Hello
COMBOFIXLOGComboFix 09-08-10.06 - Paulo Machado 13-08-2009 22:44.7.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.351.2070.18.3582.2655 [GMT 1:00]
Executando de: c:\users\Paulo Machado\Desktop\ComboFix.exe
Comandos utilizados :: c:\users\Paulo Machado\Desktop\CFScript.txt
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((( Arquivos/Ficheiros criados de 2009-07-13 to 2009-08-13 ))))))))))))))))))))))))))))
.
2009-08-13 21:48 . 2009-08-13 21:48 -------- d-----w- c:\users\Paulo Machado\AppData\Local\temp
2009-08-13 21:48 . 2009-08-13 21:48 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-08-13 21:48 . 2009-08-13 21:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-08-12 20:30 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-12 20:30 . 2009-06-10 12:12 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-12 20:30 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-12 20:30 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-12 20:30 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-12 20:30 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-12 20:30 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-12 20:30 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-12 15:36 . 2009-08-12 15:36 -------- d-----w- c:\programdata\Geek Squad
2009-08-06 12:52 . 2009-08-03 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-06 12:52 . 2009-08-06 12:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-06 12:52 . 2009-08-03 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-06 11:47 . 2009-08-06 11:47 -------- d-----w- c:\program files\Huawei technologies
2009-08-05 14:09 . 2009-08-05 16:01 -------- d-----w- c:\programdata\FarmFrenzy3
2009-08-05 14:08 . 2009-08-05 14:08 -------- d-----w- c:\program files\Alawar
2009-07-24 10:29 . 2009-07-24 10:29 -------- d-----w- C:\00000082
2009-07-24 02:56 . 2009-07-24 02:56 -------- d-----w- c:\users\Paulo Machado\AppData\Roaming\Malwarebytes
2009-07-24 02:56 . 2009-07-24 02:56 -------- d-----w- c:\programdata\Malwarebytes
2009-07-24 02:34 . 2009-07-24 02:34 -------- d-----w- c:\windows\system32\EventProviders
2009-07-24 01:00 . 2009-07-24 02:00 -------- d-----w- c:\programdata\FarmFrenzy-PizzaParty
2009-07-24 00:35 . 2009-07-24 00:35 -------- d-----w- c:\users\Paulo Machado\AppData\Local\Symantec
2009-07-21 11:29 . 2009-07-21 11:30 -------- d-----w- c:\programdata\Symantec
2009-07-21 11:28 . 2009-07-24 10:27 -------- d-----w- c:\programdata\Norton
2009-07-21 11:27 . 2009-07-21 11:27 -------- d-----w- c:\programdata\NortonInstaller
2009-07-15 17:09 . 2009-07-21 11:00 -------- d-----w- c:\program files\BT Next Evolution
2009-07-15 09:46 . 2009-06-15 15:24 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-15 09:46 . 2009-06-15 15:20 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-15 09:46 . 2009-06-15 12:52 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-15 09:46 . 2009-06-15 15:20 10240 ----a-w- c:\windows\system32\dciman32.dll
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-13 19:35 . 2009-04-14 21:29 -------- d-----w- c:\programdata\DVD Shrink
2009-08-13 19:22 . 2007-01-18 04:49 828864 ----a-w- c:\windows\system32\prfh0816.dat
2009-08-13 19:22 . 2007-01-18 04:49 294632 ----a-w- c:\windows\system32\prfc0816.dat
2009-08-13 02:01 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-08-13 01:14 . 2009-01-03 21:33 -------- d-----w- c:\program files\Steam
2009-08-12 19:35 . 2008-12-23 21:05 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-27 17:50 . 2009-01-26 00:58 -------- d-----w- c:\users\Paulo Machado\AppData\Roaming\dvdcss
2009-07-24 10:14 . 2009-04-03 12:05 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-07-24 09:58 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-07-24 02:26 . 2009-06-25 19:28 -------- d-----w- c:\program files\Google
2009-07-21 21:52 . 2009-07-29 08:02 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 08:02 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 08:02 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 08:02 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-20 13:10 . 2008-12-26 22:09 -------- d-----w- c:\programdata\McAfee
2009-07-20 12:22 . 2006-07-11 18:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-07-03 23:53 . 2009-01-03 21:33 -------- d-----w- c:\program files\Common Files\Steam
2009-06-27 12:58 . 2009-06-27 12:55 -------- d-----w- c:\users\Paulo Machado\AppData\Roaming\DataCast
2009-06-27 12:55 . 2009-06-27 12:55 -------- d-----w- c:\program files\MarkAny
2009-06-27 12:55 . 2009-06-27 12:55 -------- d-----w- c:\program files\Samsung
2009-06-26 01:47 . 2009-06-26 01:47 -------- d-----w- c:\program files\AGEIA Technologies
2009-06-26 01:46 . 2009-06-26 01:46 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-26 01:40 . 2009-04-05 21:45 -------- d-----w- c:\users\Paulo Machado\AppData\Roaming\DAEMON Tools Lite
2009-06-25 21:45 . 2009-06-25 21:45 -------- d-----w- c:\program files\Codemasters
2009-06-20 21:14 . 2009-02-11 12:07 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-03 15:03 . 2008-12-23 20:42 85600 ----a-w- c:\users\Paulo Machado\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-01 12:05 . 2008-12-24 11:12 1 ----a-w- c:\users\Paulo Machado\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-05-21 16:29 . 2009-05-21 16:29 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-03-19 20:12 . 2009-01-12 20:22 48 --sh--w- c:\windows\SBE112F39.tmp
.
((((((((((((((((((((((((((((( SnapShot_2009-08-12_23.31.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-12 20:30 . 2009-06-10 11:44 31232 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6002.22150_none_946bf5749f2e8c01\msvidc32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:44 12800 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6002.22150_none_946bf5749f2e8c01\msrle32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:44 82944 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6002.22150_none_946bf5749f2e8c01\mciavi32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:42 91136 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6002.22150_none_946bf5749f2e8c01\avifil32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:42 65024 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6002.22150_none_946bf5749f2e8c01\avicap32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:38 91136 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6002.18049_none_93f62b2f8600b455\avifil32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:58 31232 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6001.22447_none_9297557ea1f9cc4d\msvidc32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:57 12800 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6001.22447_none_9297557ea1f9cc4d\msrle32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:56 82944 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6001.22447_none_9297557ea1f9cc4d\mciavi32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:52 91136 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6001.22447_none_9297557ea1f9cc4d\avifil32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:52 65024 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6001.22447_none_9297557ea1f9cc4d\avicap32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:07 91136 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6001.18270_none_91e6450388fad1ce\avifil32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:03 31232 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.21065_none_90994ca8a4e576ab\msvidc32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:03 12800 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.21065_none_90994ca8a4e576ab\msrle32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:00 82944 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.21065_none_90994ca8a4e576ab\mciavi32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:57 88576 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.21065_none_90994ca8a4e576ab\avifil32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:57 65024 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.21065_none_90994ca8a4e576ab\avicap32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:10 31232 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.16868_none_9012d8998bc4efa4\msvidc32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:09 12800 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.16868_none_9012d8998bc4efa4\msrle32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:07 82944 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.16868_none_9012d8998bc4efa4\mciavi32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:04 88576 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.16868_none_9012d8998bc4efa4\avifil32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:04 65024 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.16868_none_9012d8998bc4efa4\avicap32.dll
+ 2009-08-12 20:30 . 2009-06-04 10:52 53248 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6002.22146_none_3238de2ddc072aae\tsgqec.dll
+ 2009-08-12 20:30 . 2009-06-04 12:35 53248 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6001.22443_none_304f6b67dee38985\tsgqec.dll
+ 2009-08-12 20:30 . 2009-06-04 12:34 36352 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6000.21061_none_2e516291e1cf33e3\tsgqec.dll
+ 2009-08-12 20:30 . 2009-06-04 12:47 36352 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6000.16865_none_2dcbeeccc8adc633\tsgqec.dll
+ 2009-08-12 20:30 . 2009-07-17 14:15 71680 c:\windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6002.22179_none_ad4da751702700f0\atl.dll
+ 2009-08-12 20:30 . 2009-07-17 13:54 71680 c:\windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6002.18070_none_acbb07ec57117d17\atl.dll
+ 2009-08-12 20:30 . 2009-07-17 14:24 71680 c:\windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6001.22474_none_ab6233f773052d19\atl.dll
+ 2009-08-12 20:30 . 2009-07-17 14:35 71680 c:\windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6001.18293_none_aac1f52459f8aeb3\atl.dll
+ 2009-08-12 20:30 . 2009-07-17 14:39 71680 c:\windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6000.21088_none_a974fcc975e35390\atl.dll
+ 2009-08-12 20:30 . 2009-07-17 14:52 71680 c:\windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6000.16889_none_a8ec88265cc499db\atl.dll
+ 2008-12-23 21:09 . 2009-08-13 19:16 52354 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-12-23 20:43 . 2009-08-13 19:16 10866 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1130331581-1154666309-3599531796-1000_UserData.bin
+ 2006-11-02 13:02 . 2009-08-13 21:41 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-08-12 21:36 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2009-08-13 21:41 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2009-08-12 21:36 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2009-08-12 21:36 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:02 . 2009-08-13 21:41 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-06-01 12:17 . 2009-07-15 14:29 23040 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 23040 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 61440 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 61440 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 27136 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 27136 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 11264 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 11264 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 86016 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 86016 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 12288 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 12288 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-08-12 20:30 . 2009-07-15 12:46 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22172_none_0d9028a465949c3d\spwmp.dll
+ 2009-08-12 20:30 . 2009-07-15 12:46 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22172_none_0d9028a465949c3d\dxmasf.dll
+ 2009-08-12 20:30 . 2009-07-15 12:39 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18065_none_0d145ca34c6c2c87\spwmp.dll
+ 2009-08-12 20:30 . 2009-07-15 12:39 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18065_none_0d145ca34c6c2c87\dxmasf.dll
+ 2009-08-12 20:30 . 2009-07-15 14:51 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22470_none_0ba7b6286870146b\spwmp.dll
+ 2009-08-12 20:30 . 2009-07-15 14:51 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22470_none_0ba7b6286870146b\dxmasf.dll
+ 2009-08-12 20:30 . 2009-07-14 12:58 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18289_none_0b1c4a254f52777a\spwmp.dll
+ 2009-08-12 20:30 . 2009-07-14 12:59 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18289_none_0b1c4a254f52777a\dxmasf.dll
+ 2009-08-12 20:30 . 2009-07-15 14:42 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21083_none_09b97eb06b4f218b\spwmp.dll
+ 2009-08-12 20:30 . 2009-07-15 14:43 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21083_none_09b97eb06b4f218b\dxmasf.dll
+ 2009-08-12 20:30 . 2009-07-14 13:00 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16885_none_09320a57522f812d\spwmp.dll
+ 2009-08-12 20:30 . 2009-07-14 13:01 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16885_none_09320a57522f812d\dxmasf.dll
+ 2009-08-13 19:14 . 2009-08-13 19:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-08-12 21:34 . 2009-08-12 21:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-08-13 19:14 . 2009-08-13 19:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-08-12 21:34 . 2009-08-12 21:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-06-01 12:17 . 2009-07-15 14:29 4096 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 4096 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-08-12 20:30 . 2009-06-10 11:46 160256 c:\windows\winsxs\x86_microsoft-windows-workstationservice_31bf3856ad364e35_6.0.6002.22150_none_ce741cb6ed3e398c\wkssvc.dll
+ 2009-08-12 20:30 . 2009-06-10 11:42 160256 c:\windows\winsxs\x86_microsoft-windows-workstationservice_31bf3856ad364e35_6.0.6002.18049_none_cdfe5271d41061e0\wkssvc.dll
+ 2009-08-12 20:30 . 2009-06-10 12:00 160256 c:\windows\winsxs\x86_microsoft-windows-workstationservice_31bf3856ad364e35_6.0.6001.22447_none_cc9f7cc0f00979d8\wkssvc.dll
+ 2009-08-12 20:30 . 2009-06-10 12:12 160256 c:\windows\winsxs\x86_microsoft-windows-workstationservice_31bf3856ad364e35_6.0.6001.18270_none_cbee6c45d70a7f59\wkssvc.dll
+ 2009-08-12 20:30 . 2009-06-10 12:06 158208 c:\windows\winsxs\x86_microsoft-windows-workstationservice_31bf3856ad364e35_6.0.6000.21065_none_caa173eaf2f52436\wkssvc.dll
+ 2009-08-12 20:30 . 2009-06-10 12:16 156160 c:\windows\winsxs\x86_microsoft-windows-workstationservice_31bf3856ad364e35_6.0.6000.16868_none_ca1affdbd9d49d2f\wkssvc.dll
+ 2009-08-12 20:30 . 2009-06-10 11:44 123904 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6002.22150_none_946bf5749f2e8c01\msvfw32.dll
+ 2009-08-12 20:30 . 2009-06-10 11:58 123904 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6001.22447_none_9297557ea1f9cc4d\msvfw32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:03 123904 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.21065_none_90994ca8a4e576ab\msvfw32.dll
+ 2009-08-12 20:30 . 2009-06-10 12:10 123904 c:\windows\winsxs\x86_microsoft-windows-video-for-windows_31bf3856ad364e35_6.0.6000.16868_none_9012d8998bc4efa4\msvfw32.dll
+ 2009-08-12 20:30 . 2009-06-04 12:54 136192 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6002.22146_none_3238de2ddc072aae\aaclient.dll
+ 2009-08-12 20:30 . 2009-06-04 12:29 136192 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6001.22443_none_304f6b67dee38985\aaclient.dll
+ 2009-08-12 20:30 . 2009-06-04 12:25 116736 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6000.21061_none_2e516291e1cf33e3\aaclient.dll
+ 2009-08-12 20:30 . 2009-06-04 12:36 116736 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6000.16865_none_2dcbeeccc8adc633\aaclient.dll
+ 2009-08-12 20:30 . 2009-07-15 12:46 313344 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmpdxm_31bf3856ad364e35_6.0.6002.22172_none_a65e88df3e466bbf\wmpdxm.dll
+ 2009-08-12 20:30 . 2009-07-15 12:39 313344 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmpdxm_31bf3856ad364e35_6.0.6002.18065_none_a5e2bcde251dfc09\wmpdxm.dll
+ 2009-08-12 20:30 . 2009-07-15 14:52 313344 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmpdxm_31bf3856ad364e35_6.0.6001.22470_none_a47616634121e3ed\wmpdxm.dll
+ 2009-08-12 20:30 . 2009-07-14 13:00 313344 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmpdxm_31bf3856ad364e35_6.0.6001.18289_none_a3eaaa60280446fc\wmpdxm.dll
+ 2009-08-12 20:30 . 2009-07-15 14:44 313344 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmpdxm_31bf3856ad364e35_6.0.6000.21083_none_a287deeb4400f10d\wmpdxm.dll
+ 2009-08-12 20:30 . 2009-07-14 13:02 313344 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-wmpdxm_31bf3856ad364e35_6.0.6000.16885_none_a2006a922ae150af\wmpdxm.dll
+ 2009-08-12 20:30 . 2009-07-15 12:45 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22172_none_0d9028a465949c3d\wmpshare.exe
+ 2009-08-12 20:30 . 2009-07-15 12:46 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22172_none_0d9028a465949c3d\wmplayer.exe
+ 2009-08-12 20:30 . 2009-07-15 12:46 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22172_none_0d9028a465949c3d\wmpconfig.exe
+ 2009-08-12 20:30 . 2009-07-15 12:39 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18065_none_0d145ca34c6c2c87\wmpshare.exe
+ 2009-08-12 20:30 . 2009-07-15 12:39 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18065_none_0d145ca34c6c2c87\wmplayer.exe
+ 2009-08-12 20:30 . 2009-07-15 12:39 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18065_none_0d145ca34c6c2c87\wmpconfig.exe
+ 2009-08-12 20:30 . 2009-07-15 13:05 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22470_none_0ba7b6286870146b\wmpshare.exe
+ 2009-08-12 20:30 . 2009-07-15 13:06 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22470_none_0ba7b6286870146b\wmplayer.exe
+ 2009-08-12 20:30 . 2009-07-15 13:06 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22470_none_0ba7b6286870146b\wmpconfig.exe
+ 2009-08-12 20:30 . 2009-07-14 10:58 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18289_none_0b1c4a254f52777a\wmpshare.exe
+ 2009-08-12 20:30 . 2009-07-14 10:59 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18289_none_0b1c4a254f52777a\wmplayer.exe
+ 2009-08-12 20:30 . 2009-07-14 10:59 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18289_none_0b1c4a254f52777a\wmpconfig.exe
+ 2009-08-12 20:30 . 2009-07-15 12:53 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21083_none_09b97eb06b4f218b\wmpshare.exe
+ 2009-08-12 20:30 . 2009-07-15 12:53 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21083_none_09b97eb06b4f218b\wmplayer.exe
+ 2009-08-12 20:30 . 2009-07-15 12:53 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21083_none_09b97eb06b4f218b\wmpconfig.exe
+ 2009-08-12 20:30 . 2009-07-14 11:10 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16885_none_09320a57522f812d\wmpshare.exe
+ 2009-08-12 20:30 . 2009-07-14 11:10 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16885_none_09320a57522f812d\wmplayer.exe
+ 2009-08-12 20:30 . 2009-07-14 11:11 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16885_none_09320a57522f812d\wmpconfig.exe
+ 2006-11-02 13:05 . 2009-08-13 19:16 100096 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 10:33 . 2009-08-13 19:22 764876 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-08-13 19:22 267102 c:\windows\System32\perfc009.dat
- 2009-06-06 15:26 . 2009-08-12 21:36 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-06-06 15:26 . 2009-08-13 20:54 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-06-01 12:17 . 2009-08-13 02:02 409600 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 409600 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 286720 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 286720 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 249856 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 249856 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 794624 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 794624 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 135168 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 135168 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-06-01 12:17 . 2009-08-13 02:02 593920 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2009-06-01 12:17 . 2009-07-15 14:29 593920 c:\windows\Installer\{90110816-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2003-07-15 10:18 . 2003-07-15 10:18 141360 c:\windows\Installer\$PatchCache$\Managed\6180110900063D11C8EF10054038389C\11.0.5614\ATP.DLL
+ 2009-08-12 20:30 . 2009-06-04 12:56 2067968 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6002.22146_none_3238de2ddc072aae\mstscax.dll
+ 2009-08-12 20:30 . 2009-06-04 12:07 2066432 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6002.18045_none_31ae4118c2ea718d\mstscax.dll
+ 2009-08-12 20:30 . 2009-06-04 12:33 2067968 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6001.22443_none_304f6b67dee38985\mstscax.dll
+ 2009-08-12 20:30 . 2009-06-04 12:34 2066432 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6001.18266_none_2fb32dbcc5d3707b\mstscax.dll
+ 2009-08-12 20:30 . 2009-06-04 12:31 1874432 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6000.21061_none_2e516291e1cf33e3\mstscax.dll
+ 2009-08-12 20:30 . 2009-06-04 12:43 1871872 c:\windows\winsxs\x86_microsoft-windows-t..s-clientactivexcore_31bf3856ad364e35_6.0.6000.16865_none_2dcbeeccc8adc633\mstscax.dll
+ 2009-08-12 20:30 . 2009-07-02 07:47 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22179_none_f4b581af81eee730\OESpamFilter.dat
+ 2009-08-12 20:30 . 2009-07-02 07:48 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18070_none_f422e24a68d96357\OESpamFilter.dat
+ 2009-08-12 20:30 . 2009-07-02 07:47 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22474_none_f2ca0e5584cd1359\OESpamFilter.dat
+ 2009-08-12 20:30 . 2009-07-02 07:47 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18293_none_f229cf826bc094f3\OESpamFilter.dat
+ 2009-08-12 20:30 . 2009-07-02 07:47 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21088_none_f0dcd72787ab39d0\OESpamFilter.dat
+ 2009-08-12 20:30 . 2009-07-02 07:48 2409784 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16889_none_f05462846e8c801b\OESpamFilter.dat
+ 2009-08-12 20:30 . 2009-07-15 12:47 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22172_none_0d9028a465949c3d\wmploc.DLL
+ 2009-08-12 20:30 . 2009-07-15 12:40 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18065_none_0d145ca34c6c2c87\wmploc.DLL
+ 2009-08-12 20:30 . 2009-07-15 13:07 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22470_none_0ba7b6286870146b\wmploc.DLL
+ 2009-08-12 20:30 . 2009-07-14 10:59 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18289_none_0b1c4a254f52777a\wmploc.DLL
+ 2009-08-12 20:30 . 2009-07-15 12:53 8147968 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21083_none_09b97eb06b4f218b\wmploc.DLL
+ 2009-08-12 20:30 . 2009-07-14 11:11 8147968 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16885_none_09320a57522f812d\wmploc.DLL
- 2006-11-02 10:22 . 2009-08-12 20:40 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 10:22 . 2009-08-13 03:02 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 12:47 . 2009-08-13 02:09 2683032 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
- 2006-11-02 12:47 . 2009-07-24 02:15 2683032 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
+ 2009-08-05 01:11 . 2009-08-05 01:11 5518848 c:\windows\Installer\f4f846.msp
+ 2009-07-01 12:21 . 2009-07-01 12:21 8891904 c:\windows\Installer\f4f82f.msp
+ 2007-05-10 12:45 . 2007-05-10 12:45 8069464 c:\windows\Installer\$PatchCache$\Managed\6180110900063D11C8EF10054038389C\11.0.8173\OWC11.DLL
+ 2007-03-14 12:10 . 2007-03-14 12:10 7255384 c:\windows\Installer\$PatchCache$\Managed\6180110900063D11C8EF10054038389C\11.0.8173\OWC10.DLL
+ 2009-08-12 20:30 . 2009-07-15 14:36 10628096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22172_none_0d9028a465949c3d\wmp.dll
+ 2009-08-12 20:30 . 2009-07-15 14:30 10628096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18065_none_0d145ca34c6c2c87\wmp.dll
+ 2009-08-12 20:30 . 2009-07-15 14:52 10627584 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22470_none_0ba7b6286870146b\wmp.dll
+ 2009-08-12 20:30 . 2009-07-14 13:00 10626048 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18289_none_0b1c4a254f52777a\wmp.dll
+ 2009-08-12 20:30 . 2009-07-15 14:44 10622464 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21083_none_09b97eb06b4f218b\wmp.dll
+ 2009-08-12 20:30 . 2009-07-14 13:02 10621952 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16885_none_09320a57522f812d\wmp.dll
+ 2009-08-12 20:30 . 2009-07-14 13:00 10626048 c:\windows\System32\wmp.dll
+ 2009-04-16 10:44 . 2009-07-30 00:49 24281536 c:\windows\System32\MRT.exe
+ 2009-07-01 12:19 . 2009-07-01 12:19 10607104 c:\windows\Installer\f4f830.msp
.
-- Snapshot resetado para data atual --
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-09-05 81920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2008-03-25 14131200]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^Paulo Machado^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\users\Paulo Machado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1130331581-1154666309-3599531796-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{67A44428-8E3C-4E2F-8096-8A7FEFD888AF}c:\\program files\\windows sidebar\\sidebar.exe"= UDP:c:\program files\windows sidebar\sidebar.exe:Barra lateral do Windows
"UDP Query User{BB953416-7053-4397-ACA3-6848F4C66C5D}c:\\program files\\windows sidebar\\sidebar.exe"= TCP:c:\program files\windows sidebar\sidebar.exe:Barra lateral do Windows
"{E39BE721-5CDA-4037-949C-D8255BF12F55}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{41F518AF-6619-475C-9571-7AE32D503553}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{7E0F28FE-3BAA-482C-8717-E03CE31FEFAA}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{345CB6E6-67E2-4D04-9620-74D5D486F9F3}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{8A60D238-6FC9-45F6-842E-762E1C4F25C3}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare
"{EE506C63-7222-4C03-9AA3-0CBC5C9AB3A2}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare
"{8B10CCD6-0E15-4DA6-9686-2ABEF2833063}"= UDP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{C959D744-95CC-4AAB-912D-019D22837FEB}"= TCP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{2FF38F3F-A204-4A70-8C4A-C05773FE5AE4}"= UDP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{B79FE053-1C6F-4452-9A91-1B621D7E859F}"= TCP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{F29318F3-57B0-40E5-B1C1-CDB4D879558D}"= UDP:c:\windows\explorer.exe:Explorer
"{3A8387B3-5E21-403A-B01E-377F3079396F}"= TCP:c:\windows\explorer.exe:Explorer
"{5DE32FDB-C968-4EB8-9CBE-7D14623AB039}"= UDP:c:\program files\McAfee\VirusScan\mcvsmap.exe:mcvsmap
"{4CD3435D-AAD7-41AD-A68D-E8525291A5CF}"= TCP:c:\program files\McAfee\VirusScan\mcvsmap.exe:mcvsmap
"{4AF792AE-81E1-4C2F-AD59-42204C3DA3FE}"= UDP:c:\windows\System32\dwm.exe:Dwm
"{FFABDF6C-081F-4D75-BC00-92B40780A83B}"= TCP:c:\windows\System32\dwm.exe:Dwm
"{04DC8800-C282-451F-9FEC-A701637483BF}"= UDP:c:\windows\System32\LogonUI.exe:LogonUI
"{ABCEAE1D-9459-4DF6-92F6-5D6320D14CA8}"= TCP:c:\windows\System32\LogonUI.exe:LogonUI
"{CA3C2CB3-CB47-4D24-9CD7-21235544BA49}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{931F6369-FEB2-4911-B8EF-F86C2C2F045B}"= UDP:c:\windows\System32\wininit.exe:wininit
"{31BEE82B-623A-4FD6-810F-2BF4FC1FC226}"= TCP:c:\windows\System32\wininit.exe:wininit
"{A52613FC-8C13-4032-8F19-0D15642E47E9}"= UDP:c:\windows\System32\taskeng.exe:taskeng
"{47BA3F39-3B61-452F-A482-3C3A1C5E8D76}"= TCP:c:\windows\System32\taskeng.exe:taskeng
"{58F3643E-A491-4F8A-B1DE-90A9DB4DC485}"= UDP:c:\windows\System32\services.exe:services
"{3952E4EF-6AB9-42A1-B415-465D1B27B121}"= TCP:c:\windows\System32\services.exe:services
"{0BB51D01-E942-4411-9C21-2B6F40816568}"= UDP:c:\windows\System32\services.exe:services
"{40BB5D3C-C509-47B5-8E10-FAEA38C48533}"= TCP:c:\windows\System32\services.exe:services
"{46603B7B-3C9B-4923-8296-6112CBAEA290}"= UDP:c:\windows\System32\lsass.exe:lsass
"{8EEF70C8-D19C-41AA-829F-C171A939F596}"= TCP:c:\windows\System32\lsass.exe:lsass
"{FEEB1D79-EA81-4655-A2D8-1530C0CEAFE1}"= UDP:c:\program files\McAfee\MSC\mcmscsvc.exe:mcmscsvc
"{8582C608-FE0E-42FE-BEB1-5BB16824FBEF}"= TCP:c:\program files\McAfee\MSC\mcmscsvc.exe:mcmscsvc
"{964530BF-4818-4B67-BF13-DBEA850CEFEC}"= UDP:c:\program files\McAfee\MPF\MpfSrv.exe:MPFSrv
"{2210A3C2-6B33-4685-B081-DCC8B7C9F35D}"= TCP:c:\program files\McAfee\MPF\MpfSrv.exe:MPFSrv
"{7B3EDE70-0871-4EF1-B94A-AA1CC9F91439}"= UDP:c:\windows\System32\Ati2evxx.exe:Ati2evxx
"{17AD1397-5975-494E-9355-94D789E7CA9A}"= TCP:c:\windows\System32\Ati2evxx.exe:Ati2evxx
"{3214D0D9-C7CD-470D-A706-52431F048D2F}"= UDP:c:\windows\System32\SearchIndexer.exe:SearchIndexer
"{754847D7-B6E4-4351-84C7-3AEA97434079}"= UDP:c:\windows\System32\SearchIndexer.exe:SearchIndexer
"{36395B9A-C60C-48AB-B8C4-5726E6A9C719}"= TCP:c:\windows\System32\SearchIndexer.exe:SearchIndexer
"{064E850C-4682-465E-818F-D553E683E231}"= TCP:c:\windows\System32\SearchIndexer.exe:SearchIndexer
"{77F92F00-7B90-4623-B2E7-645727230791}"= UDP:c:\windows\explorer.exe:Explorer
"{F8063591-42AB-4143-8E5F-F2F0D6317663}"= TCP:c:\windows\explorer.exe:Explorer
"{A32F622D-25F0-477E-A5FF-B1B73CA84EA6}"= UDP:c:\program files\Microsoft LifeCam\MSCamS32.exe:MSCamS32
"{E26E5B36-3E35-4C9B-98EC-F54F1A007E06}"= TCP:c:\program files\Microsoft LifeCam\MSCamS32.exe:MSCamS32
"{BBBB5268-C05B-4BFE-BAEA-31536E76D7D8}"= UDP:c:\combofix\NirCmd.cfexe:NirCmd
"{5799FA8B-B384-483D-A66C-88C127FBAB20}"= TCP:c:\combofix\NirCmd.cfexe:NirCmd
"{C4606F59-A627-4BFB-98BA-731B30DB55F6}"= UDP:c:\windows\System32\dwm.exe:Dwm
"{C97C069A-2F0D-4469-B5DF-1640115E54DD}"= TCP:c:\windows\System32\dwm.exe:Dwm
"{A2A313F6-5C48-4345-98E0-69C0B217EF9F}"= UDP:c:\program files\McAfee\SiteAdvisor\McSACore.exe:McSACore
"{05A601D6-6206-4B59-A7ED-B6C219CEEA16}"= TCP:c:\program files\McAfee\SiteAdvisor\McSACore.exe:McSACore
"{64CCF949-895C-4D45-88FC-5F1A6F610B5F}"= UDP:c:\program files\BT Next Evolution\btnext.exe:BT Next Evolution
"{B40FFDC6-BA4E-413E-A9CE-4E13CE1A5762}"= TCP:c:\program files\BT Next Evolution\btnext.exe:BT Next Evolution
"{086310FB-61DE-46E4-B0E5-F3C0DF5CDBA4}"= UDP:c:\program files\Microsoft Games\Dungeon Siege 2\DungeonSiege2.exe:Dungeon Siege 2 Game Executable
"{D3871CD2-FAD2-4813-9B4D-5E70B449FE72}"= TCP:c:\program files\Microsoft Games\Dungeon Siege 2\DungeonSiege2.exe:Dungeon Siege 2 Game Executable
"{C9AC6928-D0E2-4433-AA9D-AD094396780F}"= UDP:c:\program files\Codemasters\Overlord II\Overlord2.exe:Overlord II
"{254BC55F-F37A-4FE0-938D-2C6D2DA77A7E}"= TCP:c:\program files\Codemasters\Overlord II\Overlord2.exe:Overlord II
"{E7D424AA-4FFD-473C-AE6A-13821DFBAC74}"= UDP:c:\windows\System32\muzapp.exe:MUZ AOD APP player
"{AC607783-0EEC-4710-A7C6-E5846050325F}"= TCP:c:\windows\System32\muzapp.exe:MUZ AOD APP player
"TCP Query User{19171C3B-E031-4834-A976-31A558B849EC}c:\\program files\\steam\\steamapps\\_ultima_\\counter-strike\\hl.exe"= UDP:c:\program files\steam\steamapps\_ultima_\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{F4C3C9D2-064F-4771-A8B9-3A4153BA796E}c:\\program files\\steam\\steamapps\\_ultima_\\counter-strike\\hl.exe"= TCP:c:\program files\steam\steamapps\_ultima_\counter-strike\hl.exe:Half-Life Launcher
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\System32\drivers\L1E60x86.sys [23-12-2008 22:01 48128]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\System32\drivers\viahduaa.sys [23-12-2008 22:05 250880]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.google.pt/
uInternet Settings,ProxyOverride = *.local
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-13 22:48
Windows 6.0.6001 Service Pack 1 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\VDeck\VDeck.exe????????????????????????????????????????????
Procurando ficheiros/arquivos ocultos ...
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
**************************************************************************
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Tempo para conclusão: 2009-08-13 22:49
ComboFix-quarantined-files.txt 2009-08-13 21:49
ComboFix2.txt 2009-08-12 23:33
ComboFix3.txt 2009-08-06 11:18
ComboFix4.txt 2009-08-05 18:28
Pré-execução: 36.967.444.480 bytes livres
Pós execução: 37.008.334.848 bytes livres
372 --- E O F --- 2009-08-13 02:02
MBAM LOGMalwarebytes' Anti-Malware 1.40
Versão do banco de dados: 2617
Windows 6.0.6001 Service Pack 1
13-08-2009 23:28:31
mbam-log-2009-08-13 (23-28-31).txt
Tipo de Verificação: Completa (C:\|E:\|)
Objetos verificados: 224159
Tempo decorrido: 32 minute(s), 48 second(s)
Processos da Memória infectados: 0
Módulos de Memória Infectados: 0
Chaves do Registo infectadas: 0
Valores do Registo infectados: 0
Ítens do Registo infectados: 0
Pastas infectadas: 0
Ficheiros infectados: 0
Processos da Memória infectados:
(Nenhum item malicioso foi detectado)
Módulos de Memória Infectados:
(Nenhum item malicioso foi detectado)
Chaves do Registo infectadas:
(Nenhum item malicioso foi detectado)
Valores do Registo infectados:
(Nenhum item malicioso foi detectado)
Ítens do Registo infectados:
(Nenhum item malicioso foi detectado)
Pastas infectadas:
(Nenhum item malicioso foi detectado)
Ficheiros infectados:
(Nenhum item malicioso foi detectado)
Edited by fpnc, 13 August 2009 - 05:31 PM.