warner 0 Denunciar post Postado Setembro 10, 2006 Boa noite a todos. O meu mouse esta se movimentando sem o meu comando, não obedece ao meu comando e fica abrindo janelas com se estivese sendo clicado com o botão direito. Acho q tem alguma coisa com "MSNMSNR.SCR", pois quando eu o finalizo no gerenciado de tarefas fica um pouco melhor. Ao utiliza alt + tab aparece os iconis dos programas abertos + o icone no msn ESCRITO "FORM 1" e ao finalizar "MSNMSNR.SCR" ele some. Esse log foi tirado sem finalizar o "MSNMSNR.SCR" Desde já agradeço a atenção. Logfile of HijackThis v1.99.1 Scan saved at 20:06:44, on 10/9/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\pctspk.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe C:\Arquivos de programas\D-Link\DSL-210\CnxDslTb.exe C:\WINDOWS\system32\msnmsnr.scr C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\WINDOWS\system32\hosts.scr C:\Arquivos de programas\eMule\emule.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe C:\Arquivos de programas\IC Media Corp\ICM532\Launchpad.exe C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\alexa\Desktop\virus\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com.br/0SEPTBR/SAOS01 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\Yahoo! Acesso Gratis\bho.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\ARQUIV~1\FLASHGET\jccatch.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\fgiebar.dll O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Arquivos de programas\D-Link\DSL-210\CnxDslTb.exe" O4 - HKLM\..\Run: [Msn Messenger] C:\WINDOWS\system32\msnmsnr.scr O4 - HKCU\..\Run: [LightDialer] C:\Arquivos de programas\Turbo\Discador Turbo\DISCADOR.EXE O4 - HKCU\..\Run: [tark] C:\WINDOWS\system32\hosts.scr O4 - HKCU\..\Run: [eMuleAutoStart] C:\Arquivos de programas\eMule\emule.exe -AutoStart O4 - Global Startup: Launchpad.lnk = ? O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm O8 - Extra context menu item: Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\ARQUIV~1\YAHOO!\COMMON\yhexbmesbr.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\ARQUIV~1\YAHOO!\COMMON\yhexbmesbr.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab34246.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{547F72F5-4E3C-4D93-827A-EEED1C9A4446}: NameServer = 200.199.241.38,200.199.241.17 O17 - HKLM\System\CCS\Services\Tcpip\..\{9F0973B4-ACA4-410F-A533-6CB391A9D1D1}: NameServer = 201.10.128.2 201.10.120.2 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe Compartilhar este post Link para o post Compartilhar em outros sites
Waggamama 0 Denunciar post Postado Setembro 11, 2006 Olá warner Há infeçção por Banker, um trojan que rouba senhas e as envia á um Hacker. Faça o download da ferramenta clicando no link abaixo: http://linhadefensiva.uol.com.br/dl/bankerfix Salve a ferramenta no seu disco rígido Clique em bankerfix.exe; Pressione Enter Espere terminar Um relatorio será salvo em C:\LinhaDefensiva\relatorio.txt Gere um novo log do hijackthis e poste + Log BankerFix Waggamama. Abraços :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
warner 0 Denunciar post Postado Setembro 11, 2006 Bom dia waggamama. Acho q fiz besteira, eu executei 2 vezes o probrama BANHERFIX e apagou o 1º relatorio e esse é o 2º. Depois q execudei o BANKERFIX o meu mouse continua a mesma coisa. Também executei o HijackThis depois do BANKERFIX Obrigado pela atenção. INICIANDO BANKER FIX ======================================================= INICIANDO FOX FIX ======================================================= Iniciando Log do PV ----------------------------------- Killing '*' Arquivos a remover ----------------------------------- Arquivos ruins restantes ----------------------------------- Reg Importado ----------------------------------- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Logfile of HijackThis v1.99.1 Scan saved at 02:00:17, on 11/9/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\pctspk.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe C:\Arquivos de programas\D-Link\DSL-210\CnxDslTb.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\WINDOWS\system32\hosts.scr C:\Arquivos de programas\eMule\emule.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe C:\Arquivos de programas\IC Media Corp\ICM532\Launchpad.exe C:\WINDOWS\system32\wuauclt.exe C:\Arquivos de programas\Internet Explorer\iexplore.exe C:\Documents and Settings\alexa\Desktop\virus\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com.br/0SEPTBR/SAOS01 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\Yahoo! Acesso Gratis\bho.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\ARQUIV~1\FLASHGET\jccatch.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\fgiebar.dll O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Arquivos de programas\D-Link\DSL-210\CnxDslTb.exe" O4 - HKCU\..\Run: [LightDialer] C:\Arquivos de programas\Turbo\Discador Turbo\DISCADOR.EXE O4 - HKCU\..\Run: [tark] C:\WINDOWS\system32\hosts.scr O4 - HKCU\..\Run: [eMuleAutoStart] C:\Arquivos de programas\eMule\emule.exe -AutoStart O4 - Global Startup: Launchpad.lnk = ? O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm O8 - Extra context menu item: Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\ARQUIV~1\YAHOO!\COMMON\yhexbmesbr.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\ARQUIV~1\YAHOO!\COMMON\yhexbmesbr.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab34246.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{547F72F5-4E3C-4D93-827A-EEED1C9A4446}: NameServer = 200.199.241.38,200.199.241.17 O17 - HKLM\System\CCS\Services\Tcpip\..\{9F0973B4-ACA4-410F-A533-6CB391A9D1D1}: NameServer = 201.10.128.2 201.10.120.2 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe Compartilhar este post Link para o post Compartilhar em outros sites
Waggamama 0 Denunciar post Postado Setembro 11, 2006 Olá warner Bom dia... Faça o Download do Pocket Killbox Salve numa pasta em C:\ Rode-o. Marque a função Delete on Reboot na caixa Full path of file to delete insira esta linha: C:\WINDOWS\system32\hosts.scr Clique no botão Single File e clique no X e responda Sim a pergunta. Reinicie o PC em Modo Seguro...(Pressionando itermintentemente a tecla F8 e no menu que aparecerá escolha Modo Seguro). Rode o Hijackthis. Clique em Do a system scan and a logfile e dê um Fix Checked na seguinte entrada: O4 - HKCU\..\Run: [tark] C:\WINDOWS\system32\hosts.scr Feche o Hijackthis. Reinicie em Modo Normal, gere um novo log e poste. Waggamama. Abraços :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
warner 0 Denunciar post Postado Setembro 11, 2006 Ola Waggamama. O mouse ainda esta sem controle. ai esta o novo log Logfile of HijackThis v1.99.1 Scan saved at 12:42:20, on 11/9/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\pctspk.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe C:\Arquivos de programas\D-Link\DSL-210\CnxDslTb.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\Arquivos de programas\eMule\emule.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe C:\Arquivos de programas\IC Media Corp\ICM532\Launchpad.exe C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\alexa\Desktop\virus\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com.br/0SEPTBR/SAOS01 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\Yahoo! Acesso Gratis\bho.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\ARQUIV~1\FLASHGET\jccatch.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\fgiebar.dll O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Arquivos de programas\D-Link\DSL-210\CnxDslTb.exe" O4 - HKCU\..\Run: [LightDialer] C:\Arquivos de programas\Turbo\Discador Turbo\DISCADOR.EXE O4 - HKCU\..\Run: [eMuleAutoStart] C:\Arquivos de programas\eMule\emule.exe -AutoStart O4 - Global Startup: Launchpad.lnk = ? O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm O8 - Extra context menu item: Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\ARQUIV~1\YAHOO!\COMMON\yhexbmesbr.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\ARQUIV~1\YAHOO!\COMMON\yhexbmesbr.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab34246.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{547F72F5-4E3C-4D93-827A-EEED1C9A4446}: NameServer = 200.199.241.38,200.199.241.17 O17 - HKLM\System\CCS\Services\Tcpip\..\{9F0973B4-ACA4-410F-A533-6CB391A9D1D1}: NameServer = 201.10.128.2 201.10.120.2 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe Compartilhar este post Link para o post Compartilhar em outros sites
Waggamama 0 Denunciar post Postado Setembro 11, 2006 Olá warner O Log está limpo...creio que o problema não seja Malwares, mas faça um Scan Online: http://www.pandasoftware.com/activescan/ Após o termino, salve o log e poste. Waggamma. Abraços :thumbsup: Compartilhar este post Link para o post Compartilhar em outros sites
warner 0 Denunciar post Postado Setembro 12, 2006 Ola wagamama.fiz o scan com o panda ta ai o log.Incident Status Location Virus:Trj/Banbra.CGO Disinfected C:\WINDOWS\system32\leetch32.exe Dialer:Dialer.B Not disinfected C:\WINDOWS\ExeDialer.exe Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Configurações locais\Temp\Cookies\alexa@google.com[1].txt Spyware:Cookie/Admotion Not disinfected C:\Documents and Settings\alexa\Configurações locais\Temp\Cookies\alexa@admotion.com[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Configurações locais\Temp\Cookies\alexa@terra.com[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Configurações locais\Temp\Cookies\alexa@uol.com[1].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\alexa\Configurações locais\Temp\Cookies\alexa@ad.yieldmanager[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Configurações locais\Temp\Cookies\alexa@de.uol.com[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Configurações locais\Temp\Cookies\alexa@ig.com[1].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\alexa\Configurações locais\Temp\Cookies\alexa@ad.yieldmanager[2].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Configurações locais\Temp\Cookies\alexa@uol.com[2].txt Dialer:dialer.akd Not disinfected C:\Documents and Settings\alexa\Meus documentos\W1inMoviePlugIn.lnk Spyware:Cookie/Admotion Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@admotion.com[1].txt Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@findwhat[1].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@atdmt[2].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@de.uol.com[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@terra.com[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ig.com[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@dist.belnk[1].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@zedo[2].txt Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@valueclick[1].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@doubleclick[1].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@as1.falkag[1].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@tribalfusion[2].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@hitbox[1].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@phg.hitbox[2].txt Spyware:Cookie/web-stat Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@www.web-stat[1].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@hg1.hitbox[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@com[2].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@overture[2].txt Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@sexlist[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@google.com[1].txt Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@yadro[2].txt Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@toplist[1].txt Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@counter14.sextracker[1].txt Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@sextracker[2].txt Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@rightmedia[1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@advertising[2].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@fastclick[1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@servedby.advertising[1].txt Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@bravenet[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@realmedia[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@google.com[4].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@advertising[1].txt Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@sexlist[2].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@mediaplex[1].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@questionmarket[1].txt Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@adopt.hbmediapro[2].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@uol.com[1].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@zedo[3].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@hitbox[3].txt Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ccbill[1].txt Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@spylog[1].txt Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@cs.sexcounter[2].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@phg.hitbox[3].txt Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@z1.adserver[1].txt Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@counter9.sextracker[1].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@overture[3].txt Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@statcounter[1].txt Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@paycounter[1].txt Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@landing.domainsponsor[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@google.com[2].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ads.pointroll[2].txt Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@counter5.sextracker[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@as-us.falkag[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@dist.belnk[3].txt Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@counter14.sextracker[2].txt Spyware:Cookie/XXXCounter Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@xxxcounter[2].txt Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@revenue[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@realmedia[2].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@atwola[1].txt Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@weborama[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@fastclick[3].txt Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ads.addynamix[2].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@trafficmp[1].txt Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@stats1.reliablestats[2].txt Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@statse.webtrendslive[1].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@hg1.hitbox[3].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ig.com[3].txt Spyware:Cookie/Match Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@promo.match[2].txt Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@2o7[2].txt Spyware:Cookie/Paypopup Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@paypopup[1].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@casalemedia[2].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@servedby.advertising[3].txt Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@searchportal.information[2].txt Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@bravenet[1].txt Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@hc2.humanclick[1].txt Spyware:Cookie/Admotion Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@admotion.com[3].txt Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@server.iad.liveperson[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@uol.com[3].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@serving-sys[1].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ad.yieldmanager[2].txt Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@spylog[2].txt Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@statcounter[3].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@cgi-bin[7].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@dist.belnk[4].txt Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@c.goclick[1].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@serving-sys[3].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@google.com[3].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@casalemedia[3].txt Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@apmebf[2].txt Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@qksrv[2].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@overture[4].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@247realmedia[1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@advertising[4].txt Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@2o7[1].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@cgi-bin[8].txt Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@adopt.hbmediapro[3].txt Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@tucows[2].txt Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@weborama[3].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@questionmarket[2].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@hitbox[2].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@atwola[2].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@hg1.hitbox[4].txt Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@gostats[2].txt Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@z1.adserver[3].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ehg-dig.hitbox[2].txt Spyware:Cookie/Itrack Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ilead.itrack[1].txt Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@stat.onestat[1].txt Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@stats1.reliablestats[3].txt Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@winfixer[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ig.com[1].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@realmedia[3].txt Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ads.addynamix[3].txt Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@revenue[3].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ads.pointroll[1].txt Spyware:Cookie/XXXCounter Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@xxxcounter[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@uol.com[4].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@phg.hitbox[4].txt Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@counter15.sextracker[1].txt Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ccbill[2].txt Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@hc2.humanclick[3].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@media.fastclick[2].txt Spyware:Cookie/Paypopup Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@paypopup[2].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@cgi-bin[9].txt Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@burstnet[2].txt Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@adultfriendfinder[2].txt Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@counter5.sextracker[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@fastclick[2].txt Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@bravenet[4].txt Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@paycounter[3].txt Spyware:Cookie/Admotion Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@admotion.com[2].txt Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@counter8.sextracker[2].txt Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@counter14.sextracker[3].txt Spyware:Cookie/GangbangSquad Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@gangbangsquad[1].txt Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@counter9.sextracker[3].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@trafficmp[2].txt Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@statse.webtrendslive[3].txt Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@server.iad.liveperson[3].txt Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@errorsafe[2].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@zedo[1].txt Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@landing.domainsponsor[3].txt Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@fe.lea.lycos[2].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@ad.yieldmanager[3].txt Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@bluestreak[1].txt Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\alexa\Cookies\alexa@searchportal.information[3].txt Dialer:Dialer.GRA Not disinfected C:\Downloads\videosessoestremo.exe Adware:Adware/ClockSync Not disinfected C:\Downloads\bsplayer139.829.exe[VVSNInst.exe] Virus:Trj/Banker.EGU Disinfected C:\!KillBox\hosts.scr Compartilhar este post Link para o post Compartilhar em outros sites
Waggamama 0 Denunciar post Postado Setembro 12, 2006 Opa warner, Faça o Download do ATF-Cleaner Salve no seu Desktop. Rode o Killbox. Marque Delete on Reboot, copie as linhas abaixo(Ctrl+C): C:\WINDOWS\ExeDialer.exe C:\Documents and Settings\alexa\Meus documentos\W1inMoviePlugIn.lnk C:\Downloads\videosessoestremo.exe C:\Downloads\bsplayer139.829.exe Clique em File, e clique emPaste from clipboard. Clique no botão All Files e em seguida clique no X e responda Sim. Reincie em Modo Seguro...(Pressionando itermintentemente a tecla F8 e no menu que aparecerá escolha Modo Seguro). Execute o ATF-Cleaner. Marque a opção Select All e clique no botão Empty Selected. Reinicie em Modo Normal... abraço, Compartilhar este post Link para o post Compartilhar em outros sites
warner 0 Denunciar post Postado Setembro 15, 2006 Ola Waggamama Obrigado pela ajuda. Estou mandando o Log do hijackthis para, se você achar necessário, da uma útima olhada. Valeu mesmo. Logfile of HijackThis v1.99.1 Scan saved at 15:09:23, on 15/9/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\WINDOWS\system32\pctspk.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe C:\Arquivos de programas\D-Link\DSL-210\CnxDslTb.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\Arquivos de programas\eMule\emule.exe C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe C:\Arquivos de programas\IC Media Corp\ICM532\Launchpad.exe C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\alexa\Desktop\virus\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com.br/0SEPTBR/SAOS01 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &http://home.microsoft.com/intl/br/access/allinone.asp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://br.yahoo.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARQUIV~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: IbestBHO Class - {7E6CDC1C-3B90-47D7-B2A8-24438CA96075} - C:\Arquivos de programas\Yahoo! Acesso Gratis\bho.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\ARQUIV~1\FLASHGET\jccatch.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\fgiebar.dll O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Arquivos de programas\D-Link\DSL-210\CnxDslTb.exe" O4 - HKCU\..\Run: [LightDialer] C:\Arquivos de programas\Turbo\Discador Turbo\DISCADOR.EXE O4 - HKCU\..\Run: [eMuleAutoStart] C:\Arquivos de programas\eMule\emule.exe -AutoStart O4 - Global Startup: Launchpad.lnk = ? O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm O8 - Extra context menu item: Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\ARQUIV~1\YAHOO!\COMMON\yhexbmesbr.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\ARQUIV~1\YAHOO!\COMMON\yhexbmesbr.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARQUIV~1\FLASHGET\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab34246.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{547F72F5-4E3C-4D93-827A-EEED1C9A4446}: NameServer = 200.199.241.38,200.199.241.17 O17 - HKLM\System\CCS\Services\Tcpip\..\{9F0973B4-ACA4-410F-A533-6CB391A9D1D1}: NameServer = 201.10.128.2 201.10.120.2 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe Compartilhar este post Link para o post Compartilhar em outros sites
Shine 0 Denunciar post Postado Outubro 20, 2006 TÓPICO ARQUIVADO Como o autor não respondeu por mais de 20 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites