Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Quinho Knupp (Ber)²t

[Resolvido!] CID iexplore.exe entre outros!

Recommended Posts

Hello! Seguinte, meu pc ta todo estranhoooooooo... existem várias instâncias do iexplore.exe abertas ao mesmo tempo, o pop-up CID tbm aparece toda hora... o meu programa Ares naum ta conseguindo encontrar nenhum arkivo na net... o browser em si do Ares funciona, mas o localizador d arkivos naum... fik como c estivesse concetando o tempo todo! gostaria de uma ajudinha! Abaixo seg o meu log! Obrigado desd já!

 

 

Logfile of HijackThis v1.99.1

Scan saved at 17:22:47, on 5/7/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\AppCore\AppSvc32.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\Arquivos de programas\Enigma Software Group\SpyHunter\SpyHunter3.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\cmpe.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Windows Media Player\wmplayer.exe

C:\Documents and Settings\Administrador\Meus documentos\Downloads\Segurança\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orkut.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\Run: [second bat creative peak] C:\Documents and Settings\All Users\Dados de aplicativos\Axis Readme Second Bat\pure peak.exe

O4 - HKLM\..\Run: [ccApp] "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [osCheck] "C:\Arquivos de programas\Norton Internet Security\osCheck.exe"

O4 - HKLM\..\Run: [spyHunter Security Suite] C:\Arquivos de programas\Enigma Software Group\SpyHunter\SpyHunter3.exe

O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [Multiproc] C:\DOCUME~1\ADMINI~1\DADOSD~1\SPAMDE~1\NURBLIES.exe

O4 - HKCU\..\Run: [Conexão Oi Velox] "C:\Arquivos de programas\Oi Velox\Conexão\pppoe.exe"

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1214361483687

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2CA565DE-3C8E-4729-A75A-CB93CED9B6D1}: NameServer = 200.149.55.142 200.165.132.154

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\isPwdSvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Symantec Core LC - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\AppCore\AppSvc32.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Quinho Knupp ( Be...

 

<@> Existem infecções por Lops e,caso possua o Messenger Plus,recomendo que o desinstale!

<@> Pare,também,a proteção residente do Norton.

 

<@> Dê um duplo clique no ícone do Norton,situado ao lado do relógio.

<@> Em Sistema,clique em Auto-Protect.

<@> Desmarque as seguintes opções:

 

< 1 > Ativar Auto-Protect

 

< 2 > Iniciar o Auto-Protect ao iniciar o Windows

 

<@> Ainda em Sistema,clique em Bloqueio de scripts.

<@> Desmarque a opção:

 

< 1 > Ativar bloqueio de scripts

@@@@@@@@@@@@@@@@@@@

<@> Faça o download do LopS&D.

<@> Salve-o no Disco Local-C!

<@> Instale o programa e clique em: LopSD.cmd

<@> Na janela que abrir,aperte o "p" >> Aperte Enter.

<@> Em outra janela,aperte a opção 2 >> Aperte Enter >> Aguarde!

<@> Terminando,salve e poste o relatório. ( C:\lopR.txt )

<@> Poste,também,HJT atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aí estão os Logs

 

 

-----------------------[ Lop S&D 4.2.2-0 XP/Vista ]---------------------

 

[ Windows XP (NT 5.1) Build 2600, Service Pack 3 ]

[ USER : Administrador ] [ "C:\Lop SD" ] [ Selection : 2 ]

[ dom 06/07/2008 | 15:20:51,10 ] [ PC : QUINHO-53ADBE8C ]

[ MAJ : 06-07-2008 | 10:55 ]

 

 

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ REMOVIDOS ////////////////////////////////

 

Deletado! - C:\DOCUME~1\ALLUSE~1\DADOSD~1\Axis Readme Second Bat\pure peak.exe

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\spamde~1\NURBLIES.exe

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\spamde~1\spmptsvm.exe

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\spamde~1\storecoolsend.exe

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\spamde~1\WebJunkEachBait.exe

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\spamde~1\yvrxdaaq.exe

Deletado! - C:\WINDOWS\Tasks\AF610CFF9186BE87.job

Deletado! - C:\DOCUME~1\ALLUSE~1\DADOSD~1\Axis Readme Second Bat

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\spamde~1

Deletado! - C:\Arquivos de programas\spamde~1

 

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

 

 

-------------[ Lista de pastas em Dados de aplicativos ]------------

 

[25/06/2008|23:29] C:\DOCUME~1\ADMINI~1\DADOSD~1\Adobe

[24/06/2008|16:19] C:\DOCUME~1\ADMINI~1\DADOSD~1\desktop.ini

[30/06/2008|14:53] C:\DOCUME~1\ADMINI~1\DADOSD~1\GrabPro

[24/06/2008|22:18] C:\DOCUME~1\ADMINI~1\DADOSD~1\Identities

[24/06/2008|22:30] C:\DOCUME~1\ADMINI~1\DADOSD~1\InstallShield

[06/07/2008|14:11] C:\DOCUME~1\ADMINI~1\DADOSD~1\Lightcomm

[24/06/2008|22:51] C:\DOCUME~1\ADMINI~1\DADOSD~1\Macromedia

[03/07/2008|13:35] C:\DOCUME~1\ADMINI~1\DADOSD~1\Media Player Classic

[03/07/2008|22:06] C:\DOCUME~1\ADMINI~1\DADOSD~1\Microsoft

[27/06/2008|01:00] C:\DOCUME~1\ADMINI~1\DADOSD~1\Opera

[30/06/2008|22:43] C:\DOCUME~1\ADMINI~1\DADOSD~1\Orbit

[03/07/2008|13:52] C:\DOCUME~1\ADMINI~1\DADOSD~1\Real

[06/07/2008|15:22] C:\DOCUME~1\ADMINI~1\DADOSD~1\uTorrent

 

[25/06/2008|23:29] C:\DOCUME~1\ALLUSE~1\DADOSD~1\Adobe

[24/06/2008|16:19] C:\DOCUME~1\ALLUSE~1\DADOSD~1\desktop.ini

[28/06/2008|15:15] C:\DOCUME~1\ALLUSE~1\DADOSD~1\DVD Shrink

[03/07/2008|15:50] C:\DOCUME~1\ALLUSE~1\DADOSD~1\Macromedia

[03/07/2008|16:24] C:\DOCUME~1\ALLUSE~1\DADOSD~1\Messenger Plus!

[03/07/2008|16:05] C:\DOCUME~1\ALLUSE~1\DADOSD~1\Microsoft

[03/07/2008|13:52] C:\DOCUME~1\ALLUSE~1\DADOSD~1\Microsoft Help

[06/07/2008|15:19] C:\DOCUME~1\ALLUSE~1\DADOSD~1\Symantec

[25/06/2008|15:39] C:\DOCUME~1\ALLUSE~1\DADOSD~1\Windows Genuine Advantage

[24/06/2008|23:10] C:\DOCUME~1\ALLUSE~1\DADOSD~1\WindowsLiveInstaller

[03/07/2008|15:59] C:\DOCUME~1\ALLUSE~1\DADOSD~1\WLInstaller

 

[24/06/2008|16:19] C:\DOCUME~1\DEFAUL~1\DADOSD~1\desktop.ini

[24/06/2008|19:31] C:\DOCUME~1\DEFAUL~1\DADOSD~1\Microsoft

 

[26/06/2008|18:56] C:\DOCUME~1\LOCALS~1\DADOSD~1\Microsoft

 

[24/06/2008|19:31] C:\DOCUME~1\NETWOR~1\DADOSD~1\Microsoft

 

----------------[ Tarefas Agendadas na pasta C:\WINDOWS\Tasks ]---------------

 

[04/07/2008 12:29][--a------] C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Administrador.job

[06/07/2008 14:11][--ah-----] C:\WINDOWS\tasks\SA.DAT

[11/09/2002 09:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

 

---------------[ Lista de pastas em C:\Arquivos de programas ]--------------

 

[03/07/2008|13:29] C:\Arquivos de programas\A1 DVD Audio Ripper

[04/07/2008|18:20] C:\Arquivos de programas\Ares

[04/07/2008|12:40] C:\Arquivos de programas\Arquivos comuns

[25/06/2008|18:49] C:\Arquivos de programas\CCleaner

[24/06/2008|19:28] C:\Arquivos de programas\ComPlus Applications

[24/06/2008|22:40] C:\Arquivos de programas\DIFX

[05/07/2008|18:52] C:\Arquivos de programas\DVD Decrypter

[03/07/2008|13:56] C:\Arquivos de programas\Enigma Software Group

[04/07/2008|12:23] C:\Arquivos de programas\GIGABYTE

[04/07/2008|12:23] C:\Arquivos de programas\InstallShield Installation Information

[03/07/2008|16:09] C:\Arquivos de programas\Internet Explorer

[03/07/2008|15:50] C:\Arquivos de programas\Macromedia

[25/06/2008|16:15] C:\Arquivos de programas\Messenger

[03/07/2008|16:12] C:\Arquivos de programas\Messenger Plus! Live

[24/06/2008|19:31] C:\Arquivos de programas\microsoft frontpage

[25/06/2008|16:10] C:\Arquivos de programas\Movie Maker

[02/07/2008|18:06] C:\Arquivos de programas\Mozilla Firefox

[24/06/2008|19:28] C:\Arquivos de programas\MSN Gaming Zone

[25/06/2008|16:08] C:\Arquivos de programas\NetMeeting

[04/07/2008|13:19] C:\Arquivos de programas\Norton Internet Security

[03/07/2008|15:51] C:\Arquivos de programas\Oi Velox

[03/07/2008|13:49] C:\Arquivos de programas\Opera

[25/06/2008|16:08] C:\Arquivos de programas\Outlook Express

[03/07/2008|15:52] C:\Arquivos de programas\PLATINUM technology

[27/06/2008|00:32] C:\Arquivos de programas\Real

[24/06/2008|22:40] C:\Arquivos de programas\Realtek

[04/07/2008|13:32] C:\Arquivos de programas\RocketDock

[24/06/2008|19:30] C:\Arquivos de programas\Servi‡os on-line

[27/06/2008|13:19] C:\Arquivos de programas\Skype

[04/07/2008|12:40] C:\Arquivos de programas\Symantec

[24/06/2008|22:18] C:\Arquivos de programas\Uninstall Information

[25/06/2008|16:23] C:\Arquivos de programas\uTorrent

[03/07/2008|16:04] C:\Arquivos de programas\Windows Live

[03/07/2008|19:12] C:\Arquivos de programas\Windows Media Connect 2

[03/07/2008|19:14] C:\Arquivos de programas\Windows Media Player

[25/06/2008|16:08] C:\Arquivos de programas\Windows NT

[24/06/2008|19:30] C:\Arquivos de programas\WindowsUpdate

[03/07/2008|13:31] C:\Arquivos de programas\WinRAR

[24/06/2008|19:31] C:\Arquivos de programas\xerox

[24/06/2008|22:38] C:\Arquivos de programas\Yahoo!

 

------[ Lista de pastas em C:\Arquivos de programas\Arquivos comuns ]------

 

[01/07/2008|14:43] C:\Arquivos de programas\Arquivos comuns\Adobe

[03/07/2008|15:45] C:\Arquivos de programas\Arquivos comuns\InstallShield

[03/07/2008|15:50] C:\Arquivos de programas\Arquivos comuns\Macromedia

[03/07/2008|16:05] C:\Arquivos de programas\Arquivos comuns\Microsoft Shared

[24/06/2008|19:29] C:\Arquivos de programas\Arquivos comuns\MSSoap

[24/06/2008|16:20] C:\Arquivos de programas\Arquivos comuns\ODBC

[03/07/2008|13:52] C:\Arquivos de programas\Arquivos comuns\Real

[24/06/2008|19:29] C:\Arquivos de programas\Arquivos comuns\Servi‡os

[27/06/2008|13:19] C:\Arquivos de programas\Arquivos comuns\Skype

[24/06/2008|16:20] C:\Arquivos de programas\Arquivos comuns\SpeechEngines

[04/07/2008|14:09] C:\Arquivos de programas\Arquivos comuns\Symantec Shared

[03/07/2008|13:50] C:\Arquivos de programas\Arquivos comuns\System

[25/06/2008|16:22] C:\Arquivos de programas\Arquivos comuns\WindowsLiveInstaller

 

---------------------------[ Process ]--------------------------

 

... 37

 

... OK !

 

----------------------[ Procura pelo S_Lop ]---------------------

 

Não foram encontradas pastas com o Lop!

 

-----------------[ Procura por Arquivos/Ficheiros e pastas do Lop ]-----------------

 

Não foram encontradas pastas com o Lop!

 

----------------------[ Procura no Registro ]----------------------

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

 

..... OK !

 

--------------------[ Verificando o Arquivos/Ficheiros Hosts ]---------------------

 

Arquivos/Ficheiros Hosts LIMPO

 

 

----------------[ Procurando Arquivos/Ficheiros ocultos com o Catchme ]-----------------

 

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-06 15:25:44

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden files ...

scan completed successfully

hidden processes: 0

hidden files: 0

 

--------------------[ Procurando por outras infecções ]---------------------

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ConexÆo Oi Velox"="\"C:\\Arquivos de programas\\Oi Velox\\ConexÆo\\pppoe.exe\""

 

! EGDACCESS !

 

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Zone Alarm Pro Full License Crack - All Versions.zip

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Multim¡dia\Djïs\Disco Mobile v1.0\CRACK.exe

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Multim¡dia\Djïs\Mega.Mix.2000.v5.01\crack

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Multim¡dia\Djïs\Mega.Mix.2000.v5.01\crack\MEGAMIXC.EXE

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Multim¡dia\Djïs\MJ Studio v1.16\crack.exe

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\Crack

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\Declaration of Use!!!.txt

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\def.dat

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\HeartBug.nfo

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\How to Install!!.txt

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\Specs.txt

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\spyhunterS.exe

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\spyhunter_box_big.jpg

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\Spyhunter_capture.jpg

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\Crack\Common.dll

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Vegas\Sony Vegas 8 Pro + Crack

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Vegas\Sony_Vegas_8_Pro_+_Crack_[mininova].torrent

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Vegas\Sony Vegas 8 Pro + Crack\Readme.txt

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Vegas\Sony Vegas 8 Pro + Crack\Sony Vegas 8 Pro + Crack.uif

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Meus arquivos recebidos\CrackXp.rar

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Meus arquivos recebidos\Crack_Windows_XP_SP2

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Meus arquivos recebidos\Crack_Windows_XP_SP2.zip

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Meus arquivos recebidos\SpyHunter Security Suite v3.4.9+Crack-HeartBug [mininova].torrent

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Meus arquivos recebidos\Crack_Windows_XP_SP2\Bypassing the V5 Windows Update Invalid Product Key.txt

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Meus arquivos recebidos\Crack_Windows_XP_SP2\serial.txt

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Meus arquivos recebidos\Crack_Windows_XP_SP2\WinXP Valid KeyGen.exe

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Minhas m£sicas\Internacionais\Hip-Hop\Vico C- crack crack.mp3

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Zone alarm Pro 6.066.7.000_Fr Keygen.rar

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Zonelabs.-.Zone.Alarm.Pro.v5.5.062.011.(.Full.-.Incl.Keygen.-.by.Yoos).rar

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\3dMark06\3DMark 2006 1.0.2\keygen.exe

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Aurora 2.5.3\Keygen_AuroraDVDCopyv3.1.0.zip

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\MP3 Plugin\KeyGen

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\MP3 Plugin\KeyGen\keygen.exe

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Multim¡dia\Djïs\Otsjuke DJ Professional v1.00.078\OtsJuke_DJ_Professional_1.00.078_Keygen_by_TNT.zip

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Multim¡dia\Djïs\The Digital DJ Music System v3.6.2\KeyGen

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Multim¡dia\Djïs\The Digital DJ Music System v3.6.2\KeyGen\ORNDIGDJ.EXE

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Sound Forge 8\Sound Forge 8\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Sound Forge 8\Sound Forge 8\Sony[1].Sound.Forge.v8.0b.Incl.Keygen-SSG.ZIP

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Sound Forge 8\Sound Forge 8\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG\file_id.diz

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Sound Forge 8\Sound Forge 8\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG\keygen.exe

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Sound Forge 8\Sound Forge 8\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG\keygen.rar

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Downloads\Sound Forge 8\Sound Forge 8\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG\ssg.nfo

=> C:\DOCUME~1\ADMINI~1\MEUSDO~1\Meus arquivos recebidos\Crack_Windows_XP_SP2\WinXP Valid KeyGen.exe

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Zone Alarm Pro Full License Crack - All Versions.zip

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Multim¡dia\Djïs\Disco Mobile v1.0\CRACK.exe

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Multim¡dia\Djïs\Mega.Mix.2000.v5.01\crack

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Multim¡dia\Djïs\Mega.Mix.2000.v5.01\crack\MEGAMIXC.EXE

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Multim¡dia\Djïs\MJ Studio v1.16\crack.exe

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\Crack

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\Declaration of Use!!!.txt

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\def.dat

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\HeartBug.nfo

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\How to Install!!.txt

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\Specs.txt

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\spyhunterS.exe

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\spyhunter_box_big.jpg

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\Spyhunter_capture.jpg

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\SpyHunter Security Suite v3.4.9+Crack-HeartBug\Crack\Common.dll

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Vegas\Sony Vegas 8 Pro + Crack

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Vegas\Sony_Vegas_8_Pro_+_Crack_[mininova].torrent

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Vegas\Sony Vegas 8 Pro + Crack\Readme.txt

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Vegas\Sony Vegas 8 Pro + Crack\Sony Vegas 8 Pro + Crack.uif

=> C:\Documents and Settings\Administrador\Meus documentos\Meus arquivos recebidos\CrackXp.rar

=> C:\Documents and Settings\Administrador\Meus documentos\Meus arquivos recebidos\Crack_Windows_XP_SP2

=> C:\Documents and Settings\Administrador\Meus documentos\Meus arquivos recebidos\Crack_Windows_XP_SP2.zip

=> C:\Documents and Settings\Administrador\Meus documentos\Meus arquivos recebidos\SpyHunter Security Suite v3.4.9+Crack-HeartBug [mininova].torrent

=> C:\Documents and Settings\Administrador\Meus documentos\Meus arquivos recebidos\Crack_Windows_XP_SP2\Bypassing the V5 Windows Update Invalid Product Key.txt

=> C:\Documents and Settings\Administrador\Meus documentos\Meus arquivos recebidos\Crack_Windows_XP_SP2\serial.txt

=> C:\Documents and Settings\Administrador\Meus documentos\Meus arquivos recebidos\Crack_Windows_XP_SP2\WinXP Valid KeyGen.exe

=> C:\Documents and Settings\Administrador\Meus documentos\Minhas m£sicas\Internacionais\Hip-Hop\Vico C- crack crack.mp3

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Zone alarm Pro 6.066.7.000_Fr Keygen.rar

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Zonelabs.-.Zone.Alarm.Pro.v5.5.062.011.(.Full.-.Incl.Keygen.-.by.Yoos).rar

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\3dMark06\3DMark 2006 1.0.2\keygen.exe

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Aurora 2.5.3\Keygen_AuroraDVDCopyv3.1.0.zip

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\MP3 Plugin\KeyGen

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\MP3 Plugin\KeyGen\keygen.exe

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Multim¡dia\Djïs\Otsjuke DJ Professional v1.00.078\OtsJuke_DJ_Professional_1.00.078_Keygen_by_TNT.zip

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Multim¡dia\Djïs\The Digital DJ Music System v3.6.2\KeyGen

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Multim¡dia\Djïs\The Digital DJ Music System v3.6.2\KeyGen\ORNDIGDJ.EXE

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Sound Forge 8\Sound Forge 8\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Sound Forge 8\Sound Forge 8\Sony[1].Sound.Forge.v8.0b.Incl.Keygen-SSG.ZIP

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Sound Forge 8\Sound Forge 8\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG\file_id.diz

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Sound Forge 8\Sound Forge 8\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG\keygen.exe

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Sound Forge 8\Sound Forge 8\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG\keygen.rar

=> C:\Documents and Settings\Administrador\Meus documentos\Downloads\Sound Forge 8\Sound Forge 8\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG\ssg.nfo

=> C:\Documents and Settings\Administrador\Meus documentos\Meus arquivos recebidos\Crack_Windows_XP_SP2\WinXP Valid KeyGen.exe

 

 

[F:65][D:2]-> C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp

[F:67][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies

[F:3656][D:8]-> C:\DOCUME~1\ADMINI~1\CONFIG~1\TEMPOR~1\content.IE5

 

--------------------[ Verificação completa em 15:26:08,84 ]----------------------

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 22:52:36, on 6/7/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\AppCore\AppSvc32.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\cmpe.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Documents and Settings\Administrador\Meus documentos\Downloads\Segurança\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orkut.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [Conexão Oi Velox] "C:\Arquivos de programas\Oi Velox\Conexão\pppoe.exe"

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1214361483687

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2CA565DE-3C8E-4729-A75A-CB93CED9B6D1}: NameServer = 200.149.55.142 200.165.132.154

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\isPwdSvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Symantec Core LC - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\AppCore\AppSvc32.exe

 

Obrigado desd já!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Quinho Knupp (Be...

 

<@> Abra o HijackThis >> Clique: Do a system scan only

<@> Marque,abaixo,as entradas! ( Assinale as caixinhas! )

 

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

 

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

<@> Clique,para finalizá-las,em Fix checked.

---------------------------------------

<@> Baixe: < NaviFix >

---------------------------------------

<@> Mantenha,ainda,a proteção residente do Norton desativada.

---------------------------------------

<@> Descompacte-o para o Disco Local-C ou Arquivos de Programas.

<@> Reinicie o computador,em Modo de Segurança.

<@> Dê um duplo clique no executável: Navilog1.exe >> Non

<@> Se houver uma solicitação,siga a sequência: Clique em Non >> Suivant >> Suivant >> Oui >> Suivant >> Quitter >> Ok.

<@> Na janela DOS,aperte f >> Enter.

<@> Aperte,novamente,Enter. ( ...ou qualquer tecla! )

<@> Em sequência,aperte qualquer tecla,para continuar.

<@> Aperte o 1,para escolher Recherche*. << Escolha Free! ( * ) Diagnóstico!

<@> Aperte Enter.

<@> Aguarde a conclusão!

---------------------------------------

<@> Aperte qualquer tecla,para continuar...

<@> Abrir-se-à o Bloco de Notas,com o relatório. ( fixnavi.txt ) <--- Poste,na sua resposta!

<@> Poste,também: HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Os Logs

 

 

Search Navipromo version 3.6.0 commencé le seg 07/07/2008 à 11:10:35,12

 

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!

!!! Postez ce rapport sur le forum pour le faire analyser !!!

!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

 

Outil exécuté depuis C:\Arquivos de programas\navilog1

Session actuelle : "Administrador"

 

Mise à jour le 27.06.2008 à 23h00 par IL-MAFIOSO

 

 

Microsoft Windows XP [versÆo 5.1.2600]

Internet Explorer : 7.0.5730.13

Système de fichiers : NTFS

 

Recherche executé en mode sans échec

 

*** Recherche Programmes installés ***

 

 

*** Recherche dossiers dans "C:\WINDOWS" ***

 

 

*** Recherche dossiers dans "C:\Arquivos de programas" ***

 

 

*** Recherche dossiers dans "c:\docume~1\alluse~1\dadosd~1" ***

 

 

*** Recherche dossiers dans "c:\docume~1\alluse~1\menuin~1\progra~1" ***

 

 

*** Recherche dossiers dans "C:\Documents and Settings\Administrador\dadosd~1" ***

 

 

*** Recherche dossiers dans "C:\Documents and Settings\Administrador\config~1\dadosd~1" ***

 

 

*** Recherche dossiers dans "C:\Documents and Settings\Administrador\menuin~1\progra~1" ***

 

*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***

pour + d'infos : http://www.gmer.net

 

Aucun Fichier trouvé

 

 

*** Recherche avec GenericNaviSearch ***

!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!

!!! A vérifier impérativement avant toute suppression manuelle !!!

 

* Recherche dans "C:\WINDOWS\system32" *

 

* Recherche dans "C:\Documents and Settings\Administrador\config~1\dadosd~1" *

 

 

 

*** Recherche fichiers ***

 

 

 

*** Recherche clés spécifiques dans le Registre ***

 

 

*** Module de Recherche complémentaire ***

(Recherche fichiers spécifiques)

 

1)Recherche nouveaux fichiers Instant Access :

 

 

2)Recherche Heuristique :

 

* Dans "C:\WINDOWS\system32" :

 

 

* Dans "C:\Documents and Settings\Administrador\config~1\dadosd~1" :

 

 

3)Recherche Certificats :

 

Certificat Egroup absent !

Certificat Electronic-Group absent !

Certificat OOO-Favorit absent !

Certificat Sunny-Day-Design-Ltd absent !

 

4)Recherche fichiers connus :

 

 

 

*** Analyse terminée le seg 07/07/2008 à 11:14:21,10 ***

 

 

Hijackthis

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 11:18:15, on 7/7/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\AppCore\AppSvc32.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\cmpe.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Administrador\Meus documentos\Downloads\Segurança\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orkut.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [Conexão Oi Velox] "C:\Arquivos de programas\Oi Velox\Conexão\pppoe.exe"

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1214361483687

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2CA565DE-3C8E-4729-A75A-CB93CED9B6D1}: NameServer = 200.149.55.142 200.165.132.154

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\isPwdSvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Symantec Core LC - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\AppCore\AppSvc32.exe

 

 

Obrigado desd já! Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Quinho Knupp ( Be...

 

<@> Reabilite a proteção residente do Norton.

-----------------------------

Estando tudo Ok com o PC,crie um Ponto de Restauração do Sistema,completamente Limpo!

Clique com o botão direito do mouse em cima de Meu Computador >> Propriedades >> Restauração do Sistema >> Marque: Desativar Restauração do Sistema >> Aplicar >> Ok.

Depois,desmarque novamente! >> Aplicar >> Ok.

Para maiores detalhes,vá em:< Docs >

<@> O log está limpo!

<@> Tudo Ok?

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Muito obrigado kra... parabéns... o pc parece estar funcionando bem... a única coisa q eu naum consegui usar direito foi o Ares... mas eu sobrevivo... ah + uma coisa apareceu como c tivesse um programa instalado chamado "relevant knowledge"... eu removi,,, mas você sab c é algum malware?! Abraço kra!

 

Obrigado! :clap:

Compartilhar este post


Link para o post
Compartilhar em outros sites
Muito obrigado kra... parabéns... o pc parece estar funcionando bem... a única coisa q eu naum consegui usar direito foi o Ares... mas eu sobrevivo... ah + uma coisa apareceu como c tivesse um programa instalado chamado "relevant knowledge"... eu removi,,, mas você sab c é algum malware?! Abraço kra!

 

Obrigado! :clap:

-------------------------

Opa! Quinho Knupp ( Be...

Bom Dia!

 

<!> É um adware: < Relevant Knowledge >

-------------------------

<!> Tudo Ok! Ainda algum sinal do adware?

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Hello... poxa apareceu uma pasta com esse nome... é um adware neh?! Eu fui no site q você me mandou e baixei o programa q tava lá... eu tbm to usando o spyhunter... naum sei c funciona! Outra coisa minha máquina tem estado com o desepenho (uso PC) de 90%... as vezes... naum sei c isso é normal... abraço... e obrigado desd já!!!!!!!

 

God Bless You!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Hello... poxa apareceu uma pasta com esse nome... é um adware neh?! Eu fui no site q você me mandou e baixei o programa q tava lá... eu tbm to usando o spyhunter... naum sei c funciona! Outra coisa minha máquina tem estado com o desepenho (uso PC) de 90%... as vezes... naum sei c isso é normal... abraço... e obrigado desd já!!!!!!!

 

God Bless You!

-----------------------

Opa! Quinho Knupp ( Be...

Bom Dia!

 

>@< Faça uma análise de desinfecção,em: < Windows Live OneCare >

>@< Na página,clique em: Análise de Assistência Completa

>@< Clique em Instalar agora >> Aguarde!

>@< Na janela que abrir,clique em Instalar >> Iniciar Analista.

>@< Procure escolher a análise completa!

>@< Clique em Seguinte e,aguarde a transferência das ferramentas de análise,para que possa ocorrer o scan.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Hello! Estou aki d novo... hj estou acessando um pc q está estranho... gostaria de ajuda pra resolver esse problema!Agradeço desde já!

 

Logfile of HijackThis v1.99.1

Scan saved at 13:36:16, on 23/7/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0011)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe

C:\Arquivos de programas\Canon\CAL\CALMAIN.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\WINDOWS\system32\rundll32.exe

C:\Arquivos de programas\QuickTime\qttask.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\Ares\Ares.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqimzone.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\HP\Digital Imaging\Product Assistant\bin\hprblog.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\Hijacktihs\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\arquivos de programas\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Inicialização rápida do HP Image Zone.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3??????? 4.15\MediaManager\grab.html

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab

O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1193445537875

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1194815415625

O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://yasminrj07.spaces.live.com/PhotoUpload/MsnPUpld.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{9A3AC3A2-DC03-4B8D-B14A-BD799F7EAD27}: NameServer = 200.165.132.157,200.165.132.147

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Arquivos de programas\Canon\CAL\CALMAIN.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Arquivos de programas\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Arquivos de programas\Windows Live\installer\WLSetupSvc.exe

 

Abraço!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa! Quinho Knupp(Be...

 

<!> Como este log,é de um outro computador,não poderá ser analisado aqui.

<!> Abra um novo Tópico,relatando o problema,e cole este relatório para que seja visto pelos nobres colegas.

---------------------------

<!> Agora,em relação à primeira postagem,foi tudo resolvido?

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Hello... td bem, vou abrir outro tópico... e quanto ao meu pc axo q está trankilo...

 

Logfile of HijackThis v1.99.1

Scan saved at 13:29:42, on 24/7/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\AppCore\AppSvc32.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\cmpe.exe

C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\IoctlSvc.exe

c:\Arquivos de programas\Microsoft SQL Server\90\Shared\sqlwriter.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\TRISNA~1\SSI\SYSENF~1.EXE

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

C:\WINDOWS\vsnpstd3.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\RocketDock\RocketDock.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Arquivos de programas\uTorrent\uTorrent.exe

C:\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\ARQUIV~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [desp2k] C:\Arquivos de programas\Oi Velox\Manager\desp2k.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [ccApp] C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe

O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [Conexão Oi Velox] "C:\Arquivos de programas\Oi Velox\Conexão\pppoe.exe"

O4 - HKCU\..\Run: [RocketDock] "C:\Arquivos de programas\RocketDock\RocketDock.exe"

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\ARQUIV~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5036.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1214361483687

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2CA565DE-3C8E-4729-A75A-CB93CED9B6D1}: NameServer = 200.149.55.142 200.165.132.154

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Arquivos de programas\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\VAScanner\comHost.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Arquivos de programas\Norton Internet Security\isPwdSvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\ARQUIV~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)

O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Arquivos de programas\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)

O23 - Service: SQL Server (SONY_MEDIAMGR2) (MSSQL$SONY_MEDIAMGR2) - Unknown owner - c:\Arquivos de programas\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSONY_MEDIAMGR2 (file missing)

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Arquivos de programas\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)

O23 - Service: Symantec Core LC - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\AppCore\AppSvc32.exe

O23 - Service: SysEnforce - Unknown owner - C:\ARQUIV~1\TRISNA~1\SSI\SYSENF~1.EXE

 

deixei o log c você puder dar uma olhada só pra ver! Abraço!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Quinho Knupp( Be...

 

>@< Baixe: < CCleaner >

>@< Salve-o no Desktop!

>@< Com a opção < Limpador >,já selecionada,clique em Analisar.

>@< Aguarde o progresso!

>@< Terminando,clique em Executar Cleaner.

>@< Na janela que surgir,dê o Ok.

>@< Aguarde o progresso!

----------------------

>@< Selecionando a opção Registro,clique em Procurar erros.

>@< Terminando,clique em Corrigir erros selecionados...

>@< Na pergunta,clique em Sim!

>@< Nomeie os backups e clique em Salvar.

>@< Na janela que aparecer,clique em: Corrigir todos os erros selecionados

>@< Clique em Ok >> Fechar.

----------------------

Estando tudo Ok com o PC,crie um Ponto de Restauração do Sistema,completamente Limpo!

Clique com o botão direito do mouse em cima de Meu Computador >> Propriedades >> Restauração do Sistema >> Marque: Desativar Restauração do Sistema >> Aplicar >> Ok.

Depois,desmarque novamente! >> Aplicar >> Ok.

Para maiores detalhes,vá em:< Docs >

>@< O log está limpo! :thumbsup:

>@< Bom trabalho!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o Tópico seja reaberto é preciso enviar uma Mensagem Privada,para um Moderador,com um Link para o Tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.