Scruub 0 Denunciar post Postado Fevereiro 25, 2009 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:59:19, on 25/2/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\SigmaTel\C-Major Audio\WDM\STacSV.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe C:\WINDOWS\sttray.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\egui.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Downloads\Nova pasta\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Arquivos de programas\WebShow\WebShow.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll (file missing) O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: HelloWorldBHO - {D88E1558-7C2D-407A-953A-C044F5607CEA} - C:\Arquivos de programas\Mjcore\Mjcore.dll (file missing) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [HP Software Update] "C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [HP Component Manager] "C:\Arquivos de programas\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [Wapp] C:\Arquivos de programas\Wapp.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Media Codec Update Service] C:\Arquivos de programas\Essentials Codec Pack\update.exe -silent O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Psayik] rundll32.exe "C:\WINDOWS\Cxigodadujo.dll",e O4 - HKLM\..\Run: [egui] "C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [GGWallpaper] C:\Arquivos de programas\BeautifulEarth\Beautiful-Earth.exe O4 - HKCU\..\Run: [360desktop] "C:\Arquivos de programas\360desktop\360desktop.exe" O4 - HKCU\..\Run: [Twain] C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Last.fm Helper.lnk = C:\Arquivos de programas\Last.fm\LastFMHelper.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Arquivos de programas\PokerStars\PokerStarsUpdate.exe O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1189619805031 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: crypt - C:\WINDOWS\ O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\ekrn.exe O23 - Service: FCI (fci) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: ICF (icf) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Arquivos de programas\SigmaTel\C-Major Audio\WDM\STacSV.exe -- End of file - 9884 bytes Favor desconsiderar o erro no título Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Fevereiro 25, 2009 Sigas as instruções abaixo: Baixe o bankerfix.exe. desative o seu antivírus temporariamente, para não haver conflitos e para uma melhor detecção. Clique duas vezes sobre bankerfix.exe, dê o Enter e espere ele terminar. Ao terminar, leia a mensagem na tela e aperte Enter novamente. Habilite o seu antivírus. e gere um novo log do hijackthis, e poste juntamente com o relatório .txt do Bankerfix. Aguardo o Retorno Compartilhar este post Link para o post Compartilhar em outros sites
Scruub 0 Denunciar post Postado Fevereiro 25, 2009 Tentei passar o Bankerfix mas não aconteceu nada, criou apenas uma pasta chamada "Linha Defensiva" não apareceu nenhum arquivo .txt Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Fevereiro 26, 2009 Baixe o Norman Malware Cleaner aqui:http://superdownloads.uol.com.br/redir.cfm?softid=63672 Depois de instalado execute e adicione todas as áreas físicas e removiveis do seu pc ( ex: Ec: F: e outras) só então clique em Scan. Apos isso poste o log do Hijackthis,juntamente com o log do Norman Quanto ao bankerfix delte a pasta cria "Linha Defensiva" antes de roda o Normam Aguardo retorno. Compartilhar este post Link para o post Compartilhar em outros sites
Scruub 0 Denunciar post Postado Fevereiro 26, 2009 :!: HijackThis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:13:17, on 26/2/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Bonjour\mDNSResponder.exe C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Arquivos de programas\SigmaTel\C-Major Audio\WDM\STacSV.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe C:\WINDOWS\sttray.exe C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\egui.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Messenger\msmsgs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Arquivos de programas\Mozilla Firefox\firefox.exe C:\Downloads\Nova pasta\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.uol.com.br/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Arquivos de programas\WebShow\WebShow.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll (file missing) O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: HelloWorldBHO - {D88E1558-7C2D-407A-953A-C044F5607CEA} - C:\Arquivos de programas\Mjcore\Mjcore.dll (file missing) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [HP Software Update] "C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [HP Component Manager] "C:\Arquivos de programas\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [Wapp] C:\Arquivos de programas\Wapp.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Media Codec Update Service] C:\Arquivos de programas\Essentials Codec Pack\update.exe -silent O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Psayik] rundll32.exe "C:\WINDOWS\Cxigodadujo.dll",e O4 - HKLM\..\Run: [egui] "C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [GGWallpaper] C:\Arquivos de programas\BeautifulEarth\Beautiful-Earth.exe O4 - HKCU\..\Run: [360desktop] "C:\Arquivos de programas\360desktop\360desktop.exe" O4 - HKCU\..\Run: [Twain] C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Last.fm Helper.lnk = C:\Arquivos de programas\Last.fm\LastFMHelper.exe O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Arquivos de programas\PokerStars\PokerStarsUpdate.exe O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1189619805031 O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: crypt - C:\WINDOWS\ O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Arquivos de programas\Bonjour\mDNSResponder.exe O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\EHttpSrv.exe O23 - Service: Eset Service (ekrn) - ESET - C:\Arquivos de programas\ESET\ESET NOD32 Antivirus\ekrn.exe O23 - Service: FCI (fci) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing) O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbguard.exe O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Arquivos de programas\Firebird\Firebird_1_5\bin\fbserver.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Arquivos de programas\Arquivos comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: ICF (icf) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing) O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Arquivos de programas\SigmaTel\C-Major Audio\WDM\STacSV.exe -- End of file - 9837 bytes Compartilhar este post Link para o post Compartilhar em outros sites
Scruub 0 Denunciar post Postado Fevereiro 26, 2009 :!: Norman Malware Cleaner Norman Malware Cleaner Copyright © 1990 - 2009, Norman ASA. Built 2009/02/24 13:06:05 Norman Scanner Engine Version: 6.00.06 Nvcbin.def Version: 6.00.00, Date: 2009/02/24 13:06:05, Variants: 2904494 Scan started: 26/02/2009 14:25:24 Running pre-scan cleanup routine: Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3 Logged on user: FELIPE-ESCRITOR\Proprietário Scanning running processes and process memory... C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe (Infected with W32/DLoader.MFWI) Terminated process Deleted file Number of processes/threads found: 1909 Number of processes/threads scanned: 1884 Number of processes/threads not scanned: 25 Number of infected processes/threads terminated: 1 Total scanning time: 1m 2s Scanning file system... Scanning: C:\*.* C:\BKP ADM\BKP\Mlua\AIBMBMEH/unknown0 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\AIBMBMEH/unknown1 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\AIBMBMEH/unknown2 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\AIBMBMEH/unknown3 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\ALAJAECF/MLUA.ARJ/ADM_C201.PRG (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\AMAPDCCF/unknown0 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\AMAPDCCF/unknown1 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\AMAPDCCF/unknown2 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\AMAPDCCF/unknown3 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\AOBGACGB/unknown0 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\AOBGACGB/unknown1 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\AOBGACGB/unknown2 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\AOBGACGB/unknown3 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\AIBFCJCP/unknown0 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\AIBFCJCP/unknown1 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\AIBFCJCP/unknown2 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\AIBFCJCP/unknown3 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\AJCICMDI/unknown0 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\AJCICMDI/unknown1 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\AJCICMDI/unknown2 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\AJCICMDI/unknown3 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\APBHCPAB/unknown0 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\APBHCPAB/unknown1 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\APBHCPAB/unknown2 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\APBHCPAB/unknown3 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\BBABBPCO/unknown0 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\BBABBPCO/unknown1 (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\BBABBPCO/unknown2 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\BBABBPCO/unknown3 (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\DBF_1.zip/CADPROP2.DBF (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\DBF_1.zip/CONHECI2.DBF (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\DBF_1.zip/DECLARE2.DBF (Error whilst scanning file: I/O Error (0x00220005)) C:\BKP ADM\BKP\Mlua\LIXO\DBF_2.zip/HISTPAG.DBF (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\DBF_2.zip/VIAGENSM.DBF (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\DBF_2.zip/DIVERSOS.DBF (Error whilst scanning file: I/O Error (0x00000000)) C:\BKP ADM\BKP\Mlua\LIXO\DBF_2.zip/DIVERM.DBF (Error whilst scanning file: I/O Error (0x00000000)) C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\ED61CRQF\jlvswpczj[1].txt (Infected with W32/DLoader.MVPZ) Deleted file C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\ED61CRQF\nws32[1].exe (Infected with W32/Pandex.CS) Deleted file C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\GPKD8VEN\mzx32[1].exe (Infected with W32/Pandex.CS) Deleted file C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\OBIXCVKX\jlvswpczj[1].txt (Infected with W32/DLoader.MVPZ) Deleted file C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5\68D9R907\nws32[1].exe (Infected with W32/Pandex.CS) Deleted file C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5\HFM87127\nws32[1].exe (Infected with W32/Pandex.CS) Deleted file C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5\HFM87127\nws32[2].exe (Infected with W32/Pandex.CS) Deleted file C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5\HFM87127\nws32[3].exe (Infected with W32/Pandex.CS) Deleted file C:\Documents and Settings\Proprietário\Configurações locais\Temp\speedrunner.prod.v12015.23oct2008.exe.359786c558ef9ed8eec8b7dc39ceeb64 (Infected with W32/Agent.JCIG) Deleted file C:\Documents and Settings\Proprietário\Configurações locais\Temporary Internet Files\Content.IE5\9VGLXC8P\func_200710161248[1].js/unknown0 (Error whilst scanning file: I/O Error (0x00220005)) C:\Documents and Settings\Proprietário\Configurações locais\Temporary Internet Files\Content.IE5\9VGLXC8P\styles-sitew[3].css/unknown0 (Error whilst scanning file: I/O Error (0x00220005)) C:\Downloads\DownPremium_1.0.rar/DownPremium 1.0.exe (Infected with Smalltroj.LLRR) Deleted file C:\Downloads\DownPremium_1.0.rar (Empty archive after cleaning) Deleted file C:\SDFix\backups\backups.zip/backups/lsass.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP453\A0085265.inf (Infected with BAT/AutoRun.AE) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP453\A0085266.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP453\A0085276.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP456\A0086343.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP456\A0086344.inf (Infected with BAT/AutoRun.AE) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP456\A0086345.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP459\A0087654.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP462\A0087787.inf (Infected with BAT/AutoRun.AE) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP462\A0087788.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP463\A0087789.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP477\A0091525.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP477\A0091532.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP484\A0097321.inf (Infected with BAT/AutoRun.AE) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP484\A0097322.exe (Infected with W32/Agent.JIIR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP485\A0097351.dll (Infected with W32/HotBar.ACY) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP485\A0097359.exe (Infected with W32/Smalltroj.LCYY) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP485\A0097362.exe (Infected with Sohanad.AYH) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP485\A0097363.exe (Infected with W32/Smalltroj.LCYY) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP485\A0097419.exe (Infected with Sohanad.AYH) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP487\A0097515.exe (Infected with W32/Smalltroj.LCYY) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP488\A0097684.exe (Infected with Smalltroj.KHGR) Deleted file C:\System Volume Information\_restore{3702F08C-CF26-4E87-A4A6-59E525F74D05}\RP488\A0097686.exe (Infected with W32/Smalltroj.LCYY) Deleted file C:\WINDOWS\tjykvhkf.exe (Infected with W32/DLoader.KTNB) Deleted file C:\WINDOWS\xlpprzyh.exe (Infected with W32/DLoader.KTNB) Deleted file C:\WINDOWS\xlpqxlok.exe (Infected with W32/DLoader.KTNB) Deleted file C:\WINDOWS\system32\crypts.dll (Infected with W32/DLoader.MCXY) Deleted file C:\WINDOWS\system32\OLD11.tmp:ext.exe (Infected with W32/Agent.KJLM) Deleted file C:\WINDOWS\system32\OLD1A.tmp:ext.exe (Infected with W32/Agent.KJLM) Deleted file C:\WINDOWS\system32\svchost.exe:ext.exe (Infected with W32/Agent.KJLM) Deleted file C:\WINDOWS\system32\drivers\ati4sxxx.sys (Infected with Vundo.EQJ) Removed driver: ati4sxxx Deleted file C:\WINDOWS\system32\drivers\ati5qvxx.sys (Infected with Vundo.EQJ) Removed driver: ati5qvxx Deleted file C:\WINDOWS\Temp\1069075789exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\1384071400exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\1521583816exe (Infected with W32/Smalltroj.LCLF) Deleted file C:\WINDOWS\Temp\1609448163exe (Infected with W32/Smalltroj.LGUP) Deleted file C:\WINDOWS\Temp\1639987449exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\1714779388exe (Infected with W32/Smalltroj.LGUP) Deleted file C:\WINDOWS\Temp\1761968282exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\1903858754exe (Infected with W32/Smalltroj.LGUP) Deleted file C:\WINDOWS\Temp\2050831035exe (Infected with W32/Smalltroj.LGUP) Deleted file C:\WINDOWS\Temp\296160198exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\436128761exe (Infected with W32/Smalltroj.LGUP) Deleted file C:\WINDOWS\Temp\526351892exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\57376527exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\592579650exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\598394479exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\658927082exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\722843360exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\984064714exe (Infected with W32/Pandex.CS) Deleted file C:\WINDOWS\Temp\BN10.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN11.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN12.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN13.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN14.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN15.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN15B.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN15D.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN16.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN17.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN18.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN19.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN1A.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN1B.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN1C.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN1E.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN1F.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN2.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN20.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN2B.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN3.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN31.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN4.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN5.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN6.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN7.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN8.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BN9.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BNA.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BNB.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BNBB.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BNC.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BNCD.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BND.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\BNF.tmp (Infected with W32/Smalldoor.DFZE) Deleted file C:\WINDOWS\Temp\NOD1E.tmp (Infected with W32/Smalldoor.DFZE) Deleted file Scanning: D:\*.* D:\lrsdwc.exe (Infected with W32/Agent.JIIR) Deleted file Scanning: E:\*.* Scanning: A:\*.* Scanning: c:\System Volume Information\*.* Running post-scan cleanup routine: Number of files found: 268476 Number of archives unpacked: 4024 Number of files scanned: 268381 Number of files not scanned: 95 Number of files skipped due to exclude list: 0 Number of infected files found: 98 Number of infected files repaired/deleted: 98 Number of infections removed: 98 Total scanning time: 1h 43m 27s Compartilhar este post Link para o post Compartilhar em outros sites
Silas Martins 0 Denunciar post Postado Fevereiro 27, 2009 Siga as instruções abaixo: Baixe o Killbox Execute o KillBox,clique em Delete on Reboot. Copie a lista abaixo: Citar C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dllC:\Arquivos de programas\WebShow\WebShow.dll C:\Arquivos de programas\Mjcore\Mjcore.dll C:\Arquivos de programas\Wapp.exe C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe C:\WINDOWS\system32\svchost.exe:ext.exe Vá ao Killbox.E clique em File > Paste from clipboard. Clique em All Files. Pressione "X". Responda "NÃO" à pergunta. Reinicie o computador em Modo Seguro (após reiniciar aperte a tecla F8 repetidamente até aparecer uma tela preta em DOS e escolha Modo Seguro). Execute o HijackThis, clique em Do a system scan only e selecione as linhas: Citar O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing)O2 - BHO: CPV - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Arquivos de programas\WebShow\WebShow.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: HelloWorldBHO - {D88E1558-7C2D-407A-953A-C044F5607CEA} - C:\Arquivos de programas\Mjcore\Mjcore.dll (file missing) O4 - HKLM\..\Run: [Wapp] C:\Arquivos de programas\Wapp.exe O4 - HKCU\..\Run: [Twain] C:\Documents and Settings\Proprietário\Dados de aplicativos\Twain\Twain.exe O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Arquivos de programas\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (file missing) O20 - Winlogon Notify: crypt - C:\WINDOWS\ O23 - Service: FCI (fci) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing) O23 - Service: ICF (icf) - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe (file missing) Clique em Fix Checked Feito isso Reinicie em modo normal e gere um novo log do Hijackthis. Aguardo retorno. Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Março 28, 2009 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites