Joined
·
16 Posts
Hello.
Here is the log of Avast Antivirus :
--------------------------------------------
31/5/2008 18:24:18 Luiz Márcio 2568 Sign of "Win32:Agent-GMC [Trj]" has been found in "C:\System Volume Information\_restore{A73780C7-9903-4BC5-9A92-1848D0D7B0E9}\RP387\A0024464.scr\best_video.avi.scr\china.avi.scr\[UPX]" file.
31/5/2008 18:24:27 Luiz Márcio 2568 Sign of "Win32
oisonIvy-AM [Trj]" has been found in "C:\System Volume Information\_restore{A73780C7-9903-4BC5-9A92-1848D0D7B0E9}\RP387\A0024464.scr\best_video.avi.scr\china.avi.scr\[Embedded#1a00]" file.
31/5/2008 18:39:40 Luiz Márcio 2568 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{A73780C7-9903-4BC5-9A92-1848D0D7B0E9}\RP475\A0029764.exe\allin1dfx.exe" file.
31/5/2008 18:44:49 Luiz Márcio 2568 Sign of "Win32
elf-IWT [Trj]" has been found in "C:\System Volume Information\_restore{A73780C7-9903-4BC5-9A92-1848D0D7B0E9}\RP475\A0029764.exe\dfx.exe" file.
31/5/2008 18:45:11 Luiz Márcio 2568 Sign of "Win32:CTX" has been found in "C:\System Volume Information\_restore{A73780C7-9903-4BC5-9A92-1848D0D7B0E9}\RP477\A0029819.dll" file.
31/5/2008 18:52:57 Luiz Márcio 2568 Sign of "Win32:CTX" has been found in "C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll" file.
31/5/2008 18:55:11 Luiz Márcio 2568 Sign of "Win32:NGVCK-E" has been found in "C:\WINDOWS\SYSTEM32\pav.sig" file.
31/5/2008 22:40:38 SYSTEM 1704 Sign of "Win32:CTX" has been found in "C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll" file.
31/5/2008 22:54:29 SYSTEM 1704 Sign of "Win32:CTX" has been found in "C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll" file.
31/5/2008 22:55:05 SYSTEM 1704 Sign of "Win32:CTX" has been found in "C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll" file.
31/5/2008 22:58:27 SYSTEM 1704 Sign of "Win32:CTX" has been found in "C:\Arquivos de programas\Panda Security\ActiveScan 2.0\pskavs.dll" file.
31/5/2008 22:58:42 SYSTEM 1704 Sign of "Win32:CTX" has been found in "C:\Arquivos de programas\Panda Security\ActiveScan 2.0\pskavs.dll" file.
3/6/2008 23:49:15 SYSTEM 1676 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\svchost.exe" file.
3/6/2008 23:56:19 Luiz Márcio 1280 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\SYSTEM32\SVCHOST.EXE" file.
4/6/2008 00:42:03 SYSTEM 1676 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\SYSTEM32\SVCHOST.EXE" file.
4/6/2008 00:42:27 SYSTEM 1676 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\SYSTEM32\DLLCACHE\svchost.exe" file.
4/6/2008 00:42:47 SYSTEM 1676 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\windows\system32\SET23.tmp" file.
4/6/2008 03:23:38 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\I386\SVCHOST.EXE" file.
4/6/2008 05:38:28 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\unp28195895.tmp" file.
4/6/2008 08:26:03 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\trz26.tmp" file.
4/6/2008 08:27:39 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\trz27.tmp" file.
4/6/2008 08:28:45 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\trz28.tmp" file.
4/6/2008 08:29:26 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\trz29.tmp" file.
4/6/2008 08:36:33 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\trz2A.tmp" file.
--------------------------------------------
I think i used ACDSee to view the file with Win32:Agent-GMC [Trj] or Win32
oisonIvy-AM [Trj].
ACDSee started to act strange,abruptaly finishing with an error, but not always. And once it deleted an entire folder.
I uninstalled it.
It put all in Avast quarentine, and extracted svchost.exe from de directory i386 of the Dell OS reinstalation cd .
Then, after a reboot, no drag and drop , no system restore, not opening of property sheets, the visual of the taskbar changed.
Almost no services running. RPC server not running mensage.
I fixed the RPcss section in the registry , and still no system restore and the visual of the taskbar changed.
Here is the log of Deckards System Scanner:
Deckard's System Scanner v20071014.68
Run by Luiz Márcio on 2008-06-16 22:34:16
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Unable to create WMI object; A operação foi concluída com êxito.
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 511 MiB (512 MiB recommended).
-- HijackThis (run as Luiz Márcio.exe) -----------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:35:01, on 16/6/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\Arquivos de programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Arquivos de programas\Microsoft IntelliPoint\point32.exe
C:\Arquivos de programas\Iomega\DriveIcons\ImgIcon.exe
C:\Arquivos de programas\- internet\ZoneAlarm\zlclient.exe
C:\Arquivos de programas\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Arquivos de programas\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Arquivos de programas\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Arquivos de programas\Executive Software\Diskeeper\DkService.exe
C:\ARQUIV~1\Iomega\System32\AppServices.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Arquivos de programas\Iomega\AutoDisk\ADService.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\Luiz Márcio\Desktop\dss.exe
C:\ARQUIV~1\TRENDM~1\HIJACK~1\Luiz Márcio.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com/intl/la/brazil/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com/intl/la/brazil/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com/intl/la/brazil/index.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:12080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~2\SDHelper.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\- utilities\Free Download Manager\iefdmcks.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Arquivos de programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Arquivos de programas\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Arquivos de programas\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Arquivos de programas\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [Zone Labs Client] C:\Arquivos de programas\- internet\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Arquivos de programas\- utilities\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Arquivos de programas\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Arquivos de programas\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [SoniqueQuickStart] C:\Arquivos de programas\- utilities\Sonique\sqstart.exe -nostick
O4 - HKCU\..\Run: [AnyDVD] "C:\Arquivos de programas\SlySoft\AnyDVD\AnyDVD.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-2237029002-2704639424-2437969446-1005\..\Run: [SoniqueQuickStart] C:\Arquivos de programas\- utilities\Sonique\sqstart.exe -nostick (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Arquivos de programas\- utilities\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Arquivos de programas\- utilities\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Arquivos de programas\- utilities\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~2\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~2\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\MSMSGS.EXE
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Arquivos de programas\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\ARQUIV~1\Iomega\System32\AppServices.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Arquivos de programas\Iomega\AutoDisk\ADService.exe
--
End of file - 8834 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
3 ac97intc (Intel(r) 82801 Audio Driver Install Service (WDM)) - c:\windows\system32\drivers\ac97intc.sys <Not Verified; Intel Corporation; Intel(r) Integrated Controller Hub Audio Driver>
3 ati2mtaa - c:\windows\system32\drivers\ati2mtaa.sys <Not Verified; ATI Technologies Inc.; ATI Rage 128 Family>
3 C-Dilla - c:\windows\system32\drivers\cdant.sys <Not Verified; Macrovision; Licence Management System>
4 cbidf - c:\windows\system32\drivers\cbidf2k.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2 CdaC15BA - c:\windows\system32\drivers\cdac15ba.sys <Not Verified; Macrovision Europe Ltd; Security Windows NT>
4 dac2w2k - c:\windows\system32\drivers\dac2w2k.sys <Not Verified; Mylex Corporation; Mylex Disk Array Controller Driver>
3 EL90XBC (3Com EtherLink XL 90XB/C Adapter Driver) - c:\windows\system32\drivers\el90xbc5.sys <Not Verified; 3Com Corporation; 3Com EtherLink PCI>
3 ElbyCDFL - c:\windows\system32\drivers\elbycdfl.sys <Not Verified; SlySoft, Inc.; CloneCD>
3 emupia (E-mu Plug-in Architecture Driver) - c:\windows\system32\drivers\emupia2k.sys <Not Verified; Creative Technology Ltd; E-mu Plug-In Architecture>
3 HCF_MSFT - c:\windows\system32\drivers\hcf_msft.sys <Not Verified; Conexant; Modem>
3 HSFHWBS2 - c:\windows\system32\drivers\hsfhwbs2.sys <Not Verified; Conexant Systems; SoftK56>
3 HSF_DP - c:\windows\system32\drivers\hsf_dp.sys <Not Verified; Conexant Systems; SoftK56>
3 i81x - c:\windows\system32\drivers\i81xnt5.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimFP0 - c:\windows\system32\drivers\wadv01nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimFP1 - c:\windows\system32\drivers\wadv02nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimFP2 - c:\windows\system32\drivers\wadv05nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimFP3 - c:\windows\system32\drivers\wsiintxx.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimFP4 - c:\windows\system32\drivers\wvchntxx.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimTV0 - c:\windows\system32\drivers\watv01nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimTV1 - c:\windows\system32\drivers\watv02nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimTV2 - c:\windows\system32\drivers\watv03nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimTV3 - c:\windows\system32\drivers\watv04nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimTV4 - c:\windows\system32\drivers\wch7xxnt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
0 iomdisk (Iomega Devices Disk Filter Services) - c:\windows\system32\drivers\iomdisk.sys <Not Verified; Iomega Corporation; Microsoft(R) Windows NT(R) Operating System>
2 mdmxsdk - c:\windows\system32\drivers\mdmxsdk.sys <Not Verified; Conexant; Diagnostic Interface>
3 MODEMCSA (Dispositivo de filtro de fluxo unimodem) - c:\windows\system32\drivers\modemcsa.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
0 ppa3 (Iomega Parallel Port Legacy Filter Driver) - c:\windows\system32\drivers\ppa3.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
3 winachsf - c:\windows\system32\drivers\hsf_cnxt.sys <Not Verified; Conexant Systems; SoftK56>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
2 aawservice (Ad-Aware 2007 Service) - c:\arquivos de programas\lavasoft\ad-aware 2007\aawservice.exe
2 C-DillaCdaC11BA - c:\windows\system32\drivers\cdac11ba.exe <Not Verified; Macrovision; SafeCast Windows NT>
2 C-DillaSrv - c:\windows\system32\drivers\cdantsrv.exe <Not Verified; C-Dilla Ltd; CD-Secure/CD-Compress Windows NT>
2 Diskeeper - c:\arquivos de programas\executive software\diskeeper\dkservice.exe <Not Verified; Executive Software International, Inc.; Diskeeper (TM) Disk Defragmenter>
4 Iomega Activity Disk2 - c:\windows\system32
2 Iomega App Services - c:\arquivos de programas\iomega\system32\appservices.exe
2 _IOMEGA_ACTIVE_DISK_SERVICE_ (Iomega Active Disk) - c:\arquivos de programas\iomega\autodisk\adservice.exe
-- Device Manager: Disabled ----------------------------------------------------
Unable to create WMI object.
-- Files created between 2008-05-16 and 2008-06-16 -----------------------------
2008-06-16 22:25:44 0 d-------- C:\Arquivos de programas\Trend Micro
2008-06-16 18:17:15 0 d-------- C:\WINDOWS\tmp
2008-06-12 01:24:52 63677956 --a------ C:\regbckp3.reg
2008-06-05 17:14:37 0 d-------- C:\WINDOWS\LastGood.Tmp
2008-06-05 15:18:15 744853 --a------ C:\PAVARK.exe
2008-06-04 09:56:19 12800 --a------ C:\WINDOWS\System32\svchost.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-04 09:55:20 12800 --a------ C:\svchost.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-29 23:53:56 0 d-------- C:\Arquivos de programas\Alwil Software
2008-05-17 18:25:35 288 --a------ C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2008-05-17 18:25:35 288 --a------ C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2008-05-17 12:24:08 53552 -----n--- C:\WINDOWS\CTCCW.DLL <Not Verified; Creative® Technology Ltd.; Custom Control for Windows>
2008-05-17 12:24:05 26768 -----n--- C:\WINDOWS\System32\CTL3D.DLL <Not Verified; Microsoft Corporation; 3D Windows Control>
2008-05-17 12:24:03 1048576 -----n--- C:\WINDOWS\System32\SFMAN.DAT
2008-05-17 12:24:01 0 d-------- C:\WINDOWS\System32\Defaults
2008-05-17 12:23:23 134272 --a------ C:\WINDOWS\System32\drivers\portcls.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 12:23:23 57856 --a------ C:\WINDOWS\System32\drivers\drmk.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 12:22:53 36864 --a------ C:\WINDOWS\System32\sfman32.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:53 135728 --a------ C:\WINDOWS\System32\drivers\hap16v2k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:52 816576 --a------ C:\WINDOWS\System32\drivers\ha10kx2k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:52 115936 --a------ C:\WINDOWS\System32\drivers\emupia2k.sys <Not Verified; Creative Technology Ltd; E-mu Plug-In Architecture>
2008-05-17 12:22:51 134032 --a------ C:\WINDOWS\System32\drivers\ctsfm2k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:51 6144 --a------ C:\WINDOWS\System32\drivers\ctprxy2k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:51 183703 --a------ C:\WINDOWS\System32\ctstatic.dat
2008-05-17 12:22:50 298384 --a------ C:\WINDOWS\System32\drivers\ctdvda2k.sys
2008-05-17 12:22:50 189490 --a------ C:\WINDOWS\System32\ctdlang.dat
2008-05-17 12:22:50 53674 --a------ C:\WINDOWS\System32\ctdaught.dat
2008-05-17 12:22:50 114972 --a------ C:\WINDOWS\System32\CTBASICW.DAT
2008-05-17 12:22:50 142968 --a------ C:\WINDOWS\System32\ctbas2w.dat
2008-05-17 12:22:49 493568 --a------ C:\WINDOWS\System32\drivers\ctaud2k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:49 186068 --a------ C:\WINDOWS\System32\drivers\ctac32k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:49 65536 --a------ C:\WINDOWS\System32\a3d.dll <Not Verified; ; a3dx5>
2008-05-17 12:22:47 49152 --a------ C:\WINDOWS\CTDCRES.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:46 270336 --a------ C:\WINDOWS\System32\SFMS32.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:46 36864 --a------ C:\WINDOWS\System32\REGPLIB.EXE
2008-05-17 12:22:45 110592 --a------ C:\WINDOWS\System32\PIAPROXY.DLL <Not Verified; Creative Technology Ltd; E-mu PIA>
2008-05-17 12:22:45 159744 --a------ C:\WINDOWS\System32\OPENAL32.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:45 49152 --a------ C:\WINDOWS\System32\KILLAPPS.EXE
2008-05-17 12:22:45 20480 --a------ C:\WINDOWS\System32\ENSDEF.EXE <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:45 77824 --a------ C:\WINDOWS\System32\EAXAC3.DLL <Not Verified; Creative Labs; EAX-AC3 DLL>
2008-05-17 12:22:45 184320 --a------ C:\WINDOWS\PSCONV.EXE
2008-05-17 12:22:45 61440 --a------ C:\WINDOWS\MIDIDEF.EXE <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:44 94208 --a------ C:\WINDOWS\DEVREG.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:43 45056 --a------ C:\WINDOWS\System32\CTSPKHLP.DLL <Not Verified; Creative Technology Ltd; CtSpkHlp Dynamic Link Library>
2008-05-17 12:22:43 110592 --a------ C:\WINDOWS\System32\CTSCAL.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:43 655360 --a------ C:\WINDOWS\System32\CTSBLFX.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:42 155648 --a------ C:\WINDOWS\System32\CTOSUSER.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:42 24576 --a------ C:\WINDOWS\System32\CTHELPER.EXE <Not Verified; Creative Technology Ltd; CtHelper Application>
2008-05-17 12:22:42 36864 --a------ C:\WINDOWS\System32\CTEMUPIA.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:38 110592 --a------ C:\WINDOWS\System32\CTDPROXY.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:37 139264 --a------ C:\WINDOWS\System32\CTDCIFCE.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:37 372736 --a------ C:\WINDOWS\System32\CTDC0001.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:37 319488 --a------ C:\WINDOWS\System32\CTDC0000.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:36 495616 --a------ C:\WINDOWS\System32\CTAUDFX.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:36 106496 --a------ C:\WINDOWS\System32\CTASIO.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:36 57344 --a------ C:\WINDOWS\System32\CTAGENT.DLL <Not Verified; Creative Technology Ltd; ctagent>
2008-05-17 12:22:35 126976 --a------ C:\WINDOWS\System32\COMMONFX.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:35 53248 --a------ C:\WINDOWS\System32\AC3API.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:33 184 --a------ C:\WINDOWS\System32\e000002.dat
2008-05-17 12:22:08 77824 --a------ C:\WINDOWS\System32\ctdvda32.dll <Not Verified; Creative Technology Ltd; Creative DVD-Audio Product>
2008-05-17 12:22:08 277200 --a------ C:\WINDOWS\System32\Ctaa1.dat
2008-05-17 11:49:57 0 d-------- C:\Arquivos de programas\Creative2
2008-05-17 11:06:34 65904638 --a------ C:\regbckp2.reg
-- Find3M Report ---------------------------------------------------------------
2008-06-05 17:30:26 0 d-------- C:\Arquivos de programas\Movie Maker
2008-06-05 17:19:25 0 d-------- C:\Arquivos de programas\Windows NT
2008-05-29 21:20:27 0 d-------- C:\Arquivos de programas\DeepPaint3D
2008-05-25 23:00:43 0 d-------- C:\Arquivos de programas\Arquivos comuns
2008-05-21 19:29:38 0 d-------- C:\Arquivos de programas\GbPlugin
2008-05-17 12:22:07 0 d--h----- C:\Arquivos de programas\InstallShield Installation Information
2008-05-09 18:41:27 0 d-------- C:\Arquivos de programas\Panda Security
2008-03-24 23:17:51 2552 --a------ C:\WINDOWS\unins000.dat
2008-03-24 23:14:08 691545 --a------ C:\WINDOWS\unins000.exe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="C:\Arquivos de programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [22/05/2004 08:51]
"IntelliPoint"="C:\Arquivos de programas\Microsoft IntelliPoint\point32.exe" [15/05/2003 16:41]
"Iomega Drive Icons"="C:\Arquivos de programas\Iomega\DriveIcons\ImgIcon.exe" [13/08/2002 13:30]
"Deskup"="C:\Arquivos de programas\Iomega\DriveIcons\deskup.exe" [16/07/2002 09:55]
"Zone Labs Client"="C:\Arquivos de programas\- internet\ZoneAlarm\zlclient.exe" [17/02/2004 17:01]
"CloneCDTray"="C:\Arquivos de programas\- utilities\CloneCD\CloneCDTray.exe" [19/05/2005 10:47]
"QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [23/04/2006 22:56]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [09/07/2001 11:50]
"CTSysVol"="C:\Arquivos de programas\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [11/09/2002 11:04]
"CTDVDDet"="C:\Arquivos de programas\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [30/09/2002 01:00]
"CTHelper"="CTHELPER.EXE" [03/09/2002 15:55 C:\WINDOWS\SYSTEM32\CTHELPER.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [11/05/2000 01:00]
"avast!"="C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe" [15/05/2008 20:19]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoniqueQuickStart"="C:\Arquivos de programas\- utilities\Sonique\sqstart.exe" [02/10/2003 08:08]
"AnyDVD"="C:\Arquivos de programas\SlySoft\AnyDVD\AnyDVD.exe" [29/07/2007 08:53]
C:\Documents and Settings\Luiz M rcio\Menu Iniciar\Programas\Inicializar\
DESKTOP.INI [1/10/2002 04:33:02]
C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\
Adobe Gamma Loader.lnk - C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [9/11/2003 23:46:43]
Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [14/12/2004 04:44:06]
DESKTOP.INI [1/10/2002 04:33:02]
Digital Line Detect.lnk - C:\Arquivos de programas\Digital Line Detect\DLG.exe [18/9/2003 14:42:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Luiz Márcio^Menu Iniciar^Programas^Inicializar^PowerReg Scheduler.exe]
path=C:\Documents and Settings\Luiz Márcio\Menu Iniciar\Programas\Inicializar\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADUserMon]
C:\Arquivos de programas\Iomega\AutoDisk\ADUserMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDet]
C:\Arquivos de programas\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"c:\arquivos de programas\- internet\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sson]
C:\Documents and Settings\Luiz Márcio\Dados de aplicativos\mlri.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Tartanmcp"=3 (0x3)
"Spac32kser"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="C:\arquivos de programas\- internet\QuickTime\qttask.exe" -atboottime
-- Hosts -----------------------------------------------------------------------
127.0.0.1 images.real.com
127.0.0.1 real.com
127.0.0.1 ct5.hypercount.com
127.0.0.1 acme.bfast.com
127.0.0.1 ads.bfast.com
127.0.0.1 affiliates.bfast.com
127.0.0.1 affnet.bfast.com
127.0.0.1 airedale.bfast.com
127.0.0.1 application.bfast.com
127.0.0.1 applications.bfast.com
8026 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-06-16 22:35:28 ------------
Here is the log of Avast Antivirus :
--------------------------------------------
31/5/2008 18:24:18 Luiz Márcio 2568 Sign of "Win32:Agent-GMC [Trj]" has been found in "C:\System Volume Information\_restore{A73780C7-9903-4BC5-9A92-1848D0D7B0E9}\RP387\A0024464.scr\best_video.avi.scr\china.avi.scr\[UPX]" file.
31/5/2008 18:24:27 Luiz Márcio 2568 Sign of "Win32
31/5/2008 18:39:40 Luiz Márcio 2568 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\System Volume Information\_restore{A73780C7-9903-4BC5-9A92-1848D0D7B0E9}\RP475\A0029764.exe\allin1dfx.exe" file.
31/5/2008 18:44:49 Luiz Márcio 2568 Sign of "Win32
31/5/2008 18:45:11 Luiz Márcio 2568 Sign of "Win32:CTX" has been found in "C:\System Volume Information\_restore{A73780C7-9903-4BC5-9A92-1848D0D7B0E9}\RP477\A0029819.dll" file.
31/5/2008 18:52:57 Luiz Márcio 2568 Sign of "Win32:CTX" has been found in "C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll" file.
31/5/2008 18:55:11 Luiz Márcio 2568 Sign of "Win32:NGVCK-E" has been found in "C:\WINDOWS\SYSTEM32\pav.sig" file.
31/5/2008 22:40:38 SYSTEM 1704 Sign of "Win32:CTX" has been found in "C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll" file.
31/5/2008 22:54:29 SYSTEM 1704 Sign of "Win32:CTX" has been found in "C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll" file.
31/5/2008 22:55:05 SYSTEM 1704 Sign of "Win32:CTX" has been found in "C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll" file.
31/5/2008 22:58:27 SYSTEM 1704 Sign of "Win32:CTX" has been found in "C:\Arquivos de programas\Panda Security\ActiveScan 2.0\pskavs.dll" file.
31/5/2008 22:58:42 SYSTEM 1704 Sign of "Win32:CTX" has been found in "C:\Arquivos de programas\Panda Security\ActiveScan 2.0\pskavs.dll" file.
3/6/2008 23:49:15 SYSTEM 1676 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\system32\svchost.exe" file.
3/6/2008 23:56:19 Luiz Márcio 1280 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\SYSTEM32\SVCHOST.EXE" file.
4/6/2008 00:42:03 SYSTEM 1676 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\SYSTEM32\SVCHOST.EXE" file.
4/6/2008 00:42:27 SYSTEM 1676 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\SYSTEM32\DLLCACHE\svchost.exe" file.
4/6/2008 00:42:47 SYSTEM 1676 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\windows\system32\SET23.tmp" file.
4/6/2008 03:23:38 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\I386\SVCHOST.EXE" file.
4/6/2008 05:38:28 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\unp28195895.tmp" file.
4/6/2008 08:26:03 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\trz26.tmp" file.
4/6/2008 08:27:39 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\trz27.tmp" file.
4/6/2008 08:28:45 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\trz28.tmp" file.
4/6/2008 08:29:26 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\trz29.tmp" file.
4/6/2008 08:36:33 Luiz Márcio 2412 Sign of "Win32:Rootkit-gen [Rtk]" has been found in "C:\WINDOWS\Temp\_avast4_\trz2A.tmp" file.
--------------------------------------------
I think i used ACDSee to view the file with Win32:Agent-GMC [Trj] or Win32
ACDSee started to act strange,abruptaly finishing with an error, but not always. And once it deleted an entire folder.
I uninstalled it.
It put all in Avast quarentine, and extracted svchost.exe from de directory i386 of the Dell OS reinstalation cd .
Then, after a reboot, no drag and drop , no system restore, not opening of property sheets, the visual of the taskbar changed.
Almost no services running. RPC server not running mensage.
I fixed the RPcss section in the registry , and still no system restore and the visual of the taskbar changed.
Here is the log of Deckards System Scanner:
Deckard's System Scanner v20071014.68
Run by Luiz Márcio on 2008-06-16 22:34:16
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Unable to create WMI object; A operação foi concluída com êxito.
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 511 MiB (512 MiB recommended).
-- HijackThis (run as Luiz Márcio.exe) -----------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:35:01, on 16/6/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\Arquivos de programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Arquivos de programas\Microsoft IntelliPoint\point32.exe
C:\Arquivos de programas\Iomega\DriveIcons\ImgIcon.exe
C:\Arquivos de programas\- internet\ZoneAlarm\zlclient.exe
C:\Arquivos de programas\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Arquivos de programas\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Arquivos de programas\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Arquivos de programas\Executive Software\Diskeeper\DkService.exe
C:\ARQUIV~1\Iomega\System32\AppServices.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Arquivos de programas\Iomega\AutoDisk\ADService.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\Luiz Márcio\Desktop\dss.exe
C:\ARQUIV~1\TRENDM~1\HIJACK~1\Luiz Márcio.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com/intl/la/brazil/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com/intl/la/brazil/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com/intl/la/brazil/index.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:12080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~2\SDHelper.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\- utilities\Free Download Manager\iefdmcks.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Arquivos de programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Arquivos de programas\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Arquivos de programas\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Arquivos de programas\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [Zone Labs Client] C:\Arquivos de programas\- internet\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Arquivos de programas\- utilities\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Arquivos de programas\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Arquivos de programas\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [SoniqueQuickStart] C:\Arquivos de programas\- utilities\Sonique\sqstart.exe -nostick
O4 - HKCU\..\Run: [AnyDVD] "C:\Arquivos de programas\SlySoft\AnyDVD\AnyDVD.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-2237029002-2704639424-2437969446-1005\..\Run: [SoniqueQuickStart] C:\Arquivos de programas\- utilities\Sonique\sqstart.exe -nostick (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Arquivos de programas\- utilities\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Arquivos de programas\- utilities\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Arquivos de programas\- utilities\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~2\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARQUIV~1\SPYBOT~2\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\MSMSGS.EXE
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Arquivos de programas\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\ARQUIV~1\Iomega\System32\AppServices.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Arquivos de programas\Intel\NCS\Sync\NetSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Arquivos de programas\Iomega\AutoDisk\ADService.exe
--
End of file - 8834 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
3 ac97intc (Intel(r) 82801 Audio Driver Install Service (WDM)) - c:\windows\system32\drivers\ac97intc.sys <Not Verified; Intel Corporation; Intel(r) Integrated Controller Hub Audio Driver>
3 ati2mtaa - c:\windows\system32\drivers\ati2mtaa.sys <Not Verified; ATI Technologies Inc.; ATI Rage 128 Family>
3 C-Dilla - c:\windows\system32\drivers\cdant.sys <Not Verified; Macrovision; Licence Management System>
4 cbidf - c:\windows\system32\drivers\cbidf2k.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2 CdaC15BA - c:\windows\system32\drivers\cdac15ba.sys <Not Verified; Macrovision Europe Ltd; Security Windows NT>
4 dac2w2k - c:\windows\system32\drivers\dac2w2k.sys <Not Verified; Mylex Corporation; Mylex Disk Array Controller Driver>
3 EL90XBC (3Com EtherLink XL 90XB/C Adapter Driver) - c:\windows\system32\drivers\el90xbc5.sys <Not Verified; 3Com Corporation; 3Com EtherLink PCI>
3 ElbyCDFL - c:\windows\system32\drivers\elbycdfl.sys <Not Verified; SlySoft, Inc.; CloneCD>
3 emupia (E-mu Plug-in Architecture Driver) - c:\windows\system32\drivers\emupia2k.sys <Not Verified; Creative Technology Ltd; E-mu Plug-In Architecture>
3 HCF_MSFT - c:\windows\system32\drivers\hcf_msft.sys <Not Verified; Conexant; Modem>
3 HSFHWBS2 - c:\windows\system32\drivers\hsfhwbs2.sys <Not Verified; Conexant Systems; SoftK56>
3 HSF_DP - c:\windows\system32\drivers\hsf_dp.sys <Not Verified; Conexant Systems; SoftK56>
3 i81x - c:\windows\system32\drivers\i81xnt5.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimFP0 - c:\windows\system32\drivers\wadv01nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimFP1 - c:\windows\system32\drivers\wadv02nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimFP2 - c:\windows\system32\drivers\wadv05nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimFP3 - c:\windows\system32\drivers\wsiintxx.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimFP4 - c:\windows\system32\drivers\wvchntxx.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimTV0 - c:\windows\system32\drivers\watv01nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimTV1 - c:\windows\system32\drivers\watv02nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimTV2 - c:\windows\system32\drivers\watv03nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimTV3 - c:\windows\system32\drivers\watv04nt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
3 iAimTV4 - c:\windows\system32\drivers\wch7xxnt.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT(R)>
0 iomdisk (Iomega Devices Disk Filter Services) - c:\windows\system32\drivers\iomdisk.sys <Not Verified; Iomega Corporation; Microsoft(R) Windows NT(R) Operating System>
2 mdmxsdk - c:\windows\system32\drivers\mdmxsdk.sys <Not Verified; Conexant; Diagnostic Interface>
3 MODEMCSA (Dispositivo de filtro de fluxo unimodem) - c:\windows\system32\drivers\modemcsa.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
0 ppa3 (Iomega Parallel Port Legacy Filter Driver) - c:\windows\system32\drivers\ppa3.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
3 winachsf - c:\windows\system32\drivers\hsf_cnxt.sys <Not Verified; Conexant Systems; SoftK56>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
2 aawservice (Ad-Aware 2007 Service) - c:\arquivos de programas\lavasoft\ad-aware 2007\aawservice.exe
2 C-DillaCdaC11BA - c:\windows\system32\drivers\cdac11ba.exe <Not Verified; Macrovision; SafeCast Windows NT>
2 C-DillaSrv - c:\windows\system32\drivers\cdantsrv.exe <Not Verified; C-Dilla Ltd; CD-Secure/CD-Compress Windows NT>
2 Diskeeper - c:\arquivos de programas\executive software\diskeeper\dkservice.exe <Not Verified; Executive Software International, Inc.; Diskeeper (TM) Disk Defragmenter>
4 Iomega Activity Disk2 - c:\windows\system32
2 Iomega App Services - c:\arquivos de programas\iomega\system32\appservices.exe
2 _IOMEGA_ACTIVE_DISK_SERVICE_ (Iomega Active Disk) - c:\arquivos de programas\iomega\autodisk\adservice.exe
-- Device Manager: Disabled ----------------------------------------------------
Unable to create WMI object.
-- Files created between 2008-05-16 and 2008-06-16 -----------------------------
2008-06-16 22:25:44 0 d-------- C:\Arquivos de programas\Trend Micro
2008-06-16 18:17:15 0 d-------- C:\WINDOWS\tmp
2008-06-12 01:24:52 63677956 --a------ C:\regbckp3.reg
2008-06-05 17:14:37 0 d-------- C:\WINDOWS\LastGood.Tmp
2008-06-05 15:18:15 744853 --a------ C:\PAVARK.exe
2008-06-04 09:56:19 12800 --a------ C:\WINDOWS\System32\svchost.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-04 09:55:20 12800 --a------ C:\svchost.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-29 23:53:56 0 d-------- C:\Arquivos de programas\Alwil Software
2008-05-17 18:25:35 288 --a------ C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2008-05-17 18:25:35 288 --a------ C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2008-05-17 12:24:08 53552 -----n--- C:\WINDOWS\CTCCW.DLL <Not Verified; Creative® Technology Ltd.; Custom Control for Windows>
2008-05-17 12:24:05 26768 -----n--- C:\WINDOWS\System32\CTL3D.DLL <Not Verified; Microsoft Corporation; 3D Windows Control>
2008-05-17 12:24:03 1048576 -----n--- C:\WINDOWS\System32\SFMAN.DAT
2008-05-17 12:24:01 0 d-------- C:\WINDOWS\System32\Defaults
2008-05-17 12:23:23 134272 --a------ C:\WINDOWS\System32\drivers\portcls.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 12:23:23 57856 --a------ C:\WINDOWS\System32\drivers\drmk.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 12:22:53 36864 --a------ C:\WINDOWS\System32\sfman32.dll <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:53 135728 --a------ C:\WINDOWS\System32\drivers\hap16v2k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:52 816576 --a------ C:\WINDOWS\System32\drivers\ha10kx2k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:52 115936 --a------ C:\WINDOWS\System32\drivers\emupia2k.sys <Not Verified; Creative Technology Ltd; E-mu Plug-In Architecture>
2008-05-17 12:22:51 134032 --a------ C:\WINDOWS\System32\drivers\ctsfm2k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:51 6144 --a------ C:\WINDOWS\System32\drivers\ctprxy2k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:51 183703 --a------ C:\WINDOWS\System32\ctstatic.dat
2008-05-17 12:22:50 298384 --a------ C:\WINDOWS\System32\drivers\ctdvda2k.sys
2008-05-17 12:22:50 189490 --a------ C:\WINDOWS\System32\ctdlang.dat
2008-05-17 12:22:50 53674 --a------ C:\WINDOWS\System32\ctdaught.dat
2008-05-17 12:22:50 114972 --a------ C:\WINDOWS\System32\CTBASICW.DAT
2008-05-17 12:22:50 142968 --a------ C:\WINDOWS\System32\ctbas2w.dat
2008-05-17 12:22:49 493568 --a------ C:\WINDOWS\System32\drivers\ctaud2k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:49 186068 --a------ C:\WINDOWS\System32\drivers\ctac32k.sys <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:49 65536 --a------ C:\WINDOWS\System32\a3d.dll <Not Verified; ; a3dx5>
2008-05-17 12:22:47 49152 --a------ C:\WINDOWS\CTDCRES.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:46 270336 --a------ C:\WINDOWS\System32\SFMS32.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:46 36864 --a------ C:\WINDOWS\System32\REGPLIB.EXE
2008-05-17 12:22:45 110592 --a------ C:\WINDOWS\System32\PIAPROXY.DLL <Not Verified; Creative Technology Ltd; E-mu PIA>
2008-05-17 12:22:45 159744 --a------ C:\WINDOWS\System32\OPENAL32.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:45 49152 --a------ C:\WINDOWS\System32\KILLAPPS.EXE
2008-05-17 12:22:45 20480 --a------ C:\WINDOWS\System32\ENSDEF.EXE <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:45 77824 --a------ C:\WINDOWS\System32\EAXAC3.DLL <Not Verified; Creative Labs; EAX-AC3 DLL>
2008-05-17 12:22:45 184320 --a------ C:\WINDOWS\PSCONV.EXE
2008-05-17 12:22:45 61440 --a------ C:\WINDOWS\MIDIDEF.EXE <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:44 94208 --a------ C:\WINDOWS\DEVREG.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:43 45056 --a------ C:\WINDOWS\System32\CTSPKHLP.DLL <Not Verified; Creative Technology Ltd; CtSpkHlp Dynamic Link Library>
2008-05-17 12:22:43 110592 --a------ C:\WINDOWS\System32\CTSCAL.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:43 655360 --a------ C:\WINDOWS\System32\CTSBLFX.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:42 155648 --a------ C:\WINDOWS\System32\CTOSUSER.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:42 24576 --a------ C:\WINDOWS\System32\CTHELPER.EXE <Not Verified; Creative Technology Ltd; CtHelper Application>
2008-05-17 12:22:42 36864 --a------ C:\WINDOWS\System32\CTEMUPIA.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:38 110592 --a------ C:\WINDOWS\System32\CTDPROXY.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:37 139264 --a------ C:\WINDOWS\System32\CTDCIFCE.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:37 372736 --a------ C:\WINDOWS\System32\CTDC0001.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:37 319488 --a------ C:\WINDOWS\System32\CTDC0000.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:36 495616 --a------ C:\WINDOWS\System32\CTAUDFX.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:36 106496 --a------ C:\WINDOWS\System32\CTASIO.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:36 57344 --a------ C:\WINDOWS\System32\CTAGENT.DLL <Not Verified; Creative Technology Ltd; ctagent>
2008-05-17 12:22:35 126976 --a------ C:\WINDOWS\System32\COMMONFX.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:35 53248 --a------ C:\WINDOWS\System32\AC3API.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-05-17 12:22:33 184 --a------ C:\WINDOWS\System32\e000002.dat
2008-05-17 12:22:08 77824 --a------ C:\WINDOWS\System32\ctdvda32.dll <Not Verified; Creative Technology Ltd; Creative DVD-Audio Product>
2008-05-17 12:22:08 277200 --a------ C:\WINDOWS\System32\Ctaa1.dat
2008-05-17 11:49:57 0 d-------- C:\Arquivos de programas\Creative2
2008-05-17 11:06:34 65904638 --a------ C:\regbckp2.reg
-- Find3M Report ---------------------------------------------------------------
2008-06-05 17:30:26 0 d-------- C:\Arquivos de programas\Movie Maker
2008-06-05 17:19:25 0 d-------- C:\Arquivos de programas\Windows NT
2008-05-29 21:20:27 0 d-------- C:\Arquivos de programas\DeepPaint3D
2008-05-25 23:00:43 0 d-------- C:\Arquivos de programas\Arquivos comuns
2008-05-21 19:29:38 0 d-------- C:\Arquivos de programas\GbPlugin
2008-05-17 12:22:07 0 d--h----- C:\Arquivos de programas\InstallShield Installation Information
2008-05-09 18:41:27 0 d-------- C:\Arquivos de programas\Panda Security
2008-03-24 23:17:51 2552 --a------ C:\WINDOWS\unins000.dat
2008-03-24 23:14:08 691545 --a------ C:\WINDOWS\unins000.exe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="C:\Arquivos de programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [22/05/2004 08:51]
"IntelliPoint"="C:\Arquivos de programas\Microsoft IntelliPoint\point32.exe" [15/05/2003 16:41]
"Iomega Drive Icons"="C:\Arquivos de programas\Iomega\DriveIcons\ImgIcon.exe" [13/08/2002 13:30]
"Deskup"="C:\Arquivos de programas\Iomega\DriveIcons\deskup.exe" [16/07/2002 09:55]
"Zone Labs Client"="C:\Arquivos de programas\- internet\ZoneAlarm\zlclient.exe" [17/02/2004 17:01]
"CloneCDTray"="C:\Arquivos de programas\- utilities\CloneCD\CloneCDTray.exe" [19/05/2005 10:47]
"QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [23/04/2006 22:56]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [09/07/2001 11:50]
"CTSysVol"="C:\Arquivos de programas\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [11/09/2002 11:04]
"CTDVDDet"="C:\Arquivos de programas\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [30/09/2002 01:00]
"CTHelper"="CTHELPER.EXE" [03/09/2002 15:55 C:\WINDOWS\SYSTEM32\CTHELPER.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [11/05/2000 01:00]
"avast!"="C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe" [15/05/2008 20:19]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoniqueQuickStart"="C:\Arquivos de programas\- utilities\Sonique\sqstart.exe" [02/10/2003 08:08]
"AnyDVD"="C:\Arquivos de programas\SlySoft\AnyDVD\AnyDVD.exe" [29/07/2007 08:53]
C:\Documents and Settings\Luiz M rcio\Menu Iniciar\Programas\Inicializar\
DESKTOP.INI [1/10/2002 04:33:02]
C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\
Adobe Gamma Loader.lnk - C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [9/11/2003 23:46:43]
Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe [14/12/2004 04:44:06]
DESKTOP.INI [1/10/2002 04:33:02]
Digital Line Detect.lnk - C:\Arquivos de programas\Digital Line Detect\DLG.exe [18/9/2003 14:42:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Luiz Márcio^Menu Iniciar^Programas^Inicializar^PowerReg Scheduler.exe]
path=C:\Documents and Settings\Luiz Márcio\Menu Iniciar\Programas\Inicializar\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADUserMon]
C:\Arquivos de programas\Iomega\AutoDisk\ADUserMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDet]
C:\Arquivos de programas\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"c:\arquivos de programas\- internet\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sson]
C:\Documents and Settings\Luiz Márcio\Dados de aplicativos\mlri.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Tartanmcp"=3 (0x3)
"Spac32kser"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="C:\arquivos de programas\- internet\QuickTime\qttask.exe" -atboottime
-- Hosts -----------------------------------------------------------------------
127.0.0.1 images.real.com
127.0.0.1 real.com
127.0.0.1 ct5.hypercount.com
127.0.0.1 acme.bfast.com
127.0.0.1 ads.bfast.com
127.0.0.1 affiliates.bfast.com
127.0.0.1 affnet.bfast.com
127.0.0.1 airedale.bfast.com
127.0.0.1 application.bfast.com
127.0.0.1 applications.bfast.com
8026 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-06-16 22:35:28 ------------
Attachments
-
29.1 KB Views: 22