Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

torugorj

[Resolvido!]Não consigo instalar nenhum antivirus!

Recommended Posts

Não consigo instalar nenhum antivirus, nenhum arquivo .exe é instalado...

*Tentei executar uma soluçao q li num topico similar e ate q consegui utilizar o cleaner de novo mas apos reiniciar a maquina voltava o problema...

*As vezes aparece uma msg:

------------------------------------------------------------------

Windows - Erro de aplicativo

A instrução no "0x4040b97d"fez referência à memória no "0x0b4c9937". A memória não pôde ser "read".

Clique 'OK' para encerrar o programa

Clique 'Cancelar' para depurar o programa

------------------------------------------------------------------

por favor me ajudem

aew o log do hijackthis

 

Logfile of HijackThis v1.99.1

Scan saved at 06:12:51, on 20/1/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\cmpe.exe

C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\MOZILLA FIREFOX\FIREFOX.EXE

C:\WINDOWS\system32\drivers\down\90812.exe

C:\Documents and Settings\PC\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.positivoinformatica.com.br/cadastro.asp

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\ARQUIVOS DE PROGRAMAS\Yahoo!\Companion\Installs\cpn0\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\ARQUIVOS DE PROGRAMAS\Yahoo!\Companion\Installs\cpn0\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.9.24.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MegauploadToolbar\megauploadtoolbar.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MegauploadToolbar\megauploadtoolbar.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\ARQUIVOS DE PROGRAMAS\Yahoo!\Companion\Installs\cpn0\yt.dll

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\ARQUIVOS DE PROGRAMAS\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\ARQUIVOS DE PROGRAMAS\DAP\dapextie2.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Publicar em Blogue - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Publicar no Blogue no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.9.24.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=http://www.positivoinformatica.com.br/

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{68D0BEAD-47BF-4FD0-A03E-B087D3238F5D}: NameServer = 200.149.55.140 200.165.132.147

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: textwareilluminatorbase - {CE5CD329-1650-414A-8DB0-4CBF72FAED87} - C:\WINDOWS\system32\textwareilluminatorbaseProtocol.dll

O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Arquivos de programas\Windows Live\Mail\mailcomm.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\ARQUIVOS DE PROGRAMAS\Ares\chatServer.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Arquivos de programas\Windows Live\installer\WLSetupSvc.exe

Compartilhar este post


Link para o post
Compartilhar em outros sites

PS.

Tento abrir o ccleaner e nao abre, tento abrir o windows defender e nao abre, o avg antivirus saiu da minha maquina e tentei reinstalar e no finalzinho deu um erro e ele nao instalou...

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia torugorj!

 

>@< Faça o download do < AVG Anti-Rootkit Free >

>@< Salve-o no Desktop! << Reserve!

_____________________

 

>@< Faça o download do EliBagla.

>@< Salve-o no Desktop!

>@< Agora,vá ao seu ícone e execute a ferramenta!

>@< Terminando,reinicie o computador em Modo de Segurança. << Importante!

>@< Rode,novamente,a ferramenta EliBagla e poste o seu relatório. ( C:\infoSat.txt )

>@< Ainda em Modo Seguro,execute o AVG Anti-Rootkit.

>@< Clique em: Search for rootkit >> Aguarde a conclusão!

>@< Procure remover os rootkits,caso os encontre!

>@< Reinicie,o computador,em Modo Normal!

>@< Execute,novamente,o AVG Anti-Rootkit. << Importante!

>@< Poste,na sua resposta,o relatório infoSAT.txt que está na raíz C:\ ( Disco Local-C ) + HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aew segue o HJT e o infosat!!!

 

Logfile of HijackThis v1.99.1

Scan saved at 11:04:20, on 20/1/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\cmpe.exe

C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\ARQUIV~1\MOZILLA FIREFOX\FIREFOX.EXE

C:\Documents and Settings\PC\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orkut.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.positivoinformatica.com.br/cadastro.asp

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\ARQUIVOS DE PROGRAMAS\Yahoo!\Companion\Installs\cpn0\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\ARQUIVOS DE PROGRAMAS\Yahoo!\Companion\Installs\cpn0\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.9.24.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MegauploadToolbar\megauploadtoolbar.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MegauploadToolbar\megauploadtoolbar.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\ARQUIVOS DE PROGRAMAS\Yahoo!\Companion\Installs\cpn0\yt.dll

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\ARQUIVOS DE PROGRAMAS\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\ARQUIVOS DE PROGRAMAS\DAP\dapextie2.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Publicar em Blogue - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Publicar no Blogue no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.9.24.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=http://www.positivoinformatica.com.br/

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{68D0BEAD-47BF-4FD0-A03E-B087D3238F5D}: NameServer = 200.149.55.140 200.165.132.147

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: textwareilluminatorbase - {CE5CD329-1650-414A-8DB0-4CBF72FAED87} - C:\WINDOWS\system32\textwareilluminatorbaseProtocol.dll

O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Arquivos de programas\Windows Live\Mail\mailcomm.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\ARQUIVOS DE PROGRAMAS\Ares\chatServer.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Arquivos de programas\Windows Live\installer\WLSetupSvc.exe

 

 

 

 

 

Sun Jan 20 10:41:09 2008

EliBagle v10.89 ©2008 S.G.H. / Satinfo S.L.

----------------------------------------------

Lista de Acciones (por Acción Directa):

C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Bagle Acceso Denegado.

C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle

Por favor, envienos una muestra del fichero

C:\Muestras\SROSA.SYS.Muestra EliBagle v10.89

a "virus@satinfo.es". Gracias.

C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle Acceso Denegado.

Por favor, envienos una muestra del fichero

C:\Muestras\HLDRRR.EXE.Muestra EliBagle v10.89

a "virus@satinfo.es". Gracias.

C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle Acceso Denegado.

Restaurada Clave: "SafeBoot\Minimal y Network"

 

Sun Jan 20 10:45:18 2008

EliBagle v10.89 ©2008 S.G.H. / Satinfo S.L.

----------------------------------------------

Lista de Acciones (por Acción Directa):

C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Eliminado Bagle

Por favor, envienos una muestra del fichero

C:\Muestras\SROSA.SYS.Muestra EliBagle v10.89

a "virus@satinfo.es". Gracias.

C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Eliminado Bagle

Por favor, envienos una muestra del fichero

C:\Muestras\HLDRRR.EXE.Muestra EliBagle v10.89

a "virus@satinfo.es". Gracias.

C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Eliminado Bagle

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite torugorj!

 

Voçê já pode instalar,algum Antivírus?

________________________

 

>@< Faça o download do a-squared Free 3.0

>@< Abra o programa e clique em: Atualizar agora >> Aguarde!

>@< Terminando,clique em: Analisar agora.

>@< Caso possa,procure fazer,esta análise,em Modo de Segurança!

>@< Escolha a opção: A fundo.

>@< Clique em Analisar!

>@< Terminando,envie os ítens encontrados para a quarentena.

>@< Aonde,daí,serão excluídos ou restaurados.

________________________

 

>@< Salve o relatório,desta verificação,e poste na sua resposta + HJT,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DigRam, muito obrigado pela ajuda e desculpe a demora pra responder

consegui instalar o avg e o ccleaner e executalos, fiz a ultima etapa q você enviou e aew estao os resultados do HJT e do a2scan em sequencia

 

Logfile of HijackThis v1.99.1

Scan saved at 06:36:33, on 23/1/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\ARQUIVOS DE PROGRAMAS\DAP\DAP.EXE

C:\Arquivos de programas\Windows Defender\MSASCui.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PCSuite.exe

C:\ARQUIVOS DE PROGRAMAS\HP\Digital Imaging\bin\hpqtra08.exe

C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe

C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe

C:\WINDOWS\system32\cmpe.exe

C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\PC Connectivity Solution\Transports\NclUSBSrv.exe

C:\Arquivos de programas\PC Connectivity Solution\Transports\NclRSSrv.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIVOS DE PROGRAMAS\eMule\emule.exe

C:\Arquivos de programas\a-squared Free\a2service.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\ARQUIVOS DE PROGRAMAS\Mozilla Firefox\firefox.exe

C:\Documents and Settings\PC\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/accounts/ServiceLogi...mp;passive=true

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.positivoinformatica.com.br/cadastro.asp

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\ARQUIVOS DE PROGRAMAS\Yahoo!\Companion\Installs\cpn0\yt.dll

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\ARQUIVOS DE PROGRAMAS\Yahoo!\Companion\Installs\cpn0\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.9.24.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MegauploadToolbar\megauploadtoolbar.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\ARQUIV~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARQUIV~1\MegauploadToolbar\megauploadtoolbar.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! com bloqueador de pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\ARQUIVOS DE PROGRAMAS\Yahoo!\Companion\Installs\cpn0\yt.dll

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [DownloadAccelerator] "C:\ARQUIVOS DE PROGRAMAS\DAP\DAP.EXE" /STARTUP

O4 - HKLM\..\Run: [Windows Defender] "C:\Arquivos de programas\Windows Defender\MSASCui.exe" -hide

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [PC Suite Tray] "C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray

O4 - Startup: hpqtra08.exe.lnk = C:\ARQUIVOS DE PROGRAMAS\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: &Clean Traces - C:\Arquivos de programas\DAP\Privacy Package\dapcleanerie.htm

O8 - Extra context menu item: &Download with &DAP - C:\ARQUIVOS DE PROGRAMAS\DAP\dapextie.htm

O8 - Extra context menu item: Download &all with DAP - C:\ARQUIVOS DE PROGRAMAS\DAP\dapextie2.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Publicar em Blogue - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Publicar no Blogue no Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Arquivos de programas\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.1.9.24.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=http://www.positivoinformatica.com.br/

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Arquivos de programas\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{68D0BEAD-47BF-4FD0-A03E-B087D3238F5D}: NameServer = 200.149.55.140 200.165.132.147

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: textwareilluminatorbase - {CE5CD329-1650-414A-8DB0-4CBF72FAED87} - C:\WINDOWS\system32\textwareilluminatorbaseProtocol.dll

O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Arquivos de programas\Windows Live\Mail\mailcomm.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Arquivos de programas\a-squared Free\a2service.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\ARQUIVOS DE PROGRAMAS\Ares\chatServer.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe

O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\WINDOWS\system32\cmpe.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Arquivos de programas\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Nero\Lib\NMIndexingService.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Arquivos de programas\Windows Live\installer\WLSetupSvc.exe

 

 

 

a-squared Free - Versão 3.1

Última atualização 23/1/2008 01:15:54

 

Configurações da análise:

 

Objetos: Memória, Rastros, Cookies, C:\

Análise de arquivos: Ligado

Heurística: Ligado

Análise de ADS: Ligado

 

Início da análise: 23/1/2008 01:16:37

 

c:\arquivos de programas\messengerdiscovery detectado: Trace.Directory.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\languages detectado: Trace.Directory.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources detectado: Trace.Directory.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\sounds detectado: Trace.Directory.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\languages\albanian.ini detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\languages\deutsch.ini detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\languages\eesti.ini detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\languages\english.ini detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\languages\español (latino).ini detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\languages\francais.ini detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\languages\portuguese (portugal).ini detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\languages\turkish.ini detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\loader.exe detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\messengerdiscovery live.exe detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\messengerdiscovery live.exe.manifest detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\messengerdiscovery.dll detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingsmenu_0.png detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingsmenu_1.png detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingsmenu_2.png detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingsmenu_3.png detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingsmenu_4.png detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingsmenu_5.png detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingssubmenu_0.png detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingssubmenu_1.png detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingssubmenu_2.png detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingssubmenu_left.ico detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\resources\settingssubmenu_right.ico detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\sounds\alert.wav detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\sounds\sounds copyright.txt detectado: Trace.File.DiscoveryLive

c:\arquivos de programas\messengerdiscovery\spellchk.exe detectado: Trace.File.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AlertStyle(0) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AppearOfflineHotKey detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AppearOfflineModifier detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AwayHotKey detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> AwayModifier detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> BusyHotKey detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> BusyModifier detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> ClipboardHotKey detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> ClipboardModifier detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> CloseAlert(0) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> elO(0) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> GroupChoice detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OnlineHotKey detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OnlineModifier detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> OpenSensitivity(0) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup0 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup1 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup10 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup2 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup3 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup4 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup5 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup6 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup7 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup8 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Popup9 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> RSOTime detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(13) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(2) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(22) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(37) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(44) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Setting(7) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Slider detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Slider1 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> SpeechSpeed detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> SpeechVolume detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live\Settings --> Time_Format detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(1) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(11) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(16) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(6) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> GlobalSetting(9) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> MDLCap detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> Menu1 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> Menu2 detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(0) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(1) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(2) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> MouseGesture(3) detectado: Trace.Registry.DiscoveryLive

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Matt Holwood\MessengerDiscovery Live --> WLMCaption detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Matt Holwood\MessengerDiscovery Live --> InstallDirectory detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> DisplayName detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> HelpLink detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> Inno Setup: App Path detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> Inno Setup: Icon Group detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> Inno Setup: Setup Version detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> Inno Setup: User detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> InstallDate detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> InstallLocation detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> NoModify detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> NoRepair detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> Publisher detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> QuietUninstallString detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> UninstallString detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> URLInfoAbout detectado: Trace.Registry.DiscoveryLive

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MessengerDiscovery Live_is1 --> URLUpdateInfo detectado: Trace.Registry.DiscoveryLive

c:\arquivos de programas\ares\ares.exe detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\anonproxies.txt.sample detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\blocked.txt.sample detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\blocked_keywords.txt.sample detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\chanlistfilter.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\chat.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\emotic.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\libbig.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\logo.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\mimesmall.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\mshareset.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\player.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\playlistbtns.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\prefs.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\searchpnl.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\searchstars.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\tabsbig.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\tabssmall.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\transfer.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\webanim.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\homepage.dat detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\p2pfilter.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\arabic.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\chinese_cn.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\chinese_tw.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\czech.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\dutch.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\finland.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\french.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\german.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\italian.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\japanese.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\kurdish.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\kyrgyz.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\polish.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\portugues.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\slovak.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\spanish.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\spanishla.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\swedish.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\lang\turkish.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\tcpip_patcher.sys detectado: Trace.File.Ares

c:\arquivos de programas\ares\tcpippatcherdll.dll detectado: Trace.File.Ares

c:\documents and settings\pc\menu iniciar\programas\ares\ares.lnk detectado: Trace.File.Ares

Value: HKEY_CLASSES_ROOT\arlnk --> URL Protocol detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\bounds --> Main.Height detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\bounds --> Main.Left detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\bounds --> Main.Maximized detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\bounds --> Main.Top detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\bounds --> Main.Width detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\Columns\Transfers --> Download detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\Columns\Transfers --> Queue detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\Columns\Transfers --> Upload detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\Data --> AresNet1 detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\Data --> JI.AresNet1 detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\Positions\Transfers --> Download detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\Positions\Transfers --> Queue detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares\Positions\Transfers --> Upload detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> ChatRoom.ServerPort detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> ChatRoom.ShowJP detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Extra.ShowActiveCaption detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> General.AutoConnect detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> General.AutoStartUp detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> General.LastLibraryMode detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> GUI.LastChatRoomBrowse detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> GUI.LastLibrary detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> GUI.LastPMBrowse detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> GUI.LastSearch detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Network.DHTID detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Personal.GUID detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Privacy.SendRegularPath detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> PrivateMessage.AllowBrowse detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> PrivateMessage.AwayMessage detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Start Menu Folder detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Stats.CAvgTime detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Stats.CDnSpeed detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Stats.CFRTime detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Stats.CTtUptime detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Stats.CUpSpeed detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Stats.HasLQCa detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Stats.LstCaQuery detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Stats.LstCaQueryInt detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Transfer.MaximizeUpBandOnIdle detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Transfer.ServerPort detectado: Trace.Registry.Ares

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ares --> DisplayName detectado: Trace.Registry.Ares

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ares --> DisplayVersion detectado: Trace.Registry.Ares

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ares --> Publisher detectado: Trace.Registry.Ares

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ares --> UninstallString detectado: Trace.Registry.Ares

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ares --> URLInfoAbout detectado: Trace.Registry.Ares

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ares --> URLUpdateInfo detectado: Trace.Registry.Ares

c:\arquivos de programas\ares detectado: Trace.Directory.Ares

c:\arquivos de programas\ares\data detectado: Trace.Directory.Ares

c:\arquivos de programas\ares\data\gui detectado: Trace.Directory.Ares

c:\arquivos de programas\ares\data\gui\general detectado: Trace.Directory.Ares

c:\arquivos de programas\ares\data\gui\osthemes detectado: Trace.Directory.Ares

c:\arquivos de programas\ares\lang detectado: Trace.Directory.Ares

c:\documents and settings\pc\menu iniciar\programas\ares detectado: Trace.Directory.Ares

c:\arquivos de programas\gamespy arcade detectado: Trace.Directory.GameSpy Arcade

c:\arquivos de programas\gamespy arcade\profiles detectado: Trace.Directory.GameSpy Arcade

c:\arquivos de programas\gamespy arcade\services detectado: Trace.Directory.GameSpy Arcade

c:\arquivos de programas\ares\asyncex.ax detectado: Trace.File.Ares

c:\arquivos de programas\ares\chatserver.exe detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\chatconf.txt detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\chatlang.txt.sample detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\gui\general\buttonsbitmap.bmp detectado: Trace.File.Ares

c:\arquivos de programas\ares\data\homepage.url detectado: Trace.File.Ares

c:\arquivos de programas\ares\libfaad2.dll detectado: Trace.File.Ares

c:\arquivos de programas\ares\mp3source.ax detectado: Trace.File.Ares

c:\documents and settings\pc\menu iniciar\programas\ares\homepage.lnk detectado: Trace.File.Ares

c:\arquivos de programas\gamespy arcade\banner.html detectado: Trace.File.GameSpy Arcade

Value: HKEY_CLASSES_ROOT\CLSID\{3E0FA044-926C-42D9-BA12-EF16E980913B}\InprocServer32 --> ThreadingModel detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> General.Language detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Hashing.Priority detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Playlist.PreviousASXApp detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Playlist.PreviousM3UApp detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Playlist.PreviousWAXApp detectado: Trace.Registry.Ares

Value: HKEY_USERS\S-1-5-21-3230164199-3094433589-404582642-1006\Software\Ares --> Torrents.PreviousApp detectado: Trace.Registry.Ares

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E0FA044-926C-42D9-BA12-EF16E980913B}\InprocServer32 --> ThreadingModel detectado: Trace.Registry.Ares

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run --> DownloadAccelerator detectado: Trace.Registry.Timbuktu Pro

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Download Accelerator Plus (DAP) --> Changed detectado: Trace.Registry.Warez P2P Faster Accelerator

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Download Accelerator Plus (DAP) --> SlowInfoCache detectado: Trace.Registry.Warez P2P Faster Accelerator

C:\Documents and Settings\PC\Cookies\pc@atdmt[2].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\PC\Cookies\pc@atdmt[3].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\PC\Cookies\pc@bs.serving-sys[2].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\PC\Cookies\pc@doubleclick[1].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\PC\Cookies\pc@serving-sys[1].txt detectado: Trace.TrackingCookie

C:\Documents and Settings\PC\Dados de aplicativos\Mozilla\Firefox\Profiles\cp4u944f.default\cookies.txt:33 detectado: Trace.TrackingCookie

C:\ARQUIVOS DE PROGRAMAS\LevelUpGames\TheDuel\XPatch.exe detectado: Email-Worm.Win32.Luder.e

C:\ARQUIVOS DE PROGRAMAS\TEXTware\QUICKfind\PlugIns\IEHelp.dll detectado: Adware.Win32.BHO.cc

C:\ARQUIVOS DE PROGRAMAS\VDownloader\VDownloader.exe detectado: Riskware.Downloader.Win32.VDown.a

C:\Documents and Settings\PC\Meus documentos\Programas\GuSTop2.zip/GuSTop2.exe/rinst.exe detectado: Riskware.Monitor.Win32.Perflogger.bx

C:\Documents and Settings\PC\Meus documentos\Programas\vdownloader.zip/VDownloader.exe detectado: Riskware.Downloader.Win32.VDown.a

C:\WINDOWS\bnetunin.exe detectado: Trojan-Downloader.Win32.Agent.drp

C:\WINDOWS\system32\closeapp.exe detectado: Riskware.RiskTool.Win32.CloseApp.a

 

Analisado

 

Arquivos: 367405

Objetos: 364402

Cookies: 120

Processos: 35

 

Encontrado

 

Arquivos: 7

Objetos: 218

Cookies: 6

Processos: 0

Chaves do registro: 0

 

Fim da análise: 23/1/2008 03:17:25

Duração da análise: 2:00:48

 

C:\WINDOWS\bnetunin.exe Excluído Trojan-Downloader.Win32.Agent.drp

C:\ARQUIVOS DE PROGRAMAS\LevelUpGames\TheDuel\XPatch.exe Excluído Email-Worm.Win32.Luder.e

 

Excluído

 

Arquivos: 2

Objetos: 0

Cookies: 0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia torugorj!

 

>@< Estando tudo Ok e os objetos/arquivos,quarantinados,vá ao a-squared e elimine-os.

_____________________

 

>@< Para a sua segurança,leia: < Cuidados ao navegar na Net >

_____________________

 

>@< O Log está limpo! :thumbsup:

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o Tópico seja reaberto é preciso enviar uma Mensagem Privada,para um Moderador,com um Link para o Tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.