Fiz o procedimento em partes, não sei se vai resolver alguma coisa, mas o ComboFix está apresentando erro, segue o print
Já baixei outro ComboFix e apresenta a mesma coisa, o que é isso?
Agora os outros logs seguem abaixo:
![4559855963_62dd882cf5_b.jpg](http://farm4.static.flickr.com/3406/4559855963_62dd882cf5_b.jpg)
Já baixei outro ComboFix e apresenta a mesma coisa, o que é isso?
Agora os outros logs seguem abaixo:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:58:40, on 28/04/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe
C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\netdde.exe
C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe
C:\ARQUIV~1\SYMANT~1\VPTray.exe
C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe
C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbguard.exe
C:\Arquivos de programas\ngsrv\epsng_certd.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\FreePDF_XP\fpassist.exe
C:\Arquivos de programas\ngsrv\ngslotd.exe
C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe
C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe
C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe
C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbserver.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.192.19.53:80
R3 - URLSearchHook: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Arquivos de programas\myBabylon_English\tbmyBa.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_15\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Arquivos de programas\myBabylon_English\tbmyBa.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll (file missing)
O2 - BHO: G-Buster Browser Defense Banco Real - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll
O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehuni.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Arquivos de programas\myBabylon_English\tbmyBa.dll
O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [epsng_certd] C:\Arquivos de programas\ngsrv\epsng_certd.exe -r
O4 - HKLM\..\Run: [FreePDF Assistant] C:\Arquivos de programas\FreePDF_XP\fpassist.exe
O4 - HKLM\..\Run: [Babylon Client] C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_15\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_15\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238007160953
O16 - DPF: {6F7864F9-DB33-11D3-8166-0060B0F885E6} (VSPTA Class) - https://certificacao.unibanco.com.br/VSApps/vspta3.cab
O16 - DPF: {9EC30204-384D-11D3-9CA3-00A024F0AF03} (ValidaUsuario Class) - https://cpne.bradesco.com.br/certifexp.cab
O16 - DPF: {A2CD4A80-DDA5-11D3-8DAC-0000B45FF7C8} (Controlador Class) - https://ic400.interchange.com.br/icnet/Componentes/ICWCLI.CAB
O16 - DPF: {B3D3825B-2120-4B0E-8C45-80ECC1D3E70D} (GeraCert Class) - https://cpne.bradesco.com.br/CA.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugin/Cab/GbPluginABN.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1F90C07-0CF9-4154-97A8-00B3CE36FB4D}: NameServer = 201.10.128.3,201.10.120.3
O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll
O20 - Winlogon Notify: GbPluginBb - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll
O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll (file missing)
O20 - Winlogon Notify: GbPluginUni - C:\ARQUIV~1\GbPlugin\gbiehuni.dll (file missing)
O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll
O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - Firebird Project - C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - Firebird Project - C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ngSlotDaemon (ngSlotD) - Feitian Technologies Co.,Ltd. - C:\Arquivos de programas\ngsrv\ngslotd.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe
--
End of file - 11909 bytes
Scan saved at 08:58:40, on 28/04/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe
C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\netdde.exe
C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe
C:\ARQUIV~1\SYMANT~1\VPTray.exe
C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe
C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbguard.exe
C:\Arquivos de programas\ngsrv\epsng_certd.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\FreePDF_XP\fpassist.exe
C:\Arquivos de programas\ngsrv\ngslotd.exe
C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe
C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe
C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe
C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbserver.exe
C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe
C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.192.19.53:80
R3 - URLSearchHook: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Arquivos de programas\myBabylon_English\tbmyBa.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_15\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Arquivos de programas\myBabylon_English\tbmyBa.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll (file missing)
O2 - BHO: G-Buster Browser Defense Banco Real - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll
O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehuni.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Arquivos de programas\myBabylon_English\tbmyBa.dll
O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\ARQUIV~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [epsng_certd] C:\Arquivos de programas\ngsrv\epsng_certd.exe -r
O4 - HKLM\..\Run: [FreePDF Assistant] C:\Arquivos de programas\FreePDF_XP\fpassist.exe
O4 - HKLM\..\Run: [Babylon Client] C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_15\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_15\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238007160953
O16 - DPF: {6F7864F9-DB33-11D3-8166-0060B0F885E6} (VSPTA Class) - https://certificacao.unibanco.com.br/VSApps/vspta3.cab
O16 - DPF: {9EC30204-384D-11D3-9CA3-00A024F0AF03} (ValidaUsuario Class) - https://cpne.bradesco.com.br/certifexp.cab
O16 - DPF: {A2CD4A80-DDA5-11D3-8DAC-0000B45FF7C8} (Controlador Class) - https://ic400.interchange.com.br/icnet/Componentes/ICWCLI.CAB
O16 - DPF: {B3D3825B-2120-4B0E-8C45-80ECC1D3E70D} (GeraCert Class) - https://cpne.bradesco.com.br/CA.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugin/Cab/GbPluginABN.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1F90C07-0CF9-4154-97A8-00B3CE36FB4D}: NameServer = 201.10.128.3,201.10.120.3
O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll
O20 - Winlogon Notify: GbPluginBb - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll
O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll (file missing)
O20 - Winlogon Notify: GbPluginUni - C:\ARQUIV~1\GbPlugin\gbiehuni.dll (file missing)
O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll
O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - Firebird Project - C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - Firebird Project - C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ngSlotDaemon (ngSlotD) - Feitian Technologies Co.,Ltd. - C:\Arquivos de programas\ngsrv\ngslotd.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe
--
End of file - 11909 bytes
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\smss.exe
PID: 1100
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\csrss.exe
PID: 1148
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\winlogon.exe
PID: 1172
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 1216
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\lsass.exe
PID: 1228
Hidden: No
Window Visible: No
Name: C:\ARQUIV~1\GbPlugin\gbpsv.exe
PID: 1404
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1452
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1536
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1624
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1724
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1828
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe
PID: 1904
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe
PID: 1964
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\spoolsv.exe
PID: 188
Hidden: No
Window Visible: No
Name: C:\WINDOWS\explorer.exe
PID: 436
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\scardsvr.exe
PID: 452
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 660
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe
PID: 744
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\netdde.exe
PID: 748
Hidden: No
Window Visible: No
Name: C:\ARQUIV~1\SYMANT~1\VPTray.exe
PID: 792
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe
PID: 832
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbguard.exe
PID: 876
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\ngsrv\epsng_certd.exe
PID: 1136
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 128
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\FreePDF_XP\fpassist.exe
PID: 1476
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\ngsrv\ngslotd.exe
PID: 1888
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe
PID: 224
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe
PID: 1040
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1572
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe
PID: 1880
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
PID: 2176
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\hkcmd.exe
PID: 2272
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\igfxpers.exe
PID: 2324
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\igfxsrvc.exe
PID: 2328
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PID: 2436
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ctfmon.exe
PID: 2460
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 2720
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe
PID: 3060
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbserver.exe
PID: 2348
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
PID: 2252
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
PID: 1612
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
PID: 3260
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wbem\wmiprvse.exe
PID: 1804
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\User\Desktop\SysProt\SysProt\SysProt.exe
PID: 2360
Hidden: No
Window Visible: Yes
******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \??\C:\Documents and Settings\User\Desktop\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: A8754000
Module End: A875F000
Hidden: No
Module Name: \WINDOWS\system32\ntkrnlpa.exe
Service Name: ---
Module Base: 804D7000
Module End: 806E4000
Hidden: No
Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806E4000
Module End: 80704D00
Hidden: No
Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: BA5A8000
Module End: BA5AA000
Hidden: No
Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: BA4B8000
Module End: BA4BB000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: B9F79000
Module End: B9FA7000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\WMILIB.SYS
Service Name: ---
Module Base: BA5AA000
Module End: BA5AC000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: B9F68000
Module End: B9F79000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: BA0A8000
Module End: BA0B1000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pciide.sys
Service Name: PCIIde
Module Base: BA670000
Module End: BA671000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Service Name: ---
Module Base: BA328000
Module End: BA32F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: BA0B8000
Module End: BA0C3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: B9F49000
Module End: B9F68000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmload.sys
Service Name: dmload
Module Base: BA5AC000
Module End: BA5AE000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmio.sys
Service Name: dmio
Module Base: B9F23000
Module End: B9F49000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: BA330000
Module End: BA335000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: BA0C8000
Module End: BA0D5000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: B9F0B000
Module End: B9F23000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: BA0D8000
Module End: BA0E1000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: BA0E8000
Module End: BA0F5000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\fltMgr.sys
Service Name: FltMgr
Module Base: B9EEB000
Module End: B9F0B000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: B9ED9000
Module End: B9EEB000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: B9EC2000
Module End: B9ED9000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: B9E35000
Module End: B9EC2000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\gbpkm.sys
Service Name: GbpKm
Module Base: BA338000
Module End: BA33F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: B9E08000
Module End: B9E35000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: B9DEE000
Module End: B9E08000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: BA1E8000
Module End: BA1F2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
Service Name: ialm
Module Base: B9823000
Module End: B9DA6000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: B980F000
Module End: B9823000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
Service Name: HDAudBus
Module Base: B97EA000
Module End: B980F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
Service Name: RTLE8023xp
Module Base: B97D2000
Module End: B97EA000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: BA3D0000
Module End: BA3D6000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: B97AE000
Module End: B97D2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: BA3D8000
Module End: BA3E0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\serial.sys
Service Name: Serial
Module Base: B979D000
Module End: B97AE000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\serenum.sys
Service Name: serenum
Module Base: BA558000
Module End: BA55C000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\parport.sys
Service Name: Parport
Module Base: B9789000
Module End: B979D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: BA1F8000
Module End: BA203000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: BA208000
Module End: BA218000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: BA218000
Module End: BA227000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ks.sys
Service Name: ---
Module Base: B9766000
Module End: B9789000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: BA7D5000
Module End: BA7D6000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: BA228000
Module End: BA235000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: BA564000
Module End: BA567000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: B974F000
Module End: B9766000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: BA238000
Module End: BA243000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: BA248000
Module End: BA254000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: BA3E0000
Module End: BA3E5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\psched.sys
Service Name: PSched
Module Base: B973E000
Module End: B974F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: BA258000
Module End: BA261000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: BA3E8000
Module End: BA3ED000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: BA3F0000
Module End: BA3F5000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\RootMdm.sys
Service Name: ROOTMODEM
Module Base: BA5C8000
Module End: BA5CA000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: BA400000
Module End: BA408000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdpdr.sys
Service Name: rdpdr
Module Base: B970D000
Module End: B973E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: BA268000
Module End: BA272000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: BA408000
Module End: BA40F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: BA410000
Module End: BA416000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\smccardc.sys
Service Name: FT12BaseSmc
Module Base: BA584000
Module End: BA588000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\SMCLIB.SYS
Service Name: ---
Module Base: BA590000
Module End: BA594000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: BA5CA000
Module End: BA5CC000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\update.sys
Service Name: Update
Module Base: B968C000
Module End: B96E5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: BA594000
Module End: BA598000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: BA288000
Module End: BA292000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\RtkHDAud.sys
Service Name: IntcAzAudAddService
Module Base: A9145000
Module End: A95A4000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: A9123000
Module End: A9145000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: BA298000
Module End: BA2A7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: BA2A8000
Module End: BA2B7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: BA5CE000
Module End: BA5D0000
Hidden: No
Module Name: \??\C:\Arquivos de programas\Symantec AntiVirus\savrt.sys
Service Name: SAVRT
Module Base: A90A3000
Module End: A90FB000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\hidusb.sys
Service Name: hidusb
Module Base: B96ED000
Module End: B96F0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Service Name: ---
Module Base: BA2B8000
Module End: BA2C1000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: BA430000
Module End: BA437000
Hidden: No
Module Name: \??\C:\Arquivos de programas\Symantec\SYMEVENT.SYS
Service Name: SymEvent
Module Base: A8FB9000
Module End: A8FDB000
Hidden: No
Module Name: \??\C:\Arquivos de programas\Symantec AntiVirus\Savrtpel.sys
Service Name: SAVRTPEL
Module Base: A8FA5000
Module End: A8FB9000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Service Name: USBSTOR
Module Base: BA450000
Module End: BA457000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdhid.sys
Service Name: kbdhid
Module Base: A95BC000
Module End: A95C0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouhid.sys
Service Name: mouhid
Module Base: A95B8000
Module End: A95BB000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: BA5EA000
Module End: BA5EC000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: BA6B8000
Module End: BA6B9000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: BA5F6000
Module End: BA5F8000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: BA480000
Module End: BA486000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: BA602000
Module End: BA604000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: BA606000
Module End: BA608000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: BA490000
Module End: BA495000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: BA498000
Module End: BA4A0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: A9103000
Module End: A9106000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: A8E1C000
Module End: A8E2F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: A8DC3000
Module End: A8E1C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\SYMTDI.SYS
Service Name: SYMTDI
Module Base: A8D88000
Module End: A8DC3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: A8D66000
Module End: A8D88000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: BA2F8000
Module End: BA301000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: A8D3E000
Module End: A8D66000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: A8D1C000
Module End: A8D3E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: BA308000
Module End: BA311000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: A8CF1000
Module End: A8D1C000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: A8C82000
Module End: A8CF1000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: BA318000
Module End: BA321000
Hidden: No
Module Name: \??\C:\Arquivos de programas\Arquivos comuns\Symantec Shared\EENGINE\eeCtrl.sys
Service Name: eeCtrl
Module Base: A8C24000
Module End: A8C82000
Hidden: No
Module Name: \??\C:\Arquivos de programas\Arquivos comuns\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
Service Name: EraserUtilRebootDrv
Module Base: A8C07000
Module End: A8C24000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: A8BBC000
Module End: A8BDF000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Service Name: Cdfs
Module Base: BA128000
Module End: BA138000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: BA58C000
Module End: BA58F000
Hidden: No
Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: BA3A0000
Module End: BA3A5000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: BA733000
Module End: BA734000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: A8A90000
Module End: A8A94000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: A862F000
Module End: A8644000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: A87E4000
Module End: A87F3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxdav.sys
Service Name: MRxDAV
Module Base: A83D3000
Module End: A83FF000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Service Name: ParVdm
Module Base: BA66E000
Module End: BA670000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\cpuz132_x32.sys
Service Name: cpuz132
Module Base: A8608000
Module End: A860C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\DgiVecp.sys
Service Name: DgiVecp
Module Base: A847F000
Module End: A848D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\srv.sys
Service Name: Srv
Module Base: A823C000
Module End: A8293000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\SpPortEx.sys
Service Name: SpPortEx
Module Base: BA488000
Module End: BA48E000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys
Service Name: HTTP
Module Base: A7D23000
Module End: A7D64000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\TDTCP.SYS
Service Name: TDTCP
Module Base: BA3B0000
Module End: BA3B6000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\RDPWD.SYS
Service Name: RDPWD
Module Base: A7C88000
Module End: A7CAB000
Hidden: No
Module Name: \??\C:\ARQUIV~1\ARQUIV~1\SYMANT~1\VIRUSD~1\20100426.003\navex15.sys
Service Name: NAVEX15
Module Base: A7966000
Module End: A7AA8000
Hidden: No
Module Name: \??\C:\ARQUIV~1\ARQUIV~1\SYMANT~1\VIRUSD~1\20100426.003\naveng.sys
Service Name: NAVENG
Module Base: A7952000
Module End: A7966000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
Service Name: SYMREDRV
Module Base: A7C50000
Module End: A7C5A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\kmixer.sys
Service Name: kmixer
Module Base: A7219000
Module End: A7244000
Hidden: No
******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwConnectPort
Address: 8995E9E8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwDeleteValueKey
Address: A8FCD350
Driver Base: A8FB9000
Driver End: A8FDB000
Driver Name: \??\C:\Arquivos de programas\Symantec\SYMEVENT.SYS
Function Name: ZwSetValueKey
Address: A8FCD580
Driver Base: A8FB9000
Driver End: A8FDB000
Driver Name: \??\C:\Arquivos de programas\Symantec\SYMEVENT.SYS
******************************************************************************************
******************************************************************************************
No Kernel Hooks found
******************************************************************************************
******************************************************************************************
No IRP Hooks found
******************************************************************************************
******************************************************************************************
Ports:
Local Address: COMERCIAL:1501
Remote Address: LOCALHOST:1500
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1500
Remote Address: LOCALHOST:1501
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1476
Remote Address: LOCALHOST:1473
Type: TCP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: ESTABLISHED
Local Address: COMERCIAL:1473
Remote Address: LOCALHOST:1476
Type: TCP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: ESTABLISHED
Local Address: COMERCIAL:1473
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: LISTENING
Local Address: COMERCIAL:1469
Remote Address: LOCALHOST:1468
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1468
Remote Address: LOCALHOST:1469
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1031
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe
State: LISTENING
Local Address: COMERCIAL:1726
Remote Address: CDS42.GRU9.MSECN.NET:HTTP
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: ESTABLISHED
Local Address: COMERCIAL:1724
Remote Address: 74.125.110.37:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL
PTP
Remote Address: BS-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1722
Remote Address: YO-IN-F137.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1721
Remote Address: YO-IN-F147.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1720
Remote Address: BS-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1718
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1717
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1716
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1715
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1714
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1713
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1712
Remote Address: NUQ04S01-IN-F100.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1711
Remote Address: BS-IN-F164.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1710
Remote Address: BS-IN-F164.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1709
Remote Address: NUQ04S01-IN-F100.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1705
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1704
Remote Address: BS-IN-F154.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1703
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1702
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1701
Remote Address: BS-IN-F118.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1700
Remote Address: BS-IN-F118.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1699
Remote Address: BS-IN-F118.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1698
Remote Address: BS-IN-F118.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1697
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1696
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1695
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1694
Remote Address: BS-IN-F154.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1693
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1692
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1691
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1690
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1689
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1688
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1687
Remote Address: BS-IN-F164.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1686
Remote Address: BS-IN-F154.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1682
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1681
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1680
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1679
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1678
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1677
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1669
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1667
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1664
Remote Address: BS-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1662
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1661
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1660
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1659
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1658
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1653
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1651
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1650
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1649
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1648
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1646
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1645
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1643
Remote Address: BS-IN-F100.1E100.NET:HTTPS
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1639
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1637
Remote Address: BS-IN-F148.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1626
Remote Address: BS-IN-F104.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1576
Remote Address: BS-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1467
Remote Address: SN1MSG2010529.PHX.GBL:1863
Type: TCP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: ESTABLISHED
Local Address: COMERCIAL:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: COMERCIAL:3389
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: COMERCIAL:GDS_DB
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbserver.exe
State: LISTENING
Local Address: COMERCIAL:2967
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe
State: LISTENING
Local Address: COMERCIAL:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: COMERCIAL:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: COMERCIAL:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: COMERCIAL:1729
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: COMERCIAL:1504
Remote Address: NA
Type: UDP
Process: C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
State: NA
Local Address: COMERCIAL:1464
Remote Address: NA
Type: UDP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: NA
Local Address: COMERCIAL:1029
Remote Address: NA
Type: UDP
Process: C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
State: NA
Local Address: COMERCIAL:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: COMERCIAL:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: COMERCIAL:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: COMERCIAL:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: COMERCIAL:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: COMERCIAL
ISCARD
Remote Address: NA
Type: UDP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: NA
Local Address: COMERCIAL:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: COMERCIAL:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: COMERCIAL:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA
******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: E:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: E:\System Volume Information\tracking.log
Status: Access denied
Object: E:\System Volume Information\_restore{76878019-AA02-42F3-B159-42201D702097}
Status: Access denied
Object: C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Microsoft\Messenger\rodrigoedc@hotmail.com\SharingMetadata\juliananataly@hotmail.com\DFSR\Staging\CS{1E77F5AE-2C2E-4C69-421D-C6E38EE7F0A2}\01\11-{1E77F5AE-2C2E-4C69-421D-C6E38EE7F0A2
Status: Hidden
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: C:\System Volume Information\tracking.log
Status: Access denied
Object: C:\System Volume Information\_restore{76878019-AA02-42F3-B159-42201D702097}
Status: Access denied
by swatkat
******************************************************************************************
******************************************************************************************
Process:
Name: [System Idle Process]
PID: 0
Hidden: No
Window Visible: No
Name: System
PID: 4
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\smss.exe
PID: 1100
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\csrss.exe
PID: 1148
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\winlogon.exe
PID: 1172
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\services.exe
PID: 1216
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\lsass.exe
PID: 1228
Hidden: No
Window Visible: No
Name: C:\ARQUIV~1\GbPlugin\gbpsv.exe
PID: 1404
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1452
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1536
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1624
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1724
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1828
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSetMgr.exe
PID: 1904
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe
PID: 1964
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\spoolsv.exe
PID: 188
Hidden: No
Window Visible: No
Name: C:\WINDOWS\explorer.exe
PID: 436
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\scardsvr.exe
PID: 452
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 660
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe
PID: 744
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\netdde.exe
PID: 748
Hidden: No
Window Visible: No
Name: C:\ARQUIV~1\SYMANT~1\VPTray.exe
PID: 792
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Symantec AntiVirus\DefWatch.exe
PID: 832
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbguard.exe
PID: 876
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\ngsrv\epsng_certd.exe
PID: 1136
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 128
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\FreePDF_XP\fpassist.exe
PID: 1476
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\ngsrv\ngslotd.exe
PID: 1888
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Babylon\Babylon-Pro\Babylon.exe
PID: 224
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe
PID: 1040
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 1572
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Symantec AntiVirus\SavRoam.exe
PID: 1880
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
PID: 2176
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\hkcmd.exe
PID: 2272
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\igfxpers.exe
PID: 2324
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\igfxsrvc.exe
PID: 2328
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PID: 2436
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\ctfmon.exe
PID: 2460
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\svchost.exe
PID: 2720
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe
PID: 3060
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbserver.exe
PID: 2348
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
PID: 2252
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
PID: 1612
Hidden: No
Window Visible: No
Name: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
PID: 3260
Hidden: No
Window Visible: No
Name: C:\WINDOWS\system32\wbem\wmiprvse.exe
PID: 1804
Hidden: No
Window Visible: No
Name: C:\Documents and Settings\User\Desktop\SysProt\SysProt\SysProt.exe
PID: 2360
Hidden: No
Window Visible: Yes
******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \??\C:\Documents and Settings\User\Desktop\SysProt\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: A8754000
Module End: A875F000
Hidden: No
Module Name: \WINDOWS\system32\ntkrnlpa.exe
Service Name: ---
Module Base: 804D7000
Module End: 806E4000
Hidden: No
Module Name: \WINDOWS\system32\hal.dll
Service Name: ---
Module Base: 806E4000
Module End: 80704D00
Hidden: No
Module Name: \WINDOWS\system32\KDCOM.DLL
Service Name: ---
Module Base: BA5A8000
Module End: BA5AA000
Hidden: No
Module Name: \WINDOWS\system32\BOOTVID.dll
Service Name: ---
Module Base: BA4B8000
Module End: BA4BB000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: B9F79000
Module End: B9FA7000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\WMILIB.SYS
Service Name: ---
Module Base: BA5AA000
Module End: BA5AC000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pci.sys
Service Name: PCI
Module Base: B9F68000
Module End: B9F79000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\isapnp.sys
Service Name: isapnp
Module Base: BA0A8000
Module End: BA0B1000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\pciide.sys
Service Name: PCIIde
Module Base: BA670000
Module End: BA671000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Service Name: ---
Module Base: BA328000
Module End: BA32F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys
Service Name: MountMgr
Module Base: BA0B8000
Module End: BA0C3000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys
Service Name: Disk
Module Base: B9F49000
Module End: B9F68000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmload.sys
Service Name: dmload
Module Base: BA5AC000
Module End: BA5AE000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\dmio.sys
Service Name: dmio
Module Base: B9F23000
Module End: B9F49000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys
Service Name: PartMgr
Module Base: BA330000
Module End: BA335000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys
Service Name: VolSnap
Module Base: BA0C8000
Module End: BA0D5000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\atapi.sys
Service Name: atapi
Module Base: B9F0B000
Module End: B9F23000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\disk.sys
Service Name: ---
Module Base: BA0D8000
Module End: BA0E1000
Hidden: No
Module Name: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Service Name: ---
Module Base: BA0E8000
Module End: BA0F5000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\fltMgr.sys
Service Name: FltMgr
Module Base: B9EEB000
Module End: B9F0B000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sr.sys
Service Name: sr
Module Base: B9ED9000
Module End: B9EEB000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys
Service Name: KSecDD
Module Base: B9EC2000
Module End: B9ED9000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys
Service Name: Ntfs
Module Base: B9E35000
Module End: B9EC2000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\gbpkm.sys
Service Name: GbpKm
Module Base: BA338000
Module End: BA33F000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\NDIS.sys
Service Name: NDIS
Module Base: B9E08000
Module End: B9E35000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\Mup.sys
Service Name: Mup
Module Base: B9DEE000
Module End: B9E08000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\intelppm.sys
Service Name: intelppm
Module Base: BA1E8000
Module End: BA1F2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
Service Name: ialm
Module Base: B9823000
Module End: B9DA6000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Service Name: ---
Module Base: B980F000
Module End: B9823000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
Service Name: HDAudBus
Module Base: B97EA000
Module End: B980F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
Service Name: RTLE8023xp
Module Base: B97D2000
Module End: B97EA000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbuhci.sys
Service Name: usbuhci
Module Base: BA3D0000
Module End: BA3D6000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: B97AE000
Module End: B97D2000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: BA3D8000
Module End: BA3E0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\serial.sys
Service Name: Serial
Module Base: B979D000
Module End: B97AE000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\serenum.sys
Service Name: serenum
Module Base: BA558000
Module End: BA55C000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\parport.sys
Service Name: Parport
Module Base: B9789000
Module End: B979D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\imapi.sys
Service Name: Imapi
Module Base: BA1F8000
Module End: BA203000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Service Name: Cdrom
Module Base: BA208000
Module End: BA218000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\redbook.sys
Service Name: redbook
Module Base: BA218000
Module End: BA227000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ks.sys
Service Name: ---
Module Base: B9766000
Module End: B9789000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\audstub.sys
Service Name: audstub
Module Base: BA7D5000
Module End: BA7D6000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: BA228000
Module End: BA235000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: BA564000
Module End: BA567000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: B974F000
Module End: B9766000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: BA238000
Module End: BA243000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: BA248000
Module End: BA254000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: BA3E0000
Module End: BA3E5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\psched.sys
Service Name: PSched
Module Base: B973E000
Module End: B974F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\msgpc.sys
Service Name: Gpc
Module Base: BA258000
Module End: BA261000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ptilink.sys
Service Name: Ptilink
Module Base: BA3E8000
Module End: BA3ED000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\raspti.sys
Service Name: Raspti
Module Base: BA3F0000
Module End: BA3F5000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\RootMdm.sys
Service Name: ROOTMODEM
Module Base: BA5C8000
Module End: BA5CA000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS
Service Name: Modem
Module Base: BA400000
Module End: BA408000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdpdr.sys
Service Name: rdpdr
Module Base: B970D000
Module End: B973E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: BA268000
Module End: BA272000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Service Name: Kbdclass
Module Base: BA408000
Module End: BA40F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouclass.sys
Service Name: Mouclass
Module Base: BA410000
Module End: BA416000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\smccardc.sys
Service Name: FT12BaseSmc
Module Base: BA584000
Module End: BA588000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\SMCLIB.SYS
Service Name: ---
Module Base: BA590000
Module End: BA594000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: BA5CA000
Module End: BA5CC000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\update.sys
Service Name: Update
Module Base: B968C000
Module End: B96E5000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: BA594000
Module End: BA598000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Service Name: NDProxy
Module Base: BA288000
Module End: BA292000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\RtkHDAud.sys
Service Name: IntcAzAudAddService
Module Base: A9145000
Module End: A95A4000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\portcls.sys
Service Name: ---
Module Base: A9123000
Module End: A9145000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\drmk.sys
Service Name: ---
Module Base: BA298000
Module End: BA2A7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: BA2A8000
Module End: BA2B7000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Service Name: ---
Module Base: BA5CE000
Module End: BA5D0000
Hidden: No
Module Name: \??\C:\Arquivos de programas\Symantec AntiVirus\savrt.sys
Service Name: SAVRT
Module Base: A90A3000
Module End: A90FB000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\hidusb.sys
Service Name: hidusb
Module Base: B96ED000
Module End: B96F0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Service Name: ---
Module Base: BA2B8000
Module End: BA2C1000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: BA430000
Module End: BA437000
Hidden: No
Module Name: \??\C:\Arquivos de programas\Symantec\SYMEVENT.SYS
Service Name: SymEvent
Module Base: A8FB9000
Module End: A8FDB000
Hidden: No
Module Name: \??\C:\Arquivos de programas\Symantec AntiVirus\Savrtpel.sys
Service Name: SAVRTPEL
Module Base: A8FA5000
Module End: A8FB9000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
Service Name: USBSTOR
Module Base: BA450000
Module End: BA457000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\kbdhid.sys
Service Name: kbdhid
Module Base: A95BC000
Module End: A95C0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mouhid.sys
Service Name: mouhid
Module Base: A95B8000
Module End: A95BB000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Service Name: Fs_Rec
Module Base: BA5EA000
Module End: BA5EC000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Null.SYS
Service Name: Null
Module Base: BA6B8000
Module End: BA6B9000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS
Service Name: Beep
Module Base: BA5F6000
Module End: BA5F8000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\vga.sys
Service Name: VgaSave
Module Base: BA480000
Module End: BA486000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Service Name: mnmdd
Module Base: BA602000
Module End: BA604000
Hidden: No
Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: BA606000
Module End: BA608000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS
Service Name: Msfs
Module Base: BA490000
Module End: BA495000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS
Service Name: Npfs
Module Base: BA498000
Module End: BA4A0000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rasacd.sys
Service Name: RasAcd
Module Base: A9103000
Module End: A9106000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Service Name: IPSec
Module Base: A8E1C000
Module End: A8E2F000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Service Name: Tcpip
Module Base: A8DC3000
Module End: A8E1C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\SYMTDI.SYS
Service Name: SYMTDI
Module Base: A8D88000
Module End: A8DC3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ipnat.sys
Service Name: IpNat
Module Base: A8D66000
Module End: A8D88000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\wanarp.sys
Service Name: Wanarp
Module Base: BA2F8000
Module End: BA301000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: A8D3E000
Module End: A8D66000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\afd.sys
Service Name: AFD
Module Base: A8D1C000
Module End: A8D3E000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: BA308000
Module End: BA311000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\rdbss.sys
Service Name: Rdbss
Module Base: A8CF1000
Module End: A8D1C000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Service Name: MRxSmb
Module Base: A8C82000
Module End: A8CF1000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS
Service Name: Fips
Module Base: BA318000
Module End: BA321000
Hidden: No
Module Name: \??\C:\Arquivos de programas\Arquivos comuns\Symantec Shared\EENGINE\eeCtrl.sys
Service Name: eeCtrl
Module Base: A8C24000
Module End: A8C82000
Hidden: No
Module Name: \??\C:\Arquivos de programas\Arquivos comuns\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
Service Name: EraserUtilRebootDrv
Module Base: A8C07000
Module End: A8C24000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Service Name: Fastfat
Module Base: A8BBC000
Module End: A8BDF000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Service Name: Cdfs
Module Base: BA128000
Module End: BA138000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: BA58C000
Module End: BA58F000
Hidden: No
Module Name: C:\WINDOWS\System32\watchdog.sys
Service Name: ---
Module Base: BA3A0000
Module End: BA3A5000
Hidden: No
Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys
Service Name: ---
Module Base: BA733000
Module End: BA734000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Service Name: Ndisuio
Module Base: A8A90000
Module End: A8A94000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys
Service Name: wdmaud
Module Base: A862F000
Module End: A8644000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys
Service Name: sysaudio
Module Base: A87E4000
Module End: A87F3000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\mrxdav.sys
Service Name: MRxDAV
Module Base: A83D3000
Module End: A83FF000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Service Name: ParVdm
Module Base: BA66E000
Module End: BA670000
Hidden: No
Module Name: \??\C:\WINDOWS\system32\drivers\cpuz132_x32.sys
Service Name: cpuz132
Module Base: A8608000
Module End: A860C000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\DgiVecp.sys
Service Name: DgiVecp
Module Base: A847F000
Module End: A848D000
Hidden: No
Module Name: C:\WINDOWS\system32\DRIVERS\srv.sys
Service Name: Srv
Module Base: A823C000
Module End: A8293000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\SpPortEx.sys
Service Name: SpPortEx
Module Base: BA488000
Module End: BA48E000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys
Service Name: HTTP
Module Base: A7D23000
Module End: A7D64000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\TDTCP.SYS
Service Name: TDTCP
Module Base: BA3B0000
Module End: BA3B6000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\RDPWD.SYS
Service Name: RDPWD
Module Base: A7C88000
Module End: A7CAB000
Hidden: No
Module Name: \??\C:\ARQUIV~1\ARQUIV~1\SYMANT~1\VIRUSD~1\20100426.003\navex15.sys
Service Name: NAVEX15
Module Base: A7966000
Module End: A7AA8000
Hidden: No
Module Name: \??\C:\ARQUIV~1\ARQUIV~1\SYMANT~1\VIRUSD~1\20100426.003\naveng.sys
Service Name: NAVENG
Module Base: A7952000
Module End: A7966000
Hidden: No
Module Name: C:\WINDOWS\System32\Drivers\SYMREDRV.SYS
Service Name: SYMREDRV
Module Base: A7C50000
Module End: A7C5A000
Hidden: No
Module Name: C:\WINDOWS\system32\drivers\kmixer.sys
Service Name: kmixer
Module Base: A7219000
Module End: A7244000
Hidden: No
******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwConnectPort
Address: 8995E9E8
Driver Base: 0
Driver End: 0
Driver Name: _unknown_
Function Name: ZwDeleteValueKey
Address: A8FCD350
Driver Base: A8FB9000
Driver End: A8FDB000
Driver Name: \??\C:\Arquivos de programas\Symantec\SYMEVENT.SYS
Function Name: ZwSetValueKey
Address: A8FCD580
Driver Base: A8FB9000
Driver End: A8FDB000
Driver Name: \??\C:\Arquivos de programas\Symantec\SYMEVENT.SYS
******************************************************************************************
******************************************************************************************
No Kernel Hooks found
******************************************************************************************
******************************************************************************************
No IRP Hooks found
******************************************************************************************
******************************************************************************************
Ports:
Local Address: COMERCIAL:1501
Remote Address: LOCALHOST:1500
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1500
Remote Address: LOCALHOST:1501
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1476
Remote Address: LOCALHOST:1473
Type: TCP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: ESTABLISHED
Local Address: COMERCIAL:1473
Remote Address: LOCALHOST:1476
Type: TCP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: ESTABLISHED
Local Address: COMERCIAL:1473
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: LISTENING
Local Address: COMERCIAL:1469
Remote Address: LOCALHOST:1468
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1468
Remote Address: LOCALHOST:1469
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1031
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe
State: LISTENING
Local Address: COMERCIAL:1726
Remote Address: CDS42.GRU9.MSECN.NET:HTTP
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: ESTABLISHED
Local Address: COMERCIAL:1724
Remote Address: 74.125.110.37:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL
Remote Address: BS-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1722
Remote Address: YO-IN-F137.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1721
Remote Address: YO-IN-F147.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1720
Remote Address: BS-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1718
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1717
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1716
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1715
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1714
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1713
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1712
Remote Address: NUQ04S01-IN-F100.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1711
Remote Address: BS-IN-F164.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1710
Remote Address: BS-IN-F164.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1709
Remote Address: NUQ04S01-IN-F100.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1705
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1704
Remote Address: BS-IN-F154.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1703
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1702
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1701
Remote Address: BS-IN-F118.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1700
Remote Address: BS-IN-F118.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1699
Remote Address: BS-IN-F118.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1698
Remote Address: BS-IN-F118.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1697
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1696
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1695
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1694
Remote Address: BS-IN-F154.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1693
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1692
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1691
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1690
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1689
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1688
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1687
Remote Address: BS-IN-F164.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1686
Remote Address: BS-IN-F154.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1682
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1681
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1680
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1679
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1678
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1677
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1669
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1667
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1664
Remote Address: BS-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1662
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1661
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1660
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1659
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1658
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1653
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1651
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1650
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1649
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1648
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1646
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1645
Remote Address: BS-IN-F86.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1643
Remote Address: BS-IN-F100.1E100.NET:HTTPS
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1639
Remote Address: BS-IN-F85.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1637
Remote Address: BS-IN-F148.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1626
Remote Address: BS-IN-F104.1E100.NET:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: COMERCIAL:1576
Remote Address: BS-IN-F100.1E100.NET:HTTP
Type: TCP
Process: C:\Arquivos de programas\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: COMERCIAL:1467
Remote Address: SN1MSG2010529.PHX.GBL:1863
Type: TCP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: ESTABLISHED
Local Address: COMERCIAL:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: COMERCIAL:3389
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: COMERCIAL:GDS_DB
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Arquivos de programas\Firebird\Firebird_2_1\bin\fbserver.exe
State: LISTENING
Local Address: COMERCIAL:2967
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Arquivos de programas\Symantec AntiVirus\Rtvscan.exe
State: LISTENING
Local Address: COMERCIAL:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: COMERCIAL:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\system32\svchost.exe
State: LISTENING
Local Address: COMERCIAL:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: COMERCIAL:1729
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: COMERCIAL:1504
Remote Address: NA
Type: UDP
Process: C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe
State: NA
Local Address: COMERCIAL:1464
Remote Address: NA
Type: UDP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: NA
Local Address: COMERCIAL:1029
Remote Address: NA
Type: UDP
Process: C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
State: NA
Local Address: COMERCIAL:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: COMERCIAL:1900
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: COMERCIAL:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: COMERCIAL:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: COMERCIAL:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\svchost.exe
State: NA
Local Address: COMERCIAL
Remote Address: NA
Type: UDP
Process: C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
State: NA
Local Address: COMERCIAL:4500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: COMERCIAL:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\system32\lsass.exe
State: NA
Local Address: COMERCIAL:MICROSOFT-DS
Remote Address: NA
Type: UDP
Process: System
State: NA
******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: E:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: E:\System Volume Information\tracking.log
Status: Access denied
Object: E:\System Volume Information\_restore{76878019-AA02-42F3-B159-42201D702097}
Status: Access denied
Object: C:\Documents and Settings\User\Configurações locais\Dados de aplicativos\Microsoft\Messenger\rodrigoedc@hotmail.com\SharingMetadata\juliananataly@hotmail.com\DFSR\Staging\CS{1E77F5AE-2C2E-4C69-421D-C6E38EE7F0A2}\01\11-{1E77F5AE-2C2E-4C69-421D-C6E38EE7F0A2
Status: Hidden
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: C:\System Volume Information\tracking.log
Status: Access denied
Object: C:\System Volume Information\_restore{76878019-AA02-42F3-B159-42201D702097}
Status: Access denied