Logo Hardware.com.br
katielly
katielly Novo Membro Registrado
13 Mensagens 0 Curtidas

como remover BackDoor.Turkojan?

#1 Por katielly 21/10/2010 - 11:52
Olá
Gostaria de saber como remover do meu PC o BackDoor Turkojan.
Meu anti vírus é o AVG Free 2011.
Meu anti-vírus detectou o backdoor e removeu-o p/ a quarentena. Mas, ainda não me sinto segura. Gostaria portanto de eliminar, destri-lo do meu PC.
Como saber também se existem outros backdoor instalado no meu PC? Meu anti-virus não detecta mais nenhum outo. Posso então ficar mais tranquila?
Grata
Katielly Itikawa
Wings
Wings Cyber Highlander Registrado
20.3K Mensagens 1.2K Curtidas
#2 Por Wings
21/10/2010 - 11:53
Olá katielly

*Desative seu antivírus temporariamente

Clique em [Iniciar] > [Programas] > [AVG]
Abra a Interface do usuário do AVG
Duplo clique na Proteção Residente
Desmarque a opção "Proteção Residente ativa"
Salve as alterações
*Baixe o RSIT e salve-o no desktop
*Execute o RSIT e clique [Continue]
*Cole o relatório C:\rsit\log.txt
katielly
katielly Novo Membro Registrado
13 Mensagens 0 Curtidas
#5 Por katielly
21/10/2010 - 13:19
apareceu isso:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Usuario at 2010-10-21 13:18:06
Microsoft Windows XP Professional Service Pack 3
System drive H: has 256 GB (84%) free of 305 GB
Total RAM: 1470 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:18:22, on 21/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
H:\WINDOWS\System32\smss.exe
H:\ARQUIV~1\AVG\AVG10\avgchsvx.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\ARQUIV~1\GbPlugin\GbpSv.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe
H:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe
H:\WINDOWS\system32\VTTimer.exe
H:\WINDOWS\system32\VTtrayp.exe
H:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe
H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe
H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
H:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe
H:\Arquivos de programas\AVG\AVG10\avgtray.exe
H:\WINDOWS\system32\ctfmon.exe
H:\WINDOWS\system32\svchost.exe
H:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
H:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
H:\Arquivos de programas\AVG\AVG10\avgwdsvc.exe
H:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe
H:\Arquivos de programas\Java\jre6\bin\jqs.exe
H:\Arquivos de programas\BrOffice.org 3\program\soffice.exe
H:\Arquivos de programas\BrOffice.org 3\program\soffice.bin
H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe
H:\Arquivos de programas\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\SearchIndexer.exe
H:\Arquivos de programas\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
H:\Arquivos de programas\AVG\AVG10\avgnsx.exe
H:\Arquivos de programas\AVG\AVG10\avgemcx.exe
H:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe
H:\WINDOWS\System32\alg.exe
H:\Arquivos de programas\Mozilla Firefox\firefox.exe
H:\Arquivos de programas\Mozilla Firefox\plugin-container.exe
H:\ARQUIV~1\AVG\AVG10\avgrsx.exe
H:\Arquivos de programas\AVG\AVG10\avgcsrvx.exe
H:\Documents and Settings\Usuario\Meus documentos\Downloads\RSIT.exe
H:\WINDOWS\system32\SearchProtocolHost.exe
H:\WINDOWS\system32\SearchFilterHost.exe
H:\WINDOWS\system32\wbem\wmiprvse.exe
H:\Arquivos de programas\trend micro\Usuario.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/accounts/ServiceLogin?service=orkut&hl=pt-BR&rm=false&cd=BR&passive=true&skipvpage=true&sendvemail=false&continue=http%3A%2F%2Fwww.orkut.com%2FRedirLogin%3Fmsg%3D0%26page%3D%252FMain
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - H:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Arquivos de programas\AVG\AVG10\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - H:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - H:\Arquivos de programas\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - H:\Arquivos de programas\GbPlugin\gbieh.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - H:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - H:\Arquivos de programas\AVG\AVG10\Toolbar\IEToolbar.dll
O3 - Toolbar: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] H:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "H:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "H:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RemoteControl] "H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "H:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [HP Software Update] H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AVG_TRAY] H:\Arquivos de programas\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "H:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "H:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: BrOffice.org 3.2.lnk = H:\Arquivos de programas\BrOffice.org 3\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = H:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Windows Search.lnk = H:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://H:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O15 - Trusted Zone: www.bancobrasil.com.br
O15 - Trusted Zone: www14.bancobrasil.com.br
O15 - Trusted Zone: www2.bancobrasil.com.br
O15 - Trusted Zone: www.bb.com.br
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1275413637703
O16 - DPF: {7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} (Qualys BrowserCheck) - https://browsercheck.qualys.com/qbc_ax.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C94695E-F97B-491E-8D24-FF9175C142FB}: NameServer = 200.204.0.10 200.204.0.138
O17 - HKLM\System\CS1\Services\Tcpip\..\{4C94695E-F97B-491E-8D24-FF9175C142FB}: NameServer = 200.204.0.10 200.204.0.138
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - H:\Arquivos de programas\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - H:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Arquivos de programas\AVG\AVG10\avgpp.dll
O20 - Winlogon Notify: GbPluginBb - H:\Arquivos de programas\GbPlugin\gbieh.dll
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - H:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - H:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Security Toolbar Service - Unknown owner - H:\Arquivos de programas\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - H:\Arquivos de programas\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Watchdog do AVG (avgwd) - AVG Technologies CZ, s.r.o. - H:\Arquivos de programas\AVG\AVG10\avgwdsvc.exe
O23 - Service: Gbp Service (GbpSv) - - H:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - H:\Arquivos de programas\Java\jre6\bin\jqs.exe
O23 - Service: NMIndexingService - Unknown owner - H:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - H:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe

--
End of file - 11200 bytes

======Scheduled tasks folder======

H:\WINDOWS\tasks\OGALogon.job
H:\WINDOWS\tasks\User_Feed_Synchronization-{003402A5-DA35-4871-88E3-8A1EF26EFF4C}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - H:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - H:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - H:\Arquivos de programas\AVG\AVG10\avgssie.dll [2010-09-16 2890592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - H:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Auxiliar de Conexão do Windows Live - H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - H:\Arquivos de programas\AVG\AVG10\Toolbar\IEToolbar.dll [2010-08-27 2565448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540000}]
GbIehObj Class - H:\Arquivos de programas\GbPlugin\gbieh.dll [2010-09-29 342304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - H:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll [2010-07-17 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - H:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-07-17 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - H:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - H:\Arquivos de programas\AVG\AVG10\Toolbar\IEToolbar.dll [2010-08-27 2565448]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Barra de Ferramentas do Yahoo! - H:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=H:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"SoundMAX"=H:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe [2005-09-07 716800]
"VTTimer"=H:\WINDOWS\system32\VTTimer.exe [2010-05-31 53248]
"VTTrayp"=H:\WINDOWS\system32\VTtrayp.exe [2010-05-31 163840]
"GrooveMonitor"=H:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"RemoteControl"=H:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
"LanguageShortcut"=H:\Arquivos de programas\CyberLink\PowerDVD\Language\Language.exe [2007-01-08 52256]
"HP Software Update"=H:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe [2010-06-09 49208]
""= []
"SunJavaUpdateSched"=H:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe [2010-05-14 248552]
"AVG_TRAY"=H:\Arquivos de programas\AVG\AVG10\avgtray.exe [2010-09-15 2745696]
"Adobe Reader Speed Launcher"=H:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=H:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=H:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"msnmsgr"=H:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe [2010-04-16 3872080]

H:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar
HP Digital Imaging Monitor.lnk - H:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe
Windows Search.lnk - H:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe

H:\Documents and Settings\Usuario\Menu Iniciar\Programas\Inicializar
BrOffice.org 3.2.lnk - H:\Arquivos de programas\BrOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ GbPluginBb]
H:\Arquivos de programas\GbPlugin\gbieh.dll [2010-09-29 342304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
H:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=H:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=H:\Arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
"{E37CB5F0-51F5-4395-A808-5FA49E399F83}"=H:\Arquivos de programas\GbPlugin\gbieh.dll [2010-09-29 342304]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveTypeAutoRun"=60

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="H:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"H:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="H:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"H:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE"="H:\Arquivos de programas\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"H:\Arquivos de programas\Microsoft Office\Office12\GROOVE.EXE"="H:\Arquivos de programas\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"H:\Arquivos de programas\Microsoft Office\Office12\ONENOTE.EXE"="H:\Arquivos de programas\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"H:\Arquivos de programas\LimeWire\LimeWire.exe"="H:\Arquivos de programas\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hpofxm08.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hposfx08.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hposid01.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hpqscnvw.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hpqkygrp.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hpqCopy.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hpfccopy.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hpzwiz01.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"H:\Arquivos de programas\HP\Digital Imaging\Unload\HpqPhUnl.exe"="H:\Arquivos de programas\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"H:\Arquivos de programas\HP\Digital Imaging\Unload\HpqDIA.exe"="H:\Arquivos de programas\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hpoews01.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"H:\Arquivos de programas\HP\Digital Imaging\bin\hpqnrs08.exe"="H:\Arquivos de programas\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"H:\Arquivos de programas\Messenger\msmsgs.exe"="H:\Arquivos de programas\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"H:\Arquivos de programas\Internet Explorer\iexplore.exe"="H:\Arquivos de programas\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"H:\WINDOWS\system32\sessmgr.exe"="H:\WINDOWS\system32\sessmgr.exe:*big_green.pngisabled:@xpsp2res.dll,-22019"
"H:\Arquivos de programas\AVG\AVG10\avgmfapx.exe"="H:\Arquivos de programas\AVG\AVG10\avgmfapx.exe:*:Enabled:Instalador do AVG"
"H:\Arquivos de programas\Mozilla Firefox\firefox.exe"="H:\Arquivos de programas\Mozilla Firefox\firefox.exe:*big_green.pngisabled:Firefox"
"H:\Arquivos de programas\AVG\AVG10\avgdiagex.exe"="H:\Arquivos de programas\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011"
"H:\Arquivos de programas\AVG\AVG10\avgnsx.exe"="H:\Arquivos de programas\AVG\AVG10\avgnsx.exe:*:Enabled:Proteção Online"
"H:\Arquivos de programas\AVG\AVG10\avgemcx.exe"="H:\Arquivos de programas\AVG\AVG10\avgemcx.exe:*:Enabled:Verificador Pessoal de E-mail"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"H:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe"="H:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"H:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe"="H:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======List of files/folders created in the last 1 months======

2010-10-21 13:02:16 ----D---- H:\Arquivos de programas\trend micro
2010-10-21 13:02:15 ----D---- H:\rsit
2010-10-13 16:57:24 ----HDC---- H:\WINDOWS\$NtUninstallKB2387149$
2010-10-13 16:56:58 ----HDC---- H:\WINDOWS\$NtUninstallKB2279986$
2010-10-13 16:56:46 ----HDC---- H:\WINDOWS\$NtUninstallKB2345886$
2010-10-13 16:56:37 ----HDC---- H:\WINDOWS\$NtUninstallKB2296011$
2010-10-13 16:56:13 ----HDC---- H:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-10-13 16:55:08 ----HDC---- H:\WINDOWS\$NtUninstallKB982132$
2010-10-13 16:53:34 ----HDC---- H:\WINDOWS\$NtUninstallKB979687$
2010-10-13 16:44:33 ----HDC---- H:\WINDOWS\$NtUninstallKB981957$
2010-10-13 16:44:22 ----HDC---- H:\WINDOWS\$NtUninstallKB2360937$
2010-10-06 14:13:01 ----D---- H:\Arquivos de programas\Adobe
2010-10-01 16:44:33 ----D---- H:\Documents and Settings\Usuario\Dados de aplicativos\Help
2010-09-30 15:48:50 ----D---- H:\Documents and Settings\All Users\Dados de aplicativos\PC Tools
2010-09-30 15:16:24 ----D---- H:\Documents and Settings\Usuario\Dados de aplicativos\AVG10
2010-09-30 15:15:15 ----HD---- H:\Documents and Settings\All Users\Dados de aplicativos\Common Files
2010-09-30 15:15:02 ----D---- H:\Documents and Settings\All Users\Dados de aplicativos\AVG Security Toolbar
2010-09-30 15:13:28 ----D---- H:\WINDOWS\system32\drivers\AVG
2010-09-30 15:13:28 ----D---- H:\Documents and Settings\All Users\Dados de aplicativos\AVG10
2010-09-30 14:57:08 ----D---- H:\Documents and Settings\All Users\Dados de aplicativos\MFAData
2010-09-28 16:02:20 ----HDC---- H:\WINDOWS\$NtUninstallKB2158563$

======List of files/folders modified in the last 1 months======

2010-10-21 13:12:45 ----D---- H:\Arquivos de programas\Mozilla Firefox
2010-10-21 13:11:55 ----D---- H:\WINDOWS\system32
2010-10-21 13:11:48 ----D---- H:\WINDOWS\system32\CatRoot2
2010-10-21 13:11:46 ----D---- H:\WINDOWS\Temp
2010-10-21 13:11:05 ----SHD---- H:\System Volume Information
2010-10-21 13:11:05 ----RD---- H:\Arquivos de programas
2010-10-21 13:11:05 ----D---- H:\Arquivos de programas\Arquivos comuns
2010-10-21 13:10:01 ----A---- H:\WINDOWS\SchedLgU.Txt
2010-10-21 13:09:51 ----AD---- H:\Documents and Settings\All Users\Dados de aplicativos\Temp
2010-10-21 13:09:04 ----D---- H:\WINDOWS\system32\drivers
2010-10-21 13:08:56 ----D---- H:\WINDOWS\Prefetch
2010-10-21 13:08:54 ----HD---- H:\WINDOWS\inf
2010-10-21 09:12:31 ----D---- H:\WINDOWS
2010-10-21 00:53:29 ----SHD---- H:\WINDOWS\Installer
2010-10-21 00:53:27 ----HD---- H:\Config.Msi
2010-10-21 00:53:24 ----D---- H:\WINDOWS\WinSxS
2010-10-19 13:58:27 ----D---- H:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin
2010-10-18 13:38:23 ----D---- H:\Documents and Settings\Usuario\Dados de aplicativos\Media Player Classic
2010-10-18 13:38:20 ----D---- H:\WINDOWS\Debug
2010-10-18 09:39:54 ----A---- H:\WINDOWS\system32\PerfStringBackup.INI
2010-10-13 16:59:08 ----D---- H:\Arquivos de programas\Internet Explorer
2010-10-13 16:57:33 ----RSHDC---- H:\WINDOWS\system32\dllcache
2010-10-13 16:57:15 ----HD---- H:\WINDOWS\$hf_mig$
2010-10-13 16:55:59 ----D---- H:\Documents and Settings\All Users\Dados de aplicativos\Microsoft Help
2010-10-13 16:51:30 ----D---- H:\WINDOWS\ie8updates
2010-10-13 16:48:23 ----D---- H:\Documents and Settings\Usuario\Dados de aplicativos\Image Zone Express
2010-10-13 16:44:41 ----A---- H:\WINDOWS\system32\MRT.exe
2010-10-10 13:37:20 ----D---- H:\WINDOWS\Microsoft.NET
2010-10-10 13:37:12 ----RSD---- H:\WINDOWS\assembly
2010-10-06 14:13:26 ----D---- H:\Arquivos de programas\Arquivos comuns\Adobe
2010-10-06 14:13:25 ----D---- H:\Documents and Settings\All Users\Dados de aplicativos\Adobe
2010-10-03 09:56:03 ----D---- H:\Arquivos de programas\GbPlugin
2010-09-30 15:08:47 ----D---- H:\Documents and Settings\All Users\Dados de aplicativos\avg9
2010-09-30 15:08:24 ----D---- H:\Arquivos de programas\AVG
2010-09-30 14:04:19 ----D---- H:\Arquivos de programas\Microsoft Silverlight

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSEH;AVGIDSEH; H:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver; H:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2010-09-07 26064]
R0 GbpKm;Gbp KernelMode; H:\WINDOWS\system32\drivers\gbpkm.sys [2010-09-29 45472]
R0 uagp35;Filtro Microsoft AGPv3.5; H:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-13 44672]
R1 Avgldx86;AVG AVI Loader Driver; H:\WINDOWS\system32\DRIVERS\avgldx86.sys [2010-09-07 249424]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; H:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2010-09-07 34384]
R1 Avgtdix;AVG TDI Driver; H:\WINDOWS\system32\DRIVERS\avgtdix.sys [2010-09-07 298448]
R1 intelppm;Driver de Processador Intel; H:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; H:\WINDOWS\system32\drivers\ADIHdAud.sys [2005-10-05 141312]
R3 AEAudioService;AEAudio Service; H:\WINDOWS\system32\drivers\AEAudio.sys [2005-03-04 127872]
R3 AgereSoftModem;Agere Systems Soft Modem; H:\WINDOWS\system32\DRIVERS\AGRSM.sys [2006-01-25 1149888]
R3 AVGIDSDriver;AVGIDSDriver; H:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys [2010-08-19 123472]
R3 AVGIDSFilter;AVGIDSFilter; H:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2010-08-19 30288]
R3 AVGIDSShim;AVGIDSShim; H:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [2010-08-19 26192]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; H:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 HDAudBus;Driver de Barramento Microsoft UAA para High Definition Audio; H:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 MTsensor;ATK0110 ACPI UTILITY; H:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-14 5810]
R3 SenFiltService;SenFilt Service; H:\WINDOWS\system32\drivers\Senfilt.sys [2005-08-11 393088]
R3 usbstor;USB Mass Storage Driver; H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; H:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 viagfx;viagfx; H:\WINDOWS\system32\DRIVERS\vtmini.sys [2010-05-31 244352]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; H:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; H:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-12 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; H:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
S3 usbccgp;Microsoft USB Generic Parent Driver; H:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; H:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; H:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; H:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; H:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Ambiente de suporte a provedores de serviços não-IFS do Windows Socket 2.0; H:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AVGIDSAgent;AVGIDSAgent; H:\Arquivos de programas\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-09-03 6104144]
R2 avgwd;Watchdog do AVG; H:\Arquivos de programas\AVG\AVG10\avgwdsvc.exe [2010-09-10 265400]
R2 GbpSv;Gbp Service; H:\ARQUIV~1\GbPlugin\GbpSv.exe [2010-09-29 55072]
R2 JavaQuickStarterService;Java Quick Starter; H:\Arquivos de programas\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); H:\Arquivos de programas\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 WSearch;Windows Search; H:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
S2 Pml Driver HPZ12;Pml Driver HPZ12; H:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
S3 aspnet_state;ASP.NET State Service; H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service; H:\Arquivos de programas\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-08-27 488776]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; h:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; h:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; h:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; H:\Arquivos de programas\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 NMIndexingService;NMIndexingService; H:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe []
S3 odserv;Microsoft Office Diagnostics Service; H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Serviço de Partilha de Rede do Windows Media Player; H:\Arquivos de programas\Windows Media Player\WMPNetwk.exe [2006-11-03 914944]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; H:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; h:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
katielly
katielly Novo Membro Registrado
13 Mensagens 0 Curtidas
#6 Por katielly
21/10/2010 - 13:21
e mais isso
info.txt logfile of random's system information tool 1.08 2010-10-21 13:18:26

======Uninstall list======

-->H:\ARQUIV~1\Yahoo!\Common\UNYT_W~1.EXE
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 H:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 ActiveX-->H:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_ActiveX.exe -maintain activex
Adobe Flash Player 10 Plugin-->H:\WINDOWS\system32\Macromed\Flash\FlashUtil10h_Plugin.exe -maintain plugin
Adobe Reader 9.4.0 - Português-->MsiExec.exe /I{AC76BA86-7AD7-1046-7B44-A94000000001}
Agere Systems PCI-SV92PP Soft Modem-->agrsmdel
Arquivo do WinRAR-->H:\Arquivos de programas\WinRAR\uninstall.exe
Assistente de Conexão do Windows Live-->MsiExec.exe /I{51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}
Atualização de Segurança para o Windows Media Player (KB2378111)-->"H:\WINDOWS\$NtUninstallKB2378111_WM9$\spuninst\spuninst.exe"
Atualização de Segurança para o Windows Media Player (KB952069)-->"H:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Atualização de Segurança para o Windows Media Player (KB954155)-->"H:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Atualização de Segurança para o Windows Media Player (KB973540)-->"H:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Atualização de Segurança para o Windows Media Player (KB975558)-->"H:\WINDOWS\$NtUninstallKB975558_WM8$\spuninst\spuninst.exe"
Atualização de Segurança para o Windows Media Player (KB978695)-->"H:\WINDOWS\$NtUninstallKB978695_WM9$\spuninst\spuninst.exe"
Atualização de Segurança para o Windows Media Player 11 (KB954154)-->"H:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Atualização de Segurança para Windows Internet Explorer 8 (KB2183461)-->"H:\WINDOWS\ie8updates\KB2183461-IE8\spuninst\spuninst.exe"
Atualização de Segurança para Windows Internet Explorer 8 (KB2360131)-->"H:\WINDOWS\ie8updates\KB2360131-IE8\spuninst\spuninst.exe"
Atualização de Segurança para Windows Internet Explorer 8 (KB971961)-->"H:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Atualização de Segurança para Windows Internet Explorer 8 (KB981332)-->"H:\WINDOWS\ie8updates\KB981332-IE8\spuninst\spuninst.exe"
Atualização de Segurança para Windows Internet Explorer 8 (KB982381)-->"H:\WINDOWS\ie8updates\KB982381-IE8\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2079403)-->"H:\WINDOWS\$NtUninstallKB2079403$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2115168)-->"H:\WINDOWS\$NtUninstallKB2115168$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2121546)-->"H:\WINDOWS\$NtUninstallKB2121546$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2160329)-->"H:\WINDOWS\$NtUninstallKB2160329$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2229593)-->"H:\WINDOWS\$NtUninstallKB2229593$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2259922)-->"H:\WINDOWS\$NtUninstallKB2259922$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2279986)-->"H:\WINDOWS\$NtUninstallKB2279986$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2286198)-->"H:\WINDOWS\$NtUninstallKB2286198$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2296011)-->"H:\WINDOWS\$NtUninstallKB2296011$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2347290)-->"H:\WINDOWS\$NtUninstallKB2347290$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2360937)-->"H:\WINDOWS\$NtUninstallKB2360937$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB2387149)-->"H:\WINDOWS\$NtUninstallKB2387149$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB923561)-->"H:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB941569)-->"H:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB946648)-->"H:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB950760)-->"H:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB950762)-->"H:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB950974)-->"H:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB951376-v2)-->"H:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB951748)-->"H:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB952004)-->"H:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB952954)-->"H:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB954459)-->"H:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB955069)-->"H:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB956572)-->"H:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB956744)-->"H:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB956802)-->"H:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB956803)-->"H:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB956844)-->"H:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB958644)-->"H:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB958869)-->"H:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB959426)-->"H:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB960225)-->"H:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB960803)-->"H:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB960859)-->"H:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB961501)-->"H:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB969059)-->"H:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB969947)-->"H:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB970238)-->"H:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB970430)-->"H:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB971468)-->"H:\WINDOWS\$NtUninstallKB971468$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB971657)-->"H:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB972270)-->"H:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB973507)-->"H:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB973869)-->"H:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB973904)-->"H:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB974112)-->"H:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB974318)-->"H:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB974392)-->"H:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB974571)-->"H:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB975025)-->"H:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB975467)-->"H:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB975560)-->"H:\WINDOWS\$NtUninstallKB975560$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB975561)-->"H:\WINDOWS\$NtUninstallKB975561$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB975562)-->"H:\WINDOWS\$NtUninstallKB975562$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB975713)-->"H:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB977816)-->"H:\WINDOWS\$NtUninstallKB977816$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB977914)-->"H:\WINDOWS\$NtUninstallKB977914$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB978037)-->"H:\WINDOWS\$NtUninstallKB978037$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB978262)-->"H:\WINDOWS\$NtUninstallKB978262$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB978338)-->"H:\WINDOWS\$NtUninstallKB978338$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB978542)-->"H:\WINDOWS\$NtUninstallKB978542$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB978601)-->"H:\WINDOWS\$NtUninstallKB978601$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB978706)-->"H:\WINDOWS\$NtUninstallKB978706$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB979309)-->"H:\WINDOWS\$NtUninstallKB979309$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB979482)-->"H:\WINDOWS\$NtUninstallKB979482$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB979559)-->"H:\WINDOWS\$NtUninstallKB979559$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB979683)-->"H:\WINDOWS\$NtUninstallKB979683$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB979687)-->"H:\WINDOWS\$NtUninstallKB979687$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB980195)-->"H:\WINDOWS\$NtUninstallKB980195$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB980218)-->"H:\WINDOWS\$NtUninstallKB980218$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB980232)-->"H:\WINDOWS\$NtUninstallKB980232$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB980436)-->"H:\WINDOWS\$NtUninstallKB980436$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB981322)-->"H:\WINDOWS\$NtUninstallKB981322$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB981852)-->"H:\WINDOWS\$NtUninstallKB981852$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB981957)-->"H:\WINDOWS\$NtUninstallKB981957$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB981997)-->"H:\WINDOWS\$NtUninstallKB981997$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB982132)-->"H:\WINDOWS\$NtUninstallKB982132$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB982214)-->"H:\WINDOWS\$NtUninstallKB982214$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB982665)-->"H:\WINDOWS\$NtUninstallKB982665$\spuninst\spuninst.exe"
Atualização de Segurança para Windows XP (KB982802)-->"H:\WINDOWS\$NtUninstallKB982802$\spuninst\spuninst.exe"
Atualização do Microsoft Windows (KB971513)-->"H:\WINDOWS\$NtUninstallKB971513$\spuninst\spuninst.exe"
Atualização do produto Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0416-0000-0000000FF1CE} /uninstall {717C9095-8AAE-41CB-B046-BD6E8399F4F3}
Atualização do produto Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-0416-0000-0000000FF1CE} /uninstall {5016CB22-B9A7-44FB-AA72-AF28B27B15EA}
Atualização do produto Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0416-0000-0000000FF1CE} /uninstall {BE3A7C0C-0081-4694-B5F9-980DD66BDDF8}
Atualização do produto Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0416-0000-0000000FF1CE} /uninstall {7297E3A9-FCD4-4E0E-A306-7A90359E50E3}
Atualização para Windows Internet Explorer 8 (KB976662)-->"H:\WINDOWS\ie8updates\KB976662-IE8\spuninst\spuninst.exe"
Atualização para Windows Internet Explorer 8 (KB980182)-->"H:\WINDOWS\ie8updates\KB980182-IE8\spuninst\spuninst.exe"
Atualização para Windows Internet Explorer 8 (KB982632)-->"H:\WINDOWS\ie8updates\KB982632-IE8\spuninst\spuninst.exe"
Atualização para Windows XP (KB2141007)-->"H:\WINDOWS\$NtUninstallKB2141007$\spuninst\spuninst.exe"
Atualização para Windows XP (KB2345886)-->"H:\WINDOWS\$NtUninstallKB2345886$\spuninst\spuninst.exe"
Atualização para Windows XP (KB898461)-->"H:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Atualização para Windows XP (KB951978)-->"H:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Atualização para Windows XP (KB955759)-->"H:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
Atualização para Windows XP (KB961503)-->"H:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
Atualização para Windows XP (KB967715)-->"H:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Atualização para Windows XP (KB968389)-->"H:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Atualização para Windows XP (KB971737)-->"H:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
Atualização para Windows XP (KB973687)-->"H:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Atualização para Windows XP (KB973815)-->"H:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
AVG 2011-->"H:\Arquivos de programas\AVG\AVG10\avgmfapx.exe" /AppMode=SETUP /Uninstall
AVG 2011-->MsiExec.exe /I{704BA20C-E4D5-4265-92B4-9768345AB76B}
AVG 2011-->MsiExec.exe /I{739F4CE3-6443-40AB-ACB3-2CF6FD3702AE}
Barra de Ferramentas do Yahoo!-->H:\ARQUIV~1\Yahoo!\Common\UNYT_W~1.EXE
BrOffice.org 3.2-->MsiExec.exe /I{1FD5861E-57EE-49F2-9854-93B846D4E54F}
CCleaner-->"H:\Arquivos de programas\CCleaner\uninst.exe"
DVD Suite-->RunDll32 H:\ARQUIV~1\ARQUIV~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "H:\Arquivos de programas\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
Ferramenta de Carregamento do Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->H:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->H:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)-->"H:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB915800-v4)-->"H:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
Hotfix para o Windows Media Player 11 (KB939683)-->"H:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix para Windows XP (KB2158563)-->"H:\WINDOWS\$NtUninstallKB2158563$\spuninst\spuninst.exe"
Hotfix para Windows XP (KB952287)-->"H:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix para Windows XP (KB961118)-->"H:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Hotfix para Windows XP (KB981793)-->"H:\WINDOWS\$NtUninstallKB981793$\spuninst\spuninst.exe"
HP Customer Participation Program 7.0-->H:\Arquivos de programas\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Imaging Device Functions 7.0-->H:\Arquivos de programas\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential-->MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F}
HP Photosmart, Officejet and Deskjet 7.0.A-->H:\Arquivos de programas\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat
HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
HP Solution Center 7.0-->H:\Arquivos de programas\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update-->MsiExec.exe /X{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}
J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Java(TM) 6 Update 21-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216020FF}
Microsoft .NET Framework 1.1 Brazilian Portuguese Language Pack-->MsiExec.exe /X{0CBADDF4-2CF6-4CDB-B4F5-29B8FCA7FE07}
Microsoft .NET Framework 1.1 Security Update (KB2416447)-->"H:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "H:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M2416447\M2416447Uninstall.msp"
Microsoft .NET Framework 1.1 Security Update (KB979906)-->"H:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "H:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M979906\M979906Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->H:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Compression Client Pack 1.0 for Windows XP-->"H:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0416-0000-0000000FF1CE} /uninstall {02A880E2-B8B9-4BF5-8822-EA1374734E2E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0416-0000-0000000FF1CE} /uninstall {02A880E2-B8B9-4BF5-8822-EA1374734E2E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0416-0000-0000000FF1CE} /uninstall {02A880E2-B8B9-4BF5-8822-EA1374734E2E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0416-0000-0000000FF1CE} /uninstall {02A880E2-B8B9-4BF5-8822-EA1374734E2E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0416-0000-0000000FF1CE} /uninstall {02A880E2-B8B9-4BF5-8822-EA1374734E2E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0416-0000-0000000FF1CE} /uninstall {02A880E2-B8B9-4BF5-8822-EA1374734E2E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-0416-0000-0000000FF1CE} /uninstall {02A880E2-B8B9-4BF5-8822-EA1374734E2E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0416-0000-0000000FF1CE} /uninstall {9A141B2B-7C5E-47D2-8E9E-9AC6018F3C42}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0416-0000-0000000FF1CE} /uninstall {02A880E2-B8B9-4BF5-8822-EA1374734E2E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00BA-0416-0000-0000000FF1CE} /uninstall {02A880E2-B8B9-4BF5-8822-EA1374734E2E}
Microsoft Office Access MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0015-0416-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"H:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0016-0416-0000-0000000FF1CE}
Microsoft Office Groove MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-00BA-0416-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0044-0416-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-00A1-0416-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-001A-0416-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0018-0416-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-001F-0416-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-002C-0416-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0416-0000-0000000FF1CE} /uninstall {75EBE365-7FC5-4720-A7D3-804BF550D1BC}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Publisher MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-0019-0416-0000-0000000FF1CE}
Microsoft Office Shared MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-006E-0416-0000-0000000FF1CE}
Microsoft Office Word MUI (Portuguese (Brazil)) 2007-->MsiExec.exe /X{90120000-001B-0416-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"H:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Mozilla Firefox (3.6.8)-->H:\Arquivos de programas\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
OCR Software by I.R.I.S 7.0-->H:\Arquivos de programas\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
Pacote de Provedor de Serviços de Criptografia para o Microsoft Base Smart Card-->"H:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
PowerDVD-->RunDll32 H:\ARQUIV~1\ARQUIV~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "H:\Arquivos de programas\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
Receitanet Java 2010.02a-->H:\ARQUIV~1\PROGRA~1\RECEIT~1\DesinstJ.exe
Security Update for 2007 Microsoft Office System (KB2288621)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5C497F0B-2061-4CC9-A61C-6B45B867354D}
Security Update for 2007 Microsoft Office System (KB2344875)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6FC5C4C1-D7AE-44C3-94B7-6424FC3E752F}
Security Update for 2007 Microsoft Office System (KB2345043)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {536FB502-775F-4494-BACE-C02CC90B7A5B}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for 2007 Microsoft Office System (KB982312)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B0EC5722-241F-4CDA-83B4-AA5846B6F9F4}
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)-->H:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A8894F19-59C8-38D2-8A75-36C0CCE56A5B} /qb+ REBOOTPROMPT=""
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5A4E43D5-858F-49BD-BA72-8F30E1793060}
Security Update for Microsoft Office Excel 2007 (KB2345035)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B23002DD-34EC-4988-B810-A5E2A0BF04F1}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office Outlook 2007 (KB2288953)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8B772E1C-7C05-42D2-839D-3EC2D39EFF22}
Security Update for Microsoft Office PowerPoint 2007 (KB982158)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F5B70033-E79C-4569-90BF-BC9B4E4F3F46}
Security Update for Microsoft Office Publisher 2007 (KB982124)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {289FA8BC-6A8E-4341-B194-EB26B49E9F5D}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB2344993)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
Security Update for Windows Search 4 - KB963093-->"H:\WINDOWS\$NtUninstallKB963093$\spuninst\spuninst.exe"
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
SoundMAX-->RunDll32 H:\ARQUIV~1\ARQUIV~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "H:\Arquivos de programas\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe" -l0x416 -removeonly
Superprovas 2010-->MsiExec.exe /I{7137F893-9B4E-4BA6-85A6-A84DB67F3B7A}
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->H:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Microsoft Office OneNote 2007 (KB980729)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {329050A9-EF80-40F9-B633-74508F54C1FF}
Update for Outlook 2007 Junk Email Filter (kb2410711)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BB5A2EB0-4515-4C6B-A618-A6F6B0AB7BAA}
VIA/S3G Display Driver-->H:\ARQUIV~1\S3\UChromeP\s3minset.exe /u UChromeP.uns
Windows Internet Explorer 8-->"H:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{590035D9-BFA0-406A-A7F0-479C72C0DDB2}
Windows Live Communications Platform-->MsiExec.exe /I{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}
Windows Live Essentials-->H:\Arquivos de programas\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{0FFEA8EE-7BC7-4C9D-8CC6-5B8C891BA3F2}
Windows Live Messenger-->MsiExec.exe /X{9ADC3E4F-34DA-48CD-8727-BB26D90257BD}
Windows Media Format 11 runtime-->"H:\Arquivos de programas\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"H:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"H:\Arquivos de programas\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"H:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Search 4.0-->"H:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"
XP Codec Pack-->H:\Arquivos de programas\XP Codec Pack\Uninstall.exe

