kainan 0 Denunciar post Postado Fevereiro 13, 2010 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:17:49, on 13/2/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe C:\Documents and Settings\All Users\Dados de aplicativos\Zwunzi\zwunzi141.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\system32\mmc.exe C:\WINDOWS\system32\DfrgNtfs.exe C:\WINDOWS\system32\DfrgNtfs.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\MessengerDiscovery 2\MessengerDiscovery 2.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Meus documentos\Downloads\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.localstrike.com.ar/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.plusnetwork.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.localstrike.com.ar/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.localstrike.com.ar/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.localstrike.com.ar/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.localstrike.com.ar/ R3 - URLSearchHook: (no name) - - (no file) R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG9\Toolbar\IEToolbar.dll (file missing) O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\arquivos de programas\real\realplayer\rpbrowserrecordplugin.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Arquivos de programas\AVG\AVG9\Toolbar\IEToolbar.dll (file missing) O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Arquivos de programas\AVG\AVG9\Toolbar\IEToolbar.dll (file missing) O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [sXe Injected] C:\Arquivos de programas\sXe Injected\sXe Injected.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [Motive SmartBridge] "C:\ARQUIV~1\ASSIST~1\SMARTB~1\MotiveSB.exe" /restart O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Arquivos de programas\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [dki] c:\tst.com O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [storegrim] C:\DOCUME~1\ADMINI~1\DADOSD~1\SPAMGP~1\KeepMail.exe O4 - HKCU\..\Run: [iCQ] "C:\Arquivos de programas\ICQ6.5\ICQ.exe" silent O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user') O4 - Startup: raw32.dll O4 - Global Startup: Assistente Tecnico Speedy.lnk = C:\Arquivos de programas\Assistente Tecnico Speedy\bin\matcli.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: @C:\Arquivos de programas\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: @C:\Arquivos de programas\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{8704DD1F-AEE6-4803-9B5B-E3B99EA55ECC}: NameServer = 200.204.0.10 200.204.0.138 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: Zwunzi Service - Unknown owner - C:\Documents and Settings\All Users\Dados de aplicativos\Zwunzi\zwunzi141.exe -- End of file - 8404 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 13, 2010 Boa tarde.... *Baixe o AD-Remover e salve-o no desktop *Duplo clique em AD-R.exe e instale o programa. *Duplo clique no ícone criado no desktop e clique em [Oui] *Tecle S > [ENTER] *Aguarde o término *Cole o relatório criado em C:\Ad-Report-SCAN.log Compartilhar este post Link para o post Compartilhar em outros sites
kainan 0 Denunciar post Postado Fevereiro 14, 2010 . ======= LOGFILE OF AD-REMOVER 1.1.4.6_J | ONLY XP/VISTA/7 ======= . Updated by C_XX on 05.02.2010 at 17:34 Contact: AdRemover.contact@gmail.com Website: http://pagesperso-orange.fr/NosTools/ad_remover.html . Launch at: 12:17:52, dom 14/02/2010 | Normal Boot | Option: SCAN Executed from: C:\Ad-Remover\ Operating system: Microsoft® Windows XP™ Service Pack 3 versÆo 5.1.2600 Computer Name: ADMIN | Current user: Administrador . ============== FOUND ELEMENT(S) ============== . Service: *Zwunzi Service* C:\DOCUME~1\ADMINI~1\DADOSD~1\Mozilla\FireFox\Profiles\zag4kr2y.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} C:\Arquivos de programas\Mozilla FireFox\Components\AskSearch.js C:\Arquivos de programas\AskBarDis C:\Arquivos de programas\Zwunzi . HKCU\software\appdatalow\AskBarDis HKCU\software\AskBarDis HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420} HKLM\software\AskBarDis HKLM\software\classes\AskIBar.PopSwatterBarButton HKLM\software\classes\AskIBar.PopSwatterBarButton.1 HKLM\software\classes\AskIBar.PopSwatterSettingsControl HKLM\software\classes\AskIBar.PopSwatterSettingsControl.1 HKLM\software\classes\AskToolBar.SettingsPlugin HKLM\software\classes\AskToolBar.SettingsPlugin.1 HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f} HKLM\Software\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2} HKLM\Software\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E} HKLM\Software\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed} HKLM\Software\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98} HKLM\Software\Classes\CLSID\{571715D7-3395-4DF0-B43C-784836209E60} HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf} HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b} HKLM\Software\Classes\Interface\{4634804A-F0B0-4A74-A550-FC0EEF8A4362} HKLM\Software\Classes\Interface\{4C07EA4F-5F52-4222-B170-4CD9ED33BAEA} HKLM\Software\Classes\Interface\{C44FEFF4-EF0C-4CF7-83D0-92B4266A32B9} HKLM\Software\Classes\Interface\{F131923C-381D-4E4C-A472-4A17118FD742} HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150} HKLM\Software\Classes\TypeLib\{D2E5FA06-DCC7-46F9-BEFF-BFD06F69B9B2} HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98} HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed} HKLM\software\microsoft\windows\currentversion\uninstall\Ask Toolbar_is1 HKLM\software\Trymedia Systems HKLM\software\Zwunzi HKU\s-1-5-21-299502267-1336601894-1177238915-500\software\appdatalow\AskBarDis HKU\s-1-5-21-299502267-1336601894-1177238915-500\software\AskBarDis . ============== Added scan ============== . . * Mozilla FireFox Version 3.6b2 [pt-BR] * . ProfilePath: zag4kr2y.default (Administrador) . (ADMINI~1, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Administrador\Meus documentos (ADMINI~1, prefs.js) Browser.search.defaultenginename, LocalStrike (ADMINI~1, prefs.js) Browser.search.defaulturl, hxxp://search.localstrike.com.ar/?q={searchTerms} (ADMINI~1, prefs.js) Browser.search.selectedEngine, Google (ADMINI~1, prefs.js) Browser.startup.homepage, hxxp://pt-BR.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:pt-BR:official (ADMINI~1, prefs.js) Extensions.enabledItems, jqs@sun.com:1.0,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3,nasanightlaunch@example.com:0.6.20091031 (ADMINI~1, prefs.js) Keyword.URL, hxxp://search.localstrike.com.ar/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= . . * Internet Explorer Version 8.0.6001.18702 * . [HKEY_CURRENT_USER\..\Internet Explorer\Main] . Do404Search: 01000000 Local Page: C:\WINDOWS\system32\blank.htm Show_ToolBar: yes Start Page: hxxp://www.plusnetwork.com/ Search Page: hxxp://search.localstrike.com.ar/ Enable Browser Extensions: yes Search Bar: hxxp://www.google.com/ie Default_Search_URL: hxxp://www.google.com/ie Start Page Redirect Cache: hxxp://br.msn.com/?ocid=iehp Start Page Redirect Cache_TIMESTAMP: f83faf50e49eca01 Start Page Redirect Cache AcceptLangs: pt-br . [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main] . Default_Page_URL: hxxp://search.localstrike.com.ar/ Default_Search_URL: hxxp://search.localstrike.com.ar/ Search Page: hxxp://search.localstrike.com.ar/ Delete_Temp_Files_On_Exit: yes Local Page: C:\WINDOWS\system32\blank.htm Start Page: hxxp://search.localstrike.com.ar/ . [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS] . Tabs: C:\Documents and Settings\All Users\Dados de aplicativos\ICQ\ICQNewTab\newTab.html . =================================== . 4796 Byte(s) - C:\Ad-Report-SCAN[1].log . 349 File(s) - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp 73 File(s) - C:\WINDOWS\Temp 117 File(s) - C:\WINDOWS\Prefetch . 1 File(s) - C:\Ad-Remover\BACKUP 0 File(s) - C:\Ad-Remover\QUARANTINE . End at: 12:27:58 | dom 14/02/2010 - SCAN[1] . ============== E.O.F ============== . Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 14, 2010 *Execute novamente o AD-Remover *Tecle L > [ENTER]...aguarde. O PC poderá ser reiniciado. *Cole o relatório criado em C:\Ad-Report-CLEAN.log e novo log do hijack Compartilhar este post Link para o post Compartilhar em outros sites
kainan 0 Denunciar post Postado Fevereiro 15, 2010 . ======= LOGFILE OF AD-REMOVER 1.1.4.6_J | ONLY XP/VISTA/7 ======= . Updated by C_XX on 05.02.2010 at 17:34 Contact: AdRemover.contact@gmail.com Website: http://pagesperso-orange.fr/NosTools/ad_remover.html . Launch at: 11:28:46, seg 15/02/2010 | Normal Boot | Option: CLEAN Executed from: C:\Ad-Remover\ Operating system: Microsoft® Windows XP™ Service Pack 3 versÆo 5.1.2600 Computer Name: ADMIN | Current user: Administrador . ============== NEUTRALIZED ELEMENT(S) ============== . Service: *Zwunzi Service* (!) -- Temp files deleted. . HKCU\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420} HKLM\software\AskBarDis HKLM\software\Trymedia Systems HKLM\software\Zwunzi . ============== Added scan ============== . . * Mozilla FireFox Version 3.6b2 [pt-BR] * . ProfilePath: zag4kr2y.default (Administrador) . (ADMINI~1, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Administrador\Meus documentos (ADMINI~1, prefs.js) Browser.search.defaultenginename, LocalStrike (ADMINI~1, prefs.js) Browser.search.defaulturl, hxxp://search.localstrike.com.ar/?q={searchTerms} (ADMINI~1, prefs.js) Browser.search.selectedEngine, Google (ADMINI~1, prefs.js) Browser.startup.homepage, hxxp://pt-BR.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:pt-BR:official (ADMINI~1, prefs.js) Extensions.enabledItems, jqs@sun.com:1.0,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0,{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}:6.0.16,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3,nasanightlaunch@example.com:0.6.20091031 (ADMINI~1, prefs.js) Keyword.URL, hxxp://search.localstrike.com.ar/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= . . . * Internet Explorer Version 8.0.6001.18702 * . [HKEY_CURRENT_USER\..\Internet Explorer\Main] . Do404Search: 01000000 Local Page: C:\WINDOWS\system32\blank.htm Show_ToolBar: yes Start Page: hxxp://fr.msn.com/ Enable Browser Extensions: yes Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896 Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Start Page Redirect Cache: hxxp://br.msn.com/?ocid=iehp Start Page Redirect Cache_TIMESTAMP: f83faf50e49eca01 Start Page Redirect Cache AcceptLangs: pt-br Use Search Asst: no Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome . [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main] . Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Delete_Temp_Files_On_Exit: yes Local Page: C:\WINDOWS\system32\blank.htm Start Page: hxxp://fr.msn.com/ Search bar: hxxp://search.msn.com/spbasic.htm . [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS] . Tabs: res://ieframe.dll/tabswelcome.htm . =================================== . 3058 Byte(s) - C:\Ad-Report-CLEAN[1].log . 31 File(s) - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp 4 File(s) - C:\WINDOWS\Temp 9 File(s) - C:\WINDOWS\Prefetch . 19 File(s) - C:\Ad-Remover\BACKUP 0 File(s) - C:\Ad-Remover\QUARANTINE . End at: 11:29:46 | seg 15/02/2010 - CLEAN[1] . ============== E.O.F ============== . Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:33:57, on 15/2/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\VTTimer.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\ARQUIV~1\ASSIST~1\SMARTB~1\MotiveSB.exe C:\Arquivos de programas\Lexmark X1100 Series\lxbkbmgr.exe C:\Arquivos de programas\Lexmark X1100 Series\lxbkbmon.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Assistente Tecnico Speedy\bin\mad.exe C:\ARQUIV~1\Motive\ASSTCO~1\MOTIVE~1.EXE C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\Rar$EX00.593\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R3 - URLSearchHook: (no name) - - (no file) R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file) R3 - URLSearchHook: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Arquivos de programas\MyAshampoo\tbMyAs.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\arquivos de programas\real\realplayer\rpbrowserrecordplugin.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Arquivos de programas\MyAshampoo\tbMyAs.dll O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) O3 - Toolbar: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Arquivos de programas\MyAshampoo\tbMyAs.dll O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [sXe Injected] C:\Arquivos de programas\sXe Injected\sXe Injected.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [Motive SmartBridge] "C:\ARQUIV~1\ASSIST~1\SMARTB~1\MotiveSB.exe" /restart O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Arquivos de programas\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [dki] c:\tst.com O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [storegrim] C:\DOCUME~1\ADMINI~1\DADOSD~1\SPAMGP~1\KeepMail.exe O4 - HKCU\..\Run: [iCQ] "C:\Arquivos de programas\ICQ6.5\ICQ.exe" silent O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - Global Startup: Assistente Tecnico Speedy.lnk = C:\Arquivos de programas\Assistente Tecnico Speedy\bin\matcli.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: @C:\Arquivos de programas\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: @C:\Arquivos de programas\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{8704DD1F-AEE6-4803-9B5B-E3B99EA55ECC}: NameServer = 200.204.0.10 200.204.0.138 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Arquivos de programas\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) -- End of file - 7775 bytes Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 15, 2010 1. *Desative seu antivírus temporariamente Clique com o botão direito do mouse no ícone do Avast que fica rodando ao lado do relógio > Selecione "Pausar a proteção residente" > Confirme. *Faça o download do LopUninstall e salve-o no desktop *Execute-o. Digite os números e clique em [uninstall] 2. *Execute o hijack, clique em [Do a system scan only], selecione as entradas abaixo e clique em [Fix checked] R3 - URLSearchHook: (no name) - - (no file)R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file) O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) 3. *Novo log do hijack *Informe também como está o PC. Compartilhar este post Link para o post Compartilhar em outros sites
kainan 0 Denunciar post Postado Fevereiro 15, 2010 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:45:30, on 15/2/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\VTTimer.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\ARQUIV~1\ASSIST~1\SMARTB~1\MotiveSB.exe C:\Arquivos de programas\Lexmark X1100 Series\lxbkbmgr.exe C:\Arquivos de programas\Lexmark X1100 Series\lxbkbmon.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\1.2.183.13\GoogleCrashHandler.exe C:\Arquivos de programas\Assistente Tecnico Speedy\bin\mad.exe C:\ARQUIV~1\Motive\ASSTCO~1\MOTIVE~1.EXE C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\WINDOWS\explorer.exe C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\Rar$EX00.312\HijackThis.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R3 - URLSearchHook: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Arquivos de programas\MyAshampoo\tbMyAs.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\arquivos de programas\real\realplayer\rpbrowserrecordplugin.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Arquivos de programas\MyAshampoo\tbMyAs.dll O3 - Toolbar: MyAshampoo Toolbar - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Arquivos de programas\MyAshampoo\tbMyAs.dll O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [sXe Injected] C:\Arquivos de programas\sXe Injected\sXe Injected.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [soundMAX] "C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [Motive SmartBridge] "C:\ARQUIV~1\ASSIST~1\SMARTB~1\MotiveSB.exe" /restart O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Arquivos de programas\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [dki] c:\tst.com O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [iCQ] "C:\Arquivos de programas\ICQ6.5\ICQ.exe" silent O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - Global Startup: Assistente Tecnico Speedy.lnk = C:\Arquivos de programas\Assistente Tecnico Speedy\bin\matcli.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: @C:\Arquivos de programas\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: @C:\Arquivos de programas\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing) O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{8704DD1F-AEE6-4803-9B5B-E3B99EA55ECC}: NameServer = 200.204.0.10 200.204.0.138 O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Arquivos de programas\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) -- End of file - 7000 bytes __________________________________________ então ,o computador está bem lento ,alguns executáveis foram excluidos sem eu ter mexido ,mais de resto anda tudo normal. Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 15, 2010 1. *Delete o arquivo Uninstall.exe localizado no desktop 2. *Execute novamente o AD-Remover *Tecle D > [ENTER] 3. *Baixe o OTL e salve-o no desktop *Duplo clique em OTL.exe *Selecione as opções abaixo: [x] Scan All Users [x] Use Company Name WhiteList [x] Skip Microsoft Files [x] LOP Check [x] Purity Check *Em "Extra Registry", selecione: [x] Use SafeList *Clique em [Run Scan] e aguarde o término do processo *Dois relatórios serão criados no desktop chamados: OTL.txt e Extras.txt, cole-os na sua próxima resposta. Compartilhar este post Link para o post Compartilhar em outros sites
kainan 0 Denunciar post Postado Fevereiro 15, 2010 OTL logfile created on: 15/2/2010 19:48:14 - Run 1 OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\Administrador\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy 446,00 Mb Total Physical Memory | 107,00 Mb Available Physical Memory | 24,00% Memory free 1,00 Gb Paging File | 1,00 Gb Available in Paging File | 58,00% Paging File free Paging file location(s): C:\pagefile.sys 750 2000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas Drive C: | 19,53 Gb Total Space | 13,35 Gb Free Space | 68,34% Space Free | Partition Type: NTFS Drive D: | 54,99 Gb Total Space | 53,83 Gb Free Space | 97,89% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded Drive I: | 23,76 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: ADMIN Current User Name: Administrador Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Standard ========== Processes (SafeList) ========== PRC - [2010/02/15 19:42:10 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrador\Desktop\OTL.exe PRC - [2010/02/15 12:25:49 | 000,136,176 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\1.2.183.13\GoogleCrashHandler.exe PRC - [2010/02/05 20:38:09 | 000,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe PRC - [2010/02/05 15:36:00 | 000,527,344 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe PRC - [2009/10/11 03:17:36 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Arquivos de programas\Java\jre6\bin\jusched.exe PRC - [2009/10/11 03:17:35 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Arquivos de programas\Java\jre6\bin\jqs.exe PRC - [2009/09/30 18:58:42 | 000,026,464 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe PRC - [2008/04/14 09:00:00 | 001,035,776 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2005/04/15 15:46:04 | 000,397,312 | ---- | M] (Motive Communications, Inc.) -- C:\Arquivos de programas\Assistente Tecnico Speedy\SmartBridge\MotiveSB.exe PRC - [2005/04/15 13:47:00 | 002,392,064 | ---- | M] (Motive Communications, Inc.) -- C:\Arquivos de programas\Assistente Tecnico Speedy\bin\mad.exe PRC - [2005/04/15 13:47:00 | 000,245,760 | ---- | M] (Motive Communications, Inc.) -- C:\Arquivos de programas\Motive\AsstCommon\MotiveDirectory.exe PRC - [2005/03/08 00:33:28 | 000,053,248 | R--- | M] (S3 Graphics, Inc.) -- C:\WINDOWS\system32\VTTimer.exe PRC - [2003/08/19 08:12:19 | 000,057,344 | ---- | M] (Lexmark International, Inc.) -- C:\Arquivos de programas\Lexmark X1100 Series\lxbkbmgr.exe PRC - [2003/08/19 08:00:39 | 000,053,248 | ---- | M] (Lexmark International, Inc.) -- C:\Arquivos de programas\Lexmark X1100 Series\lxbkbmon.exe PRC - [2003/08/18 07:37:09 | 000,303,104 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\system32\LEXBCES.EXE PRC - [2003/08/18 07:32:55 | 000,174,592 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\system32\LEXPPS.EXE ========== Modules (SafeList) ========== MOD - [2010/02/15 19:42:10 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrador\Desktop\OTL.exe MOD - [2010/02/05 20:38:51 | 000,102,400 | ---- | M] (RealPlayer) -- c:\Arquivos de programas\Real\RealPlayer\browserrecord\chrome\hook\rpchromebrowserrecordhelper.dll MOD - [2009/12/04 10:49:57 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp71.dll MOD - [2009/12/04 10:49:57 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcr71.dll MOD - [2008/04/14 09:00:00 | 001,724,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\GdiPlus.dll MOD - [2008/04/14 09:00:00 | 000,586,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mlang.dll MOD - [2008/04/14 09:00:00 | 000,019,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\linkinfo.dll MOD - [2005/04/15 13:44:56 | 000,122,880 | ---- | M] (Motive Communications, Inc.) -- C:\Arquivos de programas\Assistente Tecnico Speedy\SmartBridge\SBHook.dll ========== Win32 Services (SafeList) ========== SRV - [2009/10/11 03:17:35 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Arquivos de programas\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService) SRV - [2009/09/20 13:18:00 | 003,314,512 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\System32\GameMon.des -- (npggsvc) SRV - [2009/08/24 21:16:36 | 000,406,016 | ---- | M] (mst software GmbH, Germany) [On_Demand | Stopped] -- C:\Arquivos de programas\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe -- (DfSdkS) SRV - [2008/11/20 16:18:52 | 000,136,120 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc) SRV - [2006/10/26 18:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv) SRV - [2006/10/26 12:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Source Engine\OSE.EXE -- (ose) SRV - [2003/08/18 07:37:09 | 000,303,104 | ---- | M] (Lexmark International, Inc.) [Auto | Running] -- C:\WINDOWS\system32\LEXBCES.EXE -- (LexBceS) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | Unknown | Running] -- -- (aswTdi) DRV - File not found [Kernel | Unknown | Running] -- -- (aswSP) DRV - File not found [File_System | Unknown | Running] -- -- (aswMon2) DRV - File not found [File_System | Unknown | Running] -- -- (aswFsBlk) DRV - File not found [Kernel | Unknown | Running] -- -- (Aavmker4) DRV - [2008/11/20 16:19:06 | 000,043,872 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20) DRV - [2008/08/18 18:45:04 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k) DRV - [2008/08/18 18:45:00 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea) DRV - [2008/08/18 18:44:40 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k) DRV - [2008/04/14 09:00:00 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus) DRV - [2008/04/14 09:00:00 | 000,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv) DRV - [2008/04/14 09:00:00 | 000,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink) DRV - [2006/02/07 22:15:02 | 000,244,352 | R--- | M] (Copyright © VIA/S3 Graphics Co, Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vtmini.sys -- (viagfx) DRV - [2005/10/05 14:21:10 | 000,141,312 | R--- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ADIHdAud.sys -- (ADIHdAudAddService) DRV - [2005/08/11 10:49:28 | 000,393,088 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService) DRV - [2005/03/04 17:53:00 | 000,127,872 | R--- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\aeaudio.sys -- (AEAudioService) DRV - [2005/01/02 18:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\npptNT2.sys -- (NPPTNT2) DRV - [2004/11/22 18:36:40 | 000,018,003 | ---- | M] (Motive, Inc.) [Kernel | On_Demand | Stopped] -- C:\Arquivos de programas\Common Files\Motive\MRENDIS5.sys -- (MRENDIS5) DRV - [2001/08/17 21:13:08 | 000,027,165 | ---- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fetnd5.sys -- (FETNDIS) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ IE - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://br.msn.com/?ocid=iehp IE - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-br IE - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F8 3F AF 50 E4 9E CA 01 [binary data] IE - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie IE - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = about:blank IE - HKU\S-1-5-21-299502267-1336601894-1177238915-500\Software\Microsoft\Internet Explorer\SearchURL\g, = http://www.google.com/search?q=%s IE - HKU\S-1-5-21-299502267-1336601894-1177238915-500\..\URLSearchHook: {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Arquivos de programas\MyAshampoo\tbMyAs.dll (Conduit Ltd.) IE - HKU\S-1-5-21-299502267-1336601894-1177238915-500\S-1-5-21-299502267-1336601894-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - user.js..browser.search.openintab: false FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Arquivos de programas\AVG\AVG9\Toolbar\Firefox\avg@igeared FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox\components FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox\plugins FF - HKLM\software\mozilla\Mozilla Firefox 3.6b2\extensions\\Components: C:\Arquivos de programas\Mozilla Firefox 3.6 Beta 2\components FF - HKLM\software\mozilla\Mozilla Firefox 3.6b2\extensions\\Plugins: C:\Arquivos de programas\Mozilla Firefox 3.6 Beta 2\plugins [2009/10/27 20:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Extensions [2010/02/14 17:34:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\zag4kr2y.default\extensions [2010/02/14 17:34:44 | 000,000,000 | ---D | M] (MyAshampoo Toolbar) -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\zag4kr2y.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} [2009/11/05 10:48:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\zag4kr2y.default\extensions\nasanightlaunch@example.com [2009/12/07 15:41:30 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\Administrador\Dados de aplicativos\Mozilla\Firefox\Profiles\zag4kr2y.default\searchplugins\icqplugin.xml O1 HOSTS File: ([2008/04/14 09:00:00 | 000,000,776 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Arquivos de programas\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) O2 - BHO: (MyAshampoo Toolbar) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Arquivos de programas\MyAshampoo\tbMyAs.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (MyAshampoo Toolbar) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - C:\Arquivos de programas\MyAshampoo\tbMyAs.dll (Conduit Ltd.) O3 - HKU\S-1-5-21-299502267-1336601894-1177238915-500\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O4 - HKLM..\Run: [dki] c:\tst.com File not found O4 - HKLM..\Run: [Lexmark X1100 Series] C:\Arquivos de programas\Lexmark X1100 Series\lxbkbmgr.exe (Lexmark International, Inc.) O4 - HKLM..\Run: [Motive SmartBridge] C:\Arquivos de programas\Assistente Tecnico Speedy\SmartBridge\MotiveSB.exe (Motive Communications, Inc.) O4 - HKLM..\Run: [soundMAX] C:\Arquivos de programas\Analog Devices\SoundMAX\Smax4.exe File not found O4 - HKLM..\Run: [soundMAXPnP] C:\Arquivos de programas\Analog Devices\Core\smax4pnp.exe File not found O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Arquivos de programas\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [sXe Injected] C:\Arquivos de programas\sXe Injected\sXe Injected.exe File not found O4 - HKLM..\Run: [TkBellExe] C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.) O4 - HKLM..\Run: [VTTrayp] File not found O4 - HKU\S-1-5-21-299502267-1336601894-1177238915-500..\Run: [Google Update] C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe (Google Inc.) O4 - HKU\S-1-5-21-299502267-1336601894-1177238915-500..\Run: [iCQ] C:\Arquivos de programas\ICQ6.5\ICQ.exe File not found O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Assistente Tecnico Speedy.lnk = C:\Arquivos de programas\Assistente Tecnico Speedy\bin\matcli.exe (Motive Communications, Inc.) O4 - Startup: C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE File not found O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideRunAsVerb = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogoff = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1 O7 - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1 O7 - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1 O7 - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1 O7 - HKU\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.) O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de programas\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Arquivos de programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe File not found O9 - Extra Button: @C:\Arquivos de programas\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe File not found O9 - Extra 'Tools' menuitem : @C:\Arquivos de programas\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe File not found O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop Components:0 (Minha página inicial atual) - About:Home O24 - Desktop WallPaper: C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009/10/24 23:41:03 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2005/07/03 23:36:24 | 000,000,034 | R--- | M] () - I:\AUTORUN.INF -- [ CDFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - comfile [open] -- "%1" %* O35 - exefile [open] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2010/02/15 19:42:12 | 000,549,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrador\Desktop\OTL.exe [2010/02/14 20:35:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft [2010/02/14 18:15:35 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Dados de aplicativos\Microsoft [2010/02/14 18:14:34 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Windows Media Connect 2 [2010/02/14 18:12:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF [2010/02/14 18:12:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles [2010/02/14 18:11:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dados de aplicativos\Windows Genuine Advantage [2010/02/14 17:34:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Conduit [2010/02/14 17:34:49 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Conduit [2010/02/14 17:34:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\MyAshampoo [2010/02/14 17:34:46 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\MyAshampoo [2010/02/14 17:34:22 | 000,028,160 | ---- | C] (mst software GmbH, Germany) -- C:\WINDOWS\System32\DfSdkBt.exe [2010/02/14 17:34:14 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Ashampoo [2010/02/14 12:17:44 | 000,000,000 | ---D | C] -- C:\Ad-Remover [2010/02/12 11:49:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Desktop\Apostilas _ Curso-Mangá [2010/02/11 20:25:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Meus documentos\Minhas gravacões de webcam [2010/02/11 17:04:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Meus documentos\My Webcam Recordings [2010/02/11 17:03:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Dados de aplicativos\MessengerDiscovery 2 [2010/02/11 16:54:50 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly [2010/02/11 16:53:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET [2010/02/07 23:34:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Meus documentos\Os Meus Registos [2010/02/05 20:48:32 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\XviD [2010/01/29 14:41:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrador\Dados de aplicativos\LimeWire [2010/01/29 11:44:09 | 000,000,000 | ---D | C] -- C:\Arquivos de programas\Arquivos comuns\SWF Studio [2009/12/16 11:57:29 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Dados de aplicativos\Microsoft [2009/12/16 11:57:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft [2009/11/14 19:50:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Google [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2010/02/15 19:42:10 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrador\Desktop\OTL.exe [2010/02/15 19:30:01 | 000,001,176 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1336601894-1177238915-500UA.job [2010/02/15 18:39:38 | 000,002,969 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2010/02/15 13:51:15 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2010/02/15 13:50:43 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010/02/15 13:33:56 | 000,000,210 | -HS- | M] () -- C:\Documents and Settings\Administrador\ntuser.ini [2010/02/15 13:33:55 | 005,242,880 | -H-- | M] () -- C:\Documents and Settings\Administrador\NTUSER.DAT [2010/02/15 13:33:38 | 005,886,738 | -H-- | M] () -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\IconCache.db [2010/02/15 12:30:38 | 000,002,434 | ---- | M] () -- C:\Documents and Settings\Administrador\Desktop\Google Chrome.lnk [2010/02/15 12:30:00 | 000,001,124 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1336601894-1177238915-500Core.job [2010/02/14 23:32:11 | 000,000,356 | ---- | M] () -- C:\Documents and Settings\Administrador\Meus documentos\Meus documentos.lnk [2010/02/14 20:35:12 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb [2010/02/14 20:35:12 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb [2010/02/14 18:14:47 | 000,000,828 | ---- | M] () -- C:\Documents and Settings\Administrador\Desktop\Windows Media Player.lnk [2010/02/14 18:14:47 | 000,000,558 | ---- | M] () -- C:\WINDOWS\win.ini [2010/02/14 18:13:10 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx [2010/02/14 18:12:07 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf [2010/02/14 18:11:09 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2010/02/14 18:06:03 | 000,000,034 | ---- | M] () -- C:\WINDOWS\System32\oeminfo.ini [2010/02/14 17:34:24 | 000,001,855 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Otimizador Um-Clique.lnk [2010/02/14 17:34:24 | 000,000,901 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ashampoo WinOptimizer 2010 Advanced.lnk [2010/02/11 16:57:42 | 000,797,000 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI [2010/02/11 16:57:42 | 000,406,938 | ---- | M] () -- C:\WINDOWS\System32\perfh016.dat [2010/02/11 16:57:42 | 000,374,236 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010/02/11 16:57:42 | 000,060,624 | ---- | M] () -- C:\WINDOWS\System32\perfc016.dat [2010/02/11 16:57:42 | 000,052,728 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010/02/09 14:26:23 | 000,000,342 | ---- | M] () -- C:\WINDOWS\lexstat.ini [2010/02/08 10:41:37 | 000,000,008 | ---- | M] () -- C:\Documents and Settings\All Users\Dados de aplicativos\SDGLYBMPWPP.SYS [2010/02/05 20:45:45 | 000,007,680 | ---- | M] () -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/02/05 20:38:52 | 000,000,755 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer SP.lnk [2010/02/05 20:38:14 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll [2010/01/24 13:13:28 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Administrador\Desktop\Letra do Samba Enredo 2010.doc [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] ========== Files Created - No Company Name ========== [2010/02/14 23:32:11 | 000,000,356 | ---- | C] () -- C:\Documents and Settings\Administrador\Meus documentos\Meus documentos.lnk [2010/02/14 18:12:07 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf [2010/02/14 18:06:03 | 000,000,034 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini [2010/02/14 17:34:24 | 000,001,855 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Otimizador Um-Clique.lnk [2010/02/14 17:34:24 | 000,000,901 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ashampoo WinOptimizer 2010 Advanced.lnk [2010/02/05 20:38:52 | 000,000,755 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer SP.lnk [2010/01/29 09:47:23 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Administrador\Desktop\Letra do Samba Enredo 2010.doc [2009/12/17 01:48:04 | 000,162,304 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar36.dll [2009/12/17 01:48:04 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar3.dll [2009/12/17 01:48:04 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\ztvunace26.dll [2009/12/17 01:48:04 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\unacev2.dll [2009/12/04 10:53:08 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2009/11/28 13:20:10 | 000,004,608 | ---- | C] () -- C:\WINDOWS\cocowawa.dll [2009/10/31 11:53:55 | 000,000,008 | ---- | C] () -- C:\Documents and Settings\All Users\Dados de aplicativos\SDGLYBMPWPP.SYS [2009/10/29 17:21:44 | 000,007,680 | ---- | C] () -- C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2009/10/28 20:18:22 | 000,000,342 | ---- | C] () -- C:\WINDOWS\lexstat.ini [2009/10/28 16:13:13 | 000,000,033 | ---- | C] () -- C:\WINDOWS\GunzLauncher.INI [2009/08/23 12:06:44 | 000,638,976 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll [2009/08/23 11:43:46 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll [2003/08/18 07:46:38 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\LXBKLCNP.DLL [2002/11/13 12:40:22 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxbkvs.dll [2002/09/13 08:40:06 | 000,000,266 | ---- | C] () -- C:\WINDOWS\System32\lxbkcoin.ini ========== LOP Check ========== [2010/02/13 16:43:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Audacity [2009/11/25 18:59:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Foxit [2010/02/14 17:44:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\LimeWire [2010/02/14 15:30:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\MessengerDiscovery 2 [2009/11/01 19:29:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Opera [2009/12/02 14:43:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\SecondLife [2009/12/17 01:48:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Simply Super Software [2009/12/12 00:00:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\Tibia [2010/02/14 17:44:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrador\Dados de aplicativos\uTorrent [2009/12/13 23:56:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\AVG Security Toolbar [2009/10/28 20:21:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\BVRP Software [2009/11/15 17:04:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\ICQ [2010/01/31 14:07:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Messenger Plus! [2009/12/08 19:25:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Nexon [2009/12/08 19:25:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\NexonUS [2009/12/08 11:25:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\PMB Files [2009/12/17 01:48:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\Simply Super Software [2009/12/20 20:56:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\TEMP [2009/12/16 12:28:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dados de aplicativos\WinZip ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 226 bytes -> C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:4EE74317 < End of report > OTL Extras logfile created on: 15/2/2010 19:48:14 - Run 1 OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\Administrador\Desktop Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: d/M/yyyy 446,00 Mb Total Physical Memory | 107,00 Mb Available Physical Memory | 24,00% Memory free 1,00 Gb Paging File | 1,00 Gb Available in Paging File | 58,00% Paging File free Paging file location(s): C:\pagefile.sys 750 2000 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas Drive C: | 19,53 Gb Total Space | 13,35 Gb Free Space | 68,34% Space Free | Partition Type: NTFS Drive D: | 54,99 Gb Total Space | 53,83 Gb Free Space | 97,89% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded Drive I: | 23,76 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS Computer Name: ADMIN Current User Name: Administrador Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Company Name Whitelist: On Skip Microsoft Files: On File Age = 30 Days Output = Standard ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .html [@ = htmlfile] -- C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) [HKEY_USERS\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Classes\<extension>] .html [@ = ChromeHTML] -- Reg Error: Key error. File not found ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- "C:\Arquivos de programas\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation) htmlfile [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) htmlfile [opennew] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) htmlfile [print] -- "C:\Arquivos de programas\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation) http [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) https [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [OneNote.Open] -- C:\ARQUIV~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Applications\iexplore.exe [open] -- "C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation) CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Arquivos de programas\Internet Explorer\iexplore.exe" (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "57311:TCP" = 57311:TCP:*:Enabled:Pando Media Booster "57311:UDP" = 57311:UDP:*:Enabled:Pando Media Booster ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- File not found "C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" = C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- File not found "C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe -- File not found "C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe -- File not found [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- File not found "C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" = C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- File not found "C:\Level Up! Games\TheDuel\GunzLauncher.exe" = C:\Level Up! Games\TheDuel\GunzLauncher.exe:*:Enabled:TheDuel -- File not found "C:\Level Up! Games\TheDuel\theduel.exe" = C:\Level Up! Games\TheDuel\theduel.exe:*:Enabled:Gunz -- File not found "C:\Level Up! Games\Grand Chase Season 2\main.exe" = C:\Level Up! Games\Grand Chase Season 2\main.exe:*:Enabled:GrandChase -- File not found "C:\Westwood\Renegade\Game.exe" = C:\Westwood\Renegade\Game.exe:*:Enabled:Renegade -- File not found "C:\Arquivos de programas\Microsoft Office\Office12\ONENOTE.EXE" = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation) "C:\Arquivos de programas\Valve\hl.exe" = C:\Arquivos de programas\Valve\hl.exe:*:Enabled:Half-Life Launcher -- File not found "D:\Half-Life\hl.exe" = D:\Half-Life\hl.exe:*:Enabled:Half-Life Launcher -- File not found "D:\Half-Life\hlds.exe" = D:\Half-Life\hlds.exe:*:Enabled:hlds -- File not found "C:\Arquivos de programas\aMSN\bin\wish.exe" = C:\Arquivos de programas\aMSN\bin\wish.exe:*:Enabled:Wish Application -- File not found "C:\Arquivos de programas\Messenger\Msmsgs.exe" = C:\Arquivos de programas\Messenger\Msmsgs.exe:*:Enabled:Windows Messenger -- File not found "C:\Arquivos de programas\OnGame\Metin2\metin2.bin" = C:\Arquivos de programas\OnGame\Metin2\metin2.bin:*:Enabled:metin2 -- File not found "C:\Arquivos de programas\Valve\hlds.exe" = C:\Arquivos de programas\Valve\hlds.exe:*:Enabled:HLDS Launcher -- File not found "C:\Arquivos de programas\SecondLife\SLVoice.exe" = C:\Arquivos de programas\SecondLife\SLVoice.exe:*:Enabled:SLVoice -- File not found "C:\Arquivos de programas\Valve\hltv.exe" = C:\Arquivos de programas\Valve\hltv.exe:*:Enabled:HLTV Launcher -- File not found "C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe" = C:\Arquivos de programas\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- File not found "C:\Documents and Settings\All Users\Dados de aplicativos\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Dados de aplicativos\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager -- File not found "C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe -- File not found "C:\Nexon\Combat Arms\NMService.exe" = C:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core -- File not found "C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*:Enabled:Combat Arms -- File not found "C:\Arquivos de programas\Tibia\Tibia.exe" = C:\Arquivos de programas\Tibia\Tibia.exe:*:Enabled:Tibia Player -- File not found "C:\ChaosGameServer5\Mu.exe" = C:\ChaosGameServer5\Mu.exe:*:Enabled:Jogar MuChaos2 Season 5 -- File not found "C:\Arquivos de programas\LimeWire\LimeWire.exe" = C:\Arquivos de programas\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{13B792AA-C078-43A4-8A3A-8B12D629940D}" = Counter-Strike 1.6 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java 6 Update 17 "{32BC546A-8AA3-4239-AE92-9CF3291C35A6}" = Windows Live Call "{51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}" = Assistente de Conexão do Windows Live "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0 "{90120000-0010-0416-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Portuguese (Brazil)) 12 "{90120000-0016-0416-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Portuguese (Brazil)) 2007 "{90120000-0018-0416-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2007 "{90120000-001B-0416-0000-0000000FF1CE}" = Microsoft Office Word MUI (Portuguese (Brazil)) 2007 "{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007 "{90120000-002C-0416-0000-0000000FF1CE}" = Microsoft Office Proofing (Portuguese (Brazil)) 2007 "{90120000-006E-0416-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Portuguese (Brazil)) 2007 "{90120000-00A1-0416-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Portuguese (Brazil)) 2007 "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007 "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9ABFB92D-93DA-49EE-8ABF-F8195DE45CA9}" = Counter-Strike 1.6 "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{B5ED7AB0-3838-4389-8549-7C8E22DD48F4}" = Windows Live Messenger "{D1E44702-21F5-4918-B8A3-6D126D5BD33C}" = Windows Messenger 5.1 "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F2CD4651-F948-467C-B014-71FD981B7F59}" = Windows Live Essentials "{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Ad-Remover" = Ad-Remover By C_XX "Ashampoo WinOptimizer 2010 Advanced_is1" = Ashampoo WinOptimizer 2010 Advanced "Connection Manager" = Microsoft Connection Manager "Foxit Reader" = Foxit Reader "HijackThis" = HijackThis 2.0.2 "HOMESTUDENTR" = Microsoft Office Home and Student 2007 "ie8" = Windows Internet Explorer 8 "Lexmark X1100 Series" = Lexmark X1100 Series "Messenger Plus! Live" = Messenger Plus! Live "Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0 "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MyAshampoo Toolbar" = MyAshampoo Toolbar "RealPlayer 12.0" = RealPlayer "Speedy" = Speedy "telefonica.MCCInstall" = Assistente Técnico Speedy "VIA/S3G UniChrome Family Win2K/XP/Server2003 Display" = VIA/S3G Display Driver "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "WinRAR archiver" = Arquivo do WinRAR "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XviD Video Codec" = XviD Video Codec (remove only) ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-299502267-1336601894-1177238915-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 13/2/2010 16:30:53 | Computer Name = ADMIN | Source = VSS | ID = 12289 Description = Error - 13/2/2010 16:32:03 | Computer Name = ADMIN | Source = VSS | ID = 12289 Description = Error - 13/2/2010 16:33:09 | Computer Name = ADMIN | Source = VSS | ID = 12289 Description = Error - 13/2/2010 16:34:14 | Computer Name = ADMIN | Source = VSS | ID = 12289 Description = Error - 13/2/2010 16:35:25 | Computer Name = ADMIN | Source = VSS | ID = 12289 Description = Error - 13/2/2010 16:36:32 | Computer Name = ADMIN | Source = VSS | ID = 12289 Description = Error - 13/2/2010 16:37:38 | Computer Name = ADMIN | Source = VSS | ID = 12289 Description = Error - 13/2/2010 16:38:43 | Computer Name = ADMIN | Source = VSS | ID = 12289 Description = Error - 13/2/2010 16:39:48 | Computer Name = ADMIN | Source = VSS | ID = 12289 Description = Error - 13/2/2010 16:40:23 | Computer Name = ADMIN | Source = VSS | ID = 12289 Description = [ System Events ] Error - 10/2/2010 18:44:37 | Computer Name = ADMIN | Source = Service Control Manager | ID = 7034 Description = O serviço Windows Installer foi encerrado inesperadamente. Isso aconteceu 2 vez(es). Error - 10/2/2010 18:45:03 | Computer Name = ADMIN | Source = Service Control Manager | ID = 7034 Description = O serviço Windows Installer foi encerrado inesperadamente. Isso aconteceu 3 vez(es). Error - 15/2/2010 08:44:01 | Computer Name = ADMIN | Source = Service Control Manager | ID = 7009 Description = Tempo limite (30000 milissegundos) de espera para que o serviço avast! Antivirus se conecte. Error - 15/2/2010 08:44:01 | Computer Name = ADMIN | Source = Service Control Manager | ID = 7000 Description = Não foi possível iniciar o serviço avast! Antivirus devido ao seguinte erro: %%1053 Error - 15/2/2010 09:00:42 | Computer Name = ADMIN | Source = Service Control Manager | ID = 7009 Description = Tempo limite (30000 milissegundos) de espera para que o serviço avast! Antivirus se conecte. Error - 15/2/2010 09:00:42 | Computer Name = ADMIN | Source = Service Control Manager | ID = 7000 Description = Não foi possível iniciar o serviço avast! Antivirus devido ao seguinte erro: %%1053 Error - 15/2/2010 10:29:56 | Computer Name = ADMIN | Source = Service Control Manager | ID = 7009 Description = Tempo limite (30000 milissegundos) de espera para que o serviço avast! Antivirus se conecte. Error - 15/2/2010 10:29:56 | Computer Name = ADMIN | Source = Service Control Manager | ID = 7000 Description = Não foi possível iniciar o serviço avast! Antivirus devido ao seguinte erro: %%1053 Error - 15/2/2010 12:52:28 | Computer Name = ADMIN | Source = Service Control Manager | ID = 7009 Description = Tempo limite (30000 milissegundos) de espera para que o serviço avast! Antivirus se conecte. Error - 15/2/2010 12:52:28 | Computer Name = ADMIN | Source = Service Control Manager | ID = 7000 Description = Não foi possível iniciar o serviço avast! Antivirus devido ao seguinte erro: %%1053 < End of report > Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 15, 2010 1. *Delete o OTL e seus relatórios 2. *Execute o hijack, clique em [Do a system scan only], selecione a entrada abaixo e clique em [Fix checked] O4 - HKLM\..\Run: [dki] c:\tst.com *Feche o hijack. Seu log está limpo. 3. *Baixe o ATF Cleaner e salve-o no desktop *Duplo clique em ATF-Cleaner.exe *Em Main selecione [select all] *Clique em [Empty Selected] =>Caso use Firefox ou Opera, também, siga os procedimentos abaixo: *Em "Firefox" ou em "Opera" clique em [select all] ( se você deseja manter suas passwords clique No, caso contrário clique Yes). *Clique [Empty Selected] ( se você deseja manter suas passwords clique No, caso contrário clique Yes). *Clique em [Exit] ou no [X] para sair do programa 4. *Faça o download e instale o CCleaner *Abra o programa e na aba "Windows", desça até a opção "Avançado" e selecione "Dados Prefetch antigos" *Clique em [Executar Limpeza] *Em seguida, clique em [Registro] -> [Procurar erros] -> [Corrigir Erros Selecionados] -> [Corrigir Todos os Erros Selecionados] Use regularmente os programas ATF-Cleaner e CCleaner para manter o PC em ordem. Um abraço. Compartilhar este post Link para o post Compartilhar em outros sites
kainan 0 Denunciar post Postado Fevereiro 16, 2010 Obrigado pela ajuda , abraço Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Fevereiro 16, 2010 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites