mahpg42 0 Denunciar post Postado Junho 7, 2011 Boa Noite galera, como varias outras pessoas já postaram na internet, eu tambem peguei o virus do itau, e o antivirus ( microsoft essentials ) naum detectou nada! Até a musica foi copiada! Não consegui resolver! Segue o LOG! Estou desesperado! Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 21:58:12, on 06/06/2011 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Users\Marcell\AppData\Local\Google\Update\1.3.21.57\GoogleCrashHandler.exe C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\SysWOW64\rundll32.exe C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Marcell\Downloads\HijackThis (1).exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.ingush-auto.ru/plugins/system/askdpd9sdc90das90a9/www.bemvindoaoclube.com.br.txt R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Program Files (x86)\GbPlugin\gbieh.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\Users\Marcell\AppData\Local\Temp\MsgPlusUninstall.exe" /Cleanup O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [Google Update] "C:\Users\Marcell\AppData\Local\Google\Update\GoogleUpdate.exe" /c O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: www.bancobrasil.com.br O15 - Trusted Zone: www14.bancobrasil.com.br O15 - Trusted Zone: www2.bancobrasil.com.br O15 - Trusted Zone: www.bb.com.br O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{EC25BAE0-5B70-4E6C-AB29-5E7E39473870}: NameServer = 208.67.222.222,200.204.0.138 O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - Winlogon Notify: GbPluginBb - C:\Program Files (x86)\GbPlugin\gbieh.dll O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe O23 - Service: Gbp Service (GbpSv) - - C:\PROGRA~2\GbPlugin\GbpSv.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: HPWMISVC - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Orolix Device Monitor (OrolixDeviceMonitor) - Orolix Desenvolvimento de Software LTDA. - C:\Program Files (x86)\TIM Communicator\module\devicemon.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: RtVOsdService Installer (RtVOsdService) - Realtek Semiconductor Corp. - C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 11737 bytes Compartilhar este post Link para o post Compartilhar em outros sites
advaldomesquita 93 Denunciar post Postado Junho 7, 2011 mahpg42, bem vindo ao fórum, mas seu post esta em lugar errado! De uma lida nas regras e peça para algum moderador mover para o local correto Abçs Compartilhar este post Link para o post Compartilhar em outros sites
mahpg42 0 Denunciar post Postado Junho 7, 2011 oBRIGADO! Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Junho 7, 2011 Olá mahpg42 1. *Baixe o Bankerfix e salve-o no desktop *Execute-o, clique [OK] > [sIM] (se pedir alguma atualização) > [OK] > [ENTER] *Ao finalizar, tecle [ENTER] *Cole o relatório C:\LinhaDefensiva\relatorio.txt 2. *Baixe o MalwareBytes e salve-o no desktop *Instale o programa e aguarde a atualização *O programa será aberto automaticamente *Na aba [Verificação], selecione [Verificação completa] *Clique [Verificar] e selecione a partição onde o Windows está instalado *Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados] *Cole o relatório apresentado Caso já tenhas o Malwarebytes instalado.... *Abra o Malwarebytes, clique [Atualização] > [baixar Atualizações] *Na aba [Verificação], selecione [x] Verificação completa *Clique [Verificar] e selecione a partição onde o Windows está instalado *Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados] *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
mahpg42 0 Denunciar post Postado Junho 8, 2011 ok, vou baixar e executar e postos os resiultados, obrigado! Compartilhar este post Link para o post Compartilhar em outros sites
mahpg42 0 Denunciar post Postado Junho 8, 2011 Estão abaixo os resultados Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Versão da Base de Dados: 6811 Windows 6.1.7600 Internet Explorer 9.0.8112.16421 08/06/2011 15:22:27 mbam-log-2011-06-08 (15-22-27).txt Tipo de Verificação: Verificação Completa (C:\|D:\|) Objetos escaneados: 372840 Tempo decorrido: 1 hora(s), 29 minuto(s), 56 segundo(s) Processos de Memória Infectados: 0 Módulos de Memória Infectados: 0 Chaves de Registro Infectadas: 0 Valores de Registro Infectados: 0 Itens de Dados no Registro Infectados: 0 Pastas Infectadas: 0 Arquivos Infectados: 0 Processos de Memória Infectados: (Não foram detectados ítens maliciosos) Módulos de Memória Infectados: (Não foram detectados ítens maliciosos) Chaves de Registro Infectadas: (Não foram detectados ítens maliciosos) Valores de Registro Infectados: (Não foram detectados ítens maliciosos) Itens de Dados no Registro Infectados: (Não foram detectados ítens maliciosos) Pastas Infectadas: (Não foram detectados ítens maliciosos) Arquivos Infectados: (Não foram detectados ítens maliciosos) BankerFix 3.1 VALKYRIE - Removedor de Bankers Linha Defensiva | http://www.linhadefensiva.org http://www.linhadefensiva.org/bankerfix/ ------------------------------------------------------- Data: 2011-06-08 - 13:47 ------------------------------------------------------- Lista de Definição: 2011-05-23-1 | CORE: 2010-12-28-6 ======================================================= ----- Fim ------------------------- Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Junho 8, 2011 1. *Delete o Bankerfix e a pasta C:\Linha Defensiva 2. *Baixe o OTL e salve-o no desktop *Execute-o e selecione a opção: [X] Verificar All Users *Clique [Verificação Rápida] e cole os relatórios apresentados (OTL.txt e Extras.txt localizados no desktop) Caso os relatórios fiquem demasiadamente grandes... *Acesse este link *Selecione [x]4 jours *Clique [Enviar arquivo] *Localize o arquivo OTL.txt no desktop *Clique [Abrir] > [Créer le lien Cjoint] *Cole o endereço criado *Faça o mesmo procedimento para o relatório Extras.txt Compartilhar este post Link para o post Compartilhar em outros sites
mahpg42 0 Denunciar post Postado Junho 9, 2011 Segue os links http://cjoint.com/data3/3Fjx4xVj6h8.htm - otl.txt http://cjoint.com/data3/3Fjx4xVj6h8.htm - extras.txt Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Junho 9, 2011 *Selecione e copie (Ctrl+c) o código abaixo: :OTL IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = http://www.ingush-auto.ru/plugins/system/askdpd9sdc90das90a9/www.bemvindoaoclube.com.br.txt FF - prefs.js..network.proxy.autoconfig_url: "http://www.ingush-auto.ru/plugins/system/askdpd9sdc90das90a9/www.bemvindoaoclube.com.br.txt" FF - prefs.js..network.proxy.socks_port: 80 FF - prefs.js..network.proxy.type: 2 :Files C:\Users\Marcell\AppData\Roaming\mozilla\Extensions\IMVUClientXUL@imvu.com @C:\Windows\SysWow64\drivers:GbpKmAp.lst :Commands [emptytemp] [Reboot] *Execute o OTL *Clique no espaço abaixo de "Exames Personalizados/Correções" e cole (Ctrl+v) o código *Clique [Consertar] *O PC será reiniciado *Cole o relatório apresentado Compartilhar este post Link para o post Compartilhar em outros sites
mahpg42 0 Denunciar post Postado Junho 10, 2011 ok Segue o resultado abaixo! All processes killed ========== OTL ========== HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Registry value HKEY_USERS\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL deleted successfully. Prefs.js: "http://www.ingush-auto.ru/plugins/system/askdpd9sdc90das90a9/www.bemvindoaoclube.com.br.txt" removed from network.proxy.autoconfig_url Prefs.js: 80 removed from network.proxy.socks_port Prefs.js: 2 removed from network.proxy.type ========== FILES ========== C:\Users\Marcell\AppData\Roaming\mozilla\Extensions\IMVUClientXUL@imvu.com folder moved successfully. ADS C:\Windows\SysWow64\drivers:GbpKmAp.lst deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Marcell ->Temp folder emptied: 654547414 bytes ->Temporary Internet Files folder emptied: 390010867 bytes ->Java cache emptied: 939270 bytes ->FireFox cache emptied: 93872629 bytes ->Google Chrome cache emptied: 385869466 bytes ->Opera cache emptied: 4717198 bytes ->Flash cache emptied: 33928 bytes User: Public User: Todos os Usuários User: Usuário Padrão ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 73347125 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50521 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1.529,00 mb OTL by OldTimer - Version 3.2.23.0 log created on 06102011_132142 Files\Folders moved on Reboot... File\Folder C:\Users\Marcell\AppData\Local\Temp\etilqs_CYixMu5ox4GqrLk3zQyh not found! C:\Users\Marcell\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Marcell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YNOIJK1L\ADSAdClient31CA1FTZH9.htm not found! C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 moved successfully. C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1 moved successfully. C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2 moved successfully. C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3 moved successfully. C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\data_4 moved successfully. C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\index moved successfully. Registry entries deleted on Reboot... Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Junho 10, 2011 *Execute o OTL e selecione a opção: [X] Verificar All Users *Clique [Verificação Rápida] e cole o relatório OTL.txt Informe também se o problema foi resolvido. Compartilhar este post Link para o post Compartilhar em outros sites
mahpg42 0 Denunciar post Postado Junho 10, 2011 OTL logfile created on: 10/06/2011 17:06:06 - Run 2 OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Marcell\Desktop 64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy 3,75 Gb Total Physical Memory | 2,17 Gb Available Physical Memory | 57,96% Memory free 7,49 Gb Paging File | 5,46 Gb Available in Paging File | 72,87% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 450,18 Gb Total Space | 400,24 Gb Free Space | 88,91% Space Free | Partition Type: NTFS Drive D: | 15,28 Gb Total Space | 2,20 Gb Free Space | 14,39% Space Free | Partition Type: NTFS Computer Name: MARCELLFILTRAL | User Name: Marcell | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2011/06/09 18:40:19 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Marcell\Desktop\OTL.exe PRC - [2011/06/01 17:03:05 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Users\Marcell\AppData\Local\Google\Update\1.3.21.57\GoogleCrashHandler.exe PRC - [2011/05/26 11:29:04 | 000,800,768 | ---- | M] (Yuna Software) -- C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe PRC - [2011/02/04 16:32:02 | 000,092,216 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe PRC - [2010/12/28 09:43:18 | 000,054,664 | ---- | M] ( ) -- C:\PROGRA~2\GbPlugin\GbpSv.exe PRC - [2010/11/07 06:22:00 | 000,286,720 | ---- | M] (Babylon Ltd.) -- C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe PRC - [2010/07/02 11:51:16 | 000,027,192 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe PRC - [2010/07/02 11:48:24 | 000,602,680 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe PRC - [2010/04/20 08:05:24 | 000,027,040 | ---- | M] (Orolix Desenvolvimento de Software LTDA.) -- C:\Program Files (x86)\TIM Communicator\module\devicemon.exe PRC - [2010/04/09 16:54:38 | 001,441,544 | ---- | M] (Motorola, Inc.) -- C:\Arquivos de Programas\Motorola\Bluetooth\btplayerctrl.exe PRC - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe ========== Modules (SafeList) ========== MOD - [2011/06/09 18:40:19 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Marcell\Desktop\OTL.exe MOD - [2010/11/20 08:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll ========== Win32 Services (SafeList) ========== SRV:64bit: - [2010/11/11 14:36:38 | 000,282,616 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv) SRV:64bit: - [2010/11/11 14:36:38 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc) SRV:64bit: - [2010/10/13 15:01:24 | 001,028,096 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Running] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64) SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:64bit: - [2010/06/29 11:52:12 | 004,181,256 | ---- | M] (Motorola, Inc.) [On_Demand | Running] -- C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe -- (Bluetooth Device Manager) SRV:64bit: - [2010/06/18 16:26:18 | 000,103,992 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe -- (HP Wireless Assistant Service) SRV:64bit: - [2010/06/17 13:59:38 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2010/05/20 13:28:14 | 000,677,128 | ---- | M] (Motorola, Inc.) [Auto | Running] -- C:\Program Files\Motorola\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service) SRV:64bit: - [2010/05/20 13:28:12 | 001,096,968 | ---- | M] (Motorola, Inc.) [On_Demand | Running] -- C:\Program Files\Motorola\Bluetooth\audiosrv.exe -- (Bluetooth Media Service) SRV:64bit: - [2010/04/19 18:55:18 | 000,315,392 | ---- | M] (Realtek Semiconductor Corp.) [Auto | Running] -- C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe -- (RtVOsdService) SRV:64bit: - [2009/07/13 22:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt) SRV - [2011/02/04 16:32:02 | 000,092,216 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe) SRV - [2010/12/28 09:43:18 | 000,054,664 | ---- | M] ( ) [unknown | Running] -- C:\PROGRA~2\GbPlugin\GbpSv.exe -- (GbpSv) SRV - [2010/10/13 15:01:23 | 000,647,680 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010/07/02 11:51:16 | 000,027,192 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe -- (HPWMISVC) SRV - [2010/04/20 08:05:24 | 000,027,040 | ---- | M] (Orolix Desenvolvimento de Software LTDA.) [Auto | Running] -- C:\Program Files (x86)\TIM Communicator\module\devicemon.exe -- (OrolixDeviceMonitor) SRV - [2010/04/03 20:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService) SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/11/17 23:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Arquivos de Programas\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters) SRV - [2009/06/10 18:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - [2011/03/21 13:22:06 | 000,452,200 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2010/11/20 10:34:02 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm) DRV:64bit: - [2010/11/20 10:34:02 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus) DRV:64bit: - [2010/11/20 10:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010/11/20 08:35:32 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb) DRV:64bit: - [2010/11/20 08:35:20 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr) DRV:64bit: - [2010/11/20 08:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/11/20 08:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:64bit: - [2010/11/20 06:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus) DRV:64bit: - [2010/10/24 21:25:38 | 000,072,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:64bit: - [2010/09/22 23:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr) DRV:64bit: - [2010/06/29 10:12:26 | 003,232,768 | ---- | M] (Motorola, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmusb.sys -- (BTMUSB) DRV:64bit: - [2010/06/23 21:37:24 | 000,931,168 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x) DRV:64bit: - [2010/06/17 14:07:42 | 006,403,072 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag) DRV:64bit: - [2010/06/17 13:10:34 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2010/06/02 09:50:36 | 000,119,680 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ONDAusbvoice.sys -- (ONDAusbvoice) DRV:64bit: - [2010/06/02 09:50:36 | 000,119,680 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Ondausbser6k.sys -- (ONDAusbser6k) DRV:64bit: - [2010/06/02 09:50:36 | 000,119,680 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Ondausbnmea.sys -- (ONDAusbnmea) DRV:64bit: - [2010/06/02 09:50:36 | 000,119,680 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Ondausbmdm6k.sys -- (ONDAusbmdm6k) DRV:64bit: - [2010/05/27 21:32:56 | 000,320,560 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP) DRV:64bit: - [2010/05/20 12:19:14 | 000,042,496 | ---- | M] (Motorola, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btmaud.sys -- (btmaudio) DRV:64bit: - [2010/05/07 16:19:58 | 000,245,792 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR) DRV:64bit: - [2010/05/06 10:21:46 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:64bit: - [2010/04/09 16:53:04 | 000,052,736 | ---- | M] (Motorola, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btmcom.sys -- (BTMCOM) DRV:64bit: - [2009/12/22 02:26:36 | 000,038,456 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter) DRV:64bit: - [2009/10/07 23:13:34 | 000,070,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2009/10/07 23:13:34 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2009/08/23 22:55:32 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO) DRV:64bit: - [2009/07/13 22:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/13 22:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/13 22:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/06/19 23:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr) DRV:64bit: - [2009/06/10 18:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92) DRV:64bit: - [2009/06/10 18:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac) DRV:64bit: - [2009/06/10 18:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA) DRV:64bit: - [2009/06/10 18:01:06 | 001,146,880 | ---- | M] (LSI Corp) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem) DRV:64bit: - [2009/06/10 17:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs) DRV:64bit: - [2009/06/10 17:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2009/06/10 17:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7) DRV:64bit: - [2009/06/10 17:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel® DRV:64bit: - [2009/06/10 17:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 17:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 17:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 17:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV - [2010/12/28 09:46:30 | 000,046,600 | ---- | M] (GAS Tecnologia) [Kernel | Boot | Stopped] -- C:\Windows\system32\drivers\gbpkm.sys -- (GbpKm) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/3 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=5c9d683e00000000000070f3956f95cd&tlver=1.4.19.19&affID=17159 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3 IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss&mntrId=5c9d683e00000000000070f3956f95cd&tlver=1.4.19.19&affID=17159 IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..network.proxy.autoconfig_url: "" FF - prefs.js..network.proxy.socks_port: "" FF - prefs.js..network.proxy.type: "" FF - prefs.js..browser.startup.homepage: "http://home.sweetim.com" FF - prefs.js..browser.startup.homepage: "http://home.sweetim.com" FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "SweetIM Search" FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: "" FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "SweetIM Search" FF - prefs.js..browser.search.selectedEngine: "SweetIM Search" FF - prefs.js..browser.search.defaultenginename: "SweetIM Search" FF - prefs.js..browser.search.defaulturl: "" FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/11 11:24:03 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/10 13:21:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcell\AppData\Roaming\mozilla\Extensions [2011/06/07 16:45:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcell\AppData\Roaming\mozilla\Firefox\Profiles\mj5fljyj.default\extensions [2011/06/07 16:45:53 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Marcell\AppData\Roaming\mozilla\Firefox\Profiles\mj5fljyj.default\extensions\ffxtlbr@babylon.com [2011/06/06 16:12:46 | 000,003,915 | ---- | M] () -- C:\Users\Marcell\AppData\Roaming\Mozilla\Firefox\Profiles\mj5fljyj.default\searchplugins\SweetIM Search.xml [2011/06/06 16:13:20 | 000,003,910 | ---- | M] () -- C:\Users\Marcell\AppData\Roaming\Mozilla\Firefox\Profiles\mj5fljyj.default\searchplugins\sweetim.xml [2011/04/11 11:24:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions File not found (No name found) -- [2011/03/18 15:04:44 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll [2011/06/07 16:45:55 | 000,002,423 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml [2010/01/01 05:00:00 | 000,001,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\buscape.xml [2010/01/01 05:00:00 | 000,001,212 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mercadolivre.xml [2010/01/01 05:00:00 | 000,001,168 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-br.xml [2010/01/01 05:00:00 | 000,000,952 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-br.xml O1 HOSTS File: ([2011/06/08 13:47:35 | 000,000,822 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (CescrtHlpr Object) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil) O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll (Babylon Ltd.) O3 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found. O4:64bit: - HKLM..\Run: [bTMTrayAgent] C:\Program Files\Motorola\Bluetooth\btmshell.dll (Motorola, Inc.) O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe () O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [babylonToolbar] C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe (Babylon Ltd.) O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Company) O4 - HKLM..\Run: [PlusService] C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe (Yuna Software) O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKU\S-1-5-19..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O9:64bit: - Extra Button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Arquivos de Programas\Motorola\Bluetooth\btmiesend.htm () O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Arquivos de Programas\Motorola\Bluetooth\btmiesend.htm () O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation) O9 - Extra Button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Arquivos de Programas\Motorola\Bluetooth\btmiesend.htm () O9 - Extra 'Tools' menuitem : @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Arquivos de Programas\Motorola\Bluetooth\btmiesend.htm () O13 - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\..Trusted Domains: bancobrasil.com.br ([www] * in Trusted sites) O15 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\..Trusted Domains: bancobrasil.com.br ([www14] * in Trusted sites) O15 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\..Trusted Domains: bancobrasil.com.br ([www2] * in Trusted sites) O15 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\..Trusted Domains: bb.com.br ([www] * in Trusted sites) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20) O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000 Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\ GbPluginBb: DllName - C:\Program Files (x86)\GbPlugin\gbieh.dll - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399F83} - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil) O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011/06/10 13:21:42 | 000,000,000 | ---D | C] -- C:\_OTL [2011/06/10 09:38:19 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview [2011/06/10 09:35:32 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders [2011/06/10 09:28:02 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{6D9189B2-7BEE-43FB-BB53-2E424AC51AEC} [2011/06/09 18:40:04 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\Marcell\Desktop\OTL.exe [2011/06/09 10:16:27 | 000,116,224 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll [2011/06/09 10:15:33 | 000,093,696 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll [2011/06/09 09:17:56 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{9D6C38CA-B371-41D4-AC68-24204A51B610} [2011/06/08 13:51:26 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Roaming\Malwarebytes [2011/06/08 13:51:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011/06/08 13:51:16 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys [2011/06/08 13:51:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011/06/08 13:51:14 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2011/06/08 13:51:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2011/06/08 13:49:21 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Marcell\Desktop\mbam-setup.exe [2011/06/08 09:04:06 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{ECF699C0-B91E-4823-8AD1-416830B6FB50} [2011/06/08 09:00:20 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{01662E6D-9673-4CE2-90AB-198948322F92} [2011/06/07 16:45:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BabylonToolbar [2011/06/07 16:45:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yuna Software [2011/06/07 15:39:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Messenger Plus! [2011/06/07 09:19:45 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{8AC61E6C-1022-4AB8-B104-B5A619779983} [2011/06/06 17:49:45 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{BF46F78E-48BC-4937-B2B4-6A1AA1259C00} [2011/06/06 08:56:41 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{87F88A3D-AF8F-4944-B26C-E09B0CE8777B} [2011/06/04 09:37:12 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{A8233B1A-EB34-44A2-AE78-FA7552E528D7} [2011/06/03 08:51:07 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{821197FF-D027-4908-80DD-B7352022F1C1} [2011/06/02 08:48:17 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{A6825642-556A-449C-AD53-2D1539D7A0AC} [2011/06/01 08:42:12 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{BAC179FB-DB08-4DFD-BE4F-77E47886DC64} [2011/05/31 08:39:47 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{7A2113CD-039A-4CD8-A661-FD6E7047AC80} [2011/05/30 09:07:57 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{5105E6AD-AFBE-4B1C-A21E-4F7E1B4DC4F1} [2011/05/28 09:28:57 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{E15C69A9-DA2E-4859-AD1B-0CB936AB7667} [2011/05/27 09:16:18 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{0137596F-0669-484C-ACD8-D777A260EF69} [2011/05/26 09:21:45 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{D628ACC1-C235-4784-AA3E-3C724F5EF401} [2011/05/25 07:25:11 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{48FDB9EE-26A9-4D76-82D4-744D0ACE3AFE} [2011/05/24 12:05:08 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{446CFBBC-7E49-450B-B757-28279C700CB7} [2011/05/24 00:04:42 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{CE4D8F1E-31ED-48FA-A2F5-CBEAE1D34AE3} [2011/05/23 08:49:19 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{53FDD64E-B1C1-4917-89AA-A04E1E376056} [2011/05/21 09:37:52 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{7383BE2C-881A-462B-90D5-191DBB9495E1} [2011/05/20 12:47:04 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{6181CA46-6565-4380-A2F7-85541194901B} [2011/05/19 09:10:20 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{61125F6F-BD56-4F28-A8B8-81D2A71671F5} [2011/05/18 11:53:39 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{A5635878-CE8A-4DF4-A9FD-431B42CBF4C6} [2011/05/17 09:31:53 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{818EE876-5B66-4447-B24D-35CD6606C6D5} [2011/05/16 08:33:46 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{A5154F08-CCA0-471D-8ECC-5E7EA6EA791B} [2011/05/14 10:04:07 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{1D0E00A2-C9D8-44A2-8D4A-67533CF2DAA5} [2011/05/13 08:48:12 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{B0ECD828-3D1C-4999-8A2B-BDFA0BE93864} [2011/05/12 08:57:32 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{65C8F994-AAAD-4652-B550-CB9525728590} [2 C:\Users\Marcell\*.tmp files -> C:\Users\Marcell\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011/06/10 17:08:00 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-781092494-2567528247-3288085175-1000UA.job [2011/06/10 17:08:00 | 000,001,034 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-781092494-2567528247-3288085175-1000Core.job [2011/06/10 16:53:24 | 001,585,302 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2011/06/10 16:53:24 | 000,688,306 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat [2011/06/10 16:53:24 | 000,638,522 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2011/06/10 16:53:24 | 000,140,072 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat [2011/06/10 16:53:24 | 000,116,316 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2011/06/10 16:52:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011/06/10 16:52:08 | 000,001,070 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2011/06/10 13:38:15 | 000,022,896 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2011/06/10 13:38:15 | 000,022,896 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2011/06/10 13:30:45 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011/06/10 13:29:37 | 3015,888,896 | -HS- | M] () -- C:\hiberfil.sys [2011/06/10 13:04:56 | 000,354,320 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2011/06/09 18:40:19 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Marcell\Desktop\OTL.exe [2011/06/08 14:11:41 | 000,002,369 | ---- | M] () -- C:\Users\Marcell\Desktop\Google Chrome.lnk [2011/06/08 13:51:18 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/06/08 13:49:57 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Marcell\Desktop\mbam-setup.exe [2011/06/07 16:46:31 | 000,001,251 | ---- | M] () -- C:\Users\Marcell\Desktop\Plus World.lnk [2011/06/06 21:55:10 | 000,167,812 | ---- | M] () -- C:\Users\Marcell\Desktop\pag itau.png [2011/05/16 09:26:11 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForMarcell.job [2 C:\Users\Marcell\*.tmp files -> C:\Users\Marcell\*.tmp -> ] ========== Files Created - No Company Name ========== [2011/06/09 10:19:07 | 000,095,744 | ---- | C] () -- C:\Windows\SysNative\RDVGHelper.exe [2011/06/09 10:18:34 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd [2011/06/09 10:14:39 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml [2011/06/09 10:14:08 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml [2011/06/09 10:14:08 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml [2011/06/09 10:13:18 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml [2011/06/09 10:13:17 | 000,146,389 | ---- | C] () -- C:\Windows\SysWow64\printmanagement.msc [2011/06/08 13:51:18 | 000,001,009 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/06/07 16:46:31 | 000,001,251 | ---- | C] () -- C:\Users\Marcell\Desktop\Plus World.lnk [2011/06/06 21:55:10 | 000,167,812 | ---- | C] () -- C:\Users\Marcell\Desktop\pag itau.png [2011/06/06 17:48:16 | 000,002,486 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk [2011/04/18 11:53:25 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\MSJCE.dll [2011/03/05 10:02:26 | 000,001,854 | ---- | C] () -- C:\Users\Marcell\AppData\Roaming\GhostObjGAFix.xml [2011/01/04 12:52:27 | 001,599,340 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2010/10/13 15:03:06 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2010/10/13 15:01:04 | 000,014,051 | ---- | C] () -- C:\Windows\SysWow64\RaCoInst.dat [2010/10/13 14:56:22 | 000,001,105 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2010/10/13 14:56:08 | 000,000,268 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog2.ini [2010/10/13 14:56:08 | 000,000,209 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog.ini [2010/08/30 19:46:56 | 000,000,197 | ---- | C] () -- C:\Windows\SysWow64\HPWA.ini [2010/02/09 18:58:12 | 000,012,800 | ---- | C] () -- C:\Windows\LPRES.DLL [2009/07/14 02:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2009/07/13 23:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT [2009/07/13 23:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat [2009/07/13 21:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2009/07/13 20:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll [2009/07/13 18:59:36 | 001,498,564 | ---- | C] () -- C:\Windows\SysWow64\igkrng400.bin [2009/07/13 18:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll [2009/06/10 18:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat ========== LOP Check ========== [2011/01/03 12:09:28 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\Opera [2011/01/19 12:08:50 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\PhotoScape [2011/01/03 22:11:15 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\PlayFirst [2011/01/22 09:37:00 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\Vivox [2010/12/24 19:01:08 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\WildTangent [2010/12/30 16:49:54 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\Windows Live Writer [2011/03/19 09:28:20 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 204 bytes -> C:\Windows\SysWow64\drivers:GbpKmAp.lst < End of report > Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Junho 11, 2011 OK...log limpo. 1. *No Internet Explorer, clique em [Ferramentas] > [Opções da Internet] *Na aba "Conexões", clique [Configurações da Lan] *Desmarque as opções "Servidor Proxy" e "Usar script de configuração automática". *Clique [OK] 2. *No Firefox, clique [Ferramentas] > [Opções] *Na aba "Avançado" clique [Rede] > [Configurar Conexão] *Selecione "Sem proxy" e clique [OK] 3. *Execute o OTL e clique [Limpeza] > [OK] *O PC será reiniciado Um abraço. Compartilhar este post Link para o post Compartilhar em outros sites
mahpg42 0 Denunciar post Postado Junho 11, 2011 Galera muitíssimo obrigado!!! Problema 100% resolvido!!! Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Junho 11, 2011 PROBLEMA RESOLVIDO Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites