Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

carol2906

[Resolvido!]Log hijack e tela do DOS abrindo sozinha

Recommended Posts

:mellow: Oi gente, de uns 4 dias pra cá toda vez que conecto na internet ou executo algum programa aparece o seguinte:

"c:\windows\temp\4379ehe7.exe A CPU NTVDM encontrou uma instrução não permitida.

CS:06ce IP:01 de OP:63 68 65 2f 31 Escolha fechar para finalizar o aplicativo." Daí aparece uma telinha do DOS...

muito estranho, isso aconteceu depois que eu baixei um arquivo no limewire que era um suposto keygen do adobe lightroom e quando executei ele criou vários arquivos como se fossem keygens de outros programas na minha pasta de compartilhamento do limewire...

 

 

Obs: Quando entro na internet o antivirus ta acusando assim: "Virus or unwanted program 'BAT/DelFiles.AY [bAT/DelFiles.AY]'

detected in file 'C:\autoexec.bat."

Meu PC tá uma carroça. Ajudem por favor!!!

 

 

Segue o log do hijack:

 

Logfile of HijackThis v1.99.1

Scan saved at 09:45:38, on 16/1/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\ARQUIV~1\mcafee.com\agent\McAgent.exe

C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe

C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe

C:\Arquivos de programas\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe

c:\arquiv~1\mcafee.com\vso\mcvsescn.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\cmpe.exe

c:\arquivos de programas\mcafee.com\agent\mcdetect.exe

c:\ARQUIV~1\mcafee.com\vso\mcshield.exe

c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe

C:\WINDOWS\system32\PSIService.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\STK017_V2.01\STK017M.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\notepad.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll

O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehCef.dll

O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\Arquivos de programas\GbPlugin\gbiehabn.dll

O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [MCUpdateExe] c:\ARQUIV~1\mcafee.com\agent\mcupdate.exe

O4 - HKLM\..\Run: [MCAgentExe] c:\ARQUIV~1\mcafee.com\agent\McAgent.exe

O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask

O4 - HKLM\..\Run: [VirusScan Online] C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe

O4 - HKLM\..\Run: [OASClnt] C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Arquivos de programas\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?

O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe

O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe

O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe

O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe

O4 - Global Startup: STK017 PNP Monitor.lnk = ?

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZSYYYYYYYYBR

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.13\AMVConverter\grab.html

O8 - Extra context menu item: Append to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab

O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O17 - HKLM\System\CS1\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: __GbPluginAbn - C:\Arquivos de programas\GbPlugin\gbiehabn.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe

O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe

O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe

O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia carol2906!

 

>@< Cole no Bloco de Notas. ( Tudo o que estiver,abaixo da palavra quote! )

>@< Em: Salvar como tipo: escolha Todos os arquivos

>@< Em: Nome do Arquivo: coloque Temp.bat

>@< Salve este arquivo,no Desktop!

>@< Execute-o com um duplo clique!

 

@ECHO OFF

IF NOT %temp% == %tmp% GOTO both

GOTO single

:both

DEL %temp%\*.* /F /S /Q

DEL %tmp%\*.* /F /S /Q

CLS

ECHO Deleted all files in the TEMP folder: %temp%

ECHO Deleted all files in the TMP folder: %tmp%

GOTO end

:single

DEL %temp%\*.* /F /S /Q

DEL %systemroot%\Temp\*.* /F /S /Q

CLS

ECHO Deleted all files in the TEMP folder: %temp%

:end

____________________

 

>@< Faça um escaneamento de desinfecção em < BitDefender > e poste o relatório.

>@< Clique em BitDefender ( Scan OnLine ).

>@< Abrirá a página: < BitDefender OnLine Scanner >

>@< Clique em I Agree.

>@< Aguarde!Permita a instalação do ActiveX,para que possa ocorrer o scan.

____________________

 

>@< Poste,então: Relatório do BitDefender + Log do HijackThis,atualizado.

 

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

BitDefender Online Scanner - Real Time Virus Report

 

 

 

Generated at: Sat, Jan 19, 2008 - 22:45:14

 

 

--------------------------------------------------------------------------------

 

 

 

 

 

Scan Info

 

 

 

Scanned Files

563240

 

Infected Files

10

 

 

 

 

 

 

 

 

Virus Detected

 

 

 

DeepScan:Generic.Malware.SI!Bdldg.7C687210

1

 

Trojan.Funweb.A

1

 

Trojan.Vundo.DWK

2

 

Trojan.Dropper.Delf.FP

2

 

Trojan.BAT.KillFiles.GD

2

 

Trojan.Vundo.DVS

2

 

 

 

 

 

 

 

 

 

 

--------------------------------------------------------------------------------

 

 

 

This summary of the scan process will be used by the BitDefender Antivirus Lab to create agregate statistics about virus activity around the world.

 

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 22:48:32, on 19/1/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\ARQUIV~1\mcafee.com\agent\McAgent.exe

C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe

C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe

C:\Arquivos de programas\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

c:\arquiv~1\mcafee.com\vso\mcvsescn.exe

C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\cmpe.exe

c:\arquivos de programas\mcafee.com\agent\mcdetect.exe

c:\ARQUIV~1\mcafee.com\vso\mcshield.exe

c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe

C:\WINDOWS\system32\PSIService.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\STK017_V2.01\STK017M.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\rundll32.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\MSN Messenger\msnmsgr.exe

c:\arquiv~1\mcafee.com\vso\mcvsftsn.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\MSN Messenger\usnsvc.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

F3 - REG:win.ini: load=C:\WINDOWS\system32\awtqr.exe

O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [MCUpdateExe] c:\ARQUIV~1\mcafee.com\agent\mcupdate.exe

O4 - HKLM\..\Run: [MCAgentExe] c:\ARQUIV~1\mcafee.com\agent\McAgent.exe

O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask

O4 - HKLM\..\Run: [VirusScan Online] C:\Arquivos de programas\McAfee.com\VSO\mcvsshld.exe

O4 - HKLM\..\Run: [OASClnt] C:\Arquivos de programas\McAfee.com\VSO\oasclnt.exe

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Arquivos de programas\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?

O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe

O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe

O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe

O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe

O4 - Global Startup: STK017 PNP Monitor.lnk = ?

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZSYYYYYYYYBR

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.13\AMVConverter\grab.html

O8 - Extra context menu item: Append to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab

O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O17 - HKLM\System\CS1\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe

O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe

O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe

O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia carol2906!

 

>@< Faça o download do ComboFix.

>@< Baixe-o para o Desktop!

>@< Feche todas as janelas e execute a ferramenta!

>@< Para quem possui o Avast,surgirá um alerta de malware ( Win32 D adobra-EY[Trj] ),que deverá ser ignorado.

>@< Abrirá a janela Auto Scan. Aguarde!

>@< Digite a opção para continuar e < Enter >

>@< Aguarde a conclusão!

________________________

 

>@< Poste o relatório: C:\ComboFix.txt,na sua resposta + Log do HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oi DigRam

 

Tentei executar o programa que você falou e acho que não deu certo, meu windows reiniciou sozinho duas vezes, era pra ser assim??? O único txt que achei com o nome combofix diz o seguinte:

 

 

ComboFix 08-01-20.1 - Karol 2008-01-20 16:13:33.2 - NTFSx86

Executando de: C:\Documents and Settings\Karol\Desktop\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 16:24, on 2008-01-20

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\cmpe.exe

c:\arquivos de programas\mcafee.com\agent\mcdetect.exe

c:\ARQUIV~1\mcafee.com\vso\mcshield.exe

c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe

C:\WINDOWS\system32\PSIService.exe

C:\Arquivos de programas\STK017_V2.01\STK017M.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: (no name) - {5AAF23D8-4489-43D8-A064-319D1254ABCA} - C:\WINDOWS\system32\jkkijkk.dll (file missing)

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll

O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehCef.dll

O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O2 - BHO: (no name) - {FDF18230-EE8E-4FC3-856C-283A21B73A9C} - C:\WINDOWS\system32\awtqr.dll (file missing)

O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?

O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe

O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe

O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe

O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe

O4 - Global Startup: STK017 PNP Monitor.lnk = ?

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZSYYYYYYYYBR

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.13\AMVConverter\grab.html

O8 - Extra context menu item: Append to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab

O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O17 - HKLM\System\CS1\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O17 - HKLM\System\CS2\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll

O20 - Winlogon Notify: jkkijkk - jkkijkk.dll (file missing)

O20 - Winlogon Notify: __GbPluginAbn - C:\Arquivos de programas\GbPlugin\gbiehabn.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe

O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe

O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe

O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia carol2906!

 

Tentei executar o programa que você falou e acho que não deu certo, meu windows reiniciou sozinho duas vezes, era pra ser assim??? O único txt que achei com o nome combofix diz o seguinte:

>@< Execute a ferramenta,em Modo de Segurança! Creio que desta forma,teremos um relatório.

____________________________

 

>@< Faça o download do VundoFix.

>@< Salve-o no Desktop!

>@< Execute o VundoFix.exe

>@< Quando o VundoFix abrir,novamente, clique em Scan for Vundo.

>@< Quando ele terminar, clique em Remove Vundo.

>@< Você receberá um prompt perguntando se quer remover os arquivos. Confirme!

>@< Sua área de trabalho vai desaparecer!

>@< Surgirá um aviso dizendo que seu computador deve ser desligado.

>@< Clique em OK e depois,ligue o computador novamente!

>@< É possível que o VundoFix encontre um arquivo, mas não consiga removê-lo. Se isso acontecer, a ferramenta rodará ao reiniciar.

>@< Quando o VundoFix aparecer, clique no botão Scan for Vundo para repetir o processo.

>@< Quando o VundoFix não encontrar mais nenhum arquivo,que não consiga remover,poste o seu relatório ( Log ) que se encontra em C:\Vundofix.txt

>@< Poste,também,um nôvo Log do HijackThis + ComboFix.txt <!>

 

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 08-01-20.1 - Karol 2008-01-21 9:24:38.4 - NTFSx86 MINIMAL

Executando de: C:\Documents and Settings\Karol\Desktop\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

---- Previous Run -------

.

C:\Arquivos de programas\MyWebSearch

C:\WINDOWS\system32\awtqr.dll

C:\WINDOWS\system32\jkkijkk.dll

C:\WINDOWS\system32\mcrh.tmp

C:\WINDOWS\system32\rqtwa.ini

C:\WINDOWS\system32\rqtwa.ini2

 

.

((((((((((((((((((((((( Ficheiros criados de 2007-12-21 to 2008-01-21 ))))))))))))))))))))))))))))))))

.

 

2008-01-20 15:56 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-19 23:28 . 2008-01-20 08:44 <DIR> d-------- C:\WINDOWS\SxsCaPendDel

2008-01-17 09:31 . 2008-01-19 22:45 <DIR> d-------- C:\WINDOWS\BDOSCAN8

2008-01-17 09:19 . 2008-01-17 09:17 150 --a------ C:\copia de autoexec.bat

2008-01-17 09:17 . 2008-01-17 09:17 6,144 --ahs---- C:\Thumbs.db

2008-01-17 09:07 . 2008-01-17 09:07 8,192 --ahs---- C:\WINDOWS\system32\Thumbs.db

2008-01-16 11:21 . 2008-01-16 11:21 <DIR> d-------- C:\Documents and Settings\Karol\Dados de aplicativos\Comodo

2008-01-16 11:21 . 2008-01-16 11:21 <DIR> d-------- C:\Arquivos de programas\COMODO

2008-01-16 11:09 . 2008-01-16 22:47 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2008-01-16 11:04 . 2008-01-16 11:04 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Avira

2008-01-16 11:04 . 2008-01-16 11:04 <DIR> d-------- C:\Arquivos de programas\Avira

2008-01-15 19:46 . 2008-01-15 19:46 <DIR> d--h----- C:\WINDOWS\PIF

2008-01-14 20:51 . 2008-01-17 09:17 <DIR> d-------- C:\Eye Candy 4000

2008-01-14 20:51 . 2008-01-20 18:48 373,248 --a------ C:\WINDOWS\EyeCand3.INI

2008-01-14 20:45 . 2008-01-14 20:48 4,285 --a------ C:\WINDOWS\IFiltSet.Ini

2008-01-14 20:43 . 2008-01-14 20:43 <DIR> d-------- C:\Arquivos de programas\byLight

2008-01-14 20:43 . 2008-01-19 23:24 33 --a------ C:\WINDOWS\iltwain.ini

2008-01-11 19:31 . 2008-01-21 09:31 <DIR> d-a------ C:\Documents and Settings\All Users\Dados de aplicativos\TEMP

2008-01-11 19:31 . 2004-08-30 21:00 1,499,136 --a------ C:\WINDOWS\system32\BTCPatcher.exe

2008-01-11 19:31 . 2008-01-11 19:31 37,888 --a------ C:\WINDOWS\system32\rar.exe

2008-01-07 21:54 . 2008-01-07 22:45 <DIR> d-------- C:\Arquivos de programas\eMule

2008-01-07 21:50 . 2008-01-07 21:50 <DIR> d-------- C:\Documents and Settings\Karol\LimeWire Store Purchased

2008-01-07 21:50 . 2008-01-15 08:29 <DIR> d-------- C:\Documents and Settings\Karol\LimeWire Shared

2008-01-07 21:50 . 2008-01-07 21:50 <DIR> d-------- C:\Documents and Settings\Karol\Incomplete

2008-01-07 21:49 . 2008-01-20 08:57 <DIR> d-------- C:\Documents and Settings\Karol\Dados de aplicativos\LimeWire

2008-01-07 21:49 . 2008-01-07 21:49 <DIR> d-------- C:\Arquivos de programas\LimeWire

2008-01-04 18:41 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys

2008-01-04 18:41 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys

2007-12-22 19:37 . 2007-12-22 19:38 <DIR> d-------- C:\Arquivos de programas\TagScanner

2007-12-22 18:45 . 2007-12-22 18:49 <DIR> d-------- C:\Arquivos de programas\eMusic Tag Editor

 

.

((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-20 18:06 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin

2008-01-20 18:06 --------- d-----w C:\Arquivos de programas\GbPlugin

2008-01-20 01:33 --------- d-----w C:\Arquivos de programas\NCH Swift Sound

2008-01-20 01:32 --------- d-----w C:\Arquivos de programas\Corel

2008-01-17 12:32 --------- d-----w C:\Documents and Settings\Karol\Dados de aplicativos\Alien Skin

2008-01-16 11:22 --------- d-----w C:\Documents and Settings\Karol\Dados de aplicativos\Corel

2007-12-27 12:04 --------- d-----w C:\Arquivos de programas\StuffPlug3

2007-12-27 11:44 --------- d-----w C:\Arquivos de programas\NCH Software

2007-12-26 13:33 --------- d-----w C:\Arquivos de programas\a-squared Free

2007-12-16 15:09 --------- d-----w C:\Arquivos de programas\Google

2007-12-15 16:44 --------- d-----w C:\Arquivos de programas\MSN Messenger

2007-12-13 22:32 --------- d-----w C:\Arquivos de programas\STK017_V2.01

2007-12-11 22:39 --------- d-----w C:\Arquivos de programas\IObit

2007-12-11 22:36 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Skype

2007-12-01 15:52 --------- d-----w C:\Documents and Settings\Karol\Dados de aplicativos\Nero

2007-11-30 13:18 --------- d-----w C:\Arquivos de programas\MP3 Player Utilities 4.00

2007-11-30 13:18 --------- d-----w C:\Arquivos de programas\MP3 Player Utilities 3.57

2007-11-29 11:10 --------- d-----w C:\Arquivos de programas\Messenger Plus! Live

2007-11-29 11:02 --------- d-----w C:\Arquivos de programas\Bonjour

2007-11-10 17:00 2 ----a-w C:\Arquivos de programas\history.rcd

2007-10-25 12:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe

2007-08-18 22:34 533 ----a-w C:\Arquivos de programas\UnInst.log

2004-10-01 18:00 40,960 ----a-w C:\Arquivos de programas\Uninstall_CDS.exe

2002-04-09 19:16 622,592 ----a-w C:\Arquivos de programas\recorder.exe

1998-02-12 19:54 149,504 ----a-w C:\Arquivos de programas\convert.dll

2007-09-05 15:58 88 --sh--r C:\WINDOWS\system32\65D31702E2.sys

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"PowerBar"="" []

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]

"swg"="C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]

"Nero PhotoShow Media Manager"="C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [ ]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"VSOCheckTask"="C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" [ ]

"avgnt"="C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [ ]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [ ]

 

C:\Documents and Settings\Karol\Menu Iniciar\Programas\Inicializar\

Recorte de tela e Iniciador do OneNote 2007.lnk - C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 21:24:54 98632]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]

"NTSpool"= NTSpool.exe

"System Patcher"= BTCPatcher.exe

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{E37CB5F0-51F5-4395-A808-5FA49E399007}"= C:\ARQUIV~1\GbPlugin\gbiehabn.dll [2007-11-19 19:02 341928]

"{E37CB5F0-51F5-4395-A808-5FA49E399003}"= C:\Arquivos de programas\GbPlugin\gbiehCef.dll [2007-11-29 11:41 337992]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginAbn]

C:\ARQUIV~1\GbPlugin\gbiehabn.dll 2007-11-19 19:02 341928 C:\ARQUIV~1\GbPlugin\gbiehabn.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]

C:\Arquivos de programas\GbPlugin\gbiehCef.dll 2007-11-29 11:41 337992 C:\Arquivos de programas\GbPlugin\gbiehCef.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__GbPluginAbn]

C:\Arquivos de programas\GbPlugin\gbiehabn.dll 2007-11-19 19:02 341928 C:\Arquivos de programas\GbPlugin\gbiehabn.dll

 

 

.

Conte£do da pasta 'Tarefas Agendadas'

"2007-12-19 19:38:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"

- C:\Arquivos de programas\Apple Software Update\SoftwareUpdate.exe

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-21 09:31:36

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializ veis ocultas ...

 

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

PowerBar = ????????????l?@?l?@?D?????6~??????????????6~l?@?l?@????? ???????????W?9~??6~??????6~K?6~x???????[?6~???????? ??????????????|x???0???????????? ot??6~????????????????????????????????l?@?l?@?????Q?7~????t?@?????l?@?8?@?l?@?3??s????????????????????8?@?_??s8?@?8?@

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

 

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]

-> C:\Arquivos de programas\ArcSoft\Software Suite\PhotoImpression\share\pihook.dll

.

Tempo para conclusÆo: 2008-01-21 9:36:13 - machine was rebooted [Karol]

ComboFix-quarantined-files.txt 2008-01-21 11:36:09

.

2008-01-09 14:24:25 --- E O F ---

 

 

-----------------------------------------------------------------------------------------------------------------------------------------

 

 

 

VundoFix V6.7.7

 

Checking Java version...

 

Sun Java not detected

Scan started at 09:38:08 21/1/2008

 

Listing files found while scanning....

 

C:\ARQUIV~1\GbPlugin\gbiehabn.dll

C:\Arquivos de programas\GbPlugin\gbiehCef.dll

 

Beginning removal...

 

Attempting to delete C:\ARQUIV~1\GbPlugin\gbiehabn.dll

C:\ARQUIV~1\GbPlugin\gbiehabn.dll Could not be deleted.

 

Attempting to delete C:\Arquivos de programas\GbPlugin\gbiehCef.dll

C:\Arquivos de programas\GbPlugin\gbiehCef.dll Could not be deleted.

 

Performing Repairs to the registry.

Done!

 

Beginning removal...

 

Attempting to delete C:\ARQUIV~1\GbPlugin\gbiehabn.dll

C:\ARQUIV~1\GbPlugin\gbiehabn.dll Could not be deleted.

 

Attempting to delete C:\Arquivos de programas\GbPlugin\gbiehCef.dll

C:\Arquivos de programas\GbPlugin\gbiehCef.dll Could not be deleted.

 

Performing Repairs to the registry.

Done!

 

Beginning removal...

 

VundoFix V6.7.7

 

Checking Java version...

 

Sun Java not detected

Scan started at 10:22:29 21/1/2008

 

Listing files found while scanning....

 

C:\ARQUIV~1\GbPlugin\gbiehabn.dll

C:\Arquivos de programas\GbPlugin\gbiehCef.dll

 

Beginning removal...

 

Attempting to delete C:\ARQUIV~1\GbPlugin\gbiehabn.dll

C:\ARQUIV~1\GbPlugin\gbiehabn.dll Could not be deleted.

 

Attempting to delete C:\Arquivos de programas\GbPlugin\gbiehCef.dll

C:\Arquivos de programas\GbPlugin\gbiehCef.dll Could not be deleted.

 

Performing Repairs to the registry.

Done!

 

 

----------------------------------------------------------------------------------------------------------------------------------------

 

 

Logfile of HijackThis v1.99.1

Scan saved at 11:02:28, on 21/1/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\cmpe.exe

c:\arquivos de programas\mcafee.com\agent\mcdetect.exe

c:\ARQUIV~1\mcafee.com\vso\mcshield.exe

c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe

C:\WINDOWS\system32\PSIService.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\STK017_V2.01\STK017M.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll

O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehCef.dll

O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?

O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe

O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe

O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe

O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe

O4 - Global Startup: STK017 PNP Monitor.lnk = ?

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZSYYYYYYYYBR

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.13\AMVConverter\grab.html

O8 - Extra context menu item: Append to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab

O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O17 - HKLM\System\CS1\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O17 - HKLM\System\CS2\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll

O20 - Winlogon Notify: __GbPluginAbn - C:\Arquivos de programas\GbPlugin\gbiehabn.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe

O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe

O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe

O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde carol2906!

 

>@< Abra o HijackThis e,com todas as janelas fechadas,dê Fix nestas entradas:

 

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZSYYYYYYYYBR

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab

________________________

 

>@< Faça o download do a-squared Free 3.0

>@< Abra o programa e clique em: Atualizar agora >> Aguarde!

>@< Terminando,clique em: Analisar agora.

>@< Caso possa,procure fazer,esta análise,em Modo de Segurança! << Opcional!

>@< Escolha a opção: A fundo.

>@< Clique em Analisar!

>@< Terminando,envie os ítens encontrados para a quarentena.

>@< Aonde,daí,serão excluídos ou restaurados.

________________________

 

>@< Copie o relatório,desta verificação,e poste na sua resposta + HJT,atualizado.

 

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

a-squared Free - Versão 3.1

Última atualização 21/1/2008 19:15:28

 

Configurações da análise:

 

Objetos: Memória, Rastros, Cookies, C:\, E:\

Análise de arquivos: Ligado

Heurística: Ligado

Análise de ADS: Ligado

 

Início da análise: 21/1/2008 19:16:35

 

[1228] C:\Arquivos de programas\STK017_V2.01\STK017M.exe detectado: Adware.Win32.Cres

Value: HKEY_CLASSES_ROOT\arlnk --> URL Protocol detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares\bounds --> Main.Maximized detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares\bounds --> Main.Maximized detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares\Columns\Transfers --> Download detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares\Columns\Transfers --> Download detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares\Columns\Transfers --> Queue detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares\Columns\Transfers --> Queue detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares\Columns\Transfers --> Upload detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares\Columns\Transfers --> Upload detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares\Data --> AresNet1 detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares\Data --> AresNet1 detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares\Data --> JI.AresNet1 detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares\Data --> JI.AresNet1 detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares\Positions\Transfers --> Download detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares\Positions\Transfers --> Download detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares\Positions\Transfers --> Queue detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares\Positions\Transfers --> Queue detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares\Positions\Transfers --> Upload detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares\Positions\Transfers --> Upload detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Extra.ShowActiveCaption detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Extra.ShowActiveCaption detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.AutoConnect detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.AutoConnect detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.AutoStartUp detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.AutoStartUp detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.LastLibraryMode detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.LastLibraryMode detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> GUI.LastChatRoomBrowse detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> GUI.LastChatRoomBrowse detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> GUI.LastLibrary detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> GUI.LastLibrary detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> GUI.LastPMBrowse detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> GUI.LastPMBrowse detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> GUI.LastSearch detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> GUI.LastSearch detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Network.DHTID detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Network.DHTID detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Personal.GUID detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Personal.GUID detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Privacy.SendRegularPath detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Privacy.SendRegularPath detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> PrivateMessage.AllowBrowse detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> PrivateMessage.AllowBrowse detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> PrivateMessage.AwayMessage detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> PrivateMessage.AwayMessage detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.CAvgTime detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.CAvgTime detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.CDnSpeed detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.CDnSpeed detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.CFRTime detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.CFRTime detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.CTtUptime detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.CTtUptime detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.CUpSpeed detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.CUpSpeed detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.HasLQCa detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.HasLQCa detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.LstCaQuery detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.LstCaQuery detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Stats.LstCaQueryInt detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Stats.LstCaQueryInt detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Transfer.MaximizeUpBandOnIdle detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Transfer.MaximizeUpBandOnIdle detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Transfer.ServerPort detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Transfer.ServerPort detectado: Trace.Registry.Ares

Key: HKEY_CLASSES_ROOT\interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} detectado: Trace.Registry.FunWebProducts

Key: HKEY_LOCAL_MACHINE\software\fun web products detectado: Trace.Registry.FunWebProducts

Value: HKEY_USERS\S-1-5-21-725345543-688789844-2147238677-1003\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} --> DisplayName detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_USERS\S-1-5-21-725345543-688789844-2147238677-1003\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} --> URL detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\ScreenSaver --> ImagesDir detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn --> ETag detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn --> HTMLMenuRevision detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\CursorManiaBtn --> LastHTMLMenuURL detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyFreqNone detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyFreqUninstalled detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyTextNone.0 detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyTextNone.numActive detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyTextUninstalled.0 detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> BuddyTextUninstalled.numActive detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> MSN.1 detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> MSN.2 detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> MSN.numActive detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\Promos --> MSN.numActive2 detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn --> ETag detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn --> HTMLMenuPosDeleted detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn --> HTMLMenuRevision detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products\Settings\SmileyCentralBtn --> LastHTMLMenuURL detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products --> CacheDir detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products --> JpegConversionLib detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} --> DisplayName detectado: Trace.Registry.MyWebSearch Toolbar

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} --> URL detectado: Trace.Registry.MyWebSearch Toolbar

Key: HKEY_CLASSES_ROOT\clsid\{a4730ebe-43a6-443e-9776-36915d323ad3} detectado: Trace.Registry.MyWebSearchToobar

Key: HKEY_CLASSES_ROOT\interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} detectado: Trace.Registry.MyWebSearchToobar

Key: HKEY_USERS\S-1-5-21-725345543-688789844-2147238677-1003\software\mywebsearch detectado: Trace.Registry.MyWebSearchToobar

Key: HKEY_CLASSES_ROOT\clsid\{a4730ebe-43a6-443e-9776-36915d323ad3} detectado: Trace.Registry.MyWebSearchToolbar

Key: HKEY_CLASSES_ROOT\interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} detectado: Trace.Registry.MyWebSearchToolbar

Key: HKEY_USERS\S-1-5-21-725345543-688789844-2147238677-1003\software\mywebsearch detectado: Trace.Registry.MyWebSearchToolbar

Value: HKEY_USERS\.DEFAULT\Software\Ares --> ChatRoom.AutoAddToFavorites detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> ChatRoom.AutoAddToFavorites detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> ChatRoom.AutoClose detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> ChatRoom.AutoClose detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> ChatRoom.ShowTaskBtn detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> ChatRoom.ShowTaskBtn detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.HookBitTorrentExt detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.HookBitTorrentExt detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.Language detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.Language detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> General.MSNSongNotif detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> General.MSNSongNotif detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Hashing.Priority detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Hashing.Priority detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Playlist.PreviousASXApp detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Playlist.PreviousASXApp detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Playlist.PreviousM3UApp detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Playlist.PreviousM3UApp detectado: Trace.Registry.Ares

Value: HKEY_USERS\.DEFAULT\Software\Ares --> Playlist.PreviousWAXApp detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-18\Software\Ares --> Playlist.PreviousWAXApp detectado: Trace.Registry.Ares

C:\Documents and Settings\Karol\Cookies\karol@bluemountain[1].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\Karol\Cookies\karol@comandoswing[1].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\Karol\Cookies\karol@comprafacil.com[1].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\Karol\Cookies\karol@doubleclick[1].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\Karol\Cookies\karol@sexobis.com[1].txt detectado: Trace.TrackingCookie

C:\Arquivos de programas\STK017_V2.01\STK017M.exe detectado: Adware.Win32.Cres

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\3D Studio Max 9 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Acrobat Professional 8.1 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Creative Suite 3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Photoshop CS3 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Photoshop CS3 Lite KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Photoshop Elements v6.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Photoshop Lightroom 1.3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Adobe Premiere Pro CS3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Advanced System Optimizer 2.20.4.746 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Advanced Uninstaller Professional 8.5.1 + Working KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Alcohol 120 v.1.9.6 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Alive YouTube Video Converter 1.2.6.9.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\ALL.Adobe.Products.Cracks.and.Keygens.(ALL.in.One).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\All.Antivirus.Keygen-Serials-Cracks.(Symantec-Antivir-McAfee-Kaspersky-Nod32-AVG).by.ElL0cos.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\All.MicroSoft.Products.Keygens.and.Cracks.(all-in-one).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\AnyDVD & AnyDVD HD 6.3 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Ashampoo Office 2008 3.00 + KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Autodesk 3DS MAX 2008 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Autodesk AutoCAD 2008 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Autodesk Inventor Suite 2008 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Black XP 5.0 DVD Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\ConvertXtoDVD 2.2.3.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\CyberLink PowerDVD 7.3.3516 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Daemon Tools Pro Basic 4.11.0219 Serial.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\DivX Bundle 6.8 Professional + Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\DivX-XviD.Multi.Converter.1.9.[Converte.movies.en.el.fomrat.de.tu.selciòn).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\DVDFab Platinum 4.0.1.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\DVDFab Platinum 4.0.3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Easy DVD Creator 1.6.2 Working KEY! Espanòl.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\ESET NOD32 Antivirus 3.0.566 Patcher to have ALL updates.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\FL Studio 7 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\FlashFXP.v3.6.MULTiLiNGUAL-(ESP-ITA-ENG-DEU-FRA)-KeyGen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\FlashGet 1.9.6.1073 [best Download manager] + Key.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Google Earth 4.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Guitar Pro v5.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Internet Download Manager 5.11.10 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Intervideo WinDVD Platinum 8.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Kaspersky Antivirus Working Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Macromedia DreamWeaver CS3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Magic DVD Ripper 5.2.1/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Magic ISO 5.4 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Magic Video Converter 8.0.2.18 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Matlab 2007 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\McAfee.Total.Protection.2007.Multilingual.Working.Crack-DAiMX.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\McAfee.Total.Protection.2008.WorkingPatch.Update.TILL.2010.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Mega.CODEC.Video.and.Audio.for.WindowsXP.and.Windows.VISTA.colleciòn.by.Mus

taX.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Microsoft Office 2007 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Microsoft Windows VISTA Validation Crack 2008 Patch.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Nero 8 Ultra Edition 8.1.1.4 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\NOD32 3.xx Universal Fix Patch.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Norton 360 Working Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Norton Ghost 12 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Norton Product Suite 2007 Keygen (WORK).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\NortonInternetSecurity 2008 Espanol [gracias oN0x].rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\O&O Defrag Professional 10.0.1634 Key (funciona).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Oxygen Phone Manager for Nokia Phones II 2.12.1.5.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Pinnacle Studio Plus v11 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\PlayStation 2 Emulator for PC (PCSX2).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Power ISO 3.8 + Aiudos + Cracks.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Power ISO 3.8 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\RapidGet.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Rapidshare Leecher 2008 + All Rapidshare Tools.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Rapidshare Premium Donloader.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Real Player 11.0.0.372 Crack-W0rking.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Roxio Easy Media Creator 10 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Spyware Doctor 5.1.0.273.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\TuneUp Utilities 2007 6.0.2311 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Winamp Pro v5.5 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\WinAVI Video Converter 8.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Windows Vista x86 Ultimate Genuine Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\Windows XP Professional Genuine Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\WinRar 3.71 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Dados de aplicativos\Ares\My Shared Folder\YouTube Downloader.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Configurações locais\Temp\TEMP.ZIP/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\Desktop\VDownloader You Tube\VDownloader.exe detectado: Riskware.Downloader.Win32.VDown.a

C:\Documents and Settings\Karol\LimeWire Shared\3D Studio Max 9 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Adobe Acrobat Professional 8.1 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Adobe Creative Suite 3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Adobe Photoshop CS3 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Adobe Photoshop CS3 Lite KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Adobe Photoshop Elements v6.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Adobe Photoshop Lightroom 1.3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Adobe Premiere Pro CS3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Advanced System Optimizer 2.20.4.746 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Advanced Uninstaller Professional 8.5.1 + Working KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Alcohol 120 v.1.9.6 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Alive YouTube Video Converter 1.2.6.9.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\ALL.Adobe.Products.Cracks.and.Keygens.(ALL.in.One).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\All.Antivirus.Keygen-Serials-Cracks.(Symantec-Antivir-McAfee-Kaspersky-Nod32-AVG).by.ElL0cos.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\All.MicroSoft.Products.Keygens.and.Cracks.(all-in-one).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\AnyDVD & AnyDVD HD 6.3 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Ashampoo Office 2008 3.00 + KEY.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Autodesk 3DS MAX 2008 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Autodesk AutoCAD 2008 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Autodesk Inventor Suite 2008 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Black XP 5.0 DVD Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\ConvertXtoDVD 2.2.3.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\CyberLink PowerDVD 7.3.3516 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Daemon Tools Pro Basic 4.11.0219 Serial.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\DivX Bundle 6.8 Professional + Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\DivX-XviD.Multi.Converter.1.9.[Converte.movies.en.el.fomrat.de.tu.selciòn).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\DVDFab Platinum 4.0.1.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\DVDFab Platinum 4.0.3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Easy DVD Creator 1.6.2 Working KEY! Espanòl.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\ESET NOD32 Antivirus 3.0.566 Patcher to have ALL updates.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\FL Studio 7 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\FlashFXP.v3.6.MULTiLiNGUAL-(ESP-ITA-ENG-DEU-FRA)-KeyGen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\FlashGet 1.9.6.1073 [best Download manager] + Key.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Google Earth 4.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Guitar Pro v5.2 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Internet Download Manager 5.11.10 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Intervideo WinDVD Platinum 8.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Kaspersky Antivirus Working Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Macromedia DreamWeaver CS3 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Magic DVD Ripper 5.2.1/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Magic ISO 5.4 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Magic Video Converter 8.0.2.18 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Matlab 2007 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\McAfee.Total.Protection.2007.Multilingual.Working.Crack-DAiMX.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\McAfee.Total.Protection.2008.WorkingPatch.Update.TILL.2010.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Mega.CODEC.Video.and.Audio.for.WindowsXP.and.Windows.VISTA.colleciòn.by.Mus

taX.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Microsoft Office 2007 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Microsoft Windows VISTA Validation Crack 2008 Patch.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Nero 8 Ultra Edition 8.1.1.4 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\NOD32 3.xx Universal Fix Patch.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Norton 360 Working Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Norton Ghost 12 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Norton Product Suite 2007 Keygen (WORK).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\NortonInternetSecurity 2008 Espanol [gracias oN0x].rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\O&O Defrag Professional 10.0.1634 Key (funciona).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Oxygen Phone Manager for Nokia Phones II 2.12.1.5.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Pinnacle Studio Plus v11 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\PlayStation 2 Emulator for PC (PCSX2).rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Power ISO 3.8 + Aiudos + Cracks.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Power ISO 3.8 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\RapidGet.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Rapidshare Leecher 2008 + All Rapidshare Tools.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Rapidshare Premium Donloader.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Real Player 11.0.0.372 Crack-W0rking.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Roxio Easy Media Creator 10 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Spyware Doctor 5.1.0.273.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\TuneUp Utilities 2007 6.0.2311 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Winamp Pro v5.5 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\WinAVI Video Converter 8.0 Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Windows Vista x86 Ultimate Genuine Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\Windows XP Professional Genuine Keygen.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\WinRar 3.71 Crack.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\Documents and Settings\Karol\LimeWire Shared\YouTube Downloader.rar/BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP149\A0033713.exe detectado: Riskware.Downloader.Win32.VDown.a

C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP149\A0033715.exe detectado: Adware.Win32.Cres

C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP162\A0036811.DLL detectado: Riskware.AdTool.Win32.MyWebSearch.as

C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP162\A0036812.DLL detectado: Riskware.AdTool.Win32.MyWebSearch.bc

C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP162\A0036813.EXE detectado: Adware.Win32.MyWebSearch

C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP162\A0036814.DLL detectado: Riskware.AdTool.Win32.MyWebSearch

C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP162\A0036822.dll detectado: Riskware.AdTool.Win32.MyWebSearch.bc

C:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP176\A0037996.exe detectado: Trojan.Win32.Agent.dvl

C:\WINDOWS\system32\BTCPatcher.exe detectado: Trojan-Dropper.Win32.Agent.dmy

E:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP176\A0038112.exe detectado: Trojan-Dropper.Win32.Agent.dmy

E:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP176\A0038113.exe detectado: Adware.Win32.Agent.zk

E:\System Volume Information\_restore{F932BFD1-059D-4A5B-A34C-31F04BF35741}\RP176\A0038114.exe detectado: Adware.Win32.NewWeb.ay

 

Analisado

 

Arquivos: 271825

Objetos: 360469

Cookies: 183

Processos: 29

 

Encontrado

 

Arquivos: 161

Objetos: 117

Cookies: 5

Processos: 1

Chaves do registro: 0

 

Fim da análise: 21/1/2008 21:29:36

Duração da análise: 2:13:01

 

 

 

--------------------------------------------------------------------------------------------------------------------------------------

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 21:34:47, on 21/1/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\cmpe.exe

c:\arquivos de programas\mcafee.com\agent\mcdetect.exe

c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe

C:\WINDOWS\system32\PSIService.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wscntfy.exe

c:\arquivos de programas\a-squared free\a2free.exe

C:\Arquivos de programas\a-squared Free\a2service.exe

C:\Arquivos de programas\Windows Media Player\wmplayer.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll

O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehCef.dll

O2 - BHO: G-Buster Browser Defense ABN AMRO - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\arquiv~1\mcafee.com\vso\mcvsshl.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [VSOCheckTask] "C:\ARQUIV~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?

O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip.exe

O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe

O4 - Global Startup: Lotus SmartCenter.lnk = C:\lotus\smartctr\smartctr.exe

O4 - Global Startup: Lotus SuiteStart.lnk = C:\lotus\smartctr\suitest.exe

O4 - Global Startup: STK017 PNP Monitor.lnk = ?

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: Add to AMV Converter... - C:\Arquivos de programas\MP3 Player Utilities 4.13\AMVConverter\grab.html

O8 - Extra context menu item: Append to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Arquivos de programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_02\bin\ssv.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p...IEGetPlugin.ocx

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O17 - HKLM\System\CS1\Services\Tcpip\..\{1258BF82-97A1-47CC-B38D-07ECB68EC0A5}: NameServer = 200.165.132.147 200.165.132.155

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll

O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll

O20 - Winlogon Notify: __GbPluginAbn - C:\Arquivos de programas\GbPlugin\gbiehabn.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe

O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\Arquivos de programas\GbPlugin\GbpSv.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\arquivos de programas\mcafee.com\agent\mcdetect.exe

O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\ARQUIV~1\mcafee.com\vso\mcshield.exe

O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARQUIV~1\mcafee.com\agent\mctskshd.exe

O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARQUIV~1\McAfee.com\Agent\mcupdmgr.exe

O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia carol2906!

 

>@< Estando tudo Ok,vá a quarentena do a-squared,selecione todo o conteúdo e clique em Eliminar.

_____________________

 

>@< Clique com o botão direito do mouse em cima de Meu Computador >> Propriedades >> Restauração do Sistema.

>@< Marque: Desativar Restauração do Sistema >> Aplicar >> Ok.

>@< Execute,agora,o seu Antivírus ( Avira ) e,tudo o que encontrar,envie para a quarentena.

>@< Terminando,reative a Restauração do sistema. >> Aplicar >> Ok.

_____________________

 

>@< O procedimento,dado àcima,foi para que tenhamos um relatório limpo,dado por um nôvo escaneamento em BitDefender.

>@< Este escaneamento,será feito em um tempo menor e isento de malware.

>@< O relatório,estará em: C:\Windows\BDOSCAN8\bdoscan.txt <!>

>@< Caso queira,poste este nôvo relatório,na sua resposta + HJT,atualizado.

_____________________

 

>@< O Log,do HijackThis,está limpo.

>@< Algum problema,ainda,com o computador?

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto é preciso enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.