Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Luiz psYco

[Resolvido!] explorer.exe reinicia incessantemente

Recommended Posts

Ola pessoal.

Esse é meu primeito topico, e gostaria da ajuda de voces.

Ultimamente, estou tendo alguns problemas com o processo explorer.exe (no meu Gerenciador de Tarefas aparece "Explorer.EXE").

Utilizo o sistema operacional Windows XP Professional SP2.

Quando inicio o computador, o explorer ja inicia travado. Quando passo o cursor sobre a barra inferior, apenas fica indicado que está a carregar, mas nunca que o explorer termina de carregar. Assim, eu abro o Gerenciador de Tarefas e o finalizo. Em seguida, executo o explorer novamente mas este fica reiniciando incessantemente.

Ja tentei diversas coisas como: desfragmentaçao de disco, escaneamento completo de disco(Karsperski 2009), Combofix, retirar alguns processos desnecessarios da inicializaçao; mas nada adiantou.

Que eu me lembre, a ultima coisa que eu modifiquei, antes de dar esse problema, foi a instalaçao do UxThemePackager, um programinha que serve pra adaptar as dlls de novos temas para o Windows, e a instalaçao de um pacote de icones.

Agora, a unica coisa que acontece é que o explorer.exe reinicia, começa a usar uma grande quantidade de RAM e CPU, e reinicia novamente.

Possuo aqui um log do HighJackThis e do ComboFix, espero que ajude.

 

Combofix:

ComboFix 09-06-22.0E - Usuario 23/06/2009 21:13.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.1023.586 [GMT -3:00]

Executando de: c:\combofix\ComboFix.exe

AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}

* Criado um novo ponto de restauração

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\windows\system32\drivers\kl1.sys

c:\windows\system32\url(2).dll

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2009-05-24 to 2009-06-24 ))))))))))))))))))))))))))))

.

 

2009-06-20 23:41 . 2009-06-20 23:41 -------- d-----w- c:\arquivos de programas\Arquivos comuns\xing shared

2009-06-20 23:41 . 2009-06-20 23:41 -------- d-----w- c:\arquivos de programas\IcoFX 1.6

2009-06-14 22:25 . 2008-05-29 06:03 37176 ----a-w- c:\documents and settings\Usuario\Dados de aplicativos\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe

2009-06-07 02:06 . 2009-06-12 18:53 -------- d-----w- c:\arquivos de programas\Gabest

2009-06-07 01:03 . 2009-06-07 01:03 -------- d-----w- c:\arquivos de programas\Codemasters

2009-06-01 20:36 . 2009-06-01 20:36 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Synetic

2009-06-01 20:34 . 2009-06-01 20:35 -------- d-----w- c:\arquivos de programas\Ferrari Virtual Race

2009-06-01 01:16 . 2009-06-01 01:47 -------- d-----w- c:\arquivos de programas\FrostWire Ultra Accelerator

2009-05-31 02:02 . 2009-05-31 02:02 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-06-24 00:20 . 2009-01-28 13:26 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Kaspersky Lab

2009-06-24 00:18 . 2009-01-28 13:26 6279200 --sha-w- c:\windows\system32\drivers\fidbox.dat

2009-06-24 00:18 . 2009-01-28 13:26 5684 --sha-w- c:\windows\system32\drivers\fidbox2.idx

2009-06-24 00:18 . 2009-01-28 13:26 51184 --sha-w- c:\windows\system32\drivers\fidbox.idx

2009-06-24 00:18 . 2009-01-28 13:26 1040416 --sha-w- c:\windows\system32\drivers\fidbox2.dat

2009-06-22 23:35 . 2008-06-30 23:44 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\DNA

2009-06-22 23:35 . 2008-06-30 23:44 -------- d-----w- c:\arquivos de programas\DNA

2009-06-21 00:31 . 2008-07-14 22:35 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Stardock

2009-06-21 00:19 . 2008-04-20 18:39 -------- d---a-w- c:\documents and settings\All Users\Dados de aplicativos\TEMP

2009-06-20 23:41 . 2009-01-31 13:45 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Real

2009-06-20 23:41 . 2008-03-06 14:36 499712 ----a-w- c:\windows\system32\msvcp71.dll

2009-06-20 23:41 . 2008-03-06 14:36 348160 ----a-w- c:\windows\system32\msvcr71.dll

2009-06-20 23:23 . 2008-12-06 21:13 83456 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\SpeedBit\DAP\SDCondition.dll

2009-06-18 00:36 . 2008-03-27 23:24 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Orbit

2009-06-17 00:04 . 2009-01-18 01:22 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Hamachi

2009-06-11 19:06 . 2009-02-03 23:15 -------- d-----w- c:\arquivos de programas\SpeedFan

2009-06-07 13:22 . 2008-11-22 16:17 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\FrostWire

2009-06-07 01:23 . 2009-03-29 15:16 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\BitTorrent

2009-06-07 00:39 . 2008-03-06 14:28 -------- d--h--w- c:\arquivos de programas\InstallShield Installation Information

2009-05-31 02:03 . 2008-03-06 14:37 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Adobe

2009-05-30 23:52 . 2008-11-05 22:23 -------- d-----w- c:\arquivos de programas\GameTop.com

2009-05-24 02:46 . 2008-04-17 23:34 -------- d-----w- c:\arquivos de programas\Google

2009-05-24 02:36 . 2008-10-30 14:54 -------- d-----w- c:\arquivos de programas\Megacubo

2009-05-21 16:55 . 2008-11-04 23:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Corel

2009-05-21 16:55 . 2008-11-04 23:25 -------- d-----w- c:\arquivos de programas\Corel

2009-05-21 13:06 . 2009-05-21 13:06 -------- d-----w- c:\arquivos de programas\PENSUITEPRO

2009-05-21 12:47 . 2009-05-21 12:28 -------- d-----w- c:\arquivos de programas\G-PEN SERIES

2009-05-20 22:08 . 2009-01-28 13:36 94643 ----a-w- c:\windows\system32\drivers\klick.dat

2009-05-20 22:08 . 2009-01-28 13:36 105395 ----a-w- c:\windows\system32\drivers\klin.dat

2009-05-18 00:05 . 2009-05-18 00:05 -------- d-----w- c:\arquivos de programas\BitTorrent

2009-05-17 13:32 . 2008-11-22 16:16 -------- d-----w- c:\arquivos de programas\FrostWire

2009-05-17 13:30 . 2008-11-22 16:16 -------- d-----w- c:\arquivos de programas\AskBarDis

2009-05-12 14:59 . 2009-02-15 21:50 -------- d-----w- c:\arquivos de programas\Microsoft Silverlight

2009-05-11 23:27 . 2009-05-11 23:27 -------- d-----w- c:\arquivos de programas\NCH Software

2009-05-11 23:27 . 2009-05-11 23:27 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\NCH Swift Sound

2009-05-11 23:27 . 2009-05-11 23:27 -------- d-----w- c:\arquivos de programas\NCH Swift Sound

2009-05-05 23:43 . 2008-03-06 14:41 -------- d-----w- c:\arquivos de programas\Java

2009-05-05 23:42 . 2009-05-05 23:42 152576 ----a-w- c:\documents and settings\Usuario\Dados de aplicativos\Sun\Java\jre1.6.0_13\lzma.dll

2009-05-03 23:39 . 2009-05-03 23:39 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Hide IP NG

2009-05-03 23:39 . 2009-05-03 23:39 -------- d-----w- c:\arquivos de programas\Hide IP NG

2009-05-03 17:28 . 2008-08-13 23:22 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys

2009-05-03 17:28 . 2008-08-13 23:22 103736 ----a-w- c:\windows\system32\PnkBstrB.exe

2009-05-03 01:31 . 2009-05-03 01:31 -------- d-----w- c:\arquivos de programas\GameVicio

2009-05-02 18:18 . 2008-08-13 23:22 66872 ----a-w- c:\windows\system32\PnkBstrA.exe

2009-05-02 18:12 . 2009-05-02 18:12 22328 ----a-w- c:\documents and settings\Usuario\Dados de aplicativos\PnkBstrK.sys

2009-05-02 18:12 . 2009-05-02 18:12 22328 ----a-w- c:\documents and settings\Usuario\Dados de aplicativos\PnkBstrK.sys

2009-05-02 17:55 . 2009-05-02 17:55 -------- d-----w- c:\arquivos de programas\Activision

2009-05-02 17:41 . 2009-01-30 12:54 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Ulead Systems

2009-05-01 20:59 . 2009-05-01 20:27 -------- d-----w- c:\arquivos de programas\Audio Mid Recorder

2009-05-01 17:36 . 2009-05-01 17:36 -------- d-----w- c:\arquivos de programas\TVUPlayer

2009-04-29 22:53 . 2009-04-29 22:53 51200 ----a-w- c:\documents and settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\86ik9tpc.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}\components\FFExternalAlert.dll

2009-04-29 22:53 . 2009-04-29 22:53 114688 ----a-w- c:\documents and settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\86ik9tpc.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}\components\npmozax.dll

2009-04-29 22:50 . 2009-04-29 22:50 -------- d-----w- c:\arquivos de programas\ASIO4ALL v2

2009-04-26 23:08 . 2008-03-06 14:43 -------- d-----w- c:\arquivos de programas\URUSoft

2009-04-26 17:17 . 2009-04-26 17:17 -------- d-----w- c:\arquivos de programas\Alien Connections

2009-04-26 15:29 . 2008-03-06 14:28 -------- d-----w- c:\arquivos de programas\Realtek

2009-04-26 15:06 . 2009-04-26 15:06 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\WinBatch

2009-04-26 14:49 . 2009-04-25 19:27 -------- d-----w- c:\arquivos de programas\AP Tuner

2009-04-25 19:38 . 2009-04-25 19:38 8 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\SDGLYBMPWPP.SYS

2009-04-25 19:38 . 2009-04-25 19:38 8 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\SDGLYBMPWPP.SYS

2009-04-21 22:48 . 2009-04-07 00:13 1554432 ----a-w- c:\windows\Explorer.EXE

2009-04-21 13:24 . 2009-04-21 13:24 150528 ----a-w- c:\windows\regedit.exe

2009-04-16 20:23 . 2008-03-06 14:28 540672 ----a-w- c:\windows\RtlExUpd.dll

2009-04-14 19:09 . 2008-03-06 14:29 5069312 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys

2009-04-10 16:38 . 2008-03-06 14:28 17879552 ----a-w- c:\windows\RTHDCPL.EXE

2009-04-01 12:58 . 2008-03-06 14:29 1200128 ----a-w- c:\windows\RtlUpd.exe

2004-07-22 12:51 . 2004-07-22 12:51 3432656 ----a-w- c:\arquivos de programas\ManagedDX.CAB

2004-07-20 00:58 . 2004-07-20 00:58 1156363 ----a-w- c:\arquivos de programas\BDANT.cab

2004-07-20 00:53 . 2004-07-20 00:53 976020 ----a-w- c:\arquivos de programas\BDAXP.cab

2004-07-09 16:17 . 2004-07-09 16:17 13265040 ----a-w- c:\arquivos de programas\dxnt.cab

2004-07-09 11:13 . 2004-07-09 11:13 15493481 ----a-w- c:\arquivos de programas\DirectX.cab

2004-07-09 11:13 . 2004-07-09 11:13 703080 ----a-w- c:\arquivos de programas\BDA.cab

2004-07-09 06:08 . 2004-07-09 06:08 472576 ----a-w- c:\arquivos de programas\dxsetup.exe

2004-07-09 06:08 . 2004-07-09 06:08 2242560 ----a-w- c:\arquivos de programas\dsetup32.dll

2004-07-09 05:03 . 2004-07-09 05:03 62976 ----a-w- c:\arquivos de programas\DSETUP.dll

2008-03-06 15:30 . 2008-03-06 14:51 24 --sh--w- c:\windows\S9AF1913F.tmp

.

 

------- Sigcheck -------

 

[7] 2004-08-04 02:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\system32\dllcache\tcpip.sys

[-] 2004-08-04 02:14 359040 6A603809F598332DBEDD535BDBCE313E c:\windows\system32\drivers\tcpip.sys

 

[-] 2004-08-04 03:45 543744 3550BFE59972A67AC2F7781041D28EA7 c:\windows\system32\winlogon.exe

[7] 2004-08-04 03:45 504320 6F7BDE7A1126DEBF0CC359A54953EFC1 c:\windows\system32\dllcache\winlogon.exe

 

[-] 2009-04-21 22:48 1554432 C7052E176D939D1C6D6585F62C02A8A2 c:\windows\Explorer.EXE

[7] 2004-08-04 03:45 1034240 FA61A19050AE14BEC1A26DE82390DD65 c:\windows\XPize Darkside\Backup\explorer.exe

 

[-] 2004-08-04 03:45 25088 A3F0971DBBA9657034C303B39464EA5B c:\windows\system32\ctfmon.exe

[-] 2004-08-04 03:45 30208 C44B39505116F6961988B8681793E572 c:\windows\system32\dllcache\ctfmon.exe

[7] 2004-08-04 03:45 15360 F40BC97996B8E53799EEF1D63996674B c:\windows\XPize Darkside\Backup\ctfmon.exe

.

((((((((((((((((((((((((((((( SnapShot@2009-04-21_13.33.13 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-06-24 00:19 . 2009-06-24 00:19 16384 c:\windows\temp\Perflib_Perfdata_394.dat

+ 2009-05-24 03:25 . 2009-03-16 17:18 69448 c:\windows\system32\XAPOFX1_3.dll

+ 2009-05-24 03:25 . 2008-10-27 13:04 70992 c:\windows\system32\XAPOFX1_2.dll

+ 2009-05-24 03:25 . 2008-07-30 09:20 68616 c:\windows\system32\XAPOFX1_1.dll

+ 2009-05-24 03:25 . 2008-05-30 17:17 65032 c:\windows\system32\XAPOFX1_0.dll

+ 2009-05-24 03:25 . 2009-03-16 17:18 22360 c:\windows\system32\X3DAudio1_6.dll

+ 2009-05-24 03:25 . 2008-10-27 13:04 23376 c:\windows\system32\X3DAudio1_5.dll

+ 2009-05-24 03:25 . 2008-05-30 17:17 25608 c:\windows\system32\X3DAudio1_4.dll

+ 2007-04-11 16:27 . 2007-04-11 16:27 40960 c:\windows\system32\WTClient.exe

+ 2007-04-24 16:27 . 2007-04-24 16:27 46080 c:\windows\system32\UCMfg.exe

+ 2007-04-24 19:31 . 2007-04-24 19:31 10240 c:\windows\system32\ucinst32.dll

+ 2009-04-26 15:29 . 2009-03-17 15:44 36352 c:\windows\system32\RtkCoInstXP.dll

+ 2009-05-21 12:46 . 2007-05-31 17:33 12800 c:\windows\system32\ReinstallBackups\0017\DriverFiles\drivers\UCTblHid.sys

+ 2009-05-21 12:46 . 2007-04-23 15:28 18432 c:\windows\system32\ReinstallBackups\0017\DriverFiles\drivers\TClass2k.sys

+ 2009-04-26 15:30 . 2006-07-21 08:14 86016 c:\windows\system32\ReinstallBackups\0016\DriverFiles\SOUNDMAN.EXE

+ 2009-04-26 15:30 . 2004-08-04 03:45 23552 c:\windows\system32\ReinstallBackups\0016\DriverFiles\i386\wdmaud.drv

+ 2009-04-26 15:30 . 2004-08-04 02:08 48640 c:\windows\system32\ReinstallBackups\0016\DriverFiles\i386\stream.sys

+ 2009-04-26 15:30 . 2004-08-04 02:08 60288 c:\windows\system32\ReinstallBackups\0016\DriverFiles\i386\drmk.sys

+ 2009-04-26 15:30 . 2005-05-03 10:43 69632 c:\windows\system32\ReinstallBackups\0016\DriverFiles\ALCMTR.EXE

+ 2002-10-29 19:53 . 2002-10-29 19:53 69632 c:\windows\system32\PcHook.DLL

+ 2008-03-06 14:14 . 2001-10-28 18:07 19429 c:\windows\system32\MsDtc\Trace\msdtcvtr.bat

+ 2008-08-04 16:43 . 2009-05-31 19:41 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe

- 2008-08-04 16:43 . 2008-11-22 18:39 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe

+ 2002-07-25 10:04 . 2002-07-25 10:04 24576 c:\windows\system32\lhtool.exe

+ 2007-05-31 13:38 . 2007-05-31 13:38 53248 c:\windows\system32\drivers\WTSrv.exe

+ 2007-05-31 17:33 . 2007-05-31 17:33 12800 c:\windows\system32\drivers\UCTblHid.sys

+ 2007-04-23 15:28 . 2007-04-23 15:28 18432 c:\windows\system32\drivers\TClass2k.sys

+ 2007-04-23 15:28 . 2007-04-23 15:28 17920 c:\windows\system32\drivers\Tablet2k.sys

+ 2007-04-23 15:28 . 2007-04-23 15:28 10752 c:\windows\system32\drivers\PTSimHid.sys

+ 2007-06-07 17:16 . 2007-06-07 17:16 18944 c:\windows\system32\drivers\PTSimBus.sys

+ 2009-05-21 12:33 . 2001-09-06 02:20 12288 c:\windows\system32\drivers\mouhid.sys

+ 2009-05-21 12:33 . 2001-09-06 02:20 12288 c:\windows\system32\dllcache\mouhid.sys

- 2008-03-06 14:21 . 2009-04-21 12:51 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat

+ 2008-03-06 14:21 . 2009-06-24 00:19 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat

+ 2009-06-24 00:19 . 2009-06-24 00:19 32768 c:\windows\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5\index.dat

- 2008-03-06 14:21 . 2009-04-21 12:51 32768 c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat

+ 2008-03-06 14:21 . 2009-06-24 00:19 32768 c:\windows\system32\config\systemprofile\Configurações locais\Histórico\History.IE5\index.dat

+ 2008-03-06 14:29 . 2008-08-19 16:26 77824 c:\windows\SOUNDMAN.EXE

+ 2009-05-31 02:05 . 2009-05-31 02:05 65536 c:\windows\Installer\{E9787678-1033-0000-8E67-000000000001}\ProgramMenuShortcut_E9787678103300008E670000000001_1.exe

+ 2009-05-31 02:05 . 2009-05-31 02:05 65536 c:\windows\Installer\{E9787678-1033-0000-8E67-000000000001}\AppLanuchShortcut_E9787678103300008E67000000000001_1.exe

+ 2009-05-31 02:02 . 2009-05-31 02:02 65536 c:\windows\Installer\{236BB7C4-4419-42FD-0409-1E257A25E34D}\NewShortcut1_236BB7C4441942FD04091E257A25E34D.exe

+ 2009-06-07 01:21 . 2009-06-07 01:21 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll

+ 2009-06-07 01:21 . 2009-06-07 01:21 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll

+ 2008-03-06 14:28 . 2009-03-02 14:14 57344 c:\windows\ALCMTR.EXE

+ 2009-04-26 15:29 . 2004-08-04 03:45 4096 c:\windows\system32\ReinstallBackups\0016\DriverFiles\i386\ksuser.dll

- 2009-01-31 13:46 . 2009-01-31 13:46 5632 c:\windows\system32\pndx5032.dll

+ 2009-01-31 13:46 . 2009-06-20 23:41 5632 c:\windows\system32\pndx5032.dll

- 2009-01-31 13:46 . 2009-01-31 13:46 6656 c:\windows\system32\pndx5016.dll

+ 2009-01-31 13:46 . 2009-06-20 23:41 6656 c:\windows\system32\pndx5016.dll

+ 2009-04-26 15:29 . 2008-10-23 20:42 290816 c:\windows\vncutil.exe

+ 2009-04-26 17:17 . 1997-01-18 14:40 299520 c:\windows\uninst.exe

+ 2009-05-24 03:25 . 2009-03-16 17:18 517448 c:\windows\system32\XAudio2_4.dll

+ 2009-05-24 03:25 . 2008-10-27 13:04 514384 c:\windows\system32\XAudio2_3.dll

+ 2009-05-24 03:25 . 2008-07-30 09:20 509448 c:\windows\system32\XAudio2_2.dll

+ 2009-05-24 03:25 . 2008-05-30 17:19 507400 c:\windows\system32\XAudio2_1.dll

+ 2009-05-24 03:25 . 2009-03-16 17:18 235352 c:\windows\system32\xactengine3_4.dll

+ 2009-05-24 03:25 . 2008-10-27 13:04 235856 c:\windows\system32\xactengine3_3.dll

+ 2009-05-24 03:25 . 2008-07-31 13:41 238088 c:\windows\system32\xactengine3_2.dll

+ 2009-05-24 03:25 . 2008-05-30 17:18 238088 c:\windows\system32\xactengine3_1.dll

+ 2007-08-23 12:42 . 2007-08-23 12:42 143360 c:\windows\system32\WinTab32.dll

+ 2004-08-04 03:45 . 2006-08-09 23:58 218624 c:\windows\system32\uxtheme.dll

+ 2007-08-08 18:37 . 2007-08-08 18:37 401408 c:\windows\system32\tabcfg.exe

+ 2008-03-06 14:29 . 2009-03-05 16:35 131072 c:\windows\system32\RTCOM\RTLCPAPI.dll

- 2008-03-06 14:29 . 2007-03-07 06:59 131072 c:\windows\system32\RTCOM\RtlCPAPI.dll

+ 2008-03-06 14:28 . 2009-04-10 19:17 266240 c:\windows\system32\RTCOM\RTCOMDLL.dll

+ 2009-01-31 13:46 . 2009-06-20 23:41 185920 c:\windows\system32\rmoc3260.dll

- 2009-01-31 13:46 . 2009-01-31 13:46 185920 c:\windows\system32\rmoc3260.dll

+ 2009-04-26 15:30 . 2007-03-07 06:59 131072 c:\windows\system32\ReinstallBackups\0016\DriverFiles\RTLCPAPI.dll

+ 2009-04-26 15:30 . 2007-03-15 06:39 262144 c:\windows\system32\ReinstallBackups\0016\DriverFiles\RTCOMDLL.dll

+ 2009-04-26 15:30 . 2004-03-16 13:58 136960 c:\windows\system32\ReinstallBackups\0016\DriverFiles\i386\portcls.sys

+ 2009-04-26 15:30 . 2004-08-04 02:15 140928 c:\windows\system32\ReinstallBackups\0016\DriverFiles\i386\ks.sys

+ 2002-09-30 00:25 . 2002-09-30 00:25 229376 c:\windows\system32\PreAnntt.exe

- 2009-01-31 13:45 . 2009-01-31 13:45 278528 c:\windows\system32\pncrt.dll

+ 2009-01-31 13:45 . 2009-06-20 23:41 278528 c:\windows\system32\pncrt.dll

+ 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe

- 2009-01-11 12:45 . 2009-01-11 12:45 148888 c:\windows\system32\javaws.exe

+ 2009-05-05 23:43 . 2009-03-09 08:19 148888 c:\windows\system32\javaws.exe

- 2009-01-11 12:45 . 2009-01-11 12:45 144792 c:\windows\system32\javaw.exe

+ 2009-05-05 23:43 . 2009-03-09 08:19 144792 c:\windows\system32\javaw.exe

- 2009-01-11 12:45 . 2009-01-11 12:45 144792 c:\windows\system32\java.exe

+ 2009-05-05 23:43 . 2009-03-09 08:19 144792 c:\windows\system32\java.exe

+ 2004-08-04 03:45 . 2006-08-09 23:58 218624 c:\windows\system32\dllcache\uxtheme.dll

+ 2004-03-16 13:58 . 2004-03-16 13:58 136960 c:\windows\system32\dllcache\portcls.sys

+ 2009-01-11 12:45 . 2009-03-09 08:19 410984 c:\windows\system32\deploytk.dll

- 2009-01-11 12:45 . 2009-01-11 12:45 410984 c:\windows\system32\deploytk.dll

+ 2009-05-24 03:25 . 2009-03-09 18:27 453456 c:\windows\system32\d3dx10_41.dll

+ 2009-05-24 03:25 . 2008-10-15 09:22 452440 c:\windows\system32\d3dx10_40.dll

+ 2009-05-24 03:25 . 2008-07-10 14:01 467984 c:\windows\system32\d3dx10_39.dll

+ 2009-05-24 03:25 . 2008-05-30 17:11 467984 c:\windows\system32\d3dx10_38.dll

+ 2007-05-15 11:21 . 2007-05-15 11:21 323584 c:\windows\SetupX32.EXE

+ 2009-04-26 15:29 . 2009-03-17 17:07 122880 c:\windows\RtkAudioService.exe

+ 2009-05-20 23:07 . 2006-10-22 00:56 382976 c:\windows\Resources\Themes\Shell\NormalColor\Shellstyle.dll

+ 2009-05-20 23:07 . 2006-10-22 00:56 382976 c:\windows\Resources\Themes\Shell\Bottom48\Shellstyle.dll

+ 2009-05-20 23:07 . 2006-10-22 00:56 382976 c:\windows\Resources\Themes\Shell\Bottom32\Shellstyle.dll

+ 2009-05-20 23:07 . 2006-10-22 00:56 382976 c:\windows\Resources\Themes\Shell\Aero48\Shellstyle.dll

+ 2009-05-20 23:29 . 2006-10-22 00:56 749568 c:\windows\Resources\Themes\Seven\Shell\NormalColor\Shellstyle.dll

+ 2009-05-20 23:28 . 2006-10-22 00:56 665088 c:\windows\Resources\Themes\AeroUltimate\Shell\NormalColor\Shellstyle.dll

+ 2009-05-20 23:28 . 2006-10-22 00:56 665088 c:\windows\Resources\Themes\AeroGlass\Shell\NormalColor\Shellstyle.dll

+ 2009-05-02 18:08 . 2009-05-02 18:08 216358 c:\windows\Installer\{E48469CC-635E-4FD5-A122-1497C286D217}\ARPPRODUCTICON.exe

- 2008-12-23 13:14 . 2008-12-23 13:14 295606 c:\windows\Installer\{AC76BA86-7AD7-1046-7B44-A81300000003}\SC_Reader.exe

+ 2008-12-23 13:14 . 2009-06-20 12:21 295606 c:\windows\Installer\{AC76BA86-7AD7-1046-7B44-A81300000003}\SC_Reader.exe

+ 2007-01-23 13:39 . 2007-01-23 13:39 443904 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76401B7448A3100000030\8.1.3\JP2KLib.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll

+ 2009-06-07 01:21 . 2009-06-07 01:21 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll

+ 2009-06-07 01:21 . 2009-06-07 01:21 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll

+ 2009-06-07 01:21 . 2009-06-07 01:21 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll

+ 2009-06-07 01:21 . 2009-06-07 01:21 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll

+ 2009-06-07 01:21 . 2009-06-07 01:21 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll

+ 2009-05-31 20:22 . 2009-05-31 20:22 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2009-05-31 20:22 . 2009-05-31 20:22 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2009-05-31 20:22 . 2009-05-31 20:22 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2009-06-07 01:21 . 2009-06-07 01:21 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2009-05-31 20:22 . 2009-05-31 20:22 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2009-05-31 20:22 . 2009-05-31 20:22 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2009-05-31 20:22 . 2009-05-31 20:22 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2009-05-31 20:22 . 2009-05-31 20:22 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll

+ 2009-06-07 01:21 . 2009-06-07 01:21 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll

+ 2009-04-26 15:30 . 2007-04-04 09:22 1822720 c:\windows\system32\ReinstallBackups\0016\DriverFiles\SkyTel.exe

+ 2009-04-26 15:30 . 2007-01-16 02:39 1191936 c:\windows\system32\ReinstallBackups\0016\DriverFiles\RtlUpd.exe

+ 2009-04-26 15:30 . 2007-03-23 11:19 9715200 c:\windows\system32\ReinstallBackups\0016\DriverFiles\RTLCPL.EXE

+ 2009-04-26 15:30 . 2007-04-10 11:04 4397568 c:\windows\system32\ReinstallBackups\0016\DriverFiles\RtkHDAud.sys

+ 2009-04-26 15:30 . 2006-10-11 09:42 2157568 c:\windows\system32\ReinstallBackups\0016\DriverFiles\MicCal.exe

+ 2009-04-26 15:30 . 2006-05-04 08:26 2808832 c:\windows\system32\ReinstallBackups\0016\DriverFiles\ALCWZRD.EXE

+ 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\system32\Macromed\Flash\NPSWF32.dll

+ 2008-03-06 11:10 . 2009-05-31 13:08 2258744 c:\windows\system32\FNTCACHE.DAT

+ 2009-04-26 15:29 . 2006-01-04 18:41 1389056 c:\windows\system32\drivers\Monfilt.sys

+ 2009-04-26 15:29 . 2008-08-05 23:10 1684736 c:\windows\system32\drivers\Ambfilt.sys

+ 2009-05-24 03:25 . 2009-03-09 18:27 4178264 c:\windows\system32\D3DX9_41.dll

+ 2009-05-24 03:25 . 2008-10-15 09:22 4379984 c:\windows\system32\D3DX9_40.dll

+ 2009-05-24 03:25 . 2008-07-10 14:00 3851784 c:\windows\system32\D3DX9_39.dll

+ 2009-05-24 03:25 . 2008-05-30 17:11 3850760 c:\windows\system32\D3DX9_38.dll

+ 2009-05-24 03:25 . 2009-03-09 18:27 1846632 c:\windows\system32\D3DCompiler_41.dll

+ 2009-05-24 03:25 . 2008-10-15 09:22 2036576 c:\windows\system32\D3DCompiler_40.dll

+ 2009-05-24 03:25 . 2008-07-10 14:00 1493528 c:\windows\system32\D3DCompiler_39.dll

+ 2009-05-24 03:25 . 2008-05-30 17:11 1491992 c:\windows\system32\D3DCompiler_38.dll

+ 2008-03-06 14:29 . 2007-11-20 21:15 1826816 c:\windows\SkyTel.exe

+ 2008-03-06 14:29 . 2008-06-19 19:27 9715200 c:\windows\RTLCPL.EXE

- 2008-03-06 14:29 . 2007-03-23 11:19 9715200 c:\windows\RTLCPL.exe

+ 2008-03-06 14:28 . 2009-03-10 17:32 2168320 c:\windows\MicCal.exe

+ 2009-05-31 20:22 . 2009-05-31 20:22 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2009-02-21 21:17 . 2009-02-21 21:17 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

+ 2009-05-31 20:22 . 2009-05-31 20:22 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll

- 2008-03-06 14:28 . 2006-05-04 08:26 2808832 c:\windows\alcwzrd.exe

+ 2008-03-06 14:28 . 2008-06-19 19:42 2808832 c:\windows\ALCWZRD.EXE

+ 2009-04-26 15:30 . 2007-04-10 07:28 16126464 c:\windows\system32\ReinstallBackups\0016\DriverFiles\RTHDCPL.EXE

+ 2008-10-15 02:42 . 2008-10-15 02:42 13219184 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76401B7448A3100000030\8.1.3\AcroRd32.dll

.

-- Snapshot resetado para data atual --

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]

2008-09-09 00:08 279944 ----a-w- c:\arquivos de programas\AskBarDis\bar\bin\askBar.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7c5c0f58-e061-457d-9033-77307f5ed00c}]

2008-05-21 02:43 1526296 ----a-w- c:\arquivos de programas\TorrentMan\tbTorr.dll

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 25088]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"AVP"="c:\arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-10 206088]

"Persistence"="c:\windows\system32\igfxpers.exe" [2006-10-05 94208]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-05 98304]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-05 114688]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2009-03-09 148888]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016]

"TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2009-06-20 198160]

"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-04-10 17879552]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoChangeStartMenu"= 1 (0x1)

"ForceStartMenuLogOff"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]

"UIHost"="c:\windows\system32\logonui.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]

2005-01-31 18:13 49152 ----a-w- c:\arquiv~1\ARQUIV~1\Stardock\MCPStub.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]

2001-12-21 02:34 24576 ----a-w- c:\arquivos de programas\AlienGUIse\fastload.dll

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Gamma Loader.lnk]

backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^AutoCAD Startup Accelerator.lnk]

backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^WatchLSDriver.lnk]

path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\WatchLSDriver.lnk

backup=c:\windows\pss\WatchLSDriver.lnkCommon Startup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Usuario^Menu Iniciar^Programas^Inicializar^Adobe Gamma.lnk]

path=c:\documents and settings\Usuario\Menu Iniciar\Programas\Inicializar\Adobe Gamma.lnk

backup=c:\windows\pss\Adobe Gamma.lnkStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Usuario^Menu Iniciar^Programas^Inicializar^Mobile Phone Manager.lnk]

backup=c:\windows\pss\Mobile Phone Manager.lnkStartup

 

[HKLM\~\startupfolder\C:^Documents and Settings^Usuario^Menu Iniciar^Programas^Inicializar^Recorte de tela e Iniciador do OneNote 2007.lnk]

path=c:\documents and settings\Usuario\Menu Iniciar\Programas\Inicializar\Recorte de tela e Iniciador do OneNote 2007.lnk

backup=c:\windows\pss\Recorte de tela e Iniciador do OneNote 2007.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"WMPNetworkSvc"=2 (0x2)

"WLSetupSvc"=3 (0x3)

"WinTabService"=2 (0x2)

"usnjsvc"=3 (0x3)

"ose"=2 (0x2)

"odserv"=2 (0x2)

"NetTcpPortSharing"=2 (0x2)

"Microsoft Office Groove Audit Service"=3 (0x3)

"MDM"=2 (0x2)

"idsvc"=3 (0x3)

"HDD & SSD access service"=2 (0x2)

"FLEXnet Licensing Service"=2 (0x2)

"cmpe"=2 (0x2)

"Capture Device Service"=3 (0x3)

"Bonjour Service"=3 (0x3)

"Autodesk Licensing Service"=3 (0x3)

"Adobe LM Service"=3 (0x3)

"a2free"=3 (0x3)

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"c:\\Arquivos de programas\\OnGame\\GunBoundWC\\GunBound.gme"=

"c:\\Arquivos de programas\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe"=

"c:\\Arquivos de programas\\DNA\\btdna.exe"=

"c:\\Arquivos de programas\\DAP\\DAP.exe"=

"c:\\BMW M3 Challenge\\BMW.exe"=

"c:\\Arquivos de programas\\Aspyr\\Guitar Hero III\\GH3.exe"=

"c:\\Arquivos de programas\\FrostWire\\FrostWire.exe"=

"c:\\Arquivos de programas\\Orbitdownloader\\orbitdm.exe"=

"c:\\Arquivos de programas\\Orbitdownloader\\orbitnet.exe"=

"c:\\Arquivos de programas\\Arquivos comuns\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=

"d:\\Meus Documentos\\LFS\\LFS Pack\\LFS.exe"=

"c:\\Arquivos de programas\\Hamachi\\hamachi.exe"=

"c:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"=

"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=

"c:\\Documents and Settings\\All Users\\Dados de aplicativos\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Brazilian\\setup.exe"=

"c:\\WINDOWS\\system32\\mmc.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\SopCast\\adv\\SopAdver.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=

"c:\\WINDOWS\\system32\\PnkBstrA.exe"=

"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

"c:\\Arquivos de programas\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=

"c:\\Arquivos de programas\\BitTorrent\\bittorrent.exe"=

"d:\\Meus Documentos\\LFS\\LFS Pack\\LfsRevLimiter.0.9.exe"=

"d:\\Meus Documentos\\D1GP\\racer.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"5353:TCP"= 5353:TCP:Adobe CSI CS4

 

R0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys --> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?]

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 16:29 33808]

R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 16:06 24592]

R3 PTSimBus;PenTablet Bus Enumerator;c:\windows\system32\drivers\PTSimBus.sys [07/06/2007 14:16 18944]

R3 PTSimHid;PenTablet Simulated HID MiniDriver;c:\windows\system32\drivers\PTSimHid.sys [23/04/2007 12:28 10752]

R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\drivers\RMSPPPOE.SYS [10/06/2002 00:09 31232]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [26/04/2009 12:29 1684736]

S3 CrystalSysInfo;CrystalSysInfo;\??\c:\arquivos de programas\MediaCoder\SysInfo.sys --> c:\arquivos de programas\MediaCoder\SysInfo.sys [?]

S3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windows\system32\drivers\PPJoyBus.sys [23/01/2004 16:33 13952]

S3 PPortJoystick;Parallel Port Joystick device driver;c:\windows\system32\drivers\PPortJoy.sys [23/01/2004 16:32 28800]

S3 siusbmod;siusbmod;c:\windows\system32\drivers\siusbmod.sys [09/08/2005 12:13 27008]

S4 akl_svc;Anti-keylogger Service;c:\windows\system32\akl_svc.exe --> c:\windows\system32\akl_svc.exe [?]

S4 cmpe;Context Manager Process Extension;c:\windows\system32\cmpe.exe --> c:\windows\system32\cmpe.exe [?]

S4 HDD & SSD access service;HDD & SSD access service;"c:\arquivos de programas\Arquivos comuns\BinarySense\disksvc.exe" --> c:\arquivos de programas\Arquivos comuns\BinarySense\disksvc.exe [?]

 

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

.

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.ask.com/?o=101677&l=dis

uInternet Settings,ProxyServer = socks=

uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,

IE: &Clean Traces - c:\arquivos de programas\DAP\Privacy Package\dapcleanerie.htm

IE: &Download by Orbit - c:\arquivos de programas\Orbitdownloader\orbitmxt.dll/201

IE: &Download with &DAP - c:\arquivos de programas\DAP\dapextie.htm

IE: &Grab video by Orbit - c:\arquivos de programas\Orbitdownloader\orbitmxt.dll/204

IE: Add to AMV Convert Tool... - c:\arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

IE: Atualizar imagem com qualidade total - c:\arquivos de programas\Acelerador Propel Edição iG\pac-image.html

IE: Atualizar página com qualidade total - c:\arquivos de programas\Acelerador Propel Edição iG\pac-page.html

IE: Autorizar pop-ups deste site - c:\arquivos de programas\Acelerador Propel Edição iG\pac-addwl.html

IE: Do&wnload selected by Orbit - c:\arquivos de programas\Orbitdownloader\orbitmxt.dll/203

IE: Down&load all by Orbit - c:\arquivos de programas\Orbitdownloader\orbitmxt.dll/202

IE: Download &all with DAP - c:\arquivos de programas\DAP\dapextie2.htm

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: MediaManager tool grab multimedia file - c:\arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

Trusted Zone: kboing.com.br\www

TCP: {04677822-EA51-4FFC-B13A-F90BCA479E93} = 200.165.132.148 200.165.132.155

Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\arquiv~1\DAP\dapie.dll

Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\arquiv~1\DAP\dapie.dll

Name-Space Handler: HTTPS\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\arquiv~1\DAP\dapie.dll

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

FF - ProfilePath -

 

---- FIREFOX POLICIES ----

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

.

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-06-23 21:20

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_USERS\S-1-5-21-527237240-484763869-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]

@Denied: (Full) (LocalSystem)

 

[HKEY_USERS\S-1-5-21-527237240-484763869-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{46954830-9B4B-B97B-1BF6-A174BBFB0B2F}*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,62,3b,4a,58,7a,

a5,93,15,c8,28,51,af,b0,29,a3,98,91,0f,5c,ee,f7,68,ce,61,e2,63,26,f1,3f,c8,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,fc,91,14,f0,35,

db,ad,50,71,3b,04,66,8b,46,0d,96,ff,0e,0e,7e,66,c5,9d,39,6a,9c,d6,61,af,45,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,c0,8c,0b,c2,c0,

0b,d7,04,25,da,ec,7e,55,20,c9,26,a1,e8,70,cb,4f,08,7d,f7,ff,7c,85,e0,43,d4,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,23,58,b4,e1,48,

ba,6f,1f,3e,1e,9e,e0,57,5a,93,61,60,33,ac,87,c2,1f,a9,f1,86,8c,21,01,be,91,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,8a,b0,db,b5,02,

19,4f,59,cd,44,cd,b9,a6,33,6c,cd,3f,e9,63,53,88,da,3e,cf,f5,1d,4d,73,a8,13,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,f5,1a,e1,3b,a6,

90,05,bf,b0,18,ed,a7,3f,8d,37,a4,7b,c1,2c,81,23,76,fd,6f,df,20,58,62,78,6b,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"4d370831d2c43cd13623e232fed27b7b"=hex:97,20,4e,9a,c7,f1,35,ee,e3,c9,b3,49,f2,

bd,37,ea,31,77,e1,ba,b1,f8,68,02,4d,6b,7d,ef,34,1c,28,35,fb,a7,78,e6,12,2f,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"1d68fe701cdea33e477eb204b76f993d"=hex:aa,52,c6,00,84,3c,26,64,fa,52,2d,28,dc,

83,17,b9,83,6c,56,8b,a0,85,96,ab,a4,da,31,f0,41,04,98,f4,01,3a,48,fc,e8,04,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,77,cf,7c,55,64,

5c,5c,25,51,fa,6e,91,28,9e,14,cc,5f,f8,61,37,a8,b9,84,86,f6,0f,4e,58,98,5b,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,b5,43,67,23,bf,

03,a8,27,b1,cd,45,5a,a8,c4,f8,b9,51,3f,9a,4d,dd,28,7f,64,3d,ce,ea,26,2d,45,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,f8,86,a4,86,62,

0b,fd,a8,e3,0e,66,d5,eb,bc,2f,6b,be,fd,f8,e3,b4,36,c2,d4,2a,b7,cc,b5,b9,7f,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]

"ThreadingModel"="Apartment"

@="c:\\WINDOWS\\system32\\OLE32.DLL"

"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,8c,a5,d4,ca,f6,

5c,10,89,fa,ea,66,7f,d4,3b,6b,70,87,92,de,96,d0,d4,d1,97,6c,43,2d,1e,aa,22,\

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(1572)

c:\windows\system32\sfc_os.dll

c:\arquiv~1\ARQUIV~1\Stardock\mcpstub.dll

c:\arquivos de programas\AlienGUIse\fastload.dll

c:\arquivos de programas\Arquivos comuns\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

c:\windows\system32\cscui.dll

 

- - - - - - - > 'lsass.exe'(1652)

c:\windows\system32\psbase.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\windows\system32\scardsvr.exe

c:\windows\system32\netdde.exe

c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe

c:\windows\system32\clipsrv.exe

c:\windows\system32\dllhost.exe

c:\arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

c:\arquivos de programas\Java\jre6\bin\jqs.exe

c:\windows\system32\nvsvc32.exe

c:\windows\system32\locator.exe

c:\windows\system32\dllhost.exe

c:\windows\system32\vssvc.exe

c:\arquiv~1\ARQUIV~1\Stardock\SDMCP.exe

c:\windows\system32\wbem\wmiapsrv.exe

c:\windows\system32\msdtc.exe

.

**************************************************************************

.

Tempo para conclusão: 2009-06-24 21:24 - Máquina reiniciou

ComboFix-quarantined-files.txt 2009-06-24 00:24

ComboFix2.txt 2009-04-21 13:36

ComboFix3.txt 2009-02-02 18:48

 

Pré-execução: 7.866.982.400 bytes disponíveis

Pós execução: 8.379.027.456 bytes disponíveis

 

544

 

HighJackThis:

Logfile of HijackThis v1.99.1

Scan saved at 22:05:31, on 23/06/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\netdde.exe

C:\WINDOWS\system32\clipsrv.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\System32\dmadmin.exe

C:\ARQUIV~1\ARQUIV~1\Stardock\SDMCP.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Windows Media Player\wmplayer.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Program Files\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101677&l=dis

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,

R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Arquivos de programas\TorrentMan\tbTorr.dll

O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Arquivos de programas\TorrentMan\tbTorr.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Arquivos de programas\TorrentMan\tbTorr.dll

O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll

O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/201

O8 - Extra context menu item: &Download with &DAP - C:\Arquivos de programas\DAP\dapextie.htm

O8 - Extra context menu item: &Grab video by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/204

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: Atualizar imagem com qualidade total - C:\Arquivos de programas\Acelerador Propel Edição iG\pac-image.html

O8 - Extra context menu item: Atualizar página com qualidade total - C:\Arquivos de programas\Acelerador Propel Edição iG\pac-page.html

O8 - Extra context menu item: Autorizar pop-ups deste site - C:\Arquivos de programas\Acelerador Propel Edição iG\pac-addwl.html

O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/203

O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202

O8 - Extra context menu item: Download &all with DAP - C:\Arquivos de programas\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: Estatísticas de proteção de tráfego da web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1229694026046

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{04677822-EA51-4FFC-B13A-F90BCA479E93}: NameServer = 200.165.132.148 200.165.132.155

O17 - HKLM\System\CS1\Services\Tcpip\..\{04677822-EA51-4FFC-B13A-F90BCA479E93}: NameServer = 200.165.132.148 200.165.132.155

O17 - HKLM\System\CS2\Services\Tcpip\..\{04677822-EA51-4FFC-B13A-F90BCA479E93}: NameServer = 200.165.132.148 200.165.132.155

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: MCPClient - C:\ARQUIV~1\ARQUIV~1\Stardock\mcpstub.dll

O20 - Winlogon Notify: WB - C:\Arquivos de programas\AlienGUIse\fastload.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O21 - SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Arquivos de programas\Stardock\Object Desktop\IconPackager\iprepair.dll

O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

Agradeço desde já pela ajuda!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ola Luiz psYco,

 

Não fique executando o comboFix por contra própria, execute-o somente quando eu pedir. O log mostra que você utilizou o programa 3 vezes. Peço também que você siga os meus passos na ordem, seguindo todos os procedimentos não terá nenhum problema. :)

 

1) Passo:

 

• Vá a este Link,e baixe: < Malwarebytes >

Atualize o programa!

• Escolha o escaneamento Rápido!

Desabilite programas de proteção,ao executar o malwarebytes.

• Procure enviar os ítens detectados para a quarentena,clicando em Remover itens.

• Para maiores detalhes: < Link >

-----------------------

• Poste,os relatórios: mbam-log-2008-xx-xx (00-00-00).txt + HijackThis,atualizado.

 

2) Passo:

 

• Baixe: < ToolBar S&D >

• Salve-o no Disco Local-C, em uma pasta própria.

• Reinicie o computador, em Modo de Segurança. <-- Importante!

• Execute o programa, e à seguir, aperte o "p" --> Enter --> Ok.

• Digite o dois! ( 2 ) --> Aperte Enter --> Aguarde!

• Terminando, poste o relatório. ( C:\ToolBar SD\TB_1.txt )

• Poste, também, HijackThis atualizado.

 

3) Passo:

 

Faça o download do ATF-Cleaner.exe

 

- Execute a Ferramenta ATF-Cleaner.exe. Marque a opção Select All e clique em Empty Selected. Aparecerá uma janela "Done Cleaning". Clique em OK e Exit.

 

Poste os resultados e informe como estar o PC <- importante

 

Tenha um bom dia.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PedroN, obrigado pelas dicas.

Aqui vao os logs que você pediu.

 

mbam-log-2008-xx-xx (00-00-00).txt:

Malwarebytes' Anti-Malware 1.38

Versão do banco de dados: 2340

Windows 5.1.2600 Service Pack 2

 

26/06/2009 22:04:20

mbam-log-2009-06-26 (22-04-20).txt

 

Tipo de Verificação: Rápida

Objetos verificados: 96699

Tempo decorrido: 4 minute(s), 18 second(s)

 

Processos da Memória infectados: 0

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 0

Valores do Registro infectados: 0

Ítens do Registro infectados: 2

Pastas infectadas: 1

Arquivos infectados: 0

 

Processos da Memória infectados:

(Nenhum ítem malicioso foi detectado)

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

(Nenhum ítem malicioso foi detectado)

 

Valores do Registro infectados:

(Nenhum ítem malicioso foi detectado)

 

Ítens do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

 

Pastas infectadas:

C:\Arquivos de programas\Advantage (Adware.Advantage) -> Quarantined and deleted successfully.

 

Arquivos infectados:

(Nenhum ítem malicioso foi detectado)

 

HighJackThis atualizado:

Logfile of HijackThis v1.99.1

Scan saved at 22:05:24, on 26/06/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\netdde.exe

C:\WINDOWS\system32\clipsrv.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\System32\vssvc.exe

C:\WINDOWS\System32\dmadmin.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\ARQUIV~1\ARQUIV~1\Stardock\SDMCP.exe

C:\Arquivos de programas\AlienGUIse\wbload.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Windows Media Player\wmplayer.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

D:\Meus Documentos\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101677&l=dis

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,

R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Arquivos de programas\TorrentMan\tbTorr.dll

O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Arquivos de programas\TorrentMan\tbTorr.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Arquivos de programas\TorrentMan\tbTorr.dll

O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll

O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/201

O8 - Extra context menu item: &Download with &DAP - C:\Arquivos de programas\DAP\dapextie.htm

O8 - Extra context menu item: &Grab video by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/204

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: Atualizar imagem com qualidade total - C:\Arquivos de programas\Acelerador Propel Edição iG\pac-image.html

O8 - Extra context menu item: Atualizar página com qualidade total - C:\Arquivos de programas\Acelerador Propel Edição iG\pac-page.html

O8 - Extra context menu item: Autorizar pop-ups deste site - C:\Arquivos de programas\Acelerador Propel Edição iG\pac-addwl.html

O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/203

O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202

O8 - Extra context menu item: Download &all with DAP - C:\Arquivos de programas\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: Estatísticas de proteção de tráfego da web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1229694026046

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{04677822-EA51-4FFC-B13A-F90BCA479E93}: NameServer = 200.165.132.148 200.165.132.155

O17 - HKLM\System\CS1\Services\Tcpip\..\{04677822-EA51-4FFC-B13A-F90BCA479E93}: NameServer = 200.165.132.148 200.165.132.155

O17 - HKLM\System\CS2\Services\Tcpip\..\{04677822-EA51-4FFC-B13A-F90BCA479E93}: NameServer = 200.165.132.148 200.165.132.155

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: MCPClient - C:\ARQUIV~1\ARQUIV~1\Stardock\mcpstub.dll

O20 - Winlogon Notify: WB - C:\Arquivos de programas\AlienGUIse\fastload.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O21 - SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Arquivos de programas\Stardock\Object Desktop\IconPackager\iprepair.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

TB:

 

-----------\\ ToolBar S&D 1.2.8 XP/Vista

 

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2

X86-based PC ( Multiprocessor Free : Intel® Pentium® Dual CPU E2160 @ 1.80GHz )

BIOS : BIOS Date: 08/01/07 09:47:33 Ver: 08.00.10

USER : Usuario ( Administrator )

BOOT : Fail-safe boot

Antivirus : Kaspersky Anti-Virus 8.0.0.506 (Not Activated)

C:\ (Local Disk) - NTFS - Total:48 Go (Free:7 Go)

D:\ (Local Disk) - NTFS - Total:100 Go (Free:35 Go)

E:\ (CD or DVD)

F:\ (CD or DVD)

 

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )

Option : [2] ( 26/06/2009|22:10 )

C:\WINDOWS\iun6002.exe

 

-----------\\ REMOVIDOS

 

Deletado! - C:\Arquivos de programas\AskBarDis\bar

Deletado! - C:\Arquivos de programas\AskBarDis\unins000.dat

Deletado! - C:\Arquivos de programas\AskBarDis\unins000.exe

Deletado! - C:\Arquivos de programas\BitLord\BitLord.xml

Deletado! - C:\Arquivos de programas\BitLord\Downloads

Deletado! - C:\Arquivos de programas\BitLord\Downloads.xml

Deletado! - C:\Arquivos de programas\BitLord\lang

Deletado! - C:\Arquivos de programas\BitLord\rules

Deletado! - C:\Arquivos de programas\BitLord\Torrents

Deletado! - C:\WINDOWS\iun6002.exe

Deletado! - C:\Arquivos de programas\AskBarDis

Deletado! - C:\Arquivos de programas\BitLord

 

-----------\\ Procura por Arquivos / Ficheiros ...

 

 

-----------\\ Extensions

 

(Usuario) - {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} => forecastfox

(Usuario) - {4093c4de-454a-4329-8aff-c6b0b123c386} => httpfox

(Usuario) - {5c8bfb7c-9a54-11dc-8314-0800200c9a66} => aero_fox_-3.0.2-fx

(Usuario) - {64161300-e22b-11db-8314-0800200c9a66} => speeddial

(Usuario) - {7c5c0f58-e061-457d-9033-77307f5ed00c} => torrentman

(Usuario) - {B1018341-ED1D-4a84-991D-B4C33320533F} => orkutbar

(Usuario) - {c45c406e-ab73-11d8-be73-000a95be3b12} => webdeveloper

(Usuario) - {c50ca3c4-5656-43c2-a061-13e717f73fc8} => fvd

(Usuario) - {E9A1DEE0-C623-4439-8932-001E7D17607D} => ajtoolbar

 

 

-----------\\ [..\Internet Explorer\Main]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://www.ask.com/?o=101677&l=dis"

"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

"Url"="http://go.microsoft.com/fwlink/?LinkId=75724"

"Url"="http://go.microsoft.com/fwlink/?LinkId=75723"

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

"Start Page"="http://www.msn.com/"

 

 

--------------------\\ Procurando por outras infecções

 

 

Não foram encontradas outras infecções.

 

 

1 - "C:\ToolBar SD\TB_1.txt" - 26/06/2009|22:11 - Option : [2]

 

-----------\\ Verificação completa em 22:11:52,75

 

HighJackThis atualizado:

Logfile of HijackThis v1.99.1

Scan saved at 22:15:32, on 26/06/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\netdde.exe

C:\WINDOWS\system32\clipsrv.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\rsvp.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\System32\vssvc.exe

C:\WINDOWS\System32\dmadmin.exe

C:\ARQUIV~1\ARQUIV~1\Stardock\SDMCP.exe

C:\Arquivos de programas\AlienGUIse\wbload.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

D:\Meus Documentos\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101677&l=dis

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,

R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Arquivos de programas\TorrentMan\tbTorr.dll

O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Arquivos de programas\Orbitdownloader\orbitcth.dll

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL

O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Arquivos de programas\TorrentMan\tbTorr.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Arquivos de programas\TorrentMan\tbTorr.dll

O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/201

O8 - Extra context menu item: &Download with &DAP - C:\Arquivos de programas\DAP\dapextie.htm

O8 - Extra context menu item: &Grab video by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/204

O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Arquivos de programas\MP3 Player Utilities 4.00\AMVConverter\grab.html

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: Atualizar imagem com qualidade total - C:\Arquivos de programas\Acelerador Propel Edição iG\pac-image.html

O8 - Extra context menu item: Atualizar página com qualidade total - C:\Arquivos de programas\Acelerador Propel Edição iG\pac-page.html

O8 - Extra context menu item: Autorizar pop-ups deste site - C:\Arquivos de programas\Acelerador Propel Edição iG\pac-addwl.html

O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/203

O8 - Extra context menu item: Down&load all by Orbit - res://C:\Arquivos de programas\Orbitdownloader\orbitmxt.dll/202

O8 - Extra context menu item: Download &all with DAP - C:\Arquivos de programas\DAP\dapextie2.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Arquivos de programas\MP3 Player Utilities 4.00\MediaManager\grab.html

O9 - Extra button: Estatísticas de proteção de tráfego da web - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\arquivos de programas\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1229694026046

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O17 - HKLM\System\CS1\Services\Tcpip\..\{04677822-EA51-4FFC-B13A-F90BCA479E93}: NameServer = 200.165.132.148 200.165.132.155

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: MCPClient - C:\ARQUIV~1\ARQUIV~1\Stardock\mcpstub.dll

O20 - Winlogon Notify: WB - C:\Arquivos de programas\AlienGUIse\fastload.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O21 - SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Arquivos de programas\Stardock\Object Desktop\IconPackager\iprepair.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

________________________________________________________________________________

__________________

 

Notei que o pc ficou um pouco melhor. O explorer parou de travar, agora está tudo normal, porém tenho um problema com um driver de um dispositivo periferico que utilizo(mesa digitalizadora).

Esse dispositivo possui um mouse e uma caneta que sao reconhecidos sobre uma mesa. Porem, o mouse funciona normal, mas a caneta nao.

Vou tentar reinstalar o driver.

De toda forma, parece que o problema do explorer foi resolvido. Obrigado PedroN!!! :joia:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ola Luiz psYco, obrigado pelo retorno.

 

Acesse este site: http://www.kaspersky.com/virusscanner

 

Clique em Clipboard01-1.jpg

 

Siga as instruções de configuração do verificador conforme imagem abaixo.

 

kosjn0.gif

 

poste o log do scan aqui mesmo no tópico

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ola Luiz psYco,

 

<@> Faça um escaneamento,online,em: < Eset Nod32 >

<@> Utilize o navegador Internet Explorer.

<@> Marque a caixa: "SIM,aceito as condições de uso" --> Iniciar.

<@> Marque a caixa: "YES, I accept the Terms of Use" --> Start.

<@> Aceite a instalação do ActiveX e,ao terminar,salve e poste o relatório. ( C:\Arquivos de programas\EsetOnlineScanner\log )

Compartilhar este post


Link para o post
Compartilhar em outros sites

Fiz o escaneamento e foi encontrado apenas um arquivo infectado.

Porém, o explorer, esporadicamente, reinicia quando estao sendo carregados os programas que inicializam logo apos o logon.

Infelizmente, acho que o problema nao é nunhum Malware...

De toda forma, obrigado pela ajuda. Caso o problema volte a incomodar voltarei a postar.

Muito obrigado mesmo, PedroN! :joia:

Compartilhar este post


Link para o post
Compartilhar em outros sites

Neste caso eu posso fechar este tópico?

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.