ComboFix 12-07-26.04 - Vhagostini 25/07/2012 19:19:54.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.1023.311 [GMT -3:00]
Executando de: c:\documents and settings\Vhagostini\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
ADS - system32: deleted 6 bytes in 3 streams. ADS - drivers: deleted 412 bytes in 1 streams. .
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\arquivos de programas\AVOne3gpConverter_00000.exe
c:\documents and settings\All Users\Dados de aplicativos\944570F657.sys
c:\documents and settings\Vhagostini\Dados de aplicativos\vso_ts_preview.xml
c:\windows\daemon.dll
c:\windows\IsUn0416.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ddsxeiservice
-------\Service_ddsxeiservice
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2012-06-26 to 2012-07-26 ))))))))))))))))))))))))))))
.
.
2012-07-25 21:05 . 2012-07-25 21:05 -------- d-----w- c:\documents and settings\Vhagostini\Dados de aplicativos\Malwarebytes
2012-07-25 21:05 . 2012-07-25 21:05 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes
2012-07-25 21:05 . 2012-07-25 21:05 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware
2012-07-25 21:05 . 2012-07-03 16:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-25 21:01 . 2012-07-25 21:44 -------- d-----w- C:\LinhaDefensiva
2012-07-25 19:54 . 2012-07-25 19:54 388608 ----a-w- C:\HijackThis.exe
2012-07-25 19:37 . 2012-07-25 19:37 -------- d-----w- c:\documents and settings\NetworkService\Dados de aplicativos\360Safe
2012-07-25 19:04 . 2012-07-25 21:34 -------- d-----w- c:\documents and settings\Vhagostini\PSafe
2012-07-25 19:04 . 2012-07-25 19:04 -------- d-----w- c:\documents and settings\LocalService\Dados de aplicativos\360Safe
2012-07-25 19:03 . 2012-06-01 00:21 146304 ----a-r- c:\windows\system32\drivers\360FileOem.sys
2012-07-25 19:03 . 2012-06-01 00:21 23168 ----a-r- c:\windows\system32\drivers\360RegOem.sys
2012-07-25 19:03 . 2012-06-01 00:21 54912 ----a-r- c:\windows\system32\drivers\360HookOem.sys
2012-07-25 19:03 . 2012-07-25 21:37 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\PSafe
2012-07-25 19:01 . 2012-07-25 19:01 247 ----a-w- C:\user.js
2012-07-25 19:01 . 2012-07-25 19:01 -------- d-----w- c:\arquivos de programas\BabylonToolbar
2012-07-25 19:00 . 2012-07-25 19:00 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Babylon
2012-07-25 19:00 . 2012-07-26 01:21 -------- d-----w- c:\arquivos de programas\PSafe
2012-07-25 18:13 . 2012-07-25 18:13 -------- d-----w- c:\arquivos de programas\CCleaner
2012-07-25 18:06 . 2012-07-25 18:06 -------- d-----w- c:\documents and settings\Vhagostini\Configurações locais\Dados de aplicativos\Downloaded Installations
2012-07-25 17:57 . 2012-07-25 17:57 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\ATI
2012-07-25 17:46 . 2000-01-01 00:00 53248 ----a-w- c:\windows\system32\CSVer.dll
2012-07-25 17:16 . 2012-07-25 17:16 -------- d-----w- c:\documents and settings\Vhagostini\Configurações locais\Dados de aplicativos\SlimWare Utilities Inc
2012-07-25 17:16 . 2012-07-25 17:16 -------- d-----w- c:\arquivos de programas\SlimDrivers
2012-07-18 23:45 . 2012-07-19 00:34 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-11 13:26 . 2012-07-11 13:26 27496 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-07-05 04:15 . 2012-07-05 04:15 -------- d-----w- c:\arquivos de programas\Oracle
2012-07-05 04:15 . 2012-07-05 04:15 -------- d-----w- c:\documents and settings\Vhagostini\Dados de aplicativos\Oracle
2012-07-05 04:15 . 2012-07-05 04:15 -------- d-----w- c:\documents and settings\Vhagostini\Configurações locais\Dados de aplicativos\Sun
.
.
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-26 01:12 . 2012-05-06 01:59 28880 ----a-w- c:\windows\system32\drivers\GbpNdisrd.sys
2012-07-19 00:34 . 2011-06-09 23:04 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-02 18:19 . 2008-07-19 01:09 15896 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 18:19 . 2008-09-24 22:46 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 18:19 . 2008-09-24 22:46 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 18:19 . 2008-09-24 22:46 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 18:19 . 2008-07-19 01:08 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 18:19 . 2008-09-24 22:46 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 18:19 . 2008-09-24 22:46 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 18:19 . 2008-07-19 01:10 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 18:19 . 2008-07-19 01:09 15896 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 18:19 . 2004-08-04 00:45 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 18:19 . 2008-09-24 22:46 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 18:19 . 2008-07-19 01:10 23576 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 18:19 . 2008-09-24 22:46 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 18:18 . 2008-09-26 11:18 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 18:18 . 2008-09-26 11:18 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 18:18 . 2008-09-26 11:18 17648 ----a-w- c:\windows\system32\mucltui.dll.mui
2008-11-20 18:34 . 2008-11-20 18:33 3292936 ----a-w- c:\arquivos de programas\UnityWebPlayer.exe
2005-04-01 01:17 . 2008-09-25 14:31 40960 ----a-w- c:\arquivos de programas\Uninstall_CDS.exe
2004-07-09 07:08 . 2004-07-09 07:08 2242560 ----a-w- c:\arquivos de programas\dsetup32.dll
.
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por padrão não são apresentadas.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-07-11 13:27 2086496 ----a-w- c:\arquivos de programas\AVG Secure Search\12.1.0.13\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\arquivos de programas\AVG Secure Search\12.1.0.13\AVG Secure Search_toolbar.dll" [2012-07-11 2086496]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1PSafeOverlaySync]
@="{A48EC0D3-3DDF-4A75-B35E-B1AFBC6E40F7}"
[HKEY_CLASSES_ROOT\CLSID\{A48EC0D3-3DDF-4A75-B35E-B1AFBC6E40F7}]
2012-07-12 01:10 2051848 ----a-w- c:\arquivos de programas\PSafe\shell\v2.8.1207.11401\PSafeShellExtensionx86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2PSafeOverlayOk]
@="{A48EC0D3-4DDF-4A75-B35E-B1AFBC6E40F7}"
[HKEY_CLASSES_ROOT\CLSID\{A48EC0D3-4DDF-4A75-B35E-B1AFBC6E40F7}]
2012-07-12 01:10 2051848 ----a-w- c:\arquivos de programas\PSafe\shell\v2.8.1207.11401\PSafeShellExtensionx86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3PSafeOverlayOut]
@="{A48EC0D3-5DDF-4A75-B35E-B1AFBC6E40F7}"
[HKEY_CLASSES_ROOT\CLSID\{A48EC0D3-5DDF-4A75-B35E-B1AFBC6E40F7}]
2012-07-12 01:10 2051848 ----a-w- c:\arquivos de programas\PSafe\shell\v2.8.1207.11401\PSafeShellExtensionx86.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"="c:\arquivos de programas\Ares\Ares.exe" [2010-10-27 1015808]
"Facebook Update"="c:\documents and settings\Vhagostini\Configurações locais\Dados de aplicativos\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vistadrv"="c:\arquivos de programas\VistaDrives\vsdrv.exe" [2006-07-30 121089]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 16126464]
"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2011-10-17 2042208]
"QuickTime Task"="c:\arquivos de programas\QuickTime\qttask.exe" [2010-03-18 421888]
"GrooveMonitor"="c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"vProt"="c:\arquivos de programas\AVG Secure Search\vprot.exe" [2012-07-11 1148000]
"ROC_roc_dec12"="c:\arquivos de programas\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-23 928096]
"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"MutlimediaKbdDriver"="c:\arquivos de programas\Multimedia Keyboard Driver\M-KbdDrv.exe" [2007-09-17 1617920]
"SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2012-01-17 252296]
"ROC_roc_ssl_v12"="c:\arquivos de programas\AVG Secure Search\ROC_roc_ssl_v12.exe" [2012-07-11 1020512]
"StartCCC"="c:\arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-11 61440]
"PSafeSysTray"="c:\arquivos de programas\PSafe\PSafeSysTray.exe" [2012-07-12 5001992]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"3telefonica.BlockedAlerts"="c:\arquivos de programas\Assistente Tecnico Speedy\bin\AboutBrowser\MotiveBrowser.exe" [2006-03-15 139264]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\arquivos de programas\Windows Sidebar\sidebar.exe" [2007-01-30 1230848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-12-20 124928]
.
c:\documents and settings\Vhagostini\Menu Iniciar\Programas\Inicializar\
Recorte de tela e Iniciador do OneNote 2007.lnk - c:\arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\
Monitor.lnk - c:\arquivos de programas\Eye 312S\Monitor.exe [2007-10-16 249856]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginAbn]
2012-03-29 19:40 621808 ------w- c:\arquivos de programas\GbPlugin\gbiehabn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]
2012-05-09 12:01 1313864 ----a-w- c:\arquivos de programas\GbPlugin\gbieh.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]
2012-01-11 17:01 726360 ------w- c:\arquivos de programas\GbPlugin\gbiehcef.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 11:25 11952 ----a-w- c:\windows\system32\avgrsstx.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Assistente Tecnico Speedy.lnk]
path=c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\Assistente Tecnico Speedy.lnk
backup=c:\windows\pss\Assistente Tecnico Speedy.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Vhagostini^Menu Iniciar^Programas^Inicializar^Registration Assassin's Creed.LNK]
backup=c:\windows\pss\Registration Assassin's Creed.LNKStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gerenciador de Tarefas do Windows
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-02 13:07 843712 ----a-r- c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
2008-11-15 14:11 2235920 ----a-w- c:\arquivos de programas\IObit\Advanced SystemCare 3\AWC.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
2010-10-27 09:00 1015808 ----a-w- c:\arquivos de programas\Ares\Ares.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-02-13 23:09 486856 ----a-w- c:\arquivos de programas\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
2004-08-22 20:05 81920 ----a-w- c:\arquivos de programas\D-Tools\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-03-04 19:31 136176 ----atw- c:\documents and settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 13:44 31072 ----a-w- c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2005-06-10 14:20 1397760 ------w- c:\arquivos de programas\Ahead\InCD\InCD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
2005-04-12 13:11 229376 ----a-w- c:\arquivos de programas\lg_fwupdate\fwupdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
2005-04-15 19:46 397312 ----a-w- c:\arquiv~1\Assistente Tecnico Speedy\SmartBridge\MotiveSB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:21 1695232 ------w- c:\arquivos de programas\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-17 01:12 3872080 ----a-w- c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 14:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 00:53 421888 ----a-w- c:\arquivos de programas\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-12-08 20:35 32768 ------w- c:\arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2007-01-30 02:21 1230848 ----a-w- c:\arquivos de programas\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2007-04-04 09:22 1822720 ------r- c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartRAM]
2008-11-06 16:41 202256 ----a-w- c:\arquivos de programas\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2010-02-11 02:32 61440 ----a-w- c:\arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-12-17 17:05 1242448 ----a-w- c:\arquivos de programas\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-25 08:23 149280 ----a-w- c:\arquivos de programas\Java\jre6\bin\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Arquivos de programas\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=
"c:\\Arquivos de programas\\Valve\\hl.exe"=
"c:\\Arquivos de programas\\Valve\\hlds.exe"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=
"c:\\Arquivos de programas\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Documents and Settings\\Vhagostini\\Meus documentos\\Vhagostini\\Arquivos e programas\\Games\\Counter Strike\\Counter Strike\\Valve\\hl.exe"=
"c:\\Arquivos de programas\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Arquivos de programas\\Teamspeak2_RC2 SERVER\\server_windows.exe"=
"c:\\Arquivos de programas\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Arquivos de programas\\Tibiacast\\Tibiacast Client.exe"=
"c:\\Arquivos de programas\\Flock\\flock.exe"=
"c:\\Arquivos de programas\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Documents and Settings\\Vhagostini\\Configurações locais\\Dados de aplicativos\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Arquivos de programas\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Arquivos de programas\\Ares\\Ares.exe"=
"c:\\Arquivos de programas\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Arquivos de programas\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Documents and Settings\\Carlos Agostini\\Configurações locais\\Dados de aplicativos\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Arquivos de programas\\Steam\\steamapps\\antony_777\\counter-strike\\hl.exe"=
"c:\\Arquivos de programas\\Warcraft III\\Warcraft III.exe"=
"c:\\Arquivos de programas\\Valve\\HL2 Lost Coast\\hl2.exe"=
"c:\\Documents and Settings\\Vhagostini\\Configurações locais\\Dados de aplicativos\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Arquivos de programas\\Garena Plus\\Room\\garena_room.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
"c:\\Arquivos de programas\\PSafe\\PSRsync.exe"=
.
R0 360HookOem;360HookOem;c:\windows\system32\drivers\360HookOem.sys [25/7/2012 16:03 54912]
R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [17/7/2010 18:13 46408]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3/7/2010 22:46 716272]
R1 360FileOem;360FileOem;c:\windows\system32\drivers\360FileOem.sys [25/7/2012 16:03 146304]
R1 360RegOem;360RegOem;c:\windows\system32\drivers\360RegOem.sys [25/7/2012 16:03 23168]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/5/2009 18:55 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [19/5/2009 18:55 108552]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [11/7/2012 10:26 27496]
R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [19/5/2009 18:54 297752]
R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [17/7/2010 18:13 214088]
R2 PSafeLockBoxSvc;PSafeLockBoxSvc;c:\arquivos de programas\PSafe\PSafeCategoryFinder.exe [25/7/2012 16:03 1768200]
R2 PSafeSVC;PSafeSVC;c:\arquivos de programas\PSafe\PSafesvc.exe [25/7/2012 16:03 1775368]
R2 PSafeWD;PSafeWD;c:\arquivos de programas\PSafe\PSafeWD.exe [25/7/2012 16:03 250632]
R2 vToolbarUpdater12.1.2;vToolbarUpdater12.1.2;c:\arquivos de programas\Arquivos comuns\AVG Secure Search\vToolbarUpdater\12.1.2\ToolbarUpdater.exe [11/7/2012 10:25 830048]
R3 CamSuiteVAC;CamSuite Virtual Audio;c:\windows\system32\drivers\CamSuiteVAC.sys [28/7/2010 21:33 37560]
R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\GbpNdisrd.sys [5/5/2012 22:59 28880]
S0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [12/10/2009 22:09 155136]
S0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [12/10/2009 22:09 5248]
S2 gupdate1ca28f6c0f7256e;Google Update Service (gupdate1ca28f6c0f7256e);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [29/8/2009 19:19 133104]
S2 SkypeUpdate;Skype Updater;c:\arquivos de programas\Skype\Updater\Updater.exe [7/6/2012 19:12 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [18/7/2012 20:45 250056]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\arquivos de programas\AVG\AVG8\Toolbar\ToolbarBroker.exe [3/11/2010 08:49 167264]
S3 Ca2001v;CA2001 WebCam Driver;c:\windows\system32\drivers\Ca2001v.sys [19/2/2008 11:48 2333568]
S3 extrem.sys;extrem;\??\c:\docume~1\VHAGOS~1\CONFIG~1\Temp\extrem.sys --> c:\docume~1\VHAGOS~1\CONFIG~1\Temp\extrem.sys [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\arquivos de programas\Garena Plus\Room\safedrv.sys --> c:\arquivos de programas\Garena Plus\Room\safedrv.sys [?]
S3 gupdatem;Serviço do Google Update (gupdatem);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [29/8/2009 19:19 133104]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys --> c:\windows\system32\DRIVERS\ewusbdev.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys --> c:\windows\system32\DRIVERS\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys --> c:\windows\system32\DRIVERS\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\DRIVERS\motodrv.sys --> c:\windows\system32\DRIVERS\motodrv.sys [?]
S3 Ndisrd;GAS Tecnologia Service;c:\windows\system32\drivers\GbpNdisrd.sys [5/5/2012 22:59 28880]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{34A19196-274E-4D75-9D30-D7A45A0A4178}]
2004-08-04 00:45 11776 ----a-w- c:\arquivos de programas\Windows Sidebar\regsvr32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6B9228DA-9C15-419e-856C-19E768A13BDC}]
2004-08-04 00:45 11776 ----a-w- c:\arquivos de programas\Windows Sidebar\regsvr32.exe
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2012-07-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-18 00:34]
.
2012-06-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2008-07-30 15:34]
.
2012-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-08-29 22:19]
.
2012-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2009-08-29 22:19]
.
2012-07-26 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 18:07]
.
2012-07-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-842925246-796845957-682003330-1005.job
- c:\arquivos de programas\Real\RealUpgrade\realupgrade.exe [2011-09-27 16:40]
.
2012-07-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-842925246-796845957-682003330-1006.job
- c:\arquivos de programas\Real\RealUpgrade\realupgrade.exe [2011-09-27 16:40]
.
2012-07-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-842925246-796845957-682003330-1008.job
- c:\arquivos de programas\Real\RealUpgrade\realupgrade.exe [2011-09-27 16:40]
.
2012-07-20 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-842925246-796845957-682003330-1005.job
- c:\arquivos de programas\Real\RealUpgrade\realupgrade.exe [2011-09-27 16:40]
.
2012-07-19 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-842925246-796845957-682003330-1006.job
- c:\arquivos de programas\Real\RealUpgrade\realupgrade.exe [2011-09-27 16:40]
.
2012-07-22 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-842925246-796845957-682003330-1008.job
- c:\arquivos de programas\Real\RealUpgrade\realupgrade.exe [2011-09-27 16:40]
.
2012-07-26 c:\windows\Tasks\User_Feed_Synchronization-{E601AEFE-6E36-4533-A707-AAB966F610FE}.job
- c:\windows\system32\msfeedssync.exe [2007-02-04 01:21]
.
2012-07-26 c:\windows\Tasks\User_Feed_Synchronization-{FB65940D-4E04-48AF-99A3-1E3D6B21C23A}.job
- c:\windows\system32\msfeedssync.exe [2007-02-04 01:21]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://search.babylon.com/?affID=113480&tt=3012_8&babsrc=HP_ss&mntrId=50753085000000000000001fc603a632
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://search.minilua.com/q/%s
IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\documents and settings\Vhagostini\Dados de aplicativos\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
IE: Translate with &Babylon - c:\arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
Trusted Zone: bancoreal.com.br\www
Trusted Zone: bancosantander.com.br\www
Trusted Zone: realsecureweb.com.br\www
Trusted Zone: realsecureweb.com.br\www2
Trusted Zone: realsecureweb.com.br\wwws
Trusted Zone: santander.com.br\www
Trusted Zone: santanderempresarial.com.br\www
Trusted Zone: santandernet.com.br\www
Trusted Zone: santandernet.com.br\wwws
Trusted Zone: santandernet.com.br\wwws2
Trusted Zone: santandernetibe.com.br\www
Trusted Zone: secureweb.com.br\www
TCP: DhcpNameServer = 187.2.80.16 187.2.80.15
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\arquivos de programas\Arquivos comuns\AVG Secure Search\ViProtocolInstaller\12.1.2\ViProtocol.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Vhagostini\Dados de aplicativos\Mozilla\Firefox\Profiles\l2vbp025.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1269415&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?affID=113480&tt=3012_8&babsrc=HP_ss&mntrId=50753085000000000000001fc603a632
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=113480&tt=3012_8&babsrc=KW_ss&mntrId=50753085000000000000001fc603a632&q=
FF - user.js: extensions.BabylonToolbar_i.id - 50753085000000000000001fc603a632
FF - user.js: extensions.BabylonToolbar_i.hardId - 50753085000000000000001fc603a632
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15546
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:00
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=113480&tt=3012_8
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
.
------- Associação de arquivos/ficheiros -------
.
.scr=AutoCADScriptFile
.
- - - - ORFÃOS REMOVIDOS - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
HKLM-Run-TkBellExe - c:\arquivos de programas\real\realplayer\update\realsched.exe
HKLM-Run-Adobe Reader Speed Launcher - c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe
HKU-Default-Run-MsnMsgr - c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-awxDTools - c:\arquiv~1\arniWORX\AWXDTO~1\awxDTools.dll
MSConfigStartUp-BabylonToolbar - c:\arquivos de programas\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe
MSConfigStartUp-Free Download Manager - c:\arquivos de programas\Free Download Manager\fdm.exe
MSConfigStartUp-SpywareTerminatorUpdate - c:\arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe
MSConfigStartUp-swg - c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-WMI - c:\windows\system32\wmiprvse.exe
HKLM_ActiveSetup-{D58F39FF-953E-4F45-898F-59F243B9A523} - c:\windows\system32\hidec
AddRemove-Guitar Pro 5_is1 - c:\arquivos de programas\Guitar Pro 5.2\unins000.exe
AddRemove-Update Service - c:\documents and settings\Carlos Agostini\Meus documentos\Carlos\celular\programa celular sonyericsson\Update Service\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-07-25 22:17
Windows 5.1.2600 Service Pack 3 NTFS
.
Procurando processos ocultos ...
.
Procurando entradas auto inicializáveis ocultas ...
.
Procurando ficheiros/arquivos ocultos ...
.
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•Òw*]
"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]
"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
.
- - - - - - - > 'winlogon.exe'(1080)
c:\arquivos de programas\GbPlugin\gbieh.dll
c:\arquivos de programas\GbPlugin\gbiehCef.dll
c:\arquivos de programas\GbPlugin\gbiehabn.dll
c:\windows\system32\Ati2evxx.dll
.
------------------------ Outros Processos em Execução ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\arquivos de programas\Ahead\InCD\InCDsrv.exe
c:\windows\system32\Ati2evxx.exe
c:\arquivos de programas\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
c:\arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\arquiv~1\AVG\AVG8\avgrsx.exe
c:\arquiv~1\AVG\AVG8\avgnsx.exe
c:\arquivos de programas\Arquivos comuns\Protexis\License Service\PsiService_2.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Tempo para conclusão: 2012-07-25 22:29:07 - Máquina reiniciou
ComboFix-quarantined-files.txt 2012-07-26 01:29
.
Pré-execução: 26 pasta(s) 81.862.131.712 bytes disponíveis
Pós execução: 31 pasta(s) 83.407.077.376 bytes disponíveis
.
WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 9EC1D89280F55D54E0E8B38D0A8FE521
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:46:11, on 25/7/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\ARQUIV~1\GbPlugin\GbpSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe
C:\Arquivos de programas\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
c:\Arquivos de programas\Arquivos comuns\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\Arquivos comuns\AVG Secure Search\vToolbarUpdater\12.1.2\ToolbarUpdater.exe
C:\ARQUIV~1\AVG\AVG8\avgrsx.exe
C:\ARQUIV~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\ARQUIV~1\AVG\AVG8\avgtray.exe
C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe
C:\Arquivos de programas\AVG Secure Search\vprot.exe
C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe
C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Facebook\Update\FacebookUpdate.exe
C:\Arquivos de programas\Eye 312S\Monitor.exe
C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Arquivos de programas\PSafe\PSafeCategoryFinder.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://search.babylo...000001fc603a632R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://search.minilua.com/q/%sR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Arquivos de programas\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Arquivos de programas\AVG Secure Search\12.1.0.13\AVG Secure Search_toolbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Arquivos de programas\GbPlugin\gbieh.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Arquivos de programas\GbPlugin\gbiehCef.dll
O2 - BHO: G-Buster Browser Defense Banco Real - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\Arquivos de programas\GbPlugin\gbiehabn.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - (no file)
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Arquivos de programas\AVG Secure Search\12.1.0.13\AVG Secure Search_toolbar.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Arquivos de programas\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [Vistadrv] C:\Arquivos de programas\VistaDrives\vsdrv.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [vProt] "C:\Arquivos de programas\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [ROC_roc_dec12] "C:\Arquivos de programas\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12
O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [MutlimediaKbdDriver] C:\Arquivos de programas\Multimedia Keyboard Driver\M-KbdDrv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ROC_roc_ssl_v12] "C:\Arquivos de programas\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
O4 - HKLM\..\Run: [StartCCC] "C:\Arquivos de programas\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [PSafeSysTray] "C:\Arquivos de programas\PSafe\PSafeSysTray.exe"
O4 - HKLM\..\RunOnce: [3telefonica.BlockedAlerts] "C:\Arquivos de programas\Assistente Tecnico Speedy\bin\AboutBrowser\MotiveBrowser.exe" -APPKEY=telesp -WINDOWCONTEXT=telesp -URL=file://C:/Arquivos de programas/Assistente Tecnico Speedy/vendors/telefonica/content/template/driven_dev/BroadBandAsst/SB_Template/modificarRul.html
O4 - HKCU\..\Run: [ares] "C:\Arquivos de programas\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Facebook Update] "C:\Documents and Settings\Vhagostini\Configurações locais\Dados de aplicativos\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [Sidebar] C:\Arquivos de programas\Windows Sidebar\sidebar.exe /autoRun (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Sidebar] C:\Arquivos de programas\Windows Sidebar\sidebar.exe /autoRun (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Monitor.lnk = C:\Arquivos de programas\Eye 312S\Monitor.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Vhagostini\Dados de aplicativos\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O8 - Extra context menu item: Translate with &Babylon - res://C:\Arquivos de programas\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&
http://home.microsof...ss/allinone.aspO15 - Trusted Zone:
http://www.bancoreal.com.brO15 - Trusted Zone:
http://www.bancosantander.com.brO15 - Trusted Zone:
http://www.santander.com.brO15 - Trusted Zone:
http://www.santanderempresarial.com.brO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\Skype4COM.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Arquivos de programas\Arquivos comuns\AVG Secure Search\ViProtocolInstaller\12.1.2\ViProtocol.dll
O20 - Winlogon Notify: GbPluginAbn - C:\Arquivos de programas\GbPlugin\gbiehAbn.dll
O20 - Winlogon Notify: GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll
O20 - Winlogon Notify: GbPluginCef - C:\Arquivos de programas\GbPlugin\gbiehCef.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Arquivos de programas\Arquivos comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Arquivos de programas\AVG\AVG8\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Gbp Service (GbpSv) - - C:\ARQUIV~1\GbPlugin\GbpSv.exe
O23 - Service: Google Update Service (gupdate1ca28f6c0f7256e) (gupdate1ca28f6c0f7256e) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Arquivos de programas\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Arquivos de programas\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PSafeLockBoxSvc - PSafe - C:\Arquivos de programas\PSafe\PSafeCategoryFinder.exe
O23 - Service: PSafeSVC - PSafe S/A - C:\Arquivos de programas\PSafe\PSafesvc.exe
O23 - Service: PSafeWD - PSafe - C:\Arquivos de programas\PSafe\PSafeWD.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Arquivos de programas\Arquivos comuns\Protexis\License Service\PsiService_2.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Arquivos de programas\Skype\Updater\Updater.exe
O23 - Service: vToolbarUpdater12.1.2 - Unknown owner - C:\Arquivos de programas\Arquivos comuns\AVG Secure Search\vToolbarUpdater\12.1.2\ToolbarUpdater.exe
--
End of file - 14814 bytes
Só de alerta, o processo winlogon.exe ainda está retendo 50% da cpu