Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

mahpg42

[Resolvido] &nbspProblema de virus no ITAU

Recommended Posts

Boa Noite galera,

 

como varias outras pessoas já postaram na internet, eu tambem peguei o virus do itau, e o antivirus ( microsoft essentials ) naum detectou nada!

Até a musica foi copiada!

 

Não consegui resolver!

 

Segue o LOG!

 

Estou desesperado!

 

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 21:58:12, on 06/06/2011

Platform: Windows 7 (WinNT 6.00.3504)

MSIE: Internet Explorer v9.00 (9.00.8112.16421)

Boot mode: Normal

 

Running processes:

C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe

C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Users\Marcell\AppData\Local\Google\Update\1.3.21.57\GoogleCrashHandler.exe

C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe

C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Windows\SysWOW64\rundll32.exe

C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Windows Live\Mail\wlmail.exe

C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Marcell\AppData\Local\Google\Chrome\Application\chrome.exe

C:\Users\Marcell\Downloads\HijackThis (1).exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.ingush-auto.ru/plugins/system/askdpd9sdc90das90a9/www.bemvindoaoclube.com.br.txt

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F2 - REG:system.ini: UserInit=userinit.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Program Files (x86)\GbPlugin\gbieh.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe

O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\Users\Marcell\AppData\Local\Temp\MsgPlusUninstall.exe" /Cleanup

O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [Google Update] "C:\Users\Marcell\AppData\Local\Google\Update\GoogleUpdate.exe" /c

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm

O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O15 - Trusted Zone: www.bancobrasil.com.br

O15 - Trusted Zone: www14.bancobrasil.com.br

O15 - Trusted Zone: www2.bancobrasil.com.br

O15 - Trusted Zone: www.bb.com.br

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{EC25BAE0-5B70-4E6C-AB29-5E7E39473870}: NameServer = 208.67.222.222,200.204.0.138

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O20 - Winlogon Notify: GbPluginBb - C:\Program Files (x86)\GbPlugin\gbieh.dll

O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe

O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe

O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe

O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe

O23 - Service: Gbp Service (GbpSv) - - C:\PROGRA~2\GbPlugin\GbpSv.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe

O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe

O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe

O23 - Service: HPWMISVC - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: Orolix Device Monitor (OrolixDeviceMonitor) - Orolix Desenvolvimento de Software LTDA. - C:\Program Files (x86)\TIM Communicator\module\devicemon.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: RtVOsdService Installer (RtVOsdService) - Realtek Semiconductor Corp. - C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

 

--

End of file - 11737 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

mahpg42, bem vindo ao fórum, mas seu post esta em lugar errado!

De uma lida nas regras e peça para algum moderador mover para o local correto

 

Abçs

Compartilhar este post


Link para o post
Compartilhar em outros sites

Olá mahpg42

 

 

1.

*Baixe o Bankerfix e salve-o no desktop

*Execute-o, clique [OK] > [sIM] (se pedir alguma atualização) > [OK] > [ENTER]

*Ao finalizar, tecle [ENTER]

*Cole o relatório C:\LinhaDefensiva\relatorio.txt

 

2.

*Baixe o MalwareBytes e salve-o no desktop

*Instale o programa e aguarde a atualização

*O programa será aberto automaticamente

*Na aba [Verificação], selecione [Verificação completa]

*Clique [Verificar] e selecione a partição onde o Windows está instalado

*Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados]

*Cole o relatório apresentado

 

Caso já tenhas o Malwarebytes instalado....

 

*Abra o Malwarebytes, clique [Atualização] > [baixar Atualizações]

*Na aba [Verificação], selecione [x] Verificação completa

*Clique [Verificar] e selecione a partição onde o Windows está instalado

*Ao finalizar o scan, clique [sIM] > [OK] > [Ver Resultados] > [Remover Selecionados]

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

Estão abaixo os resultados

 

 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Versão da Base de Dados: 6811

 

Windows 6.1.7600

Internet Explorer 9.0.8112.16421

 

08/06/2011 15:22:27

mbam-log-2011-06-08 (15-22-27).txt

 

Tipo de Verificação: Verificação Completa (C:\|D:\|)

Objetos escaneados: 372840

Tempo decorrido: 1 hora(s), 29 minuto(s), 56 segundo(s)

 

Processos de Memória Infectados: 0

Módulos de Memória Infectados: 0

Chaves de Registro Infectadas: 0

Valores de Registro Infectados: 0

Itens de Dados no Registro Infectados: 0

Pastas Infectadas: 0

Arquivos Infectados: 0

 

Processos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Módulos de Memória Infectados:

(Não foram detectados ítens maliciosos)

 

Chaves de Registro Infectadas:

(Não foram detectados ítens maliciosos)

 

Valores de Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Itens de Dados no Registro Infectados:

(Não foram detectados ítens maliciosos)

 

Pastas Infectadas:

(Não foram detectados ítens maliciosos)

 

Arquivos Infectados:

(Não foram detectados ítens maliciosos)

 

 

 

BankerFix 3.1 VALKYRIE - Removedor de Bankers

Linha Defensiva | http://www.linhadefensiva.org

http://www.linhadefensiva.org/bankerfix/

-------------------------------------------------------

Data: 2011-06-08 - 13:47

-------------------------------------------------------

Lista de Definição: 2011-05-23-1 | CORE: 2010-12-28-6

=======================================================

 

 

 

----- Fim -------------------------

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Delete o Bankerfix e a pasta C:\Linha Defensiva

 

2.

*Baixe o OTL e salve-o no desktop

*Execute-o e selecione a opção:

[X] Verificar All Users

*Clique [Verificação Rápida] e cole os relatórios apresentados (OTL.txt e Extras.txt localizados no desktop)

 

Caso os relatórios fiquem demasiadamente grandes...

 

*Acesse este link

*Selecione [x]4 jours

*Clique [Enviar arquivo]

*Localize o arquivo OTL.txt no desktop

*Clique [Abrir] > [Créer le lien Cjoint]

*Cole o endereço criado

*Faça o mesmo procedimento para o relatório Extras.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Selecione e copie (Ctrl+c) o código abaixo:

:OTL

IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = http://www.ingush-auto.ru/plugins/system/askdpd9sdc90das90a9/www.bemvindoaoclube.com.br.txt

FF - prefs.js..network.proxy.autoconfig_url: "http://www.ingush-auto.ru/plugins/system/askdpd9sdc90das90a9/www.bemvindoaoclube.com.br.txt"

FF - prefs.js..network.proxy.socks_port: 80

FF - prefs.js..network.proxy.type: 2

 

:Files

C:\Users\Marcell\AppData\Roaming\mozilla\Extensions\IMVUClientXUL@imvu.com

@C:\Windows\SysWow64\drivers:GbpKmAp.lst

 

:Commands

[emptytemp]

[Reboot]

*Execute o OTL

*Clique no espaço abaixo de "Exames Personalizados/Correções" e cole (Ctrl+v) o código

*Clique [Consertar]

*O PC será reiniciado

*Cole o relatório apresentado

Compartilhar este post


Link para o post
Compartilhar em outros sites

ok

 

Segue o resultado abaixo!

 

 

All processes killed

========== OTL ==========

HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!

HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!

Registry value HKEY_USERS\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL deleted successfully.

Prefs.js: "http://www.ingush-auto.ru/plugins/system/askdpd9sdc90das90a9/www.bemvindoaoclube.com.br.txt" removed from network.proxy.autoconfig_url

Prefs.js: 80 removed from network.proxy.socks_port

Prefs.js: 2 removed from network.proxy.type

========== FILES ==========

C:\Users\Marcell\AppData\Roaming\mozilla\Extensions\IMVUClientXUL@imvu.com folder moved successfully.

ADS C:\Windows\SysWow64\drivers:GbpKmAp.lst deleted successfully.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: All Users

 

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

User: Marcell

->Temp folder emptied: 654547414 bytes

->Temporary Internet Files folder emptied: 390010867 bytes

->Java cache emptied: 939270 bytes

->FireFox cache emptied: 93872629 bytes

->Google Chrome cache emptied: 385869466 bytes

->Opera cache emptied: 4717198 bytes

->Flash cache emptied: 33928 bytes

 

User: Public

 

User: Todos os Usuários

 

User: Usuário Padrão

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 73347125 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50521 bytes

RecycleBin emptied: 0 bytes

 

Total Files Cleaned = 1.529,00 mb

 

 

OTL by OldTimer - Version 3.2.23.0 log created on 06102011_132142

 

Files\Folders moved on Reboot...

File\Folder C:\Users\Marcell\AppData\Local\Temp\etilqs_CYixMu5ox4GqrLk3zQyh not found!

C:\Users\Marcell\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

File\Folder C:\Users\Marcell\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YNOIJK1L\ADSAdClient31CA1FTZH9.htm not found!

C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 moved successfully.

C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1 moved successfully.

C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2 moved successfully.

C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3 moved successfully.

C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\data_4 moved successfully.

C:\Users\Marcell\AppData\Local\Google\Chrome\User Data\Default\Cache\index moved successfully.

 

Registry entries deleted on Reboot...

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Execute o OTL e selecione a opção:

[X] Verificar All Users

*Clique [Verificação Rápida] e cole o relatório OTL.txt

 

Informe também se o problema foi resolvido.

Compartilhar este post


Link para o post
Compartilhar em outros sites

OTL logfile created on: 10/06/2011 17:06:06 - Run 2

OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Marcell\Desktop

64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 9.0.8112.16421)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

 

3,75 Gb Total Physical Memory | 2,17 Gb Available Physical Memory | 57,96% Memory free

7,49 Gb Paging File | 5,46 Gb Available in Paging File | 72,87% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 450,18 Gb Total Space | 400,24 Gb Free Space | 88,91% Space Free | Partition Type: NTFS

Drive D: | 15,28 Gb Total Space | 2,20 Gb Free Space | 14,39% Space Free | Partition Type: NTFS

 

Computer Name: MARCELLFILTRAL | User Name: Marcell | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - [2011/06/09 18:40:19 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Marcell\Desktop\OTL.exe

PRC - [2011/06/01 17:03:05 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Users\Marcell\AppData\Local\Google\Update\1.3.21.57\GoogleCrashHandler.exe

PRC - [2011/05/26 11:29:04 | 000,800,768 | ---- | M] (Yuna Software) -- C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe

PRC - [2011/02/04 16:32:02 | 000,092,216 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

PRC - [2010/12/28 09:43:18 | 000,054,664 | ---- | M] ( ) -- C:\PROGRA~2\GbPlugin\GbpSv.exe

PRC - [2010/11/07 06:22:00 | 000,286,720 | ---- | M] (Babylon Ltd.) -- C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe

PRC - [2010/07/02 11:51:16 | 000,027,192 | ---- | M] () -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

PRC - [2010/07/02 11:48:24 | 000,602,680 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe

PRC - [2010/04/20 08:05:24 | 000,027,040 | ---- | M] (Orolix Desenvolvimento de Software LTDA.) -- C:\Program Files (x86)\TIM Communicator\module\devicemon.exe

PRC - [2010/04/09 16:54:38 | 001,441,544 | ---- | M] (Motorola, Inc.) -- C:\Arquivos de Programas\Motorola\Bluetooth\btplayerctrl.exe

PRC - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

 

 

========== Modules (SafeList) ==========

 

MOD - [2011/06/09 18:40:19 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Marcell\Desktop\OTL.exe

MOD - [2010/11/20 08:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll

 

 

========== Win32 Services (SafeList) ==========

 

SRV:64bit: - [2010/11/11 14:36:38 | 000,282,616 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)

SRV:64bit: - [2010/11/11 14:36:38 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)

SRV:64bit: - [2010/10/13 15:01:24 | 001,028,096 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Running] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)

SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)

SRV:64bit: - [2010/06/29 11:52:12 | 004,181,256 | ---- | M] (Motorola, Inc.) [On_Demand | Running] -- C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe -- (Bluetooth Device Manager)

SRV:64bit: - [2010/06/18 16:26:18 | 000,103,992 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe -- (HP Wireless Assistant Service)

SRV:64bit: - [2010/06/17 13:59:38 | 000,202,752 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)

SRV:64bit: - [2010/05/20 13:28:14 | 000,677,128 | ---- | M] (Motorola, Inc.) [Auto | Running] -- C:\Program Files\Motorola\Bluetooth\obexsrv.exe -- (Bluetooth OBEX Service)

SRV:64bit: - [2010/05/20 13:28:12 | 001,096,968 | ---- | M] (Motorola, Inc.) [On_Demand | Running] -- C:\Program Files\Motorola\Bluetooth\audiosrv.exe -- (Bluetooth Media Service)

SRV:64bit: - [2010/04/19 18:55:18 | 000,315,392 | ---- | M] (Realtek Semiconductor Corp.) [Auto | Running] -- C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe -- (RtVOsdService)

SRV:64bit: - [2009/07/13 22:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)

SRV - [2011/02/04 16:32:02 | 000,092,216 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)

SRV - [2010/12/28 09:43:18 | 000,054,664 | ---- | M] ( ) [unknown | Running] -- C:\PROGRA~2\GbPlugin\GbpSv.exe -- (GbpSv)

SRV - [2010/10/13 15:01:23 | 000,647,680 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)

SRV - [2010/07/02 11:51:16 | 000,027,192 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe -- (HPWMISVC)

SRV - [2010/04/20 08:05:24 | 000,027,040 | ---- | M] (Orolix Desenvolvimento de Software LTDA.) [Auto | Running] -- C:\Program Files (x86)\TIM Communicator\module\devicemon.exe -- (OrolixDeviceMonitor)

SRV - [2010/04/03 20:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService)

SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2009/11/17 23:14:26 | 000,098,208 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Arquivos de Programas\Realtek\Audio\HDA\AERTSr64.exe -- (AERTFilters)

SRV - [2009/06/10 18:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - [2011/03/21 13:22:06 | 000,452,200 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)

DRV:64bit: - [2010/11/20 10:34:02 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)

DRV:64bit: - [2010/11/20 10:34:02 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)

DRV:64bit: - [2010/11/20 10:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2010/11/20 08:35:32 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)

DRV:64bit: - [2010/11/20 08:35:20 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)

DRV:64bit: - [2010/11/20 08:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)

DRV:64bit: - [2010/11/20 08:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)

DRV:64bit: - [2010/11/20 06:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)

DRV:64bit: - [2010/10/24 21:25:38 | 000,072,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)

DRV:64bit: - [2010/09/22 23:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)

DRV:64bit: - [2010/06/29 10:12:26 | 003,232,768 | ---- | M] (Motorola, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btmusb.sys -- (BTMUSB)

DRV:64bit: - [2010/06/23 21:37:24 | 000,931,168 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)

DRV:64bit: - [2010/06/17 14:07:42 | 006,403,072 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atipmdag.sys -- (amdkmdag)

DRV:64bit: - [2010/06/17 13:10:34 | 000,188,928 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)

DRV:64bit: - [2010/06/02 09:50:36 | 000,119,680 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ONDAusbvoice.sys -- (ONDAusbvoice)

DRV:64bit: - [2010/06/02 09:50:36 | 000,119,680 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Ondausbser6k.sys -- (ONDAusbser6k)

DRV:64bit: - [2010/06/02 09:50:36 | 000,119,680 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Ondausbnmea.sys -- (ONDAusbnmea)

DRV:64bit: - [2010/06/02 09:50:36 | 000,119,680 | ---- | M] (Onda Communication) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Ondausbmdm6k.sys -- (ONDAusbmdm6k)

DRV:64bit: - [2010/05/27 21:32:56 | 000,320,560 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)

DRV:64bit: - [2010/05/20 12:19:14 | 000,042,496 | ---- | M] (Motorola, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btmaud.sys -- (btmaudio)

DRV:64bit: - [2010/05/07 16:19:58 | 000,245,792 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)

