samea 0 Denunciar post Postado Fevereiro 17, 2009 Sempre que inicio o pc aparece uma mensagem avisando que o windows não pode encontrar o arquivo "csrcs.exe". Já ouvi dizer que é um malware. O que devo fazer? Aproveitando a oportunidade meu pc sempre desliga do nada e as vezes quando inicia aparece a mensagem not boot failed e pede pra inserir o cd e dar o enter. Desde já agradeço a ajuda. :cry: Compartilhar este post Link para o post Compartilhar em outros sites
colum4 0 Denunciar post Postado Fevereiro 17, 2009 esse arquivo que voce se refere nao faz parte do sistema , ja o csrss ja eh problemativo , entao ... para resolver voce deve ir em executar > regedit enter ao abrir o regedit voce vai entrar na opcao editar > procurar enter vai digita o nome do arquivo e enter ele vai fazer uma pesquisa no registro e vai encontrar ele . voce pode exluir ele sem medo de ser feliz , logo apos a exclusao , presione F3 para dar continuidade na busca .. ele deve encontrar novamente outro arquivo voce exlua tambem .. geralmente sao 2 arquivos , mas pode haver mais .. se a busca nao der como finalizada , continue presionando F3 e exluindo todo arquivo q aparecer , pode ser q haja 3 , eu ja encontrei maquinas assim .. isso ira resolver seu problema . Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Fevereiro 17, 2009 post um log conforme topico http://forum.imasters.com.br/index.php?showtopic=165906 A exclusao diretamente do regedit pode nao ser o mais aconselhavel mas ai é sua escolha Com o log pode ter uma ajuda mais direcionada se for caso de malware Compartilhar este post Link para o post Compartilhar em outros sites
samea 0 Denunciar post Postado Fevereiro 18, 2009 post um log conforme topico http://forum.imasters.com.br/index.php?showtopic=165906 A exclusao diretamente do regedit pode nao ser o mais aconselhavel mas ai é sua escolha Com o log pode ter uma ajuda mais direcionada se for caso de malware Aqui estar! :unsure: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:58:44, on 18/02/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\ARQUIV~1\GbPlugin\GbpSv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\spoolsv.exe C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe C:\ARQUIV~1\AVG\AVG8\avgtray.exe C:\ARQUIV~1\AVG\AVG8\avgrsx.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\ctfmon.exe C:\ARQUIV~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\system32\HPZipm12.exe C:\Arquivos de programas\Photodex\ProShowGold\ScsiAccess.exe C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\HiJack\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://internetsearchservice.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) R3 - URLSearchHook: P2P Torrent Toolbar - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Arquivos de programas\P2P_Torrent\tbP2P_.dll F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\Arquivos de programas\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL (file missing) O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll O2 - BHO: 734914 helper - {0BD071A6-C989-49E8-9B8E-80F92A868E26} - (no file) O2 - BHO: BrowserCmp - {1D8282E6-BC4F-469B-AAED-7E4FF077AD93} - C:\WINDOWS\system32\iebrowserc.dll (file missing) O2 - BHO: superiorads browser optimizer - {2910e755-0574-9ca1-c006-c1ddc75ac7ff} - C:\WINDOWS\system32\zhnybswtguncukti.dll (file missing) O2 - BHO: ssh2 Class - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll O2 - BHO: (no name) - {6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: P2P Torrent Toolbar - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Arquivos de programas\P2P_Torrent\tbP2P_.dll O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll O2 - BHO: mysidesearch search enhancer - {D1AD53DC-8978-AAAE-31E0-11904F82C145} - C:\WINDOWS\system32\gkulgetcloezejx.dll (file missing) O3 - Toolbar: P2P Torrent Toolbar - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Arquivos de programas\P2P_Torrent\tbP2P_.dll O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [mpeg heck log link] C:\Documents and Settings\All Users\Dados de aplicativos\Joy coal mpeg heck\win team.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [RegPowerClean] "C:\Arquivos de programas\Winferno\RegistryPowerCleaner\RegPowerClean.exe" O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [bowsmove] C:\DOCUME~1\JOO~1\DADOSD~1\CREATI~1\Bolt Slow Dash.exe O4 - HKCU\..\Run: [Torrent Finder] "C:\Arquivos de programas\Torrent Finder\Torrent-Finder.exe" hmw O4 - HKCU\..\RunOnce: [shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322)" -"http://clickjogos.uol.com.br/Jogos-online/Esportes/Formula-1/" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game14.zylom.com/activex/zylomgamesplayer.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.atrativa.com.br/games/applets/p...opcaploader.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll O20 - Winlogon Notify: aGbPlugin - C:\WINDOWS\system\GBPlugins.dll O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - c:\firebird\bin\fbguard.exe O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - c:\firebird\bin\fbserver.exe O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe O23 - Service: NNServ - Unknown owner - C:\Arquivos de programas\NewDotNet\nnrun.exe (file missing) O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: ScsiAccess - Unknown owner - C:\Arquivos de programas\Photodex\ProShowGold\ScsiAccess.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O24 - Desktop Component 0: (no name) - http://by111w.bay111.mail.live.com/att/Get...CA9B283FB06D20| -- End of file - 11108 bytes Compartilhar este post Link para o post Compartilhar em outros sites
samea 0 Denunciar post Postado Fevereiro 18, 2009 post um log conforme topico http://forum.imasters.com.br/index.php?showtopic=165906 A exclusao diretamente do regedit pode nao ser o mais aconselhavel mas ai é sua escolha Com o log pode ter uma ajuda mais direcionada se for caso de malware Mais uma coisinha, quando rodei o HiJack, a opção de não mostrar pastas e arquivos ocultos estava selecionada. Isso atrapalha em algo? :blink: Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Fevereiro 21, 2009 Opa samea, Baixe o ComboFix em: ComboFix 1) Desabilite o seu anti-vírus temporariamente; 2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos); 3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Leia atentamente o texto contido nesta janela e clique sobre “SIM” para continuar. PS.: Caso não concorde com os termos clique sobre “NÃO” para sair do software, cabendo lembrar que o processo de desinfecção não será possível sem a continuidade do ComboFix. 4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console ante de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura. Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente. Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA. Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADA COM SUCESSO”. Clique sobre “SIM” para continuar a varredura. 5) O ComboFix iniciará o AUTOSCAN (aguarde). ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco). Ao término do processo a máquina será reiniciada para a emissão do relatório. 6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log ficará alocado em C:\ComboFix.txt. 7) Reabilite o seu anti-vírus; 8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta. OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Em último caso, tente utilizar o ComboFix em MODO SEGURO. OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
samea 0 Denunciar post Postado Fevereiro 27, 2009 Fiz tudo como você falou, mas ao começar a varredura(que não durou nem 30 seg.) meu pc reiniciou e apareceu uma mensagem da microsoft relatando que o windows teve um problema. E não encontrei o log do combofix. E agora? Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 3, 2009 Opa samea, O Malwarebytes AntiMalware é um produto relativamente novo, porém com grande eficácia na remoção de infecções comuns. O programa é pequeno, gratuito e em português. A sua instalação é o primeiro passo para a limpeza de um sistema operacional infectado. Neste tutorial você aprenderá a instalá-lo e executá-lo. 1) Primeiramente faça o download do programa: http://www.malwarebytes.org/mbam/program/mbam-setup.exe 2) Agora proceda a instalação do programa, conforme segue: Execute o programa de instalação: Logo após a execução do arquivo de instalação, será exibida a seguinte tela: Agora, clique em Instalar para concluir: Ao término da instalação deixe marcadas as opções de Atualização e Execução: Será exibida então a tela de atualização do programa: 3) Essa é a tela inicial do programa. Marque a opção Verificação Completa e clique no botão Verificar. Aguarde até o final da verificação: Ao concluir a verificação, será exibida essa mensagem: O resultado da verificação será exibido, com o nome dos arquivos e malwares encontrados. Para efetivar a limpeza, clique em Remover selecionados: Para concluir a limpeza haverá a necessidade da reinicialização do computador: O programa guarda os logs das verificações feitas na pasta C:\Documents and Settings\Seu nome de Usuario\Dados de aplicativos\Malwarebytes\Malwarebytes' Anti-Malware\Logs, que também pode ser acessados na aba Logs, dentro do programa. Retorne com o resultado da varredura. Créditos: Fabio Assolini. Link para a postagem original: aqui. Compartilhar este post Link para o post Compartilhar em outros sites
samea 0 Denunciar post Postado Março 9, 2009 Fiz o Procedimento. Já não aparece mais o a janela sobre o "csrcs" Aqui esta o log: Malwarebytes' Anti-Malware 1.34 Versão do banco de dados: 1828 Windows 5.1.2600 Service Pack 3 2009-03-09 05:51:47 mbam-log-2009-03-09 (05-51-47).txt Tipo de Verificação: Completa (C:\|) Objetos verificados: 220660 Tempo decorrido: 1 hour(s), 57 minute(s), 50 second(s) Processos da Memória infectados: 0 Módulos de Memória Infectados: 0 Chaves do Registro infectadas: 56 Valores do Registro infectados: 16 Ítens do Registro infectados: 13 Pastas infectadas: 10 Arquivos infectados: 22 Processos da Memória infectados: (Nenhum ítem malicioso foi detectado) Módulos de Memória Infectados: (Nenhum ítem malicioso foi detectado) Chaves do Registro infectadas: HKEY_CLASSES_ROOT\iebrowsercmp.browsercmp (Adware.RightOnAds) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\iebrowsercmp.browsercmp.1 (Adware.RightOnAds) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1601d447-7424-4866-8dcc-acf98a2a41e1} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{c1a6d8b8-93c3-4186-9dd1-13983f9f1d9b} (Adware.RightOnAds) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{ceb9c60d-f0ad-4b73-a3ab-4fc822e38d66} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{ceb9c60d-f0ad-4b73-a3ab-4fc822e38d66} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{c3c0ec2c-2c1c-495c-9ad0-1f0ef833d7b5} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{3160f356-e8c3-4de2-a698-92eeeb3d3400} (Adware.RightOnAds) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{43fc67b6-4c25-4afd-ae7a-9ef3e4587026} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.Antivirus2008) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6156a32a-c512-4e23-aa9a-2315f4265681} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0bd071a6-c989-49e8-9b8e-80f92a868e26} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7aa32fc7-133b-4ae7-998e-ced0d9829b12} (Trojan.Dialer) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fc3c36d-7635-4d43-ba62-0d9d2f2cd06e} (Adware.Fotomoto) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{79f562e5-768c-4494-8e6c-824ada4a9c2c} (Adware.SuperiorAds) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c17e102b-bd29-4e92-b699-1a21d2cb8e6c} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0bd071a6-c989-49e8-9b8e-80f92a868e26} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6fc3c36d-7635-4d43-ba62-0d9d2f2cd06e} (Adware.Fotomoto) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\Sidebar.DLL (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\MyWay (Adware.MyWay) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\AdvRemoteDbg (Adware.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dcadssocial (Adware.RightOnAds) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\e405.e405mgr (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\WUSN.1 (Adware.WhenUSave) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dcads (Adware.Dcads) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2910e755-0574-9ca1-c006-c1ddc75ac7ff} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{2910e755-0574-9ca1-c006-c1ddc75ac7ff} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1ad53dc-8978-aaae-31e0-11904f82c145} (Adware.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d1ad53dc-8978-aaae-31e0-11904f82c145} (Adware.BHO) -> Quarantined and deleted successfully. Valores do Registro infectados: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\searchassistant (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\searchassistant (Trojan.Zlob) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\default_search_url (Trojan.Zlob) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl (Trojan.Zlob) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\searchurl (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\default_search_url (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\search page (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\search bar (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\searchurl (Trojan.Zlob) -> Delete on reboot. Ítens do Registro infectados: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q=%s'>http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q=%s'>http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (http://internetsearchservice.com/ie6.html) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe csrcs.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully. Pastas infectadas: C:\Arquivos de programas\MyWay (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\myBar (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\myBar\History (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\myBar\Settings (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\SrchAstt (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\SrchAstt\1.bin (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\SrchAstt\Cache (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\SrchAstt\Settings (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\NewDotNet (Adware.NewDotNet) -> Quarantined and deleted successfully. C:\WINDOWS\system32\734914 (Trojan.BHO) -> Quarantined and deleted successfully. Arquivos infectados: C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully. C:\Arquivos de programas\P2P_Torrent\tbP2P1.dll (Adware.Shopper) -> Quarantined and deleted successfully. C:\WINDOWS\system32\myss_sb_uninstall.exe (Adware.BHO) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\myBar\History\search (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\SrchAstt\1.bin\PARTNER.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\SrchAstt\Cache\004002F6 (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\SrchAstt\Cache\00400FF6 (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\SrchAstt\Cache\files.ini (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\MyWay\SrchAstt\Settings\prevcfg.htm (Adware.MyWay) -> Quarantined and deleted successfully. C:\Arquivos de programas\NewDotNet\readme.html (Adware.NewDotNet) -> Quarantined and deleted successfully. C:\WINDOWS\Downloaded Program Files\scpsssh2.inf (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\{273b9b6e-4f66-1694-2da2-48276ae4247b}.dll-uninst.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\{968ca23d-6ef5-c9a0-6a8d-9004e9867165}.dll-uninst.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe (Adware.BHO) -> Quarantined and deleted successfully. C:\WINDOWS\system32\superiorads-uninst.exe (Adware.BHO) -> Quarantined and deleted successfully. C:\WINDOWS\system32\DcadsSocial-uninstall.exe (Adware.RightOnAds) -> Quarantined and deleted successfully. C:\Documents and Settings\João\Dados de aplicativos\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully. C:\WINDOWS\Fonts\blazed.zip (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\Fonts\candy.zip (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\Fonts\download.zip (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\Fonts\fiolex_girls.zip (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\Fonts\mamae_que_nos_faz.zip (Worm.Archive) -> Quarantined and deleted successfully. :thumbsup: Obrigado!!! Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 15, 2009 Opa samea, 1. Baixe o BankerFix 3.0. 2. Desative o seu anti-vírus temporariamente. 3. Dê um duplo-clique sobre o bankerfix.exe. A janela do Banker Fix 3.0 abrir-se-á com a seguinte pergunta Instalar o BankerFix 3.0 / Install BankerFix 3.0 ? >> clique em SIM. 4. Uma janela informando que o BankerFix 3.0 será baixado via internet abrir-se-á >> clique sobre OK e aguarde. Na próxima janela clique em OK mais uma vez, a fim de que o BankerFix 3.0 seja iniciado. 5. Pressione qualquer tecla para dar continuidade ao processo e aguarde até que a varredura se complete. Tenha paciência, pois ela pode demorar alguns minutos. 6. Terminado o scan, leia a mensagem na tela e aperte Enter. 7. Habilite o seu anti-vírus. 8. Retorne com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\). 9. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C. Abraços. PS.: Caso apareça a seguinte mensagem: Site denunciado como foco de ataques!, não se preocupe e clique sobre Ignorar este alerta. Compartilhar este post Link para o post Compartilhar em outros sites
samea 0 Denunciar post Postado Março 20, 2009 BankerFix 3.0 VALKYRIE Linha Defensiva | http://www.linhadefensiva.org http://www.linhadefensiva.org/bankerfix/ ------------------------------------------------------- Data: 2009-03-19 - 23:05 ======================================================= C:\WINDOWS\system\GBPlugins.dll: Arquivo infectado removido com sucesso! ----- Fim ------------------------- Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 20, 2009 Opa samea, 1. Baixe o Kaspersky Virus Removal Tool. 2. O arquivo possui aproximadamente 35 Mb, mas o resultado compensará o trabalho. 3. Reinicie a máquina em Modo Seguro. 4. Execute a ferramenta dando duplo-clique sobre o arquivo baixado. 5. Abrir-se-á a seguinte janela: 6. Marque os diretórios que deseja varrer (é melhor marcar todos). 7. Clique em Scan e aguarde o término do processo. 8. Terminada a varredura, retorne com o resultado. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
samea 0 Denunciar post Postado Março 23, 2009 Opa samea, 1. Baixe o Kaspersky Virus Removal Tool. 2. O arquivo possui aproximadamente 35 Mb, mas o resultado compensará o trabalho. 3. Reinicie a máquina em Modo Seguro. 4. Execute a ferramenta dando duplo-clique sobre o arquivo baixado. 5. Abrir-se-á a seguinte janela: 6. Marque os diretórios que deseja varrer (é melhor marcar todos). 7. Clique em Scan e aguarde o término do processo. 8. Terminada a varredura, retorne com o resultado. Abraços. Rodei o programa, mas só achei esse resultado num arquivo XML seria esse? <?xml version="1.0" encoding="windows-1251" ?> - <!-- AVZ XML Report --> - <AVZ> - <PROCESS> <ITEM PID="932" File="c:\windows\explorer.exe" CheckResult="0" Descr="Windows Explorer" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Hidden="-1" CmdLine="C:\WINDOWS\Explorer.EXE" Size="1035776" Attr="rsAh" CreateDate="2004-08-04 00:45:34" ChageDate="2008-04-13 23:20:58" MD5="064EC7FF5F58B928C3E119402977FA6D" /> <ITEM PID="2044" File="c:\arquivos de programas\mozilla firefox\firefox.exe" CheckResult="-1" Descr="Firefox" LegalCopyright="©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable." CmdLine="" Size="307704" Attr="rsAh" CreateDate="2009-02-09 14:22:52" ChageDate="2009-03-06 22:30:07" MD5="762D1D11BB4E7C8D238D957E5AB60D0E" /> <ITEM PID="1556" File="c:\documents and settings\joгo\desktop\virus removal tool\is-rmfni\is-rmfni.exe" CheckResult="0" Descr="Kaspersky Anti-Virus" LegalCopyright="Copyright © Kaspersky Lab 1996-2007." Hidden="-1" CmdLine=""C:\Documents and Settings\Joгo\Desktop\Virus Removal Tool\is-RMFNI\is-RMFNI.exe"" Size="217088" Attr="rsAh" CreateDate="2009-03-22 15:00:26" ChageDate="2008-11-12 13:32:32" MD5="C408C0C4420A021A964D9888DD1183D4" NationalName="Y" /> <ITEM PID="376" File="c:\windows\system32\lsass.exe" CheckResult="0" Descr="LSA Shell (Export Version)" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="-1" CmdLine="C:\WINDOWS\system32\lsass.exe" Size="13312" Attr="rsAh" CreateDate="2004-08-04 00:45:36" ChageDate="2008-04-13 23:21:05" MD5="9607142710D3B64AB7FCCE4BE4E30D37" /> <ITEM PID="532" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="-1" CmdLine="C:\WINDOWS\system32\svchost -k DcomLaunch" Size="14336" Attr="rsAh" CreateDate="2004-08-04 00:45:44" ChageDate="2008-04-13 23:21:20" MD5="ED2D69CD4B0EBE37EFE11D4DC4ABC68F" /> <ITEM PID="596" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="-1" CmdLine="C:\WINDOWS\system32\svchost -k rpcss" Size="14336" Attr="rsAh" CreateDate="2004-08-04 00:45:44" ChageDate="2008-04-13 23:21:20" MD5="ED2D69CD4B0EBE37EFE11D4DC4ABC68F" /> <ITEM PID="640" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="-1" CmdLine="C:\WINDOWS\system32\svchost.exe -k netsvcs" Size="14336" Attr="rsAh" CreateDate="2004-08-04 00:45:44" ChageDate="2008-04-13 23:21:20" MD5="ED2D69CD4B0EBE37EFE11D4DC4ABC68F" /> <ITEM PID="320" File="c:\windows\system32\winlogon.exe" CheckResult="0" Descr="Aplicativo de logon do Windows NT" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Hidden="-1" CmdLine="winlogon.exe" Size="509952" Attr="rsAh" CreateDate="2004-08-04 00:45:46" ChageDate="2008-04-13 23:21:23" MD5="71D440F79B711627B12B567FB2EADB42" /> </PROCESS> - <DLL> <ITEM File="C:\WINDOWS\system32\serwvdrv.dll" CheckResult="-1" Descr="Driver Unimodem Serial Wave" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." UsedBy="932,1556,376,532,596,640,320" Hidden="-1" Size="14848" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="7BAE7061357C489E3C41314A1EC85B3B" /> <ITEM File="C:\WINDOWS\system32\umdmxfrm.dll" CheckResult="-1" Descr="Unimodem Tranform Module" LegalCopyright="© Microsoft Corporation. All rights reserved." UsedBy="932,1556,376,532,596,640,320" Hidden="-1" Size="13312" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="6EBC082A88B651640EB1526D7267FD26" /> <ITEM File="C:\Arquivos de programas\GbPlugin\gbiehcef.dll" CheckResult="-1" Descr="Gbieh Module" LegalCopyright="Copyright © 2003-2009, Caixa Economica Federal" UsedBy="932,320" Hidden="-1" Size="404032" Attr="rsAh" CreateDate="2008-12-30 12:39:03" ChageDate="2009-01-27 13:40:04" MD5="342503A85A961384A705725B2D97B123" /> <ITEM File="C:\Arquivos de programas\Scpad\scpLIB.dll" CheckResult="-1" Descr="scpIBLoad Module" LegalCopyright="Copyright 2005" UsedBy="932" Hidden="-1" Size="128512" Attr="rsah" CreateDate="2007-07-06 10:47:06" ChageDate="2007-03-27 01:29:08" MD5="5345D0E15C89EBE3FD3E1A2881345BA6" /> <ITEM File="C:\Arquivos de programas\Scpad\scpMIB.dll" CheckResult="-1" Descr="scpMIB Module" LegalCopyright="Copyright 2005" UsedBy="932" Hidden="-1" Size="256512" Attr="rsAh" CreateDate="2007-07-06 10:47:03" ChageDate="2007-03-27 16:47:04" MD5="20E3FBD9BF10C2C05995E106CF059000" /> <ITEM File="C:\Arquivos de programas\Scpad\sshib.dll" CheckResult="-1" Descr="sshib" LegalCopyright="Copyright © 2004" UsedBy="932" Hidden="-1" Size="19968" Attr="rsah" CreateDate="2007-07-06 10:47:06" ChageDate="2007-03-27 01:27:18" MD5="CB0AA677738A57D157B5D82FD76340C6" /> <ITEM File="C:\WINDOWS\system32\msacm32.drv" CheckResult="-1" Descr="Mapeador de som da Microsoft" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." UsedBy="932,1556,320" Hidden="-1" Size="20992" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="CF2BAE9C79C39E012605647A485C1320" /> <ITEM File="C:\WINDOWS\system32\msg711.acm" CheckResult="-1" Descr="CODEC Microsoft CCITT G.711 (A-Law e u-Law) para MSACM" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." UsedBy="932,1556,320" Hidden="-1" Size="9216" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="FD77D822F8D8F93C3C7CDD190CE76F96" /> <ITEM File="C:\WINDOWS\system32\msgsm32.acm" CheckResult="-1" Descr="CODEC de бudio Microsoft GSM 6.10 para MSACM" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." UsedBy="932,1556,320" Hidden="-1" Size="19968" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="6109521768E6E2E7F6C246C2D8E911DF" /> <ITEM File="C:\WINDOWS\system32\tssoft32.acm" CheckResult="-1" Descr="Codec de бudio DSP Group TrueSpeech para MSACM V3.50" LegalCopyright="Copyright DSP Group, Inc. 1993-1996" UsedBy="932,1556,320" Hidden="-1" Size="8192" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="F2AD69138348EAD46DEE28B0543C0977" /> <ITEM File="C:\WINDOWS\system32\tsd32.dll" CheckResult="-1" Descr="" LegalCopyright="" UsedBy="932,1556,320" Hidden="-1" Size="15360" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="56AD8DBD8CECCDE394B235527E8B04D9" /> <ITEM File="C:\WINDOWS\system32\msg723.acm" CheckResult="-1" Descr="Microsoft G.723.1 CODEC para MSACM" LegalCopyright="Copyright © Intel Corp. e Microsoft Corporation 1995-1999" UsedBy="932,1556,320" Hidden="-1" Size="118784" Attr="rsAh" CreateDate="2007-06-02 14:08:27" ChageDate="1782-01-19 00:14:07" MD5="4D25497C7108F3CD024412E295B41027" /> <ITEM File="C:\WINDOWS\system32\sirenacm.dll" CheckResult="-1" Descr="Messenger Audio Codec" LegalCopyright="Copyright © 1997 - 2006 Microsoft Corporation" UsedBy="932,1556,320" Hidden="-1" Size="51224" Attr="rsAh" CreateDate="2007-10-18 11:31:46" ChageDate="2007-10-18 11:31:46" MD5="69D044C73A1BA2485A017DBBB037C1A0" /> <ITEM File="C:\WINDOWS\system32\scg726.acm" CheckResult="-1" Descr="SHARP G.726 ACM Audio Decoder" LegalCopyright="Copyright © 2000 SHARP Corporation" UsedBy="932,1556,320" Hidden="-1" Size="13239" Attr="rsAh" CreateDate="2008-10-22 14:30:14" ChageDate="2000-03-14 19:55:44" MD5="DC4B2F21968AC6E7E6C8A4417ED0D85C" /> <ITEM File="C:\WINDOWS\system32\alf2cd.acm" CheckResult="-1" Descr="NCT ALF2CD Audio CODEC" LegalCopyright="NCT Company Copyright 1999 - 2001" UsedBy="932,1556,320" Hidden="-1" Size="38912" Attr="rsAh" CreateDate="2008-10-22 14:30:14" ChageDate="2003-05-21 22:50:36" MD5="8210141840CE237FBF40B6E26E2DD11D" /> <ITEM File="C:\WINDOWS\system32\avgrsstx.dll" CheckResult="-1" Descr="AVG Resident Shield Starter" LegalCopyright="Copyright © 2008 AVG Technologies CZ, s.r.o." UsedBy="320" Hidden="-1" Size="10520" Attr="rsAh" CreateDate="2009-02-02 14:24:16" ChageDate="2009-02-02 14:24:16" MD5="0AC7886F80734680E3463780CEDEA4A4" /> <ITEM File="C:\WINDOWS\system32\WgaLogon.dll" CheckResult="-1" Descr="Notificaзхes do Programa de Vantagens do Windows Original" LegalCopyright="© 1995-2008 Microsoft Corporation" UsedBy="320" Hidden="-1" Size="267304" Attr="rsAh" CreateDate="2007-03-15 18:16:56" ChageDate="2008-09-05 22:31:14" MD5="7C89FD192C0D83F0C0F88152411DA12A" /> </DLL> - <KERNELOBJ> <ITEM File="C:\WINDOWS\System32\Drivers\aex3mvvn.SYS" CheckResult="-1" Base="F9159000" MemSize="066000" Descr="" LegalCopyright="" /> <ITEM File="dmload.sys" CheckResult="-1" Base="F9A93000" MemSize="002000" Descr="" LegalCopyright="" /> <ITEM File="C:\WINDOWS\System32\Drivers\dump_atapi.sys" CheckResult="-1" Base="F8FEA000" MemSize="018000" Descr="" LegalCopyright="" /> <ITEM File="C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS" CheckResult="-1" Base="F9AC1000" MemSize="002000" Descr="" LegalCopyright="" /> <ITEM File="C:\WINDOWS\System32\Drivers\ElbyDelay.sys" CheckResult="-1" Base="F9A99000" MemSize="002000" Descr="Elby Delay Lower Filter Driver" LegalCopyright="Copyright © 2003 - 2006 Elaborate Bytes AG" Size="11984" Attr="rsAh" CreateDate="2007-02-15 21:56:49" ChageDate="2007-02-15 21:56:49" MD5="E205C313417DA6FA7AFE85912A310A65" /> <ITEM File="ftdisk.sys" CheckResult="-1" Base="F940C000" MemSize="01F000" Descr="" LegalCopyright="" /> <ITEM File="C:\WINDOWS\system32\Drivers\GbpKm.sys" CheckResult="-1" Base="F9825000" MemSize="007000" Descr="GbPlugin Device Driver" LegalCopyright="® GAS Tecnologia" Size="31296" Attr="rsAh" CreateDate="2008-12-30 12:39:20" ChageDate="2009-01-27 13:51:02" MD5="BB38AF368934928174751C156CBDD7D1" /> <ITEM File="PCIIde.sys" CheckResult="-1" Base="F9B55000" MemSize="001000" Descr="" LegalCopyright="" /> <ITEM File="C:\WINDOWS\system32\Drivers\sptd.sys" CheckResult="-1" Base="F9482000" MemSize="0EA000" Descr="" LegalCopyright="" Size="685816" Attr="rsAh" CreateDate="2007-06-29 16:51:28" ChageDate="2007-07-02 14:31:34" MD5="" /> </KERNELOBJ> - <Service> <ITEM File="C:\Arquivos de programas\Ares\chatServer.exe" Name="AresChatServer" CheckResult="-1" Type="272" State="1" Size="263168" Attr="rsAh" CreateDate="2007-03-19 22:19:14" ChageDate="2007-03-19 22:19:14" MD5="D0C8B41A2690CD3B57783C759B3B72D5" /> <ITEM File="C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe" Name="avg8wd" CheckResult="-1" Type="16" State="1" Size="298264" Attr="rsAh" CreateDate="2009-02-02 14:23:41" ChageDate="2009-02-02 14:23:41" MD5="C661B44D8E12EA95F51BAF2AEFF6364B" /> <ITEM File="C:\ARQUIV~1\GbPlugin\GbpSv.exe" Name="GbpSv" CheckResult="-1" Type="16" State="1" Size="52808" Attr="rsAh" CreateDate="2008-12-30 12:39:18" ChageDate="2009-01-27 13:35:44" MD5="A8C529C4D66687C255AC33867B8989F3" /> <ITEM File="C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe" Name="NMIndexingService" CheckResult="-1" Type="16" State="1" Size="447784" Attr="rsAh" CreateDate="2007-12-13 18:10:56" ChageDate="2007-12-13 18:10:56" MD5="74149BCF0307BB76D68C0F8912DF731C" /> <ITEM File="C:\Arquivos de programas\NewDotNet\nnrun.exe" Name="NNServ" CheckResult="-1" Type="16" State="1" /> <ITEM File="C:\WINDOWS\system32\HPZipm12.exe" Name="Pml Driver HPZ12" CheckResult="-1" Type="16" State="1" Size="73728" Attr="rsAh" CreateDate="2007-06-07 20:23:54" ChageDate="2007-08-09 04:27:52" MD5="2D091A99624FB9E7EEF0A86D872EC0C3" /> <ITEM File="C:\WINDOWS\system32\rsvp.exe" Name="RSVP" CheckResult="-1" Type="16" State="1" Size="132608" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="669B392EB438238E76AB120E02FB48E5" /> </Service> - <Drivers> <ITEM File="Beep.sys" Name="Beep" CheckResult="-1" Type="1" State="4" /> <ITEM File="C:\WINDOWS\system32\Drivers\ElbyDelay.sys" Name="ElbyDelay" CheckResult="-1" Type="1" State="4" Size="11984" Attr="rsAh" CreateDate="2007-02-15 21:56:49" ChageDate="2007-02-15 21:56:49" MD5="E205C313417DA6FA7AFE85912A310A65" /> <ITEM File="C:\WINDOWS\system32\DRIVERS\ftdisk.sys" Name="Ftdisk" CheckResult="-1" Type="1" State="4" Size="125824" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="D24D7839D594B255E1C298245B7BA6A2" /> <ITEM File="C:\WINDOWS\system32\drivers\GbpKm.sys" Name="GbpKm" CheckResult="-1" Type="1" State="4" Size="31296" Attr="rsAh" CreateDate="2008-12-30 12:39:20" ChageDate="2009-01-27 13:51:02" MD5="BB38AF368934928174751C156CBDD7D1" /> <ITEM File="Null.sys" Name="Null" CheckResult="-1" Type="1" State="4" /> <ITEM File="PCIIde.sys" Name="PCIIde" CheckResult="-1" Type="1" State="4" /> <ITEM File="C:\WINDOWS\System32\Drivers\sptd.sys" Name="sptd" CheckResult="-1" Type="1" State="4" Size="685816" Attr="rsAh" CreateDate="2007-06-29 16:51:28" ChageDate="2007-07-02 14:31:34" MD5="" /> <ITEM File="Abiosdsk.sys" Name="Abiosdsk" CheckResult="-1" Type="1" State="1" /> <ITEM File="abp480n5.sys" Name="abp480n5" CheckResult="-1" Type="1" State="1" /> <ITEM File="ACPIEC.sys" Name="ACPIEC" CheckResult="-1" Type="1" State="1" /> <ITEM File="adpu160m.sys" Name="adpu160m" CheckResult="-1" Type="1" State="1" /> <ITEM File="Aha154x.sys" Name="Aha154x" CheckResult="-1" Type="1" State="1" /> <ITEM File="aic78u2.sys" Name="aic78u2" CheckResult="-1" Type="1" State="1" /> <ITEM File="aic78xx.sys" Name="aic78xx" CheckResult="-1" Type="1" State="1" /> <ITEM File="AliIde.sys" Name="AliIde" CheckResult="-1" Type="1" State="1" /> <ITEM File="amsint.sys" Name="amsint" CheckResult="-1" Type="1" State="1" /> <ITEM File="asc.sys" Name="asc" CheckResult="-1" Type="1" State="1" /> <ITEM File="asc3350p.sys" Name="asc3350p" CheckResult="-1" Type="1" State="1" /> <ITEM File="asc3550.sys" Name="asc3550" CheckResult="-1" Type="1" State="1" /> <ITEM File="Atdisk.sys" Name="Atdisk" CheckResult="-1" Type="1" State="1" /> <ITEM File="C:\WINDOWS\System32\Drivers\avgldx86.sys" Name="AvgLdx86" CheckResult="-1" Type="1" State="1" Size="325128" Attr="rsAh" CreateDate="2009-02-02 14:24:06" ChageDate="2009-02-02 14:24:06" MD5="96E8AA914DAE8AB817DE504A7E75B5A5" /> <ITEM File="C:\WINDOWS\System32\Drivers\avgmfx86.sys" Name="AvgMfx86" CheckResult="-1" Type="2" State="1" Size="27656" Attr="rsAh" CreateDate="2009-02-02 14:24:05" ChageDate="2009-02-02 14:24:05" MD5="97A381475F5215C22931841A174F8E8D" /> <ITEM File="C:\WINDOWS\System32\Drivers\avgtdix.sys" Name="AvgTdiX" CheckResult="-1" Type="1" State="1" Size="107272" Attr="rsAh" CreateDate="2009-02-02 14:24:14" ChageDate="2009-02-02 14:24:14" MD5="F35C173DFD596DD3140506B5670ECDF5" /> <ITEM File="cbidf2k.sys" Name="cbidf2k" CheckResult="-1" Type="1" State="1" /> <ITEM File="cd20xrnt.sys" Name="cd20xrnt" CheckResult="-1" Type="1" State="1" /> <ITEM File="Cdaudio.sys" Name="Cdaudio" CheckResult="-1" Type="1" State="1" /> <ITEM File="Changer.sys" Name="Changer" CheckResult="-1" Type="1" State="1" /> <ITEM File="CmdIde.sys" Name="CmdIde" CheckResult="-1" Type="1" State="1" /> <ITEM File="Cpqarray.sys" Name="Cpqarray" CheckResult="-1" Type="1" State="1" /> <ITEM File="dac960nt.sys" Name="dac960nt" CheckResult="-1" Type="1" State="1" /> <ITEM File="dpti2o.sys" Name="dpti2o" CheckResult="-1" Type="1" State="1" /> <ITEM File="C:\Documents and Settings\Joгo\Desktop\Grand Chase\GameGuard\dump_wmimmc.sys" Name="dump_wmimmc" CheckResult="-1" Type="1" State="1" NationalName="Y" /> <ITEM File="C:\WINDOWS\system32\Drivers\ElbyCDIO.sys" Name="ElbyCDIO" CheckResult="-1" Type="1" State="1" Size="25160" Attr="rsAh" CreateDate="2007-08-07 16:48:33" ChageDate="2007-08-07 16:48:33" MD5="AAA8999A169E39FB8B48AE49CD6AC30A" /> <ITEM File="hpn.sys" Name="hpn" CheckResult="-1" Type="1" State="1" /> <ITEM File="i2omgmt.sys" Name="i2omgmt" CheckResult="-1" Type="1" State="1" /> <ITEM File="i2omp.sys" Name="i2omp" CheckResult="-1" Type="1" State="1" /> <ITEM File="ini910u.sys" Name="ini910u" CheckResult="-1" Type="1" State="1" /> <ITEM File="lbrtfdc.sys" Name="lbrtfdc" CheckResult="-1" Type="1" State="1" /> <ITEM File="mnmdd.sys" Name="mnmdd" CheckResult="-1" Type="1" State="1" /> <ITEM File="mraid35x.sys" Name="mraid35x" CheckResult="-1" Type="1" State="1" /> <ITEM File="ParVdm.sys" Name="ParVdm" CheckResult="-1" Type="1" State="1" /> <ITEM File="PCIDump.sys" Name="PCIDump" CheckResult="-1" Type="1" State="1" /> <ITEM File="PDCOMP.sys" Name="PDCOMP" CheckResult="-1" Type="1" State="1" /> <ITEM File="PDFRAME.sys" Name="PDFRAME" CheckResult="-1" Type="1" State="1" /> <ITEM File="PDRELI.sys" Name="PDRELI" CheckResult="-1" Type="1" State="1" /> <ITEM File="PDRFRAME.sys" Name="PDRFRAME" CheckResult="-1" Type="1" State="1" /> <ITEM File="perc2.sys" Name="perc2" CheckResult="-1" Type="1" State="1" /> <ITEM File="perc2hib.sys" Name="perc2hib" CheckResult="-1" Type="1" State="1" /> <ITEM File="C:\WINDOWS\system32\DRIVERS\CoachUsb.sys" Name="ProCam Usb" CheckResult="-1" Type="1" State="1" Size="46944" Attr="RsAh" CreateDate="2007-06-04 21:10:42" ChageDate="2003-11-14 03:14:10" MD5="62B20BED4F2804C1CEF8553CC654DA94" /> <ITEM File="ql1080.sys" Name="ql1080" CheckResult="-1" Type="1" State="1" /> <ITEM File="Ql10wnt.sys" Name="Ql10wnt" CheckResult="-1" Type="1" State="1" /> <ITEM File="ql12160.sys" Name="ql12160" CheckResult="-1" Type="1" State="1" /> <ITEM File="ql1240.sys" Name="ql1240" CheckResult="-1" Type="1" State="1" /> <ITEM File="ql1280.sys" Name="ql1280" CheckResult="-1" Type="1" State="1" /> <ITEM File="Simbad.sys" Name="Simbad" CheckResult="-1" Type="1" State="1" /> <ITEM File="Sparrow.sys" Name="Sparrow" CheckResult="-1" Type="1" State="1" /> <ITEM File="sym_hi.sys" Name="sym_hi" CheckResult="-1" Type="1" State="1" /> <ITEM File="sym_u3.sys" Name="sym_u3" CheckResult="-1" Type="1" State="1" /> <ITEM File="symc810.sys" Name="symc810" CheckResult="-1" Type="1" State="1" /> <ITEM File="symc8xx.sys" Name="symc8xx" CheckResult="-1" Type="1" State="1" /> <ITEM File="TosIde.sys" Name="TosIde" CheckResult="-1" Type="1" State="1" /> <ITEM File="ultra.sys" Name="ultra" CheckResult="-1" Type="1" State="1" /> <ITEM File="ViaIde.sys" Name="ViaIde" CheckResult="-1" Type="1" State="1" /> <ITEM File="WDICA.sys" Name="WDICA" CheckResult="-1" Type="1" State="1" /> </Drivers> - <AUTORUN> <ITEM File="" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Narrator" X3="Application path" /> <ITEM File="C:\ARQUIV~1\AVG\AVG8\avgtray.exe" CheckResult="-1" Enabled="1" Type="REG" Size="1601304" Attr="rsAh" CreateDate="2009-02-02 14:23:43" ChageDate="2009-02-02 14:23:45" MD5="1FC8B35E97123A9DF64F092DA8784E4C" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="AVG8_TRAY" /> <ITEM File="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_USERS" X2="S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run" X3="BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" /> <ITEM File="C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="210520" Attr="rsAh" CreateDate="2007-03-11 20:26:24" ChageDate="2007-03-11 20:26:24" MD5="F14219FC767F1383526AB423F278A8E3" X1="C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\" X2="C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\HP Digital Imaging Monitor.lnk" X3="" /> <ITEM File="C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" CheckResult="-1" Enabled="1" Type="REG" Size="49152" Attr="rsAh" CreateDate="2007-03-11 20:34:40" ChageDate="2007-03-11 20:34:40" MD5="7AF5A466CF4AECA28E3DCBCF5B6FD220" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="HP Software Update" /> <ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe" CheckResult="-1" Enabled="1" Type="REG" Size="144784" Attr="rsAh" CreateDate="2008-10-19 15:54:18" ChageDate="2008-06-10 03:27:04" MD5="6AB4C021FBD36DC6764924C312428D97" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="SunJavaUpdateSched" /> <ITEM File="C:\Arquivos de programas\Scpad\scpLIB.dll" CheckResult="-1" Enabled="1" Type="REG" Size="128512" Attr="rsah" CreateDate="2007-07-06 10:47:06" ChageDate="2007-03-27 01:29:08" MD5="5345D0E15C89EBE3FD3E1A2881345BA6" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler" X3="{A3717295-941D-416F-9384-ED1736729F1C}" /> <ITEM File="C:\Arquivos de programas\Scpad\scpLIB.dll" CheckResult="-1" Enabled="1" Type="REG" Size="128512" Attr="rsah" CreateDate="2007-07-06 10:47:06" ChageDate="2007-03-27 01:29:08" MD5="5345D0E15C89EBE3FD3E1A2881345BA6" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad" X3="CompIBBrd" /> <ITEM File="C:\Arquivos de programas\Torrent Finder\Torrent-Finder.exe" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_USERS" X2="S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run" X3="Torrent Finder" /> <ITEM File="C:\Arquivos de programas\Winferno\RegistryPowerCleaner\RegPowerClean.exe" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_USERS" X2="S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run" X3="RegPowerClean" /> <ITEM File="C:\DOCUME~1\JOO~1\DADOSD~1\CREATI~1\Bolt Slow Dash.exe" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_USERS" X2="S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run" X3="bowsmove" /> <ITEM File="C:\Documents and Settings\All Users\Dados de aplicativos\Joy coal mpeg heck\win team.exe" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="mpeg heck log link" /> <ITEM File="C:\WINDOWS\system32\dfrg.msc %c:" CheckResult="-1" Enabled="-1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath" X3="" /> <ITEM File="C:\WINDOWS\system\GBPlugins.dll" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ aGbPlugin" X3="DLLName" /> <ITEM File="WgaLogon.dll" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon" X3="DLLName" /> <ITEM File="avgrsstx.dll" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter" X3="DLLName" /> </AUTORUN> - <BHO> <ITEM File="C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{0347C33E-8762-4905-BF09-768834316C61}" Descr="hpswp_printenhancer dll" LegalCopyright="HP. All rights reserved." Size="1298024" Attr="RsAh" CreateDate="2007-03-02 15:52:24" ChageDate="2007-03-02 15:52:24" MD5="1062E80907867BFC14EB844241391331" /> <ITEM File="C:\Arquivos de programas\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{04079851-5845-4dea-848C-3ECD647AA554}" Descr="" LegalCopyright="" /> <ITEM File="C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{053F9267-DC04-4294-A72C-58F732D338C0}" Descr="Leo (Framework) - add-on for Internet Explorer" LegalCopyright="Copyright © Hewlett-Packard Co. 1995-2006" Size="177768" Attr="RsAh" CreateDate="2007-03-02 15:52:08" ChageDate="2007-03-02 15:52:08" MD5="A40456DE4EF7E318104955361C72AC9D" /> <ITEM File="C:\Arquivos de programas\Scpad\scpsssh2.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{2E3C3651-B19C-4DD9-A979-901EC3E930AF}" Descr="scpsssh2 Module" LegalCopyright="Copyright 2001" Size="124416" Attr="rsah" CreateDate="2007-07-06 12:56:05" ChageDate="2007-03-27 01:28:16" MD5="59D8245EA3128BAF96DF6C3A1F4DA435" /> <ITEM File="C:\Arquivos de programas\AVG\AVG8\avgssie.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" Descr="Safe Search for Internet Explorer" LegalCopyright="Copyright © 2008 AVG Technologies CZ, s.r.o." Size="1078552" Attr="rsAh" CreateDate="2009-02-02 14:23:52" ChageDate="2009-02-02 14:23:53" MD5="2225E1B951EC0E3209D11C167F96D834" /> <ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" /> <ITEM File="" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{7E853D72-626A-48EC-A868-BA8D5E23E045}" Descr="" LegalCopyright="" /> <ITEM File="C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{9030D464-4C02-4ABF-8ECC-5164760863C6}" Descr="WindowsLiveLogin.dll" LegalCopyright="Copyright © 1995-2006 Microsoft Corporation." Size="408440" Attr="rsAh" CreateDate="2009-02-17 16:11:04" ChageDate="2009-02-17 16:11:04" MD5="1A82C1B9BB43385695EFC3A84F6756A2" /> <ITEM File="C:\Arquivos de programas\GbPlugin\gbiehcef.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{C41A1C0E-EA6C-11D4-B1B8-444553540003}" Descr="Gbieh Module" LegalCopyright="Copyright © 2003-2009, Caixa Economica Federal" Size="404032" Attr="rsAh" CreateDate="2008-12-30 12:39:03" ChageDate="2009-01-27 13:40:04" MD5="342503A85A961384A705725B2D97B123" /> <ITEM File="" CheckResult="-1" Enabled="1" BHOType="3" RegKey="Software\Microsoft\Internet Explorer\Extensions" CLSID="{58ECB495-38F0-49cb-A538-10282ABF65E7}" Descr="" LegalCopyright="" /> <ITEM File="" CheckResult="-1" Enabled="1" BHOType="3" RegKey="Software\Microsoft\Internet Explorer\Extensions" CLSID="{700259D7-1666-479a-93B1-3250410481E8}" Descr="" LegalCopyright="" /> </BHO> - <ExplorerExt> <ITEM File="icmui.dll" CheckResult="-1" Enabled="1" ExtName="Gerenciamento de scanner ICM" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{176d6597-26d3-11d1-b350-080036a75b03}" Descr="DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." /> <ITEM File="docprop.dll" CheckResult="-1" Enabled="1" ExtName="Pбgina de propriedades do arquivo de documento OLE" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{3EA48300-8CF6-101B-84FB-666CCB9BCD32}" Descr="Pбgina de propriedades do arquivo de documento OLE" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." /> <ITEM File="deskadp.dll" CheckResult="-1" Enabled="1" ExtName="Extensгo do 'Painel de controle' para adaptador de vнdeo" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{42071712-76d4-11d1-8b24-00a0c9068ff3}" Descr="Propriedades avanзadas de adaptador de vнdeo" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." /> <ITEM File="deskmon.dll" CheckResult="-1" Enabled="1" ExtName="Extensгo do 'Painel de controle' para monitor de vнdeo" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{42071713-76d4-11d1-8b24-00a0c9068ff3}" Descr="Propriedades avanзadas de monitor" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." /> <ITEM File="" CheckResult="-1" Enabled="1" ExtName="Extensгo do 'Painel de controle' para panorвmica de vнdeo" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{42071714-76d4-11d1-8b24-00a0c9068ff3}" Descr="" LegalCopyright="" /> <ITEM File="ntlanui2.dll" CheckResult="-1" Enabled="1" ExtName="Extensхes do shell para objetos Microsoft Windows Network" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{59be4990-f85c-11ce-aff7-00aa003ca9f6}" Descr="Objeto de rede do shell da interface de usuбrio" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." /> <ITEM File="C:\WINDOWS\System32\icmui.dll" CheckResult="-1" Enabled="1" ExtName="Gerenciamento de monitor ICM" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{5DB2625A-54DF-11D0-B6C4-0800091AA605}" Descr="DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="55808" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="71B1979A285B2A0FACFE2A01231FE4DB" /> <ITEM File="C:\WINDOWS\system32\icmui.dll" CheckResult="-1" Enabled="1" ExtName="Gerenciamento de impressora ICM" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{675F097E-4C4D-11D0-B6C1-0800091AA605}" Descr="DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="55808" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="71B1979A285B2A0FACFE2A01231FE4DB" /> <ITEM File="" CheckResult="-1" Enabled="1" ExtName="Extensхes do shell para compactaзгo de arquivos" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{764BF0E1-F219-11ce-972D-00AA00A14F56}" Descr="" LegalCopyright="" /> <ITEM File="" CheckResult="-1" Enabled="1" ExtName="Menu de contexto de criptografia" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}" Descr="" LegalCopyright="" /> <ITEM File="C:\WINDOWS\system32\hticons.dll" CheckResult="-1" Enabled="1" ExtName="Extensгo de нcone do HyperTerminal" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{88895560-9AA2-1069-930E-00AA0030EBC8}" Descr="HyperTerminal Applet Library" LegalCopyright="Copyright © Hilgraeve, Inc. 2001" Size="44544" Attr="rsAh" CreateDate="2007-06-02 14:06:42" ChageDate="1782-01-19 00:14:07" MD5="42F92CD0BD982401067DD69AC3445CD5" /> <ITEM File="C:\WINDOWS\system32\icmui.dll" CheckResult="-1" Enabled="1" ExtName="Perfil ICC" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{DBCE2480-C732-101B-BE72-BA78E9AD5B27}" Descr="DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="55808" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="71B1979A285B2A0FACFE2A01231FE4DB" /> <ITEM File="deskperf.dll" CheckResult="-1" Enabled="1" ExtName="Display TroubleShoot CPL Extension" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{f92e8c40-3d33-11d2-b1aa-080036a75b03}" Descr="Propriedades avanзadas de desempenho de vнdeo" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." /> <ITEM File="" CheckResult="-1" Enabled="1" ExtName="Barra de tarefas e menu Iniciar" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{0DF44EAA-FF21-4412-828E-260A8728E7F1}" Descr="" LegalCopyright="" /> <ITEM File="rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}" CheckResult="-1" Enabled="1" ExtName="Autoplay for SlideShow" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}" Descr="" LegalCopyright="" /> <ITEM File="" CheckResult="-1" Enabled="1" ExtName="Contas de usuбrio" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{7A9D77BD-5403-11d2-8785-2E0420524153}" Descr="" LegalCopyright="" /> <ITEM File="C:\Arquivos de programas\Microsoft Office\Office10\OLKFSTUB.DLL" CheckResult="-1" Enabled="1" ExtName="Microsoft Outlook Custom Icon Handler" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{0006F045-0000-0000-C000-000000000046}" Descr="Outlook Shell Hook for Start/Find" LegalCopyright="Copyright© Microsoft Corporation 1995-2001. Todos os direitos reservados." Size="56032" Attr="rsAh" CreateDate="2004-01-22 09:06:14" ChageDate="2004-01-22 09:06:14" MD5="DA477B3A22B736900C2565BFF00C7D31" /> <ITEM File="" CheckResult="-1" Enabled="1" ExtName="CorelDRAW Shell Extension Component" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="" Descr="" LegalCopyright="" /> <ITEM File="C:\WINDOWS\system32\mscoree.dll" CheckResult="-1" Enabled="1" ExtName="Fusion Cache" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{1D2680C9-0E2A-469d-B787-065558BC7D43}" Descr="Microsoft .NET Runtime Execution Engine" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="271360" Attr="rsAh" CreateDate="2006-12-22 11:28:14" ChageDate="2006-12-22 11:28:14" MD5="B5B67EE09B52D7129B8041B9BD411F7B" /> <ITEM File="" CheckResult="-1" Enabled="1" ExtName="Shell Extension for Malware scanning" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" Descr="" LegalCopyright="" /> <ITEM File="C:\Arquivos de programas\GbPlugin\gbiehcef.dll" CheckResult="-1" Enabled="1" ExtName="GbPlugin ShlObj" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{E37CB5F0-51F5-4395-A808-5FA49E399003}" Descr="Gbieh Module" LegalCopyright="Copyright © 2003-2009, Caixa Economica Federal" Size="404032" Attr="rsAh" CreateDate="2008-12-30 12:39:03" ChageDate="2009-01-27 13:40:04" MD5="342503A85A961384A705725B2D97B123" /> <ITEM File="C:\Arquivos de programas\AVG\AVG8\avgse.dll" CheckResult="-1" Enabled="1" ExtName="AVG8 Shell Extension" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" Descr="AVG Shell Extension" LegalCopyright="Copyright © 2008 AVG Technologies CZ, s.r.o." Size="117528" Attr="rsAh" CreateDate="2009-02-02 14:23:48" ChageDate="2009-02-02 14:23:48" MD5="076506D1F442D732B348B7C9E1921CD6" /> <ITEM File="" CheckResult="-1" Enabled="1" ExtName="AVG8 Find Extension" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" Descr="" LegalCopyright="" /> </ExplorerExt> - <PrintEXT> <ITEM File="C:\WINDOWS\system32\hpz3l054.dll" CheckResult="-1" Enabled="1" RegKey="SYSTEM\CurrentControlSet\Control\Print\Monitors" Descr="LanguageMonitor" LegalCopyright="Copyright © 1999" Size="38400" Attr="rsAh" CreateDate="2007-06-07 20:25:12" ChageDate="2006-04-10 14:03:02" MD5="FDB859F93C8491F961C3B9168FA90F51" /> </PrintEXT> - <TaskScheduler> <ITEM File="c:\docume~1\joo~1\dadosd~1\creati~1\pokeviewfunk.exe" CheckResult="-1" Enabled="122424880" Descr="" LegalCopyright="" /> <ITEM File="C:\Arquivos de programas\Winferno\RegistryPowerCleaner\RegPowerClean.exe" CheckResult="-1" Enabled="122424880" Descr="" LegalCopyright="" /> </TaskScheduler> - <DPF> <ITEM File="" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="Microsoft XML Parser for Java" CodeBase="file://C:\WINDOWS\Java\classes\xmldso.cab" Descr="" LegalCopyright="" /> <ITEM File="C:\WINDOWS\Downloaded Program Files\msgrchkr.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{20A60F0D-9AFA-4515-A0FD-83BD84642501}" CodeBase="http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab" Descr="Zone.com Checkers for MSN Messenger" LegalCopyright="Copyright © 1995-2004 Microsoft Corporation" Size="131472" Attr="rsAh" CreateDate="2007-02-28 13:21:04" ChageDate="2007-02-28 13:21:04" MD5="1E5CFDF9AEBDD84305A4C8154277A269" /> <ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{8AD9C840-044E-11D1-B3E9-00805F499D93}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" /> <ITEM File="" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" CodeBase="http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab" Descr="" LegalCopyright="" /> <ITEM File="C:\WINDOWS\Downloaded Program Files\zylomgamesplayer.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}" CodeBase="http://game14.zylom.com/activex/zylomgamesplayer.cab" Descr="Zylom Games Player" LegalCopyright="Copyright 2004" Size="161976" Attr="rsAh" CreateDate="2006-08-29 14:17:22" ChageDate="2006-08-29 14:17:22" MD5="7FAF5222EEB546E1DC0F348DCB314B0B" /> <ITEM File="C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{C3F79A2B-B9B4-4A66-B012-3EE46475B072}" CodeBase="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab" Descr="Zone.com Stats Client for MSN Messenger" LegalCopyright="Copyright © 1995-2004 Microsoft Corporation" Size="304544" Attr="rsAh" CreateDate="2007-02-22 22:41:12" ChageDate="2007-02-22 22:41:12" MD5="8945CCA5FC4F25168E8B6F401EFAF51F" /> <ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" /> <ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" /> <ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" /> <ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" /> <ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\npjpi160_07.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" Descr="Java Plug-in 1.6.0_07 for Netscape Navigator (DLL Helper)" LegalCopyright="Copyright © 2004" Size="132496" Attr="rsAh" CreateDate="2008-06-10 01:32:34" ChageDate="2008-06-10 03:27:02" MD5="7C83A2809E13950359189767AC9D5DB8" /> <ITEM File="C:\Arquivos de programas\GbPlugin\GbpDist.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931}" CodeBase="https://imagem.caixa.gov.br/cab/gbpdist.cab" Descr="GbpDist Module" LegalCopyright="Copyright © 2008" Size="79424" Attr="rsAh" CreateDate="2008-12-30 12:39:15" ChageDate="2009-01-27 13:49:26" MD5="21587F8E147B0BDC1B7734EBD94D9D4D" /> </DPF> - <CPL> <ITEM File="C:\WINDOWS\system32\ImageDrive.cpl" CheckResult="-1" Enabled="1" Descr="" LegalCopyright="" Size="57344" Attr="rsah" CreateDate="2007-06-02 17:42:57" ChageDate="2003-03-31 16:27:54" MD5="4BE82722A9802EEB07B04450E56D7655" /> <ITEM File="C:\WINDOWS\system32\ISUSPM.cpl" CheckResult="-1" Enabled="1" Descr="InstallShield Update Service Update Manager Applet" LegalCopyright="Copyright © 1990-2004 InstallShield Software Corporation" Size="61440" Attr="rsAh" CreateDate="2004-04-16 11:24:54" ChageDate="2004-04-16 11:24:54" MD5="A7EB7AC7145C0B2D9E8103A90AE255E0" /> <ITEM File="C:\WINDOWS\system32\javacpl.cpl" CheckResult="-1" Enabled="1" Descr="Java Control Panel" LegalCopyright="Copyright © 2004" Size="73728" Attr="rsAh" CreateDate="2007-09-22 17:34:11" ChageDate="2008-06-10 01:32:34" MD5="370716E3CA99E6A4346F272DA56017C1" /> <ITEM File="C:\WINDOWS\system32\main.cpl" CheckResult="-1" Enabled="1" Descr="DLL do 'Painel de controle'" LegalCopyright="Copyright © Microsoft Corp. 1991-1999" Size="188928" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="6088DFCD542C1B5646A99C2B71607800" /> <ITEM File="C:\WINDOWS\system32\ncpa.cpl" CheckResult="-1" Enabled="1" Descr="Conexхes de rede no painel de controle" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="35840" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="43B08C09D30DCAA0D08F161FCF51F734" /> <ITEM File="C:\WINDOWS\system32\nwc.cpl" CheckResult="-1" Enabled="1" Descr="Aplicativo Serviзo de cliente para NetWare" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="37888" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="08A1A1C5A5971C39AD263C3580464B80" /> <ITEM File="C:\WINDOWS\system32\telephon.cpl" CheckResult="-1" Enabled="1" Descr="Painel de controle de telefonia" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="28160" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="69B830766F6D52109F822ACC106B8AEF" /> </CPL> <ActiveSetup /> - <HOSTS> <ITEM Line="127.0.0.1 localhost" /> </HOSTS> - <SuspFiles> <ITEM File="C:\WINDOWS\system32\serwvdrv.dll" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> <ITEM File="C:\WINDOWS\system32\umdmxfrm.dll" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> <ITEM File="C:\WINDOWS\system32\msacm32.drv" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> <ITEM File="C:\WINDOWS\system32\msg711.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> <ITEM File="C:\WINDOWS\system32\msgsm32.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> <ITEM File="C:\WINDOWS\system32\tssoft32.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> <ITEM File="C:\WINDOWS\system32\tsd32.dll" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> <ITEM File="C:\WINDOWS\system32\msg723.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> <ITEM File="C:\WINDOWS\system32\sirenacm.dll" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> <ITEM File="C:\WINDOWS\system32\scg726.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> <ITEM File="C:\WINDOWS\system32\alf2cd.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" /> </SuspFiles> - <RK_UM> <ITEM DLL="kernel32.dll" FNaim="CreateProcessA" FIndx="98" HookPtr="61F03F42" HookType="1" /> <ITEM DLL="kernel32.dll" FNaim="CreateProcessW" FIndx="102" HookPtr="61F04040" HookType="1" /> <ITEM DLL="kernel32.dll" FNaim="FreeLibrary" FIndx="240" HookPtr="61F041FC" HookType="1" /> <ITEM DLL="kernel32.dll" FNaim="GetModuleFileNameA" FIndx="372" HookPtr="61F040FB" HookType="1" /> <ITEM DLL="kernel32.dll" FNaim="GetModuleFileNameW" FIndx="373" HookPtr="61F041A0" HookType="1" /> <ITEM DLL="kernel32.dll" FNaim="GetProcAddress" FIndx="408" HookPtr="61F04648" HookType="1" /> <ITEM DLL="kernel32.dll" FNaim="LoadLibraryA" FIndx="580" HookPtr="61F03C6F" HookType="1" /> <ITEM DLL="kernel32.dll" FNaim="LoadLibraryExA" FIndx="581" HookPtr="61F03DAF" HookType="1" /> <ITEM DLL="kernel32.dll" FNaim="LoadLibraryExW" FIndx="582" HookPtr="61F03E5A" HookType="1" /> <ITEM DLL="kernel32.dll" FNaim="LoadLibraryW" FIndx="583" HookPtr="61F03D0C" HookType="1" /> </RK_UM> - <KEYLOGGER> <ITEM File="C:\WINDOWS\system32\serwvdrv.dll" Verdict="" CheckResult="-1" Size="14848" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="7BAE7061357C489E3C41314A1EC85B3B" /> <ITEM File="C:\WINDOWS\system32\umdmxfrm.dll" Verdict="" CheckResult="-1" Size="13312" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="6EBC082A88B651640EB1526D7267FD26" /> <ITEM File="C:\WINDOWS\system32\msacm32.drv" Verdict="" CheckResult="-1" Size="20992" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="CF2BAE9C79C39E012605647A485C1320" /> <ITEM File="C:\WINDOWS\system32\msg711.acm" Verdict="" CheckResult="-1" Size="9216" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="FD77D822F8D8F93C3C7CDD190CE76F96" /> <ITEM File="C:\WINDOWS\system32\msgsm32.acm" Verdict="" CheckResult="-1" Size="19968" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="6109521768E6E2E7F6C246C2D8E911DF" /> <ITEM File="C:\WINDOWS\system32\tssoft32.acm" Verdict="" CheckResult="-1" Size="8192" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="F2AD69138348EAD46DEE28B0543C0977" /> <ITEM File="C:\WINDOWS\system32\tsd32.dll" Verdict="" CheckResult="-1" Size="15360" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="56AD8DBD8CECCDE394B235527E8B04D9" /> <ITEM File="C:\WINDOWS\system32\msg723.acm" Verdict="" CheckResult="-1" Size="118784" Attr="rsAh" CreateDate="2007-06-02 14:08:27" ChageDate="1782-01-19 00:14:07" MD5="4D25497C7108F3CD024412E295B41027" /> <ITEM File="C:\WINDOWS\system32\sirenacm.dll" Verdict="" CheckResult="-1" Size="51224" Attr="rsAh" CreateDate="2007-10-18 11:31:46" ChageDate="2007-10-18 11:31:46" MD5="69D044C73A1BA2485A017DBBB037C1A0" /> <ITEM File="C:\WINDOWS\system32\scg726.acm" Verdict="" CheckResult="-1" Size="13239" Attr="rsAh" CreateDate="2008-10-22 14:30:14" ChageDate="2000-03-14 19:55:44" MD5="DC4B2F21968AC6E7E6C8A4417ED0D85C" /> <ITEM File="C:\WINDOWS\system32\alf2cd.acm" Verdict="" CheckResult="-1" Size="38912" Attr="rsAh" CreateDate="2008-10-22 14:30:14" ChageDate="2003-05-21 22:50:36" MD5="8210141840CE237FBF40B6E26E2DD11D" /> </KEYLOGGER> - <WIZARD-TSW> <ITEM ID="58" Level="3" Fixed="0" /> <ITEM ID="59" Level="3" Fixed="0" /> <ITEM ID="60" Level="1" Fixed="0" /> <ITEM ID="61" Level="2" Fixed="0" /> </WIZARD-TSW> </AVZ> Compartilhar este post Link para o post Compartilhar em outros sites
samea 0 Denunciar post Postado Março 23, 2009 E esse outro: Results of system analysis Kaspersky Virus Removal Tool 7.0.0.290 (database released 22/03/2009; 14:42) List of processes File name PID Description Copyright MD5 Information c:\windows\explorer.exe Script: Quarantine, Delete, BC delete, Terminate 932 Windows Explorer © Microsoft Corporation. Todos os direitos reservados. ?? 1011.50 kb, rsAh, created: 2004-08-04 00:45:34, modified: 2008-04-13 23:20:58 Command line: C:\WINDOWS\Explorer.EXE c:\arquivos de programas\mozilla firefox\firefox.exe Script: Quarantine, Delete, BC delete, Terminate 2044 Firefox ©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable. ?? 300.49 kb, rsAh, created: 2009-02-09 14:22:52, modified: 2009-03-06 22:30:07 Command line: c:\documents and settings\joгo\desktop\virus removal tool\is-rmfni\is-rmfni.exe Script: Quarantine, Delete, BC delete, Terminate 1556 Kaspersky Anti-Virus Copyright © Kaspersky Lab 1996-2007. ?? 212.00 kb, rsAh, created: 2009-03-22 15:00:26, modified: 2008-11-12 13:32:32, name contains national symbols Command line: "C:\Documents and Settings\Joгo\Desktop\Virus Removal Tool\is-RMFNI\is-RMFNI.exe" c:\windows\system32\lsass.exe Script: Quarantine, Delete, BC delete, Terminate 376 LSA Shell (Export Version) © Microsoft Corporation. All rights reserved. ?? 13.00 kb, rsAh, created: 2004-08-04 00:45:36, modified: 2008-04-13 23:21:05 Command line: C:\WINDOWS\system32\lsass.exe c:\windows\system32\svchost.exe Script: Quarantine, Delete, BC delete, Terminate 532 Generic Host Process for Win32 Services © Microsoft Corporation. All rights reserved. ?? 14.00 kb, rsAh, created: 2004-08-04 00:45:44, modified: 2008-04-13 23:21:20 Command line: C:\WINDOWS\system32\svchost -k DcomLaunch c:\windows\system32\svchost.exe Script: Quarantine, Delete, BC delete, Terminate 596 Generic Host Process for Win32 Services © Microsoft Corporation. All rights reserved. ?? 14.00 kb, rsAh, created: 2004-08-04 00:45:44, modified: 2008-04-13 23:21:20 Command line: C:\WINDOWS\system32\svchost -k rpcss c:\windows\system32\svchost.exe Script: Quarantine, Delete, BC delete, Terminate 640 Generic Host Process for Win32 Services © Microsoft Corporation. All rights reserved. ?? 14.00 kb, rsAh, created: 2004-08-04 00:45:44, modified: 2008-04-13 23:21:20 Command line: C:\WINDOWS\system32\svchost.exe -k netsvcs c:\windows\system32\winlogon.exe Script: Quarantine, Delete, BC delete, Terminate 320 Aplicativo de logon do Windows NT © Microsoft Corporation. Todos os direitos reservados. ?? 498.00 kb, rsAh, created: 2004-08-04 00:45:46, modified: 2008-04-13 23:21:23 Command line: winlogon.exe Detected:15, recognized as trusted 14 Module name Handle Description Copyright MD5 Used by processes C:\Arquivos de programas\GbPlugin\gbiehcef.dll Script: Quarantine, Delete, BC delete 268435456 Gbieh Module Copyright © 2003-2009, Caixa Economica Federal -- 932, 320 C:\Arquivos de programas\Scpad\scpLIB.dll Script: Quarantine, Delete, BC delete 26935296 scpIBLoad Module Copyright 2005 -- 932 C:\Arquivos de programas\Scpad\scpMIB.dll Script: Quarantine, Delete, BC delete 27197440 scpMIB Module Copyright 2005 -- 932 C:\Arquivos de programas\Scpad\sshib.dll Script: Quarantine, Delete, BC delete 28180480 sshib Copyright © 2004 -- 932 C:\WINDOWS\system32\alf2cd.acm Script: Quarantine, Delete, BC delete 34406400 NCT ALF2CD Audio CODEC NCT Company Copyright 1999 - 2001 -- 932, 1556, 320 C:\WINDOWS\system32\avgrsstx.dll Script: Quarantine, Delete, BC delete 1813708800 AVG Resident Shield Starter Copyright © 2008 AVG Technologies CZ, s.r.o. -- 320 C:\WINDOWS\system32\msacm32.drv Script: Quarantine, Delete, BC delete 1925971968 Mapeador de som da Microsoft © Microsoft Corporation. Todos os direitos reservados. -- 932, 1556, 320 C:\WINDOWS\system32\msg711.acm Script: Quarantine, Delete, BC delete 1483931648 CODEC Microsoft CCITT G.711 (A-Law e u-Law) para MSACM © Microsoft Corporation. Todos os direitos reservados. -- 932, 1556, 320 C:\WINDOWS\system32\msg723.acm Script: Quarantine, Delete, BC delete 1483800576 Microsoft G.723.1 CODEC para MSACM Copyright © Intel Corp. e Microsoft Corporation 1995-1999 -- 932, 1556, 320 C:\WINDOWS\system32\msgsm32.acm Script: Quarantine, Delete, BC delete 1483735040 CODEC de бudio Microsoft GSM 6.10 para MSACM © Microsoft Corporation. Todos os direitos reservados. -- 932, 1556, 320 C:\WINDOWS\system32\scg726.acm Script: Quarantine, Delete, BC delete 34340864 SHARP G.726 ACM Audio Decoder Copyright © 2000 SHARP Corporation -- 932, 1556, 320 C:\WINDOWS\system32\serwvdrv.dll Script: Quarantine, Delete, BC delete 1562181632 Driver Unimodem Serial Wave © Microsoft Corporation. Todos os direitos reservados. -- 932, 1556, 376, 532, 596, 640, 320 C:\WINDOWS\system32\sirenacm.dll Script: Quarantine, Delete, BC delete 1516240896 Messenger Audio Codec Copyright © 1997 - 2006 Microsoft Corporation -- 932, 1556, 320 C:\WINDOWS\system32\tsd32.dll Script: Quarantine, Delete, BC delete 1941045248 -- 932, 1556, 320 C:\WINDOWS\system32\tssoft32.acm Script: Quarantine, Delete, BC delete 1483538432 Codec de бudio DSP Group TrueSpeech para MSACM V3.50 Copyright DSP Group, Inc. 1993-1996 -- 932, 1556, 320 C:\WINDOWS\system32\umdmxfrm.dll Script: Quarantine, Delete, BC delete 1531904000 Unimodem Tranform Module © Microsoft Corporation. All rights reserved. -- 932, 1556, 376, 532, 596, 640, 320 C:\WINDOWS\system32\WgaLogon.dll Script: Quarantine, Delete, BC delete 18939904 Notificaзхes do Programa de Vantagens do Windows Original © 1995-2008 Microsoft Corporation -- 320 Modules detected:255, recognized as trusted 238 Kernel Space Modules Viewer Module Base address Size in memory Description Manufacturer C:\WINDOWS\System32\Drivers\aex3mvvn.SYS Script: Quarantine, Delete, BC delete F9159000 066000 (417792) dmload.sys Script: Quarantine, Delete, BC delete F9A93000 002000 (8192) C:\WINDOWS\System32\Drivers\dump_atapi.sys Script: Quarantine, Delete, BC delete F8FEA000 018000 (98304) C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Script: Quarantine, Delete, BC delete F9AC1000 002000 (8192) C:\WINDOWS\System32\Drivers\ElbyDelay.sys Script: Quarantine, Delete, BC delete F9A99000 002000 (8192) Elby Delay Lower Filter Driver Copyright © 2003 - 2006 Elaborate Bytes AG ftdisk.sys Script: Quarantine, Delete, BC delete F940C000 01F000 (126976) C:\WINDOWS\system32\Drivers\GbpKm.sys Script: Quarantine, Delete, BC delete F9825000 007000 (28672) GbPlugin Device Driver ® GAS Tecnologia PCIIde.sys Script: Quarantine, Delete, BC delete F9B55000 001000 (4096) C:\WINDOWS\system32\Drivers\sptd.sys Script: Quarantine, Delete, BC delete F9482000 0EA000 (958464) Modules detected - 73, recognized as trusted - 64 Services Service Description Status File Group Dependencies AresChatServer Service: Stop, Delete, Disable Ares Chatroom server Not started C:\Arquivos de programas\Ares\chatServer.exe Script: Quarantine, Delete, BC delete avg8wd Service: Stop, Delete, Disable AVG Free8 WatchDog Not started C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe Script: Quarantine, Delete, BC delete GbpSv Service: Stop, Delete, Disable Gbp Service Not started C:\ARQUIV~1\GbPlugin\GbpSv.exe Script: Quarantine, Delete, BC delete GbPlugin Group NMIndexingService Service: Stop, Delete, Disable NMIndexingService Not started C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe Script: Quarantine, Delete, BC delete RPCSS NNServ Service: Stop, Delete, Disable NNServ Not started C:\Arquivos de programas\NewDotNet\nnrun.exe Script: Quarantine, Delete, BC delete Pml Driver HPZ12 Service: Stop, Delete, Disable Pml Driver HPZ12 Not started C:\WINDOWS\system32\HPZipm12.exe Script: Quarantine, Delete, BC delete RSVP Service: Stop, Delete, Disable QoS RSVP Not started C:\WINDOWS\system32\rsvp.exe Script: Quarantine, Delete, BC delete TcpIp Detected - 104, recognized as trusted - 97 Drivers Service Description Status File Group Dependencies Beep Driver: Unload, Delete, Disable Beep Running Beep.sys Script: Quarantine, Delete, BC delete Base ElbyDelay Driver: Unload, Delete, Disable ElbyDelay Running C:\WINDOWS\system32\Drivers\ElbyDelay.sys Script: Quarantine, Delete, BC delete Ftdisk Driver: Unload, Delete, Disable Volume Manager Driver Running C:\WINDOWS\system32\DRIVERS\ftdisk.sys Script: Quarantine, Delete, BC delete System Bus Extender GbpKm Driver: Unload, Delete, Disable Gbp KernelMode Running C:\WINDOWS\system32\drivers\GbpKm.sys Script: Quarantine, Delete, BC delete GbPlugin Group Null Driver: Unload, Delete, Disable Null Running Null.sys Script: Quarantine, Delete, BC delete Base PCIIde Driver: Unload, Delete, Disable PCIIde Running PCIIde.sys Script: Quarantine, Delete, BC delete System Bus Extender sptd Driver: Unload, Delete, Disable sptd Running C:\WINDOWS\System32\Drivers\sptd.sys Script: Quarantine, Delete, BC delete Boot Bus Extender Abiosdsk Driver: Unload, Delete, Disable Abiosdsk Not started Abiosdsk.sys Script: Quarantine, Delete, BC delete Primary disk abp480n5 Driver: Unload, Delete, Disable abp480n5 Not started abp480n5.sys Script: Quarantine, Delete, BC delete SCSI miniport ACPIEC Driver: Unload, Delete, Disable ACPIEC Not started ACPIEC.sys Script: Quarantine, Delete, BC delete Boot Bus Extender adpu160m Driver: Unload, Delete, Disable adpu160m Not started adpu160m.sys Script: Quarantine, Delete, BC delete SCSI miniport Aha154x Driver: Unload, Delete, Disable Aha154x Not started Aha154x.sys Script: Quarantine, Delete, BC delete SCSI miniport aic78u2 Driver: Unload, Delete, Disable aic78u2 Not started aic78u2.sys Script: Quarantine, Delete, BC delete SCSI miniport aic78xx Driver: Unload, Delete, Disable aic78xx Not started aic78xx.sys Script: Quarantine, Delete, BC delete SCSI miniport AliIde Driver: Unload, Delete, Disable AliIde Not started AliIde.sys Script: Quarantine, Delete, BC delete System Bus Extender amsint Driver: Unload, Delete, Disable amsint Not started amsint.sys Script: Quarantine, Delete, BC delete SCSI miniport asc Driver: Unload, Delete, Disable asc Not started asc.sys Script: Quarantine, Delete, BC delete SCSI miniport asc3350p Driver: Unload, Delete, Disable asc3350p Not started asc3350p.sys Script: Quarantine, Delete, BC delete SCSI miniport asc3550 Driver: Unload, Delete, Disable asc3550 Not started asc3550.sys Script: Quarantine, Delete, BC delete SCSI miniport Atdisk Driver: Unload, Delete, Disable Atdisk Not started Atdisk.sys Script: Quarantine, Delete, BC delete Primary disk AvgLdx86 Driver: Unload, Delete, Disable AVG Free AVI Loader Driver x86 Not started C:\WINDOWS\System32\Drivers\avgldx86.sys Script: Quarantine, Delete, BC delete AVG AvgMfx86 Driver: Unload, Delete, Disable AVG Free On-access Scanner Minifilter Driver x86 Not started C:\WINDOWS\System32\Drivers\avgmfx86.sys Script: Quarantine, Delete, BC delete AVG AvgTdiX Driver: Unload, Delete, Disable AVG Free8 Network Redirector Not started C:\WINDOWS\System32\Drivers\avgtdix.sys Script: Quarantine, Delete, BC delete PNP_TDI cbidf2k Driver: Unload, Delete, Disable cbidf2k Not started cbidf2k.sys Script: Quarantine, Delete, BC delete SCSI miniport cd20xrnt Driver: Unload, Delete, Disable cd20xrnt Not started cd20xrnt.sys Script: Quarantine, Delete, BC delete SCSI miniport Cdaudio Driver: Unload, Delete, Disable Cdaudio Not started Cdaudio.sys Script: Quarantine, Delete, BC delete Filter Changer Driver: Unload, Delete, Disable Changer Not started Changer.sys Script: Quarantine, Delete, BC delete Filter CmdIde Driver: Unload, Delete, Disable CmdIde Not started CmdIde.sys Script: Quarantine, Delete, BC delete System Bus Extender Cpqarray Driver: Unload, Delete, Disable Cpqarray Not started Cpqarray.sys Script: Quarantine, Delete, BC delete SCSI miniport dac960nt Driver: Unload, Delete, Disable dac960nt Not started dac960nt.sys Script: Quarantine, Delete, BC delete SCSI miniport dpti2o Driver: Unload, Delete, Disable dpti2o Not started dpti2o.sys Script: Quarantine, Delete, BC delete SCSI miniport dump_wmimmc Driver: Unload, Delete, Disable dump_wmimmc Not started C:\Documents and Settings\Joгo\Desktop\Grand Chase\GameGuard\dump_wmimmc.sys Script: Quarantine, Delete, BC delete ElbyCDIO Driver: Unload, Delete, Disable ElbyCDIO Driver Not started C:\WINDOWS\system32\Drivers\ElbyCDIO.sys Script: Quarantine, Delete, BC delete hpn Driver: Unload, Delete, Disable hpn Not started hpn.sys Script: Quarantine, Delete, BC delete SCSI miniport i2omgmt Driver: Unload, Delete, Disable i2omgmt Not started i2omgmt.sys Script: Quarantine, Delete, BC delete SCSI Class i2omp Driver: Unload, Delete, Disable i2omp Not started i2omp.sys Script: Quarantine, Delete, BC delete SCSI miniport ini910u Driver: Unload, Delete, Disable ini910u Not started ini910u.sys Script: Quarantine, Delete, BC delete SCSI miniport lbrtfdc Driver: Unload, Delete, Disable lbrtfdc Not started lbrtfdc.sys Script: Quarantine, Delete, BC delete System Bus Extender mnmdd Driver: Unload, Delete, Disable mnmdd Not started mnmdd.sys Script: Quarantine, Delete, BC delete Video Save mraid35x Driver: Unload, Delete, Disable mraid35x Not started mraid35x.sys Script: Quarantine, Delete, BC delete SCSI miniport ParVdm Driver: Unload, Delete, Disable ParVdm Not started ParVdm.sys Script: Quarantine, Delete, BC delete Extended base Parport PCIDump Driver: Unload, Delete, Disable PCIDump Not started PCIDump.sys Script: Quarantine, Delete, BC delete PCI Configuration PDCOMP Driver: Unload, Delete, Disable PDCOMP Not started PDCOMP.sys Script: Quarantine, Delete, BC delete PDFRAME Driver: Unload, Delete, Disable PDFRAME Not started PDFRAME.sys Script: Quarantine, Delete, BC delete PDRELI Driver: Unload, Delete, Disable PDRELI Not started PDRELI.sys Script: Quarantine, Delete, BC delete PDRFRAME Driver: Unload, Delete, Disable PDRFRAME Not started PDRFRAME.sys Script: Quarantine, Delete, BC delete perc2 Driver: Unload, Delete, Disable perc2 Not started perc2.sys Script: Quarantine, Delete, BC delete SCSI miniport perc2hib Driver: Unload, Delete, Disable perc2hib Not started perc2hib.sys Script: Quarantine, Delete, BC delete Filter ProCam Usb Driver: Unload, Delete, Disable ProCam Digital Camera on USB Not started C:\WINDOWS\system32\DRIVERS\CoachUsb.sys Script: Quarantine, Delete, BC delete ql1080 Driver: Unload, Delete, Disable ql1080 Not started ql1080.sys Script: Quarantine, Delete, BC delete SCSI miniport Ql10wnt Driver: Unload, Delete, Disable Ql10wnt Not started Ql10wnt.sys Script: Quarantine, Delete, BC delete SCSI miniport ql12160 Driver: Unload, Delete, Disable ql12160 Not started ql12160.sys Script: Quarantine, Delete, BC delete SCSI miniport ql1240 Driver: Unload, Delete, Disable ql1240 Not started ql1240.sys Script: Quarantine, Delete, BC delete SCSI miniport ql1280 Driver: Unload, Delete, Disable ql1280 Not started ql1280.sys Script: Quarantine, Delete, BC delete SCSI miniport Simbad Driver: Unload, Delete, Disable Simbad Not started Simbad.sys Script: Quarantine, Delete, BC delete Filter Sparrow Driver: Unload, Delete, Disable Sparrow Not started Sparrow.sys Script: Quarantine, Delete, BC delete SCSI miniport sym_hi Driver: Unload, Delete, Disable sym_hi Not started sym_hi.sys Script: Quarantine, Delete, BC delete SCSI miniport sym_u3 Driver: Unload, Delete, Disable sym_u3 Not started sym_u3.sys Script: Quarantine, Delete, BC delete SCSI miniport symc810 Driver: Unload, Delete, Disable symc810 Not started symc810.sys Script: Quarantine, Delete, BC delete SCSI miniport symc8xx Driver: Unload, Delete, Disable symc8xx Not started symc8xx.sys Script: Quarantine, Delete, BC delete SCSI miniport TosIde Driver: Unload, Delete, Disable TosIde Not started TosIde.sys Script: Quarantine, Delete, BC delete System Bus Extender ultra Driver: Unload, Delete, Disable ultra Not started ultra.sys Script: Quarantine, Delete, BC delete SCSI miniport ViaIde Driver: Unload, Delete, Disable ViaIde Not started ViaIde.sys Script: Quarantine, Delete, BC delete System Bus Extender WDICA Driver: Unload, Delete, Disable WDICA Not started WDICA.sys Script: Quarantine, Delete, BC delete Detected - 191, recognized as trusted - 127 Autoruns File name Status Startup method Description Active Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Narrator, Application path C:\ARQUIV~1\AVG\AVG8\avgtray.exe Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AVG8_TRAY C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe Script: Quarantine, Delete, BC delete Active Registry key HKEY_USERS, S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run, BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe Script: Quarantine, Delete, BC delete Active Shortcut in Autoruns folder C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\, C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\HP Digital Imaging Monitor.lnk, C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, HP Software Update C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SunJavaUpdateSched C:\Arquivos de programas\Scpad\scpLIB.dll Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {A3717295-941D-416F-9384-ED1736729F1C} C:\Arquivos de programas\Scpad\scpLIB.dll Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CompIBBrd C:\Arquivos de programas\Torrent Finder\Torrent-Finder.exe Script: Quarantine, Delete, BC delete Active Registry key HKEY_USERS, S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run, Torrent Finder C:\Arquivos de programas\Winferno\RegistryPowerCleaner\RegPowerClean.exe Script: Quarantine, Delete, BC delete Active Registry key HKEY_USERS, S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run, RegPowerClean C:\DOCUME~1\JOO~1\DADOSD~1\CREATI~1\Bolt Slow Dash.exe Script: Quarantine, Delete, BC delete Active Registry key HKEY_USERS, S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run, bowsmove C:\Documents and Settings\All Users\Dados de aplicativos\Joy coal mpeg heck\win team.exe Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, mpeg heck log link C:\WINDOWS\system32\dfrg.msc %c: Script: Quarantine, Delete, BC delete -- Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath, C:\WINDOWS\system\GBPlugins.dll Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ aGbPlugin, DLLName WgaLogon.dll Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon, DLLName avgrsstx.dll Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter, DLLName Autoruns items detected - 74, recognized as trusted - 58 Microsoft Internet Explorer extension modules (BHOs, Toolbars ...) File name Type Description Manufacturer CLSID C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll Script: Quarantine, Delete, BC delete BHO hpswp_printenhancer dll HP. All rights reserved. {0347C33E-8762-4905-BF09-768834316C61} Delete C:\Arquivos de programas\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL Script: Quarantine, Delete, BC delete BHO {04079851-5845-4dea-848C-3ECD647AA554} Delete C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll Script: Quarantine, Delete, BC delete BHO Leo (Framework) - add-on for Internet Explorer Copyright © Hewlett-Packard Co. 1995-2006 {053F9267-DC04-4294-A72C-58F732D338C0} Delete C:\Arquivos de programas\Scpad\scpsssh2.dll Script: Quarantine, Delete, BC delete BHO scpsssh2 Module Copyright 2001 {2E3C3651-B19C-4DD9-A979-901EC3E930AF} Delete C:\Arquivos de programas\AVG\AVG8\avgssie.dll Script: Quarantine, Delete, BC delete BHO Safe Search for Internet Explorer Copyright © 2008 AVG Technologies CZ, s.r.o. {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Delete C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll Script: Quarantine, Delete, BC delete BHO Java Platform SE binary Copyright © 2004 {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} Delete BHO {7E853D72-626A-48EC-A868-BA8D5E23E045} Delete C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll Script: Quarantine, Delete, BC delete BHO WindowsLiveLogin.dll Copyright © 1995-2006 Microsoft Corporation. {9030D464-4C02-4ABF-8ECC-5164760863C6} Delete C:\Arquivos de programas\GbPlugin\gbiehcef.dll Script: Quarantine, Delete, BC delete BHO Gbieh Module Copyright © 2003-2009, Caixa Economica Federal {C41A1C0E-EA6C-11D4-B1B8-444553540003} Delete Extension module {58ECB495-38F0-49cb-A538-10282ABF65E7} Delete Extension module {700259D7-1666-479a-93B1-3250410481E8} Delete Elements detected - 14, recognized as trusted - 3 Windows Explorer extension modules File name Destination Description Manufacturer CLSID icmui.dll Script: Quarantine, Delete, BC delete Gerenciamento de scanner ICM DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft © Microsoft Corporation. Todos os direitos reservados. {176d6597-26d3-11d1-b350-080036a75b03} docprop.dll Script: Quarantine, Delete, BC delete Pбgina de propriedades do arquivo de documento OLE Pбgina de propriedades do arquivo de documento OLE © Microsoft Corporation. Todos os direitos reservados. {3EA48300-8CF6-101B-84FB-666CCB9BCD32} deskadp.dll Script: Quarantine, Delete, BC delete Extensгo do 'Painel de controle' para adaptador de vнdeo Propriedades avanзadas de adaptador de vнdeo © Microsoft Corporation. Todos os direitos reservados. {42071712-76d4-11d1-8b24-00a0c9068ff3} deskmon.dll Script: Quarantine, Delete, BC delete Extensгo do 'Painel de controle' para monitor de vнdeo Propriedades avanзadas de monitor © Microsoft Corporation. Todos os direitos reservados. {42071713-76d4-11d1-8b24-00a0c9068ff3} Extensгo do 'Painel de controle' para panorвmica de vнdeo {42071714-76d4-11d1-8b24-00a0c9068ff3} ntlanui2.dll Script: Quarantine, Delete, BC delete Extensхes do shell para objetos Microsoft Windows Network Objeto de rede do shell da interface de usuбrio © Microsoft Corporation. Todos os direitos reservados. {59be4990-f85c-11ce-aff7-00aa003ca9f6} C:\WINDOWS\System32\icmui.dll Script: Quarantine, Delete, BC delete Gerenciamento de monitor ICM DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft © Microsoft Corporation. Todos os direitos reservados. {5DB2625A-54DF-11D0-B6C4-0800091AA605} C:\WINDOWS\system32\icmui.dll Script: Quarantine, Delete, BC delete Gerenciamento de impressora ICM DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft © Microsoft Corporation. Todos os direitos reservados. {675F097E-4C4D-11D0-B6C1-0800091AA605} Extensхes do shell para compactaзгo de arquivos {764BF0E1-F219-11ce-972D-00AA00A14F56} Menu de contexto de criptografia {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} C:\WINDOWS\system32\hticons.dll Script: Quarantine, Delete, BC delete Extensгo de нcone do HyperTerminal HyperTerminal Applet Library Copyright © Hilgraeve, Inc. 2001 {88895560-9AA2-1069-930E-00AA0030EBC8} C:\WINDOWS\system32\icmui.dll Script: Quarantine, Delete, BC delete Perfil ICC DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft © Microsoft Corporation. Todos os direitos reservados. {DBCE2480-C732-101B-BE72-BA78E9AD5B27} deskperf.dll Script: Quarantine, Delete, BC delete Display TroubleShoot CPL Extension Propriedades avanзadas de desempenho de vнdeo © Microsoft Corporation. Todos os direitos reservados. {f92e8c40-3d33-11d2-b1aa-080036a75b03} Barra de tarefas e menu Iniciar {0DF44EAA-FF21-4412-828E-260A8728E7F1} rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} Script: Quarantine, Delete, BC delete Autoplay for SlideShow {00E7B358-F65B-4dcf-83DF-CD026B94BFD4} Contas de usuбrio {7A9D77BD-5403-11d2-8785-2E0420524153} C:\Arquivos de programas\Microsoft Office\Office10\OLKFSTUB.DLL Script: Quarantine, Delete, BC delete Microsoft Outlook Custom Icon Handler Outlook Shell Hook for Start/Find Copyright© Microsoft Corporation 1995-2001. Todos os direitos reservados. {0006F045-0000-0000-C000-000000000046} CorelDRAW Shell Extension Component C:\WINDOWS\system32\mscoree.dll Script: Quarantine, Delete, BC delete Fusion Cache Microsoft .NET Runtime Execution Engine © Microsoft Corporation. All rights reserved. {1D2680C9-0E2A-469d-B787-065558BC7D43} Shell Extension for Malware scanning {45AC2688-0253-4ED8-97DE-B5370FA7D48A} C:\Arquivos de programas\GbPlugin\gbiehcef.dll Script: Quarantine, Delete, BC delete GbPlugin ShlObj Gbieh Module Copyright © 2003-2009, Caixa Economica Federal {E37CB5F0-51F5-4395-A808-5FA49E399003} C:\Arquivos de programas\AVG\AVG8\avgse.dll Script: Quarantine, Delete, BC delete AVG8 Shell Extension AVG Shell Extension Copyright © 2008 AVG Technologies CZ, s.r.o. {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} AVG8 Find Extension {9F97547E-460A-42C5-AE0C-81C61FFAEBC3} Elements detected - 206, recognized as trusted - 183 Printing system extensions (print monitors, providers) File name Type Name Description Manufacturer C:\WINDOWS\system32\hpz3l054.dll Script: Quarantine, Delete, BC delete Monitor PCL hpz3l054 LanguageMonitor Copyright © 1999 Elements detected - 10, recognized as trusted - 9 Task Scheduler jobs File name Job name Job status Description Manufacturer c:\docume~1\joo~1\dadosd~1\creati~1\pokeviewfunk.exe Script: Quarantine, Delete, BC delete BC5747FE9388E1CE.job The task is ready to run at its next scheduled time. C:\Arquivos de programas\Winferno\RegistryPowerCleaner\RegPowerClean.exe Script: Quarantine, Delete, BC delete rpc.job The task has not yet run. Elements detected - 2, recognized as trusted - 0 SPI/LSP settings Namespace providers (NSP) Manufacturer Status EXE file Description GUID Detected - 3, recognized as trusted - 3 Transport protocol providers (TSP, LSP) Manufacturer EXE file Description Detected - 15, recognized as trusted - 15 Results of automatic SPI settings check LSP settings checked. No errors detected TCP/UDP ports Port Status Remote Host Remote Port Application Notes TCP ports UDP ports Downloaded Program Files (DPF) File name Description Manufacturer CLSID Source URL Microsoft XML Parser for Java Delete file://C:\WINDOWS\Java\classes\xmldso.cab C:\WINDOWS\Downloaded Program Files\msgrchkr.dll Script: Quarantine, Delete, BC delete Zone.com Checkers for MSN Messenger Copyright © 1995-2004 Microsoft Corporation {20A60F0D-9AFA-4515-A0FD-83BD84642501} Delete http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll Script: Quarantine, Delete, BC delete Java Platform SE binary Copyright © 2004 {8AD9C840-044E-11D1-B3E9-00805F499D93} Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} Delete http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab C:\WINDOWS\Downloaded Program Files\zylomgamesplayer.dll Script: Quarantine, Delete, BC delete Zylom Games Player Copyright 2004 {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} Delete http://game14.zylom.com/activex/zylomgamesplayer.cab C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll Script: Quarantine, Delete, BC delete Zone.com Stats Client for MSN Messenger Copyright © 1995-2004 Microsoft Corporation {C3F79A2B-B9B4-4A66-B012-3EE46475B072} Delete http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll Script: Quarantine, Delete, BC delete Java Platform SE binary Copyright © 2004 {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll Script: Quarantine, Delete, BC delete Java Platform SE binary Copyright © 2004 {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll Script: Quarantine, Delete, BC delete Java Platform SE binary Copyright © 2004 {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll Script: Quarantine, Delete, BC delete Java Platform SE binary Copyright © 2004 {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab C:\Arquivos de programas\Java\jre1.6.0_07\bin\npjpi160_07.dll Script: Quarantine, Delete, BC delete Java Plug-in 1.6.0_07 for Netscape Navigator (DLL Helper) Copyright © 2004 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab C:\Arquivos de programas\GbPlugin\GbpDist.dll Script: Quarantine, Delete, BC delete GbpDist Module Copyright © 2008 {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} Delete https://imagem.caixa.gov.br/cab/gbpdist.cab Elements detected - 12, recognized as trusted - 0 Control Panel Applets (CPL) File name Description Manufacturer C:\WINDOWS\system32\ImageDrive.cpl Script: Quarantine, Delete, BC delete C:\WINDOWS\system32\ISUSPM.cpl Script: Quarantine, Delete, BC delete InstallShield Update Service Update Manager Applet Copyright © 1990-2004 InstallShield Software Corporation C:\WINDOWS\system32\javacpl.cpl Script: Quarantine, Delete, BC delete Java Control Panel Copyright © 2004 C:\WINDOWS\system32\main.cpl Script: Quarantine, Delete, BC delete DLL do 'Painel de controle' Copyright © Microsoft Corp. 1991-1999 C:\WINDOWS\system32\ncpa.cpl Script: Quarantine, Delete, BC delete Conexхes de rede no painel de controle © Microsoft Corporation. Todos os direitos reservados. C:\WINDOWS\system32\nwc.cpl Script: Quarantine, Delete, BC delete Aplicativo Serviзo de cliente para NetWare © Microsoft Corporation. Todos os direitos reservados. C:\WINDOWS\system32\telephon.cpl Script: Quarantine, Delete, BC delete Painel de controle de telefonia © Microsoft Corporation. Todos os direitos reservados. Elements detected - 28, recognized as trusted - 21 Active Setup File name Description Manufacturer CLSID Elements detected - 15, recognized as trusted - 15 HOSTS file Hosts file record 127.0.0.1 localhost Protocols and handlers File name Type Description Manufacturer CLSID C:\WINDOWS\system32\mscoree.dll Script: Quarantine, Delete, BC delete Protocol Microsoft .NET Runtime Execution Engine () © Microsoft Corporation. All rights reserved. {1E66F26B-79EE-11D2-8710-00C04F79ED0D} C:\WINDOWS\system32\mscoree.dll Script: Quarantine, Delete, BC delete Protocol Microsoft .NET Runtime Execution Engine () © Microsoft Corporation. All rights reserved. {1E66F26B-79EE-11D2-8710-00C04F79ED0D} C:\WINDOWS\system32\mscoree.dll Script: Quarantine, Delete, BC delete Protocol Microsoft .NET Runtime Execution Engine () © Microsoft Corporation. All rights reserved. {1E66F26B-79EE-11D2-8710-00C04F79ED0D} C:\Arquivos de programas\AVG\AVG8\avgpp.dll Script: Quarantine, Delete, BC delete Handler Safe Search pluggable protocol (linkscanner: ExPLabs.com Pluggable Protocol) Copyright © 2008 AVG Technologies CZ, s.r.o. {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} Elements detected - 33, recognized as trusted - 29 Suspicious objects File Description Type C:\WINDOWS\system32\serwvdrv.dll Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\umdmxfrm.dll Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\msacm32.drv Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\msg711.acm Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\msgsm32.acm Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\tssoft32.acm Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\tsd32.dll Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\msg723.acm Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\sirenacm.dll Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\scg726.acm Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\alf2cd.acm Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL Windows version: Microsoft Windows XP, Build=2600, SP="Service Pack 3" System Restore: enabled System booted in Safe Mode 1.1 Searching for user-mode API hooks Analysis: kernel32.dll, export table found in section .text Function kernel32.dll:CreateProcessA (99) intercepted, method ProcAddressHijack.GetProcAddress ->7C80236B->61F03F42 Hook kernel32.dll:CreateProcessA (99) blocked Function kernel32.dll:CreateProcessW (103) intercepted, method ProcAddressHijack.GetProcAddress ->7C802336->61F04040 Hook kernel32.dll:CreateProcessW (103) blocked Function kernel32.dll:FreeLibrary (241) intercepted, method ProcAddressHijack.GetProcAddress ->7C80AC6E->61F041FC Hook kernel32.dll:FreeLibrary (241) blocked Function kernel32.dll:GetModuleFileNameA (373) intercepted, method ProcAddressHijack.GetProcAddress ->7C80B55F->61F040FB Hook kernel32.dll:GetModuleFileNameA (373) blocked Function kernel32.dll:GetModuleFileNameW (374) intercepted, method ProcAddressHijack.GetProcAddress ->7C80B465->61F041A0 Hook kernel32.dll:GetModuleFileNameW (374) blocked Function kernel32.dll:GetProcAddress (409) intercepted, method ProcAddressHijack.GetProcAddress ->7C80AE30->61F04648 Hook kernel32.dll:GetProcAddress (409) blocked Function kernel32.dll:LoadLibraryA (581) intercepted, method ProcAddressHijack.GetProcAddress ->7C801D7B->61F03C6F Hook kernel32.dll:LoadLibraryA (581) blocked >>> Functions LoadLibraryA - preventing AVZ process from being intercepted by address replacement !!) Function kernel32.dll:LoadLibraryExA (582) intercepted, method ProcAddressHijack.GetProcAddress ->7C801D53->61F03DAF Hook kernel32.dll:LoadLibraryExA (582) blocked >>> Functions LoadLibraryExA - preventing AVZ process from being intercepted by address replacement !!) Function kernel32.dll:LoadLibraryExW (583) intercepted, method ProcAddressHijack.GetProcAddress ->7C801AF5->61F03E5A Hook kernel32.dll:LoadLibraryExW (583) blocked Function kernel32.dll:LoadLibraryW (584) intercepted, method ProcAddressHijack.GetProcAddress ->7C80AEDB->61F03D0C Hook kernel32.dll:LoadLibraryW (584) blocked IAT modification detected: LoadLibraryW - 00B40010<>7C80AEDB Analysis: ntdll.dll, export table found in section .text Analysis: user32.dll, export table found in section .text Analysis: advapi32.dll, export table found in section .text Analysis: ws2_32.dll, export table found in section .text Analysis: wininet.dll, export table found in section .text Analysis: rasapi32.dll, export table found in section .text Analysis: urlmon.dll, export table found in section .text Analysis: netapi32.dll, export table found in section .text 1.2 Searching for kernel-mode API hooks Driver loaded successfully Driver communication failure [00000002] - [1] 1.4 Searching for masking processes and drivers Checking not performed: extended monitoring driver (AVZPM) is not installed Driver loaded successfully Driver communication failure [00000002] - [1] C:\WINDOWS\system32\serwvdrv.dll --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\serwvdrv.dll>>> Behavioral analysis Behaviour typical for keyloggers not detected C:\WINDOWS\system32\umdmxfrm.dll --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\umdmxfrm.dll>>> Behavioral analysis Behaviour typical for keyloggers not detected C:\WINDOWS\system32\msacm32.drv --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\msacm32.drv>>> Behavioral analysis Behaviour typical for keyloggers not detected C:\WINDOWS\system32\msg711.acm --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\msg711.acm>>> Behavioral analysis Behaviour typical for keyloggers not detected C:\WINDOWS\system32\msgsm32.acm --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\msgsm32.acm>>> Behavioral analysis Behaviour typical for keyloggers not detected C:\WINDOWS\system32\tssoft32.acm --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\tssoft32.acm>>> Behavioral analysis Behaviour typical for keyloggers not detected C:\WINDOWS\system32\tsd32.dll --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\tsd32.dll>>> Behavioral analysis Behaviour typical for keyloggers not detected C:\WINDOWS\system32\msg723.acm --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\msg723.acm>>> Behavioral analysis Behaviour typical for keyloggers not detected C:\WINDOWS\system32\sirenacm.dll --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\sirenacm.dll>>> Behavioral analysis Behaviour typical for keyloggers not detected C:\WINDOWS\system32\scg726.acm --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\scg726.acm>>> Behavioral analysis Behaviour typical for keyloggers not detected C:\WINDOWS\system32\alf2cd.acm --> Suspicion for Keylogger or Trojan DLL C:\WINDOWS\system32\alf2cd.acm>>> Behavioral analysis Behaviour typical for keyloggers not detected Note: Do NOT delete suspicious files, send them for analysis (see FAQ for more details), because there are lots of useful hooking DLLs >> Services: potentially dangerous service allowed: RemoteRegistry (Registro remoto) >> Services: potentially dangerous service allowed: TermService (Serviзos de terminal) >> Services: potentially dangerous service allowed: SSDPSRV (Serviзo de descoberta SSDP) >> Services: potentially dangerous service allowed: Schedule (Agendador de tarefas) >> Services: potentially dangerous service allowed: mnmsrvc (Compartilhamento remoto da бrea de trabalho do NetMeeting) >> Services: potentially dangerous service allowed: RDSessMgr (Gerenciador de sessгo de ajuda de бrea de trabalho remota) > Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)! >> Security: disk drives' autorun is enabled >> Security: administrative shares (C$, D$ ...) are enabled >> Security: anonymous user access is enabled >> Security: sending Remote Assistant queries is enabled >> Disable HDD autorun >> Disable autorun from network drives >> Disable CD/DVD autorun >> Disable removable media autorun System Analysis in progress Script commands Add commands to script: * Blocking hooks using Anti-Rootkit * Enable AVZGuard * BootCleaner - import list of deleted files * Registry cleanup after deleting files * BootCleaner - activate * Reboot * Insert template for QuarantineFile() - quarantining file * Insert template for BC_QrFile() - quarantining file via BootCleaner * Insert template for DeleteFile() - deleting file * Insert template for DelCLSID() - deleting CLSID item from registry Additional operations: * Performance tweaking: disable service RemoteRegistry (Registro remoto) * Performance tweaking: disable service TermService (Serviзos de terminal) * Performance tweaking: disable service SSDPSRV (Serviзo de descoberta SSDP) * Performance tweaking: disable service Schedule (Agendador de tarefas) * Performance tweaking: disable service mnmsrvc (Compartilhamento remoto da бrea de trabalho do NetMeeting) * Performance tweaking: disable service RDSessMgr (Gerenciador de sessгo de ajuda de бrea de trabalho remota) * Security tweaking: disable CD autorun * Security tweaking: disable administrative shares * Security tweaking: disable anonymous user access * Security: disable sending Remote Assistant queries File list Compartilhar este post Link para o post Compartilhar em outros sites
jgarcia 1 Denunciar post Postado Março 26, 2009 Opa samea, Desative o seu anti-vírus temporariamente. Execute um Scan Online com o Kasperky Virusscanner. * Clique em ; * Quando questionado sobre a instalação do ActiveX, clique sobre ; * Aguarde a instalação e a atualização. Depois clique em ; * Clique agora sobre ; * Nas opções do scan (settings), certifique-se de que as entradas abaixo estão selecionadas: Scan using the following Anti-Virus database:Extended (if available otherwise Standard).Scan Options:Scan Archives Scan Mail Bases * Clique em ; * Clique em My Computer para que seja feito um scan completo em seu sistema; * Será iniciado o scan e a varredura poderá demorar um pouco. Seja paciente e aguarde; * No final do scan, clique no botão Save as Text; * Salve o log com os resultados e cole o conteúdo em sua próxima mensagem. Abraços. Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Abril 27, 2009 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites