ComboFix 09-02-02.04 - User 2009-02-03 10:32:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.2030.1565 [GMT -2:00]
Executando de: c:\documents and settings\User\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *enabled*
* Criado um novo ponto de restauro
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\arquivos de programas\temp.tmp
.
(((((((((((((((( Arquivos/Ficheiros criados de 2009-01-03 to 2009-02-03 ))))))))))))))))))))))))))))
.
2009-02-03 10:06 . 2009-02-03 10:26 <DIR> d-------- c:\arquivos de programas\FindyKill
2009-02-03 10:04 . 2009-02-03 10:05 <DIR> d-------- C:\HijackThis
2009-02-03 03:17 . 2009-02-03 03:17 220,672 -r-hs---- C:\vshost.exe
2009-02-02 21:14 . 2009-02-02 21:14 <DIR> d-------- c:\documents and settings\User\Tracing
2009-02-02 21:09 . 2009-02-02 21:09 <DIR> d-------- c:\arquivos de programas\Microsoft
2009-02-02 21:08 . 2009-02-02 21:08 <DIR> d-------- c:\arquivos de programas\Windows Live SkyDrive
2009-02-02 20:52 . 2009-02-02 20:52 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Windows Live
2009-02-01 07:24 . 2003-10-27 14:06 140,488 --a------ c:\windows\system32\comdlg32.ocx
2009-02-01 07:24 . 2003-10-27 14:06 115,016 --a------ c:\windows\system32\MSINET.OCX
2009-02-01 07:24 . 2003-10-27 14:06 89,360 --a------ c:\windows\system32\VB5DB.DLL
2009-02-01 07:24 . 2003-10-27 14:06 69,632 --a------ c:\windows\system32\xmltok.dll
2009-02-01 07:24 . 2003-10-27 14:06 36,864 --a------ c:\windows\system32\xmlparse.dll
2009-02-01 07:24 . 2003-10-27 14:06 35,840 --a------ c:\windows\system32\comdlg32.oca
2009-02-01 07:24 . 2003-10-27 14:06 29,184 --a------ c:\windows\system32\MSINET.oca
2009-02-01 07:24 . 2003-10-27 14:06 26,096 --a------ c:\windows\system32\xmlinst.exe
2009-02-01 07:24 . 2003-10-27 14:06 24,576 --a------ c:\windows\system32\msxml3a.dll
2009-02-01 07:21 . 2009-02-01 07:24 <DIR> d-------- c:\arquivos de programas\UBISOFT
2009-01-23 00:23 . 2009-01-23 00:23 <DIR> d-------- c:\arquivos de programas\CCleaner
2009-01-22 23:12 . 2009-01-22 23:32 96,976 --a------ c:\windows\system32\drivers\klin.dat
2009-01-22 23:12 . 2009-01-22 23:12 87,855 --a------ c:\windows\system32\drivers\klick.dat
2009-01-22 23:11 . 2009-01-22 23:11 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab Setup Files
2009-01-22 23:11 . 2009-02-03 09:39 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab
2009-01-22 23:11 . 2009-01-22 23:11 <DIR> d-------- c:\arquivos de programas\Kaspersky Lab
2009-01-22 23:11 . 2009-02-03 11:29 5,419,040 --ahs---- c:\windows\system32\drivers\fidbox.dat
2009-01-22 23:11 . 2009-02-03 11:29 622,624 --ahs---- c:\windows\system32\drivers\fidbox2.dat
2009-01-22 23:11 . 2009-02-03 11:29 43,416 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-01-22 23:11 . 2009-02-03 11:29 3,208 --ahs---- c:\windows\system32\drivers\fidbox2.idx
2009-01-22 01:34 . 2009-01-22 01:34 <DIR> d-------- c:\arquivos de programas\Microsoft XNA
2009-01-22 01:25 . 2009-01-22 01:25 <DIR> d-------- c:\arquivos de programas\Beatnik Games
2009-01-14 23:33 . 2009-01-14 23:33 4,212 --ah----- c:\windows\system32\zllictbl.dat
2009-01-14 23:32 . 2009-01-22 23:00 <DIR> d-------- c:\windows\system32\ZoneLabs
2009-01-14 23:29 . 2009-01-22 22:56 <DIR> d-------- c:\windows\Internet Logs
2009-01-12 17:03 . 2009-01-12 17:03 <DIR> d-------- c:\arquivos de programas\Dyson
2009-01-11 14:46 . 2009-01-11 14:46 <DIR> d-------- c:\arquivos de programas\Codemasters
2009-01-10 23:36 . 2009-01-10 23:37 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Crayon Physics Deluxe
2009-01-10 23:36 . 2009-01-11 00:02 <DIR> d-------- c:\arquivos de programas\Crayon Physics Deluxe Demo
2009-01-10 17:12 . 2009-01-10 17:12 <DIR> d-------- c:\arquivos de programas\Audacity
2009-01-08 19:27 . 2009-01-08 19:34 203 --a------ c:\windows\GSdx9 sse2.INI
2009-01-06 23:55 . 2009-01-10 00:03 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\skypePM
2009-01-06 23:55 . 2009-01-06 23:55 56 --ah----- c:\windows\system32\ezsidmv.dat
2009-01-06 23:53 . 2009-01-22 22:54 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\Skype
2009-01-06 23:53 . 2009-01-06 23:53 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Skype
2009-01-06 23:53 . 2009-01-06 23:53 <DIR> d-------- c:\arquivos de programas\Skype
2009-01-06 23:53 . 2009-01-06 23:53 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Skype
2009-01-06 23:26 . 2009-01-06 23:26 <DIR> d-------- c:\documents and settings\User\Dados de aplicativos\teamspeak2
2009-01-06 23:26 . 2009-01-06 23:50 <DIR> d-------- c:\arquivos de programas\Teamspeak2_RC2
2009-01-06 23:26 . 2009-01-06 23:26 34,064 --a------ c:\windows\system32\lhacm.acm
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 13:29 --------- d-----w c:\documents and settings\User\Dados de aplicativos\WTablet
2009-02-02 23:22 --------- d-----w c:\arquivos de programas\Steam
2009-02-02 23:08 --------- d-----w c:\arquivos de programas\Windows Live
2009-02-01 09:21 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information
2009-01-30 04:02 --------- d-----w c:\arquivos de programas\DivX
2009-01-28 20:47 --------- d-----w c:\arquivos de programas\PaintTool SAI English Pack
2009-01-23 21:11 --------- d-----w c:\arquivos de programas\Lightside - Legend Ragnarok
2009-01-23 20:08 --------- d-----w c:\arquivos de programas\Gravity
2009-01-23 02:06 --------- d-----w c:\arquivos de programas\EA GAMES
2009-01-23 00:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Apple
2009-01-14 23:58 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Microsoft Help
2009-01-02 05:12 --------- d-----w c:\arquivos de programas\CFS-Technologies
2008-12-27 13:55 --------- d-----w c:\arquivos de programas\Cakewalk
2008-12-25 14:37 --------- d-----w c:\documents and settings\User\Dados de aplicativos\SYSTEMAX Software Development
2008-12-25 14:37 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SYSTEMAX Software Development
2008-12-25 05:49 --------- d-----w c:\arquivos de programas\Tablet
2008-12-24 19:01 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Test Drive Unlimited
2008-12-23 15:37 --------- d-----w c:\documents and settings\User\Dados de aplicativos\Image Zone Express
2008-12-20 01:10 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\TechSmith
2008-12-20 01:10 --------- d-----w c:\arquivos de programas\TechSmith
2008-12-20 01:10 --------- d-----w c:\arquivos de programas\Arquivos comuns\TechSmith Shared
2008-12-20 00:37 --------- d---a-w c:\documents and settings\All Users\Dados de aplicativos\TEMP
2008-12-19 06:33 --------- d-----w c:\arquivos de programas\CamStudio
2008-12-19 05:55 --------- d-----w c:\documents and settings\User\Dados de aplicativos\DivX
2008-12-19 05:06 --------- d-----w c:\documents and settings\User\Dados de aplicativos\Webcammax
2008-12-16 20:25 --------- d-----w c:\documents and settings\User\Dados de aplicativos\ZOO Digital Publishing
2008-12-16 20:16 --------- d-----w c:\arquivos de programas\ZOO Digital Publishing
2008-12-14 20:24 --------- d-----w c:\documents and settings\User\Dados de aplicativos\Hamachi
2008-12-14 02:33 --------- d-----w c:\documents and settings\User\Dados de aplicativos\SPORE
2008-12-14 01:38 --------- d-----w c:\arquivos de programas\Electronic Arts
2008-12-13 13:42 --------- d-----w c:\arquivos de programas\Violeiro
2008-12-13 01:14 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Subversion
2008-12-13 00:49 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Media Center Programs
2008-12-13 00:37 --------- d-----w c:\arquivos de programas\THQ
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-11 10:26 --------- d-----w c:\documents and settings\User\Dados de aplicativos\Printer Info Cache
2008-12-11 00:45 --------- d-----w c:\arquivos de programas\Hamachi
2008-12-11 00:44 25,280 ----a-w c:\windows\system32\drivers\hamachi.sys
2008-12-08 18:00 44 ----a-w c:\arquivos de programas\error_message.txt
2008-12-08 18:00 2,292,201 ----a-w c:\arquivos de programas\CHLOG.TXT
2008-12-08 17:59 479 ----a-w c:\arquivos de programas\R3Engine.ini
2008-12-08 17:59 --------- d-----w c:\arquivos de programas\System
2008-12-08 17:59 --------- d-----w c:\arquivos de programas\NetLog
2008-12-08 17:57 30,511 ----a-w c:\arquivos de programas\Uninstall.ini
2008-12-08 17:57 230,498 ----a-w c:\arquivos de programas\Uninstall.exe
2008-12-08 17:57 --------- d-----w c:\arquivos de programas\SpriteImage
2008-12-08 17:57 --------- d-----w c:\arquivos de programas\Snd
2008-12-08 17:57 --------- d-----w c:\arquivos de programas\HackShield
2008-12-08 17:57 --------- d-----w c:\arquivos de programas\Effect
2008-12-08 17:57 --------- d-----w c:\arquivos de programas\DataTable
2008-12-08 17:57 --------- d-----w c:\arquivos de programas\Chef
2008-12-08 14:33 --------- d-----w c:\arquivos de programas\Temp
2008-12-08 14:33 --------- d-----w c:\arquivos de programas\ScreenShots
2008-12-08 14:33 --------- d-----w c:\arquivos de programas\Map
2008-12-08 14:33 --------- d-----w c:\arquivos de programas\Item
2008-12-08 14:33 --------- d-----w c:\arquivos de programas\Character
2008-12-04 18:35 --------- d-----w c:\documents and settings\User\Dados de aplicativos\Nexon
2008-12-03 23:39 --------- d-----w c:\arquivos de programas\Arquivos comuns\DirectX
2008-11-07 02:24 65,536 ----a-w c:\windows\IFinst27.exe
2008-10-04 17:05 10,141,468 ----a-w c:\arquivos de programas\RF_Online.bin
2008-09-20 17:23 16,842 ----a-w c:\arquivos de programas\LauncherMessage.ini
2008-09-20 03:13 7,421,952 ----a-w c:\arquivos de programas\Just RF CCR.exe
2008-07-28 00:34 48,610 ----a-w c:\arquivos de programas\GameData.edf
2008-06-06 11:25 437,457 ----a-w c:\arquivos de programas\CharacterW.edf
2008-06-06 11:25 437,457 ----a-w c:\arquivos de programas\Character.edf
2008-04-25 15:11 2,127,673 ----a-w c:\arquivos de programas\Language.pak
2007-01-16 17:19 143,360 ----a-w c:\arquivos de programas\Updater.lc
2005-12-16 11:51 126 ----a-w c:\arquivos de programas\Ceba.env
2005-07-14 18:03 69,632 ----a-w c:\arquivos de programas\PurifierA.dll
2005-07-14 18:03 61,440 ----a-w c:\arquivos de programas\StringLoaderA.dll
2004-12-07 13:11 258,352 ----a-w c:\arquivos de programas\unicows.dll
2004-12-03 18:10 77,824 ----a-w c:\arquivos de programas\Adv.dll
2004-12-03 17:36 77,824 ----a-w c:\arquivos de programas\ABuse.dll
2004-10-08 14:34 163,840 ----a-w c:\arquivos de programas\X2PU.dll
2004-09-16 22:19 53,248 ----a-w c:\arquivos de programas\PDLL.dll
2004-08-29 22:31 14,816 ----a-w c:\arquivos de programas\x2prtm.sys
2004-08-18 18:20 184,320 ----a-w c:\arquivos de programas\TcX2G.dll
2004-08-18 18:20 15,264 ----a-w c:\arquivos de programas\x2prm2.sys
2004-08-18 18:20 106,496 ----a-w c:\arquivos de programas\X2PMgr.dll
2004-08-17 18:09 15,264 ----a-w c:\arquivos de programas\x2prm.sys
2004-08-17 18:09 106,496 ----a-w c:\arquivos de programas\X2ProcMon.dll
2004-05-10 22:50 188,416 ----a-w c:\arquivos de programas\X2ReportDll.dll
2003-06-14 21:18 39 ----a-w c:\arquivos de programas\dlctemp.db
2003-01-29 17:10 764,928 ----a-w c:\arquivos de programas\dbghelp.dll
2003-01-20 14:15 349,696 ----a-w c:\arquivos de programas\MSS32.DLL
2003-01-20 14:15 125,952 ----a-w c:\arquivos de programas\mssmp3.asi
2002-09-13 16:17 630 ----a-w c:\arquivos de programas\Sound.ini
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 18:52 80384 --a------ c:\arquivos de programas\Arquivos comuns\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 18:52 80384 --a------ c:\arquivos de programas\Arquivos comuns\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 18:52 80384 --a------ c:\arquivos de programas\Arquivos comuns\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 18:52 80384 --a------ c:\arquivos de programas\Arquivos comuns\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 18:52 80384 --a------ c:\arquivos de programas\Arquivos comuns\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 18:52 80384 --a------ c:\arquivos de programas\Arquivos comuns\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 18:52 80384 --a------ c:\arquivos de programas\Arquivos comuns\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 18:52 80384 --a------ c:\arquivos de programas\Arquivos comuns\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 18:52 80384 --a------ c:\arquivos de programas\Arquivos comuns\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Windows Service help"="c:\recycler\S-1-5-21-6804593228-6886361236-461749516-8377\winservices.exe" [2009-02-01 101376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-10-16 c:\windows\system32\advpack.dll]
c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\
HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.MJPG"= pvmjpg30.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 c:\arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
--a------ 2008-08-10 02:17 4608 c:\arquivos de programas\Alcohol Soft\Alcohol 120\AxCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 09:00 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-02-19 03:41 49152 c:\arquivos de programas\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-09-10 18:40 289576 c:\arquivos de programas\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 16:09 413696 c:\arquivos de programas\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-11-18 16:31 21633320 c:\arquivos de programas\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2008-08-01 15:23 61440 c:\arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 05:27 144784 c:\arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
--a------ 2008-04-10 21:07 413696 c:\arquivos de programas\IDT\WDM\sttray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=
"c:\\Arquivos de programas\\eMule\\emule.exe"=
"c:\\Arquivos de programas\\Arquivos comuns\\AOL\\Loader\\aolload.exe"=
"c:\\Arquivos de programas\\AIM6\\aim6.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\sysreset\\mirc.exe"=
"c:\\Arquivos de programas\\Mozilla Firefox\\firefox.exe"=
"c:\\Arquivos de programas\\Steam\\SteamApps\\dark_harpuia\\garrysmod\\hl2.exe"=
"c:\\Arquivos de programas\\Steam\\SteamApps\\dark_harpuia\\team fortress 2\\hl2.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Arquivos de programas\\Steam\\SteamApps\\dark_harpuia\\source sdk base\\hl2.exe"=
"c:\\Arquivos de programas\\Steam\\SteamApps\\dark_harpuia\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=
"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=
"c:\\Arquivos de programas\\Steam\\SteamApps\\dark_harpuia\\zombie panic! source\\hl2.exe"=
"c:\\Arquivos de programas\\Electronic Arts\\Red Alert 3\\RA3.exe"=
"c:\\Arquivos de programas\\Electronic Arts\\Red Alert 3\\Data\\ra3_1.0.game"=
"c:\\Arquivos de programas\\Steam\\SteamApps\\dark_harpuia\\synergy\\hl2.exe"=
"c:\\Arquivos de programas\\Electronic Arts\\Red Alert 3\\Data\\ra3_1.4.game"=
"c:\\Arquivos de programas\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"c:\\Arquivos de programas\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"c:\\Documents and Settings\\All Users\\Documentos\\TDU\\TestDriveUnlimited.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
"c:\\Arquivos de programas\\Steam\\SteamApps\\dark_harpuia\\counter-strike source\\hl2.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2008-08-04 143360]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-12-25 1373480]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\arquivos de programas\Viewpoint\Common\ViewpointService.exe [2008-08-10 24652]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
S3 XDva164;XDva164;\??\c:\windows\system32\XDva164.sys --> c:\windows\system32\XDva164.sys [?]
--- ---
*NewlyCreated* - HELPSVC
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-21CX1C987892}]
c:\recycle\X-5-4-27-2345678318-4567890223-4234567884-2341\RisinG.exe
.
- - - - ORFÃOS REMOVIDOS - - - -
MSConfigStartUp-Windows Service help - c:\recycler\S-1-5-21-1976568937-2908462829-913181723-8365\winservices.exe
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.uol.com.br/
uInternet Settings,ProxyOverride = *.local
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {9387692E-DB41-42AF-ABDD-570105DB4E74} = 200.204.0.10,192.168.0.1
FF - ProfilePath - c:\documents and settings\User\Dados de aplicativos\Mozilla\Firefox\Profiles\72q44vj2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.uol.com.br/
FF - component: c:\arquivos de programas\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\arquivos de programas\GameTap\bin\Release\npgametaptool.dll
FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\arquivos de programas\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\documents and settings\User\Dados de aplicativos\Mozilla\Firefox\Profiles\72q44vj2.default\extensions\activegs@freetoolsassociation.com\plugins\npActiveGS.dll
---- FIREFOX POLICIES ----
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-03 11:31:53
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(268)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Outros Processos em Execução ------------------------
.
c:\arquivos de programas\TortoiseSVN\bin\TSVNCache.exe
.
**************************************************************************
.
Tempo para conclusão: 2009-02-03 11:36:11 - Máquina reiniciou
ComboFix-quarantined-files.txt 2009-02-03 13:36:09
Pré-execução: 21 pasta(s) 70.492.815.360 bytes disponíveis
Pós execução: 21 pasta(s) 70,513,897,472 bytes disponíveis
WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
345 --- E O F --- 2009-01-14 23:58:16