Ir para conteúdo



Este tópico foi arquivado e está fechado para novas respostas.


[Resolvido] &nbspGoogle: modulosegurança.cpl

Recommended Posts

Boa tarde. Desde ontem, notei que algo estranho vem acontecendo na internet. Os CAPTCHAs de sites não apareciam mais, o Facebook não abria e também o google, porém no google surgiu o seguinte termo:


"para continuar a sua navegação execute o modulo de segurança do google"


Além disso, pedia para instalar o arquivo "modulosegurança.cpl" (não instalei).


Pesquisei um pouco via Bing e duckduckgo (estavam funcionando) e falam que pode ser ataque via roteador que altera o dns, enfim... desliguei o roteador e conectei pelo cabo e voltou ao 'normal'.


Meu modem wireless: TL-WR740N TP-link.



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:31:39, on 14/10/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16514)
Boot mode: Normal

Running processes:
C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Users\ISAIAS\Desktop\Proteção; Limpadores\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Program Files\GbPlugin\gbiehCef.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)
O3 - Toolbar: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - (no file)
O4 - HKLM\..\Run: [OiVelox] C:\Program Files\Oi\Programmer\OiVeloxCheck.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Helper.lnk = C:\Program Files\\LastFMHelper.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone:
O15 - Trusted Zone:
O15 - Trusted Zone:
O15 - Trusted Zone:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{803A8E8F-63A9-4E12-AD24-5FC7651E7FD0}: NameServer =,
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: GbPluginBb - C:\Program Files\GbPlugin\gbieh.dll
O20 - Winlogon Notify: GbPluginCef - C:\Program Files\GbPlugin\gbiehCef.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Agendamento (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\PROGRA~1\GbPlugin\GbpSv.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Windows\RtkAudioService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files\Sony\VAIO Media plus\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files\Sony\VAIO Media plus\SOHDs.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
O23 - Service: UI Assistant Service - Unknown owner - C:\Program Files\Join Air\AssistantServices.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

End of file - 10566 bytes


Compartilhar este post

Link para o post
Compartilhar em outros sites

Boa Noite! isaiaslopes3

<'>Como instalar e configurar o roteador TP-Link TL-WR740N >

|- Já tentou reconfigurar o modem e atribuir nova senha no processo?


Compartilhar este post

Link para o post
Compartilhar em outros sites

eu resolvi ligar hoje de novo a internet via roteador, não está mais aparecendo o problema do google e facebook, mesmo assim vou trocar a senha. tem perigo de isso passar pro notebook?

Compartilhar este post

Link para o post
Compartilhar em outros sites

Boa Tarde! isaiaslopes3


eu resolvi ligar hoje de novo a internet via roteador, não está mais aparecendo o problema do google e facebook, mesmo assim vou trocar a senha. tem perigo de isso passar pro notebook?

|- Não há perigo,mas recomendo substituir a senha padrão que vem disponibilizada.



Compartilhar este post

Link para o post
Compartilhar em outros sites



voltou a dar o mesmo problema exatamente agora. é melhor resetar o modem? como substitui essa senha padrão?

|- Sim! Pode resetar... e quanto a senha,as instruções estão no Tutorial que lhe passei.



Compartilhar este post

Link para o post
Compartilhar em outros sites

ah tá, essa senha já tinha trocado. Resetei e continua aparecendo isso no site do google, não sei o que faço mais. o facebook e os sites com captchas voltaram ao normal.



passei o ccleaner. voltou ao normal agora o google. qualquer coisa eu aviso. obg. 17h28





18h06: ah, já voltou de novo, quando clica no botao do google manda pra esse link:

Compartilhar este post

Link para o post
Compartilhar em outros sites

Boa Noite! isaiaslopes3

|- Baixe: < zoek > ( ... by Smeenk )

|- Ou aqui! < 51a612a8b27e2-Zoek.png zoek.exe >

|- Salve-o no desktop!
|- Desabilite seu antivírus!
|- Para Windows 7,execute zoek.exe como administrador.


|- Copie e cole estas informações,em vermelho,no campo da ferramenta.
|- Clique "Run Script".

Zoek.exe is running now.
Do not start any browser windows, they will be closed automatically.
Please wait! This window will close when finished.
A logfile will open afterwards and can also be found on your systemdrive as zoek-results.log

|- Surgirão estas informações,pedindo-lhe que aguarde o relatório.


|- Aceite e/ou confirme o reboot!

zoek.hta failed by unknown error.
Restart computer, and try again.

|- Ps: Ao obter algum erro,reinicie o PC e execute,novamente,a ferramenta.
|- Poste o relatório,que estará em C:\zoek-results.txt <<



Compartilhar este post

Link para o post
Compartilhar em outros sites

olá, mesmo passando o programa, continua abrindo o site fake do google. o botão pra instalar tal programa leva a esse link:




Zoek.exe Version Updated 13-October-2013

Tool run by ISAIAS on 15/10/2013 at 19:04:14,36.

Microsoft® Windows Vista Home Basic 6.0.6002 Service Pack 2 x86

Running in: Normal Mode Internet Access Detected

Launched: C:\Users\ISAIAS\Desktop\zoek.exe [script inserted]


==== System Restore Info ======================


15/10/2013 19:06:38 Zoek.exe System Restore Point Created Succesfully.


==== Deleting CLSID Registry Keys ======================



==== Deleting CLSID Registry Values ======================



==== Deleting Services ======================



==== Firefox Extensions Registry ======================



"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension" [25/06/2009 12:28]


==== Firefox Extensions ======================


ProfilePath: C:\Users\ISAIAS\AppData\Roaming\Mozilla\Firefox\Profiles\lrdbzwws.default

- Microsoft .NET Framework Assistant - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

- DivX Web Player - %ProfilePath%\extensions\


AppDir: C:\Program Files\Mozilla Firefox

- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}


==== Firefox Plugins ======================


Profilepath: C:\Users\ISAIAS\AppData\Roaming\Mozilla\Firefox\Profiles\lrdbzwws.default

4BF70B35B943BD73BD6E13EB7C1BA4B3 - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll - Shockwave Flash

CFAF7B67C78D09D79688AEDCA3D090E2 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll - Google Update

BE501CBC29B2025A263D80D399F1797A - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll - Silverlight Plug-In

75300E5ED4CD5B4363C3DBBB2D03269C - C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMSS.dll - McAfee Security Scanner +

A843FC35574ECFD9E7A41C5505A9921B - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin

255C2A5EB2C0E9707805CEEEE511F329 - C:\Program Files\Research In Motion Limited\Plug-in do navegador do BlackBerry App World\npappworld.dll - BlackBerry AppWorld

FAE937CED2DCEB5001FF08ACC81BA479 - C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll - RIM Handheld Application Loader

34E3709244736B8976820F730E5A8815 - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll - Java Platform SE 6 U31

A878453A1714870EAADA83E6434BDB77 - C:\Program Files\Java\jre6\bin\plugin2\npdeployJava1.dll - Java Deployment Toolkit 6.0.310.5

C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery

4393DCB856A2A109E266E6F59E2EF31A - C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll - Adobe Acrobat

4393DCB856A2A109E266E6F59E2EF31A - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll - Adobe Acrobat

24E990B1E6D55428001843CF7217DD81 - C:\Program Files\Microsoft\Office Live\npOLW.dll - Microsoft Office Live Plug-in for Firefox / Microsoft Office Live Plug-in for Firefox

65FB4909BD29CAAA81FDC69AD21BB905 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll - RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit)

01F0264937036BD962563F1ADF35CE72 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll - RealPlayer Version Plugin

04D8297D6E237A01157765653BF5259F - C:\Program Files\Garmin GPS Plugin\npGarmin.dll - Garmin Communicator Plug-In

AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation

B27CCB1168B1960AEC6E9D3E0E0F0D2A - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrlui.dll - Microsoft® Silverlight



==== Set IE to Default ======================


Old Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"=""


New Values:

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"=""


==== All HKCU SearchScopes ======================


HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes


{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="{searchTerms}&FORM=IEFM1&src=IE-SearchBox"

{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="{searchTerms}&{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

{93D338C5-4995-4C17-940A-15DB6907DC78} Google Url="{searchTerms}&{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7"


==== Reset Google Chrome ======================


Nothing found to reset


==== HijackThis Entries ======================


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll

O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\PROGRAM FILES\GBPLUGIN\gbieh.dll

O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Program Files\GbPlugin\gbiehCef.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: (no name) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - (no file)

O3 - Toolbar: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - (no file)

O4 - HKLM\..\Run: [OiVelox] C:\Program Files\Oi\Programmer\OiVeloxCheck.exe

O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - Startup: Helper.lnk = C:\Program Files\\LastFMHelper.exe

O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html

O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

O15 - Trusted Zone:

O15 - Trusted Zone:

O15 - Trusted Zone:

O15 - Trusted Zone:

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

O20 - Winlogon Notify: GbPluginBb - C:\Program Files\GbPlugin\gbieh.dll

O20 - Winlogon Notify: GbPluginCef - C:\Program Files\GbPlugin\gbiehCef.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: Avira Agendamento (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE

O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\PROGRA~1\GbPlugin\GbpSv.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Windows\RtkAudioService.exe

O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe

O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files\Sony\VAIO Media plus\SOHDms.exe

O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files\Sony\VAIO Media plus\SOHDs.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe

O23 - Service: UI Assistant Service - Unknown owner - C:\Program Files\Join Air\AssistantServices.exe

O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe

O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe

O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe

O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe

O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe

O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe

O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe


==== Empty IE Cache ======================


C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

C:\Users\ISAIAS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot


==== Empty FireFox Cache ======================


C:\Users\ISAIAS\AppData\Local\Mozilla\Firefox\Profiles\lrdbzwws.default\Cache emptied successfully


==== Empty Chrome Cache ======================


No Chrome User Data found


==== Empty All Flash Cache ======================


Flash Cache Emptied Successfully


==== Empty All Java Cache ======================


Java Cache cleared successfully


==== After Reboot ======================


==== Empty Temp Folders ======================


C:\Windows\Temp successfully emptied

C:\Users\ISAIAS\AppData\Local\Temp successfully emptied


==== Empty Recycle Bin ======================


C:\$RECYCLE.BIN successfully emptied


==== Deleting Files / Folders ======================


"C:\Users\ISAIAS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted


==== EOF on 15/10/2013 at 19:36:37,51 ======================


agora está pedindo para instalar modulo de segurança no facebook.

Compartilhar este post

Link para o post
Compartilhar em outros sites

Bom Dia! isaiaslopes3


|- Baixe: < Complete Internet Repair >
|- Extraia o conteúdo e execute o arquivo "CIntRep.exe".




|- Marque as checkbox:

Reset Internet Protocol (TCP/IP)
Repair Winsock (Reset Catalog)
Renew Internet Connections
Flush DNS Resolver Cache
Restore the default hosts file
Repair SSL /HTTPS /Cryptography

|- Clique "Go!".
|- Ao concluir,reinicie o computador!
|- À seguir,acesse a pasta "Complete Internet Repair" >> "Logging".
|- Duplo-clique em "CIntRep.log".
|- Poste o log resultante!



Compartilhar este post

Link para o post
Compartilhar em outros sites

Boa tarde.


(o o)
[16/10/2013 13:15:20] Resetting all TCP/IP Interfaces, Please wait.....
[16/10/2013 13:15:26] TCP/IP interfaces reset successful.
[16/10/2013 13:15:27] TCP/IP v6 interfaces reset successful.
[16/10/2013 13:15:27] You may need to restart your computer for the settings to take effect.
[16/10/2013 13:15:27] Finished resetting the Internet Protocol (TCP/IP).

[16/10/2013 13:15:27] Attempting to reset Winsock catalog, Please wait.....
[16/10/2013 13:15:31] Successfully reset the Winsock Catalog.
[16/10/2013 13:15:31] Finished repairing Winsock

[16/10/2013 13:15:31] Releasing TCP/IP connections, Please wait.....
[16/10/2013 13:15:32] Successfully released TCP/IP connections.

[16/10/2013 13:15:32] Renewing TCP/IP connections, Please wait.....
[16/10/2013 13:15:38] Successfully renewed TCP/IP adapters.

[16/10/2013 13:15:38] Configuring the Windows Event Log Service, Please wait.....
[16/10/2013 13:15:50] Windows Event Log Service Configured.
[16/10/2013 13:15:50] Starting the Windows Event Log Service.....
[16/10/2013 13:15:51] Windows Event Log Service Started Successfully.

[16/10/2013 13:15:51] Flushing DNS Resolver Cache, Please wait.....
[16/10/2013 13:15:51] Successfully flushed DNS Resolver Cache.
[16/10/2013 13:15:51] Refreshing all DHCP leases and re-registering DNS names, Please wait.....
[16/10/2013 13:15:54] Registration of the DNS resource records has been initiated.
[16/10/2013 13:15:54] Note: Any errors will be reported in the 'Event Viewer' in about 15 minutes.
[16/10/2013 13:15:54] Note: Click on 'File' and then 'Event Viewer...' to open the Event Viewer.

[16/10/2013 13:15:54] Repairing SSL / HTTPS / Cryptography service, Please wait.....
[16/10/2013 13:15:54] Configuring the Cryptographic Service.....
[16/10/2013 13:15:55] Cryptographic Service Configured.
[16/10/2013 13:15:55] Stopping the Cryptographic Service.....
[16/10/2013 13:15:55] Cryptographic service Stopped Successfully.
[16/10/2013 13:15:55] Clearing [C:\Windows\system32\CatRoot].....
[16/10/2013 13:15:56] [C:\Windows\system32\CatRoot] cleared.
[16/10/2013 13:15:56] Re-registering SSL / HTTPS / Cryptography DLLs.....
[16/10/2013 13:15:57] RegSvr32.exe: 'cryptdlg.dll' registration succeeded.
[16/10/2013 13:15:58] RegSvr32.exe: 'cryptext.dll' registration succeeded.
[16/10/2013 13:15:58] RegSvr32.exe: 'cryptui.dll' registration succeeded.
[16/10/2013 13:15:59] RegSvr32.exe: 'dssenh.dll' registration succeeded.
[16/10/2013 13:15:59] RegSvr32.exe: 'gpkcsp.dll' Specified module not found
[16/10/2013 13:15:59] RegSvr32.exe: 'initpki.dll' Specified module not found
[16/10/2013 13:15:59] RegSvr32.exe: 'licdll.dll' Specified module not found
[16/10/2013 13:16:00] RegSvr32.exe: 'mssign32.dll' registration succeeded.
[16/10/2013 13:16:00] RegSvr32.exe: 'mssip32.dll' registration succeeded.
[16/10/2013 13:16:00] RegSvr32.exe: 'regwizc.dll' Specified module not found
[16/10/2013 13:16:00] RegSvr32.exe: 'rsaenh.dll' registration succeeded.
[16/10/2013 13:16:00] RegSvr32.exe: 'scardssp.dll' Specified module not found
[16/10/2013 13:16:01] RegSvr32.exe: 'sccbase.dll' Specified module not found
[16/10/2013 13:16:06] RegSvr32.exe: 'scecli.dll' registration succeeded.
[16/10/2013 13:16:06] RegSvr32.exe: 'slbcsp.dll' Specified module not found
[16/10/2013 13:16:06] RegSvr32.exe: 'softpub.dll' registration succeeded.
[16/10/2013 13:16:06] RegSvr32.exe: 'winhttp.dll' registration succeeded.
[16/10/2013 13:16:07] RegSvr32.exe: 'wintrust.dll' registration succeeded.
[16/10/2013 13:16:07] SSL / HTTPS / Cryptography DLLs re-registered.
[16/10/2013 13:16:16] Restarting the Cryptographic Service.....
[16/10/2013 13:16:17] Cryptographic Service restarted.
[16/10/2013 13:16:17] Finished repairing SSL / HTTPS / Cryptography service.

[16/10/2013 13:16:17] Restoring the default Windows HOSTS file, Please wait.....
[16/10/2013 13:16:17] Writing data to the HOSTS file.....
[16/10/2013 13:16:17] HOSTS file created successfully.

[16/10/2013 13:16:17] You will need to reboot your computer before the settings will take effect.
[16/10/2013 13:17:18] Your computer is restarting now.....


Compartilhar este post

Link para o post
Compartilhar em outros sites

Boa Tarde! isaiaslopes3


|- O problema permanece?



Compartilhar este post

Link para o post
Compartilhar em outros sites

Bom Dia! isaiaslopes3


sim, continua com a pagina fake do google. vou resetar tudo, modem zte e roteador tp-link.

|- Ok! Se após o reset as páginas retornarem,verifique se existe a presença de rootkit no PC.




|- Baixe: ||
|- Salve-o no disco local e descompacte-o,direcionando-o ao desktop. ( Área de trabalho! )
|- Feche aplicações que estejam abertas! <- Importante!
|- Desabilite seu antivírus e/ou antispyware. <- Importante!
|- Execute-o com um duplo clique em TDSSKiller.exe
"%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt
|- Caso prefira executá-lo por linha de comando,digite ou cole a linha,em destaque,no executar.
|- Vá em Iniciar -> Executar -> Digite a LC -> Clique OK.
|- Ps: Essa modalidade na execução,somente funcionará se TDSSKiller.exe estiver no desktop.
|- Ps: Para Windows Vista ou 7,clique direito no arquivo e execute-o como administrador.
|- Na tela principal,siga a ordem numérica até a obtenção do relatório.
|- Em "Change parameters",marque todas as caixinhas.
|- Á seguir,clique em "Start scan"
|- Ao concluir,clique em "Skip" para detecções suspeitas.
|- Clique em "Continue". < TDSSKiller-continue.png >
|- Ao concluir,clique em "Report".
|- Poste-o em: < >
|- Ou... < >
|- Ou... < >

Compartilhar este post

Link para o post
Compartilhar em outros sites

Boa Tarde! isaiaslopes3



pelo menos por enquanto, o google ta normal.

|- Tudo aponta ser mesmo infecção rooterhijacker.

|- TDSSKiller,não mostrou a presença de rootkit em sua máquina.




|- Baixe: < GooredFix > ( jpshortstuff )
|- Salve-o no desktop!
|- Feche todas as janelas do Firefox,que estejam abertas.
|- Desabilite a proteção residente de antivírus ou antispywares.
|- Execute o arquivo GooredFix.exe,com um duplo-clique.
|- Execute o arquivo GooredFix.exe,como administrador,ao utilizar Windows Vista ou 7.
|- No prompt,aperte o 1 ( No Fix ) >> Enter.
|- Poste o relatório! ( GooredLog.txt )

Compartilhar este post

Link para o post
Compartilhar em outros sites

GooredFix by jpshortstuff (
Log created at 19:12 on 17/10/2013 (ISAIAS)
Firefox version 24.0 (pt-BR)

========== GooredScan ==========

========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\

"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [14:54 03/05/2009]


Compartilhar este post

Link para o post
Compartilhar em outros sites
Boa Noite! isaiaslopes3

|- O Firefox está isento de problemas,segundo GooredFix.

|- Remova as ferramentas que foram empregadas.


|- Baixe: |DelFix| ( ... de Xplode )


|- Estando na página,clique na seta verde para o download.

|- Salve-a em um local conveniente! ( desktop! )

|- Feche aplicativos que estejam abertos.


|- Execute-a!

|- Com as 3 checkbox marcadas!

|- Clique "Run".

|- Caso queira,poste o relatório.

|- Tudo Ok?


Compartilhar este post

Link para o post
Compartilhar em outros sites

Pra mim, tá normal. testei o e, facebook e deu certo.


# DelFix v10.5 - Logfile created 17/10/2013 at 20:01:26
# Updated 17/10/2013 by Xplode
# Username : ISAIAS - ISAIAS-PC
# Operating System : Windows Vista Home Basic Service Pack 2 (32 bits)

~ Removing disinfection tools ...

Deleted : C:\AdwCleaner
Deleted : C:\Users\ISAIAS\Desktop\GooredFix Backups
Deleted : C:\Program Files\Hijackthis
Deleted : C:\TDSSKiller.
Deleted : C:\TDSSKiller.
Deleted : C:\zoek-results.log
Deleted : C:\Users\ISAIAS\Desktop\GooredFix.exe
Deleted : C:\Users\ISAIAS\Desktop\GooredFix.txt
Deleted : C:\Users\ISAIAS\Desktop\TDSSKiller.exe
Deleted : C:\Users\ISAIAS\Desktop\
Deleted : C:\Users\ISAIAS\Desktop\
Deleted : C:\Users\ISAIAS\Desktop\zoek.exe
Deleted : C:\Users\ISAIAS\Desktop\zoek.scr
Deleted : C:\Users\ISAIAS\Desktop\
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis

~ Cleaning system restore ...

Deleted : RP #1528 [End of disinfection | 10/14/2013 19:34:41]
Deleted : RP #1529 [Ponto de Verificação Agendado | 10/15/2013 12:47:24]
Deleted : RP #1530 [Windows Update | 10/15/2013 14:06:10]
Deleted : RP #1531 [zoek.exe restore point | 10/15/2013 22:05:55]
Deleted : RP #1532 [Ponto de Verificação Agendado | 10/16/2013 17:20:56]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########

Compartilhar este post

Link para o post
Compartilhar em outros sites



Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post

Link para o post
Compartilhar em outros sites


Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.