ComboFix 09-07-13.01 - azul 13/07/2009 17:00.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.1983.1538 [GMT -3:00]
Executando de: c:\documents and settings\azul\Desktop\ComboFix.exe
Comandos utilizados :: c:\documents and settings\azul\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
* Criado um novo ponto de restauração
ATENÇAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAÇÃO INSTALADA !!
FILE ::
"C:\9j.exe"
"C:\dkelr.exe"
"c:\documents and settings\azul\Menu Iniciar\Programas\Inicializar\ihaupd32.exe"
"C:\kmvu.exe"
"C:\mkvknro.exe"
"c:\windows\system32\ubb.exe"
.
(((((((((((((((( Arquivos/Ficheiros criados de 2009-06-13 to 2009-07-13 ))))))))))))))))))))))))))))
.
2009-07-11 12:46 . 2009-07-11 12:46 -------- d-----w- c:\documents and settings\azul\Dados de aplicativos\TeamViewer
2009-07-11 12:46 . 2009-07-11 12:46 -------- d-----w- c:\arquivos de programas\TeamViewer
2009-07-11 12:46 . 2009-07-11 12:46 -------- d-----w- c:\documents and settings\azul\temp
2009-07-10 17:59 . 2009-07-10 18:04 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-07-10 17:59 . 2009-07-10 18:04 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-10 17:59 . 2009-02-13 14:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-07-10 17:59 . 2009-02-13 14:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-07-10 17:59 . 2009-07-10 17:59 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Avira
2009-07-10 17:59 . 2009-07-10 17:59 -------- d-----w- c:\arquivos de programas\Avira
2009-07-10 17:58 . 2009-07-10 17:58 -------- d-----w- C:\Avira Free
2009-07-10 14:35 . 2009-07-10 14:35 -------- d-----w- c:\arquivos de programas\CCleaner
2009-07-10 14:33 . 2009-07-10 14:34 3252640 ----a-w- C:\ccsetup221.exe
2009-07-10 14:30 . 2009-07-13 19:24 -------- d-----w- C:\HijackThis
2009-07-10 14:30 . 2009-07-10 14:30 812344 ----a-w- C:\HJTInstall.exe
2009-07-10 14:25 . 2009-07-10 14:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\NOS
2009-07-10 14:25 . 2009-07-10 14:38 -------- d-----w- c:\arquivos de programas\NOS
2009-07-10 13:49 . 2009-07-10 13:49 -------- d-----w- c:\documents and settings\azul\Dados de aplicativos\Malwarebytes
2009-07-10 13:23 . 2009-06-21 18:45 -------- d--h--w- c:\documents and settings\Administrador\Modelos
2009-07-10 13:23 . 2009-06-21 15:38 -------- d-----w- c:\documents and settings\Administrador\Meus documentos
2009-07-10 13:23 . 2009-06-21 15:38 -------- d-----w- c:\documents and settings\Administrador\Favoritos
2009-07-10 13:23 . 2009-06-21 15:38 -------- d-----r- c:\documents and settings\Administrador\Menu Iniciar
2009-06-25 12:21 . 2009-06-25 12:21 -------- d-----w- c:\documents and settings\azul\Dados de aplicativos\HP
2009-06-25 12:21 . 2009-06-25 12:21 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\HP
2009-06-25 12:17 . 2006-03-04 00:03 65536 ----a-w- c:\windows\system32\HPZinw12.exe
2009-06-25 12:17 . 2006-03-04 00:03 69632 ----a-w- c:\windows\system32\HPZipm12.exe
2009-06-25 12:17 . 2006-03-04 00:02 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2009-06-25 12:17 . 2006-03-04 00:02 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2009-06-25 12:17 . 2006-03-04 00:02 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2009-06-25 12:17 . 2006-03-04 00:03 282680 ----a-w- c:\windows\system32\HPZidr12.dll
2009-06-25 12:15 . 2009-06-25 12:25 126123 ----a-w- c:\windows\HPHins12.dat
2009-06-25 12:15 . 2006-06-12 22:21 14916 ------w- c:\windows\hphmdl12.dat
2009-06-25 12:14 . 2006-05-16 06:25 77824 ----a-r- c:\windows\system32\hpzids01.dll
2009-06-25 12:14 . 2006-06-04 00:29 48640 ----a-w- c:\windows\system32\hpzll4pi.dll
2009-06-25 12:12 . 2004-08-04 02:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-06-25 12:12 . 2004-08-04 02:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-06-25 12:08 . 2001-03-08 21:30 24064 ------w- c:\windows\system32\msxml3a.dll
2009-06-25 12:07 . 2009-06-25 12:08 -------- d-----w- c:\arquivos de programas\CyberLink
2009-06-25 11:51 . 2009-06-25 12:52 -------- d-----w- c:\documents and settings\azul\Dados de aplicativos\Ahead
2009-06-25 11:47 . 2009-06-25 11:53 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Ahead
2009-06-25 11:47 . 2009-06-25 11:47 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Nero
2009-06-25 11:47 . 2009-06-25 11:47 -------- d-----w- c:\arquivos de programas\Nero
2009-06-25 11:41 . 2002-11-05 20:15 1806 ----a-w- c:\windows\mHotkey.reg
2009-06-25 11:41 . 2001-12-26 17:12 472576 ----a-w- c:\windows\mHotkey.exe
2009-06-25 11:41 . 2001-07-02 23:36 24576 ----a-w- c:\windows\HKNTDLL.dll
2009-06-25 11:41 . 2000-09-01 23:21 294912 ----a-r- c:\windows\Record.exe
2009-06-25 11:40 . 2009-07-07 12:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Bluetooth
2009-06-25 11:38 . 2009-06-25 11:38 -------- d-----w- c:\windows\BisonC07
2009-06-25 11:38 . 2007-09-11 22:49 810280 ----a-w- c:\windows\system32\drivers\BisonC07.sys
2009-06-25 11:38 . 2007-08-10 20:02 188416 ----a-w- c:\windows\system32\BisonR07.dll
2009-06-25 11:38 . 2007-07-23 22:35 106496 ----a-w- c:\windows\system\BisonV07.dll
2009-06-25 11:38 . 2007-07-23 22:35 172032 ----a-w- c:\windows\system\BisonC07.dll
2009-06-25 11:38 . 2005-01-14 00:47 180224 ----a-w- c:\windows\system\StillDrv.dll
2009-06-25 11:37 . 2009-06-25 11:38 -------- d-----w- c:\windows\BisonCam
2009-06-25 11:37 . 2009-06-25 11:37 -------- d-----w- c:\documents and settings\azul\Dados de aplicativos\InstallShield
2009-06-25 11:35 . 2004-08-04 03:45 54784 ----a-w- c:\windows\system32\drivers\vfwwdm32.dll
2009-06-25 11:33 . 2009-06-25 11:33 -------- d-----w- c:\arquivos de programas\DIFX
2009-06-25 11:32 . 2006-05-10 15:12 43520 ----a-w- c:\windows\system32\drivers\AmdK8.sys
2009-06-25 11:22 . 2005-07-28 10:26 69721 ----a-w- c:\windows\system32\SynTPFcs.dll
2009-06-25 11:22 . 2005-07-28 10:27 81920 ----a-w- c:\windows\system32\SynTPCo2.dll
2009-06-25 11:22 . 2005-07-28 10:16 90201 ----a-w- c:\windows\system32\SynTPAPI.dll
2009-06-25 11:22 . 2005-07-28 10:15 82012 ----a-w- c:\windows\system32\SynCOM.dll
2009-06-25 11:22 . 2005-07-28 10:15 114688 ----a-w- c:\windows\system32\SynCtrl.dll
2009-06-25 11:22 . 2005-07-28 10:13 190592 ----a-w- c:\windows\system32\drivers\SynTP.sys
2009-06-25 11:22 . 2009-06-25 11:22 -------- d-----w- c:\arquivos de programas\Synaptics
2009-06-24 17:03 . 2008-06-14 17:59 272384 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-06-24 17:03 . 2008-06-14 17:59 272384 ------w- c:\windows\system32\drivers\bthport.sys
2009-06-24 17:01 . 2009-02-09 11:50 2019840 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-06-24 17:01 . 2009-02-09 11:50 2061952 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-06-24 17:01 . 2009-02-09 11:50 2184704 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-06-24 17:01 . 2009-02-09 11:50 2140160 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-06-24 16:35 . 2008-10-24 11:10 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-06-24 15:44 . 2008-03-17 14:56 103168 ----a-w- c:\windows\system32\drivers\ewusbfake.sys
2009-06-24 15:44 . 2008-03-17 14:03 101376 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2009-06-24 15:44 . 2008-03-16 17:47 872192 ----a-w- c:\windows\system32\drivers\mod7700.sys
2009-06-24 15:44 . 2008-01-22 18:09 100992 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2009-06-24 15:44 . 2007-08-09 07:13 24448 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2009-06-23 13:57 . 2001-09-06 02:20 12288 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-06-23 13:57 . 2001-09-06 02:20 12288 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-06-23 13:57 . 2001-08-18 01:02 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-06-23 13:57 . 2001-08-18 01:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-06-23 12:38 . 2009-07-07 13:11 2620 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-23 12:38 . 2009-06-23 12:38 -------- d-----w- c:\documents and settings\azul\Dados de aplicativos\Corel
2009-06-23 01:37 . 2009-06-23 12:31 65536 ----a-r- c:\documents and settings\azul\Dados de aplicativos\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
2009-06-23 01:37 . 2009-06-23 12:31 10134 ----a-r- c:\documents and settings\azul\Dados de aplicativos\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\ARPPRODUCTICON.exe
2009-06-23 01:37 . 2009-06-23 01:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\InstallShield
2009-06-23 01:19 . 2006-10-26 22:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-06-23 01:14 . 2009-07-06 13:33 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft Help
2009-06-23 01:13 . 2003-03-18 21:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-06-23 01:13 . 2003-03-18 20:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2009-06-23 01:13 . 2003-02-21 04:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2009-06-23 01:10 . 2009-06-23 01:10 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\nView_Profiles
2009-06-23 01:07 . 2009-06-23 01:05 180224 ----a-w- c:\windows\system32\nvudisp.exe
2009-06-23 01:00 . 2009-06-23 00:59 180608 ----a-w- c:\windows\system32\drivers\RTL8187.sys
2009-06-23 00:48 . 2009-06-23 00:48 -------- d-----w- c:\arquivos de programas\Clevo
2009-06-23 00:48 . 2002-10-16 13:06 32768 ----a-w- c:\windows\system32\Fngkhlib.dll
2009-06-23 00:48 . 1998-04-24 18:09 28160 ----a-w- c:\windows\system32\Fngmhlib.dll
2009-06-23 00:48 . 1998-10-29 19:45 306688 ----a-w- c:\windows\IsUninst.exe
2009-06-23 00:48 . 2009-06-23 00:48 -------- d-----w- c:\documents and settings\azul\WINDOWS
2009-06-21 20:07 . 2004-08-04 02:08 60288 -c--a-w- c:\windows\system32\dllcache\drmk.sys
2009-06-21 20:07 . 2004-08-04 02:08 60288 ----a-w- c:\windows\system32\drivers\drmk.sys
2009-06-21 20:07 . 2008-07-09 07:34 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-06-21 20:07 . 2009-06-21 19:36 487424 ----a-w- c:\windows\RtlExUpd.dll
2009-06-21 20:06 . 2008-03-26 15:30 442368 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-21 20:06 . 2004-08-04 02:08 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2009-06-21 20:03 . 2009-06-23 00:37 222592 ----a-w- c:\windows\system32\drivers\nvsnpu.sys
2009-06-21 18:54 . 2009-07-10 15:18 -------- d--h--w- c:\documents and settings\LocalService.AUTORIDADE NT\Configurações locais
2009-06-21 18:54 . 2009-06-21 18:54 -------- d-----w- c:\documents and settings\LocalService.AUTORIDADE NT\Dados de aplicativos
2009-06-21 18:54 . 2009-06-21 18:54 -------- d-sh--w- c:\documents and settings\LocalService.AUTORIDADE NT
2009-06-21 18:53 . 2009-07-10 15:18 -------- d--h--w- c:\documents and settings\NetworkService.AUTORIDADE NT\Configurações locais
2009-06-21 18:53 . 2009-06-21 18:53 -------- d-----w- c:\documents and settings\NetworkService.AUTORIDADE NT\Dados de aplicativos
2009-06-21 18:53 . 2009-06-21 18:53 -------- d-sh--w- c:\documents and settings\NetworkService.AUTORIDADE NT
2009-06-21 18:51 . 2001-10-28 18:07 111104 -c--a-w- c:\windows\system32\dllcache\mtstocom.exe
2009-06-21 18:50 . 2004-08-04 01:31 480256 -c--a-w- c:\windows\system32\dllcache\cintsetp.exe
2009-06-21 18:48 . 2009-06-25 11:46 -------- d-sh--w- c:\documents and settings\All Users.WINDOWS\DRM
2009-06-21 18:46 . 2009-06-21 18:46 21844 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-21 15:43 . 2004-08-03 22:58 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2009-06-21 15:42 . 2004-08-04 00:36 57984 ----a-w- c:\windows\system32\drivers\redbook.sys
2009-06-21 15:42 . 2001-08-17 21:46 6400 ----a-w- c:\windows\system32\drivers\enum1394.sys
2009-06-21 15:41 . 2004-08-04 00:45 76288 ----a-w- c:\windows\system32\usbui.dll
2009-06-21 15:41 . 2004-08-03 23:07 8832 ----a-w- c:\windows\system32\drivers\wmiacpi.sys
2009-06-21 15:41 . 2001-08-17 21:58 9344 ----a-w- c:\windows\system32\drivers\compbatt.sys
2009-06-21 15:41 . 2004-08-03 23:07 14080 ----a-w- c:\windows\system32\drivers\CmBatt.sys
2009-06-21 15:41 . 2001-08-17 21:57 14080 ----a-w- c:\windows\system32\drivers\battc.sys
2009-06-17 16:32 . 2009-06-17 16:32 -------- d-----w- c:\documents and settings\lincoln\Dados de aplicativos\Windows Search
2009-06-17 13:37 . 2009-06-17 13:37 -------- d-----w- c:\windows\system32\LogFiles
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-13 19:27 . 2001-10-28 18:07 49044 ----a-w- c:\windows\system32\perfc016.dat
2009-07-13 19:27 . 2001-10-28 18:07 344972 ----a-w- c:\windows\system32\perfh016.dat
2009-07-10 14:46 . 2008-09-30 11:31 -------- d-----w- c:\arquivos de programas\Alwil Software
2009-07-10 13:41 . 2009-07-10 13:41 -------- d-----w- c:\documents and settings\Administrador\Dados de aplicativos\Malwarebytes
2009-07-10 13:41 . 2009-07-10 13:41 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware
2009-07-10 13:41 . 2009-07-10 13:41 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Malwarebytes
2009-07-07 13:09 . 2004-08-04 02:14 212480 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-06-25 12:17 . 2008-11-06 11:49 -------- d-----w- c:\arquivos de programas\HP
2009-06-25 12:08 . 2008-09-30 01:09 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information
2009-06-25 11:19 . 2008-09-30 01:33 -------- d-----w- c:\arquivos de programas\Ahead
2009-06-24 15:44 . 2009-02-27 21:03 -------- d-----w- c:\arquivos de programas\TIM Web Banda Larga
2009-06-23 14:17 . 2008-09-30 01:08 -------- d-----w- c:\arquivos de programas\Arquivos comuns\InstallShield
2009-06-23 01:27 . 2008-09-30 10:52 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe
2009-06-23 00:37 . 2009-06-21 20:08 101632 ----a-w- c:\windows\system32\drivers\nvtcp.sys
2009-06-21 19:36 . 2008-09-30 01:10 86016 ----a-w- c:\windows\SoundMan.exe
2009-06-21 19:36 . 2008-09-30 01:10 2879488 ----a-w- c:\windows\SkyTel.exe
2009-06-21 19:36 . 2009-06-21 20:08 135168 ----a-w- c:\windows\system32\RtlCPAPI.dll
2009-06-21 19:36 . 2008-09-30 01:10 364544 ----a-w- c:\windows\RtlUpd.exe
2009-06-21 19:36 . 2008-09-30 01:10 4299264 ----a-w- c:\windows\system32\drivers\RtkHDAud.Sys
2009-06-21 19:36 . 2008-09-30 01:09 9709568 ----a-w- c:\windows\RTLCPL.exe
2009-06-21 19:36 . 2008-09-30 01:09 16239616 ----a-w- c:\windows\RTHDCPL.exe
2009-06-21 19:36 . 2008-09-30 01:09 2158592 ----a-w- c:\windows\MicCal.exe
2009-06-21 19:36 . 2008-09-30 01:09 69632 ----a-w- c:\windows\Alcmtr.exe
2009-06-21 19:36 . 2008-09-30 01:09 2808832 ----a-w- c:\windows\alcwzrd.exe
2009-06-21 19:35 . 2009-06-21 20:08 40960 ----a-w- c:\windows\system32\ChCfg.exe
2009-06-21 19:33 . 2009-06-21 18:49 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-21 19:20 . 2009-06-21 20:08 176128 ----a-w- c:\windows\system32\nvunrm.exe
2009-06-21 19:20 . 2009-06-21 20:02 35840 ----a-w- c:\windows\system32\nvconrm.dll
2009-06-21 19:20 . 2009-06-21 20:02 158720 ----a-w- c:\windows\system32\fdco_l1046.dll
2009-06-21 19:20 . 2009-06-21 20:02 9728 ----a-w- c:\windows\system32\bdco1.dll
2009-06-21 19:20 . 2009-06-21 20:02 204288 ----a-w- c:\windows\system32\fdco1.dll
2009-06-17 14:27 . 2009-07-10 13:41 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 14:27 . 2009-07-10 13:41 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 17:20 . 2008-10-18 18:44 -------- d-----w- c:\arquivos de programas\GbPlugin
2009-05-18 21:56 . 2008-10-01 11:31 -------- d-----w- c:\arquivos de programas\Windows Live Safety Center
2009-05-07 15:43 . 2004-08-04 03:45 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:45 . 2004-08-04 03:45 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:45 . 2004-08-04 03:45 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 20:10 . 2004-08-04 03:38 1846784 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:17 . 2004-08-04 03:45 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2008-10-06 13:36 . 2008-10-06 13:36 24543376 ----a-w- c:\arquivos de programas\AdbeRdr90_pt_BR.exe
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="c:\documents and settings\azul\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2009-06-24 133104]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoMailChecker"="c:\arquivos de programas\Clevo\AutoMailChkr\MailChkr.exe" [2002-11-22 847360]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-23 7561216]
"ISUSPM Startup"="c:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"SMSERIAL"="c:\windows\sm56hlpr.exe" [2009-06-24 565248]
"SynTPEnh"="c:\arquivos de programas\Synaptics\SynTP\SynTPEnh.exe" [2005-08-01 729177]
"BisonHK"="c:\windows\BisonCam\BisonHK.exe" [2007-10-03 77824]
"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"RemoteControl"="c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\arquivos de programas\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2009-06-21 16239616]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2009-06-21 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-06-23 1519616]
"CHotkey"="mHotkey.exe" - c:\windows\mHotkey.exe [2001-12-26 472576]
c:\documents and settings\lincoln\Menu Iniciar\Programas\Inicializar\
Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\
BlueSoleil.lnk - c:\arquivos de programas\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-3-1 653312]
HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
[HKLM\~\startupfolder\C:^Documents and Settings^azul^Menu Iniciar^Programas^Inicializar^ihaupd32.exe]
path=c:\documents and settings\azul\Menu Iniciar\Programas\Inicializar\ihaupd32.exe
backup=c:\windows\pss\ihaupd32.exeStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Arquivos de programas\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Arquivos de programas\\TeamViewer\\Version4\\TeamViewer.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [10/7/2009 14:59 108289]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [22/6/2009 22:00 180608]
S1 4972d5c0;4972d5c0;c:\windows\system32\drivers\4972d5c0.sys --> c:\windows\system32\drivers\4972d5c0.sys [?]
.
Conteúdo da pasta 'Tarefas Agendadas'
2009-07-02 c:\windows\Tasks\WebReg Deskjet D1300 series.job
- c:\arquivos de programas\HP\Digital Imaging\bin\hpqwrg.exe [2006-02-19 07:09]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.google.com.br/
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {e2883e8f-472f-4fb0-9522-ac9bf37916a7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-13 17:05
Windows 5.1.2600 Service Pack 2 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'explorer.exe'(3076)
c:\windows\system32\msi.dll
.
------------------------ Outros Processos em Execução ------------------------
.
c:\windows\system32\WgaTray.exe
c:\arquivos de programas\Avira\AntiVir Desktop\avguard.exe
c:\arquivos de programas\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\arquivos de programas\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\wdfmgr.exe
c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe
c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
c:\windows\system32\wscntfy.exe
c:\arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Tempo para conclusão: 2009-07-13 17:08 - Máquina reiniciou
ComboFix-quarantined-files.txt 2009-07-13 20:08
ComboFix2.txt 2009-07-10 15:18
Pré-execução: 7 pasta(s) 14.481.399.808 bytes disponíveis
Pós execução: 7 pasta(s) 14.482.100.224 bytes disponíveis
280 --- E O F --- 2009-06-24 19:18