Logfile of random's system information tool 1.06 (written by random/random)
Run by Nanda at 2009-05-19 18:27:04
Microsoft Windows XP Professional Service Pack 3
System drive C: has 244 MB (2%) free of 15 GB
Total RAM: 1280 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:27:12, on 19/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
C:\Arquivos de programas\Justsoft WinPolicy\WPService.exe
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\Arquivos de programas\Justsoft WinPolicy\autolock.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe
C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe
C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe
C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe
C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Nanda\Desktop\RSIT.exe
C:\Arquivos de programas\trend micro\Nanda.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &
http://home.microsoft.com/intl/br/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\ARQUIV~1\GbPlugin\gbiehuni.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [WinPolicy] WPLocker.exe
O4 - HKLM\..\RunServices: [WinPolicy] WPLocker.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&
http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1231535316093
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) -
http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) -
https://www14.bancobrasil.com.br/plugin/GbpDist.cab
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} (GbPluginObj Class) -
https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab
O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll
O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O20 - Winlogon Notify: GbPluginUni - C:\ARQUIV~1\GbPlugin\gbiehuni.dll
O23 - Service: 1A3EB52E6AA1211D33BE0B506F603A2E - Unknown owner - cmd /k start /i "/dC:" "C:\ComboFix\HIDEC.exe" "C:\ComboFix\SWREG.EXE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q (file missing)
O23 - Service: 5E97F1BB56B10FEA933EDE3BD6BC91DE - Unknown owner - cmd /k start /i "/dC:" "C:\ComboFix\HIDEC.exe" "C:\ComboFix\SWREG.EXE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q (file missing)
O23 - Service: A1CC99E0A931743763C41EA94D6A6CDF - Unknown owner - cmd /k start /i "/dC:" "C:\ComboFix\HIDEC.exe" "C:\ComboFix\SWREG.EXE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q (file missing)
O23 - Service: ADBDAC948DCA2ECE559564AA3F229144 - Unknown owner - cmd /k start /i "/dC:" "C:\ComboFix\HIDEC.exe" "C:\ComboFix\SWREG.EXE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe
O23 - Service: WinPolicy AutoLock (AutoLock) - Unknown owner - C:\Arquivos de programas\Justsoft WinPolicy\WPService.exe
O23 - Service: DCA3DDEC447564CE7E4E0ADA14189564 - Unknown owner - cmd /k start /i "/dC:" "C:\ComboFix\HIDEC.exe" "C:\ComboFix\SWREG.EXE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q (file missing)
O23 - Service: EAA18C593446C91C67AEAF9FEE6792B8 - Unknown owner - cmd /k start /i "/dC:" "C:\ComboFix\HIDEC.exe" "C:\ComboFix\SWREG.EXE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q (file missing)
O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe
--
End of file - 9302 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-01-09 304736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}]
Megaupload Toolbar - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL [2006-10-31 1803720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Arquivos de programas\Java\jre6\bin\ssv.dll [2009-01-09 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Auxiliar de Conexão do Windows Live - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540000}]
GbIehObj Class - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll [2009-03-25 271152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540003}]
GbIehObj Class - C:\Arquivos de programas\GbPlugin\gbiehcef.dll [2009-03-27 264776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540008}]
GbIehObj Class - C:\ARQUIV~1\GbPlugin\gbiehuni.dll [2009-03-25 414624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll [2009-01-09 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-09 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Megaupload Toolbar - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL [2006-10-31 1803720]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"=C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe [2009-01-09 185872]
"SpywareTerminator"=C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe [2009-03-29 2233856]
"ISUSPM Startup"=C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe [2005-08-11 249856]
"ISUSScheduler"=C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe [2005-08-11 81920]
"avgnt"=C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"WinPolicy"=C:\WINDOWS\system32\WPLocker.exe [2006-09-27 420420]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ GbPluginBb]
C:\Arquivos de programas\GbPlugin\gbieh.dll [2009-03-25 271152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ GbPluginCef]
C:\Arquivos de programas\GbPlugin\gbiehcef.dll [2009-03-27 264776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ GbPluginUni]
C:\ARQUIV~1\GbPlugin\gbiehuni.dll [2009-03-25 414624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E37CB5F0-51F5-4395-A808-5FA49E399F83}"=C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll [2009-03-25 271152]
"{E37CB5F0-51F5-4395-A808-5FA49E399003}"=C:\Arquivos de programas\GbPlugin\gbiehcef.dll [2009-03-27 264776]
"{E37CB5F0-51F5-4395-A808-5FA49E399008}"=C:\ARQUIV~1\GbPlugin\gbiehuni.dll [2009-03-25 414624]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"RestrictRun"=0
"NoDrives"=0
"NoViewOnDrive"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled
![Mad :mad: :mad:](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled
![Mad :mad: :mad:](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
xpsp3res.dll,-20000"
"C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe"="C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe:*:Enabled
![Stick Out Tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
ando Media Booster"
"C:\Arquivos de programas\LimeWire\LimeWire.exe"="C:\Arquivos de programas\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Arquivos de programas\uTorrent\uTorrent.exe"="C:\Arquivos de programas\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Arquivos de programas\SopCast\adv\SopAdver.exe"="C:\Arquivos de programas\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\Documents and Settings\All Users\Dados de aplicativos\NexonUS\NGM\NGM.exe"="C:\Documents and Settings\All Users\Dados de aplicativos\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager"
"C:\Arquivos de programas\Internet Explorer\iexplore.exe"="C:\Arquivos de programas\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Arquivos de programas\Java\jre6\launch4j-tmp\JDownloader.exe"="C:\Arquivos de programas\Java\jre6\launch4j-tmp\JDownloader.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\WINDOWS\system32\ftp.exe"="C:\WINDOWS\system32\ftp.exe:*:Enabled
![Stick Out Tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rograma de transferência de arquivos"
"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled
![Mad :mad: :mad:](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled
![Mad :mad: :mad:](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
xpsp3res.dll,-20000"
"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
======List of files/folders created in the last 2 months======
2009-05-19 17:47:09 ----D---- C:\ComboFix
2009-05-19 17:47:08 ----A---- C:\WINDOWS\system32\CF1355.exe
2009-05-19 17:43:11 ----A---- C:\WINDOWS\system32\CF588.exe
2009-05-19 17:30:04 ----A---- C:\WINDOWS\system32\CF30668.exe
2009-05-19 07:49:08 ----D---- C:\Arquivos de programas\Justsoft WinPolicy
2009-05-18 20:15:38 ----A---- C:\WINDOWS\system32\CF10453.exe
2009-05-18 20:13:47 ----A---- C:\WINDOWS\OEWABLog.txt
2009-05-18 20:12:47 ----D---- C:\WINDOWS\Prefetch
2009-05-18 19:40:29 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-05-18 19:40:09 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-05-18 19:38:26 ----A---- C:\WINDOWS\setuplog.txt
2009-05-18 19:32:24 ----D---- C:\Arquivos de programas\Messenger
2009-05-18 19:32:02 ----D---- C:\WINDOWS\system32\bits
2009-05-18 19:32:02 ----D---- C:\WINDOWS\l2schemas
2009-05-18 19:28:20 ----D---- C:\WINDOWS\ServicePackFiles
2009-05-18 19:23:10 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-05-18 19:20:03 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-05-18 19:04:17 ----SHD---- C:\Config.Msi
2009-05-18 18:53:45 ----A---- C:\WINDOWS\system32\CF27174.exe
2009-05-18 18:51:03 ----A---- C:\WINDOWS\system32\CF26651.exe
2009-05-18 18:50:14 ----D---- C:\WINDOWS\CSC
2009-05-18 18:50:05 ----A---- C:\WINDOWS\ntbtlog.txt
2009-05-18 18:45:26 ----A---- C:\Boot.bak
2009-05-18 18:45:20 ----RASHD---- C:\cmdcons
2009-05-18 18:41:28 ----A---- C:\WINDOWS\zip.exe
2009-05-18 18:41:28 ----A---- C:\WINDOWS\vFind.exe
2009-05-18 18:41:28 ----A---- C:\WINDOWS\SWREG.exe
2009-05-18 18:41:28 ----A---- C:\WINDOWS\NIRCMD.exe
2009-05-18 18:41:27 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-05-18 18:41:27 ----A---- C:\WINDOWS\SWSC.exe
2009-05-18 18:41:27 ----A---- C:\WINDOWS\sed.exe
2009-05-18 18:41:27 ----A---- C:\WINDOWS\grep.exe
2009-05-18 18:41:22 ----D---- C:\WINDOWS\ERDNT
2009-05-18 18:41:21 ----A---- C:\WINDOWS\system32\CF24750.exe
2009-05-18 18:41:13 ----D---- C:\Qoobox
2009-05-18 18:28:05 ----HDC---- C:\WINDOWS\ie8
2009-05-18 18:23:01 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2009-05-17 12:11:49 ----D---- C:\_OTMoveIt
2009-05-16 21:47:28 ----D---- C:\Arquivos de programas\Windows Live Safety Center
2009-05-16 13:39:03 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Avira
2009-05-16 13:39:03 ----D---- C:\Arquivos de programas\Avira
2009-05-16 13:21:38 ----D---- C:\rsit
2009-05-16 13:21:38 ----D---- C:\Arquivos de programas\trend micro
2009-05-16 13:04:46 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2009-05-11 18:33:28 ----HD---- C:\WINDOWS\system32\GroupPolicy
2009-05-03 22:22:02 ----A---- C:\WINDOWS\SYMGAMES.INI
2009-04-26 11:09:06 ----D---- C:\Documents and Settings\Nanda\Dados de aplicativos\teamspeak2
2009-04-24 22:40:48 ----A---- C:\WINDOWS\casino1.ini
2009-04-22 11:45:00 ----D---- C:\Arquivos de programas\MSECache
2009-04-22 11:29:42 ----A---- C:\WINDOWS\MegaManager.INI
2009-04-22 11:20:09 ----D---- C:\Arquivos de programas\MegauploadToolbar
2009-04-22 11:20:08 ----D---- C:\Documents and Settings\Nanda\Dados de aplicativos\MegauploadToolbar
2009-04-22 10:02:05 ----D---- C:\downloads
2009-04-22 10:02:05 ----D---- C:\Documents and Settings\Nanda\Dados de aplicativos\GrabPro
2009-04-22 10:01:58 ----D---- C:\Documents and Settings\Nanda\Dados de aplicativos\Orbit
2009-04-18 20:22:21 ----D---- C:\Documents and Settings\Nanda\Dados de aplicativos\Corel
2009-04-18 19:00:23 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\InstallShield
2009-04-18 18:56:46 ----D---- C:\Arquivos de programas\Corel
2009-04-18 18:56:46 ----D---- C:\Arquivos de programas\Arquivos comuns\Corel
2009-04-18 16:13:54 ----A---- C:\WINDOWS\HEARTS.INI
2009-04-18 15:56:38 ----A---- C:\WINDOWS\EntPack.ini
2009-04-18 15:43:08 ----A---- C:\WINDOWS\EmSoft.ini
2009-04-12 22:32:02 ----D---- C:\Arquivos de programas\Jufsoft
2009-04-12 22:23:20 ----D---- C:\Arquivos de programas\Runtime Software
2009-04-12 22:17:30 ----D---- C:\Arquivos de programas\PowerDataRecovery
2009-04-12 22:02:47 ----D---- C:\Arquivos de programas\PC Inspector File Recovery
2009-04-04 14:50:53 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\NexonUS
2009-04-03 08:57:14 ----D---- C:\Arquivos de programas\TVUPlayer
2009-04-03 08:56:26 ----D---- C:\Arquivos de programas\SopCast
2009-04-02 23:04:21 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\VistaCodecs
2009-04-02 18:06:24 ----D---- C:\Documents and Settings\Nanda\Dados de aplicativos\GRETECH
2009-04-02 18:05:40 ----D---- C:\Arquivos de programas\GRETECH
2009-03-29 09:27:15 ----D---- C:\Documents and Settings\Nanda\Dados de aplicativos\Spyware Terminator
2009-03-29 09:27:12 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\Spyware Terminator
2009-03-29 09:27:11 ----D---- C:\Arquivos de programas\Spyware Terminator
2009-03-29 09:01:13 ----D---- C:\Arquivos de programas\Arquivos comuns\EZB Systems
2009-03-29 09:01:12 ----D---- C:\Arquivos de programas\UltraISO
2009-03-23 22:46:57 ----D---- C:\Documents and Settings\Nanda\Dados de aplicativos\Desktopicon
2009-03-23 22:46:55 ----D---- C:\Arquivos de programas\Unlocker
======List of files/folders modified in the last 2 months======
2009-05-19 17:49:04 ----D---- C:\WINDOWS\system32\CatRoot2
2009-05-19 17:48:55 ----D---- C:\WINDOWS\Temp
2009-05-19 17:48:16 ----AD---- C:\WINDOWS\system32\drivers
2009-05-19 17:47:33 ----D---- C:\WINDOWS\system32
2009-05-19 17:47:19 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-05-19 13:29:58 ----D---- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin
2009-05-19 07:49:08 ----RD---- C:\Arquivos de programas
2009-05-18 20:17:30 ----D---- C:\WINDOWS
2009-05-18 20:14:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-05-18 20:13:51 ----D---- C:\WINDOWS\Debug
2009-05-18 20:12:24 ----D---- C:\WINDOWS\system32\Setup
2009-05-18 20:12:24 ----D---- C:\WINDOWS\AppPatch
2009-05-18 20:12:23 ----RSD---- C:\WINDOWS\Fonts
2009-05-18 20:12:23 ----D---- C:\WINDOWS\system32\wbem
2009-05-18 19:45:53 ----D---- C:\WINDOWS\security
2009-05-18 19:40:58 ----D---- C:\WINDOWS\system32\CatRoot
2009-05-18 19:40:45 ----HD---- C:\WINDOWS\inf
2009-05-18 19:40:34 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-05-18 19:36:57 ----D---- C:\WINDOWS\WinSxS
2009-05-18 19:32:23 ----D---- C:\WINDOWS\ehome
2009-05-18 19:32:21 ----D---- C:\WINDOWS\system32\inetsrv
2009-05-18 19:32:21 ----D---- C:\WINDOWS\network diagnostic
2009-05-18 19:32:21 ----D---- C:\WINDOWS\Help
2009-05-18 19:32:20 ----D---- C:\WINDOWS\ime
2009-05-18 19:32:04 ----D---- C:\WINDOWS\system32\usmt
2009-05-18 19:32:04 ----D---- C:\WINDOWS\system32\pt-br
2009-05-18 19:32:02 ----SHD---- C:\WINDOWS\Installer
2009-05-18 19:32:02 ----D---- C:\WINDOWS\PeerNet
2009-05-18 19:32:01 ----D---- C:\Arquivos de programas\Movie Maker
2009-05-18 19:27:59 ----D---- C:\WINDOWS\system32\Restore
2009-05-18 19:27:59 ----D---- C:\WINDOWS\system32\npp
2009-05-18 19:27:57 ----D---- C:\WINDOWS\msagent
2009-05-18 19:27:54 ----D---- C:\WINDOWS\srchasst
2009-05-18 19:27:53 ----D---- C:\Arquivos de programas\NetMeeting
2009-05-18 19:27:51 ----D---- C:\WINDOWS\system32\Com
2009-05-18 19:27:49 ----D---- C:\Arquivos de programas\Windows Media Player
2009-05-18 19:27:48 ----D---- C:\Arquivos de programas\Windows NT
2009-05-18 19:27:48 ----D---- C:\Arquivos de programas\Outlook Express
2009-05-18 19:27:44 ----D---- C:\Arquivos de programas\Arquivos comuns\System
2009-05-18 19:27:15 ----D---- C:\WINDOWS\system32\oobe
2009-05-18 19:27:13 ----D---- C:\WINDOWS\system
2009-05-18 19:06:36 ----D---- C:\WINDOWS\SoftwareDistribution
2009-05-18 18:45:26 ----RASH---- C:\boot.ini
2009-05-18 18:37:13 ----D---- C:\WINDOWS\Media
2009-05-18 18:37:13 ----D---- C:\Arquivos de programas\Internet Explorer
2009-05-18 18:22:59 ----HD---- C:\WINDOWS\$hf_mig$
2009-05-16 13:38:34 ----D---- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared
2009-05-16 13:16:33 ----SHD---- C:\System Volume Information
2009-05-16 11:48:08 ----D---- C:\WINDOWS\system32\config
2009-05-07 00:16:30 ----A---- C:\WINDOWS\system32\MRT.exe
2009-05-06 19:00:13 ----A---- C:\WINDOWS\NeroDigital.ini
2009-04-27 18:10:01 ----D---- C:\Arquivos de programas\GbPlugin
2009-04-26 23:33:08 ----D---- C:\Arquivos de programas\Foxit Software
2009-04-25 14:41:43 ----SD---- C:\Documents and Settings\Nanda\Dados de aplicativos\Microsoft
2009-04-22 11:45:16 ----D---- C:\Arquivos de programas\Microsoft Office
2009-04-22 11:19:57 ----HD---- C:\Arquivos de programas\InstallShield Installation Information
2009-04-18 19:00:15 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-04-18 19:00:14 ----D---- C:\Arquivos de programas\Arquivos comuns\InstallShield
2009-04-18 18:59:53 ----D---- C:\Arquivos de programas\Arquivos comuns\DESIGNER
2009-04-18 18:56:46 ----D---- C:\Arquivos de programas\Arquivos comuns
2009-04-12 18:41:01 ----SD---- C:\WINDOWS\Tasks
2009-04-02 18:14:39 ----D---- C:\Documents and Settings\Nanda\Dados de aplicativos\Vso
2009-03-31 00:52:28 ----A---- C:\WINDOWS\win.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK7;AMD K7 Processor Driver; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-13 41856]
R1 avgio;avgio; \??\C:\Arquivos de programas\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-05-16 96104]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Arquivos de programas\UltraISO\drivers\ISODrive.sys []
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14720]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-02-13 28376]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-05-16 55640]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 hidusb;Driver de classe HID da Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-28 12288]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-03-19 47360]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-07-15 578368]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 as8wpoml;as8wpoml; C:\WINDOWS\system32\drivers\as8wpoml.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\Nanda\CONFIG~1\Temp\catchme.sys []
S3 EagleNT;EagleNT; C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 XDva224;XDva224; C:\WINDOWS\system32\drivers\XDva224.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe [2009-05-16 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe [2009-03-02 185089]
R2 AutoLock;WinPolicy AutoLock; C:\Arquivos de programas\Justsoft WinPolicy\WPService.exe [2006-09-27 93132]
R2 GbpSv;Gbp Service; C:\ARQUIV~1\GbPlugin\GbpSv.exe [2009-03-27 52808]
R2 JavaQuickStarterService;Java Quick Starter; C:\Arquivos de programas\Java\jre6\bin\jqs.exe [2009-01-09 152984]
R2 MDM;Machine Debug Manager; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe [2009-03-29 540672]
S2 1A3EB52E6AA1211D33BE0B506F603A2E;1A3EB52E6AA1211D33BE0B506F603A2E; cmd /k start /i /dC: C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q []
S2 5E97F1BB56B10FEA933EDE3BD6BC91DE;5E97F1BB56B10FEA933EDE3BD6BC91DE; cmd /k start /i /dC: C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q []
S2 A1CC99E0A931743763C41EA94D6A6CDF;A1CC99E0A931743763C41EA94D6A6CDF; cmd /k start /i /dC: C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q []
S2 ADBDAC948DCA2ECE559564AA3F229144;ADBDAC948DCA2ECE559564AA3F229144; cmd /k start /i /dC: C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q []
S2 DCA3DDEC447564CE7E4E0ADA14189564;DCA3DDEC447564CE7E4E0ADA14189564; cmd /k start /i /dC: C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q []
S2 EAA18C593446C91C67AEAF9FEE6792B8;EAA18C593446C91C67AEAF9FEE6792B8; cmd /k start /i /dC: C:\ComboFix\HIDEC.exe C:\ComboFix\SWREG.EXE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q []
S3 NMIndexingService;NMIndexingService; C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe [2007-12-13 447784]
S3 ose;Office Source Engine; C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WLSetupSvc;Windows Live Setup Service; C:\Arquivos de programas\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Serviço de Compartilhamento de Rede do Windows Media Player; C:\Arquivos de programas\Windows Media Player\WMPNetwk.exe [2006-11-02 914944]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
-----------------EOF-----------------