Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

LucasTO

[Arquivado] Processo IEXPLORER.EXE inicia sozinho, muita memoria.

Recommended Posts

Eu tinha pegado um virus muito forte que travou meu windows, tive de formatar. Depois disso, quando eu ligo o pc, e sem conectar ainda á internet, o arquivo de paginaçao fica á cerca de 219, depois que eu conecto á net o Processo IEXPLORER.EXE inicia sozinho e fica uns 2 ou 3 no gerenciador de tarefas, e o arquivo de paginaçao vai só aumentando, pra casa de 400 á 600, e ja notei que mesmo com o navegador fexado, fica consumindo a net, e entao ela fika bem mais lenta.

O que devo fazer?

Aguardo.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! LucasTO

 

<@> Faça o download do HijackThis.

<@> Baixe-o para o Arquivos de programas!

<@> Mas,não execute-o ainda!

<@> Para que o Log do HijackThis saia completo,vá em Iniciar --> Executar.

<@> Digite: msconfig --> Clique Ok.

<@> Na janela que abrir,marque: Inicialização normal - Carregar todos os drivers de dispositivo e serviços

<@> Clique em Aplicar --> Ok.

<@> Reinicie o computador!

<@> Execute o HijackThis.exe --> Clique em: Do a system scan and save a logfile

<@> Abrir-se-á um Bloco de Notas!

<@> Selecione e copie o seu conteúdo,para este Tópico.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

E tem mais uma coisa: tem alguma coisa que ta consumindo a minha net, porque mesmo com os programas que utilizam a net fexados ja vi lá que consome, e os downloads estao muito lentos, e como eu uso internet discada fica ruim.

 

-----------------------------

Aqui o Log do Hijackthis:

-----------------------------

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:57:45, on 15/3/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe

C:\ARQUIV~1\AVG\AVG8\avgemc.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\taskmgr.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\TEMP\BN1.tmp

C:\Arquivos de programas\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,C:\WINDOWS\system32\actcontroller.exe,C:\WINDOWS\system32\7z.exe,C:\WINDOWS\system32\makehm.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\gcc.exe,C:\WINDOWS\system32\hhupd.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\pdbcopy.exe,C:\WINDOWS\system32\c++.exe,C:\WINDOWS\system32\makehm.exe,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARQUIV~1\AVG\AVG8\AVGTOO~1.DLL

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

O4 - HKLM\..\Run: [EPSON Stylus CX3700 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACL.EXE /P26 "EPSON Stylus CX3700 Series" /O6 "USB001" /M "Stylus CX3700"

O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Arquivos de programas\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{0EA20956-2EBE-4DFA-98CD-4F78320BABB0}: NameServer = 201.10.120.3 201.10.128.2

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 4877 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! LucasTO

 

<!> Alem de outras,a principal infecção é devido a um file infector. ( Win32.Virut )

<><><><><><><><><>

<@> Baixe: < Del.zip >

<@> À direita,digite na caixa o texto,e clique em: "Faça o download do seu Fiche..."

<@> Descompacte-o para o desktop...mas,não execute-o ainda! ( Del.bat )

<><><><><><><><><>

<@> Baixe: < ATF.gif > ( ...by Atribune )

<@> Salve-o no Desktop!

<@> Reinicie o computador,em Modo de Segurança! <-- Importante!

<@> Clique em ATF-Cleaner.exe

<@> Em "Select Files To Delete",marque Select All.

<@> Clique em Empty Selected.

<@> Na janela Done Cleaning,dê o OK --> Exit

 

<@> Atenção: Se utiliza o Firefox:

 

* No topo,clique em Firefox e escolha: Select All --> Clique em Empty Selected.

 

<@> Atenção: Se utiliza o Opera:

 

* No topo,clique em Opera e escolha: Select All --> Clique em Empty Selected.

 

<@> Ainda em Modo Seguro,execute o arquivo Del.bat,com um duplo-clique.

<@> Confirme a solicitação!

<@> Não reinicie o computador!

<@> Faça um scan com o seu antivírus. ( AVG )

<@> Terminando,reinicie para o Modo Normal e repita o scan com o AVG.

<@> Informe a situação e poste um novo log do HijackThis.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Eu nao entendi a parte de reiniciar o computador em modo seguro e em modo normal.

Pode me explicar?

Valew.

<><><><><><><><><>

Opa! LucasTO

 

<!> Todos os procedimentos deverão ser realizados em Modo de Segurança,e ao reiniciar o computador,executar outra vez o AVG,em Modo Normal. ( Procedimento final! )

<!> Se voçê está em Modo de Segurança e,ao reiniciar o computador,irás para o Modo Normal.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ixi DigRam, hoge na hora que eu ia fazer os procedimentos, deu erro no meu windows, ele resetou e sempre que eu ligava de novo resetava, e resetava...

Eu nao sabia o que fazer, e agora á noite eu pensei em recuperar o sistema, fiz isso, mais tenho certeza que ainda estou com virus "/.

Fiz um novo log no modo normal, para que voce analize e me diga o que devo fazer (ja baixei aqueles dois arquivos).

Desculpa.

 

----------------------------

Log Hijackthis

----------------------------

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:19:33, on 16/3/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\rundll32.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

C:\Arquivos de programas\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\AVG\AVG8\avgui.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\cmd.exe

C:\WINDOWS\services.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\reader_s.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\Arquivos de programas\HiJackThis.exe

C:\WINDOWS\system32\taskmgr.exe

C:\WINDOWS\system32\svchost.exe

C:\Documents and Settings\Lucas\reader_s.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,C:\WINDOWS\system32\actcontroller.exe,C:\WINDOWS\system32\7z.exe,C:\WINDOWS\system32\makehm.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\gcc.exe,C:\WINDOWS\system32\hhupd.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\pdbcopy.exe,C:\WINDOWS\system32\c++.exe,C:\WINDOWS\system32\makehm.exe,C:\WINDOWS\system32\idaw64.exe,C:\WINDOWS\system32\pdbcopy.exe,C:\WINDOWS\system32\i386kd.exe,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

O4 - HKLM\..\Run: [EPSON Stylus CX3700 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACL.EXE /P26 "EPSON Stylus CX3700 Series" /O6 "USB001" /M "Stylus CX3700"

O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Lucas\reader_s.exe

O4 - HKCU\..\Run: [services] 63400A04031D427E16192C214A5D0D2D2035500531252544330C290B26AFDDA5DFE41A3025100732

56452D3B132807C0DB70DFA3B3A6B42060606020202020602020202060202020202060206035EAF1E

EFFE4CF5E62032C213A312B3A49015E2C227C1F233D34113556525913191B35493C38310E710A3930

28326300402A1C09372E152D006D422C2BÅã

O4 - HKLM\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe

O4 - HKCU\..\Policies\Explorer\Run: [services] 63400A04031D427E16192C214A5D0D2D2035500531252544330C290B26AFDDA5DFE41A3025100732

56452D3B132807C0DB70DFA3B3A6B42060606020202020602020202060202020202060206035EAF1E

EFFE4CF5E62032C213A312B3A49015E2C227C1F233D34113556525913191B35493C38310E710A3930

28326300402A1C09372E152D006D422C2BÅã

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{0EA20956-2EBE-4DFA-98CD-4F78320BABB0}: NameServer = 201.10.120.3 201.10.128.2

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 6223 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites
Fiz um novo log no modo normal, para que voce analize e me diga o que devo fazer (ja baixei aqueles dois arquivos).

<><><><><><><><><>

Opa! LucasTO

 

<!> Apesar do ocorrido,siga com os procedimentos já lhe passados.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Eu fiz tudo como voce me falou, mais eu acho que nao tirou os virus tudo, ainda esta com 610 de arquivo de paginaçao "/ .

E tem algo connsumindo a net tambem ...

Falow ..

 

----------------------------

Aqui o log do Hijackthis

----------------------------

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:49:31, on 17/3/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACL.EXE

C:\WINDOWS\system32\taskmgr.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\rundll32.exe

C:\Documents and Settings\Lucas\reader_s.exe

C:\Arquivos de programas\AVG\AVG8\avgui.exe

C:\Arquivos de programas\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,C:\WINDOWS\system32\actcontroller.exe,C:\WINDOWS\system32\7z.exe,C:\WINDOWS\system32\makehm.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\gcc.exe,C:\WINDOWS\system32\hhupd.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\pdbcopy.exe,C:\WINDOWS\system32\c++.exe,C:\WINDOWS\system32\makehm.exe,C:\WINDOWS\system32\idaw64.exe,C:\WINDOWS\system32\pdbcopy.exe,C:\WINDOWS\system32\i386kd.exe,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

O4 - HKLM\..\Run: [EPSON Stylus CX3700 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACL.EXE /P26 "EPSON Stylus CX3700 Series" /O6 "USB001" /M "Stylus CX3700"

O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Lucas\reader_s.exe

O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe

O4 - HKLM\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe

O4 - HKCU\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 5145 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! LucasTO

 

<!> Recomendo que enquanto estiver infectado,restrinja o seu acesso à Net.

<!> Ao final dos procedimentos,se houver neçessidade,utilizaremos a vacina anti-virut.

<><><><><><><><><><><>

<@> Baixe: < Pocket Killbox >

<@> Salve-o no Desktop!

<@> Abra o KillBox --> Marque a opção: Delete on Reboot

<@> Marque a caixa: "End Explorer Shell While Killing File" --> Minimize a ferramenta!

<@> Copie o(s) ficheiro(s),sob o QUOTE,para o Bloco de Notas.

<@> Estando desconectado,acesse o Bloco de Notas e execute estes atalhos: ( ctrl + a ) --> ( ctrl + c )

<><><><><><><><><><><><><><><>

C:\Documents and Settings\Lucas\reader_s.exe

C:\WINDOWS\system32\windres.exe

C:\WINDOWS\System32\reader_s.exe

C:\WINDOWS\system32\actcontroller.exe

C:\WINDOWS\system32\7z.exe

C:\WINDOWS\system32\makehm.exe

C:\WINDOWS\system32\undname.exe

C:\WINDOWS\system32\gcc.exe

C:\WINDOWS\system32\hhupd.exe

C:\WINDOWS\system32\deviceemulator.exe

C:\WINDOWS\system32\pdbcopy.exe

C:\WINDOWS\system32\c++.exe

C:\WINDOWS\system32\idaw64.exe

C:\WINDOWS\system32\i386kd.exe

C:\WINDOWS\system32\olhrwef.exe

C:\WINDOWS\services.exe

<><><><><><><><><><><><><><><>

<@> No KillBox,que estava minimizado,clique em File --> Paste from Clipboard --> All Files.

<@> Clique no X e,na pergunta,diga Não!

<@> Reinicie o computador! <-- Importante!

<@> Vá até a pasta: C:\!KillBox...que foi gerada!

<@> Poste o relatório de backup,que está em seu interior! ( C:\!KillBox\Logs\kb.log )

<><><><><><><><><><><>

<@> Abra o HijackThis --> Clique: Do a system scan only

<@> Reinicie o computador,em Modo de Segurança.

<@> Marque,abaixo,estas entradas:

<><><><><><><><><><><><><><><>

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\windres.exe,C:\WINDOWS\system32\actcontroller.exe,C:\WINDOWS\system32\7z.exe,C:\WINDOWS\system32\makehm.exe,C:\WINDOWS\system32\undname.exe,C:\WINDOWS\system32\gcc.exe,C:\WINDOWS\system32\hhupd.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\pdbcopy.exe,C:\WINDOWS\system32\c++.exe,C:\WINDOWS\system32\makehm.exe,C:\WINDOWS\system32\idaw64.exe,C:\WINDOWS\system32\pdbcopy.exe,C:\WINDOWS\system32\i386kd.exe,

 

O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe

 

O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe

 

O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe

 

O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Lucas\reader_s.exe

 

O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe

 

O4 - HKLM\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe

 

O4 - HKCU\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe

 

O4 - HKUS\S-1-5-18\..\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')

 

O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')

 

O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')

<><><><><><><><><><><><><><><>

<@> Com todos os programas fechados,clique em Fix checked --> Sim!

<@> Ainda em Modo Seguro,faça um scan com o seu antivírus.

<@> Terminando,poste: kb.log + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites
Mais se eu nao conectar á net como que eu vou ver os procedimentos que eu tenho que fazer?

Ir á uma lan?

<><><><><><><><><><>

Opa! LucasTO

 

<!> ...somente utilizar a navegação para acessar o iMasters.E,também,evite baixar programas de qualquer tipo sem a minha orientação.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aqui o primeiro kb.log, vou fazer os outros procedimentos:

 

Pocket Killbox version 2.0.0.978

Running on Windows XP as Lucas(Administrator)

was started @ terça-feira, março 17, 2009, 9:25 PM

 

Killbox Closed(Exit) @ 9:30:23 PM

__________________________________________________

 

Pocket Killbox version 2.0.0.978

Running on Windows XP as Lucas(Administrator)

was started @ terça-feira, março 17, 2009, 9:30 PM

 

# 1 [Delete on Reboot]

Path = C:\Documents and Settings\Lucas\reader_s.exe

 

 

# 2 [Delete on Reboot]

Path = C:\WINDOWS\System32\reader_s.exe

 

 

Killbox Closed(Exit) @ 9:32:07 PM

__________________________________________________

 

Tá certo esse log aí, posso continuar com as outras coisas ?

Compartilhar este post


Link para o post
Compartilhar em outros sites
Aqui o primeiro kb.log, vou fazer os outros procedimentos:

 

Pocket Killbox version 2.0.0.978

Running on Windows XP as Lucas(Administrator)

was started @ terça-feira, março 17, 2009, 9:25 PM

 

Killbox Closed(Exit) @ 9:30:23 PM

__________________________________________________

 

Pocket Killbox version 2.0.0.978

Running on Windows XP as Lucas(Administrator)

was started @ terça-feira, março 17, 2009, 9:30 PM

 

# 1 [Delete on Reboot]

Path = C:\Documents and Settings\Lucas\reader_s.exe

 

 

# 2 [Delete on Reboot]

Path = C:\WINDOWS\System32\reader_s.exe

 

 

Killbox Closed(Exit) @ 9:32:07 PM

__________________________________________________

 

Tá certo esse log aí, posso continuar com as outras coisas ?

<><><><><><><><><>

Boa Noite! LucasTO

 

<!> O relatório kb.log está correto! Mas parece que está incompleto...mas,siga com os outros procedimentos.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Eu fiz tudo já, só que realmente nao sei como fazer um outro log do KillBox.

 

Ta aí o log do Hijackthis:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:35:47, on 18/3/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\taskmgr.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\Arquivos de programas\Internet Explorer\iexplore.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Messenger\msmsgs.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

O4 - HKLM\..\Run: [EPSON Stylus CX3700 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACL.EXE /P26 "EPSON Stylus CX3700 Series" /O6 "USB001" /M "Stylus CX3700"

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O17 - HKLM\System\CCS\Services\Tcpip\..\{0EA20956-2EBE-4DFA-98CD-4F78320BABB0}: NameServer = 201.10.120.3 201.10.128.2

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 3900 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! LucasTO

 

<!> Delete a pasta: !KillBox

<!> O ideal,nesse caso,seria configurar o Windows para que essa pasta não fique na lixeira.

<><><><><><><><><><>

<@> Baixe: < Kaspersky Virus Removal Tool >

<@> Salve-o em Arquivos de Programas,e instale-o aí mesmo!

<@> Reinicie o computador,em Modo de Segurança! <-- Importante!

<@> Dê início ao exame,clicando em "Scan".

<@> A verificação é muito demorada. <-- Aguarde!

<@> Caso seja encontrada infecções,clique em "disinfect".

<@> Terminando,clique na aba Events.

<@> Desmarque a caixa de seleção "Show all events".

<@> Clique em "Save to file".

<@> Nomeie-o e salve-o no desktop! <-- Relatório para postagem!

<@> Poste,também,HijackThis atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ja fiz. Abraço..

 

Log Hijackthis:

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:19:23, on 20/3/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe

C:\WINDOWS\system32\rundll32.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\System32\rs32net.exe

C:\Arquivos de programas\AVerTV\QuickTV.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\WINDOWS\system32\taskmgr.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Arquivos de programas\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp

F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\system32\deviceemulator.exe,C:\WINDOWS\system32\c++.exe,C:\WINDOWS\system32\vmware-ufad.exe,C:\WINDOWS\system32\deviceemulator.exe,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [ink Monitor] C:\Arquivos de programas\EPSON\Ink Monitor\InkMonitor.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: is-CN788.lnk = C:\Arquivos de programas\Virus Removal Tool\is-CN788\startup.exe

O4 - Global Startup: QuickTV.lnk = C:\Arquivos de programas\AVerTV\QuickTV.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O20 - Winlogon Notify: hfivki - hfivki.dll (file missing)

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 

--

End of file - 4008 bytes

 

 

 

Log do Kaspersky

 

Scan

----

Scanned: 1411

Detected: 83

Untreated: 0

Start time: 20/3/2009 13:02:14

Duration: 00:07:39

Finish time: 20/3/2009 13:09:53

 

 

Detected

--------

Status Object

------ ------

will be disinfected when the computer is restarted: virus Virus.Win32.Virut.ce File: C:\WINDOWS\Explorer.EXE

will be disinfected when the computer is restarted: virus Virus.Win32.Virut.ce File: C:\WINDOWS\system32\taskmgr.exe

will be disinfected when the computer is restarted: virus Virus.Win32.Virut.ce File: C:\WINDOWS\system32\cmd.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\mshta.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\notepad.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\regedit.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\accwiz.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\windows media player\wmplayer.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\rundll32.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\outlook express\wab.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\hh.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\clipbrd.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\fontview.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\winhlp32.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\winhlp32.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\windows nt\hypertrm.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\internet explorer\iexplore.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\wscript.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\ntbackup.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\mmc.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\rasphone.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\perfmon.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\cyberlink\powerdvd\powerdvd.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\windows nt\acessórios\wordpad.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\notepad.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\avertv\teletext.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\avertv\scheduler.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\cyberlink\common\updateipr.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\wpnpinst.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\drwtsn32.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\userinit.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\cyberlink\powerdvd\pdvdserv.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\nwiz.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\rs32net.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\ctfmon.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\alg.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\cisvc.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\clipsrv.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\dllhost.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\dmadmin.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\imapi.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\mnmsrvc.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\msdtc.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\msiexec.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\netdde.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\sessmgr.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\rsvp.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\scardsvr.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\spoolsv.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\smlogsvc.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\tlntsvr.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\vssvc.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\inf\unregmp2.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\shmgrate.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\regsvr32.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\outlook express\setup50.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\ie4uinit.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\progman.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\logon.scr

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\netmeeting\conf.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\windows nt\dialer.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\twain_32\escndv\escndv.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\pchealth\helpctr\binaries\helpctr.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\internet explorer\connection wizard\isignup.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\usmt\migwiz.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\movie maker\moviemk.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\k-lite codec pack\media player classic\mplayerc.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\outlook express\msimn.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\messenger\msmsgs.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\ahead\nero mediahome\neromediahome.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\mspaint.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\windows nt\pinball\pinball.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\ahead\nero showtime\showtime.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\outlook express\wabmig.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\winrar\winrar.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\windows\system32\ntsd.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\avertv\quicktv.exe

disinfected: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\virus removal tool\is-cn788\startup.exe

will be disinfected when the computer is restarted: virus Virus.Win32.Virut.ce File: c:\arquivos de programas\virus removal tool\is-cn788\is-cn788.exe

 

 

Events

------

Time Name Status Reason

---- ---- ------ ------

20/3/2009 13:03:38 File: C:\WINDOWS\Explorer.EXE detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:03:38 File: C:\WINDOWS\Explorer.EXE not disinfected postponed

20/3/2009 13:03:53 File: C:\WINDOWS\system32\taskmgr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:03:53 File: C:\WINDOWS\system32\taskmgr.exe not disinfected postponed

20/3/2009 13:03:59 File: C:\WINDOWS\system32\cmd.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:03:59 File: C:\WINDOWS\system32\cmd.exe not disinfected postponed

20/3/2009 13:04:03 File: c:\windows\system32\mshta.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:03 File: c:\windows\system32\mshta.exe not disinfected postponed

20/3/2009 13:04:03 File: c:\windows\system32\notepad.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:03 File: c:\windows\system32\notepad.exe not disinfected postponed

20/3/2009 13:04:03 File: c:\windows\regedit.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:04 File: c:\windows\regedit.exe not disinfected postponed

20/3/2009 13:04:06 File: c:\windows\system32\accwiz.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:07 File: c:\windows\system32\accwiz.exe not disinfected postponed

20/3/2009 13:04:07 File: c:\arquivos de programas\windows media player\wmplayer.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:07 File: c:\arquivos de programas\windows media player\wmplayer.exe not disinfected postponed

20/3/2009 13:04:07 File: c:\windows\system32\rundll32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:08 File: c:\windows\system32\rundll32.exe not disinfected postponed

20/3/2009 13:04:08 File: C:\WINDOWS\system32\rundll32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:08 File: C:\WINDOWS\system32\rundll32.exe not disinfected postponed

20/3/2009 13:04:08 File: c:\arquivos de programas\outlook express\wab.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:09 File: c:\arquivos de programas\outlook express\wab.exe not disinfected postponed

20/3/2009 13:04:09 File: c:\windows\explorer.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:09 File: c:\windows\explorer.exe not disinfected postponed

20/3/2009 13:04:09 File: c:\windows\hh.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:10 File: c:\windows\hh.exe not disinfected postponed

20/3/2009 13:04:10 File: c:\windows\system32\clipbrd.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:10 File: c:\windows\system32\clipbrd.exe not disinfected postponed

20/3/2009 13:04:14 File: c:\windows\system32\fontview.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:14 File: c:\windows\system32\fontview.exe not disinfected postponed

20/3/2009 13:04:14 File: c:\windows\winhlp32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:15 File: c:\windows\winhlp32.exe not disinfected postponed

20/3/2009 13:04:15 File: c:\windows\system32\winhlp32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:15 File: c:\windows\system32\winhlp32.exe not disinfected postponed

20/3/2009 13:04:16 File: c:\arquivos de programas\windows nt\hypertrm.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:16 File: c:\arquivos de programas\windows nt\hypertrm.exe not disinfected postponed

20/3/2009 13:04:16 File: c:\arquivos de programas\internet explorer\iexplore.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:17 File: c:\arquivos de programas\internet explorer\iexplore.exe not disinfected postponed

20/3/2009 13:04:17 File: c:\windows\system32\wscript.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:18 File: c:\windows\system32\wscript.exe not disinfected postponed

20/3/2009 13:04:18 File: c:\windows\system32\ntbackup.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:19 File: c:\windows\system32\ntbackup.exe not disinfected postponed

20/3/2009 13:04:19 File: c:\windows\system32\mmc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:20 File: c:\windows\system32\mmc.exe not disinfected postponed

20/3/2009 13:04:22 File: c:\windows\system32\rasphone.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:22 File: c:\windows\system32\rasphone.exe not disinfected postponed

20/3/2009 13:04:23 File: c:\windows\system32\perfmon.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:23 File: c:\windows\system32\perfmon.exe not disinfected postponed

20/3/2009 13:04:23 File: c:\arquivos de programas\cyberlink\powerdvd\powerdvd.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:24 File: c:\arquivos de programas\cyberlink\powerdvd\powerdvd.exe not disinfected postponed

20/3/2009 13:04:26 File: C:\WINDOWS\regedit.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:26 File: C:\WINDOWS\regedit.exe not disinfected postponed

20/3/2009 13:04:27 File: c:\arquivos de programas\windows nt\acessórios\wordpad.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:27 File: c:\arquivos de programas\windows nt\acessórios\wordpad.exe not disinfected postponed

20/3/2009 13:04:27 File: c:\windows\notepad.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:27 File: c:\windows\notepad.exe not disinfected postponed

20/3/2009 13:04:28 File: c:\arquivos de programas\avertv\teletext.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:28 File: c:\arquivos de programas\avertv\teletext.exe not disinfected postponed

20/3/2009 13:04:29 File: c:\arquivos de programas\avertv\scheduler.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:29 File: c:\arquivos de programas\avertv\scheduler.exe not disinfected postponed

20/3/2009 13:04:30 File: c:\arquivos de programas\cyberlink\common\updateipr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:30 File: c:\arquivos de programas\cyberlink\common\updateipr.exe not disinfected postponed

20/3/2009 13:04:30 File: c:\windows\system32\wpnpinst.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:30 File: c:\windows\system32\wpnpinst.exe not disinfected postponed

20/3/2009 13:04:34 File: c:\windows\system32\drwtsn32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:35 File: c:\windows\system32\drwtsn32.exe not disinfected postponed

20/3/2009 13:04:35 File: C:\WINDOWS\explorer.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:35 File: C:\WINDOWS\explorer.exe not disinfected postponed

20/3/2009 13:04:35 File: c:\windows\system32\userinit.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:35 File: c:\windows\system32\userinit.exe not disinfected postponed

20/3/2009 13:04:36 File: c:\arquivos de programas\cyberlink\powerdvd\pdvdserv.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:36 File: c:\arquivos de programas\cyberlink\powerdvd\pdvdserv.exe not disinfected postponed

20/3/2009 13:04:39 File: c:\windows\system32\nwiz.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:39 File: c:\windows\system32\nwiz.exe not disinfected postponed

20/3/2009 13:04:41 File: c:\windows\system32\rs32net.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:41 File: c:\windows\system32\rs32net.exe not disinfected postponed

20/3/2009 13:04:41 File: c:\windows\system32\ctfmon.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:42 File: c:\windows\system32\ctfmon.exe not disinfected postponed

20/3/2009 13:04:50 File: c:\windows\system32\alg.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:50 File: c:\windows\system32\alg.exe not disinfected postponed

20/3/2009 13:04:53 File: c:\windows\system32\cisvc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:53 File: c:\windows\system32\cisvc.exe not disinfected postponed

20/3/2009 13:04:53 File: c:\windows\system32\clipsrv.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:53 File: c:\windows\system32\clipsrv.exe not disinfected postponed

20/3/2009 13:04:53 File: c:\windows\system32\dllhost.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:54 File: c:\windows\system32\dllhost.exe not disinfected postponed

20/3/2009 13:04:54 File: c:\windows\system32\dmadmin.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:54 File: c:\windows\system32\dmadmin.exe not disinfected postponed

20/3/2009 13:04:58 File: c:\windows\system32\imapi.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:04:58 File: c:\windows\system32\imapi.exe not disinfected postponed

20/3/2009 13:05:00 File: c:\windows\system32\mnmsrvc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:00 File: c:\windows\system32\mnmsrvc.exe not disinfected postponed

20/3/2009 13:05:02 File: c:\windows\system32\msdtc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:02 File: c:\windows\system32\msdtc.exe not disinfected postponed

20/3/2009 13:05:02 File: c:\windows\system32\msiexec.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:03 File: c:\windows\system32\msiexec.exe not disinfected postponed

20/3/2009 13:05:04 File: c:\windows\system32\netdde.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:05 File: c:\windows\system32\netdde.exe not disinfected postponed

20/3/2009 13:05:08 File: c:\windows\system32\sessmgr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:08 File: c:\windows\system32\sessmgr.exe not disinfected postponed

20/3/2009 13:05:09 File: c:\windows\system32\rsvp.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:09 File: c:\windows\system32\rsvp.exe not disinfected postponed

20/3/2009 13:05:09 File: c:\windows\system32\scardsvr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:09 File: c:\windows\system32\scardsvr.exe not disinfected postponed

20/3/2009 13:05:10 File: c:\windows\system32\spoolsv.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:10 File: c:\windows\system32\spoolsv.exe not disinfected postponed

20/3/2009 13:05:12 File: c:\windows\system32\smlogsvc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:12 File: c:\windows\system32\smlogsvc.exe not disinfected postponed

20/3/2009 13:05:13 File: c:\windows\system32\tlntsvr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:13 File: c:\windows\system32\tlntsvr.exe not disinfected postponed

20/3/2009 13:05:16 File: c:\windows\system32\vssvc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:16 File: c:\windows\system32\vssvc.exe not disinfected postponed

20/3/2009 13:05:30 File: c:\windows\inf\unregmp2.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:30 File: c:\windows\inf\unregmp2.exe not disinfected postponed

20/3/2009 13:05:31 File: c:\windows\system32\shmgrate.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:31 File: c:\windows\system32\shmgrate.exe not disinfected postponed

20/3/2009 13:05:31 File: c:\windows\system32\regsvr32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:31 File: c:\windows\system32\regsvr32.exe not disinfected postponed

20/3/2009 13:05:32 File: c:\arquivos de programas\outlook express\setup50.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:32 File: c:\arquivos de programas\outlook express\setup50.exe not disinfected postponed

20/3/2009 13:05:33 File: c:\windows\system32\ie4uinit.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:34 File: c:\windows\system32\ie4uinit.exe not disinfected postponed

20/3/2009 13:05:35 File: c:\windows\system32\progman.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:35 File: c:\windows\system32\progman.exe not disinfected postponed

20/3/2009 13:05:42 File: c:\windows\system32\logon.scr detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:42 File: c:\windows\system32\logon.scr not disinfected postponed

20/3/2009 13:05:43 File: C:\WINDOWS\system32\logon.scr detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:43 File: C:\WINDOWS\system32\logon.scr not disinfected postponed

20/3/2009 13:05:54 File: c:\arquivos de programas\netmeeting\conf.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:55 File: c:\arquivos de programas\netmeeting\conf.exe not disinfected postponed

20/3/2009 13:05:55 File: c:\arquivos de programas\windows nt\dialer.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:56 File: c:\arquivos de programas\windows nt\dialer.exe not disinfected postponed

20/3/2009 13:05:56 File: c:\windows\twain_32\escndv\escndv.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:56 File: c:\windows\twain_32\escndv\escndv.exe not disinfected postponed

20/3/2009 13:05:57 File: c:\windows\pchealth\helpctr\binaries\helpctr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:05:57 File: c:\windows\pchealth\helpctr\binaries\helpctr.exe not disinfected postponed

20/3/2009 13:06:00 File: c:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:00 File: c:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe not disinfected postponed

20/3/2009 13:06:01 File: c:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:01 File: c:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe not disinfected postponed

20/3/2009 13:06:01 File: c:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:01 File: c:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe not disinfected postponed

20/3/2009 13:06:02 File: c:\arquivos de programas\internet explorer\connection wizard\isignup.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:02 File: c:\arquivos de programas\internet explorer\connection wizard\isignup.exe not disinfected postponed

20/3/2009 13:06:02 File: c:\windows\system32\usmt\migwiz.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:02 File: c:\windows\system32\usmt\migwiz.exe not disinfected postponed

20/3/2009 13:06:03 File: c:\arquivos de programas\movie maker\moviemk.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:05 File: c:\arquivos de programas\movie maker\moviemk.exe not disinfected postponed

20/3/2009 13:06:06 File: c:\arquivos de programas\k-lite codec pack\media player classic\mplayerc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:08 File: c:\arquivos de programas\k-lite codec pack\media player classic\mplayerc.exe not disinfected postponed

20/3/2009 13:06:09 File: c:\arquivos de programas\outlook express\msimn.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:09 File: c:\arquivos de programas\outlook express\msimn.exe not disinfected postponed

20/3/2009 13:06:09 File: c:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:10 File: c:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe not disinfected postponed

20/3/2009 13:06:10 File: c:\arquivos de programas\messenger\msmsgs.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:11 File: c:\arquivos de programas\messenger\msmsgs.exe not disinfected postponed

20/3/2009 13:06:14 File: c:\arquivos de programas\ahead\nero mediahome\neromediahome.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:15 File: c:\arquivos de programas\ahead\nero mediahome\neromediahome.exe not disinfected postponed

20/3/2009 13:06:17 File: c:\windows\system32\mspaint.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:18 File: c:\windows\system32\mspaint.exe not disinfected postponed

20/3/2009 13:06:18 File: c:\arquivos de programas\windows nt\pinball\pinball.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:18 File: c:\arquivos de programas\windows nt\pinball\pinball.exe not disinfected postponed

20/3/2009 13:06:21 File: c:\arquivos de programas\ahead\nero showtime\showtime.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:23 File: c:\arquivos de programas\ahead\nero showtime\showtime.exe not disinfected postponed

20/3/2009 13:06:24 File: c:\arquivos de programas\outlook express\wabmig.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:24 File: c:\arquivos de programas\outlook express\wabmig.exe not disinfected postponed

20/3/2009 13:06:24 File: c:\arquivos de programas\winrar\winrar.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:25 File: c:\arquivos de programas\winrar\winrar.exe not disinfected postponed

20/3/2009 13:06:26 File: c:\windows\system32\ntsd.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:26 File: c:\windows\system32\ntsd.exe not disinfected postponed

20/3/2009 13:06:27 File: c:\arquivos de programas\avertv\quicktv.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:27 File: c:\arquivos de programas\avertv\quicktv.exe not disinfected postponed

20/3/2009 13:06:28 File: c:\arquivos de programas\virus removal tool\is-cn788\startup.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:28 File: c:\arquivos de programas\virus removal tool\is-cn788\startup.exe not disinfected postponed

20/3/2009 13:06:29 File: c:\arquivos de programas\virus removal tool\is-cn788\is-cn788.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:29 File: c:\arquivos de programas\virus removal tool\is-cn788\is-cn788.exe not disinfected postponed

20/3/2009 13:06:32 File: c:\windows\explorer.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:44 File: c:\windows\explorer.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:44 File: c:\windows\explorer.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:44 File: c:\windows\explorer.exe will be disinfected on system restart

20/3/2009 13:06:45 File: c:\windows\system32\taskmgr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:50 File: c:\windows\system32\taskmgr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:50 File: c:\windows\system32\taskmgr.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:50 File: c:\windows\system32\taskmgr.exe will be disinfected on system restart

20/3/2009 13:06:50 File: c:\windows\system32\cmd.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:53 File: c:\windows\system32\cmd.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:53 File: c:\windows\system32\cmd.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:53 File: c:\windows\system32\cmd.exe will be disinfected on system restart

20/3/2009 13:06:54 File: c:\windows\system32\mshta.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:57 File: c:\windows\system32\mshta.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:06:57 File: c:\windows\system32\notepad.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:00 File: c:\windows\system32\notepad.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:00 File: c:\windows\regedit.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:03 File: c:\windows\regedit.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:03 File: c:\windows\system32\accwiz.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:12 File: c:\windows\system32\accwiz.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:12 File: c:\arquivos de programas\windows media player\wmplayer.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:15 File: c:\arquivos de programas\windows media player\wmplayer.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:15 File: c:\windows\system32\rundll32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:17 File: c:\windows\system32\rundll32.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:18 File: c:\arquivos de programas\outlook express\wab.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:19 File: c:\arquivos de programas\outlook express\wab.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:20 File: c:\windows\hh.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:21 File: c:\windows\hh.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:21 File: c:\windows\system32\clipbrd.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:23 File: c:\windows\system32\clipbrd.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:23 File: c:\windows\system32\fontview.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:25 File: c:\windows\system32\fontview.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:25 File: c:\windows\winhlp32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:26 File: c:\windows\winhlp32.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:27 File: c:\windows\system32\winhlp32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:30 File: c:\windows\system32\winhlp32.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:30 File: c:\arquivos de programas\windows nt\hypertrm.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:34 File: c:\arquivos de programas\windows nt\hypertrm.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:35 File: c:\arquivos de programas\internet explorer\iexplore.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:37 File: c:\arquivos de programas\internet explorer\iexplore.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:38 File: c:\windows\system32\wscript.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:40 File: c:\windows\system32\wscript.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:40 File: c:\windows\system32\ntbackup.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:41 File: c:\windows\system32\ntbackup.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:42 File: c:\windows\system32\mmc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:43 File: c:\windows\system32\mmc.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:44 File: c:\windows\system32\rasphone.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:45 File: c:\windows\system32\rasphone.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:46 File: c:\windows\system32\perfmon.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:47 File: c:\windows\system32\perfmon.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:47 File: c:\arquivos de programas\cyberlink\powerdvd\powerdvd.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:48 File: c:\arquivos de programas\cyberlink\powerdvd\powerdvd.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:49 File: c:\arquivos de programas\windows nt\acessórios\wordpad.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:50 File: c:\arquivos de programas\windows nt\acessórios\wordpad.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:51 File: c:\windows\notepad.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:51 File: c:\windows\notepad.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:52 File: c:\arquivos de programas\avertv\teletext.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:53 File: c:\arquivos de programas\avertv\teletext.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:54 File: c:\arquivos de programas\avertv\scheduler.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:57 File: c:\arquivos de programas\avertv\scheduler.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:58 File: c:\arquivos de programas\cyberlink\common\updateipr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:59 File: c:\arquivos de programas\cyberlink\common\updateipr.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:07:59 File: c:\windows\system32\wpnpinst.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:00 File: c:\windows\system32\wpnpinst.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:01 File: c:\windows\system32\drwtsn32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:02 File: c:\windows\system32\drwtsn32.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:02 File: c:\windows\system32\userinit.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:04 File: c:\windows\system32\userinit.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:04 File: c:\arquivos de programas\cyberlink\powerdvd\pdvdserv.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:05 File: c:\arquivos de programas\cyberlink\powerdvd\pdvdserv.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:06 File: c:\windows\system32\nwiz.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:07 File: c:\windows\system32\nwiz.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:08 File: c:\windows\system32\rs32net.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:09 File: c:\windows\system32\rs32net.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:10 File: c:\windows\system32\ctfmon.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:11 File: c:\windows\system32\ctfmon.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:11 File: c:\windows\system32\alg.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:13 File: c:\windows\system32\alg.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:13 File: c:\windows\system32\cisvc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:15 File: c:\windows\system32\cisvc.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:15 File: c:\windows\system32\clipsrv.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:17 File: c:\windows\system32\clipsrv.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:17 File: c:\windows\system32\dllhost.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:18 File: c:\windows\system32\dllhost.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:18 File: c:\windows\system32\dmadmin.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:19 File: c:\windows\system32\dmadmin.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:20 File: c:\windows\system32\imapi.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:21 File: c:\windows\system32\imapi.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:21 File: c:\windows\system32\mnmsrvc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:22 File: c:\windows\system32\mnmsrvc.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:23 File: c:\windows\system32\msdtc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:24 File: c:\windows\system32\msdtc.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:24 File: c:\windows\system32\msiexec.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:25 File: c:\windows\system32\msiexec.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:26 File: c:\windows\system32\netdde.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:27 File: c:\windows\system32\netdde.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:27 File: c:\windows\system32\sessmgr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:28 File: c:\windows\system32\sessmgr.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:29 File: c:\windows\system32\rsvp.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:30 File: c:\windows\system32\rsvp.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:30 File: c:\windows\system32\scardsvr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:31 File: c:\windows\system32\scardsvr.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:31 File: c:\windows\system32\spoolsv.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:32 File: c:\windows\system32\spoolsv.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:33 File: c:\windows\system32\smlogsvc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:35 File: c:\windows\system32\smlogsvc.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:35 File: c:\windows\system32\tlntsvr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:36 File: c:\windows\system32\tlntsvr.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:36 File: c:\windows\system32\vssvc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:38 File: c:\windows\system32\vssvc.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:38 File: c:\windows\inf\unregmp2.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:40 File: c:\windows\inf\unregmp2.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:40 File: c:\windows\system32\shmgrate.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:45 File: c:\windows\system32\shmgrate.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:45 File: c:\windows\system32\regsvr32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:47 File: c:\windows\system32\regsvr32.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:47 File: c:\arquivos de programas\outlook express\setup50.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:48 File: c:\arquivos de programas\outlook express\setup50.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:49 File: c:\windows\system32\ie4uinit.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:51 File: c:\windows\system32\ie4uinit.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:52 File: c:\windows\system32\progman.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:53 File: c:\windows\system32\progman.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:53 File: c:\windows\system32\logon.scr detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:54 File: c:\windows\system32\logon.scr disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:54 File: c:\arquivos de programas\netmeeting\conf.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:56 File: c:\arquivos de programas\netmeeting\conf.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:56 File: c:\arquivos de programas\windows nt\dialer.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:58 File: c:\arquivos de programas\windows nt\dialer.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:08:58 File: c:\windows\twain_32\escndv\escndv.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:00 File: c:\windows\twain_32\escndv\escndv.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:00 File: c:\windows\pchealth\helpctr\binaries\helpctr.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:02 File: c:\windows\pchealth\helpctr\binaries\helpctr.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:03 File: c:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:04 File: c:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:05 File: c:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:06 File: c:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:07 File: c:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:08 File: c:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:09 File: c:\arquivos de programas\internet explorer\connection wizard\isignup.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:11 File: c:\arquivos de programas\internet explorer\connection wizard\isignup.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:11 File: c:\windows\system32\usmt\migwiz.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:13 File: c:\windows\system32\usmt\migwiz.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:13 File: c:\arquivos de programas\movie maker\moviemk.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:15 File: c:\arquivos de programas\movie maker\moviemk.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:16 File: c:\arquivos de programas\k-lite codec pack\media player classic\mplayerc.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:17 File: c:\arquivos de programas\k-lite codec pack\media player classic\mplayerc.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:18 File: c:\arquivos de programas\outlook express\msimn.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:19 File: c:\arquivos de programas\outlook express\msimn.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:20 File: c:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:21 File: c:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:22 File: c:\arquivos de programas\messenger\msmsgs.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:24 File: c:\arquivos de programas\messenger\msmsgs.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:25 File: c:\arquivos de programas\ahead\nero mediahome\neromediahome.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:28 File: c:\arquivos de programas\ahead\nero mediahome\neromediahome.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:29 File: c:\windows\system32\mspaint.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:31 File: c:\windows\system32\mspaint.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:31 File: c:\arquivos de programas\windows nt\pinball\pinball.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:33 File: c:\arquivos de programas\windows nt\pinball\pinball.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:33 File: c:\arquivos de programas\ahead\nero showtime\showtime.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:35 File: c:\arquivos de programas\ahead\nero showtime\showtime.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:36 File: c:\arquivos de programas\outlook express\wabmig.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:38 File: c:\arquivos de programas\outlook express\wabmig.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:39 File: c:\arquivos de programas\winrar\winrar.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:40 File: c:\arquivos de programas\winrar\winrar.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:41 File: c:\windows\system32\ntsd.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:47 File: c:\windows\system32\ntsd.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:47 File: c:\arquivos de programas\avertv\quicktv.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:49 File: c:\arquivos de programas\avertv\quicktv.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:50 File: c:\arquivos de programas\virus removal tool\is-cn788\startup.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:51 File: c:\arquivos de programas\virus removal tool\is-cn788\startup.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:52 File: c:\arquivos de programas\virus removal tool\is-cn788\is-cn788.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:53 File: c:\arquivos de programas\virus removal tool\is-cn788\is-cn788.exe detected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:53 File: c:\arquivos de programas\virus removal tool\is-cn788\is-cn788.exe disinfected virus 'Virus.Win32.Virut.ce'

20/3/2009 13:09:53 File: c:\arquivos de programas\virus removal tool\is-cn788\is-cn788.exe will be disinfected on system restart

 

 

Statistics

----------

Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted

------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------

 

 

Settings

--------

Parameter Value

--------- -----

Security Level Recommended

Action Prompt for action when the scan is complete

Run mode Manually

File types Scan all files

Scan only new and changed files No

Scan archives All

Scan embedded OLE objects All

Skip if object is larger than No

Skip if scan takes longer than No

Parse email formats No

Scan password-protected archives No

Enable iChecker technology No

Enable iSwift technology No

Show detected threats on "Detected" tab Yes

Rootkits search Yes

Deep rootkits search No

Use heuristic analyzer Yes

 

 

Quarantine

----------

Status Object Size Added

------ ------ ---- -----

 

 

Backup

------

Status Object Size

------ ------ ----

Infected: virus Virus.Win32.Virut.ce c:\windows\twain_32\escndv\escndv.exe 132 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\progman.exe 124 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\outlook express\msimn.exe 76 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\avertv\scheduler.exe 544 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\windows nt\pinball\pinball.exe 294 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\windows nt\dialer.exe 549,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\nwiz.exe 1,4 MB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\tlntsvr.exe 89 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\cyberlink\common\updateipr.exe 174,2 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\mshta.exe 45,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\perfmon.exe 32,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\cyberlink\powerdvd\powerdvd.exe 424 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\netmeeting\conf.exe 1 MB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\netdde.exe 128 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\fontview.exe 38 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\spoolsv.exe 73,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\userinit.exe 41 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\rsvp.exe 146,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\scardsvr.exe 114 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\ahead\nero mediahome\neromediahome.exe 2,6 MB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\internet explorer\connection wizard\icwconn2.exe 104 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\smlogsvc.exe 105,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\winhlp32.exe 298 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\msiexec.exe 92,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\internet explorer\iexplore.exe 108 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\regedit.exe 164 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\wscript.exe 132 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\avertv\teletext.exe 616 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\regsvr32.exe 28,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\hh.exe 27,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\alg.exe 60,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\notepad.exe 85,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\virus removal tool\is-cn788\is-cn788.exe 232 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\rundll32.exe 49,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\inf\unregmp2.exe 228 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\cmd.exe 408 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\outlook express\setup50.exe 89 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\k-lite codec pack\media player classic\mplayerc.exe 4,2 MB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\sessmgr.exe 156 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\msdtc.exe 23 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\rasphone.exe 73 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\taskmgr.exe 155 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\ntbackup.exe 1,2 MB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\drwtsn32.exe 63 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\arquivos comuns\microsoft shared\msinfo\msinfo32.exe 56,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\cisvc.exe 22,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\movie maker\moviemk.exe 3,4 MB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\clipsrv.exe 49,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\windows nt\acessórios\wordpad.exe 227 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\dmadmin.exe 237 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\imapi.exe 163,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\wpnpinst.exe 49 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\ctfmon.exe 32 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\windows nt\hypertrm.exe 44,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\cyberlink\powerdvd\pdvdserv.exe 52 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\winrar\winrar.exe 965 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\clipbrd.exe 119,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\internet explorer\connection wizard\icwconn1.exe 229,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\vssvc.exe 303 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\winhlp32.exe 25 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\shmgrate.exe 58,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\dllhost.exe 22 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\pchealth\helpctr\binaries\helpctr.exe 767,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\notepad.exe 85,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\internet explorer\connection wizard\inetwiz.exe 40 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\outlook express\wab.exe 62 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\usmt\migwiz.exe 256,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\ntsd.exe 48 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\mspaint.exe 354,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\accwiz.exe 200,5 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\logon.scr 232,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\ahead\nero showtime\showtime.exe 3,5 MB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\windows media player\wmplayer.exe 92 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\virus removal tool\is-cn788\startup.exe 84 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\ie4uinit.exe 50,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\messenger\msmsgs.exe 1,6 MB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\outlook express\wabmig.exe 46,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\internet explorer\connection wizard\isignup.exe 36 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\explorer.exe 1 MB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\mnmsrvc.exe 52 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\mmc.exe 813,5 KB

Infected: virus Virus.Win32.Virut.ce c:\arquivos de programas\avertv\quicktv.exe 412 KB

Infected: virus Virus.Win32.Virut.ce c:\windows\system32\rs32net.exe 40 KB

Compartilhar este post


Link para o post
Compartilhar em outros sites
Porque sera que minha net tá tao lenta?

Ela nao era assim, ela ta bem lenta mesmo.

<><><><><><><><><>

Opa! LucasTO

 

<!> Voçê ainda está infectado pelo Virut. :mellow:

<><><><><><><><><>

<!> Vá neste endereço,Post #2,e execute a vacina anti-virut.

 

< http://forum.imasters.com.br/index.php?showtopic=248543 >

 

<!> Terminando,baixe e execute o DrWebCureit.

<><><><><><><><><>

<@> Baixe: < drweb.gif >

<@> Salve-o no desktop!

<@> Reinicie o computador em Modo de Segurança.

<@> Inicie a instalação/execução,com um duplo-clique em drweb-cureit.

<@> Na janela que abrir,clique em Iniciar --> OK.

<@> Será dado início a "Verificação rápida" --> Feche a janela de propaganda!

<@> Terminando,marque a caixa de "Verificação Completa".

<@> Click em "Options" --> Em Change settings,desmarque a "Heuristic analysis".

 

Neste modo são verificados os seguintes objectos:

 

* Sectores de Arranque de Todos os Discos. <--

 

* Todas as Unidades Removíveis. <--

 

* Todos os Discos Locais. <--

<@> Clique em "Iniciar verificação" --> Aguarde!

<@> Surgindo mensagens para mover ou desinfectar arquivos,clique em Sim.

<@> Terminando,clique em "Ficheiro" --> "Guardar lista de relatórios".

<@> Procure salvá-lo em um local adequado. ( DrWeb.csv ) <-- Texto!

<@> Poste: DrWeb.csv + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.