ComboFix 10-09-03.02 - user 04/09/2010 18:13:40.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.55.1046.18.3327.2546 [GMT -3:00]
Executando de: c:\users\user\Desktop\ComboFix*****
AV: ESET NOD32 sistema antivírus 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
c:\windows\system32\%appdata%
D:\install*****
.
(((((((((((((((( Arquivos/Ficheiros criados de 2010-08-04 to 2010-09-04 ))))))))))))))))))))))))))))
.
2010-09-04 17:45 . 2010-09-04 17:45 -------- d-----w- c:\users\user\AppData\Roaming\Malwarebytes
2010-09-04 17:44 . 2010-04-29 18:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-04 17:44 . 2010-09-04 17:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-04 17:44 . 2010-09-04 17:44 -------- d-----w- c:\programdata\Malwarebytes
2010-09-04 17:44 . 2010-04-29 18:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-04 11:43 . 2010-09-04 11:43 -------- d-----w- c:\users\user\AppData\Roaming\Tibia
2010-09-04 11:37 . 2010-09-04 11:29 304884 ----a-w- c:\windows\system32\Tibia.dat
2010-09-02 02:03 . 2010-09-02 02:03 -------- d-----w- c:\program files\BitTorrent
2010-09-02 02:03 . 2010-09-02 02:03 -------- d-----w- c:\program files\Ask.com
2010-09-02 02:03 . 2010-09-04 21:19 -------- d-----w- c:\users\user\AppData\Roaming\BitTorrent
2010-09-01 20:17 . 2010-09-04 11:42 -------- d-----w- c:\program files\Tibia
2010-09-01 20:06 . 2010-09-01 20:06 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\L ocal\Mozilla
2010-09-01 20:05 . 2010-09-01 20:05 -------- d-----w- c:\windows\system32\config\systemprofile\Tracing
2010-09-01 20:03 . 2010-09-01 20:03 -------- d-----w- c:\windows\system32\Wat
2010-09-01 19:56 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-09-01 19:55 . 2009-11-25 15:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-09-01 19:55 . 2009-11-25 15:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-09-01 19:55 . 2009-11-25 15:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-09-01 19:55 . 2009-11-25 15:47 295264 ----a-w- c:\windows\system32\PresentationHost*****
2010-09-01 19:55 . 2009-11-25 15:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-09-01 19:48 . 2010-09-01 19:48 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-09-01 19:45 . 2010-09-01 19:45 -------- d-----w- c:\program files\MSXML 4.0
2010-09-01 17:54 . 2010-09-01 17:54 -------- d-----w- c:\users\user\AppData\Local\ElevatedDiagnostics
2010-09-01 17:38 . 2010-09-01 17:38 -------- d-----w- c:\program files\Common Files\Steam
2010-09-01 17:38 . 2010-09-04 21:19 -------- d-----w- c:\program files\Steam
2010-09-01 17:33 . 2009-12-19 09:02 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2010-09-01 17:30 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-09-01 17:30 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 17:30 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-09-01 17:30 . 2010-09-01 17:30 0 ----a-w- c:\windows\nsreg.dat
2010-09-01 17:30 . 2010-09-01 17:30 -------- d-----w- c:\users\user\AppData\Local\Mozilla
2010-09-01 17:29 . 2010-05-21 17:14 221568 ------w- c:\windows\system32\MpSigStub*****
2010-08-31 22:58 . 2010-08-31 18:05 -------- d-----w- c:\windows\Panther
2010-08-31 22:58 . 2010-08-31 22:58 -------- d-----w- C:\Boot
2010-08-31 19:50 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2010-08-31 19:50 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-08-31 19:08 . 2010-08-31 19:08 -------- d-----w- c:\users\user\AppData\Roaming\Nero
2010-08-31 18:59 . 2007-02-07 04:02 65536 ----a-w- c:\windows\cmiboot*****
2010-08-31 18:59 . 2007-01-17 10:57 327680 ----a-w- c:\windows\system32\CmUCRRm*****
2010-08-31 18:59 . 2007-01-12 03:20 93056 ----a-w- c:\windows\system32\drivers\cmiucr.SYS
2010-08-31 18:59 . 2006-12-19 03:04 241664 ----a-w- c:\windows\CmUCREye*****
2010-08-31 18:59 . 2006-12-07 08:10 53248 ----a-w- c:\windows\system32\CmUCRRm.Dll
2010-08-31 18:59 . 2007-02-14 08:04 311296 ------r- c:\windows\CmiUCRUninstall*****
2010-08-31 18:59 . 2007-02-14 08:03 464384 ------r- c:\windows\CmiUCRUninstall_x64*****
2010-08-31 18:59 . 2010-08-31 18:59 -------- d-----w- c:\program files\C-Media USB2.0 Card Reader
2010-08-31 18:55 . 2007-05-06 09:11 94208 ----a-w- c:\windows\system32\stacsv*****
2010-08-31 18:55 . 2007-05-06 09:10 405504 ----a-w- c:\windows\sttray*****
2010-08-31 18:55 . 2007-05-06 09:10 2187264 ----a-w- c:\windows\system32\stlang.dll
2010-08-31 18:54 . 2007-05-06 09:12 326656 ----a-w- c:\windows\system32\drivers\stwrt.sys
2010-08-31 18:54 . 2007-05-06 09:11 326144 ----a-w- c:\windows\system32\stcplx.dll
2010-08-31 18:54 . 2007-05-06 09:11 587776 ----a-w- c:\windows\system32\stapo.dll
2010-08-31 18:54 . 2007-05-06 09:11 144896 ----a-w- c:\windows\system32\staco.dll
2010-08-31 18:54 . 2007-05-06 09:10 244736 ----a-w- c:\windows\system32\stapi32.dll
2010-08-31 18:54 . 2010-08-31 18:54 -------- d-----w- c:\program files\SigmaTel
2010-08-31 18:54 . 2010-08-31 18:54 -------- d-----w- c:\program files\Intel
2010-08-31 18:53 . 2010-08-31 18:53 -------- d-----w- C:\Intel
2010-08-31 18:53 . 2010-08-31 18:53 -------- d-----w- c:\windows\system32\Tools
2010-08-31 18:49 . 2005-05-26 18:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2010-08-31 18:48 . 2010-08-31 18:48 -------- d-----w- c:\windows\nview
2010-08-31 18:48 . 2007-05-10 21:39 356352 ----a-w- c:\windows\system32\NVUNINST*****
2010-08-31 18:42 . 2010-08-31 18:42 -------- d-----w- c:\users\user\AppData\Local\Adobe
2010-08-31 18:41 . 2010-08-31 18:41 -------- d-----w- c:\program files\XP Codec Pack
2010-08-31 18:40 . 2010-09-04 21:19 -------- d-----w- c:\users\user\Tracing
2010-08-31 18:40 . 2010-09-01 19:46 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-31 18:40 . 2010-08-31 18:40 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2010-08-31 18:39 . 2010-08-31 18:39 -------- d-----w- c:\program files\Microsoft Sync Framework
2010-08-31 18:38 . 2006-11-29 16:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-08-31 18:38 . 2010-08-31 18:38 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-08-31 18:37 . 2010-08-31 18:40 -------- d-----w- c:\program files\Microsoft
2010-08-31 18:37 . 2010-08-31 18:37 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-08-31 18:37 . 2010-08-31 18:39 -------- d-----w- c:\program files\Windows Live
2010-08-31 18:36 . 2010-08-31 18:36 -------- d-----w- c:\program files\Common Files\Windows Live
2010-08-31 18:35 . 2010-08-31 18:35 -------- d-----w- c:\users\user\AppData\Local\Ahead
2010-08-31 18:33 . 2010-08-31 18:34 -------- d-----w- c:\program files\Common Files\Nero
2010-08-31 18:33 . 2010-08-31 18:33 -------- d-----w- c:\programdata\Nero
2010-08-31 18:33 . 2010-08-31 18:33 -------- d-----w- c:\program files\Nero
2010-08-31 18:29 . 2010-08-31 18:29 -------- d-----w- c:\programdata\CyberLink
2010-08-31 18:29 . 2010-08-31 18:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-31 18:29 . 2010-08-31 18:29 -------- d-----w- c:\program files\CyberLink
2010-08-31 18:29 . 2010-08-31 18:48 -------- d-----w- c:\program files\Common Files\InstallShield
2010-08-31 18:25 . 2010-08-31 18:25 -------- d-----w- c:\windows\system32\custom matrices
2010-08-31 18:25 . 2010-08-31 18:25 -------- d-----w- c:\windows\system32\C2MP
2010-08-31 18:25 . 2010-08-31 18:25 -------- d-----w- c:\windows\system32\QuickTime
2010-08-31 18:23 . 2010-08-31 18:23 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-31 18:21 . 2008-11-10 14:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2010-08-31 18:21 . 2006-10-26 22:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr .dll
2010-08-31 18:20 . 2010-09-01 19:49 -------- d-----w- c:\program files\Microsoft Works
2010-08-31 18:19 . 2010-08-31 18:19 -------- d-----w- c:\windows\PCHEALTH
2010-08-31 18:19 . 2010-08-31 18:19 -------- d-----w- c:\program files\Microsoft.NET
2010-08-31 18:18 . 2010-08-31 18:18 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-08-31 18:18 . 2010-08-31 18:18 -------- d-----w- c:\users\user\AppData\Local\Microsoft Help
2010-08-31 18:18 . 2010-09-02 17:07 -------- d-----w- c:\programdata\Microsoft Help
2010-08-31 18:18 . 2010-09-02 17:07 -------- d-sh--w- c:\windows\Installer
2010-08-31 18:18 . 2010-08-31 18:18 -------- d-----r- C:\MSOCache
2010-08-31 18:16 . 2010-08-31 18:16 512096 ----a-w- c:\windows\system32\drivers\amon.sys
2010-08-31 18:16 . 2010-08-31 18:16 298104 ----a-w- c:\windows\system32\imon.dll
2010-08-31 18:16 . 2010-08-31 18:16 15424 ----a-w- c:\windows\system32\drivers\nod32drv.sys
2010-08-31 18:16 . 2010-09-02 16:05 -------- d-----w- c:\program files\ESET
2010-08-31 18:11 . 2010-08-31 18:36 108824 ----a-w- c:\users\user\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-31 18:08 . 2010-09-04 21:15 -------- d-----w- c:\windows\system32\wbem\Performance
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2010-09-04 21:15 . 2009-07-17 18:48 654272 ----a-w- c:\windows\system32\prfh0416.dat
2010-09-04 21:15 . 2009-07-17 18:48 124724 ----a-w- c:\windows\system32\prfc0416.dat
2010-09-01 20:03 . 2009-07-14 02:37 -------- d-----w- c:\program files\Windows Mail
2010-08-31 18:59 . 2010-08-31 18:59 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_ 00.Wdf
2010-08-31 18:20 . 2009-07-14 04:52 -------- d-----w- c:\program files\MSBuild
2010-08-31 18:05 . 2010-08-31 18:05 -------- d-sh--we c:\programdata\Modelos
2010-08-31 18:05 . 2010-08-31 18:05 -------- d-sh--we c:\programdata\Menu Iniciar
2010-08-31 18:05 . 2010-08-31 18:05 -------- d-sh--we c:\programdata\Favoritos
2010-08-31 18:05 . 2010-08-31 18:05 -------- d-sh--we c:\programdata\Documentos
2010-08-31 18:05 . 2010-08-31 18:05 -------- d-sh--we c:\programdata\Dados de aplicativos
2010-08-31 18:05 . 2010-08-31 18:05 -------- d-sh--we c:\program files\Common Files\Sistema
2010-08-31 18:05 . 2010-08-31 18:05 -------- d-sh--we c:\program files\Arquivos Comuns
2010-07-29 06:30 . 2010-09-01 17:34 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-09-01 17:34 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-06-30 06:25 . 2010-09-01 17:33 978432 ----a-w- c:\windows\system32\wininet.dll
2010-06-22 02:47 . 2010-09-01 17:34 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-22 02:47 . 2010-09-01 17:34 307200 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-22 02:47 . 2010-09-01 17:34 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-06-19 06:33 . 2010-09-01 17:33 3955080 ----a-w- c:\windows\system32\ntkrnlpa*****
2010-06-19 06:33 . 2010-09-01 17:33 3899784 ----a-w- c:\windows\system32\ntoskrnl*****
2010-06-19 06:23 . 2010-09-01 17:34 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-06-19 04:07 . 2010-09-01 17:33 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48 . 2010-09-01 17:33 224256 ----a-w- c:\windows\system32\schannel.dll
2010-06-14 06:12 . 2010-09-01 17:34 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-08 06:02 . 2010-09-01 17:34 1233920 ----a-w- c:\windows\system32\msxml3.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb 108c86c\WinMail*****
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por defeito não são mostradas.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 18:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr*****" [2008-06-24 1840424]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr*****" [2009-07-26 3883840]
"Steam"="c:\program files\Steam\Steam*****" [2010-09-01 1242448]
"BitTorrent"="c:\program files\BitTorrent\BitTorrent*****" [2010-09-02 2931568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"nod32kui"="c:\program files\Eset\nod32kui*****" [2010-08-31 949376]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor*****" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl*****" [2008-06-12 34672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-10 8429568]
"nwiz"="nwiz*****" [2007-05-10 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2007-05-10 81920]
"SigmatelSysTrayApp"="sttray*****" [2007-05-06 405504]
"Cmiboot"="c:\windows\cmiboot*****" [2007-02-07 65536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
R3 WatAdminSvc;Serviço de Tecnologias de Ativação do Windows;c:\windows\system32\Wat\WatAdminSvc***** [2010-09-01 1343400]
S1 nod32drv;nod32drv;c:\windows\system32\drivers\nod3 2drv.sys [2010-08-31 15424]
S3 CMISTOR;CMIUCR.SYS CM320/CM220 Card Reader Driver;c:\windows\system32\DRIVERS\cmiucr.SYS [2007-01-12 93056]
.
.
------- Scan Suplementar -------
.
IE: E&xportar para o Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL*****/3000
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\windows\System32\config\systemprofile\AppData\R oaming\Mozilla\Firefox\Profiles\89bg5wzn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PC W\Security]
@Denied: (Full) (Everyone)
.
------------------------ Outros Processos em Execução ------------------------
.
c:\windows\system32\taskhost*****
c:\program files\Eset\nod32krn*****
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort*****
c:\windows\system32\sppsvc*****
c:\windows\system32\STacSV*****
c:\windows\system32\conhost*****
c:\windows\sttray*****
c:\windows\CmUCReye*****
c:\program files\Windows Live\Contacts\wlcomm*****
c:\program files\Common Files\Nero\Lib\NMIndexingService*****
c:\windows\system32\WUDFHost*****
c:\program files\Windows Media Player\wmpnetwk*****
.
************************************************** ************************
.
Tempo para conclusão: 2010-09-04 18:23:28 - Máquina reiniciou
ComboFix-quarantined-files.txt 2010-09-04 21:23
Pré-execução: 75.115.122.688 bytes disponíveis
Pós execução: 74.965.323.776 bytes disponíveis
- - End Of File - - D2CB49D4B875C5A30082720BFB047970