OK, all the steps have been completed successfully plus you should know that my trojan has now a new "friend". original Trojan was Trojan Downloader:Win32/Renos.IO and i now have Trojan Downloader:Win32/Renos.JI as well…both being noticed by windows defender, as before.
log1:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 12:39:47,88 on 28-07-2009
Internet Explorer: 8.0.6001.18783
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.351.2070.18.2039.962 [GMT 1:00]
AV: Panda Internet Security 2008 *On-access scanning enabled* (Updated) {4570FB70-5C9E-47E9-B16C-A3A6A06C4BF0}
SP: Panda Internet Security 2008 *enabled* (Updated) {FE6602D3-1E71-4EBB-B4E3-D1C9CBDAF0A1}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: Panda Internet Security 2008 *enabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}
============== Running Processes ===============
C:\Windows\SYSTEM32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Panda Security\Panda Internet Security 2008\PskSvc.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\pavsrvx86.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\TPSrv.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\AEADISRV.EXE
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Windows\system32\IoctlSvc.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\AntiSpam\pskmssvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Panda Security\Panda Internet Security 2008\psimsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
C:\Windows\system32\UAService7.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\SMINST\scheduler.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\apvxdwin.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\tmn\tmn\tmn.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\SRVLOAD.EXE
C:\Program Files\Panda Security\Panda Internet Security 2008\WebProxy.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\PavBckPT.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\uTorrent\uTorrent.exe
C:\Windows\SYSTEM32\taskeng.exe
C:\Windows\msa.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\UTILIZ~1\AppData\Local\Temp\b.exe
C:\Program Files\Panda Security\Panda Internet Security 2008\AVENGINE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\utilizador\Desktop\dds.pif
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Page = hxxp://g.msn.com.br/0SEPTBR/SAOS01?FORM=TOOLBR
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://g.msn.com.br/0SEPTBR/SAOS01?FORM=TOOLBR
uInternet Settings,ProxyServer = proxy.uminho.pt:3128
uSearchURL,(Default) = hxxp://g.msn.com.br/0SEPTBR/SAOS01?FORM=TOOLBR
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Programa Auxiliar de Início de Sessão do Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Microsoft Location Finder] "c:\program files\microsoft location finder\LocationFinder.exe"
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [Monopod] c:\users\utiliz~1\appdata\local\temp\b.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0\bin\jusched.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [APVXDWIN] "c:\program files\panda security\panda internet security 2008\APVXDWIN.EXE" /s
mRun: [SCANINICIO] "c:\program files\panda security\panda internet security 2008\Inicio.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [WatchDog] c:\program files\intervideo\dvd check\DVDCheck.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [PCSuiteTrayApplication] c:\program files\nokia\nokia pc suite 6\LaunchApplication.exe -startup
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRunOnce: [ST Recovery Launcher] %WINDIR%\SMINST\launcher.exe
dRun: [Nokia.PCSync] c:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dvdche~1.lnk - c:\program files\intervideo\dvd check\DVDCheck.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\tmn.lnk - c:\program files\tmn\tmn\tmn.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xportar para o Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
LSP: c:\program files\panda security\panda internet security 2008\pavlsp.dll
DPF: {588031A3-94BF-4CDD-86D0-939F6F93910F} - hxxps://fixit.support.microsoft.com/ActiveX/FixItClient.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
Notify: avldr - avldr.dll
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\utiliz~1\appdata\roaming\mozilla\firefox\profiles\pbcagi8r.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: network.proxy.ftp - proxy.uminho.pt
FF - prefs.js: network.proxy.ftp_port - 3128
FF - prefs.js: network.proxy.http - proxy.uminho.pt
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.ssl - proxy.uminho.pt
FF - prefs.js: network.proxy.ssl_port - 3128
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");
============= SERVICES / DRIVERS ===============
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-6-20 28544]
R1 APPFLT;App Filter Plugin;c:\windows\system32\drivers\APPFLT.SYS [2008-10-1 71736]
R1 DSAFLT;DSA Filter Plugin;c:\windows\system32\drivers\dsaflt.sys [2008-10-1 51256]
R1 FNETMON;NetMon Filter Plugin;c:\windows\system32\drivers\fnetmon.sys [2008-10-1 22072]
R1 IDSFLT;Ids Filter Plugin;c:\windows\system32\drivers\idsflt.sys [2008-10-1 191672]
R1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\drivers\NETFLTDI.SYS [2008-10-1 132920]
R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShlDrv51.sys [2008-10-1 38968]
R1 SMSFLT;SMS Filter Plugin;c:\windows\system32\drivers\smsflt.sys [2008-10-1 37304]
R1 WNMFLT;Wifi Monitor Filter Plugin;c:\windows\system32\drivers\wnmflt.sys [2008-10-1 30648]
R2 AmFSM;AmFSM;c:\windows\system32\drivers\amm8660.sys [2008-10-1 46904]
R2 ComFiltr;Panda Anti-Dialer;c:\windows\system32\drivers\COMFiltr.sys [2008-10-1 13880]
R2 cpoint;Panda CPoint Driver;c:\windows\system32\drivers\cpoint.sys [2008-10-1 24760]
R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [2008-10-1 178872]
R2 PskSvcRetail;Panda PSK service;c:\program files\panda security\panda internet security 2008\psksvc.exe [2008-10-1 27696]
R2 TeamViewer4;TeamViewer 4;c:\program files\teamviewer\version4\TeamViewer_Service.exe [2008-12-15 185640]
R3 NETIMFLT;PANDA NDIS IM Filter Miniport;c:\windows\system32\drivers\netimflt.sys [2008-10-1 142128]
S3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\drivers\Gt51Ip.sys [2007-11-13 106112]
S3 GT72UBUS;GT 72 U BUS;c:\windows\system32\drivers\gt72ubus.sys [2007-10-9 59264]
S3 GTPTSER;GT PT SER;c:\windows\system32\drivers\gtptser.sys [2007-3-30 8064]
S3 GTSCSER;GT SC SER;c:\windows\system32\drivers\gtscser.sys [2007-11-30 21504]
S3 LTXMD_VAC;Litex Media Virtual Audio Cable (WDM);c:\windows\system32\drivers\lmvac.sys [2009-6-19 18912]
============== File Associations ===============
JSEFile=c:\progra~1\pandas~1\pandai~1\PavScrip.exe "%1" %*
VBEFile=c:\progra~1\pandas~1\pandai~1\PavScrip.exe "%1" %*
VBSFile=c:\progra~1\pandas~1\pandai~1\PavScrip.exe "%1" %*
=============== Created Last 30 ================
2009-07-27 13:43 140,288 a——- c:\windows\msa.exe
2009-07-22 19:18 34,064 a——- c:\windows\system32\lhacm.acm
2009-07-22 19:18 –d—– c:\program files\Teamspeak2_RC2
2009-07-22 15:17 –d—– c:\program files\MovieXplayer
2009-07-22 01:45 77,464 a——- c:\windows\War3Unin.dat
2009-07-22 01:45 2,829 a——- c:\windows\War3Unin.pif
2009-07-22 01:45 139,264 a——- c:\windows\War3Unin.exe
2009-07-21 22:16 25,280 a——- c:\windows\system32\drivers\hamachi.sys
2009-07-21 22:16 –d—– c:\program files\Hamachi
2009-07-21 21:21 –d—– C:\NeverwinterNights
2009-07-21 18:03 261 a——- c:\windows\system32\PavCPL.dat
2009-07-21 18:02 0 a——- c:\windows\system32\drivers\wnmsav.dat
2009-07-20 22:44 –d—– c:\program files\Atari
2009-07-18 21:48 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-07-18 21:48 97,800 a——- c:\windows\system32\infocardapi.dll
2009-07-18 21:48 622,080 a——- c:\windows\system32\icardagt.exe
2009-07-18 21:48 43,544 a——- c:\windows\system32\PresentationHostProxy.dll
2009-07-18 21:48 37,384 a——- c:\windows\system32\infocardcpl.cpl
2009-07-18 21:48 11,264 a——- c:\windows\system32\icardres.dll
2009-07-18 21:48 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll
2009-07-18 21:48 326,160 a——- c:\windows\system32\PresentationHost.exe
2009-07-18 21:39 96,760 a——- c:\windows\system32\dfshim.dll
2009-07-18 21:39 282,112 a——- c:\windows\system32\mscoree.dll
2009-07-18 21:39 41,984 a——- c:\windows\system32\netfxperf.dll
2009-07-18 21:39 158,720 a——- c:\windows\system32\mscorier.dll
2009-07-18 21:39 83,968 a——- c:\windows\system32\mscories.dll
2009-07-14 23:53 267,272 a——- c:\windows\system32\xactengine2_10.dll
2009-07-14 23:53 1,374,232 a——- c:\windows\system32\D3DCompiler_36.dll
2009-07-14 23:53 444,776 a——- c:\windows\system32\d3dx10_36.dll
2009-07-14 23:53 3,734,536 a——- c:\windows\system32\d3dx9_36.dll
2009-07-14 23:53 267,112 a——- c:\windows\system32\xactengine2_9.dll
2009-07-14 23:53 3,727,720 a——- c:\windows\system32\d3dx9_35.dll
2009-07-14 23:53 1,358,192 a——- c:\windows\system32\D3DCompiler_35.dll
2009-07-14 23:53 444,776 a——- c:\windows\system32\d3dx10_35.dll
2009-07-14 23:53 266,088 a——- c:\windows\system32\xactengine2_8.dll
2009-07-14 23:53 17,928 a——- c:\windows\system32\X3DAudio1_2.dll
2009-07-14 23:53 3,497,832 a——- c:\windows\system32\d3dx9_34.dll
2009-07-14 23:53 1,124,720 a——- c:\windows\system32\D3DCompiler_34.dll
2009-07-14 23:53 443,752 a——- c:\windows\system32\d3dx10_34.dll
2009-07-14 22:06 289,792 a——- c:\windows\system32\atmfd.dll
2009-07-14 22:06 156,672 a——- c:\windows\system32\t2embed.dll
2009-07-14 22:06 72,704 a——- c:\windows\system32\fontsub.dll
2009-07-14 22:06 10,240 a——- c:\windows\system32\dciman32.dll
2009-07-03 13:26 –d—– C:\ConverterOutput
2009-07-03 13:25 –d—– c:\program files\Cucusoft
==================== Find3M ====================
2009-07-28 00:36 292,760 a——- c:\windows\system32\drivers\APPFCONT.DAT.bck
2009-07-28 00:36 292,760 a——- c:\windows\system32\drivers\APPFCONT.DAT
2009-07-28 00:36 1,304 a——- c:\windows\system32\drivers\APPFLTR.CFG.bck
2009-07-28 00:36 1,304 a——- c:\windows\system32\drivers\APPFLTR.CFG
2009-07-25 17:04 662,398 a——- c:\windows\system32\prfh0816.dat
2009-07-25 17:04 133,314 a——- c:\windows\system32\prfc0816.dat
2009-07-21 18:04 13,880 a——- c:\windows\system32\drivers\COMFiltr.sys
2009-07-21 18:03 143,360 a——- c:\windows\inf\infstrng.dat
2009-07-21 18:03 51,200 a——- c:\windows\inf\infpub.dat
2009-06-19 13:03 86,016 a——- c:\windows\inf\infstor.dat
2009-05-28 21:20 107,888 a——- c:\windows\system32\CmdLineExt.dll
2009-05-21 21:25 126,976 a——- c:\windows\system32\UAService7.exe
2009-05-21 01:45 93,403 a——- c:\windows\system32\~uTorrentPartFile_2AC2C1CF.dat
2009-05-09 06:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 06:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-04-30 13:37 293,376 a——- c:\windows\system32\psisdecd.dll
2009-04-30 13:37 428,544 a——- c:\windows\system32\EncDec.dll
2008-06-13 17:12 665,600 a——- c:\windows\inf\drvindex.dat
2008-04-23 11:34 174 a–sh— c:\program files\desktop.ini
2007-01-18 05:46 332,682 a——- c:\windows\inf\perflib\0816\perfi.dat
2007-01-18 05:46 332,682 a——- c:\windows\inf\perflib\0816\perfh.dat
2007-01-18 05:46 39,514 a——- c:\windows\inf\perflib\0816\perfd.dat
2007-01-18 05:46 39,514 a——- c:\windows\inf\perflib\0816\perfc.dat
2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-04-04 13:00 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-04-04 13:00 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-04-04 13:00 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-10-02 00:39 22 a–sh— c:\windows\sminst\HPCD.sys
============= FINISH: 12:42:33,70 ===============
log2:
DDS (Ver_09-06-26.01)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 23-04-2008 08:55:05
System Uptime: 28-07-2009 01:52:14 (11 hours ago)
Motherboard: Hewlett-Packard | | 30D8
Processor: Intel® Pentium® Dual CPU T2390 @ 1.86GHz | U10 | 1867/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 221 GiB total, 79,537 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 12 GiB total, 2,319 GiB free.
F: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: Nokia 5310 XpressMusic
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 5310 XpressMusic
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd
==== System Restore Points ===================
RP399: 22-07-2009 19:44:44 - Windows Update
RP400: 22-07-2009 21:33:01 - Windows Update
RP401: 23-07-2009 19:02:59 - Windows Update
RP402: 26-07-2009 03:35:56 - Ponto de Verificação Agendado
RP403: 27-07-2009 03:56:28 - Ponto de Verificação Agendado
RP405: 27-07-2009 13:44:09 - Windows Defender Checkpoint
RP407: 27-07-2009 13:52:54 - Installed Dance eJay 7 Demo
RP409: 27-07-2009 15:16:47 - Removed Dance eJay 7 Demo
RP411: 28-07-2009 00:42:07 - Windows Defender Checkpoint
==== Installed Programs ======================
7-Zip 4.65
ACE Mega CoDecS Pack
Actualização do Microsoft Office Excel 2007 Help (KB963678)
Actualização do Microsoft Office Powerpoint 2007 Help (KB963669)
Actualização do Microsoft Office Word 2007 Help (KB963665)
Adobe Acrobat 5.0
Adobe Acrobat 6.0.1 Professional
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
Adobe Reader 9.1.1 - Português
Adobe Shockwave Player 11.5
Agere Systems HDA Modem
Apple Software Update
Arquivo do WinRAR
Assistente de Início de Sessão do Windows Live
µTorrent
AviSynth 2.5
Barra de Ferramentas do Outlook do Windows Live (Windows Live Toolbar)
Broadcom 802.11 Wireless LAN Adapter
Conexant HD Audio
Creative MediaSource
Cucusoft Ultimate DVD + Video Converter Suite [removed]
DAEMON Tools Toolbar
Detector de Feed do Windows Live Toolbar (Windows Live Toolbar)
DVD Decrypter (Remove Only)
e-escola_tmn
ESU for Microsoft Vista
Extensão do Windows Live Toolbar (Windows Live Toolbar)
FileASSASSIN
Finale 2008
FLV Player 1.3.3
Free M4a to MP3 Converter 6.0
Free YouTube to Mp3 Converter version 3.1
GameShadow
Garritan Instruments for Finale
Haali Media Splitter
Hamachi 1.0.3.0
Harry Potter e a Ordem da Fénix™
HDAUDIO Soft Data Fax Modem with SmartCP
Hewlett-Packard Active Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Active Support Library 32 bit components
HP Doc Viewer
HP Help and Support
HP MULTIPLE WLAN INSTALLER for VISTA
HP Notebook Accessories Product Tour
HP Quick Launch Buttons 6.30 A3
HP Update
HP User Guides 0077
HP Wireless Assistant
Instalador do Gerenciador de backup e recuperação HP
Intel® Graphics Media Accelerator Driver
Intel® Network Connections Drivers
InterVideo DVD Check
InterVideo Register Manager
InterVideo WinDVD
Java™ SE Runtime Environment 6
KRyLack Password Recovery
Macromedia Flash Player 8
Mario Forever 4.0
Menus Inteligentes (Windows Live Toolbar)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft .NET Framework 3.5 SP1
Microsoft Calculator Plus
Microsoft Location Finder
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (Portuguese (Portugal)) 2007
Microsoft Office Outlook MUI (Portuguese (Portugal)) 2007
Microsoft Office PowerPoint MUI (Portuguese (Portugal)) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Portuguese (Portugal)) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (Portuguese (Portugal)) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (Portuguese (Portugal)) 2007
Microsoft Office Standard 2007
Microsoft Office Word MUI (Portuguese (Portugal)) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mozilla Firefox (3.0.12)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
Nero 8 Ultra Edition HD
neroxml
NetWaiting
Neverwinter Nights
Neverwinter Nights 2
Nokia Connectivity Cable Driver
Nokia PC Suite
NOMAD MuVo TX
Pacote de controladores do Windows - Nokia (WUDFRd) WPD (06/01/2007 6.84.33.0)
Pacote de controladores do Windows - Nokia Modem (02/15/2007 3.1)
Pacote de controladores do Windows - Nokia Modem (05/24/2007 6.84.0.1)
Panda ActiveScan 2.0
Panda Internet Security 2008
PC Connectivity Solution
Photo Story 3 para Windows
Pro Evolution Soccer 2009
QuickTime
Real Alternative 1.9.0
Real Race
Roxio Creator Audio
Roxio Creator Basic v9
Roxio Creator Copy
Roxio Creator Data
Roxio Creator Tools
Roxio Express Labeler 3
Roxio MyDVD Basic v9
SecureW2 TTLS Client 3.3.3 for Windows
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB969679)
Security Update for Microsoft Office Excel 2007 (KB969682)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office Word 2007 (KB969604)
Sibelius Scorch Plugin [removed]
Sonic Activation Module
Star Wars®: Knights of the Old Republic ™
Synaptics Pointing Device Driver
TeamSpeak 2 RC2
TeamViewer 4
The Sims™ Castaway Stories
tmn
Uninstall 1.0.0.1
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office Outlook 2007 (KB969907)
Update for Outlook 2007 Junk Email Filter (kb971933)
Vista Default Settings
VLC media player 0.9.9
Warcraft III
Warcraft III: All Products
Windows Live Favorites para Windows Live Toolbar
Windows Live installer
Windows Live Messenger
Windows Live Toolbar
Windows Movie Maker 2.6
Xvid 1.2.1 final uninstall
==== End Of File ===========================
Gmer:
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-07-29 00:42:15
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.15 —-
SSDT \??\C:\Windows\system32\PavSRK.sys ZwWriteVirtualMemory [0xA7B124E8]
INT 0x51 ? 86766BF8
INT 0x51 ? 86766BF8
INT 0x72 ? 86766BF8
INT 0x82 ? 86766BF8
INT 0x92 ? 86766BF8
INT 0xA2 ? 84A7DBF8
INT 0xB2 ? 84A7DBF8
—- Devices - GMER 1.0.15 —-
Device ShlDrv51.sys (PandaShield driver/Panda Software)
Device 854111F8
Device Ntfs.sys (Controlador de Sistema de Ficheiros NT/Microsoft Corporation)
Device B26FD500
Device fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\volmgr \Device\VolMgrControl 84A7F1F8
Device \Driver\netbt \Device\NetBT_Tcpip_{FD2CD838-AB60-440B-A7B9-2614701A95A2} 86E90500
Device \Driver\usbuhci \Device\USBPDO-0 864EA1F8
Device \Driver\usbehci \Device\USBPDO-1 864D61F8
Device \Driver\usbuhci \Device\USBPDO-2 864EA1F8
Device \Driver\usbuhci \Device\USBPDO-3 864EA1F8
Device \Driver\usbuhci \Device\USBPDO-4 864EA1F8
AttachedDevice \Driver\tdx \Device\Tcp NETFLTDI.SYS
Device \Driver\usbehci \Device\USBPDO-5 864D61F8
Device \Driver\PCI_PNP1877 \Device\00000070 splx.sys
Device \Driver\volmgr \Device\HarddiskVolume1 84A7F1F8
Device \Driver\sptd \Device\4182845891 splx.sys
Device \Driver\volmgr \Device\HarddiskVolume2 84A7F1F8
Device \Driver\cdrom \Device\CdRom0 865931F8
Device \Driver\cdrom \Device\CdRom1 865931F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 8540F1F8
Device \Driver\atapi \Device\Ide\IdePort0 8540F1F8
Device \Driver\atapi \Device\Ide\IdePort1 8540F1F8
Device \Driver\msahci \Device\Ide\PciIde1Channel0 854101F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-2 8540F1F8
Device \Driver\netbt \Device\NetBt_Wins_Export 86E90500
Device \Driver\Smb \Device\NetbiosSmb 86E9D500
Device \Driver\netbt \Device\NetBT_Tcpip_{DF4375F8-419D-433B-8A8A-B5B8E4037073} 86E90500
Device \Driver\iScsiPrt \Device\RaidPort0 865C31F8
AttachedDevice \Driver\tdx \Device\Udp NETFLTDI.SYS
Device \Driver\usbuhci \Device\USBFDO-0 864EA1F8
Device \Driver\usbehci \Device\USBFDO-1 864D61F8
Device \Driver\usbuhci \Device\USBFDO-2 864EA1F8
Device \Driver\usbuhci \Device\USBFDO-3 864EA1F8
Device \Driver\usbuhci \Device\USBFDO-4 864EA1F8
Device \Driver\usbehci \Device\USBFDO-5 864D61F8
Device \Driver\netbt \Device\NetBT_Tcpip_{A1637B19-49F6-4E95-B710-47A4CE1BC4AE} 86E90500
Device \Driver\Modem \Device\0000008c COMFiltr.sys
Device \Driver\arj8yuun \Device\Scsi\arj8yuun1Port3Path0Target0Lun0 865C91F8
Device \Driver\arj8yuun \Device\Scsi\arj8yuun1 865C91F8
AttachedDevice fltmgr.sys (Gestor de Filtros de Sistema de Ficheiros da Microsoft/Microsoft Corporation)
Device \FileSystem\cdfs \Cdfs AE1A7500
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x10 0x3F 0x77 0x93 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x26 0x4A 0x26 0xC8 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x43 0xD7 0xD1 0x9B …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x10 0x3F 0x77 0x93 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x26 0x4A 0x26 0xC8 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x43 0xD7 0xD1 0x9B …
—- EOF - GMER 1.0.15 —-
hope to read from u soon!