2010/05/04 09:45:07 | 000,061,386 | ---- | C] (Compaq Computer Corp.) -- C:\WINDOWS\System32\dllcache\cpqtrnd5.sys [2010/05/04 09:44:51 | 000,020,864 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\cmbp0wdm.sys [2010/05/04 09:44:39 | 000,980,034 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\cicap.sys [2010/05/04 09:44:30 | 000,049,182 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem56n5.sys [2010/05/04 09:44:29 | 000,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem33n5.sys [2010/05/04 09:44:28 | 000,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem28n5.sys [2010/05/04 09:44:27 | 000,027,164 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce3n5.sys [2010/05/04 09:44:25 | 000,021,530 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce2n5.sys [2010/05/04 09:44:22 | 000,715,210 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cbmdmkxx.sys [2010/05/04 09:44:21 | 000,046,108 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cben5.sys [2010/05/04 09:44:20 | 000,039,680 | ---- | C] (Silicom Ltd.) -- C:\WINDOWS\System32\dllcache\cb325.sys [2010/05/04 09:44:20 | 000,037,916 | ---- | C] (Fast Ethernet Controller Provider) -- C:\WINDOWS\System32\dllcache\cb102.sys [2010/05/04 09:44:18 | 000,164,923 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\diapi2.sys [2010/05/04 09:44:18 | 000,032,256 | ---- | C] (Eicon Technology Corporation) -- C:\WINDOWS\System32\dllcache\diapi2NT.dll [2010/05/04 09:43:50 | 000,031,529 | ---- | C] (BreezeCOM) -- C:\WINDOWS\System32\dllcache\brzwlan.sys [2010/05/04 09:43:42 | 000,871,388 | ---- | C] (BCM) -- C:\WINDOWS\System32\dllcache\bcmdm.sys [2010/05/04 09:43:40 | 000,342,336 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.dll [2010/05/04 09:43:40 | 000,036,128 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.sys [2010/05/04 09:43:38 | 000,089,952 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\b1cbase.sys [2010/05/04 09:43:37 | 000,036,992 | ---- | C] (Aztech Systems Ltd) -- C:\WINDOWS\System32\dllcache\aztw2320.sys [2010/05/04 09:43:36 | 000,144,384 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmenum.dll [2010/05/04 09:43:36 | 000,087,552 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmcoxp.dll [2010/05/04 09:43:36 | 000,037,568 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmwan.sys [2010/05/04 09:43:05 | 000,077,824 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\dllcache\ati.sys [2010/05/04 09:43:01 | 000,097,354 | ---- | C] (Bay Networks, Inc.) -- C:\WINDOWS\System32\dllcache\aspndis3.sys [2010/05/04 09:42:46 | 000,016,969 | ---- | C] (AmbiCom, Inc.) -- C:\WINDOWS\System32\dllcache\amb8002.sys [2010/05/04 09:42:33 | 000,046,112 | ---- | C] (Adaptec, Inc ) -- C:\WINDOWS\System32\dllcache\adptsf50.sys [2010/05/04 09:42:32 | 000,010,880 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\admjoy.sys [2010/05/04 09:42:28 | 000,747,392 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8830.sys [2010/05/04 09:42:26 | 000,553,984 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8820.sys [2010/05/04 09:42:25 | 000,584,448 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8810.sys [2010/05/04 09:42:24 | 000,020,160 | ---- | C] (ADMtek Incorporated) -- C:\WINDOWS\System32\dllcache\adm8511.sys [2010/05/04 09:42:19 | 000,297,728 | ---- | C] (Silicon Integrated Systems Corp.) -- C:\WINDOWS\System32\dllcache\ac97sis.sys [2010/05/04 09:42:16 | 000,462,848 | ---- | C] (Aureal Inc.) -- C:\WINDOWS\System32\dllcache\a3dapi.dll [2010/05/04 09:42:16 | 000,098,304 | ---- | C] (Aureal Semiconductor) -- C:\WINDOWS\System32\dllcache\a3d.dll [2010/05/04 09:42:12 | 000,148,352 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvsm.sys [2010/05/04 09:42:11 | 000,762,780 | ---- | C] (3Com, Inc.) -- C:\WINDOWS\System32\dllcache\3cwmcru.sys [2010/05/04 09:42:11 | 000,689,216 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvs.dll [2010/05/03 22:42:14 | 000,839,680 | ---- | C] (http://www.mp3dev.org/) -- C:\WINDOWS\System32\lameACM.acm [2010/05/03 22:42:14 | 000,217,088 | ---- | C] (www.helixcommunity.org) -- C:\WINDOWS\System32\yv12vfw.dll [2010/05/03 22:42:14 | 000,151,552 | ---- | C] (fccHandler) -- C:\WINDOWS\System32\ac3acm.acm [2010/05/03 22:41:58 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\K-Lite Codec Pack [2010/05/03 20:09:55 | 000,100,896 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\RTNUninst32.dll [2010/05/03 20:05:55 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\SystemRequirementsLab [2010/05/03 20:02:46 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Intel [2010/05/03 17:31:36 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2010/05/03 17:27:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp [2010/05/03 17:22:48 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2010/05/03 17:22:45 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2010/05/03 17:22:43 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2010/05/03 17:22:42 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2010/05/03 17:22:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2010/05/03 17:22:09 | 000,000,000 | ---D | C] -- C:\ComboFix [2010/05/03 17:21:53 | 000,000,000 | ---D | C] -- C:\Qoobox [2010/05/03 17:16:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Dados de aplicativos\GetRightToGo [2010/05/03 17:05:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Malwarebytes [2010/05/03 17:05:34 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2010/05/03 17:05:32 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2010/05/03 17:05:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Malwarebytes [2010/05/03 17:05:29 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Malwarebytes' Anti-Malware [2010/05/03 10:54:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Meus documentos\HospitalTycoon [2010/05/03 10:54:30 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\DirectX [2010/05/03 10:52:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX [2010/05/03 10:52:15 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Codemasters [2010/05/03 00:13:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Dados de aplicativos\uTorrent [2010/04/30 00:06:37 | 000,358,944 | ---- | C] (Realtek Semiconductor Crop.) -- C:\WINDOWS\vncutil.exe [2010/04/30 00:06:30 | 000,129,568 | ---- | C] (Realtek Semiconductor) -- C:\WINDOWS\RtkAudioService.exe [2010/04/30 00:06:18 | 001,691,480 | ---- | C] (Creative) -- C:\WINDOWS\System32\drivers\Ambfilt.sys [2010/04/29 22:13:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss [2010/04/28 16:39:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Meus documentos\My Downloads [2010/04/28 16:39:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Megaupload [2010/04/28 16:37:44 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Megaupload [2010/04/27 23:36:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Adobe [2010/04/27 22:14:18 | 000,115,200 | ---- | C] (Snowblind / www.snowblind.net) -- C:\Documents and Settings\Administrador\Desktop\imapic2.exe [2010/04/27 16:14:15 | 000,339,968 | ---- | C] (Sonix) -- C:\WINDOWS\vsnpstd3.exe [2010/04/27 16:14:14 | 000,057,344 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll [2010/04/27 16:14:13 | 000,061,440 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll [2010/04/27 16:14:13 | 000,036,864 | ---- | C] ( ) -- C:\WINDOWS\System32\vsnpstd3.dll [2010/04/27 16:14:13 | 000,036,864 | ---- | C] ( ) -- C:\WINDOWS\System32\dsnpstd3.ax [2010/04/27 16:14:13 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\snpstd3 [2010/04/27 01:12:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell [2010/04/26 23:05:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Desktop\Cores [2010/04/26 22:12:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Desktop\Roça [2010/04/26 21:22:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Thinstall [2010/04/26 20:26:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Desktop\team [2010/04/26 20:16:37 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\SpacialAudio [2010/04/26 18:13:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups [2010/04/26 18:07:12 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Microsoft Silverlight [2010/04/26 17:53:05 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\MSECache [2010/04/26 00:41:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Meus documentos\Blocos de Anotações do OneNote [2010/04/25 23:45:45 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Firebird [2010/04/25 23:32:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy [2010/04/25 23:32:51 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Spybot - Search & Destroy [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 14 Days ========== [2010/05/09 15:32:29 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrador\Desktop\OTL.exe [2010/05/09 15:05:04 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010/05/09 15:05:03 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010/05/08 22:36:41 | 003,670,016 | -H-- | M] () -- C:\Documents and Settings\Administrador\NTUSER.DAT [2010/05/08 22:36:41 | 000,000,210 | -HS- | M] () -- C:\Documents and Settings\Administrador\ntuser.ini [2010/05/08 22:34:10 | 003,767,592 | -H-- | M] () -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\IconCache.db [2010/05/08 01:58:00 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Administrador\winscp.RND [2010/05/08 01:40:41 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\PUTTY.RND [2010/05/07 00:09:47 | 000,000,076 | ---- | M] () -- C:\Documents and Settings\Administrador\Desktop\Counter-Strike Source.url [2010/05/07 00:00:34 | 000,000,720 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk [2010/05/06 23:36:48 | 000,022,016 | ---- | M] () -- C:\Documents and Settings\Administrador\Meus documentos\grafico.xls [2010/05/06 23:35:07 | 000,063,642 | ---- | M] () -- C:\Documents and Settings\Administrador\Meus documentos\metamod-p-1.19p32-linux_i586.tar.gz [2010/05/06 23:16:30 | 000,000,685 | ---- | M] () -- C:\Documents and Settings\Administrador\Desktop\Atalho para winscp3.lnk [2010/05/06 13:11:16 | 000,020,167 | ---- | M] () -- C:\Documents and Settings\Administrador\Desktop\ccauth.pdf [2010/05/06 12:39:57 | 001,896,389 | ---- | M] () -- C:\Documents and Settings\Administrador\Meus documentos\pedro.cdr [2010/05/05 17:43:41 | 000,005,120 | ---- | M] () -- C:\6XSourceFilter.grf [2010/05/05 17:43:33 | 000,000,014 | ---- | M] () -- C:\WINDOWS\System32\systeminfo.dll [2010/05/04 21:12:45 | 000,013,184 | ---- | M] () -- C:\Documents and Settings\Administrador\Meus documentos\net.JPG [2010/05/04 15:38:37 | 000,040,789 | ---- | M] () -- C:\Documents and Settings\Administrador\Meus documentos\lento.JPG [2010/05/03 17:26:52 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini [2010/05/03 16:56:46 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\HiJackThis.exe [2010/05/03 16:49:49 | 000,000,834 | ---- | M] () -- C:\WINDOWS\win.ini [2010/05/03 16:49:49 | 000,000,211 | -HS- | M] () -- C:\boot.ini [2010/05/03 12:50:09 | 000,000,000 | RHS- | M] () -- C:\Documents and Settings\All Users\Documentos\khx [2010/05/03 10:52:47 | 000,001,089 | ---- | M] () -- C:\Documents and Settings\Administrador\Desktop\Hospital Tycoon.lnk [2010/04/29 22:35:37 | 000,458,336 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat [2010/04/29 22:35:37 | 000,417,398 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010/04/29 22:35:37 | 000,074,794 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat [2010/04/29 22:35:37 | 000,062,486 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010/04/29 22:35:36 | 001,023,882 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2010/04/28 19:08:25 | 000,008,386 | ---- | M] () -- C:\Documents and Settings\Administrador\Meus documentos\navemae.voahost.com.br.err [2010/04/28 16:39:14 | 000,001,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mega Manager.lnk [2010/04/27 01:12:48 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2010/04/26 22:36:01 | 000,000,000 | RHS- | M] () -- C:\Documents and Settings\All Users\Documentos\kht [2010/04/26 22:20:46 | 000,006,144 | ---- | M] () -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/04/26 20:16:38 | 000,001,815 | ---- | M] () -- C:\Documents and Settings\Administrador\Desktop\SimpleCast.lnk [2010/04/26 17:53:37 | 000,123,768 | ---- | M] () -- C:\Documents and Settings\Administrador\Meus documentos\proposta_futuro.pdf [2010/04/26 17:51:57 | 000,030,615 | ---- | M] () -- C:\Documents and Settings\Administrador\Meus documentos\proposta_invest.docx [2010/04/26 16:55:02 | 000,056,129 | ---- | M] () -- C:\WINDOWS\FontData.fdb [2010/04/26 15:58:12 | 000,256,512 | ---- | M] () -- C:\WINDOWS\PEV.exe [2010/04/26 13:43:23 | 000,000,000 | -H-- | M] () -- C:\Documents and Settings\Administrador\Meus documentos\Default.rdp [2010/04/26 08:24:28 | 000,359,344 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010/04/25 23:19:26 | 000,423,142 | ---- | M] () -- C:\Documents and Settings\Administrador\Desktop\placa.cdr [2010/04/25 23:19:21 | 000,632,603 | ---- | M] () -- C:\Documents and Settings\Administrador\Desktop\PLACA.pdf [2010/04/25 23:18:54 | 000,424,514 | ---- | M] () -- C:\Documents and Settings\Administrador\Desktop\Cópia_de_segurança_de_placa.cdr [2010/04/25 23:18:35 | 000,091,280 | ---- | M] () -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2010/05/07 00:09:47 | 000,000,076 | ---- | C] () -- C:\Documents and Settings\Administrador\Desktop\Counter-Strike Source.url [2010/05/06 23:46:57 | 000,000,720 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk [2010/05/06 23:36:48 | 000,022,016 | ---- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\grafico.xls [2010/05/06 23:35:14 | 000,168,545 | ---- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\metamod_i386.so [2010/05/06 23:35:06 | 000,063,642 | ---- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\metamod-p-1.19p32-linux_i586.tar.gz [2010/05/06 23:16:30 | 000,000,685 | ---- | C] () -- C:\Documents and Settings\Administrador\Desktop\Atalho para winscp3.lnk [2010/05/06 13:11:15 | 000,020,167 | ---- | C] () -- C:\Documents and Settings\Administrador\Desktop\ccauth.pdf [2010/05/06 12:39:56 | 001,896,389 | ---- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\pedro.cdr [2010/05/05 17:43:33 | 000,000,014 | ---- | C] () -- C:\WINDOWS\System32\systeminfo.dll [2010/05/04 21:12:45 | 000,013,184 | ---- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\net.JPG [2010/05/04 15:38:37 | 000,040,789 | ---- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\lento.JPG [2010/05/04 09:53:48 | 000,044,009 | ---- | C] () -- C:\WINDOWS\System32\dllcache\otceth5.sys [2010/05/04 09:45:45 | 000,037,962 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaprop.dll [2010/05/04 09:45:45 | 000,029,768 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divasu.dll [2010/05/04 09:45:45 | 000,006,216 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaci.dll [2010/05/04 09:45:43 | 000,031,817 | ---- | C] () -- C:\WINDOWS\System32\dllcache\disrvpp.dll [2010/05/04 09:43:25 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativxbar.sys [2010/05/04 09:43:25 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atixbar.sys [2010/05/04 09:43:25 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativttxx.sys [2010/05/04 09:43:24 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitvsnd.sys [2010/05/04 09:43:24 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativmdcd.sys [2010/05/04 09:43:23 | 000,049,920 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtcap.sys [2010/05/04 09:43:23 | 000,026,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtsnd.sys [2010/05/04 09:43:23 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitunep.sys [2010/05/04 09:43:21 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atipcxxx.sys [2010/05/04 09:43:14 | 000,046,464 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atibt829.sys [2010/05/03 22:42:33 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll [2010/05/03 22:42:30 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini [2010/05/03 22:42:14 | 000,000,414 | ---- | C] () -- C:\WINDOWS\System32\lame_acm.xml [2010/05/03 22:42:12 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2010/05/03 22:42:12 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2010/05/03 22:42:03 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest [2010/05/03 22:42:02 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll [2010/05/03 20:11:27 | 000,001,023 | ---- | C] () -- C:\WINDOWS\System32\igxpxa32.vp [2010/05/03 20:11:26 | 001,674,683 | ---- | C] () -- C:\WINDOWS\System32\igxpxa32.cpa [2010/05/03 20:11:26 | 001,498,560 | ---- | C] () -- C:\WINDOWS\System32\igkrng400.bin [2010/05/03 20:09:55 | 000,080,416 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll [2010/05/03 17:22:49 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe [2010/05/03 17:22:46 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe [2010/05/03 17:22:44 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2010/05/03 17:22:44 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2010/05/03 17:22:44 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2010/05/03 12:50:09 | 000,000,000 | RHS- | C] () -- C:\Documents and Settings\All Users\Documentos\khx [2010/05/03 10:52:47 | 000,001,089 | ---- | C] () -- C:\Documents and Settings\Administrador\Desktop\Hospital Tycoon.lnk [2010/04/28 20:00:20 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Administrador\winscp.RND [2010/04/28 20:00:08 | 000,008,386 | ---- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\navemae.voahost.com.br.err [2010/04/28 16:39:14 | 000,001,724 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mega Manager.lnk [2010/04/27 16:14:14 | 000,494,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\snpstd3.sys [2010/04/27 16:14:14 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini [2010/04/27 16:14:14 | 000,013,023 | ---- | C] () -- C:\WINDOWS\snpstd3.src [2010/04/27 16:14:13 | 000,020,480 | ---- | C] () -- C:\WINDOWS\usnpstd3.exe [2010/04/26 22:36:01 | 000,000,000 | RHS- | C] () -- C:\Documents and Settings\All Users\Documentos\kht [2010/04/26 20:16:38 | 000,001,815 | ---- | C] () -- C:\Documents and Settings\Administrador\Desktop\SimpleCast.lnk [2010/04/26 17:53:35 | 000,123,768 | ---- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\proposta_futuro.pdf [2010/04/26 17:42:08 | 000,030,615 | ---- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\proposta_invest.docx [2010/04/26 13:43:23 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\Default.rdp [2010/04/25 23:16:42 | 000,632,603 | ---- | C] () -- C:\Documents and Settings\Administrador\Desktop\PLACA.pdf [2010/04/25 23:13:09 | 000,424,514 | ---- | C] () -- C:\Documents and Settings\Administrador\Desktop\Cópia_de_segurança_de_placa.cdr [2010/04/25 23:04:25 | 000,423,142 | ---- | C] () -- C:\Documents and Settings\Administrador\Desktop\placa.cdr [2010/04/20 17:14:43 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll [2010/04/19 19:41:37 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll [2010/04/19 17:13:06 | 000,000,190 | ---- | C] () -- C:\WINDOWS\dvrnet.ini [2010/04/19 17:08:40 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4833.dll [2010/04/19 17:08:39 | 000,910,464 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll [2010/04/19 11:00:23 | 000,015,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\nod32drv.sys ========== LOP Check ========== [2010/05/03 17:21:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\GetRightToGo [2010/04/28 16:39:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Megaupload [2010/04/26 21:22:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Thinstall [2010/05/03 10:26:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\uTorrent [2010/04/20 17:14:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\BlazeVideo [2010/04/20 07:33:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin [2010/04/21 23:08:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\SHOUTcast Radio Toolbar ========== Purity Check ========== < End of report > E muito obrigado pela ajuda Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Maio 9, 2010 Boa Tarde! raphaelfx <!> Desinstale: Spybot <-- 0000000000000000000000 oooooooooooooooooooooo <@> Execute o OTL.exe. <@> Copie estas informações que estão na Quote,para o campo abaixo de: Exames Personalizados/Correções :otlSRV - (UPS) -- File not found SRV - (gupdate) Google Update Service (gupdate) -- File not found SRV - (ClipSrv) -- File not found SRV - (CiSvc) -- File not found DRV - (mvd20) -- File not found DRV - (mdf15) -- File not found [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] :services CiSvc ClipSrv UPS :commands [resethosts] [purity] [emptyflash] [emptytemp] [Reboot] <@> Clique no botão Consertar --> Aguarde a conclusão! --> Executar! <@> Poste o relatório,que está na pasta: C:\_OTL\MovedFiles\*.log 0000000000000000000000 oooooooooooooooooooooo <@> Baixe: < TFC > ( by Old Timer ) <!> Link - 2 < http://www.geekstogo.com/forum/TFC-Temp-File-Cleaner-OldTimer-file187.html > <@> Salve-o no desktop! <@> Feche todos os programas! ( Internet,navegador,etc... ) <@> Execute TFC.exe,com um duplo-clique. <@> Ps: Para Windows Vista --> Clique direito --> Escolha: Executar como Administrador <@> Clique em Start --> Aguarde! <@> Terminando,reinicie o computador...caso a ferramenta não o solicite e dê início ao processo. ( reboot ) Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
raphaelfx 0 Denunciar post Postado Maio 11, 2010 OTL: All processes killed ========== OTL ========== Error: No service named UPS was found to stop! Service\Driver key UPS not found. File File not found not found. Error: No service named gupdate) Google Update Service (gupdate was found to stop! Service\Driver key gupdate) Google Update Service (gupdate not found. File File not found not found. Error: No service named ClipSrv was found to stop! Service\Driver key ClipSrv not found. File File not found not found. Error: No service named CiSvc was found to stop! Service\Driver key CiSvc not found. File File not found not found. Error: Unable to stop service mvd20! Service\Driver key mvd20 not found. File File not found not found. Error: Unable to stop service mdf15! Service\Driver key mdf15 not found. File File not found not found. C:\WINDOWS\SET3.tmp deleted successfully. C:\WINDOWS\SET4.tmp deleted successfully. C:\WINDOWS\SET8.tmp deleted successfully. C:\WINDOWS\System32\CONFIG.TMP deleted successfully. ========== SERVICES/DRIVERS ========== Error: No service named CiSvc was found to stop! Service\Driver key CiSvc not found. Error: No service named ClipSrv was found to stop! Service\Driver key ClipSrv not found. Error: No service named UPS was found to stop! Service\Driver key UPS not found. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYFLASH] User: Administrador ->Flash cache emptied: 20984 bytes User: All Users User: Cleiton User: Default User User: LocalService User: NetworkService Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: Administrador ->Temp folder emptied: 4670665 bytes ->Temporary Internet Files folder emptied: 23257914 bytes ->FireFox cache emptied: 91693680 bytes ->Flash cache emptied: 0 bytes User: All Users User: Cleiton User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 34630 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 5050548 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 119,00 mb OTL by OldTimer - Version 3.2.4.1 log created on 05102010_225859 Files\Folders moved on Reboot... Registry entries deleted on Reboot... Seguinte, o problema pelo menos até antes de eu fazer esse processo ainda estava acontecendo. Eu percebi uma coisa que não tem sentido nenhum, mas depois da meia noite quando deixo downloads ativos a internet não cai, pela manhã ta sempre conectado ainda... Não entendi a relação hehe... Outro problema que ta rolando é que o audio funciona normal, mas quando preciso utilizar ele em dois lugares ele para. Exemplo estou ouvindo musica no Winamp, eu fecho o Winamp para ver um vídeo no youtube, o vídeo esta sem som, dai tenho que ir no services e ativar o Audio do Windows Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Maio 11, 2010 Bom Dia! raphaelfx <@> Faça escaneamento,online,em: '>http://www.eset.com/onlinescan/index.php"] <@> Ps: Utilize o navegador Internet Explorer. <@> Clique em: < > <@> Marque a caixa: "SIM,aceito as condições de uso" --> Iniciar. <@> Marque a caixa: "YES, I accept the Terms of Use" --> Start. <@> Aceite a instalação do ActiveX --> Dê início ao scan. <@> Concluindo,poste o relatório: C:\Program Files\EsetOnlineScanner\log.txt Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
raphaelfx 0 Denunciar post Postado Maio 11, 2010 Não foi gerado nenhum LOG pois não detectou nenhum vírus. Corrigindo, log do scan: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=6.00.2900.5512 (xpsp.080413-2105) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=eac3d9da8e329643b01fc5cecf79b9d1 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-05-11 04:04:57 # local_time=2010-05-11 01:04:57 (-0300, Hora oficial do Brasil) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=crash # scanned=43532 # found=0 # cleaned=0 # scan_time=4296 # nod_component=NOD32MOD_WINNT_PORTUGUESE_BASE Build:0x11081627 # nod_component=NOD32MOD_WINNT_PORTUGUESE_INET Build:0x11081627 # nod_component=NOD32MOD_WINNT_PORTUGUESE_STANDARD Build:0x11081627 Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Maio 12, 2010 Bom Dia! raphaelfx <@> Baixe: < WORT > <@> Salve-o no desktop! <@> Dê um duplo-clique em WORT.exe --> Clique em Accept. <@> O programa será instalado no próprio desktop! --> Clique em Install. <@> Ao término surgirá a mensagem "Installation de WORT réussie!" --> Clique em OK. <@> Maiores detalhes: < wings > <-- Tutorial! <@> No desktop,surgirão uma pasta ( WORT ) e um batch file. ( WareOut Removal Tool.bat ) <@> Reinicie o computador em Modo de Segurança. <@> Dê um duplo-clique no arquivo WareOut Removal Tool.bat --> Aperte Enter. <@> Nas opções,que teremos,escolha: <!> Opção 1 = Commencer la recherche/supression <@> Tecle [1] --> Enter --> Continue teclando Enter,até o início do scan. <@> Terminando,reinicie o computador! <@> Poste: HijackThis,atualizado + C:\WORT\WORT_report.txt <-- Relatório! 0000000000000000000000 oooooooooooooooooooooo <@> Baixe: < > <!> < Link - 2 > <!> < Link - 3 > <@> Salve-o no desktop! <@> Reinicie o computador em Modo de Segurança! <@> Execute o WinsockFix! <@> Duplo-clique em WinsockFix.exe <@> Abrir-se-á a janela: VB_Winfix 1.2 <@> Clique em Fix. <@> Surgirá uma mensagem! >> Clique em Sim! <@> Ps: Repita o procedimento! <@> Terminando,reinicie normalmente o computador! <@> Teste sua conecção à Internet. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Junho 13, 2010 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites