EDSSX 0 Denunciar post Postado Outubro 29, 2011 Boa noite ! Meu(inha_) windows seven/internet trava direto . Segue os logs : DDS (Ver_10-12-12.02) - NTFSx86 Run by Edson Luis at 22:44:09,94 on 28/10/2011 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.1.0 Microsoft Windows 7 Enterprise 6.1.7601.1.1252.55.1033.18.512.46 [GMT -2:00] ============== Running Processes =============== D:\Windows\system32\wininit.exe D:\Windows\system32\lsm.exe D:\Windows\system32\svchost.exe -k DcomLaunch D:\Windows\system32\svchost.exe -k RPCSS D:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted D:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted D:\Windows\system32\svchost.exe -k netsvcs D:\Windows\system32\svchost.exe -k LocalService D:\Windows\system32\svchost.exe -k NetworkService D:\Windows\System32\spoolsv.exe D:\Windows\system32\svchost.exe -k LocalServiceNoNetwork D:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe D:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation D:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe D:\Windows\system32\taskhost.exe D:\Windows\system32\Dwm.exe D:\Windows\Explorer.EXE D:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe D:\Windows\system32\SearchIndexer.exe D:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted D:\Program Files\Windows Media Player\wmpnetwk.exe D:\Windows\System32\svchost.exe -k LocalServicePeerNet D:\Program Files\Mozilla Firefox\firefox.exe D:\Program Files\Mozilla Firefox\plugin-container.exe D:\Windows\system32\svchost.exe -k bthsvcs D:\Windows\System32\svchost.exe -k secsvcs D:\Program Files\Windows Live\Messenger\msnmsgr.exe D:\Program Files\Windows Live\Contacts\wlcomm.exe D:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe D:\Users\Edson Luis\Downloads\HijackThis.exe D:\Windows\system32\wbem\wmiprvse.exe D:\Users\Edson Luis\Downloads\dds.scr D:\Windows\system32\conhost.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com.br/ uURLSearchHooks: H - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll uRun: [msnmsgr] "d:\program files\windows live\messenger\msnmsgr.exe" /background mRun: [PSUNMain] "d:\program files\panda security\panda cloud antivirus\PSUNMain.exe" /Traybar mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) Trusted Zone: microsoft.com\update Trusted Zone: microsoft.com\windowsupdate DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Notify: AtiExtEvent - Ati2evxx.dll ================= FIREFOX =================== FF - ProfilePath - d:\users\edsonl~1\appdata\roaming\mozilla\firefox\profiles\rkmrrjvd.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br/ FF - prefs.js: network.proxy.type - 0 FF - plugin: d:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: d:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: d:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll FF - plugin: d:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: d:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: d:\users\edson luis\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll ============= SERVICES / DRIVERS =============== R0 360HookOem;360HookOem;d:\windows\system32\drivers\360HookOem.sys [2011-5-20 54912] R0 Lbd;Lbd;d:\windows\system32\drivers\Lbd.sys [2011-5-2 64512] R1 PSINKNC;PSINKNC;d:\windows\system32\drivers\PSINKNC.sys [2011-4-28 126024] R2 PSINAflt;PSINAflt;d:\windows\system32\drivers\PSINAflt.sys [2011-7-5 143624] R2 PSINFile;PSINFile;d:\windows\system32\drivers\PSINFile.sys [2011-4-28 99400] R2 PSINProc;PSINProc;d:\windows\system32\drivers\PSINProc.sys [2011-4-28 111176] R2 PSINProt;PSINProt;d:\windows\system32\drivers\PSINProt.sys [2011-4-28 112712] R3 3xHybrid;SAA713x TV Card Service;d:\windows\system32\drivers\3xHybrid.sys [2010-12-1 1141888] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;d:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;d:\windows\system32\drivers\rdpvideominiport.sys [2011-2-23 15872] S3 TsUsbFlt;TsUsbFlt;d:\windows\system32\drivers\TsUsbFlt.sys [2011-2-23 52224] =============== Created Last 30 ================ 2011-10-28 22:14:41 -------- d-----w- d:\users\edsonl~1\appdata\local\{F5CA0041-19BB-4CF0-9C1B-9A3FAC4F91A7} 2011-10-28 22:14:23 -------- d-----w- d:\users\edsonl~1\appdata\local\{F1B1BB94-FA78-455B-AA62-9C14DFC74C43} 2011-10-28 11:46:54 56200 ----a-w- d:\progra~2\microsoft\windows defender\definition updates\{3c0a7c77-a526-4e37-8e75-8aca27cfa505}\offreg.dll 2011-10-28 11:46:47 6668624 ----a-w- d:\progra~2\microsoft\windows defender\definition updates\{3c0a7c77-a526-4e37-8e75-8aca27cfa505}\mpengine.dll 2011-10-28 00:06:34 -------- d-----w- d:\users\edsonl~1\appdata\local\{804F9B0C-63BA-40C0-AE40-3F5E34901489} 2011-10-28 00:05:59 -------- d-----w- d:\users\edsonl~1\appdata\local\{8AB827E8-8614-4D7D-986C-59882734D711} 2011-10-27 12:04:29 -------- d-----w- d:\users\edsonl~1\appdata\local\{2897F100-EEF2-40BB-8AC8-3B364992C246} 2011-10-27 12:03:21 -------- d-----w- d:\users\edsonl~1\appdata\local\{6A09D7BE-AA8A-45FD-9063-AE3D50797426} 2011-10-26 23:37:03 -------- d-----w- d:\users\edsonl~1\appdata\local\{3C345069-D292-4C39-B02F-91966A7C589C} 2011-10-26 23:36:36 -------- d-----w- d:\users\edsonl~1\appdata\local\{F9DC1EAC-7DC5-45FD-88EC-E4B10E8AACD3} 2011-10-26 11:01:16 -------- d-----w- d:\users\edsonl~1\appdata\local\{30D9592C-60D6-4751-A991-C81E49DAF858} 2011-10-26 10:59:05 -------- d-----w- d:\users\edsonl~1\appdata\local\{6F929658-B494-42DF-A189-A982A78B3198} 2011-10-25 22:54:15 -------- d-----w- d:\users\edsonl~1\appdata\local\{731E5C86-34DF-42E9-878B-54B249DDC52E} 2011-10-25 22:53:15 -------- d-----w- d:\users\edsonl~1\appdata\local\{F90FB180-C3C0-4D68-B322-F193D3D2DEA2} 2011-10-24 14:13:58 -------- d-----w- d:\users\edsonl~1\appdata\local\{FD937E75-154A-498B-8953-9FD3641E7F7E} 2011-10-24 14:13:18 -------- d-----w- d:\users\edsonl~1\appdata\local\{A8B1B3EC-BCD3-4881-97D2-0E3D5BAD8E81} 2011-10-24 04:05:25 -------- d-----w- d:\users\edsonl~1\appdata\roaming\Panda Security 2011-10-24 04:02:20 -------- d-----w- d:\progra~2\Panda Security 2011-10-24 04:02:18 -------- d-----w- d:\program files\Panda Security 2011-10-24 02:11:25 -------- d-----w- d:\users\edsonl~1\appdata\local\{94E7AF12-9496-4E95-A0FF-359C9CB08D43} 2011-10-24 02:10:54 -------- d-----w- d:\users\edsonl~1\appdata\local\{2DBD8B1F-EC96-402E-9E8E-EEF5D6AB9E67} 2011-10-23 23:54:04 146304 ----a-r- d:\windows\system32\drivers\360FileOem.sys 2011-10-23 14:08:37 -------- d-----w- d:\users\edsonl~1\appdata\local\{6BE5402E-8376-4E8C-974E-CFFA2F8EFFD7} 2011-10-23 14:08:09 -------- d-----w- d:\users\edsonl~1\appdata\local\{5A9890AC-ED80-49BE-A36D-4FD66C7ECD6C} 2011-10-22 13:12:55 -------- d-----w- d:\users\edsonl~1\appdata\local\{68672461-63C4-4B68-820F-4D5F332931A9} 2011-10-22 13:12:31 -------- d-----w- d:\users\edsonl~1\appdata\local\{6B811924-C5B8-4785-BD3D-DC993293FD3E} 2011-10-22 01:11:12 -------- d-----w- d:\users\edsonl~1\appdata\local\{A946BD12-4639-4063-8698-048B90A106A9} 2011-10-22 01:10:44 -------- d-----w- d:\users\edsonl~1\appdata\local\{D60AC9EA-BAC4-41B5-9A75-7A04E4BCFBD9} 2011-10-21 13:09:10 -------- d-----w- d:\users\edsonl~1\appdata\local\{CFA3B34F-E4B8-4FAC-8288-F0E8717191C5} 2011-10-21 13:08:47 -------- d-----w- d:\users\edsonl~1\appdata\local\{DEE4E607-CBF1-442F-B5B4-7270479D83C9} 2011-10-21 00:49:34 -------- d-----w- d:\users\edsonl~1\appdata\local\{394B074B-96C3-49D9-BA82-E97AE98B16B1} 2011-10-21 00:49:08 -------- d-----w- d:\users\edsonl~1\appdata\local\{98CFE000-1960-4346-9AA1-F2E22C5F1D8D} 2011-10-20 12:31:54 -------- d-----w- d:\users\edsonl~1\appdata\local\{F30C3598-320E-4DFA-9E19-B3599D246826} 2011-10-20 12:31:28 -------- d-----w- d:\users\edsonl~1\appdata\local\{70259D2B-02BE-49EC-AEA8-046C3D22B84C} 2011-10-19 15:46:27 -------- d-----w- d:\users\edsonl~1\appdata\local\{40743B41-1D16-4D1E-84BB-3DD700B3CD64} 2011-10-19 15:46:02 -------- d-----w- d:\users\edsonl~1\appdata\local\{9F3D0450-B7B9-4557-905E-9B66DF3521F7} 2011-10-19 03:45:02 -------- d-----w- d:\users\edsonl~1\appdata\local\{311F897F-3301-4796-B3D2-9F554B446242} 2011-10-18 15:44:18 -------- d-----w- d:\users\edsonl~1\appdata\local\{D3B35C9A-7549-4DDD-8E81-7F221C54C94D} 2011-10-18 15:43:54 -------- d-----w- d:\users\edsonl~1\appdata\local\{69BB7DD0-2F9E-49DD-9A69-8DF97FA050EC} 2011-10-18 03:43:11 -------- d-----w- d:\users\edsonl~1\appdata\local\{F9FD70AB-39CB-44E8-9DA8-EE9482A77DEC} 2011-10-18 03:42:47 -------- d-----w- d:\users\edsonl~1\appdata\local\{E1A88D20-AFEF-4046-9BA2-B432B30CCA62} 2011-10-17 15:41:54 -------- d-----w- d:\users\edsonl~1\appdata\local\{ADAA700B-2E9D-496A-A7C0-BFBABF891AE2} 2011-10-17 15:40:59 -------- d-----w- d:\users\edsonl~1\appdata\local\{47FD2D64-571D-4C0A-80B7-371F78F454AA} 2011-10-16 13:39:24 -------- d-----w- d:\users\edsonl~1\appdata\local\{BF678830-537E-4E68-BB60-B337E9C801B2} 2011-10-16 13:38:58 -------- d-----w- d:\users\edsonl~1\appdata\local\{D5D71DEB-6580-40AB-991B-D8015FCABC42} 2011-10-15 13:35:31 -------- d-----w- d:\users\edsonl~1\appdata\local\{860999FE-B81E-465C-893A-2CE007B1F67E} 2011-10-15 13:35:05 -------- d-----w- d:\users\edsonl~1\appdata\local\{BBFFAC72-F6D9-4CC4-AB2A-F0C7D62247E0} 2011-10-14 12:57:32 -------- d-----w- d:\users\edsonl~1\appdata\local\{E265032E-566C-45F3-B095-D4A59C85DDAF} 2011-10-14 12:56:32 -------- d-----w- d:\users\edsonl~1\appdata\local\{A6884348-61F9-40D7-864D-104D971DFDAA} 2011-10-14 00:54:50 -------- d-----w- d:\users\edsonl~1\appdata\local\{50931753-39CE-43D1-BE6E-F9EF1D3B96B6} 2011-10-13 12:54:04 -------- d-----w- d:\users\edsonl~1\appdata\local\{6DFA14B2-8D20-47CC-87AB-421CD33A7F07} 2011-10-13 12:53:37 -------- d-----w- d:\users\edsonl~1\appdata\local\{BE83BEFA-0B95-4329-AFB3-0247367C4D94} 2011-10-12 15:39:29 75776 ----a-w- d:\windows\system32\psisrndr.ax 2011-10-12 15:39:29 465408 ----a-w- d:\windows\system32\psisdecd.dll 2011-10-12 15:39:23 571904 ----a-w- d:\windows\system32\oleaut32.dll 2011-10-12 15:39:23 233472 ----a-w- d:\windows\system32\oleacc.dll 2011-10-12 15:38:47 2334720 ----a-w- d:\windows\system32\win32k.sys 2011-10-12 15:29:19 -------- d-----w- d:\users\edsonl~1\appdata\local\{BE831935-317D-45C8-8EAC-08B207155D5B} 2011-10-12 15:28:51 -------- d-----w- d:\users\edsonl~1\appdata\local\{B0FDC36E-F7EB-4BE6-AFA2-723B188B5D36} 2011-10-12 01:13:57 -------- d-----w- d:\users\edsonl~1\appdata\local\{9EA7C40A-8240-4E7B-AAFE-6C3C49E686A8} 2011-10-12 01:13:31 -------- d-----w- d:\users\edsonl~1\appdata\local\{FB6B7553-6DB4-4A7B-A00F-63A9EB3C1068} 2011-10-11 13:12:57 -------- d-----w- d:\users\edsonl~1\appdata\local\{7D78B131-F46E-4A6B-9142-571973811D99} 2011-10-11 13:12:32 -------- d-----w- d:\users\edsonl~1\appdata\local\{5B5D0F83-9E12-448A-B1C6-E5E3314B5F76} 2011-10-11 01:11:51 -------- d-----w- d:\users\edsonl~1\appdata\local\{4D0A47D1-65A1-468F-BF1C-CD5E2EC60D4F} 2011-10-11 01:11:24 -------- d-----w- d:\users\edsonl~1\appdata\local\{9120CE02-9AD4-461C-BCFE-A35E58C04467} 2011-10-10 13:09:15 -------- d-----w- d:\users\edsonl~1\appdata\local\{FA8413C2-F0F3-4A7C-9432-F8B97BC810AE} 2011-10-10 13:08:53 -------- d-----w- d:\users\edsonl~1\appdata\local\{A2315DA4-3BED-4F5C-B308-5C2EC29CC12D} 2011-10-10 01:06:40 -------- d-----w- d:\users\edsonl~1\appdata\local\{35D15065-53D5-4DAA-92B8-D375028F21A1} 2011-10-09 13:04:27 -------- d-----w- d:\users\edsonl~1\appdata\local\{AFA1F5E6-82A8-421B-969B-74DD549BE0EA} 2011-10-09 13:04:07 -------- d-----w- d:\users\edsonl~1\appdata\local\{397CFE00-E8B7-4115-8C58-73E72ADAA8D6} 2011-10-09 00:59:50 -------- d-----w- d:\users\edsonl~1\appdata\local\{AC578EBB-C767-49AA-8F57-B3D648076C06} 2011-10-08 12:59:03 -------- d-----w- d:\users\edsonl~1\appdata\local\{A2438236-50E0-47CE-A75E-73CCC4B8AC65} 2011-10-08 12:58:39 -------- d-----w- d:\users\edsonl~1\appdata\local\{98B4DF75-A736-46C2-BFB5-B695510575B8} 2011-10-08 00:57:46 -------- d-----w- d:\users\edsonl~1\appdata\local\{82994D54-19B7-46D5-BB0B-DAF9F9DAC6F6} 2011-10-08 00:57:10 -------- d-----w- d:\users\edsonl~1\appdata\local\{8F3B1B4E-168D-474B-9420-D595E3B391D9} 2011-10-07 11:05:13 -------- d-----w- d:\users\edsonl~1\appdata\local\{8C0EF2B1-EF42-485C-9AD2-9FC5C0E5ED23} 2011-10-07 11:04:37 -------- d-----w- d:\users\edsonl~1\appdata\local\{4ED9962A-99F4-41FD-BB9F-79F95EA136A2} 2011-10-06 12:10:45 -------- d-----w- d:\users\edsonl~1\appdata\local\{922447ED-7CD0-4B96-A21B-43372250A33A} 2011-10-06 12:10:19 -------- d-----w- d:\users\edsonl~1\appdata\local\{212A6573-A588-4342-8724-EC09E38BC017} 2011-10-06 00:09:47 -------- d-----w- d:\users\edsonl~1\appdata\local\{8E188336-09EC-45AB-BEC3-5784E5265D9E} 2011-10-06 00:09:31 -------- d-----w- d:\users\edsonl~1\appdata\local\{318A6C59-0CC8-4EE1-B3AC-E5BEFC274983} 2011-10-05 10:46:37 -------- d-----w- d:\users\edsonl~1\appdata\local\{147D0C31-DD99-42FC-8BDE-AE5ACBDDC90F} 2011-10-05 10:46:25 -------- d-----w- d:\users\edsonl~1\appdata\local\{6A3F5722-40BC-4588-999A-E6D6FD50378B} 2011-10-04 15:10:08 -------- d-----w- d:\users\edsonl~1\appdata\roaming\f-secure 2011-10-04 15:06:31 -------- d-----w- d:\progra~2\F-Secure 2011-10-04 12:11:59 -------- d-----w- d:\users\edsonl~1\appdata\local\{9018A5B5-170B-4C91-97EC-DDE9DCA984BA} 2011-10-04 12:11:35 -------- d-----w- d:\users\edsonl~1\appdata\local\{D5BC8227-22B9-4CA3-BEAD-F5F6A97560C4} 2011-10-04 00:08:40 -------- d-----w- d:\users\edsonl~1\appdata\local\{3D959386-4002-413F-A928-50862850687A} 2011-10-04 00:07:53 -------- d-----w- d:\users\edsonl~1\appdata\local\{E9ADEAA9-51CD-4A0D-8001-A7B182FF10D4} 2011-10-03 12:05:57 -------- d-----w- d:\users\edsonl~1\appdata\local\{EE3F9ACC-56E0-4C5E-B915-A69FA08D9A74} 2011-10-03 12:05:27 -------- d-----w- d:\users\edsonl~1\appdata\local\{6919E495-82F8-448A-9971-DF7093CFD90E} 2011-10-03 00:04:43 -------- d-----w- d:\users\edsonl~1\appdata\local\{72AED5B1-91BA-49D9-B8BE-76B5C0AF88E1} 2011-10-03 00:04:18 -------- d-----w- d:\users\edsonl~1\appdata\local\{9AA394FC-8171-4508-9B55-003AD7AABCB2} 2011-10-02 21:46:37 -------- d-----w- d:\program files\CCleaner 2011-10-02 20:41:40 22216 ----a-w- d:\windows\system32\drivers\mbam.sys 2011-10-02 12:03:44 -------- d-----w- d:\users\edsonl~1\appdata\local\{9D960EAA-8D03-48FA-A035-AA11E5803679} 2011-10-02 12:03:19 -------- d-----w- d:\users\edsonl~1\appdata\local\{DCE54AD9-0586-4647-84F5-91BFD13ED159} 2011-10-02 00:02:32 -------- d-----w- d:\users\edsonl~1\appdata\local\{F754140D-31CC-4E91-AFAD-37FFDE3F8A7F} 2011-10-02 00:02:05 -------- d-----w- d:\users\edsonl~1\appdata\local\{59FDF809-06F0-4EA2-99EE-A306A92EE7A4} 2011-10-01 11:59:23 -------- d-----w- d:\users\edsonl~1\appdata\local\{36FB494B-CD40-4CBE-A098-9A694BD7B2C7} 2011-10-01 11:58:41 -------- d-----w- d:\users\edsonl~1\appdata\local\{58155D43-6DED-45C6-8882-AD6FF2253718} 2011-09-30 23:57:33 -------- d-----w- d:\users\edsonl~1\appdata\local\{61A52F0F-702A-4925-A357-903C7214C1A3} 2011-09-30 11:56:29 -------- d-----w- d:\users\edsonl~1\appdata\local\{23586458-6305-4332-83DC-5DD4C55D8161} 2011-09-30 11:56:04 -------- d-----w- d:\users\edsonl~1\appdata\local\{C51A796B-9998-4D05-858E-69DE124B1C43} 2011-09-29 18:30:19 -------- d-----w- d:\users\edsonl~1\appdata\local\{A509E3CB-3A9B-40FA-8ACF-0ADFF4E661A1} 2011-09-29 18:29:52 -------- d-----w- d:\users\edsonl~1\appdata\local\{9146581C-CA4D-4E39-AFD4-AD82F8CC785C} ==================== Find3M ==================== 2011-10-27 17:10:37 1228 ----a-w- D:\FixitRegBackup.reg 2011-10-04 19:00:56 414368 ----a-w- d:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-03 04:50:34 544656 ----a-w- d:\windows\system32\deployJava1.dll 2011-09-01 02:35:59 1798144 ----a-w- d:\windows\system32\jscript9.dll 2011-09-01 02:28:15 1126912 ----a-w- d:\windows\system32\wininet.dll 2011-09-01 02:22:54 2382848 ----a-w- d:\windows\system32\mshtml.tlb ============= FINISH: 22:50:32,83 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-12-12.02) Microsoft Windows 7 Enterprise Boot Device: \Device\HarddiskVolume1 Install Date: 29/01/2011 22:13:48 System Uptime: 28/10/2011 20:09:43 (2 hours ago) Motherboard: ECS | | M825G Processor: AMD Sempron 2400+ | Socket-A | 1666/166mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 17 GiB total, 10,464 GiB free. D: is FIXED (NTFS) - 59 GiB total, 20,338 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsldebc8b84 Device ID: ROOT\LEGACY_MPKSLDEBC8B84\0000 Manufacturer: Name: MpKsldebc8b84 PNP Device ID: ROOT\LEGACY_MPKSLDEBC8B84\0000 Service: MpKsldebc8b84 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsla83e3892 Device ID: ROOT\LEGACY_MPKSLA83E3892\0000 Manufacturer: Name: MpKsla83e3892 PNP Device ID: ROOT\LEGACY_MPKSLA83E3892\0000 Service: MpKsla83e3892 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsla8ded396 Device ID: ROOT\LEGACY_MPKSLA8DED396\0000 Manufacturer: Name: MpKsla8ded396 PNP Device ID: ROOT\LEGACY_MPKSLA8DED396\0000 Service: MpKsla8ded396 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl18306c09 Device ID: ROOT\LEGACY_MPKSL18306C09\0000 Manufacturer: Name: MpKsl18306c09 PNP Device ID: ROOT\LEGACY_MPKSL18306C09\0000 Service: MpKsl18306c09 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsle5123dc0 Device ID: ROOT\LEGACY_MPKSLE5123DC0\0000 Manufacturer: Name: MpKsle5123dc0 PNP Device ID: ROOT\LEGACY_MPKSLE5123DC0\0000 Service: MpKsle5123dc0 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKslaa9488f7 Device ID: ROOT\LEGACY_MPKSLAA9488F7\0000 Manufacturer: Name: MpKslaa9488f7 PNP Device ID: ROOT\LEGACY_MPKSLAA9488F7\0000 Service: MpKslaa9488f7 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKslee3c0906 Device ID: ROOT\LEGACY_MPKSLEE3C0906\0000 Manufacturer: Name: MpKslee3c0906 PNP Device ID: ROOT\LEGACY_MPKSLEE3C0906\0000 Service: MpKslee3c0906 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl7867e008 Device ID: ROOT\LEGACY_MPKSL7867E008\0000 Manufacturer: Name: MpKsl7867e008 PNP Device ID: ROOT\LEGACY_MPKSL7867E008\0000 Service: MpKsl7867e008 Class GUID: Description: PCI Simple Communications Controller Device ID: PCI\VEN_1106&DEV_3068&SUBSYS_4C211543&REV_80\3&18D45AA6&0&8E Manufacturer: Name: PCI Simple Communications Controller PNP Device ID: PCI\VEN_1106&DEV_3068&SUBSYS_4C211543&REV_80\3&18D45AA6&0&8E Service: Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKslee872fe2 Device ID: ROOT\LEGACY_MPKSLEE872FE2\0000 Manufacturer: Name: MpKslee872fe2 PNP Device ID: ROOT\LEGACY_MPKSLEE872FE2\0000 Service: MpKslee872fe2 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKslb2280dc1 Device ID: ROOT\LEGACY_MPKSLB2280DC1\0000 Manufacturer: Name: MpKslb2280dc1 PNP Device ID: ROOT\LEGACY_MPKSLB2280DC1\0000 Service: MpKslb2280dc1 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl790fefb3 Device ID: ROOT\LEGACY_MPKSL790FEFB3\0000 Manufacturer: Name: MpKsl790fefb3 PNP Device ID: ROOT\LEGACY_MPKSL790FEFB3\0000 Service: MpKsl790fefb3 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKslb6d617b1 Device ID: ROOT\LEGACY_MPKSLB6D617B1\0000 Manufacturer: Name: MpKslb6d617b1 PNP Device ID: ROOT\LEGACY_MPKSLB6D617B1\0000 Service: MpKslb6d617b1 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKslf5acc910 Device ID: ROOT\LEGACY_MPKSLF5ACC910\0000 Manufacturer: Name: MpKslf5acc910 PNP Device ID: ROOT\LEGACY_MPKSLF5ACC910\0000 Service: MpKslf5acc910 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKslfc4dd0c2 Device ID: ROOT\LEGACY_MPKSLFC4DD0C2\0000 Manufacturer: Name: MpKslfc4dd0c2 PNP Device ID: ROOT\LEGACY_MPKSLFC4DD0C2\0000 Service: MpKslfc4dd0c2 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKslfe7356a1 Device ID: ROOT\LEGACY_MPKSLFE7356A1\0000 Manufacturer: Name: MpKslfe7356a1 PNP Device ID: ROOT\LEGACY_MPKSLFE7356A1\0000 Service: MpKslfe7356a1 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl3d28269a Device ID: ROOT\LEGACY_MPKSL3D28269A\0000 Manufacturer: Name: MpKsl3d28269a PNP Device ID: ROOT\LEGACY_MPKSL3D28269A\0000 Service: MpKsl3d28269a Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl8e160de3 Device ID: ROOT\LEGACY_MPKSL8E160DE3\0000 Manufacturer: Name: MpKsl8e160de3 PNP Device ID: ROOT\LEGACY_MPKSL8E160DE3\0000 Service: MpKsl8e160de3 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl05e81f3a Device ID: ROOT\LEGACY_MPKSL05E81F3A\0000 Manufacturer: Name: MpKsl05e81f3a PNP Device ID: ROOT\LEGACY_MPKSL05E81F3A\0000 Service: MpKsl05e81f3a Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl94251af1 Device ID: ROOT\LEGACY_MPKSL94251AF1\0000 Manufacturer: Name: MpKsl94251af1 PNP Device ID: ROOT\LEGACY_MPKSL94251AF1\0000 Service: MpKsl94251af1 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl4c026cd4 Device ID: ROOT\LEGACY_MPKSL4C026CD4\0000 Manufacturer: Name: MpKsl4c026cd4 PNP Device ID: ROOT\LEGACY_MPKSL4C026CD4\0000 Service: MpKsl4c026cd4 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl9a6f0553 Device ID: ROOT\LEGACY_MPKSL9A6F0553\0000 Manufacturer: Name: MpKsl9a6f0553 PNP Device ID: ROOT\LEGACY_MPKSL9A6F0553\0000 Service: MpKsl9a6f0553 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl5284be21 Device ID: ROOT\LEGACY_MPKSL5284BE21\0000 Manufacturer: Name: MpKsl5284be21 PNP Device ID: ROOT\LEGACY_MPKSL5284BE21\0000 Service: MpKsl5284be21 Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: MpKsl11542338 Device ID: ROOT\LEGACY_MPKSL11542338\0000 Manufacturer: Name: MpKsl11542338 PNP Device ID: ROOT\LEGACY_MPKSL11542338\0000 Service: MpKsl11542338 ==== System Restore Points =================== ==== Installed Programs ====================== Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X (10.0.1) - Português Adobe Reader X (10.1.1) - Português Adobe Shockwave Player 11.6 ATI - Software Uninstall Utility ATI Display Driver CCleaner D3DX10 Gadwin PrintScreen Google Chrome Java Auto Updater Java SE Development Kit 7 Update 1 LibreOffice 3.3 Malwarebytes' Anti-Malware versão 1.51.2.1300 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Application Error Reporting Microsoft Silverlight Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 Mozilla Firefox 8.0 (x86 pt-BR) MSVCRT Opera 11.51 Panda Cloud Antivirus Revo Uninstaller 1.92 Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) swMSM Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) VIA Rhine Family Fast Ethernet Adapter Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Windows Internet Explorer Platform Preview Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Messenger Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack ==== End Of File =========================== Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 22:54:06, on 28/10/2011 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: D:\Windows\system32\taskhost.exe D:\Windows\system32\Dwm.exe D:\Windows\Explorer.EXE D:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe D:\Program Files\Mozilla Firefox\firefox.exe D:\Program Files\Mozilla Firefox\plugin-container.exe D:\Program Files\Windows Live\Messenger\msnmsgr.exe D:\Program Files\Windows Live\Contacts\wlcomm.exe D:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe D:\Users\Edson Luis\Downloads\HijackThis.exe D:\Users\Edson Luis\Downloads\dds.scr D:\Windows\system32\conhost.exe D:\Windows\system32\cmd.exe D:\Users\Edson Luis\AppData\Local\temp\497E.tmp\PEV.DAT R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [PSUNMain] "D:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - D:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\Windows\system32\Ati2evxx.exe O23 - Service: Panda Cloud Antivirus Service (NanoServiceMain) - Panda Security, S.L. - D:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe -- End of file - 2658 bytes Abraços e obrigado desde já . Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Outubro 30, 2011 Olá EDSSX O seu caso já está em andamento no Linha Defensiva. Procede? Compartilhar este post Link para o post Compartilhar em outros sites
EDSSX 0 Denunciar post Postado Outubro 30, 2011 Bom dia ! wings Sim ; positivo ! Pode trancar aqui . Abraços Compartilhar este post Link para o post Compartilhar em outros sites
wings 22 Denunciar post Postado Outubro 30, 2011 PROBLEMA RESOLVIDO Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites