ComboFix 08-11-10.01 - Julinho 2008-11-11 13:14:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.2220 [GMT -2:00]
Executando de: d:\programas\ComboFix.exe
* Criado um novo ponto de restauro
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ISODRIVE
-------\Service_ISODrive
(((((((((((((((( Arquivos/Ficheiros criados de 2008-10-11 to 2008-11-11 ))))))))))))))))))))))))))))
.
2008-11-11 13:00 . 2008-11-11 13:07 <DIR> d-------- c:\arquivos de programas\UsbFix
2008-11-11 12:39 . 2008-11-11 12:38 109,736 -r-hs---- C:\lky.exe
2008-11-11 12:38 . 2008-11-11 12:38 85,504 -r-hs---- c:\windows\system32\gasretyw1.dll
2008-11-10 14:49 . 2008-11-10 14:49 <DIR> d--hs---- c:\windows\ftpcache
2008-11-10 01:14 . 2008-07-10 04:07 7,143 --a------ c:\windows\system32\nvide.nvu
2008-11-10 00:46 . 2008-11-10 00:46 <DIR> d-------- c:\documents and settings\Julinho\SystemRequirementsLab
2008-11-10 00:46 . 2008-11-10 00:49 <DIR> d-------- c:\arquivos de programas\SystemRequirementsLab
2008-11-09 23:01 . 2008-11-11 12:38 109,736 -r-hs---- c:\windows\system32\kamsoft.exe
2008-11-09 23:01 . 2008-11-10 22:20 108,271 -r-hs---- C:\whi.com
2008-11-09 23:01 . 2008-11-11 12:37 85,504 --------- c:\windows\system32\gasretyw0.dll
2008-11-08 21:22 . 2008-10-10 04:52 4,379,984 --a------ c:\windows\system32\D3DX9_40.dll
2008-11-08 21:22 . 2008-10-10 04:52 2,036,576 --a------ c:\windows\system32\D3DCompiler_40.dll
2008-11-08 21:22 . 2008-10-27 10:04 514,384 --a------ c:\windows\system32\XAudio2_3.dll
2008-11-08 21:22 . 2008-10-10 04:52 452,440 --a------ c:\windows\system32\d3dx10_40.dll
2008-11-08 21:22 . 2008-10-27 10:04 235,856 --a------ c:\windows\system32\xactengine3_3.dll
2008-11-08 21:22 . 2008-10-27 10:04 70,992 --a------ c:\windows\system32\XAPOFX1_2.dll
2008-11-08 21:22 . 2008-10-27 10:04 23,376 --a------ c:\windows\system32\X3DAudio1_5.dll
2008-11-08 17:40 . 2008-11-08 17:40 <DIR> d-------- c:\arquivos de programas\RocketDock
2008-11-06 21:06 . 2008-11-06 21:06 <DIR> d-------- c:\windows\SHELLNEW
2008-11-06 21:06 . 2003-06-19 01:31 17,920 --a------ c:\windows\system32\mdimon.dll
2008-11-06 21:06 . 2008-11-06 21:06 421 --a------ c:\windows\ODBC.INI
2008-11-06 21:05 . 2008-11-06 21:05 <DIR> d-------- c:\arquivos de programas\Microsoft.NET
2008-11-06 20:52 . 2008-11-06 20:52 <DIR> d-------- c:\documents and settings\Julinho\Contacts
2008-11-04 13:31 . 2008-11-04 13:31 2,910 --a------ c:\windows\system32\ealregsnapshot1.reg
2008-11-04 01:56 . 2008-11-04 01:56 208 --ah----- C:\sqmdata01.sqm
2008-11-04 01:56 . 2008-11-04 01:56 172 --ah----- C:\sqmnoopt01.sqm
2008-11-04 01:55 . 2008-11-04 01:55 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-11-04 01:55 . 2008-11-04 01:55 268 --ah----- C:\sqmdata00.sqm
2008-11-04 01:55 . 2008-11-04 01:55 244 --ah----- C:\sqmnoopt00.sqm
2008-11-04 01:29 . 2008-11-04 01:54 <DIR> d-------- c:\arquivos de programas\Windows Live
2008-11-04 01:26 . 2008-11-04 01:54 <DIR> d--hsc--- c:\arquivos de programas\Arquivos comuns\WindowsLiveInstaller
2008-11-04 01:25 . 2008-11-04 01:29 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\WLInstaller
2008-11-02 23:33 . 2008-11-03 01:26 <DIR> d-------- c:\arquivos de programas\MoorHunt
2008-11-02 14:01 . 2008-11-02 14:01 <DIR> d-------- c:\documents and settings\Julinho\Dados de aplicativos\Nero
2008-10-30 12:56 . 2005-01-14 02:41 11,254 --a------ c:\windows\system32\locate.com
2008-10-29 22:34 . 2008-10-29 22:34 <DIR> d-------- c:\windows\system32\xlive
2008-10-29 20:59 . 2008-10-29 20:59 <DIR> d-------- c:\arquivos de programas\Trend Micro
2008-10-29 18:27 . 2008-10-29 18:27 <DIR> d-------- c:\arquivos de programas\RivaTuner v2.10
2008-10-29 17:02 . 2008-10-29 20:55 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Avira
2008-10-29 13:08 . 2008-10-31 07:39 <DIR> d--h----- c:\windows\$hf_mig$
2008-10-29 00:16 . 2008-10-29 12:39 454 --a------ C:\autorun.MSNFix
2008-10-29 00:15 . 2008-10-29 12:42 105,339 --a------ c:\windows\system32\ckvo.MSNFix
2008-10-29 00:15 . 2008-04-13 11:45 32,128 --a------ c:\windows\system32\drivers\usbccgp.sys
2008-10-28 16:19 . 2008-10-28 16:19 <DIR> d-------- c:\documents and settings\Julinho\Shaders
2008-10-25 18:46 . 2008-10-25 18:46 <DIR> d-------- c:\windows\Sun
2008-10-25 18:44 . 2008-10-25 18:44 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Ubisoft
2008-10-25 13:45 . 2008-10-25 13:45 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-10-20 23:57 . 2008-10-20 23:57 <DIR> d-------- c:\windows\74224F8D4A1748169EDB7BB854DE532C.TMP
2008-10-18 18:54 . 2008-10-18 18:54 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\KONAMI
2008-10-16 23:55 . 2008-11-10 19:43 138,464 --a------ c:\windows\system32\drivers\PnkBstrK.sys
2008-10-16 23:55 . 2008-11-10 15:05 22,328 --a------ c:\documents and settings\Julinho\Dados de aplicativos\PnkBstrK.sys
2008-10-16 23:54 . 2008-11-10 15:04 682,280 --a------ c:\windows\system32\pbsvc.exe
2008-10-16 23:54 . 2008-11-10 19:43 111,928 --a------ c:\windows\system32\PnkBstrB.exe
2008-10-16 23:54 . 2008-11-10 15:04 66,872 --a------ c:\windows\system32\PnkBstrA.exe
2008-10-16 23:06 . 2008-11-02 02:10 <DIR> d-------- c:\arquivos de programas\Valve
2008-10-16 21:44 . 2008-04-13 12:45 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2008-10-16 21:44 . 2008-04-13 12:45 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2008-10-16 21:39 . 2008-10-16 21:39 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Codemasters
2008-10-16 16:17 . 2008-10-16 16:17 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\vsosdk
2008-10-16 15:27 . 2008-04-13 12:45 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-10-16 13:50 . 2008-10-16 13:50 <DIR> d-------- c:\windows\system32\AGEIA
2008-10-16 13:50 . 2008-10-16 13:50 <DIR> d-------- c:\arquivos de programas\AGEIA Technologies
2008-10-16 13:49 . 2008-10-20 23:57 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard
2008-10-16 13:49 . 2008-10-07 14:33 453,152 --a------ c:\windows\system32\nvudisp.exe
2008-10-16 13:49 . 2008-10-07 14:33 201,157 --a------ c:\windows\system32\nvapps.nvb
2008-10-16 13:49 . 2008-10-07 14:33 18,477 --a------ c:\windows\system32\nvdisp.nvu
2008-10-16 01:20 . 2008-10-16 23:57 <DIR> d-------- c:\arquivos de programas\GameVicio
2008-10-16 01:16 . 2008-10-16 01:16 <DIR> d-------- c:\arquivos de programas\OpenAL
2008-10-16 01:16 . 2008-04-28 16:53 805,400 -ra------ c:\windows\system32\tmpFF.tmp
2008-10-16 01:16 . 2008-04-28 16:53 805,400 -ra------ c:\windows\system32\tmpFE.tmp
2008-10-16 01:16 . 2008-10-16 01:16 444,952 --a------ c:\windows\system32\wrap_oal.dll
2008-10-16 01:16 . 2008-10-16 01:16 109,080 --a------ c:\windows\system32\OpenAL32.dll
2008-10-16 00:17 . 2008-11-10 15:04 <DIR> d--h----- c:\arquivos de programas\InstallShield Installation Information
2008-10-15 23:54 . 2008-11-10 18:45 <DIR> d-a------ c:\documents and settings\All Users\Dados de aplicativos\TEMP
2008-10-15 23:25 . 2008-11-09 16:23 <DIR> d-------- c:\documents and settings\Julinho\Dados de aplicativos\Bioshock
2008-10-15 22:47 . 2008-10-15 22:47 <DIR> d-------- c:\documents and settings\Julinho\Dados de aplicativos\Ashampoo
2008-10-15 22:40 . 2008-10-28 16:04 <DIR> d-------- c:\documents and settings\Julinho\Dados de aplicativos\InstallShield Installation Information
2008-10-15 22:40 . 2008-10-15 22:40 <DIR> d-------- c:\documents and settings\Julinho\Dados de aplicativos\InstallShield
2008-10-14 19:07 . 2008-11-10 19:29 <DIR> dr------- C:\Musicas
2008-10-14 13:19 . 2008-10-14 13:19 <DIR> d-------- C:\temp
2008-10-14 00:52 . 2008-10-14 00:52 <DIR> d-------- C:\Program Files
2008-10-13 01:54 . 2008-10-13 01:54 <DIR> d-------- c:\arquivos de programas\Java
2008-10-13 01:54 . 2008-06-10 03:32 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-10-13 01:41 . 2008-10-13 01:41 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Java
2008-10-13 00:53 . 2007-03-07 21:51 129,784 --------- c:\windows\system32\pxafs.dll
2008-10-13 00:53 . 2007-03-07 21:51 43,528 --------- c:\windows\system32\drivers\PxHelp20.sys
2008-10-13 00:53 . 2007-03-07 21:51 9,464 --------- c:\windows\system32\drivers\cdralw2k.sys
2008-10-13 00:53 . 2007-03-07 21:51 9,336 --------- c:\windows\system32\drivers\cdr4_xp.sys
2008-10-13 00:52 . 2008-10-13 00:54 <DIR> d-------- c:\documents and settings\Julinho\Dados de aplicativos\Winamp
2008-10-13 00:52 . 2008-10-13 00:54 <DIR> d-------- c:\arquivos de programas\Winamp
2008-10-12 23:47 . 2008-11-10 14:37 69 --a------ c:\windows\NeroDigital.ini
2008-10-12 23:46 . 2008-10-12 23:46 <DIR> d-------- c:\documents and settings\Julinho\Dados de aplicativos\Media Player Classic
2008-10-12 23:36 . 2008-11-11 13:19 <DIR> d-------- c:\documents and settings\Julinho\Dados de aplicativos\uTorrent
2008-10-12 23:36 . 2008-10-12 23:36 <DIR> d-------- c:\arquivos de programas\uTorrent
2008-10-12 23:36 . 2007-07-30 20:19 43,352 --a------ c:\windows\system32\wups2.dll
2008-10-12 23:36 . 2007-07-30 20:18 34,136 --a------ c:\windows\system32\wucltui.dll.mui
2008-10-12 23:36 . 2007-07-30 20:20 30,040 --a------ c:\windows\system32\wuaucpl.cpl.mui
2008-10-12 23:36 . 2007-07-30 20:20 30,040 --a------ c:\windows\system32\wuapi.dll.mui
2008-10-12 23:36 . 2007-07-30 20:18 20,824 --a------ c:\windows\system32\wuaueng.dll.mui
2008-10-12 23:35 . 2008-11-10 01:14 <DIR> d-------- C:\NVIDIA
2008-10-12 23:35 . 2008-11-04 13:31 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\InstallShield
2008-10-12 23:35 . 2008-08-20 18:35 453,152 --a------ c:\windows\system32\nvusmb.exe
2008-10-12 23:35 . 2008-10-02 11:07 453,152 --a------ c:\windows\system32\NVUNINST.EXE
2008-10-12 23:35 . 2008-08-19 11:41 2,344 --a------ c:\windows\system32\nvsmb.nvu
2008-10-12 23:29 . 2008-10-12 23:29 <DIR> d---s---- c:\documents and settings\Julinho\UserData
2008-10-12 23:28 . 2008-10-12 23:35 <DIR> d-------- c:\arquivos de programas\LimeWire
2008-10-12 23:28 . 2008-10-12 23:28 <DIR> d-------- c:\arquivos de programas\K-Lite Codec Pack
2008-10-12 23:05 . 2008-10-12 23:05 <DIR> d-------- c:\arquivos de programas\Foxit Software
2008-10-12 23:03 . 2008-10-12 23:03 0 --a------ c:\windows\nsreg.dat
2008-10-12 23:02 . 2008-10-12 23:02 <DIR> d-------- c:\windows\Logs
2008-10-12 23:02 . 2008-11-06 23:33 <DIR> d-------- c:\arquivos de programas\DreaMule
2008-10-12 23:01 . 2008-10-12 23:01 <DIR> d-------- c:\arquivos de programas\Windows Media Connect 2
2008-10-12 23:01 . 2008-10-12 23:01 <DIR> d-------- c:\arquivos de programas\CCleaner
2008-10-12 23:00 . 2008-10-16 23:54 <DIR> d-------- c:\windows\system32\LogFiles
2008-10-12 23:00 . 2008-10-12 23:00 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-10-12 23:00 . 2006-09-25 18:58 23,856 --a------ c:\windows\system32\spupdsvc.exe
2008-10-12 22:59 . 2008-10-12 22:59 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite
2008-10-12 22:56 . 2008-10-12 21:09 <DIR> d--h----- c:\documents and settings\Administrador\Modelos
2008-10-12 22:56 . 2008-10-12 18:04 <DIR> d-------- c:\documents and settings\Administrador\Meus documentos
2008-10-12 22:56 . 2008-10-12 18:04 <DIR> dr------- c:\documents and settings\Administrador\Menu Iniciar
2008-10-12 22:56 . 2008-10-12 18:04 <DIR> d-------- c:\documents and settings\Administrador\Favoritos
2008-10-12 22:56 . 2008-10-30 19:30 <DIR> dr-h----- c:\documents and settings\Administrador\Dados de aplicativos
2008-10-12 22:56 . 2008-10-25 14:37 <DIR> d--h----- c:\documents and settings\Administrador\Configurações locais
2008-10-12 22:56 . 2008-10-12 18:04 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de rede
2008-10-12 22:56 . 2008-10-12 18:04 <DIR> d--h----- c:\documents and settings\Administrador\Ambiente de impressão
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-13 00:51 361,344 ----a-w c:\windows\system32\drivers\TCPIP.SYS
2008-10-12 23:19 --------- d-----w c:\arquivos de programas\Driver-Soft
2008-10-12 23:13 --------- d-----w c:\arquivos de programas\microsoft frontpage
2008-10-12 23:11 --------- d-----w c:\arquivos de programas\Serviços on-line
2008-10-12 23:11 --------- d-----w c:\arquivos de programas\Arquivos comuns\Serviços
2008-10-02 22:50 81,920 ----a-w c:\windows\system32\frapsvid.dll
2008-09-04 12:31 288,024 ----a-w c:\windows\system32\PhysXCplUI.exe
2008-08-29 11:57 70,936 ----a-w c:\windows\system32\PhysXLoader.dll
2008-08-20 20:35 122,880 ----a-w c:\windows\system32\NVCOSMB.DLL
.
((((((((((((((((((((((((((((( snapshot@2008-10-25_14.37.09,32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-06 23:06:01 110,592 ----a-w c:\windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
- 2008-10-25 15:44:08 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-11-08 23:22:08 53,248 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2008-10-25 15:44:08 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-11-08 23:22:08 12,800 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2008-10-25 15:44:08 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-11-08 23:22:08 473,600 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2008-10-25 15:44:05 2,676,224 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 23:22:03 2,676,224 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-10-25 15:44:06 2,846,720 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 23:22:04 2,846,720 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-10-25 15:44:06 563,712 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 23:22:05 563,712 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-10-25 15:44:06 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 23:22:05 567,296 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-10-25 15:44:07 576,000 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 23:22:05 576,000 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-10-25 15:44:07 577,024 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 23:22:06 577,024 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-10-25 15:44:07 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 23:22:06 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-10-25 15:44:07 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 23:22:07 577,536 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-10-25 15:44:07 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 23:22:07 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-10-25 15:44:08 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-11-08 23:22:09 578,560 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-10-25 15:44:09 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-11-08 23:22:09 145,920 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2008-10-25 15:44:09 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-11-08 23:22:09 159,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2008-10-25 15:44:09 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-11-08 23:22:09 364,544 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2008-10-25 15:44:09 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-11-08 23:22:10 178,176 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2008-10-25 15:44:08 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-11-08 23:22:08 223,232 ----a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-11-06 23:06:01 64,088 ----a-w c:\windows\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2008-11-06 23:06:01 229,376 ----a-w c:\windows\assembly\GAC\mscomctl\10.0.4504.0__31bf3856ad364e35\MSCOMCTL.DLL
+ 2008-11-06 23:06:01 4,096 ----a-w c:\windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2008-11-06 23:06:01 223,800 ----a-w c:\windows\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2008-11-06 23:06:02 16,384 ----a-w c:\windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
+ 2005-10-20 22:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2008-11-04 15:30:27 15,086 ----a-r c:\windows\Installer\{4D87DC92-C328-46EC-A7B4-9C88129DC696}\DS_48.exe
+ 2008-11-04 15:30:28 4,374,792 ----a-r c:\windows\Installer\{4D87DC92-C328-46EC-A7B4-9C88129DC696}\EAregister.exe
+ 2008-10-30 00:52:55 136,914 ----a-r c:\windows\Installer\{6FCFA783-CE7B-4018-AC48-0E6EEAAEA322}\ARPPRODUCTICON.exe
+ 2008-10-30 00:52:55 176,128 ----a-r c:\windows\Installer\{6FCFA783-CE7B-4018-AC48-0E6EEAAEA322}\LPCLauncher.exe_6FCFA783CE7B4018AC480E6EEAAEA322.exe
+ 2008-10-30 00:52:55 176,128 ----a-r c:\windows\Installer\{6FCFA783-CE7B-4018-AC48-0E6EEAAEA322}\LPCLauncher.exe1_6FCFA783CE7B4018AC480E6EEAAEA322.exe
+ 2008-11-04 03:54:44 29,926 ----a-r c:\windows\Installer\{8EADB73B-026D-4978-A8F0-1EEF5E1ECEC7}\MsblIco.Exe
+ 2008-11-06 23:06:36 593,920 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-11-06 23:06:36 12,288 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-11-06 23:06:36 86,016 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-11-06 23:06:36 135,168 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-11-06 23:06:36 11,264 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-11-06 23:06:36 27,136 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-11-06 23:06:36 4,096 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-11-06 23:06:36 794,624 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-11-06 23:06:36 249,856 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-11-06 23:06:36 61,440 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-11-06 23:06:36 23,040 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-11-06 23:06:36 286,720 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-11-06 23:06:36 409,600 ----a-r c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-10-28 18:04:40 25,214 ----a-r c:\windows\Installer\{A724605D-B399-4304-B8C7-33B3EF7D4677}\ARPPRODUCTICON.exe
+ 2008-10-28 18:04:40 25,214 ----a-r c:\windows\Installer\{A724605D-B399-4304-B8C7-33B3EF7D4677}\Shortcut_Bully_EFI_A786D89EB9F04DED932F18E487236621.exe
+ 2008-11-10 17:04:38 11,502 ----a-r c:\windows\Installer\{D80A6A73-E58A-4673-AFF5-F12D7110661F}\ARPPRODUCTICON.exe
+ 2008-08-18 20:54:00 145,952 ----a-w c:\windows\system32\drivers\nvgts.sys
+ 2003-08-03 20:56:16 1,146,184 ----a-w c:\windows\system32\FM20.DLL
+ 2003-08-18 13:47:42 41,616 ----a-w c:\windows\system32\FM20PTB.DLL
+ 2001-01-23 03:05:06 28,944 ----a-w c:\windows\system32\FM20PTG.DLL
- 2008-10-12 23:16:16 91,088 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-11-07 14:22:22 110,992 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2002-08-21 07:10:16 204,800 ----a-w c:\windows\system32\INKED.DLL
+ 2008-03-20 20:06:36 1,480,232 ------w c:\windows\system32\LegitCheckControl.dll
+ 2008-03-25 02:32:44 218,496 ----a-r c:\windows\system32\Macromed\Flash\FlashUtil9f.exe
+ 2008-11-04 15:31:17 74,137 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 1999-05-10 20:08:20 57,344 ----a-w c:\windows\system32\MFC42PTB.DLL
+ 1999-05-18 17:16:48 7,680 ----a-w c:\windows\system32\MSPRPPTB.DLL
+ 2000-05-11 15:06:20 397,312 ----a-w c:\windows\system32\MSRDO20.DLL
+ 2000-05-24 08:45:58 118,784 ----a-w c:\windows\system32\MSSTDFMT.DLL
+ 1998-08-09 21:07:34 94,208 ----a-w c:\windows\system32\MSSTKPRP.DLL
+ 2007-07-30 21:18:34 207,736 ----a-w c:\windows\system32\muweb.dll
+ 2008-08-18 20:54:00 372,256 ----a-w c:\windows\system32\nvraidco.dll
+ 2008-08-18 20:54:00 372,256 ----a-w c:\windows\system32\nvraiins.dll
+ 2008-08-18 20:54:00 15,904 ----a-w c:\windows\system32\NvRCoAr.dll
+ 2008-08-18 20:54:00 15,904 ----a-w c:\windows\system32\NvRCoCs.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoDa.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoDe.dll
+ 2008-08-18 20:54:00 16,928 ----a-w c:\windows\system32\NvRCoEl.dll
+ 2008-08-18 20:54:00 15,904 ----a-w c:\windows\system32\NvRCoEng.dll
+ 2008-08-18 20:54:00 15,904 ----a-w c:\windows\system32\NvRCoENU.dll
+ 2008-08-18 20:54:00 16,928 ----a-w c:\windows\system32\NvRCoEs.dll
+ 2008-08-18 20:54:00 16,928 ----a-w c:\windows\system32\NvRCoEsm.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoFi.dll
+ 2008-08-18 20:54:00 16,928 ----a-w c:\windows\system32\NvRCoFr.dll
+ 2008-08-18 20:54:00 15,392 ----a-w c:\windows\system32\NvRCoHe.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoHu.dll
+ 2008-08-18 20:54:00 16,928 ----a-w c:\windows\system32\NvRCoIt.dll
+ 2008-08-18 20:54:00 14,880 ----a-w c:\windows\system32\NvRCoJa.dll
+ 2008-08-18 20:54:00 14,368 ----a-w c:\windows\system32\NvRCoKo.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoNl.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoNo.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoPl.dll
+ 2008-08-18 20:54:00 16,928 ----a-w c:\windows\system32\NvRCoPt.dll
+ 2008-08-18 20:54:00 16,928 ----a-w c:\windows\system32\NvRCoPtb.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoRu.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoSk.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoSl.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoSv.dll
+ 2008-08-18 20:54:00 15,904 ----a-w c:\windows\system32\NvRCoTh.dll
+ 2008-08-18 20:54:00 16,416 ----a-w c:\windows\system32\NvRCoTr.dll
+ 2008-08-18 20:54:00 13,856 ----a-w c:\windows\system32\NvRCoZhc.dll
+ 2008-08-18 20:54:00 13,856 ----a-w c:\windows\system32\NvRCoZht.dll
+ 2000-04-03 19:52:54 151,552 ----a-w c:\windows\system32\RDOCURS.DLL
+ 2008-04-14 12:00:00 96,512 ----a-w c:\windows\system32\ReinstallBackups\
0077\DriverFiles\i386\atapi.sys
+ 2008-04-14 12:00:00 3,456 ----a-w c:\windows\system32\ReinstallBackups\
0077\DriverFiles\i386\pciide.sys
+ 2008-04-14 12:00:00 24,960 ----a-w c:\windows\system32\ReinstallBackups\
0077\DriverFiles\i386\pciidex.sys
+ 2008-04-14 12:00:00 96,512 ----a-w c:\windows\system32\ReinstallBackups\
0078\DriverFiles\i386\atapi.sys
+ 2008-04-14 12:00:00 3,456 ----a-w c:\windows\system32\ReinstallBackups\
0078\DriverFiles\i386\pciide.sys
+ 2008-04-14 12:00:00 24,960 ----a-w c:\windows\system32\ReinstallBackups\
0078\DriverFiles\i386\pciidex.sys
+ 1998-03-25 07:54:08 15,872 ----a-w c:\windows\system32\SCP32.DLL
+ 2007-10-18 13:31:46 51,224 ----a-w c:\windows\system32\sirenacm.dll
- 2006-09-25 20:58:48 14,640 ------w c:\windows\system32\spmsg.dll
+ 2008-03-20 16:41:20 14,640 ------w c:\windows\system32\spmsg.dll
+ 2003-06-19 03:31:44 758,784 ----a-w c:\windows\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2003-06-19 03:31:46 35,328 ----a-w c:\windows\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2003-06-19 03:31:44 758,784 ----a-w c:\windows\system32\spool\drivers\w32x86\mdigraph.dll
+ 2003-06-19 03:31:46 35,328 ----a-w c:\windows\system32\spool\drivers\w32x86\mdiui.dll
+ 2003-06-19 03:31:48 18,944 ----a-w c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
+ 1999-11-25 04:40:50 40,960 ----a-w c:\windows\system32\VBAME.DLL
+ 2002-08-21 07:13:12 189,952 ----a-w c:\windows\system32\WISPTIS.EXE
- 2007-08-07 22:22:14 8,607,552 ----a-w c:\windows\system32\xlive.dll
+ 2007-11-26 23:56:20 10,155,840 ----a-w c:\windows\system32\xlive.dll
+ 2007-09-18 17:01:02 134,144 ----a-w c:\windows\system32\xlive\sqmapi.dll
- 2007-08-07 22:22:16 13,653,824 ----a-w c:\windows\system32\xlivefnt.dll
+ 2007-11-26 23:56:20 13,653,824 ----a-w c:\windows\system32\xlivefnt.dll
+ 2006-06-05 16:14:28 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
+ 2006-06-05 16:14:28 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
+ 2006-06-05 16:14:28 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
.
-- Snapshot resetado para data atual --
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\arquivos de programas\uTorrent\uTorrent.exe" [2008-10-12 219952]
"RocketDock"="c:\arquivos de programas\RocketDock\RocketDock.exe" [2007-09-02 495616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKLM\~\startupfolder\C:^Documents and Settings^Julinho^Menu Iniciar^Programas^Inicializar^Debugger.exe.lnk]
path=c:\documents and settings\Julinho\Menu Iniciar\Programas\Inicializar\Debugger.exe.lnk
backup=c:\windows\pss\Debugger.exe.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-14 10:00 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-07-24 13:02 490952 c:\arquivos de programas\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kamsoft]
-r-hs---- 2008-11-11 12:38 109736 c:\windows\system32\kamsoft.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-10-07 14:33 13574144 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-10-07 14:33 86016 c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a--c--- 2006-12-18 22:34 868352 c:\arquivos de programas\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 05:27 144784 c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-10-07 14:33 1630208 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=
"d:\\Jogos\\Race Driver GRID\\GRID.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Jogos\\Pro Evolution Soccer 2009\\pes2009.exe"=
"c:\\Arquivos de programas\\DreaMule\\emule.exe"=
"d:\\Jogos\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"d:\\Jogos\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"d:\\Programas\\Vdownloader\\VDownloader.exe"=
"d:\\Jogos\\Lost Planet Colonies\\LostPlanetColoniesDX9.exe"=
"d:\\Jogos\\Lost Planet Colonies\\LostPlanetColoniesDX10.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Jogos\\Dead Space\\Dead Space.exe"=
"d:\\Jogos\\Call of Duty - World at War\\CoDWaWmp.exe"=
"d:\\Jogos\\Call of Duty - World at War\\CoDWaW.exe"=
R0 nvgts;nvgts;c:\windows\system32\DRIVERS\nvgts.sys [2008-08-18 145952]
.
.
------- Scan Suplementar -------
.
FireFox -: Profile - c:\documents and settings\Julinho\Dados de aplicativos\Mozilla\Firefox\Profiles\rl9r1z6a.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
FF -: plugin - c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-11 13:19:32
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
------------------------ Outros Processos em Execução ------------------------
.
c:\windows\system32\PnkBstrA.exe
.
**************************************************************************
.
Tempo para conclusão: 2008-11-11 13:20:55 - Máquina reiniciou
ComboFix-quarantined-files.txt 2008-11-11 15:20:52
ComboFix2.txt 2008-10-25 16:37:26
Pré-execução: 231.514.112 bytes disponíveis
Pós execução: 178,839,552 bytes disponíveis
385