<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
	<title>Malwares</title>
	<description></description>
	<link>http://www.babooforum.com.br/forum</link>
	<pubDate>Thu, 23 May 2013 14:45:56 +0000</pubDate>
	<ttl>60</ttl>
	<item>
		<title>Análise de Log</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767256-análise-de-log/</link>
		<description><![CDATA[<p>Procedi conforme solicitado para o post. Barras no Chrome esquisitas na hora da pesquisa.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div>Logfile of Trend Micro HijackThis v2.0.4</div>
<div>Scan saved at 11:40:53, on 23/05/2013</div>
<div>Platform: Unknown Windows (WinNT 6.02.1008)</div>
<div>MSIE: Internet Explorer v10.0 (10.00.9200.16537)</div>
<div>Boot mode: Normal</div>
<div>&nbsp;</div>
<div>Running processes:</div>
<div>C:\Program Files (x86)\Windows Media Player\wmplayer.exe</div>
<div>C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe</div>
<div>C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe</div>
<div>C:\Program Files (x86)\iTunes\iTunesHelper.exe</div>
<div>C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe</div>
<div>C:\Users\Silvio\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Silvio\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Silvio\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Silvio\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Silvio\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Silvio\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Silvio\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Silvio\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Silvio\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Silvio\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Silvio\Downloads\HijackThis.exe</div>
<div>&nbsp;</div>
<div>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =&nbsp;</div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =&nbsp;</div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm</div>
<div>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local</div>
<div>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =&nbsp;</div>
<div>F2 - REG:system.ini: UserInit=userinit.exe</div>
<div>O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll</div>
<div>O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll</div>
<div>O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll</div>
<div>O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll</div>
<div>O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll</div>
<div>O2 - BHO: DealPly Shopping - {a6c63b7f-2171-47fa-ab34-e64c4737169d} - C:\Program Files (x86)\DealPly\DealPlyIE.dll</div>
<div>O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL</div>
<div>O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL</div>
<div>O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll</div>
<div>O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll</div>
<div>O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll</div>
<div>O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe"</div>
<div>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"</div>
<div>O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"</div>
<div>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"</div>
<div>O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"</div>
<div>O4 - HKCU\..\Run: [Google Update] "C:\Users\Silvio\AppData\Local\Google\Update\GoogleUpdate.exe" /c</div>
<div>O4 - HKCU\..\Run: [BankerFixV3] \LinhaDefensiva\rotinas\postreboot.bat</div>
<div>O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105</div>
<div>O8 - Extra context menu item: Adicionar ao Antibanner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm</div>
<div>O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000</div>
<div>O9 - Extra button: Teclado Virtual - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll</div>
<div>O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll</div>
<div>O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll</div>
<div>O9 - Extra button: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll</div>
<div>O9 - Extra 'Tools' menuitem: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll</div>
<div>O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll</div>
<div>O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll</div>
<div>O9 - Extra button: Verificação de URLs - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll</div>
<div>O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics</div>
<div>O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL</div>
<div>O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL</div>
<div>O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)</div>
<div>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe</div>
<div>O23 - Service: Serviço do Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe</div>
<div>O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)</div>
<div>O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - Firebird Project - C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe</div>
<div>O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - Firebird Project - C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe</div>
<div>O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)</div>
<div>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe</div>
<div>O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)</div>
<div>O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe</div>
<div>O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe</div>
<div>O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)</div>
<div>O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)</div>
<div>O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)</div>
<div>O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)</div>
<div>O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)</div>
<div>&nbsp;</div>
<div>--</div>
<div>End of file - 11030 bytes</div>
<div>&nbsp;</div>
<div>_____________________________</div>
<div>Log Mban</div>
<div>&nbsp;</div>
<div>
<div>Malwarebytes Anti-Malware 1.75.0.1300</div>
<div>www.malwarebytes.org</div>
<div>&nbsp;</div>
<div>Versão da Base de Dados: &nbsp;v2013.05.23.06</div>
<div>&nbsp;</div>
<div>Windows 8 x64 NTFS</div>
<div>Internet Explorer 10.0.9200.16580</div>
<div>Silvio :: WOLVERINE [administrador]</div>
<div>&nbsp;</div>
<div>23/05/2013 11:42:36</div>
<div>mbam-log-2013-05-23 (11-42-36).txt</div>
<div>&nbsp;</div>
<div>Tipo de Verificação: &nbsp;Verificação Rápida&nbsp;</div>
<div>Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos &nbsp;| Heurística/Extra | Heurística/Shuriken | PUP | PUM</div>
<div>Opções de verificação desativadas: P2P</div>
<div>Objetos escaneados: &nbsp;235457</div>
<div>Tempo decorrido: 1 minuto(s), 54 segundo(s)</div>
<div>&nbsp;</div>
<div>Processos de Memória Detectados: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>Módulos de Memória Detectados: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>Chaves de Registro Detectadas: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>Valores de Registro Detectadas: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>Itens de Dados no Registro Detectadas: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>Pastas Detectadas: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>Arquivos Detectados: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>(fim)</div>
<div>&nbsp;</div>
</div>
<div>&nbsp;</div>
]]></description>
		<pubDate>Thu, 23 May 2013 14:45:56 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767256-análise-de-log/</guid>
	</item>
	<item>
		<title>Analise de Log.</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767255-analise-de-log/</link>
		<description><![CDATA[<div>Meu computador/desktop &nbsp;esta dando alguns erro no google chrome ,driver grafico e no adobe as vezes,<br>
então só para ver se não tem nenhum maldito virus estou fazendo essa analise do log.<br><br>
Ja passei escaneamento completo do (!avast) Anti virus.<br><br><br><br><br><br><br><br>
--------------------------------------------------------------------------------------------------------------------------------------<br><br><br>
Logfile of Trend Micro HijackThis v2.0.4</div>
<div>Scan saved at 10:55:16, on 23/05/2013</div>
<div>Platform: Windows 7 &nbsp;(WinNT 6.00.3504)</div>
<div>MSIE: Internet Explorer v9.00 (9.00.8112.16470)</div>
<div>Boot mode: Normal</div>
<div>&nbsp;</div>
<div>Running processes:</div>
<div>C:\Program Files (x86)\Skype\Phone\Skype.exe</div>
<div>C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe</div>
<div>C:\Program Files\AVAST Software\Avast\AvastUI.exe</div>
<div>C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Sunny\Documents\HijackThis.exe</div>
<div>&nbsp;</div>
<div>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =&nbsp;</div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =&nbsp;</div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm</div>
<div>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =&nbsp;</div>
<div>F2 - REG:system.ini: UserInit=userinit.exe</div>
<div>O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll</div>
<div>O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll</div>
<div>O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll</div>
<div>O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll</div>
<div>O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui</div>
<div>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"</div>
<div>O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start</div>
<div>O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun</div>
<div>O4 - HKCU\..\Run: [GarenaPlus] "D:\Instalados\Garena Plus\GarenaMessenger.exe" -autolaunch</div>
<div>O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Instalados\DAEMON Tools Lite\DTLite.exe" -autorun</div>
<div>O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe</div>
<div>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO LOCAL')</div>
<div>O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO LOCAL')</div>
<div>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO DE REDE')</div>
<div>O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO DE REDE')</div>
<div>O4 - HKUS\S-1-5-21-2538448955-1683294703-1021672089-1004\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')</div>
<div>O4 - HKUS\S-1-5-21-2538448955-1683294703-1021672089-1004\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')</div>
<div>O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics</div>
<div>O15 - Trusted Zone: *.clonewarsadventures.com</div>
<div>O15 - Trusted Zone: *.freerealms.com</div>
<div>O15 - Trusted Zone: *.soe.com</div>
<div>O15 - Trusted Zone: *.sony.com</div>
<div>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL</div>
<div>O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)</div>
<div>O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe</div>
<div>O23 - Service: avast! antivírus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)</div>
<div>O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe</div>
<div>O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe</div>
<div>O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe</div>
<div>O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)</div>
<div>O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe</div>
<div>O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe</div>
<div>O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)</div>
<div>O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe</div>
<div>O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe</div>
<div>O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe</div>
<div>O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)</div>
<div>O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)</div>
<div>O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)</div>
<div>&nbsp;</div>
<div>--</div>
<div>End of file - 9081 bytes</div>
<div>&nbsp;</div>
]]></description>
		<pubDate>Thu, 23 May 2013 13:59:02 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767255-analise-de-log/</guid>
	</item>
	<item>
		<title>Analise de Log!</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767252-analise-de-log/</link>
		<description><![CDATA[<p>Pessoal bom dia, estou precisando de uma ajuda, usei um pendrive no meu note, e estou com receio de ter infectado o mesmo, porque meus outros pcs deram problema.</p>
<p>Segue Log, desde já muito obrigado!</p>
<p>&nbsp;</p>
<div>Logfile of Trend Micro HijackThis v2.0.4</div>
<div>Scan saved at 09:09:04, on 23/05/2013</div>
<div>Platform: Unknown Windows (WinNT 6.02.1008)</div>
<div>MSIE: Internet Explorer v10.0 (10.00.9200.16537)</div>
<div>Boot mode: Normal</div>
<div>&nbsp;</div>
<div>Running processes:</div>
<div>C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe</div>
<div>C:\Program Files (x86)\Skype\Phone\Skype.exe</div>
<div>C:\Program Files (x86)\AVG\AVG2013\avgui.exe</div>
<div>C:\Program Files\Sony\VAIO Care\listener.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\RODRIGOLUIZ\Downloads\HijackThis.exe</div>
<div>&nbsp;</div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =&nbsp;</div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =&nbsp;</div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm</div>
<div>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local</div>
<div>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =&nbsp;</div>
<div>F2 - REG:system.ini: UserInit=userinit.exe</div>
<div>O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll</div>
<div>O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL</div>
<div>O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL</div>
<div>O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun</div>
<div>O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"</div>
<div>O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY</div>
<div>O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"</div>
<div>O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe</div>
<div>O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe</div>
<div>O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin</div>
<div>O4 - HKLM\..\Run: [FireBird Guardian] C:\FireBird\bin\fbguard.exe</div>
<div>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime</div>
<div>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"</div>
<div>O4 - HKCU\..\Run: [HP Deskjet 3510 series (NET)] "C:\Program Files\HP\HP Deskjet 3510 series\Bin\ScanToPCActivationApp.exe" -deviceID "BR328FG11605TY:NW" -scfn "HP Deskjet 3510 series (NET)" -AutoStart 1</div>
<div>O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun</div>
<div>O4 - HKCU\..\Run: [Ybaqao] C:\Users\RODRIGOLUIZ\AppData\Roaming\Ybaqao.exe</div>
<div>O4 - Startup: Dropbox.lnk = RODRIGOLUIZ\AppData\Roaming\Dropbox\bin\Dropbox.exe</div>
<div>O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE</div>
<div>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe</div>
<div>O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105</div>
<div>O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200</div>
<div>O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000</div>
<div>O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe</div>
<div>O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe</div>
<div>O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll</div>
<div>O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll</div>
<div>O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll</div>
<div>O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll</div>
<div>O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics</div>
<div>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL</div>
<div>O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll</div>
<div>O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL</div>
<div>O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)</div>
<div>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe</div>
<div>O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe</div>
<div>O23 - Service: Autodesk Content Service - Unknown owner - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe</div>
<div>O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe</div>
<div>O23 - Service: Watchdog do AVG (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe</div>
<div>O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe</div>
<div>O23 - Service: Intel&reg; Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)</div>
<div>O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\FireBird\bin\fbguard.exe</div>
<div>O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\FireBird\bin\fbserver.exe</div>
<div>O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe</div>
<div>O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe</div>
<div>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe</div>
<div>O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)</div>
<div>O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)</div>
<div>O23 - Service: NetworkSupport - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkSupport.exe</div>
<div>O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe</div>
<div>O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)</div>
<div>O23 - Service: VAIO Care Performance Service (SampleCollector) - Unknown owner - C:\Program Files\Sony\VAIO Care\VCPerfService.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)</div>
<div>O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)</div>
<div>O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe</div>
<div>O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)</div>
<div>O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe</div>
<div>O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)</div>
<div>O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)</div>
<div>O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe</div>
<div>O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)</div>
<div>O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)</div>
<div>O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)</div>
<div>O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)</div>
<div>O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe</div>
<div>&nbsp;</div>
<div>--</div>
<div>End of file - 11422 bytes</div>
<div>&nbsp;</div>
]]></description>
		<pubDate>Thu, 23 May 2013 12:15:21 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767252-analise-de-log/</guid>
	</item>
	<item>
		<title>Notebook não inicia mais</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767247-notebook-não-inicia-mais/</link>
		<description><![CDATA[<p>Oi.</p>
<p>Minha irmã pegou um notebook meu e acessou uma rede wireless, a qual segundo ela foi identificada como internet Intelbras.</p>
<p>Achei estranho, porque a empresa costuma fabricar roteadores, celulares, telefones sem fio etc.</p>
<p>Só que ao ligar hoje pela manhã, ao ligar o notebook, ele inicia, e nem chega a entrar o Windows. aparece uma tela preta e uma carinha rindo e depois desliga.</p>
<p>Realmente tenho suspeita de virus mas não tenho como fazer a verificação pois o windows nem carrega.</p>
<p>&nbsp;</p>
<p>Sabem me informar o que pode ser ?</p>
]]></description>
		<pubDate>Wed, 22 May 2013 18:34:52 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767247-notebook-não-inicia-mais/</guid>
	</item>
	<item>
		<title>Notebook com Websearch (adware?)</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767246-notebook-com-websearch-adware/</link>
		<description><![CDATA[<p>Como diz o tópico, acabei instalando sem querer esse <strike>maldito </strike>WebSearch, e está estragando meus navegadores.</p>
<p><br>
Também senti um pouco de travadas em aplicações que utilizam o Adobe Flash, como YouTube.com / Twitch.tv / Jogos do Facebook. Não sei se tem algo relacionado. De qualquer forma, peço uma análise no log:<br><br>
(realizei todos os procedimentos no tópico fixo)<br><br>
Logfile of Trend Micro HijackThis v2.0.4<br>
Scan saved at 14:44:49, on 22/05/2013<br>
Platform: Windows 7 SP1 (WinNT 6.00.3505)<br>
MSIE: Internet Explorer v10.0 (10.00.9200.16537)<br>
Boot mode: Normal<br><br>
Running processes:<br>
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe<br>
C:\Program Files (x86)\Skype\Phone\Skype.exe<br>
C:\Program Files (x86)\LOLReplay\LOLRecorder.exe<br>
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe<br>
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe<br>
C:\Program Files (x86)\Razer\Mamba\RazerMambaSysTray.exe<br>
C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray.exe<br>
C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe<br>
C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.153\deploy\LoLLauncher.exe<br>
C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.18\deploy\LolClient.exe<br>
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br>
C:\Program Files (x86)\Easy Macro Recorder\Macro Recorder.exe<br>
C:\Riot Games\League of Legends\RADS\solutions\lol_game_client_sln\releases\0.0.0.232\deploy\League of Legends.exe<br>
C:\HijackThis.exe<br><br>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://websearch.searchrocket.info/?pid=298&r=2013/05/22&hid=518132871&lg=EN&cc=BR&unqvl=16' class='bbc_url' title='Link Externo' rel='nofollow external'>http://websearch.searchrocket.info/?pid=298&r=2013/05/22&hid=518132871&lg=EN&cc=BR&unqvl=16</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://websearch.searchrocket.info/?pid=298&r=2013/05/22&hid=518132871&lg=EN&cc=BR&unqvl=16' class='bbc_url' title='Link Externo' rel='nofollow external'>http://websearch.searchrocket.info/?pid=298&r=2013/05/22&hid=518132871&lg=EN&cc=BR&unqvl=16</a><br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br>
F2 - REG:system.ini: UserInit=userinit.exe<br>
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br>
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll<br>
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll<br>
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll<br>
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll<br>
O2 - BHO: Adobe Acrobat Create PDF Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll<br>
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office15\URLREDIR.DLL<br>
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~2\Office15\GROOVEEX.DLL<br>
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br>
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll<br>
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll<br>
O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll<br>
O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe"<br>
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"<br>
O4 - HKLM\..\Run: [Razer Mamba Elite Driver] C:\Program Files (x86)\Razer\Mamba\RazerMambaSysTray.exe<br>
O4 - HKLM\..\Run: [Razer StarcraftII Driver] C:\Program Files (x86)\Razer\Razer StarCraftII\RazerStarCraftIISysTray<br>
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun<br>
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO LOCAL')<br>
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO LOCAL')<br>
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO DE REDE')<br>
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO DE REDE')<br>
O4 - HKUS\S-1-5-21-1367692324-2732637912-253290389-1008\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')<br>
O4 - HKUS\S-1-5-21-1367692324-2732637912-253290389-1008\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')<br>
O4 - Global Startup: LOLRecorder.lnk = C:\Program Files (x86)\LOLReplay\LOLRecorder.exe<br>
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~2\Office15\ONBttnIE.dll/105<br>
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office15\EXCEL.EXE/3000<br>
O9 - Extra button: Virtual Keyboard - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll<br>
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll<br>
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll<br>
O9 - Extra button: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll<br>
O9 - Extra 'Tools' menuitem: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll<br>
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll<br>
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll<br>
O9 - Extra button: URLs check - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\IEExt\UrlAdvisor\klwtbbho.dll<br>
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics<br>
O15 - Trusted Zone: *.dell.com<br>
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL<br>
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL<br>
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL<br>
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll<br>
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe<br>
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe<br>
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe<br>
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br>
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe<br>
O23 - Service: Kaspersky Anti-Virus Service (AVP) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2013\avp.exe<br>
O23 - Service: Intel&reg; Centrino&reg; Wireless Bluetooth&reg; + High Speed Security Service (BTHSSecurityMgr) - Intel&reg; Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe<br>
O23 - Service: Intel&reg; Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe<br>
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)<br>
O23 - Service: Intel&reg; PROSet/Wireless Event Log (EvtEng) - Intel&reg; Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br>
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)<br>
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe<br>
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe<br>
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe<br>
O23 - Service: Intel&reg; Integrated Clock Controller Service - Intel&reg; ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel&reg; Integrated Clock Controller Service\ICCProxy.exe<br>
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe<br>
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br>
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe<br>
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)<br>
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe<br>
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: Intel&reg; PROSet/Wireless Registry Service (RegSrvc) - Intel&reg; Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br>
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br>
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe<br>
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br>
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br>
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)<br>
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe<br>
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br>
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe<br>
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br>
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br>
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br>
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)<br>
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)<br>
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br>
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br>
O23 - Service: Intel&reg; PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe<br><br>
--<br>
End of file - 13671 bytes<br>
&nbsp;</p>
]]></description>
		<pubDate>Wed, 22 May 2013 17:48:22 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767246-notebook-com-websearch-adware/</guid>
	</item>
	<item>
		<title>dúvida</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767241-dúvida/</link>
		<description><![CDATA[<p>Bom dia amigos. O log está limpo?</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div>Logfile of Trend Micro HijackThis v2.0.4</div>
<div>Scan saved at 09:13:10, on 22/5/2013</div>
<div>Platform: Windows XP SP3 (WinNT 5.01.2600)</div>
<div>MSIE: Internet Explorer v8.00 (8.00.6001.18702)</div>
<div>Boot mode: Normal</div>
<div>&nbsp;</div>
<div>Running processes:</div>
<div>C:\WINDOWS\System32\smss.exe</div>
<div>C:\WINDOWS\system32\winlogon.exe</div>
<div>C:\WINDOWS\system32\services.exe</div>
<div>C:\WINDOWS\system32\lsass.exe</div>
<div>C:\WINDOWS\system32\svchost.exe</div>
<div>C:\WINDOWS\System32\svchost.exe</div>
<div>C:\WINDOWS\system32\spoolsv.exe</div>
<div>C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe</div>
<div>C:\WINDOWS\Explorer.EXE</div>
<div>C:\WINDOWS\system32\ctfmon.exe</div>
<div>C:\WINDOWS\system32\igfxtray.exe</div>
<div>C:\WINDOWS\system32\hkcmd.exe</div>
<div>C:\WINDOWS\system32\igfxpers.exe</div>
<div>C:\WINDOWS\system32\igfxsrvc.exe</div>
<div>C:\Arquivos de programas\VIA\VIAudioi\HDADeck\HDeck.exe</div>
<div>C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe</div>
<div>C:\Arquivos de programas\Nero\Nero 10\Nero BackItUp\NBAgent.exe</div>
<div>C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe</div>
<div>C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe</div>
<div>C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamscheduler.exe</div>
<div>C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe</div>
<div>C:\Arquivos de programas\Nero\Update\NASvc.exe</div>
<div>C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe</div>
<div>C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe</div>
<div>C:\WINDOWS\system32\wuauclt.exe</div>
<div>C:\WINDOWS\system32\svchost.exe</div>
<div>C:\WINDOWS\system32\NOTEPAD.EXE</div>
<div>C:\Documents and Settings\Luciano\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe</div>
<div>C:\Documents and Settings\Luciano\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe</div>
<div>C:\Documents and Settings\Luciano\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe</div>
<div>D:\HijackThis (1).exe</div>
<div>&nbsp;</div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a></div>
<div>O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - (no file)</div>
<div>O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe</div>
<div>O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe</div>
<div>O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe</div>
<div>O4 - HKLM\..\Run: [HDAudDeck] C:\Arquivos de programas\VIA\VIAudioi\HDADeck\HDeck.exe 1</div>
<div>O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min</div>
<div>O4 - HKLM\..\Run: [NBAgent] "C:\Arquivos de programas\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart</div>
<div>O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"</div>
<div>O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"</div>
<div>O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe</div>
<div>O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Luciano\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c</div>
<div>O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')</div>
<div>O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')</div>
<div>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000</div>
<div>O14 - IERESET.INF: SEARCH_PAGE_URL=&<a href='http://home.microsoft.com/intl/br/access/allinone.asp' class='bbc_url' title='Link Externo' rel='nofollow external'>http://home.microsoft.com/intl/br/access/allinone.asp</a></div>
<div>O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - <a href='http://download.eset.com/special/eos/OnlineScanner.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://download.eset.com/special/eos/OnlineScanner.cab</a></div>
<div>O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL</div>
<div>O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll</div>
<div>O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll</div>
<div>O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe</div>
<div>O23 - Service: Avira Agendamento (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe</div>
<div>O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe</div>
<div>O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamscheduler.exe</div>
<div>O23 - Service: MBAMService - Malwarebytes Corporation - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe</div>
<div>O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe</div>
<div>O23 - Service: @C:\Arquivos de programas\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Arquivos de programas\Nero\Update\NASvc.exe</div>
<div>&nbsp;</div>
<div>--</div>
<div>End of file - 5150 bytes</div>
<div>&nbsp;</div>
]]></description>
		<pubDate>Wed, 22 May 2013 12:13:25 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767241-dúvida/</guid>
	</item>
	<item>
		<title>Instalei um vírus em meu PC, como tirá-lo? antivírus não detecta</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767237-instalei-um-vírus-em-meu-pc-como-tirá-lo-antivírus-não-detecta/</link>
		<description><![CDATA[<p>Amigos,</p>
<p>&nbsp;</p>
<p>Eu estava pesquisando uma imagem no Google sobre assinaturas pessoais de e-mail, e em um site eu fui redirecionado para um suposto site da Adobe, me solicitando que eu instalasse o flash player por ser um requisito daquele site. O site era tão igual ao da Adobe que fui logo instalando rsrsrs</p>
<p>Quando me alertei para olhar pra URL, notei que era um endereço de IP, e que o arquivo que baixei era ZIP (ainda o tenho em minha área de trabalho)...</p>
<p>&nbsp;</p>
<p>Enfim, instalei a praga em meu notebook. Agora o que faço para tirá-la?</p>
<p>&nbsp;</p>
<p>Não sei o nome do processo que pode estar aberto (se é que há algum processo pra esta praga), como tenho o arquivo do suposto vírus, posso dar um jeito de postá-lo para vocês analisarem-no.</p>
<p>&nbsp;</p>
<p>Passei o AdwCleaner no modo remover, e ele me deu o seguinte log:</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div># AdwCleaner v2.301 - Relatório criado em 21/05/2013 às 23:25:02</div>
<div># Atualizado em 16/05/2013 por Xplode</div>
<div># Sistema Operacional : Windows 8 Single Language &nbsp;(64 bits)</div>
<div># Usuário : Usuario&nbsp;Duanees - USUARIO</div>
<div># Modo de Boot : Normal</div>
<div># Executado de : C:\Users\Usuario&nbsp;Duanees\Downloads\adwcleaner.exe</div>
<div># Opção [Remover]</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>***** [Serviços] *****</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>***** [Arquivos/Pastas] *****</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>***** [Registro] *****</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>***** [Navegadores] *****</div>
<div>&nbsp;</div>
<div>-\\ Internet Explorer v10.0.9200.16537</div>
<div>&nbsp;</div>
<div>[OK] Registro está limpo.</div>
<div>&nbsp;</div>
<div>-\\ Mozilla Firefox v20.0.1 (pt-BR)</div>
<div>&nbsp;</div>
<div>Arquivo : C:\Users\Usuario&nbsp;Duanees\AppData\Roaming\Mozilla\Firefox\Profiles\r6ejm9jr.default\prefs.js</div>
<div>&nbsp;</div>
<div>[OK] Arquivo está limpo.</div>
<div>&nbsp;</div>
<div>-\\ Google Chrome v26.0.1410.64</div>
<div>&nbsp;</div>
<div>Arquivo : C:\Users\Usuario Duanees\AppData\Local\Google\Chrome\User Data\Default\Preferences</div>
<div>&nbsp;</div>
<div>[OK] Arquivo está limpo.</div>
<div>&nbsp;</div>
<div>*************************</div>
<div>&nbsp;</div>
<div>AdwCleaner[R1].txt - [997 octets] - [21/05/2013 23:24:41]</div>
<div>AdwCleaner[S2].txt - [927 octets] - [21/05/2013 23:25:02]</div>
<div>&nbsp;</div>
<div>########## EOF - C:\AdwCleaner[S2].txt - [986 octets] ##########</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>Ficarei muito agradecido pela ajuda!</div>
]]></description>
		<pubDate>Wed, 22 May 2013 02:42:24 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767237-instalei-um-vírus-em-meu-pc-como-tirá-lo-antivírus-não-detecta/</guid>
	</item>
	<item>
		<title>Log Do PC Da Minha Professora</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767224-log-do-pc-da-minha-professora/</link>
		<description><![CDATA[<p>Oi, Tudo Bem?</p>
<p>&nbsp;</p>
<p>Aqui Está O Log Do HijackThis Para O PC Da Minha Professora <img src='http://www.babooforum.com.br/forum/public/style_emoticons/chumbo/01_feliz.png' class='bbc_emoticon' alt=':)' /></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div>Logfile of Trend Micro HijackThis v2.0.4</div>
<div>Scan saved at 07:56:46, on 21/5/2013</div>
<div>Platform: Windows XP SP3 (WinNT 5.01.2600)</div>
<div>MSIE: Internet Explorer v8.00 (8.00.6001.18702)</div>
<div>Boot mode: Normal</div>
<div>&nbsp;</div>
<div>Running processes:</div>
<div>C:\WINDOWS\System32\smss.exe</div>
<div>C:\WINDOWS\system32\winlogon.exe</div>
<div>C:\WINDOWS\system32\services.exe</div>
<div>C:\WINDOWS\system32\lsass.exe</div>
<div>C:\Arquivos de programas\IObit\Advanced SystemCare 6\ASCService.exe</div>
<div>C:\WINDOWS\system32\svchost.exe</div>
<div>C:\WINDOWS\System32\svchost.exe</div>
<div>C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe</div>
<div>C:\WINDOWS\system32\spoolsv.exe</div>
<div>C:\WINDOWS\Explorer.EXE</div>
<div>C:\WINDOWS\SOUNDMAN.EXE</div>
<div>C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe</div>
<div>C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe</div>
<div>C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe</div>
<div>C:\WINDOWS\system32\ctfmon.exe</div>
<div>C:\Arquivos de programas\Skype\Phone\Skype.exe</div>
<div>C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE</div>
<div>C:\Arquivos de programas\Java\jre7\bin\jqs.exe</div>
<div>C:\WINDOWS\system32\svchost.exe</div>
<div>C:\Arquivos de programas\TeamViewer\Version8\TeamViewer_Service.exe</div>
<div>C:\WINDOWS\system32\wuauclt.exe</div>
<div>C:\Arquivos de programas\Google\Chrome\Application\chrome.exe</div>
<div>C:\Arquivos de programas\Google\Chrome\Application\chrome.exe</div>
<div>C:\Arquivos de programas\Google\Chrome\Application\chrome.exe</div>
<div>C:\Arquivos de programas\Google\Chrome\Application\chrome.exe</div>
<div>C:\Arquivos de programas\Google\Chrome\Application\chrome.exe</div>
<div>C:\HijackThis.exe</div>
<div>&nbsp;</div>
<div>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &<a href='http://home.microsoft.com/intl/br/access/allinone.asp' class='bbc_url' title='Link Externo' rel='nofollow external'>http://home.microsoft.com/intl/br/access/allinone.asp</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a></div>
<div>O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - (no file)</div>
<div>O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll</div>
<div>O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre7\bin\ssv.dll</div>
<div>O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\AVAST Software\Avast\aswWebRepIE.dll</div>
<div>O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll</div>
<div>O2 - BHO: 4sharedExt - {95525BD9-6136-4A26-8263-9CEE295D442D} - C:\Arquivos de programas\4shared Toolbar\4sharedExt32.dll</div>
<div>O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll</div>
<div>O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll</div>
<div>O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre7\bin\jp2ssv.dll</div>
<div>O3 - Toolbar: 4shared Toolbar - {95080B13-AA71-4EE8-B951-7E98221E1ED5} - C:\Arquivos de programas\4shared Toolbar\4sharedbar32.dll</div>
<div>O3 - Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - (no file)</div>
<div>O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll</div>
<div>O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\AVAST Software\Avast\aswWebRepIE.dll</div>
<div>O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE</div>
<div>O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"</div>
<div>O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"</div>
<div>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"</div>
<div>O4 - HKLM\..\Run: [avast] "C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe" /nogui</div>
<div>O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe</div>
<div>O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"</div>
<div>O4 - HKCU\..\Run: [Skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /minimized /regrun</div>
<div>O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')</div>
<div>O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')</div>
<div>O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')</div>
<div>O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')</div>
<div>O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE</div>
<div>O4 - Startup: Sumário do OneNote.onetoc2</div>
<div>O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll</div>
<div>O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll</div>
<div>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL</div>
<div>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe</div>
<div>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe</div>
<div>O14 - IERESET.INF: SEARCH_PAGE_URL=&<a href='http://home.microsoft.com/intl/br/access/allinone.asp' class='bbc_url' title='Link Externo' rel='nofollow external'>http://home.microsoft.com/intl/br/access/allinone.asp</a></div>
<div>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href='http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1344360810468' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1344360810468</a></div>
<div>O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll</div>
<div>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL</div>
<div>O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll</div>
<div>O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll</div>
<div>O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe</div>
<div>O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Arquivos de programas\IObit\Advanced SystemCare 6\ASCService.exe</div>
<div>O23 - Service: avast! antivírus - AVAST Software - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe</div>
<div>O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe</div>
<div>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Arquivos de programas\Java\jre7\bin\jqs.exe</div>
<div>O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe</div>
<div>O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Arquivos de programas\Skype\Updater\Updater.exe</div>
<div>O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Arquivos de programas\TeamViewer\Version8\TeamViewer_Service.exe</div>
<div>&nbsp;</div>
<div>--</div>
<div>End of file - 7923 bytes</div>
<div>&nbsp;</div>
]]></description>
		<pubDate>Tue, 21 May 2013 10:58:45 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767224-log-do-pc-da-minha-professora/</guid>
	</item>
	<item>
		<title>Analise de Log</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767218-analise-de-log/</link>
		<description><![CDATA[Olá, estou com problemas de lerdeza no computador<br>alem dos pop ups, q eu ja tentei quase todas ferramentas e nao consegui remover<br>segue log do Hijackthis<br>e do super anti spyware<br>&nbsp;<br>&nbsp;<br>&nbsp;<br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 19:04:48, on 20/05/2013<br>Platform: Windows Vista SP2 (WinNT 6.00.1906)<br>MSIE: Internet Explorer v9.00 (9.00.8112.16483)<br>Boot mode: Normal<br>&nbsp;<br>Running processes:<br>C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe<br>C:\Program Files (x86)\Steam\Steam.exe<br>C:\Program Files (x86)\Windows Media Player\wmplayer.exe<br>C:\Users\Jiraya\AppData\Roaming\Yontoo\YontooDesktop.exe<br>C:\Program Files (x86)\Razer\Lachesis\razerhid.exe<br>C:\Program Files (x86)\Razer\Lachesis\OSD.exe<br>C:\Program Files (x86)\AVG\AVG2013\avgui.exe<br>C:\Program Files (x86)\Razer\Lachesis\razertra.exe<br>C:\Program Files (x86)\AVG Secure Search\vprot.exe<br>C:\Program Files (x86)\Razer\Lachesis\razerofa.exe<br>C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe<br>C:\Program Files (x86)\iTunes\iTunesHelper.exe<br>C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br>C:\Windows\SysWOW64\conime.exe<br>C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Users\Jiraya\AppData\Local\Google\Chrome\Application\chrome.exe<br>C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe<br>&nbsp;<br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://www.sony.com/vaiopeople_f08' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.sony.com/vaiopeople_f08</a><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://www.sony.com/vaiopeople_f08' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.sony.com/vaiopeople_f08</a><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =&nbsp;<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =&nbsp;<br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br>R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =&nbsp;<br>F2 - REG:system.ini: UserInit=userinit.exe<br>O1 - Hosts: ::1 localhost<br>O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br>O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office12\GRA8E1~1.DLL<br>O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll<br>O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll<br>O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br>O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br>O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll<br>O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun<br>O4 - HKLM\..\Run: [Lachesis] "C:\Program Files (x86)\Razer\Lachesis\razerhid.exe"<br>O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY<br>O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"<br>O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br>O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"<br>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"<br>O4 - HKLM\..\Run: [myWIFIzone] C:\Program Files (x86)\myWIFIzone\myWIFIzone.exe<br>O4 - HKCU\..\Run: [Google Update] "C:\Users\Jiraya\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br>O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent<br>O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Jiraya\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver<br>O4 - HKCU\..\Run: [Yontoo Desktop] "C:\Users\Jiraya\AppData\Roaming\Yontoo\YontooDesktop.exe"<br>O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe<br>O4 - HKCU\..\Run: [R-Updater scheduler] C:\Program Files (x86)\R-Updater\rupdater.exe -autostart<br>O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')<br>O4 - Global Startup: Bluetooth.lnk = ?<br>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000<br>O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br>O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll<br>O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll<br>O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br>O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL<br>O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br>O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics<br>O13 - Gopher Prefix:&nbsp;<br>O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - <a href='http://esupport.sony.com/VaioInfo.CAB' class='bbc_url' title='Link Externo' rel='nofollow external'>http://esupport.sony.com/VaioInfo.CAB</a><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{3AE47831-50C4-43BA-85E3-B03AF6C6AE1D}: NameServer = 8.26.56.26,156.154.70.22<br>O17 - HKLM\System\CCS\Services\Tcpip\..\{E1032B33-7071-4846-88A0-6055C6285632}: NameServer = 8.26.56.26,156.154.70.22<br>O17 - HKLM\System\CS1\Services\Tcpip\..\{3AE47831-50C4-43BA-85E3-B03AF6C6AE1D}: NameServer = 8.26.56.26,156.154.70.22<br>O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~2\Office12\GR99D3~1.DLL<br>O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\windows\SysWow64\skype4com.dll<br>O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll<br>O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE<br>O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe<br>O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br>O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br>O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)<br>O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe<br>O23 - Service: Watchdog do AVG (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe<br>O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br>O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe<br>O23 - Service: COMODO Virtual Service Manager (cmdvirth) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe (file missing)<br>O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel&reg; Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br>O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe<br>O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe<br>O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe<br>O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe<br>O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br>O23 - Service: MySQL56 - Unknown owner - C:/Program.exe (file missing)<br>O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel&reg; Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br>O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br>O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Windows\RtkAudioService.exe<br>O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe<br>O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe<br>O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)<br>O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br>O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Media plus\SOHCImp.exe<br>O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Media plus\SOHDms.exe<br>O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Media plus\SOHDs.exe<br>O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br>O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe<br>O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe<br>O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe<br>O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br>O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe<br>O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe<br>O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe<br>O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe<br>O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe<br>O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe<br>O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe<br>O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br>O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br>O23 - Service: vToolbarUpdater14.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe<br>O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe<br>O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br>O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br>&nbsp;<br>--<br>End of file - 15934 bytes]]></description>
		<pubDate>Mon, 20 May 2013 22:09:19 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767218-analise-de-log/</guid>
	</item>
	<item>
		<title>Análise de log - Combofix</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767215-análise-de-log-combofix/</link>
		<description><![CDATA[<p>PC com vírus não abre Internet Explorer, e o Chrome, não deixa atualizar o Avast.</p>
<p>&nbsp;</p>
<p>Segue log do combofix.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div>ComboFix 13-05-20.01 - carla 20/05/2013 &nbsp;16:19:08.1.2 - x64</div>
<div>Microsoft Windows 7 Ultimate &nbsp; 6.1.7601.1.1252.55.1046.18.2013.737 [GMT -3:00]</div>
<div>Executando de: E:\ComboFix.exe</div>
<div>AV: avast! antivírus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}</div>
<div>SP: avast! antivírus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}</div>
<div>SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}</div>
<div>.</div>
<div>.</div>
<div>((((((((((((((((((((((((((((((((((((( &nbsp; Outras Exclusões &nbsp; )))))))))))))))))))))))))))))))))))))))))))))))))))</div>
<div>.</div>
<div>.</div>
<div>c:\danfeview\danfemon.exe</div>
<div>c:\unimake\UniNFe\danfemon.exe</div>
<div>c:\users\carla\AppData\Roaming\unins000.exe</div>
<div>c:\windows\msvcr71.dll</div>
<div>.</div>
<div>.</div>
<div>(((((((((((((((( &nbsp; Arquivos/Ficheiros criados de 2013-04-20 to 2013-05-20 &nbsp;))))))))))))))))))))))))))))</div>
<div>.</div>
<div>.</div>
<div>2013-05-20 19:24 . 2013-05-20 19:24 -------- d-----w- c:\users\Default\AppData\Local\temp</div>
<div>2013-05-20 14:41 . 2013-05-20 19:14 -------- d-----w- c:\programdata\GAS Tecnologia</div>
<div>2013-05-20 13:12 . 2013-05-05 21:36 17818624 ----a-w- c:\windows\system32\mshtml.dll</div>
<div>2013-05-20 13:12 . 2013-05-05 21:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb</div>
<div>2013-05-20 13:12 . 2013-05-05 19:12 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb</div>
<div>2013-05-20 12:40 . 2013-05-20 13:32 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6F0D65FB-0830-471B-AC94-41A10AFC69A9}\offreg.dll</div>
<div>2013-05-20 12:38 . 2013-05-20 12:38 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service</div>
<div>2013-05-20 11:36 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe</div>
<div>2013-05-20 11:36 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe</div>
<div>2013-05-17 21:05 . 2013-05-17 21:05 -------- d-----w- c:\windows\system32\SPReview</div>
<div>2013-05-17 21:04 . 2013-05-17 21:04 -------- d-----w- c:\windows\system32\EventProviders</div>
<div>2013-05-17 20:59 . 2013-05-17 20:59 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help</div>
<div>2013-05-17 16:45 . 2013-05-17 16:45 210432 ----a-w- c:\program files (x86)\Internet Explorer\02y3s13oo.exe</div>
<div>2013-05-17 16:22 . 2010-11-20 13:27 1197056 ----a-w- c:\windows\system32\taskschd.dll</div>
<div>2013-05-17 16:21 . 2010-11-20 13:27 605696 ----a-w- c:\windows\system32\wmpeffects.dll</div>
<div>2013-05-17 16:20 . 2010-11-20 13:33 14720 ----a-w- c:\windows\system32\drivers\hwpolicy.sys</div>
<div>2013-05-17 16:19 . 2010-11-20 13:16 12625920 ----a-w- c:\windows\system32\wmploc.DLL</div>
<div>2013-05-17 16:17 . 2010-11-20 13:27 244736 ----a-w- c:\program files\Windows Portable Devices\sqmapi.dll</div>
<div>2013-05-17 16:17 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll</div>
<div>2013-05-17 16:17 . 2010-11-20 13:27 244736 ----a-w- c:\windows\system32\sqmapi.dll</div>
<div>2013-05-17 14:57 . 2013-05-14 04:48 9460464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6F0D65FB-0830-471B-AC94-41A10AFC69A9}\mpengine.dll</div>
<div>2013-05-17 11:05 . 2013-05-17 11:05 -------- d-----w- c:\program files (x86)\Common Files\Skype</div>
<div>2013-05-17 10:59 . 2013-05-17 10:59 -------- d-----w- c:\windows\SysWow64\Wat</div>
<div>2013-05-17 10:59 . 2013-05-17 10:59 -------- d-----w- c:\windows\system32\Wat</div>
<div>2013-05-16 16:23 . 2012-12-04 19:23 47192 ----a-w- c:\windows\SysWow64\drivers\gbpkm.sys</div>
<div>2013-05-16 16:22 . 2013-05-16 16:23 -------- d-----w- c:\program files (x86)\GbPlugin</div>
<div>2013-05-16 16:22 . 2013-05-16 16:23 -------- d-----w- c:\programdata\GbPlugin</div>
<div>2013-05-16 12:56 . 2013-05-16 12:56 -------- d-----w- C:\nfe</div>
<div>2013-05-16 12:01 . 2012-07-26 07:56 2560 ----a-w- c:\windows\system32\drivers\pt-BR\wdf01000.sys.mui</div>
<div>2013-05-16 12:01 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys</div>
<div>2013-05-16 12:01 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys</div>
<div>2013-05-16 12:01 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll</div>
<div>2013-05-16 06:12 . 2012-12-16 17:11 46080 ----a-w- c:\windows\system32\atmlib.dll</div>
<div>2013-05-16 06:12 . 2012-12-16 14:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll</div>
<div>2013-05-16 06:12 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll</div>
<div>2013-05-16 06:12 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll</div>
<div>2013-05-16 06:12 . 2012-12-16 14:45 367616 ----a-w- c:\windows\system32\atmfd.dll</div>
<div>2013-05-16 06:12 . 2012-12-16 14:13 295424 ----a-w- c:\windows\SysWow64\atmfd.dll</div>
<div>2013-05-16 06:11 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys</div>
<div>2013-05-16 06:11 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys</div>
<div>2013-05-16 06:11 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll</div>
<div>2013-05-16 06:11 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll</div>
<div>2013-05-16 06:11 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe</div>
<div>2013-05-16 06:11 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll</div>
<div>2013-05-16 06:11 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll</div>
<div>2013-05-16 06:06 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys</div>
<div>2013-05-16 06:06 . 2012-03-01 06:33 81408 ----a-w- c:\windows\system32\imagehlp.dll</div>
<div>2013-05-16 06:06 . 2012-03-01 05:33 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll</div>
<div>2013-05-16 06:06 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll</div>
<div>2013-05-16 06:06 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll</div>
<div>2013-05-15 22:21 . 2012-12-07 11:19 51712 ----a-w- c:\windows\system32\esrb.rs</div>
<div>2013-05-15 22:21 . 2012-12-07 11:20 23552 ----a-w- c:\windows\system32\oflc.rs</div>
<div>2013-05-15 22:21 . 2012-12-07 11:20 20480 ----a-w- c:\windows\system32\pegi-fi.rs</div>
<div>2013-05-15 22:21 . 2012-12-07 11:19 55296 ----a-w- c:\windows\system32\cero.rs</div>
<div>2013-05-15 22:21 . 2012-12-07 10:46 23552 ----a-w- c:\windows\SysWow64\oflc.rs</div>
<div>2013-05-15 22:21 . 2012-12-07 10:46 20480 ----a-w- c:\windows\SysWow64\pegi-fi.rs</div>
<div>2013-05-15 22:21 . 2012-12-07 10:46 55296 ----a-w- c:\windows\SysWow64\cero.rs</div>
<div>2013-05-15 22:21 . 2012-12-07 10:46 51712 ----a-w- c:\windows\SysWow64\esrb.rs</div>
<div>2013-05-15 22:21 . 2012-11-09 05:45 2048 ----a-w- c:\windows\system32\tzres.dll</div>
<div>2013-05-15 22:21 . 2012-11-09 04:42 2048 ----a-w- c:\windows\SysWow64\tzres.dll</div>
<div>2013-05-15 22:20 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe</div>
<div>2013-05-15 22:20 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe</div>
<div>2013-05-15 22:20 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll</div>
<div>2013-05-15 22:20 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll</div>
<div>2013-05-15 22:20 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll</div>
<div>2013-05-15 22:20 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll</div>
<div>2013-05-15 22:20 . 2011-07-09 02:46 288768 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys</div>
<div>2013-05-15 22:20 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys</div>
<div>2013-05-15 22:20 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys</div>
<div>2013-05-15 22:19 . 2013-04-12 14:45 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys</div>
<div>2013-05-15 22:19 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys</div>
<div>2013-05-15 22:19 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll</div>
<div>2013-05-15 22:19 . 2012-04-26 05:41 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll</div>
<div>2013-05-15 22:19 . 2012-04-26 05:34 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe</div>
<div>2013-05-15 22:18 . 2012-05-01 05:40 209920 ----a-w- c:\windows\system32\profsvc.dll</div>
<div>2013-05-15 22:18 . 2010-11-20 13:27 33792 ----a-w- c:\windows\system32\profprov.dll</div>
<div>2013-05-15 22:18 . 2012-08-24 18:05 220160 ----a-w- c:\windows\system32\wintrust.dll</div>
<div>2013-05-15 22:18 . 2012-08-24 16:57 172544 ----a-w- c:\windows\SysWow64\wintrust.dll</div>
<div>2013-05-15 22:18 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys</div>
<div>2013-05-15 22:18 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys</div>
<div>2013-05-15 22:18 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys</div>
<div>2013-05-15 22:18 . 2012-04-07 12:31 3216384 ----a-w- c:\windows\system32\msi.dll</div>
<div>2013-05-15 22:18 . 2012-04-07 11:26 2342400 ----a-w- c:\windows\SysWow64\msi.dll</div>
<div>2013-05-15 22:07 . 2013-05-02 05:06 278800 ------w- c:\windows\system32\MpSigStub.exe</div>
<div>2013-05-15 21:49 . 2012-06-06 06:05 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll</div>
<div>2013-05-15 21:48 . 2011-03-11 05:33 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll</div>
<div>2013-05-15 21:47 . 2011-03-03 06:24 183296 ----a-w- c:\windows\system32\dnsrslvr.dll</div>
<div>2013-05-15 21:46 . 2013-01-04 05:46 215040 ----a-w- c:\windows\system32\winsrv.dll</div>
<div>2013-05-15 21:45 . 2012-11-30 05:41 424448 ----a-w- c:\windows\system32\KernelBase.dll</div>
<div>2013-05-15 21:32 . 2012-11-02 05:59 478208 ----a-w- c:\windows\system32\dpnet.dll</div>
<div>2013-05-15 21:32 . 2012-11-02 05:11 376832 ----a-w- c:\windows\SysWow64\dpnet.dll</div>
<div>2013-05-15 21:32 . 2010-11-20 12:58 3072 ----a-w- c:\windows\system32\dpnaddr.dll</div>
<div>2013-05-15 21:32 . 2010-11-20 11:57 2560 ----a-w- c:\windows\SysWow64\dpnaddr.dll</div>
<div>2013-05-15 21:28 . 2013-05-17 11:05 -------- d-----r- c:\program files (x86)\Skype</div>
<div>2013-05-15 21:28 . 2013-05-15 21:28 -------- d-----w- C:\f3dec307a6e534e344872b01</div>
<div>2013-05-15 21:28 . 2013-05-20 13:21 -------- d-----w- c:\program files (x86)\Iminent</div>
<div>2013-05-15 21:28 . 2013-05-20 12:42 -------- d-----w- c:\programdata\Tarma Installer</div>
<div>2013-05-15 21:26 . 2012-09-18 18:27 65024 ----a-w- c:\windows\system32\Spool\prtprocs\x64\PPhp1020.DLL</div>
<div>2013-05-15 21:24 . 2012-09-18 18:27 192512 ----a-w- c:\windows\system32\ZLhp1020.DLL</div>
<div>2013-05-15 21:24 . 2012-09-18 18:27 501760 ----a-w- c:\windows\system32\ZSHP1020.EXE</div>
<div>2013-05-15 21:24 . 2012-09-18 07:34 245248 ----a-w- c:\windows\system32\zshp1020s.dll</div>
<div>2013-05-15 21:24 . 2013-05-15 21:24 -------- d-----w- c:\program files\HP</div>
<div>2013-05-15 21:23 . 2013-05-17 21:00 -------- d-----w- c:\program files (x86)\Microsoft Works</div>
<div>2013-05-15 21:22 . 2013-05-15 21:50 -------- d-----w- c:\program files (x86)\Microsoft.NET</div>
<div>2013-05-15 21:22 . 2013-05-15 21:22 -------- d-----w- c:\windows\PCHEALTH</div>
<div>2013-05-15 21:22 . 2013-05-20 19:23 -------- d-----w- C:\DANFEView</div>
<div>2013-05-15 21:21 . 2013-05-15 21:21 -------- d-----w- c:\program files\CCleaner</div>
<div>2013-05-15 21:20 . 2013-05-15 21:20 -------- d-----w- C:\Unimake</div>
<div>2013-05-15 21:20 . 2013-05-15 21:31 4096000 ----a-w- c:\program files (x86)\GUT560C.tmp</div>
<div>2013-05-15 21:20 . 2013-05-15 21:20 -------- d-----w- c:\program files (x86)\GUM560B.tmp</div>
<div>2013-05-15 21:20 . 2013-05-09 08:59 378432 ----a-w- c:\windows\system32\drivers\aswSP.sys</div>
<div>2013-05-15 21:20 . 2013-05-09 08:59 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys</div>
<div>2013-05-15 21:20 . 2013-05-09 08:59 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys</div>
<div>2013-05-15 21:20 . 2013-05-09 08:59 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys</div>
<div>2013-05-15 21:20 . 2013-05-09 08:59 1025808 ----a-w- c:\windows\system32\drivers\aswSnx.sys</div>
<div>2013-05-15 21:20 . 2013-05-09 08:59 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys</div>
<div>2013-05-15 21:20 . 2013-05-09 08:59 189936 ----a-w- c:\windows\system32\drivers\aswVmm.sys</div>
<div>2013-05-15 21:20 . 2013-05-09 08:59 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys</div>
<div>2013-05-15 21:20 . 2013-05-09 08:58 287840 ----a-w- c:\windows\system32\aswBoot.exe</div>
<div>2013-05-15 21:17 . 2013-05-09 08:58 41664 ----a-w- c:\windows\avastSS.scr</div>
<div>2013-05-15 21:17 . 2013-05-15 21:17 -------- d-----w- c:\program files\AVAST Software</div>
<div>2013-05-15 21:17 . 2013-05-15 21:17 -------- d-----w- c:\program files\Microsoft Office</div>
<div>2013-05-15 21:17 . 2013-05-15 21:17 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8</div>
<div>2013-05-15 21:17 . 2013-05-20 12:41 -------- d-----w- c:\program files (x86)\Google</div>
<div>2013-05-15 21:16 . 2013-05-15 21:17 -------- d-----w- c:\programdata\AVAST Software</div>
<div>.</div>
<div>.</div>
<div>((((((((((((((((((((((((((((((((((((( &nbsp; Relatório Find3M &nbsp; ))))))))))))))))))))))))))))))))))))))))))))))))))))</div>
<div>.</div>
<div>2013-05-20 11:10 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll</div>
<div>2013-05-20 11:10 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll</div>
<div>.</div>
<div>.</div>
<div>(((((((((((((((((((((((((( &nbsp; Pontos de Carregamento do Registro &nbsp; )))))))))))))))))))))))))))))))))))))))</div>
<div>.</div>
<div>.</div>
<div>*Nota* entradas vazias e legítimas por padrão não são apresentadas.&nbsp;</div>
<div>REGEDIT4</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{26D50806-E012-4917-B895-46D1604CF213}]</div>
<div>.</div>
<div>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</div>
<div>"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-04-19 18678376]</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]</div>
<div>"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]</div>
<div>"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]</div>
<div>"ConsentPromptBehaviorAdmin"= 0 (0x0)</div>
<div>"ConsentPromptBehaviorUser"= 3 (0x3)</div>
<div>"EnableLUA"= 0 (0x0)</div>
<div>"EnableUIADesktopToggle"= 0 (0x0)</div>
<div>"PromptOnSecureDesktop"= 0 (0x0)</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]</div>
<div>2012-12-26 16:03 1652584 ----a-w- c:\program files (x86)\GbPlugin\gbiehcef.dll</div>
<div>.</div>
<div>R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\GbpKm.sys [x]</div>
<div>R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]</div>
<div>R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]</div>
<div>R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992]</div>
<div>R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]</div>
<div>R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]</div>
<div>R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]</div>
<div>R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]</div>
<div>R3 WatAdminSvc;Serviço de Tecnologias de Ativação do Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2013-05-16 1255736]</div>
<div>S0 aswRvrt;aswRvrt; [x]</div>
<div>S0 aswVmm;aswVmm; [x]</div>
<div>S1 aswSnx;aswSnx; [x]</div>
<div>S1 aswSP;aswSP; [x]</div>
<div>S2 aswFsBlk;aswFsBlk; [x]</div>
<div>S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-05-09 80816]</div>
<div>S2 GbpSv;Gbp Service;c:\progra~2\GbPlugin\GbpSv.exe [2012-12-26 527720]</div>
<div>S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]</div>
<div>.</div>
<div>.</div>
<div>--- =Outros Serviços/Drivers Na Memória ---</div>
<div>.</div>
<div>*NewlyCreated* - WUDFPF</div>
<div>.</div>
<div>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost &nbsp;- NetSvcs</div>
<div>NETSVCS PRECISA DE REPAROS - Entradas atuais mostradas</div>
<div>.</div>
<div>Rebuilding ... You need to reboot your machine for this to take effect.</div>
<div>.</div>
<div>AeLookupSvc</div>
<div>AppMgmt</div>
<div>AudioSrv</div>
<div>BITS</div>
<div>CertPropSvc</div>
<div>FastUserSwitchingCompatibility</div>
<div>gpsvc</div>
<div>helpsvc</div>
<div>Ias</div>
<div>iphlpsvc</div>
<div>Irmon</div>
<div>lanmanserver</div>
<div>LogonHours</div>
<div>msiscsi</div>
<div>Nla</div>
<div>Ntmssvc</div>
<div>NWCWorkstation</div>
<div>Nwsapagent</div>
<div>PCAudit</div>
<div>Rasauto</div>
<div>Rasman</div>
<div>Remoteaccess</div>
<div>schedule</div>
<div>SCPolicySvc</div>
<div>SENS</div>
<div>SessionEnv</div>
<div>Sharedaccess</div>
<div>ShellHWDetection</div>
<div>SRService</div>
<div>Tapisrv</div>
<div>TermService</div>
<div>uploadmgr</div>
<div>winmgmt</div>
<div>WmdmPmSp</div>
<div>Wmi</div>
<div>wuauserv</div>
<div>.</div>
<div>Conteúdo da pasta 'Tarefas Agendadas'</div>
<div>.</div>
<div>2013-05-20 c:\windows\Tasks\Adobe Flash Player Updater.job</div>
<div>- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-15 12:45]</div>
<div>.</div>
<div>.</div>
<div>--------- X64 Entries -----------</div>
<div>.</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]</div>
<div>@="{472083B0-C522-11CF-8763-00608CC02F24}"</div>
<div>[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]</div>
<div>2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll</div>
<div>.</div>
<div>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost &nbsp;- LocalService</div>
<div>FontCache</div>
<div>.</div>
<div>------- Scan Suplementar -------</div>
<div>.</div>
<div>uLocal Page = c:\windows\system32\blank.htm</div>
<div>mLocal Page = c:\windows\SysWOW64\blank.htm</div>
<div>IE: E&xportar para o Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000</div>
<div>Trusted Zone: caixa.gov.br\imagem</div>
<div>Trusted Zone: caixa.gov.br\internetbanking</div>
<div>Trusted Zone: caixa.gov.br\internetbankingpf</div>
<div>Trusted Zone: caixa.gov.br\www</div>
<div>TCP: Interfaces\{322DD4E5-B83F-4B97-9954-6270E300FFF5}: NameServer = 192.168.1.100,192.168.1.200</div>
<div>FF - ProfilePath - c:\users\carla\AppData\Roaming\Mozilla\Firefox\Profiles\3fyial6o.default\</div>
<div>FF - ExtSQL: 2013-05-20 11:41; {87F8774F-B485-47E2-A755-A40A8A5E8874}; c:\users\carla\AppData\Local\GAS Tecnologia\GBBD\abn\xpi</div>
<div>.</div>
<div>- - - - ORFÃOS REMOVIDOS - - - -</div>
<div>.</div>
<div>Wow6432Node-HKLM-Run-DANFEmon - c:\unimake\UniNFe\danfemon.exe</div>
<div>Wow6432Node-HKLM-Run-DANFEViewMon - c:\danfeview\danfemon.exe</div>
<div>Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe</div>
<div>WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)</div>
<div>AddRemove-{83033d93-48d0-48fc-9c5b-82e57e7e0dd6}_is1 - c:\users\carla\AppData\Roaming\unins000.exe</div>
<div>.</div>
<div>.</div>
<div>.</div>
<div>--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]</div>
<div>@Denied: (A 2) (Everyone)</div>
<div>@="FlashBroker"</div>
<div>"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]</div>
<div>"Enabled"=dword:00000001</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]</div>
<div>@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]</div>
<div>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]</div>
<div>@Denied: (A 2) (Everyone)</div>
<div>@="IFlashBroker5"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]</div>
<div>@="{00020424-0000-0000-C000-000000000046}"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]</div>
<div>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"</div>
<div>"Version"="1.0"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]</div>
<div>@Denied: (A 2) (Everyone)</div>
<div>@="FlashBroker"</div>
<div>"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]</div>
<div>"Enabled"=dword:00000001</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]</div>
<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]</div>
<div>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]</div>
<div>@Denied: (A 2) (Everyone)</div>
<div>@="Shockwave Flash Object"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]</div>
<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"</div>
<div>"ThreadingModel"="Apartment"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]</div>
<div>@="0"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]</div>
<div>@="ShockwaveFlash.ShockwaveFlash.11"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]</div>
<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]</div>
<div>@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]</div>
<div>@="1.0"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]</div>
<div>@="ShockwaveFlash.ShockwaveFlash"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]</div>
<div>@Denied: (A 2) (Everyone)</div>
<div>@="Macromedia Flash Factory Object"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]</div>
<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"</div>
<div>"ThreadingModel"="Apartment"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]</div>
<div>@="FlashFactory.FlashFactory.1"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]</div>
<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]</div>
<div>@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]</div>
<div>@="1.0"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]</div>
<div>@="FlashFactory.FlashFactory"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]</div>
<div>@Denied: (A 2) (Everyone)</div>
<div>@="IFlashBroker5"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]</div>
<div>@="{00020424-0000-0000-C000-000000000046}"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]</div>
<div>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"</div>
<div>"Version"="1.0"</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]</div>
<div>@Denied: (Full) (Everyone)</div>
<div>.</div>
<div>Tempo para conclusão: 2013-05-20 &nbsp;16:26:54</div>
<div>ComboFix-quarantined-files.txt &nbsp;2013-05-20 19:26</div>
<div>.</div>
<div>Pré-execução: 462.286.753.792 bytes disponíveis</div>
<div>Pós execução: 462.013.050.880 bytes disponíveis</div>
<div>.</div>
<div>- - End Of File - - C32CDF545C1926BC86DF20FC2546E6CE</div>
<div>&nbsp;</div>
]]></description>
		<pubDate>Mon, 20 May 2013 19:29:54 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767215-análise-de-log-combofix/</guid>
	</item>
	<item>
		<title>Análise de log</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767209-análise-de-log/</link>
		<description><![CDATA[<div>Logfile of Trend Micro HijackThis v2.0.4</div>
<div>Scan saved at 09:54:55, on 20/05/2013</div>
<div>Platform: Windows 7 SP1 (WinNT 6.00.3505)</div>
<div>MSIE: Internet Explorer v9.00 (9.00.8112.16448)</div>
<div>Boot mode: Normal</div>
<div>&nbsp;</div>
<div>Running processes:</div>
<div>C:\Windows\system32\Dwm.exe</div>
<div>C:\Windows\Explorer.EXE</div>
<div>C:\Windows\system32\taskhost.exe</div>
<div>C:\Program Files\Synaptics\SynTP\SynTPEnh.exe</div>
<div>C:\Program Files\BisonCam\BisonHK.exe</div>
<div>C:\Program Files\Nero\Tools\InCD\NBHGui.exe</div>
<div>C:\Program Files\Nero\Tools\InCD\InCD.exe</div>
<div>C:\Program Files\Microsoft Security Client\msseces.exe</div>
<div>C:\Program Files\HP\HP Software Update\hpwuschd2.exe</div>
<div>C:\Program Files\Nike\Nike+ Connect\Nike+ Connect daemon.exe</div>
<div>C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe</div>
<div>C:\Program Files\Samsung\Kies\KiesTrayAgent.exe</div>
<div>C:\Program Files\Real\RealPlayer\Update\realsched.exe</div>
<div>C:\Program Files\Common Files\Java\Java Update\jusched.exe</div>
<div>C:\Program Files\Iminent\Iminent.exe</div>
<div>C:\Program Files\Iminent\Iminent.Messengers.exe</div>
<div>C:\Program Files\Ares\Ares.exe</div>
<div>C:\Users\Richart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe</div>
<div>C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe</div>
<div>C:\Program Files\Samsung\Kies\Kies.exe</div>
<div>C:\Program Files\Samsung\Kies\KiesAirMessage.exe</div>
<div>C:\Program Files\Google\Drive\googledrivesync.exe</div>
<div>C:\Users\Richart\AppData\Roaming\Yontoo\YontooDesktop.exe</div>
<div>C:\Program Files\Desk 365\desk365.exe</div>
<div>C:\Users\Richart\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe</div>
<div>C:\Program Files\Google\Drive\googledrivesync.exe</div>
<div>C:\Windows\system32\wuauclt.exe</div>
<div>C:\Windows\system32\taskeng.exe</div>
<div>C:\Users\Richart\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Richart\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Richart\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Richart\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Richart\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Richart\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Richart\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Richart\AppData\Local\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Richart\Desktop\HijackThis.exe</div>
<div>&nbsp;</div>
<div>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://www.portaldosites.com/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=1368990125' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.portaldosites.com/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=1368990125</a></div>
<div>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://www.portaldosites.com/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=1368990125' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.portaldosites.com/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=1368990125</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://www.portaldosites.com/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=1368990125' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.portaldosites.com/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=1368990125</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://www.portaldosites.com/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=1368990125' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.portaldosites.com/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=1368990125</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = <a href='http://search.portaldosites.com/web/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=0' class='bbc_url' title='Link Externo' rel='nofollow external'>http://search.portaldosites.com/web/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=0</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = <a href='http://search.portaldosites.com/web/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=0' class='bbc_url' title='Link Externo' rel='nofollow external'>http://search.portaldosites.com/web/?utm_source=b&utm_medium=smt&from=smt&uid=SAMSUNGXHM160HI_S1C6J56Z437486&ts=0</a></div>
<div>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =&nbsp;</div>
<div>O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll</div>
<div>O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll</div>
<div>O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll</div>
<div>O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll</div>
<div>O2 - BHO: IMinent WebBooster - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files\Iminent\Iminent.WebBooster.InternetExplorer.dll</div>
<div>O2 - BHO: DealPly Shopping - {a6c63b7f-2171-47fa-ab34-e64c4737169d} - C:\Program Files\DealPly\DealPlyIE.dll</div>
<div>O2 - BHO: Wajam IE BHO - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll</div>
<div>O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll</div>
<div>O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll</div>
<div>O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe</div>
<div>O4 - HKLM\..\Run: [BisonHK] C:\Program Files\BisonCam\BisonHK.exe</div>
<div>O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"</div>
<div>O4 - HKLM\..\Run: [NBHGui] C:\Program Files\Nero\Tools\InCD\NBHGui.exe</div>
<div>O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Tools\InCD\InCD.exe</div>
<div>O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey</div>
<div>O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe</div>
<div>O4 - HKLM\..\Run: [Nike+ Connect] "C:\Program Files\Nike\Nike+ Connect\Nike+ Connect daemon.exe"</div>
<div>O4 - HKLM\..\Run: [USBToolTip] C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe</div>
<div>O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe</div>
<div>O4 - HKLM\..\Run: [TkBellExe] "c:\program files\real\realplayer\Update\realsched.exe" -osboot</div>
<div>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"</div>
<div>O4 - HKLM\..\Run: [Iminent] C:\Program Files\Iminent\Iminent.exe /warmup "F77F87E5-A6BD-4922-A530-EDF63D7E9F8C"</div>
<div>O4 - HKLM\..\Run: [IminentMessenger] C:\Program Files\Iminent\Iminent.Messengers.exe</div>
<div>O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h</div>
<div>O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Richart\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver</div>
<div>O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Users\Richart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun</div>
<div>O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe -tray</div>
<div>O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background</div>
<div>O4 - HKCU\..\Run: [Google Update] "C:\Users\Richart\AppData\Local\Google\Update\GoogleUpdate.exe" /c</div>
<div>O4 - HKCU\..\Run: [KiesPreload] C:\Program Files\Samsung\Kies\Kies.exe /preload</div>
<div>O4 - HKCU\..\Run: [KiesAirMessage] C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup</div>
<div>O4 - HKCU\..\Run: [] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe</div>
<div>O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart</div>
<div>O4 - HKCU\..\Run: [Yontoo Desktop] "C:\Users\Richart\AppData\Roaming\Yontoo\YontooDesktop.exe"</div>
<div>O4 - HKCU\..\Run: [Desk 365] "C:\Program Files\Desk 365\desk365.exe" /autorun</div>
<div>O4 - Startup: Facebook Messenger.lnk = C:\Users\Richart\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe</div>
<div>O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200</div>
<div>O8 - Extra context menu item: Baixar com Mipony - file://C:\Program Files\MiPony\Browser\IEContext.htm</div>
<div>O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll</div>
<div>O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll</div>
<div>O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll</div>
<div>O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll</div>
<div>O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll</div>
<div>O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics</div>
<div>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href='http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a></div>
<div>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL</div>
<div>O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll</div>
<div>O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe</div>
<div>O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe</div>
<div>O23 - Service: Desk 365 service (desksvc) - 337 Technology Limited. - C:\Program Files\Desk 365\deskSvc.exe</div>
<div>O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe</div>
<div>O23 - Service: InCD Helper (InCDSrv) - Nero AG - C:\Program Files\Nero\Tools\InCD\InCDSrv.exe</div>
<div>O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe</div>
<div>O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe</div>
<div>O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Tools\InCD\NBHRegInCDSrv.exe</div>
<div>O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe</div>
<div>O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe</div>
<div>O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe</div>
<div>O23 - Service: SProtection - Iminent - C:\Program Files\Common Files\Umbrella\umbrella.exe</div>
<div>O23 - Service: WajamUpdater - Wajam - C:\Program Files\Wajam\Updater\WajamUpdater.exe</div>
<div>&nbsp;</div>
<div>--</div>
<div>End of file - 10713 bytes</div>
<div>&nbsp;</div>]]></description>
		<pubDate>Mon, 20 May 2013 12:56:13 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767209-análise-de-log/</guid>
	</item>
	<item>
		<title>Analise de Log</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767207-analise-de-log/</link>
		<description><![CDATA[<p>Mais uma vez venho pedi auxílio para limpar uma máquina,&nbsp;</p>
<p>Segue abaixo o logo do HijackThis</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div>Logfile of Trend Micro HijackThis v2.0.4</div>
<div>Scan saved at 00:01:36, on 20/5/2013</div>
<div>Platform: Windows XP SP2 (WinNT 5.01.2600)</div>
<div>MSIE: Internet Explorer v7.00 (7.00.6000.20627)</div>
<div>Boot mode: Normal</div>
<div>&nbsp;</div>
<div>Running processes:</div>
<div>C:\WXP\System32\smss.exe</div>
<div>C:\WXP\system32\csrss.exe</div>
<div>C:\WXP\system32\winlogon.exe</div>
<div>C:\WXP\system32\services.exe</div>
<div>C:\WXP\system32\lsass.exe</div>
<div>C:\ARQUIV~1\GbPlugin\GbpSv.exe</div>
<div>C:\WXP\system32\svchost.exe</div>
<div>C:\WXP\system32\svchost.exe</div>
<div>C:\WXP\System32\svchost.exe</div>
<div>C:\WXP\system32\svchost.exe</div>
<div>C:\WXP\system32\svchost.exe</div>
<div>C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe</div>
<div>C:\WXP\System32\svchost.exe</div>
<div>C:\WXP\system32\spoolsv.exe</div>
<div>C:\WXP\System32\SCardSvr.exe</div>
<div>C:\Arquivos de programas\Application Updater\ApplicationUpdater.exe</div>
<div>C:\WXP\system32\svchost.exe</div>
<div>C:\Arquivos de programas\Java\jre7\bin\jqs.exe</div>
<div>C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamscheduler.exe</div>
<div>C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe</div>
<div>C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE</div>
<div>C:\WXP\System32\svchost.exe</div>
<div>C:\WXP\System32\svchost.exe</div>
<div>C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamgui.exe</div>
<div>C:\Arquivos de programas\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe</div>
<div>C:\WXP\Explorer.EXE</div>
<div>C:\Documents and Settings\All Users\Dados de aplicativos\Skype\Toolbars\Skype C2C Service\c2c_service.exe</div>
<div>C:\WXP\system32\svchost.exe</div>
<div>C:\WXP\system32\wdfmgr.exe</div>
<div>C:\WXP\system32\svchost.exe</div>
<div>C:\WXP\system32\wscntfy.exe</div>
<div>C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe</div>
<div>C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe</div>
<div>C:\Arquivos de programas\TOPRO\TP6810\TPPOLL10.EXE</div>
<div>C:\WXP\system32\hkcmd.exe</div>
<div>C:\WXP\System32\alg.exe</div>
<div>C:\WXP\system32\igfxpers.exe</div>
<div>C:\WXP\system32\igfxsrvc.exe</div>
<div>C:\Arquivos de programas\VIA\VIAudioi\HDADeck\HDeck.exe</div>
<div>C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe</div>
<div>C:\Arquivos de programas\Arquivos comuns\Spigot\Search Settings\SearchSettings.exe</div>
<div>C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe</div>
<div>C:\Documents and Settings\Mycomp\Configurações locais\Dados de aplicativos\Facebook\Update\FacebookUpdate.exe</div>
<div>C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe</div>
<div>C:\Arquivos de programas\BrOffice.org 3\program\soffice.exe</div>
<div>C:\Arquivos de programas\BrOffice.org 3\program\soffice.bin</div>
<div>C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe</div>
<div>C:\WXP\system32\ctfmon.exe</div>
<div>C:\Documents and Settings\Mycomp\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe</div>
<div>C:\Documents and Settings\Mycomp\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe</div>
<div>C:\Arquivos de programas\Skype\Phone\Skype.exe</div>
<div>C:\Documents and Settings\Mycomp\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe</div>
<div>C:\Documents and Settings\Mycomp\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe</div>
<div>C:\Documents and Settings\Mycomp\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe</div>
<div>C:\Documents and Settings\Mycomp\Configurações locais\Dados de aplicativos\Google\Chrome\Application\chrome.exe</div>
<div>C:\Arquivos de programas\TeamViewer\Version7\TeamViewer.exe</div>
<div>C:\Arquivos de programas\TeamViewer\Version7\tv_w32.exe</div>
<div>c:\arquivos de programas\teamviewer\version7\TeamViewer_Desktop.exe</div>
<div>C:\WXP\system32\notepad.exe</div>
<div>E:\Documents and Settings\Mycomp\Meus documentos\Downloads\HijackThis.exe</div>
<div>C:\WXP\system32\wbem\wmiprvse.exe</div>
<div>&nbsp;</div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = <a href='http://farejador.ig.com.br/ie/' class='bbc_url' title='Link Externo' rel='nofollow external'>http://farejador.ig.com.br/ie/</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a></div>
<div>R3 - URLSearchHook: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Arquivos de programas\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll</div>
<div>R3 - URLSearchHook: uTorrentBar_PT Toolbar - {e0301295-ab3e-4af3-979f-3d453c5f9f48} - C:\Arquivos de programas\uTorrentBar_PT\prxtbuTo2.dll</div>
<div>O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_printenhancer.dll</div>
<div>O2 - BHO: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Arquivos de programas\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll</div>
<div>O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_framework.dll</div>
<div>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll</div>
<div>O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)</div>
<div>O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Arquivos de programas\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll</div>
<div>O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre7\bin\ssv.dll</div>
<div>O2 - BHO: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll</div>
<div>O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\AVAST Software\Avast\aswWebRepIE.dll</div>
<div>O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll</div>
<div>O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll</div>
<div>O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\ARQUIVOS DE PROGRAMAS\GBPLUGIN\gbieh.dll</div>
<div>O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre7\bin\jp2ssv.dll</div>
<div>O2 - BHO: uTorrentBar_PT - {e0301295-ab3e-4af3-979f-3d453c5f9f48} - C:\Arquivos de programas\uTorrentBar_PT\prxtbuTo2.dll</div>
<div>O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll</div>
<div>O3 - Toolbar: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll</div>
<div>O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Arquivos de programas\AVAST Software\Avast\aswWebRepIE.dll</div>
<div>O3 - Toolbar: uTorrentBar_PT Toolbar - {e0301295-ab3e-4af3-979f-3d453c5f9f48} - C:\Arquivos de programas\uTorrentBar_PT\prxtbuTo2.dll</div>
<div>O3 - Toolbar: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Arquivos de programas\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll</div>
<div>O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Arquivos de programas\Windows Live\Toolbar\wltcore.dll</div>
<div>O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe</div>
<div>O4 - HKLM\..\Run: [SMSERIAL] C:\Arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe</div>
<div>O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe</div>
<div>O4 - HKLM\..\Run: [TPPOLL10] C:\Arquivos de programas\TOPRO\TP6810\TPPOLL10.EXE</div>
<div>O4 - HKLM\..\Run: [IgfxTray] C:\WXP\system32\igfxtray.exe</div>
<div>O4 - HKLM\..\Run: [HotKeysCmds] C:\WXP\system32\hkcmd.exe</div>
<div>O4 - HKLM\..\Run: [Persistence] C:\WXP\system32\igfxpers.exe</div>
<div>O4 - HKLM\..\Run: [HDAudDeck] C:\Arquivos de programas\VIA\VIAudioi\HDADeck\HDeck.exe 1</div>
<div>O4 - HKLM\..\Run: [avast] "C:\Arquivos de programas\AVAST Software\Avast\avastUI.exe" /nogui</div>
<div>O4 - HKLM\..\Run: [SearchSettings] "C:\Arquivos de programas\Arquivos comuns\Spigot\Search Settings\SearchSettings.exe"</div>
<div>O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"</div>
<div>O4 - HKLM\..\Run: [APSDaemon] "C:\Arquivos de programas\Arquivos comuns\Apple\Apple Application Support\APSDaemon.exe"</div>
<div>O4 - HKLM\..\Run: [QuickTime Task] "E:\Arquivos de programas\K-Lite Codec Pack\QuickTime\QTTask.exe" -atboottime</div>
<div>O4 - HKCU\..\Run: [uTorrent] "E:\Documents and Settings\Mycomp\Meus documentos\Downloads\uTorrent.exe" &nbsp;/MINIMIZED</div>
<div>O4 - HKCU\..\Run: [Facebook Update] "C:\Documents and Settings\Mycomp\Configurações locais\Dados de aplicativos\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver</div>
<div>O4 - HKCU\..\Run: [ctfmon.exe] C:\WXP\system32\ctfmon.exe</div>
<div>O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')</div>
<div>O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')</div>
<div>O4 - Startup: BrOffice.org 3.2.lnk = C:\Arquivos de programas\BrOffice.org 3\program\quickstart.exe</div>
<div>O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe</div>
<div>O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe</div>
<div>O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000</div>
<div>O9 - Extra button: Livro de recortes HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll</div>
<div>O9 - Extra button: Seleção HP Smart - {700259D7-1666-479a-93B1-3250410481E8} - C:\Arquivos de programas\HP\Smart Web Printing\hpswp_extensions.dll</div>
<div>O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll</div>
<div>O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL</div>
<div>O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WXP\Network Diagnostic\xpnetdiag.exe</div>
<div>O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WXP\Network Diagnostic\xpnetdiag.exe</div>
<div>O9 - Extra button: Barra do iG - {FD1672E0-AE0D-465B-B345-F7B0944A121D} - C:\ARQUIV~1\iGv6\igshop.dll</div>
<div>O10 - Unknown file in Winsock LSP: c:\wxp\system32\nwprovau.dll</div>
<div>O14 - IERESET.INF: SEARCH_PAGE_URL=&<a href='http://home.microsoft.com/intl/br/access/allinone.asp' class='bbc_url' title='Link Externo' rel='nofollow external'>http://home.microsoft.com/intl/br/access/allinone.asp</a></div>
<div>O15 - Trusted Zone: www.bancobrasil.com.br</div>
<div>O15 - Trusted Zone: www14.bancobrasil.com.br</div>
<div>O15 - Trusted Zone: www2.bancobrasil.com.br</div>
<div>O15 - Trusted Zone: www.bb.com.br</div>
<div>O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - <a href='http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a></div>
<div>O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\skypeieplugin.dll</div>
<div>O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL</div>
<div>O20 - Winlogon Notify: &nbsp;GbPluginBb - C:\Arquivos de programas\GbPlugin\gbieh.dll</div>
<div>O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WXP\system32\browseui.dll</div>
<div>O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WXP\system32\browseui.dll</div>
<div>O23 - Service: Application Updater - Spigot, Inc. - C:\Arquivos de programas\Application Updater\ApplicationUpdater.exe</div>
<div>O23 - Service: avast! antivírus - AVAST Software - C:\Arquivos de programas\AVAST Software\Avast\AvastSvc.exe</div>
<div>O23 - Service: Gbp Service (GbpSv) - &nbsp; - C:\ARQUIV~1\GbPlugin\GbpSv.exe</div>
<div>O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\1050\Intel 32\IDriverT.exe</div>
<div>O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Arquivos de programas\Java\jre7\bin\jqs.exe</div>
<div>O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamscheduler.exe</div>
<div>O23 - Service: MBAMService - Malwarebytes Corporation - C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe</div>
<div>O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe</div>
<div>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WXP\system32\nvsvc32.exe</div>
<div>O23 - Service: Prime95 Service - Unknown owner - C:\DOCUME~1\Mycomp\CONFIG~1\Temp\Rar$EX00.891\prime95.exe (file missing)</div>
<div>O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Dados de aplicativos\Skype\Toolbars\Skype C2C Service\c2c_service.exe</div>
<div>O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Arquivos de programas\Skype\Updater\Updater.exe</div>
<div>&nbsp;</div>
<div>--</div>
<div>End of file - 12955 bytes</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>Segue abaixo o log do combofix</div>
<div>&nbsp;</div>
<div><br />
<div>ComboFix 13-05-18.04 - Mycomp 19/05/2013 &nbsp;23:32:13.1.2 - x86</div>
<div>Microsoft Windows XP Professional &nbsp;5.1.2600.2.1252.55.1046.18.2013.890 [GMT -3:00]</div>
<div>Executando de: e:\documents and settings\Mycomp\Meus documentos\Downloads\ComboFix.exe</div>
<div>AV: avast! antivírus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}</div>
<div>FW: avast! antivírus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}</div>
<div>.</div>
<div><em class='bbc'> ADS - system32: deleted 2 bytes in 1 streams. </em></div>
<div><em class='bbc'> ADS - drivers: deleted 216 bytes in 2 streams. </em></div>
<div>.</div>
<div>((((((((((((((((((((((((((((((((((((( &nbsp; Outras Exclusões &nbsp; )))))))))))))))))))))))))))))))))))))))))))))))))))</div>
<div>.</div>
<div>.</div>
<div>c:\arquivos de programas\DealPly</div>
<div>c:\arquivos de programas\DealPly\DealPly.crx</div>
<div>c:\arquivos de programas\DealPly\DealPly.xpi</div>
<div>c:\arquivos de programas\DealPly\DealPlyIE.dll</div>
<div>c:\arquivos de programas\DealPly\DealPlyUpdate.exe</div>
<div>c:\arquivos de programas\DealPly\DealPlyUpdateRun.exe</div>
<div>c:\arquivos de programas\DealPly\icon.ico</div>
<div>c:\arquivos de programas\DealPly\uninst.exe</div>
<div>c:\documents and settings\All Users\Dados de aplicativos\TEMP</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\Google\Update\1</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\Google\Update\1\SD\m.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\Google\Update\1\SD\s.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\1.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\2355.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\a.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\b.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\c.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\d.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\e.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\f.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\g.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\h.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\i.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\j.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\k.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\l.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\m.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\mru.xml</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\n.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\o.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\p.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\q.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\r.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\s.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\t.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\u.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\v.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\w.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\wlu.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\x.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\y.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\PriceGong\Data\z.txt</div>
<div>c:\documents and settings\Mycomp\Dados de aplicativos\Toolbar4</div>
<div>c:\documents and settings\Mycomp\WINDOWS</div>
<div>c:\wxp\IsUn0416.exe</div>
<div>c:\wxp\system32\AutoRun.inf</div>
<div>c:\wxp\system32\drivers\ctl_w32.sys</div>
<div>c:\wxp\system32\drivers\mgcscrd.sys</div>
<div>c:\wxp\system32\drivers\msliksurserv.sys</div>
<div>c:\wxp\system32\drivers\parport32.sys</div>
<div>c:\wxp\system32\drivers\str.sys</div>
<div>c:\wxp\system32\URTTemp</div>
<div>c:\wxp\system32\URTTemp\fusion.dll</div>
<div>c:\wxp\system32\URTTemp\mscoree.dll</div>
<div>c:\wxp\system32\URTTemp\mscoree.dll.local</div>
<div>c:\wxp\system32\URTTemp\mscorsn.dll</div>
<div>c:\wxp\system32\URTTemp\mscorwks.dll</div>
<div>c:\wxp\system32\URTTemp\msvcr71.dll</div>
<div>.</div>
<div>.</div>
<div>(((((((((((((((( &nbsp; Arquivos/Ficheiros criados de 2013-04-20 to 2013-05-20 &nbsp;))))))))))))))))))))))))))))</div>
<div>.</div>
<div>.</div>
<div>2013-05-20 02:35 . 2013-05-20 02:35 0 ----a-w- c:\wxp\system32\drivers\seneka.sys</div>
<div>2013-05-20 02:05 . 2013-05-20 02:05 414368 ----a-w- c:\wxp\system32\FlashPlayerCPLApp.cpl</div>
<div>2013-05-19 21:29 . 2013-05-19 21:29 -------- d-----w- c:\documents and settings\Mycomp\Dados de aplicativos\Malwarebytes</div>
<div>2013-05-19 21:29 . 2013-05-19 21:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes</div>
<div>2013-05-19 21:29 . 2013-04-04 17:50 22856 ----a-w- c:\wxp\system32\drivers\mbam.sys</div>
<div>2013-05-19 21:29 . 2013-05-19 21:29 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware</div>
<div>2013-05-19 20:27 . 2013-05-19 20:27 159744 ----a-w- c:\arquivos de programas\Internet Explorer\PLUGINS\npqtplugin5.dll</div>
<div>2013-05-19 20:27 . 2013-05-19 20:27 159744 ----a-w- c:\arquivos de programas\Internet Explorer\PLUGINS\npqtplugin4.dll</div>
<div>2013-05-19 20:27 . 2013-05-19 20:27 159744 ----a-w- c:\arquivos de programas\Internet Explorer\PLUGINS\npqtplugin3.dll</div>
<div>2013-05-19 20:27 . 2013-05-19 20:27 159744 ----a-w- c:\arquivos de programas\Internet Explorer\PLUGINS\npqtplugin2.dll</div>
<div>2013-05-19 20:27 . 2013-05-19 20:27 159744 ----a-w- c:\arquivos de programas\Internet Explorer\PLUGINS\npqtplugin.dll</div>
<div>2013-05-19 20:25 . 2013-05-19 20:25 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Apple</div>
<div>2013-05-19 20:25 . 2013-05-19 20:25 -------- d-----w- c:\documents and settings\Mycomp\Configurações locais\Dados de aplicativos\Apple</div>
<div>2013-05-19 20:25 . 2013-05-19 20:25 -------- d-----w- c:\arquivos de programas\Apple Software Update</div>
<div>2013-05-19 20:25 . 2013-05-19 20:25 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Apple</div>
<div>2013-05-19 20:25 . 2013-05-19 20:25 -------- d-----w- c:\documents and settings\Mycomp\Configurações locais\Dados de aplicativos\Apple Computer</div>
<div>2013-05-19 19:57 . 2013-05-19 19:58 -------- d-----w- c:\arquivos de programas\CCleaner</div>
<div>2013-05-19 19:33 . 2013-05-19 19:33 -------- d-----w- c:\wxp\system32\wbem\Repository</div>
<div>2013-05-16 18:02 . 2013-05-16 18:03 -------- d-----w- c:\arquivos de programas\GUM247.tmp</div>
<div>2013-05-14 17:58 . 2013-05-09 08:59 21576 ----a-w- c:\wxp\system32\drivers\aswKbd.sys</div>
<div>2013-05-08 19:23 . 2013-04-04 08:35 94112 ----a-w- c:\wxp\system32\WindowsAccessBridge.dll</div>
<div>2013-04-25 03:49 . 2013-04-25 03:49 -------- d-----w- c:\arquivos de programas\Microsoft Sync Framework</div>
<div>2013-04-25 03:46 . 2013-04-25 03:46 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Skype</div>
<div>2013-04-25 03:45 . 2013-04-25 03:49 -------- d-----w- c:\arquivos de programas\Windows Live</div>
<div>2013-04-25 03:37 . 2013-04-25 03:37 -------- d-----w- c:\arquivos de programas\Microsoft Silverlight</div>
<div>2013-04-25 03:35 . 2010-04-16 22:16 4927864 ----a-w- c:\arquivos de programas\Arquivos comuns\Windows Live\.cache\e50eda421ce4165\Silverlight.2.0.exe</div>
<div>2013-04-25 03:25 . 2013-05-17 01:24 -------- d-----r- c:\arquivos de programas\Skype</div>
<div>2013-04-25 02:50 . 2013-04-25 02:50 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\DAEMON Tools Lite</div>
<div>.</div>
<div>.</div>
<div>.</div>
<div>((((((((((((((((((((((((((((((((((((( &nbsp; Relatório Find3M &nbsp; ))))))))))))))))))))))))))))))))))))))))))))))))))))</div>
<div>.</div>
<div>2013-05-09 08:59 . 2013-03-06 18:53 174664 ----a-w- c:\wxp\system32\drivers\aswVmm.sys</div>
<div>2013-05-09 08:59 . 2013-03-06 18:53 49376 ----a-w- c:\wxp\system32\drivers\aswRvrt.sys</div>
<div>2013-05-09 08:59 . 2011-10-08 03:18 368944 ----a-w- c:\wxp\system32\drivers\aswSP.sys</div>
<div>2013-05-09 08:59 . 2011-10-08 03:18 56080 ----a-w- c:\wxp\system32\drivers\aswTdi.sys</div>
<div>2013-05-09 08:59 . 2011-10-08 03:18 765736 ----a-w- c:\wxp\system32\drivers\aswSnx.sys</div>
<div>2013-05-09 08:59 . 2013-03-06 18:53 66336 ----a-w- c:\wxp\system32\drivers\aswMonFlt.sys</div>
<div>2013-05-09 08:59 . 2011-10-08 03:18 49760 ----a-w- c:\wxp\system32\drivers\aswRdr.sys</div>
<div>2013-05-09 08:59 . 2011-10-08 03:18 29816 ----a-w- c:\wxp\system32\drivers\aswFsBlk.sys</div>
<div>2013-05-09 08:58 . 2011-10-08 03:18 41664 ----a-w- c:\wxp\avastSS.scr</div>
<div>2013-05-09 08:58 . 2011-10-08 03:18 229648 ----a-w- c:\wxp\system32\aswBoot.exe</div>
<div>2013-05-08 19:15 . 2012-04-12 17:40 73728 ----a-w- c:\wxp\system32\javacpl.cpl</div>
<div>2013-03-06 23:50 . 2012-10-21 00:40 861088 ----a-w- c:\wxp\system32\npDeployJava1.dll</div>
<div>2013-03-06 23:50 . 2012-10-21 00:40 782240 -c--a-w- c:\wxp\system32\deployJava1.dll</div>
<div>.</div>
<div>.</div>
<div>------- Sigcheck -------</div>
<div>Note: Unsigned files aren't necessarily malware.</div>
<div>.</div>
<div>[-] 2007-07-21 21:40 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\wxp\system32\drivers\atapi.sys</div>
<div>.</div>
<div>[-] 2007-09-03 . BD8686216E34E22C4ED45A2320B2BEA1 . 360576 . . [5.1.2600.2892] . . c:\wxp\system32\drivers\tcpip.sys</div>
<div>[7] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\wxp\$hf_mig$\KB917953\SP2QFE\tcpip.sys</div>
<div>.</div>
<div>[-] 2007-09-02 . DB3AA410ED1228B9DF98C06549AE0763 . 1548288 . . [5.1.2600.2180] . . c:\wxp\system32\sfcfiles.dll</div>
<div>.</div>
<div>(((((((((((((((((((((((((( &nbsp; Pontos de Carregamento do Registro &nbsp; )))))))))))))))))))))))))))))))))))))))</div>
<div>.</div>
<div>.</div>
<div>*Nota* entradas vazias e legítimas por padrão não são apresentadas.&nbsp;</div>
<div>REGEDIT4</div>
<div>.</div>
<div>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]</div>
<div>"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\arquivos de programas\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll" [2013-02-23 1352512]</div>
<div>"{e0301295-ab3e-4af3-979f-3d453c5f9f48}"= "c:\arquivos de programas\uTorrentBar_PT\prxtbuTo2.dll" [2013-03-05 231168]</div>
<div>.</div>
<div>[HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]</div>
<div>.</div>
<div>[HKEY_CLASSES_ROOT\clsid\{e0301295-ab3e-4af3-979f-3d453c5f9f48}]</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]</div>
<div>2013-02-23 22:17 1352512 ----a-w- c:\arquivos de programas\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{e0301295-ab3e-4af3-979f-3d453c5f9f48}]</div>
<div>2013-03-05 13:37 231168 ----a-w- c:\arquivos de programas\uTorrentBar_PT\prxtbuTo2.dll</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]</div>
<div>"{e0301295-ab3e-4af3-979f-3d453c5f9f48}"= "c:\arquivos de programas\uTorrentBar_PT\prxtbuTo2.dll" [2013-03-05 231168]</div>
<div>"{03EB0E9C-7A91-4381-A220-9B52B641CDB1}"= "c:\arquivos de programas\IObit Apps Toolbar\IE\7.0\iobitappsToolbarIE.dll" [2013-02-23 1352512]</div>
<div>.</div>
<div>[HKEY_CLASSES_ROOT\clsid\{e0301295-ab3e-4af3-979f-3d453c5f9f48}]</div>
<div>.</div>
<div>[HKEY_CLASSES_ROOT\clsid\{03eb0e9c-7a91-4381-a220-9b52b641cdb1}]</div>
<div>.</div>
<div>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]</div>
<div>"{E0301295-AB3E-4AF3-979F-3D453C5F9F48}"= "c:\arquivos de programas\uTorrentBar_PT\prxtbuTo2.dll" [2013-03-05 231168]</div>
<div>.</div>
<div>[HKEY_CLASSES_ROOT\clsid\{e0301295-ab3e-4af3-979f-3d453c5f9f48}]</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]</div>
<div>@="{472083B0-C522-11CF-8763-00608CC02F24}"</div>
<div>[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]</div>
<div>2013-05-09 08:58 121968 ----a-w- c:\arquivos de programas\AVAST Software\Avast\ashShell.dll</div>
<div>.</div>
<div>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</div>
<div>"uTorrent"="e:\documents and settings\Mycomp\Meus documentos\Downloads\uTorrent.exe" [2013-05-03 802136]</div>
<div>"Facebook Update"="c:\documents and settings\Mycomp\Configurações locais\Dados de aplicativos\Facebook\Update\FacebookUpdate.exe" [2012-11-11 138096]</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</div>
<div>"HP Software Update"="c:\arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]</div>
<div>"SMSERIAL"="c:\arquivos de programas\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]</div>
<div>"SigmatelSysTrayApp"="sttray.exe" [2007-05-06 405504]</div>
<div>"TPPOLL10"="c:\arquivos de programas\TOPRO\TP6810\TPPOLL10.EXE" [2005-12-26 24576]</div>
<div>"IgfxTray"="c:\wxp\system32\igfxtray.exe" [2009-06-25 134656]</div>
<div>"HotKeysCmds"="c:\wxp\system32\hkcmd.exe" [2009-06-25 166912]</div>
<div>"Persistence"="c:\wxp\system32\igfxpers.exe" [2009-06-25 136192]</div>
<div>"HDAudDeck"="c:\arquivos de programas\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-11-18 33697792]</div>
<div>"avast"="c:\arquivos de programas\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]</div>
<div>"SearchSettings"="c:\arquivos de programas\Arquivos comuns\Spigot\Search Settings\SearchSettings.exe" [2013-02-23 1297728]</div>
<div>"SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2013-03-12 253816]</div>
<div>"APSDaemon"="c:\arquivos de programas\Arquivos comuns\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]</div>
<div>"QuickTime Task"="e:\arquivos de programas\K-Lite Codec Pack\QuickTime\QTTask.exe" [2012-10-25 421888]</div>
<div>.</div>
<div>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]</div>
<div>"nltide_2"="shell32" [X]</div>
<div>.</div>
<div>c:\documents and settings\Mycomp\Menu Iniciar\Programas\Inicializar\</div>
<div>BrOffice.org 3.2.lnk - c:\arquivos de programas\BrOffice.org 3\program\quickstart.exe [2009-12-15 384000]</div>
<div>.</div>
<div>c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\</div>
<div>Adobe Gamma Loader.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-25 110592]</div>
<div>HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]</div>
<div>2012-11-22 19:05 1585768 ----a-w- c:\arquivos de programas\GbPlugin\gbieh.dll</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]</div>
<div>BootExecute REG_MULTI_SZ &nbsp; autocheck autochk *\0\0sdnclean.exe</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Discador iG]</div>
<div>2007-01-07 02:10 1329664 -c--a-w- c:\arquivos de programas\iGv6\discador ig.exe</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]</div>
<div>2007-03-12 00:34 49152 ----a-w- c:\arquivos de programas\HP\HP Software Update\hpwuSchd2.exe</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSRaid]</div>
<div>2004-11-12 13:50 892928 -c--a-w- c:\arquivos de programas\Silicon Integrated Systems\SiSRaidPackage\Sraid.exe</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]</div>
<div>2002-07-12 10:15 106496 -c--a-w- c:\wxp\SiSUSBrg.exe</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]</div>
<div>2004-11-15 10:20 77824 -c--a-w- c:\wxp\SOUNDMAN.EXE</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysBrand]</div>
<div>2004-12-08 22:23 36864 -c--a-w- c:\arquiv~1\iGv6\sysbrand.exe</div>
<div>.</div>
<div>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]</div>
<div>"c:\\Arquivos de programas\\eMule\\emule.exe"=</div>
<div>"%windir%\\Network Diagnostic\\xpnetdiag.exe"=</div>
<div>"c:\\WXP\\system32\\sessmgr.exe"=</div>
<div>"c:\\Arquivos de programas\\Google\\Google Earth\\client\\googleearth.exe"=</div>
<div>"c:\\Documents and Settings\\Mycomp\\Configurações locais\\Dados de aplicativos\\Google\\Google Talk Plugin\\googletalkplugin.exe"=</div>
<div>"c:\\Arquivos de programas\\TeamViewer\\Version7\\TeamViewer.exe"=</div>
<div>"c:\\Arquivos de programas\\TeamViewer\\Version7\\TeamViewer_Service.exe"=</div>
<div>"c:\\Arquivos de programas\\Java\\jre6\\bin\\javaw.exe"=</div>
<div>"e:\\Documents and Settings\\Mycomp\\Meus documentos\\Downloads\\uTorrent.exe"=</div>
<div>"c:\\Arquivos de programas\\Java\\jre7\\bin\\javaw.exe"=</div>
<div>"c:\\Documents and Settings\\Mycomp\\Configurações locais\\Dados de aplicativos\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=</div>
<div>"c:\\Arquivos de programas\\Windows Live\\Messenger\\wlcsdk.exe"=</div>
<div>"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=</div>
<div>"c:\\Arquivos de programas\\Windows Live\\Sync\\WindowsLiveSync.exe"=</div>
<div>"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=</div>
<div>"c:\\Arquivos de programas\\Arquivos comuns\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=</div>
<div>.</div>
<div>R0 a347bus;a347bus;c:\wxp\system32\drivers\a347bus.sys [28/11/2012 18:51 160640]</div>
<div>R0 a347scsi;a347scsi;c:\wxp\system32\drivers\a347scsi.sys [28/11/2012 18:51 5248]</div>
<div>R0 aswRvrt;aswRvrt;c:\wxp\system32\drivers\aswRvrt.sys [6/3/2013 15:53 49376]</div>
<div>R0 aswVmm;aswVmm;c:\wxp\system32\drivers\aswVmm.sys [6/3/2013 15:53 174664]</div>
<div>R0 GbpKm;Gbp KernelMode;c:\wxp\system32\drivers\gbpkm.sys [31/8/2011 20:20 46440]</div>
<div>R1 aswKbd;aswKbd;c:\wxp\system32\drivers\aswKbd.sys [14/5/2013 14:58 21576]</div>
<div>R1 aswSnx;aswSnx;c:\wxp\system32\drivers\aswSnx.sys [8/10/2011 00:18 765736]</div>
<div>R1 aswSP;aswSP;c:\wxp\system32\drivers\aswSP.sys [8/10/2011 00:18 368944]</div>
<div>R2 Application Updater;Application Updater;c:\arquivos de programas\Application Updater\ApplicationUpdater.exe [23/2/2013 16:54 805752]</div>
<div>R2 aswFsBlk;aswFsBlk;c:\wxp\system32\drivers\aswFsBlk.sys [8/10/2011 00:18 29816]</div>
<div>R2 aswMonFlt;aswMonFlt;c:\wxp\system32\drivers\aswMonFlt.sys [6/3/2013 15:53 66336]</div>
<div>R2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe [31/8/2011 20:20 280168]</div>
<div>R2 MBAMScheduler;MBAMScheduler;c:\arquivos de programas\Malwarebytes' Anti-Malware\mbamscheduler.exe [19/5/2013 18:29 418376]</div>
<div>R2 MBAMService;MBAMService;c:\arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe [19/5/2013 18:29 701512]</div>
<div>R3 MBAMProtector;MBAMProtector;c:\wxp\system32\drivers\mbam.sys [19/5/2013 18:29 22856]</div>
<div>R3 NdisrdMP;NdisrdMP;c:\wxp\system32\drivers\GbpNdisrd.sys [29/12/2011 21:14 31088]</div>
<div>R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\wxp\system32\drivers\viahduaa.sys [14/8/2011 17:06 1425280]</div>
<div>S2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Dados de aplicativos\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2/10/2012 12:13 3064000]</div>
<div>S2 SkypeUpdate;Skype Updater;c:\arquivos de programas\Skype\Updater\Updater.exe [1/3/2013 12:11 161384]</div>
<div>S3 Ndisrd;GAS Tecnologia Service;c:\wxp\system32\drivers\GbpNdisrd.sys [29/12/2011 21:14 31088]</div>
<div>S3 sembbus;SEMC WMC Composite Device driver (WDM);c:\wxp\system32\drivers\sembbus.sys [11/1/2010 21:19 260992]</div>
<div>S3 sembcard;Sony Ericsson PC300 Mobile Broadband Command Interface Drivers (WDM);c:\wxp\system32\drivers\sembcard.sys [11/1/2010 21:22 337408]</div>
<div>S3 sembmdfl2;Sony Ericsson PC300 Wireless Modem Filter;c:\wxp\system32\drivers\sembmdfl2.sys [11/1/2010 21:22 14976]</div>
<div>S3 sembmdm2;Sony Ericsson PC300 Wireless Modem Driver;c:\wxp\system32\drivers\sembmdm2.sys [11/1/2010 21:22 380672]</div>
<div>S3 sembmgmt;Sony Ericsson PC300 Mobile Broadband Device Management Drivers (WDM);c:\wxp\system32\drivers\sembmgmt.sys [11/1/2010 21:22 343680]</div>
<div>S3 sembnd5;Sony Ericsson PC300 Mobile Broadband Network Adapter SENECA (NDIS);c:\wxp\system32\drivers\sembnd5.sys [11/1/2010 21:22 24960]</div>
<div>S3 sembunic;Sony Ericsson PC300 Mobile Broadband Network Adapter SENECA (WDM);c:\wxp\system32\drivers\sembunic.sys [11/1/2010 21:22 344064]</div>
<div>S3 sembwwan;Sony Ericsson PC300 Mobile Broadband Ethernet Control Drivers (WDM);c:\wxp\system32\drivers\sembwwan.sys [11/1/2010 21:22 337408]</div>
<div>S3 SEMCReserved;SEMC Reserved Interface;c:\wxp\system32\drivers\semcreserved.sys [11/1/2010 21:22 17408]</div>
<div>S3 Sony_EricssonWWSC;Sony Ericsson SIM Card Reader;c:\wxp\system32\drivers\sesc.sys [11/1/2010 21:22 12672]</div>
<div>S3 usb2vcom;USB to Serial Bridge Controller;c:\wxp\system32\Drivers\usb2vcom.sys --&gt; c:\wxp\system32\Drivers\usb2vcom.sys [?]</div>
<div>.</div>
<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]</div>
<div>HPZ12 REG_MULTI_SZ &nbsp; Pml Driver HPZ12 Net Driver HPZ12</div>
<div>hpdevmgmt REG_MULTI_SZ &nbsp; hpqcxs08 hpqddsvc</div>
<div>.</div>
<div>Conteúdo da pasta 'Tarefas Agendadas'</div>
<div>.</div>
<div>2013-05-19 c:\wxp\Tasks\AppleSoftwareUpdate.job</div>
<div>- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2011-06-01 20:57]</div>
<div>.</div>
<div>2013-05-20 c:\wxp\Tasks\avast! Emergency Update.job</div>
<div>- c:\arquivos de programas\AVAST Software\Avast\AvastEmUpdate.exe [2012-06-30 08:58]</div>
<div>.</div>
<div>2013-05-20 c:\wxp\Tasks\GoogleUpdateTaskMachineCore.job</div>
<div>- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-09-24 00:17]</div>
<div>.</div>
<div>2013-05-20 c:\wxp\Tasks\GoogleUpdateTaskMachineUA.job</div>
<div>- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2010-09-24 00:17]</div>
<div>.</div>
<div>2013-05-16 c:\wxp\Tasks\WebReg Photosmart C4200 series.job</div>
<div>- c:\arquivos de programas\HP\Digital Imaging\bin\hpqwrg.exe [2007-03-12 00:27]</div>
<div>.</div>
<div>.</div>
<div>------- Scan Suplementar -------</div>
<div>.</div>
<div>uStart Page = hxxp://www.google.com.br/</div>
<div>uSearchMigratedDefaultURL = hxxp://farejador.ig.com.br/query.cgi?utf8&query={searchTerms}</div>
<div>mSearch Bar = hxxp://farejador.ig.com.br/ie/</div>
<div>uSearchAssistant = hxxp://www.google.com/ie</div>
<div>uSearchURL,(Default) = hxxp://www.google.com/search?q=%s</div>
<div>IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000</div>
<div>Trusted Zone: bancobrasil.com.br\www</div>
<div>Trusted Zone: bancobrasil.com.br\www14</div>
<div>Trusted Zone: bancobrasil.com.br\www2</div>
<div>Trusted Zone: bb.com.br\www</div>
<div>TCP: DhcpNameServer = 189.124.128.33 189.124.128.32</div>
<div>DPF: Microsoft XML Parser for Java - file://c:\wxp\Java\classes\xmldso.cab</div>
<div>FF - ProfilePath - c:\documents and settings\Mycomp\Dados de aplicativos\Mozilla\Firefox\Profiles\mkb72tzx.default\</div>
<div>FF - prefs.js: browser.search.selectedEngine - Yahoo</div>
<div>FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/</div>
<div>FF - prefs.js: keyword.URL - hxxp://br.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=668083&p=</div>
<div>FF - user.js: extensions.autoDisableScopes - 0&nbsp;</div>
<div>FF - user.js: extensions.shownSelectionUI - true</div>
<div>.</div>
<div>- - - - ORFÃOS REMOVIDOS - - - -</div>
<div>.</div>
<div>MSConfigStartUp-GrooveMonitor - c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe</div>
<div>MSConfigStartUp-NeroFilterCheck - c:\wxp\system32\NeroCheck.exe</div>
<div>MSConfigStartUp-snpstd3 - c:\wxp\vsnpstd3.exe</div>
<div>AddRemove-Adobe Photoshop 7.0 - c:\wxp\ISUN0416.EXE</div>
<div>AddRemove-DealPly - c:\arquivos de programas\DealPly\uninst.exe</div>
<div>.</div>
<div>.</div>
<div>.</div>
<div>**************************************************************************</div>
<div>.</div>
<div>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a href='http://www.gmer.net' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.gmer.net</a></div>
<div>Rootkit scan 2013-05-19 23:38</div>
<div>Windows 5.1.2600 Service Pack 2 NTFS</div>
<div>.</div>
<div>Procurando processos ocultos ...&nbsp;</div>
<div>.</div>
<div>Procurando entradas auto inicializáveis ocultas ...&nbsp;</div>
<div>.</div>
<div>HKLM\Software\Microsoft\Windows\CurrentVersion\Run</div>
<div>&nbsp; HDAudDeck = c:\arquivos de programas\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????????????&nbsp;</div>
<div>.</div>
<div>Procurando ficheiros/arquivos ocultos ...&nbsp;</div>
<div>.</div>
<div>Varredura completada com sucesso</div>
<div>arquivos/ficheiros ocultos: 0</div>
<div>.</div>
<div>**************************************************************************</div>
<div>.</div>
<div>--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------</div>
<div>.</div>
<div>- - - - - - - &gt; 'winlogon.exe'(1072)</div>
<div>c:\arquivos de programas\GBPLUGIN\gbieh.dll</div>
<div>.</div>
<div>Tempo para conclusão: 2013-05-19 &nbsp;23:41:29</div>
<div>ComboFix-quarantined-files.txt &nbsp;2013-05-20 02:41</div>
<div>.</div>
<div>Pré-execução: 9 pasta(s) 31.814.836.224 bytes disponíveis</div>
<div>Pós execução: 14 pasta(s) 32.076.480.512 bytes disponíveis</div>
<div>.</div>
<div>WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe</div>
<div>[boot loader]</div>
<div>timeout=2</div>
<div>default=multi(0)disk(0)rdisk(0)partition(1)\WXP</div>
<div>[operating systems]</div>
<div>c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons</div>
<div>UnsupportedDebug="do not select this" /debug</div>
<div>multi(0)disk(0)rdisk(0)partition(1)\WXP="Microsoft Windows XP Professional" /noexecute=optin /fastdetect</div>
<div>.</div>
<div>- - End Of File - - 0AD38E8006C16F1DDAF414928D884A66</div>
<div>&nbsp;</div>
<div>Segue abaixo o Log do MalwareByte</div>
<div>&nbsp;</div>
<div><br />
<div>Malwarebytes Anti-Malware (Trial) 1.75.0.1300</div>
<div>www.malwarebytes.org</div>
<div>&nbsp;</div>
<div>Versão da Base de Dados: &nbsp;v2013.05.19.10</div>
<div>&nbsp;</div>
<div>Windows XP Service Pack 2 x86 NTFS</div>
<div>Internet Explorer 7.0.5730.11</div>
<div>Mycomp :: WILSON [administrador]</div>
<div>&nbsp;</div>
<div>Proteção: Permitir</div>
<div>&nbsp;</div>
<div>19/5/2013 18:34:07</div>
<div>mbam-log-2013-05-19 (18-34-07).txt</div>
<div>&nbsp;</div>
<div>Tipo de Verificação: &nbsp;Verificação Completa &nbsp;(C:\|E:\|)</div>
<div>Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos &nbsp;| Heurística/Extra | Heurística/Shuriken | PUP | PUM</div>
<div>Opções de verificação desativadas: P2P</div>
<div>Objetos escaneados: &nbsp;346603</div>
<div>Tempo decorrido: 1 hora(s), 12 minuto(s), 39 segundo(s)</div>
<div>&nbsp;</div>
<div>Processos de Memória Detectados: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>Módulos de Memória Detectados: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>Chaves de Registro Detectadas: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>Valores de Registro Detectadas: 1</div>
<div>HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|ForceClassicControlPanel (Hijack.ControlPanelStyle) -&gt; Data: 1 -&gt; Enviado para a Quarentena e deletado com sucesso.</div>
<div>&nbsp;</div>
<div>Itens de Dados no Registro Detectadas: 3</div>
<div>HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -&gt; Ruim: (1) Bom: (0) -&gt; Enviado para a Quarentena e reparado com sucesso.</div>
<div>HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -&gt; Ruim: (1) Bom: (0) -&gt; Enviado para a Quarentena e reparado com sucesso.</div>
<div>HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -&gt; Ruim: (1) Bom: (0) -&gt; Enviado para a Quarentena e reparado com sucesso.</div>
<div>&nbsp;</div>
<div>Pastas Detectadas: 0</div>
<div>(Não foram detectados ítens maliciosos)</div>
<div>&nbsp;</div>
<div>Arquivos Detectados: 1</div>
<div>E:\System Volume Information\_restore{A3A219DC-A636-41B9-988C-85A1D9094577}\RP354\A0232769.exe (PUP.Hacktool.Patcher) -&gt; Enviado para a Quarentena e deletado com sucesso.</div>
<div>&nbsp;</div>
<div>(fim)</div>
<div>&nbsp;</div>
</div>
</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
]]></description>
		<pubDate>Mon, 20 May 2013 03:23:38 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767207-analise-de-log/</guid>
	</item>
	<item>
		<title>Verificação de Malwares</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767201-verificação-de-malwares/</link>
		<description><![CDATA[<p>Olá, gostaria que vocês fizessem a verificação de logs do meu PC</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Segue o registro do HijackThis:</p>
<p>&nbsp;</p>
<p>Logfile of Trend Micro HijackThis v2.0.4<br>
Scan saved at 19:07:18, on 19/05/2013<br>
Platform: Windows 7&nbsp; (WinNT 6.00.3504)<br>
MSIE: Internet Explorer v8.00 (8.00.7600.16385)<br>
Boot mode: Normal<br><br>
Running processes:<br>
C:\Windows\system32\Dwm.exe<br>
C:\Windows\system32\taskhost.exe<br>
C:\Windows\Explorer.EXE<br>
C:\Program Files\My Lockbox\mylbx.exe<br>
C:\Program Files\AVAST Software\Avast\AvastUI.exe<br>
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br>
C:\Windows\System32\StikyNot.exe<br>
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe<br>
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE<br>
C:\Windows\system32\taskeng.exe<br>
C:\Program Files\Mozilla Firefox\firefox.exe<br>
C:\Program Files\Mozilla Firefox\plugin-container.exe<br>
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe<br>
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe<br>
C:\HijackThis.exe<br><br>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br>
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL<br>
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll<br>
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br>
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL<br>
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll<br>
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll<br>
O4 - HKLM\..\Run: [mylbx] C:\Program Files\My Lockbox\mylbx.exe /a<br>
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui<br>
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices<br>
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br>
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br>
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe<br>
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun<br>
O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"<br>
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO LOCAL')<br>
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO LOCAL')<br>
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO DE REDE')<br>
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO DE REDE')<br>
O4 - HKUS\S-1-5-21-379823776-2352937355-677121396-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')<br>
O4 - HKUS\S-1-5-21-379823776-2352937355-677121396-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')<br>
O4 - HKUS\S-1-5-21-379823776-2352937355-677121396-1004\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'postgres')<br>
O4 - HKUS\S-1-5-21-379823776-2352937355-677121396-1004\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'postgres')<br>
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105<br>
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000<br>
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll<br>
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll<br>
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br>
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br>
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href='http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br>
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br>
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL<br>
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe<br>
O23 - Service: avast! antivírus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe<br>
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe<br>
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe<br>
O23 - Service: MySQL56 - Unknown owner - C:\Program.exe (file missing)<br>
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe<br>
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe<br>
O23 - Service: postgresql-9.1 - PostgreSQL Server 9.1 (postgresql-9.1) - PostgreSQL Global Development Group - C:/Program Files/PostgreSQL/9.1/bin/pg_ctl.exe<br>
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe<br>
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br><br>
--<br>
End of file - 7007 bytes<br>
&nbsp;</p>
]]></description>
		<pubDate>Sun, 19 May 2013 22:13:48 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767201-verificação-de-malwares/</guid>
	</item>
	<item>
		<title>Solicitação de Analise Logs</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767196-solicitação-de-analise-logs/</link>
		<description><![CDATA[<p>Solicitação de <strong>Análise de Logs</strong><br><br>
Já fiz todos os procedimentos solicitados no Tópico Oficial.</p>
<p>&nbsp;</p>
<p>Tenho tido alguns pequenos problemas. Hoje, em especial, não consigo abrir algumas paginas da internet. O mais estranho que percebi é que meu AVG tenta bloquear essa pagina, quando tento abrir.</p>
<p>&nbsp;</p>
<p>Segue meu <strong>Log</strong> para exame:</p>
<p>&nbsp;</p>
<p>Logfile of Trend Micro HijackThis v2.0.4<br>
Scan saved at 12:43:32, on 19/05/2013<br>
Platform: Windows 7 SP1 (WinNT 6.00.3505)<br>
MSIE: Internet Explorer v10.0 (10.00.9200.16576)<br>
Boot mode: Normal</p>
<p>Running processes:<br>
C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIcon.exe<br>
C:\Windows\SysWOW64\msiexec.exe<br>
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe<br>
C:\Program Files (x86)\AVG\AVG2013\avgui.exe<br>
C:\Windows\SysWOW64\svchost.exe<br>
C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe<br>
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE<br>
C:\Program Files\Sony\VAIO Care\listener.exe<br>
C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe<br>
C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE<br>
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE<br>
C:\Users\Gmarluci\HijackThis.exe</p>
<p>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://sony.msn.com' class='bbc_url' title='Link Externo' rel='nofollow external'>http://sony.msn.com</a><br>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='https://www.google.com.br/' class='bbc_url' title='Link Externo' rel='nofollow external'>https://www.google.com.br/</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br>
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br>
F3 - REG:win.ini: load=c:\users\gmarluci\dxlhfvnm.exe<br>
F2 - REG:system.ini: UserInit=userinit.exe<br>
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br>
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll<br>
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll<br>
O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL<br>
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll<br>
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIcon.exe<br>
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"<br>
O4 - HKLM\..\Run: [OiVelox] C:\Program Files (x86)\Oi\Programmer\OiVeloxCheck.exe<br>
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY<br>
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br>
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO LOCAL')<br>
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO LOCAL')<br>
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO DE REDE')<br>
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO DE REDE')<br>
O4 - Startup: Windows Calendar.lnk = C:\Program Files\Windows Calendar\WinCal.exe<br>
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105<br>
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000<br>
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br>
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br>
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll<br>
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll<br>
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br>
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br>
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll<br>
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll<br>
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics<br>
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)<br>
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL<br>
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br>
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL<br>
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe<br>
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe<br>
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe<br>
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br>
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br>
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe<br>
O23 - Service: Watchdog do AVG (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe<br>
O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>
O23 - Service: DCDhcpService - Atheros Communication Inc. - C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe<br>
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)<br>
O23 - Service: Energy Server Service (ESRV_SVC) - Unknown owner - C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe<br>
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)<br>
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe<br>
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe<br>
O23 - Service: Intel&reg; Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorDataMgrSvc.exe<br>
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe<br>
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>
O23 - Service: IviRegMgr - InterVideo - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe<br>
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: Intel&reg; Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\LMS\LMS.exe<br>
O23 - Service: McAfee Security Scan Component Host Service for Sony (McComponentHostServiceSony) - McAfee, Inc. - C:\Program Files (x86)\Sony\MSS\3.0.271\McCHSvc.exe<br>
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe<br>
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br>
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: Oasis2Service - Unknown owner - C:\Program Files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe<br>
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe<br>
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe<br>
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br>
O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe<br>
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe<br>
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br>
O23 - Service: VAIO Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe<br>
O23 - Service: VAIO Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe<br>
O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe<br>
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)<br>
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe<br>
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br>
O23 - Service: Intel&reg; Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe<br>
O23 - Service: User Energy Server Service (USER_ESRV_SVC) - Unknown owner - C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe<br>
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe<br>
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe<br>
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe<br>
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe<br>
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe<br>
O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe<br>
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br>
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe<br>
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br>
O23 - Service: vToolbarUpdater14.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe<br>
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update\VUAgent.exe<br>
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)<br>
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)<br>
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br>
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)</p>
<p>--<br>
End of file - 13800 bytes</p>
<p><br>
&nbsp;</p>
]]></description>
		<pubDate>Sun, 19 May 2013 15:53:39 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767196-solicitação-de-analise-logs/</guid>
	</item>
	<item>
		<title>Como Está o Meu PC?</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767195-como-está-o-meu-pc/</link>
		<description><![CDATA[<p>Oi, Tudo Bem? Como Está o Meu PC? Notebook?</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Logfile of Trend Micro HijackThis v2.0.4<br>
Scan saved at 12:41:19, on 19/05/2013<br>
Platform: Windows 7 SP1 (WinNT 6.00.3505)<br>
MSIE: Internet Explorer v10.0 (10.00.9200.16576)<br>
Boot mode: Normal</p>
<p>Running processes:<br>
C:\Windows\system32\taskhost.exe<br>
C:\Windows\system32\Dwm.exe<br>
C:\Windows\Explorer.EXE<br>
C:\Program Files\Bluetooth Suite\BtvStack.exe<br>
C:\Program Files\Bluetooth Suite\AthBtTray.exe<br>
C:\Windows\System32\hkcmd.exe<br>
C:\Windows\System32\igfxpers.exe<br>
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe<br>
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe<br>
C:\Program Files\Common Files\Java\Java Update\jusched.exe<br>
C:\Program Files\Real\RealPlayer\Update\realsched.exe<br>
C:\Program Files\iTunes\iTunesHelper.exe<br>
C:\Program Files\Windows Sidebar\sidebar.exe<br>
C:\Windows\system32\taskeng.exe<br>
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe<br>
C:\Program Files\Samsung\Easy Display Manager\WifiManager.exe<br>
C:\Windows\system32\igfxext.exe<br>
C:\Windows\system32\cmd.exe<br>
C:\Users\Christopher\AppData\Local\Akamai\netsession_win.exe<br>
C:\Users\Christopher\AppData\Local\Akamai\netsession_win.exe<br>
C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe<br>
C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe<br>
C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe<br>
C:\Program Files\Skype\Phone\Skype.exe<br>
C:\Program Files\Internet Explorer\iexplore.exe<br>
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\klwtblfs.exe<br>
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_7_700_202_ActiveX.exe<br>
C:\Program Files\Internet Explorer\iexplore.exe<br>
C:\HijackThis.exe</p>
<p>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve<br>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://www.globo.com/sanguebom' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.globo.com/sanguebom</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br>
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;&lt;local&gt;??????????????s;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;local&gt;;&lt;lo<br>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br>
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll<br>
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll<br>
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll<br>
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll<br>
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll<br>
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>
O2 - BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll<br>
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll<br>
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br>
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL<br>
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll<br>
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll<br>
O4 - HKLM\..\Run: [AtherosBtStack] "C:\Program Files\Bluetooth Suite\BtvStack.exe"<br>
O4 - HKLM\..\Run: [AthBtTray] "C:\Program Files\Bluetooth Suite\AthBtTray.exe"<br>
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe<br>
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe<br>
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe<br>
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s<br>
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"<br>
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe"<br>
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"<br>
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br>
O4 - HKLM\..\Run: [TkBellExe] "c:\program files\real\realplayer\Update\realsched.exe" -osboot<br>
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"<br>
O4 - HKCU\..\Run: [Google Update] "C:\Users\Christopher\AppData\Local\Google\Update\GoogleUpdate.exe" /c<br>
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun<br>
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Christopher\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver<br>
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun<br>
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Christopher\AppData\Local\Akamai\netsession_win.exe"<br>
O4 - HKUS\S-1-5-18\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'SISTEMA')<br>
O4 - HKUS\.DEFAULT\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Default user')<br>
O8 - Extra context menu item: Adicionar ao Antibanner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm<br>
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll<br>
O9 - Extra button: Teclado Virtual - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll<br>
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll<br>
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll<br>
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll<br>
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll<br>
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br>
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br>
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br>
O9 - Extra button: Verificação de URLs - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll<br>
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll<br>
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll<br>
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics<br>
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - <a href='http://200.195.190.6/msupdate/E%2F5%2F6%2FE5611B10-0D6D-4117-8430-A67417AA88CD%2FLegitCheckControl.cab?ivit=6195&original=download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://200.195.190.6/msupdate/E%2F5%2F6%2FE5611B10-0D6D-4117-8430-A67417AA88CD%2FLegitCheckControl.cab?ivit=6195&original=download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab</a><br>
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - <a href='http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://messenger.zone.msn.com/MessengerGamesContent/GameContent/pt/uno1/GAME_UNO1.cab</a><br>
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} - <a href='http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab</a><br>
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - <a href='http://www.superadblocker.com/activex/sabspx.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.superadblocker.com/activex/sabspx.cab</a><br>
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - <a href='http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab</a><br>
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br>
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL<br>
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br>
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL<br>
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe<br>
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe<br>
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe<br>
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br>
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe<br>
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files\Bluetooth Suite\adminservice.exe<br>
O23 - Service: Serviço do Kaspersky Anti-Virus (AVP) - Kaspersky Lab ZAO - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe<br>
O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 9\DfsdkS.exe<br>
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe<br>
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe<br>
O23 - Service: Intel&reg; Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel&reg; Rapid Storage Technology\IAStorDataMgrSvc.exe<br>
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>
O23 - Service: Intel&reg; Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel&reg; Management Engine Components\LMS\LMS.exe<br>
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe<br>
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe<br>
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe<br>
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe<br>
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe<br>
O23 - Service: Intel&reg; Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe<br>
O23 - Service: Ashampoo LiveTuner Service (WO_LiveService) - Unknown owner - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 9\LiveTunerService.exe</p>
<p>--<br>
End of file - 13462 bytes</p>
]]></description>
		<pubDate>Sun, 19 May 2013 15:46:41 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767195-como-está-o-meu-pc/</guid>
	</item>
	<item>
		<title>malwares</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767194-malwares/</link>
		<description><![CDATA[<p>ola, boa tarde, creio que o meu problema é o mesmo de muitos como ja tenho visto nos foruns.</p>
<p>eu tento acessar minha conta do itau e não consigo, logo a minha conta não abre e aparece no lugar do endereço isso, &nbsp;<em>GRIPNET</em>/<em>bklcom</em>.<em>dll &nbsp;eu não sei oque fazer , pesso por favor que aguem possa me ajudar a resolver esse problemão, obrigado estarei aguardando ajuda.</em></p>
]]></description>
		<pubDate>Sun, 19 May 2013 14:40:54 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767194-malwares/</guid>
	</item>
	<item>
		<title>Analise de Log</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767193-analise-de-log/</link>
		<description><![CDATA[<p>O computador inicia e a pra ficar disponível pra navegação na intenret leva quase dois minutos, e não era assim antes. Rodei alguns programas pra ver se havia algo errado - tenho o <strong>Malwarebytes Anti-Malware</strong>, mas ele não abre&nbsp; - , seguem os logs, para, por favor, darem uma olhada:</p>
<p>&nbsp;</p>
<p>====================================== Informations ======================================<br><br>
Rapport de recherche de GabKiller<br><br>
Outil développé par 2011N2<br>
Contact : lot12@hotmail.fr<br>
Site : <a href='http://2011n2.forumgratuit.fr/' class='bbc_url' title='Link Externo' rel='nofollow external'>http://2011n2.forumgratuit.fr/</a><br>
Mis à jour le : 04/08/2011 à 13h | 1.45 par 2011N2<br><br>
Début du scan de recherche : 11:11:50<br>
Nom du PC : MAURICIO-043B91<br>
&nbsp;<br>
Système d'exploitation : VERSION 3.0&nbsp; &nbsp;<br>
Système d'exploitation : Microsoft Windows XP&nbsp; &nbsp;<br>
Internet Explorer : VERSION 3.0&nbsp; &nbsp;<br>
Internet Explorer : 8.0.6001.18702&nbsp;&nbsp; &nbsp;<br>
Mozilla Firefox : VERSION 3.0&nbsp; &nbsp;<br>
Mozilla Firefox : 20.0.1 (pt-BR)&nbsp; &nbsp;<br>
Mozilla Firefox : version 5&nbsp; &nbsp;<br>
Mozilla Firefox : version 6&nbsp; &nbsp;<br><br>
############################# Éléments infectieux #############################<br><br>
============================ Section HKLM ============================<br>
&nbsp;<br>
Présent : HKLM\Software\Classes\CLSID\{9461b922-3c5a-11d2-bf8b-00c04fb93661}<br><br>
============================ Section HKCU ============================<br>
&nbsp;<br><br>
============================ Section HKCR ============================<br>
&nbsp;<br><br>
========================== Dossiers/Fichiers ==========================<br>
&nbsp;<br><br><br>
================================================================================================<br><br>
Fin du scan de recherche : 11:12:33<br><br>
Copyright © 2011. Tous droits réservés.<br>
############### EOF ###############</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Logfile of Trend Micro HijackThis v2.0.4<br>
Scan saved at 11:19:54, on 19/5/2013<br>
Platform: Windows XP SP3 (WinNT 5.01.2600)<br>
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>
Boot mode: Normal<br><br>
Running processes:<br>
C:\WINDOWS\System32\smss.exe<br>
C:\WINDOWS\system32\winlogon.exe<br>
C:\WINDOWS\system32\services.exe<br>
C:\WINDOWS\system32\lsass.exe<br>
C:\WINDOWS\system32\svchost.exe<br>
C:\WINDOWS\System32\svchost.exe<br>
C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe<br>
C:\WINDOWS\Explorer.EXE<br>
C:\WINDOWS\system32\spoolsv.exe<br>
C:\WINDOWS\system32\svchost.exe<br>
C:\Arquivos de programas\Java\jre7\bin\jqs.exe<br>
C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe<br>
C:\Arquivos de programas\Spyware Terminator\st_rsser.exe<br>
C:\WINDOWS\RTHDCPL.EXE<br>
C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe<br>
C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe<br>
C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe<br>
C:\WINDOWS\system32\ctfmon.exe<br>
C:\WINDOWS\system32\svchost.exe<br>
C:\WINDOWS\system32\wbem\wmiapsrv.exe<br>
C:\WINDOWS\system32\wscntfy.exe<br>
C:\WINDOWS\system32\wuauclt.exe<br>
C:\WINDOWS\system32\NOTEPAD.EXE<br>
C:\Arquivos de programas\Mozilla Firefox\firefox.exe<br>
C:\Documents and Settings\Mauricio Dias\Desktop\HijackThis.exe<br><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br>
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARQUIV~1\MICROS~2\Office12\GRA8E1~1.DLL<br>
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)<br>
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre7\bin\jp2ssv.dll<br>
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"<br>
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE<br>
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br>
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"<br>
O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"<br>
O4 - HKLM\..\Run: [OutpostFeedBack] "C:\Arquivos de programas\Agnitum\Outpost Firewall\feedback.exe" /dump:os_startup<br>
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"<br>
O4 - HKLM\..\Run: [SpywareTerminatorUpdater] C:\Arquivos de programas\Spyware Terminator\SpywareTerminatorUpdate.exe<br>
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br>
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')<br>
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br>
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')<br>
O4 - Startup: Recorte de tela e Iniciador do OneNote 2007.lnk = C:\Arquivos de programas\Microsoft Office\Office12\ONENOTEM.EXE<br>
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000<br>
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll<br>
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll<br>
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL<br>
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe<br>
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe<br>
O14 - IERESET.INF: SEARCH_PAGE_URL=&<a href='http://home.microsoft.com/intl/br/access/allinone.asp' class='bbc_url' title='Link Externo' rel='nofollow external'>http://home.microsoft.com/intl/br/access/allinone.asp</a><br>
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - <a href='http://download.eset.com/special/eos/OnlineScanner.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://download.eset.com/special/eos/OnlineScanner.cab</a><br>
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - <a href='http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab</a><br>
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARQUIV~1\MICROS~2\Office12\GR99D3~1.DLL<br>
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br>
O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br>
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\ARQUIV~1\Agnitum\OUTPOS~1\acs.exe<br>
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe<br>
O23 - Service: avast! antivírus - AVAST Software - C:\Arquivos de programas\Alwil Software\Avast5\AvastSvc.exe<br>
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe<br>
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe<br>
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Arquivos de programas\Java\jre7\bin\jqs.exe<br>
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe<br>
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Arquivos de programas\SiSoftware\SiSoftware Sandra Lite 2012.SP5c\RpcAgentSrv.exe<br>
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Arquivos de programas\Spyware Terminator\st_rsser.exe<br><br>
--<br>
End of file - 6518 bytes<br>
&nbsp;</p>
<p>&nbsp;</p>
]]></description>
		<pubDate>Sun, 19 May 2013 14:22:06 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767193-analise-de-log/</guid>
	</item>
	<item>
		<title>Possivel Malware...</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767192-possivel-malware/</link>
		<description><![CDATA[<p>Olá!</p>
<p>&nbsp;</p>
<p>sou novo no Forum do Baboo e estou com problemas com meu PC (Obviously -.-)</p>
<p>e os mesmos são meio bizarros nada que ja tinha acontecido antes.. muito frustrante..</p>
<p>&nbsp;</p>
<p>Eu li o topico oficial com as regras e TODAS foram feitas.. exibir arquivos ocultos e protegidos do sistema e limpeza com Ccleaner Slim..</p>
<p>&nbsp;</p>
<p>vamos aos problemas.. vou tentar ser o mais breve possivel..</p>
<p>&nbsp;</p>
<p>1º</p>
<p>&nbsp;</p>
<p>Minha frustração começa nesse tópico ~&gt;</p>
<p>&nbsp;</p>
<p><a href='http://www.babooforum.com.br/forum/index.php?/topic/767169-navegadores-n%C3%A3o-restauram-sess%C3%B5es/' class='bbc_url' title=''>http://www.babooforum.com.br/forum/index.php?/topic/767169-navegadores-n%C3%A3o-restauram-sess%C3%B5es/</a></p>
<p>&nbsp;</p>
<p>2º</p>
<p>&nbsp;</p>
<p>Alguns arquivos fechando na inicialização.. pastas, jogos e programas sem quaisquer</p>
<p>ligação uns com os outros.. eu preciso abri-los umas 4 vezes até pararem de fechar</p>
<p>&nbsp;</p>
<p>3º</p>
<p>&nbsp;</p>
<p>Navegadores pedem pra instalarem a barra FreeSecureSearch do Avira</p>
<p>sendo que ja a tenho instalada.. o estranho é que nunca termina incomodando muito</p>
<p>a navegação.. uma janelinha de instalação fantasma que aparece e desaparece carregando..</p>
<p>e isso começou do nada.. acontece umas 3 de 10 vezes que abro um navegador</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>nao sei se me expressei bem.. tomara que tenha dado pra entender rsrs..</p>
<p>&nbsp;</p>
<p>abaixo segue log do hijackthis!</p>
<p>&nbsp;</p>
<p>Abraços!</p>
<p>&nbsp;</p>
<p>Logfile of Trend Micro HijackThis v2.0.4<br>
Scan saved at 10:58:55, on 19/5/2013<br>
Platform: Windows XP SP3 (WinNT 5.01.2600)<br>
MSIE: Internet Explorer v8.00 (8.00.6001.18702)<br>
Boot mode: Normal<br><br>
Running processes:<br>
C:\WINDOWS\System32\smss.exe<br>
C:\WINDOWS\system32\winlogon.exe<br>
C:\WINDOWS\system32\services.exe<br>
C:\WINDOWS\system32\lsass.exe<br>
C:\Arquivos de programas\IObit\Advanced SystemCare 6\ASCService.exe<br>
C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe<br>
C:\Arquivos de programas\Avira\AntiVir Desktop\avshadow.exe<br>
C:\WINDOWS\system32\svchost.exe<br>
C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe<br>
C:\WINDOWS\system32\svchost.exe<br>
C:\WINDOWS\system32\svchost.exe<br>
C:\WINDOWS\system32\spoolsv.exe<br>
C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe<br>
C:\Arquivos de programas\IObit\IObit Malware Fighter\IMFsrv.exe<br>
C:\Arquivos de programas\SUPERAntiSpyware\SASCORE.EXE<br>
C:\Arquivos de programas\Avira\AntiVir Desktop\AVWEBGRD.EXE<br>
C:\Arquivos de programas\Java\jre7\bin\jqs.exe<br>
C:\WINDOWS\system32\nvsvc32.exe<br>
C:\WINDOWS\system32\svchost.exe<br>
C:\WINDOWS\Explorer.EXE<br>
C:\Arquivos de programas\IObit\Advanced SystemCare 6\Monitor.exe<br>
C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe<br>
C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe<br>
C:\WINDOWS\system32\wbem\wmiapsrv.exe<br>
C:\WINDOWS\RTHDCPL.EXE<br>
C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe<br>
C:\Arquivos de programas\Ask.com\Updater\Updater.exe<br>
C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe<br>
C:\Arquivos de programas\Unlocker\UnlockerAssistant.exe<br>
C:\Arquivos de programas\Real\RealPlayer\update\realsched.exe<br>
C:\WINDOWS\system32\RunDLL32.exe<br>
C:\WINDOWS\system32\ctfmon.exe<br>
C:\WINDOWS\system32\rundll32.exe<br>
C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe<br>
C:\Arquivos de programas\IObit\Advanced SystemCare 6\ASCTray.exe<br>
C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe<br>
C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe<br>
C:\Arquivos de programas\Mozilla Firefox\firefox.exe<br>
C:\Arquivos de programas\Mozilla Firefox\plugin-container.exe<br>
C:\HiJackThis.exe<br><br>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank<br>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/?LinkId=69157' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=69157</a><br>
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll<br>
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dados de aplicativos\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll<br>
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)<br>
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveShellExtensions.dll<br>
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre7\bin\ssv.dll<br>
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\ARQUIV~1\IObit\ADVANC~3\BROWER~1\ASCPLU~1.DLL<br>
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll<br>
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre7\bin\jp2ssv.dll<br>
O3 - Toolbar: Avira SearchFree Toolbar plus Web Protection - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Arquivos de programas\Ask.com\GenericAskToolbar.dll<br>
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe"<br>
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Arquivos de programas\COMODO\COMODO Internet Security\cfp.exe" -h<br>
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE<br>
O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe<br>
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k<br>
O4 - HKLM\..\Run: [ApnUpdater] "C:\Arquivos de programas\Ask.com\Updater\Updater.exe"<br>
O4 - HKLM\..\Run: [avgnt] "C:\Arquivos de programas\Avira\AntiVir Desktop\avgnt.exe" /min<br>
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Arquivos de programas\Unlocker\UnlockerAssistant.exe"<br>
O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Real\RealPlayer\update\realsched.exe"&nbsp; -osboot<br>
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup<br>
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login<br>
O4 - HKLM\..\Run: [nwiz] C:\Arquivos de programas\NVIDIA Corporation\nview\nwiz.exe /installquiet<br>
O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"<br>
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe<br>
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrador\Configurações locais\Dados de aplicativos\Google\Update\GoogleUpdate.exe" /c<br>
O4 - HKCU\..\Run: [Advanced SystemCare 6] "C:\Arquivos de programas\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart<br>
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')<br>
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')<br>
O4 - HKUS\S-1-5-21-1715567821-1844237615-1801674531-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')<br>
O4 - HKUS\S-1-5-21-1715567821-1844237615-1801674531-1004\..\RunOnce: [NeroHomeFirstStart] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMFirstStart.exe (User 'UpdatusUser')<br>
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')<br>
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')<br>
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe<br>
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office12\EXCEL.EXE/3000<br>
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll<br>
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARQUIV~1\MICROS~2\Office12\ONBttnIE.dll<br>
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\Office12\REFIEBAR.DLL<br>
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe<br>
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe<br>
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe<br>
O14 - IERESET.INF: SEARCH_PAGE_URL=&<a href='http://home.microsoft.com/intl/br/access/allinone.asp' class='bbc_url' title='Link Externo' rel='nofollow external'>http://home.microsoft.com/intl/br/access/allinone.asp</a><br>
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - <a href='http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1359303328859' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1359303328859</a><br>
O17 - HKLM\System\CCS\Services\Tcpip\..\{8FE06CD5-6C14-45DE-914C-43E4A518237A}: NameServer = 8.26.56.26,156.154.70.22<br>
O17 - HKLM\System\CCS\Services\Tcpip\..\{F27C1E84-D878-41B2-85CE-70F726C6FCC4}: NameServer = 8.26.56.26,156.154.70.22<br>
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de programas\Microsoft Office\Office12\GrooveSystemServices.dll<br>
O20 - AppInit_DLLs:&nbsp;&nbsp;&nbsp; C:\WINDOWS\system32\guard32.dll<br>
O22 - SharedTaskScheduler: Pré-carregador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll<br>
O22 - SharedTaskScheduler: Daemon de cache de categorias de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll<br>
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Arquivos de programas\SUPERAntiSpyware\SASCORE.EXE<br>
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe<br>
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Arquivos de programas\IObit\Advanced SystemCare 6\ASCService.exe<br>
O23 - Service: Avira Agendamento (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Arquivos de programas\Avira\AntiVir Desktop\sched.exe<br>
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Arquivos de programas\Avira\AntiVir Desktop\avguard.exe<br>
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Arquivos de programas\Avira\AntiVir Desktop\AVWEBGRD.EXE<br>
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Arquivos de programas\COMODO\COMODO Internet Security\cmdagent.exe<br>
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe<br>
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe<br>
O23 - Service: IMF Service (IMFservice) - IObit - C:\Arquivos de programas\IObit\IObit Malware Fighter\IMFsrv.exe<br>
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Arquivos de programas\Java\jre7\bin\jqs.exe<br>
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Arquivos de programas\Mozilla Maintenance Service\maintenanceservice.exe<br>
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe<br>
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Arquivos de programas\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe<br>
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe<br><br>
--<br>
End of file - 10776 bytes<br>
&nbsp;</p>
]]></description>
		<pubDate>Sun, 19 May 2013 14:20:38 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767192-possivel-malware/</guid>
	</item>
	<item>
		<title>Solicitação de Análise de Logs</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767190-solicitação-de-análise-de-logs/</link>
		<description><![CDATA[<p>Já fiz todos os procedimentos solicitados no Tópico Oficial.<br><br><strong>Hoje quando acessei o Globo.com e clicava nos links das notícias, ele estava redirecionando para essa página: </strong><a href='http://agesinxt.com/?dn=sawpf.com&fp=sSai141Q%2FfjVmRG5PjmPX0Hdy6HttXCO5%2BjAYtJA0vEHbtRqEul65DmvA54wpiJfELf9f2J2Zwp0%2FODNbvCvqA%3D%3D&prvtof=oV84QX56cv4xFwKMDaSpZ7Ic%2BQcWwO82MTHU6VkWqag89fICbGuGYJrFMPocRiE7gXBFDbJTnueCisGBQt3L5OEZisvzFSHH6jj1pEzj%2FWtv9yLUwC5oPVQ1j9wwUi3hLi8zH18sLm54LJM7hTDDnPT3eo0VCXFWBlZElR%2F3UHY%3D&poru=3UK145CPQbcB8LgIGh72X9pKkVPFmw4LayB4vhoV3YLjeXhbFoE95XcPu%2BtC8I7k4QaqUDJWLuYPaaXh6u5SVXW0IqdD4Er6TfCGeUARmg4%3D&cifr=1&flrdr=yes&nxte=js' class='bbc_url' title='Link Externo' rel='nofollow external'>http://agesinxt.com/?dn=sawpf.com&fp=sSai141Q%2FfjVmRG5PjmPX0Hdy6HttXCO5%2BjAYtJA0vEHbtRqEul65DmvA54wpiJfELf9f2J2Zwp0%2FODNbvCvqA%3D%3D&prvtof=oV84QX56cv4xFwKMDaSpZ7Ic%2BQcWwO82MTHU6VkWqag89fICbGuGYJrFMPocRiE7gXBFDbJTnueCisGBQt3L5OEZisvzFSHH6jj1pEzj%2FWtv9yLUwC5oPVQ1j9wwUi3hLi8zH18sLm54LJM7hTDDnPT3eo0VCXFWBlZElR%2F3UHY%3D&poru=3UK145CPQbcB8LgIGh72X9pKkVPFmw4LayB4vhoV3YLjeXhbFoE95XcPu%2BtC8I7k4QaqUDJWLuYPaaXh6u5SVXW0IqdD4Er6TfCGeUARmg4%3D&cifr=1&flrdr=yes&nxte=js</a></p>
<div>&nbsp;</div>
<div>Segue meu <strong>Log</strong> para exame:</div>
<div>&nbsp;</div>
<div>Logfile of Trend Micro HijackThis v2.0.4<br>
Scan saved at 10:05:02, on 19/05/2013<br>
Platform: Windows 7 SP1 (WinNT 6.00.3505)<br>
MSIE: Internet Explorer v10.0 (10.00.9200.16576)<br>
Boot mode: Normal<br><br>
Running processes:<br>
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe<br>
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe<br>
C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe<br>
C:\Program Files (x86)\uTorrent\uTorrent.exe<br>
C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe<br>
C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe<br>
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe<br>
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe<br>
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe<br>
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe<br>
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe<br>
C:\Program Files (x86)\Winamp\winampa.exe<br>
C:\Program Files (x86)\iTunes\iTunesHelper.exe<br>
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe<br>
C:\Program Files (x86)\Mozilla Firefox\firefox.exe<br>
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe<br>
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe<br>
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_202.exe<br>
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe<br>
C:\Windows\SysWOW64\DllHost.exe<br><br>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://g.msn.com/USCON/5' class='bbc_url' title='Link Externo' rel='nofollow external'>http://g.msn.com/USCON/5</a><br>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://br.hao123.com/?tn=smt_hp_hao123_br' class='bbc_url' title='Link Externo' rel='nofollow external'>http://br.hao123.com/?tn=smt_hp_hao123_br</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a><br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a><br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =<br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =<br>
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm<br>
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local<br>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br>
F2 - REG:system.ini: UserInit=userinit.exe<br>
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll<br>
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll<br>
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll<br>
O2 - BHO: Increase performance and video formats for your HTML5 &lt;video&gt; - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll<br>
O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll<br>
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120630084442.dll<br>
O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll<br>
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br>
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL<br>
O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll<br>
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey<br>
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"<br>
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"<br>
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"<br>
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"<br>
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2<br>
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW<br>
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"<br>
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"<br>
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime<br>
O4 - HKLM\..\Run: [Java Update] C:\Program Files\Java\setup.vbs<br>
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"<br>
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"<br>
O4 - HKCU\..\Run: [PCSpeedUp] C:\Program Files (x86)\Velocidade Do PC\PCSpeedUp.lnk<br>
O4 - HKCU\..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe<br>
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe<br>
O4 - HKCU\..\Run: [com.apple.dav.bookmarks.daemon] C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe<br>
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"<br>
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe<br>
O4 - Global Startup: PHOTOfunSTUDIO 5.0.lnk = C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe<br>
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105<br>
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000<br>
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br>
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll<br>
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll<br>
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll<br>
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br>
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll<br>
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br>
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br>
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll<br>
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll<br>
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics<br>
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - <a href='http://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://ccfiles.creative.com/Web/softwareupdate/su/ocx/15102/CTSUEng.cab</a><br>
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - <a href='http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab</a><br>
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - <a href='http://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab' class='bbc_url' title='Link Externo' rel='nofollow external'>http://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab</a><br>
O17 - HKLM\System\CCS\Services\Tcpip\..\{2384213D-902E-4259-A7B0-85A81E17AA3B}: NameServer = 8.8.8.8,8.8.4.4<br>
O17 - HKLM\System\CS1\Services\Tcpip\..\{2384213D-902E-4259-A7B0-85A81E17AA3B}: NameServer = 8.8.8.8,8.8.4.4<br>
O17 - HKLM\System\CS2\Services\Tcpip\..\{2384213D-902E-4259-A7B0-85A81E17AA3B}: NameServer = 8.8.8.8,8.8.4.4<br>
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll<br>
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL<br>
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll<br>
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll<br>
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL<br>
O20 - AppInit_DLLs: c:\progra~3\browse~1\261095~1.52\{c16c1~1\browse~1.dll<br>
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe<br>
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe<br>
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe<br>
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)<br>
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe<br>
O23 - Service: Bluetooth Device Monitor - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe<br>
O23 - Service: Bluetooth Media Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe<br>
O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe<br>
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)<br>
O23 - Service: Intel&reg; PROSet/Wireless Event Log (EvtEng) - Intel&reg; Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe<br>
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)<br>
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe<br>
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: McAfee Activation Service (McAWFwk) - McAfee, Inc. - c:\PROGRA~1\mcafee\msc\mcawfwk.exe<br>
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe<br>
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe<br>
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe<br>
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe<br>
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe<br>
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe<br>
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe<br>
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe<br>
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe<br>
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)<br>
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe<br>
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)<br>
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe<br>
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe<br>
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: Intel&reg; PROSet/Wireless Registry Service (RegSrvc) - Intel&reg; Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe<br>
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe<br>
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe<br>
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)<br>
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE<br>
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe<br>
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)<br>
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)<br>
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)<br>
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10102 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe<br>
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe<br>
O23 - Service: Intel&reg; Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel&reg; Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe<br>
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)<br>
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)<br>
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)<br>
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)<br>
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)<br>
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)<br>
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)<br><br>
--<br>
End of file - 16384 bytes<br><br>
Obrigado<br>
&nbsp;</div>
]]></description>
		<pubDate>Sun, 19 May 2013 13:12:16 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767190-solicitação-de-análise-de-logs/</guid>
	</item>
	<item>
		<title>Solicitação de Análise de Logs</title>
		<link>http://www.babooforum.com.br/forum/index.php?/topic/767187-solicitação-de-análise-de-logs/</link>
		<description><![CDATA[<p>Já fiz todos os procedimentos solicitados no Tópico Oficial e aguardo a análise por parte dos&nbsp;<strong>Colegas Analistas.</strong><br><br><u>O meu problema é o seguinte</u>: Todos os arquivos do excel e word foram e estão atualmente corrompidos. E isto aconteceu após eu ter inserido um pendrive de minha propriedade em computadores de uma determinada Prefeitura Municipal aqui do meu Estado, e logo a seguir, ter&nbsp;reinserido&nbsp;em meu ultrabook.</p>
<p>&nbsp;</p>
<p>Segue meu&nbsp;<strong>Log</strong>&nbsp;para exame:</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div>Logfile of Trend Micro HijackThis v2.0.4</div>
<div>Scan saved at 18:14:20, on 18/05/2013</div>
<div>Platform: Unknown Windows (WinNT 6.02.1008)</div>
<div>MSIE: Internet Explorer v10.0 (10.00.9200.16384)</div>
<div>Boot mode: Normal</div>
<div>&nbsp;</div>
<div>Running processes:</div>
<div>C:\Users\Sílvio\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe</div>
<div>C:\Users\Sílvio\AppData\Roaming\Yontoo\YontooDesktop.exe</div>
<div>C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe</div>
<div>C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe</div>
<div>C:\Program Files\AVAST Software\Avast\AvastUI.exe</div>
<div>C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE</div>
<div>C:\Program Files\Sony\VAIO Care\listener.exe</div>
<div>C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIcon.exe</div>
<div>C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Program Files (x86)\Google\Chrome\Application\chrome.exe</div>
<div>C:\Users\Sílvio\Downloads\HijackThis.exe</div>
<div>&nbsp;</div>
<div>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://sony13.msn.com' class='bbc_url' title='Link Externo' rel='nofollow external'>http://sony13.msn.com</a></div>
<div>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://www.baixaki.com.br/portal/?utm_source=core&utm_medium=ppi&utm_campaign=portal' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.baixaki.com.br/portal/?utm_source=core&utm_medium=ppi&utm_campaign=portal</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = <a href='http://go.microsoft.com/fwlink/p/?LinkId=255141' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/p/?LinkId=255141</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = <a href='http://go.microsoft.com/fwlink/?LinkId=54896' class='bbc_url' title='Link Externo' rel='nofollow external'>http://go.microsoft.com/fwlink/?LinkId=54896</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = <a href='http://www.baixaki.com.br/portal/?utm_source=core&utm_medium=ppi&utm_campaign=portal' class='bbc_url' title='Link Externo' rel='nofollow external'>http://www.baixaki.com.br/portal/?utm_source=core&utm_medium=ppi&utm_campaign=portal</a></div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =&nbsp;</div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =&nbsp;</div>
<div>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm</div>
<div>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =&nbsp;</div>
<div>F2 - REG:system.ini: UserInit=userinit.exe</div>
<div>O2 - BHO: Java&#153; Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll</div>
<div>O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll</div>
<div>O2 - BHO: DealPly Shopping - {a6c63b7f-2171-47fa-ab34-e64c4737169d} - C:\Program Files (x86)\DealPly\DealPlyIE.dll</div>
<div>O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL</div>
<div>O2 - BHO: Java&#153; Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll</div>
<div>O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll</div>
<div>O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll</div>
<div>O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorIcon.exe" 60</div>
<div>O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"</div>
<div>O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe</div>
<div>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"</div>
<div>O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"</div>
<div>O4 - HKLM\..\Run: [Intel AT Service signup] c:\Program Files (x86)\Intel Corporation\Intel AT Service signup\IntelATServiceSignup.exe -launchonboot</div>
<div>O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui</div>
<div>O4 - HKLM\..\RunOnce: [Del20129328] cmd.exe /Q /D /c del "C:\Users\SLVIO~1\AppData\Local\Temp\0.del"</div>
<div>O4 - HKCU\..\Run: [SkyDrive] "C:\Users\Sílvio\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background</div>
<div>O4 - HKCU\..\Run: [Yontoo Desktop] "C:\Users\Sílvio\AppData\Roaming\Yontoo\YontooDesktop.exe"</div>
<div>O4 - HKCU\..\RunOnce: [Del20129296] cmd.exe /Q /D /c del "C:\Users\SLVIO~1\AppData\Local\Temp\0.del"</div>
<div>O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000</div>
<div>O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105</div>
<div>O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll</div>
<div>O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll</div>
<div>O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll</div>
<div>O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll</div>
<div>O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics</div>
<div>O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL</div>
<div>O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)</div>
<div>O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe</div>
<div>O23 - Service: avast! antivírus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe</div>
<div>O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe</div>
<div>O23 - Service: Intel&reg; Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)</div>
<div>O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe</div>
<div>O23 - Service: Tecnologia de armazenamento Intel&reg; Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel&reg; Rapid Storage Technology\IAStorDataMgrSvc.exe</div>
<div>O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe</div>
<div>O23 - Service: Intel&reg; Capability Licensing Service Interface - Intel&reg; Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe</div>
<div>O23 - Service: Intel&reg; ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\FWService\IntelMeFWService.exe</div>
<div>O23 - Service: Intel&reg; Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\DAL\jhi_service.exe</div>
<div>O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: Intel&reg; Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\LMS\LMS.exe</div>
<div>O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: NetworkSupport - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkSupport.exe</div>
<div>O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe</div>
<div>O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)</div>
<div>O23 - Service: VAIO Care Performance Service (SampleCollector) - Unknown owner - C:\Program Files\Sony\VAIO Care\VCPerfService.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)</div>
<div>O23 - Service: VAIO Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe</div>
<div>O23 - Service: VAIO Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe</div>
<div>O23 - Service: VAIO Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe</div>
<div>O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe</div>
<div>O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)</div>
<div>O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)</div>
<div>O23 - Service: Intel&reg; Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel&reg; Management Engine Components\UNS\UNS.exe</div>
<div>O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe</div>
<div>O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)</div>
<div>O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe</div>
<div>O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe</div>
<div>O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)</div>
<div>O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)</div>
<div>O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update\VUAgent.exe</div>
<div>O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)</div>
<div>O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)</div>
<div>O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)</div>
<div>O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)</div>
<div>O23 - Service: ZAtheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe</div>
<div>&nbsp;</div>
<div>--</div>
<div>End of file - 11956 bytes</div>
<div>&nbsp;</div>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></description>
		<pubDate>Sat, 18 May 2013 21:30:17 +0000</pubDate>
		<guid>http://www.babooforum.com.br/forum/index.php?/topic/767187-solicitação-de-análise-de-logs/</guid>
	</item>
</channel>
</rss>