Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

mig.bel

[Arquivado] &nbspInfectado ao validar kis2011

Recommended Posts

Olá pessoal do iMasters,

 

fui infectado pelo vírus (hacktool.win32.kiser.zv), ao tentar validar meu antivirus KIS 2011 para 3700 dias.

 

Aparece a mensagem no KIS dizendo que "a segurança do pc está em risco pois foi detectado software suspeito",

 

ocorre que qdo o antivirus é executado, e mesmo detectando o hacktool.win32.kiser.zv, este não é desinfectado, sendo

 

que ao terminar a varredura o pc é desligado. Gostaria muito da ajuda de vcs. Abçs

 

Segue abaixo o Log do HijacjThis:

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 22:39:39, on 14/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Internet Download Manager\IDMan.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Foxit Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"

O4 - HKLM\..\Run: [NBKeyScan] "C:\Arquivos de programas\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: Adicionar ao Antibanner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: &Teclado Virtual - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: Veri&ficação de URLs - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - AppInit_DLLs: C:\ARQUIV~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\ARQUIV~1\KASPER~1\KASPER~1\kloehk.dll

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Serviço do Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" -r (file missing)

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Olá mig.bel!

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque a entrada abaixo e clique em Fix checked:

 

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

____________________

 

:seta: Siga estas dicas:

 

Tutorial do Malwarebytes Anti-Malware

 

Tutorial do Ad-Remover

_________________________

 

fui infectado pelo vírus (hacktool.win32.kiser.zv), ao tentar validar meu antivirus KIS 2011 para 3700 dias.

:!: Nunca use antivirus pirateado ou crackeado, é muito importante desinstalá-lo, pois um antivírus falsificado é mais perigoso do que os próprios vírus!

 

A empresa produtora do antivirus sempre descobre que ele foi pirateado e bloqueia as atualizações para ele.

 

E no caso de antivirus crackeados, as pessoas que criam esses cracks sempre fazem alguma modificação que abrem brechas de segurança no seu PC para que depois ela possa invadir o seu PC ou instalar malwares sem que o antivirus se dê conta disso (pois ele foi modificado ou crackeado justamente para este fim). Você acha que as pessoas que crackeiam os antivirus estão fazendo isso porque são caridosas e bondosas? É claro que não, o que elas querem é um modo de invadir o PC das pessoas que usam esses antivirus.

 

Caso você não queira comprar o Kaspersky original, sugiro um ótimo antivirus gratuito para você, como o Avira AntiVir Personal Edition Classic 2010.

 

Para instalar, configurar e usar corretamente o Avira antivir é só seguir as dicas destes tutoriais:

 

Tutorial do Avira AntiVir Personal Edition Classic 2010 (Instalação e Configuração)

 

Tutorial do Avira AntiVir Personal Edition Classic 2010 (como usá-lo corretamente)

 

• Depois de instalar e configurar o Avira Antivir seguindo as dicas dos tutoriais acima, atualize-o (faça um update) e reinicie o seu computador e entre pelo Modo de Segurança (apertando a tecla F8 (ou a tecla F5 em alguns computadores) repetidas vezes quando o computador estiver reiniciando e escolhendo a opção Modo Seguro ou Modo de Segurança). Aí quando o computador tiver reiniciado, clique com o botão direito do mouse sobre o símbolo do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Iniciar o AntiVir > clique na opção Verif. sistema agora > e aguarde a conclusão do escaneamento.

 

Obs: Caso não seja possível fazer o escaneamento com o Avira Antivir no Modo Seguro do Windows, faça-o no modo normal.

_________________________

 

:seta: Quando você tiver removido os virus que o Avira Antivir encontrar, reinicie o computador normalmente. Clique com o botão direito do mouse sobre o ícone do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Iniciar o AntiVir > clique na opção Relatórios > dê um duplo clique com o botão esquerdo do mouse sobre o log mais recente e clique no botão Arquivo de relatório > Depois será aberta uma tela com o log, então é só selecionar este Log (Clique no menu: Editar » Selecionar Tudo), depois disso volte novamente no menu: Editar » e clique na opção: Copiar) > Depois disso é só voltar aqui no fórum e postar este log do Avira Antivir juntamente com um novo log do Hijackthis, o log do Malwarebytes e o log do Ad-Remover que estará em C:\Ad-Report-CLEAN[1].log para que eles possam ser analizados.

 

Ficamos no aguardo de sua resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Olá mig.bel!

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque a entrada abaixo e clique em Fix checked:

 

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

____________________

 

:seta: Siga estas dicas:

 

Tutorial do Malwarebytes Anti-Malware

 

Tutorial do Ad-Remover

_________________________

 

fui infectado pelo vírus (hacktool.win32.kiser.zv), ao tentar validar meu antivirus KIS 2011 para 3700 dias.

:!: Nunca use antivirus pirateado ou crackeado, é muito importante desinstalá-lo, pois um antivírus falsificado é mais perigoso do que os próprios vírus!

 

A empresa produtora do antivirus sempre descobre que ele foi pirateado e bloqueia as atualizações para ele.

 

E no caso de antivirus crackeados, as pessoas que criam esses cracks sempre fazem alguma modificação que abrem brechas de segurança no seu PC para que depois ela possa invadir o seu PC ou instalar malwares sem que o antivirus se dê conta disso (pois ele foi modificado ou crackeado justamente para este fim). Você acha que as pessoas que crackeiam os antivirus estão fazendo isso porque são caridosas e bondosas? É claro que não, o que elas querem é um modo de invadir o PC das pessoas que usam esses antivirus.

 

Caso você não queira comprar o Kaspersky original, sugiro um ótimo antivirus gratuito para você, como o Avira AntiVir Personal Edition Classic 2010.

 

Para instalar, configurar e usar corretamente o Avira antivir é só seguir as dicas destes tutoriais:

 

Tutorial do Avira AntiVir Personal Edition Classic 2010 (Instalação e Configuração)

 

Tutorial do Avira AntiVir Personal Edition Classic 2010 (como usá-lo corretamente)

 

• Depois de instalar e configurar o Avira Antivir seguindo as dicas dos tutoriais acima, atualize-o (faça um update) e reinicie o seu computador e entre pelo Modo de Segurança (apertando a tecla F8 (ou a tecla F5 em alguns computadores) repetidas vezes quando o computador estiver reiniciando e escolhendo a opção Modo Seguro ou Modo de Segurança). Aí quando o computador tiver reiniciado, clique com o botão direito do mouse sobre o símbolo do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Iniciar o AntiVir > clique na opção Verif. sistema agora > e aguarde a conclusão do escaneamento.

 

Obs: Caso não seja possível fazer o escaneamento com o Avira Antivir no Modo Seguro do Windows, faça-o no modo normal.

_________________________

 

:seta: Quando você tiver removido os virus que o Avira Antivir encontrar, reinicie o computador normalmente. Clique com o botão direito do mouse sobre o ícone do Avira (aquele guarda-chuva vermelho aberto ao lado do relógio do Windows) e escolha a opção Iniciar o AntiVir > clique na opção Relatórios > dê um duplo clique com o botão esquerdo do mouse sobre o log mais recente e clique no botão Arquivo de relatório > Depois será aberta uma tela com o log, então é só selecionar este Log (Clique no menu: Editar » Selecionar Tudo), depois disso volte novamente no menu: Editar » e clique na opção: Copiar) > Depois disso é só voltar aqui no fórum e postar este log do Avira Antivir juntamente com um novo log do Hijackthis, o log do Malwarebytes e o log do Ad-Remover que estará em C:\Ad-Report-CLEAN[1].log para que eles possam ser analizados.

 

Ficamos no aguardo de sua resposta.

 

 

 

..................................................................................................................................................

 

 

Olá Antônio,

 

realizei os procedimentos que me indicaste, e estou enviando os logs das análises feitas.

 

Desde já mto obrigado!!!

 

Abçs

 

 

-------------------------------------------------------------------------------------------------------------------------------------------------

ANTIVÍRUS:

Data: Hoje (212)

16/1/2011 10:11:05 Centro de Proteção Detectado software legal que pode ser usado por criminosos para danificar seu computador ou seus dados pessoais

16/1/2011 10:11:06 Antispam Tarefa iniciada Antispam

16/1/2011 10:11:06 Antivírus de Email Tarefa iniciada Antivírus de Email

16/1/2011 10:11:06 Antivírus de Arquivos Tarefa iniciada Antivírus de Arquivos

16/1/2011 10:11:06 Controle de Aplicativos Tarefa iniciada Controle de Aplicativos

16/1/2011 10:11:06 Firewall Tarefa iniciada Firewall

16/1/2011 10:11:06 Defesa Proativa Tarefa iniciada Defesa Proativa

16/1/2011 10:11:06 Antivírus de IM Tarefa iniciada Antivírus de IM

16/1/2011 10:11:06 Bloqueador de Ataques de Rede Tarefa iniciada Bloqueador de Ataques de Rede

16/1/2011 10:11:06 Antivírus da Web Tarefa iniciada Antivírus da Web

16/1/2011 10:11:20 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração

16/1/2011 10:11:20 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows

16/1/2011 10:11:20 LSA Shell (Export Version) Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração

16/1/2011 10:11:20 LSA Shell (Export Version) Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows

16/1/2011 10:11:20 TuneUp Utilities Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\tuneup utilities 2011\tuneuputilitiesservice32.exe Usando interfaces de programa de outro processo

16/1/2011 10:11:20 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\alg.exe Usando interfaces de programa de outro processo

16/1/2011 10:11:20 TuneUp Utilities Service Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\tuneup utilities 2011\tuneuputilitiesapp32.exe Usando interfaces de programa de outro processo

16/1/2011 10:11:24 Notificações do Programa de Vantagens do Windows Original Controle de Aplicativos Permitido: Acesso direto à memória física Acesso à memória global Acesso direto à memória física

16/1/2011 10:11:24 Notificações do Programa de Vantagens do Windows Original Controle de Aplicativos Permitido: Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema

16/1/2011 10:11:24 Windows Explorer Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:11:25 Application Layer Gateway Service Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:11:25 Notificações do Programa de Vantagens do Windows Original Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas

16/1/2011 10:11:25 RealUpgrade Launcher Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão client-software.real.com Usando interfaces de programa do sistema (DNS)

16/1/2011 10:11:26 Windows Explorer Controle de Aplicativos Permitido: Alça duplicada Alça interna do processo duplicada c:\windows\explorer.exe Alça duplicada

16/1/2011 10:11:26 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Alça duplicada Alça interna do processo duplicada c:\windows\explorer.exe Alça duplicada

16/1/2011 10:11:31 Desconhecido Controle de Aplicativos Permitido: Iniciar driver Início de driver C:\WINDOWS\SYSTEM32\DRIVERS\HTTP.SYS Iniciar driver

16/1/2011 10:11:31 Adobe Reader and Acrobat Manager Controle de Aplicativos Permitido: Usando interfaces de programa do sistema Uso de função do sistema para envio oculto de dados através da rede Usando interfaces de programa do sistema

16/1/2011 10:11:31 Adobe Reader and Acrobat Manager Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:11:31 Windows Explorer Controle de Aplicativos Permitido: Acesso a disco de nível inferior Acesso a disco de nível inferior Device\CdRom0 Acesso a disco de nível inferior

16/1/2011 10:11:32 Windows Explorer Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows

16/1/2011 10:11:44 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Acesso a disco de nível inferior Acesso a disco de nível inferior Device\HarddiskVolume1 Acesso a disco de nível inferior

16/1/2011 10:11:48 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão armmf.adobe.com Usando interfaces de programa do sistema (DNS)

16/1/2011 10:11:54 Spooler SubSystem App Controle de Aplicativos Permitido: Alterando os direitos de acesso ao objeto Alterando os direitos de acesso ao objeto REGISTRY\USER\S-1-5-21-606747145-329068152-1801674531-1003\Software\Microsoft\Windows NT\CurrentVersion\Devices Alterando os direitos de acesso ao objeto

16/1/2011 10:11:59 WMI Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração

16/1/2011 10:12:03 WMI Controle de Aplicativos Permitido: Acesso a disco de nível inferior Acesso a disco de nível inferior Device\Harddisk0\DR0 Acesso a disco de nível inferior

16/1/2011 10:12:04 Nero Home Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\arquivos comuns\ahead\lib\nmindexingservice.exe Usando interfaces de programa de outro processo

16/1/2011 10:12:11 Malwarebytes' Anti-Malware Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração

16/1/2011 10:12:11 Malwarebytes' Anti-Malware Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows

16/1/2011 10:12:12 Google Installer Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão cr-tools.clients.google.com Usando interfaces de programa do sistema (DNS)

16/1/2011 10:12:13 Nero Home Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\arquivos comuns\ahead\lib\nmindexingservice.exe Usando interfaces de programa de outro processo

16/1/2011 10:12:21 Nero Home Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\arquivos comuns\ahead\lib\nmindexstoresvr.exe Usando interfaces de programa de outro processo

16/1/2011 10:12:21 Spyware Terminator Update Support Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão www.spywareterminator.com Usando interfaces de programa do sistema (DNS)

16/1/2011 10:12:22 Nero Home Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows

16/1/2011 10:12:24 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4} Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935} Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\PROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\VERSIONINDEPENDENTPROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\PROGRAMMABLE Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\INPROCSERVER32\ThreadingModel Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}\TYPELIB Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8} Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\PROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\VERSIONINDEPENDENTPROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\PROGRAMMABLE Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\INPROCSERVER32\ThreadingModel Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}\TYPELIB Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D} Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\PROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\VERSIONINDEPENDENTPROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\PROGRAMMABLE Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\INPROCSERVER32\ThreadingModel Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}\TYPELIB Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\CONTROL Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A} Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\PROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\VERSIONINDEPENDENTPROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\PROGRAMMABLE Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\INPROCSERVER32\ThreadingModel Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\CONTROL Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\INSERTABLE Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\TOOLBOXBITMAP32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\TOOLBOXBITMAP32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\MISCSTATUS Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\MISCSTATUS\1 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\TYPELIB Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{52F6F7BD-DF73-44B3-AE13-89E1E1FB8F6A}\VERSION Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038} Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\PROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\VERSIONINDEPENDENTPROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\PROGRAMMABLE Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\INPROCSERVER32\ThreadingModel Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{CDD67718-A430-4AB9-A939-83D9074B0038}\TYPELIB Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861} Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\PROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\VERSIONINDEPENDENTPROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\PROGRAMMABLE Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\INPROCSERVER32\ThreadingModel Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{4764030F-2733-45B9-AE62-3D1F4F6F2861}\TYPELIB Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7} Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\PROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\VERSIONINDEPENDENTPROGID Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Excluir hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\PROGRAMMABLE Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\INPROCSERVER32\ThreadingModel Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{7D11E719-FF90-479C-B0D7-96EB43EE55D7}\TYPELIB Classes_CLSID

16/1/2011 10:12:25 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Classes_CLSID Modificar hklm\SOFTWARE\CLASSES\CLSID\{6B9EB066-DA1F-4C0A-AC62-01AC892EF175}\INPROCSERVER32 Classes_CLSID

16/1/2011 10:12:26 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Main_Run Excluir hklm\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Adsoff Startup Main_Run

16/1/2011 10:12:26 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Main_Run Excluir hklm\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\OSSPoxy Main_Run

16/1/2011 10:12:26 Internet Download Manager (IDM) Controle de Aplicativos Recusado: Main_Run Excluir hklm\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\New.net Startup Main_Run

16/1/2011 10:12:26 Internet Download Manager (IDM) Controle de Aplicativos Permitido: Alterando os direitos de acesso ao objeto Alterando os direitos de acesso ao objeto REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{14190654-4dd9-457a-b001-8cd81c3932e5} Alterando os direitos de acesso ao objeto

16/1/2011 10:12:27 Windows Live Messenger Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:12:27 Google Installer Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:12:27 Windows Live Messenger Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas

16/1/2011 10:12:28 Internet Download Manager (IDM) Controle de Aplicativos Permitido: Iniciando outros processos Outro processo iniciado c:\arquivos de programas\internet download manager\iemonitor.exe Iniciando outros processos

16/1/2011 10:12:34 WMI Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:12:39 WMI Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:12:43 HP Digital Imaging Monitor Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:12:50 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\arquivos de programas\hp\digital imaging\bin\hpqtra08.exe Usando interfaces de programa de outro processo

16/1/2011 10:12:54 HP CUE Status Root Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:13:11 Centro de Proteção O computador está protegido

16/1/2011 10:13:53 Service Executable Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:13:56 Generic Host Process for Win32 Services Controle de Aplicativos Aplicativo colocado no grupo Confiável

16/1/2011 10:13:56 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas

16/1/2011 10:13:56 LSA Shell (Export Version) Controle de Aplicativos Permitido: Criando chaves ocultas do Registro Criação de chave do Registro oculta REGISTRY\MACHINE\SECURITY\POLICY\SECRETS\SAI Criando chaves ocultas do Registro

16/1/2011 10:14:02 Google Installer Controle de Aplicativos Aplicativo colocado no grupo Confiável

16/1/2011 10:14:02 Google Installer Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas

16/1/2011 10:14:02 Google Installer Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão tools.google.com Usando interfaces de programa do sistema (DNS)

16/1/2011 10:14:21 Windows Explorer Autodefesa Recusado Abrir C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe

16/1/2011 10:14:25 WMI Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:14:57 Google Chrome Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão www.google.pt Usando interfaces de programa do sistema (DNS)

16/1/2011 10:14:57 Google Chrome Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão ajax.googleapis.com Usando interfaces de programa do sistema (DNS)

16/1/2011 10:14:58 Google Chrome Controle de Aplicativos Permitido: Invasão de código Invasão de código c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Invasão de código

16/1/2011 10:15:01 Google Chrome Antivírus de Arquivos Compactado: UPX C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.63_0\npqscan.dll

16/1/2011 10:15:05 WMI Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:15:13 Google Chrome Controle de Aplicativos Permitido: Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema

16/1/2011 10:15:13 Google Chrome Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:15:25 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000702

16/1/2011 10:15:28 Google Chrome Controle de Aplicativos Aplicativo colocado no grupo Confiável

16/1/2011 10:15:28 Google Chrome Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas

16/1/2011 10:15:29 Spyware Terminator Controle de Aplicativos Permitido: Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema

16/1/2011 10:15:29 Spyware Terminator Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:16:00 Google Installer Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração

16/1/2011 10:16:04 Google Installer Controle de Aplicativos Aplicativo colocado no grupo Confiável

16/1/2011 10:16:04 Google Installer Controle de Aplicativos Permitido: Acesso ao armazenamento de senhas Acesso ao armazenamento protegido Acesso ao armazenamento de senhas

16/1/2011 10:16:04 Google Installer Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão tools.google.com Usando interfaces de programa do sistema (DNS)

16/1/2011 10:20:06 Google Chrome Controle de Aplicativos Permitido: Operações suspeitas Executando operação suspeita em outro processo c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Operações suspeitas

16/1/2011 10:20:08 Google Chrome Antivírus da Web Compactado: Swf2Swc http://s.ytimg.com/yt/swfbin/watch_as3-vflqEsLb3.swf

16/1/2011 10:20:08 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_00084e

16/1/2011 10:20:12 Google Chrome Controle de Aplicativos Permitido: Operações suspeitas Executando operação suspeita em outro processo c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Operações suspeitas

16/1/2011 10:21:24 Google Chrome Controle de Aplicativos Permitido: Operações suspeitas Executando operação suspeita em outro processo c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Operações suspeitas

16/1/2011 10:23:24 Google Chrome Antivírus da Web Compactado: Swf2Swc http://static.imasters.com.br/anuncio/impacta/2010/novembro/728x90.swf

16/1/2011 10:23:24 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000854

16/1/2011 10:23:34 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000747

16/1/2011 10:23:57 Google Chrome Controle de Aplicativos Permitido: Operações suspeitas Executando operação suspeita em outro processo c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Operações suspeitas

16/1/2011 10:26:20 File Downloader Controle de Aplicativos Aplicativo colocado no grupo Baixa restrição Classificação de ameaça calculada heuristicamente

16/1/2011 10:26:26 Nero Home Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows

16/1/2011 10:27:03 Google Chrome Controle de Aplicativos Permitido: Usando interfaces de programa do sistema (DNS) Usar sistema de cache DNS para conversão www.caixadedicas.com Usando interfaces de programa do sistema (DNS)

16/1/2011 10:27:06 Google Chrome Controle de Aplicativos Permitido: Invasão de código Invasão de código c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Invasão de código

16/1/2011 10:27:18 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s55_001_diversos_101202/mitos_300x100_v03_CS4.swf/1294438259//mitos_300x100_v03_CS4

16/1/2011 10:27:19 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s93_001_diversos_101202/300x100_bones.swf/1294754710//300x100_bones

16/1/2011 10:27:20 Google Chrome Controle de Aplicativos Permitido: Operações suspeitas Executando operação suspeita em outro processo c:\documents and settings\usuario\configurações locais\dados de aplicativos\google\chrome\application\chrome.exe Operações suspeitas

16/1/2011 10:27:20 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/apetrexo_959_002_apetrexo_110147/NOVAHOME_Globo.com_SeloCat_PowerBalance_SomenteHj_DePor.swf/1295034567//NOVAHOME_Globo.com_SeloCat_PowerBalance_SomenteHj_DePor

16/1/2011 10:27:23 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/apetrexo_959_002_apetrexo_110143/Globocom_DhtmlHome_W320Prata-Rosa-Preta-Verde_APartirDe.swf/1294948689//Globocom_DhtmlHome_W320Prata-Rosa-Preta-Verde_APartirDe

16/1/2011 10:28:08 Google Chrome Antivírus da Web Compactado: Swf2Swc http://s0.2mdn.net/2162474/Super_Exp_BRBWL09BB_160111.swf?clicktag=http%3A//ad.doubleclick.net/click%253Bh%253Dv8/3a91/3/0/%252a/i%253B235040250%253B0-0%253B1%253B32492552%253B3454-728/90%253B40288114/40305901/1%253B%253B%257Eaopt%253D2/1/81/0%253B%257Esscs%253D%253fhttp%3A//www.fastshop.com.br/product.aspx%3Fpar%3Dsupertop%26product_id%3DBRBWL09BB

16/1/2011 10:28:08 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_00086f

16/1/2011 10:28:11 Google Chrome Antivírus da Web Compactado: Swf2Swc http://spe.atdmt.com/ds/F1FRCDTMDCLT/01_09_Terra_consumer_HP_All_in_One_100_5010_pen_JAN11/Terra_Ret300x250_ConsHPAllinOne1005010pen_ADS.swf?ver=1&clickTag1=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/p%3B235037658%3B0-0%3B1%3B32492552%3B4307-300/250%3B40288949/40306736/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550569/direct;ai.199363994;ct.1/01&clickTag=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/p%3B235037658%3B0-0%3B1%3B32492552%3B4307-300/250%3B40288949/40306736/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550569/direct;ai.199363994;ct.1/01

16/1/2011 10:28:11 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000870

16/1/2011 10:28:13 Google Chrome Antivírus da Web Compactado: Swf2Swc http://spe.atdmt.com/ds/F1FRCDTMDCLT/01_09_Terra_consumer_HP_All_in_One_100_5010_pen_JAN11/Terra_Barra200x446_ConsHPAllinOne1005010pen_ADS.swf?ver=1&clickTag1=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/m%3B235037657%3B0-0%3B1%3B32492552%3B34450-200/446%3B40288743/40306530/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550571/direct;ai.199362121;ct.1/01&clickTag=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/m%3B235037657%3B0-0%3B1%3B32492552%3B34450-200/446%3B40288743/40306530/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550571/direct;ai.199362121;ct.1/01

16/1/2011 10:28:14 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000871

16/1/2011 10:28:20 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ec.atdmt.com/ds/F1FRCDTMDCLT/01_01_v2_E_01_03_v2_Retangulo_Terra_DEZ10/Terra_Ret_01_01_V2_Cons_HPMini210_1030_ADS.swf?ver=1&clickTag1=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/v%3B235037659%3B0-0%3B1%3B32492552%3B4307-300/250%3B40289246/40307033/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550570/direct;ai.196400091;ct.1/01&clickTag=http://ad.doubleclick.net/click%3Bh%3Dv8/3a91/3/0/%2a/v%3B235037659%3B0-0%3B1%3B32492552%3B4307-300/250%3B40289246/40307033/1%3B%3B%7Eaopt%3D2/1/81/0%3B%7Esscs%3D%3fhttp://clk.atdmt.com/go/289550570/direct;ai.196400091;ct.1/01

16/1/2011 10:28:20 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000872

16/1/2011 10:29:15 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/rotativo_p03_002_bbb11_110101/insertmarca_BBB11_padrao_ABCDE_multclick.swf/1294841514//insertmarca_BBB11_padrao_ABCDE_multclick

16/1/2011 10:29:18 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s33_015_ego_101203/Banner-Horoscopo-300x100-Escorpiao-v2.swf/1292612774//Banner-Horoscopo-300x100-Escorpiao-v2

16/1/2011 10:29:19 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s76_001_glbmarca_101201/retmedio_araguaia.swf/1292509409//retmedio_araguaia

16/1/2011 10:30:26 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s33_015_ego_101203/Banner-Horoscopo-300x100-Aries-v2.swf/1292612519//Banner-Horoscopo-300x100-Aries-v2

16/1/2011 10:30:26 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s55_001_guiadeca_101201/guia_carreiras_300x250.swf/1290091296//guia_carreiras_300x250

16/1/2011 10:30:30 Google Chrome Antivírus da Web Compactado: Swf2Swc http://s.videos.globo.com/p2/player.swf

16/1/2011 10:30:30 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_00087b

16/1/2011 10:30:45 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/skybr_020_088_skybr_110101/SKY_GLOBO_GE_MIDBANNER_DIAG_201210.swf/1294694258//SKY_GLOBO_GE_MIDBANNER_DIAG_201210

16/1/2011 10:30:45 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração

16/1/2011 10:30:45 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows

16/1/2011 10:30:47 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_0004f4

16/1/2011 10:30:50 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/netshoes/netshoes_rm_10101503/300x250_linhanike3_frete_airmaxlaranja.swf

16/1/2011 10:30:50 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000880

16/1/2011 10:30:58 Windows Defender Command Line Utility Controle de Aplicativos Permitido: Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema Acesso a objetos críticos do sistema

16/1/2011 10:30:58 Windows Defender Command Line Utility Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:30:59 WMI Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\svchost.exe Usando interfaces de programa de outro processo

16/1/2011 10:30:59 Generic Host Process for Win32 Services Controle de Aplicativos Permitido: Usando interfaces de programa de outro processo Usando interfaces de programa de outros aplicativos c:\windows\system32\wbem\wmiprvse.exe Usando interfaces de programa de outro processo

16/1/2011 10:31:01 Windows Defender Command Line Utility Controle de Aplicativos Permitido: Acesso direto à memória física Acesso à memória global Acesso direto à memória física

16/1/2011 10:31:02 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/apetrexo_959_002_apetrexo_110153/Globocom_Dhtml_SaldTechnosJS25AA1K_APartir.swf/1295035974//Globocom_Dhtml_SaldTechnosJS25AA1K_APartir

16/1/2011 10:31:25 LSA Shell (Export Version) Controle de Aplicativos Permitido: Definindo privilégios de depuração Definição de privilégios de depuração Definindo privilégios de depuração

16/1/2011 10:31:25 LSA Shell (Export Version) Controle de Aplicativos Permitido: Saindo do Microsoft Windows Desligamento do Windows Saindo do Microsoft Windows

16/1/2011 10:31:50 Google Chrome Antivírus da Web Compactado: Swf2Swc http://s0.2mdn.net/2662185/Terra_Super_Barbeadores_Eletricos.swf

16/1/2011 10:31:51 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_00071b

16/1/2011 10:31:51 Google Chrome Antivírus da Web Compactado: Swf2Swc http://s0.2mdn.net/2706403/Y_F_300x250_FrutasBr.swf

16/1/2011 10:31:52 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000893

16/1/2011 10:31:54 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_0005de

16/1/2011 10:31:54 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000622

16/1/2011 10:31:55 Google Chrome Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_00067d

16/1/2011 10:32:03 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/rotativo_p101_001_vespet_110101/insertmarca_GE_padrao_VERAO_ESPETACULAR_CDAB.swf/1293798711//insertmarca_GE_padrao_VERAO_ESPETACULAR_CDAB

16/1/2011 10:32:09 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/b2u_006_158_neosa_110101/rosa_globo_300x250.swf/1294928463

16/1/2011 10:32:09 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000895

16/1/2011 10:32:09 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/lojagloboesporte/vitrine_netshoes_06071002b/300x300_Diversos_II_100111.swf

16/1/2011 10:32:10 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/cef_p101_055_caixa_110104/caixa_faturazero_globo_eletr_retangulo.swf/1293797664//caixa_faturazero_globo_eletr_retangulo

16/1/2011 10:32:10 Google Chrome Antivírus da Web Compactado: Swf2Swc http://ads.img.globo.com/RealMedia/ads/Creatives/globocom/globocom_s82_001_isp_101212/Banner-BBB111-300x100-v5.swf/1294863372//Banner-BBB111-300x100-v5

16/1/2011 10:32:10 Spyware Terminator Realtime Shield 32-bit Service Antivírus de Arquivos Compactado: Swf2Swc C:\DOCUMENTS AND SETTINGS\USUARIO\CONFIGURAÇÕES LOCAIS\DADOS DE APLICATIVOS\GOOGLE\CHROME\User Data\Default\Cache\f_000896

 

--------------------------------------------------------------------------------------------------------------------------------------------------

1 - Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

 

Versão da Base de Dados: 5527

 

Windows 5.1.2600 Service Pack 3 (Safe Mode)

Internet Explorer 8.0.6001.18702

 

16/1/2011 10:08:30

mbam-log-2011-01-16 (10-08-14).txt

 

Tipo de Verificação: Verificação Completa (C:\|E:\|F:\|)

Objetos escaneados: 214596

Tempo decorrido: 58 minuto(s), 45 segundo(s)

 

Processos de Memória Infectados: 0

Módulos de Memória Infectados: 0

Chaves de Registro Infectadas: 0

Valores de Registro Infectados: 0

Itens de Dados no Registro Infectados: 0

Pastas Infectadas: 0

Arquivos Infectados: 3

 

Processos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Infectadas:

(Não foram detectados ítens maliciosos)

 

Valores de Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Pastas Infectadas:

(Não foram detectados ítens maliciosos)

 

Arquivos Infectados:

c:\RECYCLER\s-1-5-21-606747145-329068152-1801674531-1003\Dc194\__incomplete__kaspersky 2011 crack.exe (RiskWare.Tool.CK) -> No action taken.

c:\system volume information\_restore{2e688ff2-c923-4539-bed5-d6b4329ec271}\RP84\A0052856.exe (RiskWare.Tool.CK) -> No action taken.

e:\meus documentos\downloads\keygen.exe (Trojan.Dropper.PGen) -> No action taken.

 

 

 

 

2 - Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

 

Versão da Base de Dados: 5527

 

Windows 5.1.2600 Service Pack 3 (Safe Mode)

Internet Explorer 8.0.6001.18702

 

16/1/2011 10:08:53

mbam-log-2011-01-16 (10-08-53).txt

 

Tipo de Verificação: Verificação Completa (C:\|E:\|F:\|)

Objetos escaneados: 214596

Tempo decorrido: 58 minuto(s), 45 segundo(s)

 

Processos de Memória Infectados: 0

Módulos de Memória Infectados: 0

Chaves de Registro Infectadas: 0

Valores de Registro Infectados: 0

Itens de Dados no Registro Infectados: 0

Pastas Infectadas: 0

Arquivos Infectados: 3

 

Processos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Infectadas:

(Não foram detectados ítens maliciosos)

 

Valores de Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Pastas Infectadas:

(Não foram detectados ítens maliciosos)

 

Arquivos Infectados:

c:\RECYCLER\s-1-5-21-606747145-329068152-1801674531-1003\Dc194\__incomplete__kaspersky 2011 crack.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.

c:\system volume information\_restore{2e688ff2-c923-4539-bed5-d6b4329ec271}\RP84\A0052856.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.

e:\meus documentos\downloads\keygen.exe (Trojan.Dropper.PGen) -> Quarantined and deleted successfully.

 

 

..................................................................................................................................................

 

======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 =======

 

Updated by TeamXscript on 16/01/11 at 02:00

Contact: AdRemover[DOT]contact[AT]gmail[DOT]com

website: http://www.teamxscript.org

 

C:\Arquivos de programas\Ad-Remover\main.exe (SCAN [1]) -> Launched at 22:29:59 on 15/01/2011, Normal boot

 

Microsoft Windows XP Professional Service Pack 3 (X86)

Usuario@MIGUEL ( )

 

============== SEARCH ==============

 

 

File found: C:\Arquivos de programas\Mozilla FireFox\searchplugins\crawlersrch.xml

File found: C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

Folder found: C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\extensions\toolbar@ask.com

Folder found: C:\Arquivos de programas\Ask.com

Folder found: C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\AskToolbar

Folder found: C:\Arquivos de programas\Crawler

 

-- File opened: C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\Prefs.js --

Line found: user_pref("extensions.asktb.cbid", "F4");

Line found: user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}...

Line found: user_pref("extensions.asktb.dtid", "YYYYYYYYBR");

Line found: user_pref("extensions.asktb.fresh-install", false);

Line found: user_pref("extensions.asktb.l", "dis");

Line found: user_pref("extensions.asktb.last-config-req", "1321496627732");

Line found: user_pref("extensions.asktb.locale", "en_US");

Line found: user_pref("extensions.asktb.o", "101699");

Line found: user_pref("extensions.asktb.overlay-reloaded-using-restart", true);

Line found: user_pref("extensions.asktb.qsrc", "2871");

Line found: user_pref("extensions.asktb.r", "4");

Line found: user_pref("extensions.asktb.search-suggestions-enabled", true);

Line found: user_pref("extensions.asktb.v", "3.8.0.99999");

Line found: user_pref("extensions.enabledItems", "KavAntiBanner@Kaspersky.ru:11.0.1.400,linkfilter@kaspersky.ru:...

-- File closed --

 

 

Key found: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}

Key found: HKLM\Software\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}

Key found: HKLM\Software\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Key found: HKLM\Software\Classes\CLSID\{1DDA201E-5B42-4352-933E-21A92B297E3B}

Key found: HKLM\Software\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

Key found: HKLM\Software\Classes\CLSID\{4D25FB7A-8902-4291-960E-9ADA051CFBBF}

Key found: HKLM\Software\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}

Key found: HKLM\Software\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}

Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}

Key found: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}

Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}

Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}

Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}

Key found: HKLM\Software\Classes\CLSID\{DBDB6FAA-1F5F-4A18-B60B-7A905C7FF83F}

Key found: HKLM\Software\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}

Key found: HKLM\Software\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}

Key found: HKLM\Software\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}

Key found: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}

Key found: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}

Key found: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}

Key found: HKLM\Software\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}

Key found: HKLM\Software\Classes\TypeLib\{04006843-5199-4CE4-B3CD-8092CC91706E}

Key found: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}

Key found: HKLM\Software\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}

Key found: HKLM\Software\Classes\TypeLib\{E79BB61D-7F1A-41DF-8AD0-402795E3B566}

Key found: HKLM\Software\Classes\ctbcommon.Buttons

Key found: HKLM\Software\Classes\ctbr.R404Pro

Key found: HKLM\Software\Classes\CToolbar.TB4Client

Key found: HKLM\Software\Classes\CToolbar.TB4Script

Key found: HKLM\Software\Classes\CToolbar.TB4Server

Key found: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd

Key found: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1

Key found: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL

Key found: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}

Key found: HKLM\Software\CToolbar

Key found: HKCU\Software\Ask.com

Key found: HKCU\Software\AskToolbar

Key found: HKCU\Software\CToolbar

Key found: HKCU\Software\AppDataLow\AskToolbarInfo

Key found: HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF

Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF

Key found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Key found: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}

Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}

Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\CToolbar_UNINSTALL

Key found: HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search

Key found: HKLM\Software\Classes\PROTOCOLS\Handler\tbr

Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\Crawler

 

Value found: HKLM\Software\Mozilla\Firefox\Extensions|{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

Value found: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Value found: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}

Value found: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

Value found: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}

Value found: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

 

 

============== ADDITIONNAL SCAN ==============

 

** Mozilla Firefox Version [3.6.13 (pt-BR)] **

 

-- C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\Prefs.js --

browser.download.lastDir, C:\\Documents and Settings\\Usuario\\Desktop\\BUENOS AIRES

browser.startup.homepage, www.google.com.br

browser.startup.homepage_override.mstone, rv:1.9.2.13

keyword.URL, hxxp://search.instantfirefox.com/google#q=

 

========================================

 

** Internet Explorer Version [8.0.6001.18702] **

 

[HKCU\Software\Microsoft\Internet Explorer\Main]

Do404Search: 0x01000000

Enable Browser Extensions: yes

Local Page: C:\WINDOWS\system32\blank.htm

Search bar: hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60076

Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896

Show_ToolBar: yes

Start Page: hxxp://www.crawler.com/homepage.aspx?tbid=60076

Use Search Asst: no

 

[HKLM\Software\Microsoft\Internet Explorer\Main]

Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157

Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896

Delete_Temp_Files_On_Exit: yes

Local Page: C:\WINDOWS\system32\blank.htm

SearchAssistant: hxxp://www.crawler.com/search/ie.aspx?tb_id=60076

Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896

Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

 

[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]

Tabs: res://ieframe.dll/tabswelcome.htm

Blank: res://mshtml.dll/blank.htm

 

========================================

 

C:\Arquivos de programas\Ad-Remover\Quarantine: 0 File(s)

C:\Arquivos de programas\Ad-Remover\Backup: 1 File(s)

 

C:\Ad-Report-SCAN[1].txt - 15/01/2011 (8828 Byte(s))

 

End at: 22:32:00, 15/01/2011

 

============== E.O.F ==============

 

 

..................................................................................................................................................

 

 

Logfile of HijackThis v1.99.1

Scan saved at 00:53:20, on 17/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Windows Defender\MSASCui.exe

C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Internet Download Manager\IDMan.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe

C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtblfs.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\ARQUIV~1\Crawler\Toolbar\CToolbar.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60076

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076

R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\ARQUIV~1\Crawler\Toolbar\ctbr.dll

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\ARQUIV~1\Crawler\Toolbar\ctbr.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Foxit Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll

O3 - Toolbar: Barra de ferramentas &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\Toolbar\ctbr.dll

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [AVP] "C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe"

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [Windows Defender] "C:\Arquivos de programas\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: Adicionar ao Antibanner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm

O8 - Extra context menu item: Crawler Search - tbr:iemenu

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: &Teclado Virtual - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: Veri&ficação de URLs - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\Toolbar\ctbr.dll

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - AppInit_DLLs: C:\ARQUIV~1\KASPER~1\KASPER~1\mzvkbd3.dll, C:\ARQUIV~1\KASPER~1\KASPER~1\kloehk.dll

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Serviço do Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" -r (file missing)

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

 

...............................................................................................................................................

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Alguns problemas foram removidos pelo Malwarebytes.

___________________

 

======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 =======

 

============== SEARCH ==============

:!: No seu log do Ad-remover está constando que você usou somente a função de pesquisa dele. Por isto ele encontrou vários problemas mas ainda não os removeu. Execute novamente o Ad-Remover > Surgirá a tela principal do Ad-Remover, na qual você clicará no botão Clean para que os problemas que estejam em seu PC possam ser removidos > Surgirá mais uma tela na qual você teclará no botão Sim > Aguarde... pode demorar um pouco > Assim que o escaneamento for concluído, surgirá uma mensagem pedindo para que o PC seja reiniciado afim de que a limpeza possa ser concluida, clique no botão Sim para confirmar o procedimento > O relatório (log) estará em C:\Ad-Report-CLEAN[2].log

____________________

 

C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011

:!: No seu log consta que você ainda continua com o Kaspersky. Se a causa da infecção foi o uso de um antivirus pirata, o PC continuará infectado enquanto você permanecer com ele.

_____________________

 

:seta: Na sua próxima respostas poste o log que estará em C:\Ad-Report-CLEAN[2].log juntamente com um novo log do Hijackthis.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Alguns problemas foram removidos pelo Malwarebytes.

___________________

 

======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 =======

 

============== SEARCH ==============

:!: No seu log do Ad-remover está constando que você usou somente a função de pesquisa dele. Por isto ele encontrou vários problemas mas ainda não os removeu. Execute novamente o Ad-Remover > Surgirá a tela principal do Ad-Remover, na qual você clicará no botão Clean para que os problemas que estejam em seu PC possam ser removidos > Surgirá mais uma tela na qual você teclará no botão Sim > Aguarde... pode demorar um pouco > Assim que o escaneamento for concluído, surgirá uma mensagem pedindo para que o PC seja reiniciado afim de que a limpeza possa ser concluida, clique no botão Sim para confirmar o procedimento > O relatório (log) estará em C:\Ad-Report-CLEAN[2].log

____________________

 

C:\Arquivos de programas\Kaspersky Lab\Kaspersky Internet Security 2011

:!: No seu log consta que você ainda continua com o Kaspersky. Se a causa da infecção foi o uso de um antivirus pirata, o PC continuará infectado enquanto você permanecer com ele.

_____________________

 

:seta: Na sua próxima respostas poste o log que estará em C:\Ad-Report-CLEAN[2].log juntamente com um novo log do Hijackthis.

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Olá Antônio,

 

fiz o que pediu... desinstalei o KIS, instalei o AVIRA e realizei novamente os procedimentos anteriores, segue os dados para tua análise.

 

Abçs

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

 

 

Avira AntiVir Personal

Report file date: segunda-feira, 17 de janeiro de 2011 10:46

 

Scanning for 2373520 virus strains and unwanted programs.

 

The program is running as an unrestricted full version.

Online services are available:

 

Licensee : Avira AntiVir Personal - FREE Antivirus

Serial number : 0000149996-ADJIE-0000001

Platform : Windows XP

Windows version : (Service Pack 3) [5.1.2600]

Boot mode : Normally booted

Username : SYSTEM

Computer name : MIGUEL

 

Version information:

BUILD.DAT : 10.0.0.609 31824 Bytes 13/12/2010 09:43:00

AVSCAN.EXE : 10.0.3.5 435368 Bytes 13/12/2010 11:39:56

AVSCAN.DLL : 10.0.3.0 46440 Bytes 1/4/2010 15:57:04

LUKE.DLL : 10.0.3.2 104296 Bytes 13/12/2010 11:40:06

LUKERES.DLL : 10.0.0.1 12648 Bytes 11/2/2010 02:40:49

VBASE000.VDF : 7.10.0.0 19875328 Bytes 6/11/2009 12:05:36

VBASE001.VDF : 7.11.0.0 13342208 Bytes 14/12/2010 13:37:48

VBASE002.VDF : 7.11.0.1 2048 Bytes 14/12/2010 13:37:48

VBASE003.VDF : 7.11.0.2 2048 Bytes 14/12/2010 13:37:49

VBASE004.VDF : 7.11.0.3 2048 Bytes 14/12/2010 13:37:49

VBASE005.VDF : 7.11.0.4 2048 Bytes 14/12/2010 13:37:49

VBASE006.VDF : 7.11.0.5 2048 Bytes 14/12/2010 13:37:50

VBASE007.VDF : 7.11.0.6 2048 Bytes 14/12/2010 13:37:51

VBASE008.VDF : 7.11.0.7 2048 Bytes 14/12/2010 13:37:51

VBASE009.VDF : 7.11.0.8 2048 Bytes 14/12/2010 13:37:51

VBASE010.VDF : 7.11.0.9 2048 Bytes 14/12/2010 13:37:52

VBASE011.VDF : 7.11.0.10 2048 Bytes 14/12/2010 13:37:52

VBASE012.VDF : 7.11.0.11 2048 Bytes 14/12/2010 13:37:52

VBASE013.VDF : 7.11.0.52 128000 Bytes 16/12/2010 13:38:02

VBASE014.VDF : 7.11.0.91 226816 Bytes 20/12/2010 13:38:17

VBASE015.VDF : 7.11.0.122 136192 Bytes 21/12/2010 13:38:28

VBASE016.VDF : 7.11.0.156 122880 Bytes 24/12/2010 13:38:43

VBASE017.VDF : 7.11.0.185 146944 Bytes 27/12/2010 13:38:46

VBASE018.VDF : 7.11.0.228 132608 Bytes 30/12/2010 13:38:47

VBASE019.VDF : 7.11.1.5 148480 Bytes 3/1/2011 13:38:50

VBASE020.VDF : 7.11.1.37 156672 Bytes 7/1/2011 13:38:52

VBASE021.VDF : 7.11.1.65 140800 Bytes 10/1/2011 13:38:53

VBASE022.VDF : 7.11.1.87 225280 Bytes 11/1/2011 13:38:57

VBASE023.VDF : 7.11.1.124 125440 Bytes 14/1/2011 13:38:58

VBASE024.VDF : 7.11.1.125 2048 Bytes 14/1/2011 13:38:59

VBASE025.VDF : 7.11.1.126 2048 Bytes 14/1/2011 13:38:59

VBASE026.VDF : 7.11.1.127 2048 Bytes 14/1/2011 13:38:59

VBASE027.VDF : 7.11.1.128 2048 Bytes 14/1/2011 13:39:00

VBASE028.VDF : 7.11.1.129 2048 Bytes 14/1/2011 13:39:00

VBASE029.VDF : 7.11.1.130 2048 Bytes 14/1/2011 13:39:00

VBASE030.VDF : 7.11.1.131 2048 Bytes 14/1/2011 13:39:00

VBASE031.VDF : 7.11.1.151 93184 Bytes 17/1/2011 13:39:02

Engineversion : 8.2.4.140

AEVDF.DLL : 8.1.2.1 106868 Bytes 13/12/2010 11:39:51

AESCRIPT.DLL : 8.1.3.52 1282426 Bytes 17/1/2011 13:39:29

AESCN.DLL : 8.1.7.2 127349 Bytes 13/12/2010 11:39:50

AESBX.DLL : 8.1.3.2 254324 Bytes 13/12/2010 11:39:50

AERDL.DLL : 8.1.9.2 635252 Bytes 13/12/2010 11:39:50

AEPACK.DLL : 8.2.4.7 512375 Bytes 17/1/2011 13:39:25

AEOFFICE.DLL : 8.1.1.10 201084 Bytes 13/12/2010 11:39:49

AEHEUR.DLL : 8.1.2.64 3154294 Bytes 17/1/2011 13:39:21

AEHELP.DLL : 8.1.16.0 246136 Bytes 13/12/2010 11:39:42

AEGEN.DLL : 8.1.5.1 397683 Bytes 17/1/2011 13:39:07

AEEMU.DLL : 8.1.3.0 393589 Bytes 13/12/2010 11:39:42

AECORE.DLL : 8.1.19.0 196984 Bytes 13/12/2010 11:39:41

AEBB.DLL : 8.1.1.0 53618 Bytes 13/12/2010 11:39:41

AVWINLL.DLL : 10.0.0.0 19304 Bytes 13/12/2010 11:39:56

AVPREF.DLL : 10.0.0.0 44904 Bytes 13/12/2010 11:39:54

AVREP.DLL : 10.0.0.8 62209 Bytes 17/6/2010 17:27:13

AVREG.DLL : 10.0.3.2 53096 Bytes 13/12/2010 11:39:54

AVSCPLR.DLL : 10.0.3.2 84328 Bytes 13/12/2010 11:39:56

AVARKT.DLL : 10.0.22.6 231784 Bytes 13/12/2010 11:39:52

AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 13/12/2010 11:39:53

SQLITE3.DLL : 3.6.19.0 355688 Bytes 17/6/2010 17:27:22

AVSMTP.DLL : 10.0.0.17 63848 Bytes 13/12/2010 11:39:56

NETNT.DLL : 10.0.0.0 11624 Bytes 17/6/2010 17:27:21

RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 28/1/2010 16:10:20

RCTEXT.DLL : 10.0.58.0 97128 Bytes 13/12/2010 11:40:20

 

Configuration settings for the scan:

Jobname.............................: Complete system scan

Configuration file..................: C:\Arquivos de programas\Avira\AntiVir Desktop\sysscan.avp

Logging.............................: low

Primary action......................: interactive

Secondary action....................: ignore

Scan master boot sector.............: on

Scan boot sector....................: on

Boot sectors........................: C:, E:,

Process scan........................: on

Extended process scan...............: on

Scan registry.......................: on

Search for rootkits.................: on

Integrity checking of system files..: off

Scan all files......................: All files

Scan archives.......................: on

Recursion depth.....................: 20

Smart extensions....................: on

Macro heuristic.....................: on

File heuristic......................: medium

 

Start of the scan: segunda-feira, 17 de janeiro de 2011 10:46

 

Starting search for hidden objects.

HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NtmsSvc\Config\Standalone\drivelist

[NOTE] The registry entry is invisible.

 

The scan of running processes will be started

Scan process 'msdtc.exe' - '40' Module(s) have been scanned

Scan process 'dllhost.exe' - '59' Module(s) have been scanned

Scan process 'dllhost.exe' - '45' Module(s) have been scanned

Scan process 'vssvc.exe' - '48' Module(s) have been scanned

Scan process 'avscan.exe' - '69' Module(s) have been scanned

Scan process 'avcenter.exe' - '79' Module(s) have been scanned

Scan process 'chrome.exe' - '37' Module(s) have been scanned

Scan process 'chrome.exe' - '37' Module(s) have been scanned

Scan process 'avgnt.exe' - '52' Module(s) have been scanned

Scan process 'sched.exe' - '46' Module(s) have been scanned

Scan process 'avshadow.exe' - '26' Module(s) have been scanned

Scan process 'avguard.exe' - '54' Module(s) have been scanned

Scan process 'chrome.exe' - '56' Module(s) have been scanned

Scan process 'chrome.exe' - '54' Module(s) have been scanned

Scan process 'chrome.exe' - '37' Module(s) have been scanned

Scan process 'chrome.exe' - '40' Module(s) have been scanned

Scan process 'chrome.exe' - '37' Module(s) have been scanned

Scan process 'chrome.exe' - '37' Module(s) have been scanned

Scan process 'chrome.exe' - '37' Module(s) have been scanned

Scan process 'chrome.exe' - '68' Module(s) have been scanned

Scan process 'NOTEPAD.EXE' - '27' Module(s) have been scanned

Scan process 'NOTEPAD.EXE' - '27' Module(s) have been scanned

Scan process 'hpqSTE08.exe' - '50' Module(s) have been scanned

Scan process 'IEMonitor.exe' - '28' Module(s) have been scanned

Scan process 'hpqtra08.exe' - '71' Module(s) have been scanned

Scan process 'svchost.exe' - '34' Module(s) have been scanned

Scan process 'NMIndexStoreSvr.exe' - '52' Module(s) have been scanned

Scan process 'alg.exe' - '34' Module(s) have been scanned

Scan process 'NMIndexingService.exe' - '38' Module(s) have been scanned

Scan process 'wmiapsrv.exe' - '45' Module(s) have been scanned

Scan process 'TuneUpUtilitiesApp32.exe' - '24' Module(s) have been scanned

Scan process 'TeaTimer.exe' - '37' Module(s) have been scanned

Scan process 'SpywareTerminatorUpdate.exe' - '52' Module(s) have been scanned

Scan process 'msnmsgr.exe' - '109' Module(s) have been scanned

Scan process 'IDMan.exe' - '61' Module(s) have been scanned

Scan process 'NMBgMonitor.exe' - '46' Module(s) have been scanned

Scan process 'ctfmon.exe' - '25' Module(s) have been scanned

Scan process 'SpywareTerminatorShield.exe' - '32' Module(s) have been scanned

Scan process 'MSASCui.exe' - '65' Module(s) have been scanned

Scan process 'GrooveMonitor.exe' - '44' Module(s) have been scanned

Scan process 'realsched.exe' - '28' Module(s) have been scanned

Scan process 'jusched.exe' - '21' Module(s) have been scanned

Scan process 'HPWuSchd2.exe' - '19' Module(s) have been scanned

Scan process 'RTHDCPL.EXE' - '37' Module(s) have been scanned

Scan process 'sm56hlpr.exe' - '48' Module(s) have been scanned

Scan process 'PDVDServ.exe' - '25' Module(s) have been scanned

Scan process 'Explorer.EXE' - '164' Module(s) have been scanned

Scan process 'TuneUpUtilitiesService32.exe' - '67' Module(s) have been scanned

Scan process 'svchost.exe' - '42' Module(s) have been scanned

Scan process 'sp_rsser.exe' - '25' Module(s) have been scanned

Scan process 'svchost.exe' - '35' Module(s) have been scanned

Scan process 'svchost.exe' - '30' Module(s) have been scanned

Scan process 'jqs.exe' - '84' Module(s) have been scanned

Scan process 'svchost.exe' - '42' Module(s) have been scanned

Scan process 'spoolsv.exe' - '57' Module(s) have been scanned

Scan process 'svchost.exe' - '42' Module(s) have been scanned

Scan process 'svchost.exe' - '42' Module(s) have been scanned

Scan process 'svchost.exe' - '30' Module(s) have been scanned

Scan process 'svchost.exe' - '175' Module(s) have been scanned

Scan process 'MsMpEng.exe' - '44' Module(s) have been scanned

Scan process 'svchost.exe' - '40' Module(s) have been scanned

Scan process 'svchost.exe' - '54' Module(s) have been scanned

Scan process 'lsass.exe' - '59' Module(s) have been scanned

Scan process 'services.exe' - '36' Module(s) have been scanned

Scan process 'winlogon.exe' - '66' Module(s) have been scanned

Scan process 'csrss.exe' - '14' Module(s) have been scanned

Scan process 'smss.exe' - '2' Module(s) have been scanned

 

Starting master boot sector scan:

Master boot sector HD0

[iNFO] No virus was found!

 

Start scanning boot sectors:

Boot sector 'C:\'

[iNFO] No virus was found!

Boot sector 'E:\'

[iNFO] No virus was found!

 

Starting to scan executable files (registry).

The registry was scanned ( '498' files ).

 

 

Starting the file scan:

 

Begin scan in 'C:\' <Sistema>

Begin scan in 'E:\' <Documentos>

E:\Meus Documentos\Downloads\instala.exe

[DETECTION] Is the TR/Spy.Banker.Gen Trojan

E:\Meus Documentos\Downloads\Internet_Download_Manager_5.19_build_4_%2B_Patch_Upload_Jefferson.rar

[0] Archive type: RAR

[DETECTION] Is the TR/Spy.166912.14 Trojan

--> Internet Download Manager 5.19 build 4 + Patch Upload Jefferson\Patch IDM\Patch 6.xx.exe

[DETECTION] Is the TR/Spy.166912.14 Trojan

E:\Meus Documentos\Downloads\PhotoFiltre_Studio_X_1030.rar

[0] Archive type: RAR

[DETECTION] Is the TR/Horse.SXL Trojan

--> keygen.exe

[DETECTION] Is the TR/Horse.SXL Trojan

--> pfs-setup-en.exe

[1] Archive type: NSIS

--> ProgramFilesDir/PhotoFiltre Studio.htm

[WARNING] The file could not be written!

--> ProgramFilesDir/PhotoMasque.htm

[WARNING] The file could not be written!

--> ProgramFilesDir/Read-me.txt

[WARNING] The file could not be written!

--> ProgramFilesDir/Aeroplan.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Arrow01.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Arrow02.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Arrow03.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Balloon01.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Cat.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Cross.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Envelope.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Fisherman.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Hexagon.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Hunter.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Misc02.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Stamp01.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Stamp02.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Star02.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Triangle02.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Triangle03.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Triangle04.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Australia.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Austria.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Belgium.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Brazil.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Island.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Italy.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Marocoo.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_NorthAmerica.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Norway.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Poland.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Romania.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Spain.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_Sweden.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_UnitedKingdom.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/Map_World.pfs

[WARNING] The file could not be written!

--> ProgramFilesDir/8bf.pfl

[WARNING] The file could not be written!

--> ProgramFilesDir/PfiShellExt.dll

[WARNING] The file could not be written!

--> ProgramFilesDir/Raw.pfl

[WARNING] The file could not be written!

--> ProgramFilesDir/Read-me.txt

[WARNING] The file could not be written!

--> ProgramFilesDir/Border01.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Border03.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Border05.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Border07.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Border09.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Border10.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Border11.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Border13.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Border14.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Camera01.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Camera03.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Camera07.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Camera08.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame02.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame03.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame04.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame05.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame08.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame09.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame10.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame11.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Misc01.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Misc03.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Misc04.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Misc06.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Misc07.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Brush.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Bubbles.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Chaos.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Dilution.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Ellipse.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Flame.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Fog.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Keyhole.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Lines.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Motion.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Pastels.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Radial.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Slide.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Snowflake.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Star.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Watercolor.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Stamp02.gif

[WARNING] The file could not be written!

--> ProgramFilesDir/Star04.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Braid01.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Braid02.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Canvas03.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Color01.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Color02.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Color03.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Fabric01.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Fabric03.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Marble02.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Metal01.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Metal02.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Metal04.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Nature01.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Paper02.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Wall01.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Wall03.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Wood01.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Animals.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Decoration.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Default.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Digital.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Flowers.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Pastels.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Space.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Splash.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Butterflies.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Cord.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Flowers.png

[WARNING] The file could not be written!

--> ProgramFilesDir/PFS.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Rabbits.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Shells.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Star01.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Texture03.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Texture08.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Texture09.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Texture12.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Texture13.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Texture15.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Texture17.jpg

[WARNING] The file could not be written!

--> ProgramFilesDir/Flower01.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Flower02.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame01.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame02.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame03.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame04.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Frame05.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Nature01.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Nature02.png

[WARNING] The file could not be written!

--> ProgramFilesDir/Curve 01.pfv

[WARNING] The file could not be written!

--> ProgramFilesDir/Curve 03.pfv

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Diamond.pfv

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Heart.pfv

[WARNING] The file could not be written!

--> ProgramFilesDir/PF-Spade.pfv

[WARNING] The file could not be written!

[WARNING] The file could not be written!

 

Beginning disinfection:

E:\Meus Documentos\Downloads\PhotoFiltre_Studio_X_1030.rar

[DETECTION] Is the TR/Horse.SXL Trojan

[NOTE] The file was moved to the quarantine directory under the name '4a1df6e1.qua'.

E:\Meus Documentos\Downloads\Internet_Download_Manager_5.19_build_4_%2B_Patch_Upload_Jefferson.rar

[DETECTION] Is the TR/Spy.166912.14 Trojan

[NOTE] The file was moved to the quarantine directory under the name '5281d94c.qua'.

E:\Meus Documentos\Downloads\instala.exe

[DETECTION] Is the TR/Spy.Banker.Gen Trojan

[NOTE] The file was moved to the quarantine directory under the name '00d183a4.qua'.

 

 

End of the scan: segunda-feira, 17 de janeiro de 2011 11:28

Used time: 40:04 Minute(s)

 

The scan has been done completely.

 

6511 Scanned directories

195919 Files were scanned

3 Viruses and/or unwanted programs were found

0 Files were classified as suspicious

0 files were deleted

0 Viruses and unwanted programs were repaired

3 Files were moved to quarantine

0 Files were renamed

0 Files cannot be scanned

195916 Files not concerned

2165 Archives were scanned

138 Warnings

3 Notes

360358 Objects were scanned with rootkit scan

1 Hidden objects were found

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 =======

 

Updated by TeamXscript on 16/01/11 at 02:00

Contact: AdRemover[DOT]contact[AT]gmail[DOT]com

website: http://www.teamxscript.org

 

C:\Arquivos de programas\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 10:05:31 on 17/01/2011, Normal boot

 

Microsoft Windows XP Professional Service Pack 3 (X86)

Usuario@MIGUEL ( )

 

============== ACTION(S) ==============

 

 

File deleted: C:\Arquivos de programas\Mozilla FireFox\searchplugins\crawlersrch.xml

File deleted: C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

Folder deleted: C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\extensions\toolbar@ask.com

Folder deleted: C:\Arquivos de programas\Ask.com

Folder deleted: C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\AskToolbar

Folder deleted: C:\Arquivos de programas\Crawler

 

(!) -- Temporary files deleted.

 

 

-- File opened: C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\Prefs.js --

Line deleted: user_pref("browser.search.defaultenginename", "Crawler Search");

Line deleted: user_pref("browser.search.order.1", "Crawler Search");

Line deleted: user_pref("extensions.asktb.cbid", "F4");

Line deleted: user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}...

Line deleted: user_pref("extensions.asktb.dtid", "YYYYYYYYBR");

Line deleted: user_pref("extensions.asktb.fresh-install", false);

Line deleted: user_pref("extensions.asktb.l", "dis");

Line deleted: user_pref("extensions.asktb.last-config-req", "1321496627732");

Line deleted: user_pref("extensions.asktb.locale", "en_US");

Line deleted: user_pref("extensions.asktb.o", "101699");

Line deleted: user_pref("extensions.asktb.overlay-reloaded-using-restart", true);

Line deleted: user_pref("extensions.asktb.qsrc", "2871");

Line deleted: user_pref("extensions.asktb.r", "4");

Line deleted: user_pref("extensions.asktb.search-suggestions-enabled", true);

Line deleted: user_pref("extensions.asktb.v", "3.8.0.99999");

Line deleted: user_pref("extensions.enabledItems", "{b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1,{CAFEEFAC-0016-00...

-- File closed --

 

 

Key deleted: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}

Key deleted: HKLM\Software\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}

Key deleted: HKLM\Software\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Key deleted: HKLM\Software\Classes\CLSID\{1DDA201E-5B42-4352-933E-21A92B297E3B}

Key deleted: HKLM\Software\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

Key deleted: HKLM\Software\Classes\CLSID\{4D25FB7A-8902-4291-960E-9ADA051CFBBF}

Key deleted: HKLM\Software\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}

Key deleted: HKLM\Software\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}

Key deleted: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}

Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}

Key deleted: HKLM\Software\Classes\CLSID\{DBDB6FAA-1F5F-4A18-B60B-7A905C7FF83F}

Key deleted: HKLM\Software\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}

Key deleted: HKLM\Software\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}

Key deleted: HKLM\Software\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}

Key deleted: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}

Key deleted: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}

Key deleted: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}

Key deleted: HKLM\Software\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}

Key deleted: HKLM\Software\Classes\TypeLib\{04006843-5199-4CE4-B3CD-8092CC91706E}

Key deleted: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}

Key deleted: HKLM\Software\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}

Key deleted: HKLM\Software\Classes\TypeLib\{E79BB61D-7F1A-41DF-8AD0-402795E3B566}

Key deleted: HKLM\Software\Classes\ctbcommon.Buttons

Key deleted: HKLM\Software\Classes\ctbr.R404Pro

Key deleted: HKLM\Software\Classes\CToolbar.TB4Client

Key deleted: HKLM\Software\Classes\CToolbar.TB4Script

Key deleted: HKLM\Software\Classes\CToolbar.TB4Server

Key deleted: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd

Key deleted: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1

Key deleted: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL

Key deleted: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}

Key deleted: HKLM\Software\CToolbar

Key deleted: HKCU\Software\Ask.com

Key deleted: HKCU\Software\AskToolbar

Key deleted: HKCU\Software\CToolbar

Key deleted: HKCU\Software\AppDataLow\AskToolbarInfo

Key deleted: HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF

Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF

Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Key deleted: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}

Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}

Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\CToolbar_UNINSTALL

Key deleted: HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search

Key deleted: HKLM\Software\Classes\PROTOCOLS\Handler\tbr

Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\Crawler

 

Value deleted: HKLM\Software\Mozilla\Firefox\Extensions|{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

Value deleted: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}

Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}

Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

Value deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}

Value deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

 

 

============== ADDITIONNAL SCAN ==============

 

** Mozilla Firefox Version [3.6.13 (pt-BR)] **

 

-- C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\Prefs.js --

browser.download.lastDir, C:\\Documents and Settings\\Usuario\\Desktop\\BUENOS AIRES

browser.search.selectedEngine, Google

browser.startup.homepage, hxxp://www.crawler.com/homepage.aspx?tbid=60076

browser.startup.homepage_override.mstone, rv:1.9.2.13

keyword.URL, hxxp://search.instantfirefox.com/google#q=

 

========================================

 

** Internet Explorer Version [8.0.6001.18702] **

 

[HKCU\Software\Microsoft\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

Do404Search: 0x01000000

Enable Browser Extensions: yes

Local Page: C:\WINDOWS\system32\blank.htm

Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896

Show_ToolBar: yes

Start Page: hxxp://fr.msn.com/

Use Search Asst: no

 

[HKLM\Software\Microsoft\Internet Explorer\Main]

Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896

Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

Delete_Temp_Files_On_Exit: yes

Local Page: C:\WINDOWS\system32\blank.htm

Search bar: hxxp://search.msn.com/spbasic.htm

Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

Start Page: hxxp://fr.msn.com/

 

[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]

Tabs: res://ieframe.dll/tabswelcome.htm

Blank: res://mshtml.dll/blank.htm

 

========================================

 

C:\Arquivos de programas\Ad-Remover\Quarantine: 331 File(s)

C:\Arquivos de programas\Ad-Remover\Backup: 15 File(s)

 

C:\Ad-Report-CLEAN[1].txt - 17/01/2011 (8062 Byte(s))

C:\Ad-Report-SCAN[1].txt - 15/01/2011 (8957 Byte(s))

 

End at: 10:09:41, 17/01/2011

 

============== E.O.F ==============

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

======= REPORT FROM AD-REMOVER 2.0.0.2,D | ONLY XP/VISTA/7 =======

 

Updated by TeamXscript on 16/01/11 at 02:00

Contact: AdRemover[DOT]contact[AT]gmail[DOT]com

website: http://www.teamxscript.org

 

C:\Arquivos de programas\Ad-Remover\main.exe (CLEAN [2]) -> Launched at 10:18:16 on 17/01/2011, Normal boot

 

Microsoft Windows XP Professional Service Pack 3 (X86)

Usuario@MIGUEL ( )

 

============== ACTION(S) ==============

 

 

 

(!) -- Temporary files deleted.

 

 

Key deleted: HKCU\Software\Microsoft\Internet Explorer\MenuExt\Crawler Search

 

 

============== ADDITIONNAL SCAN ==============

 

** Mozilla Firefox Version [3.6.13 (pt-BR)] **

 

-- C:\Documents and Settings\Usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\3mjwaakv.default\Prefs.js --

browser.download.lastDir, C:\\Documents and Settings\\Usuario\\Desktop\\BUENOS AIRES

browser.search.selectedEngine, Google

browser.startup.homepage, hxxp://www.crawler.com/homepage.aspx?tbid=60076

browser.startup.homepage_override.mstone, rv:1.9.2.13

keyword.URL, hxxp://search.instantfirefox.com/google#q=

 

========================================

 

** Internet Explorer Version [8.0.6001.18702] **

 

[HKCU\Software\Microsoft\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

Do404Search: 0x01000000

Enable Browser Extensions: yes

Local Page: C:\WINDOWS\system32\blank.htm

Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896

Show_ToolBar: yes

Start Page: hxxp://fr.msn.com/

Use Search Asst: no

 

[HKLM\Software\Microsoft\Internet Explorer\Main]

Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896

Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

Delete_Temp_Files_On_Exit: yes

Local Page: C:\WINDOWS\system32\blank.htm

Search bar: hxxp://search.msn.com/spbasic.htm

Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

Start Page: hxxp://fr.msn.com/

 

[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]

Tabs: res://ieframe.dll/tabswelcome.htm

Blank: res://mshtml.dll/blank.htm

 

========================================

 

C:\Arquivos de programas\Ad-Remover\Quarantine: 331 File(s)

C:\Arquivos de programas\Ad-Remover\Backup: 16 File(s)

 

C:\Ad-Report-CLEAN[1].txt - 17/01/2011 (9473 Byte(s))

C:\Ad-Report-CLEAN[2].txt - 17/01/2011 (2238 Byte(s))

C:\Ad-Report-SCAN[1].txt - 15/01/2011 (8957 Byte(s))

 

End at: 10:19:28, 17/01/2011

 

============== E.O.F ==============

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

Logfile of HijackThis v1.99.1

Scan saved at 10:14:24, on 17/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Windows Defender\MSASCui.exe

C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Internet Download Manager\IDMan.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R3 - Default URLSearchHook is missing

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [Windows Defender] "C:\Arquivos de programas\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Vários outros problemas foram removidos.

___________________

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked:

 

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)

 

O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

____________________

 

:seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

Faça o download do ComboFix

Salve-o no Desktop (área de trabalho).

* Desabilite as proteções residente de: antivírus, antispywares e firewall ( menos o do Windows! )

* Feche todas as janelas e execute a ferramenta.

* Ps: A execução, por comando, também é possível:

* Vá em Iniciar --> Executar --> Digite ou cole:

"%userprofile%\desktop\Combofix.exe" /killall

 

combofixejr8.gif

 

* Clique em Ok.

* Na solicitação: "Negação de garantia de software" --> Clique em Sim.

 

RcAuto1.gif

 

* Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo.

* Terminando,clique Sim ou Yes. --> Aguarde.

 

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

 

:!: Caso aconteça a notificação de: Aplicativo Win32 inválido ou alguma mensagem parecida com esta, delete a ferramenta ComboFix.exe e faça, novamente, seu download.

* Salve-a no Desktop,renomeada como: Kombo.exe

* Ps: Nomeie durante o salvamento,e não após salvá-la!

* Ps: Surgindo alguma mensagem de erro, rode o ComboFix.exe em "Modo Seguro". <-- Link!

* Ps: Na presença de atividades rootkit,teremos a seguinte janela de notificação:

 

Rookit_found.gif

 

* Ps: Anote essas detecções, e dê o OK. Neste caso poste estas detecções que você terá anotado em sua próxima resposta juntamente com os logs pedidos.

* Ps: Para completar as remoções, talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!

* Ps: Para evitar problemas, siga todas as recomendações propostas.

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

 

* Abrir-se-á a janela Auto Scan. --> Aguarde!

* Para finalizar remoções, o ComboFix poderá reiniciar o computador.

* Se houver necessidade, digite a opção ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!

* Durante o scan, evite manusear o mouse ou teclado! <-- Importante!

* Caso, por algum motivo de força maior, precise parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter.

<><><><><><><><><><><><>

 

Poste o log do Combofix que estará em C:\ComboFix.txt juntamente com um novo log do Hijackthis em sua próxima resposta e nos diga como está o seu PC depois disto.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Vários outros problemas foram removidos.

___________________

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked:

 

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)

 

O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

____________________

 

:seta: Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

Faça o download do ComboFix

Salve-o no Desktop (área de trabalho).

* Desabilite as proteções residente de: antivírus, antispywares e firewall ( menos o do Windows! )

* Feche todas as janelas e execute a ferramenta.

* Ps: A execução, por comando, também é possível:

* Vá em Iniciar --> Executar --> Digite ou cole:

"%userprofile%\desktop\Combofix.exe" /killall

 

combofixejr8.gif

 

* Clique em Ok.

* Na solicitação: "Negação de garantia de software" --> Clique em Sim.

 

RcAuto1.gif

 

* Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo.

* Terminando,clique Sim ou Yes. --> Aguarde.

 

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

 

:!: Caso aconteça a notificação de: Aplicativo Win32 inválido ou alguma mensagem parecida com esta, delete a ferramenta ComboFix.exe e faça, novamente, seu download.

* Salve-a no Desktop,renomeada como: Kombo.exe

* Ps: Nomeie durante o salvamento,e não após salvá-la!

* Ps: Surgindo alguma mensagem de erro, rode o ComboFix.exe em "Modo Seguro". <-- Link!

* Ps: Na presença de atividades rootkit,teremos a seguinte janela de notificação:

 

Rookit_found.gif

 

* Ps: Anote essas detecções, e dê o OK. Neste caso poste estas detecções que você terá anotado em sua próxima resposta juntamente com os logs pedidos.

* Ps: Para completar as remoções, talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!

* Ps: Para evitar problemas, siga todas as recomendações propostas.

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

 

* Abrir-se-á a janela Auto Scan. --> Aguarde!

* Para finalizar remoções, o ComboFix poderá reiniciar o computador.

* Se houver necessidade, digite a opção ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!

* Durante o scan, evite manusear o mouse ou teclado! <-- Importante!

* Caso, por algum motivo de força maior, precise parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter.

<><><><><><><><><><><><>

 

Poste o log do Combofix que estará em C:\ComboFix.txt juntamente com um novo log do Hijackthis em sua próxima resposta e nos diga como está o seu PC depois disto.

 

Ficamos no aguardo.

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

Olá Antônio,

 

mais uma vez segui todos os passos por ti sugeridos, segue adiante os logs solicitados.

 

P.S:

 

A entrada a que referiste não estava presente no Hijack This:

 

O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

ComboFix 11-01-16.04 - Usuario 17/01/2011 15:07:19.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.3005.2080 [GMT -3:00]

Executando de: e:\meus documentos\Downloads\Programs\ComboFix.exe

AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Autorun.inf

 

A cópia de c:\windows\regedit.exe foi encontrada e desinfectada

Cópia restaurada de - c:\windows\VistaMizer\old\regedit.exe

 

A cópia de c:\windows\system32\midimap.dll foi encontrada e desinfectada

Cópia restaurada de - c:\windows\VistaMizer\old\midimap.dll

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2010-12-17 to 2011-01-17 ))))))))))))))))))))))))))))

.

 

2011-01-17 14:41 . 2011-01-17 14:41 -------- d-----r- c:\documents and settings\LocalService\Favoritos

2011-01-17 13:46 . 2011-01-17 14:18 -------- d-----w- c:\windows\system32\NtmsData

2011-01-17 13:45 . 2011-01-17 13:45 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Avira

2011-01-17 13:26 . 2010-12-13 11:40 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2011-01-17 13:26 . 2010-12-13 11:40 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys

2011-01-17 13:26 . 2010-06-17 17:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys

2011-01-17 13:26 . 2010-06-17 17:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys

2011-01-17 13:26 . 2011-01-17 13:26 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Avira

2011-01-17 13:26 . 2011-01-17 13:26 -------- d-----w- c:\arquivos de programas\Avira

2011-01-16 02:44 . 2011-01-16 02:47 -------- d-----w- C:\LinhaDefensiva

2011-01-16 01:34 . 2011-01-16 01:34 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Malwarebytes

2011-01-16 01:34 . 2010-12-20 21:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-01-16 01:34 . 2011-01-16 01:34 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2011-01-16 01:34 . 2011-01-16 01:34 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2011-01-16 01:34 . 2010-12-20 21:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-01-16 01:29 . 2011-01-16 01:29 -------- d-----w- c:\arquivos de programas\Ad-Remover

2011-01-15 14:55 . 2011-01-15 16:48 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spybot - Search & Destroy

2011-01-15 14:55 . 2011-01-15 15:17 -------- d-----w- c:\arquivos de programas\Spybot - Search & Destroy

2011-01-15 13:05 . 2011-01-15 13:05 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys

2011-01-15 13:05 . 2011-01-17 17:53 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Spyware Terminator

2011-01-15 13:04 . 2011-01-17 16:06 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Spyware Terminator

2011-01-15 13:04 . 2011-01-16 02:28 -------- d-----w- c:\arquivos de programas\Spyware Terminator

2011-01-15 12:24 . 2007-03-09 14:25 2321288 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll

2011-01-15 12:24 . 2010-11-16 15:01 6273872 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Microsoft\Windows Defender\Definition Updates\{64602B69-06C2-40B3-BDE1-8B15AD8AA92B}\mpengine.dll

2011-01-15 12:24 . 2010-10-19 13:41 222080 ------w- c:\windows\system32\MpSigStub.exe

2011-01-15 12:21 . 2011-01-15 12:21 -------- d-----w- c:\arquivos de programas\Windows Defender

2011-01-15 01:34 . 2011-01-15 01:34 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\QuickScan

2011-01-12 13:00 . 2011-01-12 13:00 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Media Player Classic

2011-01-10 08:41 . 2011-01-10 08:41 -------- d-----w- c:\arquivos de programas\Pcsx2

2011-01-09 16:45 . 2011-01-09 16:45 -------- d-----w- c:\arquivos de programas\VirtualDJ

2011-01-03 12:22 . 2011-01-03 12:22 -------- d-----w- c:\arquivos de programas\Free DVD MP3 Ripper

2011-01-01 15:48 . 2011-01-01 15:48 -------- d-----w- c:\arquivos de programas\Ashampoo

2010-12-28 11:52 . 2010-12-28 11:52 -------- d-----w- c:\arquivos de programas\FreeTime

2010-12-28 11:33 . 2010-12-28 11:33 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\VOWSoft

2010-12-28 11:33 . 2010-12-28 11:35 -------- d-----w- c:\arquivos de programas\ABC 3GP Converter

2010-12-28 03:04 . 2010-12-28 03:04 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\Foxit Software

2010-12-27 15:53 . 2010-12-27 15:53 -------- d-----w- c:\arquivos de programas\visao

2010-12-26 02:26 . 2010-12-26 02:26 -------- d-----w- c:\documents and settings\Usuario\Configurações locais\Dados de aplicativos\WMTools Downloaded Files

2010-12-20 19:00 . 2010-12-20 19:00 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Windows Live

2010-12-20 18:06 . 2010-12-20 18:21 -------- d-----w- c:\documents and settings\Usuario\Dados de aplicativos\PhotoFiltre Studio X

2010-12-20 18:06 . 2010-12-20 18:29 -------- d-----w- c:\arquivos de programas\PhotoFiltre Studio X

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-12-02 03:35 . 2010-12-02 03:35 4280320 ----a-w- c:\windows\system32\GPhotos.scr

2010-12-01 17:29 . 2010-12-10 22:34 31552 ----a-w- c:\windows\system32\TURegOpt.exe

2010-12-01 17:25 . 2010-12-10 22:34 29504 ----a-w- c:\windows\system32\uxtuneup.dll

2010-11-18 18:15 . 2010-09-07 15:47 86016 ----a-w- c:\windows\system32\isign32.dll

2010-11-12 21:53 . 2010-09-23 16:38 472808 ----a-w- c:\windows\system32\deployJava1.dll

2010-11-12 19:34 . 2010-09-23 16:38 73728 ----a-w- c:\windows\system32\javacpl.cpl

2010-11-09 14:52 . 2008-04-13 21:20 249856 ----a-w- c:\windows\system32\odbc32.dll

2010-11-06 00:21 . 2008-04-13 21:20 916480 ----a-w- c:\windows\system32\wininet.dll

2010-11-06 00:21 . 2008-04-13 21:21 1469440 ----a-w- c:\windows\system32\inetcpl.cpl

2010-11-06 00:21 . 2008-04-13 21:20 43520 ----a-w- c:\windows\system32\licmgr10.dll

2010-11-03 12:27 . 2008-04-13 20:55 385024 ----a-w- c:\windows\system32\html.iec

2010-11-02 15:17 . 2008-04-13 13:57 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys

2010-10-28 13:09 . 2008-04-13 21:18 290048 ----a-w- c:\windows\system32\atmfd.dll

2010-10-26 14:04 . 2009-05-02 02:37 1862400 ----a-w- c:\windows\system32\win32k.sys

.

 

------- Sigcheck -------

 

[-] 2008-04-13 . B0C0BF2504B830BFC1E93CA39F3C75FE . 549376 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

[-] 2008-04-13 . B0C0BF2504B830BFC1E93CA39F3C75FE . 549376 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\winlogon.exe

[7] 2008-04-13 . 71D440F79B711627B12B567FB2EADB42 . 509952 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\winlogon.exe

 

[-] 2008-04-13 . 7C0E5D593730414B5994A15A6D10C201 . 588288 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll

[-] 2008-04-13 . 7C0E5D593730414B5994A15A6D10C201 . 588288 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\user32.dll

[7] 2008-04-13 . 54907DB28872A7A6D3EE2B4747A23828 . 579072 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\user32.dll

 

[-] 2008-04-13 . F1A3E95588DB92660C8C6DAA9101D49B . 1554432 . . [6.00.2900.5512] . . c:\windows\explorer.exe

[-] 2008-04-13 . F1A3E95588DB92660C8C6DAA9101D49B . 1554432 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\explorer.exe

[7] 2008-04-13 . 064EC7FF5F58B928C3E119402977FA6D . 1035776 . . [6.00.2900.5512] . . c:\windows\VistaMizer\old\explorer.exe

 

[-] 2008-04-13 . D67945A2290E98BB54D7792F09E7504E . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe

[-] 2008-04-13 . D67945A2290E98BB54D7792F09E7504E . 25088 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ctfmon.exe

[7] 2008-04-13 . 4E486ADFE3A0B9ED0EB0639902E9F64F . 15360 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ctfmon.exe

 

[7] 2010-04-29 . 7FDAC9D0C4F6EBC61160EC9F00F03C20 . 2071168 . . [5.1.2600.5973] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe

[-] 2010-04-28 . 27701C241C40FA5F23DB1F92993FD51D . 2285568 . . [5.1.2600.5973] . . c:\windows\system32\ntkrnlpa.exe

[-] 2010-04-28 . 27701C241C40FA5F23DB1F92993FD51D . 2285568 . . [5.1.2600.5973] . . c:\windows\system32\dllcache\ntkrnlpa.exe

[7] 2010-04-28 . BB68023414EBBEDC12D413E8FEA056A8 . 2028544 . . [5.1.2600.5973] . . c:\windows\VistaMizer\old\ntkrnlpa.exe

[7] 2009-05-03 . B82DF02FCDE92772201E59F0C9AC7E60 . 2028032 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB981852$\ntkrnlpa.exe

 

[-] 2009-03-08 . C94590AF0DB0E97199688FF1A77037D2 . 727904 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\iexplore.exe

[7] 2009-03-08 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702] . . c:\windows\VistaMizer\old\iexplore.exe

[7] 2008-04-13 . 04CABAD69BE78EB9C03CD4346D776DA5 . 93184 . . [6.00.2900.5512] . . c:\windows\ie8\iexplore.exe

 

[7] 2010-04-28 . 2B14801C5D196E8BEC3EA573B3B2DA44 . 2194304 . . [5.1.2600.5973] . . c:\windows\Driver Cache\i386\ntoskrnl.exe

[-] 2010-04-28 . 46D199719181A8BE461E56D1975D6ED2 . 2407424 . . [5.1.2600.5973] . . c:\windows\system32\ntoskrnl.exe

[-] 2010-04-28 . 46D199719181A8BE461E56D1975D6ED2 . 2407424 . . [5.1.2600.5973] . . c:\windows\system32\dllcache\ntoskrnl.exe

[7] 2010-04-28 . 235F0AD0AEF8530F06A54453F235B23C . 2150400 . . [5.1.2600.5973] . . c:\windows\VistaMizer\old\ntoskrnl.exe

[7] 2009-05-03 . 3523020464F53C8FF7A3A59661F1CAA2 . 2149376 . . [5.1.2600.5755] . . c:\windows\$NtUninstallKB981852$\ntoskrnl.exe

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]

"Google Update"="c:\documents and settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" [2010-09-08 136176]

"IDMan"="c:\arquivos de programas\Internet Download Manager\IDMan.exe" [2010-10-12 3245408]

"SpywareTerminatorUpdate"="c:\arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe" [2011-01-15 3318784]

"SpybotSD TeaTimer"="c:\arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]

"SMSERIAL"="c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe" [2008-02-21 1216512]

"RTHDCPL"="RTHDCPL.EXE" [2009-08-24 18702336]

"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]

"SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-05-14 248552]

"TkBellExe"="c:\arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" [2010-10-04 202256]

"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]

"SpywareTerminator"="c:\arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe" [2011-01-15 2216960]

"avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2010-12-13 281768]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 25088]

"DWQueuedReporting"="c:\arquiv~1\ARQUIV~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

 

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

@="Service"

 

[HKLM\~\startupfolder\C:^Documents and Settings^Usuario^Menu Iniciar^Programas^Inicializar^Recorte de tela e Iniciador do OneNote 2007.lnk]

path=c:\documents and settings\Usuario\Menu Iniciar\Programas\Inicializar\Recorte de tela e Iniciador do OneNote 2007.lnk

backup=c:\windows\pss\Recorte de tela e Iniciador do OneNote 2007.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

2010-09-21 18:37 932288 ----a-w- c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]

2009-07-26 19:44 3883840 ----a-w- c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]

2003-12-08 20:35 32768 ----a-w- c:\arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Arquivos de programas\\Ares\\Ares.exe"=

"c:\\Arquivos de programas\\Google\\Google Earth\\client\\googleearth.exe"=

"c:\\Arquivos de programas\\Megacubo\\megacubo.exe"=

"c:\\Arquivos de programas\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=

 

R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [15/1/2011 10:05 142592]

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [17/1/2011 10:26 135336]

R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [1/12/2010 14:27 1483072]

R2 WinDefend;Windows Defender;c:\arquivos de programas\Windows Defender\MsMpEng.exe [3/11/2006 19:19 13592]

R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [7/9/2010 20:42 113504]

R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [7/9/2010 20:46 335104]

R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [7/10/2010 12:34 10064]

S2 gupdate;Google Update Service (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [8/9/2010 18:58 136176]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [7/9/2010 20:43 1684736]

S3 smsbda;SMS Digital Video;c:\windows\system32\drivers\smsbda.sys [30/10/2010 01:39 51872]

S3 ZTEusbdvbh;ZTE HS-USB DVBH-RF Service;c:\windows\system32\drivers\ZTEusbdvbh.sys [30/10/2010 01:39 105216]

 

--- =Outros Serviços/Drivers Na Memória ---

 

*NewlyCreated* - SSMDRV

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

UxTuneUp

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2011-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-09-08 21:58]

 

2011-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-09-08 21:58]

 

2011-01-17 c:\windows\Tasks\MP Scheduled Scan.job

- c:\arquivos de programas\Windows Defender\MpCmdRun.exe [2006-11-03 22:20]

 

2011-01-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job

- c:\arquivos de programas\Real\RealUpgrade\realupgrade.exe [2010-06-03 06:02]

 

2011-01-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job

- c:\arquivos de programas\Real\RealUpgrade\realupgrade.exe [2010-06-03 06:02]

.

.

------- Scan Suplementar -------

.

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: Crawler Search

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~3\Office12\EXCEL.EXE/3000

IE: Fazer o download de conteúdo de vídeo FLV usando o IDM - c:\arquivos de programas\Internet Download Manager\IEGetVL.htm

IE: Fazer o download de todos os links usando o IDM - c:\arquivos de programas\Internet Download Manager\IEGetAll.htm

IE: Fazer o download usando o IDM - c:\arquivos de programas\Internet Download Manager\IEExt.htm

LSP: c:\windows\system32\idmmbc.dll

FF - ProfilePath - c:\documents and settings\Usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\3mjwaakv.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.crawler.com/homepage.aspx?tbid=60076

FF - prefs.js: keyword.URL - hxxp://search.instantfirefox.com/google#q=

FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\arquivos de programas\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

FF - Ext: Instant Firefox: instantfirefox@crossrider.com - %profile%\extensions\instantfirefox@crossrider.com

FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}

FF - Ext: Java Quick Starter: jqs@sun.com - c:\arquivos de programas\Java\jre6\lib\deploy\jqs\ff

FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

FF - Ext: IDM CC: mozilla_cc@internetdownloadmanager.com - c:\documents and settings\Usuario\Dados de aplicativos\IDM\idmmzcc3

.

- - - - ORFÃOS REMOVIDOS - - - -

 

BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-01-17 15:12

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{14190654-4dd9-457a-b001-8cd81c3932e5}]

@Denied: (Full) (Everyone)

"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,

1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]

@Denied: (Full) (Everyone)

"scansk"=hex(0):e3,ac,aa,f3,bd,58,85,e1,7e,de,cd,55,be,cc,6d,d5,68,0a,bc,14,b2,

34,b7,09,aa,87,cd,49,ee,7f,64,b7,a3,fd,33,07,89,64,8e,4b,00,00,00,00,00,00,\

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

 

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

 

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

 

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

 

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

 

- - - - - - - > 'winlogon.exe'(860)

c:\windows\system32\SETUPAPI.dll

c:\windows\system32\sfc_os.dll

c:\windows\system32\COMRes.dll

c:\windows\system32\cscui.dll

 

- - - - - - - > 'lsass.exe'(916)

c:\windows\system32\setupapi.dll

c:\windows\system32\psbase.dll

c:\windows\system32\idmmbc.dll

 

- - - - - - - > 'explorer.exe'(984)

c:\windows\system32\SHDOCVW.dll

c:\windows\system32\WININET.dll

c:\windows\system32\COMRes.dll

c:\windows\System32\cscui.dll

c:\arquiv~1\WINDOW~2\wmpband.dll

c:\windows\system32\LINKINFO.dll

c:\windows\system32\ntshrui.dll

c:\arquivos de programas\Internet Download Manager\idmmkb.dll

c:\windows\system32\msi.dll

c:\windows\system32\SETUPAPI.dll

c:\windows\system32\NETSHELL.dll

c:\windows\system32\credui.dll

c:\windows\system32\MSVCP60.dll

c:\windows\system32\wpdshserviceobj.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\portabledevicetypes.dll

c:\windows\system32\portabledeviceapi.dll

c:\arquivos de programas\Internet Download Manager\IDMIECC.dll

c:\arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

c:\arquivos de programas\Microsoft Office\Office12\1046\GrooveIntlResource.dll

c:\arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\PDFShell.dll

c:\arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\PDFShell.PTB

.

------------------------ Outros Processos em Execução ------------------------

.

c:\arquivos de programas\Avira\AntiVir Desktop\avguard.exe

c:\arquivos de programas\Java\jre6\bin\jqs.exe

c:\arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

c:\arquivos de programas\Spyware Terminator\sp_rsser.exe

c:\windows\RTHDCPL.EXE

c:\windows\system32\wbem\wmiapsrv.exe

c:\arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

c:\arquivos de programas\Internet Download Manager\IEMonitor.exe

c:\arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

.

**************************************************************************

.

Tempo para conclusão: 2011-01-17 15:18:14 - Máquina reiniciou

ComboFix-quarantined-files.txt 2011-01-17 18:18

 

Pré-execução: 6 pasta(s) 88.452.485.120 bytes disponíveis

Pós execução: 9 pasta(s) 88.557.477.888 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

- - End Of File - - EE7C35A9F56E48FACA88EBA6926539F4

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Logfile of HijackThis v1.99.1

Scan saved at 15:27:57, on 17/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Internet Download Manager\IDMan.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Adobe\Reader 9.0\Reader\AcroRd32.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [spywareTerminator] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Mais problemas removidos pelo Combofix.

 

:seta: Siga, por gentileza, as dicas destes tutoriais:

 

Tutorial do USBFix

 

Tutorial do Norman Malware Cleaner

_____________________

 

:seta: Poste o log do Usbfix que estará em C:\UsbFix.txt em sua próxima resposta juntamente com um novo log do Hijackthis e o log do Norman Malware Cleaner e nos diga como está o PC após estes procedimentos.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Mais problemas removidos pelo Combofix.

 

:seta: Siga, por gentileza, as dicas destes tutoriais:

 

Tutorial do USBFix

 

Tutorial do Norman Malware Cleaner

_____________________

 

:seta: Poste o log do Usbfix que estará em C:\UsbFix.txt em sua próxima resposta juntamente com um novo log do Hijackthis e o log do Norman Malware Cleaner e nos diga como está o PC após estes procedimentos.

 

Ficamos no aguardo.

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Olá Antonio...

 

conforme orientações, seguem os LOGS dos programas indicados:

 

 

Norman Malware Cleaner

Version 1.8.3

Copyright © 1990 - 2010, Norman ASA. Built 2011/01/17 15:43:01

 

Norman Scanner Engine Version: 6.06.12

Nvcbin.def Version: 6.06.00, Date: 2011/01/17 15:43:01, Variants: 9156159

 

Scan started: 2011/01/18 17:15:45

 

Running pre-scan cleanup routine:

Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3

Logged on user: MIGUEL\Usuario

 

Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = -> ""

 

Scanning kernel...

 

Kernel scan complete

 

 

Scanning bootsectors...

 

Number of sectors found: 2

Number of sectors scanned: 2

Number of sectors not scanned: 0

Number of infections found: 0

Number of infections removed: 0

Total scanning time: 0s 32ms

 

 

Scanning running processes and process memory...

 

Number of processes/threads found: 3027

Number of processes/threads scanned: 3027

Number of processes/threads not scanned: 0

Number of infected processes/threads terminated: 0

Total scanning time: 1m 52s

 

 

Scanning file system...

 

Scanning: prescan

 

Scanning: C:\*.*

 

C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6/NERO_I~2.007 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6/NERO_S~1.006 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6/NERO_U~1.005 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6/NERO_V~1.004 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe/noname.nsis/file0/file6/NERO_V~2.003 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Cache\f_000632/file0 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\System Volume Information\_restore{2E688FF2-C923-4539-BED5-D6B4329EC271}\RP85\A0056031.dll (Infected with W32/Hacktool.KQU)

Deleted file

 

Scanning: E:\*.*

 

E:\Meus Documentos\Downloads\Atomix Virtual DJ Pro 6.1.2 (b301)\Activator Virtual DJ 6.1.2.exe (Infected with W32/Suspicious_Gen.NHP.dropper)

Deleted file

 

E:\Meus Documentos\Downloads\aTube_Catcher.exe/noname.nsis/file0/file26 (Error whilst scanning file: I/O Error (0x00220005))

 

E:\Meus Documentos\Downloads\dexpot_156_r1351.exe/noname.nsis/file0/file64 (Error whilst scanning file: I/O Error (0x00220005))

 

E:\Meus Documentos\Downloads\PCDJ_DEX\setup_dex_1.1.7269.exe/noname.nsis/file0/file14 (Error whilst scanning file: I/O Error (0x00220005))

 

E:\Meus Documentos\Downloads\PCDJ_DEX.rar/setup_dex_1.1.7269.exe/noname.nsis/file0/file14 (Error whilst scanning file: I/O Error (0x00220005))

 

E:\Meus Documentos\Downloads\redmobile\pcdjredmobile_1.1.7269.exe/noname.nsis/file0/file19 (Error whilst scanning file: I/O Error (0x00220005))

 

E:\Meus Documentos\Downloads\redmobile.rar/pcdjredmobile_1.1.7269.exe/noname.nsis/file0/file19 (Error whilst scanning file: I/O Error (0x00220005))

 

E:\Meus Documentos\Downloads\VDJ Pro 6.1.2 (b301) + Tradução pt_BR.zip/Atomix Virtual DJ Pro 6.1.2 (b301)/Activator Virtual DJ 6.1.2.exe (Infected with W32/Suspicious_Gen.NHP.dropper)

Deleted file

 

 

Running post-scan cleanup routine:

 

Aborted by user

Number of files found: 193347

Number of archives unpacked: 2511

Number of files scanned: 193331

Number of files not scanned: 16

Number of files skipped due to exclude list: 0

Number of infected files found: 3

Number of infected files repaired/deleted: 3

Number of infections removed: 3

Total scanning time: 1h 9m 33s

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

############################## | UsbFix 7.038 | [supressão]

 

Usuário: Usuario (Administrador) # MIGUEL [ ]

Atualizado em 14/01/2011 por El Desaparecido / C_XX

Começou em 17:06:35 | 18/01/2011

Site: http://www.teamxscript.org

Contato: eldesaparecido@teamxscript.org

 

CPU: Intel® Pentium® Dual CPU T3400 @ 2.16GHz

CPU 2: Intel® Pentium® Dual CPU T3400 @ 2.16GHz

Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3

Internet Explorer 8.0.6001.18702

 

Windows Firewall: Habilitado

Antivirus: AntiVir Desktop 10.0.1.56 [(!) Disabled | Updated]

RAM -> 3005 Mb

C:\ (%systemdrive%) -> Disco fixo # 100 Gb (81 Mb livre - 81%) [sistema] # NTFS

D:\ -> CD-ROM

E:\ -> Disco fixo # 366 Gb (349 Mb livre - 95%) [Documentos] # NTFS

F:\ -> Disco removível # 4 Gb (655 Mb livre - 17%) [MIGUEL JR] # FAT32

 

################## | Ficheiros # pastas infeciosos |

 

 

Supprimido ! C:\Recycler\S-1-5-21-606747145-329068152-1801674531-1003

Supprimido ! E:\Recycler\S-1-5-21-606747145-329068152-1801674531-1003

 

################## | Registro |

 

Supprimido ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools

Supprimido ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

Supprimido ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

 

################## | Mountpoints2 |

 

 

################## | Listing |

 

[17/01/2011 - 10:09:42 | N | 9473] C:\Ad-Report-CLEAN[1].txt

[17/01/2011 - 10:19:29 | N | 2598] C:\Ad-Report-CLEAN[2].txt

[15/01/2011 - 22:32:00 | N | 8957] C:\Ad-Report-SCAN[1].txt

[17/01/2011 - 10:26:39 | D ] C:\Arquivos de programas

[07/09/2010 - 12:49:47 | N | 0] C:\AUTOEXEC.BAT

[17/01/2011 - 10:35:44 | N | 211] C:\Boot.bak

[17/01/2011 - 15:06:43 | N | 327] C:\boot.ini

[28/09/2001 - 08:00:00 | N | 4952] C:\Bootfont.bin

[17/01/2011 - 15:06:43 | D ] C:\cmdcons

[03/08/2004 - 23:00:16 | N | 261856] C:\cmldr

[17/01/2011 - 15:18:14 | N | 23778] C:\ComboFix.txt

[17/01/2011 - 09:56:37 | D ] C:\Config.Msi

[07/09/2010 - 12:49:47 | N | 0] C:\CONFIG.SYS

[07/09/2010 - 12:55:21 | D ] C:\Documents and Settings

[07/09/2010 - 12:49:47 | N | 0] C:\IO.SYS

[15/01/2011 - 23:47:47 | D ] C:\LinhaDefensiva

[07/09/2010 - 12:49:47 | N | 0] C:\MSDOS.SYS

[07/09/2010 - 13:32:01 | RD ] C:\MSOCache

[13/04/2008 - 08:43:04 | N | 47564] C:\NTDETECT.COM

[13/04/2008 - 10:31:44 | N | 251696] C:\ntldr

[18/01/2011 - 16:59:14 | ASH | 2145386496] C:\pagefile.sys

[07/10/2010 - 14:24:51 | D ] C:\Program Files

[17/01/2011 - 15:18:17 | D ] C:\Qoobox

[18/01/2011 - 17:08:01 | SHD ] C:\RECYCLER

[08/09/2010 - 15:56:44 | SHD ] C:\System Volume Information

[18/01/2011 - 17:08:01 | D ] C:\UsbFix

[18/01/2011 - 17:08:06 | A | 1344] C:\UsbFix.txt

[16/08/2010 - 06:12:00 | N | 3118080] C:\virtualdj_trial.exe

[15/04/2007 - 07:57:52 | N | 25214] C:\vista.ico

[17/01/2011 - 15:11:49 | D ] C:\WINDOWS

[17/01/2011 - 11:53:26 | D ] E:\Meus Documentos

[18/01/2011 - 17:08:01 | SHD ] E:\RECYCLER

[17/01/2011 - 11:21:45 | SHD ] E:\System Volume Information

 

################## | Vaccin |

 

C:\Autorun.inf -> Folder criado por UsbFix (El Desaparecido & C_XX)

E:\Autorun.inf -> Folder criado por UsbFix (El Desaparecido & C_XX)

 

################## | Upload |

 

Favor enviar o arquivo: C:\UsbFix_Upload_Me_MIGUEL.zip

http://www.teamxscript.org/Upload.php

Obrigado pela sua contribuição.

 

################## | E.O.F |

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Logfile of HijackThis v1.99.1

Scan saved at 18:29:50, on 18/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\Explorer.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Logfile of HijackThis v1.99.1

Scan saved at 18:35:27, on 18/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\Explorer.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Vários outros problemas foram removidos.

_____________________

 

:seta: Favor enviar o arquivo: C:\UsbFix_Upload_Me_MIGUEL.zip para o endereço abaixo para que o Usbfix possa ser aperfeiçoado:

http://www.teamxscript.org/Upload.php

A equipe desenvolvedora do Usbfix agradece pela sua contribuição.

_____________________

 

:seta: Acesse o site http://virscan.org/ e envie estes arquivos destacados em vermelho abaixo para serem analisados (um de cada vez) e assim que análise de cada um deles for concluida copie o endereço (link) que aparecerá na barra de endereços de seu navegador e poste estes links com o resultado das análises em sua próxima resposta juntamente com os outros logs pedidos abaixo:

 

C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe

E:\Meus Documentos\Downloads\aTube_Catcher.exe

E:\Meus Documentos\Downloads\dexpot_156_r1351.exe

E:\Meus Documentos\Downloads\PCDJ_DEX\setup_dex_1.1.7269.exe

E:\Meus Documentos\Downloads\PCDJ_DEX.rar

E:\Meus Documentos\Downloads\redmobile\pcdjredmobile_1.1.7269.exe

E:\Meus Documentos\Downloads\redmobile.rar

___________________

 

:seta: Siga também, por gentileza, as dicas deste tutorial para fazer um escaneamento de seu PC pelo Nod32 Online:

 

Tutorial do antivirus Nod32 Online

 

Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador:

C:\Arquivos de programas\Eset\Eset Online Scanner\log.txt

 

Na sua próxima resposta poste este log do Nod32 Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir este procedimento. Ficamos no aguardo de sua resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Vários outros problemas foram removidos.

_____________________

 

:seta: Favor enviar o arquivo: C:\UsbFix_Upload_Me_MIGUEL.zip para o endereço abaixo para que o Usbfix possa ser aperfeiçoado:

http://www.teamxscript.org/Upload.php

A equipe desenvolvedora do Usbfix agradece pela sua contribuição.

_____________________

 

:seta: Acesse o site http://virscan.org/ e envie estes arquivos destacados em vermelho abaixo para serem analisados (um de cada vez) e assim que análise de cada um deles for concluida copie o endereço (link) que aparecerá na barra de endereços de seu navegador e poste estes links com o resultado das análises em sua próxima resposta juntamente com os outros logs pedidos abaixo:

 

C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe

E:\Meus Documentos\Downloads\aTube_Catcher.exe

E:\Meus Documentos\Downloads\dexpot_156_r1351.exe

E:\Meus Documentos\Downloads\PCDJ_DEX\setup_dex_1.1.7269.exe

E:\Meus Documentos\Downloads\PCDJ_DEX.rar

E:\Meus Documentos\Downloads\redmobile\pcdjredmobile_1.1.7269.exe

E:\Meus Documentos\Downloads\redmobile.rar

___________________

 

:seta: Siga também, por gentileza, as dicas deste tutorial para fazer um escaneamento de seu PC pelo Nod32 Online:

 

Tutorial do antivirus Nod32 Online

 

Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador:

C:\Arquivos de programas\Eset\Eset Online Scanner\log.txt

 

Na sua próxima resposta poste este log do Nod32 Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir este procedimento. Ficamos no aguardo de sua resposta.

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

Olá novamente Antônio,

 

segue adiante o resultado dos procedimentos.

 

Um grande abraço!!!

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

http://virscan.org/report/fb5f5dcd9c7da5eaf6b4b37950177a88.html (setupneromobile.exe)

 

http://virscan.org/report/cca6a807e85b426dd66f97f73ed95363.html (atubecather.exe)

 

http://virscan.org/report/26406ac841c2b5bcdb8dc0c9697a5b51.html (dexpot)

 

http://virscan.org/report/682928965261c40de95c85f7e029606a.html (PCDJDex)

 

http://virscan.org/report/2999af15bf0a26de04ae1edab1feba2b.html (PCDJ.rar)

 

http://virscan.org/report/8c3c42ea3ef4b56f6b6ac18491799d85.html (PCDJ.Redmobile)

 

http://virscan.org/report/ab2bb0ee30c2d4fd617e0221cfbcb9e6.html (redmobile.rar)

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)

# OnlineScanner.ocx=1.0.0.6419

# api_version=3.0.2

# EOSSerial=107904083ebf98498ec9947942649315

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2011-01-21 04:22:03

# local_time=2011-01-21 01:22:03 (-0300, Hora oficial do Brasil)

# country="Brazil"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=768 16777215 100 0 10744076 10744076 0 0

# compatibility_mode=1797 16775141 100 93 0 31177610 0 0

# compatibility_mode=6143 16777215 0 0 0 0 0 0

# compatibility_mode=7937 16777213 100 100 0 4001305 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=61913

# found=1

# cleaned=1

# scan_time=3070

E:\Meus Documentos\Downloads\Programs\Real Desktop - Setup.exe a variant of Win32/TrojanDownloader.Agent.QIY trojan (deleted - quarantined) 00000000000000000000000000000000 C

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 01:42:49, on 21/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\Internet Download Manager\IDMan.exe

C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Dexpot\dexpot.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

:) Vários outros problemas foram removidos.

_____________________

 

:seta: Favor enviar o arquivo: C:\UsbFix_Upload_Me_MIGUEL.zip para o endereço abaixo para que o Usbfix possa ser aperfeiçoado:

http://www.teamxscript.org/Upload.php

A equipe desenvolvedora do Usbfix agradece pela sua contribuição.

_____________________

 

:seta: Acesse o site http://virscan.org/ e envie estes arquivos destacados em vermelho abaixo para serem analisados (um de cada vez) e assim que análise de cada um deles for concluida copie o endereço (link) que aparecerá na barra de endereços de seu navegador e poste estes links com o resultado das análises em sua próxima resposta juntamente com os outros logs pedidos abaixo:

 

C:\Arquivos de programas\Nero\Nero 7\Nero Mobile\SetupNeroMobile.exe

E:\Meus Documentos\Downloads\aTube_Catcher.exe

E:\Meus Documentos\Downloads\dexpot_156_r1351.exe

E:\Meus Documentos\Downloads\PCDJ_DEX\setup_dex_1.1.7269.exe

E:\Meus Documentos\Downloads\PCDJ_DEX.rar

E:\Meus Documentos\Downloads\redmobile\pcdjredmobile_1.1.7269.exe

E:\Meus Documentos\Downloads\redmobile.rar

___________________

 

:seta: Siga também, por gentileza, as dicas deste tutorial para fazer um escaneamento de seu PC pelo Nod32 Online:

 

Tutorial do antivirus Nod32 Online

 

Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador:

C:\Arquivos de programas\Eset\Eset Online Scanner\log.txt

 

Na sua próxima resposta poste este log do Nod32 Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir este procedimento. Ficamos no aguardo de sua resposta.

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

Olá novamente Antônio,

 

segue adiante o resultado dos procedimentos.

 

Um grande abraço!!!

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

http://virscan.org/report/fb5f5dcd9c7da5eaf6b4b37950177a88.html (setupneromobile.exe)

 

http://virscan.org/report/cca6a807e85b426dd66f97f73ed95363.html (atubecather.exe)

 

http://virscan.org/report/26406ac841c2b5bcdb8dc0c9697a5b51.html (dexpot)

 

http://virscan.org/report/682928965261c40de95c85f7e029606a.html (PCDJDex)

 

http://virscan.org/report/2999af15bf0a26de04ae1edab1feba2b.html (PCDJ.rar)

 

http://virscan.org/report/8c3c42ea3ef4b56f6b6ac18491799d85.html (PCDJ.Redmobile)

 

http://virscan.org/report/ab2bb0ee30c2d4fd617e0221cfbcb9e6.html (redmobile.rar)

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)

# OnlineScanner.ocx=1.0.0.6419

# api_version=3.0.2

# EOSSerial=107904083ebf98498ec9947942649315

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2011-01-21 04:22:03

# local_time=2011-01-21 01:22:03 (-0300, Hora oficial do Brasil)

# country="Brazil"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=768 16777215 100 0 10744076 10744076 0 0

# compatibility_mode=1797 16775141 100 93 0 31177610 0 0

# compatibility_mode=6143 16777215 0 0 0 0 0 0

# compatibility_mode=7937 16777213 100 100 0 4001305 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=61913

# found=1

# cleaned=1

# scan_time=3070

E:\Meus Documentos\Downloads\Programs\Real Desktop - Setup.exe a variant of Win32/TrojanDownloader.Agent.QIY trojan (deleted - quarantined) 00000000000000000000000000000000 C

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 01:42:49, on 21/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\Internet Download Manager\IDMan.exe

C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Dexpot\dexpot.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Antônio, estou enviando tbm um Log do Spyware Terminator, caso tenha tempo e repute necessário, por favor,

 

analise-o para mim. Grato!!!

 

 

...................

 

 

Logfile of Spyware Terminator v2.8.2.192 (db:5.001.020.000)

Scan Time: 21/1/2011 01:58:36 length: 273 s

Platform: WXP (5.1.0.2600)

User: Admin

Boot Mode: Normal

Scan type: Fast_Spyware_Scan

Scanned Objects: 41186 (Critical:0)

Filter: No System items, No Safe items, No Invalid items

 

Running Processes

TuneUpUtilitiesService32.exe [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

TuneUpUtilitiesApp32.exe [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

sm56hlpr.exe [Motorola Inc.] : C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

HPWuSchd2.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

GoogleUpdate.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

NMIndexingService.exe [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

NMIndexStoreSvr.exe [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

hpqtra08.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

IEMonitor.exe [Tonec Inc.] : C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

hpqSTE08.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

dexpot.exe [Dexpot GbR] : C:\Arquivos de programas\Dexpot\dexpot.exe

msnmsgr.exe [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

wlcomm.exe [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

 

Internet Settings

R - HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://fr.msn.com/

R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =

R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =

 

BHO

02 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - [RealPlayer] : C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

 

StartUps

04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Google Update : [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, msnmsgr : [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NeroFilterCheck : [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMSERIAL : [Motorola Inc.] : C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HP Software Update : [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

04 - Startup: %STARTUPALL%\HP Digital Imaging Monitor.lnk [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

 

Shell Extensions

RealOne Player Context Menu Class - {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - [RealNetworks, Inc.] : C:\Arquivos de programas\Real\RealPlayer\rpshell.dll

TuneUp Theme Extension - {44440D00-FF19-4AFC-B765-9A0970567D97} - [TuneUp Software] : C:\WINDOWS\system32\uxtuneup.dll

TuneUp Shredder Shell Extension - {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\SDShelEx-win32.dll

TuneUp Disk Space Explorer Shell Extension - {4838CD50-7E5D-4811-9B17-C47A85539F28} - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\DseShExt-x86.dll

 

Protocol Handler

- {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll

- {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll

 

Services

23 - [bison Electronics. Inc.] : C:\WINDOWS\system32\Drivers\BisonC07.sys

23 - [Realtek Semiconductor Corp.] : C:\WINDOWS\system32\drivers\RtkHDAud.sys

23 - [JMicron Technology Corporation] : C:\WINDOWS\system32\DRIVERS\jmcr.sys

23 - [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

23 - [Realtek Semiconductor Corporation] : C:\WINDOWS\system32\DRIVERS\RTL8187B.sys

23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\sisgrp.sys

23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\SISAGPX.sys

23 - [silicon Integrated Systems Corp.] : C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys

23 - [silicon Integrated Systems Corp.] : C:\WINDOWS\system32\DRIVERS\siside.sys

23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\srvkp.sys

23 - [Motorola Inc.] : C:\WINDOWS\system32\DRIVERS\smserial.sys

23 - [Crawler.com] : C:\WINDOWS\system32\drivers\sp_rsdrv2.sys

23 - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

23 - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys

 

Threat Files

<Tracking Flash Shared Objects> : C:\Documents and Settings\Usuario\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\ENXNCN9X\core.mochibot.com\com.mochibot.sol

 

Advanced Files Report

%SYSDIR%\idmmbc.dll [Tonec Inc.] [internet Download Manager LSP dll] MD5=4FB32F1DE01FFA2D3FDE897AF26EA527 SIZE=210272

%SYSDIR%\uxtuneup.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=B5C3BFDA09352789414DCA2066C0ED58 SIZE=29504

%SYSDIR%\hpz3l5ha.dll [Hewlett-Packard Company] [Language Monitor] MD5=9558DAA1DB859250A677CCE97B048151 SIZE=118272

%SYSDIR%\spool\PRTPROCS\W32X86\hpzpp5ha.dll [Hewlett-Packard Corporation] [HP Print Processor] MD5=D0E39177C896D2F8191A9C96636276DF SIZE=274944

%PROGRAMFILES%\hp\digital imaging\bin\hpqddsvc.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=3EE4A63539EC04EE2D4BD293985087AB SIZE=131072

%PROGRAMFILES%\hp\digital imaging\bin\hpqddcmn.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=5B973EA48E154C83ADF42D0A0F57BB29 SIZE=184320

%PROGRAMFILES%\hp\digital imaging\bin\hpqcxs08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=38D6B51F04DEF7FB248FA56E4C47407E SIZE=217088

%PROGRAMFILES%\HP\Digital Imaging\bin\hpocxi08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0642843485D687CB2BA37F007ECC92E4 SIZE=442368

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqcob08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=6D15B5F97EB3332D4BBE19B6FFD512F2 SIZE=135168

%PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [TuneUp Software] [TuneUp Utilities 2011] MD5=6D6B644FD1C874480BB664DE7A30C304 SIZE=1483072

%PROGRAMFILES%\Internet Download Manager\idmmkb.dll [Tonec Inc.] [internet Download Manager] MD5=11C64B3E86F4C691C02092302AF38410 SIZE=34224

%COMMONFILES%\Adobe\Acrobat\ActiveX\PDFShell.PTB [Adobe Systems, Inc.] [Adobe PDF Shell Extension] MD5=B242AFF9B81DDBC6501296D90350FB37 SIZE=311296

%PROGRAMFILES%\Dexpot\hooxpot.dll [Dexpot GbR] [Dexpot] MD5=F651BC45DD1774A3E15126FA59500959 SIZE=45568

%PROGRAMFILES%\TuneUp Utilities 2011\SDShelEx-win32.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=5A9B57BA81ECFFCA62190786494B30C3 SIZE=29504

%COMMONFILES%\Ahead\Lib\AdvrCntr2.dll [Nero AG] [AdvrCntr Module] MD5=54D3D6904ACE021D2B761FB8248BDBAE SIZE=3073320

%PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe [TuneUp Software] [TuneUp Utilities 2011] MD5=965DB099D1A5C4E4B90BA086241DA1A9 SIZE=645952

%PROGRAMFILES%\Motorola\SMSERIAL\sm56eng.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=EC94D60C1C0778ABA382A077B5DF3B32 SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56fra.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=81EBA7ECEB8F3A5C2092615B379F021D SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56brz.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=2ADC4557FABBBE2D4547EA14F634B755 SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56chs.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=36CA10B8CB23AF849A11BA45CB3DE775 SIZE=65536

%PROGRAMFILES%\Motorola\SMSERIAL\sm56cht.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=32680786954F426C193C37BD5D65A7B8 SIZE=65536

%PROGRAMFILES%\Motorola\SMSERIAL\sm56ger.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=8A3947808D6088B8F67FC74E2FA13C54 SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56ita.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=948C03C102ED14FFCF28005FAE0CC701 SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56jpn.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=6BC2A57629C1AFA03B5F648349E6507D SIZE=69632

%PROGRAMFILES%\Motorola\SMSERIAL\sm56esp.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=FA0711174D3936225DBB170EC3FC9D9D SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56kor.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=A2B45C9A19908D6D541CF2755617409E SIZE=65536

%PROGRAMFILES%\Motorola\SMSERIAL\sm56dnk.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=48813EDD60F93C6ABB1B73793C0B0D3F SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56ara.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=4D87D615152D8D08F976674C3F719B8A SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56cro.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=559345B1AA1BFE7DFC7DFDB29A90A71D SIZE=86016

%PROGRAMFILES%\Motorola\SMSERIAL\sm56pol.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=DDB8B6F73C0C36B239653A8051225C9F SIZE=86016

%PROGRAMFILES%\Motorola\SMSERIAL\sm56rus.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=A36E84F7A352DD754987238F5362A076 SIZE=86016

%PROGRAMFILES%\Motorola\SMSERIAL\sm56nor.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=BB6284F22EE739A005013403D987E564 SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56cze.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=4CEFF3DD5EB75ABDACFCD670BBCC5F7C SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56dan.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=03636ED3870B5FC9E0AD8075E6DBD5F1 SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56fin.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=428EB23FF701676D0F8542BDF290AE30 SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56gre.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=EEF1AE7B7B9647B03CEA608CDC25E4C6 SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56swe.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=BDE6D6D377CD056480125859D471266B SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56tur.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=B3E20973B15C25DCDDCADA0C37D5C140 SIZE=81920

%COMMONFILES%\Ahead\Lib\NMIndexingServicePS.dll [Nero AG] [Nero Home] MD5=49130B95291F0269689AF46A461DB034 SIZE=59176

%COMMONFILES%\Ahead\Lib\NMIndexStoreSvrPS.dll [Nero AG] [Nero Home] MD5=A00F1027925AEDEAC8EDEFC46133F691 SIZE=20776

%COMMONFILES%\Ahead\Lib\NMDataServices.dll [Nero AG] [Nero Home] MD5=A63E5D51FBDB18AFA2EC67CADCB062FD SIZE=2749736

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Update\1.2.183.39\goopdate.dll [Google Inc.] [Google Update] MD5=68CA45DAF2A425E9719B3122EDDDB343 SIZE=682648

%COMMONFILES%\Ahead\Lib\NMIndexingService.exe [Nero AG] [Nero Home] MD5=A328A46D87BB92CE4D8A4528E9D84787 SIZE=279848

%COMMONFILES%\Ahead\Lib\NMLogCxx.dll [Nero AG] [Nero Home] MD5=0C01B2C22322C48D8ADAE3B9D467E924 SIZE=70952

%COMMONFILES%\Ahead\Lib\log4cxx.dll [Nero AG] [Nero Home] MD5=421B260404162F1F00A9618C3F42315B SIZE=742696

%COMMONFILES%\Ahead\Lib\NMIndexStoreSvr.exe [Nero AG] [Nero Home] MD5=FFBD5650348D4F9E0AA8E72938DC6478 SIZE=1213736

%COMMONFILES%\Ahead\Lib\NMSQLDB.dll [Nero AG] [Nero Home] MD5=B8E87E8DA00838B208801B57B86AC5E4 SIZE=320808

%COMMONFILES%\Ahead\Lib\NMCoFoundation.dll [Nero AG] [Nero Home] MD5=0366D598F2C36B7C08B848B2BD5E11D3 SIZE=541992

%COMMONFILES%\Ahead\Lib\NMPluginBase.dll [Nero AG] [Nero Home] MD5=65261A7F650F4C7E56D874FD4A5F2BDA SIZE=107816

%COMMONFILES%\Ahead\Lib\NMFullTextExtraction.dll [Nero AG] [Nero Home] MD5=97165BC95B8690A51521EF2AA5B61F0E SIZE=181544

%COMMONFILES%\Ahead\Lib\NMSearchPluginSimilarImages.dll [Nero AG] [Nero Home] MD5=363A7929BF3E0DA91E9FFACCF336777E SIZE=181544

%COMMONFILES%\Ahead\Lib\NeroIPP.dll [Nero AG] [Nero Suite] MD5=94BB4635AE6CA64356B2D0E60EFD6038 SIZE=3376424

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqtra08.exe [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=F14219FC767F1383526AB423F278A8E3 SIZE=210520

%PROGRAMFILES%\HP\Digital Imaging\bin\hpquio08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=9507A8E70A620A36CF2CF60740B8F022 SIZE=151552

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqtra08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=2B57FA15C56154BE2F728EE485720F2E SIZE=47104

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqtao08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=021CFC69A1874431DC88BEFC37A2A2FD SIZE=98304

%PROGRAMFILES%\HP\Digital Imaging\bin\hpotra08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=23D3BFA480C5DA9256DD9A97185678C4 SIZE=323584

%PROGRAMFILES%\HP\Digital Imaging\bin\hpotra08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0EEF3AA9B7B567464C3010875A2F5A92 SIZE=12800

%PROGRAMFILES%\HP\Digital Imaging\bin\hpotradd.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=7DAFE566BB13C16439CBAADB43582128 SIZE=77824

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqrif08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=A6E02F65BE0C48DE7101923AE70268BD SIZE=290816

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqmif08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=D0716BD0C0822A642D36E82F49F2B5B8 SIZE=299008

%PROGRAMFILES%\HP\Digital Imaging\bin\hpodio08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=8861AB06F667429B94DBFE97550F82D5 SIZE=1007616

%SYSDIR%\hpzipr12.dll [Hewlett-Packard] [bidi User Mode] MD5=AF880166DAC5880219F748ED83902CB2 SIZE=33280

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqddusr.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=1AE183708EC0CA7E8CECF98B9785D57C SIZE=61440

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqusg.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=5B6748DFA56A0BE54C45B989378293E1 SIZE=401408

%SYSDIR%\hpzidr12.dll [Hewlett-Packard] [bidi User Mode] MD5=26AE2CA34FA4342749EC1157CB1FE954 SIZE=49152

%PROGRAMFILES%\Internet Download Manager\IEMonitor.exe [Tonec Inc.] [iEMonitor Application] MD5=207B16FA69F61D1895F8D8532F587E4B SIZE=263600

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqSTE08.exe [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=FEDDD3579FEE51A9873D856DF3933C68 SIZE=151552

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqwso08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=1D0A76276AD7A836F29F447968C61CE6 SIZE=516096

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqsti08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0A0A339D07FF5E9989EEF1E1D476CD29 SIZE=249856

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqstp08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=7C4DCFF108869D7915D39B9371BE5FFE SIZE=217088

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqstp08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=860B5D266F74CED0ED86C4D118016C7F SIZE=11776

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqsem08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=8AB4E23C6FB10F8FE35AA9F624A8D4E3 SIZE=655360

%PROGRAMFILES%\Dexpot\dexpot.exe [Dexpot GbR] [Dexpot] MD5=AC22FEBC423BF6E596282E9C25102D86 SIZE=1273856

%PROGRAMFILES%\Dexpot\Dexpot.dll [Dexpot GbR] [Dexpot] MD5=F3C39C6331463AA2A13D7C19C9EA6754 SIZE=63488

%SYSDIR%\hpzipm12.dll [Hewlett-Packard] [bidi User Mode] MD5=79834AA2FBF9FE81EEBB229024F6F7FC SIZE=53248

%PROGRAMFILES%\Windows Live\Contacts\wlcomm.exe [Microsoft Corporation] [Windows Live Communications Platform] MD5=654480EA67078C7B4C6C8BA871B07D5D SIZE=27512

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe [Google Inc.] [Google Chrome] MD5=4BFE28145799174386393B1E09764ED4 SIZE=991800

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\chrome.dll [Google Inc.] [Google Chrome] MD5=E00A403F4D5560799925809C5968A29E SIZE=22112312

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\icudt42.dll [iBM Corporation and others] [international Components for Unicode] MD5=AF7B02DA57568DB12CD97892A1E21279 SIZE=11046456

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\locales\pt-BR.dll MD5=F8FB352012C84DC1A0D1083C69C2B928 SIZE=235576

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\gears.dll [Google Inc.] [Google Gears 0.5.33.0] MD5=837173438BB8B1774FB9C39F75D9380D SIZE=3184184

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\pdf.dll [Chrome PDF Viewer] MD5=51C3DC3713CC321BB33631DC77B4BEA2 SIZE=4049976

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avcodec-52.dll MD5=EC1B9BCDDC37F828B91E2F52801E6512 SIZE=1475128

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avutil-50.dll MD5=D039B0D6E1F707E19CB8A8B22944002C SIZE=99896

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avformat-52.dll MD5=282E6252AD1F4B5AB13CCA8D349B5DEA SIZE=197688

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.63_0\npqslauncher.dll [bitDefender LLC] [bitDefender QuickScan] MD5=7528FCCE4AFC2A309EA33DDC2509C2AD SIZE=49056

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\gcswf32.dll [Adobe Systems, Inc.] [shockwave Flash] MD5=F02C4AAA6AC913FAAB0EAA74EAD94D9A SIZE=6021120

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\libglesv2.dll MD5=F2C24BF4C77E8719D3D20159957DEFCD SIZE=462904

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\libegl.dll MD5=762B6BB323A3A2E5133A427686C9CC1C SIZE=123960

deskpan.dll

%PROGRAMFILES%\Real\RealPlayer\rpshell.dll [RealNetworks, Inc.] [RealPlayer] MD5=0740ABDF0265BA0260D52FE88DCB9067 SIZE=63016

%PROGRAMFILES%\TuneUp Utilities 2011\DseShExt-x86.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=7643655C6BA19B57D863684F5DFCA19B SIZE=25920

%SYSDIR%\svchost.exe -k netsvcs

%SYSDIR%\Drivers\BisonC07.sys [bison Electronics. Inc.] [bisonCam UVC, USB 2.0 Camera] MD5=BB04CB2F027D8DE7D3BDAEA147A706CB SIZE=974248

%SYSDIR%\svchost -k DcomLaunch

%SYSDIR%\svchost.exe -k NetworkService

%SYSDIR%\svchost.exe -k hpdevmgmt

%SYSDIR%\svchost.exe -k HTTPFilter

%SYSDIR%\drivers\RtkHDAud.sys [Realtek Semiconductor Corp.] [Realtek® High Definition Audio Function Driver (HRTF data Copyright 1994 by MIT Media Lab)] MD5=3FA02C6E3E9EBE8523A2D4E51D0ECE1F SIZE=5891584

%SYSDIR%\DRIVERS\jmcr.sys [JMicron Technology Corporation] [JMB38X Flash Media Controller Driver] MD5=9EFE54794B3A94E93DA50703692E011E SIZE=113504

%SYSDIR%\svchost.exe -k LocalService

%SYSDIR%\svchost.exe -k HPZ12

%SYSDIR%\svchost -k rpcss

%SYSDIR%\DRIVERS\RTL8187B.sys [Realtek Semiconductor Corporation] [Realtek RTL8187B Wireless USB 2.0 Adapter] MD5=2E2E3A2D1BA5E540C32558F3F37D33E3 SIZE=335104

%SYSDIR%\DRIVERS\sisgrp.sys [silicon Integrated Systems Corporation] [siS ® Compatible Super VGA Miniport Driver for Windows XP] MD5=4FABFAB9231F7E7C833677377CF013B8 SIZE=323584

%SYSDIR%\DRIVERS\SISAGPX.sys [silicon Integrated Systems Corporation] [siS AGPv3.5 Filter for Windows XP] MD5=F8150C74FF24BDBD19F47A6DFD05514A SIZE=35712

%SYSDIR%\DRIVERS\SiSGbeXP.sys [silicon Integrated Systems Corp.] [siS191/190 Ethernet Device] MD5=A86E52C55DE3488B3FC0FF2B8AD711BF SIZE=43392

%SYSDIR%\DRIVERS\siside.sys [silicon Integrated Systems Corp.] [siS PCI Mini IDE Driver] MD5=B4485881BD8AED9B157A2E6CF43C2D51 SIZE=4096

%SYSDIR%\DRIVERS\srvkp.sys [silicon Integrated Systems Corporation] [siS ® WindowsXP Display Manager] MD5=82387BF8F5A35358118B2129FF91C890 SIZE=19072

%SYSDIR%\DRIVERS\smserial.sys [Motorola Inc.] [Motorola SM56 Modem] MD5=BDFD18C04466EDBF78FF663B7CDE08AE SIZE=1092608

%SYSDIR%\drivers\sp_rsdrv2.sys [Crawler.com] [spyware Terminator] MD5=8831252BCF05FCFB5ABD116A22E552D8 SIZE=142592

%SYSDIR%\svchost.exe -k imgsvc

%PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [TuneUp Software] [TuneUp Utilities] MD5=F2107C9D85EC0DF116939CCCE06AE697 SIZE=10064

%SYSDIR%\svchost.exe -k WudfServiceGroup

%PROGRAMFILES%\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [Microsoft Corporation] [Windows Live Messenger Protocol Handler Module] MD5=61B0C981F7C10B8861809ADC1B31E8E5 SIZE=61264

 

End of Report

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Mais um problema foi removido pelo Nod32 Online.

___________________

 

Antônio, estou enviando tbm um Log do Spyware Terminator

:seta: Faça uma atualização (update) do Spyware Terminator > faça uma verificação completa com ele e remova os problemas que ele encontrar > depois nos diga se algum virus ou spyware foi removido por ele.

____________________

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked:

 

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)

 

O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

_______________________

 

:seta: Siga também esta dica:

 

Tutorial do Dr. Web CureIt

 

Na sua próxima resposta poste este log do Dr. Web CureIt juntamente com um novo log do Hijackthis e nos diga se alguns problemas foram removidos pelo Spyware Terminator e nos diga como está o seu Pc depois disto.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Mais um problema foi removido pelo Nod32 Online.

___________________

 

Antônio, estou enviando tbm um Log do Spyware Terminator

:seta: Faça uma atualização (update) do Spyware Terminator > faça uma verificação completa com ele e remova os problemas que ele encontrar > depois nos diga se algum virus ou spyware foi removido por ele.

____________________

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked:

 

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)

 

O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)

_______________________

 

:seta: Siga também esta dica:

 

Tutorial do Dr. Web CureIt

 

Na sua próxima resposta poste este log do Dr. Web CureIt juntamente com um novo log do Hijackthis e nos diga se alguns problemas foram removidos pelo Spyware Terminator e nos diga como está o seu Pc depois disto.

 

Ficamos no aguardo.

 

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

Segue abaixo os procedimentos solicitados.

.

Abçs

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Logfile of Spyware Terminator v2.8.2.192 (db:5.001.021.000)

Scan Time: 21/1/2011 09:20:18 length: 339 s

Platform: WXP (5.1.0.2600)

User: Admin

Boot Mode: Normal

Scan type: Fast_Spyware_Scan

Scanned Objects: 41207 (Critical:0)

Filter: No System items, No Safe items, No Invalid items

 

Running Processes

TuneUpUtilitiesService32.exe [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

TuneUpUtilitiesApp32.exe [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

sm56hlpr.exe [Motorola Inc.] : C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

HPWuSchd2.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

GoogleUpdate.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

NMIndexingService.exe [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

NMIndexStoreSvr.exe [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

msnmsgr.exe [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

IEMonitor.exe [Tonec Inc.] : C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

hpqtra08.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

hpqSTE08.exe [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

chrome.exe [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

 

Internet Settings

R - HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://fr.msn.com/

R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm

R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =

R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =

 

BHO

02 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - [RealPlayer] : C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

 

StartUps

04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Google Update : [Google Inc.] : C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, msnmsgr : [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NeroFilterCheck : [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SMSERIAL : [Motorola Inc.] : C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, HP Software Update : [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

04 - Startup: %STARTUPALL%\HP Digital Imaging Monitor.lnk [Hewlett-Packard Co.] : C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

 

Shell Extensions

RealOne Player Context Menu Class - {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - [RealNetworks, Inc.] : C:\Arquivos de programas\Real\RealPlayer\rpshell.dll

TuneUp Theme Extension - {44440D00-FF19-4AFC-B765-9A0970567D97} - [TuneUp Software] : C:\WINDOWS\system32\uxtuneup.dll

TuneUp Shredder Shell Extension - {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\SDShelEx-win32.dll

TuneUp Disk Space Explorer Shell Extension - {4838CD50-7E5D-4811-9B17-C47A85539F28} - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\DseShExt-x86.dll

 

Protocol Handler

- {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll

- {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Arquivos de programas\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll

 

Services

23 - [bison Electronics. Inc.] : C:\WINDOWS\system32\Drivers\BisonC07.sys

23 - [Realtek Semiconductor Corp.] : C:\WINDOWS\system32\drivers\RtkHDAud.sys

23 - [JMicron Technology Corporation] : C:\WINDOWS\system32\DRIVERS\jmcr.sys

23 - [Nero AG] : C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

23 - [Realtek Semiconductor Corporation] : C:\WINDOWS\system32\DRIVERS\RTL8187B.sys

23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\sisgrp.sys

23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\SISAGPX.sys

23 - [silicon Integrated Systems Corp.] : C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys

23 - [silicon Integrated Systems Corp.] : C:\WINDOWS\system32\DRIVERS\siside.sys

23 - [silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\srvkp.sys

23 - [Motorola Inc.] : C:\WINDOWS\system32\DRIVERS\smserial.sys

23 - [Crawler.com] : C:\WINDOWS\system32\drivers\sp_rsdrv2.sys

23 - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

23 - [TuneUp Software] : C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys

 

Threat Files

<Tracking Flash Shared Objects> : C:\Documents and Settings\Usuario\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\ENXNCN9X\core.mochibot.com\com.mochibot.sol

 

Advanced Files Report

%SYSDIR%\idmmbc.dll [Tonec Inc.] [internet Download Manager LSP dll] MD5=4FB32F1DE01FFA2D3FDE897AF26EA527 SIZE=210272

%SYSDIR%\uxtuneup.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=B5C3BFDA09352789414DCA2066C0ED58 SIZE=29504

%SYSDIR%\hpz3l5ha.dll [Hewlett-Packard Company] [Language Monitor] MD5=9558DAA1DB859250A677CCE97B048151 SIZE=118272

%SYSDIR%\spool\PRTPROCS\W32X86\hpzpp5ha.dll [Hewlett-Packard Corporation] [HP Print Processor] MD5=D0E39177C896D2F8191A9C96636276DF SIZE=274944

%PROGRAMFILES%\hp\digital imaging\bin\hpqddsvc.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=3EE4A63539EC04EE2D4BD293985087AB SIZE=131072

%PROGRAMFILES%\hp\digital imaging\bin\hpqddcmn.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=5B973EA48E154C83ADF42D0A0F57BB29 SIZE=184320

%PROGRAMFILES%\hp\digital imaging\bin\hpqcxs08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=38D6B51F04DEF7FB248FA56E4C47407E SIZE=217088

%PROGRAMFILES%\HP\Digital Imaging\bin\hpocxi08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0642843485D687CB2BA37F007ECC92E4 SIZE=442368

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqcob08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=6D15B5F97EB3332D4BBE19B6FFD512F2 SIZE=135168

%PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [TuneUp Software] [TuneUp Utilities 2011] MD5=6D6B644FD1C874480BB664DE7A30C304 SIZE=1483072

%PROGRAMFILES%\Internet Download Manager\idmmkb.dll [Tonec Inc.] [internet Download Manager] MD5=11C64B3E86F4C691C02092302AF38410 SIZE=34224

%COMMONFILES%\Adobe\Acrobat\ActiveX\PDFShell.PTB [Adobe Systems, Inc.] [Adobe PDF Shell Extension] MD5=B242AFF9B81DDBC6501296D90350FB37 SIZE=311296

%ALLUSERS_APPDATA%\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll MD5=13F611AD51310D4A6EF0D87D7D4E8EA5 SIZE=40960

%PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe [TuneUp Software] [TuneUp Utilities 2011] MD5=965DB099D1A5C4E4B90BA086241DA1A9 SIZE=645952

%PROGRAMFILES%\Motorola\SMSERIAL\sm56eng.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=EC94D60C1C0778ABA382A077B5DF3B32 SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56fra.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=81EBA7ECEB8F3A5C2092615B379F021D SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56brz.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=2ADC4557FABBBE2D4547EA14F634B755 SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56chs.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=36CA10B8CB23AF849A11BA45CB3DE775 SIZE=65536

%PROGRAMFILES%\Motorola\SMSERIAL\sm56cht.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=32680786954F426C193C37BD5D65A7B8 SIZE=65536

%PROGRAMFILES%\Motorola\SMSERIAL\sm56ger.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=8A3947808D6088B8F67FC74E2FA13C54 SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56ita.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=948C03C102ED14FFCF28005FAE0CC701 SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56jpn.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=6BC2A57629C1AFA03B5F648349E6507D SIZE=69632

%PROGRAMFILES%\Motorola\SMSERIAL\sm56esp.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=FA0711174D3936225DBB170EC3FC9D9D SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56kor.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=A2B45C9A19908D6D541CF2755617409E SIZE=65536

%PROGRAMFILES%\Motorola\SMSERIAL\sm56dnk.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=48813EDD60F93C6ABB1B73793C0B0D3F SIZE=77824

%PROGRAMFILES%\Motorola\SMSERIAL\sm56ara.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=4D87D615152D8D08F976674C3F719B8A SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56cro.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=559345B1AA1BFE7DFC7DFDB29A90A71D SIZE=86016

%PROGRAMFILES%\Motorola\SMSERIAL\sm56pol.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=DDB8B6F73C0C36B239653A8051225C9F SIZE=86016

%PROGRAMFILES%\Motorola\SMSERIAL\sm56rus.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=A36E84F7A352DD754987238F5362A076 SIZE=86016

%PROGRAMFILES%\Motorola\SMSERIAL\sm56nor.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=BB6284F22EE739A005013403D987E564 SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56cze.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=4CEFF3DD5EB75ABDACFCD670BBCC5F7C SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56dan.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=03636ED3870B5FC9E0AD8075E6DBD5F1 SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56fin.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=428EB23FF701676D0F8542BDF290AE30 SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56gre.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=EEF1AE7B7B9647B03CEA608CDC25E4C6 SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56swe.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=BDE6D6D377CD056480125859D471266B SIZE=81920

%PROGRAMFILES%\Motorola\SMSERIAL\sm56tur.dll [Motorola Inc.] [sM56 Helper Win32 Utility] MD5=B3E20973B15C25DCDDCADA0C37D5C140 SIZE=81920

%COMMONFILES%\Ahead\Lib\AdvrCntr2.dll [Nero AG] [AdvrCntr Module] MD5=54D3D6904ACE021D2B761FB8248BDBAE SIZE=3073320

%COMMONFILES%\Ahead\Lib\NMIndexingServicePS.dll [Nero AG] [Nero Home] MD5=49130B95291F0269689AF46A461DB034 SIZE=59176

%COMMONFILES%\Ahead\Lib\NMIndexStoreSvrPS.dll [Nero AG] [Nero Home] MD5=A00F1027925AEDEAC8EDEFC46133F691 SIZE=20776

%COMMONFILES%\Ahead\Lib\NMDataServices.dll [Nero AG] [Nero Home] MD5=A63E5D51FBDB18AFA2EC67CADCB062FD SIZE=2749736

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Update\1.2.183.39\goopdate.dll [Google Inc.] [Google Update] MD5=68CA45DAF2A425E9719B3122EDDDB343 SIZE=682648

%COMMONFILES%\Ahead\Lib\NMIndexingService.exe [Nero AG] [Nero Home] MD5=A328A46D87BB92CE4D8A4528E9D84787 SIZE=279848

%COMMONFILES%\Ahead\Lib\NMLogCxx.dll [Nero AG] [Nero Home] MD5=0C01B2C22322C48D8ADAE3B9D467E924 SIZE=70952

%COMMONFILES%\Ahead\Lib\log4cxx.dll [Nero AG] [Nero Home] MD5=421B260404162F1F00A9618C3F42315B SIZE=742696

%COMMONFILES%\Ahead\Lib\NMIndexStoreSvr.exe [Nero AG] [Nero Home] MD5=FFBD5650348D4F9E0AA8E72938DC6478 SIZE=1213736

%COMMONFILES%\Ahead\Lib\NMSQLDB.dll [Nero AG] [Nero Home] MD5=B8E87E8DA00838B208801B57B86AC5E4 SIZE=320808

%COMMONFILES%\Ahead\Lib\NMCoFoundation.dll [Nero AG] [Nero Home] MD5=0366D598F2C36B7C08B848B2BD5E11D3 SIZE=541992

%COMMONFILES%\Ahead\Lib\NMPluginBase.dll [Nero AG] [Nero Home] MD5=65261A7F650F4C7E56D874FD4A5F2BDA SIZE=107816

%COMMONFILES%\Ahead\Lib\NMFullTextExtraction.dll [Nero AG] [Nero Home] MD5=97165BC95B8690A51521EF2AA5B61F0E SIZE=181544

%COMMONFILES%\Ahead\Lib\NMSearchPluginSimilarImages.dll [Nero AG] [Nero Home] MD5=363A7929BF3E0DA91E9FFACCF336777E SIZE=181544

%COMMONFILES%\Ahead\Lib\NeroIPP.dll [Nero AG] [Nero Suite] MD5=94BB4635AE6CA64356B2D0E60EFD6038 SIZE=3376424

%PROGRAMFILES%\Internet Download Manager\IEMonitor.exe [Tonec Inc.] [iEMonitor Application] MD5=207B16FA69F61D1895F8D8532F587E4B SIZE=263600

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqtra08.exe [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=F14219FC767F1383526AB423F278A8E3 SIZE=210520

%PROGRAMFILES%\HP\Digital Imaging\bin\hpquio08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=9507A8E70A620A36CF2CF60740B8F022 SIZE=151552

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqtra08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=2B57FA15C56154BE2F728EE485720F2E SIZE=47104

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqtao08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=021CFC69A1874431DC88BEFC37A2A2FD SIZE=98304

%PROGRAMFILES%\HP\Digital Imaging\bin\hpotra08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=23D3BFA480C5DA9256DD9A97185678C4 SIZE=323584

%PROGRAMFILES%\HP\Digital Imaging\bin\hpotra08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0EEF3AA9B7B567464C3010875A2F5A92 SIZE=12800

%PROGRAMFILES%\HP\Digital Imaging\bin\hpotradd.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=7DAFE566BB13C16439CBAADB43582128 SIZE=77824

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqrif08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=A6E02F65BE0C48DE7101923AE70268BD SIZE=290816

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqmif08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=D0716BD0C0822A642D36E82F49F2B5B8 SIZE=299008

%PROGRAMFILES%\HP\Digital Imaging\bin\hpodio08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=8861AB06F667429B94DBFE97550F82D5 SIZE=1007616

%SYSDIR%\hpzipr12.dll [Hewlett-Packard] [bidi User Mode] MD5=AF880166DAC5880219F748ED83902CB2 SIZE=33280

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqddusr.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=1AE183708EC0CA7E8CECF98B9785D57C SIZE=61440

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqusg.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=5B6748DFA56A0BE54C45B989378293E1 SIZE=401408

%SYSDIR%\hpzidr12.dll [Hewlett-Packard] [bidi User Mode] MD5=26AE2CA34FA4342749EC1157CB1FE954 SIZE=49152

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqSTE08.exe [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=FEDDD3579FEE51A9873D856DF3933C68 SIZE=151552

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqwso08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=1D0A76276AD7A836F29F447968C61CE6 SIZE=516096

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqsti08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=0A0A339D07FF5E9989EEF1E1D476CD29 SIZE=249856

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqstp08.dll [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=7C4DCFF108869D7915D39B9371BE5FFE SIZE=217088

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqstp08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=860B5D266F74CED0ED86C4D118016C7F SIZE=11776

%PROGRAMFILES%\HP\Digital Imaging\bin\hpqsem08.rsc [Hewlett-Packard Co.] [hp digital imaging - hp all-in-one series] MD5=8AB4E23C6FB10F8FE35AA9F624A8D4E3 SIZE=655360

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe [Google Inc.] [Google Chrome] MD5=4BFE28145799174386393B1E09764ED4 SIZE=991800

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\chrome.dll [Google Inc.] [Google Chrome] MD5=E00A403F4D5560799925809C5968A29E SIZE=22112312

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\icudt42.dll [iBM Corporation and others] [international Components for Unicode] MD5=AF7B02DA57568DB12CD97892A1E21279 SIZE=11046456

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\locales\pt-BR.dll MD5=F8FB352012C84DC1A0D1083C69C2B928 SIZE=235576

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\gears.dll [Google Inc.] [Google Gears 0.5.33.0] MD5=837173438BB8B1774FB9C39F75D9380D SIZE=3184184

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\pdf.dll [Chrome PDF Viewer] MD5=51C3DC3713CC321BB33631DC77B4BEA2 SIZE=4049976

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avcodec-52.dll MD5=EC1B9BCDDC37F828B91E2F52801E6512 SIZE=1475128

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avutil-50.dll MD5=D039B0D6E1F707E19CB8A8B22944002C SIZE=99896

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\avformat-52.dll MD5=282E6252AD1F4B5AB13CCA8D349B5DEA SIZE=197688

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.63_0\npqslauncher.dll [bitDefender LLC] [bitDefender QuickScan] MD5=7528FCCE4AFC2A309EA33DDC2509C2AD SIZE=49056

%SYSDIR%\hpzipm12.dll [Hewlett-Packard] [bidi User Mode] MD5=79834AA2FBF9FE81EEBB229024F6F7FC SIZE=53248

%USERPROFILE%\Configurações locais\Dados de aplicativos\Google\Chrome\Application\8.0.552.237\gcswf32.dll [Adobe Systems, Inc.] [shockwave Flash] MD5=F02C4AAA6AC913FAAB0EAA74EAD94D9A SIZE=6021120

%APPDATA%\IDM\idmmzcc3\components\idmmzcc.dll [Tonec Inc.] [internet Download Manager module] MD5=0EDF32D15BA4B6BEEB9C355B26D468B1 SIZE=271712

%ALLUSERS_APPDATA%\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll MD5=ACE8DDA26B36242F774AC6648ABAAA60 SIZE=49152

%ALLUSERS_APPDATA%\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll [RealPlayer] MD5=B38D56DF1DE9778D3B8184B269ADA873 SIZE=308808

deskpan.dll

%PROGRAMFILES%\Real\RealPlayer\rpshell.dll [RealNetworks, Inc.] [RealPlayer] MD5=0740ABDF0265BA0260D52FE88DCB9067 SIZE=63016

%PROGRAMFILES%\TuneUp Utilities 2011\SDShelEx-win32.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=5A9B57BA81ECFFCA62190786494B30C3 SIZE=29504

%PROGRAMFILES%\TuneUp Utilities 2011\DseShExt-x86.dll [TuneUp Software] [TuneUp Utilities 2011] MD5=7643655C6BA19B57D863684F5DFCA19B SIZE=25920

%SYSDIR%\svchost.exe -k netsvcs

%SYSDIR%\Drivers\BisonC07.sys [bison Electronics. Inc.] [bisonCam UVC, USB 2.0 Camera] MD5=BB04CB2F027D8DE7D3BDAEA147A706CB SIZE=974248

%SYSDIR%\svchost -k DcomLaunch

%SYSDIR%\svchost.exe -k NetworkService

%SYSDIR%\svchost.exe -k hpdevmgmt

%SYSDIR%\svchost.exe -k HTTPFilter

%SYSDIR%\drivers\RtkHDAud.sys [Realtek Semiconductor Corp.] [Realtek® High Definition Audio Function Driver (HRTF data Copyright 1994 by MIT Media Lab)] MD5=3FA02C6E3E9EBE8523A2D4E51D0ECE1F SIZE=5891584

%SYSDIR%\DRIVERS\jmcr.sys [JMicron Technology Corporation] [JMB38X Flash Media Controller Driver] MD5=9EFE54794B3A94E93DA50703692E011E SIZE=113504

%SYSDIR%\svchost.exe -k LocalService

%SYSDIR%\svchost.exe -k HPZ12

%SYSDIR%\svchost -k rpcss

%SYSDIR%\DRIVERS\RTL8187B.sys [Realtek Semiconductor Corporation] [Realtek RTL8187B Wireless USB 2.0 Adapter] MD5=2E2E3A2D1BA5E540C32558F3F37D33E3 SIZE=335104

%SYSDIR%\DRIVERS\sisgrp.sys [silicon Integrated Systems Corporation] [siS ® Compatible Super VGA Miniport Driver for Windows XP] MD5=4FABFAB9231F7E7C833677377CF013B8 SIZE=323584

%SYSDIR%\DRIVERS\SISAGPX.sys [silicon Integrated Systems Corporation] [siS AGPv3.5 Filter for Windows XP] MD5=F8150C74FF24BDBD19F47A6DFD05514A SIZE=35712

%SYSDIR%\DRIVERS\SiSGbeXP.sys [silicon Integrated Systems Corp.] [siS191/190 Ethernet Device] MD5=A86E52C55DE3488B3FC0FF2B8AD711BF SIZE=43392

%SYSDIR%\DRIVERS\siside.sys [silicon Integrated Systems Corp.] [siS PCI Mini IDE Driver] MD5=B4485881BD8AED9B157A2E6CF43C2D51 SIZE=4096

%SYSDIR%\DRIVERS\srvkp.sys [silicon Integrated Systems Corporation] [siS ® WindowsXP Display Manager] MD5=82387BF8F5A35358118B2129FF91C890 SIZE=19072

%SYSDIR%\DRIVERS\smserial.sys [Motorola Inc.] [Motorola SM56 Modem] MD5=BDFD18C04466EDBF78FF663B7CDE08AE SIZE=1092608

%SYSDIR%\drivers\sp_rsdrv2.sys [Crawler.com] [spyware Terminator] MD5=8831252BCF05FCFB5ABD116A22E552D8 SIZE=142592

%SYSDIR%\svchost.exe -k imgsvc

%PROGRAMFILES%\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [TuneUp Software] [TuneUp Utilities] MD5=F2107C9D85EC0DF116939CCCE06AE697 SIZE=10064

%SYSDIR%\svchost.exe -k WudfServiceGroup

%PROGRAMFILES%\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [Microsoft Corporation] [Windows Live Messenger Protocol Handler Module] MD5=61B0C981F7C10B8861809ADC1B31E8E5 SIZE=61264

 

End of Report

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Logfile of HijackThis v1.99.1

Scan saved at 10:08:04, on 21/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe

C:\Arquivos de programas\Internet Download Manager\IDMan.exe

C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Internet Download Manager\IEMonitor.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\WINDOWS\System32\svchost.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\WINDOWS\System32\svchost.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Barra de ferramentas &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing)

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [spywareTerminator] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorShield.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [iDMan] C:\Arquivos de programas\Internet Download Manager\IDMan.exe /onboot

O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: Crawler Search - tbr:iemenu

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing)

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Logfile of HijackThis v1.99.1

Scan saved at 12:38:04, on 23/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\ARQUIV~1\Crawler\CToolbar.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Microsoft Office\Office12\EXCEL.EXE

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Barra de ferramentas &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing)

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: Crawler Search - tbr:iemenu

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{A8B34B3D-AD3F-4884-B364-B6B101BF4CD8}: NameServer = 200.165.132.154 200.149.55.142

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing)

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

LOG DO DrWeb

 

 

4ef45825.qua\data001 C:\Documents and Settings\All Users\Dados de aplicativos\Avira\AntiVir Desktop\INFECTED\4ef45825.qua Win32.HLLW.Autoruner.6412

 

4ef45825.qua C:\Documents and Settings\All Users\Dados de aplicativos\Avira\AntiVir Desktop\INFECTED A pasta contem objectos infectados Movido.

 

RegUBP2b-Usuario.reg C:\Documents and Settings\All Users\Dados de aplicativos\Spybot - Search & Destroy\Snapshots2 Trojan.StartPage.1505 Eliminado.

 

A0057005.reg C:\System Volume Information\_restore{2E688FF2-C923-4539-BED5-D6B4329EC271}\RP86 Trojan.StartPage.1505 Eliminado.

 

A0057231.reg C:\System Volume Information\_restore{2E688FF2-C923-4539-BED5-D6B4329EC271}\RP88 Trojan.StartPage.1505 Eliminado.

 

A0057699.reg C:\System Volume Information\_restore{2E688FF2-C923-4539-BED5-D6B4329EC271}\RP90 Trojan.StartPage.1505 Eliminado.

 

RealDesktopBundle.exe\zwankysearch-stub.exe E:\Meus Documentos\Downloads\Programs\Real Desktop - Setup.exe/data002/{tmp}\RealDesktopBundle.exe Adware.Searchlook.5

 

{tmp}\RealDesktopBundle.exe E:\Meus Documentos\Downloads\Programs\Real Desktop - Setup.exe/data002/{tmp} A pasta contem objectos infectados

 

data002 E:\Meus Documentos\Downloads\Programs A pasta contem objectos infectados

 

Real Desktop - Setup.exe E:\Meus Documentos\Downloads\Programs A pasta contem objectos infectados Movido.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Outros problemas foram removidos pelo Dr. Web CureIt.

______________________

 

:seta: Você observou se o Spyware Terminator removeu mais alguns virus durante a limpeza que você efetuou com ele?

_______________________

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked:

 

O3 - Toolbar: Barra de ferramentas &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing)

 

O8 - Extra context menu item: Crawler Search - tbr:iemenu

_________________________

 

:seta: Depois disto siga esta dica:

 

Tutorial do antivírus BitDefender Online

 

Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador:

C:\Windows\BDOSCAN8\bdoscan.log

 

Na sua próxima resposta responda a pergunta que te fiz acima e poste o log do BitDefender Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir estes procedimentos.

 

Ficamos no aguardo de sua resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Outros problemas foram removidos pelo Dr. Web CureIt.

______________________

 

:seta: Você observou se o Spyware Terminator removeu mais alguns virus durante a limpeza que você efetuou com ele?

_______________________

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked:

 

O3 - Toolbar: Barra de ferramentas &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing)

 

O8 - Extra context menu item: Crawler Search - tbr:iemenu

_________________________

 

:seta: Depois disto siga esta dica:

 

Tutorial do antivírus BitDefender Online

 

Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador:

C:\Windows\BDOSCAN8\bdoscan.log

 

Na sua próxima resposta responda a pergunta que te fiz acima e poste o log do BitDefender Online juntamente com um novo log do Hijackthis e nos diga, por gentileza, como está o seu PC após seguir estes procedimentos.

 

Ficamos no aguardo de sua resposta.

 

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

Antônio, realizei os escaneamentos necessários, trazendo os resultados abaixo pra tua análise: [/b]

 

 

Quanto ao Terminator, nada grave foi encontrado.

 

 

 

[General]

App = "楂䑴晥湥敤⁲湏楬敮匠慣湮牥 v8"

Date = 24:01:2011

Time = 13:05:57

Scan Path = C:\;D:\;E:\;

 

[Engines Info]

Virus Definitions = 6675230

Engine build = "AVCORE v2.1 Windows/i386 11.0.0.42 (Oct 18 2010)"

Scan plugins = 18

Archive plugins = 44

Unpack plugins = 10

E-mail plugins = 6

System plugins = 4

 

[scan Statistics]

Folders = 5640

Files = 190532

Archives = 2689

Packed files = 7027

Identified viruses = 2

Infected files = 2

Warnings = 0

Suspect files = 0

Disinfected files = 0

Deleted files = 2

Copied files = 0

Moved files = 0

Renamed files = 0

I/O Errors = 37

 

[scan Settings]

SecondAction = Delete

FirstAction = Disinfect

Heuristics = 1

Enable Warnings = 1

Exclude Ext =

Extensions = *;

Scan Emails = 1

Scan Archives = 1

Scan Packed = 1

Scan Files = 1

Scan Boot = 1

Verify Memory = 0

 

[scan Results]

Line00000005 = "C:\Documents and Settings\All Users\Dados de aplicativos\Avira\AntiVir Desktop\INFECTED\5281d94c.qua=>(Quarantine-8)=>Internet Download Manager 5.19 build 4 + Patch Upload Jefferson\Patch IDM\Patch 6.xx.exe Detected with: Application.Patch.FA"

Line00000004 = "C:\Documents and Settings\All Users\Dados de aplicativos\Avira\AntiVir Desktop\INFECTED\5281d94c.qua=>(Quarantine-8)=>Internet Download Manager 5.19 build 4 + Patch Upload Jefferson\Patch IDM\Patch 6.xx.exe Disinfection failed"

Line00000003 = "C:\Documents and Settings\All Users\Dados de aplicativos\Avira\AntiVir Desktop\INFECTED\5281d94c.qua=>(Quarantine-8)=>Internet Download Manager 5.19 build 4 + Patch Upload Jefferson\Patch IDM\Patch 6.xx.exe Delete failed"

Line00000002 = "C:\Documents and Settings\Usuario\DoctorWeb\Quarantine\4ef45825.qua=>(Quarantine-8) Infected with: Trojan.Generic.4137406"

Line00000001 = "C:\Documents and Settings\Usuario\DoctorWeb\Quarantine\4ef45825.qua=>(Quarantine-8) Deleted"

Line00000000 = "C:\Documents and Settings\Usuario\DoctorWeb\Quarantine\4ef45825.qua Deleted"

 

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 13:52:29, on 24/1/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\ARQUIV~1\Crawler\CToolbar.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe

C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe

C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe

C:\WINDOWS\System32\svchost.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Documents and Settings\Usuario\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Documents and Settings\Usuario\Desktop\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Arquivos de programas\Internet Download Manager\IDMIECC.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [spywareTerminator] "C:\ARQUIV~1\SPYWAR~1\SpywareTerminatorShield.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [spywareTerminatorUpdate] "C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe"

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Fazer o download de conteúdo de vídeo FLV usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Fazer o download usando o IDM - C:\Arquivos de programas\Internet Download Manager\IEExt.htm

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\idmmbc.dll

O11 - Options group: [iNTERNATIONAL] International

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\ARQUIV~1\Crawler\ctbr.dll (file missing)

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\ARQUIV~1\ARQUIV~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe" /svc (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Arquivos de programas\Java\jre6\bin\jqs.exe" -service -config "C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\sp_rsser.exe

O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Arquivos de programas\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Os problemas encontrados pelo Dr. Web estavam só na quarentena do Avira e do Dr. Web.

____________________

 

:seta: Como está seu PC atualmente?

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Os problemas encontrados pelo Dr. Web estavam só na quarentena do Avira e do Dr. Web.

____________________

 

:seta: Como está seu PC atualmente?

 

 

 

--------------------------------------------------------------------------------------------------------------------------------------------------

 

 

 

Olá Antônio,

 

meu PC até que voltou a funcionar normalmente,

 

ocorre que repentinamente apareceu um outro problema, o Windows Explorer vem fechando automaticamente,

 

bem como qualquer outra janela que eu abra do Windows (tipo Meus Documentos, Meu Computador, etc...)

 

Por Favor, me ajude novamente!!!

 

Desculpe por estar abusando de sua atenção e paciência!!!

 

Abçs!!!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Olá Antônio,

 

meu PC até que voltou a funcionar normalmente,

 

ocorre que repentinamente apareceu um outro problema, o Windows Explorer vem fechando automaticamente,

 

bem como qualquer outra janela que eu abra do Windows (tipo Meus Documentos, Meu Computador, etc...)

 

Por Favor, me ajude novamente!!!

:seta: Siga então, por gentileza as dicas deste tutorial para fazer uma limpeza de seu PC com o Spyware Doctor:

 

Tutorial do Spyware Doctor Starter Edition

 

Na sua próxima resposta poste este log do Spyware Doctor juntamente com um novo log do Hijackthis e nos diga como está o seu Pc depois disto.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.