omboFix 09-07-14.08 - Ricardo 16/07/2009 23:45.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1247.789 [GMT -3:00]
Executando de: c:\documents and settings\Ricardo\Desktop\ComboFix.exe
Comandos utilizados :: c:\documents and settings\Ricardo\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FILE ::
"c:\arquivos de programas\INSO042009.log"
"C:\INSO.EXE"
"c:\windows\system32\424C.tmp"
"c:\windows\system32\427D.tmp"
"c:\windows\Tasks\Scheduled Update for Ask Toolbar.job"
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\arquivos de programas\Ask.com
c:\arquivos de programas\Ask.com\config.xml
c:\arquivos de programas\Ask.com\GenericAskToolbar.dll
c:\arquivos de programas\Ask.com\mupcfg.xml
c:\arquivos de programas\Ask.com\UpdateTask.exe
c:\arquivos de programas\Eazel-PR
c:\arquivos de programas\Eazel-PR\Eazel-PRToolbarHelper.exe
c:\arquivos de programas\Eazel-PR\INSTALL.LOG
c:\arquivos de programas\Eazel-PR\tbEaze.dll
c:\arquivos de programas\Eazel-PR\toolbar.cfg
c:\arquivos de programas\Eazel-PR\UNWISE.EXE
c:\arquivos de programas\INSO042009.log
c:\arquivos de programas\MySearch
C:\INSO.EXE
c:\windows\system32\424C.tmp
c:\windows\system32\427D.tmp
c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
.
(((((((((((((((( Arquivos/Ficheiros criados de 2009-06-17 to 2009-07-17 ))))))))))))))))))))))))))))
.
2009-07-16 17:29 . 2009-07-16 17:29 296976 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.459\sys\i386\5.1\klif.sys
2009-07-16 17:29 . 2009-07-16 17:29 128016 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.459\sys\i386\kl1.sys
2009-07-16 17:28 . 2009-07-16 17:28 296976 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\sys\i386\5.1\klif.sys
2009-07-16 17:28 . 2009-07-16 17:28 128016 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.459\sys\i386\kl1.sys
2009-07-16 17:21 . 2009-07-16 17:21 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-07-16 17:15 . 2009-07-16 17:15 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-07-16 17:15 . 2009-07-16 17:15 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-07-16 17:14 . 2009-07-17 02:42 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab
2009-07-16 17:14 . 2009-07-16 17:14 -------- d-----w- c:\arquivos de programas\Kaspersky Lab
2009-07-16 16:56 . 2009-07-16 16:56 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab Setup Files
2009-07-16 15:57 . 2009-07-16 15:57 -------- d-----w- c:\arquivos de programas\Trend Micro
2009-07-16 03:23 . 2008-09-16 19:23 168448 ----a-w- c:\windows\system32\unrar.dll
2009-07-16 03:23 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-07-16 03:23 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-07-16 03:23 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-07-16 03:23 . 2009-05-01 21:02 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-07-16 03:23 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2009-07-16 03:23 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\divx.dll
2009-07-16 03:23 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-07-16 03:23 . 2009-07-16 03:23 -------- d-----w- c:\arquivos de programas\K-Lite Codec Pack
2009-07-16 02:58 . 2009-07-16 02:58 -------- d-----w- c:\arquivos de programas\Conduit
2009-07-16 00:55 . 2009-07-16 00:55 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\CyberLink
2009-07-16 00:51 . 2009-07-16 00:56 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\CyberLink
2009-07-16 00:51 . 2009-07-16 00:51 -------- d-----w- c:\arquivos de programas\Arquivos comuns\CyberLink
2009-07-16 00:48 . 2009-07-16 00:48 29480 ----a-w- c:\windows\system32\msxml3a.dll
2009-07-16 00:48 . 2009-07-16 00:58 53319 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\TEMP\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2009-07-16 00:32 . 2009-07-16 00:48 505128 ----a-w- c:\windows\system32\msvcp71.dll
2009-07-15 23:49 . 2009-07-15 23:49 -------- d-----w- c:\arquivos de programas\Marcos Velasco Security
2009-07-15 15:50 . 2009-07-15 15:50 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\Uniblue
2009-07-15 15:44 . 2009-07-15 15:44 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\Nero
2009-07-15 15:06 . 2009-07-15 23:29 -------- d-----w- c:\arquivos de programas\GRETECH
2009-07-15 12:22 . 2009-07-15 13:13 -------- d-----w- c:\arquivos de programas\DVDlabPro2
2009-07-15 09:52 . 2009-07-15 11:59 -------- d-----w- c:\arquivos de programas\Aiseesoft Studio
2009-07-15 09:41 . 2009-07-15 14:58 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\dvdcss
2009-07-15 09:37 . 2009-07-15 09:37 -------- d-----w- c:\arquivos de programas\VideoLAN
2009-07-10 23:34 . 2009-07-15 11:58 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\uTorrent
2009-07-10 21:59 . 2009-07-15 13:29 -------- d-----w- C:\DVDVolume
2009-07-10 21:37 . 2009-07-10 21:37 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\Desktopicon
2009-07-10 21:37 . 2009-07-10 21:37 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\FreeRIP
2009-07-10 21:37 . 2009-07-15 11:52 -------- d-----w- c:\arquivos de programas\FreeRIP3
2009-07-10 04:22 . 2009-07-17 02:46 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\Free Download Manager
2009-07-10 04:22 . 2009-07-10 04:22 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\FreeDownloadManager.ORG
2009-07-10 02:45 . 2009-07-10 02:45 -------- d-----w- c:\arquivos de programas\SpeedBit Video Accelerator
2009-07-10 02:28 . 2009-07-10 15:28 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\SpeedBit
2009-07-10 02:27 . 2009-07-10 15:29 -------- d-----w- c:\arquivos de programas\DAP
2009-07-08 21:24 . 2009-07-17 02:21 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\Software Informer
2009-07-08 21:24 . 2009-07-08 21:24 -------- d-----w- c:\arquivos de programas\Software Informer
2009-07-08 21:23 . 2009-07-16 17:12 -------- d-----w- c:\arquivos de programas\Free Download Manager
2009-07-07 17:06 . 2009-07-07 17:06 488960 ----a-w- c:\documents and settings\Ricardo\Dados de aplicativos\Macromedia\Flash Player\
www.macromedia.com\bin\octoshape\pmv302-0811070-0-main.dll
2009-07-07 17:05 . 2009-07-07 17:05 320000 ----a-w- c:\documents and settings\Ricardo\Dados de aplicativos\Macromedia\Flash Player\
www.macromedia.com\bin\octoshape\OCTOSHAPE.EXE
2009-07-07 01:01 . 2009-07-16 00:48 -------- d---a-w- c:\documents and settings\All Users\Dados de aplicativos\TEMP
2009-07-07 00:45 . 2009-07-07 00:45 -------- d-----w- c:\windows\system32\IOSUBSYS
2009-07-07 00:42 . 2009-07-15 12:47 -------- d-----w- C:\temp
2009-07-07 00:42 . 2009-07-07 00:43 -------- d-----w- c:\temp\google
2009-07-03 16:26 . 2003-11-04 18:10 69632 ----a-w- c:\windows\system32\lfgif13n.dll
2009-07-03 16:26 . 2004-05-14 19:53 462848 ----a-w- c:\windows\system32\ltkrn13n.dll
2009-07-03 16:26 . 2004-05-14 19:53 450560 ----a-w- c:\windows\system32\ltimg13n.dll
2009-07-03 16:26 . 2004-05-14 19:53 299008 ----a-w- c:\windows\system32\ltdis13n.dll
2009-07-03 16:26 . 2004-05-14 19:53 163840 ----a-w- c:\windows\system32\ltfil13n.dll
2009-07-03 16:26 . 2004-05-14 19:53 57344 ----a-w- c:\windows\system32\lfbmp13n.dll
2009-07-03 16:26 . 2004-05-14 19:53 401408 ----a-w- c:\windows\system32\lfcmp13n.dll
2009-07-03 16:26 . 2004-01-12 05:09 206336 ----a-w- c:\windows\system32\ltefx13n.dll
2009-06-25 20:08 . 2009-06-25 20:08 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\Nokia
2009-06-25 20:08 . 2009-06-25 20:08 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\PC Suite
2009-06-25 20:08 . 2009-06-25 20:08 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\PC Suite
2009-06-25 20:07 . 2009-06-25 20:07 -------- d-----w- c:\arquivos de programas\DIFX
2009-06-25 20:07 . 2008-08-26 13:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-06-25 20:07 . 2009-06-25 20:07 -------- d-----w- c:\arquivos de programas\PC Connectivity Solution
