Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Kaminhant

[Resolvido] &nbspPC lento e com malwares

Recommended Posts

Amigos do Imasters - Bom Dia! Abaixo segue log do hijackthis para sua verificação:

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 11:18:59, on 12/11/2011

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Arquivos comuns\Research In Motion\Auto Update\RIMAutoUpdate.exe

C:\WINDOWS\CameraFixer.exe

C:\WINDOWS\tsnpstd3.exe

C:\Arquivos de programas\Alwil Software\Avast5\avastUI.exe

C:\WINDOWS\twain_32\600x1200\Detector.exe

C:\ARQUIV~1\TEXTBR~1.0\Bin\INSTAN~1.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\WINDOWS\system32\msiexec.exe

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Trend Micro\HiJackThis\HiJackThis.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Arquivos de programas\Canon\Easy-WebPrint\EWPBrowseLoader.dll

O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (file missing)

O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Arquivos de programas\Megaupload\Mega Manager\MegaIEMn.dll

O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\ARQUIV~1\GbPlugin\gbiehcef.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Arquivos de programas\Yontoo Layers\YontooIEClient.dll

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll

O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [MP10_EnsureFileVer] C:\WINDOWS\inf\unregmp2.exe /EnsureFileVersions

O4 - HKLM\..\Run: [blackBerryAutoUpdate] C:\Arquivos de programas\Arquivos comuns\Research In Motion\Auto Update\RIMAutoUpdate.exe /background

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [qQ] C:\WINDOWS\ali.exe

O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe

O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe

O4 - HKLM\..\Run: [avast] "C:\Arquivos de programas\Alwil Software\Avast5\avastUI.exe" /nogui

O4 - HKLM\..\Run: [Detector] C:\WINDOWS\twain_32\600x1200\Detector.exe

O4 - HKLM\..\Run: [instantAccess] C:\ARQUIV~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h

O4 - HKLM\..\Run: [RegisterDropHandler] C:\ARQUIV~1\TEXTBR~1.0\Bin\REGIST~1.EXE

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\ARQUIV~1\TEXTBR~1.0\Bin\REGIST~1.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: Baixar Link Utiizando Gerenciador Mega... - C:\Arquivos de programas\Megaupload\Mega Manager\mm_file.htm

O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Arquivos de programas\Megaupload\Mega Manager\mm_file.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Andreia\Dados de aplicativos\DVDVideoSoftIEHelpers\freeyoutubedownload.htm

O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Andreia\Dados de aplicativos\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html

O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: http://sn104w.snt104.mail.live.com

O15 - Trusted Zone: http://www.orkut.com.br

O15 - Trusted IP range: 192.168.1.4

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{C7DDC215-21FF-4ACD-A57B-5D43D42D1472}: NameServer = 201.10.120.3,201.10.1.2

O20 - Winlogon Notify: GbPluginCef - C:\ARQUIV~1\GbPlugin\gbiehCef.dll

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: avast! Antivirus - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Arquivos de programas\WinPcap\rpcapd.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Arquivos de programas\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Arquivos de programas\Spyware Doctor\pctsSvc.exe

 

--

End of file - 11228 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Kaminhant

 

 

1.

*Baixe o SecurityCheck e salve-o no desktop

*Execute-o, tecle [Enter] e cole o relatório apresentado

 

2.

*Baixe o OTL e salve-o no desktop

 

*Execute-o e selecione as opções:

Verificar All Users

Usar WhiteList para Nomes de Companhias

Ignorar Arquivos Microsoft

Verificar LOP

Verificar Purity

*Clique [Verificar] e cole os relatório OTL.txt e Extras.txt localizados no desktop

 

Caso o relatório OTL.txt fique demasiadamente grande...

 

*Acesse este link

*Selecione 4 jours

*Clique [Enviar arquivo]

*Localize o arquivo OTL.txt no desktop

*Clique [Abrir] > [Créer le lien Cjoint]

*Cole o endereço criado

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá Kaminhant

 

 

1.

*Baixe o SecurityCheck e salve-o no desktop

*Execute-o, tecle [Enter] e cole o relatório apresentado

 

2.

*Baixe o OTL e salve-o no desktop

 

*Execute-o e selecione as opções:

Verificar All Users

Usar WhiteList para Nomes de Companhias

Ignorar Arquivos Microsoft

Verificar LOP

Verificar Purity

*Clique [Verificar] e cole os relatório OTL.txt e Extras.txt localizados no desktop

 

Caso o relatório OTL.txt fique demasiadamente grande...

 

*Acesse este link

*Selecione 4 jours

*Clique [Enviar arquivo]

*Localize o arquivo OTL.txt no desktop

*Clique [Abrir] > [Créer le lien Cjoint]

*Cole o endereço criado

 

 

ABAIXO Logs solicitados:

Results of screen317's Security Check version 0.99.24

Windows XP Service Pack 2 x86

Out of date service pack!!

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

avast! Free Antivirus

ESET Online Scanner v3

Antivirus up to date! (On Access scanning disabled!)

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

Receitanet Java 2010.02b

Java 6 Update 17

Out of date Java installed!

Adobe Flash Player ( 10.2.153.1) Flash Player Out of Date!

Mozilla Firefox (3.6.23) Firefox Out of Date!

````````````````````````````````

Process Check:

objlist.exe by Laurent

Alwil Software Avast5 AvastSvc.exe

Alwil Software Avast5 avastUI.exe

``````````End of Log````````````

 

 

 

OTL logfile created on: 15/11/2011 21:07:39 - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Andreia\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy

 

895,17 Mb Total Physical Memory | 336,88 Mb Available Physical Memory | 37,63% Memory free

2,12 Gb Paging File | 1,48 Gb Available in Paging File | 69,79% Paging File free

Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas

Drive C: | 149,04 Gb Total Space | 26,82 Gb Free Space | 18,00% Space Free | Partition Type: NTFS

Drive E: | 7,81 Mb Total Space | 3,33 Mb Free Space | 42,60% Space Free | Partition Type: NTFS

 

Computer Name: CASA | User Name: Andreia | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2011/11/15 20:56:09 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Andreia\Desktop\OTL.exe

PRC - [2011/11/08 01:02:58 | 001,036,344 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

PRC - [2011/07/04 09:43:54 | 003,493,720 | ---- | M] (AVAST Software) -- C:\Arquivos de programas\Alwil Software\Avast5\AvastUI.exe

PRC - [2011/07/04 09:43:51 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe

PRC - [2011/04/18 16:13:40 | 000,056,776 | ---- | M] ( ) -- C:\Arquivos de programas\GbPlugin\gbpsv.exe

PRC - [2008/09/17 16:22:50 | 000,615,696 | ---- | M] (Research In Motion Limited) -- C:\Arquivos de programas\Arquivos comuns\Research In Motion\Auto Update\RIMAutoUpdate.exe

PRC - [2007/06/01 10:05:56 | 001,551,408 | ---- | M] (Nero AG) -- C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe

PRC - [2006/06/19 14:21:32 | 000,114,688 | ---- | M] () -- C:\WINDOWS\tsnpstd3.exe

PRC - [2006/06/01 12:26:10 | 000,020,480 | ---- | M] () -- C:\WINDOWS\CameraFixer.exe

PRC - [2004/08/04 01:45:34 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2000/08/07 02:00:12 | 000,038,400 | R--- | M] () -- C:\WINDOWS\twain_32\600x1200\Detector.exe

PRC - [1998/12/14 12:49:20 | 000,037,376 | ---- | M] () -- C:\Arquivos de programas\TextBridge Pro 8.0\Bin\InstantAccess.exe

 

 

========== Modules (No Company Name) ==========

 

MOD - [2011/11/15 16:27:35 | 001,616,896 | ---- | M] () -- C:\Arquivos de programas\Alwil Software\Avast5\defs\11111501\algo.dll

MOD - [2011/11/15 09:59:54 | 000,241,528 | ---- | M] () -- C:\Arquivos de programas\Alwil Software\Avast5\defs\11111501\aswRep.dll

MOD - [2011/11/08 01:02:56 | 000,420,920 | ---- | M] () -- C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\15.0.874.120\ppgooglenaclpluginchrome.dll

MOD - [2011/11/08 01:02:55 | 003,702,840 | ---- | M] () -- C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\15.0.874.120\pdf.dll

MOD - [2011/11/08 01:01:20 | 000,122,952 | ---- | M] () -- C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\15.0.874.120\avutil-51.dll

MOD - [2011/11/08 01:01:19 | 000,222,280 | ---- | M] () -- C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\15.0.874.120\avformat-53.dll

MOD - [2011/11/08 01:01:17 | 001,746,504 | ---- | M] () -- C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\15.0.874.120\avcodec-53.dll

MOD - [2011/11/07 21:44:56 | 008,593,056 | ---- | M] () -- C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\15.0.874.120\gcswf32.dll

MOD - [2009/02/27 19:49:12 | 000,311,296 | ---- | M] () -- C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\pdfshell.PTB

MOD - [2006/09/14 01:20:24 | 000,126,464 | ---- | M] () -- C:\PROGRAMAS_pcPai\WinRAR\RarExt.dll

MOD - [2006/06/19 14:21:32 | 000,114,688 | ---- | M] () -- C:\WINDOWS\tsnpstd3.exe

MOD - [2006/06/01 12:26:10 | 000,020,480 | ---- | M] () -- C:\WINDOWS\CameraFixer.exe

MOD - [2004/08/04 01:45:24 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll

MOD - [2000/08/07 02:00:12 | 000,038,400 | R--- | M] () -- C:\WINDOWS\twain_32\600x1200\Detector.exe

MOD - [1998/12/18 18:39:18 | 000,131,584 | ---- | M] () -- C:\Arquivos de programas\TextBridge Pro 8.0\Bin\IAResPOR.dll

MOD - [1998/12/14 12:49:20 | 000,037,376 | ---- | M] () -- C:\Arquivos de programas\TextBridge Pro 8.0\Bin\InstantAccess.exe

MOD - [1998/12/14 12:46:26 | 000,034,304 | ---- | M] () -- C:\Arquivos de programas\TextBridge Pro 8.0\Bin\OfficeAccess.dll

MOD - [1998/12/14 12:45:26 | 000,034,304 | ---- | M] () -- C:\Arquivos de programas\TextBridge Pro 8.0\Bin\ExcelAccess.dll

MOD - [1998/12/14 12:42:48 | 000,045,568 | ---- | M] () -- C:\Arquivos de programas\TextBridge Pro 8.0\Bin\WordAccess.dll

MOD - [1998/12/14 12:40:10 | 000,008,704 | ---- | M] () -- C:\Arquivos de programas\TextBridge Pro 8.0\Bin\MSAppAccess.dll

MOD - [1998/12/14 12:35:20 | 000,022,016 | ---- | M] () -- C:\Arquivos de programas\TextBridge Pro 8.0\Bin\REGDATA.DLL

MOD - [1998/12/14 12:21:24 | 000,119,808 | ---- | M] () -- C:\Arquivos de programas\TextBridge Pro 8.0\Bin\Tbmhook.dll

MOD - [1998/12/14 12:06:38 | 000,034,304 | ---- | M] () -- C:\Arquivos de programas\Arquivos comuns\Xerox Shared\VGFILE.DLL

MOD - [1998/12/14 12:06:32 | 000,163,328 | ---- | M] () -- C:\Arquivos de programas\Arquivos comuns\Xerox Shared\EASYTB32.DLL

 

 

========== Win32 Services (SafeList) ==========

 

SRV - [2011/07/04 09:43:51 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)

SRV - [2011/04/18 16:13:40 | 000,056,776 | ---- | M] ( ) [unknown | Running] -- C:\Arquivos de programas\GbPlugin\gbpsv.exe -- (GbpSv)

SRV - [2010/06/25 15:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Arquivos de programas\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)

SRV - [2009/01/21 13:08:06 | 001,095,560 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Arquivos de programas\Spyware Doctor\pctsSvc.exe -- (sdCoreService)

SRV - [2009/01/07 12:40:56 | 000,348,752 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Arquivos de programas\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)

SRV - [2007/06/01 10:21:30 | 000,271,920 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)

SRV - [2007/06/01 10:05:56 | 001,551,408 | ---- | M] (Nero AG) [Auto | Running] -- C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe -- (InCDsrv)

SRV - [2003/07/28 13:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE -- (ose)

 

 

========== Driver Services (SafeList) ==========

 

DRV - [2011/09/06 18:38:05 | 000,442,200 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)

DRV - [2011/09/06 18:36:38 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)

DRV - [2011/09/06 18:36:36 | 000,052,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)

DRV - [2011/09/06 18:36:23 | 000,110,552 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)

DRV - [2011/09/06 18:33:11 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)

DRV - [2011/07/04 09:36:32 | 000,309,848 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)

DRV - [2011/07/04 09:32:12 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)

DRV - [2011/04/18 16:14:16 | 000,046,664 | ---- | M] (GAS Tecnologia) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\gbpkm.sys -- (GbpKm)

DRV - [2010/06/25 15:07:14 | 000,035,088 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)

DRV - [2009/04/22 14:28:08 | 000,008,704 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\epmntdrv.sys -- (epmntdrv)

DRV - [2009/04/22 14:28:06 | 000,003,072 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\EuGdiDrv.sys -- (EuGdiDrv)

DRV - [2009/04/03 11:18:26 | 000,130,936 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\PCTCore.sys -- (PCTCore)

DRV - [2008/10/31 01:38:08 | 004,942,336 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2008/10/21 10:22:48 | 000,114,600 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mdm.sys -- (s0017mdm)

DRV - [2008/10/21 10:22:48 | 000,109,736 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017unic.sys -- (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM)

DRV - [2008/10/21 10:22:48 | 000,108,328 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mgmt.sys -- (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM)

DRV - [2008/10/21 10:22:48 | 000,104,616 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017obex.sys -- (s0017obex)

DRV - [2008/10/21 10:22:48 | 000,086,824 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017bus.sys -- (s0017bus) Sony Ericsson Device 0017 driver (WDM)

DRV - [2008/10/21 10:22:48 | 000,026,024 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017nd5.sys -- (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS)

DRV - [2008/10/21 10:22:48 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mdfl.sys -- (s0017mdfl)

DRV - [2008/01/09 11:28:34 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\seehcri.sys -- (seehcri)

DRV - [2007/09/20 08:07:40 | 000,022,016 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)

DRV - [2007/09/20 08:07:38 | 000,053,632 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)

DRV - [2007/07/07 04:13:10 | 000,012,032 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu)

DRV - [2007/06/25 09:43:38 | 000,098,344 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117obex.sys -- (s117obex)

DRV - [2007/06/25 09:43:36 | 000,098,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117unic.sys -- (s117unic) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM)

DRV - [2007/06/25 09:43:36 | 000,022,952 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117nd5.sys -- (s117nd5) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS)

DRV - [2007/06/25 09:43:22 | 000,082,984 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s117bus.sys -- (s117bus) Sony Ericsson Device 117 driver (WDM)

DRV - [2007/06/14 17:59:38 | 000,557,568 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\3xHybrid.sys -- (3xHybrid)

DRV - [2007/06/01 10:05:56 | 000,038,576 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDRm.sys -- (incdrm)

DRV - [2007/06/01 10:05:56 | 000,037,040 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDPass.sys -- (InCDPass)

DRV - [2007/06/01 10:05:46 | 000,118,704 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\system32\drivers\InCDfs.sys -- (InCDfs)

DRV - [2007/05/22 06:23:00 | 001,036,928 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)

DRV - [2007/05/22 06:23:00 | 000,702,592 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)

DRV - [2007/05/22 06:23:00 | 000,219,136 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)

DRV - [2006/11/26 15:59:45 | 000,020,096 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AnyDVD.sys -- (AnyDVD)

DRV - [2006/09/05 22:07:00 | 000,061,536 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se59bus.sys -- (se59bus) Sony Ericsson Device 089 driver (WDM)

DRV - [2006/07/24 17:05:00 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)

DRV - [2005/05/03 13:34:02 | 000,027,392 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL)

DRV - [2005/04/12 06:41:20 | 000,004,608 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ElbyDelay.sys -- (ElbyDelay)

DRV - [2005/02/23 15:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)

DRV - [2004/11/30 13:00:00 | 000,276,736 | ---- | M] (Philips Semiconductors) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\SAA713x.sys -- (713xTVCard)

DRV - [2004/08/03 23:10:14 | 000,015,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

 

 

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-1935655697-854245398-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm

IE - HKU\S-1-5-21-1935655697-854245398-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.br/

IE - HKU\S-1-5-21-1935655697-854245398-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKU\S-1-5-21-1935655697-854245398-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - prefs.js..browser.startup.homepage: "http://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:pt-BR:official"

 

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Arquivos de programas\Google\Google Earth\plugin\npgeplugin.dll (Google)

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Arquivos de programas\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Arquivos de programas\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Arquivos de programas\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Arquivos de programas\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Arquivos de programas\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\plugins\npgoogletalk.dll (Google)

FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\plugins\npgtpo3dautoplugin.dll ()

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\wrc@avast.com: C:\Arquivos de programas\Alwil Software\Avast5\WebRep\FF [2011/09/12 18:54:09 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox\components [2011/10/22 18:47:56 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox\plugins [2011/10/22 18:47:57 | 000,000,000 | ---D | M]

 

[2010/01/26 14:51:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Extensions

[2011/07/15 14:04:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\5y1o11k1.default\extensions

[2011/03/25 17:27:02 | 000,000,000 | ---D | M] (DVDVideoSoftTB Toolbar) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\5y1o11k1.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}

[2010/09/02 15:33:45 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\5y1o11k1.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}

[2011/07/15 14:04:48 | 000,000,000 | ---D | M] (Yontoo Layers) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\5y1o11k1.default\extensions\plugin@yontoo.com

[2011/11/09 09:20:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions

[2010/08/15 02:41:53 | 000,000,000 | ---D | M] (Softonic_Brasil Toolbar) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\{12fc3d37-2a42-4fe3-8489-81296878cba5}

[2011/07/23 13:25:08 | 000,000,000 | ---D | M] (Paste Quote) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\{1C7CCF7A-ECB8-4CE5-B5D1-A4FA477A7242}

[2011/07/23 13:25:05 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2011/02/04 16:41:25 | 000,000,000 | ---D | M] (Mega Manager Integration) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\{40a1f5d7-afc2-498f-b264-02668d616ff6}

[2011/07/23 13:25:04 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}

[2011/07/04 22:15:38 | 000,000,000 | ---D | M] (Serif PhotoPlus Community Toolbar) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\{8f2767f8-338a-4258-bd1c-4de5a3d8cdb2}

[2010/09/02 15:33:45 | 000,000,000 | ---D | M] ("DVDVideoSoft Menu") -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}

[2010/01/27 09:09:01 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}

[2011/07/23 13:25:01 | 000,000,000 | ---D | M] (Autofill Forms) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\autofillForms@blueimp.net

[2011/07/23 13:25:03 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\engine@conduit.com

[2011/08/03 21:56:15 | 000,000,000 | ---D | M] (Greasefire) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\greasefire@skrul.com

[2011/07/23 13:25:05 | 000,000,000 | ---D | M] (NASA Night Launch) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\nasanightlaunch@example.com

[2011/07/23 13:25:08 | 000,000,000 | ---D | M] (Orkut Manager) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\om.brunolm@gmail.com

[2011/07/15 14:04:49 | 000,000,000 | ---D | M] (Yontoo Layers) -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\jmcynhak.default\extensions\plugin@yontoo.com

[2010/05/26 15:18:50 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\Firefox\Profiles\5y1o11k1.default\searchplugins\askcom.xml

[2011/03/18 01:12:18 | 000,000,000 | ---D | M] (No name found) -- C:\Arquivos de programas\Mozilla Firefox\extensions

[2007/12/17 15:16:14 | 000,065,536 | ---- | M] ( ) -- C:\Arquivos de programas\mozilla firefox\plugins\npkimi.dll

[2011/09/08 21:32:37 | 000,159,744 | ---- | M] (Apple Inc.) -- C:\Arquivos de programas\mozilla firefox\plugins\npqtplugin9.dll

[2010/12/09 08:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Arquivos de programas\mozilla firefox\plugins\npwachk.dll

[2011/10/22 18:47:49 | 000,001,027 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\buscape.xml

[2011/10/22 18:47:49 | 000,001,212 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\mercadolivre.xml

[2010/04/12 15:01:50 | 000,005,495 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\SearchquWebSearch.xml

[2011/10/22 18:47:49 | 000,001,168 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\wikipedia-br.xml

[2011/10/22 18:47:49 | 000,000,952 | ---- | M] () -- C:\Arquivos de programas\mozilla firefox\searchplugins\yahoo-br.xml

 

========== Chrome ==========

 

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = http://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&aq=t

CHR - default_search_provider: suggest_url = http://suggestqueries.google.com/complete/search?q={searchTerms}

CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Andreia\Configura\u00E7\u00F5es locais\Dados de aplicativos\Google\Chrome\Application\15.0.874.120\gcswf32.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npqtplugin.dll

CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npqtplugin2.dll

CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npqtplugin3.dll

CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npqtplugin4.dll

CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npqtplugin5.dll

CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npqtplugin6.dll

CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npqtplugin7.dll

CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npqtplugin8.dll

CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npqtplugin9.dll

CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Arquivos de programas\Java\jre6\bin\new_plugin\npdeploytk.dll

CHR - plugin: Java Platform SE 6 U17 (Enabled) = C:\Arquivos de programas\Java\jre6\bin\new_plugin\npjp2.dll

CHR - plugin: Adobe Acrobat (Disabled) = C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll

CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Arquivos de programas\Windows Media Player\npdsplay.dll

CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Arquivos de programas\Microsoft\Office Live\npOLW.dll

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Andreia\Configura\u00E7\u00F5es locais\Dados de aplicativos\Google\Chrome\Application\15.0.874.120\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Andreia\Configura\u00E7\u00F5es locais\Dados de aplicativos\Google\Chrome\Application\15.0.874.120\pdf.dll

CHR - plugin: Imikimi.com Plugin (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npkimi.dll

CHR - plugin: Winamp Application Detector (Enabled) = C:\Arquivos de programas\Mozilla Firefox\plugins\npwachk.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Arquivos de programas\Windows Media Player\npdrmv2.dll

CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Arquivos de programas\Windows Media Player\npwmsdrm.dll

CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\plugins\npgoogletalk.dll

CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\plugins\npgtpo3dautoplugin.dll

CHR - plugin: Google Earth Plugin (Enabled) = C:\Arquivos de programas\Google\Google Earth\plugin\npgeplugin.dll

CHR - plugin: Google Update (Enabled) = C:\Arquivos de programas\Google\Update\1.3.21.69\npGoogleUpdate3.dll

CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll

CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

CHR - plugin: Default Plug-in (Enabled) = default_plugin

CHR - Extension: Orkut Chrome Extension = C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\dikgpddfoaipimjmmedapimgedgddhoj\1.0.0.3\

CHR - Extension: avast! WebRep = C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1203_0\

CHR - Extension: Chrome Sounds = C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\kkfibincabhfblmkmhcabnlghmncdcaf\1.1\

CHR - Extension: Visualizador de PDF/PowerPoint do Google Docs (do Google) = C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\nnbmlagghjjcbdhgmkedmbmedengocbn\3.7_0\

 

O1 HOSTS File: ([2010/11/16 15:48:46 | 000,000,774 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)

O2 - BHO: (ssh2 Class) - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll (Scopus Tecnologia Ltda)

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.

O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Arquivos de programas\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()

O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)

O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll File not found

O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Arquivos de programas\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)

O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll (Caixa Economica Federal)

O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Arquivos de programas\Yontoo Layers\YontooIEClient.dll (Yontoo Technology, Inc.)

O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll ()

O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)

O3 - HKU\S-1-5-21-1935655697-854245398-725345543-1003\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.

O3 - HKU\S-1-5-21-1935655697-854245398-725345543-1003\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.

O3 - HKU\S-1-5-21-1935655697-854245398-725345543-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.

O4 - HKU\S-1-5-21-1935655697-854245398-725345543-1003..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe (Nero AG)

O4 - HKU\S-1-5-21-1935655697-854245398-725345543-1003..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File not found

O4 - HKLM..\RunServices: [RegisterDropHandler] C:\Arquivos de programas\TextBridge Pro 8.0\Bin\RegisterDropHandler.exe ()

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O7 - HKU\S-1-5-21-1935655697-854245398-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: Baixar Link Utiizando Gerenciador Mega... - C:\Arquivos de programas\Megaupload\Mega Manager\mm_file.htm ()

O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Arquivos de programas\Megaupload\Mega Manager\mm_file.htm ()

O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Andreia\Dados de aplicativos\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()

O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Andreia\Dados de aplicativos\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html File not found

O15 - HKU\S-1-5-21-1935655697-854245398-725345543-1003\..Trusted Domains: live.com ([sn104w.snt104.mail] http in Sites confiáveis)

O15 - HKU\S-1-5-21-1935655697-854245398-725345543-1003\..Trusted Domains: microsoft.com ([windowsupdate] https in Sites confiáveis)

O15 - HKU\S-1-5-21-1935655697-854245398-725345543-1003\..Trusted Domains: microsoft.com ([www.update] https in Sites confiáveis)

O15 - HKU\S-1-5-21-1935655697-854245398-725345543-1003\..Trusted Domains: orkut.com.br ([www] http in Sites confiáveis)

O15 - HKU\S-1-5-21-1935655697-854245398-725345543-1003\..Trusted Domains: yahoo.com ([br.mc1607.mail] http in Sites confiáveis)

O15 - HKU\S-1-5-21-1935655697-854245398-725345543-1003\..Trusted Ranges: Range1 ([*] in Sites confiáveis)

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} https://imagem.caixa.gov.br/cab/gbpdist.cab (GbpDistObj Class)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C7DDC215-21FF-4ACD-A57B-5D43D42D1472}: NameServer = 201.10.120.3,201.10.1.2

O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)

O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\Userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

O20 - Winlogon\Notify\ GbPluginCef: DllName - (C:\ARQUIV~1\GbPlugin\gbiehCef.dll) - C:\Arquivos de programas\GbPlugin\gbiehcef.dll (Caixa Economica Federal)

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll (Scopus Tecnologia Ltda)

O22 - SharedTaskScheduler: {A3717295-941D-416F-9384-ED1736729F1C} - scpLIB - C:\Arquivos de programas\Scpad\scpLIB.dll (Scopus Tecnologia Ltda)

O24 - Desktop Components:0 (Minha página inicial atual) - About:Home

O24 - Desktop WallPaper: C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Microsoft\Wallpaper1.bmp

O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll (Caixa Economica Federal)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009/06/10 22:31:01 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\{1340d0ae-6d9e-11de-89e0-ac3a2db22a9f}\Shell\AutoRun\command - "" = wscript.exe .\.vbs

O33 - MountPoints2\{1340d0ae-6d9e-11de-89e0-ac3a2db22a9f}\Shell\open\command - "" = wscript.exe .\.vbs

O33 - MountPoints2\{6e7a9762-bfe8-11df-8c06-001966a5cb0e}\Shell - "" = AutoRun

O33 - MountPoints2\{6e7a9762-bfe8-11df-8c06-001966a5cb0e}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

O34 - HKLM BootExecute: (autocheck autochk *)

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2011/11/15 20:56:05 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Andreia\Desktop\OTL.exe

[2011/11/15 20:15:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Iniciar\Programas\E.M. PowerPoint Video Converter

[2011/11/15 18:43:38 | 000,000,000 | ---D | C] -- C:\Slide 1AV

[2011/11/15 17:39:16 | 013,962,599 | ---- | C] (Leawo Software Co., LTD ) -- C:\Documents and Settings\Andreia\Desktop\leawo_ppt2video_free.exe

[2011/11/14 23:18:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Iniciar\Programas\Google Earth

[2011/11/13 17:39:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andreia\Meus documentos\dianaaa

[2011/11/12 11:13:44 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Trend Micro

[2011/11/12 11:13:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andreia\Menu Iniciar\Programas\HiJackThis

[2011/11/09 19:10:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Andreia\Meus documentos\Gmail - Entrada (6) - felizeca@gmail.com_files

[2011/11/03 11:42:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Iniciar\Programas\Microsoft Silverlight

[2011/11/03 11:41:57 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Microsoft Silverlight

[2010/09/15 22:18:15 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Andreia\Dados de aplicativos\pcouffin.sys

[2010/08/15 02:40:51 | 000,822,296 | ---- | C] (RealNetworks, Inc.) -- C:\Arquivos de programas\RealPlayerSPGold_br.exe

[2010/08/15 02:32:37 | 010,427,196 | ---- | C] (ZJMedia ) -- C:\Arquivos de programas\WinAVI_Video_Converter.exe

[2010/02/14 23:27:10 | 000,147,456 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnpstd3.dll

[2010/02/14 23:27:10 | 000,053,248 | ---- | C] ( ) -- C:\WINDOWS\vsnpstd3.dll

[2010/02/14 23:27:10 | 000,018,944 | ---- | C] ( ) -- C:\WINDOWS\System32\csnpstd3.dll

[2010/01/26 14:50:48 | 008,154,064 | ---- | C] (Mozilla) -- C:\Arquivos de programas\Firefox Setup 3.6.exe

[2010/01/14 12:30:42 | 018,184,760 | ---- | C] (Sony Ericsson ) -- C:\Arquivos de programas\Sony_Ericsson_PC_Suite_6.009.00_Web_ENG.exe

[2010/01/12 14:37:55 | 001,154,384 | ---- | C] (Microsoft Corporation) -- C:\Arquivos de programas\wlsetup-custom.exe

[2009/10/30 18:50:10 | 000,598,086 | ---- | C] (DVD Shrink) -- C:\Arquivos de programas\DVD Shrink 3.2.exe

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2011/11/15 21:09:05 | 000,001,176 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1935655697-854245398-725345543-1003UA.job

[2011/11/15 20:58:00 | 000,001,072 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2011/11/15 20:56:21 | 000,869,194 | ---- | M] () -- C:\Documents and Settings\Andreia\Desktop\SecurityCheck.exe

[2011/11/15 20:56:09 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Andreia\Desktop\OTL.exe

[2011/11/15 20:15:15 | 000,000,789 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\E.M. PowerPoint Video Converter.lnk

[2011/11/15 18:28:30 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2011/11/15 17:58:15 | 000,059,978 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\FamilinterneT.jpg

[2011/11/15 17:57:51 | 000,100,898 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Gente12.jpg

[2011/11/15 17:57:32 | 000,068,486 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Aguias10.jpg

[2011/11/15 17:40:26 | 013,962,599 | ---- | M] (Leawo Software Co., LTD ) -- C:\Documents and Settings\Andreia\Desktop\leawo_ppt2video_free.exe

[2011/11/15 17:04:03 | 000,023,384 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\RosaPraVC.gif

[2011/11/15 16:19:32 | 000,164,864 | ---- | M] () -- C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2011/11/15 16:14:22 | 000,000,458 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{F1D47F1B-F51D-4555-8335-DF4591747F37}.job

[2011/11/15 11:25:13 | 000,001,068 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2011/11/15 11:25:10 | 000,000,298 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1935655697-854245398-725345543-1003.job

[2011/11/15 11:25:10 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job

[2011/11/15 11:25:10 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\DriverScanner.job

[2011/11/15 11:22:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat

[2011/11/15 00:09:01 | 000,001,124 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1935655697-854245398-725345543-1003Core.job

[2011/11/14 23:18:20 | 000,001,971 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk

[2011/11/14 17:27:37 | 003,368,730 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\PenhahC.bmp

[2011/11/14 12:43:30 | 001,170,944 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Veice.pps

[2011/11/13 23:32:17 | 000,739,770 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Re_ {POESIAEAMIGOS} CADA DIA EU TE AMO MAIS - FERA MANHOSA - ARTESDAM.eml

[2011/11/13 22:34:56 | 000,183,864 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Os Eus que nao sou Eu.jpg

[2011/11/13 21:03:19 | 001,238,016 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\AmorVirtual.pps

[2011/11/13 15:34:29 | 000,048,366 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\AmorVirtual-charge.jpg

[2011/11/13 15:01:20 | 000,034,018 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\SexoVirtual-7.jpg

[2011/11/13 14:38:58 | 000,073,402 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\SexVirt1.jpg

[2011/11/13 14:29:26 | 000,058,392 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\AmorVirtual1.jpg

[2011/11/13 14:11:06 | 000,067,261 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\redes-sociais.jpg

[2011/11/13 14:08:38 | 000,038,104 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\VirtualLove.jpg

[2011/11/13 14:00:25 | 000,029,390 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\SexoVirtual8.jpg

[2011/11/13 13:58:27 | 000,041,442 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\SexoVirtual5.JPG

[2011/11/13 13:56:54 | 000,024,963 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\sexo-virtual.jpg

[2011/11/13 13:51:31 | 000,041,582 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\SexVirtual3a.jpg

[2011/11/13 13:49:18 | 000,028,847 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\1281618345410_f (1).jpg

[2011/11/13 13:47:54 | 000,037,404 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\AmorVirt1a.jpg

[2011/11/13 13:41:57 | 000,040,853 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\SexVirt2.jpg

[2011/11/13 13:37:38 | 000,032,251 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\sexo-virtual1.jpg

[2011/11/13 13:33:00 | 000,019,428 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\cybersex2.jpg

[2011/11/13 13:25:08 | 000,026,073 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\AmorVirtual.jpg

[2011/11/13 13:12:39 | 000,058,538 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Corujas.jpg

[2011/11/13 12:28:16 | 000,091,427 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Ninfas-Angelicas.jpg

[2011/11/13 11:28:51 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl

[2011/11/12 23:06:39 | 000,017,750 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\QuadroAzul.jpg

[2011/11/12 22:50:45 | 001,440,054 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\CriançasZkptk.bmp

[2011/11/12 18:39:31 | 000,018,556 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Anjinhos-Flores.jpg

[2011/11/12 18:28:49 | 000,117,340 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\PenhahC-Lindaaa.jpg

[2011/11/12 18:24:37 | 000,260,941 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\PenhahCastro-2011.jpg

[2011/11/12 17:10:35 | 000,044,534 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Estrelas.luz.noite.jpg

[2011/11/12 16:25:03 | 000,647,226 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\BIAFRA~1-NumaNoit.MID

[2011/11/12 16:20:26 | 000,111,645 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura11.jpg

[2011/11/12 16:19:52 | 000,105,090 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura10.jpg

[2011/11/12 16:19:08 | 000,104,136 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura9.jpg

[2011/11/12 16:18:48 | 000,106,901 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura8.jpg

[2011/11/12 16:18:29 | 000,104,581 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura7.jpg

[2011/11/12 16:18:06 | 000,103,289 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura6.jpg

[2011/11/12 16:17:48 | 000,103,711 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura5.jpg

[2011/11/12 16:17:25 | 000,102,326 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura4.jpg

[2011/11/12 16:17:04 | 000,105,775 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura3.jpg

[2011/11/12 16:16:33 | 000,106,739 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura2.jpg

[2011/11/12 16:16:07 | 000,104,215 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura1.jpg

[2011/11/12 16:15:35 | 000,105,090 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura12.jpg

[2011/11/12 15:53:43 | 000,079,228 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\SolPalmeira-fdo-1024.jpg

[2011/11/12 15:51:27 | 000,251,482 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\SolPalmeira-fdo.bmp

[2011/11/12 13:05:15 | 000,469,504 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Pedacinhos.pps

[2011/11/12 13:04:58 | 000,589,824 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\bomdia-cristo.pps

[2011/11/12 11:13:44 | 000,002,012 | ---- | M] () -- C:\Documents and Settings\Andreia\Desktop\HiJackThis.lnk

[2011/11/11 21:42:28 | 000,015,225 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Monitor-da-Alma-Zeca-Feliz.jpg

[2011/11/11 21:38:32 | 000,025,203 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\e-agora-oh-ze.jpg

[2011/11/11 21:28:49 | 000,016,014 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Zeca-Feliz-OrqVersoProsa.jpg

[2011/11/11 21:25:54 | 000,021,031 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\tic-tac-Zeca Avelar.jpg

[2011/11/11 21:22:12 | 000,085,525 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\zeca_tag.jpg

[2011/11/11 19:01:12 | 000,043,781 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Velhs Falantes.jpg

[2011/11/11 18:58:54 | 000,068,491 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Velhs Falantes.png

[2011/11/11 18:40:17 | 000,030,297 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Ouvidos-de-Deus.jpg

[2011/11/11 18:38:58 | 000,285,890 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Ouvidos-de-Deus.png

[2011/11/11 18:05:42 | 000,110,882 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Palacio-Planalto-Drogas.jpg

[2011/11/11 18:02:05 | 000,089,601 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Mulheres-Nuasss.jpg

[2011/11/11 15:36:44 | 000,150,016 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\FOTO_DE_MACHU_PICCHU.pps

[2011/11/11 15:36:39 | 000,451,584 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\FOTO_DA_BIRMANIA.pps

[2011/11/11 15:35:08 | 000,219,294 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Soldado-Desconhecido.jpg

[2011/11/11 15:31:18 | 000,119,372 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Viva-sua-vida-1280x1024.jpg

[2011/11/11 15:29:53 | 000,243,274 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Chuva de Verao.jpg

[2011/11/11 15:28:12 | 000,190,740 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Deus.jpg

[2011/11/11 15:25:18 | 000,207,579 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\SonhosPartilhados.jpg

[2011/11/11 15:22:36 | 000,139,328 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\cachoeiras-9.jpg

[2011/11/11 15:20:49 | 000,065,658 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Alegria pela Vida.jpg

[2011/11/11 15:18:36 | 000,044,137 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Meninas-Puras.jpg

[2011/11/11 15:14:46 | 000,113,858 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\MeninasPuras.jpg

[2011/11/11 15:10:51 | 000,021,618 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\guerra1.jpg

[2011/11/11 15:07:04 | 000,017,579 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\chs007.jpg

[2011/11/11 15:06:01 | 000,074,652 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\DiaNublado.jpg

[2011/11/11 15:04:57 | 000,008,191 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\500758.jpg

[2011/11/11 15:02:00 | 000,615,305 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Meninos-DEscalcos.JPG

[2011/11/11 14:56:49 | 000,082,333 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Palacio-Planalto.jpeg

[2011/11/11 14:54:38 | 000,030,154 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\foto drogas.jpg

[2011/11/11 14:49:15 | 000,071,013 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\MulherNua.jpg

[2011/11/11 14:48:26 | 000,266,821 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\MiopiadaGananciaMatutina.jpg

[2011/11/11 14:45:37 | 000,236,451 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Predios.jpg

[2011/11/11 14:44:03 | 000,053,519 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Amantesss.jpg

[2011/11/11 14:38:36 | 000,045,110 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\OlhardeDeus.jpg

[2011/11/11 14:37:04 | 000,130,526 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\olho_de_deus1.jpg

[2011/11/11 14:32:53 | 000,018,941 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\o olho de deus.jpg

[2011/11/11 14:32:03 | 000,015,076 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\jjjboneca.jpg

[2011/11/11 14:31:28 | 000,013,259 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\nua.jpg

[2011/11/11 14:30:31 | 000,657,461 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\aa2p.png

[2011/11/11 14:29:27 | 000,090,619 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\kukula001.jpg

[2011/11/11 14:25:55 | 000,104,516 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\meninas_bonecas_contorno2[1].jpg

[2011/11/11 14:23:30 | 000,224,347 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Homem-de-Terno.jpg

[2011/11/11 14:19:12 | 000,059,132 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Brincos.jpg

[2011/11/11 14:11:50 | 000,006,416 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Monica-Bellucci-443.jpg

[2011/11/11 14:01:43 | 000,045,396 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\expulsparaiso.jpg

[2011/11/11 13:43:13 | 001,453,568 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Sonata_ao_Luar.pps

[2011/11/11 10:40:57 | 000,000,125 | -HS- | M] () -- C:\Documents and Settings\Andreia\Dados de aplicativos\.zreglib

[2011/11/10 23:44:00 | 000,000,306 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1935655697-854245398-725345543-1003.job

[2011/11/10 21:39:29 | 000,214,118 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Utopia.pdf

[2011/11/10 21:33:44 | 000,519,954 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\The picture of Dorian Gray pdf.pdf

[2011/11/10 21:32:00 | 000,130,279 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\A-esfinge-sem-segredo2.pdf

[2011/11/10 21:23:37 | 000,115,672 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\The Comedy of Errors.pdf

[2011/11/10 21:13:15 | 001,797,156 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Divina Comedia Pt.pdf

[2011/11/10 21:08:13 | 000,083,118 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\O Livro Dele.pdf

[2011/11/10 21:06:01 | 002,708,489 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Ulysses.pdf

[2011/11/10 21:03:35 | 000,130,279 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\A Esfinge.pdf

[2011/11/10 21:00:42 | 000,219,080 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\aNTIGONAS.pdf

[2011/11/10 20:56:53 | 000,844,905 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Divina cOMEDIA.pdf

[2011/11/10 20:54:29 | 000,130,279 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\A-esfinge-sem-segredo.pdf

[2011/11/10 20:11:20 | 000,661,504 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\AME MARIA.pps

[2011/11/10 19:06:18 | 000,124,813 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Niver-Parabens.jpg

[2011/11/10 17:54:21 | 000,214,829 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Zinha-Niver-10112011.jpg

[2011/11/10 17:52:45 | 000,157,634 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Zinha-Niver-101111.jpg

[2011/11/10 17:41:10 | 000,089,488 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Feliz Aniversario.jpg

[2011/11/10 13:13:34 | 000,067,193 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\OdeteD-FB-Fpolis.jpg

[2011/11/10 13:13:02 | 000,081,816 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\OdeteDaminelli.jpg

[2011/11/10 13:10:27 | 000,137,201 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\OdeteD.jpg

[2011/11/10 13:09:40 | 000,141,219 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\OdeteDaminelli FB.jpg

[2011/11/10 13:08:40 | 000,034,167 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\OdeteDaminelli FB - Fpolis.jpg

[2011/11/10 12:49:35 | 000,528,896 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\voo_de_gansos.pps

[2011/11/09 21:01:17 | 000,043,804 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Deus-EscadaparaCeu.jpg

[2011/11/09 21:00:06 | 000,153,104 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\AveMaria-txt.jpg

[2011/11/09 19:10:28 | 000,407,049 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Gmail - Entrada (6) - felizeca@gmail.com.htm

[2011/11/09 14:34:09 | 000,035,400 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\_Euosou_ ESPETACULAR!!! UM EMAIL PARA NÃO APAGAR.eml

[2011/11/09 13:57:15 | 000,118,241 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Lunna Pains Parabéns.jpg

[2011/11/09 13:29:41 | 000,031,308 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\RosaLunna.jpg

[2011/11/09 13:27:22 | 000,022,336 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Lunna Pains.jpg

[2011/11/09 13:00:05 | 000,314,666 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Obras Poeticas Gregorio de Matos.pdf

[2011/11/09 12:55:27 | 000,091,776 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Saudade.pdf

[2011/11/09 12:54:00 | 000,101,767 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\El Arte de la Guerra.pdf

[2011/11/09 12:51:47 | 000,098,010 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\O Navio Negreiro.pdf

[2011/11/09 12:50:05 | 000,000,300 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[2011/11/09 12:34:26 | 000,120,139 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\O Alienista.pdf

[2011/11/08 21:58:41 | 000,097,992 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Musicas 1940 a 2005.eml

[2011/11/08 19:43:57 | 000,136,273 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\bolinho-de-chuva-f8-1525.jpg

[2011/11/08 11:49:48 | 000,218,896 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Um dia de Graças.eml

[2011/11/08 11:42:14 | 000,157,142 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\ZK-Cel 025.jpg

[2011/11/05 12:57:04 | 000,000,668 | ---- | M] () -- C:\Documents and Settings\Andreia\Dados de aplicativos\vso_ts_preview.xml

[2011/11/04 21:11:50 | 000,011,683 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!ZecaZenFeliz.gif

[2011/11/04 19:20:55 | 000,002,545 | ---- | M] () -- C:\Documents and Settings\Andreia\Desktop\Microsoft Word.lnk

[2011/11/03 12:31:42 | 000,001,113 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!!!LosangoSU-stars.gif

[2011/11/03 12:31:14 | 000,003,548 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!!!Anobannerestrela155.gif

[2011/10/30 10:25:26 | 000,001,769 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2011/10/27 21:23:14 | 000,141,600 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!Karinhos Kentinhos ZF.gif

[2011/10/27 21:06:53 | 000,078,366 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!!!Karinhos Kentinhos ZK.gif

[2011/10/27 21:02:25 | 000,040,384 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!gaDs x3d.gif

[2011/10/27 21:00:01 | 000,081,356 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!KarinhosKentinhos.gif

[2011/10/27 20:56:06 | 000,031,611 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!gaDs-x3d.gif

[2011/10/27 15:00:34 | 000,119,941 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\AlimentosDiv.jpg

[2011/10/26 19:22:49 | 000,108,075 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\PraidadoZamor.jpg

[2011/10/26 17:04:06 | 000,204,918 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\KZK-MiPq.jpg

[2011/10/26 16:57:32 | 000,136,357 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\KZK-Cel 019.jpg

[2011/10/26 10:45:40 | 000,422,400 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Forte.CRLemberg-pps

[2011/10/25 16:18:54 | 000,236,158 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Gaiola.jpg

[2011/10/25 15:02:51 | 000,139,138 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\CanarionaGaiola.jpg

[2011/10/25 14:51:08 | 000,096,253 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Canarinhos_zep.jpg

[2011/10/25 12:51:17 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat

[2011/10/24 13:36:18 | 000,134,991 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Loren-Niver-Je-Sam-Naith-ZK.jpg

[2011/10/24 13:33:42 | 000,177,166 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\ZK-ZK-231011.jpg

[2011/10/24 13:29:30 | 000,131,257 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\ZK-CelOut11 012.jpg

[2011/10/24 13:27:21 | 000,112,691 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\ZK-ZKza-Sabia.jpg

[2011/10/23 10:47:22 | 000,468,462 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat

[2011/10/23 10:47:22 | 000,432,492 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat

[2011/10/23 10:47:22 | 000,079,240 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat

[2011/10/23 10:47:22 | 000,067,448 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

[2011/10/22 22:54:58 | 000,394,752 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Convite.SueliWeber-pps

[2011/10/21 18:40:59 | 001,187,082 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\aaaa.jpg

[2011/10/20 10:00:47 | 000,229,516 | ---- | M] () -- C:\Documents and Settings\Andreia\Meus documentos\Mi_Spacial_Niver_0711.jpg

[2011/10/20 07:50:16 | 000,000,111 | ---- | M] () -- C:\Documents and Settings\Andreia\default.pls

[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2011/11/15 20:55:30 | 000,869,194 | ---- | C] () -- C:\Documents and Settings\Andreia\Desktop\SecurityCheck.exe

[2011/11/15 20:15:15 | 000,000,789 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\E.M. PowerPoint Video Converter.lnk

[2011/11/15 17:59:01 | 000,059,978 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\FamilinterneT.jpg

[2011/11/15 17:58:01 | 000,100,898 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Gente12.jpg

[2011/11/15 17:57:41 | 000,068,486 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Aguias10.jpg

[2011/11/15 17:04:22 | 000,023,384 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\RosaPraVC.gif

[2011/11/14 23:18:20 | 000,001,971 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk

[2011/11/14 17:27:36 | 003,368,730 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\PenhahC.bmp

[2011/11/14 12:43:29 | 001,170,944 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Veice.pps

[2011/11/13 23:32:17 | 000,739,770 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Re_ {POESIAEAMIGOS} CADA DIA EU TE AMO MAIS - FERA MANHOSA - ARTESDAM.eml

[2011/11/13 22:32:55 | 000,183,864 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Os Eus que nao sou Eu.jpg

[2011/11/13 21:03:18 | 001,238,016 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\AmorVirtual.pps

[2011/11/13 15:35:29 | 000,048,366 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\AmorVirtual-charge.jpg

[2011/11/13 14:52:14 | 000,034,018 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\SexoVirtual-7.jpg

[2011/11/13 14:11:09 | 000,067,261 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\redes-sociais.jpg

[2011/11/13 14:08:37 | 000,038,104 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\VirtualLove.jpg

[2011/11/13 14:00:39 | 000,029,390 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\SexoVirtual8.jpg

[2011/11/13 13:58:41 | 000,041,442 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\SexoVirtual5.JPG

[2011/11/13 13:56:58 | 000,024,963 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\sexo-virtual.jpg

[2011/11/13 13:51:31 | 000,041,582 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\SexVirtual3a.jpg

[2011/11/13 13:49:23 | 000,028,847 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\1281618345410_f (1).jpg

[2011/11/13 13:47:54 | 000,037,404 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\AmorVirt1a.jpg

[2011/11/13 13:44:23 | 000,058,392 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\AmorVirtual1.jpg

[2011/11/13 13:43:07 | 000,073,402 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\SexVirt1.jpg

[2011/11/13 13:41:57 | 000,040,853 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\SexVirt2.jpg

[2011/11/13 13:37:41 | 000,032,251 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\sexo-virtual1.jpg

[2011/11/13 13:33:05 | 000,019,428 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\cybersex2.jpg

[2011/11/13 13:25:25 | 000,026,073 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\AmorVirtual.jpg

[2011/11/13 13:12:48 | 000,058,538 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Corujas.jpg

[2011/11/13 12:29:05 | 000,091,427 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Ninfas-Angelicas.jpg

[2011/11/12 23:05:15 | 000,017,750 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\QuadroAzul.jpg

[2011/11/12 22:50:45 | 001,440,054 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\CriançasZkptk.bmp

[2011/11/12 18:39:30 | 000,018,556 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Anjinhos-Flores.jpg

[2011/11/12 18:28:49 | 000,117,340 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\PenhahC-Lindaaa.jpg

[2011/11/12 18:24:51 | 000,260,941 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\PenhahCastro-2011.jpg

[2011/11/12 17:10:55 | 000,044,534 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Estrelas.luz.noite.jpg

[2011/11/12 16:31:34 | 002,648,343 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\AmaZK Gr.mp3

[2011/11/12 16:25:03 | 000,647,226 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\BIAFRA~1-NumaNoit.MID

[2011/11/12 16:19:52 | 000,105,090 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura10.jpg

[2011/11/12 16:19:08 | 000,104,136 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura9.jpg

[2011/11/12 16:18:48 | 000,106,901 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura8.jpg

[2011/11/12 16:18:28 | 000,104,581 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura7.jpg

[2011/11/12 16:18:06 | 000,103,289 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura6.jpg

[2011/11/12 16:17:48 | 000,103,711 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura5.jpg

[2011/11/12 16:17:24 | 000,102,326 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura4.jpg

[2011/11/12 16:17:03 | 000,105,775 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura3.jpg

[2011/11/12 16:16:32 | 000,106,739 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura2.jpg

[2011/11/12 16:16:07 | 000,104,215 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura1.jpg

[2011/11/12 16:15:35 | 000,105,090 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura12.jpg

[2011/11/12 16:15:04 | 000,111,645 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Figura11.jpg

[2011/11/12 15:53:43 | 000,079,228 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\SolPalmeira-fdo-1024.jpg

[2011/11/12 15:51:27 | 000,251,482 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\SolPalmeira-fdo.bmp

[2011/11/12 13:05:15 | 000,469,504 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Pedacinhos.pps

[2011/11/12 13:04:58 | 000,589,824 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\bomdia-cristo.pps

[2011/11/12 11:13:44 | 000,002,012 | ---- | C] () -- C:\Documents and Settings\Andreia\Desktop\HiJackThis.lnk

[2011/11/11 21:42:57 | 000,015,225 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Monitor-da-Alma-Zeca-Feliz.jpg

[2011/11/11 21:38:37 | 000,025,203 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\e-agora-oh-ze.jpg

[2011/11/11 21:29:17 | 000,016,014 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Zeca-Feliz-OrqVersoProsa.jpg

[2011/11/11 21:26:17 | 000,021,031 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\tic-tac-Zeca Avelar.jpg

[2011/11/11 21:22:43 | 000,085,525 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\zeca_tag.jpg

[2011/11/11 20:04:26 | 001,782,735 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\The sound of silence ac.mp3

[2011/11/11 19:01:12 | 000,043,781 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Velhs Falantes.jpg

[2011/11/11 18:59:05 | 000,068,491 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Velhs Falantes.png

[2011/11/11 18:40:17 | 000,030,297 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Ouvidos-de-Deus.jpg

[2011/11/11 18:39:31 | 000,285,890 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Ouvidos-de-Deus.png

[2011/11/11 18:05:42 | 000,110,882 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Palacio-Planalto-Drogas.jpg

[2011/11/11 18:02:05 | 000,089,601 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Mulheres-Nuasss.jpg

[2011/11/11 15:36:44 | 000,150,016 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\FOTO_DE_MACHU_PICCHU.pps

[2011/11/11 15:36:39 | 000,451,584 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\FOTO_DA_BIRMANIA.pps

[2011/11/11 15:35:22 | 000,219,294 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Soldado-Desconhecido.jpg

[2011/11/11 15:31:34 | 000,119,372 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Viva-sua-vida-1280x1024.jpg

[2011/11/11 15:30:06 | 000,243,274 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Chuva de Verao.jpg

[2011/11/11 15:28:15 | 000,190,740 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Deus.jpg

[2011/11/11 15:25:32 | 000,207,579 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\SonhosPartilhados.jpg

[2011/11/11 15:22:45 | 000,139,328 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\cachoeiras-9.jpg

[2011/11/11 15:20:59 | 000,065,658 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Alegria pela Vida.jpg

[2011/11/11 15:18:55 | 000,044,137 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Meninas-Puras.jpg

[2011/11/11 15:15:04 | 000,113,858 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\MeninasPuras.jpg

[2011/11/11 15:10:53 | 000,021,618 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\guerra1.jpg

[2011/11/11 15:07:07 | 000,017,579 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\chs007.jpg

[2011/11/11 15:06:12 | 000,074,652 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\DiaNublado.jpg

[2011/11/11 15:05:01 | 000,008,191 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\500758.jpg

[2011/11/11 15:02:19 | 000,615,305 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Meninos-DEscalcos.JPG

[2011/11/11 14:56:53 | 000,082,333 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Palacio-Planalto.jpeg

[2011/11/11 14:54:45 | 000,030,154 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\foto drogas.jpg

[2011/11/11 14:49:20 | 000,071,013 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\MulherNua.jpg

[2011/11/11 14:48:51 | 000,266,821 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\MiopiadaGananciaMatutina.jpg

[2011/11/11 14:45:42 | 000,236,451 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Predios.jpg

[2011/11/11 14:44:05 | 000,053,519 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Amantesss.jpg

[2011/11/11 14:38:38 | 000,045,110 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\OlhardeDeus.jpg

[2011/11/11 14:37:08 | 000,130,526 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\olho_de_deus1.jpg

[2011/11/11 14:32:55 | 000,018,941 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\o olho de deus.jpg

[2011/11/11 14:32:06 | 000,015,076 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\jjjboneca.jpg

[2011/11/11 14:31:31 | 000,013,259 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\nua.jpg

[2011/11/11 14:30:37 | 000,657,461 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\aa2p.png

[2011/11/11 14:29:31 | 000,090,619 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\kukula001.jpg

[2011/11/11 14:25:58 | 000,104,516 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\meninas_bonecas_contorno2[1].jpg

[2011/11/11 14:23:33 | 000,224,347 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Homem-de-Terno.jpg

[2011/11/11 14:19:16 | 000,059,132 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Brincos.jpg

[2011/11/11 14:11:55 | 000,006,416 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Monica-Bellucci-443.jpg

[2011/11/11 14:01:55 | 000,045,396 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\expulsparaiso.jpg

[2011/11/11 13:43:12 | 001,453,568 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Sonata_ao_Luar.pps

[2011/11/10 21:39:42 | 000,214,118 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Utopia.pdf

[2011/11/10 21:34:20 | 000,519,954 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\The picture of Dorian Gray pdf.pdf

[2011/11/10 21:32:31 | 000,130,279 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\A-esfinge-sem-segredo2.pdf

[2011/11/10 21:23:58 | 000,115,672 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\The Comedy of Errors.pdf

[2011/11/10 21:13:27 | 001,797,156 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Divina Comedia Pt.pdf

[2011/11/10 21:08:28 | 000,083,118 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\O Livro Dele.pdf

[2011/11/10 21:06:10 | 002,708,489 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Ulysses.pdf

[2011/11/10 21:03:50 | 000,130,279 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\A Esfinge.pdf

[2011/11/10 21:00:54 | 000,219,080 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\aNTIGONAS.pdf

[2011/11/10 20:57:14 | 000,844,905 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Divina cOMEDIA.pdf

[2011/11/10 20:54:49 | 000,130,279 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\A-esfinge-sem-segredo.pdf

[2011/11/10 20:11:20 | 000,661,504 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\AME MARIA.pps

[2011/11/10 19:06:18 | 000,124,813 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Niver-Parabens.jpg

[2011/11/10 17:54:21 | 000,214,829 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Zinha-Niver-10112011.jpg

[2011/11/10 17:52:44 | 000,157,634 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Zinha-Niver-101111.jpg

[2011/11/10 17:36:36 | 000,089,488 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Feliz Aniversario.jpg

[2011/11/10 13:13:45 | 000,067,193 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\OdeteD-FB-Fpolis.jpg

[2011/11/10 13:13:11 | 000,081,816 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\OdeteDaminelli.jpg

[2011/11/10 13:10:33 | 000,137,201 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\OdeteD.jpg

[2011/11/10 13:09:55 | 000,141,219 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\OdeteDaminelli FB.jpg

[2011/11/10 13:09:11 | 000,034,167 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\OdeteDaminelli FB - Fpolis.jpg

[2011/11/10 12:49:34 | 000,528,896 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\voo_de_gansos.pps

[2011/11/09 21:01:17 | 000,043,804 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Deus-EscadaparaCeu.jpg

[2011/11/09 21:00:06 | 000,153,104 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\AveMaria-txt.jpg

[2011/11/09 19:10:28 | 000,407,049 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Gmail - Entrada (6) - felizeca@gmail.com.htm

[2011/11/09 14:34:09 | 000,035,400 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\_Euosou_ ESPETACULAR!!! UM EMAIL PARA NÃO APAGAR.eml

[2011/11/09 13:55:19 | 000,118,241 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Lunna Pains Parabéns.jpg

[2011/11/09 13:29:41 | 000,031,308 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\RosaLunna.jpg

[2011/11/09 13:27:56 | 000,022,336 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Lunna Pains.jpg

[2011/11/09 13:00:35 | 000,314,666 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Obras Poeticas Gregorio de Matos.pdf

[2011/11/09 12:55:42 | 000,091,776 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Saudade.pdf

[2011/11/09 12:54:21 | 000,101,767 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\El Arte de la Guerra.pdf

[2011/11/09 12:52:02 | 000,098,010 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\O Navio Negreiro.pdf

[2011/11/09 12:34:55 | 000,120,139 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\O Alienista.pdf

[2011/11/08 21:58:41 | 000,097,992 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Musicas 1940 a 2005.eml

[2011/11/08 19:44:09 | 000,136,273 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\bolinho-de-chuva-f8-1525.jpg

[2011/11/08 11:49:48 | 000,218,896 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Um dia de Graças.eml

[2011/11/08 11:42:14 | 000,157,142 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\ZK-Cel 025.jpg

[2011/11/04 21:12:21 | 000,011,683 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!ZecaZenFeliz.gif

[2011/11/03 12:32:08 | 000,001,113 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!!!LosangoSU-stars.gif

[2011/11/03 12:31:32 | 000,003,548 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!!!Anobannerestrela155.gif

[2011/10/30 10:25:26 | 000,001,769 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk

[2011/10/27 21:23:12 | 000,141,600 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!Karinhos Kentinhos ZF.gif

[2011/10/27 21:06:51 | 000,078,366 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!!!Karinhos Kentinhos ZK.gif

[2011/10/27 21:02:24 | 000,040,384 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!gaDs x3d.gif

[2011/10/27 20:56:05 | 000,031,611 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!gaDs-x3d.gif

[2011/10/27 20:54:00 | 000,081,356 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\!!!KarinhosKentinhos.gif

[2011/10/27 15:00:34 | 000,119,941 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\AlimentosDiv.jpg

[2011/10/26 19:22:49 | 000,108,075 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\PraidadoZamor.jpg

[2011/10/26 17:04:05 | 000,204,918 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\KZK-MiPq.jpg

[2011/10/26 16:57:31 | 000,136,357 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\KZK-Cel 019.jpg

[2011/10/26 10:45:40 | 000,422,400 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Forte.CRLemberg-pps

[2011/10/25 16:18:54 | 000,236,158 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Gaiola.jpg

[2011/10/25 15:02:51 | 000,139,138 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\CanarionaGaiola.jpg

[2011/10/25 14:51:08 | 000,096,253 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Canarinhos_zep.jpg

[2011/10/24 13:36:17 | 000,134,991 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Loren-Niver-Je-Sam-Naith-ZK.jpg

[2011/10/24 13:33:42 | 000,177,166 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\ZK-ZK-231011.jpg

[2011/10/24 13:29:29 | 000,131,257 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\ZK-CelOut11 012.jpg

[2011/10/24 13:27:21 | 000,112,691 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\ZK-ZKza-Sabia.jpg

[2011/10/22 22:54:58 | 000,394,752 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Convite.SueliWeber-pps

[2011/10/21 18:40:58 | 001,187,082 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\aaaa.jpg

[2011/10/20 10:00:37 | 000,229,516 | ---- | C] () -- C:\Documents and Settings\Andreia\Meus documentos\Mi_Spacial_Niver_0711.jpg

[2011/08/26 00:42:02 | 000,000,591 | ---- | C] () -- C:\WINDOWS\MyHeritage.INI

[2011/08/26 00:39:15 | 000,454,656 | ---- | C] () -- C:\WINDOWS\System32\PaintX.dll

[2011/07/30 03:15:37 | 000,194,560 | ---- | C] () -- C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\FontCache3.0.0.0.dat

[2011/07/13 22:35:25 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys

[2011/07/13 19:22:58 | 000,000,033 | ---- | C] () -- C:\WINDOWS\Multimedia manager.INI

[2011/07/13 19:21:12 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\LauncherAccess.dt

[2011/07/13 19:10:18 | 000,000,438 | ---- | C] () -- C:\Arquivos de programas\Atalho para Samsung em KZK (Biba).lnk

[2011/07/06 19:58:27 | 000,000,000 | ---- | C] () -- C:\WINDOWS\TBRIDGE.INI

[2011/07/06 18:19:01 | 000,000,095 | ---- | C] () -- C:\WINDOWS\tb96.ini

[2011/07/06 16:39:40 | 000,000,200 | ---- | C] () -- C:\WINDOWS\maxlink.ini

[2011/07/06 16:39:40 | 000,000,104 | ---- | C] () -- C:\WINDOWS\Tb98.ini

[2011/07/06 16:38:51 | 000,046,512 | ---- | C] () -- C:\WINDOWS\System32\EPSN.DLL

[2011/07/06 16:38:51 | 000,012,126 | ---- | C] () -- C:\WINDOWS\System32\PIXPCZ.DLL

[2011/07/06 16:38:51 | 000,011,934 | ---- | C] () -- C:\WINDOWS\System32\PIXPNR.DLL

[2011/07/06 16:38:51 | 000,009,136 | ---- | C] () -- C:\WINDOWS\System32\INETWH16.DLL

[2011/07/06 16:38:51 | 000,004,528 | ---- | C] () -- C:\WINDOWS\System32\SETBROWS.EXE

[2011/07/06 16:36:40 | 000,000,153 | ---- | C] () -- C:\WINDOWS\ACROREAD.INI

[2011/02/04 20:25:43 | 000,000,183 | ---- | C] () -- C:\WINDOWS\rar_crck.ini

[2011/01/23 01:46:30 | 000,000,067 | ---- | C] () -- C:\WINDOWS\swf2avi.INI

[2011/01/23 01:46:22 | 000,758,018 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll

[2011/01/23 01:46:22 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll

[2011/01/12 01:36:28 | 000,000,050 | ---- | C] () -- C:\WINDOWS\MegaManager.INI

[2011/01/01 23:55:32 | 000,020,480 | ---- | C] () -- C:\WINDOWS\CameraFixer.exe

[2011/01/01 23:55:28 | 000,788,480 | ---- | C] () -- C:\WINDOWS\System32\drivers\snpstd3.sys

[2010/12/11 18:35:27 | 000,120,200 | ---- | C] () -- C:\WINDOWS\System32\DLLDEV32i.dll

[2010/12/11 18:34:33 | 000,006,211 | ---- | C] () -- C:\WINDOWS\mgxoschk.ini

[2010/09/15 22:18:15 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Andreia\Dados de aplicativos\inst.exe

[2010/09/15 22:18:15 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Andreia\Dados de aplicativos\pcouffin.cat

[2010/09/15 22:18:15 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Andreia\Dados de aplicativos\pcouffin.inf

[2010/09/15 21:59:33 | 000,000,668 | ---- | C] () -- C:\Documents and Settings\Andreia\Dados de aplicativos\vso_ts_preview.xml

[2010/09/12 20:26:29 | 000,073,220 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat

[2010/09/12 20:26:29 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat

[2010/09/12 20:26:29 | 000,029,114 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat

[2010/09/12 20:26:29 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat

[2010/09/12 20:26:29 | 000,021,021 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat

[2010/09/12 20:26:29 | 000,015,670 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat

[2010/09/12 20:26:29 | 000,013,280 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat

[2010/09/12 20:26:29 | 000,010,673 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat

[2010/09/12 20:26:29 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat

[2010/09/12 20:26:29 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat

[2010/09/12 20:26:29 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat

[2010/09/12 20:26:29 | 000,001,137 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat

[2010/09/12 20:26:29 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat

[2010/09/12 20:26:29 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat

[2010/09/12 20:26:29 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat

[2010/09/12 20:26:29 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini

[2010/09/12 20:26:02 | 000,000,079 | ---- | C] () -- C:\WINDOWS\EPCX5600.ini

[2010/08/15 03:11:45 | 000,000,050 | ---- | C] () -- C:\WINDOWS\cdplayer.ini

[2010/08/15 02:39:23 | 000,260,392 | ---- | C] () -- C:\Arquivos de programas\SoftonicDownloader11477.exe

[2010/08/12 21:00:26 | 000,328,684 | ---- | C] () -- C:\Arquivos de programas\audacity-win-unicode-1.3.12.exe

[2010/06/25 15:03:12 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll

[2010/04/28 20:58:21 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\MSJCE.dll

[2010/03/03 00:11:53 | 000,484,352 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2010/02/14 23:27:14 | 000,339,968 | ---- | C] () -- C:\WINDOWS\vsnpstd3.exe

[2010/02/14 23:27:14 | 000,114,688 | ---- | C] () -- C:\WINDOWS\tsnpstd3.exe

[2010/02/14 23:27:13 | 000,015,498 | ---- | C] () -- C:\WINDOWS\snpstd3.ini

[2010/02/14 23:27:10 | 008,410,880 | ---- | C] () -- C:\WINDOWS\System32\drivers\snpstd3.sys.off

[2010/02/14 23:27:10 | 000,020,480 | ---- | C] () -- C:\WINDOWS\usnpstd3.exe

[2010/01/11 20:16:21 | 000,000,002 | ---- | C] () -- C:\WINDOWS\memf8.dll

[2010/01/01 13:35:00 | 000,000,120 | ---- | C] () -- C:\Documents and Settings\Andreia\Dados de aplicativos\FixVTS.ini

[2009/12/26 18:03:36 | 000,000,421 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2009/11/27 17:26:34 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll

[2009/11/27 17:26:15 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\34CoInstaller.dll

[2009/11/24 00:13:28 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI

[2009/11/01 21:33:20 | 001,663,488 | ---- | C] () -- C:\WINDOWS\System32\BootMan.exe

[2009/11/01 21:33:20 | 000,086,408 | ---- | C] () -- C:\WINDOWS\System32\setupempdrv03.exe

[2009/11/01 21:33:20 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\EuEpmGdi.dll

[2009/11/01 21:33:20 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\epmntdrv.sys

[2009/11/01 21:33:20 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\EuGdiDrv.sys

[2009/10/29 14:29:43 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2009/10/27 18:54:55 | 001,094,021 | ---- | C] () -- C:\Arquivos de programas\dvdshrink32setup.zip

[2009/10/23 07:21:14 | 000,003,594 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini

[2009/10/23 07:21:12 | 000,010,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS

[2009/10/22 18:21:27 | 000,164,864 | ---- | C] () -- C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2009/10/01 16:01:46 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat

[2009/09/30 22:11:06 | 000,000,041 | -H-- | C] () -- C:\WINDOWS\dsez1345.dat

[2009/09/21 01:56:16 | 000,000,125 | -HS- | C] () -- C:\Documents and Settings\Andreia\Dados de aplicativos\.zreglib

[2009/09/18 00:11:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat

[2009/09/18 00:11:24 | 000,003,353 | ---- | C] () -- C:\WINDOWS\mozver.dat

[2009/09/15 01:11:35 | 000,001,732 | R--- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin

[2009/06/10 22:32:51 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat

[2009/06/10 22:28:36 | 000,021,844 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

[2009/06/07 09:27:20 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\vbzlib1.dll

[2009/03/30 04:28:37 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI

[2009/03/30 04:27:41 | 000,315,560 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2007/10/04 06:14:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll

[2007/10/04 06:14:00 | 001,626,112 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe

[2007/10/04 06:14:00 | 001,478,656 | ---- | C] () -- C:\WINDOWS\System32\nview.dll

[2007/10/04 06:14:00 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe

[2007/10/04 06:14:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll

[2007/10/04 06:14:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll

[2007/10/04 06:14:00 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe

[2007/10/04 06:14:00 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe

[2007/10/04 06:14:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll

[2007/01/26 02:04:12 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\mase32.dll

[2007/01/26 02:04:12 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\ma32.dll

[2004/08/04 01:57:52 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

[2004/08/02 15:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat

[2004/07/17 12:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys

[1782/01/19 01:14:07 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin

[1782/01/19 01:14:07 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat

[1782/01/19 01:14:07 | 000,468,462 | ---- | C] () -- C:\WINDOWS\System32\perfh016.dat

[1782/01/19 01:14:07 | 000,432,492 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat

[1782/01/19 01:14:07 | 000,301,776 | ---- | C] () -- C:\WINDOWS\System32\perfi016.dat

[1782/01/19 01:14:07 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat

[1782/01/19 01:14:07 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat

[1782/01/19 01:14:07 | 000,079,240 | ---- | C] () -- C:\WINDOWS\System32\perfc016.dat

[1782/01/19 01:14:07 | 000,067,448 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat

[1782/01/19 01:14:07 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin

[1782/01/19 01:14:07 | 000,035,178 | ---- | C] () -- C:\WINDOWS\System32\perfd016.dat

[1782/01/19 01:14:07 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat

[1782/01/19 01:14:07 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat

[1782/01/19 01:14:07 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

 

========== LOP Check ==========

 

[2010/11/14 23:08:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Bandoo

[2010/11/10 20:16:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Alwil Software

[2011/01/03 11:47:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\ashampoo

[2010/01/14 12:38:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\BVRP Software

[2009/10/22 18:06:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\DVDXStudio(2)

[2010/01/07 20:16:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\EPSON

[2011/07/10 00:59:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin

[2010/12/11 18:35:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\MAGIX

[2011/08/26 00:46:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\MyHeritage

[2011/09/05 19:06:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Pinnacle

[2011/09/05 19:15:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Pinnacle VideoSpin

[2011/07/15 14:04:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Tarma Installer

[2010/12/01 16:34:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP

[2010/09/15 23:24:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\vsosdk

[2011/07/14 21:01:32 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}

[2009/10/01 08:30:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Any Video Converter

[2011/01/03 11:49:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Ashampoo

[2011/11/15 15:04:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Audacity

[2011/01/25 16:44:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Bluefive software

[2009/08/18 20:52:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\BrOffice.org

[2010/12/08 17:05:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\BSplayer

[2010/12/08 17:05:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\BSplayer Pro

[2011/07/30 13:16:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\DVDVideoSoft

[2011/03/25 17:46:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\DVDVideoSoftIEHelpers

[2009/10/27 19:30:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Elaborate Bytes

[2010/09/12 20:31:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\EPSON

[2010/03/03 00:11:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\FreeAudioPack

[2011/04/02 15:36:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\iSpring Solutions

[2009/09/24 13:52:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Jasc

[2010/12/11 18:55:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\MAGIX

[2009/09/18 00:05:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Megaupload

[2011/08/26 00:42:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\MyHeritage

[2011/08/11 13:44:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\OpenCandy

[2011/02/04 20:44:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Passware

[2010/01/03 11:36:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\PhotoFiltre

[2010/09/23 21:37:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\PhotoFiltre Studio X

[2010/11/18 09:34:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\PriceGong

[2010/12/18 19:10:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Research In Motion

[2010/01/01 13:33:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\RipIt4Me

[2011/07/13 19:22:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Samsung

[2011/08/26 00:39:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\The Complete Genealogy Reporter - FTB

[2011/07/15 14:15:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Uniblue

[2011/02/08 12:41:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\uTorrent

[2011/11/05 12:57:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Vso

[2010/08/15 02:51:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\WinAVI

[2011/04/02 20:06:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Andreia\Dados de aplicativos\Xilisoft

[2010/11/14 23:32:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zeca Feliz\Dados de aplicativos\Bandoo

[2010/11/14 23:33:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zeca Feliz\Dados de aplicativos\PriceGong

[2010/12/27 23:30:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Zeca Feliz\Dados de aplicativos\Research In Motion

[2011/11/15 11:25:10 | 000,000,280 | ---- | M] () -- C:\WINDOWS\Tasks\DriverScanner.job

[2011/11/15 11:25:10 | 000,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\RegistryBooster.job

[2011/11/15 16:14:22 | 000,000,458 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{F1D47F1B-F51D-4555-8335-DF4591747F37}.job

 

========== Purity Check ==========

 

 

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 58 bytes -> C:\WINDOWS\System32\drivers:GbpKmAp.lst

@Alternate Data Stream - 2 bytes -> C:\WINDOWS\system32:A8363D97_Cef.gbp

@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:DFC5A2B2

 

< End of report >

 

 

 

OTL Extras logfile created on: 15/11/2011 21:07:39 - Run 1

OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Andreia\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy

 

895,17 Mb Total Physical Memory | 336,88 Mb Available Physical Memory | 37,63% Memory free

2,12 Gb Paging File | 1,48 Gb Available in Paging File | 69,79% Paging File free

Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas

Drive C: | 149,04 Gb Total Space | 26,82 Gb Free Space | 18,00% Space Free | Partition Type: NTFS

Drive E: | 7,81 Mb Total Space | 3,33 Mb Free Space | 42,60% Space Free | Partition Type: NTFS

 

Computer Name: CASA | User Name: Andreia | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

 

[HKEY_USERS\S-1-5-21-1935655697-854245398-725345543-1003\SOFTWARE\Classes\<extension>]

.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

 

========== Shell Spawning ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

exefile [open] -- "%1" %*

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:\Arquivos de programas\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Arquivos de programas\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Arquivos de programas\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

 

========== System Restore Settings ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]

"Start" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]

"Start" = 2

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

"DisableNotifications" = 0

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

 

========== Authorized Applications List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Arquivos de programas\DreaMule\emule.exe" = C:\Arquivos de programas\DreaMule\emule.exe:*:Disabled:Dreamule -- (http://www.dreamule.org)

"C:\Arquivos de programas\eMule\eMule.exe" = C:\Arquivos de programas\eMule\eMule.exe:*:Disabled:eMule Plus

"C:\Arquivos de programas\Arquivos comuns\Ahead\Nero Web\SetupX.exe" = C:\Arquivos de programas\Arquivos comuns\Ahead\Nero Web\SetupX.exe:*:Disabled:Nero ProductSetup -- (Nero AG)

"C:\Arquivos de programas\Java\jre6\bin\javaw.exe" = C:\Arquivos de programas\Java\jre6\bin\javaw.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)

"C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)

"C:\WINDOWS\system32\ftp.exe" = C:\WINDOWS\system32\ftp.exe:*:Disabled:Programa de transferência de arquivos -- (Microsoft Corporation)

"C:\avira_antivir_personal_ptbr.exe" = C:\avira_antivir_personal_ptbr.exe:*:Enabled:avira_antivir_personal_ptbr

"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)

"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Console de gerenciamento Microsoft -- (Microsoft Corporation)

"C:\Arquivos de programas\uTorrent\uTorrent.exe" = C:\Arquivos de programas\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)

"C:\Arquivos de programas\Outlook Express\msimn.exe" = C:\Arquivos de programas\Outlook Express\msimn.exe:*:Enabled:Outlook Express -- (Microsoft Corporation)

"C:\Arquivos de programas\Alwil Software\Avast5\AvastUI.exe" = C:\Arquivos de programas\Alwil Software\Avast5\AvastUI.exe:*:Enabled:avast! Free Antivirus -- (AVAST Software)

"C:\Arquivos de programas\Mozilla Firefox\firefox.exe" = C:\Arquivos de programas\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox -- (Mozilla Corporation)

"C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" = C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware -- (Malwarebytes Corporation)

"C:\WINDOWS\amcap.exe" = C:\WINDOWS\amcap.exe:*:Enabled:AMCap -- (Microsoft Corporation)

"C:\Arquivos de programas\DsNET Corp\aTube Catcher 2.0\yct.exe" = C:\Arquivos de programas\DsNET Corp\aTube Catcher 2.0\yct.exe:*:Enabled:aTube Catcher to download and convert videos. -- (DsNET)

"C:\PROGRAMAS_pcPai\Programs\RM.exe" = C:\PROGRAMAS_pcPai\Programs\RM.exe:*:Enabled:Render Manager -- (Pinnacle Systems)

"C:\PROGRAMAS_pcPai\Programs\umi.exe" = C:\PROGRAMAS_pcPai\Programs\umi.exe:*:Enabled:umi -- (Pinnacle Systems)

"C:\PROGRAMAS_pcPai\Programs\VideoSpin.exe" = C:\PROGRAMAS_pcPai\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin -- (Pinnacle Systems)

"C:\Arquivos de programas\Arquivos comuns\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Arquivos de programas\Arquivos comuns\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)

"C:\Arquivos de programas\Google\Google Earth\client\googleearth.exe" = C:\Arquivos de programas\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)

 

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{0609D0AF-1382-42BE-81DB-CF30F8B0F6E2}" = Serif PhotoPlus 6.0

"{0FFEA8EE-7BC7-4C9D-8CC6-5B8C891BA3F2}" = Windows Live Essentials

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live

"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT

"{25B535F5-8E56-4F9E-981E-83AC2EDE7DCA}" = ENLTV

"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java 6 Update 17

"{2DF215E0-BD3C-4C98-8616-AFEF09747285}" = Windows Live Sync

"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform

"{3315B802-84C6-47BC-907A-9B77A4646197}_is1" = SWF to AVI 1.7.1

"{350C9416-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager

"{41BB38A4-ED84-4682-8329-042FEBD8C30B}" = Mega Manager

"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis

"{51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}" = Assistente de Conexão do Windows Live

"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml

"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3

"{590035D9-BFA0-406A-A7F0-479C72C0DDB2}" = Windows Live Call

"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth

"{66EBD70F-A42C-475F-AEDF-277378151046}" = Nero 7 Essentials

"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Suporte para Aplicativos Apple

"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable

"{74AD1846-2010-4FB1-8E24-B6F2B87150C2}" = Windows Live Mail

"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD 3.2.4.82

"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update

"{87A9C015-C2BA-44EE-9C20-6E1A764B8E23}" = Windows Live Galeria de Fotos

"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers 1.10.01

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update

"{90AB0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint 2003 Template Pack 1

"{90AC0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint 2003 Template Pack 2

"{90AD0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint 2003 Template Pack 3

"{91110416-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional

"{91B2D706-5320-4AC0-9B9E-66E297E34EE0}" = Samsung PC Studio 3

"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{9555B4ED-09A3-4722-8E8C-57A49401D059}" = Windows Live Writer

"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6

"{962A241C-3405-4680-B3E1-F34EA7B989E5}" = iSpring Free 5

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9ADC3E4F-34DA-48CD-8727-BB26D90257BD}" = Windows Live Messenger

"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI

"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2

"{A4A14B15-F25D-44F8-8483-291C1DF7C548}_is1" = WAV MP3 Converter v4.3 build 1287

"{A66DBCC6-8802-3D15-9FDF-9552742C08B0}" = Google Talk Plugin

"{A7E19604-93AF-4611-8C9F-CE509C2B286E}_is1" = VDownloader 2.8.387

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{AC76BA86-7AD7-1046-7B44-A94000000001}" = Adobe Reader 9.4.6 - Português

"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint

"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2

"{C26D7EF1-A5AD-4B46-9F49-535E9255A669}" = BlackBerry Desktop Software 4.7

"{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1" = Uniblue DriverScanner

"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3

"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime

"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1

"{D1F94690-C59F-4BF1-A9C5-001DCCE8364D}_is1" = X2X Free Audio Converter 3.1

"{ECD03DA7-5952-406A-8156-5F0C93618D1F}" = USB PC Camera

"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard

"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver

"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0

"{F60B8CC3-561F-47BE-B1F9-8F208617B830}" = ENLTV Driver Setup

"{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}" = Pinnacle VideoSpin

"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

"0EE3AC5002FEB7039D326B15866A23084073CB72" = Pacote de Driver do Windows - Active Development Co., Ltd. (3xHybrid) MEDIA (01/28/2007 1.3.3.2)

"600x1200 V7" = 600x1200 V7

"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Pacote de Driver do Windows - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)

"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Pacote de Driver do Windows - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)

"Adobe Acrobat Reader 3.01" = Adobe Acrobat Reader 3.01

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin

"AnalogX Vocal Remover" = AnalogX Vocal Remover

"AnalogX Vocal Remover (WinAmp)" = AnalogX Vocal Remover (WinAmp)

"AnyDVD" = AnyDVD

"Ashampoo Burning Studio 9_is1" = Ashampoo Burning Studio 9.21

"aTube Catcher" = aTube Catcher

"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)

"Audio Video To WMA Converter_is1" = Audio Video To WMA Converter version 1.3

"avast" = avast! Free Antivirus

"BlackBerry_{C26D7EF1-A5AD-4B46-9F49-535E9255A669}" = BlackBerry Desktop Software 4.7

"BSPlayerf" = BS.Player FREE

"CloneCD" = CloneCD

"CloneDVD2" = CloneDVD2

"CNXT_MODEM_PCI_VEN_14F1&DEV_2F30&SUBSYS_205514F1" = PCI SoftV92 Modem

"DreaMule_is1" = DreaMule 3.2

"DVD Decrypter" = DVD Decrypter (Remove Only)

"DVD Flick_is1" = DVD Flick

"DVD Shrink_is1" = DVD Shrink 3.2

"E.M. PowerPoint Video Converter_is1" = E.M. PowerPoint Video Converter 2.71

"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 4.0 Home Edition

"Easy-WebPrint" = Easy-WebPrint

"EPSON Printer and Utilities" = Software para Impressoras EPSON

"EPSON Scanner" = EPSON Scan

"ESET Online Scanner" = ESET Online Scanner v3

"Family Tree Builder" = MyHeritage Family Tree Builder

"FMCODEC" = FM Screen Capture Codec (Remove Only)

"Free 3GP Video Converter_is1" = Free 3GP Video Converter version 3.5

"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4

"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 1.9

"Free Studio_is1" = Free Studio version 5.0.8

"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.8

"GIF Optimizer_is1" = GIF Optimizer 1.0

"ie8" = Windows Internet Explorer 8

"Imikimi Plugin" = Imikimi Plugin

"IRPF2010 - Declaração de Ajuste Anual e Final de Espólio" = IRPF2010 - Declaração de Ajuste Anual e Final de Espólio

"IRPF2011" = IRPF2011 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva do País

"iWisoft Flash SWF to Video Converter_is1" = iWisoft Flash SWF to Video Converter 3.4

"LAME for Audacity_is1" = LAME v3.98.2 for Audacity

"MAGIX Slideshow Maker US" = MAGIX Slideshow Maker 1.0.1.3 (US)

"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware

"MGI_PHOTOSUITE_SE_V10" = MGI PhotoSuite SE

"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1

"Mozilla Firefox (3.6.23)" = Mozilla Firefox (3.6.23)

"Music Editor Free" = Music Editor Free

"NVIDIA Drivers" = NVIDIA Drivers

"PIXresizer_is1" = PIXresizer 2.0.3

"Receitanet Java 2010.02b" = Receitanet Java 2010.02b

"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software

"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set

"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software

"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software

"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software

"Silent Package Run-Time Sample" = EPSON Reference Guide

"Spyware Doctor" = Spyware Doctor 6.0

"SubtitleWorkshop" = Subtitle Workshop 2.51

"TextBridge Pro 8.0" = TextBridge Pro 8.0

"Uniblue RegistryBooster" = Uniblue RegistryBooster

"Uninstall_is1" = Uninstall 1.0.0.1

"uTorrent" = µTorrent

"WIC" = Windows Imaging Component

"Winamp" = Winamp

"WinAVI Video Converter 10.5_is1" = WinAVI Video Converter

"Windows Media Format Runtime" = Windows Media Format 11 runtime

"WinLiveSuite_Wave3" = Windows Live Essentials

"WinPcapInst" = WinPcap 4.1.2

"WMFDist11" = Windows Media Format 11 runtime

"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

 

========== HKEY_USERS Uninstall List ==========

 

[HKEY_USERS\S-1-5-21-1935655697-854245398-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Google Chrome" = Google Chrome

"PhotoFiltre" = PhotoFiltre

"PhotoFiltre Studio X" = PhotoFiltre Studio X

"Winamp Detect" = Winamp Detectar Aplicação

 

========== Last 10 Event Log Errors ==========

 

[ Antivirus Events ]

Error - 6/10/2010 16:08:32 | Computer Name = CASA | Source = avast! | ID = 33554522

Description =

 

Error - 10/11/2010 15:11:27 | Computer Name = CASA | Source = avast! | ID = 33554522

Description =

 

Error - 10/11/2010 15:11:27 | Computer Name = CASA | Source = avast! | ID = 33554522

Description =

 

Error - 10/11/2010 15:11:28 | Computer Name = CASA | Source = avast! | ID = 33554522

Description =

 

Error - 10/11/2010 15:11:28 | Computer Name = CASA | Source = avast! | ID = 33554522

Description =

 

Error - 10/11/2010 15:11:35 | Computer Name = CASA | Source = avast! | ID = 33554522

Description =

 

Error - 10/11/2010 15:11:36 | Computer Name = CASA | Source = avast! | ID = 33554522

Description =

 

Error - 10/11/2010 15:11:36 | Computer Name = CASA | Source = avast! | ID = 33554522

Description =

 

Error - 10/11/2010 15:11:36 | Computer Name = CASA | Source = avast! | ID = 33554522

Description =

 

Error - 10/11/2010 15:11:38 | Computer Name = CASA | Source = avast! | ID = 33554522

Description =

 

[ Application Events ]

Error - 11/11/2011 16:07:24 | Computer Name = CASA | Source = Application Error | ID = 1001

Description = Falha no compartimento de memória 778305547.

 

Error - 13/11/2011 12:20:57 | Computer Name = CASA | Source = Application Error | ID = 1000

Description = Aplicativo com falha explorer.exe, versão 6.0.2900.2180, módulo com

falha fun_avcodec.dll, versão 0.0.0.0, endereço com falha 0x0000301a.

 

Error - 13/11/2011 13:11:35 | Computer Name = CASA | Source = Application Error | ID = 1000

Description = Aplicativo com falha explorer.exe, versão 6.0.2900.2180, módulo com

falha fun_avcodec.dll, versão 0.0.0.0, endereço com falha 0x0000301a.

 

Error - 15/11/2011 16:39:22 | Computer Name = CASA | Source = Microsoft Office 10 | ID = 1000

Description = Faulting application powerpnt.exe, version 10.0.6858.0, faulting module

powerpnt.exe, version 10.0.6858.0, fault address 0x0019b12d.

 

Error - 15/11/2011 16:40:15 | Computer Name = CASA | Source = Microsoft Office 10 | ID = 2001

Description = Rejected Safe Mode action : Microsoft PowerPoint.

 

Error - 15/11/2011 17:44:56 | Computer Name = CASA | Source = MsiInstaller | ID = 11402

Description = Product: Iminent -- Error 1402. Could not open key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

System error 1450. Verify that you have sufficient access to that key, or contact

your support personnel.

 

Error - 15/11/2011 17:53:37 | Computer Name = CASA | Source = MsiInstaller | ID = 11402

Description = Product: Iminent -- Error 1402. Could not open key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

System error 1450. Verify that you have sufficient access to that key, or contact

your support personnel.

 

Error - 15/11/2011 18:19:05 | Computer Name = CASA | Source = Application Error | ID = 1000

Description = Aplicativo com falha pptvideo.exe, versão 2.7.9.1226, módulo com falha

pptvideo.exe, versão 2.7.9.1226, endereço com falha 0x0001ae44.

 

Error - 15/11/2011 18:19:56 | Computer Name = CASA | Source = Application Error | ID = 1001

Description = Falha no compartimento de memória 1629118660.

 

Error - 15/11/2011 18:23:06 | Computer Name = CASA | Source = Application Error | ID = 1000

Description = Aplicativo com falha pptvideo.exe, versão 2.7.9.1226, módulo com falha

pptvideo.exe, versão 2.7.9.1226, endereço com falha 0x0001ae44.

 

[ Application Events ]

Error - 11/11/2011 16:07:24 | Computer Name = CASA | Source = Application Error | ID = 1001

Description = Falha no compartimento de memória 778305547.

 

Error - 13/11/2011 12:20:57 | Computer Name = CASA | Source = Application Error | ID = 1000

Description = Aplicativo com falha explorer.exe, versão 6.0.2900.2180, módulo com

falha fun_avcodec.dll, versão 0.0.0.0, endereço com falha 0x0000301a.

 

Error - 13/11/2011 13:11:35 | Computer Name = CASA | Source = Application Error | ID = 1000

Description = Aplicativo com falha explorer.exe, versão 6.0.2900.2180, módulo com

falha fun_avcodec.dll, versão 0.0.0.0, endereço com falha 0x0000301a.

 

Error - 15/11/2011 16:39:22 | Computer Name = CASA | Source = Microsoft Office 10 | ID = 1000

Description = Faulting application powerpnt.exe, version 10.0.6858.0, faulting module

powerpnt.exe, version 10.0.6858.0, fault address 0x0019b12d.

 

Error - 15/11/2011 16:40:15 | Computer Name = CASA | Source = Microsoft Office 10 | ID = 2001

Description = Rejected Safe Mode action : Microsoft PowerPoint.

 

Error - 15/11/2011 17:44:56 | Computer Name = CASA | Source = MsiInstaller | ID = 11402

Description = Product: Iminent -- Error 1402. Could not open key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

System error 1450. Verify that you have sufficient access to that key, or contact

your support personnel.

 

Error - 15/11/2011 17:53:37 | Computer Name = CASA | Source = MsiInstaller | ID = 11402

Description = Product: Iminent -- Error 1402. Could not open key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.

System error 1450. Verify that you have sufficient access to that key, or contact

your support personnel.

 

Error - 15/11/2011 18:19:05 | Computer Name = CASA | Source = Application Error | ID = 1000

Description = Aplicativo com falha pptvideo.exe, versão 2.7.9.1226, módulo com falha

pptvideo.exe, versão 2.7.9.1226, endereço com falha 0x0001ae44.

 

Error - 15/11/2011 18:19:56 | Computer Name = CASA | Source = Application Error | ID = 1001

Description = Falha no compartimento de memória 1629118660.

 

Error - 15/11/2011 18:23:06 | Computer Name = CASA | Source = Application Error | ID = 1000

Description = Aplicativo com falha pptvideo.exe, versão 2.7.9.1226, módulo com falha

pptvideo.exe, versão 2.7.9.1226, endereço com falha 0x0001ae44.

 

[ System Events ]

Error - 14/11/2011 10:12:33 | Computer Name = CASA | Source = DCOM | ID = 10005

Description = Erro "%1058" no DCOM na tentativa de iniciar o serviço NMIndexingService

com argumentos "" para iniciar o servidor: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

 

Error - 14/11/2011 10:12:45 | Computer Name = CASA | Source = DCOM | ID = 10005

Description = Erro "%1058" no DCOM na tentativa de iniciar o serviço NMIndexingService

com argumentos "" para iniciar o servidor: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

 

Error - 14/11/2011 10:12:49 | Computer Name = CASA | Source = DCOM | ID = 10005

Description = Erro "%1058" no DCOM na tentativa de iniciar o serviço NMIndexingService

com argumentos "" para iniciar o servidor: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

 

Error - 15/11/2011 09:22:38 | Computer Name = CASA | Source = Service Control Manager | ID = 7000

Description = Não foi possível iniciar o serviço SAA7130 TV Card devido ao seguinte

erro: %%1058

 

Error - 15/11/2011 09:22:38 | Computer Name = CASA | Source = Service Control Manager | ID = 7000

Description = Não foi possível iniciar o serviço TCP Half Open Limited Patcher (

TCP-Z) devido ao seguinte erro: %%2

 

Error - 15/11/2011 09:22:50 | Computer Name = CASA | Source = sr | ID = 1

Description = O filtro da restauração do sistema encontrou o erro inesperado '0xC0000001'

ao processar o arquivo '' no volume 'HarddiskVolume1'. O monitoramento do volume

foi interrompido.

 

Error - 15/11/2011 09:25:37 | Computer Name = CASA | Source = DCOM | ID = 10005

Description = Erro "%1058" no DCOM na tentativa de iniciar o serviço NMIndexingService

com argumentos "" para iniciar o servidor: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

 

Error - 15/11/2011 09:25:48 | Computer Name = CASA | Source = DCOM | ID = 10005

Description = Erro "%1058" no DCOM na tentativa de iniciar o serviço NMIndexingService

com argumentos "" para iniciar o servidor: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

 

Error - 15/11/2011 09:25:52 | Computer Name = CASA | Source = DCOM | ID = 10005

Description = Erro "%1058" no DCOM na tentativa de iniciar o serviço NMIndexingService

com argumentos "" para iniciar o servidor: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

 

Error - 15/11/2011 09:30:23 | Computer Name = CASA | Source = ipnathlp | ID = 30013

Description = O alocador DHCP se desativou no endereço IP 192.168.1.5, porque o endereço

IP está fora do escopo 192.168.0.0/255.255.255.0, do qual os endereços estão sendo

alocados para clientes DHCP. Para ativar o alocador DHCP neste endereço IP, altere

o escopo para incluir o endereço IP ou altere o endereço IP para que ele se encaixe

no escopo.

 

 

< End of report >

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Execute o OTL e clique [Limpeza] > [OK]

*O PC será reiniciado

 

2.

*Delete o SecurityCheck

 

3.

*Execute o Malwarebytes, clique [Atualização] > [baixar Atualizações]

*Na aba [Verificação], selecione Verificação completa

*Clique [Verificar] e selecione a partição onde o Windows está instalado

*Ao término, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados]

*Cole o relatório apresentado

 

4.

*Baixe o AD-Remover e salve-o no desktop

 

*Execute-o, clique [Clean] > [sim] > [OK] > [sim]. O PC poderá ser reiniciado para a completa limpeza.

*Cole o relatório C:\Ad-Report-CLEAN[1].txt

 

5.

*Baixe o USBFix e salve-o no desktop

 

*Conecte o pen drive no PC, execute o USBFix e clique [Pesquisa]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

Abaixo os Logs (3) Solicitados.

 

Malwarebytes' Anti-Malware 1.51.2.1300

www.malwarebytes.org

 

Versão da Base de Dados: 8193

 

Windows 5.1.2600 Service Pack 2

Internet Explorer 8.0.6001.18702

 

19/11/2011 15:18:46

mbam-log-2011-11-19 (15-18-46).txt

 

Tipo de Verificação: Verificação Completa (C:\|E:\|)

Objetos escaneados: 399310

Tempo decorrido: 2 hora(s), 5 minuto(s), 2 segundo(s)

 

Processos de Memória Infectados: 0

Módulos de Memória Infectados: 0

Chaves de Registro Infectadas: 0

Valores de Registro Infectados: 1

Itens de Dados no Registro Infectados: 0

Pastas Infectadas: 0

Arquivos Infectados: 2

 

Processos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Infectadas:

(Não foram detectados ítens maliciosos)

 

Valores de Registro Infectados:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\qQ (Trojan.Clicker) -> Value: qQ -> Quarantined and deleted successfully.

 

Itens de Dados no Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Pastas Infectadas:

(Não foram detectados ítens maliciosos)

 

Arquivos Infectados:

c:\arquivos de programas\vdownloader\vdownloader.exe (VirTool.DelfInject) -> Quarantined and deleted successfully.

c:\documents and settings\all users\Desktop\mp3 downloader.lnk (Rogue.Link) -> Quarantined and deleted successfully.

 

 

 

 

 

======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 =======

 

Updated by TeamXscript on 12/04/11

Contact: AdRemover[DOT]contact[AT]gmail[DOT]com

website: http://www.teamxscript.org

 

C:\Arquivos de programas\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 15:31:28 on 19/11/2011, Normal boot

 

Microsoft Windows XP Professional Service Pack 2 (X86)

Andreia@CASA ( )

 

============== ACTION(S) ==============

 

 

File deleted: C:\Arquivos de programas\Mozilla FireFox\searchplugins\SearchquWebSearch.xml

Folder deleted: C:\Arquivos de programas\Windows Searchqu Toolbar

File deleted: C:\WINDOWS\system32\ConduitEngine.tmp

File deleted: C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\FireFox\Profiles\5y1o11k1.default\searchplugins\askcom.xml

Folder deleted: C:\Arquivos de programas\Ask.com

Folder deleted: C:\Documents and Settings\Administrador\Dados de aplicativos\Bandoo

Folder deleted: C:\Documents and Settings\Zeca Feliz\Dados de aplicativos\Bandoo

Folder deleted: C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Conduit

Folder deleted: C:\Documents and Settings\Andreia\Dados de aplicativos\OpenCandy

Folder deleted: C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\OpenCandy

Folder deleted: C:\Documents and Settings\Andreia\Dados de aplicativos\PriceGong

Folder deleted: C:\Documents and Settings\Zeca Feliz\Dados de aplicativos\PriceGong

 

(!) -- Temporary files deleted.

 

 

Key deleted: HKLM\Software\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E}

Key deleted: HKLM\Software\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644}

Key deleted: HKLM\Software\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C}

Key deleted: HKLM\Software\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C}

Key deleted: HKLM\Software\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB}

Key deleted: HKLM\Software\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}

Key deleted: HKLM\Software\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}

Key deleted: HKLM\Software\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}

Key deleted: HKLM\Software\Classes\BandooCore.BandooCore

Key deleted: HKLM\Software\Classes\BandooCore.BandooCore.1

Key deleted: HKLM\Software\Classes\BandooCore.ResourcesMngr

Key deleted: HKLM\Software\Classes\BandooCore.ResourcesMngr.1

Key deleted: HKLM\Software\Classes\BandooCore.SettingsMngr

Key deleted: HKLM\Software\Classes\BandooCore.SettingsMngr.1

Key deleted: HKLM\Software\Classes\BandooCore.StatisticMngr

Key deleted: HKLM\Software\Classes\BandooCore.StatisticMngr.1

Key deleted: HKLM\Software\Classes\Conduit.Engine

Key deleted: HKLM\Software\Classes\Toolbar.CT2552374

Key deleted: HKLM\Software\Classes\Toolbar.CT2642715

Key deleted: HKLM\Software\Classes\Toolbar.CT2737658

Key deleted: HKLM\Software\Classes\Toolbar.CT2956691

Key deleted: HKLM\Software\Classes\AppID\BandooCore.EXE

Key deleted: HKLM\Software\bandoo

Key deleted: HKLM\Software\Conduit

Key deleted: HKLM\Software\DataMngr

Key deleted: HKCU\Software\Conduit

Key deleted: HKCU\Software\DataMngr

Key deleted: HKCU\Software\PriceGong

Key deleted: HKCU\Software\Toolbar

Key deleted: HKLM\Software\aTube Catcher\OpenCandy

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Bandoo

Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}

Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA74C8}

Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}

Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4e1d-BDD0-1E9C9B7799CC}

Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7f000001-db8e-f89c-2fec-49bf726f8c12}

Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}

Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4fde-B055-AE7B0F4CF080}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}

 

Value deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|InstantAccess

Value deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}

 

 

============== ADDITIONNAL SCAN ==============

 

**** Mozilla Firefox Version [3.6.23 (pt-BR)] ****

 

Plugins\npkimi.dll ( )

Plugins\npwachk.dll (Nullsoft, Inc.)

HKLM_MozillaPlugins\Adobe Reader (x)

Searchplugins\adawaretb.xml ( hxxp://www.google.com/search)

Searchplugins\buscape.xml (hxxp://busca.buscape.com.br/cprocura)

Searchplugins\mercadolivre.xml (hxxp://pmstrk.mercadolivre.com.br/jm/PmsTrk)

Searchplugins\wikipedia-br.xml (hxxp://pt.wikipedia.org/wiki/Especial:Busca)

Searchplugins\yahoo-br.xml (hxxp://br.search.yahoo.com/search)

 

-- C:\Documents and Settings\Andreia\Dados de aplicativos\Mozilla\FireFox\Profiles\5y1o11k1.default --

Extensions\plugin@yontoo.com (Yontoo Layers)

Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} (DVDVideoSoftTB Toolbar)

Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} (DVDVideoSoft Menu)

Prefs.js - browser.search.selectedEngine, Google

Prefs.js - browser.startup.homepage, hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:pt-BR:official

Prefs.js - browser.startup.homepage_override.mstone, rv:1.8.0.6

 

-- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\FireFox\Profiles\sr4i8kjw.default --

Prefs.js - browser.search.defaultenginename, Search the Web

Prefs.js - browser.search.selectedEngine, Search the Web

Prefs.js - browser.startup.homepage, hxxp://www.google.com/

 

-- C:\Documents and Settings\Zeca Feliz\Dados de aplicativos\Mozilla\FireFox\Profiles\n3yq67wq.default --

Prefs.js - browser.search.defaultenginename, Search the Web

Prefs.js - browser.search.selectedEngine, Search the Web

Prefs.js - browser.startup.homepage, hxxp://www.google.com/

 

========================================

 

**** Google Chrome Version [15.0.874.121] ****

 

Extension\eijoglodfkeicibboibphapnoahoaapi (C:\DOCUME~1\Andreia\CONFIG~1\Temp\eijoglodfkeicibboibphapnoahoaapi.crx) (x)

Extension\icmlaeflemplmjndnaapfdbbnpncnbda (C:\Arquivos de programas\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx) (?)

Extension - jfmjfhklogoienhpfnppmbcbjfjnkonk (x)

Extension\niapdbllcanepiiimjjndipklodoedlc (C:\DOCUME~1\Andreia\CONFIG~1\Temp\YontooLayers.crx) (x)

 

-- C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default --

Preferences - default_search_provider: "Google" (Enabled: true) (hxxp://www.google.com/search?q={searchTerms}&ie=utf-8&oe=utf-8&aq=t)

Preferences - homepage: hxxps://www.facebook.com/zecafeliz

Preferences - homepage_is_newtabpage: false

Plugin - Remoting Viewer (Enabled: true) (internal-remoting-viewer) (x)

Plugin - Native Client (Enabled: true) (C:\Documents and Settings\Andreia\Configura\u00E7\u00F5es locais\Dados de aplicativos\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll) (x)

Plugin - "Java" (Enabled: true)

Plugin - "Remoting Viewer" (Enabled: true)

Plugin - "Native Client" (Enabled: true)

Plugin - "Imikimi.com Plugin" (Enabled: true)

Plugin - "Winamp Application Detector" (Enabled: true)

Preferences - urls_to_restore_on_startup: hxxp://search.conduit.com/?ctid=ct2956691&SearchSource=48

 

========================================

 

**** Internet Explorer Version [8.0.6001.18702] ****

 

HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896

HKCU_Main|Start Page - hxxp://fr.msn.com/

HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896

HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm

HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKLM_Main|Start Page - hxxp://fr.msn.com/

HKLM_Toolbar|{327C2873-E90D-4c37-AA9D-10AC9BABA46C} (C:\Arquivos de programas\Canon\Easy-WebPrint\Toolband.dll)

HKLM_Toolbar|{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} (C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll)

HKLM_ElevationPolicy\29d0a7a7-2f39-4de9-a31c-2f0bb709d178 - C:\Arquivos de programas\Softonic_Brasil\Softonic_BrasilToolbarHelper.exe (x)

HKLM_ElevationPolicy\6272422d-b898-4bb4-a74f-299f2637b546 - C:\Arquivos de programas\Softonic_Brasil\Softonic_BrasilToolbarHelper.exe (x)

HKLM_ElevationPolicy\cb6a8b68-0cdd-4bdd-a414-81eb6fea0f7d - C:\Arquivos de programas\Softonic_Brasil\Softonic_BrasilToolbarHelper.exe (x)

HKLM_ElevationPolicy\cba6e21e-cd99-4827-8151-c7c9d27dd425 - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\FreeOnlineRadioPlayerRecorderToolbarHelper.exe (x)

HKLM_ElevationPolicy\{ba20b5da-0f48-40c5-b8c9-2cda4ecf75c2} - C:\Arquivos de programas\Toolbar Cleaner\ToolbarCleaner.exe (Visicom Media Inc.)

HKLM_Extensions\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - "?" (?)

BHO\{2E3C3651-B19C-4DD9-A979-901EC3E930AF} - "ssh2 Class" (C:\Arquivos de programas\Scpad\scpsssh2.dll)

BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)

BHO\{68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - "EWPBrowseObject Class" (C:\Arquivos de programas\Canon\Easy-WebPrint\EWPBrowseLoader.dll)

BHO\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - "avast! WebRep" (C:\Arquivos de programas\Alwil Software\Avast5\aswWebRepIE.dll)

BHO\{9030D464-4C02-4ABF-8ECC-5164760863C6} - "Auxiliar de Conexão do Windows Live" (C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll)

BHO\{bf00e119-21a3-4fd1-b178-3b8537e75c92} - "IeMonitorBho Class" (C:\Arquivos de programas\Megaupload\Mega Manager\MegaIEMn.dll)

BHO\{C41A1C0E-EA6C-11D4-B1B8-444553540003} - "GbIehObj Class" (C:\ARQUIV~1\GbPlugin\gbiehcef.dll)

BHO\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - "Yontoo Layers" (C:\Arquivos de programas\Yontoo Layers\YontooIEClient.dll)

 

========================================

 

C:\Arquivos de programas\Ad-Remover\Quarantine: 119 File(s)

C:\Arquivos de programas\Ad-Remover\Backup: 12 File(s)

 

C:\Ad-Report-CLEAN[1].txt - 19/11/2011 15:32:08 (9446 Byte(s))

 

End at: 15:33:33, 19/11/2011

 

============== E.O.F ==============

 

 

 

 

 

############################## | UsbFix V 7.068 | [Pesquisa]

 

Usuário: Andreia (Administrador) # CASA

Atualizado em 15/11/2011 por El Desaparecido

Começou em 15:41:53 | 19/11/2011

 

Site: http://eldesaparecido.com

Arquivo suspeito ? : http://eldesaparecido.com/support.php

Contato: contact@eldesaparecido.com

 

PC: To Be Filled By O.E.M. (To Be Filled By O.E.M.) (X86-based PC) # Desktop Computer

CPU: Processador Intel Pentium II (1800)

RAM -> [ Total : 895 | Free : 140 ]

BIOS: BIOS Ver. L0.03

BOOT: Normal boot

 

OS: Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 2

WB: Windows Internet Explorer 8.0.6001.18702

 

SC: Security Center Service [ Enabled ]

WU: Windows Update Service [ Enabled ]

FW: Windows FireWall Service [ Enabled ]

 

C:\ (%systemdrive%) -> Disco fixo # 149 Gb (26 Mb livre - 18%) [] # NTFS

D:\ -> CD-ROM

E:\ -> Disco fixo # 8 Mb (3 Mb livre - 43%) [MiNino] # NTFS

F:\ -> Disco removível # 15 Gb (12 Mb livre - 83%) [KINGSTON] # FAT32

 

################## | Processos Ativos |

 

C:\WINDOWS\System32\smss.exe (672)

C:\WINDOWS\system32\csrss.exe (724)

C:\WINDOWS\system32\winlogon.exe (748)

C:\WINDOWS\system32\services.exe (792)

C:\WINDOWS\system32\lsass.exe (804)

C:\ARQUIV~1\GbPlugin\GbpSv.exe (964)

C:\WINDOWS\system32\svchost.exe (1096)

C:\WINDOWS\system32\svchost.exe (1144)

C:\WINDOWS\System32\svchost.exe (1232)

C:\WINDOWS\system32\svchost.exe (1312)

C:\WINDOWS\system32\svchost.exe (1400)

C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe (1544)

C:\WINDOWS\Explorer.EXE (1960)

C:\WINDOWS\system32\spoolsv.exe (1988)

C:\WINDOWS\system32\svchost.exe (576)

C:\WINDOWS\system32\RUNDLL32.EXE (600)

C:\WINDOWS\RTHDCPL.EXE (976)

C:\Arquivos de programas\Arquivos comuns\Research In Motion\Auto Update\RIMAutoUpdate.exe (1072)

C:\WINDOWS\CameraFixer.exe (1204)

C:\WINDOWS\tsnpstd3.exe (1224)

C:\Arquivos de programas\Alwil Software\Avast5\avastUI.exe (1268)

C:\WINDOWS\twain_32\600x1200\Detector.exe (1280)

C:\WINDOWS\system32\ctfmon.exe (1352)

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (1556)

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe (1780)

C:\Arquivos de programas\Java\jre6\bin\jqs.exe (2116)

C:\WINDOWS\system32\nvsvc32.exe (2276)

C:\WINDOWS\system32\svchost.exe (2472)

C:\WINDOWS\System32\alg.exe (3816)

C:\WINDOWS\System32\svchost.exe (4088)

C:\WINDOWS\system32\wbem\wmiapsrv.exe (2516)

C:\UsbFix\UsbFix.exe (2636)

C:\WINDOWS\system32\wbem\wmiprvse.exe (2704)

C:\WINDOWS\system32\wbem\wmiprvse.exe (2868)

C:\WINDOWS\system32\wuauclt.exe (164)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (2060)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (1384)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (2468)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (2536)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (2452)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (2584)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (4012)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (2884)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (1796)

C:\WINDOWS\system32\wscntfy.exe (3996)

 

################## | Ficheiros # pastas infeciosos |

 

Presente ! C:\Documents and Settings\Andreia\Dados de aplicativos\inst.exe

 

################## | Registro |

 

 

################## | Mountpoints2 |

 

HKCU\.\.\.\.\Explorer\MountPoints2\{1340d0ae-6d9e-11de-89e0-ac3a2db22a9f}

Shell\AutoRun\Command = wscript.exe .\.vbs

Shell\open\Command = wscript.exe .\.vbs

 

HKCU\.\.\.\.\Explorer\MountPoints2\{6e7a9762-bfe8-11df-8c06-001966a5cb0e}

Shell\AutoRun\Command = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

 

 

 

################## | Vaccin |

 

(!) Este computador não é vacinada!

 

################## | E.O.F |

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Execute o AD-Remover e clique [uninstall] > [Não] > [Close]

*Delete a pasta C:\Arquivos de programas\Ad-Remover

*Delete o arquivo C:\Ad-Report-CLEAN[1].txt

 

2.

*Conecte novamente o pen drive

*Execute o UsbFix e clique [supressão]

*Ao finalizar, desconecte o pen drive e cole o relatório apresentado

 

 

Informe se foi resolvido

Compartilhar este post


Link para o post
Compartilhar em outros sites

Abaixo o log do Usb-Fix solicitado. Vou operar uns dias para informar se o problema está resolvido. Obrigado até agora.

 

 

############################## | UsbFix V 7.069 | [supressão]

 

Usuário: Andreia (Administrador) # CASA

Atualizado em 20/11/2011 por El Desaparecido

Começou em 15:24:24 | 25/11/2011

 

Site: http://eldesaparecido.com

Arquivo suspeito ? : http://eldesaparecido.com/support.php

Contato: contact@eldesaparecido.com

 

PC: To Be Filled By O.E.M. (To Be Filled By O.E.M.) (X86-based PC) # Desktop Computer

CPU: Processador Intel Pentium II (1800)

RAM -> [ Total : 895 | Free : 292 ]

BIOS: BIOS Ver. L0.03

BOOT: Normal boot

 

OS: Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 2

WB: Windows Internet Explorer 8.0.6001.18702

 

SC: Security Center Service [ Enabled ]

WU: Windows Update Service [ Enabled ]

FW: Windows FireWall Service [ Enabled ]

 

C:\ (%systemdrive%) -> Disco fixo # 149 Gb (26 Mb livre - 18%) [] # NTFS

D:\ -> CD-ROM

E:\ -> Disco fixo # 8 Mb (3 Mb livre - 43%) [MiNino] # NTFS

F:\ -> Disco removível # 15 Gb (12 Mb livre - 83%) [KINGSTON] # FAT32

 

################## | Processos Ativos |

 

C:\WINDOWS\System32\smss.exe (672)

C:\WINDOWS\system32\csrss.exe (724)

C:\WINDOWS\system32\winlogon.exe (748)

C:\WINDOWS\system32\services.exe (792)

C:\WINDOWS\system32\lsass.exe (804)

C:\ARQUIV~1\GbPlugin\GbpSv.exe (964)

C:\WINDOWS\system32\svchost.exe (1096)

C:\WINDOWS\system32\svchost.exe (1144)

C:\WINDOWS\System32\svchost.exe (1232)

C:\WINDOWS\system32\svchost.exe (1316)

C:\WINDOWS\system32\svchost.exe (1400)

C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe (1560)

C:\WINDOWS\system32\spoolsv.exe (1864)

C:\WINDOWS\system32\svchost.exe (1968)

C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe (180)

C:\Arquivos de programas\Java\jre6\bin\jqs.exe (192)

C:\WINDOWS\system32\nvsvc32.exe (272)

C:\WINDOWS\system32\svchost.exe (440)

C:\WINDOWS\System32\alg.exe (1516)

C:\WINDOWS\System32\svchost.exe (2384)

C:\WINDOWS\system32\wbem\wmiapsrv.exe (2784)

C:\WINDOWS\Explorer.EXE (3252)

C:\WINDOWS\system32\RUNDLL32.EXE (3804)

C:\WINDOWS\RTHDCPL.EXE (3908)

C:\Arquivos de programas\Arquivos comuns\Research In Motion\Auto Update\RIMAutoUpdate.exe (3960)

C:\WINDOWS\CameraFixer.exe (4036)

C:\WINDOWS\tsnpstd3.exe (4060)

C:\Arquivos de programas\Alwil Software\Avast5\avastUI.exe (4084)

C:\WINDOWS\twain_32\600x1200\Detector.exe (260)

C:\WINDOWS\vsnpstd3.exe (244)

C:\WINDOWS\system32\ctfmon.exe (912)

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (2204)

C:\WINDOWS\system32\wuauclt.exe (3940)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (1012)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (3304)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (3480)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (3916)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (1724)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (3512)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (3264)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (4072)

C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (2380)

C:\UsbFix\UsbFix.exe (3492)

C:\WINDOWS\system32\wbem\wmiprvse.exe (896)

 

################## | Processos parados |

 

Parado! C:\ARQUIV~1\GbPlugin\GbpSv.exe (964)

Parado! C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe (1560)

Parado! C:\WINDOWS\system32\spoolsv.exe (1864)

Parado! C:\Arquivos de programas\Nero\Nero 7\InCD\InCDsrv.exe (180)

Parado! C:\Arquivos de programas\Java\jre6\bin\jqs.exe (192)

Parado! C:\WINDOWS\system32\nvsvc32.exe (272)

Parado! C:\WINDOWS\System32\alg.exe (1516)

Parado! C:\WINDOWS\system32\wbem\wmiapsrv.exe (2784)

Parado! C:\WINDOWS\Explorer.EXE (3252)

Parado! C:\WINDOWS\system32\RUNDLL32.EXE (3804)

Parado! C:\WINDOWS\RTHDCPL.EXE (3908)

Parado! C:\Arquivos de programas\Arquivos comuns\Research In Motion\Auto Update\RIMAutoUpdate.exe (3960)

Parado! C:\WINDOWS\CameraFixer.exe (4036)

Parado! C:\WINDOWS\tsnpstd3.exe (4060)

Parado! C:\Arquivos de programas\Alwil Software\Avast5\avastUI.exe (4084)

Parado! C:\WINDOWS\twain_32\600x1200\Detector.exe (260)

Parado! C:\WINDOWS\vsnpstd3.exe (244)

Parado! C:\WINDOWS\system32\ctfmon.exe (912)

Parado! C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe (2204)

Parado! C:\WINDOWS\system32\wuauclt.exe (3940)

Parado! C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (1012)

Parado! C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (3304)

Parado! C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (3480)

Parado! C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (3916)

Parado! C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (1724)

Parado! C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (3512)

Parado! C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (3264)

Parado! C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (4072)

Parado! C:\Documents and Settings\Andreia\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe (2380)

Parado! C:\WINDOWS\system32\wscntfy.exe (3896)

 

################## | Ficheiros # pastas infeciosos |

 

Não supprimido ! D:\setup.exe

Supprimido ! C:\Recycler\S-1-5-21-1935655697-854245398-725345543-1003

Supprimido ! E:\Recycler\S-1-5-21-1935655697-854245398-725345543-1003

Supprimido ! F:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665

Não supprimido ! D:\autorun.inf

 

(!) Ficheiros temporários suprimido.

 

################## | Registro |

 

 

################## | Mountpoints2 |

 

Supprimido ! HKCU\.\.\.\.\Explorer\MountPoints2\{1340d0ae-6d9e-11de-89e0-ac3a2db22a9f}

Supprimido ! HKCU\.\.\.\.\Explorer\MountPoints2\{6e7a9762-bfe8-11df-8c06-001966a5cb0e}

 

################## | Listing |

 

[30/12/2010 - 18:55:38 | N | 141612] C:\ Il Giorno Di Dolore Che Uno Ha.wav

[15/03/2009 - 12:29:02 | N | 264320] C:\!memoryzk.wav

[15/10/2005 - 19:50:34 | N | 211398] C:\10kartes.wav

[15/08/2011 - 19:17:58 | N | 365949] C:\172392_129612380445611_100001905494570_192979_4686918_o.jpg

[23/08/2011 - 20:15:28 | N | 399872] C:\26-11-09_Quebra_cabecalindodemais!!!.pps

[30/04/2010 - 11:33:43 | N | 33066] C:\32372515853_jca.xml

[22/10/2007 - 01:45:20 | N | 439358] C:\3Zks.mp3

[16/07/2011 - 02:05:38 | N | 664294] C:\A day In The Life-AdapZK.wav

[20/01/2011 - 17:35:30 | N | 383314] C:\A kumplice - Juca Chaves.wav

[21/07/2011 - 20:45:45 | N | 725446] C:\A Mont-Orq.wav

[19/08/2011 - 16:37:02 | N | 290950] C:\A Semente do Amor.wav

[06/07/2011 - 21:33:29 | N | 475942] C:\Abriu guitar.wav

[06/07/2011 - 16:36:33 | D ] C:\Acrobat3

[06/07/2011 - 16:39:30 | D ] C:\AcrobatX

[17/01/2011 - 15:29:30 | N | 80878] C:\Ai LovYu_zkpt.wav

[07/07/2011 - 22:08:18 | N | 432357] C:\Ale-DiplMerito.jpg

[02/04/2011 - 18:25:57 | N | 329884] C:\Ama zk Gr.wav

[19/08/2011 - 23:58:06 | N | 413734] C:\AmaZKfilhos.wav

[25/01/2011 - 23:54:57 | N | 498194] C:\Amigos para sempreee.wav

[20/08/2011 - 15:51:06 | N | 390118] C:\AMOR.wav

[25/07/2011 - 17:51:44 | N | 16567] C:\AmorVSTM.jpg

[28/04/2011 - 16:58:31 | N | 722266] C:\AmorZinho-aVe.wav

[27/07/2011 - 13:03:10 | D ] C:\AnalogX

[04/03/2011 - 21:14:33 | N | 548386] C:\Angie - The Rolling Stones.wav

[17/05/2011 - 12:28:44 | N | 448582] C:\AnieZKong Guitar.wav

[14/08/2011 - 19:34:27 | N | 1818447] C:\anjinho da guarda mau.wmv

[27/04/2011 - 14:47:32 | N | 475162] C:\AnJOZK rec.wav

[26/06/2011 - 07:06:11 | N | 717766] C:\anne unplugged - ErikSanne.wav

[28/05/2011 - 04:33:32 | N | 646342] C:\Annie Song JG.wav

[13/08/2011 - 21:17:26 | N | 12024] C:\antispam_br.htm

[31/01/2011 - 16:44:03 | N | 372850] C:\Antonio Marcos - Imagine - JL.wav

[20/07/2011 - 15:48:39 | N | 1654] C:\aos_zecas_da_vida....pdf

[18/02/2011 - 02:09:17 | N | 29446] C:\ApaiXonado17AAA.wav

[04/03/2001 - 16:49:24 | N | 14093] C:\apropaga.gif

[11/09/2011 - 01:29:14 | N | 1889] C:\aqui_jaz.pdf

[03/05/2011 - 15:27:34 | N | 590398] C:\ARISE.wav

[25/11/2011 - 15:19:43 | D ] C:\Arquivos de programas

[23/08/2011 - 20:25:39 | N | 1644032] C:\As crianças.pps

[24/08/2011 - 16:34:45 | N | 515494] C:\Assum Preto N Krassik Cord.wav

[04/04/2011 - 02:20:27 | N | 434950] C:\aSSumBlaZK insTr.wav

[12/08/2011 - 02:08:09 | D ] C:\Atalhos não utilizados da área de trabalho

[11/08/2011 - 13:36:57 | N | 13748560] C:\aTube_Catcher.exe

[23/09/2008 - 19:35:27 | N | 161458] C:\AUGUSTO B V - Setembro!.wav

[10/06/2009 - 22:31:01 | N | 0] C:\AUTOEXEC.BAT

[28/06/2004 - 10:58:28 | N | 20992] C:\AvaliAvelar.ppt

[24/01/2011 - 00:57:45 | N | 501036] C:\Ave Maria (1).wav

[24/01/2011 - 00:39:10 | N | 444948] C:\Ave Maria - Beyonce.wav

[01/09/2011 - 17:02:40 | N | 50121368] C:\Ave Maria Violin.wav

[31/01/2011 - 16:42:51 | N | 444948] C:\Ave Maria(1).wav

[24/01/2011 - 01:12:58 | N | 886272] C:\Ave Maria(1a).wav

[27/07/2011 - 14:41:55 | D ] C:\AVELAR_ZK

[20/04/2011 - 11:09:10 | N | 426022] C:\AZABkZK-JCPAIX_Rec.wav

[17/08/2011 - 13:12:31 | D ] C:\A_backpar

[28/06/2004 - 10:30:20 | N | 5516] C:\batendoasBotas.jpg

[16/08/2011 - 14:25:09 | N | 2283381] C:\Bebe colabora con las tareas de la casa.wmv

[04/03/2011 - 21:13:40 | N | 392592] C:\Bee Gees x ChiXo words.wav

[25/08/2011 - 16:09:41 | N | 598528] C:\BEIJA FLOR.pps

[13/04/2011 - 21:12:19 | N | 275782] C:\BeijoKissesZKrec.wav

[30/04/2011 - 18:25:41 | N | 404422] C:\BelleMariliazrec.wav

[07/05/2011 - 14:26:14 | N | 904198] C:\BencaMaeZK.wav

[22/11/2011 - 17:08:03 | N | 5727] C:\Bicarbonato de Sodio.txt

[02/03/2011 - 09:44:31 | N | 445734] C:\Birds of Paradise Peter Sue e Marc.wav

[31/01/2011 - 22:42:50 | N | 439686] C:\Birds of Paradise - Peter Sue e Marc.wav

[06/04/2011 - 00:01:40 | N | 436446] C:\BlagueDuguiDegue - Os CrioGenes.wav

[29/06/2011 - 01:23:58 | N | 1189414] C:\BlagueDuguiDegue-ZK.wav

[09/07/2011 - 02:38:34 | N | 461926] C:\Blowing in the wind - ZKdapt.wav

[05/05/2011 - 15:53:02 | N | 133894] C:\Blue39 Last Vlog.wav

[24/06/2011 - 00:53:12 | N | 640006] C:\Blues for Zerard.wav

[29/12/2010 - 11:32:03 | N | 132228] C:\Bobby Solo-UnaLacrimaSulViso.wav

[18/12/2010 - 00:04:11 | N | 220334] C:\BOIADA_AMIR_SATTER_JECT.wav

[10/12/2010 - 07:51:13 | N | 211] C:\boot.ini

[19/01/1782 - 01:14:07 | N | 4952] C:\Bootfont.bin

[04/08/2011 - 23:45:41 | N | 86730] C:\BridgeOTW-ZK.jpg

[04/08/2011 - 23:50:27 | N | 849490] C:\BridgeOver-SeG.wav

[21/04/2011 - 17:23:01 | N | 546838] C:\BSB Refrigera BSB.wav

[16/08/2011 - 14:24:13 | N | 33241] C:\butterflies3_hyper+btn_po.gif

[06/06/2011 - 02:19:19 | N | 572710] C:\Butterfly_PMZK.wav

[31/01/2011 - 16:49:42 | N | 91134] C:\b_honey I am Home !.wav

[23/07/2011 - 18:45:58 | N | 860422] C:\CabanaOndeNasci-GeraldinhoDoEng-WandaRab.wav

[26/09/2008 - 01:52:57 | N | 172642] C:\cancao_para_ana.wav

[29/01/2011 - 19:37:35 | N | 594202] C:\Canção dAmizade - Ludmila F.wav

[25/01/2011 - 22:54:28 | N | 597930] C:\CANÇÃO DO AMIGO - L FERBER.wav

[28/04/2011 - 10:53:12 | N | 496656] C:\carpenters_onlyesterday.wav

[19/08/2011 - 23:44:32 | N | 23455696] C:\CartadeUmPai.wav

[13/08/2011 - 21:19:47 | N | 199212] C:\cartilha-01-conceitos.pdf

[13/08/2011 - 21:19:56 | N | 233187] C:\cartilha-02-prevencao.pdf

[13/08/2011 - 21:20:04 | N | 167282] C:\cartilha-03-privacidade.pdf

[13/08/2011 - 21:20:12 | N | 293701] C:\cartilha-04-fraudes.pdf

[13/08/2011 - 21:20:19 | N | 172217] C:\cartilha-05-banda-larga-wireless.pdf

[13/08/2011 - 21:20:26 | N | 169586] C:\cartilha-06-spam.pdf

[13/08/2011 - 21:20:33 | N | 179259] C:\cartilha-07-incidentes.pdf

[13/08/2011 - 21:20:39 | N | 240677] C:\cartilha-08-malware.pdf

[13/08/2011 - 21:20:46 | N | 163027] C:\cartilha-checklist.pdf

[13/08/2011 - 21:19:44 | N | 1773097] C:\cartilha-completa.zip

[13/08/2011 - 21:21:31 | N | 1107479] C:\cartilha-folder-a4.pdf

[13/08/2011 - 21:21:05 | N | 108075] C:\cartilha-folheto-a4.pdf

[13/08/2011 - 21:20:54 | N | 154686] C:\cartilha-glossario.pdf

[13/08/2011 - 21:19:15 | N | 907199] C:\cartilha-seguranca-internet.pdf

[13/08/2011 - 21:17:14 | N | 10029] C:\cartilha_cert_br.htm

[30/12/2010 - 19:02:49 | N | 648256] C:\CD CELTA - Lord Of The dance - Hardiman, Ronan.wav

[18/07/2011 - 00:29:38 | N | 377344] C:\Celebrando-o-amor.ppt

[30/01/2011 - 14:44:42 | N | 350102] C:\Celtic Pan-Flute.wav

[15/11/2011 - 21:59:08 | N | 2172] C:\checkup.txt

[23/08/2011 - 20:21:32 | N | 41185] C:\chiks_small1.jpg

[29/05/2011 - 03:29:21 | N | 673126] C:\Chiq panflute_zkpt.wav

[07/04/2011 - 12:30:25 | N | 634910] C:\Chuvaaa.wav

[27/10/2008 - 16:33:12 | N | 102152] C:\ChuvaKaindo.wav

[02/02/2011 - 12:07:21 | N | 480852] C:\Ciclo Sem Fim - O Rei Leão.wav

[02/02/2011 - 21:43:26 | N | 534912] C:\ComoNossosPais.wav

[10/11/2010 - 18:55:12 | N | 0] C:\Config.Msi

[10/06/2009 - 22:31:01 | N | 0] C:\CONFIG.SYS

[18/08/2011 - 17:35:36 | N | 41984] C:\Controle da rifa mi.doc

[16/04/2006 - 02:59:04 | N | 385702] C:\Coruja_Vipss.wav

[06/04/2011 - 20:20:24 | N | 526150] C:\Crai ai ai ai.wav

[15/07/2011 - 23:47:52 | N | 444838] C:\CutucadaII.wav

[08/05/2011 - 21:49:59 | N | 745126] C:\DioZKomeT.wav

[16/05/2011 - 10:35:17 | N | 844486] C:\Doce Sentir - E.Lacerda.wav

[13/02/2011 - 13:32:24 | N | 422566] C:\DoceSentir - E Lacerda.wav

[18/03/2011 - 19:47:44 | D ] C:\Documents and Settings

[06/10/2005 - 18:14:48 | N | 431982] C:\DomenicoModugno-IlMaestroDiViolino(1)-CA.wav

[31/01/2011 - 16:46:05 | N | 128042] C:\Dominique original_modif_zk.wav

[22/07/2011 - 17:39:52 | N | 27615788] C:\Dona Dona guitar.wav

[22/07/2011 - 17:42:38 | N | 12669632] C:\Dona recZK guitar.wav

[24/05/2011 - 21:18:00 | N | 510262] C:\Dpoimto-Prof-Amanda-Gurgel.wav

[12/05/2011 - 02:53:44 | N | 493846] C:\Drazkula.wav

[24/08/2011 - 00:32:13 | N | 674758] C:\Dri-BelPach.wav

[02/06/2011 - 19:12:58 | N | 703462] C:\Dri-Vai-em-FrenT.wav

[24/08/2011 - 00:15:29 | N | 21923876] C:\DriAmada_Guitar.wav

[20/08/2011 - 02:14:57 | N | 2028948] C:\DSC01549.JPG

[20/08/2011 - 02:15:29 | N | 2263565] C:\DSC01723.JPG

[20/08/2011 - 02:15:55 | N | 2157251] C:\DSC01727.JPG

[20/08/2011 - 02:14:03 | N | 2071009] C:\DSC02272.JPG

[16/08/2011 - 14:23:01 | N | 2027529] C:\Duas facilidades.wmv

[14/07/2011 - 20:49:43 | D ] C:\DVDS

[26/07/2011 - 00:51:43 | N | 980422] C:\DW-CP.wav

[13/09/2011 - 17:27:19 | N | 2928] C:\d_testand_na.pdf

[16/02/2011 - 15:03:26 | N | 419384] C:\Edith Piaf - Autumn Leaves.wav

[16/11/2008 - 00:55:06 | N | 278536] C:\Eduardo Lages - E por isso estou aqui.wav

[22/07/2011 - 17:46:41 | N | 680038] C:\eliZK-serenade.wav

[01/04/2011 - 13:55:07 | N | 349644] C:\eliZKbethan Serenad.wav

[28/05/2011 - 16:36:29 | N | 429382] C:\elvis - always on my mind.wav

[24/05/2011 - 11:14:47 | N | 441958] C:\Elvis - Wooden Heart.wav

[28/05/2011 - 16:35:55 | N | 637126] C:\Elvis Love Me Tender.wav

[28/06/2004 - 10:30:22 | N | 7304] C:\engolindosapo.jpg

[28/06/2004 - 10:30:20 | N | 4769] C:\entrandopelocano.jpg

[04/02/2011 - 00:48:00 | N | 300548] C:\Era - Angel.wav

[20/04/2011 - 15:43:09 | N | 715182] C:\Erik e Sane unpluged.wav

[20/04/2011 - 15:41:49 | N | 446862] C:\Erik e Sane unplugged.wav

[29/10/2008 - 17:15:30 | N | 434842] C:\esKutMidi wave.wav

[16/05/2011 - 15:53:19 | N | 1087270] C:\EspeZarec.wav

[26/01/2011 - 22:52:45 | N | 294230] C:\Estrelas - O.Mont.wav

[17/09/2011 - 12:28:47 | N | 832642] C:\Etta James - You Lost That Lovin' Feelin'.wav

[26/08/2011 - 21:22:59 | N | 797184] C:\EU VIM.pps

[26/08/2011 - 21:22:49 | N | 797184] C:\EU VIM.ppt

[26/08/2011 - 21:21:56 | N | 797184] C:\EU.ppt

[14/02/2011 - 00:24:28 | N | 279418] C:\Eu_Sei_Que_Vou_Te_Amar.wav

[14/02/2011 - 00:01:14 | N | 279310] C:\Eu_Sei_Q_Vou_Te_Amar.wav

[13/02/2011 - 23:59:35 | N | 224566] C:\Eu_Sei_Q_Vou_T_Amar.wav

[16/05/2011 - 15:53:57 | N | 468502] C:\Evangeline.wav

[19/06/2005 - 12:43:24 | N | 719607] C:\fagner_mercedes_sosa_anos.mid

[15/08/2011 - 23:57:25 | N | 959110] C:\Falla El Amor Brujo Danza ritual del fuego.wav

[25/07/2011 - 18:57:20 | N | 43697] C:\FazkomQ.jpg

[19/06/2011 - 01:23:25 | N | 812998] C:\FILOpqkiloSOFIA.wav

[30/07/2011 - 01:02:15 | N | 24735604] C:\Five H Miles The Br Four.wav

[25/07/2011 - 18:26:36 | N | 19401] C:\Fluemdas Almasdos-Poetas-br.jpg

[25/07/2011 - 18:11:40 | N | 32840] C:\FluemdasAlmasdos-Poetas-br.jpg

[25/07/2011 - 18:05:45 | N | 58035] C:\FluemdasAlmasdosPoetas.jpg

[13/11/2007 - 00:40:05 | N | 6031] C:\FoguinhAapaiXonado.gif

[09/12/2010 - 15:21:48 | D ] C:\FONTES

[09/02/2011 - 00:57:21 | N | 339610] C:\For A Few Dollars More.wav

[23/08/2011 - 20:15:46 | N | 617850] C:\FORRO.wma

[10/11/2010 - 19:56:02 | D ] C:\found.000

[16/07/2011 - 14:43:02 | N | 1607] C:\fracasso.pdf

[15/07/2011 - 13:31:11 | N | 14339200] C:\FreeVideoToJPGConverter.exe

[15/07/2011 - 13:18:44 | N | 15922432] C:\FreeYouTubeDownload.exe

[04/08/2011 - 14:46:26 | N | 14406136] C:\FreeYouTubeToMP3Converter.exe

[03/05/2005 - 11:21:47 | N | 238677] C:\Friacho.gif

[31/01/2011 - 16:44:40 | N | 279274] C:\Gigliola Cinquetti Il Condor.wav

[16/07/2011 - 22:45:52 | N | 555046] C:\Gracias a la vida.wav

[15/07/2011 - 15:19:34 | N | 557734] C:\guitar guehu.wav

[16/09/2011 - 00:48:10 | N | 7085760] C:\GuitarZK-rec55seg.wav

[27/04/2011 - 15:58:26 | N | 202966] C:\Halelujah_zkpatty_pt.wav

[01/07/2011 - 21:31:45 | N | 217798] C:\Hallelujah-JN.wav

[12/11/2011 - 11:19:32 | N | 22462] C:\hijackthis.log

[19/04/2011 - 19:42:44 | N | 644182] C:\Hino a Sao Expedito.wav

[08/07/2011 - 21:30:06 | N | 397942] C:\Hoje Tiengo Tam_po.WAV

[08/07/2011 - 21:28:32 | N | 45568556] C:\HojeTiengoTempo.wav

[14/02/2011 - 19:39:50 | N | 420394] C:\House of the rising sun Panflut.wav

[25/05/2011 - 20:14:01 | N | 360646] C:\HumHumHumZK.wav

[05/05/2011 - 17:03:29 | N | 374182] C:\HummmZC.wav

[03/08/2011 - 03:39:33 | N | 374182] C:\HummmZkboto.wav

[17/09/2011 - 21:49:45 | N | 2591] C:\iii_adi_mob.pdf

[10/06/2009 - 22:31:01 | N | 0] C:\IO.SYS

[16/07/2011 - 16:52:08 | N | 1664] C:\ir..._ou_ficar....pdf

[04/03/2011 - 21:13:13 | N | 219504] C:\ISLA DE PASCUA.wav

[05/06/2011 - 00:01:55 | N | 457510] C:\JaNella - PMFSilent.wav

[04/06/2011 - 21:29:12 | N | 24218828] C:\JaNella-Gracias a la vida.wav

[04/06/2011 - 21:35:23 | N | 24147492] C:\Janella-ZKondorP-Rec.wav

[04/06/2011 - 23:37:25 | N | 430822] C:\Jannella-AnnieS-VZK.wav

[04/03/2011 - 21:15:15 | N | 400206] C:\jeanette porque te vas.wav

[12/02/2011 - 02:46:23 | N | 376970] C:\Jennifer Warnes Song Of Bernadette.wav

[16/08/2011 - 14:32:17 | N | 3843991] C:\JESSIER QUIRINO NO JÔ.wmv

[14/08/2011 - 19:33:33 | N | 5311682] C:\Jesus pescando.wmv

[28/08/2011 - 21:01:31 | N | 557446] C:\JM- Menina.wav

[16/09/2003 - 20:38:18 | N | 10825] C:\jovensbarra.gif

[07/09/2011 - 00:26:46 | N | 21216540] C:\JoZehdeAracy.wav

[29/04/2006 - 15:25:26 | N | 216358] C:\joZesonhador.wav

[27/04/2011 - 15:38:55 | N | 500758] C:\JZEHDaracy.wav

[15/05/2009 - 19:14:18 | N | 386306] C:\Kaminhant pelas Vidas.wav

[25/06/2011 - 01:31:41 | N | 371590] C:\KarinhosKalienteZK.wav

[29/04/2006 - 15:28:48 | N | 258550] C:\KulpadaMae.wav

[09/06/2011 - 17:33:31 | N | 801132] C:\Laudelina.wav

[24/05/2011 - 01:35:42 | N | 781422] C:\Lavem o Trem.wav

[29/10/2011 - 09:50:44 | D ] C:\LegExp1

[28/06/2004 - 10:30:22 | N | 8248] C:\leitDerramado.jpg

[18/07/2011 - 15:31:58 | N | 499750] C:\Let guitar.wav

[26/08/2011 - 00:30:51 | D ] C:\Lian Pedro-Maio-2010

[05/07/2011 - 23:12:58 | N | 412294] C:\LijsterZ.wav

[27/04/2011 - 15:38:00 | N | 703042] C:\Lilith Angel.wav

[12/04/2011 - 20:21:27 | N | 337798] C:\LilithAngel_Rec.wav

[07/07/2011 - 22:16:16 | N | 53] C:\List.txt

[19/11/2011 - 16:08:50 | N | 33164] C:\Logs-Imasters-181111.txt

[06/04/2005 - 23:58:21 | N | 15665] C:\Loren_o3o3o5.jpg

[15/08/2011 - 19:16:59 | N | 308283] C:\Lourdes-Ass.jpg

[15/08/2011 - 19:16:35 | N | 376337] C:\LOurdesAss.jpg

[04/03/2011 - 21:15:47 | N | 294686] C:\Love isSu Guitar By Boghrat.wav

[26/08/2011 - 20:45:08 | N | 575302] C:\Love me t guitar.wav

[28/05/2011 - 16:35:06 | N | 583990] C:\Love me tender - Jorg Nolla.wav

[28/05/2011 - 16:34:04 | N | 563958] C:\Love Me Tendo.wav

[28/05/2011 - 16:17:40 | N | 39090748] C:\Love of My Life J Nolla.wav

[06/03/2011 - 11:51:58 | N | 491102] C:\Madagascar Olodum.wav

[17/09/2011 - 12:27:30 | N | 403954] C:\Mardi Gras - Girl I`ve Got News For You.wav

[03/06/2011 - 20:50:03 | N | 17900196] C:\Maria Bethânia - Oração ao Tempo‏.wav

[16/02/2011 - 15:39:54 | N | 515408] C:\MAVI - Alain Barriere.wav

[03/06/2011 - 01:53:21 | N | 482326] C:\me quitte - JN.wav

[16/05/2011 - 16:31:36 | N | 550726] C:\Memory G Zamfir RecZK.wav

[16/05/2011 - 16:13:07 | N | 444742] C:\MemoryZKtsHarmonik.wav

[04/10/2008 - 19:23:28 | D ] C:\Memórias Vol. 5

[22/01/2011 - 15:19:41 | N | 494290] C:\Menina Flali Só Por Voceh.wav

[22/01/2011 - 15:27:20 | N | 618476] C:\Menina Flali Só Por Voceheheh.wav

[22/01/2011 - 15:26:42 | N | 496852] C:\Menina Flali Só Por Vocehehehh.wav

[06/04/2011 - 20:16:45 | N | 511854] C:\Menina Misterio.wav

[06/04/2011 - 20:16:08 | N | 1023118] C:\Menina Mistherio.wav

[31/01/2011 - 02:35:14 | N | 347364] C:\Metade - OMont_zkqta.wav

[20/04/2011 - 02:23:51 | N | 687094] C:\MFDreansZK.wav

[20/06/2011 - 23:44:35 | N | 813958] C:\MGenuHino.wav

[17/04/2011 - 21:44:47 | N | 859348] C:\Mi-BeyJust.wav

[06/04/2011 - 11:52:29 | N | 446758] C:\Minha MenT.wav

[06/04/2011 - 11:52:51 | N | 222630] C:\MinhaMenT.wav

[28/07/2011 - 15:04:21 | D ] C:\MIsDVDs

[16/11/2011 - 17:12:09 | D ] C:\Mi_pC_Imagens

[20/12/2010 - 13:56:31 | D ] C:\Mi_pC_OutlookSoltos

[21/09/2011 - 13:41:05 | D ] C:\Mi_pC_Txts

[24/08/2011 - 01:58:37 | D ] C:\Mi_pC_Zkz_ppTppS

[30/07/2011 - 03:09:27 | D ] C:\Mi_pC_Zk_Sons

[07/10/2011 - 02:34:28 | D ] C:\Mi_pC_Zk_Videos

[28/06/2004 - 10:30:20 | N | 5472] C:\molhandobiskoito.jpg

[10/06/2009 - 22:31:01 | N | 0] C:\MSDOS.SYS

[31/01/2011 - 16:43:14 | N | 387400] C:\Msg D'Amour - jzeh.wav

[18/08/2011 - 21:33:27 | N | 597958] C:\MsgPraVc.wav

[06/04/2003 - 16:53:20 | N | 29696] C:\MsgsJzehfevMars.doc

[11/04/2011 - 01:02:56 | RHD ] C:\MSOCache

[07/05/2011 - 11:35:18 | N | 464118] C:\Mulher NBC ZKR.wav

[29/04/2006 - 15:18:34 | N | 326086] C:\NairAlacy.wav

[17/09/2011 - 21:32:20 | N | 1646] C:\nao_me_deixe....pdf

[28/07/2011 - 22:59:51 | D ] C:\NA_SA_MI

[06/06/2005 - 19:45:56 | N | 341558] C:\NOCOES_1_SOCORROS.pdf

[07/07/2011 - 21:17:56 | N | 448890] C:\Nossa-Senhora.jpg

[18/05/2011 - 11:46:07 | N | 588550] C:\Nowcryguit.wav

[03/08/2004 - 23:38:34 | N | 47564] C:\NTDETECT.COM

[03/08/2004 - 23:59:34 | N | 251168] C:\ntldr

[12/11/2011 - 18:10:40 | N | 2424] C:\Numa NoiT cheia de Estrelas.txt

[23/08/2011 - 20:25:14 | N | 316928] C:\Nutricionista lista os 10 piores alimentos para a sua saude.doc

[31/01/2011 - 16:42:05 | N | 516120] C:\O amor - To Fly.wav

[27/04/2011 - 15:50:04 | N | 305044] C:\O Caderno - Filipe Rossi.wav

[29/06/2011 - 00:57:10 | D ] C:\O Corvo

[25/05/2011 - 02:50:13 | D ] C:\O Iraci

[23/08/2011 - 20:20:21 | N | 352768] C:\O MUNDO DO FAZ DE CONTA.pps

[23/05/2011 - 12:11:04 | N | 649030] C:\O-Iraci-Eu-Canto-Assim-ZCG.wav

[15/04/2011 - 23:59:43 | N | 210254] C:\ObrigadoSRZ.wav

[08/02/2011 - 23:09:40 | N | 450540] C:\OraSao Francisco - Elizabete Lacerda.wav

[19/08/2011 - 20:52:48 | N | 679366] C:\Orquidea-GA-92.wav

[25/08/2011 - 16:07:42 | N | 3982848] C:\Orquideas - Simplesmente Lindo.pps

[23/08/2011 - 20:26:31 | N | 170496] C:\Os professores bravos fazem muita falta._.doc

[02/02/2011 - 02:48:17 | N | 297686] C:\Oswaldo Montenegro - Estrelas.wav

[17/08/2011 - 16:06:25 | D ] C:\OUTEXPRZKPATTY

[21/08/2011 - 02:49:22 | D ] C:\Outlook6

[15/04/2000 - 12:28:06 | N | 19968] C:\OuzodoZ.doc

[21/06/2011 - 20:05:03 | N | 24233776] C:\Over-the-rainbow-Guit.wav

[23/08/2011 - 20:21:43 | N | 187904] C:\o_pedaco_perdido_pow.pps

[02/08/2011 - 15:21:53 | N | 666431] C:\P - ART BY SDAM.eml

[01/08/2011 - 20:57:57 | N | 674758] C:\Pachelbel Canon in D guita_reczk.wav

[27/04/2011 - 15:33:53 | N | 674690] C:\Pachelbel guitar_zkdap.wav

[07/08/2011 - 14:56:28 | N | 1890816] C:\Pacto.ppt

[25/11/2011 - 13:00:48 | ASH | 1409286144] C:\pagefile.sys

[25/07/2011 - 18:49:26 | N | 52544] C:\Palavras10ComneXas.jpg

[25/07/2011 - 17:59:09 | N | 50408] C:\PalavrasumBeloDia.jpg

[25/01/2011 - 21:38:16 | N | 458962] C:\Paula Fernandes - VagalumesSSS.wav

[31/01/2011 - 16:42:29 | N | 458962] C:\Paula Fernandes - Vagalumes.wav

[01/07/2011 - 03:58:31 | N | 44294848] C:\Pelos prados e campinas.wav

[21/07/2011 - 23:09:26 | N | 674816] C:\PenhaCastro.pps

[31/01/2011 - 16:45:27 | N | 196830] C:\Penistory.wav

[23/01/2011 - 15:56:00 | N | 379326] C:\Pensem Mi - Windar.wav

[29/08/2011 - 18:05:51 | N | 774502] C:\Pensem mi Dar.wav

[31/01/2011 - 19:43:10 | N | 831798] C:\Petrus_3101.wav

[31/01/2011 - 19:45:20 | N | 207342] C:\Petrus_31Jan.wav

[18/04/2011 - 16:37:30 | N | 1303020] C:\Pilares Miro Saldanha.wav

[18/04/2011 - 16:35:53 | N | 648652] C:\Pilares-Miro Saldanha.wav

[08/05/2011 - 23:33:14 | N | 665350] C:\Pintppa.wav

[02/08/2011 - 15:59:47 | N | 799078] C:\Plaisir DamorUS.wav

[02/08/2011 - 15:58:12 | N | 599686] C:\Plaizir DamorUS.wav

[25/07/2011 - 18:30:26 | N | 54117] C:\POalavras10conexas.jpg

[17/11/1998 - 13:37:42 | N | 20992] C:\Poligrafia.doc

[03/08/2011 - 20:40:33 | N | 45809076] C:\PontesobreAguasTurbulentas.wav

[04/08/2011 - 23:54:03 | N | 1671680] C:\PonTeZ.pps

[04/08/2011 - 23:53:24 | N | 1671680] C:\PonTeZ.ppt

[04/08/2011 - 23:41:42 | N | 815104] C:\PonTeZK.pps

[25/08/2011 - 16:08:53 | N | 1620480] C:\POR_DO_SOL.pps

[25/08/2011 - 16:10:36 | N | 1411072] C:\pps.msguniverso.pps

[06/05/2011 - 20:59:44 | N | 292678] C:\Pra Voceh SC.wav

[08/06/2011 - 01:59:29 | N | 591334] C:\PraNumDiZk.wav

[06/02/2011 - 22:10:39 | N | 450540] C:\Prayer St Francis E Lacerda.wav

[19/02/2011 - 22:48:10 | N | 379192] C:\Pro c* rando Tu - G L.wav

[05/09/2011 - 19:10:28 | D ] C:\PROGRAMAS_pcPai

[17/08/2011 - 12:56:36 | D ] C:\ProgramData

[23/08/2011 - 20:25:33 | N | 3979264] C:\Que linda é minha terra.pps

[29/03/2011 - 15:29:12 | N | 175106] C:\Queda jfaf.wav

[27/08/2011 - 22:47:40 | N | 767110] C:\QueroVC.wav

[16/05/2011 - 16:18:21 | N | 651634] C:\R V Tu quanto tempo haiZmix.wav

[16/05/2011 - 16:17:05 | N | 827134] C:\R V Tu quanto tempo hai.wav

[26/01/2011 - 18:01:22 | N | 527400] C:\Race Credo (C cadIrmão) OM_E.Costa.wav

[06/04/2005 - 23:58:43 | N | 11114] C:\raissa.jpg

[05/06/2005 - 15:27:58 | N | 568035] C:\RaulzitoPanterasVcIndaPodSonhar.mid

[05/06/2005 - 14:37:26 | N | 950085] C:\Raul_Canto_pra_Mi_Morte.mid

[05/06/2005 - 14:39:48 | N | 842409] C:\Raul_Maluco_Beleza.mid

[05/06/2005 - 14:59:40 | N | 718059] C:\Raul_Minha_Viola.mid

[05/06/2005 - 14:39:28 | N | 742385] C:\Raul_NoFundoQuintaldEscola.mid

[05/06/2005 - 14:38:48 | N | 689257] C:\Raul_SeixasQue_Luz_E_Essa.mid

[05/06/2005 - 14:37:30 | N | 757523] C:\Raul_Seixas_08_O_Homem.mid

[05/06/2005 - 14:36:46 | N | 663549] C:\Raul_Seixas_10_Cantiga_de_Ninar.mid

[05/06/2005 - 14:34:36 | N | 793813] C:\Raul_Seixas_Super_Herois.mid

[11/11/2010 - 15:52:24 | N | 827] C:\readme.txt

[04/03/2011 - 21:12:35 | N | 290214] C:\Recebas Flores Q lhe dou - Nilton Cesar.wav

[25/11/2011 - 15:31:16 | SHD ] C:\RECYCLER

[23/08/2011 - 20:29:59 | N | 2810368] C:\relacionamento.pps

[17/12/2010 - 23:51:43 | N | 527374] C:\Richard Marx-Right here waiting for you.wav

[18/08/2011 - 19:19:44 | N | 981504] C:\RifaAndreSam-Final.doc

[18/08/2011 - 18:17:54 | N | 39936] C:\RifaAndreSam.doc

[18/08/2011 - 18:35:23 | N | 945664] C:\RifaAndreSam_Z1.doc

[18/08/2011 - 18:44:50 | N | 960512] C:\RifaAndreSam_Z1z.doc

[22/01/2011 - 12:33:41 | N | 396626] C:\Rock and Roll lullaby - B.J.Tthomas(1972).wav

[18/07/2011 - 01:02:03 | N | 214572] C:\Romantikpoesia.wav

[28/04/2011 - 18:37:18 | N | 513050] C:\Rosa mf.wav

[10/09/2011 - 23:22:27 | N | 838918] C:\RS-Metamb.wav

[06/04/2005 - 23:58:56 | N | 16782] C:\Rubelita_o3o3o5.jpg

[22/01/2011 - 19:29:10 | N | 363140] C:\Runaround Ange_Tony Stevensl.wav

[12/06/2011 - 20:04:29 | N | 824134] C:\RV La Bellezza-MFqacdm.wav

[11/06/2011 - 20:13:23 | N | 344422] C:\SantanToin-18726.wav

[23/08/2011 - 20:26:47 | N | 7082496] C:\Santuario Nacional de Ap_.pps

[08/06/2011 - 18:58:22 | N | 37550636] C:\Sapore di Sale.wav

[06/08/2011 - 01:44:51 | N | 479494] C:\sara_mc-Joanna.wav

[24/08/2011 - 13:38:44 | N | 88092] C:\scrapeenet_20110824123735JIr8.jpg

[08/07/2011 - 22:28:07 | N | 677254] C:\Sealed With a Kiss-Bobby Vinton.wav

[19/09/2011 - 01:21:17 | N | 769894] C:\SerafimZK.wav

[17/05/2011 - 11:46:51 | N | 429670] C:\SerahLieshSerahVerdad_zkrec.wav

[24/05/2011 - 01:36:20 | N | 651318] C:\SinaZKantado.wav

[15/08/2011 - 18:18:53 | N | 3859456] C:\SJRP.pps

[15/11/2011 - 18:44:12 | D ] C:\Slide 1AV

[20/04/2011 - 10:50:42 | N | 402342] C:\Slim Dusty - Waltzing Matilda.wav

[21/06/2011 - 00:17:04 | N | 639286] C:\Sobre ead.wav

[31/01/2011 - 16:41:37 | N | 520168] C:\Son of The Moon.wav

[02/04/2011 - 21:48:18 | D ] C:\Sonho de Jzeh - Kaminhant das Vidas

[15/06/2011 - 16:55:00 | N | 594406] C:\Sorella Luna.wav

[13/05/2011 - 11:30:52 | N | 546886] C:\Stand by me guitarz.wav

[18/08/2011 - 16:08:10 | N | 543622] C:\Stand by me guitarZMNF.wav

[23/06/2011 - 21:15:52 | N | 594790] C:\Stand by MF-guitar.wav

[31/08/2011 - 22:08:31 | N | 622246] C:\StarsZK.wav

[17/04/2011 - 13:55:53 | N | 347686] C:\StarwayTH_zkdapt.wav

[25/10/2009 - 20:05:44 | SHD ] C:\System Volume Information

[24/05/2011 - 14:55:06 | N | 657574] C:\Tamed Cover.wav

[27/04/2011 - 15:28:41 | N | 580246] C:\Tank yourl.wav

[20/05/2011 - 17:59:31 | N | 456838] C:\tatMFz.wav

[12/05/2011 - 14:41:31 | N | 456550] C:\tatMFzk.wav

[16/04/2011 - 16:09:18 | N | 404422] C:\TeclandoSonhos.wav

[29/09/2011 - 16:54:45 | D ] C:\Temp

[03/06/2011 - 20:51:26 | N | 406246] C:\Temp.wav

[28/06/2004 - 10:30:20 | N | 8318] C:\tempestadcopodagua.jpg

[17/09/2011 - 12:29:23 | N | 345454] C:\The Toys - Deserted.wav

[26/08/2011 - 00:30:39 | ASH | 675382] C:\Thumbs.db

[27/04/2011 - 16:03:28 | N | 163618] C:\ToGoBackToBahiaZKrec.wav

[18/07/2011 - 00:12:29 | N | 64306] C:\top.jpg

[15/07/2011 - 01:34:11 | N | 530470] C:\Trio Esperança - Dominique (Vers. Dif)1964.wav

[08/07/2011 - 00:56:44 | N | 464806] C:\TristeZadodoZK-Pt.wav

[05/05/2011 - 16:03:45 | N | 780406] C:\Tu.wav

[18/02/2011 - 02:25:22 | N | 277522] C:\Tutano AAA.wav

[16/05/2011 - 16:17:48 | N | 484486] C:\TuZPrec.wav

[30/04/2011 - 10:59:29 | N | 484630] C:\TuZPrecz.wav

[12/02/2011 - 01:04:01 | N | 307812] C:\Twinkle Twinkle Little Star.wav

[03/03/2011 - 14:45:09 | N | 309348] C:\Twinkle Twinkle Little Starz.wav

[05/06/2011 - 22:51:01 | N | 536614] C:\Tê-Woman-Zk.wav

[20/06/2004 - 13:21:10 | N | 24064] C:\Umaestoriaa100dedos.doc

[08/06/2011 - 18:55:42 | N | 46983212] C:\Un Angelo - I Santo California‏.wav

[08/06/2011 - 19:15:55 | N | 10622000] C:\UnAng-ZKrecMix.wav

[16/08/2011 - 17:41:08 | N | 41984] C:\Uniao-Estavel.doc

[09/06/2011 - 03:17:10 | N | 270214] C:\Unnag-Z.wav

[07/07/2011 - 11:56:49 | N | 11117238] C:\untitl1.BMP

[07/07/2011 - 21:36:56 | N | 932054] C:\untitl10.BMP

[07/07/2011 - 21:38:42 | N | 354814] C:\untitl11.BMP

[07/07/2011 - 22:07:20 | N | 8370934] C:\untitl12.BMP

[07/07/2011 - 22:13:15 | N | 8836758] C:\untitl13.BMP

[07/07/2011 - 22:15:58 | N | 6062966] C:\untitl14.BMP

[07/07/2011 - 12:09:04 | N | 566258] C:\untitl3.TIF

[07/07/2011 - 21:16:52 | N | 11459622] C:\untitl5.BMP

[07/07/2011 - 21:32:54 | N | 5356902] C:\untitl6.BMP

[07/07/2011 - 21:34:06 | N | 1437854] C:\untitl7.BMP

[07/07/2011 - 21:35:01 | N | 1344634] C:\untitl8.BMP

[07/07/2011 - 21:36:09 | N | 415638] C:\untitl9.BMP

[25/11/2011 - 15:31:16 | D ] C:\UsbFix

[25/11/2011 - 15:31:17 | A | 6440] C:\UsbFix.txt

[22/02/2011 - 12:41:59 | N | 346544] C:\VAI CHOVER MULHER.wav

[16/05/2011 - 16:14:24 | N | 587446] C:\ValsImpeZKrec.wav

[19/06/2005 - 12:34:30 | N | 830932] C:\vangelis_song_of_the_seas.mid

[16/05/2011 - 16:31:03 | N | 626814] C:\VaZKeiro.wav

[28/01/2011 - 23:52:41 | D ] C:\VeraJ VeraR

[20/04/2011 - 14:17:29 | N | 470150] C:\VerdesLives-zkrec.wav

[22/04/2011 - 21:24:09 | N | 433438] C:\ViaSakra.wav

[23/08/2011 - 20:17:01 | N | 1117184] C:\vida_2011.pps

[23/01/2011 - 13:07:07 | N | 528916] C:\Viva a Vida Curtaa!.wav

[01/09/2011 - 18:31:51 | N | 43617680] C:\VivaVida-Scorpions-RecZK.wav

[08/06/2011 - 19:05:55 | N | 36027024] C:\vuelvo a ti - manolo otero.wav

[07/06/2011 - 19:22:54 | N | 750310] C:\WCdi last Rose ofS.wav

[30/08/2011 - 00:41:10 | N | 721030] C:\WCSoniaM.wav

[06/04/2005 - 23:59:15 | N | 8199] C:\welcomeab.gif

[20/11/2011 - 00:20:12 | D ] C:\WINDOWS

[27/04/2011 - 15:22:53 | N | 531742] C:\Windszzz.wav

[04/08/2011 - 13:51:12 | N | 915920] C:\WinPcap_4_1_2.exe

[29/09/2011 - 16:47:52 | N | 7146] C:\winzip.log

[16/05/2011 - 16:33:42 | N | 388294] C:\Yesterday guitar.wav

[15/05/2011 - 13:09:52 | N | 387622] C:\Yesterday guitarz.wav

[31/01/2011 - 16:46:40 | N | 118246] C:\YouroLeyyyLy.wav

[12/11/2010 - 14:52:29 | N | 522046] C:\YouTube - Taximetro - Oswaldo Montenegro.wav

[17/09/2011 - 13:27:23 | N | 21576830] C:\Youtube-MundAnoAtual

[16/05/2011 - 16:34:18 | N | 268390] C:\YromemoryZKrec3.wav

[16/05/2011 - 16:15:54 | N | 335302] C:\Zana.wav

[16/05/2011 - 16:29:02 | N | 443110] C:\Zangel zrec.wav

[15/05/2011 - 00:17:10 | N | 437158] C:\Zanies Onguitar.wav

[29/04/2011 - 23:21:56 | N | 335302] C:\Zanna.wav

[27/04/2011 - 15:21:26 | N | 662902] C:\Zapaxe.wav

[05/05/2011 - 16:14:09 | N | 365398] C:\Zaskultarv.wav

[05/05/2011 - 16:14:39 | N | 448630] C:\Zaskultarvz.wav

[24/08/2011 - 18:36:03 | N | 99656] C:\Zeca-BeiradoRio.jpg

[22/05/2011 - 18:50:43 | N | 631462] C:\Zehf.wav

[15/06/2011 - 01:52:27 | N | 383302] C:\Zesterdey.wav

[26/05/2005 - 19:12:52 | N | 738032] C:\ze_ramalho_e_elba_ramalho-asa_branca_e_volta_da_asa_branca_eq.mid

[27/04/2011 - 15:20:02 | N | 360302] C:\Zhe house of the rising sun.wav

[06/07/2011 - 14:04:17 | N | 609562] C:\Zilencio Zeh de Zouro.wav

[19/04/2011 - 18:27:24 | N | 509046] C:\Zindios.wav

[30/08/2011 - 21:37:34 | N | 1132006] C:\zk-fmat.wav

[30/08/2011 - 21:40:17 | N | 758470] C:\zk-fmqnc.wav

[09/06/2011 - 19:09:26 | N | 112358] C:\ZK-Laude-intro.wav

[30/08/2011 - 21:35:14 | N | 16711268] C:\zk-MI.wav

[30/08/2011 - 21:30:04 | N | 8355656] C:\zk-MI2.wav

[31/01/2011 - 16:49:15 | N | 92194] C:\ZKbal_ZKf_Intro7.wav

[18/07/2011 - 15:33:27 | N | 795358] C:\ZkBe-Zec.wav

[21/05/2011 - 19:15:31 | N | 352294] C:\Zkisparrou.wav

[02/08/2011 - 01:56:20 | N | 238054] C:\ZKKoniff-zkr.wav

[08/06/2011 - 14:10:24 | N | 655846] C:\Zklipse damor.wav

[01/07/2011 - 04:22:36 | N | 823894] C:\ZKminhanT.wav

[07/09/2011 - 03:35:59 | N | 320134] C:\ZKours.wav

[09/08/2011 - 00:25:33 | N | 1149952] C:\Zkpelo-Gaivota-Passaro-Ferido.pps

[31/08/2011 - 16:13:19 | N | 96934] C:\ZKpito.wav

[19/08/2011 - 17:02:33 | N | 370630] C:\ZKsinceroMEP.wav

[16/05/2011 - 16:32:43 | N | 409414] C:\ZKtatanZK.wav

[04/06/2011 - 14:10:57 | N | 632230] C:\ZKuiteliZK.wav

[26/05/2011 - 12:56:16 | N | 616534] C:\ZKuiTPX.wav

[26/05/2011 - 12:58:33 | N | 43738224] C:\ZKuiTz.wav

[26/05/2011 - 12:59:30 | N | 493966] C:\ZKuiTzk.wav

[15/05/2011 - 04:08:13 | N | 276166] C:\ZKVak-r-.wav

[16/05/2011 - 16:35:28 | N | 156814] C:\ZKVakeiro-rec.wav

[21/09/2011 - 16:00:56 | D ] C:\ZK_PaiG

[08/07/2011 - 12:37:51 | N | 189286] C:\Zminik.wav

[04/06/2011 - 21:41:29 | N | 14013540] C:\Zocean-ptrec.wav

[04/07/2011 - 03:08:30 | N | 524614] C:\ZOh Susanna.wav

[25/05/2011 - 18:52:27 | N | 826342] C:\ZolhosTristt.wav

[15/06/2011 - 14:06:40 | N | 162982] C:\ZoVendoTudo_zk_rec.wav

[22/07/2011 - 16:39:55 | N | 39845420] C:\Zé Ramalho-Educação.wav

[10/12/2006 - 01:15:29 | RD ] D:\Fscommand

[15/04/2004 - 02:50:26 | R | 43] D:\autorun.inf

[10/12/2006 - 01:10:47 | R | 1586613] D:\setup.exe

[20/11/2007 - 19:50:30 | N | 174480] E:\786786.JPG

[29/10/2011 - 09:50:17 | D ] E:\Language

[28/01/2005 - 13:41:00 | N | 20545] E:\Leggimi.rtf

[14/01/2008 - 12:14:58 | N | 143360] E:\OeMsgXtract.exe

[14/01/2008 - 12:15:17 | N | 528] E:\OeMsgXtract.exe.manifest

[09/06/2010 - 01:46:43 | N | 161] E:\OeMsgXtract.ini

[14/01/2008 - 12:18:54 | N | 27443] E:\Readme.rtf

[25/11/2011 - 15:31:16 | SHD ] E:\RECYCLER

[01/11/2009 - 23:25:33 | SHD ] E:\System Volume Information

[12/01/2010 - 13:50:54 | ASH | 8192] E:\Thumbs.db

[30/11/2003 - 00:39:06 | N | 45] E:\www.gaijin.at.url

[18/08/2011 - 18:19:46 | N | 981504] F:\RifaAndreSam-Final.doc

[26/09/2011 - 19:42:04 | N | 1293904] F:\camera 332.jpg

[26/09/2011 - 19:42:04 | N | 1163400] F:\camera 333.jpg

[26/09/2011 - 19:42:06 | N | 1157598] F:\camera 334.jpg

[26/09/2011 - 19:39:50 | N | 1999343] F:\Cópia de camera 240.jpg

[26/09/2011 - 19:39:48 | N | 2467264] F:\Cópia de camera 239.jpg

[26/09/2011 - 19:39:48 | N | 2452000] F:\Cópia de camera 238.jpg

[26/09/2011 - 19:39:46 | N | 2410206] F:\Cópia de camera 237.jpg

[26/09/2011 - 19:39:44 | N | 1796165] F:\Cópia de camera 236.jpg

[26/09/2011 - 19:39:44 | N | 1936754] F:\Cópia de camera 235.jpg

[26/09/2011 - 19:39:42 | N | 2001198] F:\Cópia de camera 234.jpg

[26/09/2011 - 19:39:42 | N | 2426183] F:\Cópia de camera 233.jpg

[26/09/2011 - 19:39:40 | N | 2469603] F:\Cópia de camera 232.jpg

[26/09/2011 - 19:39:38 | N | 2468831] F:\Cópia de camera 231.jpg

[26/09/2011 - 19:39:38 | N | 2088919] F:\Cópia de camera 230.jpg

[26/09/2011 - 19:39:36 | N | 2171110] F:\Cópia de camera 229.jpg

[26/09/2011 - 19:39:34 | N | 2461574] F:\Cópia de camera 228.jpg

[26/09/2011 - 19:39:34 | N | 2396838] F:\Cópia de camera 227.jpg

[26/09/2011 - 19:39:32 | N | 2465877] F:\Cópia de camera 226.jpg

[26/09/2011 - 19:39:30 | N | 1807985] F:\Cópia de camera 225.jpg

[26/09/2011 - 19:39:30 | N | 2002372] F:\Cópia de camera 224.jpg

[18/08/2011 - 18:56:20 | D ] F:\SONS

[15/07/2010 - 11:19:16 | D ] F:\ZKLinux

[26/09/2011 - 19:39:28 | N | 1887644] F:\Cópia de camera 223.jpg

[18/08/2011 - 18:57:10 | D ] F:\IMAGENS

[16/07/2010 - 12:29:18 | D ] F:\ZK_PaiG

[18/08/2011 - 18:51:52 | D ] F:\Documentos

[26/09/2011 - 19:39:28 | N | 2426259] F:\Cópia de camera 222.jpg

[26/09/2011 - 19:39:26 | N | 867640] F:\Cópia de camera 221.jpg

[26/09/2011 - 19:39:24 | N | 958681] F:\Cópia de camera 220.jpg

[23/03/2011 - 19:27:44 | D ] F:\Rubia

[26/09/2011 - 19:39:24 | N | 1979654] F:\Cópia de camera 219.jpg

[26/09/2011 - 19:39:22 | N | 1911633] F:\Cópia de camera 218.jpg

[26/09/2011 - 19:39:20 | N | 1945053] F:\Cópia de camera 217.jpg

[26/09/2011 - 19:39:20 | N | 1948355] F:\Cópia de camera 216.jpg

[26/09/2011 - 19:39:18 | N | 2377805] F:\Cópia de camera 215.jpg

[26/09/2011 - 19:39:18 | N | 1908853] F:\Cópia de camera 214.jpg

[26/09/2011 - 19:39:16 | N | 2372550] F:\Cópia de camera 213.jpg

[26/09/2011 - 19:39:14 | N | 1972013] F:\Cópia de camera 212.jpg

[26/09/2011 - 19:39:14 | N | 2484601] F:\Cópia de camera 211.jpg

[26/09/2011 - 19:39:12 | N | 2221718] F:\Cópia de camera 210.jpg

[26/09/2011 - 19:39:10 | N | 2449181] F:\Cópia de camera 209.jpg

[26/09/2011 - 19:39:10 | N | 2204261] F:\Cópia de camera 208.jpg

[26/09/2011 - 19:39:08 | N | 2494937] F:\Cópia de camera 207.jpg

[26/09/2011 - 19:39:08 | N | 1997681] F:\Cópia de camera 206.jpg

[26/09/2011 - 19:39:06 | N | 2010028] F:\Cópia de camera 205.jpg

[26/09/2011 - 19:39:04 | N | 1997006] F:\Cópia de camera 204.jpg

[26/09/2011 - 19:39:04 | N | 2010105] F:\Cópia de camera 203.jpg

[26/09/2011 - 19:39:02 | N | 1941913] F:\Cópia de camera 202.jpg

[26/09/2011 - 19:39:00 | N | 1798163] F:\Cópia de camera 201.jpg

[26/09/2011 - 19:39:00 | N | 1593900] F:\Cópia de camera 200.jpg

[26/09/2011 - 19:38:58 | N | 1759027] F:\Cópia de camera 199.jpg

[26/09/2011 - 19:38:56 | N | 1623387] F:\Cópia de camera 198.jpg

[26/09/2011 - 19:38:56 | N | 1864091] F:\Cópia de camera 197.jpg

[26/09/2011 - 19:38:54 | N | 1997508] F:\Cópia de camera 196.jpg

[26/09/2011 - 19:38:54 | N | 2086697] F:\Cópia de camera 195.jpg

[26/09/2011 - 19:38:52 | N | 2040273] F:\Cópia de camera 194.jpg

[26/09/2011 - 19:38:50 | N | 1957179] F:\Cópia de camera 193.jpg

[26/09/2011 - 19:38:50 | N | 2436578] F:\Cópia de camera 192.jpg

[26/09/2011 - 19:38:48 | N | 2589643] F:\Cópia de camera 191.jpg

[26/09/2011 - 19:38:46 | N | 2083454] F:\Cópia de camera 190.jpg

[26/09/2011 - 19:38:46 | N | 1609191] F:\Cópia de camera 189.jpg

[26/09/2011 - 19:38:44 | N | 2035407] F:\Cópia de Cópia de camera 187.jpg

[26/09/2011 - 19:34:54 | N | 2456579] F:\Cópia de Cópia de camera 005.jpg

[26/09/2011 - 19:34:54 | N | 1984602] F:\Cópia de Cópia de camera 006.jpg

[26/09/2011 - 19:34:56 | N | 1997129] F:\Cópia de Cópia de camera 007.jpg

[26/09/2011 - 19:34:58 | N | 2059299] F:\Cópia de Cópia de camera 008.jpg

[26/09/2011 - 19:34:58 | N | 2034167] F:\Cópia de Cópia de camera 009.jpg

[26/09/2011 - 19:35:00 | N | 2415760] F:\Cópia de Cópia de camera 011.jpg

[26/09/2011 - 19:35:08 | N | 2456166] F:\Cópia de Cópia de camera 016.jpg

[26/09/2011 - 19:35:08 | N | 2482857] F:\Cópia de Cópia de camera 017.jpg

[26/09/2011 - 19:35:10 | N | 2082292] F:\Cópia de Cópia de camera 018.jpg

[26/09/2011 - 19:35:12 | N | 2054371] F:\Cópia de Cópia de camera 020.jpg

[26/09/2011 - 19:35:14 | N | 2448079] F:\Cópia de Cópia de camera 021.jpg

[26/09/2011 - 19:35:20 | N | 2417111] F:\Cópia de Cópia de camera 027.jpg

[26/09/2011 - 19:35:22 | N | 2482816] F:\Cópia de Cópia de camera 028.jpg

[26/09/2011 - 19:35:24 | N | 2401835] F:\Cópia de Cópia de camera 029.jpg

[26/09/2011 - 19:35:24 | N | 1940469] F:\Cópia de Cópia de camera 030.jpg

[26/09/2011 - 19:35:30 | N | 2466435] F:\Cópia de Cópia de camera 035.jpg

[26/09/2011 - 19:39:52 | N | 1853024] F:\Cópia de camera 241.jpg

[05/04/2011 - 10:36:58 | D ] F:\PIXresizer

[05/04/2011 - 12:52:12 | RSHD ] F:\RECYCLER

[26/09/2011 - 19:35:34 | N | 2187559] F:\Cópia de Cópia de camera 037.jpg

[26/09/2011 - 19:35:34 | N | 2166355] F:\Cópia de Cópia de camera 038.jpg

[26/09/2011 - 19:35:38 | N | 2412288] F:\Cópia de Cópia de camera 040.jpg

[26/09/2011 - 19:35:42 | N | 2023986] F:\Cópia de Cópia de camera 044.jpg

[26/09/2011 - 19:35:44 | N | 2391995] F:\Cópia de Cópia de camera 045.jpg

[26/09/2011 - 19:35:44 | N | 2016912] F:\Cópia de Cópia de camera 046.jpg

[26/09/2011 - 19:35:46 | N | 2074356] F:\Cópia de Cópia de camera 047.jpg

[26/09/2011 - 19:35:48 | N | 2492202] F:\Cópia de Cópia de camera 048.jpg

[26/09/2011 - 19:35:48 | N | 2069906] F:\Cópia de Cópia de camera 049.jpg

[26/09/2011 - 19:35:50 | N | 2406743] F:\Cópia de Cópia de camera 050.jpg

[26/09/2011 - 19:35:52 | N | 1905934] F:\Cópia de Cópia de camera 051.jpg

[26/09/2011 - 19:35:52 | N | 2386709] F:\Cópia de Cópia de camera 052.jpg

[26/09/2011 - 19:36:02 | N | 2070514] F:\Cópia de Cópia de camera 060.jpg

[26/09/2011 - 19:36:04 | N | 2415197] F:\Cópia de Cópia de camera 062.jpg

[26/09/2011 - 19:36:06 | N | 2438707] F:\Cópia de Cópia de camera 063.jpg

[26/09/2011 - 19:36:08 | N | 1956330] F:\Cópia de Cópia de camera 064.jpg

[26/09/2011 - 19:36:08 | N | 2446790] F:\Cópia de Cópia de camera 065.jpg

[26/09/2011 - 19:36:10 | N | 2047768] F:\Cópia de Cópia de camera 066.jpg

[26/09/2011 - 19:36:12 | N | 2372875] F:\Cópia de Cópia de camera 068.jpg

[26/09/2011 - 19:36:14 | N | 2376088] F:\Cópia de Cópia de camera 069.jpg

[26/09/2011 - 19:36:14 | N | 2018339] F:\Cópia de Cópia de camera 070.jpg

[26/09/2011 - 19:36:16 | N | 2456069] F:\Cópia de Cópia de camera 071.jpg

[26/09/2011 - 19:36:18 | N | 2471884] F:\Cópia de Cópia de camera 072.jpg

[26/09/2011 - 19:37:08 | N | 2412190] F:\Cópia de Cópia de camera 111.jpg

[26/09/2011 - 19:37:08 | N | 2385546] F:\Cópia de Cópia de camera 112.jpg

[26/09/2011 - 19:37:10 | N | 2380036] F:\Cópia de Cópia de camera 114.jpg

[26/09/2011 - 19:37:12 | N | 1871001] F:\Cópia de Cópia de camera 115.jpg

[26/09/2011 - 19:37:18 | N | 2440077] F:\Cópia de Cópia de camera 119.jpg

[26/09/2011 - 19:37:30 | N | 1913601] F:\Cópia de Cópia de camera 130.jpg

[26/09/2011 - 19:37:32 | N | 2034003] F:\Cópia de Cópia de camera 131.jpg

[26/09/2011 - 19:37:46 | N | 2444185] F:\Cópia de Cópia de camera 142.jpg

[26/09/2011 - 19:37:48 | N | 2397035] F:\Cópia de Cópia de camera 143.jpg

[26/09/2011 - 19:37:48 | N | 2518265] F:\Cópia de Cópia de camera 144.jpg

[26/09/2011 - 19:37:50 | N | 2484480] F:\Cópia de Cópia de camera 145.jpg

[26/09/2011 - 19:38:14 | N | 2370632] F:\Cópia de Cópia de camera 164.jpg

[26/09/2011 - 19:38:14 | N | 2435705] F:\Cópia de Cópia de camera 165.jpg

[26/09/2011 - 19:40:54 | N | 4567159] F:\camera 284.jpg

[26/09/2011 - 19:40:56 | N | 4707829] F:\camera 285.jpg

[26/09/2011 - 19:40:56 | N | 4329469] F:\camera 286.jpg

[26/09/2011 - 19:40:58 | N | 5311088] F:\camera 287.jpg

[26/09/2011 - 19:41:00 | N | 3192537] F:\camera 288.jpg

[26/09/2011 - 19:41:00 | N | 3695506] F:\camera 289.jpg

[26/09/2011 - 19:41:02 | N | 3473381] F:\camera 290.jpg

[26/09/2011 - 19:41:04 | N | 3845536] F:\camera 291.jpg

[26/09/2011 - 19:41:06 | N | 3491060] F:\camera 292.jpg

[26/09/2011 - 19:41:06 | N | 3521812] F:\camera 293.jpg

[26/09/2011 - 19:41:08 | N | 3488268] F:\camera 294.jpg

[26/09/2011 - 19:41:10 | N | 3678792] F:\camera 295.jpg

[26/09/2011 - 19:41:10 | N | 3465694] F:\camera 296.jpg

[26/09/2011 - 19:41:12 | N | 3637326] F:\camera 297.jpg

[26/09/2011 - 19:41:14 | N | 3522816] F:\camera 298.jpg

[26/09/2011 - 19:41:14 | N | 3613747] F:\camera 299.jpg

[26/09/2011 - 19:41:16 | N | 3886285] F:\camera 300.jpg

[26/09/2011 - 19:41:18 | N | 4504678] F:\camera 301.jpg

[27/02/2011 - 11:55:48 | D ] F:\BlocoNotas

 

################## | Vaccin |

 

C:\Autorun.inf -> Vacina criada por UsbFix (El Desaparecido)

E:\Autorun.inf -> Vacina criada por UsbFix (El Desaparecido)

F:\Autorun.inf -> Vacina criada por UsbFix (El Desaparecido)

 

################## | Upload |

 

Favor enviar o arquivo: C:\UsbFix_Upload_Me_CASA.zip

http://eldesaparecido.com/upload.htmlp

Obrigado pela sua contribuição.

 

################## | Reboot |

 

(!) O computar foi reiniciado.

 

################## | E.O.F |

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

Favor enviar o arquivo C:\UsbFix_Upload_Me_CASA.zip para o link abaixo:

http://eldesaparecido.com/upload.htmlp

Obrigado pela sua contribuição.

 

2.

*Execute o UsbFix e clique [uninstall]

*Delete o arquivo C:\UsbFix_Upload_Me_CASA.zip

 

O autorun da porta USB foi desativado pelo USBFix. Isso é uma medida preventiva. Deseja ativá-lo novamente?

 

3.

*Atualize o Windows instalando o SP3

 

4.

Atualize o Java

*Baixe o JavaRa

*Extraia para o desktop

*Execute-o e clique [search For Updates]

*Selecione Update Using jucheck.exe e clique [search]

*Aguarde o término do download e da instalação, e em seguida, clique [Remove Older Versions]

 

5.

*Seu Firefox está desatualizado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.