Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

P@TY

[Arquivado] Suspeita de virus! Analisem log

Recommended Posts

Acho que meu pc tá com virus, o ieexplore.exe está sendo executado, roubando boa parte da memoria e deixando o pc lento...

Gostaria que analisassem o log!!!

 

Agradeço desde já!

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:25:45, on 19/3/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\tsnpstd3.exe

C:\WINDOWS\vsnpstd3.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\Search Settings\SearchSettings.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AcroRd32.exe

C:\hijackthis\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.compartilhando.org/

R3 - URLSearchHook: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg1.dll

R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Arquivos de programas\Search Settings\kb127\SearchSettings.dll

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.3.1.15.dll

O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg1.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Arquivos de programas\Search Settings\kb127\SearchSettings.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg1.dll

O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll

O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe

O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [au] C:\Arquivos de programas\Dealio\DealioAU.exe

O4 - HKLM\..\Run: [searchSettings] C:\Arquivos de programas\Search Settings\SearchSettings.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [bitComet] "C:\Arquivos de programas\BitComet\BitComet.exe" /tray

O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O8 - Extra context menu item: &B&aixar &com o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: &B&aixar todos os vídeos com o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: &B&aixar tudo usando o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Administrador\Dados de aplicativos\Dealio\kb127\res\DealioSearch.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~1\OFFICE11\REFIEBAR.DLL

O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.3.1.15.dll/206 (file missing)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll

O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/

O15 - Trusted Zone: http://asia.msi.com.tw

O15 - Trusted Zone: http://global.msi.com.tw

O15 - Trusted Zone: http://www.msi.com.tw

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1215217802500

O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1...ows-i586-jc.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9D2031-23A5-4E75-9C48-45FF09206DE3}: NameServer = 200.204.0.10 200.204.0.138

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Arquivos de programas\NOS\bin\getPlus_HelperSvc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

 

--

End of file - 12579 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! P@TY

 

<@> Baixe: < desktopicon.png > ( ...by sUBs )

<@> Salve-o no desktop!

<@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! )

<@> Feche todas as janelas e execute a ferramenta!

<@> Na solicitação: "Negação de garantia de software" --> Clique em Sim!

<@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo!

 

<!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.

<!> Salve-a no desktop,renomeada como: Kombo.exe

<!> Ps: Nomeie durante o salvamento,e não após salvá-la!

<!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança. <-- Link!

<!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde!

<!> Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas.

<!> Ps: O ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão profissional.

<@> Abrir-se-á a janela Auto Scan. --> Aguarde!

<@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador.

<@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão!

<@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante!

<@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter!

<><><><><><><><><><><><>

<@> Terminando,poste os relatórios: C:\ComboFix\ComboFix.txt + HijackThis,atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 09-03-19.02 - Administrador 2009-03-21 22:07:54.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.447.204 [GMT -3:00]

Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe

AV: avast! antivirus 4.8.1335 [VPS 090321-0] *On-access scanning disabled* (Updated)

* Criado um novo ponto de restauro

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-02-22 to 2009-03-22 ))))))))))))))))))))))))))))

.

 

2009-03-19 15:12 . 2009-03-19 15:25 <DIR> d-------- C:\hijackthis

2009-02-26 23:29 . 2009-02-26 23:29 268 --ah----- C:\sqmdata01.sqm

2009-02-26 23:29 . 2009-02-26 23:29 244 --ah----- C:\sqmnoopt01.sqm

2009-02-26 01:34 . 2009-02-26 01:35 <DIR> d-------- C:\DVD

2009-02-24 21:36 . 2009-02-24 21:36 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Lavasoft

2009-02-24 21:36 . 2009-02-24 21:36 <DIR> d-------- c:\arquivos de programas\Lavasoft

2009-02-24 20:43 . 2009-02-24 20:43 <DIR> d-------- c:\documents and settings\Administrador\Configuraes locais

2009-02-24 20:24 . 2009-02-24 20:24 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems

2009-02-24 20:24 . 2009-02-24 20:24 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared

2009-02-24 20:06 . 2009-02-24 20:06 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools Pro

2009-02-24 20:06 . 2009-02-24 20:06 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools

2009-02-24 20:05 . 2009-02-24 20:05 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\DAEMON Tools Lite

2009-02-24 20:02 . 2009-02-24 21:07 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Toolbar

2009-02-24 20:01 . 2009-02-24 20:04 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite

2009-02-24 19:55 . 2009-02-24 20:14 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools Lite

2009-02-24 19:55 . 2009-02-24 19:55 717,296 --a------ c:\windows\system32\drivers\sptd.sys

2009-02-23 18:58 . 2009-02-23 19:31 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\FairStars Audio Converter

2009-02-23 18:58 . 2009-02-23 18:58 <DIR> d-------- c:\arquivos de programas\FairStars Audio Converter

2009-02-23 17:01 . 2009-03-16 13:11 <DIR> d-------- C:\Downloads

2009-02-23 17:00 . 2009-03-21 12:52 <DIR> d-------- c:\arquivos de programas\BitComet

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-03-22 00:34 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Skype

2009-03-21 16:11 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Google Updater

2009-03-17 12:24 --------- d-----w c:\arquivos de programas\Yahoo!

2009-03-16 16:15 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Skype

2009-03-16 16:15 --------- d-----r c:\arquivos de programas\Skype

2009-03-16 15:15 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\skypePM

2009-03-15 21:00 --------- d-----w c:\arquivos de programas\Norton Security Scan

2009-03-08 21:03 --------- d-----w c:\arquivos de programas\Arquivos comuns\Symantec Shared

2009-02-24 23:28 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2009-02-24 23:12 --------- d-----w c:\arquivos de programas\eMule

2009-02-10 03:17 --------- d-----w c:\arquivos de programas\Messenger Plus! Live

2009-02-10 01:52 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DriverScanner

2009-02-10 01:52 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Uniblue

2009-02-10 00:53 --------- d--h--w c:\documents and settings\All Users\Dados de aplicativos\CanonBJ

2009-02-10 00:51 --------- d--h--w c:\arquivos de programas\CanonBJ

2009-02-09 14:06 1,846,912 ----a-w c:\windows\system32\win32k.sys

2009-02-09 14:06 1,846,912 ------w c:\windows\system32\DllCache\win32k.sys

2009-01-16 23:16 3,594,752 ------w c:\windows\system32\DllCache\mshtml.dll

2004-07-22 13:51 3,432,656 ----a-w c:\arquivos de programas\ManagedDX.CAB

2004-07-20 01:58 1,156,363 ----a-w c:\arquivos de programas\BDANT.cab

2004-07-20 01:53 976,020 ----a-w c:\arquivos de programas\BDAXP.cab

2004-07-09 17:17 13,265,040 ----a-w c:\arquivos de programas\dxnt.cab

2004-07-09 12:13 703,080 ----a-w c:\arquivos de programas\BDA.cab

2004-07-09 12:13 15,493,481 ----a-w c:\arquivos de programas\DirectX.cab

2004-07-09 07:08 472,576 ----a-w c:\arquivos de programas\dxsetup.exe

2004-07-09 07:08 2,242,560 ----a-w c:\arquivos de programas\dsetup32.dll

2004-07-09 06:03 62,976 ----a-w c:\arquivos de programas\DSETUP.dll

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]

"{db9d7a78-a76c-4bf2-97c6-258925ee1542}"= "c:\arquivos de programas\Reganam\tbReg0.dll" [2009-03-20 1883672]

 

[HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]

2009-03-20 23:06 1883672 --a------ c:\arquivos de programas\Reganam\tbReg0.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{db9d7a78-a76c-4bf2-97c6-258925ee1542}"= "c:\arquivos de programas\Reganam\tbReg0.dll" [2009-03-20 1883672]

 

[HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{DB9D7A78-A76C-4BF2-97C6-258925EE1542}"= "c:\arquivos de programas\Reganam\tbReg0.dll" [2009-03-20 1883672]

 

[HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

"swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-01 68856]

"MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2008-10-06 5724184]

"BitComet"="c:\arquivos de programas\BitComet\BitComet.exe" [2009-01-20 2523960]

"Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2009-03-06 24095528]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]

"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-07-07 262144]

"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600]

"au"="c:\arquivos de programas\Dealio\DealioAU.exe" [2008-05-26 595296]

"SearchSettings"="c:\arquivos de programas\Search Settings\SearchSettings.exe" [2008-06-12 991584]

"VTTimer"="VTTimer.exe" [2005-03-08 c:\windows\system32\VTTimer.exe]

"VTTrayp"="VTtrayp.exe" [2005-03-11 c:\windows\system32\VTTrayp.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"nlsf"="move" [X]

"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]

 

c:\documents and settings\Administrador\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"ForceClassicControlPanel"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.DIV3"= DivXc32.dll

"vidc.DIV4"= DivXc32f.dll

"vidc.3iv2"= 3ivxVfWCodec.dll

"msacm.divxa32"= divxa32.acm

"VIDC.HFYU"= huffyuv.dll

"VIDC.i263"= i263_32.drv

"msacm.imc"= imc32.acm

"VIDC.VP31"= vp31vfw.dll

"msacm.avis"= ff_acm.acm

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\Ares\\Ares.exe"=

"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=

"c:\\Arquivos de programas\\eMule\\emule.exe"=

"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"23189:TCP"= 23189:TCP:BitComet 23189 TCP

"23189:UDP"= 23189:UDP:BitComet 23189 UDP

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-01 114768]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-07-01 20560]

S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2005-09-19 77312]

S3 A0380VID;USB2.0 PC Camera;c:\windows\system32\DRIVERS\A0380Vid.sys --> c:\windows\system32\DRIVERS\A0380Vid.sys [?]

S3 getPlus® Helper;getPlus® Helper;c:\arquivos de programas\NOS\bin\getPlus_HelperSvc.exe [2008-07-02 31592]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1cff4ec0-488f-11dd-866e-001617ff2b8e}]

\Shell\Auto\command - E:\MicrosoftPowerPoint.exe

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-03-15 c:\windows\Tasks\Norton Security Scan for Administrador.job

- c:\arquivos de programas\Norton Security Scan\Nss.exe [2009-03-11 20:20]

.

- - - - ORFÃOS REMOVIDOS - - - -

 

HKU-Default-Run-MsnMsgr - c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe

 

 

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.daemon-search.com/startpage

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Connection Wizard,ShellNext = hxxp://www.compartilhando.org/

IE: &B&aixar &com o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddLink.htm

IE: &B&aixar todos os vídeos com o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

IE: &B&aixar tudo usando o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

IE: Compare Prices with &Dealio - c:\documents and settings\Administrador\Dados de aplicativos\Dealio\kb127\res\DealioSearch.html

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~1\OFFICE11\EXCEL.EXE/3000

Trusted Zone: com.tw\asia.msi

Trusted Zone: com.tw\global.msi

Trusted Zone: com.tw\www.msi

TCP: {BA9D2031-23A5-4E75-9C48-45FF09206DE3} = 200.204.0.10 200.204.0.138

DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab

DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-21 22:12:48

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

Tempo para conclusão: 2009-03-21 22:16:06

ComboFix-quarantined-files.txt 2009-03-22 01:15:54

 

Pré-execução: 21 pasta(s) 47.418.265.600 bytes disponíveis

Pós execução: 21 pasta(s) 48,128,352,256 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

184 --- E O F --- 2009-03-13 05:58:07

 

 

 

 

 

 

 

----------------------

 

 

Hijackthis

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:21:51, on 21/3/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AcroRd32.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\explorer.exe

C:\hijackthis\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.compartilhando.org/

R3 - URLSearchHook: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg0.dll

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.3.1.15.dll

O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

O2 - BHO: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg0.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg0.dll

O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll

O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll

O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe

O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe

O4 - HKLM\..\Run: [VTTimer] VTTimer.exe

O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [au] C:\Arquivos de programas\Dealio\DealioAU.exe

O4 - HKLM\..\Run: [searchSettings] C:\Arquivos de programas\Search Settings\SearchSettings.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [bitComet] "C:\Arquivos de programas\BitComet\BitComet.exe" /tray

O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe

O8 - Extra context menu item: &B&aixar &com o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm

O8 - Extra context menu item: &B&aixar todos os vídeos com o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

O8 - Extra context menu item: &B&aixar tudo usando o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Administrador\Dados de aplicativos\Dealio\kb127\res\DealioSearch.html

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~1\OFFICE11\REFIEBAR.DLL

O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.3.1.15.dll/206 (file missing)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll

O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/

O15 - Trusted Zone: http://asia.msi.com.tw

O15 - Trusted Zone: http://global.msi.com.tw

O15 - Trusted Zone: http://www.msi.com.tw

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1215217802500

O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1...ows-i586-jc.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9D2031-23A5-4E75-9C48-45FF09206DE3}: NameServer = 200.204.0.10 200.204.0.138

O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll

O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Arquivos de programas\NOS\bin\getPlus_HelperSvc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

 

--

End of file - 11457 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! P@TY

 

<@> Baixe: < ToolBar S&D >

<@> Salve-o no desktop!

<@> Reinicie o computador,em Modo de Segurança. <-- Importante!

<@> Execute o programa,e à seguir,aperte o "p" --> Enter --> Ok.

<@> Digite o dois! ( 2 ) --> Aperte Enter --> Aguarde!

<@> Terminando,poste o relatório. ( C:\ToolBar SD\TB_1.txt )

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

-----------\\ ToolBar S&D 1.2.8 XP/Vista

 

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3

X86-based PC ( Uniprocessor Free : Intel® Celeron® CPU 2.66GHz )

BIOS : Phoenix - AwardBIOS v6.00PG

USER : Administrador ( Administrator )

BOOT : Fail-safe boot

Antivirus : avast! antivirus 4.8.1335 [VPS 090328-0] 4.8.1335 (Activated)

C:\ (Local Disk) - NTFS - Total:74 Go (Free:41 Go)

D:\ (CD or DVD) - CDFS - Total:3 Go (Free:0 Go)

E:\ (CD or DVD)

 

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )

Option : [2] ( dom 29/03/2009|15:05 )

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsb1A.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nscB.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsd13.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsf11.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsfB.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsg13.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsg7E.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsi22.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsi6F.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsjB.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsk11.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsk18.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nskF.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nslB.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsm92.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsn10.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsp15.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nspB.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nspE.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsr19.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsrD.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nss12.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nst1D.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsv47.tmp(null)

C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsvA.tmp(null)

 

-----------\\ REMOVIDOS

 

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\Dealio\dinstallhelper.92681965C6DA4818A90872AA5A777D3D.dll

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\Dealio\kb127

Deletado! - C:\Arquivos de programas\Dealio\DealioAU.exe

Deletado! - C:\Arquivos de programas\Dealio\kb127

Deletado! - C:\Arquivos de programas\Dealio\SearchSettingsKit.exe

Deletado! - C:\DOCUME~1\ALLUSE~1\MENUIN~1\PROGRA~1\Dealio

Deletado! - C:\Arquivos de programas\DAEMON Tools Toolbar\_DTLite.xml

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\Search Settings\kb127

Deletado! - C:\Arquivos de programas\Search Settings\kb127

Deletado! - C:\Arquivos de programas\Search Settings\SearchSettings.exe

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsb1A.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nscB.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsd13.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsf11.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsfB.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsg13.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsg7E.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsi22.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsi6F.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsjB.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsk11.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsk18.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nskF.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nslB.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsm92.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsn10.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsp15.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nspB.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nspE.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsr19.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsrD.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nss12.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nst1D.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsv47.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsvA.tmp(null)

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\Dealio

Deletado! - C:\Arquivos de programas\Dealio

Deletado! - C:\Arquivos de programas\DAEMON Tools Toolbar

Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\Search Settings

Deletado! - C:\Arquivos de programas\Search Settings

 

-----------\\ Procura por Arquivos / Ficheiros ...

 

 

-----------\\ [..\Internet Explorer\Main]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

"Start Page"="http://www.daemon-search.com/startpage"

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

"SearchMigratedDefaultURL"="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"

"Url"="http://go.microsoft.com/fwlink/?LinkId=75724"

"Url"="http://go.microsoft.com/fwlink/?LinkId=75723"

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Start Page"="http://www.msn.com/"

 

 

--------------------\\ Procurando por outras infecções

 

 

Não foram encontradas outras infecções.

 

 

1 - "C:\ToolBar SD\TB_1.txt" - dom 29/03/2009|15:08 - Option : [2]

 

-----------\\ Verificação completa em 15:08:17,54

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! P@TY

 

<@> Baixe: < DDS > ( ...by sUBs )

<@> Salve-o no desktop!

<@> Desabilite seus programas de proteção: antivírus,antimalware,antispyware ou firewall.

<@> Estando desconectado,execute a ferramenta! --> Duplo clique em dds.scr.

<@> Aguarde o término do scan,até obtermos o relatório. ( DDS.txt ) <--

<@> Surgirá,também,uma nova janela: "D.D.S - Optional_Scan" --> Clique em Sim.

<@> O Bloco de Notas irá abrir,com outro relatório. ( Attach.txt ) <--

<@> Ps: Caso o relatório seja incompreensível,renomeie o executável para DDS.exe e repita o scan.

<@> Outra janela,finalmente,abrir-se-à! --> Clique em OK.

<@> Salve os relatórios: DDS.txt + Attach.txt <-- Poste-os!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

DDS (Ver_09-03-16.01) - NTFSx86

Run by Administrador at 15:48:33,56 on sáb 04/04/2009

Internet Explorer: 7.0.5730.13

Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.447.204 [GMT -3:00]

 

AV: avast! antivirus 4.8.1335 [VPS 090404-0] *On-access scanning disabled* (Updated)

 

============== Running Processes ===============

 

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe

C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\HPZipm12.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\tsnpstd3.exe

C:\WINDOWS\vsnpstd3.exe

C:\WINDOWS\system32\VTTimer.exe

C:\WINDOWS\system32\VTtrayp.exe

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\Google\Quick Search Box\qsb.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe

C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AcroRd32.exe

C:\Arquivos de programas\Ares\Ares.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Documents and Settings\Administrador\Desktop\dds.scr

 

============== Pseudo HJT Report ===============

 

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

mWindow Title =

uInternet Connection Wizard,ShellNext = hxxp://www.compartilhando.org/

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File

BHO: Facilitador de Leitor de Link Adobe PDF: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\arquivos de programas\arquivos comuns\adobe\acrobat\activex\AcroIEHelper.dll

BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\arquivos de programas\skype\toolbars\internet explorer\SkypeIEPlugin.dll

BHO: ssh2 Class: {2e3c3651-b19c-4dd9-a979-901ec3e930af} - c:\arquivos de programas\scpad\scpsssh2.dll

BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\arquivos de programas\bitcomet\tools\BitCometBHO_1.3.1.15.dll

BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\arquivos de programas\java\jre6\bin\ssv.dll

BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\arquivos de programas\google\google toolbar\GoogleToolbar.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\arquivos de programas\google\googletoolbarnotifier\5.1.1309.3572\swg.dll

BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\arquivos de programas\google\google toolbar\component\fastsearch_9993303B90FE6C1D.dll

BHO: {db9d7a78-a76c-4bf2-97c6-258925ee1542} - No File

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\arquivos de programas\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\arquivos de programas\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\arquivos de programas\google\google toolbar\GoogleToolbar.dll

TB: Dealio: {e67c74f4-a00a-4f2c-9fec-fd9dc004a67f} - c:\arquivos de programas\dealio\kb127\Dealio.dll

uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe

uRun: [swg] c:\arquivos de programas\google\googletoolbarnotifier\GoogleToolbarNotifier.exe

uRun: [MsnMsgr] "c:\arquivos de programas\windows live\messenger\MsnMsgr.Exe" /background

uRun: [bitComet] "c:\arquivos de programas\bitcomet\BitComet.exe" /tray

mRun: [avast!] c:\arquiv~1\alwils~1\avast4\ashDisp.exe

mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe

mRun: [Adobe Reader Speed Launcher] "c:\arquivos de programas\adobe\reader 8.0\reader\Reader_sl.exe"

mRun: [tsnpstd3] c:\windows\tsnpstd3.exe

mRun: [snpstd3] c:\windows\vsnpstd3.exe

mRun: [VTTimer] VTTimer.exe

mRun: [VTTrayp] VTtrayp.exe

mRun: [sunJavaUpdateSched] "c:\arquivos de programas\java\jre6\bin\jusched.exe"

mRun: [Google Quick Search Box] "c:\arquivos de programas\google\quick search box\qsb.exe" /autorun

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

dRunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"

dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe

StartupFolder: c:\docume~1\admini~1\menuin~1\progra~1\inicia~1\adobeg~1.lnk - c:\arquivos de programas\arquivos comuns\adobe\calibration\Adobe Gamma Loader.exe

mPolicies-explorer: ForceClassicControlPanel = 1 (0x1)

IE: &B&aixar &com o BitComet - c:\arquivos de programas\bitcomet\BitComet.exe/AddLink.htm

IE: &B&aixar todos os vídeos com o BitComet - c:\arquivos de programas\bitcomet\BitComet.exe/AddVideo.htm

IE: &B&aixar tudo usando o BitComet - c:\arquivos de programas\bitcomet\BitComet.exe/AddAllLink.htm

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\micros~1\office11\EXCEL.EXE/3000

IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\arquivos de programas\bitcomet\tools\BitCometBHO_1.3.1.15.dll/206

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\arquivos de programas\messenger\msmsgs.exe

IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\arquivos de programas\skype\toolbars\internet explorer\SkypeIEPlugin.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\arquiv~1\micros~1\office11\REFIEBAR.DLL

Trusted Zone: com.tw\asia.msi

Trusted Zone: com.tw\global.msi

Trusted Zone: com.tw\www.msi

DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab

DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215217802500

DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?AuthParam=1228950478_5f63fcd06eb021484fd53032919ca405&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab&File=jinstall-6u11-windows-i586-jc.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game05.zylom.com/activex/zylomgamesplayer.cab

DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab

DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab

DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab

TCP: {BA9D2031-23A5-4E75-9C48-45FF09206DE3} = 200.204.0.10 200.204.0.138

Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\arquivos de programas\google\google toolbar\component\fastsearch_9993303B90FE6C1D.dll

SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - c:\arquivos de programas\scpad\scpLIB.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

STS: compIB Class: {a3717295-941d-416f-9384-ed1736729f1c} - c:\arquivos de programas\scpad\scpLIB.dll

 

============= SERVICES / DRIVERS ===============

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-7-1 114768]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-7-1 20560]

R2 avast! Antivirus;avast! Antivirus;c:\arquivos de programas\alwil software\avast4\ashServ.exe [2008-7-1 138680]

S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2005-9-19 77312]

S3 A0380VID;USB2.0 PC Camera;c:\windows\system32\drivers\a0380vid.sys --> c:\windows\system32\drivers\A0380Vid.sys [?]

S3 avast! Mail Scanner;avast! Mail Scanner;c:\arquivos de programas\alwil software\avast4\ashMaiSv.exe [2008-7-1 254040]

S3 avast! Web Scanner;avast! Web Scanner;c:\arquivos de programas\alwil software\avast4\ashWebSv.exe [2008-7-1 352920]

S3 getPlus® Helper;getPlus® Helper;c:\arquivos de programas\nos\bin\getPlus_HelperSvc.exe [2008-7-2 31592]

 

=============== Created Last 30 ================

 

2009-04-04 15:40 <DIR> --d----- c:\arquivos de programas\CCleaner

2009-03-29 18:34 <DIR> --d----- c:\docume~1\alluse~1\dadosd~1\Zylom

2009-03-29 16:01 207,120 a------- c:\arquivos de programas\GoogleToolbarInstaller_download_signed.exe

2009-03-29 15:04 <DIR> --d----- C:\ToolBar SD

2009-03-28 13:44 <DIR> --d----- c:\arquivos de programas\WorldUnlock Codes Calculator

2009-03-28 13:44 170,393 a------- c:\arquivos de programas\WorldUnlock-v44-Setup-Baixaki.exe

2009-03-22 21:12 <DIR> --d----- c:\docume~1\alluse~1\dadosd~1\SSScanAppDataDir

2009-03-22 21:11 <DIR> --d----- c:\docume~1\alluse~1\dadosd~1\MSScanAppDataDir

2009-03-21 22:03 <DIR> a-dshr-- C:\cmdcons

2009-03-21 21:46 161,792 a------- c:\windows\SWREG.exe

2009-03-21 21:46 98,816 a------- c:\windows\sed.exe

2009-03-19 15:12 <DIR> --d----- C:\hijackthis

 

==================== Find3M ====================

 

2009-02-24 19:55 717,296 a------- c:\windows\system32\drivers\sptd.sys

2009-02-23 16:58 5,517,160 a------- c:\arquivos de programas\bitcomet_setup.exe

2009-02-15 11:23 338,240 a------- c:\windows\system32\perfh016.dat

2009-02-15 11:23 46,226 a------- c:\windows\system32\perfc016.dat

2009-02-09 11:06 1,846,912 a------- c:\windows\system32\win32k.sys

2009-02-09 11:06 1,846,912 -------- c:\windows\system32\dllcache\win32k.sys

2009-01-16 20:16 3,594,752 -------- c:\windows\system32\dllcache\mshtml.dll

2008-12-18 17:57 6,121,482 a------- c:\arquivos de programas\Setup_FreeFlvConverter.exe

2008-10-03 02:46 3,518,422 a------- c:\arquivos de programas\flvplayer_setup.exe

2008-09-16 15:40 382,104 a------- c:\arquivos de programas\wpsetup.exe

2008-07-08 21:52 767 a------- c:\arquivos de programas\save2pc Light.lnk

2008-07-07 23:03 4,780,368 a------- c:\arquivos de programas\MsgPlusLive-460.exe

2008-07-07 22:55 2,403,344 a------- c:\arquivos de programas\WLinstaller.exe

2004-07-22 10:51 3,432,656 a------- c:\arquivos de programas\ManagedDX.CAB

2004-07-19 22:58 1,156,363 a------- c:\arquivos de programas\BDANT.cab

2004-07-19 22:53 976,020 a------- c:\arquivos de programas\BDAXP.cab

2004-07-09 14:17 13,265,040 a------- c:\arquivos de programas\dxnt.cab

2004-07-09 09:13 15,493,481 a------- c:\arquivos de programas\DirectX.cab

2004-07-09 09:13 703,080 a------- c:\arquivos de programas\BDA.cab

2004-07-09 04:08 472,576 a------- c:\arquivos de programas\dxsetup.exe

2004-07-09 04:08 2,242,560 a------- c:\arquivos de programas\dsetup32.dll

2004-07-09 03:03 62,976 a------- c:\arquivos de programas\DSETUP.dll

 

============= FINISH: 15:49:15,59 ===============

 

 

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

 

DDS (Ver_09-03-16.01)

 

Microsoft Windows XP Professional

Boot Device: \Device\HarddiskVolume1

Install Date: 1/7/2008 22:23:11

System Uptime: 4/4/2009 11:33:59 (4 hours ago)

 

Motherboard: MICRO-STAR INTERNATIONAL CO., LTD | | MS-7211

Processor: Intel® Celeron® CPU 2.66GHz | Socket 775 | 2660/133mhz

 

==== Disk Partitions =========================

 

C: is FIXED (NTFS) - 75 GiB total, 43,878 GiB free.

D: is CDROM (CDFS)

E: is CDROM ()

 

==== Disabled Device Manager Items =============

 

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}

Description: Modem PCI

Device ID: PCI\VEN_1057&DEV_3052&SUBSYS_30201057&REV_04\3&13C0B0C5&0&48

Manufacturer:

Name: Modem PCI

PNP Device ID: PCI\VEN_1057&DEV_3052&SUBSYS_30201057&REV_04\3&13C0B0C5&0&48

Service:

 

==== System Restore Points ===================

 

RP154: 30/1/2009 02:20:53 - Software Distribution Service 3.0

RP155: 31/1/2009 13:14:23 - Ponto de verificação do sistema

RP156: 1/2/2009 14:52:07 - Ponto de verificação do sistema

RP157: 2/2/2009 22:11:27 - Ponto de verificação do sistema

RP158: 3/2/2009 23:53:51 - Ponto de verificação do sistema

RP159: 5/2/2009 12:57:32 - Ponto de verificação do sistema

RP160: 6/2/2009 16:35:46 - Ponto de verificação do sistema

RP161: 7/2/2009 22:29:59 - Ponto de verificação do sistema

RP162: 9/2/2009 15:47:20 - Ponto de verificação do sistema

RP163: 10/2/2009 16:22:32 - Ponto de verificação do sistema

RP164: 11/2/2009 17:52:23 - Software Distribution Service 3.0

RP165: 13/2/2009 12:42:13 - Ponto de verificação do sistema

RP166: 14/2/2009 21:30:31 - Ponto de verificação do sistema

RP167: 15/2/2009 16:39:22 -

RP168: 15/2/2009 16:40:11 -

RP169: 15/2/2009 16:41:36 -

RP170: 16/2/2009 21:16:30 - Ponto de verificação do sistema

RP171: 17/2/2009 23:42:00 - Ponto de verificação do sistema

RP172: 19/2/2009 15:03:54 - Ponto de verificação do sistema

RP173: 21/2/2009 22:14:32 - Ponto de verificação do sistema

RP174: 23/2/2009 11:46:43 - Ponto de verificação do sistema

RP175: 24/2/2009 19:55:42 - SPTD setup V1.56

RP176: 24/2/2009 20:21:42 - Installed Adobe Photoshop CS2

RP177: 25/2/2009 22:52:25 - Software Distribution Service 3.0

RP178: 28/2/2009 11:40:33 - Ponto de verificação do sistema

RP179: 1/3/2009 22:14:54 - Ponto de verificação do sistema

RP180: 2/3/2009 22:34:49 - Ponto de verificação do sistema

RP181: 4/3/2009 09:54:42 - Ponto de verificação do sistema

RP182: 5/3/2009 17:20:40 - Ponto de verificação do sistema

RP183: 10/3/2009 17:28:00 - Ponto de verificação do sistema

RP184: 11/3/2009 18:10:42 - Software Distribution Service 3.0

RP185: 13/3/2009 02:56:10 - Software Distribution Service 3.0

RP186: 14/3/2009 16:09:04 - Ponto de verificação do sistema

RP187: 15/3/2009 19:24:24 - Ponto de verificação do sistema

RP188: 16/3/2009 19:37:13 - Ponto de verificação do sistema

RP189: 18/3/2009 14:05:22 - Ponto de verificação do sistema

RP190: 19/3/2009 16:18:44 - Ponto de verificação do sistema

RP191: 20/3/2009 22:25:27 - Ponto de verificação do sistema

RP192: 21/3/2009 21:46:36 - ComboFix created restore point

RP193: 23/3/2009 13:01:30 - Ponto de verificação do sistema

RP194: 24/3/2009 15:37:53 - Ponto de verificação do sistema

RP195: 25/3/2009 17:53:15 - Ponto de verificação do sistema

RP196: 26/3/2009 22:58:05 - Ponto de verificação do sistema

RP197: 27/3/2009 23:11:17 - Ponto de verificação do sistema

RP198: 30/3/2009 17:07:41 - Ponto de verificação do sistema

RP199: 31/3/2009 22:07:46 - Ponto de verificação do sistema

RP200: 2/4/2009 23:34:05 - Ponto de verificação do sistema

RP201: 4/4/2009 13:59:04 - Ponto de verificação do sistema

 

