There is the log:
ComboFix 08-11-24.03 - Rickgauden 2008-11-25 16:57:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.100 [GMT -2:00]
Executando de: c:\rapidget_-_downloads\ComboFix.exe
* Criado um novo ponto de restauro
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\avrt.dll
c:\windows\system32\d3d10core.dll
c:\windows\system32\D3DX10d_39.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\micr0st.dll
c:\windows\system32\systeminfo3.dll
.
(((((((((((((((( Arquivos/Ficheiros criados de 2008-10-25 to 2008-11-25 ))))))))))))))))))))))))))))
.
2008-11-25 12:33 . 2008-11-25 12:46 <DIR> d-------- C:\videos-
2008-11-24 21:21 . 2008-10-13 15:23 7,533 --a------ c:\windows\system32\dopdf6.ctm
2008-11-24 20:29 . 2008-11-24 20:29 730,656 --a------ c:\arquivos de programas\Arquivos comuns\unins000.exe
2008-11-24 20:29 . 2008-11-24 20:29 3,018 --a------ c:\arquivos de programas\Arquivos comuns\unins000.dat
2008-11-23 20:06 . 2008-11-23 20:09 <DIR> d-------- C:\LinhaDefensiva
2008-11-19 20:48 . 2008-11-21 19:45 230,424 --a------ C:\img2-001.raw
2008-11-19 18:30 . 2008-11-21 20:01 31 --a------ c:\windows\system32\bbcap.err
2008-11-19 18:23 . 2008-11-19 18:31 <DIR> d-------- c:\documents and settings\Rickgauden\Dados de aplicativos\Blueberry
2008-11-19 18:23 . 2008-11-19 18:26 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Blueberry
2008-11-19 18:23 . 2008-11-19 18:23 <DIR> d-------- c:\arquivos de programas\BB FlashBack
2008-11-19 18:23 . 2008-11-19 18:23 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Blueberry Software
2008-11-19 18:23 . 2008-11-19 18:23 27,776 --a------ c:\windows\system32\bbcap.dll
2008-11-19 18:23 . 2008-11-19 18:23 4,608 --a------ c:\windows\system32\bbchlp.dll
2008-11-19 18:23 . 2008-11-19 18:23 2,944 --a------ c:\windows\system32\drivers\bbcap.sys
2008-11-19 18:22 . 2008-11-19 18:23 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\{1125ADE1-D617-4AFC-A2BB-E9DE22F436B6}
2008-11-18 14:17 . 2008-11-18 14:22 <DIR> d-------- c:\arquivos de programas\NetMeter
2008-11-16 20:57 . 2008-11-16 20:57 <DIR> d-------- c:\arquivos de programas\Fake Webcam
2008-11-15 14:43 . 2008-11-15 14:43 <DIR> d-------- c:\documents and settings\Rickgauden\Dados de aplicativos\Malwarebytes
2008-11-15 14:43 . 2008-11-15 14:43 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes
2008-11-15 14:43 . 2008-11-15 14:43 <DIR> d-------- c:\arquivos de programas\Malwarebytes' Anti-Malware
2008-11-15 14:43 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-15 14:43 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-14 14:07 . 2008-11-22 13:17 <DIR> d-------- c:\arquivos de programas\Simpsons Hit and Run
2008-11-13 13:00 . 2008-11-13 13:00 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\TechSmith
2008-11-13 13:00 . 2008-11-13 13:00 <DIR> d-------- c:\arquivos de programas\TechSmith
2008-11-12 15:39 . 2008-11-25 16:00 117 --a------ c:\windows\DailyMugshot.ini
2008-11-12 15:38 . 2008-11-12 15:38 <DIR> d-------- c:\arquivos de programas\Daily Mugshot Windows Reminder
2008-11-11 17:24 . 2008-11-11 18:00 292,750 --a------ C:\RAP.rar
2008-11-11 16:44 . 2008-11-11 16:44 <DIR> d-------- c:\arquivos de programas\MegaJogos
2008-11-11 13:20 . 2008-11-11 13:22 <DIR> d-------- C:\MP4
2008-11-09 18:02 . 2008-11-09 18:03 <DIR> d-------- c:\documents and settings\Rickgauden\Dados de aplicativos\Hide IP NG
2008-11-09 18:02 . 2008-11-09 18:03 <DIR> d-------- c:\arquivos de programas\Hide IP NG
2008-11-09 09:30 . 2008-11-12 19:48 <DIR> d-------- C:\RAP
2008-10-29 22:02 . 2008-11-14 14:23 <DIR> d-------- c:\arquivos de programas\GameVicio
2008-10-29 21:34 . 2008-10-29 21:34 <DIR> d-------- c:\arquivos de programas\Microsoft Games
2008-10-28 18:36 . 2008-10-28 19:15 <DIR> d-------- C:\Converted Music
2008-10-28 18:33 . 2008-10-28 18:35 14,069,664 --a------ C:\Image.nrg
2008-10-26 13:44 . 2008-10-26 13:44 <DIR> d-------- c:\documents and settings\Rickgauden\Dados de aplicativos\Avira
2008-10-25 13:14 . 2008-10-25 13:14 <DIR> d-------- c:\documents and settings\Rickgauden\Dados de aplicativos\TrojanHunter
2008-10-25 12:11 . 2008-10-25 12:13 <DIR> d-------- c:\arquivos de programas\TrojanHunter 5.0
2008-10-25 11:49 . 2008-10-25 12:02 <DIR> d-------- c:\documents and settings\Rickgauden\Dados de aplicativos\ICQ
2008-10-25 11:47 . 2008-10-25 12:02 <DIR> d-------- c:\arquivos de programas\ICQ6.5
2008-10-25 09:18 . 2008-10-25 09:18 <DIR> d-------- c:\windows\Easy Rapidshare Points
2008-10-25 09:18 . 2008-10-25 09:18 <DIR> d-------- c:\arquivos de programas\Easy Rapidshare Points
2008-10-25 08:52 . 2008-10-25 09:00 <DIR> d-------- c:\documents and settings\Rickgauden\Dados de aplicativos\Teeworlds
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 19:02 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\DMCache
2008-11-25 14:06 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\Lightcomm
2008-11-17 00:44 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\uTorrent
2008-11-13 23:36 --------- d---a-w c:\documents and settings\All Users\Dados de aplicativos\TEMP
2008-11-13 14:59 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard
2008-11-12 22:51 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\netsuper
2008-11-09 20:32 --------- d-----w c:\arquivos de programas\Messenger Plus! Live
2008-11-05 22:09 99,856 ----a-w c:\windows\system32\drivers\cmdguard.sys
2008-11-05 22:09 31,504 ----a-w c:\windows\system32\drivers\cmdhlp.sys
2008-11-05 22:09 143,096 ----a-w c:\windows\system32\guard32.dll
2008-10-29 23:53 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information
2008-10-29 23:31 --------- d-----w c:\arquivos de programas\Arquivos comuns\InstallShield
2008-10-29 22:53 --------- d-----w c:\arquivos de programas\dBpowerAMP
2008-10-26 15:52 --------- d-----w c:\arquivos de programas\Internet Download Manager
2008-10-25 15:18 --------- d--h--w c:\arquivos de programas\Avira
2008-10-25 15:18 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Avira
2008-10-24 22:29 --------- d-----w c:\arquivos de programas\Max Payne
2008-10-24 17:34 --------- d-----w c:\arquivos de programas\sXe Injected
2008-10-21 21:45 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Lavasoft
2008-10-21 21:39 --------- d-----w c:\arquivos de programas\Lavasoft
2008-10-20 20:19 --------- d-----w c:\arquivos de programas\Valve
2008-10-19 21:36 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\IDM
2008-10-19 15:54 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\Notepad++
2008-10-19 15:51 --------- d-----w c:\arquivos de programas\Notepad++
2008-10-17 11:36 --------- d-----w c:\arquivos de programas\Batch Watermark Creator
2008-10-17 08:09 602,112 ----a-w c:\windows\system32\nvapi.dll
2008-10-16 17:33 --------- d-----w c:\arquivos de programas\Microsoft LifeCam
2008-10-16 13:47 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe
2008-10-15 21:29 --------- d-----w c:\arquivos de programas\Rockstar Games
2008-10-15 15:21 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\comodo
2008-10-15 12:54 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\Comodo
2008-10-15 12:54 --------- d-----w c:\arquivos de programas\COMODO
2008-10-14 23:25 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\PC Drivers Headquarters