DRV:64bit: - [2010/05/06 10:21:46 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)

DRV:64bit: - [2010/04/09 16:53:04 | 000,052,736 | ---- | M] (Motorola, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btmcom.sys -- (BTMCOM)

DRV:64bit: - [2009/12/22 02:26:36 | 000,038,456 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)

DRV:64bit: - [2009/10/07 23:13:34 | 000,070,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV:64bit: - [2009/10/07 23:13:34 | 000,028,728 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV:64bit: - [2009/08/23 22:55:32 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)

DRV:64bit: - [2009/07/13 22:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/13 22:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/13 22:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/06/19 23:09:57 | 001,394,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)

DRV:64bit: - [2009/06/10 18:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)

DRV:64bit: - [2009/06/10 18:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)

DRV:64bit: - [2009/06/10 18:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)

DRV:64bit: - [2009/06/10 18:01:06 | 001,146,880 | ---- | M] (LSI Corp) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)

DRV:64bit: - [2009/06/10 17:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)

DRV:64bit: - [2009/06/10 17:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)

DRV:64bit: - [2009/06/10 17:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)

DRV:64bit: - [2009/06/10 17:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel®

DRV:64bit: - [2009/06/10 17:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/10 17:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/10 17:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/10 17:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV - [2010/12/28 09:46:30 | 000,046,600 | ---- | M] (GAS Tecnologia) [Kernel | Boot | Stopped] -- C:\Windows\system32\drivers\gbpkm.sys -- (GbpKm)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/3

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=5c9d683e00000000000070f3956f95cd&tlver=1.4.19.19&affID=17159

 

 

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

 

 

IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/3

IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =

IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss&mntrId=5c9d683e00000000000070f3956f95cd&tlver=1.4.19.19&affID=17159

IE - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..network.proxy.autoconfig_url: ""

FF - prefs.js..network.proxy.socks_port: ""

FF - prefs.js..network.proxy.type: ""

FF - prefs.js..browser.startup.homepage: "http://home.sweetim.com"

FF - prefs.js..browser.startup.homepage: "http://home.sweetim.com"

FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "SweetIM Search"

FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""

FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "SweetIM Search"

FF - prefs.js..browser.search.selectedEngine: "SweetIM Search"

FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"

FF - prefs.js..browser.search.defaulturl: ""

 

FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/11 11:24:03 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

 

[2011/06/10 13:21:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcell\AppData\Roaming\mozilla\Extensions

[2011/06/07 16:45:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Marcell\AppData\Roaming\mozilla\Firefox\Profiles\mj5fljyj.default\extensions

[2011/06/07 16:45:53 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Marcell\AppData\Roaming\mozilla\Firefox\Profiles\mj5fljyj.default\extensions\ffxtlbr@babylon.com

[2011/06/06 16:12:46 | 000,003,915 | ---- | M] () -- C:\Users\Marcell\AppData\Roaming\Mozilla\Firefox\Profiles\mj5fljyj.default\searchplugins\SweetIM Search.xml

[2011/06/06 16:13:20 | 000,003,910 | ---- | M] () -- C:\Users\Marcell\AppData\Roaming\Mozilla\Firefox\Profiles\mj5fljyj.default\searchplugins\sweetim.xml

[2011/04/11 11:24:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions

File not found (No name found) --

[2011/03/18 15:04:44 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll

[2011/06/07 16:45:55 | 000,002,423 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml

[2010/01/01 05:00:00 | 000,001,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\buscape.xml

[2010/01/01 05:00:00 | 000,001,212 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\mercadolivre.xml

[2010/01/01 05:00:00 | 000,001,168 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-br.xml

[2010/01/01 05:00:00 | 000,000,952 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-br.xml

 

O1 HOSTS File: ([2011/06/08 13:47:35 | 000,000,822 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)

O2 - BHO: (CescrtHlpr Object) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\bh\BabylonToolbar.dll (Babylon BHO)

O2 - BHO: (GbIehObj Class) - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)

O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarTlbr.dll (Babylon Ltd.)

O3 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.

O4:64bit: - HKLM..\Run: [bTMTrayAgent] C:\Program Files\Motorola\Bluetooth\btmshell.dll (Motorola, Inc.)

O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()

O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)

O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)

O4 - HKLM..\Run: [babylonToolbar] C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe (Babylon Ltd.)

O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Company)

O4 - HKLM..\Run: [PlusService] C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe (Yuna Software)

O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

O4 - HKU\S-1-5-19..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-20..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)

O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] File not found

O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] File not found

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O9:64bit: - Extra Button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Arquivos de Programas\Motorola\Bluetooth\btmiesend.htm ()

O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Arquivos de Programas\Motorola\Bluetooth\btmiesend.htm ()

O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL (Microsoft Corporation)

O9 - Extra Button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Arquivos de Programas\Motorola\Bluetooth\btmiesend.htm ()

O9 - Extra 'Tools' menuitem : @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Arquivos de Programas\Motorola\Bluetooth\btmiesend.htm ()

O13 - gopher Prefix: missing

O13 - gopher Prefix: missing

O15 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\..Trusted Domains: bancobrasil.com.br ([www] * in Trusted sites)

O15 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\..Trusted Domains: bancobrasil.com.br ([www14] * in Trusted sites)

O15 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\..Trusted Domains: bancobrasil.com.br ([www2] * in Trusted sites)

O15 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000\..Trusted Domains: bb.com.br ([www] * in Trusted sites)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)

O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)

O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found

O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20 - HKU\S-1-5-21-781092494-2567528247-3288085175-1000 Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\ GbPluginBb: DllName - C:\Program Files (x86)\GbPlugin\gbieh.dll - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

O28 - HKLM ShellExecuteHooks: {E37CB5F0-51F5-4395-A808-5FA49E399F83} - C:\Program Files (x86)\GbPlugin\gbieh.dll (Banco do Brasil)

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

 

[2011/06/10 13:21:42 | 000,000,000 | ---D | C] -- C:\_OTL

[2011/06/10 09:38:19 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\SPReview

[2011/06/10 09:35:32 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\EventProviders

[2011/06/10 09:28:02 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{6D9189B2-7BEE-43FB-BB53-2E424AC51AEC}

[2011/06/09 18:40:04 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\Marcell\Desktop\OTL.exe

[2011/06/09 10:16:27 | 000,116,224 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\SysNative\fms.dll

[2011/06/09 10:15:33 | 000,093,696 | ---- | C] (Windows ® Codename Longhorn DDK provider) -- C:\Windows\SysWow64\fms.dll

[2011/06/09 09:17:56 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{9D6C38CA-B371-41D4-AC68-24204A51B610}

[2011/06/08 13:51:26 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Roaming\Malwarebytes

[2011/06/08 13:51:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2011/06/08 13:51:16 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys

[2011/06/08 13:51:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2011/06/08 13:51:14 | 000,024,664 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2011/06/08 13:51:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2011/06/08 13:49:21 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Marcell\Desktop\mbam-setup.exe

[2011/06/08 09:04:06 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{ECF699C0-B91E-4823-8AD1-416830B6FB50}

[2011/06/08 09:00:20 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{01662E6D-9673-4CE2-90AB-198948322F92}

[2011/06/07 16:45:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BabylonToolbar

[2011/06/07 16:45:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yuna Software

[2011/06/07 15:39:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Messenger Plus!

[2011/06/07 09:19:45 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{8AC61E6C-1022-4AB8-B104-B5A619779983}

[2011/06/06 17:49:45 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{BF46F78E-48BC-4937-B2B4-6A1AA1259C00}

[2011/06/06 08:56:41 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{87F88A3D-AF8F-4944-B26C-E09B0CE8777B}

[2011/06/04 09:37:12 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{A8233B1A-EB34-44A2-AE78-FA7552E528D7}

[2011/06/03 08:51:07 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{821197FF-D027-4908-80DD-B7352022F1C1}

[2011/06/02 08:48:17 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{A6825642-556A-449C-AD53-2D1539D7A0AC}

[2011/06/01 08:42:12 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{BAC179FB-DB08-4DFD-BE4F-77E47886DC64}

[2011/05/31 08:39:47 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{7A2113CD-039A-4CD8-A661-FD6E7047AC80}

[2011/05/30 09:07:57 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{5105E6AD-AFBE-4B1C-A21E-4F7E1B4DC4F1}

[2011/05/28 09:28:57 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{E15C69A9-DA2E-4859-AD1B-0CB936AB7667}

[2011/05/27 09:16:18 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{0137596F-0669-484C-ACD8-D777A260EF69}

[2011/05/26 09:21:45 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{D628ACC1-C235-4784-AA3E-3C724F5EF401}

[2011/05/25 07:25:11 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{48FDB9EE-26A9-4D76-82D4-744D0ACE3AFE}

[2011/05/24 12:05:08 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{446CFBBC-7E49-450B-B757-28279C700CB7}

[2011/05/24 00:04:42 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{CE4D8F1E-31ED-48FA-A2F5-CBEAE1D34AE3}

[2011/05/23 08:49:19 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{53FDD64E-B1C1-4917-89AA-A04E1E376056}

[2011/05/21 09:37:52 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{7383BE2C-881A-462B-90D5-191DBB9495E1}

[2011/05/20 12:47:04 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{6181CA46-6565-4380-A2F7-85541194901B}

[2011/05/19 09:10:20 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{61125F6F-BD56-4F28-A8B8-81D2A71671F5}

[2011/05/18 11:53:39 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{A5635878-CE8A-4DF4-A9FD-431B42CBF4C6}

[2011/05/17 09:31:53 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{818EE876-5B66-4447-B24D-35CD6606C6D5}

[2011/05/16 08:33:46 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{A5154F08-CCA0-471D-8ECC-5E7EA6EA791B}

[2011/05/14 10:04:07 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{1D0E00A2-C9D8-44A2-8D4A-67533CF2DAA5}

[2011/05/13 08:48:12 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{B0ECD828-3D1C-4999-8A2B-BDFA0BE93864}

[2011/05/12 08:57:32 | 000,000,000 | ---D | C] -- C:\Users\Marcell\AppData\Local\{65C8F994-AAAD-4652-B550-CB9525728590}

[2 C:\Users\Marcell\*.tmp files -> C:\Users\Marcell\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2011/06/10 17:08:00 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-781092494-2567528247-3288085175-1000UA.job

[2011/06/10 17:08:00 | 000,001,034 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-781092494-2567528247-3288085175-1000Core.job

[2011/06/10 16:53:24 | 001,585,302 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2011/06/10 16:53:24 | 000,688,306 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat

[2011/06/10 16:53:24 | 000,638,522 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2011/06/10 16:53:24 | 000,140,072 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat

[2011/06/10 16:53:24 | 000,116,316 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2011/06/10 16:52:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2011/06/10 16:52:08 | 000,001,070 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[2011/06/10 13:38:15 | 000,022,896 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2011/06/10 13:38:15 | 000,022,896 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2011/06/10 13:30:45 | 000,001,066 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

[2011/06/10 13:29:37 | 3015,888,896 | -HS- | M] () -- C:\hiberfil.sys

[2011/06/10 13:04:56 | 000,354,320 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

[2011/06/09 18:40:19 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Marcell\Desktop\OTL.exe

[2011/06/08 14:11:41 | 000,002,369 | ---- | M] () -- C:\Users\Marcell\Desktop\Google Chrome.lnk

[2011/06/08 13:51:18 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/06/08 13:49:57 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Marcell\Desktop\mbam-setup.exe

[2011/06/07 16:46:31 | 000,001,251 | ---- | M] () -- C:\Users\Marcell\Desktop\Plus World.lnk

[2011/06/06 21:55:10 | 000,167,812 | ---- | M] () -- C:\Users\Marcell\Desktop\pag itau.png

[2011/05/16 09:26:11 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForMarcell.job

[2 C:\Users\Marcell\*.tmp files -> C:\Users\Marcell\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2011/06/09 10:19:07 | 000,095,744 | ---- | C] () -- C:\Windows\SysNative\RDVGHelper.exe

[2011/06/09 10:18:34 | 000,347,904 | ---- | C] () -- C:\Windows\SysNative\systemsf.ebd

[2011/06/09 10:14:39 | 000,010,429 | ---- | C] () -- C:\Windows\SysNative\ScavengeSpace.xml

[2011/06/09 10:14:08 | 000,105,559 | ---- | C] () -- C:\Windows\SysWow64\RacRules.xml

[2011/06/09 10:14:08 | 000,105,559 | ---- | C] () -- C:\Windows\SysNative\RacRules.xml

[2011/06/09 10:13:18 | 000,001,041 | ---- | C] () -- C:\Windows\SysWow64\tcpbidi.xml

[2011/06/09 10:13:17 | 000,146,389 | ---- | C] () -- C:\Windows\SysWow64\printmanagement.msc

[2011/06/08 13:51:18 | 000,001,009 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk

[2011/06/07 16:46:31 | 000,001,251 | ---- | C] () -- C:\Users\Marcell\Desktop\Plus World.lnk

[2011/06/06 21:55:10 | 000,167,812 | ---- | C] () -- C:\Users\Marcell\Desktop\pag itau.png

[2011/06/06 17:48:16 | 000,002,486 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk

[2011/04/18 11:53:25 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\MSJCE.dll

[2011/03/05 10:02:26 | 000,001,854 | ---- | C] () -- C:\Users\Marcell\AppData\Roaming\GhostObjGAFix.xml

[2011/01/04 12:52:27 | 001,599,340 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2010/10/13 15:03:06 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin

[2010/10/13 15:01:04 | 000,014,051 | ---- | C] () -- C:\Windows\SysWow64\RaCoInst.dat

[2010/10/13 14:56:22 | 000,001,105 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

[2010/10/13 14:56:08 | 000,000,268 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog2.ini

[2010/10/13 14:56:08 | 000,000,209 | ---- | C] () -- C:\Windows\SysWow64\RStoneLog.ini

[2010/08/30 19:46:56 | 000,000,197 | ---- | C] () -- C:\Windows\SysWow64\HPWA.ini

[2010/02/09 18:58:12 | 000,012,800 | ---- | C] () -- C:\Windows\LPRES.DLL

[2009/07/14 02:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat

[2009/07/13 23:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT

[2009/07/13 23:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat

[2009/07/13 21:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin

[2009/07/13 20:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll

[2009/07/13 18:59:36 | 001,498,564 | ---- | C] () -- C:\Windows\SysWow64\igkrng400.bin

[2009/07/13 18:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll

[2009/06/10 18:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

 

========== LOP Check ==========

 

[2011/01/03 12:09:28 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\Opera

[2011/01/19 12:08:50 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\PhotoScape

[2011/01/03 22:11:15 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\PlayFirst

[2011/01/22 09:37:00 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\Vivox

[2010/12/24 19:01:08 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\WildTangent

[2010/12/30 16:49:54 | 000,000,000 | ---D | M] -- C:\Users\Marcell\AppData\Roaming\Windows Live Writer

[2011/03/19 09:28:20 | 000,032,534 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

 

========== Purity Check ==========

 

 

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 204 bytes -> C:\Windows\SysWow64\drivers:GbpKmAp.lst

 

< End of report >

Compartilhar este post


Link para o post
Compartilhar em outros sites

OK...log limpo.

 

 

1.

*No Internet Explorer, clique em [Ferramentas] > [Opções da Internet]

*Na aba "Conexões", clique [Configurações da Lan]

*Desmarque as opções "Servidor Proxy" e "Usar script de configuração automática".

*Clique [OK]

 

2.

*No Firefox, clique [Ferramentas] > [Opções]

*Na aba "Avançado" clique [Rede] > [Configurar Conexão]

*Selecione "Sem proxy" e clique [OK]

 

3.

*Execute o OTL e clique [Limpeza] > [OK]

*O PC será reiniciado

 

 

Um abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.