1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.959.668 [GMT -3:00]
Executando de: c:\documents and settings\Antonio\Meus documentos\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 091007-0] *On-access scanning disabled*
(Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((( Relat�rio
Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-04 19:58 . 2009-10-04 17:47 -------- d--h--w- c:\arquivos de
programas\InstallShield Installation Information
2009-10-04 19:12 . 2009-10-04 17:47 -------- d-----w- c:\arquivos de
programas\Arquivos comuns\InstallShield
2009-10-04 18:02 . 2001-10-28 17:07 48846 ----a-w-
c:\windows\system32\perfc016.dat
2009-10-04 18:02 . 2001-10-28 17:07 344734 ----a-w-
c:\windows\system32\perfh016.dat
2009-10-04 17:56 . 2009-10-04 17:56 -------- d-----w- c:\arquivos de
programas\S3
2009-10-04 17:51 . 2009-10-04 17:51 -------- d-----w- c:\arquivos de
programas\VIA
2009-10-04 17:47 . 2009-10-04 17:47 -------- d-----w- c:\arquivos de
programas\AMD
2009-10-04 17:29 . 2009-10-04 17:29 -------- d-----w- c:\arquivos de
programas\microsoft frontpage
2009-10-04 17:26 . 2009-10-04 17:26 -------- d-----w- c:\arquivos de
programas\Servi�os on-line
2009-10-04 17:25 . 2009-10-04 17:25 -------- d-----w- c:\arquivos de
programas\Arquivos comuns\Servi�os
2009-10-04 17:23 . 2009-10-04 17:23 21844 ----a-w-
c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((( SnapShot_2009-10-
05_04.05.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-07 22:04 . 2009-10-07 22:04 16384
c:\windows\Temp\Perflib_Perfdata_618.dat
+ 2009-10-05 04:33 . 2003-04-03 15:10 46080
c:\windows\system32\_easywall.dll
+ 2009-10-04 17:27 . 2009-10-06 18:22 86327
c:\windows\pchealth\helpctr\OfflineCache\index.dat
- 2009-10-04 17:27 . 2009-10-04 17:27 86327
c:\windows\pchealth\helpctr\OfflineCache\index.dat
+ 2009-10-05 18:01 . 2009-10-05 18:01 80395 c:\windows\Installer\
{BF6CDAFB-F8C3-4DE1-B2E6-25F4EC27CAA2}\MsblIco.Exe
- 2009-10-04 19:32 . 2009-10-04 19:32 80395 c:\windows\Installer\
{BF6CDAFB-F8C3-4DE1-B2E6-25F4EC27CAA2}\MsblIco.Exe
+ 2009-10-04 17:27 . 2009-10-06 18:22 2426
c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2009-10-04 17:27 . 2009-10-06 18:21 8972
c:\windows\pchealth\helpctr\Config\Cntstore.bin
+ 2009-10-04 13:52 . 2009-10-05 11:19 263824
c:\windows\system32\FNTCACHE.DAT
.
(((((((((((((((((((((((((( Pontos de Carregamento do
Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e leg�timas por defeito n�o s�o mostradas.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\arquivos de programas\Messenger\msmsgs.exe" [2004-08-04 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"Client"="c:\arquiv~1\TinaSoft\EASYCA~1\client.exe" [2003-04-14 451072]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2005-03-08 53248]
"S3Trayp"="S3trayp.exe" - c:\windows\system32\S3Trayp.exe [2005-04-05 159744]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-03-03 16006656]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Authorized
Applications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Arquivos de programas\\TinaSoft\\Easy Cafe Client\\client.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed
components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe"
"c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Conte�do da pasta 'Tarefas Agendadas'
2009-10-07 c:\windows\Tasks\User_Feed_Synchronization-{9503CB9F-2134-445C-9A72-
E2A7C26CB6CF}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 07:31]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = hxxp://192.168.2.2:918
IE: E&xportar para o Microsoft Excel -
c:\arquiv~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {9B0A17EF-CFF5-46CF-B42A-5C9F04BEDAEB} = 189.43.121.138,189.43.121.136
.
**************************************************************************
**************************************************************************
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-
17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-
17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-
17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-
98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-
98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-
98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Carregadas Sob os Processos em Execu��o
---------------------
- - - - - - - > 'explorer.exe'(1652)
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Tempo para conclus�o: 2009-10-07 19:15
ComboFix-quarantined-files.txt 2009-10-07 22:15
ComboFix2.txt 2009-10-05 04:07
ComboFix3.txt 2009-10-05 01:25
193