Beruflich Dokumente
Kultur Dokumente
2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1983.1223 [GMT -3:
00]
Executando de: c:\documents and settings\sula.vasques\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *Disabled/Updated* {918A2B0B-2C60-4016-A4AB-E868
DEABF7F0}
.
ATENAO - ESTA MAQUINA NAO TEM O CONSOLE DE RECUPERAO INSTALADO !!
.
[i] ADS - system32: deleted 2 bytes in 1 streams. [/i]
[i] ADS - drivers: deleted 208 bytes in 1 streams. [/i]
.
((((((((((((((((((((((((((((((((((((( Outras Excluses )))))))))))))))))))))))
))))))))))))))))))))))))))))
.
.
C:\JAMA
c:\jama\CRAFT\DeSKtOp.InI
c:\jama\CRAFT\pop.exe
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2011-09-18 to 2011-10-18 )))))
)))))))))))))))))))))))
.
.
2011-10-17 14:05 . 2011-10-17 14:05
-------d-----wc:\docum
ents and settings\All Users\Dados de aplicativos\Hewlett-Packard
2011-10-17 14:04 . 2008-01-16 21:46
117248 ----a-wc:\windows\syste
m32\hpzpnp.dll
2011-10-17 14:04 . 2008-01-16 21:45
241664 ----a-wc:\windows\syste
m32\Spool\prtprocs\w32x86\hpzpp5k4.DLL
2011-10-17 14:04 . 2007-11-21 18:44
348160 ----a-rc:\windows\syste
m32\hpbicoin.dll
2011-10-17 13:15 . 2011-10-17 13:15
-------d-----wc:\docum
ents and settings\Administrador\Dados de aplicativos\Softland
2011-10-11 14:14 . 2011-10-11 14:14
-------d-----wc:\docum
ents and settings\genardo.oliveira
2011-09-28 11:53 . 2011-10-13 15:47
-------d-----wc:\docum
ents and settings\sandro.foro
2011-09-26 11:53 . 2011-09-26 11:54
-------d-----wc:\docum
ents and settings\wladimir.cardoso
2011-09-20 18:39 . 2011-09-20 18:40
-------d-----wc:\docum
ents and settings\sula.vasques\Configuraes locais\Dados de aplicativos\WMTools Dow
nloaded Files
.
.
.
((((((((((((((((((((((((((((((((((((( Relatrio Find3M )))))))))))))))))))))))
)))))))))))))))))))))))))))))
.
2011-10-17 12:39 . 2011-07-08 11:17
414368 ----a-wc:\windows\syste
m32\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))
)))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legtimas por padro no so apresentadas.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\arquivos de programas\DeviceVM\Browser Configuration Utility\BCU.exe"
[2009-08-04 346320]
"nwiz"="nwiz.exe" [2006-10-31 1622016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"McAfeeUpdaterUI"="c:\arquivos de programas\McAfee\Common Framework\udaterui.exe
" [2009-01-16 136512]
"ShStatEXE"="c:\arquivos de programas\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2
009-04-29 124240]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-31 86016]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416]
"SkyTel"="SkyTel.EXE" [2007-06-15 1826816]
"googletalk"="c:\arquivos de programas\Google\Google Talk\googletalk.exe" [200701-01 3735552]
"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre1.6.0\bin\jusched.exe" [2
011-06-16 77824]
"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\
Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
" [2009-09-04 935288]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\
Windows Search.lnk - c:\arquivos de programas\Windows Desktop Search\WindowsSear
ch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExec
uteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desk
top Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify
\ GbPluginCef]
2011-04-18 18:12
496072 ------wc:\arquivos de programas\GbPlugi
n\gbiehcef.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngi
neService]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Authoriz
edApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Arquivos de programas\\Google\\Google Earth\\client\\googleearth.exe"=
.
R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [26/7/2011 11:06 4
6664]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\arquivos de programas\ASTRA32\astra3
2.sys [22/2/2007 11:28 30864]
R2 BCUService;Browser Configuration Utility Service;c:\arquivos de programas\Dev
iceVM\Browser Configuration Utility\BCUService.exe [10/5/2011 11:33 219360]
R2 FortiSslvpnDaemon;FortiClient SSL VPN;c:\windows\system32\FortiSSLVPNdaemon.e