Ir para conteúdo

Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

guigcs

[Resolvido!] Cavalo de Troa PSW. Banker 5

Recommended Posts

Aqui vai o Log file do Hijack This. Não sei o q faço, esse vírus está atormentando minha vida. rs

Agradeço a colaboração!

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:28:55, on 19/3/2010

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\system32\csrcs.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\VM_STI.EXE

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\ctfmon.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\MessengerPlus\wmplayer.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Microsoft Office\OFFICE11\WINWORD.EXE

C:\Arquivos de programas\AVG\AVG8\avgcsrvx.exe

C:\Arquivos de programas\Microsoft\Office Live\OfficeLiveSignIn.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\svchost.exe

C:\Documents and Settings\usuario\Desktop\HiJackThis\HijackThis.exe

C:\Documents and Settings\usuario\Desktop\HiJackThis\HijackThis.exe

C:\WINDOWS\system32\cmd.exe

C:\WINDOWS\system32\net.exe

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx

F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: flvdirect - {2e7929b5-b903-340d-eb69-96c8e83d402c} - C:\WINDOWS\system32\RQVvIO.dll

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Arquivos de programas\FlashGet\jccatch_2.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Arquivos de programas\FlashGet\getflash.dll

O2 - BHO: (no name) - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - C:\MessengerPlus\IEBrowserEvents.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.EXE LG Web Camera driver

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup

O4 - HKLM\..\Run: [explorer] C:\Documents and Settings\All Users\Dados de aplicativos\Winthkill.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\RunServices: [csrcs] C:\WINDOWS\system32\csrcs.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [TaskServ.exe] C:\Documents and Settings\All Users\Dados de aplicativos\TaskServ.exe

O4 - HKCU\..\Run: [wmplayer] C:\MessengerPlus\wmplayer.exe

O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm

O8 - Extra context menu item: &Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe

O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: http://www.flvdirect.com

O15 - ESC Trusted Zone: http://www.flvdirect.com

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

 

--

End of file - 8923 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Baixe o MalwareBytes Anti-malware e salve-o no desktop:

*Instale o programa

*Se alguma atualização existir,o download será automático. Aguarde...

*O programa será aberto automaticamente.

*Na aba [Verificação], selecione a opção [Verificação completa]

*Clique em [Verificar] e selecione as unidades (C:\ e D:\) a serem examinadas

*Ao término do scan, poderá ser interrogado se deseja remover objetos da memória. Clique [sIM] > [OK] > [Mostrar Resultados]

*Clique em [Remover Selecionados]

*Um relatório (mbam-log-ano-mês-data.txt) será apresentado.

*Cole-o na sua próxima resposta e novo log do hijack

Compartilhar este post


Link para o post
Compartilhar em outros sites

Aí vão os resultados do Malwarebytes' e do novo log do hijack.

Valeu pela ajuda!!!

 

Malwarebytes' Anti-Malware 1.44

Versão do banco de dados: 3885

Windows 5.1.2600 Service Pack 2

Internet Explorer 6.0.2900.2180

 

19/3/2010 18:07:48

mbam-log-2010-03-19 (18-07-46).txt

 

Tipo de Verificação: Completa (C:\|D:\|)

Objetos verificados: 165174

Tempo decorrido: 2 hour(s), 26 minute(s), 13 second(s)

 

Processos da Memória infectados: 2

Módulos de Memória Infectados: 0

Chaves do Registro infectadas: 12

Valores do Registro infectados: 4

Ítens do Registro infectados: 4

Pastas infectadas: 9

Arquivos infectados: 49

 

Processos da Memória infectados:

C:\MessengerPlus\wmplayer.exe (Trojan.VB) -> Unloaded process successfully.

C:\WINDOWS\system32\csrcs.exe (Trojan.Agent) -> Unloaded process successfully.

 

Módulos de Memória Infectados:

(Nenhum ítem malicioso foi detectado)

 

Chaves do Registro infectadas:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb} (Trojan.BHO.H) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb} (Trojan.BHO.H) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67kln5j0-4opm-01we-aax5-314cca322142} (Generic.Bot.H) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb} (Trojan.Banker) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{ef34404a-747c-81d8-843a-d938e181273d} (Adware.BHO.FL) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{67kln5j0-4opm-01we-aax5-314cca322142} (Worm.AutoRun) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\s7eho-nia_6 (Adware.LoudMo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\flv direct player (Adware.BHO.FL) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DRM\amty (Worm.Autorun) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2e7929b5-b903-340d-eb69-96c8e83d402c} (Adware.AdRotator) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{2e7929b5-b903-340d-eb69-96c8e83d402c} (Adware.AdRotator) -> Quarantined and deleted successfully.

 

Valores do Registro infectados:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wmplayer (Trojan.VB) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\explorer (Malware.Trace) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\csrcs (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\taskserv.exe (Trojan.Banker) -> Quarantined and deleted successfully.

 

Ítens do Registro infectados:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe csrcs.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.

 

Pastas infectadas:

C:\Arquivos de programas\FLV Direct Player (Adware.BHO.FL) -> Delete on reboot.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\ComboBox (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users\Menu Iniciar\Programas\FLV Direct Player (Adware.FLVPlayer) -> Quarantined and deleted successfully.

 

Arquivos infectados:

C:\MessengerPlus\IEBrowserEvents.dll (Trojan.BHO.H) -> Quarantined and deleted successfully.

C:\MessengerPlus\wmplayer.exe (Trojan.VB) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{3F3BB39D-29BA-4782-ABA0-87EC32C7B760}\RP337\A0087997.exe (Trojan.Banker) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\s7EhO-nIA_6.exe (Adware.LoudMo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\FLVDirect.exe (Adware.MediaPass) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\downloading.swf (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\dskinliteu.dll (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\FLVPlayer.exe (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\player.dat (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\preload.swf (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\uninstall.exe (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin.xml (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button\button_default.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button\button_disable.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button\button_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button\button_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Button\button_normal.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\ComboBox\combobox_buttonDown.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\ComboBox\combobox_buttonHot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\ComboBox\combobox_buttonNor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\ComboBox\edit_back.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu\menubg.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu\menuItem_arrow.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu\menuItem_check.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu\menuitem_select.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Menu\menuItem_seperator.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_close_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_close_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_close_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_max_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_max_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_max_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_min_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_min_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_min_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_restore_down.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_restore_hot.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\SysButton\sys_restore_nor.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\BottomBorder.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\downarrow.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\LeftBorder.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\Logo.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\main.ico (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\RightBorder.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Arquivos de programas\FLV Direct Player\SkinDirectFLV\skin\Window\TitlePattern.bmp (Adware.BHO.FL) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users\Menu Iniciar\Programas\FLV Direct Player\FLV Direct Player.lnk (Adware.FLVPlayer) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users\Menu Iniciar\Programas\FLV Direct Player\Uninstall FLV Direct Player.lnk (Adware.FLVPlayer) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\csrcs.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\RQVvIO.dll (Adware.AdRotator) -> Quarantined and deleted successfully.

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 18:20:41, on 19/3/2010

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\VM_STI.EXE

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Documents and Settings\usuario\Desktop\HiJackThis\HijackThis.exe

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Arquivos de programas\FlashGet\jccatch_2.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Arquivos de programas\FlashGet\getflash.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Arquivos de programas\AskBarDis\bar\bin\askBar.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.EXE LG Web Camera driver

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\RunServices: [csrcs] C:\WINDOWS\system32\csrcs.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm

O8 - Extra context menu item: &Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe

O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: http://www.flvdirect.com

O15 - ESC Trusted Zone: http://www.flvdirect.com

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

 

--

End of file - 8171 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

*Baixe o AD-Remover e salve-o no desktop

*Duplo clique em AD-R.exe

*Clique em [Clean]...aguarde o término

*Cole o relatório criado em C:\Ad-Report-CLEAN.log e novo log do hijack

Compartilhar este post


Link para o post
Compartilhar em outros sites

.

======= AD-REMOVER 2.0.0.0,BREPORT | ONLY XP/VISTA/7 =======

.

Updated by C_XX on 19/03/10 à 20:40

Contact: AdRemover.contact@gmail.com

Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html

.

Started: 19:42:33 le 19/03/2010 | Normal boot | Option: CLEAN

Executed from: C:\Ad-Remover\ADR.exe

OS: Microsoft® Windows XP™ Service Pack 2 - X86

Computer name: ASDF-8BFEDC562E | Current user: usuario (Administrator)

.

============== FIXED ELEMENTS ==============

.

.

C:\Arquivos de programas\AskBarDis

C:\Arquivos de programas\PokerStars

C:\Documents and Settings\usuario\Dados de aplicativos\Mozilla\FireFox\Profiles\4u2vjo6r.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}

 

(!) -- Deleted temporary files.

.

HKCU\Software\AppDataLow\AskBarDis

HKCU\Software\AskBarDis

HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201f27d4-3704-41d6-89c1-aa35e39143ed}

HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041d03e-fd4b-44e0-b742-2d9b88305f98}

HKLM\Software\AskBarDis

HKLM\Software\Classes\AskIBar.PopSwatterBarButton

HKLM\Software\Classes\AskIBar.PopSwatterBarButton.1

HKLM\Software\Classes\AskIBar.PopSwatterSettingsControl

HKLM\Software\Classes\AskIBar.PopSwatterSettingsControl.1

HKLM\Software\Classes\AskToolBar.SettingsPlugin

HKLM\Software\Classes\AskToolBar.SettingsPlugin.1

HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}

HKLM\Software\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2}

HKLM\Software\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E}

HKLM\Software\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}

HKLM\Software\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}

HKLM\Software\Classes\CLSID\{571715D7-3395-4DF0-B43C-784836209E60}

HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}

HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}

HKLM\Software\Classes\Interface\{4634804A-F0B0-4A74-A550-FC0EEF8A4362}

HKLM\Software\Classes\Interface\{4C07EA4F-5F52-4222-B170-4CD9ED33BAEA}

HKLM\Software\Classes\Interface\{C44FEFF4-EF0C-4CF7-83D0-92B4266A32B9}

HKLM\Software\Classes\Interface\{F131923C-381D-4E4C-A472-4A17118FD742}

HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}

HKLM\Software\Classes\TypeLib\{D2E5FA06-DCC7-46F9-BEFF-BFD06F69B9B2}

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ask Toolbar_is1

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{3041D03E-FD4B-44E0-B742-2D9B88305F98}

HKLM\Software\Microsoft\Internet Explorer\Toolbar|{3041D03E-FD4B-44E0-B742-2D9B88305F98}

.

============== ADDITIONNAL SCAN ==============

.

* Mozilla FireFox Version 3.5.8 (pt-BR) *

.

C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.download.dir: C:\\Documents and Settings\\usuario\\Desktop

C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.download.lastDir: C:\\Documents and Settings\\usuario\\Desktop

C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.search.defaultenginename: Search

C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.search.defaulturl: hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search=

C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.startup.homepage: hxxp://www.google.com.br/

C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - browser.startup.homepage_override.mstone: rv:1.9.1.8

C:\Documents and Settings\usuario\Dados de aplicativos\mozilla\firefox\profiles\4u2vjo6r.default\prefs.js - keyword.URL: hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search=

.

.

* Internet Explorer Version 6.0.2900.2180 *

.

[HKCU\Software\Microsoft\Internet Explorer\Main]

.

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

Do404Search: 0x01000000

Local Page: C:\WINDOWS\system32\blank.htm

Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896

Show_ToolBar: yes

Start Page: hxxp://fr.msn.com/

Use Search Asst: no

.

[HKLM\Software\Microsoft\Internet Explorer\Main]

.

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

Delete_Temp_Files_On_Exit: yes

Local Page: %SystemRoot%\system32\blank.htm

Search bar: hxxp://search.msn.com/spbasic.htm

Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

Start Page: hxxp://fr.msn.com/

.

[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]

.

Tabs: res://ieframe.dll/tabswelcome.htm

Blank: res://mshtml.dll/blank.htm

.

========================================

.

C:\DOCUME~1\usuario\CONFIG~1\Temp: 2 Files, 22 Folders

C:\WINDOWS\temp: 2 Files, 6 Folders

Temporary Internet Files: 0 Files, 10 Folders

.

C:\Ad-Remover\Quarantine: 0 Files

C:\Ad-Remover\Backup: 14 Files

.

C:\Ad-Report-CLEAN[1].txt - 5333 Byte(s)

.

End at:19:53:20, 19/03/2010

.

============== E.O.F - CLEAN[1] ==============

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:02:21, on 19/3/2010

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\VM_STI.EXE

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\usuario\Desktop\HiJackThis\HijackThis.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Arquivos de programas\FlashGet\jccatch_2.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Arquivos de programas\FlashGet\getflash.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.EXE LG Web Camera driver

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\RunServices: [csrcs] C:\WINDOWS\system32\csrcs.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm

O8 - Extra context menu item: &Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe

O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: http://www.flvdirect.com

O15 - ESC Trusted Zone: http://www.flvdirect.com

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

 

--

End of file - 8065 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

1.

*Execute novamente o AD-Remover

*Clique em [uninstall]

 

2.

*Abra o programa Malwarebytes e na aba [Quarentena], selecione todos os resultados e clique em [Remover tudo]

*Clique na aba [Logs], selecione o relatório e clique em [Remover]

 

3.

*Desative temporariamente seu antivírus

 

Iniciar > Programas > AVG

Abra a Interface do usuário do AVG

Clique duas vezes na Proteção Residente

Desmarque a opção "Proteção Residente ativa"

Salve as alterações

*Baixe o ComboFix e salve-o no desktop

*Duplo-clique no arquivo Combofix.exe

*Aceite o contrato

 

*Se o console de recuperação do Windows já estiver instalado, o ComboFix continuará o processo automaticamente. Caso não esteja, uma janela conforme abaixo será aberta. Clique em [sIM] para aceitar a instalação do mesmo.

 

recovery-console-prompt.jpg

 

*Após a instalação, clique em [sIM] para continuar.

 

recovery-console-installed.jpg

 

*Aguarde a conclusão de todas as etapas

 

etapas.jpg

*Importante: enquanto o ComboFix estiver em execução, não use o mouse nem o teclado!!..... Para interromper o procedimento tecle N ou 2 e depois ENTER.

 

*O programa será fechado automaticamente

 

*Cole o relatório criado em C:\combofix.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

ComboFix 10-03-19.06 - usuario 19/03/2010 20:41:59.1.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.55.1046.18.223.7 [GMT -3:00]

Executando de: c:\documents and settings\usuario\Desktop\ComboFix.exe

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

.

 

((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\documents and settings\All Users\Dados de aplicativos\UpApp32.dll

c:\driver\Files\Desktop.ini

C:\MessengerPlus

c:\messengerplus\a01campos@ig.com.br1.log

c:\messengerplus\acmottavilela@hotmail.com1.log

c:\messengerplus\adeliagb@hotmail.com1.log

c:\messengerplus\adeliamagal@hotmail.com1.log

c:\messengerplus\alan_hilario@hotmail.com1.log

c:\messengerplus\alepachecosvm@hotmail.com1.log

c:\messengerplus\alexandrasvm@hotmail.com1.log

c:\messengerplus\alexcamposfisco@hotmail.com1.log

c:\messengerplus\alicealmeidaferreira@hotmail.com1.log

c:\messengerplus\aline_sasso@hotmail.com1.log

c:\messengerplus\alinejuste@gmail.com1.log

c:\messengerplus\alinejuste@hotmail.com1.log

c:\messengerplus\alinnecaneschi@hotmail.com1.log

c:\messengerplus\alyne402@hotmail.com1.log

c:\messengerplus\amanda_mg@msn.com1.log

c:\messengerplus\amandadias_britto@hotmail.com1.log

c:\messengerplus\anacondutta@hotmail.com1.log

c:\messengerplus\anakrol_santos@hotmail.com1.log

c:\messengerplus\analuisarleite@hotmail.com1.log

c:\messengerplus\anapaulacamppos@hotmail.com1.log

c:\messengerplus\anatereza007@hotmail.com1.log

c:\messengerplus\andinhaloks@hotmail.com1.log

c:\messengerplus\andre-fperon@hotmail.com1.log

c:\messengerplus\andressacretha@hotmail.com1.log

c:\messengerplus\anepotter_67@hotmail.com1.log

c:\messengerplus\aninha_ksb@hotmail.com1.log

c:\messengerplus\annapaulaguida@hotmail.com1.log

c:\messengerplus\anninha.souza@hotmail.com1.log

c:\messengerplus\annybruno@yahoo.com.br1.log

c:\messengerplus\apruma@yahoo.com.br1.log

c:\messengerplus\arcanjinhu@hotmail.com1.log

c:\messengerplus\asmoxinhas@hotmail.com1.log

c:\messengerplus\aspiranteapsicologa_joca@yahoo.com.br1.log

c:\messengerplus\avirgilioferreira@yahoo.com.br1.log

c:\messengerplus\baixinha141@hotmail.com1.log

c:\messengerplus\bardock_lf@hotmail.com1.log

c:\messengerplus\barreto279@hotmail.com1.log

c:\messengerplus\baxandre@hotmail.com1.log

c:\messengerplus\bebel-bela@hotmail.com1.log

c:\messengerplus\bebeporto@hotmail.com1.log

c:\messengerplus\belissimais@hotmail.com1.log

c:\messengerplus\bethania_fm@hotmail.com1.log

c:\messengerplus\bianca_012@hotmail.com1.log

c:\messengerplus\biancas_rossi@hotmail.com1.log

c:\messengerplus\bibifileh@hotmail.com1.log

c:\messengerplus\bigtaycosta@hotmail.com1.log

c:\messengerplus\bininhatavares@hotmail.com1.log

c:\messengerplus\bmflipper@hotmail.com1.log

c:\messengerplus\botelho963@hotmail.com1.log

c:\messengerplus\bovareto@terra.com.br1.log

c:\messengerplus\brauliomarciano@yahoo.com.br1.log

c:\messengerplus\bruninha_bsv@hotmail.com1.log

c:\messengerplus\bruninha_zampier@msn.com1.log

c:\messengerplus\brunninh@hotmail.com1.log

c:\messengerplus\bruno_uba@hotmail.com1.log

c:\messengerplus\brunoazeve8@hotmail.com1.log

c:\messengerplus\brunodasilvamiranda@gmail.com1.log

c:\messengerplus\brunompboia@hotmail.com1.log

c:\messengerplus\bulu_mirai@hotmail.com1.log

c:\messengerplus\caiolreboucas@hotmail.com1.log

c:\messengerplus\caiom_moreira@hotmail.com1.log

c:\messengerplus\camilacalsavara@hotmail.com1.log

c:\messengerplus\carla_ppzinha@hotmail.com1.log

c:\messengerplus\carloseduardo_tuc@hotmail.com1.log

c:\messengerplus\carolinapiva@hotmail.com1.log

c:\messengerplus\carolugs@hotmail.com1.log

c:\messengerplus\carolzinha.tur@hotmail.com1.log

c:\messengerplus\carolzinhapaes@hotmail.com1.log

c:\messengerplus\celsi.campos@hotmail.com1.log

c:\messengerplus\celsiane.souza@fazenda.mg.gov.br1.log

c:\messengerplus\celsicampos@hotmail.com1.log

c:\messengerplus\celsosouzauba@hotmail.com1.log

c:\messengerplus\ciceromaia@hotmail.com1.log

c:\messengerplus\cinthia-ufjf@hotmail.com1.log

c:\messengerplus\cintyaufv@hotmail.com1.log

c:\messengerplus\claudinein@snv.com.br1.log

c:\messengerplus\clebergomides@hotmail.com1.log

c:\messengerplus\cleo_mariacoelho@hotmail.com1.log

c:\messengerplus\clown-adm@hotmail.com1.log

c:\messengerplus\colleman7@hotmail.com1.log

c:\messengerplus\conradotgs@hotmail.com1.log

c:\messengerplus\cpanalise1@intermedium.com.br1.log

c:\messengerplus\cpanalise2@intermedium.com.br1.log

c:\messengerplus\creonice_21@hotmail.com1.log

c:\messengerplus\cristiane_alves_456@hotmail.com1.log

c:\messengerplus\cupidopammachado@hotmail.com1.log

c:\messengerplus\dalvinha.teixeira@hotmail.com1.log

c:\messengerplus\danicoelhojf@hotmail.com1.log

c:\messengerplus\daniele@intermedium.com.br1.log

c:\messengerplus\daniloamedina@hotmail.com1.log

c:\messengerplus\danizinha_guimaraes@hotmail.com1.log

c:\messengerplus\dannyzimmermann@hotmail.com1.log

c:\messengerplus\dayana_ribeirojf@hotmail.com1.log

c:\messengerplus\deboraheloli@hotmail.com1.log

c:\messengerplus\denisematipo@hotmail.com1.log

c:\messengerplus\dennerskiter@hotmail.com1.log

c:\messengerplus\deus_hades@hotmail.com1.log

c:\messengerplus\diego_bianchi_@hotmail.com1.log

c:\messengerplus\diogo_moreira82@hotmail.com1.log

c:\messengerplus\distribuidoraakitem@hotmail.com1.log

c:\messengerplus\djcka@hotmail.com1.log

c:\messengerplus\djcka@yahoo.com.br1.log

c:\messengerplus\drigommachado@hotmail.com1.log

c:\messengerplus\du_152@hotmail.com1.log

c:\messengerplus\dudaduda_888@hotmail.com1.log

c:\messengerplus\dudinkka@hotmail.com1.log

c:\messengerplus\ecila.vieira@hotmail.com1.log

c:\messengerplus\edite80@hotmail.com1.log

c:\messengerplus\eduardocpp@hotmail.com1.log

c:\messengerplus\ehdementirinha@hotmail.com1.log

c:\messengerplus\elainepatriciacm@hotmail.com1.log

c:\messengerplus\eliermelo@yahoo.com.br1.log

c:\messengerplus\elisaprocopio01@hotmail.com1.log

c:\messengerplus\elton_me@hotmail.com1.log

c:\messengerplus\emmanuel_costa@hotmail.com1.log

c:\messengerplus\enviado.flg

c:\messengerplus\estevaocruz@hotmail.com1.log

c:\messengerplus\evelynalbuquerque@hotmail.com1.log

c:\messengerplus\evezinha_maia@hotmail.com1.log

c:\messengerplus\extra_cred@hotmail.com1.log

c:\messengerplus\f.rbraga@hotmail.com1.log

c:\messengerplus\fabin_magrin@hotmail.com1.log

c:\messengerplus\fastdel@hotmail.com1.log

c:\messengerplus\fefe_thebest_vip@hotmail.com1.log

c:\messengerplus\feiterer@hotmail.com1.log

c:\messengerplus\felipecogu@hotmail.com1.log

c:\messengerplus\felipepiva@hotmail.com1.log

c:\messengerplus\feliperodriguestokio@hotmail.com1.log

c:\messengerplus\felippe_cr7@hotmail.com1.log

c:\messengerplus\felippebalbi@msn.com1.log

c:\messengerplus\fernanda_salomao@hotmail.com1.log

c:\messengerplus\fernandinha_cp2@hotmail.com1.log

c:\messengerplus\feuzinho4@hotmail.com1.log

c:\messengerplus\filippemoreira@msn.com1.log

c:\messengerplus\fiuza_@hotmail.com1.log

c:\messengerplus\flaviajunqueira@msn.com1.log

c:\messengerplus\fotoiris@yahoo.com.br1.log

c:\messengerplus\francielecasal@hotmail.com1.log

c:\messengerplus\frbilheri@hotmail.com1.log

c:\messengerplus\g735@hotmail.com1.log

c:\messengerplus\gabih_kuwabara@hotmail.com1.log

c:\messengerplus\gabimehri@hotmail.com1.log

c:\messengerplus\gabrielamello_01@hotmail.com1.log

c:\messengerplus\gabriellaramos@hotmail.com1.log

c:\messengerplus\gabrielmcampos@msn.com1.log

c:\messengerplus\gabrielmcampos@yahoo.com.br1.log

c:\messengerplus\gaofernandes@hotmail.com1.log

c:\messengerplus\gatas_groppo@hotmail.com1.log

c:\messengerplus\gerfisio@hotmail.com1.log

c:\messengerplus\gestor.cadastro@intermedium.com.br1.log

c:\messengerplus\gestor.operacional@intermedium.com.br1.log

c:\messengerplus\gi_htinha666@hotmail.com1.log

c:\messengerplus\gianinigandhi@yahoo.com1.log

c:\messengerplus\gipcardoso@hotmail.com1.log

c:\messengerplus\gisellerq@hotmail.com1.log

c:\messengerplus\gisiane-lopes@hotmail.com1.log

c:\messengerplus\gmvalverde@hotmail.com1.log

c:\messengerplus\graziroberti@hotmail.com1.log

c:\messengerplus\grazitrevenzoli@hotmail.com1.log

c:\messengerplus\guigcs@gmail.com1.log

c:\messengerplus\guilherme.c.toledo@hotmail.com1.log

c:\messengerplus\guilhermegravina@hotmail.com1.log

c:\messengerplus\guilhermesreis10@hotmail.com1.log

c:\messengerplus\guimaraes_araujo@hotmail.com1.log

c:\messengerplus\gustavocamposalmeida@hotmail.com1.log

c:\messengerplus\guytruta@hotmail.com1.log

c:\messengerplus\gvcasado@hotmail.com1.log

c:\messengerplus\hbovareto@hotmail.com1.log

c:\messengerplus\helves@intermedium.com.br1.log

c:\messengerplus\henrao@hotmail.com1.log

c:\messengerplus\heronfchagas@hotmail.com1.log

c:\messengerplus\hugomn@gmail.com1.log

c:\messengerplus\huguin_moreira@hotmail.com1.log

c:\messengerplus\humbertindocoracao@hotmail.com1.log

c:\messengerplus\igor_mdvm@hotmail.com1.log

c:\messengerplus\ikaroteixeira@hotmail.com1.log

c:\messengerplus\iki.almeida@hotmail.com1.log

c:\messengerplus\isabelamariadeoliveira@hotmail.com1.log

c:\messengerplus\isabella_limaoliveira@hotmail.com1.log

c:\messengerplus\isagily@hotmail.com1.log

c:\messengerplus\isianedurso1@hotmail.com1.log

c:\messengerplus\ivsgyn@hotmail.com1.log

c:\messengerplus\jannyso@hotmail.com1.log

c:\messengerplus\jaop_sol@hotmail.com1.log

c:\messengerplus\jardelhc@hotmail.com1.log

c:\messengerplus\jayme_ab@hotmail.com1.log

c:\messengerplus\jessiquinha_tdb@hotmail.com1.log

c:\messengerplus\jlcarpolminastex@hotmail.com1.log

c:\messengerplus\jmarepre@yahoo.com.br1.log

c:\messengerplus\jmoreira102@hotmail.com1.log

c:\messengerplus\joanna.dantas@hotmail.com1.log

c:\messengerplus\jonedebruce@hotmail.com1.log

c:\messengerplus\jordanamarques@uol.com.br1.log

c:\messengerplus\joseanedoa@hotmail.com1.log

c:\messengerplus\josi.real@hotmail.com1.log

c:\messengerplus\jositavares21@hotmail.com1.log

c:\messengerplus\joyce_af@hotmail.com1.log

c:\messengerplus\ju_filezinha@hotmail.com1.log

c:\messengerplus\jubcastro1@hotmail.com1.log

c:\messengerplus\jujubinha_mag@hotmail.com1.log

c:\messengerplus\julia_furiati@hotmail.com1.log

c:\messengerplus\juliana-cretha@hotmail.com1.log

c:\messengerplus\julianaphonseca@hotmail.com1.log

c:\messengerplus\julianasalimena@terra.com.br1.log

c:\messengerplus\julibressan@hotmail.com1.log

c:\messengerplus\julis_jacob@hotmail.com1.log

c:\messengerplus\julisjacob@hotmail.com1.log

c:\messengerplus\july_kt@hotmail.com1.log

c:\messengerplus\juniabretas@hotmail.com1.log

c:\messengerplus\juninho2501@hotmail.com1.log

c:\messengerplus\jussara_mag@hotmail.com1.log

c:\messengerplus\juupdate18.log

c:\messengerplus\kaizinhaaa@hotmail.com1.log

c:\messengerplus\kaka_rp16@hotmail.com1.log

c:\messengerplus\kamilacrp@hotmail.com1.log

c:\messengerplus\karolcaputo@hotmail.com1.log

c:\messengerplus\kezinhah@hotmail.com1.log

c:\messengerplus\kikamcg@hotmail.com1.log

c:\messengerplus\kk.soares@hotmail.com1.log

c:\messengerplus\kley_2005@hotmail.com1.log

c:\messengerplus\kulla_botelho@hotmail.com1.log

c:\messengerplus\kynhacarvalho@hotmail.com1.log

c:\messengerplus\lailacfp@hotmail.com1.log

c:\messengerplus\lailapiva@hotmail.com1.log

c:\messengerplus\lais_fonseca@hotmail.com1.log

c:\messengerplus\laisbalbi@hotmail.com1.log

c:\messengerplus\laiscruzp@hotmail.com1.log

c:\messengerplus\laisfonseca_@hotmail.com1.log

c:\messengerplus\laizmn@hotmail.com1.log

c:\messengerplus\lala_nteixeira@hotmail.com1.log

c:\messengerplus\laramnogueira@hotmail.com1.log

c:\messengerplus\larinha3@yahoo.com.br1.log

c:\messengerplus\larinhafeital@hotmail.com1.log

c:\messengerplus\larissa_cotta@hotmail.com1.log

c:\messengerplus\lauragprata@hotmail.com1.log

c:\messengerplus\laurobombinha@hotmail.com1.log

c:\messengerplus\laysecohen@live.com1.log

c:\messengerplus\leandrouba@hotmail.com1.log

c:\messengerplus\leila-_-@hotmail.com1.log

c:\messengerplus\leliudes@hotmail.com1.log

c:\messengerplus\lenasouza02@hotmail.com1.log

c:\messengerplus\leofaki@hotmail.com.br1.log

c:\messengerplus\lialilida@hotmail.com1.log

c:\messengerplus\liamaradruda@hotmail.com1.log

c:\messengerplus\lidao1@msn.com1.log

c:\messengerplus\lili_stp@hotmail.com1.log

c:\messengerplus\lilianetolomelli@hotmail.com1.log

c:\messengerplus\liviacurty@hotmail.com1.log

c:\messengerplus\livinhamsb@hotmail.com1.log

c:\messengerplus\livinhasimoes@yahoo.com.br1.log

c:\messengerplus\lorraine.cso@hotmail.com1.log

c:\messengerplus\luanacb2000@yahoo.com.br1.log

c:\messengerplus\luanamc6@hotmail.com1.log

c:\messengerplus\luanaribeiro2006@hotmail.com1.log

c:\messengerplus\luanatoledo7_9@hotmail.com1.log

c:\messengerplus\luannalexandre@hotmail.com1.log

c:\messengerplus\lucaspiersanti@hotmail.com1.log

c:\messengerplus\luciana_gravina@hotmail.com1.log

c:\messengerplus\lucyassef29@hotmail.com1.log

c:\messengerplus\lud_werneque@hotmail.com1.log

c:\messengerplus\ludmila555@hotmail.com1.log

c:\messengerplus\luga_brandao@hotmail.com1.log

c:\messengerplus\luis_o_bom@hotmail.com1.log

c:\messengerplus\luiza_sansao@hotmail.com1.log

c:\messengerplus\luizabethlopes@hotmail.com1.log

c:\messengerplus\luizabranches@hotmail.com1.log

c:\messengerplus\luizapabranches@hotmail.com1.log

c:\messengerplus\luizinhoff@msn.com1.log

c:\messengerplus\lunna_vc@hotmail.com1.log

c:\messengerplus\lusaiki@hotmail.com1.log

c:\messengerplus\maira_rosa85@hotmail.com1.log

c:\messengerplus\mapalmas@hotmail.com1.log

c:\messengerplus\marcelabaiao2@hotmail.com1.log

c:\messengerplus\marcelacretha@hotmail.com1.log

c:\messengerplus\marcelinhamf15@hotmail.com1.log

c:\messengerplus\marcelo_ramos@hotmail.com1.log

c:\messengerplus\marcioartesanato@hotmail.com1.log

c:\messengerplus\marcobonoto@hotmail.com1.log

c:\messengerplus\mari_vieirajf@hotmail.com1.log

c:\messengerplus\mariana_teixeira_44@hotmail.com1.log

c:\messengerplus\marianacampos_88@hotmail.com1.log

c:\messengerplus\marianacasella27@hotmail.com1.log

c:\messengerplus\marianepena@yahoo.com.br1.log

c:\messengerplus\marinabitarello@hotmail.com1.log

c:\messengerplus\marinaflautista@hotmail.com1.log

c:\messengerplus\marinafusaro@yahoo.com.br1.log

c:\messengerplus\mariviannatop@hotmail.com1.log

c:\messengerplus\mary-inha@hotmail.com1.log

c:\messengerplus\maryrossinjf@hotmail.com1.log

c:\messengerplus\massai_tr@hotmail.com1.log

c:\messengerplus\mathiasagostini@yahoo.com.br1.log

c:\messengerplus\meirepaivamoreira@hotmail.com1.log

c:\messengerplus\meiretmpaiva@hotmail.com1.log

c:\messengerplus\meli_mschmid@hotmail.com1.log

c:\messengerplus\mfernandacls@hotmail.com1.log

c:\messengerplus\micheleangel_79@hotmail.com1.log

c:\messengerplus\migamali@hotmail.com1.log

c:\messengerplus\milamoises@hotmail.com1.log

c:\messengerplus\millasiv@hotmail.com1.log

c:\messengerplus\mimilamarinho@hotmail.com1.log

c:\messengerplus\mississippi_brazilian@hotmail.com1.log

c:\messengerplus\mo_jf@hotmail.com1.log

c:\messengerplus\morais_881@hotmail.com1.log

c:\messengerplus\moraleida@oi.com.br1.log

c:\messengerplus\moygori@hotmail.com1.log

c:\messengerplus\mpsjf@hotmail.com1.log

c:\messengerplus\myller666@hotmail.com1.log

c:\messengerplus\myndocrym@msn.com1.log

c:\messengerplus\nadja_ganda@hotmail.com1.log

c:\messengerplus\nandalimasd@hotmail.com1.log

c:\messengerplus\nandavicosa@hotmail.com1.log

c:\messengerplus\nandopovoa@hotmail.com1.log

c:\messengerplus\nataliaparma@hotmail.com1.log

c:\messengerplus\natashatgs@hotmail.com1.log

c:\messengerplus\nathaliabonissatto@hotmail.com1.log

c:\messengerplus\nathaliagm@hotmail.com1.log

c:\messengerplus\nathcb@hotmail.com1.log

c:\messengerplus\nathypa@hotmail.com1.log

c:\messengerplus\nati_az@hotmail.com1.log

c:\messengerplus\naty_camposp@hotmail.com1.log

c:\messengerplus\nayracoelho@hotmail.com1.log

c:\messengerplus\nebailarocca@hotmail.com1.log

c:\messengerplus\nessafreis@hotmail.com1.log

c:\messengerplus\nicoletolomelli@hotmail.com1.log

c:\messengerplus\nina-sousa@hotmail.com1.log

c:\messengerplus\nina_apocalypse@hotmail.com1.log

c:\messengerplus\odilontokio@hotmail.com1.log

c:\messengerplus\olaninola@hotmail.com1.log

c:\messengerplus\olinda-chaves@hotmail.com1.log

c:\messengerplus\oliviamoreira_oli@hotmail.com1.log

c:\messengerplus\oscarwgbressan@hotmail.com1.log

c:\messengerplus\pamellamachadomadagascar@hotmail.com1.log

c:\messengerplus\pat_uba@hotmail.com1.log

c:\messengerplus\patmontesi@msn.com1.log

c:\messengerplus\patriciagomes@intermedium.com.br1.log

c:\messengerplus\paty_sanna@hotmail.com1.log

c:\messengerplus\paulacorbelli@gmail.com1.log

c:\messengerplus\paulatmarques@hotmail.com1.log

c:\messengerplus\paulo.cadastro@intermedium.com.br1.log

c:\messengerplus\pc_mantikeira@hotmail.com1.log

c:\messengerplus\pf_relacionamento1@intermedium.com.br1.log

c:\messengerplus\pf_relacionamento2@intermedium.com.br1.log

c:\messengerplus\pf_relacionamento4@intermedium.com.br1.log

c:\messengerplus\pf_relacionamento5@intermedium.com.br1.log

c:\messengerplus\pilarzinhamc@hotmail.com1.log

c:\messengerplus\pimentinhajf@hotmail.com1.log

c:\messengerplus\poetajf@hotmail.com1.log

c:\messengerplus\poliaps@hotmail.com1.log

c:\messengerplus\pollyanaalbuquerque@hotmail.com1.log

c:\messengerplus\polyanapsoares@hotmail.com1.log

c:\messengerplus\prigp_87@hotmail.com1.log

c:\messengerplus\priprilla21@hotmail.com1.log

c:\messengerplus\prock2001@msn.com1.log

c:\messengerplus\quel-mmonteiro@hotmail.com1.log

c:\messengerplus\rafael_defaria@hotmail.com1.log

c:\messengerplus\rafaleviana@hotmail.com1.log

c:\messengerplus\rafitxacastelloes@hotmail.com1.log

c:\messengerplus\ramfmg@hotmail.com1.log

c:\messengerplus\raphaela2807@hotmail.com1.log

c:\messengerplus\raphaelaqueiroz@hotmail.com1.log

c:\messengerplus\raphinhapx@hotmail.com1.log

c:\messengerplus\raquelcardosojf@hotmail.com1.log

c:\messengerplus\raulzitah@hotmail.com1.log

c:\messengerplus\re_cheaps@hotmail.com1.log

c:\messengerplus\rebsbeca@hotmail.com1.log

c:\messengerplus\recarvalho16@hotmail.com1.log

c:\messengerplus\ree_camarano@hotmail.com1.log

c:\messengerplus\regina.remonteiro@gmail.com1.log

c:\messengerplus\renata_campomizzi@hotmail.com1.log

c:\messengerplus\renata_s_souza@hotmail.com1.log

c:\messengerplus\renatatokio@hotmail.com1.log

c:\messengerplus\renatinhabperes@hotmail.com1.log

c:\messengerplus\ricardo_muranga@hotmail.com1.log

c:\messengerplus\robertafeital@hotmail.com1.log

c:\messengerplus\rodney.quirino@hotmail.com1.log

c:\messengerplus\rodrigolima_159@hotmail.com1.log

c:\messengerplus\ronanbahia@hotmail.com1.log

c:\messengerplus\rosane-sf@hotmail.com1.log

c:\messengerplus\rosane_fernandes@bol.com.br1.log

c:\messengerplus\rpcorbelli@hotmail.com1.log

c:\messengerplus\ruivavp@hotmail.com1.log

c:\messengerplus\sa_caio@hotmail.com1.log

c:\messengerplus\sammycardoso17@hotmail.com1.log

c:\messengerplus\samuca_do_mau@hotmail.com1.log

c:\messengerplus\samuel_chaves@hotmail.com1.log

c:\messengerplus\samyaiasbeck@gmail.com1.log

c:\messengerplus\sanpam_10@hotmail.com1.log

c:\messengerplus\sapi@intermedium.com.br1.log

c:\messengerplus\sapi1@intermedium.com.br1.log

c:\messengerplus\sapi2@intermedium.com.br1.log

c:\messengerplus\sapi3@intermedium.com.br1.log

c:\messengerplus\sapi5@intermedium.com.br1.log

c:\messengerplus\sapi6@intermedium.com.br1.log

c:\messengerplus\sapi7@intermedium.com.br1.log

c:\messengerplus\saradtb@hotmail.com1.log

c:\messengerplus\sazaneti@hotmail.com1.log

c:\messengerplus\sde_dudzzz@hotmail.com1.log

c:\messengerplus\sheilasperandio@hotmail.com1.log

c:\messengerplus\sillasesacol@yahoo.com.br1.log

c:\messengerplus\skiterd2@hotmail.com1.log

c:\messengerplus\ssminasgerais@hotmail.com1.log

c:\messengerplus\stephanemeirelesmarques@hotmail.com1.log

c:\messengerplus\stksf@hotmail.com1.log

c:\messengerplus\studio1fot@hotmail.com1.log

c:\messengerplus\sylvianecascata@hotmail.com1.log

c:\messengerplus\sylvinho_caxambu@hotmail.com1.log

c:\messengerplus\sylvinho69@hotmail.com1.log

c:\messengerplus\taci.lee@hotmail.com1.log

c:\messengerplus\taci_lee@hotmail.com1.log

c:\messengerplus\talise_machado@hotmail.com1.log

c:\messengerplus\tataqp@hotmail.com1.log

c:\messengerplus\tatiass@hotmail.com1.log

c:\messengerplus\tattinha_pimenta85@hotmail.com1.log

c:\messengerplus\teoniliof@snv.com.br1.log

c:\messengerplus\terracred@yahoo.com.br1.log

c:\messengerplus\tete_nejaim@hotmail.com1.log

c:\messengerplus\thabatasofia@hotmail.com1.log

c:\messengerplus\thais_minnie@hotmail.com1.log

c:\messengerplus\thaiscostaamaral@hotmail.com1.log

c:\messengerplus\thaismatosdeassis@hotmail.com1.log

c:\messengerplus\thalytaqueiroz1@hotmail.com1.log

c:\messengerplus\thatalentosa@hotmail.com1.log

c:\messengerplus\thati_magalhaes@hotmail.com1.log

c:\messengerplus\theresasingulani@hotmail.com1.log

c:\messengerplus\thety_zotta@hotmail.com1.log

c:\messengerplus\thiarama@hotmail.com1.log

c:\messengerplus\thielytavares@hotmail.com1.log

c:\messengerplus\tiagodutra31@hotmail.com1.log

c:\messengerplus\tianinhabento@yahoo.com.br1.log

c:\messengerplus\toniana_gc@hotmail.com1.log

c:\messengerplus\tovalente@gmail.com1.log

c:\messengerplus\trinca_jf@hotmail.com1.log

c:\messengerplus\triplicerepresentacoes@hotmail.com1.log

c:\messengerplus\uba_mg@hotmail.com1.log

c:\messengerplus\ubacred@hotmail.com1.log

c:\messengerplus\ubacreduba@yahoo.com.br1.log

c:\messengerplus\ubahisufv@yahoo.com.br1.log

c:\messengerplus\ubashop@msn.com1.log

c:\messengerplus\valeriabraga25@hotmail.com1.log

c:\messengerplus\valeriabragacb@hotmail.com1.log

c:\messengerplus\valtaglia@hotmail.com1.log

c:\messengerplus\vanessasabioni@hotmail.com1.log

c:\messengerplus\vanessasterk@hotmail.com1.log

c:\messengerplus\veninasilveira@hotmail.com1.log

c:\messengerplus\victoragroufv@hotmail.com1.log

c:\messengerplus\virginia@intermedium.com.br1.log

c:\messengerplus\virginiacancado@terra.com.br1.log

c:\messengerplus\viror3000@hotmail.com1.log

c:\messengerplus\vitougaloucura@hotmail.com1.log

c:\messengerplus\vivialevato_11@hotmail.com1.log

c:\messengerplus\vrbcred@konet.com.br1.log

c:\messengerplus\walaceame@yahoo.com.br1.log

c:\messengerplus\wanessacampos@yahoo.com.br1.log

c:\messengerplus\waniaalmeidaa@uol.com.br1.log

c:\messengerplus\weimarbcjunior@yahoo.com.br1.log

c:\messengerplus\weimarbraga@yahoo.com.br1.log

c:\messengerplus\william.guidini@hotmail.com1.log

c:\messengerplus\wilmabcs@hotmail.com1.log

c:\messengerplus\wilmarjuniocm@hotmail.com1.log

c:\messengerplus\xavier1357@hotmail.com1.log

c:\messengerplus\xgnomax@tayrine.com1.log

c:\messengerplus\yahoo

c:\messengerplus\yohanabraga10@hotmail.com1.log

c:\messengerplus\yvini@hotmail.com1.log

c:\messengerplus\zoommiag@hotmail.com1.log

c:\windows\system32\AutoRun.inf

 

.

(((((((((((((((( Arquivos/Ficheiros criados de 2010-02-19 to 2010-03-19 ))))))))))))))))))))))))))))

.

 

2010-03-19 18:04 . 2010-03-19 18:04 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Malwarebytes

2010-03-19 18:04 . 2010-01-07 19:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-03-19 18:03 . 2010-03-19 18:03 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Malwarebytes

2010-03-19 18:03 . 2010-01-07 19:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-03-19 18:03 . 2010-03-19 18:04 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware

2010-03-19 14:50 . 2010-03-19 21:12 -------- d-----w- c:\windows\SxsCaPendDel

2010-03-19 13:06 . 2010-03-18 23:12 1111320 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgssie.dll

2010-03-18 23:16 . 2010-03-18 19:13 90632 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgtdix.sys

2010-03-18 23:16 . 2010-03-18 19:13 98440 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgldx86.sys

2010-03-18 23:15 . 2010-03-18 19:13 10520 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgrsstx.dll

2010-03-18 23:15 . 2010-03-18 19:13 287000 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgrsx.exe

2010-03-18 23:15 . 2010-03-18 19:13 26824 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgmfx86.sys

2010-03-18 22:37 . 2010-03-18 22:36 1126168 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgupd.exe

2010-03-18 22:37 . 2010-03-18 22:36 1471768 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgupd.dll

2010-03-18 22:37 . 2010-03-18 22:36 587032 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgiproxy.exe

2010-03-18 22:37 . 2010-03-18 22:36 758040 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avginet.dll

2010-03-18 22:13 . 2010-03-19 18:26 -------- d-----w- C:\$AVG8.VAULT$

2010-03-18 19:13 . 2010-03-18 23:13 11952 ----a-w- c:\windows\system32\avgrsstx.dll

2010-03-18 19:13 . 2010-03-18 23:13 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys

2010-03-18 19:13 . 2010-03-18 23:13 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys

2010-03-18 19:13 . 2010-03-18 23:13 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys

2010-03-18 19:13 . 2010-03-19 13:12 -------- d-----w- c:\windows\system32\drivers\Avg

2010-03-07 16:16 . 2010-03-07 16:16 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Skype

2010-03-06 13:18 . 2010-03-06 13:18 -------- d-----r- C:\Driver

 

.

((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-03-19 00:16 . 2008-09-24 11:05 -------- d-----w- c:\arquivos de programas\LHSP

2010-03-18 23:16 . 2008-12-01 18:27 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Avg8

2010-03-18 23:13 . 2010-03-19 13:07 693016 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgcsrvx.exe

2010-03-18 23:13 . 2010-03-19 13:07 390424 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgclitx.dll

2010-03-18 23:13 . 2010-03-19 13:07 70424 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgcrlpx.dll

2010-03-18 23:13 . 2010-03-19 13:07 418072 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgcclix.dll

2010-03-18 23:13 . 2010-03-19 13:07 2061592 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgcorex.dll

2010-03-18 23:13 . 2010-03-19 13:07 2308888 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avguiadv.dll

2010-03-18 23:13 . 2010-03-19 13:07 2808600 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avguires.dll

2010-03-18 23:13 . 2010-03-19 13:07 3476760 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgui.exe

2010-03-18 23:13 . 2010-03-19 13:07 2000152 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgtray.exe

2010-03-18 23:13 . 2010-03-19 13:07 1213720 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgfrw.exe

2010-03-18 23:13 . 2010-03-19 13:07 1209112 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgabout.dll

2010-03-18 23:13 . 2010-03-19 13:07 3299608 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\setup.exe

2010-03-18 23:11 . 2010-03-19 13:06 339736 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgscanx.dll

2010-03-18 23:11 . 2010-03-19 13:06 305944 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgmvflx.dll

2010-03-18 23:11 . 2010-03-19 13:06 177432 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgmail.dll

2010-03-18 23:11 . 2010-03-19 13:06 310552 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avglngx.dll

2010-03-18 23:11 . 2010-03-19 13:06 836888 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgcfgx.dll

2010-03-18 19:13 . 2010-03-19 13:07 2075416 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Avg8\update\backup\avgresf.dll

2010-03-07 16:38 . 2009-11-24 00:15 79488 ----a-w- c:\documents and settings\usuario\Dados de aplicativos\Sun\Java\jre1.6.0_17\gtapi.dll

2010-03-07 16:26 . 2008-10-27 13:38 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Skype

2010-03-07 16:18 . 2008-10-27 13:42 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\skypePM

2010-03-07 16:16 . 2009-09-06 16:34 -------- d-----r- c:\arquivos de programas\Skype

2010-03-07 16:16 . 2008-10-27 13:32 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Skype

2010-02-19 11:46 . 2001-10-28 13:07 68408 ----a-w- c:\windows\system32\perfc016.dat

2010-02-19 11:46 . 2001-10-28 13:07 428340 ----a-w- c:\windows\system32\perfh016.dat

2010-02-10 14:35 . 2010-02-04 13:26 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Youtube Downloader HD

2010-02-05 15:12 . 2010-02-05 15:12 -------- d-----w- c:\arquivos de programas\MSECache

2010-02-04 13:26 . 2010-02-04 13:26 -------- d-----w- c:\arquivos de programas\Youtube Downloader HD

2010-01-24 14:50 . 2010-01-24 14:50 -------- d-----w- c:\documents and settings\usuario\Dados de aplicativos\Foxit

2010-01-24 14:50 . 2010-01-24 14:50 -------- d-----w- c:\arquivos de programas\Foxit Software

2010-01-19 22:10 . 2008-09-25 21:32 -------- d-----w- c:\arquivos de programas\FlashGet

.

 

(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))

.

.

*Nota* entradas vazias e legítimas por defeito não são mostradas.

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]

"swg"="c:\arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-09 68856]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NeroFilterCheck"="c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]

"BigDogPath"="c:\windows\VM_STI.EXE" [2003-01-22 40960]

"SunJavaUpdateSched"="c:\arquivos de programas\Java\jre6\bin\jusched.exe" [2008-12-21 136600]

"PCSuiteTrayApplication"="c:\arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360]

"Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]

"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

"AVG8_TRAY"="c:\arquiv~1\AVG\AVG8\avgtray.exe" [2010-03-19 2046816]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

"Nokia.PCSync"="c:\arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2010-03-18 23:13 11952 ----a-w- c:\windows\system32\avgrsstx.dll

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Arquivos de programas\\FlashGet\\FlashGet.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Arquivos de programas\\RkSoft\\Xadrez\\xadrez.exe"=

"c:\\Arquivos de programas\\Mozilla Firefox\\firefox.exe"=

"c:\\Arquivos de programas\\NetMeeting\\conf.exe"=

"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=

"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgupd.exe"=

"c:\\Arquivos de programas\\AVG\\AVG8\\avgnsx.exe"=

 

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [18/3/2010 16:13 335240]

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [18/3/2010 16:13 108552]

R1 HWiNFO32;HWiNFO32 Kernel Driver;c:\arquivos de programas\HWiNFO32\HWiNFO32.SYS [10/1/2010 14:02 19064]

R2 avg8wd;AVG Free8 WatchDog;c:\arquiv~1\AVG\AVG8\avgwdsvc.exe [18/3/2010 20:12 297752]

.

.

------- Scan Suplementar -------

.

uSearch Page = hxxp://www.google.com

uSearch Bar = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: &Descarregar tudo com o FlashGet - c:\arquivos de programas\FlashGet\jc_all.htm

IE: &Descarregar utilizando o FlashGet - c:\arquivos de programas\FlashGet\jc_link.htm

IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

Trusted Zone: flvdirect.com\www

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

FF - ProfilePath - c:\documents and settings\usuario\Dados de aplicativos\Mozilla\Firefox\Profiles\4u2vjo6r.default\

FF - prefs.js: browser.search.defaulturl - hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search=

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.br/

FF - prefs.js: keyword.URL - hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search=

FF - component: c:\arquivos de programas\AVG\AVG8\Firefox\components\avgssff.dll

FF - component: c:\arquivos de programas\Mozilla Firefox\extensions\{347f6522-829d-3f64-db77-001c59f0aa68}\components\4wNzgJ9l-JALh.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll

FF - plugin: c:\arquivos de programas\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll

FF - plugin: c:\arquivos de programas\Microsoft\Office Live\npOLW.dll

FF - plugin: c:\arquivos de programas\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

 

---- FIREFOX POLICIES ----

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

c:\arquivos de programas\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".com.br");

.

- - - - ORFÃOS REMOVIDOS - - - -

 

HKCU-Run-MsnMsgr - c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe

 

 

 

**************************************************************************

 

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-03-19 20:53

Windows 5.1.2600 Service Pack 2 NTFS

 

Procurando processos ocultos ...

 

Procurando entradas auto inicializáveis ocultas ...

 

Procurando ficheiros/arquivos ocultos ...

 

Varredura completada com sucesso

arquivos/ficheiros ocultos: 0

 

**************************************************************************

.

--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------

 

[HKEY_USERS\S-1-5-21-1275210071-1993962763-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C45B8DE4-45A6-3F60-9886-8E844345BAC7}*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

"abpecplbnoajdiialjgnkjpmbagmplplig"=hex:69,61,61,65,61,6d,6b,6d,6f,61,61,63,

63,66,61,6a,65,6b,00,00

"maoennbnmkegmoimmpkpnjmpok"=hex:6f,61,6c,6b,62,6e,65,69,61,69,62,66,6c,64,61,

67,68,65,6a,66,61,6e,6c,61,6d,6a,6f,63,6b,70,00,00

 

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Òw*]

"6140110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

.

Tempo para conclusão: 2010-03-19 20:59:33

ComboFix-quarantined-files.txt 2010-03-19 23:59

 

Pré-execução: 2.927.632.384 bytes disponíveis

Pós execução: 2.908.372.992 bytes disponíveis

 

WindowsXP-KB310994-SP2-Pro-BootDisk-PTG.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

 

- - End Of File - - 844738871136205603DDB38DC40DBD8C

Compartilhar este post


Link para o post
Compartilhar em outros sites

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:40:13, on 20/3/2010

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

C:\Arquivos de programas\Java\jre6\bin\jqs.exe

C:\WINDOWS\VM_STI.EXE

C:\Arquivos de programas\Java\jre6\bin\jusched.exe

C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\svchost.exe

C:\ARQUIV~1\AVG\AVG8\avgrsx.exe

C:\ARQUIV~1\AVG\AVG8\avgnsx.exe

C:\ARQUIV~1\AVG\AVG8\avgtray.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe

C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexStoreSvr.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

C:\WINDOWS\system32\wbem\wmiapsrv.exe

C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

C:\Arquivos de programas\Mozilla Firefox\firefox.exe

C:\Documents and Settings\usuario\Desktop\HiJackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Arquivos de programas\FlashGet\jccatch_2.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Arquivos de programas\AVG\AVG8\avgssie.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre6\bin\ssv.dll

O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de programas\Arquivos comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Arquivos de programas\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de programas\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Arquivos de programas\FlashGet\getflash.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Arquivos de programas\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [bigDogPath] C:\WINDOWS\VM_STI.EXE LG Web Camera driver

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Arquivos de programas\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Arquivos de programas\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe ARM] "C:\Arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARQUIV~1\AVG\AVG8\avgtray.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [swg] "C:\Arquivos de programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Arquivos de programas\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Descarregar tudo com o FlashGet - C:\Arquivos de programas\FlashGet\jc_all.htm

O8 - Extra context menu item: &Descarregar utilizando o FlashGet - C:\Arquivos de programas\FlashGet\jc_link.htm

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Google Sidewiki... - res://C:\Arquivos de programas\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Arquivos de programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe

O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Arquivos de programas\FlashGet\FlashGet.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe (file missing)

O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp

O15 - Trusted Zone: http://www.flvdirect.com

O15 - ESC Trusted Zone: http://www.flvdirect.com

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Arquivos de programas\AVG\AVG8\avgpp.dll

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARQUIV~1\ARQUIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARQUIV~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Arquivos de programas\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Arquivos de programas\Java\jre6\bin\jqs.exe

O23 - Service: NMIndexingService - Nero AG - C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMIndexingService.exe

O23 - Service: ServiceLayer - Nokia. - C:\Arquivos de programas\PC Connectivity Solution\ServiceLayer.exe

 

--

End of file - 7906 bytes

Compartilhar este post


Link para o post
Compartilhar em outros sites

OK...o PC está limpo. :)

 

 

*Clique em [iniciar] > [Executar] > digite: Combofix /uninstall

*Clique [OK]

 

92674490.jpg

 

*Clique em [Executar]

*Aguarde até surgir a mensagem: "ComboFix está desinstalado"

*Clique [OK]

 

 

Um abraço.

Compartilhar este post


Link para o post
Compartilhar em outros sites

Muito obrigado, deu tudo certo.

Só mais uma dúvida. Eu reparei q apareceu a lista das pessoas do meu msn. E tb enquanto estava com vírus ficava acusando a pasta messenger plus. Inclusive nesse meio tempo eu desinstalei o windows live.

Hoje, durante a instalação do messenger eu precisei cancelá-la e agora quando fui instalar de novo não tá dando de jeito nenhum. tá dando erro.

você sabe me explicar porquê disso? E o q devo fazer?

Novamente, muito obrigado!

Compartilhar este post


Link para o post
Compartilhar em outros sites

PROBLEMA RESOLVIDO!

 

Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.

Compartilhar este post


Link para o post
Compartilhar em outros sites

×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.