ComboFix 09-05-05.03 - Kym3ra 05/05/2009 20:12.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.55.1046.18.3198.2371 [GMT -3:00]
Executando de: c:\users\Kym3ra\Desktop\ComboFix.exe
.
(((((((((((((((( Arquivos/Ficheiros criados de 2009-04-05 to 2009-05-05 ))))))))))))))))))))))))))))
.
2009-05-05 18:18 . 2008-07-31 13:41 68616 ----a-w c:\windows\system32\XAPOFX1_1.dll
2009-05-05 18:18 . 2008-07-31 13:40 509448 ----a-w c:\windows\system32\XAudio2_2.dll
2009-05-05 18:18 . 2008-07-31 13:41 238088 ----a-w c:\windows\system32\xactengine3_2.dll
2009-05-05 18:18 . 2008-07-12 11:18 1493528 ----a-w c:\windows\system32\D3DCompiler_39.dll
2009-05-05 18:18 . 2008-07-12 11:18 467984 ----a-w c:\windows\system32\d3dx10_39.dll
2009-05-05 18:18 . 2008-07-12 11:18 3851784 ----a-w c:\windows\system32\D3DX9_39.dll
2009-05-05 18:18 . 2009-05-05 18:18 -------- d-----w c:\windows\64F6748976BB4CDDA236F954BE774B35.TMP
2009-05-05 17:57 . 2009-05-05 18:19 -------- d-----w c:\program files\Activision
2009-05-05 17:54 . 2009-05-05 17:54 -------- d-sh--w c:\windows\ftpcache
2009-05-05 00:55 . 2009-05-05 02:23 -------- d-----w c:\program files\VS Revo Group
2009-05-05 00:19 . 2009-05-05 00:19 -------- d--h--w c:\users\Kym3ra\AppData\Roaming\Malwarebytes
2009-05-05 00:19 . 2009-04-06 18:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-05 00:19 . 2009-04-06 18:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-05 00:19 . 2009-05-05 00:19 -------- d-----w c:\programdata\Malwarebytes
2009-05-05 00:19 . 2009-05-05 00:19 -------- d-----w c:\users\All Users\Malwarebytes
2009-05-05 00:19 . 2009-05-05 00:19 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-05 00:14 . 2009-05-05 00:14 -------- d-----w c:\program files\e-Softer
2009-05-03 23:38 . 2009-05-03 23:38 -------- d--h--r c:\users\Kym3ra\AppData\Roaming\SecuROM
2009-05-03 23:33 . 2009-05-03 23:33 22328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-05-03 23:33 . 2009-05-03 23:33 22328 ---ha-w c:\users\Kym3ra\AppData\Roaming\PnkBstrK.sys
2009-05-03 23:32 . 2009-05-03 23:32 107832 ----a-w c:\windows\system32\PnkBstrB.exe
2009-05-03 23:32 . 2009-05-03 23:32 66872 ----a-w c:\windows\system32\PnkBstrA.exe
2009-05-03 23:32 . 2009-05-03 23:32 2250024 ----a-w c:\windows\system32\pbsvc.exe
2009-05-03 23:28 . 2009-05-03 23:28 -------- d-----w c:\program files\Ubisoft
2009-05-03 22:53 . 2009-05-04 00:45 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-05-03 22:41 . 2009-05-03 22:41 -------- d-----w c:\program files\Trend Micro
2009-05-02 00:11 . 2009-05-02 00:11 -------- d-----w c:\programdata\wanted
2009-05-02 00:11 . 2009-05-02 00:11 -------- d-----w c:\users\All Users\wanted
2009-05-02 00:11 . 2009-05-02 00:11 -------- d--h--w c:\users\Kym3ra\AppData\Local\wanted
2009-05-01 23:08 . 2009-05-01 23:08 -------- d-----w c:\program files\WarnerBros
2009-04-30 21:17 . 2009-04-30 21:17 -------- d-----w c:\programdata\ATI
2009-04-30 21:17 . 2009-04-30 21:17 -------- d-----w c:\users\All Users\ATI
2009-04-30 21:09 . 2009-04-30 21:11 -------- d-----w c:\program files\ATI Technologies
2009-04-30 21:09 . 2009-05-01 16:49 -------- d-----w c:\program files\ATI
2009-04-30 17:38 . 2009-04-30 18:36 -------- d--h--w c:\users\Kym3ra\AppData\Roaming\LimeWire
2009-04-30 17:38 . 2009-05-03 23:18 -------- d-----w c:\program files\LimeWire
2009-04-28 22:04 . 2009-04-28 22:04 -------- d-----w c:\program files\Common Files\SWF Studio
2009-04-28 00:25 . 2009-05-03 23:18 -------- d-----w c:\program files\uTorrent
2009-04-26 23:00 . 2009-04-26 23:04 -------- d--h--w c:\users\Kym3ra\AppData\Roaming\Ahead
2009-04-26 22:59 . 2009-04-26 22:59 -------- d-----w c:\programdata\Ahead
2009-04-26 22:59 . 2009-04-26 22:59 -------- d-----w c:\users\All Users\Ahead
2009-04-26 22:57 . 2009-04-26 22:57 -------- d-----w c:\program files\Nero
2009-04-26 22:57 . 2009-04-26 22:57 -------- d-----w c:\programdata\Nero
2009-04-26 22:57 . 2009-04-26 22:57 -------- d-----w c:\users\All Users\Nero
2009-04-26 22:57 . 2009-04-26 22:59 -------- d-----w c:\program files\Common Files\Ahead
2009-04-26 22:53 . 2009-05-02 14:51 -------- d-----w c:\program files\GameVicio
2009-04-25 18:21 . 2009-04-26 02:20 -------- d-----w c:\program files\AlphaBrowser
2009-04-24 22:38 . 2009-05-03 23:18 -------- d-----w c:\program files\ZenoClash
2009-04-23 02:19 . 2009-04-23 02:29 -------- d-----w c:\program files\Unreal Tournament 3
2009-04-18 03:52 . 2009-04-18 03:53 -------- d--h--w c:\users\Kym3ra\AppData\Local\Rockstar Games
2009-04-18 03:22 . 2009-04-20 21:02 -------- d-----w c:\program files\Rockstar Games
2009-04-16 16:36 . 2009-05-03 23:18 -------- d-----w c:\program files\CryptLoad_1.1.6
2009-04-16 01:06 . 2009-04-16 01:06 -------- d--h--w c:\users\Kym3ra\AppData\Local\NFS Underground 2
2009-04-14 18:32 . 2009-03-03 04:39 551424 ----a-w c:\windows\system32\rpcss.dll
2009-04-14 18:32 . 2009-03-03 04:46 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-04-14 18:32 . 2009-03-03 04:46 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-04-14 18:32 . 2009-03-03 03:04 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-04-14 18:32 . 2009-03-03 04:39 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-04-14 18:32 . 2009-03-03 04:39 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-04-14 18:32 . 2009-03-03 04:37 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-04-14 18:32 . 2009-03-03 04:37 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-04-14 18:32 . 2009-03-03 04:37 54784 ----a-w c:\windows\system32\iasads.dll
2009-04-14 18:32 . 2009-03-03 02:38 17408 ----a-w c:\windows\system32\iashost.exe
2009-04-14 18:32 . 2008-12-06 04:42 376832 ----a-w c:\windows\system32\winhttp.dll
2009-04-14 18:31 . 2009-02-13 08:49 1255936 ----a-w c:\windows\system32\lsasrv.dll
2009-04-14 18:31 . 2009-02-13 08:49 72704 ----a-w c:\windows\system32\secur32.dll
2009-04-14 18:31 . 2009-03-17 03:38 13824 ----a-w c:\windows\system32\apilogen.dll
2009-04-14 18:31 . 2009-03-17 03:38 24064 ----a-w c:\windows\system32\amxread.dll
2009-04-14 18:31 . 2008-06-06 03:27 562176 ----a-w c:\windows\system32\msdtcprx.dll
2009-04-14 18:31 . 2008-06-06 03:27 38912 ----a-w c:\windows\system32\xolehlp.dll
2009-04-14 02:01 . 2009-04-26 23:25 -------- d-----w c:\program files\Project64 1.6
2009-04-13 19:11 . 2009-04-30 20:18 -------- d-----w c:\users\Kym3ra\.receitanet
2009-04-13 19:10 . 2008-12-23 20:01 69632 ----a-w c:\windows\system32\MSJCE.dll
2009-04-13 19:10 . 2009-04-13 19:10 -------- d-----w c:\program files\Programas RFB
2009-04-13 16:17 . 2009-04-13 16:17 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-13 16:17 . 2009-04-13 16:17 -------- d-----w c:\program files\Java
2009-04-13 16:01 . 2009-04-13 16:01 -------- d-----w C:\Arquivos de Programas RFB
2009-04-12 23:28 . 2009-05-04 00:45 -------- d-----w c:\programdata\Spybot - Search & Destroy
2009-04-12 23:28 . 2009-05-04 00:45 -------- d-----w c:\users\All Users\Spybot - Search & Destroy
2009-04-12 21:51 . 2009-04-12 23:34 -------- d-----w c:\programdata\Kaspersky Lab
2009-04-12 21:51 . 2009-04-12 23:34 -------- d-----w c:\users\All Users\Kaspersky Lab
2009-04-12 21:50 . 2009-04-12 21:50 -------- d-----w c:\programdata\Kaspersky Lab Setup Files
2009-04-12 21:50 . 2009-04-12 21:50 -------- d-----w c:\users\All Users\Kaspersky Lab Setup Files
2009-04-11 01:46 . 2009-04-11 01:46 -------- d-----w c:\programdata\vsosdk
2009-04-11 01:46 . 2009-04-11 01:46 -------- d-----w c:\users\All Users\vsosdk
2009-04-11 01:22 . 2006-05-11 22:21 626688 ----a-w c:\windows\system32\vp7vfw.dll
2009-04-11 01:22 . 2006-05-20 19:16 1184984 ----a-w c:\windows\system32\wvc1dmod.dll
2009-04-10 21:59 . 2009-04-10 21:59 -------- d--h--w c:\users\Kym3ra\AppData\Roaming\Foxit
2009-04-10 21:59 . 2009-04-10 21:59 -------- d-----w c:\program files\Foxit Software
2009-04-09 15:09 . 2009-04-09 15:09 -------- d-----w c:\program files\MSXML 4.0
2009-04-09 14:57 . 2009-05-03 23:18 -------- d-----w c:\program files\Dolphin
2009-04-08 14:22 . 2009-04-08 14:22 -------- d--h--w c:\users\Kym3ra\AppData\Local\EA Games
2009-04-08 14:10 . 2009-04-20 23:22 -------- d-----w c:\program files\EA Games
2009-04-07 20:19 . 2009-04-07 20:19 -------- d-----w c:\program files\Common Files\Hewlett-Packard
2009-04-07 20:18 . 2009-04-07 20:18 -------- d-----w c:\program files\Common Files\HP
2009-04-07 20:11 . 2009-04-07 20:25 148809 ----a-w c:\windows\hpoins19.dat
2009-04-07 20:11 . 2009-04-07 20:25 -------- d-----w c:\programdata\HP
2009-04-07 20:11 . 2009-04-07 20:25 -------- d-----w c:\users\All Users\HP
2009-04-07 20:11 . 2006-11-20 21:36 258048 ----a-w c:\windows\system32\hpzids01.dll
2009-04-07 20:11 . 2006-12-16 06:19 303104 ----a-w c:\windows\system32\hpovst01.dll
2009-04-07 20:11 . 2006-12-16 06:19 573440 ----a-w c:\windows\system32\hpotscl1.dll
2009-04-07 20:11 . 2007-03-13 19:52 26952 ----a-w c:\windows\hpomdl19.dat
2009-04-07 19:38 . 2009-04-07 20:16 -------- d-----w c:\program files\HP
2009-04-07 15:53 . 2009-04-07 19:46 -------- d--h--w c:\users\Kym3ra\AppData\Roaming\VMware
2009-04-07 15:45 . 2008-10-28 20:03 50736 ----a-w c:\windows\system32\vmnetbridge.dll
2009-04-07 15:44 . 2009-04-07 19:50 -------- d-----w c:\programdata\VMware
2009-04-07 15:44 . 2009-04-07 19:50 -------- d-----w c:\users\All Users\VMware
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 23:11 . 2006-11-06 01:25 634020 ----a-w c:\windows\system32\prfh0416.dat
2009-05-05 23:11 . 2006-11-06 01:25 121690 ----a-w c:\windows\system32\prfc0416.dat
2009-05-05 18:18 . 2009-04-01 01:38 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-05-05 18:18 . 2009-03-27 02:31 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-03 23:38 . 2009-03-27 18:25 107888 ----a-w c:\windows\system32\CmdLineExt.dll
2009-05-03 23:18 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-05-03 23:18 . 2009-03-28 23:15 -------- d---a-w c:\program files\Quantum of Solace
2009-05-03 23:18 . 2009-03-27 18:18 -------- d-----w c:\program files\OpenAL
2009-05-03 23:18 . 2009-03-27 17:44 -------- d-----w c:\program files\RocketDock
2009-05-03 23:18 . 2009-03-27 17:44 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-03 23:18 . 2009-03-27 17:15 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-03 23:18 . 2009-03-27 17:24 -------- d-----w c:\program files\DAEMON Tools Lite
2009-05-03 23:18 . 2009-03-27 17:21 -------- d-----w c:\program files\Fraps
2009-05-03 23:18 . 2009-03-27 17:19 -------- d-----w c:\program files\BMPtoJPG
2009-04-30 21:10 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat
2009-04-30 21:10 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstrng.dat
2009-04-30 21:10 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat
2009-04-30 21:07 . 2009-03-27 01:52 680 ---ha-w c:\users\Kym3ra\AppData\Local\d3d9caps.dat
2009-04-26 22:45 . 2009-03-28 21:22 -------- d-----w c:\program files\Electronic Arts
2009-04-18 03:11 . 2009-04-01 01:14 -------- d--h--w c:\program files\Temp
2009-03-28 21:48 . 2009-03-28 21:48 -------- d-----w c:\program files\Atari
2009-03-28 20:07 . 2009-03-28 20:07 1125376 ----a-w c:\windows\system32\osu!.exe
2009-03-28 20:07 . 2009-03-28 20:07 105773568 ----a-w c:\windows\system32\osu.dll
2009-03-28 20:02 . 2009-03-28 20:02 96320 ----a-w c:\windows\system32\bass.dll
2009-03-28 20:02 . 2009-03-28 20:02 749568 ----a-w c:\windows\system32\Microsoft.Xna.Framework.dll
2009-03-28 20:02 . 2009-03-28 20:02 516096 ----a-w c:\windows\system32\Microsoft.Ink.dll
2009-03-28 20:02 . 2009-03-28 20:02 26712 ----a-w c:\windows\system32\bass_fx.dll
2009-03-28 20:02 . 2009-03-27 02:43 4379984 ----a-w c:\windows\system32\d3dx9_31.dll
2009-03-28 20:02 . 2009-03-27 02:43 15128 ----a-w c:\windows\system32\x3daudio1_1.dll
2009-03-28 20:02 . 2009-03-28 20:02 175104 ----a-w c:\windows\system32\osume.exe
2009-03-27 19:42 . 2006-11-02 10:25 665600 ----a-w c:\windows\inf\drvindex.dat
2009-03-27 18:18 . 2009-03-27 18:18 444952 ----a-w c:\windows\system32\wrap_oal.dll
2009-03-27 18:18 . 2009-03-27 18:18 109080 ----a-w c:\windows\system32\OpenAL32.dll
2009-03-27 17:43 . 2009-03-27 17:43 -------- d-----w c:\program files\Microsoft
2009-03-27 17:43 . 2009-03-27 17:43 -------- d-----w c:\program files\Windows Live SkyDrive
2009-03-27 17:32 . 2009-03-27 17:32 -------- d-----w c:\program files\Windows Live
2009-03-27 17:27 . 2009-03-27 17:27 -------- d-----w c:\program files\Common Files\Windows Live
2009-03-27 17:21 . 2009-03-27 17:21 -------- d-----w c:\program files\Golden Bow
2009-03-27 17:19 . 2009-03-27 17:19 47360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-03-27 17:19 . 2009-03-27 17:18 -------- d-----w c:\program files\Microsoft Games for Windows - LIVE
2009-03-27 17:16 . 2009-03-27 17:16 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-03-27 17:15 . 2009-03-27 17:15 -------- d-----w c:\program files\GRETECH
2009-03-27 02:45 . 2009-03-27 02:45 0 ----a-w c:\windows\ativpsrm.bin
2009-03-27 02:23 . 2006-11-02 12:49 174 --sha-w c:\program files\desktop.ini
2009-03-27 02:19 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Calendar
2009-03-27 02:19 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Sidebar
2009-03-27 02:19 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Photo Gallery
2009-03-27 02:19 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Journal
2009-03-27 02:19 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Collaboration
2009-03-27 02:19 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Defender
2009-03-27 02:14 . 2006-11-02 10:32 101888 ----a-w c:\windows\system32\ifxcardm.dll
2009-03-27 02:14 . 2006-11-02 10:32 82432 ----a-w c:\windows\system32\axaltocm.dll
2009-03-27 01:54 . 2009-03-27 02:09 47560 ----a-w c:\windows\system32\SPReview.exe
2009-03-27 01:54 . 2009-03-27 02:09 152576 ----a-w c:\windows\system32\SPWizUI.dll
2009-03-27 01:51 . 2009-03-27 01:51 -------- d-sh--w c:\program files\Common Files\Sistema
2009-03-27 01:51 . 2009-03-27 01:51 -------- d-sh--w c:\program files\Arquivos Comuns
2009-03-25 13:06 . 2009-04-18 03:10 142848 ----a-w c:\windows\system32\AERTACap.dll
2009-03-17 11:58 . 2009-04-18 03:10 540672 ----a-w c:\windows\RtlExUpd.dll
2009-03-16 21:33 . 2009-03-16 21:33 4361216 ----a-w c:\windows\system32\drivers\atikmdag.sys
2009-03-16 20:28 . 2009-03-16 20:28 442368 ----a-w c:\windows\system32\ATIDEMGX.dll
2009-03-16 20:27 . 2009-03-16 20:27 290816 ----a-w c:\windows\system32\atieclxx.exe
2009-03-16 20:27 . 2009-03-16 20:27 180224 ----a-w c:\windows\system32\atiesrxx.exe
2009-03-16 20:26 . 2009-03-16 20:26 159744 ----a-w c:\windows\system32\atitmmxx.dll
2009-03-16 20:25 . 2009-03-16 20:25 348160 ----a-w c:\windows\system32\atipdlxx.dll
2009-03-16 20:25 . 2009-03-16 20:25 274432 ----a-w c:\windows\system32\Oemdspif.dll
2009-03-16 20:25 . 2009-03-16 20:25 11776 ----a-w c:\windows\system32\atimuixx.dll
2009-03-16 20:25 . 2009-03-16 20:25 43520 ----a-w c:\windows\system32\ati2edxx.dll
2009-03-16 20:21 . 2009-03-16 20:21 2381312 ----a-w c:\windows\system32\atidxx32.dll
2009-03-16 20:11 . 2009-03-16 20:11 3837440 ----a-w c:\windows\system32\atiumdag.dll
2009-03-16 19:57 . 2009-03-16 19:57 11520000 ----a-w c:\windows\system32\atioglxx.dll
2009-03-16 19:53 . 2009-03-16 19:53 4950528 ----a-w c:\windows\system32\atiumdva.dll
2009-03-16 19:41 . 2009-03-16 19:41 51712 ----a-w c:\windows\system32\amdpcom32.dll
2009-03-16 19:41 . 2009-03-16 19:41 51712 ----a-w c:\windows\system32\atimpc32.dll
2009-03-16 19:41 . 2009-03-16 19:41 151552 ----a-w c:\windows\system32\atiadlxx.dll
2009-03-16 19:36 . 2009-03-16 19:36 53248 ----a-w c:\windows\system32\aticalrt.dll
2009-03-16 19:36 . 2009-03-16 19:36 53248 ----a-w c:\windows\system32\aticalcl.dll
2009-03-16 19:35 . 2009-03-16 19:35 3272704 ----a-w c:\windows\system32\aticaldd.dll
2009-03-16 19:27 . 2009-03-16 19:27 53248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2009-03-16 17:18 . 2009-03-27 02:43 69448 ----a-w c:\windows\system32\XAPOFX1_3.dll
2009-03-16 17:18 . 2009-03-27 02:43 517448 ----a-w c:\windows\system32\XAudio2_4.dll
2009-03-16 17:18 . 2009-03-27 02:43 235352 ----a-w c:\windows\system32\xactengine3_4.dll
2009-03-16 17:18 . 2009-03-27 02:43 22360 ----a-w c:\windows\system32\X3DAudio1_6.dll
2009-03-09 18:27 . 2009-03-27 02:43 453456 ----a-w c:\windows\system32\d3dx10_41.dll
2009-03-09 18:27 . 2009-03-27 02:43 4178264 ----a-w c:\windows\system32\D3DX9_41.dll
2009-03-09 18:27 . 2009-03-27 02:43 1846632 ----a-w c:\windows\system32\D3DCompiler_41.dll
2009-03-08 11:34 . 2009-04-07 21:28 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-04-07 21:28 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-04-07 21:28 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-04-07 21:28 109056 ----a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-04-07 21:28 109568 ----a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-04-07 21:28 132608 ----a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-04-07 21:28 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-04-07 21:28 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-04-07 21:28 103936 ----a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-04-07 21:28 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-04-07 21:28 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-04-07 21:28 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-04-07 21:28 66560 ----a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-04-07 21:28 169472 ----a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-04-07 21:28 34816 ----a-w c:\windows\system32\imgutil.dll
2007-06-22 17:50 . 2007-03-01 19:52 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-03-18 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3861016936-1555234343-1621014405-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4C344265-8E0D-49B6-ADCB-9DE7A0BDF87B}"= UDP:c:\users\Kym3ra\Desktop\utorrent.exe:µTorrent (TCP-In)
"{7EDCD9E9-678B-44FE-841A-FF1EDD0A0283}"= TCP:c:\users\Kym3ra\Desktop\utorrent.exe:µTorrent (UDP-In)
"{CBB11DBF-28B7-4345-942B-DAE62760EDDC}"= UDP:c:\users\Kym3ra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\utorrent.exe:µTorrent (TCP-In)
"{521F3D92-49FE-43A9-BA5E-15291846E5DB}"= TCP:c:\users\Kym3ra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\utorrent.exe:µTorrent (UDP-In)
"TCP Query User{44AD5208-3819-4474-9DAE-D9C7E1029327}c:\\program files\\electronic arts\\dead space\\dead space.exe"= UDP:c:\program files\electronic arts\dead space\dead space.exe
ead Space ™
"UDP Query User{5D36FD5D-E69A-4C81-B4FF-972629511341}c:\\program files\\electronic arts\\dead space\\dead space.exe"= TCP:c:\program files\electronic arts\dead space\dead space.exe
ead Space ™
"TCP Query User{9624F9BC-4420-499A-A5D7-93A26D2DC316}c:\\program files\\atari\\test drive unlimited\\testdriveunlimited.exe"= UDP:c:\program files\atari\test drive unlimited\testdriveunlimited.exe:Test Drive Unlimited
"UDP Query User{5FC07DF9-2A2D-4FAF-9E08-4023BB5D307A}c:\\program files\\atari\\test drive unlimited\\testdriveunlimited.exe"= TCP:c:\program files\atari\test drive unlimited\testdriveunlimited.exe:Test Drive Unlimited
"TCP Query User{26CE175F-4D17-4517-97C3-66BCBE96798B}c:\\program files\\quantum of solace\\jb_liveengine_s.exe"= UDP:c:\program files\quantum of solace\jb_liveengine_s.exe:Quantum of Solace(TM)
"UDP Query User{2748E936-98BE-46E6-A4DD-6834A41AC6BD}c:\\program files\\quantum of solace\\jb_liveengine_s.exe"= TCP:c:\program files\quantum of solace\jb_liveengine_s.exe:Quantum of Solace(TM)
"TCP Query User{262FB271-A3A6-4AFA-974E-84F008858C22}c:\\program files\\aspyr\\dark sector\\ds.exe"= UDP:c:\program files\aspyr\dark sector\ds.exe
ark Sector
"UDP Query User{726B5534-C860-4BA2-BB06-F86A04B8C271}c:\\program files\\aspyr\\dark sector\\ds.exe"= TCP:c:\program files\aspyr\dark sector\ds.exe
ark Sector
"TCP Query User{E785E27E-A9FF-47AC-9AA6-487B73A34EFC}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{84292C7A-E55D-49FF-870A-D3C53E0EAA2F}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{56DE282D-0437-45CD-A830-8E48B1058DF7}c:\\program files\\valve\\counter-strike source\\hl2.exe"= UDP:c:\program files\valve\counter-strike source\hl2.exe:hl2
"UDP Query User{04A59A7A-67F2-4B02-B519-276F67C48880}c:\\program files\\valve\\counter-strike source\\hl2.exe"= TCP:c:\program files\valve\counter-strike source\hl2.exe:hl2
"TCP Query User{4E32429B-6431-431F-9010-A0FD21334FFE}c:\\ut2003demo\\system\\ut2003.exe"= UDP:c:\ut2003demo\system\ut2003.exe:UT2003
"UDP Query User{318C8296-E6FF-4EB3-8DBC-073C45D22AB9}c:\\ut2003demo\\system\\ut2003.exe"= TCP:c:\ut2003demo\system\ut2003.exe:UT2003
"{0AF70501-EA19-4482-86D1-279E3B46B9B8}"= UDP:c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club
"{B6960B15-8FDD-417F-85A6-26F5F753C8A1}"= TCP:c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club
"{A157F86C-9729-4360-A02C-79C4DFE382E9}"= UDP:c:\program files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV
"{6D405464-8869-4756-B537-FB7A93B9E968}"= TCP:c:\program files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV
"TCP Query User{74805E57-8FEF-41BF-8932-E4CFA7571788}c:\\program files\\rockstar games\\grand theft auto iv\\gtaiv.exe"= UDP:c:\program files\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV
"UDP Query User{C82FC01C-70B2-4979-AE32-ADF4F4843879}c:\\program files\\rockstar games\\grand theft auto iv\\gtaiv.exe"= TCP:c:\program files\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV
"{AA8C2C3D-E93F-45DC-A49D-03ABB0095374}"= UDP:c:\users\Kym3ra\Games\Unreal Tournament 3\Binaries\UT3.exe:Unreal_Tournament_1
"{5E2A12F5-3B1E-44B7-AFF1-5F219812A783}"= TCP:c:\users\Kym3ra\Games\Unreal Tournament 3\Binaries\UT3.exe:Unreal_Tournament_1
"{DDA70E5A-7CEC-4DA1-9125-7C34C2C7AD71}"= UDP:c:\users\Kym3ra\Games\Unreal Tournament 3\Binaries\UnrealFrontend.exe:Unreal_Tournament_2
"{D611552F-AB88-4F98-AA21-21DE97F8A5DF}"= TCP:c:\users\Kym3ra\Games\Unreal Tournament 3\Binaries\UnrealFrontend.exe:Unreal_Tournament_2
"{5A7F0DB5-F556-484C-8B78-CE24FFDC6885}"= UDP:c:\users\Kym3ra\Games\Unreal Tournament 3\Binaries\UnrealConsole.exe:Unreal_Tournament_3
"{F258122B-BD01-4B26-85F3-3E5C67808FD5}"= TCP:c:\users\Kym3ra\Games\Unreal Tournament 3\Binaries\UnrealConsole.exe:Unreal_Tournament_3
"TCP Query User{09DB18DB-E6FA-465F-872E-9E32CD26A8BC}c:\\program files\\unreal tournament 3\\binaries\\ut3.exe"= UDP:c:\program files\unreal tournament 3\binaries\ut3.exe:UT3
"UDP Query User{B4AA9D3E-C802-492C-805C-E466F0ED12A6}c:\\program files\\unreal tournament 3\\binaries\\ut3.exe"= TCP:c:\program files\unreal tournament 3\binaries\ut3.exe:UT3
"{6AC90A82-EA52-49DC-8109-1DFFEB6D1E7B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{1D33BA05-F1C7-4358-A48F-A04E9F7004C2}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{6F3ADF71-8400-4283-B5D7-3081C415D075}c:\\program files\\id software\\quake 4 demo\\quake4.exe"= UDP:c:\program files\id software\quake 4 demo\quake4.exe:Quake 4
"UDP Query User{9ABC85E9-9017-44FF-9588-8DBF04056E62}c:\\program files\\id software\\quake 4 demo\\quake4.exe"= TCP:c:\program files\id software\quake 4 demo\quake4.exe:Quake 4
"TCP Query User{B66416F1-0765-456A-B968-7086A9C1ED7D}c:\\program files\\codemasters\\race driver online demo\\racedriverd.exe"= UDP:c:\program files\codemasters\race driver online demo\racedriverd.exe:RaceDriverd
"UDP Query User{4EBEB26F-AAC4-417B-B2B4-E0C5B1797925}c:\\program files\\codemasters\\race driver online demo\\racedriverd.exe"= TCP:c:\program files\codemasters\race driver online demo\racedriverd.exe:RaceDriverd
"TCP Query User{2FD5792C-4982-4D56-B42C-6CF847ED8209}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{B8FB59C3-9EE5-49FB-BB84-FE4E93AE5404}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"{0BD1F179-B0A8-477B-82A8-2D6353B26898}"= UDP:c:\program files\Ubisoft\Far Cry 2\bin\FarCry2.exe:Far Cry 2
"{2DEB92FE-B686-41D4-982E-ECA59F72F93E}"= TCP:c:\program files\Ubisoft\Far Cry 2\bin\FarCry2.exe:Far Cry 2
"{31678D7D-F5C0-491E-8AD9-C767DA904C42}"= UDP:c:\program files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{D523DD0B-CBF8-4F92-BEE9-FFD0A911F89E}"= TCP:c:\program files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{04AAFBBF-CA6F-4B5D-8289-308CC093F1D5}"= UDP:c:\program files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:Editor
"{21FB946F-79ED-4CC5-8DB5-BAE48EDADF60}"= TCP:c:\program files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:Editor
"{3C6C8887-80FE-4C10-AB8F-9937963B1EDD}"= UDP:c:\windows\System32\PnkBstrA.exe
nkBstrA
"{1A7EB8D4-1D42-4962-B9D4-E8AAEF072DE8}"= TCP:c:\windows\System32\PnkBstrA.exe
nkBstrA
"{7DE0E001-C3E4-4E1C-B9BC-78D85B239B80}"= UDP:c:\windows\System32\PnkBstrB.exe
nkBstrB
"{E28EACAD-0BC3-49B3-A145-7B76E7F28675}"= TCP:c:\windows\System32\PnkBstrB.exe
nkBstrB
"{25D1E509-CF82-413F-8F3D-5C3813B52ADF}"= UDP:c:\program files\Activision\X-Men Origins - Wolverine(TM)\Binaries\Wolverine.exe:X-Men Origins - Wolverine
"{2979EFCD-4CFF-4A0E-800D-68171DE9B87F}"= TCP:c:\program files\Activision\X-Men Origins - Wolverine(TM)\Binaries\Wolverine.exe:X-Men Origins - Wolverine
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Windows\\system32\\hpdrv.exe"= c:\windows\system32\hpdrv.exe:*:Enabled:svhost
R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\System32\drivers\RtlProt.sys [26/03/2009 23:31 25896]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [16/03/2009 17:27 180224]
R2 RealtekUSB;RealtekUSB;c:\program files\REALTEK\RTL8187 Wireless LAN Utility\RtlService.exe [26/03/2009 23:31 36864]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\System32\drivers\AtiHdmi.sys [20/02/2009 02:17 95760]
R3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\System32\drivers\rtl8187.sys [26/03/2009 23:31 335872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORFÃOS REMOVIDOS - - - -
HKCU-Run-ares - c:\program files\Ares\Ares.exe
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.google.com.br/
FF - ProfilePath - c:\users\Kym3ra\AppData\Roaming\Mozilla\Firefox\Profiles\3qhoa161.default\
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-05 20:14
Windows 6.0.6001 Service Pack 1 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3861016936-1555234343-1621014405-1000\Software\SecuROM\License information*]
"datasecu"=hex:b1,40,a9,4c,0a,49,a5,3d,d0,b0,19,5f,ab,d2,5f,51,6a,57,62,05,3e,
1e,f3,8c,62,b4,01,f3,1e,c4,13,89,da,d7,04,13,bb,c0,5e,61,60,67,6d,09,df,fe,\
"rkeysecu"=hex:fb,fe,a5,4d,69,0c,b4,b5,b7,d6,79,3f,cd,b3,bc,23
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'Explorer.exe'(208)
c:\program files\RocketDock\RocketDock.dll
.
Tempo para conclusão: 2009-05-05 20:15
ComboFix-quarantined-files.txt 2009-05-05 23:15
Pré-execução: 150.280.933.376 bytes disponíveis
Pós execução: 150.294.429.696 bytes disponíveis
340 --- E O F --- 2009-04-30 21:09