Hello RatHat,
Thanks a lot for your willingness to help me. Timely replies will be a problem for me due to work constraints, but I'm ready to follow every step to kill the bloody [bleep] bagle.
I did try to install SDFix.exe a couple of times but it only gave me 'Some installations files are corrupt' message at the end. At least it enabled me to reboot the computer in safe mode, which I wasnt able to before, but it didnt generate the RunThis.bat file. Text files are all the SDFix folder and subfolders contain. (See image attached). So i got no log from SDFix.
But here's DSS reports.
Deckard's System Scanner v20071014.68
Run by Marcos on 2008-05-22 19:53:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 1 Restore Point(s) --
1: 2008-05-22 22:53:38 UTC - RP210 - Deckard's System Scanner Restore Point
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Marcos.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:54, on 2008-05-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\KILLWIN\System32\smss.exe
C:\KILLWIN\system32\csrss.exe
C:\KILLWIN\system32\winlogon.exe
C:\KILLWIN\system32\services.exe
C:\KILLWIN\system32\lsass.exe
C:\KILLWIN\system32\svchost.exe
C:\KILLWIN\system32\svchost.exe
C:\KILLWIN\System32\svchost.exe
C:\KILLWIN\system32\svchost.exe
C:\KILLWIN\system32\svchost.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\KILLWIN\system32\spoolsv.exe
C:\KILLWIN\Explorer.EXE
C:\Arquivos de programas\Lexmark 1400 Series\lxdjamon.exe
C:\Arquivos de programas\Winamp\winampa.exe
C:\KILLWIN\system32\lxdjcoms.exe
C:\KILLWIN\system32\wdfmgr.exe
C:\Arquivos de programas\QuickTime\qttask.exe
C:\Arquivos de programas\JavaCore\JavaCore.exe
C:\KILLWIN\system32\ctfmon.exe
C:\KILLWIN\system32\UAService7.exe
C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\WinTouch\WinTouch.exe
C:\Arquivos de programas\Svconr\Svconr.exe
C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\SpeedRunner\SpeedRunner.exe
C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Microsoft\Windows\hvasuo.exe
C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Microsoft\Windows\tncqdc.exe
C:\Arquivos de programas\AdVantage\AdVantage.exe
C:\Arquivos de programas\Stardock\ObjectDock\ObjectDock.exe
C:\KILLWIN\System32\alg.exe
C:\KILLWIN\system32\rVCPj3C2.exe
C:\KILLWIN\system32\V752Nw5c.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\Documents and Settings\Marcos.CASA\Desktop\dss.exe
C:\KILLWIN\system32\wbem\wmiprvse.exe
C:\ARQUIV~1\TRENDM~1\HIJACK~1\Marcos.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &
http://home.microsof...ss/allinone.aspR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.com.br/R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Barra de ferramentas - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Arquivos de programas\Lexmark Toolbar\toolband.dll
O2 - BHO: BHO Class - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Arquivos de programas\Spcron\Spcron.dll
O2 - BHO: ssh2 Class - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O3 - Toolbar: Lexmark Barra de ferramentas - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Arquivos de programas\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [lxdjamon] "C:\Arquivos de programas\Lexmark 1400 Series\lxdjamon.exe"
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp\winampa.exe"
O4 - HKLM\..\Run: [UDC Integration] C:\ARQUIV~1\UNIVER~1\getstart.exe "C:\Arquivos de programas\Universal Document Converter" -silent -default -noshowmanual
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Setup] C:\Program Files\Common Files\setup.exe -cleaning
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKCU\..\Run: [JavaCore] C:\Arquivos de programas\\JavaCore\\JavaCore.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\KILLWIN\system32\ctfmon.exe
O4 - HKCU\..\Run: [WinTouch] C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\WinTouch\WinTouch.exe
O4 - HKCU\..\Run: [Twain] C:\Arquivos de programas\Twain\Twain.exe
O4 - HKCU\..\Run: [Svconr] C:\Arquivos de programas\Svconr\Svconr.exe
O4 - HKCU\..\Run: [Steam] "C:\Arquivos de programas\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [SpeedRunner] C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\SpeedRunner\SpeedRunner.exe
O4 - HKCU\..\Run: [Skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Microsoft\Windows\hvasuo.exe
O4 - HKCU\..\Run: [SfKg6w] C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Microsoft\Windows\tncqdc.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [AdVantage] "C:\Arquivos de programas\AdVantage\AdVantage.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\KILLWIN\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\KILLWIN\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\KILLWIN\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\KILLWIN\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Stardock ObjectDock.lnk = C:\Arquivos de programas\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: PersonalBrain 4.lnk = C:\Arquivos de programas\PersonalBrain\PersonalBrainS.exe
O4 - Global Startup: PalTalk.lnk = C:\Arquivos de programas\Paltalk Messenger\paltalk.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Arquivos de programas\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Arquivos de programas\Arquivos comuns\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Arquivos de programas\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Arquivos de programas\Arquivos comuns\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Arquivos de programas\Arquivos comuns\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&
http://home.microsof...ss/allinone.aspO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) -
http://support.f-sec...m/ols/fscax.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://fpdownload.m...ash/swflash.cabO16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) -
https://imagem.caixa...cab/gbpdist.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll
O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll
O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATI Smart - Unknown owner - C:\KILLWIN\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: lxdjCATSCustConnectService - Lexmark International, Inc. - C:\KILLWIN\System32\spool\DRIVERS\W32X86\3\\lxdjserv.exe
O23 - Service: lxdj_device - - C:\KILLWIN\system32\lxdjcoms.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\KILLWIN\system32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\KILLWIN\system32\UAService7.exe
--
End of file - 10581 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
All drivers whitelisted.
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 UserAccess7 (SecuROM User Access Service (V7)) - c:\killwin\system32\uaservice7.exe
0
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Modem PCI
Device ID: PCI\VEN_2003&DEV_8800&SUBSYS_28001801&REV_02\4&11D7AD53&0&4040
Manufacturer:
Name: Modem PCI
PNP Device ID: PCI\VEN_2003&DEV_8800&SUBSYS_28001801&REV_02\4&11D7AD53&0&4040
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-05-22 19:09:02 300 --a------ C:\KILLWIN\Tasks\AppleSoftwareUpdate.job
2008-05-22 19:00:06 350 --a------ C:\KILLWIN\Tasks\At68.job
2008-05-22 19:00:06 350 --a------ C:\KILLWIN\Tasks\At44.job
2008-05-22 19:00:02 350 --a------ C:\KILLWIN\Tasks\At20.job
2008-05-22 18:00:04 350 --a------ C:\KILLWIN\Tasks\At19.job
2008-05-22 18:00:02 350 --a------ C:\KILLWIN\Tasks\At67.job
2008-05-22 18:00:02 350 --a------ C:\KILLWIN\Tasks\At43.job
2008-05-22 17:23:18 350 --a------ C:\KILLWIN\Tasks\At61.job
2008-05-22 17:23:18 350 --a------ C:\KILLWIN\Tasks\At37.job
2008-05-22 12:00:02 350 --a------ C:\KILLWIN\Tasks\At13.job
2008-05-22 11:48:16 350 --a------ C:\KILLWIN\Tasks\At58.job
2008-05-22 11:48:14 350 --a------ C:\KILLWIN\Tasks\At34.job
2008-05-22 11:00:20 350 --a------ C:\KILLWIN\Tasks\At12.job
2008-05-22 11:00:16 350 --a------ C:\KILLWIN\Tasks\At60.job
2008-05-22 11:00:10 350 --a------ C:\KILLWIN\Tasks\At36.job
2008-05-22 10:00:08 350 --a------ C:\KILLWIN\Tasks\At59.job
2008-05-22 10:00:08 350 --a------ C:\KILLWIN\Tasks\At35.job
2008-05-22 10:00:06 350 --a------ C:\KILLWIN\Tasks\At11.job
2008-05-22 09:00:04 350 --a------ C:\KILLWIN\Tasks\At10.job
2008-05-22 08:00:02 350 --a------ C:\KILLWIN\Tasks\At51.job
2008-05-22 08:00:02 350 --a------ C:\KILLWIN\Tasks\At27.job
2008-05-22 07:00:06 350 --a------ C:\KILLWIN\Tasks\At56.job
2008-05-22 07:00:06 350 --a------ C:\KILLWIN\Tasks\At32.job
2008-05-22 07:00:02 350 --a------ C:\KILLWIN\Tasks\At8.job
2008-05-22 06:00:06 350 --a------ C:\KILLWIN\Tasks\At55.job
2008-05-22 06:00:06 350 --a------ C:\KILLWIN\Tasks\At31.job
2008-05-22 06:00:02 350 --a------ C:\KILLWIN\Tasks\At7.job
2008-05-22 05:00:06 350 --a------ C:\KILLWIN\Tasks\At54.job
2008-05-22 05:00:06 350 --a------ C:\KILLWIN\Tasks\At30.job
2008-05-22 05:00:02 350 --a------ C:\KILLWIN\Tasks\At6.job
2008-05-22 04:00:06 350 --a------ C:\KILLWIN\Tasks\At53.job
2008-05-22 04:00:06 350 --a------ C:\KILLWIN\Tasks\At29.job
2008-05-22 04:00:02 350 --a------ C:\KILLWIN\Tasks\At5.job
2008-05-22 03:00:06 350 --a------ C:\KILLWIN\Tasks\At52.job
2008-05-22 03:00:06 350 --a------ C:\KILLWIN\Tasks\At28.job
2008-05-22 03:00:04 350 --a------ C:\KILLWIN\Tasks\At4.job
2008-05-22 02:00:04 350 --a------ C:\KILLWIN\Tasks\At3.job
2008-05-22 01:17:12 350 --a------ C:\KILLWIN\Tasks\At69.job
2008-05-22 01:17:12 350 --a------ C:\KILLWIN\Tasks\At45.job
2008-05-22 01:00:06 350 --a------ C:\KILLWIN\Tasks\At50.job
2008-05-22 01:00:06 350 --a------ C:\KILLWIN\Tasks\At26.job
2008-05-22 01:00:04 350 --a------ C:\KILLWIN\Tasks\At2.job
2008-05-22 00:11:06 350 --a------ C:\KILLWIN\Tasks\At25.job
2008-05-22 00:09:08 350 --a------ C:\KILLWIN\Tasks\At49.job
2008-05-22 00:00:04 350 --a------ C:\KILLWIN\Tasks\At1.job
2008-05-21 23:00:06 350 --a------ C:\KILLWIN\Tasks\At72.job
2008-05-21 23:00:06 350 --a------ C:\KILLWIN\Tasks\At48.job
2008-05-21 23:00:04 350 --a------ C:\KILLWIN\Tasks\At24.job
2008-05-21 22:00:06 350 --a------ C:\KILLWIN\Tasks\At71.job
2008-05-21 22:00:06 350 --a------ C:\KILLWIN\Tasks\At47.job
2008-05-21 22:00:02 350 --a------ C:\KILLWIN\Tasks\At23.job
2008-05-21 21:00:06 350 --a------ C:\KILLWIN\Tasks\At70.job
2008-05-21 21:00:06 350 --a------ C:\KILLWIN\Tasks\At46.job
2008-05-21 21:00:02 350 --a------ C:\KILLWIN\Tasks\At22.job
2008-05-21 20:00:02 350 --a------ C:\KILLWIN\Tasks\At21.job
2008-05-21 19:55:08 350 --a------ C:\KILLWIN\Tasks\At64.job
2008-05-21 19:55:06 350 --a------ C:\KILLWIN\Tasks\At40.job
2008-05-21 15:00:02 350 --a------ C:\KILLWIN\Tasks\At16.job
2008-05-20 08:15:02 350 --a------ C:\KILLWIN\Tasks\At57.job
2008-05-20 08:15:00 350 --a------ C:\KILLWIN\Tasks\At33.job
2008-05-20 08:00:04 350 --a------ C:\KILLWIN\Tasks\At9.job
2008-05-20 07:54:36 350 --a------ C:\KILLWIN\Tasks\At65.job
2008-05-20 07:54:34 350 --a------ C:\KILLWIN\Tasks\At41.job
2008-05-19 17:00:06 350 --a------ C:\KILLWIN\Tasks\At66.job
2008-05-19 17:00:06 350 --a------ C:\KILLWIN\Tasks\At42.job
2008-05-19 17:00:04 350 --a------ C:\KILLWIN\Tasks\At18.job
2008-05-19 16:00:04 350 --a------ C:\KILLWIN\Tasks\At17.job
2008-05-19 15:51:52 350 --a------ C:\KILLWIN\Tasks\At63.job
2008-05-19 15:51:52 350 --a------ C:\KILLWIN\Tasks\At39.job
2008-05-19 14:00:06 350 --a------ C:\KILLWIN\Tasks\At15.job
2008-05-16 17:15:02 394 --a------ C:\KILLWIN\Tasks\1-Click Maintenance.job
2008-05-14 23:05:20 350 --a------ C:\KILLWIN\Tasks\At62.job
2008-05-14 23:05:20 350 --a------ C:\KILLWIN\Tasks\At38.job
2008-05-14 13:00:04 350 --a------ C:\KILLWIN\Tasks\At14.job
-- Files created between 2008-04-22 and 2008-05-22 -----------------------------
2008-05-22 07:57:35 0 d-------- C:\Arquivos de programas\Trend Micro
2008-05-22 01:14:50 0 d--hs---- C:\FOUND.156
2008-05-21 20:09:03 0 d-------- C:\Arquivos de programas\Yahoo!
2008-05-20 11:25:09 0 d-------- C:\fsaua.data
2008-05-20 11:06:53 0 d-------- C:\Combo-Fix
2008-05-20 11:01:34 0 d--hs---- C:\FOUND.155
2008-05-20 10:55:10 68096 --a------ C:\KILLWIN\zip.exe
2008-05-20 10:55:10 49152 --a------ C:\KILLWIN\VFind.exe
2008-05-20 10:55:10 212480 --a------ C:\KILLWIN\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-05-20 10:55:10 136704 --a------ C:\KILLWIN\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-05-20 10:55:10 161792 --a------ C:\KILLWIN\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-05-20 10:55:10 98816 --a------ C:\KILLWIN\sed.exe
2008-05-20 10:55:10 80412 --a------ C:\KILLWIN\grep.exe
2008-05-20 10:55:10 89504 --a------ C:\KILLWIN\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-05-20 10:38:43 0 d-------- C:\Arquivos de programas\Participatory Culture Foundation
2008-05-20 10:02:31 0 d-------- C:\Arquivos de programas\PersonalBrain
2008-05-20 09:48:43 0 d-------- C:\My Brains
2008-05-20 09:47:53 0 d-------- C:\Arquivos de programas\TheBrain
2008-05-20 08:36:36 0 d-------- C:\KILLWIN\system32\QuickTime
2008-05-20 08:25:36 5632 --a------ C:\KILLWIN\system32\udcpm.dll <Not Verified; fCoder Group, Inc.; Universal Document Converter>
2008-05-20 08:25:34 0 d-------- C:\UDC Snapshots
2008-05-20 08:25:33 0 d-------- C:\Arquivos de programas\Universal Document Converter
2008-05-20 08:05:26 0 d-------- C:\lotuspro
2008-05-20 07:57:15 0 d-------- C:\Arquivos de programas\Arquivos comuns\TechSmith Shared
2008-05-20 07:57:12 0 d-------- C:\Arquivos de programas\TechSmith
2008-05-19 15:51:32 0 d--hs---- C:\FOUND.154
2008-05-19 13:39:38 10240 --a------ C:\KILLWIN\system32\MVut14n.dll <Not Verified; Microsoft Corporation; Microsoft Media View>
2008-05-19 13:39:38 50688 --a------ C:\KILLWIN\system32\MVtl14n.dll <Not Verified; Microsoft Corporation; Microsoft Media View>
2008-05-19 13:39:38 51200 --a------ C:\KILLWIN\system32\MVsr14n.dll <Not Verified; Microsoft Corporation; Microsoft Media View>
2008-05-19 13:39:38 32768 --a------ C:\KILLWIN\system32\MVmg14n.dll <Not Verified; Microsoft Corporation; Microsoft Media View>
2008-05-19 13:39:38 73728 --a------ C:\KILLWIN\system32\MVmc14n.dll <Not Verified; Microsoft Corporation; Microsoft Media View>
2008-05-19 13:39:38 68608 --a------ C:\KILLWIN\system32\MVix14n.dll <Not Verified; Microsoft Corporation; Microsoft Media View>
2008-05-19 13:39:38 56320 --a------ C:\KILLWIN\system32\MVfs14n.dll <Not Verified; Microsoft Corporation; Microsoft Media View>
2008-05-19 13:39:38 112128 --a------ C:\KILLWIN\system32\MVcl14n.dll <Not Verified; Microsoft Corporation; Microsoft Media View>
2008-05-19 13:39:38 25600 --a------ C:\KILLWIN\system32\MVbk14n.dll <Not Verified; Microsoft Corporation; Microsoft Media View>
2008-05-19 13:39:38 0 d-------- C:\KILLWIN\Epa
2008-05-19 05:06:32 0 d--hs---- C:\FOUND.153
2008-05-18 23:05:26 0 d-------- C:\Arquivos de programas\Alwil Software
2008-05-18 23:04:09 0 d-------- C:\Arquivos de programas\RootKit Hook Analyzer
2008-05-18 22:56:17 3584 --a------ C:\KILLWIN\system32\wmfhotfix.dll
2008-05-18 22:56:17 0 d-------- C:\Arquivos de programas\WindowsMetafileFix
2008-05-18 20:46:21 0 d-------- C:\Arquivos de programas\CCleaner
2008-05-18 19:35:48 0 d-------- C:\Arquivos de programas\Arquivos comuns\Panda Software
2008-05-17 20:41:10 0 d-------- C:\KILLWIN\system32\Kaspersky Lab
2008-05-16 23:15:56 0 d--hs---- C:\FOUND.152
2008-05-15 13:56:42 0 d--hs---- C:\FOUND.151
2008-05-14 23:04:56 0 d--hs---- C:\FOUND.150
2008-05-13 16:43:02 126976 --a------ C:\KILLWIN\system32\UAService7.exe
2008-05-13 05:12:51 46594 --a------ C:\KILLWIN\system32\V752Nw5c.exe
2008-05-13 05:12:50 53248 --a------ C:\KILLWIN\system32\oml.dll
2008-05-13 04:21:13 0 d-------- C:\Arquivos de programas\Metastock Expresso e-Book
2008-05-13 01:41:54 0 d--hs---- C:\FOUND.149
2008-05-12 02:02:50 0 d--hs---- C:\FOUND.148
2008-05-12 01:41:46 0 d--hs---- C:\FOUND.147
2008-05-10 11:17:44 0 d--hs---- C:\FOUND.146
2008-05-07 20:16:57 30722 --a------ C:\KILLWIN\system32\rVCPj3C2.exe
2008-05-07 19:40:50 0 d--hs---- C:\FOUND.145
2008-05-05 15:32:49 0 d-------- C:\Arquivos de programas\Spcron
2008-05-05 15:27:37 0 d-------- C:\Arquivos de programas\Svconr
2008-05-02 09:25:45 0 d-------- C:\Arquivos de programas\AMP Font Viewer
2008-05-01 09:40:16 68608 --a------ C:\KILLWIN\b155.exe
2008-04-30 13:03:34 0 d--hs---- C:\FOUND.144
2008-04-28 13:17:41 0 d-------- C:\Arquivos de programas\Arquivos comuns\SourceTec
2008-04-28 13:17:37 0 d-------- C:\Arquivos de programas\SourceTec
2008-04-26 07:14:57 33280 --a------ C:\KILLWIN\system32\nRXLf3X2.dll
2008-04-25 09:42:48 0 d--hs---- C:\FOUND.143
2008-04-24 18:44:20 73728 --a------ C:\KILLWIN\b156.exe
2008-04-24 04:39:34 0 d-------- C:\Arquivos de programas\Juice
2008-04-24 02:47:08 0 d-------- C:\Arquivos de programas\MagicISO
2008-04-24 02:44:59 0 d-------- C:\Arquivos de programas\MagicISO Maker v5 4
2008-04-22 17:28:14 0 d--hs---- C:\FOUND.142
2008-04-22 05:07:09 0 d-------- C:\Arquivos de programas\Stardock
2008-04-22 05:07:09 0 d-------- C:\Arquivos de programas\Arquivos comuns\Stardock
2008-04-22 00:54:42 0 d--hs---- C:\FOUND.141
-- Find3M Report ---------------------------------------------------------------
2008-05-22 07:10:16 0 d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\PCF-VLC
2008-05-20 10:39:20 0 d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Participatory Culture Foundation
2008-05-20 10:03:34 0 d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\PersonalBrain
2008-05-19 17:54:42 0 d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Audacity
2008-05-13 16:43:08 0 d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\SecuROM
2008-05-13 01:23:36 4563 --a------ C:\KILLWIN\mozver.dat
2008-05-02 09:19:20 37376 -ra------ C:\KILLWIN\mrofinu1395.exe
2008-04-24 04:39:46 0 d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\iPodder
2008-04-19 20:54:20 10 --a------ C:\Arquivos de programas\.autoreg
2008-04-19 20:53:50 0 d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\WinTouch
2008-04-19 20:53:44 0 d-------- C:\Arquivos de programas\Inet_Get_2
2008-04-19 20:48:44 0 d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\SpeedRunner
2008-04-19 20:43:52 0 d-------- C:\Arquivos de programas\JavaCore
2008-04-19 20:43:52 0 d-------- C:\Arquivos de programas\InetGet2
2008-04-19 20:33:46 0 d-------- C:\Arquivos de programas\Temporary
2008-04-17 06:46:52 57775 --a------ C:\KILLWIN\system32\1.exe
2008-04-15 16:35:08 55596 --a------ C:\KILLWIN\system32\AnalFTP2.exe
2008-04-14 15:26:02 0 d-------- C:\Arquivos de programas\GbPlugin
2008-04-14 12:08:18 46592 --a------ C:\KILLWIN\b157.exe
2008-04-13 05:37:00 0 d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\MegauploadToolbar
2008-04-13 05:37:00 0 d-------- C:\Arquivos de programas\MegauploadToolbar
2008-04-12 22:01:56 0 d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Lexmark Productivity Studio
2008-04-11 08:48:26 11264 --a------ C:\KILLWIN\b138.exe
2008-04-06 23:45:38 0 d-------- C:\Arquivos de programas\passFIRST-Certificate-Demo
2008-03-30 21:54:26 0 d-------- C:\Arquivos de programas\QuienNoAdmitido
2008-03-23 06:07:04 0 d-------- C:\Arquivos de programas\SopCast
2008-03-23 06:04:44 0 d-------- C:\Arquivos de programas\MegaCubo
2008-03-04 16:32:28 105984 --a------ C:\KILLWIN\b152.exe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15421B84-3488-49A7-AD18-CBF84A3EFAF6}]
2008-05-05 15:32 55808 --a------ C:\Arquivos de programas\Spcron\Spcron.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"lxdjamon"="C:\Arquivos de programas\Lexmark 1400 Series\lxdjamon.exe" [2007-04-30 08:19]
"avast!"="C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-18 23:06]
"WinampAgent"="C:\Arquivos de programas\Winamp\winampa.exe" [2007-12-20 13:16]
"UDC Integration"="C:\ARQUIV~1\UNIVER~1\getstart.exe" [2006-02-06 19:00]
"SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"Setup"="C:\Program Files\Common Files\setup.exe" [2008-02-19 05:30]
"QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-04-27 09:41]
"nwiz"="nwiz.exe" [2002-01-15 05:06 C:\KILLWIN\system32\nwiz.exe]
"NvCplDaemon"="NvQTwk" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JavaCore"="C:\Arquivos de programas\\JavaCore\\JavaCore.exe" [2008-04-19 20:43]
"ctfmon.exe"="C:\KILLWIN\system32\ctfmon.exe" [2004-08-04 00:45]
"WinTouch"="C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\WinTouch\WinTouch.exe" [2008-04-19 20:54]
"Twain"="C:\Arquivos de programas\Twain\Twain.exe" []
"Svconr"="C:\Arquivos de programas\Svconr\Svconr.exe" [2008-05-05 15:27]
"Steam"="C:\Arquivos de programas\Steam\Steam.exe" []
"SpeedRunner"="C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\SpeedRunner\SpeedRunner.exe" [2008-04-19 20:48]
"Skype"="C:\Arquivos de programas\Skype\Phone\Skype.exe" [2007-06-08 15:18]
"SfKg6wIP"="C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Microsoft\Windows\hvasuo.exe" [2008-04-19 20:48]
"SfKg6w"="C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Microsoft\Windows\tncqdc.exe" [2008-04-19 20:54]
"MsnMsgr"="C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]
"DAEMON Tools Lite"="C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-01-17 14:51]
"AdVantage"="C:\Arquivos de programas\AdVantage\AdVantage.exe" [2007-11-05 11:12]
C:\Documents and Settings\Marcos.CASA\Menu Iniciar\Programas\Inicializar\
Stardock ObjectDock.lnk - C:\Arquivos de programas\Stardock\ObjectDock\ObjectDock.exe [2008-04-22 05:07:27]
Recorte de tela e Iniciador do OneNote 2007.lnk - C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54]
PersonalBrain 4.lnk - C:\Arquivos de programas\PersonalBrain\PersonalBrainS.exe [2008-05-20 10:02:37]
C:\Documents and Settings\All Users.KILLWIN\Menu Iniciar\Programas\Inicializar\
PalTalk.lnk - C:\Arquivos de programas\Paltalk Messenger\paltalk.exe [2008-05-08 19:17:29]
InterVideo WinCinema Manager.lnk - C:\Arquivos de programas\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-08-04 17:17:11]
Adobe Reader Synchronizer.lnk - C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50]
Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{A3717295-941D-416F-9384-ED1736729F1C}"= C:\Arquivos de programas\Scpad\scpLIB.dll [2007-03-27 01:29 128512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E37CB5F0-51F5-4395-A808-5FA49E399003}"= C:\Arquivos de programas\GbPlugin\gbiehcef.dll [2008-03-05 11:29 341576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"CompIBBrd"= {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll [2007-03-27 01:29 128512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]
C:\Arquivos de programas\GbPlugin\gbiehcef.dll 2008-03-05 11:29 341576 C:\Arquivos de programas\GbPlugin\gbiehcef.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
-- End of Deckard's System Scanner: finished at 2008-05-22 19:55:05 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: Portuguese
CPU 0: AMD Athlon XP 2000+
Percentage of Memory in Use: 27%
Physical Memory (total/avail): 1535.35 MiB / 1107.25 MiB
Pagefile Memory (total/avail): 3434.88 MiB / 2911.87 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1933.28 MiB
A: is Removable (No Media)
C: is Fixed (FAT32) - 28.61 GiB total, 5.28 GiB free.
D: is Fixed (NTFS) - 149.04 GiB total, 0.04 GiB free.
E: is CDROM (CDFS)
F: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - IBM-DTLA-307030 - 28.63 GiB - 1 partition
\PARTITION0 (bootable) - Unknown - 28.62 GiB - C:
\\.\PHYSICALDRIVE1 - SAMSUNG SP1604N - 149.05 GiB - 1 partition
\PARTITION0 - Sistema de arquivos instalável - 149.04 GiB - D:
-- Security Center -------------------------------------------------------------
AUOptions is disabled.
Windows Internal Firewall is enabled.
FirstRunDisabled is set.
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"="C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"="C:\\Arquivos de programas\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Arquivos de programas\\Messenger\\msmsgs.exe"="C:\\Arquivos de programas\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Arquivos de programas\\InterVideo\\DVD7\\WinDVD.exe"="C:\\Arquivos de programas\\InterVideo\\DVD7\\WinDVD.exe:*:Enabled:WinDVD"
"C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"="C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"="C:\\Arquivos de programas\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Arquivos de programas\\Paltalk Messenger\\paltalk.exe"="C:\\Arquivos de programas\\Paltalk Messenger\\paltalk.exe:*:Enabled:Paltalk 9.0"
"C:\\KILLWIN\\System32\\lxdjcoms.exe"="C:\\KILLWIN\\System32\\lxdjcoms.exe:*:Enabled:Lexmark Communications System"
"C:\\Arquivos de programas\\Lexmark 1400 Series\\lxdjamon.exe"="C:\\Arquivos de programas\\Lexmark 1400 Series\\lxdjamon.exe:*:Enabled:Lexmark Device Monitor"
"C:\\Arquivos de programas\\Lexmark 1400 Series\\App4R.exe"="C:\\Arquivos de programas\\Lexmark 1400 Series\\App4R.exe:*:Enabled:Lexmark Imaging Studio"
"C:\\KILLWIN\\System32\\spool\\drivers\\W32X86\\3\\lxdjwbgw.exe"="C:\\KILLWIN\\System32\\spool\\drivers\\W32X86\\3\\lxdjwbgw.exe:*:Enabled: "
"C:\\Program Files\\Hasbro Sports\\Grand Prix 3\\GP3.exe"="C:\\Program Files\\Hasbro Sports\\Grand Prix 3\\GP3.exe:*:Enabled:GP3"
"C:\\Arquivos de programas\\uTorrent\\uTorrent.exe"="C:\\Arquivos de programas\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\Arquivos de programas\\Cedro Market & Finances\\Cedro Lite\\zebedee\\tunnelcedro.exe"="C:\\Arquivos de programas\\Cedro Market & Finances\\Cedro Lite\\zebedee\\tunnelcedro.exe:*:Enabled:Tunnel Cedro"
"D:\\Jogos\\Bohemia Interactive\\ArmA Demo\\ArmADemo.exe"="D:\\Jogos\\Bohemia Interactive\\ArmA Demo\\ArmADemo.exe:*:Enabled:ArmA"
"C:\\Program Files\\Atari\\ArmA Demo\\ArmADemo.exe"="C:\\Program Files\\Atari\\ArmA Demo\\ArmADemo.exe:*:Enabled:ArmA Demo"
"C:\\Arquivos de programas\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"="C:\\Arquivos de programas\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
"D:\\Arquivos de Programas\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"="D:\\Arquivos de Programas\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
"C:\\Arquivos de programas\\Mozilla Firefox\\FIREFOX.EXE"="C:\\Arquivos de programas\\Mozilla Firefox\\FIREFOX.EXE:*:Enabled:Firefox"
"C:\\Arquivos de programas\\Avant Browser\\avant.exe"="C:\\Arquivos de programas\\Avant Browser\\avant.exe:*:Enabled:Avant Browser"
"C:\\KILLWIN\\System32\\SPOOL\\DRIVERS\\W32X86\\3\\lxdjPSWX.EXE"="C:\\KILLWIN\\System32\\SPOOL\\DRIVERS\\W32X86\\3\\lxdjPSWX.EXE:*:Enabled: "
"C:\\KILLWIN\\System32\\SPOOL\\DRIVERS\\W32X86\\3\\lxdjjswx.exe"="C:\\KILLWIN\\System32\\SPOOL\\DRIVERS\\W32X86\\3\\lxdjjswx.exe:*:Enabled: "
"C:\\KILLWIN\\System32\\SPOOL\\DRIVERS\\W32X86\\3\\LXDJtime.exe"="C:\\KILLWIN\\System32\\SPOOL\\DRIVERS\\W32X86\\3\\LXDJtime.exe:*:Enabled: "
"D:\\Arquivos de Programas\\DreMule\\emule.exe"="D:\\Arquivos de Programas\\DreMule\\emule.exe:*:Enabled:Dreamule"
"C:\\Arquivos de programas\\Participatory Culture Foundation\\Miro\\xulrunner\\python\\Miro_Downloader.exe"="C:\\Arquivos de programas\\Participatory Culture Foundation\\Miro\\xulrunner\\python\\Miro_Downloader.exe:*:Enabled:Miro_Downloader"
"C:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"="C:\\Arquivos de programas\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users.KILLWIN
APPDATA=C:\Documents and Settings\Marcos.CASA\Dados de aplicativos
CLASSPATH=.;C:\Arquivos de programas\Java\jre1.6.0_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Arquivos de programas\Arquivos comuns
COMPUTERNAME=CASA
ComSpec=C:\KILLWIN\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Marcos.CASA
LOGONSERVER=\\CASA
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\KILLWIN\system32;C:\KILLWIN;C:\KILLWIN\system32\wbem;C:\Arquivos de programas\QuickTime\QTSystem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 8 Stepping 0, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0800
ProgramFiles=C:\Arquivos de programas
PROMPT=$P$G
QTJAVA=C:\Arquivos de programas\Java\jre1.6.0_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\KILLWIN
TEMP=C:\DOCUME~1\MARCOS~1.CAS\CONFIG~1\Temp
TMP=C:\DOCUME~1\MARCOS~1.CAS\CONFIG~1\Temp
USERDOMAIN=CASA
USERNAME=Marcos
USERPROFILE=C:\Documents and Settings\Marcos.CASA
windir=C:\KILLWIN
-- User Profiles ---------------------------------------------------------------
Marcos.CASA
(admin)Gamer
-- Add/Remove Programs ---------------------------------------------------------
--> C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Arquivos de programas\DivX\DivXConverterUninstall.exe /CONVERTER
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\KILLWIN\INF\PCHealth.inf
AC3Filter (remove only) --> C:\Arquivos de programas\AC3Filter\uninstall.exe
Adobe Flash Player ActiveX --> C:\KILLWIN\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\KILLWIN\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8 - Português --> MsiExec.exe /I{AC76BA86-7AD7-1046-7B44-A80000000000}
AdVantage (Powering DAEMON Tools) --> "C:\Arquivos de programas\AdVantage\AdVUninst.exe" /r DAEM /d "AdVantage (Powering DAEMON Tools)" /m "AdVantage is safe advertising software that supports Freeze.com.\nAdVantage is certified by TRUSTe as a Trusted Download.\n\nAre you sure you want to uninstall AdVantage support for DAEMON Tools?"
AMP Font Viewer --> "C:\Arquivos de programas\AMP Font Viewer\uninstall.exe"
Ap PDF Split/Merge --> "C:\Arquivos de programas\AdultPDF\Ap PDF Split-Merge\unins000.exe"
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Arquivo do WinRAR --> C:\Arquivos de programas\WinRAR\uninstall.exe
ATI - Software Uninstall Utility --> C:\Arquivos de programas\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Display Driver --> rundll32 C:\KILLWIN\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
µTorrent --> "C:\Arquivos de programas\uTorrent\uTorrent.exe" /UNINSTALL
Atualização de segurança para Step by Step Interactive Training (KB923723) --> "C:\KILLWIN\$NtUninstallKB923723$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB890046) --> "C:\KILLWIN\$NtUninstallKB890046$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB893756) --> "C:\KILLWIN\$NtUninstallKB893756$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB896358) --> "C:\KILLWIN\$NtUninstallKB896358$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB896423) --> "C:\KILLWIN\$NtUninstallKB896423$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB896428) --> "C:\KILLWIN\$NtUninstallKB896428$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB899587) --> "C:\KILLWIN\$NtUninstallKB899587$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB899589) --> "C:\KILLWIN\$NtUninstallKB899589$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB899591) --> "C:\KILLWIN\$NtUninstallKB899591$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB900725) --> "C:\KILLWIN\$NtUninstallKB900725$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB901017) --> "C:\KILLWIN\$NtUninstallKB901017$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB901190) --> "C:\KILLWIN\$NtUninstallKB901190$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB901214) --> "C:\KILLWIN\$NtUninstallKB901214$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB902400) --> "C:\KILLWIN\$NtUninstallKB902400$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB904706) --> "C:\KILLWIN\$NtUninstallKB904706$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB905414) --> "C:\KILLWIN\$NtUninstallKB905414$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB905749) --> "C:\KILLWIN\$NtUninstallKB905749$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB908519) --> "C:\KILLWIN\$NtUninstallKB908519$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB911562) --> "C:\KILLWIN\$NtUninstallKB911562$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB911927) --> "C:\KILLWIN\$NtUninstallKB911927$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB913580) --> "C:\KILLWIN\$NtUninstallKB913580$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB914388) --> "C:\KILLWIN\$NtUninstallKB914388$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB914389) --> "C:\KILLWIN\$NtUninstallKB914389$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB917422) --> "C:\KILLWIN\$NtUninstallKB917422$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB917537) --> "C:\KILLWIN\$NtUninstallKB917537$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB917953) --> "C:\KILLWIN\$NtUninstallKB917953$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB918118) --> "C:\KILLWIN\$NtUninstallKB918118$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB918439) --> "C:\KILLWIN\$NtUninstallKB918439$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB919007) --> "C:\KILLWIN\$NtUninstallKB919007$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB920213) --> "C:\KILLWIN\$NtUninstallKB920213$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB920670) --> "C:\KILLWIN\$NtUninstallKB920670$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB920683) --> "C:\KILLWIN\$NtUninstallKB920683$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB920685) --> "C:\KILLWIN\$NtUninstallKB920685$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB922819) --> "C:\KILLWIN\$NtUninstallKB922819$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB923191) --> "C:\KILLWIN\$NtUninstallKB923191$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB923414) --> "C:\KILLWIN\$NtUninstallKB923414$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB923980) --> "C:\KILLWIN\$NtUninstallKB923980$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB924270) --> "C:\KILLWIN\$NtUninstallKB924270$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB924496) --> "C:\KILLWIN\$NtUninstallKB924496$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB924667) --> "C:\KILLWIN\$NtUninstallKB924667$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB925902) --> "C:\KILLWIN\$NtUninstallKB925902$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB926255) --> "C:\KILLWIN\$NtUninstallKB926255$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB926436) --> "C:\KILLWIN\$NtUninstallKB926436$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB927779) --> "C:\KILLWIN\$NtUninstallKB927779$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB927802) --> "C:\KILLWIN\$NtUninstallKB927802$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB928255) --> "C:\KILLWIN\$NtUninstallKB928255$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB928843) --> "C:\KILLWIN\$NtUninstallKB928843$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB929123) --> "C:\KILLWIN\$NtUninstallKB929123$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB929969) --> "C:\KILLWIN\$NtUninstallKB929969$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB930178) --> "C:\KILLWIN\$NtUninstallKB930178$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB931261) --> "C:\KILLWIN\$NtUninstallKB931261$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB931784) --> "C:\KILLWIN\$NtUninstallKB931784$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB932168) --> "C:\KILLWIN\$NtUninstallKB932168$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB933566) --> "C:\KILLWIN\$NtUninstallKB933566$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB935839) --> "C:\KILLWIN\$NtUninstallKB935839$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB935840) --> "C:\KILLWIN\$NtUninstallKB935840$\spuninst\spuninst.exe"
Atualização para Windows XP (KB908531) --> "C:\KILLWIN\$NtUninstallKB908531$\spuninst\spuninst.exe"
Atualização para Windows XP (KB911280) --> "C:\KILLWIN\$NtUninstallKB911280$\spuninst\spuninst.exe"
Atualização para Windows XP (KB922582) --> "C:\KILLWIN\$NtUninstallKB922582$\spuninst\spuninst.exe"
Atualização para Windows XP (KB925720) --> "C:\KILLWIN\$NtUninstallKB925720$\spuninst\spuninst.exe"
Avant Browser (remove only) --> "C:\Arquivos de programas\Avant Browser\uninst.exe"
avast! Antivirus --> C:\Arquivos de programas\Alwil Software\Avast4\aswRunDll.exe "C:\Arquivos de programas\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
AVG Anti-Rootkit Free --> C:\Arquivos de programas\GRISOFT\AVG Anti-Rootkit Free\Uninstall.exe
Bink and Smacker --> C:\ARQUIV~1\RADVIDEO\UNWISE.EXE C:\ARQUIV~1\RADVIDEO\INSTALL.LOG
Camtasia Studio --> C:\Arquivos de programas\TechSmith\Camtasia Studio\CSuninst.EXE
Camtasia Studio 5 --> MsiExec.exe /I{7BB40A22-8D98-43F9-A08A-E7EFF5AB1324}
CCleaner (remove only) --> "C:\Arquivos de programas\CCleaner\uninst.exe"
CDBurnerXP Pro 3 --> MsiExec.exe /I{896D642C-7125-44F0-AC49-A23ABF82209C}
Collins COBUILD Student's Dictionary Plus Grammar --> D:\Arquivos de ProgramasSetup.exe /u
CPV --> cmd /C regsvr32 /u /s "C:\Arquivos de programas\CPV\CPV8.dll" & reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\CPV" /f & REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce /v DelOldFile /d "cmd.exe /C del /Q \"C:\Arquivos de programas\CPV\"" /f
CPV --> cmd /C regsvr32 /u /s "C:\Arquivos de programas\Spcron\Spcron.dll" & reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spcron" /f & REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce /v DelOldFile /d "cmd.exe /C del /Q \"C:\Arquivos de programas\Spcron\"" /f
Creative DVD Audio Plugin for Audigy Series --> "C:\Arquivos de programas\Creative\CTDPlugin\CTUIDVD.exe " -u
DivX Codec --> C:\Arquivos de programas\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader --> C:\Arquivos de programas\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter --> C:\Arquivos de programas\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player --> C:\Arquivos de programas\DivX\DivXPlayerUninstall.exe /PLAYER
Dreamule 3.1 --> "D:\Arquivos de programas\DreMule\unins000.exe"
Easy Video Downloader v. 1.4.2 --> "C:\Arquivos de programas\Easy Video Downloader\unins000.exe"
ffdshow (remove only) --> "C:\Arquivos de programas\ffdshow\uninstall.exe"
HijackThis 2.0.2 --> "C:\Arquivos de programas\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Indeo® XP Software --> C:\KILLWIN\IsUninst.exe -f"C:\Arquivos de programas\Ligos\Indeo\UninstXP.isu"
InterActual Player --> C:\Program Files\InterActual\InterActual Player\inuninst.exe
InterVideo WinDVD 7 --> "C:\Arquivos de programas\InstallShield Installation Information\{90885A82-9673-49EA-AB39-AF776639C67C}\setup.exe" REMOVEALL
Java 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Juice 2.2 --> C:\Arquivos de programas\Juice\uninst.exe
Kaspersky Online Scanner --> C:\KILLWIN\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
L&H TTS3000 Português (Brasil) --> RunDll32 advpack.d