2009-06-25 20:07 . 2009-02-09 10:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-06-25 20:07 . 2009-07-07 02:44 -------- d-----w- c:\arquivos de programas\Nokia
2009-06-25 20:07 . 2009-06-25 20:06 34511040 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_wu_por_br.exe
2009-06-25 20:06 . 2009-06-25 20:06 61440 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-06-25 20:06 . 2009-06-25 20:06 8192 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-06-25 20:06 . 2009-06-25 20:06 10240 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-06-25 20:06 . 2009-06-25 20:06 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Installations
2009-06-25 19:41 . 2009-06-25 19:41 -------- d-sh--w- c:\windows\ftpcache
2009-06-20 05:04 . 2008-04-13 18:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-06-20 05:04 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-06-20 05:04 . 2001-09-06 02:50 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-06-20 05:04 . 2008-04-14 02:20 159232 ----a-w- c:\windows\system32\ptpusd.dll
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-16 17:29 . 2009-05-24 18:30 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
2009-07-16 03:31 . 2009-06-16 03:43 -------- d-----w- c:\arquivos de programas\Google
2009-07-16 02:10 . 2009-05-25 04:40 -------- d-----w- c:\arquivos de programas\FreeRIP2
2009-07-16 00:51 . 2009-03-22 21:04 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information
2009-07-16 00:48 . 2009-05-18 22:02 353576 ----a-w- c:\windows\system32\msvcr71.dll
2009-07-15 11:53 . 2009-07-15 11:53 361600 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-07-15 11:53 . 2004-08-04 02:14 361600 ----a-w- c:\windows\system32\drivers\TCPIP.SYS
2009-07-13 22:50 . 2009-03-22 21:23 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\Ahead
2009-07-13 22:35 . 2009-03-22 22:52 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\DVD Shrink
2009-06-25 19:36 . 2009-06-12 04:54 -------- d-----w- c:\arquivos de programas\ScannerP
2009-06-25 19:36 . 2009-03-30 23:45 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\GbPlugin
2009-06-25 12:02 . 2009-03-30 23:45 -------- d-----w- c:\arquivos de programas\GbPlugin
2009-06-16 14:39 . 2004-08-04 03:45 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:39 . 2001-10-28 12:06 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 22:19 . 2009-03-30 23:46 27056 ----a-w- c:\windows\system32\drivers\gbpkm.sys
2009-06-12 04:55 . 2009-06-12 04:55 -------- d-----w- c:\arquivos de programas\Common Files
2009-06-08 08:56 . 2009-06-08 08:56 64072 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2010 9.0.0.459\Spanish\setup.exe
2009-06-04 01:04 . 2001-10-28 12:07 67450 ----a-w- c:\windows\system32\perfc016.dat
2009-06-04 01:04 . 2001-10-28 12:07 425426 ----a-w- c:\windows\system32\perfh016.dat
2009-06-03 19:10 . 2004-08-04 03:45 1295872 ----a-w- c:\windows\system32\quartz.dll
2009-06-03 12:35 . 2009-06-03 12:35 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe
2009-05-25 08:21 . 2009-05-25 08:21 219664 ----a-w- c:\windows\system32\klogon.dll
2009-05-25 08:18 . 2009-05-25 08:18 27507 ----a-w- c:\windows\system32\drivers\klopp.dat
2009-05-21 05:34 . 2009-05-21 05:34 -------- d-----w- c:\arquivos de programas\WinAVI MP4 Converter
2009-05-18 22:02 . 2009-05-18 22:02 -------- d-----w- c:\documents and settings\Ricardo\Dados de aplicativos\Media Player Classic
2009-05-16 23:59 . 2009-05-16 23:59 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2009-05-13 20:46 . 2009-05-13 20:46 31760 ----a-w- c:\windows\system32\drivers\klim5.sys
2009-05-07 15:33 . 2004-08-04 03:45 347136 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:34 . 2004-08-04 03:45 668672 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:34 . 2009-03-23 01:03 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 19:50 . 2004-08-04 03:38 1847296 ----a-w- c:\windows\system32\win32k.sys
2009-06-24 18:03 . 2009-07-10 10:56 137208 ----a-w- c:\arquivos de programas\mozilla firefox\components\brwsrcmp.dll
.
------- Sigcheck -------
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2004-08-04 02:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2009-07-15 11:53 361600 A29E1209F925A0E9B330E11DA5FC7BAB c:\windows\system32\dllcache\TCPIP.SYS
[-] 2009-07-15 11:53 361600 A29E1209F925A0E9B330E11DA5FC7BAB c:\windows\system32\drivers\TCPIP.SYS
[7] 2004-08-04 03:45 24576 4CA695EC1EE4C7CF2144DFA00EA0E1F7 c:\windows\$NtServicePackUninstall$\userinit.exe
[7] 2008-04-14 02:21 26112 A7EA40F680163808D96F89B4FF991876 c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2008-04-14 02:21 26112 4352437014F966BDB031563314941A0E c:\windows\system32\USERINIT.EXE
.
((((((((((((((((((((((((((((( SnapShot@2009-07-16_19.47.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-17 02:42 . 2009-07-17 02:42 16384 c:\windows\Temp\Perflib_Perfdata_688.dat
+ 2009-06-16 14:39 . 2009-06-16 14:39 81920 c:\windows\system32\dllcache\fontsub.dll
- 2009-03-22 21:32 . 2009-06-11 00:25 23040 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 23040 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2009-03-22 21:32 . 2009-06-11 00:25 61440 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 61440 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2009-03-22 21:32 . 2009-06-11 00:25 27136 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 27136 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2009-03-22 21:32 . 2009-06-11 00:25 11264 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 11264 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 86016 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2009-03-22 21:32 . 2009-06-11 00:25 86016 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2009-03-22 21:32 . 2009-06-11 00:25 12288 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 12288 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 4096 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2009-03-22 21:32 . 2009-06-11 00:25 4096 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-06-16 14:39 . 2009-06-16 14:39 119808 c:\windows\system32\dllcache\t2embed.dll
- 2009-03-22 21:32 . 2009-06-11 00:25 409600 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 409600 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 286720 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2009-03-22 21:32 . 2009-06-11 00:25 286720 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 249856 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2009-03-22 21:32 . 2009-06-11 00:25 249856 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 794624 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2009-03-22 21:32 . 2009-06-11 00:25 794624 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 135168 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2009-03-22 21:32 . 2009-06-11 00:25 593920 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-03-22 21:32 . 2009-07-16 20:15 593920 c:\windows\Installer\{90110416-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-05-07 05:11 . 2009-06-03 19:10 1295872 c:\windows\system32\dllcache\quartz.dll
+ 2009-06-30 14:30 . 2009-06-30 14:30 5520384 c:\windows\Installer\1b78ca.msp
+ 2009-03-23 01:01 . 2009-07-07 15:10 24539592 c:\windows\system32\MRT.exe
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"Software Informer"="c:\arquivos de programas\Software Informer\softinfo.exe" [2009-07-09 1937477]
"Free Download Manager"="c:\arquivos de programas\Free Download Manager\fdm.exe" [2009-01-31 3399727]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2009-07-15 27660]
"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-03-27 148888]
"InstantAccess"="c:\arquivos de programas\ScannerP\TBRIDGE\BIN\InstantAccess.exe" [1998-07-08 37376]
"AVP"="c:\arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-05-25 303376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-07 16862208]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2007-02-28 53248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-3-22 262144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]
2009-06-18 21:00 302368 ----a-w- c:\arquivos de programas\GbPlugin\gbieh.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\UltraVNC\\vncviewer.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Arquivos de programas\\Free Download Manager\\fdm.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [30/3/2009 20:46 27056]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15/12/2008 20:41 33808]
R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [30/3/2009 20:45 53552]
R2 uvnc_service;uvnc_service;c:\arquivos de programas\UltraVNC\winvnc.exe [22/3/2009 20:05 1519168]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\arquiv~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm --> c:\arquiv~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13/5/2009 17:46 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16/5/2009 20:59 19472]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys --> c:\windows\system32\drivers\nmwcdnsu.sys [?]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2097962
IE: Baixar com o Free Download Manager - file://c:\arquivos de programas\Free Download Manager\dllink.htm
IE: Baixar tudo com o Free Download Manager - file://c:\arquivos de programas\Free Download Manager\dlall.htm
IE: Baixar vídeo com o Free Download Manager - file://c:\arquivos de programas\Free Download Manager\dlfvideo.htm
IE: Download selecionado pelo Free Download Manager - file://c:\arquivos de programas\Free Download Manager\dlselected.htm
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: com.br\www2.bancobrasil
TCP: {02942639-828C-4F33-BBBE-FCA410E7894F} = 200.202.193.75,200.202.193.76
FF - ProfilePath - c:\documents and settings\Ricardo\Dados de aplicativos\Mozilla\Firefox\Profiles\gbefks5e.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.orkut.com
FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/searchresults.asp?src=default&q=
FF - component: c:\arquivos de programas\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - component: c:\arquivos de programas\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\arquivos de programas\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\arquivos de programas\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\arquivos de programas\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\arquivos de programas\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-16 23:49
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•6~*]
"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'winlogon.exe'(1084)
c:\arquivos de programas\GBPLUGIN\gbieh.dll
.
Tempo para conclusão: 2009-07-17 23:51
ComboFix-quarantined-files.txt 2009-07-17 02:51
ComboFix2.txt 2009-07-17 02:39
Pré-execução: 9.532.985.344 bytes disponíveis
Pós execução: 9.517.678.592 bytes disponíveis
336 --- E O F --- 2009-07-16 20:16
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:56:05, on 16/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Arquivos de programas\Java\jre6\bin\jqs.exe
C:\Arquivos de programas\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe
C:\Arquivos de programas\Software Informer\softinfo.exe
C:\Arquivos de programas\Free Download Manager\fdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\sistray.exe
C:\Arquivos de programas\UltraVNC\WinVNC.exe
C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe
C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe
C:\Arquivos de programas\UltraVNC\WinVNC.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://search.conduit.com?SearchSource=10&ctid=CT2097962
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [InstantAccess] C:\Arquivos de programas\ScannerP\TBRIDGE\BIN\InstantAccess.exe /h
O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Software Informer] "C:\Arquivos de programas\Software Informer\softinfo.exe" -autorun
O4 - HKCU\..\Run: [Free Download Manager] C:\Arquivos de programas\Free Download Manager\fdm.exe -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: Baixar com o Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dllink.htm
O8 - Extra context menu item: Baixar tudo com o Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlall.htm
O8 - Extra context menu item: Baixar vídeo com o Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download selecionado pelo Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: &Teclado virtual - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Compro&bar direcciones URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&
http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://sdlc-esd.sun.com/ESD7/JSCDL/...6u13-windows-i586-jc.cab&BHost=javadl.sun.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{02942639-828C-4F33-BBBE-FCA410E7894F}: NameServer = 200.202.193.75,200.202.193.76
O17 - HKLM\System\CS1\Services\Tcpip\..\{02942639-828C-4F33-BBBE-FCA410E7894F}: NameServer = 200.202.193.75,200.202.193.76
O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe
O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: uvnc_service - UltraVNC - C:\Arquivos de programas\UltraVNC\WinVNC.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe
--
End of file - 8082 bytes
Você é nosso salvador Mr.Wolf não vejo a hora de retirar esse maldito virus e vê se consigo assitir o video em HD, Meus meritos a vc! rsrs