P@TY 0 Denunciar post Postado Março 19, 2009 Acho que meu pc tá com virus, o ieexplore.exe está sendo executado, roubando boa parte da memoria e deixando o pc lento... Gostaria que analisassem o log!!! Agradeço desde já! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:25:45, on 19/3/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\tsnpstd3.exe C:\WINDOWS\vsnpstd3.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\system32\VTtrayp.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Search Settings\SearchSettings.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\hijackthis\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.compartilhando.org/ R3 - URLSearchHook: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg1.dll R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Arquivos de programas\Search Settings\kb127\SearchSettings.dll O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.3.1.15.dll O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll O2 - BHO: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg1.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Arquivos de programas\Search Settings\kb127\SearchSettings.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg1.dll O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [au] C:\Arquivos de programas\Dealio\DealioAU.exe O4 - HKLM\..\Run: [searchSettings] C:\Arquivos de programas\Search Settings\SearchSettings.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [bitComet] "C:\Arquivos de programas\BitComet\BitComet.exe" /tray O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: &B&aixar &com o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: &B&aixar todos os vídeos com o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: &B&aixar tudo usando o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Administrador\Dados de aplicativos\Dealio\kb127\res\DealioSearch.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.3.1.15.dll/206 (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/ O15 - Trusted Zone: http://asia.msi.com.tw O15 - Trusted Zone: http://global.msi.com.tw O15 - Trusted Zone: http://www.msi.com.tw O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1215217802500 O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1...ows-i586-jc.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9D2031-23A5-4E75-9C48-45FF09206DE3}: NameServer = 200.204.0.10 200.204.0.138 O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Arquivos de programas\NOS\bin\getPlus_HelperSvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe -- End of file - 12579 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 20, 2009 Boa Tarde! P@TY <@> Baixe: < > ( ...by sUBs ) <@> Salve-o no desktop! <@> Desabilite as proteções residente de: antivírus,antispywares e firewall. ( Menos o do Windows! ) <@> Feche todas as janelas e execute a ferramenta! <@> Na solicitação: "Negação de garantia de software" --> Clique em Sim! <@> Não possuindo o "Console de Recuperação",aceite optar pela instalação do mesmo! <!> Caso aconteça a notificação de: Aplicativo Win32 inválido,delete a ferramenta e faça,novamente,o download.<!> Salve-a no desktop,renomeada como: Kombo.exe <!> Ps: Nomeie durante o salvamento,e não após salvá-la! <!> Ps: Surgindo alguma mensagem de erro,rode o ComboFix.exe em Modo de Segurança. <-- Link! <!> Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador. <-- Aguarde! <!> Ps: Evite executar,voluntariamente,esta ferramenta!Siga,àcima,todas as recomendações propostas. <!> Ps: O ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão profissional. <@> Abrir-se-á a janela Auto Scan. --> Aguarde! <@> Àfim de completar as remoções,o ComboFix poderá reiniciar o computador. <@> Se houver necessidade,digite a opção para continuar! --> ( 1 ) --> Aperte Enter! --> Aguarde a conclusão! <@> Durante o scan,evite manusear o mouse ou teclado! <-- Importante! <@> Para parar ou sair do ComboFix,tecle "N" ou "2" --> Aperte Enter! <><><><><><><><><><><><> <@> Terminando,poste os relatórios: C:\ComboFix\ComboFix.txt + HijackThis,atualizado. Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
P@TY 0 Denunciar post Postado Março 22, 2009 ComboFix 09-03-19.02 - Administrador 2009-03-21 22:07:54.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.447.204 [GMT -3:00] Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1335 [VPS 090321-0] *On-access scanning disabled* (Updated) * Criado um novo ponto de restauro . (((((((((((((((( Arquivos/Ficheiros criados de 2009-02-22 to 2009-03-22 )))))))))))))))))))))))))))) . 2009-03-19 15:12 . 2009-03-19 15:25 <DIR> d-------- C:\hijackthis 2009-02-26 23:29 . 2009-02-26 23:29 268 --ah----- C:\sqmdata01.sqm 2009-02-26 23:29 . 2009-02-26 23:29 244 --ah----- C:\sqmnoopt01.sqm 2009-02-26 01:34 . 2009-02-26 01:35 <DIR> d-------- C:\DVD 2009-02-24 21:36 . 2009-02-24 21:36 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Lavasoft 2009-02-24 21:36 . 2009-02-24 21:36 <DIR> d-------- c:\arquivos de programas\Lavasoft 2009-02-24 20:43 . 2009-02-24 20:43 <DIR> d-------- c:\documents and settings\Administrador\Configuraes locais 2009-02-24 20:24 . 2009-02-24 20:24 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems 2009-02-24 20:24 . 2009-02-24 20:24 <DIR> d-------- c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared 2009-02-24 20:06 . 2009-02-24 20:06 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools Pro 2009-02-24 20:06 . 2009-02-24 20:06 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools 2009-02-24 20:05 . 2009-02-24 20:05 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\DAEMON Tools Lite 2009-02-24 20:02 . 2009-02-24 21:07 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Toolbar 2009-02-24 20:01 . 2009-02-24 20:04 <DIR> d-------- c:\arquivos de programas\DAEMON Tools Lite 2009-02-24 19:55 . 2009-02-24 20:14 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools Lite 2009-02-24 19:55 . 2009-02-24 19:55 717,296 --a------ c:\windows\system32\drivers\sptd.sys 2009-02-23 18:58 . 2009-02-23 19:31 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\FairStars Audio Converter 2009-02-23 18:58 . 2009-02-23 18:58 <DIR> d-------- c:\arquivos de programas\FairStars Audio Converter 2009-02-23 17:01 . 2009-03-16 13:11 <DIR> d-------- C:\Downloads 2009-02-23 17:00 . 2009-03-21 12:52 <DIR> d-------- c:\arquivos de programas\BitComet . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-22 00:34 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Skype 2009-03-21 16:11 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Google Updater 2009-03-17 12:24 --------- d-----w c:\arquivos de programas\Yahoo! 2009-03-16 16:15 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Skype 2009-03-16 16:15 --------- d-----r c:\arquivos de programas\Skype 2009-03-16 15:15 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\skypePM 2009-03-15 21:00 --------- d-----w c:\arquivos de programas\Norton Security Scan 2009-03-08 21:03 --------- d-----w c:\arquivos de programas\Arquivos comuns\Symantec Shared 2009-02-24 23:28 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2009-02-24 23:12 --------- d-----w c:\arquivos de programas\eMule 2009-02-10 03:17 --------- d-----w c:\arquivos de programas\Messenger Plus! Live 2009-02-10 01:52 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DriverScanner 2009-02-10 01:52 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Uniblue 2009-02-10 00:53 --------- d--h--w c:\documents and settings\All Users\Dados de aplicativos\CanonBJ 2009-02-10 00:51 --------- d--h--w c:\arquivos de programas\CanonBJ 2009-02-09 14:06 1,846,912 ----a-w c:\windows\system32\win32k.sys 2009-02-09 14:06 1,846,912 ------w c:\windows\system32\DllCache\win32k.sys 2009-01-16 23:16 3,594,752 ------w c:\windows\system32\DllCache\mshtml.dll 2004-07-22 13:51 3,432,656 ----a-w c:\arquivos de programas\ManagedDX.CAB 2004-07-20 01:58 1,156,363 ----a-w c:\arquivos de programas\BDANT.cab 2004-07-20 01:53 976,020 ----a-w c:\arquivos de programas\BDAXP.cab 2004-07-09 17:17 13,265,040 ----a-w c:\arquivos de programas\dxnt.cab 2004-07-09 12:13 703,080 ----a-w c:\arquivos de programas\BDA.cab 2004-07-09 12:13 15,493,481 ----a-w c:\arquivos de programas\DirectX.cab 2004-07-09 07:08 472,576 ----a-w c:\arquivos de programas\dxsetup.exe 2004-07-09 07:08 2,242,560 ----a-w c:\arquivos de programas\dsetup32.dll 2004-07-09 06:03 62,976 ----a-w c:\arquivos de programas\DSETUP.dll . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{db9d7a78-a76c-4bf2-97c6-258925ee1542}"= "c:\arquivos de programas\Reganam\tbReg0.dll" [2009-03-20 1883672] [HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{db9d7a78-a76c-4bf2-97c6-258925ee1542}] 2009-03-20 23:06 1883672 --a------ c:\arquivos de programas\Reganam\tbReg0.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{db9d7a78-a76c-4bf2-97c6-258925ee1542}"= "c:\arquivos de programas\Reganam\tbReg0.dll" [2009-03-20 1883672] [HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{DB9D7A78-A76C-4BF2-97C6-258925EE1542}"= "c:\arquivos de programas\Reganam\tbReg0.dll" [2009-03-20 1883672] [HKEY_CLASSES_ROOT\clsid\{db9d7a78-a76c-4bf2-97c6-258925ee1542}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-01 68856] "MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2008-10-06 5724184] "BitComet"="c:\arquivos de programas\BitComet\BitComet.exe" [2009-01-20 2523960] "Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2009-03-06 24095528] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-07-07 262144] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600] "au"="c:\arquivos de programas\Dealio\DealioAU.exe" [2008-05-26 595296] "SearchSettings"="c:\arquivos de programas\Search Settings\SearchSettings.exe" [2008-06-12 991584] "VTTimer"="VTTimer.exe" [2005-03-08 c:\windows\system32\VTTimer.exe] "VTTrayp"="VTtrayp.exe" [2005-03-11 c:\windows\system32\VTTrayp.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nlsf"="move" [X] "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544] c:\documents and settings\Administrador\Menu Iniciar\Programas\Inicializar\ Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "ForceClassicControlPanel"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.DIV3"= DivXc32.dll "vidc.DIV4"= DivXc32f.dll "vidc.3iv2"= 3ivxVfWCodec.dll "msacm.divxa32"= divxa32.acm "VIDC.HFYU"= huffyuv.dll "VIDC.i263"= i263_32.drv "msacm.imc"= imc32.acm "VIDC.VP31"= vp31vfw.dll "msacm.avis"= ff_acm.acm [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "c:\\Arquivos de programas\\Ares\\Ares.exe"= "c:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "c:\\Arquivos de programas\\eMule\\emule.exe"= "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "23189:TCP"= 23189:TCP:BitComet 23189 TCP "23189:UDP"= 23189:UDP:BitComet 23189 UDP R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-01 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-07-01 20560] S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2005-09-19 77312] S3 A0380VID;USB2.0 PC Camera;c:\windows\system32\DRIVERS\A0380Vid.sys --> c:\windows\system32\DRIVERS\A0380Vid.sys [?] S3 getPlus® Helper;getPlus® Helper;c:\arquivos de programas\NOS\bin\getPlus_HelperSvc.exe [2008-07-02 31592] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1cff4ec0-488f-11dd-866e-001617ff2b8e}] \Shell\Auto\command - E:\MicrosoftPowerPoint.exe \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe . Conteúdo da pasta 'Tarefas Agendadas' 2009-03-15 c:\windows\Tasks\Norton Security Scan for Administrador.job - c:\arquivos de programas\Norton Security Scan\Nss.exe [2009-03-11 20:20] . - - - - ORFÃOS REMOVIDOS - - - - HKU-Default-Run-MsnMsgr - c:\arquivos de programas\MSN Messenger\MsnMsgr.Exe . ------- Scan Suplementar ------- . uStart Page = hxxp://www.daemon-search.com/startpage uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Connection Wizard,ShellNext = hxxp://www.compartilhando.org/ IE: &B&aixar &com o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddLink.htm IE: &B&aixar todos os vídeos com o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddVideo.htm IE: &B&aixar tudo usando o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm IE: Compare Prices with &Dealio - c:\documents and settings\Administrador\Dados de aplicativos\Dealio\kb127\res\DealioSearch.html IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 Trusted Zone: com.tw\asia.msi Trusted Zone: com.tw\global.msi Trusted Zone: com.tw\www.msi TCP: {BA9D2031-23A5-4E75-9C48-45FF09206DE3} = 200.204.0.10 200.204.0.138 DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-21 22:12:48 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . Tempo para conclusão: 2009-03-21 22:16:06 ComboFix-quarantined-files.txt 2009-03-22 01:15:54 Pré-execução: 21 pasta(s) 47.418.265.600 bytes disponíveis Pós execução: 21 pasta(s) 48,128,352,256 bytes disponíveis WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 184 --- E O F --- 2009-03-13 05:58:07 ---------------------- Hijackthis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:21:51, on 21/3/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\system32\VTtrayp.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\explorer.exe C:\hijackthis\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.compartilhando.org/ R3 - URLSearchHook: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg0.dll O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\Arquivos de programas\Scpad\scpsssh2.dll O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.3.1.15.dll O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Arquivos de programas\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll O2 - BHO: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg0.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Reganam Toolbar - {db9d7a78-a76c-4bf2-97c6-258925ee1542} - C:\Arquivos de programas\Reganam\tbReg0.dll O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [au] C:\Arquivos de programas\Dealio\DealioAU.exe O4 - HKLM\..\Run: [searchSettings] C:\Arquivos de programas\Search Settings\SearchSettings.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [bitComet] "C:\Arquivos de programas\BitComet\BitComet.exe" /tray O4 - HKCU\..\Run: [skype] "C:\Arquivos de programas\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: &B&aixar &com o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddLink.htm O8 - Extra context menu item: &B&aixar todos os vídeos com o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddVideo.htm O8 - Extra context menu item: &B&aixar tudo usando o BitComet - res://C:\Arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Administrador\Dados de aplicativos\Dealio\kb127\res\DealioSearch.html O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Arquivos de programas\BitComet\tools\BitCometBHO_1.3.1.15.dll/206 (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Arquivos de programas\Dealio\kb127\Dealio.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp O14 - IERESET.INF: START_PAGE_URL=http://www.compartilhando.org/ O15 - Trusted Zone: http://asia.msi.com.tw O15 - Trusted Zone: http://global.msi.com.tw O15 - Trusted Zone: http://www.msi.com.tw O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1215217802500 O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1...ows-i586-jc.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{BA9D2031-23A5-4E75-9C48-45FF09206DE3}: NameServer = 200.204.0.10 200.204.0.138 O21 - SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O22 - SharedTaskScheduler: scpLIB - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Arquivos de programas\Scpad\scpLIB.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Arquivos de programas\Ares\chatServer.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Arquivos de programas\NOS\bin\getPlus_HelperSvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe -- End of file - 11457 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 22, 2009 Bom Dia! P@TY <@> Baixe: < ToolBar S&D > <@> Salve-o no desktop! <@> Reinicie o computador,em Modo de Segurança. <-- Importante! <@> Execute o programa,e à seguir,aperte o "p" --> Enter --> Ok. <@> Digite o dois! ( 2 ) --> Aperte Enter --> Aguarde! <@> Terminando,poste o relatório. ( C:\ToolBar SD\TB_1.txt ) Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
P@TY 0 Denunciar post Postado Março 29, 2009 -----------\\ ToolBar S&D 1.2.8 XP/Vista Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3 X86-based PC ( Uniprocessor Free : Intel® Celeron® CPU 2.66GHz ) BIOS : Phoenix - AwardBIOS v6.00PG USER : Administrador ( Administrator ) BOOT : Fail-safe boot Antivirus : avast! antivirus 4.8.1335 [VPS 090328-0] 4.8.1335 (Activated) C:\ (Local Disk) - NTFS - Total:74 Go (Free:41 Go) D:\ (CD or DVD) - CDFS - Total:3 Go (Free:0 Go) E:\ (CD or DVD) "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 ) Option : [2] ( dom 29/03/2009|15:05 ) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsb1A.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nscB.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsd13.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsf11.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsfB.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsg13.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsg7E.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsi22.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsi6F.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsjB.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsk11.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsk18.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nskF.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nslB.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsm92.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsn10.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsp15.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nspB.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nspE.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsr19.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsrD.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nss12.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nst1D.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsv47.tmp(null) C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsvA.tmp(null) -----------\\ REMOVIDOS Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\Dealio\dinstallhelper.92681965C6DA4818A90872AA5A777D3D.dll Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\Dealio\kb127 Deletado! - C:\Arquivos de programas\Dealio\DealioAU.exe Deletado! - C:\Arquivos de programas\Dealio\kb127 Deletado! - C:\Arquivos de programas\Dealio\SearchSettingsKit.exe Deletado! - C:\DOCUME~1\ALLUSE~1\MENUIN~1\PROGRA~1\Dealio Deletado! - C:\Arquivos de programas\DAEMON Tools Toolbar\_DTLite.xml Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\Search Settings\kb127 Deletado! - C:\Arquivos de programas\Search Settings\kb127 Deletado! - C:\Arquivos de programas\Search Settings\SearchSettings.exe Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsb1A.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nscB.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsd13.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsf11.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsfB.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsg13.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsg7E.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsi22.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsi6F.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsjB.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsk11.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsk18.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nskF.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nslB.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsm92.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsn10.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsp15.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nspB.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nspE.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsr19.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsrD.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nss12.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nst1D.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsv47.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\nsvA.tmp(null) Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\Dealio Deletado! - C:\Arquivos de programas\Dealio Deletado! - C:\Arquivos de programas\DAEMON Tools Toolbar Deletado! - C:\DOCUME~1\ADMINI~1\DADOSD~1\Search Settings Deletado! - C:\Arquivos de programas\Search Settings -----------\\ Procura por Arquivos / Ficheiros ... -----------\\ [..\Internet Explorer\Main] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" "Start Page"="http://www.daemon-search.com/startpage" "Local Page"="C:\\WINDOWS\\system32\\blank.htm" "SearchMigratedDefaultURL"="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" "Url"="http://go.microsoft.com/fwlink/?LinkId=75724" "Url"="http://go.microsoft.com/fwlink/?LinkId=75723" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://www.msn.com/" --------------------\\ Procurando por outras infecções Não foram encontradas outras infecções. 1 - "C:\ToolBar SD\TB_1.txt" - dom 29/03/2009|15:08 - Option : [2] -----------\\ Verificação completa em 15:08:17,54 Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Março 30, 2009 Bom Dia! P@TY <@> Baixe: < DDS > ( ...by sUBs ) <@> Salve-o no desktop! <@> Desabilite seus programas de proteção: antivírus,antimalware,antispyware ou firewall. <@> Estando desconectado,execute a ferramenta! --> Duplo clique em dds.scr. <@> Aguarde o término do scan,até obtermos o relatório. ( DDS.txt ) <-- <@> Surgirá,também,uma nova janela: "D.D.S - Optional_Scan" --> Clique em Sim. <@> O Bloco de Notas irá abrir,com outro relatório. ( Attach.txt ) <-- <@> Ps: Caso o relatório seja incompreensível,renomeie o executável para DDS.exe e repita o scan. <@> Outra janela,finalmente,abrir-se-à! --> Clique em OK. <@> Salve os relatórios: DDS.txt + Attach.txt <-- Poste-os! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
P@TY 0 Denunciar post Postado Abril 4, 2009 DDS (Ver_09-03-16.01) - NTFSx86 Run by Administrador at 15:48:33,56 on sáb 04/04/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.55.1046.18.447.204 [GMT -3:00] AV: avast! antivirus 4.8.1335 [VPS 090404-0] *On-access scanning disabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Arquivos de programas\Java\jre6\bin\jqs.exe C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\tsnpstd3.exe C:\WINDOWS\vsnpstd3.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\system32\VTtrayp.exe C:\Arquivos de programas\Java\jre6\bin\jusched.exe C:\Arquivos de programas\Google\Quick Search Box\qsb.exe C:\WINDOWS\system32\ctfmon.exe C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Arquivos de programas\Windows Live\Messenger\usnsvc.exe C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Arquivos de programas\Ares\Ares.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Administrador\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mWindow Title = uInternet Connection Wizard,ShellNext = hxxp://www.compartilhando.org/ BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Facilitador de Leitor de Link Adobe PDF: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\arquivos de programas\arquivos comuns\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\arquivos de programas\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: ssh2 Class: {2e3c3651-b19c-4dd9-a979-901ec3e930af} - c:\arquivos de programas\scpad\scpsssh2.dll BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\arquivos de programas\bitcomet\tools\BitCometBHO_1.3.1.15.dll BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\arquivos de programas\java\jre6\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\arquivos de programas\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\arquivos de programas\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\arquivos de programas\google\google toolbar\component\fastsearch_9993303B90FE6C1D.dll BHO: {db9d7a78-a76c-4bf2-97c6-258925ee1542} - No File BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\arquivos de programas\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\arquivos de programas\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\arquivos de programas\google\google toolbar\GoogleToolbar.dll TB: Dealio: {e67c74f4-a00a-4f2c-9fec-fd9dc004a67f} - c:\arquivos de programas\dealio\kb127\Dealio.dll uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [swg] c:\arquivos de programas\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [MsnMsgr] "c:\arquivos de programas\windows live\messenger\MsnMsgr.Exe" /background uRun: [bitComet] "c:\arquivos de programas\bitcomet\BitComet.exe" /tray mRun: [avast!] c:\arquiv~1\alwils~1\avast4\ashDisp.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [Adobe Reader Speed Launcher] "c:\arquivos de programas\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [tsnpstd3] c:\windows\tsnpstd3.exe mRun: [snpstd3] c:\windows\vsnpstd3.exe mRun: [VTTimer] VTTimer.exe mRun: [VTTrayp] VTtrayp.exe mRun: [sunJavaUpdateSched] "c:\arquivos de programas\java\jre6\bin\jusched.exe" mRun: [Google Quick Search Box] "c:\arquivos de programas\google\quick search box\qsb.exe" /autorun dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe StartupFolder: c:\docume~1\admini~1\menuin~1\progra~1\inicia~1\adobeg~1.lnk - c:\arquivos de programas\arquivos comuns\adobe\calibration\Adobe Gamma Loader.exe mPolicies-explorer: ForceClassicControlPanel = 1 (0x1) IE: &B&aixar &com o BitComet - c:\arquivos de programas\bitcomet\BitComet.exe/AddLink.htm IE: &B&aixar todos os vídeos com o BitComet - c:\arquivos de programas\bitcomet\BitComet.exe/AddVideo.htm IE: &B&aixar tudo usando o BitComet - c:\arquivos de programas\bitcomet\BitComet.exe/AddAllLink.htm IE: E&xportar para o Microsoft Excel - c:\arquiv~1\micros~1\office11\EXCEL.EXE/3000 IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\arquivos de programas\bitcomet\tools\BitCometBHO_1.3.1.15.dll/206 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\arquivos de programas\messenger\msmsgs.exe IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\arquivos de programas\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\arquiv~1\micros~1\office11\REFIEBAR.DLL Trusted Zone: com.tw\asia.msi Trusted Zone: com.tw\global.msi Trusted Zone: com.tw\www.msi DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215217802500 DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?AuthParam=1228950478_5f63fcd06eb021484fd53032919ca405&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab&File=jinstall-6u11-windows-i586-jc.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game05.zylom.com/activex/zylomgamesplayer.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab TCP: {BA9D2031-23A5-4E75-9C48-45FF09206DE3} = 200.204.0.10 200.204.0.138 Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\arquivos de programas\google\google toolbar\component\fastsearch_9993303B90FE6C1D.dll SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - c:\arquivos de programas\scpad\scpLIB.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll STS: compIB Class: {a3717295-941d-416f-9384-ed1736729f1c} - c:\arquivos de programas\scpad\scpLIB.dll ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-7-1 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-7-1 20560] R2 avast! Antivirus;avast! Antivirus;c:\arquivos de programas\alwil software\avast4\ashServ.exe [2008-7-1 138680] S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2005-9-19 77312] S3 A0380VID;USB2.0 PC Camera;c:\windows\system32\drivers\a0380vid.sys --> c:\windows\system32\drivers\A0380Vid.sys [?] S3 avast! Mail Scanner;avast! Mail Scanner;c:\arquivos de programas\alwil software\avast4\ashMaiSv.exe [2008-7-1 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\arquivos de programas\alwil software\avast4\ashWebSv.exe [2008-7-1 352920] S3 getPlus® Helper;getPlus® Helper;c:\arquivos de programas\nos\bin\getPlus_HelperSvc.exe [2008-7-2 31592] =============== Created Last 30 ================ 2009-04-04 15:40 <DIR> --d----- c:\arquivos de programas\CCleaner 2009-03-29 18:34 <DIR> --d----- c:\docume~1\alluse~1\dadosd~1\Zylom 2009-03-29 16:01 207,120 a------- c:\arquivos de programas\GoogleToolbarInstaller_download_signed.exe 2009-03-29 15:04 <DIR> --d----- C:\ToolBar SD 2009-03-28 13:44 <DIR> --d----- c:\arquivos de programas\WorldUnlock Codes Calculator 2009-03-28 13:44 170,393 a------- c:\arquivos de programas\WorldUnlock-v44-Setup-Baixaki.exe 2009-03-22 21:12 <DIR> --d----- c:\docume~1\alluse~1\dadosd~1\SSScanAppDataDir 2009-03-22 21:11 <DIR> --d----- c:\docume~1\alluse~1\dadosd~1\MSScanAppDataDir 2009-03-21 22:03 <DIR> a-dshr-- C:\cmdcons 2009-03-21 21:46 161,792 a------- c:\windows\SWREG.exe 2009-03-21 21:46 98,816 a------- c:\windows\sed.exe 2009-03-19 15:12 <DIR> --d----- C:\hijackthis ==================== Find3M ==================== 2009-02-24 19:55 717,296 a------- c:\windows\system32\drivers\sptd.sys 2009-02-23 16:58 5,517,160 a------- c:\arquivos de programas\bitcomet_setup.exe 2009-02-15 11:23 338,240 a------- c:\windows\system32\perfh016.dat 2009-02-15 11:23 46,226 a------- c:\windows\system32\perfc016.dat 2009-02-09 11:06 1,846,912 a------- c:\windows\system32\win32k.sys 2009-02-09 11:06 1,846,912 -------- c:\windows\system32\dllcache\win32k.sys 2009-01-16 20:16 3,594,752 -------- c:\windows\system32\dllcache\mshtml.dll 2008-12-18 17:57 6,121,482 a------- c:\arquivos de programas\Setup_FreeFlvConverter.exe 2008-10-03 02:46 3,518,422 a------- c:\arquivos de programas\flvplayer_setup.exe 2008-09-16 15:40 382,104 a------- c:\arquivos de programas\wpsetup.exe 2008-07-08 21:52 767 a------- c:\arquivos de programas\save2pc Light.lnk 2008-07-07 23:03 4,780,368 a------- c:\arquivos de programas\MsgPlusLive-460.exe 2008-07-07 22:55 2,403,344 a------- c:\arquivos de programas\WLinstaller.exe 2004-07-22 10:51 3,432,656 a------- c:\arquivos de programas\ManagedDX.CAB 2004-07-19 22:58 1,156,363 a------- c:\arquivos de programas\BDANT.cab 2004-07-19 22:53 976,020 a------- c:\arquivos de programas\BDAXP.cab 2004-07-09 14:17 13,265,040 a------- c:\arquivos de programas\dxnt.cab 2004-07-09 09:13 15,493,481 a------- c:\arquivos de programas\DirectX.cab 2004-07-09 09:13 703,080 a------- c:\arquivos de programas\BDA.cab 2004-07-09 04:08 472,576 a------- c:\arquivos de programas\dxsetup.exe 2004-07-09 04:08 2,242,560 a------- c:\arquivos de programas\dsetup32.dll 2004-07-09 03:03 62,976 a------- c:\arquivos de programas\DSETUP.dll ============= FINISH: 15:49:15,59 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-03-16.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 1/7/2008 22:23:11 System Uptime: 4/4/2009 11:33:59 (4 hours ago) Motherboard: MICRO-STAR INTERNATIONAL CO., LTD | | MS-7211 Processor: Intel® Celeron® CPU 2.66GHz | Socket 775 | 2660/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 75 GiB total, 43,878 GiB free. D: is CDROM (CDFS) E: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Modem PCI Device ID: PCI\VEN_1057&DEV_3052&SUBSYS_30201057&REV_04\3&13C0B0C5&0&48 Manufacturer: Name: Modem PCI PNP Device ID: PCI\VEN_1057&DEV_3052&SUBSYS_30201057&REV_04\3&13C0B0C5&0&48 Service: ==== System Restore Points =================== RP154: 30/1/2009 02:20:53 - Software Distribution Service 3.0 RP155: 31/1/2009 13:14:23 - Ponto de verificação do sistema RP156: 1/2/2009 14:52:07 - Ponto de verificação do sistema RP157: 2/2/2009 22:11:27 - Ponto de verificação do sistema RP158: 3/2/2009 23:53:51 - Ponto de verificação do sistema RP159: 5/2/2009 12:57:32 - Ponto de verificação do sistema RP160: 6/2/2009 16:35:46 - Ponto de verificação do sistema RP161: 7/2/2009 22:29:59 - Ponto de verificação do sistema RP162: 9/2/2009 15:47:20 - Ponto de verificação do sistema RP163: 10/2/2009 16:22:32 - Ponto de verificação do sistema RP164: 11/2/2009 17:52:23 - Software Distribution Service 3.0 RP165: 13/2/2009 12:42:13 - Ponto de verificação do sistema RP166: 14/2/2009 21:30:31 - Ponto de verificação do sistema RP167: 15/2/2009 16:39:22 - RP168: 15/2/2009 16:40:11 - RP169: 15/2/2009 16:41:36 - RP170: 16/2/2009 21:16:30 - Ponto de verificação do sistema RP171: 17/2/2009 23:42:00 - Ponto de verificação do sistema RP172: 19/2/2009 15:03:54 - Ponto de verificação do sistema RP173: 21/2/2009 22:14:32 - Ponto de verificação do sistema RP174: 23/2/2009 11:46:43 - Ponto de verificação do sistema RP175: 24/2/2009 19:55:42 - SPTD setup V1.56 RP176: 24/2/2009 20:21:42 - Installed Adobe Photoshop CS2 RP177: 25/2/2009 22:52:25 - Software Distribution Service 3.0 RP178: 28/2/2009 11:40:33 - Ponto de verificação do sistema RP179: 1/3/2009 22:14:54 - Ponto de verificação do sistema RP180: 2/3/2009 22:34:49 - Ponto de verificação do sistema RP181: 4/3/2009 09:54:42 - Ponto de verificação do sistema RP182: 5/3/2009 17:20:40 - Ponto de verificação do sistema RP183: 10/3/2009 17:28:00 - Ponto de verificação do sistema RP184: 11/3/2009 18:10:42 - Software Distribution Service 3.0 RP185: 13/3/2009 02:56:10 - Software Distribution Service 3.0 RP186: 14/3/2009 16:09:04 - Ponto de verificação do sistema RP187: 15/3/2009 19:24:24 - Ponto de verificação do sistema RP188: 16/3/2009 19:37:13 - Ponto de verificação do sistema RP189: 18/3/2009 14:05:22 - Ponto de verificação do sistema RP190: 19/3/2009 16:18:44 - Ponto de verificação do sistema RP191: 20/3/2009 22:25:27 - Ponto de verificação do sistema RP192: 21/3/2009 21:46:36 - ComboFix created restore point RP193: 23/3/2009 13:01:30 - Ponto de verificação do sistema RP194: 24/3/2009 15:37:53 - Ponto de verificação do sistema RP195: 25/3/2009 17:53:15 - Ponto de verificação do sistema RP196: 26/3/2009 22:58:05 - Ponto de verificação do sistema RP197: 27/3/2009 23:11:17 - Ponto de verificação do sistema RP198: 30/3/2009 17:07:41 - Ponto de verificação do sistema RP199: 31/3/2009 22:07:46 - Ponto de verificação do sistema RP200: 2/4/2009 23:34:05 - Ponto de verificação do sistema RP201: 4/4/2009 13:59:04 - Ponto de verificação do sistema ==== Installed Programs ====================== Ad-Aware SE Personal Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player 10 ActiveX Adobe Help Center 1.0 Adobe Photoshop CS2 Adobe Reader 8.1.2 - Português Adobe Reader 8.1.2 Security Update 1 (KB403742) Adobe Shockwave Player Adobe Stock Photos 1.0 Ares 2.0.9 Arquivo do WinRAR Atualização Crítica para o Windows Media Player 11 (KB959772) Atualização de Segurança para o Windows Media Player (KB952069) Atualização de Segurança para o Windows Media Player 10 (KB936782) Atualização de Segurança para o Windows Media Player 11 (KB936782) Atualização de Segurança para o Windows Media Player 11 (KB954154) Atualização de Segurança para Windows Internet Explorer 7 (KB938127-v2) Atualização de Segurança para Windows Internet Explorer 7 (KB950759) Atualização de Segurança para Windows Internet Explorer 7 (KB953838) Atualização de Segurança para Windows Internet Explorer 7 (KB956390) Atualização de Segurança para Windows Internet Explorer 7 (KB958215) Atualização de Segurança para Windows Internet Explorer 7 (KB960714) Atualização de Segurança para Windows Internet Explorer 7 (KB961260) Atualização de Segurança para Windows XP (KB923689) Atualização de Segurança para Windows XP (KB938464) Atualização de Segurança para Windows XP (KB941569) Atualização de Segurança para Windows XP (KB946648) Atualização de Segurança para Windows XP (KB950760) Atualização de Segurança para Windows XP (KB950762) Atualização de Segurança para Windows XP (KB950974) Atualização de Segurança para Windows XP (KB951066) Atualização de Segurança para Windows XP (KB951376-v2) Atualização de Segurança para Windows XP (KB951698) Atualização de Segurança para Windows XP (KB951748) Atualização de Segurança para Windows XP (KB952954) Atualização de Segurança para Windows XP (KB953839) Atualização de Segurança para Windows XP (KB954211) Atualização de Segurança para Windows XP (KB954459) Atualização de Segurança para Windows XP (KB954600) Atualização de Segurança para Windows XP (KB955069) Atualização de Segurança para Windows XP (KB956391) Atualização de Segurança para Windows XP (KB956802) Atualização de Segurança para Windows XP (KB956803) Atualização de Segurança para Windows XP (KB956841) Atualização de Segurança para Windows XP (KB957095) Atualização de Segurança para Windows XP (KB957097) Atualização de Segurança para Windows XP (KB958644) Atualização de Segurança para Windows XP (KB958687) Atualização de Segurança para Windows XP (KB958690) Atualização de Segurança para Windows XP (KB960225) Atualização de Segurança para Windows XP (KB960715) Atualização para Windows XP (KB942763) Atualização para Windows XP (KB951072-v2) Atualização para Windows XP (KB951978) Atualização para Windows XP (KB955839) Atualização para Windows XP (KB967715) avast! Antivirus BitComet 1.09 BufferChm Canon MP160 CCleaner (remove only) Crystal Player Professional 1.98 Dealio Toolbar 3.4 DeviceManagementQFolder Dic Michaelis - UOL DVD Shrink 3.2 eMule EVEREST Ultimate Edition v4.50 FLV Player 2.0, build 24 Free FLV Converter V 5.9.1 getPlus® Google Toolbar for Internet Explorer Google Updater HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix para o Windows Media Player 11 (KB939683) Hotfix para Windows XP (KB952287) HP Imaging Device Functions 7.0 HP Photosmart and Deskjet 7.0 Software (ptb) hph_software_req J2SE Runtime Environment 5.0 Update 5 Japanese Fonts Support For Adobe Reader 8 Java 6 Update 11 Java 6 Update 5 Java 6 Update 7 K-Lite Mega Codec Pack 1.38 Macromedia Dreamweaver 8 Macromedia Extension Manager Messenger Plus! Live Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edição 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 MP3 Player Utilities 3.68 Nero 7 Ultra Edition OpenOffice.org Installer 1.0 PhotoFiltre Platform save2pc Light 3.22 Search Settings 1.2 Skype™ 4.0 Toolbox USB PC Camera Plus VeryPDF PDF2Word v3.0 VIA Gerenciador de dispositivo de plataforma VIA Rhine-Family Fast Ethernet Adapter WavePad Sound Editor WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Live installer Windows Live Messenger Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WorldUnlock Codes Calculator ==== End Of File =========================== OBS: no final dos scans apareceu uma mensagem falando que nao foi possivel achar o dds Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 4, 2009 Boa Tarde! P@TY <@> Baixe: < DelDomains > <@> Extraia o DelDomains.inf,no Desktop. <@> Clique com o botão direito do mouse,e escolha Instalar. <@> Aparentemente,parece que nada aconteceu,pois sua ação é imperceptível! <><><><><><><><><><><> <@> Copie estas informações,entre os XXXXXXX....,para o Bloco de Notas. <@> Salve-as,no desktop,como: CFScript <-- Texto! XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX File:: c:\arquivos de programas\dealio\kb127\Dealio.dll DDS:: DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab Folder:: c:\arquivos de programas\dealio\kb127 c:\arquivos de programas\dealio XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX <@> Arraste o CFScript.txt,para o ícone do ComboFix. <@> Arraste-o,até que surja uma solicitação para executar o ComboFix.exe. <@> Terminando,poste: ComboFix.txt <><><><><><><><><><><> <@> Baixe: < Norman Malware Cleaner > <@> Salve-o no desktop. <@> Abra o arquivo e clique em Executar --> Accept. <@> Clique em Add,para adicionar ou Remove,para remover unidades/setores à serem escaneados. ( C:\*.*,D:\*.*,E:\*.*,etc... ) <@> Clique em "Start scan" --> Aguarde! <@> Terminando,poste o relatório,que estará no desktop. ( NFix_2009-xx-xx_yy-yy-yy.log ) <-- Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
P@TY 0 Denunciar post Postado Abril 5, 2009 ComboFix 09-04-04.01 - Administrador 2009-04-05 17:44:19.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1046.18.447.192 [GMT -3:00] Executando de: c:\documents and settings\Administrador\Desktop\ComboFix.exe Comandos utilizados :: c:\documents and settings\Administrador\Desktop\CFScript.txt AV: avast! antivirus 4.8.1335 [VPS 090405-1] *On-access scanning disabled* (Updated) * Criado um novo ponto de restauro FILE :: c:\arquivos de programas\dealio\kb127\Dealio.dll . (((((((((((((((( Arquivos/Ficheiros criados de 2009-03-05 to 2009-04-05 )))))))))))))))))))))))))))) . 2009-04-04 15:40 . 2009-04-04 15:40 <DIR> d-------- c:\arquivos de programas\CCleaner 2009-03-29 18:34 . 2009-03-29 18:34 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\Zylom 2009-03-29 16:01 . 2009-03-29 16:02 207,120 --a------ c:\arquivos de programas\GoogleToolbarInstaller_download_signed.exe 2009-03-29 15:04 . 2009-03-29 15:08 <DIR> d-------- C:\ToolBar SD 2009-03-28 13:44 . 2009-03-28 13:46 <DIR> d-------- c:\arquivos de programas\WorldUnlock Codes Calculator 2009-03-28 13:44 . 2009-03-28 13:44 170,393 --a------ c:\arquivos de programas\WorldUnlock-v44-Setup-Baixaki.exe 2009-03-22 21:12 . 2009-03-22 21:13 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\SSScanAppDataDir 2009-03-22 21:12 . 2009-03-22 21:12 <DIR> d-------- c:\documents and settings\Administrador\Dados de aplicativos\Canon 2009-03-22 21:11 . 2009-03-22 21:11 <DIR> d-------- c:\documents and settings\All Users\Dados de aplicativos\MSScanAppDataDir 2009-03-19 15:12 . 2009-03-21 22:21 <DIR> d-------- C:\hijackthis . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-05 19:16 --------- d-----w c:\arquivos de programas\BitComet 2009-04-05 03:37 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Google Updater 2009-04-04 18:33 --------- d-----w c:\arquivos de programas\NCH Swift Sound 2009-04-01 20:32 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Skype 2009-03-29 19:30 --------- d-----w c:\arquivos de programas\Reganam 2009-03-29 19:26 --------- d-----w c:\arquivos de programas\Norton Security Scan 2009-03-29 19:03 --------- d-----w c:\arquivos de programas\Google 2009-03-17 12:24 --------- d-----w c:\arquivos de programas\Yahoo! 2009-03-16 16:15 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Skype 2009-03-16 16:15 --------- d-----r c:\arquivos de programas\Skype 2009-03-16 15:15 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\skypePM 2009-02-25 00:36 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Lavasoft 2009-02-25 00:36 --------- d-----w c:\arquivos de programas\Lavasoft 2009-02-24 23:28 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe 2009-02-24 23:24 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\Adobe Systems 2009-02-24 23:24 --------- d-----w c:\arquivos de programas\Arquivos comuns\Adobe Systems Shared 2009-02-24 23:14 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools Lite 2009-02-24 23:12 --------- d-----w c:\arquivos de programas\eMule 2009-02-24 23:06 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools Pro 2009-02-24 23:06 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\DAEMON Tools 2009-02-24 23:05 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DAEMON Tools Lite 2009-02-24 23:04 --------- d-----w c:\arquivos de programas\DAEMON Tools Lite 2009-02-24 22:55 717,296 ----a-w c:\windows\system32\drivers\sptd.sys 2009-02-23 22:31 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\FairStars Audio Converter 2009-02-23 19:58 5,517,160 ----a-w c:\arquivos de programas\bitcomet_setup.exe 2009-02-10 03:17 --------- d-----w c:\arquivos de programas\Messenger Plus! Live 2009-02-10 01:52 --------- d-----w c:\documents and settings\All Users\Dados de aplicativos\DriverScanner 2009-02-10 01:52 --------- d-----w c:\documents and settings\Administrador\Dados de aplicativos\Uniblue 2009-02-10 01:42 --------- d-----w c:\arquivos de programas\Canon 2009-02-10 00:53 --------- d--h--w c:\documents and settings\All Users\Dados de aplicativos\CanonBJ 2009-02-10 00:51 --------- d--h--w c:\arquivos de programas\CanonBJ 2009-02-09 14:06 1,846,912 ----a-w c:\windows\system32\win32k.sys 2009-02-09 14:06 1,846,912 ------w c:\windows\system32\DllCache\win32k.sys 2009-01-16 23:16 3,594,752 ------w c:\windows\system32\DllCache\mshtml.dll 2008-12-18 20:57 6,121,482 ----a-w c:\arquivos de programas\Setup_FreeFlvConverter.exe 2008-10-03 05:46 3,518,422 ----a-w c:\arquivos de programas\flvplayer_setup.exe 2008-09-16 18:40 382,104 ----a-w c:\arquivos de programas\wpsetup.exe 2008-07-09 00:52 767 ----a-w c:\arquivos de programas\save2pc Light.lnk 2008-07-08 02:03 4,780,368 ----a-w c:\arquivos de programas\MsgPlusLive-460.exe 2008-07-08 01:55 2,403,344 ----a-w c:\arquivos de programas\WLinstaller.exe 2004-07-22 13:51 3,432,656 ----a-w c:\arquivos de programas\ManagedDX.CAB 2004-07-20 01:58 1,156,363 ----a-w c:\arquivos de programas\BDANT.cab 2004-07-20 01:53 976,020 ----a-w c:\arquivos de programas\BDAXP.cab 2004-07-09 17:17 13,265,040 ----a-w c:\arquivos de programas\dxnt.cab 2004-07-09 12:13 703,080 ----a-w c:\arquivos de programas\BDA.cab 2004-07-09 12:13 15,493,481 ----a-w c:\arquivos de programas\DirectX.cab 2004-07-09 07:08 472,576 ----a-w c:\arquivos de programas\dxsetup.exe 2004-07-09 07:08 2,242,560 ----a-w c:\arquivos de programas\dsetup32.dll 2004-07-09 06:03 62,976 ----a-w c:\arquivos de programas\DSETUP.dll . ((((((((((((((((((((((((((((( SnapShot@2009-03-21_22.14.46,51 ))))))))))))))))))))))))))))))))))))))))) . + 2006-08-29 17:17:22 161,976 ----a-w c:\windows\Downloaded Program Files\zylomgamesplayer.dll + 2009-04-05 19:12:47 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_344.dat . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por defeito não são mostradas. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-01 68856] "MsnMsgr"="c:\arquivos de programas\Windows Live\Messenger\MsnMsgr.Exe" [2008-10-06 5724184] "BitComet"="c:\arquivos de programas\BitComet\BitComet.exe" [2009-01-20 2523960] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="c:\arquiv~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-07-07 262144] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776] "SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-11-10 136600] "Google Quick Search Box"="c:\arquivos de programas\Google\Quick Search Box\qsb.exe" [2009-03-29 68592] "VTTimer"="VTTimer.exe" [2005-03-08 c:\windows\system32\VTTimer.exe] "VTTrayp"="VTtrayp.exe" [2005-03-11 c:\windows\system32\VTTrayp.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nlsf"="move" [X] "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544] c:\documents and settings\Administrador\Menu Iniciar\Programas\Inicializar\ Adobe Gamma.lnk - c:\arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "ForceClassicControlPanel"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.DIV3"= DivXc32.dll "vidc.DIV4"= DivXc32f.dll "vidc.3iv2"= 3ivxVfWCodec.dll "msacm.divxa32"= divxa32.acm "VIDC.HFYU"= huffyuv.dll "VIDC.i263"= i263_32.drv "msacm.imc"= imc32.acm "VIDC.VP31"= vp31vfw.dll "msacm.avis"= ff_acm.acm [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Arquivos de programas\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Arquivos de programas\\Windows Live\\Messenger\\livecall.exe"= "c:\\Arquivos de programas\\Ares\\Ares.exe"= "c:\\Arquivos de programas\\Messenger\\msmsgs.exe"= "c:\\Arquivos de programas\\eMule\\emule.exe"= "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"= "c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "23189:TCP"= 23189:TCP:BitComet 23189 TCP "23189:UDP"= 23189:UDP:BitComet 23189 UDP R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-01 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-07-01 20560] S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2005-09-19 77312] S3 A0380VID;USB2.0 PC Camera;c:\windows\system32\DRIVERS\A0380Vid.sys --> c:\windows\system32\DRIVERS\A0380Vid.sys [?] S3 getPlus® Helper;getPlus® Helper;c:\arquivos de programas\NOS\bin\getPlus_HelperSvc.exe [2008-07-02 31592] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1cff4ec0-488f-11dd-866e-001617ff2b8e}] \Shell\Auto\command - E:\MicrosoftPowerPoint.exe \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe . Conteúdo da pasta 'Tarefas Agendadas' 2009-04-05 c:\windows\Tasks\Google Software Updater.job - c:\arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-25 23:56] . - - - - ORFÃOS REMOVIDOS - - - - BHO-{db9d7a78-a76c-4bf2-97c6-258925ee1542} - (no file) . ------- Scan Suplementar ------- . uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mWindow Title = uInternet Connection Wizard,ShellNext = hxxp://www.compartilhando.org/ IE: &B&aixar &com o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddLink.htm IE: &B&aixar todos os vídeos com o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddVideo.htm IE: &B&aixar tudo usando o BitComet - c:\arquivos de programas\BitComet\BitComet.exe/AddAllLink.htm IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 TCP: {BA9D2031-23A5-4E75-9C48-45FF09206DE3} = 200.204.0.10 200.204.0.138 Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\arquivos de programas\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game05.zylom.com/activex/zylomgamesplayer.cab DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab . ************************************************************************** catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-04-05 17:49:32 Windows 5.1.2600 Service Pack 3 NTFS Procurando processos ocultos ... Procurando entradas auto inicializáveis ocultas ... Procurando ficheiros/arquivos ocultos ... Varredura completada com sucesso arquivos/ficheiros ocultos: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•6~*] "6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL" . Tempo para conclusão: 2009-04-05 17:52:45 ComboFix-quarantined-files.txt 2009-04-05 20:52:21 ComboFix2.txt 2009-03-22 01:16:08 Pré-execução: 22 pasta(s) 51.445.383.168 bytes disponíveis Pós execução: 21 pasta(s) 51,832,274,944 bytes disponíveis 184 --- E O F --- 2009-03-13 05:58:07 Compartilhar este post Link para o post Compartilhar em outros sites
P@TY 0 Denunciar post Postado Abril 5, 2009 o outro log que gerou tá muito grande, ta ultrapassando o limite daqui e não vai... como faço?! Reiniciei o PC após isso e não iniciou normal, ta pedindo um cd de instalação... :upset: Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 6, 2009 o outro log que gerou tá muito grande, ta ultrapassando o limite daqui e não vai... como faço?!Reiniciei o PC após isso e não iniciou normal, ta pedindo um cd de instalação... :upset: <><><><><><><><><><> Opa! P@TY <!> Se voçê possui o CD-ROM do Windows XP,atenda à solicitação e faça o reparo. <!> Concluindo,poste o relatório do Norman. <!> Como é muito grande,hospede-o no Badongo. <-- Link! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
P@TY 0 Denunciar post Postado Abril 6, 2009 Tá certo! Postei em outro site... Mas tá aqui o link: NFix_2009-04-05_18-10-11.log ---------------------------------- Norman Malware Cleaner Copyright © 1990 - 2009, Norman ASA. Built 2009/03/26 05:17:51 Norman Scanner Engine Version: 6.00.06 Nvcbin.def Version: 6.00.00, Date: 2009/03/26 05:17:51, Variants: 3045527 Scan started: 05/04/2009 18:10:11 Running pre-scan cleanup routine: Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3 Logged on user: CASA-A3B2BA9D4A\Administrador Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00000000 Removed registry value: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -> NoDrives = 0x00000000 Removed registry value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer -> NoDrives = 0x00000000 Removed hosts entry: 0.0.0.0 gtcc1.acecounter.com Removed hosts entry: 0.0.0.0 zedo.com Removed hosts entry: 0.0.0.0 ads.zedo.com Removed hosts entry: 0.0.0.0 c1.zedo.com Removed hosts entry: 0.0.0.0 c2.zedo.com Removed hosts entry: 0.0.0.0 c3.zedo.com Removed hosts entry: 0.0.0.0 c4.zedo.com Removed hosts entry: 0.0.0.0 c5.zedo.com Removed hosts entry: 0.0.0.0 c6.zedo.com Removed hosts entry: 0.0.0.0 c7.zedo.com Removed hosts entry: 0.0.0.0 g.zedo.com Removed hosts entry: 0.0.0.0 www.advnt02.com Removed hosts entry: 0.0.0.0 advnt03.com Removed hosts entry: 0.0.0.0 advnt04.com Removed hosts entry: 0.0.0.0 advnt05.com Removed hosts entry: 0.0.0.0 mediacharger.com Removed hosts entry: 0.0.0.0 devfast.mediacharger.com Removed hosts entry: 0.0.0.0 download.mediacharger.com Removed hosts entry: 0.0.0.0 fast.mediacharger.com Removed hosts entry: 0.0.0.0 www.pml.mediacharger.com Removed hosts entry: 0.0.0.0 www.movienetworks.com Removed hosts entry: 0.0.0.0 banners.asiafriendfinder.com Removed hosts entry: 0.0.0.0 www.adultbrowser.com Removed hosts entry: 0.0.0.0 adultlinksco.com Removed hosts entry: 0.0.0.0 www.adultlinksco.com Removed hosts entry: 0.0.0.0 www.adultpassfinder.com Removed hosts entry: 0.0.0.0 dn.adzerver.com Removed hosts entry: 0.0.0.0 temp.adzerver.com Removed hosts entry: 0.0.0.0 ctc.amateurpages.com Removed hosts entry: 0.0.0.0 angelsfucked.com Removed hosts entry: 0.0.0.0 www.angelsfucked.com Removed hosts entry: 0.0.0.0 ads.asexstories.com Removed hosts entry: 0.0.0.0 clicks.asianamateurpages.com ------------------------------------------- ------------------------------------------- Removed hosts entry: 0.0.0.0 stxbans.sextracker.com Removed hosts entry: 0.0.0.0 webmasters.sextracker.com Removed hosts entry: 0.0.0.0 stx.banners.sextracker.com Removed hosts entry: 0.0.0.0 wm.banners.sextracker.com Removed hosts entry: 0.0.0.0 streamate.com Removed hosts entry: 0.0.0.0 broadcaster.streamate.com Removed hosts entry: 0.0.0.0 static.gfx.streamate.com Removed hosts entry: 0.0.0.0 www.streamate.com Removed hosts entry: 0.0.0.0 amateur.xxxcounter.com Removed hosts entry: 0.0.0.0 c1.xxxcounter.com Removed hosts entry: 0.0.0.0 c2.xxxcounter.com Removed hosts entry: 0.0.0.0 c3.xxxcounter.com Removed hosts entry: 0.0.0.0 free.xxxcounter.com Removed hosts entry: 0.0.0.0 grafix.xxxcounter.com Removed hosts entry: 0.0.0.0 hardcore.xxxcounter.com Removed hosts entry: 0.0.0.0 gay.xxxcounter.com Removed hosts entry: 0.0.0.0 mature.xxxcounter.com Removed hosts entry: 0.0.0.0 other.xxxcounter.com Removed hosts entry: 0.0.0.0 rr1.xxxcounter.com Removed hosts entry: 0.0.0.0 rr2.xxxcounter.com Removed hosts entry: 0.0.0.0 rr3.xxxcounter.com Removed hosts entry: 0.0.0.0 rr4.xxxcounter.com Removed hosts entry: 0.0.0.0 rr5.xxxcounter.com Removed hosts entry: 0.0.0.0 rr6.xxxcounter.com Removed hosts entry: 0.0.0.0 rr7.xxxcounter.com Removed hosts entry: 0.0.0.0 rr8.xxxcounter.com Removed hosts entry: 0.0.0.0 rr9.xxxcounter.com Removed hosts entry: 0.0.0.0 rr10.xxxcounter.com Removed hosts entry: 0.0.0.0 start.xxxcounter.com Removed hosts entry: 0.0.0.0 adultfriendfinder.com Removed hosts entry: 0.0.0.0 adserver.adultfriendfinder.com Removed hosts entry: 0.0.0.0 banners.adultfriendfinder.com Removed hosts entry: 0.0.0.0 guest.adultfriendfinder.com Removed hosts entry: 0.0.0.0 iframe.adultfriendfinder.com Removed hosts entry: 0.0.0.0 www.adultfriendfinder.com Removed hosts entry: 0.0.0.0 exit.xpays.com Removed hosts entry: 0.0.0.0 www.xpays.com Removed hosts entry: 0.0.0.0 our-counter.com Removed hosts entry: 0.0.0.0 www.our-counter.com Removed hosts entry: 0.0.0.0 couldnotfind.com Removed hosts entry: 0.0.0.0 www.couldnotfind.com Removed hosts entry: 0.0.0.0 stats.gammacash.com Removed hosts entry: 0.0.0.0 www.gammacash.com Removed hosts entry: 0.0.0.0 advertising.gammae.com Removed hosts entry: 0.0.0.0 hourly.gammae.com Removed hosts entry: 0.0.0.0 php.gammae.com Removed hosts entry: 0.0.0.0 tracking.gammae.com Removed hosts entry: 0.0.0.0 installcash.com Removed hosts entry: 0.0.0.0 www.installcash.com Removed hosts entry: 0.0.0.0 isearchtech.com Removed hosts entry: 0.0.0.0 in.paycounter.com Removed hosts entry: 0.0.0.0 stats.paycounter.com Removed hosts entry: 0.0.0.0 www.paycounter.com Removed hosts entry: 0.0.0.0 sort.trafficjuicer.com Removed hosts entry: 0.0.0.0 stats.trafficjuicer.com Removed hosts entry: 0.0.0.0 www.trafficjuicer.com Removed hosts entry: 0.0.0.0 www.ladylust.com Removed hosts entry: 0.0.0.0 www.nudecash.com Removed hosts entry: 0.0.0.0 www.smut1000.com Removed hosts entry: 0.0.0.0 www.18access.com Removed hosts entry: 0.0.0.0 www.hentaidatabase.com Removed hosts entry: 0.0.0.0 www.pussypool.net Removed hosts entry: 0.0.0.0 support.sextronix.com Removed hosts entry: 0.0.0.0 www.sextronix.com Removed hosts entry: 0.0.0.0 www.teenygirlshome.com Removed hosts entry: 0.0.0.0 www.myrealpics.com Removed hosts entry: 0.0.0.0 www.picsdrive.com Removed hosts entry: 0.0.0.0 www.picsplace.com Removed hosts entry: 0.0.0.0 www.takebest.com Removed hosts entry: 0.0.0.0 www.zonebest.com Removed hosts entry: 0.0.0.0 www.euro-dialers.com Removed hosts entry: 0.0.0.0 www.hit4hit.com Removed hosts entry: 0.0.0.0 www.hitboss.com Removed hosts entry: 0.0.0.0 www.popuptop.com Removed hosts entry: 0.0.0.0 visitfind.net Removed hosts entry: 0.0.0.0 www.visitfind.net Scanning running processes and process memory... Number of processes/threads found: 1984 Number of processes/threads scanned: 1984 Number of processes/threads not scanned: 0 Number of infected processes/threads terminated: 0 Total scanning time: 1m 33s Scanning file system... Scanning: C:\*.* C:\System Volume Information\_restore{C45A67E8-71E2-4AFE-ACA3-7CB8DCED9421}\RP192\A0034148.exe (Infected with W32/Malware.WMQ) Deleted file C:\ToolBar SD\pv.exe (Infected with W32/Ircbot.ANFB) Deleted file Scanning: c:\System Volume Information\*.* c:\System Volume Information\_restore{C45A67E8-71E2-4AFE-ACA3-7CB8DCED9421}\RP202\A0036438.exe (Infected with W32/Ircbot.ANFB) Deleted file Running post-scan cleanup routine: Number of files found: 155678 Number of archives unpacked: 991 Number of files scanned: 155635 Number of files not scanned: 43 Number of files skipped due to exclude list: 0 Number of infected files found: 3 Number of infected files repaired/deleted: 3 Number of infections removed: 3 Total scanning time: 46m 29s Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 6, 2009 Boa Noite! P@TY <@> Baixe: < Flash Disinfector > <@> Salve-o,diretamente,no Disco Local-C. <@> Conecte,na entrada USB,suas unidades removíveis! <@> Dê um duplo clique em: Flash_Disinfector.exe <@> Espere a conclusão! <><><><><><><><><><><><><><><> <@> Atualize o Java. <@> Versões antigas têm vulnerabilidades que,malwares,podem usar para infectar seu sistema. <><><><><><><><><><><><><><><> <@> Faça download da última versão do Java Runtime Environment (JRE) 6u13. <@> Localize: "Java Runtime Environment (JRE) 6 Update 13" <@> Clique no botão Download. <@> Marque a opção que diz: "Accept License Agreement" <@> A página será atualizada! <@> Clique no link,para download do Windows Offline Installation --> Salve-o no desktop! <@> Feche o IE ou Firefox + Programas que estejam sendo executados. <@> Vá em Iniciar --> Painel de Controle. <@> Em Adicionar ou Remover Programas;remova todas as antigas versões do Java. <><><><><><><><><><><><><><><> <@> Exemplos de antigas versões: < > Java 2 Runtime Environment, SE v1.4.2 < > J2SE Runtime Environment 5.0 < > J2SE Runtime Environment 5.0 Update 6 <@> Selecione qualquer item com nome: Java Runtime Environment (JRE ou J2SE) <@> Clique no botão Remover ou Alterar/Remover. <@> Repita quantas vezes for necessária,para remover cada versão do Java. <@> Concluindo,reinicie o computador! <@> Instale a nova versão,com um duplo clique em jre-6u13-windows-i586-p.exe. <><><><><><><><><><><><><><><> <!> O log está limpo! <!> Tudo Ok? Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
P@TY 0 Denunciar post Postado Abril 9, 2009 O Pc esta funcionando normalmente... Mas desde o segundo scan do combofix, ta aparecendo uma mensagem quando ligo ele, ainda no DOS... é algo como: esifling DMI pool data oot from cd: O que significa isso?! E sim, farei o que passos que você solicitou! Muito obrigada mesmo!! :joia: Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Abril 9, 2009 O Pc esta funcionando normalmente... Mas desde o segundo scan do combofix, ta aparecendo uma mensagem quando ligo ele, ainda no DOS... é algo como: esifling DMI pool data oot from cd: O que significa isso?! E sim, farei o que passos que você solicitou! Muito obrigada mesmo!! :joia: <><><><><><><><><><> Opa! P@TY <!> Pode ser uma falha física,no HD. Tente,preliminarmente,uma correção de erros lógicos. <><><><><><><><><><> <@> Agende,para o próximo boot,o scandisk. <@> No Executar,digite: cmd --> Clique: OK <@> Na janela DOS,digite: chkdsk /f --> Aperte Enter. <@> Aguarde! <@> Nas informações,que surgirem,escolha o scandisk para o próximo boot. <@> Para sair,digite exit --> Aperte Enter. <@> Reinicie o computador,para que tenha início o scandisk. <><><><><><><><><><> <@> Terminando,vá em Iniciar --> Executar --> Digite: sfc /scannow --> Clique OK. < > <@> Será pedido a colocação do CD-ROM,do Windows XP,no drive. <@> Aguarde a conclusão do reparo! --> Reinicie! <@> Verifique se o erro permanece! Abraços! Compartilhar este post Link para o post Compartilhar em outros sites
Mário Monteiro 179 Denunciar post Postado Maio 9, 2009 Tópico Arquivado Como o autor não respondeu por mais de 30 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura. Compartilhar este post Link para o post Compartilhar em outros sites