Logo Hardware.com.br
Robson ls
Robson ls Membro Senior Registrado
236 Mensagens 13 Curtidas

Problemas com funções do mouse.. sinal de vírus??

#1 Por Robson ls 05/05/2013 - 11:46
Olá pessoal,
Devido a uns problemas com as funções do mouse (https://www.hardware.com.br/comunidade/mouse-problema/1301364/#post6537184), amigos do fórum me recomendaram postar um log aqui para análise.
Não consegui usar o programa OTL... parece que só roda em windows 32 bits, o meu é 64 bits. (Segui o roteiro indicado pelo colega Wings - https://www.hardware.com.br/comunidade/problemas-securitycheck/1226830/#post5956862)

Seguem os logs:

Security Check

Results of screen317's Security Check version 0.99.63
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Norton Internet Security
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware versão 1.75.0.1300
Duplicate Cleaner 2.1b
Java 7 Update 17
Java version out of Date!
Adobe Reader 10.1.4 Adobe Reader out of Date!
Google Chrome 26.0.1410.43
Google Chrome 26.0.1410.64
Google Chrome Plugins...
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: =
````````````````````End of Log``````````````````````



Gmer

http://cjoint.com/?3EfqKBH6OKv


Agradeço aos amigos que puderem analisar os logs.
Wings
Wings Cyber Highlander Registrado
20.3K Mensagens 1.2K Curtidas
#8 Por Wings
19/05/2013 - 14:56
veja.png Desinstale InterApp Control


veja.png Baixe o AdwCleaner (...de Xplode) e salve-o no Desktop (Área de Trabalho)

*Execute-o e clique [Remover]

Imagem

*Salve qualquer trabalho aberto, feche o seu navegador e clique [OK]

Imagem

*Caso seja solicitada a reinicialização do PC, clique [OK] para reiniciar

*Cole o relatório apresentado


veja.png Baixe o Junkware Removal Tool (...de Oleg N. Scherbakov) e salve-o no Desktop (Área de Trabalho)

*Não esqueça!!! -> Feche o seu navegador (Firefox, IE, Google Chrome)

*Execute-o e tecle [ENTER]

Imagem

*Será feito um backup do registro e, em seguida, o programa será executado automaticamente

Imagem

*Aguarde...pode demorar.

*Cole o relatório apresentado
Robson ls
Robson ls Membro Senior Registrado
236 Mensagens 13 Curtidas
#9 Por Robson ls
01/06/2013 - 14:15
Olá amigos,
Desculpe a demora em postar uma resposta, mas é que tenho tido muitos trabalhos da faculdade.... vou dar continuidade as instruções que me passsaram. Agora, o Norton tem dado um alerta sobre um tal Adware Singalng, toda vez que inicio o Internet Explorer ou o Chrome...


*Moderadores, desculpe ter postado duas vezes em seguida... realmente me esqueci desta regra. Minha intenção foi separar o relatório da mensagem, pra não ficar muita coisa junto (deletei a mensagem).

Aqui vai o relatório do AdwCleaner, após ter feito a remoção:



# AdwCleaner v2.301 - Relatório criado em 01/06/2013 às 14:05:37
# Atualizado em 16/05/2013 por Xplode
# Sistema Operacional : Windows 7 Home Premium Service Pack 1 (64 bits)
# Usuário : Robson - ROBSON-PC
# Modo de Boot : Normal
# Executado de : C:\Users\Robson\Desktop\AdwCleaner.exe
# Opção [Remover]

***** [Serviços] *****

***** [Arquivos/Pastas] *****
Arquivo Removido : C:\Users\Public\Desktop\Get The Best Facebook Chat Messenger.lnk
Pasta Removido : C:\Program Files (x86)\continuetosave
Pasta Removido : C:\ProgramData\continuetosuave
Pasta Removido : C:\ProgramData\EbboOkkBrOwsee
Pasta Removido : C:\ProgramData\InstallMate
Pasta Removido : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\continuetosuave
Pasta Removido : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EbboOkkBrOwsee
Pasta Removido : C:\Users\Graciele\AppData\LocalLow\PriceGong
Pasta Removido : C:\Users\Robson\AppData\Local\Google\Chrome\User Data\Default\Extensions\pedinofhdhfgdgichjcejbbejcjglgfj
Pasta Removido : C:\Users\Robson\AppData\Local\Google\Chrome\User Data\Default\Extensions\pepokfiagcbbkfdfanpeobeeljdpaohm
Pasta Removido : C:\Users\Robson\AppData\Local\OpenCandy
Pasta Removido : C:\Users\Robson\AppData\LocalLow\continuetosuave
Pasta Removido : C:\Users\Robson\AppData\LocalLow\EbboOkkBrOwsee
Pasta Removido : C:\Users\Robson\AppData\LocalLow\searchquband
Pasta Removido : C:\Users\Robson\AppData\Roaming\OpenCandy
Pasta Removido : C:\Users\Win!!!\AppData\LocalLow\AskToolbar
Pasta Removido : C:\Users\Win!!!\AppData\LocalLow\continuetosuave
Pasta Removido : C:\Users\Win!!!\AppData\LocalLow\EbboOkkBrOwsee
Pasta Removido : C:\Users\Win!!!\AppData\LocalLow\PriceGong
***** [Registro] *****
Chave Removida : HKCU\Software\AppDataLow\Software\PriceGong
Chave Removida : HKCU\Software\AppDataLow\Software\searchqutoolbar
Chave Removida : HKCU\Software\AppDataLow\Software\SmartBar
Chave Removida : HKCU\Software\AppDataLow\SProtector
Chave Removida : HKCU\Software\Conduit
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{44B45586-449F-E285-1C3A-D9FD6DDB3396}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A3F26ED0-5263-F94B-1573-0E903717705C}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{44B45586-449F-E285-1C3A-D9FD6DDB3396}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3F26ED0-5263-F94B-1573-0E903717705C}
Chave Removida : HKCU\Software\pc optimizer pro
Chave Removida : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Chave Removida : HKLM\Software\Conduit
Chave Removida : HKLM\Software\Freeze.com
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28}
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chave Removida : HKLM\Software\SP Global
Chave Removida : HKLM\Software\SProtector
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{44B45586-449F-E285-1C3A-D9FD6DDB3396}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A3F26ED0-5263-F94B-1573-0E903717705C}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44B45586-449F-E285-1C3A-D9FD6DDB3396}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3F26ED0-5263-F94B-1573-0E903717705C}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C1C6816E-CBB3-A748-85F9-A8B47B68985B}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E5B7E1B4-21FC-6765-A3D7-BA0416DC6AF7}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{EB9E5C1C-B1F9-4C2B-BE8A-27D6446FDAF8}
Chave Removida : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Valor Removida : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Valor Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
Valor Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [10]
***** [Navegadores] *****
-\\ Internet Explorer v9.0.8112.16470
[OK] Registro está limpo.
-\\ Google Chrome v27.0.1453.94
Arquivo : C:\Users\Robson\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Arquivo está limpo.
Arquivo : C:\Users\Win!!!\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Arquivo está limpo.
Arquivo : C:\Users\Graciele\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Arquivo está limpo.
*************************
AdwCleaner[R1].txt - [7089 octets] - [01/06/2013 13:58:57]
AdwCleaner[R2].txt - [7149 octets] - [01/06/2013 14:05:09]
AdwCleaner[S1].txt - [6810 octets] - [01/06/2013 14:05:37]
########## EOF - C:\AdwCleaner[S1].txt - [6870 octets] ##########


Relatório JRT: http://cjoint.com/?0FbtFwrKlj0
Wings
Wings Cyber Highlander Registrado
20.3K Mensagens 1.2K Curtidas
#10 Por Wings
02/06/2013 - 12:36
veja.png Execute o AdwCleaner, clique [Desinstalar] > [Sim]


veja.png Delete o JRT, seu relatório e a pasta C:\JRT


veja.png Execute o OTL e selecione:

Verificar All Users
Ignorar Arquivos Microsoft
Verificar Lop
Verificar Purity


*Cole as linhas, em marrom, no espaço abaixo de Exames Personalizados/Correções

C:\windows\system32\Tasks\*.* /64
%windir%\tasks\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes


*Clique [Verificar]

*Aguarde o término e cole o relatório OTL.txt criado no Desktop


veja.png Desinstale Java 7 Update 17


veja.png Delete o SecurityCheck, o GMER e seu relatório
Robson ls
Robson ls Membro Senior Registrado
236 Mensagens 13 Curtidas
#11 Por Robson ls
03/06/2013 - 22:57
Obrigado, aqui vai o relatório do OTL. O Java eu já desinstalei antes de pedir ajuda aqui no fórum, ele tava dando muito problema, toda hora pedindo pra atualizar... Isso tem a ver com o vírus? Por curiosidade, porque devo apagar os programas gmer, jrt, securitycheck e seus relatórios??

OTL logfile created on: 03/06/2013 22:45:16 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Robson\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

3,99 Gb Total Physical Memory | 2,28 Gb Available Physical Memory | 57,06% Memory free
7,98 Gb Paging File | 6,26 Gb Available in Paging File | 78,50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 509,50 Gb Total Space | 299,59 Gb Free Space | 58,80% Space Free | Partition Type: NTFS
Drive D: | 412,25 Gb Total Space | 278,29 Gb Free Space | 67,51% Space Free | Partition Type: NTFS

Computer Name: ROBSON-PC | User Name: Robson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/05/19 13:43:25 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Robson\Desktop\absa3KgV.com
PRC - [2013/03/25 16:45:52 | 000,694,584 | ---- | M] (Motorola Mobility LLC) -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
PRC - [2013/03/25 16:45:52 | 000,121,144 | ---- | M] (Motorola Mobility LLC) -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
PRC - [2013/02/02 19:51:07 | 000,360,640 | ---- | M] (Banco Bradesco S.A.) -- C:\Program Files (x86)\Scpad\scpVista.exe
PRC - [2012/07/27 17:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/06/15 23:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
PRC - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) -- C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
PRC - [2010/05/21 00:56:36 | 000,334,384 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
PRC - [2010/05/21 00:56:32 | 000,113,200 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
PRC - [2010/05/21 00:56:18 | 000,399,920 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
PRC - [2010/05/20 23:40:20 | 000,539,184 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV - [2013/05/14 15:17:16 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/03/25 16:45:52 | 000,121,144 | ---- | M] (Motorola Mobility LLC) [Auto | Running] -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe -- (Motorola Device Manager)
SRV - [2013/02/02 19:51:07 | 000,360,640 | ---- | M] (Banco Bradesco S.A.) [Auto | Running] -- C:\Program Files (x86)\Scpad\scpVista.exe -- (scpVista)
SRV - [2013/01/08 11:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/09/15 13:37:50 | 001,138,692 | ---- | M] (NCH Software) [On_Demand | Stopped] -- C:\Program Files (x86)\NCH Swift Sound\IMS\ims.exe -- (IMSService)
SRV - [2012/09/15 13:37:26 | 001,324,036 | ---- | M] (NCH Software) [Auto | Stopped] -- C:\Program Files (x86)\NCH Software\VRS\vrs.exe -- (VRSService)
SRV - [2012/09/15 13:37:00 | 001,287,684 | ---- | M] (NCH Software) [On_Demand | Stopped] -- C:\Program Files (x86)\NCH Software\Axon\axon.exe -- (AxonService)
SRV - [2012/07/27 17:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/06/15 23:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe -- (NIS)
SRV - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) [Auto | Running] -- C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe -- (PST Service)
SRV - [2011/06/13 21:21:14 | 000,343,856 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Arquivos de Programas\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2011/03/28 21:11:06 | 002,292,096 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011/01/17 20:20:04 | 000,301,720 | ---- | M] () [Auto | Running] -- C:\Arquivos de Programas\Macrium\Reflect\ReflectService.exe -- (ReflectService)
SRV - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Arquivos de Programas\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010/05/21 00:56:36 | 000,334,384 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2010/05/21 00:56:32 | 000,113,200 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)
SRV - [2010/05/21 00:56:18 | 000,399,920 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2010/05/20 23:40:20 | 000,539,184 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService)
SRV - [2010/04/27 16:42:04 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe -- (ufad-ws60)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/09 20:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Arquivos de Programas\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV - [2010/01/09 20:20:56 | 000,174,440 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Arquivos de Programas\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose64)
SRV - [2009/06/10 18:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2007/12/17 03:00:00 | 000,163,840 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE -- (EPSON_EB_RPCV4_01)
SRV - [2007/01/11 03:02:00 | 000,126,464 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE -- (EPSON_PM_RPCV4_01)


========== Driver Services (SafeList) ==========

DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x64\Sandra.sys -- (SANDRA)
DRV:64bit: - [2012/08/23 11:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 11:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/07/05 23:17:58 | 000,037,536 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\srtspx64.sys -- (SRTSPX)
DRV:64bit: - [2012/07/05 23:17:57 | 000,737,952 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2012/06/07 01:43:38 | 000,167,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\ccsetx64.sys -- (ccSet_NIS)
DRV:64bit: - [2012/05/29 12:55:46 | 000,175,736 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2012/05/21 22:37:12 | 001,129,120 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\symefa64.sys -- (SymEFA)
DRV:64bit: - [2012/04/17 23:13:32 | 000,405,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\symnets.sys -- (SymNetS)
DRV:64bit: - [2012/04/17 22:42:14 | 000,190,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\ironx64.sys -- (SymIRON)
DRV:64bit: - [2012/03/28 19:28:26 | 000,451,192 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\symds64.sys -- (SymDS)
DRV:64bit: - [2012/03/08 18:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2012/03/01 03:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/11/25 00:25:52 | 000,015,360 | ---- | M] (June Fabrics Technology Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pneteth.sys -- (pneteth)
DRV:64bit: - [2011/03/11 03:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 03:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/03 01:56:09 | 000,056,408 | ---- | M] (NCH Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stdriver64.sys -- (stdriver)
DRV:64bit: - [2011/01/08 17:13:01 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2010/11/20 10:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010/10/10 13:11:00 | 001,924,096 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athurx.sys -- (athur)
DRV:64bit: - [2010/05/21 00:57:12 | 000,080,944 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:64bit: - [2010/05/21 00:57:08 | 000,018,480 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\VMparport.sys -- (VMparport)
DRV:64bit: - [2010/05/21 00:57:04 | 000,068,656 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:64bit: - [2010/05/21 00:55:04 | 000,031,792 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMkbd.sys -- (vmkbd)
DRV:64bit: - [2010/05/21 00:54:52 | 000,030,256 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2010/05/20 23:40:12 | 000,038,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:64bit: - [2010/05/20 21:19:18 | 000,045,104 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2010/05/20 21:19:18 | 000,020,016 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2010/04/09 13:17:04 | 000,019,936 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdrvio.sys -- (pwdrvio)
DRV:64bit: - [2010/04/09 13:16:58 | 000,013,280 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\pwdspio.sys -- (pwdspio)
DRV:64bit: - [2009/10/26 14:36:22 | 001,202,688 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\smserial.sys -- (smserial)
DRV:64bit: - [2009/09/23 18:23:02 | 006,180,832 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/07/13 22:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 22:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 22:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 21:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 21:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/07/13 21:10:49 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MODEMCSA.sys -- (MODEMCSA)
DRV:64bit: - [2009/06/10 17:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 17:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 17:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 17:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/03/27 01:23:54 | 000,019,432 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz132_x64.sys -- (cpuz132)
DRV:64bit: - [2008/11/12 13:42:00 | 000,057,344 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\l160x64.sys -- (AtcL001)
DRV - [2013/05/22 14:15:33 | 002,098,776 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\Definitions\VirusDefs\20130603.003\ex64.sys -- (NAVEX15)
DRV - [2013/05/22 14:15:33 | 000,126,040 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\Definitions\VirusDefs\20130603.003\eng64.sys -- (NAVENG)
DRV - [2013/04/12 20:53:05 | 001,390,680 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\Definitions\BASHDefs\20130515.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2012/12/18 13:09:59 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2012/08/31 21:27:23 | 000,513,184 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\Definitions\IPSDefs\20130531.001\IDSviA64.sys -- (IDSVia64)
DRV - [2012/08/08 23:43:56 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/02/03 01:56:09 | 000,056,408 | ---- | M] (NCH Software) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\stdriver64.sys -- (stdriver)
DRV - [2010/04/27 16:41:34 | 000,032,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2010/01/29 10:40:16 | 000,115,600 | ---- | M] (EZB Systems, Inc.) [File_System | System | Running] -- C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys -- (ISODrive)
DRV - [2009/07/13 22:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=pt&pid=NIS&pvid=19.9.1.14
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.oquefazernainternet.com/
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=pt&pid=NIS&pvid=19.9.1.14
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=pt&pid=NIS&pvid=19.9.1.14
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=pt&pid=NIS&pvid=19.9.1.14
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=pt&pid=NIS&pvid=19.9.1.14
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = https://login.live.com/login.srf?w [Binary data over 200 bytes]
IE - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=pt&pid=NIS&pvid=19.9.1.14
IE - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-BR
IE - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 2E 5F F1 5F 2C 51 CC 01 [binary data]
IE - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\..\SearchScopes,DefaultScope = {C1DDD436-51A5-4366-96E6-9475805CB813}
IE - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
IE - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\..\SearchScopes\{C1DDD436-51A5-4366-96E6-9475805CB813}: "URL" = http://www.google.com.br/search?hl=pt-BR&q={searchTerms}&meta=
IE - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\..\SearchScopes\{FF46EF4A-CE07-4CC6-85F9-BCE5B75772D8}: "URL" = http://busca.buscape.com.br/cprocura?site_origem=941243&produto={searchTerms}
IE - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\IPSFFPlgn\ [2012/05/29 12:59:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.0.9\coFFPlgn\ [2013/06/03 22:27:10 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}

O1 HOSTS File: ([2012/09/26 23:15:48 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de Programas\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Arquivos de Programas\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (ssh2 Class) - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Program Files (x86)\Scpad\scpsssh2.dll (Banco Bradesco S.A.)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O3 - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SMSERIAL] C:\Arquivos de Programas\Motorola\SMSERIAL\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [VRS] C:\Program Files (x86)\NCH Software\VRS\vrs.exe (NCH Software)
O4 - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Users\Robson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Conexão de Banda Larga - Atalho.lnk = File not found
O4 - Startup: C:\Users\Robson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = File not found
O4 - Startup: C:\Users\Robson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
O4 - Startup: C:\Users\Win!!!\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3768386665-1314383183-1947410892-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: &Enviar para o OneNote - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8:64bit: - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:64bit: - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: &Download by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Enviar para o OneNote - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9:64bit: - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Arquivos de Programas\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Arquivos de Programas\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} https://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB (Hewlett-Packard Online Support Services)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect118.cab (GMNRev Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{25D70B92-6CCF-417B-AC70-7E4FC9D2F3C7}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3952709D-A521-4B14-85F8-EFADD7081CCB}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de Programas\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files (x86)\Scpad\scpLIB.dll (Banco Bradesco S.A.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper:
O28:64bit: - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de Programas\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/01 14:20:47 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/06/01 14:18:43 | 000,545,954 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\Robson\Desktop\JRT.exe
[2013/06/01 14:18:28 | 000,000,000 | ---D | C] -- C:\JRT
[2013/06/01 00:43:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\MSSoap
[2013/06/01 00:43:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Motorola Mobility
[2013/06/01 00:43:39 | 000,000,000 | ---D | C] -- C:\Program Files\Motorola Inc
[2013/05/19 13:43:18 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Robson\Desktop\absa3KgV.com
[2013/05/19 13:29:14 | 000,000,000 | ---D | C] -- C:\Users\Robson\Documents\Bradesco reclamação
[2013/05/06 00:47:40 | 000,000,000 | ---D | C] -- C:\ProgramData\StarApp
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/09/23 00:41:14 | 000,094,871 | ---- | M] () -- C:\Users\Robson\Desktop\NORTON HOJE.png
[2013/06/03 22:46:00 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2013/06/03 22:32:54 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/03 22:32:54 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/03 22:25:45 | 000,001,064 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/03 22:25:25 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/03 22:25:07 | 3213,549,568 | -HS- | M] () -- C:\hiberfil.sys
[2013/06/03 12:16:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/03 11:50:02 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/03 00:24:35 | 001,533,460 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/03 00:24:35 | 000,669,444 | ---- | M] () -- C:\Windows\SysNative\prfh0416.dat
[2013/06/03 00:24:35 | 000,621,648 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/06/03 00:24:35 | 000,130,200 | ---- | M] () -- C:\Windows\SysNative\prfc0416.dat
[2013/06/03 00:24:35 | 000,108,494 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/06/01 18:13:26 | 000,423,800 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/01 14:18:43 | 000,545,954 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\Robson\Desktop\JRT.exe
[2013/05/19 13:43:25 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Robson\Desktop\absa3KgV.com
[2013/05/15 23:37:21 | 000,259,511 | ---- | M] () -- C:\Users\Robson\Desktop\enem 2013.png
[2013/05/14 15:17:14 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/05/14 15:17:14 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/05/08 23:15:26 | 000,105,586 | ---- | M] () -- C:\Users\Robson\Documents\mateus passaporti duplo para o hopi - que eu vendi.pdf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/09/23 00:41:14 | 000,094,871 | ---- | C] () -- C:\Users\Robson\Desktop\NORTON HOJE.png
[2013/05/15 23:37:21 | 000,259,511 | ---- | C] () -- C:\Users\Robson\Desktop\enem 2013.png
[2013/05/08 23:15:23 | 000,105,586 | ---- | C] () -- C:\Users\Robson\Documents\mateus passaporti duplo para o hopi - que eu vendi.pdf
[2012/01/28 01:01:07 | 000,000,050 | ---- | C] () -- C:\Users\Robson\ireportte Pimaco +.location
[2012/01/28 01:00:49 | 000,002,199 | ---- | C] () -- C:\Users\Robson\config.xml
[2011/11/26 16:30:14 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011/11/26 16:30:14 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011/11/26 16:30:14 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/11/26 02:05:17 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2011/11/26 01:25:26 | 000,077,312 | ---- | C] () -- C:\Users\Robson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/12 22:48:07 | 000,000,660 | RHS- | C] () -- C:\Users\Robson\ntuser.pol
[2011/08/27 14:56:44 | 001,541,728 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/08/20 01:47:40 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2011/08/13 00:38:01 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011/08/06 02:23:49 | 000,000,022 | ---- | C] () -- C:\Windows\SysWow64\Video90cedf5aDrivers.dll

========== ZeroAccess Check ==========

[2009/07/14 01:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/02/27 02:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/02/27 01:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 22:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 09:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 22:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/03/31 14:56:28 | 000,000,000 | ---D | M] -- C:\Users\Graciele\AppData\Roaming\ADPHONE
[2012/05/21 01:02:55 | 000,000,000 | ---D | M] -- C:\Users\Graciele\AppData\Roaming\Foxit Software
[2011/06/01 16:29:50 | 000,000,000 | ---D | M] -- C:\Users\Graciele\AppData\Roaming\GrabPro
[2013/03/03 14:12:26 | 000,000,000 | ---D | M] -- C:\Users\Graciele\AppData\Roaming\Motorola Mobility
[2012/04/29 19:00:58 | 000,000,000 | ---D | M] -- C:\Users\Graciele\AppData\Roaming\NCH Swift Sound
[2012/10/15 00:34:59 | 000,000,000 | ---D | M] -- C:\Users\Graciele\AppData\Roaming\Orbit
[2011/06/08 22:43:04 | 000,000,000 | ---D | M] -- C:\Users\Graciele\AppData\Roaming\ProgSense
[2011/09/25 23:38:44 | 000,000,000 | ---D | M] -- C:\Users\Graciele\AppData\Roaming\Softland
[2012/04/21 20:48:18 | 000,000,000 | ---D | M] -- C:\Users\Graciele\AppData\Roaming\VitySoft
[2011/09/08 01:20:05 | 000,000,000 | ---D | M] -- C:\Users\Graciele\AppData\Roaming\Windows Live Writer
[2012/11/13 19:01:33 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\ADPHONE
[2011/01/08 18:42:25 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\DAEMON Tools Lite
[2011/01/12 17:24:05 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\Foxit Software
[2011/08/06 01:33:28 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\FreeFLVConverter
[2011/03/14 15:22:43 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\GIRDAC
[2011/01/05 13:58:22 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\GrabPro
[2011/04/02 19:49:48 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\Houaiss3
[2013/03/03 00:34:46 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\Motorola
[2013/03/03 00:37:56 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\Motorola Mobility
[2011/02/03 01:56:06 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\NCH Swift Sound
[2011/11/23 16:23:20 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\Nullsoft
[2013/06/01 14:03:37 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\Orbit
[2011/01/05 13:58:25 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\ProgSense
[2011/07/29 13:12:26 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\Softland
[2011/04/30 01:40:39 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\Tific
[2012/10/07 00:12:14 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\uTorrent
[2012/02/13 13:35:04 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\Visan
[2011/01/08 16:41:42 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\VitySoft
[2012/05/15 22:18:52 | 000,000,000 | ---D | M] -- C:\Users\Robson\AppData\Roaming\Windows Live Writer
[2011/09/27 01:51:59 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\ADPHONE
[2012/10/27 22:36:12 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\DAEMON Tools Lite
[2011/01/17 12:50:42 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\Foxit Software
[2011/08/06 01:42:38 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\FreeFLVConverter
[2013/03/05 11:07:16 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\Motorola Mobility
[2012/11/23 10:45:49 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\NCH Swift Sound
[2013/05/27 00:46:05 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\Orbit
[2011/01/06 19:52:46 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\ProgSense
[2011/09/26 00:30:59 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\Softland
[2011/01/09 14:21:29 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\VitySoft
[2011/01/11 00:59:30 | 000,000,000 | ---D | M] -- C:\Users\Win!!!\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< C:\windows\system32\Tasks\*.* /64 >
[2013/05/14 15:17:19 | 000,003,840 | ---- | M] () -- C:\Windows\SysNative\Tasks\Adobe Flash Player Updater
[2013/05/02 00:45:30 | 000,003,812 | ---- | M] () -- C:\Windows\SysNative\Tasks\GoogleUpdateTaskMachineCore
[2013/05/02 00:45:31 | 000,004,064 | ---- | M] () -- C:\Windows\SysNative\Tasks\GoogleUpdateTaskMachineUA
[2012/09/01 14:15:47 | 000,003,350 | ---- | M] () -- C:\Windows\SysNative\Tasks\HP Photo Creations Communicator
[2012/01/25 20:12:27 | 000,003,634 | ---- | M] () -- C:\Windows\SysNative\Tasks\HPCustParticipation HP Photosmart Plus B210 series
[2012/12/02 04:30:44 | 000,007,870 | ---- | M] () -- C:\Windows\SysNative\Tasks\hpwebreg_xxxxxxxxxx
[2013/06/01 00:44:17 | 000,003,470 | ---- | M] () -- C:\Windows\SysNative\Tasks\Motorola Device Manager Engine
[2013/06/01 00:44:18 | 000,003,296 | ---- | M] () -- C:\Windows\SysNative\Tasks\Motorola Device Manager Initial Update
[2013/06/01 00:44:16 | 000,003,488 | ---- | M] () -- C:\Windows\SysNative\Tasks\Motorola Device Manager Update
[2013/02/11 21:04:37 | 000,003,234 | ---- | M] () -- C:\Windows\SysNative\Tasks\Norton WSC Integration
[2011/06/03 00:08:03 | 000,003,148 | ---- | M] () -- C:\Windows\SysNative\Tasks\SidebarExecute
[2013/03/16 10:56:47 | 000,003,950 | ---- | M] () -- C:\Windows\SysNative\Tasks\User_Feed_Synchronization-{90C65472-9618-43E6-AF8E-D79CA7F75A18}
[2013/03/16 19:40:38 | 000,003,950 | ---- | M] () -- C:\Windows\SysNative\Tasks\User_Feed_Synchronization-{D12ABB5C-9EEB-4FE7-9FBD-57105DCD2120}
[2013/04/15 11:35:42 | 000,003,958 | ---- | M] () -- C:\Windows\SysNative\Tasks\User_Feed_Synchronization-{FC57EC46-8AE8-4D01-AEB8-33CA4FDF177D}
[2011/08/23 00:30:15 | 000,003,056 | ---- | M] () -- C:\Windows\SysNative\Tasks\{1E851435-BCFC-46C9-989B-D44DD3645A05}
[2012/05/14 02:34:32 | 000,003,202 | ---- | M] () -- C:\Windows\SysNative\Tasks\{27959614-E772-4C36-909B-8401FCBA77FF}
[2012/05/14 02:36:19 | 000,003,202 | ---- | M] () -- C:\Windows\SysNative\Tasks\{327D6E49-90D0-469A-815F-0555CDE3DC46}
[2013/05/19 22:02:40 | 000,003,086 | ---- | M] () -- C:\Windows\SysNative\Tasks\{38426C6D-F9DA-4587-A5F2-6CF1429EA62B}
[2012/05/14 02:37:18 | 000,003,202 | ---- | M] () -- C:\Windows\SysNative\Tasks\{4FE584C7-ADB5-4D38-9F31-20AC35AB560E}
[2012/05/14 02:39:25 | 000,003,202 | ---- | M] () -- C:\Windows\SysNative\Tasks\{554E01B7-B4FA-4A14-9503-BC13D1B49259}
[2011/08/23 00:31:31 | 000,003,056 | ---- | M] () -- C:\Windows\SysNative\Tasks\{61552AC9-67BE-411A-9BE0-9D5B2DEA7B97}
[2012/01/29 11:02:43 | 000,003,014 | ---- | M] () -- C:\Windows\SysNative\Tasks\{931161B7-B04F-437B-AE0D-1E78B1C63647}
[2012/05/14 02:42:42 | 000,003,202 | ---- | M] () -- C:\Windows\SysNative\Tasks\{B9EA6D98-6172-4B12-8F6A-85CF4915208B}
[2011/08/23 00:30:42 | 000,003,056 | ---- | M] () -- C:\Windows\SysNative\Tasks\{C96C6282-266C-4122-9A8A-C0945BD70E14}
[2012/05/14 02:37:58 | 000,003,202 | ---- | M] () -- C:\Windows\SysNative\Tasks\{E3246E44-7E5C-441C-9BBE-2E09B77A912E}
[2012/05/14 02:38:35 | 000,003,202 | ---- | M] () -- C:\Windows\SysNative\Tasks\{E4129F6C-9008-4F0C-834B-E4F6C2A9BD35}
[2012/01/29 11:07:14 | 000,003,014 | ---- | M] () -- C:\Windows\SysNative\Tasks\{E5ABD05E-D3BA-4DE4-98D0-BAD023D333C7}
[2011/04/02 20:05:06 | 000,002,958 | ---- | M] () -- C:\Windows\SysNative\Tasks\{EB14CDEB-D401-40A6-81A1-60C5F114AFBC}
[2012/11/04 00:49:41 | 000,003,234 | ---- | M] () -- C:\Windows\SysNative\Tasks\{F6EADE02-B01E-4ABE-9DB4-DBDABB9941D7}
[2009/07/14 02:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009/07/14 02:08:49 | 000,032,608 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/01/25 20:13:44 | 000,005,158 | ---- | C] () -- C:\Windows\Tasks\hpwebreg_xxxxxxxxxx.job
[2012/01/25 20:16:36 | 000,000,340 | ---- | C] () -- C:\Windows\Tasks\HP Photo Creations Communicator.job
[2012/08/13 00:56:01 | 000,000,902 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012/11/17 15:33:53 | 000,001,064 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012/11/17 15:33:54 | 000,001,068 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

< %windir%\tasks\*.* >
[2013/06/03 12:16:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/03 22:25:45 | 000,001,064 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/03 22:50:01 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/03 22:52:48 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2012/12/02 04:30:44 | 000,005,158 | ---- | M] () -- C:\Windows\tasks\hpwebreg_xxxxxxxxxx.job
[2013/06/03 22:25:26 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2013/05/08 14:37:46 | 000,032,608 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes >
"DefaultScope" =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]

< HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes >
"DefaultScope" = {C1DDD436-51A5-4366-96E6-9475805CB813}
"DownloadUpdates" = 1
"Version" = 3
"UpgradeTime" = 89 0D B0 C0 75 46 CE 01 [binary data]
"ShowSearchSuggestionsInAddressGlobal" = 0
"KnownProvidersUpgradeTime" = D6 49 30 BF 75 46 CE 01 [binary data]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C1DDD436-51A5-4366-96E6-9475805CB813}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FF46EF4A-CE07-4CC6-85F9-BCE5B75772D8}]
< End of report >
Robson ls
Robson ls Membro Senior Registrado
236 Mensagens 13 Curtidas
#13 Por Robson ls
04/06/2013 - 21:42
Resultado: https://www.virustotal.com/pt/file/eeabb0fa519d90987c4c6576640efc72a2cbff383622dab02f48977327da0e1c/analysis/1370392778/

Amigo, ontem o Norton deu um aviso de que um malware alterou minha homepage assim que abri o IE... Meu pc continua com esse problema chato com o mouse... será que terei que reinstalar o windows? O vírus pode ter causado alguma modificação no sistema pra fazer isso com as funções do mouse?
Wings
Wings Cyber Highlander Registrado
20.3K Mensagens 1.2K Curtidas
#14 Por Wings
04/06/2013 - 21:48
Seu problema não está relacionado a vírus.

Irei remover algumas entradas sem arquivos do PC.


veja.png Execute o OTL

*Copie e cole as linhas em marrom no espaço abaixo de Exames Personalizados/Correções


:OTL
DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x64\Sandra.sys -- (SANDRA)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.oquefazernainternet.com/
O4 - HKLM..\Run: [] File not found
O4 - Startup: C:\Users\Robson\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\Conexão de Banda Larga - Atalho.lnk = File not found
O4 - Startup: C:\Users\Robson\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = File not found
O4 - Startup: C:\Users\Win!!!\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = File not found

:Commands
[emptytemp]


*Clique [Consertar]

Imagem

*Clique [OK] para reiniciar o PC

Imagem

*Ao reiniciar, surgirá uma janela de Aviso de Segurança do Windows, perguntando se deseja executar o OTL. Clique [Executar]

Imagem

*Cole o relatório apresentado após a inicialização do Windows
Robson ls
Robson ls Membro Senior Registrado
236 Mensagens 13 Curtidas
#15 Por Robson ls
04/06/2013 - 22:28
Eu testei um outro mouse, mas o problema continuou... Estranhamente ele sempre volta a funcionar depois que dou ctrl+alt+del...
Obrigado mais uma vez!

Aqui vai o log:

All processes killed
========== OTL ==========
Service SANDRA stopped successfully!
Service SANDRA deleted successfully!
File C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x64\Sandra.sys not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\Default_Search_URL| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
File move failed. C:\Users\Robson\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\Conexão de Banda Larga - Atalho.lnk scheduled to be moved on reboot.
File move failed. C:\Users\Robson\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk scheduled to be moved on reboot.
File move failed. C:\Users\Win!!!\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk scheduled to be moved on reboot.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Graciele
->Temp folder emptied: 7473651 bytes
->Temporary Internet Files folder emptied: 3150672363 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 400449341 bytes
->Flash cache emptied: 1243 bytes

User: Public
->Temp folder emptied: 0 bytes

User: Robson
->Temp folder emptied: 143531921 bytes
->Temporary Internet Files folder emptied: 4115812843 bytes
->Java cache emptied: 330319 bytes
->Google Chrome cache emptied: 325529513 bytes
->Flash cache emptied: 63403 bytes

User: Todos os Usuários

User: Usuário Padrão
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Win!!!
->Temp folder emptied: 64671362 bytes
->Temporary Internet Files folder emptied: 11972990348 bytes
->Java cache emptied: 34838 bytes
->Google Chrome cache emptied: 358826637 bytes
->Flash cache emptied: 19186387 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 171459046 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 95712 bytes
RecycleBin emptied: 5682023 bytes

Total Files Cleaned = 19.776,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 06042013_215608
Files\Folders moved on Reboot...
File\Folder C:\Users\Robson\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\Conexão de Banda Larga - Atalho.lnk not found!
File\Folder C:\Users\Robson\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk not found!
File\Folder C:\Users\Win!!!\AppData\Roaming\Microsoft\Windows\ Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk not found!
C:\Users\Robson\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Robson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Robson\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db moved successfully.
File\Folder C:\Users\Robson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZJIQVS51\Messenger[1].htm not found!
C:\Users\Robson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JXJRF2E9\index[1].htm moved successfully.
C:\Users\Robson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JXJRF2E9\RteFrameResources[1].htm moved successfully.
C:\Users\Robson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JX9WE9H8\AjaxHistoryFrame[1].htm moved successfully.
File\Folder C:\Users\Robson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JX9WE9H8\default[1].htm not found!
C:\Users\Robson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1E7LFQTQ\xd_arbiter[1].htm moved successfully.
C:\Users\Robson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1E7LFQTQ\xd_arbiter[2].htm moved successfully.
C:\Users\Robson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\Robson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
C:\Windows\temp\vmware-SISTEMA-3687049583\vmware-usbarb-SISTEMA-1968.log moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal