Ir para conteúdo

POWERED BY:

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

Bechir Bitar

[Resolvido!] Navegadores dando erro e travando

Recommended Posts

DigRam Boa tarde !!!

 

Camarada passei um aperto doido quando rodei o usbfix porque a maquina travou e tive que dar um boot pra ela voltar só que não entrava nada... Mais no final deu tudo certo.

 

Segue log´s

 

All processes killed

========== FILES ==========

C:\khw moved successfully.

C:\WINDOWS\System32\autorun.i moved successfully.

C:\WINDOWS\System32\autorun.in moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.

========== REGISTRY ==========

Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\lgqig not found.

========== OTL ==========

Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully.

C:\WINDOWS\002627_.tmp deleted successfully.

C:\WINDOWS\SET3.tmp deleted successfully.

C:\WINDOWS\SET4.tmp deleted successfully.

C:\WINDOWS\SET8.tmp deleted successfully.

C:\WINDOWS\System32\CONFIG.TMP deleted successfully.

ADS C:\Documents and Settings\All Users\Dados de aplicativos\TEMP:A9662AE0 deleted successfully.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: Administrador

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

->Flash cache emptied: 41 bytes

 

User: All Users

 

User: B&J Cyber

->Temp folder emptied: 508313 bytes

->Temporary Internet Files folder emptied: 16755474 bytes

->Java cache emptied: 12636675 bytes

->FireFox cache emptied: 43108156 bytes

->Flash cache emptied: 1513 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

->Flash cache emptied: 41 bytes

 

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 32902 bytes

 

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 16127 bytes

RecycleBin emptied: 1902 bytes

 

Total Files Cleaned = 70,00 mb

 

 

OTL by OldTimer - Version 3.1.37.3 log created on 03232010_144422

 

Files\Folders moved on Reboot...

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\NV4IH1DF\01[1].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\NV4IH1DF\ads[10].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\NV4IH1DF\BuddyList[1].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\NV4IH1DF\default[1].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\NV4IH1DF\InboxLight[1].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\NV4IH1DF\SmartAd[1].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\NV4IH1DF\ToastFull[1].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\NV4IH1DF\ToastMini[1].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\J9NGKWFU\ads[3].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\J9NGKWFU\myML[1].txt moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\E1GI5JB5\barra[1].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\E1GI5JB5\index[2].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\DY65D8P1\im[1].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.

 

Registry entries deleted on Reboot...

 

 

 

############################## | UsbFix V6.100 |

 

User : B&J Cyber (Administradores) # SERVIDOR400

Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8

Start at: 15:54:35 | 23/03/2010

Website : http://pagesperso-orange.fr/NosTools/index.html

Contact : FindyKill.Contact@gmail.com

 

AMD Sempron Processor 2800+

Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3

Internet Explorer 8.0.6001.18702

Windows Firewall Status : Enabled

AV : AntiVir Desktop 9.0.1.30 [ Enabled | Updated ]

 

C:\ -> Disco fixo local # 20,02 Go (6,17 Go free) [Clonador_C] # NTFS

D:\ -> Disco fixo local # 17,27 Go (8,05 Go free) [CLONADOR_D] # FAT32

E:\ -> Disco removível # 982,05 Mo (19,55 Mo free) [bECHIR JR] # FAT32

Z:\ -> Conexão de rede

 

################## | Ficheiros # pastas infeciosos |

 

Supprimido ! C:\Recycler\S-1-5-21-1547161642-789336058-725345543-1003

Supprimido ! D:\khw

Supprimido ! E:\autorun.inf

Supprimido ! E:\cold\hott\Desktop.ini

Supprimido ! E:\cold\hott

Supprimido ! E:\cold

Supprimido ! E:\kapeg.scr

Supprimido ! E:\kapeg.exe

Supprimido ! E:\Documents.lnk

Supprimido ! E:\Music.lnk

Supprimido ! E:\New Folder.lnk

Supprimido ! E:\Passwords.lnk

Supprimido ! E:\Pictures.lnk

Supprimido ! E:\Video.lnk

 

################## | Registro |

 

Supprimido ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

Supprimido ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

Supprimido ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoResolveSearch"

 

################## | Mountpoints2 |

 

 

################## | Listing |

 

[04/01/2008 01:11|--a------|0] C:\AUTOEXEC.BAT

[08/03/2010 17:57|--a------|211] C:\Boot.bak

[19/03/2010 22:33|-rahs----|281] C:\boot.ini

[28/10/2001 15:06|-rahs----|4952] C:\Bootfont.bin

[03/08/2004 23:00|--a------|261856] C:\cmldr

[22/03/2010 22:05|--a------|35878] C:\ComboFix.txt

[04/01/2008 01:11|--a------|0] C:\CONFIG.SYS

[04/01/2008 01:11|-rahs----|0] C:\IO.SYS

[26/02/2010 13:46|--a------|135] C:\mbam-error.txt

[04/01/2008 01:11|-rahs----|0] C:\MSDOS.SYS

[03/08/2004 23:38|-rahs----|47564] C:\NTDETECT.COM

[10/08/2008 13:01|-rahs----|251696] C:\ntldr

[?|?|?] C:\pagefile.sys

[23/03/2010 15:43|--a------|13030] C:\PDOXUSRS.NET

[22/03/2010 08:12|--a------|288654] C:\SafeBootKeyRepair.exe

[23/03/2010 15:57|--a------|2400] C:\UsbFix.txt

[22/06/2009 12:45|--a------|27262976] C:\VIRTPART.DAT

[22/03/2010 21:47|--a------|1131520] D:\Controle De Entrada.xls

[26/02/2010 18:26|--a------|71680] D:\Roda d.doc

[08/07/2009 14:29|--a------|31232] D:\Jogadas.doc

[13/02/2010 18:30|--a------|25088] D:\Lar ‚ o espa‡o privado e pode ser entendido como um local sagrado.doc

[26/02/2010 15:02|--a------|7866] D:\mbam-log-2010-02-26 (15-02-27).txt

[06/01/2010 12:37|--a------|247298] D:\Capitulo_10_10.pdf

[04/10/2009 19:12|--a------|23192064] D:\Trabalho Karine.doc

[05/09/2009 17:44|---hs----|2193] D:\AlbumArtSmall.jpg

[05/09/2009 17:44|---hs----|9028] D:\Folder.jpg

[05/09/2009 17:44|---hs----|9028] D:\AlbumArt_{ED215DC1-657D-4724-AD87-A5499957EF06}_Large.jpg

[05/09/2009 17:44|---hs----|2193] D:\AlbumArt_{ED215DC1-657D-4724-AD87-A5499957EF06}_Small.jpg

[19/07/2009 20:14|--ahs----|107520] D:\Thumbs.db

[20/10/2009 13:07|--a------|1258] E:\Melhoria do Sistema Operacional.txt

[02/12/2009 22:43|--a------|1035264] E:\Controle De Entrada.xls

[22/03/2010 21:04|--a------|204800] E:\segunda.doc

[01/12/2009 17:17|--a------|893440] E:\tela cyber.doc

[22/03/2010 20:13|--a------|87918] E:\index.php.htm

[27/11/2009 14:34|--a------|112640] E:\Artigo muito bom sobre socket.doc

[22/03/2010 18:53|--a------|11260] E:\hijackthis.log

[11/01/2010 19:22|--a------|11237] E:\Truques e Dicas para Windows XP.txt

[12/03/2010 22:20|--a------|1615] E:\musicascelular.txt

 

################## | Vaccinação |

 

# C:\autorun.inf -> Autorun.inf criado por UsbFix (El Desaparecido).

# D:\autorun.inf -> Autorun.inf criado por UsbFix (El Desaparecido).

# E:\autorun.inf -> Autorun.inf criado por UsbFix (El Desaparecido).

 

################## | Upload |

 

Favor enviar o arquivo : C:\UsbFix_Upload_Me_SERVIDOR400.zip : http://chiquitine.changelog.fr/Sample/Upload.php

Obrigado pela sua contribuição .

 

################## | ! Fim do relatório # UsbFix V6.100 ! |

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:17:18, on 23/03/2010

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\WINDOWS\system32\sistray.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqbam08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgpc01.exe

D:\Arquivos de programas\TinaSoft\Easy Cafe Server\EASYSERVER.EXE

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\WINDOWS\system32\NOTEPAD.EXE

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG9\avgssie.dll (file missing)

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll

O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [hpqSRMon] C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSRMon.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Seleção HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: http://www.ead.sebrae.com.br

O15 - Trusted Zone: www.webaula.com.br

O16 - DPF: {9EC30204-384D-11D3-9CA3-00A024F0AF03} (ValidaUsuario Class) - https://cpne.bradesco.com.br/certifexp.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{C7406FA5-7351-496B-92E4-D557BAB81CAE}: NameServer = 192.168.1.1

 

--

End of file - 5997 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Noite! Bechir Bitar

 

<@> Abra o OTL.exe --> Clique em CleanUp.jpg --> Aguarde!

<@> Na solicitação,clique OK --> Reinicie o computador!

0000000000000000000

0000000000000000000

################## | Upload |

 

Favor enviar o arquivo : C:\UsbFix_Upload_Me_SERVIDOR400.zip : http://chiquitine.ch...mple/Upload.php

Obrigado pela sua contribuição .

<!> Contribua com os desenvolvedores,enviando o arquivo em destaque.

0000000000000000000

0000000000000000000

<@> Caso queira,faça este escaneamento,online,em: < Eset Nod32 >

<@> Ps: Utilize o navegador Internet Explorer.

<@> Marque a caixa: "SIM,aceito as condições de uso" --> Iniciar.

<@> Marque a caixa: "YES, I accept the Terms of Use" --> Start.

<@> Aceite a instalação do ActiveX --> Dê início ao scan.

<@> Concluindo,poste o relatório.

<@> No mais,seus logs estão limpos! :)

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde DigRam !!!

 

Os erros que estavam dando nos navegadores param, agora fiacaram dois problemas pra gente tentar resolver que são:

 

1 - O dispositivo de rede demora quaze 2 minutos pra entrar depois que o sistema está todo carregado.

2 - Não consigo instalar o AVG porque da a mensagem que o antivir desktop esta instalado e que esta gerando um conflito e poe si vai.

 

ps - Já removi tudo que indicio deste Antivir Desktop, mesmo assim continua acusando.

 

Me de alguma luz para resolver estes dois casos.

 

Obrigado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde DigRam !!!

 

Os erros que estavam dando nos navegadores param, agora fiacaram dois problemas pra gente tentar resolver que são:

 

1 - O dispositivo de rede demora quaze 2 minutos pra entrar depois que o sistema está todo carregado.

2 - Não consigo instalar o AVG porque da a mensagem que o antivir desktop esta instalado e que esta gerando um conflito e poe si vai.

 

ps - Já removi tudo que indicio deste Antivir Desktop, mesmo assim continua acusando.

 

Me de alguma luz para resolver estes dois casos.

 

Obrigado.

//////////////\\\\\\\\\\\\\

Opa! Bechir Bitar

 

<!> São problemas,possivelmente,não relacionados à vírus.

0000000000000000000

0000000000000000000

<@> Baixe: < Avira AntiVir Removal Tool > ( 359 Kb )

<@> Execute esta tool,na remoção de resquícios do Avira.

0000000000000000000

0000000000000000000

<@> Ps: Faça o scan em Eset e,à seguir,em Kaspersky.

0000000000000000000

0000000000000000000

<@> Acesse: < Kaspersky Online Scanner >

<@> Clique em Accept.

<@> Na janela "Segurança do Java",clique em Aceitar.

<@> Aguarde a atualização do banco de dados. ( Update em 100% )

<@> Ps: Desabilite seu antivírus ou firewall.

<@> Dê início ao scan,clicando em "My Computer",dentre outras opções.

<@> Ps: Para um escaneamento mais rápido,escolha: "Critical areas"

<@> Terminando,obtenha o relatório clicando em "View report".

<@> Poste-o na sua resposta.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oba DigRam !!! Bom dia, Conforme você determinou tentei fazer:

- OTL.exe --> Clean Up --- Feito 100%

- Não enviado --> C:\UsbFix_Upload_Me_SERVIDOR400.zip -> saite http://chiquitine.ch...mple/Upload.php inexiste

- NOD 32 On-line Executado achou 8 Pragas no entanto não disponibilizou o log na pasta onde foi instalado.

- Avira AntiVir Removal Tool --> Não removeu Antivir DESKTOP tive que isnatalar o avg 9.9 na marra.

- Kaspersky Online Scanner --> Não pode ser feito porque achou Antivir DESKTOP instalado no equipamento.

 

A lentidão continua, leva até 5 minutos para carragar desde o momento que liga até a disponibinilade da rede...

A maior demora e na tela de boas vindas depois que abre demora uns 2 minutos para disponibilizar a rede e quando a rede entra mostra uma mensagem muito rapida no tray dizendo o seu computador pode estar em risco e fecha rapidamente. Antes quando o windows carregava podia teclar no icone de qualquer navegador que ele iniciava imetamente a gora leva este tempo todo, gostaria que me ajudasse a resolver esta lentidão.

 

 

Mais uma vez obrigado pela ajuda.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Bechir Bitar

 

<@> Ps: Caso tenha desinstalado o Avira.

<@> Vá a esta página e baixe: < Avira AntiVir RegistryCleaner > ( 887 KB )

<@> Execute o utilitário,mas...não esqueça de tirá-lo do zip.

000000000000000000000

000000000000000000000

<!> Desinstale: C:\Arquivos de programas\Yahoo! <--

000000000000000000000

000000000000000000000

<@> Baixe: < ClamWin Free Antivirus 0.95.3 Released >

<@> Para baixar,clique em Download Now: < http://www.clamwin.com/index.php?option=com_content&task=view&id=132&version=0.95.3&source=sf >

000000000000000000000

<!> Procure instalar este antivírus,que não lhe trará problemas.

000000000000000000000

<!> Poste: HijackThis atualizado.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia DigRam !!!

 

Foi feito o que você mandou, infelizmente a lentidão persiste, fico intrigado é que antes quando abria o desktop a rede já estava disponível.

 

Segue o report do ClamWim e o Log do HijackThis

 

 

Report do ClamWim

 

Scan Started Tue Mar 30 21:24:15 2010

 

-------------------------------------------------------------------------------

 

C:\Documents and Settings\All Users\Dados de aplicativos\avg9\Chjw\4cf83050f8303b12\0729c555-2819-4e54-b033-92a979bd065a: Permission denied

 

C:\Documents and Settings\All Users\Dados de aplicativos\avg9\Chjw\4cf83050f8303b12\867c59f4-3919-4d18-86ca-4536e82e7e99: Permission denied

 

C:\Documents and Settings\B&J Cyber\Configurações locais\Dados de aplicativos\Microsoft\Windows Live Contacts\9194abb3-fc55-4e93-9967-e5a744d8c7cc\DBStore\contacts.edb: Permission denied

 

C:\Documents and Settings\B&J Cyber\Configurações locais\Dados de aplicativos\Microsoft\Windows Live Contacts\9194abb3-fc55-4e93-9967-e5a744d8c7cc\DBStore\tempedb.edb: Permission denied

 

C:\Documents and Settings\B&J Cyber\Configurações locais\temp\~DF25CC.tmp: Permission denied

 

C:\Documents and Settings\B&J Cyber\Configurações locais\temp\~DFDAA0.tmp: Permission denied

 

C:\pagefile.sys: Permission denied

 

C:\WINDOWS\system32\CatRoot2\tmp.edb: Permission denied

 

C:\WINDOWS\system32\config\default: Permission denied

 

C:\WINDOWS\system32\config\SAM: Permission denied

 

C:\WINDOWS\system32\config\SECURITY: Permission denied

 

C:\WINDOWS\system32\config\software: Permission denied

 

C:\WINDOWS\system32\config\system: Permission denied

 

 

 

C:\System Volume Information\_restoreC70F14DE-9D8D-4A4F-A71D-996D80C4A438\RP238\A0134272.ini: Backdoor.Poison-4 FOUND

 

C:\System Volume Information\_restoreC70F14DE-9D8D-4A4F-A71D-996D80C4A438\RP238\A0134277.inf: Worm.Autorun-1792 FOUND

 

----------- SCAN SUMMARY -----------

 

Known viruses: 750450

 

Engine version: 0.95.3

 

Scanned directories: 4433

 

Scanned files: 62307

 

Infected files: 2

 

 

 

Data scanned: 13572.60 MB

 

Data read: 16001.29 MB (ratio 0.85:1)

 

Time: 6557.828 sec (109 m 17 s)

 

--------------------------------------

 

Completed

 

--------------------------------------

 

 

 

Scan Started Tue Mar 30 23:14:57 2010

 

-------------------------------------------------------------------------------

 

 

 

 

 

D:\System Volume Information\_restoreC70F14DE-9D8D-4A4F-A71D-996D80C4A438\RP252\A0138033.exe: Trojan.Autoit-70 FOUND

 

----------- SCAN SUMMARY -----------

 

Known viruses: 750450

 

Engine version: 0.95.3

 

Scanned directories: 357

 

Scanned files: 1624

 

Infected files: 1

 

 

 

Data scanned: 3331.82 MB

 

Data read: 5432.97 MB (ratio 0.61:1)

 

Time: 1289.532 sec (21 m 29 s)

 

--------------------------------------

 

Completed

 

--------------------------------------

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:12:32, on 31/03/2010

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\AVG\AVG9\avgchsvx.exe

C:\Arquivos de programas\AVG\AVG9\avgrsx.exe

C:\Arquivos de programas\AVG\AVG9\avgcsrvx.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\netdde.exe

C:\Arquivos de programas\AVG\AVG9\avgwdsvc.exe

C:\WINDOWS\system32\svchost.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Arquivos de programas\AVG\AVG9\avgnsx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\Explorer.EXE

C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

C:\ARQUIV~1\AVG\AVG9\avgtray.exe

C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe

C:\Arquivos de programas\ClamWin\bin\ClamTray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

C:\WINDOWS\system32\sistray.exe

D:\Arquivos de programas\TinaSoft\Easy Cafe Server\EASYSERVER.EXE

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqbam08.exe

C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgpc01.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer

R3 - URLSearchHook: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG9\avgssie.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll (file missing)

O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll

O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O3 - Toolbar: Barra de Ferramentas do Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Arquivos de programas\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [HP Software Update] C:\Arquivos de programas\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [hpqSRMon] C:\Arquivos de programas\HP\Digital Imaging\bin\hpqSRMon.exe

O4 - HKLM\..\Run: [unlockerAssistant] "C:\Arquivos de programas\Unlocker\UnlockerAssistant.exe"

O4 - HKLM\..\Run: [AVG9_TRAY] C:\ARQUIV~1\AVG\AVG9\avgtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [ClamWin] "C:\Arquivos de programas\ClamWin\bin\ClamTray.exe" --logon

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Seleção HP Smart - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: http://www.ead.sebrae.com.br

O15 - Trusted Zone: www.webaula.com.br

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab

O16 - DPF: {9EC30204-384D-11D3-9CA3-00A024F0AF03} (ValidaUsuario Class) - https://cpne.bradesco.com.br/certifexp.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{C7406FA5-7351-496B-92E4-D557BAB81CAE}: NameServer = 192.168.1.1

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG9\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Arquivos de programas\AVG\AVG9\avgwdsvc.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Arquivos de programas\Google\Update\GoogleUpdate.exe

 

--

End of file - 7465 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa Tarde! Bechir Bitar

 

<@> Desinstale estes programas!

 

C:\Arquivos de programas\AVG\AVG9 <--

 

C:\Arquivos de programas\Yahoo! <--

 

C:\Arquivos de programas\Unlocker <--

 

C:\Arquivos de programas\Google <--

 

C:\Arquivos de programas\HP <--

 

C:\Arquivos de programas\Adobe <--

 

<@> Após isso,utilize o CCleaner,na correção de Erros.

<@> Faça outra verificação com o ClamWin e delete tudo o que encontrar.

<@> Ps: Posteriormente,alguns destes programas serão reinstalados.

<@> Mas..faça-o de forma gradativa,sempre observando o 'comportamento' da 'máquina'.

<@> Otimize o computador e navegação com o TuneUp Utilities.

0000000000000000000000

<@> Faça o download do TuneUp Utilities 2010.

<@> Para baixar,digite o seu E-Mail e clique em Start download.

<@> Salve o executável,TU2010TrialEN.exe,em Arquivos de Programas.

<@> O programa é Trial! Mas...haverá tempo,para a otimização do computador.

<@> Procure desfragmentar o Disco e Registro.

<@> Otimize a navegação!

0000000000000000000000

<@> Baixe: < GenProc >

<@> Salve-o no desktop!

<@> Execute-o,clicando em GenProc.exe --> Enter --> Aguarde!

 

Rapport GenProc 2.660 [2] - dom 10/01/2010 à 18:02:17

@ Windows XP Service Pack 3 - Mode normal

@ Mozilla Firefox 3.5.7 (pt-BR) [Navigateur par défaut]

 

~~ ECHEC DU TELECHARGEMENT DE CM ~~

~~ ECHEC DU TELECHARGEMENT DE MBR.EXE ~~

~~ ECHEC DU TELECHARGEMENT D'HIJACKTHIS ~~

~~ ECHEC DU TELECHARGEMENT DE ZHP ~~

 

GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :

 

Poste un rapport Nod32 http://www.eset-nod32.fr/scanner.html (il faut utiliser Internet Explorer)

- coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :

C:\Program Files\EsetOnlineScanner\log.txt

 

----------------------------------------------------------------------

Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com

----------------------------------------------------------------------

 

~~ Fin à 18:03:09 ~~

<@> Terminando,clique em Sim.

<@> Conforme a Quote,surgirá uma pop-up contendo o relatório. ( Rapport GenProc )

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa tarde DigRam ! Estive com problemas no meu link de internet e não pude retornar, fiz tudo o que me recomendou: removi todos os arquivos e programas rodei o tuneup, gemproc fui instalando os programas um a um, desligava o sistema e contava o tempo de 5 minutos caiu para 2 ao instalar os drivers da Impressora HP o tempo sobe para 5 minutos, ai vem uma pergunta como é que antes ele estava isntalado e o tempo de carga era menos de 1 minuto ?

Voce acha que ainda resta alguma chance para que o computador diminua este tempo de 2 para pelo menos 1 minuto ?

 

Obrigado pela atenção !!!

Compartilhar este post


Link para o post
Compartilhar em outros sites

O GemProc gerou isto !

 

Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers temporaires de Windows datant de plus de 24 heures" ; par la suite, laisse-le avec ses réglages par défaut. C'est tout.

 

 

Etape 1/ Télécharge :

 

 

Toolbar-S&D (Eric_71) sur ton Bureau.

 

 

 

 

Redémarre en mode sans échec comme indiqué ICI ; Choisis ta session courante *** BUSERNAMEJ Cyber *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[1]" sur ton bureau).

 

 

 

 

Etape 2/

 

 

Lance Toolbar-S&D situé sur le Bureau. Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.

 

 

Etape 3/

 

 

Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

 

 

 

Etape 4/

 

 

Redémarre normalement et poste, dans la même réponse :

 

- Le contenu du rapport TB.txt situé dans C:\ ;

- Un nouveau rapport GenProc ;

 

 

Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Opa! Bechir Bitar

 

<!> Execute a ferramenta GenProc em Modo de Segurança,e poste seu relatório.

00000000000000000000

00000000000000000000

<@> Baixe: < ToolBar S&D >

<@> Salve-o no Disco Local-C,em uma pasta própria.

<@> Reinicie o computador,em Modo de Segurança. <-- Importante!

<@> Execute o programa,e à seguir,aperte o "p" --> Enter --> Ok.

<@> Digite o dois! ( 2 ) --> Aperte Enter --> Aguarde!

<@> Terminando,poste o relatório. ( C:\ToolBar SD\TB_1.txt ) <--

00000000000000000000

00000000000000000000

<!> Ps: Caso esteja utilizando TuneUp Utilities,proceda à desfragmentação de sua unidade C:\.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Boa noite DigRam !!!

 

Ai o log que voce pediu

 

Do GemProc

 

Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers temporaires de Windows datant de plus de 24 heures" ; par la suite, laisse-le avec ses réglages par défaut. C'est tout.

 

 

Etape 1/ Télécharge :

 

 

Toolbar-S&D (Eric_71) sur ton Bureau.

 

 

 

 

Redémarre en mode sans échec comme indiqué ICI ; Choisis ta session courante *** BUSERNAMEJ Cyber *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[1]" sur ton bureau).

 

 

 

 

Etape 2/

 

 

Lance Toolbar-S&D situé sur le Bureau. Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.

 

 

Etape 3/

 

 

Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

 

 

 

Etape 4/

 

 

Redémarre normalement et poste, dans la même réponse :

 

- Le contenu du rapport TB.txt situé dans C:\ ;

- Un nouveau rapport GenProc ;

 

 

Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

 

 

Liste Ajout-Suppression de programmes - Arguments de la procédure

 

 

 

-----------\\ ToolBar S&D 1.2.9 XP/Vista

 

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3

X86-based PC ( Uniprocessor Free : AMD Sempron Processor 2800+ )

BIOS : Phoenix - AwardBIOS v6.00PG

USER : B&J Cyber ( Administrator )

BOOT : Fail-safe boot

Antivirus : AntiVir Desktop 9.0.1.30 (Activated)

C:\ (Local Disk) - NTFS - Total:20 Go (Free:5 Go)

D:\ (Local Disk) - FAT32 - Total:17 Go (Free:4 Go)

 

"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )

Option : [2] ( 09/04/2010|23:04 )

 

-----------\\ REMOVIDOS

 

Deletado! - C:\Arquivos de programas\AskBarDis\bar

Deletado! - C:\Arquivos de programas\AskBarDis\unins000.dat

Deletado! - C:\Arquivos de programas\AskBarDis

 

-----------\\ Procura por Arquivos / Ficheiros ...

 

 

-----------\\ Extensions

 

(B&J Cyber) - {E9A1DEE0-C623-4439-8932-001E7D17607D} => ajtoolbar

(B&J Cyber) - {DDC359D1-844A-42a7-9AA1-88A850A938A8} => chrome

 

 

-----------\\ [..\Internet Explorer\Main]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

"Start Page"="http://www.google.com.br/"

"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

"Url"="http://go.microsoft.com/fwlink/?LinkId=75724"

"Url"="http://go.microsoft.com/fwlink/?LinkId=75723"

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

"Start Page"="http://www.msn.com/"

 

 

--------------------\\ Procurando por outras infecções

 

--------------------\\ ROOTKIT !!

 

Rootkit Pandex ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HOOKSYS]

Rootkit Pandex ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_HOOKSYS]

Rootkit Pandex ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_HOOKSYS]

Rootkit Pandex ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HOOKSYS]

 

--------------------\\ Cracks & Keygens ..

 

C:\DOCUME~1\B&JCYB~1\Meus documentos\Diversos\TIMER_CAFE_4.3.3___CRACK.rar.dap

 

 

 

1 - "C:\ToolBar SD\TB_1.txt" - 09/04/2010|23:05 - Option : [2]

 

-----------\\ Verificação completa em 23:05:59,70

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom Dia! Bechir Bitar

 

<@> Baixe: < otm1.jpg > ( ...by OldTimer Tools )

<@> Salve-o no desktop e,execute-o aí mesmo!

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

:Processes

explorer.exe

:files

C:\Documents and Settings\All Users\Dados de aplicativos\Rising

:reg

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HOOKSYS]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_HOOKSYS]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\hooksys]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HOOKSYS]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HOOKSYS]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_HOOKSYS]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HOOKSYS]

:services

hooksys

:Commands

[purity]

[emptytemp]

[start explorer]

[Reboot]

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

<@> Copie e cole estas informações,entre os XXXXX...,para o campo ( clipboard ),da ferramenta.

<@> Ps: Área abaixo de "Paste Instructions for Items to be Moved".

<@> Clique em MoveIt.

<@> Na solicitação de reboot,confirme! --> Aguarde!

<@> Terminando,verifique o conteúdo texto da pasta: C:\_OTM\MovedFiles

<@> Copie e poste,seu relatório mais recente: C:\_OTM\MovedFiles\xxxx2010_xxxxxx.log <--

<@> Ps: Como a ferramenta não sobreescreve seus relatórios,devemos observar o que foi gerado logo após sua execução.

<@> Ps: Poste,também,um novo relatório do TooBar S&D,nas mesmas opções.

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Doa Noite DigRam

 

Os drivers da HP ainda não foram instalados.

 

No aguardo, obrigado.

 

---------------------------------------------------------------------------------------------

 

Seguem os resultados das verificações

 

 

 

All processes killed

========== PROCESSES ==========

No active process named explorer.exe was found!

========== FILES ==========

C:\Documents and Settings\All Users\Dados de aplicativos\Rising\common folder moved successfully.

C:\Documents and Settings\All Users\Dados de aplicativos\Rising folder moved successfully.

========== REGISTRY ==========

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HOOKSYS\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_HOOKSYS\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\hooksys\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HOOKSYS\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HOOKSYS\ not found.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_HOOKSYS\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HOOKSYS\ not found.

========== SERVICES/DRIVERS ==========

Error: No service named hooksys was found to stop!

Service\Driver key hooksys not found.

========== COMMANDS ==========

 

[EMPTYTEMP]

 

User: Administrador

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

 

User: All Users

 

User: B&J Cyber

->Temp folder emptied: 12146684 bytes

->Temporary Internet Files folder emptied: 38835404 bytes

->Java cache emptied: 766625 bytes

->FireFox cache emptied: 88964937 bytes

->Google Chrome cache emptied: 0 bytes

->Flash cache emptied: 1659 bytes

 

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

 

User: LocalService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

 

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

 

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 647379 bytes

RecycleBin emptied: 408243 bytes

 

Total Files Cleaned = 135,00 mb

 

 

OTM by OldTimer - Version 3.1.10.1 log created on 04112010_184146

 

Files moved on Reboot...

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\3C3PXTFF\adsCAG4JQIS.htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\1NIJJCDF\index[3].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\1AY9MGEO\adsCA192HCV.htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\Content.IE5\1AY9MGEO\barra[1].htm moved successfully.

C:\Documents and Settings\B&J Cyber\Configurações locais\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.

 

Registry entries deleted on Reboot...

 

 

----------------------------------------------------------------------------------------------------------------------------------

 

-----------\\ ToolBar S&D 1.2.9 XP/Vista

 

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3

X86-based PC ( Uniprocessor Free : AMD Sempron Processor 2800+ )

BIOS : Phoenix - AwardBIOS v6.00PG

USER : B&J Cyber ( Administrator )

BOOT : Normal boot

Antivirus : AntiVir Desktop 9.0.1.30 (Activated)

C:\ (Local Disk) - NTFS - Total:20 Go (Free:5 Go)

D:\ (Local Disk) - FAT32 - Total:17 Go (Free:4 Go)

 

"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )

Option : [2] ( 11/04/2010|18:54 )

 

-----------\\ Procura por Arquivos / Ficheiros ...

 

 

-----------\\ Extensions

 

(B&J Cyber) - {E9A1DEE0-C623-4439-8932-001E7D17607D} => ajtoolbar

(B&J Cyber) - {DDC359D1-844A-42a7-9AA1-88A850A938A8} => chrome

 

 

-----------\\ [..\Internet Explorer\Main]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

"Start Page"="http://www.google.com.br/"

"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

"Url"="http://go.microsoft.com/fwlink/?LinkId=75724"

"Url"="http://go.microsoft.com/fwlink/?LinkId=75723"

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

"Start Page"="http://www.msn.com/"

 

 

--------------------\\ Procurando por outras infecções

 

--------------------\\ Cracks & Keygens ..

 

C:\DOCUME~1\B&JCYB~1\Meus documentos\Diversos\TIMER_CAFE_4.3.3___CRACK.rar.dap

 

 

 

1 - "C:\ToolBar SD\TB_1.txt" - 09/04/2010|23:05 - Option : [2]

2 - "C:\ToolBar SD\TB_2.txt" - 11/04/2010|18:55 - Option : [2]

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oi DigRam !!!

 

Observando o log do Toolbar encontrei a linha a baixo que entra em conflito toda vez que instalo o AVG e esta referencia não é encontrada em lugar algum, ela existe e está muito bem escondida porque não está no registro e nem em pastas.

 

Antivirus : AntiVir Desktop 9.0.1.30 (Activated)

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oi DigRam !!!

 

Observando o log do Toolbar encontrei a linha a baixo que entra em conflito toda vez que instalo o AVG e esta referencia não é encontrada em lugar algum, ela existe e está muito bem escondida porque não está no registro e nem em pastas.

 

Antivirus : AntiVir Desktop 9.0.1.30 (Activated)

////////////\\\\\\\\\\\

Opa! Bechir Bitar

 

<!> Existem resquícios do Avira,que devem ser removidos.

0000000000000000000

0000000000000000000

<@> Abra o OTMoveIt3 --> Clique em < 8gehxg0.gif > --> Aguarde! --> Yes!

0000000000000000000

0000000000000000000

<@> Baixe: < 331oifp.png > <-- Link!

<@> Salve-o no desktop ou C:\.

<@> Duplo-clique em OTS.exe.

<@> Ps: Para Windows Vista,execute-o logado como administrador.

<@> Na opção "Additional Scans",clique em "Extras".

<@> Complemente,marcando também as caixinhas:

 

[] Reg - NetSvcs

[] File - Lop Check

 

 

<@> Para sistemas 64bits,teremos a opção:

<!> "Include 64bit Scans" < 64bitscan.png > <-- Marque-a!

<@> Em "Basic Scans" marque,também,as caixinhas:

 

[] Use Company Name Whitelist

[] Skip Microsoft Files

 

<@> Verifique: 250ii3s.png & n19ytt.png

<@> À seguir,clique em 2lasxtt.png

<@> Terminando,abrir-se-á o Bloco de Notas,com o relatório. ( OTS.txt )

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ola DigRam !!!

 

Feito a execução segue o log do OTS o OTMoveIt3 sumiu pasta com log e tudo é isto mesmo ?

 

Obrigado.

 

------------------

------------------

 

OTS logfile created on: 11/04/2010 22:42:49 - Run 1

OTS by OldTimer - Version 3.1.28.1 Folder = C:\Documents and Settings\B&J Cyber\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

 

959,00 Mb Total Physical Memory | 502,00 Mb Available Physical Memory | 52,00% Memory free

2,00 Gb Paging File | 1,00 Gb Available in Paging File | 76,00% Paging File free

Paging file location(s): C:\pagefile.sys 672 1344 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Arquivos de programas

Drive C: | 20,02 Gb Total Space | 5,93 Gb Free Space | 29,64% Space Free | Partition Type: NTFS

Drive D: | 17,27 Gb Total Space | 4,15 Gb Free Space | 24,04% Space Free | Partition Type: FAT32

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

 

Computer Name: SERVIDOR400

Current User Name: B&J Cyber

Logged in as Administrator.

 

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 30 Days

 

[Processes - Safe List]

ots.exe -> C:\Documents and Settings\B&J Cyber\Desktop\OTS.exe -> [2010/04/11 22:38:49 | 000,638,464 | ---- | M] (OldTimer Tools)

avgtray.exe -> C:\Arquivos de programas\AVG\AVG9\avgtray.exe -> [2010/04/02 10:33:50 | 002,064,224 | ---- | M] (AVG Technologies CZ, s.r.o.)

avgchsvx.exe -> C:\Arquivos de programas\AVG\AVG9\avgchsvx.exe -> [2010/04/02 10:33:11 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.)

avgrsx.exe -> C:\Arquivos de programas\AVG\AVG9\avgrsx.exe -> [2010/03/31 17:59:34 | 000,508,184 | ---- | M] (AVG Technologies CZ, s.r.o.)

avgnsx.exe -> C:\Arquivos de programas\AVG\AVG9\avgnsx.exe -> [2010/03/31 17:59:33 | 000,617,752 | ---- | M] (AVG Technologies CZ, s.r.o.)

avgwdsvc.exe -> C:\Arquivos de programas\AVG\AVG9\avgwdsvc.exe -> [2010/03/31 17:59:28 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.)

avgcsrvx.exe -> C:\Arquivos de programas\AVG\AVG9\avgcsrvx.exe -> [2010/03/31 17:59:24 | 000,710,424 | ---- | M] (AVG Technologies CZ, s.r.o.)

jusched.exe -> C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe -> [2010/02/18 11:43:18 | 000,248,040 | ---- | M] (Sun Microsystems, Inc.)

clamtray.exe -> C:\Arquivos de programas\ClamWin\bin\ClamTray.exe -> [2009/11/03 21:49:02 | 000,086,016 | ---- | M] (alch)

wlcomm.exe -> C:\Arquivos de programas\Windows Live\Contacts\wlcomm.exe -> [2009/02/06 17:07:48 | 000,027,512 | ---- | M] (Microsoft Corporation)

explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 19:21:00 | 001,035,776 | ---- | M] (Microsoft Corporation)

sistray.exe -> C:\WINDOWS\system32\sistray.exe -> [2005/07/13 01:53:38 | 000,262,144 | ---- | M] (Silicon Integrated Systems Corporation)

mdm.exe -> C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe -> [2001/02/23 09:07:30 | 000,270,336 | ---- | M] (Microsoft Corporation)

 

[Modules - Safe List]

ots.exe -> C:\Documents and Settings\B&J Cyber\Desktop\OTS.exe -> [2010/04/11 22:38:49 | 000,638,464 | ---- | M] (OldTimer Tools)

framedyn.dll -> C:\WINDOWS\system32\framedyn.dll -> [2006/05/03 22:53:54 | 000,174,592 | ---- | M] (Microsoft Corporation)

 

[Win32 Services - Safe List]

(avg9wd) AVG Free WatchDog [Auto | Running] -> C:\Arquivos de programas\AVG\AVG9\avgwdsvc.exe -> [2010/03/31 17:59:28 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.)

(getPlusHelper) getPlus® Helper [On_Demand | Stopped] -> C:\Arquivos de programas\NOS\bin\getPlus_Helper.dll -> [2010/03/22 15:51:54 | 000,068,000 | ---- | M] (NOS Microsystems Ltd.)

(MDM) Machine Debug Manager [Auto | Running] -> C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7Debug\mdm.exe -> [2001/02/23 09:07:30 | 000,270,336 | ---- | M] (Microsoft Corporation)

 

[Driver Services - Safe List]

(AvgTdiX) AVG Free Network Redirector [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\avgtdix.sys -> [2010/03/31 17:59:35 | 000,242,696 | ---- | M] (AVG Technologies CZ, s.r.o.)

(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> C:\WINDOWS\System32\Drivers\avgmfx86.sys -> [2010/03/31 17:59:33 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.)

(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\avgldx86.sys -> [2010/03/31 17:59:24 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.)

(teamviewervpn) TeamViewer VPN Adapter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\teamviewervpn.sys -> [2008/01/25 06:12:34 | 000,025,088 | ---- | M] (TeamViewer GmbH)

(vncdrv) vncdrv [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\vncdrv.sys -> [2007/06/07 17:17:28 | 000,002,218 | ---- | M] (Microsoft Corporation)

(ss_mdm) SAMSUNG Mobile USB Modem 1.0 Drivers [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\ss_mdm.sys -> [2007/05/02 11:11:18 | 000,109,704 | ---- | M] (MCCI Corporation)

(ss_mdfl) SAMSUNG Mobile USB Modem 1.0 Filter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\ss_mdfl.sys -> [2007/05/02 11:11:18 | 000,015,112 | ---- | M] (MCCI Corporation)

(ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM) [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\ss_bus.sys -> [2007/05/02 11:11:16 | 000,083,592 | ---- | M] (MCCI Corporation)

(StarOpen) StarOpen [File_System | System | Running] -> C:\WINDOWS\system32\drivers\StarOpen.sys -> [2006/07/24 16:05:00 | 000,005,632 | ---- | M] ()

(ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\ALCXWDM.SYS -> [2005/08/19 06:31:52 | 003,644,800 | R--- | M] (Realtek Semiconductor Corp.)

(SiSkp) SiSkp [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\srvkp.sys -> [2005/07/12 16:48:02 | 000,011,904 | R--- | M] (Silicon Integrated Systems Corporation)

(SiS315) SiS315 [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\sisgrp.sys -> [2005/07/12 16:07:18 | 000,257,024 | R--- | M] (Silicon Integrated Systems Corporation)

(SISNIC) SiS PCI Fast Ethernet Adapter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\sisnic.sys -> [2004/08/03 19:31:36 | 000,032,768 | ---- | M] (SiS Corporation)

(Aspi32) Aspi32 [Kernel | Auto | Running] -> C:\WINDOWS\system32\drivers\ASPI32.SYS -> [2002/08/14 14:03:36 | 000,017,005 | ---- | M] (Adaptec)

 

[Registry - Safe List]

< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->

HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.msn.com/ ->

< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->

HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->

< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->

HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->

< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->

< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->

< Internet Explorer Settings [HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\] > -> ->

HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\: Main\\"Start Page" -> http://www.google.com.br/ ->

HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\: "ProxyEnable" -> 0 ->

< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\FireFox\Profiles\rzhc27jr.default\prefs.js ->

browser.startup.homepage -> "http://www.google.com.br/" ->

extensions.enabledItems -> {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.9 ->

extensions.enabledItems -> {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.783 ->

network.proxy.ftp -> "localhost" ->

network.proxy.ftp_port -> 8080 ->

network.proxy.gopher -> "localhost" ->

network.proxy.gopher_port -> 8080 ->

network.proxy.http -> "localhost" ->

network.proxy.http_port -> 8080 ->

network.proxy.no_proxies_on -> "http://192.168.0.9:918,http://192.168.1.9:918" ->

network.proxy.socks -> "localhost" ->

network.proxy.socks_port -> 1080 ->

network.proxy.ssl -> "localhost" ->

network.proxy.ssl_port -> 8080 ->

< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla

HKLM\software\mozilla\Firefox\extensions -> ->

HKLM\software\mozilla\Firefox\extensions\\smartwebprinting@hp.com -> C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [C:\ARQUIVOS DE PROGRAMAS\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON2] -> [2010/03/16 16:58:57 | 000,000,000 | ---D | M]

HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} -> C:\Arquivos de programas\AVG\AVG9\Firefox [C:\ARQUIVOS DE PROGRAMAS\AVG\AVG9\FIREFOX] -> [2010/03/31 18:05:02 | 000,000,000 | ---D | M]

HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions -> ->

HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components -> C:\Arquivos de programas\Mozilla Firefox\components [C:\ARQUIVOS DE PROGRAMAS\MOZILLA FIREFOX\COMPONENTS] -> [2010/04/03 19:18:08 | 000,000,000 | ---D | M]

HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins -> C:\Arquivos de programas\Mozilla Firefox\plugins [C:\ARQUIVOS DE PROGRAMAS\MOZILLA FIREFOX\PLUGINS] -> [2010/04/11 20:23:22 | 000,000,000 | ---D | M]

< FireFox Extensions [user Folders] > ->

-> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Extensions -> [2010/03/17 16:50:16 | 000,000,000 | ---D | M]

-> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Extensions\mozswing@mozswing.org -> [2009/08/10 14:06:27 | 000,000,000 | ---D | M]

-> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\extensions -> [2009/06/22 20:36:30 | 000,000,000 | ---D | M]

No name found -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} -> [2009/06/24 18:43:55 | 000,000,000 | ---D | M]

-> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\extensions -> [2010/04/10 14:29:26 | 000,000,000 | ---D | M]

DownThemAll! -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8} -> [2010/04/04 22:17:35 | 000,000,000 | ---D | M]

< FireFox Extensions [Program Folders] > ->

-> C:\Arquivos de programas\Mozilla Firefox\extensions -> [2010/04/10 14:29:26 | 000,000,000 | ---D | M]

< HOSTS File > ([2010/03/22 08:35:07 | 000,000,027 | ---- | M] - 1 lines) -> C:\WINDOWS\system32\drivers\etc\hosts ->

Reset Hosts

127.0.0.1 localhost

< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->

{0347C33E-8762-4905-BF09-768834316C61} [HKLM] -> C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [HP Print Enhancer] -> [2008/03/27 23:51:18 | 000,322,880 | ---- | M] (Hewlett-Packard Co.)

{18DF081C-E8AD-4283-A596-FA578C2EBDC3} [HKLM] -> C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [Adobe PDF Link Helper] -> [2009/12/21 18:27:44 | 000,075,200 | ---- | M] (Adobe Systems Incorporated)

{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> C:\Arquivos de programas\AVG\AVG9\avgssie.dll [AVG Safe Search] -> [2010/04/02 10:33:49 | 001,602,912 | ---- | M] (AVG Technologies CZ, s.r.o.)

{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Auxiliar de Conexão do Windows Live] -> [2009/01/22 15:41:30 | 000,408,448 | ---- | M] (Microsoft Corporation)

{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} [HKLM] -> C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [HP Smart BHO Class] -> [2008/03/27 23:51:18 | 000,501,056 | ---- | M] (Hewlett-Packard Co.)

< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->

"Adobe ARM" -> C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe ["C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"] -> [2009/12/11 15:57:56 | 000,948,672 | R--- | M] (Adobe Systems Incorporated)

"AVG9_TRAY" -> C:\Arquivos de programas\AVG\AVG9\avgtray.exe [C:\ARQUIV~1\AVG\AVG9\avgtray.exe] -> [2010/04/02 10:33:50 | 002,064,224 | ---- | M] (AVG Technologies CZ, s.r.o.)

"ClamWin" -> C:\Arquivos de programas\ClamWin\bin\ClamTray.exe ["C:\Arquivos de programas\ClamWin\bin\ClamTray.exe" --logon] -> [2009/11/03 21:49:02 | 000,086,016 | ---- | M] (alch)

"SiSPower" -> C:\WINDOWS\System32\SiSPower.dll [Rundll32.exe SiSPower.dll,ModeAgent] -> [2005/07/12 15:55:30 | 000,049,152 | R--- | M] (Silicon Integrated Systems Corporation)

"SunJavaUpdateSched" -> C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe ["C:\Arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe"] -> [2010/02/18 11:43:18 | 000,248,040 | ---- | M] (Sun Microsystems, Inc.)

< RunOnce [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ->

"Uninstall Adobe Download Manager" -> ["C:\WINDOWS\system32\rundll32.exe" "C:\Arquivos de programas\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp] -> File not found

< Administrador Startup Folder > -> C:\Documents and Settings\Administrador\Menu Iniciar\Programas\Inicializar ->

< All Users Startup Folder > -> C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar ->

C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Utility Tray.lnk -> C:\WINDOWS\system32\sistray.exe -> [2005/07/13 01:53:38 | 000,262,144 | ---- | M] (Silicon Integrated Systems Corporation)

< B&J Cyber Startup Folder > -> C:\Documents and Settings\B&J Cyber\Menu Iniciar\Programas\Inicializar ->

< Default User Startup Folder > -> C:\Documents and Settings\Default User\Menu Iniciar\Programas\Inicializar ->

< Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer ->

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions

\Infodelivery\Restrictions\\"NoUpdateCheck" -> [1] -> File not found

< Software Policy Settings [HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003] > -> HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Policies\Microsoft\Internet Explorer ->

< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer

\\"HonorAutoRunSetting" -> [0] -> File not found

\\"LinkResolveIgnoreLinkInfo" -> [0] -> File not found

\\"NoDriveAutoRun" -> [255] -> File not found

\\"NoDriveTypeAutoRun" -> [255] -> File not found

< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System

< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer

\\"NoDriveTypeAutoRun" -> [323] -> File not found

\\"NoDriveAutoRun" -> [67108863] -> File not found

< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer

\\"NoDriveTypeAutoRun" -> [323] -> File not found

\\"NoDriveAutoRun" -> [67108863] -> File not found

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->

HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer

\\"NoDriveTypeAutoRun" -> [145] -> File not found

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->

HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer

\\"NoDriveTypeAutoRun" -> [145] -> File not found

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003] > -> HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->

HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer

\\"NoDriveTypeAutoRun" -> [255] -> File not found

\\"NoDeletePrinter" -> [0] -> File not found

\\"NoAddPrinter" -> [0] -> File not found

\\"NoSetTaskbar" -> [0] -> File not found

\\"NoNetHood" -> [0] -> File not found

\\"LinkResolveIgnoreLinkInfo" -> [0] -> File not found

\\"NoDriveAutoRun" -> [255] -> File not found

\\"HonorAutoRunSetting" -> [0] -> File not found

< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003] > -> HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->

HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System

\\"NoSecCPL" -> [0] -> File not found

\\"NoPwdpage" -> [0] -> File not found

\\"NoProfilePage" -> [0] -> File not found

\\"NoDevMgrPage" -> [0] -> File not found

\\"NoConfigpage" -> [0] -> File not found

\\"NoFileSysPage" -> [0] -> File not found

\\"NoVirtMemPage" -> [0] -> File not found

< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\] > -> HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\Software\Microsoft\Internet Explorer\MenuExt\ ->

E&xportar para o Microsoft Excel -> C:\Arquivos de programas\Microsoft Office\Office10\EXCEL.EXE [res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000] -> [2009/12/13 11:35:18 | 009,158,656 | ---- | M] (Microsoft Corporation)

< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->

{DDE87865-83C5-48c4-8357-2F5B1AA84522}:{DDE87865-83C5-48c4-8357-2F5B1AA84522} [HKLM] -> C:\Arquivos de programas\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [button: Seleção HP Smart] -> [2008/03/27 23:51:18 | 000,501,056 | ---- | M] (Hewlett-Packard Co.)

< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\] > -> HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\Software\Microsoft\Internet Explorer\Extensions\ ->

CmdMapping\\"{77BF5300-1474-4EC7-9980-D32B190E9B07}" [HKLM] -> [Reg Error: Key error.] -> File not found

< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->

< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix

"" -> http://

< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->

< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->

< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->

< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->

HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->

< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->

< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->

HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->

< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->

HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->

< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->

HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->

< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->

HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->

< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->

HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->

< Trusted Sites Domains [HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\] > -> HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->

HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1571 domain(s) found. ->

www.ead_sebrae.com.br [http] -> Trusted sites ->

www_webaula.com.br [*] -> Trusted sites ->

< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\] > -> HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->

HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->

< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->

{17492023-C23A-453E-A040-C7C580BBF700} [HKLM] -> http://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab [Windows Genuine Advantage Validation Tool] ->

{7530BFB8-7293-4D34-9923-61A11451AFC5} [HKLM] -> http://download.eset.com/special/eos/OnlineScanner.cab [Reg Error: Key error.] ->

{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [Reg Error: Value error.] ->

{9EC30204-384D-11D3-9CA3-00A024F0AF03} [HKLM] -> https://cpne.bradesco.com.br/certifexp.cab [ValidaUsuario Class] ->

{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab [shockwave Flash Object] ->

{E2883E8F-472F-4FB0-9522-AC9BF37916A7} [HKLM] -> http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab [get_atlcom Class] ->

{E77F23EB-E7AB-4502-8F37-247DBAF1A147} [HKLM] -> http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab [Windows Live Hotmail Photo Upload Tool] ->

< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->

{C7406FA5-7351-496B-92E4-D557BAB81CAE}\\NameServer -> 192.168.1.1 (SiS 900-Based PCI Fast Ethernet Adapter) ->

< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->

*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->

explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 19:21:00 | 001,035,776 | ---- | M] (Microsoft Corporation)

*MultiFile Done* -> ->

< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->

avgrsstarter -> C:\WINDOWS\System32\avgrsstx.dll -> [2010/03/31 17:59:33 | 000,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.)

< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpiscnapp.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpiscnapp.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hposid01.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hposid01.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqcopy2.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqcopy2.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgpc01.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgpc01.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgplgtupl.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgplgtupl.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqkygrp.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqkygrp.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpsapp.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpsapp.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpse.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpse.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqsudi.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqsudi.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe] -> File not found

"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" -> C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe [C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call] -> [2009/02/06 18:21:00 | 000,583,024 | ---- | M] (Microsoft Corporation)

< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->

"C:\Arquivos de programas\AVG\AVG9\avgnsx.exe" -> C:\Arquivos de programas\AVG\AVG9\avgnsx.exe [C:\Arquivos de programas\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe] -> [2010/03/31 17:59:33 | 000,617,752 | ---- | M] (AVG Technologies CZ, s.r.o.)

"C:\Arquivos de programas\AVG\AVG9\avgupd.exe" -> C:\Arquivos de programas\AVG\AVG9\avgupd.exe [C:\Arquivos de programas\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe] -> [2010/04/02 10:06:43 | 001,038,688 | ---- | M] (AVG Technologies CZ, s.r.o.)

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpiscnapp.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpiscnapp.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hposid01.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hposid01.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqcopy2.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqcopy2.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgpc01.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgpc01.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgplgtupl.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgplgtupl.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqkygrp.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqkygrp.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpsapp.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpsapp.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpse.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpse.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqsudi.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqsudi.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe] -> File not found

"C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe" -> C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [C:\Arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe] -> File not found

"C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe" -> C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe [C:\Arquivos de programas\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:ipsec] -> [2010/03/30 00:46:02 | 001,086,856 | ---- | M] (Malwarebytes Corporation)

"C:\Arquivos de programas\Mozilla Firefox\firefox.exe" -> C:\Arquivos de programas\Mozilla Firefox\firefox.exe [C:\Arquivos de programas\Mozilla Firefox\firefox.exe:*:Enabled:Firefox] -> [2010/04/03 19:18:00 | 000,910,296 | ---- | M] (Mozilla Corporation)

"C:\Arquivos de programas\TinaSoft\Easy Cafe Client\client.exe" -> C:\Arquivos de programas\TinaSoft\Easy Cafe Client\client.exe [C:\Arquivos de programas\TinaSoft\Easy Cafe Client\client.exe:*:Enabled:client] -> [2003/04/14 17:37:48 | 000,451,072 | ---- | M] ()

"C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe" -> C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe [C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call] -> [2009/02/06 18:21:00 | 000,583,024 | ---- | M] (Microsoft Corporation)

"C:\Documents and Settings\B&J Cyber\temp\TeamViewer\Version4\TeamViewer.exe" -> C:\Documents and Settings\B&J Cyber\temp\TeamViewer\Version4\TeamViewer.exe [C:\Documents and Settings\B&J Cyber\temp\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application] -> [2009/06/25 04:37:36 | 004,356,392 | ---- | M] (TeamViewer GmbH)

"D:\Arquivos de programas\TinaSoft\Easy Cafe Server\EasyServer.exe" -> D:\Arquivos de programas\TinaSoft\Easy Cafe Server\EasyServer.exe [D:\Arquivos de programas\TinaSoft\Easy Cafe Server\EasyServer.exe:*:Enabled:EasyServer] -> [2003/04/14 18:20:34 | 002,593,280 | ---- | M] ()

"D:\eMule\emule.exe" -> D:\eMule\emule.exe [D:\eMule\emule.exe:*:Enabled:eMule] -> [2009/12/13 10:53:58 | 005,668,864 | ---- | M] (http://www.emule-project.net)

"D:\Ferramentas\TeamViewerPortable_pt\TeamViewer.exe" -> D:\Ferramentas\TeamViewerPortable_pt\TeamViewer.exe [D:\Ferramentas\TeamViewerPortable_pt\TeamViewer.exe:*:Enabled:Aplicação de controle remoto TeamViewer] -> [2009/06/25 09:58:08 | 004,369,192 | ---- | M] (TeamViewer GmbH)

< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->

< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->

"AutoRun" -> 1 ->

"DisplayName" -> Driver de CD-ROM ->

"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found

< Drives with AutoRun files > -> ->

C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2008/01/04 01:11:32 | 000,000,000 | ---- | M] ()

C:\autorun.inf [] -> C:\autorun.inf [ NTFS ] -> [2010/03/23 15:57:20 | 000,000,000 | RHSD | M]

D:\autorun.inf [] -> D:\autorun.inf [ FAT32 ] -> [2010/03/23 15:57:22 | 000,000,000 | RHSD | M]

< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->

\{050c58ac-3c0b-11df-8065-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{050c58ac-3c0b-11df-8065-00016c066432}\Shell

\{050c58ac-3c0b-11df-8065-00016c066432}\Shell\\"" -> [AutoRun] -> File not found

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{050c58ac-3c0b-11df-8065-00016c066432}\Shell\AutoRun\command

\{050c58ac-3c0b-11df-8065-00016c066432}\Shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe -a] -> File not found

\{15ea0171-40e5-11df-807f-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{15ea0171-40e5-11df-807f-00016c066432}\Shell\AutoRun\command

\{15ea0171-40e5-11df-807f-00016c066432}\Shell\AutoRun\command\\"" -> E:\pozuda\malena.exe [E:\pozuda/malena.exe] -> File not found

\{15ea0171-40e5-11df-807f-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{15ea0171-40e5-11df-807f-00016c066432}\Shell\explore\command

\{15ea0171-40e5-11df-807f-00016c066432}\Shell\explore\command\\"" -> E:\pozuda\malena.exe [E:\pozuda/malena.exe] -> File not found

\{15ea0171-40e5-11df-807f-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{15ea0171-40e5-11df-807f-00016c066432}\Shell\open\command

\{15ea0171-40e5-11df-807f-00016c066432}\Shell\open\command\\"" -> E:\pozuda\malena.exe [E:\pozuda/malena.exe] -> File not found

\{1fc84806-3793-11df-805d-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1fc84806-3793-11df-805d-00016c066432}\Shell

\{1fc84806-3793-11df-805d-00016c066432}\Shell\\"" -> [AutoRun] -> File not found

\{1fc84807-3793-11df-805d-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1fc84807-3793-11df-805d-00016c066432}\Shell\AutoRun\command

\{1fc84807-3793-11df-805d-00016c066432}\Shell\AutoRun\command\\"" -> E:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\DrvGuard32.exe [E:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\DrvGuard32.exe] -> File not found

\{1fc84807-3793-11df-805d-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1fc84807-3793-11df-805d-00016c066432}\Shell\open\command

\{1fc84807-3793-11df-805d-00016c066432}\Shell\open\command\\"" -> E:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\DrvGuard32.exe [E:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\DrvGuard32.exe] -> File not found

\{222b8f48-7f9f-11de-8f70-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{222b8f48-7f9f-11de-8f70-00016c066432}\sHell\AutOPLay\command

\{222b8f48-7f9f-11de-8f70-00016c066432}\sHell\AutOPLay\command\\"" -> E:\lmpx.exe [E:\lmpx.exe] -> File not found

\{222b8f48-7f9f-11de-8f70-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{222b8f48-7f9f-11de-8f70-00016c066432}\sHell\AutoRun\command

\{222b8f48-7f9f-11de-8f70-00016c066432}\sHell\AutoRun\command\\"" -> E:\lmpx.exe [E:\lmpx.exe] -> File not found

\{222b8f48-7f9f-11de-8f70-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{222b8f48-7f9f-11de-8f70-00016c066432}\sHell\expLORe\COmMand

\{222b8f48-7f9f-11de-8f70-00016c066432}\sHell\expLORe\COmMand\\"" -> E:\lmpx.exe [E:\lmpx.exe] -> File not found

\{222b8f48-7f9f-11de-8f70-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{222b8f48-7f9f-11de-8f70-00016c066432}\sHell\opEn\command

\{222b8f48-7f9f-11de-8f70-00016c066432}\sHell\opEn\command\\"" -> E:\lmpx.exe [E:\lmpx.exe] -> File not found

\{3c93538f-4256-11df-8082-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3c93538f-4256-11df-8082-00016c066432}\Shell

\{3c93538f-4256-11df-8082-00016c066432}\Shell\\"" -> [AutoRun] -> File not found

\{3c935390-4256-11df-8082-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3c935390-4256-11df-8082-00016c066432}\Shell

\{3c935390-4256-11df-8082-00016c066432}\Shell\\"" -> [AutoRun] -> File not found

\{3c935391-4256-11df-8082-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3c935391-4256-11df-8082-00016c066432}\shell\Open(&0)\command

\{3c935391-4256-11df-8082-00016c066432}\shell\Open(&0)\command\\"" -> [windrive.exe] -> File not found

\{3e4e0d22-a83b-11de-8fcd-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3e4e0d22-a83b-11de-8fcd-00016c066432}\Shell

\{3e4e0d22-a83b-11de-8fcd-00016c066432}\Shell\\"" -> [AutoRun] -> File not found

\{54b4cebc-68a7-11de-8f1d-00016c0678f9}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b4cebc-68a7-11de-8f1d-00016c0678f9}\Shell\AutoRun\command

\{54b4cebc-68a7-11de-8f1d-00016c0678f9}\Shell\AutoRun\command\\"" -> E:\ws.exe [E:\ws.exe] -> File not found

\{54b4cebc-68a7-11de-8f1d-00016c0678f9}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54b4cebc-68a7-11de-8f1d-00016c0678f9}\Shell\open\Command

\{54b4cebc-68a7-11de-8f1d-00016c0678f9}\Shell\open\Command\\"" -> E:\ws.exe [E:\ws.exe] -> File not found

\{550a36ad-a129-11de-8fbd-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{550a36ad-a129-11de-8fbd-00016c066432}\Shell

\{550a36ad-a129-11de-8fbd-00016c066432}\Shell\\"" -> [AutoRun] -> File not found

\{5baea245-9ed0-11de-8fb9-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5baea245-9ed0-11de-8fb9-00016c066432}\SHELl\AutoRun\command

\{5baea245-9ed0-11de-8fb9-00016c066432}\SHELl\AutoRun\command\\"" -> E:\QMLLBp.Exe [E:\QMLLBp.Exe] -> File not found

\{5baea245-9ed0-11de-8fb9-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5baea245-9ed0-11de-8fb9-00016c066432}\SHELl\oPEN\ComManD

\{5baea245-9ed0-11de-8fb9-00016c066432}\SHELl\oPEN\ComManD\\"" -> E:\qMLLbp.exe [E:\qMLLbp.exe] -> File not found

\{95679f72-249b-11df-bffc-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{95679f72-249b-11df-bffc-00016c066432}\Shell

\{95679f72-249b-11df-bffc-00016c066432}\Shell\\"" -> [AutoRun] -> File not found

\{bf8b3d94-44b3-11df-8092-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf8b3d94-44b3-11df-8092-00016c066432}\Shell

\{bf8b3d94-44b3-11df-8092-00016c066432}\Shell\\"" -> [AutoRun] -> File not found

\{bf8b3d95-44b3-11df-8092-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bf8b3d95-44b3-11df-8092-00016c066432}\Shell

\{bf8b3d95-44b3-11df-8092-00016c066432}\Shell\\"" -> [AutoRun] -> File not found

\{cc6e0379-67fc-11de-8f1c-00016c0678f9}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cc6e0379-67fc-11de-8f1c-00016c0678f9}\Shell

\{cc6e0379-67fc-11de-8f1c-00016c0678f9}\Shell\\"" -> [AutoRun] -> File not found

\{e65b7be4-6bff-11de-8f23-00016c0678f9}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e65b7be4-6bff-11de-8f23-00016c0678f9}\Shell\AutoRun\command

\{e65b7be4-6bff-11de-8f23-00016c0678f9}\Shell\AutoRun\command\\"" -> [p.exe] -> File not found

\{e65b7be4-6bff-11de-8f23-00016c0678f9}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e65b7be4-6bff-11de-8f23-00016c0678f9}\Shell\open\Command

\{e65b7be4-6bff-11de-8f23-00016c0678f9}\Shell\open\Command\\"" -> [p.exe] -> File not found

\{e7e1644c-335d-11df-8034-00016c066432}

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e7e1644c-335d-11df-8034-00016c066432}\Shell

\{e7e1644c-335d-11df-8034-00016c066432}\Shell\\"" -> [AutoRun] -> File not found

< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->

comfile [open] -> "%1" %* ->

exefile [open] -> "%1" %* ->

< AppCertDlls [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls ->

< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->

.com [@ = ComFile] -> "%1" %* ->

.exe [@ = exefile] -> "%1" %* ->

 

[Registry - Additional Scans - Safe List]

< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->

.bat [@ = batfile] -> "%1" %* ->

.cmd [@ = cmdfile] -> "%1" %* ->

.com [@ = ComFile] -> "%1" %* ->

.exe [@ = exefile] -> "%1" %* ->

.pif [@ = piffile] -> "%1" %* ->

.scr [@ = scrfile] -> "%1" /S ->

< File Associations - Select to Repair > -> HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Classes\<extension>\ ->

.html [@ = htmlfile] -> Reg Error: Key error. -> File not found

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost > -> ->

*netsvcs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ->

6to4 -> -> File not found

Ias -> C:\WINDOWS\system32\ias -> [2008/01/04 01:11:00 | 000,000,000 | ---D | M]

Iprip -> -> File not found

Irmon -> -> File not found

NWCWorkstation -> -> File not found

Nwsapagent -> -> File not found

WmdmPmSp -> -> File not found

*MultiFile Done* -> ->

< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->

cdo:{CD00020A-8B95-11D1-82DB-00C04FB1625D} [HKLM] -> C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Folders\PKMCDO.DLL[Microsoft PKM KnowledgePluggable Class] -> [2001/01/22 03:25:24 | 000,872,448 | ---- | M] (Microsoft Corporation)

ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL[MSDAMON.BINDER] -> [2001/02/12 02:25:24 | 001,187,840 | ---- | M] (Microsoft Corporation)

linkscanner:{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} [HKLM] -> C:\Arquivos de programas\AVG\AVG9\avgpp.dll[XPLPPFilter Class] -> [2010/03/31 17:59:31 | 000,091,416 | ---- | M] (AVG Technologies CZ, s.r.o.)

msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL[MSDAMON.BINDER] -> [2001/02/12 02:25:24 | 001,187,840 | ---- | M] (Microsoft Corporation)

msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} [HKLM] -> C:\Arquivos de programas\Arquivos comuns\System\Ole DB\MSDAIPP.DLL[MSDAIPP.BINDER] -> [2001/02/12 02:25:24 | 001,187,840 | ---- | M] (Microsoft Corporation)

mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} [HKLM] -> C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Web Components\10\OWC10.DLL[Data Page Pluggable Protocol mso-offdap Handler] -> [2001/02/24 02:36:24 | 007,436,272 | ---- | M] (Microsoft Corporation)

< Security Center Settings > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center

\\"FirstRunDisabled" -> [1] -> File not found

\\"AntiVirusOverride" -> [0] -> File not found

\\"FirewallOverride" -> [0] -> File not found

\\"FirewallDisableNotify" -> [0] -> File not found

\\"AntiVirusDisableNotify" -> [0] -> File not found

\\"UpdatesDisableNotify" -> [1] -> File not found

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

\\"EnableFirewall" -> [1] -> File not found

\\"DoNotAllowExceptions" -> [0] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> ->

< Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->

{1185566F-12ED-3EF0-89CC-38866DCE1EEE} -> Microsoft .NET Framework 3.0 Client Service Pack 2

{205C6BDD-7B73-42DE-8505-9A093F35A238} -> Ferramenta de Carregamento do Windows Live

{22B775E7-6C42-4FC5-8E10-9A5E3257BD94} -> MSVCRT

{2695AE49-2FA7-3D48-BD77-23439E688F63} -> Microsoft .NET Framework 3.5 Client Profile - Language Pack (PTB)

{32BC546A-8AA3-4239-AE92-9CF3291C35A6} -> Windows Live Call

{350C9416-3D7C-4EE8-BAA9-00BCB3D54227} -> WebFldrs XP

{3B4E636E-9D65-4D67-BA61-189800823F52} -> Windows Live Communications Platform

{4A03706F-666A-4037-7777-5F2748764D10} -> Java Auto Updater

{51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48} -> Assistente de Conexão do Windows Live

{656C0E21-331E-11DF-81CE-005056806466} -> Google Earth

{80E0DA10-F4F6-34B3-8840-D5B5058DF8EF} -> Microsoft .NET Framework 2.0 Client Service Pack 2 - Language Pack (PTB)

{837b34e3-7c30-493c-8f6a-2b0f04e2912c} -> Microsoft Visual C++ 2005 Redistributable

{8B4AB829-DFD3-436D-B808-D9733D76C590} -> Macromedia Dreamweaver MX

{90280416-6000-11D3-8CFE-0050048383C9} -> Microsoft Office XP Professional com FrontPage

{923DED41-1143-11D4-B133-0000B434DE24} -> Simulado

{95120000-00B9-0409-0000-0000000FF1CE} -> Microsoft Application Error Reporting

{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7} -> Segoe UI

{A5BA14E0-7384-11D4-BAE7-00409631A2C8} -> Macromedia Extension Manager

{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} -> Google Update Helper

{AC76BA86-7AD7-1046-7B44-A93000000001} -> Adobe Reader 9.3.1 - Português

{B5ED7AB0-3838-4389-8549-7C8E22DD48F4} -> Windows Live Messenger

{BCF2CEFB-E23D-42EF-A5FA-F9ED2A085821}_is1 -> CoolSMS 2.05 beta

{C645AAA5-DA3D-3CDB-82BA-ABC1D078676A} -> Microsoft .NET Framework 3.0 Client Profile - Language Pack (PTB)

{CAAFB8F9-F8D1-3D27-9AAA-6301A4429440} -> Microsoft .NET Framework 2.0 Client Service Pack 2

{CC0E1AE3-091D-4969-B151-7AC142062C28} -> SmartWebPrinting

{D617A4DC-C915-3F25-BE43-57E5FD99B441} -> Microsoft .NET Framework 3.5 Client Service Pack 1

{DC226AC9-0314-496C-BE6A-B6A132628466} -> SiSAGP driver

{E2883E8F-472F-4fb0-9522-AC9BF37916A7} -> Adobe Download Manager

{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A} -> Samsung PC Studio 3 USB Driver Installer

{F0E12BBA-AD66-4022-A453-A1C8A0C4D570} -> Microsoft Choice Guard

{F2CD4651-F948-467C-B014-71FD981B7F59} -> Windows Live Essentials

{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB} -> 32 Bit HP CIO Components Installer

{FB08F381-6533-4108-B7DD-039E11FBC27E} -> Realtek AC'97 Audio

6194C28A8F62DD817EA1B918E6E46E806A21B452 -> Pacote de Driver do Windows - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)

65B6FE5418CE28F4D72543FB2D964C3CEC83F161 -> Pacote de Driver do Windows - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)

Adobe Flash Player ActiveX -> Adobe Flash Player 10 ActiveX

Adobe Flash Player Plugin -> Adobe Flash Player 10 Plugin

AVG9Uninstall -> AVG Free 9.0

CCleaner -> CCleaner

ClamWin Free Antivirus_is1 -> ClamWin Free Antivirus 0.95.3

EasyCafe Server 2.2 (Firewall Edition) -> EasyCafe Server 2.2 (Firewall Edition)

HijackThis -> HijackThis 2.0.2

IDNMitigationAPIs -> Microsoft Internationalized Domain Names Mitigation APIs

ie7 -> Windows Internet Explorer 7

ie8 -> Windows Internet Explorer 8

Malwarebytes' Anti-Malware_is1 -> Malwarebytes' Anti-Malware

Microsoft.Net.Client.3.5 -> Microsoft .NET Framework Client Profile

Microsoft.Net.Client.3.5.LangPack.ptb -> Pacote de Idiomas do Microsoft .NET Framework Client Profile - PTB

Mozilla Firefox (3.6.3) -> Mozilla Firefox (3.6.3)

NLSDownlevelMapping -> Microsoft National Language Support Downlevel APIs

Revo Uninstaller -> Revo Uninstaller 1.85

SAMSUNG Mobile Composite Device -> SAMSUNG Mobile Composite Device Software

SAMSUNG Mobile Modem -> SAMSUNG Mobile Modem Driver Set

Samsung Mobile phone USB driver -> Samsung Mobile phone USB driver Software

SAMSUNG Mobile USB Modem -> SAMSUNG Mobile USB Modem Software

SAMSUNG Mobile USB Modem 1.0 -> SAMSUNG Mobile USB Modem 1.0 Software

SiS VGA Driver -> SiS VGA Utilities

Windows Media Format Runtime -> Windows Media Format 11 runtime

Windows Media Player -> Windows Media Player 11

Windows XP Service Pack -> Windows XP Service Pack 3

WinLiveSuite_Wave3 -> Windows Live Essentials

WinRAR archiver -> Compressor WinRAR

WMFDist11 -> Windows Media Format 11 runtime

wmp11 -> Windows Media Player 11

Wudf01000 -> Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348)

< Uninstall List [HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\] > -> HKEY_USERS\S-1-5-21-1547161642-789336058-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->

Google Chrome -> Google Chrome

< EventViewer Logs - Last 10 Errors > -> Event Information -> Description

Application [ Error ] 05/04/2010 07:31:14 Computer Name = SERVIDOR400 | Source = Google Update | ID = 20 -> Description =

Application [ Error ] 08/04/2010 13:37:21 Computer Name = SERVIDOR400 | Source = MsiInstaller | ID = 11904 -> Description = Produto: SolutionCenter -- Error 1904. Módulo C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx falhou ao registrar. HRESULT -2147220473. Entre em contato com a equipe de suporte.

Application [ Error ] 09/04/2010 03:57:14 Computer Name = SERVIDOR400 | Source = Google Update | ID = 20 -> Description =

Application [ Error ] 09/04/2010 04:11:14 Computer Name = SERVIDOR400 | Source = Google Update | ID = 20 -> Description =

Application [ Error ] 09/04/2010 04:57:14 Computer Name = SERVIDOR400 | Source = Google Update | ID = 20 -> Description =

Application [ Error ] 09/04/2010 05:11:14 Computer Name = SERVIDOR400 | Source = Google Update | ID = 20 -> Description =

Application [ Error ] 09/04/2010 05:57:14 Computer Name = SERVIDOR400 | Source = Google Update | ID = 20 -> Description =

Application [ Error ] 09/04/2010 06:11:14 Computer Name = SERVIDOR400 | Source = Google Update | ID = 20 -> Description =

Application [ Error ] 09/04/2010 06:57:14 Computer Name = SERVIDOR400 | Source = Google Update | ID = 20 -> Description =

Application [ Error ] 09/04/2010 10:32:14 Computer Name = SERVIDOR400 | Source = MsiInstaller | ID = 11705 -> Description = Produto: HP Update -- Erro 1705. Uma instalação anterior deste produto está em andamento. Você deve desfazer as alterações feitas por essa instalação para continuar. Deseja desfazer essas alterações?

