ComboFix worked ok again (but why is it this warning keeps turning up?):
ComboFix 08-05-21.3 - Marcos 2008-05-26 2:43:44.2 -
FAT32x86 MINIMAL
Executando de: C:\Documents and Settings\Marcos.CASA\Desktop\PauBrasil.exe
Command switches used :: C:\Documents and Settings\Marcos.CASA\Desktop\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\KILLWIN\system32\d3d9caps.dat
C:\KILLWIN\system32\drivers\dwshd.sys
C:\KILLWIN\system32\nRXLf3X2.dll
C:\KILLWIN\system32\ob227n37.exe
.
((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\FOUND.006
C:\FOUND.006\FILE0000.CHK
C:\FOUND.006\FILE0001.CHK
C:\FOUND.006\FILE0002.CHK
C:\FOUND.007
C:\FOUND.007\FILE0000.CHK
C:\FOUND.007\FILE0001.CHK
C:\FOUND.007\FILE0002.CHK
C:\FOUND.007\FILE0003.CHK
C:\FOUND.007\FILE0004.CHK
C:\FOUND.007\FILE0005.CHK
C:\FOUND.141
C:\FOUND.141\FILE0000.CHK
C:\FOUND.141\FILE0001.CHK
C:\FOUND.141\FILE0002.CHK
C:\FOUND.141\FILE0003.CHK
C:\FOUND.141\FILE0004.CHK
C:\KILLWIN\system32\d3d9caps.dat
C:\KILLWIN\system32\drivers\dwshd.sys
C:\KILLWIN\system32\nRXLf3X2.dll
C:\Documents and Settings\Marcos.CASA\Configurações locais\Temporary Internet Files\bestwiner.stt . . . . falha na exclusão
C:\Documents and Settings\Marcos.CASA\Configurações locais\Temporary Internet Files\CPV.stt . . . . falha na exclusão
.
((((((((((((((((((((((( Ficheiros criados de 2008-04-26 to 2008-05-26 ))))))))))))))))))))))))))))))))
.
2008-05-26 00:29 . 2008-05-26 00:29 <DIR> d-------- C:\KILLWIN\system32\config\systemprofile\Configurações locais
2008-05-26 00:29 . 2008-05-26 00:29 <DIR> d-------- C:\Documents and Settings\NetworkService.AUTORIDADE NT\Configurações locais
2008-05-26 00:29 . 2008-05-26 00:29 <DIR> d-------- C:\Documents and Settings\Marcos\Configurações locais
2008-05-26 00:29 . 2008-05-26 00:29 <DIR> d-------- C:\Documents and Settings\Marcos.CASA\Configurações locais
2008-05-26 00:29 . 2008-05-26 00:29 <DIR> d-------- C:\Documents and Settings\LocalService.AUTORIDADE NT\Configurações locais
2008-05-26 00:29 . 2008-05-26 00:29 <DIR> d-------- C:\Documents and Settings\Gamer\Configurações locais
2008-05-26 00:29 . 2008-05-26 00:29 <DIR> d-------- C:\Documents and Settings\Default User.KILLWIN\Configurações locais
2008-05-25 22:43 . 2008-05-25 22:43 <DIR> d-------- C:\KILLWIN\ERUNT
2008-05-25 22:37 . 2008-05-23 03:54 <DIR> d-------- C:\SDFix
2008-05-25 21:35 . 2008-05-25 21:35 <DIR> d-------- C:\DAEMON Tools
2008-05-24 15:20 . 2008-05-24 15:20 <DIR> d-------- C:\Documents and Settings\Marcos.CASA\DoctorWeb
2008-05-23 08:14 . 2008-05-23 08:14 <DIR> d-------- C:\_OTMoveIt
2008-05-22 19:53 . 2008-05-22 19:53 <DIR> d-------- C:\Deckard
2008-05-22 07:57 . 2008-05-22 07:57 <DIR> d-------- C:\Arquivos de programas\Trend Micro
2008-05-22 07:10 . 2008-05-22 07:10 <DIR> d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\PCF-VLC
2008-05-21 20:09 . 2008-05-21 20:09 <DIR> d-------- C:\Arquivos de programas\Yahoo!
2008-05-20 23:51 . 2004-08-04 00:45 15,360 --a------ C:\KILLWIN\system32\dllcache\ctfmon.exe
2008-05-20 23:51 . 2004-08-04 00:45 15,360 --a------ C:\KILLWIN\system32\ctfmon.exe
2008-05-20 11:25 . 2008-05-20 11:25 <DIR> d-------- C:\fsaua.data
2008-05-20 10:39 . 2008-05-20 10:39 <DIR> d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Participatory Culture Foundation
2008-05-20 10:38 . 2008-05-20 10:38 <DIR> d-------- C:\Arquivos de programas\Participatory Culture Foundation
2008-05-20 10:03 . 2008-05-20 10:03 <DIR> d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\PersonalBrain
2008-05-20 10:03 . 2008-05-20 10:03 97 --a------ C:\Documents and Settings\EditLiveForJava.ini
2008-05-20 10:02 . 2008-05-20 10:02 <DIR> d-------- C:\Arquivos de programas\PersonalBrain
2008-05-20 09:48 . 2008-05-20 09:48 <DIR> d-------- C:\My Brains
2008-05-20 09:47 . 2008-05-20 09:47 <DIR> d-------- C:\Arquivos de programas\TheBrain
2008-05-20 08:46 . 2008-05-20 08:46 <DIR> d-------- C:\Documents and Settings\All Users.KILLWIN\Dados de aplicativos\TechSmith
2008-05-20 08:36 . 2008-05-20 08:36 <DIR> d-------- C:\KILLWIN\system32\QuickTime
2008-05-20 08:25 . 2008-05-20 08:25 <DIR> d-------- C:\UDC Snapshots
2008-05-20 08:25 . 2008-05-20 08:25 <DIR> d-------- C:\Arquivos de programas\Universal Document Converter
2008-05-20 08:25 . 2005-12-01 20:22 5,632 --a------ C:\KILLWIN\system32\udcpm.dll
2008-05-20 08:05 . 2008-05-20 08:05 <DIR> d-------- C:\lotuspro
2008-05-20 07:57 . 2008-05-20 07:57 <DIR> d-------- C:\Arquivos de programas\TechSmith
2008-05-20 07:57 . 2008-05-20 07:57 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\TechSmith Shared
2008-05-20 07:57 . 2008-03-12 02:37 107,864 --a------ C:\KILLWIN\system32\tsccvid.dll
2008-05-19 17:54 . 2008-05-19 17:54 <DIR> d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Audacity
2008-05-18 23:05 . 2008-05-18 23:05 <DIR> d-------- C:\Arquivos de programas\Alwil Software
2008-05-18 23:05 . 2003-03-18 18:20 1,060,864 --a------ C:\KILLWIN\system32\MFC71.dll
2008-05-18 23:05 . 2003-03-18 17:14 499,712 --a------ C:\KILLWIN\system32\MSVCP71.dll
2008-05-18 23:05 . 2003-02-21 01:42 348,160 --a------ C:\KILLWIN\system32\MSVCR71.dll
2008-05-18 23:04 . 2008-05-18 23:04 <DIR> d-------- C:\Arquivos de programas\RootKit Hook Analyzer
2008-05-18 22:56 . 2008-05-18 22:56 <DIR> d-------- C:\Arquivos de programas\WindowsMetafileFix
2008-05-18 22:56 . 2006-01-02 22:23 3,584 --a------ C:\KILLWIN\system32\wmfhotfix.dll
2008-05-18 20:46 . 2008-05-18 20:46 <DIR> d-------- C:\Arquivos de programas\CCleaner
2008-05-18 19:36 . 2008-05-18 19:42 26 --a------ C:\KILLWIN\DGcounter.ini
2008-05-18 19:35 . 2008-05-18 19:35 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Panda Software
2008-05-17 20:41 . 2008-05-17 20:41 <DIR> d-------- C:\Documents and Settings\All Users.KILLWIN\Dados de aplicativos\Kaspersky Lab
2008-05-13 17:01 . 2008-05-20 08:40 54,156 --ah----- C:\KILLWIN\QTFont.qfn
2008-05-13 17:01 . 2008-05-13 17:01 1,409 --a------ C:\KILLWIN\QTFont.for
2008-05-13 16:43 . 2008-05-13 16:43 <DIR> d-------- C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\SecuROM
2008-05-13 16:43 . 2008-05-13 16:43 126,976 --a------ C:\KILLWIN\system32\UAService7.exe
2008-05-13 05:12 . 2008-05-13 05:12 53,248 --a------ C:\KILLWIN\system32\oml.dll
2008-05-13 04:21 . 2008-05-13 04:21 <DIR> d-------- C:\Arquivos de programas\Metastock Expresso e-Book
2008-05-12 18:18 . 2008-05-12 18:24 2 --a------ C:\KILLWIN\system32\RICHTX.DEP
2008-05-08 08:00 . 2008-05-08 08:00 <DIR> dr------- C:\Documents and Settings\NetworkService.AUTORIDADE NT\Favoritos
2008-05-08 08:00 . 2008-05-08 08:00 <DIR> d-------- C:\Documents and Settings\NetworkService.AUTORIDADE NT\Dados de aplicativos\MEGAUPLOADTOOLBAR
2008-05-02 09:25 . 2008-05-02 09:25 <DIR> d-------- C:\Arquivos de programas\AMP Font Viewer
2008-04-28 13:17 . 2008-04-28 13:17 <DIR> d-------- C:\Arquivos de programas\SourceTec
2008-04-28 13:17 . 2008-04-28 13:17 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\SourceTec
.
((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-24 07:39 --------- d-----w C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\iPodder
2008-04-24 07:39 --------- d-----w C:\Arquivos de programas\Juice
2008-04-24 05:47 --------- d-----w C:\Arquivos de programas\MagicISO
2008-04-24 05:45 --------- d-----w C:\Arquivos de programas\MagicISO Maker v5 4
2008-04-22 08:07 --------- d-----w C:\Arquivos de programas\Stardock
2008-04-22 08:07 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Stardock
2008-04-19 23:53 --------- d-----w C:\Arquivos de programas\Inet_Get_2
2008-04-14 18:26 --------- d-----w C:\Documents and Settings\All Users.KILLWIN\Dados de aplicativos\GbPlugin
2008-04-14 18:26 --------- d-----w C:\Arquivos de programas\GbPlugin
2008-04-13 08:37 --------- d-----w C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\MegauploadToolbar
2008-04-13 08:37 --------- d-----w C:\Arquivos de programas\MegauploadToolbar
2008-04-13 01:01 --------- d-----w C:\Documents and Settings\Marcos.CASA\Dados de aplicativos\Lexmark Productivity Studio
2008-04-07 02:45 --------- d-----w C:\Arquivos de programas\passFIRST-Certificate-Demo
2008-03-31 00:54 --------- d-----w C:\Arquivos de programas\QuienNoAdmitido
2008-03-12 23:27 50,520 ----a-w C:\KILLWIN\system32\csvidcap.dll
2007-08-20 14:21 94,208 ----a-w C:\Documents and Settings\Marcos\Dados de aplicativos\ezplay.sys
2007-08-20 14:21 47,360 ----a-w C:\Documents and Settings\Marcos\Dados de aplicativos\pcouffin.sys
.
((((((((((((((((((((((((((((( snapshot@2008-05-26_ 0.29.25.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-26 03:23:20 2,048 --s-a-w C:\KILLWIN\bootstat.dat
+ 2008-05-26 05:47:02 2,048 --s-a-w C:\KILLWIN\bootstat.dat
+ 2008-05-26 05:49:30 16,384 ----a-w C:\KILLWIN\TEMP\Perflib_Perfdata_264.dat
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\KILLWIN\system32\ctfmon.exe" [2004-08-04 00:45 15360]
"Skype"="C:\Arquivos de programas\Skype\Phone\Skype.exe" [2007-06-08 15:18 23233576]
"MsnMsgr"="C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]
"DAEMON Tools Lite"="C:\Arquivos de programas\DAEMON Tools Lite\daemon.exe" [2008-01-17 14:51 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"lxdjamon"="C:\Arquivos de programas\Lexmark 1400 Series\lxdjamon.exe" [2007-04-30 08:19 20480]
"avast!"="C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-18 23:06 79224]
"WinampAgent"="C:\Arquivos de programas\Winamp\winampa.exe" [2007-12-20 13:16 37376]
"UDC Integration"="C:\ARQUIV~1\UNIVER~1\getstart.exe" [2006-02-06 19:00 159744]
"SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Arquivos de programas\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"nwiz"="nwiz.exe" [2002-01-15 05:06 299008 C:\KILLWIN\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\KILLWIN\system32\CTFMON.EXE" [2004-08-04 00:45 15360]
C:\Documents and Settings\Marcos\Menu Iniciar\Programas\Inicializar\
Recorte de tela e Iniciador do OneNote 2007.lnk - C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
C:\Documents and Settings\Marcos.CASA\Menu Iniciar\Programas\Inicializar\
Stardock ObjectDock.lnk - C:\Arquivos de programas\Stardock\ObjectDock\ObjectDock.exe [2008-04-22 05:07:27 2746104]
Recorte de tela e Iniciador do OneNote 2007.lnk - C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]
PersonalBrain 4.lnk - C:\Arquivos de programas\PersonalBrain\PersonalBrainS.exe [2008-05-20 10:02:37 221184]
C:\Documents and Settings\All Users.KILLWIN\Menu Iniciar\Programas\Inicializar\
PalTalk.lnk - C:\Arquivos de programas\Paltalk Messenger\paltalk.exe [2008-05-08 19:17:29 10452992]
InterVideo WinCinema Manager.lnk - C:\Arquivos de programas\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-08-04 17:17:11 278528]
Adobe Reader Synchronizer.lnk - C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
Adobe Reader Speed Launch.lnk - C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{A3717295-941D-416F-9384-ED1736729F1C}"= C:\Arquivos de programas\Scpad\scpLIB.dll [2007-03-27 01:29 128512]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{E37CB5F0-51F5-4395-A808-5FA49E399003}"= C:\Arquivos de programas\GbPlugin\gbiehcef.dll [2008-03-05 11:29 341576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"CompIBBrd"= {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll [2007-03-27 01:29 128512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]
C:\Arquivos de programas\GbPlugin\gbiehcef.dll 2008-03-05 11:29 341576 C:\Arquivos de programas\GbPlugin\gbiehcef.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\KILLWIN\system32\wmfhotfix.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Arquivos de programas\\Messenger\\msmsgs.exe"=
"C:\\Arquivos de programas\\InterVideo\\DVD7\\WinDVD.exe"=
"C:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=
"C:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=
"C:\\Arquivos de programas\\Paltalk Messenger\\paltalk.exe"=
"C:\\KILLWIN\\System32\\lxdjcoms.exe"=
"C:\\Arquivos de programas\\Lexmark 1400 Series\\lxdjamon.exe"=
"C:\\Arquivos de programas\\Lexmark 1400 Series\\App4R.exe"=
"C:\\KILLWIN\\System32\\spool\\drivers\\W32X86\\3\\lxdjwbgw.exe"=
"C:\\Arquivos de programas\\Mozilla Firefox\\FIREFOX.EXE"=
"C:\\Arquivos de programas\\Avant Browser\\avant.exe"=
"C:\\Arquivos de programas\\Participatory Culture Foundation\\Miro\\xulrunner\\python\\Miro_Downloader.exe"=
"C:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
"C:\\KILLWIN\\System32\\SPOOL\\DRIVERS\\W32X86\\3\\lxdjPSWX.EXE"=
"C:\\KILLWIN\\System32\\SPOOL\\DRIVERS\\W32X86\\3\\lxdjjswx.exe"=
"C:\\KILLWIN\\System32\\SPOOL\\DRIVERS\\W32X86\\3\\LXDJtime.exe"=
R1 aswSP;avast! Self Protection;C:\KILLWIN\system32\drivers\aswSP.sys [2008-05-15 20:20]
R2 aswFsBlk;aswFsBlk;C:\KILLWIN\system32\DRIVERS\aswFsBlk.sys [2008-05-15 20:16]
S2 lxdjCATSCustConnectService;lxdjCATSCustConnectService;C:\KILLWIN\System32\spool\DRIVERS\W32X86\3\\lxdjserv.exe [2007-06-11 11:17]
.
Conte£do da pasta 'Tarefas Agendadas'
"2008-05-26 03:00:02 C:\KILLWIN\Tasks\At1.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-26 04:00:02 C:\KILLWIN\Tasks\At2.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-26 05:00:00 C:\KILLWIN\Tasks\At3.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 06:00:02 C:\KILLWIN\Tasks\At4.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 07:00:02 C:\KILLWIN\Tasks\At5.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 08:00:02 C:\KILLWIN\Tasks\At6.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 09:00:02 C:\KILLWIN\Tasks\At7.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 10:00:02 C:\KILLWIN\Tasks\At8.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 11:00:02 C:\KILLWIN\Tasks\At9.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 12:00:02 C:\KILLWIN\Tasks\At10.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 13:00:02 C:\KILLWIN\Tasks\At11.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 14:00:02 C:\KILLWIN\Tasks\At12.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 15:00:00 C:\KILLWIN\Tasks\At13.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 16:00:00 C:\KILLWIN\Tasks\At14.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 17:00:00 C:\KILLWIN\Tasks\At15.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 18:00:00 C:\KILLWIN\Tasks\At16.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 19:00:00 C:\KILLWIN\Tasks\At17.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 20:00:00 C:\KILLWIN\Tasks\At18.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 21:00:00 C:\KILLWIN\Tasks\At19.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 22:00:02 C:\KILLWIN\Tasks\At20.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-25 23:00:02 C:\KILLWIN\Tasks\At21.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-26 00:00:02 C:\KILLWIN\Tasks\At22.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-26 01:00:02 C:\KILLWIN\Tasks\At23.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-26 02:00:02 C:\KILLWIN\Tasks\At24.job"
- C:\KILLWIN\system32\ob227n37.exe
"2008-05-23 20:15:02 C:\KILLWIN\Tasks\1-Click Maintenance.job"
- C:\Arquivos de programas\TuneUp Utilities 2008\OneClick.exe
"2008-05-22 22:09:02 C:\KILLWIN\Tasks\AppleSoftwareUpdate.job"
- C:\Arquivos de programas\Apple Software Update\SoftwareUpdate.exe
"2008-05-26 03:11:02 C:\KILLWIN\Tasks\At73.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-26 04:00:02 C:\KILLWIN\Tasks\At74.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-26 05:00:02 C:\KILLWIN\Tasks\At75.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 06:00:02 C:\KILLWIN\Tasks\At76.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 07:00:02 C:\KILLWIN\Tasks\At77.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 08:00:02 C:\KILLWIN\Tasks\At78.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 09:00:02 C:\KILLWIN\Tasks\At79.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 10:00:02 C:\KILLWIN\Tasks\At80.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 11:00:02 C:\KILLWIN\Tasks\At81.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 12:00:02 C:\KILLWIN\Tasks\At82.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 13:00:02 C:\KILLWIN\Tasks\At83.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 14:00:02 C:\KILLWIN\Tasks\At84.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 15:00:02 C:\KILLWIN\Tasks\At85.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 16:00:02 C:\KILLWIN\Tasks\At86.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 17:00:02 C:\KILLWIN\Tasks\At87.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 18:00:02 C:\KILLWIN\Tasks\At88.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 19:00:02 C:\KILLWIN\Tasks\At89.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 20:00:00 C:\KILLWIN\Tasks\At90.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 21:00:02 C:\KILLWIN\Tasks\At91.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 22:00:02 C:\KILLWIN\Tasks\At92.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-25 23:00:02 C:\KILLWIN\Tasks\At93.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-26 00:00:02 C:\KILLWIN\Tasks\At94.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-26 01:00:02 C:\KILLWIN\Tasks\At95.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
"2008-05-26 02:00:02 C:\KILLWIN\Tasks\At96.job"
- C:\KILLWIN\system32\rVCPj3C2.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-26 02:48:47
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Procurando processos ocultos ...
Procurando entradas auto inicializ veis ocultas ...
Procurando ficheiros ocultos ...
Varredura completada com sucesso
Ficheiros ocultos: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\KILLWIN\explorer.exe
-> C:\Arquivos de programas\Stardock\ObjectDock\DockShellHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\GBPSV.EXE
C:\KILLWIN\SYSTEM32\LXDJCOMS.EXE
C:\KILLWIN\SYSTEM32\WDFMGR.EXE
C:\KILLWIN\system32\UAService7.exe
C:\KILLWIN\system32\wscntfy.exe
.
**************************************************************************
.
Tempo para conclusÆo: 2008-05-26 2:51:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-26 05:51:40
ComboFix2.txt 2008-05-26 03:29:52
Pre-Run: 5,286,526,976 bytes disponíveis
Post-Run: 5,296,357,376 bytes dispon¡veis
318
~~~~~~~~~~~~
F-Secure Online Scan comes in the following post.
Regards,
Marcos