==== Installed Programs ======================

 

Ad-Aware SE Personal

Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)

Adobe Bridge 1.0

Adobe Common File Installer

Adobe Flash Player 10 ActiveX

Adobe Help Center 1.0

Adobe Photoshop CS2

Adobe Reader 8.1.2 - Português

Adobe Reader 8.1.2 Security Update 1 (KB403742)

Adobe Shockwave Player

Adobe Stock Photos 1.0

Ares 2.0.9

Arquivo do WinRAR

Atualização Crítica para o Windows Media Player 11 (KB959772)

Atualização de Segurança para o Windows Media Player (KB952069)

Atualização de Segurança para o Windows Media Player 10 (KB936782)

Atualização de Segurança para o Windows Media Player 11 (KB936782)

Atualização de Segurança para o Windows Media Player 11 (KB954154)

Atualização de Segurança para Windows Internet Explorer 7 (KB938127-v2)

Atualização de Segurança para Windows Internet Explorer 7 (KB950759)

Atualização de Segurança para Windows Internet Explorer 7 (KB953838)

Atualização de Segurança para Windows Internet Explorer 7 (KB956390)

Atualização de Segurança para Windows Internet Explorer 7 (KB958215)

Atualização de Segurança para Windows Internet Explorer 7 (KB960714)

Atualização de Segurança para Windows Internet Explorer 7 (KB961260)

Atualização de Segurança para Windows XP (KB923689)

Atualização de Segurança para Windows XP (KB938464)

Atualização de Segurança para Windows XP (KB941569)

Atualização de Segurança para Windows XP (KB946648)

Atualização de Segurança para Windows XP (KB950760)

Atualização de Segurança para Windows XP (KB950762)

Atualização de Segurança para Windows XP (KB950974)

Atualização de Segurança para Windows XP (KB951066)

Atualização de Segurança para Windows XP (KB951376-v2)

Atualização de Segurança para Windows XP (KB951698)

Atualização de Segurança para Windows XP (KB951748)

Atualização de Segurança para Windows XP (KB952954)

Atualização de Segurança para Windows XP (KB953839)

Atualização de Segurança para Windows XP (KB954211)

Atualização de Segurança para Windows XP (KB954459)

Atualização de Segurança para Windows XP (KB954600)

Atualização de Segurança para Windows XP (KB955069)

Atualização de Segurança para Windows XP (KB956391)

Atualização de Segurança para Windows XP (KB956802)

Atualização de Segurança para Windows XP (KB956803)

Atualização de Segurança para Windows XP (KB956841)

Atualização de Segurança para Windows XP (KB957095)

Atualização de Segurança para Windows XP (KB957097)

Atualização de Segurança para Windows XP (KB958644)

Atualização de Segurança para Windows XP (KB958687)

Atualização de Segurança para Windows XP (KB958690)

Atualização de Segurança para Windows XP (KB960225)

Atualização de Segurança para Windows XP (KB960715)

Atualização para Windows XP (KB942763)

Atualização para Windows XP (KB951072-v2)

Atualização para Windows XP (KB951978)

Atualização para Windows XP (KB955839)

Atualização para Windows XP (KB967715)

avast! Antivirus

BitComet 1.09

BufferChm

Canon MP160

CCleaner (remove only)

Crystal Player Professional 1.98

Dealio Toolbar 3.4

DeviceManagementQFolder

Dic Michaelis - UOL

DVD Shrink 3.2

eMule

EVEREST Ultimate Edition v4.50

FLV Player 2.0, build 24

Free FLV Converter V 5.9.1

getPlus®

Google Toolbar for Internet Explorer

Google Updater

HijackThis 2.0.2

Hotfix for Windows Media Format 11 SDK (KB929399)

Hotfix para o Windows Media Player 11 (KB939683)

Hotfix para Windows XP (KB952287)

HP Imaging Device Functions 7.0

HP Photosmart and Deskjet 7.0 Software (ptb)

hph_software_req

J2SE Runtime Environment 5.0 Update 5

Japanese Fonts Support For Adobe Reader 8

Java 6 Update 11

Java 6 Update 5

Java 6 Update 7

K-Lite Mega Codec Pack 1.38

Macromedia Dreamweaver 8

Macromedia Extension Manager

Messenger Plus! Live

Microsoft Compression Client Pack 1.0 for Windows XP

Microsoft Internationalized Domain Names Mitigation APIs

Microsoft National Language Support Downlevel APIs

Microsoft Office Professional Edição 2003

Microsoft User-Mode Driver Framework Feature Pack 1.0

MP3 Player Utilities 3.68

Nero 7 Ultra Edition

OpenOffice.org Installer 1.0

PhotoFiltre

Platform

save2pc Light 3.22

Search Settings 1.2

Skype™ 4.0

Toolbox

USB PC Camera Plus

VeryPDF PDF2Word v3.0

VIA Gerenciador de dispositivo de plataforma

VIA Rhine-Family Fast Ethernet Adapter

WavePad Sound Editor

WebFldrs XP

Windows Genuine Advantage Notifications (KB905474)

Windows Genuine Advantage Validation Tool (KB892130)

Windows Internet Explorer 7

Windows Live installer

Windows Live Messenger

Windows Media Format 11 runtime

Windows Media Player 11

Windows XP Service Pack 3

WorldUnlock Codes Calculator

 

==== End Of File ===========================

 

OBS: no final dos scans apareceu uma mensagem falando que nao foi possivel achar o dds

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! P@TY

 

<@> Baixe: < DelDomains >

<@> Extraia o DelDomains.inf,no Desktop.

<@> Clique com o botão direito do mouse,e escolha Instalar.

<@> Aparentemente,parece que nada aconteceu,pois sua ação é imperceptível!

<><><><><><><><><><><>

<@> Copie estas informações,entre os XXXXXXX....,para o Bloco de Notas.

<@> Salve-as,no desktop,como: CFScript <-- Texto!

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

File::

c:\arquivos de programas\dealio\kb127\Dealio.dll

DDS::

DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab

Folder::

c:\arquivos de programas\dealio\kb127

c:\arquivos de programas\dealio

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

<@> Arraste o CFScript.txt,para o ícone do ComboFix.

<@> Arraste-o,até que surja uma solicitação para executar o ComboFix.exe.

<@> Terminando,poste: ComboFix.txt

<><><><><><><><><><><>

<@> Baixe: < Norman Malware Cleaner >

<@> Salve-o no desktop.

<@> Abra o arquivo e clique em Executar --> Accept.

<@> Clique em Add,para adicionar ou Remove,para remover unidades/setores à serem escaneados. ( C:\*.*,D:\*.*,E:\*.*,etc... )

<@> Clique em "Start scan" --> Aguarde!

<@> Terminando,poste o relatório,que estará no desktop. ( NFix_2009-xx-xx_yy-yy-yy.log ) <--

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 09-04-04.01 - Administrador 2009-04-05 17:44:19.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.447.192 [GMT -3:00]

Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe

Comandos utilizados :: c:\documents and settings\Administrador\Desktop\CFScript.txt

AV: avast! antivirus 4.8.1335 [VPS 090405-1] *On-access scanning disabled* (Updated)

* Criado um novo ponto de restauro

 

FILE ::

c:\arquivos de programas\dealio\kb127\Dealio.dll

.

 

(((((((((((((((( Arquivos/Ficheiros criados de 2009-03-05 to 2009-04-05 ))))))))))))))))))))))))))))

.

 

2009-04-04 15:40 . 2009-04-04 15:40 <DIR> d-------- c:\arquivos de programas\CCleaner

2009-03-29 18:34 . 2009-03-29 18:34 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Zylom

2009-03-29 16:01 . 2009-03-29 16:02 207,120 --a------ c:\arquivos de programas\GoogleToolbarInstaller_download_signed.exe

2009-03-29 15:04 . 2009-03-29 15:08 <DIR> d-------- C:\ToolBar SD

2009-03-28 13:44 . 2009-03-28 13:46 <DIR> d-------- c:\arquivos de programas\WorldUnlock Codes Calculator

2009-03-28 13:44 . 2009-03-28 13:44 170,393 --a------ c:\arquivos de programas\WorldUnlock-v44-Setup-Baixaki.exe

2009-03-22 21:12 . 2009-03-22 21:13 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SSScanAppDataDir

2009-03-22 21:12 . 2009-03-22 21:12 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Canon

2009-03-22 21:11 . 2009-03-22 21:11 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\MSScanAppDataDir

2009-03-19 15:12 . 2009-03-21 22:21 <DIR> d-------- C:\hijackthis

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-04-05 19:16 --------- d-----w c:\arquivos de programas\BitComet

2009-04-05 03:37 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Google Updater

2009-04-04 18:33 --------- d-----w c:\arquivos de programas\NCH Swift Sound

2009-04-01 20:32 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Skype

2009-03-29 19:30 --------- d-----w c:\arquivos de programas\Reganam

2009-03-29 19:26 --------- d-----w c:\arquivos de programas\Norton Security Scan

2009-03-29 19:03 --------- d-----w c:\arquivos de programas\Google

2009-03-17 12:24 --------- d-----w c:\arquivos de programas\Yahoo!

2009-03-16 16:15 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Skype

2009-03-16 16:15 --------- d-----r c:\arquivos de programas\Skype

2009-03-16 15:15 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\skypePM

2009-02-25 00:36 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Lavasoft

2009-02-25 00:36 --------- d-----w c:\arquivos de programas\Lavasoft

2009-02-24 23:28 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe

2009-02-24 23:24 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems

2009-02-24 23:24 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared

2009-02-24 23:14 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools Lite

2009-02-24 23:12 --------- d-----w c:\arquivos de programas\eMule

2009-02-24 23:06 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools Pro

2009-02-24 23:06 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools

2009-02-24 23:05 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DAEMON Tools Lite

2009-02-24 23:04 --------- d-----w c:\arquivos de programas\DAEMON Tools Lite

2009-02-24 22:55 717,296 ----a-w c:\windows\system32\drivers\sptd.sys

2009-02-23 22:31 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\FairStars Audio Converter

2009-02-23 19:58 5,517,160 ----a-w c:\arquivos de programas\bitcomet_setup.exe

2009-02-10 03:17 --------- d-----w c:\arquivos de programas\Messenger Plus! Live

2009-02-10 01:52 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DriverScanner

2009-02-10 01:52 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Uniblue

2009-02-10 01:42 --------- d-----w c:\arquivos de programas\Canon

2009-02-10 00:53 --------- d--h--w c:\documents and settings\All Users\Dados de aplicativos\CanonBJ

2009-02-10 00:51 --------- d--h--w c:\arquivos de programas\CanonBJ

2009-02-09 14:06 1,846,912 ----a-w c:\windows\system32\win32k.sys

2009-02-09 14:06 1,846,912 ------w c:\windows\system32\DllCache\win32k.sys

2009-01-16 23:16 3,594,752 ------w c:\windows\system32\DllCache\mshtml.dll

2008-12-18 20:57 6,121,482 ----a-w c:\arquivos de programas\Setup_FreeFlvConverter.exe

2008-10-03 05:46 3,518,422 ----a-w c:\arquivos de programas\flvplayer_setup.exe

2008-09-16 18:40 382,104 ----a-w c:\arquivos de programas\wpsetup.exe

2008-07-09 00:52 767 ----a-w c:\arquivos de programas\save2pc Light.lnk

2008-07-08 02:03 4,780,368 ----a-w c:\arquivos de programas\MsgPlusLive-460.exe

2008-07-08 01:55 2,403,344 ----a-w c:\arquivos de programas\WLinstaller.exe

2004-07-22 13:51 3,432,656 ----a-w c:\arquivos de programas\ManagedDX.CAB

2004-07-20 01:58 1,156,363 ----a-w c:\arquivos de programas\BDANT.cab

2004-07-20 01:53 976,020 ----a-w c:\arquivos de programas\BDAXP.cab

2004-07-09 17:17 13,265,040 ----a-w c:\arquivos de programas\dxnt.cab

2004-07-09 12:13 703,080 ----a-w c:\arquivos de programas\BDA.cab

2004-07-09 12:13 15,493,481 ----a-w c:\arquivos de programas\DirectX.cab

2004-07-09 07:08 472,576 ----a-w c:\arquivos de programas\dxsetup.exe

2004-07-09 07:08 2,242,560 ----a-w c:\arquivos de programas\dsetup32.dll

2004-07-09 06:03 62,976 ----a-w c:\arquivos de programas\DSETUP.dll

.

 

((((((((((((((((((((((((((((( SnapShot@2009-03-21_22.14.46,51 )))))))))))))))))))))))))))))))))))))))))

.

+ 2006-08-29 17:17:22 161,976 ----a-w c:\windows\Downloaded Program Files\zylomgamesplayer.dll

+ 2009-04-05 19:12:47 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_344.dat

.

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

"swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-01 68856]

"MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2008-10-06 5724184]

"BitComet"="c:\arquivos de programas\BitComet\BitComet.exe" [2009-01-20 2523960]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]

"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-07-07 262144]

"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600]

"Google Quick Search Box"="c:\arquivos de programas\Google\Quick Search Box\qsb.exe" [2009-03-29 68592]

"VTTimer"="VTTimer.exe" [2005-03-08 c:\windows\system32\VTTimer.exe]

"VTTrayp"="VTtrayp.exe" [2005-03-11 c:\windows\system32\VTTrayp.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"nlsf"="move" [X]

"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]

 

c:\documents and settings\Administrador\Menu Iniciar\Programas\Inicializar\

Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

"ForceClassicControlPanel"= 1 (0x1)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"vidc.DIV3"= DivXc32.dll

"vidc.DIV4"= DivXc32f.dll

"vidc.3iv2"= 3ivxVfWCodec.dll

"msacm.divxa32"= divxa32.acm

"VIDC.HFYU"= huffyuv.dll

"VIDC.i263"= i263_32.drv

"msacm.imc"= imc32.acm

"VIDC.VP31"= vp31vfw.dll

"msacm.avis"= ff_acm.acm

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"=

"c:\\Arquivos de programas\\Ares\\Ares.exe"=

"c:\\Arquivos de programas\\Messenger\\msmsgs.exe"=

"c:\\Arquivos de programas\\eMule\\emule.exe"=

"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"23189:TCP"= 23189:TCP:BitComet 23189 TCP

"23189:UDP"= 23189:UDP:BitComet 23189 UDP

 

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-01 114768]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-07-01 20560]

S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2005-09-19 77312]

S3 A0380VID;USB2.0 PC Camera;c:\windows\system32\DRIVERS\A0380Vid.sys --> c:\windows\system32\DRIVERS\A0380Vid.sys [?]

S3 getPlus® Helper;getPlus® Helper;c:\arquivos de programas\NOS\bin\getPlus_HelperSvc.exe [2008-07-02 31592]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1cff4ec0-488f-11dd-866e-001617ff2b8e}]

\Shell\Auto\command - E:\MicrosoftPowerPoint.exe

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe

.

Conteúdo da pasta 'Tarefas Agendadas'

 

2009-04-05 c:\windows\Tasks\Google Software Updater.job

- c:\arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-25 23:56]

.

- - - - ORFÃOS REMOVIDOS - - - -

 

BHO-{db9d7a78-a76c-4bf2-97c6-258925ee1542} - (no file)

 

 

.

------- Scan Suplementar -------

.

uStart Page = hxxp://www.google.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

mWindow Title =

uInternet Connection Wizard,ShellNext = hxxp://www.compartilhando.org/

IE: &B&aixar &com o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddLink.htm

IE: &B&aixar todos os vídeos com o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddVideo.htm

IE: &B&aixar tudo usando o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~1\OFFICE11\EXCEL.EXE/3000

TCP: {BA9D2031-23A5-4E75-9C48-45FF09206DE3} = 200.204.0.10 200.204.0.138

Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\arquivos de programas\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll

DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab

DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game05.zylom.com/activex/zylomgamesplayer.cab

DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab

.

 

**************************************************************************

 

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-04-05 17:49:32

Windows 5.1.2600 Service Pack 3 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

Tempo para conclusão: 2009-04-05 17:52:45

ComboFix-quarantined-files.txt 2009-04-05 20:52:21

ComboFix2.txt 2009-03-22 01:16:08

 

Pré-execução: 22 pasta(s) 51.445.383.168 bytes disponíveis

Pós execução: 21 pasta(s) 51,832,274,944 bytes disponíveis

 

184 --- E O F --- 2009-03-13 05:58:07

Compartilhar este post


Link para o post
Compartilhar em outros sites

o outro log que gerou tá muito grande, ta ultrapassando o limite daqui e não vai... como faço?!

Reiniciei o PC após isso e não iniciou normal, ta pedindo um cd de instalação... :upset:

Compartilhar este post


Link para o post
Compartilhar em outros sites
o outro log que gerou tá muito grande, ta ultrapassando o limite daqui e não vai... como faço?!

Reiniciei o PC após isso e não iniciou normal, ta pedindo um cd de instalação... :upset:

<><><><><><><><><><>

Opa! P@TY

 

<!> Se voçê possui o CD-ROM do Windows XP,atenda à solicitação e faça o reparo.

<!> Concluindo,poste o relatório do Norman.

<!> Como é muito grande,hospede-o no Badongo. <-- Link!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tá certo!

 

Postei em outro site... Mas tá aqui o link: NFix_2009-04-05_18-10-11.log

----------------------------------

Norman Malware Cleaner

Copyright © 1990 - 2009, Norman ASA. Built 2009/03/26 05:17:51

 

Norman Scanner Engine Version: 6.00.06

Nvcbin.def Version: 6.00.00, Date: 2009/03/26 05:17:51, Variants: 3045527

 

Scan started: 05/04/2009 18:10:11

 

Running pre-scan cleanup routine:

Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3

Logged on user: CASA-A3B2BA9D4A\Administrador

 

Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00000000

Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -> NoDrives = 0x00000000

Removed registry value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -> NoDrives = 0x00000000

Removed hosts entry: 0.0.0.0 gtcc1.acecounter.com

Removed hosts entry: 0.0.0.0 zedo.com

Removed hosts entry: 0.0.0.0 ads.zedo.com

Removed hosts entry: 0.0.0.0 c1.zedo.com

Removed hosts entry: 0.0.0.0 c2.zedo.com

Removed hosts entry: 0.0.0.0 c3.zedo.com

Removed hosts entry: 0.0.0.0 c4.zedo.com

Removed hosts entry: 0.0.0.0 c5.zedo.com

Removed hosts entry: 0.0.0.0 c6.zedo.com

Removed hosts entry: 0.0.0.0 c7.zedo.com

Removed hosts entry: 0.0.0.0 g.zedo.com

Removed hosts entry: 0.0.0.0 www.advnt02.com

Removed hosts entry: 0.0.0.0 advnt03.com

Removed hosts entry: 0.0.0.0 advnt04.com

Removed hosts entry: 0.0.0.0 advnt05.com

Removed hosts entry: 0.0.0.0 mediacharger.com

Removed hosts entry: 0.0.0.0 devfast.mediacharger.com

Removed hosts entry: 0.0.0.0 download.mediacharger.com

Removed hosts entry: 0.0.0.0 fast.mediacharger.com

Removed hosts entry: 0.0.0.0 www.pml.mediacharger.com

Removed hosts entry: 0.0.0.0 www.movienetworks.com

Removed hosts entry: 0.0.0.0 banners.asiafriendfinder.com

Removed hosts entry: 0.0.0.0 www.adultbrowser.com

Removed hosts entry: 0.0.0.0 adultlinksco.com

Removed hosts entry: 0.0.0.0 www.adultlinksco.com

Removed hosts entry: 0.0.0.0 www.adultpassfinder.com

Removed hosts entry: 0.0.0.0 dn.adzerver.com

Removed hosts entry: 0.0.0.0 temp.adzerver.com

Removed hosts entry: 0.0.0.0 ctc.amateurpages.com

Removed hosts entry: 0.0.0.0 angelsfucked.com

Removed hosts entry: 0.0.0.0 www.angelsfucked.com

Removed hosts entry: 0.0.0.0 ads.asexstories.com

Removed hosts entry: 0.0.0.0 clicks.asianamateurpages.com

-------------------------------------------

-------------------------------------------

Removed hosts entry: 0.0.0.0 stxbans.sextracker.com

Removed hosts entry: 0.0.0.0 webmasters.sextracker.com

Removed hosts entry: 0.0.0.0 stx.banners.sextracker.com

Removed hosts entry: 0.0.0.0 wm.banners.sextracker.com

Removed hosts entry: 0.0.0.0 streamate.com

Removed hosts entry: 0.0.0.0 broadcaster.streamate.com

Removed hosts entry: 0.0.0.0 static.gfx.streamate.com

Removed hosts entry: 0.0.0.0 www.streamate.com

Removed hosts entry: 0.0.0.0 amateur.xxxcounter.com

Removed hosts entry: 0.0.0.0 c1.xxxcounter.com

Removed hosts entry: 0.0.0.0 c2.xxxcounter.com

Removed hosts entry: 0.0.0.0 c3.xxxcounter.com

Removed hosts entry: 0.0.0.0 free.xxxcounter.com

Removed hosts entry: 0.0.0.0 grafix.xxxcounter.com

Removed hosts entry: 0.0.0.0 hardcore.xxxcounter.com

Removed hosts entry: 0.0.0.0 gay.xxxcounter.com

Removed hosts entry: 0.0.0.0 mature.xxxcounter.com

Removed hosts entry: 0.0.0.0 other.xxxcounter.com

Removed hosts entry: 0.0.0.0 rr1.xxxcounter.com

Removed hosts entry: 0.0.0.0 rr2.xxxcounter.com

Removed hosts entry: 0.0.0.0 rr3.xxxcounter.com

Removed hosts entry: 0.0.0.0 rr4.xxxcounter.com

Removed hosts entry: 0.0.0.0 rr5.xxxcounter.com

Removed hosts entry: 0.0.0.0 rr6.xxxcounter.com

Removed hosts entry: 0.0.0.0 rr7.xxxcounter.com

Removed hosts entry: 0.0.0.0 rr8.xxxcounter.com

Removed hosts entry: 0.0.0.0 rr9.xxxcounter.com

Removed hosts entry: 0.0.0.0 rr10.xxxcounter.com

Removed hosts entry: 0.0.0.0 start.xxxcounter.com

Removed hosts entry: 0.0.0.0 adultfriendfinder.com

Removed hosts entry: 0.0.0.0 adserver.adultfriendfinder.com

Removed hosts entry: 0.0.0.0 banners.adultfriendfinder.com

Removed hosts entry: 0.0.0.0 guest.adultfriendfinder.com

Removed hosts entry: 0.0.0.0 iframe.adultfriendfinder.com

Removed hosts entry: 0.0.0.0 www.adultfriendfinder.com

Removed hosts entry: 0.0.0.0 exit.xpays.com

Removed hosts entry: 0.0.0.0 www.xpays.com

Removed hosts entry: 0.0.0.0 our-counter.com

Removed hosts entry: 0.0.0.0 www.our-counter.com

Removed hosts entry: 0.0.0.0 couldnotfind.com

Removed hosts entry: 0.0.0.0 www.couldnotfind.com

Removed hosts entry: 0.0.0.0 stats.gammacash.com

Removed hosts entry: 0.0.0.0 www.gammacash.com

Removed hosts entry: 0.0.0.0 advertising.gammae.com

Removed hosts entry: 0.0.0.0 hourly.gammae.com

Removed hosts entry: 0.0.0.0 php.gammae.com

Removed hosts entry: 0.0.0.0 tracking.gammae.com

Removed hosts entry: 0.0.0.0 installcash.com

Removed hosts entry: 0.0.0.0 www.installcash.com

Removed hosts entry: 0.0.0.0 isearchtech.com

Removed hosts entry: 0.0.0.0 in.paycounter.com

Removed hosts entry: 0.0.0.0 stats.paycounter.com

Removed hosts entry: 0.0.0.0 www.paycounter.com

Removed hosts entry: 0.0.0.0 sort.trafficjuicer.com

Removed hosts entry: 0.0.0.0 stats.trafficjuicer.com

Removed hosts entry: 0.0.0.0 www.trafficjuicer.com

Removed hosts entry: 0.0.0.0 www.ladylust.com

Removed hosts entry: 0.0.0.0 www.nudecash.com

Removed hosts entry: 0.0.0.0 www.smut1000.com

Removed hosts entry: 0.0.0.0 www.18access.com

Removed hosts entry: 0.0.0.0 www.hentaidatabase.com

Removed hosts entry: 0.0.0.0 www.pussypool.net

Removed hosts entry: 0.0.0.0 support.sextronix.com

Removed hosts entry: 0.0.0.0 www.sextronix.com

Removed hosts entry: 0.0.0.0 www.teenygirlshome.com

Removed hosts entry: 0.0.0.0 www.myrealpics.com

Removed hosts entry: 0.0.0.0 www.picsdrive.com

Removed hosts entry: 0.0.0.0 www.picsplace.com

Removed hosts entry: 0.0.0.0 www.takebest.com

Removed hosts entry: 0.0.0.0 www.zonebest.com

Removed hosts entry: 0.0.0.0 www.euro-dialers.com

Removed hosts entry: 0.0.0.0 www.hit4hit.com

Removed hosts entry: 0.0.0.0 www.hitboss.com

Removed hosts entry: 0.0.0.0 www.popuptop.com

Removed hosts entry: 0.0.0.0 visitfind.net

Removed hosts entry: 0.0.0.0 www.visitfind.net

 

 

Scanning running processes and process memory...

 

Number of processes/threads found: 1984

Number of processes/threads scanned: 1984

Number of processes/threads not scanned: 0

Number of infected processes/threads terminated: 0

Total scanning time: 1m 33s

 

 

Scanning file system...

 

Scanning: C:\*.*

 

C:\System Volume Information\_restore{C45A67E8-71E2-4AFE-ACA3-7CB8DCED9421}\RP192\A0034148.exe (Infected with W32/Malware.WMQ)

Deleted file

 

C:\ToolBar SD\pv.exe (Infected with W32/Ircbot.ANFB)

Deleted file

 

Scanning: c:\System Volume Information\*.*

 

c:\System Volume Information\_restore{C45A67E8-71E2-4AFE-ACA3-7CB8DCED9421}\RP202\A0036438.exe (Infected with W32/Ircbot.ANFB)

Deleted file

 

 

Running post-scan cleanup routine:

 

Number of files found: 155678

Number of archives unpacked: 991

Number of files scanned: 155635

Number of files not scanned: 43

Number of files skipped due to exclude list: 0

Number of infected files found: 3

Number of infected files repaired/deleted: 3

Number of infections removed: 3

Total scanning time: 46m 29s

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! P@TY

 

<@> Baixe: < Flash Disinfector >

<@> Salve-o,diretamente,no Disco Local-C.

<@> Conecte,na entrada USB,suas unidades removíveis!

<@> Dê um duplo clique em: Flash_Disinfector.exe

<@> Espere a conclusão!

<><><><><><><><><><><><><><><>

<@> Atualize o Java.

<@> Versões antigas têm vulnerabilidades que,malwares,podem usar para infectar seu sistema.

<><><><><><><><><><><><><><><>

<@> Faça download da última versão do Java Runtime Environment (JRE) 6u13.

<@> Localize: "Java Runtime Environment (JRE) 6 Update 13"

<@> Clique no botão Download.

<@> Marque a opção que diz: "Accept License Agreement"

<@> A página será atualizada!

<@> Clique no link,para download do Windows Offline Installation --> Salve-o no desktop!

<@> Feche o IE ou Firefox + Programas que estejam sendo executados.

<@> Vá em Iniciar --> Painel de Controle.

<@> Em Adicionar ou Remover Programas;remova todas as antigas versões do Java.

<><><><><><><><><><><><><><><>

<@> Exemplos de antigas versões:

 

< javaicon.jpg > Java 2 Runtime Environment, SE v1.4.2

< javaicon.jpg > J2SE Runtime Environment 5.0

< javaicon.jpg > J2SE Runtime Environment 5.0 Update 6

 

<@> Selecione qualquer item com nome: Java Runtime Environment (JRE ou J2SE)

<@> Clique no botão Remover ou Alterar/Remover.

<@> Repita quantas vezes for necessária,para remover cada versão do Java.

<@> Concluindo,reinicie o computador!

<@> Instale a nova versão,com um duplo clique em jre-6u13-windows-i586-p.exe.

<><><><><><><><><><><><><><><>

<!> O log está limpo!

<!> Tudo Ok?

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

O Pc esta funcionando normalmente...

Mas desde o segundo scan do combofix, ta aparecendo uma mensagem quando ligo ele, ainda no DOS... é algo como:

 

esifling DMI pool data

oot from cd:

 

O que significa isso?!

 

 

E sim, farei o que passos que você solicitou! Muito obrigada mesmo!! :joia:

Compartilhar este post


Link para o post
Compartilhar em outros sites
O Pc esta funcionando normalmente...

Mas desde o segundo scan do combofix, ta aparecendo uma mensagem quando ligo ele, ainda no DOS... é algo como:

 

esifling DMI pool data

oot from cd:

 

O que significa isso?!

 

 

E sim, farei o que passos que você solicitou! Muito obrigada mesmo!! :joia:

<><><><><><><><><><>

Opa! P@TY

 

<!> Pode ser uma falha física,no HD. Tente,preliminarmente,uma correção de erros lógicos.

<><><><><><><><><><>

<@> Agende,para o próximo boot,o scandisk.

<@> No Executar,digite: cmd --> Clique: OK

<@> Na janela DOS,digite: chkdsk /f --> Aperte Enter.

<@> Aguarde!

<@> Nas informações,que surgirem,escolha o scandisk para o próximo boot.

<@> Para sair,digite exit --> Aperte Enter.

<@> Reinicie o computador,para que tenha início o scandisk.

<><><><><><><><><><>

<@> Terminando,vá em Iniciar --> Executar --> Digite: sfc /scannow --> Clique OK.

 

< 2.jpg >

 

<@> Será pedido a colocação do CD-ROM,do Windows XP,no drive.

<@> Aguarde a conclusão do reparo! --> Reinicie!

<@> Verifique se o erro permanece!

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Tópico Arquivado

 

Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado.

 

Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.