Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Davi Vasconcellos

[Arquivado] Não consigo executar nenhum antivirus ou antispyware.

Recommended Posts

Há dois meses formatei o PC e agora ele não deixa eu usar o Gerenciador de Tarefas ("o 'Gerenciador de tarefas' foi desativado pelo administrador"), não consigo executar Antivírus, aparecem erros de script quando inicio o XP, Não reinicia em Modo Seguro, etc. Uma vez cliquei no ícone do Avira (ou foi do Avast) e o PC reiniciou.

Ficarei muito agradecido se me ajudarem. Sei que vai ser uma batalha, mas temos que ter determinação!

 

Salvei o Hijackthis no disco C:\ . Cliquei e apareceu 'Editor Desconhecido' mesmo assim cliquei Executar, segui os procedimentos e aqui segue o log:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 01:24:48, on 19/3/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\FixCamera.exe

C:\WINDOWS\tsnp2std.exe

C:\WINDOWS\vsnp2std.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\RALINK\Common\RaUI.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\MSN Messenger\usnsvc.exe

C:\Hijackthis\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec...amp;gc=1&q=

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec...amp;gc=1&q=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirec...p;gc=1&q=%s

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9000/proxy.pac

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Arquivos de programas\AskSearch\bin\DefaultSearch.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Arquivos de programas\HP\Smart Web Printing\SmartWebPrinting.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: BywifiBHO - {C4743D3E-20D7-4B52-84F2-5E4E277B2D82} - C:\Arquivos de programas\Bywifi\bywifiie.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll

O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe

O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe

O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [bywifi] C:\Arquivos de programas\Bywifi\bywifi.exe "-silent"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ares] "C:\Documents and Settings\Marília\Meus documentos\Ares\Ares.exe" -h

O4 - HKCU\..\Run: [bywifi] C:\Arquivos de programas\Bywifi\bywifi.exe "-silent"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Arquivos de programas\RALINK\Common\RaUI.exe

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O17 - HKLM\System\CS1\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O17 - HKLM\System\CS2\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O23 - Service: Google Update Service (gupdate1c9947de6b77398) (gupdate1c9947de6b77398) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 7887 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe o ComboFix em:

ComboFix

 

1) Desabilite o seu anti-vírus temporariamente;

 

2) Dê um duplo-clique no combofix.exe e aguarde (o processo total demora cerca de 10 minutos);

 

3) A janela de “NEGAÇÃO DE GARANTIA DO SOFTWARE” abrir-se-á. Leia atentamente o texto contido nesta janela e clique sobre “SIM” para continuar.

 

PS.: Caso não concorde com os termos clique sobre “NÃO” para sair do software, cabendo lembrar que o processo de desinfecção não será possível sem a continuidade do ComboFix.

 

4) Outra janela irá abrir, caso a sua máquina não possua o CONSOLE DE RECUPERAÇÃO DO WINDOWS. É recomendável executar a instalação do console ante de dar continuidade ao processo, pois tal ação proporcionará a garantia de que o sistema poderá ser recuperado em caso de problemas durante a varredura.

 

Clique sobre “SIM” e aguarde, pois o processo de instalação do console dar-se-á automaticamente através do próprio ComboFix. Ele poderá demorar alguns minutos (dependerá da velocidade de sua conexão), portanto seja paciente.

 

Quando a janela “INSTALANDO O CONSOLE DE RECUPERAÇÃO” aparecer clique em “OK”, depois clique sobre “SIM” para aceitar a licença EULA.

 

Ao término da instalação do console de recuperação abrir-se-á uma janela avisando que “O CONSOLE DE RECUPERAÇÃO FOI INSTALADA COM SUCESSO”.

 

Clique sobre “SIM” para continuar a varredura.

 

5) O ComboFix iniciará o AUTOSCAN (aguarde).

 

ATENÇÃO: Não clique na janela do ComboFix, nem termine o processo abruptamente enquanto a ferramenta estiver sendo executada, pois isto implicará na desconfiguração de seu desktop (ele ficará todo branco).

 

Ao término do processo a máquina será reiniciada para a emissão do relatório.

 

6) Ao reiniciar a máquina o ComboFix irá executar o FIND3M para a criação do relatório final da varredura. O log ficará alocado em C:\ComboFix.txt.

 

7) Reabilite o seu anti-vírus;

 

8) Preciso que você cole o conteúdo do ComboFix.txt e do novo log Hijackthis em sua próxima resposta.

 

OBS.1: Caso apareça uma mensagem avisando que ESTE NÃO É UM APLICATIVO WIN 32 VÁLIDO baixe o ComboFix novamente, mas salve-o em seu Desktop como KomboFix. Em último caso, tente utilizar o ComboFix em MODO SEGURO.

 

OBS.2: Caso haja um clique sobre a janela do ComboFix em execução, ela irá MAXIMIZAR, sobrepondo-se sobre as demais. Para minimizá-la novamente basta utilizar a combinação ALT + TAB.

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 09-03-19.02 - Marília 2009-03-21 10:04:59.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.503.213 [GMT -3:00]

Executando de: c:\documents and settings\Marília\Desktop\ComboFix.exe

* Criado um novo ponto de restauro

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\IE4 Error Log.txt

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_DAC970NT

-------\Service_dac970nt

 

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-02-21 to 2009-03-21 ))))))))))))))))))))))))))))

.

 

2009-03-21 08:58 . 2009-03-21 08:58 <DIR> d-------- c:\arquivos de programas\XP Codec Pack

2009-03-21 08:58 . 2008-07-09 06:05 421,888 --a------ c:\windows\system32\ac3filter.acm

2009-03-21 08:33 . 2008-08-05 20:10 1,684,736 --a------ c:\windows\system32\drivers\Ambfilt.sys

2009-03-21 08:33 . 2006-01-04 15:41 1,389,056 --a------ c:\windows\system32\drivers\Monfilt.sys

2009-03-21 08:33 . 2008-10-23 17:42 290,816 --a------ c:\windows\vncutil.exe

2009-03-21 08:33 . 2008-06-24 14:46 104,992 --a------ c:\windows\RtkAudioService.exe

2009-03-21 08:33 . 2009-02-03 16:35 35,840 --a------ c:\windows\system32\RtkCoInstXP.dll

2009-03-21 05:20 . 2009-03-21 05:20 <DIR> d-------- c:\arquivos de programas\MSXML 4.0

2009-03-21 03:39 . 2008-06-14 14:34 272,384 --------- c:\windows\system32\drivers\bthport.sys

2009-03-21 03:39 . 2008-06-14 14:34 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys

2009-03-21 03:26 . 2008-08-14 10:24 2,193,408 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe

2009-03-21 03:26 . 2008-08-14 10:24 2,149,376 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe

2009-03-21 03:26 . 2008-08-14 10:24 2,070,272 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe

2009-03-21 03:26 . 2008-08-14 10:24 2,028,032 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe

2009-03-21 03:19 . 2008-10-24 08:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2009-03-21 03:00 . 2009-03-21 05:26 <DIR> d--h----- c:\windows\$hf_mig$

2009-03-21 03:00 . 2006-05-25 10:29 22,752 --a------ c:\windows\system32\spupdsvc.exe

2009-03-19 13:11 . 2009-03-19 13:11 <DIR> d--h----- c:\windows\PIF

2009-03-19 12:56 . 2009-03-19 12:56 <DIR> d-------- c:\arquivos de programas\Lavalys

2009-03-18 23:49 . 2009-03-19 01:24 <DIR> d-------- C:\Hijackthis

2009-03-11 22:56 . 2009-03-20 22:40 <DIR> d-------- C:\BywifiShare

2009-03-11 22:56 . 2009-03-11 22:56 <DIR> d-------- C:\BywifiSave

2009-03-11 22:56 . 2009-03-20 22:40 <DIR> d-------- c:\arquivos de programas\Bywifi

2009-03-11 22:28 . 2009-03-11 22:28 <DIR> d-------- c:\arquivos de programas\AskSearch

2009-03-11 22:28 . 2002-01-05 14:37 344,064 --a------ c:\windows\system32\msvcr70.dll

2009-03-01 18:30 . 2009-03-01 18:30 921,624 --a------ C:\snp2sxp-001.raw

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-03-21 11:33 --------- d-----w c:\arquivos de programas\Realtek

2009-03-12 01:33 --------- d-----w c:\arquivos de programas\Google

2009-03-02 06:13 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\Image Zone Express

2009-02-14 16:40 --------- d-----w c:\arquivos de programas\Unity

2009-02-14 09:05 46,129 ----a-w c:\windows\Fonts\angelina.zip

2009-02-14 09:05 34,131 ----a-w c:\windows\Fonts\blazed.zip

2009-02-14 09:05 141,855 ----a-w c:\windows\Fonts\amaze.zip

2009-02-14 09:04 40,104 ----a-w c:\windows\Fonts\banana_split.zip

2009-02-14 09:04 33,383 ----a-w c:\windows\Fonts\loki_cola.zip

2009-02-14 09:03 74,634 ----a-w c:\windows\Fonts\base_02.zip

2009-02-14 09:03 56,008 ----a-w c:\windows\Fonts\dark_crystal.zip

2009-02-14 09:03 29,847 ----a-w c:\windows\Fonts\adine_kirnberg.zip

2009-02-14 09:03 29,082 ----a-w c:\windows\Fonts\walt_disney.zip

2009-02-14 09:02 25,184 ----a-w c:\windows\Fonts\french_grotesque.zip

2009-02-14 09:02 10,869 ----a-w c:\windows\Fonts\freshman.zip

2009-02-14 09:00 8,655 ----a-w c:\windows\Fonts\grado_gradoo.zip

2009-02-14 09:00 28,674 ----a-w c:\windows\Fonts\graffiti.zip

2009-02-14 09:00 10,431 ----a-w c:\windows\Fonts\grand_stylus.zip

2009-02-14 08:59 26,230 ----a-w c:\windows\Fonts\gravicon_display.zip

2009-02-14 08:58 48,877 ----a-w c:\windows\Fonts\lelf_noir_du_mal.zip

2009-02-14 08:58 21,611 ----a-w c:\windows\Fonts\gregs_other_hand.zip

2009-02-14 08:58 16,680 ----a-w c:\windows\Fonts\gregs_hand.zip

2009-02-12 02:30 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!

2009-02-12 00:09 --------- d-----w c:\arquivos de programas\Windows Live

2009-02-12 00:09 --------- d-----w c:\arquivos de programas\MSN Messenger

2009-02-12 00:09 --------- d-----w c:\arquivos de programas\Messenger Plus! Live

2009-02-09 14:06 1,846,912 ----a-w c:\windows\system32\win32k.sys

2009-02-06 21:04 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\SlipStream

2009-02-03 20:32 18,085,888 ----a-w c:\windows\RTHDCPL.EXE

2009-02-03 20:22 5,030,912 ----a-w c:\windows\system32\drivers\RtkHDAud.sys

2009-02-01 04:06 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\Media Player Classic

2009-01-31 14:54 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Yahoo! Companion

2009-01-31 14:32 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\Yahoo!

2009-01-31 14:32 --------- d-----w c:\arquivos de programas\Yahoo!

2009-01-30 14:15 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\NOS

2009-01-30 14:15 --------- d-----w c:\arquivos de programas\NOS

2009-01-30 00:16 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2009-01-21 18:54 1,206,816 ----a-w c:\windows\RtlUpd.exe

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 226864]

"swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-20 146680]

"ares"="c:\documents and settings\Marília\Meus documentos\Ares\Ares.exe" [2009-01-27 983040]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 226864]

"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 180224]

"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 151552]

"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 188416]

"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 122880]

"FixCamera"="c:\windows\FixCamera.exe" [2007-07-11 20480]

"tsnp2std"="c:\windows\tsnp2std.exe" [2007-05-10 348160]

"snp2std"="c:\windows\vsnp2std.exe" [2007-09-28 413696]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 112496]

"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 c:\windows\RTHDCPL.EXE]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-10 191488]

HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 284248]

Ralink Wireless Utility.lnk - c:\arquivos de programas\RALINK\Common\RaUI.exe [2009-01-10 671744]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"DisableTaskMgr"= 1 (0x1)

"DisableRegistryTools"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.ffds"= ffdshow.ax

"msacm.ac3filter"= ac3filter.acm

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

"UacDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]

"AntiVirusOverride"=dword:00000001

"AntiVirusDisableNotify"=dword:00000001

"FirewallDisableNotify"=dword:00000001

"FirewallOverride"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"UacDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Lib\\NeroCheck.exe"=

"c:\\Arquivos de programas\\HP\\HP Software Update\\HPWuSchd2.exe"=

"c:\\WINDOWS\\ALCMTR.EXE"=

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=

"c:\\WINDOWS\\system32\\igfxpers.exe"=

"c:\\WINDOWS\\system32\\userinit.exe"=

"c:\\WINDOWS\\system32\\igfxtray.exe"=

"c:\\WINDOWS\\RTHDCPL.EXE"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqSTE08.exe"=

"c:\\WINDOWS\\system32\\hkcmd.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Arquivos de programas\\RALINK\\Common\\RaUI.exe"=

"c:\\Arquivos de programas\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=

"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Lib\\NMIndexStoreSvr.exe"=

"c:\\WINDOWS\\tsnp2std.exe"=

"c:\\WINDOWS\\system32\\netsh.exe"=

"c:\\Arquivos de programas\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe"=

"c:\\WINDOWS\\vsnp2std.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\usnsvc.exe"=

"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Lib\\NMBgMonitor.exe"=

"c:\\Arquivos de programas\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=

"c:\\WINDOWS\\system32\\WISPTIS.EXE"=

"c:\\Arquivos de programas\\Bywifi\\bywifi.exe"=

"c:\\Documents and Settings\\Marília\\Meus documentos\\Ares\\Ares.exe"=

"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe"=

 

S2 gupdate1c9947de6b77398;Google Update Service (gupdate1c9947de6b77398);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-21 133104]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-03-21 1684736]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-03-21 c:\windows\Tasks\GoogleUpdateTaskMachine.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-21 20:41]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

uInternet Connection Wizard,ShellNext = hxxp://www.google.com.br/

uInternet Settings,ProxyOverride = local

uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=%s

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

TCP: {255D53F9-DA11-4382-A77C-C183289A2512} = 192.168.1.1

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-21 10:07:19

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

c:\windows\explorer.exe [1444] 0x820183B8

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_USERS\S-1-5-21-606747145-963894560-1177238915-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\wdfmgr.exe

c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

c:\arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe

.

**************************************************************************

.

Tempo para conclusão: 2009-03-21 10:09:36 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-03-21 13:09:33

 

Pré-execução: 13 pasta(s) 137.954.934.784 bytes disponíveis

Pós execução: 13 pasta(s) 138,638,065,664 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

218 --- E O F --- 2009-03-21 08:31:15

 

 

 

------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:13:29, on 21/3/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\tsnp2std.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Documents and Settings\Marília\Meus documentos\Ares\Ares.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Hijackthis\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec...amp;gc=1&q=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirec...p;gc=1&q=%s

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Arquivos de programas\HP\Smart Web Printing\SmartWebPrinting.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll

O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe

O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe

O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ares] "C:\Documents and Settings\Marília\Meus documentos\Ares\Ares.exe" -h

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Arquivos de programas\RALINK\Common\RaUI.exe

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O17 - HKLM\System\CS1\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O17 - HKLM\System\CS2\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O23 - Service: Google Update Service (gupdate1c9947de6b77398) (gupdate1c9947de6b77398) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 7271 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

1ºPasso:

CFScript

 

Copie,todo conteúdo citado abaixo e cole no Bloco de Notas.

Salve o arquivo na área de trabalho com o nome de: CFScript.txt

File::

c:\\Arquivos de programas\\Bywifi\\bywifi.exe

Registry::

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"DisableTaskMgr"= 1 (0x1)

"DisableRegistryTools"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

"UacDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]

"AntiVirusOverride"=dword:00000001

"AntiVirusDisableNotify"=dword:00000001

"FirewallDisableNotify"=dword:00000001

"FirewallOverride"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"UacDisableNotify"=dword:00000001

[-HKEY_LOCAL_MACHINE \ SOFTWARE \ Bywifi]

[-HKEY_CURRENT_USER \ Software \ Bywifi]

[-HKEY_USERS\S-1-5-21-606747145-963894560-1177238915-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

Dirlook::

C:\BywifiSave

C:\BywifiShare

 

Arraste o CFScript.txt até o ícone do Combofix, conforme ilustração abaixo:

cfscript.gif

 

Atenda à solicitação,que deverá surgir,para rodar o ComboFix

OBS: Arraste o CFScript até para o ícone até que apareça a janela(pequena) do combofix

Ao final poste o ComboFix.txt juntamente com o novo log do hijackthis

 

Obs.: Execute a ação com o seu pendrive conectado ao PC.

 

2º Passo:

 

# Execute a ferramenta HiJackThis;

 

# Selecione o(s) item(s) abaixo indicado(s):

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec...amp;gc=1&q=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirec...p;gc=1&q=%s

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

 

# Clique no botão "Fix checked";

 

Reinicie em modo normal gere um novo log do Hijackthis e poste na sua próxima resposta.

 

Aguardo o retorno

Compartilhar este post


Link para o post
Compartilhar em outros sites

pendrive?

 

Obs.: Execute a ação com o seu pendrive conectado ao PC.

 

Qual dos dois eu posto ?

 

Ao final poste o ComboFix.txt juntamente com o novo log do hijackthis

 

ou

 

Reinicie em modo normal gere um novo log do Hijackthis e poste na sua próxima resposta

 

Aguardo o retorno

Compartilhar este post


Link para o post
Compartilhar em outros sites

Qual dos dois eu posto ? Você vai postar o ComboFix.txt e o novo log do hijackthis, ou seja os dois.

 

As duas mensagens são alertas para você não se esquecer de gerar um novo log na primeira com enfase na reiniciação do sistema mais só se gera o novo log do hijackthis uma vez depois de reiniciado em modo normal.

Espero ter sanado suas dúvidas.

Sobre o pen-drive é CASO você tenha um, conectar ele ao pc durante o scan pen-drive ou (cartão de memória)

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 09-03-19.02 - Marília 2009-03-23 7:23:28.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.503.229 [GMT -3:00]

Executando de: c:\documents and settings\Marília\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\Marília\Desktop\CFScript.txt

* Criado um novo ponto de restauro

 

FILE ::

c:\\Arquivos de programas\\Bywifi\\bywifi.exe

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\\Arquivos de programas\\Bywifi\\bywifi.exe

E:\autorun.inf

E:\xpfpn.pif

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_DAC970NT

-------\Service_dac970nt

 

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-02-23 to 2009-03-23 ))))))))))))))))))))))))))))

.

 

2009-03-21 08:58 . 2009-03-21 08:58 <DIR> d-------- c:\arquivos de programas\XP Codec Pack

2009-03-21 08:58 . 2008-07-09 06:05 421,888 --a------ c:\windows\system32\ac3filter.acm

2009-03-21 08:33 . 2008-08-05 20:10 1,684,736 --a------ c:\windows\system32\drivers\Ambfilt.sys

2009-03-21 08:33 . 2006-01-04 15:41 1,389,056 --a------ c:\windows\system32\drivers\Monfilt.sys

2009-03-21 08:33 . 2008-10-23 17:42 290,816 --a------ c:\windows\vncutil.exe

2009-03-21 08:33 . 2008-06-24 14:46 104,992 --a------ c:\windows\RtkAudioService.exe

2009-03-21 08:33 . 2009-02-03 16:35 35,840 --a------ c:\windows\system32\RtkCoInstXP.dll

2009-03-21 05:20 . 2009-03-21 05:20 <DIR> d-------- c:\arquivos de programas\MSXML 4.0

2009-03-21 03:39 . 2008-06-14 14:34 272,384 --------- c:\windows\system32\drivers\bthport.sys

2009-03-21 03:39 . 2008-06-14 14:34 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys

2009-03-21 03:26 . 2008-08-14 10:24 2,193,408 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe

2009-03-21 03:26 . 2008-08-14 10:24 2,149,376 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe

2009-03-21 03:26 . 2008-08-14 10:24 2,070,272 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe

2009-03-21 03:26 . 2008-08-14 10:24 2,028,032 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe

2009-03-21 03:19 . 2008-10-24 08:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2009-03-21 03:00 . 2009-03-21 05:26 <DIR> d--h----- c:\windows\$hf_mig$

2009-03-21 03:00 . 2006-05-25 10:29 22,752 --a------ c:\windows\system32\spupdsvc.exe

2009-03-19 13:11 . 2009-03-19 13:11 <DIR> d--h----- c:\windows\PIF

2009-03-19 12:56 . 2009-03-19 12:56 <DIR> d-------- c:\arquivos de programas\Lavalys

2009-03-18 23:49 . 2009-03-21 10:24 <DIR> d-------- C:\Hijackthis

2009-03-11 22:56 . 2009-03-20 22:40 <DIR> d-------- C:\BywifiShare

2009-03-11 22:56 . 2009-03-11 22:56 <DIR> d-------- C:\BywifiSave

2009-03-11 22:56 . 2009-03-23 07:23 <DIR> d-------- c:\arquivos de programas\Bywifi

2009-03-11 22:28 . 2009-03-11 22:28 <DIR> d-------- c:\arquivos de programas\AskSearch

2009-03-11 22:28 . 2002-01-05 14:37 344,064 --a------ c:\windows\system32\msvcr70.dll

2009-03-01 18:30 . 2009-03-01 18:30 921,624 --a------ C:\snp2sxp-001.raw

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-03-21 11:33 --------- d-----w c:\arquivos de programas\Realtek

2009-03-12 01:33 --------- d-----w c:\arquivos de programas\Google

2009-03-02 06:13 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\Image Zone Express

2009-02-14 16:40 --------- d-----w c:\arquivos de programas\Unity

2009-02-14 09:05 46,129 ----a-w c:\windows\Fonts\angelina.zip

2009-02-14 09:05 34,131 ----a-w c:\windows\Fonts\blazed.zip

2009-02-14 09:05 141,855 ----a-w c:\windows\Fonts\amaze.zip

2009-02-14 09:04 40,104 ----a-w c:\windows\Fonts\banana_split.zip

2009-02-14 09:04 33,383 ----a-w c:\windows\Fonts\loki_cola.zip

2009-02-14 09:03 74,634 ----a-w c:\windows\Fonts\base_02.zip

2009-02-14 09:03 56,008 ----a-w c:\windows\Fonts\dark_crystal.zip

2009-02-14 09:03 29,847 ----a-w c:\windows\Fonts\adine_kirnberg.zip

2009-02-14 09:03 29,082 ----a-w c:\windows\Fonts\walt_disney.zip

2009-02-14 09:02 25,184 ----a-w c:\windows\Fonts\french_grotesque.zip

2009-02-14 09:02 10,869 ----a-w c:\windows\Fonts\freshman.zip

2009-02-14 09:00 8,655 ----a-w c:\windows\Fonts\grado_gradoo.zip

2009-02-14 09:00 28,674 ----a-w c:\windows\Fonts\graffiti.zip

2009-02-14 09:00 10,431 ----a-w c:\windows\Fonts\grand_stylus.zip

2009-02-14 08:59 26,230 ----a-w c:\windows\Fonts\gravicon_display.zip

2009-02-14 08:58 48,877 ----a-w c:\windows\Fonts\lelf_noir_du_mal.zip

2009-02-14 08:58 21,611 ----a-w c:\windows\Fonts\gregs_other_hand.zip

2009-02-14 08:58 16,680 ----a-w c:\windows\Fonts\gregs_hand.zip

2009-02-12 02:30 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!

2009-02-12 00:09 --------- d-----w c:\arquivos de programas\Windows Live

2009-02-12 00:09 --------- d-----w c:\arquivos de programas\MSN Messenger

2009-02-12 00:09 --------- d-----w c:\arquivos de programas\Messenger Plus! Live

2009-02-09 14:06 1,846,912 ----a-w c:\windows\system32\win32k.sys

2009-02-06 21:04 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\SlipStream

2009-02-03 20:32 18,085,888 ----a-w c:\windows\RTHDCPL.EXE

2009-02-03 20:22 5,030,912 ----a-w c:\windows\system32\drivers\RtkHDAud.sys

2009-02-01 04:06 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\Media Player Classic

2009-01-31 14:54 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Yahoo! Companion

2009-01-31 14:32 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\Yahoo!

2009-01-31 14:32 --------- d-----w c:\arquivos de programas\Yahoo!

2009-01-30 14:15 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\NOS

2009-01-30 14:15 --------- d-----w c:\arquivos de programas\NOS

2009-01-30 00:16 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2009-01-21 18:54 1,206,816 ----a-w c:\windows\RtlUpd.exe

.

 

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

---- Directory of C:\BywifiSave ----

 

 

---- Directory of C:\BywifiShare ----

 

 

 

((((((((((((((((((((((((((((( SnapShot@2009-03-21_10.08.11.28 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-03-23 10:27:42 16,384 ----atw c:\windows\temp\Perflib_Perfdata_a68.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 226864]

"swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-20 146680]

"ares"="c:\documents and settings\Marília\Meus documentos\Ares\Ares.exe" [2009-01-27 983040]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 226864]

"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 180224]

"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 151552]

"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 188416]

"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 122880]

"FixCamera"="c:\windows\FixCamera.exe" [2007-07-11 20480]

"tsnp2std"="c:\windows\tsnp2std.exe" [2007-05-10 348160]

"snp2std"="c:\windows\vsnp2std.exe" [2007-09-28 413696]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 112496]

"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 c:\windows\RTHDCPL.EXE]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-10 191488]

HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 284248]

Ralink Wireless Utility.lnk - c:\arquivos de programas\RALINK\Common\RaUI.exe [2009-01-10 671744]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"DisableTaskMgr"= 1 (0x1)

"DisableRegistryTools"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.ffds"= ffdshow.ax

"msacm.ac3filter"= ac3filter.acm

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

"UacDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]

"AntiVirusOverride"=dword:00000001

"AntiVirusDisableNotify"=dword:00000001

"FirewallDisableNotify"=dword:00000001

"FirewallOverride"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"UacDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Lib\\NeroCheck.exe"=

"c:\\Arquivos de programas\\HP\\HP Software Update\\HPWuSchd2.exe"=

"c:\\WINDOWS\\ALCMTR.EXE"=

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=

"c:\\WINDOWS\\system32\\igfxpers.exe"=

"c:\\WINDOWS\\system32\\userinit.exe"=

"c:\\WINDOWS\\system32\\igfxtray.exe"=

"c:\\WINDOWS\\RTHDCPL.EXE"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqSTE08.exe"=

"c:\\WINDOWS\\system32\\hkcmd.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Arquivos de programas\\RALINK\\Common\\RaUI.exe"=

"c:\\Arquivos de programas\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=

"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Lib\\NMIndexStoreSvr.exe"=

"c:\\WINDOWS\\tsnp2std.exe"=

"c:\\WINDOWS\\system32\\netsh.exe"=

"c:\\Arquivos de programas\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe"=

"c:\\WINDOWS\\vsnp2std.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\usnsvc.exe"=

"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Lib\\NMBgMonitor.exe"=

"c:\\Arquivos de programas\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=

"c:\\WINDOWS\\system32\\WISPTIS.EXE"=

"c:\\Documents and Settings\\Marília\\Meus documentos\\Ares\\Ares.exe"=

"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe"=

 

S2 gupdate1c9947de6b77398;Google Update Service (gupdate1c9947de6b77398);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-21 133104]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-03-21 1684736]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-03-23 c:\windows\Tasks\GoogleUpdateTaskMachine.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-21 20:41]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

uInternet Connection Wizard,ShellNext = hxxp://www.google.com.br/

uInternet Settings,ProxyOverride = local

uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=%s

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

TCP: {255D53F9-DA11-4382-A77C-C183289A2512} = 192.168.1.1

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-23 07:27:37

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_USERS\S-1-5-21-606747145-963894560-1177238915-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\wdfmgr.exe

c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

c:\arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe

.

**************************************************************************

.

Tempo para conclusão: 2009-03-23 7:29:49 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-03-23 10:29:46

ComboFix2.txt 2009-03-21 13:09:37

 

Pré-execução: 13 pasta(s) 137.399.275.520 bytes disponíveis

Pós execução: 13 pasta(s) 137,459,597,312 bytes disponíveis

 

225 --- E O F --- 2009-03-21 08:31:15

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 07:59:42, on 23/3/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\FixCamera.exe

C:\WINDOWS\tsnp2std.exe

C:\WINDOWS\vsnp2std.exe

C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Documents and Settings\Marília\Meus documentos\Ares\Ares.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\RALINK\Common\RaUI.exe

C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Hijackthis\HiJackThis.exe

C:\WINDOWS\system32\wuauclt.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Arquivos de programas\HP\Smart Web Printing\SmartWebPrinting.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll

O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe

O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe

O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ares] "C:\Documents and Settings\Marília\Meus documentos\Ares\Ares.exe" -h

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Arquivos de programas\RALINK\Common\RaUI.exe

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O17 - HKLM\System\CS1\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O17 - HKLM\System\CS2\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O23 - Service: Google Update Service (gupdate1c9947de6b77398) (gupdate1c9947de6b77398) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 7050 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Siga os passos abaixo, um por vez↓:

 

Copie,todo conteúdo citado abaixo e cole no Bloco de Notas.

Salve o arquivo na área de trabalho com o nome de: CFScript.txt

Folder::

C:\BywifiShare

C:\BywifiSave

RegNull::

[HKEY_USERS\S-1-5-21-606747145-963894560-1177238915-1003\Software\Microsoft\SystemCertificates\AddressBook*]

Registry::

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000000

"FirewallOverride"=dword:00000000

"UacDisableNotify"=dword:00000000

"AntiVirusDisableNotify"=dword:00000000

"UpdatesDisableNotify"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]

"AntiVirusOverride"=dword:00000000

"AntiVirusDisableNotify"=dword:00000000

"FirewallDisableNotify"=dword:00000000

"FirewallOverride"=dword:00000000

"UpdatesDisableNotify"=dword:00000000

"UacDisableNotify"=dword:00000000

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 1 (0x0)

 

Arraste o CFScript.txt até o ícone do Combofix, conforme ilustração abaixo:

cfscript.gif

 

Atenda à solicitação,que deverá surgir,para rodar o ComboFix

OBS: Arraste o CFScript até para o ícone até que apareça a janela(pequena) do combofix

Ao final poste o ComboFix.txt juntamente com o novo log do hijackthis

 

Obs.: Execute a ação com o seu pendrive conectado ao PC.

 

2º Passo:

 

# Execute a ferramenta HiJackThis;

 

# Selecione o(s) item(s) abaixo indicado(s):

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

 

# Clique no botão "Fix checked";

 

Reinicie em modo normal gere um novo log do Hijackthis e poste na sua próxima resposta.

 

Aguardo o retorno

Compartilhar este post


Link para o post
Compartilhar em outros sites

Obs: Quando o Combofix começa a executar o scan aparece essa mensagem: Windows - A unidade não está pronta. Exception processing message c00000a3 parameters 75b3bf7c 4 75b3bf7c 75b3bf7c

 

Seguem os dois logs:

 

 

ComboFix 09-03-19.02 - Marília 2009-03-24 4:01:33.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.503.254 [GMT -3:00]

Executando de: c:\documents and settings\Marília\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\Marília\Desktop\CFScript.txt

* Criado um novo ponto de restauro

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\BywifiSave

C:\BywifiShare

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_DAC970NT

-------\Service_dac970nt

 

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-02-24 to 2009-03-24 ))))))))))))))))))))))))))))

.

 

2009-03-21 08:58 . 2009-03-21 08:58 <DIR> d-------- c:\arquivos de programas\XP Codec Pack

2009-03-21 08:58 . 2008-07-09 06:05 421,888 --a------ c:\windows\system32\ac3filter.acm

2009-03-21 08:33 . 2008-08-05 20:10 1,684,736 --a------ c:\windows\system32\drivers\Ambfilt.sys

2009-03-21 08:33 . 2006-01-04 15:41 1,389,056 --a------ c:\windows\system32\drivers\Monfilt.sys

2009-03-21 08:33 . 2008-10-23 17:42 290,816 --a------ c:\windows\vncutil.exe

2009-03-21 08:33 . 2008-06-24 14:46 104,992 --a------ c:\windows\RtkAudioService.exe

2009-03-21 08:33 . 2009-02-03 16:35 35,840 --a------ c:\windows\system32\RtkCoInstXP.dll

2009-03-21 05:20 . 2009-03-21 05:20 <DIR> d-------- c:\arquivos de programas\MSXML 4.0

2009-03-21 03:39 . 2008-06-14 14:34 272,384 --------- c:\windows\system32\drivers\bthport.sys

2009-03-21 03:39 . 2008-06-14 14:34 272,384 -----c--- c:\windows\system32\dllcache\bthport.sys

2009-03-21 03:26 . 2008-08-14 10:24 2,193,408 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe

2009-03-21 03:26 . 2008-08-14 10:24 2,149,376 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe

2009-03-21 03:26 . 2008-08-14 10:24 2,070,272 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe

2009-03-21 03:26 . 2008-08-14 10:24 2,028,032 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe

2009-03-21 03:19 . 2008-10-24 08:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

2009-03-21 03:00 . 2009-03-21 05:26 <DIR> d--h----- c:\windows\$hf_mig$

2009-03-21 03:00 . 2006-05-25 10:29 22,752 --a------ c:\windows\system32\spupdsvc.exe

2009-03-19 13:11 . 2009-03-19 13:11 <DIR> d--h----- c:\windows\PIF

2009-03-19 12:56 . 2009-03-19 12:56 <DIR> d-------- c:\arquivos de programas\Lavalys

2009-03-18 23:49 . 2009-03-23 08:02 <DIR> d-------- C:\Hijackthis

2009-03-11 22:56 . 2009-03-23 07:23 <DIR> d-------- c:\arquivos de programas\Bywifi

2009-03-11 22:28 . 2009-03-11 22:28 <DIR> d-------- c:\arquivos de programas\AskSearch

2009-03-11 22:28 . 2002-01-05 14:37 344,064 --a------ c:\windows\system32\msvcr70.dll

2009-03-01 18:30 . 2009-03-01 18:30 921,624 --a------ C:\snp2sxp-001.raw

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-03-21 11:33 --------- d-----w c:\arquivos de programas\Realtek

2009-03-12 01:33 --------- d-----w c:\arquivos de programas\Google

2009-03-02 06:13 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\Image Zone Express

2009-02-14 16:40 --------- d-----w c:\arquivos de programas\Unity

2009-02-14 09:05 46,129 ----a-w c:\windows\Fonts\angelina.zip

2009-02-14 09:05 34,131 ----a-w c:\windows\Fonts\blazed.zip

2009-02-14 09:05 141,855 ----a-w c:\windows\Fonts\amaze.zip

2009-02-14 09:04 40,104 ----a-w c:\windows\Fonts\banana_split.zip

2009-02-14 09:04 33,383 ----a-w c:\windows\Fonts\loki_cola.zip

2009-02-14 09:03 74,634 ----a-w c:\windows\Fonts\base_02.zip

2009-02-14 09:03 56,008 ----a-w c:\windows\Fonts\dark_crystal.zip

2009-02-14 09:03 29,847 ----a-w c:\windows\Fonts\adine_kirnberg.zip

2009-02-14 09:03 29,082 ----a-w c:\windows\Fonts\walt_disney.zip

2009-02-14 09:02 25,184 ----a-w c:\windows\Fonts\french_grotesque.zip

2009-02-14 09:02 10,869 ----a-w c:\windows\Fonts\freshman.zip

2009-02-14 09:00 8,655 ----a-w c:\windows\Fonts\grado_gradoo.zip

2009-02-14 09:00 28,674 ----a-w c:\windows\Fonts\graffiti.zip

2009-02-14 09:00 10,431 ----a-w c:\windows\Fonts\grand_stylus.zip

2009-02-14 08:59 26,230 ----a-w c:\windows\Fonts\gravicon_display.zip

2009-02-14 08:58 48,877 ----a-w c:\windows\Fonts\lelf_noir_du_mal.zip

2009-02-14 08:58 21,611 ----a-w c:\windows\Fonts\gregs_other_hand.zip

2009-02-14 08:58 16,680 ----a-w c:\windows\Fonts\gregs_hand.zip

2009-02-12 02:30 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Messenger Plus!

2009-02-12 00:09 --------- d-----w c:\arquivos de programas\Windows Live

2009-02-12 00:09 --------- d-----w c:\arquivos de programas\MSN Messenger

2009-02-12 00:09 --------- d-----w c:\arquivos de programas\Messenger Plus! Live

2009-02-09 14:06 1,846,912 ----a-w c:\windows\system32\win32k.sys

2009-02-06 21:04 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\SlipStream

2009-02-03 20:32 18,085,888 ----a-w c:\windows\RTHDCPL.EXE

2009-02-03 20:22 5,030,912 ----a-w c:\windows\system32\drivers\RtkHDAud.sys

2009-02-01 04:06 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\Media Player Classic

2009-01-31 14:54 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Yahoo! Companion

2009-01-31 14:32 --------- d-----w c:\documents and settings\Marília\Dados de aplicativos\Yahoo!

2009-01-31 14:32 --------- d-----w c:\arquivos de programas\Yahoo!

2009-01-30 14:15 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\NOS

2009-01-30 14:15 --------- d-----w c:\arquivos de programas\NOS

2009-01-30 00:16 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2009-01-21 18:54 1,206,816 ----a-w c:\windows\RtlUpd.exe

.

 

((((((((((((((((((((((((((((( SnapShot@2009-03-21_10.08.11.28 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-03-24 07:04:17 16,384 ----atw c:\windows\temp\Perflib_Perfdata_a70.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 226864]

"swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-20 146680]

"ares"="c:\documents and settings\Marília\Meus documentos\Ares\Ares.exe" [2009-01-27 983040]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 226864]

"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 180224]

"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 151552]

"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 188416]

"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 122880]

"FixCamera"="c:\windows\FixCamera.exe" [2007-07-11 20480]

"tsnp2std"="c:\windows\tsnp2std.exe" [2007-05-10 348160]

"snp2std"="c:\windows\vsnp2std.exe" [2007-09-28 413696]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 112496]

"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 c:\windows\RTHDCPL.EXE]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-01-10 191488]

HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 284248]

Ralink Wireless Utility.lnk - c:\arquivos de programas\RALINK\Common\RaUI.exe [2009-01-10 671744]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"DisableTaskMgr"= 1 (0x1)

"DisableRegistryTools"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.ffds"= ffdshow.ax

"msacm.ac3filter"= ac3filter.acm

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Lib\\NeroCheck.exe"=

"c:\\Arquivos de programas\\HP\\HP Software Update\\HPWuSchd2.exe"=

"c:\\WINDOWS\\ALCMTR.EXE"=

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=

"c:\\WINDOWS\\system32\\igfxpers.exe"=

"c:\\WINDOWS\\system32\\userinit.exe"=

"c:\\WINDOWS\\system32\\igfxtray.exe"=

"c:\\WINDOWS\\RTHDCPL.EXE"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqSTE08.exe"=

"c:\\WINDOWS\\system32\\hkcmd.exe"=

"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=

"c:\\Arquivos de programas\\RALINK\\Common\\RaUI.exe"=

"c:\\Arquivos de programas\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=

"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Lib\\NMIndexStoreSvr.exe"=

"c:\\WINDOWS\\tsnp2std.exe"=

"c:\\WINDOWS\\system32\\netsh.exe"=

"c:\\Arquivos de programas\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe"=

"c:\\WINDOWS\\vsnp2std.exe"=

"c:\\Arquivos de programas\\MSN Messenger\\usnsvc.exe"=

"c:\\Arquivos de programas\\Arquivos comuns\\Ahead\\Lib\\NMBgMonitor.exe"=

"c:\\Arquivos de programas\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=

"c:\\WINDOWS\\system32\\WISPTIS.EXE"=

"c:\\Documents and Settings\\Marília\\Meus documentos\\Ares\\Ares.exe"=

"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\HelpCtr.exe"=

 

S2 gupdate1c9947de6b77398;Google Update Service (gupdate1c9947de6b77398);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-21 133104]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-03-21 1684736]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-03-24 c:\windows\Tasks\GoogleUpdateTaskMachine.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-02-21 20:41]

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com.br/

uInternet Connection Wizard,ShellNext = hxxp://www.google.com.br/

uInternet Settings,ProxyOverride = local

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

TCP: {255D53F9-DA11-4382-A77C-C183289A2512} = 192.168.1.1

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-24 04:04:11

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_USERS\S-1-5-21-606747145-963894560-1177238915-1003\Software\Microsoft\SystemCertificates\AddressBook*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\wdfmgr.exe

c:\windows\system32\wscntfy.exe

c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

c:\arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe

.

**************************************************************************

.

Tempo para conclusão: 2009-03-24 4:06:25 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-03-24 07:06:22

ComboFix2.txt 2009-03-23 10:29:50

ComboFix3.txt 2009-03-21 13:09:37

 

Pré-execução: 13 pasta(s) 136.317.239.296 bytes disponíveis

Pós execução: 11 pasta(s) 136,345,440,256 bytes disponíveis

 

204 --- E O F --- 2009-03-21 08:31:15

 

 

 

-----------------------------------------------------------------------------------------------------

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 04:28:22, on 24/3/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\FixCamera.exe

C:\WINDOWS\tsnp2std.exe

C:\WINDOWS\vsnp2std.exe

C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\RALINK\Common\RaUI.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Hijackthis\HiJackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Arquivos de programas\HP\Smart Web Printing\SmartWebPrinting.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll

O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe

O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe

O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ares] "C:\Documents and Settings\Marília\Meus documentos\Ares\Ares.exe" -h

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Arquivos de programas\RALINK\Common\RaUI.exe

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O17 - HKLM\System\CS1\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O17 - HKLM\System\CS2\Services\Tcpip\..\{255D53F9-DA11-4382-A77C-C183289A2512}: NameServer = 192.168.1.1

O23 - Service: Google Update Service (gupdate1c9947de6b77398) (gupdate1c9947de6b77398) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: NBService - Nero AG - C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

 

--

End of file - 6952 bytes

 

 

Obs: Esse "O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1" insiste em não sair. Marquei e cliquei em Fixchecked, mas ele continua constando no log.

 

Abraço

Compartilhar este post


Link para o post
Compartilhar em outros sites

Repita esse procedimento em modo de segurança (para entrar em modo de segurança , reinicie o computado ao primeiro beep segure f8 até que a tela de seleção ofereça a opção Modo de Segurança):

 

# Execute a ferramenta HiJackThis;

 

# Selecione o(s) item(s) abaixo indicado(s):

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

 

# Clique no botão "Fix checked";

 

Reinicie em modo normal gere um novo log do Hijackthis e poste na sua próxima resposta.

 

Aguardo o retorno

Compartilhar este post


Link para o post
Compartilhar em outros sites

Está do mesmo jeito Silas. Aparece tudo lá: Modo Seguro, Modo Seguro com Rede e etc... Quando aperto Enter em Modo Seguro ele vai reiniciar, mas não reinicia aí aparece as mensagens: "O Windows não foireiniciado com sucesso. Isso pode tersido causado por uma alteração recente de hardware ou software" aí tem a opção "Iniciar normalmente" e pronto eu reinicio normalmete novamente. :/

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tem aqui no Everest: Service Pack do Sistema Operacional - [ TRIAL VERSION ]

 

Dia 21/03 dei uma atualizada, mas se não me engano antes desse dia já havia tentado reiniciar em Modo Seguro e não tinha dado certo.

 

Grato

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue o Relatório de varredura de registros

 

Logfile of Advanced SystemCare 3 Registry Scan

Scan Date: 24/3/2009

OS Platform: Windows XP

x64 Bit: No

ASC Version: 3.2.0.633

Problems Count: 319

-----------------------------

 

[Classes e Controles ActiveX]

HKEY_CLASSES_ROOT\CLSID\{0B6DC6EE-C4FD-11d1-819A-00C04FB69B4D}\InProcServer32 C:\Arquivos de programas\Arquivos comuns\Adobe\Shell\psicon.dll

[Classes e Controles ActiveX]

HKEY_CLASSES_ROOT\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32 C:\WINDOWS\system32\macromed\flash\flash.ocx

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ToolboxBitmap32 N/A C:\WINDOWS\system32\Adobe\Shockwave 11\Control.dll, 203

[Classes e Controles ActiveX]

HKEY_CLASSES_ROOT\CLSID\{1FF84C3B-1140-4eb6-BE38-4BE618D2E7D6}\InprocServer32 %SystemRoot%\system32\eapa3hst.dll

[Classes e Controles ActiveX]

HKEY_CLASSES_ROOT\CLSID\{9DAA7B9D-CE5B-42CE-B942-32BBC284AC44}\InProcServer32 %SystemRoot%\system32\eapa3hst.dll

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\CLSID\{A4C4671C-499F-101B-BB78-00AA00383CBB}\InprocServer N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\CLSID\{A4C4671C-499F-101B-BB78-00AA00383CBB}\InprocServer32 N/A

[Classes e Controles ActiveX]

HKEY_CLASSES_ROOT\CLSID\{B0E28D63-52F6-4e30-992B-78ECF97268E9}\InprocServer32 %SystemRoot%\system32\eapa3hst.dll

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{00020430-0000-0000-C000-000000000046}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}\5.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{0548C79F-7B8C-455D-B228-97D35371BB62}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{166B1BC7-3F9C-11CF-8075-444553540000}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{218CB45F-20B6-11d2-8E17-0000F803A446}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{2991F100-D9C3-4243-82A2-A718747FC0CF}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.3\HELPDIR N/A

[Classes e Controles ActiveX]

HKEY_CLASSES_ROOT\TypeLib\{367463F0-A306-4F6D-9AE2-E40E8EA6EF2A}\2.0\0 N/A C:\DOCUME~1\MARLIA~1\CONFIG~1\Temp\Word8.0\MSForms.exd

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{41738EEA-442F-477F-92CF-2889BD6CD7E7}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{43136EB0-D36C-11CF-ADBC-00AA00A80033}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{4A1E52AC-64F2-49E9-BFD7-0806D9494DBB}\4.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{4B0AB3E1-80F1-11CF-86B4-444553540000}\CS\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{53CED51D-432B-45b2-A3E0-0CE2C24235D4}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{56D04F5D-964F-4DBF-8D23-B97989E53418}\1.5\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{5924C60B-6D7F-4AD6-8084-24A59431C967}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{773F1B9A-35B9-4E95-83A0-A210F2DE3B37}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{78DB07DF-483E-4829-AB44-ED7952083584}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{8AE029D0-08E3-11D1-BAA2-444553540000}\3.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{A2C55651-A23E-43CA-B63D-C10B99EFF7E0}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}\1.0\HELPDIR N/A

[Classes e Controles ActiveX]

HKEY_CLASSES_ROOT\TypeLib\{AAAF0528-2124-4DBD-9C63-C91E8C938A01}\2.0\0 N/A C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{AEB84C80-95DC-11D0-B7FC-B61140119C4A}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{B82D18E0-1649-48DE-92D7-AA89BBB5F0AD}\1.0\HELPDIR N/A

[Classes e Controles ActiveX]

HKEY_CLASSES_ROOT\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\3.0\0 N/A C:\Arquivos de programas\Google\GoogleToolbarNotifier\1.2.1128.5462\swg.dll

[Classes e Controles ActiveX]

HKEY_CLASSES_ROOT\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\d.0\0 N/A C:\Arquivos de programas\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{CCD973EF-4D88-48B2-ABF4-13EAF25BAE3B}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{D2EA97F6-6235-4B2D-B5AA-A4472B9CE557}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{E503D000-5C7F-11D2-8B74-00104B2AFB41}\1.0\HELPDIR N/A

[Chaves de Registro em branco]

HKEY_CLASSES_ROOT\TypeLib\{F5078F18-C551-11D3-89B9-0000F81FE221}\4.0\HELPDIR N/A

[Diretorio não existem]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe C:\WINDOWS\system32\cmmgr32.exe

[Diretorio não existem]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\msimn.exe C:\Program Files\Outlook Express\msimn.exe

[Diretorio não existem]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\setup.exe C:\Arquivos de programas\RALINK\RT6x Wireless LAN Card\RT6x Wireless LAN Card

[Diretorio não existem]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\wab.exe C:\Program Files\Outlook Express\wab.exe

[Diretorio não existem]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\wabmig.exe C:\Program Files\Outlook Express\wabmig.exe

[Diretorio não existem]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\WORDPAD.EXE C:\Program Files\Windows NT\Acessórios\WORDPAD.EXE

[Diretorio não existem]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\WRITE.EXE C:\Program Files\Windows NT\Acessórios\WORDPAD.EXE

[Extensões não usadas]

HKEY_CLASSES_ROOT\.oga N/A

[Extensões não usadas]

HKEY_CLASSES_ROOT\.ogv N/A

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\acrobat\DefaultIcon N/A C:\Arquivos de programas\Adobe\Reader 9.0\Acrobat\AcroRd32.exe

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\AcroExch.Sequence N/A C:\WINDOWS\Installer\{AC76BA86-7AD7-1046-7B44-A90000000001}\SequenceFile.ico,0

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\ADCS N/A {89E30300-764D-11d0-B282-00A0C90F56FC}

[Extensões não usadas]

HKEY_CLASSES_ROOT\Adobe.workflow.files\shell\open\command "C:\Arquivos de programas\Arquivos comuns\Adobe\WorkFlow\AdobeWorkGroupHelper.exe "%1""

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\Connection Manager Profile\DefaultIcon N/A C:\WINDOWS\system32\CMMGR32.EXE,1

[Extensões não usadas]

HKEY_CLASSES_ROOT\Connection Manager Profile\shell\open\command C:\WINDOWS\system32\CMMGR32.EXE "%1"

[Extensões não usadas]

HKEY_CLASSES_ROOT\Connection Manager Profile\shell\Settings...\command C:\WINDOWS\system32\CMMGR32.EXE /settings "%1"

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\dcsfile\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,11

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\DefaultSearch.DefaultSearchHook N/A {C94E154B-1459-4A47-966B-4B843BEFC7DB}

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\DefaultSearch.DefaultSearchHook.1 N/A {C94E154B-1459-4A47-966B-4B843BEFC7DB}

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\ecsfile\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,10

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\fcsfile\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,12

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\HeaderFooter.HeaderFooter.1 N/A {30c3f6cd-98b5-11cf-bb82-00aa00bdce0b}

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\iHDPlayer.CiHDPlayer.1 N/A 702A4E71-DCE4-4db4-B311-8349C7DDB22E}

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\ncsfile\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,14

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\NMUIEngine.NMUIResourceLoaderHarddisk N/A {03DC5606-EA66-4f02-AB52-2065524B03821}

[Extensões não usadas]

HKEY_CLASSES_ROOT\OISbmpfile N/A

[Extensões não usadas]

HKEY_CLASSES_ROOT\OISemffile N/A

[Extensões não usadas]

HKEY_CLASSES_ROOT\OISgiffile N/A

[Extensões não usadas]

HKEY_CLASSES_ROOT\OISjpegfile N/A

[Extensões não usadas]

HKEY_CLASSES_ROOT\OISpngfile N/A

[Extensões não usadas]

HKEY_CLASSES_ROOT\OIStiffile N/A

[Extensões não usadas]

HKEY_CLASSES_ROOT\OISwmffile N/A

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\PKMSA.AddStartAddress N/A 3753737A-DD75-11D2-966A-00C04F79487A

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\PKMSA.AddStartAddress.1 N/A 3753737A-DD75-11D2-966A-00C04F79487A

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\PKMSA.CatalogCommands N/A 3753737C-DD75-11D2-966A-00C04F79487A

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\PKMSA.CatalogCommands.1 N/A 3753737C-DD75-11D2-966A-00C04F79487A

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\PKMSA.StartAddressCommands N/A 3753737B-DD75-11D2-966A-00C04F79487A

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\PKMSA.StartAddressCommands.1 N/A 3753737B-DD75-11D2-966A-00C04F79487A

[Extensões não usadas]

HKEY_CLASSES_ROOT\SysmonLogManager.Snapin N/A

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\Tahoe.CCMenu N/A 9020EB60-77B2-11D3-83DA-00C04F505F43

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\Tahoe.CCMenu.1 N/A 9020EB60-77B2-11D3-83DA-00C04F505F43

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\Tahoe.FolderControl N/A 787E8FD0-7AD6-11D3-83DA-00C04F505F43

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\Tahoe.FolderControl.1 N/A 787E8FD0-7AD6-11D3-83DA-00C04F505F43

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\Tahoe.NewCCWizardMenu N/A 0948E980-3A31-11D3-83CF-00C04F505F43

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\Tahoe.NewCCWizardMenu.1 N/A 0948E980-3A31-11D3-83CF-00C04F505F43

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\Tahoe.SchManMenu N/A F84399C0-18A1-11D3-83C5-00C04F505F43

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\Tahoe.SchManMenu.1 N/A F84399C0-18A1-11D3-83C5-00C04F505F43

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\tcsfile\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,13

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:catalog\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,15

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:catalog-settings\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12471

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:contentclassdef N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-13101

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:exchange55startaddress\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12451

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:exchangestartaddress\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12451

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:filestartaddress\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12453

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:management\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,20

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:notesstartaddress\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12456

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:remoteworkspacestartaddress\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12454

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:webstartaddress\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12450

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:wizard/addcontentclass N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-13100

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:wizard/addsearchcontentlocation\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12461

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:workspace-settings\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12472

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:workspaceconfiguration\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12476

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\urn:content-classes:workspacestartaddress\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,-12454

[Extensões de Arquivo invalidas]

HKEY_CLASSES_ROOT\wcsfile\DefaultIcon N/A C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\pkmres.dll,9

[Extensões não usadas]

HKEY_CLASSES_ROOT\WMPCD N/A

[Extensões não usadas]

HKEY_CLASSES_ROOT\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79} N/A

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU a

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU MRUList

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU b

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU c

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU d

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU e

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU f

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU MRUListEx

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 0

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 1

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 2

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 3

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 4

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 5

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 6

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 7

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 8

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 9

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 10

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 11

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 12

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 13

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 14

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 15

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 16

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 17

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 18

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 19

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 20

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 21

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 22

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 23

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 24

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 25

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 26

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 27

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 28

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 29

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 30

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 31

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 32

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 33

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 34

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 35

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 36

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 37

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU 38

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* a C:\Hijackthis\hijackthis4.txt

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* MRUList jachifgedb

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* b C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\deolho.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* c C:\Documents and Settings\Marília\Desktop\CFScript.txt

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* d C:\logComboFix.txt

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* e C:\Hijackthis\hijackthis3.txt

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* f C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Nova pasta\brasilsilsilru4.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* g C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Nova pasta\retaguardapanamericana.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* h C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Eu 21-02-09\DSC000055.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* i C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cnec e balneario\DSC00013.JPG

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\* j C:\Documents and Settings\Marília\Desktop\38122_adv_sys_care_free_320.exe

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp a C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\sem título.bmp

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp MRUList ihgfedcba

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp b C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\cangaco.bmp

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp c C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\cangaceiross.bmp

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp d C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\lampiao, vida e morte.bmp

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp e C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\lampiao, o rei do cangaço bmp.bmp

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp f C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\lampiao-e-maria-bonita bmp.bmp

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp g C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\jurubeba.bmp

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp h C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\jose-saturnino-de-barros 1º inimigo bmp.bmp

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bmp i C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\tragedia das cabeças cortadas bmp.bmp

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe a C:\Documents and Settings\Marília\Meus documentos\Free3GPVideoConverter.exe

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe MRUList ihgfedcba

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe b C:\Documents and Settings\Marília\Meus documentos\bywifi_setup.exe

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe c C:\Hijackthis\HijackThis.exe

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe d C:\Documents and Settings\Marília\Meus documentos\everestultimate500.exe

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe e C:\Documents and Settings\Marília\Meus documentos\KeyTweak_install.exe

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe f C:\Documents and Settings\Marília\Desktop\ComboFix.exe

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe g C:\Documents and Settings\Marília\Meus documentos\AUD_allOS_5783_PV_RTL.exe

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe h C:\Documents and Settings\Marília\Meus documentos\XP-Codec-Pack_2[1].4.6.exe

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe i C:\Documents and Settings\Marília\Desktop\38122_adv_sys_care_free_320.exe

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\flv a C:\Documents and Settings\Marília\Meus documentos\Meus vídeos\fran.flv

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\flv MRUList a

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg a C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\deolho.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg MRUList edcbajighf

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg b C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Nova pasta\retaguardapanamericana.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg c C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Nova pasta\brasilsilsilru4.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg d C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cnec e balneario\DSC00013.JPG

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg e C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Eu 21-02-09\DSC000055.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg f C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\volei_de_voadoras.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg g C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\volei1.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg h C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\images.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg i C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\9263012.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\jpg j C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\mau-5911-55123.jpg

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\txt a C:\Hijackthis\hijackthis2.txt

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\txt MRUList ebdca

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\txt b C:\Documents and Settings\Marília\Desktop\CFScript.txt

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\txt c C:\logComboFix.txt

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\txt d C:\Hijackthis\hijackthis3.txt

[MRU Cache]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\txt e C:\Hijackthis\hijackthis4.txt

[Ausencia de DLL(Compart)]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls C:\Documents and Settings\All Users\Dados de aplicativos\Nero\DrWeb\DRWEBASE.VDB 1

[Ausencia de DLL(Compart)]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls C:\WINDOWS\Downloaded Program Files\gp.ocx 1

[Atalhos inválidos]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Acelerador POP N/A

[Atalhos inválidos]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AntiVir PersonalEdition Premium N/A

[Atalhos inválidos]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Bywifi N/A

[Atalhos inválidos]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\DVDVideoSoft N/A

[Atalhos inválidos]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Google Updater N/A

[Atalhos inválidos]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\K-Lite Codec Pack N/A

[Atalhos inválidos]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\KeyTweak N/A

[Atalhos de arquivo inválido]

Ares.lnk C:\Arquivos de programas\Ares\Ares.exe C:\Documents and Settings\Marília\Menu Iniciar\Programas\Ares\Ares.lnk

[Atalhos de arquivo inválido]

Homepage.lnk C:\Arquivos de programas\Ares\data\Homepage.url C:\Documents and Settings\Marília\Menu Iniciar\Programas\Ares\Homepage.lnk

[Atalhos de arquivo inválido]

Host Chatroom.lnk C:\Arquivos de programas\Ares\chatServer.exe C:\Documents and Settings\Marília\Menu Iniciar\Programas\Ares\Host Chatroom.lnk

[Atalhos de arquivo inválido]

Uninstall.lnk C:\Arquivos de programas\Ares\Uninstall.exe C:\Documents and Settings\Marília\Menu Iniciar\Programas\Ares\Uninstall.lnk

[Atalhos de arquivo inválido]

01-john_acquaviva_pres _swen_weber_-_first_stroke_(original)-fgz (3m 29s).lnk C:\Documents and Settings\Marília\Meus documentos\Ares\music\Passadas 16-02-09\01-john_acquaviva_pres _swen_weber_-_first_stroke_(original)-fgz (3m 29s).mp3 C:\Documents and Settings\Marília\Recent\01-john_acquaviva_pres _swen_weber_-_first_stroke_(original)-fgz (3m 29s).lnk

[Atalhos de arquivo inválido]

9263012.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\9263012.jpg C:\Documents and Settings\Marília\Recent\9263012.lnk

[Atalhos de arquivo inválido]

a vida....lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\a vida....bmp C:\Documents and Settings\Marília\Recent\a vida....lnk

[Atalhos de arquivo inválido]

Bola De Vôlei.lnk C:\Documents and Settings\Marília\Meus documentos\Arquivos Word - Davi\Bola De Vôlei.doc C:\Documents and Settings\Marília\Recent\Bola De Vôlei.lnk

[Atalhos de arquivo inválido]

cangaceiross.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\cangaceiross.bmp C:\Documents and Settings\Marília\Recent\cangaceiross.lnk

[Atalhos de arquivo inválido]

cangaco.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\cangaco.bmp C:\Documents and Settings\Marília\Recent\cangaco.lnk

[Atalhos de arquivo inválido]

CFScript.lnk C:\Documents and Settings\Marília\Desktop\CFScript.txt C:\Documents and Settings\Marília\Recent\CFScript.lnk

[Atalhos de arquivo inválido]

deolho.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\deolho.jpg C:\Documents and Settings\Marília\Recent\deolho.lnk

[Atalhos de arquivo inválido]

Documento Recorte 'Antigamente publ...'.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\Documento Recorte 'Antigamente publ...'.shs C:\Documents and Settings\Marília\Recent\Documento Recorte 'Antigamente publ...'.lnk

[Atalhos de arquivo inválido]

FORRÓ REAL - PROMOCIONAL - 22 - Track 22.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas músicas\FORRÓ REAL\FORRÓ REAL - PROMOCIONAL - 22 - Track 22.mp3 C:\Documents and Settings\Marília\Recent\FORRÓ REAL - PROMOCIONAL - 22 - Track 22.lnk

[Atalhos de arquivo inválido]

fran (2).lnk C:\Documents and Settings\Marília\Meus documentos\Meus vídeos\fran.rar C:\Documents and Settings\Marília\Recent\fran (2).lnk

[Atalhos de arquivo inválido]

Frete grátis mesmo.lnk C:\Documents and Settings\Marília\Meus documentos\Arquivos Word - Davi\Frete grátis mesmo.doc C:\Documents and Settings\Marília\Recent\Frete grátis mesmo.lnk

[Atalhos de arquivo inválido]

images.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\images.jpg C:\Documents and Settings\Marília\Recent\images.lnk

[Atalhos de arquivo inválido]

imagess.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\imagess.jpg C:\Documents and Settings\Marília\Recent\imagess.lnk

[Atalhos de arquivo inválido]

lampiao, vida e morte.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\lampiao, vida e morte.bmp C:\Documents and Settings\Marília\Recent\lampiao, vida e morte.lnk

[Atalhos de arquivo inválido]

LIGA MASCULINA.lnk C:\Documents and Settings\Marília\Meus documentos\Arquivos Word - Davi\LIGA MASCULINA.doc C:\Documents and Settings\Marília\Recent\LIGA MASCULINA.lnk

[Atalhos de arquivo inválido]

mau-5911-55123.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\mau-5911-55123.jpg C:\Documents and Settings\Marília\Recent\mau-5911-55123.lnk

[Atalhos de arquivo inválido]

Passadas dia 21-11-08.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas músicas\Passadas dia 21-11-08 C:\Documents and Settings\Marília\Recent\Passadas dia 21-11-08.lnk

[Atalhos de arquivo inválido]

Quem sou eu.lnk C:\Documents and Settings\Marília\Meus documentos\Arquivos Word - Davi\Quem sou eu.doc C:\Documents and Settings\Marília\Recent\Quem sou eu.lnk

[Atalhos de arquivo inválido]

Rasga!.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas músicas\Passadas dia 21-11-08\Rasga!.mp3 C:\Documents and Settings\Marília\Recent\Rasga!.lnk

[Atalhos de arquivo inválido]

Scraps das bolas.lnk C:\Documents and Settings\Marília\Meus documentos\Arquivos Word - Davi\Scraps das bolas.doc C:\Documents and Settings\Marília\Recent\Scraps das bolas.lnk

[Atalhos de arquivo inválido]

Scrapss.lnk C:\Documents and Settings\Marília\Meus documentos\Arquivos Word - Davi\Scrapss.doc C:\Documents and Settings\Marília\Recent\Scrapss.lnk

[Atalhos de arquivo inválido]

sem título.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\Cangaço\sem título.bmp C:\Documents and Settings\Marília\Recent\sem título.lnk

[Atalhos de arquivo inválido]

volei1.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\volei1.jpg C:\Documents and Settings\Marília\Recent\volei1.lnk

[Atalhos de arquivo inválido]

volei_de_voadoras.lnk C:\Documents and Settings\Marília\Meus documentos\Minhas imagens\volei_de_voadoras.jpg C:\Documents and Settings\Marília\Recent\volei_de_voadoras.lnk

[Atalhos de arquivo inválido]

___ARESTRA___03 - freak.lnk C:\Documents and Settings\Marília\Meus documentos\Ares\music\___ARESTRA___03 - freak.mp3 C:\Documents and Settings\Marília\Recent\___ARESTRA___03 - freak.lnk

[Programa Obsoleto]

HKEY_CURRENT_USER\Software\Piriform N/A

[Programa Obsoleto]

HKEY_CURRENT_USER\Software\Wget N/A

[Programa Obsoleto]

HKEY_LOCAL_MACHINE\Software\ALWIL Software N/A

[Programa Obsoleto]

HKEY_LOCAL_MACHINE\Software\Secure N/A

[instalação Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders\ C:\WINDOWS\PCHEALTH\ERRORREP\QHEADLES\

[instalação Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders\ C:\WINDOWS\PCHEALTH\ERRORREP\QSIGNOFF\

[instalação Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Folders\ C:\DOCUME~1\MARLIA~1\CONFIG~1\Temp\HPLocal\

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Ares UninstallString "C:\Arquivos de programas\Ares\uninstall.exe"

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\DirectAnimation N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\ICW N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\IE40 N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\IEData N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\OutlookExpress N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall_is1 Inno Setup: App Path C:\Arquivos de programas\Arquivos comuns\DVDVideoSoft

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall_is1 InstallLocation C:\Arquivos de programas\Arquivos comuns\DVDVideoSoft\

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall_is1 UninstallString "C:\Arquivos de programas\Arquivos comuns\DVDVideoSoft\unins000.exe"

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall_is1 QuietUninstallString "C:\Arquivos de programas\Arquivos comuns\DVDVideoSoft\unins000.exe" /SILENT

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} InstallSource c:\445da24aaa68bcce72c23ae801\

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1046-7B44-A90000000001} InstallSource C:\Documents and Settings\Marília\Desktop\Instalador do Adobe Reader 9\

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1046-7B44-A90000000001} Readme C:\Arquivos de programas\Adobe\Reader 9.0\Leaime.htm

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Google Updater N/A

[Desinstalador Invalida]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\KLiteCodecPack_is1 N/A

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\Arquivos de programas\K-Lite Codec Pack\Media Player Classic\mplayerc.exe Media Player Classic - Homecinema

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\Arquivos de programas\K-Lite Codec Pack\unins000.exe Setup/Uninstall

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\DOCUME~1\MARLIA~1\CONFIG~1\Temp\_iu14D2N.tmp Setup/Uninstall

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\32788R22FWJFW\n.com NirCmd

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\32788R22FWJFW\hidec.exe hidec

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\WINDOWS\system32\CF6108.exe Processador de comandos do Windows

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\ComboFix\NirCmdC.cfexe NirCmd

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\ComboFix\ERUNT.cfexe ERUNT

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\ComboFix\Nircmd.com NirCmd

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\ComboFix\NirCmd.cfexe NirCmd

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\ComboFix\WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe Programa de extracção automática de ficheiros CAB para Win32

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\DOCUME~1\MARLIA~1\CONFIG~1\Temp\Rar$EX01.000\Avast Professional Edition 4.8.1296 (Português).exe ALWIL Software Setup Engine

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\DOCUME~1\MARLIA~1\CONFIG~1\Temp\Rar$EX28.000\Avast Professional Edition 4.8.1296 (Português).exe ALWIL Software Setup Engine

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\WINDOWS\system32\CF16803.exe Processador de comandos do Windows

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\WINDOWS\system32\CF29011.exe Processador de comandos do Windows

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\DOCUME~1\MARLIA~1\CONFIG~1\Temp\is-JU1HI.tmp\38122_adv_sys_care_free_320.exe.tmp Setup/Uninstall

[Diretorio não existem]

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\ C:\DOCUME~1\MARLIA~1\CONFIG~1\Temp\is-FMTOH.tmp\ydetect.exe Yahoo! Toolbar Detecter Setup

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2 N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2 N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.A8A07C0EEFD604CC630D2B6E2718F13A213EC4F0&sver=2&expire=1235441982&key=yt1&ipbits=0 N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CE6D5AA73653077E1DE5EC1B782DA4709CDC6AD5&sver=2&expire=1235442100&key=yt1&ipbits=0 N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdmov N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.key N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mka N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mkv N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpc N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qt N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmm N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmvb N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rp N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rt N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rv N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tmp N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wv N/A

[Extensões não usadas]

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\OpenWithList N/A

[Chaves de Registro em branco]

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.oga N/A

[Chaves de Registro em branco]

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ogv N/A

[Chaves de Registro em branco]

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SysmonLogManager.Snapin N/A

[Chaves de Registro em branco]

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WMPCD N/A

[Chaves de Registro em branco]

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79} N/A

 

 

 

 

Obs.: Reparei todos esses erros de "Reparo no Registro", reparei também o "Remoção de Spyware", "Limpeza de Privacidade" e por último também reparei os "Arquivos Temporários"

 

Já é um avanço, pois antes nada rodava aqui...

 

Abraço, Davi

Compartilhar este post


Link para o post
Compartilhar em outros sites

1ºPasso

 

 

CFScript

 

Copie,todo conteúdo citado abaixo e cole no Bloco de Notas.

Salve o arquivo na área de trabalho com o nome de: CFScript.txt

Registry::

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]

"DisableTaskMgr"= 0 (0x1)

"DisableRegistryTools"= 0 (0x1)

 

Arraste o CFScript.txt até o ícone do Combofix, conforme ilustração abaixo:

cfscript.gif

 

Atenda à solicitação,que deverá surgir,para rodar o ComboFix

OBS: Arraste o CFScript até para o ícone até que apareça a janela(pequena) do combofix

Ao final poste o ComboFix.txt juntamente com o novo log do hijackthis

 

Obs.: Execute a ação com o seu pendrive conectado ao PC.

 

2ºPasso

 

1. Baixe o Kaspersky Virus Removal Tool.

 

2. O arquivo possui aproximadamente 32 Mb, mas o resultado compensará o trabalho.

 

3. Reinicie a máquina em Modo Seguro.

 

4. Execute a ferramenta dando duplo-clique sobre o arquivo baixado.

 

5. Abrir-se-á a seguinte janela:

Kaspersky-Virus-Removal-Tool_1.png

 

6. Marque os diretórios que deseja varrer (é melhor marcar todos).

 

7. Clique em Scan e aguarde o término do processo.

 

8. Terminada a varredura, retorne com o resultado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.