2008-10-10 06:52 452,440 ----a-w c:\windows\system32\d3dx10_40.dll
2008-10-10 06:52 4,379,984 ----a-w c:\windows\system32\d3dx9_40.dll
2008-10-09 20:24 --------- d-----w c:\arquivos de programas\Streamripper
2008-10-08 20:43 --------- d-----w c:\arquivos de programas\XviD
2008-10-06 19:31 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\Vso
2008-10-06 19:30 81,920 ----a-w c:\documents and settings\Rickgauden\Dados de aplicativos\ezpinst.exe
2008-10-06 19:30 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-10-06 19:30 47,360 ----a-w c:\documents and settings\Rickgauden\Dados de aplicativos\pcouffin.sys
2008-10-06 19:30 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DVDXStudio
2008-10-06 19:30 --------- d-----w c:\arquivos de programas\CloneDVD
2008-10-06 18:14 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\SlySoft
2008-10-06 17:41 --------- d-----w c:\arquivos de programas\SlySoft
2008-10-06 00:15 --------- d-----w c:\arquivos de programas\Arquivos comuns\Ahead
2008-10-06 00:12 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Nero
2008-10-06 00:11 --------- d-----w c:\arquivos de programas\Nero
2008-10-02 18:01 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\WildTangent
2008-10-02 17:45 --------- d-----w c:\arquivos de programas\Arquivos comuns\SWF Studio
2008-10-02 16:50 355,584 ----a-w c:\windows\system32\TuneUpDefragService.exe
2008-10-02 16:49 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\TuneUp Software
2008-10-02 16:48 --------- d-----w c:\arquivos de programas\TuneUp Utilities 2008
2008-10-02 16:47 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\TuneUp Software
2008-10-02 02:23 471,040 ----a-w c:\windows\dog4.scr
2008-10-02 02:23 12,288 ----a-w c:\windows\impborl.dll
2008-10-01 18:46 --------- d-----w c:\arquivos de programas\Batch File Renamer 2.51
2008-10-01 18:45 --------- d-----w c:\arquivos de programas\BIMP Lite
2008-09-30 21:51 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\streamripper
2008-09-27 20:14 --------- d-----w c:\documents and settings\Rickgauden\Dados de aplicativos\Audacity
2008-09-18 16:47 940,304 ----a-w c:\windows\system32\msjava.dll
2008-09-18 16:47 73,728 ----a-w c:\windows\system32\CompressATI2.dll
2008-09-18 16:47 430,088 ----a-w c:\windows\system32\D3D10SDKLayers.DLL
2008-09-18 16:47 1,171,456 ----a-w c:\windows\system32\msvcr80d.dll
2008-09-17 21:00 17 ----a-w c:\documents and settings\Rickgauden\autoexec.bat
2008-08-26 19:03 167,424 ----a-w c:\windows\system32\SpoonUninstall.exe
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Conexão NetSuper"="c:\arquivos de programas\netsuper\Discador\pppoe.exe" [2007-08-08 2600448]
"c:\arquivos de programas\NetMeter\NetMeter.exe"="c:\arquivos de programas\NetMeter\NetMeter.exe" [2007-08-11 331264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\arquivos de programas\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 86016]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"COMODO Firewall Pro"="c:\arquivos de programas\COMODO\Firewall\cfp.exe" [2008-11-05 1797880]
"THGuard"="c:\arquivos de programas\TrojanHunter 5.0\THGuard.exe" [2008-10-25 1046688]
"avgnt"="c:\arquivos de programas\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-06-12 266497]
"COMODO Internet Security"="c:\arquivos de programas\COMODO\Firewall\cfp.exe" [2008-11-05 1797880]
"nwiz"="nwiz.exe" [2008-05-02 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\
DailyMugshot.lnk - c:\arquivos de programas\Daily Mugshot Windows Reminder\DailyMugshot.exe [2008-11-12 757760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XVID"= xvid.dll
"VIDC.mcsv"= prodad-mercalli-10-codec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Rickgauden^Menu Iniciar^Programas^Inicializar^Adobe Gamma.lnk]
path=c:\documents and settings\Rickgauden\Menu Iniciar\Programas\Inicializar\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Adobe LM Service"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\valve\\hl.exe"=
"c:\\Arquivos de programas\\valve\\hlds.exe"=
"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=
"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Arquivos de programas\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Arquivos de programas\\ICQ6.5\\ICQ.exe"=
R1 bbcap;bbcap;c:\windows\system32\DRIVERS\bbcap.sys [2008-11-19 2944]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2008-10-15 99856]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2008-10-15 31504]
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;"c:\arquivos de programas\Avira\AntiVir PersonalEdition Premium\avmailc.exe" [2008-10-25 164097]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;"c:\arquivos de programas\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE" [2008-10-25 258305]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;"c:\arquivos de programas\Avira\AntiVir PersonalEdition Premium\avesvc.exe" [2008-10-25 41217]
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe -k netsvcs [2008-04-14 14336]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\DRIVERS\RMSPPPOE.SYS [2002-06-10 31232]
R3 VX1000;VX-1000;c:\windows\system32\DRIVERS\VX1000.sys [2008-10-16 1966312]
S1 avfwot;avfwot;c:\windows\system32\DRIVERS\avfwot.sys []
S2 MSCamSvc;MSCamSvc;"c:\arquivos de programas\Microsoft LifeCam\MSCamS32.exe" [2007-05-17 271720]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys []
S3 ddsxeiservice;ddsxeiservice2;\??\c:\arquivos de programas\sXe Injected\ddsxei.sys [2008-09-16 46464]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [2008-10-02 355584]
S3 XDva195;XDva195;\??\c:\windows\system32\XDva195.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0524e22-9eb4-11dd-825c-000fead95b65}]
\Shell\AutoRun\command - F:\xih9.cmd
\Shell\explore\Command - F:\xih9.cmd
\Shell\open\Command - F:\xih9.cmd
*Newly Created Service* - PROCEXP90
.
Conteúdo da pasta 'Tarefas Agendadas'
2008-11-25 c:\windows\Tasks\1-Click Maintenance.job
- c:\arquivos de programas\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 10:09]
2008-11-25 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Erlandex\Configura []
.
- - - - ORFÃOS REMOVIDOS - - - -
Toolbar-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Scan Suplementar -------
.
FireFox -: Profile - c:\documents and settings\Rickgauden\Dados de aplicativos\Mozilla\Firefox\Profiles\vjcmlypo.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://prouni-inscricao.mec.gov.br/inscricao/consulta/nota_corte/resultado/login/
FF -: plugin - c:\arquivos de programas\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF -: plugin - c:\documents and settings\All Users\Dados de aplicativos\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - c:\documents and settings\Rickgauden\Configurações locais\Dados de aplicativos\Google\Update\1.2.131.25\npGoogleOneClick6.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-25 17:01:57
Windows 5.1.2600 Service Pack 3 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - - > 'lsass.exe'(880)
c:\windows\system32\idmmbc.dll
c:\windows\system32\avsda.dll
.
Tempo para conclusão: 2008-11-25 17:04:13
ComboFix-quarantined-files.txt 2008-11-25 19:03:15
Pré-execução: 2.014.597.120 bytes disponíveis
Pós execução: 2,030,473,216 bytes disponíveis
WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
253