OTListIt logfile created on: 23/10/2008 14:58:26 - Run
OTListIt by OldTimer - Version 1.0.11.0 Folder = C:\Documents and Settings\usuario\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy
1022,73 Mb Total Physical Memory | 712,79 Mb Available Physical Memory | 69,69% Memory free
1,65 Gb Paging File | 1,48 Gb Available in Paging File | 89,49% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas
Drive C: | 74,55 Gb Total Space | 36,11 Gb Free Space | 48,43% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 149,04 Gb Total Space | 88,17 Gb Free Space | 59,16% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CAT
Current User Name: usuario
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ========== [2002/07/01 08:02:00 | 00,062,464 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\system32\E_S00RP1.EXE
[2005/01/28 02:36:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe
[2004/08/03 19:45:46 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
[2004/08/22 18:05:02 | 00,081,920 | ---- | M] (DAEMON'S HOME) -- C:\Arquivos de programas\D-Tools\daemon.exe
[2004/01/14 09:00:00 | 00,099,840 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I4T1.EXE
[2007/01/19 13:54:56 | 05,674,352 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\MSN Messenger\msnmsgr.exe
[2008/10/23 14:57:36 | 00,417,792 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\usuario\Desktop\OTListIt.exe
========== (O23) Win32 Services ========== [2003/08/30 19:41:41 | 00,068,096 | ---- | M] () -- C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service [On_Demand | Stopped])
[2008/01/15 03:40:04 | 00,110,592 | ---- | M] (Apple, Inc.) -- C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Disabled | Stopped])
[2004/07/15 02:49:26 | 00,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2003/09/30 11:19:56 | 00,376,832 | ---- | M] () -- C:\WINDOWS\system32\ati2evxx.exe -- (Ati HotKey Poller [Disabled | Stopped])
[2003/10/13 22:10:00 | 00,114,688 | ---- | M] () -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart [Disabled | Stopped])
[2007/07/24 16:17:08 | 00,229,376 | ---- | M] (Apple Inc.) -- C:\Arquivos de programas\Bonjour\mDNSResponder.exe -- (Bonjour Service [Disabled | Stopped])
[2003/05/23 02:38:26 | 00,106,496 | ---- | M] (Matsushita Electric Industrial Co., Ltd.) -- C:\WINDOWS\system32\DVDRAMSV.exe -- (DVD-RAM_Service [Disabled | Stopped])
[2002/07/01 08:02:00 | 00,062,464 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\system32\E_S00RP1.EXE -- (EPSON_PM_RPCV2_01 [Auto | Running])
[2004/08/20 15:46:35 | 00,040,960 | ---- | M] (F-Secure Corporation) -- C:\Arquivos de programas\F-Secure Internet Security\fswsclds.exe -- (Fswsclds [Disabled | Stopped])
[2005/04/04 01:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2008/03/30 11:36:30 | 00,504,104 | ---- | M] (Apple Inc.) -- C:\Arquivos de programas\iPod\bin\iPodService.exe -- (iPod Service [Disabled | Stopped])
[2003/06/19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\MDM.EXE -- (MDM [Disabled | Stopped])
[2003/07/28 20:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE -- (ose [Disabled | Stopped])
[2008/04/07 20:26:40 | 00,098,488 | ---- | M] (SiSoftware) -- C:\Arquivos de programas\SiSoftware\SiSoftware Sandra Professional Business XII.SP2\RpcAgentSrv.exe -- (SandraAgentSrv [Disabled | Stopped])
[2003/07/02 07:40:08 | 00,045,056 | ---- | M] ( ) -- C:\WINDOWS\system32\slserv.exe -- (SLService [Disabled | Stopped])
[2005/04/05 12:17:22 | 00,206,552 | ---- | M] (Symantec Corporation) -- C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [On_Demand | Stopped])
[2002/09/20 17:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default) [Disabled | Stopped])
[2005/01/28 02:36:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running])
[2007/01/19 13:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\MSN Messenger\usnsvc.exe -- (usnjsvc [Disabled | Stopped])
========== Driver Services ========== [2002/04/01 04:15:00 | 00,004,816 | ---- | M] (Andrea Electronics Corporation) -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (aeaudio [On_Demand | Running])
[2003/05/28 19:53:46 | 00,017,005 | ---- | M] (Adaptec) -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32 [Auto | Running])
[2005/08/31 03:11:52 | 00,701,440 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
[2002/06/06 02:07:00 | 00,009,344 | ---- | M] (B.H.A Co.,Ltd.) -- C:\WINDOWS\System32\drivers\BsStor.sys -- (BsStor [Boot | Running])
[2004/03/08 13:55:50 | 00,013,567 | ---- | M] (B.H.A Corporation) -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS -- (cdrbsdrv [System | Running])
[2003/12/03 18:44:58 | 00,013,566 | ---- | M] (B.H.A Corporation) -- C:\WINDOWS\System32\drivers\cdrbsvsd.sys -- (cdrbsvsd [System | Running])
[2004/08/22 17:31:10 | 00,155,136 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\d347bus.sys -- (d347bus [Boot | Running])
[2004/08/22 17:31:48 | 00,005,248 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\d347prt.sys -- (d347prt [Boot | Running])
[2002/11/28 12:18:04 | 00,015,360 | ---- | M] (Elaborate Bytes AG) -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL [On_Demand | Running])
[2002/11/29 09:38:16 | 00,016,320 | ---- | M] (Elaborate Bytes AG) -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO [Auto | Running])
[2003/01/31 21:08:54 | 00,028,005 | ---- | M] (Efficient Networks, Inc.) -- C:\WINDOWS\system32\drivers\enethusb.sys -- (ENETHUSB [On_Demand | Running])
[2001/08/17 21:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. ) -- C:\WINDOWS\system32\drivers\fetnd5.sys -- (FETNDIS [On_Demand | Stopped])
[2003/01/16 02:17:00 | 00,040,960 | R--- | M] (VIA Technologies, Inc. ) -- C:\WINDOWS\system32\drivers\fetnd5b.sys -- (FETNDISB [On_Demand | Stopped])
[2008/01/29 13:01:28 | 00,016,168 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
[2003/08/21 12:56:36 | 00,025,520 | ---- | M] (Ahead Software AG) -- C:\WINDOWS\System32\drivers\incdrm.sys -- (incdrm [System | Running])
[2003/10/24 02:53:14 | 00,090,416 | ---- | M] (Matsushita Electric Industrial Co.,Ltd.) -- C:\WINDOWS\system32\drivers\meiudf.sys -- (meiudf [System | Running])
[2001/08/17 22:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Running])
[2003/07/16 02:30:26 | 00,221,736 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\mtlmnt5.sys -- (Mtlmnt5 [On_Demand | Running])
[2003/07/02 06:26:36 | 01,301,128 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\mtlstrm.sys -- (Mtlstrm [On_Demand | Stopped])
[2005/08/31 03:11:26 | 00,032,840 | ---- | M] (NETGEAR Corporation.) -- C:\WINDOWS\system32\drivers\Ngrpci.sys -- (ngrpci [On_Demand | Stopped])
[2003/07/02 05:57:10 | 00,167,384 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\ntmtlfax.sys -- (NtMtlFax [On_Demand | Stopped])
[2002/09/12 22:29:00 | 00,006,016 | R--- | M] (VIA Technologies, Inc. ) -- C:\WINDOWS\system32\ntsim.sys -- (NTSIM [On_Demand | Stopped])
[2008/06/19 17:24:30 | 00,028,544 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot [Boot | Running])
[2007/05/28 20:39:19 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\system32\drivers\pcouffin.sys -- (Pcouffin [On_Demand | Running])
[2004/01/31 00:40:08 | 00,010,368 | ---- | M] (Padus, Inc.) -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc [On_Demand | Running])
[2001/10/28 09:07:22 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2007/02/23 02:29:52 | 00,036,624 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2004/08/04 04:41:40 | 00,013,776 | ---- | M] (Smart Link) -- C:\WINDOWS\system32\drivers\recagent.sys -- (RecAgent [On_Demand | Stopped])
[2002/06/10 01:09:08 | 00,031,232 | ---- | M] (Robert Schlabbach) -- C:\WINDOWS\system32\drivers\RMSPPPOE.SYS -- (RMSPPPOE [On_Demand | Running])
[2008/03/10 20:30:36 | 00,021,408 | ---- | M] (SiSoftware) -- C:\Arquivos de programas\SiSoftware\SiSoftware Sandra Professional Business XII.SP2\WNt500x86\sandra.sys -- (SANDRA [On_Demand | Stopped])
[2007/11/13 08:25:56 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2001/09/05 23:27:44 | 00,018,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\sermouse.sys -- (sermouse [On_Demand | Stopped])
[2003/07/16 02:39:32 | 00,545,528 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\slntamr.sys -- (Slntamr [On_Demand | Running])
[2003/07/02 06:24:36 | 00,086,128 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\slnthal.sys -- (SlNtHal [On_Demand | Stopped])
[2003/07/02 06:12:52 | 00,039,348 | ---- | M] (Vireo Software) -- C:\WINDOWS\system32\drivers\slwdmsup.sys -- (SlWdmSup [On_Demand | Running])
[2003/07/15 17:00:00 | 00,578,368 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])
[2001/08/17 21:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
[2006/09/15 23:52:12 | 00,124,016 | ---- | M] (Symantec Corporation) -- C:\Arquivos de programas\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
[2005/04/05 12:17:00 | 00,017,976 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symredrv.sys -- (SYMREDRV [On_Demand | Stopped])
[2005/04/05 12:17:02 | 00,267,192 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symtdi.sys -- (SYMTDI [System | Running])
[2003/07/02 05:42:00 | 00,027,904 | ---- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\system32\drivers\VIAAGP1.SYS -- (viaagp1 [Boot | Running])
[2005/09/01 10:22:22 | 00,077,312 | ---- | M] (VIA Technologies inc,.ltd) -- C:\WINDOWS\system32\drivers\viasraid.sys -- (viasraid [Boot | Running])
[2003/08/04 05:29:08 | 00,006,912 | ---- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\system32\drivers\vulfnth.sys -- (vulfnths [On_Demand | Running])
[2003/08/04 05:29:32 | 00,011,392 | ---- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\system32\drivers\vulfntr.sys -- (vulfntrs [On_Demand | Running])
========== Internet Explorer ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhomeHKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieHKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htmHKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieHKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comHKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comHKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieHKU\S-1-5-21-220523388-688789844-1417001333-1003\S-1-5-21-220523388-688789844-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (316782 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 0.0.0.0 acestats.com
O1 - Hosts: 0.0.0.0 www.acestats.com
O1 - Hosts: 0.0.0.0 www.activesearch.com #[Adware.ActiveSearch]
O1 - Hosts: 0.0.0.0 actualnames.com #[Parasite.ActualNames][Spyware.ActualNames]
O1 - Hosts: 0.0.0.0 www.actualnames.com
O1 - Hosts: 0.0.0.0 ad-up.com
O1 - Hosts: 0.0.0.0 www.ad-up.com
O1 - Hosts: 0.0.0.0 adatom.com
O1 - Hosts: 0.0.0.0 aesp.adatom.com
O1 - Hosts: 0.0.0.0 adbest.com #[IE-SpyAd]
O1 - Hosts: 0.0.0.0 www.adcipta.net #[W32/Malware]
O1 - Hosts: 0.0.0.0 adserv.adbonus.com #[IE-SpyAd]
O1 - Hosts: 0.0.0.0 www.adbonus.com
O1 - Hosts: 0.0.0.0 media.adcentriconline.com #[IE-SpyAd]
O1 - Hosts: 0.0.0.0 ad2.adcept.net
O1 - Hosts: 0.0.0.0 ad3.adcept.net
O1 - Hosts: 0.0.0.0 www.adcept.net #[IE-SpyAd]
O1 - Hosts: 0.0.0.0 adcomplete.com #[IE-SpyAd]
O1 - Hosts: 0.0.0.0 www.adcomplete.com
O1 - Hosts: 0.0.0.0 www.adcopy.info
O1 - Hosts: 0.0.0.0 ads.adcorps.com #[verticalwebventures.com]
O1 - Hosts: 0.0.0.0 ads2.adcorps.com
O1 - Hosts: 0.0.0.0 ads.addynamix.com #[IE-SpyAd]
O1 - Hosts: 0.0.0.0 pt.server1.adexit.com
O1 - Hosts: 9001 more lines...
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\Arquivos de programas\TEXTware\QUICKfind\PlugIns\IEHelp.dll ()
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\..\Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\..\Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033 (DAEMON'S HOME)
O4 - HKCU..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE /P23 "EPSON Stylus C45 Series" /M "Stylus C45" /EF "HKCU" (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-220523388-688789844-1417001333-1003..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE /P23 "EPSON Stylus C45 Series" /M "Stylus C45" /EF "HKCU" (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-220523388-688789844-1417001333-1003..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMorePrograms = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingPage = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMorePrograms = 0
O7 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogOff = 0
O7 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O7 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingPage = 1
O7 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - Reg Error: Value does not exist or could not be read.
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key does not exist or could not be opened. File not found
O9 - Extra Button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Arquivos de programas\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Web Entry - {B4E30F61-16D9-11D3-85D1-005004229569} - c:\lotus\organize\bandobjs.dll ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (Microsoft Corporation)
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\PLUGINS\NPDocBox.dll [2001/01/30 14:56:24 | 00,225,280 | ---- | M] (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: (msn in Meu computador)
O15 - HKU\S-1-5-21-220523388-688789844-1417001333-1003\..Trusted Sites: (msn in Meu computador)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/products/plugin/1.4/ji...indows-i586.cab (Java Plug-in 1.4.1_01)
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/1.4/ji...indows-i586.cab (Java Plug-in 1.4.1_01)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 192.168.254.254
O18 - Protocol\Handler: - cetihpz - C:\Arquivos de programas\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - livecall - C:\Arquivos de programas\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-itss - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\Arquivos de programas\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap11 - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
========== LSA *Authentication Packages* ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,C:\WINDOWS\system32\awtUOefC,
>File not found --
========== Safeboot Options ========== "AlternateShell" = cmd.exe
========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ========== autoAlbum.log [-i="C:\Documents and Settings\usuario\Configurações locais\Dados de aplicativos\HP\Digital Imaging\tmpAlb_2\tmpAlb_2_0.txt" -o="C:\Documents and Settings\usuario\Configurações locais\Dados de aplicativos\HP\Digital Imaging\tmpAlb_2\tmpAlb_2_0_out.txt" -g -b -s=4 -f="text"input text file: C:\Documents and Settings\usuario\Configurações locais\Dados de aplicativos\HP\Digital Imaging\tmpAlb_2\tmpAlb_2_0.txt | output file: C:\Documents and Settings\usuario\Configurações locais\Dados de aplicativos\HP\Digital Imaging\tmpAlb_2\tmpAlb_2_0_out.txt | | Value of width is 1529 and ht is 1284creating book layout ... | layout is complete, writing output file of type 1... | ]
[2005/03/12 16:24:16 | 00,000,667 | ---- | M] () -- C:\autoAlbum.log -- [ NTFS ]
AUTOEXEC.BAT [PATH=%PATH%;C:\ARQUIV~1\ARQUIV~1\MUVEET~1\030625 | ]
[2006/05/23 13:29:55 | 00,000,050 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
AUTOEXEC.BAT []
[2008/05/18 14:58:35 | 00,000,000 | ---- | M] () -- G:\AUTOEXEC.BAT -- [ NTFS ]
========== Files/Folders - Created Within 30 Days ========== [3 C:\Documents and Settings\All Users\Dados de aplicativos\*.tmp files]
[2008/10/23 14:57:33 | 00,417,792 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\usuario\Desktop\OTListIt.exe
[2008/10/23 14:37:22 | 49,801,8304 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\Imagine - The Story of the Guitar, Out of the Frying Pan (12th October 2008) [TVRip (XviD)].avi
[2008/10/23 14:12:46 | 00,014,413 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\The Longest Yard.torrent
[2008/10/23 08:25:20 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\usuario\Meus documentos\members need deleting.doc
[2008/10/21 08:16:52 | 00,063,755 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\smallvilleavvy.jpg
[2008/10/21 08:09:04 | 00,047,527 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\smallville.jpg
[2008/10/20 18:25:33 | 00,017,006 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\13.Hours.In.A.Warehouse.2008.DVDRip.XviD-DOMiNO(2).torrent
[2008/10/20 17:23:36 | 00,025,088 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\Adopt a torrent.doc
[2008/10/20 13:15:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\usuario\Desktop\Washington DC Suburb Offers Tale of Two Economies
[2008/10/16 10:47:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\usuario\Desktop\FixPolicies
[2008/10/16 10:46:33 | 00,185,065 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\FixPolicies.exe
[2008/10/16 08:47:22 | 00,025,088 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\Fix.doc
[2008/10/15 20:36:57 | 00,030,720 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\Malwarebytes Full report.doc
[2008/10/15 18:25:41 | 00,028,544 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\pavboot.sys
[2008/10/15 18:13:56 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Panda Security
[2008/10/15 18:13:29 | 00,175,648 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\activescan2_en.exe
[2008/10/15 18:10:31 | 00,001,806 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\HijackThis.lnk
[2008/10/15 18:10:30 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Trend Micro
[2008/10/15 10:48:18 | 00,001,632 | ---- | C] () -- C:\Documents and Settings\usuario\Desktop\CCleaner.lnk
[2008/10/15 10:40:58 | 01,392,109 | -HS- | C] () -- C:\WINDOWS\System32\clnxdwxy.ini
[2008/10/15 09:30:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\usuario\Dados de aplicativos\Malwarebytes
[2008/10/15 09:30:06 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008/10/15 09:30:06 | 00,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/10/15 09:30:05 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/10/15 09:30:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Malwarebytes
[2008/10/15 09:30:02 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\Malwarebytes' Anti-Malware
[2008/10/15 08:53:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:DFC5A2B2
[2008/10/15 08:51:29 | 00,074,752 | ---- | C] () -- C:\WINDOWS\System32\YUR11.exe
[2008/10/15 08:44:12 | 00,024,064 | ---- | C] () -- C:\WINDOWS\System32\YUR4.exe
[2008/10/15 08:44:11 | 00,025,088 | ---- | C] () -- C:\WINDOWS\System32\YUR3.exe
[2008/10/15 08:44:10 | 00,025,088 | ---- | C] () -- C:\WINDOWS\System32\YUR1.exe
[2008/10/15 08:44:10 | 00,024,064 | ---- | C] () -- C:\WINDOWS\System32\YUR2.exe
[2008/10/15 08:38:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\usuario\Dados de aplicativos\TmpRecentIcons
[2008/10/15 08:38:37 | 00,094,208 | ---- | C] () -- C:\WINDOWS\evsw.exe
[2008/10/15 08:38:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\usuario\Dados de aplicativos\0000005738
[2008/10/15 08:37:46 | 00,701,952 | ---- | C] () -- C:\0000005738.exe
[2008/10/15 08:37:39 | 00,025,088 | ---- | C] () -- C:\WINDOWS\System32\YUR18.exe
[2008/10/15 08:37:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\wpebgbmb
[2008/10/15 08:37:17 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\vqfsvgvs.exe
[2008/10/14 14:14:30 | 00,000,000 | ---D | C] -- C:\Arquivos de programas\HalloweenPack
[2008/10/09 16:09:26 | 00,001,445 | ---- | C] () -- C:\Documents and Settings\usuario\Meus documentos\Candy nfo.nfo
[2008/10/07 16:25:36 | 00,033,792 | ---- | C] () -- C:\Documents and Settings\All Users\Documentos\Curriculum Vitae - Mateus.doc
[2008/10/05 21:44:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documentos\Burn.Notice.S01.DVDRip.XviD-TOPAZ
========== Files - Modified Within 30 Days ========== [2 C:\*.tmp files]
[3 C:\WINDOWS\System32\*.tmp files]
[8 C:\WINDOWS\*.tmp files]
[3 C:\Documents and Settings\All Users\Dados de aplicativos\*.tmp files]
[2008/10/23 14:57:36 | 00,417,792 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\usuario\Desktop\OTListIt.exe
[2008/10/23 14:57:18 | 00,368,128 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\Torrential Greetings.doc
[2008/10/23 14:40:25 | 00,080,384 | ---- | M] () -- C:\Documents and Settings\usuario\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/23 14:12:44 | 00,014,413 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\The Longest Yard.torrent
[2008/10/23 14:00:00 | 00,000,274 | -H-- | M] () -- C:\WINDOWS\tasks\ABABD9D491884F38.job
[2008/10/23 08:25:20 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\usuario\Meus documentos\members need deleting.doc
[2008/10/23 08:01:02 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/10/23 08:01:00 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008/10/23 08:00:59 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008/10/22 08:14:02 | 00,000,300 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008/10/21 08:16:52 | 00,063,755 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\smallvilleavvy.jpg
[2008/10/21 08:10:05 | 00,047,527 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\smallville.jpg
[2008/10/20 18:25:32 | 00,017,006 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\13.Hours.In.A.Warehouse.2008.DVDRip.XviD-DOMiNO(2).torrent
[2008/10/20 17:23:36 | 00,025,088 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\Adopt a torrent.doc
[2008/10/16 20:25:46 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/10/16 20:25:34 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008/10/16 10:46:04 | 00,185,065 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\FixPolicies.exe
[2008/10/16 10:39:45 | 00,076,648 | ---- | M] () -- C:\Documents and Settings\usuario\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT
[2008/10/16 10:39:21 | 00,270,984 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/10/16 08:51:02 | 00,000,142 | ---- | M] () -- C:\WINDOWS\TEXTware.ini
[2008/10/16 08:47:22 | 00,025,088 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\Fix.doc
[2008/10/15 20:36:57 | 00,030,720 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\Malwarebytes Full report.doc
[2008/10/15 18:13:45 | 00,175,648 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\activescan2_en.exe
[2008/10/15 18:10:31 | 00,001,806 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\HijackThis.lnk
[2008/10/15 11:23:16 | 00,000,477 | ---- | M] () -- C:\WINDOWS\win.ini
[2008/10/15 11:23:16 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2008/10/15 11:23:16 | 00,000,210 | RHS- | M] () -- C:\boot.ini
[2008/10/15 10:41:08 | 01,392,109 | -HS- | M] () -- C:\WINDOWS\System32\clnxdwxy.ini
[2008/10/15 09:30:06 | 00,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/10/15 08:54:31 | 00,339,292 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat
[2008/10/15 08:54:31 | 00,305,898 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2008/10/15 08:54:31 | 00,046,778 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat
[2008/10/15 08:54:31 | 00,038,148 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2008/10/15 08:54:30 | 00,737,568 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2008/10/15 08:47:40 | 00,701,952 | ---- | M] () -- C:\0000005738.exe
[2008/10/15 08:37:17 | 00,077,824 | ---- | M] () -- C:\WINDOWS\System32\vqfsvgvs.exe
[2008/10/15 03:15:18 | 00,094,208 | ---- | M] () -- C:\WINDOWS\evsw.exe
[2008/10/14 17:01:19 | 49,801,8304 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\Imagine - The Story of the Guitar, Out of the Frying Pan (12th October 2008) [TVRip (XviD)].avi
[2008/10/12 18:15:48 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2008/10/10 10:54:43 | 00,074,752 | ---- | M] () -- C:\WINDOWS\System32\YUR11.exe
[2008/10/10 10:54:42 | 00,024,064 | ---- | M] () -- C:\WINDOWS\System32\YUR2.exe
[2008/10/10 10:54:41 | 00,025,088 | ---- | M] () -- C:\WINDOWS\System32\YUR3.exe
[2008/10/10 10:54:41 | 00,025,088 | ---- | M] () -- C:\WINDOWS\System32\YUR18.exe
[2008/10/10 10:54:41 | 00,025,088 | ---- | M] () -- C:\WINDOWS\System32\YUR1.exe
[2008/10/10 10:54:41 | 00,024,064 | ---- | M] () -- C:\WINDOWS\System32\YUR4.exe
[2008/10/09 23:47:44 | 00,421,888 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\Welcome1.doc
[2008/10/08 18:09:25 | 00,001,445 | ---- | M] () -- C:\Documents and Settings\usuario\Meus documentos\Candy nfo.nfo
[2008/10/06 12:54:47 | 00,000,192 | ---- | M] () -- C:\WINDOWS\winamp.ini
[2008/10/04 19:30:54 | 00,036,352 | ---- | M] () -- C:\Documents and Settings\usuario\Desktop\PreToMe.doc
[2008/09/27 08:21:37 | 00,000,597 | ---- | M] () -- C:\Documents and Settings\usuario\Meus documentos\My Sharing Folders.lnk
< End of report >