Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

IsraelArantes

[Resolvido!]  Erro no explorer.exe

Recommended Posts

ComboFix

 

ComboFix 08-08-12.01 - Administrador 2008-08-14 20:04:27.2 - NTFSx86 MINIMAL

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.1702 [GMT -3:00]

Executando de: C:\Documents and Settings\Administrador\Desktop\ComboFix.exe

Command switches used :: C:\Documents and Settings\Administrador\Desktop\CFScript.txt.txt

 

ATENÇAO - ESTA MAQUINA NAO TEM A CONSOLE DE RECUPERAÇÃO INSTALADA !!

 

FILE ::

C:\WINDOWS\d3dx.dat

C:\WINDOWS\system32\GroupPolicy :#:

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusäes )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\WINDOWS\d3dx.dat

 

.

((((((((((((((((((((((( Ficheiros criados de 2008-07-14 to 2008-08-14 ))))))))))))))))))))))))))))))))

.

 

2008-08-14 14:01 . 2008-08-14 14:04 1,374 --a------ C:\WINDOWS\imsins.BAK

2008-08-14 01:57 . 2008-05-01 11:32 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll

2008-08-13 15:32 . 2008-08-13 15:32 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Configurações locais

2008-08-13 15:32 . 2008-08-13 15:32 <DIR> d-------- C:\Documents and Settings\NetworkService\Configurações locais

2008-08-13 15:32 . 2008-08-13 15:32 <DIR> d-------- C:\Documents and Settings\LocalService\Configurações locais

2008-08-13 15:32 . 2008-08-13 15:32 <DIR> d-------- C:\Documents and Settings\Administrador\Configurações locais

2008-08-13 14:51 . 2008-08-13 14:51 <DIR> d-------- C:\WINDOWS\ERUNT

2008-08-12 22:14 . 2008-08-12 22:14 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy

2008-08-12 21:01 . 2008-08-12 21:01 401,720 --a------ C:\HiJackThis.exe

2008-08-12 11:08 . 2008-08-12 11:08 <DIR> d-------- C:\Arquivos de programas\IObit

2008-08-10 18:10 . 2008-08-10 18:10 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\FLEXnet

2008-08-10 18:02 . 2008-08-10 18:02 <DIR> d-------- C:\Arquivos de programas\Bonjour

2008-08-10 17:53 . 2008-08-10 17:53 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Macrovision Shared

2008-08-06 18:29 . 2008-08-06 18:29 <DIR> d-------- C:\Arquivos de programas\Google

2008-08-06 10:51 . 2008-08-06 10:52 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Yahoo! Companion

2008-08-05 23:00 . 2008-08-05 23:00 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Elaborate Bytes

2008-08-05 22:59 . 2008-08-05 22:59 <DIR> d-------- C:\Arquivos de programas\Elaborate Bytes

2008-08-05 16:18 . 2008-08-05 16:18 <DIR> d-------- C:\Arquivos de programas\Yahoo!

2008-08-02 16:43 . 2008-08-02 16:43 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\vsosdk

2008-08-02 12:08 . 2008-08-06 03:22 <DIR> d-------- C:\Arquivos de programas\PIXresizer

2008-08-02 12:08 . 2007-04-15 00:05 991,232 --a------ C:\WINDOWS\system32\imageviewer2.ocx

2008-08-02 12:08 . 2004-03-08 23:00 224,016 --a------ C:\WINDOWS\system32\tabctl32.ocx

2008-08-02 12:08 . 1996-01-12 00:00 200,704 --a------ C:\WINDOWS\system32\threed32.ocx

2008-08-02 12:08 . 1998-06-24 00:00 164,144 --a------ C:\WINDOWS\system32\comct232.ocx

2008-08-02 12:08 . 1999-09-16 09:04 151,552 --a------ C:\WINDOWS\system32\ccrpfd6.ocx

2008-08-02 12:08 . 2000-05-01 23:02 110,592 --a------ C:\WINDOWS\system32\ccrpbds6.dll

2008-08-02 12:08 . 2000-07-09 18:15 106,496 --a------ C:\WINDOWS\system32\mbprgbar.ocx

2008-08-01 10:27 . 2008-08-01 10:27 99,648 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys

2008-07-31 15:08 . 2008-07-31 15:08 <DIR> d-------- C:\Arquivos de programas\MSBuild

2008-07-31 15:08 . 2008-07-31 15:08 <DIR> d-------- C:\Arquivos de programas\Microsoft Works

2008-07-31 15:07 . 2008-07-31 15:07 <DIR> d-------- C:\Arquivos de programas\Microsoft.NET

2008-07-29 23:20 . 2008-07-31 15:05 <DIR> d-------- C:\Arquivos de programas\Microsoft Visual Studio 8

2008-07-29 23:19 . 2008-07-31 15:07 <DIR> d-------- C:\WINDOWS\SHELLNEW

2008-07-29 23:19 . 2008-07-29 23:19 <DIR> dr-h----- C:\MSOCache

2008-07-29 23:01 . 2008-07-29 23:01 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\ICAClient

2008-07-29 16:32 . 2008-07-31 02:26 <DIR> d-a------ C:\Documents and Settings\All Users\Dados de aplicativos\TEMP

2008-07-29 16:32 . 2008-07-29 16:32 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\SpeedBit

2008-07-29 16:32 . 2008-07-31 02:28 <DIR> d-------- C:\Arquivos de programas\DAP

2008-07-29 16:32 . 2008-07-29 16:32 479,298 --a------ C:\WINDOWS\system32\wbocx.ocx

2008-07-29 16:32 . 2008-07-29 16:32 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll

2008-07-29 16:28 . 2008-07-29 16:30 <DIR> d-------- C:\Arquivos de programas\Puxa R pido

2008-07-29 13:14 . 2008-07-29 13:14 <DIR> d-------- C:\Arquivos de programas\ReflexiveArcade

2008-07-29 13:14 . 2008-07-31 02:22 <DIR> d-------- C:\Arquivos de programas\Rack Em Up Roadtrip

2008-07-29 12:33 . 2008-07-29 12:33 268 --ah----- C:\sqmdata00.sqm

2008-07-29 12:33 . 2008-07-29 12:33 244 --ah----- C:\sqmnoopt00.sqm

2008-07-28 18:26 . 2008-07-28 18:26 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\Nero

2008-07-28 18:22 . 2008-07-28 18:22 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\Nero

2008-07-28 18:22 . 2008-07-28 18:24 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Nero

2008-07-28 18:03 . 2008-07-28 18:03 <DIR> d-------- C:\WINDOWS\Sun

2008-07-28 18:01 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl

2008-07-28 18:00 . 2008-07-28 18:01 <DIR> d-------- C:\Arquivos de programas\Java

2008-07-28 17:59 . 2008-07-28 17:59 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Java

2008-07-28 17:53 . 2008-07-29 05:33 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\GbPlugin

2008-07-28 17:53 . 2008-07-28 17:54 <DIR> d-------- C:\Arquivos de programas\GbPlugin

2008-07-28 01:17 . 2008-08-11 22:38 <DIR> d-------- C:\Arquivos de programas\MessengerDiscovery

2008-07-28 01:17 . 2004-03-09 00:00 212,240 --a------ C:\WINDOWS\system32\richtx32.OCX

2008-07-28 01:17 . 2004-03-08 22:00 152,848 --a------ C:\WINDOWS\system32\comdlg32.OCX

2008-07-28 01:17 . 2004-03-09 00:00 124,688 --a------ C:\WINDOWS\system32\MSWINSCK.ocx

2008-07-27 23:46 . 2008-07-27 23:46 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\SlySoft

2008-07-27 23:25 . 2008-08-05 22:43 <DIR> d-------- C:\Arquivos de programas\SlySoft

2008-07-27 22:01 . 2008-07-27 22:04 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\snpstd

2008-07-27 19:31 . 2008-07-27 19:31 <DIR> d-------- C:\Arquivos de programas\Guitar Pro 5

2008-07-26 23:23 . 2008-07-26 23:23 <DIR> d-------- C:\Arquivos de programas\Total Video Converter

2008-07-26 23:23 . 2000-05-22 22:58 608,448 --a------ C:\WINDOWS\system32\comctl32.ocx

2008-07-26 23:12 . 2008-07-26 23:12 <DIR> d-------- C:\Arquivos de programas\DVDFab 5

2008-07-26 23:00 . 2008-07-26 23:01 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\DVD Shrink

2008-07-26 02:42 . 2003-07-17 15:17 5,174 --a------ C:\WINDOWS\system32\nppt9x.vxd

2008-07-26 02:42 . 2005-01-01 06:43 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys

2008-07-26 02:31 . 2008-08-09 23:59 <DIR> d-------- C:\Arquivos de programas\OnGame

2008-07-24 19:37 . 2008-07-24 19:37 0 --a------ C:\WINDOWS\Versabook.INI

2008-07-24 19:23 . 2008-07-24 19:23 <DIR> d-------- C:\WINDOWS\speech

2008-07-24 19:23 . 2008-07-29 23:01 <DIR> d-------- C:\Program Files

2008-07-24 19:23 . 1997-06-11 18:51 1,294,336 --------- C:\WINDOWS\system32\Cgrm_en.dll

2008-07-24 19:23 . 1999-01-21 15:57 188,416 --a------ C:\WINDOWS\system32\VbMediaControl.ocx

2008-07-24 19:23 . 1998-06-28 14:00 185,856 --------- C:\WINDOWS\system32\swflash.ocx

2008-07-24 19:23 . 1999-01-31 15:16 102,400 --------- C:\WINDOWS\system32\GamesLib.dll

2008-07-24 19:23 . 1998-05-12 14:18 27,136 --------- C:\WINDOWS\system32\VbMCHook.dll

2008-07-24 19:23 . 1997-10-30 15:11 17,640 --a------ C:\WINDOWS\system32\VersaFontLN.ttf

2008-07-24 19:23 . 1997-10-30 15:11 6,100 --a------ C:\WINDOWS\system32\VersaFont01.ttf

2008-07-24 19:22 . 2008-07-24 19:22 <DIR> d-------- C:\Documents and Settings\Administrador\WINDOWS

2008-07-24 19:22 . 1998-07-30 12:51 305,152 --a------ C:\WINDOWS\IsUninst.exe

2008-07-24 13:40 . 2007-06-02 18:48 676,224 --a------ C:\WINDOWS\system32\ogacheckcontrol.dll

2008-07-24 13:37 . 2008-07-24 13:37 <DIR> d-------- C:\WINDOWS\system32\ogacheckcontrol

2008-07-24 00:17 . 2007-07-09 10:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll

2008-07-23 02:12 . 2008-08-14 20:09 <DIR> d-------- C:\Arquivos de programas\SpeedBit Video Accelerator

2008-07-23 02:12 . 2008-07-23 02:12 172,032 --a------ C:\WINDOWS\system32\AniGIF.ocx

2008-07-22 11:41 . 2008-07-22 11:41 <DIR> d--h----- C:\WINDOWS\PIF

2008-07-21 16:42 . 2008-08-11 15:43 <DIR> d-------- C:\Arquivos de programas\sXe Injected

2008-07-21 16:24 . 2008-07-21 16:24 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe AIR

2008-07-21 16:23 . 2008-08-10 18:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Adobe

2008-07-21 12:07 . 2008-08-10 00:02 <DIR> d-------- C:\Arquivos de programas\Valve

2008-07-21 09:11 . 2008-07-21 09:11 24,392 --------- C:\WINDOWS\system32\drivers\ElbyCDIO.sys

2008-07-21 00:36 . 2008-07-21 00:46 <DIR> d-------- C:\Arquivos de programas\Steam

2008-07-19 11:14 . 2008-07-19 11:15 <DIR> d-------- C:\Arquivos de programas\DVD Decrypter

2008-07-19 03:22 . 2008-06-23 13:29 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll

2008-07-19 03:22 . 2007-04-17 06:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat

2008-07-19 03:22 . 2007-03-08 02:12 1,024,000 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui

2008-07-19 03:22 . 2008-06-23 13:29 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll

2008-07-19 03:22 . 2008-06-23 13:29 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll

2008-07-19 03:22 . 2008-06-23 13:29 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll

2008-07-19 03:22 . 2008-06-23 13:29 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll

2008-07-19 03:22 . 2008-06-23 13:29 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll

2008-07-19 03:22 . 2008-06-23 06:20 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe

2008-07-19 03:16 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll

2008-07-19 03:15 . 2008-07-20 02:28 <DIR> d-------- C:\Arquivos de programas\Windows Live Toolbar

2008-07-19 03:01 . 2008-07-19 03:02 <DIR> d--hsc--- C:\Arquivos de programas\Arquivos comuns\WindowsLiveInstaller

2008-07-19 03:00 . 2008-07-19 03:00 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\WLInstaller

2008-07-19 00:19 . 2001-08-17 21:56 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS

2008-07-18 22:33 . 2008-08-14 19:50 <DIR> d-------- C:\Downloads

2008-07-18 22:33 . 2008-07-18 22:33 <DIR> d-------- C:\Arquivos de programas\AP Tuner

2008-07-18 18:05 . 2008-07-18 18:05 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\FreeDownloadManager.ORG

2008-07-18 18:05 . 2008-08-14 20:00 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\Free Download Manager

2008-07-18 18:05 . 2008-07-18 18:05 <DIR> d-------- C:\Arquivos de programas\Free Download Manager

2008-07-18 17:35 . 2008-07-27 19:00 <DIR> d-------- C:\Arquivos de programas\PhotoScape

2008-07-17 17:24 . 2008-08-12 01:55 <DIR> d-------- C:\Arquivos de programas\CoolSMS

2008-07-16 18:03 . 2008-07-18 21:02 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\Symantec Shared

2008-07-16 15:46 . 2008-07-16 15:46 <DIR> d-------- C:\Arquivos de programas\Microsoft CAPICOM 2.1.0.2

2008-07-16 09:26 . 2008-07-18 21:55 <DIR> d-------- C:\Documents and Settings\Administrador\Tracing

2008-07-16 09:23 . 2008-07-16 09:23 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\Canon

2008-07-16 09:20 . 2008-07-16 09:20 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\ScanSoft

2008-07-16 09:20 . 2008-07-16 09:20 <DIR> d-------- C:\Documents and Settings\All Users\Dados de aplicativos\InstallShield

2008-07-16 09:20 . 2008-07-16 09:20 <DIR> d-------- C:\Documents and Settings\Administrador\Dados de aplicativos\ScanSoft

2008-07-16 09:20 . 2008-07-16 09:20 <DIR> d-------- C:\Arquivos de programas\Arquivos comuns\ScanSoft Shared

2008-07-16 09:20 . 2008-07-16 09:20 435 --a------ C:\WINDOWS\MAXLINK.INI

2008-07-16 09:19 . 2008-07-16 09:19 <DIR> d-------- C:\Arquivos de programas\ScanSoft

 

.

((((((((((((((((((((((((((((((((((((( Relat¢rio Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-29 19:30 --------- d-----w C:\Arquivos de programas\Puxa Rápido

2008-07-28 21:22 --------- d-----w C:\Arquivos de programas\Nero

2008-07-14 23:39 --------- d-----w C:\Arquivos de programas\CCleaner

2008-07-14 23:15 --------- d-----w C:\Arquivos de programas\microsoft frontpage

2008-07-14 23:13 --------- d-----w C:\Arquivos de programas\Arquivos comuns\Serviços

2008-07-14 23:12 --------- d-----w C:\Arquivos de programas\Serviços on-line

2008-07-14 20:28 --------- d-----w C:\Documents and Settings\All Users\Dados de aplicativos\Ahead

2008-07-14 20:28 --------- d-----w C:\Documents and Settings\Administrador\Dados de aplicativos\Ahead

2008-06-24 19:06 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe

2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-14 17:59 272,384 ----a-w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-06 17:54 972,072 ----a-w C:\WINDOWS\UNRecode.exe

.

 

((((((((((((((((((((((((((((( snapshot@2008-08-13_15.31.51.32 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-08-01 17:12:21 251,272 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll

+ 2008-08-14 17:02:40 250,928 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll

+ 2008-04-23 07:14:09 124,928 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\advpack.dll

+ 2008-04-23 07:14:09 347,136 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtmsft.dll

+ 2008-04-23 07:14:09 214,528 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\dxtrans.dll

+ 2008-04-23 07:14:09 133,120 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\extmgr.dll

+ 2008-04-23 07:14:09 63,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\icardie.dll

+ 2008-04-22 07:43:30 70,656 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe

+ 2008-04-23 07:14:09 153,088 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakeng.dll

+ 2008-04-23 07:14:09 230,400 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieaksie.dll

+ 2008-04-20 05:07:51 161,792 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieakui.dll

+ 2008-04-23 07:14:09 383,488 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieapfltr.dll

+ 2008-04-23 07:14:09 384,512 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iedkcs32.dll

+ 2008-04-23 07:14:10 6,066,176 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieframe.dll

+ 2008-04-23 07:14:10 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iernonce.dll

+ 2008-04-23 07:14:10 267,776 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iertutil.dll

+ 2008-04-22 07:39:58 13,824 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe

+ 2008-04-22 07:43:46 625,664 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe

+ 2008-04-23 07:14:10 27,648 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\jsproxy.dll

+ 2008-04-23 07:14:10 459,264 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeeds.dll

+ 2008-04-23 07:14:10 52,224 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msfeedsbs.dll

+ 2008-04-24 04:14:12 3,591,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll

+ 2008-04-23 07:14:11 478,208 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mshtmled.dll

+ 2008-04-23 07:14:11 193,024 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\msrating.dll

+ 2008-04-23 07:14:11 671,232 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\mstime.dll

+ 2008-04-23 07:14:11 102,912 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\occache.dll

+ 2008-04-23 07:14:11 44,544 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\pngfilt.dll

+ 2007-03-06 01:01:00 215,264 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe

+ 2007-03-06 01:02:08 384,224 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\updspapi.dll

+ 2008-04-23 07:14:11 105,984 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\url.dll

+ 2008-04-23 07:14:11 1,159,680 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\urlmon.dll

+ 2008-04-23 07:14:11 233,472 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\webcheck.dll

+ 2008-04-23 07:14:11 826,368 -c----w C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll

+ 2007-08-29 02:06:16 467,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\POWERPNT.EXE

+ 2007-08-29 02:06:44 7,990,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPCORE.DLL

+ 2008-08-01 17:12:21 251,272 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6215\PPTPIA.DLL

- 2008-08-01 17:39:54 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe

+ 2008-08-14 17:04:35 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe

- 2008-08-01 17:39:55 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe

+ 2008-08-14 17:04:35 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe

- 2008-08-01 17:39:54 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe

+ 2008-08-14 17:04:35 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe

- 2008-08-01 17:39:54 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe

+ 2008-08-14 17:04:35 184,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe

- 2008-08-01 17:39:55 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe

+ 2008-08-14 17:04:35 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe

- 2008-08-01 17:39:55 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe

+ 2008-08-14 17:04:35 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe

- 2008-08-01 17:39:55 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe

+ 2008-08-14 17:04:35 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe

- 2008-08-01 17:39:54 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe

+ 2008-08-14 17:04:35 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe

- 2008-08-01 17:39:55 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe

+ 2008-08-14 17:04:35 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe

- 2008-08-01 17:39:55 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe

+ 2008-08-14 17:04:35 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe

- 2008-08-01 17:39:55 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe

+ 2008-08-14 17:04:35 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe

- 2008-08-01 17:39:54 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe

+ 2008-08-14 17:04:35 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe

+ 2008-08-14 19:53:55 2,054 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{749531D7-BE89-497F-92D9-90DCF0AAFC39}.bin

- 2008-04-23 07:14:09 124,928 ----a-w C:\WINDOWS\system32\advpack.dll

+ 2008-06-23 16:29:40 124,928 ----a-w C:\WINDOWS\system32\advpack.dll

- 2008-04-23 07:14:09 124,928 -c----w C:\WINDOWS\system32\dllcache\advpack.dll

+ 2008-06-23 16:29:40 124,928 -c----w C:\WINDOWS\system32\dllcache\advpack.dll

- 2008-04-23 07:14:09 347,136 -c----w C:\WINDOWS\system32\dllcache\dxtmsft.dll

+ 2008-06-23 16:29:40 347,136 -c----w C:\WINDOWS\system32\dllcache\dxtmsft.dll

- 2008-04-23 07:14:09 214,528 -c----w C:\WINDOWS\system32\dllcache\dxtrans.dll

+ 2008-06-23 16:29:40 214,528 -c----w C:\WINDOWS\system32\dllcache\dxtrans.dll

+ 2008-07-07 20:31:58 253,952 -c----w C:\WINDOWS\system32\dllcache\es.dll

- 2008-04-23 07:14:09 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll

+ 2008-06-23 16:29:40 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll

- 2008-04-22 07:43:30 70,656 -c----w C:\WINDOWS\system32\dllcache\ie4uinit.exe

+ 2008-06-23 09:24:09 70,656 -c----w C:\WINDOWS\system32\dllcache\ie4uinit.exe

- 2008-04-23 07:14:09 153,088 -c----w C:\WINDOWS\system32\dllcache\ieakeng.dll

+ 2008-06-23 16:29:41 153,088 -c----w C:\WINDOWS\system32\dllcache\ieakeng.dll

- 2008-04-23 07:14:09 230,400 -c----w C:\WINDOWS\system32\dllcache\ieaksie.dll

+ 2008-06-23 16:29:41 230,400 -c----w C:\WINDOWS\system32\dllcache\ieaksie.dll

- 2008-04-20 05:07:51 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll

+ 2008-06-21 05:23:54 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll

- 2008-04-23 07:14:09 384,512 -c----w C:\WINDOWS\system32\dllcache\iedkcs32.dll

+ 2008-06-23 16:29:41 384,512 -c----w C:\WINDOWS\system32\dllcache\iedkcs32.dll

- 2008-04-23 07:14:10 44,544 -c----w C:\WINDOWS\system32\dllcache\iernonce.dll

+ 2008-06-23 16:29:42 44,544 -c----w C:\WINDOWS\system32\dllcache\iernonce.dll

- 2008-04-22 07:43:46 625,664 -c----w C:\WINDOWS\system32\dllcache\iexplore.exe

+ 2008-06-23 09:24:22 625,664 -c----w C:\WINDOWS\system32\dllcache\iexplore.exe

- 2007-08-21 06:17:40 683,520 -c----w C:\WINDOWS\system32\dllcache\inetcomm.dll

+ 2008-04-11 18:51:08 683,520 -c----w C:\WINDOWS\system32\dllcache\inetcomm.dll

- 2008-04-23 07:14:10 27,648 -c----w C:\WINDOWS\system32\dllcache\jsproxy.dll

+ 2008-06-23 16:29:43 27,648 -c----w C:\WINDOWS\system32\dllcache\jsproxy.dll

+ 2008-06-24 16:24:13 74,240 -c----w C:\WINDOWS\system32\dllcache\mscms.dll

- 2008-04-24 04:14:12 3,591,680 -c----w C:\WINDOWS\system32\dllcache\mshtml.dll

+ 2008-06-24 13:29:46 3,592,192 -c----w C:\WINDOWS\system32\dllcache\mshtml.dll

- 2008-04-23 07:14:11 478,208 -c----w C:\WINDOWS\system32\dllcache\mshtmled.dll

+ 2008-06-23 16:29:44 477,696 -c----w C:\WINDOWS\system32\dllcache\mshtmled.dll

- 2008-04-23 07:14:11 193,024 -c----w C:\WINDOWS\system32\dllcache\msrating.dll

+ 2008-06-23 16:29:44 193,024 -c----w C:\WINDOWS\system32\dllcache\msrating.dll

- 2008-04-23 07:14:11 671,232 -c----w C:\WINDOWS\system32\dllcache\mstime.dll

+ 2008-06-23 16:29:45 671,232 -c----w C:\WINDOWS\system32\dllcache\mstime.dll

- 2008-04-23 07:14:11 102,912 -c----w C:\WINDOWS\system32\dllcache\occache.dll

+ 2008-06-23 16:29:45 102,912 -c----w C:\WINDOWS\system32\dllcache\occache.dll

- 2008-04-23 07:14:11 44,544 -c----w C:\WINDOWS\system32\dllcache\pngfilt.dll

+ 2008-06-23 16:29:45 44,544 -c----w C:\WINDOWS\system32\dllcache\pngfilt.dll

- 2008-04-23 07:14:11 105,984 -c----w C:\WINDOWS\system32\dllcache\url.dll

+ 2008-06-23 16:29:45 105,984 -c----w C:\WINDOWS\system32\dllcache\url.dll

- 2008-04-23 07:14:11 1,159,680 -c----w C:\WINDOWS\system32\dllcache\urlmon.dll

+ 2008-06-23 16:29:46 1,159,680 -c----w C:\WINDOWS\system32\dllcache\urlmon.dll

- 2008-04-23 07:14:11 233,472 -c----w C:\WINDOWS\system32\dllcache\webcheck.dll

+ 2008-06-23 16:29:46 233,472 -c----w C:\WINDOWS\system32\dllcache\webcheck.dll

- 2008-04-23 07:14:11 826,368 -c----w C:\WINDOWS\system32\dllcache\wininet.dll

+ 2008-06-23 16:29:46 826,368 -c----w C:\WINDOWS\system32\dllcache\wininet.dll

- 2008-04-23 07:14:09 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll

+ 2008-06-23 16:29:40 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll

- 2008-04-23 07:14:09 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll

+ 2008-06-23 16:29:40 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll

- 2005-07-26 04:40:30 243,200 ----a-w C:\WINDOWS\system32\es.dll

+ 2008-07-07 20:31:58 253,952 ----a-w C:\WINDOWS\system32\es.dll

- 2008-04-23 07:14:09 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll

+ 2008-06-23 16:29:40 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll

- 2008-04-23 07:14:09 63,488 ----a-w C:\WINDOWS\system32\icardie.dll

+ 2008-06-23 16:29:40 63,488 ----a-w C:\WINDOWS\system32\icardie.dll

- 2008-04-22 07:43:30 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe

+ 2008-06-23 09:24:09 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe

- 2008-04-23 07:14:09 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll

+ 2008-06-23 16:29:41 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll

- 2008-04-23 07:14:09 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll

+ 2008-06-23 16:29:41 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll

- 2008-04-20 05:07:51 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll

+ 2008-06-21 05:23:54 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll

- 2008-04-23 07:14:09 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll

+ 2008-06-23 16:29:41 383,488 ----a-w C:\WINDOWS\system32\ieapfltr.dll

- 2008-04-23 07:14:09 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll

+ 2008-06-23 16:29:41 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll

- 2008-04-23 07:14:10 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll

+ 2008-06-23 16:29:42 6,066,176 ----a-w C:\WINDOWS\system32\ieframe.dll

- 2008-04-23 07:14:10 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll

+ 2008-06-23 16:29:42 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll

- 2008-04-23 07:14:10 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll

+ 2008-06-23 16:29:43 267,776 ----a-w C:\WINDOWS\system32\iertutil.dll

- 2008-04-22 07:39:58 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe

+ 2008-06-23 09:20:26 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe

- 2007-08-21 06:17:40 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll

+ 2008-04-11 18:51:08 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll

- 2008-04-23 07:14:10 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll

+ 2008-06-23 16:29:43 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll

- 2008-06-25 12:15:48 17,972,344 ----a-w C:\WINDOWS\system32\MRT.exe

+ 2008-08-05 18:11:01 15,888,504 ----a-w C:\WINDOWS\system32\MRT.exe

- 2005-06-29 01:49:48 74,240 ----a-w C:\WINDOWS\system32\mscms.dll

+ 2008-06-24 16:24:13 74,240 ----a-w C:\WINDOWS\system32\mscms.dll

- 2008-04-23 07:14:10 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll

+ 2008-06-23 16:29:43 459,264 ----a-w C:\WINDOWS\system32\msfeeds.dll

- 2008-04-23 07:14:10 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll

+ 2008-06-23 16:29:43 52,224 ----a-w C:\WINDOWS\system32\msfeedsbs.dll

- 2008-04-24 04:14:12 3,591,680 ----a-w C:\WINDOWS\system32\mshtml.dll

+ 2008-06-24 13:29:46 3,592,192 ----a-w C:\WINDOWS\system32\mshtml.dll

- 2008-04-23 07:14:11 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll

+ 2008-06-23 16:29:44 477,696 ----a-w C:\WINDOWS\system32\mshtmled.dll

- 2008-04-23 07:14:11 193,024 ----a-w C:\WINDOWS\system32\msrating.dll

+ 2008-06-23 16:29:44 193,024 ----a-w C:\WINDOWS\system32\msrating.dll

- 2008-04-23 07:14:11 671,232 ----a-w C:\WINDOWS\system32\mstime.dll

+ 2008-06-23 16:29:45 671,232 ----a-w C:\WINDOWS\system32\mstime.dll

- 2008-04-23 07:14:11 102,912 ----a-w C:\WINDOWS\system32\occache.dll

+ 2008-06-23 16:29:45 102,912 ----a-w C:\WINDOWS\system32\occache.dll

- 2008-04-23 07:14:11 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll

+ 2008-06-23 16:29:45 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll

- 2007-08-10 11:12:44 18,296 ------w C:\WINDOWS\system32\spmsg.dll

+ 2007-11-30 12:39:04 18,296 ------w C:\WINDOWS\system32\spmsg.dll

+ 2008-07-14 11:09:18 62,976 ------w C:\WINDOWS\system32\tzchange.exe

- 2008-04-23 07:14:11 105,984 ----a-w C:\WINDOWS\system32\url.dll

+ 2008-06-23 16:29:45 105,984 ----a-w C:\WINDOWS\system32\url.dll

- 2008-04-23 07:14:11 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll

+ 2008-06-23 16:29:46 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll

- 2008-04-23 07:14:11 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll

+ 2008-06-23 16:29:46 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll

- 2008-04-23 07:14:11 826,368 ----a-w C:\WINDOWS\system32\wininet.dll

+ 2008-06-23 16:29:46 826,368 ----a-w C:\WINDOWS\system32\wininet.dll

.

-- Snapshot reset to current date --

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Nota* entradas vazias & leg¡timas por defeito nÆo sÆo mostradas.

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:45 15360]

"AVG8_TRAY"="C:\ARQUIV~1\AVG\AVG8\avgtray.exe" [2008-07-15 00:02 1232152]

"SpeedBitVideoAccelerator"="C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe" [2008-07-23 02:12 2705008]

"msnmsgr"="C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

"ares"="C:\Arquivos de programas\Ares\Ares.exe" [2008-02-20 11:33 963072]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SSBkgdUpdate"="C:\Arquivos de programas\Arquivos comuns\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 00:14 155648]

"OpwareSE4"="C:\Arquivos de programas\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 13:19 69632]

"SunJavaUpdateSched"="C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

"NeroFilterCheck"="C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NeroCheck.exe" [2008-06-19 09:53 570664]

"NBKeyScan"="C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 09:31 2221352]

"GrooveMonitor"="C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]

"SDFix"="I:\SDFix\RunThis.bat" [2008-08-11 03:49 726078]

"VTTimer"="VTTimer.exe" [2006-08-03 03:53 53248 C:\WINDOWS\system32\VTTimer.exe]

"VTTrayp"="VTtrayp.exe" [2006-08-25 02:52 176128 C:\WINDOWS\system32\VTTrayp.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 04:45 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"NoResolveSearch"= 1 (0x1)

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= "C:\Arquivos de programas\GbPlugin\gbieh.dll" [2008-04-15 09:37 378696]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]

2008-04-15 09:37 378696 C:\Arquivos de programas\GbPlugin\gbieh.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.ffds"= ffdshow.ax

"msacm.ac3filter"= ac3filter.acm

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Notification Packages REG_MULTI_SZ scecli scecli

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Arquivos de programas\\Ares\\Ares.exe"=

"C:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"=

"C:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"C:\\Arquivos de programas\\AVG\\AVG8\\avgemc.exe"=

"C:\\Arquivos de programas\\eMule\\emule.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"C:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAccelerator.exe"=

"C:\\Arquivos de programas\\Free Download Manager\\fdm.exe"=

"C:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"=

"C:\\Arquivos de programas\\MessengerDiscovery\\MessengerDiscovery Live.exe"=

"C:\\Arquivos de programas\\Arquivos comuns\\Nero\\Nero Web\\SetupX.exe"=

"C:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"C:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"C:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"C:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=

"I:\\Arquivos de programas\\Valve\\hl.exe"=

 

R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 00:38]

R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-23 00:39]

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-15 00:02]

R2 avg8emc;AVG8 E-mail Scanner;C:\ARQUIV~1\AVG\AVG8\avgemc.exe [2008-07-15 00:02]

R2 avg8wd;AVG8 WatchDog;C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe [2008-07-15 00:02]

R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-15 00:02]

R2 sbbotdi;sbbotdi;C:\ARQUIV~1\SPEEDB~1\sbbotdi.sys [2008-07-23 02:12]

R2 VideoAcceleratorService;VideoAcceleratorService;C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe [2008-07-23 02:12]

S3 ddsxeiservice;ddsxeiservice2;C:\Arquivos de programas\sXe Injected\ddsxei.sys [2008-08-03 23:32]

.

Conte£do da pasta 'Tarefas Agendadas'

 

2008-08-13 C:\WINDOWS\Tasks\Norton Security Scan.job

- C:\Arquivos de programas\Norton Security Scan\Nss.exe [2008-01-09 04:08]

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-08-14 20:08:48

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializ veis ocultas ...

 

Procurando ficheiros ocultos ...

 

Varredura completada com sucesso

Ficheiros ocultos: 0

 

**************************************************************************

 

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GbpSv]

"ImagePath"="C:\ARQUIV~1\GbPlugin\GbpSv.exe"

.

------------------------ Outros Processos em Execu‡Æo ------------------------

.

C:\Arquivos de programas\GbPlugin\GbpSv.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\Arquivos de programas\MessengerDiscovery\MessengerDiscovery Live.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe

.

**************************************************************************

.

Tempo para conclusÆo: 2008-08-14 20:11:59 - Maquina reiniciou [Administrador]

ComboFix-quarantined-files.txt 2008-08-14 23:11:37

ComboFix2.txt 2008-08-13 18:32:24

 

Pre-Run: 7 pasta(s) 95,357,558,784 bytes disponíveis

Post-Run: 11 pasta(s) 95,444,295,680 bytes dispon¡veis

 

437 --- E O F --- 2008-08-14 17:04:54

 

Hijackthis

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:14:59, on 14/8/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\ScanSoft\OmniPageSE4.0\OpwareSE4.exe

C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe

C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\WINDOWS\system32\ctfmon.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Ares\Ares.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\MessengerDiscovery\MessengerDiscovery Live.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorEngine.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\ARQUIV~1\AVG\AVG8\avgscanx.exe

C:\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\ARQUIV~1\SPEEDB~1\vaproxy.pac

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {6EF05952-B48D-4944-AA91-57A6A1A48EF8} - C:\Arquivos de programas\Puxa Rápido\IEBHO.DLL

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll

O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdm2.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Arquivos de programas\Arquivos comuns\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

O4 - HKLM\..\Run: [OpwareSE4] "C:\Arquivos de programas\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [sDFix] I:\SDFix\RunThis.bat /second

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [speedBitVideoAccelerator] C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Arquivos de programas\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\Arquivos de programas\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Transferir com FDM - file://C:\Arquivos de programas\Free Download Manager\dllink.htm

O8 - Extra context menu item: Transferir todos com FDM - file://C:\Arquivos de programas\Free Download Manager\dlall.htm

O8 - Extra context menu item: Transferir vídeo com FDM - file://C:\Arquivos de programas\Free Download Manager\dlfvideo.htm

O8 - Extra context menu item: Transferência seleccionada pelo FDM - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru...cat-no-eula.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {460324E8-CFB4-4357-85EF-CE3EBFE23A62} (Crystal ActiveX Report Viewer Control 11.0) - http://www.sigo.ms.gov.br/crystalreportvie...tiveXViewer.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1216072356639

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: PLFlash DeviceIoControl Service - Unknown owner - C:\WINDOWS\system32\IoctlSvc.exe (file missing)

O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

 

--

End of file - 9698 bytes

 

 

Aguardando :thumbsup: :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

IsraelArantes,

 

- Faça o download do ATF-Cleaner mais não execute ainda.

 

◘ Reinicie o computador em Modo Seguro (fique pressionando a tecla F8, ou F5 em alguns casos, durante a inicialização).

 

Rode o hijackthis Clique em Do a System Scan Only marque a entrada abaixo na caixa cinza.

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/

 

Depois de marque a entrada acima clique em Fix Checked...

 

 

- Em modo seguro execute a Ferramenta ATF-Cleaner.exe. Marque a opção Select All e clique em Empty Selected. Aparecerá uma janela "Done Cleaning". Clique em OK e Exit.

 

Proximo resposta poste o log do hijackthis atualizado

 

- Como estar o PC?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Sr. Perfect, o pc está bom, é uma máquina boa, o unico problema que está acontecendo ainda é o do Explorer.exe.

o do csrss.exe ja foi resolvido, e o problema de quando eu desligo ele reinicia também foi resolvido.

 

vou fazer o procedimento a cima e retorno com a resposta. :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites
Sr. Perfect, o pc está bom, é uma máquina boa, o unico problema que está acontecendo ainda é o do Explorer.exe.

o do csrss.exe ja foi resolvido, e o problema de quando eu desligo ele reinicia também foi resolvido.

 

vou fazer o procedimento a cima e retorno com a resposta. :thumbsup:

 

Ok, fico no aguardo. Após os procedimentos informe como estar o seu PC

 

:)

Compartilhar este post


Link para o post
Compartilhar em outros sites

HiJackThis

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 00:05:06, on 15/8/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Boot mode: Safe mode

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\ARQUIV~1\SPEEDB~1\vaproxy.pac

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {6EF05952-B48D-4944-AA91-57A6A1A48EF8} - C:\Arquivos de programas\Puxa Rápido\IEBHO.DLL

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll

O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdm2.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Arquivos de programas\Arquivos comuns\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

O4 - HKLM\..\Run: [OpwareSE4] "C:\Arquivos de programas\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [sDFix] I:\SDFix\RunThis.bat /second

O4 - HKLM\..\RunOnce: [ GbPluginBb] RunDll32.exe C:\ARQUIV~1\GbPlugin\gbieh.dll,Gbieh

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [speedBitVideoAccelerator] C:\Arquivos de programas\SpeedBit Video Accelerator\VideoAccelerator.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\Arquivos de programas\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\Arquivos de programas\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Transferir com FDM - file://C:\Arquivos de programas\Free Download Manager\dllink.htm

O8 - Extra context menu item: Transferir todos com FDM - file://C:\Arquivos de programas\Free Download Manager\dlall.htm

O8 - Extra context menu item: Transferir vídeo com FDM - file://C:\Arquivos de programas\Free Download Manager\dlfvideo.htm

O8 - Extra context menu item: Transferência seleccionada pelo FDM - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru...cat-no-eula.cab

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {460324E8-CFB4-4357-85EF-CE3EBFE23A62} (Crystal ActiveX Report Viewer Control 11.0) - http://www.sigo.ms.gov.br/crystalreportvie...tiveXViewer.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1216072356639

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://www14.bancobrasil.com.br/plugin/GbpDist.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Gbp Service (GbpSv) - Unknown owner - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: PLFlash DeviceIoControl Service - Unknown owner - C:\WINDOWS\system32\IoctlSvc.exe (file missing)

O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\ARQUIV~1\SPEEDB~1\VideoAcceleratorService.exe

 

--

End of file - 8596 bytes

 

 

aí está. :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ok, o log estar limpo :)

 

- Digite no Executar combofix /u e clique em Ok e aguarde a remoção do combofix.

 

Visite o Windows Update e atualize o seu sistema, baixando o Service Pack 3

 

Ou, se preferir, baixe e instale o pacote completo (+- 300 Mb):

http://www.microsoft.com/downloads/details...splayLang=pt-br

 

- Recomendo uma manutenção no computador para exclusão dos arquivos temporários, desnecessários e entradas inválidas no registro. Faça o download do CCleaner

 

◘ Abra o programa e clique em Executar Limpeza;

◘ Após isto, clique em Registro > Procurar erros > Corrigir Erros

 

- Desative e ative novamente a Restauração do Sistema

 

Leia o artigo Cuidados ao navegar na net para maiores informações sobre como evitar infecções.

 

segue o erro:

 

O explorer.exe encontrou um problema e precisa ser fechado.

 

Assinatura do erro:

 

AppName: explorer.exe AppVer: 6.0.2900.3156 ModName: unknown

ModVer: 0.0.0.0 Offset: 03eb16ce

 

Vá em iniciar > Executar > e digite regsrv32 user32.dll e tecle ENTER, caso essa ação não resolva tenta essa abaixo.

 

Tenha em mão um CD de intalação do XP, ponha ele no drive de CD

Clique em Iniciar > Executar , Digite: sfc /scannow e de OK.

Espere terminar o processo, e veja se resolveu.

 

Abraços

Compartilhar este post


Link para o post
Compartilhar em outros sites
acho q vou fazer o procedimento com o CD do windows mesmo.

 

Ok, fico no aguardo :)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa IsraelArantes,

 

Vôu ajudar até onde dé, ok?. Espero que possa ajuda-lo, vamos lá.

 

Tente esse link abaixo.

 

http://support.microsoft.com/kb/293623/pt-br

Compartilhar este post


Link para o post
Compartilhar em outros sites

Sr. Perfect, esse link não me ajudou, o Edvan já havia me passado.

será que tenho que formatar a máquina?

acho que não é preciso, pois acho que não é um erro que pode prejudicar a máquina, ele só me encomoda pois ocorre toda vez que fecho uma pasta.

continuo esperando. :thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Formatação não é aconselhado em seu caso, se você decidir formata seu micro, nois informe pois tem gente que precisa de ajuda assim como você, ok?

 

De uma olhada nesses seguintes tópicos relacionados ao seu erro.

 

http://www.guiadohardware.net/comunidade/e...xplorer/827218/

 

http://linhadefensiva.uol.com.br/forum/ind...showtopic=75064

 

http://www.clubedosoftware.com.br/forum/vi...?f=11&t=373

 

:)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Sr. Perfect, nenhum dos fóruns resolveram.

tenho uma duvida.

será que se eu pegar esse arquivo explorer.exe de um amigo meu, dará certo?

o windows instalado na máquina dele é o mesmo que o meu.

abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites
Sr. Perfect, nenhum dos fóruns resolveram.

tenho uma duvida.

será que se eu pegar esse arquivo explorer.exe de um amigo meu, dará certo?

o windows instalado na máquina dele é o mesmo que o meu.

abraços.

 

Não custa nada tentar :)

Compartilhar este post


Link para o post
Compartilhar em outros sites
aah não deu certo.

vou continuar procurando a solução.

abraços

 

Olá amigo, tentei em tudo que pena que não obtive sucesso para resolver essa questão, fico bastante triste.

 

mais às minhas participações com sua maquina se incerra aqui, como seu problema não se trata mais de malware, ok?

 

Abraços e boa sorte

 

:thumbsup:

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.