Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

altasena

[Resolvido!] PC travando e abrindo páginas

Recommended Posts

Olá, pessoal estou novamente precisando da ajuda de vcs!!! Não sei mais o que fazer!! Grato Altair!

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:44:23, on 27/12/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe

C:\Arquivos de programas\D-Tools\daemon.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\QuickTime\QTTask.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\WINDOWS\vsnpstd.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe

C:\Arquivos de programas\Skype\Phone\Skype.exe

C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe

C:\WINDOWS\system32\twumk.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\LightSurf\Common\IconMgr.exe

C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe

C:\Arquivos de programas\LightSurf\Colorific\hgcctl95.exe

C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\LightSurf\Color Indicator\TICIcon.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\UAService7.exe

C:\WINDOWS\system32\SearchIndexer.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Documents and Settings\Altair.HOME\Configurações locais\Temporary Internet Files\Content.IE5\TIGEHO6T\HiJackThis[2].exe

C:\WINDOWS\system32\HPZipm12.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globo.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\cbXNHWQK.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\IDM\QUICKF~1\PlugIns\IEHelp.dll

O2 - BHO: {b2755231-0b14-6dc9-be34-bedbe901145c} - {c541109e-bdeb-43eb-9cd6-41b01325572b} - C:\WINDOWS\system32\tefmey.dll

O2 - BHO: (no name) - {C7EF6252-DF2E-4622-B55A-D25E0736DFF3} - C:\WINDOWS\system32\cbXOFvUK.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Arquivos de programas\LEC\Translate DotNet\LEC IE Translation Extension.dll (file missing)

O4 - HKLM\..\Run: [ATIPTA] C:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [ATICCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" runtime

O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [WinampAgent] "C:\Arquivos de programas\Winamp\winampa.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [84af38f1] rundll32.exe "C:\WINDOWS\system32\swuwcsdo.dll",b

O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\ARQUIV~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h

O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe

O4 - HKCU\..\Run: [twumk.exe] C:\WINDOWS\system32\twumk.exe

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Startup: Sumário do OneNote.onetoc2

O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: LightSurf.lnk = C:\Arquivos de programas\LightSurf\Common\IconMgr.exe

O4 - Global Startup: Windows Search.lnk = C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab

O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1200439285468

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1214509059609

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399007} (GbPluginObj Class) - https://wwws.realsecureweb.com.br/mpr/plugi...GbPluginABN.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS1\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS2\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS3\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: c:\arquiv~1\bandoo\bndhook.dll,avgrsstx.dll tefmey.dll

O20 - Winlogon Notify: GbPluginAbn - C:\ARQUIV~1\GbPlugin\gbiehabn.dll (file missing)

O20 - Winlogon Notify: cbXNHWQK - C:\WINDOWS\SYSTEM32\cbXNHWQK.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

 

--

End of file - 12214 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! altasena

 

<@> Baixe: < ComboFix.exe > ( ...by sUBs )

<@> Salve-o no Desktop!

<@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! )

<@> Feche todas as janelas e execute a ferramenta!

<@> Na solicitação: "Negação de garantia de software" --> Clique em Sim!

<@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo!

 

<!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.

<!> Salve-a no desktop,renomeada como: Kombo.exe

<!> Ps: Nomeie durante o salvamento,e não após salvá-la!

<!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança. <-- Link!

<!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!

<!> Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas.

<@> Abrir-se-á a janela Auto Scan. --> Aguarde!

<@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador.

<@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!

<@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante!

<@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter!

----------------------

<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Boa Tarde! altasena

 

<@> Baixe: < ComboFix.exe > ( ...by sUBs )

<@> Salve-o no Desktop!

<@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! )

<@> Feche todas as janelas e execute a ferramenta!

<@> Na solicitação: "Negação de garantia de software" --> Clique em Sim!

<@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo!

 

<!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.

<!> Salve-a no desktop,renomeada como: Kombo.exe

<!> Ps: Nomeie durante o salvamento,e não após salvá-la!

<!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança. <-- Link!

<!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!

<!> Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas.

<@> Abrir-se-á a janela Auto Scan. --> Aguarde!

<@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador.

<@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!

<@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante!

<@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter!

----------------------

<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Olá amigo fiz o que você pediu!!! Muito grato !! UM abraço!

ComboFix 08-12-28.01 - Altair 2008-12-28 18:16:47.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1023.452 [GMT -2:00]

Executando de: c:\documents and settings\Altair.HOME\Desktop\ComboFix.exe

AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated)

* Criado um novo ponto de restauro

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\arquivos de programas\Antivirus 2009

c:\arquivos de programas\Antivirus 2009\av2009.exe

c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr0.dat

c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr1.dat

c:\windows\pi.exe

c:\windows\system32\amjgjc.dll

c:\windows\system32\Cache

c:\windows\system32\cbXNHWQK.dll

c:\windows\system32\cbXOFvUK.dll

c:\windows\system32\cmifrr.dll

c:\windows\system32\efcBrOhh.dll

c:\windows\system32\eijscg.dll

c:\windows\system32\erkfykas.dll

c:\windows\system32\fluqfwcb.dll

c:\windows\system32\gbiehuni.dll , GBIEHCEF.DLL , gbiehabn.dll, GBIEHABN.DLL, SCPSSSH2.DLL

c:\windows\system32\gegsvdwq.dll

c:\windows\system32\ieupdates.exe

c:\windows\system32\Implode.dll

c:\windows\system32\jmgnlsib.dll

c:\windows\system32\KUvFOXbc.ini

c:\windows\system32\KUvFOXbc.ini2

c:\windows\system32\odscwuws.ini

c:\windows\system32\ogkdymgg.ini

c:\windows\system32\qwdvsgeg.ini

c:\windows\system32\tefmey.dll

c:\windows\system32\xywgaeve.dll

 

----- BITS: Sites possivelmente infetados -----

 

hxxp://childhe.com

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_GBPSV

-------\Service_GbpSv

 

 

(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-28 to 2008-12-28 ))))))))))))))))))))))))))))

.

 

2008-12-27 14:03 . 2008-12-27 14:05 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Lavasoft

2008-12-27 12:26 . 2008-12-27 12:25 401,720 --a------ C:\HiJackThis.exe

2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\Babylon

2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Babylon

2008-12-24 22:44 . 2008-12-24 22:44 45,056 --a------ c:\windows\system32\jkkjIbxy.dll

2008-12-22 21:07 . 2008-12-28 14:08 <DIR> d--h----- C:\$AVG8.VAULT$

2008-12-22 18:09 . 2008-12-24 19:49 <DIR> d-------- c:\windows\system32\Prefetchxs

2008-12-22 18:09 . 2008-12-28 14:28 <DIR> d-------- c:\windows\system32\CatRoot_3

2008-12-22 18:09 . 2008-12-22 18:09 478,064 ---hs---- c:\windows\system32\twumk.exe

2008-12-22 18:08 . 2008-12-22 18:09 1,127,936 ---hs---- c:\windows\system32\jumps.exe

2008-12-16 14:08 . 2008-12-16 14:08 268 --ah----- C:\sqmdata18.sqm

2008-12-16 14:08 . 2008-12-16 14:08 244 --ah----- C:\sqmnoopt18.sqm

2008-12-14 22:14 . 2008-12-14 22:15 <DIR> d-------- c:\arquivos de programas\milhao

2008-12-14 22:10 . 2008-12-14 22:10 <DIR> d-------- C:\ACROREAD

2008-12-14 22:10 . 2008-12-14 22:10 103 --a------ c:\windows\~ACROBAT.TMP

2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\windows\UNWISE

2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\arquivos de programas\TOONWORX

2008-12-14 22:09 . 2000-01-01 23:20 72,960 --a------ c:\windows\system\P3LIB250.DLL

2008-12-14 22:09 . 2000-01-01 23:20 54,272 --a------ c:\windows\system\P3LIB200.DLL

2008-12-14 22:09 . 2000-01-01 23:20 29,354 --a------ c:\windows\system\WEMU387.386

2008-12-14 22:09 . 2000-01-01 23:20 5,195 --a------ c:\windows\system\DVA.386

2008-12-14 22:09 . 2008-12-14 22:10 207 --a------ c:\windows\TOONWORX.INI

2008-12-14 22:03 . 2008-12-14 22:03 <DIR> d-------- C:\WALLY

2008-12-14 22:03 . 1995-03-16 10:02 53,456 --a------ c:\windows\system\IP20.DRV

2008-12-14 22:02 . 1996-01-12 12:22 246,784 --a------ c:\windows\UN160416.EXE

2008-12-14 22:02 . 1995-08-15 13:56 160,084 --a------ c:\windows\system\CDTEST.DLL

2008-12-14 22:02 . 2000-01-01 23:20 26,000 --a------ c:\windows\system\CTL3D.DLL

2008-12-14 22:02 . 1995-05-10 22:30 12,672 --a------ c:\windows\system\DCVIDEO.DLL

2008-12-06 23:10 . 2008-12-06 23:10 <DIR> d-------- C:\Games

2008-12-03 21:38 . 2008-12-03 22:54 377,211,788 --a------ C:\top_setup_1.37.exe.sl

2008-12-02 09:09 . 2008-12-02 09:09 268 --ah----- C:\sqmdata17.sqm

2008-12-02 09:09 . 2008-12-02 09:09 244 --ah----- C:\sqmnoopt17.sqm

2008-11-29 15:40 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll

2008-11-29 09:44 . 2001-02-12 15:56 45,568 --a------ c:\windows\UniFish3.exe

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-27 16:04 --------- d-----w c:\arquivos de programas\Lavasoft

2008-12-27 16:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Lavasoft

2008-12-27 16:02 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard

2008-12-25 00:44 --------- d-----w c:\arquivos de programas\eMule

2008-12-22 20:14 --------- d-----w c:\arquivos de programas\GbPlugin

2008-12-17 02:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Image Zone Express

2008-12-13 20:28 --------- d-----w c:\arquivos de programas\Java

2008-12-11 20:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft Help

2008-12-11 13:24 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Skype

2008-12-09 14:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2008-11-26 23:43 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\zweitgeist

2008-11-26 23:43 --------- d-----w c:\arquivos de programas\weblin

2008-11-24 14:14 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys

2008-11-24 14:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\avg8

2008-11-14 11:40 --------- d-----w c:\arquivos de programas\O Resgate dos Bichos - CD 2

2008-11-14 10:50 90,112 ----a-w c:\windows\Cuninst.exe

2008-11-03 20:35 --------- d-----w c:\arquivos de programas\gamespeed

2008-11-01 13:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Messenger Plus!

2008-10-31 22:36 --------- d-----w c:\arquivos de programas\MSN Messenger

2008-10-31 22:09 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\WLInstaller

2008-10-30 23:00 --------- d-----w c:\arquivos de programas\Windows Live

2008-10-30 21:05 --------- d-----w c:\arquivos de programas\Messenger Plus! Live

2008-10-30 20:32 --------- d-----w c:\arquivos de programas\Microsoft Office Outlook Connector

2008-10-30 20:03 --------- d-----w c:\arquivos de programas\Microsoft

2008-10-30 19:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live

2008-10-23 11:07 1,188,152 ----a-w c:\windows\Sempre Roupa Nova.scr

2008-10-22 18:15 178,591 ----a-w C:\bankerfix.exe

2008-03-03 16:07 92,064 ----a-w c:\documents and settings\Altair.HOME\mqdmmdm.sys

2008-03-03 16:07 9,232 ----a-w c:\documents and settings\Altair.HOME\mqdmmdfl.sys

2008-03-03 16:07 79,328 ----a-w c:\documents and settings\Altair.HOME\mqdmserd.sys

2008-03-03 16:07 66,656 ----a-w c:\documents and settings\Altair.HOME\mqdmbus.sys

2008-03-03 16:07 6,208 ----a-w c:\documents and settings\Altair.HOME\mqdmcmnt.sys

2008-03-03 16:07 5,936 ----a-w c:\documents and settings\Altair.HOME\mqdmwhnt.sys

2008-03-03 16:07 4,048 ----a-w c:\documents and settings\Altair.HOME\mqdmcr.sys

2008-03-03 16:07 25,600 ----a-w c:\documents and settings\Altair.HOME\usbsermptxp.sys

2008-03-03 16:07 22,768 ----a-w c:\documents and settings\Altair.HOME\usbsermpt.sys

2008-11-23 23:48 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll

2008-11-23 23:48 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll

2008-11-23 23:48 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll

2008-11-23 23:48 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll

2008-11-23 23:48 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2006-10-13 20058152]

"PhotoShow Deluxe Media Manager"="c:\arquiv~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [2005-02-25 212992]

"twumk.exe"="c:\windows\system32\twumk.exe" [2008-12-22 478064]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ATIPTA"="c:\arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064]

"ATICCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" [2005-05-13 32768]

"SoundMAXPnP"="c:\arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]

"DAEMON Tools-1033"="c:\arquivos de programas\D-Tools\daemon.exe" [2004-08-22 81920]

"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]

"QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2008-09-06 413696]

"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2008-09-10 289576]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-29 1261336]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600]

 

c:\documents and settings\Altair.HOME\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

Sum rio do OneNote.onetoc2 [2008-04-15 3656]

 

c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\

ATI CATALYST System Tray.lnk - c:\arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe [2005-05-13 32768]

HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

LightSurf.lnk - c:\arquivos de programas\LightSurf\Common\IconMgr.exe [2008-04-18 98304]

Windows Search.lnk - c:\arquivos de programas\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Arquivos de programas\\Valve\\hlds.exe"=

"c:\\Arquivos de programas\\Valve\\hl.exe"=

"c:\\Arquivos de programas\\eMule\\emule.exe"=

"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=

"c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"=

"c:\\Documents and Settings\\Altair.HOME\\Meus documentos\\eMule0.46c\\emule.exe"=

"c:\\Arquivos de programas\\Java\\jre1.6.0_03\\bin\\javaw.exe"=

"c:\\Arquivos de programas\\MegaJogos\\jre\\jre\\bin\\javaw.exe"=

"c:\\Documents and Settings\\Altair.HOME\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\Shareaza\\Shareaza.exe"=

"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=

"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-24 97928]

R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-24 231704]

R2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [2006-04-05 7040]

S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys []

S3 XDva081;XDva081;\??\c:\windows\system32\XDva081.sys []

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]

 

2008-12-28 c:\windows\Tasks\okvtgigf.job

- c:\windows\system32\rundll32.exe [2008-04-14 00:21]

.

- - - - ORFÃOS REMOVIDOS - - - -

 

BHO-{4c956910-c391-4da7-8b81-3a2feefd6a37} - c:\windows\system32\amjgjc.dll

BHO-{C025DEA7-A297-406D-9FA7-A62C66973A3D} - c:\windows\system32\cbXOFvUK.dll

HKCU-Run-Nero PhotoShow Media Manager - c:\arquiv~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe

HKCU-Run-ares - c:\arquivos de programas\Ares\Ares.exe

HKLM-Run-WinampAgent - c:\arquivos de programas\Winamp\winampa.exe

HKLM-Run-NWEReboot - (no file)

ShellExecuteHooks-{E37CB5F0-51F5-4395-A808-5FA49E399007} - c:\arquiv~1\GbPlugin\gbiehabn.dll

Notify- GbPluginAbn - c:\arquiv~1\GbPlugin\gbiehabn.dll

 

 

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.globo.com.br/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}

uInternet Connection Wizard,ShellNext = iexplore

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000

 

c:\windows\Downloaded Program Files\PowerLoader.dll - O16 -: {4BFD075D-C36E-4F28-BB0A-5D472795197A}

hxxp://www.powerchallenge.com/applet/PowerLoader.cab

c:\windows\Downloaded Program Files\PowerLoader.inf

 

O16 -: {E37CB5F0-51F5-4395-A808-5FA49E399007} - hxxps://wwws.realsecureweb.com.br/mpr/plugin/Cab/GbPluginABN.cab

c:\windows\Downloaded Program Files\GbPluginABN.inf

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-28 18:24:53

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(688)

c:\windows\system32\Ati2evxx.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\ati2evxx.exe

c:\arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

c:\windows\system32\ati2evxx.exe

c:\arquivos de programas\LightSurf\Colorific\hgcctl95.exe

c:\arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe

c:\arquivos de programas\LightSurf\Color Indicator\TICIcon.exe

c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\arquivos de programas\Bonjour\mDNSResponder.exe

c:\arquivos de programas\Java\jre6\bin\jqs.exe

c:\arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

c:\windows\system32\UAService7.exe

c:\windows\system32\searchindexer.exe

c:\arquivos de programas\AVG\AVG8\avgrsx.exe

c:\arquivos de programas\iPod\bin\iPodService.exe

c:\windows\system32\wbem\wmiapsrv.exe

.

**************************************************************************

.

Tempo para conclusão: 2008-12-28 18:29:36 - Máquina reiniciou [Altair]

ComboFix-quarantined-files.txt 2008-12-28 20:29:11

 

Pré-execução: 41 pasta(s) 19.734.994.944 bytes disponíveis

Pós execução: 41 pasta(s) 20,452,155,392 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

276 --- E O F --- 2008-12-19 21:40:20

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 18:35:05, on 28/12/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

C:\Arquivos de programas\D-Tools\daemon.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\QuickTime\QTTask.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe

C:\Arquivos de programas\Skype\Phone\Skype.exe

C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe

C:\WINDOWS\system32\twumk.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\LightSurf\Common\IconMgr.exe

C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe

C:\Arquivos de programas\LightSurf\Colorific\hgcctl95.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\LightSurf\Color Indicator\TICIcon.exe

C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\UAService7.exe

C:\WINDOWS\system32\SearchIndexer.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe

C:\WINDOWS\explorer.exe

C:\Documents and Settings\Altair.HOME\Desktop\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globo.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\IDM\QUICKF~1\PlugIns\IEHelp.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Arquivos de programas\LEC\Translate DotNet\LEC IE Translation Extension.dll (file missing)

O4 - HKLM\..\Run: [ATIPTA] C:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [ATICCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" runtime

O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe

O4 - HKCU\..\Run: [twumk.exe] C:\WINDOWS\system32\twumk.exe

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Startup: Sumário do OneNote.onetoc2

O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: LightSurf.lnk = C:\Arquivos de programas\LightSurf\Common\IconMgr.exe

O4 - Global Startup: Windows Search.lnk = C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab

O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1200439285468

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1214509059609

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS1\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS2\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS3\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

 

--

End of file - 10892 bytes

Um abraço!!! Te aguardo!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! altasena

 

<@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas.

<@> Salve-o,no Desktop,com o nome: CFScript.txt

 

Files::

c:\windows\system32\jkkjIbxy.dll

c:\windows\system32\twumk.exe

c:\windows\system32\jumps.exe

c:\windows\Tasks\okvtgigf.job

C:\sqmdata18.sqm

C:\sqmnoopt18.sqm

C:\sqmdata17.sqm

C:\sqmnoopt17.sqm

Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"twumk.exe"=-

Folder::

c:\windows\system32\Prefetchxs

c:\windows\system32\CatRoot_3

<@> Arraste,o CFScript.txt para o ícone/interior do ComboFix.

<@> Veja a demonstração!

 

2872959479_997d4500c4_o.gif

 

<@> Atenda à solicitação,que deverá surgir,para rodar o ComboFix.

<@> Ps: Faça o arraste,até surgir essa solicitação! ( janela )

<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Boa Noite! altasena

 

<@> Selecione e copie,todo o conteúdo que está na área do QUOTE,para o Bloco de Notas.

<@> Salve-o,no Desktop,com o nome: CFScript.txt

 

Files::

c:\windows\system32\jkkjIbxy.dll

c:\windows\system32\twumk.exe

c:\windows\system32\jumps.exe

c:\windows\Tasks\okvtgigf.job

C:\sqmdata18.sqm

C:\sqmnoopt18.sqm

C:\sqmdata17.sqm

C:\sqmnoopt17.sqm

Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"twumk.exe"=-

Folder::

c:\windows\system32\Prefetchxs

c:\windows\system32\CatRoot_3

<@> Arraste,o CFScript.txt para o ícone/interior do ComboFix.

<@> Veja a demonstração!

 

2872959479_997d4500c4_o.gif

 

<@> Atenda à solicitação,que deverá surgir,para rodar o ComboFix.

<@> Ps: Faça o arraste,até surgir essa solicitação! ( janela )

<@> Terminando,poste os relatórios: C:\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Olá DigRam, desde já quero lhe agradecer a atenção!! Abaixo posto o que você pede!! Um abraço!! Altair!!

 

ComboFix 08-12-28.01 - Altair 2008-12-29 15:03:04.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1023.473 [GMT -2:00]

Executando de: c:\documents and settings\Altair.HOME\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\Altair.HOME\Desktop\CFScript.txt

AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated)

* Criado um novo ponto de restauro

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\CatRoot_3

c:\windows\system32\CatRoot_3\edb.chk

c:\windows\system32\CatRoot_3\TimeStemp

c:\windows\system32\Prefetchxs

c:\windows\system32\Prefetchxs\euzinho.rifle@gmail.com

c:\windows\system32\Prefetchxs\paulaa1968@gmail.com

c:\windows\system32\Prefetchxs\ruan1995@globo.com

c:\windows\system32\Prefetchxs\uid=10073878566382367689

c:\windows\system32\Prefetchxs\uid=10093758571540450781

c:\windows\system32\Prefetchxs\uid=10318076534728906346

c:\windows\system32\Prefetchxs\uid=10376206228721919992

c:\windows\system32\Prefetchxs\uid=1037826073188409423

c:\windows\system32\Prefetchxs\uid=1051980406115856981

c:\windows\system32\Prefetchxs\uid=1055921848046133103

c:\windows\system32\Prefetchxs\uid=10721037389106661121

c:\windows\system32\Prefetchxs\uid=10728788135134822204

c:\windows\system32\Prefetchxs\uid=10753374287914678364

c:\windows\system32\Prefetchxs\uid=10877353640376038936

c:\windows\system32\Prefetchxs\uid=10918111566442582744

c:\windows\system32\Prefetchxs\uid=10950601282798126008

c:\windows\system32\Prefetchxs\uid=10956919542720223358

c:\windows\system32\Prefetchxs\uid=11016391003574553870

c:\windows\system32\Prefetchxs\uid=11020678768250863806

c:\windows\system32\Prefetchxs\uid=11036436431735649852

c:\windows\system32\Prefetchxs\uid=11199477647029985133

c:\windows\system32\Prefetchxs\uid=11262391093952789965

c:\windows\system32\Prefetchxs\uid=11280594305607972052

c:\windows\system32\Prefetchxs\uid=11358131272357950205

c:\windows\system32\Prefetchxs\uid=11443970396258807410

c:\windows\system32\Prefetchxs\uid=11484878243886469514

c:\windows\system32\Prefetchxs\uid=11571005024792751819

c:\windows\system32\Prefetchxs\uid=11745451256050003900

c:\windows\system32\Prefetchxs\uid=11749763375533333310

c:\windows\system32\Prefetchxs\uid=11797652174971255140

c:\windows\system32\Prefetchxs\uid=11813171764432298374

c:\windows\system32\Prefetchxs\uid=11830588709266355629

c:\windows\system32\Prefetchxs\uid=11839414164978064914

c:\windows\system32\Prefetchxs\uid=11874960705434815573

c:\windows\system32\Prefetchxs\uid=11916729235859937679

c:\windows\system32\Prefetchxs\uid=12010613158930182566

c:\windows\system32\Prefetchxs\uid=1205304755662828404

c:\windows\system32\Prefetchxs\uid=12096663257902347545

c:\windows\system32\Prefetchxs\uid=1213353535175675734

c:\windows\system32\Prefetchxs\uid=12199251504948993038

c:\windows\system32\Prefetchxs\uid=12201939323992660801

c:\windows\system32\Prefetchxs\uid=12235547070827549821

c:\windows\system32\Prefetchxs\uid=12244952592532755868

c:\windows\system32\Prefetchxs\uid=12270485368898448011

c:\windows\system32\Prefetchxs\uid=12284256882460730488

c:\windows\system32\Prefetchxs\uid=12286974763530794004

c:\windows\system32\Prefetchxs\uid=12297297778612910959

c:\windows\system32\Prefetchxs\uid=12343713330503194813

c:\windows\system32\Prefetchxs\uid=12369969336459853282

c:\windows\system32\Prefetchxs\uid=12461194792458146462

c:\windows\system32\Prefetchxs\uid=12593241567072277950

c:\windows\system32\Prefetchxs\uid=12646740765483213484

c:\windows\system32\Prefetchxs\uid=12656349530278003562

c:\windows\system32\Prefetchxs\uid=12759868615278858725

c:\windows\system32\Prefetchxs\uid=12785222156104882519

c:\windows\system32\Prefetchxs\uid=12926907381779125893

c:\windows\system32\Prefetchxs\uid=12979005293491328285

c:\windows\system32\Prefetchxs\uid=13004242084970453072

c:\windows\system32\Prefetchxs\uid=13248116689144518380

c:\windows\system32\Prefetchxs\uid=13319763956901222665

c:\windows\system32\Prefetchxs\uid=13408001446782127852

c:\windows\system32\Prefetchxs\uid=13575821045996628990

c:\windows\system32\Prefetchxs\uid=13578932015319581870

c:\windows\system32\Prefetchxs\uid=13586797816265553385

c:\windows\system32\Prefetchxs\uid=13618910123000198975

c:\windows\system32\Prefetchxs\uid=1368406374434022710

c:\windows\system32\Prefetchxs\uid=13708106737354049354

c:\windows\system32\Prefetchxs\uid=14033681777567248755

c:\windows\system32\Prefetchxs\uid=14154274315834407116

c:\windows\system32\Prefetchxs\uid=14345836480146051042

c:\windows\system32\Prefetchxs\uid=14391558695245912892

c:\windows\system32\Prefetchxs\uid=14397424949232815178

c:\windows\system32\Prefetchxs\uid=14517859927662358394

c:\windows\system32\Prefetchxs\uid=14621169681292567846

c:\windows\system32\Prefetchxs\uid=14758020743406156925

c:\windows\system32\Prefetchxs\uid=14758331840854850809

c:\windows\system32\Prefetchxs\uid=14788114409140444079

c:\windows\system32\Prefetchxs\uid=14836681653344905388

c:\windows\system32\Prefetchxs\uid=14837581274728878233

c:\windows\system32\Prefetchxs\uid=15099378276452038829

c:\windows\system32\Prefetchxs\uid=15139606282167918330

c:\windows\system32\Prefetchxs\uid=15227835053411261543

c:\windows\system32\Prefetchxs\uid=15319911708974642101

c:\windows\system32\Prefetchxs\uid=15333671415825547775

c:\windows\system32\Prefetchxs\uid=15443312399709093574

c:\windows\system32\Prefetchxs\uid=15591697453809545723

c:\windows\system32\Prefetchxs\uid=15610140654977286660

c:\windows\system32\Prefetchxs\uid=15631772112373874146

c:\windows\system32\Prefetchxs\uid=15650598175424752713

c:\windows\system32\Prefetchxs\uid=1572516361401864176

c:\windows\system32\Prefetchxs\uid=15779539878669013717

c:\windows\system32\Prefetchxs\uid=15986415852703340375

c:\windows\system32\Prefetchxs\uid=16045898512434157296

c:\windows\system32\Prefetchxs\uid=16089154660527986624

c:\windows\system32\Prefetchxs\uid=16092442136748431046

c:\windows\system32\Prefetchxs\uid=16098201787268449689

c:\windows\system32\Prefetchxs\uid=16203958252952290316

c:\windows\system32\Prefetchxs\uid=16459392728856169014

c:\windows\system32\Prefetchxs\uid=16537765680623062569

c:\windows\system32\Prefetchxs\uid=16541748872158314859

c:\windows\system32\Prefetchxs\uid=16752773174491741816

c:\windows\system32\Prefetchxs\uid=16815558688181237951

c:\windows\system32\Prefetchxs\uid=16849388344701797543

c:\windows\system32\Prefetchxs\uid=1695625355352171933

c:\windows\system32\Prefetchxs\uid=17007434935122131458

c:\windows\system32\Prefetchxs\uid=17026999308948241214

c:\windows\system32\Prefetchxs\uid=17087965737943822296

c:\windows\system32\Prefetchxs\uid=17104061258941128375

c:\windows\system32\Prefetchxs\uid=17149192978996363067

c:\windows\system32\Prefetchxs\uid=17283461571260786246

c:\windows\system32\Prefetchxs\uid=17371238549052410729

c:\windows\system32\Prefetchxs\uid=17409921102459049983

c:\windows\system32\Prefetchxs\uid=17453284220659407758

c:\windows\system32\Prefetchxs\uid=17470466962151896115

c:\windows\system32\Prefetchxs\uid=17572219506996396869

c:\windows\system32\Prefetchxs\uid=17594411983989541530

c:\windows\system32\Prefetchxs\uid=17611956217266136712

c:\windows\system32\Prefetchxs\uid=17630906075949467253

c:\windows\system32\Prefetchxs\uid=17725963066297716235

c:\windows\system32\Prefetchxs\uid=17774204340009323036

c:\windows\system32\Prefetchxs\uid=17832459778107465151

c:\windows\system32\Prefetchxs\uid=17840185582919609449

c:\windows\system32\Prefetchxs\uid=18033996669212227995

c:\windows\system32\Prefetchxs\uid=18092516642475707604

c:\windows\system32\Prefetchxs\uid=18094354364943314380

c:\windows\system32\Prefetchxs\uid=18135830265463537323

c:\windows\system32\Prefetchxs\uid=18164650581172002042

c:\windows\system32\Prefetchxs\uid=18181004936305455425

c:\windows\system32\Prefetchxs\uid=18264835970928276117

c:\windows\system32\Prefetchxs\uid=18363885718008299196

c:\windows\system32\Prefetchxs\uid=1857279662614826226

c:\windows\system32\Prefetchxs\uid=2130968248785583708

c:\windows\system32\Prefetchxs\uid=216482689323116115

c:\windows\system32\Prefetchxs\uid=2399042952424672621

c:\windows\system32\Prefetchxs\uid=2476615765253753718

c:\windows\system32\Prefetchxs\uid=2678703094997445236

c:\windows\system32\Prefetchxs\uid=2787885661403679677

c:\windows\system32\Prefetchxs\uid=2803487434741902881

c:\windows\system32\Prefetchxs\uid=2833342090580429834

c:\windows\system32\Prefetchxs\uid=2858862162027413768

c:\windows\system32\Prefetchxs\uid=2864067739441436794

c:\windows\system32\Prefetchxs\uid=2899585598435687001

c:\windows\system32\Prefetchxs\uid=2969901922060825967

c:\windows\system32\Prefetchxs\uid=3043016122715034243

c:\windows\system32\Prefetchxs\uid=3063404058926592050

c:\windows\system32\Prefetchxs\uid=3098975966941828863

c:\windows\system32\Prefetchxs\uid=3144168639184154694

c:\windows\system32\Prefetchxs\uid=3285559606333028835

c:\windows\system32\Prefetchxs\uid=3347575097387378572

c:\windows\system32\Prefetchxs\uid=355052566428888648

c:\windows\system32\Prefetchxs\uid=3566026570809483114

c:\windows\system32\Prefetchxs\uid=3624645770535521750

c:\windows\system32\Prefetchxs\uid=3710671789055322065

c:\windows\system32\Prefetchxs\uid=3753167318627965364

c:\windows\system32\Prefetchxs\uid=3854783922219264407

c:\windows\system32\Prefetchxs\uid=3902194959107196915

c:\windows\system32\Prefetchxs\uid=3918931612567757498

c:\windows\system32\Prefetchxs\uid=4014980926181728886

c:\windows\system32\Prefetchxs\uid=4022627279217337851

c:\windows\system32\Prefetchxs\uid=4056639853220268424

c:\windows\system32\Prefetchxs\uid=4093857205928726547

c:\windows\system32\Prefetchxs\uid=4167717884913735448

c:\windows\system32\Prefetchxs\uid=4242227188048141702

c:\windows\system32\Prefetchxs\uid=4243016045489330693

c:\windows\system32\Prefetchxs\uid=4422922577410055706

c:\windows\system32\Prefetchxs\uid=4510223448302285363

c:\windows\system32\Prefetchxs\uid=4545892322993955079

c:\windows\system32\Prefetchxs\uid=4731658822392730112

c:\windows\system32\Prefetchxs\uid=4853723186040484838

c:\windows\system32\Prefetchxs\uid=5143566996177373149

c:\windows\system32\Prefetchxs\uid=5163557574071812023

c:\windows\system32\Prefetchxs\uid=5186846842581322570

c:\windows\system32\Prefetchxs\uid=520169805547905569

c:\windows\system32\Prefetchxs\uid=5259498052295135294

c:\windows\system32\Prefetchxs\uid=5408626071421062022

c:\windows\system32\Prefetchxs\uid=5449234284126105896

c:\windows\system32\Prefetchxs\uid=5467250980643862831

c:\windows\system32\Prefetchxs\uid=549321652507702352

c:\windows\system32\Prefetchxs\uid=5521397596668568035

c:\windows\system32\Prefetchxs\uid=5629875623574554170

c:\windows\system32\Prefetchxs\uid=583320514511203722

c:\windows\system32\Prefetchxs\uid=5845373145314677688

c:\windows\system32\Prefetchxs\uid=5910815741967626367

c:\windows\system32\Prefetchxs\uid=591289038084055870

c:\windows\system32\Prefetchxs\uid=5939472925834161514

c:\windows\system32\Prefetchxs\uid=6010620053536081532

c:\windows\system32\Prefetchxs\uid=6187802616734630159

c:\windows\system32\Prefetchxs\uid=6392425348096693941

c:\windows\system32\Prefetchxs\uid=6479605176319772615

c:\windows\system32\Prefetchxs\uid=64885662926306312

c:\windows\system32\Prefetchxs\uid=6516552060363860497

c:\windows\system32\Prefetchxs\uid=6597658775284147558

c:\windows\system32\Prefetchxs\uid=659792742321439189

c:\windows\system32\Prefetchxs\uid=6640759388682189402

c:\windows\system32\Prefetchxs\uid=6678949085630121456

c:\windows\system32\Prefetchxs\uid=6696289611759756857

c:\windows\system32\Prefetchxs\uid=6708085563630436084

c:\windows\system32\Prefetchxs\uid=6769778535346891805

c:\windows\system32\Prefetchxs\uid=6832904718025177134

c:\windows\system32\Prefetchxs\uid=6884213501064563330

c:\windows\system32\Prefetchxs\uid=6976390535963747801

c:\windows\system32\Prefetchxs\uid=7183318946386091091

c:\windows\system32\Prefetchxs\uid=7247856382081566212

c:\windows\system32\Prefetchxs\uid=727995930909720907

c:\windows\system32\Prefetchxs\uid=7417978813562875197

c:\windows\system32\Prefetchxs\uid=7447859970100521944

c:\windows\system32\Prefetchxs\uid=7479574837620946000

c:\windows\system32\Prefetchxs\uid=7547919322998424447

c:\windows\system32\Prefetchxs\uid=7649585037296408922

c:\windows\system32\Prefetchxs\uid=7689447059690104835

c:\windows\system32\Prefetchxs\uid=7713853776959622769

c:\windows\system32\Prefetchxs\uid=7743603295177440899

c:\windows\system32\Prefetchxs\uid=7899684907037879963

c:\windows\system32\Prefetchxs\uid=7916152784990654420

c:\windows\system32\Prefetchxs\uid=798948828211733739

c:\windows\system32\Prefetchxs\uid=8001925070752697414

c:\windows\system32\Prefetchxs\uid=8059680416395077494

c:\windows\system32\Prefetchxs\uid=8120382425132161521

c:\windows\system32\Prefetchxs\uid=8135391379948449263

c:\windows\system32\Prefetchxs\uid=8175479418631985633

c:\windows\system32\Prefetchxs\uid=8177403549451759729

c:\windows\system32\Prefetchxs\uid=8205100703250754696

c:\windows\system32\Prefetchxs\uid=82434288492434776

c:\windows\system32\Prefetchxs\uid=8271340054378194125

c:\windows\system32\Prefetchxs\uid=8316336335839885650

c:\windows\system32\Prefetchxs\uid=8335288639516210566

c:\windows\system32\Prefetchxs\uid=8357388538391273941

c:\windows\system32\Prefetchxs\uid=8466853291579384225

c:\windows\system32\Prefetchxs\uid=8484094847063476271

c:\windows\system32\Prefetchxs\uid=8513840659578531302

c:\windows\system32\Prefetchxs\uid=8551955857254593212

c:\windows\system32\Prefetchxs\uid=870702175526869565

c:\windows\system32\Prefetchxs\uid=8765030040314685288

c:\windows\system32\Prefetchxs\uid=8801447007258465991

c:\windows\system32\Prefetchxs\uid=8821179526365770801

c:\windows\system32\Prefetchxs\uid=8858581735769172969

c:\windows\system32\Prefetchxs\uid=8928734603918484442

c:\windows\system32\Prefetchxs\uid=9004109795273719271

c:\windows\system32\Prefetchxs\uid=9214622304138349084

c:\windows\system32\Prefetchxs\uid=9215459002929603959

c:\windows\system32\Prefetchxs\uid=9254453388885949959

c:\windows\system32\Prefetchxs\uid=9313112675929779222

c:\windows\system32\Prefetchxs\uid=9381675108527649814

c:\windows\system32\Prefetchxs\uid=9384431913903158521

c:\windows\system32\Prefetchxs\uid=9554252579906789770

c:\windows\system32\Prefetchxs\uid=9605882217387355497

c:\windows\system32\Prefetchxs\uid=961808341291469650

c:\windows\system32\Prefetchxs\uid=9635350036978112307

c:\windows\system32\Prefetchxs\uid=9663001314758677592

c:\windows\system32\Prefetchxs\uid=9664000623637542800

c:\windows\system32\Prefetchxs\uid=980085587220775764

c:\windows\system32\Prefetchxs\uid=9853152139065298060

c:\windows\system32\Prefetchxs\uid=9951860571554449712

c:\windows\system32\Prefetchxs\uid=9953917749837968090

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-28 to 2008-12-29 ))))))))))))))))))))))))))))

.

 

2008-12-28 19:18 . 2008-12-28 19:18 401,720 --a------ C:\HiJackThis.exe

2008-12-27 14:03 . 2008-12-27 14:05 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Lavasoft

2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\Babylon

2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Babylon

2008-12-24 22:44 . 2008-12-24 22:44 45,056 --a------ c:\windows\system32\jkkjIbxy.dll

2008-12-22 21:07 . 2008-12-28 14:08 <DIR> d--h----- C:\$AVG8.VAULT$

2008-12-22 18:09 . 2008-12-22 18:09 478,064 ---hs---- c:\windows\system32\twumk.exe

2008-12-22 18:08 . 2008-12-22 18:09 1,127,936 ---hs---- c:\windows\system32\jumps.exe

2008-12-16 14:08 . 2008-12-16 14:08 268 --ah----- C:\sqmdata18.sqm

2008-12-16 14:08 . 2008-12-16 14:08 244 --ah----- C:\sqmnoopt18.sqm

2008-12-14 22:14 . 2008-12-14 22:15 <DIR> d-------- c:\arquivos de programas\milhao

2008-12-14 22:10 . 2008-12-14 22:10 <DIR> d-------- C:\ACROREAD

2008-12-14 22:10 . 2008-12-14 22:10 103 --a------ c:\windows\~ACROBAT.TMP

2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\windows\UNWISE

2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\arquivos de programas\TOONWORX

2008-12-14 22:09 . 2000-01-01 23:20 72,960 --a------ c:\windows\system\P3LIB250.DLL

2008-12-14 22:09 . 2000-01-01 23:20 54,272 --a------ c:\windows\system\P3LIB200.DLL

2008-12-14 22:09 . 2000-01-01 23:20 29,354 --a------ c:\windows\system\WEMU387.386

2008-12-14 22:09 . 2000-01-01 23:20 5,195 --a------ c:\windows\system\DVA.386

2008-12-14 22:09 . 2008-12-14 22:10 207 --a------ c:\windows\TOONWORX.INI

2008-12-14 22:03 . 2008-12-14 22:03 <DIR> d-------- C:\WALLY

2008-12-14 22:03 . 1995-03-16 10:02 53,456 --a------ c:\windows\system\IP20.DRV

2008-12-14 22:02 . 1996-01-12 12:22 246,784 --a------ c:\windows\UN160416.EXE

2008-12-14 22:02 . 1995-08-15 13:56 160,084 --a------ c:\windows\system\CDTEST.DLL

2008-12-14 22:02 . 2000-01-01 23:20 26,000 --a------ c:\windows\system\CTL3D.DLL

2008-12-14 22:02 . 1995-05-10 22:30 12,672 --a------ c:\windows\system\DCVIDEO.DLL

2008-12-06 23:10 . 2008-12-06 23:10 <DIR> d-------- C:\Games

2008-12-03 21:38 . 2008-12-03 22:54 377,211,788 --a------ C:\top_setup_1.37.exe.sl

2008-12-02 09:09 . 2008-12-02 09:09 268 --ah----- C:\sqmdata17.sqm

2008-12-02 09:09 . 2008-12-02 09:09 244 --ah----- C:\sqmnoopt17.sqm

2008-11-29 15:40 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll

2008-11-29 09:44 . 2001-02-12 15:56 45,568 --a------ c:\windows\UniFish3.exe

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-27 16:04 --------- d-----w c:\arquivos de programas\Lavasoft

2008-12-27 16:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Lavasoft

2008-12-27 16:02 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard

2008-12-25 00:44 --------- d-----w c:\arquivos de programas\eMule

2008-12-22 20:14 --------- d-----w c:\arquivos de programas\GbPlugin

2008-12-17 02:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Image Zone Express

2008-12-13 20:28 --------- d-----w c:\arquivos de programas\Java

2008-12-11 20:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft Help

2008-12-11 13:24 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Skype

2008-12-09 14:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2008-11-26 23:43 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\zweitgeist

2008-11-26 23:43 --------- d-----w c:\arquivos de programas\weblin

2008-11-24 14:14 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys

2008-11-24 14:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\avg8

2008-11-14 11:40 --------- d-----w c:\arquivos de programas\O Resgate dos Bichos - CD 2

2008-11-14 10:50 90,112 ----a-w c:\windows\Cuninst.exe

2008-11-03 20:35 --------- d-----w c:\arquivos de programas\gamespeed

2008-11-01 13:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Messenger Plus!

2008-10-31 22:36 --------- d-----w c:\arquivos de programas\MSN Messenger

2008-10-31 22:09 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\WLInstaller

2008-10-30 23:00 --------- d-----w c:\arquivos de programas\Windows Live

2008-10-30 21:05 --------- d-----w c:\arquivos de programas\Messenger Plus! Live

2008-10-30 20:32 --------- d-----w c:\arquivos de programas\Microsoft Office Outlook Connector

2008-10-30 20:03 --------- d-----w c:\arquivos de programas\Microsoft

2008-10-30 19:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live

2008-10-23 11:07 1,188,152 ----a-w c:\windows\Sempre Roupa Nova.scr

2008-10-22 18:15 178,591 ----a-w C:\bankerfix.exe

2008-03-03 16:07 92,064 ----a-w c:\documents and settings\Altair.HOME\mqdmmdm.sys

2008-03-03 16:07 9,232 ----a-w c:\documents and settings\Altair.HOME\mqdmmdfl.sys

2008-03-03 16:07 79,328 ----a-w c:\documents and settings\Altair.HOME\mqdmserd.sys

2008-03-03 16:07 66,656 ----a-w c:\documents and settings\Altair.HOME\mqdmbus.sys

2008-03-03 16:07 6,208 ----a-w c:\documents and settings\Altair.HOME\mqdmcmnt.sys

2008-03-03 16:07 5,936 ----a-w c:\documents and settings\Altair.HOME\mqdmwhnt.sys

2008-03-03 16:07 4,048 ----a-w c:\documents and settings\Altair.HOME\mqdmcr.sys

2008-03-03 16:07 25,600 ----a-w c:\documents and settings\Altair.HOME\usbsermptxp.sys

2008-03-03 16:07 22,768 ----a-w c:\documents and settings\Altair.HOME\usbsermpt.sys

2008-11-23 23:48 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll

2008-11-23 23:48 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll

2008-11-23 23:48 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll

2008-11-23 23:48 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll

2008-11-23 23:48 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll

.

 

((((((((((((((((((((((((((((( snapshot@2008-12-28_18.28.31.92 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-12-29 17:12:11 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_9d4.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2006-10-13 20058152]

"PhotoShow Deluxe Media Manager"="c:\arquiv~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [2005-02-25 212992]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ATIPTA"="c:\arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064]

"ATICCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" [2005-05-13 32768]

"SoundMAXPnP"="c:\arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]

"DAEMON Tools-1033"="c:\arquivos de programas\D-Tools\daemon.exe" [2004-08-22 81920]

"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]

"QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2008-09-06 413696]

"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2008-09-10 289576]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-29 1261336]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600]

 

c:\documents and settings\Altair.HOME\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

Sum rio do OneNote.onetoc2 [2008-04-15 3656]

 

c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\

ATI CATALYST System Tray.lnk - c:\arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe [2005-05-13 32768]

HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

LightSurf.lnk - c:\arquivos de programas\LightSurf\Common\IconMgr.exe [2008-04-18 98304]

Windows Search.lnk - c:\arquivos de programas\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Arquivos de programas\\Valve\\hlds.exe"=

"c:\\Arquivos de programas\\Valve\\hl.exe"=

"c:\\Arquivos de programas\\eMule\\emule.exe"=

"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=

"c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"=

"c:\\Documents and Settings\\Altair.HOME\\Meus documentos\\eMule0.46c\\emule.exe"=

"c:\\Arquivos de programas\\Java\\jre1.6.0_03\\bin\\javaw.exe"=

"c:\\Arquivos de programas\\MegaJogos\\jre\\jre\\bin\\javaw.exe"=

"c:\\Documents and Settings\\Altair.HOME\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\Shareaza\\Shareaza.exe"=

"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=

"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-24 97928]

R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-24 231704]

R2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [2006-04-05 7040]

S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys []

S3 XDva081;XDva081;\??\c:\windows\system32\XDva081.sys []

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]

 

2008-12-29 c:\windows\Tasks\okvtgigf.job

- c:\windows\system32\rundll32.exe [2008-04-14 00:21]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.globo.com.br/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}

uInternet Connection Wizard,ShellNext = iexplore

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000

TCP: {387FC9CF-08B4-459B-9E10-A3DC53457045} = 200.149.55.140 200.165.132.147

 

c:\windows\Downloaded Program Files\PowerLoader.dll - O16 -: {4BFD075D-C36E-4F28-BB0A-5D472795197A}

hxxp://www.powerchallenge.com/applet/PowerLoader.cab

c:\windows\Downloaded Program Files\PowerLoader.inf

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-29 15:12:22

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(688)

c:\windows\system32\Ati2evxx.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\ati2evxx.exe

c:\arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

c:\windows\system32\ati2evxx.exe

c:\arquivos de programas\LightSurf\Colorific\hgcctl95.exe

c:\arquivos de programas\LightSurf\Color Indicator\TICIcon.exe

c:\arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe

c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\arquivos de programas\Bonjour\mDNSResponder.exe

c:\arquivos de programas\Java\jre6\bin\jqs.exe

c:\windows\system32\HPZipm12.exe

c:\arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

c:\windows\system32\UAService7.exe

c:\windows\system32\searchindexer.exe

c:\arquivos de programas\AVG\AVG8\avgrsx.exe

c:\arquivos de programas\iPod\bin\iPodService.exe

.

**************************************************************************

.

Tempo para conclusão: 2008-12-29 15:18:17 - Máquina reiniciou

ComboFix-quarantined-files.txt 2008-12-29 17:17:53

ComboFix2.txt 2008-12-28 20:29:42

 

Pré-execução: 41 pasta(s) 20.478.480.384 bytes disponíveis

Pós execução: 41 pasta(s) 20,421,996,544 bytes disponíveis

 

488 --- E O F --- 2008-12-19 21:40:20

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:28:31, on 29/12/2008

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

C:\Arquivos de programas\D-Tools\daemon.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\QuickTime\QTTask.exe

C:\Arquivos de programas\iTunes\iTunesHelper.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe

C:\Arquivos de programas\Skype\Phone\Skype.exe

C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\LightSurf\Common\IconMgr.exe

C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe

C:\Arquivos de programas\LightSurf\Colorific\hgcctl95.exe

C:\Arquivos de programas\LightSurf\Color Indicator\TICIcon.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\UAService7.exe

C:\WINDOWS\system32\SearchIndexer.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\Arquivos de programas\iPod\bin\iPodService.exe

C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globo.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\IDM\QUICKF~1\PlugIns\IEHelp.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: LEC - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - C:\Arquivos de programas\LEC\Translate DotNet\LEC IE Translation Extension.dll (file missing)

O4 - HKLM\..\Run: [ATIPTA] C:\Arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [ATICCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" runtime

O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Arquivos de programas\D-Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Arquivos de programas\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\ARQUIV~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Startup: Sumário do OneNote.onetoc2

O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: LightSurf.lnk = C:\Arquivos de programas\LightSurf\Common\IconMgr.exe

O4 - Global Startup: Windows Search.lnk = C:\Arquivos de programas\Windows Desktop Search\WindowsSearch.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab

O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1200439285468

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1214509059609

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS1\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS2\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O17 - HKLM\System\CS3\Services\Tcpip\..\{387FC9CF-08B4-459B-9E10-A3DC53457045}: NameServer = 200.149.55.140 200.165.132.147

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Arquivos de programas\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Arquivos de programas\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Arquivos de programas\Power Translator\LogoMedia TranslateDotNet Server.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Arquivos de programas\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

O24 - Desktop Component 0: (no name) - http://www.google-analytics.com/urchin.js

 

--

End of file - 10892 bytes

Um abraço!!! Aguardo!!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! altasena

 

<@> Copie estas informações,entre os XXXXXXX....,para o Bloco de Notas.

<@> Salve-as,no desktop,como: CFScript <-- Texto!

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

File::

c:\windows\system32\jkkjIbxy.dll

c:\windows\Tasks\okvtgigf.job

C:\sqmdata18.sqm

C:\sqmnoopt18.sqm

C:\sqmdata17.sqm

C:\sqmnoopt17.sqm

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

<@> Arraste o CFScript.txt,para o ícone do ComboFix.

<@> Arraste-o,até que surja uma solicitação para executar o ComboFix.exe.

<@> Terminando,poste: ComboFix.txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Bom Dia! altasena

 

<@> Copie estas informações,entre os XXXXXXX....,para o Bloco de Notas.

<@> Salve-as,no desktop,como: CFScript <-- Texto!

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

File::

c:\windows\system32\jkkjIbxy.dll

c:\windows\Tasks\okvtgigf.job

C:\sqmdata18.sqm

C:\sqmnoopt18.sqm

C:\sqmdata17.sqm

C:\sqmnoopt17.sqm

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

<@> Arraste o CFScript.txt,para o ícone do ComboFix.

<@> Arraste-o,até que surja uma solicitação para executar o ComboFix.exe.

<@> Terminando,poste: ComboFix.txt

 

Abraços!

OLá Digram, boa tarde, mais uma vez muito obrigada pela atenção!!! UM abraço!!

 

 

ComboFix 08-12-29.02 - Altair 2008-12-30 15:22:57.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.1023.558 [GMT -2:00]

Executando de: c:\documents and settings\Altair.HOME\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\Altair.HOME\Desktop\CFScript.txt

* Criado um novo ponto de restauro

 

FILE ::

C:\sqmdata17.sqm

C:\sqmdata18.sqm

C:\sqmnoopt17.sqm

C:\sqmnoopt18.sqm

c:\windows\system32\jkkjIbxy.dll

c:\windows\Tasks\okvtgigf.job

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr0.dat

c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft\Network\Downloader\qmgr1.dat

C:\sqmdata17.sqm

C:\sqmdata18.sqm

C:\sqmnoopt17.sqm

C:\sqmnoopt18.sqm

c:\windows\system32\jkkjIbxy.dll

c:\windows\Tasks\okvtgigf.job

 

----- BITS: Sites possivelmente infetados -----

 

hxxp://childhe.com

.

(((((((((((((((( Arquivos/Ficheiros criados de 2008-11-28 to 2008-12-30 ))))))))))))))))))))))))))))

.

 

2008-12-28 19:18 . 2008-12-28 19:18 401,720 --a------ C:\HiJackThis.exe

2008-12-27 14:03 . 2008-12-27 14:05 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Lavasoft

2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\Babylon

2008-12-24 22:45 . 2008-12-24 22:45 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Babylon

2008-12-22 21:07 . 2008-12-28 14:08 <DIR> d--h----- C:\$AVG8.VAULT$

2008-12-22 18:09 . 2008-12-22 18:09 478,064 ---hs---- c:\windows\system32\twumk.exe

2008-12-22 18:08 . 2008-12-22 18:09 1,127,936 ---hs---- c:\windows\system32\jumps.exe

2008-12-14 22:14 . 2008-12-14 22:15 <DIR> d-------- c:\arquivos de programas\milhao

2008-12-14 22:10 . 2008-12-14 22:10 <DIR> d-------- C:\ACROREAD

2008-12-14 22:10 . 2008-12-14 22:10 103 --a------ c:\windows\~ACROBAT.TMP

2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\windows\UNWISE

2008-12-14 22:09 . 2008-12-14 22:10 <DIR> d-------- c:\arquivos de programas\TOONWORX

2008-12-14 22:09 . 2000-01-01 23:20 72,960 --a------ c:\windows\system\P3LIB250.DLL

2008-12-14 22:09 . 2000-01-01 23:20 54,272 --a------ c:\windows\system\P3LIB200.DLL

2008-12-14 22:09 . 2000-01-01 23:20 29,354 --a------ c:\windows\system\WEMU387.386

2008-12-14 22:09 . 2000-01-01 23:20 5,195 --a------ c:\windows\system\DVA.386

2008-12-14 22:09 . 2008-12-14 22:10 207 --a------ c:\windows\TOONWORX.INI

2008-12-14 22:03 . 2008-12-14 22:03 <DIR> d-------- C:\WALLY

2008-12-14 22:03 . 1995-03-16 10:02 53,456 --a------ c:\windows\system\IP20.DRV

2008-12-14 22:02 . 1996-01-12 12:22 246,784 --a------ c:\windows\UN160416.EXE

2008-12-14 22:02 . 1995-08-15 13:56 160,084 --a------ c:\windows\system\CDTEST.DLL

2008-12-14 22:02 . 2000-01-01 23:20 26,000 --a------ c:\windows\system\CTL3D.DLL

2008-12-14 22:02 . 1995-05-10 22:30 12,672 --a------ c:\windows\system\DCVIDEO.DLL

2008-12-06 23:10 . 2008-12-06 23:10 <DIR> d-------- C:\Games

2008-12-03 21:38 . 2008-12-03 22:54 377,211,788 --a------ C:\top_setup_1.37.exe.sl

2008-11-29 15:40 . 2008-11-10 05:43 410,984 --a------ c:\windows\system32\deploytk.dll

2008-11-29 09:44 . 2001-02-12 15:56 45,568 --a------ c:\windows\UniFish3.exe

2008-11-26 21:42 . 2008-11-26 21:43 <DIR> d-------- c:\arquivos de programas\weblin

2008-11-26 21:40 . 2008-11-26 21:43 <DIR> d-------- c:\documents and settings\Altair.HOME\Dados de aplicativos\zweitgeist

2008-11-24 12:14 . 2008-12-30 14:20 <DIR> d-------- c:\windows\system32\drivers\Avg

2008-11-24 12:14 . 2008-11-24 12:14 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\avg8

2008-11-24 12:14 . 2008-11-24 12:14 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys

2008-11-24 12:14 . 2008-11-24 12:14 10,520 --a------ c:\windows\system32\avgrsstx.dll

2008-11-14 08:50 . 2008-11-14 09:40 <DIR> d-------- c:\arquivos de programas\O Resgate dos Bichos - CD 2

2008-11-14 08:50 . 2008-11-14 08:50 90,112 --a------ c:\windows\Cuninst.exe

2008-11-14 08:01 . 2008-11-14 08:04 1,385 --a------ c:\windows\disney.ini

2008-11-14 08:01 . 2008-11-14 08:01 205 --a------ c:\windows\disneysy.ini

2008-11-12 09:47 . 2008-09-04 15:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll

2008-11-12 09:47 . 2008-10-24 09:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2008-11-05 18:45 . 2008-11-05 18:45 224 --a------ c:\documents and settings\ALTAIR~1.xml

2008-11-05 18:22 . 2008-11-05 18:30 119,001 --a------ c:\windows\hpoins11.dat

2008-11-02 21:41 . 2008-11-03 18:35 <DIR> d-------- c:\arquivos de programas\gamespeed

2008-11-02 21:41 . 2005-12-08 10:09 49,152 --a------ c:\windows\system32\mydll.dll

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-12-30 16:56 --------- d-----w c:\arquivos de programas\MegaJogos

2008-12-27 16:04 --------- d-----w c:\arquivos de programas\Lavasoft

2008-12-27 16:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Lavasoft

2008-12-27 16:02 --------- d-----w c:\arquivos de programas\Arquivos comuns\Wise Installation Wizard

2008-12-25 00:44 --------- d-----w c:\arquivos de programas\eMule

2008-12-22 20:14 --------- d-----w c:\arquivos de programas\GbPlugin

2008-12-17 02:03 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Image Zone Express

2008-12-13 20:28 --------- d-----w c:\arquivos de programas\Java

2008-12-11 20:10 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Microsoft Help

2008-12-11 13:24 --------- d-----w c:\documents and settings\Altair.HOME\Dados de aplicativos\Skype

2008-12-09 14:09 --------- d--h--w c:\arquivos de programas\InstallShield Installation Information

2008-11-01 13:14 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\Messenger Plus!

2008-10-31 22:36 --------- d-----w c:\arquivos de programas\MSN Messenger

2008-10-31 22:09 --------- d-----w c:\documents and settings\All Users.WINDOWS\Dados de aplicativos\WLInstaller

2008-10-30 23:00 --------- d-----w c:\arquivos de programas\Windows Live

2008-10-30 21:05 --------- d-----w c:\arquivos de programas\Messenger Plus! Live

2008-10-30 20:32 --------- d-----w c:\arquivos de programas\Microsoft Office Outlook Connector

2008-10-30 20:03 --------- d-----w c:\arquivos de programas\Microsoft

2008-10-30 19:50 --------- d-----w c:\arquivos de programas\Arquivos comuns\Windows Live

2008-10-23 12:37 286,720 ----a-w c:\windows\system32\gdi32.dll

2008-10-23 11:07 1,188,152 ----a-w c:\windows\Sempre Roupa Nova.scr

2008-10-22 18:15 178,591 ----a-w C:\bankerfix.exe

2008-10-16 20:23 826,368 ----a-w c:\windows\system32\wininet.dll

2008-10-16 16:13 202,776 ----a-w c:\windows\system32\wuweb.dll

2008-10-16 16:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll

2008-10-16 16:12 561,688 ----a-w c:\windows\system32\wuapi.dll

2008-10-16 16:12 323,608 ----a-w c:\windows\system32\wucltui.dll

2008-10-16 16:09 92,696 ----a-w c:\windows\system32\cdm.dll

2008-10-16 16:09 51,224 ----a-w c:\windows\system32\wuauclt.exe

2008-10-16 16:09 43,544 ----a-w c:\windows\system32\wups2.dll

2008-10-16 16:08 34,328 ----a-w c:\windows\system32\wups.dll

2008-10-16 16:06 268,648 ----a-w c:\windows\system32\mucltui.dll

2008-10-16 16:06 208,744 ----a-w c:\windows\system32\muweb.dll

2008-10-03 10:04 247,326 ----a-w c:\windows\system32\strmdll.dll

2008-09-30 18:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll

2008-09-27 14:12 94,578 ----a-w c:\windows\FreeOCR.net Uninstaller.exe

2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys

2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll

2008-09-08 16:57 126,976 ----a-w c:\windows\system32\UAService7.exe

2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll

2008-03-03 16:07 92,064 ----a-w c:\documents and settings\Altair.HOME\mqdmmdm.sys

2008-03-03 16:07 9,232 ----a-w c:\documents and settings\Altair.HOME\mqdmmdfl.sys

2008-03-03 16:07 79,328 ----a-w c:\documents and settings\Altair.HOME\mqdmserd.sys

2008-03-03 16:07 66,656 ----a-w c:\documents and settings\Altair.HOME\mqdmbus.sys

2008-03-03 16:07 6,208 ----a-w c:\documents and settings\Altair.HOME\mqdmcmnt.sys

2008-03-03 16:07 5,936 ----a-w c:\documents and settings\Altair.HOME\mqdmwhnt.sys

2008-03-03 16:07 4,048 ----a-w c:\documents and settings\Altair.HOME\mqdmcr.sys

2008-03-03 16:07 25,600 ----a-w c:\documents and settings\Altair.HOME\usbsermptxp.sys

2008-03-03 16:07 22,768 ----a-w c:\documents and settings\Altair.HOME\usbsermpt.sys

2008-11-23 23:48 67,696 ----a-w c:\arquivos de programas\mozilla firefox\components\jar50.dll

2008-11-23 23:48 54,376 ----a-w c:\arquivos de programas\mozilla firefox\components\jsd3250.dll

2008-11-23 23:48 34,952 ----a-w c:\arquivos de programas\mozilla firefox\components\myspell.dll

2008-11-23 23:48 46,720 ----a-w c:\arquivos de programas\mozilla firefox\components\spellchk.dll

2008-11-23 23:48 172,144 ----a-w c:\arquivos de programas\mozilla firefox\components\xpinstal.dll

.

 

((((((((((((((((((((((((((((( snapshot@2008-12-28_18.28.31.92 )))))))))))))))))))))))))))))))))))))))))

.

+ 2008-12-15 00:07:11 181,268 ----a-w c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1046.dat

+ 2008-12-15 00:07:11 181,268 ----a-w c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1046.dat.bak

- 2008-12-28 20:00:33 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat

+ 2008-12-29 18:01:00 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat

+ 2008-12-29 18:01:05 78,924 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat

- 2008-12-28 20:00:33 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\index.dat

+ 2008-12-29 18:01:00 32,768 ----a-w c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\index.dat

- 2008-12-28 20:00:33 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat

+ 2008-12-29 18:01:00 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat

+ 2008-12-30 17:18:41 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_948.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2006-10-13 20058152]

"PhotoShow Deluxe Media Manager"="c:\arquiv~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [2005-02-25 212992]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ATIPTA"="c:\arquivos de programas\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064]

"ATICCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\cli.exe" [2005-05-13 32768]

"SoundMAXPnP"="c:\arquivos de programas\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]

"DAEMON Tools-1033"="c:\arquivos de programas\D-Tools\daemon.exe" [2004-08-22 81920]

"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]

"QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2008-09-06 413696]

"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2008-09-10 289576]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2008-11-29 1261336]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600]

 

c:\documents and settings\Altair.HOME\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

Sum rio do OneNote.onetoc2 [2008-04-15 3656]

 

c:\documents and settings\All Users.WINDOWS\Menu Iniciar\Programas\Inicializar\

ATI CATALYST System Tray.lnk - c:\arquivos de programas\ATI Technologies\ATI.ACE\CLI.exe [2005-05-13 32768]

HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

LightSurf.lnk - c:\arquivos de programas\LightSurf\Common\IconMgr.exe [2008-04-18 98304]

Windows Search.lnk - c:\arquivos de programas\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\arquivos de programas\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Arquivos de programas\\Valve\\hlds.exe"=

"c:\\Arquivos de programas\\Valve\\hl.exe"=

"c:\\Arquivos de programas\\eMule\\emule.exe"=

"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=

"c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"=

"c:\\Documents and Settings\\Altair.HOME\\Meus documentos\\eMule0.46c\\emule.exe"=

"c:\\Arquivos de programas\\Java\\jre1.6.0_03\\bin\\javaw.exe"=

"c:\\Arquivos de programas\\MegaJogos\\jre\\jre\\bin\\javaw.exe"=

"c:\\Documents and Settings\\Altair.HOME\\Dados de aplicativos\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Arquivos de programas\\Shareaza\\Shareaza.exe"=

"c:\\Arquivos de programas\\LimeWire\\LimeWire.exe"=

"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=

"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqste08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposfx08.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hposid01.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-24 97928]

R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [2008-11-24 231704]

R2 HWiNFO32;HWiNFO32 Kernel Driver;\??\c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [2006-04-05 7040]

S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys []

S3 XDva081;XDva081;\??\c:\windows\system32\XDva081.sys []

 

*Newly Created Service* - CATCHME

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.globo.com.br/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}

uInternet Connection Wizard,ShellNext = iexplore

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000

TCP: {387FC9CF-08B4-459B-9E10-A3DC53457045} = 200.149.55.140 200.165.132.147

 

c:\windows\Downloaded Program Files\PowerLoader.dll - O16 -: {4BFD075D-C36E-4F28-BB0A-5D472795197A}

hxxp://www.powerchallenge.com/applet/PowerLoader.cab

c:\windows\Downloaded Program Files\PowerLoader.inf

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-12-30 15:26:22

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(688)

c:\windows\system32\Ati2evxx.dll

.

Tempo para conclusão: 2008-12-30 15:28:51

ComboFix-quarantined-files.txt 2008-12-30 17:27:48

ComboFix2.txt 2008-12-29 17:18:19

ComboFix3.txt 2008-12-28 20:29:42

 

Pré-execução: 41 pasta(s) 20.443.369.472 bytes disponíveis

Pós execução: 41 pasta(s) 20,439,085,056 bytes disponíveis

 

259 --- E O F --- 2008-12-19 21:40:20

 

Grato Altair!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! altasena

 

<@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /u --> Clique OK.

<@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança )

<@> Clique em Executar --> Aguarde!

<@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK.

<@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório!

----------------------------

<@> Vá a este Link,e baixe: < Malwarebytes >

<@> Atualize o programa!

<@> Escolha o escaneamento Rápido!

<@> Desabilite programas de proteção,ao executar o malwarebytes.

<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

<@> Para maiores detalhes: < Link >

-----------------------

<@> Poste: mbam-log-2008-xx-xx (00-00-00).txt

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Bom Dia! altasena

 

<@> Vá em Iniciar --> Executar --> Digite ou cole: combofix.exe /u --> Clique OK.

<@> Abrir-se-á,a seguinte janela: ( Abrir arquivo - Aviso de Segurança )

<@> Clique em Executar --> Aguarde!

<@> Surgirá,finalmente,a mensagem: "ComboFix está desinstalado" --> Clique OK.

<@> Caso encontre,apague: C:\ComboFix <-- A pasta! + C:\ComboFix.txt <-- Relatório!

----------------------------

<@> Vá a este Link,e baixe: < Malwarebytes >

<@> Atualize o programa!

<@> Escolha o escaneamento Rápido!

<@> Desabilite programas de proteção,ao executar o malwarebytes.

<@> Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

<@> Para maiores detalhes: < Link >

-----------------------

<@> Poste: mbam-log-2008-xx-xx (00-00-00).txt

 

Abraços!

Boa Tarde e feilz 2009 DigRam

Malwarebytes' Anti-Malware 1.31

Versão do banco de dados: 1590

Windows 5.1.2600 Service Pack 3

 

1/1/2009 17:58:09

mbam-log-2009-01-01 (17-58-09).txt

 

Tipo de Verificação: Rápida

Objetos verificados: 73565

Tempo decorrido: 6 minute(s), 12 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 1

Valores do Registro infectados: 0

Ítens do Registro infectados: 0

Pastas infectadas: 0

Arquivos infectados: 0

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Pastas infectadas:

(Nenhum ítem malicioso foi detectado)

 

Arquivos infectados:

(Nenhum ítem malicioso foi detectado)

 

 

Um abraço Altair e muito obrigado...

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! altasena

 

<!> Estando tudo Ok,crie um ponto limpo de Restauração do Sistema.

<!> Clique com o direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema.

<!> Marque: Desativar Restauração do Sistema --> Aplicar --> Ok.

<!> Depois,desmarque novamente! --> Aplicar --> Ok.

<!> Para maiores detalhes,vá em: < Docs >

----------------------------

<!> Não existe mais traços do Vundo. :natal_happy:

<!> Os logs estão limpos!

<!> Tudo Ok?

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Boa Noite! altasena

 

<!> Estando tudo Ok,crie um ponto limpo de Restauração do Sistema.

<!> Clique com o direito do mouse,em cima de Meu Computador --> Propriedades --> Restauração do Sistema.

<!> Marque: Desativar Restauração do Sistema --> Aplicar --> Ok.

<!> Depois,desmarque novamente! --> Aplicar --> Ok.

<!> Para maiores detalhes,vá em: < Docs >

----------------------------

<!> Não existe mais traços do Vundo. :natal_happy:

<!> Os logs estão limpos!

<!> Tudo Ok?

 

Abraços!

Boa tarde DigRam e muito obrigado pelo seu trabalho,você me tirou de mais um problema no pc dos meus filhos..Que papai do céu te abençoe.Feliz 2009.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.