Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

samea

[Arquivado] "csrcs" não inicia!

Recommended Posts

Sempre que inicio o pc aparece uma mensagem avisando que o windows não pode encontrar o arquivo "csrcs.exe".

Já ouvi dizer que é um malware. O que devo fazer?

Aproveitando a oportunidade meu pc sempre desliga do nada e as vezes quando inicia aparece a mensagem

not boot failed e pede pra inserir o cd e dar o enter.

Desde já agradeço a ajuda. :cry:

Compartilhar este post


Link para o post
Compartilhar em outros sites

esse arquivo que voce se refere nao faz parte do sistema , ja o csrss ja eh problemativo , entao ...

 

para resolver voce deve ir em executar > regedit enter

 

ao abrir o regedit voce vai entrar na opcao editar > procurar enter

 

vai digita o nome do arquivo e enter

ele vai fazer uma pesquisa no registro e vai encontrar ele . voce pode exluir ele sem medo de ser feliz , logo apos a exclusao , presione F3 para dar continuidade na busca ..

ele deve encontrar novamente outro arquivo voce exlua tambem .. geralmente sao 2 arquivos , mas pode haver mais .. se a busca nao der como finalizada , continue presionando F3 e exluindo

todo arquivo q aparecer , pode ser q haja 3 , eu ja encontrei maquinas assim .. isso ira resolver seu problema .

Compartilhar este post


Link para o post
Compartilhar em outros sites

post um log conforme topico

 

http://forum.imasters.com.br/index.php?showtopic=165906

 

A exclusao diretamente do regedit pode nao ser o mais aconselhavel mas ai é sua escolha

 

Com o log pode ter uma ajuda mais direcionada se for caso de malware

Compartilhar este post


Link para o post
Compartilhar em outros sites
post um log conforme topico

 

http://forum.imasters.com.br/index.php?showtopic=165906

 

A exclusao diretamente do regedit pode nao ser o mais aconselhavel mas ai é sua escolha

 

Com o log pode ter uma ajuda mais direcionada se for caso de malware

 

Aqui estar! :unsure:

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 8:58:44, on 18/02/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.exe

C:\WINDOWS\system32\spoolsv.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\ctfmon.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\Arquivos de programas\Photodex\ProShowGold\ScsiAccess.exe

C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\HiJack\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com

R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://internetsearchservice.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

R3 - URLSearchHook: P2P Torrent Toolbar - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Arquivos de programas\P2P_Torrent\tbP2P_.dll

F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\Arquivos de programas\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL (file missing)

O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll

O2 - BHO: 734914 helper - {0BD071A6-C989-49E8-9B8E-80F92A868E26} - (no file)

O2 - BHO: BrowserCmp - {1D8282E6-BC4F-469B-AAED-7E4FF077AD93} - C:\WINDOWS\system32\iebrowserc.dll (file missing)

O2 - BHO: superiorads browser optimizer - {2910e755-0574-9ca1-c006-c1ddc75ac7ff} - C:\WINDOWS\system32\zhnybswtguncukti.dll (file missing)

O2 - BHO: ssh2 Class - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E} - (no file)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: P2P Torrent Toolbar - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Arquivos de programas\P2P_Torrent\tbP2P_.dll

O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehcef.dll

O2 - BHO: mysidesearch search enhancer - {D1AD53DC-8978-AAAE-31E0-11904F82C145} - C:\WINDOWS\system32\gkulgetcloezejx.dll (file missing)

O3 - Toolbar: P2P Torrent Toolbar - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Arquivos de programas\P2P_Torrent\tbP2P_.dll

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [mpeg heck log link] C:\Documents and Settings\All Users\Dados de aplicativos\Joy coal mpeg heck\win team.exe

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKCU\..\Run: [RegPowerClean] "C:\Arquivos de programas\Winferno\RegistryPowerCleaner\RegPowerClean.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bowsmove] C:\DOCUME~1\JOO~1\DADOSD~1\CREATI~1\Bolt Slow Dash.exe

O4 - HKCU\..\Run: [Torrent Finder] "C:\Arquivos de programas\Torrent Finder\Torrent-Finder.exe" hmw

O4 - HKCU\..\RunOnce: [shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322)" -"http://clickjogos.uol.com.br/Jogos-online/Esportes/Formula-1/"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game14.zylom.com/activex/zylomgamesplayer.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} (GbpDistObj Class) - https://imagem.caixa.gov.br/cab/gbpdist.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.atrativa.com.br/games/applets/p...opcaploader.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: aGbPlugin - C:\WINDOWS\system\GBPlugins.dll

O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehcef.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - c:\firebird\bin\fbguard.exe

O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - c:\firebird\bin\fbserver.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: NNServ - Unknown owner - C:\Arquivos de programas\NewDotNet\nnrun.exe (file missing)

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: ScsiAccess - Unknown owner - C:\Arquivos de programas\Photodex\ProShowGold\ScsiAccess.exe

O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Arquivos de programas\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

O24 - Desktop Component 0: (no name) - http://by111w.bay111.mail.live.com/att/Get...CA9B283FB06D20|

 

--

End of file - 11108 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites
post um log conforme topico

 

http://forum.imasters.com.br/index.php?showtopic=165906

 

A exclusao diretamente do regedit pode nao ser o mais aconselhavel mas ai é sua escolha

 

Com o log pode ter uma ajuda mais direcionada se for caso de malware

 

 

Mais uma coisinha, quando rodei o HiJack, a opção de não mostrar pastas e arquivos ocultos estava selecionada.

Isso atrapalha em algo? :blink:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa samea,

 

Baixe o ComboFix em:

ComboFix

 

1) Desabilite o seu anti-vírus temporariamente;

 

2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos);

 

3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Leia atentamente o texto contido nesta janela e clique sobre “SIM” para continuar.

 

PS.: Caso não concorde com os termos clique sobre “NÃO” para sair do software, cabendo lembrar que o processo de desinfecção não será possível sem a continuidade do ComboFix.

 

4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console ante de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura.

 

Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente.

 

Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA.

 

Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADA COM SUCESSO”.

 

Clique sobre “SIM” para continuar a varredura.

 

5) O ComboFix iniciará o AUTOSCAN (aguarde).

 

ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco).

 

Ao término do processo a máquina será reiniciada para a emissão do relatório.

 

6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log ficará alocado em C:\ComboFix.txt.

 

7) Reabilite o seu anti-vírus;

 

8) Preciso que você cole o conteúdo do ComboFix.txt em sua próxima resposta.

 

OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Em último caso, tente utilizar o ComboFix em MODO SEGURO.

 

OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Fiz tudo como você falou, mas ao começar a varredura(que não durou nem 30 seg.) meu pc reiniciou e apareceu uma mensagem da microsoft relatando que o windows teve um problema. E não encontrei o log do combofix.

E agora?

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa samea,

 

O Malwarebytes AntiMalware é um produto relativamente novo, porém com grande eficácia na remoção de infecções comuns. O programa é pequeno, gratuito e em português.

 

A sua instalação é o primeiro passo para a limpeza de um sistema operacional infectado.

 

Neste tutorial você aprenderá a instalá-lo e executá-lo.

 

1) Primeiramente faça o download do programa:

http://www.malwarebytes.org/mbam/program/mbam-setup.exe

 

2) Agora proceda a instalação do programa, conforme segue:

 

Execute o programa de instalação:

capturadatelaha4.png

 

Logo após a execução do arquivo de instalação, será exibida a seguinte tela:

capturadatela1zv8.png

 

Agora, clique em Instalar para concluir:

capturadatela6yd8.png

 

Ao término da instalação deixe marcadas as opções de Atualização e Execução:

capturadatela7cd6.png

 

Será exibida então a tela de atualização do programa:

capturadatela9en9.png

 

3) Essa é a tela inicial do programa. Marque a opção Verificação Completa e clique no botão Verificar.

capturadatela10vs1.png

 

Aguarde até o final da verificação:

capturadatela12zo1.png

 

Ao concluir a verificação, será exibida essa mensagem:

capturadatela13oi2.png

 

O resultado da verificação será exibido, com o nome dos arquivos e malwares encontrados.

Para efetivar a limpeza, clique em Remover selecionados:

capturadatela14qb8.png

 

Para concluir a limpeza haverá a necessidade da reinicialização do computador:

capturadatela15um2ed5.png

 

O programa guarda os logs das verificações feitas na pasta C:\Documents and Settings\Seu nome de Usuario\Dados de aplicativos\Malwarebytes\Malwarebytes' Anti-Malware\Logs, que também pode ser acessados na aba Logs, dentro do programa.

 

Retorne com o resultado da varredura.

 

Créditos: Fabio Assolini.

 

Link para a postagem original: aqui.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Fiz o Procedimento.

Já não aparece mais o a janela sobre o "csrcs"

Aqui esta o log:

 

Malwarebytes' Anti-Malware 1.34

Versão do banco de dados: 1828

Windows 5.1.2600 Service Pack 3

 

2009-03-09 05:51:47

mbam-log-2009-03-09 (05-51-47).txt

 

Tipo de Verificação: Completa (C:\|)

Objetos verificados: 220660

Tempo decorrido: 1 hour(s), 57 minute(s), 50 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 56

Valores do Registro infectados: 16

Ítens do Registro infectados: 13

Pastas infectadas: 10

Arquivos infectados: 22

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

HKEY_CLASSES_ROOT\iebrowsercmp.browsercmp (Adware.RightOnAds) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\iebrowsercmp.browsercmp.1 (Adware.RightOnAds) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{1601d447-7424-4866-8dcc-acf98a2a41e1} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{c1a6d8b8-93c3-4186-9dd1-13983f9f1d9b} (Adware.RightOnAds) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{ceb9c60d-f0ad-4b73-a3ab-4fc822e38d66} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836} (Trojan.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{ceb9c60d-f0ad-4b73-a3ab-4fc822e38d66} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb} (Trojan.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{c3c0ec2c-2c1c-495c-9ad0-1f0ef833d7b5} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{3160f356-e8c3-4de2-a698-92eeeb3d3400} (Adware.RightOnAds) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{43fc67b6-4c25-4afd-ae7a-9ef3e4587026} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.Antivirus2008) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6156a32a-c512-4e23-aa9a-2315f4265681} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0bd071a6-c989-49e8-9b8e-80f92a868e26} (Trojan.BHO) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7aa32fc7-133b-4ae7-998e-ced0d9829b12} (Trojan.Dialer) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fc3c36d-7635-4d43-ba62-0d9d2f2cd06e} (Adware.Fotomoto) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{79f562e5-768c-4494-8e6c-824ada4a9c2c} (Adware.SuperiorAds) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c17e102b-bd29-4e92-b699-1a21d2cb8e6c} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0bd071a6-c989-49e8-9b8e-80f92a868e26} (Trojan.BHO) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6fc3c36d-7635-4d43-ba62-0d9d2f2cd06e} (Adware.Fotomoto) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\AppID\Sidebar.DLL (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\MyWay (Adware.MyWay) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\AdvRemoteDbg (Adware.Agent) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dcadssocial (Adware.RightOnAds) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\e405.e405mgr (Trojan.Zlob) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\WUSN.1 (Adware.WhenUSave) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dcads (Adware.Dcads) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2910e755-0574-9ca1-c006-c1ddc75ac7ff} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{2910e755-0574-9ca1-c006-c1ddc75ac7ff} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d1ad53dc-8978-aaae-31e0-11904f82c145} (Adware.BHO) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{d1ad53dc-8978-aaae-31e0-11904f82c145} (Adware.BHO) -> Quarantined and deleted successfully.

 

Valores do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{bc4be15d-6a34-4356-9e97-79e43da32b1d} (Adware.Shopper) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\searchassistant (Trojan.Zlob) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\searchassistant (Trojan.Zlob) -> Delete on reboot.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\default_search_url (Trojan.Zlob) -> Delete on reboot.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl (Trojan.Zlob) -> Delete on reboot.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -> Delete on reboot.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\searchurl (Trojan.Zlob) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\default_search_url (Trojan.Zlob) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\search page (Trojan.Zlob) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\search bar (Trojan.Zlob) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl (Trojan.Zlob) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\searchurl (Trojan.Zlob) -> Delete on reboot.

 

Ítens do Registro infectados:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q=%s'>http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q=%s'>http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (http://internetsearchservice.com/ie6.html) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe csrcs.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.

 

Pastas infectadas:

C:\Arquivos de programas\MyWay (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\myBar (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\myBar\History (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\myBar\Settings (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\SrchAstt (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\SrchAstt\1.bin (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\SrchAstt\Cache (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\SrchAstt\Settings (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\NewDotNet (Adware.NewDotNet) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\734914 (Trojan.BHO) -> Quarantined and deleted successfully.

 

Arquivos infectados:

C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.

C:\Arquivos de programas\P2P_Torrent\tbP2P1.dll (Adware.Shopper) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\myss_sb_uninstall.exe (Adware.BHO) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\myBar\History\search (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\SrchAstt\1.bin\PARTNER.DAT (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\SrchAstt\Cache\004002F6 (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\SrchAstt\Cache\00400FF6 (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\SrchAstt\Cache\files.ini (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\MyWay\SrchAstt\Settings\prevcfg.htm (Adware.MyWay) -> Quarantined and deleted successfully.

C:\Arquivos de programas\NewDotNet\readme.html (Adware.NewDotNet) -> Quarantined and deleted successfully.

C:\WINDOWS\Downloaded Program Files\scpsssh2.inf (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\{273b9b6e-4f66-1694-2da2-48276ae4247b}.dll-uninst.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\{968ca23d-6ef5-c9a0-6a8d-9004e9867165}.dll-uninst.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe (Adware.BHO) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\superiorads-uninst.exe (Adware.BHO) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\DcadsSocial-uninstall.exe (Adware.RightOnAds) -> Quarantined and deleted successfully.

C:\Documents and Settings\João\Dados de aplicativos\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.

C:\WINDOWS\Fonts\blazed.zip (Worm.Archive) -> Quarantined and deleted successfully.

C:\WINDOWS\Fonts\candy.zip (Worm.Archive) -> Quarantined and deleted successfully.

C:\WINDOWS\Fonts\download.zip (Worm.Archive) -> Quarantined and deleted successfully.

C:\WINDOWS\Fonts\fiolex_girls.zip (Worm.Archive) -> Quarantined and deleted successfully.

C:\WINDOWS\Fonts\mamae_que_nos_faz.zip (Worm.Archive) -> Quarantined and deleted successfully.

 

:thumbsup: Obrigado!!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa samea,

 

1. Baixe o BankerFix 3.0.

 

2. Desative o seu anti-vírus temporariamente.

 

3. Dê um duplo-clique sobre o bankerfix.exe. A janela do Banker Fix 3.0 abrir-se-á com a seguinte pergunta Instalar o BankerFix 3.0 / Install BankerFix 3.0 ? >> clique em SIM.

 

4. Uma janela informando que o BankerFix 3.0 será baixado via internet abrir-se-á >> clique sobre OK e aguarde. Na próxima janela clique em OK mais uma vez, a fim de que o BankerFix 3.0 seja iniciado.

 

5. Pressione qualquer tecla para dar continuidade ao processo e aguarde até que a varredura se complete. Tenha paciência, pois ela pode demorar alguns minutos.

 

6. Terminado o scan, leia a mensagem na tela e aperte Enter.

 

7. Habilite o seu anti-vírus.

 

8. Retorne com o relatorio.txt do BankerFix (ele estará em C:\LinhaDefensiva\).

 

9. Depois de postar a sua resposta você poderá deletar a pasta LinhaDefensiva contida no C.

 

Abraços.

 

PS.: Caso apareça a seguinte mensagem: Site denunciado como foco de ataques!, não se preocupe e clique sobre Ignorar este alerta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

BankerFix 3.0 VALKYRIE

Linha Defensiva | http://www.linhadefensiva.org

http://www.linhadefensiva.org/bankerfix/

-------------------------------------------------------

Data: 2009-03-19 - 23:05

=======================================================

 

C:\WINDOWS\system\GBPlugins.dll: Arquivo infectado removido com sucesso!

 

----- Fim -------------------------

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa samea,

 

1. Baixe o Kaspersky Virus Removal Tool.

 

2. O arquivo possui aproximadamente 35 Mb, mas o resultado compensará o trabalho.

 

3. Reinicie a máquina em Modo Seguro.

 

4. Execute a ferramenta dando duplo-clique sobre o arquivo baixado.

 

5. Abrir-se-á a seguinte janela:

Kaspersky-Virus-Removal-Tool_1.png

 

6. Marque os diretórios que deseja varrer (é melhor marcar todos).

 

7. Clique em Scan e aguarde o término do processo.

 

8. Terminada a varredura, retorne com o resultado.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites
Opa samea,

 

1. Baixe o Kaspersky Virus Removal Tool.

 

2. O arquivo possui aproximadamente 35 Mb, mas o resultado compensará o trabalho.

 

3. Reinicie a máquina em Modo Seguro.

 

4. Execute a ferramenta dando duplo-clique sobre o arquivo baixado.

 

5. Abrir-se-á a seguinte janela:

Kaspersky-Virus-Removal-Tool_1.png

 

6. Marque os diretórios que deseja varrer (é melhor marcar todos).

 

7. Clique em Scan e aguarde o término do processo.

 

8. Terminada a varredura, retorne com o resultado.

 

Abraços.

 

Rodei o programa, mas só achei esse resultado num arquivo XML seria esse?

 

<?xml version="1.0" encoding="windows-1251" ?>

- <!-- AVZ XML Report

-->

- <AVZ>

- <PROCESS>

<ITEM PID="932" File="c:\windows\explorer.exe" CheckResult="0" Descr="Windows Explorer" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Hidden="-1" CmdLine="C:\WINDOWS\Explorer.EXE" Size="1035776" Attr="rsAh" CreateDate="2004-08-04 00:45:34" ChageDate="2008-04-13 23:20:58" MD5="064EC7FF5F58B928C3E119402977FA6D" />

<ITEM PID="2044" File="c:\arquivos de programas\mozilla firefox\firefox.exe" CheckResult="-1" Descr="Firefox" LegalCopyright="©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable." CmdLine="" Size="307704" Attr="rsAh" CreateDate="2009-02-09 14:22:52" ChageDate="2009-03-06 22:30:07" MD5="762D1D11BB4E7C8D238D957E5AB60D0E" />

<ITEM PID="1556" File="c:\documents and settings\joгo\desktop\virus removal tool\is-rmfni\is-rmfni.exe" CheckResult="0" Descr="Kaspersky Anti-Virus" LegalCopyright="Copyright © Kaspersky Lab 1996-2007." Hidden="-1" CmdLine=""C:\Documents and Settings\Joгo\Desktop\Virus Removal Tool\is-RMFNI\is-RMFNI.exe"" Size="217088" Attr="rsAh" CreateDate="2009-03-22 15:00:26" ChageDate="2008-11-12 13:32:32" MD5="C408C0C4420A021A964D9888DD1183D4" NationalName="Y" />

<ITEM PID="376" File="c:\windows\system32\lsass.exe" CheckResult="0" Descr="LSA Shell (Export Version)" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="-1" CmdLine="C:\WINDOWS\system32\lsass.exe" Size="13312" Attr="rsAh" CreateDate="2004-08-04 00:45:36" ChageDate="2008-04-13 23:21:05" MD5="9607142710D3B64AB7FCCE4BE4E30D37" />

<ITEM PID="532" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="-1" CmdLine="C:\WINDOWS\system32\svchost -k DcomLaunch" Size="14336" Attr="rsAh" CreateDate="2004-08-04 00:45:44" ChageDate="2008-04-13 23:21:20" MD5="ED2D69CD4B0EBE37EFE11D4DC4ABC68F" />

<ITEM PID="596" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="-1" CmdLine="C:\WINDOWS\system32\svchost -k rpcss" Size="14336" Attr="rsAh" CreateDate="2004-08-04 00:45:44" ChageDate="2008-04-13 23:21:20" MD5="ED2D69CD4B0EBE37EFE11D4DC4ABC68F" />

<ITEM PID="640" File="c:\windows\system32\svchost.exe" CheckResult="0" Descr="Generic Host Process for Win32 Services" LegalCopyright="© Microsoft Corporation. All rights reserved." Hidden="-1" CmdLine="C:\WINDOWS\system32\svchost.exe -k netsvcs" Size="14336" Attr="rsAh" CreateDate="2004-08-04 00:45:44" ChageDate="2008-04-13 23:21:20" MD5="ED2D69CD4B0EBE37EFE11D4DC4ABC68F" />

<ITEM PID="320" File="c:\windows\system32\winlogon.exe" CheckResult="0" Descr="Aplicativo de logon do Windows NT" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Hidden="-1" CmdLine="winlogon.exe" Size="509952" Attr="rsAh" CreateDate="2004-08-04 00:45:46" ChageDate="2008-04-13 23:21:23" MD5="71D440F79B711627B12B567FB2EADB42" />

</PROCESS>

- <DLL>

<ITEM File="C:\WINDOWS\system32\serwvdrv.dll" CheckResult="-1" Descr="Driver Unimodem Serial Wave" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." UsedBy="932,1556,376,532,596,640,320" Hidden="-1" Size="14848" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="7BAE7061357C489E3C41314A1EC85B3B" />

<ITEM File="C:\WINDOWS\system32\umdmxfrm.dll" CheckResult="-1" Descr="Unimodem Tranform Module" LegalCopyright="© Microsoft Corporation. All rights reserved." UsedBy="932,1556,376,532,596,640,320" Hidden="-1" Size="13312" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="6EBC082A88B651640EB1526D7267FD26" />

<ITEM File="C:\Arquivos de programas\GbPlugin\gbiehcef.dll" CheckResult="-1" Descr="Gbieh Module" LegalCopyright="Copyright © 2003-2009, Caixa Economica Federal" UsedBy="932,320" Hidden="-1" Size="404032" Attr="rsAh" CreateDate="2008-12-30 12:39:03" ChageDate="2009-01-27 13:40:04" MD5="342503A85A961384A705725B2D97B123" />

<ITEM File="C:\Arquivos de programas\Scpad\scpLIB.dll" CheckResult="-1" Descr="scpIBLoad Module" LegalCopyright="Copyright 2005" UsedBy="932" Hidden="-1" Size="128512" Attr="rsah" CreateDate="2007-07-06 10:47:06" ChageDate="2007-03-27 01:29:08" MD5="5345D0E15C89EBE3FD3E1A2881345BA6" />

<ITEM File="C:\Arquivos de programas\Scpad\scpMIB.dll" CheckResult="-1" Descr="scpMIB Module" LegalCopyright="Copyright 2005" UsedBy="932" Hidden="-1" Size="256512" Attr="rsAh" CreateDate="2007-07-06 10:47:03" ChageDate="2007-03-27 16:47:04" MD5="20E3FBD9BF10C2C05995E106CF059000" />

<ITEM File="C:\Arquivos de programas\Scpad\sshib.dll" CheckResult="-1" Descr="sshib" LegalCopyright="Copyright © 2004" UsedBy="932" Hidden="-1" Size="19968" Attr="rsah" CreateDate="2007-07-06 10:47:06" ChageDate="2007-03-27 01:27:18" MD5="CB0AA677738A57D157B5D82FD76340C6" />

<ITEM File="C:\WINDOWS\system32\msacm32.drv" CheckResult="-1" Descr="Mapeador de som da Microsoft" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." UsedBy="932,1556,320" Hidden="-1" Size="20992" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="CF2BAE9C79C39E012605647A485C1320" />

<ITEM File="C:\WINDOWS\system32\msg711.acm" CheckResult="-1" Descr="CODEC Microsoft CCITT G.711 (A-Law e u-Law) para MSACM" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." UsedBy="932,1556,320" Hidden="-1" Size="9216" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="FD77D822F8D8F93C3C7CDD190CE76F96" />

<ITEM File="C:\WINDOWS\system32\msgsm32.acm" CheckResult="-1" Descr="CODEC de бudio Microsoft GSM 6.10 para MSACM" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." UsedBy="932,1556,320" Hidden="-1" Size="19968" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="6109521768E6E2E7F6C246C2D8E911DF" />

<ITEM File="C:\WINDOWS\system32\tssoft32.acm" CheckResult="-1" Descr="Codec de бudio DSP Group TrueSpeech para MSACM V3.50" LegalCopyright="Copyright DSP Group, Inc. 1993-1996" UsedBy="932,1556,320" Hidden="-1" Size="8192" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="F2AD69138348EAD46DEE28B0543C0977" />

<ITEM File="C:\WINDOWS\system32\tsd32.dll" CheckResult="-1" Descr="" LegalCopyright="" UsedBy="932,1556,320" Hidden="-1" Size="15360" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="56AD8DBD8CECCDE394B235527E8B04D9" />

<ITEM File="C:\WINDOWS\system32\msg723.acm" CheckResult="-1" Descr="Microsoft G.723.1 CODEC para MSACM" LegalCopyright="Copyright © Intel Corp. e Microsoft Corporation 1995-1999" UsedBy="932,1556,320" Hidden="-1" Size="118784" Attr="rsAh" CreateDate="2007-06-02 14:08:27" ChageDate="1782-01-19 00:14:07" MD5="4D25497C7108F3CD024412E295B41027" />

<ITEM File="C:\WINDOWS\system32\sirenacm.dll" CheckResult="-1" Descr="Messenger Audio Codec" LegalCopyright="Copyright © 1997 - 2006 Microsoft Corporation" UsedBy="932,1556,320" Hidden="-1" Size="51224" Attr="rsAh" CreateDate="2007-10-18 11:31:46" ChageDate="2007-10-18 11:31:46" MD5="69D044C73A1BA2485A017DBBB037C1A0" />

<ITEM File="C:\WINDOWS\system32\scg726.acm" CheckResult="-1" Descr="SHARP G.726 ACM Audio Decoder" LegalCopyright="Copyright © 2000 SHARP Corporation" UsedBy="932,1556,320" Hidden="-1" Size="13239" Attr="rsAh" CreateDate="2008-10-22 14:30:14" ChageDate="2000-03-14 19:55:44" MD5="DC4B2F21968AC6E7E6C8A4417ED0D85C" />

<ITEM File="C:\WINDOWS\system32\alf2cd.acm" CheckResult="-1" Descr="NCT ALF2CD Audio CODEC" LegalCopyright="NCT Company Copyright 1999 - 2001" UsedBy="932,1556,320" Hidden="-1" Size="38912" Attr="rsAh" CreateDate="2008-10-22 14:30:14" ChageDate="2003-05-21 22:50:36" MD5="8210141840CE237FBF40B6E26E2DD11D" />

<ITEM File="C:\WINDOWS\system32\avgrsstx.dll" CheckResult="-1" Descr="AVG Resident Shield Starter" LegalCopyright="Copyright © 2008 AVG Technologies CZ, s.r.o." UsedBy="320" Hidden="-1" Size="10520" Attr="rsAh" CreateDate="2009-02-02 14:24:16" ChageDate="2009-02-02 14:24:16" MD5="0AC7886F80734680E3463780CEDEA4A4" />

<ITEM File="C:\WINDOWS\system32\WgaLogon.dll" CheckResult="-1" Descr="Notificaзхes do Programa de Vantagens do Windows Original" LegalCopyright="© 1995-2008 Microsoft Corporation" UsedBy="320" Hidden="-1" Size="267304" Attr="rsAh" CreateDate="2007-03-15 18:16:56" ChageDate="2008-09-05 22:31:14" MD5="7C89FD192C0D83F0C0F88152411DA12A" />

</DLL>

- <KERNELOBJ>

<ITEM File="C:\WINDOWS\System32\Drivers\aex3mvvn.SYS" CheckResult="-1" Base="F9159000" MemSize="066000" Descr="" LegalCopyright="" />

<ITEM File="dmload.sys" CheckResult="-1" Base="F9A93000" MemSize="002000" Descr="" LegalCopyright="" />

<ITEM File="C:\WINDOWS\System32\Drivers\dump_atapi.sys" CheckResult="-1" Base="F8FEA000" MemSize="018000" Descr="" LegalCopyright="" />

<ITEM File="C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS" CheckResult="-1" Base="F9AC1000" MemSize="002000" Descr="" LegalCopyright="" />

<ITEM File="C:\WINDOWS\System32\Drivers\ElbyDelay.sys" CheckResult="-1" Base="F9A99000" MemSize="002000" Descr="Elby Delay Lower Filter Driver" LegalCopyright="Copyright © 2003 - 2006 Elaborate Bytes AG" Size="11984" Attr="rsAh" CreateDate="2007-02-15 21:56:49" ChageDate="2007-02-15 21:56:49" MD5="E205C313417DA6FA7AFE85912A310A65" />

<ITEM File="ftdisk.sys" CheckResult="-1" Base="F940C000" MemSize="01F000" Descr="" LegalCopyright="" />

<ITEM File="C:\WINDOWS\system32\Drivers\GbpKm.sys" CheckResult="-1" Base="F9825000" MemSize="007000" Descr="GbPlugin Device Driver" LegalCopyright="® GAS Tecnologia" Size="31296" Attr="rsAh" CreateDate="2008-12-30 12:39:20" ChageDate="2009-01-27 13:51:02" MD5="BB38AF368934928174751C156CBDD7D1" />

<ITEM File="PCIIde.sys" CheckResult="-1" Base="F9B55000" MemSize="001000" Descr="" LegalCopyright="" />

<ITEM File="C:\WINDOWS\system32\Drivers\sptd.sys" CheckResult="-1" Base="F9482000" MemSize="0EA000" Descr="" LegalCopyright="" Size="685816" Attr="rsAh" CreateDate="2007-06-29 16:51:28" ChageDate="2007-07-02 14:31:34" MD5="" />

</KERNELOBJ>

- <Service>

<ITEM File="C:\Arquivos de programas\Ares\chatServer.exe" Name="AresChatServer" CheckResult="-1" Type="272" State="1" Size="263168" Attr="rsAh" CreateDate="2007-03-19 22:19:14" ChageDate="2007-03-19 22:19:14" MD5="D0C8B41A2690CD3B57783C759B3B72D5" />

<ITEM File="C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe" Name="avg8wd" CheckResult="-1" Type="16" State="1" Size="298264" Attr="rsAh" CreateDate="2009-02-02 14:23:41" ChageDate="2009-02-02 14:23:41" MD5="C661B44D8E12EA95F51BAF2AEFF6364B" />

<ITEM File="C:\ARQUIV~1\GbPlugin\GbpSv.exe" Name="GbpSv" CheckResult="-1" Type="16" State="1" Size="52808" Attr="rsAh" CreateDate="2008-12-30 12:39:18" ChageDate="2009-01-27 13:35:44" MD5="A8C529C4D66687C255AC33867B8989F3" />

<ITEM File="C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe" Name="NMIndexingService" CheckResult="-1" Type="16" State="1" Size="447784" Attr="rsAh" CreateDate="2007-12-13 18:10:56" ChageDate="2007-12-13 18:10:56" MD5="74149BCF0307BB76D68C0F8912DF731C" />

<ITEM File="C:\Arquivos de programas\NewDotNet\nnrun.exe" Name="NNServ" CheckResult="-1" Type="16" State="1" />

<ITEM File="C:\WINDOWS\system32\HPZipm12.exe" Name="Pml Driver HPZ12" CheckResult="-1" Type="16" State="1" Size="73728" Attr="rsAh" CreateDate="2007-06-07 20:23:54" ChageDate="2007-08-09 04:27:52" MD5="2D091A99624FB9E7EEF0A86D872EC0C3" />

<ITEM File="C:\WINDOWS\system32\rsvp.exe" Name="RSVP" CheckResult="-1" Type="16" State="1" Size="132608" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="669B392EB438238E76AB120E02FB48E5" />

</Service>

- <Drivers>

<ITEM File="Beep.sys" Name="Beep" CheckResult="-1" Type="1" State="4" />

<ITEM File="C:\WINDOWS\system32\Drivers\ElbyDelay.sys" Name="ElbyDelay" CheckResult="-1" Type="1" State="4" Size="11984" Attr="rsAh" CreateDate="2007-02-15 21:56:49" ChageDate="2007-02-15 21:56:49" MD5="E205C313417DA6FA7AFE85912A310A65" />

<ITEM File="C:\WINDOWS\system32\DRIVERS\ftdisk.sys" Name="Ftdisk" CheckResult="-1" Type="1" State="4" Size="125824" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="D24D7839D594B255E1C298245B7BA6A2" />

<ITEM File="C:\WINDOWS\system32\drivers\GbpKm.sys" Name="GbpKm" CheckResult="-1" Type="1" State="4" Size="31296" Attr="rsAh" CreateDate="2008-12-30 12:39:20" ChageDate="2009-01-27 13:51:02" MD5="BB38AF368934928174751C156CBDD7D1" />

<ITEM File="Null.sys" Name="Null" CheckResult="-1" Type="1" State="4" />

<ITEM File="PCIIde.sys" Name="PCIIde" CheckResult="-1" Type="1" State="4" />

<ITEM File="C:\WINDOWS\System32\Drivers\sptd.sys" Name="sptd" CheckResult="-1" Type="1" State="4" Size="685816" Attr="rsAh" CreateDate="2007-06-29 16:51:28" ChageDate="2007-07-02 14:31:34" MD5="" />

<ITEM File="Abiosdsk.sys" Name="Abiosdsk" CheckResult="-1" Type="1" State="1" />

<ITEM File="abp480n5.sys" Name="abp480n5" CheckResult="-1" Type="1" State="1" />

<ITEM File="ACPIEC.sys" Name="ACPIEC" CheckResult="-1" Type="1" State="1" />

<ITEM File="adpu160m.sys" Name="adpu160m" CheckResult="-1" Type="1" State="1" />

<ITEM File="Aha154x.sys" Name="Aha154x" CheckResult="-1" Type="1" State="1" />

<ITEM File="aic78u2.sys" Name="aic78u2" CheckResult="-1" Type="1" State="1" />

<ITEM File="aic78xx.sys" Name="aic78xx" CheckResult="-1" Type="1" State="1" />

<ITEM File="AliIde.sys" Name="AliIde" CheckResult="-1" Type="1" State="1" />

<ITEM File="amsint.sys" Name="amsint" CheckResult="-1" Type="1" State="1" />

<ITEM File="asc.sys" Name="asc" CheckResult="-1" Type="1" State="1" />

<ITEM File="asc3350p.sys" Name="asc3350p" CheckResult="-1" Type="1" State="1" />

<ITEM File="asc3550.sys" Name="asc3550" CheckResult="-1" Type="1" State="1" />

<ITEM File="Atdisk.sys" Name="Atdisk" CheckResult="-1" Type="1" State="1" />

<ITEM File="C:\WINDOWS\System32\Drivers\avgldx86.sys" Name="AvgLdx86" CheckResult="-1" Type="1" State="1" Size="325128" Attr="rsAh" CreateDate="2009-02-02 14:24:06" ChageDate="2009-02-02 14:24:06" MD5="96E8AA914DAE8AB817DE504A7E75B5A5" />

<ITEM File="C:\WINDOWS\System32\Drivers\avgmfx86.sys" Name="AvgMfx86" CheckResult="-1" Type="2" State="1" Size="27656" Attr="rsAh" CreateDate="2009-02-02 14:24:05" ChageDate="2009-02-02 14:24:05" MD5="97A381475F5215C22931841A174F8E8D" />

<ITEM File="C:\WINDOWS\System32\Drivers\avgtdix.sys" Name="AvgTdiX" CheckResult="-1" Type="1" State="1" Size="107272" Attr="rsAh" CreateDate="2009-02-02 14:24:14" ChageDate="2009-02-02 14:24:14" MD5="F35C173DFD596DD3140506B5670ECDF5" />

<ITEM File="cbidf2k.sys" Name="cbidf2k" CheckResult="-1" Type="1" State="1" />

<ITEM File="cd20xrnt.sys" Name="cd20xrnt" CheckResult="-1" Type="1" State="1" />

<ITEM File="Cdaudio.sys" Name="Cdaudio" CheckResult="-1" Type="1" State="1" />

<ITEM File="Changer.sys" Name="Changer" CheckResult="-1" Type="1" State="1" />

<ITEM File="CmdIde.sys" Name="CmdIde" CheckResult="-1" Type="1" State="1" />

<ITEM File="Cpqarray.sys" Name="Cpqarray" CheckResult="-1" Type="1" State="1" />

<ITEM File="dac960nt.sys" Name="dac960nt" CheckResult="-1" Type="1" State="1" />

<ITEM File="dpti2o.sys" Name="dpti2o" CheckResult="-1" Type="1" State="1" />

<ITEM File="C:\Documents and Settings\Joгo\Desktop\Grand Chase\GameGuard\dump_wmimmc.sys" Name="dump_wmimmc" CheckResult="-1" Type="1" State="1" NationalName="Y" />

<ITEM File="C:\WINDOWS\system32\Drivers\ElbyCDIO.sys" Name="ElbyCDIO" CheckResult="-1" Type="1" State="1" Size="25160" Attr="rsAh" CreateDate="2007-08-07 16:48:33" ChageDate="2007-08-07 16:48:33" MD5="AAA8999A169E39FB8B48AE49CD6AC30A" />

<ITEM File="hpn.sys" Name="hpn" CheckResult="-1" Type="1" State="1" />

<ITEM File="i2omgmt.sys" Name="i2omgmt" CheckResult="-1" Type="1" State="1" />

<ITEM File="i2omp.sys" Name="i2omp" CheckResult="-1" Type="1" State="1" />

<ITEM File="ini910u.sys" Name="ini910u" CheckResult="-1" Type="1" State="1" />

<ITEM File="lbrtfdc.sys" Name="lbrtfdc" CheckResult="-1" Type="1" State="1" />

<ITEM File="mnmdd.sys" Name="mnmdd" CheckResult="-1" Type="1" State="1" />

<ITEM File="mraid35x.sys" Name="mraid35x" CheckResult="-1" Type="1" State="1" />

<ITEM File="ParVdm.sys" Name="ParVdm" CheckResult="-1" Type="1" State="1" />

<ITEM File="PCIDump.sys" Name="PCIDump" CheckResult="-1" Type="1" State="1" />

<ITEM File="PDCOMP.sys" Name="PDCOMP" CheckResult="-1" Type="1" State="1" />

<ITEM File="PDFRAME.sys" Name="PDFRAME" CheckResult="-1" Type="1" State="1" />

<ITEM File="PDRELI.sys" Name="PDRELI" CheckResult="-1" Type="1" State="1" />

<ITEM File="PDRFRAME.sys" Name="PDRFRAME" CheckResult="-1" Type="1" State="1" />

<ITEM File="perc2.sys" Name="perc2" CheckResult="-1" Type="1" State="1" />

<ITEM File="perc2hib.sys" Name="perc2hib" CheckResult="-1" Type="1" State="1" />

<ITEM File="C:\WINDOWS\system32\DRIVERS\CoachUsb.sys" Name="ProCam Usb" CheckResult="-1" Type="1" State="1" Size="46944" Attr="RsAh" CreateDate="2007-06-04 21:10:42" ChageDate="2003-11-14 03:14:10" MD5="62B20BED4F2804C1CEF8553CC654DA94" />

<ITEM File="ql1080.sys" Name="ql1080" CheckResult="-1" Type="1" State="1" />

<ITEM File="Ql10wnt.sys" Name="Ql10wnt" CheckResult="-1" Type="1" State="1" />

<ITEM File="ql12160.sys" Name="ql12160" CheckResult="-1" Type="1" State="1" />

<ITEM File="ql1240.sys" Name="ql1240" CheckResult="-1" Type="1" State="1" />

<ITEM File="ql1280.sys" Name="ql1280" CheckResult="-1" Type="1" State="1" />

<ITEM File="Simbad.sys" Name="Simbad" CheckResult="-1" Type="1" State="1" />

<ITEM File="Sparrow.sys" Name="Sparrow" CheckResult="-1" Type="1" State="1" />

<ITEM File="sym_hi.sys" Name="sym_hi" CheckResult="-1" Type="1" State="1" />

<ITEM File="sym_u3.sys" Name="sym_u3" CheckResult="-1" Type="1" State="1" />

<ITEM File="symc810.sys" Name="symc810" CheckResult="-1" Type="1" State="1" />

<ITEM File="symc8xx.sys" Name="symc8xx" CheckResult="-1" Type="1" State="1" />

<ITEM File="TosIde.sys" Name="TosIde" CheckResult="-1" Type="1" State="1" />

<ITEM File="ultra.sys" Name="ultra" CheckResult="-1" Type="1" State="1" />

<ITEM File="ViaIde.sys" Name="ViaIde" CheckResult="-1" Type="1" State="1" />

<ITEM File="WDICA.sys" Name="WDICA" CheckResult="-1" Type="1" State="1" />

</Drivers>

- <AUTORUN>

<ITEM File="" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Narrator" X3="Application path" />

<ITEM File="C:\ARQUIV~1\AVG\AVG8\avgtray.exe" CheckResult="-1" Enabled="1" Type="REG" Size="1601304" Attr="rsAh" CreateDate="2009-02-02 14:23:43" ChageDate="2009-02-02 14:23:45" MD5="1FC8B35E97123A9DF64F092DA8784E4C" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="AVG8_TRAY" />

<ITEM File="C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_USERS" X2="S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run" X3="BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" />

<ITEM File="C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe" CheckResult="-1" Enabled="1" Type="LNK" Size="210520" Attr="rsAh" CreateDate="2007-03-11 20:26:24" ChageDate="2007-03-11 20:26:24" MD5="F14219FC767F1383526AB423F278A8E3" X1="C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\" X2="C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\HP Digital Imaging Monitor.lnk" X3="" />

<ITEM File="C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" CheckResult="-1" Enabled="1" Type="REG" Size="49152" Attr="rsAh" CreateDate="2007-03-11 20:34:40" ChageDate="2007-03-11 20:34:40" MD5="7AF5A466CF4AECA28E3DCBCF5B6FD220" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="HP Software Update" />

<ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe" CheckResult="-1" Enabled="1" Type="REG" Size="144784" Attr="rsAh" CreateDate="2008-10-19 15:54:18" ChageDate="2008-06-10 03:27:04" MD5="6AB4C021FBD36DC6764924C312428D97" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="SunJavaUpdateSched" />

<ITEM File="C:\Arquivos de programas\Scpad\scpLIB.dll" CheckResult="-1" Enabled="1" Type="REG" Size="128512" Attr="rsah" CreateDate="2007-07-06 10:47:06" ChageDate="2007-03-27 01:29:08" MD5="5345D0E15C89EBE3FD3E1A2881345BA6" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler" X3="{A3717295-941D-416F-9384-ED1736729F1C}" />

<ITEM File="C:\Arquivos de programas\Scpad\scpLIB.dll" CheckResult="-1" Enabled="1" Type="REG" Size="128512" Attr="rsah" CreateDate="2007-07-06 10:47:06" ChageDate="2007-03-27 01:29:08" MD5="5345D0E15C89EBE3FD3E1A2881345BA6" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad" X3="CompIBBrd" />

<ITEM File="C:\Arquivos de programas\Torrent Finder\Torrent-Finder.exe" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_USERS" X2="S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run" X3="Torrent Finder" />

<ITEM File="C:\Arquivos de programas\Winferno\RegistryPowerCleaner\RegPowerClean.exe" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_USERS" X2="S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run" X3="RegPowerClean" />

<ITEM File="C:\DOCUME~1\JOO~1\DADOSD~1\CREATI~1\Bolt Slow Dash.exe" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_USERS" X2="S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run" X3="bowsmove" />

<ITEM File="C:\Documents and Settings\All Users\Dados de aplicativos\Joy coal mpeg heck\win team.exe" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="Software\Microsoft\Windows\CurrentVersion\Run" X3="mpeg heck log link" />

<ITEM File="C:\WINDOWS\system32\dfrg.msc %c:" CheckResult="-1" Enabled="-1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath" X3="" />

<ITEM File="C:\WINDOWS\system\GBPlugins.dll" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ aGbPlugin" X3="DLLName" />

<ITEM File="WgaLogon.dll" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon" X3="DLLName" />

<ITEM File="avgrsstx.dll" CheckResult="-1" Enabled="1" Type="REG" X1="HKEY_LOCAL_MACHINE" X2="SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter" X3="DLLName" />

</AUTORUN>

- <BHO>

<ITEM File="C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{0347C33E-8762-4905-BF09-768834316C61}" Descr="hpswp_printenhancer dll" LegalCopyright="HP. All rights reserved." Size="1298024" Attr="RsAh" CreateDate="2007-03-02 15:52:24" ChageDate="2007-03-02 15:52:24" MD5="1062E80907867BFC14EB844241391331" />

<ITEM File="C:\Arquivos de programas\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{04079851-5845-4dea-848C-3ECD647AA554}" Descr="" LegalCopyright="" />

<ITEM File="C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{053F9267-DC04-4294-A72C-58F732D338C0}" Descr="Leo (Framework) - add-on for Internet Explorer" LegalCopyright="Copyright © Hewlett-Packard Co. 1995-2006" Size="177768" Attr="RsAh" CreateDate="2007-03-02 15:52:08" ChageDate="2007-03-02 15:52:08" MD5="A40456DE4EF7E318104955361C72AC9D" />

<ITEM File="C:\Arquivos de programas\Scpad\scpsssh2.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{2E3C3651-B19C-4DD9-A979-901EC3E930AF}" Descr="scpsssh2 Module" LegalCopyright="Copyright 2001" Size="124416" Attr="rsah" CreateDate="2007-07-06 12:56:05" ChageDate="2007-03-27 01:28:16" MD5="59D8245EA3128BAF96DF6C3A1F4DA435" />

<ITEM File="C:\Arquivos de programas\AVG\AVG8\avgssie.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" Descr="Safe Search for Internet Explorer" LegalCopyright="Copyright © 2008 AVG Technologies CZ, s.r.o." Size="1078552" Attr="rsAh" CreateDate="2009-02-02 14:23:52" ChageDate="2009-02-02 14:23:53" MD5="2225E1B951EC0E3209D11C167F96D834" />

<ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" />

<ITEM File="" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{7E853D72-626A-48EC-A868-BA8D5E23E045}" Descr="" LegalCopyright="" />

<ITEM File="C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{9030D464-4C02-4ABF-8ECC-5164760863C6}" Descr="WindowsLiveLogin.dll" LegalCopyright="Copyright © 1995-2006 Microsoft Corporation." Size="408440" Attr="rsAh" CreateDate="2009-02-17 16:11:04" ChageDate="2009-02-17 16:11:04" MD5="1A82C1B9BB43385695EFC3A84F6756A2" />

<ITEM File="C:\Arquivos de programas\GbPlugin\gbiehcef.dll" CheckResult="-1" Enabled="1" BHOType="1" RegKey="Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" CLSID="{C41A1C0E-EA6C-11D4-B1B8-444553540003}" Descr="Gbieh Module" LegalCopyright="Copyright © 2003-2009, Caixa Economica Federal" Size="404032" Attr="rsAh" CreateDate="2008-12-30 12:39:03" ChageDate="2009-01-27 13:40:04" MD5="342503A85A961384A705725B2D97B123" />

<ITEM File="" CheckResult="-1" Enabled="1" BHOType="3" RegKey="Software\Microsoft\Internet Explorer\Extensions" CLSID="{58ECB495-38F0-49cb-A538-10282ABF65E7}" Descr="" LegalCopyright="" />

<ITEM File="" CheckResult="-1" Enabled="1" BHOType="3" RegKey="Software\Microsoft\Internet Explorer\Extensions" CLSID="{700259D7-1666-479a-93B1-3250410481E8}" Descr="" LegalCopyright="" />

</BHO>

- <ExplorerExt>

<ITEM File="icmui.dll" CheckResult="-1" Enabled="1" ExtName="Gerenciamento de scanner ICM" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{176d6597-26d3-11d1-b350-080036a75b03}" Descr="DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." />

<ITEM File="docprop.dll" CheckResult="-1" Enabled="1" ExtName="Pбgina de propriedades do arquivo de documento OLE" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{3EA48300-8CF6-101B-84FB-666CCB9BCD32}" Descr="Pбgina de propriedades do arquivo de documento OLE" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." />

<ITEM File="deskadp.dll" CheckResult="-1" Enabled="1" ExtName="Extensгo do 'Painel de controle' para adaptador de vнdeo" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{42071712-76d4-11d1-8b24-00a0c9068ff3}" Descr="Propriedades avanзadas de adaptador de vнdeo" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." />

<ITEM File="deskmon.dll" CheckResult="-1" Enabled="1" ExtName="Extensгo do 'Painel de controle' para monitor de vнdeo" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{42071713-76d4-11d1-8b24-00a0c9068ff3}" Descr="Propriedades avanзadas de monitor" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." />

<ITEM File="" CheckResult="-1" Enabled="1" ExtName="Extensгo do 'Painel de controle' para panorвmica de vнdeo" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{42071714-76d4-11d1-8b24-00a0c9068ff3}" Descr="" LegalCopyright="" />

<ITEM File="ntlanui2.dll" CheckResult="-1" Enabled="1" ExtName="Extensхes do shell para objetos Microsoft Windows Network" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{59be4990-f85c-11ce-aff7-00aa003ca9f6}" Descr="Objeto de rede do shell da interface de usuбrio" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." />

<ITEM File="C:\WINDOWS\System32\icmui.dll" CheckResult="-1" Enabled="1" ExtName="Gerenciamento de monitor ICM" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{5DB2625A-54DF-11D0-B6C4-0800091AA605}" Descr="DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="55808" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="71B1979A285B2A0FACFE2A01231FE4DB" />

<ITEM File="C:\WINDOWS\system32\icmui.dll" CheckResult="-1" Enabled="1" ExtName="Gerenciamento de impressora ICM" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{675F097E-4C4D-11D0-B6C1-0800091AA605}" Descr="DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="55808" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="71B1979A285B2A0FACFE2A01231FE4DB" />

<ITEM File="" CheckResult="-1" Enabled="1" ExtName="Extensхes do shell para compactaзгo de arquivos" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{764BF0E1-F219-11ce-972D-00AA00A14F56}" Descr="" LegalCopyright="" />

<ITEM File="" CheckResult="-1" Enabled="1" ExtName="Menu de contexto de criptografia" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}" Descr="" LegalCopyright="" />

<ITEM File="C:\WINDOWS\system32\hticons.dll" CheckResult="-1" Enabled="1" ExtName="Extensгo de нcone do HyperTerminal" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{88895560-9AA2-1069-930E-00AA0030EBC8}" Descr="HyperTerminal Applet Library" LegalCopyright="Copyright © Hilgraeve, Inc. 2001" Size="44544" Attr="rsAh" CreateDate="2007-06-02 14:06:42" ChageDate="1782-01-19 00:14:07" MD5="42F92CD0BD982401067DD69AC3445CD5" />

<ITEM File="C:\WINDOWS\system32\icmui.dll" CheckResult="-1" Enabled="1" ExtName="Perfil ICC" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{DBCE2480-C732-101B-BE72-BA78E9AD5B27}" Descr="DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="55808" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="71B1979A285B2A0FACFE2A01231FE4DB" />

<ITEM File="deskperf.dll" CheckResult="-1" Enabled="1" ExtName="Display TroubleShoot CPL Extension" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{f92e8c40-3d33-11d2-b1aa-080036a75b03}" Descr="Propriedades avanзadas de desempenho de vнdeo" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." />

<ITEM File="" CheckResult="-1" Enabled="1" ExtName="Barra de tarefas e menu Iniciar" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{0DF44EAA-FF21-4412-828E-260A8728E7F1}" Descr="" LegalCopyright="" />

<ITEM File="rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}" CheckResult="-1" Enabled="1" ExtName="Autoplay for SlideShow" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}" Descr="" LegalCopyright="" />

<ITEM File="" CheckResult="-1" Enabled="1" ExtName="Contas de usuбrio" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{7A9D77BD-5403-11d2-8785-2E0420524153}" Descr="" LegalCopyright="" />

<ITEM File="C:\Arquivos de programas\Microsoft Office\Office10\OLKFSTUB.DLL" CheckResult="-1" Enabled="1" ExtName="Microsoft Outlook Custom Icon Handler" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{0006F045-0000-0000-C000-000000000046}" Descr="Outlook Shell Hook for Start/Find" LegalCopyright="Copyright© Microsoft Corporation 1995-2001. Todos os direitos reservados." Size="56032" Attr="rsAh" CreateDate="2004-01-22 09:06:14" ChageDate="2004-01-22 09:06:14" MD5="DA477B3A22B736900C2565BFF00C7D31" />

<ITEM File="" CheckResult="-1" Enabled="1" ExtName="CorelDRAW Shell Extension Component" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="" Descr="" LegalCopyright="" />

<ITEM File="C:\WINDOWS\system32\mscoree.dll" CheckResult="-1" Enabled="1" ExtName="Fusion Cache" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{1D2680C9-0E2A-469d-B787-065558BC7D43}" Descr="Microsoft .NET Runtime Execution Engine" LegalCopyright="© Microsoft Corporation. All rights reserved." Size="271360" Attr="rsAh" CreateDate="2006-12-22 11:28:14" ChageDate="2006-12-22 11:28:14" MD5="B5B67EE09B52D7129B8041B9BD411F7B" />

<ITEM File="" CheckResult="-1" Enabled="1" ExtName="Shell Extension for Malware scanning" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" Descr="" LegalCopyright="" />

<ITEM File="C:\Arquivos de programas\GbPlugin\gbiehcef.dll" CheckResult="-1" Enabled="1" ExtName="GbPlugin ShlObj" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{E37CB5F0-51F5-4395-A808-5FA49E399003}" Descr="Gbieh Module" LegalCopyright="Copyright © 2003-2009, Caixa Economica Federal" Size="404032" Attr="rsAh" CreateDate="2008-12-30 12:39:03" ChageDate="2009-01-27 13:40:04" MD5="342503A85A961384A705725B2D97B123" />

<ITEM File="C:\Arquivos de programas\AVG\AVG8\avgse.dll" CheckResult="-1" Enabled="1" ExtName="AVG8 Shell Extension" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" Descr="AVG Shell Extension" LegalCopyright="Copyright © 2008 AVG Technologies CZ, s.r.o." Size="117528" Attr="rsAh" CreateDate="2009-02-02 14:23:48" ChageDate="2009-02-02 14:23:48" MD5="076506D1F442D732B348B7C9E1921CD6" />

<ITEM File="" CheckResult="-1" Enabled="1" ExtName="AVG8 Find Extension" RegKey="SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved" CLSID="{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" Descr="" LegalCopyright="" />

</ExplorerExt>

- <PrintEXT>

<ITEM File="C:\WINDOWS\system32\hpz3l054.dll" CheckResult="-1" Enabled="1" RegKey="SYSTEM\CurrentControlSet\Control\Print\Monitors" Descr="LanguageMonitor" LegalCopyright="Copyright © 1999" Size="38400" Attr="rsAh" CreateDate="2007-06-07 20:25:12" ChageDate="2006-04-10 14:03:02" MD5="FDB859F93C8491F961C3B9168FA90F51" />

</PrintEXT>

- <TaskScheduler>

<ITEM File="c:\docume~1\joo~1\dadosd~1\creati~1\pokeviewfunk.exe" CheckResult="-1" Enabled="122424880" Descr="" LegalCopyright="" />

<ITEM File="C:\Arquivos de programas\Winferno\RegistryPowerCleaner\RegPowerClean.exe" CheckResult="-1" Enabled="122424880" Descr="" LegalCopyright="" />

</TaskScheduler>

- <DPF>

<ITEM File="" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="Microsoft XML Parser for Java" CodeBase="file://C:\WINDOWS\Java\classes\xmldso.cab" Descr="" LegalCopyright="" />

<ITEM File="C:\WINDOWS\Downloaded Program Files\msgrchkr.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{20A60F0D-9AFA-4515-A0FD-83BD84642501}" CodeBase="http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab" Descr="Zone.com Checkers for MSN Messenger" LegalCopyright="Copyright © 1995-2004 Microsoft Corporation" Size="131472" Attr="rsAh" CreateDate="2007-02-28 13:21:04" ChageDate="2007-02-28 13:21:04" MD5="1E5CFDF9AEBDD84305A4C8154277A269" />

<ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{8AD9C840-044E-11D1-B3E9-00805F499D93}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" />

<ITEM File="" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" CodeBase="http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab" Descr="" LegalCopyright="" />

<ITEM File="C:\WINDOWS\Downloaded Program Files\zylomgamesplayer.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}" CodeBase="http://game14.zylom.com/activex/zylomgamesplayer.cab" Descr="Zylom Games Player" LegalCopyright="Copyright 2004" Size="161976" Attr="rsAh" CreateDate="2006-08-29 14:17:22" ChageDate="2006-08-29 14:17:22" MD5="7FAF5222EEB546E1DC0F348DCB314B0B" />

<ITEM File="C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{C3F79A2B-B9B4-4A66-B012-3EE46475B072}" CodeBase="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab" Descr="Zone.com Stats Client for MSN Messenger" LegalCopyright="Copyright © 1995-2004 Microsoft Corporation" Size="304544" Attr="rsAh" CreateDate="2007-02-22 22:41:12" ChageDate="2007-02-22 22:41:12" MD5="8945CCA5FC4F25168E8B6F401EFAF51F" />

<ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" />

<ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" />

<ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" />

<ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" Descr="Java Platform SE binary" LegalCopyright="Copyright © 2004" Size="509328" Attr="rsAh" CreateDate="2008-10-19 15:54:21" ChageDate="2008-06-10 03:27:02" MD5="F921D875A1CBD69A6A462BA2514BC831" />

<ITEM File="C:\Arquivos de programas\Java\jre1.6.0_07\bin\npjpi160_07.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" CodeBase="http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab" Descr="Java Plug-in 1.6.0_07 for Netscape Navigator (DLL Helper)" LegalCopyright="Copyright © 2004" Size="132496" Attr="rsAh" CreateDate="2008-06-10 01:32:34" ChageDate="2008-06-10 03:27:02" MD5="7C83A2809E13950359189767AC9D5DB8" />

<ITEM File="C:\Arquivos de programas\GbPlugin\GbpDist.dll" CheckResult="-1" Enabled="1" RegKey="SOFTWARE\Microsoft\Code Store Database\Distribution Units" CLSID="{DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931}" CodeBase="https://imagem.caixa.gov.br/cab/gbpdist.cab" Descr="GbpDist Module" LegalCopyright="Copyright © 2008" Size="79424" Attr="rsAh" CreateDate="2008-12-30 12:39:15" ChageDate="2009-01-27 13:49:26" MD5="21587F8E147B0BDC1B7734EBD94D9D4D" />

</DPF>

- <CPL>

<ITEM File="C:\WINDOWS\system32\ImageDrive.cpl" CheckResult="-1" Enabled="1" Descr="" LegalCopyright="" Size="57344" Attr="rsah" CreateDate="2007-06-02 17:42:57" ChageDate="2003-03-31 16:27:54" MD5="4BE82722A9802EEB07B04450E56D7655" />

<ITEM File="C:\WINDOWS\system32\ISUSPM.cpl" CheckResult="-1" Enabled="1" Descr="InstallShield Update Service Update Manager Applet" LegalCopyright="Copyright © 1990-2004 InstallShield Software Corporation" Size="61440" Attr="rsAh" CreateDate="2004-04-16 11:24:54" ChageDate="2004-04-16 11:24:54" MD5="A7EB7AC7145C0B2D9E8103A90AE255E0" />

<ITEM File="C:\WINDOWS\system32\javacpl.cpl" CheckResult="-1" Enabled="1" Descr="Java Control Panel" LegalCopyright="Copyright © 2004" Size="73728" Attr="rsAh" CreateDate="2007-09-22 17:34:11" ChageDate="2008-06-10 01:32:34" MD5="370716E3CA99E6A4346F272DA56017C1" />

<ITEM File="C:\WINDOWS\system32\main.cpl" CheckResult="-1" Enabled="1" Descr="DLL do 'Painel de controle'" LegalCopyright="Copyright © Microsoft Corp. 1991-1999" Size="188928" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="6088DFCD542C1B5646A99C2B71607800" />

<ITEM File="C:\WINDOWS\system32\ncpa.cpl" CheckResult="-1" Enabled="1" Descr="Conexхes de rede no painel de controle" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="35840" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="43B08C09D30DCAA0D08F161FCF51F734" />

<ITEM File="C:\WINDOWS\system32\nwc.cpl" CheckResult="-1" Enabled="1" Descr="Aplicativo Serviзo de cliente para NetWare" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="37888" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="08A1A1C5A5971C39AD263C3580464B80" />

<ITEM File="C:\WINDOWS\system32\telephon.cpl" CheckResult="-1" Enabled="1" Descr="Painel de controle de telefonia" LegalCopyright="© Microsoft Corporation. Todos os direitos reservados." Size="28160" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="69B830766F6D52109F822ACC106B8AEF" />

</CPL>

<ActiveSetup />

- <HOSTS>

<ITEM Line="127.0.0.1 localhost" />

</HOSTS>

- <SuspFiles>

<ITEM File="C:\WINDOWS\system32\serwvdrv.dll" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

<ITEM File="C:\WINDOWS\system32\umdmxfrm.dll" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

<ITEM File="C:\WINDOWS\system32\msacm32.drv" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

<ITEM File="C:\WINDOWS\system32\msg711.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

<ITEM File="C:\WINDOWS\system32\msgsm32.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

<ITEM File="C:\WINDOWS\system32\tssoft32.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

<ITEM File="C:\WINDOWS\system32\tsd32.dll" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

<ITEM File="C:\WINDOWS\system32\msg723.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

<ITEM File="C:\WINDOWS\system32\sirenacm.dll" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

<ITEM File="C:\WINDOWS\system32\scg726.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

<ITEM File="C:\WINDOWS\system32\alf2cd.acm" VirType="5" Descr="Suspicion for Keylogger or Trojan DLL" />

</SuspFiles>

- <RK_UM>

<ITEM DLL="kernel32.dll" FNaim="CreateProcessA" FIndx="98" HookPtr="61F03F42" HookType="1" />

<ITEM DLL="kernel32.dll" FNaim="CreateProcessW" FIndx="102" HookPtr="61F04040" HookType="1" />

<ITEM DLL="kernel32.dll" FNaim="FreeLibrary" FIndx="240" HookPtr="61F041FC" HookType="1" />

<ITEM DLL="kernel32.dll" FNaim="GetModuleFileNameA" FIndx="372" HookPtr="61F040FB" HookType="1" />

<ITEM DLL="kernel32.dll" FNaim="GetModuleFileNameW" FIndx="373" HookPtr="61F041A0" HookType="1" />

<ITEM DLL="kernel32.dll" FNaim="GetProcAddress" FIndx="408" HookPtr="61F04648" HookType="1" />

<ITEM DLL="kernel32.dll" FNaim="LoadLibraryA" FIndx="580" HookPtr="61F03C6F" HookType="1" />

<ITEM DLL="kernel32.dll" FNaim="LoadLibraryExA" FIndx="581" HookPtr="61F03DAF" HookType="1" />

<ITEM DLL="kernel32.dll" FNaim="LoadLibraryExW" FIndx="582" HookPtr="61F03E5A" HookType="1" />

<ITEM DLL="kernel32.dll" FNaim="LoadLibraryW" FIndx="583" HookPtr="61F03D0C" HookType="1" />

</RK_UM>

- <KEYLOGGER>

<ITEM File="C:\WINDOWS\system32\serwvdrv.dll" Verdict="" CheckResult="-1" Size="14848" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="7BAE7061357C489E3C41314A1EC85B3B" />

<ITEM File="C:\WINDOWS\system32\umdmxfrm.dll" Verdict="" CheckResult="-1" Size="13312" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="6EBC082A88B651640EB1526D7267FD26" />

<ITEM File="C:\WINDOWS\system32\msacm32.drv" Verdict="" CheckResult="-1" Size="20992" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="CF2BAE9C79C39E012605647A485C1320" />

<ITEM File="C:\WINDOWS\system32\msg711.acm" Verdict="" CheckResult="-1" Size="9216" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="FD77D822F8D8F93C3C7CDD190CE76F96" />

<ITEM File="C:\WINDOWS\system32\msgsm32.acm" Verdict="" CheckResult="-1" Size="19968" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="6109521768E6E2E7F6C246C2D8E911DF" />

<ITEM File="C:\WINDOWS\system32\tssoft32.acm" Verdict="" CheckResult="-1" Size="8192" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="F2AD69138348EAD46DEE28B0543C0977" />

<ITEM File="C:\WINDOWS\system32\tsd32.dll" Verdict="" CheckResult="-1" Size="15360" Attr="rsAh" CreateDate="1782-01-19 00:14:07" ChageDate="1782-01-19 00:14:07" MD5="56AD8DBD8CECCDE394B235527E8B04D9" />

<ITEM File="C:\WINDOWS\system32\msg723.acm" Verdict="" CheckResult="-1" Size="118784" Attr="rsAh" CreateDate="2007-06-02 14:08:27" ChageDate="1782-01-19 00:14:07" MD5="4D25497C7108F3CD024412E295B41027" />

<ITEM File="C:\WINDOWS\system32\sirenacm.dll" Verdict="" CheckResult="-1" Size="51224" Attr="rsAh" CreateDate="2007-10-18 11:31:46" ChageDate="2007-10-18 11:31:46" MD5="69D044C73A1BA2485A017DBBB037C1A0" />

<ITEM File="C:\WINDOWS\system32\scg726.acm" Verdict="" CheckResult="-1" Size="13239" Attr="rsAh" CreateDate="2008-10-22 14:30:14" ChageDate="2000-03-14 19:55:44" MD5="DC4B2F21968AC6E7E6C8A4417ED0D85C" />

<ITEM File="C:\WINDOWS\system32\alf2cd.acm" Verdict="" CheckResult="-1" Size="38912" Attr="rsAh" CreateDate="2008-10-22 14:30:14" ChageDate="2003-05-21 22:50:36" MD5="8210141840CE237FBF40B6E26E2DD11D" />

</KEYLOGGER>

- <WIZARD-TSW>

<ITEM ID="58" Level="3" Fixed="0" />

<ITEM ID="59" Level="3" Fixed="0" />

<ITEM ID="60" Level="1" Fixed="0" />

<ITEM ID="61" Level="2" Fixed="0" />

</WIZARD-TSW>

</AVZ>

Compartilhar este post


Link para o post
Compartilhar em outros sites

E esse outro:

 

Results of system analysis

 

Kaspersky Virus Removal Tool 7.0.0.290 (database released 22/03/2009; 14:42)

List of processes

File name PID Description Copyright MD5 Information

c:\windows\explorer.exe

Script: Quarantine, Delete, BC delete, Terminate 932 Windows Explorer © Microsoft Corporation. Todos os direitos reservados. ?? 1011.50 kb, rsAh,

created: 2004-08-04 00:45:34,

modified: 2008-04-13 23:20:58

Command line:

C:\WINDOWS\Explorer.EXE

c:\arquivos de programas\mozilla firefox\firefox.exe

Script: Quarantine, Delete, BC delete, Terminate 2044 Firefox ©Firefox and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable. ?? 300.49 kb, rsAh,

created: 2009-02-09 14:22:52,

modified: 2009-03-06 22:30:07

Command line:

c:\documents and settings\joгo\desktop\virus removal tool\is-rmfni\is-rmfni.exe

Script: Quarantine, Delete, BC delete, Terminate 1556 Kaspersky Anti-Virus Copyright © Kaspersky Lab 1996-2007. ?? 212.00 kb, rsAh,

created: 2009-03-22 15:00:26,

modified: 2008-11-12 13:32:32,

name contains national symbols

Command line:

"C:\Documents and Settings\Joгo\Desktop\Virus Removal Tool\is-RMFNI\is-RMFNI.exe"

c:\windows\system32\lsass.exe

Script: Quarantine, Delete, BC delete, Terminate 376 LSA Shell (Export Version) © Microsoft Corporation. All rights reserved. ?? 13.00 kb, rsAh,

created: 2004-08-04 00:45:36,

modified: 2008-04-13 23:21:05

Command line:

C:\WINDOWS\system32\lsass.exe

c:\windows\system32\svchost.exe

Script: Quarantine, Delete, BC delete, Terminate 532 Generic Host Process for Win32 Services © Microsoft Corporation. All rights reserved. ?? 14.00 kb, rsAh,

created: 2004-08-04 00:45:44,

modified: 2008-04-13 23:21:20

Command line:

C:\WINDOWS\system32\svchost -k DcomLaunch

c:\windows\system32\svchost.exe

Script: Quarantine, Delete, BC delete, Terminate 596 Generic Host Process for Win32 Services © Microsoft Corporation. All rights reserved. ?? 14.00 kb, rsAh,

created: 2004-08-04 00:45:44,

modified: 2008-04-13 23:21:20

Command line:

C:\WINDOWS\system32\svchost -k rpcss

c:\windows\system32\svchost.exe

Script: Quarantine, Delete, BC delete, Terminate 640 Generic Host Process for Win32 Services © Microsoft Corporation. All rights reserved. ?? 14.00 kb, rsAh,

created: 2004-08-04 00:45:44,

modified: 2008-04-13 23:21:20

Command line:

C:\WINDOWS\system32\svchost.exe -k netsvcs

c:\windows\system32\winlogon.exe

Script: Quarantine, Delete, BC delete, Terminate 320 Aplicativo de logon do Windows NT © Microsoft Corporation. Todos os direitos reservados. ?? 498.00 kb, rsAh,

created: 2004-08-04 00:45:46,

modified: 2008-04-13 23:21:23

Command line:

winlogon.exe

Detected:15, recognized as trusted 14

Module name Handle Description Copyright MD5 Used by processes

C:\Arquivos de programas\GbPlugin\gbiehcef.dll

Script: Quarantine, Delete, BC delete 268435456 Gbieh Module Copyright © 2003-2009, Caixa Economica Federal -- 932, 320

C:\Arquivos de programas\Scpad\scpLIB.dll

Script: Quarantine, Delete, BC delete 26935296 scpIBLoad Module Copyright 2005 -- 932

C:\Arquivos de programas\Scpad\scpMIB.dll

Script: Quarantine, Delete, BC delete 27197440 scpMIB Module Copyright 2005 -- 932

C:\Arquivos de programas\Scpad\sshib.dll

Script: Quarantine, Delete, BC delete 28180480 sshib Copyright © 2004 -- 932

C:\WINDOWS\system32\alf2cd.acm

Script: Quarantine, Delete, BC delete 34406400 NCT ALF2CD Audio CODEC NCT Company Copyright 1999 - 2001 -- 932, 1556, 320

C:\WINDOWS\system32\avgrsstx.dll

Script: Quarantine, Delete, BC delete 1813708800 AVG Resident Shield Starter Copyright © 2008 AVG Technologies CZ, s.r.o. -- 320

C:\WINDOWS\system32\msacm32.drv

Script: Quarantine, Delete, BC delete 1925971968 Mapeador de som da Microsoft © Microsoft Corporation. Todos os direitos reservados. -- 932, 1556, 320

C:\WINDOWS\system32\msg711.acm

Script: Quarantine, Delete, BC delete 1483931648 CODEC Microsoft CCITT G.711 (A-Law e u-Law) para MSACM © Microsoft Corporation. Todos os direitos reservados. -- 932, 1556, 320

C:\WINDOWS\system32\msg723.acm

Script: Quarantine, Delete, BC delete 1483800576 Microsoft G.723.1 CODEC para MSACM Copyright © Intel Corp. e Microsoft Corporation 1995-1999 -- 932, 1556, 320

C:\WINDOWS\system32\msgsm32.acm

Script: Quarantine, Delete, BC delete 1483735040 CODEC de бudio Microsoft GSM 6.10 para MSACM © Microsoft Corporation. Todos os direitos reservados. -- 932, 1556, 320

C:\WINDOWS\system32\scg726.acm

Script: Quarantine, Delete, BC delete 34340864 SHARP G.726 ACM Audio Decoder Copyright © 2000 SHARP Corporation -- 932, 1556, 320

C:\WINDOWS\system32\serwvdrv.dll

Script: Quarantine, Delete, BC delete 1562181632 Driver Unimodem Serial Wave © Microsoft Corporation. Todos os direitos reservados. -- 932, 1556, 376, 532, 596, 640, 320

C:\WINDOWS\system32\sirenacm.dll

Script: Quarantine, Delete, BC delete 1516240896 Messenger Audio Codec Copyright © 1997 - 2006 Microsoft Corporation -- 932, 1556, 320

C:\WINDOWS\system32\tsd32.dll

Script: Quarantine, Delete, BC delete 1941045248 -- 932, 1556, 320

C:\WINDOWS\system32\tssoft32.acm

Script: Quarantine, Delete, BC delete 1483538432 Codec de бudio DSP Group TrueSpeech para MSACM V3.50 Copyright DSP Group, Inc. 1993-1996 -- 932, 1556, 320

C:\WINDOWS\system32\umdmxfrm.dll

Script: Quarantine, Delete, BC delete 1531904000 Unimodem Tranform Module © Microsoft Corporation. All rights reserved. -- 932, 1556, 376, 532, 596, 640, 320

C:\WINDOWS\system32\WgaLogon.dll

Script: Quarantine, Delete, BC delete 18939904 Notificaзхes do Programa de Vantagens do Windows Original © 1995-2008 Microsoft Corporation -- 320

Modules detected:255, recognized as trusted 238

Kernel Space Modules Viewer

Module Base address Size in memory Description Manufacturer

C:\WINDOWS\System32\Drivers\aex3mvvn.SYS

Script: Quarantine, Delete, BC delete F9159000 066000 (417792)

dmload.sys

Script: Quarantine, Delete, BC delete F9A93000 002000 (8192)

C:\WINDOWS\System32\Drivers\dump_atapi.sys

Script: Quarantine, Delete, BC delete F8FEA000 018000 (98304)

C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS

Script: Quarantine, Delete, BC delete F9AC1000 002000 (8192)

C:\WINDOWS\System32\Drivers\ElbyDelay.sys

Script: Quarantine, Delete, BC delete F9A99000 002000 (8192) Elby Delay Lower Filter Driver Copyright © 2003 - 2006 Elaborate Bytes AG

ftdisk.sys

Script: Quarantine, Delete, BC delete F940C000 01F000 (126976)

C:\WINDOWS\system32\Drivers\GbpKm.sys

Script: Quarantine, Delete, BC delete F9825000 007000 (28672) GbPlugin Device Driver ® GAS Tecnologia

PCIIde.sys

Script: Quarantine, Delete, BC delete F9B55000 001000 (4096)

C:\WINDOWS\system32\Drivers\sptd.sys

Script: Quarantine, Delete, BC delete F9482000 0EA000 (958464)

Modules detected - 73, recognized as trusted - 64

Services

Service Description Status File Group Dependencies

AresChatServer

Service: Stop, Delete, Disable Ares Chatroom server Not started C:\Arquivos de programas\Ares\chatServer.exe

Script: Quarantine, Delete, BC delete

avg8wd

Service: Stop, Delete, Disable AVG Free8 WatchDog Not started C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

Script: Quarantine, Delete, BC delete

GbpSv

Service: Stop, Delete, Disable Gbp Service Not started C:\ARQUIV~1\GbPlugin\GbpSv.exe

Script: Quarantine, Delete, BC delete GbPlugin Group

NMIndexingService

Service: Stop, Delete, Disable NMIndexingService Not started C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

Script: Quarantine, Delete, BC delete RPCSS

NNServ

Service: Stop, Delete, Disable NNServ Not started C:\Arquivos de programas\NewDotNet\nnrun.exe

Script: Quarantine, Delete, BC delete

Pml Driver HPZ12

Service: Stop, Delete, Disable Pml Driver HPZ12 Not started C:\WINDOWS\system32\HPZipm12.exe

Script: Quarantine, Delete, BC delete

RSVP

Service: Stop, Delete, Disable QoS RSVP Not started C:\WINDOWS\system32\rsvp.exe

Script: Quarantine, Delete, BC delete TcpIp

Detected - 104, recognized as trusted - 97

Drivers

Service Description Status File Group Dependencies

Beep

Driver: Unload, Delete, Disable Beep Running Beep.sys

Script: Quarantine, Delete, BC delete Base

ElbyDelay

Driver: Unload, Delete, Disable ElbyDelay Running C:\WINDOWS\system32\Drivers\ElbyDelay.sys

Script: Quarantine, Delete, BC delete

Ftdisk

Driver: Unload, Delete, Disable Volume Manager Driver Running C:\WINDOWS\system32\DRIVERS\ftdisk.sys

Script: Quarantine, Delete, BC delete System Bus Extender

GbpKm

Driver: Unload, Delete, Disable Gbp KernelMode Running C:\WINDOWS\system32\drivers\GbpKm.sys

Script: Quarantine, Delete, BC delete GbPlugin Group

Null

Driver: Unload, Delete, Disable Null Running Null.sys

Script: Quarantine, Delete, BC delete Base

PCIIde

Driver: Unload, Delete, Disable PCIIde Running PCIIde.sys

Script: Quarantine, Delete, BC delete System Bus Extender

sptd

Driver: Unload, Delete, Disable sptd Running C:\WINDOWS\System32\Drivers\sptd.sys

Script: Quarantine, Delete, BC delete Boot Bus Extender

Abiosdsk

Driver: Unload, Delete, Disable Abiosdsk Not started Abiosdsk.sys

Script: Quarantine, Delete, BC delete Primary disk

abp480n5

Driver: Unload, Delete, Disable abp480n5 Not started abp480n5.sys

Script: Quarantine, Delete, BC delete SCSI miniport

ACPIEC

Driver: Unload, Delete, Disable ACPIEC Not started ACPIEC.sys

Script: Quarantine, Delete, BC delete Boot Bus Extender

adpu160m

Driver: Unload, Delete, Disable adpu160m Not started adpu160m.sys

Script: Quarantine, Delete, BC delete SCSI miniport

Aha154x

Driver: Unload, Delete, Disable Aha154x Not started Aha154x.sys

Script: Quarantine, Delete, BC delete SCSI miniport

aic78u2

Driver: Unload, Delete, Disable aic78u2 Not started aic78u2.sys

Script: Quarantine, Delete, BC delete SCSI miniport

aic78xx

Driver: Unload, Delete, Disable aic78xx Not started aic78xx.sys

Script: Quarantine, Delete, BC delete SCSI miniport

AliIde

Driver: Unload, Delete, Disable AliIde Not started AliIde.sys

Script: Quarantine, Delete, BC delete System Bus Extender

amsint

Driver: Unload, Delete, Disable amsint Not started amsint.sys

Script: Quarantine, Delete, BC delete SCSI miniport

asc

Driver: Unload, Delete, Disable asc Not started asc.sys

Script: Quarantine, Delete, BC delete SCSI miniport

asc3350p

Driver: Unload, Delete, Disable asc3350p Not started asc3350p.sys

Script: Quarantine, Delete, BC delete SCSI miniport

asc3550

Driver: Unload, Delete, Disable asc3550 Not started asc3550.sys

Script: Quarantine, Delete, BC delete SCSI miniport

Atdisk

Driver: Unload, Delete, Disable Atdisk Not started Atdisk.sys

Script: Quarantine, Delete, BC delete Primary disk

AvgLdx86

Driver: Unload, Delete, Disable AVG Free AVI Loader Driver x86 Not started C:\WINDOWS\System32\Drivers\avgldx86.sys

Script: Quarantine, Delete, BC delete AVG

AvgMfx86

Driver: Unload, Delete, Disable AVG Free On-access Scanner Minifilter Driver x86 Not started C:\WINDOWS\System32\Drivers\avgmfx86.sys

Script: Quarantine, Delete, BC delete AVG

AvgTdiX

Driver: Unload, Delete, Disable AVG Free8 Network Redirector Not started C:\WINDOWS\System32\Drivers\avgtdix.sys

Script: Quarantine, Delete, BC delete PNP_TDI

cbidf2k

Driver: Unload, Delete, Disable cbidf2k Not started cbidf2k.sys

Script: Quarantine, Delete, BC delete SCSI miniport

cd20xrnt

Driver: Unload, Delete, Disable cd20xrnt Not started cd20xrnt.sys

Script: Quarantine, Delete, BC delete SCSI miniport

Cdaudio

Driver: Unload, Delete, Disable Cdaudio Not started Cdaudio.sys

Script: Quarantine, Delete, BC delete Filter

Changer

Driver: Unload, Delete, Disable Changer Not started Changer.sys

Script: Quarantine, Delete, BC delete Filter

CmdIde

Driver: Unload, Delete, Disable CmdIde Not started CmdIde.sys

Script: Quarantine, Delete, BC delete System Bus Extender

Cpqarray

Driver: Unload, Delete, Disable Cpqarray Not started Cpqarray.sys

Script: Quarantine, Delete, BC delete SCSI miniport

dac960nt

Driver: Unload, Delete, Disable dac960nt Not started dac960nt.sys

Script: Quarantine, Delete, BC delete SCSI miniport

dpti2o

Driver: Unload, Delete, Disable dpti2o Not started dpti2o.sys

Script: Quarantine, Delete, BC delete SCSI miniport

dump_wmimmc

Driver: Unload, Delete, Disable dump_wmimmc Not started C:\Documents and Settings\Joгo\Desktop\Grand Chase\GameGuard\dump_wmimmc.sys

Script: Quarantine, Delete, BC delete

ElbyCDIO

Driver: Unload, Delete, Disable ElbyCDIO Driver Not started C:\WINDOWS\system32\Drivers\ElbyCDIO.sys

Script: Quarantine, Delete, BC delete

hpn

Driver: Unload, Delete, Disable hpn Not started hpn.sys

Script: Quarantine, Delete, BC delete SCSI miniport

i2omgmt

Driver: Unload, Delete, Disable i2omgmt Not started i2omgmt.sys

Script: Quarantine, Delete, BC delete SCSI Class

i2omp

Driver: Unload, Delete, Disable i2omp Not started i2omp.sys

Script: Quarantine, Delete, BC delete SCSI miniport

ini910u

Driver: Unload, Delete, Disable ini910u Not started ini910u.sys

Script: Quarantine, Delete, BC delete SCSI miniport

lbrtfdc

Driver: Unload, Delete, Disable lbrtfdc Not started lbrtfdc.sys

Script: Quarantine, Delete, BC delete System Bus Extender

mnmdd

Driver: Unload, Delete, Disable mnmdd Not started mnmdd.sys

Script: Quarantine, Delete, BC delete Video Save

mraid35x

Driver: Unload, Delete, Disable mraid35x Not started mraid35x.sys

Script: Quarantine, Delete, BC delete SCSI miniport

ParVdm

Driver: Unload, Delete, Disable ParVdm Not started ParVdm.sys

Script: Quarantine, Delete, BC delete Extended base Parport

PCIDump

Driver: Unload, Delete, Disable PCIDump Not started PCIDump.sys

Script: Quarantine, Delete, BC delete PCI Configuration

PDCOMP

Driver: Unload, Delete, Disable PDCOMP Not started PDCOMP.sys

Script: Quarantine, Delete, BC delete

PDFRAME

Driver: Unload, Delete, Disable PDFRAME Not started PDFRAME.sys

Script: Quarantine, Delete, BC delete

PDRELI

Driver: Unload, Delete, Disable PDRELI Not started PDRELI.sys

Script: Quarantine, Delete, BC delete

PDRFRAME

Driver: Unload, Delete, Disable PDRFRAME Not started PDRFRAME.sys

Script: Quarantine, Delete, BC delete

perc2

Driver: Unload, Delete, Disable perc2 Not started perc2.sys

Script: Quarantine, Delete, BC delete SCSI miniport

perc2hib

Driver: Unload, Delete, Disable perc2hib Not started perc2hib.sys

Script: Quarantine, Delete, BC delete Filter

ProCam Usb

Driver: Unload, Delete, Disable ProCam Digital Camera on USB Not started C:\WINDOWS\system32\DRIVERS\CoachUsb.sys

Script: Quarantine, Delete, BC delete

ql1080

Driver: Unload, Delete, Disable ql1080 Not started ql1080.sys

Script: Quarantine, Delete, BC delete SCSI miniport

Ql10wnt

Driver: Unload, Delete, Disable Ql10wnt Not started Ql10wnt.sys

Script: Quarantine, Delete, BC delete SCSI miniport

ql12160

Driver: Unload, Delete, Disable ql12160 Not started ql12160.sys

Script: Quarantine, Delete, BC delete SCSI miniport

ql1240

Driver: Unload, Delete, Disable ql1240 Not started ql1240.sys

Script: Quarantine, Delete, BC delete SCSI miniport

ql1280

Driver: Unload, Delete, Disable ql1280 Not started ql1280.sys

Script: Quarantine, Delete, BC delete SCSI miniport

Simbad

Driver: Unload, Delete, Disable Simbad Not started Simbad.sys

Script: Quarantine, Delete, BC delete Filter

Sparrow

Driver: Unload, Delete, Disable Sparrow Not started Sparrow.sys

Script: Quarantine, Delete, BC delete SCSI miniport

sym_hi

Driver: Unload, Delete, Disable sym_hi Not started sym_hi.sys

Script: Quarantine, Delete, BC delete SCSI miniport

sym_u3

Driver: Unload, Delete, Disable sym_u3 Not started sym_u3.sys

Script: Quarantine, Delete, BC delete SCSI miniport

symc810

Driver: Unload, Delete, Disable symc810 Not started symc810.sys

Script: Quarantine, Delete, BC delete SCSI miniport

symc8xx

Driver: Unload, Delete, Disable symc8xx Not started symc8xx.sys

Script: Quarantine, Delete, BC delete SCSI miniport

TosIde

Driver: Unload, Delete, Disable TosIde Not started TosIde.sys

Script: Quarantine, Delete, BC delete System Bus Extender

ultra

Driver: Unload, Delete, Disable ultra Not started ultra.sys

Script: Quarantine, Delete, BC delete SCSI miniport

ViaIde

Driver: Unload, Delete, Disable ViaIde Not started ViaIde.sys

Script: Quarantine, Delete, BC delete System Bus Extender

WDICA

Driver: Unload, Delete, Disable WDICA Not started WDICA.sys

Script: Quarantine, Delete, BC delete

Detected - 191, recognized as trusted - 127

Autoruns

File name Status Startup method Description

Active Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager\Narrator, Application path

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, AVG8_TRAY

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

Script: Quarantine, Delete, BC delete Active Registry key HKEY_USERS, S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run, BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

Script: Quarantine, Delete, BC delete Active Shortcut in Autoruns folder C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\, C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\HP Digital Imaging Monitor.lnk,

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, HP Software Update

C:\Arquivos de programas\Java\jre1.6.0_07\bin\jusched.exe

Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, SunJavaUpdateSched

C:\Arquivos de programas\Scpad\scpLIB.dll

Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler, {A3717295-941D-416F-9384-ED1736729F1C}

C:\Arquivos de programas\Scpad\scpLIB.dll

Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad, CompIBBrd

C:\Arquivos de programas\Torrent Finder\Torrent-Finder.exe

Script: Quarantine, Delete, BC delete Active Registry key HKEY_USERS, S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run, Torrent Finder

C:\Arquivos de programas\Winferno\RegistryPowerCleaner\RegPowerClean.exe

Script: Quarantine, Delete, BC delete Active Registry key HKEY_USERS, S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run, RegPowerClean

C:\DOCUME~1\JOO~1\DADOSD~1\CREATI~1\Bolt Slow Dash.exe

Script: Quarantine, Delete, BC delete Active Registry key HKEY_USERS, S-1-5-21-1960408961-682003330-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run, bowsmove

C:\Documents and Settings\All Users\Dados de aplicativos\Joy coal mpeg heck\win team.exe

Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, Software\Microsoft\Windows\CurrentVersion\Run, mpeg heck log link

C:\WINDOWS\system32\dfrg.msc %c:

Script: Quarantine, Delete, BC delete -- Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath,

C:\WINDOWS\system\GBPlugins.dll

Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ aGbPlugin, DLLName

WgaLogon.dll

Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon, DLLName

avgrsstx.dll

Script: Quarantine, Delete, BC delete Active Registry key HKEY_LOCAL_MACHINE, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter, DLLName

Autoruns items detected - 74, recognized as trusted - 58

Microsoft Internet Explorer extension modules (BHOs, Toolbars ...)

File name Type Description Manufacturer CLSID

C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll

Script: Quarantine, Delete, BC delete BHO hpswp_printenhancer dll HP. All rights reserved. {0347C33E-8762-4905-BF09-768834316C61}

Delete

C:\Arquivos de programas\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL

Script: Quarantine, Delete, BC delete BHO {04079851-5845-4dea-848C-3ECD647AA554}

Delete

C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll

Script: Quarantine, Delete, BC delete BHO Leo (Framework) - add-on for Internet Explorer Copyright © Hewlett-Packard Co. 1995-2006 {053F9267-DC04-4294-A72C-58F732D338C0}

Delete

C:\Arquivos de programas\Scpad\scpsssh2.dll

Script: Quarantine, Delete, BC delete BHO scpsssh2 Module Copyright 2001 {2E3C3651-B19C-4DD9-A979-901EC3E930AF}

Delete

C:\Arquivos de programas\AVG\AVG8\avgssie.dll

Script: Quarantine, Delete, BC delete BHO Safe Search for Internet Explorer Copyright © 2008 AVG Technologies CZ, s.r.o. {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}

Delete

C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

Script: Quarantine, Delete, BC delete BHO Java Platform SE binary Copyright © 2004 {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}

Delete

BHO {7E853D72-626A-48EC-A868-BA8D5E23E045}

Delete

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

Script: Quarantine, Delete, BC delete BHO WindowsLiveLogin.dll Copyright © 1995-2006 Microsoft Corporation. {9030D464-4C02-4ABF-8ECC-5164760863C6}

Delete

C:\Arquivos de programas\GbPlugin\gbiehcef.dll

Script: Quarantine, Delete, BC delete BHO Gbieh Module Copyright © 2003-2009, Caixa Economica Federal {C41A1C0E-EA6C-11D4-B1B8-444553540003}

Delete

Extension module {58ECB495-38F0-49cb-A538-10282ABF65E7}

Delete

Extension module {700259D7-1666-479a-93B1-3250410481E8}

Delete

Elements detected - 14, recognized as trusted - 3

Windows Explorer extension modules

File name Destination Description Manufacturer CLSID

icmui.dll

Script: Quarantine, Delete, BC delete Gerenciamento de scanner ICM DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft © Microsoft Corporation. Todos os direitos reservados. {176d6597-26d3-11d1-b350-080036a75b03}

docprop.dll

Script: Quarantine, Delete, BC delete Pбgina de propriedades do arquivo de documento OLE Pбgina de propriedades do arquivo de documento OLE © Microsoft Corporation. Todos os direitos reservados. {3EA48300-8CF6-101B-84FB-666CCB9BCD32}

deskadp.dll

Script: Quarantine, Delete, BC delete Extensгo do 'Painel de controle' para adaptador de vнdeo Propriedades avanзadas de adaptador de vнdeo © Microsoft Corporation. Todos os direitos reservados. {42071712-76d4-11d1-8b24-00a0c9068ff3}

deskmon.dll

Script: Quarantine, Delete, BC delete Extensгo do 'Painel de controle' para monitor de vнdeo Propriedades avanзadas de monitor © Microsoft Corporation. Todos os direitos reservados. {42071713-76d4-11d1-8b24-00a0c9068ff3}

Extensгo do 'Painel de controle' para panorвmica de vнdeo {42071714-76d4-11d1-8b24-00a0c9068ff3}

ntlanui2.dll

Script: Quarantine, Delete, BC delete Extensхes do shell para objetos Microsoft Windows Network Objeto de rede do shell da interface de usuбrio © Microsoft Corporation. Todos os direitos reservados. {59be4990-f85c-11ce-aff7-00aa003ca9f6}

C:\WINDOWS\System32\icmui.dll

Script: Quarantine, Delete, BC delete Gerenciamento de monitor ICM DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft © Microsoft Corporation. Todos os direitos reservados. {5DB2625A-54DF-11D0-B6C4-0800091AA605}

C:\WINDOWS\system32\icmui.dll

Script: Quarantine, Delete, BC delete Gerenciamento de impressora ICM DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft © Microsoft Corporation. Todos os direitos reservados. {675F097E-4C4D-11D0-B6C1-0800091AA605}

Extensхes do shell para compactaзгo de arquivos {764BF0E1-F219-11ce-972D-00AA00A14F56}

Menu de contexto de criptografia {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}

C:\WINDOWS\system32\hticons.dll

Script: Quarantine, Delete, BC delete Extensгo de нcone do HyperTerminal HyperTerminal Applet Library Copyright © Hilgraeve, Inc. 2001 {88895560-9AA2-1069-930E-00AA0030EBC8}

C:\WINDOWS\system32\icmui.dll

Script: Quarantine, Delete, BC delete Perfil ICC DLL da interface com o usuбrio do sistema de correspondкncia de cores Microsoft © Microsoft Corporation. Todos os direitos reservados. {DBCE2480-C732-101B-BE72-BA78E9AD5B27}

deskperf.dll

Script: Quarantine, Delete, BC delete Display TroubleShoot CPL Extension Propriedades avanзadas de desempenho de vнdeo © Microsoft Corporation. Todos os direitos reservados. {f92e8c40-3d33-11d2-b1aa-080036a75b03}

Barra de tarefas e menu Iniciar {0DF44EAA-FF21-4412-828E-260A8728E7F1}

rundll32.exe C:\WINDOWS\system32\shimgvw.dll,ImageView_COMServer {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}

Script: Quarantine, Delete, BC delete Autoplay for SlideShow {00E7B358-F65B-4dcf-83DF-CD026B94BFD4}

Contas de usuбrio {7A9D77BD-5403-11d2-8785-2E0420524153}

C:\Arquivos de programas\Microsoft Office\Office10\OLKFSTUB.DLL

Script: Quarantine, Delete, BC delete Microsoft Outlook Custom Icon Handler Outlook Shell Hook for Start/Find Copyright© Microsoft Corporation 1995-2001. Todos os direitos reservados. {0006F045-0000-0000-C000-000000000046}

CorelDRAW Shell Extension Component

C:\WINDOWS\system32\mscoree.dll

Script: Quarantine, Delete, BC delete Fusion Cache Microsoft .NET Runtime Execution Engine © Microsoft Corporation. All rights reserved. {1D2680C9-0E2A-469d-B787-065558BC7D43}

Shell Extension for Malware scanning {45AC2688-0253-4ED8-97DE-B5370FA7D48A}

C:\Arquivos de programas\GbPlugin\gbiehcef.dll

Script: Quarantine, Delete, BC delete GbPlugin ShlObj Gbieh Module Copyright © 2003-2009, Caixa Economica Federal {E37CB5F0-51F5-4395-A808-5FA49E399003}

C:\Arquivos de programas\AVG\AVG8\avgse.dll

Script: Quarantine, Delete, BC delete AVG8 Shell Extension AVG Shell Extension Copyright © 2008 AVG Technologies CZ, s.r.o. {9F97547E-4609-42C5-AE0C-81C61FFAEBC3}

AVG8 Find Extension {9F97547E-460A-42C5-AE0C-81C61FFAEBC3}

Elements detected - 206, recognized as trusted - 183

Printing system extensions (print monitors, providers)

File name Type Name Description Manufacturer

C:\WINDOWS\system32\hpz3l054.dll

Script: Quarantine, Delete, BC delete Monitor PCL hpz3l054 LanguageMonitor Copyright © 1999

Elements detected - 10, recognized as trusted - 9

Task Scheduler jobs

File name Job name Job status Description Manufacturer

c:\docume~1\joo~1\dadosd~1\creati~1\pokeviewfunk.exe

Script: Quarantine, Delete, BC delete BC5747FE9388E1CE.job The task is ready to run at its next scheduled time.

C:\Arquivos de programas\Winferno\RegistryPowerCleaner\RegPowerClean.exe

Script: Quarantine, Delete, BC delete rpc.job The task has not yet run.

Elements detected - 2, recognized as trusted - 0

SPI/LSP settings

Namespace providers (NSP)

Manufacturer Status EXE file Description GUID

Detected - 3, recognized as trusted - 3

Transport protocol providers (TSP, LSP)

Manufacturer EXE file Description

Detected - 15, recognized as trusted - 15

Results of automatic SPI settings check

 

LSP settings checked. No errors detected

 

TCP/UDP ports

Port Status Remote Host Remote Port Application Notes

TCP ports

UDP ports

Downloaded Program Files (DPF)

File name Description Manufacturer CLSID Source URL

Microsoft XML Parser for Java

Delete file://C:\WINDOWS\Java\classes\xmldso.cab

C:\WINDOWS\Downloaded Program Files\msgrchkr.dll

Script: Quarantine, Delete, BC delete Zone.com Checkers for MSN Messenger Copyright © 1995-2004 Microsoft Corporation {20A60F0D-9AFA-4515-A0FD-83BD84642501}

Delete http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

Script: Quarantine, Delete, BC delete Java Platform SE binary Copyright © 2004 {8AD9C840-044E-11D1-B3E9-00805F499D93}

Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab

{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}

Delete http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab

C:\WINDOWS\Downloaded Program Files\zylomgamesplayer.dll

Script: Quarantine, Delete, BC delete Zylom Games Player Copyright 2004 {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}

Delete http://game14.zylom.com/activex/zylomgamesplayer.cab

C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll

Script: Quarantine, Delete, BC delete Zone.com Stats Client for MSN Messenger Copyright © 1995-2004 Microsoft Corporation {C3F79A2B-B9B4-4A66-B012-3EE46475B072}

Delete http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

Script: Quarantine, Delete, BC delete Java Platform SE binary Copyright © 2004 {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab

C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

Script: Quarantine, Delete, BC delete Java Platform SE binary Copyright © 2004 {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab

C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

Script: Quarantine, Delete, BC delete Java Platform SE binary Copyright © 2004 {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab

C:\Arquivos de programas\Java\jre1.6.0_07\bin\ssv.dll

Script: Quarantine, Delete, BC delete Java Platform SE binary Copyright © 2004 {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab

C:\Arquivos de programas\Java\jre1.6.0_07\bin\npjpi160_07.dll

Script: Quarantine, Delete, BC delete Java Plug-in 1.6.0_07 for Netscape Navigator (DLL Helper) Copyright © 2004 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

Delete http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab

C:\Arquivos de programas\GbPlugin\GbpDist.dll

Script: Quarantine, Delete, BC delete GbpDist Module Copyright © 2008 {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931}

Delete https://imagem.caixa.gov.br/cab/gbpdist.cab

Elements detected - 12, recognized as trusted - 0

Control Panel Applets (CPL)

File name Description Manufacturer

C:\WINDOWS\system32\ImageDrive.cpl

Script: Quarantine, Delete, BC delete

C:\WINDOWS\system32\ISUSPM.cpl

Script: Quarantine, Delete, BC delete InstallShield Update Service Update Manager Applet Copyright © 1990-2004 InstallShield Software Corporation

C:\WINDOWS\system32\javacpl.cpl

Script: Quarantine, Delete, BC delete Java Control Panel Copyright © 2004

C:\WINDOWS\system32\main.cpl

Script: Quarantine, Delete, BC delete DLL do 'Painel de controle' Copyright © Microsoft Corp. 1991-1999

C:\WINDOWS\system32\ncpa.cpl

Script: Quarantine, Delete, BC delete Conexхes de rede no painel de controle © Microsoft Corporation. Todos os direitos reservados.

C:\WINDOWS\system32\nwc.cpl

Script: Quarantine, Delete, BC delete Aplicativo Serviзo de cliente para NetWare © Microsoft Corporation. Todos os direitos reservados.

C:\WINDOWS\system32\telephon.cpl

Script: Quarantine, Delete, BC delete Painel de controle de telefonia © Microsoft Corporation. Todos os direitos reservados.

Elements detected - 28, recognized as trusted - 21

Active Setup

File name Description Manufacturer CLSID

Elements detected - 15, recognized as trusted - 15

HOSTS file

Hosts file record

 

 

127.0.0.1 localhost

 

Protocols and handlers

File name Type Description Manufacturer CLSID

C:\WINDOWS\system32\mscoree.dll

Script: Quarantine, Delete, BC delete Protocol Microsoft .NET Runtime Execution Engine () © Microsoft Corporation. All rights reserved. {1E66F26B-79EE-11D2-8710-00C04F79ED0D}

C:\WINDOWS\system32\mscoree.dll

Script: Quarantine, Delete, BC delete Protocol Microsoft .NET Runtime Execution Engine () © Microsoft Corporation. All rights reserved. {1E66F26B-79EE-11D2-8710-00C04F79ED0D}

C:\WINDOWS\system32\mscoree.dll

Script: Quarantine, Delete, BC delete Protocol Microsoft .NET Runtime Execution Engine () © Microsoft Corporation. All rights reserved. {1E66F26B-79EE-11D2-8710-00C04F79ED0D}

C:\Arquivos de programas\AVG\AVG8\avgpp.dll

Script: Quarantine, Delete, BC delete Handler Safe Search pluggable protocol (linkscanner: ExPLabs.com Pluggable Protocol) Copyright © 2008 AVG Technologies CZ, s.r.o. {F274614C-63F8-47D5-A4D1-FBDDE494F8D1}

Elements detected - 33, recognized as trusted - 29

Suspicious objects

File Description Type

C:\WINDOWS\system32\serwvdrv.dll

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\umdmxfrm.dll

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\msacm32.drv

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\msg711.acm

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\msgsm32.acm

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\tssoft32.acm

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\tsd32.dll

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\msg723.acm

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\sirenacm.dll

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\scg726.acm

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\alf2cd.acm

Script: Quarantine, Delete, BC delete Suspicion for Keylogger Suspicion for Keylogger or Trojan DLL

 

Windows version: Microsoft Windows XP, Build=2600, SP="Service Pack 3"

System Restore: enabled

System booted in Safe Mode

1.1 Searching for user-mode API hooks

Analysis: kernel32.dll, export table found in section .text

Function kernel32.dll:CreateProcessA (99) intercepted, method ProcAddressHijack.GetProcAddress ->7C80236B->61F03F42

Hook kernel32.dll:CreateProcessA (99) blocked

Function kernel32.dll:CreateProcessW (103) intercepted, method ProcAddressHijack.GetProcAddress ->7C802336->61F04040

Hook kernel32.dll:CreateProcessW (103) blocked

Function kernel32.dll:FreeLibrary (241) intercepted, method ProcAddressHijack.GetProcAddress ->7C80AC6E->61F041FC

Hook kernel32.dll:FreeLibrary (241) blocked

Function kernel32.dll:GetModuleFileNameA (373) intercepted, method ProcAddressHijack.GetProcAddress ->7C80B55F->61F040FB

Hook kernel32.dll:GetModuleFileNameA (373) blocked

Function kernel32.dll:GetModuleFileNameW (374) intercepted, method ProcAddressHijack.GetProcAddress ->7C80B465->61F041A0

Hook kernel32.dll:GetModuleFileNameW (374) blocked

Function kernel32.dll:GetProcAddress (409) intercepted, method ProcAddressHijack.GetProcAddress ->7C80AE30->61F04648

Hook kernel32.dll:GetProcAddress (409) blocked

Function kernel32.dll:LoadLibraryA (581) intercepted, method ProcAddressHijack.GetProcAddress ->7C801D7B->61F03C6F

Hook kernel32.dll:LoadLibraryA (581) blocked

>>> Functions LoadLibraryA - preventing AVZ process from being intercepted by address replacement !!)

Function kernel32.dll:LoadLibraryExA (582) intercepted, method ProcAddressHijack.GetProcAddress ->7C801D53->61F03DAF

Hook kernel32.dll:LoadLibraryExA (582) blocked

>>> Functions LoadLibraryExA - preventing AVZ process from being intercepted by address replacement !!)

Function kernel32.dll:LoadLibraryExW (583) intercepted, method ProcAddressHijack.GetProcAddress ->7C801AF5->61F03E5A

Hook kernel32.dll:LoadLibraryExW (583) blocked

Function kernel32.dll:LoadLibraryW (584) intercepted, method ProcAddressHijack.GetProcAddress ->7C80AEDB->61F03D0C

Hook kernel32.dll:LoadLibraryW (584) blocked

IAT modification detected: LoadLibraryW - 00B40010<>7C80AEDB

Analysis: ntdll.dll, export table found in section .text

Analysis: user32.dll, export table found in section .text

Analysis: advapi32.dll, export table found in section .text

Analysis: ws2_32.dll, export table found in section .text

Analysis: wininet.dll, export table found in section .text

Analysis: rasapi32.dll, export table found in section .text

Analysis: urlmon.dll, export table found in section .text

Analysis: netapi32.dll, export table found in section .text

1.2 Searching for kernel-mode API hooks

Driver loaded successfully

Driver communication failure [00000002] - [1]

1.4 Searching for masking processes and drivers

Checking not performed: extended monitoring driver (AVZPM) is not installed

Driver loaded successfully

Driver communication failure [00000002] - [1]

C:\WINDOWS\system32\serwvdrv.dll --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\serwvdrv.dll>>> Behavioral analysis

Behaviour typical for keyloggers not detected

C:\WINDOWS\system32\umdmxfrm.dll --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\umdmxfrm.dll>>> Behavioral analysis

Behaviour typical for keyloggers not detected

C:\WINDOWS\system32\msacm32.drv --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\msacm32.drv>>> Behavioral analysis

Behaviour typical for keyloggers not detected

C:\WINDOWS\system32\msg711.acm --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\msg711.acm>>> Behavioral analysis

Behaviour typical for keyloggers not detected

C:\WINDOWS\system32\msgsm32.acm --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\msgsm32.acm>>> Behavioral analysis

Behaviour typical for keyloggers not detected

C:\WINDOWS\system32\tssoft32.acm --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\tssoft32.acm>>> Behavioral analysis

Behaviour typical for keyloggers not detected

C:\WINDOWS\system32\tsd32.dll --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\tsd32.dll>>> Behavioral analysis

Behaviour typical for keyloggers not detected

C:\WINDOWS\system32\msg723.acm --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\msg723.acm>>> Behavioral analysis

Behaviour typical for keyloggers not detected

C:\WINDOWS\system32\sirenacm.dll --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\sirenacm.dll>>> Behavioral analysis

Behaviour typical for keyloggers not detected

C:\WINDOWS\system32\scg726.acm --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\scg726.acm>>> Behavioral analysis

Behaviour typical for keyloggers not detected

C:\WINDOWS\system32\alf2cd.acm --> Suspicion for Keylogger or Trojan DLL

C:\WINDOWS\system32\alf2cd.acm>>> Behavioral analysis

Behaviour typical for keyloggers not detected

Note: Do NOT delete suspicious files, send them for analysis (see FAQ for more details), because there are lots of useful hooking DLLs

>> Services: potentially dangerous service allowed: RemoteRegistry (Registro remoto)

>> Services: potentially dangerous service allowed: TermService (Serviзos de terminal)

>> Services: potentially dangerous service allowed: SSDPSRV (Serviзo de descoberta SSDP)

>> Services: potentially dangerous service allowed: Schedule (Agendador de tarefas)

>> Services: potentially dangerous service allowed: mnmsrvc (Compartilhamento remoto da бrea de trabalho do NetMeeting)

>> Services: potentially dangerous service allowed: RDSessMgr (Gerenciador de sessгo de ajuda de бrea de trabalho remota)

> Services: please bear in mind that the set of services depends on the use of the PC (home PC, office PC connected to corporate network, etc)!

>> Security: disk drives' autorun is enabled

>> Security: administrative shares (C$, D$ ...) are enabled

>> Security: anonymous user access is enabled

>> Security: sending Remote Assistant queries is enabled

>> Disable HDD autorun

>> Disable autorun from network drives

>> Disable CD/DVD autorun

>> Disable removable media autorun

System Analysis in progress

 

 

Script commands

 

Add commands to script:

 

* Blocking hooks using Anti-Rootkit

* Enable AVZGuard

* BootCleaner - import list of deleted files

* Registry cleanup after deleting files

* BootCleaner - activate

* Reboot

* Insert template for QuarantineFile() - quarantining file

* Insert template for BC_QrFile() - quarantining file via BootCleaner

* Insert template for DeleteFile() - deleting file

* Insert template for DelCLSID() - deleting CLSID item from registry

 

Additional operations:

 

* Performance tweaking: disable service RemoteRegistry (Registro remoto)

* Performance tweaking: disable service TermService (Serviзos de terminal)

* Performance tweaking: disable service SSDPSRV (Serviзo de descoberta SSDP)

* Performance tweaking: disable service Schedule (Agendador de tarefas)

* Performance tweaking: disable service mnmsrvc (Compartilhamento remoto da бrea de trabalho do NetMeeting)

* Performance tweaking: disable service RDSessMgr (Gerenciador de sessгo de ajuda de бrea de trabalho remota)

* Security tweaking: disable CD autorun

* Security tweaking: disable administrative shares

* Security tweaking: disable anonymous user access

* Security: disable sending Remote Assistant queries

 

 

File list

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa samea,

 

Desative o seu anti-vírus temporariamente.

 

Execute um Scan Online com o Kasperky Virusscanner.

 

* Clique em Clipboard01-1.jpg;

* Quando questionado sobre a instalação do ActiveX, clique sobre Clipboard015.jpg;

* Aguarde a instalação e a atualização. Depois clique em Clipboard013.jpg;

* Clique agora sobre Clipboard016.jpg;

* Nas opções do scan (settings), certifique-se de que as entradas abaixo estão selecionadas:

  • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard).
    Scan Options:
    Scan Archives Scan Mail Bases

* Clique em Clipboard014.jpg;

* Clique em My Computer para que seja feito um scan completo em seu sistema;

* Será iniciado o scan e a varredura poderá demorar um pouco. Seja paciente e aguarde;

* No final do scan, clique no botão Save as Text;

* Salve o log com os resultados e cole o conteúdo em sua próxima mensagem.

 

Abraços.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.