======Security center information======

AV: AVG Anti-Virus Free Edition 2011 (disabled)

======System event log======

Computer Name: DESKTOP
Event Code: 29
Message: O provedor de tempo NtpClient foi configurado para obter tempo de uma ou mais
fontes de tempo; no entanto, nenhuma delas está acessível no momento.
Não será feita nenhuma tentativa de contatar uma fonte durante 14 minutos.
O NtpClient não tem uma fonte de tempo preciso.

Record Number: 51753
Source Name: W32Time
Time Written: 20101018093837.000000-120
Event Type: Erro
User:

Computer Name: DESKTOP
Event Code: 17
Message: Provedor de tempo NtpClient: erro durante a pesquisa de DNS do nível de protocolo 'time.windows.com,0x1' configurado
manualmente. O NtpClient fará uma nova tentativa em 15
minutos.
Erro: Uma operação de soquete foi tentada em um host inacessível. (0x80072751)

Record Number: 51752
Source Name: W32Time
Time Written: 20101018093837.000000-120
Event Type: Erro
User:

Computer Name: DESKTOP
Event Code: 1
Message: O filtro da restauração do sistema encontrou o erro inesperado '0xC0000001' ao processar o arquivo '' no volume 'HarddiskVolume1'. O monitoramento do volume foi interrompido.

