Logfile da Trend Micro HijackThis 2.0.2
Varredura salva às 15:25:01, em 04/05/2009
Plataforma: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Modo de inicialização: Normal
Processos em execução:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LckFldService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Arquivos Files\Eset\nod32krn.exe
C:\WINDOWS\system32\wdfmgr.exe
Explorer
C:\WINDOWS\System32\alg.exe
C:\Arquivos Files\Java\jre6\bin\jusched.exe
C:\Arquivos Files\MagicDisc\MagicDisc.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R3 - URLSearchHook: Barra de ferramentas Yahoo!-{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA1\YAHOO!\Companion\Installs\cpn\yt.dll
O2 - BHO: & Yahoo! Toolbar Helper-{02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA1\YAHOO!\Companion\Installs\cpn\yt.dll
O2 - BHO: (sem nome)-{0F610C9D-DCCB-4513-A866-5651EDB30A0C} - C:\WINDOWS\system32\extsu.dll
O2 - BHO: (sem nome)-{20AF2A03-F27D-4528-984F-F4DEF6096150} - c:\windows\system32\eanqeaf.dll
O2 - BHO: Java (tm) plug-in 2 SSV Helper-{DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl-{E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Classe SingleInstance-{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA1\YAHOO!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Barra de ferramentas Yahoo!-{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA1\YAHOO!\Companion\Installs\cpn\yt.dll
O4 - HKLM\...\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\...\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKUS\S-1-5-18\...\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\...\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'SYSTEM')
O4 - HKUS\.DEFAULT\...\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: MagicDisc.lnk = c:\Arquivos Files\MagicDisc\MagicDisc.exe
S8 - item de menu de contexto Extra: E & xportar para o Microsoft Excel - res: / / C:\PROGRA1\MICROS2\Office10\EXCEL.EXE/3000
S9 - botão Extra: Messenger-{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
S9 - Extra 'Tools' menuitem: Windows Messenger-{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon notificar: czklxcsu - C:\WINDOWS\SYSTEM32\eanqeaf.dll
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - c:\Arquivos Files\Java\jre6\bin\jqs.exe
O23 - Service: LckFldService - proprietário desconhecido - C:\WINDOWS\system32\LckFldService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - c:\Arquivos de Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - c:\Arquivos de programas\Arquivos Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - c:\Arquivos Files\Eset\nod32krn.exe
Fim de arquivo - 3586 bytes