mig.bel 0 Denunciar post Postado Janeiro 15, 2011 Olá pessoal do iMasters, fui infectado pelo vírus (hacktool.win32.kiser.zv), ao tentar validar meu antivirus KIS 2011 para 3700 dias. Aparece a mensagem no KIS dizendo que "a segurança do pc está em risco pois foi detectado software suspeito", ocorre que qdo o antivirus é executado, e mesmo detectando o hacktool.win32.kiser.zv, este não é desinfectado, sendo que ao terminar a varredura o pc é desligado. Gostaria muito da ajuda de vcs. Abçs Segue abaixo o Log do HijacjThis: Logfile of HijackThis v1.99.1 Scan saved at 22:39:39, on 14/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Arquivos de programas\Internet Download Manager\IDMan.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Foxit Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Adicionar ao Antibanner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: &Teclado Virtual - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: Veri&ficação de URLs - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - AppInit_DLLs: C:\ARQUIV~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\ARQUIV~1\KASPER~1\KASPER~1\kloehk.dll O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Serviço do Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" -r (file missing) O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Janeiro 15, 2011 :) Olá mig.bel! :seta: Abra o HijackThis, clique em Do a system scan only, marque a entrada abaixo e clique em Fix checked: O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) ____________________ :seta: Siga estas dicas: Tutorial do Malwarebytes Anti-Malware Tutorial do Ad-Remover _________________________ fui infectado pelo vírus (hacktool.win32.kiser.zv), ao tentar validar meu antivirus KIS 2011 para 3700 dias. :!: Nunca use antivirus pirateado ou crackeado, é muito importante desinstalá-lo, pois um antivírus falsificado é mais perigoso do que os próprios vírus! A empresa produtora do antivirus sempre descobre que ele foi pirateado e bloqueia as atualizações para ele. E no caso de antivirus crackeados, as pessoas que criam esses cracks sempre fazem alguma modificação que abrem brechas de segurança no seu PC para que depois ela possa invadir o seu PC ou instalar malwares sem que o antivirus se dê conta disso (pois ele foi modificado ou crackeado justamente para este fim). Você acha que as pessoas que crackeiam os antivirus estão fazendo isso porque são caridosas e bondosas? É claro que não, o que elas querem é um modo de invadir o PC das pessoas que usam esses antivirus. Caso você não queira comprar o Kaspersky original, sugiro um ótimo antivirus gratuito para você, como o Avira AntiVir Personal Edition Classic 2010. Para instalar, configurar e usar corretamente o Avira antivir é só seguir as dicas destes tutoriais: Tutorial do Avira AntiVir Personal Edition Classic 2010 (Instalação e Configuração) Tutorial do Avira AntiVir Personal Edition Classic 2010 (como usá-lo corretamente) • Depois de instalar e configurar o Avira Antivir seguindo as dicas dos tutoriais acima, atualize-o (faça um update) e reinicie o seu computador e entre pelo Modo de Segurança (apertando a tecla F8 (ou a tecla F5 em alguns computadores) repetidas vezes quando o computador estiver reiniciando e escolhendo a opção Modo Seguro ou Modo de Segurança). Aí quando o computador tiver reiniciado, clique com o botão direito do mouse sobre o símbolo do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Iniciar o AntiVir > clique na opção Verif. sistema agora > e aguarde a conclusão do escaneamento. Obs: Caso não seja possível fazer o escaneamento com o Avira Antivir no Modo Seguro do Windows, faça-o no modo normal. _________________________ :seta: Quando você tiver removido os virus que o Avira Antivir encontrar, reinicie o computador normalmente. Clique com o botão direito do mouse sobre o ícone do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Iniciar o AntiVir > clique na opção Relatórios > dê um duplo clique com o botão esquerdo do mouse sobre o log mais recente e clique no botão Arquivo de relatório > Depois será aberta uma tela com o log, então é só selecionar este Log (Clique no menu: Editar » Selecionar Tudo), depois disso volte novamente no menu: Editar » e clique na opção: Copiar) > Depois disso é só voltar aqui no fórum e postar este log do Avira Antivir juntamente com um novo log do Hijackthis, o log do Malwarebytes e o log do Ad-Remover que estará em C:\Ad-Report-CLEAN[1].log para que eles possam ser analizados. Ficamos no aguardo de sua resposta. Compartilhar este post Link para o post Compartilhar em outros sites
mig.bel 0 Denunciar post Postado Janeiro 17, 2011 :) Olá mig.bel! :seta: Abra o HijackThis, clique em Do a system scan only, marque a entrada abaixo e clique em Fix checked: O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) ____________________ :seta: Siga estas dicas: Tutorial do Malwarebytes Anti-Malware Tutorial do Ad-Remover _________________________ fui infectado pelo vírus (hacktool.win32.kiser.zv), ao tentar validar meu antivirus KIS 2011 para 3700 dias. :!: Nunca use antivirus pirateado ou crackeado, é muito importante desinstalá-lo, pois um antivírus falsificado é mais perigoso do que os próprios vírus! A empresa produtora do antivirus sempre descobre que ele foi pirateado e bloqueia as atualizações para ele. E no caso de antivirus crackeados, as pessoas que criam esses cracks sempre fazem alguma modificação que abrem brechas de segurança no seu PC para que depois ela possa invadir o seu PC ou instalar malwares sem que o antivirus se dê conta disso (pois ele foi modificado ou crackeado justamente para este fim). Você acha que as pessoas que crackeiam os antivirus estão fazendo isso porque são caridosas e bondosas? É claro que não, o que elas querem é um modo de invadir o PC das pessoas que usam esses antivirus. Caso você não queira comprar o Kaspersky original, sugiro um ótimo antivirus gratuito para você, como o Avira AntiVir Personal Edition Classic 2010. Para instalar, configurar e usar corretamente o Avira antivir é só seguir as dicas destes tutoriais: Tutorial do Avira AntiVir Personal Edition Classic 2010 (Instalação e Configuração) Tutorial do Avira AntiVir Personal Edition Classic 2010 (como usá-lo corretamente) • Depois de instalar e configurar o Avira Antivir seguindo as dicas dos tutoriais acima, atualize-o (faça um update) e reinicie o seu computador e entre pelo Modo de Segurança (apertando a tecla F8 (ou a tecla F5 em alguns computadores) repetidas vezes quando o computador estiver reiniciando e escolhendo a opção Modo Seguro ou Modo de Segurança). Aí quando o computador tiver reiniciado, clique com o botão direito do mouse sobre o símbolo do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Iniciar o AntiVir > clique na opção Verif. sistema agora > e aguarde a conclusão do escaneamento. Obs: Caso não seja possível fazer o escaneamento com o Avira Antivir no Modo Seguro do Windows, faça-o no modo normal. _________________________ :seta: Quando você tiver removido os virus que o Avira Antivir encontrar, reinicie o computador normalmente. Clique com o botão direito do mouse sobre o ícone do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Iniciar o AntiVir > clique na opção Relatórios > dê um duplo clique com o botão esquerdo do mouse sobre o log mais recente e clique no botão Arquivo de relatório > Depois será aberta uma tela com o log, então é só selecionar este Log (Clique no menu: Editar » Selecionar Tudo), depois disso volte novamente no menu: Editar » e clique na opção: Copiar) > Depois disso é só voltar aqui no fórum e postar este log do Avira Antivir juntamente com um novo log do Hijackthis, o log do Malwarebytes e o log do Ad-Remover que estará em C:\Ad-Report-CLEAN[1].log para que eles possam ser analizados. Ficamos no aguardo de sua resposta. .................................................................................................................................................. Olá Antônio, realizei os procedimentos que me indicaste, e estou enviando os logs das análises feitas. Desde já mto obrigado!!! Abçs ------------------------------------------------------------------------------------------------------------------------------------------------- ANTIVÍRUS: Data: Hoje (212) 16/1/2011 10:11:05 Centro de Proteção Detectado software legal que pode ser usado por criminosos para danificar seu computador ou seus dados pessoais 16/1/2011 10:11:06 Antispam Tarefa iniciada Antispam 16/1/2011 10:11:06 Antivírus de Email Tarefa iniciada Antivírus de Email 16/1/2011 10:11:06 Antivírus de Arquivos Tarefa iniciada Antivírus de Arquivos 16/1/2011 10:11:06 Controle de Aplicativos Tarefa iniciada Controle de Aplicativos 16/1/2011 10:11:06 Firewall Tarefa iniciada Firewall 16/1/2011 10:11:06 Defesa Proativa Tarefa iniciada Defesa Proativa 16/1/2011 10:11:06 Antivírus de IM Tarefa iniciada Antivírus de IM 16/1/2011 10:11:06 Bloqueador de Ataques de Rede Tarefa iniciada Bloqueador de Ataques de Rede 16/1/2011 10:11:06 Antivírus da Web Tarefa iniciada Antivírus da Web 16/1/2011 10:11:20 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração 16/1/2011 10:11:20 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows 16/1/2011 10:11:20 LSA Shell (Export Version) Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração 16/1/2011 10:11:20 LSA Shell (Export Version) Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows 16/1/2011 10:11:20 TuneUp Utilities Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\tuneup utilities 2011\tuneuputilitiesservice32.exe Usando interfaces de programa de outro processo 16/1/2011 10:11:20 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\alg.exe Usando interfaces de programa de outro processo 16/1/2011 10:11:20 TuneUp Utilities Service Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\tuneup utilities 2011\tuneuputilitiesapp32.exe Usando interfaces de programa de outro processo 16/1/2011 10:11:24 Notificações do Programa de Vantagens do Windows Original Controle de Aplicativos Permitido: Acesso direto à memória física Acesso à memória global Acesso direto à memória física 16/1/2011 10:11:24 Notificações do Programa de Vantagens do Windows Original Controle de Aplicativos Permitido: Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema 16/1/2011 10:11:24 Windows Explorer Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:11:25 Application Layer Gateway Service Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:11:25 Notificações do Programa de Vantagens do Windows Original Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas 16/1/2011 10:11:25 RealUpgrade Launcher Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão client-software.real.com Usando interfaces de programa do sistema (DNS) 16/1/2011 10:11:26 Windows Explorer Controle de Aplicativos Permitido: Alça duplicada Alça interna do processo duplicada c:\windows\explorer.exe Alça duplicada 16/1/2011 10:11:26 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Alça duplicada Alça interna do processo duplicada c:\windows\explorer.exe Alça duplicada 16/1/2011 10:11:31 Desconhecido Controle de Aplicativos Permitido: Iniciar driver Início de driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Iniciar driver 16/1/2011 10:11:31 Adobe Reader and Acrobat Manager Controle de Aplicativos Permitido: Usando interfaces de programa do sistema Uso de função do sistema para envio oculto de dados através da rede Usando interfaces de programa do sistema 16/1/2011 10:11:31 Adobe Reader and Acrobat Manager Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:11:31 Windows Explorer Controle de Aplicativos Permitido: Acesso a disco de nível inferior Acesso a disco de nível inferior Device\CdRom0 Acesso a disco de nível inferior 16/1/2011 10:11:32 Windows Explorer Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows 16/1/2011 10:11:44 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Acesso a disco de nível inferior Acesso a disco de nível inferior Device\HarddiskVolume1 Acesso a disco de nível inferior 16/1/2011 10:11:48 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão armmf.adobe.com Usando interfaces de programa do sistema (DNS) 16/1/2011 10:11:54 Spooler SubSystem App Controle de Aplicativos Permitido: Alterando os direitos de acesso ao objeto Alterando os direitos de acesso ao objeto REGISTRY\USER\S-1-5-21-606747145-329068152-1801674531-1003\Software\Microsoft\Windows NT\CurrentVersion\Devices Alterando os direitos de acesso ao objeto 16/1/2011 10:11:59 WMI Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração 16/1/2011 10:12:03 WMI Controle de Aplicativos Permitido: Acesso a disco de nível inferior Acesso a disco de nível inferior Device\Harddisk0\DR0 Acesso a disco de nível inferior 16/1/2011 10:12:04 Nero Home Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\arquivos comuns\ahead\lib\nmindexingservice.exe Usando interfaces de programa de outro processo 16/1/2011 10:12:11 Malwarebytes' Anti-Malware Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração 16/1/2011 10:12:11 Malwarebytes' Anti-Malware Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows 16/1/2011 10:12:12 Google Installer Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão cr-tools.clients.google.com Usando interfaces de programa do sistema (DNS) 16/1/2011 10:12:13 Nero Home Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\arquivos comuns\ahead\lib\nmindexingservice.exe Usando interfaces de programa de outro processo 16/1/2011 10:12:21 Nero Home Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\arquivos comuns\ahead\lib\nmindexstoresvr.exe Usando interfaces de programa de outro processo 16/1/2011 10:12:21 Spyware Terminator Update Support Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão www.spywareterminator.com Usando interfaces de programa do sistema (DNS) 16/1/2011 10:12:22 Nero Home Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows 16/1/2011 10:12:24 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4} Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935} Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\PROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\VERSIONINDEPENDENTPROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\PROGRAMMABLE Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\INPROCSERVER32\ThreadingModel Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\TYPELIB Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8} Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\PROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\VERSIONINDEPENDENTPROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\PROGRAMMABLE Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\INPROCSERVER32\ThreadingModel Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\TYPELIB Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D} Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\PROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\VERSIONINDEPENDENTPROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\PROGRAMMABLE Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\INPROCSERVER32\ThreadingModel Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\TYPELIB Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\CONTROL Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A} Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\PROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\VERSIONINDEPENDENTPROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\PROGRAMMABLE Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\INPROCSERVER32\ThreadingModel Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\CONTROL Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\INSERTABLE Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\TOOLBOXBITMAP32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\TOOLBOXBITMAP32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\MISCSTATUS Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\MISCSTATUS\1 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\TYPELIB Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\VERSION Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038} Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\PROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\VERSIONINDEPENDENTPROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\PROGRAMMABLE Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\INPROCSERVER32\ThreadingModel Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\TYPELIB Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861} Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\PROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\VERSIONINDEPENDENTPROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\PROGRAMMABLE Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\INPROCSERVER32\ThreadingModel Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\TYPELIB Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7} Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\PROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\VERSIONINDEPENDENTPROGID Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\PROGRAMMABLE Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\INPROCSERVER32\ThreadingModel Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\TYPELIB Classes_CLSID 16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{6B9EB066-DA1F-4C0A-AC62-01AC892EF175}\INPROCSERVER32 Classes_CLSID 16/1/2011 10:12:26 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Main_Run Excluir hklm\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Adsoff Startup Main_Run 16/1/2011 10:12:26 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Main_Run Excluir hklm\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\OSSPoxy Main_Run 16/1/2011 10:12:26 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Main_Run Excluir hklm\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\New.net Startup Main_Run 16/1/2011 10:12:26 Internet Download Manager (IDM) Controle de Aplicativos Permitido: Alterando os direitos de acesso ao objeto Alterando os direitos de acesso ao objeto REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{14190654-4dd9-457a-b001-8cd81c3932e5} Alterando os direitos de acesso ao objeto 16/1/2011 10:12:27 Windows Live Messenger Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:12:27 Google Installer Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:12:27 Windows Live Messenger Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas 16/1/2011 10:12:28 Internet Download Manager (IDM) Controle de Aplicativos Permitido: Iniciando outros processos Outro processo iniciado c:\arquivos de programas\internet download manager\iemonitor.exe Iniciando outros processos 16/1/2011 10:12:34 WMI Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:12:39 WMI Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:12:43 HP Digital Imaging Monitor Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:12:50 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\hp\digital imaging\bin\hpqtra08.exe Usando interfaces de programa de outro processo 16/1/2011 10:12:54 HP CUE Status Root Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:13:11 Centro de Proteção O computador está protegido 16/1/2011 10:13:53 Service Executable Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:13:56 Generic Host Process for Win32 Services Controle de Aplicativos Aplicativo colocado no grupo Confiável 16/1/2011 10:13:56 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas 16/1/2011 10:13:56 LSA Shell (Export Version) Controle de Aplicativos Permitido: Criando chaves ocultas do Registro Criação de chave do Registro oculta REGISTRY\MACHINE\SECURITY\POLICY\SECRETS\SAI Criando chaves ocultas do Registro 16/1/2011 10:14:02 Google Installer Controle de Aplicativos Aplicativo colocado no grupo Confiável 16/1/2011 10:14:02 Google Installer Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas 16/1/2011 10:14:02 Google Installer Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão tools.google.com Usando interfaces de programa do sistema (DNS) 16/1/2011 10:14:21 Windows Explorer Autodefesa Recusado Abrir C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe 16/1/2011 10:14:25 WMI Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:14:57 Google Chrome Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão www.google.pt Usando interfaces de programa do sistema (DNS) 16/1/2011 10:14:57 Google Chrome Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão ajax.googleapis.com Usando interfaces de programa do sistema (DNS) 16/1/2011 10:14:58 Google Chrome Controle de Aplicativos Permitido: Invasão de código Invasão de código c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Invasão de código 16/1/2011 10:15:01 Google Chrome Antivírus de Arquivos Compactado: UPX C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.63_0\npqscan.dll 16/1/2011 10:15:05 WMI Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:15:13 Google Chrome Controle de Aplicativos Permitido: Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema 16/1/2011 10:15:13 Google Chrome Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:15:25 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000702 16/1/2011 10:15:28 Google Chrome Controle de Aplicativos Aplicativo colocado no grupo Confiável 16/1/2011 10:15:28 Google Chrome Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas 16/1/2011 10:15:29 Spyware Terminator Controle de Aplicativos Permitido: Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema 16/1/2011 10:15:29 Spyware Terminator Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:16:00 Google Installer Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração 16/1/2011 10:16:04 Google Installer Controle de Aplicativos Aplicativo colocado no grupo Confiável 16/1/2011 10:16:04 Google Installer Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas 16/1/2011 10:16:04 Google Installer Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão tools.google.com Usando interfaces de programa do sistema (DNS) 16/1/2011 10:20:06 Google Chrome Controle de Aplicativos Permitido: Operações suspeitas Executando operação suspeita em outro processo c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Operações suspeitas 16/1/2011 10:20:08 Google Chrome Antivírus da Web Compactado: Swf2Swc http://s.ytimg.com/yt/swfbin/watch_as3-vflqEsLb3.swf 16/1/2011 10:20:08 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_00084e 16/1/2011 10:20:12 Google Chrome Controle de Aplicativos Permitido: Operações suspeitas Executando operação suspeita em outro processo c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Operações suspeitas 16/1/2011 10:21:24 Google Chrome Controle de Aplicativos Permitido: Operações suspeitas Executando operação suspeita em outro processo c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Operações suspeitas 16/1/2011 10:23:24 Google Chrome Antivírus da Web Compactado: Swf2Swc http://static.imasters.com.br/anuncio/impacta/2010/novembro/728x90.swf 16/1/2011 10:23:24 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000854 16/1/2011 10:23:34 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000747 16/1/2011 10:23:57 Google Chrome Controle de Aplicativos Permitido: Operações suspeitas Executando operação suspeita em outro processo c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Operações suspeitas 16/1/2011 10:26:20 File Downloader Controle de Aplicativos Aplicativo colocado no grupo Baixa restrição Classificação de ameaça calculada heuristicamente 16/1/2011 10:26:26 Nero Home Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows 16/1/2011 10:27:03 Google Chrome Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão www.caixadedicas.com Usando interfaces de programa do sistema (DNS) 16/1/2011 10:27:06 Google Chrome Controle de Aplicativos Permitido: Invasão de código Invasão de código c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Invasão de código 16/1/2011 10:27:18 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s55_001_diversos_101202/mitos_300x100_v03_CS4.swf/1294438259//mitos_300x100_v03_CS4 16/1/2011 10:27:19 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s93_001_diversos_101202/300x100_bones.swf/1294754710//300x100_bones 16/1/2011 10:27:20 Google Chrome Controle de Aplicativos Permitido: Operações suspeitas Executando operação suspeita em outro processo c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Operações suspeitas 16/1/2011 10:27:20 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/apetrexo_959_002_apetrexo_110147/NOVAHOME_Globo.com_SeloCat_PowerBalance_SomenteHj_DePor.swf/1295034567//NOVAHOME_Globo.com_SeloCat_PowerBalance_SomenteHj_DePor 16/1/2011 10:27:23 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/apetrexo_959_002_apetrexo_110143/Globocom_DhtmlHome_W320Prata-Rosa-Preta-Verde_APartirDe.swf/1294948689//Globocom_DhtmlHome_W320Prata-Rosa-Preta-Verde_APartirDe 16/1/2011 10:28:08 Google Chrome Antivírus da Web Compactado: Swf2Swc http://s0.2mdn.net/2162474/Super_Exp_BRBWL09BB_160111.swf?clicktag=http%3A//ad.doubleclick.net/click%253Bh%253Dv8/3a91/3/0/%252a/i%253B235040250%253B0-0%253B1%253B32492552%253B3454-728/90%253B40288114/40305901/1%253B%253B%257Eaopt%253D2/1/81/0%253B%257Esscs%253D%253fhttp%3A//www.fastshop.com.br/product.aspx%3Fpar%3Dsupertop%26product_id%3DBRBWL09BB 16/1/2011 10:28:08 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_00086f 16/1/2011 10:28:11 Google Chrome Antivírus da Web Compactado: Swf2Swc http://spe.atdmt.com/ds/F1FRCDTMDCLT/01_09_Terra_consumer_HP_All_in_One_100_5010_pen_JAN11/Terra_Ret300x250_ConsHPAllinOne1005010pen_ADS.swf?ver=1&clickTag1=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/p%3B235037658%3B0-0%3B1%3B32492552%3B4307-300/250%3B40288949/40306736/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550569/direct;ai.199363994;ct.1/01&clickTag=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/p%3B235037658%3B0-0%3B1%3B32492552%3B4307-300/250%3B40288949/40306736/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550569/direct;ai.199363994;ct.1/01 16/1/2011 10:28:11 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000870 16/1/2011 10:28:13 Google Chrome Antivírus da Web Compactado: Swf2Swc http://spe.atdmt.com/ds/F1FRCDTMDCLT/01_09_Terra_consumer_HP_All_in_One_100_5010_pen_JAN11/Terra_Barra200x446_ConsHPAllinOne1005010pen_ADS.swf?ver=1&clickTag1=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/m%3B235037657%3B0-0%3B1%3B32492552%3B34450-200/446%3B40288743/40306530/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550571/direct;ai.199362121;ct.1/01&clickTag=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/m%3B235037657%3B0-0%3B1%3B32492552%3B34450-200/446%3B40288743/40306530/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550571/direct;ai.199362121;ct.1/01 16/1/2011 10:28:14 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000871 16/1/2011 10:28:20 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ec.atdmt.com/ds/F1FRCDTMDCLT/01_01_v2_E_01_03_v2_Retangulo_Terra_DEZ10/Terra_Ret_01_01_V2_Cons_HPMini210_1030_ADS.swf?ver=1&clickTag1=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/v%3B235037659%3B0-0%3B1%3B32492552%3B4307-300/250%3B40289246/40307033/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550570/direct;ai.196400091;ct.1/01&clickTag=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/v%3B235037659%3B0-0%3B1%3B32492552%3B4307-300/250%3B40289246/40307033/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550570/direct;ai.196400091;ct.1/01 16/1/2011 10:28:20 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000872 16/1/2011 10:29:15 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/rotativo_p03_002_bbb11_110101/insertmarca_BBB11_padrao_ABCDE_multclick.swf/1294841514//insertmarca_BBB11_padrao_ABCDE_multclick 16/1/2011 10:29:18 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s33_015_ego_101203/Banner-Horoscopo-300x100-Escorpiao-v2.swf/1292612774//Banner-Horoscopo-300x100-Escorpiao-v2 16/1/2011 10:29:19 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s76_001_glbmarca_101201/retmedio_araguaia.swf/1292509409//retmedio_araguaia 16/1/2011 10:30:26 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s33_015_ego_101203/Banner-Horoscopo-300x100-Aries-v2.swf/1292612519//Banner-Horoscopo-300x100-Aries-v2 16/1/2011 10:30:26 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s55_001_guiadeca_101201/guia_carreiras_300x250.swf/1290091296//guia_carreiras_300x250 16/1/2011 10:30:30 Google Chrome Antivírus da Web Compactado: Swf2Swc http://s.videos.globo.com/p2/player.swf 16/1/2011 10:30:30 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_00087b 16/1/2011 10:30:45 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/skybr_020_088_skybr_110101/SKY_GLOBO_GE_MIDBANNER_DIAG_201210.swf/1294694258//SKY_GLOBO_GE_MIDBANNER_DIAG_201210 16/1/2011 10:30:45 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração 16/1/2011 10:30:45 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows 16/1/2011 10:30:47 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_0004f4 16/1/2011 10:30:50 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/netshoes/netshoes_rm_10101503/300x250_linhanike3_frete_airmaxlaranja.swf 16/1/2011 10:30:50 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000880 16/1/2011 10:30:58 Windows Defender Command Line Utility Controle de Aplicativos Permitido: Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema 16/1/2011 10:30:58 Windows Defender Command Line Utility Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:30:59 WMI Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo 16/1/2011 10:30:59 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\wbem\wmiprvse.exe Usando interfaces de programa de outro processo 16/1/2011 10:31:01 Windows Defender Command Line Utility Controle de Aplicativos Permitido: Acesso direto à memória física Acesso à memória global Acesso direto à memória física 16/1/2011 10:31:02 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/apetrexo_959_002_apetrexo_110153/Globocom_Dhtml_SaldTechnosJS25AA1K_APartir.swf/1295035974//Globocom_Dhtml_SaldTechnosJS25AA1K_APartir 16/1/2011 10:31:25 LSA Shell (Export Version) Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração 16/1/2011 10:31:25 LSA Shell (Export Version) Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows 16/1/2011 10:31:50 Google Chrome Antivírus da Web Compactado: Swf2Swc http://s0.2mdn.net/2662185/Terra_Super_Barbeadores_Eletricos.swf 16/1/2011 10:31:51 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_00071b 16/1/2011 10:31:51 Google Chrome Antivírus da Web Compactado: Swf2Swc http://s0.2mdn.net/2706403/Y_F_300x250_FrutasBr.swf 16/1/2011 10:31:52 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000893 16/1/2011 10:31:54 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_0005de 16/1/2011 10:31:54 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000622 16/1/2011 10:31:55 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_00067d 16/1/2011 10:32:03 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/rotativo_p101_001_vespet_110101/insertmarca_GE_padrao_VERAO_ESPETACULAR_CDAB.swf/1293798711//insertmarca_GE_padrao_VERAO_ESPETACULAR_CDAB 16/1/2011 10:32:09 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/b2u_006_158_neosa_110101/rosa_globo_300x250.swf/1294928463 16/1/2011 10:32:09 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000895 16/1/2011 10:32:09 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/lojagloboesporte/vitrine_netshoes_06071002b/300x300_Diversos_II_100111.swf 16/1/2011 10:32:10 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/cef_p101_055_caixa_110104/caixa_faturazero_globo_eletr_retangulo.swf/1293797664//caixa_faturazero_globo_eletr_retangulo 16/1/2011 10:32:10 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s82_001_isp_101212/Banner-BBB111-300x100-v5.swf/1294863372//Banner-BBB111-300x100-v5 16/1/2011 10:32:10 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000896 -------------------------------------------------------------------------------------------------------------------------------------------------- 1 - Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Versão da Base de Dados: 5527 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 8.0.6001.18702 16/1/2011 10:08:30 mbam-log-2011-01-16 (10-08-14).txt Tipo de Verificação: Verificação Completa (C:\|E:\|F:\|) Objetos escaneados: 214596 Tempo decorrido: 58 minuto(s), 45 segundo(s) Processos de Memória Infectados: 0 Módulos de Memória Infectados: 0 Chaves de Registro Infectadas: 0 Valores de Registro Infectados: 0 Itens de Dados no Registro Infectados: 0 Pastas Infectadas: 0 Arquivos Infectados: 3 Processos de Memória Infectados: (Não foram detectados ítens maliciosos) Módulos de Memória Infectados: (Não foram detectados ítens maliciosos) Chaves de Registro Infectadas: (Não foram detectados ítens maliciosos) Valores de Registro Infectados: (Não foram detectados ítens maliciosos) Itens de Dados no Registro Infectados: (Não foram detectados ítens maliciosos) Pastas Infectadas: (Não foram detectados ítens maliciosos) Arquivos Infectados: c:\RECYCLER\s-1-5-21-606747145-329068152-1801674531-1003\Dc194\__incomplete__kaspersky 2011 crack.exe (RiskWare.Tool.CK) -> No action taken. c:\system volume information\_restore{2e688ff2-c923-4539-bed5-d6b4329ec271}\RP84\A0052856.exe (RiskWare.Tool.CK) -> No action taken. e:\meus documentos\downloads\keygen.exe (Trojan.Dropper.PGen) -> No action taken. 2 - Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Versão da Base de Dados: 5527 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 8.0.6001.18702 16/1/2011 10:08:53 mbam-log-2011-01-16 (10-08-53).txt Tipo de Verificação: Verificação Completa (C:\|E:\|F:\|) Objetos escaneados: 214596 Tempo decorrido: 58 minuto(s), 45 segundo(s) Processos de Memória Infectados: 0 Módulos de Memória Infectados: 0 Chaves de Registro Infectadas: 0 Valores de Registro Infectados: 0 Itens de Dados no Registro Infectados: 0 Pastas Infectadas: 0 Arquivos Infectados: 3 Processos de Memória Infectados: (Não foram detectados ítens maliciosos) Módulos de Memória Infectados: (Não foram detectados ítens maliciosos) Chaves de Registro Infectadas: (Não foram detectados ítens maliciosos) Valores de Registro Infectados: (Não foram detectados ítens maliciosos) Itens de Dados no Registro Infectados: (Não foram detectados ítens maliciosos) Pastas Infectadas: (Não foram detectados ítens maliciosos) Arquivos Infectados: c:\RECYCLER\s-1-5-21-606747145-329068152-1801674531-1003\Dc194\__incomplete__kaspersky 2011 crack.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. c:\system volume information\_restore{2e688ff2-c923-4539-bed5-d6b4329ec271}\RP84\A0052856.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. e:\meus documentos\downloads\keygen.exe (Trojan.Dropper.PGen) -> Quarantined and deleted successfully. .................................................................................................................................................. ======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 16/01/11 at 02:00 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Arquivos de programas\Ad-Remover\main.exe (SCAN [1]) -> Launched at 22:29:59 on 15/01/2011, Normal boot Microsoft Windows XP Professional Service Pack 3 (X86) Usuario@MIGUEL ( ) ============== SEARCH ============== File found: C:\Arquivos de programas\Mozilla FireFox\searchplugins\crawlersrch.xml File found: C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job Folder found: C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\extensions\toolbar@ask.com Folder found: C:\Arquivos de programas\Ask.com Folder found: C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\AskToolbar Folder found: C:\Arquivos de programas\Crawler -- File opened: C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\Prefs.js -- Line found: user_pref("extensions.asktb.cbid", "F4"); Line found: user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}... Line found: user_pref("extensions.asktb.dtid", "YYYYYYYYBR"); Line found: user_pref("extensions.asktb.fresh-install", false); Line found: user_pref("extensions.asktb.l", "dis"); Line found: user_pref("extensions.asktb.last-config-req", "1321496627732"); Line found: user_pref("extensions.asktb.locale", "en_US"); Line found: user_pref("extensions.asktb.o", "101699"); Line found: user_pref("extensions.asktb.overlay-reloaded-using-restart", true); Line found: user_pref("extensions.asktb.qsrc", "2871"); Line found: user_pref("extensions.asktb.r", "4"); Line found: user_pref("extensions.asktb.search-suggestions-enabled", true); Line found: user_pref("extensions.asktb.v", "3.8.0.99999"); Line found: user_pref("extensions.enabledItems", "KavAntiBanner@Kaspersky.ru:11.0.1.400,linkfilter@kaspersky.ru:... -- File closed -- Key found: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key found: HKLM\Software\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163} Key found: HKLM\Software\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Key found: HKLM\Software\Classes\CLSID\{1DDA201E-5B42-4352-933E-21A92B297E3B} Key found: HKLM\Software\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Key found: HKLM\Software\Classes\CLSID\{4D25FB7A-8902-4291-960E-9ADA051CFBBF} Key found: HKLM\Software\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC} Key found: HKLM\Software\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C} Key found: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key found: HKLM\Software\Classes\CLSID\{DBDB6FAA-1F5F-4A18-B60B-7A905C7FF83F} Key found: HKLM\Software\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF} Key found: HKLM\Software\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE} Key found: HKLM\Software\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808} Key found: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key found: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key found: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key found: HKLM\Software\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9} Key found: HKLM\Software\Classes\TypeLib\{04006843-5199-4CE4-B3CD-8092CC91706E} Key found: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key found: HKLM\Software\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966} Key found: HKLM\Software\Classes\TypeLib\{E79BB61D-7F1A-41DF-8AD0-402795E3B566} Key found: HKLM\Software\Classes\ctbcommon.Buttons Key found: HKLM\Software\Classes\ctbr.R404Pro Key found: HKLM\Software\Classes\CToolbar.TB4Client Key found: HKLM\Software\Classes\CToolbar.TB4Script Key found: HKLM\Software\Classes\CToolbar.TB4Server Key found: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd Key found: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1 Key found: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL Key found: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key found: HKLM\Software\CToolbar Key found: HKCU\Software\Ask.com Key found: HKCU\Software\AskToolbar Key found: HKCU\Software\CToolbar Key found: HKCU\Software\AppDataLow\AskToolbarInfo Key found: HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Key found: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\CToolbar_UNINSTALL Key found: HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search Key found: HKLM\Software\Classes\PROTOCOLS\Handler\tbr Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\Crawler Value found: HKLM\Software\Mozilla\Firefox\Extensions|{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Value found: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Value found: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440} Value found: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Value found: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440} Value found: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{4B3803EA-5230-4DC3-A7FC-33638F3D3542} ============== ADDITIONNAL SCAN ============== ** Mozilla Firefox Version [3.6.13 (pt-BR)] ** -- C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\Prefs.js -- browser.download.lastDir, C:\\Documents and Settings\\Usuario\\Desktop\\BUENOS AIRES browser.startup.homepage, www.google.com.br browser.startup.homepage_override.mstone, rv:1.9.2.13 keyword.URL, hxxp://search.instantfirefox.com/google#q= ======================================== ** Internet Explorer Version [8.0.6001.18702] ** [HKCU\Software\Microsoft\Internet Explorer\Main] Do404Search: 0x01000000 Enable Browser Extensions: yes Local Page: C:\WINDOWS\system32\blank.htm Search bar: hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60076 Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896 Show_ToolBar: yes Start Page: hxxp://www.crawler.com/homepage.aspx?tbid=60076 Use Search Asst: no [HKLM\Software\Microsoft\Internet Explorer\Main] Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157 Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896 Delete_Temp_Files_On_Exit: yes Local Page: C:\WINDOWS\system32\blank.htm SearchAssistant: hxxp://www.crawler.com/search/ie.aspx?tb_id=60076 Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896 Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157 [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS] Tabs: res://ieframe.dll/tabswelcome.htm Blank: res://mshtml.dll/blank.htm ======================================== C:\Arquivos de programas\Ad-Remover\Quarantine: 0 File(s) C:\Arquivos de programas\Ad-Remover\Backup: 1 File(s) C:\Ad-Report-SCAN[1].txt - 15/01/2011 (8828 Byte(s)) End at: 22:32:00, 15/01/2011 ============== E.O.F ============== .................................................................................................................................................. Logfile of HijackThis v1.99.1 Scan saved at 00:53:20, on 17/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Windows Defender\MSASCui.exe C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Arquivos de programas\Internet Download Manager\IDMan.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\ARQUIV~1\Crawler\Toolbar\CToolbar.exe C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60076 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076 R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\ARQUIV~1\Crawler\Toolbar\ctbr.dll O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\ARQUIV~1\Crawler\Toolbar\ctbr.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Foxit Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll O3 - Toolbar: Barra de ferramentas &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\Toolbar\ctbr.dll O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Arquivos de programas\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Adicionar ao Antibanner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm O8 - Extra context menu item: Crawler Search - tbr:iemenu O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: &Teclado Virtual - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: Veri&ficação de URLs - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\Toolbar\ctbr.dll O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - AppInit_DLLs: C:\ARQUIV~1\KASPER~1\KASPER~1\mzvkbd3.dll, C:\ARQUIV~1\KASPER~1\KASPER~1\kloehk.dll O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Serviço do Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" -r (file missing) O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe ............................................................................................................................................... Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Janeiro 17, 2011 :) Alguns problemas foram removidos pelo Malwarebytes. ___________________ ======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 ======= ============== SEARCH ============== :!: No seu log do Ad-remover está constando que você usou somente a função de pesquisa dele. Por isto ele encontrou vários problemas mas ainda não os removeu. Execute novamente o Ad-Remover > Surgirá a tela principal do Ad-Remover, na qual você clicará no botão Clean para que os problemas que estejam em seu PC possam ser removidos > Surgirá mais uma tela na qual você teclará no botão Sim > Aguarde... pode demorar um pouco > Assim que o escaneamento for concluído, surgirá uma mensagem pedindo para que o PC seja reiniciado afim de que a limpeza possa ser concluida, clique no botão Sim para confirmar o procedimento > O relatório (log) estará em C:\Ad-Report-CLEAN[2].log ____________________ C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011 :!: No seu log consta que você ainda continua com o Kaspersky. Se a causa da infecção foi o uso de um antivirus pirata, o PC continuará infectado enquanto você permanecer com ele. _____________________ :seta: Na sua próxima respostas poste o log que estará em C:\Ad-Report-CLEAN[2].log juntamente com um novo log do Hijackthis. Compartilhar este post Link para o post Compartilhar em outros sites
mig.bel 0 Denunciar post Postado Janeiro 17, 2011 :) Alguns problemas foram removidos pelo Malwarebytes. ___________________ ======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 ======= ============== SEARCH ============== :!: No seu log do Ad-remover está constando que você usou somente a função de pesquisa dele. Por isto ele encontrou vários problemas mas ainda não os removeu. Execute novamente o Ad-Remover > Surgirá a tela principal do Ad-Remover, na qual você clicará no botão Clean para que os problemas que estejam em seu PC possam ser removidos > Surgirá mais uma tela na qual você teclará no botão Sim > Aguarde... pode demorar um pouco > Assim que o escaneamento for concluído, surgirá uma mensagem pedindo para que o PC seja reiniciado afim de que a limpeza possa ser concluida, clique no botão Sim para confirmar o procedimento > O relatório (log) estará em C:\Ad-Report-CLEAN[2].log ____________________ C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011 :!: No seu log consta que você ainda continua com o Kaspersky. Se a causa da infecção foi o uso de um antivirus pirata, o PC continuará infectado enquanto você permanecer com ele. _____________________ :seta: Na sua próxima respostas poste o log que estará em C:\Ad-Report-CLEAN[2].log juntamente com um novo log do Hijackthis. -------------------------------------------------------------------------------------------------------------------------------------------------- Olá Antônio, fiz o que pediu... desinstalei o KIS, instalei o AVIRA e realizei novamente os procedimentos anteriores, segue os dados para tua análise. Abçs -------------------------------------------------------------------------------------------------------------------------------------------------- Avira AntiVir Personal Report file date: segunda-feira, 17 de janeiro de 2011 10:46 Scanning for 2373520 virus strains and unwanted programs. The program is running as an unrestricted full version. Online services are available: Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Service Pack 3) [5.1.2600] Boot mode : Normally booted Username : SYSTEM Computer name : MIGUEL Version information: BUILD.DAT : 10.0.0.609 31824 Bytes 13/12/2010 09:43:00 AVSCAN.EXE : 10.0.3.5 435368 Bytes 13/12/2010 11:39:56 AVSCAN.DLL : 10.0.3.0 46440 Bytes 1/4/2010 15:57:04 LUKE.DLL : 10.0.3.2 104296 Bytes 13/12/2010 11:40:06 LUKERES.DLL : 10.0.0.1 12648 Bytes 11/2/2010 02:40:49 VBASE000.VDF : 7.10.0.0 19875328 Bytes 6/11/2009 12:05:36 VBASE001.VDF : 7.11.0.0 13342208 Bytes 14/12/2010 13:37:48 VBASE002.VDF : 7.11.0.1 2048 Bytes 14/12/2010 13:37:48 VBASE003.VDF : 7.11.0.2 2048 Bytes 14/12/2010 13:37:49 VBASE004.VDF : 7.11.0.3 2048 Bytes 14/12/2010 13:37:49 VBASE005.VDF : 7.11.0.4 2048 Bytes 14/12/2010 13:37:49 VBASE006.VDF : 7.11.0.5 2048 Bytes 14/12/2010 13:37:50 VBASE007.VDF : 7.11.0.6 2048 Bytes 14/12/2010 13:37:51 VBASE008.VDF : 7.11.0.7 2048 Bytes 14/12/2010 13:37:51 VBASE009.VDF : 7.11.0.8 2048 Bytes 14/12/2010 13:37:51 VBASE010.VDF : 7.11.0.9 2048 Bytes 14/12/2010 13:37:52 VBASE011.VDF : 7.11.0.10 2048 Bytes 14/12/2010 13:37:52 VBASE012.VDF : 7.11.0.11 2048 Bytes 14/12/2010 13:37:52 VBASE013.VDF : 7.11.0.52 128000 Bytes 16/12/2010 13:38:02 VBASE014.VDF : 7.11.0.91 226816 Bytes 20/12/2010 13:38:17 VBASE015.VDF : 7.11.0.122 136192 Bytes 21/12/2010 13:38:28 VBASE016.VDF : 7.11.0.156 122880 Bytes 24/12/2010 13:38:43 VBASE017.VDF : 7.11.0.185 146944 Bytes 27/12/2010 13:38:46 VBASE018.VDF : 7.11.0.228 132608 Bytes 30/12/2010 13:38:47 VBASE019.VDF : 7.11.1.5 148480 Bytes 3/1/2011 13:38:50 VBASE020.VDF : 7.11.1.37 156672 Bytes 7/1/2011 13:38:52 VBASE021.VDF : 7.11.1.65 140800 Bytes 10/1/2011 13:38:53 VBASE022.VDF : 7.11.1.87 225280 Bytes 11/1/2011 13:38:57 VBASE023.VDF : 7.11.1.124 125440 Bytes 14/1/2011 13:38:58 VBASE024.VDF : 7.11.1.125 2048 Bytes 14/1/2011 13:38:59 VBASE025.VDF : 7.11.1.126 2048 Bytes 14/1/2011 13:38:59 VBASE026.VDF : 7.11.1.127 2048 Bytes 14/1/2011 13:38:59 VBASE027.VDF : 7.11.1.128 2048 Bytes 14/1/2011 13:39:00 VBASE028.VDF : 7.11.1.129 2048 Bytes 14/1/2011 13:39:00 VBASE029.VDF : 7.11.1.130 2048 Bytes 14/1/2011 13:39:00 VBASE030.VDF : 7.11.1.131 2048 Bytes 14/1/2011 13:39:00 VBASE031.VDF : 7.11.1.151 93184 Bytes 17/1/2011 13:39:02 Engineversion : 8.2.4.140 AEVDF.DLL : 8.1.2.1 106868 Bytes 13/12/2010 11:39:51 AESCRIPT.DLL : 8.1.3.52 1282426 Bytes 17/1/2011 13:39:29 AESCN.DLL : 8.1.7.2 127349 Bytes 13/12/2010 11:39:50 AESBX.DLL : 8.1.3.2 254324 Bytes 13/12/2010 11:39:50 AERDL.DLL : 8.1.9.2 635252 Bytes 13/12/2010 11:39:50 AEPACK.DLL : 8.2.4.7 512375 Bytes 17/1/2011 13:39:25 AEOFFICE.DLL : 8.1.1.10 201084 Bytes 13/12/2010 11:39:49 AEHEUR.DLL : 8.1.2.64 3154294 Bytes 17/1/2011 13:39:21 AEHELP.DLL : 8.1.16.0 246136 Bytes 13/12/2010 11:39:42 AEGEN.DLL : 8.1.5.1 397683 Bytes 17/1/2011 13:39:07 AEEMU.DLL : 8.1.3.0 393589 Bytes 13/12/2010 11:39:42 AECORE.DLL : 8.1.19.0 196984 Bytes 13/12/2010 11:39:41 AEBB.DLL : 8.1.1.0 53618 Bytes 13/12/2010 11:39:41 AVWINLL.DLL : 10.0.0.0 19304 Bytes 13/12/2010 11:39:56 AVPREF.DLL : 10.0.0.0 44904 Bytes 13/12/2010 11:39:54 AVREP.DLL : 10.0.0.8 62209 Bytes 17/6/2010 17:27:13 AVREG.DLL : 10.0.3.2 53096 Bytes 13/12/2010 11:39:54 AVSCPLR.DLL : 10.0.3.2 84328 Bytes 13/12/2010 11:39:56 AVARKT.DLL : 10.0.22.6 231784 Bytes 13/12/2010 11:39:52 AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 13/12/2010 11:39:53 SQLITE3.DLL : 3.6.19.0 355688 Bytes 17/6/2010 17:27:22 AVSMTP.DLL : 10.0.0.17 63848 Bytes 13/12/2010 11:39:56 NETNT.DLL : 10.0.0.0 11624 Bytes 17/6/2010 17:27:21 RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 28/1/2010 16:10:20 RCTEXT.DLL : 10.0.58.0 97128 Bytes 13/12/2010 11:40:20 Configuration settings for the scan: Jobname.............................: Complete system scan Configuration file..................: C:\Arquivos de programas\Avira\AntiVir Desktop\sysscan.avp Logging.............................: low Primary action......................: interactive Secondary action....................: ignore Scan master boot sector.............: on Scan boot sector....................: on Boot sectors........................: C:, E:, Process scan........................: on Extended process scan...............: on Scan registry.......................: on Search for rootkits.................: on Integrity checking of system files..: off Scan all files......................: All files Scan archives.......................: on Recursion depth.....................: 20 Smart extensions....................: on Macro heuristic.....................: on File heuristic......................: medium Start of the scan: segunda-feira, 17 de janeiro de 2011 10:46 Starting search for hidden objects. HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc\Config\Standalone\drivelist [NOTE] The registry entry is invisible. The scan of running processes will be started Scan process 'msdtc.exe' - '40' Module(s) have been scanned Scan process 'dllhost.exe' - '59' Module(s) have been scanned Scan process 'dllhost.exe' - '45' Module(s) have been scanned Scan process 'vssvc.exe' - '48' Module(s) have been scanned Scan process 'avscan.exe' - '69' Module(s) have been scanned Scan process 'avcenter.exe' - '79' Module(s) have been scanned Scan process 'chrome.exe' - '37' Module(s) have been scanned Scan process 'chrome.exe' - '37' Module(s) have been scanned Scan process 'avgnt.exe' - '52' Module(s) have been scanned Scan process 'sched.exe' - '46' Module(s) have been scanned Scan process 'avshadow.exe' - '26' Module(s) have been scanned Scan process 'avguard.exe' - '54' Module(s) have been scanned Scan process 'chrome.exe' - '56' Module(s) have been scanned Scan process 'chrome.exe' - '54' Module(s) have been scanned Scan process 'chrome.exe' - '37' Module(s) have been scanned Scan process 'chrome.exe' - '40' Module(s) have been scanned Scan process 'chrome.exe' - '37' Module(s) have been scanned Scan process 'chrome.exe' - '37' Module(s) have been scanned Scan process 'chrome.exe' - '37' Module(s) have been scanned Scan process 'chrome.exe' - '68' Module(s) have been scanned Scan process 'NOTEPAD.EXE' - '27' Module(s) have been scanned Scan process 'NOTEPAD.EXE' - '27' Module(s) have been scanned Scan process 'hpqSTE08.exe' - '50' Module(s) have been scanned Scan process 'IEMonitor.exe' - '28' Module(s) have been scanned Scan process 'hpqtra08.exe' - '71' Module(s) have been scanned Scan process 'svchost.exe' - '34' Module(s) have been scanned Scan process 'NMIndexStoreSvr.exe' - '52' Module(s) have been scanned Scan process 'alg.exe' - '34' Module(s) have been scanned Scan process 'NMIndexingService.exe' - '38' Module(s) have been scanned Scan process 'wmiapsrv.exe' - '45' Module(s) have been scanned Scan process 'TuneUpUtilitiesApp32.exe' - '24' Module(s) have been scanned Scan process 'TeaTimer.exe' - '37' Module(s) have been scanned Scan process 'SpywareTerminatorUpdate.exe' - '52' Module(s) have been scanned Scan process 'msnmsgr.exe' - '109' Module(s) have been scanned Scan process 'IDMan.exe' - '61' Module(s) have been scanned Scan process 'NMBgMonitor.exe' - '46' Module(s) have been scanned Scan process 'ctfmon.exe' - '25' Module(s) have been scanned Scan process 'SpywareTerminatorShield.exe' - '32' Module(s) have been scanned Scan process 'MSASCui.exe' - '65' Module(s) have been scanned Scan process 'GrooveMonitor.exe' - '44' Module(s) have been scanned Scan process 'realsched.exe' - '28' Module(s) have been scanned Scan process 'jusched.exe' - '21' Module(s) have been scanned Scan process 'HPWuSchd2.exe' - '19' Module(s) have been scanned Scan process 'RTHDCPL.EXE' - '37' Module(s) have been scanned Scan process 'sm56hlpr.exe' - '48' Module(s) have been scanned Scan process 'PDVDServ.exe' - '25' Module(s) have been scanned Scan process 'Explorer.EXE' - '164' Module(s) have been scanned Scan process 'TuneUpUtilitiesService32.exe' - '67' Module(s) have been scanned Scan process 'svchost.exe' - '42' Module(s) have been scanned Scan process 'sp_rsser.exe' - '25' Module(s) have been scanned Scan process 'svchost.exe' - '35' Module(s) have been scanned Scan process 'svchost.exe' - '30' Module(s) have been scanned Scan process 'jqs.exe' - '84' Module(s) have been scanned Scan process 'svchost.exe' - '42' Module(s) have been scanned Scan process 'spoolsv.exe' - '57' Module(s) have been scanned Scan process 'svchost.exe' - '42' Module(s) have been scanned Scan process 'svchost.exe' - '42' Module(s) have been scanned Scan process 'svchost.exe' - '30' Module(s) have been scanned Scan process 'svchost.exe' - '175' Module(s) have been scanned Scan process 'MsMpEng.exe' - '44' Module(s) have been scanned Scan process 'svchost.exe' - '40' Module(s) have been scanned Scan process 'svchost.exe' - '54' Module(s) have been scanned Scan process 'lsass.exe' - '59' Module(s) have been scanned Scan process 'services.exe' - '36' Module(s) have been scanned Scan process 'winlogon.exe' - '66' Module(s) have been scanned Scan process 'csrss.exe' - '14' Module(s) have been scanned Scan process 'smss.exe' - '2' Module(s) have been scanned Starting master boot sector scan: Master boot sector HD0 [iNFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [iNFO] No virus was found! Boot sector 'E:\' [iNFO] No virus was found! Starting to scan executable files (registry). The registry was scanned ( '498' files ). Starting the file scan: Begin scan in 'C:\' <Sistema> Begin scan in 'E:\' <Documentos> E:\Meus Documentos\Downloads\instala.exe [DETECTION] Is the TR/Spy.Banker.Gen Trojan E:\Meus Documentos\Downloads\Internet_Download_Manager_5.19_build_4_%2B_Patch_Upload_Jefferson.rar [0] Archive type: RAR [DETECTION] Is the TR/Spy.166912.14 Trojan --> Internet Download Manager 5.19 build 4 + Patch Upload Jefferson\Patch IDM\Patch 6.xx.exe [DETECTION] Is the TR/Spy.166912.14 Trojan E:\Meus Documentos\Downloads\PhotoFiltre_Studio_X_1030.rar [0] Archive type: RAR [DETECTION] Is the TR/Horse.SXL Trojan --> keygen.exe [DETECTION] Is the TR/Horse.SXL Trojan --> pfs-setup-en.exe [1] Archive type: NSIS --> ProgramFilesDir/PhotoFiltre Studio.htm [WARNING] The file could not be written! --> ProgramFilesDir/PhotoMasque.htm [WARNING] The file could not be written! --> ProgramFilesDir/Read-me.txt [WARNING] The file could not be written! --> ProgramFilesDir/Aeroplan.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Arrow01.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Arrow02.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Arrow03.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Balloon01.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Cat.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Cross.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Envelope.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Fisherman.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Hexagon.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Hunter.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Misc02.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Stamp01.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Stamp02.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Star02.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Triangle02.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Triangle03.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Triangle04.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Australia.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Austria.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Belgium.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Brazil.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Island.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Italy.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Marocoo.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_NorthAmerica.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Norway.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Poland.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Romania.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Spain.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_Sweden.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_UnitedKingdom.pfs [WARNING] The file could not be written! --> ProgramFilesDir/Map_World.pfs [WARNING] The file could not be written! --> ProgramFilesDir/8bf.pfl [WARNING] The file could not be written! --> ProgramFilesDir/PfiShellExt.dll [WARNING] The file could not be written! --> ProgramFilesDir/Raw.pfl [WARNING] The file could not be written! --> ProgramFilesDir/Read-me.txt [WARNING] The file could not be written! --> ProgramFilesDir/Border01.gif [WARNING] The file could not be written! --> ProgramFilesDir/Border03.gif [WARNING] The file could not be written! --> ProgramFilesDir/Border05.gif [WARNING] The file could not be written! --> ProgramFilesDir/Border07.gif [WARNING] The file could not be written! --> ProgramFilesDir/Border09.gif [WARNING] The file could not be written! --> ProgramFilesDir/Border10.gif [WARNING] The file could not be written! --> ProgramFilesDir/Border11.gif [WARNING] The file could not be written! --> ProgramFilesDir/Border13.gif [WARNING] The file could not be written! --> ProgramFilesDir/Border14.gif [WARNING] The file could not be written! --> ProgramFilesDir/Camera01.gif [WARNING] The file could not be written! --> ProgramFilesDir/Camera03.gif [WARNING] The file could not be written! --> ProgramFilesDir/Camera07.gif [WARNING] The file could not be written! --> ProgramFilesDir/Camera08.gif [WARNING] The file could not be written! --> ProgramFilesDir/Frame02.gif [WARNING] The file could not be written! --> ProgramFilesDir/Frame03.gif [WARNING] The file could not be written! --> ProgramFilesDir/Frame04.gif [WARNING] The file could not be written! --> ProgramFilesDir/Frame05.gif [WARNING] The file could not be written! --> ProgramFilesDir/Frame08.gif [WARNING] The file could not be written! --> ProgramFilesDir/Frame09.gif [WARNING] The file could not be written! --> ProgramFilesDir/Frame10.gif [WARNING] The file could not be written! --> ProgramFilesDir/Frame11.gif [WARNING] The file could not be written! --> ProgramFilesDir/Misc01.gif [WARNING] The file could not be written! --> ProgramFilesDir/Misc03.gif [WARNING] The file could not be written! --> ProgramFilesDir/Misc04.gif [WARNING] The file could not be written! --> ProgramFilesDir/Misc06.gif [WARNING] The file could not be written! --> ProgramFilesDir/Misc07.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Brush.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Bubbles.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Chaos.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Dilution.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Ellipse.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Flame.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Fog.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Keyhole.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Lines.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Motion.jpg [WARNING] The file could not be written! --> ProgramFilesDir/PF-Pastels.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Radial.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Slide.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Snowflake.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Star.gif [WARNING] The file could not be written! --> ProgramFilesDir/PF-Watercolor.gif [WARNING] The file could not be written! --> ProgramFilesDir/Stamp02.gif [WARNING] The file could not be written! --> ProgramFilesDir/Star04.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Braid01.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Braid02.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Canvas03.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Color01.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Color02.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Color03.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Fabric01.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Fabric03.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Marble02.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Metal01.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Metal02.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Metal04.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Nature01.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Paper02.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Wall01.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Wall03.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Wood01.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Animals.png [WARNING] The file could not be written! --> ProgramFilesDir/Decoration.png [WARNING] The file could not be written! --> ProgramFilesDir/Default.png [WARNING] The file could not be written! --> ProgramFilesDir/Digital.png [WARNING] The file could not be written! --> ProgramFilesDir/Flowers.png [WARNING] The file could not be written! --> ProgramFilesDir/Pastels.png [WARNING] The file could not be written! --> ProgramFilesDir/Space.png [WARNING] The file could not be written! --> ProgramFilesDir/Splash.png [WARNING] The file could not be written! --> ProgramFilesDir/Butterflies.png [WARNING] The file could not be written! --> ProgramFilesDir/Cord.png [WARNING] The file could not be written! --> ProgramFilesDir/Flowers.png [WARNING] The file could not be written! --> ProgramFilesDir/PFS.png [WARNING] The file could not be written! --> ProgramFilesDir/Rabbits.png [WARNING] The file could not be written! --> ProgramFilesDir/Shells.png [WARNING] The file could not be written! --> ProgramFilesDir/Star01.png [WARNING] The file could not be written! --> ProgramFilesDir/Texture03.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Texture08.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Texture09.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Texture12.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Texture13.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Texture15.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Texture17.jpg [WARNING] The file could not be written! --> ProgramFilesDir/Flower01.png [WARNING] The file could not be written! --> ProgramFilesDir/Flower02.png [WARNING] The file could not be written! --> ProgramFilesDir/Frame01.png [WARNING] The file could not be written! --> ProgramFilesDir/Frame02.png [WARNING] The file could not be written! --> ProgramFilesDir/Frame03.png [WARNING] The file could not be written! --> ProgramFilesDir/Frame04.png [WARNING] The file could not be written! --> ProgramFilesDir/Frame05.png [WARNING] The file could not be written! --> ProgramFilesDir/Nature01.png [WARNING] The file could not be written! --> ProgramFilesDir/Nature02.png [WARNING] The file could not be written! --> ProgramFilesDir/Curve 01.pfv [WARNING] The file could not be written! --> ProgramFilesDir/Curve 03.pfv [WARNING] The file could not be written! --> ProgramFilesDir/PF-Diamond.pfv [WARNING] The file could not be written! --> ProgramFilesDir/PF-Heart.pfv [WARNING] The file could not be written! --> ProgramFilesDir/PF-Spade.pfv [WARNING] The file could not be written! [WARNING] The file could not be written! Beginning disinfection: E:\Meus Documentos\Downloads\PhotoFiltre_Studio_X_1030.rar [DETECTION] Is the TR/Horse.SXL Trojan [NOTE] The file was moved to the quarantine directory under the name '4a1df6e1.qua'. E:\Meus Documentos\Downloads\Internet_Download_Manager_5.19_build_4_%2B_Patch_Upload_Jefferson.rar [DETECTION] Is the TR/Spy.166912.14 Trojan [NOTE] The file was moved to the quarantine directory under the name '5281d94c.qua'. E:\Meus Documentos\Downloads\instala.exe [DETECTION] Is the TR/Spy.Banker.Gen Trojan [NOTE] The file was moved to the quarantine directory under the name '00d183a4.qua'. End of the scan: segunda-feira, 17 de janeiro de 2011 11:28 Used time: 40:04 Minute(s) The scan has been done completely. 6511 Scanned directories 195919 Files were scanned 3 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 3 Files were moved to quarantine 0 Files were renamed 0 Files cannot be scanned 195916 Files not concerned 2165 Archives were scanned 138 Warnings 3 Notes 360358 Objects were scanned with rootkit scan 1 Hidden objects were found -------------------------------------------------------------------------------------------------------------------------------------------------- ======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 16/01/11 at 02:00 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Arquivos de programas\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 10:05:31 on 17/01/2011, Normal boot Microsoft Windows XP Professional Service Pack 3 (X86) Usuario@MIGUEL ( ) ============== ACTION(S) ============== File deleted: C:\Arquivos de programas\Mozilla FireFox\searchplugins\crawlersrch.xml File deleted: C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job Folder deleted: C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\extensions\toolbar@ask.com Folder deleted: C:\Arquivos de programas\Ask.com Folder deleted: C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\AskToolbar Folder deleted: C:\Arquivos de programas\Crawler (!) -- Temporary files deleted. -- File opened: C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\Prefs.js -- Line deleted: user_pref("browser.search.defaultenginename", "Crawler Search"); Line deleted: user_pref("browser.search.order.1", "Crawler Search"); Line deleted: user_pref("extensions.asktb.cbid", "F4"); Line deleted: user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}... Line deleted: user_pref("extensions.asktb.dtid", "YYYYYYYYBR"); Line deleted: user_pref("extensions.asktb.fresh-install", false); Line deleted: user_pref("extensions.asktb.l", "dis"); Line deleted: user_pref("extensions.asktb.last-config-req", "1321496627732"); Line deleted: user_pref("extensions.asktb.locale", "en_US"); Line deleted: user_pref("extensions.asktb.o", "101699"); Line deleted: user_pref("extensions.asktb.overlay-reloaded-using-restart", true); Line deleted: user_pref("extensions.asktb.qsrc", "2871"); Line deleted: user_pref("extensions.asktb.r", "4"); Line deleted: user_pref("extensions.asktb.search-suggestions-enabled", true); Line deleted: user_pref("extensions.asktb.v", "3.8.0.99999"); Line deleted: user_pref("extensions.enabledItems", "{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1,{CAFEEFAC-0016-00... -- File closed -- Key deleted: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key deleted: HKLM\Software\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163} Key deleted: HKLM\Software\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Key deleted: HKLM\Software\Classes\CLSID\{1DDA201E-5B42-4352-933E-21A92B297E3B} Key deleted: HKLM\Software\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Key deleted: HKLM\Software\Classes\CLSID\{4D25FB7A-8902-4291-960E-9ADA051CFBBF} Key deleted: HKLM\Software\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC} Key deleted: HKLM\Software\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C} Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C} Key deleted: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key deleted: HKLM\Software\Classes\CLSID\{DBDB6FAA-1F5F-4A18-B60B-7A905C7FF83F} Key deleted: HKLM\Software\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF} Key deleted: HKLM\Software\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE} Key deleted: HKLM\Software\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808} Key deleted: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key deleted: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key deleted: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key deleted: HKLM\Software\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9} Key deleted: HKLM\Software\Classes\TypeLib\{04006843-5199-4CE4-B3CD-8092CC91706E} Key deleted: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key deleted: HKLM\Software\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966} Key deleted: HKLM\Software\Classes\TypeLib\{E79BB61D-7F1A-41DF-8AD0-402795E3B566} Key deleted: HKLM\Software\Classes\ctbcommon.Buttons Key deleted: HKLM\Software\Classes\ctbr.R404Pro Key deleted: HKLM\Software\Classes\CToolbar.TB4Client Key deleted: HKLM\Software\Classes\CToolbar.TB4Script Key deleted: HKLM\Software\Classes\CToolbar.TB4Server Key deleted: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd Key deleted: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1 Key deleted: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL Key deleted: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key deleted: HKLM\Software\CToolbar Key deleted: HKCU\Software\Ask.com Key deleted: HKCU\Software\AskToolbar Key deleted: HKCU\Software\CToolbar Key deleted: HKCU\Software\AppDataLow\AskToolbarInfo Key deleted: HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Key deleted: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\CToolbar_UNINSTALL Key deleted: HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search Key deleted: HKLM\Software\Classes\PROTOCOLS\Handler\tbr Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\Crawler Value deleted: HKLM\Software\Mozilla\Firefox\Extensions|{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Value deleted: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440} Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{4B3803EA-5230-4DC3-A7FC-33638F3D3542} Value deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440} Value deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{4B3803EA-5230-4DC3-A7FC-33638F3D3542} ============== ADDITIONNAL SCAN ============== ** Mozilla Firefox Version [3.6.13 (pt-BR)] ** -- C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\Prefs.js -- browser.download.lastDir, C:\\Documents and Settings\\Usuario\\Desktop\\BUENOS AIRES browser.search.selectedEngine, Google browser.startup.homepage, hxxp://www.crawler.com/homepage.aspx?tbid=60076 browser.startup.homepage_override.mstone, rv:1.9.2.13 keyword.URL, hxxp://search.instantfirefox.com/google#q= ======================================== ** Internet Explorer Version [8.0.6001.18702] ** [HKCU\Software\Microsoft\Internet Explorer\Main] Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Do404Search: 0x01000000 Enable Browser Extensions: yes Local Page: C:\WINDOWS\system32\blank.htm Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896 Show_ToolBar: yes Start Page: hxxp://fr.msn.com/ Use Search Asst: no [HKLM\Software\Microsoft\Internet Explorer\Main] Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896 Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Delete_Temp_Files_On_Exit: yes Local Page: C:\WINDOWS\system32\blank.htm Search bar: hxxp://search.msn.com/spbasic.htm Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Start Page: hxxp://fr.msn.com/ [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS] Tabs: res://ieframe.dll/tabswelcome.htm Blank: res://mshtml.dll/blank.htm ======================================== C:\Arquivos de programas\Ad-Remover\Quarantine: 331 File(s) C:\Arquivos de programas\Ad-Remover\Backup: 15 File(s) C:\Ad-Report-CLEAN[1].txt - 17/01/2011 (8062 Byte(s)) C:\Ad-Report-SCAN[1].txt - 15/01/2011 (8957 Byte(s)) End at: 10:09:41, 17/01/2011 ============== E.O.F ============== -------------------------------------------------------------------------------------------------------------------------------------------------- ======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 ======= Updated by TeamXscript on 16/01/11 at 02:00 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com website: http://www.teamxscript.org C:\Arquivos de programas\Ad-Remover\main.exe (CLEAN [2]) -> Launched at 10:18:16 on 17/01/2011, Normal boot Microsoft Windows XP Professional Service Pack 3 (X86) Usuario@MIGUEL ( ) ============== ACTION(S) ============== (!) -- Temporary files deleted. Key deleted: HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search ============== ADDITIONNAL SCAN ============== ** Mozilla Firefox Version [3.6.13 (pt-BR)] ** -- C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\Prefs.js -- browser.download.lastDir, C:\\Documents and Settings\\Usuario\\Desktop\\BUENOS AIRES browser.search.selectedEngine, Google browser.startup.homepage, hxxp://www.crawler.com/homepage.aspx?tbid=60076 browser.startup.homepage_override.mstone, rv:1.9.2.13 keyword.URL, hxxp://search.instantfirefox.com/google#q= ======================================== ** Internet Explorer Version [8.0.6001.18702] ** [HKCU\Software\Microsoft\Internet Explorer\Main] Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Do404Search: 0x01000000 Enable Browser Extensions: yes Local Page: C:\WINDOWS\system32\blank.htm Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896 Show_ToolBar: yes Start Page: hxxp://fr.msn.com/ Use Search Asst: no [HKLM\Software\Microsoft\Internet Explorer\Main] Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896 Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Delete_Temp_Files_On_Exit: yes Local Page: C:\WINDOWS\system32\blank.htm Search bar: hxxp://search.msn.com/spbasic.htm Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Start Page: hxxp://fr.msn.com/ [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS] Tabs: res://ieframe.dll/tabswelcome.htm Blank: res://mshtml.dll/blank.htm ======================================== C:\Arquivos de programas\Ad-Remover\Quarantine: 331 File(s) C:\Arquivos de programas\Ad-Remover\Backup: 16 File(s) C:\Ad-Report-CLEAN[1].txt - 17/01/2011 (9473 Byte(s)) C:\Ad-Report-CLEAN[2].txt - 17/01/2011 (2238 Byte(s)) C:\Ad-Report-SCAN[1].txt - 15/01/2011 (8957 Byte(s)) End at: 10:19:28, 17/01/2011 ============== E.O.F ============== -------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 10:14:24, on 17/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\Arquivos de programas\Google\Update\GoogleUpdate.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Google\Update\GoogleUpdate.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Windows Defender\MSASCui.exe C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Internet Download Manager\IDMan.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R3 - Default URLSearchHook is missing O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file) O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Arquivos de programas\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Janeiro 17, 2011 :) Vários outros problemas foram removidos. ___________________ :seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked: O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file) O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) ____________________ :seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: Faça o download do ComboFix Salve-o no Desktop (área de trabalho). * Desabilite as proteções residente de: antivírus, antispywares e firewall ( menos o do Windows! ) * Feche todas as janelas e execute a ferramenta. * Ps: A execução, por comando, também é possível: * Vá em Iniciar --> Executar --> Digite ou cole: "%userprofile%\desktop\Combofix.exe" /killall * Clique em Ok. * Na solicitação: "Negação de garantia de software" --> Clique em Sim. * Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo. * Terminando,clique Sim ou Yes. --> Aguarde. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX :!: Caso aconteça a notificação de: Aplicativo Win32 inválido ou alguma mensagem parecida com esta, delete a ferramenta ComboFix.exe e faça, novamente, seu download. * Salve-a no Desktop,renomeada como: Kombo.exe * Ps: Nomeie durante o salvamento,e não após salvá-la! * Ps: Surgindo alguma mensagem de erro, rode o ComboFix.exe em "Modo Seguro". <-- Link! * Ps: Na presença de atividades rootkit,teremos a seguinte janela de notificação: * Ps: Anote essas detecções, e dê o OK. Neste caso poste estas detecções que você terá anotado em sua próxima resposta juntamente com os logs pedidos. * Ps: Para completar as remoções, talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde! * Ps: Para evitar problemas, siga todas as recomendações propostas. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX * Abrir-se-á a janela Auto Scan. --> Aguarde! * Para finalizar remoções, o ComboFix poderá reiniciar o computador. * Se houver necessidade, digite a opção ( 1 ) --> Aperte Enter! --> Aguarde a conclusão! * Durante o scan, evite manusear o mouse ou teclado! <-- Importante! * Caso, por algum motivo de força maior, precise parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter. <><><><><><><><><><><><> Poste o log do Combofix que estará em C:\ComboFix.txt juntamente com um novo log do Hijackthis em sua próxima resposta e nos diga como está o seu PC depois disto. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
mig.bel 0 Denunciar post Postado Janeiro 17, 2011 :) Vários outros problemas foram removidos. ___________________ :seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked: O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file) O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) ____________________ :seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet: Faça o download do ComboFix Salve-o no Desktop (área de trabalho). * Desabilite as proteções residente de: antivírus, antispywares e firewall ( menos o do Windows! ) * Feche todas as janelas e execute a ferramenta. * Ps: A execução, por comando, também é possível: * Vá em Iniciar --> Executar --> Digite ou cole: "%userprofile%\desktop\Combofix.exe" /killall * Clique em Ok. * Na solicitação: "Negação de garantia de software" --> Clique em Sim. * Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo. * Terminando,clique Sim ou Yes. --> Aguarde. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX :!: Caso aconteça a notificação de: Aplicativo Win32 inválido ou alguma mensagem parecida com esta, delete a ferramenta ComboFix.exe e faça, novamente, seu download. * Salve-a no Desktop,renomeada como: Kombo.exe * Ps: Nomeie durante o salvamento,e não após salvá-la! * Ps: Surgindo alguma mensagem de erro, rode o ComboFix.exe em "Modo Seguro". <-- Link! * Ps: Na presença de atividades rootkit,teremos a seguinte janela de notificação: * Ps: Anote essas detecções, e dê o OK. Neste caso poste estas detecções que você terá anotado em sua próxima resposta juntamente com os logs pedidos. * Ps: Para completar as remoções, talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde! * Ps: Para evitar problemas, siga todas as recomendações propostas. XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX * Abrir-se-á a janela Auto Scan. --> Aguarde! * Para finalizar remoções, o ComboFix poderá reiniciar o computador. * Se houver necessidade, digite a opção ( 1 ) --> Aperte Enter! --> Aguarde a conclusão! * Durante o scan, evite manusear o mouse ou teclado! <-- Importante! * Caso, por algum motivo de força maior, precise parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter. <><><><><><><><><><><><> Poste o log do Combofix que estará em C:\ComboFix.txt juntamente com um novo log do Hijackthis em sua próxima resposta e nos diga como está o seu PC depois disto. Ficamos no aguardo. -------------------------------------------------------------------------------------------------------------------------------------------------- Olá Antônio, mais uma vez segui todos os passos por ti sugeridos, segue adiante os logs solicitados. P.S: A entrada a que referiste não estava presente no Hijack This: O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) -------------------------------------------------------------------------------------------------------------------------------------------------- ComboFix 11-01-16.04 - Usuario 17/01/2011 15:07:19.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.3005.2080 [GMT -3:00] Executando de: e:\meus documentos\Downloads\Programs\ComboFix.exe AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Autorun.inf A cópia de c:\windows\regedit.exe foi encontrada e desinfectada Cópia restaurada de - c:\windows\VistaMizer\old\regedit.exe A cópia de c:\windows\system32\midimap.dll foi encontrada e desinfectada Cópia restaurada de - c:\windows\VistaMizer\old\midimap.dll . (((((((((((((((( Arquivos/Ficheiros criados de 2010-12-17 to 2011-01-17 )))))))))))))))))))))))))))) . 2011-01-17 14:41 . 2011-01-17 14:41 -------- d-----r- c:\documents and settings\LocalService\Favoritos 2011-01-17 13:46 . 2011-01-17 14:18 -------- d-----w- c:\windows\system32\NtmsData 2011-01-17 13:45 . 2011-01-17 13:45 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Avira 2011-01-17 13:26 . 2010-12-13 11:40 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2011-01-17 13:26 . 2010-12-13 11:40 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys 2011-01-17 13:26 . 2010-06-17 17:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys 2011-01-17 13:26 . 2010-06-17 17:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys 2011-01-17 13:26 . 2011-01-17 13:26 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Avira 2011-01-17 13:26 . 2011-01-17 13:26 -------- d-----w- c:\arquivos de programas\Avira 2011-01-16 02:44 . 2011-01-16 02:47 -------- d-----w- C:\LinhaDefensiva 2011-01-16 01:34 . 2011-01-16 01:34 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Malwarebytes 2011-01-16 01:34 . 2010-12-20 21:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-01-16 01:34 . 2011-01-16 01:34 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes 2011-01-16 01:34 . 2011-01-16 01:34 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware 2011-01-16 01:34 . 2010-12-20 21:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-01-16 01:29 . 2011-01-16 01:29 -------- d-----w- c:\arquivos de programas\Ad-Remover 2011-01-15 14:55 . 2011-01-15 16:48 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy 2011-01-15 14:55 . 2011-01-15 15:17 -------- d-----w- c:\arquivos de programas\Spybot - Search & Destroy 2011-01-15 13:05 . 2011-01-15 13:05 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys 2011-01-15 13:05 . 2011-01-17 17:53 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Spyware Terminator 2011-01-15 13:04 . 2011-01-17 16:06 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spyware Terminator 2011-01-15 13:04 . 2011-01-16 02:28 -------- d-----w- c:\arquivos de programas\Spyware Terminator 2011-01-15 12:24 . 2007-03-09 14:25 2321288 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2011-01-15 12:24 . 2010-11-16 15:01 6273872 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Microsoft\Windows Defender\Definition Updates\{64602B69-06C2-40B3-BDE1-8B15AD8AA92B}\mpengine.dll 2011-01-15 12:24 . 2010-10-19 13:41 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-01-15 12:21 . 2011-01-15 12:21 -------- d-----w- c:\arquivos de programas\Windows Defender 2011-01-15 01:34 . 2011-01-15 01:34 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\QuickScan 2011-01-12 13:00 . 2011-01-12 13:00 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Media Player Classic 2011-01-10 08:41 . 2011-01-10 08:41 -------- d-----w- c:\arquivos de programas\Pcsx2 2011-01-09 16:45 . 2011-01-09 16:45 -------- d-----w- c:\arquivos de programas\VirtualDJ 2011-01-03 12:22 . 2011-01-03 12:22 -------- d-----w- c:\arquivos de programas\Free DVD MP3 Ripper 2011-01-01 15:48 . 2011-01-01 15:48 -------- d-----w- c:\arquivos de programas\Ashampoo 2010-12-28 11:52 . 2010-12-28 11:52 -------- d-----w- c:\arquivos de programas\FreeTime 2010-12-28 11:33 . 2010-12-28 11:33 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\VOWSoft 2010-12-28 11:33 . 2010-12-28 11:35 -------- d-----w- c:\arquivos de programas\ABC 3GP Converter 2010-12-28 03:04 . 2010-12-28 03:04 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Foxit Software 2010-12-27 15:53 . 2010-12-27 15:53 -------- d-----w- c:\arquivos de programas\visao 2010-12-26 02:26 . 2010-12-26 02:26 -------- d-----w- c:\documents and settings\Usuario\Configurações locais\Dados de aplicativos\WMTools Downloaded Files 2010-12-20 19:00 . 2010-12-20 19:00 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Windows Live 2010-12-20 18:06 . 2010-12-20 18:21 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\PhotoFiltre Studio X 2010-12-20 18:06 . 2010-12-20 18:29 -------- d-----w- c:\arquivos de programas\PhotoFiltre Studio X . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-12-02 03:35 . 2010-12-02 03:35 4280320 ----a-w- c:\windows\system32\GPhotos.scr 2010-12-01 17:29 . 2010-12-10 22:34 31552 ----a-w- c:\windows\system32\TURegOpt.exe 2010-12-01 17:25 . 2010-12-10 22:34 29504 ----a-w- c:\windows\system32\uxtuneup.dll 2010-11-18 18:15 . 2010-09-07 15:47 86016 ----a-w- c:\windows\system32\isign32.dll 2010-11-12 21:53 . 2010-09-23 16:38 472808 ----a-w- c:\windows\system32\deployJava1.dll 2010-11-12 19:34 . 2010-09-23 16:38 73728 ----a-w- c:\windows\system32\javacpl.cpl 2010-11-09 14:52 . 2008-04-13 21:20 249856 ----a-w- c:\windows\system32\odbc32.dll 2010-11-06 00:21 . 2008-04-13 21:20 916480 ----a-w- c:\windows\system32\wininet.dll 2010-11-06 00:21 . 2008-04-13 21:21 1469440 ----a-w- c:\windows\system32\inetcpl.cpl 2010-11-06 00:21 . 2008-04-13 21:20 43520 ----a-w- c:\windows\system32\licmgr10.dll 2010-11-03 12:27 . 2008-04-13 20:55 385024 ----a-w- c:\windows\system32\html.iec 2010-11-02 15:17 . 2008-04-13 13:57 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys 2010-10-28 13:09 . 2008-04-13 21:18 290048 ----a-w- c:\windows\system32\atmfd.dll 2010-10-26 14:04 . 2009-05-02 02:37 1862400 ----a-w- c:\windows\system32\win32k.sys . ------- Sigcheck ------- [-] 2008-04-13 . B0C0BF2504B830BFC1E93CA39F3C75FE . 549376 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe [-] 2008-04-13 . B0C0BF2504B830BFC1E93CA39F3C75FE . 549376 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\winlogon.exe [7] 2008-04-13 . 71D440F79B711627B12B567FB2EADB42 . 509952 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\winlogon.exe [-] 2008-04-13 . 7C0E5D593730414B5994A15A6D10C201 . 588288 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll [-] 2008-04-13 . 7C0E5D593730414B5994A15A6D10C201 . 588288 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\user32.dll [7] 2008-04-13 . 54907DB28872A7A6D3EE2B4747A23828 . 579072 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\user32.dll [-] 2008-04-13 . F1A3E95588DB92660C8C6DAA9101D49B . 1554432 . . [6.00.2900.5512] . . c:\windows\explorer.exe [-] 2008-04-13 . F1A3E95588DB92660C8C6DAA9101D49B . 1554432 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\explorer.exe [7] 2008-04-13 . 064EC7FF5F58B928C3E119402977FA6D . 1035776 . . [6.00.2900.5512] . . c:\windows\VistaMizer\old\explorer.exe [-] 2008-04-13 . D67945A2290E98BB54D7792F09E7504E . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe [-] 2008-04-13 . D67945A2290E98BB54D7792F09E7504E . 25088 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ctfmon.exe [7] 2008-04-13 . 4E486ADFE3A0B9ED0EB0639902E9F64F . 15360 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ctfmon.exe [7] 2010-04-29 . 7FDAC9D0C4F6EBC61160EC9F00F03C20 . 2071168 . . [5.1.2600.5973] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe [-] 2010-04-28 . 27701C241C40FA5F23DB1F92993FD51D . 2285568 . . [5.1.2600.5973] . . c:\windows\system32\ntkrnlpa.exe [-] 2010-04-28 . 27701C241C40FA5F23DB1F92993FD51D . 2285568 . . [5.1.2600.5973] . . c:\windows\system32\dllcache\ntkrnlpa.exe [7] 2010-04-28 . BB68023414EBBEDC12D413E8FEA056A8 . 2028544 . . [5.1.2600.5973] . . c:\windows\VistaMizer\old\ntkrnlpa.exe [7] 2009-05-03 . B82DF02FCDE92772201E59F0C9AC7E60 . 2028032 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB981852$\ntkrnlpa.exe [-] 2009-03-08 . C94590AF0DB0E97199688FF1A77037D2 . 727904 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\iexplore.exe [7] 2009-03-08 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702] . . c:\windows\VistaMizer\old\iexplore.exe [7] 2008-04-13 . 04CABAD69BE78EB9C03CD4346D776DA5 . 93184 . . [6.00.2900.5512] . . c:\windows\ie8\iexplore.exe [7] 2010-04-28 . 2B14801C5D196E8BEC3EA573B3B2DA44 . 2194304 . . [5.1.2600.5973] . . c:\windows\Driver Cache\i386\ntoskrnl.exe [-] 2010-04-28 . 46D199719181A8BE461E56D1975D6ED2 . 2407424 . . [5.1.2600.5973] . . c:\windows\system32\ntoskrnl.exe [-] 2010-04-28 . 46D199719181A8BE461E56D1975D6ED2 . 2407424 . . [5.1.2600.5973] . . c:\windows\system32\dllcache\ntoskrnl.exe [7] 2010-04-28 . 235F0AD0AEF8530F06A54453F235B23C . 2150400 . . [5.1.2600.5973] . . c:\windows\VistaMizer\old\ntoskrnl.exe [7] 2009-05-03 . 3523020464F53C8FF7A3A59661F1CAA2 . 2149376 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB981852$\ntoskrnl.exe . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872] "Google Update"="c:\documents and settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2010-09-08 136176] "IDMan"="c:\arquivos de programas\Internet Download Manager\IDMan.exe" [2010-10-12 3245408] "SpywareTerminatorUpdate"="c:\arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" [2011-01-15 3318784] "SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136] "SMSERIAL"="c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe" [2008-02-21 1216512] "RTHDCPL"="RTHDCPL.EXE" [2009-08-24 18702336] "HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152] "SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-05-14 248552] "TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2010-10-04 202256] "GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "SpywareTerminator"="c:\arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe" [2011-01-15 2216960] "avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 25088] "DWQueuedReporting"="c:\arquiv~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096] c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\ HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^Usuario^Menu Iniciar^Programas^Inicializar^Recorte de tela e Iniciador do OneNote 2007.lnk] path=c:\documents and settings\Usuario\Menu Iniciar\Programas\Inicializar\Recorte de tela e Iniciador do OneNote 2007.lnk backup=c:\windows\pss\Recorte de tela e Iniciador do OneNote 2007.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2010-09-21 18:37 932288 ----a-w- c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr] 2009-07-26 19:44 3883840 ----a-w- c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] 2003-12-08 20:35 32768 ----a-w- c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Arquivos de programas\\Ares\\Ares.exe"= "c:\\Arquivos de programas\\Google\\Google Earth\\client\\googleearth.exe"= "c:\\Arquivos de programas\\Megacubo\\megacubo.exe"= "c:\\Arquivos de programas\\Spyware Terminator\\SpywareTerminatorUpdate.exe"= R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [15/1/2011 10:05 142592] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [17/1/2011 10:26 135336] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [1/12/2010 14:27 1483072] R2 WinDefend;Windows Defender;c:\arquivos de programas\Windows Defender\MsMpEng.exe [3/11/2006 19:19 13592] R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [7/9/2010 20:42 113504] R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [7/9/2010 20:46 335104] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [7/10/2010 12:34 10064] S2 gupdate;Google Update Service (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [8/9/2010 18:58 136176] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [7/9/2010 20:43 1684736] S3 smsbda;SMS Digital Video;c:\windows\system32\drivers\smsbda.sys [30/10/2010 01:39 51872] S3 ZTEusbdvbh;ZTE HS-USB DVBH-RF Service;c:\windows\system32\drivers\ZTEusbdvbh.sys [30/10/2010 01:39 105216] --- =Outros Serviços/Drivers Na Memória --- *NewlyCreated* - SSMDRV [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Conteúdo da pasta 'Tarefas Agendadas' 2011-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-09-08 21:58] 2011-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-09-08 21:58] 2011-01-17 c:\windows\Tasks\MP Scheduled Scan.job - c:\arquivos de programas\Windows Defender\MpCmdRun.exe [2006-11-03 22:20] 2011-01-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job - c:\arquivos de programas\Real\RealUpgrade\realupgrade.exe [2010-06-03 06:02] 2011-01-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job - c:\arquivos de programas\Real\RealUpgrade\realupgrade.exe [2010-06-03 06:02] . . ------- Scan Suplementar ------- . IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Crawler Search IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: Fazer o download de conteúdo de vídeo FLV usando o IDM - c:\arquivos de programas\Internet Download Manager\IEGetVL.htm IE: Fazer o download de todos os links usando o IDM - c:\arquivos de programas\Internet Download Manager\IEGetAll.htm IE: Fazer o download usando o IDM - c:\arquivos de programas\Internet Download Manager\IEExt.htm LSP: c:\windows\system32\idmmbc.dll FF - ProfilePath - c:\documents and settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\3mjwaakv.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.crawler.com/homepage.aspx?tbid=60076 FF - prefs.js: keyword.URL - hxxp://search.instantfirefox.com/google#q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\arquivos de programas\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF - Ext: Instant Firefox: instantfirefox@crossrider.com - %profile%\extensions\instantfirefox@crossrider.com FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: Java Quick Starter: jqs@sun.com - c:\arquivos de programas\Java\jre6\lib\deploy\jqs\ff FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - Ext: IDM CC: mozilla_cc@internetdownloadmanager.com - c:\documents and settings\Usuario\Dados de aplicativos\IDM\idmmzcc3 . - - - - ORFÃOS REMOVIDOS - - - - BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-01-17 15:12 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{14190654-4dd9-457a-b001-8cd81c3932e5}] @Denied: (Full) (Everyone) "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a, 1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) "scansk"=hex(0):e3,ac,aa,f3,bd,58,85,e1,7e,de,cd,55,be,cc,6d,d5,68,0a,bc,14,b2, 34,b7,09,aa,87,cd,49,ee,7f,64,b7,a3,fd,33,07,89,64,8e,4b,00,00,00,00,00,00,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Carregadas Sob os Processos em Execução --------------------- - - - - - - - > 'winlogon.exe'(860) c:\windows\system32\SETUPAPI.dll c:\windows\system32\sfc_os.dll c:\windows\system32\COMRes.dll c:\windows\system32\cscui.dll - - - - - - - > 'lsass.exe'(916) c:\windows\system32\setupapi.dll c:\windows\system32\psbase.dll c:\windows\system32\idmmbc.dll - - - - - - - > 'explorer.exe'(984) c:\windows\system32\SHDOCVW.dll c:\windows\system32\WININET.dll c:\windows\system32\COMRes.dll c:\windows\System32\cscui.dll c:\arquiv~1\WINDOW~2\wmpband.dll c:\windows\system32\LINKINFO.dll c:\windows\system32\ntshrui.dll c:\arquivos de programas\Internet Download Manager\idmmkb.dll c:\windows\system32\msi.dll c:\windows\system32\SETUPAPI.dll c:\windows\system32\NETSHELL.dll c:\windows\system32\credui.dll c:\windows\system32\MSVCP60.dll c:\windows\system32\wpdshserviceobj.dll c:\windows\system32\webcheck.dll c:\windows\system32\portabledevicetypes.dll c:\windows\system32\portabledeviceapi.dll c:\arquivos de programas\Internet Download Manager\IDMIECC.dll c:\arquivos de programas\Spybot - Search & Destroy\SDHelper.dll c:\arquivos de programas\Microsoft Office\Office12\1046\GrooveIntlResource.dll c:\arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\PDFShell.dll c:\arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\PDFShell.PTB . ------------------------ Outros Processos em Execução ------------------------ . c:\arquivos de programas\Avira\AntiVir Desktop\avguard.exe c:\arquivos de programas\Java\jre6\bin\jqs.exe c:\arquivos de programas\Avira\AntiVir Desktop\avshadow.exe c:\arquivos de programas\Spyware Terminator\sp_rsser.exe c:\windows\RTHDCPL.EXE c:\windows\system32\wbem\wmiapsrv.exe c:\arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe c:\arquivos de programas\Internet Download Manager\IEMonitor.exe c:\arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe . ************************************************************************** . Tempo para conclusão: 2011-01-17 15:18:14 - Máquina reiniciou ComboFix-quarantined-files.txt 2011-01-17 18:18 Pré-execução: 6 pasta(s) 88.452.485.120 bytes disponíveis Pós execução: 9 pasta(s) 88.557.477.888 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - EE7C35A9F56E48FACA88EBA6926539F4 -------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 15:27:57, on 17/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Internet Download Manager\IDMan.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Adobe\Reader 9.0\Reader\AcroRd32.exe C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [spywareTerminator] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Janeiro 17, 2011 :) Mais problemas removidos pelo Combofix. :seta: Siga, por gentileza, as dicas destes tutoriais: Tutorial do USBFix Tutorial do Norman Malware Cleaner _____________________ :seta: Poste o log do Usbfix que estará em C:\UsbFix.txt em sua próxima resposta juntamente com um novo log do Hijackthis e o log do Norman Malware Cleaner e nos diga como está o PC após estes procedimentos. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
mig.bel 0 Denunciar post Postado Janeiro 18, 2011 :) Mais problemas removidos pelo Combofix. :seta: Siga, por gentileza, as dicas destes tutoriais: Tutorial do USBFix Tutorial do Norman Malware Cleaner _____________________ :seta: Poste o log do Usbfix que estará em C:\UsbFix.txt em sua próxima resposta juntamente com um novo log do Hijackthis e o log do Norman Malware Cleaner e nos diga como está o PC após estes procedimentos. Ficamos no aguardo. -------------------------------------------------------------------------------------------------------------------------------------------------- Olá Antonio... conforme orientações, seguem os LOGS dos programas indicados: Norman Malware Cleaner Version 1.8.3 Copyright © 1990 - 2010, Norman ASA. Built 2011/01/17 15:43:01 Norman Scanner Engine Version: 6.06.12 Nvcbin.def Version: 6.06.00, Date: 2011/01/17 15:43:01, Variants: 9156159 Scan started: 2011/01/18 17:15:45 Running pre-scan cleanup routine: Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3 Logged on user: MIGUEL\Usuario Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = -> "" Scanning kernel... Kernel scan complete Scanning bootsectors... Number of sectors found: 2 Number of sectors scanned: 2 Number of sectors not scanned: 0 Number of infections found: 0 Number of infections removed: 0 Total scanning time: 0s 32ms Scanning running processes and process memory... Number of processes/threads found: 3027 Number of processes/threads scanned: 3027 Number of processes/threads not scanned: 0 Number of infected processes/threads terminated: 0 Total scanning time: 1m 52s Scanning file system... Scanning: prescan Scanning: C:\*.* C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6 (Error whilst scanning file: I/O Error (0x00220005)) C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6/NERO_I~2.007 (Error whilst scanning file: I/O Error (0x00220005)) C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6/NERO_S~1.006 (Error whilst scanning file: I/O Error (0x00220005)) C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6/NERO_U~1.005 (Error whilst scanning file: I/O Error (0x00220005)) C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6/NERO_V~1.004 (Error whilst scanning file: I/O Error (0x00220005)) C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6/NERO_V~2.003 (Error whilst scanning file: I/O Error (0x00220005)) C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Cache\f_000632/file0 (Error whilst scanning file: I/O Error (0x00220005)) C:\System Volume Information\_restore{2E688FF2-C923-4539-BED5-D6B4329EC271}\RP85\A0056031.dll (Infected with W32/Hacktool.KQU) Deleted file Scanning: E:\*.* E:\Meus Documentos\Downloads\Atomix Virtual DJ Pro 6.1.2 (b301)\Activator Virtual DJ 6.1.2.exe (Infected with W32/Suspicious_Gen.NHP.dropper) Deleted file E:\Meus Documentos\Downloads\aTube_Catcher.exe/noname.nsis/file0/file26 (Error whilst scanning file: I/O Error (0x00220005)) E:\Meus Documentos\Downloads\dexpot_156_r1351.exe/noname.nsis/file0/file64 (Error whilst scanning file: I/O Error (0x00220005)) E:\Meus Documentos\Downloads\PCDJ_DEX\setup_dex_1.1.7269.exe/noname.nsis/file0/file14 (Error whilst scanning file: I/O Error (0x00220005)) E:\Meus Documentos\Downloads\PCDJ_DEX.rar/setup_dex_1.1.7269.exe/noname.nsis/file0/file14 (Error whilst scanning file: I/O Error (0x00220005)) E:\Meus Documentos\Downloads\redmobile\pcdjredmobile_1.1.7269.exe/noname.nsis/file0/file19 (Error whilst scanning file: I/O Error (0x00220005)) E:\Meus Documentos\Downloads\redmobile.rar/pcdjredmobile_1.1.7269.exe/noname.nsis/file0/file19 (Error whilst scanning file: I/O Error (0x00220005)) E:\Meus Documentos\Downloads\VDJ Pro 6.1.2 (b301) + Tradução pt_BR.zip/Atomix Virtual DJ Pro 6.1.2 (b301)/Activator Virtual DJ 6.1.2.exe (Infected with W32/Suspicious_Gen.NHP.dropper) Deleted file Running post-scan cleanup routine: Aborted by user Number of files found: 193347 Number of archives unpacked: 2511 Number of files scanned: 193331 Number of files not scanned: 16 Number of files skipped due to exclude list: 0 Number of infected files found: 3 Number of infected files repaired/deleted: 3 Number of infections removed: 3 Total scanning time: 1h 9m 33s -------------------------------------------------------------------------------------------------------------------------------------------------- ############################## | UsbFix 7.038 | [supressão] Usuário: Usuario (Administrador) # MIGUEL [ ] Atualizado em 14/01/2011 por El Desaparecido / C_XX Começou em 17:06:35 | 18/01/2011 Site: http://www.teamxscript.org Contato: eldesaparecido@teamxscript.org CPU: Intel® Pentium® Dual CPU T3400 @ 2.16GHz CPU 2: Intel® Pentium® Dual CPU T3400 @ 2.16GHz Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3 Internet Explorer 8.0.6001.18702 Windows Firewall: Habilitado Antivirus: AntiVir Desktop 10.0.1.56 [(!) Disabled | Updated] RAM -> 3005 Mb C:\ (%systemdrive%) -> Disco fixo # 100 Gb (81 Mb livre - 81%) [sistema] # NTFS D:\ -> CD-ROM E:\ -> Disco fixo # 366 Gb (349 Mb livre - 95%) [Documentos] # NTFS F:\ -> Disco removível # 4 Gb (655 Mb livre - 17%) [MIGUEL JR] # FAT32 ################## | Ficheiros # pastas infeciosos | Supprimido ! C:\Recycler\S-1-5-21-606747145-329068152-1801674531-1003 Supprimido ! E:\Recycler\S-1-5-21-606747145-329068152-1801674531-1003 ################## | Registro | Supprimido ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools Supprimido ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives Supprimido ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives ################## | Mountpoints2 | ################## | Listing | [17/01/2011 - 10:09:42 | N | 9473] C:\Ad-Report-CLEAN[1].txt [17/01/2011 - 10:19:29 | N | 2598] C:\Ad-Report-CLEAN[2].txt [15/01/2011 - 22:32:00 | N | 8957] C:\Ad-Report-SCAN[1].txt [17/01/2011 - 10:26:39 | D ] C:\Arquivos de programas [07/09/2010 - 12:49:47 | N | 0] C:\AUTOEXEC.BAT [17/01/2011 - 10:35:44 | N | 211] C:\Boot.bak [17/01/2011 - 15:06:43 | N | 327] C:\boot.ini [28/09/2001 - 08:00:00 | N | 4952] C:\Bootfont.bin [17/01/2011 - 15:06:43 | D ] C:\cmdcons [03/08/2004 - 23:00:16 | N | 261856] C:\cmldr [17/01/2011 - 15:18:14 | N | 23778] C:\ComboFix.txt [17/01/2011 - 09:56:37 | D ] C:\Config.Msi [07/09/2010 - 12:49:47 | N | 0] C:\CONFIG.SYS [07/09/2010 - 12:55:21 | D ] C:\Documents and Settings [07/09/2010 - 12:49:47 | N | 0] C:\IO.SYS [15/01/2011 - 23:47:47 | D ] C:\LinhaDefensiva [07/09/2010 - 12:49:47 | N | 0] C:\MSDOS.SYS [07/09/2010 - 13:32:01 | RD ] C:\MSOCache [13/04/2008 - 08:43:04 | N | 47564] C:\NTDETECT.COM [13/04/2008 - 10:31:44 | N | 251696] C:\ntldr [18/01/2011 - 16:59:14 | ASH | 2145386496] C:\pagefile.sys [07/10/2010 - 14:24:51 | D ] C:\Program Files [17/01/2011 - 15:18:17 | D ] C:\Qoobox [18/01/2011 - 17:08:01 | SHD ] C:\RECYCLER [08/09/2010 - 15:56:44 | SHD ] C:\System Volume Information [18/01/2011 - 17:08:01 | D ] C:\UsbFix [18/01/2011 - 17:08:06 | A | 1344] C:\UsbFix.txt [16/08/2010 - 06:12:00 | N | 3118080] C:\virtualdj_trial.exe [15/04/2007 - 07:57:52 | N | 25214] C:\vista.ico [17/01/2011 - 15:11:49 | D ] C:\WINDOWS [17/01/2011 - 11:53:26 | D ] E:\Meus Documentos [18/01/2011 - 17:08:01 | SHD ] E:\RECYCLER [17/01/2011 - 11:21:45 | SHD ] E:\System Volume Information ################## | Vaccin | C:\Autorun.inf -> Folder criado por UsbFix (El Desaparecido & C_XX) E:\Autorun.inf -> Folder criado por UsbFix (El Desaparecido & C_XX) ################## | Upload | Favor enviar o arquivo: C:\UsbFix_Upload_Me_MIGUEL.zip http://www.teamxscript.org/Upload.php Obrigado pela sua contribuição. ################## | E.O.F | -------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 18:29:50, on 18/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file) O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 18:35:27, on 18/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Janeiro 20, 2011 :) Vários outros problemas foram removidos. _____________________ :seta: Favor enviar o arquivo: C:\UsbFix_Upload_Me_MIGUEL.zip para o endereço abaixo para que o Usbfix possa ser aperfeiçoado: http://www.teamxscript.org/Upload.php A equipe desenvolvedora do Usbfix agradece pela sua contribuição. _____________________ :seta: Acesse o site http://virscan.org/ e envie estes arquivos destacados em vermelho abaixo para serem analisados (um de cada vez) e assim que análise de cada um deles for concluida copie o endereço (link) que aparecerá na barra de endereços de seu navegador e poste estes links com o resultado das análises em sua próxima resposta juntamente com os outros logs pedidos abaixo: C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe E:\Meus Documentos\Downloads\aTube_Catcher.exe E:\Meus Documentos\Downloads\dexpot_156_r1351.exe E:\Meus Documentos\Downloads\PCDJ_DEX\setup_dex_1.1.7269.exe E:\Meus Documentos\Downloads\PCDJ_DEX.rar E:\Meus Documentos\Downloads\redmobile\pcdjredmobile_1.1.7269.exe E:\Meus Documentos\Downloads\redmobile.rar ___________________ :seta: Siga também, por gentileza, as dicas deste tutorial para fazer um escaneamento de seu PC pelo Nod32 Online: Tutorial do antivirus Nod32 Online Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador: C:\Arquivos de programas\Eset\Eset Online Scanner\log.txt Na sua próxima resposta poste este log do Nod32 Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir este procedimento. Ficamos no aguardo de sua resposta. Compartilhar este post Link para o post Compartilhar em outros sites
mig.bel 0 Denunciar post Postado Janeiro 21, 2011 :) Vários outros problemas foram removidos. _____________________ :seta: Favor enviar o arquivo: C:\UsbFix_Upload_Me_MIGUEL.zip para o endereço abaixo para que o Usbfix possa ser aperfeiçoado: http://www.teamxscript.org/Upload.php A equipe desenvolvedora do Usbfix agradece pela sua contribuição. _____________________ :seta: Acesse o site http://virscan.org/ e envie estes arquivos destacados em vermelho abaixo para serem analisados (um de cada vez) e assim que análise de cada um deles for concluida copie o endereço (link) que aparecerá na barra de endereços de seu navegador e poste estes links com o resultado das análises em sua próxima resposta juntamente com os outros logs pedidos abaixo: C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe E:\Meus Documentos\Downloads\aTube_Catcher.exe E:\Meus Documentos\Downloads\dexpot_156_r1351.exe E:\Meus Documentos\Downloads\PCDJ_DEX\setup_dex_1.1.7269.exe E:\Meus Documentos\Downloads\PCDJ_DEX.rar E:\Meus Documentos\Downloads\redmobile\pcdjredmobile_1.1.7269.exe E:\Meus Documentos\Downloads\redmobile.rar ___________________ :seta: Siga também, por gentileza, as dicas deste tutorial para fazer um escaneamento de seu PC pelo Nod32 Online: Tutorial do antivirus Nod32 Online Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador: C:\Arquivos de programas\Eset\Eset Online Scanner\log.txt Na sua próxima resposta poste este log do Nod32 Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir este procedimento. Ficamos no aguardo de sua resposta. -------------------------------------------------------------------------------------------------------------------------------------------------- Olá novamente Antônio, segue adiante o resultado dos procedimentos. Um grande abraço!!! -------------------------------------------------------------------------------------------------------------------------------------------------- http://virscan.org/report/fb5f5dcd9c7da5eaf6b4b37950177a88.html (setupneromobile.exe) http://virscan.org/report/cca6a807e85b426dd66f97f73ed95363.html (atubecather.exe) http://virscan.org/report/26406ac841c2b5bcdb8dc0c9697a5b51.html (dexpot) http://virscan.org/report/682928965261c40de95c85f7e029606a.html (PCDJDex) http://virscan.org/report/2999af15bf0a26de04ae1edab1feba2b.html (PCDJ.rar) http://virscan.org/report/8c3c42ea3ef4b56f6b6ac18491799d85.html (PCDJ.Redmobile) http://virscan.org/report/ab2bb0ee30c2d4fd617e0221cfbcb9e6.html (redmobile.rar) -------------------------------------------------------------------------------------------------------------------------------------------------- ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=107904083ebf98498ec9947942649315 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-01-21 04:22:03 # local_time=2011-01-21 01:22:03 (-0300, Hora oficial do Brasil) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=768 16777215 100 0 10744076 10744076 0 0 # compatibility_mode=1797 16775141 100 93 0 31177610 0 0 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=7937 16777213 100 100 0 4001305 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=61913 # found=1 # cleaned=1 # scan_time=3070 E:\Meus Documentos\Downloads\Programs\Real Desktop - Setup.exe a variant of Win32/TrojanDownloader.Agent.QIY trojan (deleted - quarantined) 00000000000000000000000000000000 C -------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 01:42:49, on 21/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\Internet Download Manager\IDMan.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Dexpot\dexpot.exe C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file) O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -------------------------------------------------------------------------------------------------------------------------------------------------- :) Vários outros problemas foram removidos. _____________________ :seta: Favor enviar o arquivo: C:\UsbFix_Upload_Me_MIGUEL.zip para o endereço abaixo para que o Usbfix possa ser aperfeiçoado: http://www.teamxscript.org/Upload.php A equipe desenvolvedora do Usbfix agradece pela sua contribuição. _____________________ :seta: Acesse o site http://virscan.org/ e envie estes arquivos destacados em vermelho abaixo para serem analisados (um de cada vez) e assim que análise de cada um deles for concluida copie o endereço (link) que aparecerá na barra de endereços de seu navegador e poste estes links com o resultado das análises em sua próxima resposta juntamente com os outros logs pedidos abaixo: C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe E:\Meus Documentos\Downloads\aTube_Catcher.exe E:\Meus Documentos\Downloads\dexpot_156_r1351.exe E:\Meus Documentos\Downloads\PCDJ_DEX\setup_dex_1.1.7269.exe E:\Meus Documentos\Downloads\PCDJ_DEX.rar E:\Meus Documentos\Downloads\redmobile\pcdjredmobile_1.1.7269.exe E:\Meus Documentos\Downloads\redmobile.rar ___________________ :seta: Siga também, por gentileza, as dicas deste tutorial para fazer um escaneamento de seu PC pelo Nod32 Online: Tutorial do antivirus Nod32 Online Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador: C:\Arquivos de programas\Eset\Eset Online Scanner\log.txt Na sua próxima resposta poste este log do Nod32 Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir este procedimento. Ficamos no aguardo de sua resposta. -------------------------------------------------------------------------------------------------------------------------------------------------- Olá novamente Antônio, segue adiante o resultado dos procedimentos. Um grande abraço!!! -------------------------------------------------------------------------------------------------------------------------------------------------- http://virscan.org/report/fb5f5dcd9c7da5eaf6b4b37950177a88.html (setupneromobile.exe) http://virscan.org/report/cca6a807e85b426dd66f97f73ed95363.html (atubecather.exe) http://virscan.org/report/26406ac841c2b5bcdb8dc0c9697a5b51.html (dexpot) http://virscan.org/report/682928965261c40de95c85f7e029606a.html (PCDJDex) http://virscan.org/report/2999af15bf0a26de04ae1edab1feba2b.html (PCDJ.rar) http://virscan.org/report/8c3c42ea3ef4b56f6b6ac18491799d85.html (PCDJ.Redmobile) http://virscan.org/report/ab2bb0ee30c2d4fd617e0221cfbcb9e6.html (redmobile.rar) -------------------------------------------------------------------------------------------------------------------------------------------------- ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=107904083ebf98498ec9947942649315 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-01-21 04:22:03 # local_time=2011-01-21 01:22:03 (-0300, Hora oficial do Brasil) # country="Brazil" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=768 16777215 100 0 10744076 10744076 0 0 # compatibility_mode=1797 16775141 100 93 0 31177610 0 0 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=7937 16777213 100 100 0 4001305 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=61913 # found=1 # cleaned=1 # scan_time=3070 E:\Meus Documentos\Downloads\Programs\Real Desktop - Setup.exe a variant of Win32/TrojanDownloader.Agent.QIY trojan (deleted - quarantined) 00000000000000000000000000000000 C -------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 01:42:49, on 21/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\Internet Download Manager\IDMan.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Dexpot\dexpot.exe C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file) O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -------------------------------------------------------------------------------------------------------------------------------------------------- Antônio, estou enviando tbm um Log do Spyware Terminator, caso tenha tempo e repute necessário, por favor, analise-o para mim. Grato!!! ................... Logfile of Spyware Terminator v2.8.2.192 (db:5.001.020.000) Scan Time: 21/1/2011 01:58:36 length: 273 s Platform: WXP (5.1.0.2600) User: Admin Boot Mode: Normal Scan type: Fast_Spyware_Scan Scanned Objects: 41186 (Critical:0) Filter: No System items, No Safe items, No Invalid items Running Processes TuneUpUtilitiesService32.exe [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe TuneUpUtilitiesApp32.exe [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe sm56hlpr.exe [Motorola Inc.] : C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe HPWuSchd2.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe GoogleUpdate.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe NMIndexingService.exe [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe NMIndexStoreSvr.exe [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe hpqtra08.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe IEMonitor.exe [Tonec Inc.] : C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe hpqSTE08.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe dexpot.exe [Dexpot GbR] : C:\Arquivos de programas\Dexpot\dexpot.exe msnmsgr.exe [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe wlcomm.exe [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe Internet Settings R - HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://fr.msn.com/ R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain = R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName = BHO 02 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - [RealPlayer] : C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll StartUps 04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Google Update : [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe 04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, msnmsgr : [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe 04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NeroFilterCheck : [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe 04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMSERIAL : [Motorola Inc.] : C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe 04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HP Software Update : [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe 04 - Startup: %STARTUPALL%\HP Digital Imaging Monitor.lnk [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe Shell Extensions RealOne Player Context Menu Class - {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - [RealNetworks, Inc.] : C:\Arquivos de programas\Real\RealPlayer\rpshell.dll TuneUp Theme Extension - {44440D00-FF19-4AFC-B765-9A0970567D97} - [TuneUp Software] : C:\WINDOWS\system32\uxtuneup.dll TuneUp Shredder Shell Extension - {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\SDShelEx-win32.dll TuneUp Disk Space Explorer Shell Extension - {4838CD50-7E5D-4811-9B17-C47A85539F28} - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\DseShExt-x86.dll Protocol Handler - {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll - {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll Services 23 - [bison Electronics. Inc.] : C:\WINDOWS\system32\Drivers\BisonC07.sys 23 - [Realtek Semiconductor Corp.] : C:\WINDOWS\system32\drivers\RtkHDAud.sys 23 - [JMicron Technology Corporation] : C:\WINDOWS\system32\DRIVERS\jmcr.sys 23 - [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe 23 - [Realtek Semiconductor Corporation] : C:\WINDOWS\system32\DRIVERS\RTL8187B.sys 23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\sisgrp.sys 23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\SISAGPX.sys 23 - [silicon Integrated Systems Corp.] : C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys 23 - [silicon Integrated Systems Corp.] : C:\WINDOWS\system32\DRIVERS\siside.sys 23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\srvkp.sys 23 - [Motorola Inc.] : C:\WINDOWS\system32\DRIVERS\smserial.sys 23 - [Crawler.com] : C:\WINDOWS\system32\drivers\sp_rsdrv2.sys 23 - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe 23 - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys Threat Files <Tracking Flash Shared Objects> : C:\Documents and Settings\Usuario\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\ENXNCN9X\core.mochibot.com\com.mochibot.sol Advanced Files Report %SYSDIR%\idmmbc.dll [Tonec Inc.] [internet Download Manager LSP dll] MD5=4FB32F1DE01FFA2D3FDE897AF26EA527 SIZE=210272 %SYSDIR%\uxtuneup.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=B5C3BFDA09352789414DCA2066C0ED58 SIZE=29504 %SYSDIR%\hpz3l5ha.dll [Hewlett-Packard Company] [Language Monitor] MD5=9558DAA1DB859250A677CCE97B048151 SIZE=118272 %SYSDIR%\spool\PRTPROCS\W32X86\hpzpp5ha.dll [Hewlett-Packard Corporation] [HP Print Processor] MD5=D0E39177C896D2F8191A9C96636276DF SIZE=274944 %PROGRAMFILES%\hp\digital imaging\bin\hpqddsvc.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=3EE4A63539EC04EE2D4BD293985087AB SIZE=131072 %PROGRAMFILES%\hp\digital imaging\bin\hpqddcmn.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=5B973EA48E154C83ADF42D0A0F57BB29 SIZE=184320 %PROGRAMFILES%\hp\digital imaging\bin\hpqcxs08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=38D6B51F04DEF7FB248FA56E4C47407E SIZE=217088 %PROGRAMFILES%\HP\Digital Imaging\bin\hpocxi08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0642843485D687CB2BA37F007ECC92E4 SIZE=442368 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqcob08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=6D15B5F97EB3332D4BBE19B6FFD512F2 SIZE=135168 %PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [TuneUp Software] [TuneUp Utilities 2011] MD5=6D6B644FD1C874480BB664DE7A30C304 SIZE=1483072 %PROGRAMFILES%\Internet Download Manager\idmmkb.dll [Tonec Inc.] [internet Download Manager] MD5=11C64B3E86F4C691C02092302AF38410 SIZE=34224 %COMMONFILES%\Adobe\Acrobat\ActiveX\PDFShell.PTB [Adobe Systems, Inc.] [Adobe PDF Shell Extension] MD5=B242AFF9B81DDBC6501296D90350FB37 SIZE=311296 %PROGRAMFILES%\Dexpot\hooxpot.dll [Dexpot GbR] [Dexpot] MD5=F651BC45DD1774A3E15126FA59500959 SIZE=45568 %PROGRAMFILES%\TuneUp Utilities 2011\SDShelEx-win32.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=5A9B57BA81ECFFCA62190786494B30C3 SIZE=29504 %COMMONFILES%\Ahead\Lib\AdvrCntr2.dll [Nero AG] [AdvrCntr Module] MD5=54D3D6904ACE021D2B761FB8248BDBAE SIZE=3073320 %PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe [TuneUp Software] [TuneUp Utilities 2011] MD5=965DB099D1A5C4E4B90BA086241DA1A9 SIZE=645952 %PROGRAMFILES%\Motorola\SMSERIAL\sm56eng.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=EC94D60C1C0778ABA382A077B5DF3B32 SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56fra.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=81EBA7ECEB8F3A5C2092615B379F021D SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56brz.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=2ADC4557FABBBE2D4547EA14F634B755 SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56chs.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=36CA10B8CB23AF849A11BA45CB3DE775 SIZE=65536 %PROGRAMFILES%\Motorola\SMSERIAL\sm56cht.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=32680786954F426C193C37BD5D65A7B8 SIZE=65536 %PROGRAMFILES%\Motorola\SMSERIAL\sm56ger.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=8A3947808D6088B8F67FC74E2FA13C54 SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56ita.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=948C03C102ED14FFCF28005FAE0CC701 SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56jpn.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=6BC2A57629C1AFA03B5F648349E6507D SIZE=69632 %PROGRAMFILES%\Motorola\SMSERIAL\sm56esp.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=FA0711174D3936225DBB170EC3FC9D9D SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56kor.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=A2B45C9A19908D6D541CF2755617409E SIZE=65536 %PROGRAMFILES%\Motorola\SMSERIAL\sm56dnk.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=48813EDD60F93C6ABB1B73793C0B0D3F SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56ara.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=4D87D615152D8D08F976674C3F719B8A SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56cro.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=559345B1AA1BFE7DFC7DFDB29A90A71D SIZE=86016 %PROGRAMFILES%\Motorola\SMSERIAL\sm56pol.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=DDB8B6F73C0C36B239653A8051225C9F SIZE=86016 %PROGRAMFILES%\Motorola\SMSERIAL\sm56rus.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=A36E84F7A352DD754987238F5362A076 SIZE=86016 %PROGRAMFILES%\Motorola\SMSERIAL\sm56nor.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=BB6284F22EE739A005013403D987E564 SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56cze.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=4CEFF3DD5EB75ABDACFCD670BBCC5F7C SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56dan.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=03636ED3870B5FC9E0AD8075E6DBD5F1 SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56fin.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=428EB23FF701676D0F8542BDF290AE30 SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56gre.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=EEF1AE7B7B9647B03CEA608CDC25E4C6 SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56swe.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=BDE6D6D377CD056480125859D471266B SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56tur.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=B3E20973B15C25DCDDCADA0C37D5C140 SIZE=81920 %COMMONFILES%\Ahead\Lib\NMIndexingServicePS.dll [Nero AG] [Nero Home] MD5=49130B95291F0269689AF46A461DB034 SIZE=59176 %COMMONFILES%\Ahead\Lib\NMIndexStoreSvrPS.dll [Nero AG] [Nero Home] MD5=A00F1027925AEDEAC8EDEFC46133F691 SIZE=20776 %COMMONFILES%\Ahead\Lib\NMDataServices.dll [Nero AG] [Nero Home] MD5=A63E5D51FBDB18AFA2EC67CADCB062FD SIZE=2749736 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Update\1.2.183.39\goopdate.dll [Google Inc.] [Google Update] MD5=68CA45DAF2A425E9719B3122EDDDB343 SIZE=682648 %COMMONFILES%\Ahead\Lib\NMIndexingService.exe [Nero AG] [Nero Home] MD5=A328A46D87BB92CE4D8A4528E9D84787 SIZE=279848 %COMMONFILES%\Ahead\Lib\NMLogCxx.dll [Nero AG] [Nero Home] MD5=0C01B2C22322C48D8ADAE3B9D467E924 SIZE=70952 %COMMONFILES%\Ahead\Lib\log4cxx.dll [Nero AG] [Nero Home] MD5=421B260404162F1F00A9618C3F42315B SIZE=742696 %COMMONFILES%\Ahead\Lib\NMIndexStoreSvr.exe [Nero AG] [Nero Home] MD5=FFBD5650348D4F9E0AA8E72938DC6478 SIZE=1213736 %COMMONFILES%\Ahead\Lib\NMSQLDB.dll [Nero AG] [Nero Home] MD5=B8E87E8DA00838B208801B57B86AC5E4 SIZE=320808 %COMMONFILES%\Ahead\Lib\NMCoFoundation.dll [Nero AG] [Nero Home] MD5=0366D598F2C36B7C08B848B2BD5E11D3 SIZE=541992 %COMMONFILES%\Ahead\Lib\NMPluginBase.dll [Nero AG] [Nero Home] MD5=65261A7F650F4C7E56D874FD4A5F2BDA SIZE=107816 %COMMONFILES%\Ahead\Lib\NMFullTextExtraction.dll [Nero AG] [Nero Home] MD5=97165BC95B8690A51521EF2AA5B61F0E SIZE=181544 %COMMONFILES%\Ahead\Lib\NMSearchPluginSimilarImages.dll [Nero AG] [Nero Home] MD5=363A7929BF3E0DA91E9FFACCF336777E SIZE=181544 %COMMONFILES%\Ahead\Lib\NeroIPP.dll [Nero AG] [Nero Suite] MD5=94BB4635AE6CA64356B2D0E60EFD6038 SIZE=3376424 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqtra08.exe [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=F14219FC767F1383526AB423F278A8E3 SIZE=210520 %PROGRAMFILES%\HP\Digital Imaging\bin\hpquio08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=9507A8E70A620A36CF2CF60740B8F022 SIZE=151552 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqtra08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=2B57FA15C56154BE2F728EE485720F2E SIZE=47104 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqtao08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=021CFC69A1874431DC88BEFC37A2A2FD SIZE=98304 %PROGRAMFILES%\HP\Digital Imaging\bin\hpotra08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=23D3BFA480C5DA9256DD9A97185678C4 SIZE=323584 %PROGRAMFILES%\HP\Digital Imaging\bin\hpotra08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0EEF3AA9B7B567464C3010875A2F5A92 SIZE=12800 %PROGRAMFILES%\HP\Digital Imaging\bin\hpotradd.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=7DAFE566BB13C16439CBAADB43582128 SIZE=77824 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqrif08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=A6E02F65BE0C48DE7101923AE70268BD SIZE=290816 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqmif08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=D0716BD0C0822A642D36E82F49F2B5B8 SIZE=299008 %PROGRAMFILES%\HP\Digital Imaging\bin\hpodio08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=8861AB06F667429B94DBFE97550F82D5 SIZE=1007616 %SYSDIR%\hpzipr12.dll [Hewlett-Packard] [bidi User Mode] MD5=AF880166DAC5880219F748ED83902CB2 SIZE=33280 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqddusr.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=1AE183708EC0CA7E8CECF98B9785D57C SIZE=61440 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqusg.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=5B6748DFA56A0BE54C45B989378293E1 SIZE=401408 %SYSDIR%\hpzidr12.dll [Hewlett-Packard] [bidi User Mode] MD5=26AE2CA34FA4342749EC1157CB1FE954 SIZE=49152 %PROGRAMFILES%\Internet Download Manager\IEMonitor.exe [Tonec Inc.] [iEMonitor Application] MD5=207B16FA69F61D1895F8D8532F587E4B SIZE=263600 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqSTE08.exe [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=FEDDD3579FEE51A9873D856DF3933C68 SIZE=151552 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqwso08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=1D0A76276AD7A836F29F447968C61CE6 SIZE=516096 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqsti08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0A0A339D07FF5E9989EEF1E1D476CD29 SIZE=249856 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqstp08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=7C4DCFF108869D7915D39B9371BE5FFE SIZE=217088 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqstp08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=860B5D266F74CED0ED86C4D118016C7F SIZE=11776 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqsem08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=8AB4E23C6FB10F8FE35AA9F624A8D4E3 SIZE=655360 %PROGRAMFILES%\Dexpot\dexpot.exe [Dexpot GbR] [Dexpot] MD5=AC22FEBC423BF6E596282E9C25102D86 SIZE=1273856 %PROGRAMFILES%\Dexpot\Dexpot.dll [Dexpot GbR] [Dexpot] MD5=F3C39C6331463AA2A13D7C19C9EA6754 SIZE=63488 %SYSDIR%\hpzipm12.dll [Hewlett-Packard] [bidi User Mode] MD5=79834AA2FBF9FE81EEBB229024F6F7FC SIZE=53248 %PROGRAMFILES%\Windows Live\Contacts\wlcomm.exe [Microsoft Corporation] [Windows Live Communications Platform] MD5=654480EA67078C7B4C6C8BA871B07D5D SIZE=27512 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe [Google Inc.] [Google Chrome] MD5=4BFE28145799174386393B1E09764ED4 SIZE=991800 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\chrome.dll [Google Inc.] [Google Chrome] MD5=E00A403F4D5560799925809C5968A29E SIZE=22112312 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\icudt42.dll [iBM Corporation and others] [international Components for Unicode] MD5=AF7B02DA57568DB12CD97892A1E21279 SIZE=11046456 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\locales\pt-BR.dll MD5=F8FB352012C84DC1A0D1083C69C2B928 SIZE=235576 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\gears.dll [Google Inc.] [Google Gears 0.5.33.0] MD5=837173438BB8B1774FB9C39F75D9380D SIZE=3184184 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\pdf.dll [Chrome PDF Viewer] MD5=51C3DC3713CC321BB33631DC77B4BEA2 SIZE=4049976 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avcodec-52.dll MD5=EC1B9BCDDC37F828B91E2F52801E6512 SIZE=1475128 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avutil-50.dll MD5=D039B0D6E1F707E19CB8A8B22944002C SIZE=99896 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avformat-52.dll MD5=282E6252AD1F4B5AB13CCA8D349B5DEA SIZE=197688 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.63_0\npqslauncher.dll [bitDefender LLC] [bitDefender QuickScan] MD5=7528FCCE4AFC2A309EA33DDC2509C2AD SIZE=49056 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\gcswf32.dll [Adobe Systems, Inc.] [shockwave Flash] MD5=F02C4AAA6AC913FAAB0EAA74EAD94D9A SIZE=6021120 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\libglesv2.dll MD5=F2C24BF4C77E8719D3D20159957DEFCD SIZE=462904 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\libegl.dll MD5=762B6BB323A3A2E5133A427686C9CC1C SIZE=123960 deskpan.dll %PROGRAMFILES%\Real\RealPlayer\rpshell.dll [RealNetworks, Inc.] [RealPlayer] MD5=0740ABDF0265BA0260D52FE88DCB9067 SIZE=63016 %PROGRAMFILES%\TuneUp Utilities 2011\DseShExt-x86.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=7643655C6BA19B57D863684F5DFCA19B SIZE=25920 %SYSDIR%\svchost.exe -k netsvcs %SYSDIR%\Drivers\BisonC07.sys [bison Electronics. Inc.] [bisonCam UVC, USB 2.0 Camera] MD5=BB04CB2F027D8DE7D3BDAEA147A706CB SIZE=974248 %SYSDIR%\svchost -k DcomLaunch %SYSDIR%\svchost.exe -k NetworkService %SYSDIR%\svchost.exe -k hpdevmgmt %SYSDIR%\svchost.exe -k HTTPFilter %SYSDIR%\drivers\RtkHDAud.sys [Realtek Semiconductor Corp.] [Realtek® High Definition Audio Function Driver (HRTF data Copyright 1994 by MIT Media Lab)] MD5=3FA02C6E3E9EBE8523A2D4E51D0ECE1F SIZE=5891584 %SYSDIR%\DRIVERS\jmcr.sys [JMicron Technology Corporation] [JMB38X Flash Media Controller Driver] MD5=9EFE54794B3A94E93DA50703692E011E SIZE=113504 %SYSDIR%\svchost.exe -k LocalService %SYSDIR%\svchost.exe -k HPZ12 %SYSDIR%\svchost -k rpcss %SYSDIR%\DRIVERS\RTL8187B.sys [Realtek Semiconductor Corporation] [Realtek RTL8187B Wireless USB 2.0 Adapter] MD5=2E2E3A2D1BA5E540C32558F3F37D33E3 SIZE=335104 %SYSDIR%\DRIVERS\sisgrp.sys [silicon Integrated Systems Corporation] [siS ® Compatible Super VGA Miniport Driver for Windows XP] MD5=4FABFAB9231F7E7C833677377CF013B8 SIZE=323584 %SYSDIR%\DRIVERS\SISAGPX.sys [silicon Integrated Systems Corporation] [siS AGPv3.5 Filter for Windows XP] MD5=F8150C74FF24BDBD19F47A6DFD05514A SIZE=35712 %SYSDIR%\DRIVERS\SiSGbeXP.sys [silicon Integrated Systems Corp.] [siS191/190 Ethernet Device] MD5=A86E52C55DE3488B3FC0FF2B8AD711BF SIZE=43392 %SYSDIR%\DRIVERS\siside.sys [silicon Integrated Systems Corp.] [siS PCI Mini IDE Driver] MD5=B4485881BD8AED9B157A2E6CF43C2D51 SIZE=4096 %SYSDIR%\DRIVERS\srvkp.sys [silicon Integrated Systems Corporation] [siS ® WindowsXP Display Manager] MD5=82387BF8F5A35358118B2129FF91C890 SIZE=19072 %SYSDIR%\DRIVERS\smserial.sys [Motorola Inc.] [Motorola SM56 Modem] MD5=BDFD18C04466EDBF78FF663B7CDE08AE SIZE=1092608 %SYSDIR%\drivers\sp_rsdrv2.sys [Crawler.com] [spyware Terminator] MD5=8831252BCF05FCFB5ABD116A22E552D8 SIZE=142592 %SYSDIR%\svchost.exe -k imgsvc %PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [TuneUp Software] [TuneUp Utilities] MD5=F2107C9D85EC0DF116939CCCE06AE697 SIZE=10064 %SYSDIR%\svchost.exe -k WudfServiceGroup %PROGRAMFILES%\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [Microsoft Corporation] [Windows Live Messenger Protocol Handler Module] MD5=61B0C981F7C10B8861809ADC1B31E8E5 SIZE=61264 End of Report Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Janeiro 21, 2011 :) Mais um problema foi removido pelo Nod32 Online. ___________________ Antônio, estou enviando tbm um Log do Spyware Terminator :seta: Faça uma atualização (update) do Spyware Terminator > faça uma verificação completa com ele e remova os problemas que ele encontrar > depois nos diga se algum virus ou spyware foi removido por ele. ____________________ :seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked: O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file) O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) _______________________ :seta: Siga também esta dica: Tutorial do Dr. Web CureIt Na sua próxima resposta poste este log do Dr. Web CureIt juntamente com um novo log do Hijackthis e nos diga se alguns problemas foram removidos pelo Spyware Terminator e nos diga como está o seu Pc depois disto. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
mig.bel 0 Denunciar post Postado Janeiro 23, 2011 :) Mais um problema foi removido pelo Nod32 Online. ___________________ Antônio, estou enviando tbm um Log do Spyware Terminator :seta: Faça uma atualização (update) do Spyware Terminator > faça uma verificação completa com ele e remova os problemas que ele encontrar > depois nos diga se algum virus ou spyware foi removido por ele. ____________________ :seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked: O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file) O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) _______________________ :seta: Siga também esta dica: Tutorial do Dr. Web CureIt Na sua próxima resposta poste este log do Dr. Web CureIt juntamente com um novo log do Hijackthis e nos diga se alguns problemas foram removidos pelo Spyware Terminator e nos diga como está o seu Pc depois disto. Ficamos no aguardo. -------------------------------------------------------------------------------------------------------------------------------------------------- Segue abaixo os procedimentos solicitados. . Abçs -------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of Spyware Terminator v2.8.2.192 (db:5.001.021.000) Scan Time: 21/1/2011 09:20:18 length: 339 s Platform: WXP (5.1.0.2600) User: Admin Boot Mode: Normal Scan type: Fast_Spyware_Scan Scanned Objects: 41207 (Critical:0) Filter: No System items, No Safe items, No Invalid items Running Processes TuneUpUtilitiesService32.exe [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe TuneUpUtilitiesApp32.exe [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe sm56hlpr.exe [Motorola Inc.] : C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe HPWuSchd2.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe GoogleUpdate.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe NMIndexingService.exe [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe NMIndexStoreSvr.exe [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe msnmsgr.exe [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe IEMonitor.exe [Tonec Inc.] : C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe hpqtra08.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe hpqSTE08.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe Internet Settings R - HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://fr.msn.com/ R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain = R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName = BHO 02 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - [RealPlayer] : C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll StartUps 04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Google Update : [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe 04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, msnmsgr : [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe 04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NeroFilterCheck : [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe 04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMSERIAL : [Motorola Inc.] : C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe 04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HP Software Update : [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe 04 - Startup: %STARTUPALL%\HP Digital Imaging Monitor.lnk [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe Shell Extensions RealOne Player Context Menu Class - {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - [RealNetworks, Inc.] : C:\Arquivos de programas\Real\RealPlayer\rpshell.dll TuneUp Theme Extension - {44440D00-FF19-4AFC-B765-9A0970567D97} - [TuneUp Software] : C:\WINDOWS\system32\uxtuneup.dll TuneUp Shredder Shell Extension - {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\SDShelEx-win32.dll TuneUp Disk Space Explorer Shell Extension - {4838CD50-7E5D-4811-9B17-C47A85539F28} - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\DseShExt-x86.dll Protocol Handler - {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll - {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll Services 23 - [bison Electronics. Inc.] : C:\WINDOWS\system32\Drivers\BisonC07.sys 23 - [Realtek Semiconductor Corp.] : C:\WINDOWS\system32\drivers\RtkHDAud.sys 23 - [JMicron Technology Corporation] : C:\WINDOWS\system32\DRIVERS\jmcr.sys 23 - [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe 23 - [Realtek Semiconductor Corporation] : C:\WINDOWS\system32\DRIVERS\RTL8187B.sys 23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\sisgrp.sys 23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\SISAGPX.sys 23 - [silicon Integrated Systems Corp.] : C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys 23 - [silicon Integrated Systems Corp.] : C:\WINDOWS\system32\DRIVERS\siside.sys 23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\srvkp.sys 23 - [Motorola Inc.] : C:\WINDOWS\system32\DRIVERS\smserial.sys 23 - [Crawler.com] : C:\WINDOWS\system32\drivers\sp_rsdrv2.sys 23 - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe 23 - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys Threat Files <Tracking Flash Shared Objects> : C:\Documents and Settings\Usuario\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\ENXNCN9X\core.mochibot.com\com.mochibot.sol Advanced Files Report %SYSDIR%\idmmbc.dll [Tonec Inc.] [internet Download Manager LSP dll] MD5=4FB32F1DE01FFA2D3FDE897AF26EA527 SIZE=210272 %SYSDIR%\uxtuneup.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=B5C3BFDA09352789414DCA2066C0ED58 SIZE=29504 %SYSDIR%\hpz3l5ha.dll [Hewlett-Packard Company] [Language Monitor] MD5=9558DAA1DB859250A677CCE97B048151 SIZE=118272 %SYSDIR%\spool\PRTPROCS\W32X86\hpzpp5ha.dll [Hewlett-Packard Corporation] [HP Print Processor] MD5=D0E39177C896D2F8191A9C96636276DF SIZE=274944 %PROGRAMFILES%\hp\digital imaging\bin\hpqddsvc.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=3EE4A63539EC04EE2D4BD293985087AB SIZE=131072 %PROGRAMFILES%\hp\digital imaging\bin\hpqddcmn.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=5B973EA48E154C83ADF42D0A0F57BB29 SIZE=184320 %PROGRAMFILES%\hp\digital imaging\bin\hpqcxs08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=38D6B51F04DEF7FB248FA56E4C47407E SIZE=217088 %PROGRAMFILES%\HP\Digital Imaging\bin\hpocxi08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0642843485D687CB2BA37F007ECC92E4 SIZE=442368 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqcob08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=6D15B5F97EB3332D4BBE19B6FFD512F2 SIZE=135168 %PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [TuneUp Software] [TuneUp Utilities 2011] MD5=6D6B644FD1C874480BB664DE7A30C304 SIZE=1483072 %PROGRAMFILES%\Internet Download Manager\idmmkb.dll [Tonec Inc.] [internet Download Manager] MD5=11C64B3E86F4C691C02092302AF38410 SIZE=34224 %COMMONFILES%\Adobe\Acrobat\ActiveX\PDFShell.PTB [Adobe Systems, Inc.] [Adobe PDF Shell Extension] MD5=B242AFF9B81DDBC6501296D90350FB37 SIZE=311296 %ALLUSERS_APPDATA%\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll MD5=13F611AD51310D4A6EF0D87D7D4E8EA5 SIZE=40960 %PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe [TuneUp Software] [TuneUp Utilities 2011] MD5=965DB099D1A5C4E4B90BA086241DA1A9 SIZE=645952 %PROGRAMFILES%\Motorola\SMSERIAL\sm56eng.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=EC94D60C1C0778ABA382A077B5DF3B32 SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56fra.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=81EBA7ECEB8F3A5C2092615B379F021D SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56brz.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=2ADC4557FABBBE2D4547EA14F634B755 SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56chs.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=36CA10B8CB23AF849A11BA45CB3DE775 SIZE=65536 %PROGRAMFILES%\Motorola\SMSERIAL\sm56cht.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=32680786954F426C193C37BD5D65A7B8 SIZE=65536 %PROGRAMFILES%\Motorola\SMSERIAL\sm56ger.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=8A3947808D6088B8F67FC74E2FA13C54 SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56ita.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=948C03C102ED14FFCF28005FAE0CC701 SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56jpn.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=6BC2A57629C1AFA03B5F648349E6507D SIZE=69632 %PROGRAMFILES%\Motorola\SMSERIAL\sm56esp.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=FA0711174D3936225DBB170EC3FC9D9D SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56kor.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=A2B45C9A19908D6D541CF2755617409E SIZE=65536 %PROGRAMFILES%\Motorola\SMSERIAL\sm56dnk.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=48813EDD60F93C6ABB1B73793C0B0D3F SIZE=77824 %PROGRAMFILES%\Motorola\SMSERIAL\sm56ara.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=4D87D615152D8D08F976674C3F719B8A SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56cro.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=559345B1AA1BFE7DFC7DFDB29A90A71D SIZE=86016 %PROGRAMFILES%\Motorola\SMSERIAL\sm56pol.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=DDB8B6F73C0C36B239653A8051225C9F SIZE=86016 %PROGRAMFILES%\Motorola\SMSERIAL\sm56rus.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=A36E84F7A352DD754987238F5362A076 SIZE=86016 %PROGRAMFILES%\Motorola\SMSERIAL\sm56nor.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=BB6284F22EE739A005013403D987E564 SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56cze.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=4CEFF3DD5EB75ABDACFCD670BBCC5F7C SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56dan.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=03636ED3870B5FC9E0AD8075E6DBD5F1 SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56fin.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=428EB23FF701676D0F8542BDF290AE30 SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56gre.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=EEF1AE7B7B9647B03CEA608CDC25E4C6 SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56swe.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=BDE6D6D377CD056480125859D471266B SIZE=81920 %PROGRAMFILES%\Motorola\SMSERIAL\sm56tur.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=B3E20973B15C25DCDDCADA0C37D5C140 SIZE=81920 %COMMONFILES%\Ahead\Lib\AdvrCntr2.dll [Nero AG] [AdvrCntr Module] MD5=54D3D6904ACE021D2B761FB8248BDBAE SIZE=3073320 %COMMONFILES%\Ahead\Lib\NMIndexingServicePS.dll [Nero AG] [Nero Home] MD5=49130B95291F0269689AF46A461DB034 SIZE=59176 %COMMONFILES%\Ahead\Lib\NMIndexStoreSvrPS.dll [Nero AG] [Nero Home] MD5=A00F1027925AEDEAC8EDEFC46133F691 SIZE=20776 %COMMONFILES%\Ahead\Lib\NMDataServices.dll [Nero AG] [Nero Home] MD5=A63E5D51FBDB18AFA2EC67CADCB062FD SIZE=2749736 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Update\1.2.183.39\goopdate.dll [Google Inc.] [Google Update] MD5=68CA45DAF2A425E9719B3122EDDDB343 SIZE=682648 %COMMONFILES%\Ahead\Lib\NMIndexingService.exe [Nero AG] [Nero Home] MD5=A328A46D87BB92CE4D8A4528E9D84787 SIZE=279848 %COMMONFILES%\Ahead\Lib\NMLogCxx.dll [Nero AG] [Nero Home] MD5=0C01B2C22322C48D8ADAE3B9D467E924 SIZE=70952 %COMMONFILES%\Ahead\Lib\log4cxx.dll [Nero AG] [Nero Home] MD5=421B260404162F1F00A9618C3F42315B SIZE=742696 %COMMONFILES%\Ahead\Lib\NMIndexStoreSvr.exe [Nero AG] [Nero Home] MD5=FFBD5650348D4F9E0AA8E72938DC6478 SIZE=1213736 %COMMONFILES%\Ahead\Lib\NMSQLDB.dll [Nero AG] [Nero Home] MD5=B8E87E8DA00838B208801B57B86AC5E4 SIZE=320808 %COMMONFILES%\Ahead\Lib\NMCoFoundation.dll [Nero AG] [Nero Home] MD5=0366D598F2C36B7C08B848B2BD5E11D3 SIZE=541992 %COMMONFILES%\Ahead\Lib\NMPluginBase.dll [Nero AG] [Nero Home] MD5=65261A7F650F4C7E56D874FD4A5F2BDA SIZE=107816 %COMMONFILES%\Ahead\Lib\NMFullTextExtraction.dll [Nero AG] [Nero Home] MD5=97165BC95B8690A51521EF2AA5B61F0E SIZE=181544 %COMMONFILES%\Ahead\Lib\NMSearchPluginSimilarImages.dll [Nero AG] [Nero Home] MD5=363A7929BF3E0DA91E9FFACCF336777E SIZE=181544 %COMMONFILES%\Ahead\Lib\NeroIPP.dll [Nero AG] [Nero Suite] MD5=94BB4635AE6CA64356B2D0E60EFD6038 SIZE=3376424 %PROGRAMFILES%\Internet Download Manager\IEMonitor.exe [Tonec Inc.] [iEMonitor Application] MD5=207B16FA69F61D1895F8D8532F587E4B SIZE=263600 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqtra08.exe [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=F14219FC767F1383526AB423F278A8E3 SIZE=210520 %PROGRAMFILES%\HP\Digital Imaging\bin\hpquio08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=9507A8E70A620A36CF2CF60740B8F022 SIZE=151552 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqtra08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=2B57FA15C56154BE2F728EE485720F2E SIZE=47104 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqtao08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=021CFC69A1874431DC88BEFC37A2A2FD SIZE=98304 %PROGRAMFILES%\HP\Digital Imaging\bin\hpotra08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=23D3BFA480C5DA9256DD9A97185678C4 SIZE=323584 %PROGRAMFILES%\HP\Digital Imaging\bin\hpotra08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0EEF3AA9B7B567464C3010875A2F5A92 SIZE=12800 %PROGRAMFILES%\HP\Digital Imaging\bin\hpotradd.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=7DAFE566BB13C16439CBAADB43582128 SIZE=77824 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqrif08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=A6E02F65BE0C48DE7101923AE70268BD SIZE=290816 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqmif08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=D0716BD0C0822A642D36E82F49F2B5B8 SIZE=299008 %PROGRAMFILES%\HP\Digital Imaging\bin\hpodio08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=8861AB06F667429B94DBFE97550F82D5 SIZE=1007616 %SYSDIR%\hpzipr12.dll [Hewlett-Packard] [bidi User Mode] MD5=AF880166DAC5880219F748ED83902CB2 SIZE=33280 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqddusr.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=1AE183708EC0CA7E8CECF98B9785D57C SIZE=61440 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqusg.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=5B6748DFA56A0BE54C45B989378293E1 SIZE=401408 %SYSDIR%\hpzidr12.dll [Hewlett-Packard] [bidi User Mode] MD5=26AE2CA34FA4342749EC1157CB1FE954 SIZE=49152 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqSTE08.exe [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=FEDDD3579FEE51A9873D856DF3933C68 SIZE=151552 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqwso08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=1D0A76276AD7A836F29F447968C61CE6 SIZE=516096 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqsti08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0A0A339D07FF5E9989EEF1E1D476CD29 SIZE=249856 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqstp08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=7C4DCFF108869D7915D39B9371BE5FFE SIZE=217088 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqstp08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=860B5D266F74CED0ED86C4D118016C7F SIZE=11776 %PROGRAMFILES%\HP\Digital Imaging\bin\hpqsem08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=8AB4E23C6FB10F8FE35AA9F624A8D4E3 SIZE=655360 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe [Google Inc.] [Google Chrome] MD5=4BFE28145799174386393B1E09764ED4 SIZE=991800 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\chrome.dll [Google Inc.] [Google Chrome] MD5=E00A403F4D5560799925809C5968A29E SIZE=22112312 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\icudt42.dll [iBM Corporation and others] [international Components for Unicode] MD5=AF7B02DA57568DB12CD97892A1E21279 SIZE=11046456 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\locales\pt-BR.dll MD5=F8FB352012C84DC1A0D1083C69C2B928 SIZE=235576 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\gears.dll [Google Inc.] [Google Gears 0.5.33.0] MD5=837173438BB8B1774FB9C39F75D9380D SIZE=3184184 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\pdf.dll [Chrome PDF Viewer] MD5=51C3DC3713CC321BB33631DC77B4BEA2 SIZE=4049976 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avcodec-52.dll MD5=EC1B9BCDDC37F828B91E2F52801E6512 SIZE=1475128 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avutil-50.dll MD5=D039B0D6E1F707E19CB8A8B22944002C SIZE=99896 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avformat-52.dll MD5=282E6252AD1F4B5AB13CCA8D349B5DEA SIZE=197688 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.63_0\npqslauncher.dll [bitDefender LLC] [bitDefender QuickScan] MD5=7528FCCE4AFC2A309EA33DDC2509C2AD SIZE=49056 %SYSDIR%\hpzipm12.dll [Hewlett-Packard] [bidi User Mode] MD5=79834AA2FBF9FE81EEBB229024F6F7FC SIZE=53248 %USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\gcswf32.dll [Adobe Systems, Inc.] [shockwave Flash] MD5=F02C4AAA6AC913FAAB0EAA74EAD94D9A SIZE=6021120 %APPDATA%\IDM\idmmzcc3\components\idmmzcc.dll [Tonec Inc.] [internet Download Manager module] MD5=0EDF32D15BA4B6BEEB9C355B26D468B1 SIZE=271712 %ALLUSERS_APPDATA%\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll MD5=ACE8DDA26B36242F774AC6648ABAAA60 SIZE=49152 %ALLUSERS_APPDATA%\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll [RealPlayer] MD5=B38D56DF1DE9778D3B8184B269ADA873 SIZE=308808 deskpan.dll %PROGRAMFILES%\Real\RealPlayer\rpshell.dll [RealNetworks, Inc.] [RealPlayer] MD5=0740ABDF0265BA0260D52FE88DCB9067 SIZE=63016 %PROGRAMFILES%\TuneUp Utilities 2011\SDShelEx-win32.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=5A9B57BA81ECFFCA62190786494B30C3 SIZE=29504 %PROGRAMFILES%\TuneUp Utilities 2011\DseShExt-x86.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=7643655C6BA19B57D863684F5DFCA19B SIZE=25920 %SYSDIR%\svchost.exe -k netsvcs %SYSDIR%\Drivers\BisonC07.sys [bison Electronics. Inc.] [bisonCam UVC, USB 2.0 Camera] MD5=BB04CB2F027D8DE7D3BDAEA147A706CB SIZE=974248 %SYSDIR%\svchost -k DcomLaunch %SYSDIR%\svchost.exe -k NetworkService %SYSDIR%\svchost.exe -k hpdevmgmt %SYSDIR%\svchost.exe -k HTTPFilter %SYSDIR%\drivers\RtkHDAud.sys [Realtek Semiconductor Corp.] [Realtek® High Definition Audio Function Driver (HRTF data Copyright 1994 by MIT Media Lab)] MD5=3FA02C6E3E9EBE8523A2D4E51D0ECE1F SIZE=5891584 %SYSDIR%\DRIVERS\jmcr.sys [JMicron Technology Corporation] [JMB38X Flash Media Controller Driver] MD5=9EFE54794B3A94E93DA50703692E011E SIZE=113504 %SYSDIR%\svchost.exe -k LocalService %SYSDIR%\svchost.exe -k HPZ12 %SYSDIR%\svchost -k rpcss %SYSDIR%\DRIVERS\RTL8187B.sys [Realtek Semiconductor Corporation] [Realtek RTL8187B Wireless USB 2.0 Adapter] MD5=2E2E3A2D1BA5E540C32558F3F37D33E3 SIZE=335104 %SYSDIR%\DRIVERS\sisgrp.sys [silicon Integrated Systems Corporation] [siS ® Compatible Super VGA Miniport Driver for Windows XP] MD5=4FABFAB9231F7E7C833677377CF013B8 SIZE=323584 %SYSDIR%\DRIVERS\SISAGPX.sys [silicon Integrated Systems Corporation] [siS AGPv3.5 Filter for Windows XP] MD5=F8150C74FF24BDBD19F47A6DFD05514A SIZE=35712 %SYSDIR%\DRIVERS\SiSGbeXP.sys [silicon Integrated Systems Corp.] [siS191/190 Ethernet Device] MD5=A86E52C55DE3488B3FC0FF2B8AD711BF SIZE=43392 %SYSDIR%\DRIVERS\siside.sys [silicon Integrated Systems Corp.] [siS PCI Mini IDE Driver] MD5=B4485881BD8AED9B157A2E6CF43C2D51 SIZE=4096 %SYSDIR%\DRIVERS\srvkp.sys [silicon Integrated Systems Corporation] [siS ® WindowsXP Display Manager] MD5=82387BF8F5A35358118B2129FF91C890 SIZE=19072 %SYSDIR%\DRIVERS\smserial.sys [Motorola Inc.] [Motorola SM56 Modem] MD5=BDFD18C04466EDBF78FF663B7CDE08AE SIZE=1092608 %SYSDIR%\drivers\sp_rsdrv2.sys [Crawler.com] [spyware Terminator] MD5=8831252BCF05FCFB5ABD116A22E552D8 SIZE=142592 %SYSDIR%\svchost.exe -k imgsvc %PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [TuneUp Software] [TuneUp Utilities] MD5=F2107C9D85EC0DF116939CCCE06AE697 SIZE=10064 %SYSDIR%\svchost.exe -k WudfServiceGroup %PROGRAMFILES%\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [Microsoft Corporation] [Windows Live Messenger Protocol Handler Module] MD5=61B0C981F7C10B8861809ADC1B31E8E5 SIZE=61264 End of Report -------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 10:08:04, on 21/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe C:\Arquivos de programas\Internet Download Manager\IDMan.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Barra de ferramentas &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing) O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [spywareTerminator] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Crawler Search - tbr:iemenu O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing) O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 12:38:04, on 23/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\ARQUIV~1\Crawler\CToolbar.exe C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Arquivos de programas\Microsoft Office\Office12\EXCEL.EXE C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Barra de ferramentas &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing) O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Crawler Search - tbr:iemenu O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing) O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -------------------------------------------------------------------------------------------------------------------------------------------------- LOG DO DrWeb 4ef45825.qua\data001 C:\Documents and Settings\All Users\Dados de aplicativos\Avira\AntiVir Desktop\INFECTED\4ef45825.qua Win32.HLLW.Autoruner.6412 4ef45825.qua C:\Documents and Settings\All Users\Dados de aplicativos\Avira\AntiVir Desktop\INFECTED A pasta contem objectos infectados Movido. RegUBP2b-Usuario.reg C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Snapshots2 Trojan.StartPage.1505 Eliminado. A0057005.reg C:\System Volume Information\_restore{2E688FF2-C923-4539-BED5-D6B4329EC271}\RP86 Trojan.StartPage.1505 Eliminado. A0057231.reg C:\System Volume Information\_restore{2E688FF2-C923-4539-BED5-D6B4329EC271}\RP88 Trojan.StartPage.1505 Eliminado. A0057699.reg C:\System Volume Information\_restore{2E688FF2-C923-4539-BED5-D6B4329EC271}\RP90 Trojan.StartPage.1505 Eliminado. RealDesktopBundle.exe\zwankysearch-stub.exe E:\Meus Documentos\Downloads\Programs\Real Desktop - Setup.exe/data002/{tmp}\RealDesktopBundle.exe Adware.Searchlook.5 {tmp}\RealDesktopBundle.exe E:\Meus Documentos\Downloads\Programs\Real Desktop - Setup.exe/data002/{tmp} A pasta contem objectos infectados data002 E:\Meus Documentos\Downloads\Programs A pasta contem objectos infectados Real Desktop - Setup.exe E:\Meus Documentos\Downloads\Programs A pasta contem objectos infectados Movido. Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Janeiro 23, 2011 :) Outros problemas foram removidos pelo Dr. Web CureIt. ______________________ :seta: Você observou se o Spyware Terminator removeu mais alguns virus durante a limpeza que você efetuou com ele? _______________________ :seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked: O3 - Toolbar: Barra de ferramentas &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing) O8 - Extra context menu item: Crawler Search - tbr:iemenu _________________________ :seta: Depois disto siga esta dica: Tutorial do antivírus BitDefender Online Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador: C:\Windows\BDOSCAN8\bdoscan.log Na sua próxima resposta responda a pergunta que te fiz acima e poste o log do BitDefender Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir estes procedimentos. Ficamos no aguardo de sua resposta. Compartilhar este post Link para o post Compartilhar em outros sites
mig.bel 0 Denunciar post Postado Janeiro 25, 2011 :) Outros problemas foram removidos pelo Dr. Web CureIt. ______________________ :seta: Você observou se o Spyware Terminator removeu mais alguns virus durante a limpeza que você efetuou com ele? _______________________ :seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked: O3 - Toolbar: Barra de ferramentas &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing) O8 - Extra context menu item: Crawler Search - tbr:iemenu _________________________ :seta: Depois disto siga esta dica: Tutorial do antivírus BitDefender Online Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador: C:\Windows\BDOSCAN8\bdoscan.log Na sua próxima resposta responda a pergunta que te fiz acima e poste o log do BitDefender Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir estes procedimentos. Ficamos no aguardo de sua resposta. -------------------------------------------------------------------------------------------------------------------------------------------------- Antônio, realizei os escaneamentos necessários, trazendo os resultados abaixo pra tua análise: [/b] Quanto ao Terminator, nada grave foi encontrado. [General] App = "楂䑴晥湥敤湏楬敮匠慣湮牥 v8" Date = 24:01:2011 Time = 13:05:57 Scan Path = C:\;D:\;E:\; [Engines Info] Virus Definitions = 6675230 Engine build = "AVCORE v2.1 Windows/i386 11.0.0.42 (Oct 18 2010)" Scan plugins = 18 Archive plugins = 44 Unpack plugins = 10 E-mail plugins = 6 System plugins = 4 [scan Statistics] Folders = 5640 Files = 190532 Archives = 2689 Packed files = 7027 Identified viruses = 2 Infected files = 2 Warnings = 0 Suspect files = 0 Disinfected files = 0 Deleted files = 2 Copied files = 0 Moved files = 0 Renamed files = 0 I/O Errors = 37 [scan Settings] SecondAction = Delete FirstAction = Disinfect Heuristics = 1 Enable Warnings = 1 Exclude Ext = Extensions = *; Scan Emails = 1 Scan Archives = 1 Scan Packed = 1 Scan Files = 1 Scan Boot = 1 Verify Memory = 0 [scan Results] Line00000005 = "C:\Documents and Settings\All Users\Dados de aplicativos\Avira\AntiVir Desktop\INFECTED\5281d94c.qua=>(Quarantine-8)=>Internet Download Manager 5.19 build 4 + Patch Upload Jefferson\Patch IDM\Patch 6.xx.exe Detected with: Application.Patch.FA" Line00000004 = "C:\Documents and Settings\All Users\Dados de aplicativos\Avira\AntiVir Desktop\INFECTED\5281d94c.qua=>(Quarantine-8)=>Internet Download Manager 5.19 build 4 + Patch Upload Jefferson\Patch IDM\Patch 6.xx.exe Disinfection failed" Line00000003 = "C:\Documents and Settings\All Users\Dados de aplicativos\Avira\AntiVir Desktop\INFECTED\5281d94c.qua=>(Quarantine-8)=>Internet Download Manager 5.19 build 4 + Patch Upload Jefferson\Patch IDM\Patch 6.xx.exe Delete failed" Line00000002 = "C:\Documents and Settings\Usuario\DoctorWeb\Quarantine\4ef45825.qua=>(Quarantine-8) Infected with: Trojan.Generic.4137406" Line00000001 = "C:\Documents and Settings\Usuario\DoctorWeb\Quarantine\4ef45825.qua=>(Quarantine-8) Deleted" Line00000000 = "C:\Documents and Settings\Usuario\DoctorWeb\Quarantine\4ef45825.qua Deleted" -------------------------------------------------------------------------------------------------------------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 13:52:29, on 24/1/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe C:\WINDOWS\RTHDCPL.EXE C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe C:\ARQUIV~1\Crawler\CToolbar.exe C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wscntfy.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe" O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll O11 - Options group: [iNTERNATIONAL] International O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing) O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing) O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Janeiro 25, 2011 :) Os problemas encontrados pelo Dr. Web estavam só na quarentena do Avira e do Dr. Web. ____________________ :seta: Como está seu PC atualmente? Compartilhar este post Link para o post Compartilhar em outros sites
mig.bel 0 Denunciar post Postado Janeiro 28, 2011 :) Os problemas encontrados pelo Dr. Web estavam só na quarentena do Avira e do Dr. Web. ____________________ :seta: Como está seu PC atualmente? -------------------------------------------------------------------------------------------------------------------------------------------------- Olá Antônio, meu PC até que voltou a funcionar normalmente, ocorre que repentinamente apareceu um outro problema, o Windows Explorer vem fechando automaticamente, bem como qualquer outra janela que eu abra do Windows (tipo Meus Documentos, Meu Computador, etc...) Por Favor, me ajude novamente!!! Desculpe por estar abusando de sua atenção e paciência!!! Abçs!!! Compartilhar este post Link para o post Compartilhar em outros sites
Power Max 54 Denunciar post Postado Janeiro 28, 2011 Olá Antônio, meu PC até que voltou a funcionar normalmente, ocorre que repentinamente apareceu um outro problema, o Windows Explorer vem fechando automaticamente, bem como qualquer outra janela que eu abra do Windows (tipo Meus Documentos, Meu Computador, etc...) Por Favor, me ajude novamente!!! :seta: Siga então, por gentileza as dicas deste tutorial para fazer uma limpeza de seu PC com o Spyware Doctor: Tutorial do Spyware Doctor Starter Edition Na sua próxima resposta poste este log do Spyware Doctor juntamente com um novo log do Hijackthis e nos diga como está o seu Pc depois disto. Ficamos no aguardo. Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Fevereiro 28, 2011 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites