Passei o ComboFix, como não consegui passar o Dr. veja o log do ComboFix:
ComboFix 09-12-02.05 - Ticiana 02/12/2009 21:01.4.2 - 86
Microsoft ® Windows Vista ™ Home Basic 6.0.6002.2.1252.55.1046.18.1789.971 [GMT -2:00]
Executando de: C: \ Users \ Ticiana \ Downloads \ ComboFix.exe
SP: Spybot - Search and Destroy * deficiência * (Atualizado) (ED588FAF-1B8F-43B4-AcA8-8E3C85DADBE9)
SP: O Windows Defender habilitado * * (Atualizado) (D68DDC3A-831F-4FAE-9E44-DA132C1ACF46)
.
[i] ADS - motoristas: foi excluído 204 bytes in 1 streams. [/ i]
(((((((((((((((( Arquivos / Ficheiros criados de 2009/11/02 a 2009/12/02 )))))))))))))))))) ))))))))))
.
2009-12-02 23:19. 2009-12-02 23:19 -------- d ----- w-C: \ Users \ Public \ AppData \ Local \ Temp
2009-12-02 23:19. 2009-12-02 23:19 -------- d ----- w-C: \ Users \ Default \ AppData \ Local \ Temp
2009-12-02 22:39. 2009-12-02 22:39 1438704----- aw C: \ ProgramData \ Google \ Google Toolbar \ Componente \ SearchWithGoogleUpdate_C58171F2E8870EA4.exe
2009-12-02 22:39. 2009-12-02 22:39 1002096----- aw C: \ ProgramData \ Google \ Google Toolbar \ Componente \ GoogleToolbarManager_0E996B068B56FCA2.exe
2009-12-02 22:39. 2009-12-02 22:39 392704----- aw C: \ ProgramData \ Google \ Google Toolbar \ Componente \ GoogleToolbarDynamic_mui_pt-BR_324E45F73759905B.dll
2009-12-02 22:39. 2009-12-02 22:39 648192----- aw C: \ ProgramData \ Google \ Google Toolbar \ Componente \ GoogleToolbarDynamic_mui_en_60D6097707281E79.dll
2009-12-02 22:39. 2009-12-02 22:39 2726000----- aw C: \ ProgramData \ Google \ Google Toolbar \ Componente \ GoogleToolbarDynamic_32_E0B3D00E06C2FA01.dll
2009-12-02 22:37. 2009-12-02 22:37 1230960----- aw C: \ ProgramData \ Google \ Google Toolbar \ Componente \ GoogleCld_3F6C343113693CD9.dll
2009-12-02 22:37. 2009-12-02 22:37 390144----- aw C: \ ProgramData \ Google \ Google Toolbar \ Componente \ GoogleToolbarDynamic_mui_pt-BR_4484EF110BC303E9.dll
2009-12-02 22:36. 2009-12-02 22:36 33553----- aw C: \ ProgramData \ Google \ Google Toolbar para Firefox \ Firefox_Toolbar_Uninstaller.exe
2009-12-01 00:31. 2009-12-01 00:31 -------- d ----- w-C: \ Users \ Ticiana \ AppData \ Roaming \ Malwarebytes
2009-12-01 00:30. 2009-09-10 16:54 38224 ---- aw-c: \ windows \ system32 \ drivers \ mbamswissarmy.sys
2009-12-01 00:30. 2009-12-01 00:31 4096-d ----- w C: \ Program Files \ Malwarebytes 'Anti-Malware
2009-12-01 00:30. 2009-12-01 00:30 -------- d ----- w-C: \ ProgramData \ Malwarebytes
2009-12-01 00:30. 2009-09-10 16:53 19160 ---- aw-c: \ windows \ system32 \ drivers \ mbam.sys
2009-11-30 22:38. 2009-11-30 23:59 -------- d ----- w-C: \ Users \ Ticiana \ DoctorWeb
2009-11-30 00:17. 2009-11-30 00:17 318976 ---- aw-c: \ windows \ system32 \ CF13204.exe
2009-11-29 22:53. 2009-11-29 22:53 -------- d ----- w-C: \ ProgramData \ é-9RGPQ
2009-11-29 22:45. 2009-12-02 06:34 37578784 Sha --w-c: \ windows \ system32 \ drivers \ fidbox.dat
2009-11-29 22:35. 2008-07-08 15:54 148496 ---- aw-c: \ windows \ system32 \ drivers \ 21163858.sys
2009-11-29 22:28. 2009-11-29 22:28 673280----- aw C: \ WINDOWS \ is-618L6.exe
2009-11-25 22:17. 2009-10-29 09:17 2048 ---- aw-c: \ windows \ system32 \ Tzres.dll
2009-11-25 22:15. 2009-11-25 22:15 -------- d ----- w-c: \ Program Files \ MSXML 4.0
2009-11-24 23:04. 2009-08-11 16:44 1401856 ---- aw-c: \ windows \ system32 \ msxml6.dll
2009-11-24 23:04. 2009-08-11 16:44 1248768 ---- aw-c: \ windows \ system32 \ msxml3.dll
2009-11-19 00:14. 2009-11-19 00:14 180224 ---- aw-c: \ windows \ system32 \ pausep.exe
2009-11-18 00:17. 2009-09-15 09:54 23152 ---- aw-c: \ windows \ system32 \ drivers \ aswRdr.sys
2009-11-18 00:17. 2009-09-15 09:54 52368 ---- aw-c: \ windows \ system32 \ drivers \ aswTdi.sys
2009-11-18 00:17. 2009-09-15 09:53 97480 ---- aw-c: \ windows \ system32 \ AvastSS.scr
2009-11-18 00:17. 2009-09-15 09:55 114768 ---- aw-c: \ windows \ system32 \ drivers \ aswSP.sys
2009-11-18 00:17. 2009-09-15 09:55 20560 ---- aw-c: \ windows \ system32 \ drivers \ aswFsBlk.sys
2009-11-18 00:16. 2009-09-15 09:59 1279968 ---- aw-c: \ windows \ system32 \ aswBoot.exe
2009-11-18 00:16. 2009-09-15 09:55 53328 ---- aw-c: \ windows \ system32 \ drivers \ aswMonFlt.sys
2009-11-11 21:58. 2009-08-14 13:27 2036736 ---- aw-c: \ windows \ system32 \ win32k.sys
2009-11-11 21:58. 2009-08-10 12:35 355328 ---- aw-c: \ windows \ system32 \ Wsdapi.dll
2009-11-07 01:31. 2009/11/15 01:35 180,488 ---- aw-c: \ windows \ PSEXESVC.EXE
2009-11-04 00:18. 2009-11-04 00:41 -------- d ----- w-C: \ SMCLpav
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))) )))))))))))))))))))))))))))))))))))))))))
.
2009-12-02 22:36. 2009-08-12 20:18 4096-d ----- w C: \ Program Files \ Google
2009-12-01 02:26. 2009-11-29 22:45 344288 Sha --w-c: \ windows \ system32 \ drivers \ fidbox.idx
2009-12-01 02:26. 2009-06-23 22:53 12 ---- aw-c: \ windows \ bthservsdp.dat
2009-11-29 23:43. 2009/06/24 02:57 634,222 ---- aw-c: \ windows \ system32 \ prfh0416.dat
2009-11-29 23:43. 2009/06/24 02:57 121,888 ---- aw-c: \ windows \ system32 \ prfc0416.dat
2009-11-29 22:45. 2009-08-18 19:06 20480 d ----- w-c: \ Program Files \ Glary Utilities
2009-11-29 22:42. 2009-09-12 16:57 4096-d ----- w C: \ Users \ Ticiana \ AppData \ Roaming \ Free Download Manager
2009-11-29 15:47. 2009-08-12 03:27 4096-d ----- w C: \ Program Files \ QuickTime
2009-11-25 22:12. 2009-08-18 19:29 7052----- aw C: \ Users \ Ticiana \ AppData \ Local \ d3d9caps.dat
2009-11-18 22:51. 2009-06-24 00:28 4096-d ----- w C: \ Program Files \ Java
2009-11-15 01:40. 2009-10-27 01:37 4096-d ----- w C: \ Program Files \ Megacubo
2009-11-14 22:38. 2009-08-13 23:45 8192-d ----- w C: \ Program Files \ Spybot - Search & Destroy
2009-11-14 02:27. 2009-08-13 23:45 4096-d ----- w C: \ ProgramData \ Spybot - Search & Destroy
2009-11-04 00:23. 2009-06-23 23:19 8192 d - h - w-c: \ Arquivos de programas \ InstallShield Installation Information
2009-11-04 00:22. 2009-10-13 04:24 4096-d ----- w C: \ Program Files \ Panda Security
2009-11-04 00:22. 2009-10-13 04:00 -------- d ----- w-c: \ Program Files \ Common Files \ Panda Security
2009-11-04 00:19. 2009-10-13 04:06 -------- d ----- w-C: \ ProgramData \ Panda Security
2009-11-02 22:42. 2009-10-12 17:00 195456 ------ w-c: \ windows \ system32 \ MpSigStub.exe
2009-11-02 03:39. 2009-11-02 03:39 -------- d ----- w-c: \ Arquivos de programas \ Alwil Software
2009-10-28 00:29. 2009-10-28 00:25 -------- d ----- w-C: \ Users \ Ticiana \ AppData \ Roaming \ PhotoFiltre Studio X
2009-10-28 00:24. 2009-10-28 00:24 4096-d ----- w C: \ Program Files \ PhotoFiltre Studio X
2009-10-28 00:23. 2009-10-28 00:23 -------- d ----- w-C: \ Users \ Ticiana \ AppData \ Roaming \ DivX
2009-10-26 14:06. 2009-10-26 14:06 79856----- aw C: \ ProgramData \ Google \ Google Toolbar para Firefox \ (3112ca9c-de6d-4884-a869-9855de68056c) \ uninstaller.exe
2009-10-26 01:21. 2009-10-26 00:41 -------- d ----- w-c: \ Arquivos de Programas \ backup
2009-10-24 17:16. 2006-11-02 12:35 4096-d ----- w C: \ Program Files \ Windows Sidebar
2009-10-23 23:07. 2009-09-12 16:57 8192-d ----- w C: \ Program Files \ Free Download Manager
2009-10-23 23:06. 2009-10-23 23:06 -------- d ----- w-c: ProgramData \ \ FreeDownloadManager.ORG
2009-10-23 03:40. 2009-10-23 02:36 4096-d ----- w C: \ Program Files \ Naevius USB Antivirus
2009-10-20 03:21. 2009-10-20 03:21 -------- d ----- w-c: ProgramData \ \ Macro
2009-10-19 21:30. 2009-10-19 21:30 872960----- aw C: \ ProgramData \ Google \ Google Toolbar para Firefox \ (3112ca9c-de6d-4884-a869-9855de68056c) \ components \ frozen.dll
2009-10-19 21:30. 2009-10-19 21:30 43008----- aw C: \ ProgramData \ Google \ Google Toolbar para Firefox \ (3112ca9c-de6d-4884-a869-9855de68056c) \ components \ googletoolbarloader.dll
2009-10-19 21:30. 2009-10-19 21:30 340480----- aw C: \ ProgramData \ Google \ Google Toolbar para Firefox \ (3112ca9c-de6d-4884-a869-9855de68056c) \ bibliotecas \ googletoolbar-ff2.dll
2009-10-19 21:30. 2009-10-19 21:30 346624----- aw C: \ ProgramData \ Google \ Google Toolbar para Firefox \ (3112ca9c-de6d-4884-a869-9855de68056c) \ bibliotecas \ googletoolbar-ff3.dll
2009-10-19 03:47. 2009-10-13 04:07 -------- d ----- w-c: ProgramData \ \ Backup
2009-10-18 23:19. 2009-08-29 19:40 4096-d ----- w C: \ Program Files \ GbPlugin
2009-10-18 23:19. 2009-06-24 00:13 4096-d ----- w C: \ Program Files \ Common Files \ Adobe
2009-10-18 16:22. 2009-08-29 19:40 -------- d ----- w-C: \ ProgramData \ GbPlugin
2009-10-15 16:48. 2009-08-29 19:40 30752 ---- aw-c: \ windows \ system32 \ drivers \ gbpkm.sys
2009-10-13 23:21. 2009-10-13 23:16 4096-d ----- w C: \ Program Files \ Common Files \ Real
2009-10-13 23:20. 2009-10-13 23:20 -------- d ----- w-c: \ Program Files \ Common Files \ xing compartilhada
2009-10-13 23:16. 2009-10-13 23:16 -------- d ----- w-c: \ Program Files \ Real
2009-10-13 03:55. 2009-06-23 23:21 -------- d ----- w-c: ProgramData \ \ Norton
2009-10-13 02:41. 2009-08-13 06:29 4096-d ----- w C: \ Program Files \ SopCast
2009-10-12 19:15. 2009-10-12 19:14 -------- d ----- w-C: \ Users \ Ticiana \ AppData \ Roaming \ TigerPlayer
2009-10-12 19:14. 2009-10-12 19:14 4096-d ----- w C: \ Arquivos de programas \ MpcStar
2009-10-12 18:15. 2009-10-12 18:15 232557 ---- aw-c: \ windows \ Cole2k_Media_Toolbar_Uninstaller_5596.exe
2009-10-12 17:50. 2009-10-12 17:50 36864----- aw C: \ ProgramData \ Temp \ (637CDC99-AEBB-4265-9C47-A3239C95937E) \ PostBuild.exe
2009-10-12 17:12. 2009-06-23 23:03 4096-d ----- w C: \ Program Files \ Hewlett-Packard
2009-10-12 17:11. 2009-06-24 02:36 36864----- aw C: \ ProgramData \ Temp \ (DCCAD079-F92C-44DA-B258-624FC6517A5A) \ PostBuild.exe
2009-10-12 03:56. 2009-06-23 23:19 4096-d ----- w C: \ ProgramData \ Hewlett-Packard
2009-10-11 06:21. 2009-09-27 00:24 -------- d ----- w-c: \ Program Files \ Ashampoo
2009-10-11 06:17. 2009-09-28 00:50 411368 ---- aw-c: \ windows \ system32 \ deploytk.dll
2009-10-10 17:46. 2009-08-22 06:48 -------- d ----- w-c: \ Program Files \ SharpSoft
2009-10-06 03:29. 2009-10-06 03:29 -------- d ----- w-C: \ Users \ Ticiana \ AppData \ Roaming \ vlc
2009-10-04 16:42. 2009-10-04 16:42 8192-d ----- w C: \ Program Files \ 'Full Speed' Internet Booster + Performance Tests
2009-10-04 14:56. 2009-10-04 14:56 4096-d ----- w C: \ Program Files \ Photo Studio Effects
2009-10-04 14:52. 2009-10-04 14:52 -------- d ----- w-C: \ Users \ Ticiana \ AppData \ Roaming \ Auslogics
2009-09-26 23:50. 2009-09-26 23:50 318976 ---- aw-c: \ windows \ system32 \ CF12858.exe
2009-09-20 21:44. 2006-11-02 10:25 665600 ---- aw-c: \ windows \ inf \ drvindex.dat
2009-09-17 23:27. 2009-09-17 23:26 2560 ---- aw-c: \ windows \ _Msrstrt.exe
2009-09-14 09:29. 2009-10-17 01:56 144896 ---- aw-c: \ windows \ system32 \ drivers \ Srv2.sys
2009-09-11 03:42. 2009-09-11 03:42 0 ---- aw-c: \ windows \ ativpsrm.bin
2009-09-10 16:48. 2009/10/17 02:02 218,624 ---- aw-c: \ windows \ system32 \ Msv1_0.dll
2009-09-10 03:29. 2009-08-11 22:25 92544----- aw C: \ Users \ Ticiana \ AppData \ Local \ GDIPFONTCACHEV1.DAT
2009-09-07 15:29. 2009-09-07 15:29 4455865 ---- aw-c: \ windows \ system32 \ libavcodec.dll
2009-09-06 14:52. 2009-09-06 14:52 828611 ---- aw-c: \ windows \ system32 \ ff_x264.dll
2009-09-06 07:00. 2009-06-24 02:53 36864----- aw C: \ ProgramData \ Temp \ (01FB4998-33C4-4431-85ED-079E3EEFE75D) \ PostBuild.exe
2009-09-06 06:58. 2009-06-24 02:49 36864----- aw C: \ ProgramData \ Temp \ (67626E09-5366-4480-8F1E-93FADF50CA15) \ PostBuild.exe
2009-09-06 06:55. 2009-06-24 02:39 36864----- aw C: \ ProgramData \ Temp \ (B2EE25B9-5B00-4ACF-94F0-92433C28C39E) \ PostBuild.exe
2009-09-04 11:41. 2009-10-17 01:56 60928 ---- aw-c: \ windows \ system32 \ msasn1.dll
2009-06-24 03:24. 2009-06-24 03:01 8192 Sha --w-c: \ windows \ Users \ Default \ NTUSER.DAT
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))) ))))))))))))))))))))
.
.
* Nota * entradas vazias e legítimas por defeito não são Mostradas.
REGEDIT4
[HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"CTFMON.EXE" = "c: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe" [2009-03-05 2260480]
"msnmsgr" = "c: \ Program Files \ Windows Live \ Messenger \ MsnMsgr.Exe" [2009-07-26 3883840]
"swg" = "C: \ Arquivos de programas \ Google \ Google Talk \ googletalk.exe" [2009-12-02 39408]
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"CTFMON.EXE" = "c: \ Program Files \ ATI Technologies \ ATI.ACE \ Core-Static \ CLIStart.exe MSRun" [X]
"O Google Caixa de pesquisa rápida" = "c: \ Program Files \ Google \ Caixa de pesquisa rápida \ GoogleQuickSearchBox.exe" [X]
"NeroFilterCheck" = "c: \ Program Files \ Apoint \ Apoint.exe" [2008-06-20 1316136]
"Windows Defender" = "c: \ Program Files \ Windows Defender \ MSASCui.exe" [2008-01-21 1008184]
"QlbCtrl.exe" = "c: \ Program Files \ Hewlett-Packard \ HP Quick Launch Buttons \ QlbCtrl.exe" [2008-10-10 206128]
"HP Health Check Scheduler" = "c: \ Program Files \ Hewlett-Packard \ HP Health Check \ HPHC_Scheduler.exe" [2008-10-09 75008]
"WirelessAssistant" = "c: \ Program Files \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe" [2008-12-08 432432]
"SmartMenu" = "c: \ Program Files \ Hewlett-Packard \ HP MediaSmart \ SmartMenu.exe" [2008-11-18 914224]
"SysTrayApp" = "C: \ Arquivos de programas \ IDT \ WDM \ sttray.exe" [2008-09-11 446556]
"DVDAgent" = "c: \ Program Files \ Hewlett-Packard \ Media \ DVD \ DVDAgent.exe" [2009-03-11 1148200]
"A Adobe ARM" = "c: \ Program Files \ Common Files \ Adobe \ ARM \ 1,0 \ AdobeARM.exe" [2009-09-04 935288]
"avast!" = "c: \ progra ~ 1 \ ALWILS ~ 1 \ Avast4 \ ashDisp.exe" [2009-09-15 81000]
"SunJavaUpdateSched" = "C: \ Arquivos de programas \ Java \ jre6 \ bin \ jusched.exe" [2009-10-11 149280]
"QuickTime Task" = "c: \ Program Files \ QuickTime \ qttask.exe" [2007-06-29 286720]
"Malwarebytes Anti-Malware (reboot)" = "c: \ Program Files \ Malwarebytes 'Anti-Malware \ mbam.exe" [2009-09-10 1312080]
C: \ ProgramData \ Microsoft \ Windows \ Start Menu \ Programs \ Startup \
BTTray.lnk - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ BTTray.exe [2008-6-19 727592]
[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System]
"EnableUIADesktopToggle" = 0 (0x0)
[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \ GbPluginBb]
2009-10-15 16:42 316192----- aw C: \ Program Files \ GbPlugin \ gbieh.dll
[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ drivers32]
"mixer" = Wdmaud.drv
[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Lsa]
Pacotes de notificação REG_MULTI_SZ SceCli DPPWDFLT
[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ SafeBoot \ Minimal \ Wdf01000.sys]
@ = "Driver"
[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ SafeBoot \ Minimal \ WinDefend]
@ = "Service"
[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ run-disabled]
"O Google Caixa de pesquisa rápida" = "c: \ Program Files \ Google \ Caixa de pesquisa rápida \ GoogleQuickSearchBox.exe" / autorun
"SmartMenu" =% ProgramFiles% \ Hewlett-Packard \ HP MediaSmart \ SmartMenu.exe
"UCam_Menu" = "c: \ Program Files \ Hewlett-Packard \ Media \ Webcam \ MUITransfer \ MUIStartMenu.exe" c: \ Program Files \ Hewlett-Packard \ Media \ Webcam "update" Software \ Hewlett-Packard \ Media \ Webcam "
"QuickTime Task" = "c: \ Program Files \ QuickTime \ qttask.exe"-atboottime
"SunJavaUpdateSched" = "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-startup
[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Security Center \ Svc]
"AntiVirusOverride" = dword: 00000001
"VistaSp2" = hex (b): 2b, 8a, 19,12,3 d, 3a, CA, 01
R0 GbpKm; Gbp KernelMode; c: \ windows \ system32 \ drivers \ gbpkm.sys [29/08/2009 17:40 30752]
R1 aswSP; avast! Self Protection; c: \ windows \ system32 \ drivers \ aswSP.sys [17/11/2009 22:17 114768]
R1 is-STLMLdrv; é-STLMLdrv; c: \ windows \ system32 \ drivers \ 21163858.sys [29/11/2009 20:35 148496]
R2 AESTFilters; Andrea ST Filters Service; c: \ windows \ system32 \ DriverStore \ FileRepository stwrt.inf_805f33de \ \ AEstSrv.exe [23/06/2009 23:58 77824]
R2 aswFsBlk; aswFsBlk; c: \ windows \ system32 \ drivers \ aswFsBlk.sys [17/11/2009 22:17 20560]
AswMonFlt R2; aswMonFlt; c: \ windows \ system32 \ drivers \ aswMonFlt.sys [17/11/2009 22:16 53328]
R2 GbpSv; Gbp Service; c: \ progra ~ 1 \ GbPlugin \ GbpSv.exe [29/08/2009 17:40 54048]
R2 hpsrv, HP Service; c: \ windows \ system32 \ hpservice.exe [18/03/2008 17:24 19456]
R2 Recovery Service for Windows; Recovery Service for Windows, C: \ Program Files \ SMINST \ BLService.exe [23/06/2009 22:32 365952]
R2 SBSDWSCService; SBSD Security Center Service; C: \ Arquivos de Programas \ Spybot - Search & Destroy \ SDWinSec.exe [13/08/2009 21:45 1153368]
VfsFPService R2; Validade Fingerprint Serviço; c: \ windows \ system32 \ vfsFPService.exe [18/11/2008 07:09 599344]
R3 Com4QLBEx; Com4QLBEx C: \ Program Files \ Hewlett-Packard \ HP Quick Launch Buttons \ Com4QLBEx.exe [23/06/2009 21:35 222512]
Enecir R3; ENE CIR Receiver; c: \ windows \ system32 \ drivers \ enecir.sys [04/09/2008 15:47 54784]
Usbfilter R3; AMD USB Driver Filter; c: \ windows \ system32 \ drivers \ usbfilter.sys [24/06/2009 00:03 22072]
Gupdate S2; Google Update Service (gupdate); C: \ Program Files \ Google \ Update \ GoogleUpdate.exe [02/12/2009 20:31 135664]
[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
getPlusHelper REG_MULTI_SZ getPlusHelper
[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Active Setup \ Installed Components \ (10880D85-AAD9-4558-ABDC-2AB1552D831F)]
"c: \ Program Files \ Common Files \ LightScribe \ LSRunOnce.exe"
.
Conteúdo da pasta 'Tarefas AGENDADAS'
2009/12/02 c: \ windows \ Tasks \ GlaryInitialize.job
- C: \ Program Files \ Glary Utilities \ initialize.exe [2009-08-18 12:21]
2009/12/02 c: \ windows \ Tasks \ GoogleUpdateTaskMachineCore.job
- C: \ Program Files \ Google \ Update \ GoogleUpdate.exe [2009-12-02 22:30]
2009/12/02 c: \ windows \ Tasks \ GoogleUpdateTaskMachineUA.job
- C: \ Program Files \ Google \ Update \ GoogleUpdate.exe [2009-12-02 22:30]
2009/12/01 c: \ windows \ Tasks \ User_Feed_Synchronization-(648F99F2-089B-4D96-8FBC-A0423D2C8D15) emprego.
- C: \ windows \ system32 \ msfeedssync.exe [2009-10-21 03:41]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp: / /
www.forospyware.com/uDefault_Search_URL = hxxp: / /
www.google.com / ie
mStart Page = hxxp: / /
www.forospyware.com/uSearchURL, (Default) = hxxp: / /% s =
www.google.com/search?qIE: Add to Google Photos Screensa & ver - c: \ windows \ system32 \ GPhotos.scr/200
IE: E & xportar para o Microsoft Excel - C: \ PROGRA ~ 1 \ MICROS ~ 3 \ Office12 \ EXCEL.EXE/3000
IE: Enviar imagem para Dispositivo & Bluetooth ... - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ btsendto_ie_ctx.htm
IE: Enviar página para Dispositivo & Bluetooth ... - C: \ Program Files \ WIDCOMM \ Bluetooth Software \ btsendto_ie.htm
IE: Google Sidewiki ... - C: \ Program Files \ Google \ Google Toolbar \ Componente \ GoogleToolbarDynamic_mui_en_803138DCE93649E4.dll/cmsidewiki.html
IE: Transferir com FDM - file: / / C: \ Program Files \ Free Download Manager \ dllink.htm
IE: Transferir todos com FDM - file: / / C: \ Arquivos de programas \ Free Download Manager \ dlall.htm
IE: Transferir vídeo com FDM - file: / / C: \ Program Files \ Free Download Manager \ dlfvideo.htm
IE: Transferência seleccionada pelo FDM - file: / / C: \ Program Files \ Free Download Manager \ dlselected.htm
Trusted Zone: bb.com.br \ www17
Trusted Zone: blogspot.com \ TV Globo
Trusted Zone: gmail.com \ www
Trusted Zone: megacubo.net \ www
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit / stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-02 21:19
Windows 6.0.6002 Service Pack 2 NTFS
Procurando processos ocultos ...
Procurando entradas auto inicializáveis ocultas ...
Procurando ficheiros / arquivos ocultos ...
C: \ Users \ Ticiana \ AppData \ Local \ Temp \ catchme.dll 53248 bytes executável
Varredura completada com sucesso
Arquivos / Ficheiros ocultos: 1
************************************************** ************************
.
--------------------- CHAVES DO REGISTRO Bloqueadas ---------------------
[HKEY_LOCAL_MACHINE \ system \ ControlSet001 \ Control \ Class \ (4D36E96D-E325-11CE-BFC1-08002BE10318) \ 0000 \ AllUserSettings]
@ Negado: (A) (Usuários)
@ Negado: (A) (Everyone)
@ Permitidos: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial" = dword: 00000000
"MSCurrentCountry" = dword: 000000B5
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
- - - - - - -> 'Lsass.exe' (628)
c: \ windows \ system32 \ DPPWDFLT.dll
- - - - - - -> 'Explorer.exe' (1996)
c: \ windows \ system32 \ btmmhook.dll
.
Tempo para conclusão: 2009-12-02 21:23
ComboFix-quarantined-files.txt 2009-12-02 23:23
ComboFix2.txt 2009-11-30 01:17
Pré-execução: 101.381.992.448 bytes disponíveis
Pós execução: 101.465.956.352 bytes disponíveis
- - End of file - - 18E8026C