Record Number: 51751
Source Name: sr
Time Written: 20101018093823.000000-120
Event Type: Erro
User:

Computer Name: DESKTOP
Event Code: 6005
Message: O serviço Log de eventos foi iniciado.

Record Number: 51750
Source Name: EventLog
Time Written: 20101018093756.000000-120
Event Type: Informações
User:

Computer Name: DESKTOP
Event Code: 6009
Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 3 Uniprocessor Free.

Record Number: 51749
Source Name: EventLog
Time Written: 20101018093756.000000-120
Event Type: Informações
User:

=====Application event log=====

Computer Name: DESKTOP
Event Code: 102
Message: Windows (216) Windows: O mecanismo de banco de dados iniciou uma nova instância (0).

Record Number: 1763
Source Name: ESENT
Time Written: 20100822090623.000000-180
Event Type: Informações
User:

Computer Name: DESKTOP
Event Code: 1800
Message: O Serviço da Central de Segurança do Windows foi iniciado.

Record Number: 1762
Source Name: SecurityCenter
Time Written: 20100822090623.000000-180
Event Type: Informações
User:

Computer Name: DESKTOP
Event Code: 100
Message: SearchIndexer (216) O mecanismo de banco de dados 5.01.2600.5512 foi iniciado.

Record Number: 1761
Source Name: ESENT
Time Written: 20100822090623.000000-180
Event Type: Informações
User:

Computer Name: DESKTOP
Event Code: 0
Message:
Record Number: 1760
Source Name: RichVideo
Time Written: 20100822090618.000000-180
Event Type: Informações
User:

Computer Name: DESKTOP
Event Code: 1517
Message: O Windows salvou o Registro DESKTOP\Usuario do usuário enquanto um aplicativo ou serviço ainda estava usando o Registro durante o logoff. A memória usada pelo Registro do usuário não foi liberada. O Registro será descarregado quando não estiver mais em uso.


Em geral, isso é causado por serviços que estão sendo executados como uma conta de usuário. Tente configurá-los para que sejam executados na conta LocalService ou NetworkService.

Record Number: 1759
Source Name: Userenv
Time Written: 20100821193839.000000-180
Event Type: aviso
User: AUTORIDADE NT\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0409
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------
Wings
Wings Cyber Highlander Registrado
20.3K Mensagens 1.2K Curtidas
#13 Por Wings
21/10/2010 - 13:36
katielly disse:


Uma apostila com extensão .exe é bem sugistivo de ser um trojan...

Mantenha o AVG desativado.

*Baixe o MalwareBytes Anti-malware e salve-o no desktop

*Instale o programa e aguarde a atualização
*O programa será aberto automaticamente
*Na aba [Verificação], selecione [Verificação completa]
*Clique [Verificar] e selecione a partição onde o Windows está instalado. No seu caso é H:\
*Ao finalizar o scan, clique [SIM] > [OK] > [Mostrar Resultados]
*Clique [Remover Selecionados]
*Cole o relatório apresentado
katielly
katielly Novo Membro Registrado
13 Mensagens 0 Curtidas
#14 Por katielly
21/10/2010 - 14:34
ufa...terminou
Relatório:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Versão da Base de Dados: 4903

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

21/10/2010 14:33:35
mbam-log-2010-10-21 (14-33-35).txt

Tipo de Verificação: Verificação Completa (C:\|H:\|)
Objetos escaneados: 261683
Tempo decorrido: 50 minuto(s), 29 segundo(s)

Processos de Memória Infectados: 0
Módulos de Memória Infectados: 0
Chaves de Registro Infectadas: 0
Valores de Registro Infectados: 0
Itens de Dados no Registro Infectados: 3
Pastas Infectadas: 0
Arquivos Infectados: 4

Processos de Memória Infectados:
(Não foram detectados ítens maliciosos)

Módulos de Memória Infectados:
(Não foram detectados ítens maliciosos)

Chaves de Registro Infectadas:
(Não foram detectados ítens maliciosos)

Valores de Registro Infectados:
(Não foram detectados ítens maliciosos)

Itens de Dados no Registro Infectados:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Pastas Infectadas:
(Não foram detectados ítens maliciosos)

Arquivos Infectados:
H:\BKP Katielly\System Volume Information\_restore{035DAA95-2376-4213-8A0F-A9179645387F}\RP7\A0006336.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
H:\BKP Katielly\System Volume Information\_restore{035DAA95-2376-4213-8A0F-A9179645387F}\RP7\A0006349.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
H:\BKP Katielly\USUARIOS\katielly itikawa\Downloads\discador.exe (Trojan.Agent) -> Quarantined and deleted successfully.
H:\BKP Katielly\USUARIOS\katielly itikawa\Downloads\discadoruolinternetilimitada.exe (Trojan.Agent) -> Quarantined and deleted successfully.

Posso manter o programa anti-malware no meu PC ou ele entrará em conflito com meu ani-vírus.
Acho que pelo relatório do anti-malware posso ficar tranquila. Já não existem mais trojan's né?!
© 1999-2025 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal