trend 0 Denunciar post Postado Outubro 3, 2011 Olá pessoal, tentarei descrever brevemente meu caso. Ontem (domingo.2) eu liguei o pc, daí ele ñ queria acessar a internet, nem com o Firefox, nem com o IE. Daí então pc travou geral, reiniciou e me bateu o desespero, pq ao msmo tempo em que os navegadores ñ acessavam a net, o uTorrent continuava baixando os arquivos normalmente. Toda vez que eu executava o firefox pelo desktop, recebia uma msg mais ou menos falando que eu não tinha "privilégios suficientes para realizar a ação", daí no lugar do ícone do firefox, apareceu um ícone com um quadrado branco (igual qdo o programa ñ existe, o atalho é inválido etc). Instalei o MalwareBytes, atualizei e fechei. Qdo tentei abrir ele recebi a msma mensagem do firefox. Instalei o Spybot, atualizei, mas ele não se auto-executou ao término da instalação. Iniciei o pC do modo seguro e reinstalei o malwarebytes e ele pegou 15 ameaças, vários trojans, depois usei o combofix, que me disse que "havia sido encontrado atividade rootkit", então foram-se mais de 40 etapas e parte dos problemas como o acesso a internet do IE foi restaurado, o problema do privilégio também foi resolvido, mas sempre que escaneio o pc com o malwarebytes ele sempre encontra novas ameaças. Sumiram tb uns processos estranhos denominados "temp" no ger. de tarefas, mas em compensação, qdo ligo o pc, sempre recebo a mensagem que um driver incompatível foi bloqueado, agora, tem mais de 15 processos "svchost" sendo executados, o firefox ñ entra na net, só o IE. Segue log: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 14:57:39, on 03/10/2011 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\USB Disk Security\USBGuard.exe C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\Internet Download Manager\IEMonitor.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\explorer.exe C:\Users\Christian Fernando\Downloads\Programs\HijackThis 2.0.5 beta.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:64869 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [bCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe --background O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [uSB Security] C:\Program Files\USB Disk Security\USBGuard.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [iDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\Run: [iDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Program Files\Internet Download Manager\IEExt.htm O8 - Extra context menu item: Free YouTube Download - C:\Users\Christian Fernando\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Christian Fernando\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- End of file - 6183 bytes Compartilhar este post Link para o post Compartilhar em outros sites
trend 0 Denunciar post Postado Outubro 3, 2011 RSIT LOG: Logfile of random's system information tool 1.09 (written by random/random) Run by Christian Fernando at 2011-10-03 17:40:37 Microsoft Windows 7 Ultimate Service Pack 1 System drive C: has 98 GB (45%) free of 215 GB Total RAM: 2047 MB (37% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:40:53, on 03/10/2011 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\USB Disk Security\USBGuard.exe C:\Program Files\DAEMON Tools Lite\DTLite.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\Internet Download Manager\IEMonitor.exe C:\Windows\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\taskmgr.exe C:\Users\Christian Fernando\Desktop\RSIT.exe C:\Program Files\trend micro\Christian Fernando.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:64869 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [bCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [vspdfprsrv.exe] C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe --background O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [uSB Security] C:\Program Files\USB Disk Security\USBGuard.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" O4 - HKCU\..\Run: [iDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\Run: [iDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'UpdatusUser') O4 - HKUS\S-1-5-21-3043748444-1542819765-3838197750-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser') O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Program Files\Internet Download Manager\IEExt.htm O8 - Extra context menu item: Free YouTube Download - C:\Users\Christian Fernando\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Christian Fernando\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- End of file - 5904 bytes =========Mozilla firefox========= ProfilePath - C:\Users\Christian Fernando\AppData\Roaming\Mozilla\Firefox\Profiles\6whjna59.default prefs.js - "browser.search.useDBForOrder" - true prefs.js - "browser.startup.homepage" - "http://www.google.com.br/" [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer] "Description"=Adobe® Flash® Player 10.1 Plugin "Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer] "Description"=Adobe Shockwave Player "Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin] "Description"=Oracle® Next Generation Java™ Plug-In "Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE] "Description"= "Path"=C:\Windows\system32\Wat\npWatWeb.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0] "Description"=Ag Player Plugin "Path"=c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0] "Description"=Office Authorization plug-in for NPAPI browsers "Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0] "Description"=Microsoft SharePoint Plug-in for Firefox "Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVision] "Description"=NVIDIA stereo images plugin for Mozilla browsers "Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@nvidia.com/3DVisionStreaming] "Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers "Path"=C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} C:\Program Files\Mozilla Firefox\components\ binary.manifest browsercomps.dll C:\Program Files\Mozilla Firefox\plugins\ np-mswmp.dll npdeployJava1.dll WMP Firefox Plugin License.rtf WMP Firefox Plugin RelNotes.txt C:\Program Files\Mozilla Firefox\searchplugins\ buscape.xml google.xml mercadolivre.xml wikipedia-br.xml yahoo-br.xml C:\Users\Christian Fernando\AppData\Roaming\Mozilla\Firefox\Profiles\6whjna59.default\extensions\ foxmarks@kei.com C:\Users\Christian Fernando\AppData\Roaming\Mozilla\Firefox\Profiles\6whjna59.default\searchplugins\ 4shared.xml baixaki.xml google-brasil.xml google-images.xml mycroft-project.xml the-pirate-bay.xml ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}] IDM integration (IDMIEHlprObj Class) - C:\Program Files\Internet Download Manager\IDMIECC.dll [2011-04-15 210352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-09-21 41760] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520] "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-11-29 421888] "vspdfprsrv.exe"=C:\Program Files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe [2007-07-02 1179648] "RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-04-30 9210400] "USB Security"=C:\Program Files\USB Disk Security\USBGuard.exe [2011-05-21 623520] "SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408] "uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2011-09-21 395128] "IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2011-09-21 3298712] "msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2011-05-13 4283256] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-09-25 203776] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=0 "ConsentPromptBehaviorUser"=3 "EnableLUA"=0 "EnableUIADesktopToggle"=0 "PromptOnSecureDesktop"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 "NoDrives"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDrives"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "vidc.mrle"=msrle32.dll "vidc.msvc"=msvidc32.dll "msacm.imaadpcm"=imaadp32.acm "msacm.msg711"=msg711.acm "msacm.msgsm610"=msgsm32.acm "msacm.msadpcm"=msadp32.acm "midimapper"=midimap.dll "wavemapper"=msacm32.drv "vidc.uyvy"=msyuv.dll "vidc.yuy2"=msyuv.dll "vidc.yvyu"=msyuv.dll "vidc.iyuv"=iyuv_32.dll "vidc.i420"=iyuv_32.dll "vidc.yvu9"=tsbyuv.dll "msacm.l3acm"=C:\Windows\System32\l3codeca.acm "vidc.cvid"=iccvid.dll "msacm.l3fhg"=mp3fhg.acm "VIDC.XVID"=xvidvfw.dll "VIDC.YV12"=yv12vfw.dll "msacm.ac3acm"=ac3acm.acm "VIDC.FFDS"=ff_vfw.dll "msacm.siren"=sirenacm.dll "wave"=wdmaud.drv "midi"=wdmaud.drv "mixer"=wdmaud.drv "aux"=wdmaud.drv "VIDC.XFR1"=xfcodec.dll ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 ======List of files/folders created in the last 1 month====== 2011-10-03 17:40:38 ----D---- C:\Program Files\trend micro 2011-10-03 17:40:37 ----D---- C:\rsit 2011-10-03 16:11:50 ----D---- C:\Program Files\Common Files\Java 2011-10-03 16:08:23 ----A---- C:\Windows\system32\javaws.exe 2011-10-03 16:08:23 ----A---- C:\Windows\system32\javaw.exe 2011-10-03 16:08:22 ----A---- C:\Windows\system32\java.exe 2011-10-02 20:44:48 ----A---- C:\ComboFix.txt 2011-10-02 20:43:35 ----SHD---- C:\$RECYCLE.BIN 2011-10-02 20:19:11 ----A---- C:\Windows\system32\drivers\i8042prt.sys 2011-10-02 20:16:50 ----A---- C:\Windows\zip.exe 2011-10-02 20:16:50 ----A---- C:\Windows\SWSC.exe 2011-10-02 20:16:50 ----A---- C:\Windows\SWREG.exe 2011-10-02 20:16:50 ----A---- C:\Windows\sed.exe 2011-10-02 20:16:50 ----A---- C:\Windows\PEV.exe 2011-10-02 20:16:50 ----A---- C:\Windows\NIRCMD.exe 2011-10-02 20:16:50 ----A---- C:\Windows\MBR.exe 2011-10-02 20:16:50 ----A---- C:\Windows\grep.exe 2011-10-02 20:16:45 ----D---- C:\ComboFix 2011-10-02 20:14:12 ----D---- C:\Windows\ERDNT 2011-10-02 20:14:07 ----D---- C:\Qoobox 2011-10-02 18:04:50 ----A---- C:\Windows\ntbtlog.txt 2011-10-02 18:03:09 ----D---- C:\Program Files\Spybot - Search & Destroy 2011-10-02 17:55:02 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Malwarebytes 2011-10-02 17:54:56 ----D---- C:\ProgramData\Malwarebytes 2011-10-02 17:54:53 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2011-10-02 17:54:53 ----A---- C:\Windows\system32\drivers\mbam.sys 2011-10-02 17:14:28 ----A---- C:\Windows\system32\8BAA6192-3DA3-8718-6DED-FAC89CA97838.txt 2011-10-01 16:02:11 ----A---- C:\Windows\system32\NPSExec.exe 2011-10-01 13:23:16 ----D---- C:\Program Files\Need for Speed 3 Vista Edition 2011-09-30 23:30:39 ----D---- C:\Program Files\GlideWrapper 2011-09-30 23:02:12 ----D---- C:\Program Files\Gadwin Systems 2011-09-30 22:07:30 ----D---- C:\ProgramData\NFS Underground 2011-09-28 18:02:52 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Leadertech 2011-09-28 17:38:09 ----A---- C:\Windows\eReg.dat 2011-09-28 17:27:52 ----A---- C:\Windows\system32\MSVCP50.DLL 2011-09-28 17:25:32 ----A---- C:\Windows\IsUninst.exe 2011-09-28 17:24:35 ----A---- C:\Windows\EReg072.dat 2011-09-28 17:22:17 ----D---- C:\Program Files\Electronic Arts 2011-09-28 17:18:31 ----A---- C:\Windows\uninst.exe 2011-09-28 17:18:09 ----RASH---- C:\MSDOS.SYS 2011-09-28 17:18:09 ----RASH---- C:\IO.SYS 2011-09-27 23:19:39 ----D---- C:\Users\Christian Fernando\AppData\Roaming\FileZilla 2011-09-27 23:19:02 ----D---- C:\Program Files\FileZilla FTP Client 2011-09-26 16:26:33 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Media Player Classic 2011-09-25 00:40:55 ----A---- C:\Windows\system32\wininet.dll 2011-09-25 00:40:55 ----A---- C:\Windows\system32\urlmon.dll 2011-09-25 00:40:55 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe 2011-09-25 00:40:55 ----A---- C:\Windows\system32\msls31.dll 2011-09-25 00:40:55 ----A---- C:\Windows\system32\jsproxy.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\wextract.exe 2011-09-25 00:40:54 ----A---- C:\Windows\system32\webcheck.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\vbscript.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\url.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\SetIEInstalledDate.exe 2011-09-25 00:40:54 ----A---- C:\Windows\system32\pngfilt.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\occache.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\msrating.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\mshtmler.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\mshtmled.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\mshtml.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\mshta.exe 2011-09-25 00:40:54 ----A---- C:\Windows\system32\msfeedssync.exe 2011-09-25 00:40:54 ----A---- C:\Windows\system32\msfeedsbs.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\msfeeds.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\licmgr10.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\jscript9.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\jscript.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\inseng.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\imgutil.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\iexpress.exe 2011-09-25 00:40:54 ----A---- C:\Windows\system32\ieUnatt.exe 2011-09-25 00:40:54 ----A---- C:\Windows\system32\ieui.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\iesysprep.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\iesetup.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\iertutil.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\iernonce.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\iepeers.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\ieframe.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\iedkcs32.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\ieapfltr.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\ieapfltr.dat 2011-09-25 00:40:54 ----A---- C:\Windows\system32\ieakui.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\ieaksie.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\ieakeng.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\IEAdvpack.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\ie4uinit.exe 2011-09-25 00:40:54 ----A---- C:\Windows\system32\icardie.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\dxtrans.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\dxtmsft.dll 2011-09-25 00:40:54 ----A---- C:\Windows\system32\admparse.dll 2011-09-25 00:28:27 ----A---- C:\Windows\system32\MRT.exe 2011-09-24 20:51:18 ----D---- C:\Windows\system32\SupportAppXL 2011-09-24 20:51:14 ----D---- C:\Program Files\Brasil Telecom 2011-09-24 17:37:26 ----A---- C:\Windows\system32\drivers\atksgt.sys 2011-09-24 17:37:15 ----A---- C:\Windows\system32\drivers\lirsgt.sys 2011-09-24 17:34:44 ----A---- C:\Windows\system32\XAudio2_1.dll 2011-09-24 17:34:44 ----A---- C:\Windows\system32\XAPOFX1_0.dll 2011-09-24 17:34:43 ----A---- C:\Windows\system32\xactengine3_1.dll 2011-09-24 17:34:43 ----A---- C:\Windows\system32\X3DAudio1_4.dll 2011-09-24 17:34:43 ----A---- C:\Windows\system32\d3dx10_38.dll 2011-09-24 17:34:43 ----A---- C:\Windows\system32\D3DCompiler_38.dll 2011-09-24 17:34:39 ----A---- C:\Windows\system32\D3DX9_38.dll 2011-09-24 17:34:38 ----A---- C:\Windows\system32\XAudio2_0.dll 2011-09-24 17:34:37 ----A---- C:\Windows\system32\xactengine3_0.dll 2011-09-24 17:34:37 ----A---- C:\Windows\system32\X3DAudio1_3.dll 2011-09-24 17:34:37 ----A---- C:\Windows\system32\D3DX9_37.dll 2011-09-24 17:34:37 ----A---- C:\Windows\system32\d3dx10_37.dll 2011-09-24 17:34:37 ----A---- C:\Windows\system32\D3DCompiler_37.dll 2011-09-24 17:34:36 ----A---- C:\Windows\system32\xactengine2_10.dll 2011-09-24 17:34:35 ----A---- C:\Windows\system32\d3dx9_36.dll 2011-09-24 17:34:35 ----A---- C:\Windows\system32\d3dx10_36.dll 2011-09-24 17:34:35 ----A---- C:\Windows\system32\D3DCompiler_36.dll 2011-09-24 17:34:33 ----A---- C:\Windows\system32\xactengine2_9.dll 2011-09-24 17:34:33 ----A---- C:\Windows\system32\d3dx10_35.dll 2011-09-24 17:34:33 ----A---- C:\Windows\system32\D3DCompiler_35.dll 2011-09-24 17:34:31 ----A---- C:\Windows\system32\xactengine2_8.dll 2011-09-24 17:34:31 ----A---- C:\Windows\system32\X3DAudio1_2.dll 2011-09-24 17:34:31 ----A---- C:\Windows\system32\d3dx10_34.dll 2011-09-24 17:34:31 ----A---- C:\Windows\system32\D3DCompiler_34.dll 2011-09-24 17:34:30 ----A---- C:\Windows\system32\xinput1_3.dll 2011-09-24 17:34:28 ----A---- C:\Windows\system32\xactengine2_7.dll 2011-09-24 17:34:27 ----A---- C:\Windows\system32\d3dx9_33.dll 2011-09-24 17:34:27 ----A---- C:\Windows\system32\d3dx10_33.dll 2011-09-24 17:34:27 ----A---- C:\Windows\system32\D3DCompiler_33.dll 2011-09-24 17:34:26 ----A---- C:\Windows\system32\xactengine2_6.dll 2011-09-24 17:34:24 ----A---- C:\Windows\system32\xactengine2_5.dll 2011-09-24 17:34:24 ----A---- C:\Windows\system32\d3dx9_32.dll 2011-09-24 17:34:24 ----A---- C:\Windows\system32\d3dx10.dll 2011-09-24 17:34:23 ----A---- C:\Windows\system32\xactengine2_4.dll 2011-09-24 17:34:23 ----A---- C:\Windows\system32\x3daudio1_1.dll 2011-09-24 17:34:22 ----A---- C:\Windows\system32\d3dx9_31.dll 2011-09-24 17:34:21 ----A---- C:\Windows\system32\xinput1_2.dll 2011-09-24 17:34:21 ----A---- C:\Windows\system32\xactengine2_3.dll 2011-09-24 17:34:20 ----A---- C:\Windows\system32\xinput1_1.dll 2011-09-24 17:34:20 ----A---- C:\Windows\system32\xactengine2_2.dll 2011-09-24 17:34:19 ----A---- C:\Windows\system32\xactengine2_1.dll 2011-09-24 17:33:26 ----A---- C:\Windows\system32\xactengine2_0.dll 2011-09-24 17:33:26 ----A---- C:\Windows\system32\x3daudio1_0.dll 2011-09-24 17:33:26 ----A---- C:\Windows\system32\d3dx9_29.dll 2011-09-24 17:33:26 ----A---- C:\Windows\system32\d3dx9_28.dll 2011-09-24 17:33:26 ----A---- C:\Windows\system32\d3dx9_27.dll 2011-09-24 17:19:32 ----D---- C:\Program Files\The Witcher Enhanced Edition 2011-09-24 16:15:59 ----D---- C:\Program Files\HTML Help Workshop 2011-09-24 16:15:06 ----D---- C:\Users\Christian Fernando\AppData\Roaming\HelpNDoc 2011-09-24 15:59:11 ----D---- C:\Windows\SWAT 4 2011-09-24 15:59:11 ----D---- C:\Program Files\SWAT 4 2011-09-24 14:59:20 ----D---- C:\Program Files\Common Files\SWF Studio 2011-09-24 14:09:39 ----D---- C:\Program Files\Euro Truck Simulator 2011-09-24 13:24:14 ----A---- C:\Windows\game.ini 2011-09-24 13:22:27 ----D---- C:\Program Files\Activision 2011-09-24 13:17:13 ----D---- C:\Program Files\IBE Software 2011-09-24 13:16:33 ----SHD---- C:\Windows\ftpcache 2011-09-24 11:47:26 ----D---- C:\Program Files\Yamicsoft 2011-09-24 00:19:30 ----A---- C:\Windows\system32\d3dx9_24.dll 2011-09-24 00:16:57 ----D---- C:\Program Files\EA GAMES 2011-09-23 23:27:52 ----D---- C:\Program Files\Common Files\Microsoft Games 2011-09-23 23:16:46 ----D---- C:\ProgramData\Age of Empires 3 2011-09-23 23:15:23 ----D---- C:\Program Files\GameVicio 2011-09-23 23:03:06 ----A---- C:\Windows\system32\d3dx9_26.dll 2011-09-23 23:03:04 ----A---- C:\Windows\system32\d3dx9_25.dll 2011-09-23 22:48:20 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Xfire 2011-09-23 22:48:17 ----D---- C:\ProgramData\Xfire 2011-09-23 22:48:17 ----D---- C:\Program Files\Xfire 2011-09-23 22:36:06 ----D---- C:\Users\Christian Fernando\AppData\Roaming\WinRAR 2011-09-23 22:35:08 ----D---- C:\Program Files\WinRAR 2011-09-23 22:34:39 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Zbshareware Lab 2011-09-23 22:34:39 ----D---- C:\ProgramData\Zbshareware Lab 2011-09-23 22:34:02 ----D---- C:\Program Files\USB Disk Security 2011-09-23 22:26:30 ----A---- C:\Windows\system32\drivers\revoflt.sys 2011-09-23 22:26:28 ----D---- C:\Program Files\VS Revo Group 2011-09-23 22:14:00 ----AD---- C:\ProgramData\TEMP 2011-09-23 22:13:54 ----D---- C:\Program Files\Auslogics 2011-09-23 20:53:21 ----A---- C:\Windows\system32\fsutil.exe 2011-09-23 20:53:21 ----A---- C:\Windows\system32\esent.dll 2011-09-23 20:53:21 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS 2011-09-23 20:53:21 ----A---- C:\Windows\system32\drivers\storport.sys 2011-09-23 20:53:21 ----A---- C:\Windows\system32\drivers\nvstor.sys 2011-09-23 20:53:21 ----A---- C:\Windows\system32\drivers\nvraid.sys 2011-09-23 20:53:21 ----A---- C:\Windows\system32\drivers\ntfs.sys 2011-09-23 20:53:21 ----A---- C:\Windows\system32\drivers\iaStorV.sys 2011-09-23 20:53:21 ----A---- C:\Windows\system32\drivers\amdxata.sys 2011-09-23 20:53:21 ----A---- C:\Windows\system32\drivers\amdsata.sys 2011-09-23 20:28:41 ----A---- C:\Windows\system32\drivers\usbuhci.sys 2011-09-23 20:28:41 ----A---- C:\Windows\system32\drivers\usbport.sys 2011-09-23 20:28:41 ----A---- C:\Windows\system32\drivers\usbohci.sys 2011-09-23 20:28:41 ----A---- C:\Windows\system32\drivers\usbhub.sys 2011-09-23 20:28:41 ----A---- C:\Windows\system32\drivers\usbehci.sys 2011-09-23 20:28:41 ----A---- C:\Windows\system32\drivers\usbd.sys 2011-09-23 20:28:41 ----A---- C:\Windows\system32\drivers\usbccgp.sys 2011-09-23 09:21:48 ----RD---- C:\Favoritos 2011-09-22 15:11:26 ----A---- C:\Windows\system32\FntCache.dll 2011-09-22 15:11:26 ----A---- C:\Windows\system32\DWrite.dll 2011-09-22 15:11:25 ----A---- C:\Windows\system32\d2d1.dll 2011-09-22 08:57:17 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Nero 2011-09-22 08:19:04 ----D---- C:\Program Files\MSXML 4.0 2011-09-22 07:33:49 ----A---- C:\Windows\system32\drivers\srvnet.sys 2011-09-22 07:33:49 ----A---- C:\Windows\system32\drivers\srv2.sys 2011-09-22 07:33:49 ----A---- C:\Windows\system32\drivers\srv.sys 2011-09-22 07:32:57 ----A---- C:\Windows\system32\dnsrslvr.dll 2011-09-22 07:32:57 ----A---- C:\Windows\system32\dnscacheugc.exe 2011-09-22 07:32:57 ----A---- C:\Windows\system32\dnsapi.dll 2011-09-22 07:32:53 ----A---- C:\Windows\system32\fontsub.dll 2011-09-22 07:32:53 ----A---- C:\Windows\system32\atmlib.dll 2011-09-22 07:32:53 ----A---- C:\Windows\system32\atmfd.dll 2011-09-22 07:31:03 ----A---- C:\Windows\system32\drivers\afd.sys 2011-09-22 07:29:27 ----A---- C:\Windows\system32\xmllite.dll 2011-09-22 07:29:25 ----A---- C:\Windows\system32\prevhost.exe 2011-09-22 07:29:22 ----A---- C:\Windows\system32\oleaut32.dll 2011-09-22 07:29:18 ----A---- C:\Windows\system32\ntoskrnl.exe 2011-09-22 07:29:18 ----A---- C:\Windows\system32\ntkrnlpa.exe 2011-09-22 07:18:02 ----A---- C:\Windows\system32\umpnpmgr.dll 2011-09-22 07:17:37 ----A---- C:\Windows\system32\kerberos.dll 2011-09-22 07:17:35 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys 2011-09-22 07:17:35 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys 2011-09-22 07:17:35 ----A---- C:\Windows\system32\drivers\mrxsmb.sys 2011-09-22 07:13:48 ----A---- C:\Windows\system32\tzres.dll 2011-09-22 07:13:40 ----A---- C:\Windows\system32\drivers\tcpip.sys 2011-09-22 07:13:38 ----A---- C:\Windows\system32\inetcomm.dll 2011-09-22 07:13:34 ----A---- C:\Windows\system32\tquery.dll 2011-09-22 07:13:34 ----A---- C:\Windows\system32\SearchProtocolHost.exe 2011-09-22 07:13:34 ----A---- C:\Windows\system32\SearchIndexer.exe 2011-09-22 07:13:34 ----A---- C:\Windows\system32\SearchFilterHost.exe 2011-09-22 07:13:34 ----A---- C:\Windows\system32\mssvp.dll 2011-09-22 07:13:34 ----A---- C:\Windows\system32\mssrch.dll 2011-09-22 07:13:34 ----A---- C:\Windows\system32\mssph.dll 2011-09-22 07:13:33 ----A---- C:\Windows\system32\mssphtb.dll 2011-09-22 07:13:33 ----A---- C:\Windows\system32\msscntrs.dll 2011-09-22 07:13:30 ----A---- C:\Windows\system32\FXSCOVER.exe 2011-09-22 07:13:27 ----A---- C:\Windows\system32\XpsPrint.dll 2011-09-22 07:13:24 ----A---- C:\Windows\system32\XpsGdiConverter.dll 2011-09-22 07:13:20 ----A---- C:\Windows\system32\sbe.dll 2011-09-22 07:13:20 ----A---- C:\Windows\system32\EncDec.dll 2011-09-22 07:13:20 ----A---- C:\Windows\system32\CPFilters.dll 2011-09-22 07:12:54 ----A---- C:\Windows\explorer.exe 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2011-09-22 07:12:08 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2011-09-22 07:12:08 ----A---- C:\Windows\system32\winsrv.dll 2011-09-22 07:12:08 ----A---- C:\Windows\system32\KernelBase.dll 2011-09-22 07:12:08 ----A---- C:\Windows\system32\kernel32.dll 2011-09-22 07:12:08 ----A---- C:\Windows\system32\conhost.exe 2011-09-22 07:11:52 ----A---- C:\Windows\system32\win32k.sys 2011-09-22 07:11:46 ----A---- C:\Windows\system32\odbctrac.dll 2011-09-22 07:11:46 ----A---- C:\Windows\system32\odbcjt32.dll 2011-09-22 07:11:46 ----A---- C:\Windows\system32\odbccu32.dll 2011-09-22 07:11:46 ----A---- C:\Windows\system32\odbccr32.dll 2011-09-22 07:11:46 ----A---- C:\Windows\system32\odbccp32.dll 2011-09-22 07:11:43 ----A---- C:\Windows\system32\d3d10_1.dll 2011-09-22 07:11:34 ----A---- C:\Windows\system32\mfc42u.dll 2011-09-22 07:11:34 ----A---- C:\Windows\system32\mfc42.dll 2011-09-22 07:11:24 ----A---- C:\Windows\system32\drivers\bowser.sys 2011-09-22 07:11:20 ----A---- C:\Windows\system32\poqexec.exe 2011-09-22 07:11:15 ----A---- C:\Windows\system32\drivers\Diskdump.sys 2011-09-22 07:11:11 ----A---- C:\Windows\system32\drivers\dxgmms1.sys 2011-09-21 21:48:09 ----D---- C:\Windows\system32\Atheros_L2 2011-09-21 21:46:42 ----D---- C:\Windows\system32\Adobe 2011-09-21 21:20:41 ----D---- C:\ProgramData\eXPert PDF 5 2011-09-21 21:18:15 ----D---- C:\Windows\system32\RTCOM 2011-09-21 21:18:02 ----A---- C:\Windows\system32\WavesLib.dll 2011-09-21 21:18:02 ----A---- C:\Windows\system32\WavesGUILib.dll 2011-09-21 21:18:02 ----A---- C:\Windows\system32\SRSWOW.dll 2011-09-21 21:18:02 ----A---- C:\Windows\system32\SRSTSXT.dll 2011-09-21 21:18:02 ----A---- C:\Windows\system32\SRSTSHD.dll 2011-09-21 21:18:01 ----A---- C:\Windows\system32\SRSHP360.dll 2011-09-21 21:18:01 ----A---- C:\Windows\system32\RtkPgExt.dll 2011-09-21 21:18:01 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys 2011-09-21 21:18:00 ----A---- C:\Windows\system32\RtkCoInst.dll 2011-09-21 21:18:00 ----A---- C:\Windows\system32\RtkApoApi.dll 2011-09-21 21:18:00 ----A---- C:\Windows\system32\RtkAPO.dll 2011-09-21 21:18:00 ----A---- C:\Windows\system32\RTEEP32A.dll 2011-09-21 21:18:00 ----A---- C:\Windows\system32\RTEEL32A.dll 2011-09-21 21:18:00 ----A---- C:\Windows\system32\RTEEG32A.dll 2011-09-21 21:18:00 ----A---- C:\Windows\system32\RTEED32A.dll 2011-09-21 21:18:00 ----A---- C:\Windows\system32\RP3DHT32.dll 2011-09-21 21:18:00 ----A---- C:\Windows\system32\RP3DAA32.dll 2011-09-21 21:18:00 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll 2011-09-21 21:18:00 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll 2011-09-21 21:17:59 ----A---- C:\Windows\system32\MaxxAudioEQ.dll 2011-09-21 21:17:59 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll 2011-09-21 21:17:59 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll 2011-09-21 21:17:59 ----A---- C:\Windows\system32\MaxxAudioAPO.dll 2011-09-21 21:17:57 ----A---- C:\Windows\system32\FMAPO.dll 2011-09-21 21:17:57 ----A---- C:\Windows\system32\DTSVoiceClarityDLL.dll 2011-09-21 21:17:57 ----A---- C:\Windows\system32\DTSSymmetryDLL.dll 2011-09-21 21:17:56 ----D---- C:\Program Files\Realtek 2011-09-21 21:17:56 ----A---- C:\Windows\system32\DTSS2SpeakerDLL.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\DTSNeoPCDLL.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\DTSLimiterDLL.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\DTSLFXAPO.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\DTSGFXAPONS.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\DTSGFXAPO.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\DTSGainCompensatorDLL.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\DTSBoostDLL.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\DTSBassEnhancementDLL.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\AERTARen.dll 2011-09-21 21:17:56 ----A---- C:\Windows\system32\AERTACap.dll 2011-09-21 21:17:54 ----HD---- C:\Program Files\Temp 2011-09-21 21:17:54 ----A---- C:\Windows\RtlExUpd.dll 2011-09-21 21:17:12 ----HD---- C:\Program Files\InstallShield Installation Information 2011-09-21 21:16:14 ----D---- C:\ProgramData\NVIDIA 2011-09-21 21:15:45 ----D---- C:\ProgramData\NVIDIA Corporation 2011-09-21 21:15:31 ----A---- C:\Windows\system32\OpenCL.dll 2011-09-21 21:15:31 ----A---- C:\Windows\system32\nvoglv32.dll 2011-09-21 21:15:31 ----A---- C:\Windows\system32\nvgenco322060.dll 2011-09-21 21:15:31 ----A---- C:\Windows\system32\nvdispco3220140.dll 2011-09-21 21:15:31 ----A---- C:\Windows\system32\nvd3dum.dll 2011-09-21 21:15:31 ----A---- C:\Windows\system32\nvcuvid.dll 2011-09-21 21:15:31 ----A---- C:\Windows\system32\nvcuvenc.dll 2011-09-21 21:15:31 ----A---- C:\Windows\system32\nvcuda.dll 2011-09-21 21:15:31 ----A---- C:\Windows\system32\nvcompiler.dll 2011-09-21 21:15:31 ----A---- C:\Windows\system32\nvapi.dll 2011-09-21 21:15:31 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys 2011-09-21 21:15:05 ----D---- C:\Program Files\NVIDIA Corporation 2011-09-21 21:14:50 ----D---- C:\NVIDIA 2011-09-21 18:49:58 ----D---- C:\Windows\Panther 2011-09-21 18:49:49 ----RASH---- C:\BOOTSECT.BAK 2011-09-21 18:49:47 ----D---- C:\Boot 2011-09-21 18:34:11 ----D---- C:\Windows\Sun 2011-09-21 16:52:42 ----D---- C:\Program Files\Windows Live 2011-09-21 16:52:03 ----D---- C:\Program Files\Microsoft Silverlight 2011-09-21 16:50:55 ----D---- C:\Program Files\Common Files\Windows Live 2011-09-21 16:49:01 ----D---- C:\Users\Christian Fernando\AppData\Roaming\eXPert PDF Editor 2011-09-21 16:48:23 ----D---- C:\IORRT 2011-09-21 16:46:22 ----A---- C:\Windows\system32\vsmon1.dll 2011-09-21 16:46:16 ----D---- C:\Windows\My Documents 2011-09-21 16:46:16 ----D---- C:\ProgramData\eXPert PDF Jobs 2011-09-21 16:46:16 ----D---- C:\ProgramData\eXPert PDF 2011-09-21 16:46:16 ----D---- C:\Program Files\Visagesoft 2011-09-21 16:42:36 ----D---- C:\Windows\system32\Wat 2011-09-21 16:42:33 ----D---- C:\Program Files\Windows Media Player Plus! 2011-09-21 16:41:54 ----D---- C:\Program Files\FirmTools 2011-09-21 16:40:50 ----D---- C:\Users\Christian Fernando\AppData\Roaming\DVDVideoSoftIEHelpers 2011-09-21 16:40:41 ----D---- C:\Program Files\Common Files\Plasmoo 2011-09-21 16:40:33 ----D---- C:\Users\Christian Fernando\AppData\Roaming\DVDVideoSoft 2011-09-21 16:40:23 ----D---- C:\Program Files\Common Files\DVDVideoSoft 2011-09-21 16:40:21 ----D---- C:\Program Files\DVDVideoSoft 2011-09-21 16:36:15 ----N---- C:\Windows\system32\MpSigStub.exe 2011-09-21 16:26:00 ----D---- C:\ProgramData\BVRP Software 2011-09-21 16:25:20 ----D---- C:\Program Files\MozBackup 2011-09-21 16:24:53 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Mozilla 2011-09-21 16:24:48 ----D---- C:\Program Files\Mozilla Firefox 2011-09-21 15:20:34 ----D---- C:\Users\Christian Fernando\AppData\Roaming\HP 2011-09-21 15:20:34 ----D---- C:\ProgramData\WEBREG 2011-09-21 15:19:00 ----D---- C:\Program Files\Common Files\HP 2011-09-21 15:18:52 ----D---- C:\UniScan 2011-09-21 15:18:41 ----D---- C:\Program Files\Common Files\Hewlett-Packard 2011-09-21 15:18:32 ----D---- C:\Program Files\HP 2011-09-21 15:18:32 ----D---- C:\Config.Msi 2011-09-21 15:17:25 ----D---- C:\ProgramData\HP 2011-09-21 15:16:54 ----D---- C:\ProgramData\Sun 2011-09-21 15:16:45 ----A---- C:\Windows\system32\deployJava1.dll 2011-09-21 15:16:39 ----D---- C:\Program Files\Java 2011-09-21 15:13:51 ----D---- C:\Program Files\Intel 2011-09-21 15:13:51 ----A---- C:\Windows\system32\CSVer.dll 2011-09-21 15:13:43 ----D---- C:\Intel 2011-09-21 15:12:03 ----D---- C:\Program Files\QuickTime 2011-09-21 15:12:02 ----D---- C:\ProgramData\Apple Computer 2011-09-21 15:11:38 ----D---- C:\Program Files\Common Files\Apple 2011-09-21 15:11:32 ----D---- C:\ProgramData\Apple 2011-09-21 15:11:32 ----D---- C:\Program Files\Apple Software Update 2011-09-21 15:07:27 ----D---- C:\Program Files\PowerISO 2011-09-21 15:07:20 ----D---- C:\ProgramData\Nero 2011-09-21 15:06:54 ----D---- C:\Program Files\Common Files\Nero 2011-09-21 15:06:48 ----D---- C:\Program Files\Nero 2011-09-21 15:02:20 ----A---- C:\Windows\system32\D3DCompiler_42.dll 2011-09-21 15:02:05 ----A---- C:\Windows\system32\D3DX9_42.dll 2011-09-21 15:01:50 ----A---- C:\Windows\system32\D3DX9_40.dll 2011-09-21 15:01:35 ----A---- C:\Windows\system32\d3dx9_35.dll 2011-09-21 15:01:21 ----A---- C:\Windows\system32\d3dx9_34.dll 2011-09-21 15:01:05 ----A---- C:\Windows\system32\d3dx9_30.dll 2011-09-21 14:55:20 ----D---- C:\ProgramData\Macromedia 2011-09-21 14:55:16 ----D---- C:\Program Files\Macromedia 2011-09-21 14:55:16 ----D---- C:\Program Files\Common Files\Macromedia 2011-09-21 14:54:24 ----D---- C:\Program Files\Common Files\InstallShield 2011-09-21 14:54:21 ----D---- C:\Windows\Downloaded Installations 2011-09-21 14:51:39 ----D---- C:\Users\Christian Fernando\AppData\Roaming\IDM 2011-09-21 14:51:38 ----D---- C:\Users\Christian Fernando\AppData\Roaming\DMCache 2011-09-21 14:51:34 ----D---- C:\Program Files\Internet Download Manager 2011-09-21 14:50:33 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Crystal Art Software 2011-09-21 14:50:18 ----A---- C:\Windows\system32\BASSMOD.dll 2011-09-21 14:50:08 ----D---- C:\Program Files\Crystal FTP Pro 2011-09-21 14:48:42 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Vso 2011-09-21 14:48:42 ----A---- C:\Windows\system32\drivers\pcouffin.sys 2011-09-21 14:48:42 ----A---- C:\Users\Christian Fernando\AppData\Roaming\pcouffin.sys 2011-09-21 14:48:42 ----A---- C:\Users\Christian Fernando\AppData\Roaming\inst.exe 2011-09-21 14:48:40 ----A---- C:\Windows\system32\Pncrt.dll 2011-09-21 14:48:40 ----A---- C:\Windows\system32\drv43260.dll 2011-09-21 14:48:40 ----A---- C:\Windows\system32\drv33260.dll 2011-09-21 14:48:40 ----A---- C:\Windows\system32\drv23260.dll 2011-09-21 14:48:39 ----D---- C:\Program Files\VSO 2011-09-21 14:47:21 ----D---- C:\ProgramData\Protexis 2011-09-21 14:47:20 ----D---- C:\ProgramData\Bitstream 2011-09-21 14:46:24 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Corel 2011-09-21 14:42:44 ----D---- C:\Program Files\Microsoft Visual Studio 9.0 2011-09-21 14:42:44 ----D---- C:\Program Files\Microsoft SDKs 2011-09-21 14:42:31 ----D---- C:\Program Files\gs 2011-09-21 14:42:20 ----D---- C:\Program Files\Common Files\Corel 2011-09-21 14:42:06 ----D---- C:\ProgramData\Corel 2011-09-21 14:40:11 ----D---- C:\Program Files\Corel 2011-09-21 14:33:06 ----A---- C:\Windows\system32\unrar.dll 2011-09-21 14:33:05 ----A---- C:\Windows\avisplitter.ini 2011-09-21 14:33:04 ----A---- C:\Windows\system32\yv12vfw.dll 2011-09-21 14:33:04 ----A---- C:\Windows\system32\xvidvfw.dll 2011-09-21 14:33:04 ----A---- C:\Windows\system32\xvidcore.dll 2011-09-21 14:33:04 ----A---- C:\Windows\system32\ff_vfw.dll 2011-09-21 14:33:02 ----D---- C:\Program Files\K-Lite Codec Pack 2011-09-21 14:31:36 ----D---- C:\Program Files\mp3DirectCut 2011-09-21 14:31:22 ----D---- C:\Program Files\CCleaner 2011-09-21 14:31:09 ----D---- C:\Program Files\Microsoft Synchronization Services 2011-09-21 14:31:08 ----D---- C:\Program Files\Common Files\DESIGNER 2011-09-21 14:31:00 ----D---- C:\Windows\PCHEALTH 2011-09-21 14:31:00 ----D---- C:\Program Files\Microsoft.NET 2011-09-21 14:31:00 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition 2011-09-21 14:30:06 ----D---- C:\Program Files\Microsoft Analysis Services 2011-09-21 14:29:50 ----D---- C:\Windows\system32\Macromed 2011-09-21 14:29:45 ----D---- C:\ProgramData\Microsoft Help 2011-09-21 14:29:45 ----D---- C:\Program Files\Microsoft Office 2011-09-21 14:29:37 ----RD---- C:\MSOCache 2011-09-21 14:29:28 ----D---- C:\ProgramData\Adobe 2011-09-21 14:28:39 ----D---- C:\Program Files\Common Files\Adobe AIR 2011-09-21 14:28:39 ----D---- C:\Program Files\Adobe 2011-09-21 14:28:37 ----SHD---- C:\Windows\Installer 2011-09-21 14:27:45 ----AH---- C:\Windows\system32\mlfcache.dat 2011-09-21 14:27:44 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Macromedia 2011-09-21 14:27:44 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Adobe 2011-09-21 14:22:40 ----D---- C:\Windows\system32\SPReview 2011-09-21 14:15:09 ----D---- C:\Program Files\uTorrent 2011-09-21 14:14:17 ----D---- C:\Users\Christian Fernando\AppData\Roaming\uTorrent 2011-09-21 14:08:57 ----A---- C:\Windows\system32\olepro32.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\odbc32.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\ntlanman.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\netiougc.exe 2011-09-21 14:08:57 ----A---- C:\Windows\system32\netiohlp.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\netcfgx.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\ncryptui.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\Mystify.scr 2011-09-21 14:08:57 ----A---- C:\Windows\system32\msxml3.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\msvidc32.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\msvfw32.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\mprddm.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\MediaMetadataHandler.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\MdSched.exe 2011-09-21 14:08:57 ----A---- C:\Windows\system32\Mcx2Svc.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\mcmde.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\mciavi32.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\mcbuilder.exe 2011-09-21 14:08:57 ----A---- C:\Windows\system32\mblctr.exe 2011-09-21 14:08:57 ----A---- C:\Windows\system32\mapistub.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\mapi32.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\lsmproxy.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\LSCSHostPolicy.dll 2011-09-21 14:08:57 ----A---- C:\Windows\system32\lpremove.exe 2011-09-21 14:08:57 ----A---- C:\Windows\system32\lpksetup.exe 2011-09-21 14:08:57 ----A---- C:\Windows\system32\LogonUI.exe 2011-09-21 14:08:57 ----A---- C:\Windows\system32\KMSVC.DLL 2011-09-21 14:08:57 ----A---- C:\Windows\system32\KBDUS.DLL 2011-09-21 14:08:57 ----A---- C:\Windows\system32\KBDPO.DLL 2011-09-21 14:08:57 ----A---- C:\Windows\system32\KBDINTEL.DLL 2011-09-21 14:08:57 ----A---- C:\Windows\system32\KBDINBEN.DLL 2011-09-21 14:08:57 ----A---- C:\Windows\system32\KBDBULG.DLL 2011-09-21 14:08:57 ----A---- C:\Windows\system32\drivers\netio.sys 2011-09-21 14:08:57 ----A---- C:\Windows\system32\drivers\ndproxy.sys 2011-09-21 14:08:57 ----A---- C:\Windows\system32\drivers\mrxdav.sys 2011-09-21 14:08:57 ----A---- C:\Windows\system32\drivers\mountmgr.sys 2011-09-21 14:08:57 ----A---- C:\Windows\system32\drivers\ks.sys 2011-09-21 14:08:56 ----A---- C:\Windows\system32\nlsbres.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\mstask.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\msrle32.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\msdri.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\mscories.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\mscoree.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\msconfig.exe 2011-09-21 14:08:56 ----A---- C:\Windows\system32\MSAC3ENC.DLL 2011-09-21 14:08:56 ----A---- C:\Windows\system32\iphlpsvc.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\IPHLPAPI.DLL 2011-09-21 14:08:56 ----A---- C:\Windows\system32\imapi2.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\iasrecst.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\httpapi.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\halmacpi.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\halacpi.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\hal.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\drivers\msahci.sys 2011-09-21 14:08:56 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys 2011-09-21 14:08:56 ----A---- C:\Windows\system32\drivers\ataport.sys 2011-09-21 14:08:56 ----A---- C:\Windows\system32\drivers\acpi.sys 2011-09-21 14:08:56 ----A---- C:\Windows\system32\drivers\1394ohci.sys 2011-09-21 14:08:56 ----A---- C:\Windows\system32\Display.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\dfshim.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\defaultlocationcpl.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\davclnt.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\d3d9.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\d3d11.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\d3d10level9.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\cryptui.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\consent.exe 2011-09-21 14:08:56 ----A---- C:\Windows\system32\certcli.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\C_ISCII.DLL 2011-09-21 14:08:56 ----A---- C:\Windows\system32\bootres.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\biocpl.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\basecsp.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\AxInstSv.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\avifil32.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\authui.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\AuthFWSnapin.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\asycfilt.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\appinfo.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\advapi32.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\adsldp.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\activeds.dll 2011-09-21 14:08:56 ----A---- C:\Windows\system32\acppage.dll 2011-09-21 14:08:55 ----A---- C:\Windows\twain_32.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\XpsRasterService.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wvc.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wuwebv.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wuapp.exe 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wtsapi32.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wsqmcons.exe 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wscapi.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\WPDSp.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wpd_ci.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wmpps.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wmicmiplugin.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wlangpui.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wksprt.exe 2011-09-21 14:08:55 ----A---- C:\Windows\system32\winhttp.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wimserv.exe 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wimgapi.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\wiadefui.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\VAN.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\uxlib.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\twext.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\tssrvlic.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\themecpl.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\tcpipcfg.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\tapisrv.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\StructuredQuery.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\sscore.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\srvsvc.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\srrstr.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\sqlsrv32.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\spwizres.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\spwizeng.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\sppobjs.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\sppnp.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\spp.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\spoolsv.exe 2011-09-21 14:08:55 ----A---- C:\Windows\system32\spbcd.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\shlwapi.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\shacct.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\onex.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\FXSSVC.exe 2011-09-21 14:08:55 ----A---- C:\Windows\system32\FXSMON.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\fveapi.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\framedynos.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\framedyn.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\fms.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\ExplorerFrame.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\evr.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\eudcedit.exe 2011-09-21 14:08:55 ----A---- C:\Windows\system32\dxgi.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\dskquoui.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\dsauth.dll 2011-09-21 14:08:55 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys 2011-09-21 14:08:55 ----A---- C:\Windows\system32\drivers\tcpipreg.sys 2011-09-21 14:08:55 ----A---- C:\Windows\system32\dps.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\wdc.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\WavDest.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\Vault.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\utildll.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\usp10.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\untfs.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\unlodctr.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\unattend.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\umpo.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\setupcl.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\scecli.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\samcli.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\rpcss.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\Robocopy.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\RMActivate.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\remotepg.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\recovery.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\ReAgent.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\rdpwsx.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\rdpudd.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\rdpshell.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\rdpinit.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\RDPENCDD.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\rdpcorets.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\rdpcorekmts.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\rdpcore.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\rdpclip.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\raschap.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\RacEngn.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\quartz.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\QSVRMGMT.DLL 2011-09-21 14:08:54 ----A---- C:\Windows\system32\QSHVHOST.DLL 2011-09-21 14:08:54 ----A---- C:\Windows\system32\QCLIPROV.DLL 2011-09-21 14:08:54 ----A---- C:\Windows\system32\QAGENTRT.DLL 2011-09-21 14:08:54 ----A---- C:\Windows\system32\QAGENT.DLL 2011-09-21 14:08:54 ----A---- C:\Windows\system32\proquota.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\propsys.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\prnfldr.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\PrintIsolationProxy.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\PrintBrmUi.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\PresentationSettings.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\pifmgr.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\perfts.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\perfmon.exe 2011-09-21 14:08:54 ----A---- C:\Windows\system32\pdhui.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\onexui.dll 2011-09-21 14:08:54 ----A---- C:\Windows\system32\drivers\wanarp.sys 2011-09-21 14:08:54 ----A---- C:\Windows\system32\drivers\vms3cap.sys 2011-09-21 14:08:54 ----A---- C:\Windows\system32\drivers\sffp_sd.sys 2011-09-21 14:08:54 ----A---- C:\Windows\system32\drivers\sbp2port.sys 2011-09-21 14:08:54 ----A---- C:\Windows\system32\drivers\rdyboost.sys 2011-09-21 14:08:54 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys 2011-09-21 14:08:53 ----A---- C:\Windows\system32\secproc.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\schtasks.exe 2011-09-21 14:08:53 ----A---- C:\Windows\system32\scansetting.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\PerfCenterCPL.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\ntprint.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\ntdll.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\msasn1.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\mobsync.exe 2011-09-21 14:08:53 ----A---- C:\Windows\system32\MMDevAPI.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\mmcndmgr.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\mfreadwrite.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\MFPlay.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\mfc40.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\mciqtz32.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\lsm.exe 2011-09-21 14:08:53 ----A---- C:\Windows\system32\logoff.exe 2011-09-21 14:08:53 ----A---- C:\Windows\system32\logman.exe 2011-09-21 14:08:53 ----A---- C:\Windows\system32\logagent.exe 2011-09-21 14:08:53 ----A---- C:\Windows\system32\localsec.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\ListSvc.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\KBDTUQ.DLL 2011-09-21 14:08:53 ----A---- C:\Windows\system32\KBDTUF.DLL 2011-09-21 14:08:53 ----A---- C:\Windows\system32\KBDNEPR.DLL 2011-09-21 14:08:53 ----A---- C:\Windows\system32\KBDBLR.DLL 2011-09-21 14:08:53 ----A---- C:\Windows\system32\KBDBASH.DLL 2011-09-21 14:08:53 ----A---- C:\Windows\system32\itircl.dll 2011-09-21 14:08:53 ----A---- C:\Windows\system32\iprtrmgr.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\nslookup.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\nshipsec.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\nlasvc.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\nlaapi.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\netutils.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\netplwiz.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\netid.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\netapi32.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\ncsi.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\Narrator.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\NAPHLPR.DLL 2011-09-21 14:08:52 ----A---- C:\Windows\system32\mydocs.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\MuiUnattend.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\muifontsetup.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\mtxclu.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\msscp.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\msnetobj.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\msihnd.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\msi.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\msg.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\msdtctm.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\imapi2fs.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\gpprefcl.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\gameux.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\fvecpl.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\fphc.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\fontext.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\drivers\partmgr.sys 2011-09-21 14:08:52 ----A---- C:\Windows\system32\drivers\ndiswan.sys 2011-09-21 14:08:52 ----A---- C:\Windows\system32\drivers\ndis.sys 2011-09-21 14:08:52 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS 2011-09-21 14:08:52 ----A---- C:\Windows\system32\diskpart.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\dhcpcore.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\d3d10warp.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\cscui.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\cryptsvc.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\crypt32.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\credui.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\comdlg32.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\cmstp.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\chgusr.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\chgport.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\chglogon.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\change.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\certprop.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\CertEnroll.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\Bubbles.scr 2011-09-21 14:08:52 ----A---- C:\Windows\system32\browcli.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\blackbox.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\bitsadmin.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\bcdsrv.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\bcdedit.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\bcdboot.exe 2011-09-21 14:08:52 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\apphelp.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\amstream.dll 2011-09-21 14:08:52 ----A---- C:\Windows\system32\accessibilitycpl.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\WMPhoto.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\umrdp.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\umb.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\tzutil.exe 2011-09-21 14:08:51 ----A---- C:\Windows\system32\tsmf.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\tskill.exe 2011-09-21 14:08:51 ----A---- C:\Windows\system32\tsdiscon.exe 2011-09-21 14:08:51 ----A---- C:\Windows\system32\tscon.exe 2011-09-21 14:08:51 ----A---- C:\Windows\system32\TRAPI.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\themeui.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\taskschd.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\TabSvc.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\systemcpl.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\sysmain.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\SyncCenter.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\sxs.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\sud.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\ssText3d.scr 2011-09-21 14:08:51 ----A---- C:\Windows\system32\srvcli.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\input.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\imm32.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\iasrad.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\iasacct.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\efscore.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\dxdiagn.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\dwmredir.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\DShowRdpFilter.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\drmmgrtn.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\dot3ui.dll 2011-09-21 14:08:51 ----A---- C:\Windows\system32\dosx.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\wwanprotdim.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\WUDFx.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\WUDFSvc.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\WUDFPlatform.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\WUDFHost.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\WUDFCoinstaller.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\wshbth.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\WSDApi.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\ws2_32.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\wpdbusenum.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\WMVDECOD.DLL 2011-09-21 14:08:50 ----A---- C:\Windows\system32\wmpsrcwp.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\wmdrmsdk.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\WMADMOD.DLL 2011-09-21 14:08:50 ----A---- C:\Windows\system32\Wldap32.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\wkssvc.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\wisptis.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\WinSAT.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\WFS.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\werconcpl.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\webio.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\vssapi.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\vpnike.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\vdsutil.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\vds.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\usercpl.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\upnp.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\riched32.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\riched20.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\reset.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\relog.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\recdisc.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\RDVGHelper.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\rdpendp.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\rdpcfgex.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\rastls.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\qwinsta.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\quser.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\query.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\qprocess.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\qdv.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\qcap.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\qappsrv.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\puiobj.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\provsvc.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\prncache.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\printui.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\PresentationHostProxy.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\PresentationHost.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\powercpl.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\PortableDeviceSyncProvider.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\PortableDeviceStatus.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\PortableDeviceApi.dll 2011-09-21 14:08:50 ----A---- C:\Windows\system32\PkgMgr.exe 2011-09-21 14:08:50 ----A---- C:\Windows\system32\drivers\WUDFRd.sys 2011-09-21 14:08:50 ----A---- C:\Windows\system32\drivers\WUDFPf.sys 2011-09-21 14:08:50 ----A---- C:\Windows\system32\drivers\volsnap.sys 2011-09-21 14:08:50 ----A---- C:\Windows\system32\drivers\usbrpm.sys 2011-09-21 14:08:50 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys 2011-09-21 14:08:50 ----A---- C:\Windows\system32\drivers\USBCAMD.sys 2011-09-21 14:08:50 ----A---- C:\Windows\system32\drivers\RDPCDD.sys 2011-09-21 14:08:49 ----A---- C:\Windows\system32\srchadmin.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\sqlcese30.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\spwizui.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\spreview.exe 2011-09-21 14:08:49 ----A---- C:\Windows\system32\sppwinob.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\sppinst.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\sppc.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\spinstall.exe 2011-09-21 14:08:49 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\shunimpl.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\shsvcs.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\shsetup.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\shimgvw.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\shadow.exe 2011-09-21 14:08:49 ----A---- C:\Windows\system32\setupugc.exe 2011-09-21 14:08:49 ----A---- C:\Windows\system32\setupcln.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\setupapi.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\SearchFolder.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\schedsvc.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\schedcli.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\samsrv.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\rwinsta.exe 2011-09-21 14:08:49 ----A---- C:\Windows\system32\MPSSVC.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\mprapi.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\mimefilt.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\mfc40u.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\lsasrv.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\logoncli.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\KBDUGHR1.DLL 2011-09-21 14:08:49 ----A---- C:\Windows\system32\KBDTAJIK.DLL 2011-09-21 14:08:49 ----A---- C:\Windows\system32\IPSECSVC.DLL 2011-09-21 14:08:49 ----A---- C:\Windows\system32\imagehlp.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\ifsutil.dll 2011-09-21 14:08:49 ----A---- C:\Windows\system32\drivers\scfilter.sys 2011-09-21 14:08:49 ----A---- C:\Windows\system32\drivers\mpio.sys 2011-09-21 14:08:48 ----A---- C:\Windows\system32\rastapi.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\rasppp.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\qmgr.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\qdvd.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\qasf.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\pla.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\pdh.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\OobeFldr.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\OnLineIDCpl.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\ocsetup.exe 2011-09-21 14:08:48 ----A---- C:\Windows\system32\ocsetapi.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\ntshrui.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\networkmap.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\networkexplorer.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\netjoin.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\netfxperf.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\netcfg.exe 2011-09-21 14:08:48 ----A---- C:\Windows\system32\nci.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\NAPCRYPT.DLL 2011-09-21 14:08:48 ----A---- C:\Windows\system32\MultiDigiMon.exe 2011-09-21 14:08:48 ----A---- C:\Windows\system32\msxml6.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\msv1_0.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\mstscax.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\mstsc.exe 2011-09-21 14:08:48 ----A---- C:\Windows\system32\mspbda.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\msiexec.exe 2011-09-21 14:08:48 ----A---- C:\Windows\system32\msdrm.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\mscorier.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\localspl.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\KBDMON.DLL 2011-09-21 14:08:48 ----A---- C:\Windows\system32\KBDMAORI.DLL 2011-09-21 14:08:48 ----A---- C:\Windows\system32\KBDINORI.DLL 2011-09-21 14:08:48 ----A---- C:\Windows\system32\KBDGR1.DLL 2011-09-21 14:08:48 ----A---- C:\Windows\system32\drivers\rdbss.sys 2011-09-21 14:08:48 ----A---- C:\Windows\system32\drivers\ndisuio.sys 2011-09-21 14:08:48 ----A---- C:\Windows\system32\drivers\msiscsi.sys 2011-09-21 14:08:48 ----A---- C:\Windows\system32\drivers\msdsm.sys 2011-09-21 14:08:48 ----A---- C:\Windows\system32\drivers\ksecdd.sys 2011-09-21 14:08:48 ----A---- C:\Windows\system32\drivers\kbdhid.sys 2011-09-21 14:08:48 ----A---- C:\Windows\system32\drivers\dfsc.sys 2011-09-21 14:08:48 ----A---- C:\Windows\system32\drivers\appid.sys 2011-09-21 14:08:48 ----A---- C:\Windows\system32\DiagCpl.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\dfrgui.exe 2011-09-21 14:08:48 ----A---- C:\Windows\system32\DevicePairingFolder.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\DeviceCenter.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\dbghelp.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\dbgeng.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\d3d10_1core.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\cscdll.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\cscapi.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\comctl32.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\clusapi.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\ci.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\cfgmgr32.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\certmgr.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\cdosys.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\cdd.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\cabview.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\BlbEvents.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\basesrv.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\audiodev.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\appmgr.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\aitagent.exe 2011-09-21 14:08:48 ----A---- C:\Windows\system32\AdmTmpl.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\ActionQueue.dll 2011-09-21 14:08:48 ----A---- C:\Windows\system32\aaclient.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\vaultsvc.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\userinit.exe 2011-09-21 14:08:47 ----A---- C:\Windows\system32\user32.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\UIRibbonRes.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\UIRibbon.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\TSWorkspace.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2011-09-21 14:08:47 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\tsgqec.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\rdpd3d.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\iccvid.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\icaapi.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\hgprint.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\gdi32.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\FXSTIFF.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\fde.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\Faultrep.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\elsTrans.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\DxpTaskSync.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\dxmasf.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\dsuiext.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\drvstore.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\drivers\umbus.sys 2011-09-21 14:08:47 ----A---- C:\Windows\system32\drivers\tssecsrv.sys 2011-09-21 14:08:47 ----A---- C:\Windows\system32\drivers\tdx.sys 2011-09-21 14:08:47 ----A---- C:\Windows\system32\drivers\hwpolicy.sys 2011-09-21 14:08:47 ----A---- C:\Windows\system32\drivers\http.sys 2011-09-21 14:08:47 ----A---- C:\Windows\system32\drivers\HdAudio.sys 2011-09-21 14:08:47 ----A---- C:\Windows\system32\drivers\fvevol.sys 2011-09-21 14:08:47 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys 2011-09-21 14:08:47 ----A---- C:\Windows\system32\dot3cfg.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\diskraid.exe 2011-09-21 14:08:47 ----A---- C:\Windows\system32\bitsperf.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\BdeHdCfg.exe 2011-09-21 14:08:47 ----A---- C:\Windows\system32\batmeter.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\AzSqlExt.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\azroles.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\autoplay.dll 2011-09-21 14:08:47 ----A---- C:\Windows\system32\autofmt.exe 2011-09-21 14:08:47 ----A---- C:\Windows\system32\autochk.exe 2011-09-21 14:08:47 ----A---- C:\Windows\bfsvc.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\zipfldr.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\xpsservices.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wwanconn.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wups.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wudriver.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wucltux.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wuapi.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wsnmp32.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wpdwcn.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\WPDShServiceObj.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wpdshext.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\WMVSDECD.DLL 2011-09-21 14:08:46 ----A---- C:\Windows\system32\WMVCORE.DLL 2011-09-21 14:08:46 ----A---- C:\Windows\system32\WMSPDMOD.DLL 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wmploc.DLL 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wmp.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wlanui.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wlanpref.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\WinSATAPI.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\winmm.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\winlogon.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wiavideo.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wiaservc.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wiarpc.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wevtsvc.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\WerFaultSecure.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wer.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wdscore.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wdiasqmmodule.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wbengine.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\wbemcomn.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\VSSVC.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\vpnikeapi.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\vmstorfltres.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\VmdCoinstall.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\tlscsp.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\taskhost.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\taskeng.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\tabcal.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\t2embed.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\RMActivate_ssp.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\Ribbons.scr 2011-09-21 14:08:46 ----A---- C:\Windows\system32\resutils.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\repair-bde.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\RelPost.exe 2011-09-21 14:08:46 ----A---- C:\Windows\system32\regapi.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\rdprefdrvapi.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\RDPREFDD.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\rdpencom.dll 2011-09-21 14:08:46 ----A---- C:\Windows\system32\drivers\vmstorfl.sys 2011-09-21 14:08:46 ----A---- C:\Windows\system32\drivers\tdi.sys 2011-09-21 14:08:45 ----A---- C:\Windows\system32\syssetup.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\syncui.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\sspisrv.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\sspicli.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\spwmp.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\spopk.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\slwga.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\sisbkup.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\shwebsvc.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\secur32.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\secproc_ssp_isv.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\secproc_ssp.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\runonce.exe 2011-09-21 14:08:45 ----A---- C:\Windows\system32\rtutils.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\rpcrt4.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\rpchttp.dll 2011-09-21 14:08:45 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe 2011-09-21 14:08:45 ----A---- C:\Windows\system32\drivers\storvsc.sys 2011-09-21 14:08:45 ----A---- C:\Windows\system32\drivers\scsiport.sys 2011-09-21 14:08:44 ----A---- C:\Windows\system32\shdocvw.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\SessEnv.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\secproc_isv.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\sdrsvc.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\sdengin2.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\sdcpl.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\sdclt.exe 2011-09-21 14:08:44 ----A---- C:\Windows\system32\scrptadm.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\schannel.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\scesrv.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\scavengeui.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\rstrui.exe 2011-09-21 14:08:44 ----A---- C:\Windows\system32\RpcRtRemote.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\RMActivate_isv.exe 2011-09-21 14:08:44 ----A---- C:\Windows\system32\ReAgentc.exe 2011-09-21 14:08:44 ----A---- C:\Windows\system32\rdpsign.exe 2011-09-21 14:08:44 ----A---- C:\Windows\system32\rdpdd.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\rasmans.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\QUTIL.DLL 2011-09-21 14:08:44 ----A---- C:\Windows\system32\Query.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\qedit.dll 2011-09-21 14:08:44 ----A---- C:\Windows\system32\PushPrinterConnections.exe 2011-09-21 14:08:44 ----A---- C:\Windows\system32\drivers\rmcast.sys 2011-09-21 14:08:44 ----A---- C:\Windows\system32\drivers\rdpwd.sys 2011-09-21 14:08:44 ----A---- C:\Windows\system32\drivers\rdpdr.sys 2011-09-21 14:08:43 ----A---- C:\Windows\system32\wpccpl.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\wcncsvc.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\wavemsp.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\w32tm.exe 2011-09-21 14:08:43 ----A---- C:\Windows\system32\vmictimeprovider.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\vmicsvc.exe 2011-09-21 14:08:43 ----A---- C:\Windows\system32\vmicres.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\vmbusres.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\vmbuspipe.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\VmbusCoinstaller.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\vfwwdm32.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\vdsbas.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\userenv.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\UserAccountControlSettings.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\unimdmat.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\tspubwmi.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\TSpkg.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\tscfgwmi.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\tsbyuv.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\profsvc.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\profprov.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\prntvpt.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\PnPUnattend.exe 2011-09-21 14:08:43 ----A---- C:\Windows\system32\pnidui.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\photowiz.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\PhotoScreensaver.scr 2011-09-21 14:08:43 ----A---- C:\Windows\system32\OpcServices.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\olethk32.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\ole32.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\odbcconf.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\nshwfp.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\nrpsrv.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\nltest.exe 2011-09-21 14:08:43 ----A---- C:\Windows\system32\netshell.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\netlogon.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\netdiagfx.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\netcenter.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\netbtugc.exe 2011-09-21 14:08:43 ----A---- C:\Windows\system32\net1.exe 2011-09-21 14:08:43 ----A---- C:\Windows\system32\NaturalLanguage6.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\napdsnap.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\msyuv.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\mswsock.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\MSVidCtl.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\msutb.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\msorcl32.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL 2011-09-21 14:08:43 ----A---- C:\Windows\system32\msinfo32.exe 2011-09-21 14:08:43 ----A---- C:\Windows\system32\msieftp.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\msftedit.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\msdmo.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\mscms.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\migisol.dll 2011-09-21 14:08:43 ----A---- C:\Windows\system32\drivers\volmgr.sys 2011-09-21 14:08:43 ----A---- C:\Windows\system32\drivers\VMBusHID.sys 2011-09-21 14:08:43 ----A---- C:\Windows\system32\drivers\vmbus.sys 2011-09-21 14:08:43 ----A---- C:\Windows\system32\drivers\vhdmp.sys 2011-09-21 14:08:43 ----A---- C:\Windows\system32\drivers\udfs.sys 2011-09-21 14:08:43 ----A---- C:\Windows\system32\drivers\tunnel.sys 2011-09-21 14:08:43 ----A---- C:\Windows\system32\drivers\pci.sys 2011-09-21 14:08:43 ----A---- C:\Windows\system32\drivers\netbt.sys 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wusa.exe 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wups2.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wuaueng.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wuauclt.exe 2011-09-21 14:08:42 ----A---- C:\Windows\system32\WsmSvc.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wshirda.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wsdchngr.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wmpshell.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wmpmde.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\WMPEncEn.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wmpeffects.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wmpdxm.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\WMNetMgr.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wmdrmnet.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wmdrmdev.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wlanmsm.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wkscli.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\wintrust.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\winsta.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\WinSCard.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\winresume.exe 2011-09-21 14:08:42 ----A---- C:\Windows\system32\winload.exe 2011-09-21 14:08:42 ----A---- C:\Windows\system32\WindowsCodecs.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeResults.exe 2011-09-21 14:08:42 ----A---- C:\Windows\system32\win32spl.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\webservices.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\WebClnt.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\takeown.exe 2011-09-21 14:08:42 ----A---- C:\Windows\system32\stobject.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\srcore.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\sqmapi.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\sppuinotify.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\sppsvc.exe 2011-09-21 14:08:42 ----A---- C:\Windows\system32\sppcomapi.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\SndVolSSO.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\SndVol.exe 2011-09-21 14:08:42 ----A---- C:\Windows\system32\SmiEngine.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\slui.exe 2011-09-21 14:08:42 ----A---- C:\Windows\system32\shgina.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\shell32.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\sharemediacpl.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\sethc.exe 2011-09-21 14:08:42 ----A---- C:\Windows\system32\setbcdlocale.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\SensorsCpl.dll 2011-09-21 14:08:42 ----A---- C:\Windows\system32\drivers\winhv.sys 2011-09-21 14:08:41 ----A---- C:\Windows\system32\thumbcache.dll 2011-09-21 14:08:41 ----A---- C:\Windows\system32\termsrv.dll 2011-09-21 14:08:41 ----A---- C:\Windows\system32\termmgr.dll 2011-09-21 14:08:41 ----A---- C:\Windows\system32\taskmgr.exe 2011-09-21 14:08:41 ----A---- C:\Windows\system32\taskcomp.dll 2011-09-21 14:08:41 ----A---- C:\Windows\system32\taskbarcpl.dll 2011-09-21 14:08:41 ----A---- C:\Windows\system32\sysclass.dll 2011-09-21 14:08:41 ----A---- C:\Windows\system32\drivers\termdd.sys 2011-09-21 14:08:41 ----A---- C:\Windows\system32\drivers\tdtcp.sys 2011-09-21 14:08:41 ----A---- C:\Windows\system32\drivers\tdpipe.sys 2011-09-21 14:08:40 ----A---- C:\Windows\system32\mfds.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\mf.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\MCEWMDRMNDBootstrap.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\manage-bde.exe 2011-09-21 14:08:40 ----A---- C:\Windows\system32\luainstall.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDTURME.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDSG.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDSF.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDLT1.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\kbdlk41a.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDINTAM.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDINMAR.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDINKAN.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDINHIN.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDGKL.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDGEO.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\KBDCZ1.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\iyuv_32.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\iTVData.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\isoburn.exe 2011-09-21 14:08:40 ----A---- C:\Windows\system32\iscsium.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\iscsicli.exe 2011-09-21 14:08:40 ----A---- C:\Windows\system32\ipsmsnap.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\inetpp.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\inetmib1.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\IKEEXT.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\IcCoinstall.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\HotStartUserAgent.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\hgcpl.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\hbaapi.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\gpsvc.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\FWPUCLNT.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\ftp.exe 2011-09-21 14:08:40 ----A---- C:\Windows\system32\FirewallControlPanel.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\findstr.exe 2011-09-21 14:08:40 ----A---- C:\Windows\system32\fdeploy.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\EhStorAPI.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\drivers\hidusb.sys 2011-09-21 14:08:40 ----A---- C:\Windows\system32\drivers\hidclass.sys 2011-09-21 14:08:40 ----A---- C:\Windows\system32\drivers\hdaudbus.sys 2011-09-21 14:08:40 ----A---- C:\Windows\system32\drivers\cdrom.sys 2011-09-21 14:08:40 ----A---- C:\Windows\system32\drivers\acpipmi.sys 2011-09-21 14:08:40 ----A---- C:\Windows\system32\cmd.exe 2011-09-21 14:08:40 ----A---- C:\Windows\system32\CertPolEng.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\cca.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\calc.exe 2011-09-21 14:08:40 ----A---- C:\Windows\system32\cabinet.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\browseui.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\browser.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\BFE.DLL 2011-09-21 14:08:40 ----A---- C:\Windows\system32\azroleui.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\autoconv.exe 2011-09-21 14:08:40 ----A---- C:\Windows\system32\audiosrv.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\AudioSes.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\audiodg.exe 2011-09-21 14:08:40 ----A---- C:\Windows\system32\aepdu.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\aeinv.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\actxprxy.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\ActionCenterCPL.dll 2011-09-21 14:08:40 ----A---- C:\Windows\system32\ActionCenter.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\eapphost.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\eappgnui.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\eapp3hst.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\DXPTaskRingtone.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\DXP.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\dwmcore.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\drivers\csc.sys 2011-09-21 14:08:39 ----A---- C:\Windows\system32\drivers\CompositeBus.sys 2011-09-21 14:08:39 ----A---- C:\Windows\system32\dpx.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\dpnaddr.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\dot3svc.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\dot3msm.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\dot3api.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\dnscmmc.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\djoin.exe 2011-09-21 14:08:39 ----A---- C:\Windows\system32\diagperf.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\cscsvc.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\cscobj.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\CscMig.dll 2011-09-21 14:08:39 ----A---- C:\Windows\system32\credssp.dll 2011-09-21 14:07:32 ----D---- C:\Windows\system32\EventProviders 2011-09-21 14:06:31 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys 2011-09-21 14:06:25 ----D---- C:\Program Files\DAEMON Tools Lite 2011-09-21 14:06:14 ----D---- C:\Users\Christian Fernando\AppData\Roaming\DAEMON Tools Lite 2011-09-21 14:06:14 ----D---- C:\ProgramData\DAEMON Tools Lite 2011-09-21 14:01:41 ----A---- C:\Windows\system32\PerfStringBackup.INI 2011-09-21 13:57:35 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Identities 2011-09-21 13:57:19 ----SD---- C:\Users\Christian Fernando\AppData\Roaming\Microsoft 2011-09-21 13:57:19 ----D---- C:\Users\Christian Fernando\AppData\Roaming\Media Center Programs 2011-09-21 13:57:13 ----SHD---- C:\ProgramData\Modelos 2011-09-21 13:57:13 ----SHD---- C:\ProgramData\Menu Iniciar 2011-09-21 13:57:13 ----SHD---- C:\ProgramData\Favoritos 2011-09-21 13:57:13 ----SHD---- C:\ProgramData\Documentos 2011-09-21 13:57:13 ----SHD---- C:\ProgramData\Dados de aplicativos 2011-09-21 13:57:13 ----SHD---- C:\Program Files\Common Files\Sistema 2011-09-21 13:57:13 ----SHD---- C:\Program Files\Arquivos Comuns 2011-09-21 13:57:13 ----SHD---- C:\Arquivos de Programas 2011-09-21 13:57:13 ----D---- C:\Recovery 2011-09-21 13:53:50 ----D---- C:\Windows\SoftwareDistribution 2011-09-21 13:51:20 ----D---- C:\Windows\Prefetch 2011-09-21 13:51:09 ----ASH---- C:\pagefile.sys 2011-09-21 13:51:02 ----SHD---- C:\System Volume Information 2011-09-21 13:51:02 ----ASH---- C:\hiberfil.sys ======List of files/folders modified in the last 1 month====== 2011-10-03 17:40:52 ----D---- C:\Windows\Temp 2011-10-03 17:40:38 ----RD---- C:\Program Files 2011-10-03 16:11:50 ----D---- C:\Program Files\Common Files 2011-10-03 16:08:23 ----D---- C:\Windows\System32 2011-10-03 15:59:54 ----D---- C:\Windows\inf 2011-10-03 14:34:03 ----D---- C:\ProgramData 2011-10-03 14:32:54 ----D---- C:\Windows\system32\drivers 2011-10-03 14:15:59 ----D---- C:\Windows\system32\Tasks 2011-10-03 14:15:03 ----D---- C:\Windows\system32\config 2011-10-03 14:14:27 ----D---- C:\Windows\Offline Web Pages 2011-10-03 13:06:44 ----D---- C:\Windows\system32\catroot2 2011-10-02 20:47:12 ----D---- C:\Windows\system32\NDF 2011-10-02 20:40:25 ----D---- C:\Windows 2011-10-02 20:40:25 ----A---- C:\Windows\system.ini 2011-10-02 20:40:08 ----D---- C:\Windows\system32\drivers\etc 2011-10-02 20:35:15 ----D---- C:\Windows\AppPatch 2011-10-02 20:18:59 ----DC---- C:\Windows\$NtUninstallKB43327$ 2011-10-02 20:05:50 ----D---- C:\Windows\Resources 2011-10-01 10:18:07 ----RSD---- C:\Windows\Fonts 2011-09-30 23:29:47 ----A---- C:\Windows\win.ini 2011-09-30 12:21:31 ----D---- C:\Windows\Logs 2011-09-28 17:54:01 ----RSD---- C:\Windows\assembly 2011-09-25 09:49:20 ----D---- C:\Windows\rescache 2011-09-25 09:43:42 ----D---- C:\Windows\system32\wdi 2011-09-25 07:31:31 ----D---- C:\Windows\winsxs 2011-09-25 07:30:57 ----D---- C:\Program Files\Internet Explorer 2011-09-25 01:16:32 ----D---- C:\Windows\system32\pt-BR 2011-09-25 01:16:31 ----D---- C:\Windows\system32\migration 2011-09-25 01:16:31 ----D---- C:\Windows\system32\en-US 2011-09-25 01:16:31 ----D---- C:\Windows\PolicyDefinitions 2011-09-25 00:42:48 ----D---- C:\Windows\servicing 2011-09-25 00:42:23 ----D---- C:\Windows\system32\catroot 2011-09-25 00:28:29 ----D---- C:\Windows\debug 2011-09-24 16:16:00 ----D---- C:\Windows\Help 2011-09-24 14:41:57 ----D---- C:\Program Files\Microsoft Games 2011-09-24 03:16:46 ----D---- C:\Windows\system32\DriverStore 2011-09-23 23:03:05 ----D---- C:\Windows\Microsoft.NET 2011-09-21 21:17:23 ----RD---- C:\Users 2011-09-21 16:54:57 ----SD---- C:\ProgramData\Microsoft 2011-09-21 16:52:26 ----D---- C:\Program Files\Common Files\microsoft shared 2011-09-21 16:42:33 ----D---- C:\Program Files\Windows Media Player 2011-09-21 16:37:43 ----D---- C:\Windows\system32\LogFiles 2011-09-21 15:19:00 ----D---- C:\Windows\twain_32 2011-09-21 15:10:24 ----D---- C:\Windows\system32\drivers\UMDF 2011-09-21 14:30:10 ----D---- C:\Windows\ShellNew 2011-09-21 14:23:49 ----D---- C:\Program Files\Windows Sidebar 2011-09-21 14:23:49 ----D---- C:\Program Files\Windows Portable Devices 2011-09-21 14:23:49 ----D---- C:\Program Files\Windows Photo Viewer 2011-09-21 14:23:49 ----D---- C:\Program Files\Windows Mail 2011-09-21 14:23:49 ----D---- C:\Program Files\Windows Journal 2011-09-21 14:23:49 ----D---- C:\Program Files\DVD Maker 2011-09-21 14:23:48 ----D---- C:\Windows\ehome 2011-09-21 14:23:48 ----D---- C:\Program Files\Windows Defender 2011-09-21 14:23:47 ----SHD---- C:\Windows\BitLockerDiscoveryVolumeContents 2011-09-21 14:23:44 ----D---- C:\Windows\system32\da-DK 2011-09-21 14:23:43 ----D---- C:\Windows\system32\sysprep 2011-09-21 14:23:43 ----D---- C:\Windows\system32\oobe 2011-09-21 14:23:42 ----D---- C:\Windows\system32\wbem 2011-09-21 14:23:42 ----D---- C:\Windows\system32\sppui 2011-09-21 14:23:42 ----D---- C:\Windows\system32\Setup 2011-09-21 14:23:42 ----D---- C:\Windows\system32\manifeststore 2011-09-21 14:23:42 ----D---- C:\Windows\system32\es-ES 2011-09-21 14:23:42 ----D---- C:\Windows\system32\en 2011-09-21 14:23:42 ----D---- C:\Windows\system32\drivers\pt-BR 2011-09-21 14:23:42 ----D---- C:\Windows\system32\drivers\en-US 2011-09-21 14:23:42 ----D---- C:\Windows\system32\cs-CZ 2011-09-21 14:23:42 ----D---- C:\Windows\system32\AdvancedInstallers 2011-09-21 14:23:41 ----D---- C:\Windows\system32\migwiz 2011-09-21 14:23:41 ----D---- C:\Windows\system32\Dism 2011-09-21 14:23:30 ----D---- C:\Windows\system32\Boot 2011-09-21 14:20:21 ----A---- C:\Windows\system32\msclmd.dll 2011-09-21 14:13:19 ----D---- C:\Windows\system32\CodeIntegrity 2011-09-21 14:06:35 ----D---- C:\Windows\system32\restore 2011-09-21 13:57:13 ----D---- C:\Program Files\Windows NT 2011-09-21 13:51:41 ----D---- C:\Windows\CSC ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440] R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360] R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-09-21 218688] R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 59388] R2 IDMWFP;IDMWFP; C:\Windows\system32\DRIVERS\idmwfp.sys [2011-03-28 86792] R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-09-24 25888] R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-13 8704] R3 Atc002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller; C:\Windows\system32\DRIVERS\l260x86.sys [2008-10-16 29184] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-04-30 3086752] R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810] R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2011-09-21 47360] S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-09-24 279712] S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-13 70720] S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-13 53312] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888] S3 catchme;catchme; \??\C:\Users\CHRIST~1\AppData\Local\Temp\catchme.sys [] S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [] S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-13 12368] S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872] S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys [2009-12-30 27192] S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632] S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-13 52304] S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032] S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [] S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224] S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [] S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-13 35840] S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [] S3 viaagp;Filtro de barramento VIA AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-13 53328] S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-13 52736] S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-13 20992] R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2011-04-07 612456] R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-04-07 378472] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536] R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] S2 wazduclb; de Dispositivo de Erro de Hardware da MicrosoftController; C:\Windows\System32\svchost.exe [2009-07-13 20992] S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-13 20992] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352] S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-13 20992] S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-13 20992] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-09-21 1343400] -----------------EOF----------------- GMER LOG: GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2011-10-03 19:10:28 Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 SAMSUNG_HD322HJ rev.1AC01118 Running: GMER.exe; Driver: C:\Users\CHRIST~1\AppData\Local\Temp\kglyipod.sys ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwSaveKey + 13D1 82C3F349 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C78D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} ? System32\drivers\graxxdh.sys O sistema não pode encontrar o caminho especificado. ! .text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0x97BFB300, 0x1BCE, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5140] USER32.dll!SetWindowLongA 75BD8BA3 5 Bytes JMP 5FD9E349 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5140] USER32.dll!SetWindowLongW 75BE4449 5 Bytes JMP 5FD9E2DB C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5140] USER32.dll!GetWindowInfo 75BE4B5E 5 Bytes JMP 5FB589A7 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[5140] USER32.dll!TrackPopupMenu 75BF2228 5 Bytes JMP 5FB58F65 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[5964] ntdll.dll!LdrLoadDll 774522B8 5 Bytes JMP 5F9DFAE0 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [741C2437] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [741A5600] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [741A56BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [741C24B2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [741B8514] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [741B4CC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [741B506F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [741B5144] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [741B6671] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [741B826B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [741B87BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [741B901B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [741BE1BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[1984] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [741B4BFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipAlloc] [741C2437] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusStartup] [741A5600] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusShutdown] [741A56BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipFree] [741C24B2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDeleteGraphics] [741B8514] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDisposeImage] [741B4CC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageWidth] [741B506F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageHeight] [741B5144] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [741B6671] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateFromHDC] [741B826B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetCompositingMode] [741B87BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetInterpolationMode] [741B901B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDrawImageRectI] [741BE1BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5764] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCloneImage] [741B4BFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- Device \Driver\ACPI_HAL \Device\00000048 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation) AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation) AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gerenciador de Filtro do Filesystem Microsoft/Microsoft Corporation) Device \Driver\00000529 \GLOBAL??\84f6d236 85FE5190 ---- Files - GMER 1.0.15 ---- ADS C:\Qoobox\Quarantine\C\Windows\919795332.vir:2064199113.exe 784 bytes executable ---- EOF - GMER 1.0.15 ---- Desde já, Obg. T+ Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Outubro 4, 2011 Cole o log do combofix. Compartilhar este post Link para o post Compartilhar em outros sites
trend 0 Denunciar post Postado Outubro 4, 2011 Feito! :) ComboFix 11-10-04.04 - Christian Fernando 04/10/2011 17:49:29.2.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.55.1046.18.2047.1273 [GMT -3:00] Executando de: c:\combofix\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3 c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\chrome.manifest c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\chrome\idmmzcc.jar c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\components\iIDMMzCC.xpt c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\components2\idmhelper.js c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\components2\idmhelper2.js c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\components2\idmmzcc.dll c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\components2\idmmzcc64.dll c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\components2\iIDMHelper.xpt c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\components2\iIDMHelper2.xpt c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\components2\iIDMMzCC.xpt c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\install.js c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\install.rdf c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\META-INF\manifest.mf c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\META-INF\zigbert.rsa c:\users\Christian Fernando\AppData\Roaming\IDM\idmmzcc3\META-INF\zigbert.sf . . (((((((((((((((( Arquivos/Ficheiros criados de 2011-09-04 to 2011-10-04 )))))))))))))))))))))))))))) . . 2074-05-18 20:44 . 2008-03-21 17:46 607296 ------w- c:\program files\Microsoft Games\Age of Empires III\deformerdllyD.dll 2074-05-07 21:38 . 2006-11-21 23:48 203576 ------w- c:\program files\Microsoft Games\Age of Empires III\autopatcher2.exe 2011-10-04 20:55 . 2011-10-04 20:55 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-10-04 14:13 . 2011-10-04 14:13 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{87FC7D9C-13D2-455B-8DE7-570498596DBB}\offreg.dll 2011-10-04 14:13 . 2011-09-12 23:14 7269712 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{87FC7D9C-13D2-455B-8DE7-570498596DBB}\mpengine.dll 2011-10-03 20:40 . 2011-10-03 20:40 -------- d-----w- c:\program files\trend micro 2011-10-03 20:40 . 2011-10-03 20:40 -------- d-----w- C:\rsit 2011-10-03 19:11 . 2011-10-03 19:11 -------- d-----w- c:\program files\Common Files\Java 2011-10-02 23:19 . 2009-07-13 23:11 80896 ----a-w- c:\windows\system32\drivers\i8042prt.sys 2011-10-02 21:03 . 2011-10-03 17:36 -------- d-----w- c:\program files\Spybot - Search & Destroy 2011-10-02 20:54 . 2011-10-02 20:54 -------- d-----w- c:\programdata\Malwarebytes 2011-10-02 20:54 . 2011-10-03 17:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2011-10-02 20:54 . 2011-08-31 20:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-10-01 19:02 . 1999-05-19 03:19 33792 ----a-w- c:\windows\system32\NPSExec.exe 2011-10-01 16:23 . 2011-10-01 16:50 -------- d-----w- c:\program files\Need for Speed 3 Vista Edition 2011-10-01 02:30 . 2011-10-01 02:30 -------- d-----w- c:\program files\GlideWrapper 2011-10-01 02:02 . 2011-10-01 02:02 -------- d-----w- c:\program files\Gadwin Systems 2011-10-01 01:07 . 2011-10-01 01:07 -------- d-----w- c:\programdata\NFS Underground 2011-09-28 20:27 . 1999-05-19 03:19 565760 ----a-w- c:\windows\system32\MSVCP50.DLL 2011-09-28 20:25 . 1998-10-29 19:45 306688 ----a-w- c:\windows\IsUninst.exe 2011-09-28 20:22 . 2011-10-01 19:01 -------- d-----w- c:\program files\Electronic Arts 2011-09-28 20:18 . 1998-05-01 16:39 299008 ----a-w- c:\windows\uninst.exe 2011-09-28 02:19 . 2011-09-28 02:19 -------- d-----w- c:\program files\FileZilla FTP Client 2011-09-24 23:51 . 2011-09-24 23:51 -------- d-----w- c:\windows\system32\SupportAppXL 2011-09-24 23:51 . 2011-09-25 20:57 -------- d-----w- c:\program files\Brasil Telecom 2011-09-24 20:37 . 2011-09-24 20:37 279712 ----a-w- c:\windows\system32\drivers\atksgt.sys 2011-09-24 20:37 . 2011-09-24 20:37 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys 2011-09-24 20:19 . 2011-09-24 20:37 -------- d-----w- c:\program files\The Witcher Enhanced Edition 2011-09-24 19:15 . 2011-09-24 19:16 -------- d-----w- c:\program files\HTML Help Workshop 2011-09-24 18:59 . 2011-09-24 19:47 -------- d-----w- c:\program files\SWAT 4 2011-09-24 18:59 . 2011-09-24 18:59 -------- d-----w- c:\windows\SWAT 4 2011-09-24 17:59 . 2011-09-24 17:59 -------- d-----w- c:\program files\Common Files\SWF Studio 2011-09-24 17:43 . 2003-02-21 10:03 3005956 ----a-w- c:\program files\Microsoft Games\Freelancer\EXE\Freelancer.exe 2011-09-24 17:09 . 2011-09-24 17:11 -------- d-----w- c:\program files\Euro Truck Simulator 2011-09-24 16:22 . 2011-09-24 16:30 -------- d-----w- c:\program files\Activision 2011-09-24 16:17 . 2011-09-24 16:17 -------- d-----w- c:\program files\IBE Software 2011-09-24 16:16 . 2011-09-24 16:16 -------- d-sh--w- c:\windows\ftpcache 2011-09-24 14:47 . 2011-09-24 14:47 -------- d-----w- c:\program files\Yamicsoft 2011-09-24 03:16 . 2011-10-01 13:43 -------- d-----w- c:\program files\EA GAMES 2011-09-24 02:33 . 2006-08-30 22:03 34304 ------r- c:\program files\Microsoft Games\Age of Empires III\SetupENU2.dll 2011-09-24 02:27 . 2011-09-24 02:33 -------- d-----w- c:\program files\Common Files\Microsoft Games 2011-09-24 02:16 . 2011-09-24 02:16 -------- d-----w- c:\programdata\Age of Empires 3 2011-09-24 02:15 . 2011-10-01 20:21 -------- d-----w- c:\program files\GameVicio 2011-09-24 02:03 . 2005-05-26 18:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll 2011-09-24 01:48 . 2011-09-24 03:14 -------- d-----w- c:\programdata\Xfire 2011-09-24 01:48 . 2011-09-24 02:40 -------- d-----w- c:\program files\Xfire 2011-09-24 01:34 . 2011-09-24 01:34 -------- d-----w- c:\programdata\Zbshareware Lab 2011-09-24 01:34 . 2011-09-24 01:34 -------- d-----w- c:\program files\USB Disk Security 2011-09-24 01:26 . 2009-12-30 14:21 27192 ----a-w- c:\windows\system32\drivers\revoflt.sys 2011-09-24 01:26 . 2011-09-24 01:26 -------- d-----w- c:\program files\VS Revo Group 2011-09-24 01:13 . 2011-09-24 01:13 -------- d-----w- c:\program files\Auslogics 2011-09-23 23:53 . 2011-03-11 05:39 148864 ----a-w- c:\windows\system32\drivers\storport.sys 2011-09-23 23:53 . 2011-03-11 05:39 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys 2011-09-23 23:53 . 2011-03-11 05:39 1211264 ----a-w- c:\windows\system32\drivers\ntfs.sys 2011-09-23 23:53 . 2011-03-11 05:39 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys 2011-09-23 23:53 . 2011-03-11 05:38 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys 2011-09-23 23:53 . 2011-03-11 05:38 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys 2011-09-23 23:53 . 2011-03-11 05:38 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys 2011-09-23 23:53 . 2011-03-11 05:33 1699328 ----a-w- c:\windows\system32\esent.dll 2011-09-23 23:53 . 2011-03-11 05:31 74240 ----a-w- c:\windows\system32\fsutil.exe 2011-09-23 23:28 . 2011-03-25 02:58 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys 2011-09-23 23:28 . 2011-03-25 02:58 284672 ----a-w- c:\windows\system32\drivers\usbport.sys 2011-09-23 23:28 . 2011-03-25 02:58 75776 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2011-09-23 23:28 . 2011-03-25 02:57 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys 2011-09-23 23:28 . 2011-03-25 02:57 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys 2011-09-23 23:28 . 2011-03-25 02:57 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2011-09-23 23:28 . 2011-03-25 02:57 5888 ----a-w- c:\windows\system32\drivers\usbd.sys 2011-09-23 12:21 . 2011-09-23 12:22 -------- d-----r- C:\Favoritos 2011-09-22 18:11 . 2011-02-19 06:30 805376 ----a-w- c:\windows\system32\FntCache.dll 2011-09-22 18:11 . 2011-02-19 06:30 1076736 ----a-w- c:\windows\system32\DWrite.dll 2011-09-22 18:11 . 2011-02-19 06:30 739840 ----a-w- c:\windows\system32\d2d1.dll 2011-09-22 11:26 . 2011-09-22 11:26 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help 2011-09-22 11:19 . 2011-09-22 11:19 -------- d-----w- c:\program files\MSXML 4.0 2011-09-22 10:33 . 2011-04-29 02:46 311808 ----a-w- c:\windows\system32\drivers\srv.sys 2011-09-22 10:33 . 2011-04-29 02:46 310272 ----a-w- c:\windows\system32\drivers\srv2.sys 2011-09-22 10:33 . 2011-04-29 02:46 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys 2011-09-22 10:32 . 2011-03-03 05:38 132608 ----a-w- c:\windows\system32\dnsrslvr.dll 2011-09-22 10:32 . 2011-03-03 05:36 28672 ----a-w- c:\windows\system32\dnscacheugc.exe 2011-09-22 10:32 . 2011-02-19 06:30 34304 ----a-w- c:\windows\system32\atmlib.dll 2011-09-22 10:32 . 2011-02-19 04:34 294912 ----a-w- c:\windows\system32\atmfd.dll 2011-09-22 10:32 . 2010-09-30 06:47 70656 ----a-w- c:\windows\system32\fontsub.dll 2011-09-22 10:31 . 2011-04-25 02:18 338944 ----a-w- c:\windows\system32\drivers\afd.sys 2011-09-22 10:29 . 2011-02-18 05:39 31232 ----a-w- c:\windows\system32\prevhost.exe 2011-09-22 10:29 . 2011-02-25 05:34 571904 ----a-w- c:\windows\system32\oleaut32.dll 2011-09-22 10:29 . 2011-06-23 04:33 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-09-22 10:29 . 2011-06-23 04:33 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-09-22 10:18 . 2011-05-24 10:44 293376 ----a-w- c:\windows\system32\umpnpmgr.dll 2011-09-22 10:17 . 2010-12-17 07:07 542208 ----a-w- c:\windows\system32\kerberos.dll 2011-09-22 10:17 . 2011-07-09 02:30 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-09-22 10:17 . 2011-04-27 02:17 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-09-22 10:17 . 2011-04-27 02:17 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-09-22 10:12 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\explorer.exe 2011-09-22 10:11 . 2011-06-11 02:29 2334208 ----a-w- c:\windows\system32\win32k.sys 2011-09-22 00:48 . 2011-09-22 00:48 -------- d-----w- c:\windows\system32\Atheros_L2 2011-09-22 00:46 . 2011-09-22 00:46 -------- d-----w- c:\windows\system32\Adobe 2011-09-22 00:20 . 2011-09-22 00:20 -------- d-----w- c:\programdata\eXPert PDF 5 2011-09-22 00:17 . 2010-04-27 23:51 253784 ----a-w- c:\windows\system32\MaxxAudioAPO30.dll 2011-09-22 00:16 . 2011-10-04 13:36 -------- d-----w- c:\programdata\NVIDIA 2011-09-22 00:14 . 2011-09-22 00:14 -------- d-----w- C:\NVIDIA 2011-09-21 21:49 . 2011-09-21 16:57 -------- d-----w- c:\windows\Panther 2011-09-21 21:49 . 2011-09-21 17:26 -------- d-----w- C:\Boot 2011-09-21 21:34 . 2011-09-21 21:34 -------- d-----w- c:\windows\Sun 2011-09-21 19:52 . 2011-09-21 19:57 -------- d-----w- c:\program files\Windows Live 2011-09-21 19:52 . 2011-09-24 06:17 -------- d-----w- c:\program files\Microsoft Silverlight 2011-09-21 19:50 . 2011-09-21 19:50 -------- d-----w- c:\program files\Common Files\Windows Live 2011-09-21 19:48 . 2011-09-21 19:48 -------- d-----w- C:\IORRT 2011-09-21 19:46 . 2005-06-02 15:40 14336 ----a-w- c:\windows\system32\vsmon1.dll 2011-09-21 19:46 . 2011-09-21 19:46 -------- d-----w- c:\windows\My Documents 2011-09-21 19:46 . 2011-09-21 19:46 -------- d-----w- c:\programdata\eXPert PDF 2011-09-21 19:46 . 2011-09-21 19:46 -------- d-----w- c:\programdata\eXPert PDF Jobs 2011-09-21 19:46 . 2011-09-21 19:46 -------- d-----w- c:\program files\Visagesoft 2011-09-21 19:42 . 2011-09-21 19:42 -------- d-----w- c:\windows\system32\Wat 2011-09-21 19:42 . 2011-09-21 19:42 -------- d-----w- c:\program files\Windows Media Player Plus! 2011-09-21 19:42 . 2010-04-11 20:09 83456 ----a-w- c:\program files\Windows Media Player\wmp.dll 2011-09-21 19:41 . 2011-09-21 19:41 -------- d-----w- c:\program files\FirmTools 2011-09-21 19:40 . 2011-09-21 19:40 -------- d-----w- c:\program files\Common Files\Plasmoo 2011-09-21 19:40 . 2011-09-21 19:40 -------- d-----w- c:\program files\Common Files\DVDVideoSoft 2011-09-21 19:40 . 2011-09-21 19:40 -------- d-----w- c:\program files\DVDVideoSoft 2011-09-21 19:36 . 2011-05-24 22:14 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-09-21 19:26 . 2011-09-21 19:26 -------- d-----w- c:\programdata\BVRP Software 2011-09-21 19:25 . 2011-09-21 19:25 -------- d-----w- c:\program files\MozBackup 2011-09-21 18:20 . 2011-09-21 18:20 -------- d-----w- c:\programdata\WEBREG 2011-09-21 18:19 . 2011-09-21 18:19 -------- d-----w- c:\program files\Common Files\HP 2011-09-21 18:18 . 2011-09-21 18:18 -------- d-----w- C:\UniScan 2011-09-21 18:18 . 2011-09-21 18:18 -------- d-----w- c:\program files\Common Files\Hewlett-Packard . . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-21 19:52 . 2011-03-28 21:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-09-21 17:20 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll 2011-08-26 22:22 . 2011-08-26 22:22 42392 ----a-w- c:\windows\system32\xfcodec.dll 2011-09-29 07:30 . 2011-10-03 16:53 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por padrão não são apresentadas. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension] @="{CDC95B92-E27C-4745-A8C5-64A52A78855D}" [HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}] 2011-03-02 15:23 68216 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-09-21 395128] "IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2011-09-21 3298712] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "vspdfprsrv.exe"="c:\program files\Visagesoft\eXPert PDF 5\vspdfprsrv.exe" [2007-07-02 1179648] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-04-30 9210400] "USB Security"="c:\program files\USB Disk Security\USBGuard.exe" [2011-05-21 623520] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 wazduclb; de Dispositivo de Erro de Hardware da MicrosoftController;c:\windows\System32\svchost.exe [2009-07-14 20992] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [2009-12-30 27192] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Serviço de Tecnologias de Ativação do Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-09-21 1343400] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-09-21 218688] S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2011-03-28 86792] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-04-08 378472] S3 Atc002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\DRIVERS\l260x86.sys [2008-10-17 29184] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4640000] S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2011-09-21 47360] . . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs wazduclb . . ------- Scan Suplementar ------- . uInternet Settings,ProxyServer = http=127.0.0.1:64869 IE: E&xportar para o Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Fazer o download de todos os links usando o IDM - c:\program files\Internet Download Manager\IEGetAll.htm IE: Fazer o download usando o IDM - c:\program files\Internet Download Manager\IEExt.htm IE: Free YouTube Download - c:\users\Christian Fernando\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm IE: Free YouTube to MP3 Converter - c:\users\Christian Fernando\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: DhcpNameServer = 192.168.254.254 192.168.254.254 FF - ProfilePath - c:\users\Christian Fernando\AppData\Roaming\Mozilla\Firefox\Profiles\6whjna59.default\ FF - prefs.js: browser.search.selectedEngine - Google Brasil FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br/ FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 64869 FF - prefs.js: network.proxy.type - 4 . . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- . [HKEY_USERS\S-1-5-21-3043748444-1542819765-3838197750-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*m$|*3*] @Class="Shell" . [HKEY_USERS\S-1-5-21-3043748444-1542819765-3838197750-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*m$|*3*\OpenWithList] @Class="Shell" . [HKEY_USERS\S-1-5-21-3043748444-1542819765-3838197750-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) "scansk"=hex(0):dc,c1,b6,cc,96,54,ac,86,a8,6b,dc,fd,6e,7e,a0,44,79,f3,5e,e6,5f, 68,f4,b1,5b,72,d2,7f,d0,7e,c8,a1,92,ef,a6,a4,fd,01,c0,04,00,00,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-3043748444-1542819765-3838197750-1000_Classes\CLSID\{a35a0179-b4c6-48f7-a5fb-160d187e6ee6}] @Denied: (Full) (Everyone) @Allowed: (Read) (RestrictedCode) "Model"=dword:0000010a "Therad"=dword:00000004 "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a, 1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Tempo para conclusão: 2011-10-04 17:58:09 ComboFix-quarantined-files.txt 2011-10-04 20:58 ComboFix2.txt 2011-10-02 23:44 . Pré-execução: 101.826.596.864 bytes disponíveis Pós execução: 102.104.104.960 bytes disponíveis . - - End Of File - - 9190B95062125694F18B4765B06E2978 Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Outubro 4, 2011 OK...o log está limpo. 1. *Clique [iniciar] > [Todos os programas] > [Acessórios] > [Executar] > copie e cole: c:\combofix\ComboFix.exe /uninstall *Clique [OK] e aguarde a mensagem: "ComboFix está desinstalado" 2. *Delete o RSIT e a pasta C:\rsit 3. *Delete o GMER e seu relatório. Um abraço. Compartilhar este post Link para o post Compartilhar em outros sites
trend 0 Denunciar post Postado Outubro 5, 2011 Está tudo certoo mesmo? No momento eu tenho aqui uns 15 processos svchost como SERVIÇO LOCAL E SISTEMA. Isso é normal mesmo ? Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Outubro 5, 2011 Está tudo certoo mesmo? No momento eu tenho aqui uns 15 processos svchost como SERVIÇO LOCAL E SISTEMA. Isso é normal mesmo ? O svchost roda vários processos o que acaba resultando em vários svchost.exe na lista de processos, o que é extremamente comum. Mas se deseja um scan.... *Baixe o Kaspersky Virus Removal Tool Versão 11 e salve-o no desktop *Execute-o e clique no botão *Selecione: Meu computador *Clique *Clique [start scanning] *Caso encontre algo, selecione Apply to all objects e clique [skip] *Ao término, clique *Clique Automatic Scan report > [save] e salve no desktop como log.txt *Cole o relatório log.txt salvo no desktop Compartilhar este post Link para o post Compartilhar em outros sites
trend 0 Denunciar post Postado Outubro 7, 2011 Ok, minha internet tá lenta hoje... O quanto antes posto o scan. Desde já, obrigado novamente! Ok, minha internet tá lenta hoje... O quanto antes posto o scan. Desde já, obrigado novamente! Compartilhar este post Link para o post Compartilhar em outros sites
trend 0 Denunciar post Postado Outubro 8, 2011 Legalz, ñ achou nada. :) Muito Obrigado pela ajuda mesmo! Sem você's com certeza eu ñ teria saído dessa sozinho! Obg de novo :joia: Edit: Não existe outra forma de remover o combofix, pois da forma mencionada acima ñ estou conseguindo! Ele fala q o local não foi encontrado, mesmo o programa estando salvo no desktop! Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Outubro 8, 2011 Edit: Não existe outra forma de remover o combofix, pois da forma mencionada acima ñ estou conseguindo! Ele fala q o local não foi encontrado, mesmo o programa estando salvo no desktop! Renomei o combofix para uninstall Execute-o e ele será desinstalado. Compartilhar este post Link para o post Compartilhar em outros sites
trend 0 Denunciar post Postado Outubro 8, 2011 Ok, muito obrigado novamente!! Parabens pelo "serviço" :joia: Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Outubro 8, 2011 PROBLEMA RESOLVIDO Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites