Sei sulla pagina 1di 9

Logfile created: 23/09/2011 18:38:28 Ad-Aware version: 9.0.7 Extended engine: 3 Extended engine version: 3.1.

2770 User performing scan: Tonin *********************** Definitions database information *********************** Lavasoft definition file: 150.577 Genotype definition file version: 2011/09/01 12:38:06 Extended engine definition file: 10538.0 ******************************** Scan results: ********************************* Scan profile name: Smart Scan (ID: smart) Objects scanned: 73460 Objects detected: 1 Type Detected ========================== Processes.......: 0 Registry entries: 0 Hostfile entries: 0 Files...........: 1 Folders.........: 0 LSPs............: 0 Cookies.........: 0 Browser hijacks.: 0 MRU objects.....: 0

Quarantined items: Description: c:\users\tonin\appdata\local\microsoft\windows\temporary internet f iles\content.ie5\cekfqp63\atualizacao[1].exe Family Name: Trojan.Win32.Generic.p ak!cobra Engine: 3 Clean status: Success Item ID: 1 Family ID: 0 MD5: d1ef5ea5d6 2d7db0321287d84bcdfe85 Scan and cleaning complete: Finished correctly after 1027 seconds *********************************** Settings *********************************** Scan profile: ID: smart, enabled:1, value: Smart Scan ID: folderstoscan, enabled:1, value: ID: useantivirus, enabled:1, value: true ID: sections, enabled:1 ID: scancriticalareas, enabled:1, value: true ID: scanrunningapps, enabled:1, value: true ID: scanregistry, enabled:1, value: true ID: scanlsp, enabled:1, value: true ID: scanads, enabled:1, value: false ID: scanhostsfile, enabled:1, value: false ID: scanmru, enabled:1, value: false ID: scanbrowserhijacks, enabled:1, value: true ID: scantrackingcookies, enabled:1, value: true ID: closebrowsers, enabled:1, value: false ID: filescanningoptions, enabled:1 ID: archives, enabled:1, value: false ID: onlyexecutables, enabled:1, value: true ID: skiplargerthan, enabled:1, value: 20480

ID: scanrootkits, enabled:1, value: true ID: rootkitlevel, enabled:1, value: mild, domain: medium,mild,strict ID: usespywareheuristics, enabled:1, value: true Scan global: ID: global, enabled:1 ID: addtocontextmenu, enabled:1, value: true ID: playsoundoninfection, enabled:1, value: false ID: soundfile, enabled:0, value: N/A Scheduled scan settings: <Empty> Update settings: ID: updates, enabled:1 ID: launchthreatworksafterscan, enabled:1, value: silently, domain: normal,off ,silently ID: deffiles, enabled:1, value: downloadandinstall, domain: dontcheck,download andinstall ID: licenseandinfo, enabled:1, value: downloadandinstall, domain: dontcheck,do wnloadandinstall ID: schedules, enabled:1, value: true ID: updatedaily1, enabled:1, value: Daily 1 ID: time, enabled:1, value: Mon Aug 01 10:37:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systems tart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updatedaily2, enabled:1, value: Daily 2 ID: time, enabled:1, value: Mon Aug 01 16:37:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systems tart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updatedaily3, enabled:1, value: Daily 3 ID: time, enabled:1, value: Mon Aug 01 22:37:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systems tart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false

ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updatedaily4, enabled:1, value: Daily 4 ID: time, enabled:1, value: Mon Aug 01 04:37:00 2011 ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systems tart,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: false ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: false ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false ID: updateweekly1, enabled:1, value: Weekly ID: time, enabled:1, value: Mon Aug 01 10:37:00 2011 ID: frequency, enabled:1, value: weekly, domain: daily,monthly,once,system start,weekly ID: weekdays, enabled:1 ID: monday, enabled:1, value: true ID: tuesday, enabled:1, value: false ID: wednesday, enabled:1, value: false ID: thursday, enabled:1, value: true ID: friday, enabled:1, value: false ID: saturday, enabled:1, value: false ID: sunday, enabled:1, value: false ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 ID: scanprofile, enabled:1, value: ID: auto_deal_with_infections, enabled:1, value: false Appearance settings: ID: appearance, enabled:1 ID: skin, enabled:1, value: Default.eGL, reglocation: HKEY_LOCAL_MACHINE\SOFTW ARE\Lavasoft\Ad-Aware\Resource ID: showtrayicon, enabled:1, value: true ID: autoentertainmentmode, enabled:1, value: true ID: guimode, enabled:1, value: mode_simple, domain: mode_advanced,mode_simple ID: language, enabled:1, value: en, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\L avasoft\Ad-Aware\Language Realtime protection settings: ID: realtime, enabled:1 ID: infomessages, enabled:1, value: onlyimportant, domain: display,dontnotify, onlyimportant ID: layers, enabled:1 ID: useantivirus, enabled:1, value: true ID: usespywareheuristics, enabled:1, value: true ID: maintainbackup, enabled:1, value: true ID: modules, enabled:1 ID: processprotection, enabled:1, value: true ID: onaccessprotection, enabled:1, value: true ID: registryprotection, enabled:1, value: true

ID: networkprotection, enabled:1, value: true ****************************** System information ****************************** Computer name: TONIN-PC Processor name: Pentium(R) Dual-Core CPU T4500 @ 2.30GHz Processor identifier: Intel64 Family 6 Model 23 Stepping 10 Processor speed: ~2294MHZ Raw info: processorarchitecture 9, processortype 8664, processorlevel 6, process or revision 5898, number of processors 2, processor features: [MMX,SSE,SSE2,SSE3 ] Physical memory available: 2527543296 bytes Physical memory total: 4254031872 bytes Virtual memory available: 1923239936 bytes Virtual memory total: 2147352576 bytes Memory load: 40% Microsoft Service Pack 1 (build 7601) Windows startup mode: Running processes: PID: 304 name: C:\Windows\System32\smss.exe owner: SISTEMA domain: AUTORIDADE NT PID: 460 name: C:\Windows\System32\csrss.exe owner: SISTEMA domain: AUTORIDADE N T PID: 500 name: C:\Windows\System32\wininit.exe owner: SISTEMA domain: AUTORIDADE NT PID: 512 name: C:\Windows\System32\csrss.exe owner: SISTEMA domain: AUTORIDADE N T PID: 560 name: C:\Windows\System32\services.exe owner: SISTEMA domain: AUTORIDAD E NT PID: 584 name: C:\Windows\System32\lsass.exe owner: SISTEMA domain: AUTORIDADE N T PID: 592 name: C:\Windows\System32\lsm.exe owner: SISTEMA domain: AUTORIDADE NT PID: 604 name: C:\Windows\System32\winlogon.exe owner: SISTEMA domain: AUTORIDAD E NT PID: 740 name: C:\Windows\System32\svchost.exe owner: SISTEMA domain: AUTORIDADE NT PID: 824 name: C:\Windows\System32\svchost.exe owner: SERVIO DE REDE domain: AUTO RIDADE NT PID: 908 name: C:\Windows\System32\svchost.exe owner: SERVIO LOCAL domain: AUTORI DADE NT PID: 956 name: C:\Windows\System32\svchost.exe owner: SISTEMA domain: AUTORIDADE NT PID: 980 name: C:\Windows\System32\svchost.exe owner: SISTEMA domain: AUTORIDADE NT PID: 492 name: C:\Windows\System32\svchost.exe owner: SERVIO LOCAL domain: AUTORI DADE NT PID: 392 name: C:\Program Files\Dell\DellDock\DockLogin.exe owner: SISTEMA domai n: AUTORIDADE NT PID: 1100 name: C:\Windows\System32\svchost.exe owner: SERVIO DE REDE domain: AUT ORIDADE NT PID: 1240 name: C:\Windows\System32\wlanext.exe owner: SISTEMA domain: AUTORIDAD E NT PID: 1248 name: C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE owner : SISTEMA domain: AUTORIDADE NT PID: 1256 name: C:\Windows\System32\conhost.exe owner: SISTEMA domain: AUTORIDAD E NT PID: 1528 name: C:\Windows\System32\dwm.exe owner: Tonin domain: Tonin-PC PID: 1548 name: C:\Windows\explorer.exe owner: Tonin domain: Tonin-PC PID: 1940 name: C:\Windows\System32\spoolsv.exe owner: SISTEMA domain: AUTORIDAD E NT

PID: 2008 name: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnot if.exe owner: Tonin domain: Tonin-PC PID: 2024 name: C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe owner: SI STEMA domain: AUTORIDADE NT PID: 2040 name: C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe owner: Tonin dom ain: Tonin-PC PID: 1036 name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe owner: Tonin domai n: Tonin-PC PID: 1352 name: C:\Windows\System32\svchost.exe owner: SERVIO LOCAL domain: AUTOR IDADE NT PID: 1132 name: C:\Windows\System32\taskhost.exe owner: Tonin domain: Tonin-PC PID: 1364 name: C:\Windows\System32\igfxtray.exe owner: Tonin domain: Tonin-PC PID: 1404 name: C:\Windows\System32\hkcmd.exe owner: Tonin domain: Tonin-PC PID: 1376 name: C:\Windows\System32\igfxpers.exe owner: Tonin domain: Tonin-PC PID: 1428 name: C:\Program Files\Synaptics\SynTP\SynTPHelper.exe owner: Tonin do main: Tonin-PC PID: 1440 name: C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe owner: Tonin domain: Tonin-PC PID: 1472 name: C:\Program Files (x86)\Efficient Sticky Notes\EfficientStickyNot es.exe owner: Tonin domain: Tonin-PC PID: 1720 name: C:\Program Files (x86)\WSED\WSED.exe owner: Tonin domain: ToninPC PID: 1728 name: C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ issch.exe owner: Tonin domain: Tonin-PC PID: 2092 name: C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe owner: To nin domain: Tonin-PC PID: 2164 name: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe owner: Tonin domain: Tonin-PC PID: 2192 name: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe own er: SISTEMA domain: AUTORIDADE NT PID: 2216 name: C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.ex e owner: SISTEMA domain: AUTORIDADE NT PID: 2316 name: C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe owner: SISTEMA d omain: AUTORIDADE NT PID: 2384 name: C:\Windows\SysWOW64\svchost.exe owner: SISTEMA domain: AUTORIDAD E NT PID: 2416 name: C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe owner: SISTEMA domain: AUTORIDADE NT PID: 2516 name: C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\B inn\sqlservr.exe owner: SERVIO DE REDE domain: AUTORIDADE NT PID: 2692 name: C:\Program Files\Common Files\NATIVE INSTRUMENTS\Hardware\NIHard wareService.exe owner: SISTEMA domain: AUTORIDADE NT PID: 2776 name: C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe owner: SISTEMA domain: AUTORIDADE NT PID: 2796 name: C:\Windows\System32\conhost.exe owner: SISTEMA domain: AUTORIDAD E NT PID: 2848 name: C:\Windows\System32\drivers\o2flash.exe owner: SISTEMA domain: A UTORIDADE NT PID: 3020 name: C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE owner: SIST EMA domain: AUTORIDADE NT PID: 2088 name: C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe owner: SISTEMA domain: AUTORIDADE NT PID: 1340 name: C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe owner: SIS TEMA domain: AUTORIDADE NT PID: 2336 name: C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe ow ner: SISTEMA domain: AUTORIDADE NT PID: 2432 name: C:\Windows\System32\svchost.exe owner: SERVIO LOCAL domain: AUTOR IDADE NT PID: 2640 name: C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLID SVC.EXE owner: SISTEMA domain: AUTORIDADE NT

PID: 2340 name: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTm on.exe owner: SISTEMA domain: AUTORIDADE NT PID: 2604 name: C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLID SVCM.EXE owner: SISTEMA domain: AUTORIDADE NT PID: 3140 name: C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe ow ner: Tonin domain: Tonin-PC PID: 3236 name: C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Sch eduler\STService.exe owner: Tonin domain: Tonin-PC PID: 3760 name: C:\Windows\System32\SearchIndexer.exe owner: SISTEMA domain: AUT ORIDADE NT PID: 3840 name: C:\Windows\System32\svchost.exe owner: SERVIO DE REDE domain: AUT ORIDADE NT PID: 3924 name: C:\Windows\System32\svchost.exe owner: SERVIO LOCAL domain: AUTOR IDADE NT PID: 4536 name: C:\Windows\System32\svchost.exe owner: SISTEMA domain: AUTORIDAD E NT PID: 4688 name: C:\Windows\System32\svchost.exe owner: SISTEMA domain: AUTORIDAD E NT PID: 4572 name: C:\Program Files (x86)\Google\Google Desktop Search\GoogleDeskto p.exe owner: Tonin domain: Tonin-PC PID: 4640 name: C:\Program Files (x86)\aMSN\bin\wish.exe owner: Tonin domain: To nin-PC PID: 3164 name: C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe owner: Tonin domain: Tonin-PC PID: 1928 name: C:\Windows\System32\svchost.exe owner: SISTEMA domain: AUTORIDAD E NT PID: 2412 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe owner: Ton in domain: Tonin-PC PID: 412 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe owner: SI STEMA domain: AUTORIDADE NT PID: 5028 name: C:\Windows\System32\wbem\unsecapp.exe owner: SISTEMA domain: AUT ORIDADE NT PID: 3404 name: C:\Windows\System32\wbem\WmiPrvSE.exe owner: SISTEMA domain: AUT ORIDADE NT PID: 4372 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe owner: Toni n domain: Tonin-PC Startup items: Name: WebCheck imagepath: {E6FB5E20-DE35-11CF-9C87-00AA005127ED} Name: WSED imagepath: C:\Program Files (x86)\WSED\WSED.exe Name: GrooveMonitor imagepath: "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMon itor.exe" Name: Openwares LiveUpdate imagepath: C:\Program Files\LiveUpdate\LiveUpdate.exe Name: ISUSScheduler imagepath: "C:\Program Files (x86)\Common Files\InstallShield\UpdateSe rvice\issch.exe" -start Name: avgnt imagepath: "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /m in Name: SunJavaUpdateSched imagepath: "C:\Program Files (x86)\Common Files\Java\Java Update\jusch ed.exe" Name: Google Desktop Search imagepath: "C:\Program Files (x86)\Google\Google Desktop Search\Google Desktop.exe" /startup Name: Adobe ARM

imagepath: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM .exe" Name: EfficientStickyNotes Name: imagepath: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startu p\desktop.ini Bootexecute items: Name: imagepath: autocheck autochk * Name: imagepath: lsdelete Running services: Name: AdobeARMservice displayname: Adobe Acrobat Update Service Name: AdvancedSystemCareService displayname: Advanced SystemCare Service Name: AeLookupSvc displayname: Experincia com Aplicativo Name: AERTFilters displayname: Andrea RT Filters Service Name: Akamai displayname: Akamai NetSession Interface Name: AntiVirSchedulerService displayname: Avira AntiVir Scheduler Name: AntiVirService displayname: Avira AntiVir Guard Name: AudioEndpointBuilder displayname: Construtor de Pontos de Extremidade de udio do Windows Name: AudioSrv displayname: udio do Windows Name: BFE displayname: Mecanismo de Filtragem Bsica Name: BITS displayname: Servio de transferncia inteligente de plano de fundo Name: Browser displayname: Pesquisador de Computadores Name: CryptSvc displayname: Servios de criptografia Name: DcomLaunch displayname: Inicializador de Processo de Servidor DCOM Name: Dhcp displayname: Cliente DHCP Name: Dnscache displayname: Cliente DNS Name: DockLoginService displayname: Dock Login Service Name: DPS displayname: Servio de Diretiva de Diagnstico Name: EapHost displayname: Protocolo de Autenticao Extensvel Name: EFS displayname: EFS (Encrypting File System) Name: eventlog displayname: Log de Eventos do Windows Name: EventSystem displayname: COM+ evento do sistema Name: FontCache displayname: Servio de Cache de Fontes do Windows

Name: gpsvc displayname: Cliente da Diretiva de Grupo Name: IAANTMON displayname: Intel(R) Matrix Storage Event Monitor Name: IKEEXT displayname: Mdulos de Criao de Chaves IKE e AuthIP do IPSec Name: KeyIso displayname: Isolamento de Chave CNG Name: LanmanServer displayname: Server Name: LanmanWorkstation displayname: Estao de trabalho Name: Lavasoft Ad-Aware Service displayname: Lavasoft Ad-Aware Service Name: lmhosts displayname: Auxiliar NetBIOS TCP/IP Name: MpsSvc displayname: Firewall do Windows Name: MSSQL$SQLEXPRESS displayname: SQL Server (SQLEXPRESS) Name: Netman displayname: Conexes de Rede Name: netprofm displayname: Servio da Lista de Redes Name: NIHardwareService displayname: NIHardwareService Name: NlaSvc displayname: Reconhecimento de Locais de Rede Name: nsi displayname: Servio de Interface de Repositrio de Rede Name: O2FLASH displayname: O2FLASH Name: PcaSvc displayname: Servio Auxiliar de Compatibilidade de Programas Name: PlugPlay displayname: Plug and Play Name: PolicyAgent displayname: Agente de Diretiva IPsec Name: Power displayname: Energia Name: ProfSvc displayname: Servio de Perfil de Usurio Name: RpcEptMapper displayname: Mapeador de Ponto de Extremidade RPC Name: RpcSs displayname: Chamada de procedimento remoto (RPC) Name: SamSs displayname: Gerente de Contas de Segurana Name: Schedule displayname: Agendador de Tarefas Name: SDRSVC displayname: Backup do Windows Name: SeaPort displayname: SeaPort Name: SENS displayname: Servio de Notificao de Eventos do Sistema Name: SftService displayname: SoftThinks Agent Service Name: ShellHWDetection displayname: Deteco do hardware do shell

Name: Spooler displayname: Spooler de Impresso Name: sprtsvc_DellComms displayname: SupportSoft Sprocket Service (DellComms) Name: SQLWriter displayname: SQL Server VSS Writer Name: SSDPSRV displayname: Descoberta SSDP Name: stisvc displayname: Assistente de aquisio de imagens do Windows (WIA) Name: SysMain displayname: Superfetch Name: Themes displayname: Temas Name: TrkWks displayname: Cliente de rastreamento de link distribudo Name: upnphost displayname: Host de dispositivo UPnP Name: UxSms displayname: Gerenciador de Sesso do Gerenciador de Janelas da rea de Tr abalho Name: WdiServiceHost displayname: Host do Servio de Diagnstico Name: WerSvc displayname: Servio de Relatrios de Erro do Windows Name: WinDefend displayname: Windows Defender Name: WinHttpAutoProxySvc displayname: Servio de Descoberta Automtica de Proxy da Web do WinHTTP Name: Winmgmt displayname: Testador de instrumentao de gerenciam. do Windows Name: Wlansvc displayname: Configurao Automtica de WLAN Name: wlidsvc displayname: Windows Live ID Sign-in Assistant Name: wscsvc displayname: Central de Segurana Name: WSearch displayname: Windows Search Name: wuauserv displayname: Windows Update Name: wudfsvc displayname: Windows Driver Foundation - Estrutura do Driver de Modo d e Usurio

Potrebbero piacerti anche