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

 

[Files/Folders - Created Within 30 Days]

OTS.exe -> C:\Documents and Settings\B&J Cyber\Desktop\OTS.exe -> [2010/04/11 22:38:49 | 000,638,464 | ---- | C] (OldTimer Tools)

NOS -> C:\Documents and Settings\All Users\Dados de aplicativos\NOS -> [2010/04/11 20:23:17 | 000,000,000 | ---D | C]

NOS -> C:\Arquivos de programas\NOS -> [2010/04/11 20:23:17 | 000,000,000 | ---D | C]

OTM.exe -> C:\Documents and Settings\B&J Cyber\Desktop\OTM.exe -> [2010/04/11 18:38:19 | 000,510,464 | ---- | C] (OldTimer Tools)

ToolBar SD -> C:\ToolBar SD -> [2010/04/09 22:44:50 | 000,000,000 | ---D | C]

GenProc -> C:\GenProc -> [2010/04/09 11:42:27 | 000,000,000 | ---D | C]

TuneUp Software -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\TuneUp Software -> [2010/04/08 22:56:15 | 000,000,000 | ---D | C]

TuneUp Software -> C:\Documents and Settings\All Users\Dados de aplicativos\TuneUp Software -> [2010/04/08 22:55:47 | 000,000,000 | ---D | C]

{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} -> C:\Documents and Settings\All Users\Dados de aplicativos\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} -> [2010/04/08 18:28:38 | 000,000,000 | -HSD | C]

Recent -> C:\Documents and Settings\B&J Cyber\Recent -> [2010/04/08 17:00:21 | 000,000,000 | RH-D | C]

$AVG -> C:\$AVG -> [2010/04/03 14:49:33 | 000,000,000 | -H-D | C]

VSRevoGroup -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\VSRevoGroup -> [2010/03/31 19:00:24 | 000,000,000 | ---D | C]

avgrsstx.dll -> C:\WINDOWS\System32\avgrsstx.dll -> [2010/03/31 17:59:33 | 000,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.)

avgtdix.sys -> C:\WINDOWS\System32\drivers\avgtdix.sys -> [2010/03/31 16:58:53 | 000,242,696 | ---- | C] (AVG Technologies CZ, s.r.o.)

avgldx86.sys -> C:\WINDOWS\System32\drivers\avgldx86.sys -> [2010/03/31 16:58:46 | 000,216,200 | ---- | C] (AVG Technologies CZ, s.r.o.)

avgmfx86.sys -> C:\WINDOWS\System32\drivers\avgmfx86.sys -> [2010/03/31 16:58:45 | 000,029,512 | ---- | C] (AVG Technologies CZ, s.r.o.)

Avg -> C:\WINDOWS\System32\drivers\Avg -> [2010/03/31 16:58:39 | 000,000,000 | ---D | C]

avg9 -> C:\Documents and Settings\All Users\Dados de aplicativos\avg9 -> [2010/03/31 16:58:21 | 000,000,000 | ---D | C]

Microsoft -> C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft -> [2010/03/31 16:56:43 | 000,000,000 | ---D | M]

Microsoft -> C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft -> [2010/03/31 16:56:43 | 000,000,000 | ---D | M]

Microsoft -> C:\Documents and Settings\NetworkService\Dados de aplicativos\Microsoft -> [2010/03/31 16:56:42 | 000,000,000 | --SD | M]

Microsoft -> C:\Documents and Settings\LocalService\Dados de aplicativos\Microsoft -> [2010/03/31 16:56:42 | 000,000,000 | --SD | M]

.clamwin -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\.clamwin -> [2010/03/30 21:20:54 | 000,000,000 | ---D | C]

ClamWin -> C:\Arquivos de programas\ClamWin -> [2010/03/30 21:20:41 | 000,000,000 | ---D | C]

.clamwin -> C:\Documents and Settings\All Users\.clamwin -> [2010/03/30 21:20:41 | 000,000,000 | ---D | C]

FOTOS DA MAQ MEIRE - FAVOR NÃO APAGAR SEM FAZER COPIA -> C:\Documents and Settings\B&J Cyber\Meus documentos\FOTOS DA MAQ MEIRE - FAVOR NÃO APAGAR SEM FAZER COPIA -> [2010/03/28 14:12:54 | 000,000,000 | ---D | C]

Java -> C:\Arquivos de programas\Arquivos comuns\Java -> [2010/03/26 13:03:30 | 000,000,000 | ---D | C]

ESET -> C:\Arquivos de programas\ESET -> [2010/03/26 06:59:44 | 000,000,000 | ---D | C]

FineRecovery -> C:\Arquivos de programas\FineRecovery -> [2010/03/24 12:46:54 | 000,000,000 | ---D | C]

autorun.inf -> C:\autorun.inf -> [2010/03/23 15:57:20 | 000,000,000 | RHSD | C]

UsbFix -> C:\UsbFix -> [2010/03/23 15:41:35 | 000,000,000 | ---D | C]

RECYCLER -> C:\RECYCLER -> [2010/03/22 22:37:22 | 000,000,000 | -HSD | C]

temp -> C:\WINDOWS\temp -> [2010/03/22 22:05:08 | 000,000,000 | ---D | C]

SafeBootKeyRepair.exe -> C:\SafeBootKeyRepair.exe -> [2010/03/22 08:20:03 | 000,288,654 | ---- | C] ( )

crime organizado -> C:\Documents and Settings\B&J Cyber\Meus documentos\crime organizado -> [2010/03/21 15:32:37 | 000,000,000 | ---D | C]

Sun -> C:\Documents and Settings\All Users\Dados de aplicativos\Sun -> [2010/03/20 21:11:41 | 000,000,000 | ---D | C]

cmdcons -> C:\cmdcons -> [2010/03/19 22:33:17 | 000,000,000 | RHSD | C]

ERDNT -> C:\WINDOWS\ERDNT -> [2010/03/19 22:27:09 | 000,000,000 | ---D | C]

IObit -> C:\Arquivos de programas\IObit -> [2010/03/19 20:17:32 | 000,000,000 | ---D | C]

Program Files -> C:\Program Files -> [2010/03/18 13:04:43 | 000,000,000 | ---D | C]

Diversos -> C:\Documents and Settings\B&J Cyber\Meus documentos\Diversos -> [2010/03/18 10:53:01 | 000,000,000 | ---D | C]

Trabalhos Universidade BJ -> C:\Documents and Settings\B&J Cyber\Meus documentos\Trabalhos Universidade BJ -> [2010/03/18 10:04:37 | 000,000,000 | ---D | C]

Declarações -> C:\Documents and Settings\B&J Cyber\Meus documentos\Declarações -> [2010/03/18 09:52:15 | 000,000,000 | ---D | C]

WinRAR -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\WinRAR -> [2010/03/17 17:34:33 | 000,000,000 | ---D | C]

VS Revo Group -> C:\Arquivos de programas\VS Revo Group -> [2010/03/16 19:55:00 | 000,000,000 | ---D | C]

HPAppData -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\HPAppData -> [2010/03/16 17:17:10 | 000,000,000 | ---D | C]

ie8updates -> C:\WINDOWS\ie8updates -> [2010/03/15 22:12:48 | 000,000,000 | ---D | C]

ie8 -> C:\WINDOWS\ie8 -> [2010/03/15 22:10:11 | 000,000,000 | -H-D | C]

Hagel Technologies -> C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Hagel Technologies -> [2010/01/12 20:37:09 | 000,000,000 | ---D | M]

Google -> C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Google -> [2009/09/08 11:39:04 | 000,000,000 | ---D | M]

Google -> C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Google -> [2009/09/08 11:24:28 | 000,000,000 | ---D | M]

TeamViewer -> C:\Documents and Settings\LocalService\Dados de aplicativos\TeamViewer -> [2009/07/02 09:47:13 | 000,000,000 | ---D | M]

Adobe -> C:\Documents and Settings\LocalService\Dados de aplicativos\Adobe -> [2009/05/13 12:22:52 | 000,000,000 | ---D | M]

implode.dll -> C:\WINDOWS\System32\implode.dll -> [2008/01/05 11:23:13 | 000,018,944 | ---- | C] ( )

 

[Files/Folders - Modified Within 30 Days]

OTS.exe -> C:\Documents and Settings\B&J Cyber\Desktop\OTS.exe -> [2010/04/11 22:38:49 | 000,638,464 | ---- | M] (OldTimer Tools)

PDOXUSRS.NET -> C:\PDOXUSRS.NET -> [2010/04/11 22:25:17 | 000,013,030 | ---- | M] ()

GoogleUpdateTaskUserS-1-5-21-1547161642-789336058-725345543-1003UA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-789336058-725345543-1003UA.job -> [2010/04/11 22:08:00 | 000,001,160 | ---- | M] ()

GoogleUpdateTaskMachineUA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job -> [2010/04/11 21:54:00 | 000,001,048 | ---- | M] ()

User_Feed_Synchronization-{D80D9FDE-CA24-47BA-A6A5-278907BFFD93}.job -> C:\WINDOWS\tasks\User_Feed_Synchronization-{D80D9FDE-CA24-47BA-A6A5-278907BFFD93}.job -> [2010/04/11 19:06:19 | 000,000,462 | -H-- | M] ()

GoogleUpdateTaskMachineCore.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job -> [2010/04/11 18:54:08 | 000,001,044 | ---- | M] ()

SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2010/04/11 18:53:47 | 000,000,006 | -H-- | M] ()

bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2010/04/11 18:53:45 | 000,002,048 | --S- | M] ()

ntuser.dat -> C:\Documents and Settings\B&J Cyber\ntuser.dat -> [2010/04/11 18:52:50 | 008,650,752 | ---- | M] ()

ntuser.ini -> C:\Documents and Settings\B&J Cyber\ntuser.ini -> [2010/04/11 18:52:50 | 000,000,330 | -HS- | M] ()

IconCache.db -> C:\Documents and Settings\B&J Cyber\Configurações locais\Dados de aplicativos\IconCache.db -> [2010/04/11 18:52:45 | 003,768,788 | -H-- | M] ()

OTM.exe -> C:\Documents and Settings\B&J Cyber\Desktop\OTM.exe -> [2010/04/11 18:38:19 | 000,510,464 | ---- | M] (OldTimer Tools)

incavi.avm -> C:\WINDOWS\System32\drivers\Avg\incavi.avm -> [2010/04/11 17:55:55 | 058,823,525 | ---- | M] ()

GoogleUpdateTaskUserS-1-5-21-1547161642-789336058-725345543-1003Core.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-789336058-725345543-1003Core.job -> [2010/04/11 14:08:00 | 000,001,108 | ---- | M] ()

wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2010/04/11 13:17:06 | 000,002,206 | ---- | M] ()

P029-05.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\P029-05.doc -> [2010/04/10 13:37:04 | 000,103,936 | ---- | M] ()

ToolBarSD.exe -> C:\Documents and Settings\B&J Cyber\Desktop\ToolBarSD.exe -> [2010/04/09 22:38:22 | 000,343,020 | ---- | M] ()

Globocop sobrevoa Rio das Pedras (RJ) - Globo Vídeos Player.url -> C:\Documents and Settings\B&J Cyber\Desktop\Globocop sobrevoa Rio das Pedras (RJ) - Globo Vídeos Player.url -> [2010/04/09 22:04:46 | 000,000,298 | ---- | M] ()

Rapport - GenProc[1].URL -> C:\Documents and Settings\B&J Cyber\Desktop\Rapport - GenProc[1].URL -> [2010/04/09 11:44:16 | 000,000,132 | ---- | M] ()

Raccourci - GenProc.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Raccourci - GenProc.lnk -> [2010/04/09 11:42:50 | 000,001,372 | ---- | M] ()

Ÿ9Ÿ9 -> C:\Documents and Settings\B&J Cyber\Ÿ9Ÿ9 -> [2010/04/09 08:56:34 | 000,000,000 | ---- | M] ()

cc_20100408_170105.reg -> C:\Documents and Settings\B&J Cyber\Meus documentos\cc_20100408_170105.reg -> [2010/04/08 17:01:10 | 000,000,314 | ---- | M] ()

win.ini -> C:\WINDOWS\win.ini -> [2010/04/08 16:48:16 | 000,000,784 | ---- | M] ()

wininit.ini -> C:\WINDOWS\wininit.ini -> [2010/04/08 16:03:53 | 000,000,051 | ---- | M] ()

hpoins28.dat.temp -> C:\WINDOWS\hpoins28.dat.temp -> [2010/04/08 16:03:46 | 000,176,236 | ---- | M] ()

FLEXFORM.url -> C:\Documents and Settings\B&J Cyber\Desktop\FLEXFORM.url -> [2010/04/08 12:10:37 | 000,000,139 | ---- | M] ()

Adobe Reader 9.lnk -> C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk -> [2010/04/08 11:14:49 | 000,001,779 | ---- | M] ()

Número do Benefício.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Número do Benefício.doc -> [2010/04/08 10:38:05 | 000,051,712 | ---- | M] ()

Radio Vanderlirio.url -> C:\Documents and Settings\B&J Cyber\Desktop\Radio Vanderlirio.url -> [2010/04/07 18:04:44 | 000,000,121 | ---- | M] ()

Tabela de vitaminas.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Tabela de vitaminas.doc -> [2010/04/05 21:14:28 | 000,043,008 | ---- | M] ()

Google Chrome.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Google Chrome.lnk -> [2010/04/05 14:44:51 | 000,002,416 | ---- | M] ()

Google Earth.lnk -> C:\Documents and Settings\All Users\Desktop\Google Earth.lnk -> [2010/04/05 12:34:25 | 000,001,981 | ---- | M] ()

Dance.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Dance.doc -> [2010/04/04 21:26:09 | 000,090,624 | ---- | M] ()

Germânio.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Germânio.doc -> [2010/04/04 17:55:01 | 000,021,504 | ---- | M] ()

apostila-manual-adobe-photoshop-cs3.rar -> C:\Documents and Settings\B&J Cyber\Meus documentos\apostila-manual-adobe-photoshop-cs3.rar -> [2010/04/03 15:32:19 | 000,007,647 | ---- | M] ()

TUTO PHOTOSHOP.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\TUTO PHOTOSHOP.doc -> [2010/04/03 14:10:38 | 000,038,912 | ---- | M] ()

anexos_03_04_2010.zip -> C:\Documents and Settings\B&J Cyber\Meus documentos\anexos_03_04_2010.zip -> [2010/04/03 10:41:25 | 000,446,493 | ---- | M] ()

Aula Talentos Humanos_Desempenho.ppt -> C:\Documents and Settings\B&J Cyber\Meus documentos\Aula Talentos Humanos_Desempenho.ppt -> [2010/04/03 10:40:44 | 000,220,672 | ---- | M] ()

Radio Casa.url -> C:\Documents and Settings\B&J Cyber\Desktop\Radio Casa.url -> [2010/04/02 16:27:25 | 000,000,174 | ---- | M] ()

cc_20100331_234438.reg -> C:\Documents and Settings\B&J Cyber\Meus documentos\cc_20100331_234438.reg -> [2010/03/31 23:44:54 | 000,010,594 | ---- | M] ()

Adelita.xls -> C:\Documents and Settings\B&J Cyber\Meus documentos\Adelita.xls -> [2010/03/31 21:02:07 | 000,021,504 | ---- | M] ()

avgtdix.sys -> C:\WINDOWS\System32\drivers\avgtdix.sys -> [2010/03/31 17:59:35 | 000,242,696 | ---- | M] (AVG Technologies CZ, s.r.o.)

avgmfx86.sys -> C:\WINDOWS\System32\drivers\avgmfx86.sys -> [2010/03/31 17:59:33 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.)

avgrsstx.dll -> C:\WINDOWS\System32\avgrsstx.dll -> [2010/03/31 17:59:33 | 000,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.)

avgldx86.sys -> C:\WINDOWS\System32\drivers\avgldx86.sys -> [2010/03/31 17:59:24 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.)

microavi.avg -> C:\WINDOWS\System32\drivers\Avg\microavi.avg -> [2010/03/31 17:24:23 | 000,142,495 | ---- | M] ()

AVG Free 9.0.lnk -> C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk -> [2010/03/31 16:58:55 | 000,001,573 | ---- | M] ()

iavichjw.avm -> C:\WINDOWS\System32\drivers\Avg\iavichjw.avm -> [2010/03/31 16:58:45 | 000,113,461 | ---- | M] ()

avi7.avg -> C:\WINDOWS\System32\drivers\Avg\avi7.avg -> [2010/03/31 16:58:39 | 006,061,540 | ---- | M] ()

miniavi.avg -> C:\WINDOWS\System32\drivers\Avg\miniavi.avg -> [2010/03/31 16:58:39 | 000,492,629 | ---- | M] ()

cc_20100331_163158.reg -> C:\Documents and Settings\B&J Cyber\Meus documentos\cc_20100331_163158.reg -> [2010/03/31 16:32:08 | 000,010,814 | ---- | M] ()

ClamWin Antivirus.lnk -> C:\Documents and Settings\All Users\Desktop\ClamWin Antivirus.lnk -> [2010/03/30 21:20:51 | 000,000,836 | ---- | M] ()

mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2010/03/30 00:46:30 | 000,038,224 | ---- | M] (Malwarebytes Corporation)

mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2010/03/30 00:45:52 | 000,020,824 | ---- | M] (Malwarebytes Corporation)

Resultado susam 2010.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Resultado susam 2010.doc -> [2010/03/29 14:30:03 | 000,236,544 | ---- | M] ()

DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\B&J Cyber\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2010/03/28 15:03:22 | 000,005,120 | ---- | M] ()

Microsoft Excel.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Microsoft Excel.lnk -> [2010/03/27 15:13:41 | 000,002,507 | ---- | M] ()

marilena.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\marilena.doc -> [2010/03/27 12:00:17 | 000,020,480 | ---- | M] ()

Microsoft Word.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Microsoft Word.lnk -> [2010/03/27 11:34:04 | 000,002,545 | ---- | M] ()

A-Virus encontrado.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\A-Virus encontrado.doc -> [2010/03/26 15:30:22 | 000,020,480 | ---- | M] ()

GDIPFONTCACHEV1.DAT -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\GDIPFONTCACHEV1.DAT -> [2010/03/24 20:58:40 | 000,021,408 | ---- | M] ()

MercadoLivre Brasil.url -> C:\Documents and Settings\B&J Cyber\Desktop\MercadoLivre Brasil.url -> [2010/03/24 20:29:57 | 000,000,390 | ---- | M] ()

GDIPFONTCACHEV1.DAT -> C:\Documents and Settings\B&J Cyber\Configurações locais\Dados de aplicativos\GDIPFONTCACHEV1.DAT -> [2010/03/24 17:12:59 | 000,021,408 | ---- | M] ()

Radio Alessandro.url -> C:\Documents and Settings\B&J Cyber\Desktop\Radio Alessandro.url -> [2010/03/24 17:12:43 | 000,000,121 | ---- | M] ()

FNTCACHE.DAT -> C:\WINDOWS\System32\FNTCACHE.DAT -> [2010/03/24 16:59:34 | 000,124,520 | ---- | M] ()

Familia Trapo.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Familia Trapo.doc -> [2010/03/24 12:33:08 | 002,351,104 | ---- | M] ()

cc_20100324_122455.reg -> C:\Documents and Settings\B&J Cyber\Meus documentos\cc_20100324_122455.reg -> [2010/03/24 12:25:04 | 000,006,182 | ---- | M] ()

PlaxMetal - Soluções em Plástico e Metal.url -> C:\Documents and Settings\B&J Cyber\Desktop\PlaxMetal - Soluções em Plástico e Metal.url -> [2010/03/23 20:59:26 | 000,000,202 | ---- | M] ()

system.ini -> C:\WINDOWS\system.ini -> [2010/03/22 22:03:23 | 000,000,379 | ---- | M] ()

o fazendeiro, o compadre e o burro.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\o fazendeiro, o compadre e o burro.doc -> [2010/03/22 14:55:46 | 000,020,992 | ---- | M] ()

CONDUÇÃO ESCOLAR.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\CONDUÇÃO ESCOLAR.doc -> [2010/03/22 12:51:44 | 000,019,968 | ---- | M] ()

Rastreamento-T&T Correios.url -> C:\Documents and Settings\B&J Cyber\Desktop\Rastreamento-T&T Correios.url -> [2010/03/22 11:21:07 | 000,000,309 | ---- | M] ()

hosts.msn -> C:\WINDOWS\System32\drivers\etc\hosts.msn -> [2010/03/22 08:35:07 | 000,000,027 | ---- | M] ()

hosts -> C:\WINDOWS\System32\drivers\etc\hosts -> [2010/03/22 08:35:07 | 000,000,027 | ---- | M] ()

SafeBootKeyRepair.exe -> C:\SafeBootKeyRepair.exe -> [2010/03/22 08:12:46 | 000,288,654 | ---- | M] ( )

Microsoft PowerPoint.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Microsoft PowerPoint.lnk -> [2010/03/21 15:57:29 | 000,002,525 | ---- | M] ()

escala de enfermagem.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\escala de enfermagem.doc -> [2010/03/21 14:38:48 | 000,048,128 | ---- | M] ()

CCleaner.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\CCleaner.lnk -> [2010/03/19 23:34:52 | 000,001,630 | ---- | M] ()

boot.ini -> C:\boot.ini -> [2010/03/19 22:33:21 | 000,000,281 | RHS- | M] ()

Atalho para ComboFix.exe.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Atalho para ComboFix.exe.lnk -> [2010/03/19 22:14:34 | 000,000,527 | ---- | M] ()

Simulado.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Simulado.lnk -> [2010/03/19 20:07:08 | 000,001,768 | ---- | M] ()

Revo Remove.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Revo Remove.lnk -> [2010/03/19 20:05:18 | 000,001,011 | ---- | M] ()

Navegadores dando erro e travando - iMasters Fóruns.url -> C:\Documents and Settings\B&J Cyber\Desktop\Navegadores dando erro e travando - iMasters Fóruns.url -> [2010/03/19 19:32:13 | 000,000,354 | ---- | M] ()

Malwarebytes.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Malwarebytes.lnk -> [2010/03/19 17:51:32 | 000,000,850 | ---- | M] ()

Easy Café Server.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Easy Café Server.lnk -> [2010/03/18 21:29:32 | 000,000,793 | ---- | M] ()

HijackThis.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\HijackThis.lnk -> [2010/03/18 13:04:45 | 000,001,728 | ---- | M] ()

Controle De Entrada.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Controle De Entrada.lnk -> [2010/03/18 11:38:24 | 000,000,318 | ---- | M] ()

photorec.cfg -> C:\Documents and Settings\B&J Cyber\photorec.cfg -> [2010/03/16 22:17:09 | 000,001,972 | ---- | M] ()

Ÿ9Ÿ9 -> C:\WINDOWS\System32\Ÿ9Ÿ9 -> [2010/03/15 10:42:42 | 000,000,000 | ---- | M] ()

 

[Files - No Company Name]

P029-05.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\P029-05.doc -> [2010/04/10 13:37:03 | 000,103,936 | ---- | C] ()

ToolBarSD.exe -> C:\Documents and Settings\B&J Cyber\Desktop\ToolBarSD.exe -> [2010/04/09 22:38:19 | 000,343,020 | ---- | C] ()

Globocop sobrevoa Rio das Pedras (RJ) - Globo Vídeos Player.url -> C:\Documents and Settings\B&J Cyber\Desktop\Globocop sobrevoa Rio das Pedras (RJ) - Globo Vídeos Player.url -> [2010/04/09 22:04:44 | 000,000,298 | ---- | C] ()

Rapport - GenProc[1].URL -> C:\Documents and Settings\B&J Cyber\Desktop\Rapport - GenProc[1].URL -> [2010/04/09 11:44:16 | 000,000,132 | ---- | C] ()

Raccourci - GenProc.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Raccourci - GenProc.lnk -> [2010/04/09 11:42:49 | 000,001,372 | ---- | C] ()

cc_20100408_170105.reg -> C:\Documents and Settings\B&J Cyber\Meus documentos\cc_20100408_170105.reg -> [2010/04/08 17:01:08 | 000,000,314 | ---- | C] ()

FLEXFORM.url -> C:\Documents and Settings\B&J Cyber\Desktop\FLEXFORM.url -> [2010/04/08 12:10:37 | 000,000,139 | ---- | C] ()

Número do Benefício.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Número do Benefício.doc -> [2010/04/08 10:38:04 | 000,051,712 | ---- | C] ()

Radio Vanderlirio.url -> C:\Documents and Settings\B&J Cyber\Desktop\Radio Vanderlirio.url -> [2010/04/07 18:04:44 | 000,000,121 | ---- | C] ()

Tabela de vitaminas.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Tabela de vitaminas.doc -> [2010/04/05 21:14:27 | 000,043,008 | ---- | C] ()

Google Chrome.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Google Chrome.lnk -> [2010/04/05 14:44:51 | 000,002,416 | ---- | C] ()

GoogleUpdateTaskUserS-1-5-21-1547161642-789336058-725345543-1003UA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-789336058-725345543-1003UA.job -> [2010/04/05 14:03:34 | 000,001,160 | ---- | C] ()

GoogleUpdateTaskUserS-1-5-21-1547161642-789336058-725345543-1003Core.job -> C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-789336058-725345543-1003Core.job -> [2010/04/05 14:03:34 | 000,001,108 | ---- | C] ()

GoogleUpdateTaskMachineUA.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job -> [2010/04/05 12:49:29 | 000,001,048 | ---- | C] ()

GoogleUpdateTaskMachineCore.job -> C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job -> [2010/04/05 12:49:29 | 000,001,044 | ---- | C] ()

Google Earth.lnk -> C:\Documents and Settings\All Users\Desktop\Google Earth.lnk -> [2010/04/05 12:34:25 | 000,001,981 | ---- | C] ()

Dance.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Dance.doc -> [2010/04/04 21:26:09 | 000,090,624 | ---- | C] ()

Germânio.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Germânio.doc -> [2010/04/04 17:55:01 | 000,021,504 | ---- | C] ()

apostila-manual-adobe-photoshop-cs3.rar -> C:\Documents and Settings\B&J Cyber\Meus documentos\apostila-manual-adobe-photoshop-cs3.rar -> [2010/04/03 15:19:12 | 000,007,647 | ---- | C] ()

TUTO PHOTOSHOP.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\TUTO PHOTOSHOP.doc -> [2010/04/03 14:10:38 | 000,038,912 | ---- | C] ()

anexos_03_04_2010.zip -> C:\Documents and Settings\B&J Cyber\Meus documentos\anexos_03_04_2010.zip -> [2010/04/03 10:41:07 | 000,446,493 | ---- | C] ()

Aula Talentos Humanos_Desempenho.ppt -> C:\Documents and Settings\B&J Cyber\Meus documentos\Aula Talentos Humanos_Desempenho.ppt -> [2010/04/03 10:40:03 | 000,220,672 | ---- | C] ()

cc_20100331_234438.reg -> C:\Documents and Settings\B&J Cyber\Meus documentos\cc_20100331_234438.reg -> [2010/03/31 23:44:42 | 000,010,594 | ---- | C] ()

AVG Free 9.0.lnk -> C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk -> [2010/03/31 16:58:55 | 000,001,573 | ---- | C] ()

iavichjw.avm -> C:\WINDOWS\System32\drivers\Avg\iavichjw.avm -> [2010/03/31 16:58:45 | 000,113,461 | ---- | C] ()

incavi.avm -> C:\WINDOWS\System32\drivers\Avg\incavi.avm -> [2010/03/31 16:58:39 | 058,823,525 | ---- | C] ()

avi7.avg -> C:\WINDOWS\System32\drivers\Avg\avi7.avg -> [2010/03/31 16:58:39 | 006,061,540 | ---- | C] ()

miniavi.avg -> C:\WINDOWS\System32\drivers\Avg\miniavi.avg -> [2010/03/31 16:58:39 | 000,492,629 | ---- | C] ()

microavi.avg -> C:\WINDOWS\System32\drivers\Avg\microavi.avg -> [2010/03/31 16:58:39 | 000,142,495 | ---- | C] ()

Adobe Reader 9.lnk -> C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk -> [2010/03/31 16:46:22 | 000,001,779 | ---- | C] ()

cc_20100331_163158.reg -> C:\Documents and Settings\B&J Cyber\Meus documentos\cc_20100331_163158.reg -> [2010/03/31 16:32:04 | 000,010,814 | ---- | C] ()

Adelita.xls -> C:\Documents and Settings\B&J Cyber\Meus documentos\Adelita.xls -> [2010/03/31 15:14:59 | 000,021,504 | ---- | C] ()

ClamWin Antivirus.lnk -> C:\Documents and Settings\All Users\Desktop\ClamWin Antivirus.lnk -> [2010/03/30 21:20:51 | 000,000,836 | ---- | C] ()

Resultado susam 2010.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Resultado susam 2010.doc -> [2010/03/29 14:30:02 | 000,236,544 | ---- | C] ()

DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\B&J Cyber\Configurações locais\Dados de aplicativos\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2010/03/28 14:08:20 | 000,005,120 | ---- | C] ()

marilena.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\marilena.doc -> [2010/03/27 12:00:17 | 000,020,480 | ---- | C] ()

Radio Casa.url -> C:\Documents and Settings\B&J Cyber\Desktop\Radio Casa.url -> [2010/03/26 21:49:18 | 000,000,174 | ---- | C] ()

A-Virus encontrado.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\A-Virus encontrado.doc -> [2010/03/26 15:30:21 | 000,020,480 | ---- | C] ()

MercadoLivre Brasil.url -> C:\Documents and Settings\B&J Cyber\Desktop\MercadoLivre Brasil.url -> [2010/03/24 20:29:57 | 000,000,390 | ---- | C] ()

Radio Alessandro.url -> C:\Documents and Settings\B&J Cyber\Desktop\Radio Alessandro.url -> [2010/03/24 17:12:43 | 000,000,121 | ---- | C] ()

Familia Trapo.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\Familia Trapo.doc -> [2010/03/24 12:33:08 | 002,351,104 | ---- | C] ()

cc_20100324_122455.reg -> C:\Documents and Settings\B&J Cyber\Meus documentos\cc_20100324_122455.reg -> [2010/03/24 12:24:58 | 000,006,182 | ---- | C] ()

PlaxMetal - Soluções em Plástico e Metal.url -> C:\Documents and Settings\B&J Cyber\Desktop\PlaxMetal - Soluções em Plástico e Metal.url -> [2010/03/23 20:59:26 | 000,000,202 | ---- | C] ()

CONDUÇÃO ESCOLAR.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\CONDUÇÃO ESCOLAR.doc -> [2010/03/22 12:51:44 | 000,019,968 | ---- | C] ()

Rastreamento-T&T Correios.url -> C:\Documents and Settings\B&J Cyber\Desktop\Rastreamento-T&T Correios.url -> [2010/03/22 11:21:07 | 000,000,309 | ---- | C] ()

escala de enfermagem.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\escala de enfermagem.doc -> [2010/03/21 14:38:48 | 000,048,128 | ---- | C] ()

o fazendeiro, o compadre e o burro.doc -> C:\Documents and Settings\B&J Cyber\Meus documentos\o fazendeiro, o compadre e o burro.doc -> [2010/03/20 12:32:23 | 000,020,992 | ---- | C] ()

Boot.bak -> C:\Boot.bak -> [2010/03/19 22:33:20 | 000,000,211 | ---- | C] ()

cmldr -> C:\cmldr -> [2010/03/19 22:33:18 | 000,261,856 | ---- | C] ()

PEV.exe -> C:\WINDOWS\PEV.exe -> [2010/03/19 22:29:05 | 000,261,632 | ---- | C] ()

MBR.exe -> C:\WINDOWS\MBR.exe -> [2010/03/19 22:29:05 | 000,077,312 | ---- | C] ()

Atalho para ComboFix.exe.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Atalho para ComboFix.exe.lnk -> [2010/03/19 22:14:34 | 000,000,527 | ---- | C] ()

wininit.ini -> C:\WINDOWS\wininit.ini -> [2010/03/19 21:47:32 | 000,000,051 | ---- | C] ()

Simulado.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Simulado.lnk -> [2010/03/19 20:07:08 | 000,001,768 | ---- | C] ()

Revo Remove.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Revo Remove.lnk -> [2010/03/19 20:05:18 | 000,001,011 | ---- | C] ()

CCleaner.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\CCleaner.lnk -> [2010/03/19 20:04:29 | 000,001,630 | ---- | C] ()

Malwarebytes.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Malwarebytes.lnk -> [2010/03/19 17:51:32 | 000,000,850 | ---- | C] ()

Navegadores dando erro e travando - iMasters Fóruns.url -> C:\Documents and Settings\B&J Cyber\Desktop\Navegadores dando erro e travando - iMasters Fóruns.url -> [2010/03/18 22:10:10 | 000,000,354 | ---- | C] ()

HijackThis.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\HijackThis.lnk -> [2010/03/18 13:04:45 | 000,001,728 | ---- | C] ()

Controle De Entrada.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Controle De Entrada.lnk -> [2010/03/18 11:38:24 | 000,000,318 | ---- | C] ()

Easy Café Server.lnk -> C:\Documents and Settings\B&J Cyber\Desktop\Easy Café Server.lnk -> [2010/03/17 21:28:59 | 000,000,793 | ---- | C] ()

photorec.cfg -> C:\Documents and Settings\B&J Cyber\photorec.cfg -> [2010/03/16 22:17:09 | 000,001,972 | ---- | C] ()

FontCache3.0.0.0.dat -> C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\FontCache3.0.0.0.dat -> [2010/01/08 11:00:58 | 000,056,768 | ---- | C] ()

cavscan.INI -> C:\WINDOWS\cavscan.INI -> [2009/11/17 11:20:46 | 000,000,156 | ---- | C] ()

cfplogvw.INI -> C:\WINDOWS\cfplogvw.INI -> [2009/10/21 11:22:38 | 000,000,253 | ---- | C] ()

unrar.dll -> C:\WINDOWS\System32\unrar.dll -> [2009/10/18 14:39:51 | 000,178,176 | ---- | C] ()

StarOpen.sys -> C:\WINDOWS\System32\drivers\StarOpen.sys -> [2009/09/18 15:21:58 | 000,005,632 | ---- | C] ()

ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2008/01/04 01:56:43 | 000,000,421 | ---- | C] ()

VGAsetup.ini -> C:\WINDOWS\VGAsetup.ini -> [2008/01/04 01:29:25 | 000,075,230 | ---- | C] ()

VGAunistlog.ini -> C:\WINDOWS\System32\VGAunistlog.ini -> [2008/01/04 01:29:10 | 000,074,453 | ---- | C] ()

avrack.ini -> C:\WINDOWS\avrack.ini -> [2008/01/04 01:28:09 | 000,000,164 | R--- | C] ()

RTLCPAPI.dll -> C:\WINDOWS\System32\RTLCPAPI.dll -> [2008/01/04 01:27:58 | 000,156,672 | R--- | C] ()

GlobalUserInterface.CompositeFont -> C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont -> [2006/06/29 14:58:52 | 000,030,808 | ---- | C] ()

 

[File - Lop Check]

avg9 -> C:\Documents and Settings\All Users\Dados de aplicativos\avg9 -> [2010/03/31 16:58:23 | 000,000,000 | ---D | M]

Hagel Technologies -> C:\Documents and Settings\All Users\Dados de aplicativos\Hagel Technologies -> [2010/01/28 23:01:18 | 000,000,000 | ---D | M]

SpeedBit -> C:\Documents and Settings\All Users\Dados de aplicativos\SpeedBit -> [2009/07/06 21:55:26 | 000,000,000 | ---D | M]

TEMP -> C:\Documents and Settings\All Users\Dados de aplicativos\TEMP -> [2009/10/17 11:59:00 | 000,000,000 | ---D | M]

TuneUp Software -> C:\Documents and Settings\All Users\Dados de aplicativos\TuneUp Software -> [2010/04/09 11:34:48 | 000,000,000 | ---D | M]

{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} -> C:\Documents and Settings\All Users\Dados de aplicativos\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} -> [2010/04/08 18:28:38 | 000,000,000 | -HSD | M]

DNA -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\DNA -> [2009/06/24 18:43:55 | 000,000,000 | ---D | M]

Haihaisoft -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Haihaisoft -> [2009/09/29 10:34:20 | 000,000,000 | ---D | M]

Haihaisoft Universal Player -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Haihaisoft Universal Player -> [2009/09/29 10:36:27 | 000,000,000 | ---D | M]

IObit -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\IObit -> [2010/03/19 20:17:32 | 000,000,000 | ---D | M]

LimeWire -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\LimeWire -> [2009/10/06 20:12:53 | 000,000,000 | ---D | M]

Remote Queue Manager -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Remote Queue Manager -> [2009/07/28 20:51:18 | 000,000,000 | ---D | M]

Shadow Defender -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Shadow Defender -> [2009/10/14 14:03:45 | 000,000,000 | ---D | M]

TeamViewer -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\TeamViewer -> [2009/07/01 13:58:09 | 000,000,000 | ---D | M]

TuneUp Software -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\TuneUp Software -> [2010/04/08 22:56:15 | 000,000,000 | ---D | M]

TweakNow WinSecret 2009 -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\TweakNow WinSecret 2009 -> [2010/02/23 21:25:45 | 000,000,000 | ---D | M]

uniblue -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\uniblue -> [2010/01/08 11:14:27 | 000,000,000 | ---D | M]

VSRevoGroup -> C:\Documents and Settings\B&J Cyber\Dados de aplicativos\VSRevoGroup -> [2010/03/31 19:00:24 | 000,000,000 | ---D | M]

TeamViewer -> C:\Documents and Settings\LocalService\Dados de aplicativos\TeamViewer -> [2009/07/02 09:47:13 | 000,000,000 | ---D | M]

User_Feed_Synchronization-{D80D9FDE-CA24-47BA-A6A5-278907BFFD93}.job -> C:\WINDOWS\Tasks\User_Feed_Synchronization-{D80D9FDE-CA24-47BA-A6A5-278907BFFD93}.job -> [2010/04/11 19:06:19 | 000,000,462 | -H-- | M] ()

< End of report >

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia DigRam !!! Será que você desistiu? Não deu mais resposta.

Será que ja está dado por resolvido o trabalho ?

 

Me de uma posição !!!

 

Desculpe a insistencia sei que não tem obrigação nenhuma em tentar resolver, apenas faz por gentileza.

 

Obrigado.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia DigRam !!! Será que você desistiu? Não deu mais resposta.

Será que ja está dado por resolvido o trabalho ?

 

Me de uma posição !!!

 

Desculpe a insistencia sei que não tem obrigação nenhuma em tentar resolver, apenas faz por gentileza.

 

Obrigado.

/////////////\\\\\\\\\\\\\

Opa! Bechir Bitar

 

<!> Desculpe-me a demora! Estou sem Internet e,no momento,acessando-a por outra máquina.

00000000000000000000

00000000000000000000

<@> Baixe: < FixPolicies > ( ...by Bill Castner )

<@> Salve-o no Desktop!

<@> Esteja logado como Administrador.

<@> Execute o arquivo FixPolicies.exe,com um duplo-clique.

<@> Clique em Install.

<@> Abra a pasta FixPolicies,que foi criada.

<@> Duplo-clique em Fix_policies.cmd.

<@> Surgirá,por breve momento,uma caixa preta.

00000000000000000000

00000000000000000000

<@> Baixe: < a2ppf_banner.jpg > ( ...by EmsiSoft )

<@> Salve-o em Arquivos de programas.

<@> Abra o programa e clique em: Atualizar agora --> Aguarde!

<@> Terminando,clique em: "Scan PC"

<@> Escolha a opção: "A fundo" --> Clique,à seguir,em "Analisar".

<@> Terminando,marque as caixinhas dos ítens encontrados e clique em "Enviar marcados à Quarentena".

<@> Salve e poste o relatório desta verificação. ( a2scan_xxyy10-xxxxxx.txt ) <--

 

Abraços!

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oba DigRam !!!

 

Quase não consigo baixar o a-squared Free Estou com um problema qua e net so vive caindo

 

Tai o log

 

A impressora ainda não está instalada.

 

Obrigado mais uma vez.

-------------------------------------------------------------------------------------------------------

 

a-squared Free - Versão 4.5

Última atualização 17/04/2010 09:24:41

 

Configurações da análise:

 

Scan type: deep

Objetos: Memória, Rastros, Cookies, C:\, D:\

Análise de arquivos: Ligado

Heurística: Desligado

Análise de ADS: Ligado

 

Início da análise: 17/04/2010 09:29:47

 

c:\windows\joker.exe detectado: Trace.File.Joker!A2

Value: HKEY_CLASSES_ROOT\arlnk --> URL Protocol detectado: Trace.Registry.Ares Galaxy P2P Plus!A2

Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\arlnk --> URL Protocol detectado: Trace.Registry.Ares Galaxy P2P Plus!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@2o7[2].txt detectado: Trace.TrackingCookie.2o7!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@com[1].txt detectado: Trace.TrackingCookie.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@google.com[2].txt detectado: Trace.TrackingCookie.google.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@google.com[3].txt detectado: Trace.TrackingCookie.google.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@google.com[4].txt detectado: Trace.TrackingCookie.google.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@ig.com[1].txt detectado: Trace.TrackingCookie.ig.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@realmedia.com[1].txt detectado: Trace.TrackingCookie.realmedia.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@serving-sys[2].txt detectado: Trace.TrackingCookie.serving-sys!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@statcounter[2].txt detectado: Trace.TrackingCookie.statcounter!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@weborama[2].txt detectado: Trace.TrackingCookie.weborama!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269451658953000 detectado: Trace.TrackingCookie.doubleclick.net!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269478136265000 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269478136265001 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269478136265003 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269478136265004 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269478543937002 detectado: Trace.TrackingCookie.ad.yieldmanager.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269554075625000 detectado: Trace.TrackingCookie.adwords.google.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269554075625001 detectado: Trace.TrackingCookie.adwords.google.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269554152656000 detectado: Trace.TrackingCookie.s4.shinystat.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269737529203000 detectado: Trace.TrackingCookie.d1.openx.org!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269884914703000 detectado: Trace.TrackingCookie.adserv!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269900606562000 detectado: Trace.TrackingCookie.ads.xpg.com.br!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270154669468000 detectado: Trace.TrackingCookie.www.googleadservices.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270154817578000 detectado: Trace.TrackingCookie.www.googleadservices.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270585648703000 detectado: Trace.TrackingCookie.tribalfusion.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270588109921000 detectado: Trace.TrackingCookie.www.googleadservices.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270920003171000 detectado: Trace.TrackingCookie.zedo.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270920003171001 detectado: Trace.TrackingCookie.zedo.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270920003171002 detectado: Trace.TrackingCookie.zedo.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270920003203000 detectado: Trace.TrackingCookie.adbrite.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270920003203001 detectado: Trace.TrackingCookie.adbrite.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1271119628187000 detectado: Trace.TrackingCookie.ad1.clickhype.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1271458522718000 detectado: Trace.TrackingCookie.stat.onestat!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1271458522718001 detectado: Trace.TrackingCookie.stat.onestat!A2

 

Analisado

 

Arquivos: 72488

Objetos: 667059

Cookies: 622

Processos: 34

 

Encontrado

 

Arquivos: 0

Objetos: 3

Cookies: 37

Processos: 0

Chaves do registro: 0

 

Fim da análise: 17/04/2010 09:55:10

Duração da análise: 0:25:23

 

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1271458522718000 Em quarentena Trace.TrackingCookie.stat.onestat!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1271458522718001 Em quarentena Trace.TrackingCookie.stat.onestat!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1271119628187000 Em quarentena Trace.TrackingCookie.ad1.clickhype.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270920003203000 Em quarentena Trace.TrackingCookie.adbrite.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270920003203001 Em quarentena Trace.TrackingCookie.adbrite.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270920003171000 Em quarentena Trace.TrackingCookie.zedo.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270920003171001 Em quarentena Trace.TrackingCookie.zedo.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270920003171002 Em quarentena Trace.TrackingCookie.zedo.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270585648703000 Em quarentena Trace.TrackingCookie.tribalfusion.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270154669468000 Em quarentena Trace.TrackingCookie.www.googleadservices.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270154817578000 Em quarentena Trace.TrackingCookie.www.googleadservices.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1270588109921000 Em quarentena Trace.TrackingCookie.www.googleadservices.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269900606562000 Em quarentena Trace.TrackingCookie.ads.xpg.com.br!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269884914703000 Em quarentena Trace.TrackingCookie.adserv!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269737529203000 Em quarentena Trace.TrackingCookie.d1.openx.org!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269554152656000 Em quarentena Trace.TrackingCookie.s4.shinystat.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269554075625000 Em quarentena Trace.TrackingCookie.adwords.google.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269554075625001 Em quarentena Trace.TrackingCookie.adwords.google.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269478136265000 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269478136265001 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269478136265003 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269478136265004 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269478543937002 Em quarentena Trace.TrackingCookie.ad.yieldmanager.com!A2

C:\Documents and Settings\B&J Cyber\Dados de aplicativos\Mozilla\Firefox\Profiles\rzhc27jr.default\cookies.sqlite:1269451658953000 Em quarentena Trace.TrackingCookie.doubleclick.net!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@weborama[2].txt Em quarentena Trace.TrackingCookie.weborama!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@statcounter[2].txt Em quarentena Trace.TrackingCookie.statcounter!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@serving-sys[2].txt Em quarentena Trace.TrackingCookie.serving-sys!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@realmedia.com[1].txt Em quarentena Trace.TrackingCookie.realmedia.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@ig.com[1].txt Em quarentena Trace.TrackingCookie.ig.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@google.com[2].txt Em quarentena Trace.TrackingCookie.google.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@google.com[3].txt Em quarentena Trace.TrackingCookie.google.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@google.com[4].txt Em quarentena Trace.TrackingCookie.google.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@com[1].txt Em quarentena Trace.TrackingCookie.com!A2

C:\Documents and Settings\B&J Cyber\Cookies\b&j_cyber@2o7[2].txt Em quarentena Trace.TrackingCookie.2o7!A2

c:\windows\joker.exe Em quarentena Trace.File.Joker!A2

 

Em quarentena

 

Arquivos: 0

Objetos: 3

Cookies: 34

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.