haharafa 0 Denunciar post Postado Agosto 24, 2010 Oi, meu nome é Rafael e estou tendo problemas com um vírus. Meu anti-vírus é o Avast, estavatendo alguns problemas com internet e lentidão do sistema então escaniei tudo e foi encontrado um vírus no arquivo BHO.DLL e coloquei em quarentena. Agora quando ligo aparece esta mensagem: "não foi possível iniciar esta aplicação porque BHO.DLL nao foi encontrado. A reinstalação da aplicação poderá corrigir o problema. Quando clico no ok aparece outra janela que diz: "IE3SH application deixou de funcionar um problema fez com que o programa parasse de funcionar corretamente. O windows ira fechar o programa avisá-lo se existir uma solução disponível". Verifiquei na net e vi que o programa "Search Guard Plus Updater" e "Search Guard Plus" são vírus. Desinstalei os dois com o desinstalador do windows e apaguei a pasta, daí então o micro não iniciava mais. Entrei em modo de segurança e restaurei o sistema e voltei do zero. Os dois programas tem a assinatura "My Tattoo" e editor "Make the web better, LLC" o que é uma grande ironia. Posto a baixo o Log do Hijackthis para vcs me ajudarem. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:09:41, on 23/08/2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18943) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\SiS VGA Utilities\SiSTray.exe C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Nokia\Nokia Internet Modem\NokiaInternetModem_AppStart.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Nokia\Nokia Internet Modem\NokiaInternetModem.exe C:\Users\Professor\Desktop\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: SearchHelper Class - {91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} - C:\Program Files\SGPSA\mtwb3sh.dll O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Auxiliar de Conex„o do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [synTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [siSTray] %ProgramFiles%\SiS VGA Utilities\SiSTray.exe O4 - HKLM\..\Run: [sMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [FBSSA] C:\Program Files\SGPSA\ie3sh.exe O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [skytel] Skytel.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [NokiaInternetModem_AppStart.exe] "C:\Program Files\Nokia\Nokia Internet Modem\NokiaInternetModem_AppStart.exe" "-start" "C:\Program Files\Nokia\Nokia Internet Modem\NokiaInternetModem.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Incluir no Blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Incluir no Blog no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: SeleÁ„o HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{8F92C6BB-4437-4438-AADD-666D446379CD}: NameServer = 200.142.130.203 200.220.227.57 O17 - HKLM\System\CS1\Services\Tcpip\..\{8F92C6BB-4437-4438-AADD-666D446379CD}: NameServer = 200.142.130.203 200.220.227.57 O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe -- End of file - 6999 bytes Aguardo resposta. Muito obrigado. Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 24, 2010 Boa tarde... 1. *Baixe o AD-Remover e salve-o no desktop *Execute o AD-Remover *Clique em [scan]....aguarde o término *Cole o relatório criado em C:\Ad-Report-SCAN.log Compartilhar este post Link para o post Compartilhar em outros sites
haharafa 0 Denunciar post Postado Agosto 25, 2010 Muito obrigado pela velocidade na resposta, fiquei feliz agora. Está aqui o relatório: ======= REPORT FROM AD-REMOVER 2.0.0.1,D | ONLY XP/VISTA/7 ======= Updated by C_XX on 26/07/10 at 12:00 Contact: AdRemover.contact[AT]gmail.com website: http://pagesperso-orange.fr/NosTools/ad_remover.html C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Launched at 01:23:46 on 25/08/2010, Normal boot MicrosoftÆ Windows Vistaô Home Basic Service Pack 2 (X86) Professor@ATILA (Positivo Positivo Mobile) ============== SEARCH ============== 0,Folder found: C:\Program Files\Search Guard Plus 0,Folder found: C:\Program Files\Search Guard PlusU 0,Folder found: C:\Program Files\SGPSA 1,Key found: HKLM\Software\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0} 1,Key found: HKLM\Software\Classes\CLSID\{F0626A63-410B-45E2-99A1-3F2475B2D695} 1,Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F0626A63-410B-45E2-99A1-3F2475B2D695} 1,Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0626A63-410B-45E2-99A1-3F2475B2D695} 1,Key found: HKLM\Software\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} 1,Key found: HKLM\Software\Classes\TypeLib\{3088C799-9630-4719-A471-4544D7CABC2D} 1,Key found: HKLM\Software\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D} 0,Key found: HKLM\Software\Classes\BHO.PSHelper 0,Key found: HKLM\Software\Classes\BHO.PSHelper.1 0,Key found: HKLM\Software\Classes\URLSearchHook.ToolbarURLSearchHook 0,Key found: HKLM\Software\Classes\URLSearchHook.ToolbarURLSearchHook.1 0,Key found: HKCU\Software\FBSearch 0,Key found: HKCU\Software\SGPUpdater 3,Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF1C48F7-576A-404B-A01A-81BBEB71BA57} 3,Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{02EFB9A0-B693-4d49-80A7-A20EF4980C33} 0,Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Guard Plus 0,Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Guard Plus Updater 0,Value found: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|FBSSA 0,Value found: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} ============== ADDITIONNAL SCAN ============== ** Internet Explorer Version [8.0.6001.18943] ** [HKCU\Software\Microsoft\Internet Explorer\Main] AutoHide: yes Do404Search: 0x01000000 Enable Browser Extensions: yes Local Page: C:\Windows\system32\blank.htm SearchAssistant: Search bar: Search Page: Show_ToolBar: yes Start Page: hxxp://www.google.com.br/ Use Search Asst: [HKLM\Software\Microsoft\Internet Explorer\Main] AutoHide: yes Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157 Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896 Delete_Temp_Files_On_Exit: yes Local Page: C:\Windows\System32\blank.htm Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896 Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157 [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS] Tabs: hxxp://www.fastbrowsersearch.com/new-tab/?v=18&tid={FDB182B6-6CBB-46bd-B4F1-DF7775615E4E} Blank: res://mshtml.dll/blank.htm ======================================== C:\Program Files\Ad-Remover\Quarantine: 0 File(s) C:\Program Files\Ad-Remover\Backup: 1 File(s) C:\Ad-Report-SCAN[1].txt - 25/08/2010 (3296 Byte(s)) End at: 01:26:17, 25/08/2010 ============== E.O.F ============== Muito obrigado. Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 25, 2010 *Execute novamente o AD-Remover *Clique em [Clean]...aguarde o término. A reinicialização do PC poderá ser solicitada pelo programa. *Cole o relatório criado em C:\Ad-Report-CLEAN.log Compartilhar este post Link para o post Compartilhar em outros sites
haharafa 0 Denunciar post Postado Agosto 26, 2010 Está tudo muito rápido agora. Posso fazer esta ação de escaniar e limpar com frequência sem precisar passar pela análise de vcs? ======= REPORT FROM AD-REMOVER 2.0.0.1,D | ONLY XP/VISTA/7 ======= Updated by C_XX on 26/07/10 at 12:00 Contact: AdRemover.contact[AT]gmail.com website: http://pagesperso-orange.fr/NosTools/ad_remover.html C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 23:09:05 on 25/08/2010, Normal boot MicrosoftÆ Windows Vistaô Home Basic Service Pack 2 (X86) Professor@ATILA (Positivo Positivo Mobile) ============== ACTION(S) ============== 0,Folder deleted: C:\Program Files\Search Guard Plus 0,Folder deleted: C:\Program Files\Search Guard PlusU 0,Folder deleted: C:\Program Files\SGPSA (!) -- Temporary files deleted. 1,Key deleted: HKLM\Software\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0} 1,Key deleted: HKLM\Software\Classes\CLSID\{F0626A63-410B-45E2-99A1-3F2475B2D695} 1,Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F0626A63-410B-45E2-99A1-3F2475B2D695} 1,Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0626A63-410B-45E2-99A1-3F2475B2D695} 1,Key deleted: HKLM\Software\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} 1,Key deleted: HKLM\Software\Classes\TypeLib\{3088C799-9630-4719-A471-4544D7CABC2D} 1,Key deleted: HKLM\Software\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D} 0,Key deleted: HKLM\Software\Classes\BHO.PSHelper 0,Key deleted: HKLM\Software\Classes\BHO.PSHelper.1 0,Key deleted: HKLM\Software\Classes\URLSearchHook.ToolbarURLSearchHook 0,Key deleted: HKLM\Software\Classes\URLSearchHook.ToolbarURLSearchHook.1 0,Key deleted: HKCU\Software\FBSearch 0,Key deleted: HKCU\Software\SGPUpdater 3,Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF1C48F7-576A-404B-A01A-81BBEB71BA57} 3,Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{02EFB9A0-B693-4d49-80A7-A20EF4980C33} 0,Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Guard Plus 0,Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Guard Plus Updater 0,Value deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|FBSSA 0,Value deleted: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{91C18ED5-5E1C-4AE5-A148-A861DE8C8E16} ============== ADDITIONNAL SCAN ============== ** Internet Explorer Version [8.0.6001.18943] ** [HKCU\Software\Microsoft\Internet Explorer\Main] AutoHide: yes Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Do404Search: 0x01000000 Enable Browser Extensions: yes Local Page: C:\Windows\system32\blank.htm SearchAssistant: Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896 Show_ToolBar: yes Start Page: hxxp://fr.msn.com/ Use Search Asst: [HKLM\Software\Microsoft\Internet Explorer\Main] AutoHide: yes Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896 Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Delete_Temp_Files_On_Exit: yes Local Page: C:\Windows\System32\blank.htm Search bar: hxxp://search.msn.com/spbasic.htm Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Start Page: hxxp://fr.msn.com/ [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS] Tabs: res://ieframe.dll/tabswelcome.htm Blank: res://mshtml.dll/blank.htm ======================================== C:\Program Files\Ad-Remover\Quarantine: 14 File(s) C:\Program Files\Ad-Remover\Backup: 15 File(s) C:\Ad-Report-CLEAN[1].txt - 25/08/2010 (3566 Byte(s)) End at: 23:11:11, 25/08/2010 ============== E.O.F ============== Muito obrigado mesmo. Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 26, 2010 1. *Execute novamente o AD-Remover *Clique em [uninstall] 2. *Baixe o DDS e salve-o no desktop *Desative temporariamente seu antivírus *Execute o DDS e aguarde. *Salve os relatórios (DDS.txt e Attach.txt) no desktop e cole-os na sua próxima resposta. Compartilhar este post Link para o post Compartilhar em outros sites
haharafa 0 Denunciar post Postado Agosto 27, 2010 DDS.txt DDS (Ver_10-03-17.01) - NTFSx86 Run by Professor at 0:48:35,16 on 27/08/2010 Internet Explorer: 8.0.6001.18943 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.55.1046.18.1788.945 [GMT -3:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPStart.exe C:\Program Files\SiS VGA Utilities\SiSTray.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Nokia\Nokia Internet Modem\NokiaInternetModem_AppStart.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Nokia\Nokia Internet Modem\NokiaInternetModem.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Windows\system32\conime.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Professor\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com.br/ uWindow Title = BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Auxiliar de Conexão do Windows Live ID: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll uRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [synTPStart] c:\program files\synaptics\syntp\SynTPStart.exe mRun: [siSTray] %ProgramFiles%\SiS VGA Utilities\SiSTray.exe mRun: [sMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [iSUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [skytel] Skytel.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [NokiaInternetModem_AppStart.exe] "c:\program files\nokia\nokia internet modem\nokiainternetmodem_appstart.exe" "-start" "c:\program files\nokia\nokia internet modem\NokiaInternetModem.exe" mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xportar para o Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab ============= SERVICES / DRIVERS =============== R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-8-26 11608] R1 Cloverh;Cloverh;c:\windows\system32\drivers\Cloverh.sys [2009-3-20 7680] R2 AntiVirSchedulerService;Avira AntiVir Programador;c:\program files\avira\antivir desktop\sched.exe [2010-8-26 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-8-26 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-8-26 56816] R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2009-4-30 113504] R3 nokia_cs1x_cdc_acm;Nokia Internet Stick CDC-ACM driver;c:\windows\system32\drivers\nokia_cs1x_cdc_acm.sys [2010-1-20 86016] R3 nokia_cs1x_dc_enum;Nokia Internet Stick DC Enumerator;c:\windows\system32\drivers\nokia_cs1x_dc_enum.sys [2010-1-20 80000] R3 SiS6350;SiS6350;c:\windows\system32\drivers\SISGRKMD.sys [2009-4-30 463360] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\drivers\SiSGB6.sys [2009-3-6 48128] S3 FontCache;Serviço de Cache de Fontes do Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] S3 nokia_cs1x_cpo;Nokia Internet Stick Mass Storage Device;c:\windows\system32\drivers\nokia_cs1x_cpo.sys [2010-1-20 9856] S3 RTL8187;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [2009-3-13 221696] S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [2010-3-31 350720] =============== Created Last 30 ================ 2010-08-26 05:33:07 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2010-08-26 05:33:05 0 d-----w- c:\programdata\Avira 2010-08-26 05:33:05 0 d-----w- c:\program files\Avira 2010-08-24 16:17:10 0 d-----w- c:\programdata\WindowsSearch 2010-08-19 14:22:10 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll 2010-08-19 14:22:10 49472 ----a-w- c:\windows\system32\netfxperf.dll 2010-08-19 14:22:10 297808 ----a-w- c:\windows\system32\mscoree.dll 2010-08-19 14:22:10 295264 ----a-w- c:\windows\system32\PresentationHost.exe 2010-08-19 14:22:09 1130824 ----a-w- c:\windows\system32\dfshim.dll 2010-08-18 21:49:09 1248768 ----a-w- c:\windows\system32\msxml3.dll 2010-08-18 21:48:53 3600768 ----a-w- c:\windows\system32\ntkrnlpa.exe 2010-08-18 21:48:50 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe 2010-08-18 21:48:35 302080 ----a-w- c:\windows\system32\drivers\srv.sys 2010-08-18 21:48:34 144896 ----a-w- c:\windows\system32\drivers\srv2.sys 2010-08-18 21:48:24 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys 2010-08-18 21:47:57 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2010-08-18 21:47:57 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2010-08-07 04:43:31 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nokia_cs1x_cdc_acm_01009.Wdf 2010-08-07 04:34:41 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nokia_cs1x_dc_enum_01009.Wdf 2010-08-07 04:34:38 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf 2010-08-07 04:34:06 3 ----a-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf 2010-08-07 04:34:00 4052 ----a-w- c:\windows\system32\wbem\Wdf01000.mof 2010-08-07 04:34:00 38480 ----a-w- c:\windows\system32\drivers\WdfLdr.sys 2010-08-07 04:34:00 118 ----a-w- c:\windows\system32\wbem\Wdf01000Uninstall.mof 2010-08-07 04:33:59 445008 ----a-w- c:\windows\system32\drivers\Wdf01000.sys 2010-08-07 04:33:22 0 d-----w- c:\program files\Nokia ==================== Find3M ==================== 2010-08-27 03:42:32 678046 ----a-w- c:\windows\system32\prfh0416.dat 2010-08-27 03:42:32 143298 ----a-w- c:\windows\system32\prfc0416.dat 2010-08-21 04:41:42 51200 ----a-w- c:\windows\inf\infpub.dat 2010-08-21 04:41:41 86016 ----a-w- c:\windows\inf\infstor.dat 2010-08-21 04:41:41 143360 ----a-w- c:\windows\inf\infstrng.dat 2010-07-17 08:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll 2010-06-26 06:05:49 916480 ----a-w- c:\windows\system32\wininet.dll 2010-06-26 06:02:15 71680 ----a-w- c:\windows\system32\iesetup.dll 2010-06-26 06:02:15 109056 ----a-w- c:\windows\system32\iesysprep.dll 2010-06-26 04:25:02 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2010-06-21 13:37:03 2037760 ----a-w- c:\windows\system32\win32k.sys 2010-06-18 17:31:29 36864 ----a-w- c:\windows\system32\rtutils.dll 2010-06-11 16:16:20 274944 ----a-w- c:\windows\system32\schannel.dll 2010-01-05 14:48:07 665600 ----a-w- c:\windows\inf\drvindex.dat 2008-01-21 06:29:51 37412 ----a-w- c:\windows\inf\perflib\0416\perfd.dat 2008-01-21 06:29:51 37412 ----a-w- c:\windows\inf\perflib\0416\perfc.dat 2008-01-21 06:29:51 318818 ----a-w- c:\windows\inf\perflib\0416\perfi.dat 2008-01-21 06:29:51 318818 ----a-w- c:\windows\inf\perflib\0416\perfh.dat 2008-01-21 02:57:01 174 --sha-w- c:\program files\desktop.ini 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 0:48:55,55 =============== Attach.txt UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft® Windows Vista™ Home Basic Boot Device: \Device\HarddiskVolume1 Install Date: 26/05/2009 16:59:43 System Uptime: 26/08/2010 05:04:33 (19 hours ago) Motherboard: clevo | | M7x0S Processor: Intel® Pentium® Dual CPU T3400 @ 2.16GHz | uPGA 479M | 1333/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 139 GiB total, 67,092 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Adaptador do Microsoft 6to4 Device ID: ROOT\*6TO4MP\0000 Manufacturer: Microsoft Name: Adaptador do Microsoft 6to4 PNP Device ID: ROOT\*6TO4MP\0000 Service: tunnel ==== System Restore Points =================== RP272: 23/08/2010 23:24:43 - Windows Update RP273: 26/08/2010 02:05:29 - Windows Update RP275: 26/08/2010 02:26:36 - Avira AntiVir Personal - 26/08/2010 02:26 RP277: 26/08/2010 11:14:21 - Removed Warcraft III ==== Installed Programs ====================== 32 Bit HP CIO Components Installer A Internet e a World Wide Web AAC Decoder Adobe Flash Player 10 ActiveX Adobe Reader 9.3.4 - Português Adobe Shockwave Player 11 Apple Mobile Device Support Apple Software Update Assistente de Conexão do Windows Live ID Atualização do produto Microsoft Office Excel 2007 Help (KB963678) Atualização do produto Microsoft Office Outlook 2007 Help (KB963677) Atualização do produto Microsoft Office Powerpoint 2007 Help (KB963669) Atualização do produto Microsoft Office Word 2007 Help (KB963665) AutoUpdate Avira AntiVir Personal - Free Antivirus Bonjour BufferChm Cards_Calendar_OrderGift_DoMorePlugout CD/DVD Creator 1.0 Copy CustomerResearchQFolder Destination Component DeviceDiscovery DeviceManagementQFolder DivX Codec DivX Plus DirectShow Filters DivX Version Checker DivX Web Player DJ_AIO_03_F4200_ProductContext DJ_AIO_03_F4200_Software DJ_AIO_03_F4200_Software_Min Estilos de vida digitais eSupportQFolder Ferramenta de Carregamento do Windows Live GPBaseService H.264 Decoder Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Microsoft Visual C# 2008 Express Edition with SP1 - ENU (KB945282) Hotfix for Microsoft Visual C# 2008 Express Edition with SP1 - ENU (KB946040) Hotfix for Microsoft Visual C# 2008 Express Edition with SP1 - ENU (KB946308) Hotfix for Microsoft Visual C# 2008 Express Edition with SP1 - ENU (KB947540) Hotfix for Microsoft Visual C# 2008 Express Edition with SP1 - ENU (KB947789) HP Customer Participation Program 11.0 HP Deskjet F4200 All-In-One Driver Software 11.0 Rel .3 HP Imaging Device Functions 11.0 HP Photosmart Essential 2.5 HP Photosmart Essential 3.0 HP Smart Web Printing HP Solution Center 11.0 HP Update HPProductAssistant Java Auto Updater Java 6 Update 21 JMicron Flash Media Controller Driver Junk Mail filter update MarketResearch Microsoft .NET Compact Framework 3.5 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 3.5 Language Pack SP1 - ptb Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft CCR and DSS Runtime 2008 Microsoft Choice Guard Microsoft Expression Web 2 Microsoft Expression Web 2 MUI (English) Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft Math 3.0 Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (Portuguese (Brazil)) 2007 Microsoft Office Live Add-in 1.5 Microsoft Office Outlook Connector Microsoft Office Outlook MUI (Portuguese (Brazil)) 2007 Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Portuguese (Brazil)) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing (Portuguese (Brazil)) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared MUI (Portuguese (Brazil)) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Standard 2007 Microsoft Office Word MUI (Portuguese (Brazil)) 2007 Microsoft Robotics Developer Studio 2008 Express Edition Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft SQL Server 2008 Management Objects Microsoft SQL Server Compact 3.5 SP1 Design Tools English Microsoft SQL Server Compact 3.5 SP1 English Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C# 2008 Express Edition - Pacote de Idiomas PTB Microsoft Visual C# 2008 Express Edition - PTB Language Pack Microsoft Visual C# 2008 Express Edition with SP1 - ENU Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 Microsoft WorldWide Telescope Microsoft XNA Framework Redistributable 2.0 Microsoft XNA Framework Redistributable 3.0 Microsoft XNA Game Studio 3.0 Microsoft XNA Game Studio 3.0 (ARP entry) Microsoft XNA Game Studio 3.0 (Platformer) Microsoft XNA Game Studio 3.0 (Redists) Microsoft XNA Game Studio 3.0 (Shared Components) Microsoft XNA Game Studio 3.0 (VCSExpress) Microsoft XNA Game Studio 3.0 (XnaLiveProxy) Microsoft XNA Game Studio 3.0 Documentation Microsoft XNA Game Studio Platform Tools MKV Splitter MobileMe Control Panel Motorola SM56 Data Fax Modem MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML4 Parser Nokia Internet Modem Noções básicas sobre computadores NVIDIA GAME System Software 2.8.1 OGA Notifier 2.0.0048.0 Pacote de Idiomas do Microsoft .NET Framework 3.5 SP1 - PTB Princípios de Aprendizagem para Microsoft Office Programas de produtividade PSSWCORE QuickTime Realtek High Definition Audio Driver REALTEK RTL8187B Wireless LAN Driver Rise of Nations Scan Security Update for 2007 Microsoft Office System (KB2277947) Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for 2007 Microsoft Office System (KB982312) Security Update for 2007 Microsoft Office System (KB982331) Security Update for Microsoft Office Excel 2007 (KB982308) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office Outlook 2007 (KB980376) Security Update for Microsoft Office PowerPoint 2007 (KB982158) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2251419) Segurança e privacidade do computador SiS VGA Utilities SmartWebPrinting SolutionCenter Spelling Dictionaries Support For Adobe Reader 9 SQL Server System CLR Types Status Synaptics Pointing Device Driver Toolbox TrayApp Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Expression Web 2 (KB957827) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Script Editor Help (KB963671) Update for Outlook 2007 Junk Email Filter (kb2279264) VC80CRTRedist - 8.0.50727.762 VideoToolkit01 WebReg Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Galeria de Fotos Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Sync Windows Live Toolbar Windows Live Writer ==== End Of File =========================== Obrigado Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 27, 2010 OK...log limpo. Delete o DDS e seus relatórios. Um abraço. Compartilhar este post Link para o post Compartilhar em outros sites
haharafa 0 Denunciar post Postado Agosto 27, 2010 Ok. Perfeito. Obrigado mesmo Wings. Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Agosto 27, 2010 PROBLEMA RESOLVIDO! Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites