carol2906 0 Denunciar post Postado Janeiro 16, 2008 :mellow: Oi gente, de uns 4 dias pra cá toda vez que conecto na internet ou executo algum programa aparece o seguinte: "c:\windows\temp\4379ehe7.exe A CPU NTVDM encontrou uma instrução não permitida. CS:06ce IP:01 de OP:63 68 65 2f 31 Escolha fechar para finalizar o aplicativo." Daí aparece uma telinha do DOS... muito estranho, isso aconteceu depois que eu baixei um arquivo no limewire que era um suposto keygen do adobe lightroom e quando executei ele criou vários arquivos como se fossem keygens de outros programas na minha pasta de compartilhamento do limewire... Obs: Quando entro na internet o antivirus ta acusando assim: "Virus or unwanted program 'BAT/DelFiles.AY [bAT/DelFiles.AY]' detected in file 'C:\autoexec.bat." Meu PC tá uma carroça. Ajudem por favor!!! Segue o log do hijack: Logfile of HijackThis v1.99.1 Scan saved at 09:45:38, on 16/1/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\GbPlugin\GbpSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\ARQUIV~1\mcafee.com\agent\McAgent.exe C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe C:\Arquivos de programas\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe c:\arquiv~1\mcafee.com\vso\mcvsescn.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cmpe.exe c:\arquivos de programas\mcafee.com\agent\mcdetect.exe c:\ARQUIV~1\mcafee.com\vso\mcshield.exe c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe C:\WINDOWS\system32\PSIService.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\STK017_V2.01\STK017M.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\notepad.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehCef.dll O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\Arquivos de programas\GbPlugin\gbiehabn.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\ARQUIV~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [MCAgentExe] c:\ARQUIV~1\mcafee.com\agent\McAgent.exe O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Arquivos de programas\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe O4 - Global Startup: STK017 PNP Monitor.lnk = ? O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZSYYYYYYYYBR O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.13\AMVConverter\grab.html O8 - Extra context menu item: Append to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O17 - HKLM\System\CS1\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: __GbPluginAbn - C:\Arquivos de programas\GbPlugin\gbiehabn.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing) O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Janeiro 17, 2008 Bom Dia carol2906! >@< Cole no Bloco de Notas. ( Tudo o que estiver,abaixo da palavra quote! ) >@< Em: Salvar como tipo: escolha Todos os arquivos >@< Em: Nome do Arquivo: coloque Temp.bat >@< Salve este arquivo,no Desktop! >@< Execute-o com um duplo clique! @ECHO OFFIF NOT %temp% == %tmp% GOTO both GOTO single :both DEL %temp%\*.* /F /S /Q DEL %tmp%\*.* /F /S /Q CLS ECHO Deleted all files in the TEMP folder: %temp% ECHO Deleted all files in the TMP folder: %tmp% GOTO end :single DEL %temp%\*.* /F /S /Q DEL %systemroot%\Temp\*.* /F /S /Q CLS ECHO Deleted all files in the TEMP folder: %temp% :end ____________________ >@< Faça um escaneamento de desinfecção em < BitDefender > e poste o relatório. >@< Clique em BitDefender ( Scan OnLine ). >@< Abrirá a página: < BitDefender OnLine Scanner > >@< Clique em I Agree. >@< Aguarde!Permita a instalação do ActiveX,para que possa ocorrer o scan. ____________________ >@< Poste,então: Relatório do BitDefender + Log do HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
carol2906 0 Denunciar post Postado Janeiro 20, 2008 BitDefender Online Scanner - Real Time Virus Report Generated at: Sat, Jan 19, 2008 - 22:45:14 -------------------------------------------------------------------------------- Scan Info Scanned Files 563240 Infected Files 10 Virus Detected DeepScan:Generic.Malware.SI!Bdldg.7C687210 1 Trojan.Funweb.A 1 Trojan.Vundo.DWK 2 Trojan.Dropper.Delf.FP 2 Trojan.BAT.KillFiles.GD 2 Trojan.Vundo.DVS 2 -------------------------------------------------------------------------------- This summary of the scan process will be used by the BitDefender Antivirus Lab to create agregate statistics about virus activity around the world. Logfile of HijackThis v1.99.1 Scan saved at 22:48:32, on 19/1/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\ARQUIV~1\mcafee.com\agent\McAgent.exe C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe C:\Arquivos de programas\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe c:\arquiv~1\mcafee.com\vso\mcvsescn.exe C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cmpe.exe c:\arquivos de programas\mcafee.com\agent\mcdetect.exe c:\ARQUIV~1\mcafee.com\vso\mcshield.exe c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe C:\WINDOWS\system32\PSIService.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\STK017_V2.01\STK017M.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\rundll32.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\Arquivos de programas\MSN Messenger\msnmsgr.exe c:\arquiv~1\mcafee.com\vso\mcvsftsn.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Arquivos de programas\MSN Messenger\usnsvc.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) F3 - REG:win.ini: load=C:\WINDOWS\system32\awtqr.exe O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\ARQUIV~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [MCAgentExe] c:\ARQUIV~1\mcafee.com\agent\McAgent.exe O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Arquivos de programas\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe O4 - Global Startup: STK017 PNP Monitor.lnk = ? O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZSYYYYYYYYBR O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.13\AMVConverter\grab.html O8 - Extra context menu item: Append to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O17 - HKLM\System\CS1\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing) O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Janeiro 20, 2008 Bom Dia carol2906! >@< Faça o download do ComboFix. >@< Baixe-o para o Desktop! >@< Feche todas as janelas e execute a ferramenta! >@< Para quem possui o Avast,surgirá um alerta de malware ( Win32 D adobra-EY[Trj] ),que deverá ser ignorado. >@< Abrirá a janela Auto Scan. Aguarde! >@< Digite a opção para continuar e < Enter > >@< Aguarde a conclusão! ________________________ >@< Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
carol2906 0 Denunciar post Postado Janeiro 20, 2008 Oi DigRam Tentei executar o programa que você falou e acho que não deu certo, meu windows reiniciou sozinho duas vezes, era pra ser assim??? O único txt que achei com o nome combofix diz o seguinte: ComboFix 08-01-20.1 - Karol 2008-01-20 16:13:33.2 - NTFSx86 Executando de: C:\Documents and Settings\Karol\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . Logfile of HijackThis v1.99.1 Scan saved at 16:24, on 2008-01-20 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\GbPlugin\GbpSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cmpe.exe c:\arquivos de programas\mcafee.com\agent\mcdetect.exe c:\ARQUIV~1\mcafee.com\vso\mcshield.exe c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe C:\WINDOWS\system32\PSIService.exe C:\Arquivos de programas\STK017_V2.01\STK017M.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\wbem\wmiprvse.exe C:\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: (no name) - {5AAF23D8-4489-43D8-A064-319D1254ABCA} - C:\WINDOWS\system32\jkkijkk.dll (file missing) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehCef.dll O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll O2 - BHO: (no name) - {FDF18230-EE8E-4FC3-856C-283A21B73A9C} - C:\WINDOWS\system32\awtqr.dll (file missing) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe O4 - Global Startup: STK017 PNP Monitor.lnk = ? O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZSYYYYYYYYBR O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.13\AMVConverter\grab.html O8 - Extra context menu item: Append to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O17 - HKLM\System\CS1\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O17 - HKLM\System\CS2\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll O20 - Winlogon Notify: jkkijkk - jkkijkk.dll (file missing) O20 - Winlogon Notify: __GbPluginAbn - C:\Arquivos de programas\GbPlugin\gbiehabn.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing) O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Janeiro 21, 2008 Bom Dia carol2906! Tentei executar o programa que você falou e acho que não deu certo, meu windows reiniciou sozinho duas vezes, era pra ser assim??? O único txt que achei com o nome combofix diz o seguinte: >@< Execute a ferramenta,em Modo de Segurança! Creio que desta forma,teremos um relatório. ____________________________ >@< Faça o download do VundoFix. >@< Salve-o no Desktop! >@< Execute o VundoFix.exe >@< Quando o VundoFix abrir,novamente, clique em Scan for Vundo. >@< Quando ele terminar, clique em Remove Vundo. >@< Você receberá um prompt perguntando se quer remover os arquivos. Confirme! >@< Sua área de trabalho vai desaparecer! >@< Surgirá um aviso dizendo que seu computador deve ser desligado. >@< Clique em OK e depois,ligue o computador novamente! >@< É possível que o VundoFix encontre um arquivo, mas não consiga removê-lo. Se isso acontecer, a ferramenta rodará ao reiniciar. >@< Quando o VundoFix aparecer, clique no botão Scan for Vundo para repetir o processo. >@< Quando o VundoFix não encontrar mais nenhum arquivo,que não consiga remover,poste o seu relatório ( Log ) que se encontra em C:\Vundofix.txt >@< Poste,também,um nôvo Log do HijackThis + ComboFix.txt <!> Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
carol2906 0 Denunciar post Postado Janeiro 21, 2008 ComboFix 08-01-20.1 - Karol 2008-01-21 9:24:38.4 - NTFSx86 MINIMAL Executando de: C:\Documents and Settings\Karol\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((( Outras Exclusäes ))))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . C:\Arquivos de programas\MyWebSearch C:\WINDOWS\system32\awtqr.dll C:\WINDOWS\system32\jkkijkk.dll C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\rqtwa.ini C:\WINDOWS\system32\rqtwa.ini2 . ((((((((((((((((((((((( Ficheiros criados de 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))) . 2008-01-20 15:56 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe 2008-01-19 23:28 . 2008-01-20 08:44 <DIR> d-------- C:\WINDOWS\SxsCaPendDel 2008-01-17 09:31 . 2008-01-19 22:45 <DIR> d-------- C:\WINDOWS\BDOSCAN8 2008-01-17 09:19 . 2008-01-17 09:17 150 --a------ C:\copia de autoexec.bat 2008-01-17 09:17 . 2008-01-17 09:17 6,144 --ahs---- C:\Thumbs.db 2008-01-17 09:07 . 2008-01-17 09:07 8,192 --ahs---- C:\WINDOWS\system32\Thumbs.db 2008-01-16 11:21 . 2008-01-16 11:21 <DIR> d-------- C:\Documents and Settings\Karol\Dados de aplicativos\Comodo 2008-01-16 11:21 . 2008-01-16 11:21 <DIR> d-------- C:\Arquivos de programas\COMODO 2008-01-16 11:09 . 2008-01-16 22:47 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2008-01-16 11:04 . 2008-01-16 11:04 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Avira 2008-01-16 11:04 . 2008-01-16 11:04 <DIR> d-------- C:\Arquivos de programas\Avira 2008-01-15 19:46 . 2008-01-15 19:46 <DIR> d--h----- C:\WINDOWS\PIF 2008-01-14 20:51 . 2008-01-17 09:17 <DIR> d-------- C:\Eye Candy 4000 2008-01-14 20:51 . 2008-01-20 18:48 373,248 --a------ C:\WINDOWS\EyeCand3.INI 2008-01-14 20:45 . 2008-01-14 20:48 4,285 --a------ C:\WINDOWS\IFiltSet.Ini 2008-01-14 20:43 . 2008-01-14 20:43 <DIR> d-------- C:\Arquivos de programas\byLight 2008-01-14 20:43 . 2008-01-19 23:24 33 --a------ C:\WINDOWS\iltwain.ini 2008-01-11 19:31 . 2008-01-21 09:31 <DIR> d-a------ C:\Documents and Settings\All Users\Dados de aplicativos\TEMP 2008-01-11 19:31 . 2004-08-30 21:00 1,499,136 --a------ C:\WINDOWS\system32\BTCPatcher.exe 2008-01-11 19:31 . 2008-01-11 19:31 37,888 --a------ C:\WINDOWS\system32\rar.exe 2008-01-07 21:54 . 2008-01-07 22:45 <DIR> d-------- C:\Arquivos de programas\eMule 2008-01-07 21:50 . 2008-01-07 21:50 <DIR> d-------- C:\Documents and Settings\Karol\LimeWire Store Purchased 2008-01-07 21:50 . 2008-01-15 08:29 <DIR> d-------- C:\Documents and Settings\Karol\LimeWire Shared 2008-01-07 21:50 . 2008-01-07 21:50 <DIR> d-------- C:\Documents and Settings\Karol\Incomplete 2008-01-07 21:49 . 2008-01-20 08:57 <DIR> d-------- C:\Documents and Settings\Karol\Dados de aplicativos\LimeWire 2008-01-07 21:49 . 2008-01-07 21:49 <DIR> d-------- C:\Arquivos de programas\LimeWire 2008-01-04 18:41 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2008-01-04 18:41 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys 2007-12-22 19:37 . 2007-12-22 19:38 <DIR> d-------- C:\Arquivos de programas\TagScanner 2007-12-22 18:45 . 2007-12-22 18:49 <DIR> d-------- C:\Arquivos de programas\eMusic Tag Editor . ((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-20 18:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin 2008-01-20 18:06 --------- d-----w C:\Arquivos de programas\GbPlugin 2008-01-20 01:33 --------- d-----w C:\Arquivos de programas\NCH Swift Sound 2008-01-20 01:32 --------- d-----w C:\Arquivos de programas\Corel 2008-01-17 12:32 --------- d-----w C:\Documents and Settings\Karol\Dados de aplicativos\Alien Skin 2008-01-16 11:22 --------- d-----w C:\Documents and Settings\Karol\Dados de aplicativos\Corel 2007-12-27 12:04 --------- d-----w C:\Arquivos de programas\StuffPlug3 2007-12-27 11:44 --------- d-----w C:\Arquivos de programas\NCH Software 2007-12-26 13:33 --------- d-----w C:\Arquivos de programas\a-squared Free 2007-12-16 15:09 --------- d-----w C:\Arquivos de programas\Google 2007-12-15 16:44 --------- d-----w C:\Arquivos de programas\MSN Messenger 2007-12-13 22:32 --------- d-----w C:\Arquivos de programas\STK017_V2.01 2007-12-11 22:39 --------- d-----w C:\Arquivos de programas\IObit 2007-12-11 22:36 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Skype 2007-12-01 15:52 --------- d-----w C:\Documents and Settings\Karol\Dados de aplicativos\Nero 2007-11-30 13:18 --------- d-----w C:\Arquivos de programas\MP3 Player Utilities 4.00 2007-11-30 13:18 --------- d-----w C:\Arquivos de programas\MP3 Player Utilities 3.57 2007-11-29 11:10 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live 2007-11-29 11:02 --------- d-----w C:\Arquivos de programas\Bonjour 2007-11-10 17:00 2 ----a-w C:\Arquivos de programas\history.rcd 2007-10-25 12:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe 2007-08-18 22:34 533 ----a-w C:\Arquivos de programas\UnInst.log 2004-10-01 18:00 40,960 ----a-w C:\Arquivos de programas\Uninstall_CDS.exe 2002-04-09 19:16 622,592 ----a-w C:\Arquivos de programas\recorder.exe 1998-02-12 19:54 149,504 ----a-w C:\Arquivos de programas\convert.dll 2007-09-05 15:58 88 --sh--r C:\WINDOWS\system32\65D31702E2.sys . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PowerBar"="" [] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ] "swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ] "Nero PhotoShow Media Manager"="C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "VSOCheckTask"="C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" [ ] "avgnt"="C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [ ] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [ ] C:\Documents and Settings\Karol\Menu Iniciar\Programas\Inicializar\ Recorte de tela e Iniciador do OneNote 2007.lnk - C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 21:24:54 98632] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run] "NTSpool"= NTSpool.exe "System Patcher"= BTCPatcher.exe [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{E37CB5F0-51F5-4395-A808-5FA49E399007}"= C:\ARQUIV~1\GbPlugin\gbiehabn.dll [2007-11-19 19:02 341928] "{E37CB5F0-51F5-4395-A808-5FA49E399003}"= C:\Arquivos de programas\GbPlugin\gbiehCef.dll [2007-11-29 11:41 337992] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginAbn] C:\ARQUIV~1\GbPlugin\gbiehabn.dll 2007-11-19 19:02 341928 C:\ARQUIV~1\GbPlugin\gbiehabn.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef] C:\Arquivos de programas\GbPlugin\gbiehCef.dll 2007-11-29 11:41 337992 C:\Arquivos de programas\GbPlugin\gbiehCef.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__GbPluginAbn] C:\Arquivos de programas\GbPlugin\gbiehabn.dll 2007-11-19 19:02 341928 C:\Arquivos de programas\GbPlugin\gbiehabn.dll . Conte£do da pasta 'Tarefas Agendadas' "2007-12-19 19:38:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Arquivos de programas\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-21 09:31:36 Windows 5.1.2600 Service Pack 2 NTFS Procurando processos ocultos ... Procurando entradas auto inicializ veis ocultas ... HKCU\Software\Microsoft\Windows\CurrentVersion\Run PowerBar = ????????????l?@?l?@?D?????6~??????????????6~l?@?l?@????? ???????????W?9~??6~??????6~K?6~x???????[?6~???????? ??????????????|x???0???????????? ot??6~????????????????????????????????l?@?l?@?????Q?7~????t?@?????l?@?8?@?l?@?3??s????????????????????8?@?_??s8?@?8?@ Procurando ficheiros ocultos ... Varredura completada com sucesso Ficheiros ocultos: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156] -> C:\Arquivos de programas\ArcSoft\Software Suite\PhotoImpression\share\pihook.dll . Tempo para conclusÆo: 2008-01-21 9:36:13 - machine was rebooted [Karol] ComboFix-quarantined-files.txt 2008-01-21 11:36:09 . 2008-01-09 14:24:25 --- E O F --- ----------------------------------------------------------------------------------------------------------------------------------------- VundoFix V6.7.7 Checking Java version... Sun Java not detected Scan started at 09:38:08 21/1/2008 Listing files found while scanning.... C:\ARQUIV~1\GbPlugin\gbiehabn.dll C:\Arquivos de programas\GbPlugin\gbiehCef.dll Beginning removal... Attempting to delete C:\ARQUIV~1\GbPlugin\gbiehabn.dll C:\ARQUIV~1\GbPlugin\gbiehabn.dll Could not be deleted. Attempting to delete C:\Arquivos de programas\GbPlugin\gbiehCef.dll C:\Arquivos de programas\GbPlugin\gbiehCef.dll Could not be deleted. Performing Repairs to the registry. Done! Beginning removal... Attempting to delete C:\ARQUIV~1\GbPlugin\gbiehabn.dll C:\ARQUIV~1\GbPlugin\gbiehabn.dll Could not be deleted. Attempting to delete C:\Arquivos de programas\GbPlugin\gbiehCef.dll C:\Arquivos de programas\GbPlugin\gbiehCef.dll Could not be deleted. Performing Repairs to the registry. Done! Beginning removal... VundoFix V6.7.7 Checking Java version... Sun Java not detected Scan started at 10:22:29 21/1/2008 Listing files found while scanning.... C:\ARQUIV~1\GbPlugin\gbiehabn.dll C:\Arquivos de programas\GbPlugin\gbiehCef.dll Beginning removal... Attempting to delete C:\ARQUIV~1\GbPlugin\gbiehabn.dll C:\ARQUIV~1\GbPlugin\gbiehabn.dll Could not be deleted. Attempting to delete C:\Arquivos de programas\GbPlugin\gbiehCef.dll C:\Arquivos de programas\GbPlugin\gbiehCef.dll Could not be deleted. Performing Repairs to the registry. Done! ---------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 11:02:28, on 21/1/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\GbPlugin\GbpSv.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cmpe.exe c:\arquivos de programas\mcafee.com\agent\mcdetect.exe c:\ARQUIV~1\mcafee.com\vso\mcshield.exe c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe C:\WINDOWS\system32\PSIService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\STK017_V2.01\STK017M.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehCef.dll O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe O4 - Global Startup: STK017 PNP Monitor.lnk = ? O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZSYYYYYYYYBR O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.13\AMVConverter\grab.html O8 - Extra context menu item: Append to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O17 - HKLM\System\CS1\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O17 - HKLM\System\CS2\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll O20 - Winlogon Notify: __GbPluginAbn - C:\Arquivos de programas\GbPlugin\gbiehabn.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing) O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Janeiro 21, 2008 Boa Tarde carol2906! >@< Abra o HijackThis e,com todas as janelas fechadas,dê Fix nestas entradas: O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZSYYYYYYYYBRO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab ________________________ >@< Faça o download do a-squared Free 3.0 >@< Abra o programa e clique em: Atualizar agora >> Aguarde! >@< Terminando,clique em: Analisar agora. >@< Caso possa,procure fazer,esta análise,em Modo de Segurança! << Opcional! >@< Escolha a opção: A fundo. >@< Clique em Analisar! >@< Terminando,envie os ítens encontrados para a quarentena. >@< Aonde,daí,serão excluídos ou restaurados. ________________________ >@< Copie o relatório,desta verificação,e poste na sua resposta + HJT,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
carol2906 0 Denunciar post Postado Janeiro 21, 2008 a-squared Free - Versão 3.1 Última atualização 21/1/2008 19:15:28 Configurações da análise: Objetos: Memória, Rastros, Cookies, C:\, E:\ Análise de arquivos: Ligado Heurística: Ligado Análise de ADS: Ligado Início da análise: 21/1/2008 19:16:35 [1228] C:\Arquivos de programas\STK017_V2.01\STK017M.exe detectado: Adware.Win32.Cres Value: HKEY_CLASSES_ROOT\arlnk --> URL Protocol detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares\bounds --> Main.Maximized detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares\bounds --> Main.Maximized detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares\Columns\Transfers --> Download detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares\Columns\Transfers --> Download detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares\Columns\Transfers --> Queue detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares\Columns\Transfers --> Queue detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares\Columns\Transfers --> Upload detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares\Columns\Transfers --> Upload detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares\Data --> AresNet1 detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares\Data --> AresNet1 detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares\Data --> JI.AresNet1 detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares\Data --> JI.AresNet1 detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares\Positions\Transfers --> Download detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares\Positions\Transfers --> Download detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares\Positions\Transfers --> Queue detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares\Positions\Transfers --> Queue detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares\Positions\Transfers --> Upload detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares\Positions\Transfers --> Upload detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Extra.ShowActiveCaption detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Extra.ShowActiveCaption detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.AutoConnect detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.AutoConnect detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.AutoStartUp detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.AutoStartUp detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.LastLibraryMode detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.LastLibraryMode detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> GUI.LastChatRoomBrowse detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> GUI.LastChatRoomBrowse detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> GUI.LastLibrary detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> GUI.LastLibrary detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> GUI.LastPMBrowse detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> GUI.LastPMBrowse detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> GUI.LastSearch detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> GUI.LastSearch detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Network.DHTID detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Network.DHTID detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Personal.GUID detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Personal.GUID detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Privacy.SendRegularPath detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Privacy.SendRegularPath detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> PrivateMessage.AllowBrowse detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> PrivateMessage.AllowBrowse detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> PrivateMessage.AwayMessage detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> PrivateMessage.AwayMessage detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.CAvgTime detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.CAvgTime detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.CDnSpeed detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.CDnSpeed detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.CFRTime detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.CFRTime detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.CTtUptime detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.CTtUptime detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.CUpSpeed detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.CUpSpeed detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.HasLQCa detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.HasLQCa detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.LstCaQuery detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.LstCaQuery detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.LstCaQueryInt detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.LstCaQueryInt detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Transfer.MaximizeUpBandOnIdle detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Transfer.MaximizeUpBandOnIdle detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Transfer.ServerPort detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Transfer.ServerPort detectado: Trace.Registry.Ares Key: HKEY_CLASSES_ROOT\interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} detectado: Trace.Registry.FunWebProducts Key: HKEY_LOCAL_MACHINE\software\fun web products detectado: Trace.Registry.FunWebProducts Value: HKEY_USERS\S-1-5-21-725345543-688789844-2147238677-1003\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} --> DisplayName detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_USERS\S-1-5-21-725345543-688789844-2147238677-1003\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} --> URL detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\ScreenSaver --> ImagesDir detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn --> ETag detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn --> HTMLMenuRevision detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn --> LastHTMLMenuURL detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyFreqNone detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyFreqUninstalled detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyTextNone.0 detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyTextNone.numActive detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyTextUninstalled.0 detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyTextUninstalled.numActive detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> MSN.1 detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> MSN.2 detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> MSN.numActive detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> MSN.numActive2 detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn --> ETag detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn --> HTMLMenuPosDeleted detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn --> HTMLMenuRevision detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn --> LastHTMLMenuURL detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products --> CacheDir detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products --> JpegConversionLib detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} --> DisplayName detectado: Trace.Registry.MyWebSearch Toolbar Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} --> URL detectado: Trace.Registry.MyWebSearch Toolbar Key: HKEY_CLASSES_ROOT\clsid\{a4730ebe-43a6-443e-9776-36915d323ad3} detectado: Trace.Registry.MyWebSearchToobar Key: HKEY_CLASSES_ROOT\interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} detectado: Trace.Registry.MyWebSearchToobar Key: HKEY_USERS\S-1-5-21-725345543-688789844-2147238677-1003\software\mywebsearch detectado: Trace.Registry.MyWebSearchToobar Key: HKEY_CLASSES_ROOT\clsid\{a4730ebe-43a6-443e-9776-36915d323ad3} detectado: Trace.Registry.MyWebSearchToolbar Key: HKEY_CLASSES_ROOT\interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} detectado: Trace.Registry.MyWebSearchToolbar Key: HKEY_USERS\S-1-5-21-725345543-688789844-2147238677-1003\software\mywebsearch detectado: Trace.Registry.MyWebSearchToolbar Value: HKEY_USERS\.DEFAULT\Software\Ares --> ChatRoom.AutoAddToFavorites detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> ChatRoom.AutoAddToFavorites detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> ChatRoom.AutoClose detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> ChatRoom.AutoClose detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> ChatRoom.ShowTaskBtn detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> ChatRoom.ShowTaskBtn detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.HookBitTorrentExt detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.HookBitTorrentExt detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.Language detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.Language detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.MSNSongNotif detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.MSNSongNotif detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Hashing.Priority detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Hashing.Priority detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Playlist.PreviousASXApp detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Playlist.PreviousASXApp detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Playlist.PreviousM3UApp detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Playlist.PreviousM3UApp detectado: Trace.Registry.Ares Value: HKEY_USERS\.DEFAULT\Software\Ares --> Playlist.PreviousWAXApp detectado: Trace.Registry.Ares Value: HKEY_USERS\S-1-5-18\Software\Ares --> Playlist.PreviousWAXApp detectado: Trace.Registry.Ares C:\Documents and Settings\Karol\Cookies\karol@bluemountain[1].txt detectado: Trace.TrackingCookie C:\Documents and Settings\Karol\Cookies\karol@comandoswing[1].txt detectado: Trace.TrackingCookie C:\Documents and Settings\Karol\Cookies\karol@comprafacil.com[1].txt detectado: Trace.TrackingCookie C:\Documents and Settings\Karol\Cookies\karol@doubleclick[1].txt detectado: Trace.TrackingCookie C:\Documents and Settings\Karol\Cookies\karol@sexobis.com[1].txt detectado: Trace.TrackingCookie C:\Arquivos de programas\STK017_V2.01\STK017M.exe detectado: Adware.Win32.Cres C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\3D Studio Max 9 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Acrobat Professional 8.1 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Creative Suite 3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Photoshop CS3 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Photoshop CS3 Lite KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Photoshop Elements v6.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Photoshop Lightroom 1.3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Premiere Pro CS3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Advanced System Optimizer 2.20.4.746 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Advanced Uninstaller Professional 8.5.1 + Working KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Alcohol 120 v.1.9.6 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Alive YouTube Video Converter 1.2.6.9.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\ALL.Adobe.Products.Cracks.and.Keygens.(ALL.in.One).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\All.Antivirus.Keygen-Serials-Cracks.(Symantec-Antivir-McAfee-Kaspersky-Nod32-AVG).by.ElL0cos.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\All.MicroSoft.Products.Keygens.and.Cracks.(all-in-one).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\AnyDVD & AnyDVD HD 6.3 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Ashampoo Office 2008 3.00 + KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Autodesk 3DS MAX 2008 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Autodesk AutoCAD 2008 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Autodesk Inventor Suite 2008 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Black XP 5.0 DVD Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\ConvertXtoDVD 2.2.3.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\CyberLink PowerDVD 7.3.3516 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Daemon Tools Pro Basic 4.11.0219 Serial.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\DivX Bundle 6.8 Professional + Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\DivX-XviD.Multi.Converter.1.9.[Converte.movies.en.el.fomrat.de.tu.selciòn).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\DVDFab Platinum 4.0.1.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\DVDFab Platinum 4.0.3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Easy DVD Creator 1.6.2 Working KEY! Espanòl.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\ESET NOD32 Antivirus 3.0.566 Patcher to have ALL updates.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\FL Studio 7 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\FlashFXP.v3.6.MULTiLiNGUAL-(ESP-ITA-ENG-DEU-FRA)-KeyGen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\FlashGet 1.9.6.1073 [best Download manager] + Key.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Google Earth 4.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Guitar Pro v5.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Internet Download Manager 5.11.10 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Intervideo WinDVD Platinum 8.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Kaspersky Antivirus Working Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Macromedia DreamWeaver CS3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Magic DVD Ripper 5.2.1/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Magic ISO 5.4 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Magic Video Converter 8.0.2.18 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Matlab 2007 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\McAfee.Total.Protection.2007.Multilingual.Working.Crack-DAiMX.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\McAfee.Total.Protection.2008.WorkingPatch.Update.TILL.2010.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Mega.CODEC.Video.and.Audio.for.WindowsXP.and.Windows.VISTA.colleciòn.by.Mus taX.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Microsoft Office 2007 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Microsoft Windows VISTA Validation Crack 2008 Patch.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Nero 8 Ultra Edition 8.1.1.4 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\NOD32 3.xx Universal Fix Patch.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Norton 360 Working Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Norton Ghost 12 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Norton Product Suite 2007 Keygen (WORK).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\NortonInternetSecurity 2008 Espanol [gracias oN0x].rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\O&O Defrag Professional 10.0.1634 Key (funciona).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Oxygen Phone Manager for Nokia Phones II 2.12.1.5.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Pinnacle Studio Plus v11 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\PlayStation 2 Emulator for PC (PCSX2).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Power ISO 3.8 + Aiudos + Cracks.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Power ISO 3.8 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\RapidGet.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Rapidshare Leecher 2008 + All Rapidshare Tools.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Rapidshare Premium Donloader.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Real Player 11.0.0.372 Crack-W0rking.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Roxio Easy Media Creator 10 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Spyware Doctor 5.1.0.273.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\TuneUp Utilities 2007 6.0.2311 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Winamp Pro v5.5 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\WinAVI Video Converter 8.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Windows Vista x86 Ultimate Genuine Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Windows XP Professional Genuine Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\WinRar 3.71 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\YouTube Downloader.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Configurações locais\Temp\TEMP.ZIP/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\Desktop\VDownloader You Tube\VDownloader.exe detectado: Riskware.Downloader.Win32.VDown.a C:\Documents and Settings\Karol\LimeWire Shared\3D Studio Max 9 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Adobe Acrobat Professional 8.1 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Adobe Creative Suite 3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Adobe Photoshop CS3 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Adobe Photoshop CS3 Lite KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Adobe Photoshop Elements v6.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Adobe Photoshop Lightroom 1.3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Adobe Premiere Pro CS3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Advanced System Optimizer 2.20.4.746 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Advanced Uninstaller Professional 8.5.1 + Working KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Alcohol 120 v.1.9.6 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Alive YouTube Video Converter 1.2.6.9.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\ALL.Adobe.Products.Cracks.and.Keygens.(ALL.in.One).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\All.Antivirus.Keygen-Serials-Cracks.(Symantec-Antivir-McAfee-Kaspersky-Nod32-AVG).by.ElL0cos.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\All.MicroSoft.Products.Keygens.and.Cracks.(all-in-one).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\AnyDVD & AnyDVD HD 6.3 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Ashampoo Office 2008 3.00 + KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Autodesk 3DS MAX 2008 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Autodesk AutoCAD 2008 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Autodesk Inventor Suite 2008 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Black XP 5.0 DVD Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\ConvertXtoDVD 2.2.3.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\CyberLink PowerDVD 7.3.3516 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Daemon Tools Pro Basic 4.11.0219 Serial.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\DivX Bundle 6.8 Professional + Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\DivX-XviD.Multi.Converter.1.9.[Converte.movies.en.el.fomrat.de.tu.selciòn).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\DVDFab Platinum 4.0.1.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\DVDFab Platinum 4.0.3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Easy DVD Creator 1.6.2 Working KEY! Espanòl.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\ESET NOD32 Antivirus 3.0.566 Patcher to have ALL updates.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\FL Studio 7 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\FlashFXP.v3.6.MULTiLiNGUAL-(ESP-ITA-ENG-DEU-FRA)-KeyGen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\FlashGet 1.9.6.1073 [best Download manager] + Key.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Google Earth 4.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Guitar Pro v5.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Internet Download Manager 5.11.10 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Intervideo WinDVD Platinum 8.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Kaspersky Antivirus Working Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Macromedia DreamWeaver CS3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Magic DVD Ripper 5.2.1/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Magic ISO 5.4 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Magic Video Converter 8.0.2.18 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Matlab 2007 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\McAfee.Total.Protection.2007.Multilingual.Working.Crack-DAiMX.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\McAfee.Total.Protection.2008.WorkingPatch.Update.TILL.2010.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Mega.CODEC.Video.and.Audio.for.WindowsXP.and.Windows.VISTA.colleciòn.by.Mus taX.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Microsoft Office 2007 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Microsoft Windows VISTA Validation Crack 2008 Patch.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Nero 8 Ultra Edition 8.1.1.4 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\NOD32 3.xx Universal Fix Patch.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Norton 360 Working Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Norton Ghost 12 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Norton Product Suite 2007 Keygen (WORK).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\NortonInternetSecurity 2008 Espanol [gracias oN0x].rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\O&O Defrag Professional 10.0.1634 Key (funciona).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Oxygen Phone Manager for Nokia Phones II 2.12.1.5.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Pinnacle Studio Plus v11 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\PlayStation 2 Emulator for PC (PCSX2).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Power ISO 3.8 + Aiudos + Cracks.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Power ISO 3.8 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\RapidGet.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Rapidshare Leecher 2008 + All Rapidshare Tools.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Rapidshare Premium Donloader.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Real Player 11.0.0.372 Crack-W0rking.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Roxio Easy Media Creator 10 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Spyware Doctor 5.1.0.273.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\TuneUp Utilities 2007 6.0.2311 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Winamp Pro v5.5 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\WinAVI Video Converter 8.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Windows Vista x86 Ultimate Genuine Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\Windows XP Professional Genuine Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\WinRar 3.71 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\Documents and Settings\Karol\LimeWire Shared\YouTube Downloader.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP149\A0033713.exe detectado: Riskware.Downloader.Win32.VDown.a C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP149\A0033715.exe detectado: Adware.Win32.Cres C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP162\A0036811.DLL detectado: Riskware.AdTool.Win32.MyWebSearch.as C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP162\A0036812.DLL detectado: Riskware.AdTool.Win32.MyWebSearch.bc C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP162\A0036813.EXE detectado: Adware.Win32.MyWebSearch C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP162\A0036814.DLL detectado: Riskware.AdTool.Win32.MyWebSearch C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP162\A0036822.dll detectado: Riskware.AdTool.Win32.MyWebSearch.bc C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP176\A0037996.exe detectado: Trojan.Win32.Agent.dvl C:\WINDOWS\system32\BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy E:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP176\A0038112.exe detectado: Trojan-Dropper.Win32.Agent.dmy E:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP176\A0038113.exe detectado: Adware.Win32.Agent.zk E:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP176\A0038114.exe detectado: Adware.Win32.NewWeb.ay Analisado Arquivos: 271825 Objetos: 360469 Cookies: 183 Processos: 29 Encontrado Arquivos: 161 Objetos: 117 Cookies: 5 Processos: 1 Chaves do registro: 0 Fim da análise: 21/1/2008 21:29:36 Duração da análise: 2:13:01 -------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 21:34:47, on 21/1/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\GbPlugin\GbpSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cmpe.exe c:\arquivos de programas\mcafee.com\agent\mcdetect.exe c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe C:\WINDOWS\system32\PSIService.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wscntfy.exe c:\arquivos de programas\a-squared free\a2free.exe C:\Arquivos de programas\a-squared Free\a2service.exe C:\Arquivos de programas\Windows Media Player\wmplayer.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE C:\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehCef.dll O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe O4 - Global Startup: STK017 PNP Monitor.lnk = ? O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.13\AMVConverter\grab.html O8 - Extra context menu item: Append to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O17 - HKLM\System\CS1\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll O20 - Winlogon Notify: __GbPluginAbn - C:\Arquivos de programas\GbPlugin\gbiehabn.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing) O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Janeiro 22, 2008 Bom Dia carol2906! >@< Estando tudo Ok,vá a quarentena do a-squared,selecione todo o conteúdo e clique em Eliminar. _____________________ >@< Clique com o botão direito do mouse em cima de Meu Computador >> Propriedades >> Restauração do Sistema. >@< Marque: Desativar Restauração do Sistema >> Aplicar >> Ok. >@< Execute,agora,o seu Antivírus ( Avira ) e,tudo o que encontrar,envie para a quarentena. >@< Terminando,reative a Restauração do sistema. >> Aplicar >> Ok. _____________________ >@< O procedimento,dado àcima,foi para que tenhamos um relatório limpo,dado por um nôvo escaneamento em BitDefender. >@< Este escaneamento,será feito em um tempo menor e isento de malware. >@< O relatório,estará em: C:\Windows\BDOSCAN8\bdoscan.txt <!> >@< Caso queira,poste este nôvo relatório,na sua resposta + HJT,atualizado. _____________________ >@< O Log,do HijackThis,está limpo. >@< Algum problema,ainda,com o computador? Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 21, 2008 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto é preciso enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites