Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Luizfc_

[Arquivado] &nbspErro de aplicativo "avgwdsvc.exe"

Recommended Posts

Toda vez que ligo meu pc esse Erro de aplicativo "avgwdsvc.exe" aparece 2 vezes

 

Fiz um log com o Hijackthis. Segue o Log!

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 13:47:42, on 8/5/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\System32\wbem\wmiapsrv.exe

C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\1.3.21.53\GoogleCrashHandler.exe

C:\Arquivos de programas\MessengerDiscovery\MessengerDiscovery 2.exe

C:\WINDOWS\system32\sistray.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Arquivos de programas\AVG\AVG9\avgwdsvc.exe

C:\Arquivos de programas\AVG\AVG9\avgnsx.exe

C:\Arquivos de programas\AVG\AVG9\avgchsvx.exe

C:\Arquivos de programas\AVG\AVG9\avgrsx.exe

C:\Arquivos de programas\AVG\AVG9\avgcsrvx.exe

C:\Documents and Settings\Luizinho\Meus documentos\Downloads\HijackThis.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss&mntrId=48e6e46f0000000000000025d30f9274&tlver=1.4.19.19&affID=17159

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tangosearch.com/?useie5=1&q=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=48e6e46f0000000000000025d30f9274&tlver=1.4.19.19&affID=17159

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll

R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll

O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll (file missing)

O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Arquivos de programas\ConduitEngine\prxConduitEngine.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG9\avgssie.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Tango - {9C398D3F-95C3-49AB-A00E-3C4089ECD048} - C:\WINDOWS\system32\e178.dll (file missing)

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll

O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll (file missing)

O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll

O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll

O3 - Toolbar: Tango - {9C398D3E-95C3-49AB-A00E-3C4089ECD048} - C:\WINDOWS\system32\e178.dll (file missing)

O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Arquivos de programas\ConduitEngine\prxConduitEngine.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [synTPStart] C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Dados de aplicativos\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dados de aplicativos\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm

O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210

O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205

O8 - Extra context menu item: LG Air Sync Option - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257104335869

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG9\avgpp.dll

O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll

O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Arquivos de programas\AVG\AVG9\avgwdsvc.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: QuestBrowser Service - Unknown owner - C:\Documents and Settings\All Users\Dados de aplicativos\QuestBrowser\questbrowser117.exe (file missing)

O23 - Service: STSService - Unknown owner - C:\Arquivos de programas\SoundTaxi Media Suite\STSService.exe (file missing)

 

--

End of file - 13541 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Olá Luizfc_!

 

:seta: Vá no menu: Iniciar > Painel de Controle > Adicionar ou remover programas > clique no Avg e clique em Remover > aí é só ir seguindo os passos que o desinstalador do Avg vai lhe passando para desinstalar ele.

 

Depois de desinstalar o Avg, sugiro que você o troque pelo Avira ou outro antivirus gratuito de sua preferência, pois o Avg está tendo problemas ultimamente. Caso queira trocá-lo pelo Avira, é só seguir as dicas destes tutoriais para instalá-lo, configurá-lo e utilizá-lo corretamente:

 

Tutorial do Avira AntiVir Personal Edition Classic (Instalação e Configuração)

 

Tutorial do Avira AntiVir Personal Edition Classic (como usá-lo corretamente)

________________________

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked:

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylo....19&affID=17159

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylo....19&affID=17159

 

O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll (file missing)

 

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

 

O2 - BHO: Tango - {9C398D3F-95C3-49AB-A00E-3C4089ECD048} - C:\WINDOWS\system32\e178.dll (file missing)

 

O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Arquivos de programas\Winamp Toolbar\winamptb.dll (file missing)

 

O3 - Toolbar: Tango - {9C398D3E-95C3-49AB-A00E-3C4089ECD048} - C:\WINDOWS\system32\e178.dll (file missing)

 

O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)

______________________

 

:seta: Siga também estas dicas:

 

Tutorial do Ad-Remover

 

Tutorial do Malwarebytes Anti-Malware

_______________________

 

:seta: Na sua próxima resposta poste o log do Malwarebytes juntamente com um novo log do Hijackthis, o log do Ad-Remover que estará em C:\Ad-Report-CLEAN[1].log e nos diga como está o seu PC após estes procedimentos.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite, obrigado pela ajuda,

 

Segue Logs.:

 

Ad-Remover

 

======= REPORT FROM AD-REMOVER 2.0.0.2,G | ONLY XP/VISTA/7 =======

 

Updated by TeamXscript on 12/04/11

Contact: AdRemover[DOT]contact[AT]gmail[DOT]com

website: http://www.teamxscript.org

 

C:\Arquivos de programas\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 20:50:37 on 08/05/2011, Normal boot

 

Microsoft Windows XP Professional Service Pack 3 (X86)

Luizinho@CASA-72A2ETXOUB ( )

 

============== ACTION(S) ==============

 

 

File deleted: C:\WINDOWS\system32\ConduitEngine.tmp

Folder deleted: C:\Documents and Settings\Luizinho\Dados de aplicativos\Mozilla\FireFox\Profiles\dzuv881t.default\conduit

File deleted: C:\Documents and Settings\Luizinho\Dados de aplicativos\Mozilla\FireFox\Profiles\dzuv881t.default\searchplugins\conduit.xml

Folder deleted: C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Conduit

Folder deleted: C:\Arquivos de programas\Conduit

Folder deleted: C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\ConduitEngine

Folder deleted: C:\Arquivos de programas\ConduitEngine

Folder deleted: C:\Documents and Settings\Luizinho\Dados de aplicativos\GabPath

Folder deleted: C:\Documents and Settings\Luizinho\Dados de aplicativos\Toolbar4

 

(!) -- Temporary files deleted.

 

 

-- File opened: C:\Documents and Settings\Luizinho\Dados de aplicativos\Mozilla\FireFox\Profiles\dzuv881t.default\Prefs.js --

Line deleted: user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2737658&Sea...

-- File closed --

 

 

Key deleted: HKLM\Software\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}

Key deleted: HKLM\Software\Classes\CLSID\{65B3F26E-13AE-418E-AC22-ECDB8D9FD6D3}

Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{65B3F26E-13AE-418E-AC22-ECDB8D9FD6D3}

Key deleted: HKLM\Software\Classes\Conduit.Engine

Key deleted: HKLM\Software\Classes\Toolbar.CT2737658

Key deleted: HKLM\Software\Conduit

Key deleted: HKLM\Software\conduitEngine

Key deleted: HKCU\Software\Conduit

Key deleted: HKCU\Software\conduitEngine

Key deleted: HKCU\Software\IEBarProperties

Key deleted: HKCU\Software\MarketPrecision

Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Adparatus

Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{1F096B29-E9DA-4D64-8D63-936BE7762CC5}

Key deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}

Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{213DD725-3D40-4EEF-AAEE-7A48A1070CFA}

Key deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine

Key deleted: HKLM\Software\Microsoft\ESENT\Process\Adparatus

 

Value deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{30F9B915-B755-4826-820B-08FBA6BD249D}

 

 

============== ADDITIONNAL SCAN ==============

 

**** Mozilla Firefox Version [4.0.1 (pt-BR)] ****

 

Plugins\libdivx.dll (The OpenSSL Project, http://www.openssl.org/)

Plugins\npdivx32.dll (DivX,Inc.)

Plugins\npDivxPlayerPlugin.dll (DivX, Inc)

Plugins\NpFv501.dll (1 mal 1 Software GmbH)

Plugins\npganymedenet.dll ( )

Plugins\npwachk.dll (Nullsoft, Inc.)

Plugins\ssldivx.dll (The OpenSSL Project, http://www.openssl.org/)

HKCU_MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0 (x)

HKCU_MozillaPlugins\electronicarts.com/GameFacePlugin (x)

Searchplugins\babylon.xml (hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=48e6e46f0000000000000025d30f9274&tlver=1.4.19.19&affID=17159/)

Searchplugins\buscape.xml (hxxp://busca.buscape.com.br/cprocura)

Searchplugins\mercadolivre.xml (hxxp://pmstrk.mercadolivre.com.br/jm/PmsTrk)

Searchplugins\wikipedia-br.xml (hxxp://pt.wikipedia.org/wiki/Especial:Busca)

Searchplugins\yahoo-br.xml (hxxp://br.search.yahoo.com/search)

Components\browsercomps.dll (Mozilla Foundation)

Extensions\{B13721C7-F507-4982-B2E5-502A71474FED} (Skype extension for Firefox )

Extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6} (QuestBrowser)

HKLM_Extensions|{00ADD29A-66F4-4f22-BCC0-4C1D29DA647B} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\{00ADD29A-66F4-4f22-BCC0-4C1D29DA647B}\

 

-- C:\Documents and Settings\Luizinho\Dados de aplicativos\Mozilla\FireFox\Profiles\dzuv881t.default --

Extensions\newtaburl@sogame.cat (NewTabURL)

Extensions\SkipScreen@SkipScreen (SkipScreen)

Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} (Flagfox)

Extensions\{3e9a3920-1b27-11da-8cd6-0800200c9a66} (Charles Autoconfiguration)

Extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C} (Módulo de Segurança - Banco do Brasil)

Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} (DVDVideoSoft Menu)

Extensions\{cc409fe8-42b4-405b-a9fa-02dfcffbedde} (OMusic)

Searchplugins\search-the-web.xml (?)

Searchplugins\winamp-search.xml (?)

Prefs.js - browser.download.lastDir, C:\\Documents and Settings\\Luizinho\\Desktop

Prefs.js - browser.search.defaultenginename,

Prefs.js - browser.startup.homepage, hxxp://www.google.com.br/

Prefs.js - browser.startup.homepage_override.buildID, 20110413222027

Prefs.js - browser.startup.homepage_override.mstone, rv:2.0.1

Prefs.js - keyword.URL, hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=48e6e46f0000000000000025d30f9274&tlver=1.4.19.19&instlRef=ss...

 

========================================

 

**** Google Chrome Version [11.0.696.60] ****

 

Extension\dhkplhfnhceodhffomolpfigojocbpcb (C:\Arquivos de programas\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbar.crx) (x)

 

-- C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default --

Preferences - default_search_provider: "Oryte Games Brazil Customized Web Search" (Enabled: true) (hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2444516&SearchSource=3&q={searchTerms})

Preferences - homepage: hxxp://www.google.com.br/

Preferences - homepage_is_newtabpage: false

Plugin - Flatcast Viewer Plugin 5.0.225 (Enabled: true) (C:\Arquivos de programas\Mozilla Firefox\plugins\NpFv501.dll)

Plugin - Office Genuine Advantage (Enabled: true) (C:\Arquivos de programas\Mozilla Firefox\plugins\npOGAPlugin.dll)

Plugin - Microsoft DRM (Enabled: true) (C:\Arquivos de programas\Windows Media Player\npdrmv2.dll)

Plugin - Microsoft DRM (Enabled: true) (C:\Arquivos de programas\Windows Media Player\npwmsdrm.dll)

Plugin - Unity Player (Enabled: true) (C:\Documents and Settings\Luizinho\Configuraes locais\Dados de aplicativos\Unity\WebPlayer\loader\npUnity3D32.dll) (x)

Plugin - "Flatcast Viewer Plugin 5.0.225" (Enabled: true)

Plugin - "DivX Player" (Enabled: true)

Plugin - "DivX Player Netscape Plugin" (Enabled: true)

Plugin - "Office Genuine Advantage" (Enabled: true)

Plugin - "Unity Player" (Enabled: true)

Plugin - "Microsoft DRM" (Enabled: true)

Plugin - "GanymedeNet.Detector" (Enabled: true)

Plugin - "Winamp Application Detector" (Enabled: true)

 

========================================

 

**** Internet Explorer Version [8.0.6001.18702] ****

 

HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896

HKCU_Main|Start Page - hxxp://fr.msn.com/

HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896

HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm

HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

HKLM_Main|Start Page - hxxp://fr.msn.com/

HKCU_URLSearchHooks|{14f0d511-36a2-41ca-ae01-ba4f87282c97} - "SHOUTcast Toolbar Search Class" (C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll)

HKCU_URLSearchHooks|{f999a48b-1950-4d81-9971-79018f807b4b} - "FreeOnlineRadioPlayerRecorder Toolbar" (C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll)

HKLM_URLSearchHooks|{14f0d511-36a2-41ca-ae01-ba4f87282c97} - "SHOUTcast Toolbar Search Class" (C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll)

HKLM_URLSearchHooks|{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} (x)

HKCU_SearchScopes\{41A30F3E-E976-40CC-B5E5-1BBFFDA94D9A} - "Search" (hxxp://www.tangosearch.com/?q={searchTerms}&a=SEARCH)

HKCU_SearchScopes\{B576BAFD-FED1-4474-A7D6-CB89D2E13B5D} - "SpeedBit Search" (hxxp://search.speedbit.com/searchresults.asp?src=default&q={searchTerms})

HKLM_SearchScopes\{41A30F3E-E976-40CC-B5E5-1BBFFDA94D9A} - "Search" (hxxp://www.tangosearch.com/?q={searchTerms}&a=SEARCH)

HKCU_Toolbar\WebBrowser|{0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} (C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll)

HKCU_Toolbar\WebBrowser|{F999A48B-1950-4D81-9971-79018F807B4B} (C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll)

HKCU_Toolbar\WebBrowser|{9C398D3E-95C3-49AB-A00E-3C4089ECD048} (C:\WINDOWS\system32\e178.dll) (x)

HKLM_Toolbar|{0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} (C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll)

HKLM_Toolbar|{f999a48b-1950-4d81-9971-79018f807b4b} (C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll)

HKCU_ElevationPolicy\{603C4CC9-5DC6-4C44-873F-8281509DF953} - C:\Arquivos de programas\SpeedBit Video Downloader\Converter.exe (x)

HKLM_ElevationPolicy\11f8c830-530a-4313-886a-2b0b4415c22a - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\FreeOnlineRadioPlayerRecorderToolbarHelper.exe (?)

HKLM_ElevationPolicy\75645006-7c35-42d5-8fe8-608475805c58 - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\FreeOnlineRadioPlayerRecorderToolbarHelper.exe (?)

HKLM_ElevationPolicy\{1ACB6FDD-83AF-424C-8164-23197A94AC36} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\FreeOnlineRadioPlayerRecorderToolbarHelper1.exe (?)

HKLM_ElevationPolicy\{1F949079-DC18-40B2-A3D4-45545FA02DE0} - C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Conduit\CT2737658\FreeOnlineRadioPlayerRecorderAutoUpdaterHelper.exe (x)

HKLM_ElevationPolicy\{603C4CC9-5DC6-4C44-873F-8281509DF953} - C:\Arquivos de programas\SpeedBit Video Downloader\Converter.exe (x)

HKLM_ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} - C:\Arquivos de programas\IMinent Toolbar\TbHelper2.exe (x)

HKLM_ElevationPolicy\{ADADAEE2-457A-4984-A57C-E01C3A2BA612} - c:\arquivos de programas\shoutcast radio toolbar\SHOUTcastTbServer.exe (AOL LLC)

HKLM_ElevationPolicy\{E6B969FB-6D33-48d2-9061-8BBD4899EB08} - C:\Arquivos de programas\Iminent\MMServer\Iminent.MMServer.exe (x)

HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)

BHO\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - "Adobe PDF Reader Link Helper" (C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll)

BHO\{21A88CB9-84D2-4020-A2D1-B25A21034884} - "HistoryTriggerBHO Class" (C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll)

BHO\{9030D464-4C02-4ABF-8ECC-5164760863C6} - "Auxiliar de Conexão do Windows Live" (C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll)

BHO\{C41A1C0E-EA6C-11D4-B1B8-444553540000} - "GbIehObj Class" (C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll)

BHO\{ccec60fc-2608-4e58-9659-3ffc159e8ea9} - "SHOUTcast Loader" (C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll)

BHO\{f999a48b-1950-4d81-9971-79018f807b4b} - "FreeOnlineRadioPlayerRecorder Toolbar" (C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll)

 

========================================

 

C:\Arquivos de programas\Ad-Remover\Quarantine: 88 File(s)

C:\Arquivos de programas\Ad-Remover\Backup: 14 File(s)

 

C:\Ad-Report-CLEAN[1].txt - 08/05/2011 20:51:27 (10120 Byte(s))

 

End at: 20:52:41, 08/05/2011

 

============== E.O.F ==============

 

Malwarebytes

 

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

 

Versão da Base de Dados: 6534

 

Windows 5.1.2600 Service Pack 3 (Safe Mode)

Internet Explorer 8.0.6001.18702

 

8/5/2011 22:28:33

mbam-log-2011-05-08 (22-28-32).txt

 

Tipo de Verificação: Verificação Completa (C:\|)

Objetos escaneados: 221623

Tempo decorrido: 1 hora(s), 14 minuto(s), 44 segundo(s)

 

Processos de Memória Infectados: 0

Módulos de Memória Infectados: 0

Chaves de Registro Infectadas: 1

Valores de Registro Infectados: 0

Itens de Dados no Registro Infectados: 0

Pastas Infectadas: 0

Arquivos Infectados: 1

 

Processos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Infectadas:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QuestBrowser (Adware.QuestBrowser) -> Quarantined and deleted successfully.

 

Valores de Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Pastas Infectadas:

(Não foram detectados ítens maliciosos)

 

Arquivos Infectados:

c:\arquivos de programas\questbrowser\uninstall.exe (Adware.QuestBrowser) -> Quarantined and deleted successfully.

 

hijackthis

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 22:34:17, on 8/5/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\WINDOWS\System32\wbem\wmiapsrv.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\1.3.21.53\GoogleCrashHandler.exe

C:\WINDOWS\system32\sistray.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\Arquivos de programas\MessengerDiscovery\MessengerDiscovery 2.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Documents and Settings\Luizinho\Meus documentos\Downloads\HijackThis.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: SHOUTcast Toolbar Search Class - {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll

R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG9\avgssie.dll (file missing)

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll

O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll

O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Arquivos de programas\SHOUTcast Radio Toolbar\shoutcasttb.dll

O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [synTPStart] C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: &SHOUTcast Search - C:\Documents and Settings\All Users\Dados de aplicativos\SHOUTcast Radio Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dados de aplicativos\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm

O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210

O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205

O8 - Extra context menu item: LG Air Sync Option - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257104335869

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: QuestBrowser Service - Unknown owner - C:\Documents and Settings\All Users\Dados de aplicativos\QuestBrowser\questbrowser117.exe (file missing)

O23 - Service: STSService - Unknown owner - C:\Arquivos de programas\SoundTaxi Media Suite\STSService.exe (file missing)

 

--

End of file - 11952 bytes

 

 

O problema desapareceu, reiniciei o pc mais de 3x e não apareceu mais o erro.

 

Obrigado pela ajuda!

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Vários problemas foram removidos pelo Ad-Remover e Malwarebytes.

___________________

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque a entrada abaixo e clique em Fix checked:

 

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG9\avgssie.dll (file missing)

___________________

 

:seta: No seu log está constando que seu PC está sem antivirus. Sugiro que você instale o antivirus de sua preferência, atualize ele (faça um update), depois disto faça um escaneamento completo do computador com seu antivírus e à medida em que forem sendo achados vírus e programas espiões escolha a opção de desinfectar estes arquivos contaminados ou vá enviando eles para a quarentena. E no caso dos arquivos terem sido enviados para a quarentena, depois de algumas semanas, se o seu computador estiver funcionando normalmente sem estes arquivos que foram para a quarentena, você pode ir na quarentena e excluí-los definitivamente.

___________________

 

:seta: Há muitas toolbars (barras de ferramentas) desnecessárias e que acabam deixando a navegação mais lenta e podem causar travamentos e algumas ainda podem ficar monitorando seus hábitos de navegação. Sugiro que desinstale-as (como a SHOUTcast Toolbar, FreeOnlineRadioPlayerRecorder Toolbar e Winamp Toolbar.

___________________

 

:seta: Baixe o programa Avenger no link abaixo e extraia o conteúdo para o desktop (área de trabalho):

http://swandog46.geekstogo.com/avenger2/download.php

 

*Selecione e copie (Ctrl+C) todo o texto destacado em vermelho abaixo:

 

Drivers to disable:

QuestBrowser Service

STSService

 

Drivers to delete:

QuestBrowser Service

STSService

 

*Execute o programa Avenger

*Clique em [Load Script] > [Paste from Clipboard]

*Clique em [Execute] > [OK]

*O PC será reiniciado

*O relatório será criado em C:\avenger.txt

______________________

 

:seta: Siga, por gentileza, as dicas deste tutorial para fazer um escaneamento de seu PC pelo Nod32 Online:

 

Tutorial do antivirus Nod32 Online

 

Após o término do escaneamento será gerado um relatório (log) que estará no seguinte local do seu computador:

C:\Arquivos de programas\Eset\Eset Online Scanner\log.txt

 

Na sua próxima resposta poste este log do Nod32 Online juntamente com um novo log do Hijackthis, o log do Avenger que estará em C:\avenger.txt e nos diga, por gentileza, se algum virus foi removido pelo seu antivirus que você instalar e como está o seu PC após seguir estes procedimentos. Ficamos no aguardo de sua resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Obrigado pela ajuda, vou poder fazer isso somente no sábado, não tenho tempo de semana... Se puder aguardar até sábado eu agradeço!

 

Até mais.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Obrigado pela ajuda, vou poder fazer isso somente no sábado, não tenho tempo de semana... Se puder aguardar até sábado eu agradeço!

 

Até mais.

:thumbsup: Tranquilo, ficamos na espera.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite,

 

Segue o log do Nod32 Online:

 

ESETSmartInstaller@High as downloader log:

all ok

# version=7

# OnlineScannerApp.exe=1.0.0.1

# OnlineScanner.ocx=1.0.0.6427

# api_version=3.0.2

# EOSSerial=5ca7444cd5dd0e46a392d6cf01e05c80

# end=finished

# remove_checked=false

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2011-05-14 02:13:14

# local_time=2011-05-13 11:13:14 (-0300, Hora oficial do Brasil)

# country="Brazil"

# lang=1033

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=512 16777215 100 0 0 0 0 0

# compatibility_mode=1024 16777215 100 0 47282394 47282394 0 0

# compatibility_mode=1797 16775125 100 93 0 38087324 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=105140

# found=12

# cleaned=0

# scan_time=5712

C:\Arquivos de programas\Cheat Engine\Cheat Engine.exe a variant of Win32/HackTool.CheatEngine.AA application (unable to clean) 00000000000000000000000000000000 I

C:\Arquivos de programas\Cheat Engine\dbk32.dll a variant of Win32/HackTool.CheatEngine.AA application (unable to clean) 00000000000000000000000000000000 I

C:\Arquivos de programas\Cheat Engine\dbk32.sys a variant of Win32/HackTool.CheatEngine.AA application (unable to clean) 00000000000000000000000000000000 I

C:\Arquivos de programas\Cheat Engine\Systemcallretriever.exe a variant of Win32/HackTool.SystemCall.AA application (unable to clean) 00000000000000000000000000000000 I

C:\Arquivos de programas\Cheat Engine\systemcallsignal.exe a variant of Win32/HackTool.SystemCall.AA application (unable to clean) 00000000000000000000000000000000 I

C:\Arquivos de programas\DSE\AKV.exe a variant of Win32/KeyLogger.Ardamax.NAX application (unable to clean) 00000000000000000000000000000000 I

C:\Arquivos de programas\DSE\DSE.001 probably a variant of Win32/KeyLogger.Ardamax.NAY application (unable to clean) 00000000000000000000000000000000 I

C:\Arquivos de programas\NEL\NEL.002 a variant of Win32/KeyLogger.Ardamax application (unable to clean) 00000000000000000000000000000000 I

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\CopaBR2007\mooold.dll probably a variant of Win32/TrojanDropper.Agent.HJOVFDD trojan (unable to clean) 00000000000000000000000000000000 I

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCM\mooold.dll probably a variant of Win32/TrojanDropper.Agent.HJOVFDD trojan (unable to clean) 00000000000000000000000000000000 I

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\fserv\script1.ini probably unknown SCRIPT virus (unable to clean) 00000000000000000000000000000000 I

C:\Documents and Settings\Luizinho\Meus documentos\NoteAntigo\RatioMaster\RatioMaster.exe probably a variant of Win32/Spy.Agent.KUUKBEW trojan (unable to clean) 00000000000000000000000000000000 I

 

log do Hijackthis:

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 23:16:47, on 13/5/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\1.3.21.53\GoogleCrashHandler.exe

C:\WINDOWS\system32\sistray.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\WINDOWS\System32\wbem\wmiapsrv.exe

C:\WINDOWS\System32\alg.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\WINDOWS\System32\dllhost.exe

C:\WINDOWS\System32\msdtc.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Arquivos de programas\Windows Media Player\wmplayer.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Documents and Settings\Luizinho\Meus documentos\Downloads\HijackThis.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing)

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing)

O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing)

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [synTPStart] C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dados de aplicativos\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm

O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210

O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205

O8 - Extra context menu item: LG Air Sync Option - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257104335869

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll

O23 - Service: Avira AntiVir Agendamento (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

 

--

End of file - 11635 bytes

 

log do Avenger;

 

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

 

Platform: Windows XP

 

*******************

 

Script file opened successfully.

Script file read successfully.

 

Backups directory opened successfully at C:\Avenger

 

*******************

 

Beginning to process script file:

 

Rootkit scan active.

No rootkits found!

 

Driver "QuestBrowser Service" disabled successfully.

Driver "STSService" disabled successfully.

Driver "QuestBrowser Service" deleted successfully.

Driver "STSService" deleted successfully.

 

Completed script processing.

 

*******************

 

Finished! Terminate.

 

 

Bom, eu instalei o Avira, ele moveu 25 arquivos para a quarentena. Não excluiu nenhum.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:seta: Exclua o log do Avenger que está em C:\avenger.txt

 

*Selecione e copie (Ctrl+C) todo o texto destacado em vermelho abaixo:

 

Files to delete:

C:\Arquivos de programas\Cheat Engine\Cheat Engine.exe

C:\Arquivos de programas\Cheat Engine\dbk32.dll

C:\Arquivos de programas\Cheat Engine\dbk32.sys

C:\Arquivos de programas\Cheat Engine\Systemcallretriever.exe

C:\Arquivos de programas\Cheat Engine\systemcallsignal.exe

C:\Arquivos de programas\DSE\AKV.exe

C:\Arquivos de programas\DSE\DSE.001

C:\Arquivos de programas\NEL\NEL.002

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\CopaBR2007\mooold.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCM\mooold.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\fserv\script1.ini

C:\Documents and Settings\Luizinho\Meus documentos\NoteAntigo\RatioMaster\RatioMaster.exe

 

*Execute o programa Avenger

*Clique em [Load Script] > [Paste from Clipboard]

*Clique em [Execute] > [OK]

*O PC será reiniciado

*O relatório será criado em C:\avenger.txt

___________________

 

:seta: Abra o HijackThis, clique em Do a system scan only, marque as entradas abaixo e clique em Fix checked:

 

R3 - URLSearchHook: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing)

 

O2 - BHO: FreeOnlineRadioPlayerRecorder - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing)

 

O3 - Toolbar: FreeOnlineRadioPlayerRecorder Toolbar - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Arquivos de programas\FreeOnlineRadioPlayerRecorder\prxtbFre0.dll (file missing)

 

O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Dados de aplicativos\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html

______________________

 

:seta: 1. Baixe o ERUNT e salve-o no desktop

*Crie uma pasta em C:\ chamada ERUNT e extraia para ela

*Execute o arquivo C:\ERUNT\ERUNT.exe

*Clique [OK] > [OK] > [sim] > [OK]

 

2. Sugiro que você salve ou imprima essas instruções abaixo, pois em alguns momentos você poderá precisar usar o computador sem o acesso à internet:

 

Faça o download do ComboFix

Salve-o no Desktop (área de trabalho).

* Desabilite as proteções residente de: antivírus, antispywares e firewall ( menos o do Windows! )

* Feche todas as janelas e execute a ferramenta.

* Ps: A execução, por comando, também é possível:

* Vá em Iniciar --> Executar --> Digite ou cole:

"%userprofile%\desktop\Combofix.exe" /killall

 

combofixejr8.gif

 

* Clique em Ok.

* Na solicitação: "Negação de garantia de software" --> Clique em Sim.

 

RcAuto1.gif

 

* Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo.

* Terminando,clique Sim ou Yes. --> Aguarde.

 

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

 

:!: Caso aconteça a notificação de: Aplicativo Win32 inválido ou alguma mensagem parecida com esta, delete a ferramenta ComboFix.exe e faça, novamente, seu download.

* Salve-a no Desktop,renomeada como: Kombo.exe

* Ps: Nomeie durante o salvamento,e não após salvá-la!

* Ps: Surgindo alguma mensagem de erro, rode o ComboFix.exe em "Modo Seguro". <-- Link!

* Ps: Na presença de atividades rootkit,teremos a seguinte janela de notificação:

 

Rookit_found.gif

 

* Ps: Anote essas detecções, e dê o OK. Neste caso poste estas detecções que você terá anotado em sua próxima resposta juntamente com os logs pedidos.

* Ps: Para completar as remoções, talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!

* Ps: Para evitar problemas, siga todas as recomendações propostas.

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

 

* Abrir-se-á a janela Auto Scan. --> Aguarde!

* Para finalizar remoções, o ComboFix poderá reiniciar o computador.

* Se houver necessidade, digite a opção ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!

* Durante o scan, evite manusear o mouse ou teclado! <-- Importante!

* Caso, por algum motivo de força maior, precise parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter.

<><><><><><><><><><><><>

 

Poste o log do Combofix que estará em C:\ComboFix.txt juntamente com um novo log do Hijackthis e o novo log do Avenger que estará em C:\avenger.txt em sua próxima resposta e nos diga como está o seu PC depois disto.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Log do ComboFix:

 

ComboFix 11-05-14.01 - Luizinho 14/05/2011 22:45:08.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.3055.2573 [GMT -3:00]

Executando de: c:\documents and settings\Luizinho\desktop\Combofix.exe

Comandos utilizados :: /killall

AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}

* Criado um novo ponto de restauração

.

ADS - system32: deleted 2 bytes in 1 streams.

ADS - drivers: deleted 204 bytes in 1 streams.

ADS - WINDOWS: deleted 0 bytes in 1 streams.

.

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\arquivos de programas\Mozilla Firefox\extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6}

c:\arquivos de programas\Mozilla Firefox\extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6}\chrome.manifest

c:\arquivos de programas\Mozilla Firefox\extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6}\chrome\questbrowser.jar

c:\arquivos de programas\Mozilla Firefox\extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6}\defaults\preferences\prefs.js

c:\arquivos de programas\Mozilla Firefox\extensions\{B9B81A55-9C8B-4FD5-B140-714613DED7B6}\install.rdf

c:\arquivos de programas\QuestBrowser

c:\brasfoot2009\Brasfoot2009.exe

c:\brasfoot2010\Brasfoot2010.exe

C:\cleanup.exe

c:\documents and settings\All Users\Dados de aplicativos\QuestBrowser

c:\documents and settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger

c:\documents and settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger\Ardamax Keylogger.lnk

c:\documents and settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger\Help.lnk

c:\documents and settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger\Log Viewer.lnk

c:\documents and settings\Luizinho\Recent\Thumbs.db

c:\documents and settings\Luizinho\WINDOWS

c:\windows\system32\Thumbs.db

c:\windows\XSxS

C:\zip.exe

.

.

(((((((((((((((( Arquivos/Ficheiros criados de 2011-04-15 to 2011-05-15 ))))))))))))))))))))))))))))

.

.

2011-05-15 01:33 . 2011-05-15 01:36 -------- d-----w- C:\ERUNT

2011-05-14 00:20 . 2011-05-14 00:20 -------- d-----w- c:\arquivos de programas\ESET

2011-05-14 00:09 . 2011-05-14 00:09 7144 ----a-w- C:\backup.reg

2011-05-14 00:09 . 2011-05-15 01:24 574 ----a-w- C:\cleanup.bat

2011-05-09 01:59 . 2011-05-14 01:49 -------- d-----w- c:\windows\system32\NtmsData

2011-05-09 01:49 . 2011-05-09 01:49 -------- d-----w- c:\documents and settings\Luizinho\Dados de aplicativos\Avira

2011-05-09 01:44 . 2011-05-13 07:40 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys

2011-05-09 01:44 . 2011-02-04 15:11 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys

2011-05-09 01:44 . 2010-06-17 17:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys

2011-05-09 01:44 . 2010-06-17 17:29 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys

2011-05-09 01:44 . 2011-05-09 01:44 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Avira

2011-05-09 01:44 . 2011-05-09 01:44 -------- d-----w- c:\arquivos de programas\Avira

2011-05-08 23:50 . 2011-05-08 23:50 -------- d-----w- c:\arquivos de programas\Ad-Remover

2011-05-08 20:53 . 2011-05-08 20:53 -------- d-----w- c:\documents and settings\Luizinho\Dados de aplicativos\Electronic Arts

2011-05-08 00:18 . 2011-05-08 00:33 -------- d-----w- c:\arquivos de programas\eMule

2011-05-01 15:52 . 2011-04-14 16:59 142296 ----a-w- c:\arquivos de programas\Mozilla Firefox\components\browsercomps.dll

2011-05-01 15:52 . 2011-04-14 16:59 781272 ----a-w- c:\arquivos de programas\Mozilla Firefox\mozsqlite3.dll

2011-05-01 15:52 . 2011-04-14 16:59 1874904 ----a-w- c:\arquivos de programas\Mozilla Firefox\mozjs.dll

2011-05-01 15:52 . 2011-04-14 16:59 89048 ----a-w- c:\arquivos de programas\Mozilla Firefox\libEGL.dll

2011-05-01 15:52 . 2011-04-14 16:59 465880 ----a-w- c:\arquivos de programas\Mozilla Firefox\libGLESv2.dll

2011-05-01 15:52 . 2011-04-14 16:59 15832 ----a-w- c:\arquivos de programas\Mozilla Firefox\mozalloc.dll

2011-05-01 15:52 . 2010-01-01 08:00 1974616 ----a-w- c:\arquivos de programas\Mozilla Firefox\D3DCompiler_42.dll

2011-05-01 15:52 . 2010-01-01 08:00 1892184 ----a-w- c:\arquivos de programas\Mozilla Firefox\d3dx9_42.dll

2011-04-17 17:46 . 2011-04-17 17:46 -------- d-----w- c:\documents and settings\Luizinho\Dados de aplicativos\BabylonToolbar

2011-04-16 19:43 . 2011-04-16 19:43 -------- d-----w- c:\arquivos de programas\Yuna Software

.

.

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-04-20 14:14 . 2010-08-28 04:21 46600 ----a-w- c:\windows\system32\drivers\gbpkm.sys

2011-03-07 05:33 . 2009-11-01 18:38 692736 ----a-w- c:\windows\system32\inetcomm.dll

2011-03-04 06:36 . 2002-09-09 17:08 420864 ----a-w- c:\windows\system32\vbscript.dll

2011-03-03 13:53 . 2002-09-09 16:44 1858048 ----a-w- c:\windows\system32\win32k.sys

2011-02-22 23:08 . 2002-09-09 17:08 916480 ----a-w- c:\windows\system32\wininet.dll

2011-02-22 23:08 . 2002-09-09 17:08 1469440 ------w- c:\windows\system32\inetcpl.cpl

2011-02-22 23:08 . 2002-09-09 17:07 43520 ----a-w- c:\windows\system32\licmgr10.dll

2011-02-22 11:43 . 2009-11-01 21:41 385024 ----a-w- c:\windows\system32\html.iec

2011-02-17 13:18 . 2002-08-29 04:59 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-02-17 13:18 . 2001-10-28 18:07 357888 ----a-w- c:\windows\system32\drivers\srv.sys

2011-02-17 12:54 . 2008-05-05 09:24 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2011-02-15 12:56 . 2001-10-28 18:06 290432 ----a-w- c:\windows\system32\atmfd.dll

2011-02-14 05:42 . 2011-04-08 01:00 20864 ----a-w- c:\windows\system32\drivers\lgusbdiag.sys

2011-02-14 05:42 . 2011-04-08 01:00 25216 ----a-w- c:\windows\system32\drivers\lgusbmodem.sys

2011-02-14 05:42 . 2011-04-08 01:00 13056 ----a-w- c:\windows\system32\drivers\lgusbbus.sys

2009-08-28 21:42 . 2009-08-28 21:42 1044480 ----a-w- c:\arquivos de programas\mozilla firefox\plugins\libdivx.dll

2009-08-28 21:42 . 2009-08-28 21:42 200704 ----a-w- c:\arquivos de programas\mozilla firefox\plugins\ssldivx.dll

2011-04-14 16:59 . 2011-05-01 15:52 142296 ----a-w- c:\arquivos de programas\mozilla firefox\components\browsercomps.dll

.

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SiSPower"="SiSPower.dll" [2009-02-12 53248]

"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 16804864]

"SMSERIAL"="c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-21 630784]

"SynTPStart"="c:\arquivos de programas\Synaptics\SynTP\SynTPStart.exe" [2007-08-17 102400]

"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-01-22 40368]

"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

"QuickTime Task"="c:\arquivos de programas\QuickTime\QTTask.exe" [2010-11-29 421888]

"SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2010-10-29 249064]

"AdobeAAMUpdater-1.0"="c:\arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-26 500208]

"AdobeCS5ServiceManager"="c:\arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-23 402432]

"avgnt"="c:\arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" [2011-02-04 281768]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]

.

c:\documents and settings\Luizinho\Menu Iniciar\Programas\Inicializar\

Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

.

c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\

Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-11-7 110592]

Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-11-1 262144]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]

2011-04-20 14:11 505736 ----a-w- c:\arquivos de programas\GbPlugin\gbieh.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Arquivos de programas\\uTorrent\\uTorrent.exe"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=

"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"1080:TCP"= 1080:TCP:messenger

"4660:TCP"= 4660:TCP:eMule - Porta TCP

"4670:TCP"= 4670:TCP:eMule - Porta UDP

.

R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [28/8/2010 01:21 46600]

R2 AntiVirSchedulerService;Avira AntiVir Agendamento;c:\arquivos de programas\Avira\AntiVir Desktop\sched.exe [8/5/2011 22:44 136360]

R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [28/8/2010 01:21 56712]

R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [1/11/2009 15:51 113504]

R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [29/9/2009 08:11 12160]

R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [29/9/2009 08:11 10496]

R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [29/9/2009 08:11 12928]

R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187B.sys [1/11/2009 16:50 340096]

S2 gupdate;Google Update Service (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [24/4/2010 16:29 136176]

S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [7/4/2011 22:00 14336]

S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [7/4/2011 22:00 20736]

S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [7/4/2011 22:00 20096]

S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [7/4/2011 22:00 25088]

S3 FlashUSB;FlashUSB;c:\windows\system32\drivers\FlashUSB.sys [21/8/2010 14:40 16896]

S3 gupdatem;Serviço do Google Update (gupdatem);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [24/4/2010 16:29 136176]

S3 lgusbsmodem;LGE Mobile USB Modem;c:\windows\system32\DRIVERS\lgusbsmodem.sys --> c:\windows\system32\DRIVERS\lgusbsmodem.sys [?]

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

.

Conteúdo da pasta 'Tarefas Agendadas'

.

2011-04-13 c:\windows\Tasks\AdobeAAMUpdater-1.0-CASA-72A2ETXOUB-Luizinho.job

- c:\arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-03-26 21:52]

.

2009-12-04 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2008-07-30 14:34]

.

2011-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-04-24 19:29]

.

2011-05-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-04-24 19:29]

.

.

------- Scan Suplementar -------

.

uInternet Settings,ProxyServer = socks=

uInternet Settings,ProxyOverride = local

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~3\Office12\EXCEL.EXE/3000

IE: Free YouTube Download - c:\documents and settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm

IE: Free YouTube to Mp3 Converter - c:\documents and settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm

IE: LG Air Sync (R-Click) - Save as Mobile Image - c:\arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206

IE: LG Air Sync (R-Click) - Save as Mobile Memo - c:\arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208

IE: LG Air Sync (R-Click) - Save as Mobile Text file - c:\arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210

IE: LG Air Sync (R-Click) - Set as Mobile Wallpaper - c:\arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205

IE: LG Air Sync Option - c:\arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209

Trusted Zone: bancobrasil.com.br\www

Trusted Zone: bancobrasil.com.br\www14

Trusted Zone: bancobrasil.com.br\www2

Trusted Zone: bb.com.br\www

DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

FF - ProfilePath - c:\documents and settings\Luizinho\Dados de aplicativos\Mozilla\Firefox\Profiles\dzuv881t.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2737658&SearchSource=3&q={searchTerms}

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br/

FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=48e6e46f0000000000000025d30f9274&tlver=1.4.19.19&instlRef=sst&affID=17159&q=

FF - prefs.js: network.proxy.gopher -

FF - prefs.js: network.proxy.gopher_port - 0

FF - prefs.js: network.proxy.type - 0

FF - user.js: network.proxy.type - 0

FF - user.js: network.proxy.http -

FF - user.js: network.proxy.http_port - 0

FF - user.js: network.proxy.ssl -

FF - user.js: network.proxy.ssl_port - 0

FF - user.js: network.proxy.ftp -

FF - user.js: network.proxy.ftp_port - 0

FF - user.js: network.proxy.gopher -

FF - user.js: network.proxy.gopher_port - 0

FF - user.js: network.proxy.socks_version - 5

FF - user.js: network.proxy.socks -

FF - user.js: network.proxy.socks_port - 0

.

- - - - ORFÃOS REMOVIDOS - - - -

.

WebBrowser-{F999A48B-1950-4D81-9971-79018F807B4B} - (no file)

WebBrowser-{9C398D3E-95C3-49AB-A00E-3C4089ECD048} - c:\windows\system32\e178.dll

AddRemove-FreeOnlineRadioPlayerRecorder Toolbar - c:\arquivos de programas\FreeOnlineRadioPlayerRecorder\uninstall.exe

AddRemove-GabPath - c:\documents and settings\Luizinho\Dados de aplicativos\GabPath\GPUninstall.exe

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-05-14 22:54

Windows 5.1.2600 Service Pack 3 NTFS

.

Procurando processos ocultos ...

.

Procurando entradas auto inicializáveis ocultas ...

.

Procurando ficheiros/arquivos ocultos ...

.

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

.

**************************************************************************

.

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------

.

- - - - - - - > 'winlogon.exe'(720)

c:\arquivos de programas\GBPLUGIN\gbieh.dll

.

- - - - - - - > 'explorer.exe'(4064)

c:\windows\system32\WININET.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

c:\arquivos de programas\GBPLUGIN\gbieh.dll

.

------------------------ Outros Processos em Execução ------------------------

.

c:\arquivos de programas\Avira\AntiVir Desktop\avguard.exe

c:\arquivos de programas\Java\jre6\bin\jqs.exe

c:\arquivos de programas\CDBurnerXP\NMSAccessU.exe

c:\arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

c:\windows\System32\wbem\wmiapsrv.exe

c:\windows\RTHDCPL.EXE

c:\arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe

c:\arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

c:\arquivos de programas\MessengerDiscovery\MessengerDiscovery 2.exe

c:\arquivos de programas\Windows Live\Contacts\wlcomm.exe

.

**************************************************************************

.

Tempo para conclusão: 2011-05-14 23:02:39 - Máquina reiniciou

ComboFix-quarantined-files.txt 2011-05-15 02:02

ComboFix2.txt 2010-05-31 00:29

.

Pré-execução: 19 pasta(s) 241.647.796.224 bytes disponíveis

Pós execução: 20 pasta(s) 242.674.200.576 bytes disponíveis

.

- - End Of File - - A94036290ADFA4206BF56E584051B205

 

log do Hijackthis:

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 23:11:00, on 14/5/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\wbem\wmiapsrv.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

C:\WINDOWS\system32\sistray.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\Arquivos de programas\MessengerDiscovery\MessengerDiscovery 2.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe

C:\Documents and Settings\Luizinho\Meus documentos\Downloads\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [synTPStart] C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm

O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210

O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205

O8 - Extra context menu item: LG Air Sync Option - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257104335869

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll

O23 - Service: Avira AntiVir Agendamento (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

 

--

End of file - 10166 bytes

 

log do Avenger:

 

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

 

Platform: Windows XP

 

*******************

 

Script file opened successfully.

Script file read successfully.

 

Backups directory opened successfully at C:\Avenger

 

*******************

 

Beginning to process script file:

 

Rootkit scan active.

No rootkits found!

 

File "C:\Arquivos de programas\Cheat Engine\Cheat Engine.exe" deleted successfully.

File "C:\Arquivos de programas\Cheat Engine\dbk32.dll" deleted successfully.

File "C:\Arquivos de programas\Cheat Engine\dbk32.sys" deleted successfully.

File "C:\Arquivos de programas\Cheat Engine\Systemcallretriever.exe" deleted successfully.

File "C:\Arquivos de programas\Cheat Engine\systemcallsignal.exe" deleted successfully.

File "C:\Arquivos de programas\DSE\AKV.exe" deleted successfully.

File "C:\Arquivos de programas\DSE\DSE.001" deleted successfully.

File "C:\Arquivos de programas\NEL\NEL.002" deleted successfully.

File "C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\CopaBR2007\mooold.dll" deleted successfully.

File "C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCM\mooold.dll" deleted successfully.

File "C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\fserv\script1.ini" deleted successfully.

File "C:\Documents and Settings\Luizinho\Meus documentos\NoteAntigo\RatioMaster\RatioMaster.exe" deleted successfully.

 

Completed script processing.

 

*******************

 

Finished! Terminate.

 

 

Sinto que meu PC está um pouco mais rápido. Não tive problemas até agora.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) Muitos outros problemas foram removidos.

_________________

 

:seta: Siga também esta dica:

 

Tutorial do Norman Malware Cleaner

 

Na sua próxima resposta poste o conteúdo do log do Norman Malware Cleaner juntamente com um novo log do Hijackthis e nos diga como está o seu PC depois disto.

 

Ficamos na espera.

Compartilhar este post


Link para o post
Compartilhar em outros sites

log do Norman Malware:

 

Norman Malware Cleaner v2.00.05

Copyright © 1990 - 2011, Norman ASA.

 

Norman Scanner Engine Version: 6.07.07

nvcbin.def: Version: 6.07.00, Date: 2011/05/14 22:23:07, Variants: 11989707

nvcmacro.def: Version: 6.07.00, Date: 2011/02/01 12:21:31, Variants: 20465

 

Operating System: Windows XP Service Pack 3

 

Switches: /iagree

Running without NSAK

 

Scan started: 2011/05/15 15:47:29

 

Running pre-scan cleanup routine...

Modified registry value: HKCR\.com --> (null) from 'ComFile' to 'comfile'

Modified registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows --> AppInit_DLLs from '(null)' to ''

Deleted registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System --> DisableRegistryTools = 0x00000000

Deleted registry value: HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer --> NoDrives = 0x00000000

Deleted registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer --> NoDrives = 0x00000000

 

Scanning time: 1s

 

Scanning system for active rootkit activity...

 

Scanning time: 0s

 

Scanning running processes and process memory...

 

Number of objects found: 462

Number of objects scanned: 462

Number of objects not scanned: 0

Number of malicious memory objects found: 0

Scanning time: 29s

 

Running custom scan...

C:\Arquivos de programas\Gravity\Ragnarok Online\directx10.dll: File infected with W32/Obfuscated.T

Deleted file: C:\Arquivos de programas\Gravity\Ragnarok Online\directx10.dll

C:\Arquivos de programas\Gravity\Ragnarok Online\GameGuard\GameMon.des: File infected with Packed_TheMida.B

Deleted file: C:\Arquivos de programas\Gravity\Ragnarok Online\GameGuard\GameMon.des

C:\Arquivos de programas\WinRAR\Default.SFX: File infected with W32/Smalltroj.YWRV

Deleted file: C:\Arquivos de programas\WinRAR\Default.SFX

C:\Documents and Settings\Luizinho\NTUSER.DAT: Error opening file for read: 0x00000020

C:\Documents and Settings\Luizinho\ntuser.dat.LOG: Error opening file for read: 0x00000020

C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat: Error opening file for read: 0x00000020

C:\Documents and Settings\Luizinho\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG: Error opening file for read: 0x00000020

C:\Documents and Settings\Luizinho\Configurações locais\Temporary Internet Files\Content.Word\~WRS{90399EED-CF76-4242-92B3-B6ED1C9C9AF9}.tmp: Error opening file for read: 0x00000020

C:\Documents and Settings\Luizinho\Configurações locais\Temporary Internet Files\Content.Word\~WRS{AC2A3A7C-B8C8-48B9-9C7A-1DEAE78D57AC}.tmp: Error opening file for read: 0x00000020

C:\Documents and Settings\Luizinho\Dados de aplicativos\Microsoft\Modelos\Normal.dotm: Error opening file for read: 0x00000020

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\37\68bf7365-5960c1a5: Archive infected

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\37\68bf7365-5960c1a5/Main.class: File infected with JAVA/DLoader.B

Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\37\68bf7365-5960c1a5/Main.class

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\45\4e2da3ed-400158a3: Archive infected

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\45\4e2da3ed-400158a3/Main.class: File infected with JAVA/DLoader.B

Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\45\4e2da3ed-400158a3/Main.class

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\49\1d4303b1-2274f9a3: Archive infected

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\49\1d4303b1-2274f9a3/Main.class: File infected with JAVA/DLoader.B

Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\49\1d4303b1-2274f9a3/Main.class

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\58\2ad0fa3a-7c4456ed: Archive infected

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\58\2ad0fa3a-7c4456ed/Main.class: File infected with JAVA/DLoader.B

Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\58\2ad0fa3a-7c4456ed/Main.class

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-1c9174ea: Archive infected

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-1c9174ea/Main.class: File infected with JAVA/DLoader.B

Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-1c9174ea/Main.class

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-75808fd0: Archive infected

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-75808fd0/Main.class: File infected with JAVA/DLoader.B

Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\60\19b0c0fc-75808fd0/Main.class

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\8\13b97e08-64e84abf: Archive infected

C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\8\13b97e08-64e84abf/Main.class: File infected with JAVA/DLoader.B

Deleted archive object: C:\Documents and Settings\Luizinho\Dados de aplicativos\Sun\Java\Deployment\cache\6.0\8\13b97e08-64e84abf/Main.class

C:\Documents and Settings\Luizinho\Desktop\Faça o download do Norman Malware Cleaner e renomeie.docx: Error opening file for read: 0x00000020

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip: Archive infected

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/1231.zip/wiSdOmBOTv43.exe: File infected with Suspicious_Gen2.ARXBX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/1231.zip/wiSdOmBOTv43.exe

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/1231.zip

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\1231.zip: Archive infected

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\1231.zip/wiSdOmBOTv43.exe: File infected with Suspicious_Gen2.ARXBX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\1231.zip/wiSdOmBOTv43.exe

Deleted file: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\1231.zip

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\CyberScript.exe: File infected with W32/Suspicious_Gen2.CSAJZ

Deleted file: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\CyberScript.exe

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\wiSdOmBOTv43.exe: File infected with Suspicious_Gen2.ARXBX

Deleted file: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\wiSdOmBOTv43.exe

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/CopaBR2007/moo.dll: File infected with W32/Suspicious_Gen2.JOHX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/CopaBR2007/moo.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/CopaBR2007/mooold.dll: File infected with W32/Smalltroj.CXEP

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/CopaBR2007/mooold.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/FUTNEW_-_gameirc.zip/Fnewgsx/FutNEW/mirc.exe: File infected with W32/Suspicious_Gen2.AGKME

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/Tabelas/FUTNEW_-_gameirc.zip/Fnewgsx/FutNEW/mirc.exe

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\FUTNEW_-_gameirc.zip: Archive infected

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\FUTNEW_-_gameirc.zip/Fnewgsx/FutNEW/mirc.exe: File infected with W32/Suspicious_Gen2.AGKME

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\Tabelas\FUTNEW_-_gameirc.zip/Fnewgsx/FutNEW/mirc.exe

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCMs(breher).rar/xIRCM\moo.dll: File infected with W32/Suspicious_Gen2.JOHX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCMs(breher).rar/xIRCM\moo.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCMs(breher).rar/xIRCM\mooold.dll: File infected with W32/Smalltroj.CXEP

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCMs(breher).rar/xIRCM\mooold.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCM/moo.dll: File infected with W32/Suspicious_Gen2.JOHX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCM/moo.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCM/mooold.dll: File infected with W32/Smalltroj.CXEP

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/addons/textos/xIRCM/mooold.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/CyberScript.exe: File infected with W32/Suspicious_Gen2.CSAJZ

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/CyberScript.exe

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCMs(breher).rar: Archive infected

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCMs(breher).rar/xIRCM\moo.dll: File infected with W32/Suspicious_Gen2.JOHX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCMs(breher).rar/xIRCM\moo.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCMs(breher).rar/xIRCM\mooold.dll: File infected with W32/Smalltroj.CXEP

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\addons\textos\xIRCMs(breher).rar/xIRCM\mooold.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/DOWNLOAD/XirCM.rar/XirCM\moo.dll: File infected with W32/Suspicious_Gen2.JOHX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/DOWNLOAD/XirCM.rar/XirCM\moo.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/DOWNLOAD/XirCM.rar/XirCM\mooold.dll: File infected with W32/Smalltroj.CXEP

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/DOWNLOAD/XirCM.rar/XirCM\mooold.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/sistema/dlls/nHTMLn.dll: File infected with W32/Suspicious_Gen2.IYCS

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/sistema/dlls/nHTMLn.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/wiSdOmBOTv43.exe: File infected with Suspicious_Gen2.ARXBX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32.zip/CyberScript32/wiSdOmBOTv43.exe

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\DOWNLOAD\XirCM.rar: Archive infected

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\DOWNLOAD\XirCM.rar/XirCM\moo.dll: File infected with W32/Suspicious_Gen2.JOHX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\DOWNLOAD\XirCM.rar/XirCM\moo.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\DOWNLOAD\XirCM.rar/XirCM\mooold.dll: File infected with W32/Smalltroj.CXEP

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\CyberScript32\DOWNLOAD\XirCM.rar/XirCM\mooold.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\FutNew.rar: Archive infected

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\FutNew.rar/FutNew3\mirc.exe: File infected with Suspicious_Gen2.VMSE

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\FutNew.rar/FutNew3\mirc.exe

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\irCM(1)))).rar: Archive infected

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\irCM(1)))).rar/irCM\moo.dll: File infected with W32/Suspicious_Gen2.JOHX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\irCM(1)))).rar/irCM\moo.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\irCM(1)))).rar/irCM\mooold.dll: File infected with W32/Smalltroj.CXEP

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\irCM(1)))).rar/irCM\mooold.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\XirCM.zip: Archive infected

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\XirCM.zip/XirCM/moo.dll: File infected with W32/Suspicious_Gen2.JOHX

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\XirCM.zip/XirCM/moo.dll

C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\XirCM.zip/XirCM/mooold.dll: File infected with W32/Smalltroj.CXEP

Deleted archive object: C:\Documents and Settings\Luizinho\Meus documentos\MP4\z - Diversas coisas\Luizinho\Bot's do Mirc\XirCM.zip/XirCM/mooold.dll

C:\Documents and Settings\NetworkService\NTUSER.DAT: Error opening file for read: 0x00000020

C:\Documents and Settings\NetworkService\ntuser.dat.LOG: Error opening file for read: 0x00000020

C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat: Error opening file for read: 0x00000020

C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG: Error opening file for read: 0x00000020

C:\GMouse20\Gmouse.exe: File infected with W32/Suspicious_Gen2.CRFM

Deleted file: C:\GMouse20\Gmouse.exe

C:\Qoobox\Quarantine\C\cleanup.exe.vir: File infected with W32/Zapchast.CTP

Deleted file: C:\Qoobox\Quarantine\C\cleanup.exe.vir

C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger\Ardamax Keylogger.lnk.vir: File infected with LNK/Keylogger.B

Deleted file: C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Menu Iniciar\Programas\Ardamax Keylogger\Ardamax Keylogger.lnk.vir

C:\System Volume Information\_restore{1D144516-BB1B-49D7-BAE2-F6EDC28D2E29}\RP36\A0002654.exe: File infected with W32/Zapchast.CTP

Deleted file: C:\System Volume Information\_restore{1D144516-BB1B-49D7-BAE2-F6EDC28D2E29}\RP36\A0002654.exe

C:\System Volume Information\_restore{1D144516-BB1B-49D7-BAE2-F6EDC28D2E29}\RP36\A0002655.lnk: File infected with LNK/Keylogger.B

Deleted file: C:\System Volume Information\_restore{1D144516-BB1B-49D7-BAE2-F6EDC28D2E29}\RP36\A0002655.lnk

C:\WINDOWS\Installer\10e838.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\16bcf7.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\1ddd97.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\1e5f50f.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\1e5f51b.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\203cd9.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\203cc3.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\20c4f.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\20c65.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\2251b.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\245ae.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\251e8.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\25d25.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\25d3b.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\25d52.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\25d68.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\25d80.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\25d98.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\25db0.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\25dc7.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\25de2.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\26198.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\26cdd.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\26cf3.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\26d0f.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\26d25.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\286de.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\286f4.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\2870a.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\30c0a.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\31962b.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\319642.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\319658.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\31966e.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\319684.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\33133.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\34ead.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\34eb5.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\34ec8.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\34ed2.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\34f06.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\34f0c.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\35eb79.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\3d374c.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\42244.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\4225a.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\42270.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\428a32.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\45518f.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\4551a5.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\4551bb.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\4768d9.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\49980.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\4a5a8.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\4dd80.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\4f5ba.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\4fc52.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\5583e.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\56aeb.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\56b01.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\5753da.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\5753ef.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\575406.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\575432.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\57541c.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\599b0b.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\599b8a.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\64aad9.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\662e17.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\662e01.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\662e36.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69c25b.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\662e37.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69c27b.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69e363.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69e364.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69e365.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69e366.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69e367.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69e368.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69e369.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69e36a.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\69e36b.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6b391.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6b39b.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6b3a4.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6b3ab.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6b3b5.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6b3c4.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6ba966.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6ba967.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6ba968.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6ba969.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6ba96a.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6ba96b.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6ba96c.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6ba96d.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6ba96e.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6ba96f.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f00.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f01.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f02.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f03.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f04.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f14.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f15.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f17.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f16.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f18.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f19.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f1a.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f2e.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f38.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6d5f43.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\6f4129.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\79071f.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\790726.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7ace8e.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7ace99.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7aceb0.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7acebb.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7acebc.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7aceca.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7acee0.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7acef6.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7acf0c.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7acf27.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7acf28.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7acf3f.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7acf64.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7acf4e.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7f385f.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\7f386a.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\84116.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\8b48e.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\aad186.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\aad19c.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7b56.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7b6c.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7b82.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7baa.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7bc5.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7bda.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7bf2.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7c09.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7c1f.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7c39.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7c4f.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7c67.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7c7d.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7c93.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\ad7ca9.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\c53fbe.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\d0322.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\d0338.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\d0352.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\d800c9.msp: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\APEX.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\APEX.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ASPECT.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ASPECT.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CIVIC.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CIVIC.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONCOURSE.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\CONCOURSE.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EQUITY.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\EQUITY.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FLOW.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FLOW.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FOUNDRY.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\FOUNDRY.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MEDIAN.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MEDIAN.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\METRO.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\METRO.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MODULE.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\MODULE.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OPULENT.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OPULENT.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ORIEL.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ORIEL.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ORIGIN.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ORIGIN.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PAPER.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PAPER.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SOLSTICE.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\SOLSTICE.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TECHNIC.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TECHNIC.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TREK.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\TREK.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\URBAN.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\URBAN.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VERVE.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\VERVE.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\APEX.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\APEX.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\ASPECT.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\ASPECT.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\CIVIC.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\CIVIC.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\CONCOURSE.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\EQUITY.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\EQUITY.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\FLOW.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\FLOW.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\FOUNDRY.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\MEDIAN.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\MEDIAN.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\METRO.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\METRO.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\MODULE.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\MODULE.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\OPULENT.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\OPULENT.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\ORIEL.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\ORIGIN.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\ORIGIN.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\PAPER.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\PAPER.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\SOLSTICE.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\SOLSTICE.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\TECHNIC.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\TECHNIC.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\TREK.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\TREK.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\URBAN.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\URBAN.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\VERVE.EFTX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.4518\VERVE.THMX: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK01.ONEPKG_1046: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK03.ONEPKG_1046: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK04.ONEPKG_1046: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK05.ONEPKG_1046: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK06.ONEPKG_1046: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK07.ONEPKG_1046: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK10.ONEPKG_1046: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\NOTEBOOK11.ONEPKG_1046: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\000021091A0061400000000000F01FEC\12.0.4518\ONGUIDE.ONEPKG_1046: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\00002109E60061400000000000F01FEC\12.0.4518\XLATE_COMPLETE.XSN_1046: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\$PatchCache$\Managed\26DDC2EC4210AC63483DF9D4FCC5B59D\3.5.30729\Chrome_jar.3643236F_FC70_11D3_A536_0090278A1BB8: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\{26A24AE4-039D-4CA4-87B4-2F83216017FF}\sp1033.MST: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\{4286E640-B5FB-11DF-AC4B-005056C00008}\1046.MST: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\ShellUI.MST: Error opening file for read: 0x00000005

C:\WINDOWS\Installer\{90120000-0051-0000-0000-0000000FF1CE}\ShellUI.MST: Error opening file for read: 0x00000005

C:\WINDOWS\system32\config\default: Error opening file for read: 0x00000020

C:\WINDOWS\system32\config\default.LOG: Error opening file for read: 0x00000020

C:\WINDOWS\system32\config\SAM: Error opening file for read: 0x00000020

C:\WINDOWS\system32\config\SAM.LOG: Error opening file for read: 0x00000020

C:\WINDOWS\system32\config\SECURITY: Error opening file for read: 0x00000020

C:\WINDOWS\system32\config\SECURITY.LOG: Error opening file for read: 0x00000020

C:\WINDOWS\system32\config\software: Error opening file for read: 0x00000020

C:\WINDOWS\system32\config\software.LOG: Error opening file for read: 0x00000020

C:\WINDOWS\system32\config\system: Error opening file for read: 0x00000020

C:\WINDOWS\system32\config\system.LOG: Error opening file for read: 0x00000020

 

Number of files found: 91473

Number of archives unpacked: 4943

Number of objects found: 329080

Number of objects scanned: 328820

Number of objects not scanned: 273

Number of malicious objects found: 41

Number of malicious objects cleaned: 41

Number of malicious files found: 25

Number of malicious files cleaned: 25

Scanning time: 2h 18m 29s

Running post-scan cleanup routine...

Modified registry value: HKCR\.com --> (null) from 'ComFile' to 'comfile'

 

Scanning time: 0s

 

Results:

Total number of files found: 91473

Total number of archives unpacked: 4943

Total number of objects found: 329542

Total number of objects scanned: 329282

Total number of objects not scanned: 273

Total number of malicious objects found: 47

Total number of malicious objects cleaned: 47

Total number of malicious files found: 25

Total number of malicious files cleaned: 25

Total scanning time: 2h 18m 59s

 

log do Hijackthis:

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 18:10:04, on 15/5/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\ARQUIV~1\GbPlugin\GbpSv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe

C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe

C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe

C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Synaptics\SynTP\SynTPEnh.exe

C:\WINDOWS\system32\sistray.exe

C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\System32\wbem\wmiapsrv.exe

C:\Arquivos de programas\MessengerDiscovery\MessengerDiscovery 2.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe

C:\Documents and Settings\Luizinho\Meus documentos\Downloads\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: LinkAirBrowserHelper HistoryTriggerBHO - {21A88CB9-84D2-4020-A2D1-B25A21034884} - C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\LinkAirBrowserHelper.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [sMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe

O4 - HKLM\..\Run: [synTPStart] C:\Arquivos de programas\Synaptics\SynTP\SynTPStart.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Arquivos de programas\Arquivos comuns\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Arquivos de programas\Arquivos comuns\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin

O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubedownload.htm

O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Luizinho\Dados de aplicativos\DVDVideoSoftIEHelpers\youtubetomp3.htm

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Image - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/206

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Memo - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/208

O8 - Extra context menu item: LG Air Sync (R-Click) - Save as Mobile Text file - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/210

O8 - Extra context menu item: LG Air Sync (R-Click) - Set as Mobile Wallpaper - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/205

O8 - Extra context menu item: LG Air Sync Option - res://C:\Arquivos de programas\LG Electronics\LG PC Suite IV\LinkAir\IEContextMenu.dll/209

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257104335869

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll

O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll

O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll

O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll

O23 - Service: Avira AntiVir Agendamento (AntiVirSchedulerService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NMSAccessU - Unknown owner - C:\Arquivos de programas\CDBurnerXP\NMSAccessU.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

 

--

End of file - 10423 bytes

 

 

Meu pc está normal, não deu erro ainda.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:) 25 problemas foram removidos pelo Norman.

_____________________

 

:seta: Siga também esta dica:

 

Tutorial do SUPERAntispyware (instalação e utilização)

____________________

 

:seta: Na sua próxima resposta poste o log do SuperAntispyware, nos diga se os problemas encontrados por ele foram removidos e nos diga como está seu PC depois disto.

 

Ficamos no aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue log do SuperAntispyware:

 

SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 05/15/2011 at 09:42 PM

 

Application Version : 4.52.1000

 

Core Rules Database Version : 7062

Trace Rules Database Version: 4874

 

Scan type : Complete Scan

Total Scan Time : 01:19:39

 

Memory items scanned : 566

Memory threats detected : 0

Registry items scanned : 7636

Registry threats detected : 10

File items scanned : 92850

File threats detected : 82

 

Browser Hijacker.Internet Explorer Zone Hijack

HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br

HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www

HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www#*

HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www14

HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www14#*

HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www2

HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bancobrasil.com.br\www2#*

HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bb.com.br

HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bb.com.br\www

HKU\S-1-5-21-1960408961-448539723-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bb.com.br\www#*

 

Adware.Tracking Cookie

C:\Documents and Settings\Luizinho\Cookies\luizinho@eaeacom.112.2o7[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@myroitracking[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@doubleclick[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@content.yieldmanager[3].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@ad.yieldmanager[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@msnportal.112.2o7[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@atdmt.combing[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@cofidis2.solution.weborama[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@bs.serving-sys[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@media-player-classic.softonic.com[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@www.googleadservices[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@terra.112.2o7[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@boursoramabanque.solution.weborama[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@smileycentral[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@portalclaro.ad.adnetwork.com[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@eset.122.2o7[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@apmebf[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@atdmt[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@microsoftwllivemkt.112.2o7[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@cms.trafficmp[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@smartadserver[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@mediaplex[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@vivo.ad.adnetwork.com[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@advertising[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@azjmp[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@avgtechnologies.112.2o7[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@content.yieldmanager[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@www.googleadservices[3].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@weborama[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@ads.lzjl[1].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@www.googleadservices[5].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@serving-sys[3].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@fastclick[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@clicksor[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@247realmedia[2].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@www.googleadservices[6].txt

C:\Documents and Settings\Luizinho\Cookies\luizinho@www.googleadservices[4].txt

bc.you---.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

cdn-www.---hub.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

cdn4.specificclick.net [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

content3.---kolt.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

ec.atdmt.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

findel.scene7.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

ia.media-imdb.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

images.indieclick.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

latam-media.disneyinternational.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media.buto.tv [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media.ign.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media.movieweb.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media.mtvnservices.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media.mtvu.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media.scanscout.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media.shufuni.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media01.kyte.tv [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media1.break.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media1.shopto.net [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

media1.shufuni.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

naiadsystems.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

objects.tremormedia.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

---otube.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

rmd.atdmt.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

s0.2mdn.net [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

secure-us.imrworldwide.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

static.cineclick.uol.com.br [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

swf.portal---o.com.br [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

vhss-a.oddcast.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

vhss-d.oddcast.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

vidii.hardsextube.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.adult-im.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.hornypharaoh.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.mestredosexo.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.naiadsystems.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.----star.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.---hub.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.---obis.com.br [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.---otube.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.---tube.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.sexopop.com.br [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.sextvx.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.twelvefifteen.net [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

www.user---.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

wwwstatic.mega---.com [ C:\Documents and Settings\Luizinho\Dados de aplicativos\Macromedia\Flash Player\#SharedObjects\MKC93ETZ ]

 

92 Arquivos foram para quarentena e excluidos. Meu PC está um pouco mais rápido, por enquanto sem erros.

Compartilhar este post


Link para o post
Compartilhar em outros sites
92 Arquivos foram para quarentena e excluidos. Meu PC está um pouco mais rápido, por enquanto sem erros.

:seta: Siga, por gentileza, esta dica:

 

Tutorial do Ad-Aware Free Internet Security 9 (Instalação e utilização)

 

Depois disto poste o log do Ad-Aware junto com novo log do Hijackthis e nos diga como está o PC depois disto.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.