Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Scruub

[Arquivado] Anáçise de Log

Recommended Posts

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:59:19, on 25/2/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\ekrn.exe

C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Arquivos de programas\SigmaTel\C-Major Audio\WDM\STacSV.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe

C:\WINDOWS\sttray.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\egui.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Downloads\Nova pasta\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)

O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Arquivos de programas\WebShow\WebShow.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll (file missing)

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: HelloWorldBHO - {D88E1558-7C2D-407A-953A-C044F5607CEA} - C:\Arquivos de programas\Mjcore\Mjcore.dll (file missing)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Arquivos de programas\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [Wapp] C:\Arquivos de programas\Wapp.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Media Codec Update Service] C:\Arquivos de programas\Essentials Codec Pack\update.exe -silent

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Psayik] rundll32.exe "C:\WINDOWS\Cxigodadujo.dll",e

O4 - HKLM\..\Run: [egui] "C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [GGWallpaper] C:\Arquivos de programas\BeautifulEarth\Beautiful-Earth.exe

O4 - HKCU\..\Run: [360desktop] "C:\Arquivos de programas\360desktop\360desktop.exe"

O4 - HKCU\..\Run: [Twain] C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Last.fm Helper.lnk = C:\Arquivos de programas\Last.fm\LastFMHelper.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Arquivos de programas\PokerStars\PokerStarsUpdate.exe

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)

O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1189619805031

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: crypt - C:\WINDOWS\

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: FCI (fci) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe

O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: ICF (icf) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Arquivos de programas\SigmaTel\C-Major Audio\WDM\STacSV.exe

 

--

End of file - 9884 bytes

 

Favor desconsiderar o erro no título

Compartilhar este post


Link para o post
Compartilhar em outros sites

Sigas as instruções abaixo:

 

Baixe o bankerfix.exe.

desative o seu antivírus temporariamente, para não haver conflitos e para uma melhor detecção.

Clique duas vezes sobre bankerfix.exe, dê o Enter e espere ele terminar. Ao terminar, leia a mensagem na tela e aperte Enter novamente.

 

Habilite o seu antivírus. e gere um novo log do hijackthis, e poste juntamente com o relatório .txt do Bankerfix.

 

Aguardo o Retorno

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe o Norman Malware Cleaner aqui:http://superdownloads.uol.com.br/redir.cfm?softid=63672

Depois de instalado execute e adicione todas as áreas físicas e removiveis do seu pc ( ex: Ec: F: e outras) só então clique em Scan.

Apos isso poste o log do Hijackthis,juntamente com o log do Norman

 

Quanto ao bankerfix delte a pasta cria "Linha Defensiva" antes de roda o Normam

Aguardo retorno.

Compartilhar este post


Link para o post
Compartilhar em outros sites

:!: HijackThis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:13:17, on 26/2/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Bonjour\mDNSResponder.exe

C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\ekrn.exe

C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Arquivos de programas\SigmaTel\C-Major Audio\WDM\STacSV.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe

C:\WINDOWS\sttray.exe

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\egui.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\explorer.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Downloads\Nova pasta\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)

O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Arquivos de programas\WebShow\WebShow.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll (file missing)

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: HelloWorldBHO - {D88E1558-7C2D-407A-953A-C044F5607CEA} - C:\Arquivos de programas\Mjcore\Mjcore.dll (file missing)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Arquivos de programas\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [Wapp] C:\Arquivos de programas\Wapp.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Media Codec Update Service] C:\Arquivos de programas\Essentials Codec Pack\update.exe -silent

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Psayik] rundll32.exe "C:\WINDOWS\Cxigodadujo.dll",e

O4 - HKLM\..\Run: [egui] "C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [GGWallpaper] C:\Arquivos de programas\BeautifulEarth\Beautiful-Earth.exe

O4 - HKCU\..\Run: [360desktop] "C:\Arquivos de programas\360desktop\360desktop.exe"

O4 - HKCU\..\Run: [Twain] C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Last.fm Helper.lnk = C:\Arquivos de programas\Last.fm\LastFMHelper.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Arquivos de programas\PokerStars\PokerStarsUpdate.exe

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)

O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1189619805031

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: crypt - C:\WINDOWS\

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: FCI (fci) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe

O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: ICF (icf) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Arquivos de programas\SigmaTel\C-Major Audio\WDM\STacSV.exe

 

--

End of file - 9837 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

:!: Norman Malware Cleaner

 

Norman Malware Cleaner

Copyright © 1990 - 2009, Norman ASA. Built 2009/02/24 13:06:05

 

Norman Scanner Engine Version: 6.00.06

Nvcbin.def Version: 6.00.00, Date: 2009/02/24 13:06:05, Variants: 2904494

 

Scan started: 26/02/2009 14:25:24

 

Running pre-scan cleanup routine:

Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3

Logged on user: FELIPE-ESCRITOR\Proprietário

 

 

 

Scanning running processes and process memory...

 

C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe (Infected with W32/DLoader.MFWI)

Terminated process

Deleted file

 

Number of processes/threads found: 1909

Number of processes/threads scanned: 1884

Number of processes/threads not scanned: 25

Number of infected processes/threads terminated: 1

Total scanning time: 1m 2s

 

 

Scanning file system...

 

Scanning: C:\*.*

 

C:\BKP ADM\BKP\Mlua\AIBMBMEH/unknown0 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\AIBMBMEH/unknown1 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\AIBMBMEH/unknown2 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\AIBMBMEH/unknown3 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\ALAJAECF/MLUA.ARJ/ADM_C201.PRG (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\AMAPDCCF/unknown0 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\AMAPDCCF/unknown1 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\AMAPDCCF/unknown2 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\AMAPDCCF/unknown3 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\AOBGACGB/unknown0 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\AOBGACGB/unknown1 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\AOBGACGB/unknown2 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\AOBGACGB/unknown3 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\AIBFCJCP/unknown0 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\AIBFCJCP/unknown1 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\AIBFCJCP/unknown2 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\AIBFCJCP/unknown3 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\AJCICMDI/unknown0 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\AJCICMDI/unknown1 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\AJCICMDI/unknown2 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\AJCICMDI/unknown3 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\APBHCPAB/unknown0 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\APBHCPAB/unknown1 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\APBHCPAB/unknown2 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\APBHCPAB/unknown3 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\BBABBPCO/unknown0 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\BBABBPCO/unknown1 (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\BBABBPCO/unknown2 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\BBABBPCO/unknown3 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\DBF_1.zip/CADPROP2.DBF (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\DBF_1.zip/CONHECI2.DBF (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\DBF_1.zip/DECLARE2.DBF (Error whilst scanning file: I/O Error (0x00220005))

 

C:\BKP ADM\BKP\Mlua\LIXO\DBF_2.zip/HISTPAG.DBF (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\DBF_2.zip/VIAGENSM.DBF (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\DBF_2.zip/DIVERSOS.DBF (Error whilst scanning file: I/O Error (0x00000000))

 

C:\BKP ADM\BKP\Mlua\LIXO\DBF_2.zip/DIVERM.DBF (Error whilst scanning file: I/O Error (0x00000000))

 

C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\ED61CRQF\jlvswpczj[1].txt (Infected with W32/DLoader.MVPZ)

Deleted file

 

C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\ED61CRQF\nws32[1].exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\GPKD8VEN\mzx32[1].exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\OBIXCVKX\jlvswpczj[1].txt (Infected with W32/DLoader.MVPZ)

Deleted file

 

C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5\68D9R907\nws32[1].exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5\HFM87127\nws32[1].exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5\HFM87127\nws32[2].exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5\HFM87127\nws32[3].exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\Documents and Settings\Proprietário\Configurações locais\Temp\speedrunner.prod.v12015.23oct2008.exe.359786c558ef9ed8eec8b7dc39ceeb64 (Infected with W32/Agent.JCIG)

Deleted file

 

C:\Documents and Settings\Proprietário\Configurações locais\Temporary Internet Files\Content.IE5\9VGLXC8P\func_200710161248[1].js/unknown0 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\Documents and Settings\Proprietário\Configurações locais\Temporary Internet Files\Content.IE5\9VGLXC8P\styles-sitew[3].css/unknown0 (Error whilst scanning file: I/O Error (0x00220005))

 

C:\Downloads\DownPremium_1.0.rar/DownPremium 1.0.exe (Infected with Smalltroj.LLRR)

Deleted file

 

C:\Downloads\DownPremium_1.0.rar (Empty archive after cleaning)

Deleted file

 

C:\SDFix\backups\backups.zip/backups/lsass.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP453\A0085265.inf (Infected with BAT/AutoRun.AE)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP453\A0085266.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP453\A0085276.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP456\A0086343.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP456\A0086344.inf (Infected with BAT/AutoRun.AE)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP456\A0086345.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP459\A0087654.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP462\A0087787.inf (Infected with BAT/AutoRun.AE)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP462\A0087788.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP463\A0087789.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP477\A0091525.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP477\A0091532.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP484\A0097321.inf (Infected with BAT/AutoRun.AE)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP484\A0097322.exe (Infected with W32/Agent.JIIR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP485\A0097351.dll (Infected with W32/HotBar.ACY)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP485\A0097359.exe (Infected with W32/Smalltroj.LCYY)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP485\A0097362.exe (Infected with Sohanad.AYH)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP485\A0097363.exe (Infected with W32/Smalltroj.LCYY)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP485\A0097419.exe (Infected with Sohanad.AYH)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP487\A0097515.exe (Infected with W32/Smalltroj.LCYY)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP488\A0097684.exe (Infected with Smalltroj.KHGR)

Deleted file

 

C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP488\A0097686.exe (Infected with W32/Smalltroj.LCYY)

Deleted file

 

C:\WINDOWS\tjykvhkf.exe (Infected with W32/DLoader.KTNB)

Deleted file

 

C:\WINDOWS\xlpprzyh.exe (Infected with W32/DLoader.KTNB)

Deleted file

 

C:\WINDOWS\xlpqxlok.exe (Infected with W32/DLoader.KTNB)

Deleted file

 

C:\WINDOWS\system32\crypts.dll (Infected with W32/DLoader.MCXY)

Deleted file

 

C:\WINDOWS\system32\OLD11.tmp:ext.exe (Infected with W32/Agent.KJLM)

Deleted file

 

C:\WINDOWS\system32\OLD1A.tmp:ext.exe (Infected with W32/Agent.KJLM)

Deleted file

 

C:\WINDOWS\system32\svchost.exe:ext.exe (Infected with W32/Agent.KJLM)

Deleted file

 

C:\WINDOWS\system32\drivers\ati4sxxx.sys (Infected with Vundo.EQJ)

Removed driver: ati4sxxx

Deleted file

 

C:\WINDOWS\system32\drivers\ati5qvxx.sys (Infected with Vundo.EQJ)

Removed driver: ati5qvxx

Deleted file

 

C:\WINDOWS\Temp\1069075789exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\1384071400exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\1521583816exe (Infected with W32/Smalltroj.LCLF)

Deleted file

 

C:\WINDOWS\Temp\1609448163exe (Infected with W32/Smalltroj.LGUP)

Deleted file

 

C:\WINDOWS\Temp\1639987449exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\1714779388exe (Infected with W32/Smalltroj.LGUP)

Deleted file

 

C:\WINDOWS\Temp\1761968282exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\1903858754exe (Infected with W32/Smalltroj.LGUP)

Deleted file

 

C:\WINDOWS\Temp\2050831035exe (Infected with W32/Smalltroj.LGUP)

Deleted file

 

C:\WINDOWS\Temp\296160198exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\436128761exe (Infected with W32/Smalltroj.LGUP)

Deleted file

 

C:\WINDOWS\Temp\526351892exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\57376527exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\592579650exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\598394479exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\658927082exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\722843360exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\984064714exe (Infected with W32/Pandex.CS)

Deleted file

 

C:\WINDOWS\Temp\BN10.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN11.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN12.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN13.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN14.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN15.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN15B.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN15D.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN16.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN17.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN18.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN19.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN1A.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN1B.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN1C.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN1E.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN1F.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN2.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN20.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN2B.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN3.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN31.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN4.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN5.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN6.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN7.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN8.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BN9.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BNA.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BNB.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BNBB.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BNC.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BNCD.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BND.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\BNF.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

C:\WINDOWS\Temp\NOD1E.tmp (Infected with W32/Smalldoor.DFZE)

Deleted file

 

Scanning: D:\*.*

 

D:\lrsdwc.exe (Infected with W32/Agent.JIIR)

Deleted file

 

Scanning: E:\*.*

 

Scanning: A:\*.*

 

Scanning: c:\System Volume Information\*.*

 

 

Running post-scan cleanup routine:

 

Number of files found: 268476

Number of archives unpacked: 4024

Number of files scanned: 268381

Number of files not scanned: 95

Number of files skipped due to exclude list: 0

Number of infected files found: 98

Number of infected files repaired/deleted: 98

Number of infections removed: 98

Total scanning time: 1h 43m 27s

Compartilhar este post


Link para o post
Compartilhar em outros sites

Siga as instruções abaixo:

 

Baixe o Killbox

Execute o KillBox,clique em Delete on Reboot.

Copie a lista abaixo:

  Citar
C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll

C:\Arquivos de programas\WebShow\WebShow.dll

C:\Arquivos de programas\Mjcore\Mjcore.dll

C:\Arquivos de programas\Wapp.exe

C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe

C:\WINDOWS\system32\svchost.exe:ext.exe

 

Vá ao Killbox.E clique em File > Paste from clipboard. Clique em All Files.

 

Pressione "X". Responda "NÃO" à pergunta.

 

Reinicie

o computador em Modo Seguro (após reiniciar aperte a tecla F8 repetidamente até aparecer uma tela preta em DOS e escolha Modo Seguro).

 

Execute o HijackThis, clique em Do a system scan only e selecione as linhas:

  Citar
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)

O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Arquivos de programas\WebShow\WebShow.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: HelloWorldBHO - {D88E1558-7C2D-407A-953A-C044F5607CEA} - C:\Arquivos de programas\Mjcore\Mjcore.dll (file missing)

O4 - HKLM\..\Run: [Wapp] C:\Arquivos de programas\Wapp.exe

O4 - HKCU\..\Run: [Twain] C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe

O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)

O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)

O20 - Winlogon Notify: crypt - C:\WINDOWS\

O23 - Service: FCI (fci) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)

O23 - Service: ICF (icf) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing)

Clique em Fix Checked

Feito isso Reinicie em modo normal e gere um novo log do Hijackthis.

 

Aguardo retorno.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.